User User name Password  
   
Sunday 24.11.2024 / 12:07
Search AfterDawn Forums:        In English   Suomeksi   På svenska
afterdawn.com > forums > software, operating systems and more > windows - virus and spyware problems > my computer has virus that want let me do a scan
Show topics
 
Forums
Forums
My computer has virus that want let me do a scan
  Jump to:
 
Posted Message
Page:12Next >
daddy163
Junior Member
_
18. April 2006 @ 15:03 _ Link to this message    Send private message to this user   
I have the McAfee virus scan but my computer want let me do a scan. Everytime I do 1 the system reboots itself. I have tried to do a scan in safe mode but that don't work. I have even tried McAfee stinger with no luck. PLEASE HELP ME!!!!!!!!!!!! PS I am running windows XP on a built PC
Advertisement
_
__
Senior Member
_
18. April 2006 @ 21:30 _ Link to this message    Send private message to this user   
I hate to say this, but get rid of McAfee. It's by far the worst AV program on the market. Last rating it received from reliable sources was no better than a 4 (outta 10).

You could take your drive out of that system, set it as a slave in another and do an online scan from either AVG, Panda, or Trend Micro.

If you know what the virus files are, by doing the above, you can delete those files having the drive in another system.
aabbccdd
Suspended permanently
_
18. April 2006 @ 22:02 _ Link to this message    Send private message to this user   
or delete McAfee which is a crap program as said download and run Trend Mirco or AVG. thats a good free program ,DONT get norton either ,you may be able to delete the virus with "HighjackThis" its free download and try that first
xaznboitx
Senior Member
_
18. April 2006 @ 23:06 _ Link to this message    Send private message to this user   
Hm...
Trend Micro and the other two freezes my computer. I dont know why. It just does.

There is a forum for this you know..
Moderator
_
19. April 2006 @ 04:18 _ Link to this message    Send private message to this user   
thread teleported to relevant forum



Main PC ~ Intel C2Q Q6600 (G0 Stepping)/Gigabyte GA-EP45-DS3/2GB Crucial Ballistix PC2-8500/Zalman CNPS9700/Antec 900/Corsair HX 620W
Network ~ DD-WRT ~ 2node WDS-WPA2/AES ~ Buffalo WHR-G54S. 3node WPA2/AES ~ WRT54GS v6 (inc. WEP BSSID), WRT54G v2, WRT54G2 v1. *** Forum Rules ***
Senior Member
_
19. April 2006 @ 07:33 _ Link to this message    Send private message to this user   
Hi daddy163, please post a HijackThis log to here.

Instructions -> http://forums.afterdawn.com/thread_view.cfm/263784
(steps 3-5)

I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere.
Senior Member
_
19. April 2006 @ 13:55 _ Link to this message    Send private message to this user   
You wanna remove whatever it is with HjT as i've seen in a few cases malware causes scanners to hang and do whats happening to you..

JaPK's claimed your log so get it posted..

Yours Truly; Rav
BitTorrent Safety Guide: http://forums.afterdawn.com/thread_view.cfm/395674
Free Security Software: http://forums.afterdawn.com/thread_view.cfm/292257
The cleverest of all, in my opinion, is the man who calls himself a fool at least once a month. - Fyodor Dostoevsky
daddy163
Junior Member
_
22. April 2006 @ 08:43 _ Link to this message    Send private message to this user   
JaPK,
Every time I do a virus scan via your link my computer still reboots itself. DO you think it would be better for me to just reboot my whole system.
Senior Member
_
22. April 2006 @ 08:48 _ Link to this message    Send private message to this user   
Hi daddy163.

Jump straight to the step 3 -> http://forums.afterdawn.com/thread_view.cfm/263784

So don't scan with an online scanner yet.

I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere.
Senior Member
_
22. April 2006 @ 10:44 _ Link to this message    Send private message to this user   
@daddy163
Quote:
You wanna remove whatever it is with HjT as i've seen in a few cases malware causes scanners to hang and do whats happening to you..
Read it...

"Every time I do a virus scan via your link my computer still reboots itself."

Thats whats gonna happen..HjT log please, JaPK's clamied it...

Yours Truly; Rav
BitTorrent Safety Guide: http://forums.afterdawn.com/thread_view.cfm/395674
Free Security Software: http://forums.afterdawn.com/thread_view.cfm/292257
The cleverest of all, in my opinion, is the man who calls himself a fool at least once a month. - Fyodor Dostoevsky
daddy163
Junior Member
_
22. April 2006 @ 20:13 _ Link to this message    Send private message to this user   
OK I did the scan here is my log;
Logfile of HijackThis v1.99.1
Scan saved at 11:46:46 PM, on 4/22/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\VIAudioi\SBADeck\ADeck.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\progra~1\mcafee\MCAFEE~1\masalert.exe
C:\Program Files\BellSouth\Alert Manager\BellSouthAlertManager.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\progra~1\mcafee\mcafee antispyware\massrv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Microsoft Office\Office10\msoffice.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\mcafee.com\shared\mcinfo.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www...
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http...
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~1\masalert.exe
O4 - HKLM\..\Run: [BellSouthAlertManager.exe] C:\Program Files\BellSouth\Alert Manager\BellSouthAlertManager.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\system32\pwinprag.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [CU1]
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE
O4 - HKCU\..\Run: [McAfee QuickClean Imonitor] C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe /START
O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\pwinprag.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/229?8d588edfc4be46d8a2396ae9a351e6bf
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/230?8d588edfc4be46d8a2396ae9a351e6bf
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcins...
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x8...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/...
O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} (McAfee Virtual Technician Control Class) - http://us-download.mcafee.com/products/protected/mvt/mvt.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2...
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4744/mcfs...
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O18 - Filter: text/html - {CEA53356-C414-4331-A35E-AA4CE9D8DFA2} - C:\WINDOWS\system32\w9seq.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee AntiSpyware Service - McAfee, Inc. - c:\progra~1\mcafee\mcafee antispyware\massrv.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Unknown owner - C:\Program Files\Norton AntiVirus\SAVScan.exe (file missing)
O23 - Service: ScriptBlocking Service (SBService) - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

I hope one of you guys can help me get this crap off of my pc
Senior Member
_
22. April 2006 @ 20:54 _ Link to this message    Send private message to this user   
Hi daddy163.

OK, you seem to have 3 different antiviruses (well, parts of those) running at the same time. This is propably one reason to your crashes.

You seem to have uninstalled Norton earlier, but there are many remainings running. We'll take those off.
Then you seem to have uninstalled AVG Antivirus too, there is a few remainings left. We'll take those off

McAfee is your current antivirus, we'll left that.

Then you have some infections....

Cleaning instructions:

Go to Control Panel -> Add or remove programs -> Remove Zeno Search, Surf SideKick if found

Download BFU.zip -> http://www.merijn.org/files/bfu.zip
Unzip it to folder C:\BFU

Download this removal script (right-click with mouse, Save target as) ->http://downloads.subratam.org/Lon/sidekickFix.bat
And save it to the same folder than where BFU was installed earlier (c:\BFU).

Do NOT use this yet!

Restart your computer to the safe mode (Press F8 button when computer is starting and choose safe mode)

Press Start -> My Computer -> Go to folder C:\BFU
->Close all other windows, including explorer folders.
->Doubleclick sidekickFix.bat
->Click Yes and follow the instructions, when it asks a restart your pc, restart it.

Run HijackThis and fix these entries (if found): (Do a system scan only, check entries, close all other windows, press Fix checked)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www...
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http...
O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\system32\pwinprag.exe
O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\pwinprag.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2...
O18 - Filter: text/html - {CEA53356-C414-4331-A35E-AA4CE9D8DFA2} - C:\WINDOWS\system32\w9seq.dll


Then if my conclusions about your antivirus situation were right (at the beginning), remove the remainings of AVG and Norton:

Fix these three entries with HijackThis

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE


Open Notepad
-> copy the following lines into a new document:

@echo off
sc stop ccEvtMgr
sc delete ccEvtMgr
sc stop ccSetMgr
sc delete ccSetMgr
sc stop SAVScan
sc delete SAVScan
sc stop SNDSrvc
sc delete SNDSrvc
sc stop Symantec Core LC
sc delete Symantec Core LC


Save the document to your desktop as Removal.bat and filetype: All Files
Go to your desktop and run the file Removal.bat and answer yes to any questions.

Restart your computer to the safemode (Press F8 button when computer is starting and choose safemode)

Make your hidden files visible:
->On the Tools menu in Windows Explorer, click Folder Options.
->Click the View tab.
->Under Hidden files and folders, click Show hidden files and folders.

Delete these files if found:
C:\WINDOWS\system32\pwinprag.exe
C:\WINDOWS\system32\w9seq.dll

Empty the Recycle Bin

Make your hidden files invisible again:
->On the Tools menu in Windows Explorer, click Folder Options.
->Click the View tab.
->Under Hidden files and folders, click Do not show hidden files and folders.

Restart your computer normally.

Post a fresh HijackThis log to here so we can see if your computer is now clean.

I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere.

This message has been edited since posting. Last time this message was edited on 22. April 2006 @ 23:08

Senior Member
_
22. April 2006 @ 21:00 _ Link to this message    Send private message to this user   
Now you can paypal JapK the $150 he just saved you in computer repairs.

Also, the best antivirus is Kaspersky. Period. End of discussion. ;)

The BT Bible 1.2, no longer hosted on rapidshare!:
http://www.plucky.org/component/option,com_vfm/Itemid,54/

Static? Dynamic? What's wrong with your torrent? Tweaks? Fixes? Troubleshoots? All that and more...
http://www.plucky.org
aabbccdd
Suspended permanently
_
22. April 2006 @ 21:49 _ Link to this message    Send private message to this user   
TomMelee ,theres three that are all good ,Kaspersky being one of them Trend Mirco PC-cillin and Nod32 all the best
Senior Member
_
23. April 2006 @ 06:59 _ Link to this message    Send private message to this user   
AVG/AVG free is always a good alternative..

Yours Truly; Rav
BitTorrent Safety Guide: http://forums.afterdawn.com/thread_view.cfm/395674
Free Security Software: http://forums.afterdawn.com/thread_view.cfm/292257
The cleverest of all, in my opinion, is the man who calls himself a fool at least once a month. - Fyodor Dostoevsky
daddy163
Junior Member
_
23. April 2006 @ 08:15 _ Link to this message    Send private message to this user   
new log
Logfile of HijackThis v1.99.1
Scan saved at 12:13:50 PM, on 4/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\VIAudioi\SBADeck\ADeck.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\progra~1\mcafee\MCAFEE~1\masalert.exe
C:\Program Files\BellSouth\Alert Manager\BellSouthAlertManager.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Microsoft Office\Office10\msoffice.exe
c:\progra~1\mcafee\mcafee antispyware\massrv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\svchost.exe
C:\progra~1\mcafee\MCAFEE~1\MASCon.exe
C:\PROGRA~1\mcafee.com\shared\mghtml.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~1\masalert.exe
O4 - HKLM\..\Run: [BellSouthAlertManager.exe] C:\Program Files\BellSouth\Alert Manager\BellSouthAlertManager.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [McAfee QuickClean Imonitor] C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe /START
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/229?8d588edfc4be46d8a2396ae9a351e6bf
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/230?8d588edfc4be46d8a2396ae9a351e6bf
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcins...
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x8...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/...
O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} (McAfee Virtual Technician Control Class) - http://us-download.mcafee.com/products/protected/mvt/mvt.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4744/mcfs...
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee AntiSpyware Service - McAfee, Inc. - c:\progra~1\mcafee\mcafee antispyware\massrv.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe (file missing)

ty
Senior Member
_
23. April 2006 @ 08:42 _ Link to this message    Send private message to this user   
Hi daddy163.

Ok, looking good. There is still one Norton remaining left....

Open Notepad
-> copy the following lines into a new document:

@echo off
sc stop SBService
sc delete SBService

Save the document to your desktop as Removal2.bat and filetype: All Files
Go to your desktop and run the file Removal2.bat and answer yes to any questions.

Then delete these folders:
C:\Program Files\Common Files\Symantec Shared
C:\Program Files\Grisoft
C:\Program Files\Norton AntiVirus

Then we'll clean your registry:
Download CCleaner -> http://www.filehippo.com/download_ccleaner/
Install it and clean your registry with it (take a backup when asked)

Then you could download and install Ewido -> http://www.ewido.net/en/download/
Update it and run a Complete System Scan
Clean the findings and save the log.

Post a new HijackThis log and Ewidos log to here.

I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere.

This message has been edited since posting. Last time this message was edited on 23. April 2006 @ 08:43

daddy163
Junior Member
_
23. April 2006 @ 12:18 _ Link to this message    Send private message to this user   
I've done all that you told me and I hope and pray that this will cure my pc, here are the logs you ask me for;

Logfile of HijackThis v1.99.1
Scan saved at 4:00:14 PM, on 4/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\progra~1\mcafee\mcafee antispyware\massrv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\VIAudioi\SBADeck\ADeck.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\progra~1\mcafee\MCAFEE~1\masalert.exe
C:\Program Files\BellSouth\Alert Manager\BellSouthAlertManager.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\Program Files\McAfee.com\Personal Firewall\MPFTray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Microsoft Office\Office10\msoffice.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\securitysuite.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~1\masalert.exe
O4 - HKLM\..\Run: [BellSouthAlertManager.exe] C:\Program Files\BellSouth\Alert Manager\BellSouthAlertManager.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MPFEXE] "C:\Program Files\McAfee.com\Personal Firewall\MPFTray.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [McAfee QuickClean Imonitor] C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe /START
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/229?8d588edfc4be46d8a2396ae9a351e6bf
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/230?8d588edfc4be46d8a2396ae9a351e6bf
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcins...
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x8...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/...
O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} (McAfee Virtual Technician Control Class) - http://us-download.mcafee.com/products/protected/mvt/mvt.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4744/mcfs...
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee AntiSpyware Service - McAfee, Inc. - c:\progra~1\mcafee\mcafee antispyware\massrv.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 4:17:58 PM, 4/23/2006
+ Report-Checksum: FF4CDA20

+ Scan result:

HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Adware.WebRebates : Cleaned with backup
HKU\S-1-5-21-796845957-963894560-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6001CDF7-6F45-471B-A203-0225615E35A7} -> Adware.Generic : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@ads.addynamix[1].txt -> TrackingCookie.Addynamix : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@bfast[2].txt -> TrackingCookie.Bfast : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@centrport[1].txt -> TrackingCookie.Centrport : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@citi.bridgetrack[1].txt -> TrackingCookie.Bridgetrack : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@com[2].txt -> TrackingCookie.Com : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@data3.perf.overture[2].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@ehg-bestbuy.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@ehg-dig.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@ehg-foxsports.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@ehg-knightridder.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@revenue[2].txt -> TrackingCookie.Revenue : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@twci.coremetrics[1].txt -> TrackingCookie.Coremetrics : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@z1.adserver[1].txt -> TrackingCookie.Adserver : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\Documents and Settings\keno cannady\Cookies\keno cannady@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\keno cannady\Cookies\keno cannady@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\keno cannady\Cookies\keno cannady@zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@adorigin[2].txt -> TrackingCookie.Adorigin : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@ads.addynamix[2].txt -> TrackingCookie.Addynamix : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@as-us.falkag[1].txt -> TrackingCookie.Falkag : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@bfast[1].txt -> TrackingCookie.Bfast : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@bookspan.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@c.enhance[1].txt -> TrackingCookie.Enhance : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@clubmom.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@data.coremetrics[1].txt -> TrackingCookie.Coremetrics : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@ehg-acxiomcorporation.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@ehg-adteractive.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@ehg-cafepress.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@ehg-cbs.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@ehg-dig.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@ehg-electricbusiness.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@ehg-knightridder.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@ehg-lowermybills.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@ehg-medtronic.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@ehg-nestlepurinapetcare.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@ehg-rightnow.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@ehg-wachovia.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@marthastewart.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@media.fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@partnerhealth.com.33473.fb.dbbsrv[2].txt -> TrackingCookie.Dbbsrv : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@paypopup[1].txt -> TrackingCookie.Paypopup : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@phg.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@s.as-us.falkag[2].txt -> TrackingCookie.Falkag : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@sales.liveperson[2].txt -> TrackingCookie.Liveperson : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@server.iad.liveperson[2].txt -> TrackingCookie.Liveperson : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@server3.web-stat[2].txt -> TrackingCookie.Web-stat : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@statse.webtrendslive[1].txt -> TrackingCookie.Webtrendslive : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@twci.coremetrics[1].txt -> TrackingCookie.Coremetrics : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@valueclick[1].txt -> TrackingCookie.Valueclick : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@web4.realtracker[1].txt -> TrackingCookie.Realtracker : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@webstat[2].txt -> TrackingCookie.Web-stat : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@www.myaffiliateprogram[1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@z1.adserver[1].txt -> TrackingCookie.Adserver : Cleaned with backup
C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\HJT\backups\backup-20060422-235000-220.dll -> Not-A-Virus.Downloader.Win32.PopCap.b : Cleaned with backup
C:\HJT\backups\backup-20060423-114147-630.dll -> Not-A-Virus.Downloader.Win32.PopCap.b : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.Downloader.Win32.PopCap.b : Cleaned with backup


::Report End

My Pc is still rebooting itself

This message has been edited since posting. Last time this message was edited on 23. April 2006 @ 13:05

daddy163
Junior Member
_
23. April 2006 @ 13:04 _ Link to this message    Send private message to this user   
My PC is still rebooting itself. I think that I have missed something
Senior Member
_
23. April 2006 @ 21:09 _ Link to this message    Send private message to this user   
Ok, try this...

Download Blacklight and save it to your desktop http://www.f-secure.com/blacklight/try.shtml

Doubleclick blbeta.exe, accept agreement, click > Scan, then > Next

You'll see a list what have been found. There will appear a log in desktop named fsbl.xxxxxxx.log (xxxxxxx will be random numbers ).

Don't choose Rename if something was found!

Copy and paste this log to your next reply.

I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere.

This message has been edited since posting. Last time this message was edited on 23. April 2006 @ 21:09

daddy163
Junior Member
_
24. April 2006 @ 06:53 _ Link to this message    Send private message to this user   
Nothing found. I do appreciate your help, what now?
Senior Member
_
24. April 2006 @ 10:41 _ Link to this message    Send private message to this user   
Ok, your logs look clean. Those crashes might be hardware related....

You could download Memtest and run a few tests, post some results to here when you're ready -> http://hcidesign.com/memtest

You could also download HDDlife and run a few tests, post some results to here when you're ready -> http://www.majorgeeks.com/download.php?det=4486

I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere.

This message has been edited since posting. Last time this message was edited on 24. April 2006 @ 10:41

daddy163
Junior Member
_
24. April 2006 @ 13:31 _ Link to this message    Send private message to this user   
here the log from registy mechanic: This is all the problem areas or files I have on my pc

----------------------------------------------------------------------------------------------------
Registry Mechanic 5.2.0.310
----------------------------------------------------------------------------------------------------
Start of Scan
4/24/2006 4:54:46 PM
Your System Information :
CPU: Intel Pentium
IE: Internet Explorer 6.0.2900
MEMORY FREE: 494388
MEMORY TOTAL: 785904
VIRTUAL FREE: 2019252
VIRTUAL TOTAL: 2097024
WINDOWS VER: Windows XP 5.1 (Build 2600)

----------------------------------------------------------------------------------------------------
Running processes: Process ID
----------------------------------------------------------------------------------------------------
[System Process] 0
System 4
smss.exe 548
csrss.exe 612
winlogon.exe 636
services.exe 680
lsass.exe 700
svchost.exe 856
svchost.exe 916
svchost.exe 1016
svchost.exe 1096
svchost.exe 1164
spoolsv.exe 1388
ewidoctrl.exe 1936
ewidoguard.exe 1952
MASSrv.exe 2004
Mcdetect.exe 2028
McShield.exe 268
McTskshd.exe 316
mcupdmgr.exe 540
MpfService.exe 568
nvsvc32.exe 356
locator.exe 760
wdfmgr.exe 980
wmiprvse.exe 1480
explorer.exe 380
ADeck.exe 2184
mcagent.exe 2204
MASAlert.exe 2260
BellSouthAlertManager.exe 2436
oasclnt.exe 2536
MpfTray.exe 2652
McVSEscn.exe 2668
MpfAgent.exe 3816
msmsgs.exe 4032
Ymsgr_tray.exe 1920
PlgUni.exe 2256
mcvsftsn.exe 2788
WinCinemaMgr.exe 3304
MSOFFICE.EXE 3580
memtest.exe 488
iexplore.exe 2052
RegMech.exe 2756
----------------------------------------------------------------------------------------------------
Sections Scanned:
----------------------------------------------------------------------------------------------------

FX - 2
Location: HKEY_CLASSES_ROOT\.snp
Value : default = Snapshot File
Parsed :

FX - 3
Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bin\OpenWithList
Value : default = blank
Parsed :

FX - 4
Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.EX_\OpenWithList
Value : default = blank
Parsed :

FX - 5
Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.IN_\OpenWithList
Value : default = blank
Parsed :

FX - 6
Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rar\OpenWithList
Value : default = blank
Parsed :

FX - 7
Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tlb\OpenWithList
Value : default = blank
Parsed :

SP - 8
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\WINDOWS\Downloaded Program Files\popcaploader.dll = C:\WINDOWS\Downloaded Program Files\popcaploader.dll
Parsed : C:\WINDOWS\Downloaded Program Files\popcaploader.dll

ARP - 9
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BroadJump Client Foundation
Value : DisplayIcon = C:\Program Files\BroadJump\Client Foundation\CFD.exe
Parsed : C:\Program Files\BroadJump\Client Foundation\CFD.exe

ARP - 10
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sevinst
Value : QuietUninstallString = C:\Program Files\Common Files\Symantec Shared\SEVINST.EXE /U /Q
Parsed : C:\Program Files\Common Files\Symantec Shared\SEVINST.EXE

ARP - 11
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Genie OnlineMy Toolbar
Value : UninstallString = regsvr32 /u /s "C:\Program Files\KoolBar\koolbar.dll"
Parsed : C:\Program Files\KoolBar\koolbar.dll

ARP - 12
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{228F6876-A313-40A3-91C0-C3CBE6997D09}
Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\MSRedist\
Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\MSRedist

ARP - 13
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2908F0CB-C1D4-447F-97A2-CFC135C9F8D4}
Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV\
Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV

ARP - 14
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2DA85B02-13C0-4E6D-9A76-22E6B3DD0CB2}
Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SymNet\
Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SymNet

ARP - 15
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{34EEB1F5-E939-40A1-A6BA-957282A4B2C8}
Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\Help\
Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\Help

ARP - 16
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3E908702-AF35-4611-9518-955DA24B7E07}
Value : InstallSource = C:\WINDOWS\TEMP\IXP000.TMP\
Parsed : C:\WINDOWS\TEMP\IXP000.TMP

ARP - 17
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}
Value : DisplayIcon = C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe,0
Parsed : C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe

ARP - 18
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{77772678-817F-4401-9301-ED1D01A8DA56}
Value : InstallLocation = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

ARP - 19
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{77772678-817F-4401-9301-ED1D01A8DA56}
Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SPBBC\
Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SPBBC

ARP - 20
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B43D18F-DC74-4D44-814E-9BD3420B8E44}
Value : Readme = C:\Program Files\McAfee\McAfee QuickClean\Readme.txt
Parsed : C:\Program Files\McAfee\McAfee QuickClean\Readme.txt

ARP - 21
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90280409-6000-11D3-8CFE-0050048383C9}
Value : InstallSource = C:\Documents and Settings\keno cannady\Shared\Microsoft Office XP Professional (Includes Serial Number)\Microsoft Office XP\
Parsed : C:\Documents and Settings\keno cannady\Shared\Microsoft Office XP Professional (Includes Serial Number)\Microsoft Office XP

ARP - 22
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C6F5B6CF-609C-428E-876F-CA83176C021B}
Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV\
Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV

ARP - 23
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CA0A1E54-CE0F-4366-B09C-A87B61DC5633}
Value : InstallSource = C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\LIVEUP~1\DOWNLO~1\EXITEM~1.0_E\
Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\LIVEUP~1\DOWNLO~1\EXITEM~1.0_E

ARP - 24
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D1FF75E7-DD42-4CFD-B052-20B3FFF4EDB8}
Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV\
Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV

ARP - 25
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D327AFC9-7BAA-473A-8319-6EB7A0D40138}
Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\ScrBlock\
Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\ScrBlock

ARP - 26
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DC367608-64A7-4BF7-92F4-8BAA25BA02DB}
Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\ccCommon\
Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\ccCommon

ARP - 27
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E5EE9939-259F-4DE2-8023-5C49E16A4F43}
Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV\
Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV

ARP - 28
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F5346614-B7C4-4E94-826A-E2363155233D}
Value : InstallSource = C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\bye16.tmp\Disk1\
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\bye16.tmp\Disk1

ARP - 29
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F64306A5-4C32-41bb-B153-53986527FAB4}
Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SymSC\
Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SymSC

CC - 30
Location: HKEY_CLASSES_ROOT\AcroExch.Document.7\protocol\StdFileEditing\server
Value : (Default) = "C:\Program Files\Adobe\Acrobat 7.0\Acrobat\Acrobat.exe"
Parsed : C:\Program Files\Adobe\Acrobat 7.0\Acrobat\Acrobat.exe

CC - 31
Location: HKEY_CLASSES_ROOT\CLSID\{00CEDC01-864D-11D3-908D-00C0F03B3EDC}\ToolboxBitmap32
Value : (Default) = C:\Program Files\Real\RealOne Player\ierjplug.dll, 1
Parsed : C:\Program Files\Real\RealOne Player\ierjplug.dll

CC - 32
Location: HKEY_CLASSES_ROOT\CLSID\{0494D0DE-F8E0-41ad-92A3-14154ECE70AC}\Instance\InitPropertyBag
Value : Url = res://C:\PROGRA~1\MyWay\myBar\1.bin\MYBAR.DLL/105
Parsed : C:\PROGRA~1\MyWay\myBar\1.bin\MYBAR.DLL

CC - 33
Location: HKEY_CLASSES_ROOT\CLSID\{06290BD5-48AA-11D2-8432-006008C3FBFC}\InprocServer32
Value : ScriptStopper_InProcServer32 = C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrBlock.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrBlock.dll

CC - 34
Location: HKEY_CLASSES_ROOT\CLSID\{166B1BCA-3F9C-11CF-8075-444553540000}\ToolboxBitmap32
Value : (Default) = C:\WINDOWS\system32\Macromed\Shockwave 10\Control.dll, 203
Parsed : C:\WINDOWS\system32\Macromed\Shockwave 10\Control.dll

CC - 35
Location: HKEY_CLASSES_ROOT\CLSID\{9ccfb0e0-fbce-11d6-8a38-00b0d0c6b814}\LocalServer
Value : (Default) = C:\Program Files\McAfee\McAfee Privacy Service\GUARDDOG.EXE
Parsed : C:\Program Files\McAfee\McAfee Privacy Service\GUARDDOG.EXE

CC - 36
Location: HKEY_CLASSES_ROOT\CLSID\{CC2C83A6-9BE4-11D0-98E7-00C04FC2CAF5}\InprocServer32
Value : SystemDB = C:\Program Files\Microsoft Office\Office10\1033\system.mdw
Parsed : C:\Program Files\Microsoft Office\Office10\1033\system.mdw

CC - 37
Location: HKEY_CLASSES_ROOT\DVD\DefaultIcon
Value : MPlayer2.BAK = C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe,0
Parsed : C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe

CC - 38
Location: HKEY_CLASSES_ROOT\TypeLib\{00000000-0000-0000-0000-000000000002}\1.0\0\win32
Value : (Default) = C:\Program Files\KoolBar\koolbar.dll
Parsed : C:\Program Files\KoolBar\koolbar.dll

CC - 39
Location: HKEY_CLASSES_ROOT\TypeLib\{00000000-0000-0000-0000-000000000002}\1.0\HELPDIR
Value : (Default) = C:\Program Files\KoolBar\
Parsed : C:\Program Files\KoolBar

CC - 40
Location: HKEY_CLASSES_ROOT\TypeLib\{00025E01-0000-0000-C000-000000000046}\3.0\0\win32
Value : (Default) = C:\Program Files\Common Files\Microsoft Shared\DAO\DAO3032.DLL
Parsed : C:\Program Files\Common Files\Microsoft Shared\DAO\DAO3032.DLL

CC - 41
Location: HKEY_CLASSES_ROOT\TypeLib\{0002E540-0000-0000-C000-000000000046}\1.0\0\win32
Value : (Default) = C:\Program Files\Microsoft Office\Office\MSOWC.DLL
Parsed : C:\Program Files\Microsoft Office\Office\MSOWC.DLL

CC - 42
Location: HKEY_CLASSES_ROOT\TypeLib\{0002E540-0000-0000-C000-000000000046}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Microsoft Office\Office\
Parsed : C:\Program Files\Microsoft Office\Office

CC - 43
Location: HKEY_CLASSES_ROOT\TypeLib\{00CEDBF1-864D-11D3-908D-00C0F03B3EDC}\1.0\0\win32
Value : (Default) = C:\Program Files\Real\RealOne Player\ierjplug.dll
Parsed : C:\Program Files\Real\RealOne Player\ierjplug.dll

CC - 44
Location: HKEY_CLASSES_ROOT\TypeLib\{00CEDBF1-864D-11D3-908D-00C0F03B3EDC}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Real\RealOne Player\
Parsed : C:\Program Files\Real\RealOne Player

CC - 45
Location: HKEY_CLASSES_ROOT\TypeLib\{0494D0D0-F8E0-41AD-92A3-14154ECE70AC}\1.0\0\win32
Value : (Default) = C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
Parsed : C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL

CC - 46
Location: HKEY_CLASSES_ROOT\TypeLib\{0494D0D0-F8E0-41AD-92A3-14154ECE70AC}\1.0\HELPDIR
Value : (Default) = C:\Program Files\MyWay\myBar\1.bin\
Parsed : C:\Program Files\MyWay\myBar\1.bin

CC - 47
Location: HKEY_CLASSES_ROOT\TypeLib\{06DD38D0-D187-11CF-A80D-00C04FD74AD8}\1.0\0\win32
Value : (Default) = C:\WINDOWS\System32\plugin.ocx
Parsed : C:\WINDOWS\System32\plugin.ocx

CC - 48
Location: HKEY_CLASSES_ROOT\TypeLib\{091FC996-00F1-4ED0-8351-7F0BFD553172}\1.0\0\win32
Value : (Default) = C:\PROGRA~1\COMMON~1\SYMANT~1\SymLTCOM.dll
Parsed : C:\PROGRA~1\COMMON~1\SYMANT~1\SymLTCOM.dll

CC - 49
Location: HKEY_CLASSES_ROOT\TypeLib\{091FC996-00F1-4ED0-8351-7F0BFD553172}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
Parsed : C:\Program Files\Common Files\Symantec Shared

CC - 50
Location: HKEY_CLASSES_ROOT\TypeLib\{0A8B9461-3921-11D3-B1AB-0080C84E9C15}\1.0\0\win32
Value : (Default) = C:\Program Files\CyberLink\PowerDVD\CLInet.dll
Parsed : C:\Program Files\CyberLink\PowerDVD\CLInet.dll

CC - 51
Location: HKEY_CLASSES_ROOT\TypeLib\{0A8B9461-3921-11D3-B1AB-0080C84E9C15}\1.0\HELPDIR
Value : (Default) = C:\Program Files\CyberLink\PowerDVD\
Parsed : C:\Program Files\CyberLink\PowerDVD

CC - 52
Location: HKEY_CLASSES_ROOT\TypeLib\{0E9FFA9E-B267-44DF-BC81-2B08E3977ED5}\1.0\0\win32
Value : (Default) = C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
Parsed : C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe

CC - 53
Location: HKEY_CLASSES_ROOT\TypeLib\{0E9FFA9E-B267-44DF-BC81-2B08E3977ED5}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Microsoft AntiSpyware
Parsed : C:\Program Files\Microsoft AntiSpyware

CC - 54
Location: HKEY_CLASSES_ROOT\TypeLib\{140CF3D1-451B-4C9C-AB04-02C72D06A88D}\1.0\0\win32
Value : (Default) = C:\Program Files\Microsoft AntiSpyware\gcAntiSpywareLibrary.dll
Parsed : C:\Program Files\Microsoft AntiSpyware\gcAntiSpywareLibrary.dll

CC - 55
Location: HKEY_CLASSES_ROOT\TypeLib\{140CF3D1-451B-4C9C-AB04-02C72D06A88D}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Microsoft AntiSpyware
Parsed : C:\Program Files\Microsoft AntiSpyware

CC - 56
Location: HKEY_CLASSES_ROOT\TypeLib\{166B1BC7-3F9C-11CF-8075-444553540000}\1.0\0\win32
Value : (Default) = C:\WINDOWS\system32\Macromed\Shockwave 10\Control.dll
Parsed : C:\WINDOWS\system32\Macromed\Shockwave 10\Control.dll

CC - 57
Location: HKEY_CLASSES_ROOT\TypeLib\{1C3159CA-948C-4290-A920-4C804DF9FB7D}\1.0\0\win32
Value : (Default) = C:\Program Files\Norton AntiVirus\Navlcom.dll
Parsed : C:\Program Files\Norton AntiVirus\Navlcom.dll

CC - 58
Location: HKEY_CLASSES_ROOT\TypeLib\{1C3159CA-948C-4290-A920-4C804DF9FB7D}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

CC - 59
Location: HKEY_CLASSES_ROOT\TypeLib\{20F6AEAC-284A-4022-A0A8-718AB2087D37}\1.0\0\win32
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\SLTCHK01.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\SLTCHK01.dll

CC - 60
Location: HKEY_CLASSES_ROOT\TypeLib\{20F6AEAC-284A-4022-A0A8-718AB2087D37}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
Parsed : C:\Program Files\Common Files\Symantec Shared

CC - 61
Location: HKEY_CLASSES_ROOT\TypeLib\{226CDAFB-819C-4298-89FA-8A018BB188B5}\1.0\0\win32
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\ccErrDsp.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\ccErrDsp.dll

CC - 62
Location: HKEY_CLASSES_ROOT\TypeLib\{226CDAFB-819C-4298-89FA-8A018BB188B5}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
Parsed : C:\Program Files\Common Files\Symantec Shared

CC - 63
Location: HKEY_CLASSES_ROOT\TypeLib\{2292E927-BD89-40DE-999A-4E72CE0EAA4F}\1.0\0\win32
Value : (Default) = C:\Program Files\Norton AntiVirus\NavShExt.dll
Parsed : C:\Program Files\Norton AntiVirus\NavShExt.dll

CC - 64
Location: HKEY_CLASSES_ROOT\TypeLib\{2292E927-BD89-40DE-999A-4E72CE0EAA4F}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

CC - 65
Location: HKEY_CLASSES_ROOT\TypeLib\{2CECFD1F-CA35-4558-AC7F-64B6B463714A}\1.0\0\win32
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
Parsed : C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

CC - 66
Location: HKEY_CLASSES_ROOT\TypeLib\{2CECFD1F-CA35-4558-AC7F-64B6B463714A}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
Parsed : C:\Program Files\Common Files\Symantec Shared

CC - 67
Location: HKEY_CLASSES_ROOT\TypeLib\{31DDE823-839A-4DD2-8D96-DF766052E142}\1.0\0\win32
Value : (Default) = C:\Program Files\Microsoft AntiSpyware\gcTCPObjLib.dll
Parsed : C:\Program Files\Microsoft AntiSpyware\gcTCPObjLib.dll

CC - 68
Location: HKEY_CLASSES_ROOT\TypeLib\{31DDE823-839A-4DD2-8D96-DF766052E142}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Microsoft AntiSpyware
Parsed : C:\Program Files\Microsoft AntiSpyware

CC - 69
Location: HKEY_CLASSES_ROOT\TypeLib\{390CE9E4-C4A0-11D4-8A92-0090271D4F88}\1.0\0\win32
Value : (Default) = C:\Program Files\Yahoo!\Messenger\ycrwin32.dll
Parsed : C:\Program Files\Yahoo!\Messenger\ycrwin32.dll

CC - 70
Location: HKEY_CLASSES_ROOT\TypeLib\{3A76A523-4FBC-487C-A94F-A94EA80E48EF}\1.0\0\win32
Value : (Default) = C:\WINDOWS\system32\w9seq.dll
Parsed : C:\WINDOWS\system32\w9seq.dll

CC - 71
Location: HKEY_CLASSES_ROOT\TypeLib\{3ABF9055-667E-4FDF-ADDA-2622E8677CBC}\1.0\0\win32
Value : (Default) = C:\PROGRA~1\NORTON~1\NAVEVENT.DLL
Parsed : C:\PROGRA~1\NORTON~1\NAVEVENT.DLL

CC - 72
Location: HKEY_CLASSES_ROOT\TypeLib\{3ABF9055-667E-4FDF-ADDA-2622E8677CBC}\1.0\HELPDIR
Value : (Default) = C:\PROGRA~1\NORTON~1\
Parsed : C:\PROGRA~1\NORTON~1

CC - 73
Location: HKEY_CLASSES_ROOT\TypeLib\{3C2E74A0-887E-11D2-B40A-00600831DD76}\1.0\0\win32
Value : (Default) = C:\PROGRA~1\NORTON~1\NAVLUCBK.dll
Parsed : C:\PROGRA~1\NORTON~1\NAVLUCBK.dll

CC - 74
Location: HKEY_CLASSES_ROOT\TypeLib\{3C2E74A0-887E-11D2-B40A-00600831DD76}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

CC - 75
Location: HKEY_CLASSES_ROOT\TypeLib\{3C3D7949-0006-4745-B3F6-BED93B98FA9B}\1.0\0\win32
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\ccPwd.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\ccPwd.dll

CC - 76
Location: HKEY_CLASSES_ROOT\TypeLib\{3C3D7949-0006-4745-B3F6-BED93B98FA9B}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
Parsed : C:\Program Files\Common Files\Symantec Shared

CC - 77
Location: HKEY_CLASSES_ROOT\TypeLib\{3C878962-A37D-4674-AB76-2746A0E64CE7}\1.0\0\win32
Value : (Default) = C:\Program Files\BroadJump\Client Foundation\CFD.exe
Parsed : C:\Program Files\BroadJump\Client Foundation\CFD.exe

CC - 78
Location: HKEY_CLASSES_ROOT\TypeLib\{405DE7B2-E7DD-11D2-92C5-00C0F01F77C1}\1.0\0\win32
Value : (Default) = C:\Program Files\Real\RealOne Player\rpau3260.dll
Parsed : C:\Program Files\Real\RealOne Player\rpau3260.dll

CC - 79
Location: HKEY_CLASSES_ROOT\TypeLib\{405DE7B2-E7DD-11D2-92C5-00C0F01F77C1}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Real\RealOne Player\
Parsed : C:\Program Files\Real\RealOne Player

CC - 80
Location: HKEY_CLASSES_ROOT\TypeLib\{41695A81-6414-11D4-8FB3-00D0B7730277}\1.0\0\win32
Value : (Default) = C:\Program Files\Yahoo!\Messenger\asw.dll
Parsed : C:\Program Files\Yahoo!\Messenger\asw.dll

CC - 81
Location: HKEY_CLASSES_ROOT\TypeLib\{41949BA1-98CB-4D6F-B27B-4DA67A8B96A5}\1.0\0\win32
Value : (Default) = C:\Program Files\Microsoft AntiSpyware\gcASThreatAudit.dll
Parsed : C:\Program Files\Microsoft AntiSpyware\gcASThreatAudit.dll

CC - 82
Location: HKEY_CLASSES_ROOT\TypeLib\{41949BA1-98CB-4D6F-B27B-4DA67A8B96A5}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Microsoft AntiSpyware
Parsed : C:\Program Files\Microsoft AntiSpyware

CC - 83
Location: HKEY_CLASSES_ROOT\TypeLib\{45A036EA-835E-4678-A5AC-1D117F555C06}\1.0\0\win32
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\SymUIAx2.ocx
Parsed : C:\Program Files\Common Files\Symantec Shared\SymUIAx2.ocx

CC - 84
Location: HKEY_CLASSES_ROOT\TypeLib\{45A036EA-835E-4678-A5AC-1D117F555C06}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
Parsed : C:\Program Files\Common Files\Symantec Shared

CC - 85
Location: HKEY_CLASSES_ROOT\TypeLib\{47E5F2FC-9048-4D04-9A44-691584BE78A8}\1.0\0\win32
Value : (Default) = C:\Program Files\Microsoft AntiSpyware\gcASPrivacyLib.dll
Parsed : C:\Program Files\Microsoft AntiSpyware\gcASPrivacyLib.dll

CC - 86
Location: HKEY_CLASSES_ROOT\TypeLib\{47E5F2FC-9048-4D04-9A44-691584BE78A8}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Microsoft AntiSpyware
Parsed : C:\Program Files\Microsoft AntiSpyware

CC - 87
Location: HKEY_CLASSES_ROOT\TypeLib\{4D26B19F-60BD-43DB-BC69-6B5A67BA8B71}\1.0\0\win32
Value : (Default) = C:\Program Files\Norton AntiVirus\IWP\fwUI.dll
Parsed : C:\Program Files\Norton AntiVirus\IWP\fwUI.dll

CC - 88
Location: HKEY_CLASSES_ROOT\TypeLib\{4D26B19F-60BD-43DB-BC69-6B5A67BA8B71}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Norton AntiVirus\IWP\fwUI.dll
Parsed : C:\Program Files\Norton AntiVirus\IWP\fwUI.dll

CC - 89
Location: HKEY_CLASSES_ROOT\TypeLib\{4E5A5CBD-2CE8-4085-B515-A20137D70D3D}\1.0\0\win32
Value : (Default) = C:\Program Files\Norton AntiVirus\IWP\ACDisp.dll
Parsed : C:\Program Files\Norton AntiVirus\IWP\ACDisp.dll

CC - 90
Location: HKEY_CLASSES_ROOT\TypeLib\{4EE12B71-AA5E-45EC-8666-2DB3AD3FDF44}\1.0\0\win32
Value : (Default) = C:\Program Files\YourSiteBar\ysb.dll
Parsed : C:\Program Files\YourSiteBar\ysb.dll

CC - 91
Location: HKEY_CLASSES_ROOT\TypeLib\{4EE12B71-AA5E-45EC-8666-2DB3AD3FDF44}\1.0\HELPDIR
Value : (Default) = C:\Program Files\YourSiteBar\
Parsed : C:\Program Files\YourSiteBar

CC - 92
Location: HKEY_CLASSES_ROOT\TypeLib\{52D761FC-F7A2-4CF1-AEA9-B1746E2A2B5C}\1.0\0\win32
Value : (Default) = C:\Program Files\Microsoft AntiSpyware\gcASSoapLib.dll
Parsed : C:\Program Files\Microsoft AntiSpyware\gcASSoapLib.dll

CC - 93
Location: HKEY_CLASSES_ROOT\TypeLib\{52D761FC-F7A2-4CF1-AEA9-B1746E2A2B5C}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Microsoft AntiSpyware
Parsed : C:\Program Files\Microsoft AntiSpyware

CC - 94
Location: HKEY_CLASSES_ROOT\TypeLib\{52F2F122-2BC5-11D2-8FB7-000000000000}\1.0\0\win32
Value : (Default) = C:\Program Files\Adobe\Photoshop CS\ImageReady.exe
Parsed : C:\Program Files\Adobe\Photoshop CS\ImageReady.exe

CC - 95
Location: HKEY_CLASSES_ROOT\TypeLib\{54635C92-DFAF-4A99-8802-92FB068A6154}\1.0\0\win32
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Parsed : C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

CC - 96
Location: HKEY_CLASSES_ROOT\TypeLib\{54635C92-DFAF-4A99-8802-92FB068A6154}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\CCPD-LC\
Parsed : C:\Program Files\Common Files\Symantec Shared\CCPD-LC

CC - 97
Location: HKEY_CLASSES_ROOT\TypeLib\{54B0DF71-97D6-493C-834D-99FC9E19D612}\1.0\0\win32
Value : (Default) = C:\Program Files\Norton AntiVirus\IWP\ISWrap.dll
Parsed : C:\Program Files\Norton AntiVirus\IWP\ISWrap.dll

CC - 98
Location: HKEY_CLASSES_ROOT\TypeLib\{54CC4A82-E256-4AB1-BA85-F8FF36619969}\1.0\0\win32
Value : (Default) = C:\PROGRA~1\NORTON~1\NAVSTATS.dll
Parsed : C:\PROGRA~1\NORTON~1\NAVSTATS.dll

CC - 99
Location: HKEY_CLASSES_ROOT\TypeLib\{54CC4A82-E256-4AB1-BA85-F8FF36619969}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

CC - 100
Location: HKEY_CLASSES_ROOT\TypeLib\{56EBB89D-BB5A-4408-BA3F-04F68EB28690}\1.0\0\win32
Value : (Default) = C:\Program Files\Norton AntiVirus\IWP\ISLuCbk.dll
Parsed : C:\Program Files\Norton AntiVirus\IWP\ISLuCbk.dll

CC - 101
Location: HKEY_CLASSES_ROOT\TypeLib\{5830698F-7FC0-40CD-A453-9A0CAFDF3A64}\1.0\0\win32
Value : (Default) = C:\Program Files\Altnet\Download Manager\adm.exe
Parsed : C:\Program Files\Altnet\Download Manager\adm.exe

CC - 102
Location: HKEY_CLASSES_ROOT\TypeLib\{5830698F-7FC0-40CD-A453-9A0CAFDF3A64}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Altnet\Download Manager\
Parsed : C:\Program Files\Altnet\Download Manager

CC - 103
Location: HKEY_CLASSES_ROOT\TypeLib\{586C6565-AEDF-4837-A1B2-9E98EB4BD8AD}\1.0\0\win32
Value : (Default) = C:\Program Files\Norton AntiVirus\NAVAPSCR.dll
Parsed : C:\Program Files\Norton AntiVirus\NAVAPSCR.dll

CC - 104
Location: HKEY_CLASSES_ROOT\TypeLib\{586C6565-AEDF-4837-A1B2-9E98EB4BD8AD}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

CC - 105
Location: HKEY_CLASSES_ROOT\TypeLib\{58C72A18-DF21-49BC-B0D6-2EDE23281506}\1.0\0\win32
Value : (Default) = C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\SymIDSlu.dll
Parsed : C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\SymIDSlu.dll

CC - 106
Location: HKEY_CLASSES_ROOT\TypeLib\{58C72A18-DF21-49BC-B0D6-2EDE23281506}\1.0\HELPDIR
Value : (Default) = C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\
Parsed : C:\PROGRA~1\COMMON~1\SYMANT~1\IDS

CC - 107
Location: HKEY_CLASSES_ROOT\TypeLib\{60681DC5-21B2-4264-B1F1-E1289819E023}\1.0\0\win32
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
Parsed : C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

CC - 108
Location: HKEY_CLASSES_ROOT\TypeLib\{60681DC5-21B2-4264-B1F1-E1289819E023}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
Parsed : C:\Program Files\Common Files\Symantec Shared

CC - 109
Location: HKEY_CLASSES_ROOT\TypeLib\{662ADDE9-5AB3-4A01-8015-FB61D18B0067}\1.0\0\win32
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
Parsed : C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

CC - 110
Location: HKEY_CLASSES_ROOT\TypeLib\{662ADDE9-5AB3-4A01-8015-FB61D18B0067}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\SPBBC\
Parsed : C:\Program Files\Common Files\Symantec Shared\SPBBC

CC - 111
Location: HKEY_CLASSES_ROOT\TypeLib\{676F6D1D-C559-42A9-860B-27C1477B7179}\1.0\0\win32
Value : (Default) = C:\Program Files\Altnet\Download Manager\adm25.dll
Parsed : C:\Program Files\Altnet\Download Manager\adm25.dll

CC - 112
Location: HKEY_CLASSES_ROOT\TypeLib\{676F6D1D-C559-42A9-860B-27C1477B7179}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Altnet\Download Manager\
Parsed : C:\Program Files\Altnet\Download Manager

CC - 113
Location: HKEY_CLASSES_ROOT\TypeLib\{68786388-3E7A-4E69-BDB4-814A1EEB1C0D}\1.0\0\win32
Value : (Default) = C:\Program Files\Norton AntiVirus\OPScan.exe
Parsed : C:\Program Files\Norton AntiVirus\OPScan.exe

CC - 114
Location: HKEY_CLASSES_ROOT\TypeLib\{68786388-3E7A-4E69-BDB4-814A1EEB1C0D}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

CC - 115
Location: HKEY_CLASSES_ROOT\TypeLib\{6B64D109-9674-4D70-8E63-EE0F9A7C9436}\1.0\0\win32
Value : (Default) = C:\Program Files\Microsoft AntiSpyware\gcAntiSpywareLibrary.dll
Parsed : C:\Program Files\Microsoft AntiSpyware\gcAntiSpywareLibrary.dll

CC - 116
Location: HKEY_CLASSES_ROOT\TypeLib\{6B64D109-9674-4D70-8E63-EE0F9A7C9436}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Microsoft AntiSpyware
Parsed : C:\Program Files\Microsoft AntiSpyware

CC - 117
Location: HKEY_CLASSES_ROOT\TypeLib\{6E2295DE-2B0E-4ED8-91A8-D9E9A514A027}\1.0\0\win32
Value : (Default) = C:\Program Files\Norton AntiVirus\IWP\niscmnht.dll
Parsed : C:\Program Files\Norton AntiVirus\IWP\niscmnht.dll

CC - 118
Location: HKEY_CLASSES_ROOT\TypeLib\{7479B280-A309-415C-A351-05483C51F75F}\1.0\0\win32
Value : (Default) = C:\Program Files\Microsoft AntiSpyware\gcSoftwareUpdateLib.dll
Parsed : C:\Program Files\Microsoft AntiSpyware\gcSoftwareUpdateLib.dll

CC - 119
Location: HKEY_CLASSES_ROOT\TypeLib\{7479B280-A309-415C-A351-05483C51F75F}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Microsoft AntiSpyware
Parsed : C:\Program Files\Microsoft AntiSpyware

CC - 120
Location: HKEY_CLASSES_ROOT\TypeLib\{77F05869-E2D3-430E-8364-4D2247DECDE4}\1.0\0\win32
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\CfgWiz.tlb
Parsed : C:\Program Files\Common Files\Symantec Shared\CfgWiz.tlb

CC - 121
Location: HKEY_CLASSES_ROOT\TypeLib\{77F05869-E2D3-430E-8364-4D2247DECDE4}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
Parsed : C:\Program Files\Common Files\Symantec Shared

CC - 122
Location: HKEY_CLASSES_ROOT\TypeLib\{7C1B9D8B-2B5F-41B2-95F7-DE2C5BD594EC}\1.0\0\win32
Value : (Default) = C:\PROGRA~1\NORTON~1\NAVTasks.dll
Parsed : C:\PROGRA~1\NORTON~1\NAVTasks.dll

CC - 123
Location: HKEY_CLASSES_ROOT\TypeLib\{7C1B9D8B-2B5F-41B2-95F7-DE2C5BD594EC}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

CC - 124
Location: HKEY_CLASSES_ROOT\TypeLib\{822E40E5-8012-40F0-AB0E-EC7B0DFF76BC}\1.0\0\win32
Value : (Default) = C:\Program Files\Norton AntiVirus\ccIMScan.dll
Parsed : C:\Program Files\Norton AntiVirus\ccIMScan.dll

CC - 125
Location: HKEY_CLASSES_ROOT\TypeLib\{822E40E5-8012-40F0-AB0E-EC7B0DFF76BC}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

CC - 126
Location: HKEY_CLASSES_ROOT\TypeLib\{838E8E82-F171-4006-A930-9D57949BC2AC}\1.0\0\win32
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\LiveReg\LRRES.DLL
Parsed : C:\Program Files\Common Files\Symantec Shared\LiveReg\LRRES.DLL

CC - 127
Location: HKEY_CLASSES_ROOT\TypeLib\{838E8E82-F171-4006-A930-9D57949BC2AC}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\LiveReg\
Parsed : C:\Program Files\Common Files\Symantec Shared\LiveReg

CC - 128
Location: HKEY_CLASSES_ROOT\TypeLib\{84699B2B-F985-4C87-ADB8-6FDCAD52ED22}\1.0\0\win32
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\LiveReg\LSCTRL.DLL
Parsed : C:\Program Files\Common Files\Symantec Shared\LiveReg\LSCTRL.DLL

CC - 129
Location: HKEY_CLASSES_ROOT\TypeLib\{84699B2B-F985-4C87-ADB8-6FDCAD52ED22}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\LiveReg\
Parsed : C:\Program Files\Common Files\Symantec Shared\LiveReg

CC - 130
Location: HKEY_CLASSES_ROOT\TypeLib\{852C26A8-5C40-4EFB-9D81-096B21BF9D81}\1.0\0\win32
Value : (Default) = C:\PROGRA~1\NORTON~1\DefAlert.dll
Parsed : C:\PROGRA~1\NORTON~1\DefAlert.dll

CC - 131
Location: HKEY_CLASSES_ROOT\TypeLib\{852C26A8-5C40-4EFB-9D81-096B21BF9D81}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

CC - 132
Location: HKEY_CLASSES_ROOT\TypeLib\{86073239-029C-458B-8546-383694B94B7D}\1.0\0\win32
Value : (Default) = C:\Program Files\Microsoft AntiSpyware\gcASPrivacyLib.dll
Parsed : C:\Program Files\Microsoft AntiSpyware\gcASPrivacyLib.dll

CC - 133
Location: HKEY_CLASSES_ROOT\TypeLib\{86073239-029C-458B-8546-383694B94B7D}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Microsoft AntiSpyware
Parsed : C:\Program Files\Microsoft AntiSpyware

CC - 134
Location: HKEY_CLASSES_ROOT\TypeLib\{88734681-FCB2-11D2-B9D2-00C04FAC114C}\1.0\0\win32
Value : (Default) = C:\PROGRA~1\NORTON~1\NAVUI.dll
Parsed : C:\PROGRA~1\NORTON~1\NAVUI.dll

CC - 135
Location: HKEY_CLASSES_ROOT\TypeLib\{88734681-FCB2-11D2-B9D2-00C04FAC114C}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

CC - 136
Location: HKEY_CLASSES_ROOT\TypeLib\{89A10D64-83BF-41A4-86A3-7AAF1F8F3D1B}\1.0\0\win32
Value : (Default) = C:\Program Files\ISTbar\istbar.dll
Parsed : C:\Program Files\ISTbar\istbar.dll

CC - 137
Location: HKEY_CLASSES_ROOT\TypeLib\{89A10D64-83BF-41A4-86A3-7AAF1F8F3D1B}\1.0\HELPDIR
Value : (Default) = C:\Program Files\ISTbar\
Parsed : C:\Program Files\ISTbar

CC - 138
Location: HKEY_CLASSES_ROOT\TypeLib\{8A934650-3A3D-11D3-A2D4-005004184DF1}\1.0\0\win32
Value : (Default) = C:\PROGRA~1\NORTON~1\AboutPlg.dll
Parsed : C:\PROGRA~1\NORTON~1\AboutPlg.dll

CC - 139
Location: HKEY_CLASSES_ROOT\TypeLib\{8A934650-3A3D-11D3-A2D4-005004184DF1}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

CC - 140
Location: HKEY_CLASSES_ROOT\TypeLib\{903F7FB7-9888-4A4A-B1D5-2A13A7276589}\2.0\0\win32
Value : (Default) = C:\Program Files\Common Files\ScanSoft Shared\ScnWizC.dll
Parsed : C:\Program Files\Common Files\ScanSoft Shared\ScnWizC.dll

CC - 141
Location: HKEY_CLASSES_ROOT\TypeLib\{903F7FB7-9888-4A4A-B1D5-2A13A7276589}\2.0\HELPDIR
Value : (Default) = C:\Program Files\Common Files\ScanSoft Shared\
Parsed : C:\Program Files\Common Files\ScanSoft Shared

CC - 142
Location: HKEY_CLASSES_ROOT\TypeLib\{9275E229-718E-4A2D-8EE0-10C5AA524C22}\1.0\0\win32
Value : (Default) = C:\PROGRA~1\NORTON~1\NAVLnch.dll
Parsed : C:\PROGRA~1\NORTON~1\NAVLnch.dll

CC - 143
Location: HKEY_CLASSES_ROOT\TypeLib\{9275E229-718E-4A2D-8EE0-10C5AA524C22}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

CC - 144
Location: HKEY_CLASSES_ROOT\TypeLib\{941F23D1-BD56-4F90-B99F-134D55D86053}\1.0\0\win32
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
Parsed : C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

CC - 145
Location: HKEY_CLASSES_ROOT\TypeLib\{941F23D1-BD56-4F90-B99F-134D55D86053}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
Parsed : C:\Program Files\Common Files\Symantec Shared

CC - 146
Location: HKEY_CLASSES_ROOT\TypeLib\{9B422879-A1BF-44C4-AC83-B4308A1B2272}\1.0\0\win32
Value : (Default) = C:\PROGRA~1\NORTON~1\IWP\IWPLUCbk.dll
Parsed : C:\PROGRA~1\NORTON~1\IWP\IWPLUCbk.dll

CC - 147
Location: HKEY_CLASSES_ROOT\TypeLib\{9B422879-A1BF-44C4-AC83-B4308A1B2272}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Norton AntiVirus\IWP\
Parsed : C:\Program Files\Norton AntiVirus\IWP

CC - 148
Location: HKEY_CLASSES_ROOT\TypeLib\{9E93C96F-CF0D-43F6-8BA8-B807A3370712}\1.5\0\win32
Value : (Default) = C:\Program Files\iTunes\iTunes.exe
Parsed : C:\Program Files\iTunes\iTunes.exe

CC - 149
Location: HKEY_CLASSES_ROOT\TypeLib\{9E93C96F-CF0D-43F6-8BA8-B807A3370712}\1.5\HELPDIR
Value : (Default) = C:\Program Files\iTunes\
Parsed : C:\Program Files\iTunes

CC - 150
Location: HKEY_CLASSES_ROOT\TypeLib\{9F3B84DC-3631-4BCE-90E9-041A6198A2FA}\1.0\0\win32
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
Parsed : C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

CC - 151
Location: HKEY_CLASSES_ROOT\TypeLib\{9F3B84DC-3631-4BCE-90E9-041A6198A2FA}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
Parsed : C:\Program Files\Common Files\Symantec Shared

CC - 152
Location: HKEY_CLASSES_ROOT\TypeLib\{A67004E0-8362-42F9-B186-88706C346DD9}\1.0\0\win32
Value : (Default) = C:\Program Files\Real\RealOne Player\rpplugins\ierpplug.dll
Parsed : C:\Program Files\Real\RealOne Player\rpplugins\ierpplug.dll

CC - 153
Location: HKEY_CLASSES_ROOT\TypeLib\{A67004E0-8362-42F9-B186-88706C346DD9}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Real\RealOne Player\rpplugins\
Parsed : C:\Program Files\Real\RealOne Player\rpplugins

CC - 154
Location: HKEY_CLASSES_ROOT\TypeLib\{A7336B62-3374-4D2F-8C3F-946D6A9DE725}\1.0\0\win32
Value : (Default) = C:\Program Files\Norton AntiVirus\IWP\HNetCore.dll
Parsed : C:\Program Files\Norton AntiVirus\IWP\HNetCore.dll

CC - 155
Location: HKEY_CLASSES_ROOT\TypeLib\{ABA89334-36F7-4263-987C-941FF0C3E105}\1.0\0\win32
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\ccWebWnd.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\ccWebWnd.dll

CC - 156
Location: HKEY_CLASSES_ROOT\TypeLib\{ABA89334-36F7-4263-987C-941FF0C3E105}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
Parsed : C:\Program Files\Common Files\Symantec Shared

CC - 157
Location: HKEY_CLASSES_ROOT\TypeLib\{B0BD3CBA-3FB8-4A77-B0BE-D3E9E2BB6FBD}\1.0\0\win32
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\SymBbaAx.ocx
Parsed : C:\Program Files\Common Files\Symantec Shared\SymBbaAx.ocx

CC - 158
Location: HKEY_CLASSES_ROOT\TypeLib\{B0BD3CBA-3FB8-4A77-B0BE-D3E9E2BB6FBD}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
Parsed : C:\Program Files\Common Files\Symantec Shared

CC - 159
Location: HKEY_CLASSES_ROOT\TypeLib\{B53DE72C-31E1-49C7-97FD-D22CAA89B27E}\1.0\0\win32
Value : (Default) = C:\Program Files\Microsoft AntiSpyware\gcSoftwareUpdateLib.dll
Parsed : C:\Program Files\Microsoft AntiSpyware\gcSoftwareUpdateLib.dll

CC - 160
Location: HKEY_CLASSES_ROOT\TypeLib\{B53DE72C-31E1-49C7-97FD-D22CAA89B27E}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Microsoft AntiSpyware
Parsed : C:\Program Files\Microsoft AntiSpyware

CC - 161
Location: HKEY_CLASSES_ROOT\TypeLib\{BE2DF74C-BDC0-4411-9641-4B811B82A3AF}\1.0\0\win32
Value : (Default) = C:\PROGRA~1\NORTON~1\NAVComUI.dll
Parsed : C:\PROGRA~1\NORTON~1\NAVComUI.dll

CC - 162
Location: HKEY_CLASSES_ROOT\TypeLib\{BFC07EE1-0EFF-11D4-AE9A-0000E88EB84F}\1.0\0\win32
Value : (Default) = C:\Program Files\CyberLink\PowerDVD\AppBarCom.dll
Parsed : C:\Program Files\CyberLink\PowerDVD\AppBarCom.dll

CC - 163
Location: HKEY_CLASSES_ROOT\TypeLib\{BFC07EE1-0EFF-11D4-AE9A-0000E88EB84F}\1.0\HELPDIR
Value : (Default) = C:\Program Files\CyberLink\PowerDVD\
Parsed : C:\Program Files\CyberLink\PowerDVD

CC - 164
Location: HKEY_CLASSES_ROOT\TypeLib\{BFF4F684-677E-44F4-8C74-1D575C950E10}\1.0\0\win32
Value : (Default) = C:\Program Files\Altnet\Download Manager\adm4.dll
Parsed : C:\Program Files\Altnet\Download Manager\adm4.dll

CC - 165
Location: HKEY_CLASSES_ROOT\TypeLib\{BFF4F684-677E-44F4-8C74-1D575C950E10}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Altnet\Download Manager\
Parsed : C:\Program Files\Altnet\Download Manager

CC - 166
Location: HKEY_CLASSES_ROOT\TypeLib\{C02ABA7B-5269-4737-8DAE-3A453E6C9CD3}\1.0\0\win32
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\LiveReg\LRCTRL.DLL
Parsed : C:\Program Files\Common Files\Symantec Shared\LiveReg\LRCTRL.DLL

CC - 167
Location: HKEY_CLASSES_ROOT\TypeLib\{C02ABA7B-5269-4737-8DAE-3A453E6C9CD3}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\LiveReg\
Parsed : C:\Program Files\Common Files\Symantec Shared\LiveReg

CC - 168
Location: HKEY_CLASSES_ROOT\TypeLib\{C2FC361F-2281-11D2-8E21-10B404C10000}\1.b\0\win32
Value : (Default) = C:\WINDOWS\System32\cNewMenu.dll
Parsed : C:\WINDOWS\System32\cNewMenu.dll

CC - 169
Location: HKEY_CLASSES_ROOT\TypeLib\{C39962BA-5DDC-408D-9367-FEE637EE54D6}\1.0\0\win32
Value : (Default) = C:\Program Files\Microsoft AntiSpyware\gcASThreatAudit.dll
Parsed : C:\Program Files\Microsoft AntiSpyware\gcASThreatAudit.dll

CC - 170
Location: HKEY_CLASSES_ROOT\TypeLib\{C39962BA-5DDC-408D-9367-FEE637EE54D6}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Microsoft AntiSpyware
Parsed : C:\Program Files\Microsoft AntiSpyware

CC - 171
Location: HKEY_CLASSES_ROOT\TypeLib\{C3A4D68F-FD37-4617-9A58-D9BD1EE0D8D1}\1.0\0\win32
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\Security Center\SymSCWb.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Security Center\SymSCWb.dll

CC - 172
Location: HKEY_CLASSES_ROOT\TypeLib\{C3A4D68F-FD37-4617-9A58-D9BD1EE0D8D1}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\Security Center\
Parsed : C:\Program Files\Common Files\Symantec Shared\Security Center

CC - 173
Location: HKEY_CLASSES_ROOT\TypeLib\{C40049E7-5154-40E3-83B5-A94A89A29890}\1.0\0\win32
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll

CC - 174
Location: HKEY_CLASSES_ROOT\TypeLib\{C40049E7-5154-40E3-83B5-A94A89A29890}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
Parsed : C:\Program Files\Common Files\Symantec Shared

CC - 175
Location: HKEY_CLASSES_ROOT\TypeLib\{C62B7AAE-194F-475C-AA49-DE7F12E6FC06}\1.0\0\win32
Value : (Default) = C:\Program Files\Microsoft AntiSpyware\gcTCPObjLib.dll
Parsed : C:\Program Files\Microsoft AntiSpyware\gcTCPObjLib.dll

CC - 176
Location: HKEY_CLASSES_ROOT\TypeLib\{C62B7AAE-194F-475C-AA49-DE7F12E6FC06}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Microsoft AntiSpyware
Parsed : C:\Program Files\Microsoft AntiSpyware

CC - 177
Location: HKEY_CLASSES_ROOT\TypeLib\{C9C05A42-D571-4B3C-8F11-D6D6A81C90EB}\1.0\0\win32
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCEvt.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCEvt.dll

CC - 178
Location: HKEY_CLASSES_ROOT\TypeLib\{C9C05A42-D571-4B3C-8F11-D6D6A81C90EB}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\SPBBC\
Parsed : C:\Program Files\Common Files\Symantec Shared\SPBBC

CC - 179
Location: HKEY_CLASSES_ROOT\TypeLib\{CC257918-F435-4A33-8231-2B8195990CCA}\1.0\0\win32
Value : (Default) = C:\WINDOWS\Downloaded Program Files\YSBactivex.dll
Parsed : C:\WINDOWS\Downloaded Program Files\YSBactivex.dll

CC - 180
Location: HKEY_CLASSES_ROOT\TypeLib\{CE949EEF-0C75-4BCC-BF95-8173D44AEC6B}\1.0\0\win32
Value : (Default) = C:\Program Files\Microsoft AntiSpyware\gcASSoapLib.dll
Parsed : C:\Program Files\Microsoft AntiSpyware\gcASSoapLib.dll

CC - 181
Location: HKEY_CLASSES_ROOT\TypeLib\{CE949EEF-0C75-4BCC-BF95-8173D44AEC6B}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Microsoft AntiSpyware
Parsed : C:\Program Files\Microsoft AntiSpyware

CC - 182
Location: HKEY_CLASSES_ROOT\TypeLib\{CEACE91F-3F71-4A8C-B952-63716B2BC026}\1.0\0\win32
Value : (Default) = C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
Parsed : C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe

CC - 183
Location: HKEY_CLASSES_ROOT\TypeLib\{CEACE91F-3F71-4A8C-B952-63716B2BC026}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Microsoft AntiSpyware
Parsed : C:\Program Files\Microsoft AntiSpyware

CC - 184
Location: HKEY_CLASSES_ROOT\TypeLib\{CF34D2A7-C8C6-4B4E-8752-F63C2BDF1CF0}\1.0\0\win32
Value : (Default) = C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mlfoshim.dll
Parsed : C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mlfoshim.dll

CC - 185
Location: HKEY_CLASSES_ROOT\TypeLib\{CF34D2A7-C8C6-4B4E-8752-F63C2BDF1CF0}\1.0\HELPDIR
Value : (Default) = C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\
Parsed : C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1

CC - 186
Location: HKEY_CLASSES_ROOT\TypeLib\{D0FB5093-C2F0-4280-AAC9-3C35C6980FD8}\1.0\0
Value : (Default) = C:\Program Files\Norton AntiVirus\NAVError.dll
Parsed : C:\Program Files\Norton AntiVirus\NAVError.dll

CC - 187
Location: HKEY_CLASSES_ROOT\TypeLib\{D0FB5093-C2F0-4280-AAC9-3C35C6980FD8}\1.0\0\win32
Value : (Default) = C:\Program Files\Norton AntiVirus\NAVError.dll
Parsed : C:\Program Files\Norton AntiVirus\NAVError.dll

CC - 188
Location: HKEY_CLASSES_ROOT\TypeLib\{D0FB5093-C2F0-4280-AAC9-3C35C6980FD8}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

CC - 189
Location: HKEY_CLASSES_ROOT\TypeLib\{D323F395-AA30-4DF9-A379-2F3F4819AB00}\1.0\0\win32
Value : (Default) = C:\PROGRA~1\NORTON~1\NAVOpts.dll
Parsed : C:\PROGRA~1\NORTON~1\NAVOpts.dll

CC - 190
Location: HKEY_CLASSES_ROOT\TypeLib\{D323F395-AA30-4DF9-A379-2F3F4819AB00}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

CC - 191
Location: HKEY_CLASSES_ROOT\TypeLib\{D935DFEC-4546-4119-94D5-91807C7BB363}\1.0\0\win32
Value : (Default) = C:\Program Files\Norton AntiVirus\NAVCfgWz.dll
Parsed : C:\Program Files\Norton AntiVirus\NAVCfgWz.dll

CC - 192
Location: HKEY_CLASSES_ROOT\TypeLib\{D935DFEC-4546-4119-94D5-91807C7BB363}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

CC - 193
Location: HKEY_CLASSES_ROOT\TypeLib\{DCB43485-19FB-4D6D-BB3D-73C7F48D5F00}\1.0\0\win32
Value : (Default) = C:\Program Files\Messenger\rtcimsp.dll
Parsed : C:\Program Files\Messenger\rtcimsp.dll

CC - 194
Location: HKEY_CLASSES_ROOT\TypeLib\{DE1F7EE0-1851-11D3-939E-0004AC1ABE1F}\1.0\0\win32
Value : (Default) = C:\Program Files\Norton AntiVirus\OfficeAV.dll
Parsed : C:\Program Files\Norton AntiVirus\OfficeAV.dll

CC - 195
Location: HKEY_CLASSES_ROOT\TypeLib\{DE1F7EE0-1851-11D3-939E-0004AC1ABE1F}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

CC - 196
Location: HKEY_CLASSES_ROOT\TypeLib\{EB54C4A8-F9BE-429F-AA4F-F1FA39EA3537}\1.0\0\win32
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\ccProSub.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\ccProSub.dll

CC - 197
Location: HKEY_CLASSES_ROOT\TypeLib\{EB54C4A8-F9BE-429F-AA4F-F1FA39EA3537}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
Parsed : C:\Program Files\Common Files\Symantec Shared

CC - 198
Location: HKEY_CLASSES_ROOT\TypeLib\{EDD3B3E9-3FFD-4836-A6DE-D4A9C473A971}\1.0\0\win32
Value : (Default) = C:\Program Files\Kazaa\Topsearch.dll
Parsed : C:\Program Files\Kazaa\Topsearch.dll

CC - 199
Location: HKEY_CLASSES_ROOT\TypeLib\{EDD3B3E9-3FFD-4836-A6DE-D4A9C473A971}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Kazaa\
Parsed : C:\Program Files\Kazaa

CC - 200
Location: HKEY_CLASSES_ROOT\TypeLib\{EF070A21-6AD8-470A-BA49-4AF45E07B55F}\1.0\0\win32
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\ccLogin.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\ccLogin.dll

CC - 201
Location: HKEY_CLASSES_ROOT\TypeLib\{EF070A21-6AD8-470A-BA49-4AF45E07B55F}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
Parsed : C:\Program Files\Common Files\Symantec Shared

CC - 202
Location: HKEY_CLASSES_ROOT\TypeLib\{F743EA98-42BD-4E2C-A221-3F7B646748C7}\1.0\0\win32
Value : (Default) = C:\Program Files\Norton AntiVirus\navapsvc.exe
Parsed : C:\Program Files\Norton AntiVirus\navapsvc.exe

CC - 203
Location: HKEY_CLASSES_ROOT\TypeLib\{F743EA98-42BD-4E2C-A221-3F7B646748C7}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

CC - 204
Location: HKEY_CLASSES_ROOT\TypeLib\{FF2802B8-8E99-4518-B350-DF088BD26CE7}\1.0\0\win32
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\LiveReg\LSPLUGIN.DLL
Parsed : C:\Program Files\Common Files\Symantec Shared\LiveReg\LSPLUGIN.DLL

CC - 205
Location: HKEY_CLASSES_ROOT\TypeLib\{FF2802B8-8E99-4518-B350-DF088BD26CE7}\1.0\HELPDIR
Value : (Default) = C:\Program Files\Common Files\Symantec Shared\LiveReg\
Parsed : C:\Program Files\Common Files\Symantec Shared\LiveReg

DEEP - 206
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Identities\{7A9B0D75-49A0-4F63-A23C-A0DD4E68E543}\Software\Microsoft\Outlook Express\5.0
Value : Store Root = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Identities\{7A9B0D75-49A0-4F63-A23C-A0DD4E68E543}\Microsoft\Outlook Express\
Parsed : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Identities\{7A9B0D75-49A0-4F63-A23C-A0DD4E68E543}\Microsoft\Outlook Express

DEEP - 207
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Disney\DIGStream
Value : CachePath = C:\Documents and Settings\All Users\Application Data\DIGStream
Parsed : C:\Documents and Settings\All Users\Application Data\DIGStream

DEEP - 208
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\GIANTCompany\AntiSpyware\Alerts\DE17EE69-5155-42EE-A618-968589
Value : FilePath = C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hnhufu.exe
Parsed : C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hnhufu.exe

DEEP - 209
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Macromedia\Shockwave 10\location\coreplayerxtras
Value : (Default) = C:\WINDOWS\system32\Macromed\Shockwave 10\xtras\
Parsed : C:\WINDOWS\system32\Macromed\Shockwave 10\xtras

DEEP - 210
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Internet Explorer\Default HTML Editor\shell\edit\command
Value : (Default) = C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE
Parsed : C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE

DEEP - 211
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\MediaPlayer\Setup\CreatedLinks
Value : Shortcut0 = C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk
Parsed : C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk

DEEP - 212
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\MediaPlayer\Setup\CreatedLinks
Value : Shortcut1 = C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
Parsed : C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk

DEEP - 213
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012006032720060403
Value : CachePath = C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006032720060403\
Parsed : C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006032720060403

DEEP - 214
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012006040320060410
Value : CachePath = C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006040320060410\
Parsed : C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006040320060410

DEEP - 215
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012006041020060417
Value : CachePath = C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006041020060417\
Parsed : C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006041020060417

DEEP - 216
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012006041720060418
Value : CachePath = C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006041720060418\
Parsed : C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006041720060418

DEEP - 217
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Run
Value : AVG7_Run = C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE
Parsed : C:\PROGRA~1\Grisoft\AVG7\avgw.exe

DEEP - 218
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
Value : C:\Program Files\BroadJump\Client Foundation\CFD.exe = C:\Program Files\BroadJump\Client Foundation\CFD.exe
Parsed : C:\Program Files\BroadJump\Client Foundation\CFD.exe

DEEP - 219
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
Value : C:\Program Files\Microsoft AntiSpyware\gcasServ.exe = C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
Parsed : C:\Program Files\Microsoft AntiSpyware\gcasServ.exe

DEEP - 220
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
Value : C:\Program Files\ScanSoft\OmniPageSE\opware32.exe = C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
Parsed : C:\Program Files\ScanSoft\OmniPageSE\opware32.exe

DEEP - 221
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
Value : C:\Program Files\MSN Toolbar Suite\DS\02.00.0001.1203\en-us\bin\msnlAdmin.exe = C:\Program Files\MSN Toolbar Suite\DS\02.00.0001.1203\en-us\bin\msnlAdmin.exe
Parsed : C:\Program Files\MSN Toolbar Suite\DS\02.00.0001.1203\en-us\bin\msnlAdmin.exe

DEEP - 222
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
Value : C:\Program Files\Microsoft AntiSpyware\gcasServAlert.exe = C:\Program Files\Microsoft AntiSpyware\gcasServAlert.exe
Parsed : C:\Program Files\Microsoft AntiSpyware\gcasServAlert.exe

DEEP - 223
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
Value : C:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareMain.exe = C:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareMain.exe
Parsed : C:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareMain.exe

DEEP - 224
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
Value : C:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareUpdater.exe = C:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareUpdater.exe
Parsed : C:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareUpdater.exe

DEEP - 225
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
Value : C:\Program Files\Microsoft AntiSpyware\gcasSWUpdater.exe = C:\Program Files\Microsoft AntiSpyware\gcasSWUpdater.exe
Parsed : C:\Program Files\Microsoft AntiSpyware\gcasSWUpdater.exe

DEEP - 226
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
Value : C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe = C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe
Parsed : C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe

DEEP - 227
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
Value : C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe = C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe
Parsed : C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe

DEEP - 228
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
Value : C:\Program Files\Common Files\Symantec Shared\ccApp.exe = C:\Program Files\Common Files\Symantec Shared\ccApp.exe
Parsed : C:\Program Files\Common Files\Symantec Shared\ccApp.exe

DEEP - 229
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
Value : C:\PROGRA~1\SYMNET~1\SNDMon.exe = C:\PROGRA~1\SYMNET~1\SNDMon.exe
Parsed : C:\PROGRA~1\SYMNET~1\SNDMon.exe

DEEP - 230
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
Value : C:\PROGRA~1\Grisoft\AVG7\avgcc.exe = C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
Parsed : C:\PROGRA~1\Grisoft\AVG7\avgcc.exe

DEEP - 231
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
Value : C:\PROGRA~1\Grisoft\AVG7\avgw.exe = C:\PROGRA~1\Grisoft\AVG7\avgw.exe
Parsed : C:\PROGRA~1\Grisoft\AVG7\avgw.exe

DEEP - 232
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
Value : C:\PROGRA~1\Grisoft\AVG7\avgwb.dat = C:\PROGRA~1\Grisoft\AVG7\avgwb.dat
Parsed : C:\PROGRA~1\Grisoft\AVG7\avgwb.dat

DEEP - 233
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
Value : C:\Program Files\Symantec\LiveUpdate\LUALL.EXE = C:\Program Files\Symantec\LiveUpdate\LUALL.EXE
Parsed : C:\Program Files\Symantec\LiveUpdate\LUALL.EXE

DEEP - 234
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
Value : C:\WINDOWS\system32\slk8x2peu.exe = C:\WINDOWS\system32\slk8x2peu.exe
Parsed : C:\WINDOWS\system32\slk8x2peu.exe

DEEP - 235
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
Value : C:\WINDOWS\system32\nwinmrag.exe = C:\WINDOWS\system32\nwinmrag.exe
Parsed : C:\WINDOWS\system32\nwinmrag.exe

DEEP - 236
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
Value : C:\Program Files\Common Files\Symantec Shared\LiveReg\VCSetup.exe = C:\Program Files\Common Files\Symantec Shared\LiveReg\VCSetup.exe
Parsed : C:\Program Files\Common Files\Symantec Shared\LiveReg\VCSetup.exe

DEEP - 237
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
Value : C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe = C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
Parsed : C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

DEEP - 238
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
Value : C:\WINDOWS\Microsoft.NET\Framework\NETFXSBS10.exe = C:\WINDOWS\Microsoft.NET\Framework\NETFXSBS10.exe
Parsed : C:\WINDOWS\Microsoft.NET\Framework\NETFXSBS10.exe

DEEP - 239
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
Value : C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ConfigWizards.exe = C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ConfigWizards.exe
Parsed : C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ConfigWizards.exe

DEEP - 240
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
Value : C:\WINDOWS\system32\lwinrrag.exe = C:\WINDOWS\system32\lwinrrag.exe
Parsed : C:\WINDOWS\system32\lwinrrag.exe

DEEP - 241
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000001
Value : path = C:\Program Files\Zone Labs\ZoneAlarm\security.zap
Parsed : C:\Program Files\Zone Labs\ZoneAlarm\security.zap

DEEP - 242
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000002
Value : path = C:\Program Files\Zone Labs\ZoneAlarm\firewall.zap
Parsed : C:\Program Files\Zone Labs\ZoneAlarm\firewall.zap

DEEP - 243
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000004
Value : path = C:\Program Files\Zone Labs\ZoneAlarm\email.zap
Parsed : C:\Program Files\Zone Labs\ZoneAlarm\email.zap

DEEP - 244
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000008
Value : path = C:\Program Files\Zone Labs\ZoneAlarm\scan.zap
Parsed : C:\Program Files\Zone Labs\ZoneAlarm\scan.zap

DEEP - 245
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000010
Value : path = C:\Program Files\Zone Labs\ZoneAlarm\programs.zap
Parsed : C:\Program Files\Zone Labs\ZoneAlarm\programs.zap

DEEP - 246
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000020
Value : path = C:\Program Files\Zone Labs\ZoneAlarm\imsecure.zap
Parsed : C:\Program Files\Zone Labs\ZoneAlarm\imsecure.zap

DEEP - 247
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000040
Value : path = C:\Program Files\Zone Labs\ZoneAlarm\idlock.zap
Parsed : C:\Program Files\Zone Labs\ZoneAlarm\idlock.zap

DEEP - 248
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000080
Value : path = C:\Program Files\Zone Labs\ZoneAlarm\privacy.zap
Parsed : C:\Program Files\Zone Labs\ZoneAlarm\privacy.zap

DEEP - 249
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000100
Value : path = C:\Program Files\Zone Labs\ZoneAlarm\filter.zap
Parsed : C:\Program Files\Zone Labs\ZoneAlarm\filter.zap

DEEP - 250
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000400
Value : path = C:\Program Files\Zone Labs\ZoneAlarm\alert.zap
Parsed : C:\Program Files\Zone Labs\ZoneAlarm\alert.zap

DEEP - 251
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Microsoft\Internet Explorer\Default HTML Editor\shell\edit\command
Value : (Default) = C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE
Parsed : C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE

DEEP - 252
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Microsoft\MediaPlayer\Setup\CreatedLinks
Value : Shortcut0 = C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk
Parsed : C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk

DEEP - 253
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Microsoft\MediaPlayer\Setup\CreatedLinks
Value : Shortcut1 = C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
Parsed : C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk

DEEP - 254
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012006040320060410
Value : CachePath = C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006040320060410\
Parsed : C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006040320060410

DEEP - 255
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Microsoft\Windows\CurrentVersion\Run
Value : AVG7_Run = C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE
Parsed : C:\PROGRA~1\Grisoft\AVG7\avgw.exe

DEEP - 256
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Microsoft\Windows\ShellNoRoam\MUICache
Value : C:\WINDOWS\system32\slk8x2peu.exe = C:\WINDOWS\system32\slk8x2peu.exe
Parsed : C:\WINDOWS\system32\slk8x2peu.exe

DEEP - 257
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Microsoft\Windows\ShellNoRoam\MUICache
Value : C:\WINDOWS\system32\lwinrrag.exe = C:\WINDOWS\system32\lwinrrag.exe
Parsed : C:\WINDOWS\system32\lwinrrag.exe

DEEP - 258
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000001
Value : path = C:\Program Files\Zone Labs\ZoneAlarm\security.zap
Parsed : C:\Program Files\Zone Labs\ZoneAlarm\security.zap

DEEP - 259
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000002
Value : path = C:\Program Files\Zone Labs\ZoneAlarm\firewall.zap
Parsed : C:\Program Files\Zone Labs\ZoneAlarm\firewall.zap

DEEP - 260
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000004
Value : path = C:\Program Files\Zone Labs\ZoneAlarm\email.zap
Parsed : C:\Program Files\Zone Labs\ZoneAlarm\email.zap

DEEP - 261
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000008
Value : path = C:\Program Files\Zone Labs\ZoneAlarm\scan.zap
Parsed : C:\Program Files\Zone Labs\ZoneAlarm\scan.zap

DEEP - 262
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000010
Value : path = C:\Program Files\Zone Labs\ZoneAlarm\programs.zap
Parsed : C:\Program Files\Zone Labs\ZoneAlarm\programs.zap

DEEP - 263
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000020
Value : path = C:\Program Files\Zone Labs\ZoneAlarm\imsecure.zap
Parsed : C:\Program Files\Zone Labs\ZoneAlarm\imsecure.zap

DEEP - 264
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000040
Value : path = C:\Program Files\Zone Labs\ZoneAlarm\idlock.zap
Parsed : C:\Program Files\Zone Labs\ZoneAlarm\idlock.zap

DEEP - 265
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000080
Value : path = C:\Program Files\Zone Labs\ZoneAlarm\privacy.zap
Parsed : C:\Program Files\Zone Labs\ZoneAlarm\privacy.zap

DEEP - 266
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000100
Value : path = C:\Program Files\Zone Labs\ZoneAlarm\filter.zap
Parsed : C:\Program Files\Zone Labs\ZoneAlarm\filter.zap

DEEP - 267
Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000400
Value : path = C:\Program Files\Zone Labs\ZoneAlarm\alert.zap
Parsed : C:\Program Files\Zone Labs\ZoneAlarm\alert.zap

DEEP - 268
Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\McAfeePrivacyService\McAfeePrivacyService_Parental\.Current
Value : (Default) = C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV
Parsed : C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV

DEEP - 269
Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\McAfeePrivacyService\McAfeePrivacyService_Parental\.Default
Value : (Default) = C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV
Parsed : C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV

DEEP - 270
Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\McAfeePrivacyService\McAfeePrivacyService_Privacy\.Current
Value : (Default) = C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV
Parsed : C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV

DEEP - 271
Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\McAfeePrivacyService\McAfeePrivacyService_Privacy\.Default
Value : (Default) = C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV
Parsed : C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV

DEEP - 272
Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\McAfeePrivacyService\McAfeePrivacyService_Security\.Current
Value : (Default) = C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV
Parsed : C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV

DEEP - 273
Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\McAfeePrivacyService\McAfeePrivacyService_Security\.Default
Value : (Default) = C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV
Parsed : C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV

DEEP - 274
Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\MSNMSGR\MSNMSGR_ContactOnline\.Current
Value : (Default) = C:\Program Files\MSN Messenger\online.wav
Parsed : C:\Program Files\MSN Messenger\online.wav

DEEP - 275
Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\MSNMSGR\MSNMSGR_NewAlert\.Current
Value : (Default) = C:\Program Files\MSN Messenger\newalert.wav
Parsed : C:\Program Files\MSN Messenger\newalert.wav

DEEP - 276
Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\MSNMSGR\MSNMSGR_NewMail\.Current
Value : (Default) = C:\Program Files\MSN Messenger\newemail.wav
Parsed : C:\Program Files\MSN Messenger\newemail.wav

DEEP - 277
Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\MSNMSGR\MSNMSGR_NewMessage\.Current
Value : (Default) = C:\Program Files\MSN Messenger\type.wav
Parsed : C:\Program Files\MSN Messenger\type.wav

DEEP - 278
Location: HKEY_CURRENT_USER\EUDC\1252
Value : SystemDefaultEUDCFont = C:\WINDOWS\FONTS\EUDC.TTE
Parsed : C:\WINDOWS\FONTS\EUDC.TTE

DEEP - 279
Location: HKEY_CURRENT_USER\Software\Ahead\Nero - Burning Rom\Database
Value : UserDbPath = C:\Program Files\Ahead\nero\UsrDb
Parsed : C:\Program Files\Ahead\nero\UsrDb

DEEP - 280
Location: HKEY_CURRENT_USER\Software\Canon\ScanGear\7.0\Devices\CNQL30
Value : TempFolder = C:\Documents and Settings\keno cannady\Application Data\Canon
Parsed : C:\Documents and Settings\keno cannady\Application Data\Canon

DEEP - 281
Location: HKEY_CURRENT_USER\Software\Cyberlink\PowerDVD
Value : InstallDir = C:\Program Files\CyberLink\PowerDVD
Parsed : C:\Program Files\CyberLink\PowerDVD

DEEP - 282
Location: HKEY_CURRENT_USER\Software\Cyberlink\PowerDVD
Value : InstallPath = C:\Program Files\CyberLink\PowerDVD
Parsed : C:\Program Files\CyberLink\PowerDVD

DEEP - 283
Location: HKEY_CURRENT_USER\Software\Cyberlink\PowerDVD
Value : UISkinName = C:\Program Files\CyberLink\PowerDVD\UI_Skin.DLL
Parsed : C:\Program Files\CyberLink\PowerDVD\UI_Skin.DLL

DEEP - 284
Location: HKEY_CURRENT_USER\Software\DVD Shrink\DVD Shrink 3.2\Preferences
Value : TargetFolder = C:\INTERPRETER
Parsed : C:\INTERPRETER

DEEP - 285
Location: HKEY_CURRENT_USER\Software\FIRAXIS\Civ3Edit\Recent File List
Value : File1 = C:\Documents and Settings\keno cannady\Shared\PC Games - Civilization 3 - Working Full Version\Untitled.bic
Parsed : C:\Documents and Settings\keno cannady\Shared\PC Games - Civilization 3

DEEP - 286
Location: HKEY_CURRENT_USER\Software\FIRAXIS\Civ3Edit\Recent File List
Value : File2 = C:\Documents and Settings\keno cannady\Shared\PC Games - Civilization 3 - Working Full Version\civ3mod.bic
Parsed : C:\Documents and Settings\keno cannady\Shared\PC Games - Civilization 3

DEEP - 287
Location: HKEY_CURRENT_USER\Software\GIANTCompany\AntiSpyware\Alerts\719B6D7D-2163-47F8-9C9F-5A9888
Value : FilePath = C:\Documents and Settings\keno cannady\Start Menu\Programs\Startup\LimeWire On Startup.lnk
Parsed : C:\Documents and Settings\keno cannady\Start Menu\Programs\Startup\LimeWire On Startup.lnk

DEEP - 288
Location: HKEY_CURRENT_USER\Software\GIANTCompany\AntiSpyware\Alerts\9F3749B3-B089-4315-BF97-84F86B
Value : FilePath = c:\program files\istsvc\istsvc.exe
Parsed : c:\program files\istsvc\istsvc.exe

DEEP - 289
Location: HKEY_CURRENT_USER\Software\GIANTCompany\AntiSpyware\Alerts\9F3749B3-B089-4315-BF97-84F86B
Value : RegistryValue = C:\Program Files\ISTsvc\istsvc.exe
Parsed : C:\Program Files\ISTsvc\istsvc.exe

DEEP - 290
Location: HKEY_CURRENT_USER\Software\GIANTCompany\AntiSpyware\Alerts\CFBF341D-F22A-4775-AB40-7C2844
Value : DisplayDetails = Microsoft AntiSpyware has allowed the Internet Explorer Shell Browser MSN Toolbar Suite (msntb.dll) to be installed.||Name: MSN Toolbar Suite|File path: c:\program files\msn toolbar suite\tb\02.00.0001.1203\en-us\msntb.dll
Parsed : c:\program files\msn toolbar suite\tb\02.00.0001.1203\en-us\msntb.dll

DEEP - 291
Location: HKEY_CURRENT_USER\Software\GIANTCompany\AntiSpyware\Alerts\E6CC22CA-C441-480A-AD2B-49BA13
Value : FilePath = c:\windows\farmmext.exe
Parsed : c:\windows\farmmext.exe

DEEP - 292
Location: HKEY_CURRENT_USER\Software\GIANTCompany\AntiSpyware\Alerts\E6CC22CA-C441-480A-AD2B-49BA13
Value : RegistryValue = C:\WINDOWS\farmmext.exe
Parsed : C:\WINDOWS\farmmext.exe

DEEP - 293
Location: HKEY_CURRENT_USER\Software\InterVideo\DVD5R
Value : CHANNEL_FILE = C:\Documents and Settings\All Users\Application Data\InterVideo\Recorder\Recorder.chan
Parsed : C:\Documents and Settings\All Users\Application Data\InterVideo\Recorder\Recorder.chan

DEEP - 294
Location: HKEY_CURRENT_USER\Software\Macromedia\FlashPlayerUpdate
Value : Path = C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\FlashPlayerUpdate.exe
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\FlashPlayerUpdate.exe

DEEP - 295
Location: HKEY_CURRENT_USER\Software\Macromedia\Shockwave 10\location\coreplayerxtras
Value : (Default) = C:\WINDOWS\system32\Macromed\Shockwave 10\xtras\
Parsed : C:\WINDOWS\system32\Macromed\Shockwave 10\xtras

DEEP - 296
Location: HKEY_CURRENT_USER\Software\Macromedia\Shockwave 10\preffileloc
Value : (Default) = C:\Documents and Settings\keno cannady\Application Data\Macromedia\Shockwave Player\Prefs\7CPN7Q9D\
Parsed : C:\Documents and Settings\keno cannady\Application Data\Macromedia\Shockwave Player\Prefs\7CPN7Q9D

DEEP - 297
Location: HKEY_CURRENT_USER\Software\McAfee.com\SpamKiller\Settings
Value : Install Dir = C:\PROGRA~1\mcafee\SPAMKI~1\
Parsed : C:\PROGRA~1\mcafee\SPAMKI~1

DEEP - 298
Location: HKEY_CURRENT_USER\Software\Microsoft\Keyboard\Native Media Players\QuickTime Player
Value : ExePath = C:\Program Files\Quick
Parsed : C:\Program Files\Quick

DEEP - 299
Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
Value : LastNotFoundDir = C:\Documents and Settings\keno cannady\My Documents\My Videos\RCT3\
Parsed : C:\Documents and Settings\keno cannady\My Documents\My Videos\RCT3

DEEP - 300
Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Setup\CreatedLinks
Value : Shortcut0 = C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk
Parsed : C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk

DEEP - 301
Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Setup\CreatedLinks
Value : Shortcut1 = C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
Parsed : C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk

DEEP - 302
Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Setup\FileMoveCache\Source
Value : 0 = C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\setb0.tmp
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\setb0.tmp

DEEP - 303
Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Setup\FileMoveCache\Source
Value : 1 = C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\setb1.tmp
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\setb1.tmp

DEEP - 304
Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Setup\FileMoveCache\Source
Value : 2 = C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\setb2.tmp
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\setb2.tmp

DEEP - 305
Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Setup\FileMoveCache\Source
Value : 3 = C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\setb3.tmp
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\setb3.tmp

DEEP - 306
Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Databases\RSApp
Value : FileName = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Properties\RSApp.edb
Parsed : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Properties\RSApp.edb

DEEP - 307
Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Databases\RSApp
Value : LogPath = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Properties\
Parsed : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Properties

DEEP - 308
Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Gather\RSApp\MyIndex
Value : LogDirectory = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex
Parsed : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex

DEEP - 309
Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Gather\RSApp\MyIndex
Value : StreamLogsDirectory = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\GatherLogs
Parsed : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\GatherLogs

DEEP - 310
Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Gather\RSApp\MyIndex
Value : LogName = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex\MyIndex.Ntfy11.gthr
Parsed : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex\MyIndex.Ntfy11.gthr

DEEP - 311
Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Gather\RSApp\MyIndex
Value : HistoryHashMapFile = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex\MyIndex.Hash.gthr
Parsed : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex\MyIndex.Hash.gthr

DEEP - 312
Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Gather\RSApp\MyIndex
Value : DocIdMapFile = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex\MyIndex.Idm.gthr
Parsed : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex\MyIndex.Idm.gthr

DEEP - 313
Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Gathering Manager
Value : TempPath = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Temp\rssgthrsvc
Parsed : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Temp\rssgthrsvc

DEEP - 314
Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Gathering Manager\Applications\RSApp\Projects\MyIndex
Value : WorkingDirectory = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex
Parsed : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex

DEEP - 315
Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Indexer\RSApp\MyIndex
Value : ProjectPath = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex
Parsed : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex

DEEP - 316
Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache
Value : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\is-M7D7L.tmp\is-4A07N.tmp = C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\is-M7D7L.tmp\is-4A07N.tmp
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\is-M7D7L.tmp\is-4A07N.tmp

DEEP - 317
Location: HKEY_CURRENT_USER\Software\Microsoft\Works Suite
Value : C:\Program Files\Microsoft Money\System\msmoney.exe = C:\Program Files\Microsoft Money\System\msmoney.exe
Parsed : C:\Program Files\Microsoft Money\System\msmoney.exe

DEEP - 318
Location: HKEY_CURRENT_USER\Software\ScanSoft\OmniPagePro11.0\Scanner\ScanSoft API\PlugIn\1.0\Components\5
Value : InProcSrv = C:\Program Files\ScanSoft\OmniPageSE\XSCAN32.psp
Parsed : C:\Program Files\ScanSoft\OmniPageSE\XSCAN32.psp

DEEP - 319
Location: HKEY_CURRENT_USER\Software\Take2 Interactive\Mall Tycoon
Value : location = C:\Program Files\Take2 Interactive\Mall Tycoon
Parsed : C:\Program Files\Take2 Interactive\Mall Tycoon

DEEP - 320
Location: HKEY_CURRENT_USER\Software\Take2 Interactive\Mall Tycoon
Value : cdrom = C:\Documents and Settings\keno cannady\Shared\PC GAMES - Mall Tycoon\
Parsed : C:\Documents and Settings\keno cannady\Shared\PC GAMES

DEEP - 321
Location: HKEY_CURRENT_USER\Software\Toolbar Genie Online\My Toolbar\Historyfiles
Value : C:\PROGRA~1\KoolBar\toolbar.xml = C:\PROGRA~1\KoolBar\toolbar.xml
Parsed : C:\PROGRA~1\KoolBar\toolbar.xml

DEEP - 322
Location: HKEY_CURRENT_USER\Software\Valve\Half-Life\Player Profiles\Player
Value : Archive = C:\Documents and Settings\keno cannady\Shared\Games - Half Life(2)\ProfileData\Player.dat
Parsed : C:\Documents and Settings\keno cannady\Shared\Games

DEEP - 323
Location: HKEY_CURRENT_USER\Software\VFPlugin
Value : DVD2AVI = C:\Program Files\GordianKnot\DVD2AVI.vfp
Parsed : C:\Program Files\GordianKnot\DVD2AVI.vfp

DEEP - 324
Location: HKEY_CURRENT_USER\Software\Yahoo\YServer
Value : HomeDir = C:\PROGRA~1\Yahoo!\MESSEN~1\data
Parsed : C:\PROGRA~1\Yahoo!\MESSEN~1\data

DEEP - 325
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Ahead\shared
Value : OutputPath = C:\Program Files\Ahead\MyMusic
Parsed : C:\Program Files\Ahead\MyMusic

DEEP - 326
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Clients\JavaVM\MSJavaVM\InstallInfo
Value : VerifyFile = C:\WINDOWS\system32\msjava.dll
Parsed : C:\WINDOWS\system32\msjava.dll

DEEP - 327
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Clients\News\Microsoft Outlook
Value : DLLPath = C:\Program Files\Outlook ExpressMSIMNUI.DLL
Parsed : C:\Program Files\Outlook ExpressMSIMNUI.DLL

DEEP - 328
Location: HKEY_LOCAL_MACHINE\SOFTWARE\CyberLink\PowerDVD
Value : InstallDir = C:\Program Files\CyberLink\PowerDVD
Parsed : C:\Program Files\CyberLink\PowerDVD

DEEP - 329
Location: HKEY_LOCAL_MACHINE\SOFTWARE\CyberLink\PowerDVD
Value : InstallPath = C:\Program Files\CyberLink\PowerDVD
Parsed : C:\Program Files\CyberLink\PowerDVD

DEEP - 330
Location: HKEY_LOCAL_MACHINE\SOFTWARE\EA GAMES\Harry Potter
Value : Install Dir = C:\Documents and Settings\keno cannady\Shared\Games - Harry Potter Full PC Game
Parsed : C:\Documents and Settings\keno cannady\Shared\Games

DEEP - 331
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Fish Technology Group\RollerCoaster Tycoon Setup
Value : Path = C:\Program Files\Rollercoaster Tycoon
Parsed : C:\Program Files\Rollercoaster Tycoon

DEEP - 332
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Fish Technology Group\RollerCoaster Tycoon Setup
Value : SetupPath = C:\Program Files\Rollercoaster Tycoon\
Parsed : C:\Program Files\Rollercoaster Tycoon

DEEP - 333
Location: HKEY_LOCAL_MACHINE\SOFTWARE\GIANTCompany\AntiSpyware\CleanerExe\DelFiles
Value : c:\windows\system32\sfndcmsg.dll = c:\windows\system32\sfndcmsg.dll
Parsed : c:\windows\system32\sfndcmsg.dll

DEEP - 334
Location: HKEY_LOCAL_MACHINE\SOFTWARE\GordianKnot
Value : InstallDir = C:\Program Files\GordianKnot
Parsed : C:\Program Files\GordianKnot

DEEP - 335
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Grisoft\Clients\{3C9EFEC2-8D1A-11D5-989F-0000E87B4FB1}
Value : Config = C:\PROGRA~1\Grisoft\AVG7\avgemsui.dll
Parsed : C:\PROGRA~1\Grisoft\AVG7\avgemsui.dll

DEEP - 336
Location: HKEY_LOCAL_MACHINE\SOFTWARE\HipSoft\Trivia Machine
Value : InstallPath = C:\Program Files\Yahoo! Games\Trivia Machine
Parsed : C:\Program Files\Yahoo! Games\Trivia Machine

DEEP - 337
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Infogrames Interactive\Civilization III
Value : Install_Path = C:\Documents and Settings\keno cannady\Shared\PC Games - Civilization 3 - Working Full Version
Parsed : C:\Documents and Settings\keno cannady\Shared\PC Games - Civilization 3

DEEP - 338
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Infogrames Interactive\Civilization III
Value : Uninstall_Path = C:\Program Files\InstallShield Installation Information\{0AD84416-63A4-4CF3-BDDF-8FA866711FB0}\Setup.exe
Parsed : C:\Program Files\InstallShield Installation Information\{0AD84416-63A4-4CF3-BDDF-8FA866711FB0}\Setup.exe

DEEP - 339
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Infogrames Interactive\Civilization III
Value : CD_Path = C:\Documents and Settings\keno cannady\Shared\PC Games - Civilization 3 - Working Full Version
Parsed : C:\Documents and Settings\keno cannady\Shared\PC Games - Civilization 3

DEEP - 340
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Infogrames Interactive\Monopoly Tycoon
Value : PATH = C:\Documents and Settings\keno cannady\Shared\Game - Monopoly Tycoon (1)\Monopoly Tycoon
Parsed : C:\Documents and Settings\keno cannady\Shared\Game

DEEP - 341
Location: HKEY_LOCAL_MACHINE\SOFTWARE\iWin\FamilyFeud
Value : InstallDir = C:\Program Files\iWin.com Games\Family Feud
Parsed : C:\Program Files\iWin.com Games\Family Feud

DEEP - 342
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\Shockwave 10\location\coreplayerxtras
Value : (Default) = C:\WINDOWS\system32\Macromed\Shockwave 10\xtras\
Parsed : C:\WINDOWS\system32\Macromed\Shockwave 10\xtras

DEEP - 343
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Disabled
Value : BrowserUpdateSched = C:\WINDOWS\system32\lwinrrag.exe CORN001
Parsed : C:\WINDOWS\system32\lwinrrag.exe

DEEP - 344
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Disabled
Value : q8lg = "C:\WINDOWS\system32\slk8x2peu.exe"
Parsed : C:\WINDOWS\system32\slk8x2peu.exe

DEEP - 345
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
Value : MASLog047 = Exclude C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\unicows_cab\unicows.inf from installation
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\unicows_cab\unicows.inf

DEEP - 346
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
Value : MASLog048 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\psapi_cab\psapi.inf$$ Result: 0
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\psapi_cab\psapi.inf

DEEP - 347
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
Value : MASLog052 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\mas_cab\mas.inf$$ Result: 0
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\mas_cab\mas.inf

DEEP - 348
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
Value : MASLog053 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\mascfg_cab\mascfg.inf$$ Result: 0
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\mascfg_cab\mascfg.inf

DEEP - 349
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
Value : MASLog054 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masqlt_cab\masqlt.inf$$ Result: 0
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masqlt_cab\masqlt.inf

DEEP - 350
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
Value : MASLog055 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\vmap_cab\vmap.inf$$ Result: 0
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\vmap_cab\vmap.inf

DEEP - 351
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
Value : MASLog056 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\maseng_cab\maseng.inf$$ Result: 0
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\maseng_cab\maseng.inf

DEEP - 352
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
Value : MASLog057 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masvscor_cab\masvscor.inf$$ Result: 0
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masvscor_cab\masvscor.inf

DEEP - 353
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
Value : MASLog058 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masupd_cab\masupd.inf$$ Result: 0
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masupd_cab\masupd.inf

DEEP - 354
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
Value : MASLog059 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masdat_cab\masdat.inf$$ Result: 0
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masdat_cab\masdat.inf

DEEP - 355
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
Value : MASLog060 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\regwiz_cab\regwiz.inf$$ Result: 0
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\regwiz_cab\regwiz.inf

DEEP - 356
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
Value : MASLog061 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masreg_cab\masreg.inf$$ Result: 0
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masreg_cab\masreg.inf

DEEP - 357
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
Value : MASLog099 = FinalizeMAsInstall: Removing Extract Folder: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp$$Result: 0
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp$$Result

DEEP - 358
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
Value : MASLog101 = FinalizeMAsInstall: Removing Extract Folder: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp$$Result: 2
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp$$Result

DEEP - 359
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\QuickClean\Installer
Value : QclDownloadPath = C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAC8.tmp
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAC8.tmp

DEEP - 360
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\QuickClean\Installer
Value : QclLog002 = FinalizeQCLInstall: Removing$$Extract Folder: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA7.tmp$$Result: 0
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA7.tmp$$Result

DEEP - 361
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Agent\Update\ResultLog
Value : Log#022 = 4/24/2006 2:50:34 PM - CHandler::CreateHandlersWithPriority: Adding senddata handler of c:\program files\mcafee.com\agent\mcscentr.adf to the list
Parsed : c:\program files\mcafee.com\agent\mcscentr.adf to the list

DEEP - 362
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Agent\Update\ResultLog
Value : Log#023 = 4/24/2006 2:50:34 PM - CHandler::CreateHandlersWithPriority: NOT Adding update handler of c:\program files\mcafee.com\agent\mcscentr.adf to the list because the desired priority does not match
Parsed : c:\program files\mcafee.com\agent\mcscentr.adf to the list because the desired priority does not match

DEEP - 363
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Agent\Update\ResultLog
Value : Log#025 = 4/24/2006 2:50:37 PM - Priority: ASYNCHRONOUS; HandlerName: SendData (c:\program files\mcafee.com\agent\app\mas.adf); ResultCode: 8 (DATA_SENT)
Parsed : c:\program files\mcafee.com\agent\app\mas.adf)

DEEP - 364
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Agent\Update\ResultLog
Value : Log#026 = 4/24/2006 2:50:39 PM - Priority: ASYNCHRONOUS; HandlerName: SendData (c:\program files\mcafee.com\agent\app\vso.adf); ResultCode: 8 (DATA_SENT)
Parsed : c:\program files\mcafee.com\agent\app\vso.adf)

DEEP - 365
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Agent\Update\ResultLog
Value : Log#027 = 4/24/2006 2:50:40 PM - Priority: ASYNCHRONOUS; HandlerName: SendData (c:\program files\mcafee.com\agent\mcscentr.adf); ResultCode: 8 (DATA_SENT)
Parsed : c:\program files\mcafee.com\agent\mcscentr.adf)

DEEP - 366
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Agent\Update\ResultLog
Value : Log#059 = 4/24/2006 10:45:05 AM - CHandler::CreateHandlersWithPriority: NOT Adding update handler of c:\program files\mcafee.com\agent\mcscentr.adf to the list because the desired priority does not match
Parsed : c:\program files\mcafee.com\agent\mcscentr.adf to the list because the desired priority does not match

DEEP - 367
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Agent\Update\ResultLog
Value : Log#061 = 4/24/2006 10:45:09 AM - Priority: ASYNCHRONOUS; HandlerName: SendData (c:\program files\mcafee.com\agent\app\mas.adf); ResultCode: 8 (DATA_SENT)
Parsed : c:\program files\mcafee.com\agent\app\mas.adf)

DEEP - 368
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Agent\Update\ResultLog
Value : Log#062 = 4/24/2006 10:45:12 AM - Priority: ASYNCHRONOUS; HandlerName: SendData (c:\program files\mcafee.com\agent\app\vso.adf); ResultCode: 8 (DATA_SENT)
Parsed : c:\program files\mcafee.com\agent\app\vso.adf)

DEEP - 369
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Agent\Update\ResultLog
Value : Log#063 = 4/24/2006 10:45:14 AM - Priority: ASYNCHRONOUS; HandlerName: SendData (c:\program files\mcafee.com\agent\mcscentr.adf); ResultCode: 8 (DATA_SENT)
Parsed : c:\program files\mcafee.com\agent\mcscentr.adf)

DEEP - 370
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\GDLog\UPD_mas
Value : Log#115 = 3/21/2006 10:06:21 PM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:mas_24, LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\UPD_mas\MasVer.Ini
Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\UPD_mas\MasVer.Ini

DEEP - 371
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\GDLog\UPD_mas
Value : Log#123 = 3/21/2006 10:06:23 PM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:mys_1, LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\UPD_mas\AgentVer.ini
Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\UPD_mas\AgentVer.ini

DEEP - 372
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\GDLog\UPD_mas
Value : Log#135 = 3/21/2006 10:06:27 PM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:mas_0, LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\UPD_mas\mas\gdeltapup.ini
Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\UPD_mas\mas\gdeltapup.ini

DEEP - 373
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\GDLog\UPD_mas
Value : Log#141 = 3/21/2006 10:06:28 PM - CDwnldGroup::GetDownloadLocation: Download location:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\UPD_mas
Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\UPD_mas

DEEP - 374
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_QCL\GDLog\QCL_INSTALL_AgentCabs
Value : Log#043 = 3/21/2006 10:11:19 PM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:Downloading Constants File..., LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~1\AgentVer.ini
Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~1\AgentVer.ini

DEEP - 375
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_QCL\GDLog\QCL_INSTALL_AgentCabs
Value : Log#109 = 4/10/2006 12:21:45 AM - CDwnldGroup::GetDownloadLocation: Download location:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~1
Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~1

DEEP - 376
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_QCL\GDLog\QCL_INSTALL_QCLCabs
Value : Log#017 = 3/21/2006 10:11:49 PM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:Downloading Ini File..., LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2\QclVer.Ini
Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2\QclVer.Ini

DEEP - 377
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_QCL\GDLog\QCL_INSTALL_QCLCabs
Value : Log#025 = 3/21/2006 10:11:51 PM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:Downloading Application Setup..., LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2\quickcleanh\QuickCleanSetup.exe
Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2\quickcleanh\QuickCleanSetup.exe

DEEP - 378
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_QCL\GDLog\QCL_INSTALL_QCLCabs
Value : Log#044 = 4/10/2006 12:20:30 AM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:Downloading Application Setup..., LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2\quickcleanh\QuickCleanSetup.exe
Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2\quickcleanh\QuickCleanSetup.exe

DEEP - 379
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_QCL\GDLog\QCL_INSTALL_QCLCabs
Value : Log#065 = 4/10/2006 12:20:57 AM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:Downloading Application Setup..., LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2\quickcleanh\QuickCleanSetup.exe
Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2\quickcleanh\QuickCleanSetup.exe

DEEP - 380
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_QCL\GDLog\QCL_INSTALL_QCLCabs
Value : Log#071 = 4/10/2006 12:21:45 AM - CDwnldGroup::GetDownloadLocation: Download location:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2
Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2

DEEP - 381
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_Vso\GDLog\VSO_INSTALL_AgentCabs
Value : Log#108 = 4/23/2006 12:16:58 PM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:Downloading Constants File..., LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~1\AgentVer.ini
Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~1\AgentVer.ini

DEEP - 382
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_Vso\GDLog\VSO_INSTALL_AgentCabs
Value : Log#122 = 4/23/2006 12:17:31 PM - CDwnldGroup::GetDownloadLocation: Download location:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~1
Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~1

DEEP - 383
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_Vso\GDLog\VSO_INSTALL_VsoCabs
Value : Log#077 = 4/23/2006 12:17:31 PM - CDwnldGroup::GetDownloadLocation: Download location:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~2
Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~2

DEEP - 384
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_Vso\GDLog\VSO_INSTALL_VsoDatCabs
Value : Log#021 = 4/23/2006 12:16:55 PM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:Downloading Constants File..., LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~3\VsoVer.ini
Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~3\VsoVer.ini

DEEP - 385
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_Vso\GDLog\VSO_INSTALL_VsoDatCabs
Value : Log#025 = 4/23/2006 12:16:56 PM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:Downloading Virus Change File..., LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~3\vso\mcdelta.ini
Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~3\vso\mcdelta.ini

DEEP - 386
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_Vso\GDLog\VSO_INSTALL_VsoDatCabs
Value : Log#031 = 4/23/2006 12:17:31 PM - CDwnldGroup::GetDownloadLocation: Download location:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~3
Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~3

DEEP - 387
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
Value : MpfLog029 = Backup mpf data file : \data\pcfg.ent To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\pcfg.ent
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\pcfg.ent

DEEP - 388
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
Value : MpfLog030 = Backup mpf data file : \data\rdns.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\rdns.idx
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\rdns.idx

DEEP - 389
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
Value : MpfLog031 = Backup mpf data file : \data\hwid.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\hwid.idx
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\hwid.idx

DEEP - 390
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
Value : MpfLog032 = Backup mpf data file : \data\banned.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\banned.idx
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\banned.idx

DEEP - 391
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
Value : MpfLog033 = Backup mpf data file : \data\golden.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\golden.idx
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\golden.idx

DEEP - 392
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
Value : MpfLog034 = Backup mpf data file : \data\sports.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\sports.idx
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\sports.idx

DEEP - 393
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
Value : MpfLog035 = Backup mpf data file : \data\sports.ent To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\sports.ent
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\sports.ent

DEEP - 394
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
Value : MpfLog036 = Backup mpf data file : \data\winloc.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\winloc.idx
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\winloc.idx

DEEP - 395
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
Value : MpfLog037 = Backup mpf data file : \data\certi.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\certi.idx
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\certi.idx

DEEP - 396
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
Value : MpfLog038 = Backup mpf data file : \data\options.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\options.idx
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\options.idx

DEEP - 397
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
Value : MpfLog039 = Backup mpf data file : \data\log.edb To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\log.edb
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\log.edb

DEEP - 398
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
Value : MpfLog040 = Backup mpf data file : \data\log.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\log.idx
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\log.idx

DEEP - 399
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
Value : MpfLog041 = Backup mpf data file : \data\IpRules.xdb To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\IpRules.xdb
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\IpRules.xdb

DEEP - 400
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
Value : MpfLog042 = Backup mpf data file : \data\TrafficHist.xdb To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\TrafficHist.xdb
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\TrafficHist.xdb

DEEP - 401
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
Value : MpfLog043 = Backup mpf data file : \data\RIR.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\RIR.idx
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\RIR.idx

DEEP - 402
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
Value : MpfLog047 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpfcfg_cab\mpfcfg.inf$$ Result: 0
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpfcfg_cab\mpfcfg.inf

DEEP - 403
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
Value : MpfLog048 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpftray_cab\mpftray.inf$$ Result: 0
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpftray_cab\mpftray.inf

DEEP - 404
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
Value : MpfLog049 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpfmain_cab\mpfmain.inf$$ Result: 0
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpfmain_cab\mpfmain.inf

DEEP - 405
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
Value : MpfLog050 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpf_cab\mpf.inf$$ Result: 0
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpf_cab\mpf.inf

DEEP - 406
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
Value : MpfLog051 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpfadf_cab\mpfadf.inf$$ Result: 0
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpfadf_cab\mpfadf.inf

DEEP - 407
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
Value : MpfLog052 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\regwiz_cab\regwiz.inf$$ Result: 0
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\regwiz_cab\regwiz.inf

DEEP - 408
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
Value : MpfLog053 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpfreg_cab\mpfreg.inf$$ Result: 0
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpfreg_cab\mpfreg.inf

DEEP - 409
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
Value : MpfLog071 = Removing temp mpf data folder : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata

DEEP - 410
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
Value : MpfLog099 = Removing$$Extract Folder: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp$$Result: 0
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp$$Result

DEEP - 411
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
Value : MpfLog101 = Removing$$Extract Folder: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp$$Result: 2
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp$$Result

DEEP - 412
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\RegWiz\Installer
Value : RegWizLog#001 = c:\docume~1\alluse~1\applic~1\mcafee.com\agent\regwiz\regapp\vso.ini found for registration
Parsed : c:\docume~1\alluse~1\applic~1\mcafee.com\agent\regwiz\regapp\vso.ini found for registration

DEEP - 413
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\RegWiz\Installer
Value : RegWizLog#003 = Application already registered. Deleting file : c:\docume~1\alluse~1\applic~1\mcafee.com\agent\regwiz\regapp\vso.ini
Parsed : c:\docume~1\alluse~1\applic~1\mcafee.com\agent\regwiz\regapp\vso.ini

DEEP - 414
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Shredder\Installer
Value : ShredderDownloadPath = C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\SHR_6_~1.TMP
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\SHR_6_~1.TMP

DEEP - 415
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Shredder\Installer
Value : ShredderLog005 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA69.tmp\tempinst\cntrlbin_cab\cntrlbin.inf$$ Result: 0
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA69.tmp\tempinst\cntrlbin_cab\cntrlbin.inf

DEEP - 416
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Shredder\Installer
Value : ShredderLog006 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA69.tmp\tempinst\cntrlres_cab\cntrlres.inf$$ Result: 0
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA69.tmp\tempinst\cntrlres_cab\cntrlres.inf

DEEP - 417
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Shredder\Installer
Value : ShredderLog007 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA69.tmp\tempinst\shredcfg_cab\shredcfg.inf$$ Result: 0
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA69.tmp\tempinst\shredcfg_cab\shredcfg.inf

DEEP - 418
Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Shredder\Installer
Value : ShredderLog008 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA69.tmp\tempinst\shredbin_cab\shredbin.inf$$ Result: 0
Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA69.tmp\tempinst\shredbin_cab\shredbin.inf

DEEP - 419
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup
Value : JITSetupPage = file://C:\WINDOWS\web\iejit.htm
Parsed : C:\WINDOWS\web\iejit.htm

DEEP - 420
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\b107806c-d088-4344-98b4-4839c7767af9
Value : StubPath = C:\WINDOWS\System32\hqhzxz.exe
Parsed : C:\WINDOWS\System32\hqhzxz.exe

DEEP - 421
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectPlay\Applications\Age of Empires II
Value : Path = C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game - no cd crack\
Parsed : C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game

DEEP - 422
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectPlay\Applications\Age of Empires II
Value : CurrentDirectory = C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game - no cd crack\
Parsed : C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game

DEEP - 423
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectPlay\Applications\Age of Empires II - The Conquerors Expansion
Value : Path = C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game - no cd crack\
Parsed : C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game

DEEP - 424
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectPlay\Applications\Age of Empires II - The Conquerors Expansion
Value : CurrentDirectory = C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game - no cd crack\
Parsed : C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game

DEEP - 425
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Exchange\Client\Extensions
Value : Remote Exchange Extensions = 4.0;C:\WINDOWS\System32\emsui32.dll;6;111;111;MSEMS
Parsed : C:\WINDOWS\System32\emsui32.dll

DEEP - 426
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Default HTML Editor\shell\edit\command
Value : (Default) = C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE
Parsed : C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE

DEEP - 427
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer
Value : MetadataTemplatesDir = C:\Program Files\Windows Media Player\Templates
Parsed : C:\Program Files\Windows Media Player\Templates

DEEP - 428
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Games\Age of Empires\2.0
Value : CDPath = C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game - no cd crack\
Parsed : C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game

DEEP - 429
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Games\Age of Empires\2.0
Value : InstallationDirectory = C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game - no cd crack\
Parsed : C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game

DEEP - 430
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Games\Age of Empires\2.0
Value : EXE Path = C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game - no cd crack\
Parsed : C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game

DEEP - 431
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Games\Age of Empires II: The Conquerors Expansion\1.0
Value : EXE Path = C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game - no cd crack\
Parsed : C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game

DEEP - 432
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Games\Age of Empires II: The Conquerors Expansion\1.0
Value : CDPath = C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game - no cd crack\
Parsed : C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game

DEEP - 433
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\MPlayer2\Groups\Video\DVR-MS
Value : RequiredFile = C:\WINDOWS\system32\enable.dvd
Parsed : C:\WINDOWS\system32\enable.dvd

DEEP - 434
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Groups\Video\DVD
Value : RequiredFile = C:\WINDOWS\system32\enable.dvd
Parsed : C:\WINDOWS\system32\enable.dvd

DEEP - 435
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Groups\Video\DVR-MS
Value : RequiredFile = C:\WINDOWS\system32\enable.dvd
Parsed : C:\WINDOWS\system32\enable.dvd

DEEP - 436
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared\HTML\Default Editor\shell\Edit\command
Value : (Default) = C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE
Parsed : C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE

DEEP - 437
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared\HTML\Old Default Editor\shell\Edit\command
Value : (Default) = C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE
Parsed : C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE

DEEP - 438
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\DeluxeCD\Providers\Provider0000
Value : ProviderLogo = C:\WINDOWS\System32\tunes.bmp
Parsed : C:\WINDOWS\System32\tunes.bmp

DEEP - 439
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\DeluxeCD\Providers\Provider0001
Value : ProviderLogo = C:\WINDOWS\System32\n2k.bmp
Parsed : C:\WINDOWS\System32\n2k.bmp

DEEP - 440
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\Paint Shop Pro 9ShowPicturesOnArrivalHandler
Value : DefaultIcon = C:\PROGRA~1\JASCSO~1\PAINTS~1\PAINTS~1.EXE,0
Parsed : C:\PROGRA~1\JASCSO~1\PAINTS~1\PAINTS~1.EXE

DEEP - 441
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\PDVDPlayDVDMovieOnArrival
Value : DefaultIcon = C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe,0
Parsed : C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe

DEEP - 442
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FindExtensions\Static\Avg7Find\0\DefaultIcon
Value : (Default) = C:\Program Files\Grisoft\AVG7\avgse.dll,0
Parsed : C:\Program Files\Grisoft\AVG7\avgse.dll

DEEP - 443
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\WebView\TemplateMacros\BACKGROUNDIMAGE
Value : (Default) = C:\WINDOWS\Web\wvleft.bmp
Parsed : C:\WINDOWS\Web\wvleft.bmp

DEEP - 444
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\WebView\TemplateMacros\LOGOLINE
Value : (Default) = C:\WINDOWS\Web\wvline.gif
Parsed : C:\WINDOWS\Web\wvline.gif

DEEP - 445
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\00FF41F8FA41BC84091B4C07CABDF9E3
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

DEEP - 446
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0152806F405208847813DD8BED99D629
Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\ALEUpdat.exe
Parsed : C:\Program Files\Norton AntiVirus\IWP\ALEUpdat.exe

DEEP - 447
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\024EC3F90C2DE7C4FB1FFB4F5F332623
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\CfgWiz.exe
Parsed : C:\Program Files\Norton AntiVirus\CfgWiz.exe

DEEP - 448
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0322C474330FE1744AF900BCC66F5833
Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\niscmnht.dll
Parsed : C:\Program Files\Norton AntiVirus\IWP\niscmnht.dll

DEEP - 449
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\03A9FC3E3E95C0740A521901F8767CB1
Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Common Files\Symantec Shared\
Parsed : C:\Program Files\Common Files\Symantec Shared

DEEP - 450
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0411415FD32B9B946A61D0C303BD27AD
Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\TLevel.dll
Parsed : C:\Program Files\Norton AntiVirus\IWP\TLevel.dll

DEEP - 451
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\044E7B0C1B06EC14E92B7D5969253EC2
Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\ccALE.dll
Parsed : C:\Program Files\Norton AntiVirus\IWP\ccALE.dll

DEEP - 452
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\04B22DD6AA9C23646A3C3F467E57860C
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Quarantine\Portal\
Parsed : C:\Program Files\Norton AntiVirus\Quarantine\Portal

DEEP - 453
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\05396EEFA666F7742A096C3DF3072D54
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\apwcmdNT.dll
Parsed : C:\Program Files\Norton AntiVirus\apwcmdNT.dll

DEEP - 454
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\071A0387AE84BCF43AB238E53AB547C0
Value : 9CFA723DAAB7A3743891E67B0A4D1083 = C:\Program Files\Norton AntiVirus\ScriptUI.dll
Parsed : C:\Program Files\Norton AntiVirus\ScriptUI.dll

DEEP - 455
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\075603C1A0A349649BF01150129CC6A5
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\
Parsed : C:\Documents and Settings\All Users\Application Data\Symantec\Common Client

DEEP - 456
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\075603C1A0A349649BF01150129CC6A5
Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\
Parsed : C:\Documents and Settings\All Users\Application Data\Symantec\Common Client

DEEP - 457
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\075603C1A0A349649BF01150129CC6A5
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\
Parsed : C:\Documents and Settings\All Users\Application Data\Symantec\Common Client

DEEP - 458
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\07B3E601E527C0949954E5851542466B
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

DEEP - 459
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\07CEB7E467263F443B6E612F4B98D7F8
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

DEEP - 460
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\099321B84C2C2BB41851CA389FB70165
Value : 45E1A0ACF0EC66340BC98AB716CD6533 = C:\Program Files\Common Files\Symantec Shared\SPManifests\Snd.spm
Parsed : C:\Program Files\Common Files\Symantec Shared\SPManifests\Snd.spm

DEEP - 461
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0AA8DBE6FFF98184CB16089724A103B2
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVOptRF.dll
Parsed : C:\Program Files\Norton AntiVirus\NAVOptRF.dll

DEEP - 462
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0C8F566CEA001F943A1DEEF074599FDF
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Common Files\Symantec Shared\SMNLnch.exe
Parsed : C:\Program Files\Common Files\Symantec Shared\SMNLnch.exe

DEEP - 463
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0DC310B120C02754683F563C5C11B7CC
Value : 20B58AD20C31D6E4A967226E3BDDC02B = C:\Program Files\Common Files\Symantec Shared\Validate.dat
Parsed : C:\Program Files\Common Files\Symantec Shared\Validate.dat

DEEP - 464
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0DC310B120C02754683F563C5C11B7CC
Value : 45E1A0ACF0EC66340BC98AB716CD6533 = C:\Program Files\Common Files\Symantec Shared\Validate.dat
Parsed : C:\Program Files\Common Files\Symantec Shared\Validate.dat

DEEP - 465
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1060C7258FD43414295BB92A86DFD912
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Quarantine\Incoming\
Parsed : C:\Program Files\Norton AntiVirus\Quarantine\Incoming

DEEP - 466
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\10B257D254F25D11EA9F00054081F409
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\S32integ.dll
Parsed : C:\Program Files\Norton AntiVirus\S32integ.dll

DEEP - 467
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\10FC05BCE9FD5984389C446876524F82
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVCfgWz.dll
Parsed : C:\Program Files\Norton AntiVirus\NAVCfgWz.dll

DEEP - 468
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\16426ABC13D89D245B93A02C0DC9C224
Value : 9CFA723DAAB7A3743891E67B0A4D1083 = C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe
Parsed : C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe

DEEP - 469
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\17AE107A723326C46A2C93522D3F59F8
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

DEEP - 470
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\18CC08AD0DA03A34DAB29E0514DC04D1
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVShExt.dll
Parsed : C:\Program Files\Norton AntiVirus\NAVShExt.dll

DEEP - 471
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A3CD7C9A0AAA554DAAC220641E0D17E
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\navprod.dll
Parsed : C:\Program Files\Norton AntiVirus\navprod.dll

DEEP - 472
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1D666097B6EC4A44E844F041AC395953
Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\ALECmpBR.dll
Parsed : C:\Program Files\Norton AntiVirus\IWP\ALECmpBR.dll

DEEP - 473
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F0DFF6444337B64A9497B276826DB8E
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\
Parsed : C:\Program Files\Common Files\Symantec Shared

DEEP - 474
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\20383D4B10B0E3346A8BD698FE0B295D
Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\IWPLog.dll
Parsed : C:\Program Files\Norton AntiVirus\IWP\IWPLog.dll

DEEP - 475
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\22BF77BEE865A83449FBD70DE99B5F7A
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NetBrExt.DLL
Parsed : C:\Program Files\Norton AntiVirus\NetBrExt.DLL

DEEP - 476
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2575DB0D1CB48604491FD73C89519EC8
Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\IWP.dll
Parsed : C:\Program Files\Norton AntiVirus\IWP\IWP.dll

DEEP - 477
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\262DD75104DBB3B498A0AA44A2F88A19
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\probeGSE.dll
Parsed : C:\Program Files\Norton AntiVirus\probeGSE.dll

DEEP - 478
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2725A89474CB12C44BB65170875EBA48
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVAPW32.exe
Parsed : C:\Program Files\Norton AntiVirus\NAVAPW32.exe

DEEP - 479
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\291736580EC2EED4397DA98BEF610A20
Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\HNetCore.dll
Parsed : C:\Program Files\Norton AntiVirus\IWP\HNetCore.dll

DEEP - 480
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2BCD27044B81E3D4EBD766BC953C323E
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\savrt.sys
Parsed : C:\Program Files\Norton AntiVirus\savrt.sys

DEEP - 481
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2D40DF4A1B79BC94B8BB811C21CDB9F3
Value : 7E57FF1D24DDDFC40B25023BFF4FDE8B = C:\Program Files\Norton AntiVirus\ActRes.DLL
Parsed : C:\Program Files\Norton AntiVirus\ActRes.DLL

DEEP - 482
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E0E3AC586E450848BDFF8BDAA3AF964
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\
Parsed : C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus

DEEP - 483
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E53A294F83182D45A3785356A851754
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\ccInst.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\ccInst.dll

DEEP - 484
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E53A294F83182D45A3785356A851754
Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\ccInst.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\ccInst.dll

DEEP - 485
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\39A23B5C4F5C6654693A6634C7824847
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\README.TXT
Parsed : C:\Program Files\Norton AntiVirus\README.TXT

DEEP - 486
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3A8C3EA18ADB24E4C8E1875EC8F06375
Value : 9CFA723DAAB7A3743891E67B0A4D1083 = C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrTrust.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrTrust.dll

DEEP - 487
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3B288C03487C8374F965BB84C5E356C2
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

DEEP - 488
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3B2D8CCBDF636154CA11562FA1985814
Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\FRERules.dll
Parsed : C:\Program Files\Norton AntiVirus\IWP\FRERules.dll

DEEP - 489
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3C9A2AED576F5544193A0C5A8DC65BE7
Value : 45E1A0ACF0EC66340BC98AB716CD6533 = C:\Program Files\Common Files\Symantec Shared\SPManifests\Snd.sig
Parsed : C:\Program Files\Common Files\Symantec Shared\SPManifests\Snd.sig

DEEP - 490
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3DEE68F0FC3313E4CAD8E4C3EBCBEC40
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Text.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Text.dll

DEEP - 491
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3DEE68F0FC3313E4CAD8E4C3EBCBEC40
Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Text.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Text.dll

DEEP - 492
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3E63A1A0FC3E1F24BB302AC419D4841C
Value : 7E57FF1D24DDDFC40B25023BFF4FDE8B = C:\Program Files\Norton AntiVirus\LRSend.exe
Parsed : C:\Program Files\Norton AntiVirus\LRSend.exe

DEEP - 493
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3E81A4DC21026924FB5FAF933085D236
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll

DEEP - 494
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3E81A4DC21026924FB5FAF933085D236
Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll

DEEP - 495
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3EC45CFDA09D6744B8D8C04431ED1964
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\AVRES.dll
Parsed : C:\Program Files\Norton AntiVirus\AVRES.dll

DEEP - 496
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\42D544166A9040246AE61A6BD1E89875
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

DEEP - 497
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\43BE7E834BB89F74EA8045BE46CCB3F5
Value : 45E1A0ACF0EC66340BC98AB716CD6533 = C:\Program Files\Common Files\Symantec Shared\SPManifests\Snd.grd
Parsed : C:\Program Files\Common Files\Symantec Shared\SPManifests\Snd.grd

DEEP - 498
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\441567AAA28618C46A8BACAAC9BD2047
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\ecmldr32.DLL
Parsed : C:\Program Files\Common Files\Symantec Shared\ecmldr32.DLL

DEEP - 499
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\443CD4F6572D500468FFF934363232A4
Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\IWPLUCbk.dll
Parsed : C:\Program Files\Norton AntiVirus\IWP\IWPLUCbk.dll

DEEP - 500
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4542E17C204027C4A9DB81B657767BE8
Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\FREAles.dll
Parsed : C:\Program Files\Norton AntiVirus\IWP\FREAles.dll

DEEP - 501
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\471F6E8954126A04AAA3FE5AA79243D3
Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\Ales.xml
Parsed : C:\Program Files\Norton AntiVirus\IWP\Ales.xml

DEEP - 502
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4799D30A4DDA954429D8D4ED011517F9
Value : 9CFA723DAAB7A3743891E67B0A4D1083 = C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrAuth.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrAuth.dll

DEEP - 503
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\47E0174F57CC8504DA862CA99CBAEA31
Value : 9399EE5EF9522ED40832C5941EA6F434 = C:\Program Files\Common Files\Symantec Shared\SymUIAx2.ocx
Parsed : C:\Program Files\Common Files\Symantec Shared\SymUIAx2.ocx

DEEP - 504
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\48982BA41E042FE4893568B326EAE47E
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\DefAlert.dll
Parsed : C:\Program Files\Norton AntiVirus\DefAlert.dll

DEEP - 505
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\48F14AD033FE3EB4A87CDCEDC2AAE23B
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Common Files\Symantec Shared\
Parsed : C:\Program Files\Common Files\Symantec Shared

DEEP - 506
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49769A67806F0484C968C8A5358B1098
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

DEEP - 507
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4AC03AFAAEE94804C8614EFF36AFC5A1
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\SYMNAVO.DLL
Parsed : C:\Program Files\Norton AntiVirus\SYMNAVO.DLL

DEEP - 508
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4CB829E5237898741983A2C0FB59BAEF
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\
Parsed : C:\Program Files\Common Files\Symantec Shared

DEEP - 509
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4CB829E5237898741983A2C0FB59BAEF
Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Common Files\Symantec Shared\
Parsed : C:\Program Files\Common Files\Symantec Shared

DEEP - 510
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4CB829E5237898741983A2C0FB59BAEF
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Common Files\Symantec Shared\
Parsed : C:\Program Files\Common Files\Symantec Shared

DEEP - 511
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4CBC83BFDE475DB418A2AE96BCFDE865
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\avcompbr.dll
Parsed : C:\Program Files\Norton AntiVirus\avcompbr.dll

DEEP - 512
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50A419CA949024647B7A0E569BA7918C
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVComUI.dll
Parsed : C:\Program Files\Norton AntiVirus\NAVComUI.dll

DEEP - 513
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50BBD0A1CB1FD3648A16157120DF2829
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TNEF.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TNEF.dll

DEEP - 514
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50BBD0A1CB1FD3648A16157120DF2829
Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TNEF.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TNEF.dll

DEEP - 515
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50C154874C6F14B48AE0F5068BC7E626
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\DefUtDCD.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\DefUtDCD.dll

DEEP - 516
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50C154874C6F14B48AE0F5068BC7E626
Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\DefUtDCD.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\DefUtDCD.dll

DEEP - 517
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50E357748DE0DD840851872431DDB49B
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RTF.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RTF.dll

DEEP - 518
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50E357748DE0DD840851872431DDB49B
Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RTF.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RTF.dll

DEEP - 519
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5214FA3088B8BAD419A265B6153E97C0
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Common Files\Symantec Shared\VirusDefs\
Parsed : C:\Program Files\Common Files\Symantec Shared\VirusDefs

DEEP - 520
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53EC7F36FB9D406418715FDA8AC5C485
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\N32call.dll
Parsed : C:\Program Files\Norton AntiVirus\N32call.dll

DEEP - 521
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\595EDF0A76C2DF14DA38D14496F0422F
Value : 9399EE5EF9522ED40832C5941EA6F434 = C:\Program Files\Common Files\Symantec Shared\CfgWiz.tlb
Parsed : C:\Program Files\Common Files\Symantec Shared\CfgWiz.tlb

DEEP - 522
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5F14878ED4CBD6B4995778B62914DE82
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\ScanMgr.dll
Parsed : C:\Program Files\Norton AntiVirus\ScanMgr.dll

DEEP - 523
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5F711C7C816E497409B42799F858A73B
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\
Parsed : C:\Program Files\Common Files\Symantec Shared

DEEP - 524
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\615168D24A7AD1745A12D7DBE603484A
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\qspak32.dll
Parsed : C:\Program Files\Norton AntiVirus\qspak32.dll

DEEP - 525
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6175647594900AC4AB89DA41EC22BDCA
Value : 7E57FF1D24DDDFC40B25023BFF4FDE8B = C:\Program Files\Norton AntiVirus\SymLCUI.dll
Parsed : C:\Program Files\Norton AntiVirus\SymLCUI.dll

DEEP - 526
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\663818B8178761A498A24322153E6C55
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\scancfg.dat
Parsed : C:\Program Files\Norton AntiVirus\scancfg.dat

DEEP - 527
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\668C52B058E567C4A9461F74298A7B16
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\navui.nsi
Parsed : C:\Program Files\Norton AntiVirus\navui.nsi

DEEP - 528
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6714C945179DA67419B483C6A8082757
Value : 7E57FF1D24DDDFC40B25023BFF4FDE8B = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

DEEP - 529
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\681293A7B6EE4994588C3F608CE24AE7
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

DEEP - 530
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6906F858261DD5142981FFF252CECF0C
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\apwutil.dll
Parsed : C:\Program Files\Norton AntiVirus\apwutil.dll

DEEP - 531
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6925106EE9D0AF740BCCD43F8907862F
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TAR.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TAR.dll

DEEP - 532
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6925106EE9D0AF740BCCD43F8907862F
Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TAR.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TAR.dll

DEEP - 533
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6A41CC073B92EE847B8FFCE9495410A9
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

DEEP - 534
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6B0AE912F7ED2224CBB5D6B506795029
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVEvent.dll
Parsed : C:\Program Files\Norton AntiVirus\NAVEvent.dll

DEEP - 535
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6C903CD2A490B0C4B817B5822363D670
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Navwnt.exe
Parsed : C:\Program Files\Norton AntiVirus\Navwnt.exe

DEEP - 536
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6E567B288C21FE748928C2F767434E49
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

DEEP - 537
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6EEA3CF07EBD65C48A3FE380BC2FF61E
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LZ.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LZ.dll

DEEP - 538
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6EEA3CF07EBD65C48A3FE380BC2FF61E
Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LZ.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LZ.dll

DEEP - 539
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F197F7372EA24349AC09AC49ABA402E
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVAPSCR.dll
Parsed : C:\Program Files\Norton AntiVirus\NAVAPSCR.dll

DEEP - 540
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F8308D658EBA7E48AC20C2C1C53D51F
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVLogV.dll
Parsed : C:\Program Files\Norton AntiVirus\NAVLogV.dll

DEEP - 541
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7029927AC4655CF4CA5476C0F7A0844A
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVOpts.dll
Parsed : C:\Program Files\Norton AntiVirus\NAVOpts.dll

DEEP - 542
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\717AB62A0DC6B434EA08A1A45AC41341
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\ccDec.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\ccDec.dll

DEEP - 543
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\744510B0F96EA7346945429C47B772AB
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\qconsole.exe
Parsed : C:\Program Files\Norton AntiVirus\qconsole.exe

DEEP - 544
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7469F3930A15C804EBC767838BD0E200
Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\IDSDefs\
Parsed : C:\Program Files\Norton AntiVirus\IWP\IDSDefs

DEEP - 545
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\74B65AE67660E0649AB135AA083E16D6
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\ccIMScan.dll
Parsed : C:\Program Files\Norton AntiVirus\ccIMScan.dll

DEEP - 546
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\758CEDE445E075242A1B28C209469190
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

DEEP - 547
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7B50EBD049034D245BACB7DF3D3F0055
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\
Parsed : C:\Program Files\Common Files\Symantec Shared

DEEP - 548
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7B555CBEE5D5DC34DA22C85A114E44D6
Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\ccRuleIO.dll
Parsed : C:\Program Files\Norton AntiVirus\IWP\ccRuleIO.dll

DEEP - 549
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7D6437C5C6894A94F8CBB03BDF0023CE
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\ccL30.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\ccL30.dll

DEEP - 550
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7D6437C5C6894A94F8CBB03BDF0023CE
Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\ccL30.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\ccL30.dll

DEEP - 551
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8009C7720B95C304C81241A8EC4D39D6
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\ccLogin.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\ccLogin.dll

DEEP - 552
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\81CE673053E252642B9EB19881D11525
Value : 9399EE5EF9522ED40832C5941EA6F434 = C:\Program Files\Common Files\Symantec Shared\
Parsed : C:\Program Files\Common Files\Symantec Shared

DEEP - 553
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\82EF65EE71A8DFE46BF3103894868C74
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVTasks.dll
Parsed : C:\Program Files\Norton AntiVirus\NAVTasks.dll

DEEP - 554
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\83056920BAAA6E64A9DD0F72BB1F8568
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\S32NAVO.DLL
Parsed : C:\Program Files\Norton AntiVirus\S32NAVO.DLL

DEEP - 555
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8350CADA40F1245418AE0898B5F2CC8F
Value : 9CFA723DAAB7A3743891E67B0A4D1083 = C:\Program Files\Common Files\Symantec Shared\VirusDefs\MyAuth.dat
Parsed : C:\Program Files\Common Files\Symantec Shared\VirusDefs\MyAuth.dat

DEEP - 556
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\846574CE2AA8B9C40AD64866F9DE77A7
Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
Parsed : C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe

DEEP - 557
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\849F6BDFC1324574389DDBD802611B2D
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Common Files\Symantec Shared\ccGSE.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\ccGSE.dll

DEEP - 558
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\85A6640347184DE419174A7D938EE4A3
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
Parsed : C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

DEEP - 559
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8B245E22A8EFDF94EBC89D75F9CB11EC
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVStub.exe
Parsed : C:\Program Files\Norton AntiVirus\NAVStub.exe

DEEP - 560
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8B45BF4DC2F0A1B4B9327CFFF2806334
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\SavRT32.dll
Parsed : C:\Program Files\Norton AntiVirus\SavRT32.dll

DEEP - 561
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8B508B6DAB8B7964E8AD0D371CF29B5C
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\DJSAlert.dll
Parsed : C:\Program Files\Norton AntiVirus\DJSAlert.dll

DEEP - 562
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CC0AB79D89CB4549B29F8FA2785D777
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\SAVScan.exe
Parsed : C:\Program Files\Norton AntiVirus\SAVScan.exe

DEEP - 563
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8E63A159A784DEF41BB6209B779E6D45
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

DEEP - 564
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8EF9EE1FC66940B468785FE27846A4B5
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\
Parsed : C:\Program Files\Common Files\Symantec Shared

DEEP - 565
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\91F31ECC41B96D243A45422551C96C23
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Zip.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Zip.dll

DEEP - 566
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\91F31ECC41B96D243A45422551C96C23
Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Zip.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Zip.dll

DEEP - 567
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\932EEA56C5A47C8499E284F46ACC2016
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Documents and Settings\All Users\Start Menu\Programs\Norton AntiVirus\
Parsed : C:\Documents and Settings\All Users\Start Menu\Programs\Norton AntiVirus

DEEP - 568
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\953E4C7EF5A3315458FC82A7BD02EE98
Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Common Files\Symantec Shared\SPBBC\SPLVPlug.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\SPBBC\SPLVPlug.dll

DEEP - 569
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\953E4C7EF5A3315458FC82A7BD02EE98
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Common Files\Symantec Shared\SPBBC\SPLVPlug.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\SPBBC\SPLVPlug.dll

DEEP - 570
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9542A2F29521AEA49825DACE47ECB069
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\qconres.dll
Parsed : C:\Program Files\Norton AntiVirus\qconres.dll

DEEP - 571
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\956B95676BE85A84DA3C38A66DE87EF4
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RAR.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RAR.dll

DEEP - 572
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\956B95676BE85A84DA3C38A66DE87EF4
Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RAR.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RAR.dll

DEEP - 573
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9650EFDF332FF2741B72B1F1F2CA1DA7
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVUIHTM.dll
Parsed : C:\Program Files\Norton AntiVirus\NAVUIHTM.dll

DEEP - 574
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A31A16C69A2D4F40B30BC92212E9182
Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\ccFWSetg.dll
Parsed : C:\Program Files\Norton AntiVirus\IWP\ccFWSetg.dll

DEEP - 575
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D20C7BA42CFF7A43BF7BB1BD173829F
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

DEEP - 576
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A0BBBFBB9DF126841A599E50CF74E420
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

DEEP - 577
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A3CEBDA9EBF8DEA4FBE368F050BEE9B5
Value : 9399EE5EF9522ED40832C5941EA6F434 = C:\Program Files\Common Files\Symantec Shared\
Parsed : C:\Program Files\Common Files\Symantec Shared

DEEP - 578
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A53030D1FA7CD0C42A0CE951CD8D70B6
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Navap32.dll
Parsed : C:\Program Files\Norton AntiVirus\Navap32.dll

DEEP - 579
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A6AFA04EFD73D69418C4062C5576D74F
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\
Parsed : C:\Program Files\Common Files\Symantec Shared

DEEP - 580
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A8DC89FAF3F52B3448C6E06B118C405E
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2AMG.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2AMG.dll

DEEP - 581
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A8DC89FAF3F52B3448C6E06B118C405E
Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2AMG.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2AMG.dll

DEEP - 582
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AA5473481968D2C449595600631BF60F
Value : 9399EE5EF9522ED40832C5941EA6F434 = C:\Program Files\Norton AntiVirus\AVSTE.dll
Parsed : C:\Program Files\Norton AntiVirus\AVSTE.dll

DEEP - 583
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AB41244462F87CA4B9F2050D4AF13DE0
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVLUCBK.dll
Parsed : C:\Program Files\Norton AntiVirus\NAVLUCBK.dll

DEEP - 584
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AC715C67C18D0E14986117D61115B5D9
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\navapw32.dll
Parsed : C:\Program Files\Norton AntiVirus\navapw32.dll

DEEP - 585
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AD0898EB938AF6148ACBF7D389DE3E3D
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Statushp.dll
Parsed : C:\Program Files\Norton AntiVirus\Statushp.dll

DEEP - 586
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AE218B3D3A784674FA9D4ED959E3F941
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

DEEP - 587
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AE842139D531885469A1CDC35A26B1F4
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\DecSDK.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\DecSDK.dll

DEEP - 588
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AE842139D531885469A1CDC35A26B1F4
Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\DecSDK.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\DecSDK.dll

DEEP - 589
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B00431804170C134B939ED6830DA1C39
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\SDSOK32I.DLL
Parsed : C:\Program Files\Norton AntiVirus\SDSOK32I.DLL

DEEP - 590
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B16AC77B767B76344ADD68B231863B6A
Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\FREInteg.dll
Parsed : C:\Program Files\Norton AntiVirus\IWP\FREInteg.dll

DEEP - 591
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B305EF16382BB1E43B550C61C5E6C983
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVSTATS.dll
Parsed : C:\Program Files\Norton AntiVirus\NAVSTATS.dll

DEEP - 592
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3131345148ADC043AA743CF15C58161
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Scandlvr.dll
Parsed : C:\Program Files\Norton AntiVirus\Scandlvr.dll

DEEP - 593
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3F6A2DB538BA6E44B9404005AFB41E2
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Documents and Settings\All Users\Application Data\Symantec\
Parsed : C:\Documents and Settings\All Users\Application Data\Symantec

DEEP - 594
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3F6A2DB538BA6E44B9404005AFB41E2
Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Documents and Settings\All Users\Application Data\Symantec\
Parsed : C:\Documents and Settings\All Users\Application Data\Symantec

DEEP - 595
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3F6A2DB538BA6E44B9404005AFB41E2
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Documents and Settings\All Users\Application Data\Symantec\
Parsed : C:\Documents and Settings\All Users\Application Data\Symantec

DEEP - 596
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B4AA92F71A4DC8843B921505A7EE1982
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVError.dll
Parsed : C:\Program Files\Norton AntiVirus\NAVError.dll

DEEP - 597
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B95F812E3128A514B869E6BFEE1FEDF3
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\COUNTRY.DAT
Parsed : C:\Program Files\Norton AntiVirus\COUNTRY.DAT

DEEP - 598
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BB26CE3D008E2FA499FDEE6A7A5B9335
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2CAB.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2CAB.dll

DEEP - 599
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BB26CE3D008E2FA499FDEE6A7A5B9335
Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2CAB.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2CAB.dll

DEEP - 600
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BBAE3AAB8D0042547990AF991553C16B
Value : 9CFA723DAAB7A3743891E67B0A4D1083 = C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrBlock.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrBlock.dll

DEEP - 601
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BD04BAF963B867144BE7910CADB91EC8
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVUI.dll
Parsed : C:\Program Files\Norton AntiVirus\NAVUI.dll

DEEP - 602
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BDEA5D3B2A1FFDC44B55F08AD7801175
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\OPScan.exe
Parsed : C:\Program Files\Norton AntiVirus\OPScan.exe

DEEP - 603
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BE6AEA47C44CE854791235345CE87CE6
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LHA.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LHA.dll

DEEP - 604
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BE6AEA47C44CE854791235345CE87CE6
Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LHA.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LHA.dll

DEEP - 605
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BEB4972A12860764BB195C6D768E12A1
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Common Files\Symantec Shared\
Parsed : C:\Program Files\Common Files\Symantec Shared

DEEP - 606
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF34ED1C895652B4D92C1D66CE00BF98
Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\fwUI.dll
Parsed : C:\Program Files\Norton AntiVirus\IWP\fwUI.dll

DEEP - 607
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C1AC78A74A3296B4BA739BA5E5766344
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2SS.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2SS.dll

DEEP - 608
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C1AC78A74A3296B4BA739BA5E5766344
Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2SS.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2SS.dll

DEEP - 609
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C1D015D543A678D4088D751CA77430A5
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ARJ.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ARJ.dll

DEEP - 610
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C1D015D543A678D4088D751CA77430A5
Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ARJ.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ARJ.dll

DEEP - 611
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C30AE6C259C7B424E914F0A0C4C244BA
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\N32Exclu.dll
Parsed : C:\Program Files\Norton AntiVirus\N32Exclu.dll

DEEP - 612
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C33570307F55DB54396FFFF444D96E0B
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\navapsvc.exe
Parsed : C:\Program Files\Norton AntiVirus\navapsvc.exe

DEEP - 613
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C3BD2CD6023CED14080DED74FA48DDCA
Value : 7E57FF1D24DDDFC40B25023BFF4FDE8B = C:\Program Files\Common Files\Symantec Shared\CCPD-LC\
Parsed : C:\Program Files\Common Files\Symantec Shared\CCPD-LC

DEEP - 614
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C519BC4820133E149AC900B6B2F708CA
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\CfgWzRes.dll
Parsed : C:\Program Files\Norton AntiVirus\CfgWzRes.dll

DEEP - 615
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C7C4F0E638DD18A46B7A39824E3A6EE8
Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\SymFwAgt.DLL
Parsed : C:\Program Files\Norton AntiVirus\IWP\SymFwAgt.DLL

DEEP - 616
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C8C9E5A275AC91441BD5E7569AAFEDDC
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Savrtpel.sys
Parsed : C:\Program Files\Norton AntiVirus\Savrtpel.sys

DEEP - 617
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB101FE8D11198442AB0CE71DBBB7996
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVLnch.dll
Parsed : C:\Program Files\Norton AntiVirus\NAVLnch.dll

DEEP - 618
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CDAF0D299B31D614A997AC7EFF57FE6F
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Help\CCLGVIEW.CHM
Parsed : C:\Program Files\Common Files\Symantec Shared\Help\CCLGVIEW.CHM

DEEP - 619
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CDB8298C7464d6d489512651FE1AADA4
Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\ISWrap.dll
Parsed : C:\Program Files\Norton AntiVirus\IWP\ISWrap.dll

DEEP - 620
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D134FCA7554F39744BE3E935F5FDC7A8
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\quar32.dll
Parsed : C:\Program Files\Norton AntiVirus\quar32.dll

DEEP - 621
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D1F9A4570B6A53B4ABA8EABBF618BACC
Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\ICFMgr.dll
Parsed : C:\Program Files\Norton AntiVirus\IWP\ICFMgr.dll

DEEP - 622
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2B1A54B84E046A40B699A99AA183415
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Navntutl.dll
Parsed : C:\Program Files\Norton AntiVirus\Navntutl.dll

DEEP - 623
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2ED3A901D3C1E640A22123D3329A663
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\PtchInst.dll
Parsed : C:\Program Files\Norton AntiVirus\PtchInst.dll

DEEP - 624
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2EEB513BDC48C443B0FFC4606A08DFF
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ID.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ID.dll

DEEP - 625
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2EEB513BDC48C443B0FFC4606A08DFF
Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ID.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ID.dll

DEEP - 626
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D485B77AAFBE7FE4EB02F19B1C742D99
Value : 7E57FF1D24DDDFC40B25023BFF4FDE8B = C:\Program Files\Norton AntiVirus\SymUIHlp.dll
Parsed : C:\Program Files\Norton AntiVirus\SymUIHlp.dll

DEEP - 627
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D4C317E99F72CD94E80229440898C76B
Value : 20B58AD20C31D6E4A967226E3BDDC02B = C:\Program Files\Common Files\Symantec Shared\Default.rul
Parsed : C:\Program Files\Common Files\Symantec Shared\Default.rul

DEEP - 628
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D4C317E99F72CD94E80229440898C76B
Value : 45E1A0ACF0EC66340BC98AB716CD6533 = C:\Program Files\Common Files\Symantec Shared\Default.rul
Parsed : C:\Program Files\Common Files\Symantec Shared\Default.rul

DEEP - 629
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D5C7E0ECE38B2204C81A6CAC7B563C1E
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\OEHeur.dll
Parsed : C:\Program Files\Norton AntiVirus\OEHeur.dll

DEEP - 630
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB37AD6F8B343624D8A21F9536E244D0
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\ccScan.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\ccScan.dll

DEEP - 631
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DDBB2E3516FF53D49B7674092DF93A43
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Scandres.dll
Parsed : C:\Program Files\Norton AntiVirus\Scandres.dll

DEEP - 632
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DE6692E1170B7234EB5CFD71486A1C3F
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2GZIP.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2GZIP.dll

DEEP - 633
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DE6692E1170B7234EB5CFD71486A1C3F
Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2GZIP.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2GZIP.dll

DEEP - 634
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E03493F9C46190242AE587161C8E1607
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Documents and Settings\All Users\Application Data\Symantec\
Parsed : C:\Documents and Settings\All Users\Application Data\Symantec

DEEP - 635
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E226A5EC6DBEB5B41AA58B99246CA6EA
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Navlcom.dll
Parsed : C:\Program Files\Norton AntiVirus\Navlcom.dll

DEEP - 636
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E41CAC9D612ABD845B8DB1A766C5818E
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\SDPCK32I.DLL
Parsed : C:\Program Files\Norton AntiVirus\SDPCK32I.DLL

DEEP - 637
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E5A2A8E777C123D41A1B9870787E7200
Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\ACDisp.dll
Parsed : C:\Program Files\Norton AntiVirus\IWP\ACDisp.dll

DEEP - 638
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EACA16BD93C3AC64E9487A0F15FA0CB7
Value : 6786F822313A3A04190C3CBC6E99D790 = C:\Documents and Settings\All Users\Application Data\Symantec\
Parsed : C:\Documents and Settings\All Users\Application Data\Symantec

DEEP - 639
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EACA16BD93C3AC64E9487A0F15FA0CB7
Value : 20B58AD20C31D6E4A967226E3BDDC02B = C:\Documents and Settings\All Users\Application Data\Symantec\
Parsed : C:\Documents and Settings\All Users\Application Data\Symantec

DEEP - 640
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EACA16BD93C3AC64E9487A0F15FA0CB7
Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Documents and Settings\All Users\Application Data\Symantec\
Parsed : C:\Documents and Settings\All Users\Application Data\Symantec

DEEP - 641
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EACA16BD93C3AC64E9487A0F15FA0CB7
Value : 5A60346F23C4bb141B3535895672AF4B = C:\Documents and Settings\All Users\Application Data\Symantec\
Parsed : C:\Documents and Settings\All Users\Application Data\Symantec

DEEP - 642
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EBB41D27C6D48A142A21DC74BA5CD4A7
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

DEEP - 643
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED9559B59719B7648A5698448B0F5C13
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\SDSTP32I.DLL
Parsed : C:\Program Files\Norton AntiVirus\SDSTP32I.DLL

DEEP - 644
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EDA2F868189B4BB43835954121D6D84F
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\ccAVMail.dll
Parsed : C:\Program Files\Norton AntiVirus\ccAVMail.dll

DEEP - 645
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EDB816C6DB3D2D34E9E028C26D00C79E
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

DEEP - 646
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EE7648442F6386F4B974667E874252D3
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\SDSND32I.DLL
Parsed : C:\Program Files\Norton AntiVirus\SDSND32I.DLL

DEEP - 647
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF24F0C8CEA62F94AABE0F1D2DCFE65B
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVTskWz.dll
Parsed : C:\Program Files\Norton AntiVirus\NAVTskWz.dll

DEEP - 648
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F09CF45C228A5D946916CA86F0B28466
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\navsess.tpl
Parsed : C:\Program Files\Norton AntiVirus\navsess.tpl

DEEP - 649
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F1031A4EC1C5b044694350E3CF04BF73
Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\ISLuCbk.dll
Parsed : C:\Program Files\Norton AntiVirus\IWP\ISLuCbk.dll

DEEP - 650
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F14B2730986758A4FACCDABB202D7702
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\ccIMScn.exe
Parsed : C:\Program Files\Norton AntiVirus\ccIMScn.exe

DEEP - 651
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F297450C80AA7B44CAC9B12C24BFA5C5
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\LtChkRes.dll
Parsed : C:\Program Files\Norton AntiVirus\LtChkRes.dll

DEEP - 652
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F42B98E5315CA254F98CB0E739C7CEA1
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2.dll

DEEP - 653
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F42B98E5315CA254F98CB0E739C7CEA1
Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2.dll
Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2.dll

DEEP - 654
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F4BA67E73F1500B44B2BE9626C16C657
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\patch25d.dll
Parsed : C:\Program Files\Norton AntiVirus\patch25d.dll

DEEP - 655
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F890C1DE6479A8044916B360F03F6577
Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\
Parsed : C:\Program Files\Common Files\Symantec Shared

DEEP - 656
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F959C548DF373904DBA75FAB7EEDBB3C
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\end_user.txt
Parsed : C:\Program Files\Norton AntiVirus\end_user.txt

DEEP - 657
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA0AE70A711E43A4D845D528F62189C8
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\OfficeAV.dll
Parsed : C:\Program Files\Norton AntiVirus\OfficeAV.dll

DEEP - 658
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FAE59BAC70CEF6B4C907FE4AF0B1C09A
Value : F81D34B847CD44D418E4B93D24B0E844 = C:\Program Files\McAfee\McAfee QuickClean\Restore\ShredEnu.dll
Parsed : C:\Program Files\McAfee\McAfee QuickClean\Restore\ShredEnu.dll

DEEP - 659
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB9E629FE71958F499EAB75A10C537C2
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Navw32.exe
Parsed : C:\Program Files\Norton AntiVirus\Navw32.exe

DEEP - 660
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FDB73BAFBA2FA4448A9F560C8AE6AB05
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\AboutPlg.dll
Parsed : C:\Program Files\Norton AntiVirus\AboutPlg.dll

DEEP - 661
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FFEBF8E0EFEA5B440A054DF0D1F8C8C9
Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Tasks\files.sca
Parsed : C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Tasks\files.sca

DEEP - 662
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\207809E353FA1164598159D52AB4E770\InstallProperties
Value : InstallSource = C:\WINDOWS\TEMP\IXP000.TMP\
Parsed : C:\WINDOWS\TEMP\IXP000.TMP

DEEP - 663
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\20B58AD20C31D6E4A967226E3BDDC02B\InstallProperties
Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SymNet\
Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SymNet

DEEP - 664
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\45E1A0ACF0EC66340BC98AB716CD6533\InstallProperties
Value : InstallSource = C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\LIVEUP~1\DOWNLO~1\EXITEM~1.0_E\
Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\LIVEUP~1\DOWNLO~1\EXITEM~1.0_E

DEEP - 665
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5A60346F23C4bb141B3535895672AF4B\InstallProperties
Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SymSC\
Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SymSC

DEEP - 666
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5F1BEE43939E1A046AAB5927284A2B8C\InstallProperties
Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\Help\
Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\Help

DEEP - 667
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6786F822313A3A04190C3CBC6E99D790\InstallProperties
Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\MSRedist\
Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\MSRedist

DEEP - 668
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7E57FF1D24DDDFC40B25023BFF4FDE8B\InstallProperties
Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV\
Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV

DEEP - 669
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\806763CD7A467FB4294FB8AA52AB20BD\InstallProperties
Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\ccCommon\
Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\ccCommon

DEEP - 670
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\87627777F71810443910DED1108AAD65\InstallProperties
Value : InstallLocation = C:\Program Files\Norton AntiVirus\
Parsed : C:\Program Files\Norton AntiVirus

DEEP - 671
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\87627777F71810443910DED1108AAD65\InstallProperties
Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SPBBC\
Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SPBBC

DEEP - 672
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040820900063D11C8EF00054038389C\InstallProperties
Value : InstallSource = C:\Documents and Settings\keno cannady\Shared\Microsoft Office XP Professional (Includes Serial Number)\Microsoft Office XP\
Parsed : C:\Documents and Settings\keno cannady\Shared\Microsoft Office XP Professional (Includes Serial Number)\Microsoft Office XP

DEEP - 673
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9399EE5EF9522ED40832C5941EA6F434\InstallProperties
Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV\
Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV

DEEP - 674
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9CFA723DAAB7A3743891E67B0A4D1083\InstallProperties
Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\ScrBlock\
Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\ScrBlock

DEEP - 675
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC0F80924D1CF744792AFC1C539C8F4D\InstallProperties
Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV\
Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV

DEEP - 676
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F81D34B847CD44D418E4B93D24B0E844\InstallProperties
Value : Readme = C:\Program Files\McAfee\McAfee QuickClean\Readme.txt
Parsed : C:\Program Files\McAfee\McAfee QuickClean\Readme.txt

DEEP - 677
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\FC6B5F6CC906E82478F6AC3871C620B1\InstallProperties
Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV\
Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV

DEEP - 678
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
Value : Directory = C:\WINDOWS\History
Parsed : C:\WINDOWS\History

DEEP - 679
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup
Value : ServicePackCachePath = c:\windows\ServicePackFiles\ServicePackCache
Parsed : c:\windows\ServicePackFiles\ServicePackCache

DEEP - 680
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Migration DLLs
Value : {5945c046-1e7d-11d1-bc44-00c04fd912be} = C:\Program Files\Messenger\migrate.dll
Parsed : C:\Program Files\Messenger\migrate.dll

DEEP - 681
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\StillImage\Registered Applications
Value : OmniPage SE = C:\Program Files\ScanSoft\OmniPageSE\OmniPage.exe /StiDevice:%1 /StiEvent:%2
Parsed : C:\Program Files\ScanSoft\OmniPageSE\OmniPage.exe

DEEP - 682
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Reporting\EventCache\Sus
Value : CurrentCacheFile = C:\WINDOWS\SoftwareDistribution\EventCache\{07F5D015-59A7-4B7E-95D0-4A50A504ED85}.bin
Parsed : C:\WINDOWS\SoftwareDistribution\EventCache\{07F5D015-59A7-4B7E-95D0-4A50A504ED85}.bin

DEEP - 683
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Reporting\EventCache\WU
Value : CurrentCacheFile = C:\WINDOWS\SoftwareDistribution\EventCache\{E78161BE-AB16-4DEE-A62D-E3774298CEFC}.bin
Parsed : C:\WINDOWS\SoftwareDistribution\EventCache\{E78161BE-AB16-4DEE-A62D-E3774298CEFC}.bin

DEEP - 684
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SeCEdit
Value : TemplateUsed = C:\WINDOWS\SEC129B.tmp
Parsed : C:\WINDOWS\SEC129B.tmp

DEEP - 685
Location: HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar
Value : Dir = C:\Program Files\MyWay\myBar\
Parsed : C:\Program Files\MyWay\myBar

DEEP - 686
Location: HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\partner
Value : bitmap = C:\Program Files\MyWay\myBar\1.bin\partner.bmp
Parsed : C:\Program Files\MyWay\myBar\1.bin\partner.bmp

DEEP - 687
Location: HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\partner
Value : test = C:\Program Files\Altnet\Points Manager\Points Manager.exe -p 1
Parsed : C:\Program Files\Altnet\Points Manager\Points Manager.exe

DEEP - 688
Location: HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\partner
Value : PM-Home = C:\Program Files\Altnet\Points Manager\Points Manager.exe
Parsed : C:\Program Files\Altnet\Points Manager\Points Manager.exe

DEEP - 689
Location: HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\partner
Value : PM-Points = C:\Program Files\Altnet\Points Manager\Points Manager.exe -p 1
Parsed : C:\Program Files\Altnet\Points Manager\Points Manager.exe

DEEP - 690
Location: HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\partner
Value : PM-Redeem = C:\Program Files\Altnet\Points Manager\Points Manager.exe -p 2
Parsed : C:\Program Files\Altnet\Points Manager\Points Manager.exe

DEEP - 691
Location: HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\partner
Value : PM-Wallet = C:\Program Files\Altnet\Points Manager\Points Manager.exe -p 3
Parsed : C:\Program Files\Altnet\Points Manager\Points Manager.exe

DEEP - 692
Location: HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\partner
Value : PM-Settings = C:\Program Files\Altnet\Points Manager\Points Manager.exe -p 4
Parsed : C:\Program Files\Altnet\Points Manager\Points Manager.exe

DEEP - 693
Location: HKEY_LOCAL_MACHINE\SOFTWARE\NCH Swift Sound\Components\mp3el
Value : Path = C:\Program Files\NCH Swift Sound\Components\mp3el\mp3enc.exe
Parsed : C:\Program Files\NCH Swift Sound\Components\mp3el\mp3enc.exe

DEEP - 694
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Trymedia Systems\ActiveMARK Software\22CD942489E05966FCC70B6D0C25B30B
Value : path = C:\Program Files\PlayFirst\Diner Dash\Diner Dash.exe
Parsed : C:\Program Files\PlayFirst\Diner Dash\Diner Dash.exe

DEEP - 695
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Trymedia Systems\ActiveMARK Software\AC72B3AB1BCFC04699EA3EA6A35608AD
Value : path = C:\Program Files\iWin.com Games\Family Feud\FamilyFeud.exe
Parsed : C:\Program Files\iWin.com Games\Family Feud\FamilyFeud.exe

DEEP - 696
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Trymedia Systems\ActiveMARK Software\B1A6C040A5B0EA8E8F64BEED9FEBE83B
Value : path = C:\Program Files\Yahoo! Games\Trivia Machine\TriviaMachine.exe
Parsed : C:\Program Files\Yahoo! Games\Trivia Machine\TriviaMachine.exe

----------------------------------------------------------------------------------------------------
Registry Mechanic 5.2.0.310
----------------------------------------------------------------------------------------------------
End of Scan
4/24/2006 5:20:09 PM
Your System Information :
CPU: Intel Pentium
IE: Internet Explorer 6.0.2900
MEMORY FREE: 494388
MEMORY TOTAL: 785904
VIRTUAL FREE: 2019252
VIRTUAL TOTAL: 2097024
WINDOWS VER: Windows XP 5.1 (Build 2600)

This message has been edited since posting. Last time this message was edited on 24. April 2006 @ 13:45

Senior Member
_
25. April 2006 @ 04:36 _ Link to this message    Send private message to this user   
Ok, did you clean your registry with CCleaner?

I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere.
Advertisement
_
__
 
_
daddy163
Junior Member
_
25. April 2006 @ 07:27 _ Link to this message    Send private message to this user   
I think all is well now here is the new hajthis log:

Logfile of HijackThis v1.99.1
Scan saved at 11:25:24 AM, on 4/25/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\progra~1\mcafee\mcafee antispyware\massrv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\VIAudioi\SBADeck\ADeck.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\progra~1\mcafee\MCAFEE~1\masalert.exe
C:\Program Files\BellSouth\Alert Manager\BellSouthAlertManager.exe
C:\Program Files\McAfee.com\Personal Firewall\MPFTray.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Microsoft Office\Office10\msoffice.exe
C:\WINDOWS\System32\svchost.exe
C:\progra~1\mcafee\MCAFEE~1\MASCon.exe
C:\PROGRA~1\mcafee.com\shared\mghtml.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~1\masalert.exe
O4 - HKLM\..\Run: [BellSouthAlertManager.exe] C:\Program Files\BellSouth\Alert Manager\BellSouthAlertManager.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MPFEXE] "C:\Program Files\McAfee.com\Personal Firewall\MPFTray.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [McAfee QuickClean Imonitor] C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe /START
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/229?8d588edfc4be46d8a2396ae9a351e6bf
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/230?8d588edfc4be46d8a2396ae9a351e6bf
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcins...
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x8...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/...
O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} (McAfee Virtual Technician Control Class) - http://us-download.mcafee.com/products/protected/mvt/mvt.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4744/mcfs...
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee AntiSpyware Service - McAfee, Inc. - c:\progra~1\mcafee\mcafee antispyware\massrv.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

I do thank you for all your help. By the way do you know what it was that I had?

This message has been edited since posting. Last time this message was edited on 25. April 2006 @ 07:34

 
Page:12Next >
afterdawn.com > forums > software, operating systems and more > windows - virus and spyware problems > my computer has virus that want let me do a scan
 

Digital video: AfterDawn.com | AfterDawn Forums
Music: MP3Lizard.com
Gaming: Blasteroids.com | Blasteroids Forums | Compare game prices
Software: Software downloads
Blogs: User profile pages
RSS feeds: AfterDawn.com News | Software updates | AfterDawn Forums
International: AfterDawn in Finnish | AfterDawn in Swedish | AfterDawn in Norwegian | download.fi
Navigate: Search | Site map
About us: About AfterDawn Ltd | Advertise on our sites | Rules, Restrictions, Legal disclaimer & Privacy policy
Contact us: Send feedback | Contact our media sales team
 
  © 1999-2024 by AfterDawn Ltd.

  IDG TechNetwork