main.txt:
Deckard's System Scanner v20070411.38
Run by Micey on 2007-04-23 at 09:10:45
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- Last 5 Restore Point(s) --
25: 2007-04-23 07:24:29 UTC - RP134 - Installed Microsoft Office Enterprise 2007
24: 2007-04-22 13:28:32 UTC - RP132 - Installed Microsoft Office Enterprise 2007
23: 2007-04-22 13:12:33 UTC - RP130 - Installed Microsoft Office Enterprise 2007
22: 2007-04-22 12:59:24 UTC - RP128 - Removed Microsoft Office Word MUI (English) 2007
21: 2007-04-22 12:59:09 UTC - RP127 - Removed Microsoft Office Shared Setup Metadata MUI (English) 2007
-- First Restore Point --
1: 2007-04-17 16:39:49 UTC - RP106 - Removed Microsoft Office Enterprise 2007
Backed up registry hives.
Performed disk cleanup.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of HijackThis v1.99.1
Scan saved at 2007-04-23 09:22:50
Platform: Windows Vista (6.00.6000)
MSIE: Internet Explorer (7.0.6000.16386)
Running processes:
C:\Windows\System32\taskeng.exe
C:\Windows\System32\dwm.exe
C:\Windows\explorer.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Windows\autoclk.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Windows\System32\ATWTUSB.EXE
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Windows\ehome\ehmsas.exe
C:\Users\Micey\Desktop\dss.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.2.7.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {67C55A8D-E808-4caa-9EA7-F77102DE0BB6} - C:\Windows\System32\xaiflvli.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [autoclk] autoclk.exe
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [PrintDrive] rundll32.exe "C:\Windows\system32\lvlberpy.dll",setvm
O4 - HKLM\..\Run: [atwtusb] atwtusb.exe
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\RunOnce: [fsc-reg] cmd.exe /c rd /s /q "C:\ProgramData\fsc-reg\"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: hp psc 1000 series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
O4 - Global Startup: hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: hggghhe - C:\Windows\system32\hggghhe.dll
O20 - Winlogon Notify: hgghhge - C:\Windows\system32\hgghhge.dll
O20 - Winlogon Notify: igfxcui - C:\Windows\system32\igfxdev.dll
O20 - Winlogon Notify: opnlmjk - C:\Windows\system32\opnlmjk.dll
O20 - Winlogon Notify: rqrqnom - C:\Windows\system32\rqrqnom.dll
O20 - Winlogon Notify: tuvwxuu - C:\Windows\system32\tuvwxuu.dll
O20 - Winlogon Notify: vtspp - C:\Windows\System32\vtspp.dll
O23 - Service: Adobe LM Service - Adobe Systems - "C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - "C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe"
O23 - Service: Microsoft Office Groove Audit Service - Unknown owner - "C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe"
O23 - Service: O2Micro Flash Memory (O2Flash) - O2Micro International - C:\Windows\System32\o2flash.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\System32\VundoFixSVC.exe
-- File Associations -----------------------------------------------------------
.chm - unable to read key
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 O2MDRDR - c:\windows\system32\drivers\o2media.sys
R0 O2SDRDR - c:\windows\system32\drivers\o2sd.sys
R1 SCDEmu - c:\windows\system32\drivers\scdemu.sys
R3 igfx - c:\windows\system32\drivers\igdkmd32.sys
R3 NETw4v32 (Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit) - c:\windows\system32\drivers\netw4v32.sys
R3 smserial - c:\windows\system32\drivers\smserial.sys
S1 aiptektp (Pen Pad) - c:\windows\system32\drivers\aiptektp.sys
S2 ADILOADER (General Purpose USB Driver (adildr.sys)) - c:\windows\system32\drivers\adildr.sys
S3 adiusbaw (USB ADSL WAN Adapter) - c:\windows\system32\drivers\adiusbaw.sys
S3 ialm - c:\windows\system32\drivers\igdkmd32.sys
S3 NETw3v32 (Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit) - c:\windows\system32\drivers\netw3v32.sys
S3 RT25USBAP (Nintendo Wi-Fi USB Connector Service) - c:\windows\system32\drivers\rt25usbap.sys
S3 SE27bus (Sony Ericsson Device 039 Driver driver (WDM)) - c:\windows\system32\drivers\se27bus.sys
S3 SE27mdfl (Sony Ericsson Device 039 USB WMC Modem Filter) - c:\windows\system32\drivers\se27mdfl.sys
S3 SE27mdm (Sony Ericsson Device 039 USB WMC Modem Driver) - c:\windows\system32\drivers\se27mdm.sys
S3 SE27mgmt (Sony Ericsson Device 039 USB WMC Device Management Drivers (WDM)) - c:\windows\system32\drivers\se27mgmt.sys
S3 se27nd5 (Sony Ericsson Device 039 USB Ethernet Emulation SEMC39 (NDIS)) - c:\windows\system32\drivers\se27nd5.sys
S3 se27unic (Sony Ericsson Device 039 USB Ethernet Emulation SEMC39 (WDM)) - c:\windows\system32\drivers\se27unic.sys
S3 WpdUsb - c:\windows\system32\drivers\wpdusb.sys
S4 sdbus - c:\windows\system32\drivers\sdbus.sys
S4 viamraid - c:\windows\system32\drivers\viamraid.sys
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 msfwsvc (OneCare Firewall) - "c:\program files\microsoft windows onecare live\firewall\msfwsvc.exe"
R2 O2Flash (O2Micro Flash Memory) - c:\windows\system32\o2flash.exe
R2 OneCareMP (OneCare AntiSpyware and AntiVirus) - "c:\program files\microsoft windows onecare live\antivirus\msmpeng.exe"
R2 StarWindService (StarWind iSCSI Service) - c:\program files\alcohol soft\alcohol 120\starwind\starwindservice.exe
R2 TestHandler (Fujitsu Siemens Computers Diagnostic Testhandler) - c:\firststeps\onlinediagnostic\testmanager\testhandler.exe
R2 winss (Windows Live OneCare) - c:\program files\microsoft windows onecare live\winss.exe
S3 FLEXnet Licensing Service - "c:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe"
S3 Microsoft Office Groove Audit Service - "c:\program files\microsoft office\office12\grooveauditservice.exe" (file missing)
S3 VundoFixSvc (VundoFix Service) - vundofixsvc.exe
S3 ZuneNetworkSvc (Zune Network Sharing Service) - "c:\program files\zune\zunenss.exe"
-- Scheduled Tasks -------------------------------------------------------------
2007-04-23 09:20:16 418 --ah----- C:\Windows\Tasks\User_Feed_Synchronization-{B94D58B8-29B7-41FB-B4ED-AF867CAB04CD}.job<USER_F~1.JOB>
-- Files created between 2007-03-23 and 2007-04-23 -----------------------------
-- Find3M Report ---------------------------------------------------------------
2007-04-23 08:42:33 0 d-------- C:\Program Files\Microsoft Visual Studio 8<MICROS~3>
2007-04-23 08:16:59 0 d-------- C:\Program Files\PowerISO
2007-04-22 20:50:32 0 d-------- C:\Program Files\Microsoft Windows OneCare Live<MI7BEA~1>
2007-04-21 10:56:12 0 d-------- C:\Program Files\Hazard Perception 2003-2004<HAZARD~1>
2007-04-21 10:54:22 0 d-------- C:\Program Files\Driving Test Success 2003-2004<DRIVIN~2>
2007-04-20 09:40:35 0 d-------- C:\Program Files\Debugging Tools for Windows<DEBUGG~1>
2007-04-20 09:18:40 0 d---s---- C:\Users\Micey\AppData\Roaming\Microsoft<MICROS~1>
2007-04-16 22:14:47 24576 --a------ C:\Windows\system32\VundoFixSVC.exe<VUNDOF~1.EXE>
2007-04-13 10:18:18 0 d-------- C:\Program Files\MSXML 4.0<MSXML4~1.0>
2007-04-13 09:07:31 0 d-------- C:\Program Files\OpenCanvas.4.06E<OPENCA~1.06E>
2007-04-12 22:29:18 0 d--h----- C:\Program Files\InstallShield Installation Information<INSTAL~1>
2007-04-12 21:44:40 0 d-------- C:\Program Files\Common Files\InstallShield<INSTAL~1>
2007-04-12 21:24:45 774711 ---hs---- C:\Windows\system32\ppstv.ini2<PPSTV~1.INI>
2007-04-12 08:08:39 771279 -----n--- C:\Windows\system32\ppstv.bak2<PPSTV~2.BAK>
2007-04-12 07:47:20 26694 --a------ C:\Windows\system32\opnlmjk.dll
2007-04-11 23:03:08 26694 --a------ C:\Windows\system32\hgghhge.dll
2007-04-11 22:10:00 26694 --a------ C:\Windows\system32\tuvwxuu.dll
2007-04-11 19:15:10 26694 --a------ C:\Windows\system32\rqrqnom.dll
2007-04-11 17:56:50 48708 --a------ C:\Windows\system32\xaiflvli.dll
2007-04-11 17:56:28 280676 ---hs---- C:\Windows\system32\vtspp.dll
2007-04-11 17:51:23 26694 --a------ C:\Windows\system32\hggghhe.dll
2007-04-11 14:25:51 0 d-------- C:\Program Files\Windows Defender<WINDOW~3>
2007-04-11 13:34:47 49664 --a------ C:\Windows\system32\csrsrv.dll
2007-04-11 13:34:46 376320 --a------ C:\Windows\system32\winsrv.dll
2007-04-11 13:18:22 0 d-------- C:\Program Files\SAGEM
2007-04-10 14:33:38 0 d-------- C:\Users\Micey\AppData\Roaming\PC Tools<PCTOOL~1>
2007-04-08 21:02:40 0 d-------- C:\Users\Micey\AppData\Roaming\Adobe
2007-04-06 08:48:18 0 d-------- C:\Users\Micey\AppData\Roaming\LimeWire
2007-04-05 09:14:48 0 d-------- C:\Program Files\ffdshow
2007-04-05 07:32:38 0 d-------- C:\Program Files\LimeWire
2007-04-04 08:46:06 2026496 --a------ C:\Windows\system32\win32k.sys
2007-04-04 08:46:04 633856 --a------ C:\Windows\system32\user32.dll
2007-04-02 10:08:54 0 d-------- C:\Program Files\Microsoft Works<MIF2B0~1>
2007-04-02 10:08:34 0 d-------- C:\Program Files\MSBuild
2007-04-02 10:06:03 0 d-------- C:\Program Files\Microsoft.NET<MICROS~1.NET>
2007-04-02 09:49:45 0 d-------- C:\Program Files\Alcohol Soft<ALCOHO~1>
2007-03-30 12:28:20 0 d-------- C:\Program Files\Common Files\Adobe
2007-03-30 10:36:31 0 d-------- C:\Program Files\Common Files\Macrovision Shared<MACROV~1>
2007-03-30 08:30:44 0 d-------- C:\Program Files\Zune
2007-03-30 08:29:56 0 d-------- C:\Program Files\Windows Mail<WINDOW~1>
2007-03-25 12:37:07 0 d-------- C:\Users\Micey\AppData\Roaming\GetRightToGo<GETRIG~1>
2007-03-25 12:36:57 0 d-------- C:\Program Files\MiniBrowser<MINIBR~1>
2007-03-25 12:36:37 249856 -----n--- C:\Windows\Setup1.exe
2007-03-25 12:36:35 73216 --a------ C:\Windows\ST6UNST.EXE
2007-03-14 18:20:38 414208 --a------ C:\Windows\system32\msscp.dll
2007-03-14 18:20:33 229888 --a------ C:\Windows\system32\msshsq.dll
2007-03-14 18:20:16 4153344 --a------ C:\Windows\system32\GameUXLegacyGDFs.dll
2007-03-14 18:20:16 1686016 --a------ C:\Windows\system32\gameux.dll
2007-03-13 12:50:41 0 d-------- C:\Users\Micey\AppData\Roaming\MyPhoneExplorer<MYPHON~1>
2007-03-12 19:37:00 0 d-------- C:\Users\Micey\AppData\Roaming\Macromedia<MACROM~1>
2007-03-08 15:14:57 0 d-------- C:\Program Files\Common Files\Teleca Shared<TELECA~1>
2007-03-08 14:46:59 0 d-------- C:\Program Files\MyPhoneExplorer<MYPHON~1>
2007-03-05 23:18:12 0 d-------- C:\Program Files\Driving Test Success 2006-2007<DRIVIN~1>
2007-03-03 09:50:00 0 d-------- C:\Program Files\Common Files\EasyInfo
2007-02-25 16:21:35 26574 --a------ C:\Users\Micey\AppData\Roaming\UserTile.png
2007-02-24 15:01:07 0 d-------- C:\Program Files\Hewlett-Packard<HEWLET~1>
2007-02-24 14:44:35 20475 --a------ C:\Windows\hpoins01.dat
2007-02-24 14:42:06 0 d-------- C:\Users\Micey\AppData\Roaming\Hewlett-Packard<HEWLET~1>
2007-02-24 14:34:46 0 d-------- C:\Program Files\Common Files\Hewlett-Packard<HEWLET~1>
2007-02-24 14:33:10 0 d-------- C:\Program Files\Common Files\MSSoap
2007-02-23 01:45:13 0 d-------- C:\Users\Micey\AppData\Roaming\Ahead
2007-02-23 00:27:10 0 d-------- C:\Program Files\Common Files\Adobe Systems Shared<ADOBES~1>
2007-02-23 00:20:38 0 d-------- C:\Users\Micey\AppData\Roaming\Teleca
2007-02-22 18:58:39 2560 --a------ C:\Windows\system32\BitCometRes.dll<BITCOM~1.DLL>
2007-02-22 17:23:01 104448 --a------ C:\Windows\system32\DWWIN.EXE
2007-02-22 17:21:57 974336 --a------ C:\Windows\system32\crypt32.dll
2007-02-15 12:31:02 2756608 --a------ C:\Windows\system32\NETw4r32.dll
2007-02-15 12:30:34 679936 --a------ C:\Windows\system32\NETw4c32.dll
2007-01-30 09:53:32 77472 --a------ C:\Windows\system32\Tblfunc.dll
2007-01-30 09:52:42 65184 --a------ C:\Windows\system32\TBLMOUSE.EXE
2007-01-30 09:40:22 97952 --a------ C:\Windows\RmTablet.exe
2007-01-30 09:35:40 319136 --a------ C:\Windows\system32\ATWTUSB.EXE
-- Registry Dump ---------------------------------------------------------------
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Sidebar"="C:\\Program Files\\Windows Sidebar\\sidebar.exe /autoRun"
"ehTray.exe"="C:\\Windows\\ehome\\ehTray.exe"
"WMPNSCFG"="C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]
"fsc-reg"="cmd.exe /c rd /s /q \"C:\\ProgramData\\fsc-reg\\\""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Windows Defender"=hex(2):25,50,72,6f,67,72,61,6d,46,69,6c,65,73,25,5c,57,69,\
6e,64,6f,77,73,20,44,65,66,65,6e,64,65,72,5c,4d,53,41,53,43,75,69,2e,65,78,\
65,20,2d,68,69,64,65,00
"IgfxTray"="C:\\Windows\\system32\\igfxtray.exe"
"HotKeysCmds"="C:\\Windows\\system32\\hkcmd.exe"
"Persistence"="C:\\Windows\\system32\\igfxpers.exe"
"RtHDVCpl"="RtHDVCpl.exe"
"SMSERIAL"="C:\\Program Files\\Motorola\\SMSERIAL\\sm56hlpr.exe"
"NeroFilterCheck"="C:\\Program Files\\Common Files\\Ahead\\Lib\\NeroCheck.exe"
"autoclk"="autoclk.exe"
"Zune Launcher"="\"C:\\Program Files\\Zune\\ZuneLauncher.exe\""
"GrooveMonitor"="\"C:\\Program Files\\Microsoft Office\\Office12\\GrooveMonitor.exe\""
"PrintDrive"="rundll32.exe \"C:\\Windows\\system32\\lvlberpy.dll\",setvm"
"atwtusb"="atwtusb.exe"
"OneCareUI"="\"C:\\Program Files\\Microsoft Windows OneCare Live\\winssnotify.exe\""
"PWRISOVM.EXE"="C:\\Program Files\\PowerISO\\PWRISOVM.EXE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"="Groove GFS Stub Execution Hook"
"{856E36A9-A123-418A-A2CC-A05B3BF11AB9}"=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=dword:00000002
"ConsentPromptBehaviorUser"=dword:00000001
"EnableInstallerDetection"=dword:00000001
"EnableLUA"=dword:00000000
"EnableSecureUIAPaths"=dword:00000001
"EnableVirtualization"=dword:00000001
"PromptOnSecureDesktop"=dword:00000001
"ValidateAdminCodeSignatures"=dword:00000000
"scforceoption"=dword:00000000
"FilterAdministratorToken"=dword:00000000