regsearch log, part 4 of 4
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CCEVTMGR\0000]
"DeviceDesc"="Symantec Event Manager"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application]
; Contents of value:
; WSH
; WMIAdapter
; WmdmPmSN
; WLANKEEPER
; WinMgmt
; Winlogon
; Windows Product Activation
; Windows 3.1 Migration
; WebClient
; VSS
; VBRuntime
; Userinit
; Userenv
; TZMOVE
; Tlntsvr
; SysmonLog
; Symantec AntiVirus
; Starter
; SQLCTR$ACT7
; SQLAgent$ACT7
; SpoolerCtrs
; Software Restriction Policies
; Software Installation
; SecurityCenter
; SclgNtfy
; SceSrv
; SceCli
; SavRoam
; safrslv
; SAFrdms
; RPC
; Remote Assistance
; PerfProc
; PerfOS
; PerfNet
; Perfmon
; Perflib
; PerfDisk
; Perfctrs
; Outlook
; Offline Files
; Oakley
; ntbackup
; MSSQLServerADHelper
; MSSQLSERVER/MSDE
; MsiInstaller
; MSDTC Client
; MSDTC
; MSDMine
; mnmsrvc
; Microsoft Office Document Imaging
; Microsoft Office 11
; Microsoft H.323 Telephony Service Provider
; MDM
; LoadPerf
; LiveUpdate
; IntelliType Pro
; IntelliPoint
; HelpSvc
; Folder Redirection
; File Deployment
; EventSystem
; ESENT
; DrWatson
; DiskQuota
; Defwatch
; crypt32
; COM+
; COM
; Ci
; Chkdsk
; ccSetMgr
; ccEvtMgr
; Bonjour Service
; AutoEnrollment
; Autochk
; ASP.NET 1.1.4322.0
; Application Management
; Application Hang
; Application Error
; AegisP
; ACT7
; ACT! Scheduler
; .NET Runtime
; Application
;
"Sources"=hex(7):57,00,53,00,48,00,00,00,57,00,4d,00,49,00,41,00,64,00,61,00,\
70,00,74,00,65,00,72,00,00,00,57,00,6d,00,64,00,6d,00,50,00,6d,00,53,00,4e,\
00,00,00,57,00,4c,00,41,00,4e,00,4b,00,45,00,45,00,50,00,45,00,52,00,00,00,\
57,00,69,00,6e,00,4d,00,67,00,6d,00,74,00,00,00,57,00,69,00,6e,00,6c,00,6f,\
00,67,00,6f,00,6e,00,00,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,20,00,\
50,00,72,00,6f,00,64,00,75,00,63,00,74,00,20,00,41,00,63,00,74,00,69,00,76,\
00,61,00,74,00,69,00,6f,00,6e,00,00,00,57,00,69,00,6e,00,64,00,6f,00,77,00,\
73,00,20,00,33,00,2e,00,31,00,20,00,4d,00,69,00,67,00,72,00,61,00,74,00,69,\
00,6f,00,6e,00,00,00,57,00,65,00,62,00,43,00,6c,00,69,00,65,00,6e,00,74,00,\
00,00,56,00,53,00,53,00,00,00,56,00,42,00,52,00,75,00,6e,00,74,00,69,00,6d,\
00,65,00,00,00,55,00,73,00,65,00,72,00,69,00,6e,00,69,00,74,00,00,00,55,00,\
73,00,65,00,72,00,65,00,6e,00,76,00,00,00,54,00,5a,00,4d,00,4f,00,56,00,45,\
00,00,00,54,00,6c,00,6e,00,74,00,73,00,76,00,72,00,00,00,53,00,79,00,73,00,\
6d,00,6f,00,6e,00,4c,00,6f,00,67,00,00,00,53,00,79,00,6d,00,61,00,6e,00,74,\
00,65,00,63,00,20,00,41,00,6e,00,74,00,69,00,56,00,69,00,72,00,75,00,73,00,\
00,00,53,00,74,00,61,00,72,00,74,00,65,00,72,00,00,00,53,00,51,00,4c,00,43,\
00,54,00,52,00,24,00,41,00,43,00,54,00,37,00,00,00,53,00,51,00,4c,00,41,00,\
67,00,65,00,6e,00,74,00,24,00,41,00,43,00,54,00,37,00,00,00,53,00,70,00,6f,\
00,6f,00,6c,00,65,00,72,00,43,00,74,00,72,00,73,00,00,00,53,00,6f,00,66,00,\
74,00,77,00,61,00,72,00,65,00,20,00,52,00,65,00,73,00,74,00,72,00,69,00,63,\
00,74,00,69,00,6f,00,6e,00,20,00,50,00,6f,00,6c,00,69,00,63,00,69,00,65,00,\
73,00,00,00,53,00,6f,00,66,00,74,00,77,00,61,00,72,00,65,00,20,00,49,00,6e,\
00,73,00,74,00,61,00,6c,00,6c,00,61,00,74,00,69,00,6f,00,6e,00,00,00,53,00,\
65,00,63,00,75,00,72,00,69,00,74,00,79,00,43,00,65,00,6e,00,74,00,65,00,72,\
00,00,00,53,00,63,00,6c,00,67,00,4e,00,74,00,66,00,79,00,00,00,53,00,63,00,\
65,00,53,00,72,00,76,00,00,00,53,00,63,00,65,00,43,00,6c,00,69,00,00,00,53,\
00,61,00,76,00,52,00,6f,00,61,00,6d,00,00,00,73,00,61,00,66,00,72,00,73,00,\
6c,00,76,00,00,00,53,00,41,00,46,00,72,00,64,00,6d,00,73,00,00,00,52,00,50,\
00,43,00,00,00,52,00,65,00,6d,00,6f,00,74,00,65,00,20,00,41,00,73,00,73,00,\
69,00,73,00,74,00,61,00,6e,00,63,00,65,00,00,00,50,00,65,00,72,00,66,00,50,\
00,72,00,6f,00,63,00,00,00,50,00,65,00,72,00,66,00,4f,00,53,00,00,00,50,00,\
65,00,72,00,66,00,4e,00,65,00,74,00,00,00,50,00,65,00,72,00,66,00,6d,00,6f,\
00,6e,00,00,00,50,00,65,00,72,00,66,00,6c,00,69,00,62,00,00,00,50,00,65,00,\
72,00,66,00,44,00,69,00,73,00,6b,00,00,00,50,00,65,00,72,00,66,00,63,00,74,\
00,72,00,73,00,00,00,4f,00,75,00,74,00,6c,00,6f,00,6f,00,6b,00,00,00,4f,00,\
66,00,66,00,6c,00,69,00,6e,00,65,00,20,00,46,00,69,00,6c,00,65,00,73,00,00,\
00,4f,00,61,00,6b,00,6c,00,65,00,79,00,00,00,6e,00,74,00,62,00,61,00,63,00,\
6b,00,75,00,70,00,00,00,4d,00,53,00,53,00,51,00,4c,00,53,00,65,00,72,00,76,\
00,65,00,72,00,41,00,44,00,48,00,65,00,6c,00,70,00,65,00,72,00,00,00,4d,00,\
53,00,53,00,51,00,4c,00,53,00,45,00,52,00,56,00,45,00,52,00,2f,00,4d,00,53,\
00,44,00,45,00,00,00,4d,00,73,00,69,00,49,00,6e,00,73,00,74,00,61,00,6c,00,\
6c,00,65,00,72,00,00,00,4d,00,53,00,44,00,54,00,43,00,20,00,43,00,6c,00,69,\
00,65,00,6e,00,74,00,00,00,4d,00,53,00,44,00,54,00,43,00,00,00,4d,00,53,00,\
44,00,4d,00,69,00,6e,00,65,00,00,00,6d,00,6e,00,6d,00,73,00,72,00,76,00,63,\
00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,4f,00,\
66,00,66,00,69,00,63,00,65,00,20,00,44,00,6f,00,63,00,75,00,6d,00,65,00,6e,\
00,74,00,20,00,49,00,6d,00,61,00,67,00,69,00,6e,00,67,00,00,00,4d,00,69,00,\
63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,4f,00,66,00,66,00,69,00,63,\
00,65,00,20,00,31,00,31,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,\
66,00,74,00,20,00,48,00,2e,00,33,00,32,00,33,00,20,00,54,00,65,00,6c,00,65,\
00,70,00,68,00,6f,00,6e,00,79,00,20,00,53,00,65,00,72,00,76,00,69,00,63,00,\
65,00,20,00,50,00,72,00,6f,00,76,00,69,00,64,00,65,00,72,00,00,00,4d,00,44,\
00,4d,00,00,00,4c,00,6f,00,61,00,64,00,50,00,65,00,72,00,66,00,00,00,4c,00,\
69,00,76,00,65,00,55,00,70,00,64,00,61,00,74,00,65,00,00,00,49,00,6e,00,74,\
00,65,00,6c,00,6c,00,69,00,54,00,79,00,70,00,65,00,20,00,50,00,72,00,6f,00,\
00,00,49,00,6e,00,74,00,65,00,6c,00,6c,00,69,00,50,00,6f,00,69,00,6e,00,74,\
00,00,00,48,00,65,00,6c,00,70,00,53,00,76,00,63,00,00,00,46,00,6f,00,6c,00,\
64,00,65,00,72,00,20,00,52,00,65,00,64,00,69,00,72,00,65,00,63,00,74,00,69,\
00,6f,00,6e,00,00,00,46,00,69,00,6c,00,65,00,20,00,44,00,65,00,70,00,6c,00,\
6f,00,79,00,6d,00,65,00,6e,00,74,00,00,00,45,00,76,00,65,00,6e,00,74,00,53,\
00,79,00,73,00,74,00,65,00,6d,00,00,00,45,00,53,00,45,00,4e,00,54,00,00,00,\
44,00,72,00,57,00,61,00,74,00,73,00,6f,00,6e,00,00,00,44,00,69,00,73,00,6b,\
00,51,00,75,00,6f,00,74,00,61,00,00,00,44,00,65,00,66,00,77,00,61,00,74,00,\
63,00,68,00,00,00,63,00,72,00,79,00,70,00,74,00,33,00,32,00,00,00,43,00,4f,\
00,4d,00,2b,00,00,00,43,00,4f,00,4d,00,00,00,43,00,69,00,00,00,43,00,68,00,\
6b,00,64,00,73,00,6b,00,00,00,63,00,63,00,53,00,65,00,74,00,4d,00,67,00,72,\
00,00,00,63,00,63,00,45,00,76,00,74,00,4d,00,67,00,72,00,00,00,42,00,6f,00,\
6e,00,6a,00,6f,00,75,00,72,00,20,00,53,00,65,00,72,00,76,00,69,00,63,00,65,\
00,00,00,41,00,75,00,74,00,6f,00,45,00,6e,00,72,00,6f,00,6c,00,6c,00,6d,00,\
65,00,6e,00,74,00,00,00,41,00,75,00,74,00,6f,00,63,00,68,00,6b,00,00,00,41,\
00,53,00,50,00,2e,00,4e,00,45,00,54,00,20,00,31,00,2e,00,31,00,2e,00,34,00,\
33,00,32,00,32,00,2e,00,30,00,00,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,\
00,74,00,69,00,6f,00,6e,00,20,00,4d,00,61,00,6e,00,61,00,67,00,65,00,6d,00,\
65,00,6e,00,74,00,00,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,\
00,6f,00,6e,00,20,00,48,00,61,00,6e,00,67,00,00,00,41,00,70,00,70,00,6c,00,\
69,00,63,00,61,00,74,00,69,00,6f,00,6e,00,20,00,45,00,72,00,72,00,6f,00,72,\
00,00,00,41,00,65,00,67,00,69,00,73,00,50,00,00,00,41,00,43,00,54,00,37,00,\
00,00,41,00,43,00,54,00,21,00,20,00,53,00,63,00,68,00,65,00,64,00,75,00,6c,\
00,65,00,72,00,00,00,2e,00,4e,00,45,00,54,00,20,00,52,00,75,00,6e,00,74,00,\
69,00,6d,00,65,00,00,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,\
00,6f,00,6e,00,00,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\ccEvtMgr]
; Contents of value:
; C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,\
00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,43,00,6f,00,6d,00,6d,00,\
6f,00,6e,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,53,00,79,00,6d,00,61,\
00,6e,00,74,00,65,00,63,00,20,00,53,00,68,00,61,00,72,00,65,00,64,00,5c,00,\
63,00,63,00,45,00,76,00,74,00,4d,00,67,00,72,00,2e,00,65,00,78,00,65,00,00,\
00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\ccSetMgr]
; Contents of value:
; C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,\
00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,43,00,6f,00,6d,00,6d,00,\
6f,00,6e,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,53,00,79,00,6d,00,61,\
00,6e,00,74,00,65,00,63,00,20,00,53,00,68,00,61,00,72,00,65,00,64,00,5c,00,\
63,00,63,00,53,00,65,00,74,00,4d,00,67,00,72,00,2e,00,65,00,78,00,65,00,00,\
00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\Defwatch]
"EventMessageFile"="C:\\Program Files\\Symantec AntiVirus\\DefWatch.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\LiveUpdate]
"EventMessageFile"="C:\\Program Files\\Symantec\\LiveUpdate\\LuComServer.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\SavRoam]
"EventMessageFile"="C:\\Program Files\\Symantec AntiVirus\\SavRoam.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\Symantec AntiVirus]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\SAVRT]
"EventMessageFile"="C:\\Program Files\\Symantec AntiVirus\\savrt.sys"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SAVRT]
; Contents of value:
; \??\C:\Program Files\Symantec AntiVirus\savrt.sys
"ImagePath"=hex(2):5c,00,3f,00,3f,00,5c,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,\
67,00,72,00,61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,53,00,79,\
00,6d,00,61,00,6e,00,74,00,65,00,63,00,20,00,41,00,6e,00,74,00,69,00,56,00,\
69,00,72,00,75,00,73,00,5c,00,73,00,61,00,76,00,72,00,74,00,2e,00,73,00,79,\
00,73,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SAVRTPEL]
; Contents of value:
; \??\C:\Program Files\Symantec AntiVirus\Savrtpel.sys
"ImagePath"=hex(2):5c,00,3f,00,3f,00,5c,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,\
67,00,72,00,61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,53,00,79,\
00,6d,00,61,00,6e,00,74,00,65,00,63,00,20,00,41,00,6e,00,74,00,69,00,56,00,\
69,00,72,00,75,00,73,00,5c,00,53,00,61,00,76,00,72,00,74,00,70,00,65,00,6c,\
00,2e,00,73,00,79,00,73,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\ServiceGroupOrder]
; Contents of value:
; System Reserved
; Boot Bus Extender
; System Bus Extender
; SCSI miniport
; Port
; Primary Disk
; SCSI Class
; SCSI CDROM Class
; FSFilter Infrastructure
; FSFilter System
; FSFilter Bottom
; FSFilter Copy Protection
; FSFilter Security Enhancer
; FSFilter Open File
; FSFilter Physical Quota Management
; FSFilter Encryption
; FSFilter Compression
; FSFilter HSM
; FSFilter Cluster File System
; FSFilter System Recovery
; FSFilter Quota Management
; FSFilter Content Screener
; FSFilter Continuous Backup
; FSFilter Replication
; FSFilter Anti-Virus
; FSFilter Undelete
; FSFilter Activity Monitor
; FSFilter Top
; Filter
; Boot File System
; Base
; Pointer Port
; Keyboard Port
; Pointer Class
; Keyboard Class
; Video Init
; Video
; Video Save
; File System
; Event Log
; Streams Drivers
; NDIS Wrapper
; COM Infrastructure
; UIGroup
; LocalValidation
; PlugPlay
; PNP_TDI
; NDIS
; TDI
; Symantec Services
; NetBIOSGroup
; ShellSvcGroup
; SchedulerGroup
; SpoolerGroup
; AudioGroup
; SmartCardGroup
; NetworkProvider
; RemoteValidation
; NetDDEGroup
; Parallel arbitrator
; Extended Base
; PCI Configuration
; MS Transactions
;
"List"=hex(7):53,00,79,00,73,00,74,00,65,00,6d,00,20,00,52,00,65,00,73,00,65,\
00,72,00,76,00,65,00,64,00,00,00,42,00,6f,00,6f,00,74,00,20,00,42,00,75,00,\
73,00,20,00,45,00,78,00,74,00,65,00,6e,00,64,00,65,00,72,00,00,00,53,00,79,\
00,73,00,74,00,65,00,6d,00,20,00,42,00,75,00,73,00,20,00,45,00,78,00,74,00,\
65,00,6e,00,64,00,65,00,72,00,00,00,53,00,43,00,53,00,49,00,20,00,6d,00,69,\
00,6e,00,69,00,70,00,6f,00,72,00,74,00,00,00,50,00,6f,00,72,00,74,00,00,00,\
50,00,72,00,69,00,6d,00,61,00,72,00,79,00,20,00,44,00,69,00,73,00,6b,00,00,\
00,53,00,43,00,53,00,49,00,20,00,43,00,6c,00,61,00,73,00,73,00,00,00,53,00,\
43,00,53,00,49,00,20,00,43,00,44,00,52,00,4f,00,4d,00,20,00,43,00,6c,00,61,\
00,73,00,73,00,00,00,46,00,53,00,46,00,69,00,6c,00,74,00,65,00,72,00,20,00,\
49,00,6e,00,66,00,72,00,61,00,73,00,74,00,72,00,75,00,63,00,74,00,75,00,72,\
00,65,00,00,00,46,00,53,00,46,00,69,00,6c,00,74,00,65,00,72,00,20,00,53,00,\
79,00,73,00,74,00,65,00,6d,00,00,00,46,00,53,00,46,00,69,00,6c,00,74,00,65,\
00,72,00,20,00,42,00,6f,00,74,00,74,00,6f,00,6d,00,00,00,46,00,53,00,46,00,\
69,00,6c,00,74,00,65,00,72,00,20,00,43,00,6f,00,70,00,79,00,20,00,50,00,72,\
00,6f,00,74,00,65,00,63,00,74,00,69,00,6f,00,6e,00,00,00,46,00,53,00,46,00,\
69,00,6c,00,74,00,65,00,72,00,20,00,53,00,65,00,63,00,75,00,72,00,69,00,74,\
00,79,00,20,00,45,00,6e,00,68,00,61,00,6e,00,63,00,65,00,72,00,00,00,46,00,\
53,00,46,00,69,00,6c,00,74,00,65,00,72,00,20,00,4f,00,70,00,65,00,6e,00,20,\
00,46,00,69,00,6c,00,65,00,00,00,46,00,53,00,46,00,69,00,6c,00,74,00,65,00,\
72,00,20,00,50,00,68,00,79,00,73,00,69,00,63,00,61,00,6c,00,20,00,51,00,75,\
00,6f,00,74,00,61,00,20,00,4d,00,61,00,6e,00,61,00,67,00,65,00,6d,00,65,00,\
6e,00,74,00,00,00,46,00,53,00,46,00,69,00,6c,00,74,00,65,00,72,00,20,00,45,\
00,6e,00,63,00,72,00,79,00,70,00,74,00,69,00,6f,00,6e,00,00,00,46,00,53,00,\
46,00,69,00,6c,00,74,00,65,00,72,00,20,00,43,00,6f,00,6d,00,70,00,72,00,65,\
00,73,00,73,00,69,00,6f,00,6e,00,00,00,46,00,53,00,46,00,69,00,6c,00,74,00,\
65,00,72,00,20,00,48,00,53,00,4d,00,00,00,46,00,53,00,46,00,69,00,6c,00,74,\
00,65,00,72,00,20,00,43,00,6c,00,75,00,73,00,74,00,65,00,72,00,20,00,46,00,\
69,00,6c,00,65,00,20,00,53,00,79,00,73,00,74,00,65,00,6d,00,00,00,46,00,53,\
00,46,00,69,00,6c,00,74,00,65,00,72,00,20,00,53,00,79,00,73,00,74,00,65,00,\
6d,00,20,00,52,00,65,00,63,00,6f,00,76,00,65,00,72,00,79,00,00,00,46,00,53,\
00,46,00,69,00,6c,00,74,00,65,00,72,00,20,00,51,00,75,00,6f,00,74,00,61,00,\
20,00,4d,00,61,00,6e,00,61,00,67,00,65,00,6d,00,65,00,6e,00,74,00,00,00,46,\
00,53,00,46,00,69,00,6c,00,74,00,65,00,72,00,20,00,43,00,6f,00,6e,00,74,00,\
65,00,6e,00,74,00,20,00,53,00,63,00,72,00,65,00,65,00,6e,00,65,00,72,00,00,\
00,46,00,53,00,46,00,69,00,6c,00,74,00,65,00,72,00,20,00,43,00,6f,00,6e,00,\
74,00,69,00,6e,00,75,00,6f,00,75,00,73,00,20,00,42,00,61,00,63,00,6b,00,75,\
00,70,00,00,00,46,00,53,00,46,00,69,00,6c,00,74,00,65,00,72,00,20,00,52,00,\
65,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,00,6f,00,6e,00,00,00,46,00,53,\
00,46,00,69,00,6c,00,74,00,65,00,72,00,20,00,41,00,6e,00,74,00,69,00,2d,00,\
56,00,69,00,72,00,75,00,73,00,00,00,46,00,53,00,46,00,69,00,6c,00,74,00,65,\
00,72,00,20,00,55,00,6e,00,64,00,65,00,6c,00,65,00,74,00,65,00,00,00,46,00,\
53,00,46,00,69,00,6c,00,74,00,65,00,72,00,20,00,41,00,63,00,74,00,69,00,76,\
00,69,00,74,00,79,00,20,00,4d,00,6f,00,6e,00,69,00,74,00,6f,00,72,00,00,00,\
46,00,53,00,46,00,69,00,6c,00,74,00,65,00,72,00,20,00,54,00,6f,00,70,00,00,\
00,46,00,69,00,6c,00,74,00,65,00,72,00,00,00,42,00,6f,00,6f,00,74,00,20,00,\
46,00,69,00,6c,00,65,00,20,00,53,00,79,00,73,00,74,00,65,00,6d,00,00,00,42,\
00,61,00,73,00,65,00,00,00,50,00,6f,00,69,00,6e,00,74,00,65,00,72,00,20,00,\
50,00,6f,00,72,00,74,00,00,00,4b,00,65,00,79,00,62,00,6f,00,61,00,72,00,64,\
00,20,00,50,00,6f,00,72,00,74,00,00,00,50,00,6f,00,69,00,6e,00,74,00,65,00,\
72,00,20,00,43,00,6c,00,61,00,73,00,73,00,00,00,4b,00,65,00,79,00,62,00,6f,\
00,61,00,72,00,64,00,20,00,43,00,6c,00,61,00,73,00,73,00,00,00,56,00,69,00,\
64,00,65,00,6f,00,20,00,49,00,6e,00,69,00,74,00,00,00,56,00,69,00,64,00,65,\
00,6f,00,00,00,56,00,69,00,64,00,65,00,6f,00,20,00,53,00,61,00,76,00,65,00,\
00,00,46,00,69,00,6c,00,65,00,20,00,53,00,79,00,73,00,74,00,65,00,6d,00,00,\
00,45,00,76,00,65,00,6e,00,74,00,20,00,4c,00,6f,00,67,00,00,00,53,00,74,00,\
72,00,65,00,61,00,6d,00,73,00,20,00,44,00,72,00,69,00,76,00,65,00,72,00,73,\
00,00,00,4e,00,44,00,49,00,53,00,20,00,57,00,72,00,61,00,70,00,70,00,65,00,\
72,00,00,00,43,00,4f,00,4d,00,20,00,49,00,6e,00,66,00,72,00,61,00,73,00,74,\
00,72,00,75,00,63,00,74,00,75,00,72,00,65,00,00,00,55,00,49,00,47,00,72,00,\
6f,00,75,00,70,00,00,00,4c,00,6f,00,63,00,61,00,6c,00,56,00,61,00,6c,00,69,\
00,64,00,61,00,74,00,69,00,6f,00,6e,00,00,00,50,00,6c,00,75,00,67,00,50,00,\
6c,00,61,00,79,00,00,00,50,00,4e,00,50,00,5f,00,54,00,44,00,49,00,00,00,4e,\
00,44,00,49,00,53,00,00,00,54,00,44,00,49,00,00,00,53,00,79,00,6d,00,61,00,\
6e,00,74,00,65,00,63,00,20,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,\
00,00,00,4e,00,65,00,74,00,42,00,49,00,4f,00,53,00,47,00,72,00,6f,00,75,00,\
70,00,00,00,53,00,68,00,65,00,6c,00,6c,00,53,00,76,00,63,00,47,00,72,00,6f,\
00,75,00,70,00,00,00,53,00,63,00,68,00,65,00,64,00,75,00,6c,00,65,00,72,00,\
47,00,72,00,6f,00,75,00,70,00,00,00,53,00,70,00,6f,00,6f,00,6c,00,65,00,72,\
00,47,00,72,00,6f,00,75,00,70,00,00,00,41,00,75,00,64,00,69,00,6f,00,47,00,\
72,00,6f,00,75,00,70,00,00,00,53,00,6d,00,61,00,72,00,74,00,43,00,61,00,72,\
00,64,00,47,00,72,00,6f,00,75,00,70,00,00,00,4e,00,65,00,74,00,77,00,6f,00,\
72,00,6b,00,50,00,72,00,6f,00,76,00,69,00,64,00,65,00,72,00,00,00,52,00,65,\
00,6d,00,6f,00,74,00,65,00,56,00,61,00,6c,00,69,00,64,00,61,00,74,00,69,00,\
6f,00,6e,00,00,00,4e,00,65,00,74,00,44,00,44,00,45,00,47,00,72,00,6f,00,75,\
00,70,00,00,00,50,00,61,00,72,00,61,00,6c,00,6c,00,65,00,6c,00,20,00,61,00,\
72,00,62,00,69,00,74,00,72,00,61,00,74,00,6f,00,72,00,00,00,45,00,78,00,74,\
00,65,00,6e,00,64,00,65,00,64,00,20,00,42,00,61,00,73,00,65,00,00,00,50,00,\
43,00,49,00,20,00,43,00,6f,00,6e,00,66,00,69,00,67,00,75,00,72,00,61,00,74,\
00,69,00,6f,00,6e,00,00,00,4d,00,53,00,20,00,54,00,72,00,61,00,6e,00,73,00,\
61,00,63,00,74,00,69,00,6f,00,6e,00,73,00,00,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\VirtualDeviceDrivers]
; Contents of value:
; C:\PROGRA~1\Symantec\S32EVNT1.DLL
; C:\Program Files\Alwil Software\Avast4\aswMonVd.dll
;
"VDD"=hex(7):43,00,3a,00,5c,00,50,00,52,00,4f,00,47,00,52,00,41,00,7e,00,31,00,\
5c,00,53,00,79,00,6d,00,61,00,6e,00,74,00,65,00,63,00,5c,00,53,00,33,00,32,\
00,45,00,56,00,4e,00,54,00,31,00,2e,00,44,00,4c,00,4c,00,00,00,43,00,3a,00,\
5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,20,00,46,00,69,00,6c,00,65,\
00,73,00,5c,00,41,00,6c,00,77,00,69,00,6c,00,20,00,53,00,6f,00,66,00,74,00,\
77,00,61,00,72,00,65,00,5c,00,41,00,76,00,61,00,73,00,74,00,34,00,5c,00,61,\
00,73,00,77,00,4d,00,6f,00,6e,00,56,00,64,00,2e,00,64,00,6c,00,6c,00,00,00,\
00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CCEVTMGR\0000]
"DeviceDesc"="Symantec Event Manager"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application]
; Contents of value:
; WSH
; WMIAdapter
; WmdmPmSN
; WLANKEEPER
; WinMgmt
; Winlogon
; Windows Product Activation
; Windows 3.1 Migration
; WebClient
; VSS
; VBRuntime
; Userinit
; Userenv
; TZMOVE
; Tlntsvr
; SysmonLog
; Symantec AntiVirus
; Starter
; SQLCTR$ACT7
; SQLAgent$ACT7
; SpoolerCtrs
; Software Restriction Policies
; Software Installation
; SecurityCenter
; SclgNtfy
; SceSrv
; SceCli
; SavRoam
; safrslv
; SAFrdms
; RPC
; Remote Assistance
; PerfProc
; PerfOS
; PerfNet
; Perfmon
; Perflib
; PerfDisk
; Perfctrs
; Outlook
; Offline Files
; Oakley
; ntbackup
; MSSQLServerADHelper
; MSSQLSERVER/MSDE
; MsiInstaller
; MSDTC Client
; MSDTC
; MSDMine
; mnmsrvc
; Microsoft Office Document Imaging
; Microsoft Office 11
; Microsoft H.323 Telephony Service Provider
; MDM
; LoadPerf
; LiveUpdate
; IntelliType Pro
; IntelliPoint
; HelpSvc
; Folder Redirection
; File Deployment
; EventSystem
; ESENT
; DrWatson
; DiskQuota
; Defwatch
; crypt32
; COM+
; COM
; Ci
; Chkdsk
; ccSetMgr
; ccEvtMgr
; Bonjour Service
; AutoEnrollment
; Autochk
; ASP.NET 1.1.4322.0
; Application Management
; Application Hang
; Application Error
; AegisP
; ACT7
; ACT! Scheduler
; .NET Runtime
; Application
;
"Sources"=hex(7):57,00,53,00,48,00,00,00,57,00,4d,00,49,00,41,00,64,00,61,00,\
70,00,74,00,65,00,72,00,00,00,57,00,6d,00,64,00,6d,00,50,00,6d,00,53,00,4e,\
00,00,00,57,00,4c,00,41,00,4e,00,4b,00,45,00,45,00,50,00,45,00,52,00,00,00,\
57,00,69,00,6e,00,4d,00,67,00,6d,00,74,00,00,00,57,00,69,00,6e,00,6c,00,6f,\
00,67,00,6f,00,6e,00,00,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,20,00,\
50,00,72,00,6f,00,64,00,75,00,63,00,74,00,20,00,41,00,63,00,74,00,69,00,76,\
00,61,00,74,00,69,00,6f,00,6e,00,00,00,57,00,69,00,6e,00,64,00,6f,00,77,00,\
73,00,20,00,33,00,2e,00,31,00,20,00,4d,00,69,00,67,00,72,00,61,00,74,00,69,\
00,6f,00,6e,00,00,00,57,00,65,00,62,00,43,00,6c,00,69,00,65,00,6e,00,74,00,\
00,00,56,00,53,00,53,00,00,00,56,00,42,00,52,00,75,00,6e,00,74,00,69,00,6d,\
00,65,00,00,00,55,00,73,00,65,00,72,00,69,00,6e,00,69,00,74,00,00,00,55,00,\
73,00,65,00,72,00,65,00,6e,00,76,00,00,00,54,00,5a,00,4d,00,4f,00,56,00,45,\
00,00,00,54,00,6c,00,6e,00,74,00,73,00,76,00,72,00,00,00,53,00,79,00,73,00,\
6d,00,6f,00,6e,00,4c,00,6f,00,67,00,00,00,53,00,79,00,6d,00,61,00,6e,00,74,\
00,65,00,63,00,20,00,41,00,6e,00,74,00,69,00,56,00,69,00,72,00,75,00,73,00,\
00,00,53,00,74,00,61,00,72,00,74,00,65,00,72,00,00,00,53,00,51,00,4c,00,43,\
00,54,00,52,00,24,00,41,00,43,00,54,00,37,00,00,00,53,00,51,00,4c,00,41,00,\
67,00,65,00,6e,00,74,00,24,00,41,00,43,00,54,00,37,00,00,00,53,00,70,00,6f,\
00,6f,00,6c,00,65,00,72,00,43,00,74,00,72,00,73,00,00,00,53,00,6f,00,66,00,\
74,00,77,00,61,00,72,00,65,00,20,00,52,00,65,00,73,00,74,00,72,00,69,00,63,\
00,74,00,69,00,6f,00,6e,00,20,00,50,00,6f,00,6c,00,69,00,63,00,69,00,65,00,\
73,00,00,00,53,00,6f,00,66,00,74,00,77,00,61,00,72,00,65,00,20,00,49,00,6e,\
00,73,00,74,00,61,00,6c,00,6c,00,61,00,74,00,69,00,6f,00,6e,00,00,00,53,00,\
65,00,63,00,75,00,72,00,69,00,74,00,79,00,43,00,65,00,6e,00,74,00,65,00,72,\
00,00,00,53,00,63,00,6c,00,67,00,4e,00,74,00,66,00,79,00,00,00,53,00,63,00,\
65,00,53,00,72,00,76,00,00,00,53,00,63,00,65,00,43,00,6c,00,69,00,00,00,53,\
00,61,00,76,00,52,00,6f,00,61,00,6d,00,00,00,73,00,61,00,66,00,72,00,73,00,\
6c,00,76,00,00,00,53,00,41,00,46,00,72,00,64,00,6d,00,73,00,00,00,52,00,50,\
00,43,00,00,00,52,00,65,00,6d,00,6f,00,74,00,65,00,20,00,41,00,73,00,73,00,\
69,00,73,00,74,00,61,00,6e,00,63,00,65,00,00,00,50,00,65,00,72,00,66,00,50,\
00,72,00,6f,00,63,00,00,00,50,00,65,00,72,00,66,00,4f,00,53,00,00,00,50,00,\
65,00,72,00,66,00,4e,00,65,00,74,00,00,00,50,00,65,00,72,00,66,00,6d,00,6f,\
00,6e,00,00,00,50,00,65,00,72,00,66,00,6c,00,69,00,62,00,00,00,50,00,65,00,\
72,00,66,00,44,00,69,00,73,00,6b,00,00,00,50,00,65,00,72,00,66,00,63,00,74,\
00,72,00,73,00,00,00,4f,00,75,00,74,00,6c,00,6f,00,6f,00,6b,00,00,00,4f,00,\
66,00,66,00,6c,00,69,00,6e,00,65,00,20,00,46,00,69,00,6c,00,65,00,73,00,00,\
00,4f,00,61,00,6b,00,6c,00,65,00,79,00,00,00,6e,00,74,00,62,00,61,00,63,00,\
6b,00,75,00,70,00,00,00,4d,00,53,00,53,00,51,00,4c,00,53,00,65,00,72,00,76,\
00,65,00,72,00,41,00,44,00,48,00,65,00,6c,00,70,00,65,00,72,00,00,00,4d,00,\
53,00,53,00,51,00,4c,00,53,00,45,00,52,00,56,00,45,00,52,00,2f,00,4d,00,53,\
00,44,00,45,00,00,00,4d,00,73,00,69,00,49,00,6e,00,73,00,74,00,61,00,6c,00,\
6c,00,65,00,72,00,00,00,4d,00,53,00,44,00,54,00,43,00,20,00,43,00,6c,00,69,\
00,65,00,6e,00,74,00,00,00,4d,00,53,00,44,00,54,00,43,00,00,00,4d,00,53,00,\
44,00,4d,00,69,00,6e,00,65,00,00,00,6d,00,6e,00,6d,00,73,00,72,00,76,00,63,\
00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,4f,00,\
66,00,66,00,69,00,63,00,65,00,20,00,44,00,6f,00,63,00,75,00,6d,00,65,00,6e,\
00,74,00,20,00,49,00,6d,00,61,00,67,00,69,00,6e,00,67,00,00,00,4d,00,69,00,\
63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,4f,00,66,00,66,00,69,00,63,\
00,65,00,20,00,31,00,31,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,\
66,00,74,00,20,00,48,00,2e,00,33,00,32,00,33,00,20,00,54,00,65,00,6c,00,65,\
00,70,00,68,00,6f,00,6e,00,79,00,20,00,53,00,65,00,72,00,76,00,69,00,63,00,\
65,00,20,00,50,00,72,00,6f,00,76,00,69,00,64,00,65,00,72,00,00,00,4d,00,44,\
00,4d,00,00,00,4c,00,6f,00,61,00,64,00,50,00,65,00,72,00,66,00,00,00,4c,00,\
69,00,76,00,65,00,55,00,70,00,64,00,61,00,74,00,65,00,00,00,49,00,6e,00,74,\
00,65,00,6c,00,6c,00,69,00,54,00,79,00,70,00,65,00,20,00,50,00,72,00,6f,00,\
00,00,49,00,6e,00,74,00,65,00,6c,00,6c,00,69,00,50,00,6f,00,69,00,6e,00,74,\
00,00,00,48,00,65,00,6c,00,70,00,53,00,76,00,63,00,00,00,46,00,6f,00,6c,00,\
64,00,65,00,72,00,20,00,52,00,65,00,64,00,69,00,72,00,65,00,63,00,74,00,69,\
00,6f,00,6e,00,00,00,46,00,69,00,6c,00,65,00,20,00,44,00,65,00,70,00,6c,00,\
6f,00,79,00,6d,00,65,00,6e,00,74,00,00,00,45,00,76,00,65,00,6e,00,74,00,53,\
00,79,00,73,00,74,00,65,00,6d,00,00,00,45,00,53,00,45,00,4e,00,54,00,00,00,\
44,00,72,00,57,00,61,00,74,00,73,00,6f,00,6e,00,00,00,44,00,69,00,73,00,6b,\
00,51,00,75,00,6f,00,74,00,61,00,00,00,44,00,65,00,66,00,77,00,61,00,74,00,\
63,00,68,00,00,00,63,00,72,00,79,00,70,00,74,00,33,00,32,00,00,00,43,00,4f,\
00,4d,00,2b,00,00,00,43,00,4f,00,4d,00,00,00,43,00,69,00,00,00,43,00,68,00,\
6b,00,64,00,73,00,6b,00,00,00,63,00,63,00,53,00,65,00,74,00,4d,00,67,00,72,\
00,00,00,63,00,63,00,45,00,76,00,74,00,4d,00,67,00,72,00,00,00,42,00,6f,00,\
6e,00,6a,00,6f,00,75,00,72,00,20,00,53,00,65,00,72,00,76,00,69,00,63,00,65,\
00,00,00,41,00,75,00,74,00,6f,00,45,00,6e,00,72,00,6f,00,6c,00,6c,00,6d,00,\
65,00,6e,00,74,00,00,00,41,00,75,00,74,00,6f,00,63,00,68,00,6b,00,00,00,41,\
00,53,00,50,00,2e,00,4e,00,45,00,54,00,20,00,31,00,2e,00,31,00,2e,00,34,00,\
33,00,32,00,32,00,2e,00,30,00,00,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,\
00,74,00,69,00,6f,00,6e,00,20,00,4d,00,61,00,6e,00,61,00,67,00,65,00,6d,00,\
65,00,6e,00,74,00,00,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,\
00,6f,00,6e,00,20,00,48,00,61,00,6e,00,67,00,00,00,41,00,70,00,70,00,6c,00,\
69,00,63,00,61,00,74,00,69,00,6f,00,6e,00,20,00,45,00,72,00,72,00,6f,00,72,\
00,00,00,41,00,65,00,67,00,69,00,73,00,50,00,00,00,41,00,43,00,54,00,37,00,\
00,00,41,00,43,00,54,00,21,00,20,00,53,00,63,00,68,00,65,00,64,00,75,00,6c,\
00,65,00,72,00,00,00,2e,00,4e,00,45,00,54,00,20,00,52,00,75,00,6e,00,74,00,\
69,00,6d,00,65,00,00,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,\
00,6f,00,6e,00,00,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\ccEvtMgr]
; Contents of value:
; C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,\
00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,43,00,6f,00,6d,00,6d,00,\
6f,00,6e,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,53,00,79,00,6d,00,61,\
00,6e,00,74,00,65,00,63,00,20,00,53,00,68,00,61,00,72,00,65,00,64,00,5c,00,\
63,00,63,00,45,00,76,00,74,00,4d,00,67,00,72,00,2e,00,65,00,78,00,65,00,00,\
00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\ccSetMgr]
; Contents of value:
; C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,\
00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,43,00,6f,00,6d,00,6d,00,\
6f,00,6e,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,53,00,79,00,6d,00,61,\
00,6e,00,74,00,65,00,63,00,20,00,53,00,68,00,61,00,72,00,65,00,64,00,5c,00,\
63,00,63,00,53,00,65,00,74,00,4d,00,67,00,72,00,2e,00,65,00,78,00,65,00,00,\
00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\Defwatch]
"EventMessageFile"="C:\\Program Files\\Symantec AntiVirus\\DefWatch.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\LiveUpdate]
"EventMessageFile"="C:\\Program Files\\Symantec\\LiveUpdate\\LuComServer.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\SavRoam]
"EventMessageFile"="C:\\Program Files\\Symantec AntiVirus\\SavRoam.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\Symantec AntiVirus]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\SAVRT]
"EventMessageFile"="C:\\Program Files\\Symantec AntiVirus\\savrt.sys"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SAVRT]
; Contents of value:
; \??\C:\Program Files\Symantec AntiVirus\savrt.sys
"ImagePath"=hex(2):5c,00,3f,00,3f,00,5c,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,\
67,00,72,00,61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,53,00,79,\
00,6d,00,61,00,6e,00,74,00,65,00,63,00,20,00,41,00,6e,00,74,00,69,00,56,00,\
69,00,72,00,75,00,73,00,5c,00,73,00,61,00,76,00,72,00,74,00,2e,00,73,00,79,\
00,73,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SAVRTPEL]
; Contents of value:
; \??\C:\Program Files\Symantec AntiVirus\Savrtpel.sys
"ImagePath"=hex(2):5c,00,3f,00,3f,00,5c,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,\
67,00,72,00,61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,53,00,79,\
00,6d,00,61,00,6e,00,74,00,65,00,63,00,20,00,41,00,6e,00,74,00,69,00,56,00,\
69,00,72,00,75,00,73,00,5c,00,53,00,61,00,76,00,72,00,74,00,70,00,65,00,6c,\
00,2e,00,73,00,79,00,73,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ServiceGroupOrder]
; Contents of value:
; System Reserved
; Boot Bus Extender
; System Bus Extender
; SCSI miniport
; Port
; Primary Disk
; SCSI Class
; SCSI CDROM Class
; FSFilter Infrastructure
; FSFilter System
; FSFilter Bottom
; FSFilter Copy Protection
; FSFilter Security Enhancer
; FSFilter Open File
; FSFilter Physical Quota Management
; FSFilter Encryption
; FSFilter Compression
; FSFilter HSM
; FSFilter Cluster File System
; FSFilter System Recovery
; FSFilter Quota Management
; FSFilter Content Screener
; FSFilter Continuous Backup
; FSFilter Replication
; FSFilter Anti-Virus
; FSFilter Undelete
; FSFilter Activity Monitor
; FSFilter Top
; Filter
; Boot File System
; Base
; Pointer Port
; Keyboard Port
; Pointer Class
; Keyboard Class
; Video Init
; Video
; Video Save
; File System
; Event Log
; Streams Drivers
; NDIS Wrapper
; COM Infrastructure
; UIGroup
; LocalValidation
; PlugPlay
; PNP_TDI
; NDIS
; TDI
; Symantec Services
; NetBIOSGroup
; ShellSvcGroup
; SchedulerGroup
; SpoolerGroup
; AudioGroup
; SmartCardGroup
; NetworkProvider
; RemoteValidation
; NetDDEGroup
; Parallel arbitrator
; Extended Base
; PCI Configuration
; MS Transactions
;
"List"=hex(7):53,00,79,00,73,00,74,00,65,00,6d,00,20,00,52,00,65,00,73,00,65,\
00,72,00,76,00,65,00,64,00,00,00,42,00,6f,00,6f,00,74,00,20,00,42,00,75,00,\
73,00,20,00,45,00,78,00,74,00,65,00,6e,00,64,00,65,00,72,00,00,00,53,00,79,\
00,73,00,74,00,65,00,6d,00,20,00,42,00,75,00,73,00,20,00,45,00,78,00,74,00,\
65,00,6e,00,64,00,65,00,72,00,00,00,53,00,43,00,53,00,49,00,20,00,6d,00,69,\
00,6e,00,69,00,70,00,6f,00,72,00,74,00,00,00,50,00,6f,00,72,00,74,00,00,00,\
50,00,72,00,69,00,6d,00,61,00,72,00,79,00,20,00,44,00,69,00,73,00,6b,00,00,\
00,53,00,43,00,53,00,49,00,20,00,43,00,6c,00,61,00,73,00,73,00,00,00,53,00,\
43,00,53,00,49,00,20,00,43,00,44,00,52,00,4f,00,4d,00,20,00,43,00,6c,00,61,\
00,73,00,73,00,00,00,46,00,53,00,46,00,69,00,6c,00,74,00,65,00,72,00,20,00,\
49,00,6e,00,66,00,72,00,61,00,73,00,74,00,72,00,75,00,63,00,74,00,75,00,72,\
00,65,00,00,00,46,00,53,00,46,00,69,00,6c,00,74,00,65,00,72,00,20,00,53,00,\
79,00,73,00,74,00,65,00,6d,00,00,00,46,00,53,00,46,00,69,00,6c,00,74,00,65,\
00,72,00,20,00,42,00,6f,00,74,00,74,00,6f,00,6d,00,00,00,46,00,53,00,46,00,\
69,00,6c,00,74,00,65,00,72,00,20,00,43,00,6f,00,70,00,79,00,20,00,50,00,72,\
00,6f,00,74,00,65,00,63,00,74,00,69,00,6f,00,6e,00,00,00,46,00,53,00,46,00,\
69,00,6c,00,74,00,65,00,72,00,20,00,53,00,65,00,63,00,75,00,72,00,69,00,74,\
00,79,00,20,00,45,00,6e,00,68,00,61,00,6e,00,63,00,65,00,72,00,00,00,46,00,\
53,00,46,00,69,00,6c,00,74,00,65,00,72,00,20,00,4f,00,70,00,65,00,6e,00,20,\
00,46,00,69,00,6c,00,65,00,00,00,46,00,53,00,46,00,69,00,6c,00,74,00,65,00,\
72,00,20,00,50,00,68,00,79,00,73,00,69,00,63,00,61,00,6c,00,20,00,51,00,75,\
00,6f,00,74,00,61,00,20,00,4d,00,61,00,6e,00,61,00,67,00,65,00,6d,00,65,00,\
6e,00,74,00,00,00,46,00,53,00,46,00,69,00,6c,00,74,00,65,00,72,00,20,00,45,\
00,6e,00,63,00,72,00,79,00,70,00,74,00,69,00,6f,00,6e,00,00,00,46,00,53,00,\
46,00,69,00,6c,00,74,00,65,00,72,00,20,00,43,00,6f,00,6d,00,70,00,72,00,65,\
00,73,00,73,00,69,00,6f,00,6e,00,00,00,46,00,53,00,46,00,69,00,6c,00,74,00,\
65,00,72,00,20,00,48,00,53,00,4d,00,00,00,46,00,53,00,46,00,69,00,6c,00,74,\
00,65,00,72,00,20,00,43,00,6c,00,75,00,73,00,74,00,65,00,72,00,20,00,46,00,\
69,00,6c,00,65,00,20,00,53,00,79,00,73,00,74,00,65,00,6d,00,00,00,46,00,53,\
00,46,00,69,00,6c,00,74,00,65,00,72,00,20,00,53,00,79,00,73,00,74,00,65,00,\
6d,00,20,00,52,00,65,00,63,00,6f,00,76,00,65,00,72,00,79,00,00,00,46,00,53,\
00,46,00,69,00,6c,00,74,00,65,00,72,00,20,00,51,00,75,00,6f,00,74,00,61,00,\
20,00,4d,00,61,00,6e,00,61,00,67,00,65,00,6d,00,65,00,6e,00,74,00,00,00,46,\
00,53,00,46,00,69,00,6c,00,74,00,65,00,72,00,20,00,43,00,6f,00,6e,00,74,00,\
65,00,6e,00,74,00,20,00,53,00,63,00,72,00,65,00,65,00,6e,00,65,00,72,00,00,\
00,46,00,53,00,46,00,69,00,6c,00,74,00,65,00,72,00,20,00,43,00,6f,00,6e,00,\
74,00,69,00,6e,00,75,00,6f,00,75,00,73,00,20,00,42,00,61,00,63,00,6b,00,75,\
00,70,00,00,00,46,00,53,00,46,00,69,00,6c,00,74,00,65,00,72,00,20,00,52,00,\
65,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,00,6f,00,6e,00,00,00,46,00,53,\
00,46,00,69,00,6c,00,74,00,65,00,72,00,20,00,41,00,6e,00,74,00,69,00,2d,00,\
56,00,69,00,72,00,75,00,73,00,00,00,46,00,53,00,46,00,69,00,6c,00,74,00,65,\
00,72,00,20,00,55,00,6e,00,64,00,65,00,6c,00,65,00,74,00,65,00,00,00,46,00,\
53,00,46,00,69,00,6c,00,74,00,65,00,72,00,20,00,41,00,63,00,74,00,69,00,76,\
00,69,00,74,00,79,00,20,00,4d,00,6f,00,6e,00,69,00,74,00,6f,00,72,00,00,00,\
46,00,53,00,46,00,69,00,6c,00,74,00,65,00,72,00,20,00,54,00,6f,00,70,00,00,\
00,46,00,69,00,6c,00,74,00,65,00,72,00,00,00,42,00,6f,00,6f,00,74,00,20,00,\
46,00,69,00,6c,00,65,00,20,00,53,00,79,00,73,00,74,00,65,00,6d,00,00,00,42,\
00,61,00,73,00,65,00,00,00,50,00,6f,00,69,00,6e,00,74,00,65,00,72,00,20,00,\
50,00,6f,00,72,00,74,00,00,00,4b,00,65,00,79,00,62,00,6f,00,61,00,72,00,64,\
00,20,00,50,00,6f,00,72,00,74,00,00,00,50,00,6f,00,69,00,6e,00,74,00,65,00,\
72,00,20,00,43,00,6c,00,61,00,73,00,73,00,00,00,4b,00,65,00,79,00,62,00,6f,\
00,61,00,72,00,64,00,20,00,43,00,6c,00,61,00,73,00,73,00,00,00,56,00,69,00,\
64,00,65,00,6f,00,20,00,49,00,6e,00,69,00,74,00,00,00,56,00,69,00,64,00,65,\
00,6f,00,00,00,56,00,69,00,64,00,65,00,6f,00,20,00,53,00,61,00,76,00,65,00,\
00,00,46,00,69,00,6c,00,65,00,20,00,53,00,79,00,73,00,74,00,65,00,6d,00,00,\
00,45,00,76,00,65,00,6e,00,74,00,20,00,4c,00,6f,00,67,00,00,00,53,00,74,00,\
72,00,65,00,61,00,6d,00,73,00,20,00,44,00,72,00,69,00,76,00,65,00,72,00,73,\
00,00,00,4e,00,44,00,49,00,53,00,20,00,57,00,72,00,61,00,70,00,70,00,65,00,\
72,00,00,00,43,00,4f,00,4d,00,20,00,49,00,6e,00,66,00,72,00,61,00,73,00,74,\
00,72,00,75,00,63,00,74,00,75,00,72,00,65,00,00,00,55,00,49,00,47,00,72,00,\
6f,00,75,00,70,00,00,00,4c,00,6f,00,63,00,61,00,6c,00,56,00,61,00,6c,00,69,\
00,64,00,61,00,74,00,69,00,6f,00,6e,00,00,00,50,00,6c,00,75,00,67,00,50,00,\
6c,00,61,00,79,00,00,00,50,00,4e,00,50,00,5f,00,54,00,44,00,49,00,00,00,4e,\
00,44,00,49,00,53,00,00,00,54,00,44,00,49,00,00,00,53,00,79,00,6d,00,61,00,\
6e,00,74,00,65,00,63,00,20,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,73,\
00,00,00,4e,00,65,00,74,00,42,00,49,00,4f,00,53,00,47,00,72,00,6f,00,75,00,\
70,00,00,00,53,00,68,00,65,00,6c,00,6c,00,53,00,76,00,63,00,47,00,72,00,6f,\
00,75,00,70,00,00,00,53,00,63,00,68,00,65,00,64,00,75,00,6c,00,65,00,72,00,\
47,00,72,00,6f,00,75,00,70,00,00,00,53,00,70,00,6f,00,6f,00,6c,00,65,00,72,\
00,47,00,72,00,6f,00,75,00,70,00,00,00,41,00,75,00,64,00,69,00,6f,00,47,00,\
72,00,6f,00,75,00,70,00,00,00,53,00,6d,00,61,00,72,00,74,00,43,00,61,00,72,\
00,64,00,47,00,72,00,6f,00,75,00,70,00,00,00,4e,00,65,00,74,00,77,00,6f,00,\
72,00,6b,00,50,00,72,00,6f,00,76,00,69,00,64,00,65,00,72,00,00,00,52,00,65,\
00,6d,00,6f,00,74,00,65,00,56,00,61,00,6c,00,69,00,64,00,61,00,74,00,69,00,\
6f,00,6e,00,00,00,4e,00,65,00,74,00,44,00,44,00,45,00,47,00,72,00,6f,00,75,\
00,70,00,00,00,50,00,61,00,72,00,61,00,6c,00,6c,00,65,00,6c,00,20,00,61,00,\
72,00,62,00,69,00,74,00,72,00,61,00,74,00,6f,00,72,00,00,00,45,00,78,00,74,\
00,65,00,6e,00,64,00,65,00,64,00,20,00,42,00,61,00,73,00,65,00,00,00,50,00,\
43,00,49,00,20,00,43,00,6f,00,6e,00,66,00,69,00,67,00,75,00,72,00,61,00,74,\
00,69,00,6f,00,6e,00,00,00,4d,00,53,00,20,00,54,00,72,00,61,00,6e,00,73,00,\
61,00,63,00,74,00,69,00,6f,00,6e,00,73,00,00,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\VirtualDeviceDrivers]
; Contents of value:
; C:\PROGRA~1\Symantec\S32EVNT1.DLL
; C:\Program Files\Alwil Software\Avast4\aswMonVd.dll
;
"VDD"=hex(7):43,00,3a,00,5c,00,50,00,52,00,4f,00,47,00,52,00,41,00,7e,00,31,00,\
5c,00,53,00,79,00,6d,00,61,00,6e,00,74,00,65,00,63,00,5c,00,53,00,33,00,32,\
00,45,00,56,00,4e,00,54,00,31,00,2e,00,44,00,4c,00,4c,00,00,00,43,00,3a,00,\
5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,20,00,46,00,69,00,6c,00,65,\
00,73,00,5c,00,41,00,6c,00,77,00,69,00,6c,00,20,00,53,00,6f,00,66,00,74,00,\
77,00,61,00,72,00,65,00,5c,00,41,00,76,00,61,00,73,00,74,00,34,00,5c,00,61,\
00,73,00,77,00,4d,00,6f,00,6e,00,56,00,64,00,2e,00,64,00,6c,00,6c,00,00,00,\
00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CCEVTMGR\0000]
"DeviceDesc"="Symantec Event Manager"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application]
; Contents of value:
; WSH
; WMIAdapter
; WmdmPmSN
; WLANKEEPER
; WinMgmt
; Winlogon
; Windows Product Activation
; Windows 3.1 Migration
; WebClient
; VSS
; VBRuntime
; Userinit
; Userenv
; TZMOVE
; Tlntsvr
; SysmonLog
; Symantec AntiVirus
; Starter
; SQLCTR$ACT7
; SQLAgent$ACT7
; SpoolerCtrs
; Software Restriction Policies
; Software Installation
; SecurityCenter
; SclgNtfy
; SceSrv
; SceCli
; SavRoam
; safrslv
; SAFrdms
; RPC
; Remote Assistance
; PerfProc
; PerfOS
; PerfNet
; Perfmon
; Perflib
; PerfDisk
; Perfctrs
; Outlook
; Offline Files
; Oakley
; ntbackup
; MSSQLServerADHelper
; MSSQLSERVER/MSDE
; MsiInstaller
; MSDTC Client
; MSDTC
; MSDMine
; mnmsrvc
; Microsoft Office Document Imaging
; Microsoft Office 11
; Microsoft H.323 Telephony Service Provider
; MDM
; LoadPerf
; LiveUpdate
; IntelliType Pro
; IntelliPoint
; HelpSvc
; Folder Redirection
; File Deployment
; EventSystem
; ESENT
; DrWatson
; DiskQuota
; Defwatch
; crypt32
; COM+
; COM
; Ci
; Chkdsk
; ccSetMgr
; ccEvtMgr
; Bonjour Service
; AutoEnrollment
; Autochk
; ASP.NET 1.1.4322.0
; Application Management
; Application Hang
; Application Error
; AegisP
; ACT7
; ACT! Scheduler
; .NET Runtime
; Application
;
"Sources"=hex(7):57,00,53,00,48,00,00,00,57,00,4d,00,49,00,41,00,64,00,61,00,\
70,00,74,00,65,00,72,00,00,00,57,00,6d,00,64,00,6d,00,50,00,6d,00,53,00,4e,\
00,00,00,57,00,4c,00,41,00,4e,00,4b,00,45,00,45,00,50,00,45,00,52,00,00,00,\
57,00,69,00,6e,00,4d,00,67,00,6d,00,74,00,00,00,57,00,69,00,6e,00,6c,00,6f,\
00,67,00,6f,00,6e,00,00,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,20,00,\
50,00,72,00,6f,00,64,00,75,00,63,00,74,00,20,00,41,00,63,00,74,00,69,00,76,\
00,61,00,74,00,69,00,6f,00,6e,00,00,00,57,00,69,00,6e,00,64,00,6f,00,77,00,\
73,00,20,00,33,00,2e,00,31,00,20,00,4d,00,69,00,67,00,72,00,61,00,74,00,69,\
00,6f,00,6e,00,00,00,57,00,65,00,62,00,43,00,6c,00,69,00,65,00,6e,00,74,00,\
00,00,56,00,53,00,53,00,00,00,56,00,42,00,52,00,75,00,6e,00,74,00,69,00,6d,\
00,65,00,00,00,55,00,73,00,65,00,72,00,69,00,6e,00,69,00,74,00,00,00,55,00,\
73,00,65,00,72,00,65,00,6e,00,76,00,00,00,54,00,5a,00,4d,00,4f,00,56,00,45,\
00,00,00,54,00,6c,00,6e,00,74,00,73,00,76,00,72,00,00,00,53,00,79,00,73,00,\
6d,00,6f,00,6e,00,4c,00,6f,00,67,00,00,00,53,00,79,00,6d,00,61,00,6e,00,74,\
00,65,00,63,00,20,00,41,00,6e,00,74,00,69,00,56,00,69,00,72,00,75,00,73,00,\
00,00,53,00,74,00,61,00,72,00,74,00,65,00,72,00,00,00,53,00,51,00,4c,00,43,\
00,54,00,52,00,24,00,41,00,43,00,54,00,37,00,00,00,53,00,51,00,4c,00,41,00,\
67,00,65,00,6e,00,74,00,24,00,41,00,43,00,54,00,37,00,00,00,53,00,70,00,6f,\
00,6f,00,6c,00,65,00,72,00,43,00,74,00,72,00,73,00,00,00,53,00,6f,00,66,00,\
74,00,77,00,61,00,72,00,65,00,20,00,52,00,65,00,73,00,74,00,72,00,69,00,63,\
00,74,00,69,00,6f,00,6e,00,20,00,50,00,6f,00,6c,00,69,00,63,00,69,00,65,00,\
73,00,00,00,53,00,6f,00,66,00,74,00,77,00,61,00,72,00,65,00,20,00,49,00,6e,\
00,73,00,74,00,61,00,6c,00,6c,00,61,00,74,00,69,00,6f,00,6e,00,00,00,53,00,\
65,00,63,00,75,00,72,00,69,00,74,00,79,00,43,00,65,00,6e,00,74,00,65,00,72,\
00,00,00,53,00,63,00,6c,00,67,00,4e,00,74,00,66,00,79,00,00,00,53,00,63,00,\
65,00,53,00,72,00,76,00,00,00,53,00,63,00,65,00,43,00,6c,00,69,00,00,00,53,\
00,61,00,76,00,52,00,6f,00,61,00,6d,00,00,00,73,00,61,00,66,00,72,00,73,00,\
6c,00,76,00,00,00,53,00,41,00,46,00,72,00,64,00,6d,00,73,00,00,00,52,00,50,\
00,43,00,00,00,52,00,65,00,6d,00,6f,00,74,00,65,00,20,00,41,00,73,00,73,00,\
69,00,73,00,74,00,61,00,6e,00,63,00,65,00,00,00,50,00,65,00,72,00,66,00,50,\
00,72,00,6f,00,63,00,00,00,50,00,65,00,72,00,66,00,4f,00,53,00,00,00,50,00,\
65,00,72,00,66,00,4e,00,65,00,74,00,00,00,50,00,65,00,72,00,66,00,6d,00,6f,\
00,6e,00,00,00,50,00,65,00,72,00,66,00,6c,00,69,00,62,00,00,00,50,00,65,00,\
72,00,66,00,44,00,69,00,73,00,6b,00,00,00,50,00,65,00,72,00,66,00,63,00,74,\
00,72,00,73,00,00,00,4f,00,75,00,74,00,6c,00,6f,00,6f,00,6b,00,00,00,4f,00,\
66,00,66,00,6c,00,69,00,6e,00,65,00,20,00,46,00,69,00,6c,00,65,00,73,00,00,\
00,4f,00,61,00,6b,00,6c,00,65,00,79,00,00,00,6e,00,74,00,62,00,61,00,63,00,\
6b,00,75,00,70,00,00,00,4d,00,53,00,53,00,51,00,4c,00,53,00,65,00,72,00,76,\
00,65,00,72,00,41,00,44,00,48,00,65,00,6c,00,70,00,65,00,72,00,00,00,4d,00,\
53,00,53,00,51,00,4c,00,53,00,45,00,52,00,56,00,45,00,52,00,2f,00,4d,00,53,\
00,44,00,45,00,00,00,4d,00,73,00,69,00,49,00,6e,00,73,00,74,00,61,00,6c,00,\
6c,00,65,00,72,00,00,00,4d,00,53,00,44,00,54,00,43,00,20,00,43,00,6c,00,69,\
00,65,00,6e,00,74,00,00,00,4d,00,53,00,44,00,54,00,43,00,00,00,4d,00,53,00,\
44,00,4d,00,69,00,6e,00,65,00,00,00,6d,00,6e,00,6d,00,73,00,72,00,76,00,63,\
00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,4f,00,\
66,00,66,00,69,00,63,00,65,00,20,00,44,00,6f,00,63,00,75,00,6d,00,65,00,6e,\
00,74,00,20,00,49,00,6d,00,61,00,67,00,69,00,6e,00,67,00,00,00,4d,00,69,00,\
63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,4f,00,66,00,66,00,69,00,63,\
00,65,00,20,00,31,00,31,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,\
66,00,74,00,20,00,48,00,2e,00,33,00,32,00,33,00,20,00,54,00,65,00,6c,00,65,\
00,70,00,68,00,6f,00,6e,00,79,00,20,00,53,00,65,00,72,00,76,00,69,00,63,00,\
65,00,20,00,50,00,72,00,6f,00,76,00,69,00,64,00,65,00,72,00,00,00,4d,00,44,\
00,4d,00,00,00,4c,00,6f,00,61,00,64,00,50,00,65,00,72,00,66,00,00,00,4c,00,\
69,00,76,00,65,00,55,00,70,00,64,00,61,00,74,00,65,00,00,00,49,00,6e,00,74,\
00,65,00,6c,00,6c,00,69,00,54,00,79,00,70,00,65,00,20,00,50,00,72,00,6f,00,\
00,00,49,00,6e,00,74,00,65,00,6c,00,6c,00,69,00,50,00,6f,00,69,00,6e,00,74,\
00,00,00,48,00,65,00,6c,00,70,00,53,00,76,00,63,00,00,00,46,00,6f,00,6c,00,\
64,00,65,00,72,00,20,00,52,00,65,00,64,00,69,00,72,00,65,00,63,00,74,00,69,\
00,6f,00,6e,00,00,00,46,00,69,00,6c,00,65,00,20,00,44,00,65,00,70,00,6c,00,\
6f,00,79,00,6d,00,65,00,6e,00,74,00,00,00,45,00,76,00,65,00,6e,00,74,00,53,\
00,79,00,73,00,74,00,65,00,6d,00,00,00,45,00,53,00,45,00,4e,00,54,00,00,00,\
44,00,72,00,57,00,61,00,74,00,73,00,6f,00,6e,00,00,00,44,00,69,00,73,00,6b,\
00,51,00,75,00,6f,00,74,00,61,00,00,00,44,00,65,00,66,00,77,00,61,00,74,00,\
63,00,68,00,00,00,63,00,72,00,79,00,70,00,74,00,33,00,32,00,00,00,43,00,4f,\
00,4d,00,2b,00,00,00,43,00,4f,00,4d,00,00,00,43,00,69,00,00,00,43,00,68,00,\
6b,00,64,00,73,00,6b,00,00,00,63,00,63,00,53,00,65,00,74,00,4d,00,67,00,72,\
00,00,00,63,00,63,00,45,00,76,00,74,00,4d,00,67,00,72,00,00,00,42,00,6f,00,\
6e,00,6a,00,6f,00,75,00,72,00,20,00,53,00,65,00,72,00,76,00,69,00,63,00,65,\
00,00,00,41,00,75,00,74,00,6f,00,45,00,6e,00,72,00,6f,00,6c,00,6c,00,6d,00,\
65,00,6e,00,74,00,00,00,41,00,75,00,74,00,6f,00,63,00,68,00,6b,00,00,00,41,\
00,53,00,50,00,2e,00,4e,00,45,00,54,00,20,00,31,00,2e,00,31,00,2e,00,34,00,\
33,00,32,00,32,00,2e,00,30,00,00,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,\
00,74,00,69,00,6f,00,6e,00,20,00,4d,00,61,00,6e,00,61,00,67,00,65,00,6d,00,\
65,00,6e,00,74,00,00,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,\
00,6f,00,6e,00,20,00,48,00,61,00,6e,00,67,00,00,00,41,00,70,00,70,00,6c,00,\
69,00,63,00,61,00,74,00,69,00,6f,00,6e,00,20,00,45,00,72,00,72,00,6f,00,72,\
00,00,00,41,00,65,00,67,00,69,00,73,00,50,00,00,00,41,00,43,00,54,00,37,00,\
00,00,41,00,43,00,54,00,21,00,20,00,53,00,63,00,68,00,65,00,64,00,75,00,6c,\
00,65,00,72,00,00,00,2e,00,4e,00,45,00,54,00,20,00,52,00,75,00,6e,00,74,00,\
69,00,6d,00,65,00,00,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,\
00,6f,00,6e,00,00,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\ccEvtMgr]
; Contents of value:
; C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,\
00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,43,00,6f,00,6d,00,6d,00,\
6f,00,6e,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,53,00,79,00,6d,00,61,\
00,6e,00,74,00,65,00,63,00,20,00,53,00,68,00,61,00,72,00,65,00,64,00,5c,00,\
63,00,63,00,45,00,76,00,74,00,4d,00,67,00,72,00,2e,00,65,00,78,00,65,00,00,\
00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\ccSetMgr]
; Contents of value:
; C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
"EventMessageFile"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,\
00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,43,00,6f,00,6d,00,6d,00,\
6f,00,6e,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,53,00,79,00,6d,00,61,\
00,6e,00,74,00,65,00,63,00,20,00,53,00,68,00,61,00,72,00,65,00,64,00,5c,00,\
63,00,63,00,53,00,65,00,74,00,4d,00,67,00,72,00,2e,00,65,00,78,00,65,00,00,\
00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Defwatch]
"EventMessageFile"="C:\\Program Files\\Symantec AntiVirus\\DefWatch.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\LiveUpdate]
"EventMessageFile"="C:\\Program Files\\Symantec\\LiveUpdate\\LuComServer.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SavRoam]
"EventMessageFile"="C:\\Program Files\\Symantec AntiVirus\\SavRoam.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Symantec AntiVirus]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\SAVRT]
"EventMessageFile"="C:\\Program Files\\Symantec AntiVirus\\savrt.sys"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SAVRT]
; Contents of value:
; \??\C:\Program Files\Symantec AntiVirus\savrt.sys
"ImagePath"=hex(2):5c,00,3f,00,3f,00,5c,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,\
67,00,72,00,61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,53,00,79,\
00,6d,00,61,00,6e,00,74,00,65,00,63,00,20,00,41,00,6e,00,74,00,69,00,56,00,\
69,00,72,00,75,00,73,00,5c,00,73,00,61,00,76,00,72,00,74,00,2e,00,73,00,79,\
00,73,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SAVRTPEL]
; Contents of value:
; \??\C:\Program Files\Symantec AntiVirus\Savrtpel.sys
"ImagePath"=hex(2):5c,00,3f,00,3f,00,5c,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,\
67,00,72,00,61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,53,00,79,\
00,6d,00,61,00,6e,00,74,00,65,00,63,00,20,00,41,00,6e,00,74,00,69,00,56,00,\
69,00,72,00,75,00,73,00,5c,00,53,00,61,00,76,00,72,00,74,00,70,00,65,00,6c,\
00,2e,00,73,00,79,00,73,00,00,00
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Symantec Client Security]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Symantec AntiVirus\\VPC32.exe"="Symantec AntiVirus"
"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"="Common Client User Session"
"C:\\PROGRA~1\\SYMANT~1\\VPTray.exe"="Symantec AntiVirus"
"C:\\Program Files\\Symantec AntiVirus\\Rtvscan.exe"="Symantec AntiVirus"
"C:\\DOCUME~1\\soseberg\\LOCALS~1\\Temp\\WZSE0.TMP\\SymNRT.exe"="Symantec Removal Utility"
[HKEY_CURRENT_USER\Software\Symantec]
[HKEY_CURRENT_USER\Software\Symantec\ACT!]
[HKEY_CURRENT_USER\Software\Symantec\ACT!\Email]
[HKEY_CURRENT_USER\Software\Symantec\ACT!\Email\Recent Item List]
[HKEY_CURRENT_USER\Software\Symantec\ACT!\Email\Settings]
; End Of The Log...