[code] OTScanIt2 logfile created on: 2/25/2009 4:04:32 PM - Run 1 OTScanIt2 by OldTimer - Version 1.0.8.0 Folder = C:\Documents and Settings\Administrator\Desktop\OTScanIt2 Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.5512) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 1022.07 Mb Total Physical Memory | 637.45 Mb Available Physical Memory | 62.37% Memory free 2.40 Gb Paging File | 2.10 Gb Available in Paging File | 87.30% Paging File free Paging file location(s): C:\pagefile.sys 1536 3072; %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 74.50 Gb Total Space | 58.32 Gb Free Space | 78.29% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: BEASTIE Current User Name: Administrator Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Whitelist: On File Age = 30 Days [Processes - Safe List] aawservice.exe -> %ProgramFiles%\Lavasoft\Ad-Aware\aawservice.exe -> [2008/06/09 09:49:35 | 00,611,664 | ---- | M] (Lavasoft) ati2evxx.exe -> %SystemRoot%\system32\Ati2evxx.exe -> [2005/08/03 23:02:58 | 00,380,928 | ---- | M] (ATI Technologies Inc.) bjmyprt.exe -> %ProgramFiles%\Canon\MyPrinter\BJMyPrt.exe -> [2006/03/21 17:30:00 | 01,191,936 | ---- | M] (CANON INC.) ctsvccda.exe -> %SystemRoot%\system32\CTsvcCDA.EXE -> [1999/12/13 06:01:00 | 00,044,032 | ---- | M] (Creative Technology Ltd) ctsysvol.exe -> %ProgramFiles%\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe -> [2003/09/17 10:43:36 | 00,057,344 | ---- | M] (Creative Technology Ltd) explorer.exe -> %SystemRoot%\Explorer.EXE -> [2008/04/14 04:42:20 | 01,033,728 | ---- | M] (Microsoft Corporation) googletoolbarnotifier.exe -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe -> [2008/04/11 10:20:03 | 00,068,856 | ---- | M] (Google Inc.) googleupdaterservice.exe -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> [2008/10/10 07:26:34 | 00,168,432 | ---- | M] (Google) hpcmpmgr.exe -> %ProgramFiles%\HP\hpcoretech\hpcmpmgr.exe -> [2004/05/12 15:18:56 | 00,241,664 | ---- | M] (Hewlett-Packard Company) hphmon06.exe -> %SystemRoot%\system32\hphmon06.exe -> [2006/01/06 20:54:41 | 00,659,456 | ---- | M] (Hewlett-Packard) hpzipm12.exe -> %SystemRoot%\system32\HPZipm12.exe -> [2004/03/18 16:55:48 | 00,065,536 | ---- | M] (HP) iexplore.exe -> %ProgramFiles%\Internet Explorer\iexplore.exe -> [2008/04/14 04:42:24 | 00,093,184 | ---- | M] (Microsoft Corporation) khalmnpr.exe -> %CommonProgramFiles%\Logishrd\KHAL2\KHALMNPR.EXE -> [2008/05/02 01:40:56 | 00,076,304 | ---- | M] (Logitech, Inc.) kodakccs.exe -> %SystemRoot%\system32\drivers\KodakCCS.exe -> [2004/05/24 12:35:52 | 00,322,104 | ---- | M] (Eastman Kodak Company) mdm.exe -> %CommonProgramFiles%\Microsoft Shared\VS7Debug\mdm.exe -> [2003/06/19 23:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) msmsgs.exe -> %ProgramFiles%\Messenger\msmsgs.exe -> [2008/04/14 04:42:30 | 01,695,232 | ---- | M] (Microsoft Corporation) mspmspsv.exe -> %SystemRoot%\system32\MsPMSPSv.exe -> [2000/06/26 07:44:20 | 00,053,520 | ---- | M] (Microsoft Corporation) otscanit2.exe -> %UserProfile%\Desktop\OTScanIt2\OTScanIt2.exe -> [2009/02/19 11:15:40 | 00,489,984 | ---- | M] (OldTimer Tools) pdfcreatormessages.exe -> %SystemRoot%\system32\PDFCreatorMessages.exe -> [2008/02/01 18:35:02 | 00,143,360 | ---- | M] (Global Graphics Software Ltd.) qttask.exe -> %ProgramFiles%\QuickTime\qttask.exe -> [2008/05/27 09:50:30 | 00,413,696 | ---- | M] (Apple Inc.) sansadispatch.exe -> %AppData%\SanDisk\Sansa Updater\SansaDispatch.exe -> [2008/11/30 15:01:31 | 00,079,872 | ---- | M] (SanDisk Corporation) setpoint.exe -> %ProgramFiles%\Logitech\SetPoint\SetPoint.exe -> [2008/05/02 01:44:08 | 00,805,392 | ---- | M] (Logitech, Inc.) windowssearch.exe -> %ProgramFiles%\Windows Desktop Search\WindowsSearch.exe -> [2008/05/26 22:19:14 | 00,123,904 | ---- | M] (Microsoft Corporation) wscntfy.exe -> %SystemRoot%\system32\wscntfy.exe -> [2008/04/14 04:42:42 | 00,013,824 | ---- | M] (Microsoft Corporation) [Win32 Services - Safe List] (aawservice) Lavasoft Ad-Aware Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Lavasoft\Ad-Aware\aawservice.exe -> [2008/06/09 09:49:35 | 00,611,664 | ---- | M] (Lavasoft) (aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -> [2008/07/25 11:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) (Ati HotKey Poller) Ati HotKey Poller [Win32_Own | Auto | Running] -> %SystemRoot%\system32\Ati2evxx.exe -> [2005/08/03 23:02:58 | 00,380,928 | ---- | M] (ATI Technologies Inc.) (ATI Smart) ATI Smart [Win32_Own | Auto | Stopped] -> %SystemRoot%\system32\ati2sgag.exe -> [2005/08/05 20:05:00 | 00,516,096 | ---- | M] () (clr_optimization_v2.0.50727_32) .NET Runtime Optimization Service v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2008/07/25 11:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) (Creative Service for CDROM Access) Creative Service for CDROM Access [Win32_Own | Auto | Running] -> %SystemRoot%\system32\CTsvcCDA.EXE -> [1999/12/13 06:01:00 | 00,044,032 | ---- | M] (Creative Technology Ltd) (FontCache3.0.0.0) Windows Presentation Foundation Font Cache 3.0.0.0 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -> [2008/07/29 21:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) (gusvc) Google Updater Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> [2008/10/10 07:26:34 | 00,168,432 | ---- | M] (Google) (helpsvc) Help and Support [Win32_Shared | Auto | Running] -> %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll -> [2008/04/14 04:42:04 | 00,038,400 | ---- | M] (Microsoft Corporation) (HP Port Resolver) HP Port Resolver [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\system32\hpbpro.exe -> [2006/01/06 20:54:41 | 00,077,824 | ---- | M] (Hewlett-Packard Company) (HP Status Server) HP Status Server [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\system32\hpboid.exe -> [2006/01/06 20:54:41 | 00,073,728 | ---- | M] (Hewlett-Packard Company) (IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\1050\Intel 32\IDriverT.exe -> [2004/10/22 02:24:18 | 00,073,728 | ---- | M] (Macrovision Corporation) (idsvc) Windows CardSpace [Win32_Shared | Unknown | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -> [2008/07/29 19:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) (KodakCCS) Kodak Camera Connection Software [Win32_Own | Auto | Running] -> %SystemRoot%\system32\drivers\KodakCCS.exe -> [2004/05/24 12:35:52 | 00,322,104 | ---- | M] (Eastman Kodak Company) (LBTServ) Logitech Bluetooth Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Logishrd\Bluetooth\LBTServ.exe -> [2008/05/02 01:42:06 | 00,121,360 | ---- | M] (Logitech, Inc.) (MDM) Machine Debug Manager [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Microsoft Shared\VS7Debug\mdm.exe -> [2003/06/19 23:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) (NetTcpPortSharing) Net.Tcp Port Sharing Service [Win32_Shared | Disabled | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -> [2008/07/29 19:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) (PDFCreatorMessages) PDFCreatorMessages [Win32_Own | Auto | Running] -> %SystemRoot%\system32\PDFCreatorMessages.exe -> [2008/02/01 18:35:02 | 00,143,360 | ---- | M] (Global Graphics Software Ltd.) (Pml Driver HPZ12) Pml Driver HPZ12 [Win32_Own | On_Demand | Running] -> %SystemRoot%\system32\HPZipm12.exe -> [2004/03/18 16:55:48 | 00,065,536 | ---- | M] (HP) (WMDM PMSP Service) WMDM PMSP Service [Win32_Own | Auto | Running] -> %SystemRoot%\system32\MsPMSPSv.exe -> [2000/06/26 07:44:20 | 00,053,520 | ---- | M] (Microsoft Corporation) (WMPNetworkSvc) Windows Media Player Network Sharing Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Windows Media Player\WMPNetwk.exe -> [2006/10/18 20:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) [Driver Services - Safe List] (ati2mtag) ati2mtag [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\ati2mtag.sys -> [2005/08/03 23:10:18 | 01,273,344 | ---- | M] (ATI Technologies Inc.) (cercsr6) cercsr6 [Kernel | Boot | Stopped] -> %SystemRoot%\System32\drivers\cercsr6.sys -> [2005/03/21 17:48:30 | 00,039,904 | ---- | M] (Adaptec, Inc.) (ctsfm2k) Creative SoundFont Management Device Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\ctsfm2k.sys -> [2005/01/10 10:15:24 | 00,138,752 | ---- | M] (Creative Technology Ltd) (DcCam) Kodak Camera Proxy [Kernel | System | Running] -> %SystemRoot%\system32\DRIVERS\DcCam.sys -> [2004/05/20 08:21:10 | 00,036,918 | ---- | M] (Eastman Kodak Company) (DcFpoint) DcFpoint [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\DcFpoint.sys -> [2004/05/20 08:41:54 | 00,061,564 | ---- | M] (Eastman Kodak Company) (DCFS2K) Kodak DCFS2K Driver [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\dcfs2k.sys -> [2004/06/02 13:19:00 | 00,038,705 | ---- | M] (Eastman Kodak Company) (DcLps) Legacy Polling Service [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\DcLps.sys -> [2004/05/20 08:39:42 | 00,008,022 | ---- | M] (Eastman Kodak Company) (DcPTP) DcPTP [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\DcPTP.sys -> [2004/05/20 08:45:20 | 00,068,950 | ---- | M] (Eastman Kodak Company) (E100B) Intel(R) PRO Network Connection Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\e100b325.sys -> [2005/06/13 12:58:04 | 00,162,816 | ---- | M] (Intel Corporation) (Exportit) Exportit [Kernel | System | Stopped] -> %SystemRoot%\system32\DRIVERS\exportit.sys -> [2004/06/02 13:17:56 | 00,151,985 | ---- | M] (Eastman Kodak Company) (HPZid412) IEEE-1284.4 Driver HPZid412 [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HPZid412.sys -> [2007/01/19 11:46:10 | 00,049,920 | ---- | M] (HP) (HPZipr12) Print Class Driver for IEEE-1284.4 HPZipr12 [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HPZipr12.sys -> [2007/01/19 11:46:10 | 00,016,496 | ---- | M] (HP) (HPZius12) USB to IEEE-1284.4 Translation Driver HPZius12 [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HPZius12.sys -> [2007/01/19 11:46:12 | 00,021,568 | ---- | M] (HP) (HSFHWBS2) HSFHWBS2 [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HSFHWBS2.sys -> [2003/11/17 12:59:20 | 00,212,224 | R--- | M] (Conexant Systems, Inc.) (HSF_DP) HSF_DP [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HSF_DP.sys -> [2003/11/17 12:56:26 | 01,042,432 | R--- | M] (Conexant Systems, Inc.) (LHidFilt) Logitech SetPoint KMDF HID Filter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\LHidFilt.Sys -> [2008/02/29 02:13:16 | 00,035,344 | ---- | M] (Logitech, Inc.) (LMouFilt) Logitech SetPoint KMDF Mouse Filter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\LMouFilt.Sys -> [2008/02/29 02:13:24 | 00,036,880 | ---- | M] (Logitech, Inc.) (LUsbFilt) Logitech SetPoint KMDF USB Filter [Kernel | On_Demand | Running] -> %SystemRoot%\System32\Drivers\LUsbFilt.Sys -> [2008/02/29 02:13:46 | 00,028,944 | ---- | M] (Logitech, Inc.) (mdmxsdk) mdmxsdk [Kernel | Auto | Running] -> %SystemRoot%\system32\DRIVERS\mdmxsdk.sys -> [2003/04/09 10:48:08 | 00,011,043 | R--- | M] (Conexant) (MODEMCSA) Unimodem Streaming Filter Device [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\MODEMCSA.sys -> [2001/08/17 13:57:38 | 00,016,128 | ---- | M] (Microsoft Corporation) (OMCI) OMCI [Kernel | System | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\OMCI.SYS -> [2001/08/22 08:42:58 | 00,013,632 | ---- | M] (Dell Computer Corporation) (ossrv) Creative OS Services Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\ctoss2k.sys -> [2005/01/10 10:15:30 | 00,106,496 | ---- | M] (Creative Technology Ltd.) (P17) SB Live! 24-bit [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\P17.sys -> [2007/06/15 02:47:26 | 01,127,936 | ---- | M] (Creative Technology Ltd.) (PfModNT) PfModNT [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\PfModNT.sys -> [2004/12/22 11:58:14 | 00,008,704 | ---- | M] (Creative Technology Ltd.) (Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\ptilink.sys -> [2004/08/04 04:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) (PxHelp20) PxHelp20 [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\PxHelp20.sys -> [2007/03/07 15:51:00 | 00,043,528 | ---- | M] (Sonic Solutions) (Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\secdrv.sys -> [2007/11/13 02:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) (tmtdi) Trend Micro TDI Driver [Kernel | Disabled | Running] -> -> File not found (winachsf) winachsf [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HSF_CNXT.sys -> [2003/11/17 12:58:02 | 00,680,704 | R--- | M] (Conexant Systems, Inc.) [Registry - Safe List] < Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome -> HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> C:\windows\system32\blank.htm -> HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home -> HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> HKEY_LOCAL_MACHINE\: Search\\"Default_Search_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> < Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> HKEY_CURRENT_USER\: Main\\"Default_Search_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_CURRENT_USER\: Main\\"Local Page" -> C:\windows\system32\blank.htm -> HKEY_CURRENT_USER\: Main\\"Page_Transitions" -> Reg Error: Invalid data type. -> HKEY_CURRENT_USER\: Main\\"Search Page" -> http://www.google.com -> HKEY_CURRENT_USER\: Main\\"Start Page" -> http://pe.com/ -> HKEY_CURRENT_USER\: SearchURL\\"" -> http://home.microsoft.com/access/autosearch.asp?p=%s -> HKEY_CURRENT_USER\: SearchURL\\"provider" -> gogl -> HKEY_CURRENT_USER\: "ProxyEnable" -> 0 -> HKEY_CURRENT_USER\: "ProxyOverride" -> *.local -> < Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> -> HKEY_USERS\.DEFAULT\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> -> HKEY_USERS\S-1-5-18\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> -> < Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> -> < Internet Explorer Settings [HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500\] > -> -> HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500\: Main\\"Default_Search_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500\: Main\\"Local Page" -> C:\windows\system32\blank.htm -> HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500\: Main\\"Page_Transitions" -> Reg Error: Invalid data type. -> HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500\: Main\\"Search Page" -> http://www.google.com -> HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500\: Main\\"Start Page" -> http://pe.com/ -> HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500\: SearchURL\\"" -> http://home.microsoft.com/access/autosearch.asp?p=%s -> HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500\: SearchURL\\"provider" -> gogl -> HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500\: "ProxyEnable" -> 0 -> HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500\: "ProxyOverride" -> *.local -> < HOSTS File > (727 bytes and 18 lines) -> C:\WINDOWS\System32\drivers\etc\Hosts -> 127.0.0.1 localhost < BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> %CommonProgramFiles%\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> [2006/10/22 23:08:42 | 00,062,080 | ---- | M] (Adobe Systems Incorporated) {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} [HKLM] -> %ProgramFiles%\Canon\Easy-WebPrint\EWPBrowseLoader.dll [EWPBrowseObject Class] -> [2006/04/18 19:04:14 | 00,034,304 | ---- | M] () {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_07\bin\ssv.dll [SSVHelper Class] -> [2008/06/10 03:27:02 | 00,509,328 | ---- | M] (Sun Microsystems, Inc.) {A8FB8EB3-183B-4598-924D-86F0E5E37085} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found {AA58ED58-01DD-4d91-8333-CF10577473F7} [HKLM] -> %ProgramFiles%\Google\Google Toolbar\GoogleToolbar.dll [Google Toolbar Helper] -> [2008/12/19 21:56:56 | 00,251,504 | ---- | M] () {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKLM] -> %ProgramFiles%\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll [Google Toolbar Notifier BHO] -> [2008/12/19 23:57:21 | 00,657,904 | ---- | M] (Google Inc.) {C5D07EB6-BBCE-4DAE-ACBB-D13A8D28CB1F} [HKLM] -> %ProgramFiles%\Tracker Software\PDF-XChange Viewer\pdf-viewer\PDFXCviewIEPlugin.dll [PDF-XChange Viewer IE-Plugin] -> [2008/08/31 08:18:40 | 01,099,032 | ---- | M] (Tracker Software Products Ltd.) {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} [HKLM] -> %ProgramFiles%\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll [Google Dictionary Compression sdch] -> [2008/12/19 21:56:55 | 00,522,224 | ---- | M] (Google Inc.) < Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\Google\Google Toolbar\GoogleToolbar.dll [&Google Toolbar] -> [2008/12/19 21:56:56 | 00,251,504 | ---- | M] () "{327C2873-E90D-4c37-AA9D-10AC9BABA46C}" [HKLM] -> %ProgramFiles%\Canon\Easy-WebPrint\Toolband.dll [Easy-WebPrint] -> [2006/04/18 19:05:46 | 00,552,960 | ---- | M] () "SITEguard" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found < Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> ShellBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\Google\Google Toolbar\GoogleToolbar.dll [&Google Toolbar] -> [2008/12/19 21:56:56 | 00,251,504 | ---- | M] () WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\Google\Google Toolbar\GoogleToolbar.dll [&Google Toolbar] -> [2008/12/19 21:56:56 | 00,251,504 | ---- | M] () WebBrowser\\"{56CF4856-ECB4-4E46-A897-A378821F97B9}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found WebBrowser\\"{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found WebBrowser\\"{A8FB8EB3-183B-4598-924D-86F0E5E37085}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found < Internet Explorer ToolBars [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\ -> WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\Google\Google Toolbar\GoogleToolbar.dll [&Google Toolbar] -> [2008/12/19 21:56:56 | 00,251,504 | ---- | M] () WebBrowser\\"{56CF4856-ECB4-4E46-A897-A378821F97B9}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found < Internet Explorer ToolBars [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\ -> WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\Google\Google Toolbar\GoogleToolbar.dll [&Google Toolbar] -> [2008/12/19 21:56:56 | 00,251,504 | ---- | M] () WebBrowser\\"{56CF4856-ECB4-4E46-A897-A378821F97B9}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found < Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500\] > -> HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500\Software\Microsoft\Internet Explorer\Toolbar\ -> ShellBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\Google\Google Toolbar\GoogleToolbar.dll [&Google Toolbar] -> [2008/12/19 21:56:56 | 00,251,504 | ---- | M] () WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\Google\Google Toolbar\GoogleToolbar.dll [&Google Toolbar] -> [2008/12/19 21:56:56 | 00,251,504 | ---- | M] () WebBrowser\\"{56CF4856-ECB4-4E46-A897-A378821F97B9}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found WebBrowser\\"{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found WebBrowser\\"{A8FB8EB3-183B-4598-924D-86F0E5E37085}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found < Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "Adobe Reader Speed Launcher" -> %ProgramFiles%\Adobe\Reader 8.0\Reader\Reader_sl.exe ["C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"] -> [2008/10/15 01:04:34 | 00,039,792 | ---- | M] (Adobe Systems Incorporated) "ATIPTA" -> %ProgramFiles%\ATI Technologies\ATI Control Panel\atiptaxx.exe ["C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"] -> [2005/08/05 20:05:00 | 00,344,064 | ---- | M] (ATI Technologies, Inc.) "CanonMyPrinter" -> %ProgramFiles%\Canon\MyPrinter\BJMyPrt.exe [C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon] -> [2006/03/21 17:30:00 | 01,191,936 | ---- | M] (CANON INC.) "CTSysVol" -> %ProgramFiles%\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe [C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r] -> [2003/09/17 10:43:36 | 00,057,344 | ---- | M] (Creative Technology Ltd) "HP Component Manager" -> %ProgramFiles%\HP\hpcoretech\hpcmpmgr.exe ["C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"] -> [2004/05/12 15:18:56 | 00,241,664 | ---- | M] (Hewlett-Packard Company) "HPDJ Taskbar Utility" -> %SystemRoot%\system32\spool\drivers\w32x86\3\hpztsb11.exe [C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe] -> [2006/01/06 20:54:42 | 00,172,032 | ---- | M] (HP) "HPHmon06" -> %SystemRoot%\system32\hphmon06.exe [C:\WINDOWS\system32\hphmon06.exe] -> [2006/01/06 20:54:41 | 00,659,456 | ---- | M] (Hewlett-Packard) "HPHUPD06" -> %ProgramFiles%\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe [C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe] -> [2006/01/06 20:54:59 | 00,049,152 | ---- | M] (Hewlett-Packard) "Kernel and Hardware Abstraction Layer" -> %SystemRoot%\KHALMNPR.EXE [KHALMNPR.EXE] -> [2008/02/29 02:12:38 | 00,076,304 | ---- | M] (Logitech, Inc.) "P17Helper" -> %SystemRoot%\system32\P17.DLL [Rundll32 P17.dll,P17Helper] -> [2005/05/03 11:38:42 | 00,064,512 | ---- | M] () "PCMService" -> %ProgramFiles%\Dell\Media Experience\PCMService.exe ["C:\Program Files\Dell\Media Experience\PCMService.exe"] -> File not found "QuickTime Task" -> %ProgramFiles%\QuickTime\qttask.exe ["C:\Program Files\QuickTime\qttask.exe" -atboottime] -> [2008/05/27 09:50:30 | 00,413,696 | ---- | M] (Apple Inc.) "THGuard" -> %ProgramFiles%\TrojanHunter 4.0\THGuard.exe ["C:\Program Files\TrojanHunter 4.0\THGuard.exe"] -> [2004/09/02 14:47:28 | 01,073,664 | ---- | M] (Mischel Internet Security) "UpdReg" -> %SystemRoot%\UpdReg.EXE [C:\WINDOWS\UpdReg.EXE] -> [2000/05/11 01:00:00 | 00,090,112 | ---- | M] (Creative Technology Ltd.) "WinampAgent" -> %ProgramFiles%\Winamp\winampa.exe ["C:\Program Files\Winamp\winampa.exe"] -> File not found < RunOnceEx [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx -> "" -> [] -> File not found < Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "MSMSGS" -> %ProgramFiles%\Messenger\msmsgs.exe ["C:\Program Files\Messenger\msmsgs.exe" /background] -> [2008/04/14 04:42:30 | 01,695,232 | ---- | M] (Microsoft Corporation) "SansaDispatch" -> %AppData%\SanDisk\Sansa Updater\SansaDispatch.exe [C:\Documents and Settings\Administrator\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe] -> [2008/11/30 15:01:31 | 00,079,872 | ---- | M] (SanDisk Corporation) "swg" -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] -> [2008/04/11 10:20:03 | 00,068,856 | ---- | M] (Google Inc.) < Run [HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500\] > -> HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "MSMSGS" -> %ProgramFiles%\Messenger\msmsgs.exe ["C:\Program Files\Messenger\msmsgs.exe" /background] -> [2008/04/14 04:42:30 | 01,695,232 | ---- | M] (Microsoft Corporation) "SansaDispatch" -> %AppData%\SanDisk\Sansa Updater\SansaDispatch.exe [C:\Documents and Settings\Administrator\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe] -> [2008/11/30 15:01:31 | 00,079,872 | ---- | M] (SanDisk Corporation) "swg" -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] -> [2008/04/11 10:20:03 | 00,068,856 | ---- | M] (Google Inc.) < Administrator Startup Folder > -> C:\Documents and Settings\Administrator\Start Menu\Programs\Startup -> < All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> %AllUsersProfile%\Start Menu\Programs\Startup\Logitech SetPoint.lnk -> %ProgramFiles%\Logitech\SetPoint\SetPoint.exe -> [2008/05/02 01:44:08 | 00,805,392 | ---- | M] (Logitech, Inc.) %AllUsersProfile%\Start Menu\Programs\Startup\Windows Search.lnk -> %ProgramFiles%\Windows Desktop Search\WindowsSearch.exe -> [2008/05/26 22:19:14 | 00,123,904 | ---- | M] (Microsoft Corporation) < Default User Startup Folder > -> C:\Documents and Settings\Default User\Start Menu\Programs\Startup -> < Gramma Startup Folder > -> C:\Documents and Settings\Gramma\Start Menu\Programs\Startup -> < Software Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer -> < Software Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer -> < Software Policy Settings [HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500] > -> HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500\SOFTWARE\Policies\Microsoft\Internet Explorer -> < CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> < CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System \\"dontdisplaylastusername" -> [0] -> File not found \\"legalnoticecaption" -> [] -> File not found \\"legalnoticetext" -> [] -> File not found \\"shutdownwithoutlogon" -> [1] -> File not found \\"undockwithoutlogon" -> [1] -> File not found < CurrentVersion Policy Settings - Explorer [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [145] -> File not found \\"NoLogoff" -> [01 00 00 00 [binary data]] -> File not found \\"NoRecentDocsMenu" -> [01 00 00 00 [binary data]] -> File not found \\"NoWinKeys" -> [01 00 00 00 [binary data]] -> File not found \\"NoComputersNearMe" -> [01 00 00 00 [binary data]] -> File not found < CurrentVersion Policy Settings - System [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> < CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [145] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [145] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [145] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [145] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500] > -> HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [145] -> File not found \\"NoLogoff" -> [01 00 00 00 [binary data]] -> File not found \\"NoRecentDocsMenu" -> [01 00 00 00 [binary data]] -> File not found \\"NoWinKeys" -> [01 00 00 00 [binary data]] -> File not found \\"NoComputersNearMe" -> [01 00 00 00 [binary data]] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500] > -> HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> < Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> E&xport to Microsoft Excel -> %ProgramFiles%\Microsoft Office\Office10\EXCEL.EXE [res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000] -> [2008/01/29 10:41:28 | 09,364,480 | R--- | M] (Microsoft Corporation) < Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500\] > -> HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500\Software\Microsoft\Internet Explorer\MenuExt\ -> E&xport to Microsoft Excel -> %ProgramFiles%\Microsoft Office\Office10\EXCEL.EXE [res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000] -> [2008/01/29 10:41:28 | 09,364,480 | R--- | M] (Microsoft Corporation) < Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> {08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_04\bin\npjpi160_04.dll [Menu: Sun Java Console] -> [2007/12/14 02:42:37 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.) {e2e2dd38-d088-4134-82b7-f2ba38496583}:Exec [HKLM] -> %SystemRoot%\Network Diagnostic\xpnetdiag.exe [Menu: @xpsp3res.dll,-20001] -> [2008/04/13 23:23:34 | 00,558,080 | ---- | M] (Microsoft Corporation) {FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Button: Messenger] -> [2008/04/14 04:42:30 | 01,695,232 | ---- | M] (Microsoft Corporation) {FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Menu: Windows Messenger] -> [2008/04/14 04:42:30 | 01,695,232 | ---- | M] (Microsoft Corporation) < Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> %SystemRoot%\system32\msjava.dll [Web Browser Applet Control] -> [2007/03/12 13:02:26 | 00,947,472 | ---- | M] (Microsoft Corporation) CmdMapping\\"{17A27031-71FC-11d4-815C-005004D0F1FA}" [HKLM] -> [Reg Error: Key error.] -> File not found CmdMapping\\"{e2e2dd38-d088-4134-82b7-f2ba38496583}" [HKLM] -> %SystemRoot%\Network Diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2008/04/13 23:23:34 | 00,558,080 | ---- | M] (Microsoft Corporation) CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/14 04:42:30 | 01,695,232 | ---- | M] (Microsoft Corporation) < Internet Explorer Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> %SystemRoot%\system32\msjava.dll [Web Browser Applet Control] -> [2007/03/12 13:02:26 | 00,947,472 | ---- | M] (Microsoft Corporation) CmdMapping\\"{e2e2dd38-d088-4134-82b7-f2ba38496583}" [HKLM] -> %SystemRoot%\Network Diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2008/04/13 23:23:34 | 00,558,080 | ---- | M] (Microsoft Corporation) CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/14 04:42:30 | 01,695,232 | ---- | M] (Microsoft Corporation) < Internet Explorer Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> %SystemRoot%\system32\msjava.dll [Web Browser Applet Control] -> [2007/03/12 13:02:26 | 00,947,472 | ---- | M] (Microsoft Corporation) CmdMapping\\"{e2e2dd38-d088-4134-82b7-f2ba38496583}" [HKLM] -> %SystemRoot%\Network Diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2008/04/13 23:23:34 | 00,558,080 | ---- | M] (Microsoft Corporation) CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/14 04:42:30 | 01,695,232 | ---- | M] (Microsoft Corporation) < Internet Explorer Extensions [HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500\] > -> HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> %SystemRoot%\system32\msjava.dll [Web Browser Applet Control] -> [2007/03/12 13:02:26 | 00,947,472 | ---- | M] (Microsoft Corporation) CmdMapping\\"{17A27031-71FC-11d4-815C-005004D0F1FA}" [HKLM] -> [Reg Error: Key error.] -> File not found CmdMapping\\"{e2e2dd38-d088-4134-82b7-f2ba38496583}" [HKLM] -> %SystemRoot%\Network Diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2008/04/13 23:23:34 | 00,558,080 | ---- | M] (Microsoft Corporation) CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/14 04:42:30 | 01,695,232 | ---- | M] (Microsoft Corporation) < Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> < Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix "" -> http:// < Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. -> 1 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500\] > -> HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500\] > -> HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-21-854245398-861567501-682003330-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} [HKLM] -> http://go.microsoft.com/fwlink/?linkid=58813 [Office Genuine Advantage Validation Tool] -> {6414512B-B978-451D-A0D8-FCFDF33E833C} [HKLM] -> http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1230856375515 [WUWebControl Class] -> {6F15128C-E66A-490C-B848-5000B5ABEEAC} [HKLM] -> https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab [HP Download Manager] -> {8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab [Java Plug-in 1.6.0_07] -> {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} [HKLM] -> http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab [Reg Error: Key error.] -> {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} [HKLM] -> http://www.trendsecure.com/easy_install/_activex/en-US/TSEasyInstallX.CAB [TSEasyInstallX Control] -> {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} [HKLM] -> http://office.microsoft.com/officeupdate/content/opuc4.cab [Office Update Installation Engine] -> {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab [Java Plug-in 1.6.0_04] -> {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab [Java Plug-in 1.6.0_07] -> {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab [Java Plug-in 1.6.0_07] -> {D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab [Shockwave Flash Object] -> Microsoft XML Parser for Java [HKLM] -> file://C:\WINDOWS\Java\classes\xmldso.cab [Reg Error: Key error.] -> < DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> {CE63F2CA-B02C-4D9D-9C08-6A837DB1FBD1} -> (Intel(R) PRO/100 VE Network Connection) -> < Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> *Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell -> Explorer.exe -> %SystemRoot%\Explorer.exe -> [2008/04/14 04:42:20 | 01,033,728 | ---- | M] (Microsoft Corporation) *MultiFile Done* -> -> < Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> LBTWlgn -> %CommonProgramFiles%\logishrd\bluetooth\LBTWlgn.dll -> [2008/05/02 01:42:30 | 00,072,208 | ---- | M] (Logitech, Inc.) < ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks -> "{56F9679E-7826-4C84-81F3-532071A8BCC5}" [HKLM] -> %ProgramFiles%\Windows Desktop Search\MSNLNamespaceMgr.dll [] -> [2008/05/26 22:19:02 | 00,304,128 | ---- | M] (Microsoft Corporation) < Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List -> "%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 23:23:34 | 00,558,080 | ---- | M] (Microsoft Corporation) "%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/14 04:42:36 | 00,141,312 | ---- | M] (Microsoft Corporation) < Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List -> "%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 23:23:34 | 00,558,080 | ---- | M] (Microsoft Corporation) "%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/14 04:42:36 | 00,141,312 | ---- | M] (Microsoft Corporation) "C:\pfs\callatl\rteng9.exe" -> C:\pfs\callatl\rteng9.exe [C:\pfs\callatl\rteng9.exe:*:Enabled:Adaptive Server Anywhere Network Server] -> File not found "C:\Program Files\Comodo\Comodo AntiVirus\CavEmSrv.exe" -> C:\Program Files\Comodo\Comodo AntiVirus\CavEmSrv.exe [C:\Program Files\Comodo\Comodo AntiVirus\CavEmSrv.exe:*:Enabled:Comodo AntiVirus Email Proxy Server] -> File not found "C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe" -> C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe:*:Enabled:Kodak Software Updater] -> [2004/02/13 14:12:08 | 00,016,423 | ---- | M] () "C:\Program Files\LimeWire\LimeWire.exe" -> C:\Program Files\LimeWire\LimeWire.exe [C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire] -> [2008/09/18 10:50:21 | 00,147,456 | ---- | M] (Lime Wire, LLC) "C:\Program Files\Palm\HOTSYNC.EXE" -> C:\Program Files\Palm\HOTSYNC.EXE [C:\Program Files\Palm\HOTSYNC.EXE:*:Disabled:HotSync® Manager Application] -> File not found "C:\Program Files\Zoom\Install\ZoomInstall.exe" -> C:\Program Files\Zoom\Install\ZoomInstall.exe [C:\Program Files\Zoom\Install\ZoomInstall.exe:*:Enabled:Zoom DSL Install Assistant] -> [2008/04/22 11:01:02 | 17,207,296 | ---- | M] (Zoom Technologies) "C:\WINDOWS\system32\dpvsetup.exe" -> C:\WINDOWS\system32\dpvsetup.exe [C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test] -> [2008/04/14 04:42:20 | 00,083,456 | ---- | M] (Microsoft Corporation) "C:\WINDOWS\system32\fxsclnt.exe" -> C:\WINDOWS\system32\fxsclnt.exe [C:\WINDOWS\system32\fxsclnt.exe:*:Enabled:Microsoft Fax Console] -> File not found "C:\WINDOWS\system32\rundll32.exe" -> C:\WINDOWS\system32\rundll32.exe [C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App] -> [2008/04/14 04:42:34 | 00,033,280 | ---- | M] (Microsoft Corporation) "E:\Bin\Install\EngInstallAssistant\ZoomInstall.exe" -> E:\Bin\Install\EngInstallAssistant\ZoomInstall.exe [E:\Bin\Install\EngInstallAssistant\ZoomInstall.exe:*:Enabled:Zoom DSL Install Assistant] -> File not found < SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot -> "AlternateShell" -> cmd.exe -> < CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom -> "AutoRun" -> 1 -> "DisplayName" -> CD-ROM Driver -> "ImagePath" -> %SystemRoot%\system32\DRIVERS\cdrom.sys [system32\DRIVERS\cdrom.sys] -> [2008/04/13 23:10:48 | 00,062,976 | ---- | M] (Microsoft Corporation) < Drives with AutoRun files > -> -> C:\AUTOEXEC.BAT [] -> %SystemDrive%\AUTOEXEC.BAT [ NTFS ] -> [2008/01/28 10:52:37 | 00,000,000 | ---- | M] () < MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 -> \H HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\H\Shell \H\Shell\\"" -> [AutoRun] -> File not found HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\H\Shell\AutoRun \H\Shell\AutoRun\\"" -> [Auto&Play] -> File not found HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\H\Shell\AutoRun\command \H\Shell\AutoRun\command\\"" -> H:\LaunchU3.exe [H:\LaunchU3.exe -a] -> File not found \{325e88b4-f887-11dd-9f48-00123fa17c39} HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{325e88b4-f887-11dd-9f48-00123fa17c39}\Shell \{325e88b4-f887-11dd-9f48-00123fa17c39}\Shell\\"" -> [AutoRun] -> File not found HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{325e88b4-f887-11dd-9f48-00123fa17c39}\Shell\AutoRun \{325e88b4-f887-11dd-9f48-00123fa17c39}\Shell\AutoRun\\"" -> [Auto&Play] -> File not found HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{325e88b4-f887-11dd-9f48-00123fa17c39}\Shell\AutoRun\command \{325e88b4-f887-11dd-9f48-00123fa17c39}\Shell\AutoRun\command\\"" -> H:\LaunchU3.exe [H:\LaunchU3.exe -a] -> File not found \{325e88b5-f887-11dd-9f48-00123fa17c39} HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{325e88b5-f887-11dd-9f48-00123fa17c39}\Shell \{325e88b5-f887-11dd-9f48-00123fa17c39}\Shell\\"" -> [AutoRun] -> File not found HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{325e88b5-f887-11dd-9f48-00123fa17c39}\Shell\Auto\command \{325e88b5-f887-11dd-9f48-00123fa17c39}\Shell\Auto\command\\"" -> I:\rejoice91.exe [I:\rejoice91.exe] -> File not found HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{325e88b5-f887-11dd-9f48-00123fa17c39}\Shell\AutoRun \{325e88b5-f887-11dd-9f48-00123fa17c39}\Shell\AutoRun\\"" -> [Auto&Play] -> File not found \{325e88b6-f887-11dd-9f48-00123fa17c39} HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{325e88b6-f887-11dd-9f48-00123fa17c39}\Shell \{325e88b6-f887-11dd-9f48-00123fa17c39}\Shell\\"" -> [AutoRun] -> File not found HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{325e88b6-f887-11dd-9f48-00123fa17c39}\Shell\Auto\command \{325e88b6-f887-11dd-9f48-00123fa17c39}\Shell\Auto\command\\"" -> J:\rejoice91.exe [J:\rejoice91.exe] -> File not found HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{325e88b6-f887-11dd-9f48-00123fa17c39}\Shell\AutoRun \{325e88b6-f887-11dd-9f48-00123fa17c39}\Shell\AutoRun\\"" -> [Auto&Play] -> File not found [Registry - Additional Scans - Safe List] < EventViewer Logs - Last 10 Errors > -> Event Information -> Description Application [ Error ] 2/21/2009 7:02:12 PM Computer Name = BEASTIE | Source = ESENT | ID = 485 -> Description = SearchIndexer (3100) An attempt to delete the file "C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS00257.log" failed with system error 5 (0x00000005): "Access is denied. ". The delete file operation will fail with error -1032 (0xfffffbf8). Application [ Error ] 2/21/2009 7:06:37 PM Computer Name = BEASTIE | Source = ESENT | ID = 485 -> Description = SearchIndexer (3100) An attempt to delete the file "C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS0025C.log" failed with system error 5 (0x00000005): "Access is denied. ". The delete file operation will fail with error -1032 (0xfffffbf8). Application [ Error ] 2/23/2009 1:25:00 PM Computer Name = BEASTIE | Source = Application Hang | ID = 1002 -> Description = Hanging application iexplore.exe, version 6.0.2900.5512, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Application [ Error ] 2/23/2009 1:25:02 PM Computer Name = BEASTIE | Source = Application Hang | ID = 1002 -> Description = Hanging application iexplore.exe, version 6.0.2900.5512, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Application [ Error ] 2/25/2009 2:28:48 AM Computer Name = BEASTIE | Source = Application Hang | ID = 1002 -> Description = Hanging application iexplore.exe, version 6.0.2900.5512, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Application [ Error ] 2/25/2009 1:38:35 PM Computer Name = BEASTIE | Source = Windows Search Service | ID = 3013 -> Description = The entry in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details: A device attached to the system is not functioning. (0x8007001f) Application [ Error ] 2/25/2009 1:38:35 PM Computer Name = BEASTIE | Source = Windows Search Service | ID = 3013 -> Description = The entry in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details: A device attached to the system is not functioning. (0x8007001f) Application [ Error ] 2/25/2009 1:46:47 PM Computer Name = BEASTIE | Source = Application Hang | ID = 1002 -> Description = Hanging application msimn.exe, version 6.0.2900.5512, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Application [ Error ] 2/25/2009 1:46:49 PM Computer Name = BEASTIE | Source = Application Hang | ID = 1002 -> Description = Hanging application msimn.exe, version 6.0.2900.5512, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Application [ Error ] 2/25/2009 1:46:49 PM Computer Name = BEASTIE | Source = Application Hang | ID = 1002 -> Description = Hanging application msimn.exe, version 6.0.2900.5512, hang module hungapp, version 0.0.0.0, hang address 0x00000000. System [ Error ] 2/25/2009 4:34:58 PM Computer Name = BEASTIE | Source = Service Control Manager | ID = 7000 -> Description = The tmevtmgr service failed to start due to the following error: %%127 System [ Error ] 2/25/2009 4:34:58 PM Computer Name = BEASTIE | Source = Service Control Manager | ID = 7000 -> Description = The tmevtmgr service failed to start due to the following error: %%127 System [ Error ] 2/25/2009 4:34:58 PM Computer Name = BEASTIE | Source = Service Control Manager | ID = 7001 -> Description = The tmactmon service depends on the tmevtmgr service which failed to start because of the following error: %%127 System [ Error ] 2/25/2009 4:34:58 PM Computer Name = BEASTIE | Source = Service Control Manager | ID = 7001 -> Description = The Trend Micro Unauthorized Change Prevention Service service depends on the tmactmon service which failed to start because of the following error: %%1068 System [ Error ] 2/25/2009 4:36:01 PM Computer Name = BEASTIE | Source = Service Control Manager | ID = 7000 -> Description = The tmevtmgr service failed to start due to the following error: %%127 System [ Error ] 2/25/2009 4:36:01 PM Computer Name = BEASTIE | Source = Service Control Manager | ID = 7000 -> Description = The tmevtmgr service failed to start due to the following error: %%127 System [ Error ] 2/25/2009 4:36:01 PM Computer Name = BEASTIE | Source = Service Control Manager | ID = 7001 -> Description = The tmactmon service depends on the tmevtmgr service which failed to start because of the following error: %%127 System [ Error ] 2/25/2009 4:36:01 PM Computer Name = BEASTIE | Source = Service Control Manager | ID = 7001 -> Description = The Trend Micro Unauthorized Change Prevention Service service depends on the tmactmon service which failed to start because of the following error: %%1068 System [ Error ] 2/25/2009 5:37:50 PM Computer Name = BEASTIE | Source = Print | ID = 6161 -> Description = The document mhtml:mid://00000004/ owned by Administrator failed to print on printer Canon iP4300. Data type: NT EMF 1.008. Size of the spool file in bytes: 109729012. Number of bytes printed: 17303548. Total number of pages in the document: 36. Number of pages printed: 0. Client machine: \\BEASTIE. Win32 error code returned by the print processor: 13 (0xd). System [ Error ] 2/25/2009 7:56:09 PM Computer Name = BEASTIE | Source = DCOM | ID = 10010 -> Description = The server {FBA44040-BD27-4A09-ACC8-C08B7C723DCD} did not register with DCOM within the required timeout. [Files/Folders - Created Within 30 Days] 1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> OTScanIt2 -> %UserProfile%\Desktop\OTScanIt2 -> [2009/02/25 16:02:59 | 00,000,000 | ---D | C] OTScanIt2.exe -> %UserProfile%\Desktop\OTScanIt2.exe -> [2009/02/25 16:02:19 | 00,661,370 | ---- | C] () LastGood -> %SystemRoot%\LastGood -> [2009/02/25 15:57:50 | 00,000,000 | ---D | C] _OTMoveIt -> %SystemDrive%\_OTMoveIt -> [2009/02/25 15:46:58 | 00,000,000 | ---D | C] OTMoveIt3.exe -> %UserProfile%\Desktop\OTMoveIt3.exe -> [2009/02/25 15:45:34 | 00,348,160 | ---- | C] (OldTimer Tools) Trend Micro -> %AllUsersProfile%\Application Data\Trend Micro -> [2009/02/25 12:33:33 | 00,000,000 | ---D | C] TrendMicro_TIS_17.00_en-US_32-bit -> %AllUsersProfile%\Desktop\TrendMicro_TIS_17.00_en-US_32-bit -> [2009/02/25 11:51:09 | 00,000,000 | ---D | C] TrendMicro_Downloader -> %UserProfile%\Desktop\TrendMicro_Downloader -> [2009/02/25 11:47:25 | 00,000,000 | ---D | C] HP Usg Daily FY04.job -> %SystemRoot%\tasks\HP Usg Daily FY04.job -> [2009/02/25 11:41:53 | 00,000,332 | ---- | C] () How To Remove Smitfraud This tool removes Desktop Hijack malware.url -> %UserProfile%\Desktop\How To Remove Smitfraud This tool removes Desktop Hijack malware.url -> [2009/02/25 11:38:07 | 00,000,272 | ---- | C] () VCCLSID.exe -> %SystemRoot%\System32\VCCLSID.exe -> [2009/02/25 11:31:23 | 00,289,144 | ---- | C] (S!Ri) VACFix.exe -> %SystemRoot%\System32\VACFix.exe -> [2009/02/25 11:31:23 | 00,087,552 | ---- | C] (S!Ri.URZ) IEDFix.exe -> %SystemRoot%\System32\IEDFix.exe -> [2009/02/25 11:31:23 | 00,082,944 | ---- | C] (S!Ri.URZ) IEDFix.C.exe -> %SystemRoot%\System32\IEDFix.C.exe -> [2009/02/25 11:31:23 | 00,082,944 | ---- | C] (S!Ri.URZ) 404Fix.exe -> %SystemRoot%\System32\404Fix.exe -> [2009/02/25 11:31:23 | 00,082,432 | ---- | C] (S!Ri.URZ) o4Patch.exe -> %SystemRoot%\System32\o4Patch.exe -> [2009/02/25 11:31:23 | 00,080,384 | ---- | C] (S!Ri.URZ) swxcacls.exe -> %SystemRoot%\System32\swxcacls.exe -> [2009/02/25 11:31:23 | 00,079,360 | ---- | C] (SteelWerX) Agent.OMZ.Fix.exe -> %SystemRoot%\System32\Agent.OMZ.Fix.exe -> [2009/02/25 11:31:23 | 00,078,336 | ---- | C] (S!Ri.URZ) dumphive.exe -> %SystemRoot%\System32\dumphive.exe -> [2009/02/25 11:31:23 | 00,051,200 | ---- | C] () WS2Fix.exe -> %SystemRoot%\System32\WS2Fix.exe -> [2009/02/25 11:31:23 | 00,025,600 | ---- | C] () SrchSTS.exe -> %SystemRoot%\System32\SrchSTS.exe -> [2009/02/25 11:31:22 | 00,288,417 | ---- | C] (S!Ri) swreg.exe -> %SystemRoot%\System32\swreg.exe -> [2009/02/25 11:31:22 | 00,135,168 | ---- | C] (SteelWerX) Process.exe -> %SystemRoot%\System32\Process.exe -> [2009/02/25 11:31:22 | 00,053,248 | ---- | C] (http://www.beyondlogic.org) swsc.exe -> %SystemRoot%\System32\swsc.exe -> [2009/02/25 11:31:22 | 00,040,960 | ---- | C] () SmitfraudFix -> %UserProfile%\Desktop\SmitfraudFix -> [2009/02/25 11:31:04 | 00,000,000 | ---D | C] mbam-setup.exe -> %UserProfile%\Desktop\mbam-setup.exe -> [2009/02/25 11:30:20 | 02,876,728 | ---- | C] (Malwarebytes Corporation ) HijackThis™ Logs and Infections Removal - What the Tech.url -> %UserProfile%\Desktop\HijackThis™ Logs and Infections Removal - What the Tech.url -> [2009/02/25 11:25:53 | 00,000,222 | ---- | C] () Trend Micro -> %ProgramFiles%\Trend Micro -> [2009/02/25 11:13:47 | 00,000,000 | ---D | C] Tax keepers -> %UserProfile%\My Documents\Tax keepers -> [2009/02/23 09:13:39 | 00,000,000 | ---D | C] TrendMicro_TIS_17.00_en-US_32-bit.exe -> %AllUsersProfile%\Desktop\TrendMicro_TIS_17.00_en-US_32-bit.exe -> [2009/02/21 15:58:05 | 66,644,872 | ---- | C] (Trend Micro Inc.) .housecall6.6 -> %UserProfile%\.housecall6.6 -> [2009/02/20 18:58:37 | 00,000,000 | ---D | C] backup 2-20-2009.reg -> %UserProfile%\My Documents\backup 2-20-2009.reg -> [2009/02/20 18:13:11 | 92,070,862 | ---- | C] () ntuser.dat -> %UserProfile%\ntuser.dat -> [2009/02/18 17:58:45 | 06,815,744 | ---- | C] () Atx45.ocx -> %SystemRoot%\System32\Atx45.ocx -> [2009/02/14 15:28:09 | 00,598,528 | ---- | C] (Bennet-Tec Information Systems) DartSock.dll -> %SystemRoot%\System32\DartSock.dll -> [2009/02/14 15:28:09 | 00,221,184 | ---- | C] (Dart Communications) DartTelnet.dll -> %SystemRoot%\System32\DartTelnet.dll -> [2009/02/14 15:28:09 | 00,118,784 | ---- | C] (Dart Communications) Zoom -> %ProgramFiles%\Zoom -> [2009/02/14 15:28:06 | 00,000,000 | ---D | C] U3 -> %AppData%\U3 -> [2009/02/11 13:59:13 | 00,000,000 | ---D | C] del200f.cty -> %SystemRoot%\System32\drivers\del200f.cty -> [2009/02/09 20:45:38 | 00,128,398 | R--- | C] () Modem Helper -> %ProgramFiles%\Modem Helper -> [2009/02/09 20:44:27 | 00,000,000 | ---D | C] vmm32 -> %SystemRoot%\System32\vmm32 -> [2009/02/09 20:43:23 | 00,000,000 | ---D | C] unPPC.exe -> %SystemRoot%\System32\unPPC.exe -> [2009/02/09 20:30:34 | 00,067,584 | ---- | C] (PeoplePC) unPPC6000.exe -> %SystemRoot%\System32\unPPC6000.exe -> [2009/02/09 20:30:34 | 00,063,488 | ---- | C] (PeoplePC) ppcwebi.dll -> %SystemRoot%\System32\ppcwebi.dll -> [2009/02/09 20:30:34 | 00,045,056 | ---- | C] (PeoplePC, Inc.) RegHero.exe -> %SystemRoot%\System32\RegHero.exe -> [2009/02/09 20:30:34 | 00,028,672 | ---- | C] () PPCInfo.exe -> %SystemRoot%\System32\PPCInfo.exe -> [2009/02/09 20:30:34 | 00,018,432 | ---- | C] (PeoplePC, Inc.) PopWait.exe -> %SystemRoot%\System32\PopWait.exe -> [2009/02/09 20:30:33 | 00,010,752 | ---- | C] () ATL70.dll -> %SystemRoot%\System32\ATL70.dll -> [2009/02/09 20:30:32 | 00,084,992 | ---- | C] (Microsoft Corporation) Keepers.lnk -> %UserProfile%\My Documents\Keepers.lnk -> [2009/02/09 09:30:47 | 00,000,345 | ---- | C] () fe4f0663d012e80d163dea993c0b22 -> %SystemDrive%\fe4f0663d012e80d163dea993c0b22 -> [2009/02/04 10:40:09 | 00,000,000 | ---D | C] [Files/Folders - Modified Within 30 Days] 1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> OTScanIt2.exe -> %UserProfile%\Desktop\OTScanIt2.exe -> [2009/02/25 16:02:21 | 00,661,370 | ---- | M] () Perflib_Perfdata_b0.dat -> %UserProfile%\Local Settings\Temp\Perflib_Perfdata_b0.dat -> [2009/02/25 15:57:40 | 00,016,384 | ---- | M] () wpa.dbl -> %SystemRoot%\System32\wpa.dbl -> [2009/02/25 15:55:59 | 00,002,206 | ---- | M] () Perflib_Perfdata_378.dat -> %AllUsersProfile%\Application Data\Microsoft\Search\Data\Temp\usgthrsvc\Perflib_Perfdata_378.dat -> [2009/02/25 15:54:59 | 00,016,384 | ---- | M] () SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [2009/02/25 15:54:23 | 00,000,006 | -H-- | M] () bootstat.dat -> %SystemRoot%\bootstat.dat -> [2009/02/25 15:54:07 | 00,002,048 | --S- | M] () ntuser.dat -> %UserProfile%\ntuser.dat -> [2009/02/25 15:52:58 | 06,815,744 | ---- | M] () ntuser.ini -> %UserProfile%\ntuser.ini -> [2009/02/25 15:52:58 | 00,000,278 | -HS- | M] () OTMoveIt3.exe -> %UserProfile%\Desktop\OTMoveIt3.exe -> [2009/02/25 15:45:40 | 00,348,160 | ---- | M] (OldTimer Tools) TmDbg32.dll -> %UserProfile%\Local Settings\Temp\TmDbg32.dll -> [2009/02/25 12:32:17 | 00,126,208 | ---- | M] (Trend Micro Inc.) mfc80.dll -> %UserProfile%\Local Settings\Temp\mfc80.dll -> [2009/02/25 12:32:16 | 01,101,824 | ---- | M] (Microsoft Corporation) mfc80u.dll -> %UserProfile%\Local Settings\Temp\mfc80u.dll -> [2009/02/25 12:32:16 | 01,093,120 | ---- | M] (Microsoft Corporation) msvcr80.dll -> %UserProfile%\Local Settings\Temp\msvcr80.dll -> [2009/02/25 12:32:16 | 00,626,688 | ---- | M] (Microsoft Corporation) msvcp80.dll -> %UserProfile%\Local Settings\Temp\msvcp80.dll -> [2009/02/25 12:32:16 | 00,548,864 | ---- | M] (Microsoft Corporation) msvcm80.dll -> %UserProfile%\Local Settings\Temp\msvcm80.dll -> [2009/02/25 12:32:16 | 00,479,232 | ---- | M] (Microsoft Corporation) mfcm80.dll -> %UserProfile%\Local Settings\Temp\mfcm80.dll -> [2009/02/25 12:32:16 | 00,069,632 | ---- | M] (Microsoft Corporation) mfcm80u.dll -> %UserProfile%\Local Settings\Temp\mfcm80u.dll -> [2009/02/25 12:32:16 | 00,057,856 | ---- | M] (Microsoft Corporation) atl80.dll -> %UserProfile%\Local Settings\Temp\atl80.dll -> [2009/02/25 12:32:15 | 00,096,256 | ---- | M] (Microsoft Corporation) Remove.exe -> %SystemRoot%\Temp\Remove.exe -> [2009/02/25 12:32:14 | 00,665,928 | ---- | M] (Trend Micro Inc.) CONFIG.NT -> %SystemRoot%\System32\CONFIG.NT -> [2009/02/25 12:31:51 | 00,002,577 | ---- | M] () TrendMicro_TIS_17.00_en-US_32-bit.exe -> %AllUsersProfile%\Desktop\TrendMicro_TIS_17.00_en-US_32-bit.exe -> [2009/02/25 11:50:48 | 66,644,872 | ---- | M] (Trend Micro Inc.) HP Usg Daily FY04.job -> %SystemRoot%\tasks\HP Usg Daily FY04.job -> [2009/02/25 11:41:55 | 00,000,332 | ---- | M] () How To Remove Smitfraud This tool removes Desktop Hijack malware.url -> %UserProfile%\Desktop\How To Remove Smitfraud This tool removes Desktop Hijack malware.url -> [2009/02/25 11:38:07 | 00,000,272 | ---- | M] () tmp.reg -> %SystemRoot%\System32\tmp.reg -> [2009/02/25 11:33:46 | 00,003,418 | ---- | M] () hosts -> %SystemRoot%\System32\drivers\etc\hosts -> [2009/02/25 11:33:42 | 00,000,727 | ---- | M] () mbam-setup.exe -> %UserProfile%\Desktop\mbam-setup.exe -> [2009/02/25 11:30:29 | 02,876,728 | ---- | M] (Malwarebytes Corporation ) HijackThis™ Logs and Infections Removal - What the Tech.url -> %UserProfile%\Desktop\HijackThis™ Logs and Infections Removal - What the Tech.url -> [2009/02/25 11:25:53 | 00,000,222 | ---- | M] () wklntsk1.dat -> %AllUsersProfile%\Application Data\Microsoft\Works\wklntsk1.dat -> [2009/02/23 14:18:18 | 00,188,970 | ---- | M] () wklnhst.dat -> %AppData%\wklnhst.dat -> [2009/02/23 14:18:04 | 00,038,734 | ---- | M] () DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> %UserProfile%\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2009/02/21 16:06:32 | 00,011,264 | ---- | M] () backup 2-20-2009.reg -> %UserProfile%\My Documents\backup 2-20-2009.reg -> [2009/02/20 18:13:27 | 92,070,862 | ---- | M] () IconCache.db -> %UserProfile%\Local Settings\Application Data\IconCache.db -> [2009/02/19 23:17:01 | 02,188,932 | -H-- | M] () GDIPFONTCACHEV1.DAT -> %UserProfile%\Local Settings\Application Data\GDIPFONTCACHEV1.DAT -> [2009/02/17 13:09:48 | 00,135,048 | ---- | M] () Keepers.lnk -> %UserProfile%\My Documents\Keepers.lnk -> [2009/02/09 09:30:47 | 00,000,345 | ---- | M] () FNTCACHE.DAT -> %SystemRoot%\System32\FNTCACHE.DAT -> [2009/02/04 11:13:43 | 00,451,680 | ---- | M] () PerfStringBackup.INI -> %SystemRoot%\System32\PerfStringBackup.INI -> [2009/02/04 10:46:49 | 00,538,496 | ---- | M] () perfh009.dat -> %SystemRoot%\System32\perfh009.dat -> [2009/02/04 10:46:49 | 00,467,362 | ---- | M] () perfc009.dat -> %SystemRoot%\System32\perfc009.dat -> [2009/02/04 10:46:49 | 00,080,728 | ---- | M] () imsins.BAK -> %SystemRoot%\imsins.BAK -> [2009/02/04 10:32:31 | 00,001,355 | ---- | M] () qmgr0.dat -> %AllUsersProfile%\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [2009/02/04 10:31:21 | 00,004,232 | ---- | M] () qmgr1.dat -> %AllUsersProfile%\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [2009/02/04 10:31:20 | 00,005,487 | ---- | M] () wkcalcat.dat -> %AllUsersProfile%\Application Data\Microsoft\Works\wkcalcat.dat -> [2008/06/12 06:43:54 | 00,016,384 | ---- | M] () data.dat -> %AllUsersProfile%\Application Data\Microsoft\Office\Data\data.dat -> [2008/02/27 19:08:25 | 00,004,064 | ---- | M] () [Alternate Data Streams] @Alternate Data Stream - 0 bytes -> %UserProfile%\Desktop\Thumbs.db:encryptable @Alternate Data Stream - 0 bytes -> %UserProfile%\My Documents\Thumbs.db:encryptable [File - Lop Check] Application Data -> C:\Documents and Settings\Administrator\Application Data -> [2009/02/25 11:33:47 | 00,000,000 | -H-D | M] Amazon -> C:\Documents and Settings\Administrator\Application Data\Amazon -> [2008/07/24 16:32:44 | 00,000,000 | ---D | M] Canon -> C:\Documents and Settings\Administrator\Application Data\Canon -> [2009/01/27 13:27:06 | 00,000,000 | ---D | M] com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 -> C:\Documents and Settings\Administrator\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 -> [2008/08/30 12:34:05 | 00,000,000 | ---D | M] Corel -> C:\Documents and Settings\Administrator\Application Data\Corel -> [2008/01/29 10:02:49 | 00,000,000 | ---D | M] CyberLink -> C:\Documents and Settings\Administrator\Application Data\CyberLink -> [2008/09/28 14:02:41 | 00,000,000 | ---D | M] CyberMatrix -> C:\Documents and Settings\Administrator\Application Data\CyberMatrix -> [2008/04/21 10:13:25 | 00,000,000 | ---D | M] deskUNPDF -> C:\Documents and Settings\Administrator\Application Data\deskUNPDF -> [2008/07/24 12:53:48 | 00,000,000 | ---D | M] DirPrinter -> C:\Documents and Settings\Administrator\Application Data\DirPrinter -> [2008/07/20 13:51:45 | 00,000,000 | ---D | M] dvdcss -> C:\Documents and Settings\Administrator\Application Data\dvdcss -> [2008/09/28 15:13:47 | 00,000,000 | ---D | M] GameHouse -> C:\Documents and Settings\Administrator\Application Data\GameHouse -> [2008/07/06 14:51:15 | 00,000,000 | ---D | M] gtopala -> C:\Documents and Settings\Administrator\Application Data\gtopala -> [2008/02/11 15:51:51 | 00,000,000 | ---D | M] Jasc -> C:\Documents and Settings\Administrator\Application Data\Jasc -> [2008/05/07 11:34:19 | 00,000,000 | ---D | M] Leadertech -> C:\Documents and Settings\Administrator\Application Data\Leadertech -> [2008/09/19 16:14:53 | 00,000,000 | ---D | M] LimeWire -> C:\Documents and Settings\Administrator\Application Data\LimeWire -> [2009/02/21 13:59:02 | 00,000,000 | ---D | M] Move Networks -> C:\Documents and Settings\Administrator\Application Data\Move Networks -> [2009/02/09 10:15:01 | 00,000,000 | ---D | M] Nitro PDF -> C:\Documents and Settings\Administrator\Application Data\Nitro PDF -> [2008/07/24 13:29:15 | 00,000,000 | ---D | M] OfficeUpdate12 -> C:\Documents and Settings\Administrator\Application Data\OfficeUpdate12 -> [2008/07/27 14:22:15 | 00,000,000 | ---D | M] OpenOffice.org2 -> C:\Documents and Settings\Administrator\Application Data\OpenOffice.org2 -> [2008/08/27 20:46:27 | 00,000,000 | ---D | M] pdf995 -> C:\Documents and Settings\Administrator\Application Data\pdf995 -> [2008/02/28 09:59:15 | 00,000,000 | ---D | M] SanDisk -> C:\Documents and Settings\Administrator\Application Data\SanDisk -> [2008/11/30 15:01:17 | 00,000,000 | ---D | M] TrojanHunter -> C:\Documents and Settings\Administrator\Application Data\TrojanHunter -> [2008/10/07 09:15:55 | 00,000,000 | ---D | M] U3 -> C:\Documents and Settings\Administrator\Application Data\U3 -> [2009/02/11 18:21:41 | 00,000,000 | ---D | M] Web Page Maker -> C:\Documents and Settings\Administrator\Application Data\Web Page Maker -> [2008/08/04 14:59:53 | 00,000,000 | ---D | M] Windows Desktop Search -> C:\Documents and Settings\Administrator\Application Data\Windows Desktop Search -> [2009/01/01 16:41:35 | 00,000,000 | ---D | M] Windows Search -> C:\Documents and Settings\Administrator\Application Data\Windows Search -> [2008/07/25 15:25:06 | 00,000,000 | ---D | M] Application Data -> C:\Documents and Settings\All Users\Application Data -> [2009/02/25 12:33:33 | 00,000,000 | RH-D | M] Avg7 -> C:\Documents and Settings\All Users\Application Data\Avg7 -> [2008/05/07 11:34:13 | 00,000,000 | ---D | M] CanonBJ -> C:\Documents and Settings\All Users\Application Data\CanonBJ -> [2008/01/28 13:01:54 | 00,000,000 | -H-D | M] FLEXnet -> C:\Documents and Settings\All Users\Application Data\FLEXnet -> [2008/08/04 18:42:48 | 00,000,000 | ---D | M] LogiShrd -> C:\Documents and Settings\All Users\Application Data\LogiShrd -> [2008/08/19 17:53:06 | 00,000,000 | ---D | M] n7-89-o9-3r-4t-r9 -> C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9 -> [2008/07/06 14:50:15 | 00,000,000 | ---D | M] Nitro PDF -> C:\Documents and Settings\All Users\Application Data\Nitro PDF -> [2008/07/24 14:56:00 | 00,000,000 | ---D | M] PC Drivers HeadQuarters -> C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters -> [2008/05/07 11:33:22 | 00,000,000 | ---D | M] pdf995 -> C:\Documents and Settings\All Users\Application Data\pdf995 -> [2009/01/16 10:23:41 | 00,000,000 | ---D | M] SITEguard -> C:\Documents and Settings\All Users\Application Data\SITEguard -> [2008/04/22 13:45:05 | 00,000,000 | ---D | M] STOPzilla! -> C:\Documents and Settings\All Users\Application Data\STOPzilla! -> [2008/04/22 14:02:54 | 00,000,000 | ---D | M] TEMP -> C:\Documents and Settings\All Users\Application Data\TEMP -> [2008/06/10 14:40:48 | 00,000,000 | ---D | M] Application Data -> C:\Documents and Settings\Default User\Application Data -> [2008/08/02 18:37:12 | 00,000,000 | RH-D | M] Application Data -> C:\Documents and Settings\Gramma\Application Data -> [2008/08/30 13:13:08 | 00,000,000 | RH-D | M] Corel -> C:\Documents and Settings\Gramma\Application Data\Corel -> [2008/01/28 15:31:52 | 00,000,000 | ---D | M] CyberLink -> C:\Documents and Settings\Gramma\Application Data\CyberLink -> [2008/01/28 18:11:28 | 00,000,000 | ---D | M] Application Data -> C:\Documents and Settings\LocalService\Application Data -> [2008/07/24 14:55:56 | 00,000,000 | ---D | M] Application Data -> C:\Documents and Settings\NetworkService\Application Data -> [2008/01/28 10:55:40 | 00,000,000 | ---D | M] C:\WINDOWS\Tasks\ -> C:\WINDOWS\Tasks -> [2009/02/25 11:41:53 | 00,000,000 | --SD | M] desktop.ini -> C:\WINDOWS\Tasks\desktop.ini -> [2004/08/04 04:00:00 | 00,000,065 | RH-- | M] () HP Usg Daily FY04.job -> C:\WINDOWS\Tasks\HP Usg Daily FY04.job -> [2009/02/25 11:41:55 | 00,000,332 | ---- | M] () SA.DAT -> C:\WINDOWS\Tasks\SA.DAT -> [2009/02/25 15:54:23 | 00,000,006 | -H-- | M] () [File - Purity Scan] [CatchMe Rootkit Scan by GMER] < Windows folder & sub-folders > scanning hidden processes ... scanning hidden services & system hive ... [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager] "PendingFileRenameOperations"=str(7):"\x6264\2\x36282\x4e0a\x122a\xff98\xffff\x6b6e \xefac\x481e\x97a4\x1c9\0\0\xc610\20\1\0\1\0\x5808\26\xaca8\x8000\6\0\x9dc02\x218\0\xffff\xffff\22\0\0\0\30\0B\0\x159\0\21\0\x4d57\x4d44\x5020\x534d\x2050\x6553\x7672\x6369e\0\x35782\xffe0\xffff\x6b76\5\4\x8000\2\0\4\0\1\\x7453\x7261tr\xfff0\xffff\x8e0\\x928\\xe2d0\xe465\xffd8\xffff\x6b76\f\4\x8000\1\0\4\0\1C\x7245\x6f72\x4372\x6e6f\x7274\x6c6fcc\xffd8\xffff\x6b76\tB\0\x35e02\2\0\1\x1c8\x6d49\x6761\x5065\x7461h\0\0\0\xffb8\xffffC:\WINDOWS\system32\MsPMSPSv.exe\0\xe465\xfff0\xffff\xb020/\x3020/\xe2d0\xe465\xfff8\xffff\x34002\xffd8\xffff\x6b76\v$\0\x36682\1\0\1\0\x6944\x7073\x616c\x4e79\x6d61e\1\0\xffd8\xffffWMDM PMSP Service\0\xffa8\xffff\x6b6e \x96d0\x8678\xabfb\x1c8\0\0\x34f82\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x9fe02\x3120V\xffff\xffff\0\0\0\0\20\0\xa8\0\0\0\b\0\x6553\x7563\x6972\x7974\xfff0\xffff\x21383\x21a83.D\xfff0\xffff\xbbc02\xbc082\x1fe7a\xffb0\xffffIntel\0ard IDE ATA/ATAPI controllers)\0\0\xffa0\xffff{4D36E96A-E325-11CE-BFC1-08002BE10318}\0002\0\0\0\xffc8\xffff\xda68&\x4230'\x3d38'\x4098'\x49a8'\xe6c0+\xe640+\xeda8+\x7360,\xe828+\xe988+\xee18+8}\xffe0\xffff\x6b76\5\4\x8000\2\0\4\0\1*\x7453\x7261\x6e74\x7473\xffd8\xffff\x6b76\f\4\x8000\1\0\4\0\1H\x654e\x7478\x6e49\x7473\x6e61\x6563\x56f8H\xffd0\xffff\x6b76\24\4\x80002\0\1\0\1\0\x554e\x424d\x5245\x4f5f\x5f46\x5250\x434f\x5345\x4f53\x5352\0\0\xffe0\xffffUSB\UNKNOWN\0\0>\xffd8\xffff\x6b76\16\20\0\xfa8-\1\0\1\xc827\x6c41\x6574\x6e72\x7461\x5365\x6568\x6c6c\x2f7d\xffd8\xffff\xf8a8%\x76d8&\x72d0'\x9ea8'\x5358(\x6d78(\xd078,\x05f80\0\0\xffe0\xffff\x6b76\5\34\0\x46502\1\0\1&\x7247\x756f\x6e70&\xfff8\xffff\x41282\xffd8\xffff\x6b76\n0\0\x8a40O\1\0\1*\x6544\x6976\x6563\x6544\x6373\x614d\x6b73\x704f\b\0\x54902\xfff8\xffff\x5a682\xffd0\xffff\x9ad8&\xafa8&\xad88&\x7378'\x4f98'\x5260'\x9370'\x9a30'\x18a80\x1a100\x69c0'\xffe8\xffff\x686c\1\x8c100\x02457\x8c100\x02457\xffa0\xffff\x6b6e \xdcc2\x704\xee88\x1c8\0\0\x2350\17\1\0\0\0\x3ff02\xffff\xffff\1\0\xbe68,\xa988\r\xffff\xffff\b\0\0\0\30\0\4\0C\0\n\0\x454c\x4147\x5943\x4d5f\x4d442\xc8b9\xa773\xffa8\xffff\x6b6e \x5c0c\x66f7\x97a4\x1c9\0\0\x39802\0\0\1\0\xffff\xffff\x3f80\x8002\6\0\x1cb8-\xa988\r\xffff\xffff\16\0\0\0\26\0N\0\0\0\4\0\x3030\x3030\x3673\x635f\xffd8\xffff\x6b76\v\4\x8000\0\0\4\0\1\x33e4\x6f43\x666e\x6769\x6c46\x6761s\xdc33\x7f6\xffd8\xffff\x6b76\tN\0\x3a882\1\0\1\x4603\x6c43\x7361\x4773\x4955\xd144\21\x7919\x28d5\xffa8\xffff{8ECC055D-047F-11D1-A537-0000F8753ED1}\0\21\x9f2f\x8db\xffd8\xffff\x6b76\n,\0\x3b082\1\0\1\x8db\x6544\x6976\x6563\x6544\x6373\21\x54d7\xdb16\xffd0\xffffMachine Debug Manager\0\xff88\xffff\x6b6e \xfcaa\x7a6\xee88\x1c8\0\0\x12a0\r\0\0\0\0\xffff\xffff\xffff\xffff\4\0\x2980+\x218\0\xffff\xffff\0\0\0\0\16\0\xbc\0\2\0&\0\x447b\x3144\x3343\x3633\x2d34\x4444\x3238\x342d\x3945\x2d46\x4639\x3337\x422d\x3630\x3335\x3632\x3734\x4139\x7d31\x77bb\xffb8\xffffMicrosoft Office Document Imaging\0\xffb8\xffffMicrosoft Office Document Imaging\0\xffe0\xffff\x6b76\4\24\0\x56002\1\0\1\x1896\x6349\x6e6f\x62f2\xa3d7\xffd8\xffffTerminal Services\0\xffd8\xffff\x6b76\tN\0\xc7682\1\0\1\32\x6c43\x7361\x4773\x4955\x2b44Ue\0\xffe0\xffff\x6b76\6X\0\x80c0<\1\0\1\0\x7244\x7669\x7265e\xffe8\xffff\x1a58B\x1a80B\x1aa8B\x1ad0B\0\0\xffc8\xffff\xf2f8%\x36d0&\x4c70&\x80e8&\x8888&\x9078&\xbba0&\x2428'\xa8e8&\x13e0'\x7ae80\x3220')\0\xffe0\xffff\x6b76\b\4\x8000\0\0\4\0\1+\x4955\x754e\x626d\x7265\b\0\x4a782\xffa8\xffff\x6b6e \xffc2\xf9e2\x9780\x1c9\0\0\xeeb8\21\0\0\0\0\xffff\xffff\xffff\xffff\6\0\x49c82\xa988\r\xffff\xffff\16\0\0\0\26\0N\0\0\0\4\0\x3030\x3030\x7352W\xffa8\xffff{8ECC055D-047F-11D1-A537-0000F8753ED1}\0\0\x6b76\n\xffe0\xffffUSB\UNKNOWN\0\0e\xffd8\xffff\x6b76\n\xe6\0\x76f8>\a\0\1*\x6148\x6472\x6177\x6572\x4449s\x230,\xffe8\xffff\x1af8B\x1b18B\x1b40B\x1b60B\x3e882\xfff8\xffff\x56782\xffd8\xffffDriverInterface\0nd\xffd8\xffff\x6b76\n\30\0\x9b88+\1\0\1i\x624f\x656a\x7463\x614e\x656d.0.\xfff8\xffff\x38102\xffd8\xffff\x6b76\f\xc4\0\x5c78>\1\0\1'\x7953\x626d\x6c6f\x6369\x694c\x6b6e\xcf80'\xffe8\xffff\x1b80B\x1ba8B\x1bd0B\x1bf8B\x1c20B\xffa0\xffff{71A27CDD-812A-11D0-BEC7-08002BE2092F}\0002\0\0\0\xffd0\xffff\xa7e0&\xb240&\xbb30&\xbfc0&\x2648'\x6a20'\xc5c8'\x13f8(\xc398,\x1d20-\x6e49\x7473\xffa0\xffff{4D36E97D-E325-11CE-BFC1-08002BE10318}\0000\0\0\0\b\0\0\0\xfff0\xffff\x686c\1\x39e02\x2140&\x6268\x6e69\x40002\x1000\0\0\0\0\0\0\0\0\0\0\0\xffd8\xffff\x6b76\nB\0\x7920R\1\0\1\0\x6544\x6976\x6563\x6544\x6373\0\0\0\xffe0\xffff\x6b76\6X\0\xad188\1\0\1\17\x7244\x7669\x7265\17\xffd8\xffff\x6b76\v0\0\x6c182\1\0\1\0\x6944\x7073\x616c\x4e79\x6d61e\0\0\xffe0\xffff\x6b76\6X\0\xcba0<\1\0\1\17\x7244\x7669\x7265\17\20\0\x6962\x696c\b\0\0\0\xffe0\xffff\x6b76\3\24\0\x5c802\1\0\1v\x664dg\0e\xffe0\xffff\x6b76\bN\0\xd918B\1\0\1\0\x5355\x4344\x616c\x7373\xffd8\xffff\x6b76\t:\0\x5450<\2\0\1:\x6d49\x6761\x5065\x7461hME~\xffd8\xffff\x6b76\f\4\x8000\1\0\4\0\1\x7461\x654e\x7478\x6e49\x7473\x6e61\x6563\x6b76\a\xfff8\xffff\x60202\xffd8\xffff\x6b76\17@\0\x5a603\1\0\1\0\x6e45\x6d75\x7250\x706f\x6150\x6567\x33732\xfff8\xffff\x3eb82\xffd0\xffff\xaf70(\xd280*\x9a18+\x9a40+\x9a68+\xcdf8+\x4490+\x4d40+\x25c8+\x23b00\xc60&\b\0od\xfff8\xffff\x60782\xffe0\xffff\x6b76\4D\0\x3bf82\1\0\1t\x6544\x6373\0\0\xffe0\xffff\x6b76\b\4\x8000\0\0\4\0\1i\x6f53\x7275\x6563\x6449\xff68\xffffUSB\Class_03&SubClass_01&Prot_01\0USB\Class_03&SubClass_01\0USB\Class_03\0\0\0\0\xffc8\xffff\xe5a8&\xe290&\xef80&\x2980'\x4260'\xcfb8'\xed80+\xe928+\x7bb00\xe148+\xe2a0+\xedf8+)\0\xffe8\xffffusb.inf\0AD\xffe0\xffff\x6b76\4\36\0\x2eb0=\1\0\1\21\x6544\x6373\x6369e\xffd8\xffff\x6b76\th\0 5\2\0\1T\x6d49\x6761\x5065\x7461hSER\xffa8\xffffBackground Intelligent Transfer Service\0\x621f\x1c8(\0\x6b76\vD\0\xedf87\1\0\1\x6d65\x6944\x7073\x616c\x4e79\x6d61eLe\xffd8\xffff\x6b76\n\30\0\x2288-\1\0\1\0\x624f\x656a\x7463\x614e\x656d\0\0\0\xfff0\xffff\x686c\1\x57482\x2140&\xffd0\xffff\x6b76\22 \0\x44202\1\0\1o\x6f43\x666e\x6769\x7275\x7461\x6f69\x206e\x6946\x656cs\C\xffd8\xffffpdf995ps5ui.dll\0\0\0\xffe0\xffff\x6b76\6\x9de\0\x3020S\3\0\1s\x6f43\x666e\x6769h\xa0\0s\0P\0vsapint\0tmpreflt\0\0(\0\x6b76\r\4\x8000\0\0\4\0\0010\x6544\x7562\x4c67\x676f\x6c46\x6761\x44732H\0\x6b76\r\2\x8000\0\0\a\0\0014\x6544\x6570\x646e\x6e4f\x7247\x756f\x6b70\f \0\x6b76\a\32\0\xce902\1\0\1\x6e6f\x6556\x7372\x6f69\x746e\xfff0\xffffUSB\0\x6d69\x6e69\20\0\x686c\0\x54c82\x3648\x1678\xffa0\xffff\x6b6e \x5e60\x863f\xabfb\x1c8\0\0\x2350\17\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x45b02\xa988\r\xffff\xffff\b\0\0\0\30\0\4\0\21\0\17\0\x454c\x4147\x5943\x415f\x4756\x4337\x524fE\xffd8\xffff\x6b76\f\4\x8000\1\0\4\0\1 \x654e\x7478\x6e49\x7473\x6e61\x6563Ap\xfff8\xffff\x45882\xffa8\xffff{8ECC055D-047F-11D1-A537-0000F8753ED1}\0\0\0\0\xffc0\xffffCreates a network connection.\0\xffe0\xffffExtended Base\0\xffa0\xffff{4D36E966-E325-11CE-BFC1-08002BE10318}\0000\0\0\0\xffc8\xffff\x8830'\x7be8(\x8020(\xa1d0(\x9260(\x9590(\xa0a0(\xa448(\xa378(\xa488(\xa5f8(\xa678(\x87b0(\xffe0\xffff\x6b76\a\22\0\xe418'\1\0\1\0\x6553\x7672\x6369e\xffa8\xffff{4D36E966-E325-11CE-BFC1-08002BE10318}\0\0\0\0\xffe0\xffff\x6b76\a\22\0\xda98*\1\0\1H\x6e49\x5066\x7461h\xffa0\xffff{36FC9E60-C465-11CF-8056-444553540000}\0004\0\0\0\b\0)\0\xffe0\xffff\x6b76\6\32\0\xa0b83\1\0\1\0\x7244\x7669\x7265\0\xffa8\xffff{D41DD63A-1395-4419-AE14-A534F5F2AD29}\0\0\x6b76\20\xffd8\xffff\x6b76\16,\0\x53382\3\0\1n\x6146\x6c69\x7275\x4165\x7463\x6f69\x736ee\xffe0\xffff\x6b76\4\b\0\x9d80\b\1\0\1\0\x6349\x6e6f\0\0\xff70\xffffautocheck autochk *\0\0swBoot.exe /A:"*" /L:"English" /KBD:2\0\0 /KBD:2\0\0002\xffd8\xffff\x6b76\n>\0\x49802\1\0\1\3\x6544\x6976\x6563\x6544\x6373\xffff\xffff\xffff\xffb8\xffffavast! Standard Shield Support\0_ba\xffe0\xffff\x4f002\x4f382\x4f582\x4f802\x50402\x49582OC\xff78\xffffUSBSTOR\Disk&Ven_Samsung&Prod_YP-F1&Rev_0100\0002F741CD330405&0\0\x6c6f\x6369\xffd0\xffff\x7b58&\xa960&\xd068&\xd528&\x2668'\x2830'\x90e0'\x18c0(\x20f80\xd1280\x6552\x7274\xffe0\xffff\x6b76\6\4\x8000\1\0\4\0\1k\x654c\x6167\x7963\0\xffd8\xffff\x6b76\v\4\x8000\0\0\4\0\1e\x6f43\x666e\x6769\x6c46\x6761soc\xffe0\xffff\x6b76\5\32\0\x4b082\1\0\1i\x6c43\x7361sM\xffe0\xffffLegacyDriver\0c\xffd8\xffff\x6b76\tN\0\x4b502\1\0\1A\x6c43\x7361\x4773\x4955Dati\xffa8\xffff{8ECC055D-047F-11D1-A537-0000F8753ED1}\0\xffff\xffff\xffff\xffd8\xffff\x6b76\n<\0\x4bd02\1\0\1\0\x6544\x6976\x6563\x6544\x6373\0\4\0\xffc0\xffffavast! Network Shield Support\0\xffd8\xffff\xaf98(\x1d00)\xb80)\xee70)\x56f8*\x0f200\x0f480\x43b82\xb020*\xffd0\xffff\x8fd8&\xd230&\x6a40'\x2b50'\x6db0'\x8458'\x4e40'\x8150'\x6d70'\xcd38,ho\xffd8\xffff\x6b76\v\2\x8000\0\0\1\0\1,\x6f4c\x4667\x6c69\x4e65\x6d61\x6f65\x206e\x6946\b\0\xebc0+\xffd8\xffff\x6b76\v4\0\xb6983\1\0\1H\x6944\x7073\x616c\x4e79\x6d61e\x7a0H\xffd8\xffff\x6b76\n\30\0\x4e602\1\0\1,\x624f\x656a\x7463\x614e\x656d\0\x7963\0\xffb8\xffffMicrosoft Kernel Wave Audio Mixer\0\xff98\xffffMicrosoft WINMM WDM Audio Compatibility Driver\0\0\0\0\b\0\0e\xffd8\xffff\x6b76\tN\0\x41704\1\0\1\26\x6c43\x7361\x4773\x4955\x4444\x7365\x9d632\xffe0\xffff\x6b76\6X\0\x6f608\1\0\1V\x7244\x7669\x7265M\xffc0\xffffTerminal Server Mouse Driver\0\0\xffe8\xffff\x686c\2\x9dd8R\x4e64\x29c4\x9e40R\xe918\xb548\xffe0\xffff\x6b76\6X\0\xa398<\1\0\1:\x7244\x7669\x7265<\xffe0\xffffLocalSystem\0\0\0\xffa8\xffffUSB\Vid_04e8&Pid_502b\0002F741CD330405\0002b&\xffd8\xffff\x6b76\r\2\x8000\0\0\a\0\1\0\x6544\x6570\x646e\x6e4f\x7247\x756fp\0\xffe0\xffff\x6b76\a\20\0\x4f202\1\0\1\0\x6553\x7672\x6369e\xffe8\xffffaswMon2\0\x6b6e \xffe0\xffff\x6b76\6\4\x8000\1\0\4\0\1\0\x654c\x6167\x7963\xffff\xffd8\xffff\x6b76\v\4\x8000\0\0\4\0\1\0\x6f43\x666e\x6769\x6c46\x6761s\b\0\xffe0\xffff\x6b76\5\32\0\x50202\1\0\1\xe465\x6c43\x7361\x6b73\b\xffe8\xffff\x686c\1\xaec80\x02457\xaec80\x02457\xffd8\xffff\x6b76\f\4\x8000\1\0\4\0\1\0\x654e\x7478\x6e49\x7473\x6e61\x6563\0\0\xfff8\xffff\x4fb82\xfff0\xffff\x686c\1\x51302\x2140&\b\0\x40702\x6268\x6e69\x50002\x1000\0\0\0\0\0\0\0\0\0\0\0\xffe0\xffffLegacyDriver\0\0\xffd8\xffff\x6b76\tN\0\x50682\1\0\1`\x6c43\x7361\x4773\x4955\x144\2\x101\0\xffa8\xffff{8ECC055D-047F-11D1-A537-0000F8753ED1}\0\x500\22\0\20\0\x686c\0\x4d482\x2140&\xffa0\xffff\x6b6e \x5e60\x863f\xabfb\x1c8\0\0\x2350\17\1\0\0\0\x4fe82\xffff\xffff\1\0\x4fe02\xa988\r\xffff\xffff\b\0\0\0\30\0\4\0\22\0\16\0\x454c\x4147\x5943\x415f\x4756\x5237\x5753\0\xffa8\xffff\x6b6e \x5e60\x863f\xabfb\x1c8\0\0\x50d02\1\0\0\0\x7fc0\16\xffff\xffff\a\0\x53182\xa988\r\xffff\xffff\16\0\0\0\30\0N\0\0\0\4\0\x3030\x3030\0\0\xffe0\xffff\x6b76\a\20\0\x51a82\1\0\1\0\x6553\x7672\x6369e\xffe8\xffffAvg7RsW\0\0\0\xffe0\xffff\x6b76\6\4\x8000\1\0\4\0\1\0\x654c\x6167\x7963\0\xffd8\xffff\x6b76\v\4\x8000\0\0\4\0\1\0\x6f43\x666e\x6769\x6c46\x6761s\0\0\xffe0\xffff\x6b76\5\32\0\x52282\1\0\1\0\x6c43\x7361s\0\xffe0\xffffLegacyDriver\0\0\xffd8\xffff\x6b76\tN\0\x52702\1\0\1\0\x6c43\x7361\x4773\x4955D\0\0\0\xffa8\xffff{8ECC055D-047F-11D1-A537-0000F8753ED1}\0\0\0\0\xffd8\xffff\x6b76\n"\0\x52f02\1\0\1\0\x6544\x6976\x6563\x6544\x6373\0\0\0\xffd8\xffffAVG7 Wrap Driver\0\0\xffe0\xffff\x51882\x51c02\x51e02\x52082\x52482\x52c82\x02285\xffd0\xffff\x5180\1\0\0\0\0\3\0\5\3\1\0d\0\1\0d\0\0\0d\0\xffd8\xffff\x6b76\n\30\0\xe690,\1\0\1\0\x624f\x656a\x7463\x614e\x656d\0\0\0\xffe0\xffff\x6b76\5\32\0\x54302\1\0\0013\x6c43\x7361s\0\xffd8\xffff\xbc20(\x1d88)\x898)\x1fc8)\x16f0*\x7538*\x4ed82\x53682\0\0\xffd8\xffff\x6b76\f\4\x8000`\0\4\0\1 \x6143\x6170\x6962\x696c\x6974\x7365Pe\xffd8\xffff\x6b76\n\4\x8000\0\0\4\0\1+\x6f4c\x4667\x6c69\x5565\x6573,\xa98,\b\0\xca48+\xffe0\xffffLegacyDriver\0h\xffc0\xffffsystem32\DRIVERS\hidusb.sys\0\0\0\xffd8\xffff\x6b76\17\f\0\x77f0&\a\0\1\0\x6544\x6570\x646e\x6e4f\x6553\x7672\x6369e\xff68\xffffProvides support for the Running Object Table for InstallShield Drivers\0Le\xffc0\xffffsystem32\DRIVERS\isapnp.sys\0\0\0\xffd8\xffff\xff10)\x1320*\x2480*\x2828*\x2848*\xb128*\x40682\x62d02\i\xffc0\xffffsystem32\DRIVERS\mdmxsdk.sys\0\xf7f7\b\0\x4638*\xffe8\xffffsti.dll,0\0\xffa0\xffff\x6b6e \x5e60\x863f\xabfb\x1c8\0\0\x2350\17\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x3e582\xa988\r\xffff\xffff\b\0\0\0\30\0\4\0\23\0\17\0\x454c\x4147\x5943\x415f\x4756\x5237\x5853P\xffd8\xffff\x6b76\f\4\x8000\1\0\4\0\1\0\x654e\x7478\x6e49\x7473\x6e61\x6563\0\0\xffe0\xffff\x6b76\6X\0\xccd0R\1\0\0012\x7244\x7669\x7265>\xffa0\xffff\x6b6e \x5e60\x863f\xabfb\x1c8\0\0\x2350\17\1\0\0\0\x43e02\xffff\xffff\1\0\x60e82\xa988\r\xffff\xffff\b\0\0\0\30\0\4\0\3\0\17\0\x454c\x4147\x5943\x415f\x5641\x4b4d\x52454\xffd8\xffff\x6b76\f\4\x8000\1\0\4\0\1s\x654e\x7478\x6e49\x7473\x6e61\x6563\x6b76\6\xffa8\xffff\x6b6e \xc7ea\xe8ef\x9780\x1c9\0\0\x56c02\1\0\0\0\xeeb0&\xffff\xffff\b\0\xc460R\xa988\r\xffff\xffff\16\0\0\0\30\0X\0\0\0\4\0\x3030\x3030\1\0\xffe0\xffff\x6b76\a\22\0\x57c02\1\0\1y\x6553\x7672\x6369e\xffe8\xffffAavmker4\0002\b\0\x64c02\xffe0\xffff\x6b76\6\4\x8000\1\0\4\0\18\x654c\x6167\x79630\xffd8\xffff\x6b76\v\4\x8000\0\0\4\0\1D\x6f43\x666e\x6769\x6c46\x6761s-0\xffe0\xffff\x6b76\5\32\0\x58482\1\0\1}\x6c43\x7361s\0\xffe0\xffffLegacyDriver\0\x6544\xffd8\xffff\x6b76\tN\0\x58902\1\0\1R\x6c43\x7361\x4773\x4955Dnt \xffa8\xffff{8ECC055D-047F-11D1-A537-0000F8753ED1}\0\x6570\0\0\xffd8\xffff\x6b76\nD\0\x59102\1\0\1\0\x6544\x6976\x6563\x6544\x6373\0\x6b76\f\xffb8\xffffavast! Asynchronous Virus Monitor\0\xffe0\xffff\x6b76\6X\0\xcbb0R\1\0\1&\x7244\x7669\x72652\xffe0\xffff\x8138?\x8160?\x1fa0@\x2840@\x2318@\x24c0@\x5248=\xff58\xffff\\?\USB#Vid_040a&Pid_057f#KCTDL43603676#{a5dcbf10-6530-11d2-901f-00c04fb951ed}\0\0\0\0\xffd8\xffff\x6b76\f\4\x8000\24\0\4\0\1d\x6143\x6170\x6962\x696c\x6974\x73651 \xffd8\xffff\x6b76\f\xfe\0\xa220D\1\0\1\x13f2\x7953\x626d\x6c6f\x6369\x694c\x6b6e\xf7f7\xf8f7\b\0\x6b73\x704f\xffe0\xffffdisk_install\0\x6369\xffe8\xffff\x1c48B\x1c70B\x1c98B\x1cc0Bli\b\0\x44e02\xffa0\xffff{4D36E96F-E325-11CE-BFC1-08002BE10318}\0004\0\x6cc0+\20\0\x4be8&\b\0n\0\xffa0\xffff\x6b6e \x5e60\x863f\xabfb\x1c8\0\0\x2350\17\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x5bd02\xa988\r\xffff\xffff\b\0\0\0\30\0\4\0\26\0\r\0\x454c\x4147\x5943\x415f\x4756\x4454I\0\xffd8\xffff\x6b76\f\4\x8000\1\0\4\0\1\0\x654e\x7478\x6e49\x7473\x6e61\x6563\0\0\xfff8\xffff\x5ba82\xffa8\xffff{D41DD63A-1395-4419-AE14-A534F5F2AD29}\0\xffff\xffff\xffff\xffe0\xffff\xa558&\x40c0'\x9ec8'\x630(\x86a0(\xd1f8,\x6563\x6544\xffe0\xffff\x6b76\6X\0\xcd188\1\0\1\0\x7244\x7669\x7265e\20\0\xcb30,\xde60,\x1aa8-\xffe8\xffffMicrosoft\0\xffd8\xffff\x6b76\f\4\x8000\2\x2001\4\0\1+\x6f43\x746e\x6f72\x206c\x7954\x6570\xcd639(\0\x6b76\f\4\x8000\1\0\4\0\1\x1d9e\x7245\x6f72\x4372\x6e6f\x7274\x6c6f\x7561\x746c\xffd8\xffff\x6b76\n\26\0\xe78;\1\0\1*\x6544\x6976\x6563\x6544\x6373+\xc570+\xffb0\xffff(Standard IDE ATA/ATAPI controllers)\0\0\xffd8\xffff\x6b76\f\4\x8000\0\0\4\0\1\x1f6e\x6143\x6170\x6962\x696c\x6974\x7365e\0\30\0tmxpflt\0\0\0\xffe0\xffff5.1.2535.0\0\0r\0\xffe0\xffff\x6b76\2 \0\x2d608\3\0\1-\x3042\x7372\x6f69n(\0\x6b76\f\4\x8000\1\0\4\0\1e\x7245\x6f72\x4372\x6e6f\x7274\x6c6f\0\0\xffd8\xffff\x7e10(\xbe98(\xb0*\x98a0*\x99a8*\xa348*\xe8c8,\x2310-\0\0\xffd0\xffff\x6b76\23"\0\x19b0.\1\0\1\0\x6f4c\x6163\x6974\x6e6f\x6e49\x6f66\x6d72\x7461\x6f69n\1S\xffd8\xffff\x6b76\f\4\x8000\0\0\4\0\1(\x6f4c\x4667\x6c69\x4465\x6265\x6775\0\0\xffd8\xffff\x6b76\v\x1be\0\xb0c8R\1\0\1\0\x6544\x6373\x6972\x7470\x6f69n\0\0\xffd8\xffff\x6b76\n\24\0\x9850,\1\0\1\\x7244\x7669\x7265\x6144\x6574IMI\b\0\xc4a0+\xffe0\xffff\x6b76\a\22\0\x68882\1\0\1v\x6e49\x5066\x7461h\xffd8\xffff\x9ca8&\xdd28&\x90a8'\xc2c0'\xd118,\xd140,\x5c10'\x40482\0\0\xffe8\xffff\x8cd8G\x8dc0G\x8de0G\x8e08G\x8ae0G\xffd8\xffff\x6b76\r\4\x8000\4\0\4\0\1\24\x6946\x746c\x7265\x6552\x7274\x6569\xbd73\24\xffe0\xffffDisk drive\0\x5074\x6f72\x4470\xffb0\xffffSTORAGE\RemovableMedia\7&db28451&1&RM\0\b\0\x830,\xffe8\xffff\x686c\1\x88c80\xff98\x522b\x88c80\xff98\x522b\xfff8\xffff\x61502\x6268\x6e69\x60002\x1000\0\0\0\0\0\0\0\0\0\0\0\xffd8\xffff\x6b76\f\xc4\0\xa0d0>\1\0\1\x3c0d\x7953\x626d\x6c6f\x6369\x694c\x6b6e\x6a0e\x7f51\xffd8\xffff\x4758'\xcb50'\xde78'\xee70'\x930(\x1ac0(\x5d602\x10e8-e\0\b\0\0\0\xffd8\xffff\x6b76\16n\0\x5e90>\1\0\1\0\x6544\x6976\x6563\x6e49\x7473\x6e61\x6563\x4d45\xffd8\xffff\x9c0(\x1328(\xf0b0)\x7e60(\x12f8*\x7a58*\xea78,\xc9c0,\xb020*\xffe0\xffff\x6b76\a\20\0\x66902\1\0\1\0\x6f43\x6c6c\x6365t\xfff8\xffff\x57202\xffa0\xffff\x6b6e \x5e60\x863f\xabfb\x1c8\0\0\x2350\17\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x5ff82\xa988\r\xffff\xffff\b\0\0\0\30\0\4\0\24\0\17\0\x454c\x4147\x5943\x415f\x4756\x4c43\x4145N\xffd8\xffff\x6b76\f\4\x8000\1\0\4\0\1\0\x654e\x7478\x6e49\x7473\x6e61\x6563\0\0\xffd8\xffff\x6b76\f\4\x8000\0\0\4\0\0012\x6143\x6170\x6962\x696c\x6974\x7365\xff65\xffff\xffd8\xffff\x6b76\f\4\x8000\0\0\4\0\1\0\x6143\x6170\x6962\x696c\x6974\x7365\x7574s\xffc8\xffff\x6b76\e\x565a\0\x34e82\a\0\0012\x6550\x646e\x6e69\x4667\x6c69\x5265\x6e65\x6d61\x4f65\x6570\x6172\x6974\x6e6f\xff73\xffff\xffffh\0\0\0\32\0\4\0\0\0\n\0\x6150\x6172\x656d\x6574\x73727-0@\0system32\DRIVERS\tmxpflt.sys\0\0\xffe8\xfffftmxpflt\0\x2c98'\xffd8\xffff\x6b76\r\4\x8000\2\0\4\0\1\\x6143\x6574\x6f67\x7972\x6f43\x6e75t2(\0\x6b76\t<\0\x6e488\2\0\1\0\x6d49\x6761\x5065\x7461\x6d68\x6565\x6946\x656c\xffd8\xffff\x6b76\t8\0\x55502\2\0\1\0\x6d49\x6761\x5065\x7461h\0\0\0\xffe8\xffff\x8e80G\x8ea0G\x8ed8G\x8f00GN\0\xffe0\xffff\x6b76\a\26\0\x44704\1\0\1\0\x6e49\x5066\x7461h\xffd8\xffff\x6b76\n0\0\xcdf0:\1\0\1M\x6544\x6976\x6563\x6544\x6373M\xcc08M\b\0\xb1d8(\xffe0\xffff\x2ea0-\x76800\x74103\x53902\xb6183\x3f384\xefc0&\xffc8\xffff\x6b76\34\4\x8000\0\0\4\0\0015\x6944\x6173\x6c62\x2065\x6550\x6672\x726f\x616d\x636e\x2065\x6f43\x6e75\x6574\x7372\x6f72\x7267\xffc8\xffff\x7518\24\x7558\24\x75a8\24\x75d0\24\x7628\24\x7680\24\x76e0\24\x9a0.\xa10.\xa48.\x9e8.\x63802ro\xffc8\xffff\x6b76\34\4\x8000\0\0\4\0\1G\x6944\x6173\x6c62\x2065\x6550\x6672\x726f\x616d\x636e\x2065\x6f43\x6e75\x6574\x7372ga\xffc8\xffff\x77c0\24\x7810\24\x7870\24\x7898\24\x78f0\24\x7970\24\x79e0\24\xaa0.\xb10.\xb48.\xae8.\x63f02r.`\0FSFilter Anti-Virus\0\xf208)0\0\x6b76\17$\0\x44702\a\0\1\0\x6544\x6570\x646e\x6e4f\x6553\x7672\x6369\x6565\b\0\x6dc8,\xffd0\xffffMitsumi USB Floppy\0M\0+\b\0)\0\xffc8\xffffPDF995 Redirected Port\0.HL\xffd8\xffff\x6b76\16\b\0\x5b98(\3\0\0010\x7244\x7669\x7265\x6144\x6574\x6144\x6174\x4de0\xffd8\xffff\x6b76\17\x104\0\xbc90<\1\0\1i\x6553\x7261\x6863\x6e49\x6564\x6578\x2d721\xffc8\xffffSystem Restore Service\0\0\0\0\xffe0\xffff\x6b76\6\4\x8000\1\0\4\0\0012\x654c\x6167\x7963t\xffe0\xffffShellSvcGroup\0\xfff0\xffff\xea70R\xea98R\x2140&\xffd0\xffff\xd9f8&\xd790&\x4438'\xf580&\x958(\x1218(\x1648(\xdde0'\xdb28'\xe198'\x2b10(\xffc0\xffffsystem32\DRIVERS\asyncmac.sys\0\xffe8\xffffMicrosoft\0\xffe8\xffffCollect\0\0\0\xffe0\xffffmsmouse.inf\0\xbf18+\xffd8\xffff\x6b76\r\4\x8000\1\0\4\0\1\24\x7349\x6e45\x6d75\x6c41\x6f6c\x6577\x9964\24\xffe0\xffff\x6b76\5\b\0\x45082\1\0\1v\x6c43\x7361s\0\xffe0\xffff\x6b76\6X\0\x83f8>\1\0\1O\x7244\x7669\x7265O\xfff0\xffff\xeb20R\xeb48R\x67402\xffc8\xffffBOClean Kernel Monitor.\0\xd1c0<\xffe0\xffff\x6b76\a\20\0\x42d82\1\0\1<\x6e49\x5066\x7461h\xfff0\xffff\x8238S\x8858S\x84f8S\xffa8\xffff{6BDD1FC6-810F-11D0-BEC7-08002BE2092F}\0\0\0\0\xffc8\xffffACPI Multiprocessor PC\0\0\0\0\xffd8\xffff\x25c8&\x8c68&\x7cb0&\x9c28'\x94f0'\x3078,\x9060'\x6da80\0\0\xffd8\xffff\x6b76\v\4\x8000\0\0\4\0\1W\x6f43\x666e\x6769\x6c46\x6761s\s\xffe8\xffffdisk.inf\0\0\xffe8\xffff\x686c\1\xe7300\x59b7\x9d4a\xe7300\x59b7\x9d4a\xfff0\xffff\xea48R\xec08Rs\0\xffb0\xffff(Standard IDE ATA/ATAPI controllers)\0\0\xffe0\xffff\x6b76\3>\0\xae60<\1\0\1<\x664dg\xa420<\xffe8\xffff\x686c\1\x14f0\1\xe141\xc736\x14f0\1\xe141\xc736\xffd8\xffff\x6b76\n\30\0\xe5b8,\1\0\1o\x624f\x656a\x7463\x614e\x656dSys\xff90\xffffMonitors system security settings and configurations.\0\xffd8\xffff\xe670'\x9780+\xaa80+\x9e88+\xa6b8+\xa720+\xa080+\x1db80\xdd1040\0\x6b76\v\20\0\x5d882\1\0\1+\x6944\x7073\x616c\x4e79\x6d61e\xa958+\b\0\xa748+\xffe8\xffff\x1ce8B\x1d08B\x1d30B\x1d50Bs\0\xffe0\xffff\x6b76\b\4\x8000\0\0\4\0\1L\x4955\x754e\x626d\x7265\xffa8\xffff\x6b6e \x35e4\x8657\xabfb\x1c8\0\0\xb178\21\0\0\0\0\xffff\xffff\xffff\xffff\4\0\x2570-\x218\0\xffff\xffff\0\0\0\0&\0R\0\r\0\4\0\x5641\x3747\0\0\xffd8\xffff\x6b76\20H\0\x76c02\1\0\1\0\x7645\x6e65\x4d74\x7365\x6173\x6567\x6946\x656c\xffd8\xffff\x6b76\n0\0\x83d82\1\0\1~\x6544\x6976\x6563\x6544\x6373sof\xffd8\xffff\x6b76\v\4\x8000\0\0\4\0\1I\x6f43\x666e\x6769\x6c46\x6761s\0\0\xffd0\xffff\x6b76\23H\0\x77182\1\0\1\0\x6143\x6574\x6f67\x7972\x654d\x7373\x6761\x4665\x6c69e\0\0\xffd0\xffff\x6b76\23\30\0\x6ba82\1\0\1~\x6f4c\x6163\x6974\x6e6f\x6e49\x6f66\x6d72\x7461\x6f69nAV\xffe0\xffffOneTouch II\0\0\0\xffd8\xffff\x6b76\16\4\x8000\a\0\4\0\1\0\x7954\x6570\x5373\x7075\x6f70\x7472\x6465\0\xffd8\xffff\x6b76\r\4\x8000\5\0\4\0\1\0\x6143\x6574\x6f67\x7972\x6f43\x6e75t\0\xffc8\xffffPnP ISA/EISA Bus Driver\0\0\0\xffe8\xfffftm_cfwmp\0\0\xffd8\xffff\x6b76\16\4\x8000\0\0\4\0\1\0\x6257\x6d65\x6441\x7061\x7453\x7461\x7375\0\xffe0\xffff\x6b76\a\20\0\x53d8+\1\0\1<\x6e49\x5066\x7461h\xffe8\xffff\x1d70B\x1d98B\x1dc0B\x1de8B\x1e10B\xffd8\xffff\xad00(\xb360(\xb640(\xd3c8,\x4da02`(\x6e38,\x92e8,\xd8682\b\0ti\xffe0\xffff\x6b76\4\4\x8000\1\0\4\0\1r\x7954\x6570\0\0\xffd8\xffff\x6b76\v6\0\xad789\1\0\1\0\x6544\x6373\x6972\x7470\x6f69n\0\0\b\0\xb690(\xffe0\xffff\x6b76\aF\0\xfd20B\2\0\1,\x694c\x7262\x7261y\xffd8\xffff\x6b76\tn\0\x2d809\1\0\1o\x4c43\x5341\x5053\x5441Hste\xffd8\xffff\x6b76\v\x1c4\0\xa640<\1\0\1\0\x6544\x6373\x6972\x7470\x6f69n\0\0\xffa0\xffff{6BDD1FC6-810F-11D0-BEC7-08002BE2092F}\0003\0\0\0\xffa0\xffff{71A27CDD-812A-11D0-BEC7-08002BE2092F}\0000\0\0\0\xffd8\xffff\xd758&\xebe8&\xc358'\x4910'\xc4b0'\xdd48,\xfb58&\x40902er\20\0ce\0\0\0\0\xffd8\xffff\x6b76\16\4\x8000\4\0\4\0\1\0\x7954\x6570\x5373\x7075\x6f70\x7472\x6465\0\xffe0\xffffBADDEVICE.Dev\0\xffd8\xffff\x6b76\v>\0\x2da88\1\0\1\0\x6e49\x7473\x6c61\x656c\x33722\0\0\xff40\xffffProvides management for applications that require assistance in a multiple user environment.\0\0\20\0\x6c6f\x6369\x694c\x6b6e\x3b2c\xcbc9\xfff0\xffff\x8000\xc562\x1c0\x1c1\0S\x6268\x6e69\x70002\x1000\0\0\0\0\0\0\0\0\0\0\0\xffa8\xffffMicrosoft Kernel DRM Audio Descrambler\0\0\0\0\xffa0\xffff\x6b6e \xb0c6\x85f0\xabfb\x1c8\0\0\x348\0\5\0\0\0\x68d03\xffff\xffff\0\0\xffff\xffff\x51a0T\xffff\xffff\34\0\0\0\0\0\0\0\f\0\r\0\x7243\x6165\x6974\x6576\x5420\x6365hs\xffa8\xffff\x6b6e \xb0c6\x85f0\xabfb\x1c8\0\0\x70782\1\0\0\0\x9728+\xffff\xffff\0\0\xffff\xffff\x51a0T\xffff\xffff\20\0\0\0\0\0\0\0\3\0\b\0\x6144\x6174\x6162\x6573\xffa8\xffff\x6b6e \xb0c6\x85f0\xabfb\x1c8\0\0\x70d82\2\0\0\0\x7470T\xffff\xffff\0\0\xffff\xffff\x51a0T\xffff\xffff\32\0\0\0\0\0\0\0\0\0\a\0\x7250\x646f\x6375t\xffa8\xffff{CE63F2CA-B02C-4D9D-9C08-6A837DB1FBD1}\0\0B3\xffd8\xffff\x6b76\v\4\x8000\0\0\4\0\1\0\x6f43\x666e\x6769\x6c46\x6761s\0\0\xffa8\xffff{36FC9E60-C465-11CF-8056-444553540000}\0\0\0\0\xffc8\xffff\x9390'\x60c0(\x6ab8(\x3c00'\x6b38(\x6f20(\x64e0(\x65b0(\x61e0(\x71f8(\x6508(\x7670(\x79d8(\b\0\x2140&\xfff8\xffff\xaf482\xffa8\xffff{36FC9E60-C465-11CF-8056-444553540000}\0\0\0\0\xffd8\xffff\x1550'\xb4c0(\x1060)\x1840)\x5c38*\xff68*\xcfe0,\x6d182\0\0\xffb8\xffff(Standard USB Host Controller)\0\0\0\0\xffc8\xffff\xa9f0&\xe148&\xe2f8&\xe970&\x5ad8'\x56f0'\xef08'\x3f60'\x3d80'\x5718'\x1458(\x1c80(\x5298(\xffe0\xffff\x6b76\4\4\x8000\20\0\4\0\1\x6c61\x7954\x6570\x6369e\xffd8\xffff\x6b76\f\4\x8000\1\0\4\0\1\x8ab6\x654e\x7478\x6e49\x7473\x6e61\x6563\x5b6f\x8005\xffe8\xffff\x686c\1\x85f8L\xd8cc\x6cc0\x85f8L\xd8cc\x6cc0\xffd8\xffffSecurity Center\0\0\0\20\0\x686c\0\xca382\xe2d0\xe465\xffe8\xffff\x1e38B\x1e60B\x1e88B\x1eb0B\x7688\20\xffa0\xffff{8ECC055D-047F-11D1-A537-0000F8753ED1}\0034\0\P\xffd8\xffff\x6b76\v\4\x8000\0\0\4\0\1m\x6f43\x666e\x6769\x6c46\x6761sNl\b\0\x78d82\xfff8\xffff\x79a02\xffe8\xffff\x2019\x4014\0\x9000\x4820\x3615\0\0\x3de81\20\0\x686c\0\xacc02\xba4c\x5819\xffe0\xffff\1\1\0\0\4\0006\0\0\x800\x5b62\x1002\x602\0\xffd8\xffff\x6b76\17\30\0\x20205\3\0\1\6\x5441\x4c49\x474b\x7953\x4373\x6e6f\x6966\x3267\xfff8\xffff\x8d682\xffe0\xffff\x6b76\b\xa8\0\x20203\3\0\0012\x6553\x7563\x6972\x7974\xffa8\xffff\x6b6e \x25f0\x8606\xabfb\x1c8\0\0\x91884\1\0\0\0\x7530P\xffff\xffff\1\0\x96882\x218\0\xffff\xffff$\0\0\0\30\0\x102\0\0\0\5\0\x5323\x4441\xa9302\xffa0\xffff{36FC9E60-C465-11CF-8056-444553540000}\0011\0\0\0\b\0\xa2d0+\xffe8\xffffati2dvag\0\0\xffd8\xffff\x6b76\r\26\0\x1048-\1\0\1\0\x7244\x7669\x7265\x6556\x7372\x6f69ne\xffe0\xffff\x6b76\3\b\0\x76a82\3\0\1\0\x5641G\0\0\xffe8\xffff\1\0\2\0\2\0\4\0\0\0\xffa8\xffffC:\PROGRA~1\Grisoft\AVG7\avglog.dll\0.dll\0\0\xffa8\xffffC:\PROGRA~1\Grisoft\AVG7\avglog.dll\0.dll\0\0 \0\x6b76\5\4\x8000\1\0\4\0\1+\x7453\x7261\xa074,\xffd8\xffffComputer Browser\0\0\xffc8\xffffPacket Scheduler Miniport\0\xffe8\xffffvsapint\0\x06700\xfff0\xffff\x8600S\x9780S\x8ec8S\xffa0\xffff{8ECC055D-047F-11D1-A537-0000F8753ED1}\0005\0\0\0\xffd8\xffff\x4528&\x84c0&\xe5d0&\x3ba8'\x9518'\x7500,\x9498'\x82d8,1}\xffc8\xffffPacket Scheduler Miniport\08\0\xb238\f\xee88&\x2688'\x29e8'\x2ae8'\x5820'\x7638'\x7570'\xf00(\x5848'\1\0\b\0\x4372\x6e6f\xfff0\xffff\x686c\1\xaa60V\xe918\xb548\xffd8\xffff\x6b76\20\22\0\xa090,\1\0\1\0\x614d\x6374\x6968\x676e\x6544\x6976\x6563\x6449\b\0\x4e0a\x122a\xfff0\xffff\xa020S\xbca0S\xbcc8S\xffe8\xffff\x686c\1\xc080\1\x8014\x3fcf\xc080\1\x8014\x3fcf\xffd8\xffffDriverInterface\0\x6b76\21\xffd8\xffff\x6b76\f\4\x8000\1\0\4\0\1*\x654e\x7478\x6e49\x7473\x6e61\x6563\xe7d84\xffd8\xffff\x6b76\20N\0\xc0202\1\0\1\25\x654e\x4374\x6766\x6e49\x7473\x6e61\x6563\x6449\xffa0\xffff{4D36E97D-E325-11CE-BFC1-08002BE10318}\0004\0\0\0\xffd8\xffff\x6b76\nJ\0\xce002\1\0\0012\x7244\x7669\x7265\x6544\x6373IPO\b\0\x6973\x7974\xffa0\xffff\x6b6e \x9cc8\x9b7d\x9760\x1c9\0\0\x0f501\2\0\0\0\x83c0-\xffff\xffff\f\0\x84102\xa988\r\xffff\xffff"\0\0\0&\0\x90\0\0\0\f\0\x334c\x3744\x5847\x484e\x5f5f\x5f5f??\xffd8\xffff\x6b76\f\4\x8000\24\0\4\0\1\\x6143\x6170\x6962\x696c\x6974\x736532\xffa8\xffff\x6b6e \xe7c8\x8648\xabfb\x1c8\0\0\x7a802\0\0\0\0\xffff\xffff\xffff\xffff\0\0\xffff\xffff\xa988\r\xffff\xffff\0\0\0\0\0\0\0\0\1\0\a\0\x6f4c\x4367\x6e6ff\xfff0\xffff.NT\0\xe918\xb548\xff98\xffff\x6b6e \xe7c8\x8648\xabfb\x1c8\0\0\x7a802\0\0\0\0\xffff\xffff\xffff\xffff\2\0\x88e0\16\x7e582\xffff\xffff\0\0\0\0(\0\x9a\0\0\0\21\0\x6544\x6976\x6563\x5020\x7261\x6d61\x7465\x7265spd.\xffd0\xffff\x6b76\24\4\x8000\1\0\4\0\1?\x7845\x5074\x6f72\x4470\x7365\x5363\x6d65\x7061\x6f68\x6572m \xffd8\xffff\x6b76\nl\0\x7c302\a\0\1f\x6148\x6472\x6177\x6572\x44497\a\xff90\xffffUSB\Vid_0d49&Pid_7110&Rev_0203\0USB\Vid_0d49&Pid_7110\0\0\xffd8\xffff\x6b76\r\x90\0\x7cc82\a\0\1?\x6f43\x706d\x7461\x6269\x656c\x4449so\xff68\xffffUSB\Class_08&SubClass_06&Prot_50\0USB\Class_08&SubClass_06\0USB\Class_08\0\0\0\0\xffe0\xffff\x6b76\6X\0\x80202\1\0\0012\x7244\x7669\x72652\xffd8\xffff\x6b76\tN\0\x7da82\1\0\1\0\x6c43\x7361\x4773\x4955D\0\0\0\xffa8\xffff{36FC9E60-C465-11CF-8056-444553540000}\0\0\0\0\xffe0\xffff\x6b76\5\b\0\x7e202\1\0\1\0\x6c43\x7361s\0\xfff0\xffffUSB\0\0\0\xffd8\xffff\x6b76\20B\0\x82c82\1\0\0012\x614d\x6374\x6968\x676e\x6544\x6976\x6563\x6449\xff58\xffff\x6b73\0\x8c58\r\x32d85\4\0\x90\0\1\x8004t\0\x84\0\0\0\24\0\2`\3\0\x200\24?\17\x101\0\0\x500\22\0\x200\24\31\2\x101\0\0\x100\0\0\x200\30?\17\x201\0\0\x500 \0\x220\08}\0e\x4d4c\x4d45P\0\0\0\0\0\x201\0\0\x500 \0\x220\0\x101\0\0\x500\22\0\xffd8\xffff\x6b76\f\4\x8000\xe0\0\4\0\1\xf9b4\x6143\x6170\x6962\x696c\x6974\x7365\xa1ee\xa3a6\xffd8\xffff\x6b76\f\4\x8000\xe0\0\4\0\1S\x6143\x6170\x6962\x696c\x6974\x7365 D\xfff0\xffff\x686c\1\x90a82\xe918\xb548\xffa8\xffff\x6b6e P\x85e0\xabfb\x1c8\0\0\x3058\0\0\0\0\0\xffff\xffff\xffff\xffff\n\0\x83a82\x218\0\xffff\xffff\0\0\0\0 \0B\0\17\0\4\0\x3030\x3531\0\0\xffd8\xffff\x6b76\v\4\x8000\1\0\4\0\1\0\x7244\x7669\x7265\x6c46\x6761s\0\0\xffe0\xffff\x6b76\a\30\0\x80802\1\0\1\0\x6e49\x5066\x7461h\x6268\x6e69\x80002\x1000\0\0\0\0\0\0\0\0\0\0\0\xffa0\xffff{36FC9E60-C465-11CF-8056-444553540000}\0015\0\0\0\xffe0\xffffusbstor.inf\0\0\0\xffd8\xffff\x6b76\n\32\0\x80c82\1\0\1\0\x6e49\x5366\x6365\x6974\x6e6f\0\0\0\xffe0\xffffUSBSTOR_BULK\0\0\xffd8\xffff\x6b76\r\b\0\x7b602\1\0\1\0\x6e49\x5366\x6365\x6974\x6e6f\x7845t\0\xffd8\xffff\x6b76\f\24\0\x81382\1\0\1\0\x7250\x766f\x6469\x7265\x614e\x656d\0\0\xffe8\xffffMicrosoft\0\xffd8\xffff\x6b76\16\b\0\x81782\3\0\1\0\x7244\x7669\x7265\x6144\x6574\x6144\x6174\0\xfff0\xffff\x8000\xc562\x1c0\x1c1\0\0\xffe0\xffff\x6b76\3<\0\x82582\1\0\0012\x664dg\x81a82\xffd8\xffff\x6b76\n\22\0\x81d02\1\0\1\0\x7244\x7669\x7265\x6144\x6574\0\0\0\xffe8\xffff7-1-2001\0\0\xffd8\xffff\x6b76\r\26\0\x82102\1\0\1\0\x7244\x7669\x7265\x6556\x7372\x6f69n\0\xffe0\xffff5.1.2600.0\0\0\0\0\xfff0\xffff\xf18\\xf98\\x428\\xfff8\xffff\x85902\xfff0\xffff\x686c\1\x87a02\xa7bd\x3c2f\xffc0\xffffCompatible USB storage device\0\xffd8\xffff\x6b76\16F\0\x85402\1\0\0012\x6544\x6976\x6563\x6e49\x7473\x6e61\x65632\xfff8\xffff\x82982\xffb8\xffffusb\class_08&subclass_06&prot_50\0\0\xffe0\xffff\x6b76\a\20\0\x83302\1\0\1\0\x6553\x7672\x6369e\xffe8\xffffUSBSTOR\0\0\0\xffd8\xffff\x6b76\n0\0\x83702\1\0\1\0\x7244\x7669\x7265\x6544\x6373\0\0\0\xffc8\xffffUSB Mass Storage Device\0\0\0\xffd0\xffff\x7fb82\x7fe02\x80a02\x80e82\x81102\x81502\x81a82\x81e82\x7e302\x83482\0\0\xffc8\xffffUSB Mass Storage Device\0\0\0\xffc8\xffff\x6af82\x6b782\x7ae02\x0fb81\x7c082\x7ca02\x7d802\x7e002\x7d602\x81882\x83102\x6b202\0\0\xff60\xffff\x6b6e \xaf98\x9b90\x9760\x1c9\0\0\x9be8\2\1\0\0\0\x7800N\xffff\xffff\1\0\x82c02\x218\0\xffff\xffff\20\0\0\0\34\0F\0\27\0M\0\x2323\x233f\x5355\x2342\x6956\x5f64\x6430\x3934\x5026\x6469\x375f\x3131\x2330\x334c\x3744\x5847\x484e\x5f5f\x5f5f\x7b23\x3561\x6364\x6662\x3031\x362d\x3335\x2d30\x3131\x3264\x392d\x3130\x2d66\x3030\x3063\x6634\x3962\x3135\x6465}\0\xffa8\xffff\x6b6e \xaf98\x9b90\x9760\x1c9\0\0\x84482\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x82402\x218\0\xffff\xffff\20\0\0\0\30\0\x9c\0\0\0\1\0#\0\0\0\xffb0\xffffUSB\Vid_0d49&Pid_7110\L3D7GXNH____\0\0\0\0\xffd8\xffff\x6b76\f\x9c\0\x85b82\1\0\1\0\x7953\x626d\x6c6f\x6369\x694c\x6b6e\0\0\xff60\xffff\\?\USB#Vid_0d49&Pid_7110#L3D7GXNH____#{a5dcbf10-6530-11d2-901f-00c04fb951ed}\0\xffd8\xffff\x6b76\f\x9a\0\x86802\1\0\1\0\x7953\x626d\x6c6f\x6369\x614e\x656d\0\0\xff60\xffff\??\USB#Vid_0d49&Pid_7110#L3D7GXNH____#{a5dcbf10-6530-11d2-901f-00c04fb951ed}\0\xff80\xffff\x6b6e \xe7c8\x8648\xabfb\x1c8\0\0\xad50\20\1\0\0\0\x82482\xffff\xffff\0\0\xffff\xffff\xa988\r\xffff\xffff\34\0\0\0\0\0\0\0\4\0)\0\x6944\x6b73\x5626\x6e65\x4d5f\x7861\x6f74\x2672\x7250\x646f\x4f5f\x656e\x6f54\x6375\x5f68\x4949\x5226\x7665\x305f\x3332g\0\0\0\xffa0\xffff\x6b6e \x4a62\x9bcc\x9760\x1c9\0\0\x87202\2\0\0\0\x2448/\xffff\xffff\f\0\x95802\xa988\r\xffff\xffff"\0\0\0\32\0\x170\0\0\0\16\0\x334c\x3744\x5847\x484e\x5f5f\x5f5f\x3026\0\xffd8\xffff\x6b76\n\26\0\x88282\1\0\1\0\x6544\x6976\x6563\x6544\x6373\0\0\0\xffc0\xffffDisk drive\0ouch II USB Device\0\xfff8\xffff\x8de82\xffd8\xffff\x6b76\f\4\x8000\20\0\4\0\1\0\x6143\x6170\x6962\x696c\x6974\x7365\0\0\xffe0\xffff\x6b76\b\4\x8000\0\0\4\0\1\0\x4955\x754e\x626d\x7265\xffa8\xffff\x6b6e \xe7c8\x8648\xabfb\x1c8\0\0\x87a02\0\0\0\0\xffff\xffff\xffff\xffff\0\0\xffff\xffff\xa988\r\xffff\xffff\0\0\0\0\0\0\0\0\1\0\a\0\x6f4c\x4367\x6e6ff\xfff0\xffff\x1140\\x1180\\x273c\x71a2\xffd8\xffff\x6b76\n\x170\0\x89482\a\0\1\0\x6148\x6472\x6177\x6572\x4449\0\0\0\xfe88\xffffUSBSTOR\DiskMaxtor__OneTouch_II_____023g\0USBSTOR\DiskMaxtor__OneTouch_II_____\0USBSTOR\DiskMaxtor__\0USBSTOR\Maxtor__OneTouch_II_____0\0Maxtor__OneTouch_II_____0\0USBSTOR\GenDisk\0GenDisk\0\0\0\0\xffd8\xffff\x6b76\r4\0\x8ae82\a\0\1\0\x6f43\x706d\x7461\x6269\x656c\x4449s\0\xffc8\xffffUSBSTOR\Disk\0USBSTOR\RAW\0\0\xffd8\xffff\x6b76\tN\0\x8b482\1\0\1\0\x6c43\x7361\x4773\x4955D\0" scanning hidden registry entries ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 392 < Document and Settings folder & sub folders > scanning hidden files ... C:\Documents and Settings\All Users\Application Data\TEMP:4829695F 130 bytes scan completed successfully hidden files: 166 < End of report > [/code]