Regedit,cmd, virus and spyware programs, and firefox problems. please help

Discussion in 'Windows - Virus and spyware problems' started by bbiagllla, Apr 18, 2009.

  1. bbiagllla

    bbiagllla Regular member

    Joined:
    Jul 2, 2004
    Messages:
    160
    Likes Received:
    0
    Trophy Points:
    26
    Hello all,
    I am Currently fighting a huge problem on my computer and im losing the battle. MY computer is running really really slow.

    1) when i type cmd, regedit, or even command in my run box it makes my task bar dissapear for a second or two and it never opens.

    2) None of my antivirus or spyware programs can or will update. i have to do them all manually. i can go to antivirus and spy ware sites without this thing blocking that.

    3) Firefox crashes alot randomly. i have had firefox for many years and never once gotten a pop up until now. its not really a pop up per say. i type in say google.com and it will faster than i can see go to google.com and also instantly go to another page i never typed. like ads. i hit the back button in my browser and bam there is google.com. it doesnt do it everytime either its random.

    4) My online games keep crashing due to memory errors. not sure if its due to this but they never have until now.

    5) I am getting a generic host proces for win 32 services error on startup everytime. Here is the info on that.
    C:\DOCUME~1\Owner\LOCALS~1\Temp\WER5767.dir00\svchost.exe.mdmp
    C:\DOCUME~1\Owner\LOCALS~1\Temp\WER5767.dir00\appcompat.txt

    szAppName : svchost.exe szAppVer : 5.1.2600.5512 szModName : unknown
    szModVer : 0.0.0.0 offset : 10001e39

    I have tried everything imaginable and nothing can find something. i have tried malwarebytes, SD, ad aware, avg, stinger, counterspy, a-sqyuared, cccleaner, superanitspyware, spybot S & D, registry booster, sys clean, and hijack this. Nothing can be found. Any suggestions, tips, or solutions? id appreciate it alot.


    update:
    A-squared found alot of stuff as did superantispyware. However after running them in safe mode and quarantining the bads. it still is not fixed. here is my hijack this log.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 2:55:42 AM, on 4/19/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
    Boot mode: Safe mode

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Sunbelt Software\CounterSpy\SBAMSvc.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sbc.yahoo.com/dsl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - G:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [WinPatrol] G:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
    O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
    O4 - HKLM\..\Run: [Launch LCDMon] G:\Program Files\Logitech\G-series Software\LCDMon.exe
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
    O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
    O4 - HKLM\..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\CounterSpy\SBAMTray.exe
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - HKCU\..\Run: [CurseClient] G:\Program Files\Curse\CurseClient.exe -silent
    O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] G:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - Startup: 2WireSetup.lnk = C:\Program Files\2Wire\WebWorks.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
    O4 - Global Startup: SetPointII.lnk = ?
    O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\WINDOWS\system32\shdocvw.dll (HKCU)
    O16 - DPF: Yahoo! Dominoes - http://download.games.yahoo.com/games/clients/y/dot4_x.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1106352626076
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1180917515156
    O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nick.com/common/groove/gx/GrooveAX27.cab
    O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - AppInit_DLLs: c:\windows\system32\puzatuwi.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
    O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
    O23 - Service: MSSQLServerADHelper - Unknown owner - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe (file missing)
    O23 - Service: CounterSpy Antispyware (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBAMSvc.exe
    O23 - Service: STOPzilla Service (szserver) - Unknown owner - (no file)
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

    --
    End of file - 9050 bytes


    HERE IS WHAT A-SQUARED FOUND:

    a-squared Free - Version 4.0
    Last update: 4/18/2009 2:39:17 PM

    Scan settings:

    Objects: Memory, Traces, Cookies, C:\, G:\
    Scan archives: On
    Heuristics: Off
    ADS Scan: On

    Scan start: 4/18/2009 3:09:54 PM

    Value: HKEY_CLASSES_ROOT\CLSID\{183261F8-780B-4506-BE91-434C01DD010A}\InprocServer32 --> ThreadingModel detected: Trace.Registry.Remotely Anywhere Server Edition!A2
    Value: HKEY_CLASSES_ROOT\CLSID\{43534152-0000-0010-8000-00AA00389B71}\InprocServer32 --> ThreadingModel detected: Trace.Registry.Remotely Anywhere Server Edition!A2
    Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{183261F8-780B-4506-BE91-434C01DD010A}\InprocServer32 --> ThreadingModel detected: Trace.Registry.Remotely Anywhere Server Edition!A2
    Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{43534152-0000-0010-8000-00AA00389B71}\InprocServer32 --> ThreadingModel detected: Trace.Registry.Remotely Anywhere Server Edition!A2
    Value: HKEY_USERS\.DEFAULT\Software\Viewpoint\Content Debugger --> Viewpoint Manager detected: Trace.Registry.Viewpoint Media Toolbar!A2
    Value: HKEY_USERS\S-1-5-18\Software\Viewpoint\Content Debugger --> Viewpoint Manager detected: Trace.Registry.Viewpoint Media Toolbar!A2
    Value: HKEY_USERS\.DEFAULT\Software\Viewpoint\Content Debugger --> Viewpoint Manager Installer detected: Trace.Registry.Viewpoint Media Toolbar!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\Viewpoint\Content Debugger --> Viewpoint Manager Installer detected: Trace.Registry.Viewpoint Media Toolbar!A2
    Value: HKEY_USERS\S-1-5-18\Software\Viewpoint\Content Debugger --> Viewpoint Manager Installer detected: Trace.Registry.Viewpoint Media Toolbar!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station23 --> StationCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station23 --> StationID detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station23 --> StationName detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station23 --> ZIPCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station24 --> ConnectionType detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station24 --> Distance detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station24 --> NationalLink detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station24 --> StationCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station24 --> StationID detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station24 --> StationName detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station24 --> ZIPCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station3 --> ConnectionType detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station3 --> Distance detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station3 --> NationalLink detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station3 --> StationCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station3 --> StationID detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station3 --> StationName detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station3 --> ZIPCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station4 --> ConnectionType detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station4 --> Distance detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station4 --> NationalLink detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station4 --> StationCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station4 --> StationID detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station4 --> StationName detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station4 --> ZIPCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station5 --> ConnectionType detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station5 --> Distance detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station5 --> NationalLink detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station5 --> StationCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station5 --> StationID detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station5 --> StationName detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station5 --> ZIPCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station6 --> ConnectionType detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station6 --> Distance detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station6 --> NationalLink detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station6 --> StationCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station6 --> StationID detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station6 --> StationName detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station6 --> ZIPCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station7 --> ConnectionType detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station7 --> Distance detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station7 --> NationalLink detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station7 --> StationCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station7 --> StationID detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station7 --> StationName detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station7 --> ZIPCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station8 --> ConnectionType detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station8 --> Distance detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station8 --> NationalLink detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station8 --> StationCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station8 --> StationID detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station8 --> StationName detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station8 --> ZIPCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station9 --> ConnectionType detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station9 --> Distance detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station9 --> NationalLink detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station9 --> StationCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station9 --> StationID detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station9 --> StationName detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station9 --> ZIPCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Warning --> TVNetwork detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Warning --> UserWarningIcon detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Warning --> UserWarningURL detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Warning --> WarningIcon detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Warning --> WarningInterval detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Warning --> WarningURL detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Cam --> CamURL detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Command --> GetCompactDataURL detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Command --> GetDataURL detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Command --> GetDesignURL detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Command --> GetDesignURLASP detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Command --> GetForecastURL detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Command --> GetStationURL detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Command --> GetWarningURL detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\CurrentStation --> ConnectionType detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\CurrentStation --> CurrentStation detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\CurrentStation --> Distance detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\CurrentStation --> NationalLink detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\CurrentStation --> StationCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\CurrentStation --> StationID detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\CurrentStation --> StationName detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\CurrentStation --> ZIPCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> AdDormantFreshInterval detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> AdFreshInterval detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> AffiliateClick detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> AffiliateLogo detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> AffiliateLogoSize detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> ArrowB detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> ArrowG detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> ArrowR detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> BackgroundImage detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> BackSize detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> BottomADURL detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> BottomBranding detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> BottomBrandingClick detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> BottomBrandSize detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> ConditionB detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> ConditionG detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> ConditionR detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> ConditionShadowB detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> ConditionShadowDepth detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> ConditionShadowG detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> ConditionShadowR detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> DataB detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> DataG detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> DataR detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> DataShadownB detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> DataShadownDepth detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> DataShadownG detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> DataShadownR detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> DesignInterval detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> FillerB detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> FillerG detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> FillerR detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> LA detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> LastPopupID detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> LastSoundID detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> PMClicks detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> ShowTd detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> TdInterval detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> TdURL detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> TimeToDormant detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> TopADURL detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> TopBranding detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> TopBrandingClick detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> TopBrandSize detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Forecast --> Interval detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Forecast --> Sunrise detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Forecast --> Sunset detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Forecast --> TodayCondition detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Forecast --> TodayHi detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Forecast --> TodayLo detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Forecast --> TodayTitle detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Forecast --> TomorrowCondition detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Forecast --> TomorrowHi detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Forecast --> TomorrowLo detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Forecast --> TomorrowTitle detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> CLinkName0 detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> CLinkName1 detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> CLinkName2 detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> CLinkName3 detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> CLinkName4 detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> CLinkURL0 detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> CLinkURL1 detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> CLinkURL2 detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> CLinkURL3 detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> CLinkURL4 detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> CoolURL detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> CustomLinkNum detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> FiveDayURL detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> NationalURL detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> RadarURL detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Options --> CheckInstance detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Setup --> StationNum detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Setup --> UNIT detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Setup --> x detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Setup --> y detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Setup --> ZIPCode detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station0 --> ConnectionType detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station0 --> Distance detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station0 --> NationalLink detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station0 --> StationCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station0 --> StationID detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station0 --> StationName detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station0 --> ZIPCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station1 --> ConnectionType detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station1 --> Distance detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station1 --> NationalLink detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station1 --> StationCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station1 --> StationID detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station1 --> StationName detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station1 --> ZIPCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station10 --> ConnectionType detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station10 --> Distance detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station10 --> NationalLink detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station10 --> StationCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station10 --> StationID detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station10 --> StationName detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station10 --> ZIPCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station11 --> ConnectionType detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station11 --> Distance detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station11 --> NationalLink detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station11 --> StationCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station11 --> StationID detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station11 --> StationName detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station11 --> ZIPCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station12 --> ConnectionType detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station12 --> Distance detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station12 --> NationalLink detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station12 --> StationCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station12 --> StationID detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station12 --> StationName detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station12 --> ZIPCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station13 --> ConnectionType detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station13 --> Distance detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station13 --> NationalLink detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station13 --> StationCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station13 --> StationID detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station13 --> StationName detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station13 --> ZIPCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station14 --> ConnectionType detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station14 --> Distance detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station14 --> NationalLink detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station14 --> StationCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station14 --> StationID detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station14 --> StationName detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station14 --> ZIPCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station15 --> ConnectionType detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station15 --> Distance detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station15 --> NationalLink detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station15 --> StationCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station15 --> StationID detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station15 --> StationName detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station15 --> ZIPCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station16 --> ConnectionType detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station16 --> Distance detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station16 --> NationalLink detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station16 --> StationCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station16 --> StationID detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station16 --> StationName detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station16 --> ZIPCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station17 --> ConnectionType detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station17 --> Distance detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station17 --> NationalLink detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station17 --> StationCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station17 --> StationID detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station17 --> StationName detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station17 --> ZIPCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station18 --> ConnectionType detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station18 --> Distance detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station18 --> NationalLink detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station18 --> StationCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station18 --> StationID detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station18 --> StationName detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station18 --> ZIPCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station19 --> ConnectionType detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station19 --> Distance detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station19 --> NationalLink detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station19 --> StationCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station19 --> StationID detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station19 --> StationName detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station19 --> ZIPCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station2 --> ConnectionType detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station2 --> Distance detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station2 --> NationalLink detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station2 --> StationCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station2 --> StationID detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station2 --> StationName detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station2 --> ZIPCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station20 --> ConnectionType detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station20 --> Distance detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station20 --> NationalLink detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station20 --> StationCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station20 --> StationID detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station20 --> StationName detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station20 --> ZIPCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station21 --> ConnectionType detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station21 --> Distance detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station21 --> NationalLink detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station21 --> StationCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station21 --> StationID detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station21 --> StationName detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station21 --> ZIPCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station22 --> ConnectionType detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station22 --> Distance detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station22 --> NationalLink detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station22 --> StationCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station22 --> StationID detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station22 --> StationName detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station22 --> ZIPCityState detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station23 --> ConnectionType detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station23 --> Distance detected: Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station23 --> NationalLink detected: Trace.Registry.WeatherBug!A2
    c:\documents and settings\all users\start menu\programs\bittorrent detected: Trace.Directory.Bittorrent 5.0!A2
    c:\documents and settings\all users\start menu\programs\bittorrent\bittorrent.lnk detected: Trace.File.Bittorrent 5.0!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Bittorrent --> Order detected: Trace.Registry.Bittorrent 5.0!A2
    C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\teqq08ca.default\cookies.sqlite:1240081240400125 detected: Trace.TrackingCookie.humanclick!A2
    C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\teqq08ca.default\cookies.sqlite:1240081240400127 detected: Trace.TrackingCookie.humanclick!A2
    C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\teqq08ca.default\cookies.sqlite:1240081240509500 detected: Trace.TrackingCookie.humanclick!A2
    C:\Documents and Settings\Owner\My Documents\Downloads\Slipknot - All Hope Is Gone (2008)\14. Vermilion Pt.2(Bloodstone Mix) (Bonus track ).mp3 detected: Trojan.Wimad!IK
    C:\hp\bin\AUTOPLAY.EXE detected: Virus.Win32.Trojan!IK
    C:\Program Files\2Wire\sst\VNC\MotVNC.exe detected: Riskware.RemoteAdmin.Win32.WinVNC-based!IK
    C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP172\A0027884.exe detected: Riskware.RemoteAdmin.Win32.WinVNC-based!IK
    C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP200\A0036462.exe detected: Riskware.AdWare.Win32.Accoona.a!IK
    C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP208\A0037204.DLL detected: AdWare.Win32.MyQuickSearchSearchAssistant!IK
    C:\WINDOWS\xusx.qgr detected: Trojan-PWS.Delf!IK
    C:\WINDOWS\xusx.qgrx detected: Trojan-PWS.Delf!IK
    C:\WINDOWS\xusx.qgrxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx detected: Trojan-PWS.Delf!IK
    G:\Program Files\BearShare\Installer\BSInstall5.2.5.1.exe detected: Riskware.AdWare.Win32.180Solutions.ao!IK

    Scanned

    Files: 218530
    Traces: 672995
    Cookies: 262
    Processes: 66

    Found

    Files: 10
    Traces: 285
    Cookies: 3
    Processes: 0
    Registry keys: 0

    Scan end: 4/18/2009 11:16:57 PM
    Scan time: 8:07:03

    G:\Program Files\BearShare\Installer\BSInstall5.2.5.1.exe Quarantined Riskware.AdWare.Win32.180Solutions.ao!IK
    C:\WINDOWS\xusx.qgr Quarantined Trojan-PWS.Delf!IK
    C:\WINDOWS\xusx.qgrx Quarantined Trojan-PWS.Delf!IK
    C:\WINDOWS\xusx.qgrxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx Quarantined Trojan-PWS.Delf!IK
    C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP208\A0037204.DLL Quarantined AdWare.Win32.MyQuickSearchSearchAssistant!IK
    C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP200\A0036462.exe Quarantined Riskware.AdWare.Win32.Accoona.a!IK
    C:\Program Files\2Wire\sst\VNC\MotVNC.exe Quarantined Riskware.RemoteAdmin.Win32.WinVNC-based!IK
    C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP172\A0027884.exe Quarantined Riskware.RemoteAdmin.Win32.WinVNC-based!IK
    C:\hp\bin\AUTOPLAY.EXE Quarantined Virus.Win32.Trojan!IK
    C:\Documents and Settings\Owner\My Documents\Downloads\Slipknot - All Hope Is Gone (2008)\14. Vermilion Pt.2(Bloodstone Mix) (Bonus track ).mp3 Quarantined Trojan.Wimad!IK
    C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\teqq08ca.default\cookies.sqlite:1240081240400125 Quarantined Trace.TrackingCookie.humanclick!A2
    C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\teqq08ca.default\cookies.sqlite:1240081240400127 Quarantined Trace.TrackingCookie.humanclick!A2
    C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\teqq08ca.default\cookies.sqlite:1240081240509500 Quarantined Trace.TrackingCookie.humanclick!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Bittorrent --> Order Quarantined Trace.Registry.Bittorrent 5.0!A2
    c:\documents and settings\all users\start menu\programs\bittorrent\bittorrent.lnk Quarantined Trace.File.Bittorrent 5.0!A2
    c:\documents and settings\all users\start menu\programs\bittorrent Quarantined Trace.Directory.Bittorrent 5.0!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station23 --> StationCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station23 --> StationID Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station23 --> StationName Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station23 --> ZIPCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station24 --> ConnectionType Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station24 --> Distance Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station24 --> NationalLink Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station24 --> StationCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station24 --> StationID Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station24 --> StationName Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station24 --> ZIPCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station3 --> ConnectionType Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station3 --> Distance Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station3 --> NationalLink Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station3 --> StationCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station3 --> StationID Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station3 --> StationName Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station3 --> ZIPCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station4 --> ConnectionType Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station4 --> Distance Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station4 --> NationalLink Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station4 --> StationCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station4 --> StationID Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station4 --> StationName Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station4 --> ZIPCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station5 --> ConnectionType Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station5 --> Distance Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station5 --> NationalLink Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station5 --> StationCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station5 --> StationID Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station5 --> StationName Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station5 --> ZIPCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station6 --> ConnectionType Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station6 --> Distance Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station6 --> NationalLink Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station6 --> StationCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station6 --> StationID Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station6 --> StationName Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station6 --> ZIPCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station7 --> ConnectionType Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station7 --> Distance Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station7 --> NationalLink Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station7 --> StationCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station7 --> StationID Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station7 --> StationName Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station7 --> ZIPCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station8 --> ConnectionType Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station8 --> Distance Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station8 --> NationalLink Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station8 --> StationCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station8 --> StationID Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station8 --> StationName Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station8 --> ZIPCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station9 --> ConnectionType Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station9 --> Distance Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station9 --> NationalLink Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station9 --> StationCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station9 --> StationID Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station9 --> StationName Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station9 --> ZIPCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Warning --> TVNetwork Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Warning --> UserWarningIcon Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Warning --> UserWarningURL Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Warning --> WarningIcon Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Warning --> WarningInterval Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Warning --> WarningURL Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Cam --> CamURL Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Command --> GetCompactDataURL Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Command --> GetDataURL Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Command --> GetDesignURL Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Command --> GetDesignURLASP Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Command --> GetForecastURL Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Command --> GetStationURL Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Command --> GetWarningURL Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\CurrentStation --> ConnectionType Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\CurrentStation --> CurrentStation Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\CurrentStation --> Distance Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\CurrentStation --> NationalLink Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\CurrentStation --> StationCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\CurrentStation --> StationID Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\CurrentStation --> StationName Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\CurrentStation --> ZIPCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> AdDormantFreshInterval Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> AdFreshInterval Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> AffiliateClick Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> AffiliateLogo Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> AffiliateLogoSize Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> ArrowB Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> ArrowG Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> ArrowR Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> BackgroundImage Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> BackSize Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> BottomADURL Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> BottomBranding Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> BottomBrandingClick Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> BottomBrandSize Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> ConditionB Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> ConditionG Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> ConditionR Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> ConditionShadowB Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> ConditionShadowDepth Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> ConditionShadowG Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> ConditionShadowR Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> DataB Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> DataG Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> DataR Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> DataShadownB Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> DataShadownDepth Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> DataShadownG Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> DataShadownR Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> DesignInterval Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> FillerB Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> FillerG Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> FillerR Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> LA Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> LastPopupID Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> LastSoundID Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> PMClicks Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> ShowTd Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> TdInterval Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> TdURL Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> TimeToDormant Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> TopADURL Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> TopBranding Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> TopBrandingClick Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Design --> TopBrandSize Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Forecast --> Interval Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Forecast --> Sunrise Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Forecast --> Sunset Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Forecast --> TodayCondition Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Forecast --> TodayHi Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Forecast --> TodayLo Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Forecast --> TodayTitle Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Forecast --> TomorrowCondition Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Forecast --> TomorrowHi Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Forecast --> TomorrowLo Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Forecast --> TomorrowTitle Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> CLinkName0 Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> CLinkName1 Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> CLinkName2 Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> CLinkName3 Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> CLinkName4 Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> CLinkURL0 Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> CLinkURL1 Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> CLinkURL2 Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> CLinkURL3 Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> CLinkURL4 Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> CoolURL Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> CustomLinkNum Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> FiveDayURL Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> NationalURL Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Links --> RadarURL Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Options --> CheckInstance Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Setup --> StationNum Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Setup --> UNIT Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Setup --> x Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Setup --> y Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Setup --> ZIPCode Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station0 --> ConnectionType Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station0 --> Distance Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station0 --> NationalLink Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station0 --> StationCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station0 --> StationID Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station0 --> StationName Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station0 --> ZIPCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station1 --> ConnectionType Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station1 --> Distance Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station1 --> NationalLink Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station1 --> StationCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station1 --> StationID Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station1 --> StationName Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station1 --> ZIPCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station10 --> ConnectionType Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station10 --> Distance Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station10 --> NationalLink Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station10 --> StationCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station10 --> StationID Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station10 --> StationName Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station10 --> ZIPCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station11 --> ConnectionType Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station11 --> Distance Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station11 --> NationalLink Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station11 --> StationCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station11 --> StationID Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station11 --> StationName Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station11 --> ZIPCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station12 --> ConnectionType Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station12 --> Distance Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station12 --> NationalLink Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station12 --> StationCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station12 --> StationID Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station12 --> StationName Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station12 --> ZIPCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station13 --> ConnectionType Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station13 --> Distance Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station13 --> NationalLink Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station13 --> StationCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station13 --> StationID Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station13 --> StationName Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station13 --> ZIPCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station14 --> ConnectionType Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station14 --> Distance Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station14 --> NationalLink Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station14 --> StationCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station14 --> StationID Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station14 --> StationName Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station14 --> ZIPCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station15 --> ConnectionType Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station15 --> Distance Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station15 --> NationalLink Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station15 --> StationCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station15 --> StationID Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station15 --> StationName Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station15 --> ZIPCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station16 --> ConnectionType Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station16 --> Distance Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station16 --> NationalLink Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station16 --> StationCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station16 --> StationID Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station16 --> StationName Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station16 --> ZIPCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station17 --> ConnectionType Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station17 --> Distance Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station17 --> NationalLink Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station17 --> StationCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station17 --> StationID Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station17 --> StationName Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station17 --> ZIPCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station18 --> ConnectionType Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station18 --> Distance Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station18 --> NationalLink Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station18 --> StationCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station18 --> StationID Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station18 --> StationName Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station18 --> ZIPCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station19 --> ConnectionType Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station19 --> Distance Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station19 --> NationalLink Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station19 --> StationCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station19 --> StationID Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station19 --> StationName Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station19 --> ZIPCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station2 --> ConnectionType Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station2 --> Distance Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station2 --> NationalLink Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station2 --> StationCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station2 --> StationID Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station2 --> StationName Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station2 --> ZIPCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station20 --> ConnectionType Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station20 --> Distance Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station20 --> NationalLink Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station20 --> StationCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station20 --> StationID Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station20 --> StationName Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station20 --> ZIPCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station21 --> ConnectionType Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station21 --> Distance Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station21 --> NationalLink Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station21 --> StationCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station21 --> StationID Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station21 --> StationName Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station21 --> ZIPCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station22 --> ConnectionType Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station22 --> Distance Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station22 --> NationalLink Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station22 --> StationCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station22 --> StationID Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station22 --> StationName Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station22 --> ZIPCityState Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station23 --> ConnectionType Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station23 --> Distance Quarantined Trace.Registry.WeatherBug!A2
    Value: HKEY_USERS\S-1-5-21-1981001023-460486182-3293823761-1003\Software\AWS\Weather\Station23 --> NationalLink Quarantined Trace.Registry.WeatherBug!A2

    Quarantined

    Files: 10
    Traces: 285
    Cookies: 3
     
    Last edited: Apr 19, 2009
  2. ddp

    ddp Moderator Staff Member

    Joined:
    Oct 15, 2004
    Messages:
    39,167
    Likes Received:
    136
    Trophy Points:
    143
    moved to correct forum
     
  3. bbiagllla

    bbiagllla Regular member

    Joined:
    Jul 2, 2004
    Messages:
    160
    Likes Received:
    0
    Trophy Points:
    26
    good news is i don't have to worry about the viruses for now. Bad news is i try to system restore and when it restarted i get a master record boot error.

    *** i fixed the boot issue. had to restore the mbr's via xp cd.

    here is the log from my malwarebytes. No other attempt has found anything. tried 6 times.

    Malwarebytes' Anti-Malware 1.36
    Database version: 1945
    Windows 5.1.2600 Service Pack 3

    4/14/2009 8:07:04 PM
    mbam-log-2009-04-14 (20-07-04).txt

    Scan type: Full Scan (C:\|G:\|)
    Objects scanned: 174603
    Time elapsed: 2 hour(s), 58 minute(s), 24 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 20
    Registry Values Infected: 0
    Registry Data Items Infected: 1
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{2763e333-b168-41a0-a112-d35f96f410c0} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Typelib\{621feacd-8857-43a6-ae26-451d670d5370} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2eff3cf7-99c1-4c29-bc2b-68e057e22340} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\funwebproducts.shellviewcontrol (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\funwebproducts.shellviewcontrol.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

     
    Last edited: Apr 19, 2009
  4. bbiagllla

    bbiagllla Regular member

    Joined:
    Jul 2, 2004
    Messages:
    160
    Likes Received:
    0
    Trophy Points:
    26
    hmm thanks for the help. i got it fixed.
     

Share This Page