Recent Posts
PHP | 15 sec ago
C++ | 17 sec ago
None | 44 sec ago
None | 53 sec ago
PHP | 59 sec ago
None | 1 min ago
None | 1 min ago
None | 1 min ago
None | 1 min ago
JavaScript | 1 min ago
Sitereport
Find cool info about any domain on the internet?
visit sitereport
Free Subdomains
Want a pastebin.com sub-domain for your community?
learn more...
What is pastebin?
Pastebin is a website that hosts all your text & code on dedicated servers for easy sharing.
learn more...
Learn a little bit about the new Pastebin.com on our help page. hide message
By log on the 10th of Feb 2010 12:55:07 AM Download | Raw | Embed | Report
  1. Here they all are....
  2. [b]
  3. Info: [/b]
  4. [code]info.txt logfile of random's system information tool 1.06 2010-02-09 16:40:01
  5.  
  6. ======Uninstall list======
  7.  
  8. -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5549DC52-211C-44BE-8347-0C22812DEB31}\setup.exe" -l0x9
  9. -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88564CEF-20A5-4EF2-A05F-309F2EBA9B06}\setup.exe" -l0x9
  10. -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A1A5BA3E-9ABF-4037-820B-6151022B8ACB}\setup.exe" -l0x9
  11. -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A82F10CB-18B5-4EAC-AEF2-FA49CD565626}\setup.exe" -l0x9
  12. -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D5BA7C09-E523-478C-9C37-A1D86C76383E}\setup.exe" -l0x9
  13. -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F6366726-BA44-4D6A-8ECE-476E2E616AD1}\setup.exe" -l0x9
  14. 183082-->MsiExec.exe /X{33B39446-C34C-4552-BE88-FE217D79C868}
  15. 3ivx MPEG-4 5.0.3 (remove only)-->"C:\Program Files\3ivx\3ivx MPEG-4 5.0.3\uninstaller.exe"
  16. Acoustica Effects Pack-->C:\PROGRA~1\ACOUST~2\UNWISE.EXE C:\PROGRA~1\ACOUST~2\INSTALL.LOG
  17. Acrobat.com-->MsiExec.exe /I{27F00C63-449B-2FAB-CBE8-24AB80E17449}
  18. ActivePerl 5.10.0 Build 1005-->MsiExec.exe /I{FD025150-EEA0-4CAC-BED1-B9837783FCC8}
  19. Adobe AIR-->c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
  20. Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
  21. Adobe Anchor Service CS4-->MsiExec.exe /I{1618734A-3957-4ADD-8199-F973763109A8}
  22. Adobe Bridge CS4-->MsiExec.exe /I{83877DB1-8B77-45BC-AB43-2BAC22E093E0}
  23. Adobe CMaps CS4-->MsiExec.exe /I{94D398EB-D2FD-4FD1-B8C4-592635E8A191}
  24. Adobe Color - Photoshop Specific CS4-->MsiExec.exe /I{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}
  25. Adobe Color EU Extra Settings CS4-->MsiExec.exe /I{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}
  26. Adobe Color JA Extra Settings CS4-->MsiExec.exe /I{0D6013AB-A0C7-41DC-973C-E93129C9A29F}
  27. Adobe Color NA Recommended Settings CS4-->MsiExec.exe /I{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}
  28. Adobe Color Video Profiles CS CS4-->MsiExec.exe /I{63C24A08-70F3-4C8E-B9FB-9F21A903801D}
  29. Adobe CSI CS4-->MsiExec.exe /I{0F723FC1-7606-4867-866C-CE80AD292DAF}
  30. Adobe Default Language CS4-->MsiExec.exe /I{C52E3EC1-048C-45E1-8D53-10B0C6509683}
  31. Adobe Device Central CS4-->MsiExec.exe /I{67F0E67A-8E93-4C2C-B29D-47C48262738A}
  32. Adobe Drive CS4-->MsiExec.exe /I{16E16F01-2E2D-4248-A42F-76261C147B6C}
  33. Adobe ExtendScript Toolkit CS4-->MsiExec.exe /I{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}
  34. Adobe Extension Manager CS4-->MsiExec.exe /I{054EFA56-2AC1-48F4-A883-0AB89874B972}
  35. Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
  36. Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
  37. Adobe Fonts All-->MsiExec.exe /I{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}
  38. Adobe Linguistics CS4-->MsiExec.exe /I{931AB7EA-3656-4BB7-864D-022B09E3DD67}
  39. Adobe Media Player-->MsiExec.exe /I{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}
  40. Adobe Output Module-->MsiExec.exe /I{BB4E33EC-8181-4685-96F7-8554293DEC6A}
  41. Adobe PDF Library Files CS4-->MsiExec.exe /I{F93C84A6-0DC6-42AF-89FA-776F7C377353}
  42. Adobe Photoshop CS4 Support-->MsiExec.exe /I{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}
  43. Adobe Photoshop CS4-->C:\Program Files\Common Files\Adobe\Installers\faf656ef605427ee2f42989c3ad31b8\Setup.exe --uninstall=1
  44. Adobe Photoshop CS4-->MsiExec.exe /I{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}
  45. Adobe Photoshop CS4-->MsiExec.exe /I{E4848436-0345-47E2-B648-8B522FCDA623}
  46. Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90000000001}
  47. Adobe Search for Help-->MsiExec.exe /I{F0E64E2E-3A60-40D8-A55D-92F6831875DA}
  48. Adobe Service Manager Extension-->MsiExec.exe /I{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}
  49. Adobe Setup-->MsiExec.exe /I{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}
  50. Adobe Setup-->MsiExec.exe /I{14AFE241-FC6E-4FDB-BCA0-7AD6F4974171}
  51. Adobe Shockwave Player-->C:\Windows\System32\Adobe\SHOCKW~1\UNWISE.EXE C:\Windows\System32\Adobe\SHOCKW~1\Install.log
  52. Adobe Type Support CS4-->MsiExec.exe /I{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}
  53. Adobe Update Manager CS4-->MsiExec.exe /I{05308C4E-7285-4066-BAE3-6B50DA6ED755}
  54. Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}
  55. Adobe XMP Panels CS4-->MsiExec.exe /I{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}
  56. AdobeColorCommonSetCMYK-->MsiExec.exe /I{68243FF8-83CA-466B-B2B8-9F99DA5479C4}
  57. AdobeColorCommonSetRGB-->MsiExec.exe /I{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}
  58. Advanced Audio FX Engine-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88564CEF-20A5-4EF2-A05F-309F2EBA9B06}\setup.exe" -l0x9  /remove
  59. Advanced Video FX Engine-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D5BA7C09-E523-478C-9C37-A1D86C76383E}\setup.exe" -l0x9  /remove
  60. AIM 6-->C:\Program Files\AIM6\uninst.exe
  61. Akamai NetSession Interface-->C:\Program Files\Common Files\Akamai\uninstall.exe
  62. Any Video Converter 2.7.9-->"C:\Program Files\Any Video Converter\unins000.exe"
  63. Apple Application Support-->MsiExec.exe /I{3FA365DF-2D68-45ED-8F83-8C8A33E65143}
  64. Apple Mobile Device Support-->MsiExec.exe /I{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}
  65. Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
  66. Ask Toolbar-->MsiExec.exe /I{86D4B82A-ABED-442A-BE86-96357B70F4FE}
  67. avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
  68. Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
  69. Broadcom NetXtreme II Driver Installer-->MsiExec.exe /I{70C5AEBE-FAF7-4C58-80D2-B3C4B7179D5D}
  70. Browser Address Error Redirector-->MsiExec.exe /I{62230596-37E5-4618-A329-0D21F529A86F}
  71. Canon iP1800 series User Registration-->C:\Program Files\Canon\IJEREG\iP1800 series\UNINST.EXE
  72. Canon iP1800 series-->"C:\Windows\system32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP1800_series\DelDrv.exe" /U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP1800_series /L0x0009
  73. Canon My Printer-->C:\Program Files\Canon\MyPrinter\uninst.exe uninst.ini
  74. Canon Utilities Easy-LayoutPrint-->C:\Program Files\Canon\Easy-LayoutPrint\uninst.exe uninst.ini
  75. Canon Utilities Easy-PhotoPrint-->C:\Program Files\Canon\Easy-PhotoPrint\uninst.exe uninst.ini
  76. CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
  77. Cisco EAP-FAST Module-->MsiExec.exe /I{415B2719-AD3A-4944-B404-C472DB6085B3}
  78. Cisco LEAP Module-->MsiExec.exe /I{83770D14-21B9-44B3-8689-F7B523F94560}
  79. Cisco PEAP Module-->MsiExec.exe /I{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}
  80. Connect-->MsiExec.exe /I{B29AD377-CC12-490A-A480-1452337C618D}
  81. ConvertHelper 2.2-->"C:\Program Files\ConvertHelper\unins000.exe"
  82. Core FTP LE 2.1-->C:\PROGRA~1\CoreFTP\UNWISE.EXE C:\PROGRA~1\CoreFTP\INSTALL.LOG
  83. Creative Live! Cam Doodling-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5549DC52-211C-44BE-8347-0C22812DEB31}\setup.exe" -l0x9  /remove
  84. Creative Live! Cam Video IM Pro Driver (1.03.02.00)-->C:\Windows\CtDrvIns.exe -uninstall -script VF0230.uns -unsext NT -plugin V0230Pin.dll -pluginres CtCamPin.crl
  85. Dell Dock-->"C:\ProgramData\{7322D736-AA5F-4DD0-8E33-EA48318CC276}\delldock.exe" REMOVE=TRUE MODIFY=FALSE
  86. Dell Dock-->C:\ProgramData\{7322D736-AA5F-4DD0-8E33-EA48318CC276}\delldock.exe
  87. Dell Getting Started Guide-->MsiExec.exe /I{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}
  88. Dell Support Center (Support Software)-->MsiExec.exe /X{E3BFEE55-39E2-4BE0-B966-89FE583822C1}
  89. Dell Touchpad-->C:\Program Files\DellTPad\Uninstap.exe ADDREMOVE
  90. Dell Video Chat (remove only)-->C:\Program Files\Dell Video Chat\uninst.exe
  91. Dell Webcam Center-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A1A5BA3E-9ABF-4037-820B-6151022B8ACB}\setup.exe" -l0x9  /remove
  92. DELL Webcam Manager-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F6366726-BA44-4D6A-8ECE-476E2E616AD1}\setup.exe" -l0x9  /remove
  93. Dell Wireless WLAN Card Utility-->"C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwlu00.exe" verbose /rootkey="Software\Broadcom\802.11\UninstallInfo" /rootdir="C:\Program Files\Dell\Dell Wireless WLAN Card"
  94. Download Updater (AOL LLC)-->C:\Program Files\Common Files\Software Update Utility\uninstall.exe
  95. EDocs-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6B7B6D4D-8F9B-4CB3-8CA4-BCA9CC4C1A22}\setup.exe"
  96. Google Gears-->MsiExec.exe /I{BC2FE771-EDBE-3087-A676-2B6C45A2BF7E}
  97. Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0E996B068B56FCA2.exe" /uninstall
  98. Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
  99. Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
  100. Google Updater-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
  101. GoToAssist 8.0.0.514-->C:\Program Files\Citrix\GoToAssist\514\G2AUninstaller.exe /uninstall
  102. HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
  103. HiJackThis-->MsiExec.exe /X{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}
  104. Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall  /qb+ REBOOTPROMPT=""
  105. Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
  106. Integrated Webcam Driver (1.03.02.0919)  -->C:\Windows\CtDrvIns.exe -uninstall -script OA001.uns -plugin OA001Pin.dll -pluginres OA001Pin.crl -nodisconprompt -langid 0x0409
  107. Intel(R) Matrix Storage Manager-->C:\Windows\System32\Imsmudlg.exe
  108. ITECIR Driver-->C:\Program Files\InstallShield Installation Information\{FCED9B62-34FF-4C15-8A23-F65221F7874D}\setup.exe -runfromtemp -l0x0009 -removeonly
  109. iTunes-->MsiExec.exe /I{F439D7AF-03F3-4F8E-AEC4-571BFE977C61}
  110. Java DB 10.4.1.3-->MsiExec.exe /X{998D6972-F58E-479D-9248-8F179E55AE38}
  111. Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013F0}
  112. Java(TM) 6 Update 17-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013FF}
  113. Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
  114. Java(TM) SE Development Kit 6 Update 13-->MsiExec.exe /I{32A3A4F4-B792-11D6-A78A-00B0D0160130}
  115. Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
  116. KeyScrambler-->C:\Program Files\KeyScrambler\uninstall.exe
  117. kuler-->MsiExec.exe /I{098727E1-775A-4450-B573-3F441F1CA243}
  118. LimeWire 5.2.8-->"C:\Program Files\LimeWire\uninstall.exe"
  119. Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
  120. ManyCam 2.4 (remove only)-->"C:\Program Files\ManyCam 2.4\uninstall.exe"
  121. MediaDirect-->C:\Program Files\InstallShield Installation Information\{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}\setup.exe -runfromtemp -l0x0009 -cluninstall
  122. Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
  123. Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
  124. Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
  125. Microsoft Office Excel MUI (English) 2007-->MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
  126. Microsoft Office Outlook MUI (English) 2007-->MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
  127. Microsoft Office PowerPoint MUI (English) 2007-->MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
  128. Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
  129. Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
  130. Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
  131. Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
  132. Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
  133. Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
  134. Microsoft Office Standard 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall STANDARDR /dll OSETUP.DLL
  135. Microsoft Office Standard 2007-->MsiExec.exe /X{91120000-0012-0000-0000-0000000FF1CE}
  136. Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
  137. Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
  138. Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
  139. Microsoft SQL Server 2008 Browser-->MsiExec.exe /X{C688457E-03FD-4941-923B-A27F4D42A7DD}
  140. Microsoft SQL Server 2008 Common Files-->MsiExec.exe /I{196E77C5-F524-4B50-BD1A-2C21EEE9B8F7}
  141. Microsoft SQL Server 2008 Common Files-->MsiExec.exe /I{4A6F34E2-09E5-4616-B227-4A26A488A6F9}
  142. Microsoft SQL Server 2008 Database Engine Services-->MsiExec.exe /I{58721EC3-8D4E-4B79-BC51-1054E2DDCD10}
  143. Microsoft SQL Server 2008 Database Engine Services-->MsiExec.exe /I{B5153233-9AEE-4CD4-9D2C-4FAAC870DBE2}
  144. Microsoft SQL Server 2008 Database Engine Shared-->MsiExec.exe /I{4815BD99-96A4-49FE-A885-DCF06E9E4E78}
  145. Microsoft SQL Server 2008 Database Engine Shared-->MsiExec.exe /I{F3494AB6-6900-41C6-AF57-823626827ED8}
  146. Microsoft SQL Server 2008 Management Objects-->MsiExec.exe /I{F5E87B12-3C27-452F-8E78-21D42164FD83}
  147. Microsoft SQL Server 2008 Native Client-->MsiExec.exe /I{D9D937B0-E842-4130-9588-B948E876904A}
  148. Microsoft SQL Server 2008 RsFx Driver-->MsiExec.exe /I{F1DC7648-8623-442F-92B7-E118DF61872E}
  149. Microsoft SQL Server 2008 Setup Support Files (English)-->MsiExec.exe /X{9D6D76A6-4328-49E8-97A7-531A74841DA5}
  150. Microsoft SQL Server 2008-->"c:\Program Files\Microsoft SQL Server\100\Setup Bootstrap\Release\x86\SetupARP.exe" /x86
  151. Microsoft SQL Server 2008-->"c:\Program Files\Microsoft SQL Server\100\Setup Bootstrap\Release\x86\SetupARP.exe" /X86
  152. Microsoft SQL Server Compact 3.5 SP1 Design Tools English-->MsiExec.exe /X{0C19D563-5F25-4621-BF10-01F741BD283F}
  153. Microsoft SQL Server Compact 3.5 SP1 English-->MsiExec.exe /I{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}
  154. Microsoft SQL Server VSS Writer-->MsiExec.exe /I{B857D868-F8B0-43EE-BC2B-D9E5ED21F237}
  155. Mozilla Firefox (3.5.7)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
  156. MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
  157. muvee Plugin 1.0-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{82CA0A0C-A3EC-4167-B694-909205B2EDEC}\setup.exe" -l0x9
  158. Pando Media Booster-->C:\Program Files\Pando Networks\Media Booster\uninst.exe
  159. PDF Settings CS4-->MsiExec.exe /I{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}
  160. Photoshop Camera Raw-->MsiExec.exe /I{CC75AB5C-2110-4A7F-AF52-708680D22FE8}
  161. QuickSet-->MsiExec.exe /I{C4972073-2BFE-475D-8441-564EA97DA161}
  162. QuickTime-->MsiExec.exe /I{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}
  163. Roxio Creator Audio-->MsiExec.exe /I{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}
  164. Roxio Creator Copy-->MsiExec.exe /I{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}
  165. Roxio Creator Data-->MsiExec.exe /I{08E81ABD-79F7-49C2-881F-FD6CB0975693}
  166. Roxio Creator DE-->C:\ProgramData\Uninstall\{09760D42-E223-42AD-8C3E-55B47D0DDAC3}\setup.exe /x {09760D42-E223-42AD-8C3E-55B47D0DDAC3}
  167. Roxio Creator DE-->MsiExec.exe /I{ED439A64-F018-4DD4-8BA5-328D85AB09AB}
  168. Roxio Creator Tools-->MsiExec.exe /I{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}
  169. Roxio Express Labeler 3-->MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
  170. Roxio Update Manager-->MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
  171. Sql Server Customer Experience Improvement Program-->MsiExec.exe /I{C965F01C-76EA-4BD7-973E-46236AE312D7}
  172. SQL Server System CLR Types-->MsiExec.exe /I{342D4AD7-EC4C-4EC8-AEA6-E70F5905A490}
  173. Suite Shared Configuration CS4-->MsiExec.exe /I{842B4B72-9E8F-4962-B3C1-1C422A5C4434}
  174. TeamViewer 5-->C:\Program Files\TeamViewer\Version5\uninstall.exe
  175. Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
  176. VideoLAN VLC media player 0.8.6d-->C:\Program Files\VideoLAN\VLC\uninstall.exe
  177. Viewpoint Media Player-->C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /u
  178. Windows Live Call-->MsiExec.exe /I{F6BD194C-4190-4D73-B1B1-C48C99921BFE}
  179. Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
  180. Windows Live Essentials-->C:\Program Files\Windows Live\Installer\wlarp.exe
  181. Windows Live Essentials-->MsiExec.exe /I{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}
  182. Windows Live Mail-->MsiExec.exe /I{6412CECE-8172-4BE5-935B-6CECACD2CA87}
  183. Windows Live Messenger-->MsiExec.exe /X{A85FD55B-891B-4314-97A5-EA96C0BD80B5}
  184. Windows Live OneCare safety scanner-->"C:\Program Files\Windows Live Safety Center\UnInstall.exe"
  185. Windows Live OneCare safety scanner-->MsiExec.exe /X{FE0646A7-19D0-41B4-A2BB-2C35D644270D}
  186. Windows Live Photo Gallery-->MsiExec.exe /X{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}
  187. Windows Live Sign-in Assistant-->MsiExec.exe /I{45338B07-A236-4270-9A77-EBB4115517B5}
  188. Windows Live Sync-->MsiExec.exe /X{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}
  189. Windows Live Upload Tool-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
  190. Windows Live Writer-->MsiExec.exe /X{178832DE-9DE0-4C87-9F82-9315A9B03985}
  191. WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
  192. WinSCP 4.2.1 beta-->"C:\Program Files\WinSCP\unins000.exe"
  193. YouTube Account Creator-->MsiExec.exe /I{4D28A974-F0D8-4C8E-B5DD-980D8D3663EE}
  194. z2 Remote2PC 1.3 Build 1323-->C:\Program Files\z2 Remote2PC\uninst.exe
  195. ZoneAlarm-->C:\Program Files\Zone Labs\ZoneAlarm\zauninst.exe
  196.  
  197. ======Hosts File======
  198.  
  199. 127.0.0.1       www.007guard.com
  200. 127.0.0.1       007guard.com
  201. 127.0.0.1       008i.com
  202. 127.0.0.1       www.008k.com
  203. 127.0.0.1       008k.com
  204. 127.0.0.1       www.00hq.com
  205. 127.0.0.1       00hq.com
  206. 127.0.0.1       010402.com
  207. 127.0.0.1       www.032439.com
  208. 127.0.0.1       032439.com
  209.  
  210. ======Security center information======
  211.  
  212. AS: Windows Defender
  213.  
  214. ======System event log======
  215.  
  216. Computer Name: Santa-PC2
  217. Event Code: 4
  218. Message: The print spooler failed to reopen an existing printer connection because it could not read the configuration information from the registry key S-1-5-18\Printers\Connections. The print spooler could not open the registry key. This can occur if the registry key is corrupt or missing, or if the registry recently became unavailable.
  219. Record Number: 33848
  220. Source Name: Microsoft-Windows-SpoolerWin32SPL
  221. Time Written: 20090407004343.000000-000
  222. Event Type: Warning
  223. User:
  224.  
  225. Computer Name: Santa-PC2
  226. Event Code: 7
  227. Message: The speed of processor 0 is being limited by system firmware. The processor has been in this reduced performance state for 38 seconds since the last report.
  228. Record Number: 33868
  229. Source Name: Microsoft-Windows-Kernel-Processor-Power
  230. Time Written: 20090407033439.502000-000
  231. Event Type: Warning
  232. User: NT AUTHORITY\SYSTEM
  233.  
  234. Computer Name: Santa-PC2
  235. Event Code: 7
  236. Message: The speed of processor 1 is being limited by system firmware. The processor has been in this reduced performance state for 38 seconds since the last report.
  237. Record Number: 33869
  238. Source Name: Microsoft-Windows-Kernel-Processor-Power
  239. Time Written: 20090407033439.502000-000
  240. Event Type: Warning
  241. User: NT AUTHORITY\SYSTEM
  242.  
  243. Computer Name: Santa-PC2
  244. Event Code: 4
  245. Message: Broadcom NetLink (TM) Gigabit Ethernet: The network link is down.  Check to make sure the network cable is properly connected.
  246. Record Number: 33929
  247. Source Name: k57nd60x
  248. Time Written: 20090407170225.734923-000
  249. Event Type: Warning
  250. User:
  251.  
  252. Computer Name: Santa-PC2
  253. Event Code: 6008
  254. Message: The previous system shutdown at 11:41:07 PM on 4/6/2009 was unexpected.
  255. Record Number: 33934
  256. Source Name: EventLog
  257. Time Written: 20090407170251.000000-000
  258. Event Type: Error
  259. User:
  260.  
  261. =====Application event log=====
  262.  
  263. Computer Name: Santa-PC2
  264. Event Code: 33
  265. Message: Activation context generation failed for "C:\Windows\System32\bcmwltry.exe". Dependent Assembly Microsoft.VC90.MFC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8" could not be found. Please use sxstrace.exe for detailed diagnosis.
  266. Record Number: 252434
  267. Source Name: SideBySide
  268. Time Written: 20100210004035.000000-000
  269. Event Type: Error
  270. User:
  271.  
  272. Computer Name: Santa-PC2
  273. Event Code: 33
  274. Message: Activation context generation failed for "C:\Windows\System32\bcmwltry.exe". Dependent Assembly Microsoft.VC90.MFC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8" could not be found. Please use sxstrace.exe for detailed diagnosis.
  275. Record Number: 252435
  276. Source Name: SideBySide
  277. Time Written: 20100210004042.000000-000
  278. Event Type: Error
  279. User:
  280.  
  281. Computer Name: Santa-PC2
  282. Event Code: 33
  283. Message: Activation context generation failed for "C:\Windows\System32\bcmwltry.exe". Dependent Assembly Microsoft.VC90.MFC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8" could not be found. Please use sxstrace.exe for detailed diagnosis.
  284. Record Number: 252436
  285. Source Name: SideBySide
  286. Time Written: 20100210004049.000000-000
  287. Event Type: Error
  288. User:
  289.  
  290. Computer Name: Santa-PC2
  291. Event Code: 33
  292. Message: Activation context generation failed for "C:\Windows\System32\bcmwltry.exe". Dependent Assembly Microsoft.VC90.MFC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8" could not be found. Please use sxstrace.exe for detailed diagnosis.
  293. Record Number: 252437
  294. Source Name: SideBySide
  295. Time Written: 20100210004056.000000-000
  296. Event Type: Error
  297. User:
  298.  
  299. Computer Name: Santa-PC2
  300. Event Code: 33
  301. Message: Activation context generation failed for "C:\Windows\System32\bcmwltry.exe". Dependent Assembly Microsoft.VC90.MFC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8" could not be found. Please use sxstrace.exe for detailed diagnosis.
  302. Record Number: 252438
  303. Source Name: SideBySide
  304. Time Written: 20100210004103.000000-000
  305. Event Type: Error
  306. User:
  307.  
  308. =====Security event log=====
  309.  
  310. Computer Name: Santa-PC2
  311. Event Code: 4688
  312. Message: A new process has been created.
  313.  
  314. Subject:
  315.         Security ID:            S-1-5-21-1864734467-1502112414-1167469204-1014
  316.         Account Name:           Guest User
  317.         Account Domain:         Santa-PC2
  318.         Logon ID:               0x35746
  319.  
  320. Process Information:
  321.         New Process ID:         0x1874
  322.         New Process Name:       C:\Program Files\Internet Explorer\iexplore.exe
  323.         Token Elevation Type:   TokenElevationTypeDefault (1)
  324.         Creator Process ID:     0xec8
  325.  
  326. Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.
  327.  
  328. Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.
  329.  
  330. Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.
  331.  
  332. Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
  333. Record Number: 63045
  334. Source Name: Microsoft-Windows-Security-Auditing
  335. Time Written: 20100209085933.072025-000
  336. Event Type: Audit Success
  337. User:
  338.  
  339. Computer Name: Santa-PC2
  340. Event Code: 4696
  341. Message: A primary token was assigned to process.
  342.  
  343. Subject:
  344.         Security ID:            S-1-5-21-1864734467-1502112414-1167469204-1014
  345.         Account Name:           Guest User
  346.         Account Domain:         Santa-PC2
  347.         Logon ID:               0x35746
  348.  
  349. Process Information:
  350.         Process ID:     0xec8
  351.         Process Name:   C:\Program Files\Internet Explorer\iexplore.exe
  352.  
  353. Target Process:
  354.         Target Process ID:      0x1874
  355.         Target Process Name:    C:\Program Files\Internet Explorer\iexplore.exe
  356.  
  357. New Token Information:
  358.         Security ID:            S-1-5-21-1864734467-1502112414-1167469204-1014
  359.         Account Name:           Guest User
  360.         Account Domain:         Santa-PC2
  361.         Logon ID:               0x35746
  362. Record Number: 63046
  363. Source Name: Microsoft-Windows-Security-Auditing
  364. Time Written: 20100209085933.073025-000
  365. Event Type: Audit Success
  366. User:
  367.  
  368. Computer Name: Santa-PC2
  369. Event Code: 4688
  370. Message: A new process has been created.
  371.  
  372. Subject:
  373.         Security ID:            S-1-5-21-1864734467-1502112414-1167469204-1014
  374.         Account Name:           Guest User
  375.         Account Domain:         Santa-PC2
  376.         Logon ID:               0x35746
  377.  
  378. Process Information:
  379.         New Process ID:         0x1584
  380.         New Process Name:       C:\Program Files\Java\jdk1.6.0_11\bin\bin\ssvagent.exe
  381.         Token Elevation Type:   TokenElevationTypeDefault (1)
  382.         Creator Process ID:     0x1874
  383.  
  384. Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.
  385.  
  386. Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.
  387.  
  388. Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.
  389.  
  390. Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
  391. Record Number: 63047
  392. Source Name: Microsoft-Windows-Security-Auditing
  393. Time Written: 20100209085936.045025-000
  394. Event Type: Audit Success
  395. User:
  396.  
  397. Computer Name: Santa-PC2
  398. Event Code: 4689
  399. Message: A process has exited.
  400.  
  401. Subject:
  402.         Security ID:            S-1-5-21-1864734467-1502112414-1167469204-1014
  403.         Account Name:           Guest User
  404.         Account Domain:         Santa-PC2
  405.         Logon ID:               0x35746
  406.  
  407. Process Information:
  408.         Process ID:     0x1584
  409.         Process Name:   C:\Program Files\Java\jdk1.6.0_11\bin\bin\ssvagent.exe
  410.         Exit Status:    0x0
  411. Record Number: 63048
  412. Source Name: Microsoft-Windows-Security-Auditing
  413. Time Written: 20100209085937.146025-000
  414. Event Type: Audit Success
  415. User:
  416.  
  417. Computer Name: Santa-PC2
  418. Event Code: 4689
  419. Message: A process has exited.
  420.  
  421. Subject:
  422.         Security ID:            S-1-5-21-1864734467-1502112414-1167469204-1014
  423.         Account Name:           Guest User
  424.         Account Domain:         Santa-PC2
  425.         Logon ID:               0x35746
  426.  
  427. Process Information:
  428.         Process ID:     0x1d70
  429.         Process Name:   C:\Windows\System32\SearchProtocolHost.exe
  430.         Exit Status:    0x0
  431. Record Number: 63049
  432. Source Name: Microsoft-Windows-Security-Auditing
  433. Time Written: 20100209090047.697025-000
  434. Event Type: Audit Success
  435. User:
  436.  
  437. ======Environment variables======
  438.  
  439. "ComSpec"=%SystemRoot%\system32\cmd.exe
  440. "FP_NO_HOST_CHECK"=NO
  441. "OS"=Windows_NT
  442. "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\wbem;C:\Perl\site\bin;C:\Perl\bin;C:\Program Files\Common Files\Roxio Shared\DLLShared;C:\Program Files\Common Files\Roxio Shared\10.0\DLLShared;c:\Program Files\Microsoft SQL Server\100\Tools\Binn;c:\Program Files\Microsoft SQL Server\100\DTS\Binn;C:\Program Files\QuickTime\QTSystem
  443. "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
  444. "PROCESSOR_ARCHITECTURE"=x86
  445. "TEMP"=%SystemRoot%\TEMP
  446. "TMP"=%SystemRoot%\TEMP
  447. "USERNAME"=SYSTEM
  448. "windir"=%SystemRoot%
  449. "PROCESSOR_LEVEL"=6
  450. "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
  451. "PROCESSOR_REVISION"=0f0d
  452. "NUMBER_OF_PROCESSORS"=2
  453. "TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
  454. "DFSTRACINGON"=FALSE
  455. "RoxioCentral"=C:\Program Files\Common Files\Roxio Shared\10.0\Roxio Central36\
  456. "CLASSPATH"=.;C:\Program Files\Java\jdk1.6.0_11\bin\lib\ext\QTJava.zip
  457. "QTJAVA"=C:\Program Files\Java\jdk1.6.0_11\bin\lib\ext\QTJava.zip
  458. "tvdumpflags"=8
  459.  
  460. -----------------EOF-----------------
  461. [/code]
  462.  
  463. [b]Log:[/b]
  464. [code]
  465. Logfile of random's system information tool 1.06 (written by random/random)
  466. Run by Santa at 2010-02-09 16:39:16
  467. Microsoft® Windows Vista™ Home Premium  Service Pack 1
  468. System drive C: has 148 GB (65%) free of 228 GB
  469. Total RAM: 3061 MB (48% free)
  470.  
  471. Logfile of Trend Micro HijackThis v2.0.2
  472. Scan saved at 4:39:53 PM, on 2/9/2010
  473. Platform: Windows Vista SP1 (WinNT 6.00.1905)
  474. MSIE: Internet Explorer v8.00 (8.00.6001.18882)
  475. Boot mode: Normal
  476.  
  477. Running processes:
  478. C:\Windows\system32\taskeng.exe
  479. C:\Windows\system32\Dwm.exe
  480. C:\Windows\system32\taskeng.exe
  481. C:\Windows\Explorer.EXE
  482. C:\Program Files\Alwil Software\Avast4\ashDisp.exe
  483. C:\Program Files\Java\jdk1.6.0_11\bin\bin\jusched.exe
  484. C:\Windows\V0230Mon.exe
  485. C:\Windows\System32\wpcumi.exe
  486. C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
  487. C:\Program Files\iTunes\iTunesHelper.exe
  488. C:\Windows\ehome\ehtray.exe
  489. C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
  490. C:\Program Files\Windows Media Player\wmpnscfg.exe
  491. C:\Users\Santa\AppData\Local\Google\Update\GoogleUpdate.exe
  492. C:\Windows\ehome\ehmsas.exe
  493. C:\Windows\system32\wuauclt.exe
  494. C:\Program Files\Mozilla Firefox\firefox.exe
  495. C:\Windows\system32\SearchFilterHost.exe
  496. C:\Users\Santa\Desktop\RSIT.exe
  497. C:\Windows\system32\SearchProtocolHost.exe
  498. C:\Program Files\trend micro\Santa.exe
  499.  
  500. R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
  501. R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
  502. R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
  503. R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
  504. R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
  505. R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
  506. O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
  507. O2 - BHO: ZoneAlarm Toolbar Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
  508. O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
  509. O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
  510. O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
  511. O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - (no file)
  512. O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
  513. O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jdk1.6.0_11\bin\bin\jp2ssv.dll
  514. O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.33.0\gears.dll
  515. O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - (no file)
  516. O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
  517. O3 - Toolbar: ZoneAlarm Toolbar - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
  518. O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
  519. O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
  520. O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jdk1.6.0_11\bin\bin\jusched.exe"
  521. O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
  522. O4 - HKLM\..\Run: [V0230Mon.exe] C:\Windows\V0230Mon.exe
  523. O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
  524. O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
  525. O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
  526. O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
  527. O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
  528. O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
  529. O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
  530. O4 - HKCU\..\Run: [Google Update] "C:\Users\Santa\AppData\Local\Google\Update\GoogleUpdate.exe" /c
  531. O4 - HKUS\S-1-5-21-1864734467-1502112414-1167469204-1014\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Guest User')
  532. O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
  533. O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
  534. O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.33.0\gears.dll
  535. O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.33.0\gears.dll
  536. O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - (no file)
  537. O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
  538. O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
  539. O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
  540. O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
  541. O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
  542. O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
  543. O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
  544. O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
  545. O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
  546. O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
  547. O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
  548. O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
  549. O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
  550. O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
  551. O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_2ba5baa4\aestsrv.exe
  552. O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
  553. O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
  554. O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
  555. O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
  556. O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
  557. O23 - Service: Kaspersky Anti-Virus (AVP) - ALWIL Software - (no file)
  558. O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
  559. O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
  560. O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
  561. O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
  562. O23 - Service: Google Update Service (gupdate1c9af2a4ed18150) (gupdate1c9af2a4ed18150) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
  563. O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
  564. O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
  565. O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
  566. O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
  567. O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
  568. O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
  569. O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_2ba5baa4\STacSV.exe
  570. O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
  571. O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe
  572. O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
  573. O23 - Service: TrueVector Internet Monitor (vsmon) - Unknown owner - C:\Windows\System32\ZoneLabs\vsmon.exe (file missing)
  574. O23 - Service: Stardock WindowBlinds (WindowBlinds) - Stardock Corporation - C:\Program Files\Stardock\Object Desktop\WindowBlinds\vistasrv.exe
  575. O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
  576. O23 - Service: z2 Remote2PC Server (z2 R2PC Server) - z2 Software - C:\Program Files\z2 Remote2PC\R2PCServ.exe
  577.  
  578. --
  579. End of file - 9778 bytes
  580.  
  581. ======Scheduled tasks folder======
  582.  
  583. C:\Windows\tasks\Google Software Updater.job
  584. C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
  585. C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
  586. C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1864734467-1502112414-1167469204-1000Core.job
  587. C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1864734467-1502112414-1167469204-1000UA.job
  588.  
  589. ======Registry dump======
  590.  
  591. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
  592. Adobe PDF Link Helper - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]
  593.  
  594. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}]
  595. ZoneAlarm Toolbar Registrar - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll [2009-10-14 578928]
  596.  
  597. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
  598. Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
  599.  
  600. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
  601. Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-12-08 263280]
  602.  
  603. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
  604. Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll [2009-12-08 764912]
  605.  
  606. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b0cda128-b425-4eef-a174-61a11ac5dbf8}]
  607. AIM Toolbar Loader
  608.  
  609. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA6319C0-31B7-401E-A518-A07C3DB8F777}]
  610. CBrowserHelperObject Object - C:\Program Files\Dell\BAE\BAE.dll [2006-11-09 98304]
  611.  
  612. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
  613. Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jdk1.6.0_11\bin\bin\jp2ssv.dll [2009-10-11 41760]
  614.  
  615. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53}]
  616. Google Gears Helper - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.33.0\gears.dll [2009-10-16 2101248]
  617.  
  618. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
  619. {61539ecd-cc67-4437-a03c-9aaccbd14326} -  []
  620. {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-12-08 263280]
  621. {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - ZoneAlarm Toolbar - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll [2009-10-14 578928]
  622.  
  623. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  624. "avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-02-05 81000]
  625. "Broadcom Wireless Manager UI"=C:\Windows\system32\WLTRAY.exe [2008-11-17 3810304]
  626. "SunJavaUpdateSched"=C:\Program Files\Java\jdk1.6.0_11\bin\bin\jusched.exe [2009-10-11 149280]
  627. "QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-10 417792]
  628. "V0230Mon.exe"=C:\Windows\V0230Mon.exe [2006-09-07 32768]
  629. "WPCUMI"=C:\Windows\system32\WpcUmi.exe [2006-11-02 176128]
  630. "AdobeCS4ServiceManager"=C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]
  631. "Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2010-01-07 429392]
  632. "iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2010-01-22 141608]
  633.  
  634. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  635. "ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-20 125952]
  636. "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-12-10 39408]
  637. "WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-20 202240]
  638. "Google Update"=C:\Users\Santa\AppData\Local\Google\Update\GoogleUpdate.exe [2009-11-01 135664]
  639.  
  640. [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
  641. c:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
  642.  
  643. [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
  644. C:\Program Files\AIM6\aim6.exe [2009-05-18 49968]
  645.  
  646. [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
  647. C:\Program Files\DellTPad\Apoint.exe [2008-06-30 196608]
  648.  
  649. [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
  650. C:\Windows\system32\WLTRAY.exe [2008-11-17 3810304]
  651.  
  652. [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
  653. C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2006-10-16 1197648]
  654.  
  655. [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dellsupportcenter]
  656. C:\Program Files\Dell Support Center\bin\sprtcmd.exe [2008-10-04 206064]
  657.  
  658. [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
  659. C:\Windows\ehome\ehTray.exe [2008-01-20 125952]
  660.  
  661. [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
  662. C:\Windows\system32\hkcmd.exe [2008-03-10 166424]
  663.  
  664. [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
  665. C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [2007-10-03 178712]
  666.  
  667. [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
  668. C:\Windows\system32\igfxtray.exe [2008-03-10 141848]
  669.  
  670. [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
  671. C:\Program Files\iTunes\iTunesHelper.exe [2010-01-22 141608]
  672.  
  673. [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
  674. C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2010-01-07 429392]
  675.  
  676. [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
  677. C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]
  678.  
  679. [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
  680. C:\Program Files\Dell\MediaDirect\PCMService.exe [2008-01-14 132392]
  681.  
  682. [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
  683. C:\Windows\system32\igfxpers.exe [2008-03-10 133656]
  684.  
  685. [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SightSpeed]
  686. C:\Program Files\Dell Video Chat\DellVideoChat.exe [2008-08-15 4812664]
  687.  
  688. [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
  689. C:\Program Files\Java\jdk1.6.0_11\bin\bin\jusched.exe [2009-10-11 149280]
  690.  
  691. [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
  692. C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-12-10 39408]
  693.  
  694. [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SysTrayApp]
  695. C:\Program Files\IDT\WDM\sttray.exe [2008-08-29 442460]
  696.  
  697. [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\V0230Mon.exe]
  698. C:\Windows\V0230Mon.exe [2006-09-07 32768]
  699.  
  700. [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
  701. C:\Program Files\Windows Defender\MSASCui.exe [2008-01-20 1008184]
  702.  
  703. [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickSet.lnk]
  704. C:\PROGRA~1\Dell\QuickSet\quickset.exe [2008-05-02 1211472]
  705.  
  706. [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Santa^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dell Dock.lnk]
  707. C:\PROGRA~1\Dell\DellDock\DellDock.exe [2009-10-19 1316192]
  708.  
  709. [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Santa^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk]
  710. C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE  []
  711.  
  712. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\GoToAssist]
  713. C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll [2008-12-10 10536]
  714.  
  715. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
  716. C:\Windows\system32\igfxdev.dll [2008-03-10 204800]
  717.  
  718. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
  719. "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
  720.  
  721. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
  722.  
  723. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\GoToAssist]
  724.  
  725. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
  726.  
  727. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
  728.  
  729. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
  730. "LogonHoursAction"=2
  731. "DontDisplayLogonHoursWarnings"=1
  732.  
  733. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
  734. "dontdisplaylastusername"=0
  735. "legalnoticecaption"=
  736. "legalnoticetext"=
  737. "shutdownwithoutlogon"=1
  738. "undockwithoutlogon"=1
  739. "EnableUIADesktopToggle"=0
  740.  
  741. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
  742. "NoDriveTypeAutoRun"=145
  743. "NoDrives"=0
  744.  
  745. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
  746. "NoDriveTypeAutoRun"=
  747. "NoDrives"=
  748.  
  749. [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
  750. "C:\Program Files\xchat\xchat.exe"="C:\Program Files\xchat\xchat.exe:*:Enabled:XChat IRC Client"
  751.  
  752. [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
  753.  
  754. ======File associations======
  755.  
  756. .js - edit - C:\Windows\System32\Notepad.exe %1
  757. .txt - open -
  758.  
  759. ======List of files/folders created in the last 1 months======
  760.  
  761. 2010-02-09 16:39:16 ----D---- C:\rsit
  762. 2010-02-09 16:39:16 ----D---- \rsit
  763. 2010-02-09 16:20:44 ----A---- C:\RootRepeal report 02-09-10 (16-20-44).txt
  764. 2010-02-09 16:20:44 ----A---- \RootRepeal report 02-09-10 (16-20-44).txt
  765. 2010-02-09 15:49:04 ----A---- C:\RootRepeal report 02-09-10 (15-49-04).txt
  766. 2010-02-09 15:49:04 ----A---- \RootRepeal report 02-09-10 (15-49-04).txt
  767. 2010-02-09 15:48:23 ----A---- C:\RootRepeal report 02-09-10 (15-48-23).txt
  768. 2010-02-09 15:48:23 ----A---- \RootRepeal report 02-09-10 (15-48-23).txt
  769. 2010-02-08 14:41:23 ----D---- C:\Program Files\iPod
  770. 2010-02-08 14:41:19 ----D---- C:\Program Files\iTunes
  771. 2010-02-06 22:34:40 ----D---- C:\Avenger
  772. 2010-02-06 22:34:40 ----D---- \Avenger
  773. 2010-02-06 22:34:39 ----A---- C:\avenger.txt
  774. 2010-02-06 22:34:39 ----A---- \avenger.txt
  775. 2010-02-06 19:34:25 ----A---- C:\Windows\ntbtlog.txt
  776. 2010-02-03 23:04:15 ----A---- C:\ComboFix.txt
  777. 2010-02-03 23:04:15 ----A---- \ComboFix.txt
  778. 2010-02-03 22:55:03 ----SHD---- C:\$RECYCLE.BIN
  779. 2010-02-03 22:55:03 ----SHD---- \$RECYCLE.BIN
  780. 2010-02-03 22:28:12 ----A---- C:\Windows\MBR.exe
  781. 2010-02-03 22:28:11 ----A---- C:\Windows\zip.exe
  782. 2010-02-03 22:28:11 ----A---- C:\Windows\SWSC.exe
  783. 2010-02-03 22:28:11 ----A---- C:\Windows\SWREG.exe
  784. 2010-02-03 22:28:11 ----A---- C:\Windows\sed.exe
  785. 2010-02-03 22:28:11 ----A---- C:\Windows\PEV.exe
  786. 2010-02-03 22:28:11 ----A---- C:\Windows\NIRCMD.exe
  787. 2010-02-03 22:28:11 ----A---- C:\Windows\grep.exe
  788. 2010-02-03 22:22:13 ----D---- C:\Qoobox
  789. 2010-02-03 22:22:13 ----D---- \Qoobox
  790. 2010-02-03 22:21:52 ----A---- C:\Windows\SWXCACLS.exe
  791. 2010-02-01 19:34:43 ----A---- C:\Windows\wininit.ini
  792. 2010-02-01 19:15:59 ----D---- C:\Program Files\TrendMicro
  793. 2010-02-01 19:12:00 ----D---- C:\Program Files\Spybot - Search & Destroy
  794. 2010-02-01 18:57:56 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
  795. 2010-01-27 16:58:05 ----D---- C:\Program Files\Common Files\Macrovision Shared
  796. 2010-01-23 01:09:07 ----D---- C:\Adobe CS4
  797. 2010-01-23 01:09:07 ----D---- \Adobe CS4
  798. 2010-01-23 00:12:55 ----D---- C:\Program Files\Common Files\Akamai
  799. 2010-01-22 22:33:20 ----SHD---- C:\Windows\system32\%APPDATA%
  800. 2010-01-22 19:31:52 ----A---- C:\Windows\system32\mshtml.dll
  801. 2010-01-22 19:31:51 ----A---- C:\Windows\system32\ieframe.dll
  802. 2010-01-22 19:31:49 ----A---- C:\Windows\system32\urlmon.dll
  803. 2010-01-22 19:31:49 ----A---- C:\Windows\system32\iertutil.dll
  804. 2010-01-22 19:31:48 ----A---- C:\Windows\system32\wininet.dll
  805. 2010-01-22 19:31:48 ----A---- C:\Windows\system32\occache.dll
  806. 2010-01-22 19:31:48 ----A---- C:\Windows\system32\msfeeds.dll
  807. 2010-01-22 19:31:47 ----A---- C:\Windows\system32\ieui.dll
  808. 2010-01-22 19:31:47 ----A---- C:\Windows\system32\iedkcs32.dll
  809. 2010-01-22 19:31:46 ----A---- C:\Windows\system32\msfeedssync.exe
  810. 2010-01-22 19:31:46 ----A---- C:\Windows\system32\msfeedsbs.dll
  811. 2010-01-22 19:31:46 ----A---- C:\Windows\system32\jsproxy.dll
  812. 2010-01-22 19:31:46 ----A---- C:\Windows\system32\ieUnatt.exe
  813. 2010-01-22 19:31:46 ----A---- C:\Windows\system32\iesysprep.dll
  814. 2010-01-22 19:31:46 ----A---- C:\Windows\system32\iesetup.dll
  815. 2010-01-22 19:31:46 ----A---- C:\Windows\system32\iepeers.dll
  816. 2010-01-22 19:31:46 ----A---- C:\Windows\system32\ie4uinit.exe
  817. 2010-01-22 19:31:45 ----A---- C:\Windows\system32\iernonce.dll
  818. 2010-01-12 20:47:26 ----A---- C:\Windows\system32\t2embed.dll
  819. 2010-01-12 20:47:25 ----A---- C:\Windows\system32\fontsub.dll
  820.  
  821. ======List of files/folders modified in the last 1 months======
  822.  
  823. 2010-02-09 16:39:53 ----D---- C:\Program Files\Trend Micro
  824. 2010-02-09 16:39:33 ----D---- C:\Windows\Prefetch
  825. 2010-02-09 16:39:25 ----D---- C:\Windows\Temp
  826. 2010-02-09 16:13:24 ----D---- C:\Windows\Tasks
  827. 2010-02-09 15:49:37 ----D---- C:\Windows\system32\drivers
  828. 2010-02-09 11:50:16 ----D---- C:\Windows\System32
  829. 2010-02-09 11:50:16 ----A---- C:\Windows\system32\PerfStringBackup.INI
  830. 2010-02-09 11:50:15 ----D---- C:\Windows\inf
  831. 2010-02-09 11:43:53 ----D---- C:\Program Files\z2 Remote2PC
  832. 2010-02-09 11:42:20 ----D---- C:\Windows\system32\catroot2
  833. 2010-02-09 00:33:34 ----SHD---- C:\Windows\Installer
  834. 2010-02-09 00:33:34 ----D---- C:\Config.Msi
  835. 2010-02-09 00:33:34 ----D---- \Config.Msi
  836. 2010-02-08 14:41:23 ----D---- C:\Program Files
  837. 2010-02-08 14:41:23 ----D---- \Program Files
  838. 2010-02-08 14:41:21 ----D---- C:\Program Files\Common Files\Apple
  839. 2010-02-07 01:07:37 ----D---- C:\Windows
  840. 2010-02-07 01:07:37 ----D---- \Windows
  841. 2010-02-06 20:02:37 ----D---- C:\Program Files\Mozilla Firefox
  842. 2010-02-03 23:02:10 ----D---- C:\Windows\ERDNT
  843. 2010-02-03 22:55:07 ----A---- C:\Windows\system.ini
  844. 2010-02-03 22:37:43 ----D---- C:\Windows\AppPatch
  845. 2010-02-03 22:37:38 ----D---- C:\Program Files\Common Files
  846. 2010-02-03 16:02:06 ----D---- C:\Windows\PCHEALTH
  847. 2010-02-02 16:42:43 ----D---- C:\Windows\Icons
  848. 2010-02-01 19:34:44 ----D---- C:\Program Files\Free Offers from Freeze.com
  849. 2010-02-01 19:12:00 ----D---- C:\ProgramData
  850. 2010-02-01 19:12:00 ----D---- \ProgramData
  851. 2010-01-29 18:49:39 ----RD---- C:\Users
  852. 2010-01-29 18:49:39 ----RD---- \Users
  853. 2010-01-29 03:00:15 ----D---- C:\Windows\winsxs
  854. 2010-01-29 03:00:15 ----D---- C:\Program Files\Internet Explorer
  855. 2010-01-27 17:38:52 ----SHD---- C:\System Volume Information
  856. 2010-01-27 17:38:52 ----SHD---- \System Volume Information
  857. 2010-01-27 17:07:52 ----D---- C:\Program Files\Adobe
  858. 2010-01-27 17:06:10 ----D---- C:\Program Files\Common Files\Adobe
  859. 2010-01-27 17:04:17 ----RSD---- C:\Windows\Fonts
  860. 2010-01-26 14:17:40 ----D---- C:\Windows\system32\catroot
  861. 2010-01-25 14:16:13 ----D---- C:\Windows\system32\Tasks
  862. 2010-01-23 03:15:44 ----D---- C:\Windows\system32\migration
  863. 2010-01-22 22:31:12 ----D---- C:\Program Files\Microsoft Silverlight
  864. 2010-01-22 22:11:10 ----D---- C:\Program Files\CCleaner
  865. 2010-01-22 22:09:10 ----D---- C:\Windows\Debug
  866. 2010-01-14 11:12:06 ----N---- C:\Windows\system32\MpSigStub.exe
  867. 2010-01-14 03:02:36 ----D---- C:\Program Files\Windows Mail
  868. 2010-01-12 20:02:47 ----HD---- C:\Program Files\InstallShield Installation Information
  869. 2010-01-12 20:02:24 ----D---- C:\Program Files\Creative
  870. 2010-01-12 19:42:46 ----RSD---- C:\Windows\assembly
  871. 2010-01-12 19:42:25 ----D---- C:\Program Files\Microsoft Visual Studio 9.0
  872. 2010-01-12 19:42:25 ----D---- C:\Program Files\Common Files\microsoft shared
  873. 2010-01-12 19:35:56 ----D---- C:\Program Files\Google
  874.  
  875. ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
  876.  
  877. R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2009-02-05 23152]
  878. R1 aswSP;avast! Self Protection; C:\Windows\system32\drivers\aswSP.sys [2009-02-05 114768]
  879. R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2009-02-05 51376]
  880. R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\System32\DRIVERS\cmdguard.sys [2009-05-28 130080]
  881. R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2009-05-28 28704]
  882. R2 adfs;adfs; C:\Windows\system32\drivers\adfs.sys [2008-08-14 74720]
  883. R2 aswFsBlk;aswFsBlk; C:\Windows\system32\DRIVERS\aswFsBlk.sys [2009-02-05 20560]
  884. R2 aswMonFlt;aswMonFlt; C:\Windows\system32\DRIVERS\aswMonFlt.sys [2009-02-05 51792]
  885. R2 ISWKL;ZoneAlarm Toolbar ISWKL; \??\C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys [2009-10-14 25208]
  886. R2 LMIRfsDriver;LogMeIn Remote File System Driver; \??\C:\Windows\system32\drivers\LMIRfsDriver.sys [2008-07-24 47640]
  887. R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2008-03-10 46592]
  888. R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2008-03-10 43008]
  889. R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2008-03-10 38400]
  890. R2 RMCAST;RMCAST (Pgm) Protocol Driver; C:\Windows\system32\DRIVERS\RMCAST.sys [2008-12-10 113664]
  891. R2 Vsdatant;Zone Alarm Firewall Driver; C:\Windows\system32\DRIVERS\vsdatant.sys [2009-11-22 446664]
  892. R3 ApfiltrService;Alps Touch Pad Filter Driver for Windows 2000/XP/Vista; C:\Windows\system32\DRIVERS\Apfiltr.sys [2008-06-30 170032]
  893. R3 BCM43XX;Dell Wireless WLAN Card Driver; C:\Windows\system32\DRIVERS\bcmwl6.sys [2008-11-17 1331192]
  894. R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-20 14208]
  895. R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
  896. R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-03-10 2302976]
  897. R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service; C:\Windows\system32\drivers\IntcHdmi.sys [2008-03-10 111616]
  898. R3 itecir;ITECIR Infrared Receiver; C:\Windows\system32\DRIVERS\itecir.sys [2008-03-14 54784]
  899. R3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\k57nd60x.sys [2008-03-10 203264]
  900. R3 KeyScrambler;KeyScrambler; C:\Windows\System32\drivers\keyscrambler.sys [2009-10-04 115312]
  901. R3 lmimirr;lmimirr; C:\Windows\system32\DRIVERS\lmimirr.sys [2008-07-24 10144]
  902. R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2010-01-07 19160]
  903. R3 OA001Ufd;Creative Camera OA001 Upper Filter Driver; C:\Windows\system32\DRIVERS\OA001Ufd.sys [2008-10-05 144672]
  904. R3 OA001Vid;Creative Camera OA001 Function Driver; C:\Windows\system32\DRIVERS\OA001Vid.sys [2008-10-05 277440]
  905. R3 radpms;Driver for RADPMS Device; C:\Windows\system32\DRIVERS\radpms.sys [2008-07-24 12192]
  906. R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-20 88576]
  907. R3 STHDA;IDT High Definition Audio CODEC; C:\Windows\system32\DRIVERS\stwrt.sys [2008-08-29 382976]
  908. R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-20 11264]
  909. S1 kl1;kl1; C:\Windows\system32\DRIVERS\kl1.sys []
  910. S1 KLIF;Kaspersky Lab Driver; C:\Windows\system32\DRIVERS\klif.sys []
  911. S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter; C:\Windows\system32\DRIVERS\klim6.sys []
  912. S1 SymIM;Symantec Network Security Intermediate Filter Driver; C:\Windows\system32\DRIVERS\SymIMv.sys []
  913. S2 LMIInfo;LogMeIn Kernel Information Provider; \??\C:\Program Files\LogMeIn\x86\RaInfo.sys []
  914. S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2008-01-20 179712]
  915. S3 BCM42RLY;BCM42RLY; C:\Windows\system32\drivers\BCM42RLY.sys [2008-11-17 18424]
  916. S3 catchme;catchme; \??\C:\Windows\TEMP\catchme.sys []
  917. S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-20 5632]
  918. S3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\Windows\system32\DRIVERS\e1e6032.sys [2008-01-20 220672]
  919. S3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys []
  920. S3 GarenaPEngine;GarenaPEngine; \??\C:\Users\Santa\AppData\Local\Temp\FKOF70.tmp []
  921. S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.12.1; C:\Windows\system32\drivers\libusb0.sys [2007-03-20 28672]
  922. S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver; C:\Windows\system32\DRIVERS\ManyCam.sys [2008-01-14 21632]
  923. S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-20 8192]
  924. S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-20 5888]
  925. S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-20 5504]
  926. S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-20 6016]
  927. S3 ntkvpn;Loki VPN Driver Service; C:\Windows\system32\DRIVERS\ntkvpn.sys []
  928. S3 R300;R300; C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-01 2028032]
  929. S3 SUPERWEBCAM;SuperWebcam, WDM Virtual Video Capture Device; C:\Windows\system32\DRIVERS\superwebcam.sys [2006-06-27 31872]
  930. S3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS []
  931. S3 tap0901;TAP-Win32 Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2008-11-19 25216]
  932. S3 taphss;Anchorfree HSS Adapter; C:\Windows\system32\DRIVERS\taphss.sys [2009-09-15 32768]
  933. S3 tapvpn;TAP VPN Adapter; C:\Windows\system32\DRIVERS\tapvpn.sys [2008-01-23 27136]
  934. S3 UMPass;Microsoft UMPass Driver; C:\Windows\system32\DRIVERS\umpass.sys [2008-01-20 7680]
  935. S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys []
  936. S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2009-08-28 40448]
  937. S3 usbaudio;USB Audio Driver (WDM); C:\Windows\system32\drivers\usbaudio.sys [2008-01-20 73088]
  938. S3 V0230Vfx;V0230Vfx; C:\Windows\system32\DRIVERS\V0230Vfx.sys [2006-03-24 6272]
  939. S3 V0230VID;Live! Cam Video IM Pro; C:\Windows\system32\DRIVERS\V0230VID.sys [2007-08-07 509760]
  940. S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\Windows\system32\DRIVERS\VBoxNetAdp.sys [2009-10-07 94992]
  941. S3 VBoxNetFlt;VBoxNetFlt Service; C:\Windows\system32\DRIVERS\VBoxNetFlt.sys []
  942. S3 VMnetAdapter;VMware Virtual Ethernet Adapter Driver; C:\Windows\system32\DRIVERS\vmnetadapter.sys []
  943. S3 vsdatant7;vsdatant7; C:\Windows\System32\drivers\vsdatant.win7.sys []
  944. S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-20 39936]
  945. S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-20 83328]
  946. S3 xusb21;Xbox 360 Wireless Receiver Driver Service 21; C:\Windows\system32\DRIVERS\xusb21.sys [2007-08-28 55808]
  947. S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-20 6656]
  948. S4 LMIRfsClientNP;LMIRfsClientNP; C:\Windows\system32\drivers\LMIRfsClientNP.sys []
  949. S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-20 386616]
  950. S4 RsFx0102;RsFx0102 Driver; C:\Windows\system32\DRIVERS\RsFx0102.sys [2008-07-10 242712]
  951.  
  952. ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
  953.  
  954. R2 AESTFilters;Andrea ST Filters Service; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_2ba5baa4\aestsrv.exe [2008-08-29 73728]
  955. R2 Akamai;Akamai NetSession Interface; C:\Windows\System32\svchost.exe [2008-01-20 21504]
  956. R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
  957. R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-02-05 18752]
  958. R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-02-05 138680]
  959. R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
  960. R2 DockLoginService;Dock Login Service; C:\Program Files\Dell\DellDock\DockLogin.exe [2009-06-09 155648]
  961. R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe [2007-10-03 358936]
  962. R2 IswSvc;ZoneAlarm Toolbar IswSvc; C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe [2009-10-14 476528]
  963. R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2010-01-07 236368]
  964. R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2008-07-10 40999448]
  965. R2 sprtsvc_DellSupportCenter;SupportSoft Sprocket Service (DellSupportCenter); C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2008-10-04 201968]
  966. R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-07-10 98840]
  967. R2 STacSV;Audio Service; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_2ba5baa4\STacSV.exe [2008-08-29 225362]
  968. R2 TeamViewer5;TeamViewer 5; C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe [2009-12-17 185640]
  969. R2 Viewpoint Manager Service;Viewpoint Manager Service; C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
  970. R2 WindowBlinds;Stardock WindowBlinds; C:\Program Files\Stardock\Object Desktop\WindowBlinds\vistasrv.exe [2008-08-29 230648]
  971. R2 wltrysvc;Dell Wireless WLAN Tray Service; C:\Windows\System32\WLTRYSVC.EXE [2008-11-17 26112]
  972. R2 z2 R2PC Server;z2 Remote2PC Server; C:\Program Files\z2 Remote2PC\R2PCServ.exe [2007-08-26 512000]
  973. R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-02-05 254040]
  974. R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-02-05 352920]
  975. R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2010-01-22 545576]
  976. S2 gupdate1c9af2a4ed18150;Google Update Service (gupdate1c9af2a4ed18150); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-03-27 133104]
  977. S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-21 190448]
  978. S2 vsmon;TrueVector Internet Monitor; C:\Windows\System32\ZoneLabs\vsmon.exe -service []
  979. S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-01-27 655624]
  980. S3 GoToAssist;GoToAssist; C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe [2008-12-10 16680]
  981. S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
  982. S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
  983. S3 stllssvr;stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2008-03-24 74384]
  984. S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
  985. S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-10 47128]
  986. S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2008-07-10 369688]
  987. S4 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-07-10 258072]
  988.  
  989. -----------------EOF-----------------
  990. [/code]
  991.  
  992. [b]RootRepeal:[/b]
  993. [code]ROOTREPEAL (c) AD, 2007-2009
  994. ==================================================
  995. Scan Start Time:                2010/02/09 15:49
  996. Program Version:                Version 1.3.5.0
  997. Windows Version:                Windows Vista SP1
  998. ==================================================
  999.  
  1000. Drivers
  1001. -------------------
  1002. Name: dump_iaStor.sys
  1003. Image Path: C:\Windows\System32\Drivers\dump_iaStor.sys
  1004. Address: 0x8A90A000     Size: 815104    File Visible: No        Signed: -
  1005. Status: -
  1006.  
  1007. Name: rootrepeal.sys
  1008. Image Path: C:\Windows\system32\drivers\rootrepeal.sys
  1009. Address: 0xB3777000     Size: 49152     File Visible: No        Signed: -
  1010. Status: -
  1011.  
  1012. Name: spmt.sys
  1013. Image Path: C:\Windows\System32\Drivers\spmt.sys
  1014. Address: 0x80694000     Size: 1048576   File Visible: No        Signed: -
  1015. Status: -
  1016.  
  1017. Name: sptd
  1018. Image Path: \Driver\sptd
  1019. Address: 0x00000000     Size: 0 File Visible: No        Signed: -
  1020. Status: -
  1021.  
  1022. Hidden/Locked Files
  1023. -------------------
  1024. Path: C:\System Volume Information\{ace728af-ead1-11de-bb25-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  1025. Status: Locked to the Windows API!
  1026.  
  1027. Path: C:\System Volume Information\{ace728ca-ead1-11de-bb25-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  1028. Status: Locked to the Windows API!
  1029.  
  1030. Path: C:\System Volume Information\{ace72928-ead1-11de-bb25-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  1031. Status: Locked to the Windows API!
  1032.  
  1033. Path: C:\System Volume Information\{ace72960-ead1-11de-bb25-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  1034. Status: Locked to the Windows API!
  1035.  
  1036. Path: C:\System Volume Information\{ace729a1-ead1-11de-bb25-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  1037. Status: Locked to the Windows API!
  1038.  
  1039. Path: C:\System Volume Information\{ace729d5-ead1-11de-bb25-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  1040. Status: Locked to the Windows API!
  1041.  
  1042. Path: C:\System Volume Information\{ace72a14-ead1-11de-bb25-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  1043. Status: Locked to the Windows API!
  1044.  
  1045. Path: C:\System Volume Information\{ace72a3e-ead1-11de-bb25-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  1046. Status: Locked to the Windows API!
  1047.  
  1048. Path: C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
  1049. Status: Locked to the Windows API!
  1050.  
  1051. Path: C:\System Volume Information\{be2989c4-e5f3-11de-835b-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  1052. Status: Locked to the Windows API!
  1053.  
  1054. Path: C:\System Volume Information\{f85c0137-f3d5-11de-97b3-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  1055. Status: Locked to the Windows API!
  1056.  
  1057. Path: C:\System Volume Information\{f85c0168-f3d5-11de-97b3-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  1058. Status: Locked to the Windows API!
  1059.  
  1060. Path: C:\System Volume Information\{f85c019d-f3d5-11de-97b3-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  1061. Status: Locked to the Windows API!
  1062.  
  1063. Path: C:\System Volume Information\{f85c01f6-f3d5-11de-97b3-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  1064. Status: Locked to the Windows API!
  1065.  
  1066. Path: C:\System Volume Information\{5a1401ac-f764-11de-9216-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  1067. Status: Locked to the Windows API!
  1068.  
  1069. Path: C:\System Volume Information\{7201103f-e647-11de-8870-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  1070. Status: Locked to the Windows API!
  1071.  
  1072. Path: C:\System Volume Information\{7201105b-e647-11de-8870-002219d9fde2}{3808876b-c176-4e48-b7ae-04046e6cc752}
  1073. Status: Locked to the Windows API!
  1074.  
  1075. Path: C:\$RECYCLE.BIN\S-1-5-21-1864734467-1502112414-1167469204-1000\$I7KHDVO.dat
  1076. Status: Visible to the Windows API, but not on disk.
  1077.  
  1078. Path: C:\$RECYCLE.BIN\S-1-5-21-1864734467-1502112414-1167469204-1000\$I9B31E5.dmp
  1079. Status: Visible to the Windows API, but not on disk.
  1080.  
  1081. Path: C:\$RECYCLE.BIN\S-1-5-21-1864734467-1502112414-1167469204-1000\$IWUDRLF.txt
  1082. Status: Visible to the Windows API, but not on disk.
  1083.  
  1084. Path: C:\$RECYCLE.BIN\S-1-5-21-1864734467-1502112414-1167469204-1000\$R7KHDVO.dat
  1085. Status: Visible to the Windows API, but not on disk.
  1086.  
  1087. Path: C:\$RECYCLE.BIN\S-1-5-21-1864734467-1502112414-1167469204-1000\$R9B31E5.dmp
  1088. Status: Visible to the Windows API, but not on disk.
  1089.  
  1090. Path: C:\$RECYCLE.BIN\S-1-5-21-1864734467-1502112414-1167469204-1000\$RWUDRLF.txt
  1091. Status: Visible to the Windows API, but not on disk.
  1092.  
  1093. Path: C:\Windows\System32\GATHER~1.VBS
  1094. Status: Locked to the Windows API!
  1095.  
  1096. Path: C:\ProgramData\Microsoft\Windows Defender\Quarantine
  1097. Status: Locked to the Windows API!
  1098.  
  1099. Path: C:\Windows\Microsoft.NET\Framework\NETFXS~1.HKF
  1100. Status: Locked to the Windows API!
  1101.  
  1102. Path: C:\Windows\System32\drivers\sfi.dat
  1103. Status: Locked to the Windows API!
  1104.  
  1105. Path: c:\windows\temp\dwdd703.tmp\rootrepeal.exe.hu.kdmp
  1106. Status: Allocation size mismatch (API: 26476544, Raw: 0)
  1107.  
  1108. Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1833_none_d08b763a442c70c2.cat
  1109. Status: Locked to the Windows API!
  1110.  
  1111. Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_10b2f55f9bffb8f8.cat
  1112. Status: Locked to the Windows API!
  1113.  
  1114. Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_11ecb0ab9b2caf3c.cat
  1115. Status: Locked to the Windows API!
  1116.  
  1117. Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.1833_none_4dddbf6711947267.cat
  1118. Status: Locked to the Windows API!
  1119.  
  1120. Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8dd7dea5d5a7a18a.cat
  1121. Status: Locked to the Windows API!
  1122.  
  1123. Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8a14c0566bec5b24.cat
  1124. Status: Locked to the Windows API!
  1125.  
  1126. Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.1833_none_03c84dcc205e88fb.cat
  1127. Status: Locked to the Windows API!
  1128.  
  1129. Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_bcb86ed6ac711f91.cat
  1130. Status: Locked to the Windows API!
  1131.  
  1132. Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.163_none_91949b06671d08ae.cat
  1133. Status: Locked to the Windows API!
  1134.  
  1135. Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_none_5c4003bc63e949f6.cat
  1136. Status: Locked to the Windows API!
  1137.  
  1138. Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1833_none_516c26fb0f4a960b.cat
  1139. Status: Locked to the Windows API!
  1140.  
  1141. Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d131.cat
  1142. Status: Locked to the Windows API!
  1143.  
  1144. Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.163_none_10b3ea459bfee365.cat
  1145. Status: Locked to the Windows API!
  1146.  
  1147. Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.1833_none_cbf00aee470f5fb7.cat
  1148. Status: Locked to the Windows API!
  1149.  
  1150. Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.1833_none_d1c5318643596706.cat
  1151. Status: Locked to the Windows API!
  1152.  
  1153. Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_none_db5f52fb98cb24ad.cat
  1154. Status: Locked to the Windows API!
  1155.  
  1156. Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.1833_none_49ed4131141912ee.cat
  1157. Status: Locked to the Windows API!
  1158.  
  1159. Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.1833_none_4db05f807dd45954.cat
  1160. Status: Locked to the Windows API!
  1161.  
  1162. Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_60a5df56e60dc5df.cat
  1163. Status: Locked to the Windows API!
  1164.  
  1165. Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed.cat
  1166. Status: Locked to the Windows API!
  1167.  
  1168. Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d08d7da0442a985d.cat
  1169. Status: Locked to the Windows API!
  1170.  
  1171. Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_8e053e8c6967ba9d.cat
  1172. Status: Locked to the Windows API!
  1173.  
  1174. Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_9193a620671dde41.cat
  1175. Status: Locked to the Windows API!
  1176.  
  1177. Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_516e2e610f48bda6.cat
  1178. Status: Locked to the Windows API!
  1179.  
  1180. Path: C:\Windows\winsxs\x86_microsoft-windows-aero_31bf3856ad364e35_6.0.6001.18000_none_abe3118b19699649\aero.msstyles.vgorg
  1181. Status: Locked to the Windows API!
  1182.  
  1183. Path: C:\Windows\winsxs\x86_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6001.18000_none_cd305d2a1ced96e2\shsvcs.dll.vgorg
  1184. Status: Locked to the Windows API!
  1185.  
  1186. Path: C:\Windows\winsxs\x86_microsoft-windows-themeui_31bf3856ad364e35_6.0.6001.18000_none_84fe96731b81293b\themeui.dll.vgorg
  1187. Status: Locked to the Windows API!
  1188.  
  1189. Path: C:\Windows\winsxs\x86_microsoft-windows-uxtheme_31bf3856ad364e35_6.0.6001.18000_none_a5e49ad4068f9b12\uxtheme.dll.vgorg
  1190. Status: Locked to the Windows API!
  1191.  
  1192. Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.18288_none_9bf5c90f051fc5c6\GATHER~1.VBS
  1193. Status: Locked to the Windows API!
  1194.  
  1195. Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.22468_none_9c9507981e2d2ad5\GATHER~1.VBS
  1196. Status: Locked to the Windows API!
  1197.  
  1198. Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18005_none_9e2fbb5f0207ec84\GATHER~1.VBS
  1199. Status: Locked to the Windows API!
  1200.  
  1201. Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18064_none_9deddb8d02397ad3\GATHER~1.VBS
  1202. Status: Locked to the Windows API!
  1203.  
  1204. Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.22170_none_9e68a7441b62d132\GATHER~1.VBS
  1205. Status: Locked to the Windows API!
  1206.  
  1207. Path: C:\Windows\winsxs\x86_netfx-installutil_exe_config_rtm_31bf3856ad364e35_6.0.6000.16720_none_c2e2272db9e7b99c\INSTAL~1.CON
  1208. Status: Locked to the Windows API!
  1209.  
  1210. Path: C:\Windows\winsxs\x86_netfx-installutil_exe_config_rtm_31bf3856ad364e35_6.0.6000.20883_none_c32de54ed3334d11\INSTAL~1.CON
  1211. Status: Locked to the Windows API!
  1212.  
  1213. Path: C:\Windows\winsxs\x86_netfx-installutil_exe_config_rtm_31bf3856ad364e35_6.0.6001.18111_none_c4d43609b70547f3\INSTAL~1.CON
  1214. Status: Locked to the Windows API!
  1215.  
  1216. Path: C:\Windows\winsxs\x86_netfx-installutil_exe_config_rtm_31bf3856ad364e35_6.0.6001.22230_none_c54732b2d0340648\INSTAL~1.CON
  1217. Status: Locked to the Windows API!
  1218.  
  1219. Path: C:\Windows\winsxs\x86_netfx-msbuild_data_files_b03f5f7f11d50a3a_6.0.6001.18111_none_7c8b5cbf426fb0d2\MICROS~1.TAS
  1220. Status: Locked to the Windows API!
  1221.  
  1222. Path: C:\Windows\winsxs\x86_netfx-msbuild_data_files_b03f5f7f11d50a3a_6.0.6001.22230_none_65bfcd5b5c1529e5\MICROS~1.TAS
  1223. Status: Locked to the Windows API!
  1224.  
  1225. Path: C:\Windows\winsxs\x86_netfx-msbuild_targetfiles_b03f5f7f11d50a3a_6.0.6000.16720_none_8d57832b7d03f5e1\MICROS~3.TAR
  1226. Status: Locked to the Windows API!
  1227.  
  1228. Path: C:\Windows\winsxs\x86_netfx-msbuild_targetfiles_b03f5f7f11d50a3a_6.0.6000.20883_none_768f99cf96a63ad4\MICROS~3.TAR
  1229. Status: Locked to the Windows API!
  1230.  
  1231. Path: C:\Windows\winsxs\x86_netfx-uninstallsqlstate_sql_b03f5f7f11d50a3a_6.0.6000.16720_none_a2f69a4627a6df36\UNINST~1.SQL
  1232. Status: Locked to the Windows API!
  1233.  
  1234. Path: C:\Windows\winsxs\x86_netfx-uninstallsqlstate_sql_b03f5f7f11d50a3a_6.0.6000.20883_none_8c2eb0ea41492429\UNINST~1.SQL
  1235. Status: Locked to the Windows API!
  1236.  
  1237. Path: C:\Windows\winsxs\x86_netfx-uninstallsqlstate_sql_b03f5f7f11d50a3a_6.0.6001.18111_none_a2d17efc27f8ebd7\UNINST~1.SQL
  1238. Status: Locked to the Windows API!
  1239.  
  1240. Path: C:\Windows\winsxs\x86_netfx-uninstallsqlstate_sql_b03f5f7f11d50a3a_6.0.6001.22230_none_8c05ef98419e64ea\UNINST~1.SQL
  1241. Status: Locked to the Windows API!
  1242.  
  1243. Path: C:\Windows\winsxs\x86_policy.1.2.microsof..op.security.azroles_31bf3856ad364e35_6.0.6000.16386_none_ea83414c2e75b887\Microsoft.Interop.Security.AzRoles.config
  1244. Status: Locked to the Windows API!
  1245.  
  1246. Path: C:\Windows\winsxs\x86_wcf-m_smsvchost_perf_c_reg_31bf3856ad364e35_6.0.6000.16708_none_2e6f68d711833115\_SMSVC~1.REG
  1247. Status: Locked to the Windows API!
  1248.  
  1249. Path: C:\Windows\winsxs\x86_wcf-m_smsvchost_perf_c_reg_31bf3856ad364e35_6.0.6000.20864_none_2eb424f22ad51329\_SMSVC~1.REG
  1250. Status: Locked to the Windows API!
  1251.  
  1252. Path: C:\Windows\winsxs\x86_wcf-m_smsvchost_perf_c_reg_31bf3856ad364e35_6.0.6001.18096_none_2ff255b70ef48daa\_SMSVC~1.REG
  1253. Status: Locked to the Windows API!
  1254.  
  1255. Path: C:\Windows\winsxs\x86_wcf-m_smsvchost_perf_c_reg_31bf3856ad364e35_6.0.6001.22208_none_30df444827c761d0\_SMSVC~1.REG
  1256. Status: Locked to the Windows API!
  1257.  
  1258. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_reg_31bf3856ad364e35_6.0.6000.16708_none_c4f661e592b1c88e\_SERVI~1.REG
  1259. Status: Locked to the Windows API!
  1260.  
  1261. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_reg_31bf3856ad364e35_6.0.6000.20864_none_c53b1e00ac03aaa2\_SERVI~1.REG
  1262. Status: Locked to the Windows API!
  1263.  
  1264. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_reg_31bf3856ad364e35_6.0.6001.18096_none_c6794ec590232523\_SERVI~1.REG
  1265. Status: Locked to the Windows API!
  1266.  
  1267. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_reg_31bf3856ad364e35_6.0.6001.22208_none_c7663d56a8f5f949\_SERVI~1.REG
  1268. Status: Locked to the Windows API!
  1269.  
  1270. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_vrg_31bf3856ad364e35_6.0.6000.16708_none_cab9e41b8efd69ed\_SERVI~1.VRG
  1271. Status: Locked to the Windows API!
  1272.  
  1273. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_vrg_31bf3856ad364e35_6.0.6000.20864_none_cafea036a84f4c01\_SERVI~1.VRG
  1274. Status: Locked to the Windows API!
  1275.  
  1276. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_vrg_31bf3856ad364e35_6.0.6001.18096_none_cc3cd0fb8c6ec682\_SERVI~1.VRG
  1277. Status: Locked to the Windows API!
  1278.  
  1279. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_vrg_31bf3856ad364e35_6.0.6001.22208_none_cd29bf8ca5419aa8\_SERVI~1.VRG
  1280. Status: Locked to the Windows API!
  1281.  
  1282. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_h_31bf3856ad364e35_6.0.6000.16708_none_f87832f6f02b1a0c\_SERVI~1.H
  1283. Status: Locked to the Windows API!
  1284.  
  1285. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_h_31bf3856ad364e35_6.0.6000.20864_none_f8bcef12097cfc20\_SERVI~1.H
  1286. Status: Locked to the Windows API!
  1287.  
  1288. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_h_31bf3856ad364e35_6.0.6001.18096_none_f9fb1fd6ed9c76a1\_SERVI~1.H
  1289. Status: Locked to the Windows API!
  1290.  
  1291. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_reg_31bf3856ad364e35_6.0.6000.16708_none_74dcd7a292078251\_SERVI~1.REG
  1292. Status: Locked to the Windows API!
  1293.  
  1294. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_reg_31bf3856ad364e35_6.0.6000.20864_none_752193bdab596465\_SERVI~1.REG
  1295. Status: Locked to the Windows API!
  1296.  
  1297. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_reg_31bf3856ad364e35_6.0.6001.18096_none_765fc4828f78dee6\_SERVI~1.REG
  1298. Status: Locked to the Windows API!
  1299.  
  1300. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_reg_31bf3856ad364e35_6.0.6001.22208_none_774cb313a84bb30c\_SERVI~1.REG
  1301. Status: Locked to the Windows API!
  1302.  
  1303. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_vrg_31bf3856ad364e35_6.0.6000.16708_none_7aa059d88e5323b0\_SERVI~1.VRG
  1304. Status: Locked to the Windows API!
  1305.  
  1306. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_vrg_31bf3856ad364e35_6.0.6000.20864_none_7ae515f3a7a505c4\_SERVI~1.VRG
  1307. Status: Locked to the Windows API!
  1308.  
  1309. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_vrg_31bf3856ad364e35_6.0.6001.18096_none_7c2346b88bc48045\_SERVI~1.VRG
  1310. Status: Locked to the Windows API!
  1311.  
  1312. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_vrg_31bf3856ad364e35_6.0.6001.22208_none_7d103549a497546b\_SERVI~1.VRG
  1313. Status: Locked to the Windows API!
  1314.  
  1315. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_h_31bf3856ad364e35_6.0.6000.20864_none_24101549d032590a\_SERVI~1.H
  1316. Status: Locked to the Windows API!
  1317.  
  1318. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_h_31bf3856ad364e35_6.0.6001.22208_none_fae80e68066f4ac7\_SERVI~1.H
  1319. Status: Locked to the Windows API!
  1320.  
  1321. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_reg_31bf3856ad364e35_6.0.6001.22208_none_c8512a7445976b57\_SERVI~1.REG
  1322. Status: Locked to the Windows API!
  1323.  
  1324. Path: C:\Windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_8.0.6001.18865_none_474fb235c4186a78\$$DeleteMe.ieframe.dll.01ca9c1d67aaec80.0002
  1325. Status: Locked to the Windows API!
  1326.  
  1327. Path: C:\Windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_8.0.6001.18865_none_2a50efefa27d9172\$$DeleteMe.iertutil.dll.01ca9c1d67a08c40.0001
  1328. Status: Locked to the Windows API!
  1329.  
  1330. Path: C:\Windows\winsxs\x86_netfx-msbuild_targetfiles_b03f5f7f11d50a3a_6.0.6001.18111_none_8d3267e17d560282\MICROS~3.TAR
  1331. Status: Locked to the Windows API!
  1332.  
  1333. Path: C:\Windows\winsxs\x86_netfx-msbuild_targetfiles_b03f5f7f11d50a3a_6.0.6001.22230_none_7666d87d96fb7b95\MICROS~3.TAR
  1334. Status: Locked to the Windows API!
  1335.  
  1336. Path: C:\Windows\winsxs\x86_netfx-msbuild_commontypes_schema_b03f5f7f11d50a3a_6.0.6000.16720_none_7081409dee51e2d7\MICROS~1.XSD
  1337. Status: Locked to the Windows API!
  1338.  
  1339. Path: C:\Windows\winsxs\x86_netfx-msbuild_commontypes_schema_b03f5f7f11d50a3a_6.0.6000.20883_none_59b9574207f427ca\MICROS~1.XSD
  1340. Status: Locked to the Windows API!
  1341.  
  1342. Path: C:\Windows\winsxs\x86_netfx-msbuild_commontypes_schema_b03f5f7f11d50a3a_6.0.6001.18111_none_705c2553eea3ef78\MICROS~1.XSD
  1343. Status: Locked to the Windows API!
  1344.  
  1345. Path: C:\Windows\winsxs\x86_netfx-msbuild_commontypes_schema_b03f5f7f11d50a3a_6.0.6001.22230_none_599095f00849688b\MICROS~1.XSD
  1346. Status: Locked to the Windows API!
  1347.  
  1348. Path: C:\Windows\winsxs\x86_netfx-msbuild_core_schema__b03f5f7f11d50a3a_6.0.6000.16720_none_b462fc0cbe880bcb\MICROS~1.XSD
  1349. Status: Locked to the Windows API!
  1350.  
  1351. Path: C:\Windows\winsxs\x86_netfx-msbuild_core_schema__b03f5f7f11d50a3a_6.0.6000.20883_none_9d9b12b0d82a50be\MICROS~1.XSD
  1352. Status: Locked to the Windows API!
  1353.  
  1354. Path: C:\Windows\winsxs\x86_netfx-msbuild_core_schema__b03f5f7f11d50a3a_6.0.6001.18111_none_b43de0c2beda186c\MICROS~1.XSD
  1355. Status: Locked to the Windows API!
  1356.  
  1357. Path: C:\Windows\winsxs\x86_netfx-msbuild_core_schema__b03f5f7f11d50a3a_6.0.6001.22230_none_9d72515ed87f917f\MICROS~1.XSD
  1358. Status: Locked to the Windows API!
  1359.  
  1360. Path: C:\Windows\winsxs\x86_netfx-msbuild_data_files_b03f5f7f11d50a3a_6.0.6000.16720_none_7cb07809421da431\MICROS~1.TAS
  1361. Status: Locked to the Windows API!
  1362.  
  1363. Path: C:\Windows\winsxs\x86_netfx-msbuild_data_files_b03f5f7f11d50a3a_6.0.6000.20883_none_65e88ead5bbfe924\MICROS~1.TAS
  1364. Status: Locked to the Windows API!
  1365.  
  1366. Path: C:\Windows\winsxs\x86_netfx-data_perf_h_b03f5f7f11d50a3a_6.0.6000.16720_none_ea4958dde0dcb61b\_DATAP~1.H
  1367. Status: Locked to the Windows API!
  1368.  
  1369. Path: C:\Windows\winsxs\x86_netfx-data_perf_h_b03f5f7f11d50a3a_6.0.6000.16720_none_ea4958dde0dcb61b\_DATAP~2.H
  1370. Status: Locked to the Windows API!
  1371.  
  1372. Path: C:\Windows\winsxs\x86_netfx-data_perf_h_b03f5f7f11d50a3a_6.0.6000.20883_none_d3816f81fa7efb0e\_DATAP~1.H
  1373. Status: Locked to the Windows API!
  1374.  
  1375. Path: C:\Windows\winsxs\x86_netfx-data_perf_h_b03f5f7f11d50a3a_6.0.6000.20883_none_d3816f81fa7efb0e\_DATAP~2.H
  1376. Status: Locked to the Windows API!
  1377.  
  1378. Path: C:\Windows\winsxs\x86_netfx-data_perf_h_b03f5f7f11d50a3a_6.0.6001.18111_none_ea243d93e12ec2bc\_DATAP~1.H
  1379. Status: Locked to the Windows API!
  1380.  
  1381. Path: C:\Windows\winsxs\x86_netfx-data_perf_h_b03f5f7f11d50a3a_6.0.6001.18111_none_ea243d93e12ec2bc\_DATAP~2.H
  1382. Status: Locked to the Windows API!
  1383.  
  1384. Path: C:\Windows\winsxs\x86_netfx-data_perf_h_b03f5f7f11d50a3a_6.0.6001.22230_none_d358ae2ffad43bcf\_DATAP~1.H
  1385. Status: Locked to the Windows API!
  1386.  
  1387. Path: C:\Windows\winsxs\x86_netfx-data_perf_h_b03f5f7f11d50a3a_6.0.6001.22230_none_d358ae2ffad43bcf\_DATAP~2.H
  1388. Status: Locked to the Windows API!
  1389.  
  1390. Path: C:\Windows\winsxs\x86_netfx-csc_exe_config_b03f5f7f11d50a3a_6.0.6000.16720_none_879a188098bde787\CSCEXE~1.CON
  1391. Status: Locked to the Windows API!
  1392.  
  1393. Path: C:\Windows\winsxs\x86_netfx-csc_exe_config_b03f5f7f11d50a3a_6.0.6000.20883_none_70d22f24b2602c7a\CSCEXE~1.CON
  1394. Status: Locked to the Windows API!
  1395.  
  1396. Path: C:\Windows\winsxs\x86_netfx-csc_exe_config_b03f5f7f11d50a3a_6.0.6001.18111_none_8774fd36990ff428\CSCEXE~1.CON
  1397. Status: Locked to the Windows API!
  1398.  
  1399. Path: C:\Windows\winsxs\x86_netfx-csc_exe_config_b03f5f7f11d50a3a_6.0.6001.22230_none_70a96dd2b2b56d3b\CSCEXE~1.CON
  1400. Status: Locked to the Windows API!
  1401.  
  1402. Path: C:\Windows\winsxs\x86_netfx-dv_aspnetmmc_chm_res_b03f5f7f11d50a3a_6.0.6000.16720_none_f49cbb9015dc43b3\DV_ASP~1.CHM
  1403. Status: Locked to the Windows API!
  1404.  
  1405. Path: C:\Windows\winsxs\x86_netfx-redist_config_files_b03f5f7f11d50a3a_6.0.6000.16720_none_7b4eba45cecd6936\IEEXEC~1.CON
  1406. Status: Locked to the Windows API!
  1407.  
  1408. Path: C:\Windows\winsxs\x86_netfx-redist_config_files_b03f5f7f11d50a3a_6.0.6000.20883_none_6486d0e9e86fae29\IEEXEC~1.CON
  1409. Status: Locked to the Windows API!
  1410.  
  1411. Path: C:\Windows\winsxs\x86_netfx-redist_config_files_b03f5f7f11d50a3a_6.0.6001.18111_none_7b299efbcf1f75d7\IEEXEC~1.CON
  1412. Status: Locked to the Windows API!
  1413.  
  1414. Path: C:\Windows\winsxs\x86_netfx-redist_config_files_b03f5f7f11d50a3a_6.0.6001.22230_none_645e0f97e8c4eeea\IEEXEC~1.CON
  1415. Status: Locked to the Windows API!
  1416.  
  1417. Path: C:\Windows\winsxs\x86_netfx-netfxsbs12_hkf_31bf3856ad364e35_6.0.6000.16720_none_0bca521ee450d037\NETFXS~1.HKF
  1418. Status: Locked to the Windows API!
  1419.  
  1420. Path: C:\Windows\winsxs\x86_netfx-netfxsbs12_hkf_31bf3856ad364e35_6.0.6000.20883_none_0c16103ffd9c63ac\NETFXS~1.HKF
  1421. Status: Locked to the Windows API!
  1422.  
  1423. Path: C:\Windows\winsxs\x86_netfx-netfxsbs12_hkf_31bf3856ad364e35_6.0.6001.18111_none_0dbc60fae16e5e8e\NETFXS~1.HKF
  1424. Status: Locked to the Windows API!
  1425.  
  1426. Path: C:\Windows\winsxs\x86_netfx-netfxsbs12_hkf_31bf3856ad364e35_6.0.6001.22230_none_0e2f5da3fa9d1ce3\NETFXS~1.HKF
  1427. Status: Locked to the Windows API!
  1428.  
  1429. Path: C:\Windows\winsxs\x86_netfx-dv_aspnetmmc_chm_res_b03f5f7f11d50a3a_6.0.6000.20883_none_ddd4d2342f7e88a6\DV_ASP~1.CHM
  1430. Status: Locked to the Windows API!
  1431.  
  1432. Path: C:\Windows\winsxs\x86_netfx-dv_aspnetmmc_chm_res_b03f5f7f11d50a3a_6.0.6001.18111_none_f477a046162e5054\DV_ASP~1.CHM
  1433. Status: Locked to the Windows API!
  1434.  
  1435. Path: C:\Windows\winsxs\x86_netfx-dv_aspnetmmc_chm_res_b03f5f7f11d50a3a_6.0.6001.22230_none_ddac10e22fd3c967\DV_ASP~1.CHM
  1436. Status: Locked to the Windows API!
  1437.  
  1438. Path: C:\Windows\winsxs\x86_netfx-config_files_.._gacutil_exe_config_31bf3856ad364e35_6.0.6000.16720_none_9b01a5fdd9371aff\GACUTI~1.CON
  1439. Status: Locked to the Windows API!
  1440.  
  1441. Path: C:\Windows\winsxs\x86_netfx-config_files_.._gacutil_exe_config_31bf3856ad364e35_6.0.6000.20883_none_9b4d641ef282ae74\GACUTI~1.CON
  1442. Status: Locked to the Windows API!
  1443.  
  1444. Path: C:\Windows\winsxs\x86_netfx-config_files_.._gacutil_exe_config_31bf3856ad364e35_6.0.6001.18111_none_9cf3b4d9d654a956\GACUTI~1.CON
  1445. Status: Locked to the Windows API!
  1446.  
  1447. Path: C:\Windows\winsxs\x86_netfx-config_files_.._gacutil_exe_config_31bf3856ad364e35_6.0.6001.22230_none_9d66b182ef8367ab\GACUTI~1.CON
  1448. Status: Locked to the Windows API!
  1449.  
  1450. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_ini_31bf3856ad364e35_6.0.6001.18096_none_8023fb392e87c40a\_TRANS~1.INI
  1451. Status: Locked to the Windows API!
  1452.  
  1453. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_ini_31bf3856ad364e35_6.0.6001.18096_none_8023fb392e87c40a\_TRANS~2.INI
  1454. Status: Locked to the Windows API!
  1455.  
  1456. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_ini_31bf3856ad364e35_6.0.6001.22208_none_8110e9ca475a9830\_TRANS~1.INI
  1457. Status: Locked to the Windows API!
  1458.  
  1459. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_ini_31bf3856ad364e35_6.0.6001.22208_none_8110e9ca475a9830\_TRANS~2.INI
  1460. Status: Locked to the Windows API!
  1461.  
  1462. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_reg_31bf3856ad364e35_6.0.6000.16708_none_7ab8208b3397ed7d\_TRANS~1.REG
  1463. Status: Locked to the Windows API!
  1464.  
  1465. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_reg_31bf3856ad364e35_6.0.6000.20864_none_7afcdca64ce9cf91\_TRANS~1.REG
  1466. Status: Locked to the Windows API!
  1467.  
  1468. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_reg_31bf3856ad364e35_6.0.6001.18096_none_7c3b0d6b31094a12\_TRANS~1.REG
  1469. Status: Locked to the Windows API!
  1470.  
  1471. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_reg_31bf3856ad364e35_6.0.6001.22208_none_7d27fbfc49dc1e38\_TRANS~1.REG
  1472. Status: Locked to the Windows API!
  1473.  
  1474. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_vrg_31bf3856ad364e35_6.0.6000.16708_none_807ba2c12fe38edc\_TRANS~1.VRG
  1475. Status: Locked to the Windows API!
  1476.  
  1477. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_vrg_31bf3856ad364e35_6.0.6000.20864_none_80c05edc493570f0\_TRANS~1.VRG
  1478. Status: Locked to the Windows API!
  1479.  
  1480. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_vrg_31bf3856ad364e35_6.0.6001.18096_none_81fe8fa12d54eb71\_TRANS~1.VRG
  1481. Status: Locked to the Windows API!
  1482.  
  1483. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_vrg_31bf3856ad364e35_6.0.6001.22208_none_82eb7e324627bf97\_TRANS~1.VRG
  1484. Status: Locked to the Windows API!
  1485.  
  1486. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_vrg_31bf3856ad364e35_6.0.6000.16708_none_c71adcbf2e98b7f5\_SERVI~1.VRG
  1487. Status: Locked to the Windows API!
  1488.  
  1489. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_vrg_31bf3856ad364e35_6.0.6000.20864_none_c75f98da47ea9a09\_SERVI~1.VRG
  1490. Status: Locked to the Windows API!
  1491.  
  1492. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_vrg_31bf3856ad364e35_6.0.6001.18096_none_c89dc99f2c0a148a\_SERVI~1.VRG
  1493. Status: Locked to the Windows API!
  1494.  
  1495. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_vrg_31bf3856ad364e35_6.0.6001.22208_none_c98ab83044dce8b0\_SERVI~1.VRG
  1496. Status: Locked to the Windows API!
  1497.  
  1498. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_h_31bf3856ad364e35_6.0.6000.16708_none_9958372092944487\_SERVI~1.H
  1499. Status: Locked to the Windows API!
  1500.  
  1501. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_h_31bf3856ad364e35_6.0.6000.20864_none_999cf33babe6269b\_SERVI~1.H
  1502. Status: Locked to the Windows API!
  1503.  
  1504. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_h_31bf3856ad364e35_6.0.6001.18096_none_9adb24009005a11c\_SERVI~1.H
  1505. Status: Locked to the Windows API!
  1506.  
  1507. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_h_31bf3856ad364e35_6.0.6001.22208_none_9bc81291a8d87542\_SERVI~1.H
  1508. Status: Locked to the Windows API!
  1509.  
  1510. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_ini_31bf3856ad364e35_6.0.6000.16708_none_78c5c5708f85fc49\_SERVI~1.INI
  1511. Status: Locked to the Windows API!
  1512.  
  1513. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_ini_31bf3856ad364e35_6.0.6000.16708_none_78c5c5708f85fc49\_SERVI~2.INI
  1514. Status: Locked to the Windows API!
  1515.  
  1516. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_ini_31bf3856ad364e35_6.0.6000.20864_none_790a818ba8d7de5d\_SERVI~1.INI
  1517. Status: Locked to the Windows API!
  1518.  
  1519. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_ini_31bf3856ad364e35_6.0.6000.20864_none_790a818ba8d7de5d\_SERVI~2.INI
  1520. Status: Locked to the Windows API!
  1521.  
  1522. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_ini_31bf3856ad364e35_6.0.6001.18096_none_7a48b2508cf758de\_SERVI~1.INI
  1523. Status: Locked to the Windows API!
  1524.  
  1525. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_ini_31bf3856ad364e35_6.0.6001.18096_none_7a48b2508cf758de\_SERVI~2.INI
  1526. Status: Locked to the Windows API!
  1527.  
  1528. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_ini_31bf3856ad364e35_6.0.6001.22208_none_7b35a0e1a5ca2d04\_SERVI~1.INI
  1529. Status: Locked to the Windows API!
  1530.  
  1531. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_ini_31bf3856ad364e35_6.0.6001.22208_none_7b35a0e1a5ca2d04\_SERVI~2.INI
  1532. Status: Locked to the Windows API!
  1533.  
  1534. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_h_31bf3856ad364e35_6.0.6000.16708_none_23cb592eb6e076f6\_SERVI~1.H
  1535. Status: Locked to the Windows API!
  1536.  
  1537. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_h_31bf3856ad364e35_6.0.6000.16708_none_b25b01638e2dbfa3\_TRANS~1.H
  1538. Status: Locked to the Windows API!
  1539.  
  1540. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_h_31bf3856ad364e35_6.0.6000.20864_none_b29fbd7ea77fa1b7\_TRANS~1.H
  1541. Status: Locked to the Windows API!
  1542.  
  1543. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_h_31bf3856ad364e35_6.0.6001.18096_none_b3ddee438b9f1c38\_TRANS~1.H
  1544. Status: Locked to the Windows API!
  1545.  
  1546. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_h_31bf3856ad364e35_6.0.6001.22208_none_b4cadcd4a471f05e\_TRANS~1.H
  1547. Status: Locked to the Windows API!
  1548.  
  1549. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_ini_31bf3856ad364e35_6.0.6000.16708_none_7ea10e5931166775\_TRANS~1.INI
  1550. Status: Locked to the Windows API!
  1551.  
  1552. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_ini_31bf3856ad364e35_6.0.6000.16708_none_7ea10e5931166775\_TRANS~2.INI
  1553. Status: Locked to the Windows API!
  1554.  
  1555. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_ini_31bf3856ad364e35_6.0.6000.20864_none_7ee5ca744a684989\_TRANS~1.INI
  1556. Status: Locked to the Windows API!
  1557.  
  1558. Path: C:\Windows\winsxs\x86_wcf-m_tx_bridge_perf_c_ini_31bf3856ad364e35_6.0.6000.20864_none_7ee5ca744a684989\_TRANS~2.INI
  1559. Status: Locked to the Windows API!
  1560.  
  1561. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_reg_31bf3856ad364e35_6.0.6000.16708_none_c5e14f032f533a9c\_SERVI~1.REG
  1562. Status: Locked to the Windows API!
  1563.  
  1564. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_reg_31bf3856ad364e35_6.0.6000.20864_none_c6260b1e48a51cb0\_SERVI~1.REG
  1565. Status: Locked to the Windows API!
  1566.  
  1567. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_reg_31bf3856ad364e35_6.0.6001.18096_none_c7643be32cc49731\_SERVI~1.REG
  1568. Status: Locked to the Windows API!
  1569.  
  1570. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_h_31bf3856ad364e35_6.0.6001.18096_none_254e460eb451d38b\_SERVI~1.H
  1571. Status: Locked to the Windows API!
  1572.  
  1573. Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_h_31bf3856ad364e35_6.0.6001.22208_none_263b349fcd24a7b1\_SERVI~1.H
  1574. Status: Locked to the Windows API!
  1575.  
  1576. Path: C:\Windows\winsxs\x86_wcf-m_smsvchost_perf_c_h_31bf3856ad364e35_6.0.6000.16708_none_4180b46a5c473b6d\_SMSVC~1.H
  1577. Status: Locked to the Windows API!
  1578.  
  1579. Path: C:\Windows\winsxs\x86_wcf-m_smsvchost_perf_c_h_31bf3856ad36Processes
  1580. -------------------
  1581. Path: System
  1582. PID: 4  Status: Locked to the Windows API!
  1583.  
  1584. Path: C:\Windows\System32\audiodg.exe
  1585. PID: 1388       Status: Locked to the Windows API!
  1586.  
  1587. SSDT
  1588. -------------------
  1589. #: 012  Function Name: NtAdjustPrivilegesToken
  1590. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abe00fa
  1591.  
  1592. #: 021  Function Name: NtAlpcConnectPort
  1593. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abe10a8
  1594.  
  1595. #: 022  Function Name: NtAlpcCreatePort
  1596. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abe02e0
  1597.  
  1598. #: 054  Function Name: NtConnectPort
  1599. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abdf472
  1600.  
  1601. #: 060  Function Name: NtCreateFile
  1602. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d5660d8
  1603.  
  1604. #: 064  Function Name: NtCreateKey
  1605. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d584aa6
  1606.  
  1607. #: 071  Function Name: NtCreatePort
  1608. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abdf150
  1609.  
  1610. #: 075  Function Name: NtCreateSection
  1611. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abdfb0c
  1612.  
  1613. #: 077  Function Name: NtCreateSymbolicLinkObject
  1614. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abe0d7e
  1615.  
  1616. #: 078  Function Name: NtCreateThread
  1617. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abded16
  1618.  
  1619. #: 122  Function Name: NtDeleteFile
  1620. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d566f9a
  1621.  
  1622. #: 123  Function Name: NtDeleteKey
  1623. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d5864bc
  1624.  
  1625. #: 126  Function Name: NtDeleteValueKey
  1626. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d585db2
  1627.  
  1628. #: 129  Function Name: NtDuplicateObject
  1629. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abdea78
  1630.  
  1631. #: 165  Function Name: NtLoadDriver
  1632. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abe0a00
  1633.  
  1634. #: 166  Function Name: NtLoadKey
  1635. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d586e86
  1636.  
  1637. #: 167  Function Name: NtLoadKey2
  1638. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d5870c4
  1639.  
  1640. #: 168  Function Name: NtLoadKeyEx
  1641. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d587576
  1642.  
  1643. #: 174  Function Name: NtMakeTemporaryObject
  1644. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abdf6f6
  1645.  
  1646. #: 186  Function Name: NtOpenFile
  1647. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d566a8c
  1648.  
  1649. #: 194  Function Name: NtOpenProcess
  1650. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abde7a8
  1651.  
  1652. #: 197  Function Name: NtOpenSection
  1653. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abdf986
  1654.  
  1655. #: 201  Function Name: NtOpenThread
  1656. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abde920
  1657.  
  1658. #: 267  Function Name: NtRenameKey
  1659. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d58830c
  1660.  
  1661. #: 268  Function Name: NtReplaceKey
  1662. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d587840
  1663.  
  1664. #: 276  Function Name: NtRequestWaitReplyPort
  1665. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abdf26e
  1666.  
  1667. #: 280  Function Name: NtRestoreKey
  1668. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d587f4c
  1669.  
  1670. #: 286  Function Name: NtSecureConnectPort
  1671. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abe079c
  1672.  
  1673. #: 301  Function Name: NtSetInformationFile
  1674. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d5673a4
  1675.  
  1676. #: 314  Function Name: NtSetSecurityObject
  1677. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d588894
  1678.  
  1679. #: 317  Function Name: NtSetSystemInformation
  1680. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abe0bae
  1681.  
  1682. #: 324  Function Name: NtSetValueKey
  1683. Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x9d5854d6
  1684.  
  1685. #: 326  Function Name: NtShutdownSystem
  1686. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abdf690
  1687.  
  1688. #: 332  Function Name: NtSystemDebugControl
  1689. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abdf87a
  1690.  
  1691. #: 334  Function Name: NtTerminateProcess
  1692. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abdf01a
  1693.  
  1694. #: 335  Function Name: NtTerminateThread
  1695. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abdeee8
  1696.  
  1697. #: 382  Function Name: NtCreateThreadEx
  1698. Status: Hooked by "C:\Windows\System32\DRIVERS\cmdguard.sys" at address 0x8abe03ec
  1699.  
  1700. Stealth Objects
  1701. -------------------
  1702. Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
  1703. Process: System Address: 0x859181f8     Size: 121
  1704.  
  1705. Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
  1706. Process: System Address: 0x859181f8     Size: 121
  1707.  
  1708. Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
  1709. Process: System Address: 0x859181f8     Size: 121
  1710.  
  1711. Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
  1712. Process: System Address: 0x859181f8     Size: 121
  1713.  
  1714. Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
  1715. Process: System Address: 0x859181f8     Size: 121
  1716.  
  1717. Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
  1718. Process: System Address: 0x859181f8     Size: 121
  1719.  
  1720. Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
  1721. Process: System Address: 0x859181f8     Size: 121
  1722.  
  1723. Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
  1724. Process: System Address: 0x859181f8     Size: 121
  1725.  
  1726. Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
  1727. Process: System Address: 0x859181f8     Size: 121
  1728.  
  1729. Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
  1730. Process: System Address: 0x859181f8     Size: 121
  1731.  
  1732. Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
  1733. Process: System Address: 0x859181f8     Size: 121
  1734.  
  1735. Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
  1736. Process: System Address: 0x859181f8     Size: 121
  1737.  
  1738. Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
  1739. Process: System Address: 0x859181f8     Size: 121
  1740.  
  1741. Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
  1742. Process: System Address: 0x859181f8     Size: 121
  1743.  
  1744. Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
  1745. Process: System Address: 0x859181f8     Size: 121
  1746.  
  1747. Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
  1748. Process: System Address: 0x859181f8     Size: 121
  1749.  
  1750. Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
  1751. Process: System Address: 0x859181f8     Size: 121
  1752.  
  1753. Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
  1754. Process: System Address: 0x859181f8     Size: 121
  1755.  
  1756. Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
  1757. Process: System Address: 0x859181f8     Size: 121
  1758.  
  1759. Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
  1760. Process: System Address: 0x859181f8     Size: 121
  1761.  
  1762. Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
  1763. Process: System Address: 0x859181f8     Size: 121
  1764.  
  1765. Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
  1766. Process: System Address: 0x859181f8     Size: 121
  1767.  
  1768. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_CREATE]
  1769. Process: System Address: 0xb058e1f8     Size: 121
  1770.  
  1771. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_CLOSE]
  1772. Process: System Address: 0xb058e1f8     Size: 121
  1773.  
  1774. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_READ]
  1775. Process: System Address: 0xb058e1f8     Size: 121
  1776.  
  1777. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_WRITE]
  1778. Process: System Address: 0xb058e1f8     Size: 121
  1779.  
  1780. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_QUERY_INFORMATION]
  1781. Process: System Address: 0xb058e1f8     Size: 121
  1782.  
  1783. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_SET_INFORMATION]
  1784. Process: System Address: 0xb058e1f8     Size: 121
  1785.  
  1786. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_QUERY_EA]
  1787. Process: System Address: 0xb058e1f8     Size: 121
  1788.  
  1789. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_SET_EA]
  1790. Process: System Address: 0xb058e1f8     Size: 121
  1791.  
  1792. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_FLUSH_BUFFERS]
  1793. Process: System Address: 0xb058e1f8     Size: 121
  1794.  
  1795. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_QUERY_VOLUME_INFORMATION]
  1796. Process: System Address: 0xb058e1f8     Size: 121
  1797.  
  1798. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_SET_VOLUME_INFORMATION]
  1799. Process: System Address: 0xb058e1f8     Size: 121
  1800.  
  1801. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_DIRECTORY_CONTROL]
  1802. Process: System Address: 0xb058e1f8     Size: 121
  1803.  
  1804. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_FILE_SYSTEM_CONTROL]
  1805. Process: System Address: 0xb058e1f8     Size: 121
  1806.  
  1807. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_DEVICE_CONTROL]
  1808. Process: System Address: 0xb058e1f8     Size: 121
  1809.  
  1810. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_SHUTDOWN]
  1811. Process: System Address: 0xb058e1f8     Size: 121
  1812.  
  1813. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_LOCK_CONTROL]
  1814. Process: System Address: 0xb058e1f8     Size: 121
  1815.  
  1816. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_CLEANUP]
  1817. Process: System Address: 0xb058e1f8     Size: 121
  1818.  
  1819. Object: Hidden Code [Driver: fastfat끖Ѝ䵆汳`ㄤ댩ㄤ댩逈虖ヸ댩퍜芶�髹, IRP_MJ_PNP]
  1820. Process: System Address: 0xb058e1f8     Size: 121
  1821.  
  1822. Object: Hidden Code [Driver: usbuhci, IRP_MJ_CREATE]
  1823. Process: System Address: 0x869e8500     Size: 121
  1824.  
  1825. Object: Hidden Code [Driver: usbuhci, IRP_MJ_CLOSE]
  1826. Process: System Address: 0x869e8500     Size: 121
  1827.  
  1828. Object: Hidden Code [Driver: usbuhci, IRP_MJ_DEVICE_CONTROL]
  1829. Process: System Address: 0x869e8500     Size: 121
  1830.  
  1831. Object: Hidden Code [Driver: usbuhci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
  1832. Process: System Address: 0x869e8500     Size: 121
  1833.  
  1834. Object: Hidden Code [Driver: usbuhci, IRP_MJ_POWER]
  1835. Process: System Address: 0x869e8500     Size: 121
  1836.  
  1837. Object: Hidden Code [Driver: usbuhci, IRP_MJ_SYSTEM_CONTROL]
  1838. Process: System Address: 0x869e8500     Size: 121
  1839.  
  1840. Object: Hidden Code [Driver: usbuhci, IRP_MJ_PNP]
  1841. Process: System Address: 0x869e8500     Size: 121
  1842.  
  1843. Object: Hidden Code [Driver: cdrom֟灓摴逈薑, IRP_MJ_CREATE]
  1844. Process: System Address: 0x86a2a4d0     Size: 121
  1845.  
  1846. Object: Hidden Code [Driver: cdrom֟灓摴逈薑, IRP_MJ_CLOSE]
  1847. Process: System Address: 0x86a2a4d0     Size: 121
  1848.  
  1849. Object: Hidden Code [Driver: cdrom֟灓摴逈薑, IRP_MJ_READ]
  1850. Process: System Address: 0x86a2a4d0     Size: 121
  1851.  
  1852. Object: Hidden Code [Driver: cdrom֟灓摴逈薑, IRP_MJ_WRITE]
  1853. Process: System Address: 0x86a2a4d0     Size: 121
  1854.  
  1855. Object: Hidden Code [Driver: cdrom֟灓摴逈薑, IRP_MJ_FLUSH_BUFFERS]
  1856. Process: System Address: 0x86a2a4d0     Size: 121
  1857.  
  1858. Object: Hidden Code [Driver: cdrom֟灓摴逈薑, IRP_MJ_DEVICE_CONTROL]
  1859. Process: System Address: 0x86a2a4d0     Size: 121
  1860.  
  1861. Object: Hidden Code [Driver: cdrom֟灓摴逈薑, IRP_MJ_INTERNAL_DEVICE_CONTROL]
  1862. Process: System Address: 0x86a2a4d0     Size: 121
  1863.  
  1864. Object: Hidden Code [Driver: cdrom֟灓摴逈薑, IRP_MJ_SHUTDOWN]
  1865. Process: System Address: 0x86a2a4d0     Size: 121
  1866.  
  1867. Object: Hidden Code [Driver: cdrom֟灓摴逈薑, IRP_MJ_POWER]
  1868. Process: System Address: 0x86a2a4d0     Size: 121
  1869.  
  1870. Object: Hidden Code [Driver: cdrom֟灓摴逈薑, IRP_MJ_SYSTEM_CONTROL]
  1871. Process: System Address: 0x86a2a4d0     Size: 121
  1872.  
  1873. Object: Hidden Code [Driver: cdrom֟灓摴逈薑, IRP_MJ_PNP]
  1874. Process: System Address: 0x86a2a4d0     Size: 121
  1875.  
  1876. Object: Hidden Code [Driver: Smb前摄�鳾幀虾‘ሊ, IRP_MJ_CREATE]
  1877. Process: System Address: 0x870c1500     Size: 121
  1878.  
  1879. Object: Hidden Code [Driver: Smb前摄�鳾幀虾‘ሊ, IRP_MJ_CLOSE]
  1880. Process: System Address: 0x870c1500     Size: 121
  1881.  
  1882. Object: Hidden Code [Driver: Smb前摄�鳾幀虾‘ሊ, IRP_MJ_DEVICE_CONTROL]
  1883. Process: System Address: 0x870c1500     Size: 121
  1884.  
  1885. Object: Hidden Code [Driver: Smb前摄�鳾幀虾‘ሊ, IRP_MJ_INTERNAL_DEVICE_CONTROL]
  1886. Process: System Address: 0x870c1500     Size: 121
  1887.  
  1888. Object: Hidden Code [Driver: Smb前摄�鳾幀虾‘ሊ, IRP_MJ_CLEANUP]
  1889. Process: System Address: 0x870c1500     Size: 121
  1890.  
  1891. Object: Hidden Code [Driver: Smb前摄�鳾幀虾‘ሊ, IRP_MJ_PNP]
  1892. Process: System Address: 0x870c1500     Size: 121
  1893.  
  1894. Object: Hidden Code [Driver: netbt蛥, IRP_MJ_CREATE]
  1895. Process: System Address: 0x86f5c500     Size: 121
  1896.  
  1897. Object: Hidden Code [Driver: netbt蛥, IRP_MJ_CLOSE]
  1898. Process: System Address: 0x86f5c500     Size: 121
  1899.  
  1900. Object: Hidden Code [Driver: netbt蛥, IRP_MJ_DEVICE_CONTROL]
  1901. Process: System Address: 0x86f5c500     Size: 121
  1902.  
  1903. Object: Hidden Code [Driver: netbt蛥, IRP_MJ_INTERNAL_DEVICE_CONTROL]
  1904. Process: System Address: 0x86f5c500     Size: 121
  1905.  
  1906. Object: Hidden Code [Driver: netbt蛥, IRP_MJ_CLEANUP]
  1907. Process: System Address: 0x86f5c500     Size: 121
  1908.  
  1909. Object: Hidden Code [Driver: netbt蛥, IRP_MJ_PNP]
  1910. Process: System Address: 0x86f5c500     Size: 121
  1911.  
  1912. Object: Hidden Code [Driver: iScsiPrtЎ浍摌뀰蚡ﳰ蚫눀醕, IRP_MJ_CREATE]
  1913. Process: System Address: 0x86a26458     Size: 121
  1914.  
  1915. Object: Hidden Code [Driver: iScsiPrtЎ浍摌뀰蚡ﳰ蚫눀醕, IRP_MJ_CLOSE]
  1916. Process: System Address: 0x86a26458     Size: 121
  1917.  
  1918. Object: Hidden Code [Driver: iScsiPrtЎ浍摌뀰蚡ﳰ蚫눀醕, IRP_MJ_DEVICE_CONTROL]
  1919. Process: System Address: 0x86a26458     Size: 121
  1920.  
  1921. Object: Hidden Code [Driver: iScsiPrtЎ浍摌뀰蚡ﳰ蚫눀醕, IRP_MJ_INTERNAL_DEVICE_CONTROL]
  1922. Process: System Address: 0x86a26458     Size: 121
  1923.  
  1924. Object: Hidden Code [Driver: iScsiPrtЎ浍摌뀰蚡ﳰ蚫눀醕, IRP_MJ_POWER]
  1925. Process: System Address: 0x86a26458     Size: 121
  1926.  
  1927. Object: Hidden Code [Driver: iScsiPrtЎ浍摌뀰蚡ﳰ蚫눀醕, IRP_MJ_SYSTEM_CONTROL]
  1928. Process: System Address: 0x86a26458     Size: 121
  1929.  
  1930. Object: Hidden Code [Driver: iScsiPrtЎ浍摌뀰蚡ﳰ蚫눀醕, IRP_MJ_PNP]
  1931. Process: System Address: 0x86a26458     Size: 121
  1932.  
  1933. Object: Hidden Code [Driver: volmgr, IRP_MJ_CREATE]
  1934. Process: System Address: 0x84b521f8     Size: 121
  1935.  
  1936. Object: Hidden Code [Driver: volmgr, IRP_MJ_READ]
  1937. Process: System Address: 0x84b521f8     Size: 121
  1938.  
  1939. Object: Hidden Code [Driver: volmgr, IRP_MJ_WRITE]
  1940. Process: System Address: 0x84b521f8     Size: 121
  1941.  
  1942. Object: Hidden Code [Driver: volmgr, IRP_MJ_FLUSH_BUFFERS]
  1943. Process: System Address: 0x84b521f8     Size: 121
  1944.  
  1945. Object: Hidden Code [Driver: volmgr, IRP_MJ_DEVICE_CONTROL]
  1946. Process: System Address: 0x84b521f8     Size: 121
  1947.  
  1948. Object: Hidden Code [Driver: volmgr, IRP_MJ_INTERNAL_DEVICE_CONTROL]
  1949. Process: System Address: 0x84b521f8     Size: 121
  1950.  
  1951. Object: Hidden Code [Driver: volmgr, IRP_MJ_SHUTDOWN]
  1952. Process: System Address: 0x84b521f8     Size: 121
  1953.  
  1954. Object: Hidden Code [Driver: volmgr, IRP_MJ_CLEANUP]
  1955. Process: System Address: 0x84b521f8     Size: 121
  1956.  
  1957. Object: Hidden Code [Driver: volmgr, IRP_MJ_POWER]
  1958. Process: System Address: 0x84b521f8     Size: 121
  1959.  
  1960. Object: Hidden Code [Driver: volmgr, IRP_MJ_SYSTEM_CONTROL]
  1961. Process: System Address: 0x84b521f8     Size: 121
  1962.  
  1963. Object: Hidden Code [Driver: volmgr, IRP_MJ_PNP]
  1964. Process: System Address: 0x84b521f8     Size: 121
  1965.  
  1966. Object: Hidden Code [Driver: usbehciІ但塃, IRP_MJ_CREATE]
  1967. Process: System Address: 0x869f9500     Size: 121
  1968.  
  1969. Object: Hidden Code [Driver: usbehciІ但塃, IRP_MJ_CLOSE]
  1970. Process: System Address: 0x869f9500     Size: 121
  1971.  
  1972. Object: Hidden Code [Driver: usbehciІ但塃, IRP_MJ_DEVICE_CONTROL]
  1973. Process: System Address: 0x869f9500     Size: 121
  1974.  
  1975. Object: Hidden Code [Driver: usbehciІ但塃, IRP_MJ_INTERNAL_DEVICE_CONTROL]
  1976. Process: System Address: 0x869f9500     Size: 121
  1977.  
  1978. Object: Hidden Code [Driver: usbehciІ但塃, IRP_MJ_POWER]
  1979. Process: System Address: 0x869f9500     Size: 121
  1980.  
  1981. Object: Hidden Code [Driver: usbehciІ但塃, IRP_MJ_SYSTEM_CONTROL]
  1982. Process: System Address: 0x869f9500     Size: 121
  1983.  
  1984. Object: Hidden Code [Driver: usbehciІ但塃, IRP_MJ_PNP]
  1985. Process: System Address: 0x869f9500     Size: 121
  1986.  
  1987. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_CREATE]
  1988. Process: System Address: 0x85960500     Size: 121
  1989.  
  1990. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_CREATE_NAMED_PIPE]
  1991. Process: System Address: 0x85960500     Size: 121
  1992.  
  1993. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_CLOSE]
  1994. Process: System Address: 0x85960500     Size: 121
  1995.  
  1996. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_READ]
  1997. Process: System Address: 0x85960500     Size: 121
  1998.  
  1999. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_WRITE]
  2000. Process: System Address: 0x85960500     Size: 121
  2001.  
  2002. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_QUERY_INFORMATION]
  2003. Process: System Address: 0x85960500     Size: 121
  2004.  
  2005. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_SET_INFORMATION]
  2006. Process: System Address: 0x85960500     Size: 121
  2007.  
  2008. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_QUERY_EA]
  2009. Process: System Address: 0x85960500     Size: 121
  2010.  
  2011. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_SET_EA]
  2012. Process: System Address: 0x85960500     Size: 121
  2013.  
  2014. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_FLUSH_BUFFERS]
  2015. Process: System Address: 0x85960500     Size: 121
  2016.  
  2017. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_QUERY_VOLUME_INFORMATION]
  2018. Process: System Address: 0x85960500     Size: 121
  2019.  
  2020. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_SET_VOLUME_INFORMATION]
  2021. Process: System Address: 0x85960500     Size: 121
  2022.  
  2023. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_DIRECTORY_CONTROL]
  2024. Process: System Address: 0x85960500     Size: 121
  2025.  
  2026. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_FILE_SYSTEM_CONTROL]
  2027. Process: System Address: 0x85960500     Size: 121
  2028.  
  2029. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_DEVICE_CONTROL]
  2030. Process: System Address: 0x85960500     Size: 121
  2031.  
  2032. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_INTERNAL_DEVICE_CONTROL]
  2033. Process: System Address: 0x85960500     Size: 121
  2034.  
  2035. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_SHUTDOWN]
  2036. Process: System Address: 0x85960500     Size: 121
  2037.  
  2038. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_LOCK_CONTROL]
  2039. Process: System Address: 0x85960500     Size: 121
  2040.  
  2041. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_CLEANUP]
  2042. Process: System Address: 0x85960500     Size: 121
  2043.  
  2044. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_CREATE_MAILSLOT]
  2045. Process: System Address: 0x85960500     Size: 121
  2046.  
  2047. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_QUERY_SECURITY]
  2048. Process: System Address: 0x85960500     Size: 121
  2049.  
  2050. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_SET_SECURITY]
  2051. Process: System Address: 0x85960500     Size: 121
  2052.  
  2053. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_POWER]
  2054. Process: System Address: 0x85960500     Size: 121
  2055.  
  2056. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_SYSTEM_CONTROL]
  2057. Process: System Address: 0x85960500     Size: 121
  2058.  
  2059. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_DEVICE_CHANGE]
  2060. Process: System Address: 0x85960500     Size: 121
  2061.  
  2062. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_QUERY_QUOTA]
  2063. Process: System Address: 0x85960500     Size: 121
  2064.  
  2065. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_SET_QUOTA]
  2066. Process: System Address: 0x85960500     Size: 121
  2067.  
  2068. Object: Hidden Code [Driver: mrxsmb䌀髱І瑎湦܇$, IRP_MJ_PNP]
  2069. Process: System Address: 0x85960500     Size: 121
  2070.  
  2071. Object: Hidden Code [Driver: cdfsЅ瑎硦, IRP_MJ_CREATE]
  2072. Process: System Address: 0xb646c1f8     Size: 121
  2073.  
  2074. Object: Hidden Code [Driver: cdfsЅ瑎硦, IRP_MJ_CLOSE]
  2075. Process: System Address: 0xb646c1f8     Size: 121
  2076.  
  2077. Object: Hidden Code [Driver: cdfsЅ瑎硦, IRP_MJ_READ]
  2078. Process: System Address: 0xb646c1f8     Size: 121
  2079.  
  2080. Object: Hidden Code [Driver: cdfsЅ瑎硦, IRP_MJ_WRITE]
  2081. Process: System Address: 0xb646c1f8     Size: 121
  2082.  
  2083. Object: Hidden Code [Driver: cdfsЅ瑎硦, IRP_MJ_QUERY_INFORMATION]
  2084. Process: System Address: 0xb646c1f8     Size: 121
  2085.  
  2086. Object: Hidden Code [Driver: cdfsЅ瑎硦, IRP_MJ_SET_INFORMATION]
  2087. Process: System Address: 0xb646c1f8     Size: 121
  2088.  
  2089. Object: Hidden Code [Driver: cdfsЅ瑎硦, IRP_MJ_QUERY_VOLUME_INFORMATION]
  2090. Process: System Address: 0xb646c1f8     Size: 121
  2091.  
  2092. Object: Hidden Code [Driver: cdfsЅ瑎硦, IRP_MJ_DIRECTORY_CONTROL]
  2093. Process: System Address: 0xb646c1f8     Size: 121
  2094.  
  2095. Object: Hidden Code [Driver: cdfsЅ瑎硦, IRP_MJ_FILE_SYSTEM_CONTROL]
  2096. Process: System Address: 0xb646c1f8     Size: 121
  2097.  
  2098. Object: Hidden Code [Driver: cdfsЅ瑎硦, IRP_MJ_DEVICE_CONTROL]
  2099. Process: System Address: 0xb646c1f8     Size: 121
  2100.  
  2101. Object: Hidden Code [Driver: cdfsЅ瑎硦, IRP_MJ_SHUTDOWN]
  2102. Process: System Address: 0xb646c1f8     Size: 121
  2103.  
  2104. Object: Hidden Code [Driver: cdfsЅ瑎硦, IRP_MJ_LOCK_CONTROL]
  2105. Process: System Address: 0xb646c1f8     Size: 121
  2106.  
  2107. Object: Hidden Code [Driver: cdfsЅ瑎硦, IRP_MJ_CLEANUP]
  2108. Process: System Address: 0xb646c1f8     Size: 121
  2109.  
  2110. Object: Hidden Code [Driver: cdfsЅ瑎硦, IRP_MJ_PNP]
  2111. Process: System Address: 0xb646c1f8     Size: 121
  2112.  
  2113. ==EOF==
  2114. [/code]
Submit a correction or amendment below. Make A New Post
To highlight particular lines, prefix each line with @h@
Syntax highlighting:
Post expiration:
Post exposure:
Name / Title:
Email: