[code] OTScanIt2 logfile created on: 2/6/2009 5:25:28 PM - Run 1 OTScanIt2 by OldTimer - Version 1.0.7.1 Folder = C:\Users\kc\Desktop\OTScanIt2 Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation Internet Explorer (Version = 7.0.6001.18000) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 893.76 Mb Total Physical Memory | 243.02 Mb Available Physical Memory | 27.19% Memory free 2.00 Gb Paging File | 0.91 Gb Available in Paging File | 45.25% Paging File free Paging file location(s): ?:\pagefile.sys; %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 288.10 Gb Total Space | 197.88 Gb Free Space | 68.69% Space Free | Partition Type: NTFS Drive D: | 9.99 Gb Total Space | 4.44 Gb Free Space | 44.43% Space Free | Partition Type: NTFS E: Drive not present or media not loaded Drive F: | 69.75 Gb Total Space | 3.38 Gb Free Space | 4.85% Space Free | Partition Type: NTFS Drive G: | 4.76 Gb Total Space | 2.23 Gb Free Space | 46.90% Space Free | Partition Type: FAT32 H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: KC-PC Current User Name: kc Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Whitelist: On File Age = 30 Days [Processes - Safe List] a2guard.exe -> %ProgramFiles%\a-squared Anti-Malware\a2guard.exe -> [2009/01/27 16:59:40 | 02,784,912 | ---- | M] (Emsi Software GmbH) a2service.exe -> %ProgramFiles%\a-squared Anti-Malware\a2service.exe -> [2009/01/27 16:59:40 | 00,421,496 | ---- | M] (Emsi Software GmbH) applemobiledeviceservice.exe -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2008/11/07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) avgcsrvx.exe -> %ProgramFiles%\AVG\AVG8\avgcsrvx.exe -> [2009/01/29 19:34:19 | 00,687,896 | ---- | M] (AVG Technologies CZ, s.r.o.) avgemc.exe -> %ProgramFiles%\AVG\AVG8\avgemc.exe -> [2009/01/29 19:33:57 | 00,903,960 | ---- | M] (AVG Technologies CZ, s.r.o.) avgnsx.exe -> %ProgramFiles%\AVG\AVG8\avgnsx.exe -> [2009/01/29 19:34:20 | 00,592,128 | ---- | M] (AVG Technologies CZ, s.r.o.) avgrsx.exe -> %ProgramFiles%\AVG\AVG8\avgrsx.exe -> [2009/01/29 19:34:19 | 00,484,120 | ---- | M] (AVG Technologies CZ, s.r.o.) avgwdsvc.exe -> %ProgramFiles%\AVG\AVG8\avgwdsvc.exe -> [2009/01/29 19:33:52 | 00,298,264 | ---- | M] (AVG Technologies CZ, s.r.o.) dwm.exe -> %SystemRoot%\System32\dwm.exe -> [2008/01/19 00:33:08 | 00,081,920 | ---- | M] (Microsoft Corporation) googletoolbarnotifier.exe -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe -> [2009/01/23 07:29:25 | 00,039,408 | ---- | M] (Google Inc.) googleupdate.exe -> %ProgramFiles%\Google\Update\GoogleUpdate.exe -> [2009/01/27 19:47:30 | 00,119,280 | ---- | M] (Google Inc.) lsm.exe -> %SystemRoot%\System32\lsm.exe -> [2008/01/19 00:33:14 | 00,229,888 | ---- | M] (Microsoft Corporation) mdnsresponder.exe -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) mobsync.exe -> %SystemRoot%\System32\mobsync.exe -> [2008/01/19 00:33:15 | 00,095,744 | ---- | M] (Microsoft Corporation) nvvsvc.exe -> %SystemRoot%\System32\nvvsvc.exe -> [2008/06/20 00:04:00 | 00,118,784 | ---- | M] (NVIDIA Corporation) otscanit2.exe -> %UserProfile%\Desktop\OTScanIt2\OTScanIt2.exe -> [2009/01/26 12:13:22 | 00,485,376 | ---- | M] (OldTimer Tools) rthdvcpl.exe -> %SystemRoot%\RtHDVCpl.exe -> [2007/04/23 15:51:42 | 04,435,968 | ---- | M] (Realtek Semiconductor) searchfilterhost.exe -> %SystemRoot%\System32\SearchFilterHost.exe -> [2008/05/26 22:17:55 | 00,087,552 | ---- | M] (Microsoft Corporation) searchindexer.exe -> %SystemRoot%\System32\SearchIndexer.exe -> [2008/05/26 22:18:43 | 00,439,808 | ---- | M] (Microsoft Corporation) searchprotocolhost.exe -> %SystemRoot%\System32\SearchProtocolHost.exe -> [2008/05/26 22:18:16 | 00,184,832 | ---- | M] (Microsoft Corporation) slsvc.exe -> %SystemRoot%\System32\SLsvc.exe -> [2008/01/19 00:33:22 | 02,623,488 | ---- | M] (Microsoft Corporation) taskeng.exe -> %SystemRoot%\System32\taskeng.exe -> [2008/01/19 00:33:32 | 00,169,472 | ---- | M] (Microsoft Corporation) taskeng.exe -> %SystemRoot%\System32\taskeng.exe -> [2008/01/19 00:33:32 | 00,169,472 | ---- | M] (Microsoft Corporation) taskeng.exe -> %SystemRoot%\System32\taskeng.exe -> [2008/01/19 00:33:32 | 00,169,472 | ---- | M] (Microsoft Corporation) usnsvc.exe -> %ProgramFiles%\Windows Live\Messenger\usnsvc.exe -> [2007/10/18 10:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) wininit.exe -> %SystemRoot%\System32\wininit.exe -> [2008/01/19 00:33:37 | 00,096,768 | ---- | M] (Microsoft Corporation) wmpnetwk.exe -> %ProgramFiles%\Windows Media Player\wmpnetwk.exe -> [2008/01/19 00:33:39 | 00,896,512 | ---- | M] (Microsoft Corporation) wmpnscfg.exe -> %ProgramFiles%\Windows Media Player\wmpnscfg.exe -> [2008/01/19 00:33:39 | 00,202,240 | ---- | M] (Microsoft Corporation) wudfhost.exe -> %SystemRoot%\System32\WUDFHost.exe -> [2008/01/19 00:33:40 | 00,142,336 | ---- | M] (Microsoft Corporation) xaudio.exe -> %SystemRoot%\System32\drivers\XAudio.exe -> [2006/08/04 18:39:20 | 00,386,560 | ---- | M] (Conexant Systems, Inc.) [Win32 Services - Safe List] (a2AntiMalware) a-squared Anti-Malware Service [Win32_Own | Auto | Running] -> %ProgramFiles%\a-squared Anti-Malware\a2service.exe -> [2009/01/27 16:59:40 | 00,421,496 | ---- | M] (Emsi Software GmbH) (AeLookupSvc) Application Experience [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\aelupsvc.dll -> [2006/11/02 02:46:02 | 00,024,576 | ---- | M] (Microsoft Corporation) (Appinfo) Application Information [Win32_Shared | On_Demand | Running] -> %SystemRoot%\System32\appinfo.dll -> [2008/01/19 00:33:43 | 00,033,280 | ---- | M] (Microsoft Corporation) (Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2008/11/07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) (avg8emc) AVG Free8 E-mail Scanner [Win32_Own | Auto | Running] -> %ProgramFiles%\AVG\AVG8\avgemc.exe -> [2009/01/29 19:33:57 | 00,903,960 | ---- | M] (AVG Technologies CZ, s.r.o.) (avg8wd) AVG Free8 WatchDog [Win32_Own | Auto | Running] -> %ProgramFiles%\AVG\AVG8\avgwdsvc.exe -> [2009/01/29 19:33:52 | 00,298,264 | ---- | M] (AVG Technologies CZ, s.r.o.) (BFE) Base Filtering Engine [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\BFE.DLL -> [2008/01/19 00:33:47 | 00,328,704 | ---- | M] (Microsoft Corporation) (Bonjour Service) Bonjour Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) (CertPropSvc) Certificate Propagation [Win32_Shared | Unknown | Running] -> %SystemRoot%\System32\certprop.dll -> [2008/01/19 00:33:51 | 00,040,448 | ---- | M] (Microsoft Corporation) (clr_optimization_v2.0.50727_32) Microsoft .NET Framework NGEN v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2008/01/05 04:26:41 | 00,070,144 | ---- | M] (Microsoft Corporation) (DFSR) DFS Replication [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\System32\dfsr.exe -> [2008/01/19 00:33:06 | 02,091,520 | ---- | M] (Microsoft Corporation) (DPS) Diagnostic Policy Service [Win32_Shared | Unknown | Running] -> %SystemRoot%\System32\dps.dll -> [2008/01/19 00:34:06 | 00,134,656 | ---- | M] (Microsoft Corporation) (ehRecvr) Windows Media Center Receiver Service [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\ehome\ehrecvr.exe -> [2008/01/19 00:33:09 | 00,292,352 | ---- | M] (Microsoft Corporation) (ehSched) Windows Media Center Scheduler Service [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\ehome\ehsched.exe -> [2006/11/02 05:35:29 | 00,131,072 | ---- | M] (Microsoft Corporation) (ehstart) Windows Media Center Service Launcher [Win32_Shared | Auto | Stopped] -> %SystemRoot%\ehome\ehstart.dll -> [2006/11/02 05:35:29 | 00,013,312 | ---- | M] (Microsoft Corporation) (EMDMgmt) ReadyBoost [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\emdmgmt.dll -> [2008/06/25 20:29:02 | 00,565,248 | ---- | M] (Microsoft Corporation) (fdPHost) Function Discovery Provider Host [Win32_Shared | On_Demand | Running] -> %SystemRoot%\System32\fdPHost.dll -> [2008/01/19 00:34:21 | 00,013,312 | ---- | M] (Microsoft Corporation) (FDResPub) Function Discovery Resource Publication [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\FDResPub.dll -> [2006/11/02 02:46:04 | 00,027,648 | ---- | M] (Microsoft Corporation) (FontCache3.0.0.0) Windows Presentation Foundation Font Cache 3.0.0.0 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -> [2008/01/05 04:21:53 | 00,036,864 | ---- | M] (Microsoft Corporation) (GameConsoleService) GameConsoleService [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\eMachines Games\eMachines Game Console\GameConsoleService.exe -> [2008/05/05 15:25:46 | 00,165,416 | ---- | M] (WildTangent, Inc.) (GoogleDesktopManager-061008-081103) Google Desktop Manager 5.7.806.10245 [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Google\Google Desktop Search\GoogleDesktop.exe -> [2008/09/27 22:34:43 | 00,029,744 | ---- | M] (Google) (gpsvc) Group Policy Client [Win32_Shared | Unknown | Running] -> %SystemRoot%\System32\gpsvc.dll -> [2008/01/19 00:34:25 | 00,574,464 | ---- | M] (Microsoft Corporation) (gupdate1c980f2ca0647e0) Google Update Service (gupdate1c980f2ca0647e0) [Win32_Own | Auto | Stopped] -> %ProgramFiles%\Google\Update\GoogleUpdate.exe -> [2009/01/27 19:47:30 | 00,119,280 | ---- | M] (Google Inc.) (gusvc) Google Software Updater [Win32_Own | Auto | Stopped] -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> [2009/01/27 19:39:02 | 00,182,768 | ---- | M] (Google) (IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\11\Intel 32\IDriverT.exe -> [2005/04/03 23:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) (idsvc) Windows CardSpace [Win32_Shared | Unknown | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -> [2008/01/05 04:21:39 | 00,864,256 | ---- | M] (Microsoft Corporation) (IKEEXT) IKE and AuthIP IPsec Keying Modules [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\IKEEXT.DLL -> [2008/01/19 00:34:32 | 00,438,272 | ---- | M] (Microsoft Corporation) (IPBusEnum) PnP-X IP Bus Enumerator [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\System32\IPBusEnum.dll -> [2008/01/19 00:34:34 | 00,074,240 | ---- | M] (Microsoft Corporation) (iphlpsvc) IP Helper [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\iphlpsvc.dll -> [2008/01/19 00:34:34 | 00,188,416 | ---- | M] (Microsoft Corporation) (iPod Service) iPod Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\iPod\bin\iPodService.exe -> [2008/11/20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) (KtmRm) KtmRm for Distributed Transaction Coordinator [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\msdtckrm.dll -> [2008/01/19 00:34:56 | 00,344,576 | ---- | M] (Microsoft Corporation) (lltdsvc) Link-Layer Topology Discovery Mapper [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\System32\lltdsvc.dll -> [2008/01/19 00:34:42 | 00,188,928 | ---- | M] (Microsoft Corporation) (Mcx2Svc) Windows Media Center Extender Service [Win32_Shared | Disabled | Stopped] -> %SystemRoot%\System32\Mcx2Svc.dll -> [2008/01/19 00:34:44 | 00,053,760 | ---- | M] (Microsoft Corporation) (MMCSS) Multimedia Class Scheduler [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\mmcss.dll -> [2008/01/19 00:34:49 | 00,045,056 | ---- | M] (Microsoft Corporation) (MpsSvc) Windows Firewall [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\MPSSVC.dll -> [2008/01/19 00:34:53 | 00,393,216 | ---- | M] (Microsoft Corporation) (MSiSCSI) Microsoft iSCSI Initiator Service [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\System32\iscsiexe.dll -> [2008/01/19 00:34:35 | 00,111,616 | ---- | M] (Microsoft Corporation) (netprofm) Network List Service [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\netprofm.dll -> [2008/01/19 00:35:36 | 00,237,056 | ---- | M] (Microsoft Corporation) (NetTcpPortSharing) Net.Tcp Port Sharing Service [Win32_Shared | Disabled | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -> [2008/01/05 04:21:39 | 00,122,880 | ---- | M] (Microsoft Corporation) (NlaSvc) Network Location Awareness [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\nlasvc.dll -> [2008/01/19 00:35:38 | 00,168,448 | ---- | M] (Microsoft Corporation) (nsi) Network Store Interface Service [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\nsisvc.dll -> [2008/01/19 00:35:57 | 00,018,432 | ---- | M] (Microsoft Corporation) (nvsvc) NVIDIA Display Driver Service [Win32_Own | Auto | Running] -> %SystemRoot%\System32\nvvsvc.exe -> [2008/06/20 00:04:00 | 00,118,784 | ---- | M] (NVIDIA Corporation) (odserv) Microsoft Office Diagnostics Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\microsoft shared\OFFICE12\ODSERV.EXE -> [2007/08/24 02:19:12 | 00,443,776 | ---- | M] (Microsoft Corporation) (ose) Office Source Engine [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\microsoft shared\Source Engine\OSE.EXE -> [2006/10/26 15:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) (p2pimsvc) Peer Networking Identity Manager [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\System32\p2psvc.dll -> [2008/01/19 00:36:09 | 00,658,944 | ---- | M] (Microsoft Corporation) (p2psvc) Peer Networking Grouping [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\System32\p2psvc.dll -> [2008/01/19 00:36:09 | 00,658,944 | ---- | M] (Microsoft Corporation) (PcaSvc) Program Compatibility Assistant Service [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\pcasvc.dll -> [2008/01/19 00:36:03 | 00,037,888 | ---- | M] (Microsoft Corporation) (pla) Performance Logs & Alerts [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\System32\pla.dll -> [2008/01/19 00:36:06 | 01,502,208 | ---- | M] (Microsoft Corporation) (PlugPlay) Plug and Play [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\umpnpmgr.dll -> [2008/01/19 00:36:45 | 00,221,696 | ---- | M] (Microsoft Corporation) (PNRPAutoReg) PNRP Machine Name Publication Service [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\System32\p2psvc.dll -> [2008/01/19 00:36:09 | 00,658,944 | ---- | M] (Microsoft Corporation) (PNRPsvc) Peer Name Resolution Protocol [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\System32\p2psvc.dll -> [2008/01/19 00:36:09 | 00,658,944 | ---- | M] (Microsoft Corporation) (PolicyAgent) IPsec Policy Agent [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\IPSECSVC.DLL -> [2008/09/27 23:00:20 | 00,361,984 | ---- | M] (Microsoft Corporation) (ProfSvc) User Profile Service [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\profsvc.dll -> [2008/01/19 00:36:11 | 00,153,600 | ---- | M] (Microsoft Corporation) (QWAVE) Quality Windows Audio Video Experience [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\System32\qwave.dll -> [2008/01/19 00:36:14 | 00,243,712 | ---- | M] (Microsoft Corporation) (SCardSvr) Smart Card [Win32_Shared | Unknown | Stopped] -> %SystemRoot%\System32\SCardSvr.dll -> [2008/01/19 00:36:19 | 00,095,232 | ---- | M] (Microsoft Corporation) (SCPolicySvc) Smart Card Removal Policy [Win32_Shared | Unknown | Stopped] -> %SystemRoot%\System32\certprop.dll -> [2008/01/19 00:33:51 | 00,040,448 | ---- | M] (Microsoft Corporation) (SDRSVC) Windows Backup [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\System32\sdrsvc.dll -> [2008/01/19 00:36:20 | 00,104,960 | ---- | M] (Microsoft Corporation) (SessionEnv) Terminal Services Configuration [Win32_Shared | On_Demand | Running] -> %SystemRoot%\System32\SessEnv.dll -> [2008/01/19 00:36:21 | 00,084,992 | ---- | M] (Microsoft Corporation) (slsvc) Software Licensing [Win32_Own | Auto | Running] -> %SystemRoot%\System32\SLsvc.exe -> [2008/01/19 00:33:22 | 02,623,488 | ---- | M] (Microsoft Corporation) (SLUINotify) SL UI Notification Service [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\System32\SLUINotify.dll -> [2008/01/19 00:36:30 | 00,057,856 | ---- | M] (Microsoft Corporation) (SNMPTRAP) SNMP Trap [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\System32\snmptrap.exe -> [2006/11/02 02:45:46 | 00,012,800 | ---- | M] (Microsoft Corporation) (SstpSvc) Secure Socket Tunneling Protocol Service [Win32_Shared | On_Demand | Running] -> %SystemRoot%\System32\sstpsvc.dll -> [2008/01/19 00:36:36 | 00,116,736 | ---- | M] (Microsoft Corporation) (swprv) Microsoft Software Shadow Copy Provider [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\System32\swprv.dll -> [2008/01/19 00:36:37 | 00,310,784 | ---- | M] (Microsoft Corporation) (SysMain) Superfetch [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\sysmain.dll -> [2008/01/19 00:36:38 | 00,574,976 | ---- | M] (Microsoft Corporation) (TabletInputService) Tablet PC Input Service [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\TabSvc.dll -> [2006/11/02 05:35:24 | 00,068,096 | ---- | M] (Microsoft Corporation) (TBS) TPM Base Services [Win32_Shared | Auto | Stopped] -> %SystemRoot%\System32\tbssvc.dll -> [2008/01/19 00:36:39 | 00,056,320 | ---- | M] (Microsoft Corporation) (THREADORDER) Thread Ordering Server [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\System32\mmcss.dll -> [2008/01/19 00:34:49 | 00,045,056 | ---- | M] (Microsoft Corporation) (TrustedInstaller) Windows Modules Installer [Win32_Own | Unknown | Stopped] -> %SystemRoot%\servicing\TrustedInstaller.exe -> [2008/01/19 00:33:33 | 00,039,424 | ---- | M] (Microsoft Corporation) (UI0Detect) Interactive Services Detection [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\System32\UI0Detect.exe -> [2008/01/19 00:33:33 | 00,035,840 | ---- | M] (Microsoft Corporation) (UxSms) Desktop Window Manager Session Manager [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\uxsms.dll -> [2008/01/19 00:36:47 | 00,028,672 | ---- | M] (Microsoft Corporation) (vds) Virtual Disk [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\System32\vds.exe -> [2008/01/19 00:33:33 | 00,382,976 | ---- | M] (Microsoft Corporation) (wcncsvc) Windows Connect Now - Config Registrar [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\System32\wcncsvc.dll -> [2008/01/19 00:36:49 | 00,412,672 | ---- | M] (Microsoft Corporation) (WcsPlugInService) Windows Color System [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\System32\WcsPlugInService.dll -> [2006/11/02 02:46:13 | 00,032,256 | ---- | M] (Microsoft Corporation) (WdiServiceHost) Diagnostic Service Host [Win32_Shared | Unknown | Stopped] -> %SystemRoot%\System32\wdi.dll -> [2008/01/19 00:36:50 | 00,073,728 | ---- | M] (Microsoft Corporation) (WdiSystemHost) Diagnostic System Host [Win32_Shared | Unknown | Running] -> %SystemRoot%\System32\wdi.dll -> [2008/01/19 00:36:50 | 00,073,728 | ---- | M] (Microsoft Corporation) (Wecsvc) Windows Event Collector [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\System32\wecsvc.dll -> [2008/01/19 00:36:52 | 00,145,408 | ---- | M] (Microsoft Corporation) (wercplsupport) Problem Reports and Solutions Control Panel Support [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\System32\wercplsupport.dll -> [2008/01/19 00:36:52 | 00,062,976 | ---- | M] (Microsoft Corporation) (WerSvc) Windows Error Reporting Service [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\wersvc.dll -> [2008/09/17 21:56:07 | 00,125,952 | ---- | M] (Microsoft Corporation) (WinDefend) Windows Defender [Win32_Shared | Auto | Running] -> %ProgramFiles%\Windows Defender\MpSvc.dll -> [2008/01/19 00:38:24 | 00,272,952 | ---- | M] (Microsoft Corporation) (WinHttpAutoProxySvc) WinHTTP Web Proxy Auto-Discovery Service [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\System32\winhttp.dll -> [2008/01/19 00:36:55 | 00,376,832 | ---- | M] (Microsoft Corporation) (WinRM) Windows Remote Management (WS-Management) [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\System32\WsmSvc.dll -> [2008/01/19 00:37:11 | 00,745,472 | ---- | M] (Microsoft Corporation) (Wlansvc) WLAN AutoConfig [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\wlansvc.dll -> [2008/01/19 00:36:57 | 00,513,536 | ---- | M] (Microsoft Corporation) (WLSetupSvc) Windows Live Setup Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Windows Live\installer\WLSetupSvc.exe -> [2007/10/25 14:27:54 | 00,266,240 | ---- | M] (Microsoft Corporation) (WMPNetworkSvc) Windows Media Player Network Sharing Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\Windows Media Player\wmpnetwk.exe -> [2008/01/19 00:33:39 | 00,896,512 | ---- | M] (Microsoft Corporation) (WPCSvc) Parental Controls [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\System32\wpcsvc.dll -> [2008/01/19 00:37:08 | 00,140,288 | ---- | M] (Microsoft Corporation) (WPDBusEnum) Portable Device Enumerator Service [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\wpdbusenum.dll -> [2008/01/19 00:37:08 | 00,070,144 | ---- | M] (Microsoft Corporation) (WSearch) Windows Search [Win32_Own | Auto | Running] -> %SystemRoot%\System32\SearchIndexer.exe -> [2008/05/26 22:18:43 | 00,439,808 | ---- | M] (Microsoft Corporation) (wuauserv) Windows Update [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\wuaueng.dll -> [2008/10/16 14:13:38 | 01,809,944 | ---- | M] (Microsoft Corporation) (wudfsvc) Windows Driver Foundation - User-mode Driver Framework [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\WUDFSvc.dll -> [2008/01/19 00:37:12 | 00,055,296 | ---- | M] (Microsoft Corporation) (XAudioService) XAudioService [Win32_Own | Auto | Running] -> %SystemRoot%\System32\drivers\XAudio.exe -> [2006/08/04 18:39:20 | 00,386,560 | ---- | M] (Conexant Systems, Inc.) (usnjsvc) Messenger Sharing Folders USN Journal Reader service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\Windows Live\Messenger\usnsvc.exe -> [2007/10/18 10:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) [Driver Services - Safe List] (ac97intc) Intel(r) 82801 Audio Driver Install Service (WDM) [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\drivers\ac97intc.sys -> [2006/11/02 00:36:49 | 00,108,032 | ---- | M] (Intel Corporation) (adp94xx) adp94xx [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\adp94xx.sys -> [2006/11/02 02:51:38 | 00,420,968 | ---- | M] (Adaptec, Inc.) (adpahci) adpahci [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\adpahci.sys -> [2006/11/02 02:51:32 | 00,297,576 | ---- | M] (Adaptec, Inc.) (adpu160m) adpu160m [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\adpu160m.sys -> [2006/11/02 02:50:35 | 00,098,408 | ---- | M] (Adaptec, Inc.) (adpu320) adpu320 [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\adpu320.sys -> [2006/11/02 02:51:00 | 00,147,048 | ---- | M] (Adaptec, Inc.) (aic78xx) aic78xx [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\djsvs.sys -> [2006/11/02 02:50:11 | 00,071,272 | ---- | M] (Adaptec, Inc.) (aliide) aliide [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\aliide.sys -> [2006/11/02 02:49:20 | 00,014,952 | ---- | M] (Acer Laboratories Inc.) (amdagp) AMD AGP Bus Filter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\drivers\AMDAGP.SYS -> [2006/11/02 02:49:59 | 00,054,888 | ---- | M] (Microsoft Corporation) (amdide) amdide [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\amdide.sys -> [2006/11/02 02:49:26 | 00,015,464 | ---- | M] (Microsoft Corporation) (AmdK7) AMD K7 Processor Driver [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\amdk7.sys -> [2006/11/02 01:30:18 | 00,038,912 | ---- | M] (Microsoft Corporation) (AmdK8) AMD K8 Processor Driver [Kernel | On_Demand | Running] -> %SystemRoot%\System32\drivers\amdk8.sys -> [2008/01/18 22:27:20 | 00,044,032 | ---- | M] (Microsoft Corporation) (arc) arc [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\arc.sys -> [2006/11/02 02:50:09 | 00,067,688 | ---- | M] (Adaptec, Inc.) (arcsas) arcsas [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\arcsas.sys -> [2006/11/02 02:50:10 | 00,067,688 | ---- | M] (Adaptec, Inc.) (AvgLdx86) AVG Free AVI Loader Driver x86 [Kernel | System | Running] -> %SystemRoot%\System32\drivers\avgldx86.sys -> [2009/01/29 19:34:55 | 00,325,128 | ---- | M] (AVG Technologies CZ, s.r.o.) (AvgMfx86) AVG Free On-access Scanner Minifilter Driver x86 [File_System | System | Running] -> %SystemRoot%\System32\drivers\avgmfx86.sys -> [2009/01/29 19:34:54 | 00,027,656 | ---- | M] (AVG Technologies CZ, s.r.o.) (AvgTdiX) AVG Free8 Network Redirector [Kernel | System | Running] -> %SystemRoot%\System32\drivers\avgtdix.sys -> [2009/01/29 19:35:13 | 00,107,272 | ---- | M] (AVG Technologies CZ, s.r.o.) (bcm4sbxp) Broadcom 440x 10/100 Integrated Controller XP Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\drivers\bcm4sbxp.sys -> [2006/11/02 00:30:53 | 00,045,056 | ---- | M] (Broadcom Corporation) (bowser) bowser [File_System | On_Demand | Running] -> %SystemRoot%\System32\drivers\bowser.sys -> [2008/01/18 22:28:26 | 00,069,632 | ---- | M] (Microsoft Corporation) (BrFiltLo) Brother USB Mass-Storage Lower Filter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\drivers\BrFiltLo.sys -> [2006/11/02 01:24:45 | 00,013,568 | ---- | M] (Brother Industries, Ltd.) (BrFiltUp) Brother USB Mass-Storage Upper Filter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\drivers\BrFiltUp.sys -> [2006/11/02 01:24:46 | 00,005,248 | ---- | M] (Brother Industries, Ltd.) (Brserid) Brother MFC Serial Port Interface Driver (WDM) [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\BrSerId.sys -> [2006/11/02 01:25:24 | 00,071,808 | ---- | M] (Brother Industries Ltd.) (BrSerWdm) Brother WDM Serial driver [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\BrSerWdm.sys -> [2006/11/02 01:24:44 | 00,062,336 | ---- | M] (Brother Industries Ltd.) (BrUsbMdm) Brother MFC USB Fax Only Modem [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\BrUsbMdm.sys -> [2006/11/02 01:24:44 | 00,012,160 | ---- | M] (Brother Industries Ltd.) (BrUsbSer) Brother MFC USB Serial WDM Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\drivers\BrUsbSer.sys -> [2006/11/02 01:24:47 | 00,011,904 | ---- | M] (Brother Industries Ltd.) (BTHMODEM) Bluetooth Serial Communications Driver [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\bthmodem.sys -> [2006/11/02 01:55:23 | 00,039,936 | ---- | M] (Microsoft Corporation) (circlass) Consumer IR Devices [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\circlass.sys -> [2006/11/02 01:55:08 | 00,035,328 | ---- | M] (Microsoft Corporation) (CLFS) Common Log (CLFS) [Kernel | Unknown | Running] -> %SystemRoot%\System32\clfs.sys -> [2008/01/19 00:42:58 | 00,247,352 | ---- | M] (Microsoft Corporation) (cmdide) cmdide [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\cmdide.sys -> [2006/11/02 02:49:28 | 00,016,488 | ---- | M] (CMD Technology, Inc.) (crcdisk) Crcdisk Filter Driver [Kernel | Boot | Running] -> %SystemRoot%\System32\drivers\crcdisk.sys -> [2006/11/02 02:49:43 | 00,022,632 | ---- | M] (Microsoft Corporation) (Crusoe) Transmeta Crusoe Processor Driver [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\crusoe.sys -> [2006/11/02 01:30:18 | 00,038,912 | ---- | M] (Microsoft Corporation) (DfsC) DFS Namespace Client Driver [File_System | System | Running] -> %SystemRoot%\System32\drivers\dfsc.sys -> [2008/01/18 22:28:20 | 00,075,264 | ---- | M] (Microsoft Corporation) (DXGKrnl) LDDM Graphics Subsystem [Kernel | On_Demand | Running] -> %SystemRoot%\System32\drivers\dxgkrnl.sys -> [2008/08/01 18:01:23 | 00,625,152 | ---- | M] (Microsoft Corporation) (E1G60) Intel(R) PRO/1000 NDIS 6 Adapter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\drivers\E1G60I32.sys -> [2006/11/02 00:30:54 | 00,117,760 | ---- | M] (Intel Corporation) (Ecache) ReadyBoost Caching Driver [Kernel | Boot | Running] -> %SystemRoot%\System32\drivers\ecache.sys -> [2008/01/19 00:42:11 | 00,143,416 | ---- | M] (Microsoft Corporation) (elxstor) elxstor [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\elxstor.sys -> [2006/11/02 02:51:34 | 00,316,520 | ---- | M] (Emulex) (exfat) exFAT File System Driver [File_System | On_Demand | Stopped] -> %SystemRoot%\System32\drivers\exfat.sys -> [2008/01/18 22:28:01 | 00,136,192 | ---- | M] (Microsoft Corporation) (FileInfo) File Information FS MiniFilter [File_System | Boot | Running] -> %SystemRoot%\System32\drivers\fileinfo.sys -> [2008/01/19 00:42:31 | 00,058,936 | ---- | M] (Microsoft Corporation) (Filetrace) Filetrace [File_System | On_Demand | Stopped] -> %SystemRoot%\System32\drivers\filetrace.sys -> [2008/01/18 22:30:23 | 00,027,648 | ---- | M] (Microsoft Corporation) (gagp30kx) Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\drivers\GAGP30KX.SYS -> [2006/11/02 02:50:04 | 00,058,984 | ---- | M] (Microsoft Corporation) (GEARAspiWDM) GEAR ASPI Filter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\System32\drivers\GEARAspiWDM.sys -> [2008/04/17 13:12:54 | 00,015,464 | ---- | M] (GEAR Software Inc.) (gmer) gmer [Kernel | Unknown | Stopped] -> %SystemRoot%\System32\drivers\gmer.sys -> [2009/02/04 07:35:13 | 00,085,969 | ---- | M] (GMER) (HdAudAddService) Microsoft 1.1 UAA Function Driver for High Definition Audio Service [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\drivers\HdAudio.sys -> [2006/11/02 00:36:49 | 00,235,520 | ---- | M] (Microsoft Corporation) (HDAudBus) Microsoft UAA Bus Driver for High Definition Audio [Kernel | On_Demand | Running] -> %SystemRoot%\System32\drivers\hdaudbus.sys -> [2008/01/18 21:30:49 | 00,053,760 | ---- | M] (Microsoft Corporation) (HidBth) Microsoft Bluetooth HID Miniport [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\hidbth.sys -> [2006/11/02 01:55:22 | 00,029,184 | ---- | M] (Microsoft Corporation) (HidIr) Microsoft Infrared HID Driver [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\hidir.sys -> [2006/11/02 01:55:01 | 00,021,504 | ---- | M] (Microsoft Corporation) (HpCISSs) HpCISSs [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\HpCISSs.sys -> [2006/11/02 02:50:10 | 00,037,480 | ---- | M] (Hewlett-Packard Company) (HSF_DPV) HSF_DPV [Kernel | On_Demand | Running] -> %SystemRoot%\System32\drivers\HSX_DPV.sys -> [2006/11/08 16:55:10 | 00,986,624 | ---- | M] (Conexant Systems, Inc.) (HSXHWBS2) HSXHWBS2 [Kernel | On_Demand | Running] -> %SystemRoot%\System32\drivers\HSXHWBS2.sys -> [2006/11/08 16:54:02 | 00,258,048 | ---- | M] (Conexant Systems, Inc.) (ialm) ialm [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\drivers\ialmnt5.sys -> [2006/11/02 00:36:45 | 01,302,492 | ---- | M] (Intel Corporation) (iaStorV) Intel RAID Controller Vista [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\iaStorV.sys -> [2006/11/02 02:51:25 | 00,232,040 | ---- | M] (Intel Corporation) (iirsp) iirsp [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\iirsp.sys -> [2006/11/02 02:50:17 | 00,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) (IntcAzAudAddService) Service for Realtek HD Audio (WDM) [Kernel | On_Demand | Running] -> %SystemRoot%\System32\drivers\RTKVHDA.sys -> [2007/04/23 18:13:22 | 01,769,952 | ---- | M] (Realtek Semiconductor Corp.) (IPMIDRV) IPMIDRV [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\IPMIDrv.sys -> [2006/11/02 01:42:03 | 00,065,536 | ---- | M] (Microsoft Corporation) (iScsiPrt) iScsiPort Driver [Kernel | On_Demand | Running] -> %SystemRoot%\System32\drivers\msiscsi.sys -> [2008/01/19 00:42:35 | 00,181,304 | ---- | M] (Microsoft Corporation) (iteatapi) ITEATAPI_Service_Install [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\iteatapi.sys -> [2006/11/02 02:50:07 | 00,035,944 | ---- | M] (Integrated Technology Express, Inc.) (iteraid) ITERAID_Service_Install [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\iteraid.sys -> [2006/11/02 02:50:09 | 00,035,944 | ---- | M] (Integrated Technology Express, Inc.) (kbdhid) Keyboard HID Driver [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\kbdhid.sys -> [2006/11/02 01:51:12 | 00,015,872 | ---- | M] (Microsoft Corporation) (lltdio) Link-Layer Topology Discovery Mapper I/O Driver [Kernel | Auto | Running] -> %SystemRoot%\System32\drivers\lltdio.sys -> [2008/01/18 22:55:03 | 00,047,104 | ---- | M] (Microsoft Corporation) (LSI_FC) LSI_FC [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\lsi_fc.sys -> [2006/11/02 02:50:04 | 00,065,640 | ---- | M] (LSI Logic) (LSI_SAS) LSI_SAS [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\lsi_sas.sys -> [2006/11/02 02:50:05 | 00,065,640 | ---- | M] (LSI Logic) (LSI_SCSI) LSI_SCSI [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\lsi_scsi.sys -> [2006/11/02 02:50:10 | 00,065,640 | ---- | M] (LSI Logic) (luafv) UAC File Virtualization [File_System | Auto | Running] -> %SystemRoot%\System32\drivers\luafv.sys -> [2008/01/18 22:30:36 | 00,084,480 | ---- | M] (Microsoft Corporation) (mdmxsdk) mdmxsdk [Kernel | Auto | Running] -> %SystemRoot%\System32\drivers\mdmxsdk.sys -> [2006/06/19 15:26:58 | 00,012,672 | ---- | M] (Conexant) (megasas) megasas [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\megasas.sys -> [2006/11/02 02:49:53 | 00,028,776 | ---- | M] (LSI Logic Corporation) (monitor) Microsoft Monitor Class Function Driver Service [Kernel | On_Demand | Running] -> %SystemRoot%\System32\drivers\monitor.sys -> [2008/01/18 22:52:19 | 00,041,984 | ---- | M] (Microsoft Corporation) (motmodem) Motorola USB CDC ACM Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\drivers\motmodem.sys -> [2007/06/18 20:18:26 | 00,023,680 | ---- | M] (Motorola) (mpio) Microsoft Multi-Path Bus Driver [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\mpio.sys -> [2006/11/02 02:50:16 | 00,078,952 | ---- | M] (Microsoft Corporation) (mpsdrv) Windows Firewall Authorization Driver [Kernel | On_Demand | Running] -> %SystemRoot%\System32\drivers\mpsdrv.sys -> [2008/01/18 22:54:46 | 00,064,000 | ---- | M] (Microsoft Corporation) (Mraid35x) Mraid35x [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\Mraid35x.sys -> [2006/11/02 02:49:59 | 00,033,384 | ---- | M] (LSI Logic Corporation) (mrxsmb10) SMB 1.x MiniRedirector [File_System | On_Demand | Running] -> %SystemRoot%\System32\drivers\mrxsmb10.sys -> [2008/08/26 18:05:41 | 00,212,480 | ---- | M] (Microsoft Corporation) (mrxsmb20) SMB 2.0 MiniRedirector [File_System | On_Demand | Running] -> %SystemRoot%\System32\drivers\mrxsmb20.sys -> [2008/01/18 22:28:37 | 00,078,848 | ---- | M] (Microsoft Corporation) (msahci) msahci [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\msahci.sys -> [2006/11/02 02:49:44 | 00,023,144 | ---- | M] (Microsoft Corporation) (msdsm) Microsoft Multi-Path Device Specific Module [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\msdsm.sys -> [2006/11/02 02:50:17 | 00,080,488 | ---- | M] (Microsoft Corporation) (msisadrv) ISA/EISA Class Driver [Kernel | Boot | Running] -> %SystemRoot%\System32\drivers\msisadrv.sys -> [2008/01/19 00:41:14 | 00,016,440 | ---- | M] (Microsoft Corporation) (MsRPC) MsRPC [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\drivers\msrpc.sys -> [2008/01/19 00:42:29 | 00,163,384 | ---- | M] (Microsoft Corporation) (NativeWifiP) NativeWiFi Filter [Kernel | On_Demand | Running] -> %SystemRoot%\System32\drivers\nwifi.sys -> [2008/05/19 19:07:31 | 00,148,480 | ---- | M] (Microsoft Corporation) (NETw2v32) Intel(R) PRO/Wireless 2200BG Network Connection Driver for Windows Vista [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\drivers\NETw2v32.sys -> [2006/11/02 00:30:56 | 02,589,184 | ---- | M] (Intel® Corporation) (nfrd960) nfrd960 [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\nfrd960.sys -> [2006/11/02 02:50:19 | 00,045,160 | ---- | M] (IBM Corporation) (nsiproxy) NSI proxy service [Kernel | System | Running] -> %SystemRoot%\System32\drivers\nsiproxy.sys -> [2008/01/18 22:55:50 | 00,016,384 | ---- | M] (Microsoft Corporation) (ntrigdigi) N-trig HID Tablet Driver [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\ntrigdigi.sys -> [2006/11/02 00:36:50 | 00,020,608 | ---- | M] (N-trig Innovative Technologies) (nvlddmkm) nvlddmkm [Kernel | On_Demand | Running] -> %SystemRoot%\System32\drivers\nvlddmkm.sys -> [2008/06/20 00:04:00 | 07,468,128 | ---- | M] (NVIDIA Corporation) (nvraid) nvraid [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\nvraid.sys -> [2006/11/02 02:50:24 | 00,088,680 | ---- | M] (NVIDIA Corporation) (nvstor) nvstor [Kernel | Boot | Running] -> %SystemRoot%\System32\drivers\nvstor.sys -> [2006/11/02 02:50:13 | 00,040,040 | ---- | M] (NVIDIA Corporation) (nvstor32) nvstor32 [Kernel | Boot | Running] -> %SystemRoot%\System32\drivers\nvstor32.sys -> [2007/08/09 18:12:30 | 00,110,624 | ---- | M] (NVIDIA Corporation) (nv_agp) NVIDIA nForce AGP Bus Filter [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\drivers\NV_AGP.SYS -> [2006/11/02 02:50:40 | 00,106,600 | ---- | M] (Microsoft Corporation) (PEAUTH) PEAUTH [Kernel | Auto | Running] -> %SystemRoot%\System32\drivers\PEAuth.sys -> [2006/11/02 02:04:35 | 00,878,080 | ---- | M] (Microsoft Corporation) (PSched) QoS Packet Scheduler [Kernel | System | Running] -> %SystemRoot%\System32\drivers\pacer.sys -> [2008/04/04 18:21:42 | 00,072,192 | ---- | M] (Microsoft Corporation) (ql2300) QLogic Fibre Channel Miniport Driver [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\ql2300.sys -> [2006/11/02 02:51:45 | 00,900,712 | ---- | M] (QLogic Corporation) (ql40xx) QLogic iSCSI Miniport Driver [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\ql40xx.sys -> [2006/11/02 02:50:35 | 00,106,088 | ---- | M] (QLogic Corporation) (QWAVEdrv) QWAVE driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\drivers\qwavedrv.sys -> [2008/01/18 22:56:07 | 00,031,232 | ---- | M] (Microsoft Corporation) (RasSstp) WAN Miniport (SSTP) [Kernel | On_Demand | Running] -> %SystemRoot%\System32\drivers\rassstp.sys -> [2008/01/18 22:56:43 | 00,069,120 | ---- | M] (Microsoft Corporation) (RDPENCDD) RDP Encoder Mirror Driver [Kernel | System | Running] -> %SystemRoot%\System32\drivers\RDPENCDD.sys -> [2008/01/18 23:01:09 | 00,006,144 | ---- | M] (Microsoft Corporation) (rspndr) Link-Layer Topology Discovery Responder [Kernel | Auto | Running] -> %SystemRoot%\System32\drivers\rspndr.sys -> [2008/01/18 22:55:03 | 00,060,416 | ---- | M] (Microsoft Corporation) (SaiH075C) SaiH075C [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\drivers\SaiH075C.sys -> [2007/05/01 16:11:28 | 00,132,232 | ---- | M] (Saitek) (sbp2port) SBP-2 Transport/Protocol Bus Driver [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\sbp2port.sys -> [2006/11/02 02:50:16 | 00,076,392 | ---- | M] (Microsoft Corporation) (sdbus) sdbus [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\sdbus.sys -> [2006/11/02 01:35:12 | 00,082,432 | ---- | M] (Microsoft Corporation) (secdrv) Security Driver [Kernel | Auto | Running] -> %SystemRoot%\System32\drivers\secdrv.sys -> [2006/11/01 23:37:21 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) (sermouse) Serial Mouse Driver [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\sermouse.sys -> [2008/01/18 22:49:16 | 00,019,968 | ---- | M] (Microsoft Corporation) (sffdisk) SFF Storage Class Driver [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\sffdisk.sys -> [2006/11/02 01:51:38 | 00,013,312 | ---- | M] (Microsoft Corporation) (sffp_mmc) SFF Storage Protocol Driver for MMC [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\drivers\sffp_mmc.sys -> [2006/11/02 01:51:40 | 00,012,800 | ---- | M] (Microsoft Corporation) (sffp_sd) SFF Storage Protocol Driver for SDBus [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\drivers\sffp_sd.sys -> [2006/11/02 01:51:40 | 00,012,800 | ---- | M] (Microsoft Corporation) (sisagp) SIS AGP Bus Filter [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\drivers\SISAGP.SYS -> [2006/11/02 02:49:51 | 00,053,352 | ---- | M] (Microsoft Corporation) (SiSRaid2) SiSRaid2 [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\sisraid2.sys -> [2006/11/02 02:50:10 | 00,038,504 | ---- | M] (Silicon Integrated Systems Corp.) (SiSRaid4) SiSRaid4 [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\sisraid4.sys -> [2006/11/02 02:50:16 | 00,071,784 | ---- | M] (Silicon Integrated Systems) (Smb) Message-oriented TCP/IP and TCP/IPv6 Protocol (SMB session) [Kernel | System | Running] -> %SystemRoot%\System32\drivers\smb.sys -> [2008/01/18 22:55:27 | 00,066,560 | ---- | M] (Microsoft Corporation) (spldr) Security Processor Loader Driver [Kernel | Boot | Running] -> %SystemRoot%\System32\drivers\spldr.sys -> [2008/01/19 00:41:30 | 00,021,048 | ---- | M] (Microsoft Corporation) (srv2) srv2 [File_System | On_Demand | Running] -> %SystemRoot%\System32\drivers\srv2.sys -> [2008/01/18 22:29:15 | 00,144,384 | ---- | M] (Microsoft Corporation) (srvnet) srvnet [File_System | On_Demand | Running] -> %SystemRoot%\System32\drivers\srvnet.sys -> [2008/01/18 22:29:12 | 00,098,304 | ---- | M] (Microsoft Corporation) (Symc8xx) Symc8xx [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\symc8xx.sys -> [2006/11/02 02:50:05 | 00,035,944 | ---- | M] (LSI Logic) (Sym_hi) Sym_hi [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\sym_hi.sys -> [2006/11/02 02:49:56 | 00,031,848 | ---- | M] (LSI Logic) (Sym_u3) Sym_u3 [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\sym_u3.sys -> [2006/11/02 02:50:03 | 00,034,920 | ---- | M] (LSI Logic) (tcpipreg) TCP/IP Registry Compatibility [Kernel | Auto | Running] -> %SystemRoot%\System32\drivers\tcpipreg.sys -> [2008/01/18 22:56:07 | 00,030,208 | ---- | M] (Microsoft Corporation) (tdx) NetIO Legacy TDI Support Driver [Kernel | System | Running] -> %SystemRoot%\System32\drivers\tdx.sys -> [2008/01/18 22:55:58 | 00,071,680 | ---- | M] (Microsoft Corporation) (tssecsrv) Terminal Services Security Filter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\System32\drivers\tssecsrv.sys -> [2008/01/18 23:01:15 | 00,023,552 | ---- | M] (Microsoft Corporation) (tunmp) Microsoft Tun Miniport Adapter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\System32\drivers\TUNMP.SYS -> [2008/01/18 22:55:41 | 00,015,360 | ---- | M] (Microsoft Corporation) (tunnel) Microsoft IPv6 Tunnel Miniport Adapter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\System32\drivers\tunnel.sys -> [2008/01/18 22:55:50 | 00,023,040 | ---- | M] (Microsoft Corporation) (uagp35) Microsoft AGPv3.5 Filter [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\drivers\UAGP35.SYS -> [2006/11/02 02:49:59 | 00,056,936 | ---- | M] (Microsoft Corporation) (uliagpkx) Uli AGP Bus Filter [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\drivers\ULIAGPKX.SYS -> [2006/11/02 02:50:04 | 00,058,472 | ---- | M] (Microsoft Corporation) (uliahci) uliahci [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\uliahci.sys -> [2006/11/02 02:51:25 | 00,235,112 | ---- | M] (ULi Electronics Inc.) (UlSata) UlSata [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\ulsata.sys -> [2006/11/02 02:50:35 | 00,098,408 | ---- | M] (Promise Technology, Inc.) (ulsata2) ulsata2 [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\ulsata2.sys -> [2006/11/02 02:50:45 | 00,115,816 | ---- | M] (Promise Technology, Inc.) (umbus) UMBus Enumerator Driver [Kernel | On_Demand | Running] -> %SystemRoot%\System32\drivers\umbus.sys -> [2008/01/18 22:53:40 | 00,034,816 | ---- | M] (Microsoft Corporation) (usbcir) eHome Infrared Receiver (USBCIR) [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\usbcir.sys -> [2006/11/02 01:55:09 | 00,068,608 | ---- | M] (Microsoft Corporation) (vga) vga [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\drivers\vgapnp.sys -> [2006/11/02 01:53:56 | 00,026,112 | ---- | M] (Microsoft Corporation) (ViaC7) VIA C7 Processor Driver [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\viac7.sys -> [2006/11/02 01:30:19 | 00,039,424 | ---- | M] (Microsoft Corporation) (viaide) viaide [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\viaide.sys -> [2006/11/02 02:49:30 | 00,017,512 | ---- | M] (VIA Technologies, Inc.) (volmgr) Volume Manager Driver [Kernel | Boot | Running] -> %SystemRoot%\System32\drivers\volmgr.sys -> [2008/01/19 00:42:18 | 00,052,792 | ---- | M] (Microsoft Corporation) (volmgrx) Dynamic Volume Manager [Kernel | Boot | Running] -> %SystemRoot%\System32\drivers\volmgrx.sys -> [2008/01/19 00:43:03 | 00,294,456 | ---- | M] (Microsoft Corporation) (vsmraid) vsmraid [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\vsmraid.sys -> [2006/11/02 02:50:41 | 00,112,232 | ---- | M] (VIA Technologies Inc.,Ltd) (WacomPen) Wacom Serial Pen HID Driver [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\wacompen.sys -> [2006/11/02 01:52:52 | 00,020,608 | ---- | M] (Microsoft Corporation) (Wd) Microsoft Watchdog Timer Driver [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\wd.sys -> [2006/11/02 02:49:38 | 00,019,560 | ---- | M] (Microsoft Corporation) (Wdf01000) Kernel Mode Driver Frameworks service [Kernel | Boot | Running] -> %SystemRoot%\System32\drivers\Wdf01000.sys -> [2008/01/19 00:43:27 | 00,503,864 | ---- | M] (Microsoft Corporation) (winachsf) winachsf [Kernel | On_Demand | Running] -> %SystemRoot%\System32\drivers\HSX_CNXT.sys -> [2006/11/08 16:53:48 | 00,659,968 | ---- | M] (Conexant Systems, Inc.) (WmiAcpi) Microsoft Windows Management Interface for ACPI [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\wmiacpi.sys -> [2006/11/02 01:35:03 | 00,011,264 | ---- | M] (Microsoft Corporation) (ws2ifsl) Winsock IFS driver [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\ws2ifsl.sys -> [2008/01/18 22:56:49 | 00,015,872 | ---- | M] (Microsoft Corporation) (XAudio) XAudio [Kernel | Auto | Running] -> %SystemRoot%\System32\drivers\XAudio.sys -> [2006/08/04 18:39:10 | 00,008,192 | ---- | M] (Conexant Systems, Inc.) (yukonwlh) NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller [Kernel | On_Demand | Running] -> %SystemRoot%\System32\drivers\yk60x86.sys -> [2007/12/06 09:51:00 | 00,298,496 | ---- | M] (Marvell) [Registry - Safe List] < Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://go.microsoft.com/fwlink/?LinkId=69157 -> HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" -> -> HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons -> HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> C:\Windows\SYSTEM32\blank.htm -> HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk -> HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=nofound&Br=EM&Loc=ENG_US&Sys=DTP&M=T5234 -> HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> < Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> HKEY_CURRENT_USER\: Main\\"Local Page" -> C:\Windows\SYSTEM32\blank.htm -> HKEY_CURRENT_USER\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_CURRENT_USER\: Main\\"SearchDefaultBranded" -> -> HKEY_CURRENT_USER\: Main\\"Start Page" -> http://www.google.ca/ -> HKEY_CURRENT_USER\: Main\\"StartPageCache" -> -> HKEY_CURRENT_USER\: SearchURL\\"" -> http://home.microsoft.com/access/autosearch.asp?p=%s -> HKEY_CURRENT_USER\: "ProxyEnable" -> 0 -> HKEY_CURRENT_USER\: "ProxyOverride" -> *.local -> < HOSTS File > (761 bytes and 20 lines) -> C:\Windows\System32\drivers\etc\Hosts -> 127.0.0.1 localhost ::1 localhost < BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> %CommonProgramFiles%\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> [2006/10/22 23:08:42 | 00,062,080 | ---- | M] (Adobe Systems Incorporated) {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} [HKLM] -> %ProgramFiles%\AVG\AVG8\avgssie.dll [AVG Safe Search] -> [2009/01/29 19:34:23 | 01,078,552 | ---- | M] (AVG Technologies CZ, s.r.o.) {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_01\bin\ssv.dll [SSVHelper Class] -> [2007/03/14 04:43:40 | 00,501,400 | ---- | M] (Sun Microsystems, Inc.) {9030D464-4C02-4ABF-8ECC-5164760863C6} [HKLM] -> %CommonProgramFiles%\microsoft shared\Windows Live\WindowsLiveLogin.dll [Windows Live Sign-in Helper] -> [2007/09/20 09:30:18 | 00,328,752 | ---- | M] (Microsoft Corporation) {AA58ED58-01DD-4d91-8333-CF10577473F7} [HKLM] -> %ProgramFiles%\Google\Google Toolbar\GoogleToolbar.dll [Google Toolbar Helper] -> [2009/01/22 21:33:35 | 00,251,504 | ---- | M] () {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKLM] -> %ProgramFiles%\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll [Google Toolbar Notifier BHO] -> [2009/01/23 07:29:25 | 00,657,904 | ---- | M] (Google Inc.) {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} [HKLM] -> %ProgramFiles%\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll [Google Dictionary Compression sdch] -> [2009/01/22 21:33:34 | 00,522,224 | ---- | M] (Google Inc.) < Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\Google\Google Toolbar\GoogleToolbar.dll [&Google Toolbar] -> [2009/01/22 21:33:35 | 00,251,504 | ---- | M] () < Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\Google\Google Toolbar\GoogleToolbar.dll [&Google Toolbar] -> [2009/01/22 21:33:35 | 00,251,504 | ---- | M] () < Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "Adobe Reader Speed Launcher" -> %ProgramFiles%\Adobe\Reader 8.0\Reader\reader_sl.exe ["C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"] -> [2008/10/15 01:04:34 | 00,039,792 | ---- | M] (Adobe Systems Incorporated) "a-squared" -> %ProgramFiles%\a-squared Anti-Malware\a2guard.exe ["C:\PROGRAM FILES\A-SQUARED ANTI-MALWARE\a2guard.exe" /d=60] -> [2009/01/27 16:59:40 | 02,784,912 | ---- | M] (Emsi Software GmbH) "AVG8_TRAY" -> %ProgramFiles%\AVG\AVG8\avgtray.exe [C:\PROGRA~1\AVG\AVG8\avgtray.exe] -> [2009/01/29 19:34:05 | 01,601,304 | ---- | M] (AVG Technologies CZ, s.r.o.) "MSConfig" -> %SystemRoot%\System32\msconfig.exe ["C:\Windows\System32\msconfig.exe" /auto] -> [2008/01/19 00:33:16 | 00,227,840 | ---- | M] (Microsoft Corporation) "NvCplDaemon" -> %SystemRoot%\System32\nvcpl.dll [RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup] -> [2008/06/20 00:04:00 | 13,535,776 | ---- | M] (NVIDIA Corporation) "NvMediaCenter" -> %SystemRoot%\System32\nvmctray.dll [RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit] -> [2008/06/20 00:04:00 | 00,092,704 | ---- | M] (NVIDIA Corporation) "RtHDVCpl" -> %SystemRoot%\RtHDVCpl.exe [RtHDVCpl.exe] -> [2007/04/23 15:51:42 | 04,435,968 | ---- | M] (Realtek Semiconductor) < Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "msnmsgr" -> %ProgramFiles%\Windows Live\Messenger\msnmsgr.exe ["C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background] -> [2007/10/18 10:34:02 | 05,724,184 | ---- | M] (Microsoft Corporation) "swg" -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] -> [2009/01/23 07:29:25 | 00,039,408 | ---- | M] (Google Inc.) "WeatherEye" -> %ProgramFiles%\TheWeatherNetwork\WeatherEye\WeatherEye.exe [C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe] -> [2009/01/16 11:30:40 | 04,519,832 | ---- | M] (MétéoMédia/The Weather Network) < Software Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer -> < Software Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer -> < CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDrives" -> [0] -> File not found < CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System \\"ConsentPromptBehaviorAdmin" -> [2] -> File not found \\"ConsentPromptBehaviorUser" -> [1] -> File not found \\"EnableInstallerDetection" -> [1] -> File not found \\"EnableLUA" -> [1] -> File not found \\"EnableSecureUIAPaths" -> [1] -> File not found \\"EnableVirtualization" -> [1] -> File not found \\"PromptOnSecureDesktop" -> [1] -> File not found \\"ValidateAdminCodeSignatures" -> [0] -> File not found \\"dontdisplaylastusername" -> [0] -> File not found \\"legalnoticecaption" -> [] -> File not found \\"legalnoticetext" -> [] -> File not found \\"scforceoption" -> [0] -> File not found \\"shutdownwithoutlogon" -> [1] -> File not found \\"undockwithoutlogon" -> [1] -> File not found \\"FilterAdministratorToken" -> [0] -> File not found \\"EnableUIADesktopToggle" -> [0] -> File not found \\"DisableRegistryTools" -> [0] -> File not found HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats \UIPI\Clipboard\ExceptionFormats\\"CF_TEXT" -> [1] -> File not found \UIPI\Clipboard\ExceptionFormats\\"CF_BITMAP" -> [2] -> File not found \UIPI\Clipboard\ExceptionFormats\\"CF_OEMTEXT" -> [7] -> File not found \UIPI\Clipboard\ExceptionFormats\\"CF_DIB" -> [8] -> File not found \UIPI\Clipboard\ExceptionFormats\\"CF_PALETTE" -> [9] -> File not found \UIPI\Clipboard\ExceptionFormats\\"CF_UNICODETEXT" -> [13] -> File not found \UIPI\Clipboard\ExceptionFormats\\"CF_DIBV5" -> [17] -> File not found < CurrentVersion Policy Settings - Explorer [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDrives" -> [0] -> File not found < CurrentVersion Policy Settings - System [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> < Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> E&xport to Microsoft Excel -> %ProgramFiles%\Microsoft Office\Office12\EXCEL.EXE [res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000] -> [2008/10/18 18:30:22 | 17,931,616 | ---- | M] (Microsoft Corporation) < Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> {08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_01\bin\npjpi160_01.dll [Menu: Sun Java Console] -> [2007/03/14 04:43:41 | 00,132,760 | ---- | M] (Sun Microsystems, Inc.) {2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> %ProgramFiles%\Microsoft Office\Office12\ONBttnIE.dll [Button: Send to OneNote] -> [2007/12/13 01:20:58 | 00,606,288 | ---- | M] (Microsoft Corporation) {2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> %ProgramFiles%\Microsoft Office\Office12\ONBttnIE.dll [Menu: S&end to OneNote] -> [2007/12/13 01:20:58 | 00,606,288 | ---- | M] (Microsoft Corporation) {92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> %ProgramFiles%\Microsoft Office\Office12\REFIEBAR.DLL [Button: Research] -> [2006/10/26 21:12:22 | 00,040,424 | ---- | M] (Microsoft Corporation) < Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> < Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix "" -> http:// < Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 5241 domain(s) found. -> www_eset.eu [http] -> Trusted sites -> 49 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 37 range(s) found. -> GD [:Range = 127.0.0.1] -> http = Local intranet | -> < Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> {0CCA191D-13A6-4E29-B746-314DEE697D83} [HKLM] -> http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab [Facebook Photo Uploader 5 Control] -> {1D082E71-DF20-4AAF-863B-596428C49874} [HKLM] -> http://www.worldwinner.com/games/v50/tpir/tpir.cab [TPIR Control] -> {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} [HKLM] -> http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab [ActiveScan 2.0 Installer Class] -> {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} [HKLM] -> http://www.worldwinner.com/games/shared/wwlaunch.cab [Wwlaunch Control] -> {8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab [Java Plug-in 1.6.0_01] -> {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} [HKLM] -> http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab [Reg Error: Key does not exist or could not be opened.] -> {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} [HKLM] -> http://www.worldwinner.com/games/v57/wof/wof.cab [WoF Control] -> {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab [Java Plug-in 1.6.0_01] -> {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab [Java Plug-in 1.6.0_01] -> {CF969D51-F764-4FBF-9E90-475248601C8A} [HKLM] -> http://www.worldwinner.com/games/v47/familyfeud/familyfeud.cab [FamilyFeud Control] -> < DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> {39C4EDCE-C952-401B-8BDB-7A845C92F787} -> (Marvell Yukon 88E8039 PCI-E Fast Ethernet Controller) -> < AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs -> *AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls -> C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL -> %ProgramFiles%\Google\Google Desktop Search\GoogleDesktopNetwork3.dll -> [2008/09/27 22:34:44 | 00,113,664 | ---- | M] (Google) avgrsstx.dll -> %SystemRoot%\System32\avgrsstx.dll -> [2009/01/29 19:35:13 | 00,010,520 | ---- | M] (AVG Technologies CZ, s.r.o.) *MultiFile Done* -> -> < SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders -> *SecurityProviders* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders -> credssp.dll -> %SystemRoot%\System32\credssp.dll -> [2008/01/19 00:33:59 | 00,015,872 | ---- | M] (Microsoft Corporation) *MultiFile Done* -> -> < LSA Authentication Packages [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages -> *LSA Security Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages -> tspkg -> %SystemRoot%\System32\TSpkg.dll -> [2008/01/19 00:36:42 | 00,062,464 | ---- | M] (Microsoft Corporation) *MultiFile Done* -> -> < Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List -> < SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot -> "AlternateShell" -> cmd.exe -> < CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom -> "AutoRun" -> 1 -> "DisplayName" -> CD-ROM Driver -> "ImagePath" -> %SystemRoot%\System32\drivers\cdrom.sys [system32\DRIVERS\cdrom.sys] -> [2008/01/18 22:49:51 | 00,067,072 | ---- | M] (Microsoft Corporation) < Drives with AutoRun files > -> -> C:\autoexec.bat [REM Dummy file for NTVDM | ] -> %SystemDrive%\autoexec.bat [ NTFS ] -> [2006/09/18 14:43:36 | 00,000,024 | ---- | M] () F:\AUTOEXEC.BAT [] -> F:\AUTOEXEC.BAT [ NTFS ] -> [2004/08/26 11:04:39 | 00,000,000 | ---- | M] () G:\autorun.inf.aug.8 [[AUTORUN] | OPEN=Info.exe folder.htt 480 480 | ] -> G:\autorun.inf [ FAT32 ] -> File not found < MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 -> [Files/Folders - Created Within 30 Days] OTScanIt2 -> %UserProfile%\Desktop\OTScanIt2 -> [2009/02/06 17:25:04 | 00,000,000 | ---D | C] OTScanIt2.exe -> %UserProfile%\Desktop\OTScanIt2.exe -> [2009/02/06 17:23:57 | 00,656,714 | ---- | C] () LeakTest.exe -> %UserProfile%\Desktop\LeakTest.exe -> [2009/02/06 17:22:59 | 00,025,600 | R--- | C] (Gibson Research Corp.) temp -> %SystemRoot%\temp -> [2009/02/06 07:43:45 | 00,000,000 | ---D | C] SWXCACLS.exe -> %SystemRoot%\SWXCACLS.exe -> [2009/02/06 07:34:01 | 00,212,480 | ---- | C] (SteelWerX) SWREG.exe -> %SystemRoot%\SWREG.exe -> [2009/02/06 07:34:01 | 00,161,792 | ---- | C] (SteelWerX) SWSC.exe -> %SystemRoot%\SWSC.exe -> [2009/02/06 07:34:01 | 00,136,704 | ---- | C] (SteelWerX) sed.exe -> %SystemRoot%\sed.exe -> [2009/02/06 07:34:01 | 00,098,816 | ---- | C] () fdsv.exe -> %SystemRoot%\fdsv.exe -> [2009/02/06 07:34:01 | 00,089,504 | ---- | C] (Smallfrogs Studio) grep.exe -> %SystemRoot%\grep.exe -> [2009/02/06 07:34:01 | 00,080,412 | ---- | C] () zip.exe -> %SystemRoot%\zip.exe -> [2009/02/06 07:34:01 | 00,068,096 | ---- | C] () VFIND.exe -> %SystemRoot%\VFIND.exe -> [2009/02/06 07:34:01 | 00,049,152 | ---- | C] () NIRCMD.exe -> %SystemRoot%\NIRCMD.exe -> [2009/02/06 07:34:01 | 00,029,696 | ---- | C] (NirSoft) Qoobox -> %SystemDrive%\Qoobox -> [2009/02/06 07:33:41 | 00,000,000 | ---D | C] ComboFix -> %SystemDrive%\ComboFix -> [2009/02/06 07:33:40 | 00,000,000 | ---D | C] ComboFix.exe -> %UserProfile%\Desktop\ComboFix.exe -> [2009/02/06 07:28:06 | 02,913,680 | R--- | C] () Adobe -> %UserProfile%\AppData\Local\Adobe -> [2009/02/05 21:57:25 | 00,000,000 | ---D | C] Apple -> %UserProfile%\AppData\Local\Apple -> [2009/02/04 17:17:07 | 00,000,000 | ---D | C] pavboot.sys -> %SystemRoot%\System32\drivers\pavboot.sys -> [2009/02/04 14:27:55 | 00,028,544 | ---- | C] (Panda Security, S.L.) Panda Security -> %ProgramFiles%\Panda Security -> [2009/02/04 14:27:50 | 00,000,000 | ---D | C] IconCache.db -> %UserProfile%\AppData\Local\IconCache.db -> [2009/02/04 09:48:03 | 02,533,508 | -H-- | C] () gmer.ini -> %SystemRoot%\gmer.ini -> [2009/02/04 07:35:19 | 00,000,250 | ---- | C] () gmer.dll -> %SystemRoot%\gmer.dll -> [2009/02/04 07:35:13 | 00,884,736 | ---- | C] () gmer.sys -> %SystemRoot%\System32\drivers\gmer.sys -> [2009/02/04 07:35:13 | 00,085,969 | ---- | C] (GMER) gmer_uninstall.cmd -> %SystemRoot%\gmer_uninstall.cmd -> [2009/02/04 07:35:13 | 00,000,080 | ---- | C] () Template -> %AppData%\Template -> [2009/02/03 14:03:33 | 00,000,000 | ---D | C] wklnhst.dat -> %AppData%\wklnhst.dat -> [2009/02/03 14:03:28 | 00,000,000 | ---- | C] () Malwarebytes -> %AppData%\Malwarebytes -> [2009/02/03 11:13:42 | 00,000,000 | ---D | C] mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> [2009/02/03 11:13:37 | 00,015,504 | ---- | C] (Malwarebytes Corporation) Malwarebytes' Anti-Malware.lnk -> %SystemDrive%\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk -> [2009/02/03 11:13:37 | 00,000,818 | ---- | C] () mbamswissarmy.sys -> %SystemRoot%\System32\drivers\mbamswissarmy.sys -> [2009/02/03 11:13:35 | 00,038,496 | ---- | C] (Malwarebytes Corporation) Malwarebytes' Anti-Malware -> %ProgramFiles%\Malwarebytes' Anti-Malware -> [2009/02/03 11:13:34 | 00,000,000 | ---D | C] Malwarebytes -> %AllUsersProfile%\Malwarebytes -> [2009/02/03 11:13:34 | 00,000,000 | ---D | C] hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [2009/01/30 17:48:27 | 93,794,3040 | -HS- | C] () $AVG8.VAULT$ -> %SystemDrive%\$AVG8.VAULT$ -> [2009/01/29 20:47:32 | 00,000,000 | -H-D | C] ntuser.pol -> %AllUsersProfile%\ntuser.pol -> [2009/01/29 19:57:25 | 00,000,258 | RHS- | C] () AVG Free 8.0.lnk -> %SystemDrive%\Users\Public\Desktop\AVG Free 8.0.lnk -> [2009/01/29 19:35:14 | 00,001,647 | ---- | C] () avgtdix.sys -> %SystemRoot%\System32\drivers\avgtdix.sys -> [2009/01/29 19:35:13 | 00,107,272 | ---- | C] (AVG Technologies CZ, s.r.o.) avgrsstx.dll -> %SystemRoot%\System32\avgrsstx.dll -> [2009/01/29 19:35:13 | 00,010,520 | ---- | C] (AVG Technologies CZ, s.r.o.) avgldx86.sys -> %SystemRoot%\System32\drivers\avgldx86.sys -> [2009/01/29 19:34:55 | 00,325,128 | ---- | C] (AVG Technologies CZ, s.r.o.) avgmfx86.sys -> %SystemRoot%\System32\drivers\avgmfx86.sys -> [2009/01/29 19:34:54 | 00,027,656 | ---- | C] (AVG Technologies CZ, s.r.o.) incavi.avm -> %SystemRoot%\System32\drivers\Avg\incavi.avm -> [2009/01/29 19:34:33 | 32,862,719 | ---- | C] () miniavi.avg -> %SystemRoot%\System32\drivers\Avg\miniavi.avg -> [2009/01/29 19:34:33 | 00,368,010 | ---- | C] () microavi.avg -> %SystemRoot%\System32\drivers\Avg\microavi.avg -> [2009/01/29 19:34:33 | 00,088,982 | ---- | C] () avi7.avg -> %SystemRoot%\System32\drivers\Avg\avi7.avg -> [2009/01/29 19:34:29 | 06,061,540 | ---- | C] () Avg -> %SystemRoot%\System32\drivers\Avg -> [2009/01/29 19:34:29 | 00,000,000 | ---D | C] AVG -> %ProgramFiles%\AVG -> [2009/01/29 19:33:48 | 00,000,000 | ---D | C] Adobe Reader 8.lnk -> %SystemDrive%\Users\Public\Desktop\Adobe Reader 8.lnk -> [2009/01/29 18:40:49 | 00,001,887 | ---- | C] () Adobe -> %ProgramFiles%\Adobe -> [2009/01/29 18:40:36 | 00,000,000 | ---D | C] found.000 -> %SystemDrive%\found.000 -> [2009/01/29 18:24:53 | 00,000,000 | -HSD | C] a-squared Anti-Malware.lnk -> %SystemDrive%\Users\Public\Desktop\a-squared Anti-Malware.lnk -> [2009/01/28 19:02:36 | 00,000,815 | ---- | C] () a-squared Anti-Malware -> %ProgramFiles%\a-squared Anti-Malware -> [2009/01/28 19:02:25 | 00,000,000 | ---D | C] a-squared -> %UserProfile%\Documents\a-squared -> [2009/01/28 19:02:25 | 00,000,000 | ---D | C] GoogleUpdateTask.job -> %SystemRoot%\tasks\GoogleUpdateTask.job -> [2009/01/27 19:47:42 | 00,000,288 | ---- | C] () Earth Viewpoint.lnk -> %SystemDrive%\Users\Public\Desktop\Earth Viewpoint.lnk -> [2009/01/27 19:47:29 | 00,000,822 | ---- | C] () Earth Viewpoint -> %ProgramFiles%\Earth Viewpoint -> [2009/01/27 19:47:28 | 00,000,000 | ---D | C] Google Earth.lnk -> %SystemDrive%\Users\Public\Desktop\Google Earth.lnk -> [2009/01/27 19:42:59 | 00,001,976 | ---- | C] () Google Updater -> %AllUsersProfile%\Google Updater -> [2009/01/27 19:39:12 | 00,000,000 | ---D | C] Google Software Updater.job -> %SystemRoot%\tasks\Google Software Updater.job -> [2009/01/27 19:39:04 | 00,000,868 | ---- | C] () ERDNT -> %SystemRoot%\ERDNT -> [2009/01/21 21:23:15 | 00,000,000 | ---D | C] HijackThis.lnk -> %UserProfile%\Desktop\HijackThis.lnk -> [2009/01/21 20:48:42 | 00,001,874 | ---- | C] () Trend Micro -> %ProgramFiles%\Trend Micro -> [2009/01/21 20:48:42 | 00,000,000 | ---D | C] rollback.ini -> %SystemDrive%\rollback.ini -> [2009/01/21 07:31:24 | 00,003,153 | ---- | C] () ParetoLogic Registration.job -> %SystemRoot%\tasks\ParetoLogic Registration.job -> [2009/01/20 19:23:22 | 00,000,436 | ---- | C] () fidbox.dat -> %SystemRoot%\System32\drivers\fidbox.dat -> [2009/01/20 19:22:29 | 14,997,280 | -HS- | C] () fidbox.idx -> %SystemRoot%\System32\drivers\fidbox.idx -> [2009/01/20 19:22:29 | 00,000,032 | -HS- | C] () ParetoLogic Anti-Virus PLUS -> %AllUsersProfile%\ParetoLogic Anti-Virus PLUS -> [2009/01/20 19:16:15 | 00,000,000 | ---D | C] ParetoLogic -> %ProgramFiles%\ParetoLogic -> [2009/01/20 19:09:11 | 00,000,000 | ---D | C] ParetoLogic -> %CommonProgramFiles%\ParetoLogic -> [2009/01/20 19:09:11 | 00,000,000 | ---D | C] Downloaded Installations -> %UserProfile%\AppData\Local\Downloaded Installations -> [2009/01/20 19:07:39 | 00,000,000 | ---D | C] ParetoLogic -> %AllUsersProfile%\ParetoLogic -> [2009/01/20 18:17:42 | 00,000,000 | ---D | C] Downloaded Installations -> %AllUsersProfile%\Downloaded Installations -> [2009/01/20 18:16:17 | 00,000,000 | ---D | C] Avg8 -> %AllUsersProfile%\Avg8 -> [2009/01/20 18:10:39 | 00,000,000 | ---D | C] mfc70.dll -> %SystemRoot%\System32\mfc70.dll -> [2009/01/18 21:05:49 | 00,974,848 | ---- | C] (Microsoft Corporation) msvcp70.dll -> %SystemRoot%\System32\msvcp70.dll -> [2009/01/18 21:05:49 | 00,487,424 | ---- | C] (Microsoft Corporation) msvcr70.dll -> %SystemRoot%\System32\msvcr70.dll -> [2009/01/18 21:05:49 | 00,344,064 | ---- | C] (Microsoft Corporation) GlarySoft -> %AppData%\GlarySoft -> [2009/01/18 21:00:00 | 00,000,000 | ---D | C] Free Window Registry Repair -> %ProgramFiles%\Free Window Registry Repair -> [2009/01/18 20:47:59 | 00,000,000 | ---D | C] PassMark -> %UserProfile%\Documents\PassMark -> [2009/01/18 20:33:51 | 00,000,000 | ---D | C] d3dx9_31.dll -> %SystemRoot%\System32\d3dx9_31.dll -> [2009/01/18 20:33:46 | 02,414,360 | ---- | C] (Microsoft Corporation) PassMark -> %UserProfile%\AppData\Local\PassMark -> [2009/01/18 20:33:11 | 00,000,000 | ---D | C] Spybot - Search & Destroy -> %AllUsersProfile%\Spybot - Search & Destroy -> [2009/01/15 19:24:18 | 00,000,000 | ---D | C] Lavasoft -> %AllUsersProfile%\Lavasoft -> [2009/01/15 19:22:34 | 00,000,000 | ---D | C] srv.sys -> %SystemRoot%\System32\drivers\srv.sys -> [2009/01/15 19:15:36 | 00,288,768 | ---- | C] (Microsoft Corporation) ntuser.dat{4d6ada20-e372-11dd-9c03-001bb9d41043}.TMContainer00000000000000000002.regtrans-ms -> %UserProfile%\ntuser.dat{4d6ada20-e372-11dd-9c03-001bb9d41043}.TMContainer00000000000000000002.regtrans-ms -> [2009/01/15 19:07:12 | 00,524,288 | -HS- | C] () ntuser.dat{4d6ada20-e372-11dd-9c03-001bb9d41043}.TMContainer00000000000000000001.regtrans-ms -> %UserProfile%\ntuser.dat{4d6ada20-e372-11dd-9c03-001bb9d41043}.TMContainer00000000000000000001.regtrans-ms -> [2009/01/15 19:07:12 | 00,524,288 | -HS- | C] () ntuser.dat{4d6ada20-e372-11dd-9c03-001bb9d41043}.TM.blf -> %UserProfile%\ntuser.dat{4d6ada20-e372-11dd-9c03-001bb9d41043}.TM.blf -> [2009/01/15 19:07:12 | 00,065,536 | -HS- | C] () 99 audi -> %UserProfile%\Desktop\99 audi -> [2009/01/14 09:50:28 | 00,000,000 | ---D | C] 98 diesel -> %UserProfile%\Desktop\98 diesel -> [2009/01/14 09:50:17 | 00,000,000 | ---D | C] The.Chronicles.of.Narnia.Prince.Caspian.2008.Eng.TS.DivX-LTT.avi -> %UserProfile%\Desktop\The.Chronicles.of.Narnia.Prince.Caspian.2008.Eng.TS.DivX-LTT.avi -> [2009/01/13 21:28:22 | 53,079,1566 | ---- | C] () AVIConverter_3.0 -> %UserProfile%\Desktop\AVIConverter_3.0 -> [2009/01/13 21:19:58 | 00,000,000 | ---D | C] AVIConverter_3.0.zip -> %UserProfile%\Desktop\AVIConverter_3.0.zip -> [2009/01/13 21:18:59 | 15,335,202 | ---- | C] () TEMP -> %AllUsersProfile%\TEMP -> [2009/01/13 19:03:30 | 00,000,000 | ---D | C] 59fb9b707e66eb5b9028e1ce368e23c3[1] -> %UserProfile%\Documents\59fb9b707e66eb5b9028e1ce368e23c3[1] -> [2009/01/12 09:56:06 | 00,000,000 | ---D | C] AVS4YOU -> %AppData%\AVS4YOU -> [2009/01/09 12:22:25 | 00,000,000 | ---D | C] AVS4YOU -> %AllUsersProfile%\AVS4YOU -> [2009/01/09 12:22:13 | 00,000,000 | ---D | C] AVSMedia -> %CommonProgramFiles%\AVSMedia -> [2009/01/09 12:21:14 | 00,000,000 | ---D | C] AVS4YOU -> %ProgramFiles%\AVS4YOU -> [2009/01/09 12:21:12 | 00,000,000 | ---D | C] Movies -> %UserProfile%\Desktop\Movies -> [2009/01/08 12:20:18 | 00,000,000 | ---D | C] DivX -> %AppData%\DivX -> [2009/01/08 12:19:09 | 00,000,000 | ---D | C] PX Storage Engine -> %CommonProgramFiles%\PX Storage Engine -> [2009/01/08 12:16:56 | 00,000,000 | ---D | C] [Files/Folders - Modified Within 30 Days] ntuser.dat -> %UserProfile%\ntuser.dat -> [2009/02/06 17:25:21 | 04,718,592 | -HS- | M] () OTScanIt2.exe -> %UserProfile%\Desktop\OTScanIt2.exe -> [2009/02/06 17:24:06 | 00,656,714 | ---- | M] () LeakTest.exe -> %UserProfile%\Desktop\LeakTest.exe -> [2009/02/06 17:23:01 | 00,025,600 | R--- | M] (Gibson Research Corp.) incavi.avm -> %SystemRoot%\System32\drivers\Avg\incavi.avm -> [2009/02/06 17:15:23 | 32,862,719 | ---- | M] () microavi.avg -> %SystemRoot%\System32\drivers\Avg\microavi.avg -> [2009/02/06 17:15:23 | 00,088,982 | ---- | M] () My Sharing Folders.lnk -> %UserProfile%\Documents\My Sharing Folders.lnk -> [2009/02/06 16:41:50 | 00,000,512 | ---- | M] () opa12.dat -> %AllUsersProfile%\Microsoft\OFFICE\DATA\opa12.dat -> [2009/02/06 15:59:02 | 00,008,310 | ---- | M] () 7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> %SystemRoot%\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> [2009/02/06 15:54:31 | 00,003,168 | -H-- | M] () 7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> %SystemRoot%\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> [2009/02/06 15:54:31 | 00,003,168 | -H-- | M] () Google Software Updater.job -> %SystemRoot%\tasks\Google Software Updater.job -> [2009/02/06 11:52:40 | 00,000,868 | ---- | M] () qmgr1.dat -> %AllUsersProfile%\Microsoft\Network\Downloader\qmgr1.dat -> [2009/02/06 09:50:17 | 04,194,304 | ---- | M] () qmgr0.dat -> %AllUsersProfile%\Microsoft\Network\Downloader\qmgr0.dat -> [2009/02/06 09:50:17 | 04,194,304 | ---- | M] () system.ini -> %SystemRoot%\system.ini -> [2009/02/06 07:40:54 | 00,000,215 | ---- | M] () ComboFix.exe -> %UserProfile%\Desktop\ComboFix.exe -> [2009/02/06 07:28:22 | 02,913,680 | R--- | M] () PublishedRacMonSWITable.DAT -> %AllUsersProfile%\Microsoft\RAC\PublishedData\PublishedRacMonSWITable.DAT -> [2009/02/06 00:05:17 | 00,159,040 | ---- | M] () PublishedRacMonAFLTable.DAT -> %AllUsersProfile%\Microsoft\RAC\PublishedData\PublishedRacMonAFLTable.DAT -> [2009/02/06 00:05:17 | 00,027,324 | ---- | M] () PublishedRacMonOSFTable.DAT -> %AllUsersProfile%\Microsoft\RAC\PublishedData\PublishedRacMonOSFTable.DAT -> [2009/02/06 00:05:17 | 00,012,420 | ---- | M] () PublishedRacMonIndex.DAT -> %AllUsersProfile%\Microsoft\RAC\PublishedData\PublishedRacMonIndex.DAT -> [2009/02/06 00:05:17 | 00,003,168 | ---- | M] () PublishedRacMonHFLTable.DAT -> %AllUsersProfile%\Microsoft\RAC\PublishedData\PublishedRacMonHFLTable.DAT -> [2009/02/06 00:05:17 | 00,000,000 | ---- | M] () PublishedRacMonCLKTable.DAT -> %AllUsersProfile%\Microsoft\RAC\PublishedData\PublishedRacMonCLKTable.DAT -> [2009/02/06 00:05:17 | 00,000,000 | ---- | M] () PerfStringBackup.INI -> %SystemRoot%\System32\PerfStringBackup.INI -> [2009/02/05 21:44:51 | 00,690,960 | ---- | M] () perfh009.dat -> %SystemRoot%\System32\perfh009.dat -> [2009/02/05 21:44:51 | 00,595,446 | ---- | M] () perfc009.dat -> %SystemRoot%\System32\perfc009.dat -> [2009/02/05 21:44:51 | 00,101,144 | ---- | M] () ParetoLogic Registration.job -> %SystemRoot%\tasks\ParetoLogic Registration.job -> [2009/02/05 18:00:01 | 00,000,436 | ---- | M] () desktop.ini -> %UserProfile%\Desktop\desktop.ini -> [2009/02/04 13:32:06 | 00,000,476 | -HS- | M] () GoogleUpdateTask.job -> %SystemRoot%\tasks\GoogleUpdateTask.job -> [2009/02/04 09:49:56 | 00,000,288 | ---- | M] () SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [2009/02/04 09:49:55 | 00,000,006 | -H-- | M] () bootstat.dat -> %SystemRoot%\bootstat.dat -> [2009/02/04 09:49:50 | 00,067,584 | --S- | M] () hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [2009/02/04 09:49:44 | 93,794,3040 | -HS- | M] () ntuser.dat{4d6ada20-e372-11dd-9c03-001bb9d41043}.TMContainer00000000000000000001.regtrans-ms -> %UserProfile%\ntuser.dat{4d6ada20-e372-11dd-9c03-001bb9d41043}.TMContainer00000000000000000001.regtrans-ms -> [2009/02/04 09:48:59 | 00,524,288 | -HS- | M] () ntuser.dat{4d6ada20-e372-11dd-9c03-001bb9d41043}.TM.blf -> %UserProfile%\ntuser.dat{4d6ada20-e372-11dd-9c03-001bb9d41043}.TM.blf -> [2009/02/04 09:48:59 | 00,065,536 | -HS- | M] () IconCache.db -> %UserProfile%\AppData\Local\IconCache.db -> [2009/02/04 09:48:03 | 02,533,508 | -H-- | M] () gmer.ini -> %SystemRoot%\gmer.ini -> [2009/02/04 09:45:56 | 00,000,250 | ---- | M] () gmer.dll -> %SystemRoot%\gmer.dll -> [2009/02/04 07:35:13 | 00,884,736 | ---- | M] () gmer.sys -> %SystemRoot%\System32\drivers\gmer.sys -> [2009/02/04 07:35:13 | 00,085,969 | ---- | M] (GMER) gmer_uninstall.cmd -> %SystemRoot%\gmer_uninstall.cmd -> [2009/02/04 07:35:13 | 00,000,080 | ---- | M] () gmer.exe -> %SystemRoot%\gmer.exe -> [2009/02/04 07:35:07 | 00,811,008 | R--- | M] () wklntsk1.dat -> %AllUsersProfile%\Microsoft\Works\wklntsk1.dat -> [2009/02/03 14:03:56 | 00,000,000 | ---- | M] () wkcalcat.dat -> %AllUsersProfile%\Microsoft\Works\wkcalcat.dat -> [2009/02/03 14:03:38 | 00,016,384 | ---- | M] () wklnhst.dat -> %AppData%\wklnhst.dat -> [2009/02/03 14:03:28 | 00,000,000 | ---- | M] () Malwarebytes' Anti-Malware.lnk -> %SystemDrive%\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk -> [2009/02/03 11:13:37 | 00,000,818 | ---- | M] () ntuser.pol -> %AllUsersProfile%\ntuser.pol -> [2009/01/29 19:57:59 | 00,000,258 | RHS- | M] () AVG Free 8.0.lnk -> %SystemDrive%\Users\Public\Desktop\AVG Free 8.0.lnk -> [2009/01/29 19:35:14 | 00,001,647 | ---- | M] () avgtdix.sys -> %SystemRoot%\System32\drivers\avgtdix.sys -> [2009/01/29 19:35:13 | 00,107,272 | ---- | M] (AVG Technologies CZ, s.r.o.) avgrsstx.dll -> %SystemRoot%\System32\avgrsstx.dll -> [2009/01/29 19:35:13 | 00,010,520 | ---- | M] (AVG Technologies CZ, s.r.o.) avgldx86.sys -> %SystemRoot%\System32\drivers\avgldx86.sys -> [2009/01/29 19:34:55 | 00,325,128 | ---- | M] (AVG Technologies CZ, s.r.o.) avgmfx86.sys -> %SystemRoot%\System32\drivers\avgmfx86.sys -> [2009/01/29 19:34:54 | 00,027,656 | ---- | M] (AVG Technologies CZ, s.r.o.) avi7.avg -> %SystemRoot%\System32\drivers\Avg\avi7.avg -> [2009/01/29 19:34:33 | 06,061,540 | ---- | M] () miniavi.avg -> %SystemRoot%\System32\drivers\Avg\miniavi.avg -> [2009/01/29 19:34:33 | 00,368,010 | ---- | M] () Adobe Reader 8.lnk -> %SystemDrive%\Users\Public\Desktop\Adobe Reader 8.lnk -> [2009/01/29 18:40:49 | 00,001,887 | ---- | M] () fidbox.dat -> %SystemRoot%\System32\drivers\fidbox.dat -> [2009/01/29 18:20:29 | 14,997,280 | -HS- | M] () rollback.ini -> %SystemDrive%\rollback.ini -> [2009/01/29 12:19:57 | 00,003,153 | ---- | M] () a-squared Anti-Malware.lnk -> %SystemDrive%\Users\Public\Desktop\a-squared Anti-Malware.lnk -> [2009/01/28 19:02:36 | 00,000,815 | ---- | M] () Earth Viewpoint.lnk -> %SystemDrive%\Users\Public\Desktop\Earth Viewpoint.lnk -> [2009/01/27 19:47:29 | 00,000,822 | ---- | M] () Google Earth.lnk -> %SystemDrive%\Users\Public\Desktop\Google Earth.lnk -> [2009/01/27 19:42:59 | 00,001,976 | ---- | M] () HijackThis.lnk -> %UserProfile%\Desktop\HijackThis.lnk -> [2009/01/21 20:48:42 | 00,001,874 | ---- | M] () fidbox.idx -> %SystemRoot%\System32\drivers\fidbox.idx -> [2009/01/20 19:23:08 | 00,000,032 | -HS- | M] () ntuser.dat{4d6ada20-e372-11dd-9c03-001bb9d41043}.TMContainer00000000000000000002.regtrans-ms -> %UserProfile%\ntuser.dat{4d6ada20-e372-11dd-9c03-001bb9d41043}.TMContainer00000000000000000002.regtrans-ms -> [2009/01/18 19:18:04 | 00,524,288 | -HS- | M] () NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms -> %UserProfile%\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms -> [2009/01/15 18:58:48 | 00,524,288 | -HS- | M] () NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf -> %UserProfile%\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf -> [2009/01/15 18:58:48 | 00,065,536 | -HS- | M] () mbamswissarmy.sys -> %SystemRoot%\System32\drivers\mbamswissarmy.sys -> [2009/01/14 16:11:32 | 00,038,496 | ---- | M] (Malwarebytes Corporation) mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> [2009/01/14 16:11:28 | 00,015,504 | ---- | M] (Malwarebytes Corporation) The.Chronicles.of.Narnia.Prince.Caspian.2008.Eng.TS.DivX-LTT.avi -> %UserProfile%\Desktop\The.Chronicles.of.Narnia.Prince.Caspian.2008.Eng.TS.DivX-LTT.avi -> [2009/01/13 21:50:41 | 53,079,1566 | ---- | M] () AVIConverter_3.0.zip -> %UserProfile%\Desktop\AVIConverter_3.0.zip -> [2009/01/13 21:19:13 | 15,335,202 | ---- | M] () mrt.exe -> %SystemRoot%\System32\mrt.exe -> [2009/01/09 18:35:28 | 20,853,704 | ---- | M] (Microsoft Corporation) hhcolreg.dat -> %AllUsersProfile%\Microsoft\HTML Help\hhcolreg.dat -> [2008/10/02 20:15:33 | 00,000,184 | ---- | M] () FilelistIndex.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\FilelistIndex.DAT -> [2008/09/28 15:51:09 | 00,042,276 | ---- | M] () Filelist00113.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00113.DAT -> [2008/09/28 14:06:14 | 00,002,860 | ---- | M] () Filelist00114.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00114.DAT -> [2008/09/28 14:06:14 | 00,000,252 | ---- | M] () Filelist00106.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00106.DAT -> [2008/09/28 14:06:13 | 00,001,956 | ---- | M] () Filelist00107.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00107.DAT -> [2008/09/28 14:06:13 | 00,000,508 | ---- | M] () Filelist00110.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00110.DAT -> [2008/09/28 14:06:13 | 00,000,408 | ---- | M] () Filelist00108.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00108.DAT -> [2008/09/28 14:06:13 | 00,000,376 | ---- | M] () Filelist00112.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00112.DAT -> [2008/09/28 14:06:13 | 00,000,256 | ---- | M] () Filelist00111.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00111.DAT -> [2008/09/28 14:06:13 | 00,000,252 | ---- | M] () Filelist00109.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00109.DAT -> [2008/09/28 14:06:13 | 00,000,252 | ---- | M] () Filelist00103.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00103.DAT -> [2008/09/28 14:06:12 | 00,004,844 | ---- | M] () Filelist00104.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00104.DAT -> [2008/09/28 14:06:12 | 00,002,880 | ---- | M] () Filelist00105.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00105.DAT -> [2008/09/28 14:06:12 | 00,001,952 | ---- | M] () Filelist00100.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00100.DAT -> [2008/09/28 14:06:11 | 00,002,856 | ---- | M] () Filelist00101.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00101.DAT -> [2008/09/28 14:06:11 | 00,000,904 | ---- | M] () Filelist00102.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00102.DAT -> [2008/09/28 14:06:11 | 00,000,644 | ---- | M] () Filelist00097.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00097.DAT -> [2008/09/28 14:06:10 | 00,009,880 | ---- | M] () Filelist00098.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00098.DAT -> [2008/09/28 14:06:10 | 00,005,392 | ---- | M] () Filelist00099.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00099.DAT -> [2008/09/28 14:06:10 | 00,000,372 | ---- | M] () Filelist00096.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00096.DAT -> [2008/09/28 14:06:09 | 00,015,160 | ---- | M] () Filelist00095.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00095.DAT -> [2008/09/28 14:06:08 | 00,015,424 | ---- | M] () Filelist00094.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00094.DAT -> [2008/09/28 14:06:07 | 00,011,596 | ---- | M] () Filelist00093.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00093.DAT -> [2008/09/28 14:06:06 | 00,009,220 | ---- | M] () Filelist00092.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00092.DAT -> [2008/09/28 14:06:05 | 00,012,784 | ---- | M] () Filelist00089.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00089.DAT -> [2008/09/28 14:06:05 | 00,008,692 | ---- | M] () Filelist00091.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00091.DAT -> [2008/09/28 14:06:05 | 00,004,600 | ---- | M] () Filelist00090.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00090.DAT -> [2008/09/28 14:06:05 | 00,000,508 | ---- | M] () Filelist00088.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00088.DAT -> [2008/09/28 14:06:04 | 00,022,552 | ---- | M] () Filelist00087.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00087.DAT -> [2008/09/28 14:06:02 | 00,025,852 | ---- | M] () Filelist00086.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00086.DAT -> [2008/09/28 14:06:00 | 00,015,028 | ---- | M] () Filelist00085.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00085.DAT -> [2008/09/28 14:05:59 | 00,022,156 | ---- | M] () Filelist00084.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00084.DAT -> [2008/09/28 14:05:56 | 00,017,140 | ---- | M] () Filelist00081.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00081.DAT -> [2008/09/28 14:05:55 | 00,008,692 | ---- | M] () Filelist00083.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00083.DAT -> [2008/09/28 14:05:55 | 00,006,184 | ---- | M] () Filelist00082.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00082.DAT -> [2008/09/28 14:05:55 | 00,000,244 | ---- | M] () Filelist00079.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00079.DAT -> [2008/09/28 14:05:54 | 00,015,952 | ---- | M] () Filelist00080.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00080.DAT -> [2008/09/28 14:05:54 | 00,012,520 | ---- | M] () Filelist00078.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00078.DAT -> [2008/09/28 14:05:53 | 00,025,456 | ---- | M] () Filelist00077.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00077.DAT -> [2008/09/28 14:05:50 | 00,021,364 | ---- | M] () Filelist00076.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00076.DAT -> [2008/09/28 14:05:50 | 00,020,044 | ---- | M] () Filelist00075.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00075.DAT -> [2008/09/28 14:05:49 | 00,008,956 | ---- | M] () Filelist00072.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00072.DAT -> [2008/09/28 14:05:48 | 00,008,824 | ---- | M] () Filelist00073.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00073.DAT -> [2008/09/28 14:05:48 | 00,008,692 | ---- | M] () Filelist00074.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00074.DAT -> [2008/09/28 14:05:48 | 00,001,432 | ---- | M] () Filelist00071.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00071.DAT -> [2008/09/28 14:05:47 | 00,009,748 | ---- | M] () Filelist00070.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00070.DAT -> [2008/09/28 14:05:46 | 00,017,272 | ---- | M] () Filelist00069.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00069.DAT -> [2008/09/28 14:05:45 | 00,027,964 | ---- | M] () Filelist00068.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00068.DAT -> [2008/09/28 14:05:43 | 00,022,288 | ---- | M] () Filelist00067.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00067.DAT -> [2008/09/28 14:05:42 | 00,007,636 | ---- | M] () Filelist00063.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00063.DAT -> [2008/09/28 14:05:41 | 00,022,420 | ---- | M] () Filelist00064.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00064.DAT -> [2008/09/28 14:05:41 | 00,011,332 | ---- | M] () Filelist00065.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00065.DAT -> [2008/09/28 14:05:41 | 00,008,692 | ---- | M] () Filelist00066.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00066.DAT -> [2008/09/28 14:05:41 | 00,000,904 | ---- | M] () Filelist00062.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00062.DAT -> [2008/09/28 14:05:40 | 00,023,212 | ---- | M] () Filelist00061.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00061.DAT -> [2008/09/28 14:05:38 | 00,030,740 | ---- | M] () Filelist00060.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00060.DAT -> [2008/09/28 14:05:36 | 00,025,720 | ---- | M] () Filelist00059.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00059.DAT -> [2008/09/28 14:05:34 | 00,008,560 | ---- | M] () Filelist00057.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00057.DAT -> [2008/09/28 14:05:33 | 00,008,692 | ---- | M] () Filelist00058.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00058.DAT -> [2008/09/28 14:05:33 | 00,002,356 | ---- | M] () Filelist00056.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00056.DAT -> [2008/09/28 14:05:32 | 00,015,820 | ---- | M] () Filelist00055.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00055.DAT -> [2008/09/28 14:05:31 | 00,023,344 | ---- | M] () Filelist00054.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00054.DAT -> [2008/09/28 14:05:30 | 00,024,400 | ---- | M] () Filelist00053.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00053.DAT -> [2008/09/28 14:05:29 | 00,027,304 | ---- | M] () Filelist00052.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00052.DAT -> [2008/09/28 14:05:27 | 00,031,924 | ---- | M] () Filelist00051.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00051.DAT -> [2008/09/28 14:05:23 | 00,009,484 | ---- | M] () Filelist00049.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00049.DAT -> [2008/09/28 14:05:23 | 00,008,692 | ---- | M] () Filelist00050.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00050.DAT -> [2008/09/28 14:05:23 | 00,003,412 | ---- | M] () Filelist00048.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00048.DAT -> [2008/09/28 14:05:22 | 00,008,824 | ---- | M] () Filelist00046.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00046.DAT -> [2008/09/28 14:05:21 | 00,018,724 | ---- | M] () Filelist00047.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00047.DAT -> [2008/09/28 14:05:21 | 00,009,484 | ---- | M] () Filelist00045.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00045.DAT -> [2008/09/28 14:05:19 | 00,018,460 | ---- | M] () Filelist00044.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00044.DAT -> [2008/09/28 14:05:18 | 00,016,744 | ---- | M] () Filelist00043.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00043.DAT -> [2008/09/28 14:05:17 | 00,006,976 | ---- | M] () Filelist00041.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00041.DAT -> [2008/09/28 14:05:16 | 00,009,616 | ---- | M] () Filelist00042.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00042.DAT -> [2008/09/28 14:05:16 | 00,006,316 | ---- | M] () Filelist00040.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00040.DAT -> [2008/09/28 14:05:15 | 00,016,216 | ---- | M] () Filelist00039.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00039.DAT -> [2008/09/28 14:05:14 | 00,026,512 | ---- | M] () Filelist00038.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00038.DAT -> [2008/09/28 14:05:12 | 00,011,992 | ---- | M] () Filelist00036.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00036.DAT -> [2008/09/28 14:05:11 | 00,013,444 | ---- | M] () Filelist00037.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00037.DAT -> [2008/09/28 14:05:11 | 00,009,088 | ---- | M] () Filelist00034.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00034.DAT -> [2008/09/28 14:05:10 | 00,006,448 | ---- | M] () Filelist00035.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00035.DAT -> [2008/09/28 14:05:10 | 00,005,128 | ---- | M] () Filelist00032.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00032.DAT -> [2008/09/28 14:05:09 | 00,018,856 | ---- | M] () Filelist00033.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00033.DAT -> [2008/09/28 14:05:09 | 00,012,256 | ---- | M] () Filelist00031.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00031.DAT -> [2008/09/28 14:05:08 | 00,022,156 | ---- | M] () Filelist00030.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00030.DAT -> [2008/09/28 14:05:07 | 00,025,984 | ---- | M] () Filelist00029.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00029.DAT -> [2008/09/28 14:05:04 | 00,024,004 | ---- | M] () Filelist00028.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00028.DAT -> [2008/09/28 14:05:02 | 00,022,420 | ---- | M] () Filelist00027.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00027.DAT -> [2008/09/28 14:05:00 | 00,010,672 | ---- | M] () Filelist00025.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00025.DAT -> [2008/09/28 14:04:59 | 00,008,692 | ---- | M] () Filelist00026.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00026.DAT -> [2008/09/28 14:04:59 | 00,003,412 | ---- | M] () Filelist00024.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00024.DAT -> [2008/09/28 14:04:58 | 00,009,220 | ---- | M] () Filelist00023.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00023.DAT -> [2008/09/28 14:04:58 | 00,009,220 | ---- | M] () Filelist00022.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00022.DAT -> [2008/09/28 14:04:57 | 00,013,972 | ---- | M] () Filelist00021.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00021.DAT -> [2008/09/28 14:04:56 | 00,031,396 | ---- | M] () Filelist00020.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00020.DAT -> [2008/09/28 14:04:51 | 00,027,172 | ---- | M] () Filelist00019.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00019.DAT -> [2008/09/28 14:04:48 | 00,008,164 | ---- | M] () Filelist00017.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00017.DAT -> [2008/09/28 14:04:47 | 00,008,692 | ---- | M] () Filelist00018.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00018.DAT -> [2008/09/28 14:04:47 | 00,004,468 | ---- | M] () Filelist00016.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00016.DAT -> [2008/09/28 14:04:46 | 00,009,484 | ---- | M] () Filelist00015.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00015.DAT -> [2008/09/28 14:04:45 | 00,011,596 | ---- | M] () Filelist00013.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00013.DAT -> [2008/09/28 14:04:44 | 00,011,596 | ---- | M] () Filelist00014.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00014.DAT -> [2008/09/28 14:04:44 | 00,008,824 | ---- | M] () Filelist00012.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00012.DAT -> [2008/09/28 14:04:43 | 00,023,212 | ---- | M] () Filelist00009.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00009.DAT -> [2008/09/28 14:04:40 | 00,008,692 | ---- | M] () Filelist00010.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00010.DAT -> [2008/09/28 14:04:40 | 00,007,636 | ---- | M] () Filelist00011.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00011.DAT -> [2008/09/28 14:04:40 | 00,006,184 | ---- | M] () Filelist00007.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00007.DAT -> [2008/09/28 14:04:39 | 00,012,652 | ---- | M] () Filelist00008.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00008.DAT -> [2008/09/28 14:04:39 | 00,009,088 | ---- | M] () Filelist00006.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00006.DAT -> [2008/09/28 14:04:37 | 00,010,672 | ---- | M] () Filelist00005.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00005.DAT -> [2008/09/28 14:04:36 | 00,009,352 | ---- | M] () Filelist00004.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00004.DAT -> [2008/09/28 14:04:35 | 00,019,384 | ---- | M] () Filelist00003.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00003.DAT -> [2008/09/28 14:04:34 | 00,005,392 | ---- | M] () Filelist00002.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00002.DAT -> [2008/09/28 14:04:34 | 00,001,308 | ---- | M] () Filelist00001.DAT -> %AllUsersProfile%\Microsoft\FSX\SceneryIndexes\Filelist00001.DAT -> [2008/09/28 14:04:33 | 00,002,300 | ---- | M] () 4163d440-a8b9-3c28-9c6d-485986f04593.dat -> %AllUsersProfile%\Microsoft\SLDL\SoftwareLicensing\4163d440-a8b9-3c28-9c6d-485986f04593.dat -> [2008/09/28 11:26:03 | 00,011,340 | ---- | M] () 77c938ae-2f5b-aba4-66e1-a53a9cdad48f.dat -> %AllUsersProfile%\Microsoft\SLDL\SoftwareLicensing\77c938ae-2f5b-aba4-66e1-a53a9cdad48f.dat -> [2008/09/28 11:26:01 | 00,005,612 | ---- | M] () 6b048a10-d259-5ce0-45f4-73fe3bb2bcac.dat -> %AllUsersProfile%\Microsoft\SLDL\SoftwareLicensing\6b048a10-d259-5ce0-45f4-73fe3bb2bcac.dat -> [2008/09/28 11:26:01 | 00,004,248 | ---- | M] () 1485db7f-10dc-bd24-80ee-3acc1dcb19d5.dat -> %AllUsersProfile%\Microsoft\SLDL\SoftwareLicensing\1485db7f-10dc-bd24-80ee-3acc1dcb19d5.dat -> [2008/09/28 11:25:58 | 00,006,182 | ---- | M] () 010af981-cd0a-4d5c-4559-321178cd7ba5.dat -> %AllUsersProfile%\Microsoft\SLDL\SoftwareLicensing\010af981-cd0a-4d5c-4559-321178cd7ba5.dat -> [2008/09/28 11:25:58 | 00,003,037 | ---- | M] () 6d1fc144-430d-92ee-a585-fccf492243f1.dat -> %AllUsersProfile%\Microsoft\SLDL\SoftwareLicensing\6d1fc144-430d-92ee-a585-fccf492243f1.dat -> [2008/09/28 11:23:30 | 00,016,652 | ---- | M] () 2aa181cf-5771-3146-73c7-afbf7e9ced2e.dat -> %AllUsersProfile%\Microsoft\SLDL\SoftwareLicensing\2aa181cf-5771-3146-73c7-afbf7e9ced2e.dat -> [2008/09/28 11:23:30 | 00,016,644 | ---- | M] () fda68769-b92c-0baa-a72e-cdf551afdbb7.dat -> %AllUsersProfile%\Microsoft\SLDL\SoftwareLicensing\fda68769-b92c-0baa-a72e-cdf551afdbb7.dat -> [2008/09/28 11:23:30 | 00,013,323 | ---- | M] () 9728020c-33b1-869d-8ca7-2da2673eeba6.dat -> %AllUsersProfile%\Microsoft\SLDL\SoftwareLicensing\9728020c-33b1-869d-8ca7-2da2673eeba6.dat -> [2008/09/28 11:23:30 | 00,013,319 | ---- | M] () e840ba51-07a0-5a6f-202f-a1d2634d5cb6.dat -> %AllUsersProfile%\Microsoft\SLDL\SoftwareLicensing\e840ba51-07a0-5a6f-202f-a1d2634d5cb6.dat -> [2008/09/28 11:23:30 | 00,011,430 | ---- | M] () b3724b38-a0be-7e2e-680a-76a2b74d87ae.dat -> %AllUsersProfile%\Microsoft\SLDL\SoftwareLicensing\b3724b38-a0be-7e2e-680a-76a2b74d87ae.dat -> [2008/09/28 11:23:30 | 00,011,422 | ---- | M] () 7fc76939-1749-9389-638e-b057f3111dfe.dat -> %AllUsersProfile%\Microsoft\SLDL\SoftwareLicensing\7fc76939-1749-9389-638e-b057f3111dfe.dat -> [2008/09/28 11:23:30 | 00,008,266 | ---- | M] () f68611eb-e389-1a51-bd94-636faf15e309.dat -> %AllUsersProfile%\Microsoft\SLDL\SoftwareLicensing\f68611eb-e389-1a51-bd94-636faf15e309.dat -> [2008/09/28 11:23:30 | 00,007,371 | ---- | M] () 43b3fb56-0aa1-cf24-fcd5-ace4f579aa78.dat -> %AllUsersProfile%\Microsoft\SLDL\SoftwareLicensing\43b3fb56-0aa1-cf24-fcd5-ace4f579aa78.dat -> [2008/09/28 11:23:30 | 00,006,043 | ---- | M] () af154ab4-7867-7da2-509f-55369e19b78a.dat -> %AllUsersProfile%\Microsoft\SLDL\SoftwareLicensing\af154ab4-7867-7da2-509f-55369e19b78a.dat -> [2008/09/28 11:23:30 | 00,005,259 | ---- | M] () 61003c70-2333-4da9-f637-1240e25f9b46.dat -> %AllUsersProfile%\Microsoft\SLDL\SoftwareLicensing\61003c70-2333-4da9-f637-1240e25f9b46.dat -> [2008/09/28 11:23:30 | 00,005,105 | ---- | M] () 3a2d0e4e-183a-3be6-de12-f79b20b6726b.dat -> %AllUsersProfile%\Microsoft\SLDL\SoftwareLicensing\3a2d0e4e-183a-3be6-de12-f79b20b6726b.dat -> [2008/09/28 11:23:30 | 00,004,339 | ---- | M] () 325ecd9f-b45c-7657-310d-a3ec69566036.dat -> %AllUsersProfile%\Microsoft\SLDL\SoftwareLicensing\325ecd9f-b45c-7657-310d-a3ec69566036.dat -> [2008/09/28 11:23:30 | 00,004,324 | ---- | M] () 4a9b95b9-1079-3d9a-1dd0-511ab9735c52.dat -> %AllUsersProfile%\Microsoft\SLDL\SoftwareLicensing\4a9b95b9-1079-3d9a-1dd0-511ab9735c52.dat -> [2008/09/28 11:23:30 | 00,004,190 | ---- | M] () f0f642df-b163-4f5b-70aa-9dbfadeaa323.dat -> %AllUsersProfile%\Microsoft\SLDL\SoftwareLicensing\f0f642df-b163-4f5b-70aa-9dbfadeaa323.dat -> [2008/09/28 11:23:30 | 00,003,978 | ---- | M] () c7f13e4f-3a54-f72a-4415-9de346aa9a51.dat -> %AllUsersProfile%\Microsoft\SLDL\SoftwareLicensing\c7f13e4f-3a54-f72a-4415-9de346aa9a51.dat -> [2008/09/28 11:23:30 | 00,003,448 | ---- | M] () b63271ae-c613-2d09-eede-d8f740f9fbdc.dat -> %AllUsersProfile%\Microsoft\SLDL\SoftwareLicensing\b63271ae-c613-2d09-eede-d8f740f9fbdc.dat -> [2008/09/28 11:23:30 | 00,003,447 | ---- | M] () 1e5087d3-4b65-3a13-e56e-f8c0b01c389d.dat -> %AllUsersProfile%\Microsoft\SLDL\SoftwareLicensing\1e5087d3-4b65-3a13-e56e-f8c0b01c389d.dat -> [2008/09/28 11:23:30 | 00,003,338 | ---- | M] () bb94bdbd-e879-9f77-c792-8f2b062f83fa.dat -> %AllUsersProfile%\Microsoft\SLDL\SoftwareLicensing\bb94bdbd-e879-9f77-c792-8f2b062f83fa.dat -> [2008/09/28 11:23:30 | 00,003,033 | ---- | M] () kc.dat -> %AllUsersProfile%\Microsoft\User Account Pictures\kc.dat -> [2008/09/27 19:28:56 | 00,000,000 | ---- | M] () [Alternate Data Streams] @Alternate Data Stream - 104 bytes -> %AllUsersProfile%\TEMP:DFC5A2B2 @Alternate Data Stream - 115 bytes -> %AllUsersProfile%\TEMP:3AEA6AF9 < End of report > [/code]