JoeGons

Member
  • Content count

    23
  • Joined

  • Last visited

Community Reputation

0 Neutral

About JoeGons

  • Birthday 06/14/1945

Contact Methods

  • Website URL
    http://
  1. Thanks. I think I can feel a little better and stop worrying about my OS.
  2. That's the problem. Anytime I need to copy a LARGE amount of data, I guess I'll have to turn off compression. In any event, I need to be reassured that my OS, (XP) is not in trouble. I have a desktop and two Laptops and the cost of replacing all three is too much when they all serve my needs. Joe
  3. Typo? Standard cluster size in NTFS is 4 Kb. http://support.microsoft.com/kb/140365/en-us jaclaz Yes. Not Mb. I use 2KB clusters to accommodate lots of small files. OK, here’s what I did. I took the drive out of the enclosure. I connected it through a different USP connection. I then quick formatted using the compression option. I then did the file copy. Same result. I did the format again without compression and this time I copied the same file from my internal hard drive. This time there was no fragmentation. I then formatted with compression and copied from my internal drive. This time I got the fragmentation. So I formatted without compression again and copied from my internal drive. No fragmentation. To test the result I formatted without compression and copied external to external. No fragmentation!! So I tested the 2KB cluster. Formatted with NO compression and 2KB clusters. Copied external to external. NO fragmentation. There seems to be nothing wrong with the drive. So I put the drive back into the suspect enclosure. First run: External USB to external; Formatted with NO compression and 4KB cluster. NO fragmentation. Second run: Formatted with NO compression and 2KB cluster. NO fragmentation!! The enclosure seems to be good. The question now is, “Is there something wrong with my Operating System?” How does how operating System achieve the compression on a drive? Joe
  4. After full Format and copying one Folder with Disk Caching in Windows ON. Disk Check result for S ----------------------------- Windows has checked the file system and found no problems. 488385134 KB total disk space. 5820650 KB in 7 files. 16 KB in 13 indexes. 0 KB in bad sectors. 96472 KB in use by the system. 65536 KB occupied by the log file. 482467996 KB available on disk. 2048 bytes in each allocation unit. 244192567 total allocation units on disk. 241233998 allocation units available on disk. Notice 7 Files!!! Report: ----------------- Volume Backup All S (S:) Volume size = 466 GB Cluster size = 2 KB Used space = 5.64 GB Free space = 460 GB Percent free space = 98 % Volume fragmentation Total fragmentation = 49 % File fragmentation = 98 % Free space fragmentation = 0 % File fragmentation Total files = 10 Average file size = 1.37 GB Total fragmented files = 4 Total excess fragments = 1,110 Average fragments per file = 112.00 Pagefile fragmentation Pagefile size = 0 bytes Total fragments = 0 Folder fragmentation Total folders = 6 Fragmented folders = 1 Excess folder fragments = 0 Master File Table (MFT) fragmentation Total MFT size = 688 KB MFT record count = 665 Percent MFT in use = 96 % Total MFT fragments = 2 -------------------------------------------------------------------------------- Fragments File Size Most fragmented files 346 2.00 GB \Data\Clean Copy 2\Clean001.GHS 321 2.00 GB \Data\Clean Copy 2\Clean Copy 2.GHO 238 2.00 GB \Data\Clean Copy 2\Clean002.GHS 209 881 MB \Data\Clean Copy 2\Clean003.GHS Notice 10 files. Must include MFT. I actually have 5 files and the System Volume Information Folder. After de-fragmenting with Windows Defrag. Disk Check result for S ----------------------------- Windows has checked the file system and found no problems. 488385134 KB total disk space. 5820650 KB in 7 files. 16 KB in 13 indexes. 0 KB in bad sectors. 96934 KB in use by the system. 65536 KB occupied by the log file. 482467534 KB available on disk. 2048 bytes in each allocation unit. 244192567 total allocation units on disk. 241233767 allocation units available on disk. Report ------------ Volume Backup All S (S:) Volume size = 466 GB Cluster size = 2 KB Used space = 5.64 GB Free space = 460 GB Percent free space = 98 % Volume fragmentation Total fragmentation = 0 % File fragmentation = 0 % Free space fragmentation = 0 % File fragmentation Total files = 10 Average file size = 1.37 GB Total fragmented files = 0 Total excess fragments = 0 Average fragments per file = 1.00 Pagefile fragmentation Pagefile size = 0 bytes Total fragments = 0 Folder fragmentation Total folders = 6 Fragmented folders = 1 Excess folder fragments = 0 Master File Table (MFT) fragmentation Total MFT size = 1 MB MFT record count = 1,114 Percent MFT in use = 98 % Total MFT fragments = 2 -------------------------------------------------------------------------------- Fragments File Size Most fragmented files None So I tried copying to a different new drive. 320GB. Both external USB2. Same setup. Same fragmented result!!! I have a problem somewhere else. So I asked myself if I was doing anything that was not standard. Well, I was formatting NTFS with 2MB Cluster size. So I re-formatted with 4MB Cluster size. With Caching ON it is faster. On Disk #2, a 320 GB IDE disk: Did the copy and VOILA; NO FRAGMENTATION!!! On Disk #1, a 500GB SATA disk, same problem of fragmentation. I think I might have a problem with the enclosure or the drive itself. The drive tested perfectly with HD Tune. I will put the drive in a different enclosure and see what happens.
  5. That sounds very interesting. I'm working on an idea. Will post results. Joe
  6. That's a good point. That is exactly how I have my externals setup. I'll try it again with disk caching. Thanks Joe And for the Finder; I have downloaded Wincontig and will have a look. Auslogics does allow single file defrag.
  7. using a 500GB drive. that's 40% free. I should have no problems there.
  8. I just select all and copy on old drive and paste on new drive. Lots of extra space on new drive. 200GB.
  9. If I do de-frag again, I think I will do that. Joe
  10. Hi, I copied one external drive to another new external USB 2.0, NTFS XP SP3 It took over 12 hours!!! 298GB of data with some very large files. When I was finished the drive was 40% fragmented. .. One 3.6GB file had over 1200 fragments. I tried to de-fragment it with Auslogics and really messed it up. The drive became unreadable and check disk “aborted” trying to fix it. I did it over and got the same fragmentation. Checkdisk found no problems before de-fragmenting. I am reluctant to try and de-fragment it now. Is this normal? Will Windows 8 do this? Joe
  11. Thanks Ponch. That does the trick. Joe
  12. Hello, I tried this. To rename a series of files (From Windows Help) 1. Open My Documents. If the series of files you want to rename is not located in My Documents or its subfolders, use Search to find it. To open Search, click Start, point to Search, and then click For Files or Folders. 2. Select the files you want to rename. 3. On the File menu, click Rename. 4. Type the new name, and then press ENTER. All of the files in the series will be named in sequence using the new name you type. For example, if you type Birthday, the other files in the series will be named Birthday (1), Birthday (2), and so on. Notes · To open My Documents, double-click the My Documents icon on your desktop. · To select consecutive files or folders, click the first item, press and hold down SHIFT, and then click the last item. To select nonconsecutive files or folders, press and hold down CTRL, and then click each item. · To specify the starting number for the series, type the starting number in parenthesis after the new file name. The files in the series will be numbered in sequence starting with the number you type. For example, if you type Birthday (10), the other files will be named Birthday (11), Birthday (12), and so on. This does not work. When I open a folder in Windows Explorer or My Documents\My Pictures and try to rename the files (jpg), I do not get a good result. The first file is named “John.jpg” and the second is named “John (1).jpg” and the third, “John (2).jpg” etc. Is there a way to get the FIRST file “John (1).jpg” and the second “John (2).jpg” etc? I’m using XP Home SP3. Thanks, Joe
  13. Hmmm, What’s odd is that the dates of the .cab show Date Created/Modified of 1/29/2008 but the date of the .xml file within is 4/10/2006. I think I’ll just delete it and see if it returns. Thanks, Joe
  14. I found this in the Root directory. What is it? e23a0e86-07c3-4b8d-a399-232f849c5f73.cab containing; e23a0e86-07c3-4b8d-a399-232f849c5f73.xml This is the content of .xml (in text form). <?xml version="1.0" encoding="UTF-8" standalone="no" ?> - <UPLOADINFO> <UPLOADDATA USERNAME="e23a0e86-07c3-4b8d-a399-232f849c5f73" PRODUCTID="Sdc User" PRODUCTNAME="supportal" PROBLEMDESCRIPTION="Symantec ASA Index" Severity="normal" /> - <DataCollection> - <Snapshot Timestamp="20060410141618.000000+000"> - <CIM CIMVERSION="2.0" DTDVERSION="2.0"> - <DECLARATION> - <DECLGROUP.WITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/cimv2" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="PCH_Sysinfo"> - <KEYBINDING NAME="SystemID"> <KEYVALUE>{fb7fd39d-68c3-4fd6-a300-90222c9d3484}</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="PCH_Sysinfo"> - <PROPERTY NAME="ClockSpeed" TYPE="uint32"> <VALUE>2601</VALUE> </PROPERTY> - <PROPERTY NAME="OSName" TYPE="string"> <VALUE>Windows XP 5.1</VALUE> </PROPERTY> - <PROPERTY NAME="OSVersion" TYPE="string"> <VALUE>build 2600</VALUE> </PROPERTY> - <PROPERTY NAME="Processor" TYPE="string"> <VALUE>GenuineIntel</VALUE> </PROPERTY> - <PROPERTY NAME="RAM" TYPE="uint64"> <VALUE>765</VALUE> </PROPERTY> - <PROPERTY NAME="SwapFile" TYPE="string"> <VALUE>C:\pagefile.sys 1623 MB Free</VALUE> </PROPERTY> - <PROPERTY NAME="SystemID" TYPE="string"> <VALUE>{fb7fd39d-68c3-4fd6-a300-90222c9d3484}</VALUE> </PROPERTY> - <PROPERTY NAME="WindowsDirectory" TYPE="string"> <VALUE>C:\WINDOWS</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/cimv2" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="SDC_UserInfo"> - <KEYBINDING NAME="Name"> <KEYVALUE>SDC_UserInfo</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="SDC_UserInfo"> - <PROPERTY NAME="ClientVersion" TYPE="string"> <VALUE>0.0.0.0</VALUE> </PROPERTY> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>SDC_UserInfo</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/cimv2" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Win32_LogicalMemoryConfig"> - <KEYBINDING NAME="Name"> <KEYVALUE>Win32_LogicalMemoryConfig</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Win32_LogicalMemoryConfig"> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>Win32_LogicalMemoryConfig</VALUE> </PROPERTY> - <PROPERTY NAME="TotalPhysicalMemory" TYPE="uint64"> <VALUE>765</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/cimv2" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Win32_OperatingSystem"> - <KEYBINDING NAME="Name"> <KEYVALUE>Win32_OperatingSystem</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Win32_OperatingSystem"> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>Win32_OperatingSystem</VALUE> </PROPERTY> - <PROPERTY NAME="OSName" TYPE="string"> <VALUE>Windows XP 5.1</VALUE> </PROPERTY> - <PROPERTY NAME="OSType" TYPE="string"> <VALUE>WinNT</VALUE> </PROPERTY> - <PROPERTY NAME="OSVersion" TYPE="string"> <VALUE>build 2600</VALUE> </PROPERTY> - <PROPERTY NAME="SvcPack" TYPE="string"> <VALUE>Service Pack 2</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/cimv2" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="BrowserInfo"> - <KEYBINDING NAME="Name"> <KEYVALUE>BrowserInfo</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="BrowserInfo"> - <PROPERTY NAME="DefaultBrowser" TYPE="string"> <VALUE>Internet Explorer</VALUE> </PROPERTY> - <PROPERTY NAME="IEVersion" TYPE="string"> <VALUE>6.0.2900.2180</VALUE> </PROPERTY> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>BrowserInfo</VALUE> </PROPERTY> - <PROPERTY NAME="NetscapeVersion" TYPE="string"> <VALUE /> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="SDC_Connectivity"> - <KEYBINDING NAME="Name"> <KEYVALUE>ConnectionData</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="SDC_Connectivity"> - <PROPERTY NAME="CTSTicket" TYPE="string"> <VALUE /> </PROPERTY> - <PROPERTY NAME="DNSName" TYPE="string"> <VALUE>home-gateway</VALUE> </PROPERTY> - <PROPERTY NAME="Domain" TYPE="string"> <VALUE>HOME-GATEWAY</VALUE> </PROPERTY> - <PROPERTY NAME="HostName" TYPE="string"> <VALUE>HOME-GATEWAY</VALUE> </PROPERTY> - <PROPERTY NAME="MacID" TYPE="string"> <VALUE>{fb7fd39d-68c3-4fd6-a300-90222c9d3484}</VALUE> </PROPERTY> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>ConnectionData</VALUE> </PROPERTY> - <PROPERTY NAME="NetBIOSName" TYPE="string"> <VALUE>HOME-GATEWAY</VALUE> </PROPERTY> - <PROPERTY NAME="OSName" TYPE="string"> <VALUE>Windows XP 5.1</VALUE> </PROPERTY> - <PROPERTY NAME="PostToQueue" TYPE="string"> <VALUE>1</VALUE> </PROPERTY> - <PROPERTY NAME="TCPIP_Address" TYPE="string"> <VALUE>192.168.254.1</VALUE> </PROPERTY> - <PROPERTY NAME="UserName" TYPE="string"> <VALUE>Owner</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="SDC_AdditionalSysInfo"> - <KEYBINDING NAME="Name"> <KEYVALUE>SDC_AdditionalSysInfo</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="SDC_AdditionalSysInfo"> - <PROPERTY NAME="MemoryLoad" TYPE="string"> <VALUE>35</VALUE> </PROPERTY> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>SDC_AdditionalSysInfo</VALUE> </PROPERTY> - <PROPERTY NAME="NumberOfProcessors" TYPE="string"> <VALUE>1</VALUE> </PROPERTY> - <PROPERTY NAME="PageFileAvailable" TYPE="string"> <VALUE>1623</VALUE> </PROPERTY> - <PROPERTY NAME="PageFileInitialSize" TYPE="string"> <VALUE>2304</VALUE> </PROPERTY> - <PROPERTY NAME="PageFileMaxSize" TYPE="string"> <VALUE>2304</VALUE> </PROPERTY> - <PROPERTY NAME="PageFileTotal" TYPE="string"> <VALUE>1870</VALUE> </PROPERTY> - <PROPERTY NAME="Processor" TYPE="string"> <VALUE>GenuineIntel</VALUE> </PROPERTY> - <PROPERTY NAME="ProcessorArchitecture" TYPE="string"> <VALUE>INTEL</VALUE> </PROPERTY> - <PROPERTY NAME="ProcessorLevel" TYPE="string"> <VALUE>15</VALUE> </PROPERTY> - <PROPERTY NAME="ProcessorRevision" TYPE="string"> <VALUE>521</VALUE> </PROPERTY> - <PROPERTY NAME="ProcessorType" TYPE="string"> <VALUE>PROCESSOR_INTEL_PENTIUM</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="SDC_IncidentInfo"> - <KEYBINDING NAME="Name"> <KEYVALUE>IncidentInfo</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="SDC_IncidentInfo"> - <PROPERTY NAME="Description" TYPE="string"> <VALUE>Symantec ASA Index</VALUE> </PROPERTY> - <PROPERTY NAME="GUID" TYPE="string"> <VALUE>e23a0e86-07c3-4b8d-a399-232f849c5f73</VALUE> </PROPERTY> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>IncidentInfo</VALUE> </PROPERTY> - <PROPERTY NAME="Owner" TYPE="string"> <VALUE>Owner</VALUE> </PROPERTY> - <PROPERTY NAME="Time" TYPE="string"> <VALUE>4/10/2006 10:16:18 AM</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/cimv2" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Win32_LogicalDisk"> - <KEYBINDING NAME="DriveName"> <KEYVALUE>C:\</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Win32_LogicalDisk"> - <PROPERTY NAME="DriveName" TYPE="string"> <VALUE>C:\</VALUE> </PROPERTY> - <PROPERTY NAME="TotalCapacity" TYPE="uint64"> <VALUE>24579416</VALUE> </PROPERTY> - <PROPERTY NAME="TotalFreeSpace" TYPE="uint64"> <VALUE>12230720</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/cimv2" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Win32_LogicalDisk"> - <KEYBINDING NAME="DriveName"> <KEYVALUE>E:\</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Win32_LogicalDisk"> - <PROPERTY NAME="DriveName" TYPE="string"> <VALUE>E:\</VALUE> </PROPERTY> - <PROPERTY NAME="TotalCapacity" TYPE="uint64"> <VALUE>55448312</VALUE> </PROPERTY> - <PROPERTY NAME="TotalFreeSpace" TYPE="uint64"> <VALUE>18194412</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Software"> - <KEYBINDING NAME="Name"> <KEYVALUE>Software</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Software"> - <PROPERTY NAME="BrowserOpenCommand" TYPE="string"> <VALUE>"C:\Program Files\Internet Explorer\iexplore.exe" -nohome</VALUE> </PROPERTY> - <PROPERTY NAME="DefaultEmailClient" TYPE="string"> <VALUE>Outlook Express</VALUE> </PROPERTY> - <PROPERTY NAME="Locale" TYPE="string"> <VALUE>00000409</VALUE> </PROPERTY> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>Software</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="SYMC_NAV_Info"> - <KEYBINDING NAME="Filename"> <KEYVALUE>ABOUTPLG.DLL</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="SYMC_NAV_Info"> - <PROPERTY NAME="CompanyName" TYPE="string"> <VALUE>Symantec Corporation</VALUE> </PROPERTY> - <PROPERTY NAME="FileDescription" TYPE="string"> <VALUE>Norton AntiVirus About Plugin</VALUE> </PROPERTY> - <PROPERTY NAME="FileModifiedTime" TYPE="DateTime"> <VALUE>01c3bab518893d00ffffffff</VALUE> </PROPERTY> - <PROPERTY NAME="FileModifiedTimeFormated" TYPE="DateTime"> <VALUE>12/4/2003 06:22 PM</VALUE> </PROPERTY> - <PROPERTY NAME="Filename" TYPE="string"> <VALUE>ABOUTPLG.DLL</VALUE> </PROPERTY> - <PROPERTY NAME="FilePath" TYPE="string"> <VALUE>C:\Program Files\Norton SystemWorks\Norton AntiVirus\</VALUE> </PROPERTY> - <PROPERTY NAME="FileSize" TYPE="uint64"> <VALUE>156616</VALUE> </PROPERTY> - <PROPERTY NAME="FileVersion" TYPE="string"> <VALUE>10.0.10.13</VALUE> </PROPERTY> - <PROPERTY NAME="ProductName" TYPE="string"> <VALUE>Norton AntiVirus</VALUE> </PROPERTY> - <PROPERTY NAME="ProductVersion" TYPE="string"> <VALUE>10.00.13</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="SYMC_GHOST_Info"> - <KEYBINDING NAME="Filename"> <KEYVALUE>Ghostexp.exe</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="SYMC_GHOST_Info"> - <PROPERTY NAME="CompanyName" TYPE="string"> <VALUE>Symantec Corporation</VALUE> </PROPERTY> - <PROPERTY NAME="FileDescription" TYPE="string"> <VALUE>Norton Ghost Explorer</VALUE> </PROPERTY> - <PROPERTY NAME="FileModifiedTime" TYPE="DateTime"> <VALUE>01c243c6c0fa2600ffffffff</VALUE> </PROPERTY> - <PROPERTY NAME="FileModifiedTimeFormated" TYPE="DateTime"> <VALUE>8/14/2002 03:14 PM</VALUE> </PROPERTY> - <PROPERTY NAME="Filename" TYPE="string"> <VALUE>Ghostexp.exe</VALUE> </PROPERTY> - <PROPERTY NAME="FilePath" TYPE="string"> <VALUE>C:\Program Files\Norton SystemWorks\Norton Ghost\</VALUE> </PROPERTY> - <PROPERTY NAME="FileSize" TYPE="uint64"> <VALUE>761856</VALUE> </PROPERTY> - <PROPERTY NAME="FileVersion" TYPE="string"> <VALUE>2003.0.0.775</VALUE> </PROPERTY> - <PROPERTY NAME="ProductName" TYPE="string"> <VALUE>Norton Ghost Explorer</VALUE> </PROPERTY> - <PROPERTY NAME="ProductVersion" TYPE="string"> <VALUE>2003.775</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="SYMC_NCS_Info"> - <KEYBINDING NAME="Filename"> <KEYVALUE>cs32.exe</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="SYMC_NCS_Info"> - <PROPERTY NAME="CompanyName" TYPE="string"> <VALUE>Symantec Corporation</VALUE> </PROPERTY> - <PROPERTY NAME="FileDescription" TYPE="string"> <VALUE>CleanSweep Core</VALUE> </PROPERTY> - <PROPERTY NAME="FileModifiedTime" TYPE="DateTime"> <VALUE>01c2430c63090800ffffffff</VALUE> </PROPERTY> - <PROPERTY NAME="FileModifiedTimeFormated" TYPE="DateTime"> <VALUE>8/13/2002 05:00 PM</VALUE> </PROPERTY> - <PROPERTY NAME="Filename" TYPE="string"> <VALUE>cs32.exe</VALUE> </PROPERTY> - <PROPERTY NAME="FilePath" TYPE="string"> <VALUE>C:\Program Files\Norton SystemWorks\Norton CleanSweep\</VALUE> </PROPERTY> - <PROPERTY NAME="FileSize" TYPE="uint64"> <VALUE>36864</VALUE> </PROPERTY> - <PROPERTY NAME="FileVersion" TYPE="string"> <VALUE>7.0.0.15</VALUE> </PROPERTY> - <PROPERTY NAME="ProductName" TYPE="string"> <VALUE>Norton CleanSweep</VALUE> </PROPERTY> - <PROPERTY NAME="ProductVersion" TYPE="string"> <VALUE>7.0</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="SYMC_NCS_Info"> - <KEYBINDING NAME="Filename"> <KEYVALUE>cs32.exe</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="SYMC_NCS_Info"> - <PROPERTY NAME="CompanyName" TYPE="string"> <VALUE>Symantec Corporation</VALUE> </PROPERTY> - <PROPERTY NAME="FileDescription" TYPE="string"> <VALUE>CleanSweep Core</VALUE> </PROPERTY> - <PROPERTY NAME="FileModifiedTime" TYPE="DateTime"> <VALUE>01c2430c63090800ffffffff</VALUE> </PROPERTY> - <PROPERTY NAME="FileModifiedTimeFormated" TYPE="DateTime"> <VALUE>8/13/2002 05:00 PM</VALUE> </PROPERTY> - <PROPERTY NAME="Filename" TYPE="string"> <VALUE>cs32.exe</VALUE> </PROPERTY> - <PROPERTY NAME="FilePath" TYPE="string"> <VALUE>C:\Program Files\Norton SystemWorks\Norton CleanSweep\</VALUE> </PROPERTY> - <PROPERTY NAME="FileSize" TYPE="uint64"> <VALUE>36864</VALUE> </PROPERTY> - <PROPERTY NAME="FileVersion" TYPE="string"> <VALUE>7.0.0.15</VALUE> </PROPERTY> - <PROPERTY NAME="ProductName" TYPE="string"> <VALUE>Norton CleanSweep</VALUE> </PROPERTY> - <PROPERTY NAME="ProductVersion" TYPE="string"> <VALUE>7.0</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="SYMC_NSYS_Info"> - <KEYBINDING NAME="Filename"> <KEYVALUE>SWPLUGIN.DLL</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="SYMC_NSYS_Info"> - <PROPERTY NAME="CompanyName" TYPE="string"> <VALUE>Symantec Corporation</VALUE> </PROPERTY> - <PROPERTY NAME="FileDescription" TYPE="string"> <VALUE>Norton SystemWorks Plug-in for the Norton Integrator</VALUE> </PROPERTY> - <PROPERTY NAME="FileModifiedTime" TYPE="DateTime"> <VALUE>01c24fc3fbb5ae00ffffffff</VALUE> </PROPERTY> - <PROPERTY NAME="FileModifiedTimeFormated" TYPE="DateTime"> <VALUE>8/29/2002 09:24 PM</VALUE> </PROPERTY> - <PROPERTY NAME="Filename" TYPE="string"> <VALUE>SWPLUGIN.DLL</VALUE> </PROPERTY> - <PROPERTY NAME="FilePath" TYPE="string"> <VALUE>C:\Program Files\Norton SystemWorks\</VALUE> </PROPERTY> - <PROPERTY NAME="FileSize" TYPE="uint64"> <VALUE>843849</VALUE> </PROPERTY> - <PROPERTY NAME="FileVersion" TYPE="string"> <VALUE>6.6.0.12</VALUE> </PROPERTY> - <PROPERTY NAME="ProductName" TYPE="string"> <VALUE>Norton SystemWorks</VALUE> </PROPERTY> - <PROPERTY NAME="ProductVersion" TYPE="string"> <VALUE>6.6.12</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="SYMC_NU_Info"> - <KEYBINDING NAME="Filename"> <KEYVALUE>norton.exe</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="SYMC_NU_Info"> - <PROPERTY NAME="CompanyName" TYPE="string"> <VALUE>Symantec Corporation</VALUE> </PROPERTY> - <PROPERTY NAME="FileDescription" TYPE="string"> <VALUE>Norton Integrator Stub</VALUE> </PROPERTY> - <PROPERTY NAME="FileModifiedTime" TYPE="DateTime"> <VALUE>01c24379c54c2200ffffffff</VALUE> </PROPERTY> - <PROPERTY NAME="FileModifiedTimeFormated" TYPE="DateTime"> <VALUE>8/14/2002 06:03 AM</VALUE> </PROPERTY> - <PROPERTY NAME="Filename" TYPE="string"> <VALUE>norton.exe</VALUE> </PROPERTY> - <PROPERTY NAME="FilePath" TYPE="string"> <VALUE>C:\Program Files\Norton SystemWorks\Norton Utilities\</VALUE> </PROPERTY> - <PROPERTY NAME="FileSize" TYPE="uint64"> <VALUE>53248</VALUE> </PROPERTY> - <PROPERTY NAME="FileVersion" TYPE="string"> <VALUE>16.0.0.22</VALUE> </PROPERTY> - <PROPERTY NAME="ProductName" TYPE="string"> <VALUE>Norton Utilities for Windows</VALUE> </PROPERTY> - <PROPERTY NAME="ProductVersion" TYPE="string"> <VALUE>16.00.0.22</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="SOS"> - <KEYBINDING NAME="Name"> <KEYVALUE>SOS</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="SOS"> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>SOS</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Threat"> - <KEYBINDING NAME="Name"> <KEYVALUE>Klez(HKLM\System\CurrentControlSet\Services\wink|)</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Threat"> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>Klez(HKLM\System\CurrentControlSet\Services\wink|)</VALUE> </PROPERTY> - <PROPERTY NAME="regkey" TYPE="string"> <VALUE>HKLM\System\CurrentControlSet\Services\wink</VALUE> </PROPERTY> - <PROPERTY NAME="regkeyexists" TYPE="string"> <VALUE>NO</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Threat"> - <KEYBINDING NAME="Name"> <KEYVALUE>Klez(HKLM\System\CurrentControlSet\Services\WQK|DisplayName|)</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Threat"> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>Klez(HKLM\System\CurrentControlSet\Services\WQK|DisplayName|)</VALUE> </PROPERTY> - <PROPERTY NAME="regkey" TYPE="string"> <VALUE>HKLM\System\CurrentControlSet\Services\WQK</VALUE> </PROPERTY> - <PROPERTY NAME="regvalue" TYPE="string"> <VALUE>DisplayName</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Threat"> - <KEYBINDING NAME="Name"> <KEYVALUE>Klez(HKLM\System\CurrentControlSet\Services\krn132|DisplayName|)</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Threat"> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>Klez(HKLM\System\CurrentControlSet\Services\krn132|DisplayName|)</VALUE> </PROPERTY> - <PROPERTY NAME="regkey" TYPE="string"> <VALUE>HKLM\System\CurrentControlSet\Services\krn132</VALUE> </PROPERTY> - <PROPERTY NAME="regvalue" TYPE="string"> <VALUE>DisplayName</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Threat"> - <KEYBINDING NAME="Name"> <KEYVALUE>Klez(HKLM\System\CurrentControlSet\Services\WinSvc|DisplayName|)</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Threat"> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>Klez(HKLM\System\CurrentControlSet\Services\WinSvc|DisplayName|)</VALUE> </PROPERTY> - <PROPERTY NAME="regkey" TYPE="string"> <VALUE>HKLM\System\CurrentControlSet\Services\WinSvc</VALUE> </PROPERTY> - <PROPERTY NAME="regvalue" TYPE="string"> <VALUE>DisplayName</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Threat"> - <KEYBINDING NAME="Name"> <KEYVALUE>Klez(HKLM\System\CurrentControlSet\Services\Wink|DisplayName|)</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Threat"> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>Klez(HKLM\System\CurrentControlSet\Services\Wink|DisplayName|)</VALUE> </PROPERTY> - <PROPERTY NAME="regkey" TYPE="string"> <VALUE>HKLM\System\CurrentControlSet\Services\Wink</VALUE> </PROPERTY> - <PROPERTY NAME="regvalue" TYPE="string"> <VALUE>DisplayName</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Threat"> - <KEYBINDING NAME="Name"> <KEYVALUE>Lirva(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Avril Lavigne - Muse|)</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Threat"> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>Lirva(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Avril Lavigne - Muse|)</VALUE> </PROPERTY> - <PROPERTY NAME="regkey" TYPE="string"> <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE> </PROPERTY> - <PROPERTY NAME="regvalue" TYPE="string"> <VALUE>Avril Lavigne - Muse</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Threat"> - <KEYBINDING NAME="Name"> <KEYVALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ScrSvr|)</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Threat"> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ScrSvr|)</VALUE> </PROPERTY> - <PROPERTY NAME="regkey" TYPE="string"> <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE> </PROPERTY> - <PROPERTY NAME="regvalue" TYPE="string"> <VALUE>ScrSvr</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Threat"> - <KEYBINDING NAME="Name"> <KEYVALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Brasil|)</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Threat"> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Brasil|)</VALUE> </PROPERTY> - <PROPERTY NAME="regkey" TYPE="string"> <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE> </PROPERTY> - <PROPERTY NAME="regvalue" TYPE="string"> <VALUE>Brasil</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Threat"> - <KEYBINDING NAME="Name"> <KEYVALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|cronos|)</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Threat"> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|cronos|)</VALUE> </PROPERTY> - <PROPERTY NAME="regkey" TYPE="string"> <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE> </PROPERTY> - <PROPERTY NAME="regvalue" TYPE="string"> <VALUE>cronos</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Threat"> - <KEYBINDING NAME="Name"> <KEYVALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|instit|)</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Threat"> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|instit|)</VALUE> </PROPERTY> - <PROPERTY NAME="regkey" TYPE="string"> <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE> </PROPERTY> - <PROPERTY NAME="regvalue" TYPE="string"> <VALUE>instit</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Threat"> - <KEYBINDING NAME="Name"> <KEYVALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Srv32|)</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Threat"> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Srv32|)</VALUE> </PROPERTY> - <PROPERTY NAME="regkey" TYPE="string"> <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE> </PROPERTY> - <PROPERTY NAME="regvalue" TYPE="string"> <VALUE>Srv32</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Threat"> - <KEYBINDING NAME="Name"> <KEYVALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|mqbkup|)</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Threat"> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|mqbkup|)</VALUE> </PROPERTY> - <PROPERTY NAME="regkey" TYPE="string"> <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE> </PROPERTY> - <PROPERTY NAME="regvalue" TYPE="string"> <VALUE>mqbkup</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Threat"> - <KEYBINDING NAME="Name"> <KEYVALUE>W32.HLLW.Nebiwo(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Nav Live Update|)</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Threat"> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>W32.HLLW.Nebiwo(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Nav Live Update|)</VALUE> </PROPERTY> - <PROPERTY NAME="regkey" TYPE="string"> <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE> </PROPERTY> - <PROPERTY NAME="regvalue" TYPE="string"> <VALUE>Nav Live Update</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Threat"> - <KEYBINDING NAME="Name"> <KEYVALUE>W32.Sobig.A(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WindowsMGM|)</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Threat"> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>W32.Sobig.A(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WindowsMGM|)</VALUE> </PROPERTY> - <PROPERTY NAME="regkey" TYPE="string"> <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE> </PROPERTY> - <PROPERTY NAME="regvalue" TYPE="string"> <VALUE>WindowsMGM</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Threat"> - <KEYBINDING NAME="Name"> <KEYVALUE>W32.Welchia.Worm(HKLM\System\CurrentControlSet\Services\RpcPatch||)</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Threat"> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>W32.Welchia.Worm(HKLM\System\CurrentControlSet\Services\RpcPatch||)</VALUE> </PROPERTY> - <PROPERTY NAME="regkey" TYPE="string"> <VALUE>HKLM\System\CurrentControlSet\Services\RpcPatch</VALUE> </PROPERTY> - <PROPERTY NAME="regkeyexists" TYPE="string"> <VALUE>NO</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Threat"> - <KEYBINDING NAME="Name"> <KEYVALUE>W32.Welchia.Worm(HKLM\System\CurrentControlSet\Services\RpcTftpd||)</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Threat"> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>W32.Welchia.Worm(HKLM\System\CurrentControlSet\Services\RpcTftpd||)</VALUE> </PROPERTY> - <PROPERTY NAME="regkey" TYPE="string"> <VALUE>HKLM\System\CurrentControlSet\Services\RpcTftpd</VALUE> </PROPERTY> - <PROPERTY NAME="regkeyexists" TYPE="string"> <VALUE>NO</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Threat"> - <KEYBINDING NAME="Name"> <KEYVALUE>W32.Welchia.Worm(HKLM\System\CurrentControlSet\Services\WksPatch||)</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Threat"> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>W32.Welchia.Worm(HKLM\System\CurrentControlSet\Services\WksPatch||)</VALUE> </PROPERTY> - <PROPERTY NAME="regkey" TYPE="string"> <VALUE>HKLM\System\CurrentControlSet\Services\WksPatch</VALUE> </PROPERTY> - <PROPERTY NAME="regkeyexists" TYPE="string"> <VALUE>NO</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Adware"> - <KEYBINDING NAME="Name"> <KEYVALUE>Adware.180search(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|MSBB|)</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Adware"> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>Adware.180search(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|MSBB|)</VALUE> </PROPERTY> - <PROPERTY NAME="regkey" TYPE="string"> <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE> </PROPERTY> - <PROPERTY NAME="regvalue" TYPE="string"> <VALUE>MSBB</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Adware"> - <KEYBINDING NAME="Name"> <KEYVALUE>Adware.Blazefind(HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83DE62E0-5805-11D8-9B25-00E04C60FAF2}||)</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Adware"> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>Adware.Blazefind(HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83DE62E0-5805-11D8-9B25-00E04C60FAF2}||)</VALUE> </PROPERTY> - <PROPERTY NAME="regkey" TYPE="string"> <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83DE62E0-5805-11D8-9B25-00E04C60FAF2}</VALUE> </PROPERTY> - <PROPERTY NAME="regkeyexists" TYPE="string"> <VALUE>NO</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Adware"> - <KEYBINDING NAME="Name"> <KEYVALUE>Adware.HelpExpress(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|HelpExpress|)</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Adware"> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>Adware.HelpExpress(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|HelpExpress|)</VALUE> </PROPERTY> - <PROPERTY NAME="regkey" TYPE="string"> <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE> </PROPERTY> - <PROPERTY NAME="regvalue" TYPE="string"> <VALUE>HelpExpress</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Adware"> - <KEYBINDING NAME="Name"> <KEYVALUE>Adware.Iefeats(HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\IEFeatSL||)</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Adware"> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>Adware.Iefeats(HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\IEFeatSL||)</VALUE> </PROPERTY> - <PROPERTY NAME="regkey" TYPE="string"> <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\IEFeatSL</VALUE> </PROPERTY> - <PROPERTY NAME="regkeyexists" TYPE="string"> <VALUE>NO</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Adware"> - <KEYBINDING NAME="Name"> <KEYVALUE>Adware.Ilookup(HKCU\Software\ineb||)</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Adware"> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>Adware.Ilookup(HKCU\Software\ineb||)</VALUE> </PROPERTY> - <PROPERTY NAME="regkey" TYPE="string"> <VALUE>HKCU\Software\ineb</VALUE> </PROPERTY> - <PROPERTY NAME="regkeyexists" TYPE="string"> <VALUE>NO</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Adware"> - <KEYBINDING NAME="Name"> <KEYVALUE>Adware.Ipinsight(HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\IpInsight||)</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Adware"> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>Adware.Ipinsight(HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\IpInsight||)</VALUE> </PROPERTY> - <PROPERTY NAME="regkey" TYPE="string"> <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\IpInsight</VALUE> </PROPERTY> - <PROPERTY NAME="regkeyexists" TYPE="string"> <VALUE>NO</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Adware"> - <KEYBINDING NAME="Name"> <KEYVALUE>Adware.Mpgcom(HKLM\Software\Classes\Mpgcom.zoom||)</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Adware"> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>Adware.Mpgcom(HKLM\Software\Classes\Mpgcom.zoom||)</VALUE> </PROPERTY> - <PROPERTY NAME="regkey" TYPE="string"> <VALUE>HKLM\Software\Classes\Mpgcom.zoom</VALUE> </PROPERTY> - <PROPERTY NAME="regkeyexists" TYPE="string"> <VALUE>NO</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> - <VALUE.OBJECTWITHPATH> - <INSTANCEPATH> - <NAMESPACEPATH> <HOST>HOME-GATEWAY</HOST> - <LOCALNAMESPACEPATH> <NAMESPACE NAME="root/symantec" /> </LOCALNAMESPACEPATH> </NAMESPACEPATH> - <INSTANCENAME CLASSNAME="Adware"> - <KEYBINDING NAME="Name"> <KEYVALUE>Adware.Ncase(HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\nCase||)</KEYVALUE> </KEYBINDING> </INSTANCENAME> </INSTANCEPATH> - <INSTANCE CLASSNAME="Adware"> - <PROPERTY NAME="Name" TYPE="string"> <VALUE>Adware.Ncase(HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\nCase||)</VALUE> </PROPERTY> - <PROPERTY NAME="regkey" TYPE="string"> <VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\nCase</VALUE> </PROPERTY> - <PROPERTY NAME="regkeyexists" TYPE="string"> <VALUE>NO</VALUE> </PROPERTY> </INSTANCE> </VALUE.OBJECTWITHPATH> </DECLGROUP.WITHPATH> </DECLARATION> </CIM> </Snapshot> </DataCollection> </UPLOADINFO>
  15. Thanks gosh I found out how to make the file manually. I just wanted to learn how to use the Setup Wizzy. I am trying a step by step using "Next". It just can't find my Time Zone settings. I have tried three versions. Joe