0 1:38:01 PM Fgouhhie Seek L:\IE\TEMPOR\CONTENT.IE5\INDEX.DAT SUCCESS Beginning Offset: 0 / New offset: 0 1 1:38:01 PM Fgouhhie Seek L:\IE\TEMPOR\CONTENT.IE5\INDEX.DAT SUCCESS End Offset: 0 / New offset: 0 2 1:38:01 PM Fgouhhie Seek L:\IE\TEMPOR\CONTENT.IE5\INDEX.DAT SUCCESS Beginning Offset: 0 / New offset: 0 3 1:38:03 PM Sysmecha FindOpen D:\UTILS\SYSMECH\STARTUP\ORIGINAL_STARTUP_PROFILE.CFG SUCCESS Original_StartUp_Profile.cfg 4 1:38:03 PM Sysmecha FindClose D:\UTILS\SYSMECH\STARTUP\ORIGINAL_STARTUP_PROFILE.CFG SUCCESS 5 1:38:03 PM Sysmecha Attributes C:\WINDOWS SUCCESS GetAttributes 6 1:38:03 PM Sysmecha Attributes D:\UTILS\SYSMECH\SYSTRAY.EXE NOTFOUND GetAttributes 7 1:38:03 PM Sysmecha Attributes C:\WINDOWS\SYSTRAY.EXE NOTFOUND GetAttributes 8 1:38:03 PM Sysmecha Attributes C:\WINDOWS\SYSTEM\SYSTRAY.EXE SUCCESS GetAttributes 9 1:38:03 PM Sysmecha Open C:\WINDOWS\SYSTEM\SYSTRAY.EXE SUCCESS OPENEXISTING READONLY DENYWRITE 10 1:38:03 PM Sysmecha Read C:\WINDOWS\SYSTEM\SYSTRAY.EXE SUCCESS Offset: 0 Length: 64 11 1:38:03 PM Sysmecha Seek C:\WINDOWS\SYSTEM\SYSTRAY.EXE SUCCESS Beginning Offset: 192 / New offset: 192 12 1:38:03 PM Sysmecha Read C:\WINDOWS\SYSTEM\SYSTRAY.EXE SUCCESS Offset: 192 Length: 248 13 1:38:03 PM Sysmecha Close C:\WINDOWS\SYSTEM\SYSTRAY.EXE SUCCESS CLOSE_FINAL 14 1:38:03 PM Sysmecha Directory C:\WINDOWS SUCCESS CHECK 15 1:38:03 PM ??? Attributes C:\WINDOWS SUCCESS GetAttributes 16 1:38:03 PM ??? Attributes C:\WINDOWS\SYSTEM\SYSTRAY.EXE SUCCESS GetAttributes 17 1:38:03 PM ??? Directory C:\WINDOWS\SYSTEM\SYSTRAY.EXE SUCCESS QUERY 18 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SYSTRAY.EXE SUCCESS Offset: 13312 Length: 4096 19 1:38:03 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 536576 Length: 4096 20 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 340992 Length: 4096 21 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 237568 Length: 4096 22 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 237568 Length: 4096 23 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 212992 Length: 4096 24 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 212992 Length: 4096 25 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 241664 Length: 1536 26 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 345088 Length: 4096 27 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 349184 Length: 4096 28 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 340992 Length: 4096 29 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 1024 Length: 4096 30 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 1024 Length: 4096 31 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 221184 Length: 4096 32 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 225280 Length: 4096 33 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 233472 Length: 4096 34 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 229376 Length: 4096 35 1:38:03 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 536576 Length: 4096 36 1:38:03 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 4096 Length: 4096 37 1:38:03 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 4096 Length: 4096 38 1:38:03 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 540672 Length: 4096 39 1:38:03 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 544768 Length: 4096 40 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 353280 Length: 4096 41 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 357376 Length: 4096 42 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 361472 Length: 1024 43 1:38:03 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 548864 Length: 1536 44 1:38:03 PM ??? Attributes C:\WINDOWS\SYSTEM\POWRPROF.DLL SUCCESS GetAttributes 45 1:38:03 PM ??? Directory C:\WINDOWS\SYSTEM\POWRPROF.DLL SUCCESS QUERY 46 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 8192 Length: 4096 47 1:38:03 PM ??? Attributes C:\WINDOWS\SYSTEM\SETUPAPI.DLL SUCCESS GetAttributes 48 1:38:03 PM ??? Directory C:\WINDOWS\SYSTEM\SETUPAPI.DLL SUCCESS QUERY 49 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SETUPAPI.DLL SUCCESS Offset: 249856 Length: 4096 50 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SETUPAPI.DLL SUCCESS Offset: 253952 Length: 4096 51 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SETUPAPI.DLL SUCCESS Offset: 258048 Length: 4096 52 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\COMDLG32.DLL SUCCESS Offset: 110592 Length: 4096 53 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\COMDLG32.DLL SUCCESS Offset: 114688 Length: 4096 54 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\COMDLG32.DLL SUCCESS Offset: 118784 Length: 1536 55 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\COMDLG32.DLL SUCCESS Offset: 110592 Length: 4096 56 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\COMDLG32.DLL SUCCESS Offset: 4096 Length: 4096 57 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\COMDLG32.DLL SUCCESS Offset: 4096 Length: 4096 58 1:38:03 PM ??? Attributes C:\WINDOWS\SYSTEM\WINSPOOL.DRV SUCCESS GetAttributes 59 1:38:03 PM ??? Directory C:\WINDOWS\SYSTEM\WINSPOOL.DRV SUCCESS QUERY 60 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\WINSPOOL.DRV SUCCESS Offset: 18944 Length: 1536 61 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\WINSPOOL.DRV SUCCESS Offset: 18944 Length: 1536 62 1:38:03 PM ??? Attributes C:\WINDOWS\SYSTEM\CFGMGR32.DLL SUCCESS GetAttributes 63 1:38:03 PM ??? Directory C:\WINDOWS\SYSTEM\CFGMGR32.DLL SUCCESS QUERY 64 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\CFGMGR32.DLL SUCCESS Offset: 32768 Length: 1024 65 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\CFGMGR32.DLL SUCCESS Offset: 32768 Length: 4096 66 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MPR.DLL SUCCESS Offset: 36864 Length: 2048 67 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MPR.DLL SUCCESS Offset: 36864 Length: 4096 68 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\RPCRT4.DLL SUCCESS Offset: 311808 Length: 3072 69 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\RPCRT4.DLL SUCCESS Offset: 311808 Length: 3072 70 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SETUPAPI.DLL SUCCESS Offset: 249856 Length: 4096 71 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SETUPAPI.DLL SUCCESS Offset: 4096 Length: 4096 72 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SETUPAPI.DLL SUCCESS Offset: 4096 Length: 4096 73 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SETUPAPI.DLL SUCCESS Offset: 253952 Length: 4096 74 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 8192 Length: 4096 75 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 4096 Length: 4096 76 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 4096 Length: 4096 77 1:38:03 PM ??? Attributes C:\WINDOWS\SYSTEM\BATMETER.DLL SUCCESS GetAttributes 78 1:38:03 PM ??? Directory C:\WINDOWS\SYSTEM\BATMETER.DLL SUCCESS QUERY 79 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\BATMETER.DLL SUCCESS Offset: 8192 Length: 4096 80 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\BATMETER.DLL SUCCESS Offset: 12288 Length: 1536 81 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\BATMETER.DLL SUCCESS Offset: 8192 Length: 4096 82 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\BATMETER.DLL SUCCESS Offset: 4096 Length: 4096 83 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\BATMETER.DLL SUCCESS Offset: 4096 Length: 4096 84 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\BATMETER.DLL SUCCESS Offset: 12288 Length: 4096 85 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SYSTRAY.EXE SUCCESS Offset: 13312 Length: 4096 86 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SYSTRAY.EXE SUCCESS Offset: 1024 Length: 4096 87 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SYSTRAY.EXE SUCCESS Offset: 1024 Length: 4096 88 1:38:03 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 528384 Length: 4096 89 1:38:03 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 532480 Length: 4096 90 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SETUPAPI.DLL SUCCESS Offset: 262144 Length: 4096 91 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SETUPAPI.DLL SUCCESS Offset: 266240 Length: 4096 92 1:38:03 PM Sysmecha Attributes C:\WINDOWS SUCCESS GetAttributes 93 1:38:03 PM Sysmecha Attributes C:\WINDOWS\BATCH\CLR-IE.PIF SUCCESS GetAttributes 94 1:38:03 PM Sysmecha Open C:\WINDOWS\BATCH\CLR-IE.PIF SUCCESS OPENEXISTING READONLY DENYWRITE 95 1:38:03 PM Sysmecha Read C:\WINDOWS\BATCH\CLR-IE.PIF SUCCESS Offset: 0 Length: 64 96 1:38:03 PM Sysmecha Close C:\WINDOWS\BATCH\CLR-IE.PIF SUCCESS CLOSE_FINAL 97 1:38:03 PM Sysmecha Attributes C:\WINDOWS SUCCESS GetAttributes 98 1:38:03 PM Sysmecha Attributes C:\WINDOWS\SYSTEM\WINOA386.MOD SUCCESS GetAttributes 99 1:38:03 PM Sysmecha Open C:\WINDOWS\SYSTEM\WINOA386.MOD SUCCESS OPENEXISTING READONLY COMPATIBILITY 100 1:38:03 PM Sysmecha Ioctl C: SUCCESS Subfunction: 08h 101 1:38:03 PM Sysmecha Attributes C:\WINDOWS\SYSTEM\WINOA386.MOD SUCCESS Get Modify 102 1:38:03 PM Sysmecha Read C:\WINDOWS\SYSTEM\WINOA386.MOD SUCCESS Offset: 0 Length: 64 103 1:38:03 PM Sysmecha Seek C:\WINDOWS\SYSTEM\WINOA386.MOD SUCCESS Beginning Offset: 128 / New offset: 128 104 1:38:03 PM Sysmecha Read C:\WINDOWS\SYSTEM\WINOA386.MOD SUCCESS Offset: 128 Length: 64 105 1:38:03 PM Sysmecha Read C:\WINDOWS\SYSTEM\WINOA386.MOD SUCCESS Offset: 192 Length: 648 106 1:38:03 PM Sysmecha Seek C:\WINDOWS\SYSTEM\WINOA386.MOD SUCCESS Beginning Offset: 928 / New offset: 928 107 1:38:03 PM Sysmecha Read C:\WINDOWS\SYSTEM\WINOA386.MOD SUCCESS Offset: 928 Length: 32768 108 1:38:03 PM Sysmecha Read C:\WINDOWS\SYSTEM\WINOA386.MOD SUCCESS Offset: 33696 Length: 1952 109 1:38:03 PM Sysmecha Directory C:\WINDOWS SUCCESS CHECK 110 1:38:03 PM Sysmecha FindOpen C:\WINDOWS\WIN.INI SUCCESS WIN.INI 111 1:38:03 PM Sysmecha FindClose C:\WINDOWS\WIN.INI SUCCESS 112 1:38:03 PM Sysmecha Open C:\WINDOWS\WIN.INI SUCCESS OPENEXISTING READWRITE DENYWRITE 113 1:38:03 PM Sysmecha Ioctl C: SUCCESS Subfunction: 08h 114 1:38:03 PM Sysmecha Attributes C:\WINDOWS\WIN.INI SUCCESS Get Modify 115 1:38:03 PM Sysmecha Seek C:\WINDOWS\WIN.INI SUCCESS End Offset: 0 / New offset: 0 116 1:38:03 PM Sysmecha Seek C:\WINDOWS\WIN.INI SUCCESS Beginning Offset: 0 / New offset: 0 117 1:38:03 PM Sysmecha Read C:\WINDOWS\WIN.INI SUCCESS Offset: 0 Length: 8335 118 1:38:03 PM Sysmecha Close C:\WINDOWS\WIN.INI SUCCESS CLOSE_FINAL 119 1:38:03 PM Sysmecha Attributes C:\WINDOWS SUCCESS GetAttributes 120 1:38:03 PM Sysmecha Attributes C:\WINDOWS SUCCESS GetAttributes 121 1:38:03 PM Sysmecha Attributes D:\UTILS\SYSMECH\RUNDLL32.EXE NOTFOUND GetAttributes 122 1:38:03 PM Sysmecha Attributes C:\WINDOWS\RUNDLL32.EXE SUCCESS GetAttributes 123 1:38:03 PM Sysmecha Open C:\WINDOWS\RUNDLL32.EXE SUCCESS OPENEXISTING READONLY DENYWRITE 124 1:38:03 PM Sysmecha Read C:\WINDOWS\RUNDLL32.EXE SUCCESS Offset: 0 Length: 64 125 1:38:03 PM Sysmecha Seek C:\WINDOWS\RUNDLL32.EXE SUCCESS Beginning Offset: 128 / New offset: 128 126 1:38:03 PM Sysmecha Read C:\WINDOWS\RUNDLL32.EXE SUCCESS Offset: 128 Length: 248 127 1:38:03 PM Sysmecha Close C:\WINDOWS\RUNDLL32.EXE SUCCESS CLOSE_FINAL 128 1:38:03 PM Sysmecha Directory C:\WINDOWS SUCCESS CHECK 129 1:38:03 PM WINOLDAP Close C:\WINDOWS\SYSTEM\WINOA386.MOD SUCCESS CLOSE_FINAL 130 1:38:03 PM ??? Attributes C:\WINDOWS SUCCESS GetAttributes 131 1:38:03 PM ??? Attributes C:\WINDOWS\RUNDLL32.EXE SUCCESS GetAttributes 132 1:38:03 PM ??? Directory C:\WINDOWS\RUNDLL32.EXE SUCCESS QUERY 133 1:38:03 PM ??? Open C:\WINDOWS\RUNDLL32.EXE SUCCESS OPENEXISTING READONLY DENYWRITE 134 1:38:03 PM ??? Read C:\WINDOWS\RUNDLL32.EXE SUCCESS Offset: 0 Length: 64 135 1:38:03 PM ??? Seek C:\WINDOWS\RUNDLL32.EXE SUCCESS Beginning Offset: 128 / New offset: 128 136 1:38:03 PM ??? Read C:\WINDOWS\RUNDLL32.EXE SUCCESS Offset: 128 Length: 248 137 1:38:03 PM ??? Seek C:\WINDOWS\RUNDLL32.EXE SUCCESS Beginning Offset: 128 / New offset: 128 138 1:38:03 PM ??? Read C:\WINDOWS\RUNDLL32.EXE SUCCESS Offset: 128 Length: 448 139 1:38:03 PM ??? Directory C:\WINDOWS\RUNDLL32.EXE SUCCESS QUERY 140 1:38:03 PM ??? Read C:\WINDOWS\RUNDLL32.EXE SUCCESS Offset: 12288 Length: 1024 141 1:38:03 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 536576 Length: 4096 142 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 340992 Length: 4096 143 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 237568 Length: 4096 144 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 237568 Length: 4096 145 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 212992 Length: 4096 146 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 212992 Length: 4096 147 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 241664 Length: 1536 148 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 345088 Length: 4096 149 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 349184 Length: 4096 150 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 340992 Length: 4096 151 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 1024 Length: 4096 152 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 1024 Length: 4096 153 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 221184 Length: 4096 154 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 225280 Length: 4096 155 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 233472 Length: 4096 156 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 229376 Length: 4096 157 1:38:03 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 536576 Length: 4096 158 1:38:03 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 4096 Length: 4096 159 1:38:03 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 4096 Length: 4096 160 1:38:03 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 540672 Length: 4096 161 1:38:03 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 544768 Length: 4096 162 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 353280 Length: 4096 163 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 357376 Length: 4096 164 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 361472 Length: 1024 165 1:38:03 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 548864 Length: 1536 166 1:38:03 PM ??? Read C:\WINDOWS\RUNDLL32.EXE SUCCESS Offset: 12288 Length: 4096 167 1:38:03 PM Sysmecha Attributes C:\WINDOWS SUCCESS GetAttributes 168 1:38:03 PM Sysmecha Attributes D:\UTILS\SYSMECH\FGOUHHIEXNNBJ.EXE NOTFOUND GetAttributes 169 1:38:03 PM Sysmecha Attributes C:\WINDOWS\FGOUHHIEXNNBJ.EXE SUCCESS GetAttributes 170 1:38:03 PM Sysmecha Open C:\WINDOWS\FGOUHHIEXNNBJ.EXE SUCCESS OPENEXISTING READONLY DENYWRITE 171 1:38:03 PM Sysmecha Read C:\WINDOWS\FGOUHHIEXNNBJ.EXE SUCCESS Offset: 0 Length: 64 172 1:38:03 PM Sysmecha Seek C:\WINDOWS\FGOUHHIEXNNBJ.EXE SUCCESS Beginning Offset: 256 / New offset: 256 173 1:38:03 PM Sysmecha Read C:\WINDOWS\FGOUHHIEXNNBJ.EXE SUCCESS Offset: 256 Length: 248 174 1:38:03 PM Sysmecha Close C:\WINDOWS\FGOUHHIEXNNBJ.EXE SUCCESS CLOSE_FINAL 175 1:38:03 PM Sysmecha Directory C:\WINDOWS SUCCESS CHECK 176 1:38:03 PM KERNEL32 Close C:\WINDOWS\RUNDLL32.EXE SUCCESS CLOSE_FINAL 177 1:38:03 PM ??? Attributes C:\WINDOWS SUCCESS GetAttributes 178 1:38:03 PM ??? Attributes C:\WINDOWS\FGOUHHIEXNNBJ.EXE SUCCESS GetAttributes 179 1:38:03 PM ??? Directory C:\WINDOWS\FGOUHHIEXNNBJ.EXE SUCCESS QUERY 180 1:38:03 PM ??? Read C:\WINDOWS\FGOUHH~1.EXE SUCCESS Offset: 377856 Length: 2560 181 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\OLE32.DLL SUCCESS Offset: 544768 Length: 4096 182 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\OLE32.DLL SUCCESS Offset: 548864 Length: 4096 183 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\OLE32.DLL SUCCESS Offset: 669184 Length: 4096 184 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\OLE32.DLL SUCCESS Offset: 669184 Length: 4096 185 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\OLE32.DLL SUCCESS Offset: 1536 Length: 4096 186 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\OLE32.DLL SUCCESS Offset: 1536 Length: 4096 187 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\OLE32.DLL SUCCESS Offset: 673280 Length: 4096 188 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\OLE32.DLL SUCCESS Offset: 677376 Length: 2048 189 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\OLE32.DLL SUCCESS Offset: 552960 Length: 4096 190 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\OLE32.DLL SUCCESS Offset: 544768 Length: 4096 191 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\OLE32.DLL SUCCESS Offset: 8192 Length: 4096 192 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\OLE32.DLL SUCCESS Offset: 8192 Length: 4096 193 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\OLE32.DLL SUCCESS Offset: 345600 Length: 4096 194 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\OLE32.DLL SUCCESS Offset: 349696 Length: 4096 195 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\OLE32.DLL SUCCESS Offset: 353792 Length: 4096 196 1:38:03 PM ??? Attributes C:\WINDOWS\WINSPOOL.DRV NOTFOUND GetAttributes 197 1:38:03 PM ??? Attributes C:\WINDOWS\SYSTEM\WINSPOOL.DRV SUCCESS GetAttributes 198 1:38:03 PM ??? Directory C:\WINDOWS\SYSTEM\WINSPOOL.DRV SUCCESS QUERY 199 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\WINSPOOL.DRV SUCCESS Offset: 18944 Length: 1536 200 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\WINSPOOL.DRV SUCCESS Offset: 18944 Length: 1536 201 1:38:03 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 536576 Length: 4096 202 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 340992 Length: 4096 203 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 237568 Length: 4096 204 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 237568 Length: 4096 205 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 212992 Length: 4096 206 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 212992 Length: 4096 207 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 241664 Length: 1536 208 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 345088 Length: 4096 209 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 349184 Length: 4096 210 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 340992 Length: 4096 211 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 1024 Length: 4096 212 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 1024 Length: 4096 213 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 221184 Length: 4096 214 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 225280 Length: 4096 215 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 233472 Length: 4096 216 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 229376 Length: 4096 217 1:38:03 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 536576 Length: 4096 218 1:38:03 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 4096 Length: 4096 219 1:38:03 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 4096 Length: 4096 220 1:38:03 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 540672 Length: 4096 221 1:38:03 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 544768 Length: 4096 222 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 353280 Length: 4096 223 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 357376 Length: 4096 224 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 361472 Length: 1024 225 1:38:03 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 548864 Length: 1536 226 1:38:03 PM ??? Attributes C:\WINDOWS\WSOCK32.DLL NOTFOUND GetAttributes 227 1:38:03 PM ??? Attributes C:\WINDOWS\SYSTEM\WSOCK32.DLL SUCCESS GetAttributes 228 1:38:03 PM ??? Directory C:\WINDOWS\SYSTEM\WSOCK32.DLL SUCCESS QUERY 229 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\RASAPI32.DLL SUCCESS Offset: 147456 Length: 4096 230 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\RASAPI32.DLL SUCCESS Offset: 151552 Length: 2048 231 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MPR.DLL SUCCESS Offset: 36864 Length: 2048 232 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MPR.DLL SUCCESS Offset: 36864 Length: 4096 233 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\TAPI32.DLL SUCCESS Offset: 106496 Length: 4096 234 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\RPCRT4.DLL SUCCESS Offset: 311808 Length: 3072 235 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\RPCRT4.DLL SUCCESS Offset: 311808 Length: 3072 236 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\TAPI32.DLL SUCCESS Offset: 106496 Length: 4096 237 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSWSOCK.DLL SUCCESS Offset: 28672 Length: 1024 238 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSWSOCK.DLL SUCCESS Offset: 28672 Length: 4096 239 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SVRAPI.DLL SUCCESS Offset: 16384 Length: 1024 240 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SVRAPI.DLL SUCCESS Offset: 16384 Length: 4096 241 1:38:03 PM ??? Attributes C:\WINDOWS\SECUR32.DLL NOTFOUND GetAttributes 242 1:38:03 PM ??? Attributes C:\WINDOWS\SYSTEM\SECUR32.DLL SUCCESS GetAttributes 243 1:38:03 PM ??? Directory C:\WINDOWS\SYSTEM\SECUR32.DLL SUCCESS QUERY 244 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SECUR32.DLL SUCCESS Offset: 28672 Length: 1536 245 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT20.DLL SUCCESS Offset: 225280 Length: 3072 246 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT20.DLL SUCCESS Offset: 225280 Length: 4096 247 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\SECUR32.DLL SUCCESS Offset: 28672 Length: 4096 248 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\RASAPI32.DLL SUCCESS Offset: 147456 Length: 4096 249 1:38:03 PM ??? Attributes C:\WINDOWS\AVICAP32.DLL NOTFOUND GetAttributes 250 1:38:03 PM ??? Attributes C:\WINDOWS\SYSTEM\AVICAP32.DLL SUCCESS GetAttributes 251 1:38:03 PM ??? Directory C:\WINDOWS\SYSTEM\AVICAP32.DLL SUCCESS QUERY 252 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\USER.EXE SUCCESS Offset: 53248 Length: 4096 253 1:38:03 PM ??? Attributes C:\WINDOWS\MSVFW32.DLL NOTFOUND GetAttributes 254 1:38:03 PM ??? Attributes C:\WINDOWS\SYSTEM\MSVFW32.DLL SUCCESS GetAttributes 255 1:38:03 PM ??? Directory C:\WINDOWS\SYSTEM\MSVFW32.DLL SUCCESS QUERY 256 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MPR.DLL SUCCESS Offset: 114688 Length: 4096 257 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MPR.DLL SUCCESS Offset: 118784 Length: 2048 258 1:38:03 PM ??? Attributes C:\WINDOWS\DCIMAN32.DLL NOTFOUND GetAttributes 259 1:38:03 PM ??? Attributes C:\WINDOWS\SYSTEM\DCIMAN32.DLL SUCCESS GetAttributes 260 1:38:03 PM ??? Directory C:\WINDOWS\SYSTEM\DCIMAN32.DLL SUCCESS QUERY 261 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\MPR.DLL SUCCESS Offset: 114688 Length: 4096 262 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\USER.EXE SUCCESS Offset: 53248 Length: 4096 263 1:38:03 PM ??? Read C:\WINDOWS\FGOUHH~1.EXE SUCCESS Offset: 377856 Length: 2560 264 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\OLE32.DLL SUCCESS Offset: 557056 Length: 4096 265 1:38:03 PM ??? Read C:\WINDOWS\SYSTEM\OLE32.DLL SUCCESS Offset: 561152 Length: 1536 266 1:38:03 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 528384 Length: 4096 267 1:38:03 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 532480 Length: 4096 268 1:38:03 PM Sysmecha FindOpen C:\WINDOWS\START MENU\PROGRAMS\STARTUP\*.* SUCCESS . 269 1:38:03 PM Sysmecha FindNext C:\WINDOWS\START MENU\PROGRAMS\STARTUP\*.* SUCCESS .. 270 1:38:03 PM Sysmecha FindNext C:\WINDOWS\START MENU\PROGRAMS\STARTUP\*.* SUCCESS Microsoft Office Shortcut Bar.lnk 271 1:38:03 PM Sysmecha Open C:\WINDOWS\START MENU\PROGRAMS\STARTUP\MICROSOFT OFFICE SHORTCUT BAR.LNK SUCCESS OPENEXISTING READONLY DENYNONE 272 1:38:03 PM Sysmecha Read C:\WINDOWS\START MENU\PROGRAMS\STARTUP\MICROSOFT OFFICE SHORTCUT BAR.LNK SUCCESS Offset: 0 Length: 4096 273 1:38:03 PM Sysmecha FindOpen C:\WINDOWS SUCCESS WINDOWS 274 1:38:03 PM Sysmecha FindClose C:\WINDOWS SUCCESS 275 1:38:03 PM Sysmecha FindOpen C:\WINDOWS\APPLICATION DATA SUCCESS Application Data 276 1:38:03 PM Sysmecha FindClose C:\WINDOWS\APPLICATION DATA SUCCESS 277 1:38:03 PM Sysmecha FindOpen C:\WINDOWS\APPLICATION DATA\MICROSOFT SUCCESS Microsoft 278 1:38:03 PM Sysmecha FindClose C:\WINDOWS\APPLICATION DATA\MICROSOFT SUCCESS 279 1:38:03 PM Sysmecha FindOpen C:\WINDOWS\APPLICATION DATA\MICROSOFT\INSTALLER SUCCESS Installer 280 1:38:03 PM Sysmecha FindClose C:\WINDOWS\APPLICATION DATA\MICROSOFT\INSTALLER SUCCESS 281 1:38:03 PM Sysmecha FindOpen C:\WINDOWS\APPLICATION DATA\MICROSOFT\INSTALLER\{00000409-78E1-11D2-B60F-006097C998E7} SUCCESS {00000409-78E1-11D2-B60F-006097C998E7} 282 1:38:03 PM Sysmecha FindClose C:\WINDOWS\APPLICATION DATA\MICROSOFT\INSTALLER\{00000409-78E1-11D2-B60F-006097C998E7} SUCCESS 283 1:38:03 PM Sysmecha FindOpen C:\WINDOWS\APPLICATION DATA\MICROSOFT\INSTALLER\{00000409-78E1-11D2-B60F-006097C998E7}\MISC.EXE SUCCESS misc.exe 284 1:38:03 PM Sysmecha FindClose C:\WINDOWS\APPLICATION DATA\MICROSOFT\INSTALLER\{00000409-78E1-11D2-B60F-006097C998E7}\MISC.EXE SUCCESS 285 1:38:03 PM Sysmecha Close C:\WINDOWS\START MENU\PROGRAMS\STARTUP\MICROSOFT OFFICE SHORTCUT BAR.LNK SUCCESS CLOSE_FINAL 286 1:38:03 PM Sysmecha Attributes D:\PROGRAMS\MSOFFICE\OFFICE\OSA9.EXE SUCCESS GetAttributes 287 1:38:03 PM Sysmecha Attributes D:\PROGRAMS\MSOFFICE\OFFICE\1033\MSOFFICE.EXE SUCCESS GetAttributes 288 1:38:03 PM Sysmecha Attributes D:\PROGRAMS\MSOFFICE\OFFICE\MSO9.DLL SUCCESS GetAttributes 289 1:38:03 PM Sysmecha Attributes C:\WINDOWS\SYSTEM\FM20.DLL SUCCESS GetAttributes 290 1:38:03 PM Sysmecha Attributes C:\WINDOWS\SYSTEM\FM20ENU.DLL SUCCESS GetAttributes 291 1:38:03 PM Sysmecha Attributes C:\WINDOWS\SYSTEM\MSLS31.DLL SUCCESS GetAttributes 292 1:38:03 PM Sysmecha Attributes D:\PROGRAMS\MSOFFICE\OFFICE\MSO7FTP.EXE SUCCESS GetAttributes 293 1:38:03 PM Sysmecha Attributes D:\PROGRAMS\MSOFFICE\OFFICE\1033\MSO9INTL.DLL SUCCESS GetAttributes 294 1:38:03 PM Sysmecha Attributes D:\PROGRAMS\MSOFFICE\OFFICE SUCCESS GetAttributes 295 1:38:03 PM Sysmecha Attributes C:\WINDOWS\SYSTEM\USP10.DLL SUCCESS GetAttributes 296 1:38:03 PM Sysmecha Attributes D:\PROGRAMS\MSOFFICE\OFFICE\1033\WW9ASUM.DLL SUCCESS GetAttributes 297 1:38:03 PM Sysmecha Attributes D:\PROGRAMS\MSOFFICE\OFFICE\OSA9.EXE SUCCESS GetAttributes 298 1:38:03 PM Sysmecha Attributes E:\DOCS SUCCESS GetAttributes 299 1:38:03 PM Sysmecha FindOpen E:\DOCS SUCCESS Docs 300 1:38:03 PM Sysmecha FindClose E:\DOCS SUCCESS 301 1:38:03 PM Sysmecha Attributes E:\DOCS\DESKTOP.INI SUCCESS GetAttributes 302 1:38:03 PM Sysmecha FindOpen E:\DOCS\DESKTOP.INI NOTFOUND 303 1:38:03 PM Sysmecha Attributes E:\DOCS\DESKTOP.INI SUCCESS GetAttributes 304 1:38:03 PM Sysmecha Open E:\DOCS\DESKTOP.INI SUCCESS OPENEXISTING READWRITE DENYWRITE 305 1:38:03 PM Sysmecha Ioctl E: SUCCESS Subfunction: 08h 306 1:38:03 PM Sysmecha Attributes E:\DOCS\DESKTOP.INI SUCCESS Get Modify 307 1:38:03 PM Sysmecha Seek E:\DOCS\DESKTOP.INI SUCCESS End Offset: 0 / New offset: 0 308 1:38:03 PM Sysmecha Seek E:\DOCS\DESKTOP.INI SUCCESS Beginning Offset: 0 / New offset: 0 309 1:38:03 PM Sysmecha Read E:\DOCS\DESKTOP.INI SUCCESS Offset: 0 Length: 125 310 1:38:03 PM Sysmecha Close E:\DOCS\DESKTOP.INI SUCCESS CLOSE_FINAL 311 1:38:03 PM Sysmecha Attributes D:\PROGRAMS\MSOFFICE\OFFICE\OSA9.EXE SUCCESS GetAttributes 312 1:38:03 PM Sysmecha Ioctl D: SUCCESS Subfunction: 08h 313 1:38:03 PM Sysmecha FindOpen D:\*.* NOTFOUND 314 1:38:03 PM Sysmecha Ioctl D: SUCCESS Subfunction: 0Dh 315 1:38:03 PM Sysmecha FindOpen D:\*.* NOTFOUND 316 1:38:03 PM Sysmecha Ioctl D: SUCCESS Subfunction: 08h 317 1:38:03 PM Sysmecha FindOpen D:\*.* NOTFOUND 318 1:38:03 PM Sysmecha Attributes C:\WINDOWS SUCCESS GetAttributes 319 1:38:03 PM Sysmecha Attributes C:\WINDOWS\APPLICATION NOTFOUND GetAttributes 320 1:38:03 PM Sysmecha Attributes C:\WINDOWS\APPLICATION.EXE NOTFOUND GetAttributes 321 1:38:03 PM Sysmecha Attributes C:\WINDOWS SUCCESS GetAttributes 322 1:38:03 PM Sysmecha Attributes C:\WINDOWS\APPLICATION NOTFOUND GetAttributes 323 1:38:03 PM Sysmecha Attributes C:\WINDOWS\APPLICATION.EXE NOTFOUND GetAttributes 324 1:38:03 PM Sysmecha Attributes C:\WINDOWS SUCCESS GetAttributes 325 1:38:03 PM Sysmecha Attributes C:\WINDOWS\APPLICATION DATA\MICROSOFT\INSTALLER\{00000409-78E1-11D2-B60F-006097C998E7}\MISC.EXE SUCCESS GetAttributes 326 1:38:03 PM Sysmecha Open C:\WINDOWS\APPLICATION DATA\MICROSOFT\INSTALLER\{00000409-78E1-11D2-B60F-006097C998E7}\MISC.EXE SUCCESS OPENEXISTING READONLY DENYWRITE 327 1:38:03 PM Sysmecha Read C:\WINDOWS\APPLICATION DATA\MICROSOFT\INSTALLER\{00000409-78E1-11D2-B60F-006097C998E7}\MISC.EXE SUCCESS Offset: 0 Length: 64 328 1:38:03 PM Sysmecha Seek C:\WINDOWS\APPLICATION DATA\MICROSOFT\INSTALLER\{00000409-78E1-11D2-B60F-006097C998E7}\MISC.EXE SUCCESS Beginning Offset: 128 / New offset: 128 329 1:38:03 PM Sysmecha Read C:\WINDOWS\APPLICATION DATA\MICROSOFT\INSTALLER\{00000409-78E1-11D2-B60F-006097C998E7}\MISC.EXE SUCCESS Offset: 128 Length: 248 330 1:38:03 PM Sysmecha Close C:\WINDOWS\APPLICATION DATA\MICROSOFT\INSTALLER\{00000409-78E1-11D2-B60F-006097C998E7}\MISC.EXE SUCCESS CLOSE_FINAL 331 1:38:03 PM Sysmecha Directory C:\WINDOWS SUCCESS CHECK 332 1:38:04 PM ??? Attributes C:\WINDOWS SUCCESS GetAttributes 333 1:38:04 PM ??? Attributes C:\WINDOWS\APPLICATION DATA\MICROSOFT\INSTALLER\{00000409-78E1-11D2-B60F-006097C998E7}\MISC.EXE SUCCESS GetAttributes 334 1:38:04 PM ??? Directory C:\WINDOWS\APPLICATION DATA\MICROSOFT\INSTALLER\{00000409-78E1-11D2-B60F-006097C998E7}\MISC.EXE SUCCESS QUERY 335 1:38:04 PM ??? Open C:\WINDOWS\APPLICATION DATA\MICROSOFT\INSTALLER\{00000409-78E1-11D2-B60F-006097C998E7}\MISC.EXE SUCCESS OPENEXISTING READONLY DENYWRITE 336 1:38:04 PM ??? Read C:\WINDOWS\APPLICATION DATA\MICROSOFT\INSTALLER\{00000409-78E1-11D2-B60F-006097C998E7}\MISC.EXE SUCCESS Offset: 0 Length: 64 337 1:38:04 PM ??? Seek C:\WINDOWS\APPLICATION DATA\MICROSOFT\INSTALLER\{00000409-78E1-11D2-B60F-006097C998E7}\MISC.EXE SUCCESS Beginning Offset: 128 / New offset: 128 338 1:38:04 PM ??? Read C:\WINDOWS\APPLICATION DATA\MICROSOFT\INSTALLER\{00000409-78E1-11D2-B60F-006097C998E7}\MISC.EXE SUCCESS Offset: 128 Length: 248 339 1:38:04 PM ??? Seek C:\WINDOWS\APPLICATION DATA\MICROSOFT\INSTALLER\{00000409-78E1-11D2-B60F-006097C998E7}\MISC.EXE SUCCESS Beginning Offset: 128 / New offset: 128 340 1:38:04 PM ??? Read C:\WINDOWS\APPLICATION DATA\MICROSOFT\INSTALLER\{00000409-78E1-11D2-B60F-006097C998E7}\MISC.EXE SUCCESS Offset: 128 Length: 328 341 1:38:04 PM ??? Directory C:\WINDOWS\APPLICATION DATA\MICROSOFT\INSTALLER\{00000409-78E1-11D2-B60F-006097C998E7}\MISC.EXE SUCCESS QUERY 342 1:38:04 PM ??? Read C:\WINDOWS\APPLICATION DATA\MICROSOFT\INSTALLER\{00000409-78E1-11D2-B60F-006097C998E7}\MISC.EXE SUCCESS Offset: 1024 Length: 4096 343 1:38:04 PM Sysmecha FindNext C:\WINDOWS\START MENU\PROGRAMS\STARTUP\*.* NOMORE 344 1:38:04 PM Sysmecha FindClose C:\WINDOWS\START MENU\PROGRAMS\STARTUP\*.* SUCCESS 345 1:38:04 PM Sysmecha FindOpen C:\WINDOWS\ALL USERS\START MENU\PROGRAMS\STARTUP\*.* SUCCESS . 346 1:38:04 PM Sysmecha FindNext C:\WINDOWS\ALL USERS\START MENU\PROGRAMS\STARTUP\*.* SUCCESS .. 347 1:38:04 PM Sysmecha FindNext C:\WINDOWS\ALL USERS\START MENU\PROGRAMS\STARTUP\*.* NOMORE 348 1:38:04 PM Sysmecha FindClose C:\WINDOWS\ALL USERS\START MENU\PROGRAMS\STARTUP\*.* SUCCESS 349 1:38:04 PM Sysmecha Attributes D:\UTILS\SYSMECH\WINREG.DLL NOTFOUND GetAttributes 350 1:38:04 PM Sysmecha Attributes C:\WINDOWS\WINREG.DLL NOTFOUND GetAttributes 351 1:38:04 PM Sysmecha Attributes C:\WINDOWS\SYSTEM\WINREG.DLL NOTFOUND GetAttributes 352 1:38:04 PM Sysmecha Attributes C:\WINDOWS\WINREG.DLL NOTFOUND GetAttributes 353 1:38:04 PM Sysmecha Attributes C:\WINDOWS\COMMAND\WINREG.DLL NOTFOUND GetAttributes 354 1:38:04 PM Sysmecha Attributes C:\DOS\WINREG.DLL NOTFOUND GetAttributes 355 1:38:04 PM Sysmecha Attributes C:\IOMEGA\WINREG.DLL NOTFOUND GetAttributes 356 1:38:04 PM Sysmecha Attributes C:\F-PROT\WINREG.DLL NOTFOUND GetAttributes 357 1:38:04 PM Sysmecha Attributes C:\WINDOWS\BATCH\WINREG.DLL NOTFOUND GetAttributes 358 1:38:04 PM Sysmecha Attributes C:\WINREG.DLL NOTFOUND GetAttributes 359 1:38:04 PM Sysmecha Attributes D:\PROGRAMS\PGP\WINREG.DLL NOTFOUND GetAttributes 360 1:38:04 PM Sysmecha Attributes C:\WINDOWS\SYSTEM32\WINREG.DLL NOTFOUND GetAttributes 361 1:38:04 PM Sysmecha Attributes D:\UTILS\SYSMECH\WINREG.DLL NOTFOUND GetAttributes 362 1:38:04 PM Sysmecha Attributes C:\WINDOWS\WINREG.DLL NOTFOUND GetAttributes 363 1:38:04 PM Sysmecha Attributes C:\WINDOWS\SYSTEM\WINREG.DLL NOTFOUND GetAttributes 364 1:38:04 PM Sysmecha Attributes C:\WINDOWS\WINREG.DLL NOTFOUND GetAttributes 365 1:38:04 PM Sysmecha Attributes C:\WINDOWS\COMMAND\WINREG.DLL NOTFOUND GetAttributes 366 1:38:04 PM Sysmecha Attributes C:\DOS\WINREG.DLL NOTFOUND GetAttributes 367 1:38:04 PM Sysmecha Attributes C:\IOMEGA\WINREG.DLL NOTFOUND GetAttributes 368 1:38:04 PM Sysmecha Attributes C:\F-PROT\WINREG.DLL NOTFOUND GetAttributes 369 1:38:04 PM Sysmecha Attributes C:\WINDOWS\BATCH\WINREG.DLL NOTFOUND GetAttributes 370 1:38:04 PM Sysmecha Attributes C:\WINREG.DLL NOTFOUND GetAttributes 371 1:38:04 PM Sysmecha Attributes D:\PROGRAMS\PGP\WINREG.DLL NOTFOUND GetAttributes 372 1:38:04 PM Sysmecha Attributes C:\WINDOWS\SYSTEM32\WINREG.DLL NOTFOUND GetAttributes 373 1:38:04 PM KERNEL32 Close C:\WINDOWS\APPLICATION DATA\MICROSOFT\INSTALLER\{00000409-78E1-11D2-B60F-006097C998E7}\MISC.EXE SUCCESS CLOSE_FINAL 374 1:38:04 PM Sysmecha Attributes D:\UTILS\SYSMECH\WINREG.DLL NOTFOUND GetAttributes 375 1:38:04 PM Sysmecha Attributes C:\WINDOWS\WINREG.DLL NOTFOUND GetAttributes 376 1:38:04 PM Sysmecha Attributes C:\WINDOWS\SYSTEM\WINREG.DLL NOTFOUND GetAttributes 377 1:38:04 PM Sysmecha Attributes C:\WINDOWS\WINREG.DLL NOTFOUND GetAttributes 378 1:38:04 PM Sysmecha Attributes C:\WINDOWS\COMMAND\WINREG.DLL NOTFOUND GetAttributes 379 1:38:04 PM Sysmecha Attributes C:\DOS\WINREG.DLL NOTFOUND GetAttributes 380 1:38:04 PM Sysmecha Attributes C:\IOMEGA\WINREG.DLL NOTFOUND GetAttributes 381 1:38:04 PM Sysmecha Attributes C:\F-PROT\WINREG.DLL NOTFOUND GetAttributes 382 1:38:04 PM Sysmecha Attributes C:\WINDOWS\BATCH\WINREG.DLL NOTFOUND GetAttributes 383 1:38:04 PM Sysmecha Attributes C:\WINREG.DLL NOTFOUND GetAttributes 384 1:38:04 PM Sysmecha Attributes D:\PROGRAMS\PGP\WINREG.DLL NOTFOUND GetAttributes 385 1:38:04 PM Sysmecha Attributes C:\WINDOWS\SYSTEM32\WINREG.DLL NOTFOUND GetAttributes 386 1:38:04 PM Sysmecha Attributes D:\UTILS\SYSMECH\WINREG.DLL NOTFOUND GetAttributes 387 1:38:04 PM Sysmecha Attributes C:\WINDOWS\WINREG.DLL NOTFOUND GetAttributes 388 1:38:04 PM Sysmecha Attributes C:\WINDOWS\SYSTEM\WINREG.DLL NOTFOUND GetAttributes 389 1:38:04 PM Sysmecha Attributes C:\WINDOWS\WINREG.DLL NOTFOUND GetAttributes 390 1:38:04 PM Sysmecha Attributes C:\WINDOWS\COMMAND\WINREG.DLL NOTFOUND GetAttributes 391 1:38:04 PM Sysmecha Attributes C:\DOS\WINREG.DLL NOTFOUND GetAttributes 392 1:38:04 PM Sysmecha Attributes C:\IOMEGA\WINREG.DLL NOTFOUND GetAttributes 393 1:38:04 PM Sysmecha Attributes C:\F-PROT\WINREG.DLL NOTFOUND GetAttributes 394 1:38:04 PM Sysmecha Attributes C:\WINDOWS\BATCH\WINREG.DLL NOTFOUND GetAttributes 395 1:38:04 PM Sysmecha Attributes C:\WINREG.DLL NOTFOUND GetAttributes 396 1:38:04 PM Sysmecha Attributes D:\PROGRAMS\PGP\WINREG.DLL NOTFOUND GetAttributes 397 1:38:04 PM Sysmecha Attributes C:\WINDOWS\SYSTEM32\WINREG.DLL NOTFOUND GetAttributes 398 1:38:04 PM Sysmecha Attributes C:\WINDOWS SUCCESS GetAttributes 399 1:38:04 PM Sysmecha Attributes D:\UTILS\SYSMECH\RUNDLL32.EXE NOTFOUND GetAttributes 400 1:38:04 PM Sysmecha Attributes C:\WINDOWS\RUNDLL32.EXE SUCCESS GetAttributes 401 1:38:04 PM Sysmecha Open C:\WINDOWS\RUNDLL32.EXE SUCCESS OPENEXISTING READONLY DENYWRITE 402 1:38:04 PM Sysmecha Read C:\WINDOWS\RUNDLL32.EXE SUCCESS Offset: 0 Length: 64 403 1:38:04 PM Sysmecha Seek C:\WINDOWS\RUNDLL32.EXE SUCCESS Beginning Offset: 128 / New offset: 128 404 1:38:04 PM Sysmecha Read C:\WINDOWS\RUNDLL32.EXE SUCCESS Offset: 128 Length: 248 405 1:38:04 PM Sysmecha Close C:\WINDOWS\RUNDLL32.EXE SUCCESS CLOSE_FINAL 406 1:38:04 PM Sysmecha Directory C:\WINDOWS SUCCESS CHECK 407 1:38:04 PM ??? Attributes C:\WINDOWS SUCCESS GetAttributes 408 1:38:04 PM ??? Attributes C:\WINDOWS\RUNDLL32.EXE SUCCESS GetAttributes 409 1:38:04 PM ??? Directory C:\WINDOWS\RUNDLL32.EXE SUCCESS QUERY 410 1:38:04 PM ??? Open C:\WINDOWS\RUNDLL32.EXE SUCCESS OPENEXISTING READONLY DENYWRITE 411 1:38:04 PM ??? Read C:\WINDOWS\RUNDLL32.EXE SUCCESS Offset: 0 Length: 64 412 1:38:04 PM ??? Seek C:\WINDOWS\RUNDLL32.EXE SUCCESS Beginning Offset: 128 / New offset: 128 413 1:38:04 PM ??? Read C:\WINDOWS\RUNDLL32.EXE SUCCESS Offset: 128 Length: 248 414 1:38:04 PM ??? Seek C:\WINDOWS\RUNDLL32.EXE SUCCESS Beginning Offset: 128 / New offset: 128 415 1:38:04 PM ??? Read C:\WINDOWS\RUNDLL32.EXE SUCCESS Offset: 128 Length: 448 416 1:38:04 PM ??? Directory C:\WINDOWS\RUNDLL32.EXE SUCCESS QUERY 417 1:38:04 PM ??? Read C:\WINDOWS\RUNDLL32.EXE SUCCESS Offset: 12288 Length: 1024 418 1:38:04 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 536576 Length: 4096 419 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 340992 Length: 4096 420 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 237568 Length: 4096 421 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 237568 Length: 4096 422 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 212992 Length: 4096 423 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 212992 Length: 4096 424 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 241664 Length: 1536 425 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 345088 Length: 4096 426 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 349184 Length: 4096 427 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 340992 Length: 4096 428 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 1024 Length: 4096 429 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 1024 Length: 4096 430 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 221184 Length: 4096 431 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 225280 Length: 4096 432 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 233472 Length: 4096 433 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 229376 Length: 4096 434 1:38:04 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 536576 Length: 4096 435 1:38:04 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 4096 Length: 4096 436 1:38:04 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 4096 Length: 4096 437 1:38:04 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 540672 Length: 4096 438 1:38:04 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 544768 Length: 4096 439 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 353280 Length: 4096 440 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 357376 Length: 4096 441 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 361472 Length: 1024 442 1:38:04 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 548864 Length: 1536 443 1:38:04 PM ??? Read C:\WINDOWS\RUNDLL32.EXE SUCCESS Offset: 12288 Length: 4096 444 1:38:04 PM Sysmecha Attributes C:\WINDOWS SUCCESS GetAttributes 445 1:38:04 PM Sysmecha Attributes C:\WINDOWS\TASKMON.EXE SUCCESS GetAttributes 446 1:38:04 PM Sysmecha Open C:\WINDOWS\TASKMON.EXE SUCCESS OPENEXISTING READONLY DENYWRITE 447 1:38:04 PM Sysmecha Read C:\WINDOWS\TASKMON.EXE SUCCESS Offset: 0 Length: 64 448 1:38:04 PM Sysmecha Seek C:\WINDOWS\TASKMON.EXE SUCCESS Beginning Offset: 128 / New offset: 128 449 1:38:04 PM Sysmecha Read C:\WINDOWS\TASKMON.EXE SUCCESS Offset: 128 Length: 248 450 1:38:04 PM Sysmecha Close C:\WINDOWS\TASKMON.EXE SUCCESS CLOSE_FINAL 451 1:38:04 PM Sysmecha Directory C:\WINDOWS SUCCESS CHECK 452 1:38:04 PM KERNEL32 Close C:\WINDOWS\RUNDLL32.EXE SUCCESS CLOSE_FINAL 453 1:38:04 PM ??? Attributes C:\WINDOWS SUCCESS GetAttributes 454 1:38:04 PM ??? Attributes C:\WINDOWS\TASKMON.EXE SUCCESS GetAttributes 455 1:38:04 PM ??? Directory C:\WINDOWS\TASKMON.EXE SUCCESS QUERY 456 1:38:04 PM ??? Open C:\WINDOWS\TASKMON.EXE SUCCESS OPENEXISTING READONLY DENYWRITE 457 1:38:04 PM ??? Read C:\WINDOWS\TASKMON.EXE SUCCESS Offset: 0 Length: 64 458 1:38:04 PM ??? Seek C:\WINDOWS\TASKMON.EXE SUCCESS Beginning Offset: 128 / New offset: 128 459 1:38:04 PM ??? Read C:\WINDOWS\TASKMON.EXE SUCCESS Offset: 128 Length: 248 460 1:38:04 PM ??? Seek C:\WINDOWS\TASKMON.EXE SUCCESS Beginning Offset: 128 / New offset: 128 461 1:38:04 PM ??? Read C:\WINDOWS\TASKMON.EXE SUCCESS Offset: 128 Length: 448 462 1:38:04 PM ??? Directory C:\WINDOWS\TASKMON.EXE SUCCESS QUERY 463 1:38:04 PM ??? Read C:\WINDOWS\TASKMON.EXE SUCCESS Offset: 16384 Length: 1536 464 1:38:04 PM ??? Read C:\WINDOWS\TASKMON.EXE SUCCESS Offset: 16384 Length: 4096 465 1:38:04 PM Sysmecha Attributes C:\WINDOWS SUCCESS GetAttributes 466 1:38:04 PM Sysmecha Attributes D:\UTILS\SYSMECH\RUNDLL32.EXE NOTFOUND GetAttributes 467 1:38:04 PM Sysmecha Attributes C:\WINDOWS\RUNDLL32.EXE SUCCESS GetAttributes 468 1:38:04 PM Sysmecha Open C:\WINDOWS\RUNDLL32.EXE SUCCESS OPENEXISTING READONLY DENYWRITE 469 1:38:04 PM Sysmecha Read C:\WINDOWS\RUNDLL32.EXE SUCCESS Offset: 0 Length: 64 470 1:38:04 PM Sysmecha Seek C:\WINDOWS\RUNDLL32.EXE SUCCESS Beginning Offset: 128 / New offset: 128 471 1:38:04 PM Sysmecha Read C:\WINDOWS\RUNDLL32.EXE SUCCESS Offset: 128 Length: 248 472 1:38:04 PM Sysmecha Close C:\WINDOWS\RUNDLL32.EXE SUCCESS CLOSE_FINAL 473 1:38:04 PM Sysmecha Directory C:\WINDOWS SUCCESS CHECK 474 1:38:04 PM KERNEL32 Close C:\WINDOWS\TASKMON.EXE SUCCESS CLOSE_FINAL 475 1:38:04 PM ??? Attributes C:\WINDOWS SUCCESS GetAttributes 476 1:38:04 PM ??? Attributes C:\WINDOWS\RUNDLL32.EXE SUCCESS GetAttributes 477 1:38:04 PM ??? Directory C:\WINDOWS\RUNDLL32.EXE SUCCESS QUERY 478 1:38:04 PM ??? Open C:\WINDOWS\RUNDLL32.EXE SUCCESS OPENEXISTING READONLY DENYWRITE 479 1:38:04 PM ??? Read C:\WINDOWS\RUNDLL32.EXE SUCCESS Offset: 0 Length: 64 480 1:38:04 PM ??? Seek C:\WINDOWS\RUNDLL32.EXE SUCCESS Beginning Offset: 128 / New offset: 128 481 1:38:04 PM ??? Read C:\WINDOWS\RUNDLL32.EXE SUCCESS Offset: 128 Length: 248 482 1:38:04 PM ??? Seek C:\WINDOWS\RUNDLL32.EXE SUCCESS Beginning Offset: 128 / New offset: 128 483 1:38:04 PM ??? Read C:\WINDOWS\RUNDLL32.EXE SUCCESS Offset: 128 Length: 448 484 1:38:04 PM ??? Directory C:\WINDOWS\RUNDLL32.EXE SUCCESS QUERY 485 1:38:04 PM ??? Read C:\WINDOWS\RUNDLL32.EXE SUCCESS Offset: 12288 Length: 1024 486 1:38:04 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 536576 Length: 4096 487 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 340992 Length: 4096 488 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 237568 Length: 4096 489 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 237568 Length: 4096 490 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 212992 Length: 4096 491 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 212992 Length: 4096 492 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 241664 Length: 1536 493 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 345088 Length: 4096 494 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 349184 Length: 4096 495 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 340992 Length: 4096 496 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 1024 Length: 4096 497 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 1024 Length: 4096 498 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 221184 Length: 4096 499 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 225280 Length: 4096 500 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 233472 Length: 4096 501 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\MSVCRT.DLL SUCCESS Offset: 229376 Length: 4096 502 1:38:04 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 536576 Length: 4096 503 1:38:04 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 4096 Length: 4096 504 1:38:04 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 4096 Length: 4096 505 1:38:04 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 540672 Length: 4096 506 1:38:04 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 544768 Length: 4096 507 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 353280 Length: 4096 508 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 357376 Length: 4096 509 1:38:04 PM ??? Read C:\WINDOWS\SYSTEM\SHLWAPI.DLL SUCCESS Offset: 361472 Length: 1024 510 1:38:04 PM ??? Read C:\WINDOWS\BCRYPT.VXD SUCCESS Offset: 548864 Length: 1536 511 1:38:04 PM ??? Read C:\WINDOWS\RUNDLL32.EXE SUCCESS Offset: 12288 Length: 4096 512 1:38:04 PM Sysmecha FindOpen D:\UTILS\SYSMECH\STARTUP\DISABLED\*.* NOTFOUND 513 1:38:04 PM Sysmecha FindOpen D:\UTILS\SYSMECH\STARTUP\ALL USERS\DISABLED\*.* NOTFOUND 514 1:38:04 PM KERNEL32 Close C:\WINDOWS\RUNDLL32.EXE SUCCESS CLOSE_FINAL 515 1:38:06 PM Fgouhhie Seek L:\IE\TEMPOR\CONTENT.IE5\INDEX.DAT SUCCESS Beginning Offset: 0 / New offset: 0 516 1:38:06 PM Fgouhhie Seek L:\IE\TEMPOR\CONTENT.IE5\INDEX.DAT SUCCESS End Offset: 0 / New offset: 0 517 1:38:06 PM Fgouhhie Seek L:\IE\TEMPOR\CONTENT.IE5\INDEX.DAT SUCCESS Beginning Offset: 0 / New offset: 0 518 1:38:11 PM Fgouhhie Seek L:\IE\TEMPOR\CONTENT.IE5\INDEX.DAT SUCCESS Beginning Offset: 0 / New offset: 0 519 1:38:11 PM Fgouhhie Seek L:\IE\TEMPOR\CONTENT.IE5\INDEX.DAT SUCCESS End Offset: 0 / New offset: 0 520 1:38:11 PM Fgouhhie Seek L:\IE\TEMPOR\CONTENT.IE5\INDEX.DAT SUCCESS Beginning Offset: 0 / New offset: 0 521 1:38:13 PM MSGSRV32 Attributes C:\WINDOWS\SYSTEM.DAT SUCCESS SetAttributes 522 1:38:13 PM MSGSRV32 Open C:\WINDOWS\SYSTEM.DAT SUCCESS OPENEXISTING WRITEONLY COMPATIBILITY 523 1:38:13 PM MSGSRV32 Write C:\WINDOWS\SYSTEM.DAT SUCCESS Offset: 0 Length: 32 524 1:38:13 PM MSGSRV32 Commit C:\WINDOWS\SYSTEM.DAT SUCCESS NOACCESSUPDATE 525 1:38:13 PM MSGSRV32 Seek C:\WINDOWS\SYSTEM.DAT SUCCESS Beginning Offset: 5345312 / New offset: 5345312 526 1:38:13 PM MSGSRV32 Write C:\WINDOWS\SYSTEM.DAT SUCCESS Offset: 5345312 Length: 61440 527 1:38:13 PM MSGSRV32 Commit C:\WINDOWS\SYSTEM.DAT SUCCESS NOACCESSUPDATE 528 1:38:13 PM MSGSRV32 Seek C:\WINDOWS\SYSTEM.DAT SUCCESS Beginning Offset: 0 / New offset: 0 529 1:38:13 PM MSGSRV32 Write C:\WINDOWS\SYSTEM.DAT SUCCESS Offset: 0 Length: 32 530 1:38:13 PM MSGSRV32 Close C:\WINDOWS\SYSTEM.DAT SUCCESS CLOSE_FINAL 531 1:38:13 PM MSGSRV32 Attributes C:\WINDOWS\SYSTEM.DAT SUCCESS SetAttributes