1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

My computer has virus that want let me do a scan

Discussion in 'Windows - Virus and spyware problems' started by daddy163, Apr 18, 2006.

  1. daddy163

    daddy163 Member

    Joined:
    Jan 13, 2006
    Messages:
    28
    Likes Received:
    0
    Trophy Points:
    11
    Nothing found. I do appreciate your help, what now?
     
  2. JaPK

    JaPK Regular member

    Joined:
    Feb 23, 2006
    Messages:
    1,269
    Likes Received:
    0
    Trophy Points:
    46
    Last edited: Apr 24, 2006
  3. daddy163

    daddy163 Member

    Joined:
    Jan 13, 2006
    Messages:
    28
    Likes Received:
    0
    Trophy Points:
    11
    here the log from registy mechanic: This is all the problem areas or files I have on my pc

    ----------------------------------------------------------------------------------------------------
    Registry Mechanic 5.2.0.310
    ----------------------------------------------------------------------------------------------------
    Start of Scan
    4/24/2006 4:54:46 PM
    Your System Information :
    CPU: Intel Pentium
    IE: Internet Explorer 6.0.2900
    MEMORY FREE: 494388
    MEMORY TOTAL: 785904
    VIRTUAL FREE: 2019252
    VIRTUAL TOTAL: 2097024
    WINDOWS VER: Windows XP 5.1 (Build 2600)

    ----------------------------------------------------------------------------------------------------
    Running processes: Process ID
    ----------------------------------------------------------------------------------------------------
    [System Process] 0
    System 4
    smss.exe 548
    csrss.exe 612
    winlogon.exe 636
    services.exe 680
    lsass.exe 700
    svchost.exe 856
    svchost.exe 916
    svchost.exe 1016
    svchost.exe 1096
    svchost.exe 1164
    spoolsv.exe 1388
    ewidoctrl.exe 1936
    ewidoguard.exe 1952
    MASSrv.exe 2004
    Mcdetect.exe 2028
    McShield.exe 268
    McTskshd.exe 316
    mcupdmgr.exe 540
    MpfService.exe 568
    nvsvc32.exe 356
    locator.exe 760
    wdfmgr.exe 980
    wmiprvse.exe 1480
    explorer.exe 380
    ADeck.exe 2184
    mcagent.exe 2204
    MASAlert.exe 2260
    BellSouthAlertManager.exe 2436
    oasclnt.exe 2536
    MpfTray.exe 2652
    McVSEscn.exe 2668
    MpfAgent.exe 3816
    msmsgs.exe 4032
    Ymsgr_tray.exe 1920
    PlgUni.exe 2256
    mcvsftsn.exe 2788
    WinCinemaMgr.exe 3304
    MSOFFICE.EXE 3580
    memtest.exe 488
    iexplore.exe 2052
    RegMech.exe 2756
    ----------------------------------------------------------------------------------------------------
    Sections Scanned:
    ----------------------------------------------------------------------------------------------------

    FX - 2
    Location: HKEY_CLASSES_ROOT\.snp
    Value : default = Snapshot File
    Parsed :

    FX - 3
    Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bin\OpenWithList
    Value : default = blank
    Parsed :

    FX - 4
    Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.EX_\OpenWithList
    Value : default = blank
    Parsed :

    FX - 5
    Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.IN_\OpenWithList
    Value : default = blank
    Parsed :

    FX - 6
    Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rar\OpenWithList
    Value : default = blank
    Parsed :

    FX - 7
    Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tlb\OpenWithList
    Value : default = blank
    Parsed :

    SP - 8
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
    Value : C:\WINDOWS\Downloaded Program Files\popcaploader.dll = C:\WINDOWS\Downloaded Program Files\popcaploader.dll
    Parsed : C:\WINDOWS\Downloaded Program Files\popcaploader.dll

    ARP - 9
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BroadJump Client Foundation
    Value : DisplayIcon = C:\Program Files\BroadJump\Client Foundation\CFD.exe
    Parsed : C:\Program Files\BroadJump\Client Foundation\CFD.exe

    ARP - 10
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sevinst
    Value : QuietUninstallString = C:\Program Files\Common Files\Symantec Shared\SEVINST.EXE /U /Q
    Parsed : C:\Program Files\Common Files\Symantec Shared\SEVINST.EXE

    ARP - 11
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Genie OnlineMy Toolbar
    Value : UninstallString = regsvr32 /u /s "C:\Program Files\KoolBar\koolbar.dll"
    Parsed : C:\Program Files\KoolBar\koolbar.dll

    ARP - 12
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{228F6876-A313-40A3-91C0-C3CBE6997D09}
    Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\MSRedist\
    Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\MSRedist

    ARP - 13
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2908F0CB-C1D4-447F-97A2-CFC135C9F8D4}
    Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV\
    Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV

    ARP - 14
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2DA85B02-13C0-4E6D-9A76-22E6B3DD0CB2}
    Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SymNet\
    Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SymNet

    ARP - 15
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{34EEB1F5-E939-40A1-A6BA-957282A4B2C8}
    Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\Help\
    Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\Help

    ARP - 16
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3E908702-AF35-4611-9518-955DA24B7E07}
    Value : InstallSource = C:\WINDOWS\TEMP\IXP000.TMP\
    Parsed : C:\WINDOWS\TEMP\IXP000.TMP

    ARP - 17
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}
    Value : DisplayIcon = C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe,0
    Parsed : C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe

    ARP - 18
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{77772678-817F-4401-9301-ED1D01A8DA56}
    Value : InstallLocation = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    ARP - 19
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{77772678-817F-4401-9301-ED1D01A8DA56}
    Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SPBBC\
    Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SPBBC

    ARP - 20
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B43D18F-DC74-4D44-814E-9BD3420B8E44}
    Value : Readme = C:\Program Files\McAfee\McAfee QuickClean\Readme.txt
    Parsed : C:\Program Files\McAfee\McAfee QuickClean\Readme.txt

    ARP - 21
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90280409-6000-11D3-8CFE-0050048383C9}
    Value : InstallSource = C:\Documents and Settings\keno cannady\Shared\Microsoft Office XP Professional (Includes Serial Number)\Microsoft Office XP\
    Parsed : C:\Documents and Settings\keno cannady\Shared\Microsoft Office XP Professional (Includes Serial Number)\Microsoft Office XP

    ARP - 22
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C6F5B6CF-609C-428E-876F-CA83176C021B}
    Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV\
    Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV

    ARP - 23
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CA0A1E54-CE0F-4366-B09C-A87B61DC5633}
    Value : InstallSource = C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\LIVEUP~1\DOWNLO~1\EXITEM~1.0_E\
    Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\LIVEUP~1\DOWNLO~1\EXITEM~1.0_E

    ARP - 24
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D1FF75E7-DD42-4CFD-B052-20B3FFF4EDB8}
    Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV\
    Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV

    ARP - 25
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D327AFC9-7BAA-473A-8319-6EB7A0D40138}
    Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\ScrBlock\
    Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\ScrBlock

    ARP - 26
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DC367608-64A7-4BF7-92F4-8BAA25BA02DB}
    Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\ccCommon\
    Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\ccCommon

    ARP - 27
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E5EE9939-259F-4DE2-8023-5C49E16A4F43}
    Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV\
    Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV

    ARP - 28
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F5346614-B7C4-4E94-826A-E2363155233D}
    Value : InstallSource = C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\bye16.tmp\Disk1\
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\bye16.tmp\Disk1

    ARP - 29
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F64306A5-4C32-41bb-B153-53986527FAB4}
    Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SymSC\
    Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SymSC

    CC - 30
    Location: HKEY_CLASSES_ROOT\AcroExch.Document.7\protocol\StdFileEditing\server
    Value : (Default) = "C:\Program Files\Adobe\Acrobat 7.0\Acrobat\Acrobat.exe"
    Parsed : C:\Program Files\Adobe\Acrobat 7.0\Acrobat\Acrobat.exe

    CC - 31
    Location: HKEY_CLASSES_ROOT\CLSID\{00CEDC01-864D-11D3-908D-00C0F03B3EDC}\ToolboxBitmap32
    Value : (Default) = C:\Program Files\Real\RealOne Player\ierjplug.dll, 1
    Parsed : C:\Program Files\Real\RealOne Player\ierjplug.dll

    CC - 32
    Location: HKEY_CLASSES_ROOT\CLSID\{0494D0DE-F8E0-41ad-92A3-14154ECE70AC}\Instance\InitPropertyBag
    Value : Url = res://C:\PROGRA~1\MyWay\myBar\1.bin\MYBAR.DLL/105
    Parsed : C:\PROGRA~1\MyWay\myBar\1.bin\MYBAR.DLL

    CC - 33
    Location: HKEY_CLASSES_ROOT\CLSID\{06290BD5-48AA-11D2-8432-006008C3FBFC}\InprocServer32
    Value : ScriptStopper_InProcServer32 = C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrBlock.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrBlock.dll

    CC - 34
    Location: HKEY_CLASSES_ROOT\CLSID\{166B1BCA-3F9C-11CF-8075-444553540000}\ToolboxBitmap32
    Value : (Default) = C:\WINDOWS\system32\Macromed\Shockwave 10\Control.dll, 203
    Parsed : C:\WINDOWS\system32\Macromed\Shockwave 10\Control.dll

    CC - 35
    Location: HKEY_CLASSES_ROOT\CLSID\{9ccfb0e0-fbce-11d6-8a38-00b0d0c6b814}\LocalServer
    Value : (Default) = C:\Program Files\McAfee\McAfee Privacy Service\GUARDDOG.EXE
    Parsed : C:\Program Files\McAfee\McAfee Privacy Service\GUARDDOG.EXE

    CC - 36
    Location: HKEY_CLASSES_ROOT\CLSID\{CC2C83A6-9BE4-11D0-98E7-00C04FC2CAF5}\InprocServer32
    Value : SystemDB = C:\Program Files\Microsoft Office\Office10\1033\system.mdw
    Parsed : C:\Program Files\Microsoft Office\Office10\1033\system.mdw

    CC - 37
    Location: HKEY_CLASSES_ROOT\DVD\DefaultIcon
    Value : MPlayer2.BAK = C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe,0
    Parsed : C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe

    CC - 38
    Location: HKEY_CLASSES_ROOT\TypeLib\{00000000-0000-0000-0000-000000000002}\1.0\0\win32
    Value : (Default) = C:\Program Files\KoolBar\koolbar.dll
    Parsed : C:\Program Files\KoolBar\koolbar.dll

    CC - 39
    Location: HKEY_CLASSES_ROOT\TypeLib\{00000000-0000-0000-0000-000000000002}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\KoolBar\
    Parsed : C:\Program Files\KoolBar

    CC - 40
    Location: HKEY_CLASSES_ROOT\TypeLib\{00025E01-0000-0000-C000-000000000046}\3.0\0\win32
    Value : (Default) = C:\Program Files\Common Files\Microsoft Shared\DAO\DAO3032.DLL
    Parsed : C:\Program Files\Common Files\Microsoft Shared\DAO\DAO3032.DLL

    CC - 41
    Location: HKEY_CLASSES_ROOT\TypeLib\{0002E540-0000-0000-C000-000000000046}\1.0\0\win32
    Value : (Default) = C:\Program Files\Microsoft Office\Office\MSOWC.DLL
    Parsed : C:\Program Files\Microsoft Office\Office\MSOWC.DLL

    CC - 42
    Location: HKEY_CLASSES_ROOT\TypeLib\{0002E540-0000-0000-C000-000000000046}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Microsoft Office\Office\
    Parsed : C:\Program Files\Microsoft Office\Office

    CC - 43
    Location: HKEY_CLASSES_ROOT\TypeLib\{00CEDBF1-864D-11D3-908D-00C0F03B3EDC}\1.0\0\win32
    Value : (Default) = C:\Program Files\Real\RealOne Player\ierjplug.dll
    Parsed : C:\Program Files\Real\RealOne Player\ierjplug.dll

    CC - 44
    Location: HKEY_CLASSES_ROOT\TypeLib\{00CEDBF1-864D-11D3-908D-00C0F03B3EDC}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Real\RealOne Player\
    Parsed : C:\Program Files\Real\RealOne Player

    CC - 45
    Location: HKEY_CLASSES_ROOT\TypeLib\{0494D0D0-F8E0-41AD-92A3-14154ECE70AC}\1.0\0\win32
    Value : (Default) = C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
    Parsed : C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL

    CC - 46
    Location: HKEY_CLASSES_ROOT\TypeLib\{0494D0D0-F8E0-41AD-92A3-14154ECE70AC}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\MyWay\myBar\1.bin\
    Parsed : C:\Program Files\MyWay\myBar\1.bin

    CC - 47
    Location: HKEY_CLASSES_ROOT\TypeLib\{06DD38D0-D187-11CF-A80D-00C04FD74AD8}\1.0\0\win32
    Value : (Default) = C:\WINDOWS\System32\plugin.ocx
    Parsed : C:\WINDOWS\System32\plugin.ocx

    CC - 48
    Location: HKEY_CLASSES_ROOT\TypeLib\{091FC996-00F1-4ED0-8351-7F0BFD553172}\1.0\0\win32
    Value : (Default) = C:\PROGRA~1\COMMON~1\SYMANT~1\SymLTCOM.dll
    Parsed : C:\PROGRA~1\COMMON~1\SYMANT~1\SymLTCOM.dll

    CC - 49
    Location: HKEY_CLASSES_ROOT\TypeLib\{091FC996-00F1-4ED0-8351-7F0BFD553172}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
    Parsed : C:\Program Files\Common Files\Symantec Shared

    CC - 50
    Location: HKEY_CLASSES_ROOT\TypeLib\{0A8B9461-3921-11D3-B1AB-0080C84E9C15}\1.0\0\win32
    Value : (Default) = C:\Program Files\CyberLink\PowerDVD\CLInet.dll
    Parsed : C:\Program Files\CyberLink\PowerDVD\CLInet.dll

    CC - 51
    Location: HKEY_CLASSES_ROOT\TypeLib\{0A8B9461-3921-11D3-B1AB-0080C84E9C15}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\CyberLink\PowerDVD\
    Parsed : C:\Program Files\CyberLink\PowerDVD

    CC - 52
    Location: HKEY_CLASSES_ROOT\TypeLib\{0E9FFA9E-B267-44DF-BC81-2B08E3977ED5}\1.0\0\win32
    Value : (Default) = C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    Parsed : C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe

    CC - 53
    Location: HKEY_CLASSES_ROOT\TypeLib\{0E9FFA9E-B267-44DF-BC81-2B08E3977ED5}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Microsoft AntiSpyware
    Parsed : C:\Program Files\Microsoft AntiSpyware

    CC - 54
    Location: HKEY_CLASSES_ROOT\TypeLib\{140CF3D1-451B-4C9C-AB04-02C72D06A88D}\1.0\0\win32
    Value : (Default) = C:\Program Files\Microsoft AntiSpyware\gcAntiSpywareLibrary.dll
    Parsed : C:\Program Files\Microsoft AntiSpyware\gcAntiSpywareLibrary.dll

    CC - 55
    Location: HKEY_CLASSES_ROOT\TypeLib\{140CF3D1-451B-4C9C-AB04-02C72D06A88D}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Microsoft AntiSpyware
    Parsed : C:\Program Files\Microsoft AntiSpyware

    CC - 56
    Location: HKEY_CLASSES_ROOT\TypeLib\{166B1BC7-3F9C-11CF-8075-444553540000}\1.0\0\win32
    Value : (Default) = C:\WINDOWS\system32\Macromed\Shockwave 10\Control.dll
    Parsed : C:\WINDOWS\system32\Macromed\Shockwave 10\Control.dll

    CC - 57
    Location: HKEY_CLASSES_ROOT\TypeLib\{1C3159CA-948C-4290-A920-4C804DF9FB7D}\1.0\0\win32
    Value : (Default) = C:\Program Files\Norton AntiVirus\Navlcom.dll
    Parsed : C:\Program Files\Norton AntiVirus\Navlcom.dll

    CC - 58
    Location: HKEY_CLASSES_ROOT\TypeLib\{1C3159CA-948C-4290-A920-4C804DF9FB7D}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    CC - 59
    Location: HKEY_CLASSES_ROOT\TypeLib\{20F6AEAC-284A-4022-A0A8-718AB2087D37}\1.0\0\win32
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\SLTCHK01.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\SLTCHK01.dll

    CC - 60
    Location: HKEY_CLASSES_ROOT\TypeLib\{20F6AEAC-284A-4022-A0A8-718AB2087D37}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
    Parsed : C:\Program Files\Common Files\Symantec Shared

    CC - 61
    Location: HKEY_CLASSES_ROOT\TypeLib\{226CDAFB-819C-4298-89FA-8A018BB188B5}\1.0\0\win32
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\ccErrDsp.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\ccErrDsp.dll

    CC - 62
    Location: HKEY_CLASSES_ROOT\TypeLib\{226CDAFB-819C-4298-89FA-8A018BB188B5}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
    Parsed : C:\Program Files\Common Files\Symantec Shared

    CC - 63
    Location: HKEY_CLASSES_ROOT\TypeLib\{2292E927-BD89-40DE-999A-4E72CE0EAA4F}\1.0\0\win32
    Value : (Default) = C:\Program Files\Norton AntiVirus\NavShExt.dll
    Parsed : C:\Program Files\Norton AntiVirus\NavShExt.dll

    CC - 64
    Location: HKEY_CLASSES_ROOT\TypeLib\{2292E927-BD89-40DE-999A-4E72CE0EAA4F}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    CC - 65
    Location: HKEY_CLASSES_ROOT\TypeLib\{2CECFD1F-CA35-4558-AC7F-64B6B463714A}\1.0\0\win32
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    Parsed : C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

    CC - 66
    Location: HKEY_CLASSES_ROOT\TypeLib\{2CECFD1F-CA35-4558-AC7F-64B6B463714A}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
    Parsed : C:\Program Files\Common Files\Symantec Shared

    CC - 67
    Location: HKEY_CLASSES_ROOT\TypeLib\{31DDE823-839A-4DD2-8D96-DF766052E142}\1.0\0\win32
    Value : (Default) = C:\Program Files\Microsoft AntiSpyware\gcTCPObjLib.dll
    Parsed : C:\Program Files\Microsoft AntiSpyware\gcTCPObjLib.dll

    CC - 68
    Location: HKEY_CLASSES_ROOT\TypeLib\{31DDE823-839A-4DD2-8D96-DF766052E142}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Microsoft AntiSpyware
    Parsed : C:\Program Files\Microsoft AntiSpyware

    CC - 69
    Location: HKEY_CLASSES_ROOT\TypeLib\{390CE9E4-C4A0-11D4-8A92-0090271D4F88}\1.0\0\win32
    Value : (Default) = C:\Program Files\Yahoo!\Messenger\ycrwin32.dll
    Parsed : C:\Program Files\Yahoo!\Messenger\ycrwin32.dll

    CC - 70
    Location: HKEY_CLASSES_ROOT\TypeLib\{3A76A523-4FBC-487C-A94F-A94EA80E48EF}\1.0\0\win32
    Value : (Default) = C:\WINDOWS\system32\w9seq.dll
    Parsed : C:\WINDOWS\system32\w9seq.dll

    CC - 71
    Location: HKEY_CLASSES_ROOT\TypeLib\{3ABF9055-667E-4FDF-ADDA-2622E8677CBC}\1.0\0\win32
    Value : (Default) = C:\PROGRA~1\NORTON~1\NAVEVENT.DLL
    Parsed : C:\PROGRA~1\NORTON~1\NAVEVENT.DLL

    CC - 72
    Location: HKEY_CLASSES_ROOT\TypeLib\{3ABF9055-667E-4FDF-ADDA-2622E8677CBC}\1.0\HELPDIR
    Value : (Default) = C:\PROGRA~1\NORTON~1\
    Parsed : C:\PROGRA~1\NORTON~1

    CC - 73
    Location: HKEY_CLASSES_ROOT\TypeLib\{3C2E74A0-887E-11D2-B40A-00600831DD76}\1.0\0\win32
    Value : (Default) = C:\PROGRA~1\NORTON~1\NAVLUCBK.dll
    Parsed : C:\PROGRA~1\NORTON~1\NAVLUCBK.dll

    CC - 74
    Location: HKEY_CLASSES_ROOT\TypeLib\{3C2E74A0-887E-11D2-B40A-00600831DD76}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    CC - 75
    Location: HKEY_CLASSES_ROOT\TypeLib\{3C3D7949-0006-4745-B3F6-BED93B98FA9B}\1.0\0\win32
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\ccPwd.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\ccPwd.dll

    CC - 76
    Location: HKEY_CLASSES_ROOT\TypeLib\{3C3D7949-0006-4745-B3F6-BED93B98FA9B}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
    Parsed : C:\Program Files\Common Files\Symantec Shared

    CC - 77
    Location: HKEY_CLASSES_ROOT\TypeLib\{3C878962-A37D-4674-AB76-2746A0E64CE7}\1.0\0\win32
    Value : (Default) = C:\Program Files\BroadJump\Client Foundation\CFD.exe
    Parsed : C:\Program Files\BroadJump\Client Foundation\CFD.exe

    CC - 78
    Location: HKEY_CLASSES_ROOT\TypeLib\{405DE7B2-E7DD-11D2-92C5-00C0F01F77C1}\1.0\0\win32
    Value : (Default) = C:\Program Files\Real\RealOne Player\rpau3260.dll
    Parsed : C:\Program Files\Real\RealOne Player\rpau3260.dll

    CC - 79
    Location: HKEY_CLASSES_ROOT\TypeLib\{405DE7B2-E7DD-11D2-92C5-00C0F01F77C1}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Real\RealOne Player\
    Parsed : C:\Program Files\Real\RealOne Player

    CC - 80
    Location: HKEY_CLASSES_ROOT\TypeLib\{41695A81-6414-11D4-8FB3-00D0B7730277}\1.0\0\win32
    Value : (Default) = C:\Program Files\Yahoo!\Messenger\asw.dll
    Parsed : C:\Program Files\Yahoo!\Messenger\asw.dll

    CC - 81
    Location: HKEY_CLASSES_ROOT\TypeLib\{41949BA1-98CB-4D6F-B27B-4DA67A8B96A5}\1.0\0\win32
    Value : (Default) = C:\Program Files\Microsoft AntiSpyware\gcASThreatAudit.dll
    Parsed : C:\Program Files\Microsoft AntiSpyware\gcASThreatAudit.dll

    CC - 82
    Location: HKEY_CLASSES_ROOT\TypeLib\{41949BA1-98CB-4D6F-B27B-4DA67A8B96A5}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Microsoft AntiSpyware
    Parsed : C:\Program Files\Microsoft AntiSpyware

    CC - 83
    Location: HKEY_CLASSES_ROOT\TypeLib\{45A036EA-835E-4678-A5AC-1D117F555C06}\1.0\0\win32
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\SymUIAx2.ocx
    Parsed : C:\Program Files\Common Files\Symantec Shared\SymUIAx2.ocx

    CC - 84
    Location: HKEY_CLASSES_ROOT\TypeLib\{45A036EA-835E-4678-A5AC-1D117F555C06}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
    Parsed : C:\Program Files\Common Files\Symantec Shared

    CC - 85
    Location: HKEY_CLASSES_ROOT\TypeLib\{47E5F2FC-9048-4D04-9A44-691584BE78A8}\1.0\0\win32
    Value : (Default) = C:\Program Files\Microsoft AntiSpyware\gcASPrivacyLib.dll
    Parsed : C:\Program Files\Microsoft AntiSpyware\gcASPrivacyLib.dll

    CC - 86
    Location: HKEY_CLASSES_ROOT\TypeLib\{47E5F2FC-9048-4D04-9A44-691584BE78A8}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Microsoft AntiSpyware
    Parsed : C:\Program Files\Microsoft AntiSpyware

    CC - 87
    Location: HKEY_CLASSES_ROOT\TypeLib\{4D26B19F-60BD-43DB-BC69-6B5A67BA8B71}\1.0\0\win32
    Value : (Default) = C:\Program Files\Norton AntiVirus\IWP\fwUI.dll
    Parsed : C:\Program Files\Norton AntiVirus\IWP\fwUI.dll

    CC - 88
    Location: HKEY_CLASSES_ROOT\TypeLib\{4D26B19F-60BD-43DB-BC69-6B5A67BA8B71}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Norton AntiVirus\IWP\fwUI.dll
    Parsed : C:\Program Files\Norton AntiVirus\IWP\fwUI.dll

    CC - 89
    Location: HKEY_CLASSES_ROOT\TypeLib\{4E5A5CBD-2CE8-4085-B515-A20137D70D3D}\1.0\0\win32
    Value : (Default) = C:\Program Files\Norton AntiVirus\IWP\ACDisp.dll
    Parsed : C:\Program Files\Norton AntiVirus\IWP\ACDisp.dll

    CC - 90
    Location: HKEY_CLASSES_ROOT\TypeLib\{4EE12B71-AA5E-45EC-8666-2DB3AD3FDF44}\1.0\0\win32
    Value : (Default) = C:\Program Files\YourSiteBar\ysb.dll
    Parsed : C:\Program Files\YourSiteBar\ysb.dll

    CC - 91
    Location: HKEY_CLASSES_ROOT\TypeLib\{4EE12B71-AA5E-45EC-8666-2DB3AD3FDF44}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\YourSiteBar\
    Parsed : C:\Program Files\YourSiteBar

    CC - 92
    Location: HKEY_CLASSES_ROOT\TypeLib\{52D761FC-F7A2-4CF1-AEA9-B1746E2A2B5C}\1.0\0\win32
    Value : (Default) = C:\Program Files\Microsoft AntiSpyware\gcASSoapLib.dll
    Parsed : C:\Program Files\Microsoft AntiSpyware\gcASSoapLib.dll

    CC - 93
    Location: HKEY_CLASSES_ROOT\TypeLib\{52D761FC-F7A2-4CF1-AEA9-B1746E2A2B5C}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Microsoft AntiSpyware
    Parsed : C:\Program Files\Microsoft AntiSpyware

    CC - 94
    Location: HKEY_CLASSES_ROOT\TypeLib\{52F2F122-2BC5-11D2-8FB7-000000000000}\1.0\0\win32
    Value : (Default) = C:\Program Files\Adobe\Photoshop CS\ImageReady.exe
    Parsed : C:\Program Files\Adobe\Photoshop CS\ImageReady.exe

    CC - 95
    Location: HKEY_CLASSES_ROOT\TypeLib\{54635C92-DFAF-4A99-8802-92FB068A6154}\1.0\0\win32
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    Parsed : C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    CC - 96
    Location: HKEY_CLASSES_ROOT\TypeLib\{54635C92-DFAF-4A99-8802-92FB068A6154}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\CCPD-LC\
    Parsed : C:\Program Files\Common Files\Symantec Shared\CCPD-LC

    CC - 97
    Location: HKEY_CLASSES_ROOT\TypeLib\{54B0DF71-97D6-493C-834D-99FC9E19D612}\1.0\0\win32
    Value : (Default) = C:\Program Files\Norton AntiVirus\IWP\ISWrap.dll
    Parsed : C:\Program Files\Norton AntiVirus\IWP\ISWrap.dll

    CC - 98
    Location: HKEY_CLASSES_ROOT\TypeLib\{54CC4A82-E256-4AB1-BA85-F8FF36619969}\1.0\0\win32
    Value : (Default) = C:\PROGRA~1\NORTON~1\NAVSTATS.dll
    Parsed : C:\PROGRA~1\NORTON~1\NAVSTATS.dll

    CC - 99
    Location: HKEY_CLASSES_ROOT\TypeLib\{54CC4A82-E256-4AB1-BA85-F8FF36619969}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    CC - 100
    Location: HKEY_CLASSES_ROOT\TypeLib\{56EBB89D-BB5A-4408-BA3F-04F68EB28690}\1.0\0\win32
    Value : (Default) = C:\Program Files\Norton AntiVirus\IWP\ISLuCbk.dll
    Parsed : C:\Program Files\Norton AntiVirus\IWP\ISLuCbk.dll

    CC - 101
    Location: HKEY_CLASSES_ROOT\TypeLib\{5830698F-7FC0-40CD-A453-9A0CAFDF3A64}\1.0\0\win32
    Value : (Default) = C:\Program Files\Altnet\Download Manager\adm.exe
    Parsed : C:\Program Files\Altnet\Download Manager\adm.exe

    CC - 102
    Location: HKEY_CLASSES_ROOT\TypeLib\{5830698F-7FC0-40CD-A453-9A0CAFDF3A64}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Altnet\Download Manager\
    Parsed : C:\Program Files\Altnet\Download Manager

    CC - 103
    Location: HKEY_CLASSES_ROOT\TypeLib\{586C6565-AEDF-4837-A1B2-9E98EB4BD8AD}\1.0\0\win32
    Value : (Default) = C:\Program Files\Norton AntiVirus\NAVAPSCR.dll
    Parsed : C:\Program Files\Norton AntiVirus\NAVAPSCR.dll

    CC - 104
    Location: HKEY_CLASSES_ROOT\TypeLib\{586C6565-AEDF-4837-A1B2-9E98EB4BD8AD}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    CC - 105
    Location: HKEY_CLASSES_ROOT\TypeLib\{58C72A18-DF21-49BC-B0D6-2EDE23281506}\1.0\0\win32
    Value : (Default) = C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\SymIDSlu.dll
    Parsed : C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\SymIDSlu.dll

    CC - 106
    Location: HKEY_CLASSES_ROOT\TypeLib\{58C72A18-DF21-49BC-B0D6-2EDE23281506}\1.0\HELPDIR
    Value : (Default) = C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\
    Parsed : C:\PROGRA~1\COMMON~1\SYMANT~1\IDS

    CC - 107
    Location: HKEY_CLASSES_ROOT\TypeLib\{60681DC5-21B2-4264-B1F1-E1289819E023}\1.0\0\win32
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    Parsed : C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    CC - 108
    Location: HKEY_CLASSES_ROOT\TypeLib\{60681DC5-21B2-4264-B1F1-E1289819E023}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
    Parsed : C:\Program Files\Common Files\Symantec Shared

    CC - 109
    Location: HKEY_CLASSES_ROOT\TypeLib\{662ADDE9-5AB3-4A01-8015-FB61D18B0067}\1.0\0\win32
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    Parsed : C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

    CC - 110
    Location: HKEY_CLASSES_ROOT\TypeLib\{662ADDE9-5AB3-4A01-8015-FB61D18B0067}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\SPBBC\
    Parsed : C:\Program Files\Common Files\Symantec Shared\SPBBC

    CC - 111
    Location: HKEY_CLASSES_ROOT\TypeLib\{676F6D1D-C559-42A9-860B-27C1477B7179}\1.0\0\win32
    Value : (Default) = C:\Program Files\Altnet\Download Manager\adm25.dll
    Parsed : C:\Program Files\Altnet\Download Manager\adm25.dll

    CC - 112
    Location: HKEY_CLASSES_ROOT\TypeLib\{676F6D1D-C559-42A9-860B-27C1477B7179}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Altnet\Download Manager\
    Parsed : C:\Program Files\Altnet\Download Manager

    CC - 113
    Location: HKEY_CLASSES_ROOT\TypeLib\{68786388-3E7A-4E69-BDB4-814A1EEB1C0D}\1.0\0\win32
    Value : (Default) = C:\Program Files\Norton AntiVirus\OPScan.exe
    Parsed : C:\Program Files\Norton AntiVirus\OPScan.exe

    CC - 114
    Location: HKEY_CLASSES_ROOT\TypeLib\{68786388-3E7A-4E69-BDB4-814A1EEB1C0D}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    CC - 115
    Location: HKEY_CLASSES_ROOT\TypeLib\{6B64D109-9674-4D70-8E63-EE0F9A7C9436}\1.0\0\win32
    Value : (Default) = C:\Program Files\Microsoft AntiSpyware\gcAntiSpywareLibrary.dll
    Parsed : C:\Program Files\Microsoft AntiSpyware\gcAntiSpywareLibrary.dll

    CC - 116
    Location: HKEY_CLASSES_ROOT\TypeLib\{6B64D109-9674-4D70-8E63-EE0F9A7C9436}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Microsoft AntiSpyware
    Parsed : C:\Program Files\Microsoft AntiSpyware

    CC - 117
    Location: HKEY_CLASSES_ROOT\TypeLib\{6E2295DE-2B0E-4ED8-91A8-D9E9A514A027}\1.0\0\win32
    Value : (Default) = C:\Program Files\Norton AntiVirus\IWP\niscmnht.dll
    Parsed : C:\Program Files\Norton AntiVirus\IWP\niscmnht.dll

    CC - 118
    Location: HKEY_CLASSES_ROOT\TypeLib\{7479B280-A309-415C-A351-05483C51F75F}\1.0\0\win32
    Value : (Default) = C:\Program Files\Microsoft AntiSpyware\gcSoftwareUpdateLib.dll
    Parsed : C:\Program Files\Microsoft AntiSpyware\gcSoftwareUpdateLib.dll

    CC - 119
    Location: HKEY_CLASSES_ROOT\TypeLib\{7479B280-A309-415C-A351-05483C51F75F}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Microsoft AntiSpyware
    Parsed : C:\Program Files\Microsoft AntiSpyware

    CC - 120
    Location: HKEY_CLASSES_ROOT\TypeLib\{77F05869-E2D3-430E-8364-4D2247DECDE4}\1.0\0\win32
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\CfgWiz.tlb
    Parsed : C:\Program Files\Common Files\Symantec Shared\CfgWiz.tlb

    CC - 121
    Location: HKEY_CLASSES_ROOT\TypeLib\{77F05869-E2D3-430E-8364-4D2247DECDE4}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
    Parsed : C:\Program Files\Common Files\Symantec Shared

    CC - 122
    Location: HKEY_CLASSES_ROOT\TypeLib\{7C1B9D8B-2B5F-41B2-95F7-DE2C5BD594EC}\1.0\0\win32
    Value : (Default) = C:\PROGRA~1\NORTON~1\NAVTasks.dll
    Parsed : C:\PROGRA~1\NORTON~1\NAVTasks.dll

    CC - 123
    Location: HKEY_CLASSES_ROOT\TypeLib\{7C1B9D8B-2B5F-41B2-95F7-DE2C5BD594EC}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    CC - 124
    Location: HKEY_CLASSES_ROOT\TypeLib\{822E40E5-8012-40F0-AB0E-EC7B0DFF76BC}\1.0\0\win32
    Value : (Default) = C:\Program Files\Norton AntiVirus\ccIMScan.dll
    Parsed : C:\Program Files\Norton AntiVirus\ccIMScan.dll

    CC - 125
    Location: HKEY_CLASSES_ROOT\TypeLib\{822E40E5-8012-40F0-AB0E-EC7B0DFF76BC}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    CC - 126
    Location: HKEY_CLASSES_ROOT\TypeLib\{838E8E82-F171-4006-A930-9D57949BC2AC}\1.0\0\win32
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\LiveReg\LRRES.DLL
    Parsed : C:\Program Files\Common Files\Symantec Shared\LiveReg\LRRES.DLL

    CC - 127
    Location: HKEY_CLASSES_ROOT\TypeLib\{838E8E82-F171-4006-A930-9D57949BC2AC}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\LiveReg\
    Parsed : C:\Program Files\Common Files\Symantec Shared\LiveReg

    CC - 128
    Location: HKEY_CLASSES_ROOT\TypeLib\{84699B2B-F985-4C87-ADB8-6FDCAD52ED22}\1.0\0\win32
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\LiveReg\LSCTRL.DLL
    Parsed : C:\Program Files\Common Files\Symantec Shared\LiveReg\LSCTRL.DLL

    CC - 129
    Location: HKEY_CLASSES_ROOT\TypeLib\{84699B2B-F985-4C87-ADB8-6FDCAD52ED22}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\LiveReg\
    Parsed : C:\Program Files\Common Files\Symantec Shared\LiveReg

    CC - 130
    Location: HKEY_CLASSES_ROOT\TypeLib\{852C26A8-5C40-4EFB-9D81-096B21BF9D81}\1.0\0\win32
    Value : (Default) = C:\PROGRA~1\NORTON~1\DefAlert.dll
    Parsed : C:\PROGRA~1\NORTON~1\DefAlert.dll

    CC - 131
    Location: HKEY_CLASSES_ROOT\TypeLib\{852C26A8-5C40-4EFB-9D81-096B21BF9D81}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    CC - 132
    Location: HKEY_CLASSES_ROOT\TypeLib\{86073239-029C-458B-8546-383694B94B7D}\1.0\0\win32
    Value : (Default) = C:\Program Files\Microsoft AntiSpyware\gcASPrivacyLib.dll
    Parsed : C:\Program Files\Microsoft AntiSpyware\gcASPrivacyLib.dll

    CC - 133
    Location: HKEY_CLASSES_ROOT\TypeLib\{86073239-029C-458B-8546-383694B94B7D}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Microsoft AntiSpyware
    Parsed : C:\Program Files\Microsoft AntiSpyware

    CC - 134
    Location: HKEY_CLASSES_ROOT\TypeLib\{88734681-FCB2-11D2-B9D2-00C04FAC114C}\1.0\0\win32
    Value : (Default) = C:\PROGRA~1\NORTON~1\NAVUI.dll
    Parsed : C:\PROGRA~1\NORTON~1\NAVUI.dll

    CC - 135
    Location: HKEY_CLASSES_ROOT\TypeLib\{88734681-FCB2-11D2-B9D2-00C04FAC114C}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    CC - 136
    Location: HKEY_CLASSES_ROOT\TypeLib\{89A10D64-83BF-41A4-86A3-7AAF1F8F3D1B}\1.0\0\win32
    Value : (Default) = C:\Program Files\ISTbar\istbar.dll
    Parsed : C:\Program Files\ISTbar\istbar.dll

    CC - 137
    Location: HKEY_CLASSES_ROOT\TypeLib\{89A10D64-83BF-41A4-86A3-7AAF1F8F3D1B}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\ISTbar\
    Parsed : C:\Program Files\ISTbar

    CC - 138
    Location: HKEY_CLASSES_ROOT\TypeLib\{8A934650-3A3D-11D3-A2D4-005004184DF1}\1.0\0\win32
    Value : (Default) = C:\PROGRA~1\NORTON~1\AboutPlg.dll
    Parsed : C:\PROGRA~1\NORTON~1\AboutPlg.dll

    CC - 139
    Location: HKEY_CLASSES_ROOT\TypeLib\{8A934650-3A3D-11D3-A2D4-005004184DF1}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    CC - 140
    Location: HKEY_CLASSES_ROOT\TypeLib\{903F7FB7-9888-4A4A-B1D5-2A13A7276589}\2.0\0\win32
    Value : (Default) = C:\Program Files\Common Files\ScanSoft Shared\ScnWizC.dll
    Parsed : C:\Program Files\Common Files\ScanSoft Shared\ScnWizC.dll

    CC - 141
    Location: HKEY_CLASSES_ROOT\TypeLib\{903F7FB7-9888-4A4A-B1D5-2A13A7276589}\2.0\HELPDIR
    Value : (Default) = C:\Program Files\Common Files\ScanSoft Shared\
    Parsed : C:\Program Files\Common Files\ScanSoft Shared

    CC - 142
    Location: HKEY_CLASSES_ROOT\TypeLib\{9275E229-718E-4A2D-8EE0-10C5AA524C22}\1.0\0\win32
    Value : (Default) = C:\PROGRA~1\NORTON~1\NAVLnch.dll
    Parsed : C:\PROGRA~1\NORTON~1\NAVLnch.dll

    CC - 143
    Location: HKEY_CLASSES_ROOT\TypeLib\{9275E229-718E-4A2D-8EE0-10C5AA524C22}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    CC - 144
    Location: HKEY_CLASSES_ROOT\TypeLib\{941F23D1-BD56-4F90-B99F-134D55D86053}\1.0\0\win32
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    Parsed : C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    CC - 145
    Location: HKEY_CLASSES_ROOT\TypeLib\{941F23D1-BD56-4F90-B99F-134D55D86053}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
    Parsed : C:\Program Files\Common Files\Symantec Shared

    CC - 146
    Location: HKEY_CLASSES_ROOT\TypeLib\{9B422879-A1BF-44C4-AC83-B4308A1B2272}\1.0\0\win32
    Value : (Default) = C:\PROGRA~1\NORTON~1\IWP\IWPLUCbk.dll
    Parsed : C:\PROGRA~1\NORTON~1\IWP\IWPLUCbk.dll

    CC - 147
    Location: HKEY_CLASSES_ROOT\TypeLib\{9B422879-A1BF-44C4-AC83-B4308A1B2272}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Norton AntiVirus\IWP\
    Parsed : C:\Program Files\Norton AntiVirus\IWP

    CC - 148
    Location: HKEY_CLASSES_ROOT\TypeLib\{9E93C96F-CF0D-43F6-8BA8-B807A3370712}\1.5\0\win32
    Value : (Default) = C:\Program Files\iTunes\iTunes.exe
    Parsed : C:\Program Files\iTunes\iTunes.exe

    CC - 149
    Location: HKEY_CLASSES_ROOT\TypeLib\{9E93C96F-CF0D-43F6-8BA8-B807A3370712}\1.5\HELPDIR
    Value : (Default) = C:\Program Files\iTunes\
    Parsed : C:\Program Files\iTunes

    CC - 150
    Location: HKEY_CLASSES_ROOT\TypeLib\{9F3B84DC-3631-4BCE-90E9-041A6198A2FA}\1.0\0\win32
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    Parsed : C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    CC - 151
    Location: HKEY_CLASSES_ROOT\TypeLib\{9F3B84DC-3631-4BCE-90E9-041A6198A2FA}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
    Parsed : C:\Program Files\Common Files\Symantec Shared

    CC - 152
    Location: HKEY_CLASSES_ROOT\TypeLib\{A67004E0-8362-42F9-B186-88706C346DD9}\1.0\0\win32
    Value : (Default) = C:\Program Files\Real\RealOne Player\rpplugins\ierpplug.dll
    Parsed : C:\Program Files\Real\RealOne Player\rpplugins\ierpplug.dll

    CC - 153
    Location: HKEY_CLASSES_ROOT\TypeLib\{A67004E0-8362-42F9-B186-88706C346DD9}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Real\RealOne Player\rpplugins\
    Parsed : C:\Program Files\Real\RealOne Player\rpplugins

    CC - 154
    Location: HKEY_CLASSES_ROOT\TypeLib\{A7336B62-3374-4D2F-8C3F-946D6A9DE725}\1.0\0\win32
    Value : (Default) = C:\Program Files\Norton AntiVirus\IWP\HNetCore.dll
    Parsed : C:\Program Files\Norton AntiVirus\IWP\HNetCore.dll

    CC - 155
    Location: HKEY_CLASSES_ROOT\TypeLib\{ABA89334-36F7-4263-987C-941FF0C3E105}\1.0\0\win32
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\ccWebWnd.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\ccWebWnd.dll

    CC - 156
    Location: HKEY_CLASSES_ROOT\TypeLib\{ABA89334-36F7-4263-987C-941FF0C3E105}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
    Parsed : C:\Program Files\Common Files\Symantec Shared

    CC - 157
    Location: HKEY_CLASSES_ROOT\TypeLib\{B0BD3CBA-3FB8-4A77-B0BE-D3E9E2BB6FBD}\1.0\0\win32
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\SymBbaAx.ocx
    Parsed : C:\Program Files\Common Files\Symantec Shared\SymBbaAx.ocx

    CC - 158
    Location: HKEY_CLASSES_ROOT\TypeLib\{B0BD3CBA-3FB8-4A77-B0BE-D3E9E2BB6FBD}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
    Parsed : C:\Program Files\Common Files\Symantec Shared

    CC - 159
    Location: HKEY_CLASSES_ROOT\TypeLib\{B53DE72C-31E1-49C7-97FD-D22CAA89B27E}\1.0\0\win32
    Value : (Default) = C:\Program Files\Microsoft AntiSpyware\gcSoftwareUpdateLib.dll
    Parsed : C:\Program Files\Microsoft AntiSpyware\gcSoftwareUpdateLib.dll

    CC - 160
    Location: HKEY_CLASSES_ROOT\TypeLib\{B53DE72C-31E1-49C7-97FD-D22CAA89B27E}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Microsoft AntiSpyware
    Parsed : C:\Program Files\Microsoft AntiSpyware

    CC - 161
    Location: HKEY_CLASSES_ROOT\TypeLib\{BE2DF74C-BDC0-4411-9641-4B811B82A3AF}\1.0\0\win32
    Value : (Default) = C:\PROGRA~1\NORTON~1\NAVComUI.dll
    Parsed : C:\PROGRA~1\NORTON~1\NAVComUI.dll

    CC - 162
    Location: HKEY_CLASSES_ROOT\TypeLib\{BFC07EE1-0EFF-11D4-AE9A-0000E88EB84F}\1.0\0\win32
    Value : (Default) = C:\Program Files\CyberLink\PowerDVD\AppBarCom.dll
    Parsed : C:\Program Files\CyberLink\PowerDVD\AppBarCom.dll

    CC - 163
    Location: HKEY_CLASSES_ROOT\TypeLib\{BFC07EE1-0EFF-11D4-AE9A-0000E88EB84F}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\CyberLink\PowerDVD\
    Parsed : C:\Program Files\CyberLink\PowerDVD

    CC - 164
    Location: HKEY_CLASSES_ROOT\TypeLib\{BFF4F684-677E-44F4-8C74-1D575C950E10}\1.0\0\win32
    Value : (Default) = C:\Program Files\Altnet\Download Manager\adm4.dll
    Parsed : C:\Program Files\Altnet\Download Manager\adm4.dll

    CC - 165
    Location: HKEY_CLASSES_ROOT\TypeLib\{BFF4F684-677E-44F4-8C74-1D575C950E10}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Altnet\Download Manager\
    Parsed : C:\Program Files\Altnet\Download Manager

    CC - 166
    Location: HKEY_CLASSES_ROOT\TypeLib\{C02ABA7B-5269-4737-8DAE-3A453E6C9CD3}\1.0\0\win32
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\LiveReg\LRCTRL.DLL
    Parsed : C:\Program Files\Common Files\Symantec Shared\LiveReg\LRCTRL.DLL

    CC - 167
    Location: HKEY_CLASSES_ROOT\TypeLib\{C02ABA7B-5269-4737-8DAE-3A453E6C9CD3}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\LiveReg\
    Parsed : C:\Program Files\Common Files\Symantec Shared\LiveReg

    CC - 168
    Location: HKEY_CLASSES_ROOT\TypeLib\{C2FC361F-2281-11D2-8E21-10B404C10000}\1.b\0\win32
    Value : (Default) = C:\WINDOWS\System32\cNewMenu.dll
    Parsed : C:\WINDOWS\System32\cNewMenu.dll

    CC - 169
    Location: HKEY_CLASSES_ROOT\TypeLib\{C39962BA-5DDC-408D-9367-FEE637EE54D6}\1.0\0\win32
    Value : (Default) = C:\Program Files\Microsoft AntiSpyware\gcASThreatAudit.dll
    Parsed : C:\Program Files\Microsoft AntiSpyware\gcASThreatAudit.dll

    CC - 170
    Location: HKEY_CLASSES_ROOT\TypeLib\{C39962BA-5DDC-408D-9367-FEE637EE54D6}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Microsoft AntiSpyware
    Parsed : C:\Program Files\Microsoft AntiSpyware

    CC - 171
    Location: HKEY_CLASSES_ROOT\TypeLib\{C3A4D68F-FD37-4617-9A58-D9BD1EE0D8D1}\1.0\0\win32
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\Security Center\SymSCWb.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Security Center\SymSCWb.dll

    CC - 172
    Location: HKEY_CLASSES_ROOT\TypeLib\{C3A4D68F-FD37-4617-9A58-D9BD1EE0D8D1}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\Security Center\
    Parsed : C:\Program Files\Common Files\Symantec Shared\Security Center

    CC - 173
    Location: HKEY_CLASSES_ROOT\TypeLib\{C40049E7-5154-40E3-83B5-A94A89A29890}\1.0\0\win32
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll

    CC - 174
    Location: HKEY_CLASSES_ROOT\TypeLib\{C40049E7-5154-40E3-83B5-A94A89A29890}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
    Parsed : C:\Program Files\Common Files\Symantec Shared

    CC - 175
    Location: HKEY_CLASSES_ROOT\TypeLib\{C62B7AAE-194F-475C-AA49-DE7F12E6FC06}\1.0\0\win32
    Value : (Default) = C:\Program Files\Microsoft AntiSpyware\gcTCPObjLib.dll
    Parsed : C:\Program Files\Microsoft AntiSpyware\gcTCPObjLib.dll

    CC - 176
    Location: HKEY_CLASSES_ROOT\TypeLib\{C62B7AAE-194F-475C-AA49-DE7F12E6FC06}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Microsoft AntiSpyware
    Parsed : C:\Program Files\Microsoft AntiSpyware

    CC - 177
    Location: HKEY_CLASSES_ROOT\TypeLib\{C9C05A42-D571-4B3C-8F11-D6D6A81C90EB}\1.0\0\win32
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCEvt.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCEvt.dll

    CC - 178
    Location: HKEY_CLASSES_ROOT\TypeLib\{C9C05A42-D571-4B3C-8F11-D6D6A81C90EB}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\SPBBC\
    Parsed : C:\Program Files\Common Files\Symantec Shared\SPBBC

    CC - 179
    Location: HKEY_CLASSES_ROOT\TypeLib\{CC257918-F435-4A33-8231-2B8195990CCA}\1.0\0\win32
    Value : (Default) = C:\WINDOWS\Downloaded Program Files\YSBactivex.dll
    Parsed : C:\WINDOWS\Downloaded Program Files\YSBactivex.dll

    CC - 180
    Location: HKEY_CLASSES_ROOT\TypeLib\{CE949EEF-0C75-4BCC-BF95-8173D44AEC6B}\1.0\0\win32
    Value : (Default) = C:\Program Files\Microsoft AntiSpyware\gcASSoapLib.dll
    Parsed : C:\Program Files\Microsoft AntiSpyware\gcASSoapLib.dll

    CC - 181
    Location: HKEY_CLASSES_ROOT\TypeLib\{CE949EEF-0C75-4BCC-BF95-8173D44AEC6B}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Microsoft AntiSpyware
    Parsed : C:\Program Files\Microsoft AntiSpyware

    CC - 182
    Location: HKEY_CLASSES_ROOT\TypeLib\{CEACE91F-3F71-4A8C-B952-63716B2BC026}\1.0\0\win32
    Value : (Default) = C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    Parsed : C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe

    CC - 183
    Location: HKEY_CLASSES_ROOT\TypeLib\{CEACE91F-3F71-4A8C-B952-63716B2BC026}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Microsoft AntiSpyware
    Parsed : C:\Program Files\Microsoft AntiSpyware

    CC - 184
    Location: HKEY_CLASSES_ROOT\TypeLib\{CF34D2A7-C8C6-4B4E-8752-F63C2BDF1CF0}\1.0\0\win32
    Value : (Default) = C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mlfoshim.dll
    Parsed : C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mlfoshim.dll

    CC - 185
    Location: HKEY_CLASSES_ROOT\TypeLib\{CF34D2A7-C8C6-4B4E-8752-F63C2BDF1CF0}\1.0\HELPDIR
    Value : (Default) = C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\
    Parsed : C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1

    CC - 186
    Location: HKEY_CLASSES_ROOT\TypeLib\{D0FB5093-C2F0-4280-AAC9-3C35C6980FD8}\1.0\0
    Value : (Default) = C:\Program Files\Norton AntiVirus\NAVError.dll
    Parsed : C:\Program Files\Norton AntiVirus\NAVError.dll

    CC - 187
    Location: HKEY_CLASSES_ROOT\TypeLib\{D0FB5093-C2F0-4280-AAC9-3C35C6980FD8}\1.0\0\win32
    Value : (Default) = C:\Program Files\Norton AntiVirus\NAVError.dll
    Parsed : C:\Program Files\Norton AntiVirus\NAVError.dll

    CC - 188
    Location: HKEY_CLASSES_ROOT\TypeLib\{D0FB5093-C2F0-4280-AAC9-3C35C6980FD8}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    CC - 189
    Location: HKEY_CLASSES_ROOT\TypeLib\{D323F395-AA30-4DF9-A379-2F3F4819AB00}\1.0\0\win32
    Value : (Default) = C:\PROGRA~1\NORTON~1\NAVOpts.dll
    Parsed : C:\PROGRA~1\NORTON~1\NAVOpts.dll

    CC - 190
    Location: HKEY_CLASSES_ROOT\TypeLib\{D323F395-AA30-4DF9-A379-2F3F4819AB00}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    CC - 191
    Location: HKEY_CLASSES_ROOT\TypeLib\{D935DFEC-4546-4119-94D5-91807C7BB363}\1.0\0\win32
    Value : (Default) = C:\Program Files\Norton AntiVirus\NAVCfgWz.dll
    Parsed : C:\Program Files\Norton AntiVirus\NAVCfgWz.dll

    CC - 192
    Location: HKEY_CLASSES_ROOT\TypeLib\{D935DFEC-4546-4119-94D5-91807C7BB363}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    CC - 193
    Location: HKEY_CLASSES_ROOT\TypeLib\{DCB43485-19FB-4D6D-BB3D-73C7F48D5F00}\1.0\0\win32
    Value : (Default) = C:\Program Files\Messenger\rtcimsp.dll
    Parsed : C:\Program Files\Messenger\rtcimsp.dll

    CC - 194
    Location: HKEY_CLASSES_ROOT\TypeLib\{DE1F7EE0-1851-11D3-939E-0004AC1ABE1F}\1.0\0\win32
    Value : (Default) = C:\Program Files\Norton AntiVirus\OfficeAV.dll
    Parsed : C:\Program Files\Norton AntiVirus\OfficeAV.dll

    CC - 195
    Location: HKEY_CLASSES_ROOT\TypeLib\{DE1F7EE0-1851-11D3-939E-0004AC1ABE1F}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    CC - 196
    Location: HKEY_CLASSES_ROOT\TypeLib\{EB54C4A8-F9BE-429F-AA4F-F1FA39EA3537}\1.0\0\win32
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\ccProSub.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\ccProSub.dll

    CC - 197
    Location: HKEY_CLASSES_ROOT\TypeLib\{EB54C4A8-F9BE-429F-AA4F-F1FA39EA3537}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
    Parsed : C:\Program Files\Common Files\Symantec Shared

    CC - 198
    Location: HKEY_CLASSES_ROOT\TypeLib\{EDD3B3E9-3FFD-4836-A6DE-D4A9C473A971}\1.0\0\win32
    Value : (Default) = C:\Program Files\Kazaa\Topsearch.dll
    Parsed : C:\Program Files\Kazaa\Topsearch.dll

    CC - 199
    Location: HKEY_CLASSES_ROOT\TypeLib\{EDD3B3E9-3FFD-4836-A6DE-D4A9C473A971}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Kazaa\
    Parsed : C:\Program Files\Kazaa

    CC - 200
    Location: HKEY_CLASSES_ROOT\TypeLib\{EF070A21-6AD8-470A-BA49-4AF45E07B55F}\1.0\0\win32
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\ccLogin.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\ccLogin.dll

    CC - 201
    Location: HKEY_CLASSES_ROOT\TypeLib\{EF070A21-6AD8-470A-BA49-4AF45E07B55F}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\
    Parsed : C:\Program Files\Common Files\Symantec Shared

    CC - 202
    Location: HKEY_CLASSES_ROOT\TypeLib\{F743EA98-42BD-4E2C-A221-3F7B646748C7}\1.0\0\win32
    Value : (Default) = C:\Program Files\Norton AntiVirus\navapsvc.exe
    Parsed : C:\Program Files\Norton AntiVirus\navapsvc.exe

    CC - 203
    Location: HKEY_CLASSES_ROOT\TypeLib\{F743EA98-42BD-4E2C-A221-3F7B646748C7}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    CC - 204
    Location: HKEY_CLASSES_ROOT\TypeLib\{FF2802B8-8E99-4518-B350-DF088BD26CE7}\1.0\0\win32
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\LiveReg\LSPLUGIN.DLL
    Parsed : C:\Program Files\Common Files\Symantec Shared\LiveReg\LSPLUGIN.DLL

    CC - 205
    Location: HKEY_CLASSES_ROOT\TypeLib\{FF2802B8-8E99-4518-B350-DF088BD26CE7}\1.0\HELPDIR
    Value : (Default) = C:\Program Files\Common Files\Symantec Shared\LiveReg\
    Parsed : C:\Program Files\Common Files\Symantec Shared\LiveReg

    DEEP - 206
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Identities\{7A9B0D75-49A0-4F63-A23C-A0DD4E68E543}\Software\Microsoft\Outlook Express\5.0
    Value : Store Root = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Identities\{7A9B0D75-49A0-4F63-A23C-A0DD4E68E543}\Microsoft\Outlook Express\
    Parsed : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Identities\{7A9B0D75-49A0-4F63-A23C-A0DD4E68E543}\Microsoft\Outlook Express

    DEEP - 207
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Disney\DIGStream
    Value : CachePath = C:\Documents and Settings\All Users\Application Data\DIGStream
    Parsed : C:\Documents and Settings\All Users\Application Data\DIGStream

    DEEP - 208
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\GIANTCompany\AntiSpyware\Alerts\DE17EE69-5155-42EE-A618-968589
    Value : FilePath = C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hnhufu.exe
    Parsed : C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hnhufu.exe

    DEEP - 209
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Macromedia\Shockwave 10\location\coreplayerxtras
    Value : (Default) = C:\WINDOWS\system32\Macromed\Shockwave 10\xtras\
    Parsed : C:\WINDOWS\system32\Macromed\Shockwave 10\xtras

    DEEP - 210
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Internet Explorer\Default HTML Editor\shell\edit\command
    Value : (Default) = C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE
    Parsed : C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE

    DEEP - 211
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\MediaPlayer\Setup\CreatedLinks
    Value : Shortcut0 = C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk
    Parsed : C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk

    DEEP - 212
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\MediaPlayer\Setup\CreatedLinks
    Value : Shortcut1 = C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
    Parsed : C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk

    DEEP - 213
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012006032720060403
    Value : CachePath = C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006032720060403\
    Parsed : C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006032720060403

    DEEP - 214
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012006040320060410
    Value : CachePath = C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006040320060410\
    Parsed : C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006040320060410

    DEEP - 215
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012006041020060417
    Value : CachePath = C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006041020060417\
    Parsed : C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006041020060417

    DEEP - 216
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012006041720060418
    Value : CachePath = C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006041720060418\
    Parsed : C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006041720060418

    DEEP - 217
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Run
    Value : AVG7_Run = C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE
    Parsed : C:\PROGRA~1\Grisoft\AVG7\avgw.exe

    DEEP - 218
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
    Value : C:\Program Files\BroadJump\Client Foundation\CFD.exe = C:\Program Files\BroadJump\Client Foundation\CFD.exe
    Parsed : C:\Program Files\BroadJump\Client Foundation\CFD.exe

    DEEP - 219
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
    Value : C:\Program Files\Microsoft AntiSpyware\gcasServ.exe = C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
    Parsed : C:\Program Files\Microsoft AntiSpyware\gcasServ.exe

    DEEP - 220
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
    Value : C:\Program Files\ScanSoft\OmniPageSE\opware32.exe = C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
    Parsed : C:\Program Files\ScanSoft\OmniPageSE\opware32.exe

    DEEP - 221
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
    Value : C:\Program Files\MSN Toolbar Suite\DS\02.00.0001.1203\en-us\bin\msnlAdmin.exe = C:\Program Files\MSN Toolbar Suite\DS\02.00.0001.1203\en-us\bin\msnlAdmin.exe
    Parsed : C:\Program Files\MSN Toolbar Suite\DS\02.00.0001.1203\en-us\bin\msnlAdmin.exe

    DEEP - 222
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
    Value : C:\Program Files\Microsoft AntiSpyware\gcasServAlert.exe = C:\Program Files\Microsoft AntiSpyware\gcasServAlert.exe
    Parsed : C:\Program Files\Microsoft AntiSpyware\gcasServAlert.exe

    DEEP - 223
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
    Value : C:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareMain.exe = C:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareMain.exe
    Parsed : C:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareMain.exe

    DEEP - 224
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
    Value : C:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareUpdater.exe = C:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareUpdater.exe
    Parsed : C:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareUpdater.exe

    DEEP - 225
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
    Value : C:\Program Files\Microsoft AntiSpyware\gcasSWUpdater.exe = C:\Program Files\Microsoft AntiSpyware\gcasSWUpdater.exe
    Parsed : C:\Program Files\Microsoft AntiSpyware\gcasSWUpdater.exe

    DEEP - 226
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
    Value : C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe = C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe
    Parsed : C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe

    DEEP - 227
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
    Value : C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe = C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe
    Parsed : C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe

    DEEP - 228
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
    Value : C:\Program Files\Common Files\Symantec Shared\ccApp.exe = C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    Parsed : C:\Program Files\Common Files\Symantec Shared\ccApp.exe

    DEEP - 229
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
    Value : C:\PROGRA~1\SYMNET~1\SNDMon.exe = C:\PROGRA~1\SYMNET~1\SNDMon.exe
    Parsed : C:\PROGRA~1\SYMNET~1\SNDMon.exe

    DEEP - 230
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
    Value : C:\PROGRA~1\Grisoft\AVG7\avgcc.exe = C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    Parsed : C:\PROGRA~1\Grisoft\AVG7\avgcc.exe

    DEEP - 231
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
    Value : C:\PROGRA~1\Grisoft\AVG7\avgw.exe = C:\PROGRA~1\Grisoft\AVG7\avgw.exe
    Parsed : C:\PROGRA~1\Grisoft\AVG7\avgw.exe

    DEEP - 232
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
    Value : C:\PROGRA~1\Grisoft\AVG7\avgwb.dat = C:\PROGRA~1\Grisoft\AVG7\avgwb.dat
    Parsed : C:\PROGRA~1\Grisoft\AVG7\avgwb.dat

    DEEP - 233
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
    Value : C:\Program Files\Symantec\LiveUpdate\LUALL.EXE = C:\Program Files\Symantec\LiveUpdate\LUALL.EXE
    Parsed : C:\Program Files\Symantec\LiveUpdate\LUALL.EXE

    DEEP - 234
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
    Value : C:\WINDOWS\system32\slk8x2peu.exe = C:\WINDOWS\system32\slk8x2peu.exe
    Parsed : C:\WINDOWS\system32\slk8x2peu.exe

    DEEP - 235
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
    Value : C:\WINDOWS\system32\nwinmrag.exe = C:\WINDOWS\system32\nwinmrag.exe
    Parsed : C:\WINDOWS\system32\nwinmrag.exe

    DEEP - 236
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
    Value : C:\Program Files\Common Files\Symantec Shared\LiveReg\VCSetup.exe = C:\Program Files\Common Files\Symantec Shared\LiveReg\VCSetup.exe
    Parsed : C:\Program Files\Common Files\Symantec Shared\LiveReg\VCSetup.exe

    DEEP - 237
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
    Value : C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe = C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    Parsed : C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

    DEEP - 238
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
    Value : C:\WINDOWS\Microsoft.NET\Framework\NETFXSBS10.exe = C:\WINDOWS\Microsoft.NET\Framework\NETFXSBS10.exe
    Parsed : C:\WINDOWS\Microsoft.NET\Framework\NETFXSBS10.exe

    DEEP - 239
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
    Value : C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ConfigWizards.exe = C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ConfigWizards.exe
    Parsed : C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ConfigWizards.exe

    DEEP - 240
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
    Value : C:\WINDOWS\system32\lwinrrag.exe = C:\WINDOWS\system32\lwinrrag.exe
    Parsed : C:\WINDOWS\system32\lwinrrag.exe

    DEEP - 241
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000001
    Value : path = C:\Program Files\Zone Labs\ZoneAlarm\security.zap
    Parsed : C:\Program Files\Zone Labs\ZoneAlarm\security.zap

    DEEP - 242
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000002
    Value : path = C:\Program Files\Zone Labs\ZoneAlarm\firewall.zap
    Parsed : C:\Program Files\Zone Labs\ZoneAlarm\firewall.zap

    DEEP - 243
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000004
    Value : path = C:\Program Files\Zone Labs\ZoneAlarm\email.zap
    Parsed : C:\Program Files\Zone Labs\ZoneAlarm\email.zap

    DEEP - 244
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000008
    Value : path = C:\Program Files\Zone Labs\ZoneAlarm\scan.zap
    Parsed : C:\Program Files\Zone Labs\ZoneAlarm\scan.zap

    DEEP - 245
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000010
    Value : path = C:\Program Files\Zone Labs\ZoneAlarm\programs.zap
    Parsed : C:\Program Files\Zone Labs\ZoneAlarm\programs.zap

    DEEP - 246
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000020
    Value : path = C:\Program Files\Zone Labs\ZoneAlarm\imsecure.zap
    Parsed : C:\Program Files\Zone Labs\ZoneAlarm\imsecure.zap

    DEEP - 247
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000040
    Value : path = C:\Program Files\Zone Labs\ZoneAlarm\idlock.zap
    Parsed : C:\Program Files\Zone Labs\ZoneAlarm\idlock.zap

    DEEP - 248
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000080
    Value : path = C:\Program Files\Zone Labs\ZoneAlarm\privacy.zap
    Parsed : C:\Program Files\Zone Labs\ZoneAlarm\privacy.zap

    DEEP - 249
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000100
    Value : path = C:\Program Files\Zone Labs\ZoneAlarm\filter.zap
    Parsed : C:\Program Files\Zone Labs\ZoneAlarm\filter.zap

    DEEP - 250
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000400
    Value : path = C:\Program Files\Zone Labs\ZoneAlarm\alert.zap
    Parsed : C:\Program Files\Zone Labs\ZoneAlarm\alert.zap

    DEEP - 251
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Microsoft\Internet Explorer\Default HTML Editor\shell\edit\command
    Value : (Default) = C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE
    Parsed : C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE

    DEEP - 252
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Microsoft\MediaPlayer\Setup\CreatedLinks
    Value : Shortcut0 = C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk
    Parsed : C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk

    DEEP - 253
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Microsoft\MediaPlayer\Setup\CreatedLinks
    Value : Shortcut1 = C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
    Parsed : C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk

    DEEP - 254
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012006040320060410
    Value : CachePath = C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006040320060410\
    Parsed : C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006040320060410

    DEEP - 255
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Microsoft\Windows\CurrentVersion\Run
    Value : AVG7_Run = C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE
    Parsed : C:\PROGRA~1\Grisoft\AVG7\avgw.exe

    DEEP - 256
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Microsoft\Windows\ShellNoRoam\MUICache
    Value : C:\WINDOWS\system32\slk8x2peu.exe = C:\WINDOWS\system32\slk8x2peu.exe
    Parsed : C:\WINDOWS\system32\slk8x2peu.exe

    DEEP - 257
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Microsoft\Windows\ShellNoRoam\MUICache
    Value : C:\WINDOWS\system32\lwinrrag.exe = C:\WINDOWS\system32\lwinrrag.exe
    Parsed : C:\WINDOWS\system32\lwinrrag.exe

    DEEP - 258
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000001
    Value : path = C:\Program Files\Zone Labs\ZoneAlarm\security.zap
    Parsed : C:\Program Files\Zone Labs\ZoneAlarm\security.zap

    DEEP - 259
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000002
    Value : path = C:\Program Files\Zone Labs\ZoneAlarm\firewall.zap
    Parsed : C:\Program Files\Zone Labs\ZoneAlarm\firewall.zap

    DEEP - 260
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000004
    Value : path = C:\Program Files\Zone Labs\ZoneAlarm\email.zap
    Parsed : C:\Program Files\Zone Labs\ZoneAlarm\email.zap

    DEEP - 261
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000008
    Value : path = C:\Program Files\Zone Labs\ZoneAlarm\scan.zap
    Parsed : C:\Program Files\Zone Labs\ZoneAlarm\scan.zap

    DEEP - 262
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000010
    Value : path = C:\Program Files\Zone Labs\ZoneAlarm\programs.zap
    Parsed : C:\Program Files\Zone Labs\ZoneAlarm\programs.zap

    DEEP - 263
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000020
    Value : path = C:\Program Files\Zone Labs\ZoneAlarm\imsecure.zap
    Parsed : C:\Program Files\Zone Labs\ZoneAlarm\imsecure.zap

    DEEP - 264
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000040
    Value : path = C:\Program Files\Zone Labs\ZoneAlarm\idlock.zap
    Parsed : C:\Program Files\Zone Labs\ZoneAlarm\idlock.zap

    DEEP - 265
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000080
    Value : path = C:\Program Files\Zone Labs\ZoneAlarm\privacy.zap
    Parsed : C:\Program Files\Zone Labs\ZoneAlarm\privacy.zap

    DEEP - 266
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000100
    Value : path = C:\Program Files\Zone Labs\ZoneAlarm\filter.zap
    Parsed : C:\Program Files\Zone Labs\ZoneAlarm\filter.zap

    DEEP - 267
    Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000400
    Value : path = C:\Program Files\Zone Labs\ZoneAlarm\alert.zap
    Parsed : C:\Program Files\Zone Labs\ZoneAlarm\alert.zap

    DEEP - 268
    Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\McAfeePrivacyService\McAfeePrivacyService_Parental\.Current
    Value : (Default) = C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV
    Parsed : C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV

    DEEP - 269
    Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\McAfeePrivacyService\McAfeePrivacyService_Parental\.Default
    Value : (Default) = C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV
    Parsed : C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV

    DEEP - 270
    Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\McAfeePrivacyService\McAfeePrivacyService_Privacy\.Current
    Value : (Default) = C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV
    Parsed : C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV

    DEEP - 271
    Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\McAfeePrivacyService\McAfeePrivacyService_Privacy\.Default
    Value : (Default) = C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV
    Parsed : C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV

    DEEP - 272
    Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\McAfeePrivacyService\McAfeePrivacyService_Security\.Current
    Value : (Default) = C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV
    Parsed : C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV

    DEEP - 273
    Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\McAfeePrivacyService\McAfeePrivacyService_Security\.Default
    Value : (Default) = C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV
    Parsed : C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV

    DEEP - 274
    Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\MSNMSGR\MSNMSGR_ContactOnline\.Current
    Value : (Default) = C:\Program Files\MSN Messenger\online.wav
    Parsed : C:\Program Files\MSN Messenger\online.wav

    DEEP - 275
    Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\MSNMSGR\MSNMSGR_NewAlert\.Current
    Value : (Default) = C:\Program Files\MSN Messenger\newalert.wav
    Parsed : C:\Program Files\MSN Messenger\newalert.wav

    DEEP - 276
    Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\MSNMSGR\MSNMSGR_NewMail\.Current
    Value : (Default) = C:\Program Files\MSN Messenger\newemail.wav
    Parsed : C:\Program Files\MSN Messenger\newemail.wav

    DEEP - 277
    Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\MSNMSGR\MSNMSGR_NewMessage\.Current
    Value : (Default) = C:\Program Files\MSN Messenger\type.wav
    Parsed : C:\Program Files\MSN Messenger\type.wav

    DEEP - 278
    Location: HKEY_CURRENT_USER\EUDC\1252
    Value : SystemDefaultEUDCFont = C:\WINDOWS\FONTS\EUDC.TTE
    Parsed : C:\WINDOWS\FONTS\EUDC.TTE

    DEEP - 279
    Location: HKEY_CURRENT_USER\Software\Ahead\Nero - Burning Rom\Database
    Value : UserDbPath = C:\Program Files\Ahead\nero\UsrDb
    Parsed : C:\Program Files\Ahead\nero\UsrDb

    DEEP - 280
    Location: HKEY_CURRENT_USER\Software\Canon\ScanGear\7.0\Devices\CNQL30
    Value : TempFolder = C:\Documents and Settings\keno cannady\Application Data\Canon
    Parsed : C:\Documents and Settings\keno cannady\Application Data\Canon

    DEEP - 281
    Location: HKEY_CURRENT_USER\Software\Cyberlink\PowerDVD
    Value : InstallDir = C:\Program Files\CyberLink\PowerDVD
    Parsed : C:\Program Files\CyberLink\PowerDVD

    DEEP - 282
    Location: HKEY_CURRENT_USER\Software\Cyberlink\PowerDVD
    Value : InstallPath = C:\Program Files\CyberLink\PowerDVD
    Parsed : C:\Program Files\CyberLink\PowerDVD

    DEEP - 283
    Location: HKEY_CURRENT_USER\Software\Cyberlink\PowerDVD
    Value : UISkinName = C:\Program Files\CyberLink\PowerDVD\UI_Skin.DLL
    Parsed : C:\Program Files\CyberLink\PowerDVD\UI_Skin.DLL

    DEEP - 284
    Location: HKEY_CURRENT_USER\Software\DVD Shrink\DVD Shrink 3.2\Preferences
    Value : TargetFolder = C:\INTERPRETER
    Parsed : C:\INTERPRETER

    DEEP - 285
    Location: HKEY_CURRENT_USER\Software\FIRAXIS\Civ3Edit\Recent File List
    Value : File1 = C:\Documents and Settings\keno cannady\Shared\PC Games - Civilization 3 - Working Full Version\Untitled.bic
    Parsed : C:\Documents and Settings\keno cannady\Shared\PC Games - Civilization 3

    DEEP - 286
    Location: HKEY_CURRENT_USER\Software\FIRAXIS\Civ3Edit\Recent File List
    Value : File2 = C:\Documents and Settings\keno cannady\Shared\PC Games - Civilization 3 - Working Full Version\civ3mod.bic
    Parsed : C:\Documents and Settings\keno cannady\Shared\PC Games - Civilization 3

    DEEP - 287
    Location: HKEY_CURRENT_USER\Software\GIANTCompany\AntiSpyware\Alerts\719B6D7D-2163-47F8-9C9F-5A9888
    Value : FilePath = C:\Documents and Settings\keno cannady\Start Menu\Programs\Startup\LimeWire On Startup.lnk
    Parsed : C:\Documents and Settings\keno cannady\Start Menu\Programs\Startup\LimeWire On Startup.lnk

    DEEP - 288
    Location: HKEY_CURRENT_USER\Software\GIANTCompany\AntiSpyware\Alerts\9F3749B3-B089-4315-BF97-84F86B
    Value : FilePath = c:\program files\istsvc\istsvc.exe
    Parsed : c:\program files\istsvc\istsvc.exe

    DEEP - 289
    Location: HKEY_CURRENT_USER\Software\GIANTCompany\AntiSpyware\Alerts\9F3749B3-B089-4315-BF97-84F86B
    Value : RegistryValue = C:\Program Files\ISTsvc\istsvc.exe
    Parsed : C:\Program Files\ISTsvc\istsvc.exe

    DEEP - 290
    Location: HKEY_CURRENT_USER\Software\GIANTCompany\AntiSpyware\Alerts\CFBF341D-F22A-4775-AB40-7C2844
    Value : DisplayDetails = Microsoft AntiSpyware has allowed the Internet Explorer Shell Browser MSN Toolbar Suite (msntb.dll) to be installed.||Name: MSN Toolbar Suite|File path: c:\program files\msn toolbar suite\tb\02.00.0001.1203\en-us\msntb.dll
    Parsed : c:\program files\msn toolbar suite\tb\02.00.0001.1203\en-us\msntb.dll

    DEEP - 291
    Location: HKEY_CURRENT_USER\Software\GIANTCompany\AntiSpyware\Alerts\E6CC22CA-C441-480A-AD2B-49BA13
    Value : FilePath = c:\windows\farmmext.exe
    Parsed : c:\windows\farmmext.exe

    DEEP - 292
    Location: HKEY_CURRENT_USER\Software\GIANTCompany\AntiSpyware\Alerts\E6CC22CA-C441-480A-AD2B-49BA13
    Value : RegistryValue = C:\WINDOWS\farmmext.exe
    Parsed : C:\WINDOWS\farmmext.exe

    DEEP - 293
    Location: HKEY_CURRENT_USER\Software\InterVideo\DVD5R
    Value : CHANNEL_FILE = C:\Documents and Settings\All Users\Application Data\InterVideo\Recorder\Recorder.chan
    Parsed : C:\Documents and Settings\All Users\Application Data\InterVideo\Recorder\Recorder.chan

    DEEP - 294
    Location: HKEY_CURRENT_USER\Software\Macromedia\FlashPlayerUpdate
    Value : Path = C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\FlashPlayerUpdate.exe
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\FlashPlayerUpdate.exe

    DEEP - 295
    Location: HKEY_CURRENT_USER\Software\Macromedia\Shockwave 10\location\coreplayerxtras
    Value : (Default) = C:\WINDOWS\system32\Macromed\Shockwave 10\xtras\
    Parsed : C:\WINDOWS\system32\Macromed\Shockwave 10\xtras

    DEEP - 296
    Location: HKEY_CURRENT_USER\Software\Macromedia\Shockwave 10\preffileloc
    Value : (Default) = C:\Documents and Settings\keno cannady\Application Data\Macromedia\Shockwave Player\Prefs\7CPN7Q9D\
    Parsed : C:\Documents and Settings\keno cannady\Application Data\Macromedia\Shockwave Player\Prefs\7CPN7Q9D

    DEEP - 297
    Location: HKEY_CURRENT_USER\Software\McAfee.com\SpamKiller\Settings
    Value : Install Dir = C:\PROGRA~1\mcafee\SPAMKI~1\
    Parsed : C:\PROGRA~1\mcafee\SPAMKI~1

    DEEP - 298
    Location: HKEY_CURRENT_USER\Software\Microsoft\Keyboard\Native Media Players\QuickTime Player
    Value : ExePath = C:\Program Files\Quick
    Parsed : C:\Program Files\Quick

    DEEP - 299
    Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
    Value : LastNotFoundDir = C:\Documents and Settings\keno cannady\My Documents\My Videos\RCT3\
    Parsed : C:\Documents and Settings\keno cannady\My Documents\My Videos\RCT3

    DEEP - 300
    Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Setup\CreatedLinks
    Value : Shortcut0 = C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk
    Parsed : C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk

    DEEP - 301
    Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Setup\CreatedLinks
    Value : Shortcut1 = C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
    Parsed : C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk

    DEEP - 302
    Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Setup\FileMoveCache\Source
    Value : 0 = C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\setb0.tmp
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\setb0.tmp

    DEEP - 303
    Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Setup\FileMoveCache\Source
    Value : 1 = C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\setb1.tmp
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\setb1.tmp

    DEEP - 304
    Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Setup\FileMoveCache\Source
    Value : 2 = C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\setb2.tmp
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\setb2.tmp

    DEEP - 305
    Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Setup\FileMoveCache\Source
    Value : 3 = C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\setb3.tmp
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\setb3.tmp

    DEEP - 306
    Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Databases\RSApp
    Value : FileName = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Properties\RSApp.edb
    Parsed : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Properties\RSApp.edb

    DEEP - 307
    Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Databases\RSApp
    Value : LogPath = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Properties\
    Parsed : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Properties

    DEEP - 308
    Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Gather\RSApp\MyIndex
    Value : LogDirectory = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex
    Parsed : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex

    DEEP - 309
    Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Gather\RSApp\MyIndex
    Value : StreamLogsDirectory = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\GatherLogs
    Parsed : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\GatherLogs

    DEEP - 310
    Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Gather\RSApp\MyIndex
    Value : LogName = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex\MyIndex.Ntfy11.gthr
    Parsed : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex\MyIndex.Ntfy11.gthr

    DEEP - 311
    Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Gather\RSApp\MyIndex
    Value : HistoryHashMapFile = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex\MyIndex.Hash.gthr
    Parsed : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex\MyIndex.Hash.gthr

    DEEP - 312
    Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Gather\RSApp\MyIndex
    Value : DocIdMapFile = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex\MyIndex.Idm.gthr
    Parsed : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex\MyIndex.Idm.gthr

    DEEP - 313
    Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Gathering Manager
    Value : TempPath = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Temp\rssgthrsvc
    Parsed : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Temp\rssgthrsvc

    DEEP - 314
    Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Gathering Manager\Applications\RSApp\Projects\MyIndex
    Value : WorkingDirectory = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex
    Parsed : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex

    DEEP - 315
    Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Indexer\RSApp\MyIndex
    Value : ProjectPath = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex
    Parsed : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex

    DEEP - 316
    Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache
    Value : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\is-M7D7L.tmp\is-4A07N.tmp = C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\is-M7D7L.tmp\is-4A07N.tmp
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\is-M7D7L.tmp\is-4A07N.tmp

    DEEP - 317
    Location: HKEY_CURRENT_USER\Software\Microsoft\Works Suite
    Value : C:\Program Files\Microsoft Money\System\msmoney.exe = C:\Program Files\Microsoft Money\System\msmoney.exe
    Parsed : C:\Program Files\Microsoft Money\System\msmoney.exe

    DEEP - 318
    Location: HKEY_CURRENT_USER\Software\ScanSoft\OmniPagePro11.0\Scanner\ScanSoft API\PlugIn\1.0\Components\5
    Value : InProcSrv = C:\Program Files\ScanSoft\OmniPageSE\XSCAN32.psp
    Parsed : C:\Program Files\ScanSoft\OmniPageSE\XSCAN32.psp

    DEEP - 319
    Location: HKEY_CURRENT_USER\Software\Take2 Interactive\Mall Tycoon
    Value : location = C:\Program Files\Take2 Interactive\Mall Tycoon
    Parsed : C:\Program Files\Take2 Interactive\Mall Tycoon

    DEEP - 320
    Location: HKEY_CURRENT_USER\Software\Take2 Interactive\Mall Tycoon
    Value : cdrom = C:\Documents and Settings\keno cannady\Shared\PC GAMES - Mall Tycoon\
    Parsed : C:\Documents and Settings\keno cannady\Shared\PC GAMES

    DEEP - 321
    Location: HKEY_CURRENT_USER\Software\Toolbar Genie Online\My Toolbar\Historyfiles
    Value : C:\PROGRA~1\KoolBar\toolbar.xml = C:\PROGRA~1\KoolBar\toolbar.xml
    Parsed : C:\PROGRA~1\KoolBar\toolbar.xml

    DEEP - 322
    Location: HKEY_CURRENT_USER\Software\Valve\Half-Life\Player Profiles\Player
    Value : Archive = C:\Documents and Settings\keno cannady\Shared\Games - Half Life(2)\ProfileData\Player.dat
    Parsed : C:\Documents and Settings\keno cannady\Shared\Games

    DEEP - 323
    Location: HKEY_CURRENT_USER\Software\VFPlugin
    Value : DVD2AVI = C:\Program Files\GordianKnot\DVD2AVI.vfp
    Parsed : C:\Program Files\GordianKnot\DVD2AVI.vfp

    DEEP - 324
    Location: HKEY_CURRENT_USER\Software\Yahoo\YServer
    Value : HomeDir = C:\PROGRA~1\Yahoo!\MESSEN~1\data
    Parsed : C:\PROGRA~1\Yahoo!\MESSEN~1\data

    DEEP - 325
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Ahead\shared
    Value : OutputPath = C:\Program Files\Ahead\MyMusic
    Parsed : C:\Program Files\Ahead\MyMusic

    DEEP - 326
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Clients\JavaVM\MSJavaVM\InstallInfo
    Value : VerifyFile = C:\WINDOWS\system32\msjava.dll
    Parsed : C:\WINDOWS\system32\msjava.dll

    DEEP - 327
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Clients\News\Microsoft Outlook
    Value : DLLPath = C:\Program Files\Outlook ExpressMSIMNUI.DLL
    Parsed : C:\Program Files\Outlook ExpressMSIMNUI.DLL

    DEEP - 328
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\CyberLink\PowerDVD
    Value : InstallDir = C:\Program Files\CyberLink\PowerDVD
    Parsed : C:\Program Files\CyberLink\PowerDVD

    DEEP - 329
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\CyberLink\PowerDVD
    Value : InstallPath = C:\Program Files\CyberLink\PowerDVD
    Parsed : C:\Program Files\CyberLink\PowerDVD

    DEEP - 330
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\EA GAMES\Harry Potter
    Value : Install Dir = C:\Documents and Settings\keno cannady\Shared\Games - Harry Potter Full PC Game
    Parsed : C:\Documents and Settings\keno cannady\Shared\Games

    DEEP - 331
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Fish Technology Group\RollerCoaster Tycoon Setup
    Value : Path = C:\Program Files\Rollercoaster Tycoon
    Parsed : C:\Program Files\Rollercoaster Tycoon

    DEEP - 332
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Fish Technology Group\RollerCoaster Tycoon Setup
    Value : SetupPath = C:\Program Files\Rollercoaster Tycoon\
    Parsed : C:\Program Files\Rollercoaster Tycoon

    DEEP - 333
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\GIANTCompany\AntiSpyware\CleanerExe\DelFiles
    Value : c:\windows\system32\sfndcmsg.dll = c:\windows\system32\sfndcmsg.dll
    Parsed : c:\windows\system32\sfndcmsg.dll

    DEEP - 334
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\GordianKnot
    Value : InstallDir = C:\Program Files\GordianKnot
    Parsed : C:\Program Files\GordianKnot

    DEEP - 335
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Grisoft\Clients\{3C9EFEC2-8D1A-11D5-989F-0000E87B4FB1}
    Value : Config = C:\PROGRA~1\Grisoft\AVG7\avgemsui.dll
    Parsed : C:\PROGRA~1\Grisoft\AVG7\avgemsui.dll

    DEEP - 336
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\HipSoft\Trivia Machine
    Value : InstallPath = C:\Program Files\Yahoo! Games\Trivia Machine
    Parsed : C:\Program Files\Yahoo! Games\Trivia Machine

    DEEP - 337
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Infogrames Interactive\Civilization III
    Value : Install_Path = C:\Documents and Settings\keno cannady\Shared\PC Games - Civilization 3 - Working Full Version
    Parsed : C:\Documents and Settings\keno cannady\Shared\PC Games - Civilization 3

    DEEP - 338
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Infogrames Interactive\Civilization III
    Value : Uninstall_Path = C:\Program Files\InstallShield Installation Information\{0AD84416-63A4-4CF3-BDDF-8FA866711FB0}\Setup.exe
    Parsed : C:\Program Files\InstallShield Installation Information\{0AD84416-63A4-4CF3-BDDF-8FA866711FB0}\Setup.exe

    DEEP - 339
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Infogrames Interactive\Civilization III
    Value : CD_Path = C:\Documents and Settings\keno cannady\Shared\PC Games - Civilization 3 - Working Full Version
    Parsed : C:\Documents and Settings\keno cannady\Shared\PC Games - Civilization 3

    DEEP - 340
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Infogrames Interactive\Monopoly Tycoon
    Value : PATH = C:\Documents and Settings\keno cannady\Shared\Game - Monopoly Tycoon (1)\Monopoly Tycoon
    Parsed : C:\Documents and Settings\keno cannady\Shared\Game

    DEEP - 341
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\iWin\FamilyFeud
    Value : InstallDir = C:\Program Files\iWin.com Games\Family Feud
    Parsed : C:\Program Files\iWin.com Games\Family Feud

    DEEP - 342
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\Shockwave 10\location\coreplayerxtras
    Value : (Default) = C:\WINDOWS\system32\Macromed\Shockwave 10\xtras\
    Parsed : C:\WINDOWS\system32\Macromed\Shockwave 10\xtras

    DEEP - 343
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Disabled
    Value : BrowserUpdateSched = C:\WINDOWS\system32\lwinrrag.exe CORN001
    Parsed : C:\WINDOWS\system32\lwinrrag.exe

    DEEP - 344
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Disabled
    Value : q8lg = "C:\WINDOWS\system32\slk8x2peu.exe"
    Parsed : C:\WINDOWS\system32\slk8x2peu.exe

    DEEP - 345
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
    Value : MASLog047 = Exclude C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\unicows_cab\unicows.inf from installation
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\unicows_cab\unicows.inf

    DEEP - 346
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
    Value : MASLog048 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\psapi_cab\psapi.inf$$ Result: 0
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\psapi_cab\psapi.inf

    DEEP - 347
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
    Value : MASLog052 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\mas_cab\mas.inf$$ Result: 0
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\mas_cab\mas.inf

    DEEP - 348
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
    Value : MASLog053 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\mascfg_cab\mascfg.inf$$ Result: 0
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\mascfg_cab\mascfg.inf

    DEEP - 349
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
    Value : MASLog054 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masqlt_cab\masqlt.inf$$ Result: 0
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masqlt_cab\masqlt.inf

    DEEP - 350
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
    Value : MASLog055 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\vmap_cab\vmap.inf$$ Result: 0
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\vmap_cab\vmap.inf

    DEEP - 351
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
    Value : MASLog056 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\maseng_cab\maseng.inf$$ Result: 0
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\maseng_cab\maseng.inf

    DEEP - 352
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
    Value : MASLog057 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masvscor_cab\masvscor.inf$$ Result: 0
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masvscor_cab\masvscor.inf

    DEEP - 353
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
    Value : MASLog058 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masupd_cab\masupd.inf$$ Result: 0
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masupd_cab\masupd.inf

    DEEP - 354
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
    Value : MASLog059 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masdat_cab\masdat.inf$$ Result: 0
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masdat_cab\masdat.inf

    DEEP - 355
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
    Value : MASLog060 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\regwiz_cab\regwiz.inf$$ Result: 0
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\regwiz_cab\regwiz.inf

    DEEP - 356
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
    Value : MASLog061 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masreg_cab\masreg.inf$$ Result: 0
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masreg_cab\masreg.inf

    DEEP - 357
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
    Value : MASLog099 = FinalizeMAsInstall: Removing Extract Folder: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp$$Result: 0
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp$$Result

    DEEP - 358
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
    Value : MASLog101 = FinalizeMAsInstall: Removing Extract Folder: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp$$Result: 2
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp$$Result

    DEEP - 359
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\QuickClean\Installer
    Value : QclDownloadPath = C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAC8.tmp
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAC8.tmp

    DEEP - 360
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\QuickClean\Installer
    Value : QclLog002 = FinalizeQCLInstall: Removing$$Extract Folder: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA7.tmp$$Result: 0
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA7.tmp$$Result

    DEEP - 361
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Agent\Update\ResultLog
    Value : Log#022 = 4/24/2006 2:50:34 PM - CHandler::CreateHandlersWithPriority: Adding senddata handler of c:\program files\mcafee.com\agent\mcscentr.adf to the list
    Parsed : c:\program files\mcafee.com\agent\mcscentr.adf to the list

    DEEP - 362
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Agent\Update\ResultLog
    Value : Log#023 = 4/24/2006 2:50:34 PM - CHandler::CreateHandlersWithPriority: NOT Adding update handler of c:\program files\mcafee.com\agent\mcscentr.adf to the list because the desired priority does not match
    Parsed : c:\program files\mcafee.com\agent\mcscentr.adf to the list because the desired priority does not match

    DEEP - 363
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Agent\Update\ResultLog
    Value : Log#025 = 4/24/2006 2:50:37 PM - Priority: ASYNCHRONOUS; HandlerName: SendData (c:\program files\mcafee.com\agent\app\mas.adf); ResultCode: 8 (DATA_SENT)
    Parsed : c:\program files\mcafee.com\agent\app\mas.adf)

    DEEP - 364
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Agent\Update\ResultLog
    Value : Log#026 = 4/24/2006 2:50:39 PM - Priority: ASYNCHRONOUS; HandlerName: SendData (c:\program files\mcafee.com\agent\app\vso.adf); ResultCode: 8 (DATA_SENT)
    Parsed : c:\program files\mcafee.com\agent\app\vso.adf)

    DEEP - 365
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Agent\Update\ResultLog
    Value : Log#027 = 4/24/2006 2:50:40 PM - Priority: ASYNCHRONOUS; HandlerName: SendData (c:\program files\mcafee.com\agent\mcscentr.adf); ResultCode: 8 (DATA_SENT)
    Parsed : c:\program files\mcafee.com\agent\mcscentr.adf)

    DEEP - 366
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Agent\Update\ResultLog
    Value : Log#059 = 4/24/2006 10:45:05 AM - CHandler::CreateHandlersWithPriority: NOT Adding update handler of c:\program files\mcafee.com\agent\mcscentr.adf to the list because the desired priority does not match
    Parsed : c:\program files\mcafee.com\agent\mcscentr.adf to the list because the desired priority does not match

    DEEP - 367
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Agent\Update\ResultLog
    Value : Log#061 = 4/24/2006 10:45:09 AM - Priority: ASYNCHRONOUS; HandlerName: SendData (c:\program files\mcafee.com\agent\app\mas.adf); ResultCode: 8 (DATA_SENT)
    Parsed : c:\program files\mcafee.com\agent\app\mas.adf)

    DEEP - 368
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Agent\Update\ResultLog
    Value : Log#062 = 4/24/2006 10:45:12 AM - Priority: ASYNCHRONOUS; HandlerName: SendData (c:\program files\mcafee.com\agent\app\vso.adf); ResultCode: 8 (DATA_SENT)
    Parsed : c:\program files\mcafee.com\agent\app\vso.adf)

    DEEP - 369
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Agent\Update\ResultLog
    Value : Log#063 = 4/24/2006 10:45:14 AM - Priority: ASYNCHRONOUS; HandlerName: SendData (c:\program files\mcafee.com\agent\mcscentr.adf); ResultCode: 8 (DATA_SENT)
    Parsed : c:\program files\mcafee.com\agent\mcscentr.adf)

    DEEP - 370
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\GDLog\UPD_mas
    Value : Log#115 = 3/21/2006 10:06:21 PM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:mas_24, LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\UPD_mas\MasVer.Ini
    Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\UPD_mas\MasVer.Ini

    DEEP - 371
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\GDLog\UPD_mas
    Value : Log#123 = 3/21/2006 10:06:23 PM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:mys_1, LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\UPD_mas\AgentVer.ini
    Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\UPD_mas\AgentVer.ini

    DEEP - 372
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\GDLog\UPD_mas
    Value : Log#135 = 3/21/2006 10:06:27 PM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:mas_0, LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\UPD_mas\mas\gdeltapup.ini
    Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\UPD_mas\mas\gdeltapup.ini

    DEEP - 373
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\GDLog\UPD_mas
    Value : Log#141 = 3/21/2006 10:06:28 PM - CDwnldGroup::GetDownloadLocation: Download location:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\UPD_mas
    Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\UPD_mas

    DEEP - 374
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_QCL\GDLog\QCL_INSTALL_AgentCabs
    Value : Log#043 = 3/21/2006 10:11:19 PM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:Downloading Constants File..., LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~1\AgentVer.ini
    Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~1\AgentVer.ini

    DEEP - 375
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_QCL\GDLog\QCL_INSTALL_AgentCabs
    Value : Log#109 = 4/10/2006 12:21:45 AM - CDwnldGroup::GetDownloadLocation: Download location:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~1
    Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~1

    DEEP - 376
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_QCL\GDLog\QCL_INSTALL_QCLCabs
    Value : Log#017 = 3/21/2006 10:11:49 PM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:Downloading Ini File..., LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2\QclVer.Ini
    Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2\QclVer.Ini

    DEEP - 377
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_QCL\GDLog\QCL_INSTALL_QCLCabs
    Value : Log#025 = 3/21/2006 10:11:51 PM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:Downloading Application Setup..., LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2\quickcleanh\QuickCleanSetup.exe
    Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2\quickcleanh\QuickCleanSetup.exe

    DEEP - 378
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_QCL\GDLog\QCL_INSTALL_QCLCabs
    Value : Log#044 = 4/10/2006 12:20:30 AM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:Downloading Application Setup..., LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2\quickcleanh\QuickCleanSetup.exe
    Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2\quickcleanh\QuickCleanSetup.exe

    DEEP - 379
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_QCL\GDLog\QCL_INSTALL_QCLCabs
    Value : Log#065 = 4/10/2006 12:20:57 AM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:Downloading Application Setup..., LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2\quickcleanh\QuickCleanSetup.exe
    Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2\quickcleanh\QuickCleanSetup.exe

    DEEP - 380
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_QCL\GDLog\QCL_INSTALL_QCLCabs
    Value : Log#071 = 4/10/2006 12:21:45 AM - CDwnldGroup::GetDownloadLocation: Download location:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2
    Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2

    DEEP - 381
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_Vso\GDLog\VSO_INSTALL_AgentCabs
    Value : Log#108 = 4/23/2006 12:16:58 PM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:Downloading Constants File..., LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~1\AgentVer.ini
    Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~1\AgentVer.ini

    DEEP - 382
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_Vso\GDLog\VSO_INSTALL_AgentCabs
    Value : Log#122 = 4/23/2006 12:17:31 PM - CDwnldGroup::GetDownloadLocation: Download location:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~1
    Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~1

    DEEP - 383
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_Vso\GDLog\VSO_INSTALL_VsoCabs
    Value : Log#077 = 4/23/2006 12:17:31 PM - CDwnldGroup::GetDownloadLocation: Download location:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~2
    Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~2

    DEEP - 384
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_Vso\GDLog\VSO_INSTALL_VsoDatCabs
    Value : Log#021 = 4/23/2006 12:16:55 PM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:Downloading Constants File..., LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~3\VsoVer.ini
    Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~3\VsoVer.ini

    DEEP - 385
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_Vso\GDLog\VSO_INSTALL_VsoDatCabs
    Value : Log#025 = 4/23/2006 12:16:56 PM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:Downloading Virus Change File..., LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~3\vso\mcdelta.ini
    Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~3\vso\mcdelta.ini

    DEEP - 386
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_Vso\GDLog\VSO_INSTALL_VsoDatCabs
    Value : Log#031 = 4/23/2006 12:17:31 PM - CDwnldGroup::GetDownloadLocation: Download location:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~3
    Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~3

    DEEP - 387
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
    Value : MpfLog029 = Backup mpf data file : \data\pcfg.ent To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\pcfg.ent
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\pcfg.ent

    DEEP - 388
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
    Value : MpfLog030 = Backup mpf data file : \data\rdns.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\rdns.idx
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\rdns.idx

    DEEP - 389
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
    Value : MpfLog031 = Backup mpf data file : \data\hwid.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\hwid.idx
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\hwid.idx

    DEEP - 390
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
    Value : MpfLog032 = Backup mpf data file : \data\banned.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\banned.idx
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\banned.idx

    DEEP - 391
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
    Value : MpfLog033 = Backup mpf data file : \data\golden.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\golden.idx
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\golden.idx

    DEEP - 392
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
    Value : MpfLog034 = Backup mpf data file : \data\sports.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\sports.idx
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\sports.idx

    DEEP - 393
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
    Value : MpfLog035 = Backup mpf data file : \data\sports.ent To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\sports.ent
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\sports.ent

    DEEP - 394
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
    Value : MpfLog036 = Backup mpf data file : \data\winloc.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\winloc.idx
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\winloc.idx

    DEEP - 395
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
    Value : MpfLog037 = Backup mpf data file : \data\certi.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\certi.idx
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\certi.idx

    DEEP - 396
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
    Value : MpfLog038 = Backup mpf data file : \data\options.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\options.idx
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\options.idx

    DEEP - 397
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
    Value : MpfLog039 = Backup mpf data file : \data\log.edb To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\log.edb
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\log.edb

    DEEP - 398
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
    Value : MpfLog040 = Backup mpf data file : \data\log.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\log.idx
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\log.idx

    DEEP - 399
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
    Value : MpfLog041 = Backup mpf data file : \data\IpRules.xdb To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\IpRules.xdb
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\IpRules.xdb

    DEEP - 400
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
    Value : MpfLog042 = Backup mpf data file : \data\TrafficHist.xdb To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\TrafficHist.xdb
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\TrafficHist.xdb

    DEEP - 401
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
    Value : MpfLog043 = Backup mpf data file : \data\RIR.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\RIR.idx
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\RIR.idx

    DEEP - 402
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
    Value : MpfLog047 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpfcfg_cab\mpfcfg.inf$$ Result: 0
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpfcfg_cab\mpfcfg.inf

    DEEP - 403
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
    Value : MpfLog048 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpftray_cab\mpftray.inf$$ Result: 0
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpftray_cab\mpftray.inf

    DEEP - 404
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
    Value : MpfLog049 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpfmain_cab\mpfmain.inf$$ Result: 0
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpfmain_cab\mpfmain.inf

    DEEP - 405
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
    Value : MpfLog050 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpf_cab\mpf.inf$$ Result: 0
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpf_cab\mpf.inf

    DEEP - 406
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
    Value : MpfLog051 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpfadf_cab\mpfadf.inf$$ Result: 0
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpfadf_cab\mpfadf.inf

    DEEP - 407
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
    Value : MpfLog052 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\regwiz_cab\regwiz.inf$$ Result: 0
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\regwiz_cab\regwiz.inf

    DEEP - 408
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
    Value : MpfLog053 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpfreg_cab\mpfreg.inf$$ Result: 0
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpfreg_cab\mpfreg.inf

    DEEP - 409
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
    Value : MpfLog071 = Removing temp mpf data folder : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata

    DEEP - 410
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
    Value : MpfLog099 = Removing$$Extract Folder: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp$$Result: 0
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp$$Result

    DEEP - 411
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
    Value : MpfLog101 = Removing$$Extract Folder: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp$$Result: 2
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp$$Result

    DEEP - 412
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\RegWiz\Installer
    Value : RegWizLog#001 = c:\docume~1\alluse~1\applic~1\mcafee.com\agent\regwiz\regapp\vso.ini found for registration
    Parsed : c:\docume~1\alluse~1\applic~1\mcafee.com\agent\regwiz\regapp\vso.ini found for registration

    DEEP - 413
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\RegWiz\Installer
    Value : RegWizLog#003 = Application already registered. Deleting file : c:\docume~1\alluse~1\applic~1\mcafee.com\agent\regwiz\regapp\vso.ini
    Parsed : c:\docume~1\alluse~1\applic~1\mcafee.com\agent\regwiz\regapp\vso.ini

    DEEP - 414
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Shredder\Installer
    Value : ShredderDownloadPath = C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\SHR_6_~1.TMP
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\SHR_6_~1.TMP

    DEEP - 415
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Shredder\Installer
    Value : ShredderLog005 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA69.tmp\tempinst\cntrlbin_cab\cntrlbin.inf$$ Result: 0
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA69.tmp\tempinst\cntrlbin_cab\cntrlbin.inf

    DEEP - 416
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Shredder\Installer
    Value : ShredderLog006 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA69.tmp\tempinst\cntrlres_cab\cntrlres.inf$$ Result: 0
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA69.tmp\tempinst\cntrlres_cab\cntrlres.inf

    DEEP - 417
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Shredder\Installer
    Value : ShredderLog007 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA69.tmp\tempinst\shredcfg_cab\shredcfg.inf$$ Result: 0
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA69.tmp\tempinst\shredcfg_cab\shredcfg.inf

    DEEP - 418
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Shredder\Installer
    Value : ShredderLog008 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA69.tmp\tempinst\shredbin_cab\shredbin.inf$$ Result: 0
    Parsed : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA69.tmp\tempinst\shredbin_cab\shredbin.inf

    DEEP - 419
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup
    Value : JITSetupPage = file://C:\WINDOWS\web\iejit.htm
    Parsed : C:\WINDOWS\web\iejit.htm

    DEEP - 420
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\b107806c-d088-4344-98b4-4839c7767af9
    Value : StubPath = C:\WINDOWS\System32\hqhzxz.exe
    Parsed : C:\WINDOWS\System32\hqhzxz.exe

    DEEP - 421
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectPlay\Applications\Age of Empires II
    Value : Path = C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game - no cd crack\
    Parsed : C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game

    DEEP - 422
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectPlay\Applications\Age of Empires II
    Value : CurrentDirectory = C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game - no cd crack\
    Parsed : C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game

    DEEP - 423
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectPlay\Applications\Age of Empires II - The Conquerors Expansion
    Value : Path = C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game - no cd crack\
    Parsed : C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game

    DEEP - 424
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectPlay\Applications\Age of Empires II - The Conquerors Expansion
    Value : CurrentDirectory = C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game - no cd crack\
    Parsed : C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game

    DEEP - 425
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Exchange\Client\Extensions
    Value : Remote Exchange Extensions = 4.0;C:\WINDOWS\System32\emsui32.dll;6;111;111;MSEMS
    Parsed : C:\WINDOWS\System32\emsui32.dll

    DEEP - 426
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Default HTML Editor\shell\edit\command
    Value : (Default) = C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE
    Parsed : C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE

    DEEP - 427
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer
    Value : MetadataTemplatesDir = C:\Program Files\Windows Media Player\Templates
    Parsed : C:\Program Files\Windows Media Player\Templates

    DEEP - 428
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Games\Age of Empires\2.0
    Value : CDPath = C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game - no cd crack\
    Parsed : C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game

    DEEP - 429
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Games\Age of Empires\2.0
    Value : InstallationDirectory = C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game - no cd crack\
    Parsed : C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game

    DEEP - 430
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Games\Age of Empires\2.0
    Value : EXE Path = C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game - no cd crack\
    Parsed : C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game

    DEEP - 431
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Games\Age of Empires II: The Conquerors Expansion\1.0
    Value : EXE Path = C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game - no cd crack\
    Parsed : C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game

    DEEP - 432
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Games\Age of Empires II: The Conquerors Expansion\1.0
    Value : CDPath = C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game - no cd crack\
    Parsed : C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game

    DEEP - 433
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\MPlayer2\Groups\Video\DVR-MS
    Value : RequiredFile = C:\WINDOWS\system32\enable.dvd
    Parsed : C:\WINDOWS\system32\enable.dvd

    DEEP - 434
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Groups\Video\DVD
    Value : RequiredFile = C:\WINDOWS\system32\enable.dvd
    Parsed : C:\WINDOWS\system32\enable.dvd

    DEEP - 435
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Groups\Video\DVR-MS
    Value : RequiredFile = C:\WINDOWS\system32\enable.dvd
    Parsed : C:\WINDOWS\system32\enable.dvd

    DEEP - 436
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared\HTML\Default Editor\shell\Edit\command
    Value : (Default) = C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE
    Parsed : C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE

    DEEP - 437
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared\HTML\Old Default Editor\shell\Edit\command
    Value : (Default) = C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE
    Parsed : C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE

    DEEP - 438
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\DeluxeCD\Providers\Provider0000
    Value : ProviderLogo = C:\WINDOWS\System32\tunes.bmp
    Parsed : C:\WINDOWS\System32\tunes.bmp

    DEEP - 439
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\DeluxeCD\Providers\Provider0001
    Value : ProviderLogo = C:\WINDOWS\System32\n2k.bmp
    Parsed : C:\WINDOWS\System32\n2k.bmp

    DEEP - 440
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\Paint Shop Pro 9ShowPicturesOnArrivalHandler
    Value : DefaultIcon = C:\PROGRA~1\JASCSO~1\PAINTS~1\PAINTS~1.EXE,0
    Parsed : C:\PROGRA~1\JASCSO~1\PAINTS~1\PAINTS~1.EXE

    DEEP - 441
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\PDVDPlayDVDMovieOnArrival
    Value : DefaultIcon = C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe,0
    Parsed : C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe

    DEEP - 442
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FindExtensions\Static\Avg7Find\0\DefaultIcon
    Value : (Default) = C:\Program Files\Grisoft\AVG7\avgse.dll,0
    Parsed : C:\Program Files\Grisoft\AVG7\avgse.dll

    DEEP - 443
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\WebView\TemplateMacros\BACKGROUNDIMAGE
    Value : (Default) = C:\WINDOWS\Web\wvleft.bmp
    Parsed : C:\WINDOWS\Web\wvleft.bmp

    DEEP - 444
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\WebView\TemplateMacros\LOGOLINE
    Value : (Default) = C:\WINDOWS\Web\wvline.gif
    Parsed : C:\WINDOWS\Web\wvline.gif

    DEEP - 445
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\00FF41F8FA41BC84091B4C07CABDF9E3
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    DEEP - 446
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0152806F405208847813DD8BED99D629
    Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\ALEUpdat.exe
    Parsed : C:\Program Files\Norton AntiVirus\IWP\ALEUpdat.exe

    DEEP - 447
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\024EC3F90C2DE7C4FB1FFB4F5F332623
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\CfgWiz.exe
    Parsed : C:\Program Files\Norton AntiVirus\CfgWiz.exe

    DEEP - 448
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0322C474330FE1744AF900BCC66F5833
    Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\niscmnht.dll
    Parsed : C:\Program Files\Norton AntiVirus\IWP\niscmnht.dll

    DEEP - 449
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\03A9FC3E3E95C0740A521901F8767CB1
    Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Common Files\Symantec Shared\
    Parsed : C:\Program Files\Common Files\Symantec Shared

    DEEP - 450
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0411415FD32B9B946A61D0C303BD27AD
    Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\TLevel.dll
    Parsed : C:\Program Files\Norton AntiVirus\IWP\TLevel.dll

    DEEP - 451
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\044E7B0C1B06EC14E92B7D5969253EC2
    Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\ccALE.dll
    Parsed : C:\Program Files\Norton AntiVirus\IWP\ccALE.dll

    DEEP - 452
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\04B22DD6AA9C23646A3C3F467E57860C
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Quarantine\Portal\
    Parsed : C:\Program Files\Norton AntiVirus\Quarantine\Portal

    DEEP - 453
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\05396EEFA666F7742A096C3DF3072D54
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\apwcmdNT.dll
    Parsed : C:\Program Files\Norton AntiVirus\apwcmdNT.dll

    DEEP - 454
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\071A0387AE84BCF43AB238E53AB547C0
    Value : 9CFA723DAAB7A3743891E67B0A4D1083 = C:\Program Files\Norton AntiVirus\ScriptUI.dll
    Parsed : C:\Program Files\Norton AntiVirus\ScriptUI.dll

    DEEP - 455
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\075603C1A0A349649BF01150129CC6A5
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\
    Parsed : C:\Documents and Settings\All Users\Application Data\Symantec\Common Client

    DEEP - 456
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\075603C1A0A349649BF01150129CC6A5
    Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\
    Parsed : C:\Documents and Settings\All Users\Application Data\Symantec\Common Client

    DEEP - 457
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\075603C1A0A349649BF01150129CC6A5
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\
    Parsed : C:\Documents and Settings\All Users\Application Data\Symantec\Common Client

    DEEP - 458
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\07B3E601E527C0949954E5851542466B
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    DEEP - 459
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\07CEB7E467263F443B6E612F4B98D7F8
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    DEEP - 460
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\099321B84C2C2BB41851CA389FB70165
    Value : 45E1A0ACF0EC66340BC98AB716CD6533 = C:\Program Files\Common Files\Symantec Shared\SPManifests\Snd.spm
    Parsed : C:\Program Files\Common Files\Symantec Shared\SPManifests\Snd.spm

    DEEP - 461
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0AA8DBE6FFF98184CB16089724A103B2
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVOptRF.dll
    Parsed : C:\Program Files\Norton AntiVirus\NAVOptRF.dll

    DEEP - 462
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0C8F566CEA001F943A1DEEF074599FDF
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Common Files\Symantec Shared\SMNLnch.exe
    Parsed : C:\Program Files\Common Files\Symantec Shared\SMNLnch.exe

    DEEP - 463
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0DC310B120C02754683F563C5C11B7CC
    Value : 20B58AD20C31D6E4A967226E3BDDC02B = C:\Program Files\Common Files\Symantec Shared\Validate.dat
    Parsed : C:\Program Files\Common Files\Symantec Shared\Validate.dat

    DEEP - 464
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0DC310B120C02754683F563C5C11B7CC
    Value : 45E1A0ACF0EC66340BC98AB716CD6533 = C:\Program Files\Common Files\Symantec Shared\Validate.dat
    Parsed : C:\Program Files\Common Files\Symantec Shared\Validate.dat

    DEEP - 465
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1060C7258FD43414295BB92A86DFD912
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Quarantine\Incoming\
    Parsed : C:\Program Files\Norton AntiVirus\Quarantine\Incoming

    DEEP - 466
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\10B257D254F25D11EA9F00054081F409
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\S32integ.dll
    Parsed : C:\Program Files\Norton AntiVirus\S32integ.dll

    DEEP - 467
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\10FC05BCE9FD5984389C446876524F82
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVCfgWz.dll
    Parsed : C:\Program Files\Norton AntiVirus\NAVCfgWz.dll

    DEEP - 468
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\16426ABC13D89D245B93A02C0DC9C224
    Value : 9CFA723DAAB7A3743891E67B0A4D1083 = C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe
    Parsed : C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe

    DEEP - 469
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\17AE107A723326C46A2C93522D3F59F8
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    DEEP - 470
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\18CC08AD0DA03A34DAB29E0514DC04D1
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVShExt.dll
    Parsed : C:\Program Files\Norton AntiVirus\NAVShExt.dll

    DEEP - 471
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A3CD7C9A0AAA554DAAC220641E0D17E
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\navprod.dll
    Parsed : C:\Program Files\Norton AntiVirus\navprod.dll

    DEEP - 472
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1D666097B6EC4A44E844F041AC395953
    Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\ALECmpBR.dll
    Parsed : C:\Program Files\Norton AntiVirus\IWP\ALECmpBR.dll

    DEEP - 473
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F0DFF6444337B64A9497B276826DB8E
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\
    Parsed : C:\Program Files\Common Files\Symantec Shared

    DEEP - 474
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\20383D4B10B0E3346A8BD698FE0B295D
    Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\IWPLog.dll
    Parsed : C:\Program Files\Norton AntiVirus\IWP\IWPLog.dll

    DEEP - 475
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\22BF77BEE865A83449FBD70DE99B5F7A
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NetBrExt.DLL
    Parsed : C:\Program Files\Norton AntiVirus\NetBrExt.DLL

    DEEP - 476
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2575DB0D1CB48604491FD73C89519EC8
    Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\IWP.dll
    Parsed : C:\Program Files\Norton AntiVirus\IWP\IWP.dll

    DEEP - 477
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\262DD75104DBB3B498A0AA44A2F88A19
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\probeGSE.dll
    Parsed : C:\Program Files\Norton AntiVirus\probeGSE.dll

    DEEP - 478
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2725A89474CB12C44BB65170875EBA48
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVAPW32.exe
    Parsed : C:\Program Files\Norton AntiVirus\NAVAPW32.exe

    DEEP - 479
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\291736580EC2EED4397DA98BEF610A20
    Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\HNetCore.dll
    Parsed : C:\Program Files\Norton AntiVirus\IWP\HNetCore.dll

    DEEP - 480
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2BCD27044B81E3D4EBD766BC953C323E
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\savrt.sys
    Parsed : C:\Program Files\Norton AntiVirus\savrt.sys

    DEEP - 481
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2D40DF4A1B79BC94B8BB811C21CDB9F3
    Value : 7E57FF1D24DDDFC40B25023BFF4FDE8B = C:\Program Files\Norton AntiVirus\ActRes.DLL
    Parsed : C:\Program Files\Norton AntiVirus\ActRes.DLL

    DEEP - 482
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E0E3AC586E450848BDFF8BDAA3AF964
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\
    Parsed : C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus

    DEEP - 483
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E53A294F83182D45A3785356A851754
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\ccInst.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\ccInst.dll

    DEEP - 484
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E53A294F83182D45A3785356A851754
    Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\ccInst.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\ccInst.dll

    DEEP - 485
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\39A23B5C4F5C6654693A6634C7824847
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\README.TXT
    Parsed : C:\Program Files\Norton AntiVirus\README.TXT

    DEEP - 486
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3A8C3EA18ADB24E4C8E1875EC8F06375
    Value : 9CFA723DAAB7A3743891E67B0A4D1083 = C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrTrust.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrTrust.dll

    DEEP - 487
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3B288C03487C8374F965BB84C5E356C2
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    DEEP - 488
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3B2D8CCBDF636154CA11562FA1985814
    Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\FRERules.dll
    Parsed : C:\Program Files\Norton AntiVirus\IWP\FRERules.dll

    DEEP - 489
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3C9A2AED576F5544193A0C5A8DC65BE7
    Value : 45E1A0ACF0EC66340BC98AB716CD6533 = C:\Program Files\Common Files\Symantec Shared\SPManifests\Snd.sig
    Parsed : C:\Program Files\Common Files\Symantec Shared\SPManifests\Snd.sig

    DEEP - 490
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3DEE68F0FC3313E4CAD8E4C3EBCBEC40
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Text.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Text.dll

    DEEP - 491
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3DEE68F0FC3313E4CAD8E4C3EBCBEC40
    Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Text.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Text.dll

    DEEP - 492
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3E63A1A0FC3E1F24BB302AC419D4841C
    Value : 7E57FF1D24DDDFC40B25023BFF4FDE8B = C:\Program Files\Norton AntiVirus\LRSend.exe
    Parsed : C:\Program Files\Norton AntiVirus\LRSend.exe

    DEEP - 493
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3E81A4DC21026924FB5FAF933085D236
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll

    DEEP - 494
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3E81A4DC21026924FB5FAF933085D236
    Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll

    DEEP - 495
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3EC45CFDA09D6744B8D8C04431ED1964
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\AVRES.dll
    Parsed : C:\Program Files\Norton AntiVirus\AVRES.dll

    DEEP - 496
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\42D544166A9040246AE61A6BD1E89875
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    DEEP - 497
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\43BE7E834BB89F74EA8045BE46CCB3F5
    Value : 45E1A0ACF0EC66340BC98AB716CD6533 = C:\Program Files\Common Files\Symantec Shared\SPManifests\Snd.grd
    Parsed : C:\Program Files\Common Files\Symantec Shared\SPManifests\Snd.grd

    DEEP - 498
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\441567AAA28618C46A8BACAAC9BD2047
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\ecmldr32.DLL
    Parsed : C:\Program Files\Common Files\Symantec Shared\ecmldr32.DLL

    DEEP - 499
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\443CD4F6572D500468FFF934363232A4
    Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\IWPLUCbk.dll
    Parsed : C:\Program Files\Norton AntiVirus\IWP\IWPLUCbk.dll

    DEEP - 500
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4542E17C204027C4A9DB81B657767BE8
    Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\FREAles.dll
    Parsed : C:\Program Files\Norton AntiVirus\IWP\FREAles.dll

    DEEP - 501
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\471F6E8954126A04AAA3FE5AA79243D3
    Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\Ales.xml
    Parsed : C:\Program Files\Norton AntiVirus\IWP\Ales.xml

    DEEP - 502
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4799D30A4DDA954429D8D4ED011517F9
    Value : 9CFA723DAAB7A3743891E67B0A4D1083 = C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrAuth.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrAuth.dll

    DEEP - 503
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\47E0174F57CC8504DA862CA99CBAEA31
    Value : 9399EE5EF9522ED40832C5941EA6F434 = C:\Program Files\Common Files\Symantec Shared\SymUIAx2.ocx
    Parsed : C:\Program Files\Common Files\Symantec Shared\SymUIAx2.ocx

    DEEP - 504
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\48982BA41E042FE4893568B326EAE47E
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\DefAlert.dll
    Parsed : C:\Program Files\Norton AntiVirus\DefAlert.dll

    DEEP - 505
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\48F14AD033FE3EB4A87CDCEDC2AAE23B
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Common Files\Symantec Shared\
    Parsed : C:\Program Files\Common Files\Symantec Shared

    DEEP - 506
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49769A67806F0484C968C8A5358B1098
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    DEEP - 507
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4AC03AFAAEE94804C8614EFF36AFC5A1
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\SYMNAVO.DLL
    Parsed : C:\Program Files\Norton AntiVirus\SYMNAVO.DLL

    DEEP - 508
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4CB829E5237898741983A2C0FB59BAEF
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\
    Parsed : C:\Program Files\Common Files\Symantec Shared

    DEEP - 509
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4CB829E5237898741983A2C0FB59BAEF
    Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Common Files\Symantec Shared\
    Parsed : C:\Program Files\Common Files\Symantec Shared

    DEEP - 510
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4CB829E5237898741983A2C0FB59BAEF
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Common Files\Symantec Shared\
    Parsed : C:\Program Files\Common Files\Symantec Shared

    DEEP - 511
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4CBC83BFDE475DB418A2AE96BCFDE865
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\avcompbr.dll
    Parsed : C:\Program Files\Norton AntiVirus\avcompbr.dll

    DEEP - 512
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50A419CA949024647B7A0E569BA7918C
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVComUI.dll
    Parsed : C:\Program Files\Norton AntiVirus\NAVComUI.dll

    DEEP - 513
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50BBD0A1CB1FD3648A16157120DF2829
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TNEF.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TNEF.dll

    DEEP - 514
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50BBD0A1CB1FD3648A16157120DF2829
    Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TNEF.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TNEF.dll

    DEEP - 515
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50C154874C6F14B48AE0F5068BC7E626
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\DefUtDCD.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\DefUtDCD.dll

    DEEP - 516
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50C154874C6F14B48AE0F5068BC7E626
    Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\DefUtDCD.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\DefUtDCD.dll

    DEEP - 517
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50E357748DE0DD840851872431DDB49B
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RTF.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RTF.dll

    DEEP - 518
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50E357748DE0DD840851872431DDB49B
    Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RTF.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RTF.dll

    DEEP - 519
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5214FA3088B8BAD419A265B6153E97C0
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Common Files\Symantec Shared\VirusDefs\
    Parsed : C:\Program Files\Common Files\Symantec Shared\VirusDefs

    DEEP - 520
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53EC7F36FB9D406418715FDA8AC5C485
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\N32call.dll
    Parsed : C:\Program Files\Norton AntiVirus\N32call.dll

    DEEP - 521
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\595EDF0A76C2DF14DA38D14496F0422F
    Value : 9399EE5EF9522ED40832C5941EA6F434 = C:\Program Files\Common Files\Symantec Shared\CfgWiz.tlb
    Parsed : C:\Program Files\Common Files\Symantec Shared\CfgWiz.tlb

    DEEP - 522
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5F14878ED4CBD6B4995778B62914DE82
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\ScanMgr.dll
    Parsed : C:\Program Files\Norton AntiVirus\ScanMgr.dll

    DEEP - 523
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5F711C7C816E497409B42799F858A73B
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\
    Parsed : C:\Program Files\Common Files\Symantec Shared

    DEEP - 524
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\615168D24A7AD1745A12D7DBE603484A
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\qspak32.dll
    Parsed : C:\Program Files\Norton AntiVirus\qspak32.dll

    DEEP - 525
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6175647594900AC4AB89DA41EC22BDCA
    Value : 7E57FF1D24DDDFC40B25023BFF4FDE8B = C:\Program Files\Norton AntiVirus\SymLCUI.dll
    Parsed : C:\Program Files\Norton AntiVirus\SymLCUI.dll

    DEEP - 526
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\663818B8178761A498A24322153E6C55
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\scancfg.dat
    Parsed : C:\Program Files\Norton AntiVirus\scancfg.dat

    DEEP - 527
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\668C52B058E567C4A9461F74298A7B16
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\navui.nsi
    Parsed : C:\Program Files\Norton AntiVirus\navui.nsi

    DEEP - 528
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6714C945179DA67419B483C6A8082757
    Value : 7E57FF1D24DDDFC40B25023BFF4FDE8B = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    DEEP - 529
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\681293A7B6EE4994588C3F608CE24AE7
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    DEEP - 530
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6906F858261DD5142981FFF252CECF0C
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\apwutil.dll
    Parsed : C:\Program Files\Norton AntiVirus\apwutil.dll

    DEEP - 531
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6925106EE9D0AF740BCCD43F8907862F
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TAR.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TAR.dll

    DEEP - 532
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6925106EE9D0AF740BCCD43F8907862F
    Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TAR.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TAR.dll

    DEEP - 533
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6A41CC073B92EE847B8FFCE9495410A9
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    DEEP - 534
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6B0AE912F7ED2224CBB5D6B506795029
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVEvent.dll
    Parsed : C:\Program Files\Norton AntiVirus\NAVEvent.dll

    DEEP - 535
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6C903CD2A490B0C4B817B5822363D670
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Navwnt.exe
    Parsed : C:\Program Files\Norton AntiVirus\Navwnt.exe

    DEEP - 536
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6E567B288C21FE748928C2F767434E49
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    DEEP - 537
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6EEA3CF07EBD65C48A3FE380BC2FF61E
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LZ.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LZ.dll

    DEEP - 538
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6EEA3CF07EBD65C48A3FE380BC2FF61E
    Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LZ.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LZ.dll

    DEEP - 539
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F197F7372EA24349AC09AC49ABA402E
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVAPSCR.dll
    Parsed : C:\Program Files\Norton AntiVirus\NAVAPSCR.dll

    DEEP - 540
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F8308D658EBA7E48AC20C2C1C53D51F
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVLogV.dll
    Parsed : C:\Program Files\Norton AntiVirus\NAVLogV.dll

    DEEP - 541
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7029927AC4655CF4CA5476C0F7A0844A
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVOpts.dll
    Parsed : C:\Program Files\Norton AntiVirus\NAVOpts.dll

    DEEP - 542
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\717AB62A0DC6B434EA08A1A45AC41341
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\ccDec.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\ccDec.dll

    DEEP - 543
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\744510B0F96EA7346945429C47B772AB
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\qconsole.exe
    Parsed : C:\Program Files\Norton AntiVirus\qconsole.exe

    DEEP - 544
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7469F3930A15C804EBC767838BD0E200
    Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\IDSDefs\
    Parsed : C:\Program Files\Norton AntiVirus\IWP\IDSDefs

    DEEP - 545
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\74B65AE67660E0649AB135AA083E16D6
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\ccIMScan.dll
    Parsed : C:\Program Files\Norton AntiVirus\ccIMScan.dll

    DEEP - 546
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\758CEDE445E075242A1B28C209469190
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    DEEP - 547
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7B50EBD049034D245BACB7DF3D3F0055
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\
    Parsed : C:\Program Files\Common Files\Symantec Shared

    DEEP - 548
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7B555CBEE5D5DC34DA22C85A114E44D6
    Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\ccRuleIO.dll
    Parsed : C:\Program Files\Norton AntiVirus\IWP\ccRuleIO.dll

    DEEP - 549
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7D6437C5C6894A94F8CBB03BDF0023CE
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\ccL30.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\ccL30.dll

    DEEP - 550
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7D6437C5C6894A94F8CBB03BDF0023CE
    Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\ccL30.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\ccL30.dll

    DEEP - 551
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8009C7720B95C304C81241A8EC4D39D6
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\ccLogin.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\ccLogin.dll

    DEEP - 552
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\81CE673053E252642B9EB19881D11525
    Value : 9399EE5EF9522ED40832C5941EA6F434 = C:\Program Files\Common Files\Symantec Shared\
    Parsed : C:\Program Files\Common Files\Symantec Shared

    DEEP - 553
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\82EF65EE71A8DFE46BF3103894868C74
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVTasks.dll
    Parsed : C:\Program Files\Norton AntiVirus\NAVTasks.dll

    DEEP - 554
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\83056920BAAA6E64A9DD0F72BB1F8568
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\S32NAVO.DLL
    Parsed : C:\Program Files\Norton AntiVirus\S32NAVO.DLL

    DEEP - 555
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8350CADA40F1245418AE0898B5F2CC8F
    Value : 9CFA723DAAB7A3743891E67B0A4D1083 = C:\Program Files\Common Files\Symantec Shared\VirusDefs\MyAuth.dat
    Parsed : C:\Program Files\Common Files\Symantec Shared\VirusDefs\MyAuth.dat

    DEEP - 556
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\846574CE2AA8B9C40AD64866F9DE77A7
    Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    Parsed : C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe

    DEEP - 557
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\849F6BDFC1324574389DDBD802611B2D
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Common Files\Symantec Shared\ccGSE.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\ccGSE.dll

    DEEP - 558
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\85A6640347184DE419174A7D938EE4A3
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    Parsed : C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    DEEP - 559
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8B245E22A8EFDF94EBC89D75F9CB11EC
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVStub.exe
    Parsed : C:\Program Files\Norton AntiVirus\NAVStub.exe

    DEEP - 560
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8B45BF4DC2F0A1B4B9327CFFF2806334
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\SavRT32.dll
    Parsed : C:\Program Files\Norton AntiVirus\SavRT32.dll

    DEEP - 561
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8B508B6DAB8B7964E8AD0D371CF29B5C
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\DJSAlert.dll
    Parsed : C:\Program Files\Norton AntiVirus\DJSAlert.dll

    DEEP - 562
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CC0AB79D89CB4549B29F8FA2785D777
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\SAVScan.exe
    Parsed : C:\Program Files\Norton AntiVirus\SAVScan.exe

    DEEP - 563
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8E63A159A784DEF41BB6209B779E6D45
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    DEEP - 564
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8EF9EE1FC66940B468785FE27846A4B5
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\
    Parsed : C:\Program Files\Common Files\Symantec Shared

    DEEP - 565
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\91F31ECC41B96D243A45422551C96C23
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Zip.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Zip.dll

    DEEP - 566
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\91F31ECC41B96D243A45422551C96C23
    Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Zip.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Zip.dll

    DEEP - 567
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\932EEA56C5A47C8499E284F46ACC2016
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Documents and Settings\All Users\Start Menu\Programs\Norton AntiVirus\
    Parsed : C:\Documents and Settings\All Users\Start Menu\Programs\Norton AntiVirus

    DEEP - 568
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\953E4C7EF5A3315458FC82A7BD02EE98
    Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Common Files\Symantec Shared\SPBBC\SPLVPlug.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\SPBBC\SPLVPlug.dll

    DEEP - 569
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\953E4C7EF5A3315458FC82A7BD02EE98
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Common Files\Symantec Shared\SPBBC\SPLVPlug.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\SPBBC\SPLVPlug.dll

    DEEP - 570
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9542A2F29521AEA49825DACE47ECB069
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\qconres.dll
    Parsed : C:\Program Files\Norton AntiVirus\qconres.dll

    DEEP - 571
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\956B95676BE85A84DA3C38A66DE87EF4
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RAR.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RAR.dll

    DEEP - 572
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\956B95676BE85A84DA3C38A66DE87EF4
    Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RAR.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RAR.dll

    DEEP - 573
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9650EFDF332FF2741B72B1F1F2CA1DA7
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVUIHTM.dll
    Parsed : C:\Program Files\Norton AntiVirus\NAVUIHTM.dll

    DEEP - 574
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A31A16C69A2D4F40B30BC92212E9182
    Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\ccFWSetg.dll
    Parsed : C:\Program Files\Norton AntiVirus\IWP\ccFWSetg.dll

    DEEP - 575
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D20C7BA42CFF7A43BF7BB1BD173829F
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    DEEP - 576
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A0BBBFBB9DF126841A599E50CF74E420
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    DEEP - 577
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A3CEBDA9EBF8DEA4FBE368F050BEE9B5
    Value : 9399EE5EF9522ED40832C5941EA6F434 = C:\Program Files\Common Files\Symantec Shared\
    Parsed : C:\Program Files\Common Files\Symantec Shared

    DEEP - 578
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A53030D1FA7CD0C42A0CE951CD8D70B6
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Navap32.dll
    Parsed : C:\Program Files\Norton AntiVirus\Navap32.dll

    DEEP - 579
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A6AFA04EFD73D69418C4062C5576D74F
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\
    Parsed : C:\Program Files\Common Files\Symantec Shared

    DEEP - 580
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A8DC89FAF3F52B3448C6E06B118C405E
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2AMG.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2AMG.dll

    DEEP - 581
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A8DC89FAF3F52B3448C6E06B118C405E
    Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2AMG.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2AMG.dll

    DEEP - 582
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AA5473481968D2C449595600631BF60F
    Value : 9399EE5EF9522ED40832C5941EA6F434 = C:\Program Files\Norton AntiVirus\AVSTE.dll
    Parsed : C:\Program Files\Norton AntiVirus\AVSTE.dll

    DEEP - 583
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AB41244462F87CA4B9F2050D4AF13DE0
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVLUCBK.dll
    Parsed : C:\Program Files\Norton AntiVirus\NAVLUCBK.dll

    DEEP - 584
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AC715C67C18D0E14986117D61115B5D9
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\navapw32.dll
    Parsed : C:\Program Files\Norton AntiVirus\navapw32.dll

    DEEP - 585
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AD0898EB938AF6148ACBF7D389DE3E3D
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Statushp.dll
    Parsed : C:\Program Files\Norton AntiVirus\Statushp.dll

    DEEP - 586
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AE218B3D3A784674FA9D4ED959E3F941
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    DEEP - 587
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AE842139D531885469A1CDC35A26B1F4
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\DecSDK.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\DecSDK.dll

    DEEP - 588
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AE842139D531885469A1CDC35A26B1F4
    Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\DecSDK.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\DecSDK.dll

    DEEP - 589
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B00431804170C134B939ED6830DA1C39
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\SDSOK32I.DLL
    Parsed : C:\Program Files\Norton AntiVirus\SDSOK32I.DLL

    DEEP - 590
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B16AC77B767B76344ADD68B231863B6A
    Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\FREInteg.dll
    Parsed : C:\Program Files\Norton AntiVirus\IWP\FREInteg.dll

    DEEP - 591
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B305EF16382BB1E43B550C61C5E6C983
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVSTATS.dll
    Parsed : C:\Program Files\Norton AntiVirus\NAVSTATS.dll

    DEEP - 592
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3131345148ADC043AA743CF15C58161
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Scandlvr.dll
    Parsed : C:\Program Files\Norton AntiVirus\Scandlvr.dll

    DEEP - 593
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3F6A2DB538BA6E44B9404005AFB41E2
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Documents and Settings\All Users\Application Data\Symantec\
    Parsed : C:\Documents and Settings\All Users\Application Data\Symantec

    DEEP - 594
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3F6A2DB538BA6E44B9404005AFB41E2
    Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Documents and Settings\All Users\Application Data\Symantec\
    Parsed : C:\Documents and Settings\All Users\Application Data\Symantec

    DEEP - 595
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3F6A2DB538BA6E44B9404005AFB41E2
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Documents and Settings\All Users\Application Data\Symantec\
    Parsed : C:\Documents and Settings\All Users\Application Data\Symantec

    DEEP - 596
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B4AA92F71A4DC8843B921505A7EE1982
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVError.dll
    Parsed : C:\Program Files\Norton AntiVirus\NAVError.dll

    DEEP - 597
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B95F812E3128A514B869E6BFEE1FEDF3
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\COUNTRY.DAT
    Parsed : C:\Program Files\Norton AntiVirus\COUNTRY.DAT

    DEEP - 598
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BB26CE3D008E2FA499FDEE6A7A5B9335
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2CAB.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2CAB.dll

    DEEP - 599
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BB26CE3D008E2FA499FDEE6A7A5B9335
    Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2CAB.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2CAB.dll

    DEEP - 600
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BBAE3AAB8D0042547990AF991553C16B
    Value : 9CFA723DAAB7A3743891E67B0A4D1083 = C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrBlock.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrBlock.dll

    DEEP - 601
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BD04BAF963B867144BE7910CADB91EC8
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVUI.dll
    Parsed : C:\Program Files\Norton AntiVirus\NAVUI.dll

    DEEP - 602
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BDEA5D3B2A1FFDC44B55F08AD7801175
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\OPScan.exe
    Parsed : C:\Program Files\Norton AntiVirus\OPScan.exe

    DEEP - 603
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BE6AEA47C44CE854791235345CE87CE6
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LHA.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LHA.dll

    DEEP - 604
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BE6AEA47C44CE854791235345CE87CE6
    Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LHA.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LHA.dll

    DEEP - 605
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BEB4972A12860764BB195C6D768E12A1
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Common Files\Symantec Shared\
    Parsed : C:\Program Files\Common Files\Symantec Shared

    DEEP - 606
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF34ED1C895652B4D92C1D66CE00BF98
    Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\fwUI.dll
    Parsed : C:\Program Files\Norton AntiVirus\IWP\fwUI.dll

    DEEP - 607
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C1AC78A74A3296B4BA739BA5E5766344
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2SS.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2SS.dll

    DEEP - 608
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C1AC78A74A3296B4BA739BA5E5766344
    Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2SS.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2SS.dll

    DEEP - 609
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C1D015D543A678D4088D751CA77430A5
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ARJ.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ARJ.dll

    DEEP - 610
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C1D015D543A678D4088D751CA77430A5
    Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ARJ.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ARJ.dll

    DEEP - 611
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C30AE6C259C7B424E914F0A0C4C244BA
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\N32Exclu.dll
    Parsed : C:\Program Files\Norton AntiVirus\N32Exclu.dll

    DEEP - 612
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C33570307F55DB54396FFFF444D96E0B
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\navapsvc.exe
    Parsed : C:\Program Files\Norton AntiVirus\navapsvc.exe

    DEEP - 613
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C3BD2CD6023CED14080DED74FA48DDCA
    Value : 7E57FF1D24DDDFC40B25023BFF4FDE8B = C:\Program Files\Common Files\Symantec Shared\CCPD-LC\
    Parsed : C:\Program Files\Common Files\Symantec Shared\CCPD-LC

    DEEP - 614
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C519BC4820133E149AC900B6B2F708CA
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\CfgWzRes.dll
    Parsed : C:\Program Files\Norton AntiVirus\CfgWzRes.dll

    DEEP - 615
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C7C4F0E638DD18A46B7A39824E3A6EE8
    Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\SymFwAgt.DLL
    Parsed : C:\Program Files\Norton AntiVirus\IWP\SymFwAgt.DLL

    DEEP - 616
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C8C9E5A275AC91441BD5E7569AAFEDDC
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Savrtpel.sys
    Parsed : C:\Program Files\Norton AntiVirus\Savrtpel.sys

    DEEP - 617
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB101FE8D11198442AB0CE71DBBB7996
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVLnch.dll
    Parsed : C:\Program Files\Norton AntiVirus\NAVLnch.dll

    DEEP - 618
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CDAF0D299B31D614A997AC7EFF57FE6F
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Help\CCLGVIEW.CHM
    Parsed : C:\Program Files\Common Files\Symantec Shared\Help\CCLGVIEW.CHM

    DEEP - 619
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CDB8298C7464d6d489512651FE1AADA4
    Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\ISWrap.dll
    Parsed : C:\Program Files\Norton AntiVirus\IWP\ISWrap.dll

    DEEP - 620
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D134FCA7554F39744BE3E935F5FDC7A8
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\quar32.dll
    Parsed : C:\Program Files\Norton AntiVirus\quar32.dll

    DEEP - 621
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D1F9A4570B6A53B4ABA8EABBF618BACC
    Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\ICFMgr.dll
    Parsed : C:\Program Files\Norton AntiVirus\IWP\ICFMgr.dll

    DEEP - 622
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2B1A54B84E046A40B699A99AA183415
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Navntutl.dll
    Parsed : C:\Program Files\Norton AntiVirus\Navntutl.dll

    DEEP - 623
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2ED3A901D3C1E640A22123D3329A663
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\PtchInst.dll
    Parsed : C:\Program Files\Norton AntiVirus\PtchInst.dll

    DEEP - 624
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2EEB513BDC48C443B0FFC4606A08DFF
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ID.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ID.dll

    DEEP - 625
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2EEB513BDC48C443B0FFC4606A08DFF
    Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ID.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ID.dll

    DEEP - 626
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D485B77AAFBE7FE4EB02F19B1C742D99
    Value : 7E57FF1D24DDDFC40B25023BFF4FDE8B = C:\Program Files\Norton AntiVirus\SymUIHlp.dll
    Parsed : C:\Program Files\Norton AntiVirus\SymUIHlp.dll

    DEEP - 627
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D4C317E99F72CD94E80229440898C76B
    Value : 20B58AD20C31D6E4A967226E3BDDC02B = C:\Program Files\Common Files\Symantec Shared\Default.rul
    Parsed : C:\Program Files\Common Files\Symantec Shared\Default.rul

    DEEP - 628
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D4C317E99F72CD94E80229440898C76B
    Value : 45E1A0ACF0EC66340BC98AB716CD6533 = C:\Program Files\Common Files\Symantec Shared\Default.rul
    Parsed : C:\Program Files\Common Files\Symantec Shared\Default.rul

    DEEP - 629
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D5C7E0ECE38B2204C81A6CAC7B563C1E
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\OEHeur.dll
    Parsed : C:\Program Files\Norton AntiVirus\OEHeur.dll

    DEEP - 630
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB37AD6F8B343624D8A21F9536E244D0
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\ccScan.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\ccScan.dll

    DEEP - 631
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DDBB2E3516FF53D49B7674092DF93A43
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Scandres.dll
    Parsed : C:\Program Files\Norton AntiVirus\Scandres.dll

    DEEP - 632
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DE6692E1170B7234EB5CFD71486A1C3F
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2GZIP.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2GZIP.dll

    DEEP - 633
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DE6692E1170B7234EB5CFD71486A1C3F
    Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2GZIP.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2GZIP.dll

    DEEP - 634
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E03493F9C46190242AE587161C8E1607
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Documents and Settings\All Users\Application Data\Symantec\
    Parsed : C:\Documents and Settings\All Users\Application Data\Symantec

    DEEP - 635
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E226A5EC6DBEB5B41AA58B99246CA6EA
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Navlcom.dll
    Parsed : C:\Program Files\Norton AntiVirus\Navlcom.dll

    DEEP - 636
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E41CAC9D612ABD845B8DB1A766C5818E
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\SDPCK32I.DLL
    Parsed : C:\Program Files\Norton AntiVirus\SDPCK32I.DLL

    DEEP - 637
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E5A2A8E777C123D41A1B9870787E7200
    Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\ACDisp.dll
    Parsed : C:\Program Files\Norton AntiVirus\IWP\ACDisp.dll

    DEEP - 638
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EACA16BD93C3AC64E9487A0F15FA0CB7
    Value : 6786F822313A3A04190C3CBC6E99D790 = C:\Documents and Settings\All Users\Application Data\Symantec\
    Parsed : C:\Documents and Settings\All Users\Application Data\Symantec

    DEEP - 639
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EACA16BD93C3AC64E9487A0F15FA0CB7
    Value : 20B58AD20C31D6E4A967226E3BDDC02B = C:\Documents and Settings\All Users\Application Data\Symantec\
    Parsed : C:\Documents and Settings\All Users\Application Data\Symantec

    DEEP - 640
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EACA16BD93C3AC64E9487A0F15FA0CB7
    Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Documents and Settings\All Users\Application Data\Symantec\
    Parsed : C:\Documents and Settings\All Users\Application Data\Symantec

    DEEP - 641
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EACA16BD93C3AC64E9487A0F15FA0CB7
    Value : 5A60346F23C4bb141B3535895672AF4B = C:\Documents and Settings\All Users\Application Data\Symantec\
    Parsed : C:\Documents and Settings\All Users\Application Data\Symantec

    DEEP - 642
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EBB41D27C6D48A142A21DC74BA5CD4A7
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    DEEP - 643
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED9559B59719B7648A5698448B0F5C13
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\SDSTP32I.DLL
    Parsed : C:\Program Files\Norton AntiVirus\SDSTP32I.DLL

    DEEP - 644
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EDA2F868189B4BB43835954121D6D84F
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\ccAVMail.dll
    Parsed : C:\Program Files\Norton AntiVirus\ccAVMail.dll

    DEEP - 645
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EDB816C6DB3D2D34E9E028C26D00C79E
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    DEEP - 646
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EE7648442F6386F4B974667E874252D3
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\SDSND32I.DLL
    Parsed : C:\Program Files\Norton AntiVirus\SDSND32I.DLL

    DEEP - 647
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF24F0C8CEA62F94AABE0F1D2DCFE65B
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVTskWz.dll
    Parsed : C:\Program Files\Norton AntiVirus\NAVTskWz.dll

    DEEP - 648
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F09CF45C228A5D946916CA86F0B28466
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\navsess.tpl
    Parsed : C:\Program Files\Norton AntiVirus\navsess.tpl

    DEEP - 649
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F1031A4EC1C5b044694350E3CF04BF73
    Value : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\ISLuCbk.dll
    Parsed : C:\Program Files\Norton AntiVirus\IWP\ISLuCbk.dll

    DEEP - 650
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F14B2730986758A4FACCDABB202D7702
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\ccIMScn.exe
    Parsed : C:\Program Files\Norton AntiVirus\ccIMScn.exe

    DEEP - 651
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F297450C80AA7B44CAC9B12C24BFA5C5
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\LtChkRes.dll
    Parsed : C:\Program Files\Norton AntiVirus\LtChkRes.dll

    DEEP - 652
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F42B98E5315CA254F98CB0E739C7CEA1
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2.dll

    DEEP - 653
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F42B98E5315CA254F98CB0E739C7CEA1
    Value : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2.dll
    Parsed : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2.dll

    DEEP - 654
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F4BA67E73F1500B44B2BE9626C16C657
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\patch25d.dll
    Parsed : C:\Program Files\Norton AntiVirus\patch25d.dll

    DEEP - 655
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F890C1DE6479A8044916B360F03F6577
    Value : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\
    Parsed : C:\Program Files\Common Files\Symantec Shared

    DEEP - 656
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F959C548DF373904DBA75FAB7EEDBB3C
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\end_user.txt
    Parsed : C:\Program Files\Norton AntiVirus\end_user.txt

    DEEP - 657
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA0AE70A711E43A4D845D528F62189C8
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\OfficeAV.dll
    Parsed : C:\Program Files\Norton AntiVirus\OfficeAV.dll

    DEEP - 658
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FAE59BAC70CEF6B4C907FE4AF0B1C09A
    Value : F81D34B847CD44D418E4B93D24B0E844 = C:\Program Files\McAfee\McAfee QuickClean\Restore\ShredEnu.dll
    Parsed : C:\Program Files\McAfee\McAfee QuickClean\Restore\ShredEnu.dll

    DEEP - 659
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB9E629FE71958F499EAB75A10C537C2
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Navw32.exe
    Parsed : C:\Program Files\Norton AntiVirus\Navw32.exe

    DEEP - 660
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FDB73BAFBA2FA4448A9F560C8AE6AB05
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\AboutPlg.dll
    Parsed : C:\Program Files\Norton AntiVirus\AboutPlg.dll

    DEEP - 661
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FFEBF8E0EFEA5B440A054DF0D1F8C8C9
    Value : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Tasks\files.sca
    Parsed : C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Tasks\files.sca

    DEEP - 662
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\207809E353FA1164598159D52AB4E770\InstallProperties
    Value : InstallSource = C:\WINDOWS\TEMP\IXP000.TMP\
    Parsed : C:\WINDOWS\TEMP\IXP000.TMP

    DEEP - 663
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\20B58AD20C31D6E4A967226E3BDDC02B\InstallProperties
    Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SymNet\
    Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SymNet

    DEEP - 664
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\45E1A0ACF0EC66340BC98AB716CD6533\InstallProperties
    Value : InstallSource = C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\LIVEUP~1\DOWNLO~1\EXITEM~1.0_E\
    Parsed : C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\LIVEUP~1\DOWNLO~1\EXITEM~1.0_E

    DEEP - 665
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5A60346F23C4bb141B3535895672AF4B\InstallProperties
    Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SymSC\
    Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SymSC

    DEEP - 666
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5F1BEE43939E1A046AAB5927284A2B8C\InstallProperties
    Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\Help\
    Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\Help

    DEEP - 667
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6786F822313A3A04190C3CBC6E99D790\InstallProperties
    Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\MSRedist\
    Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\MSRedist

    DEEP - 668
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7E57FF1D24DDDFC40B25023BFF4FDE8B\InstallProperties
    Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV\
    Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV

    DEEP - 669
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\806763CD7A467FB4294FB8AA52AB20BD\InstallProperties
    Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\ccCommon\
    Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\ccCommon

    DEEP - 670
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\87627777F71810443910DED1108AAD65\InstallProperties
    Value : InstallLocation = C:\Program Files\Norton AntiVirus\
    Parsed : C:\Program Files\Norton AntiVirus

    DEEP - 671
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\87627777F71810443910DED1108AAD65\InstallProperties
    Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SPBBC\
    Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SPBBC

    DEEP - 672
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040820900063D11C8EF00054038389C\InstallProperties
    Value : InstallSource = C:\Documents and Settings\keno cannady\Shared\Microsoft Office XP Professional (Includes Serial Number)\Microsoft Office XP\
    Parsed : C:\Documents and Settings\keno cannady\Shared\Microsoft Office XP Professional (Includes Serial Number)\Microsoft Office XP

    DEEP - 673
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9399EE5EF9522ED40832C5941EA6F434\InstallProperties
    Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV\
    Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV

    DEEP - 674
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9CFA723DAAB7A3743891E67B0A4D1083\InstallProperties
    Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\ScrBlock\
    Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\ScrBlock

    DEEP - 675
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC0F80924D1CF744792AFC1C539C8F4D\InstallProperties
    Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV\
    Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV

    DEEP - 676
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F81D34B847CD44D418E4B93D24B0E844\InstallProperties
    Value : Readme = C:\Program Files\McAfee\McAfee QuickClean\Readme.txt
    Parsed : C:\Program Files\McAfee\McAfee QuickClean\Readme.txt

    DEEP - 677
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\FC6B5F6CC906E82478F6AC3871C620B1\InstallProperties
    Value : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV\
    Parsed : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV

    DEEP - 678
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
    Value : Directory = C:\WINDOWS\History
    Parsed : C:\WINDOWS\History

    DEEP - 679
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup
    Value : ServicePackCachePath = c:\windows\ServicePackFiles\ServicePackCache
    Parsed : c:\windows\ServicePackFiles\ServicePackCache

    DEEP - 680
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Migration DLLs
    Value : {5945c046-1e7d-11d1-bc44-00c04fd912be} = C:\Program Files\Messenger\migrate.dll
    Parsed : C:\Program Files\Messenger\migrate.dll

    DEEP - 681
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\StillImage\Registered Applications
    Value : OmniPage SE = C:\Program Files\ScanSoft\OmniPageSE\OmniPage.exe /StiDevice:%1 /StiEvent:%2
    Parsed : C:\Program Files\ScanSoft\OmniPageSE\OmniPage.exe

    DEEP - 682
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Reporting\EventCache\Sus
    Value : CurrentCacheFile = C:\WINDOWS\SoftwareDistribution\EventCache\{07F5D015-59A7-4B7E-95D0-4A50A504ED85}.bin
    Parsed : C:\WINDOWS\SoftwareDistribution\EventCache\{07F5D015-59A7-4B7E-95D0-4A50A504ED85}.bin

    DEEP - 683
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Reporting\EventCache\WU
    Value : CurrentCacheFile = C:\WINDOWS\SoftwareDistribution\EventCache\{E78161BE-AB16-4DEE-A62D-E3774298CEFC}.bin
    Parsed : C:\WINDOWS\SoftwareDistribution\EventCache\{E78161BE-AB16-4DEE-A62D-E3774298CEFC}.bin

    DEEP - 684
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SeCEdit
    Value : TemplateUsed = C:\WINDOWS\SEC129B.tmp
    Parsed : C:\WINDOWS\SEC129B.tmp

    DEEP - 685
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar
    Value : Dir = C:\Program Files\MyWay\myBar\
    Parsed : C:\Program Files\MyWay\myBar

    DEEP - 686
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\partner
    Value : bitmap = C:\Program Files\MyWay\myBar\1.bin\partner.bmp
    Parsed : C:\Program Files\MyWay\myBar\1.bin\partner.bmp

    DEEP - 687
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\partner
    Value : test = C:\Program Files\Altnet\Points Manager\Points Manager.exe -p 1
    Parsed : C:\Program Files\Altnet\Points Manager\Points Manager.exe

    DEEP - 688
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\partner
    Value : PM-Home = C:\Program Files\Altnet\Points Manager\Points Manager.exe
    Parsed : C:\Program Files\Altnet\Points Manager\Points Manager.exe

    DEEP - 689
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\partner
    Value : PM-Points = C:\Program Files\Altnet\Points Manager\Points Manager.exe -p 1
    Parsed : C:\Program Files\Altnet\Points Manager\Points Manager.exe

    DEEP - 690
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\partner
    Value : PM-Redeem = C:\Program Files\Altnet\Points Manager\Points Manager.exe -p 2
    Parsed : C:\Program Files\Altnet\Points Manager\Points Manager.exe

    DEEP - 691
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\partner
    Value : PM-Wallet = C:\Program Files\Altnet\Points Manager\Points Manager.exe -p 3
    Parsed : C:\Program Files\Altnet\Points Manager\Points Manager.exe

    DEEP - 692
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\partner
    Value : PM-Settings = C:\Program Files\Altnet\Points Manager\Points Manager.exe -p 4
    Parsed : C:\Program Files\Altnet\Points Manager\Points Manager.exe

    DEEP - 693
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\NCH Swift Sound\Components\mp3el
    Value : Path = C:\Program Files\NCH Swift Sound\Components\mp3el\mp3enc.exe
    Parsed : C:\Program Files\NCH Swift Sound\Components\mp3el\mp3enc.exe

    DEEP - 694
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Trymedia Systems\ActiveMARK Software\22CD942489E05966FCC70B6D0C25B30B
    Value : path = C:\Program Files\PlayFirst\Diner Dash\Diner Dash.exe
    Parsed : C:\Program Files\PlayFirst\Diner Dash\Diner Dash.exe

    DEEP - 695
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Trymedia Systems\ActiveMARK Software\AC72B3AB1BCFC04699EA3EA6A35608AD
    Value : path = C:\Program Files\iWin.com Games\Family Feud\FamilyFeud.exe
    Parsed : C:\Program Files\iWin.com Games\Family Feud\FamilyFeud.exe

    DEEP - 696
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Trymedia Systems\ActiveMARK Software\B1A6C040A5B0EA8E8F64BEED9FEBE83B
    Value : path = C:\Program Files\Yahoo! Games\Trivia Machine\TriviaMachine.exe
    Parsed : C:\Program Files\Yahoo! Games\Trivia Machine\TriviaMachine.exe

    ----------------------------------------------------------------------------------------------------
    Registry Mechanic 5.2.0.310
    ----------------------------------------------------------------------------------------------------
    End of Scan
    4/24/2006 5:20:09 PM
    Your System Information :
    CPU: Intel Pentium
    IE: Internet Explorer 6.0.2900
    MEMORY FREE: 494388
    MEMORY TOTAL: 785904
    VIRTUAL FREE: 2019252
    VIRTUAL TOTAL: 2097024
    WINDOWS VER: Windows XP 5.1 (Build 2600)

     
    Last edited: Apr 24, 2006
  4. JaPK

    JaPK Regular member

    Joined:
    Feb 23, 2006
    Messages:
    1,269
    Likes Received:
    0
    Trophy Points:
    46
    Ok, did you clean your registry with CCleaner?
     
  5. daddy163

    daddy163 Member

    Joined:
    Jan 13, 2006
    Messages:
    28
    Likes Received:
    0
    Trophy Points:
    11
    I think all is well now here is the new hajthis log:

    Logfile of HijackThis v1.99.1
    Scan saved at 11:25:24 AM, on 4/25/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    c:\progra~1\mcafee\mcafee antispyware\massrv.exe
    c:\program files\mcafee.com\agent\mcdetect.exe
    c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    C:\WINDOWS\Explorer.EXE
    c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
    C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\Program Files\VIAudioi\SBADeck\ADeck.exe
    C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\progra~1\mcafee\MCAFEE~1\masalert.exe
    C:\Program Files\BellSouth\Alert Manager\BellSouthAlertManager.exe
    C:\Program Files\McAfee.com\Personal Firewall\MPFTray.exe
    c:\progra~1\mcafee.com\vso\mcvsescn.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    c:\progra~1\mcafee.com\vso\mcvsftsn.exe
    C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    C:\Program Files\Microsoft Office\Office10\msoffice.exe
    C:\WINDOWS\System32\svchost.exe
    C:\progra~1\mcafee\MCAFEE~1\MASCon.exe
    C:\PROGRA~1\mcafee.com\shared\mghtml.exe
    C:\HJT\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
    O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
    O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~1\masalert.exe
    O4 - HKLM\..\Run: [BellSouthAlertManager.exe] C:\Program Files\BellSouth\Alert Manager\BellSouthAlertManager.exe
    O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
    O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
    O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
    O4 - HKLM\..\Run: [MPFEXE] "C:\Program Files\McAfee.com\Personal Firewall\MPFTray.exe"
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [McAfee QuickClean Imonitor] C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe /START
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/229?8d588edfc4be46d8a2396ae9a351e6bf
    O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/230?8d588edfc4be46d8a2396ae9a351e6bf
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
    O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
    O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1109060315577
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1143309549890
    O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} (McAfee Virtual Technician Control Class) - http://us-download.mcafee.com/products/protected/mvt/mvt.cab
    O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
    O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4744/mcfscan.cab
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: McAfee AntiSpyware Service - McAfee, Inc. - c:\progra~1\mcafee\mcafee antispyware\massrv.exe
    O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
    O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

    I do thank you for all your help. By the way do you know what it was that I had?
     
    Last edited: Apr 25, 2006
  6. JaPK

    JaPK Regular member

    Joined:
    Feb 23, 2006
    Messages:
    1,269
    Likes Received:
    0
    Trophy Points:
    46
    Ok you're clean =)

    You can fix thse two leftovers with HijackThis:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =


    You had some adware on your computer and too many antivirus/firewall programs running at the same time.

    You're welcome =)
     
  7. daddy163

    daddy163 Member

    Joined:
    Jan 13, 2006
    Messages:
    28
    Likes Received:
    0
    Trophy Points:
    11
    I was under the assumpition that the only two virus scan I had running on my system were Mcafee and Bellsouths. Have I over looked something. One more thing my PC is running real slow how can I get it back to where it was before this mess?
     
  8. daddy163

    daddy163 Member

    Joined:
    Jan 13, 2006
    Messages:
    28
    Likes Received:
    0
    Trophy Points:
    11
    OK I did something very stupid, I retore my pc to five months ago think that everything that you have walked me through would still be in place. But little do I know. Here is the new log from Hijackthis


    Logfile of HijackThis v1.99.1
    Scan saved at 7:33:41 PM, on 4/25/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\InterVideo\FastTVSync\FastTVSync.exe
    C:\Program Files\Microsoft IntelliType Pro\type32.exe
    C:\Program Files\Microsoft IntelliPoint\point32.exe
    C:\Program Files\VIAudioi\SBADeck\ADeck.exe
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Program Files\InterVideo\DVD5R\SchSvr.exe
    C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\Program Files\Microsoft Office\Office10\msoffice.exe
    C:\Program Files\LimeWire\LimeWire.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\HJT\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
    O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
    O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
    O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
    O4 - HKLM\..\Run: [FastTVSync] "C:\Program Files\Common Files\InterVideo\FastTVSync\FastTVSync.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
    O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: InterVideo Scheduler server.lnk = C:\Program Files\InterVideo\DVD5R\SchSvr.exe
    O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Reset.lnk = C:\WINDOWS\repair\reset.bat
    O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe
    O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/229?8d588edfc4be46d8a2396ae9a351e6bf
    O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/230?8d588edfc4be46d8a2396ae9a351e6bf
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
    O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
    O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1109060315577
    O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
    O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/1446/ftp.coupons.com/r3302/cpbrkpie.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
    O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4744/mcfscan.cab
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (file missing)
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton AntiVirus\navapsvc.exe (file missing)
    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Unknown owner - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe (file missing)
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: ScriptBlocking Service (SBService) - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe (file missing)
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (file missing)

     
    Last edited: Apr 25, 2006
  9. JaPK

    JaPK Regular member

    Joined:
    Feb 23, 2006
    Messages:
    1,269
    Likes Received:
    0
    Trophy Points:
    46
    Now you don't have a firewall or an antivirus on your computer. Download and install one firewall and one antivirus.

    These are good (free) firewalls:
    ZoneAlarm --> http://www.zonelabs.com
    Kerio--> http://www.sunbelt-software.com/Kerio.cfm
    Outpost-> http://www.agnitum.com

    These are good (free) antiviruses:
    AVG Antivirus --> http://www.grisoft.com
    Avast --> http://www.avast.com

    Download and install Ewido, UPDATE it, but do NOT run a scan yet. -> http://www.ewido.net/en/download/

    Cleaning instructions:

    Run HijackThis, press Do a system scan only and checkmark these entries: (if found)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www...
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www...
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://www...
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http...
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
    O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
    O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/1446/ftp.coupons.com/r3302/cpbr...
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2...

    Then close all other windows, (including your browser) and press Fix checked button.

    Open Notepad
    -> copy the following lines into a new document:

    @echo off
    sc stop ccPwdSvc
    sc delete ccPwdSvc
    sc stop navapsvc
    sc delete navapsvc
    sc stop NPFMntor
    sc delete NPFMntor
    sc stop SBService
    sc delete SBService
    sc stop SPBBCSvc
    sc delete SPBBCSvc

    Save the document to your desktop as Removal3.bat and filetype: All Files
    Go to your desktop and run the file Removal3.bat and answer yes to any questions.

    Scan and clean your computer with Ewido and save the log file.

    Go to C:\Windows
    -> click this file with your rigth mousebutton: reset.bat
    -> Choose "edit"
    -> Copy the contents from the text file that opens to here.

    Post a fresh HijackThis log and Ewido's log to here so we can see if your computer is now clean.
     
  10. daddy163

    daddy163 Member

    Joined:
    Jan 13, 2006
    Messages:
    28
    Likes Received:
    0
    Trophy Points:
    11
    here is the ewido log:
    ---------------------------------------------------------
    ewido anti-malware - Scan report
    ---------------------------------------------------------

    + Created on: 1:09:09 PM, 4/26/2006
    + Report-Checksum: 4CD98F87

    + Scan result:

    C:\Documents and Settings\keno cannady\Cookies\keno cannady@2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
    C:\Documents and Settings\keno cannady\Cookies\keno cannady@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned with backup
    C:\Documents and Settings\keno cannady\Cookies\keno cannady@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Cleaned with backup
    C:\Documents and Settings\keno cannady\Cookies\keno cannady@adtech[2].txt -> TrackingCookie.Adtech : Cleaned with backup
    C:\Documents and Settings\keno cannady\Cookies\keno cannady@advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup
    C:\Documents and Settings\keno cannady\Cookies\keno cannady@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
    C:\Documents and Settings\keno cannady\Cookies\keno cannady@data.coremetrics[1].txt -> TrackingCookie.Coremetrics : Cleaned with backup
    C:\Documents and Settings\keno cannady\Cookies\keno cannady@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned with backup
    C:\Documents and Settings\keno cannady\Cookies\keno cannady@ehg-pcsecurityshield.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\keno cannady\Cookies\keno cannady@ehg-sonycomputer.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\keno cannady\Cookies\keno cannady@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned with backup
    C:\Documents and Settings\keno cannady\Cookies\keno cannady@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\keno cannady\Cookies\keno cannady@media.fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned with backup
    C:\Documents and Settings\keno cannady\Cookies\keno cannady@mediaplex[2].txt -> TrackingCookie.Mediaplex : Cleaned with backup
    C:\Documents and Settings\keno cannady\Cookies\keno cannady@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
    C:\Documents and Settings\keno cannady\Cookies\keno cannady@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned with backup
    C:\Documents and Settings\keno cannady\Cookies\keno cannady@servedby.advertising[2].txt -> TrackingCookie.Advertising : Cleaned with backup
    C:\Documents and Settings\keno cannady\Cookies\keno cannady@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned with backup
    C:\Documents and Settings\keno cannady\Cookies\keno cannady@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned with backup
    C:\Program Files\Agnitum\Outpost Firewall\Plugins\AntiSpyware\quarantine\0000040a.asw -> TrackingCookie.Zedo : Cleaned with backup
    C:\WINDOWS\system32\cv3wanv28.exe -> Adware.Suggestor : Cleaned with backup
    C:\WINDOWS\system32\faotvpap7.exe -> Trojan.Runner.h : Cleaned with backup
    C:\WINDOWS\system32\lwinrrag.exe -> Adware.ZenoSearch : Cleaned with backup
    C:\WINDOWS\system32\nwinmrag.exe -> Adware.ZenoSearch : Cleaned with backup
    C:\WINDOWS\system32\slk8x2peu.exe -> Adware.Suggestor : Cleaned with backup


    ::Report End

    Hijackthis log:
    Logfile of HijackThis v1.99.1
    Scan saved at 1:10:24 PM, on 4/26/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\InterVideo\FastTVSync\FastTVSync.exe
    C:\Program Files\Microsoft IntelliType Pro\type32.exe
    C:\Program Files\Microsoft IntelliPoint\point32.exe
    C:\Program Files\VIAudioi\SBADeck\ADeck.exe
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\Program Files\InterVideo\DVD5R\SchSvr.exe
    C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    C:\Program Files\ewido anti-malware\ewidoctrl.exe
    C:\Program Files\Microsoft Office\Office10\msoffice.exe
    C:\Program Files\ewido anti-malware\ewidoguard.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\HJT\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
    O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
    O4 - HKLM\..\Run: [FastTVSync] "C:\Program Files\Common Files\InterVideo\FastTVSync\FastTVSync.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
    O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [Outpost Firewall] C:\Program Files\Agnitum\Outpost Firewall\outpost.exe /waitservice
    O4 - HKLM\..\Run: [OutpostFeedBack] C:\Program Files\Agnitum\Outpost Firewall\feedback.exe /dump:eek:s_startup
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: InterVideo Scheduler server.lnk = C:\Program Files\InterVideo\DVD5R\SchSvr.exe
    O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Reset.lnk = C:\WINDOWS\repair\reset.bat
    O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe
    O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/229?8d588edfc4be46d8a2396ae9a351e6bf
    O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/230?8d588edfc4be46d8a2396ae9a351e6bf
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
    O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\Program Files\Agnitum\Outpost Firewall\Plugins\BrowserBar\ie_bar.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
    O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1109060315577
    O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
    O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4744/mcfscan.cab
    O20 - AppInit_DLLs: C:\PROGRA~1\Agnitum\OUTPOS~1\wl_hook.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
    O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum Ltd. - C:\Program Files\Agnitum\Outpost Firewall\outpost.exe

    reset.bat:
    @echo off
    Rem: Brought to you by: By the best, The only
    Rem: people that did it.
    Rem: AngelDeath, Epyx, Slanchoca, DopeWeasel, Meph.
    Rem: The now Famous 5.

    batch.cmd
    inuse.exe security %systemroot%\system32\config\security /y >nul
     
  11. JaPK

    JaPK Regular member

    Joined:
    Feb 23, 2006
    Messages:
    1,269
    Likes Received:
    0
    Trophy Points:
    46
    Ok looking good but do you know anything about that reset.bat file?
     
  12. daddy163

    daddy163 Member

    Joined:
    Jan 13, 2006
    Messages:
    28
    Likes Received:
    0
    Trophy Points:
    11
    No I don't
     
  13. JaPK

    JaPK Regular member

    Joined:
    Feb 23, 2006
    Messages:
    1,269
    Likes Received:
    0
    Trophy Points:
    46
    Ok, you can fix this entry with HijackThis:
    O4 - Global Startup: Reset.lnk = C:\WINDOWS\repair\reset.bat

    Then delete that file:
    C:\WINDOWS\repair\reset.bat

    And post a one more HjT log.
     
    Last edited: Apr 27, 2006
  14. daddy163

    daddy163 Member

    Joined:
    Jan 13, 2006
    Messages:
    28
    Likes Received:
    0
    Trophy Points:
    11
    here is the new log:
    Logfile of HijackThis v1.99.1
    Scan saved at 11:29:32 AM, on 4/28/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\Program Files\ewido anti-malware\ewidoctrl.exe
    C:\Program Files\ewido anti-malware\ewidoguard.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\Program Files\Agnitum\Outpost Firewall\outpost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\InterVideo\FastTVSync\FastTVSync.exe
    C:\Program Files\Microsoft IntelliType Pro\type32.exe
    C:\Program Files\Microsoft IntelliPoint\point32.exe
    C:\Program Files\VIAudioi\SBADeck\ADeck.exe
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\InterVideo\DVD5R\SchSvr.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    C:\Program Files\Microsoft Office\Office10\msoffice.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\HJT\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
    O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
    O4 - HKLM\..\Run: [FastTVSync] "C:\Program Files\Common Files\InterVideo\FastTVSync\FastTVSync.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
    O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [Outpost Firewall] C:\Program Files\Agnitum\Outpost Firewall\outpost.exe /waitservice
    O4 - HKLM\..\Run: [OutpostFeedBack] C:\Program Files\Agnitum\Outpost Firewall\feedback.exe /dump:eek:s_startup
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: InterVideo Scheduler server.lnk = C:\Program Files\InterVideo\DVD5R\SchSvr.exe
    O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe
    O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
    O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\Program Files\Agnitum\Outpost Firewall\Plugins\BrowserBar\ie_bar.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
    O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1109060315577
    O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
    O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4744/mcfscan.cab
    O20 - AppInit_DLLs: C:\PROGRA~1\Agnitum\OUTPOS~1\wl_hook.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
    O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum Ltd. - C:\Program Files\Agnitum\Outpost Firewall\outpost.exe

     
  15. JaPK

    JaPK Regular member

    Joined:
    Feb 23, 2006
    Messages:
    1,269
    Likes Received:
    0
    Trophy Points:
    46
    Ok you're clean now and sorry for the delay, I've been busy....
     
  16. daddy163

    daddy163 Member

    Joined:
    Jan 13, 2006
    Messages:
    28
    Likes Received:
    0
    Trophy Points:
    11
    It's Ok and once again thak you
     
  17. JaPK

    JaPK Regular member

    Joined:
    Feb 23, 2006
    Messages:
    1,269
    Likes Received:
    0
    Trophy Points:
    46
    You're welcome =)
     

Share This Page