Help - Search - Members - Calendar
Full Version: Strange .cab file in Root
MSFN Forums > Software, Hardware, Media and Games Central > Malware Prevention and Security

   
Google Internet Forums Unattended CD/DVD Guide
JoeGons
I found this in the Root directory.
What is it?

e23a0e86-07c3-4b8d-a399-232f849c5f73.cab

containing;

e23a0e86-07c3-4b8d-a399-232f849c5f73.xml

This is the content of .xml (in text form).

CODE
<?xml version="1.0" encoding="UTF-8" standalone="no" ?>
- <UPLOADINFO>
  <UPLOADDATA USERNAME="e23a0e86-07c3-4b8d-a399-232f849c5f73" PRODUCTID="Sdc User" PRODUCTNAME="supportal" PROBLEMDESCRIPTION="Symantec ASA Index" Severity="normal" />
- <DataCollection>
- <Snapshot Timestamp="20060410141618.000000+000">
- <CIM CIMVERSION="2.0" DTDVERSION="2.0">
- <DECLARATION>
- <DECLGROUP.WITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/cimv2" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="PCH_Sysinfo">
- <KEYBINDING NAME="SystemID">
  <KEYVALUE>{fb7fd39d-68c3-4fd6-a300-90222c9d3484}</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="PCH_Sysinfo">
- <PROPERTY NAME="ClockSpeed" TYPE="uint32">
  <VALUE>2601</VALUE>
  </PROPERTY>
- <PROPERTY NAME="OSName" TYPE="string">
  <VALUE>Windows XP 5.1</VALUE>
  </PROPERTY>
- <PROPERTY NAME="OSVersion" TYPE="string">
  <VALUE>build 2600</VALUE>
  </PROPERTY>
- <PROPERTY NAME="Processor" TYPE="string">
  <VALUE>GenuineIntel</VALUE>
  </PROPERTY>
- <PROPERTY NAME="RAM" TYPE="uint64">
  <VALUE>765</VALUE>
  </PROPERTY>
- <PROPERTY NAME="SwapFile" TYPE="string">
  <VALUE>C:\pagefile.sys 1623 MB Free</VALUE>
  </PROPERTY>
- <PROPERTY NAME="SystemID" TYPE="string">
  <VALUE>{fb7fd39d-68c3-4fd6-a300-90222c9d3484}</VALUE>
  </PROPERTY>
- <PROPERTY NAME="WindowsDirectory" TYPE="string">
  <VALUE>C:\WINDOWS</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/cimv2" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="SDC_UserInfo">
- <KEYBINDING NAME="Name">
  <KEYVALUE>SDC_UserInfo</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="SDC_UserInfo">
- <PROPERTY NAME="ClientVersion" TYPE="string">
  <VALUE>0.0.0.0</VALUE>
  </PROPERTY>
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>SDC_UserInfo</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/cimv2" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Win32_LogicalMemoryConfig">
- <KEYBINDING NAME="Name">
  <KEYVALUE>Win32_LogicalMemoryConfig</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Win32_LogicalMemoryConfig">
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>Win32_LogicalMemoryConfig</VALUE>
  </PROPERTY>
- <PROPERTY NAME="TotalPhysicalMemory" TYPE="uint64">
  <VALUE>765</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/cimv2" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Win32_OperatingSystem">
- <KEYBINDING NAME="Name">
  <KEYVALUE>Win32_OperatingSystem</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Win32_OperatingSystem">
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>Win32_OperatingSystem</VALUE>
  </PROPERTY>
- <PROPERTY NAME="OSName" TYPE="string">
  <VALUE>Windows XP 5.1</VALUE>
  </PROPERTY>
- <PROPERTY NAME="OSType" TYPE="string">
  <VALUE>WinNT</VALUE>
  </PROPERTY>
- <PROPERTY NAME="OSVersion" TYPE="string">
  <VALUE>build 2600</VALUE>
  </PROPERTY>
- <PROPERTY NAME="SvcPack" TYPE="string">
  <VALUE>Service Pack 2</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/cimv2" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="BrowserInfo">
- <KEYBINDING NAME="Name">
  <KEYVALUE>BrowserInfo</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="BrowserInfo">
- <PROPERTY NAME="DefaultBrowser" TYPE="string">
  <VALUE>Internet Explorer</VALUE>
  </PROPERTY>
- <PROPERTY NAME="IEVersion" TYPE="string">
  <VALUE>6.0.2900.2180</VALUE>
  </PROPERTY>
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>BrowserInfo</VALUE>
  </PROPERTY>
- <PROPERTY NAME="NetscapeVersion" TYPE="string">
  <VALUE />
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="SDC_Connectivity">
- <KEYBINDING NAME="Name">
  <KEYVALUE>ConnectionData</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="SDC_Connectivity">
- <PROPERTY NAME="CTSTicket" TYPE="string">
  <VALUE />
  </PROPERTY>
- <PROPERTY NAME="DNSName" TYPE="string">
  <VALUE>home-gateway</VALUE>
  </PROPERTY>
- <PROPERTY NAME="Domain" TYPE="string">
  <VALUE>HOME-GATEWAY</VALUE>
  </PROPERTY>
- <PROPERTY NAME="HostName" TYPE="string">
  <VALUE>HOME-GATEWAY</VALUE>
  </PROPERTY>
- <PROPERTY NAME="MacID" TYPE="string">
  <VALUE>{fb7fd39d-68c3-4fd6-a300-90222c9d3484}</VALUE>
  </PROPERTY>
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>ConnectionData</VALUE>
  </PROPERTY>
- <PROPERTY NAME="NetBIOSName" TYPE="string">
  <VALUE>HOME-GATEWAY</VALUE>
  </PROPERTY>
- <PROPERTY NAME="OSName" TYPE="string">
  <VALUE>Windows XP 5.1</VALUE>
  </PROPERTY>
- <PROPERTY NAME="PostToQueue" TYPE="string">
  <VALUE>1</VALUE>
  </PROPERTY>
- <PROPERTY NAME="TCPIP_Address" TYPE="string">
  <VALUE>192.168.254.1</VALUE>
  </PROPERTY>
- <PROPERTY NAME="UserName" TYPE="string">
  <VALUE>Owner</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="SDC_AdditionalSysInfo">
- <KEYBINDING NAME="Name">
  <KEYVALUE>SDC_AdditionalSysInfo</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="SDC_AdditionalSysInfo">
- <PROPERTY NAME="MemoryLoad" TYPE="string">
  <VALUE>35</VALUE>
  </PROPERTY>
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>SDC_AdditionalSysInfo</VALUE>
  </PROPERTY>
- <PROPERTY NAME="NumberOfProcessors" TYPE="string">
  <VALUE>1</VALUE>
  </PROPERTY>
- <PROPERTY NAME="PageFileAvailable" TYPE="string">
  <VALUE>1623</VALUE>
  </PROPERTY>
- <PROPERTY NAME="PageFileInitialSize" TYPE="string">
  <VALUE>2304</VALUE>
  </PROPERTY>
- <PROPERTY NAME="PageFileMaxSize" TYPE="string">
  <VALUE>2304</VALUE>
  </PROPERTY>
- <PROPERTY NAME="PageFileTotal" TYPE="string">
  <VALUE>1870</VALUE>
  </PROPERTY>
- <PROPERTY NAME="Processor" TYPE="string">
  <VALUE>GenuineIntel</VALUE>
  </PROPERTY>
- <PROPERTY NAME="ProcessorArchitecture" TYPE="string">
  <VALUE>INTEL</VALUE>
  </PROPERTY>
- <PROPERTY NAME="ProcessorLevel" TYPE="string">
  <VALUE>15</VALUE>
  </PROPERTY>
- <PROPERTY NAME="ProcessorRevision" TYPE="string">
  <VALUE>521</VALUE>
  </PROPERTY>
- <PROPERTY NAME="ProcessorType" TYPE="string">
  <VALUE>PROCESSOR_INTEL_PENTIUM</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="SDC_IncidentInfo">
- <KEYBINDING NAME="Name">
  <KEYVALUE>IncidentInfo</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="SDC_IncidentInfo">
- <PROPERTY NAME="Description" TYPE="string">
  <VALUE>Symantec ASA Index</VALUE>
  </PROPERTY>
- <PROPERTY NAME="GUID" TYPE="string">
  <VALUE>e23a0e86-07c3-4b8d-a399-232f849c5f73</VALUE>
  </PROPERTY>
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>IncidentInfo</VALUE>
  </PROPERTY>
- <PROPERTY NAME="Owner" TYPE="string">
  <VALUE>Owner</VALUE>
  </PROPERTY>
- <PROPERTY NAME="Time" TYPE="string">
  <VALUE>4/10/2006 10:16:18 AM</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/cimv2" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Win32_LogicalDisk">
- <KEYBINDING NAME="DriveName">
  <KEYVALUE>C:\</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Win32_LogicalDisk">
- <PROPERTY NAME="DriveName" TYPE="string">
  <VALUE>C:\</VALUE>
  </PROPERTY>
- <PROPERTY NAME="TotalCapacity" TYPE="uint64">
  <VALUE>24579416</VALUE>
  </PROPERTY>
- <PROPERTY NAME="TotalFreeSpace" TYPE="uint64">
  <VALUE>12230720</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/cimv2" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Win32_LogicalDisk">
- <KEYBINDING NAME="DriveName">
  <KEYVALUE>E:\</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Win32_LogicalDisk">
- <PROPERTY NAME="DriveName" TYPE="string">
  <VALUE>E:\</VALUE>
  </PROPERTY>
- <PROPERTY NAME="TotalCapacity" TYPE="uint64">
  <VALUE>55448312</VALUE>
  </PROPERTY>
- <PROPERTY NAME="TotalFreeSpace" TYPE="uint64">
  <VALUE>18194412</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Software">
- <KEYBINDING NAME="Name">
  <KEYVALUE>Software</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Software">
- <PROPERTY NAME="BrowserOpenCommand" TYPE="string">
  <VALUE>"C:\Program Files\Internet Explorer\iexplore.exe" -nohome</VALUE>
  </PROPERTY>
- <PROPERTY NAME="DefaultEmailClient" TYPE="string">
  <VALUE>Outlook Express</VALUE>
  </PROPERTY>
- <PROPERTY NAME="Locale" TYPE="string">
  <VALUE>00000409</VALUE>
  </PROPERTY>
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>Software</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="SYMC_NAV_Info">
- <KEYBINDING NAME="Filename">
  <KEYVALUE>ABOUTPLG.DLL</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="SYMC_NAV_Info">
- <PROPERTY NAME="CompanyName" TYPE="string">
  <VALUE>Symantec Corporation</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileDescription" TYPE="string">
  <VALUE>Norton AntiVirus About Plugin</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileModifiedTime" TYPE="DateTime">
  <VALUE>01c3bab518893d00ffffffff</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileModifiedTimeFormated" TYPE="DateTime">
  <VALUE>12/4/2003 06:22 PM</VALUE>
  </PROPERTY>
- <PROPERTY NAME="Filename" TYPE="string">
  <VALUE>ABOUTPLG.DLL</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FilePath" TYPE="string">
  <VALUE>C:\Program Files\Norton SystemWorks\Norton AntiVirus\</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileSize" TYPE="uint64">
  <VALUE>156616</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileVersion" TYPE="string">
  <VALUE>10.0.10.13</VALUE>
  </PROPERTY>
- <PROPERTY NAME="ProductName" TYPE="string">
  <VALUE>Norton AntiVirus</VALUE>
  </PROPERTY>
- <PROPERTY NAME="ProductVersion" TYPE="string">
  <VALUE>10.00.13</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="SYMC_GHOST_Info">
- <KEYBINDING NAME="Filename">
  <KEYVALUE>Ghostexp.exe</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="SYMC_GHOST_Info">
- <PROPERTY NAME="CompanyName" TYPE="string">
  <VALUE>Symantec Corporation</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileDescription" TYPE="string">
  <VALUE>Norton Ghost Explorer</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileModifiedTime" TYPE="DateTime">
  <VALUE>01c243c6c0fa2600ffffffff</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileModifiedTimeFormated" TYPE="DateTime">
  <VALUE>8/14/2002 03:14 PM</VALUE>
  </PROPERTY>
- <PROPERTY NAME="Filename" TYPE="string">
  <VALUE>Ghostexp.exe</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FilePath" TYPE="string">
  <VALUE>C:\Program Files\Norton SystemWorks\Norton Ghost\</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileSize" TYPE="uint64">
  <VALUE>761856</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileVersion" TYPE="string">
  <VALUE>2003.0.0.775</VALUE>
  </PROPERTY>
- <PROPERTY NAME="ProductName" TYPE="string">
  <VALUE>Norton Ghost Explorer</VALUE>
  </PROPERTY>
- <PROPERTY NAME="ProductVersion" TYPE="string">
  <VALUE>2003.775</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="SYMC_NCS_Info">
- <KEYBINDING NAME="Filename">
  <KEYVALUE>cs32.exe</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="SYMC_NCS_Info">
- <PROPERTY NAME="CompanyName" TYPE="string">
  <VALUE>Symantec Corporation</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileDescription" TYPE="string">
  <VALUE>CleanSweep Core</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileModifiedTime" TYPE="DateTime">
  <VALUE>01c2430c63090800ffffffff</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileModifiedTimeFormated" TYPE="DateTime">
  <VALUE>8/13/2002 05:00 PM</VALUE>
  </PROPERTY>
- <PROPERTY NAME="Filename" TYPE="string">
  <VALUE>cs32.exe</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FilePath" TYPE="string">
  <VALUE>C:\Program Files\Norton SystemWorks\Norton CleanSweep\</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileSize" TYPE="uint64">
  <VALUE>36864</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileVersion" TYPE="string">
  <VALUE>7.0.0.15</VALUE>
  </PROPERTY>
- <PROPERTY NAME="ProductName" TYPE="string">
  <VALUE>Norton CleanSweep</VALUE>
  </PROPERTY>
- <PROPERTY NAME="ProductVersion" TYPE="string">
  <VALUE>7.0</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="SYMC_NCS_Info">
- <KEYBINDING NAME="Filename">
  <KEYVALUE>cs32.exe</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="SYMC_NCS_Info">
- <PROPERTY NAME="CompanyName" TYPE="string">
  <VALUE>Symantec Corporation</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileDescription" TYPE="string">
  <VALUE>CleanSweep Core</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileModifiedTime" TYPE="DateTime">
  <VALUE>01c2430c63090800ffffffff</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileModifiedTimeFormated" TYPE="DateTime">
  <VALUE>8/13/2002 05:00 PM</VALUE>
  </PROPERTY>
- <PROPERTY NAME="Filename" TYPE="string">
  <VALUE>cs32.exe</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FilePath" TYPE="string">
  <VALUE>C:\Program Files\Norton SystemWorks\Norton CleanSweep\</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileSize" TYPE="uint64">
  <VALUE>36864</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileVersion" TYPE="string">
  <VALUE>7.0.0.15</VALUE>
  </PROPERTY>
- <PROPERTY NAME="ProductName" TYPE="string">
  <VALUE>Norton CleanSweep</VALUE>
  </PROPERTY>
- <PROPERTY NAME="ProductVersion" TYPE="string">
  <VALUE>7.0</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="SYMC_NSYS_Info">
- <KEYBINDING NAME="Filename">
  <KEYVALUE>SWPLUGIN.DLL</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="SYMC_NSYS_Info">
- <PROPERTY NAME="CompanyName" TYPE="string">
  <VALUE>Symantec Corporation</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileDescription" TYPE="string">
  <VALUE>Norton SystemWorks Plug-in for the Norton Integrator</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileModifiedTime" TYPE="DateTime">
  <VALUE>01c24fc3fbb5ae00ffffffff</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileModifiedTimeFormated" TYPE="DateTime">
  <VALUE>8/29/2002 09:24 PM</VALUE>
  </PROPERTY>
- <PROPERTY NAME="Filename" TYPE="string">
  <VALUE>SWPLUGIN.DLL</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FilePath" TYPE="string">
  <VALUE>C:\Program Files\Norton SystemWorks\</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileSize" TYPE="uint64">
  <VALUE>843849</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileVersion" TYPE="string">
  <VALUE>6.6.0.12</VALUE>
  </PROPERTY>
- <PROPERTY NAME="ProductName" TYPE="string">
  <VALUE>Norton SystemWorks</VALUE>
  </PROPERTY>
- <PROPERTY NAME="ProductVersion" TYPE="string">
  <VALUE>6.6.12</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="SYMC_NU_Info">
- <KEYBINDING NAME="Filename">
  <KEYVALUE>norton.exe</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="SYMC_NU_Info">
- <PROPERTY NAME="CompanyName" TYPE="string">
  <VALUE>Symantec Corporation</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileDescription" TYPE="string">
  <VALUE>Norton Integrator Stub</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileModifiedTime" TYPE="DateTime">
  <VALUE>01c24379c54c2200ffffffff</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileModifiedTimeFormated" TYPE="DateTime">
  <VALUE>8/14/2002 06:03 AM</VALUE>
  </PROPERTY>
- <PROPERTY NAME="Filename" TYPE="string">
  <VALUE>norton.exe</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FilePath" TYPE="string">
  <VALUE>C:\Program Files\Norton SystemWorks\Norton Utilities\</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileSize" TYPE="uint64">
  <VALUE>53248</VALUE>
  </PROPERTY>
- <PROPERTY NAME="FileVersion" TYPE="string">
  <VALUE>16.0.0.22</VALUE>
  </PROPERTY>
- <PROPERTY NAME="ProductName" TYPE="string">
  <VALUE>Norton Utilities for Windows</VALUE>
  </PROPERTY>
- <PROPERTY NAME="ProductVersion" TYPE="string">
  <VALUE>16.00.0.22</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="SOS">
- <KEYBINDING NAME="Name">
  <KEYVALUE>SOS</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="SOS">
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>SOS</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
  <KEYVALUE>Klez(HKLM\System\CurrentControlSet\Services\wink|)</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>Klez(HKLM\System\CurrentControlSet\Services\wink|)</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
  <VALUE>HKLM\System\CurrentControlSet\Services\wink</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkeyexists" TYPE="string">
  <VALUE>NO</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
  <KEYVALUE>Klez(HKLM\System\CurrentControlSet\Services\WQK|DisplayName|)</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>Klez(HKLM\System\CurrentControlSet\Services\WQK|DisplayName|)</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
  <VALUE>HKLM\System\CurrentControlSet\Services\WQK</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
  <VALUE>DisplayName</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
  <KEYVALUE>Klez(HKLM\System\CurrentControlSet\Services\krn132|DisplayName|)</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>Klez(HKLM\System\CurrentControlSet\Services\krn132|DisplayName|)</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
  <VALUE>HKLM\System\CurrentControlSet\Services\krn132</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
  <VALUE>DisplayName</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
  <KEYVALUE>Klez(HKLM\System\CurrentControlSet\Services\WinSvc|DisplayName|)</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>Klez(HKLM\System\CurrentControlSet\Services\WinSvc|DisplayName|)</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
  <VALUE>HKLM\System\CurrentControlSet\Services\WinSvc</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
  <VALUE>DisplayName</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
  <KEYVALUE>Klez(HKLM\System\CurrentControlSet\Services\Wink|DisplayName|)</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>Klez(HKLM\System\CurrentControlSet\Services\Wink|DisplayName|)</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
  <VALUE>HKLM\System\CurrentControlSet\Services\Wink</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
  <VALUE>DisplayName</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
  <KEYVALUE>Lirva(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Avril Lavigne - Muse|)</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>Lirva(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Avril Lavigne - Muse|)</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
  <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
  <VALUE>Avril Lavigne - Muse</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
  <KEYVALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ScrSvr|)</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ScrSvr|)</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
  <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
  <VALUE>ScrSvr</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
  <KEYVALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Brasil|)</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Brasil|)</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
  <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
  <VALUE>Brasil</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
  <KEYVALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|cronos|)</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|cronos|)</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
  <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
  <VALUE>cronos</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
  <KEYVALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|instit|)</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|instit|)</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
  <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
  <VALUE>instit</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
  <KEYVALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Srv32|)</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Srv32|)</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
  <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
  <VALUE>Srv32</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
  <KEYVALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|mqbkup|)</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|mqbkup|)</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
  <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
  <VALUE>mqbkup</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
  <KEYVALUE>W32.HLLW.Nebiwo(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Nav Live Update|)</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>W32.HLLW.Nebiwo(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Nav Live Update|)</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
  <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
  <VALUE>Nav Live Update</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
  <KEYVALUE>W32.Sobig.A(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WindowsMGM|)</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>W32.Sobig.A(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WindowsMGM|)</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
  <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
  <VALUE>WindowsMGM</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
  <KEYVALUE>W32.Welchia.Worm(HKLM\System\CurrentControlSet\Services\RpcPatch||)</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>W32.Welchia.Worm(HKLM\System\CurrentControlSet\Services\RpcPatch||)</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
  <VALUE>HKLM\System\CurrentControlSet\Services\RpcPatch</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkeyexists" TYPE="string">
  <VALUE>NO</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
  <KEYVALUE>W32.Welchia.Worm(HKLM\System\CurrentControlSet\Services\RpcTftpd||)</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>W32.Welchia.Worm(HKLM\System\CurrentControlSet\Services\RpcTftpd||)</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
  <VALUE>HKLM\System\CurrentControlSet\Services\RpcTftpd</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkeyexists" TYPE="string">
  <VALUE>NO</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
  <KEYVALUE>W32.Welchia.Worm(HKLM\System\CurrentControlSet\Services\WksPatch||)</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>W32.Welchia.Worm(HKLM\System\CurrentControlSet\Services\WksPatch||)</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
  <VALUE>HKLM\System\CurrentControlSet\Services\WksPatch</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkeyexists" TYPE="string">
  <VALUE>NO</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Adware">
- <KEYBINDING NAME="Name">
  <KEYVALUE>Adware.180search(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|MSBB|)</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Adware">
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>Adware.180search(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|MSBB|)</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
  <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
  <VALUE>MSBB</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Adware">
- <KEYBINDING NAME="Name">
  <KEYVALUE>Adware.Blazefind(HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83DE62E0-5805-11D8-9B25-00E04C60FAF2}||)</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Adware">
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>Adware.Blazefind(HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83DE62E0-5805-11D8-9B25-00E04C60FAF2}||)</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
  <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83DE62E0-5805-11D8-9B25-00E04C60FAF2}</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkeyexists" TYPE="string">
  <VALUE>NO</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Adware">
- <KEYBINDING NAME="Name">
  <KEYVALUE>Adware.HelpExpress(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|HelpExpress|)</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Adware">
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>Adware.HelpExpress(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|HelpExpress|)</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
  <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
  <VALUE>HelpExpress</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Adware">
- <KEYBINDING NAME="Name">
  <KEYVALUE>Adware.Iefeats(HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\IEFeatSL||)</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Adware">
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>Adware.Iefeats(HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\IEFeatSL||)</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
  <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\IEFeatSL</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkeyexists" TYPE="string">
  <VALUE>NO</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Adware">
- <KEYBINDING NAME="Name">
  <KEYVALUE>Adware.Ilookup(HKCU\Software\ineb||)</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Adware">
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>Adware.Ilookup(HKCU\Software\ineb||)</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
  <VALUE>HKCU\Software\ineb</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkeyexists" TYPE="string">
  <VALUE>NO</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Adware">
- <KEYBINDING NAME="Name">
  <KEYVALUE>Adware.Ipinsight(HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\IpInsight||)</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Adware">
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>Adware.Ipinsight(HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\IpInsight||)</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
  <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\IpInsight</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkeyexists" TYPE="string">
  <VALUE>NO</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Adware">
- <KEYBINDING NAME="Name">
  <KEYVALUE>Adware.Mpgcom(HKLM\Software\Classes\Mpgcom.zoom||)</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Adware">
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>Adware.Mpgcom(HKLM\Software\Classes\Mpgcom.zoom||)</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
  <VALUE>HKLM\Software\Classes\Mpgcom.zoom</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkeyexists" TYPE="string">
  <VALUE>NO</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
  <HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
  <NAMESPACE NAME="root/symantec" />
  </LOCALNAMESPACEPATH>
  </NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Adware">
- <KEYBINDING NAME="Name">
  <KEYVALUE>Adware.Ncase(HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\nCase||)</KEYVALUE>
  </KEYBINDING>
  </INSTANCENAME>
  </INSTANCEPATH>
- <INSTANCE CLASSNAME="Adware">
- <PROPERTY NAME="Name" TYPE="string">
  <VALUE>Adware.Ncase(HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\nCase||)</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
  <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\nCase</VALUE>
  </PROPERTY>
- <PROPERTY NAME="regkeyexists" TYPE="string">
  <VALUE>NO</VALUE>
  </PROPERTY>
  </INSTANCE>
  </VALUE.OBJECTWITHPATH>
  </DECLGROUP.WITHPATH>
  </DECLARATION>
  </CIM>
  </Snapshot>
  </DataCollection>
  </UPLOADINFO>
jaclaz
It looks like some data generated by a Symantec app (Internet Security? unsure.gif) as a report of an error or a conflict, to be possibly sent to Symantec.

jaclaz
JoeGons
Hmmm,
What’s odd is that the dates of the .cab show Date Created/Modified of 1/29/2008 but the date of the .xml file within is 4/10/2006.
I think I’ll just delete it and see if it returns.
Thanks,
Joe newwink.gif

Google Internet Forums Unattended CD/DVD Guide
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.