[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\34]
"Source"="http://newyork.yankees.mlb.com/images/players/action/ph_114739.jpg"
"SubscribedURL"="http://newyork.yankees.mlb.com/images/players/action/ph_114739.jpg"
"FriendlyName"=""
"Flags"=dword:00000001
"Position"=hex:2c,00,00,00,ff,02,00,00,55,01,00,00,b8,00,00,00,7e,00,00,00,2c,\
04,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,00
"OriginalStateInfo"=hex:18,00,00,00,94,02,00,00,a1,00,00,00,bf,00,00,00,87,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:dc,ff,1c,06,09,48,e9,77,88,32,e8,77,ff,ff,ff,ff,de,60,\
e7,77,28,c0,16,05
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\35]
"Source"="http://newyork.yankees.mlb.com/images/players/action/ph_121250.jpg"
"SubscribedURL"="http://newyork.yankees.mlb.com/images/players/action/ph_121250.jpg"
"FriendlyName"=""
"Flags"=dword:00000001
"Position"=hex:2c,00,00,00,dd,02,00,00,7b,00,00,00,bf,00,00,00,87,00,00,00,2e,\
04,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,00
"OriginalStateInfo"=hex:18,00,00,00,12,02,00,00,23,00,00,00,bf,00,00,00,87,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,12,02,00,00,23,00,00,00,bf,00,00,00,87,00,\
00,00,01,00,00,00
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\36]
"Source"="http://newyork.yankees.mlb.com/images/players/action/ph_122111.jpg"
"SubscribedURL"="http://newyork.yankees.mlb.com/images/players/action/ph_122111.jpg"
"FriendlyName"=""
"Flags"=dword:00000001
"Position"=hex:2c,00,00,00,5a,02,00,00,50,00,00,00,bf,00,00,00,87,00,00,00,30,\
04,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,00
"OriginalStateInfo"=hex:18,00,00,00,12,02,00,00,19,01,00,00,bf,00,00,00,87,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:dc,ff,52,06,09,48,e9,77,88,32,e8,77,ff,ff,ff,ff,de,60,\
e7,77,18,f6,db,04
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\37]
"Source"="http://newyork.yankees.mlb.com/images/players/action/ph_116539.jpg"
"SubscribedURL"="http://newyork.yankees.mlb.com/images/players/action/ph_116539.jpg"
"FriendlyName"=""
"Flags"=dword:00000001
"Position"=hex:2c,00,00,00,ce,01,00,00,38,00,00,00,bf,00,00,00,87,00,00,00,32,\
04,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,12,01,00,00,23,00,00,00,bf,00,00,00,87,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:dc,ff,52,06,09,48,e9,77,88,32,e8,77,ff,ff,ff,ff,de,60,\
e7,77,90,93,92,05
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\38]
"Source"="http://minnesota.twins.mlb.com/images/players/action/ph_116338.jpg"
"SubscribedURL"="http://minnesota.twins.mlb.com/images/players/action/ph_116338.jpg"
"FriendlyName"=""
"Flags"=dword:00000001
"Position"=hex:2c,00,00,00,2c,01,00,00,34,00,00,00,bf,00,00,00,87,00,00,00,34,\
04,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,00
"OriginalStateInfo"=hex:18,00,00,00,ee,00,00,00,47,00,00,00,bf,00,00,00,87,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:dc,ff,8e,08,09,48,e9,77,88,32,e8,77,ff,ff,ff,ff,de,60,\
e7,77,08,53,b7,06
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\39]
"Source"="http://boston.redsox.mlb.com/images/players/action/ph_120903.jpg"
"SubscribedURL"="http://boston.redsox.mlb.com/images/players/action/ph_120903.jpg"
"FriendlyName"=""
"Flags"=dword:00000001
"Position"=hex:2c,00,00,00,67,00,00,00,21,00,00,00,b7,00,00,00,87,00,00,00,36,\
04,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ee,01,00,00,47,00,00,00,bf,00,00,00,87,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:dc,ff,6e,08,09,48,e9,77,88,32,e8,77,ff,ff,ff,ff,de,60,\
e7,77,00,a2,b2,06
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\4]
"Source"="http://chicago.cubs.mlb.com/images/players/action/ph_122544.jpg"
"SubscribedURL"="http://chicago.cubs.mlb.com/images/players/action/ph_122544.jpg"
"FriendlyName"=""
"Flags"=dword:00000001
"Position"=hex:2c,00,00,00,53,00,00,00,b3,01,00,00,bf,00,00,00,87,00,00,00,f0,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,00,03,00,00,2b,01,00,00,bf,00,00,00,87,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:dc,ff,a0,09,09,48,e9,77,88,32,e8,77,ff,ff,ff,ff,de,60,\
e7,77,e8,87,d8,04
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\40]
"Source"="http://www.nba.com/media/act_vince_carter.jpg"
"SubscribedURL"="http://www.nba.com/media/act_vince_carter.jpg"
"FriendlyName"=""
"Flags"=dword:00000001
"Position"=hex:2c,00,00,00,05,01,00,00,27,01,00,00,9a,00,00,00,f9,00,00,00,38,\
04,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,00
"OriginalStateInfo"=hex:18,00,00,00,a6,01,00,00,8f,00,00,00,8c,00,00,00,dc,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:dc,ff,e1,06,09,48,e9,77,88,32,e8,77,ff,ff,ff,ff,de,60,\
e7,77,40,84,1b,08
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\41]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,00,00,3a,\
04,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,00
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\5]
"Source"="http://newyork.yankees.mlb.com/images/players/action/ph_121347.jpg"
"SubscribedURL"="http://newyork.yankees.mlb.com/images/players/action/ph_121347.jpg"
"FriendlyName"=""
"Flags"=dword:00000001
"Position"=hex:2c,00,00,00,61,02,00,00,85,00,00,00,bf,00,00,00,87,00,00,00,f2,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,dc,02,00,00,59,00,00,00,bf,00,00,00,87,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:dc,ff,88,05,09,48,e9,77,88,32,e8,77,ff,ff,ff,ff,de,60,\
e7,77,98,8f,b3,06
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\6]
"Source"="http://chicago.whitesox.mlb.com/images/players/action/ph_123245.jpg"
"SubscribedURL"="http://chicago.whitesox.mlb.com/images/players/action/ph_123245.jpg"
"FriendlyName"=""
"Flags"=dword:00000001
"Position"=hex:2c,00,00,00,80,02,00,00,87,00,00,00,bf,00,00,00,87,00,00,00,f4,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ee,00,00,00,3d,01,00,00,bf,00,00,00,87,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:dc,ff,8e,08,09,48,e9,77,88,32,e8,77,ff,ff,ff,ff,de,60,\
e7,77,98,8f,b3,06
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\7]
"Source"="http://tampabay.devilrays.mlb.com/images/players/action/ph_408307.jpg"
"SubscribedURL"="http://tampabay.devilrays.mlb.com/images/players/action/ph_408307.jpg"
"FriendlyName"=""
"Flags"=dword:00000001
"Position"=hex:2c,00,00,00,c3,01,00,00,85,00,00,00,bf,00,00,00,87,00,00,00,f6,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,00,02,00,00,35,00,00,00,bf,00,00,00,87,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:dc,ff,63,03,09,48,e9,77,88,32,e8,77,ff,ff,ff,ff,de,60,\
e7,77,a0,87,a7,05
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\8]
"Source"="http://stlouis.cardinals.mlb.com/images/players/action/ph_405395.jpg"
"SubscribedURL"="http://stlouis.cardinals.mlb.com/images/players/action/ph_405395.jpg"
"FriendlyName"=""
"Flags"=dword:00000001
"Position"=hex:2c,00,00,00,61,02,00,00,b3,01,00,00,bf,00,00,00,87,00,00,00,f8,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,00,03,00,00,35,00,00,00,bf,00,00,00,87,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:dc,ff,9d,08,09,48,e9,77,88,32,e8,77,ff,ff,ff,ff,de,60,\
e7,77,40,68,23,00
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\9]
"Source"="http://florida.marlins.mlb.com/images/players/action/ph_334393.jpg"
"SubscribedURL"="http://florida.marlins.mlb.com/images/players/action/ph_334393.jpg"
"FriendlyName"=""
"Flags"=dword:00000001
"Position"=hex:2c,00,00,00,89,02,00,00,d4,01,00,00,bf,00,00,00,87,00,00,00,fa,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ee,02,00,00,47,00,00,00,bf,00,00,00,87,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:dc,ff,6e,08,09,48,e9,77,88,32,e8,77,ff,ff,ff,ff,de,60,\
e7,77,18,d7,e7,04
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"{259BA022-2005-45E9-A965-10EDB9C00605}"="Windows Updater"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{5BACC17E-BDF7-405B-BC68-ECB506395118}"="NSIS Media Extension"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Alexis^Start Menu^Programs^Startup^MyWebSearch Email Plugin.lnk]
"path"="C:\\Documents and Settings\\Alexis\\Start Menu\\Programs\\Startup\\MyWebSearch Email Plugin.lnk"
"backup"="C:\\WINDOWS\\pss\\MyWebSearch Email Plugin.lnkStartup"
"location"="Startup"
"command"="C:\\Program Files\\MyWebSearch\\bar\\1.bin\\MWSOEMON.EXE "
"item"="MyWebSearch Email Plugin"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~2.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Forget Me Not.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Forget Me Not.lnk"
"backup"="C:\\WINDOWS\\pss\\Forget Me Not.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\BRODER~1\\AGCREA~1\\AGRemind.exe "
"item"="Forget Me Not"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Google Updater.lnk"
"backup"="C:\\WINDOWS\\pss\\Google Updater.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Google\\GOOGLE~2\\11489~1.276\\GOOGLE~1.EXE -systray -startup"
"item"="Google Updater"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="aim"
"hkey"="HKCU"
"command"="C:\\Program Files\\AIM\\aim.exe -cnetwait.odl"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:_Program Files_WordPerfe3a]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CorUpd"
"hkey"="HKCU"
"command"="C:\\Program Files\\WordPerfect Office 11\\Programs\\CorUpd.exe /Watch"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:_PROGRA~1_WORDPE~1_Progr28]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CorUpd"
"hkey"="HKCU"
"command"="C:\\PROGRA~1\\WORDPE~1\\Programs\\CorUpd.exe /Watch"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="daemon"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\D-Tools\\daemon.exe\" -lang 1033"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DW4]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DesktopWeather"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\The Weather Channel FW\\Desktop Weather\\DesktopWeather.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GPClientMonitor]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="GPClientMonitor"
"hkey"="HKLM"
"command"="C:\\Program Files\\GalleryPlayer\\Player\\GPClientMonitor.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GPDownloadManager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="GPDownloadManager"
"hkey"="HKLM"
"command"="C:\\Program Files\\GalleryPlayer\\Player\\GPDownloadManager.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrivacyScanner]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="pscan"
"hkey"="HKCU"
"command"="C:\\Program Files\\Privacy Champion\\pscan.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealPlayer]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="realplay"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Real\\RealPlayer\\realplay.exe\" /RunUPGToolCommandReBoot"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ypager"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Yahoo!\\Messenger\\ypager.exe\" -quiet"
"inimapping"="0"
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system
DisableRegistryTools REG_DWORD 0 (0x0)
DisableTaskMgr REG_DWORD 0 (0x0)
NoDispAppearancePage REG_DWORD 0 (0x0)
NoColorChoice REG_DWORD 0 (0x0)
NoSizeChoice REG_DWORD 0 (0x0)
NoDispBackgroundPage REG_DWORD 0 (0x0)
NoDispScrSavPage REG_DWORD 0 (0x0)
NoDispCPL REG_DWORD 0 (0x0)
NoVisualStyleChoice REG_DWORD 0 (0x0)
NoDispSettingsPage REG_DWORD 0 (0x0)
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\ (HOME-Matt).job
Completion time: Fri 08/11/2006 21:34:36.89
ComboFix ver 06.07.15/30 - This logfile is located at C:\ComboFix.txt
ComboFix.2006-08-11.211509.txt