Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

System Resources Drop Worryingly And Hosts File Has Disappeared


  • Please log in to reply
20 replies to this topic

#1 licensedtoquill

licensedtoquill

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:02:20 AM

Posted 14 July 2006 - 03:40 PM

Does anyone recognise anything unusual in this HijackThis log please? Do all the pointers to various Dell sites mean anything or take up system resources? I suddenly noticed that the HOSTS file had disappeared and I started to receive lots of ads on web pages which I hadnt seen for some years! I run regular adaware and spybot and have used your recommendations on smitrem and smitfraud to remove spyquakeware from my computer: Also, the winfoxpro printer mysteriously disappeared from my computer some weeks ago for no apparent reason

Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\wfxsnt40.exe
C:\PROGRA~1\symantec\winfax\WFXSWTCH.exe
C:\Program Files\Project Lab\DDS\DDS.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\system32\hphmon04.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
D:\Program Files\Phone\Skype.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iolo\System Mechanic 4\SMUtilityBar.exe
C:\WINDOWS\system32\HPHipm11.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Symantec\WinFax\WFXCTL32.EXE
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\NETGEAR\WG511v2\wlancfg5.exe
C:\Program Files\Symantec\WinFax\WFXMOD32.EXE
C:\WINDOWS\Explorer.exe
C:\PROGRA~1\MICROS~2\Office10\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Outlook Express\Msimn.exe
C:\Program Files\Microsoft Office\Office\FRONTPG.EXE
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\PROGRA~1\MOZILL~1\FIREFO~1.EXE
C:\Program Files\Common Files\Microsoft Shared\Speech\sapisvr.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\unzipped\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.kartoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [WFXSwtch] c:\PROGRA~1\symantec\winfax\WFXSWTCH.exe
O4 - HKLM\..\Run: [OneTouch Monitor] D:\PROGRA~1\VISION~1\ONETOU~2.EXE
O4 - HKLM\..\Run: [CCD Manager] "C:\Program Files\Project Lab\DDS\DDS.EXE"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [vf9] C:\WINDOWS\system32\vf9485.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Skype] "D:\Program Files\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [iolo System Mechanic Utility Bar] "C:\Program Files\iolo\System Mechanic 4\SMUtilityBar.exe"
O4 - Global Startup: Acrobat Assistant.lnk.disabled
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Controller.LNK = C:\Program Files\Symantec\WinFax\WFXCTL32.EXE
O4 - Global Startup: Exif Launcher.lnk.disabled
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NETGEAR Smart Wizard.lnk = ?
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {36E4E9BC-4D0C-41B4-90C9-37AFDBFAAD3C} (InforbitHelper Class) - http://download.infotriever.com/bin/ifhelper.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305...meInstaller.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc...,8/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1138768415120
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://webchat.dell.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur...loadManager.ocx
O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - https://rr.esecurecare.net/rnt/rnl/java/RntX.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
O18 - Filter: text/html - (no CLSID) - (no file)
O18 - Filter: text/plain - (no CLSID) - (no file)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

BC AdBot (Login to Remove)

 


#2 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:02:20 AM

Posted 25 July 2006 - 04:40 PM

Hello licensedtoquill and welcome to the BC HijackThis forum. Let's look a little deeper and see what we find.

Download WinPFind2.zip and unzip it to your Desktop. It will create a folder named WinPFind2. Do NOT run the program directly from the zip file.

Now download ca.def and save it to the Plugins folder under the WinPfind2 folder (Note: you might need to right-click on the link and choose 'Save As' depending on your browser setup).

Also download Printers.def and save it to the Plugins folder.
  • Now open the WinPFind2 folder and double-click on winpfind2.exe to start the program.
  • Click on the Services tab. At the top are 2 drop-down boxes. Change the 2nd box to List All Services and then click back on the Configuration tab.
  • In the AddOn-Options box click the checkboxes for
    • CA.def
    • Printers.def
    to select them.
  • Now click the Run All Scans button on the toolbar.
  • When the scans are complete click the Export To Text button in the lower right-hand corner to create a report file. Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Since the report is quite large it will require multiple posts to show it all. Follow the markers for [Start Post #1], [Start Post #2] and [Start Post #3] to divide the report into 3 separate posts and use the Add Reply button to post the information back here.

I will review the information when it comes in.

Cheers.

OT

Edited by OldTimer, 25 July 2006 - 04:45 PM.

I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#3 licensedtoquill

licensedtoquill
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:02:20 AM

Posted 25 July 2006 - 06:52 PM

Many thanks, am following instructions: However ca.def wouldnt download, then printers def wouldnt either. (They both opened up text files which I saved as ANSI .txt files in Notepad)

Scan running and will report back accordingly

#4 licensedtoquill

licensedtoquill
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:02:20 AM

Posted 25 July 2006 - 07:39 PM

Logfile created on: 07/25/2006 20:24
WinPFind2 by OldTimer - Version 1.0.0 Folder = C:\Documents and Settings\Liz\Desktop\WinPFind2\
Microsoft Windows XP (Version = Service Pack 2)
Internet Explorer (Version - 6.0.2900.2180)


[Start Post #1]

Processes
Image Name---------------ProcessID--Thread Count--Parent ID--Base Priority--Full Path (Version Info)
acrotray.exe-------------002064-----0001----------001320-----Normal---------c:\program files\adobe\acrobat 6.0\distillr\acrotray.exe (Adobe Systems Inc. [Ver = 6.0.1.2003102300 | Size = 217194 bytes | Date = 10/24/2003 00:37 | Attr = ])
alg.exe------------------001120-----0006----------000788-----Normal---------c:\windows\system32\alg.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 44544 bytes | Date = 08/04/2004 03:56 | Attr = ])
apntex.exe---------------001136-----0002----------001152-----Normal---------c:\program files\apoint\apntex.exe (Alps Electric Co., Ltd. [Ver = 5.5.1.19 | Size = 45056 bytes | Date = 08/19/2004 09:40 | Attr = ])
apoint.exe---------------000408-----0002----------001320-----Normal---------c:\program files\apoint\apoint.exe (Alps Electric Co., Ltd. [Ver = 5.5.101.141 | Size = 155648 bytes | Date = 09/13/2004 11:33 | Attr = ])
avgamsvr.exe-------------001608-----0009----------000788-----Normal---------c:\progra~1\grisoft\avgfre~1\avgamsvr.exe (GRISOFT, s.r.o. [Ver = 7,1,0,365 | Size = 336896 bytes | Date = 03/30/2006 00:25 | Attr = ])
avgcc.exe----------------000400-----0006----------001320-----Normal---------c:\progra~1\grisoft\avgfre~1\avgcc.exe (GRISOFT, s.r.o. [Ver = 7,1,0,381 | Size = 357888 bytes | Date = 06/08/2006 09:30 | Attr = ])
avgupsvc.exe-------------001624-----0003----------000788-----Normal---------c:\progra~1\grisoft\avgfre~1\avgupsvc.exe (GRISOFT, s.r.o. [Ver = 7,1,0,349 | Size = 84480 bytes | Date = 03/30/2006 00:25 | Attr = ])
csrss.exe----------------000712-----0012----------000628-----Normal---------\??\c:\windows\system32\csrss.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 6144 bytes | Date = 08/04/2004 03:56 | Attr = ])
ctfmon.exe---------------000656-----0001----------001320-----Normal---------c:\windows\system32\ctfmon.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 15360 bytes | Date = 08/04/2004 03:56 | Attr = ])
dds.exe------------------002016-----0004----------001320-----Normal---------c:\program files\project lab\dds\dds.exe (Project Lab Pty. Ltd. [Ver = 1.02.02.04 | Size = 761911 bytes | Date = 09/11/2002 11:14 | Attr = ])
explorer.exe-------------001320-----0016----------001160-----Normal---------c:\windows\explorer.exe (Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 1032192 bytes | Date = 08/04/2004 03:56 | Attr = ])
firefo~1.exe-------------002688-----0010----------001320-----Normal---------c:\progra~1\mozill~1\firefo~1.exe (Mozilla Corporation [Ver = 1.8.0.3: 2006042618 | Size = 7172197 bytes | Date = 05/03/2006 17:02 | Attr = ])
fxssvc.exe---------------001956-----0015----------000788-----Normal---------c:\windows\system32\fxssvc.exe (Microsoft Corporation [Ver = 5.2.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 267776 bytes | Date = 08/04/2004 03:56 | Attr = ])
hpgs2wnf.exe-------------003188-----0004----------000948-----Normal---------c:\progra~1\hewlet~1\hpshar~1\hpgs2wnf.exe ( [Ver = 2,4,0,26 | Size = 65536 bytes | Date = 07/03/2001 10:17 | Attr = ])
hphipm11.exe-------------002824-----0002----------000788-----Normal---------c:\windows\system32\hphipm11.exe (HP [Ver = 4, 5, 0, 770 | Size = 77824 bytes | Date = 01/06/2006 15:07 | Attr = ])
hphmon04.exe-------------000592-----0005----------001320-----Normal---------c:\windows\system32\hphmon04.exe (Hewlett-Packard [Ver = 4,2,41 | Size = 348160 bytes | Date = 01/06/2006 15:07 | Attr = ])
hpzstc07.exe-------------002696-----0004----------003888-----Normal---------c:\windows\system32\spool\drivers\w32x86\3\hpzstc07.exe (HP [Ver = 2,140,0,0 | Size = 372736 bytes | Date = 01/06/2006 15:07 | Attr = ])
hpztsb07.exe-------------000480-----0001----------001320-----Normal---------c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe (HP [Ver = 2,140,0,0 | Size = 188416 bytes | Date = 01/06/2006 15:07 | Attr = ])
lsass.exe----------------000800-----0019----------000736-----Normal---------c:\windows\system32\lsass.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 13312 bytes | Date = 08/04/2004 03:56 | Attr = ])
mdm.exe------------------001692-----0004----------000788-----Normal---------c:\program files\common files\microsoft shared\vs7debug\mdm.exe (Microsoft Corporation [Ver = 7.00.9466 | Size = 322120 bytes | Date = 06/20/2003 03:25 | Attr = ])
onetou~2.exe-------------000508-----0001----------001320-----Normal---------d:\progra~1\vision~1\onetou~2.exe (Visioneer Inc [Ver = 3, 1, 2, 20 | Size = 86016 bytes | Date = 10/31/2001 08:27 | Attr = ])
outlook.exe--------------002980-----0016----------001320-----Normal---------c:\progra~1\micros~2\office10\outlook.exe (Microsoft Corporation [Ver = 10.0.6626 | Size = 47816 bytes | Date = 01/29/2004 19:38 | Attr = R ])
quickdcf.exe-------------002168-----0001----------001320-----Normal---------c:\program files\finepixviewer\quickdcf.exe (FUJI PHOTO FILM CO., LTD. [Ver = 3, 0, 0, 0 | Size = 200704 bytes | Date = 01/07/2002 15:53 | Attr = ])
rundll32.exe-------------001024-----0003----------000680-----Normal---------c:\windows\system32\rundll32.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 33280 bytes | Date = 08/04/2004 03:56 | Attr = ])
services.exe-------------000788-----0014----------000736-----Normal---------c:\windows\system32\services.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 108032 bytes | Date = 08/04/2004 03:56 | Attr = ])
skype.exe----------------000956-----0011----------001320-----Normal---------d:\program files\phone\skype.exe ( [Ver = | Size = 18577448 bytes | Date = 05/11/2006 17:24 | Attr = ])
smss.exe-----------------000628-----0003----------000004-----Normal---------\systemroot\system32\smss.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 50688 bytes | Date = 08/04/2004 03:56 | Attr = ])
smutilitybar.exe---------000964-----0002----------001320-----Normal---------c:\program files\iolo\system mechanic 4\smutilitybar.exe (iolo technologies, LLC [Ver = 4.0.10.0 | Size = 475648 bytes | Date = 06/14/2004 08:21 | Attr = ])
spoolsv.exe--------------001508-----0017----------000788-----Normal---------c:\windows\system32\spoolsv.exe (Microsoft Corporation [Ver = 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519) | Size = 57856 bytes | Date = 06/10/2005 19:53 | Attr = ])
svchost.exe--------------000948-----0016----------000788-----Normal---------c:\windows\system32\svchost.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
svchost.exe--------------001144-----0007----------000788-----Normal---------c:\windows\system32\svchost.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
svchost.exe--------------001808-----0007----------000788-----Normal---------c:\windows\system32\svchost.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
svchost.exe--------------001080-----0088----------000788-----Normal---------c:\windows\system32\svchost.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
svchost.exe--------------001040-----0011----------000788-----Normal---------c:\windows\system32\svchost.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
svchost.exe--------------003304-----0008----------000788-----Normal---------c:\windows\system32\svchost.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
svchost.exe--------------001248-----0015----------000788-----Normal---------c:\windows\system32\svchost.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
teatimer.exe-------------000752-----0003----------001320-----Idle-----------c:\program files\spybot - search & destroy\teatimer.exe (Safer Networking Limited [Ver = 1, 4, 0, 2 | Size = 1415824 bytes | Date = 05/31/2005 02:04 | Attr = ])
wdfmgr.exe---------------001876-----0004----------000788-----Normal---------c:\windows\system32\wdfmgr.exe (Microsoft Corporation [Ver = 5.2.3790.1230 built by: DNSRV(bld4act) | Size = 38912 bytes | Date = 08/11/2004 02:45 | Attr = ])
wfxctl32.exe-------------002136-----0018----------001320-----Normal---------c:\program files\symantec\winfax\wfxctl32.exe ( [Ver = | Size = 549888 bytes | Date = 12/12/2002 07:45 | Attr = R ])
wfxmod32.exe-------------002528-----0007----------002136-----High-----------c:\program files\symantec\winfax\wfxmod32.exe (Symantec Corporation [Ver = 10.00.2002.1212 | Size = 541184 bytes | Date = 12/12/2002 07:45 | Attr = R ])
wfxsnt40.exe-------------000432-----0002----------001320-----Normal---------c:\windows\system32\wfxsnt40.exe (Microsoft Corporation [Ver = 7.00 (Build 019) | Size = 45568 bytes | Date = 12/12/2002 07:45 | Attr = ])
wfxswtch.exe-------------000452-----0004----------001320-----Normal---------c:\progra~1\symantec\winfax\wfxswtch.exe ( [Ver = | Size = 28160 bytes | Date = 12/12/2002 07:45 | Attr = R ])
winlogon.exe-------------000736-----0016----------000628-----High-----------\??\c:\windows\system32\winlogon.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 502272 bytes | Date = 08/04/2004 03:56 | Attr = ])
winpfind2.exe------------003752-----0001----------001320-----Normal---------c:\documents and settings\liz\desktop\winpfind2\winpfind2.exe (OldTimer Tools [Ver = 1.0.0.0 | Size = 381440 bytes | Date = 07/16/2006 09:30 | Attr = ])
winword.exe--------------003640-----0005----------000948-----Normal---------c:\program files\microsoft office\office10\winword.exe (Microsoft Corporation [Ver = 10.0.6764 | Size = 10635976 bytes | Date = 05/31/2005 01:14 | Attr = R ])
wlancfg5.exe-------------002300-----0009----------001320-----Normal---------c:\program files\netgear\wg511v2\wlancfg5.exe ( [Ver = 3, 2, 29, 306 | Size = 1490944 bytes | Date = 11/10/2005 16:55 | Attr = ])

Registry Entries
Key--------------------------------------------------------------------------------------------------------------------- Value (Version Info)
WinPFind2 by OldTimer - Version 1.0.0-----------------------------------------------------------------------------------
Microsoft Windows XP Version = Service Pack 2--------------------------------------------------------------------------
Internet Explorer Version = 6.0.2900.2180------------------------------------------------------------------------------
Internet Explorer Settings----------------------------------------------------------------------------------------------
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page-------------------------------------------------------------- http://www.microsoft.com/isapi/redir.dll?p...ER}&ar=home
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page------------------------------------------------------------- http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default Page------------------------------------------------------------ http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default Search---------------------------------------------------------- http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page-------------------------------------------------------------- %SystemRoot%\system32\blank.htm
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page-------------------------------------------------------------- http://www.kartoo.com/
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page------------------------------------------------------------- http://www.google.com
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page--------------------------------------------------------------
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable------------------------------------------- 0
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride----------------------------------------- <local>
BHO's-------------------------------------------------------------------------------------------------------------------
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}--- AcroIEHlprObj Class = C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated [Ver = 6.0.1.2003110300 | Size = 54248 bytes | Date = 11/03/2003 18:17 | Attr = ])
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}--- = C:\PROGRA~1\SPYBOT~1\SDHelper.dll (Safer Networking Limited [Ver = 1, 4, 0, 0 | Size = 853672 bytes | Date = 05/31/2005 02:04 | Attr = ])
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}--- Google Toolbar Helper = c:\program files\google\googletoolbar1.dll (Google Inc. [Ver = 3, 0, 131, 0 | Size = 1191424 bytes | Date = 02/14/2006 21:05 | Attr = R ])
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}--- AcroIEToolbarHelper Class = C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ( [Ver = | Size = 147456 bytes | Date = 05/15/2003 01:03 | Attr = ])
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDF3E430-B101-42AD-A544-FADC6B084872}--- = (File not found)
Internet Explorer Bars, Toolbars and Extensions-------------------------------------------------------------------------
HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{182EC0BE-5110-49C8-A062-BEB1D02A220B}-------------------------- Adobe PDF = C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ( [Ver = | Size = 147456 bytes | Date = 05/15/2003 01:03 | Attr = ])
HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}-------------------------- &Tip of the Day = %SystemRoot%\System32\shdocvw.dll (Microsoft Corporation [Ver = 6.00.2900.2919 (xpsp_sp2_gdr.060529-0150) | Size = 1494016 bytes | Date = 05/29/2006 11:30 | Attr = ])
HKLM\SOFTWARE\Microsoft\Internet Explorer\ToolBar\\{2318C2B1-4965-11d4-9B18-009027A5CD4F}------------------------------- &Google = c:\program files\google\googletoolbar1.dll (Google Inc. [Ver = 3, 0, 131, 0 | Size = 1191424 bytes | Date = 02/14/2006 21:05 | Attr = R ])
HKLM\SOFTWARE\Microsoft\Internet Explorer\ToolBar\\{47833539-D0C5-4125-9FA8-0819E2EAAC93}------------------------------- Adobe PDF = C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ( [Ver = | Size = 147456 bytes | Date = 05/15/2003 01:03 | Attr = ])
HKLM\SOFTWARE\Microsoft\Internet Explorer\ToolBar\\{EF99BD32-C1FB-11D2-892F-0090271D4F88}------------------------------- = (File not found)
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}----------------------------- MenuText: Sun Java Console = (File not found)
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}----------------------------- MenuText: = (File not found)
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F}----------------------------- ButtonText: Create Mobile Favorite = (File not found)
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F}----------------------------- MenuText: Create Mobile Favorite... = (File not found)
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F}----------------------------- MenuText: = (File not found)
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}----------------------------- MenuText: = (File not found)
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}----------------------------- MenuText: = (File not found)
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}----------------------------- ButtonText: Messenger = C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation [Ver = 4.7.3001 | Size = 1694208 bytes | Date = 10/13/2004 12:24 | Attr = HS])
HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478}-------------------------- = (File not found)
HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{9404901D-06DA-4B23-A0EE-3EA4F64EC9B3}-------------------------- = (File not found)
HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}-------------------------- File Search Explorer Band = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation [Ver = 6.00.2900.2869 (xpsp_sp2_gdr.060316-1512) | Size = 8452096 bytes | Date = 03/17/2006 00:03 | Attr = ])
HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{EFA24E61-B078-11D0-89E4-00C04FC9E26E}-------------------------- Favorites Band = %SystemRoot%\System32\shdocvw.dll (Microsoft Corporation [Ver = 6.00.2900.2919 (xpsp_sp2_gdr.060529-0150) | Size = 1494016 bytes | Date = 05/29/2006 11:30 | Attr = ])
HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{EFA24E64-B078-11D0-89E4-00C04FC9E26E}-------------------------- Explorer Band = %SystemRoot%\System32\shdocvw.dll (Microsoft Corporation [Ver = 6.00.2900.2919 (xpsp_sp2_gdr.060529-0150) | Size = 1494016 bytes | Date = 05/29/2006 11:30 | Attr = ])
HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{01E04581-4EEE-11D0-BFE9-00AA005B4383}------------------ &Address = %SystemRoot%\System32\browseui.dll (Microsoft Corporation [Ver = 6.00.2900.2904 (xpsp_sp2_gdr.060509-0218) | Size = 1022976 bytes | Date = 05/10/2006 01:23 | Attr = ])
HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F}------------------ &Google = c:\program files\google\googletoolbar1.dll (Google Inc. [Ver = 3, 0, 131, 0 | Size = 1191424 bytes | Date = 02/14/2006 21:05 | Attr = R ])
HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}------------------ = (File not found)
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{01E04581-4EEE-11D0-BFE9-00AA005B4383}-------------------- &Address = %SystemRoot%\System32\browseui.dll (Microsoft Corporation [Ver = 6.00.2900.2904 (xpsp_sp2_gdr.060509-0218) | Size = 1022976 bytes | Date = 05/10/2006 01:23 | Attr = ])
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}-------------------- = (File not found)
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383}-------------------- &Links = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation [Ver = 6.00.2900.2869 (xpsp_sp2_gdr.060316-1512) | Size = 8452096 bytes | Date = 03/17/2006 00:03 | Attr = ])
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F}-------------------- &Google = c:\program files\google\googletoolbar1.dll (Google Inc. [Ver = 3, 0, 131, 0 | Size = 1191424 bytes | Date = 02/14/2006 21:05 | Attr = R ])
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}-------------------- = (File not found)
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{47833539-D0C5-4125-9FA8-0819E2EAAC93}-------------------- Adobe PDF = C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ( [Ver = | Size = 147456 bytes | Date = 05/15/2003 01:03 | Attr = ])
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88}-------------------- = (File not found)
HKCU\Software\Microsoft\Internet Explorer\MenuExt\&Google Search-------------------------------------------------------- res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html (Google Inc. [Ver = 3, 0, 131, 0 | Size = 1191424 bytes | Date = 02/14/2006 21:05 | Attr = R ])
HKCU\Software\Microsoft\Internet Explorer\MenuExt\&Translate English Word----------------------------------------------- res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html (Google Inc. [Ver = 3, 0, 131, 0 | Size = 1191424 bytes | Date = 02/14/2006 21:05 | Attr = R ])
HKCU\Software\Microsoft\Internet Explorer\MenuExt\Backward Links-------------------------------------------------------- res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html (Google Inc. [Ver = 3, 0, 131, 0 | Size = 1191424 bytes | Date = 02/14/2006 21:05 | Attr = R ])
HKCU\Software\Microsoft\Internet Explorer\MenuExt\Cached Snapshot of Page----------------------------------------------- res://c:\program files\google\GoogleToolbar1.dll/cmcache.html (Google Inc. [Ver = 3, 0, 131, 0 | Size = 1191424 bytes | Date = 02/14/2006 21:05 | Attr = R ])
HKCU\Software\Microsoft\Internet Explorer\MenuExt\E&xport to Microsoft Excel-------------------------------------------- res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 (Microsoft Corporation [Ver = 10.0.6501 | Size = 9189896 bytes | Date = 12/03/2003 18:04 | Attr = R ])
HKCU\Software\Microsoft\Internet Explorer\MenuExt\Similar Pages--------------------------------------------------------- res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html (Google Inc. [Ver = 3, 0, 131, 0 | Size = 1191424 bytes | Date = 02/14/2006 21:05 | Attr = R ])
HKCU\Software\Microsoft\Internet Explorer\MenuExt\Translate Page into English------------------------------------------- res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html (Google Inc. [Ver = 3, 0, 131, 0 | Size = 1191424 bytes | Date = 02/14/2006 21:05 | Attr = R ])
Approved Shell Extensions (Non-Microsoft only)--------------------------------------------------------------------------
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{1CDB2949-8F65-4355-8456-263E7C208A5D}--------- Desktop Explorer = C:\WINDOWS\System32\nvshell.dll (NVIDIA Corporation [Ver = 6.14.10.4482 | Size = 471112 bytes | Date = 06/24/2003 18:32 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{1E9B04FB-F9E5-4718-997B-B8DA88302A47}--------- = C:\WINDOWS\System32\nvshell.dll (NVIDIA Corporation [Ver = 6.14.10.4482 | Size = 471112 bytes | Date = 06/24/2003 18:32 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{88895560-9AA2-1069-930E-00AA0030EBC8}--------- HyperTerminal Icon Ext = C:\WINDOWS\System32\hticons.dll (Hilgraeve, Inc. [Ver = 5.1.2600.0 | Size = 44544 bytes | Date = 08/17/2001 19:00 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}--------- AVG7 Shell Extension Class = C:\Program Files\Grisoft\AVG Free\avgse.dll (GRISOFT, s.r.o. [Ver = 7,1,0,354 | Size = 40960 bytes | Date = 03/30/2006 00:25 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}--------- AVG7 Find Extension Class = C:\Program Files\Grisoft\AVG Free\avgse.dll (GRISOFT, s.r.o. [Ver = 7,1,0,354 | Size = 40960 bytes | Date = 03/30/2006 00:25 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A4DF5659-0801-4A60-9607-1C48695EFDA9}--------- Share-to-Web Upload Folder = C:\Program Files\Hewlett-Packard\HP Share-to-Web\HPGS2WNS.DLL (Hewlett-Packard [Ver = 2,4,0,26 | Size = 131072 bytes | Date = 07/03/2001 10:10 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802}--------- Acrobat Elements Context Menu = C:\Program Files\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.dll (Adobe Systems Inc. [Ver = 6.0.0.2003110300\0 | Size = 643160 bytes | Date = 11/03/2003 19:03 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E0D79304-84BE-11CE-9641-444553540000}--------- WinZip = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc. [Ver = 4.1 (32-bit) | Size = 20552 bytes | Date = 02/11/2003 08:10 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E0D79305-84BE-11CE-9641-444553540000}--------- WinZip = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc. [Ver = 4.1 (32-bit) | Size = 20552 bytes | Date = 02/11/2003 08:10 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E0D79306-84BE-11CE-9641-444553540000}--------- WinZip = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc. [Ver = 4.1 (32-bit) | Size = 20552 bytes | Date = 02/11/2003 08:10 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E0D79307-84BE-11CE-9641-444553540000}--------- WinZip = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc. [Ver = 4.1 (32-bit) | Size = 20552 bytes | Date = 02/11/2003 08:10 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}--------- RealOne Player Context Menu Class = C:\Program Files\Real\RealOne Player\rpshell.dll (RealNetworks, Inc. [Ver = 1.0.1.1783 | Size = 49198 bytes | Date = 05/05/2004 13:53 | Attr = ])
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{BDEADF00-C265-11d0-BCED-00A0C90AB50F}--------- Web Folders = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL (Microsoft Corporation [Ver = 10.145.7329.0 | Size = 1277952 bytes | Date = 01/29/2004 10:08 | Attr = ])
ContextMenuHandlers (Non-Microsoft only)--------------------------------------------------------------------------------
HKCR\*\shellex\ContextMenuHandlers\Adobe.Acrobat.ContextMenu------------------------------------------------------------ {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} = C:\Program Files\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.dll (Adobe Systems Inc. [Ver = 6.0.0.2003110300\0 | Size = 643160 bytes | Date = 11/03/2003 19:03 | Attr = ])
HKCR\*\shellex\ContextMenuHandlers\AVG7 Shell Extension----------------------------------------------------------------- {9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG Free\avgse.dll (GRISOFT, s.r.o. [Ver = 7,1,0,354 | Size = 40960 bytes | Date = 03/30/2006 00:25 | Attr = ])
HKCR\*\shellex\ContextMenuHandlers\WinZip------------------------------------------------------------------------------- {E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc. [Ver = 4.1 (32-bit) | Size = 20552 bytes | Date = 02/11/2003 08:10 | Attr = ])
HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\AVG7 Shell Extension------------------------------------------- {9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG Free\avgse.dll (GRISOFT, s.r.o. [Ver = 7,1,0,354 | Size = 40960 bytes | Date = 03/30/2006 00:25 | Attr = ])
HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\WinZip--------------------------------------------------------- {E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc. [Ver = 4.1 (32-bit) | Size = 20552 bytes | Date = 02/11/2003 08:10 | Attr = ])
HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\WinZip------------------------------------------------------ {E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc. [Ver = 4.1 (32-bit) | Size = 20552 bytes | Date = 02/11/2003 08:10 | Attr = ])
ColumnHandlers (Non-Microsoft only)-------------------------------------------------------------------------------------
Registry Run Keys-------------------------------------------------------------------------------------------------------
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Apoint-------------------------------------------------------------- C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd. [Ver = 5.5.101.141 | Size = 155648 bytes | Date = 09/13/2004 11:33 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\AVG7_CC------------------------------------------------------------- C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP (GRISOFT, s.r.o. [Ver = 7,1,0,381 | Size = 357888 bytes | Date = 06/08/2006 09:30 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\CCD Manager--------------------------------------------------------- "C:\Program Files\Project Lab\DDS\DDS.EXE" (Project Lab Pty. Ltd. [Ver = 1.02.02.04 | Size = 761911 bytes | Date = 09/11/2002 11:14 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\HPDJ Taskbar Utility------------------------------------------------ C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe (HP [Ver = 2,140,0,0 | Size = 188416 bytes | Date = 01/06/2006 15:07 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\HPHmon04------------------------------------------------------------ C:\WINDOWS\system32\hphmon04.exe (Hewlett-Packard [Ver = 4,2,41 | Size = 348160 bytes | Date = 01/06/2006 15:07 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\HPHUPD04------------------------------------------------------------ "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe" (File not found)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck---------------------------------------------------- %systemroot%\system32\dumprep 0 -k (File not found)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\NvCplDaemon--------------------------------------------------------- RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup (File not found)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\nwiz---------------------------------------------------------------- nwiz.exe /installquiet (NVIDIA Corporation [Ver = 6.14.10.4482 | Size = 323584 bytes | Date = 06/24/2003 18:32 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\OneTouch Monitor---------------------------------------------------- D:\PROGRA~1\VISION~1\ONETOU~2.EXE (Visioneer Inc [Ver = 3, 1, 2, 20 | Size = 86016 bytes | Date = 10/31/2001 08:27 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task------------------------------------------------------ "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc. [Ver = 6.3 | Size = 77824 bytes | Date = 07/24/2003 16:10 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\REGSHAVE------------------------------------------------------------ C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN (FUJI PHOTO FILM CO., LTD. [Ver = 3.0.0.1 | Size = 53248 bytes | Date = 01/21/2002 17:02 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\SynTPEnh------------------------------------------------------------ C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc. [Ver = 7.2.12 17Mar03 | Size = 569344 bytes | Date = 03/17/2003 19:20 | Attr = R ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\SynTPLpr------------------------------------------------------------ C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc. [Ver = 7.2.12 17Mar03 | Size = 110592 bytes | Date = 03/17/2003 19:21 | Attr = R ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\TkBellExe----------------------------------------------------------- "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc. [Ver = 0.1.0.3018 | Size = 180269 bytes | Date = 05/05/2004 13:52 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\UserFaultCheck------------------------------------------------------ %systemroot%\system32\dumprep 0 -u (File not found)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\vf9----------------------------------------------------------------- C:\WINDOWS\system32\vf9485.exe (File not found)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\WFXSwtch------------------------------------------------------------ c:\PROGRA~1\symantec\winfax\WFXSWTCH.exe ( [Ver = | Size = 28160 bytes | Date = 12/12/2002 07:45 | Attr = R ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\WinFaxAppPortStarter------------------------------------------------ wfxsnt40.exe (Microsoft Corporation [Ver = 7.00 (Build 019) | Size = 45568 bytes | Date = 12/12/2002 07:45 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL--------------------------------------------- Installed = 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI---------------------------------------------- Installed = 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS---------------------------------------------- Installed = 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\ctfmon.exe---------------------------------------------------------- C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 15360 bytes | Date = 08/04/2004 03:56 | Attr = ])
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\iolo System Mechanic Utility Bar------------------------------------ "C:\Program Files\iolo\System Mechanic 4\SMUtilityBar.exe" (iolo technologies, LLC [Ver = 4.0.10.0 | Size = 475648 bytes | Date = 06/14/2004 08:21 | Attr = ])
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\NVIEW--------------------------------------------------------------- rundll32.exe nview.dll,nViewLoadHook (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 33280 bytes | Date = 08/04/2004 03:56 | Attr = ])
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\NvMediaCenter------------------------------------------------------- RunDLL32.exe NvMCTray.dll,NvTaskbarInit (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 33280 bytes | Date = 08/04/2004 03:56 | Attr = ])
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Skype--------------------------------------------------------------- "D:\Program Files\Phone\Skype.exe" /nosplash /minimized ( [Ver = | Size = 18577448 bytes | Date = 05/11/2006 17:24 | Attr = ])
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\SpybotSD TeaTimer--------------------------------------------------- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited [Ver = 1, 4, 0, 2 | Size = 1415824 bytes | Date = 05/31/2005 02:04 | Attr = ])
Startup Lnks------------------------------------------------------------------------------------------------------------
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk----------------------------------- C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc. [Ver = 6.0.1.2003102300 | Size = 217194 bytes | Date = 10/24/2003 00:37 | Attr = ])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk---------------------------------- C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc. [Ver = 1, 0, 0, 1 | Size = 113664 bytes | Date = 11/04/1999 15:06 | Attr = ])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Controller.LNK------------------------------------------ C:\Program Files\Symantec\WinFax\WFXCTL32.EXE ( [Ver = | Size = 549888 bytes | Date = 12/12/2002 07:45 | Attr = R ])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DESKTOP.INI--------------------------------------------- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DESKTOP.INI ( [Ver = | Size = 84 bytes | Date = 08/30/2001 22:50 | Attr = HS])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Exif Launcher.lnk--------------------------------------- C:\Program Files\FinePixViewer\QuickDCF.exe (FUJI PHOTO FILM CO., LTD. [Ver = 3, 0, 0, 0 | Size = 200704 bytes | Date = 01/07/2002 15:53 | Attr = ])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk------------------------------------ C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation [Ver = 10.0.2609 | Size = 83360 bytes | Date = 02/12/2001 13:01 | Attr = ])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR Smart Wizard.lnk-------------------------------- C:\WINDOWS\Installer\{B93D24B3-928D-4805-B379-4AA47CB3794E}\NewShortcut1_1.exe ( [Ver = | Size = 2238 bytes | Date = 06/07/2006 08:32 | Attr = R ])
C:\Documents and Settings\Liz\Start Menu\Programs\Startup\DESKTOP.INI--------------------------------------------------- C:\Documents and Settings\Liz\Start Menu\Programs\Startup\DESKTOP.INI ( [Ver = | Size = 84 bytes | Date = 08/30/2001 22:50 | Attr = HS])
Disabled MSConfig Items-------------------------------------------------------------------------------------------------
User Agent Post Platform------------------------------------------------------------------------------------------------
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\\SV1--------------------------
AppInit DLLs------------------------------------------------------------------------------------------------------------
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs------------------------------------------------- (File not found)
Image File Execution Options--------------------------------------------------------------------------------------------
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path- Debugger = ntsd -d
Shell Service Object Delay Load-----------------------------------------------------------------------------------------
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\CDBurn-------------------------------------- {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation [Ver = 6.00.2900.2869 (xpsp_sp2_gdr.060316-1512) | Size = 8452096 bytes | Date = 03/17/2006 00:03 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\PostBootReminder---------------------------- {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation [Ver = 6.00.2900.2869 (xpsp_sp2_gdr.060316-1512) | Size = 8452096 bytes | Date = 03/17/2006 00:03 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\SysTray------------------------------------- {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\system32\stobject.dll (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 121856 bytes | Date = 08/04/2004 03:56 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck------------------------------------ {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\system32\webcheck.dll (Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 276480 bytes | Date = 08/04/2004 03:56 | Attr = ])
Shell Execute Hooks-----------------------------------------------------------------------------------------------------
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972}------- URL Exec Hook = shell32.dll (Microsoft Corporation [Ver = 6.00.2900.2869 (xpsp_sp2_gdr.060316-1512) | Size = 8452096 bytes | Date = 03/17/2006 00:03 | Attr = ])
Shared Task Scheduler---------------------------------------------------------------------------------------------------
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\\{438755C2-A8BA-11D1-B96B-00A0C90312E1}----- = (File not found)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\\{8C7461EF-2B13-11d2-BE35-3078302C2030}----- = (File not found)
Winlogon----------------------------------------------------------------------------------------------------------------
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit---------------------------------------------------- C:\WINDOWS\system32\userinit.exe, (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 24576 bytes | Date = 08/04/2004 03:56 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell------------------------------------------------------- Explorer.exe (Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 1032192 bytes | Date = 08/04/2004 03:56 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\System------------------------------------------------------ (File not found)
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain------------------------------------------ crypt32.dll (Microsoft Corporation [Ver = 5.131.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 597504 bytes | Date = 08/04/2004 03:56 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet---------------------------------------------- cryptnet.dll (Microsoft Corporation [Ver = 5.131.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 63488 bytes | Date = 08/04/2004 03:56 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll------------------------------------------------ cscdll.dll (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 101888 bytes | Date = 08/04/2004 03:56 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp-------------------------------------------- wlnotify.dll (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 92672 bytes | Date = 08/04/2004 03:56 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule---------------------------------------------- wlnotify.dll (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 92672 bytes | Date = 08/04/2004 03:56 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy---------------------------------------------- sclgntfy.dll (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 20992 bytes | Date = 08/04/2004 03:56 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn---------------------------------------------- WlNotify.dll (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 92672 bytes | Date = 08/04/2004 03:56 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv----------------------------------------------- wlnotify.dll (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 92672 bytes | Date = 08/04/2004 03:56 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon---------------------------------------------- WgaLogon.dll (Microsoft Corporation [Ver = 1.5.0540.0 | Size = 702768 bytes | Date = 06/19/2006 16:20 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon--------------------------------------------- wlnotify.dll (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 92672 bytes | Date = 08/04/2004 03:56 | Attr = ])
DNS Name Servers--------------------------------------------------------------------------------------------------------
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{11D04FA2-045A-43DB-964C-7D59B425EA18}--------------- ()
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{4DB0F895-8A84-4B29-B9A1-CF332598DE69}--------------- (Intel 8255x-based PCI Ethernet Adapter (10/100))
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{525A882D-5C75-46F4-A014-DDEE4E086565}--------------- (Belkin 802.11g Network Adapter)
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{A98E1527-102D-4B5A-9EDF-BF7BA9580699}--------------- (Buffalo WLI-PCM-L11 Wireless LAN Adapter)
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C1FC980F-08A1-48CC-832D-67F8B6B67ABF}--------------- 4.2.2.2,4.2.2.1 (3Com 3C920 Integrated Fast Ethernet Controller (3C905C-TX Compatible))
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C4F2D4BA-8CDA-4DE0-B4F6-31EE96A9C309}--------------- (1394 Net Adapter)
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{CFC4DF56-DF7E-49C1-8A76-FC1B0F9B570B}--------------- (NETGEAR WG511v2 54 Mbps Wireless PC Card)
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{DAD0A8A0-D516-40C0-8DC1-FBB4227BBAE8}--------------- (1394 Net Adapter)
Winsock2 Catalogs (Non-Microsoft only)----------------------------------------------------------------------------------
Protocol Handlers (Non-Microsoft only)----------------------------------------------------------------------------------
HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\ipp----------------------------------------------------------------------------- (File not found)
HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp------------------------------------------------------------------------- (File not found)
Protocol Filters (Non-Microsoft only)-----------------------------------------------------------------------------------
HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\text/html------------------------------------------------------------------------ (File not found)
HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\text/plain----------------------------------------------------------------------- (File not found)



[Start Post #2]

Services
Name--------------------------------------------------------Internal Name------------Startup Type---State-----Service Type--------------------------------------Path (Version Info)
Alerter-----------------------------------------------------Alerter------------------Disabled-------Stopped---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k LocalService (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Application Layer Gateway Service---------------------------ALG----------------------On Demand------Running---Win32, running in it's own process----------------C:\WINDOWS\System32\alg.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 44544 bytes | Date = 08/04/2004 03:56 | Attr = ])
Application Management--------------------------------------AppMgmt------------------On Demand------Stopped---Win32, running in a shared process----------------C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
ASP.NET State Service---------------------------------------aspnet_state-------------On Demand------Stopped---Win32, running in it's own process----------------C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation [Ver = 1.1.4322.2032 | Size = 32768 bytes | Date = 07/15/2004 02:49 | Attr = ])
Windows Audio-----------------------------------------------AudioSrv-----------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
AVG7 Alert Manager Server-----------------------------------Avg7Alrt-----------------Automatic------Running---Win32, running in it's own process----------------C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe (GRISOFT, s.r.o. [Ver = 7,1,0,365 | Size = 336896 bytes | Date = 03/30/2006 00:25 | Attr = ])
AVG7 Update Service-----------------------------------------Avg7UpdSvc---------------Automatic------Running---Win32, running in it's own process----------------C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe (GRISOFT, s.r.o. [Ver = 7,1,0,349 | Size = 84480 bytes | Date = 03/30/2006 00:25 | Attr = ])
Background Intelligent Transfer Service---------------------BITS---------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Computer Browser--------------------------------------------Browser------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Indexing Service--------------------------------------------cisvc--------------------On Demand------Stopped---Win32, running in a shared process----------------C:\WINDOWS\System32\cisvc.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 5632 bytes | Date = 08/04/2004 03:56 | Attr = ])
ClipBook----------------------------------------------------ClipSrv------------------Disabled-------Stopped---Win32, running in it's own process----------------C:\WINDOWS\system32\clipsrv.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 33280 bytes | Date = 08/04/2004 03:56 | Attr = ])
COM+ System Application-------------------------------------COMSysApp----------------On Demand------Stopped---Win32, running in it's own process----------------C:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 5120 bytes | Date = 08/04/2004 03:56 | Attr = ])
Cryptographic Services--------------------------------------CryptSvc-----------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
DCOM Server Process Launcher--------------------------------DcomLaunch---------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\system32\svchost -k DcomLaunch (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
DHCP Client-------------------------------------------------Dhcp---------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Logical Disk Manager Administrative Service-----------------dmadmin------------------On Demand------Stopped---Win32, running in a shared process----------------C:\WINDOWS\System32\dmadmin.exe /com (Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Date = 08/04/2004 03:56 | Attr = ])
Logical Disk Manager----------------------------------------dmserver-----------------On Demand------Stopped---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
DNS Client--------------------------------------------------Dnscache-----------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k NetworkService (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Error Reporting Service-------------------------------------ERSvc--------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Event Log---------------------------------------------------Eventlog-----------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\system32\services.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 108032 bytes | Date = 08/04/2004 03:56 | Attr = ])
COM+ Event System-------------------------------------------EventSystem--------------On Demand------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Fast User Switching Compatibility---------------------------FastUserSwitchingCompatibilityOn Demand------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Fax---------------------------------------------------------Fax----------------------Automatic------Running---Win32, running in it's own process----------------C:\WINDOWS\system32\fxssvc.exe (Microsoft Corporation [Ver = 5.2.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 267776 bytes | Date = 08/04/2004 03:56 | Attr = ])
Help and Support--------------------------------------------helpsvc------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
HID Input Service-------------------------------------------HidServ------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
HTTP SSL----------------------------------------------------HTTPFilter---------------On Demand------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k HTTPFilter (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
IMAPI CD-Burning COM Service--------------------------------ImapiService-------------On Demand------Stopped---Win32, running in it's own process----------------C:\WINDOWS\System32\imapi.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 150016 bytes | Date = 08/04/2004 03:56 | Attr = ])
Infrared Monitor--------------------------------------------Irmon--------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchos

#5 licensedtoquill

licensedtoquill
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:02:20 AM

Posted 25 July 2006 - 07:43 PM

[Start Post #3]

AddOn's
File or Key------------------------------------------------------------------------------------------------------------- Info or Value
>>>>Output for AddOn file ca.def<<<<------------------------------------------------------------------------------------
C:\*.log---------------------------------------------------------------------------------------------------------------- Parameters =
C:\hph7550.log---------------------------------------------------------------------------------------------------------- ( [Ver = | Size = 2009 bytes | Date = 07/25/2006 14:10 | Attr = ])
C:\IS0.log-------------------------------------------------------------------------------------------------------------- ( [Ver = | Size = 32 bytes | Date = 02/01/2006 00:15 | Attr = ])
C:\WINDOWS\slave.exe---------------------------------------------------------------------------------------------------- Parameters =
File C:\WINDOWS\slave.exe was not found!------------------------------------------------------------------------------
C:\WINDOWS\SYSTEM32\slave.exe------------------------------------------------------------------------------------------- Parameters =
File C:\WINDOWS\SYSTEM32\slave.exe was not found!---------------------------------------------------------------------
C:\WINDOWS\SYSTEM32\dntus26.exe----------------------------------------------------------------------------------------- Parameters =
File C:\WINDOWS\SYSTEM32\dntus26.exe was not found!-------------------------------------------------------------------
C:\WINDOWS\SYSTEM32\vf9485.exe------------------------------------------------------------------------------------------ Parameters =
File C:\WINDOWS\SYSTEM32\vf9485.exe was not found!--------------------------------------------------------------------
C:\WINDOWS\SYSTEM32\mui\0009\\*.*--------------------------------------------------------------------------------------- Parameters = Include SubFolders
C:\WINDOWS\SYSTEM32\mui\0009\HHCTRLUI.DLL------------------------------------------------------------------------------- (Microsoft Corporation [Ver = 4.74.9273 | Size = 87552 bytes | Date = 08/17/2001 19:00 | Attr = ])
HKLM\SYSTEM\ControlSet001\Services\lsasst------------------------------------------------------------------------------- No SUBKEYS
HKLM\SYSTEM\ControlSet001\Services\lsasst not found.--------------------------------------------------------------------
HKLM\SYSTEM\ControlSet002\Services\lsasst------------------------------------------------------------------------------- No SUBKEYS
HKLM\SYSTEM\ControlSet002\Services\lsasst not found.--------------------------------------------------------------------
HKLM\SYSTEM\ControlSet001\Services\Slave-------------------------------------------------------------------------------- No SUBKEYS
HKLM\SYSTEM\ControlSet001\Services\Slave not found.---------------------------------------------------------------------
HKLM\SYSTEM\ControlSet002\Services\Slave-------------------------------------------------------------------------------- No SUBKEYS
HKLM\SYSTEM\ControlSet002\Services\Slave not found.---------------------------------------------------------------------
HKLM\SYSTEM\ControlSet001\Services\DNTUS26------------------------------------------------------------------------------ No SUBKEYS
HKLM\SYSTEM\ControlSet001\Services\DNTUS26 not found.-------------------------------------------------------------------
HKLM\SYSTEM\ControlSet002\Services\DNTUS26------------------------------------------------------------------------------ No SUBKEYS
HKLM\SYSTEM\ControlSet002\Services\DNTUS26 not found.-------------------------------------------------------------------
>>>>Output for AddOn file printers.def<<<<------------------------------------------------------------------------------
HKCU\Printers----------------------------------------------------------------------------------------------------------- Include SUBKEYS
HKCU\Printers-----------------------------------------------------------------------------------------------------------
HKCU\Printers\\DeviceOld------------------------------------------------------------------------------------------------ Adobe PDF,winspool,Ne06:
HKCU\Printers\Connections-----------------------------------------------------------------------------------------------
HKCU\Printers\DevModePerUser--------------------------------------------------------------------------------------------
HKCU\Printers\DevModePerUser\\\\LIZ_MANNE\Auto Send with eFax Messenger Plus on DUOPOLY2,LocalsplOnly------------------- 53 00 65 00 6E 00 64 00 20 00 77 00 69 00 74 00 68 00 20 00 65 00 46 00 61 00 78 00 20 00 4D 00 65 00 73 00 73 00 65 00 6E 00 67 00 65 00 72 00 20 00 50 00 6C 00 75 00 73 00 00 00 00 00 00 00 00 04 07 02 D4 00 00 00 03 6D 45 00 01 00 01 00 00 00 00 00 00 00 01 00 00 00 2C 01 02 00 00 00 2C 01 01 00 00 00 4C 00 65 00 74 00 74 00 65 00 72 00 20 00 28 00 38 00 20 00 31 00 2F 00 32 00 20 00 78 00 20 00 31 00 31 00 20 00 69 00 6E 00 29 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 18 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
HKCU\Printers\DevModePerUser\\Adobe PDF--------------------------------------------------------------------------------- 41 00 64 00 6F 00 62 00 65 00 20 00 50 00 44 00 46 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 04 02 05 DC 00 F4 04 53 EF 80 01 01 00 01 00 EA 0A 6F 08 64 00 01 00 0F 00 B0 04 02 00 01 00 B0 04 03 00 01 00 4C 00 65 00 74 00 74 00 65 00 72 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 52 49 56 E2 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 18 00 00 00 00 00 10 27 10 27 10 27 00 00 10 27 00 00 00 00 00 00 00 00 00 00 C4 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 03 00 00 00 00 00 00 00 30 02 10 00 5C 4B 03 00 68 43 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 44 9F 6B E6 05 00 00 00 04 00 00 00 FF 00 FF 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 30 02 00 00 45 42 44 41 00 00 01 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 00 00 00 00 53 00 74 00 61 00 6E 00 64 00 61 00 72 00 64 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00
HKCU\Printers\DevModePerUser\\PFRECEPTION------------------------------------------------------------------------------- 50 00 46 00 52 00 45 00 43 00 45 00 50 00 54 00 49 00 4F 00 4E 00 00 00 50 00 46 00 52 00 45 00 43 00 45 00 50 00 54 00 49 00 4F 00 4E 00 2C 00 4C 00 6F 00 63 00 61 00 6C 00 4F 00 6E 00 00 00 01 04 02 05 DC 00 24 0F 53 FF 01 00 01 00 01 00 EA 0A 6F 08 64 00 01 00 0F 00 58 02 01 00 01 00 58 02 03 00 01 00 4C 00 65 00 74 00 74 00 65 00 72 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 52 49 56 E2 30 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 18 00 00 00 00 00 10 27 10 27 10 27 00 00 10 27 00 00 00 00 00 00 00 00 00 00 C4 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 03 00 00 00 00 00 00 00 60 0C 10 00 5C 4B 03 00 5C 4B 03 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 35 18 BA 0D 0F 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 FF 00 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 54 06 00 00 52 4A 50 48 41 41 82 82 00 00 00 00 00 00 00 00 00 00 00 00 4C 00 49 00 5A 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0C 06 00 00 42 41 50 48 41 41 82 82 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
HKCU\Printers\DevModePerUser\\hp photosmart 7550 series----------------------------------------------------------------- 68 00 70 00 20 00 70 00 68 00 6F 00 74 00 6F 00 73 00 6D 00 61 00 72 00 74 00 20 00 37 00 35 00 35 00 30 00 20 00 73 00 65 00 72 00 69 00 65 00 73 00 00 00 72 00 74 00 20 00 37 00 35 00 00 00 01 04 21 40 DC 00 6D 07 03 DF 80 07 01 00 01 00 00 00 00 00 64 00 01 00 07 00 FC FF 02 00 01 00 00 00 03 00 00 00 44 00 72 00 76 00 43 00 6F 00 6E 00 76 00 65 00 72 00 74 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 03 00 00 00 11 04 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 42 83 65 87 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 88 88 08 00 88 88 08 00 00 00 00 00 00 00 00 00 00 00 00 00 00 52 03 00 00 4C 04 00 00 00 64 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 07 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 28 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 41 00 72 00 69 00 61 00 6C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 38 00 00 00 C2 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 42 83 65 87 01 CC DA BA 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 CC DA BA 68 00 70 00 20 00 70 00 68 00 6F 00 74 00 6F 00 73 00 6D 00 61 00 72 00 74 00 20 00 37 00 35 00 35 00 30 00 20 00 73 00 65 00 72 00 69 00 65 00 73 00 00 00 72 00 74 00 20 00 37 00 35 00 35 00 30 00 20 00 73 00 65 00 72 00 69 00 65 00 73 00 2C 00 4C 00 6F 00 63 00 61 00 6C 00 4F 00 6E 00 6C 00 79 00 2C 00 44 00 72 00 76 00 43 00 6F 00 6E 00 76 00 65 00 72 00 74 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
HKCU\Printers\DevModePerUser\\HP DeskJet 950C/952C/959C----------------------------------------------------------------- 48 00 50 00 20 00 44 00 65 00 73 00 6B 00 4A 00 65 00 74 00 20 00 39 00 35 00 30 00 43 00 2F 00 39 00 35 00 32 00 43 00 2F 00 39 00 35 00 39 00 43 00 00 00 39 00 35 00 30 00 43 00 2F 00 00 00 01 04 00 05 DC 00 58 02 43 DF 81 07 01 00 01 00 EA 0A 6F 08 64 00 01 00 0F 00 2C 01 02 00 01 00 2C 01 02 00 01 00 4C 00 65 00 74 00 74 00 65 00 72 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 02 00 00 00 02 00 00 00 01 00 00 00 01 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 44 49 4E 55 22 00 00 00 34 02 24 00 F4 0C 86 D1 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 04 00 00 00 01 00 03 00 01 00 00 00 02 00 02 00 02 00 02 00 02 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 24 00 00 00 98 19 24 02 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 24 00 00 00 98 19 24 02 01 00 00 00
HKCU\Printers\DevModePerUser\\HP LaserJet 5P/5MP PostScript------------------------------------------------------------- 48 00 50 00 20 00 4C 00 61 00 73 00 65 00 72 00 4A 00 65 00 74 00 20 00 35 00 50 00 2F 00 35 00 4D 00 50 00 20 00 50 00 6F 00 73 00 74 00 53 00 63 00 72 00 69 00 70 00 74 00 00 00 35 00 00 00 01 04 02 05 DC 00 C4 02 53 EF 01 00 01 00 01 00 EA 0A 6F 08 64 00 01 00 0F 00 58 02 01 00 01 00 58 02 03 00 01 00 4C 00 65 00 74 00 74 00 65 00 72 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 52 49 56 E2 30 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 18 00 00 00 00 00 10 27 10 27 10 27 00 00 10 27 00 00 00 00 00 00 00 00 00 00 C4 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 00 00 00 00 00 00 10 00 5C 4B 03 00 5C 4B 03 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 A3 D1 65 90 08 00 00 00 00 00 00 00 02 00 00 00 00 00 FF 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
HKCU\Printers\DevModes2-------------------------------------------------------------------------------------------------
HKCU\Printers\DevModes2\\Auto HP LaserJet 1100 (MS) on BROCKEY---------------------------------------------------------- 5C 00 5C 00 42 00 52 00 4F 00 43 00 4B 00 45 00 59 00 5C 00 48 00 50 00 20 00 4C 00 61 00 73 00 65 00 72 00 4A 00 65 00 74 00 20 00 31 00 31 00 30 00 30 00 20 00 28 00 4D 00 53 00 29 00 00 00 01 04 00 05 DC 00 34 02 43 CF 81 05 01 00 01 00 EA 0A 6F 08 64 00 01 00 0F 00 58 02 01 00 01 00 58 02 03 00 01 00 4C 00 65 00 74 00 74 00 65 00 72 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 01 00 00 00 FF FF FF FF 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 44 49 4E 55 22 00 00 00 34 02 00 00 37 12 23 E7 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
HKCU\Printers\DevModes2\\Auto HP LaserJet 6P on VAIO-------------------------------------------------------------------- 5C 00 5C 00 56 00 41 00 49 00 4F 00 5C 00 48 00 50 00 20 00 4C 00 61 00 73 00 65 00 72 00 4A 00 65 00 74 00 20 00 36 00 50 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 04 00 05 DC 00 34 02 43 CF 81 05 01 00 01 00 EA 0A 6F 08 64 00 01 00 0F 00 58 02 01 00 01 00 58 02 03 00 01 00 4C 00 65 00 74 00 74 00 65 00 72 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 01 00 00 00 FF FF FF FF 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 44 49 4E 55 22 00 00 00 34 02 00 00 36 5E C6 F5 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 09 00 00 00 01 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
HKCU\Printers\DevModes2\\Auto Send with eFax Messenger Plus on DUOPOLY2------------------------------------------------- 5C 00 5C 00 44 00 55 00 4F 00 50 00 4F 00 4C 00 59 00 32 00 5C 00 53 00 65 00 6E 00 64 00 20 00 77 00 69 00 74 00 68 00 20 00 65 00 46 00 61 00 78 00 20 00 4D 00 65 00 73 00 73 00 65 00 00 00 00 04 0C 02 D4 00 00 00 03 6D 45 00 01 00 01 00 00 00 00 00 00 00 01 00 00 00 2C 01 02 00 00 00 2C 01 01 00 00 00 4C 00 65 00 74 00 74 00 65 00 72 00 20 00 28 00 38 00 20 00 31 00 2F 00 32 00 20 00 78 00 20 00 31 00 31 00 20 00 69 00 6E 00 29 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 18 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
HKCU\Printers\DevModes2\\Auto Acrobat Distiller on DUOPOLY2------------------------------------------------------------- 5C 00 5C 00 44 00 55 00 4F 00 50 00 4F 00 4C 00 59 00 32 00 5C 00 41 00 63 00 72 00 6F 00 62 00 61 00 74 00 20 00 44 00 69 00 73 00 74 00 69 00 6C 00 6C 00 65 00 72 00 00 00 00 00 00 00 00 00 01 04 02 05 DC 00 EC 04 53 EF 81 01 01 00 01 00 EA 0A 6F 08 64 00 01 00 0F 00 B0 04 02 00 01 00 B0 04 03 00 01 00 4C 00 65 00 74 00 74 00 65 00 72 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 52 49 56 E2 30 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 18 00 00 00 00 00 10 27 10 27 10 27 00 00 10 27 00 00 00 00 00 00 00 00 00 00 C4 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 03 00 00 00 00 00 00 00 28 02 10 00 5C 4B 03 00 68 43 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 85 83 E3 AC 05 00 00 00 04 00 00 00 FF 00 FF 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 28 02 00 00 45 42 44 41 00 00 01 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
HKCU\Printers\DevModes2\\Auto HP OfficeJet V40xi on PROPMAN------------------------------------------------------------- 5C 00 5C 00 50 00 52 00 4F 00 50 00 4D 00 41 00 4E 00 5C 00 48 00 50 00 20 00 4F 00 66 00 66 00 69 00 63 00 65 00 4A 00 65 00 74 00 20 00 56 00 34 00 30 00 78 00 69 00 00 00 00 00 00 00 00 00 01 04 00 05 DC 00 58 02 43 DF 81 07 01 00 01 00 EA 0A 6F 08 64 00 01 00 0F 00 2C 01 02 00 01 00 2C 01 02 00 01 00 4C 00 65 00 74 00 74 00 65 00 72 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 02 00 00 00 02 00 00 00 01 00 00 00 01 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 44 49 4E 55 22 00 00 00 34 02 24 00 F4 0C 86 D1 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 04 00 00 00 01 00 03 00 01 00 00 00 02 00 02 00 02 00 02 00 02 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 24 00 00 00 98 19 24 02 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 24 00 00 00 98 19 24 02 01 00 00 00
HKCU\Printers\DevModes2\\HP OfficeJet 5110------------------------------------------------------------------------------ 48 00 50 00 20 00 4F 00 66 00 66 00 69 00 63 00 65 00 4A 00 65 00 74 00 20 00 35 00 31 00 31 00 30 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 04 00 05 DC 00 34 02 43 CF 81 05 01 00 01 00 EA 0A 6F 08 64 00 01 00 0F 00 2C 01 01 00 01 00 2C 01 02 00 01 00 4C 00 65 00 74 00 74 00 65 00 72 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 01 00 00 00 FF FF FF FF 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 44 49 4E 55 22 00 00 00 34 02 00 00 BA C4 01 2B 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 07 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
HKCU\Printers\DevModes2\\Auto HP OfficeJet G85xi on BERTHOLON----------------------------------------------------------- 5C 00 5C 00 42 00 45 00 52 00 54 00 48 00 4F 00 4C 00 4F 00 4E 00 5C 00 48 00 50 00 20 00 4F 00 66 00 66 00 69 00 63 00 65 00 4A 00 65 00 74 00 20 00 47 00 38 00 35 00 78 00 69 00 00 00 00 00 01 04 00 05 DC 00 58 02 43 DF 81 07 01 00 01 00 EA 0A 6F 08 64 00 01 00 0F 00 2C 01 02 00 01 00 2C 01 02 00 01 00 4C 00 65 00 74 00 74 00 65 00 72 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 02 00 00 00 02 00 00 00 01 00 00 00 01 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 44 49 4E 55 22 00 00 00 34 02 24 00 F4 0C 86 D1 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 04 00 00 00 01 00 03 00 01 00 00 00 02 00 02 00 02 00 02 00 02 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 24 00 00 00 98 19 24 02 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 24 00 00 00 98 19 24 02 01 00 00 00
HKCU\Printers\DevModes2\\Auto Acrobat Distiller on DESKTOP2400---------------------------------------------------------- 5C 00 5C 00 44 00 45 00 53 00 4B 00 54 00 4F 00 50 00 32 00 34 00 30 00 30 00 5C 00 41 00 63 00 72 00 6F 00 62 00 61 00 74 00 20 00 44 00 69 00 73 00 74 00 69 00 6C 00 6C 00 65 00 72 00 00 00 01 04 02 05 DC 00 EC 04 53 EF 81 01 01 00 01 00 EA 0A 6F 08 64 00 01 00 0F 00 B0 04 02 00 01 00 B0 04 03 00 01 00 4C 00 65 00 74 00 74 00 65 00 72 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 52 49 56 E2 30 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 18 00 00 00 00 00 10 27 10 27 10 27 00 00 10 27 00 00 00 00 00 00 00 00 00 00 C4 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 03 00 00 00 00 00 00 00 28 02 10 00 5C 4B 03 00 68 43 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 85 83 E3 AC 05 00 00 00 04 00 00 00 FF 00 FF 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 28 02 00 00 45 42 44 41 00 00 01 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
HKCU\Printers\DevModes2\\Adobe PDF-------------------------------------------------------------------------------------- 41 00 64 00 6F 00 62 00 65 00 20 00 50 00 44 00 46 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 04 02 05 DC 00 F4 04 53 EF 80 01 01 00 01 00 EA 0A 6F 08 64 00 01 00 0F 00 B0 04 02 00 01 00 B0 04 03 00 01 00 4C 00 65 00 74 00 74 00 65 00 72 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 52 49 56 E2 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 18 00 00 00 00 00 10 27 10 27 10 27 00 00 10 27 00 00 00 00 00 00 00 00 00 00 C4 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 03 00 00 00 00 00 00 00 30 02 10 00 5C 4B 03 00 68 43 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 44 9F 6B E6 05 00 00 00 04 00 00 00 FF 00 FF 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 30 02 00 00 45 42 44 41 00 00 01 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 00 00 00 00 53 00 74 00 61 00 6E 00 64 00 61 00 72 00 64 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00
HKCU\Printers\DevModes2\\KONICA MINOLTA magicolor 2400W----------------------------------------------------------------- 4B 00 4F 00 4E 00 49 00 43 00 41 00 20 00 4D 00 49 00 4E 00 4F 00 4C 00 54 00 41 00 20 00 6D 00 61 00 67 00 69 00 63 00 6F 00 6C 00 6F 00 72 00 20 00 32 00 34 00 30 00 30 00 57 00 00 00 00 00 01 04 02 01 DC 00 04 03 03 1F 80 00 01 00 01 00 00 00 00 00 00 00 01 00 01 00 B0 04 02 00 01 00 58 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 53 44 44 4D 03 05 00 00 03 05 00 00 4B 4F 4E 49 43 41 20 4D 49 4E 4F 4C 54 41 20 6D 61 67 69 63 6F 6C 6F 72 20 32 34 30 30 57 00 00 00 00 00 00 43 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00 1B 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 00 00 00 00 01 00 00 00 01 00 00 00 18 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0F 00 00 00 2D 00 00 00 17 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 80 80 80 00 FF 00 00 00 FF FF 00 00 00 FF 00 00 00 FF FF 00 00 00 FF 00 FF 00 FF 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 28 00 00 00 64 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 DE 03 00 00 DE 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 03 01 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2B 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 11 04 00 00 01 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 64 00 00 00 00 00 00 00 02 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 FF 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

#6 licensedtoquill

licensedtoquill
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:02:20 AM

Posted 25 July 2006 - 07:46 PM

HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\\Default DevMode----------------------------------------- 41 00 64 00 6F 00 62 00 65 00 20 00 50 00 44 00 46 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 04 02 05 DC 00 F4 04 53 EF 80 01 01 00 01 00 EA 0A 6F 08 64 00 01 00 0F 00 B0 04 02 00 01 00 B0 04 03 00 01 00 4C 00 65 00 74 00 74 00 65 00 72 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 52 49 56 E2 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 18 00 00 00 00 00 10 27 10 27 10 27 00 00 10 27 00 00 00 00 00 00 00 00 00 00 C4 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 03 00 00 00 00 00 00 00 30 02 10 00 5C 4B 03 00 68 43 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 44 9F 6B E6 05 00 00 00 04 00 00 00 FF 00 FF 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 30 02 00 00 45 42 44 41 00 00 01 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 00 00 00 00 53 00 74 00 61 00 6E 00 64 00 61 00 72 00 64 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\\Priority------------------------------------------------ 1
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\\Default Priority---------------------------------------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\\StartTime----------------------------------------------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\\UntilTime----------------------------------------------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\\Separator File------------------------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\\Location------------------------------------------------ My Documents
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\\Attributes---------------------------------------------- 4104
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\\txTimeout----------------------------------------------- 45000
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\\dnsTimeout---------------------------------------------- 15000
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\\Security------------------------------------------------ 01 00 04 80 B4 00 00 00 C4 00 00 00 00 00 00 00 14 00 00 00 02 00 A0 00 06 00 00 00 00 0A 14 00 00 00 02 00 01 01 00 00 00 00 00 03 00 00 00 00 00 09 14 00 00 00 00 10 01 01 00 00 00 00 00 03 00 00 00 00 00 00 14 00 08 00 02 00 01 01 00 00 00 00 00 01 00 00 00 00 00 0A 14 00 00 00 00 20 01 01 00 00 00 00 00 01 00 00 00 00 00 00 18 00 0C 00 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 0B 18 00 00 00 00 10 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\\SpoolDirectory------------------------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\\Port---------------------------------------------------- My Documents\*.pdf
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsDriver-------------------------------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsDriver\\printBinNames---------------------------------- Automatically Select;OnlyOne;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsDriver\\printCollate----------------------------------- 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsDriver\\printColor------------------------------------- 01
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsDriver\\printDuplexSupported--------------------------- 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsDriver\\printStaplingSupported------------------------- 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsDriver\\printMaxXExtent-------------------------------- 32767
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsDriver\\printMaxYExtent-------------------------------- 32767
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsDriver\\printMinXExtent-------------------------------- 254
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsDriver\\printMinYExtent-------------------------------- 254
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsDriver\\printMediaSupported---------------------------- Letter;Tabloid;Ledger;Legal;Executive;A3;A4;A2;11 x 17;Screen;ANSI C;ANSI D;ANSI E;ANSI F;ARCH A;ARCH B;ARCH C;ARCH D;ARCH E;ARCH E1;ARCH E2;ARCH E3;A1;A0;Oversize A2;Oversize A1;Oversize A0;ISO B5;ISO B4;ISO B2;ISO B1;C5;JIS B4;JIS B3;JIS B2;JIS B1;JIS B0;92 x 92;PostScript Custom Page Size;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsDriver\\printMediaReady-------------------------------- Letter;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsDriver\\printNumberUp---------------------------------- 6
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsDriver\\printMemory------------------------------------ 4096
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsDriver\\printOrientationsSupported--------------------- PORTRAIT;LANDSCAPE;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsDriver\\printMaxResolutionSupported-------------------- 4000
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsDriver\\printLanguage---------------------------------- PostScript;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsDriver\\printRate-------------------------------------- 400
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsDriver\\printRateUnit---------------------------------- PagesPerMinute
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsDriver\\printPagesPerMinute---------------------------- 400
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsDriver\\driverVersion---------------------------------- 1025
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsSpooler------------------------------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsSpooler\\description----------------------------------- Creates Adobe PDF
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsSpooler\\driverName------------------------------------ Adobe PDF Converter
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsSpooler\\location-------------------------------------- My Documents
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsSpooler\\portName-------------------------------------- My Documents\*.pdf;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsSpooler\\printStartTime-------------------------------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsSpooler\\printEndTime---------------------------------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsSpooler\\printerName----------------------------------- Adobe PDF
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsSpooler\\printKeepPrintedJobs-------------------------- 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsSpooler\\printSeparatorFile----------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsSpooler\\printShareName-------------------------------- Printer2
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsSpooler\\printSpooling--------------------------------- PrintWhileSpooling
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsSpooler\\priority-------------------------------------- 1
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsSpooler\\uNCName--------------------------------------- \\Inspiron8100\Adobe PDF
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsSpooler\\versionNumber--------------------------------- 4
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsSpooler\\serverName------------------------------------ Inspiron8100
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsSpooler\\shortServerName------------------------------- INSPIRON8100
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsSpooler\\flags----------------------------------------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\DsSpooler\\url------------------------------------------- http://Inspiron8100/Printer2
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\PrinterDriverData----------------------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\PrinterDriverData\\InitDriverVersion--------------------- 1282
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\PrinterDriverData\\FreeMem------------------------------- 4096
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\PrinterDriverData\\JobTimeOut---------------------------- 120
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\PrinterDriverData\\Protocol------------------------------ 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\PrinterDriverData\\PrinterDataSize----------------------- 560
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\PrinterDriverData\\PrinterData--------------------------- 02 05 30 02 80 0B 00 00 00 00 40 00 78 00 00 00 00 00 00 00 64 00 58 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 44 9F 6B E6 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\PrinterDriverData\\FeatureKeywordSize-------------------- 24
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\PrinterDriverData\\FeatureKeyword------------------------ 49 6E 73 74 61 6C 6C 65 64 4D 65 6D 6F 72 79 00 4E 6F 6E 65 00 0A 00 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\PrinterDriverData\\Forms?-------------------------------- -429154492
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\PrinterDriverData\\DependentFiles------------------------ AD2KREGP.DLL;AD2KUIGP.DLL;AD2KGELP.INI;PSCRIPT.NTF;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\PrinterDriverData\\HostFontExceptFonts------------------- 00 00 00 00 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\PrinterDriverData\\HostFontExceptCIDFonts---------------- 00 00 00 00 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\PrinterDriverData\\DistillerHostFontHasMostFonts--------- 1
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\PrinterDriverData\\ViewPrintOutput----------------------- 1
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\PrinterDriverData\\PromptForFileName--------------------- 1
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\PrinterDriverData\\DeleteLogFiles------------------------ 1
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\PrinterDriverData\\AddDocInfo---------------------------- 1
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Adobe PDF\PrinterDriverData\\AskToReplacePDF----------------------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400------------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\\ChangeID-------------------- 1472657
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\\Status---------------------- 384
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\\Name------------------------ Auto Acrobat Distiller on DESKTOP2400
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\\Share Name------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\\Print Processor------------- WinPrint
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\\Datatype-------------------- RAW
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\\Parameters------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\\Action---------------------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\\ObjectGUID------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\\DsKeyUpdate----------------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\\DsKeyUpdateForeground------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\\Description-----------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\\Printer Driver-------------- AdobePS Acrobat Distiller
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\\Default DevMode------------- 41 00 75 00 74 00 6F 00 20 00 41 00 63 00 72 00 6F 00 62 00 61 00 74 00 20 00 44 00 69 00 73 00 74 00 69 00 6C 00 6C 00 65 00 72 00 20 00 6F 00 6E 00 20 00 44 00 45 00 53 00 4B 00 54 00 00 00 01 04 02 05 DC 00 C4 02 53 EF 81 01 01 00 01 00 EA 0A 6F 08 64 00 01 00 0F 00 B0 04 02 00 01 00 B0 04 03 00 01 00 4C 00 65 00 74 00 74 00 65 00 72 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 52 49 56 E2 30 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 18 00 00 00 00 00 10 27 10 27 10 27 00 00 10 27 00 00 00 00 00 00 00 00 00 00 C4 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 03 00 00 00 00 00 00 00 00 00 10 00 5C 4B 03 00 68 43 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 85 83 E3 AC 05 00 00 00 04 00 00 00 FF 00 FF 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\\Priority-------------------- 1
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\\Default Priority------------ 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\\StartTime------------------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\\UntilTime------------------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\\Separator File--------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\\Location--------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\\Attributes------------------ 64
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\\txTimeout------------------- 45000
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\\dnsTimeout------------------ 15000
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\\Security-------------------- 01 00 04 80 C0 00 00 00 DC 00 00 00 00 00 00 00 14 00 00 00 02 00 AC 00 06 00 00 00 00 0A 14 00 00 00 02 00 01 01 00 00 00 00 00 03 00 00 00 00 00 09 14 00 00 00 00 10 01 01 00 00 00 00 00 03 00 00 00 00 00 00 14 00 08 00 02 00 01 01 00 00 00 00 00 01 00 00 00 00 00 0A 14 00 00 00 00 20 01 01 00 00 00 00 00 01 00 00 00 00 00 00 18 00 0C 00 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 0B 18 00 00 00 00 10 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 05 00 00 00 00 00 05 15 00 00 00 27 C7 40 9A 81 77 E4 E9 15 25 E6 21 EF 03 00 00 01 05 00 00 00 00 00 05 15 00 00 00 27 C7 40 9A 81 77 E4 E9 15 25 E6 21 01 02 00 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\\SpoolDirectory--------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\\Port------------------------ \\DESKTOP2400\Printer7
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsDriver---------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsDriver\\printBinNames------ Automatically Select;OnlyOne;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsDriver\\printCollate------- 01
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsDriver\\printColor--------- 01
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsDriver\\printDuplexSupported 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsDriver\\printStaplingSupported 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsDriver\\printMaxXExtent---- 32767
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsDriver\\printMaxYExtent---- 32767
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsDriver\\printMinXExtent---- 254
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsDriver\\printMinYExtent---- 254
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsDriver\\printMediaSupported Letter;Tabloid;Ledger;Legal;Executive;A3;A4;11 x 17;Screen;PostScript Custom Page Size;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsDriver\\printMediaReady---- Letter;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsDriver\\printNumberUp------ 6
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsDriver\\printMemory-------- 4096
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsDriver\\printOrientationsSupported PORTRAIT;LANDSCAPE;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsDriver\\printMaxResolutionSupported 4000
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsDriver\\printLanguage------ PostScript;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsDriver\\printRate---------- 400
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsDriver\\printRateUnit------ PagesPerMinute
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsDriver\\printPagesPerMinute 400
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsDriver\\driverVersion------ 1025
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsSpooler--------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsSpooler\\description-------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsSpooler\\driverName-------- AdobePS Acrobat Distiller
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsSpooler\\location----------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsSpooler\\portName---------- \\DESKTOP2400\Printer7;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsSpooler\\printStartTime---- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsSpooler\\printEndTime------ 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsSpooler\\printerName------- Auto Acrobat Distiller on DESKTOP2400
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsSpooler\\printKeepPrintedJobs 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsSpooler\\printSeparatorFile
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsSpooler\\printShareName----
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsSpooler\\printSpooling----- PrintWhileSpooling
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsSpooler\\priority---------- 1
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsSpooler\\uNCName----------- \\Maria_Ripanykhazova\Auto Acrobat Distiller on DESKTOP2400
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsSpooler\\versionNumber----- 4
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsSpooler\\serverName-------- Maria_Ripanykhazova
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsSpooler\\shortServerName--- Maria_Ripanykhazova
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\DsSpooler\\flags------------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\PrinterDriverData------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\PrinterDriverData\\InitDriverVersion 1282
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\PrinterDriverData\\FreeMem--- 4096
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\PrinterDriverData\\JobTimeOut 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\PrinterDriverData\\Protocol-- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\PrinterDriverData\\PrinterDataSize 560
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\PrinterDriverData\\PrinterData 02 05 30 02 80 08 00 00 00 00 40 00 00 00 00 00 2C 01 00 00 64 00 58 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 85 83 E3 AC 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\PrinterDriverData\\FeatureKeywordSize 24
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\PrinterDriverData\\FeatureKeyword 49 6E 73 74 61 6C 6C 65 64 4D 65 6D 6F 72 79 00 4E 6F 6E 65 00 0A 00 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\PrinterDriverData\\Forms?---- -1394375803
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\PrinterDriverData\\DependentFiles AD2KREPI.DLL;AD2KUIPI.DLL;AD2KUIPI.INI;PSCRIPT.NTF;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\PrinterDriverData\\HostFontExceptFonts 00 00 00 00 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\PrinterDriverData\\HostFontExceptCIDFonts 00 00 00 00 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\PrinterDriverData\\DistillerHostFontHasMostFonts 1
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\PrinterDriverData\\ViewPrintOutput 1
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\PrinterDriverData\\PromptForFileName 1
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\PrinterDriverData\\DeleteLogFiles 1
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DESKTOP2400\PrinterDriverData\\AskToReplacePDF 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2---------------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\\ChangeID----------------------- 1472657
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\\Status------------------------- 384
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\\Name--------------------------- Auto Acrobat Distiller on DUOPOLY2
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\\Share Name---------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\\Print Processor---------------- WinPrint
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\\Datatype----------------------- RAW
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\\Parameters---------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\\Action------------------------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\\ObjectGUID---------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\\DsKeyUpdate-------------------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\\DsKeyUpdateForeground---------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\\Description--------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\\Printer Driver----------------- AdobePS Acrobat Distiller
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\\Default DevMode---------------- 41 00 75 00 74 00 6F 00 20 00 41 00 63 00 72 00 6F 00 62 00 61 00 74 00 20 00 44 00 69 00 73 00 74 00 69 00 6C 00 6C 00 65 00 72 00 20 00 6F 00 6E 00 20 00 44 00 55 00 4F 00 50 00 4F 00 00 00 01 04 02 05 DC 00 C4 02 53 EF 81 01 01 00 01 00 EA 0A 6F 08 64 00 01 00 0F 00 B0 04 02 00 01 00 B0 04 03 00 01 00 4C 00 65 00 74 00 74 00 65 00 72 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 52 49 56 E2 30 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 18 00 00 00 00 00 10 27 10 27 10 27 00 00 10 27 00 00 00 00 00 00 00 00 00 00 C4 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 03 00 00 00 00 00 00 00 00 00 10 00 5C 4B 03 00 68 43 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 85 83 E3 AC 05 00 00 00 04 00 00 00 FF 00 FF 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\\Priority----------------------- 1
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\\Default Priority--------------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\\StartTime---------------------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\\UntilTime---------------------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\\Separator File-----------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\\Location-----------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\\Attributes--------------------- 64
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\\txTimeout---------------------- 45000
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\\dnsTimeout--------------------- 15000
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\\Security----------------------- 01 00 04 80 C0 00 00 00 DC 00 00 00 00 00 00 00 14 00 00 00 02 00 AC 00 06 00 00 00 00 0A 14 00 00 00 02 00 01 01 00 00 00 00 00 03 00 00 00 00 00 09 14 00 00 00 00 10 01 01 00 00 00 00 00 03 00 00 00 00 00 00 14 00 08 00 02 00 01 01 00 00 00 00 00 01 00 00 00 00 00 0A 14 00 00 00 00 20 01 01 00 00 00 00 00 01 00 00 00 00 00 00 18 00 0C 00 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 0B 18 00 00 00 00 10 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 05 00 00 00 00 00 05 15 00 00 00 27 C7 40 9A 81 77 E4 E9 15 25 E6 21 EF 03 00 00 01 05 00 00 00 00 00 05 15 00 00 00 27 C7 40 9A 81 77 E4 E9 15 25 E6 21 01 02 00 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\\SpoolDirectory-----------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\\Port--------------------------- \\DUOPOLY2\Printer
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsDriver------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsDriver\\printBinNames--------- Automatically Select;OnlyOne;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsDriver\\printCollate---------- 01
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsDriver\\printColor------------ 01
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsDriver\\printDuplexSupported-- 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsDriver\\printStaplingSupported 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsDriver\\printMaxXExtent------- 32767
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsDriver\\printMaxYExtent------- 32767
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsDriver\\printMinXExtent------- 254
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsDriver\\printMinYExtent------- 254
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsDriver\\printMediaSupported--- Letter;Tabloid;Ledger;Legal;Executive;A3;A4;11 x 17;Screen;PostScript Custom Page Size;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsDriver\\printMediaReady------- Letter;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsDriver\\printNumberUp--------- 6
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsDriver\\printMemory----------- 4096
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsDriver\\printOrientationsSupported PORTRAIT;LANDSCAPE;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsDriver\\printMaxResolutionSupported 4000
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsDriver\\printLanguage--------- PostScript;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsDriver\\printRate------------- 400
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsDriver\\printRateUnit--------- PagesPerMinute
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsDriver\\printPagesPerMinute--- 400
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsDriver\\driverVersion--------- 1025
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsSpooler-----------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsSpooler\\description----------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsSpooler\\driverName----------- AdobePS Acrobat Distiller
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsSpooler\\location-------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsSpooler\\portName------------- \\DUOPOLY2\Printer;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsSpooler\\printStartTime------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsSpooler\\printEndTime--------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsSpooler\\printerName---------- Auto Acrobat Distiller on DUOPOLY2
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsSpooler\\printKeepPrintedJobs- 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsSpooler\\printSeparatorFile---
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsSpooler\\printShareName-------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsSpooler\\printSpooling-------- PrintWhileSpooling
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsSpooler\\priority------------- 1
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsSpooler\\uNCName-------------- \\Maria_Ripanykhazova\Auto Acrobat Distiller on DUOPOLY2
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsSpooler\\versionNumber-------- 4
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsSpooler\\serverName----------- Maria_Ripanykhazova
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsSpooler\\shortServerName------ D_MANZALUNI
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsSpooler\\flags---------------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\DsSpooler\\url------------------ http://Maria_Ripanykhazova/
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\PrinterDriverData---------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\PrinterDriverData\\IniData5----- OEMConfigFile1;AD2kUIPI.DLL;OEMDriverFile1;AD2KRePi.DLL;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\PrinterDriverData\\InitDriverVersion 1282
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\PrinterDriverData\\FreeMem------ 4096
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\PrinterDriverData\\JobTimeOut--- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\PrinterDriverData\\Protocol----- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\PrinterDriverData\\PrinterDataSize 560
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\PrinterDriverData\\PrinterData-- 02 05 30 02 80 08 00 00 00 00 40 00 00 00 00 00 2C 01 00 00 64 00 58 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 85 83 E3 AC 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\PrinterDriverData\\FeatureKeywordSize 24
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\PrinterDriverData\\FeatureKeyword 49 6E 73 74 61 6C 6C 65 64 4D 65 6D 6F 72 79 00 4E 6F 6E 65 00 0A 00 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\PrinterDriverData\\Forms?------- -1394375803
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\PrinterDriverData\\DependentFiles AD2KREPI.DLL;AD2KUIPI.DLL;AD2KUIPI.INI;PSCRIPT.NTF;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\PrinterDriverData\\HostFontExceptFonts 41 72 69 61 6C 2D 42 6F 6C 64 49 74 61 6C 69 63 4D 54 00 41 72 69 61 6C 2D 42 6F 6C 64 4D 54 00 41 72 69 61 6C 2D 49 74 61 6C 69 63 4D 54 00 41 72 69 61 6C 4D 54 00 54 69 6D 65 73 4E 65 77 52 6F 6D 61 6E 50 53 2D 42 6F 6C 64 49 74 61 6C 69 63 4D 54 00 54 69 6D 65 73 4E 65 77 52 6F 6D 61 6E 50 53 2D 42 6F 6C 64 4D 54 00 54 69 6D 65 73 4E 65 77 52 6F 6D 61 6E 50 53 2D 49 74 61 6C 69 63 4D 54 00 54 69 6D 65 73 4E 65 77 52 6F 6D 61 6E 50 53 4D 54 00 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\PrinterDriverData\\HostFontExceptCIDFonts 00 00 00 00 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\PrinterDriverData\\DistillerHostFontHasMostFonts 1
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\PrinterDriverData\\ViewPrintOutput 1
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\PrinterDriverData\\PromptForFileName 1
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\PrinterDriverData\\DeleteLogFiles 1
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Acrobat Distiller on DUOPOLY2\PrinterDriverData\\AskToReplacePDF 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Send with eFax Messenger Plus on DUOPOLY2---------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Send with eFax Messenger Plus on DUOPOLY2\\ChangeID----------- 6837051
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Send with eFax Messenger Plus on DUOPOLY2\\Status------------- 128
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Send with eFax Messenger Plus on DUOPOLY2\\Name--------------- Auto Send with eFax Messenger Plus on DUOPOLY2
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Send with eFax Messenger Plus on DUOPOLY2\\Share Name---------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Send with eFax Messenger Plus on DUOPOLY2\\Print Processor---- WinPrint
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Send with eFax Messenger Plus on DUOPOLY2\\Datatype----------- RAW
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Send with eFax Messenger Plus on DUOPOLY2\\Parameters---------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Send with eFax Messenger Plus on DUOPOLY2\\Action------------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Send with eFax Messenger Plus on DUOPOLY2\\ObjectGUID---------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Send with eFax Messenger Plus on DUOPOLY2\\DsKeyUpdate-------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Send with eFax Messenger Plus on DUOPOLY2\\DsKeyUpdateForeground 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Send with eFax Messenger Plus on DUOPOLY2\\Description--------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Send with eFax Messenger Plus on DUOPOLY2\\Printer Driver----- Send with eFax Messenger Plus
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Send with eFax Messenger Plus on DUOPOLY2\\Default DevMode---- 41 00 75 00 74 00 6F 00 20 00 53 00 65 00 6E 00 64 00 20 00 77 00 69 00 74 00 68 00 20 00 65 00 46 00 61 00 78 00 20 00 4D 00 65 00 73 00 73 00 65 00 6E 00 67 00 65 00 72 00 20 00 50 00 00 00 00 04 07 02 D4 00 00 00 03 6D 45 00 01 00 01 00 00 00 00 00 00 00 01 00 00 00 2C 01 02 00 00 00 2C 01 01 00 00 00 4C 00 65 00 74 00 74 00 65 00 72 00 20 00 28 00 38 00 20 00 31 00 2F 00 32 00 20 00 78 00 20 00 31 00 31 00 20 00 69 00 6E 00 29 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 18 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Send with eFax Messenger Plus on DUOPOLY2\\Priority----------- 1
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Send with eFax Messenger Plus on DUOPOLY2\\Default Priority--- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\Auto Send with eFax Messenger Plus on DUOPOLY2�

#7 licensedtoquill

licensedtoquill
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:02:20 AM

Posted 25 July 2006 - 07:47 PM

HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\\Default Priority------------------------ 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\\StartTime------------------------------- 60
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\\UntilTime------------------------------- 60
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\\Separator File--------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\\Location--------------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\\Attributes------------------------------ 520
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\\txTimeout------------------------------- 45000
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\\dnsTimeout------------------------------ 15000
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\\Security-------------------------------- 01 00 04 80 B4 00 00 00 C4 00 00 00 00 00 00 00 14 00 00 00 02 00 A0 00 06 00 00 00 00 0A 14 00 00 00 02 00 01 01 00 00 00 00 00 03 00 00 00 00 00 09 14 00 00 00 00 10 01 01 00 00 00 00 00 03 00 00 00 00 00 00 14 00 08 00 02 00 01 01 00 00 00 00 00 01 00 00 00 00 00 0A 14 00 00 00 00 20 01 01 00 00 00 00 00 01 00 00 00 00 00 00 18 00 0C 00 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 0B 18 00 00 00 00 10 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\\SpoolDirectory--------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\\Port------------------------------------ USB001
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\CopyFiles--------------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\CopyFiles\ICM----------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\CopyFiles\ICM\\Files--------------------- sRGB Color Space Profile.icm;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\CopyFiles\ICM\\Directory----------------- COLOR
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\CopyFiles\ICM\\Module-------------------- mscms.dll
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsDriver---------------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsDriver\\printBinNames------------------ Automatically Select;Upper Paper Tray;Manual Paper Feed;Envelope, Manual Feed;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsDriver\\printCollate------------------- 01
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsDriver\\printColor--------------------- 01
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsDriver\\printDuplexSupported----------- 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsDriver\\printStaplingSupported--------- 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsDriver\\printMaxXExtent---------------- 2159
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsDriver\\printMaxYExtent---------------- 3556
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsDriver\\printMinXExtent---------------- 1000
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsDriver\\printMinYExtent---------------- 1460
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsDriver\\printMediaSupported------------ Letter;Legal;Executive;A4;A5;B5 (JIS);Envelope #10;Envelope DL;Envelope C6;Japanese Postcard;A6;Envelope A2;US Index Card 4x6;US Index Card 5x8;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsDriver\\printMediaReady---------------- Letter;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsDriver\\printNumberUp------------------ 6
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsDriver\\printOrientationsSupported----- PORTRAIT;LANDSCAPE;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsDriver\\printMaxResolutionSupported---- 1200
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsDriver\\printLanguage------------------ PCL;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsDriver\\printRate---------------------- 11
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsDriver\\printRateUnit------------------ PagesPerMinute
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsDriver\\printPagesPerMinute------------ 11
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsDriver\\driverVersion------------------ 1025
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsSpooler--------------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsSpooler\\description-------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsSpooler\\driverName-------------------- HP DeskJet 950C/952C/959C
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsSpooler\\location----------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsSpooler\\portName---------------------- USB001;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsSpooler\\printStartTime---------------- 60
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsSpooler\\printEndTime------------------ 60
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsSpooler\\printerName------------------- HP DeskJet 950C/952C/959C
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsSpooler\\printKeepPrintedJobs---------- 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsSpooler\\printSeparatorFile------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsSpooler\\printShareName---------------- HPDeskJe
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsSpooler\\printSpooling----------------- PrintAfterSpooled
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsSpooler\\priority---------------------- 1
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsSpooler\\uNCName----------------------- \\Inspiron8100\HP DeskJet 950C/952C/959C
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsSpooler\\versionNumber----------------- 4
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsSpooler\\serverName-------------------- Inspiron8100
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsSpooler\\shortServerName--------------- INSPIRON8100
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsSpooler\\url--------------------------- http://Inspiron8100/HPDeskJe
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\DsSpooler\\flags------------------------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\PnPData----------------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\PnPData\\DeviceInstanceId---------------- USBPRINT\HEWLETT-PACKARDDESKJET_950C\7&1B47D6B5&0&USB001
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\PnPData\\HardwareID---------------------- hewlett-packarddeskj4f5e
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\PnPData\\Manufacturer-------------------- HP
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\PnPData\\OEM URL------------------------- http://go.microsoft.com/fwlink/?LinkID=37&...mp;sbp=Printers
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\PrinterDriverData------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\PrinterDriverData\\InitDriverVersion----- 1280
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\PrinterDriverData\\Model----------------- HP DeskJet 950C/952C/959C
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\PrinterDriverData\\PrinterDataSize------- 560
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\PrinterDriverData\\PrinterData----------- 00 05 30 02 80 08 00 00 80 1A 06 00 00 00 00 00 00 00 00 00 64 00 58 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 F4 0C 86 D1 01 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\PrinterDriverData\\FeatureKeywordSize---- 29
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\PrinterDriverData\\FeatureKeyword-------- 48 50 44 75 70 6C 65 78 55 6E 69 74 00 4E 6F 74 49 6E 73 74 61 6C 6C 65 64 00 0A 00 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\PrinterDriverData\\Forms?---------------- -779744012
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP DeskJet 950C/952C/959C\PrinterDriverData\\TrayFormTable--------- Upper Paper Tray;Letter;0;Manual Paper Feed;Letter;0;Envelope, Manual Feed;Letter;0;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript--------------------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\\ChangeID---------------------------- 428314103
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\\Status------------------------------ 384
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\\Name-------------------------------- HP LaserJet 5P/5MP PostScript
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\\Share Name-------------------------- HPLaserJ
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\\Print Processor--------------------- WinPrint
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\\Datatype---------------------------- RAW
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\\Parameters--------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\\Action------------------------------ 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\\ObjectGUID--------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\\DsKeyUpdate------------------------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\\DsKeyUpdateForeground--------------- 3
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\\Description-------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\\Printer Driver---------------------- HP LaserJet 5P/5MP PostScript
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\\Default DevMode--------------------- 48 00 50 00 20 00 4C 00 61 00 73 00 65 00 72 00 4A 00 65 00 74 00 20 00 35 00 50 00 2F 00 35 00 4D 00 50 00 20 00 50 00 6F 00 73 00 74 00 53 00 63 00 72 00 69 00 70 00 74 00 00 00 35 00 00 00 01 04 02 05 DC 00 C4 02 53 EF 01 00 01 00 01 00 EA 0A 6F 08 64 00 01 00 0F 00 58 02 01 00 01 00 58 02 03 00 01 00 4C 00 65 00 74 00 74 00 65 00 72 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 52 49 56 E2 30 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 18 00 00 00 00 00 10 27 10 27 10 27 00 00 10 27 00 00 00 00 00 00 00 00 00 00 C4 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 00 00 00 00 00 00 10 00 5C 4B 03 00 5C 4B 03 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 A3 D1 65 90 08 00 00 00 00 00 00 00 02 00 00 00 00 00 FF 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\\Priority---------------------------- 1
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\\Default Priority-------------------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\\StartTime--------------------------- 60
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\\UntilTime--------------------------- 60
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\\Separator File----------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\\Location----------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\\Attributes-------------------------- 520
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\\txTimeout--------------------------- 45000
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\\dnsTimeout-------------------------- 15000
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\\Security---------------------------- 01 00 04 80 B4 00 00 00 C4 00 00 00 00 00 00 00 14 00 00 00 02 00 A0 00 06 00 00 00 00 0A 14 00 00 00 02 00 01 01 00 00 00 00 00 03 00 00 00 00 00 09 14 00 00 00 00 10 01 01 00 00 00 00 00 03 00 00 00 00 00 00 14 00 08 00 02 00 01 01 00 00 00 00 00 01 00 00 00 00 00 0A 14 00 00 00 00 20 01 01 00 00 00 00 00 01 00 00 00 00 00 00 18 00 0C 00 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 0B 18 00 00 00 00 10 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\\SpoolDirectory----------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\\Port-------------------------------- LPT1:
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsDriver-----------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsDriver\\printBinNames-------------- Automatically Select;Tray 1 (MultiPurpose Tr;Tray 2 (Paper Cassette);Manual Feed;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsDriver\\printCollate--------------- 01
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsDriver\\printColor----------------- 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsDriver\\printDuplexSupported------- 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsDriver\\printStaplingSupported----- 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsDriver\\printMaxXExtent------------ 2159
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsDriver\\printMaxYExtent------------ 3556
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsDriver\\printMinXExtent------------ 762
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsDriver\\printMinYExtent------------ 1270
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsDriver\\printMediaSupported-------- Letter;Legal;Executive;A4;A5;Letter (8 1/2 x 11 in);Legal (8 1/2 x 14 in);A4 (210 x 297 mm);Executive (7 1/4 x 10 1/2 in);A5 (148 x 210 mm);Com-10 Env (4 1/8 x 9 1/2 in);Monarch Env (3 7/8 x 7 1/2 in);DL Env (110 x 220 mm);C5 Env (162 x 229 mm);B5 Env (176 x 250 mm);
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsDriver\\printMediaReady------------ Letter;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsDriver\\printNumberUp-------------- 6
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsDriver\\printMemory---------------- 767
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsDriver\\printOrientationsSupported- PORTRAIT;LANDSCAPE;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsDriver\\printMaxResolutionSupported 600
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsDriver\\printLanguage-------------- PostScript;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsDriver\\printRate------------------ 6
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsDriver\\printRateUnit-------------- PagesPerMinute
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsDriver\\printPagesPerMinute-------- 6
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsDriver\\driverVersion-------------- 1025
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsSpooler----------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsSpooler\\description---------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsSpooler\\driverName---------------- HP LaserJet 5P/5MP PostScript
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsSpooler\\location------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsSpooler\\portName------------------ LPT1:;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsSpooler\\printStartTime------------ 60
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsSpooler\\printEndTime-------------- 60
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsSpooler\\printerName--------------- HP LaserJet 5P/5MP PostScript
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsSpooler\\printKeepPrintedJobs------ 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsSpooler\\printSeparatorFile--------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsSpooler\\printShareName------------ HPLaserJ
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsSpooler\\printSpooling------------- PrintAfterSpooled
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsSpooler\\priority------------------ 1
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsSpooler\\uNCName------------------- \\Inspiron8100\HP LaserJet 5P/5MP PostScript
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsSpooler\\versionNumber------------- 4
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsSpooler\\serverName---------------- Inspiron8100
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsSpooler\\shortServerName----------- INSPIRON8100
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsSpooler\\url----------------------- http://Inspiron8100/HPLaserJ
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\DsSpooler\\flags--------------------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\PnPData------------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\PnPData\\DeviceInstanceId------------ LPTENUM\HEWLETT-PACKARDHP_LASERJET_5MP\5&363591F2&0&LPT1.4
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\PnPData\\HardwareID------------------ hewlett-packardhp_lae5a6
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\PnPData\\Manufacturer---------------- HP
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\PnPData\\OEM URL--------------------- http://go.microsoft.com/fwlink/?LinkID=37&...mp;sbp=Printers
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\PrinterDriverData--------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\PrinterDriverData\\InitDriverVersion- 1282
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\PrinterDriverData\\FreeMem----------- 767
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\PrinterDriverData\\JobTimeOut-------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\PrinterDriverData\\Protocol---------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\PrinterDriverData\\PrinterDataSize--- 560
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\PrinterDriverData\\PrinterData------- 02 05 30 02 80 0C 00 00 80 FD 0B 00 00 00 00 00 78 00 00 00 64 00 58 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 A3 D1 65 90 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\PrinterDriverData\\FeatureKeywordSize 2
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\PrinterDriverData\\FeatureKeyword---- 00 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\PrinterDriverData\\Forms?------------ -1872375389
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\PrinterDriverData\\DependentFiles---- PSCRIPT.NTF;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\PrinterDriverData\\TrayFormSize------ 178
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\HP LaserJet 5P/5MP PostScript\PrinterDriverData\\TrayFormTable----- B2 00 54 00 72 00 61 00 79 00 20 00 31 00 20 00 28 00 4D 00 75 00 6C 00 74 00 69 00 50 00 75 00 72 00 70 00 6F 00 73 00 65 00 20 00 54 00 72 00 00 00 4C 00 65 00 74 00 74 00 65 00 72 00 00 00 00 00 00 00 54 00 72 00 61 00 79 00 20 00 32 00 20 00 28 00 50 00 61 00 70 00 65 00 72 00 20 00 43 00 61 00 73 00 73 00 65 00 74 00 74 00 65 00 29 00 00 00 4C 00 65 00 74 00 74 00 65 00 72 00 00 00 00 00 00 00 4D 00 61 00 6E 00 75 00 61 00 6C 00 20 00 46 00 65 00 65 00 64 00 00 00 4C 00 65 00 74 00 74 00 65 00 72 00 00 00 00 00 00 00 00 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series------------------------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\\ChangeID-------------------------------- 144655703
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\\Status---------------------------------- 384
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\\Name------------------------------------ hp photosmart 7550 series
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\\Share Name------------------------------ hpphotos
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\\Print Processor------------------------- WinPrint
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\\Datatype-------------------------------- RAW
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\\Parameters------------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\\Action---------------------------------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\\ObjectGUID------------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\\DsKeyUpdate----------------------------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\\DsKeyUpdateForeground------------------- 3
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\\Description-----------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\\Printer Driver-------------------------- hp photosmart 7550 series
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\\Default DevMode------------------------- 68 00 70 00 20 00 70 00 68 00 6F 00 74 00 6F 00 73 00 6D 00 61 00 72 00 74 00 20 00 37 00 35 00 35 00 30 00 20 00 73 00 65 00 72 00 69 00 65 00 73 00 00 00 72 00 74 00 20 00 37 00 35 00 00 00 01 04 21 40 DC 00 6D 07 03 DF 80 07 01 00 01 00 2C 00 4C 00 64 00 01 00 07 00 FD FF 02 00 01 00 00 00 03 00 00 00 44 00 72 00 76 00 43 00 6F 00 6E 00 76 00 65 00 72 00 74 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 03 00 00 00 11 04 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 42 83 65 87 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 88 88 08 00 88 88 08 00 00 00 00 00 00 00 00 00 00 00 00 00 00 52 03 00 00 4C 04 00 00 00 64 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 11 04 07 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 41 00 72 00 69 00 61 00 6C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 38 00 00 00 C2 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 42 83 65 87 01 CC DA BA 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 CC DA BA 5C 00 5C 00 49 00 4E 00 53 00 50 00 49 00 52 00 4F 00 4E 00 38 00 31 00 30 00 30 00 5C 00 68 00 70 00 20 00 70 00 68 00 6F 00 74 00 6F 00 73 00 6D 00 61 00 72 00 74 00 20 00 37 00 35 00 35 00 30 00 20 00 73 00 65 00 72 00 69 00 65 00 73 00 2C 00 4C 00 6F 00 63 00 61 00 6C 00 4F 00 6E 00 6C 00 79 00 2C 00 44 00 72 00 76 00 43 00 6F 00 6E 00 76 00 65 00 72 00 74 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\\Priority-------------------------------- 1
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\\Default Priority------------------------ 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\\StartTime------------------------------- 60
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\\UntilTime------------------------------- 60
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\\Separator File--------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\\Location--------------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\\Attributes------------------------------ 520
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\\txTimeout------------------------------- 45000
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\\dnsTimeout------------------------------ 15000
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\\Security-------------------------------- 01 00 04 80 B4 00 00 00 C4 00 00 00 00 00 00 00 14 00 00 00 02 00 A0 00 06 00 00 00 00 0A 14 00 00 00 02 00 01 01 00 00 00 00 00 03 00 00 00 00 00 09 14 00 00 00 00 10 01 01 00 00 00 00 00 03 00 00 00 00 00 00 14 00 08 00 02 00 01 01 00 00 00 00 00 01 00 00 00 00 00 0A 14 00 00 00 00 20 01 01 00 00 00 00 00 01 00 00 00 00 00 00 18 00 0C 00 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 0B 18 00 00 00 00 10 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\\SpoolDirectory--------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\\Port------------------------------------ DOT4_002
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\CopyFiles--------------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\CopyFiles\ICM----------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\CopyFiles\ICM\\Files--------------------- sRGB Color Space Profile.icm;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\CopyFiles\ICM\\Directory----------------- COLOR
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\CopyFiles\ICM\\Module-------------------- mscms.dll
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsDriver---------------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsDriver\\printBinNames------------------ Auto;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsDriver\\printColor--------------------- 01
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsDriver\\printDuplexSupported----------- 01
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsDriver\\printMaxXExtent---------------- 2159
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsDriver\\printMaxYExtent---------------- 3556
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsDriver\\printMinXExtent---------------- 762
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsDriver\\printMinYExtent---------------- 1270
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsDriver\\printMediaSupported------------ Letter (8.5 x 11 in.) ;Legal (8.5 x 14 in.) ;Executive (7.25 x 10.5 in.) ;A4 (210 x 297 mm) ;A5 (148 x 210 mm) ;B5 (182 x 257 mm) ;Index Card (3 x 5 in.) ;Index Card (4 x 6 in.) ;Index Card (5 x 8 in.) ;Photo 4 x 6 in. (with tab);A6 Card (105 x 148.5 mm) ;No. 10 Envelope (4.12 x 9.5 in.) ;A2 Envelope (4.37 x 5.75 in.) ;C6 Envelope (114 x 162 mm) ;DL Envelope (110 x 220 mm) ;Banner [Letter (8.5 x 11 in.)];Banner [A4 (210 x 297 mm)];Hagaki Card (100 x 148 mm) ;Borderless Photo 4 x 6 in. (with tab);Borderless Photo 4 x 6 in.;Borderless Hagaki Card (100 x 148 mm);Borderless A6 Card (105 x 148.5 mm) ;Photo L (89 X 127 mm);Borderless Photo L (89 x 127 mm);User Defined Paper Size;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsDriver\\printMediaReady----------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsDriver\\printOrientationsSupported----- PORTRAIT;LANDSCAPE;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsDriver\\printLanguage------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsDriver\\printRateUnit------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsDriver\\driverVersion------------------ 1025
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsSpooler--------------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsSpooler\\description-------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsSpooler\\driverName-------------------- hp photosmart 7550 series
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsSpooler\\location----------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsSpooler\\portName---------------------- DOT4_002;
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsSpooler\\printStartTime---------------- 60
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsSpooler\\printEndTime------------------ 60
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsSpooler\\printerName------------------- hp photosmart 7550 series
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsSpooler\\printKeepPrintedJobs---------- 00
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsSpooler\\printSeparatorFile------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsSpooler\\printShareName---------------- hpphotos
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsSpooler\\printSpooling----------------- PrintAfterSpooled
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsSpooler\\priority---------------------- 1
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsSpooler\\uNCName----------------------- \\Inspiron8100\hp photosmart 7550 series
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsSpooler\\versionNumber----------------- 4
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsSpooler\\serverName-------------------- Inspiron8100
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsSpooler\\shortServerName--------------- INSPIRON8100
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsSpooler\\url--------------------------- http://Inspiron8100/hpphotos
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\DsSpooler\\flags------------------------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\PnPData----------------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\PnPData\\DeviceInstanceId---------------- DOT4PRT\VID_03F0&PID_3E02&DOT4&PRINT_HPHI11\9&1377FFD8&0&1
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\PnPData\\HardwareID---------------------- dot4prt\vid_03f0&pid_3e02&dot4&print_hphi11
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\PnPData\\Manufacturer-------------------- Hewlett-Packard
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\PrinterDriverData------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\PrinterDriverData\\SPLUserModePrinterDriver HPZNTU07.DLL
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\PrinterDriverData\\CmdBufOffset---------- 285
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\PrinterDriverData\\Printer Model--------- hp photosmart 7550 series
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\PrinterDriverData\\AITrgLev-------------- 2
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\PrinterDriverData\\YITrgLev-------------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\PrinterDriverData\\LITrgLev-------------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\PrinterDriverData\\sw_cpi_b-------------- 1
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\PrinterDriverData\\sw_cil_b-------------- 70
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\PrinterDriverData\\sw_cpi_c-------------- 1
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\PrinterDriverData\\sw_cil_c-------------- 71
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\PrinterDriverData\\sw_cpi_p-------------- 1
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\hp photosmart 7550 series\PrinterDriverData\\sw_cil_p-------------- 0
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W-------------------------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData-------------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCDisable----- 01
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_Count-- 14
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_C01---- 979
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_M01---- 998
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_Y01---- 974
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_K01---- 994
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_C02---- 883
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_M02---- 915
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_Y02---- 899
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_K02---- 910
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_C03---- 821
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_M03---- 834
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_Y03---- 819
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_K03---- 833
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_C04---- 780
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_M04---- 775
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_Y04---- 743
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_K04---- 782
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_C05---- 743
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_M05---- 712
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_Y05---- 667
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_K05---- 735
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_C06---- 687
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_M06---- 626
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_Y06---- 563
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_K06---- 688
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_C07---- 624
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_M07---- 587
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_Y07---- 490
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_K07---- 662
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_C08---- 585
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_M08---- 547
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_Y08---- 414
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_K08---- 629
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData\\EAIDCData_C09---- 557
HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\KONICA MINOLTA magicolor 2400W\PrinterDriverData

#8 licensedtoquill

licensedtoquill
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:02:20 AM

Posted 26 July 2006 - 09:40 AM

Hi OldTimer

My first thoughts are:
Did I need to upload all those 00 00 00 00 00 00s? Do they show anything or is that why my system is syrupy slow?
Why does this scan see all those printers I dont use such as Konicas, officejets, 952s etc? (Though I cant imagine they slows anything down significantly: Should I delete them from the registry with Regedit?) But nowhere is my WinFaxPro printer shown
It does seem to identify that I havent got a HOSTS file whereas I did carefully create one
It seems to show a pagefile.sys file on C: whereas I put it on the D: drive where it still shows

Lastly one other point which may be related to the lack of a working hosts file: Why does Spybot ALWAYS identify exactly the same problems with the computer as it saw and removed successfully last time it ran (eg doubleclick, Avenue A, DSO etc)? Does the immunizer update do nothing?

#9 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:02:20 AM

Posted 26 July 2006 - 03:00 PM

Hi licensedtoquill. The 2nd post of the WinPFind2 log was cut off because it was included with the 1st post. Let's rerun the parts for the 2nd post so I can see all of the items.
  • Open the WinPFind2 folder and double-click on winpfind2.exe to start the program.
  • Click on the Services tab. At the top are 2 drop-down boxes. Change the 2nd box to List All Services and then click the Scan Services button.
  • Now click on the Files tab and click the Scan Files button.
  • When the scans are complete click the Export To Text button in the lower right-hand corner to create a report file. Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Post the results back here and I will review the information when it comes in.

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#10 licensedtoquill

licensedtoquill
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:02:20 AM

Posted 26 July 2006 - 05:25 PM

Logfile created on: 07/26/2006 18:23
WinPFind2 by OldTimer - Version 1.0.0 Folder = C:\Documents and Settings\Liz\Desktop\WinPFind2\
Microsoft Windows XP (Version = Service Pack 2)
Internet Explorer (Version - 6.0.2900.2180)


[Start Post #1]



Services
Name--------------------------------------------------------Internal Name------------Startup Type---State-----Service Type--------------------------------------Path (Version Info)
Application Layer Gateway Service---------------------------ALG----------------------On Demand------Running---Win32, running in it's own process----------------C:\WINDOWS\System32\alg.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 44544 bytes | Date = 08/04/2004 03:56 | Attr = ])
Windows Audio-----------------------------------------------AudioSrv-----------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
AVG7 Alert Manager Server-----------------------------------Avg7Alrt-----------------Automatic------Running---Win32, running in it's own process----------------C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe (GRISOFT, s.r.o. [Ver = 7,1,0,365 | Size = 336896 bytes | Date = 03/30/2006 00:25 | Attr = ])
AVG7 Update Service-----------------------------------------Avg7UpdSvc---------------Automatic------Running---Win32, running in it's own process----------------C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe (GRISOFT, s.r.o. [Ver = 7,1,0,349 | Size = 84480 bytes | Date = 03/30/2006 00:25 | Attr = ])
Background Intelligent Transfer Service---------------------BITS---------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Computer Browser--------------------------------------------Browser------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Cryptographic Services--------------------------------------CryptSvc-----------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
DCOM Server Process Launcher--------------------------------DcomLaunch---------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\system32\svchost -k DcomLaunch (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
DHCP Client-------------------------------------------------Dhcp---------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
DNS Client--------------------------------------------------Dnscache-----------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k NetworkService (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Error Reporting Service-------------------------------------ERSvc--------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Event Log---------------------------------------------------Eventlog-----------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\system32\services.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 108032 bytes | Date = 08/04/2004 03:56 | Attr = ])
COM+ Event System-------------------------------------------EventSystem--------------On Demand------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Fast User Switching Compatibility---------------------------FastUserSwitchingCompatibilityOn Demand------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Fax---------------------------------------------------------Fax----------------------Automatic------Running---Win32, running in it's own process----------------C:\WINDOWS\system32\fxssvc.exe (Microsoft Corporation [Ver = 5.2.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 267776 bytes | Date = 08/04/2004 03:56 | Attr = ])
Help and Support--------------------------------------------helpsvc------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
HID Input Service-------------------------------------------HidServ------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
HTTP SSL----------------------------------------------------HTTPFilter---------------On Demand------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k HTTPFilter (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Infrared Monitor--------------------------------------------Irmon--------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Server------------------------------------------------------lanmanserver-------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Workstation-------------------------------------------------lanmanworkstation--------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
TCP/IP NetBIOS Helper---------------------------------------LmHosts------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k LocalService (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Machine Debug Manager---------------------------------------MDM----------------------Automatic------Running---Win32, running in it's own process----------------"C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe" (Microsoft Corporation [Ver = 7.00.9466 | Size = 322120 bytes | Date = 06/20/2003 03:25 | Attr = ])
Network Connections-----------------------------------------Netman-------------------On Demand------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Network Location Awareness (NLA)----------------------------Nla----------------------On Demand------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Plug and Play-----------------------------------------------PlugPlay-----------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\system32\services.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 108032 bytes | Date = 08/04/2004 03:56 | Attr = ])
Pml Driver HPH11--------------------------------------------Pml Driver HPH11---------On Demand------Running---Win32, running in it's own process----------------C:\WINDOWS\system32\HPHipm11.exe (HP [Ver = 4, 5, 0, 770 | Size = 77824 bytes | Date = 01/06/2006 15:07 | Attr = ])
IPSEC Services----------------------------------------------PolicyAgent--------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\lsass.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 13312 bytes | Date = 08/04/2004 03:56 | Attr = ])
Protected Storage-------------------------------------------ProtectedStorage---------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\system32\lsass.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 13312 bytes | Date = 08/04/2004 03:56 | Attr = ])
Remote Access Connection Manager----------------------------RasMan-------------------On Demand------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Remote Procedure Call (RPC)---------------------------------RpcSs--------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\system32\svchost -k rpcss (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Security Accounts Manager-----------------------------------SamSs--------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\system32\lsass.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 13312 bytes | Date = 08/04/2004 03:56 | Attr = ])
Task Scheduler----------------------------------------------Schedule-----------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Secondary Logon---------------------------------------------seclogon-----------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
System Event Notification-----------------------------------SENS---------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Windows Firewall/Internet Connection Sharing (ICS)----------SharedAccess-------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Shell Hardware Detection------------------------------------ShellHWDetection---------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Print Spooler-----------------------------------------------Spooler------------------Automatic------Running---Win32, running in it's own process----------------C:\WINDOWS\system32\spoolsv.exe (Microsoft Corporation [Ver = 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519) | Size = 57856 bytes | Date = 06/10/2005 19:53 | Attr = ])
System Restore Service--------------------------------------srservice----------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
SSDP Discovery Service--------------------------------------SSDPSRV------------------On Demand------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k LocalService (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Windows Image Acquisition (WIA)-----------------------------stisvc-------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k imgsvc (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Telephony---------------------------------------------------TapiSrv------------------On Demand------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Terminal Services-------------------------------------------TermService--------------On Demand------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost -k DComLaunch (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Themes------------------------------------------------------Themes-------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Distributed Link Tracking Client----------------------------TrkWks-------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Windows User Mode Driver Framework--------------------------UMWdf--------------------Automatic------Running---Win32, running in it's own process----------------C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation [Ver = 5.2.3790.1230 built by: DNSRV(bld4act) | Size = 38912 bytes | Date = 08/11/2004 02:45 | Attr = ])
Windows Time------------------------------------------------W32Time------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
WebClient---------------------------------------------------WebClient----------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k LocalService (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Windows Management Instrumentation--------------------------winmgmt------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Security Center---------------------------------------------wscsvc-------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Automatic Updates-------------------------------------------wuauserv-----------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Wireless Zero Configuration---------------------------------WZCSVC-------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
iPodService-------------------------------------------------iPodService--------------On Demand------Running---Win32, running in it's own process----------------C:\Program Files\iPod\bin\iPodService.exe (Apple Computer, Inc. [Ver = 6.0.5.20 | Size = 323584 bytes | Date = 06/14/2006 16:23 | Attr = ])

Files
Full Path--------------------------------------------------------------------------------------------------------------- Details
AllUsers ApplicationData Folder-----------------------------------------------------------------------------------------
C:\Documents and Settings\All Users\Application Data\DESKTOP.INI-------------------------------------------------------- ( [Ver = | Size = 62 bytes | Date = 08/30/2001 22:40 | Attr = HS])
C:\Documents and Settings\All Users\Application Data\hpzinstall.log----------------------------------------------------- ( [Ver = | Size = 5804 bytes | Date = 01/31/2006 22:30 | Attr = ])
C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache-------------------------------------------------- ( [Ver = | Size = 1759 bytes | Date = 10/08/2005 21:33 | Attr = ])
CurrentUser ApplicationData Folder--------------------------------------------------------------------------------------
C:\Documents and Settings\Liz\Application Data\$_hpcst$.hpc------------------------------------------------------------- ( [Ver = | Size = 2508 bytes | Date = 01/11/2006 13:35 | Attr = ])
C:\Documents and Settings\Liz\Application Data\Comma Separated Values (DOS).ADR----------------------------------------- ( [Ver = | Size = 38483 bytes | Date = 04/21/2003 20:19 | Attr = ])
C:\Documents and Settings\Liz\Application Data\Comma Separated Values (DOS).EML----------------------------------------- ( [Ver = | Size = 9359 bytes | Date = 04/21/2003 20:16 | Attr = ])
C:\Documents and Settings\Liz\Application Data\Comma Separated Values (Windows).ADR------------------------------------- ( [Ver = | Size = 38484 bytes | Date = 09/23/2004 13:40 | Attr = ])
C:\Documents and Settings\Liz\Application Data\DESKTOP.INI-------------------------------------------------------------- ( [Ver = | Size = 62 bytes | Date = 08/30/2001 22:40 | Attr = HS])
C:\Documents and Settings\Liz\Application Data\GDIPFONTCACHEV1.DAT------------------------------------------------------ ( [Ver = | Size = 95808 bytes | Date = 06/27/2006 13:27 | Attr = ])
C:\Documents and Settings\Liz\Application Data\Microsoft Excel.ADR------------------------------------------------------ ( [Ver = | Size = 38455 bytes | Date = 01/08/2004 13:47 | Attr = ])
DPF files---------------------------------------------------------------------------------------------------------------
{01A88BB1-1174-41EC-ACCB-963509EAE56B}---------------------------------------------------------------------------------- SysProWmi Class - CodeBase = http://support.dell.com/systemprofiler/SysPro.CAB
{17492023-C23A-453E-A040-C7C580BBF700}---------------------------------------------------------------------------------- Windows Genuine Advantage Validation Tool - CodeBase = http://go.microsoft.com/fwlink/?linkid=39204
{36E4E9BC-4D0C-41B4-90C9-37AFDBFAAD3C}---------------------------------------------------------------------------------- InforbitHelper Class - CodeBase = http://download.infotriever.com/bin/ifhelper.cab
{41F17733-B041-4099-A042-B518BB6A408C}---------------------------------------------------------------------------------- - CodeBase = http://a1540.g.akamai.net/7/1540/52/200305...meInstaller.exe
{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}---------------------------------------------------------------------------------- McAfee.com Operating System Class - CodeBase = http://bin.mcafee.com/molbin/shared/mcinsc...,8/mcinsctl.cab
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}---------------------------------------------------------------------------------- MUWebControl Class - CodeBase = http://update.microsoft.com/microsoftupdat...b?1138768415120
{94B82441-A413-4E43-8422-D49930E69764}---------------------------------------------------------------------------------- TLIEFlashObj Class - CodeBase = https://webchat.dell.com/Media/VisitorChat/TLIEFlash.CAB
{AB86CE53-AC9F-449F-9399-D8ABCA09EC09}---------------------------------------------------------------------------------- Get_ActiveX Control - CodeBase = https://h17000.www1.hp.com/ewfrf-JAVA/Secur...loadManager.ocx
{D27CDB6E-AE6D-11CF-96B8-444553540000}---------------------------------------------------------------------------------- Shockwave Flash Object - CodeBase = http://download.macromedia.com/pub/shockwa...ash/swflash.cab
{E7D2588A-7FB5-47DC-8830-832605661009}---------------------------------------------------------------------------------- Live Collaboration - CodeBase = https://rr.esecurecare.net/rnt/rnl/java/RntX.cab
{EB387D2F-E27B-4D36-979E-847D1036C65D}---------------------------------------------------------------------------------- QDiagHUpdateObj Class - CodeBase = http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
Microsoft XML Parser for Java------------------------------------------------------------------------------------------- - CodeBase = file://C:\WINDOWS\Java\classes\xmldso.cab
Hosts file (Non-Standard entries only)----------------------------------------------------------------------------------
Hosts file not found----------------------------------------------------------------------------------------------------

#11 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:02:20 AM

Posted 27 July 2006 - 03:59 PM

Hi licensedtoquill. Ok, let's clean out some of these entries.

Step #1

Start WinPFin2 and click on the Active Processes tab to select it. Locate the following process and click the checkox in front of it to select it:teatimer.exe
Now click the Kill Processes button to stop the process. This will stop TeaTimer so it does not interfere with the following fixes.

Step #2

Now click on the Registry tab. Click the Scan Registry button. Locate the following keys and click in the checkbox in front of each one to select it:HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDF3E430-B101-42AD-A544-FADC6B084872}
HKLM\SOFTWARE\Microsoft\Internet Explorer\ToolBar\\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F}
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F}
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F}
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478}
HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{9404901D-06DA-4B23-A0EE-3EA4F64EC9B3}
HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\vf9
HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\text/html
HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\text/plain

When finished click the Delete Entries button to remove the registry entries.

Step #3

Now click the Configuration tab and then click the Run All Scans button. When the scans are finished click the Export to Text button and post the results back here so I can review them.

Since the report is quite large it will require multiple posts to show it all. Follow the markers for [Start Post #1], [Start Post #2] and [Start Post #3] to divide the report into 3 separate posts and use the Add Reply button to post the information back here.

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#12 licensedtoquill

licensedtoquill
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:02:20 AM

Posted 27 July 2006 - 10:13 PM

Hi again OldTimer: I did what you say and was a bit surprised to note that TeaTimer isnt listed as running for me to kill. And I couldnt find the last two entries which you told me to delete? But this is the result: (Note, still says HOSTS file not found!)
Logfile created on: 07/27/2006 23:09
WinPFind2 by OldTimer - Version 1.0.0 Folder = C:\Documents and Settings\Liz\Desktop\WinPFind2\
Microsoft Windows XP (Version = Service Pack 2)
Internet Explorer (Version - 6.0.2900.2180)


[Start Post #1]

Processes
Image Name---------------ProcessID--Thread Count--Parent ID--Base Priority--Full Path (Version Info)
acrotray.exe-------------001560-----0001----------000548-----Normal---------c:\program files\adobe\acrobat 6.0\distillr\acrotray.exe (Adobe Systems Inc. [Ver = 6.0.1.2003102300 | Size = 217194 bytes | Date = 10/24/2003 00:37 | Attr = ])
alg.exe------------------002440-----0006----------000792-----Normal---------c:\windows\system32\alg.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 44544 bytes | Date = 08/04/2004 03:56 | Attr = ])
apntex.exe---------------000768-----0002----------000932-----Normal---------c:\program files\apoint\apntex.exe (Alps Electric Co., Ltd. [Ver = 5.5.1.19 | Size = 45056 bytes | Date = 08/19/2004 09:40 | Attr = ])
apoint.exe---------------000452-----0002----------000548-----Normal---------c:\program files\apoint\apoint.exe (Alps Electric Co., Ltd. [Ver = 5.5.101.141 | Size = 155648 bytes | Date = 09/13/2004 11:33 | Attr = ])
avgamsvr.exe-------------001124-----0009----------000792-----Normal---------c:\progra~1\grisoft\avgfre~1\avgamsvr.exe (GRISOFT, s.r.o. [Ver = 7,1,0,365 | Size = 336896 bytes | Date = 03/30/2006 00:25 | Attr = ])
avgcc.exe----------------000444-----0006----------000548-----Normal---------c:\progra~1\grisoft\avgfre~1\avgcc.exe (GRISOFT, s.r.o. [Ver = 7,1,0,381 | Size = 357888 bytes | Date = 06/08/2006 09:30 | Attr = ])
avgupsvc.exe-------------001144-----0003----------000792-----Normal---------c:\progra~1\grisoft\avgfre~1\avgupsvc.exe (GRISOFT, s.r.o. [Ver = 7,1,0,349 | Size = 84480 bytes | Date = 03/30/2006 00:25 | Attr = ])
csrss.exe----------------000720-----0011----------000632-----Normal---------\??\c:\windows\system32\csrss.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 6144 bytes | Date = 08/04/2004 03:56 | Attr = ])
ctfmon.exe---------------000612-----0001----------000548-----Normal---------c:\windows\system32\ctfmon.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 15360 bytes | Date = 08/04/2004 03:56 | Attr = ])
dds.exe------------------000260-----0004----------000548-----Normal---------c:\program files\project lab\dds\dds.exe (Project Lab Pty. Ltd. [Ver = 1.02.02.04 | Size = 761911 bytes | Date = 09/11/2002 11:14 | Attr = ])
explorer.exe-------------000548-----0012----------000512-----Normal---------c:\windows\explorer.exe (Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 1032192 bytes | Date = 08/04/2004 03:56 | Attr = ])
firefo~1.exe-------------003780-----0010----------000548-----Normal---------c:\progra~1\mozill~1\firefo~1.exe (Mozilla Corporation [Ver = 1.8.0.3: 2006042618 | Size = 7172197 bytes | Date = 05/03/2006 17:02 | Attr = ])
fxssvc.exe---------------001904-----0015----------000792-----Normal---------c:\windows\system32\fxssvc.exe (Microsoft Corporation [Ver = 5.2.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 267776 bytes | Date = 08/04/2004 03:56 | Attr = ])
hpgs2wnf.exe-------------003992-----0004----------000964-----Normal---------c:\progra~1\hewlet~1\hpshar~1\hpgs2wnf.exe ( [Ver = 2,4,0,26 | Size = 65536 bytes | Date = 07/03/2001 10:17 | Attr = ])
hphipm11.exe-------------001956-----0002----------000792-----Normal---------c:\windows\system32\hphipm11.exe (HP [Ver = 4, 5, 0, 770 | Size = 77824 bytes | Date = 01/06/2006 15:07 | Attr = ])
hphmon04.exe-------------000572-----0005----------000548-----Normal---------c:\windows\system32\hphmon04.exe (Hewlett-Packard [Ver = 4,2,41 | Size = 348160 bytes | Date = 01/06/2006 15:07 | Attr = ])
hpztsb07.exe-------------000228-----0001----------000548-----Normal---------c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe (HP [Ver = 2,140,0,0 | Size = 188416 bytes | Date = 01/06/2006 15:07 | Attr = ])
ipodservice.exe----------002568-----0006----------000792-----Normal---------c:\program files\ipod\bin\ipodservice.exe (Apple Computer, Inc. [Ver = 6.0.5.20 | Size = 323584 bytes | Date = 06/14/2006 16:23 | Attr = ])
ituneshelper.exe---------000204-----0004----------000272-----Normal---------d:\program files\itunes\ituneshelper.exe (Apple Computer, Inc. [Ver = 6.0.5.20 | Size = 278528 bytes | Date = 06/14/2006 16:24 | Attr = ])
lsass.exe----------------000804-----0020----------000744-----Normal---------c:\windows\system32\lsass.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 13312 bytes | Date = 08/04/2004 03:56 | Attr = ])
mdm.exe------------------001284-----0004----------000792-----Normal---------c:\program files\common files\microsoft shared\vs7debug\mdm.exe (Microsoft Corporation [Ver = 7.00.9466 | Size = 322120 bytes | Date = 06/20/2003 03:25 | Attr = ])
msimn.exe----------------001688-----0005----------000548-----Normal---------c:\program files\outlook express\msimn.exe (Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 60416 bytes | Date = 08/04/2004 03:56 | Attr = ])
onetou~2.exe-------------002036-----0001----------000548-----Normal---------d:\progra~1\vision~1\onetou~2.exe (Visioneer Inc [Ver = 3, 1, 2, 20 | Size = 86016 bytes | Date = 10/31/2001 08:27 | Attr = ])
outlook.exe--------------003660-----0016----------000548-----Normal---------c:\progra~1\micros~2\office10\outlook.exe (Microsoft Corporation [Ver = 10.0.6626 | Size = 47816 bytes | Date = 01/29/2004 19:38 | Attr = R ])
photoshp.exe-------------002964-----0006----------000548-----Normal---------c:\program files\adobe\photoshop 6.0\photoshp.exe (Adobe Systems, Incorporated [Ver = 6.0.1 | Size = 13840384 bytes | Date = 03/24/2003 17:30 | Attr = ])
qttask.exe---------------003296-----0002----------002292-----Normal---------c:\program files\quicktime\qttask.exe (Apple Computer, Inc. [Ver = 7.1 | Size = 282624 bytes | Date = 07/26/2006 13:55 | Attr = ])
quickdcf.exe-------------002176-----0001----------000548-----Normal---------c:\program files\finepixviewer\quickdcf.exe (FUJI PHOTO FILM CO., LTD. [Ver = 3, 0, 0, 0 | Size = 200704 bytes | Date = 01/07/2002 15:53 | Attr = ])
rundll32.exe-------------000672-----0003----------000616-----Normal---------c:\windows\system32\rundll32.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 33280 bytes | Date = 08/04/2004 03:56 | Attr = ])
services.exe-------------000792-----0013----------000744-----Normal---------c:\windows\system32\services.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 108032 bytes | Date = 08/04/2004 03:56 | Attr = ])
skype.exe----------------000692-----0011----------000548-----Normal---------d:\program files\phone\skype.exe ( [Ver = | Size = 18577448 bytes | Date = 05/11/2006 17:24 | Attr = ])
smss.exe-----------------000632-----0003----------000004-----Normal---------\systemroot\system32\smss.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 50688 bytes | Date = 08/04/2004 03:56 | Attr = ])
smutilitybar.exe---------000708-----0002----------000548-----Normal---------c:\program files\iolo\system mechanic 4\smutilitybar.exe (iolo technologies, LLC [Ver = 4.0.10.0 | Size = 475648 bytes | Date = 06/14/2004 08:21 | Attr = ])
spoolsv.exe--------------001668-----0014----------000792-----Normal---------c:\windows\system32\spoolsv.exe (Microsoft Corporation [Ver = 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519) | Size = 57856 bytes | Date = 06/10/2005 19:53 | Attr = ])
svchost.exe--------------000964-----0015----------000792-----Normal---------c:\windows\system32\svchost.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
svchost.exe--------------001220-----0006----------000792-----Normal---------c:\windows\system32\svchost.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
svchost.exe--------------003740-----0008----------000792-----Normal---------c:\windows\system32\svchost.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
svchost.exe--------------001528-----0005----------000792-----Normal---------c:\windows\system32\svchost.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
svchost.exe--------------001172-----0086----------000792-----Normal---------c:\windows\system32\svchost.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
svchost.exe--------------001376-----0015----------000792-----Normal---------c:\windows\system32\svchost.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
svchost.exe--------------001080-----0010----------000792-----Normal---------c:\windows\system32\svchost.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
teatimer.exe-------------000668-----0003----------000548-----Idle-----------c:\program files\spybot - search & destroy\teatimer.exe (Safer Networking Limited [Ver = 1, 4, 0, 2 | Size = 1415824 bytes | Date = 05/31/2005 02:04 | Attr = ])
wdfmgr.exe---------------001800-----0004----------000792-----Normal---------c:\windows\system32\wdfmgr.exe (Microsoft Corporation [Ver = 5.2.3790.1230 built by: DNSRV(bld4act) | Size = 38912 bytes | Date = 08/11/2004 02:45 | Attr = ])
wfxctl32.exe-------------002160-----0018----------000548-----Normal---------c:\program files\symantec\winfax\wfxctl32.exe ( [Ver = | Size = 549888 bytes | Date = 12/12/2002 07:45 | Attr = R ])
wfxmod32.exe-------------003016-----0007----------002160-----High-----------c:\program files\symantec\winfax\wfxmod32.exe (Symantec Corporation [Ver = 10.00.2002.1212 | Size = 541184 bytes | Date = 12/12/2002 07:45 | Attr = R ])
wfxsnt40.exe-------------000488-----0002----------000548-----Normal---------c:\windows\system32\wfxsnt40.exe (Microsoft Corporation [Ver = 7.00 (Build 019) | Size = 45568 bytes | Date = 12/12/2002 07:45 | Attr = ])
wfxswtch.exe-------------000524-----0004----------000548-----Normal---------c:\progra~1\symantec\winfax\wfxswtch.exe ( [Ver = | Size = 28160 bytes | Date = 12/12/2002 07:45 | Attr = R ])
winlogon.exe-------------000744-----0016----------000632-----High-----------\??\c:\windows\system32\winlogon.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 502272 bytes | Date = 08/04/2004 03:56 | Attr = ])
winpfind2.exe------------002204-----0001----------000548-----Normal---------c:\documents and settings\liz\desktop\winpfind2\winpfind2.exe (OldTimer Tools [Ver = 1.0.0.0 | Size = 381440 bytes | Date = 07/16/2006 09:30 | Attr = ])
winword.exe--------------001840-----0005----------000964-----Normal---------c:\program files\microsoft office\office10\winword.exe (Microsoft Corporation [Ver = 10.0.6764 | Size = 10635976 bytes | Date = 05/31/2005 01:14 | Attr = R ])
wlancfg5.exe-------------002400-----0009----------000548-----Normal---------c:\program files\netgear\wg511v2\wlancfg5.exe ( [Ver = 3, 2, 29, 306 | Size = 1490944 bytes | Date = 11/10/2005 16:55 | Attr = ])

Registry Entries
Key--------------------------------------------------------------------------------------------------------------------- Value (Version Info)
WinPFind2 by OldTimer - Version 1.0.0-----------------------------------------------------------------------------------
Microsoft Windows XP Version = Service Pack 2--------------------------------------------------------------------------
Internet Explorer Version = 6.0.2900.2180------------------------------------------------------------------------------
Internet Explorer Settings----------------------------------------------------------------------------------------------
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page-------------------------------------------------------------- http://www.microsoft.com/isapi/redir.dll?p...ER}&ar=home
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page------------------------------------------------------------- http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default Page------------------------------------------------------------ http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default Search---------------------------------------------------------- http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page-------------------------------------------------------------- %SystemRoot%\system32\blank.htm
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page-------------------------------------------------------------- http://www.kartoo.com/
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page------------------------------------------------------------- http://www.google.com
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page--------------------------------------------------------------
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable------------------------------------------- 0
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride----------------------------------------- <local>
BHO's-------------------------------------------------------------------------------------------------------------------
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}--- AcroIEHlprObj Class = C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated [Ver = 6.0.1.2003110300 | Size = 54248 bytes | Date = 11/03/2003 18:17 | Attr = ])
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}--- = C:\PROGRA~1\SPYBOT~1\SDHelper.dll (Safer Networking Limited [Ver = 1, 4, 0, 0 | Size = 853672 bytes | Date = 05/31/2005 02:04 | Attr = ])
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}--- Google Toolbar Helper = c:\program files\google\googletoolbar1.dll (Google Inc. [Ver = 3, 0, 131, 0 | Size = 1191424 bytes | Date = 02/14/2006 21:05 | Attr = R ])
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}--- AcroIEToolbarHelper Class = C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ( [Ver = | Size = 147456 bytes | Date = 05/15/2003 01:03 | Attr = ])
Internet Explorer Bars, Toolbars and Extensions-------------------------------------------------------------------------
HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{182EC0BE-5110-49C8-A062-BEB1D02A220B}-------------------------- Adobe PDF = C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ( [Ver = | Size = 147456 bytes | Date = 05/15/2003 01:03 | Attr = ])
HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}-------------------------- &Tip of the Day = %SystemRoot%\System32\shdocvw.dll (Microsoft Corporation [Ver = 6.00.2900.2919 (xpsp_sp2_gdr.060529-0150) | Size = 1494016 bytes | Date = 05/29/2006 11:30 | Attr = ])
HKLM\SOFTWARE\Microsoft\Internet Explorer\ToolBar\\{2318C2B1-4965-11d4-9B18-009027A5CD4F}------------------------------- &Google = c:\program files\google\googletoolbar1.dll (Google Inc. [Ver = 3, 0, 131, 0 | Size = 1191424 bytes | Date = 02/14/2006 21:05 | Attr = R ])
HKLM\SOFTWARE\Microsoft\Internet Explorer\ToolBar\\{47833539-D0C5-4125-9FA8-0819E2EAAC93}------------------------------- Adobe PDF = C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ( [Ver = | Size = 147456 bytes | Date = 05/15/2003 01:03 | Attr = ])
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}----------------------------- ButtonText: Messenger = C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation [Ver = 4.7.3001 | Size = 1694208 bytes | Date = 10/13/2004 12:24 | Attr = HS])
HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}-------------------------- File Search Explorer Band = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation [Ver = 6.00.2900.2869 (xpsp_sp2_gdr.060316-1512) | Size = 8452096 bytes | Date = 03/17/2006 00:03 | Attr = ])
HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{EFA24E61-B078-11D0-89E4-00C04FC9E26E}-------------------------- Favorites Band = %SystemRoot%\System32\shdocvw.dll (Microsoft Corporation [Ver = 6.00.2900.2919 (xpsp_sp2_gdr.060529-0150) | Size = 1494016 bytes | Date = 05/29/2006 11:30 | Attr = ])
HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{EFA24E64-B078-11D0-89E4-00C04FC9E26E}-------------------------- Explorer Band = %SystemRoot%\System32\shdocvw.dll (Microsoft Corporation [Ver = 6.00.2900.2919 (xpsp_sp2_gdr.060529-0150) | Size = 1494016 bytes | Date = 05/29/2006 11:30 | Attr = ])
HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{01E04581-4EEE-11D0-BFE9-00AA005B4383}------------------ &Address = %SystemRoot%\System32\browseui.dll (Microsoft Corporation [Ver = 6.00.2900.2904 (xpsp_sp2_gdr.060509-0218) | Size = 1022976 bytes | Date = 05/10/2006 01:23 | Attr = ])
HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F}------------------ &Google = c:\program files\google\googletoolbar1.dll (Google Inc. [Ver = 3, 0, 131, 0 | Size = 1191424 bytes | Date = 02/14/2006 21:05 | Attr = R ])
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{01E04581-4EEE-11D0-BFE9-00AA005B4383}-------------------- &Address = %SystemRoot%\System32\browseui.dll (Microsoft Corporation [Ver = 6.00.2900.2904 (xpsp_sp2_gdr.060509-0218) | Size = 1022976 bytes | Date = 05/10/2006 01:23 | Attr = ])
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383}-------------------- &Links = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation [Ver = 6.00.2900.2869 (xpsp_sp2_gdr.060316-1512) | Size = 8452096 bytes | Date = 03/17/2006 00:03 | Attr = ])
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F}-------------------- &Google = c:\program files\google\googletoolbar1.dll (Google Inc. [Ver = 3, 0, 131, 0 | Size = 1191424 bytes | Date = 02/14/2006 21:05 | Attr = R ])
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{47833539-D0C5-4125-9FA8-0819E2EAAC93}-------------------- Adobe PDF = C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ( [Ver = | Size = 147456 bytes | Date = 05/15/2003 01:03 | Attr = ])
HKCU\Software\Microsoft\Internet Explorer\MenuExt\&Google Search-------------------------------------------------------- res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html (Google Inc. [Ver = 3, 0, 131, 0 | Size = 1191424 bytes | Date = 02/14/2006 21:05 | Attr = R ])
HKCU\Software\Microsoft\Internet Explorer\MenuExt\&Translate English Word----------------------------------------------- res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html (Google Inc. [Ver = 3, 0, 131, 0 | Size = 1191424 bytes | Date = 02/14/2006 21:05 | Attr = R ])
HKCU\Software\Microsoft\Internet Explorer\MenuExt\Backward Links-------------------------------------------------------- res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html (Google Inc. [Ver = 3, 0, 131, 0 | Size = 1191424 bytes | Date = 02/14/2006 21:05 | Attr = R ])
HKCU\Software\Microsoft\Internet Explorer\MenuExt\Cached Snapshot of Page----------------------------------------------- res://c:\program files\google\GoogleToolbar1.dll/cmcache.html (Google Inc. [Ver = 3, 0, 131, 0 | Size = 1191424 bytes | Date = 02/14/2006 21:05 | Attr = R ])
HKCU\Software\Microsoft\Internet Explorer\MenuExt\E&xport to Microsoft Excel-------------------------------------------- res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 (Microsoft Corporation [Ver = 10.0.6501 | Size = 9189896 bytes | Date = 12/03/2003 18:04 | Attr = R ])
HKCU\Software\Microsoft\Internet Explorer\MenuExt\Similar Pages--------------------------------------------------------- res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html (Google Inc. [Ver = 3, 0, 131, 0 | Size = 1191424 bytes | Date = 02/14/2006 21:05 | Attr = R ])
HKCU\Software\Microsoft\Internet Explorer\MenuExt\Translate Page into English------------------------------------------- res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html (Google Inc. [Ver = 3, 0, 131, 0 | Size = 1191424 bytes | Date = 02/14/2006 21:05 | Attr = R ])
Approved Shell Extensions (Non-Microsoft only)--------------------------------------------------------------------------
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{1CDB2949-8F65-4355-8456-263E7C208A5D}--------- Desktop Explorer = C:\WINDOWS\System32\nvshell.dll (NVIDIA Corporation [Ver = 6.14.10.4482 | Size = 471112 bytes | Date = 06/24/2003 18:32 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{1E9B04FB-F9E5-4718-997B-B8DA88302A47}--------- = C:\WINDOWS\System32\nvshell.dll (NVIDIA Corporation [Ver = 6.14.10.4482 | Size = 471112 bytes | Date = 06/24/2003 18:32 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{88895560-9AA2-1069-930E-00AA0030EBC8}--------- HyperTerminal Icon Ext = C:\WINDOWS\System32\hticons.dll (Hilgraeve, Inc. [Ver = 5.1.2600.0 | Size = 44544 bytes | Date = 08/17/2001 19:00 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}--------- AVG7 Shell Extension Class = C:\Program Files\Grisoft\AVG Free\avgse.dll (GRISOFT, s.r.o. [Ver = 7,1,0,354 | Size = 40960 bytes | Date = 03/30/2006 00:25 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}--------- AVG7 Find Extension Class = C:\Program Files\Grisoft\AVG Free\avgse.dll (GRISOFT, s.r.o. [Ver = 7,1,0,354 | Size = 40960 bytes | Date = 03/30/2006 00:25 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A4DF5659-0801-4A60-9607-1C48695EFDA9}--------- Share-to-Web Upload Folder = C:\Program Files\Hewlett-Packard\HP Share-to-Web\HPGS2WNS.DLL (Hewlett-Packard [Ver = 2,4,0,26 | Size = 131072 bytes | Date = 07/03/2001 10:10 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}--------- iTunes = D:\Program Files\iTunes\iTunesMiniPlayer.dll (Apple Computer, Inc. [Ver = 6.0.5.20 | Size = 102400 bytes | Date = 06/14/2006 16:35 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802}--------- Acrobat Elements Context Menu = C:\Program Files\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.dll (Adobe Systems Inc. [Ver = 6.0.0.2003110300\0 | Size = 643160 bytes | Date = 11/03/2003 19:03 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E0D79304-84BE-11CE-9641-444553540000}--------- WinZip = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc. [Ver = 4.1 (32-bit) | Size = 20552 bytes | Date = 02/11/2003 08:10 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E0D79305-84BE-11CE-9641-444553540000}--------- WinZip = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc. [Ver = 4.1 (32-bit) | Size = 20552 bytes | Date = 02/11/2003 08:10 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E0D79306-84BE-11CE-9641-444553540000}--------- WinZip = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc. [Ver = 4.1 (32-bit) | Size = 20552 bytes | Date = 02/11/2003 08:10 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E0D79307-84BE-11CE-9641-444553540000}--------- WinZip = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc. [Ver = 4.1 (32-bit) | Size = 20552 bytes | Date = 02/11/2003 08:10 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}--------- RealOne Player Context Menu Class = C:\Program Files\Real\RealOne Player\rpshell.dll (RealNetworks, Inc. [Ver = 1.0.1.1783 | Size = 49198 bytes | Date = 05/05/2004 13:53 | Attr = ])
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{BDEADF00-C265-11d0-BCED-00A0C90AB50F}--------- Web Folders = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL (Microsoft Corporation [Ver = 10.145.7329.0 | Size = 1277952 bytes | Date = 01/29/2004 10:08 | Attr = ])
ContextMenuHandlers (Non-Microsoft only)--------------------------------------------------------------------------------
HKCR\*\shellex\ContextMenuHandlers\Adobe.Acrobat.ContextMenu------------------------------------------------------------ {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} = C:\Program Files\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.dll (Adobe Systems Inc. [Ver = 6.0.0.2003110300\0 | Size = 643160 bytes | Date = 11/03/2003 19:03 | Attr = ])
HKCR\*\shellex\ContextMenuHandlers\AVG7 Shell Extension----------------------------------------------------------------- {9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG Free\avgse.dll (GRISOFT, s.r.o. [Ver = 7,1,0,354 | Size = 40960 bytes | Date = 03/30/2006 00:25 | Attr = ])
HKCR\*\shellex\ContextMenuHandlers\WinZip------------------------------------------------------------------------------- {E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc. [Ver = 4.1 (32-bit) | Size = 20552 bytes | Date = 02/11/2003 08:10 | Attr = ])
HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\AVG7 Shell Extension------------------------------------------- {9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG Free\avgse.dll (GRISOFT, s.r.o. [Ver = 7,1,0,354 | Size = 40960 bytes | Date = 03/30/2006 00:25 | Attr = ])
HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\WinZip--------------------------------------------------------- {E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc. [Ver = 4.1 (32-bit) | Size = 20552 bytes | Date = 02/11/2003 08:10 | Attr = ])
HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\WinZip------------------------------------------------------ {E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc. [Ver = 4.1 (32-bit) | Size = 20552 bytes | Date = 02/11/2003 08:10 | Attr = ])
ColumnHandlers (Non-Microsoft only)-------------------------------------------------------------------------------------
Registry Run Keys-------------------------------------------------------------------------------------------------------
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Apoint-------------------------------------------------------------- C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd. [Ver = 5.5.101.141 | Size = 155648 bytes | Date = 09/13/2004 11:33 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\AVG7_CC------------------------------------------------------------- C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP (GRISOFT, s.r.o. [Ver = 7,1,0,381 | Size = 357888 bytes | Date = 06/08/2006 09:30 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\CCD Manager--------------------------------------------------------- "C:\Program Files\Project Lab\DDS\DDS.EXE" (Project Lab Pty. Ltd. [Ver = 1.02.02.04 | Size = 761911 bytes | Date = 09/11/2002 11:14 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\HPDJ Taskbar Utility------------------------------------------------ C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe (HP [Ver = 2,140,0,0 | Size = 188416 bytes | Date = 01/06/2006 15:07 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\HPHmon04------------------------------------------------------------ C:\WINDOWS\system32\hphmon04.exe (Hewlett-Packard [Ver = 4,2,41 | Size = 348160 bytes | Date = 01/06/2006 15:07 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\HPHUPD04------------------------------------------------------------ "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe" (File not found)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\iTunesHelper-------------------------------------------------------- "D:\Program Files\iTunes\iTunesHelper.exe" (Apple Computer, Inc. [Ver = 6.0.5.20 | Size = 278528 bytes | Date = 06/14/2006 16:24 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck---------------------------------------------------- %systemroot%\system32\dumprep 0 -k (File not found)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\NvCplDaemon--------------------------------------------------------- RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup (File not found)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\nwiz---------------------------------------------------------------- nwiz.exe /installquiet (NVIDIA Corporation [Ver = 6.14.10.4482 | Size = 323584 bytes | Date = 06/24/2003 18:32 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\OneTouch Monitor---------------------------------------------------- D:\PROGRA~1\VISION~1\ONETOU~2.EXE (Visioneer Inc [Ver = 3, 1, 2, 20 | Size = 86016 bytes | Date = 10/31/2001 08:27 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task------------------------------------------------------ "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc. [Ver = 7.1 | Size = 282624 bytes | Date = 07/26/2006 13:55 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\REGSHAVE------------------------------------------------------------ C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN (FUJI PHOTO FILM CO., LTD. [Ver = 3.0.0.1 | Size = 53248 bytes | Date = 01/21/2002 17:02 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\SynTPEnh------------------------------------------------------------ C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc. [Ver = 7.2.12 17Mar03 | Size = 569344 bytes | Date = 03/17/2003 19:20 | Attr = R ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\SynTPLpr------------------------------------------------------------ C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc. [Ver = 7.2.12 17Mar03 | Size = 110592 bytes | Date = 03/17/2003 19:21 | Attr = R ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\TkBellExe----------------------------------------------------------- "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc. [Ver = 0.1.0.3018 | Size = 180269 bytes | Date = 05/05/2004 13:52 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\UserFaultCheck------------------------------------------------------ %systemroot%\system32\dumprep 0 -u (File not found)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\vf9----------------------------------------------------------------- C:\WINDOWS\system32\vf9485.exe (File not found)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\WFXSwtch------------------------------------------------------------ c:\PROGRA~1\symantec\winfax\WFXSWTCH.exe ( [Ver = | Size = 28160 bytes | Date = 12/12/2002 07:45 | Attr = R ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\WinFaxAppPortStarter------------------------------------------------ wfxsnt40.exe (Microsoft Corporation [Ver = 7.00 (Build 019) | Size = 45568 bytes | Date = 12/12/2002 07:45 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL--------------------------------------------- Installed = 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI---------------------------------------------- Installed = 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS---------------------------------------------- Installed = 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\ctfmon.exe---------------------------------------------------------- C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 15360 bytes | Date = 08/04/2004 03:56 | Attr = ])
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\iolo System Mechanic Utility Bar------------------------------------ "C:\Program Files\iolo\System Mechanic 4\SMUtilityBar.exe" (iolo technologies, LLC [Ver = 4.0.10.0 | Size = 475648 bytes | Date = 06/14/2004 08:21 | Attr = ])
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\NVIEW--------------------------------------------------------------- rundll32.exe nview.dll,nViewLoadHook (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 33280 bytes | Date = 08/04/2004 03:56 | Attr = ])
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\NvMediaCenter------------------------------------------------------- RunDLL32.exe NvMCTray.dll,NvTaskbarInit (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 33280 bytes | Date = 08/04/2004 03:56 | Attr = ])
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Skype--------------------------------------------------------------- "D:\Program Files\Phone\Skype.exe" /nosplash /minimized ( [Ver = | Size = 18577448 bytes | Date = 05/11/2006 17:24 | Attr = ])
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\SpybotSD TeaTimer--------------------------------------------------- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited [Ver = 1, 4, 0, 2 | Size = 1415824 bytes | Date = 05/31/2005 02:04 | Attr = ])
Startup Lnks------------------------------------------------------------------------------------------------------------
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk----------------------------------- C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc. [Ver = 6.0.1.2003102300 | Size = 217194 bytes | Date = 10/24/2003 00:37 | Attr = ])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk---------------------------------- C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc. [Ver = 1, 0, 0, 1 | Size = 113664 bytes | Date = 11/04/1999 15:06 | Attr = ])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Controller.LNK------------------------------------------ C:\Program Files\Symantec\WinFax\WFXCTL32.EXE ( [Ver = | Size = 549888 bytes | Date = 12/12/2002 07:45 | Attr = R ])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DESKTOP.INI--------------------------------------------- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DESKTOP.INI ( [Ver = | Size = 84 bytes | Date = 08/30/2001 22:50 | Attr = HS])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Exif Launcher.lnk--------------------------------------- C:\Program Files\FinePixViewer\QuickDCF.exe (FUJI PHOTO FILM CO., LTD. [Ver = 3, 0, 0, 0 | Size = 200704 bytes | Date = 01/07/2002 15:53 | Attr = ])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk------------------------------------ C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation [Ver = 10.0.2609 | Size = 83360 bytes | Date = 02/12/2001 13:01 | Attr = ])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR Smart Wizard.lnk-------------------------------- C:\WINDOWS\Installer\{B93D24B3-928D-4805-B379-4AA47CB3794E}\NewShortcut1_1.exe ( [Ver = | Size = 2238 bytes | Date = 06/07/2006 08:32 | Attr = R ])
C:\Documents and Settings\Liz\Start Menu\Programs\Startup\DESKTOP.INI--------------------------------------------------- C:\Documents and Settings\Liz\Start Menu\Programs\Startup\DESKTOP.INI ( [Ver = | Size = 84 bytes | Date = 08/30/2001 22:50 | Attr = HS])
Disabled MSConfig Items-------------------------------------------------------------------------------------------------
User Agent Post Platform------------------------------------------------------------------------------------------------
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\\SV1--------------------------
AppInit DLLs------------------------------------------------------------------------------------------------------------
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs------------------------------------------------- (File not found)
Image File Execution Options--------------------------------------------------------------------------------------------
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path- Debugger = ntsd -d
Shell Service Object Delay Load-----------------------------------------------------------------------------------------
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\CDBurn-------------------------------------- {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation [Ver = 6.00.2900.2869 (xpsp_sp2_gdr.060316-1512) | Size = 8452096 bytes | Date = 03/17/2006 00:03 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\PostBootReminder---------------------------- {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation [Ver = 6.00.2900.2869 (xpsp_sp2_gdr.060316-1512) | Size = 8452096 bytes | Date = 03/17/2006 00:03 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\SysTray------------------------------------- {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\system32\stobject.dll (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 121856 bytes | Date = 08/04/2004 03:56 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck------------------------------------ {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\system32\webcheck.dll (Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 276480 bytes | Date = 08/04/2004 03:56 | Attr = ])
Shell Execute Hooks-----------------------------------------------------------------------------------------------------
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972}------- URL Exec Hook = shell32.dll (Microsoft Corporation [Ver = 6.00.2900.2869 (xpsp_sp2_gdr.060316-1512) | Size = 8452096 bytes | Date = 03/17/2006 00:03 | Attr = ])
Shared Task Scheduler---------------------------------------------------------------------------------------------------
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\\{438755C2-A8BA-11D1-B96B-00A0C90312E1}----- = (File not found)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\\{8C7461EF-2B13-11d2-BE35-3078302C2030}----- = (File not found)
Winlogon----------------------------------------------------------------------------------------------------------------
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit---------------------------------------------------- C:\WINDOWS\system32\userinit.exe, (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 24576 bytes | Date = 08/04/2004 03:56 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell------------------------------------------------------- Explorer.exe (Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 1032192 bytes | Date = 08/04/2004 03:56 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\System------------------------------------------------------ (File not found)
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain------------------------------------------ crypt32.dll (Microsoft Corporation [Ver = 5.131.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 597504 bytes | Date = 08/04/2004 03:56 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet---------------------------------------------- cryptnet.dll (Microsoft Corporation [Ver = 5.131.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 63488 bytes | Date = 08/04/2004 03:56 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll------------------------------------------------ cscdll.dll (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 101888 bytes | Date = 08/04/2004 03:56 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp-------------------------------------------- wlnotify.dll (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 92672 bytes | Date = 08/04/2004 03:56 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule---------------------------------------------- wlnotify.dll (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 92672 bytes | Date = 08/04/2004 03:56 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy---------------------------------------------- sclgntfy.dll (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 20992 bytes | Date = 08/04/2004 03:56 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn---------------------------------------------- WlNotify.dll (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 92672 bytes | Date = 08/04/2004 03:56 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv----------------------------------------------- wlnotify.dll (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 92672 bytes | Date = 08/04/2004 03:56 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon---------------------------------------------- WgaLogon.dll (Microsoft Corporation [Ver = 1.5.0540.0 | Size = 702768 bytes | Date = 06/19/2006 16:20 | Attr = ])
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon--------------------------------------------- wlnotify.dll (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 92672 bytes | Date = 08/04/2004 03:56 | Attr = ])
DNS Name Servers--------------------------------------------------------------------------------------------------------
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{11D04FA2-045A-43DB-964C-7D59B425EA18}--------------- ()
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{4DB0F895-8A84-4B29-B9A1-CF332598DE69}--------------- (Intel 8255x-based PCI Ethernet Adapter (10/100))
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{525A882D-5C75-46F4-A014-DDEE4E086565}--------------- (Belkin 802.11g Network Adapter)
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{A98E1527-102D-4B5A-9EDF-BF7BA9580699}--------------- (Buffalo WLI-PCM-L11 Wireless LAN Adapter)
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C1FC980F-08A1-48CC-832D-67F8B6B67ABF}--------------- 4.2.2.2,4.2.2.1 (3Com 3C920 Integrated Fast Ethernet Controller (3C905C-TX Compatible))
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C4F2D4BA-8CDA-4DE0-B4F6-31EE96A9C309}--------------- (1394 Net Adapter)
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{CFC4DF56-DF7E-49C1-8A76-FC1B0F9B570B}--------------- (NETGEAR WG511v2 54 Mbps Wireless PC Card)
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{DAD0A8A0-D516-40C0-8DC1-FBB4227BBAE8}--------------- (1394 Net Adapter)
Winsock2 Catalogs (Non-Microsoft only)----------------------------------------------------------------------------------
Protocol Handlers (Non-Microsoft only)----------------------------------------------------------------------------------
HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\ipp----------------------------------------------------------------------------- (File not found)
HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp------------------------------------------------------------------------- (File not found)
Protocol Filters (Non-Microsoft only)-----------------------------------------------------------------------------------
HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\text/html------------------------------------------------------------------------ (File not found)
HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\text/plain----------------------------------------------------------------------- (File not found)


[Start Post #2]

Services
Name--------------------------------------------------------Internal Name------------Startup Type---State-----Service Type--------------------------------------Path (Version Info)
Application Layer Gateway Service---------------------------ALG----------------------On Demand------Running---Win32, running in it's own process----------------C:\WINDOWS\System32\alg.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 44544 bytes | Date = 08/04/2004 03:56 | Attr = ])
Windows Audio-----------------------------------------------AudioSrv-----------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
AVG7 Alert Manager Server-----------------------------------Avg7Alrt-----------------Automatic------Running---Win32, running in it's own process----------------C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe (GRISOFT, s.r.o. [Ver = 7,1,0,365 | Size = 336896 bytes | Date = 03/30/2006 00:25 | Attr = ])
AVG7 Update Service-----------------------------------------Avg7UpdSvc---------------Automatic------Running---Win32, running in it's own process----------------C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe (GRISOFT, s.r.o. [Ver = 7,1,0,349 | Size = 84480 bytes | Date = 03/30/2006 00:25 | Attr = ])
Background Intelligent Transfer Service---------------------BITS---------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Computer Browser--------------------------------------------Browser------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Cryptographic Services--------------------------------------CryptSvc-----------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
DCOM Server Process Launcher--------------------------------DcomLaunch---------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\system32\svchost -k DcomLaunch (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
DHCP Client-------------------------------------------------Dhcp---------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
DNS Client--------------------------------------------------Dnscache-----------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k NetworkService (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Error Reporting Service-------------------------------------ERSvc--------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Event Log---------------------------------------------------Eventlog-----------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\system32\services.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 108032 bytes | Date = 08/04/2004 03:56 | Attr = ])
COM+ Event System-------------------------------------------EventSystem--------------On Demand------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Fast User Switching Compatibility---------------------------FastUserSwitchingCompatibilityOn Demand------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Fax---------------------------------------------------------Fax----------------------Automatic------Running---Win32, running in it's own process----------------C:\WINDOWS\system32\fxssvc.exe (Microsoft Corporation [Ver = 5.2.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 267776 bytes | Date = 08/04/2004 03:56 | Attr = ])
Help and Support--------------------------------------------helpsvc------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
HID Input Service-------------------------------------------HidServ------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
HTTP SSL----------------------------------------------------HTTPFilter---------------On Demand------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k HTTPFilter (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Infrared Monitor--------------------------------------------Irmon--------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Server------------------------------------------------------lanmanserver-------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Workstation-------------------------------------------------lanmanworkstation--------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
TCP/IP NetBIOS Helper---------------------------------------LmHosts------------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k LocalService (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Machine Debug Manager---------------------------------------MDM----------------------Automatic------Running---Win32, running in it's own process----------------"C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe" (Microsoft Corporation [Ver = 7.00.9466 | Size = 322120 bytes | Date = 06/20/2003 03:25 | Attr = ])
Network Connections-----------------------------------------Netman-------------------On Demand------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Network Location Awareness (NLA)----------------------------Nla----------------------On Demand------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Plug and Play-----------------------------------------------PlugPlay-----------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\system32\services.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 108032 bytes | Date = 08/04/2004 03:56 | Attr = ])
Pml Driver HPH11--------------------------------------------Pml Driver HPH11---------On Demand------Running---Win32, running in it's own process----------------C:\WINDOWS\system32\HPHipm11.exe (HP [Ver = 4, 5, 0, 770 | Size = 77824 bytes | Date = 01/06/2006 15:07 | Attr = ])
IPSEC Services----------------------------------------------PolicyAgent--------------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\lsass.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 13312 bytes | Date = 08/04/2004 03:56 | Attr = ])
Protected Storage-------------------------------------------ProtectedStorage---------Automatic------Running---Win32, running in a shared process----------------C:\WINDOWS\system32\lsass.exe (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 13312 bytes | Date = 08/04/2004 03:56 | Attr = ])
Remote Access Connection Manager----------------------------RasMan-------------------On Demand------Running---Win32, running in a shared process----------------C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 03:56 | Attr = ])
Remote Procedure Call (RPC)---------------------------------RpcSs-------------------

#13 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:02:20 AM

Posted 28 July 2006 - 03:50 PM

Hi licensedtoquill. I don't see the files portion because the info was too large for a single post but that's Ok. We already know that the hosts file is gone.

The 2 protocol lines are still showing so let's go after those again.

Start WinPFind2 and click the Registry tab. Click the Scan Registry button and when it has finished go all the way to the bottom. Sometimes you need to click the down arrow on the slider to get all the way to the end.

Put check in front of the following 2 items:HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\text/html
HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\text/plain

and then click the Delete Entries button.

As for the hosts file, check the folder C:\WINDOWS\system32\drivers\etc and see what is in there. There may be a backup. I don't know what would have caused it to disappear but stranger things have happened. When you say you made your own hosts file did you use one like the MVP hosts file?

Other than the above the log looks good.

Cheers.

OT

Edited by OldTimer, 28 July 2006 - 07:25 PM.

I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#14 licensedtoquill

licensedtoquill
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:02:20 AM

Posted 28 July 2006 - 10:15 PM

Many thanks OldTimer but the curious thing is that as I say, I did create the hosts file myself and save it as HOSTS with no extension. Possibly I should put a .sam at the end like in the old 98 days? It starts:

# This MVPS HOSTS file is a free download from: #
# http://www.mvps.org/winhelp2002/ #
# #
# Notes: the browser does not read this "#" symbol #
# You can create your own notes, after the # symbol #
# This *must* be the first line: 127.0.0.1 localhost #
# ********************************************************#
# ------------------Updated: 03-24-06---------------------#
# ********************************************************#
# Entries marked with Parasite or Trojan comments should #
# be placed in the Internet Explorer Restricted Zone. #
# http://mvps.org/winhelp2002/restricted.htm #
# #
# Entries with other comments are searchable via Google. #
# #
# Disclaimer: this file is free to use, however it is NOT #
# permitted to post on any other site without permission. #
# #
# This work is licensed under the Creative Commons #
# Attribution-NonCommercial-ShareAlike License. #
# http://creativecommons.org/licenses/by-nc-sa/2.0/ #

127.0.0.1 localhost

#start of lines added by WinHelp2002
# [Misc A - Z]
127.0.0.1 phpadsnew.abac.com
127.0.0.1 a.abnad.net
127.0.0.1 b.abnad.net
127.0.0.1 c.abnad.net #[IE-SpyAd]

and goes on for 455 kb of all this and something is stopping it from working

By the way, what were all those files or entries in the registry which I removed please?

#15 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:02:20 AM

Posted 30 July 2006 - 03:20 PM

Hi licensedtoquill. So there is a hosts file in the etc folder? If so, then the registry entry my simply be missing and we will need to add it.

As for the entries we removed, they were mostly extensions that were at one time added to IE (like Norton, Yahoo Companion, Real Player) but the files were no longer present. The vf9 file was part of an infection but that was already removed also. We just removed the run key that was still residing in the registry.

Let me know about the hosts file and when that's taken care of we can finish things up.

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users