Jump to content

Strange .cab file in Root


Recommended Posts

I found this in the Root directory.

What is it?

e23a0e86-07c3-4b8d-a399-232f849c5f73.cab

containing;

e23a0e86-07c3-4b8d-a399-232f849c5f73.xml

This is the content of .xml (in text form).

<?xml version="1.0" encoding="UTF-8" standalone="no" ?> 
- <UPLOADINFO>
<UPLOADDATA USERNAME="e23a0e86-07c3-4b8d-a399-232f849c5f73" PRODUCTID="Sdc User" PRODUCTNAME="supportal" PROBLEMDESCRIPTION="Symantec ASA Index" Severity="normal" />
- <DataCollection>
- <Snapshot Timestamp="20060410141618.000000+000">
- <CIM CIMVERSION="2.0" DTDVERSION="2.0">
- <DECLARATION>
- <DECLGROUP.WITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/cimv2" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="PCH_Sysinfo">
- <KEYBINDING NAME="SystemID">
<KEYVALUE>{fb7fd39d-68c3-4fd6-a300-90222c9d3484}</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="PCH_Sysinfo">
- <PROPERTY NAME="ClockSpeed" TYPE="uint32">
<VALUE>2601</VALUE>
</PROPERTY>
- <PROPERTY NAME="OSName" TYPE="string">
<VALUE>Windows XP 5.1</VALUE>
</PROPERTY>
- <PROPERTY NAME="OSVersion" TYPE="string">
<VALUE>build 2600</VALUE>
</PROPERTY>
- <PROPERTY NAME="Processor" TYPE="string">
<VALUE>GenuineIntel</VALUE>
</PROPERTY>
- <PROPERTY NAME="RAM" TYPE="uint64">
<VALUE>765</VALUE>
</PROPERTY>
- <PROPERTY NAME="SwapFile" TYPE="string">
<VALUE>C:\pagefile.sys 1623 MB Free</VALUE>
</PROPERTY>
- <PROPERTY NAME="SystemID" TYPE="string">
<VALUE>{fb7fd39d-68c3-4fd6-a300-90222c9d3484}</VALUE>
</PROPERTY>
- <PROPERTY NAME="WindowsDirectory" TYPE="string">
<VALUE>C:\WINDOWS</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/cimv2" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="SDC_UserInfo">
- <KEYBINDING NAME="Name">
<KEYVALUE>SDC_UserInfo</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="SDC_UserInfo">
- <PROPERTY NAME="ClientVersion" TYPE="string">
<VALUE>0.0.0.0</VALUE>
</PROPERTY>
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>SDC_UserInfo</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/cimv2" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Win32_LogicalMemoryConfig">
- <KEYBINDING NAME="Name">
<KEYVALUE>Win32_LogicalMemoryConfig</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Win32_LogicalMemoryConfig">
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>Win32_LogicalMemoryConfig</VALUE>
</PROPERTY>
- <PROPERTY NAME="TotalPhysicalMemory" TYPE="uint64">
<VALUE>765</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/cimv2" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Win32_OperatingSystem">
- <KEYBINDING NAME="Name">
<KEYVALUE>Win32_OperatingSystem</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Win32_OperatingSystem">
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>Win32_OperatingSystem</VALUE>
</PROPERTY>
- <PROPERTY NAME="OSName" TYPE="string">
<VALUE>Windows XP 5.1</VALUE>
</PROPERTY>
- <PROPERTY NAME="OSType" TYPE="string">
<VALUE>WinNT</VALUE>
</PROPERTY>
- <PROPERTY NAME="OSVersion" TYPE="string">
<VALUE>build 2600</VALUE>
</PROPERTY>
- <PROPERTY NAME="SvcPack" TYPE="string">
<VALUE>Service Pack 2</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/cimv2" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="BrowserInfo">
- <KEYBINDING NAME="Name">
<KEYVALUE>BrowserInfo</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="BrowserInfo">
- <PROPERTY NAME="DefaultBrowser" TYPE="string">
<VALUE>Internet Explorer</VALUE>
</PROPERTY>
- <PROPERTY NAME="IEVersion" TYPE="string">
<VALUE>6.0.2900.2180</VALUE>
</PROPERTY>
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>BrowserInfo</VALUE>
</PROPERTY>
- <PROPERTY NAME="NetscapeVersion" TYPE="string">
<VALUE />
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="SDC_Connectivity">
- <KEYBINDING NAME="Name">
<KEYVALUE>ConnectionData</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="SDC_Connectivity">
- <PROPERTY NAME="CTSTicket" TYPE="string">
<VALUE />
</PROPERTY>
- <PROPERTY NAME="DNSName" TYPE="string">
<VALUE>home-gateway</VALUE>
</PROPERTY>
- <PROPERTY NAME="Domain" TYPE="string">
<VALUE>HOME-GATEWAY</VALUE>
</PROPERTY>
- <PROPERTY NAME="HostName" TYPE="string">
<VALUE>HOME-GATEWAY</VALUE>
</PROPERTY>
- <PROPERTY NAME="MacID" TYPE="string">
<VALUE>{fb7fd39d-68c3-4fd6-a300-90222c9d3484}</VALUE>
</PROPERTY>
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>ConnectionData</VALUE>
</PROPERTY>
- <PROPERTY NAME="NetBIOSName" TYPE="string">
<VALUE>HOME-GATEWAY</VALUE>
</PROPERTY>
- <PROPERTY NAME="OSName" TYPE="string">
<VALUE>Windows XP 5.1</VALUE>
</PROPERTY>
- <PROPERTY NAME="PostToQueue" TYPE="string">
<VALUE>1</VALUE>
</PROPERTY>
- <PROPERTY NAME="TCPIP_Address" TYPE="string">
<VALUE>192.168.254.1</VALUE>
</PROPERTY>
- <PROPERTY NAME="UserName" TYPE="string">
<VALUE>Owner</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="SDC_AdditionalSysInfo">
- <KEYBINDING NAME="Name">
<KEYVALUE>SDC_AdditionalSysInfo</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="SDC_AdditionalSysInfo">
- <PROPERTY NAME="MemoryLoad" TYPE="string">
<VALUE>35</VALUE>
</PROPERTY>
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>SDC_AdditionalSysInfo</VALUE>
</PROPERTY>
- <PROPERTY NAME="NumberOfProcessors" TYPE="string">
<VALUE>1</VALUE>
</PROPERTY>
- <PROPERTY NAME="PageFileAvailable" TYPE="string">
<VALUE>1623</VALUE>
</PROPERTY>
- <PROPERTY NAME="PageFileInitialSize" TYPE="string">
<VALUE>2304</VALUE>
</PROPERTY>
- <PROPERTY NAME="PageFileMaxSize" TYPE="string">
<VALUE>2304</VALUE>
</PROPERTY>
- <PROPERTY NAME="PageFileTotal" TYPE="string">
<VALUE>1870</VALUE>
</PROPERTY>
- <PROPERTY NAME="Processor" TYPE="string">
<VALUE>GenuineIntel</VALUE>
</PROPERTY>
- <PROPERTY NAME="ProcessorArchitecture" TYPE="string">
<VALUE>INTEL</VALUE>
</PROPERTY>
- <PROPERTY NAME="ProcessorLevel" TYPE="string">
<VALUE>15</VALUE>
</PROPERTY>
- <PROPERTY NAME="ProcessorRevision" TYPE="string">
<VALUE>521</VALUE>
</PROPERTY>
- <PROPERTY NAME="ProcessorType" TYPE="string">
<VALUE>PROCESSOR_INTEL_PENTIUM</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="SDC_IncidentInfo">
- <KEYBINDING NAME="Name">
<KEYVALUE>IncidentInfo</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="SDC_IncidentInfo">
- <PROPERTY NAME="Description" TYPE="string">
<VALUE>Symantec ASA Index</VALUE>
</PROPERTY>
- <PROPERTY NAME="GUID" TYPE="string">
<VALUE>e23a0e86-07c3-4b8d-a399-232f849c5f73</VALUE>
</PROPERTY>
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>IncidentInfo</VALUE>
</PROPERTY>
- <PROPERTY NAME="Owner" TYPE="string">
<VALUE>Owner</VALUE>
</PROPERTY>
- <PROPERTY NAME="Time" TYPE="string">
<VALUE>4/10/2006 10:16:18 AM</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/cimv2" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Win32_LogicalDisk">
- <KEYBINDING NAME="DriveName">
<KEYVALUE>C:\</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Win32_LogicalDisk">
- <PROPERTY NAME="DriveName" TYPE="string">
<VALUE>C:\</VALUE>
</PROPERTY>
- <PROPERTY NAME="TotalCapacity" TYPE="uint64">
<VALUE>24579416</VALUE>
</PROPERTY>
- <PROPERTY NAME="TotalFreeSpace" TYPE="uint64">
<VALUE>12230720</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/cimv2" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Win32_LogicalDisk">
- <KEYBINDING NAME="DriveName">
<KEYVALUE>E:\</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Win32_LogicalDisk">
- <PROPERTY NAME="DriveName" TYPE="string">
<VALUE>E:\</VALUE>
</PROPERTY>
- <PROPERTY NAME="TotalCapacity" TYPE="uint64">
<VALUE>55448312</VALUE>
</PROPERTY>
- <PROPERTY NAME="TotalFreeSpace" TYPE="uint64">
<VALUE>18194412</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Software">
- <KEYBINDING NAME="Name">
<KEYVALUE>Software</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Software">
- <PROPERTY NAME="BrowserOpenCommand" TYPE="string">
<VALUE>"C:\Program Files\Internet Explorer\iexplore.exe" -nohome</VALUE>
</PROPERTY>
- <PROPERTY NAME="DefaultEmailClient" TYPE="string">
<VALUE>Outlook Express</VALUE>
</PROPERTY>
- <PROPERTY NAME="Locale" TYPE="string">
<VALUE>00000409</VALUE>
</PROPERTY>
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>Software</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="SYMC_NAV_Info">
- <KEYBINDING NAME="Filename">
<KEYVALUE>ABOUTPLG.DLL</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="SYMC_NAV_Info">
- <PROPERTY NAME="CompanyName" TYPE="string">
<VALUE>Symantec Corporation</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileDescription" TYPE="string">
<VALUE>Norton AntiVirus About Plugin</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileModifiedTime" TYPE="DateTime">
<VALUE>01c3bab518893d00ffffffff</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileModifiedTimeFormated" TYPE="DateTime">
<VALUE>12/4/2003 06:22 PM</VALUE>
</PROPERTY>
- <PROPERTY NAME="Filename" TYPE="string">
<VALUE>ABOUTPLG.DLL</VALUE>
</PROPERTY>
- <PROPERTY NAME="FilePath" TYPE="string">
<VALUE>C:\Program Files\Norton SystemWorks\Norton AntiVirus\</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileSize" TYPE="uint64">
<VALUE>156616</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileVersion" TYPE="string">
<VALUE>10.0.10.13</VALUE>
</PROPERTY>
- <PROPERTY NAME="ProductName" TYPE="string">
<VALUE>Norton AntiVirus</VALUE>
</PROPERTY>
- <PROPERTY NAME="ProductVersion" TYPE="string">
<VALUE>10.00.13</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="SYMC_GHOST_Info">
- <KEYBINDING NAME="Filename">
<KEYVALUE>Ghostexp.exe</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="SYMC_GHOST_Info">
- <PROPERTY NAME="CompanyName" TYPE="string">
<VALUE>Symantec Corporation</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileDescription" TYPE="string">
<VALUE>Norton Ghost Explorer</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileModifiedTime" TYPE="DateTime">
<VALUE>01c243c6c0fa2600ffffffff</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileModifiedTimeFormated" TYPE="DateTime">
<VALUE>8/14/2002 03:14 PM</VALUE>
</PROPERTY>
- <PROPERTY NAME="Filename" TYPE="string">
<VALUE>Ghostexp.exe</VALUE>
</PROPERTY>
- <PROPERTY NAME="FilePath" TYPE="string">
<VALUE>C:\Program Files\Norton SystemWorks\Norton Ghost\</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileSize" TYPE="uint64">
<VALUE>761856</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileVersion" TYPE="string">
<VALUE>2003.0.0.775</VALUE>
</PROPERTY>
- <PROPERTY NAME="ProductName" TYPE="string">
<VALUE>Norton Ghost Explorer</VALUE>
</PROPERTY>
- <PROPERTY NAME="ProductVersion" TYPE="string">
<VALUE>2003.775</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="SYMC_NCS_Info">
- <KEYBINDING NAME="Filename">
<KEYVALUE>cs32.exe</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="SYMC_NCS_Info">
- <PROPERTY NAME="CompanyName" TYPE="string">
<VALUE>Symantec Corporation</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileDescription" TYPE="string">
<VALUE>CleanSweep Core</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileModifiedTime" TYPE="DateTime">
<VALUE>01c2430c63090800ffffffff</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileModifiedTimeFormated" TYPE="DateTime">
<VALUE>8/13/2002 05:00 PM</VALUE>
</PROPERTY>
- <PROPERTY NAME="Filename" TYPE="string">
<VALUE>cs32.exe</VALUE>
</PROPERTY>
- <PROPERTY NAME="FilePath" TYPE="string">
<VALUE>C:\Program Files\Norton SystemWorks\Norton CleanSweep\</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileSize" TYPE="uint64">
<VALUE>36864</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileVersion" TYPE="string">
<VALUE>7.0.0.15</VALUE>
</PROPERTY>
- <PROPERTY NAME="ProductName" TYPE="string">
<VALUE>Norton CleanSweep</VALUE>
</PROPERTY>
- <PROPERTY NAME="ProductVersion" TYPE="string">
<VALUE>7.0</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="SYMC_NCS_Info">
- <KEYBINDING NAME="Filename">
<KEYVALUE>cs32.exe</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="SYMC_NCS_Info">
- <PROPERTY NAME="CompanyName" TYPE="string">
<VALUE>Symantec Corporation</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileDescription" TYPE="string">
<VALUE>CleanSweep Core</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileModifiedTime" TYPE="DateTime">
<VALUE>01c2430c63090800ffffffff</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileModifiedTimeFormated" TYPE="DateTime">
<VALUE>8/13/2002 05:00 PM</VALUE>
</PROPERTY>
- <PROPERTY NAME="Filename" TYPE="string">
<VALUE>cs32.exe</VALUE>
</PROPERTY>
- <PROPERTY NAME="FilePath" TYPE="string">
<VALUE>C:\Program Files\Norton SystemWorks\Norton CleanSweep\</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileSize" TYPE="uint64">
<VALUE>36864</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileVersion" TYPE="string">
<VALUE>7.0.0.15</VALUE>
</PROPERTY>
- <PROPERTY NAME="ProductName" TYPE="string">
<VALUE>Norton CleanSweep</VALUE>
</PROPERTY>
- <PROPERTY NAME="ProductVersion" TYPE="string">
<VALUE>7.0</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="SYMC_NSYS_Info">
- <KEYBINDING NAME="Filename">
<KEYVALUE>SWPLUGIN.DLL</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="SYMC_NSYS_Info">
- <PROPERTY NAME="CompanyName" TYPE="string">
<VALUE>Symantec Corporation</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileDescription" TYPE="string">
<VALUE>Norton SystemWorks Plug-in for the Norton Integrator</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileModifiedTime" TYPE="DateTime">
<VALUE>01c24fc3fbb5ae00ffffffff</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileModifiedTimeFormated" TYPE="DateTime">
<VALUE>8/29/2002 09:24 PM</VALUE>
</PROPERTY>
- <PROPERTY NAME="Filename" TYPE="string">
<VALUE>SWPLUGIN.DLL</VALUE>
</PROPERTY>
- <PROPERTY NAME="FilePath" TYPE="string">
<VALUE>C:\Program Files\Norton SystemWorks\</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileSize" TYPE="uint64">
<VALUE>843849</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileVersion" TYPE="string">
<VALUE>6.6.0.12</VALUE>
</PROPERTY>
- <PROPERTY NAME="ProductName" TYPE="string">
<VALUE>Norton SystemWorks</VALUE>
</PROPERTY>
- <PROPERTY NAME="ProductVersion" TYPE="string">
<VALUE>6.6.12</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="SYMC_NU_Info">
- <KEYBINDING NAME="Filename">
<KEYVALUE>norton.exe</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="SYMC_NU_Info">
- <PROPERTY NAME="CompanyName" TYPE="string">
<VALUE>Symantec Corporation</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileDescription" TYPE="string">
<VALUE>Norton Integrator Stub</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileModifiedTime" TYPE="DateTime">
<VALUE>01c24379c54c2200ffffffff</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileModifiedTimeFormated" TYPE="DateTime">
<VALUE>8/14/2002 06:03 AM</VALUE>
</PROPERTY>
- <PROPERTY NAME="Filename" TYPE="string">
<VALUE>norton.exe</VALUE>
</PROPERTY>
- <PROPERTY NAME="FilePath" TYPE="string">
<VALUE>C:\Program Files\Norton SystemWorks\Norton Utilities\</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileSize" TYPE="uint64">
<VALUE>53248</VALUE>
</PROPERTY>
- <PROPERTY NAME="FileVersion" TYPE="string">
<VALUE>16.0.0.22</VALUE>
</PROPERTY>
- <PROPERTY NAME="ProductName" TYPE="string">
<VALUE>Norton Utilities for Windows</VALUE>
</PROPERTY>
- <PROPERTY NAME="ProductVersion" TYPE="string">
<VALUE>16.00.0.22</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="SOS">
- <KEYBINDING NAME="Name">
<KEYVALUE>SOS</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="SOS">
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>SOS</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
<KEYVALUE>Klez(HKLM\System\CurrentControlSet\Services\wink|)</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>Klez(HKLM\System\CurrentControlSet\Services\wink|)</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
<VALUE>HKLM\System\CurrentControlSet\Services\wink</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkeyexists" TYPE="string">
<VALUE>NO</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
<KEYVALUE>Klez(HKLM\System\CurrentControlSet\Services\WQK|DisplayName|)</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>Klez(HKLM\System\CurrentControlSet\Services\WQK|DisplayName|)</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
<VALUE>HKLM\System\CurrentControlSet\Services\WQK</VALUE>
</PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
<VALUE>DisplayName</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
<KEYVALUE>Klez(HKLM\System\CurrentControlSet\Services\krn132|DisplayName|)</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>Klez(HKLM\System\CurrentControlSet\Services\krn132|DisplayName|)</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
<VALUE>HKLM\System\CurrentControlSet\Services\krn132</VALUE>
</PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
<VALUE>DisplayName</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
<KEYVALUE>Klez(HKLM\System\CurrentControlSet\Services\WinSvc|DisplayName|)</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>Klez(HKLM\System\CurrentControlSet\Services\WinSvc|DisplayName|)</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
<VALUE>HKLM\System\CurrentControlSet\Services\WinSvc</VALUE>
</PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
<VALUE>DisplayName</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
<KEYVALUE>Klez(HKLM\System\CurrentControlSet\Services\Wink|DisplayName|)</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>Klez(HKLM\System\CurrentControlSet\Services\Wink|DisplayName|)</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
<VALUE>HKLM\System\CurrentControlSet\Services\Wink</VALUE>
</PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
<VALUE>DisplayName</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
<KEYVALUE>Lirva(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Avril Lavigne - Muse|)</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>Lirva(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Avril Lavigne - Muse|)</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
<VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE>
</PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
<VALUE>Avril Lavigne - Muse</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
<KEYVALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ScrSvr|)</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ScrSvr|)</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
<VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE>
</PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
<VALUE>ScrSvr</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
<KEYVALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Brasil|)</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Brasil|)</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
<VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE>
</PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
<VALUE>Brasil</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
<KEYVALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|cronos|)</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|cronos|)</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
<VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE>
</PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
<VALUE>cronos</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
<KEYVALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|instit|)</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|instit|)</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
<VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE>
</PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
<VALUE>instit</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
<KEYVALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Srv32|)</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Srv32|)</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
<VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE>
</PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
<VALUE>Srv32</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
<KEYVALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|mqbkup|)</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>Opaserv(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|mqbkup|)</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
<VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE>
</PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
<VALUE>mqbkup</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
<KEYVALUE>W32.HLLW.Nebiwo(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Nav Live Update|)</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>W32.HLLW.Nebiwo(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Nav Live Update|)</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
<VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE>
</PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
<VALUE>Nav Live Update</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
<KEYVALUE>W32.Sobig.A(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WindowsMGM|)</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>W32.Sobig.A(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WindowsMGM|)</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
<VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE>
</PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
<VALUE>WindowsMGM</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
<KEYVALUE>W32.Welchia.Worm(HKLM\System\CurrentControlSet\Services\RpcPatch||)</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>W32.Welchia.Worm(HKLM\System\CurrentControlSet\Services\RpcPatch||)</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
<VALUE>HKLM\System\CurrentControlSet\Services\RpcPatch</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkeyexists" TYPE="string">
<VALUE>NO</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
<KEYVALUE>W32.Welchia.Worm(HKLM\System\CurrentControlSet\Services\RpcTftpd||)</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>W32.Welchia.Worm(HKLM\System\CurrentControlSet\Services\RpcTftpd||)</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
<VALUE>HKLM\System\CurrentControlSet\Services\RpcTftpd</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkeyexists" TYPE="string">
<VALUE>NO</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Threat">
- <KEYBINDING NAME="Name">
<KEYVALUE>W32.Welchia.Worm(HKLM\System\CurrentControlSet\Services\WksPatch||)</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Threat">
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>W32.Welchia.Worm(HKLM\System\CurrentControlSet\Services\WksPatch||)</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
<VALUE>HKLM\System\CurrentControlSet\Services\WksPatch</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkeyexists" TYPE="string">
<VALUE>NO</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Adware">
- <KEYBINDING NAME="Name">
<KEYVALUE>Adware.180search(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|MSBB|)</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Adware">
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>Adware.180search(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|MSBB|)</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
<VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE>
</PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
<VALUE>MSBB</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Adware">
- <KEYBINDING NAME="Name">
<KEYVALUE>Adware.Blazefind(HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83DE62E0-5805-11D8-9B25-00E04C60FAF2}||)</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Adware">
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>Adware.Blazefind(HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83DE62E0-5805-11D8-9B25-00E04C60FAF2}||)</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
<VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83DE62E0-5805-11D8-9B25-00E04C60FAF2}</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkeyexists" TYPE="string">
<VALUE>NO</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Adware">
- <KEYBINDING NAME="Name">
<KEYVALUE>Adware.HelpExpress(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|HelpExpress|)</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Adware">
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>Adware.HelpExpress(HKLM\Software\Microsoft\Windows\CurrentVersion\Run|HelpExpress|)</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
<VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</VALUE>
</PROPERTY>
- <PROPERTY NAME="regvalue" TYPE="string">
<VALUE>HelpExpress</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Adware">
- <KEYBINDING NAME="Name">
<KEYVALUE>Adware.Iefeats(HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\IEFeatSL||)</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Adware">
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>Adware.Iefeats(HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\IEFeatSL||)</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
<VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\IEFeatSL</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkeyexists" TYPE="string">
<VALUE>NO</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Adware">
- <KEYBINDING NAME="Name">
<KEYVALUE>Adware.Ilookup(HKCU\Software\ineb||)</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Adware">
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>Adware.Ilookup(HKCU\Software\ineb||)</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
<VALUE>HKCU\Software\ineb</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkeyexists" TYPE="string">
<VALUE>NO</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Adware">
- <KEYBINDING NAME="Name">
<KEYVALUE>Adware.Ipinsight(HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\IpInsight||)</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Adware">
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>Adware.Ipinsight(HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\IpInsight||)</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
<VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\IpInsight</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkeyexists" TYPE="string">
<VALUE>NO</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Adware">
- <KEYBINDING NAME="Name">
<KEYVALUE>Adware.Mpgcom(HKLM\Software\Classes\Mpgcom.zoom||)</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Adware">
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>Adware.Mpgcom(HKLM\Software\Classes\Mpgcom.zoom||)</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
<VALUE>HKLM\Software\Classes\Mpgcom.zoom</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkeyexists" TYPE="string">
<VALUE>NO</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
- <VALUE.OBJECTWITHPATH>
- <INSTANCEPATH>
- <NAMESPACEPATH>
<HOST>HOME-GATEWAY</HOST>
- <LOCALNAMESPACEPATH>
<NAMESPACE NAME="root/symantec" />
</LOCALNAMESPACEPATH>
</NAMESPACEPATH>
- <INSTANCENAME CLASSNAME="Adware">
- <KEYBINDING NAME="Name">
<KEYVALUE>Adware.Ncase(HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\nCase||)</KEYVALUE>
</KEYBINDING>
</INSTANCENAME>
</INSTANCEPATH>
- <INSTANCE CLASSNAME="Adware">
- <PROPERTY NAME="Name" TYPE="string">
<VALUE>Adware.Ncase(HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\nCase||)</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkey" TYPE="string">
<VALUE>HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\nCase</VALUE>
</PROPERTY>
- <PROPERTY NAME="regkeyexists" TYPE="string">
<VALUE>NO</VALUE>
</PROPERTY>
</INSTANCE>
</VALUE.OBJECTWITHPATH>
</DECLGROUP.WITHPATH>
</DECLARATION>
</CIM>
</Snapshot>
</DataCollection>
</UPLOADINFO>

Edited by Tarun
Codeboxes for the win!
Link to comment
Share on other sites


Hmmm,

What’s odd is that the dates of the .cab show Date Created/Modified of 1/29/2008 but the date of the .xml file within is 4/10/2006.

I think I’ll just delete it and see if it returns.

Thanks,

Joe ;)

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...