[code] OTS logfile created on: 11/10/2011 4:06:49 PM - Run 1 OTS by OldTimer - Version 3.1.46.0 Folder = C:\Documents and Settings\HP_Administrator\Desktop Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 55.00% Memory free 4.00 Gb Paging File | 3.00 Gb Available in Paging File | 78.00% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 289.54 Gb Total Space | 199.55 Gb Free Space | 68.92% Space Free | Partition Type: NTFS Drive D: | 8.53 Gb Total Space | 0.42 Gb Free Space | 4.93% Space Free | Partition Type: FAT32 E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: KevinsHP Current User Name: HP_Administrator Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days [Processes - Safe List] ots.exe -> C:\Documents and Settings\HP_Administrator\Desktop\OTS.exe -> [2011/11/10 15:00:52 | 000,646,144 | ---- | M] (OldTimer Tools) tomtomhomerunner.exe -> C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe -> [2011/04/22 06:21:10 | 000,247,728 | ---- | M] (TomTom) tomtomhomeservice.exe -> C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe -> [2011/04/22 06:21:10 | 000,092,592 | ---- | M] (TomTom) ccsvchst.exe -> C:\Program Files\Norton Internet Security\Engine\18.6.0.29\ccsvchst.exe -> [2011/04/16 18:45:11 | 000,130,008 | R--- | M] (Symantec Corporation) intuitupdateservice.exe -> C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe -> [2010/08/23 20:21:40 | 000,013,672 | ---- | M] (Intuit Inc.) motoconnectservice.exe -> C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe -> [2010/04/29 11:30:44 | 000,091,456 | ---- | M] () motoconnect.exe -> C:\Program Files\Motorola\MotoConnectService\MotoConnect.exe -> [2010/04/29 11:30:32 | 000,279,360 | ---- | M] (Motorola) bjmyprt.exe -> C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE -> [2009/07/26 20:10:00 | 001,983,816 | ---- | M] (CANON INC.) cnmnsut.exe -> C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe -> [2009/05/19 17:39:44 | 000,136,544 | ---- | M] (CANON INC.) mlb-nexdef-autobahn.exe -> C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Autobahn\mlb-nexdef-autobahn.exe -> [2009/04/01 15:51:34 | 000,801,032 | ---- | M] () teatimer.exe -> C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe -> [2009/03/05 15:07:20 | 002,260,480 | ---- | M] (Safer-Networking Ltd.) explorer.exe -> C:\WINDOWS\explorer.exe -> [2008/04/13 18:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) eeventmanager.exe -> C:\Program Files\epson\Creativity Suite\Event Manager\EEventManager.exe -> [2006/03/17 10:30:26 | 000,102,400 | ---- | M] (SEIKO EPSON CORPORATION) discgui.exe -> C:\Program Files\DISC\DiscGui.exe -> [2005/11/11 22:11:12 | 000,237,568 | ---- | M] (Digital Interactive Systems Corporation, Inc.) discover.exe -> C:\Program Files\DISC\DISCover.exe -> [2005/11/11 22:11:04 | 001,064,960 | ---- | M] (Digital Interactive Systems Corporation) discupdatemgr.exe -> C:\Program Files\DISC\DISCUpdateMgr.exe -> [2005/11/11 22:10:00 | 000,061,440 | ---- | M] (Digital Interactive Systems Corporation, Inc.) discstreamhub.exe -> C:\Program Files\DISC\DiscStreamHub.exe -> [2005/11/11 22:10:00 | 000,049,152 | ---- | M] (Digital Interactive Systems Corporation, Inc.) elservice.exe -> C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe -> [2005/11/08 15:51:54 | 000,180,224 | ---- | M] (Intel Corporation) dmascheduler.exe -> C:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe -> [2005/11/01 10:01:00 | 000,090,112 | ---- | M] (Sonic Solutions) iaanotif.exe -> C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe -> [2005/10/12 20:30:42 | 000,139,264 | ---- | M] (Intel Corporation) iaantmon.exe -> C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe -> [2005/10/12 20:30:24 | 000,086,140 | ---- | M] (Intel Corporation) cthelper.exe -> C:\WINDOWS\CTHELPER.EXE -> [2005/10/07 19:08:48 | 000,016,384 | ---- | M] (Creative Technology Ltd) dllml.exe -> C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe -> [2005/08/29 23:15:30 | 000,049,152 | ---- | M] (Creative Technology Ltd.) cli.exe -> C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe -> [2005/08/12 22:43:58 | 000,045,056 | ---- | M] (ATI Technologies Inc.) ctdvddet.exe -> C:\Program Files\Creative\SBAudigy4\DVDAudio\CTDVDDET.exe -> [2003/06/18 09:00:00 | 000,045,056 | ---- | M] (Creative Technology Ltd) [Modules - No Company Name] system.serviceprocess.ni.dll -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\abef85f2fb8ba830eda73e2d12e8d41e\System.ServiceProcess.ni.dll -> [2011/10/11 20:45:15 | 000,212,992 | ---- | M] () system.ni.dll -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll -> [2011/10/11 19:47:49 | 007,950,848 | ---- | M] () mscorlib.ni.dll -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll -> [2011/10/11 19:47:34 | 011,490,816 | ---- | M] () system.xml.dll -> C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll -> [2011/10/11 19:46:54 | 002,048,000 | ---- | M] () system.dll -> C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll -> [2011/10/11 19:46:53 | 003,182,592 | ---- | M] () system.data.dll -> C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll -> [2011/10/11 19:46:52 | 002,933,248 | ---- | M] () system.configuration.dll -> C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll -> [2011/10/11 19:46:52 | 000,425,984 | ---- | M] () system.drawing.dll -> C:\WINDOWS\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll -> [2011/10/11 19:46:47 | 000,626,688 | ---- | M] () system.runtime.remoting.dll -> C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll -> [2011/10/11 19:46:47 | 000,303,104 | ---- | M] () system.transactions.dll -> C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll -> [2011/10/11 19:46:46 | 000,261,632 | ---- | M] () system.enterpriseservices.dll -> C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll -> [2011/10/11 19:46:46 | 000,258,048 | ---- | M] () system.serviceprocess.dll -> C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll -> [2011/10/11 19:46:44 | 000,114,688 | ---- | M] () system.windows.forms.dll -> C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll -> [2011/10/11 19:46:40 | 005,025,792 | ---- | M] () mscorlib.dll -> c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_a87631d8\mscorlib.dll -> [2011/10/11 19:44:47 | 003,391,488 | ---- | M] () system.drawing.dll -> c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_a9ed7ac5\system.drawing.dll -> [2011/10/11 19:44:43 | 000,835,584 | ---- | M] () system.xml.dll -> c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_c14f95ef\system.xml.dll -> [2011/10/11 19:44:37 | 002,088,960 | ---- | M] () system.windows.forms.dll -> c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_2bde6bfa\system.windows.forms.dll -> [2011/10/11 19:44:32 | 003,018,752 | ---- | M] () system.dll -> c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_643a2702\system.dll -> [2011/10/11 19:44:25 | 001,966,080 | ---- | M] () system.web.dll -> c:\windows\assembly\gac\system.web\1.0.5000.0__b03f5f7f11d50a3a\system.web.dll -> [2011/10/11 19:44:17 | 001,265,664 | ---- | M] () system.dll -> c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll -> [2011/10/11 19:44:17 | 001,232,896 | ---- | M] () encdec.dll -> C:\WINDOWS\system32\encdec.dll -> [2011/02/04 17:48:32 | 000,456,192 | ---- | M] () sbe.dll -> C:\WINDOWS\system32\sbe.dll -> [2011/02/04 17:48:30 | 000,291,840 | ---- | M] () intuit.spc.map.reporter.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.Reporter\5.0.136.0__7ce6deabcb36a8ea\Intuit.Spc.Map.Reporter.dll -> [2011/01/30 09:11:32 | 000,476,520 | ---- | M] () intuit.spc.map.windowsfirewallutilities.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.WindowsFirewallUtilities\5.0.136.0__7ce6deabcb36a8ea\Intuit.Spc.Map.WindowsFirewallUtilities.dll -> [2011/01/30 09:11:32 | 000,409,960 | ---- | M] () intuit.spc.esd.winclient.api.net.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Api.Net\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Api.Net.dll -> [2011/01/30 09:11:31 | 000,421,224 | ---- | M] () intuit.spc.esd.core.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Core\3.1.26.0__540d4816ead86321\Intuit.Spc.Esd.Core.dll -> [2011/01/30 09:11:31 | 000,269,672 | ---- | M] () intuit.spc.esd.winclient.application.updateserviceplugin.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateServicePlugin\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateServicePlugin.dll -> [2011/01/30 09:11:31 | 000,046,952 | ---- | M] () intuit.spc.esd.winclient.application.updateservice.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateService\1.0.0.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateService.dll -> [2011/01/30 09:11:31 | 000,023,912 | ---- | M] () intuit.spc.esd.winclient.ipc.remoting.updateserviceworker.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateServiceWorker\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateServiceWorker.dll -> [2011/01/30 09:11:31 | 000,018,792 | ---- | M] () intuit.spc.esd.winclient.application.updateservice.plugincontract.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateService.PluginContract\1.0.0.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateService.PluginContract.dll -> [2011/01/30 09:11:31 | 000,012,136 | ---- | M] () intuit.spc.esd.client.businesslogic.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.BusinessLogic\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.Client.BusinessLogic.dll -> [2011/01/30 09:11:30 | 000,121,704 | ---- | M] () intuit.spc.esd.client.dataaccess.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.DataAccess\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.Client.DataAccess.dll -> [2011/01/30 09:11:30 | 000,120,168 | ---- | M] () intuit.spc.esd.client.common.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.Common\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.Client.Common.dll -> [2011/01/30 09:11:30 | 000,070,504 | ---- | M] () motoconnectservice.exe -> C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe -> [2010/04/29 11:30:44 | 000,091,456 | ---- | M] () quartz.dll -> C:\WINDOWS\system32\quartz.dll -> [2010/02/05 12:27:45 | 001,291,776 | ---- | M] () system.data.sqlite.dll -> C:\WINDOWS\assembly\GAC_32\System.Data.SQLite\1.0.61.0__db937bc2d44ff139\System.Data.SQLite.dll -> [2010/01/21 18:57:14 | 000,854,016 | ---- | M] () intuit.spc.map.reporter.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.Reporter\5.0.104.0__7ce6deabcb36a8ea\Intuit.Spc.Map.Reporter.dll -> [2010/01/21 18:57:13 | 000,471,040 | ---- | M] () intuit.spc.map.windowsfirewallutilities.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.WindowsFirewallUtilities\5.0.104.0__7ce6deabcb36a8ea\Intuit.Spc.Map.WindowsFirewallUtilities.dll -> [2010/01/21 18:57:13 | 000,403,456 | ---- | M] () intuit.spc.esd.winclient.application.updateserviceplugin.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateServicePlugin\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateServicePlugin.dll -> [2010/01/21 18:57:12 | 000,046,880 | ---- | M] () intuit.spc.esd.winclient.api.net.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Api.Net\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Api.Net.dll -> [2010/01/21 18:57:11 | 000,419,616 | ---- | M] () intuit.spc.esd.core.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Core\2.0.445.0__540d4816ead86321\Intuit.Spc.Esd.Core.dll -> [2010/01/21 18:57:11 | 000,270,112 | ---- | M] () intuit.spc.esd.client.businesslogic.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.BusinessLogic\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.Client.BusinessLogic.dll -> [2010/01/21 18:57:11 | 000,121,632 | ---- | M] () intuit.spc.esd.client.dataaccess.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.DataAccess\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.Client.DataAccess.dll -> [2010/01/21 18:57:11 | 000,120,096 | ---- | M] () intuit.spc.esd.client.common.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.Common\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.Client.Common.dll -> [2010/01/21 18:57:11 | 000,070,432 | ---- | M] () intuit.spc.esd.winclient.ipc.remoting.updateserviceworker.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateServiceWorker\3.0.335.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateServiceWorker.dll -> [2010/01/21 18:57:11 | 000,018,720 | ---- | M] () libwin32proxyconfig.dll -> C:\Documents and Settings\HP_Administrator\.autobahn\libwin32proxyconfig.dll -> [2009/04/03 18:20:44 | 000,065,536 | ---- | M] () swarmcast.dll -> C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Autobahn\bin\4.2.17.MLB_09_58\swarmcast.dll -> [2009/04/01 15:51:34 | 016,907,016 | ---- | M] () mlb-nexdef-autobahn.exe -> C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Autobahn\mlb-nexdef-autobahn.exe -> [2009/04/01 15:51:34 | 000,801,032 | ---- | M] () intuit.spc.esd.winclient.api.net.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Api.Net\2.1.72.12__540d4816ead86321\Intuit.Spc.Esd.WinClient.Api.Net.dll -> [2009/02/15 07:18:07 | 000,401,696 | ---- | M] () intuit.spc.esd.winclient.application.updateserviceplugin.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateServicePlugin\2.1.72.12__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateServicePlugin.dll -> [2009/02/15 07:18:07 | 000,047,392 | ---- | M] () intuit.spc.esd.winclient.ipc.remoting.updateserviceworker.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateServiceWorker\2.1.72.12__540d4816ead86321\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateServiceWorker.dll -> [2009/02/15 07:18:07 | 000,018,720 | ---- | M] () intuit.spc.esd.core.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Core\2.0.145.4__540d4816ead86321\Intuit.Spc.Esd.Core.dll -> [2009/02/15 07:18:06 | 000,238,368 | ---- | M] () intuit.spc.esd.client.businesslogic.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.BusinessLogic\2.1.72.12__540d4816ead86321\Intuit.Spc.Esd.Client.BusinessLogic.dll -> [2009/02/15 07:18:06 | 000,130,848 | ---- | M] () intuit.spc.esd.client.dataaccess.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.DataAccess\2.1.72.12__540d4816ead86321\Intuit.Spc.Esd.Client.DataAccess.dll -> [2009/02/15 07:18:06 | 000,120,608 | ---- | M] () intuit.spc.esd.client.common.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.Common\2.1.72.12__540d4816ead86321\Intuit.Spc.Esd.Client.Common.dll -> [2009/02/15 07:18:06 | 000,072,992 | ---- | M] () intuit.spc.map.windowsfirewallutilities.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.WindowsFirewallUtilities\4.0.114.0__7ce6deabcb36a8ea\Intuit.Spc.Map.WindowsFirewallUtilities.dll -> [2009/01/04 17:43:55 | 001,058,304 | ---- | M] () intuit.spc.map.reporter.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.Reporter\4.0.114.0__7ce6deabcb36a8ea\Intuit.Spc.Map.Reporter.dll -> [2009/01/04 17:43:54 | 000,471,040 | ---- | M] () system.data.sqlite.dll -> C:\WINDOWS\assembly\GAC_32\System.Data.SQLite\1.0.56.0__28c9bcd4dddc48a1\System.Data.SQLite.dll -> [2009/01/04 17:40:44 | 000,755,712 | ---- | M] () log4net.dll -> C:\WINDOWS\assembly\GAC_MSIL\log4net\1.2.10.0__1b44e1d426115821\log4net.dll -> [2009/01/04 17:40:43 | 000,270,336 | ---- | M] () intuit.spc.foundations.portability.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Foundations.Portability\3.1.2.2__540d4816ead86321\Intuit.Spc.Foundations.Portability.dll -> [2009/01/04 17:40:42 | 000,458,752 | ---- | M] () intuit.spc.foundations.primary.config.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Foundations.Primary.Config\3.1.2.2__540d4816ead86321\Intuit.Spc.Foundations.Primary.Config.dll -> [2009/01/04 17:40:41 | 000,073,728 | ---- | M] () intuit.spc.foundations.primary.exceptionhandling.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Foundations.Primary.ExceptionHandling\3.1.2.2__540d4816ead86321\Intuit.Spc.Foundations.Primary.ExceptionHandling.dll -> [2009/01/04 17:40:41 | 000,065,536 | ---- | M] () intuit.spc.foundations.primary.logging.dll -> C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Foundations.Primary.Logging\3.1.2.2__540d4816ead86321\Intuit.Spc.Foundations.Primary.Logging.dll -> [2009/01/04 17:40:41 | 000,045,056 | ---- | M] () msdmo.dll -> C:\WINDOWS\system32\msdmo.dll -> [2008/04/13 18:11:59 | 000,014,336 | ---- | M] () devenum.dll -> C:\WINDOWS\system32\devenum.dll -> [2008/04/13 18:11:51 | 000,059,904 | ---- | M] () system.xml.dll -> c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll -> [2006/05/17 22:02:55 | 001,339,392 | ---- | M] () system.management.dll -> c:\windows\assembly\gac\system.management\1.0.5000.0__b03f5f7f11d50a3a\system.management.dll -> [2006/05/17 22:02:55 | 000,372,736 | ---- | M] () system.runtime.remoting.dll -> c:\windows\assembly\gac\system.runtime.remoting\1.0.5000.0__b77a5c561934e089\system.runtime.remoting.dll -> [2006/05/17 22:02:55 | 000,323,584 | ---- | M] () system.windows.forms.dll -> c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll -> [2006/05/17 22:02:54 | 002,052,096 | ---- | M] () system.web.services.dll -> c:\windows\assembly\gac\system.web.services\1.0.5000.0__b03f5f7f11d50a3a\system.web.services.dll -> [2006/05/17 22:02:54 | 000,573,440 | ---- | M] () system.drawing.dll -> c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll -> [2006/05/17 22:02:54 | 000,466,944 | ---- | M] () microsoft.visualbasic.dll -> c:\windows\assembly\gac\microsoft.visualbasic\7.0.5000.0__b03f5f7f11d50a3a\microsoft.visualbasic.dll -> [2006/05/17 22:02:54 | 000,299,008 | ---- | M] () hpqutil.dll -> c:\Program Files\HP\Digital Imaging\bin\HpqUtil.dll -> [2005/09/16 08:33:56 | 000,204,800 | ---- | M] () vbicodec.ax -> C:\WINDOWS\system32\VBICodec.ax -> [2005/08/05 22:01:54 | 000,159,744 | ---- | M] () mpg2splt.ax -> C:\WINDOWS\system32\mpg2splt.ax -> [2005/08/05 21:06:50 | 000,165,376 | ---- | M] () pihook.dll -> C:\Program Files\ArcSoft\PhotoImpression 5\Share\PIHook.dll -> [2005/06/28 13:59:48 | 000,053,248 | ---- | M] () [Win32 Services - Safe List] (TomTomHOMEService) TomTomHOMEService [Auto | Running] -> C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe -> [2011/04/22 06:21:10 | 000,092,592 | ---- | M] (TomTom) (NIS) Norton Internet Security [Unknown | Running] -> C:\Program Files\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe -> [2011/04/16 18:45:11 | 000,130,008 | R--- | M] (Symantec Corporation) (IntuitUpdateService) Intuit Update Service [Auto | Running] -> C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe -> [2010/08/23 20:21:40 | 000,013,672 | ---- | M] (Intuit Inc.) (MotoConnect Service) MotoConnect Service [Auto | Running] -> C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe -> [2010/04/29 11:30:44 | 000,091,456 | ---- | M] () (ELService) Intel® Quick Resume Technology Drivers [Auto | Running] -> C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe -> [2005/11/08 15:51:54 | 000,180,224 | ---- | M] (Intel Corporation) (IAANTMon) Intel(R) Matrix Storage Event Monitor [Auto | Running] -> C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe -> [2005/10/12 20:30:24 | 000,086,140 | ---- | M] (Intel Corporation) (Pml Driver HPZ12) Pml Driver HPZ12 [Boot | Stopped] -> C:\WINDOWS\system32\HPZipm12.exe -> [2004/09/29 20:14:36 | 000,069,632 | ---- | M] (HP) [Driver Services - Safe List] (eeCtrl) Symantec Eraser Control driver [Kernel | System | Running] -> C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -> [2011/11/09 01:49:53 | 000,374,392 | ---- | M] (Symantec Corporation) (EraserUtilRebootDrv) EraserUtilRebootDrv [Kernel | On_Demand | Running] -> C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -> [2011/11/09 01:49:53 | 000,106,104 | ---- | M] (Symantec Corporation) (NAVEX15) NAVEX15 [Kernel | On_Demand | Running] -> C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20111110.002\NAVEX15.SYS -> [2011/10/30 18:34:21 | 001,576,312 | ---- | M] (Symantec Corporation) (NAVENG) NAVENG [Kernel | On_Demand | Running] -> C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20111110.002\NAVENG.SYS -> [2011/10/30 18:34:21 | 000,086,136 | ---- | M] (Symantec Corporation) (BHDrvx86) BHDrvx86 [Kernel | System | Running] -> C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20111027.001\BHDrvx86.sys -> [2011/10/14 17:10:08 | 000,818,808 | ---- | M] (Symantec Corporation) (IDSxpx86) IDSxpx86 [Kernel | On_Demand | Running] -> C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20111109.030\IDSXpx86.sys -> [2011/08/22 23:17:32 | 000,356,280 | ---- | M] (Symantec Corporation) (SymEvent) SymEvent [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\SYMEVENT.SYS -> [2011/05/02 16:07:06 | 000,126,584 | ---- | M] (Symantec Corporation) (SRTSP) Symantec Real Time Storage Protection [File_System | On_Demand | Running] -> C:\WINDOWS\System32\Drivers\NIS\1206000.01D\SRTSP.SYS -> [2011/03/30 21:00:09 | 000,516,216 | ---- | M] (Symantec Corporation) (SRTSPX) Symantec Real Time Storage Protection (PEL) [Kernel | System | Running] -> C:\WINDOWS\system32\drivers\NIS\1206000.01D\SRTSPX.SYS -> [2011/03/30 21:00:09 | 000,050,168 | ---- | M] (Symantec Corporation) (SYMTDI) Symantec Network Dispatch Driver [Kernel | System | Running] -> C:\WINDOWS\System32\Drivers\NIS\1206000.01D\SYMTDI.SYS -> [2011/03/21 18:39:49 | 000,369,784 | ---- | M] (Symantec Corporation) (SymEFA) Symantec Extended File Attributes [File_System | Boot | Running] -> C:\WINDOWS\system32\drivers\NIS\1206000.01D\SYMEFA.SYS -> [2011/03/14 20:31:23 | 000,744,568 | ---- | M] (Symantec Corporation) (SymDS) Symantec Data Store [Kernel | Boot | Running] -> C:\WINDOWS\system32\drivers\NIS\1206000.01D\SYMDS.SYS -> [2011/01/27 00:47:10 | 000,340,088 | ---- | M] (Symantec Corporation) (SymIRON) Symantec Iron Driver [Kernel | System | Running] -> C:\WINDOWS\system32\drivers\NIS\1206000.01D\Ironx86.SYS -> [2011/01/26 23:07:05 | 000,136,312 | ---- | M] (Symantec Corporation) (BVRPMPR5) BVRPMPR5 NDIS Protocol Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\BVRPMPR5.SYS -> [2010/02/17 18:17:38 | 000,049,904 | R--- | M] (Avanquest Software) (motusbdevice) Motorola USB Dev Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\motusbdevice.sys -> [2010/01/25 19:56:44 | 000,009,472 | ---- | M] (Motorola Inc) (IrBus) Infrared bus filter driver for eHome remote controls [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\irbus.sys -> [2008/04/13 12:45:34 | 000,046,592 | ---- | M] (Microsoft Corporation) (CXFALCON) Conexant Falcon II NTSC Video Capture [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\cxfalcon.sys -> [2006/02/09 12:34:42 | 000,080,384 | ---- | M] (Conexant Systems, Inc.) (ati2mtag) ati2mtag [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\ati2mtag.sys -> [2006/01/10 19:54:00 | 001,421,312 | ---- | M] (ATI Technologies Inc.) (ELacpi) ELacpi [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\ELacpi.sys -> [2005/11/08 15:51:40 | 000,007,808 | ---- | M] (Intel Corporation) (ELmon) ELmon [Kernel | System | Running] -> C:\WINDOWS\system32\drivers\ELmon.sys -> [2005/11/08 15:51:38 | 000,007,040 | ---- | M] (Intel Corporation) (ELkbd) ELkbd [Kernel | System | Running] -> C:\WINDOWS\system32\drivers\ELkbd.sys -> [2005/11/08 15:51:22 | 000,006,912 | ---- | M] (Intel Corporation) (ELmou) ELmou [Kernel | System | Running] -> C:\WINDOWS\system32\drivers\ELmou.sys -> [2005/11/08 15:51:20 | 000,006,400 | ---- | M] (Intel Corporation) (ELhid) ELhid [Kernel | System | Running] -> C:\WINDOWS\system32\drivers\ELhid.sys -> [2005/11/08 15:51:18 | 000,010,112 | ---- | M] (Intel Corporation) (ctprxy2k) Creative Proxy Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\ctprxy2k.sys -> [2005/10/07 18:55:04 | 000,007,168 | ---- | M] (Creative Technology Ltd) (ctaud2k) Creative Audio Driver (WDM) [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\ctaud2k.sys -> [2005/10/07 18:55:00 | 000,438,784 | ---- | M] (Creative Technology Ltd) (hap17v2k) Creative P17V HAL Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\haP17v2k.sys -> [2005/10/07 18:53:42 | 000,178,688 | ---- | M] (Creative Technology Ltd) (hap16v2k) Creative P16V HAL Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\haP16v2k.sys -> [2005/10/07 18:53:36 | 000,153,088 | ---- | M] (Creative Technology Ltd) (ha10kx2k) Creative Hardware Abstract Layer Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\ha10kx2k.sys -> [2005/10/07 18:53:28 | 000,751,616 | ---- | M] (Creative Technology Ltd) (ossrv) Creative OS Services Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\ctoss2k.sys -> [2005/10/07 18:53:04 | 000,114,688 | ---- | M] (Creative Technology Ltd.) (ctsfm2k) Creative SoundFont Management Device Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\ctsfm2k.sys -> [2005/10/07 18:52:40 | 000,142,336 | ---- | M] (Creative Technology Ltd) (emupia) E-mu Plug-in Architecture Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\emupia2k.sys -> [2005/10/07 18:52:32 | 000,077,824 | ---- | M] (Creative Technology Ltd) (ctac32k) Creative AC3 Software Decoder [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\ctac32k.sys -> [2005/10/07 18:52:20 | 000,501,760 | ---- | M] (Creative Technology Ltd) (ctdvda2k) Creative DVD-Audio Device Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\ctdvda2k.sys -> [2005/07/13 18:18:48 | 000,340,704 | ---- | M] (Creative Technology Ltd) (ftsata2) ftsata2 [Kernel | Boot | Running] -> C:\WINDOWS\system32\DRIVERS\ftsata2.sys -> [2005/06/29 18:03:18 | 000,175,104 | ---- | M] (Promise Technology, Inc.) (Afc) PPdus ASPI Shell [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\afc.sys -> [2005/02/23 14:58:56 | 000,011,776 | ---- | M] (Arcsoft, Inc.) (rtl8139) Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\RTL8139.sys -> [2004/08/03 15:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) (bb-run) Promise driver accelerator [Kernel | Boot | Running] -> C:\WINDOWS\system32\DRIVERS\bb-run.sys -> [2003/11/05 08:45:12 | 000,017,408 | ---- | M] (Promise Technology, Inc.) [Registry - Safe List] < Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop -> < Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> HKEY_CURRENT_USER\: Main\\"Default_Page_URL" -> http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop -> HKEY_CURRENT_USER\: Main\\"Default_Search_URL" -> http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop -> HKEY_CURRENT_USER\: Main\\"Search Page" -> http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop -> HKEY_CURRENT_USER\: Main\\"Start Page" -> http://www.yahoo.com/ -> HKEY_CURRENT_USER\: "ProxyEnable" -> 0 -> < FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla HKLM\software\mozilla\Firefox\extensions -> -> HKLM\software\mozilla\Firefox\extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB} -> C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPLGN\ [C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPLGN\] -> [2011/09/28 04:55:49 | 000,000,000 | ---D | M] HKLM\software\mozilla\Firefox\extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62} -> C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn_2011_7_3_6 [C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\COFFPLGN_2011_7_3_6] -> [2011/11/10 14:13:24 | 000,000,000 | ---D | M] HKLM\software\mozilla\Netscape Browser 8.0.3.4\Extensions -> -> HKLM\software\mozilla\Netscape Browser 8.0.3.4\Extensions\\Components -> C:\Program Files\Netscape\Netscape Browser\components [C:\PROGRAM FILES\NETSCAPE\NETSCAPE BROWSER\COMPONENTS] -> [2009/02/18 19:36:51 | 000,000,000 | ---D | M] HKLM\software\mozilla\Netscape Browser 8.0.3.4\Extensions\\Plugins -> C:\Program Files\Netscape\Netscape Browser\plugins [C:\PROGRAM FILES\NETSCAPE\NETSCAPE BROWSER\PLUGINS] -> [2009/03/14 17:34:50 | 000,000,000 | ---D | M] < FireFox Extensions [User Folders] > -> -> C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Extensions -> [2011/02/05 15:02:29 | 000,000,000 | ---D | M] -> C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Extensions\home2@tomtom.com -> [2011/02/05 15:02:29 | 000,000,000 | ---D | M] < HOSTS File > ([2011/11/01 16:26:07 | 000,000,098 | ---- | M] - 2 lines) -> C:\WINDOWS\system32\drivers\etc\Hosts -> Reset Hosts 127.0.0.1 localhost ::1 localhost < BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [AcroIEHlprObj Class] -> [2004/12/14 09:56:50 | 000,063,136 | ---- | M] (Adobe Systems Incorporated) {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} [HKLM] -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [Canon Easy-WebPrint EX BHO] -> [2010/06/28 18:55:24 | 000,202,144 | ---- | M] (CANON INC.) {53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [Spybot-S&D IE Protection] -> [2008/09/15 14:25:44 | 001,562,960 | RHS- | M] (Safer Networking Limited) {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} [HKLM] -> C:\Program Files\Norton Internet Security\Engine\18.6.0.29\coieplg.dll [Symantec NCO BHO] -> [2011/04/28 16:33:29 | 000,436,152 | R--- | M] (Symantec Corporation) {6D53EC84-6AAE-4787-AEEE-F4628F01010C} [HKLM] -> C:\Program Files\Norton Internet Security\Engine\18.6.0.29\ips\ipsbho.dll [Symantec Intrusion Prevention] -> [2011/03/30 21:01:20 | 000,210,872 | R--- | M] (Symantec Corporation) {AA58ED58-01DD-4d91-8333-CF10577473F7} [HKLM] -> c:\Program Files\Google\GoogleToolbar1.dll [Google Toolbar Helper] -> [2006/05/17 22:55:16 | 001,157,120 | R--- | M] (Google Inc.) < Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" [HKLM] -> c:\Program Files\Google\GoogleToolbar1.dll [&Google] -> [2006/05/17 22:55:16 | 001,157,120 | R--- | M] (Google Inc.) "{759D9886-0C6F-4498-BAB6-4A5F47C6C72F}" [HKLM] -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [Canon Easy-WebPrint EX] -> [2010/06/28 18:56:50 | 001,615,256 | ---- | M] (CANON INC.) "{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" [HKLM] -> C:\Program Files\Norton Internet Security\Engine\18.6.0.29\coieplg.dll [Norton Toolbar] -> [2011/04/28 16:33:29 | 000,436,152 | R--- | M] (Symantec Corporation) < Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> ShellBrowser\\"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" [HKLM] -> C:\Program Files\Norton Internet Security\Engine\18.6.0.29\coieplg.dll [Norton Toolbar] -> [2011/04/28 16:33:29 | 000,436,152 | R--- | M] (Symantec Corporation) WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> c:\Program Files\Google\GoogleToolbar1.dll [&Google] -> [2006/05/17 22:55:16 | 001,157,120 | R--- | M] (Google Inc.) WebBrowser\\"{759D9886-0C6F-4498-BAB6-4A5F47C6C72F}" [HKLM] -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [Canon Easy-WebPrint EX] -> [2010/06/28 18:56:50 | 001,615,256 | ---- | M] (CANON INC.) WebBrowser\\"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" [HKLM] -> C:\Program Files\Norton Internet Security\Engine\18.6.0.29\coieplg.dll [Norton Toolbar] -> [2011/04/28 16:33:29 | 000,436,152 | R--- | M] (Symantec Corporation) < Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "ATICCC" -> C:\Program Files\ATI Technologies\ATI.ACE\cli.exe ["C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay] -> [2005/08/12 22:43:58 | 000,045,056 | ---- | M] (ATI Technologies Inc.) "AudioDrvEmulator" -> C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe ["C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"] -> [2005/08/29 23:15:30 | 000,049,152 | ---- | M] (Creative Technology Ltd.) "CanonMyPrinter" -> C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon] -> [2009/07/26 20:10:00 | 001,983,816 | ---- | M] (CANON INC.) "CanonSolutionMenu" -> C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon] -> [2009/03/17 19:40:00 | 000,767,312 | ---- | M] (CANON INC.) "CTDVDDET" -> C:\Program Files\Creative\SBAudigy4\DVDAudio\CTDVDDET.EXE ["C:\Program Files\Creative\SBAudigy4\DVDAudio\CTDVDDET.EXE"] -> [2003/06/18 09:00:00 | 000,045,056 | ---- | M] (Creative Technology Ltd) "CTHelper" -> C:\WINDOWS\CTHELPER.EXE [CTHELPER.EXE] -> [2005/10/07 19:08:48 | 000,016,384 | ---- | M] (Creative Technology Ltd) "CTSysVol" -> C:\Program Files\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe [C:\Program Files\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe /r] -> [2005/09/15 17:47:22 | 000,057,344 | ---- | M] (Creative Technology Ltd) "DISCover" -> C:\Program Files\DISC\DISCover.exe [C:\Program Files\DISC\DISCover.exe] -> [2005/11/11 22:11:04 | 001,064,960 | ---- | M] (Digital Interactive Systems Corporation) "DiscUpdateManager" -> C:\Program Files\DISC\DISCUpdateMgr.exe [C:\Program Files\DISC\DiscUpdateMgr.exe] -> [2005/11/11 22:10:00 | 000,061,440 | ---- | M] (Digital Interactive Systems Corporation, Inc.) "DMAScheduler" -> c:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe [c:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe] -> [2005/11/01 10:01:00 | 000,090,112 | ---- | M] (Sonic Solutions) "EEventManager" -> C:\Program Files\epson\Creativity Suite\Event Manager\EEventManager.exe [C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe] -> [2006/03/17 10:30:26 | 000,102,400 | ---- | M] (SEIKO EPSON CORPORATION) "HPBootOp" -> C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe ["C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run] -> [2005/11/09 18:29:16 | 000,249,856 | ---- | M] (Hewlett-Packard Company) "HPHUPD08" -> c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe [c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe] -> [2005/06/02 00:35:56 | 000,049,152 | ---- | M] (Hewlett-Packard) "IAAnotif" -> C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe [C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe] -> [2005/10/12 20:30:42 | 000,139,264 | ---- | M] (Intel Corporation) "IJNetworkScanUtility" -> C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe [C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe] -> [2009/05/19 17:39:44 | 000,136,544 | ---- | M] (CANON INC.) "Recguard" -> C:\WINDOWS\SMINST\Recguard.exe [C:\WINDOWS\SMINST\RECGUARD.EXE] -> [2005/07/22 23:14:00 | 000,237,568 | ---- | M] () "TkBellExe" -> C:\Program Files\Common Files\Real\Update_OB\realsched.exe ["C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot] -> [2006/05/17 22:35:25 | 000,180,269 | ---- | M] (RealNetworks, Inc.) "UpdReg" -> C:\WINDOWS\Updreg.EXE [C:\WINDOWS\UpdReg.EXE] -> [2000/05/11 09:00:00 | 000,090,112 | ---- | M] (Creative Technology Ltd.) < Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "SpybotSD TeaTimer" -> C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe] -> [2009/03/05 15:07:20 | 002,260,480 | ---- | M] (Safer-Networking Ltd.) "TomTomHOME.exe" -> C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe ["C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe" -s] -> [2011/04/22 06:21:10 | 000,247,728 | ---- | M] (TomTom) < All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> < HP_Administrator Startup Folder > -> C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup -> C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup\MLB.TV NexDef Plug-in.lnk -> C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Autobahn\mlb-nexdef-autobahn.exe -> [2009/04/01 15:51:34 | 000,801,032 | ---- | M] () < CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoCDBurning" -> [0] -> File not found < CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System \\"InstallVisualStyle" -> C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles [C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles] -> [2004/08/10 03:39:00 | 001,347,728 | ---- | M] (Microsoft) \\"InstallTheme" -> C:\WINDOWS\Resources\Themes\Royale.Theme [C:\WINDOWS\Resources\Themes\Royale.theme] -> [2004/07/28 02:03:28 | 000,001,293 | ---- | M] () \\"DisableStatusMessages" -> [0] -> File not found < CurrentVersion Policy Settings - Explorer [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [149] -> File not found \\"NoDriveAutoRun" -> [0] -> File not found < CurrentVersion Policy Settings - System [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System < Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> &Google Search -> C:\Program Files\Google\GoogleToolbar1.dll [res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html] -> [2006/05/17 22:55:16 | 001,157,120 | R--- | M] (Google Inc.) &Translate English Word -> C:\Program Files\Google\GoogleToolbar1.dll [res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html] -> [2006/05/17 22:55:16 | 001,157,120 | R--- | M] (Google Inc.) Backward Links -> C:\Program Files\Google\GoogleToolbar1.dll [res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html] -> [2006/05/17 22:55:16 | 001,157,120 | R--- | M] (Google Inc.) Cached Snapshot of Page -> C:\Program Files\Google\GoogleToolbar1.dll [res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html] -> [2006/05/17 22:55:16 | 001,157,120 | R--- | M] (Google Inc.) Similar Pages -> C:\Program Files\Google\GoogleToolbar1.dll [res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html] -> [2006/05/17 22:55:16 | 001,157,120 | R--- | M] (Google Inc.) Translate Page into English -> C:\Program Files\Google\GoogleToolbar1.dll [res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html] -> [2006/05/17 22:55:16 | 001,157,120 | R--- | M] (Google Inc.) < Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}:{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [Menu: Spybot - Search & Destroy Configuration] -> [2008/09/15 14:25:44 | 001,562,960 | RHS- | M] (Safer Networking Limited) {E2D4D26B-0180-43a4-B05F-462D6D54C789}:C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm [HKLM] -> C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm [Button: Internet Connection Help] -> [2009/01/12 19:13:37 | 000,000,706 | ---- | M] () {E2D4D26B-0180-43a4-B05F-462D6D54C789}:C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm [HKLM] -> C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm [Menu: Internet Connection Help] -> [2009/01/12 19:13:37 | 000,000,706 | ---- | M] () < Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> [Reg Error: Value error.] -> File not found CmdMapping\\"{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}" [HKLM] -> C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [Spybot - Search & Destroy Configuration] -> [2008/09/15 14:25:44 | 001,562,960 | RHS- | M] (Safer Networking Limited) CmdMapping\\"{E2D4D26B-0180-43a4-B05F-462D6D54C789}" [HKLM] -> [Internet Connection Help] -> File not found < Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> < Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix "" -> http:// < Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 5447 domain(s) found. -> < Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 36 range(s) found. -> < Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 9103 domain(s) found. -> ttlc_intuit.com [https] -> Trusted sites -> < Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 36 range(s) found. -> < Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> {406B5949-7190-4245-91A9-30A17DE16AD0} [HKLM] -> http://photo1.walgreens.com/WalgreensActivia.cab [Snapfish Activia] -> {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} [HKLM] -> http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1231807218359 [MUWebControl Class] -> {6F15128C-E66A-490C-B848-5000B5ABEEAC} [HKLM] -> https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab [HP Download Manager] -> {8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> Reg Error: Value error. [Reg Error: Key error.] -> {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} [HKLM] -> Reg Error: Value error. [Reg Error: Key error.] -> {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab [Java Plug-in 1.6.0_29] -> {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> Reg Error: Value error. [Reg Error: Key error.] -> < Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ -> DhcpNameServer -> 192.168.1.1 -> < Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> {56B24BDD-4107-4A0D-BD26-51A438C6C3B6}\\DhcpNameServer -> 192.168.1.1 (Intel(R) PRO/100 VE Network Connection) -> {892900FC-9814-4488-99C0-81491C1EE93D}\\DhcpNameServer -> 16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243 (HP EN1207D-TX PCI 10/100 Fast Ethernet Adapter) -> < Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> *Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell -> Explorer.exe -> C:\WINDOWS\explorer.exe -> [2008/04/13 18:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) *MultiFile Done* -> -> *UserInit* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit -> C:\WINDOWS\system32\userinit.exe -> C:\WINDOWS\system32\userinit.exe -> [2008/04/13 18:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) *MultiFile Done* -> -> < Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> AtiExtEvent -> C:\WINDOWS\System32\ati2evxx.dll -> [2006/01/10 19:49:00 | 000,061,440 | ---- | M] (ATI Technologies Inc.) < ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks -> "{56F9679E-7826-4C84-81F3-532071A8BCC5}" [HKLM] -> C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll [] -> [2009/05/24 21:41:34 | 000,304,128 | ---- | M] (Microsoft Corporation) < Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List -> "C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe" -> C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe [C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP] -> [2006/05/17 22:48:01 | 000,036,903 | ---- | M] (Hewlett-Packard) < Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List -> "C:\Documents and Settings\HP_Administrator\Desktop\WS_FTP95.exe" -> [C:\Documents and Settings\HP_Administrator\Desktop\WS_FTP95.exe:*:Enabled:WS_FTP 95] -> File not found "C:\Documents and Settings\HP_Administrator\Local Settings\Temp\7zS45.tmp\SymNRT.exe" -> [C:\Documents and Settings\HP_Administrator\Local Settings\Temp\7zS45.tmp\SymNRT.exe:*:Enabled:Norton Removal Tool] -> File not found "C:\Documents and Settings\HP_Administrator\My Documents\Batke\WS_FTP95.exe" -> C:\Documents and Settings\HP_Administrator\My Documents\Batke\WS_FTP95.exe [C:\Documents and Settings\HP_Administrator\My Documents\Batke\WS_FTP95.exe:*:Enabled:WS_FTP 95] -> [1998/11/21 10:42:30 | 000,360,448 | ---- | M] (Ipswitch, Inc. 81 Hartwell Ave. Lexington, MA 02173) "C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" -> C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server] -> [2010/08/23 20:21:40 | 000,013,672 | ---- | M] (Intuit Inc.) "C:\Program Files\DISC\DISCover.exe" -> C:\Program Files\DISC\DISCover.exe [C:\Program Files\DISC\DISCover.exe:*:Enabled:DISCover Drop & Play System] -> [2005/11/11 22:11:04 | 001,064,960 | ---- | M] (Digital Interactive Systems Corporation) "C:\Program Files\DISC\DiscStreamHub.exe" -> C:\Program Files\DISC\DiscStreamHub.exe [C:\Program Files\DISC\DiscStreamHub.exe:*:Enabled:DISCover Stream Hub] -> [2005/11/11 22:10:00 | 000,049,152 | ---- | M] (Digital Interactive Systems Corporation, Inc.) "C:\Program Files\DISC\myFTP.exe" -> C:\Program Files\DISC\myFTP.exe [C:\Program Files\DISC\myFTP.exe:*:Enabled:DISCover FTP] -> [2005/11/11 22:09:52 | 000,090,112 | ---- | M] (Digital Interactive Systems Corporation, Inc.) "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -> [C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink] -> File not found "C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" -> C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe [C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe] -> [2005/05/11 05:34:02 | 000,151,635 | ---- | M] (Hewlett-Packard) "C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" -> C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe [C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe] -> [2005/06/03 18:06:04 | 000,057,344 | ---- | M] (Hewlett-Packard Co.) "C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" -> C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe [C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe] -> [2005/06/03 17:50:00 | 000,225,280 | ---- | M] (Hewlett-Packard Co.) "C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" -> C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe [C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe] -> [2005/06/03 17:50:14 | 000,040,960 | ---- | M] (Hewlett-Packard Co.) "C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" -> C:\Program Files\HP\Digital Imaging\bin\hposid01.exe [C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe] -> [2005/06/03 17:45:46 | 000,081,920 | ---- | M] (Hewlett-Packard Co.) "C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" -> C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe [C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe] -> [2005/06/03 18:12:34 | 000,172,032 | ---- | M] (Hewlett-Packard Co.) "C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" -> C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe [C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe] -> [2005/06/03 17:51:06 | 000,458,752 | ---- | M] (Hewlett-Packard Co.) "C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" -> C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe [C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe] -> [2005/09/16 08:34:18 | 000,733,184 | ---- | M] ( ) "C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" -> C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe [C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe] -> [2005/09/16 08:29:38 | 000,421,888 | ---- | M] () "C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe" -> C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe [C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP] -> [2006/05/17 22:48:01 | 000,036,903 | ---- | M] (Hewlett-Packard) "C:\WINDOWS\LMI42.tmp\lmi_rescue.exe" -> [C:\WINDOWS\LMI42.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue] -> File not found < SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot -> < CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom -> "AutoRun" -> 1 -> "DisplayName" -> CD-ROM Driver -> "ImagePath" -> [system32\DRIVERS\cdrom.sys] -> File not found < Drives with AutoRun files > -> -> C:\AUTOEXEC.BAT [PATH=%PATH%;C:\PROGRA~1\COMMON~1\MUVEET~1\030625 | PATH=%PATH%;C:\PROGRA~1\COMMON~1\MUVEET~1\030625 | ] -> C:\AUTOEXEC.BAT [ NTFS ] -> [2006/05/17 22:45:12 | 000,000,100 | ---- | M] () D:\AUTOEXEC.BAT [] -> D:\AUTOEXEC.BAT [ FAT32 ] -> [2001/07/27 15:07:38 | 000,000,000 | -HS- | M] () D:\Autorun.inf [[AUTORUN] | ShellExecute=Info.exe protect.ed 480 480 | ] -> D:\Autorun.inf [ FAT32 ] -> [2004/04/30 07:01:14 | 000,000,053 | -HS- | M] () < MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 -> \{193d48fd-34c2-11e0-8c6b-001731358cb9} HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{193d48fd-34c2-11e0-8c6b-001731358cb9}\Shell \{193d48fd-34c2-11e0-8c6b-001731358cb9}\Shell\\"" -> [AutoRun] -> File not found HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{193d48fd-34c2-11e0-8c6b-001731358cb9}\Shell\AutoRun \{193d48fd-34c2-11e0-8c6b-001731358cb9}\Shell\AutoRun\\"" -> [Auto&Play] -> File not found HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{193d48fd-34c2-11e0-8c6b-001731358cb9}\Shell\AutoRun\command \{193d48fd-34c2-11e0-8c6b-001731358cb9}\Shell\AutoRun\command\\"" -> [J:\setup.exe -a] -> File not found \{6c4b9426-e64a-11dd-87c5-001731358cb9} HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6c4b9426-e64a-11dd-87c5-001731358cb9}\Shell \{6c4b9426-e64a-11dd-87c5-001731358cb9}\Shell\\"" -> [AutoRun] -> File not found HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6c4b9426-e64a-11dd-87c5-001731358cb9}\Shell\AutoRun \{6c4b9426-e64a-11dd-87c5-001731358cb9}\Shell\AutoRun\\"" -> [Auto&Play] -> File not found HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6c4b9426-e64a-11dd-87c5-001731358cb9}\Shell\AutoRun\command \{6c4b9426-e64a-11dd-87c5-001731358cb9}\Shell\AutoRun\command\\"" -> [J:\LaunchU3.exe -a] -> File not found < Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command -> comfile [open] -> "%1" %* -> exefile [open] -> "%1" %* -> < File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\ -> .com [@ = comfile] -> "%1" %* -> .exe [@ = exefile] -> "%1" %* -> [Files/Folders - Created Within 30 Days] OTS.exe -> C:\Documents and Settings\HP_Administrator\Desktop\OTS.exe -> [2011/11/10 15:00:51 | 000,646,144 | ---- | C] (OldTimer Tools) LastGood -> C:\WINDOWS\LastGood -> [2011/11/10 14:15:44 | 000,000,000 | ---D | C] javaws.exe -> C:\WINDOWS\System32\javaws.exe -> [2011/10/27 17:35:06 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) javaw.exe -> C:\WINDOWS\System32\javaw.exe -> [2011/10/27 17:35:06 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) java.exe -> C:\WINDOWS\System32\java.exe -> [2011/10/27 17:35:06 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) javacpl.cpl -> C:\WINDOWS\System32\javacpl.cpl -> [2011/10/27 17:35:06 | 000,073,728 | ---- | C] (Sun Microsystems, Inc.) Fantasy -> C:\Documents and Settings\HP_Administrator\My Documents\Fantasy -> [2011/10/24 19:40:15 | 000,000,000 | ---D | C] rsit -> C:\rsit -> [2011/10/19 18:02:26 | 000,000,000 | ---D | C] appmgmt -> C:\WINDOWS\System32\appmgmt -> [2011/10/12 16:12:17 | 000,000,000 | ---D | C] temp -> C:\temp -> [2011/10/12 05:16:07 | 000,000,000 | ---D | C] My Received Files -> C:\Documents and Settings\HP_Administrator\My Documents\My Received Files -> [2011/10/11 20:08:47 | 000,000,000 | ---D | C] KILLAPPS.EXE -> C:\WINDOWS\System32\KILLAPPS.EXE -> [2006/05/17 22:21:11 | 000,009,216 | ---- | C] ( ) a3d.dll -> C:\WINDOWS\System32\a3d.dll -> [2006/05/17 22:21:10 | 000,033,792 | ---- | C] ( ) RandFont.dll -> C:\WINDOWS\Fonts\RandFont.dll -> [2005/09/24 08:49:16 | 000,012,288 | ---- | C] (Hewlett-Packard Development Company, L.P.) [Files/Folders - Modified Within 30 Days] OTS.exe -> C:\Documents and Settings\HP_Administrator\Desktop\OTS.exe -> [2011/11/10 15:00:52 | 000,646,144 | ---- | M] (OldTimer Tools) Microsoft Office Outlook 2007.lnk -> C:\Documents and Settings\HP_Administrator\Desktop\Microsoft Office Outlook 2007.lnk -> [2011/11/10 14:18:25 | 000,002,521 | ---- | M] () User_Feed_Synchronization-{5B1B9478-2A4E-410F-B47F-49AF2B1CEA41}.job -> C:\WINDOWS\tasks\User_Feed_Synchronization-{5B1B9478-2A4E-410F-B47F-49AF2B1CEA41}.job -> [2011/11/10 14:18:17 | 000,000,444 | -H-- | M] () hpsysdrv.dat -> C:\WINDOWS\System\hpsysdrv.dat -> [2011/11/10 14:15:51 | 000,000,248 | ---- | M] () {00000002-00000000-00000003-00001102-00000008-10221102}.CDF -> C:\WINDOWS\{00000002-00000000-00000003-00001102-00000008-10221102}.CDF -> [2011/11/10 14:13:11 | 004,958,588 | ---- | M] () bootstat.dat -> C:\WINDOWS\bootstat.dat -> [2011/11/10 14:13:03 | 000,002,048 | --S- | M] () hiberfil.sys -> C:\hiberfil.sys -> [2011/11/10 14:12:58 | 2145,865,728 | -HS- | M] () BMXStateBkp-{00000002-00000000-00000003-00001102-00000008-10221102}.rfx -> C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000003-00001102-00000008-10221102}.rfx -> [2011/11/10 06:36:30 | 000,030,648 | ---- | M] () BMXState-{00000002-00000000-00000003-00001102-00000008-10221102}.rfx -> C:\WINDOWS\System32\BMXState-{00000002-00000000-00000003-00001102-00000008-10221102}.rfx -> [2011/11/10 06:36:30 | 000,030,648 | ---- | M] () BMXCtrlState-{00000002-00000000-00000003-00001102-00000008-10221102}.rfx -> C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000003-00001102-00000008-10221102}.rfx -> [2011/11/10 06:36:30 | 000,029,772 | ---- | M] () BMXBkpCtrlState-{00000002-00000000-00000003-00001102-00000008-10221102}.rfx -> C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000003-00001102-00000008-10221102}.rfx -> [2011/11/10 06:36:30 | 000,029,772 | ---- | M] () DVCState-{00000002-00000000-00000003-00001102-00000008-10221102}.rfx -> C:\WINDOWS\System32\DVCState-{00000002-00000000-00000003-00001102-00000008-10221102}.rfx -> [2011/11/10 06:36:30 | 000,011,564 | ---- | M] () settingsbkup.sfm -> C:\WINDOWS\System32\settingsbkup.sfm -> [2011/11/10 06:36:30 | 000,001,080 | ---- | M] () settings.sfm -> C:\WINDOWS\System32\settings.sfm -> [2011/11/10 06:36:30 | 000,001,080 | ---- | M] () {00000002-00000000-00000003-00001102-00000008-10221102}.BAK -> C:\WINDOWS\{00000002-00000000-00000003-00001102-00000008-10221102}.BAK -> [2011/11/10 06:35:43 | 004,958,588 | ---- | M] () perfh009.dat -> C:\WINDOWS\System32\perfh009.dat -> [2011/11/06 06:25:29 | 000,466,896 | ---- | M] () perfc009.dat -> C:\WINDOWS\System32\perfc009.dat -> [2011/11/06 06:25:29 | 000,080,112 | ---- | M] () PSTUDIO.INI -> C:\WINDOWS\PSTUDIO.INI -> [2011/11/05 21:47:12 | 000,000,637 | ---- | M] () ebay001.jpg -> C:\Documents and Settings\HP_Administrator\Desktop\ebay001.jpg -> [2011/11/05 15:17:13 | 000,332,238 | ---- | M] () Hosts -> C:\WINDOWS\System32\drivers\etc\Hosts -> [2011/11/01 16:26:07 | 000,000,098 | ---- | M] () FlashPlayerCPLApp.cpl -> C:\WINDOWS\System32\FlashPlayerCPLApp.cpl -> [2011/10/28 05:21:21 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) deployJava1.dll -> C:\WINDOWS\System32\deployJava1.dll -> [2011/10/27 17:34:55 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) javaws.exe -> C:\WINDOWS\System32\javaws.exe -> [2011/10/27 17:34:55 | 000,157,472 | ---- | M] (Sun Microsystems, Inc.) javaw.exe -> C:\WINDOWS\System32\javaw.exe -> [2011/10/27 17:34:55 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) java.exe -> C:\WINDOWS\System32\java.exe -> [2011/10/27 17:34:55 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) javacpl.cpl -> C:\WINDOWS\System32\javacpl.cpl -> [2011/10/27 17:34:55 | 000,073,728 | ---- | M] (Sun Microsystems, Inc.) WS_FTP.INI -> C:\WINDOWS\WS_FTP.INI -> [2011/10/23 09:28:22 | 000,000,179 | ---- | M] () RSIT.exe -> C:\Documents and Settings\HP_Administrator\Desktop\RSIT.exe -> [2011/10/19 18:01:28 | 000,781,383 | ---- | M] () imsins.BAK -> C:\WINDOWS\imsins.BAK -> [2011/10/12 16:40:27 | 000,001,393 | ---- | M] () wpa.dbl -> C:\WINDOWS\System32\wpa.dbl -> [2011/10/12 16:39:23 | 000,001,158 | ---- | M] () FNTCACHE.DAT -> C:\WINDOWS\System32\FNTCACHE.DAT -> [2011/10/11 19:55:03 | 000,319,544 | ---- | M] () 12 C:\Documents and Settings\HP_Administrator\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\HP_Administrator\Local Settings\Temp\*.tmp -> [Files - No Company Name] ebay001.jpg -> C:\Documents and Settings\HP_Administrator\Desktop\ebay001.jpg -> [2011/11/05 14:23:38 | 000,332,238 | ---- | C] () RSIT.exe -> C:\Documents and Settings\HP_Administrator\Desktop\RSIT.exe -> [2011/10/19 18:01:21 | 000,781,383 | ---- | C] () FontCache3.0.0.0.dat -> C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat -> [2011/01/30 21:38:07 | 000,301,144 | ---- | C] () sbwin.ini -> C:\WINDOWS\sbwin.ini -> [2010/10/28 19:43:01 | 000,000,072 | ---- | C] () guitar_tabs.xml -> C:\Documents and Settings\HP_Administrator\Application Data\guitar_tabs.xml -> [2010/09/03 09:08:23 | 000,000,396 | ---- | C] () EPPICPrinterDB.dat -> C:\WINDOWS\System32\EPPICPrinterDB.dat -> [2009/01/04 01:37:17 | 000,073,220 | ---- | C] () EPPICPresetData_ES.dat -> C:\WINDOWS\System32\EPPICPresetData_ES.dat -> [2009/01/04 01:37:17 | 000,001,137 | ---- | C] () EPPICPresetData_FR.dat -> C:\WINDOWS\System32\EPPICPresetData_FR.dat -> [2009/01/04 01:37:17 | 000,001,130 | ---- | C] () EPPICPresetData_CF.dat -> C:\WINDOWS\System32\EPPICPresetData_CF.dat -> [2009/01/04 01:37:17 | 000,001,130 | ---- | C] () EPPICPresetData_EN.dat -> C:\WINDOWS\System32\EPPICPresetData_EN.dat -> [2009/01/04 01:37:17 | 000,001,104 | ---- | C] () PICSDK.ini -> C:\WINDOWS\System32\PICSDK.ini -> [2009/01/04 01:37:17 | 000,000,097 | ---- | C] () EPPICPattern131.dat -> C:\WINDOWS\System32\EPPICPattern131.dat -> [2009/01/04 01:37:16 | 000,031,053 | ---- | C] () EPPICPattern1.dat -> C:\WINDOWS\System32\EPPICPattern1.dat -> [2009/01/04 01:37:16 | 000,029,114 | ---- | C] () EPPICPattern121.dat -> C:\WINDOWS\System32\EPPICPattern121.dat -> [2009/01/04 01:37:16 | 000,027,417 | ---- | C] () EPPICPattern3.dat -> C:\WINDOWS\System32\EPPICPattern3.dat -> [2009/01/04 01:37:16 | 000,021,021 | ---- | C] () EPPICPattern5.dat -> C:\WINDOWS\System32\EPPICPattern5.dat -> [2009/01/04 01:37:16 | 000,015,670 | ---- | C] () EPPICPattern2.dat -> C:\WINDOWS\System32\EPPICPattern2.dat -> [2009/01/04 01:37:16 | 000,013,280 | ---- | C] () EPPICPattern4.dat -> C:\WINDOWS\System32\EPPICPattern4.dat -> [2009/01/04 01:37:16 | 000,010,673 | ---- | C] () EPPICPattern6.dat -> C:\WINDOWS\System32\EPPICPattern6.dat -> [2009/01/04 01:37:16 | 000,004,943 | ---- | C] () EPPICPresetData_PT.dat -> C:\WINDOWS\System32\EPPICPresetData_PT.dat -> [2009/01/04 01:37:16 | 000,001,140 | ---- | C] () EPPICPresetData_BP.dat -> C:\WINDOWS\System32\EPPICPresetData_BP.dat -> [2009/01/04 01:37:16 | 000,001,140 | ---- | C] () esfw66.bin -> C:\WINDOWS\System32\esfw66.bin -> [2009/01/04 01:34:27 | 000,065,793 | ---- | C] () PERFV100V350.ini -> C:\WINDOWS\PERFV100V350.ini -> [2009/01/04 01:33:57 | 000,000,044 | ---- | C] () WS_FTP.INI -> C:\WINDOWS\WS_FTP.INI -> [2009/01/04 01:31:33 | 000,000,179 | ---- | C] () CNMS630.EXE -> C:\WINDOWS\System32\CNMS630.EXE -> [2009/01/04 00:15:33 | 000,036,864 | ---- | C] () PSTUDIO.INI -> C:\WINDOWS\PSTUDIO.INI -> [2009/01/04 00:12:21 | 000,000,637 | ---- | C] () DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2009/01/04 00:00:51 | 000,040,960 | ---- | C] () fusioncache.dat -> C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\fusioncache.dat -> [2009/01/03 23:34:57 | 000,000,139 | ---- | C] () structuredqueryschematrivial.bin -> C:\WINDOWS\System32\structuredqueryschematrivial.bin -> [2008/05/26 21:59:42 | 000,018,904 | ---- | C] () structuredqueryschema.bin -> C:\WINDOWS\System32\structuredqueryschema.bin -> [2008/05/26 21:59:40 | 000,106,605 | ---- | C] () idxcntrs.ini -> C:\WINDOWS\System32\idxcntrs.ini -> [2007/09/27 10:51:02 | 000,020,698 | ---- | C] () gsrvctr.ini -> C:\WINDOWS\System32\gsrvctr.ini -> [2007/09/27 10:48:48 | 000,030,628 | ---- | C] () gthrctr.ini -> C:\WINDOWS\System32\gthrctr.ini -> [2007/09/27 10:48:28 | 000,031,698 | ---- | C] () smscfg.ini -> C:\WINDOWS\smscfg.ini -> [2006/05/17 23:11:05 | 000,000,061 | ---- | C] () USBkey.sys -> C:\WINDOWS\System32\drivers\USBkey.sys -> [2006/05/17 22:50:31 | 000,028,848 | ---- | C] () HPCPCUninstaller-6.3.2.116-9972322.exe -> C:\WINDOWS\HPCPCUninstaller-6.3.2.116-9972322.exe -> [2006/05/17 22:48:00 | 000,118,842 | R--- | C] () CHODDI.SYS -> C:\WINDOWS\System32\CHODDI.SYS -> [2006/05/17 22:47:16 | 000,014,316 | ---- | C] () hpreg.dll -> C:\WINDOWS\System32\hpreg.dll -> [2006/05/17 22:47:07 | 000,045,056 | ---- | C] () Quicken.ini -> C:\WINDOWS\Quicken.ini -> [2006/05/17 22:45:33 | 000,000,054 | ---- | C] () ODBC.INI -> C:\WINDOWS\ODBC.INI -> [2006/05/17 22:43:34 | 000,000,376 | ---- | C] () WININIT.INI -> C:\WINDOWS\WININIT.INI -> [2006/05/17 22:36:55 | 000,000,179 | ---- | C] () NSSetDefaultBrowser.EXE -> C:\WINDOWS\NSSetDefaultBrowser.EXE -> [2006/05/17 22:35:56 | 000,045,929 | ---- | C] () NSSetDefaultBrowser.ini -> C:\WINDOWS\NSSetDefaultBrowser.ini -> [2006/05/17 22:35:56 | 000,000,698 | ---- | C] () HPHins08.dat -> C:\WINDOWS\HPHins08.dat -> [2006/05/17 22:32:15 | 000,080,417 | ---- | C] () hphmdl08.dat -> C:\WINDOWS\hphmdl08.dat -> [2006/05/17 22:32:15 | 000,004,011 | ---- | C] () hpiins01.dat -> C:\WINDOWS\hpiins01.dat -> [2006/05/17 22:31:34 | 000,072,881 | ---- | C] () hpimdl01.dat -> C:\WINDOWS\hpimdl01.dat -> [2006/05/17 22:31:34 | 000,000,000 | ---- | C] () hpqins69.dat -> C:\WINDOWS\hpqins69.dat -> [2006/05/17 22:29:15 | 000,087,276 | ---- | C] () hpoins07.dat -> C:\WINDOWS\hpoins07.dat -> [2006/05/17 22:28:09 | 000,112,873 | ---- | C] () hpomdl07.dat -> C:\WINDOWS\hpomdl07.dat -> [2006/05/17 22:28:09 | 000,021,124 | ---- | C] () hpoins06.dat -> C:\WINDOWS\hpoins06.dat -> [2006/05/17 22:26:03 | 000,088,403 | ---- | C] () hpomdl06.dat -> C:\WINDOWS\hpomdl06.dat -> [2006/05/17 22:26:03 | 000,005,389 | ---- | C] () fxsperf.ini -> C:\WINDOWS\System32\fxsperf.ini -> [2006/05/17 22:25:16 | 000,001,793 | ---- | C] () hptina.ini -> C:\WINDOWS\System32\hptina.ini -> [2006/05/17 22:22:03 | 000,037,002 | ---- | C] () ctzapxx.ini -> C:\WINDOWS\System32\ctzapxx.ini -> [2006/05/17 22:22:03 | 000,000,191 | ---- | C] () ctstatic.dat -> C:\WINDOWS\System32\ctstatic.dat -> [2006/05/17 22:21:11 | 000,313,207 | ---- | C] () ctdlang.dat -> C:\WINDOWS\System32\ctdlang.dat -> [2006/05/17 22:21:11 | 000,293,547 | ---- | C] () ctsbas2w.dat -> C:\WINDOWS\System32\ctsbas2w.dat -> [2006/05/17 22:21:11 | 000,265,066 | ---- | C] () CTSBASW.DAT -> C:\WINDOWS\System32\CTSBASW.DAT -> [2006/05/17 22:21:11 | 000,231,821 | ---- | C] () ctbas2w.dat -> C:\WINDOWS\System32\ctbas2w.dat -> [2006/05/17 22:21:11 | 000,140,643 | ---- | C] () CTBASICW.DAT -> C:\WINDOWS\System32\CTBASICW.DAT -> [2006/05/17 22:21:11 | 000,113,221 | ---- | C] () ctdaught.dat -> C:\WINDOWS\System32\ctdaught.dat -> [2006/05/17 22:21:11 | 000,053,932 | ---- | C] () PSCONV.EXE -> C:\WINDOWS\PSCONV.EXE -> [2006/05/17 22:21:11 | 000,034,304 | ---- | C] () REGPLIB.EXE -> C:\WINDOWS\System32\REGPLIB.EXE -> [2006/05/17 22:21:11 | 000,033,792 | ---- | C] () CTBURST.DLL -> C:\WINDOWS\System32\CTBURST.DLL -> [2006/05/17 22:21:10 | 000,038,400 | ---- | C] () KILL.INI -> C:\WINDOWS\System32\KILL.INI -> [2006/05/17 22:21:10 | 000,000,194 | ---- | C] () atiicdxx.dat -> C:\WINDOWS\System32\atiicdxx.dat -> [2006/05/17 22:20:03 | 000,112,425 | ---- | C] () orun32.ini -> C:\WINDOWS\orun32.ini -> [2006/05/17 22:19:08 | 000,000,791 | ---- | C] () pythoncom22.dll -> C:\WINDOWS\System32\pythoncom22.dll -> [2006/05/17 22:00:56 | 000,323,584 | ---- | C] () pywintypes22.dll -> C:\WINDOWS\System32\pywintypes22.dll -> [2006/05/17 22:00:56 | 000,094,208 | ---- | C] () bcbmm.dll -> C:\WINDOWS\System32\bcbmm.dll -> [2006/05/17 22:00:40 | 000,016,896 | ---- | C] () px.ini -> C:\WINDOWS\System32\px.ini -> [2005/12/09 15:01:36 | 000,000,000 | ---- | C] () bootstat.dat -> C:\WINDOWS\bootstat.dat -> [2005/08/30 22:17:40 | 000,002,048 | --S- | C] () perfh009.dat -> C:\WINDOWS\System32\perfh009.dat -> [2005/08/30 22:07:46 | 000,466,896 | ---- | C] () perfc009.dat -> C:\WINDOWS\System32\perfc009.dat -> [2005/08/30 22:07:46 | 000,080,112 | ---- | C] () FNTCACHE.DAT -> C:\WINDOWS\System32\FNTCACHE.DAT -> [2005/08/30 22:05:30 | 000,319,544 | ---- | C] () ODBCINST.INI -> C:\WINDOWS\ODBCINST.INI -> [2005/08/30 22:01:42 | 000,004,161 | ---- | C] () emptyregdb.dat -> C:\WINDOWS\System32\emptyregdb.dat -> [2005/08/30 21:58:02 | 000,021,640 | ---- | C] () psisdecd.dll -> C:\WINDOWS\System32\psisdecd.dll -> [2005/08/05 22:01:54 | 000,239,104 | ---- | C] () secupd.dat -> C:\WINDOWS\System32\secupd.dat -> [2004/08/10 05:00:00 | 000,004,569 | ---- | C] () mlang.dat -> C:\WINDOWS\System32\mlang.dat -> [2004/08/09 22:00:00 | 000,673,088 | ---- | C] () perfi009.dat -> C:\WINDOWS\System32\perfi009.dat -> [2004/08/09 22:00:00 | 000,272,128 | ---- | C] () dssec.dat -> C:\WINDOWS\System32\dssec.dat -> [2004/08/09 22:00:00 | 000,218,003 | ---- | C] () mib.bin -> C:\WINDOWS\System32\mib.bin -> [2004/08/09 22:00:00 | 000,046,258 | ---- | C] () perfd009.dat -> C:\WINDOWS\System32\perfd009.dat -> [2004/08/09 22:00:00 | 000,028,626 | ---- | C] () dcache.bin -> C:\WINDOWS\System32\dcache.bin -> [2004/08/09 22:00:00 | 000,001,804 | ---- | C] () noise.dat -> C:\WINDOWS\System32\noise.dat -> [2004/08/09 22:00:00 | 000,000,741 | ---- | C] () oeminfo.ini -> C:\WINDOWS\System32\oeminfo.ini -> [2004/07/26 08:51:38 | 000,000,560 | ---- | C] () oembios.bin -> C:\WINDOWS\System32\oembios.bin -> [2001/08/23 09:12:28 | 013,107,200 | ---- | C] () oembios.dat -> C:\WINDOWS\System32\oembios.dat -> [2001/08/23 09:11:02 | 000,004,490 | ---- | C] () hptcpmon.ini -> C:\WINDOWS\System32\hptcpmon.ini -> [2001/07/06 23:30:00 | 000,003,399 | ---- | C] () < End of report > [/code]