EricDSr
Topic Starter
Fake Anti Malware notices started to pop up today. Ran Malwarebytes which ditected a bunch of stuff and removed most and said would remove the rest on reboot. Now Google redirect has started. Thanks in advance for your help.
DDS Log:
DDS (Ver_09-06-26.01) - FAT32x86
Run by [removed] at 16:04:51.39 on Fri 03/25/2011
internet explorer: 7.0.5730.11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2801 [GMT -4:00]
AV: CA Anti-Virus *On-access scanning enabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-5.1.18.0\QOELoader.exe
C:\WINDOWS\system32\CAPM1RSK.EXE
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\Documents and Settings\Amy\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\CAPPActiveProtection.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\TrayDay\TrayDay.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Brother\Brmfcmon\BrMfimon.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM1SWK.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\LxrSII1s.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPCtlPriv.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Documents and Settings\Amy\Desktop\dds.scr.scr
============== Pseudo HJT Report ===============
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
NoUpdateCheck REG_DWORD 1 (0x1)
NoJITSetup REG_DWORD 1 (0x1)
Disable Script Debugger REG_SZ no
Show_ChannelBand REG_SZ No
Anchor Underline REG_SZ yes
Cache_Update_Frequency REG_SZ Once_Per_Session
Display Inline Images REG_SZ yes
Do404Search REG_BINARY 01000000
Save_Session_History_On_Exit REG_SZ no
Show_FullURL REG_SZ no
Show_StatusBar REG_SZ yes
Show_ToolBar REG_SZ yes
Show_URLinStatusBar REG_SZ yes
Show_URLToolBar REG_SZ yes
Start Page REG_SZ http://my.yahoo.com/index.html
Use_DlgBox_Colors REG_SZ yes
Use Search Asst REG_SZ no
Use Custom Search URL REG_BINARY 01000000
FullScreen REG_SZ no
Window_Placement REG_BINARY 2c0000000000000001000000ffffffffffffffffffffffffffffffff1d0000001d0000003c030000
75020000
Use FormSuggest REG_SZ yes
StatusBarOther REG_DWORD 1 (0x1)
NotifyDownloadComplete REG_SZ yes
FavChevron_Complete REG_SZ 3
FavChevron_Failed REG_SZ 2
FavChevron_Error REG_SZ 4
AddToFavoritesExpanded REG_DWORD 1 (0x1)
Use_Combobox_DlgBox_Colors_Complete REG_SZ 3
Use_Combobox_DlgBox_Colors_Failed REG_SZ 4
Use_Combobox_DlgBox_Colors_Error REG_SZ 4
FormSuggest PW Ask REG_SZ no
Save Directory REG_SZ c:\Documents and Settings\Amy\My Documents\Word\Miscellaneous\Amy Misc\Patternse\
Error Dlg Displayed On Every Error REG_SZ no
XMLHTTP REG_DWORD 1 (0x1)
UseClearType REG_SZ yes
Enable Browser Extensions REG_SZ yes
Play_Background_Sounds REG_SZ yes
Play_Animations REG_SZ yes
CompatibilityFlags REG_DWORD 0 (0x0)
SearchMigrated REG_DWORD 1 (0x1)
RunOnceHasShown REG_DWORD 1 (0x1)
RunOnceComplete REG_DWORD 1 (0x1)
AlwaysShowMenus REG_DWORD 1 (0x1)
HistoryViewType REG_BINARY 0000
Enable_MyPics_Hoverbar REG_SZ no
ShowedCheckBrowser REG_SZ Yes
Check_Associations REG_SZ yes
HKEY_CURRENT_USER\software\microsoft\internet explorer\main\Default Feeds
HKEY_CURRENT_USER\software\microsoft\internet explorer\main\FeatureControl
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main
Enable_Disk_Cache REG_SZ yes
Cache_Percent_of_Disk REG_BINARY 0a000000
Delete_Temp_Files_On_Exit REG_SZ yes
Anchor_Visitation_Horizon REG_BINARY 01000000
Use_Async_DNS REG_SZ yes
Placeholder_Width REG_BINARY 1a000000
Placeholder_Height REG_BINARY 1a000000
CompanyName REG_SZ Microsoft Corporation
Custom_Key REG_SZ MICROSO
Wizard_Version REG_SZ 6.0.2600.0000
FullScreen REG_SZ no
Default_Secondary_Page_URL REG_MULTI_SZ \0
Extensions Off Page REG_SZ about:NoAdd-ons
Security Risk Page REG_SZ about:SecurityRisk
Check_Associations REG_SZ yes
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main\ErrorThresholds
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main\FeatureControl
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main\UrlTemplate
uinternet connection wizard,shellnext = hxxp://www.dell4me.com/myway
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings
User Agent REG_SZ Mozilla/4.0 (compatible; MSIE 7.0; Win32)
IE5_UA_Backup_Flag REG_SZ 5.0
NoNetAutodial REG_DWORD 0 (0x0)
MigrateProxy REG_DWORD 1 (0x1)
EmailName REG_SZ IEUser@
AutoConfigProxy REG_SZ wininet.dll
MimeExclusionListForCache REG_SZ multipart/mixed multipart/x-mixed-replace multipart/x-byteranges
WarnOnPost REG_BINARY 01000000
UseSchannelDirectly REG_BINARY 01000000
EnableHttp1_1 REG_DWORD 1 (0x1)
PrivacyAdvanced REG_DWORD 0 (0x0)
EnableNegotiate REG_DWORD 1 (0x1)
ProxyEnable REG_DWORD 0 (0x0)
GlobalUserOffline REG_DWORD 0 (0x0)
EnableAutodial REG_DWORD 0 (0x0)
PrivDiscUiShown REG_DWORD 1 (0x1)
WarnOnZoneCrossing REG_DWORD 0 (0x0)
UrlEncoding REG_DWORD 0 (0x0)
SecureProtocols REG_DWORD 160 (0xa0)
DisableCachingOfSSLPages REG_DWORD 0 (0x0)
WarnonBadCertRecving REG_DWORD 1 (0x1)
WarnOnPostRedirect REG_DWORD 0 (0x0)
WarnOnHTTPSToHTTPRedirect REG_DWORD 1 (0x1)
WarnOnIntranet REG_DWORD 0 (0x0)
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\5.0
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Cache
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Connections
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Lockdown_Zones
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\P3P
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Passport
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Protocols
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\TemplatePolicies
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Url History
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\ZoneMap
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Zones
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
Error: Key: software\microsoft\internet explorer\search does not exist!
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\search
SteelWerX Registry Console Tool 2.0URLSearchHooks: H - No File
Written by Bobbi Flekman 2006 ©URLSearchHooks: H - No File
HKEY_CURRENT_USER\software\microsoft\internet explorer\urlsearchhooksURLSearchHooks: H - No File
SteelWerX Registry Console Tool 2.0URLSearchHooks: H - No File
Written by Bobbi Flekman 2006 ©URLSearchHooks: H - No File
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\urlsearchhooksURLSearchHooks: H - No File
SteelWerX Registry Console Tool 2.0URLSearchHooks: H - No File
Written by Bobbi Flekman 2006 ©URLSearchHooks: H - No File
HKEY_USERS\.default\software\microsoft\internet explorer\urlsearchhooksURLSearchHooks: H - No File
{4D25F926-B9FE-4682-BF72-8AB8210D6D75}URLSearchHooks: H - No File
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon
AutoRestartShell REG_DWORD 1 (0x1)
DefaultUserName REG_SZ Amy
LegalNoticeCaption REG_SZ
LegalNoticeText REG_SZ
PowerdownAfterShutdown REG_SZ 0
ReportBootOk REG_SZ 1
Shell REG_SZ Explorer.exe
ShutdownWithoutLogon REG_SZ 0
System REG_SZ
Userinit REG_SZ c:\WINDOWS\system32e\userinit.exe,
VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
SfcQuota REG_DWORD -1 (0xffffffff)
allocatecdroms REG_SZ 0
allocatedasd REG_SZ 0
allocatefloppies REG_SZ 0
cachedlogonscount REG_SZ 10
forceunlocklogon REG_DWORD 0 (0x0)
passwordexpirywarning REG_DWORD 14 (0xe)
scremoveoption REG_SZ 0
AllowMultipleTSSessions REG_DWORD 1 (0x1)
UIHost REG_EXPAND_SZ logonui.exe
LogonType REG_DWORD 1 (0x1)
Background REG_SZ 0 0 0
DefaultPassword REG_SZ
DebugServerCommand REG_SZ no
SFCDisable REG_DWORD 0 (0x0)
WinStationsDisabled REG_SZ 0
HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
ShowLogonOptions REG_DWORD 0 (0x0)
AltDefaultUserName REG_SZ Amy
AltDefaultDomainName REG_SZ IRWINA
DefaultDomainName REG_SZ IRWINA
ChangePasswordUseKerberos REG_DWORD 1 (0x1)
Taskman REG_SZ
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\GPExtensions
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\Notify
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\SpecialAccounts
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\Credentials
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\winlogon
ParseAutoexec REG_SZ 1
ExcludeProfileDirs REG_SZ Local Settings;Temporary Internet Files;History;Temp;Local Settings\Application Data\Microsoft\Outlook
BuildNumber REG_DWORD 2600 (0xa28)
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows
DebugOptions REG_SZ 2048
Documents REG_SZ
DosPrint REG_SZ no
NetMessage REG_SZ no
NullPort REG_SZ None
Programs REG_SZ com exe bat pif cmd
Run REG_SZ
Load REG_SZ
Device REG_SZ Brother MFC-7840W Printer,winspool,Ne06:
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - No File
BHO: NoExplorer - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3} - No File
BHO: - No File
BHO: NoExplorer - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{53707962-6F74-2D53-2644-206D7942484F} - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5CA3D70E-1895-11CF-8E15-001234567890} - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7} - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} - No File
BHO: NoExplorer - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C} - No File
BHO: - No File
BHO: NoExplorer - No File
urun: [updateMgr] c:\Program Files\Adobe\Acrobat 7.0\Readere\AdobeUpdateManager.exe AcRdB7_0_9
urun: [LxrAutorun] c:\Documents and Settings\Amy\Local Settings\Application Data\Lexar Mediae\LxrAutorun.exe
urun: [ctfmon.exe] c:\WINDOWS\system32e\ctfmon.exe
urun: [swg] "c:\Program Files\Google\GoogleToolbarNotifiere\GoogleToolbarNotifier.exe"
mrun: [SunJavaUpdateSched] "c:\Program Files\Common Files\Java\Java Updatee\jusched.exe"
mrun: [ATIPTA] c:\Program Files\ATI Technologies\ATI Control Panele\atiptaxx.exe
mrun: [IntelMeM] c:\Program Files\Intel\Modem Event Monitore\IntelMEM.exe
mrun: [DVDLauncher] "c:\Program Files\CyberLink\PowerDVDe\DVDLauncher.exe"
mrun: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Managere\sgtray.exe" /r
mrun: [dla] c:\WINDOWS\system32\dlae\tfswctrl.exe
mrun: [QuickTime Task] "c:\Program Files\QuickTimee\qttask.exe" -atboottime
mrun: [SSBkgdUpdate] "c:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdatee\SSBkgdupdate.exe" -Embedding -boot
mrun: [ControlCenter2.0] c:\Program Files\Brother\ControlCenter2e\brctrcen.exe /autorun
mrun: [TkBellExe] "c:\Program Files\Common Files\Real\Update_OBe\realsched.exe" -osboot
mrun: [CAVRID] "c:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antiviruse\CAVRID.exe"
mrun: [cctray] "c:\Program Files\CA\CA Internet Security Suite\cctraye\cctray.exe"
mrun: [PaperPort PTD] "c:\Program Files\ScanSoft\PaperPorte\pptd40nt.exe"
mrun: [IndexSearch] "c:\Program Files\ScanSoft\PaperPorte\IndexSearch.exe"
mrun: [PPort11reminder] "c:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Erege\Ereg.ini"
mrun: [BrMfcWnd] c:\Program Files\Brother\Brmfcmone\BrMfcWnd.exe /AUTORUN
mrun: [ControlCenter3] c:\Program Files\Brother\ControlCenter3e\brctrcen.exe /autorun
mrun: [Adobe Reader Speed Launcher] "c:\Program Files\Adobe\Reader 9.0\Readere\Reader_sl.exe"
mrun: [Adobe ARM] "c:\Program Files\Common Files\Adobe\ARM\1.0e\AdobeARM.exe"
mrun: [QOELOADER] "c:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-5.1.18.0e\QOELoader.exe"
mrun: [Memeo Instant Backup] c:\Program Files\Memeo\AutoBackupe\MemeoLauncher2.exe –silent –no_ui
mrun: [Seagate Dashboard] c:\Program Files\Seagate\Seagate Dashboarde\MemeoLauncher.exe –silent –no_ui
c:\DOCUME~1\Amy\STARTM~1\Programs\Startup\TrayDay.lnk - C:\Program Files\TrayDaye\TrayDay.exe
c:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\QUICKB~1.LNK - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdatee\qbupdate.exe
ie: SteelWerX Registry Console Tool 2.0
ie: Written by Bobbi Flekman 2006 ©
ie: HKEY_CURRENT_USER\software\microsoft\internet explorer\menuext
ie: HKEY_CURRENT_USER\software\microsoft\internet explorer\menuext\E&xport to Microsoft Excel
ie: REG_SZ res://c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE/3000
ie: Contexts REG_DWORD 1 (0x1)
ie: HKEY_CURRENT_USER\software\microsoft\internet explorer\menuext\Google Sidewiki…
ie: REG_SZ res://c:\Program Files\Google\Google Toolbar\Componente\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
ie: Contexts REG_DWORD 19 (0x13)
ie: {SteelWerX Registry Console Tool 2.0
ie: {Written by Bobbi Flekman 2006 ©
ie: {HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions
ie: {HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{92780B25-18CC-41C8-B9BE-3C9C571A8263}
ie: { ButtonText - REG_SZ Research
ie: { Icon - REG_SZ c:\PROGRA~1\MICROS~2\OFFICE11e\REFBAR.ICO
ie: { Default Visible - REG_SZ Yes
ie: { HotIcon - REG_SZ c:\PROGRA~1\MICROS~2\OFFICE11e\REFBARH.ICO
ie: {HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
ie: { ButtonText - REG_SZ Real.com
ie: { HotIcon - REG_SZ c:\Program Files\Real\RealPlayere\eb_act.ico
ie: { Icon - REG_SZ c:\Program Files\Real\RealPlayere\eb_inact.ico
ie: { ToolTip - REG_SZ Real.com Explorer Bar
ie: { Default Visible - REG_SZ Yes
ie: {HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{e2e2dd38-d088-4134-82b7-f2ba38496583}
ie: { MenuText - REG_SZ @xpsp3res.dll,-20001
ie: { Exec - REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe
ie: {HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}
ie: { ButtonText - REG_SZ Messenger
ie: { Default Visible - REG_SZ Yes
ie: { Exec - REG_SZ c:\Program Files\Messengere\msmsgs.exe
ie: { HotIcon - REG_SZ c:\Program Files\Messengere\msmsgs.exe,302
ie: { Icon - REG_SZ c:\Program Files\Messengere\msmsgs.exe,301
ie: { MenuText - REG_SZ Windows Messenger
ie: { ToolTip - REG_SZ Windows Messenger
IE: { BandCLSID - REG_SZ {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - {ff059e31-cc5a-4e2e-bf3b-96e929d65503}\inprocserver32 does not exist!
IE: { CLSID - REG_SZ {E0DD6CAB-2D10-11D2-8F1A-0000F87ABD16} - {e0dd6cab-2d10-11d2-8f1a-0000f87abd16}\inprocserver32 does not exist!
IE: { CLSID - REG_SZ {E0DD6CAB-2D10-11D2-8F1A-0000F87ABD16} - {e0dd6cab-2d10-11d2-8f1a-0000f87abd16}\inprocserver32 does not exist!
IE: { BandCLSID - REG_SZ {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - {fe54fa40-d68c-11d2-98fa-00c0f0318afe}\inprocserver32 does not exist!
IE: { CLSID - REG_SZ {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} - {1fba04ee-3024-11d2-8f1f-0000f87abd16}\inprocserver32 does not exist!
IE: { CLSID - REG_SZ {1FBA04EE-3024-11D2-8F1F-0000F87ABD16} - {1fba04ee-3024-11d2-8f1f-0000f87abd16}\inprocserver32 does not exist!
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01010E00-5E80-11D8-9E86-0007E96C65AE}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01010E00-5E80-11D8-9E86-0007E96C65AE}\Contains
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01010E00-5E80-11D8-9E86-0007E96C65AE}\Contains\Files
c:\WINDOWS\Downloaded Program Filese\sdclicense.txt REG_SZ
c:\WINDOWS\Downloaded Program Filese\tgctlsi.dll REG_SZ
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01010E00-5E80-11D8-9E86-0007E96C65AE}\DownloadInformation
CODEBASE REG_SZ http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\tgctlsi.inf
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01010E00-5E80-11D8-9E86-0007E96C65AE}\InstalledVersion
REG_SZ 6,9,545,0
LastModified REG_SZ Tue, 21 Jun 2005 06:01:07 GMT
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01012101-5E80-11D8-9E86-0007E96C65AE}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01012101-5E80-11D8-9E86-0007E96C65AE}\Contains
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01012101-5E80-11D8-9E86-0007E96C65AE}\Contains\Files
c:\WINDOWS\Downloaded Program Filese\tgctlsr.dll REG_SZ
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01012101-5E80-11D8-9E86-0007E96C65AE}\DownloadInformation
CODEBASE REG_SZ http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\tgctlsr.inf
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01012101-5E80-11D8-9E86-0007E96C65AE}\InstalledVersion
REG_SZ 6,9,545,0
LastModified REG_SZ Tue, 21 Jun 2005 06:01:28 GMT
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{17492023-C23A-453E-A040-C7C580BBF700}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{17492023-C23A-453E-A040-C7C580BBF700}\Contains
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{17492023-C23A-453E-A040-C7C580BBF700}\Contains\Files
c:\WINDOWS\system32e\GWFSPidGen.DLL REG_SZ
c:\WINDOWS\system32e\LegitCheckControl.DLL REG_SZ
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{17492023-C23A-453E-A040-C7C580BBF700}\DownloadInformation
CODEBASE REG_SZ http://go.microsoft.com/fwlink/?linkid=39204
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\LegitCheckControl.inf
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{17492023-C23A-453E-A040-C7C580BBF700}\InstalledVersion
REG_SZ 1,4,389,0
LastModified REG_SZ Sat, 05 Nov 2005 00:53:56 GMT
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}\Contains
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}\Contains\Files
c:\WINDOWSe\opuc.dll REG_SZ
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}\DownloadInformation
CODEBASE REG_SZ http://office.microsoft.com/officeupdate/content/opuc.cab
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\opuc.inf
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}\InstalledVersion
REG_SZ 11,0,5626,0
LastModified REG_SZ Fri, 29 Aug 2003 19:59:02 GMT
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}\Contains
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}\Contains\Files
c:\WINDOWS\system32e\muweb.dll REG_SZ
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}\DownloadInformation
CODEBASE REG_SZ http://update.microsoft.com/microsoftupdat…b?1136553665781
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\muweb.inf
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}\InstalledVersion
REG_SZ 5,8,0,2469
LastModified REG_SZ Thu, 26 May 2005 11:40:19 GMT
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
REG_SZ Java Runtime Environment 1.6.0
Installer REG_SZ MSICD
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\Contains
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\DownloadInformation
CODEBASE REG_SZ http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
INF REG_SZ
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\InstalledVersion
REG_SZ 1.6.0.21
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{A762E064-A885-40E4-AC10-671BB62DC2B2}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{A762E064-A885-40E4-AC10-671BB62DC2B2}\Contains
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{A762E064-A885-40E4-AC10-671BB62DC2B2}\Contains\Files
c:\WINDOWS\system32e\OFMailX.dll REG_SZ
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{A762E064-A885-40E4-AC10-671BB62DC2B2}\DownloadInformation
CODEBASE REG_SZ http://www.eomniform.com/OF5/nsplugins/OFMailX.cab
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\OFMailX.inf
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{A762E064-A885-40E4-AC10-671BB62DC2B2}\InstalledVersion
REG_SZ 5,0,1,0
LastModified REG_SZ Sat, 19 Jan 2002 01:33:55 GMT
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
REG_SZ Java Runtime Environment 1.6.0
Installer REG_SZ MSICD
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\Contains
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\DownloadInformation
CODEBASE REG_SZ http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
INF REG_SZ
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\InstalledVersion
REG_SZ 1.6.0.21
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
REG_SZ Java Runtime Environment 1.6.0
Installer REG_SZ MSICD
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\Contains
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\DownloadInformation
CODEBASE REG_SZ http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
INF REG_SZ
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\InstalledVersion
REG_SZ 1.6.0.21
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CE28D5D2-60CF-4C7D-9FE8-0F47A3308078}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CE28D5D2-60CF-4C7D-9FE8-0F47A3308078}\Contains
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CE28D5D2-60CF-4C7D-9FE8-0F47A3308078}\Contains\Files
c:\WINDOWS\Downloaded Program Filese\SymAData.dll REG_SZ
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CE28D5D2-60CF-4C7D-9FE8-0F47A3308078}\DownloadInformation
CODEBASE REG_SZ http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CE28D5D2-60CF-4C7D-9FE8-0F47A3308078}\InstalledVersion
REG_SZ 2,6,0,0
LastModified REG_SZ Mon, 14 Nov 2005 22:15:51 GMT
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{DE22A7AB-A739-4C58-AD52-21F9CD6306B7}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{DE22A7AB-A739-4C58-AD52-21F9CD6306B7}\Contains
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{DE22A7AB-A739-4C58-AD52-21F9CD6306B7}\Contains\Files
c:\WINDOWS\Downloaded Program Filese\clearadjust.dll REG_SZ
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{DE22A7AB-A739-4C58-AD52-21F9CD6306B7}\DownloadInformation
CODEBASE REG_SZ http://download.microsoft.com/download/7/E…04/clearadj.cab
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\clearadj.inf
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{DE22A7AB-A739-4C58-AD52-21F9CD6306B7}\InstalledVersion
REG_SZ 1,0,0,4
LastModified REG_SZ Wed, 30 Apr 2003 01:12:15 GMT
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\Contains
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\Contains\Files
c:\WINDOWS\SYSTEM32e\atl.dll REG_SZ
c:\WINDOWS\Downloaded Program Filese\gp.ocx REG_SZ
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\DownloadInformation
CODEBASE REG_SZ http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\gp.inf
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\InstalledVersion
REG_SZ 1,6,2,91
LastModified REG_SZ Wed, 01 Sep 2010 22:53:46 GMT
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
Error: Value: "NameServer" does not exist!
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
d; /.* /!d; s//securityproviders: /
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
d;/^((authentication|notification) packages) .* /i!d; s//lsa: 1 = /
Authentication Packages REG_MULTI_SZ msv1_0
Bounds REG_BINARY 0030000000200000
d;/^((authentication|notification) packages) .* /i!d; s//lsa: 1 = /
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest
ImpersonatePrivilegeUpgradeToolHasRun REG_DWORD 1 (0x1)
LsaPid REG_DWORD 1816 (0x718)
SecureBoot REG_DWORD 1 (0x1)
auditbaseobjects REG_DWORD 0 (0x0)
crashonauditfail REG_DWORD 0 (0x0)
disabledomaincreds REG_DWORD 0 (0x0)
everyoneincludesanonymous REG_DWORD 0 (0x0)
fipsalgorithmpolicy REG_DWORD 0 (0x0)
forceguest REG_DWORD 1 (0x1)
fullprivilegeauditing REG_BINARY 00
limitblankpassworduse REG_DWORD 1 (0x1)
lmcompatibilitylevel REG_DWORD 0 (0x0)
nodefaultadminowner REG_DWORD 1 (0x1)
nolmhash REG_DWORD 0 (0x0)
restrictanonymous REG_DWORD 0 (0x0)
restrictanonymoussam REG_DWORD 1 (0x1)
d;/^((authentication|notification) packages) .* /i!d; s//lsa: 1 = /
Notification Packages REG_MULTI_SZ scecli
enabledcom REG_SZ y
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\AccessProviders
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\Audit
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\Data
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\GBG
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\JD
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\Kerberos
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\MSV1_0
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\Skew1
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\SSO
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\SspiCache
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager\subsystems
windows REG_EXPAND_SZ %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
============= SERVICES / DRIVERS ===============
R0 xmasbus;xmasbus;c:\WINDOWS\SYSTEM32\DRIVERSe\xmasbus.sys [2005-2-4 140800]
R0 xmasscsi;xmasscsi;c:\WINDOWS\SYSTEM32\DRIVERSe\xmasscsi.sys [2005-2-4 5504]
R1 VET-FILT;VET File System Filter;c:\WINDOWS\SYSTEM32\DRIVERSe\vet-filt.sys [2008-6-4 26352]
R1 VET-REC;VET File System Recognizer;c:\WINDOWS\SYSTEM32\DRIVERSe\vet-rec.sys [2008-6-4 21104]
R1 VETEFILE;VET File Scan Engine;c:\WINDOWS\SYSTEM32\DRIVERSe\vetefile.sys [2010-6-3 746216]
R1 VETFDDNT;VET Floppy Boot Sector Monitor;c:\WINDOWS\SYSTEM32\DRIVERSe\vetfddnt.sys [2008-6-4 21488]
R1 VETMONNT;VET File Monitor;c:\WINDOWS\SYSTEM32\DRIVERSe\vetmonnt.sys [2008-6-4 32240]
R2 CAISafe;CAISafe;c:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antiviruse\isafe.exe [2008-6-4 144960]
R2 LxrSII1d;Secure II Driver;c:\WINDOWS\SYSTEM32\DRIVERSe\LxrSII1d.sys [2008-5-13 72672]
R2 MemeoBackgroundService;MemeoBackgroundService;c:\Program Files\Memeo\AutoBackupe\MemeoBackgroundService.exe [2010-12-10 25824]
R2 RapidPortM1;RapidPortM1;c:\WINDOWS\SYSTEM32\DRIVERSe\CAPM1LP.SYS [2005-2-23 22912]
R2 SeagateDashboardService;Seagate Dashboard Service;c:\Program Files\Seagate\Seagate Dashboarde\SeagateDashboardService.exe [2010-12-14 14088]
R2 VETMSGNT;VET Message Service;c:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antiviruse\vetmsg.exe [2008-6-4 238928]
R3 PPCtlPriv;PPCtlPriv;c:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrole\PPCtlPriv.exe [2007-8-16 189704]
R3 VETEBOOT;VET Boot Scan Engine;c:\WINDOWS\SYSTEM32\DRIVERSe\veteboot.sys [2010-6-3 130280]
============== File Associations ===============
::RecordNow.GI="c:\Program Files\Sonic\RecordNow!e\RecordNow.exe" "%1"
::RecordNow.ISO="c:\Program Files\Sonic\RecordNow!e\RecordNow.exe" "%1"
::RecordNow.PXJ="c:\Program Files\Sonic\RecordNow!e\RecordNow.exe" "%1"
acrobat="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" /u "%1"
AcroExch.acrobatsecuritysettings.1="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" "%1"
AcroExch.Document="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" "%1"
AcroExch.Document.7="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" "%1"
AcroExch.FDFDoc="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" "%1"
AcroExch.pdfxml.1="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" "%1"
AcroExch.XDPDoc="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" "%1"
AcroExch.XFDFDoc="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" "%1"
acwfile=%SystemRoot%\system32\accwiz.exe %1
AIFFFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
AIR.InstallerPackage=c:\PROGRA~1\COMMON~1\ADOBEA~1\Versions\1.0e\ADOBEA~1.EXE "%1"
AnimationShop3.Animation="c:\Program Files\Jasc Software Inc\Animation Shop 3e\Anim.exe" /dde
AnimationShop3.WorkSpaceFile="c:\Program Files\Jasc Software Inc\Animation Shop 3e\Anim.exe" "/Workspace" "%1"
Application.Manifest=rundll32.exe dfshim.dll,ShOpenVerbApplication %1
Application.Reference=rundll32.exe dfshim.dll,ShOpenVerbShortcut %1|%2
ASFFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /prefetch:7 /Open "%L"
ASXFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
AUFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
AVIFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /prefetch:8 /Open "%L"
A_auto_file=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
!d
Briefcase=explorer.exe %1
callto=rundll32.exe msconf.dll,CallToProtocolHandler %l
CATFile=rundll32.exe cryptext.dll,CryptExtOpenCAT %1
cdafile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
CERFile=rundll32.exe cryptext.dll,CryptExtOpenCER %1
CertificateStoreFile=rundll32.exe cryptext.dll,CryptExtOpenSTR %1
certificate_wab_auto_file="c:\Program Files\Outlook Expresse\wab.exe" /certificate %1
cfxxefile="%1" %*
!d
clpfile=clipbrd.exe %1
!d
!d
CompressedFolder=rundll32.exe zipfldr.dll,RouteTheCall %L
ConferenceLink=rundll32.exe msconf.dll,OpenConfLink %l
Coverpage=%systemroot%\system32\fxscover.exe "%1"
CRLFile=rundll32.exe cryptext.dll,CryptExtOpenCRL %1
DBC.MPEG.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
desFile=c:\PROGRA~1\Intuit\QUICKB~1e\qbw32.exe "%1"
DocShortcut=rundll32 %SystemRoot%\System32\shscrap.dll,OpenScrap_RunDLL /r /x %1
dqyfile=c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE
dunfile=%SystemRoot%\system32\RUNDLL32.EXE NETSHELL.DLL,InvokeDunFile %1
emffile=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
Eudora.Mailbox=c:\PROGRA~1\Qualcomm\Eudorae\Eudora.exe "%1"
Eudora.Stationery=c:\PROGRA~1\Qualcomm\Eudorae\Eudora.exe "%1"
Excel.Addin="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.Backup="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.Chart=c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE /e
Excel.Chart.8="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.CSV="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.DIF="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.Macrosheet="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.Sheet.12="c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE" /e
Excel.Sheet.8="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.SheetBinaryMacroEnabled.12="c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE" /e
Excel.SheetMacroEnabled.12="c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE" /e
Excel.SLK="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.Template="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.Workspace="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.XLL="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excelhtmlfile="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE"
Excelhtmltemplate="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE"
!d
fndfile=%SystemRoot%\Explorer.exe
Folder=%SystemRoot%\Explorer.exe /idlist,%I,%L
fonfile=%SystemRoot%\System32\fontview.exe %1
ftp="c:\Program Files\Internet Explorere\IEXPLORE.EXE" %1
giffile=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
gopher="c:\Program Files\Internet Explorere\iexplore.exe" -nohome
h323file="rundll32.exe" msconf.dll,NewMediaPhone %l
HCP=%SystemRoot%\PCHEALTH\HELPCTR\Binaries\HelpCtr.exe -FromHCP -url "%1"
helpfile=winhlp32.exe %1
hlpfile=%SystemRoot%\System32\winhlp32.exe %1
holfile="c:\PROGRA~1\MICROS~2\OFFICE11e\OUTLOOK.EXE" /hol "%1"
htafile=c:\WINDOWS\system32e\mshta.exe "%1" %*
htfile="c:\Program Files\Windows NTe\HYPERTRM.EXE" %1
htmlfile="c:\Program Files\Internet Explorere\IEXPLORE.EXE" -nohome
HTTP="c:\Program Files\Internet Explorere\IEXPLORE.EXE" -nohome
https="c:\Program Files\Internet Explorere\IEXPLORE.EXE" -nohome
icsfile="c:\PROGRA~1\MICROS~2\OFFICE11e\OUTLOOK.EXE" /ical "%1"
ICY=c:\Program Files\Winampe\winamp.exe %1
iiifile="rundll32.exe" msconf.dll,NewMediaPhone %l
!d
!d
InternetShortcut=rundll32.exe ieframe.dll,OpenURL %l
iqyfile=c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE /e
ITS FILE="c:\Program Files\Internet Explorere\iexplore.exe" -nohome
jarfile="c:\Program Files\Java\jre6\bine\javaw.exe" -jar "%1" %*
JascPaintShopPhotoAlbumAlbum=c:\PROGRA~1\JASCSO~1\PAINTS~1e\pspa.exe "%1"
JascPaintShopPhotoAlbumAudio=c:\PROGRA~1\JASCSO~1\PAINTS~1e\pspa.exe "%1"
JascPaintShopPhotoAlbumImage=c:\PROGRA~1\JASCSO~1\PAINTS~1e\pspa.exe "%1"
JascPaintShopPhotoAlbumUploadAlbum=c:\PROGRA~1\JASCSO~1\PAINTS~1e\pspa.exe "%1"
JNLPFile="c:\Program Files\Java\jre6\bine\javaws.exe" "%1"
jpegfile=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
JSFile=%SystemRoot%\System32\WScript.exe "%1" %*
LDAP="c:\Program Files\Outlook Expresse\wab.exe" /ldap:%1
LiveUpdate.MIDI.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
m3ufile="c:\Program Files\Windows Media Playere\wmplayer.exe" /prefetch:6 /Open "%L"
MacromediaFlashPaper.MacromediaFlashPaper="c:\Program Files\Internet Explorere\IEXPLORE.EXE" -nohome "%1"
mailto=c:\PROGRA~1\Qualcomm\Eudorae\Eudora.exe /m %1
MediaPackageFile="c:\Program Files\Microsoft Office\OFFICE11e\MSTORE.EXE" "%1"
mhtmlfile="c:\Program Files\Internet Explorere\IEXPLORE.EXE" -nohome
Microsoft Internet Mail Message="%ProgramFiles%\Outlook Express\msimn.exe" /eml:%1
Microsoft Internet News Message="%ProgramFiles%\Outlook Express\msimn.exe" /nws:%1
Microsoft.InformationCard=c:\WINDOWS\system32\rundll32.exe c:\WINDOWS\system32e\infocardcpl.cpl,ImportInformationCard_RunDll %1
Microsoft.WindowsCardSpaceBackup=c:\WINDOWS\system32\rundll32.exe c:\WINDOWS\system32e\infocardcpl.cpl,ImportInformationCard_RunDll %1
MIDFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
MITrain.Document=c:\WINDOWS\Help\SBSI\Traininge\ORUN32.EXE -f "%1"
MMJB.AUDIOCD="c:\Program Files\Musicmatch\Musicmatch Jukeboxe\mmjblaunch.exe" /AudioCD "%1"
MMJB.BPP="c:\Program Files\Musicmatch\Musicmatch Jukeboxe\mmfwlaunch.exe" "%1"
MMJB.MMJB="c:\Program Files\Musicmatch\Musicmatch Jukeboxe\mmjblaunch.exe" "%1"
MMJB.MMO="c:\Program Files\Musicmatch\Musicmatch Jukeboxe\mmjblaunch.exe" "%1"
MMJB.MMZ="c:\Program Files\Musicmatch\Musicmatch Jukeboxe\mmjblaunch.exe" "%1"
MMS="c:\Program Files\Windows Media Playere\wmplayer.exe" "%L"
MMST="c:\Program Files\Windows Media Playere\wmplayer.exe" "%L"
MMSU="c:\Program Files\Windows Media Playere\wmplayer.exe" "%L"
mp3file="c:\Program Files\Windows Media Playere\wmplayer.exe" /prefetch:6 /Open "%L"
mpegfile="c:\Program Files\Windows Media Playere\wmplayer.exe" /prefetch:9 /Open "%L"
MPlayer=mplay32.exe /play /close "%L"
MS-ITSS FILE="c:\Program Files\Internet Explorere\iexplore.exe" -nohome ms-itss:%1::/
msbackupfile=%SystemRoot%\system32\ntbackup.exe
MSBD="c:\Program Files\Windows Media Playere\wmplayer.exe" "%L"
MSCFile=%SystemRoot%\system32\mmc.exe "%1" %*
MSDASC=Rundll32.exe c:\PROGRA~1\COMMON~1\System\OLEDB~1e\oledb32.dll,OpenDSLFile %1
msgfile="c:\Program Files\Microsoft Office\OFFICE11e\OUTLOOK.EXE" /f "%1"
Msi.Package="%SystemRoot%\System32\msiexec.exe" /i "%1" %*
Msi.Patch="%SystemRoot%\System32\msiexec.exe" /p "%1" %*
MSInfo.Document=c:\Program Files\Common Files\Microsoft Shared\MSInfoe\MSInfo32.exe /msinfo_file %1
MSPaper.Document="c:\Program Files\Common Files\Microsoft Shared\MODI\11.0e\MSPVIEW.EXE" "%1"
MSProgramGroup=c:\WINDOWS\system32e\grpconv.exe %1
MsRcIncident=%SystemRoot%\PCHealth\HelpCtr\Binaries\HelpCtr.exe -Mode "hcp://system/Remote%%20Assistance/RAClientLayout.xml" -url "hcp://system/Remote%%20Assistance/Interaction/Client/rctoolScreen1.htm" -ExtraArgument "IncidentFile=%1"
msstylesfile=%SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,Control_RunDLL %SystemRoot%\system32\desk.cpl desk,@Appearance /Action:OpenMSTheme /file:"%1"
news="%ProgramFiles%\Outlook Express\msimn.exe" /newsurl:"%1"
nntp="%ProgramFiles%\Outlook Express\msimn.exe" /newsurl:"%1"
Office.Binder="c:\PROGRA~1\MICROS~2\OFFICE11e\UNBIND.EXE" "%1"
Office.Binder.8="c:\PROGRA~1\MICROS~2\OFFICE11e\UNBIND.EXE" "%1"
Office.Binder.9="c:\Program Files\Microsoft Office\OFFICE11e\UNBIND.EXE" "%1"
Office.Binder.95="c:\PROGRA~1\MICROS~2\OFFICE11e\UNBIND.EXE" "%1"
Office.Binder.Template.9="c:\Program Files\Microsoft Office\OFFICE11e\UNBIND.EXE" "%1"
Office.Binder.Wizard.9="c:\Program Files\Microsoft Office\OFFICE11e\UNBIND.EXE" "%1"
OfficeBinder.Binder="c:\PROGRA~1\MICROS~2\OFFICE11e\UNBIND.EXE" "%1"
OfficeBinder.Binder.8="c:\PROGRA~1\MICROS~2\OFFICE11e\UNBIND.EXE" "%1"
OfficeBinder.Binder.9="c:\PROGRA~1\MICROS~2\OFFICE11e\UNBIND.EXE" "%1"
Oice.Excel.Addin=c:\PROGRA~1\MICROS~2\Office12e\Oice.exe "%1"
Oice.Excel.Sheet=c:\PROGRA~1\MICROS~2\Office12e\Oice.exe "%1"
Oice.Excel.Template=c:\PROGRA~1\MICROS~2\Office12e\Oice.exe "%1"
Oice.PowerPoint.Show=c:\PROGRA~1\MICROS~2\Office12e\Oice.exe "%1"
Oice.PowerPoint.SlideShow=c:\PROGRA~1\MICROS~2\Office12e\Oice.exe "%1"
Oice.PowerPoint.Template=c:\PROGRA~1\MICROS~2\Office12e\Oice.exe "%1"
Oice.Word.Document=c:\PROGRA~1\MICROS~2\Office12e\Oice.exe "%1"
oqyfile=c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE
ossfile="c:\Program Files\Microsoft Office\OFFICE11e\FINDER.EXE" /f "%1"
otffile=%SystemRoot%\System32\fontview.exe %1
outlook="c:\PROGRA~1\MICROS~2\OFFICE11e\OUTLOOK.EXE" /select "%1"
Outlook.NavigatorBarFile="c:\PROGRA~1\MICROS~2\OFFICE11e\OUTLOOK.EXE" /s "%1"
Outlook.Template="c:\Program Files\Microsoft Office\OFFICE11e\OUTLOOK.EXE" /t "%1"
P7RFile=rundll32.exe cryptext.dll,CryptExtOpenP7R %1
P7SFile=rundll32.exe cryptext.dll,CryptExtOpenPKCS7 %1
Paint.Picture=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
PaintShopPro8.BrowserCacheFile="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" "/Browse" "%1"
PaintShopPro8.Frame="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" /dde
PaintShopPro8.Image="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" /dde
PaintShopPro8.Mask="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" /dde
PaintShopPro8.PictureTube="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" /dde
PaintShopPro8.Script="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" "/Script" "%1"
PaintShopPro8.Shape="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" /dde
PaintShopPro8.WorkspaceFile="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" "/Workspace" "%1"
Panorama=c:\PROGRA~1\JASCSO~1\PAINTS~1e\pspa.exe "%1"
Paper.Document=c:\Program Files\ScanSoft\PaperPorte\PPPAGEVW.EXE "%1"
PaperPort.AutoplayHandler=c:\Program Files\ScanSoft\PaperPorte\PaprPort.exe /folder %L
pbkfile=%SystemRoot%\system32\rasphone.exe -f "%1"
PerfFile=%SystemRoot%\system32\perfmon.exe %1
pfmfile=%SystemRoot%\System32\fontview.exe %1
!d
pjpegfile=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
pngfile=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
pnm="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
PowerPoint.Show.12=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.Show.8=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.ShowMacroEnabled.12=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.SlideShow.12=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.SlideShow.8=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.SlideShowMacroEnabled.12=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.Template.12=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.Template.8=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.TemplateMacroEnabled.12=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
ppifile=%SystemRoot%\System32\msppcnfg.exe /Config %1
prffile="c:\Program Files\Microsoft Office\OFFICE11e\OUTLOOK.EXE" /PromptImportPRF "%1"
Publishing Folder=explorer.exe /idlist,%I,%L
qbofile=c:\Program Files\Intuit\QuickBooks Basice\qbw32.exe -X "%1"
qbwFile=c:\PROGRA~1\COMMON~1\Intuit\QUICKB~1e\qblaunch.exe "%1"
QuickTime.aif=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.aifc=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.aiff=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.cdda=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.dif=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.dv=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.mov=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.qt=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.qtl=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.qup=c:\PROGRA~1\QUICKT~1e\QuickTimeUpdater.exe "%1"
QuickTime.sd2=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
ratfile=rundll32.exe msrating.dll,ClickedOnRAT %1
RealJukebox.CDA.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealJukebox.RJS.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealJukebox.RJT.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealJukebox.RMJ.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealJukebox.RMP.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealJukebox.RMX.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealJukebox.wma.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.3GPP2.10="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.3GPP_AMR.10="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.AIFF.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.AMR.10="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.AMR_WB.10="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.AU.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.AutoPlay.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" /autoplay "%1"
RealPlayer.AVI.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.CDBurn.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" /burn "%1"
RealPlayer.DIVX.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.Flash.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" /m image/vnd.rn-realflash %1
RealPlayer.M4A.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MP1.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MP2.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MP3.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MP3PL.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MP4.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MPA.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MPEG.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MPGA.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.PIX.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.PLSPL.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.qt.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RA.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RAM.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RAX.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RM.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RMS.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RMVB.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RP.6="c:\Program Files\Common Files\Real\Update_OBe\rnxproc.exe" "%1"
RealPlayer.RSML.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RT.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RV.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RVX.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.SDP.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.SMIL.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.WAV.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.wax.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.wm.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.wmv.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.wmx.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.wvx.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
!d
!d
rlogin=rundll32.exe url.dll,TelnetProtocolHandler %l
rqyfile=c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE
rtffile="c:\Program Files\Windows NT\Accessoriese\WORDPAD.EXE" "%1"
rtsp="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
SavedDsQuery=rundll32 %SystemRoot%\system32\dsquery.dll,OpenSavedDsQuery %1
SC=c:\Program Files\Winampe\winamp.exe %1
SchedulePlus.Application.7="c:\Program Files\Microsoft Office\OFFICE11\1033e\SCHDPL32.EXE" '%1'
!d
scriptletfile="c:\WINDOWSe\NOTEPAD.EXE" "%1"
SHCmdFile=explorer.exe
Shell=%SystemRoot%\Explorer.exe /idlist,%I,%L
ShellScrap=rundll32 %SystemRoot%\system32\shscrap.dll,OpenScrap_RunDLL %1
SHOUT=c:\Program Files\Winampe\winamp.exe %1
SldSrtr.Document=c:\PROGRA~1\COMMON~1\MICROS~1\MODI\11.0e\MSPVIEW.EXE "%1"
snews="%ProgramFiles%\Outlook Express\msimn.exe" /newsurl:"%1"
SoundRec="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
SPCFile=rundll32.exe cryptext.dll,CryptExtOpenPKCS7 %1
SpybotSD.DisabledFile="c:\Program Files\Spybot - Search & Destroye\blindman.exe" "%1"
SpybotSD.SBEFile="c:\Program Files\Spybot - Search & Destroye\SpybotSD.exe" "%1"
SpybotSD.SBIFile="c:\Program Files\Spybot - Search & Destroye\SpybotSD.exe" "%1"
SpybotSD.SBSFile="c:\Program Files\Spybot - Search & Destroye\SpybotSD.exe" "%1"
SpybotSD.TInfoFile="c:\Program Files\Spybot - Search & Destroye\SpybotSD.exe" "%1"
SpybotSD.UTIFile="c:\Program Files\Spybot - Search & Destroye\SpybotSD.exe" "%1"
SpybotSD.UTSFile="c:\Program Files\Spybot - Search & Destroye\SpybotSD.exe" "%1"
SSM="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
STLFile=rundll32.exe cryptext.dll,CryptExtOpenCTL %1
stssync="c:\PROGRA~1\MICROS~2\OFFICE11e\OUTLOOK.EXE" /stssync "%1"
T126_Whiteboard="c:\Program Files\NetMeetinge\wb32.exe" - "%1"
telnet=rundll32.exe url.dll,TelnetProtocolHandler %l
themefile=%SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,Control_RunDLL %SystemRoot%\system32\desk.cpl desk,@Themes /Action:OpenTheme /file:"%1"
TIFImage.Document=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
tn3270=rundll32.exe url.dll,TelnetProtocolHandler %l
ttcfile=%SystemRoot%\System32\fontview.exe %1
ttffile=%SystemRoot%\System32\fontview.exe %1
!d
ulsfile="rundll32.exe" msconf.dll,NewMediaPhone %l
UVOX=c:\Program Files\Winampe\winamp.exe %1
vcard_wab_auto_file="c:\Program Files\Outlook Expresse\wab.exe" /vcard %1
vcffile="c:\PROGRA~1\MICROS~2\OFFICE11e\OUTLOOK.EXE" /v "%1"
vcsfile="c:\PROGRA~1\MICROS~2\OFFICE11e\OUTLOOK.EXE" /vcal "%1"
wab_auto_file="c:\Program Files\Outlook Expresse\wab.exe" %1
WAXFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
webcal=rundll32.exe c:\PROGRA~1\AMERIC~1.0e\WEBCAL~1.DLL,WebCalHandler %1
webpnpFile=%SystemRoot%\system32\wpnpinst.exe %1
Whiteboard="c:\Program Files\NetMeetinge\wb32.exe" "%1"
Winamp.File="c:\Program Files\Winampe\Winamp.exe" "%1"
Winamp.Playlist="c:\Program Files\Winampe\Winamp.exe" "%1"
Windows.CompositeFont="%WinDir%\System32\notepad.exe" "%1"
Windows.Movie.Maker="c:\Program Files\Movie Makere\moviemk.exe" %1
Windows.XamlDocument="c:\WINDOWS\system32e\PresentationHost.exe" "%1" %*
Windows.Xbap="c:\WINDOWS\system32e\PresentationHost.exe" "%1" %*
wmafile="c:\Program Files\Windows Media Playere\wmplayer.exe" /prefetch:5 /Open "%L"
WMDFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /WMPackage:"%L"
wmffile=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
WMP.DVR-MSFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
WMSFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /layout:"%L"
WMVFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /prefetch:7 /Open "%L"
WMZFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /layout:"%L"
Word.Backup.8="c:\Program Files\Microsoft Office\OFFICE11e\WINWORD.EXE" /n /dde
Word.Document.12="c:\PROGRA~1\MICROS~2\OFFICE11e\WINWORD.EXE" /n /dde
Word.Document.8="c:\Program Files\Microsoft Office\OFFICE11e\WINWORD.EXE" /n /dde
Word.DocumentMacroEnabled.12="c:\PROGRA~1\MICROS~2\OFFICE11e\WINWORD.EXE" /n /dde
Word.RTF.8="c:\Program Files\Microsoft Office\OFFICE11e\WINWORD.EXE" /n /dde
Word.Template.8="c:\Program Files\Microsoft Office\OFFICE11e\WINWORD.EXE" /n /dde
wordhtmlfile="c:\Program Files\Microsoft Office\OFFICE11e\WINWORD.EXE"
wordhtmltemplate="c:\Program Files\Microsoft Office\OFFICE11e\WINWORD.EXE"
Wordpad.Document.1="%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1"
WPLFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
wrifile="c:\Program Files\Windows NT\Accessoriese\WORDPAD.EXE" "%1"
WSFFile=%SystemRoot%\System32\WScript.exe "%1" %*
WSHFile=%SystemRoot%\System32\WScript.exe "%1" %*
WVXFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
x-eudora-option=c:\PROGRA~1\Qualcomm\Eudorae\Eudora.exe /m %1
x-internet-signup=%ProgramFiles%\Internet Explorer\Connection Wizard\ISIGNUP.EXE %1
XEV.FailSafeApp=%SystemRoot%\system32\NOTEPAD.EXE %1
XEV.GenericApp="c:\Program Files\Internet Explorere\iexplore.exe" -nohome
XEV.OriginalApp="c:\Program Files\Internet Explorere\iexplore.exe" -nohome
xmlfile="c:\Program Files\Common Files\Microsoft Shared\OFFICE11e\MSOXMLED.EXE" /verb open "%1"
xnkfile="c:\Program Files\Microsoft Office\OFFICE11e\OUTLOOK.EXE" /x "%1"
XPSViewer.Document.1="c:\WINDOWS\system32\XPSViewere\XPSViewer.exe" "%1" %*
xslfile="c:\Program Files\Internet Explorere\iexplore.exe" -nohome
ZAMailSafe="c:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewalle\ca.exe" -warning "%1"
zapfile=%SystemRoot%\system32\NOTEPAD.EXE %1
=============== Created Last 30 ================
2011-03-25 10:06:35 –D—– c:\docume~1\amy\applic~1e\F8825A71ED75651A8D57DC362A93BB58
!d
==================== Find3M ====================
2004-08-11 19:13:26 A—HR– 749 c:\windowse\WindowsShell.Manifest
2004-08-04 07:00:00 A–SH— 48,680 c:\windowse\WINNT.BMP
2004-08-04 07:00:00 A–SH— 48,680 c:\windowse\WINNT256.BMP
2004-08-11 19:21:56 A–SHR– 227 c:\windows\ASSEMBLYe\Desktop.ini
2010-10-05 13:50:04 A—HR– 0 c:\windows\ASSEMBLYe\PublisherPolicy.tme
2010-10-05 13:50:04 —-HR– 0 c:\windows\ASSEMBLYe\pubpol1.dat
2010-10-07 17:12:41 —-HR– 0 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32e\index63.dat
2010-10-08 16:40:31 —-HR– 0 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32e\indexe6.dat
2010-10-08 16:41:17 —-HR– 0 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32e\indexe7.dat
2010-09-21 11:05:44 A–S—- 64 c:\windows\CSCe\00000001
2010-09-20 10:22:46 A–S—- 64 c:\windows\CSCe\00000002
2010-04-15 12:15:25 A–S—- 64 c:\windows\CSCe\csc1.tmp
2004-08-11 19:13:34 A—H— 65 c:\windows\Downloaded Program Filese\DESKTOP.INI
2004-08-04 07:00:00 A—H— 10,976 c:\windows\Fontse\8514FIX.FON
2004-08-04 07:00:00 A—H— 10,976 c:\windows\Fontse\8514FIXE.FON
2004-08-04 07:00:00 A—H— 11,520 c:\windows\Fontse\8514FIXG.FON
2004-08-04 07:00:00 A—H— 10,976 c:\windows\Fontse\8514FIXR.FON
2004-08-04 07:00:00 A—H— 11,488 c:\windows\Fontse\8514FIXT.FON
2004-08-04 07:00:00 A—H— 12,288 c:\windows\Fontse\8514OEM.FON
2004-08-04 07:00:00 A—H— 13,248 c:\windows\Fontse\8514OEME.FON
2004-08-04 07:00:00 A—H— 12,800 c:\windows\Fontse\8514OEMG.FON
2004-08-04 07:00:00 A—H— 13,200 c:\windows\Fontse\8514OEMR.FON
2004-08-04 07:00:00 A—H— 12,720 c:\windows\Fontse\8514OEMT.FON
2004-08-04 07:00:00 A—H— 9,280 c:\windows\Fontse\8514SYS.FON
2004-08-04 07:00:00 A—H— 9,504 c:\windows\Fontse\8514SYSE.FON
2004-08-04 07:00:00 A—H— 9,856 c:\windows\Fontse\8514SYSG.FON
2004-08-04 07:00:00 A—H— 10,064 c:\windows\Fontse\8514SYSR.FON
2004-08-04 07:00:00 A—H— 9,792 c:\windows\Fontse\8514SYST.FON
2004-08-04 07:00:00 A—H— 12,304 c:\windows\Fontse\85775.FON
2004-08-04 07:00:00 A—H— 12,256 c:\windows\Fontse\85855.FON
2004-08-04 07:00:00 A—H— 10,976 c:\windows\Fontse\85F1257.FON
2004-08-04 07:00:00 A—H— 9,472 c:\windows\Fontse\85S1257.FON
2004-08-04 07:00:00 A—H— 35,808 c:\windows\Fontse\APP775.FON
2004-08-04 07:00:00 A—H— 36,672 c:\windows\Fontse\APP850.FON
2004-08-04 07:00:00 A—H— 36,656 c:\windows\Fontse\APP852.FON
2004-08-04 07:00:00 A—H— 37,296 c:\windows\Fontse\APP855.FON
2004-08-04 07:00:00 A—H— 36,672 c:\windows\Fontse\APP857.FON
2004-08-04 07:00:00 A—H— 37,472 c:\windows\Fontse\APP866.FON
2004-08-04 07:00:00 A—H— 7,216 c:\windows\Fontse\CGA40737.FON
2004-08-04 07:00:00 A—H— 6,352 c:\windows\Fontse\CGA40850.FON
2004-08-04 07:00:00 A—H— 6,672 c:\windows\Fontse\CGA40852.FON
2004-08-04 07:00:00 A—H— 6,672 c:\windows\Fontse\CGA40857.FON
2004-08-04 07:00:00 A—H— 7,232 c:\windows\Fontse\CGA40866.FON
2004-08-04 07:00:00 A—H— 7,216 c:\windows\Fontse\CGA40869.FON
2004-08-04 07:00:00 A—H— 6,336 c:\windows\Fontse\CGA40WOA.FON
2004-08-04 07:00:00 A—H— 5,168 c:\windows\Fontse\CGA80737.FON
2004-08-04 07:00:00 A—H— 4,320 c:\windows\Fontse\CGA80850.FON
2004-08-04 07:00:00 A—H— 5,200 c:\windows\Fontse\CGA80852.FON
2004-08-04 07:00:00 A—H— 4,640 c:\windows\Fontse\CGA80857.FON
2004-08-04 07:00:00 A—H— 5,168 c:\windows\Fontse\CGA80866.FON
2004-08-04 07:00:00 A—H— 5,168 c:\windows\Fontse\CGA80869.FON
2004-08-04 07:00:00 A—H— 4,304 c:\windows\Fontse\CGA80WOA.FON
2004-08-04 07:00:00 A—H— 23,440 c:\windows\Fontse\COUE1257.FON
2004-08-04 07:00:00 A—H— 31,760 c:\windows\Fontse\COUF1257.FON
2004-08-04 07:00:00 A—H— 23,408 c:\windows\Fontse\COURE.FON
2004-08-04 07:00:00 A—H— 23,440 c:\windows\Fontse\COUREE.FON
2004-08-04 07:00:00 A—H— 25,024 c:\windows\Fontse\COUREG.FON
2004-08-04 07:00:00 A—H— 23,440 c:\windows\Fontse\COURER.FON
2004-08-04 07:00:00 A—H— 25,024 c:\windows\Fontse\COURET.FON
2004-08-04 07:00:00 A—H— 31,712 c:\windows\Fontse\COURF.FON
2004-08-04 07:00:00 A—H— 31,776 c:\windows\Fontse\COURFE.FON
2004-08-04 07:00:00 A—H— 33,344 c:\windows\Fontse\COURFG.FON
2004-08-04 07:00:00 A—H— 31,808 c:\windows\Fontse\COURFR.FON
2004-08-04 07:00:00 A—H— 33,360 c:\windows\Fontse\COURFT.FON
2004-08-11 19:14:22 A–SH— 67 c:\windows\Fontse\DESKTOP.INI
2004-08-04 07:00:00 A—H— 36,336 c:\windows\Fontse\DOS737.FON
2004-08-04 07:00:00 A—H— 36,656 c:\windows\Fontse\DOSAPP.FON
2004-08-04 07:00:00 A—H— 9,248 c:\windows\Fontse\EGA40737.FON
2004-08-04 07:00:00 A—H— 8,384 c:\windows\Fontse\EGA40850.FON
2004-08-04 07:00:00 A—H— 8,368 c:\windows\Fontse\EGA40852.FON
2004-08-04 07:00:00 A—H— 8,704 c:\windows\Fontse\EGA40857.FON
2004-08-04 07:00:00 A—H— 9,232 c:\windows\Fontse\EGA40866.FON
2004-08-04 07:00:00 A—H— 9,248 c:\windows\Fontse\EGA40869.FON
2004-08-04 07:00:00 A—H— 8,368 c:\windows\Fontse\EGA40WOA.FON
2004-08-04 07:00:00 A—H— 6,192 c:\windows\Fontse\EGA80737.FON
2004-08-04 07:00:00 A—H— 5,328 c:\windows\Fontse\EGA80850.FON
2004-08-04 07:00:00 A—H— 5,344 c:\windows\Fontse\EGA80852.FON
2004-08-04 07:00:00 A—H— 5,648 c:\windows\Fontse\EGA80857.FON
2004-08-04 07:00:00 A—H— 5,280 c:\windows\Fontse\EGA80866.FON
2004-08-04 07:00:00 A—H— 6,192 c:\windows\Fontse\EGA80869.FON
2004-08-04 07:00:00 A—H— 5,312 c:\windows\Fontse\EGA80WOA.FON
2004-08-04 07:00:00 A—H— 24,124 c:\windows\Fontse\MARLETT.TTF
2004-08-04 07:00:00 A—H— 59,024 c:\windows\Fontse\SERE1257.FON
2004-08-04 07:00:00 A—H— 84,080 c:\windows\Fontse\SERF1257.FON
2004-08-04 07:00:00 A—H— 57,936 c:\windows\Fontse\SERIFE.FON
2004-08-04 07:00:00 A—H— 59,952 c:\windows\Fontse\SERIFEE.FON
2004-08-04 07:00:00 A—H— 60,752 c:\windows\Fontse\SERIFEG.FON
2004-08-04 07:00:00 A—H— 63,296 c:\windows\Fontse\SERIFER.FON
2004-08-04 07:00:00 A—H— 61,024 c:\windows\Fontse\SERIFET.FON
2004-08-04 07:00:00 A—H— 81,728 c:\windows\Fontse\SERIFF.FON
2004-08-04 07:00:00 A—H— 85,360 c:\windows\Fontse\SERIFFE.FON
2004-08-04 07:00:00 A—H— 86,256 c:\windows\Fontse\SERIFFG.FON
2004-08-04 07:00:00 A—H— 90,736 c:\windows\Fontse\SERIFFR.FON
2004-08-04 07:00:00 A—H— 84,848 c:\windows\Fontse\SERIFFT.FON
2004-08-04 07:00:00 A—H— 24,672 c:\windows\Fontse\SMAE1257.FON
2004-08-04 07:00:00 A—H— 19,904 c:\windows\Fontse\SMAF1257.FON
2004-08-04 07:00:00 A—H— 26,112 c:\windows\Fontse\SMALLE.FON
2004-08-04 07:00:00 A—H— 24,784 c:\windows\Fontse\SMALLEE.FON
2004-08-04 07:00:00 A—H— 28,912 c:\windows\Fontse\SMALLEG.FON
2004-08-04 07:00:00 A—H— 24,832 c:\windows\Fontse\SMALLER.FON
2004-08-04 07:00:00 A—H— 29,200 c:\windows\Fontse\SMALLET.FON
2004-08-04 07:00:00 A—H— 21,504 c:\windows\Fontse\SMALLF.FON
2004-08-04 07:00:00 A—H— 19,600 c:\windows\Fontse\SMALLFE.FON
2004-08-04 07:00:00 A—H— 23,120 c:\windows\Fontse\SMALLFG.FON
2004-08-04 07:00:00 A—H— 19,760 c:\windows\Fontse\SMALLFR.FON
2004-08-04 07:00:00 A—H— 23,008 c:\windows\Fontse\SMALLFT.FON
2004-08-04 07:00:00 A—H— 65,456 c:\windows\Fontse\SSEE1257.FON
2004-08-04 07:00:00 A—H— 90,336 c:\windows\Fontse\SSEF1257.FON
2004-08-04 07:00:00 A—H— 64,656 c:\windows\Fontse\SSERIFE.FON
2004-08-04 07:00:00 A—H— 66,464 c:\windows\Fontse\SSERIFEE.FON
2004-08-04 07:00:00 A—H— 65,328 c:\windows\Fontse\SSERIFEG.FON
2004-08-04 07:00:00 A—H— 68,848 c:\windows\Fontse\SSERIFER.FON
2004-08-04 07:00:00 A—H— 64,400 c:\windows\Fontse\SSERIFET.FON
2004-08-04 07:00:00 A—H— 89,856 c:\windows\Fontse\SSERIFF.FON
2004-08-04 07:00:00 A—H— 92,032 c:\windows\Fontse\SSERIFFE.FON
2004-08-04 07:00:00 A—H— 90,288 c:\windows\Fontse\SSERIFFG.FON
2004-08-04 07:00:00 A—H— 98,256 c:\windows\Fontse\SSERIFFR.FON
2004-08-04 07:00:00 A—H— 89,456 c:\windows\Fontse\SSERIFFT.FON
2004-08-04 07:00:00 A—H— 56,336 c:\windows\Fontse\SYMBOLE.FON
2004-08-04 07:00:00 A—H— 5,168 c:\windows\Fontse\VGA737.FON
2004-08-04 07:00:00 A—H— 5,168 c:\windows\Fontse\VGA775.FON
2004-08-04 07:00:00 A—H— 5,232 c:\windows\Fontse\VGA850.FON
2004-08-04 07:00:00 A—H— 6,160 c:\windows\Fontse\VGA852.FON
2004-08-04 07:00:00 A—H— 5,120 c:\windows\Fontse\VGA855.FON
2004-08-04 07:00:00 A—H— 5,552 c:\windows\Fontse\VGA857.FON
2004-08-04 07:00:00 A—H— 5,184 c:\windows\Fontse\VGA860.FON
2004-08-04 07:00:00 A—H— 5,200 c:\windows\Fontse\VGA863.FON
2004-08-04 07:00:00 A—H— 5,184 c:\windows\Fontse\VGA865.FON
2004-08-04 07:00:00 A—H— 6,128 c:\windows\Fontse\VGA866.FON
2004-08-04 07:00:00 A—H— 5,184 c:\windows\Fontse\VGA869.FON
2004-08-04 07:00:00 A—H— 5,376 c:\windows\Fontse\VGAF1257.FON
2004-08-04 07:00:00 A—H— 5,360 c:\windows\Fontse\VGAFIX.FON
2004-08-04 07:00:00 A—H— 5,376 c:\windows\Fontse\VGAFIXE.FON
2004-08-04 07:00:00 A—H— 6,112 c:\windows\Fontse\VGAFIXG.FON
2004-08-04 07:00:00 A—H— 5,600 c:\windows\Fontse\VGAFIXR.FON
2004-08-04 07:00:00 A—H— 6,112 c:\windows\Fontse\VGAFIXT.FON
2004-08-04 07:00:00 A—H— 5,168 c:\windows\Fontse\VGAOEM.FON
2004-08-04 07:00:00 A—H— 6,656 c:\windows\Fontse\VGAS1257.FON
2004-08-04 07:00:00 A—H— 7,280 c:\windows\Fontse\VGASYS.FON
2004-08-04 07:00:00 A—H— 6,608 c:\windows\Fontse\VGASYSE.FON
2004-08-04 07:00:00 A—H— 7,008 c:\windows\Fontse\VGASYSG.FON
2004-08-04 07:00:00 A—H— 6,912 c:\windows\Fontse\VGASYSR.FON
2004-08-04 07:00:00 A—H— 6,912 c:\windows\Fontse\VGASYST.FON
2005-04-29 13:54:17 A—H— 10,820 c:\windows\Helpe\update.GID
2007-02-25 12:10:46 A–S—- 2,372 c:\windows\INFe\oem20.inf
2004-08-11 19:13:34 A—H— 65 c:\windows\Offline Web Pagese\DESKTOP.INI
2004-08-04 07:00:00 A–SHR– 2,737,914 c:\windows\PCHEALTH\HELPCTR\PackageStoree\instance_Professional_32_1033.cab
2004-08-11 19:14:00 A–SHR– 727 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_1.cab
2005-01-05 14:57:43 —SHR– 21,378 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_10.cab
2005-01-05 14:57:48 —SHR– 71,564 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_11.cab
2005-01-05 14:57:55 —SHR– 657,089 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_12.cab
2005-01-05 14:58:16 —SHR– 364,090 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_13.cab
2009-08-10 08:22:44 —SHR– 309,519 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_14.cab
2009-08-10 08:24:16 —SHR– 68,704 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_15.cab
2004-08-11 19:14:00 A–SHR– 19,854 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_2.cab
2004-08-11 19:14:00 A–SHR– 244,933 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_3.cab
2004-08-04 07:00:00 A–SHR– 7,068 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_4.cab
2004-08-04 07:00:00 A–SHR– 68,327 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_5.cab
2004-08-04 07:00:00 A–SHR– 305,145 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_6.cab
2004-08-11 19:24:40 A–SHR– 68,704 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_7.cab
2005-01-05 14:56:28 —SHR– 7,166 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_8.cab
2005-01-05 14:56:43 —SHR– 7,351 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_9.cab
2004-08-11 19:15:08 A—H— 229,376 c:\windows\REPAIRe\NTUSER.DAT
2005-04-04 18:38:50 —-H— 0 c:\windows\SYSTEMe\TSCNTDWN.80
2004-08-11 19:13:26 A—HR– 749 c:\windows\SYSTEM32e\cdplayer.exe.manifest
2004-08-11 19:13:34 A—HR– 488 c:\windows\SYSTEM32e\logonui.exe.manifest
1999-09-09 22:06:38 A–S—- 252,688 c:\windows\SYSTEM32e\msexcl35.dll
1999-09-28 21:42:48 A–S—- 1,050,896 c:\windows\SYSTEM32e\msjet35.dll
1999-06-10 09:34:04 A–S—- 123,664 c:\windows\SYSTEM32e\msjint35.dll
1999-06-10 09:34:04 A–S—- 24,848 c:\windows\SYSTEM32e\msjter35.dll
1999-09-09 22:06:38 A–S—- 168,720 c:\windows\SYSTEM32e\msltus35.dll
1999-06-07 18:59:34 A–S—- 250,128 c:\windows\SYSTEM32e\mspdox35.dll
1999-04-25 17:00:00 A–S—- 252,176 c:\windows\SYSTEM32e\Msrd2x35.dll
1999-08-25 14:57:26 A–S—- 415,504 c:\windows\SYSTEM32e\msrepl35.dll
1999-09-30 19:21:24 A–S—- 166,672 c:\windows\SYSTEM32e\mstext35.dll
1999-04-25 17:00:00 A–S—- 287,504 c:\windows\SYSTEM32e\Msxbse35.dll
2004-08-11 19:13:26 A—HR– 749 c:\windows\SYSTEM32e\ncpa.cpl.manifest
2004-08-11 19:13:26 A—HR– 749 c:\windows\SYSTEM32e\nwc.cpl.manifest
2004-08-11 19:13:26 A—HR– 749 c:\windows\SYSTEM32e\sapi.cpl.manifest
1999-04-25 17:00:00 A–S—- 368,912 c:\windows\SYSTEM32e\Vbar332.dll
2004-08-11 19:13:34 A—HR– 488 c:\windows\SYSTEM32e\WindowsLogon.manifest
2004-08-11 19:13:26 A—HR– 749 c:\windows\SYSTEM32e\wuaucpl.cpl.manifest
2007-01-15 16:36:25 A—H— 4,212 c:\windows\SYSTEM32e\zllictbl_cpy.dat
2005-01-28 14:44:28 —S—- 8,520 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\codecs10.CAT
2005-01-28 14:44:28 —S—- 8,818 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\DRM10.CAT
2008-04-13 22:04:37 —S—- 34,063 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\fp4.cat
2004-08-04 07:00:00 —S—- 13,472 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\HPCRDP.CAT
2004-08-04 07:00:00 —S—- 8,574 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\IASNT4.CAT
2006-06-29 09:11:06 —S—- 10,181 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\IDNMitigationAPIs.cat
2006-11-07 22:04:24 —S—- 42,340 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\ie7.cat
2008-04-13 22:04:34 —S—- 16,535 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\ims.cat
2010-07-15 03:28:23 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2079403.cat
2010-06-15 12:43:45 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2115168.cat
2010-06-18 13:56:32 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2121546.cat
2010-08-04 05:40:48 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2141007.cat
2010-06-22 21:03:17 —S—- 7,170 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2158563.cat
2010-06-28 06:41:05 —S—- 8,158 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2160329.cat
2010-06-24 08:46:40 —S—- 31,754 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2183461-IE7.cat
2010-06-15 12:37:34 —S—- 9,146 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2229593.cat
2010-06-28 06:55:54 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2259922.cat
2010-09-01 12:21:44 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2279986.cat
2010-07-27 02:46:39 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2286198.cat
2010-08-23 12:36:18 —S—- 8,150 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2296011.cat
2010-10-28 09:20:08 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2296199.cat
2010-09-07 07:12:29 —S—- 8,864 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2345886.cat
2010-08-17 10:30:39 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2347290.cat
2010-09-09 10:09:06 —S—- 31,754 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2360131-IE7.cat
2010-08-16 05:01:08 —S—- 8,158 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2360937.cat
2010-09-06 16:20:42 —S—- 7,470 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2378111.cat
2010-09-18 03:26:24 —S—- 9,965 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2387149.cat
2010-12-09 11:29:31 —S—- 11,198 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2393802.cat
2010-11-05 20:57:46 —S—- 31,754 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2416400-IE7.cat
2010-11-09 11:09:15 —S—- 14,920 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2419632.cat
2010-10-20 09:08:05 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2423089.cat
2010-10-26 10:24:13 —S—- 8,158 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2436673.cat
2010-11-03 14:50:34 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2440591.cat
2010-11-19 01:32:06 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2443105.cat
2010-11-05 10:13:09 —S—- 7,170 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2443685.cat
2010-11-20 08:08:00 —S—- 7,154 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2467659.cat
2010-12-09 10:37:58 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2476687.cat
2010-12-20 13:30:43 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2478960.cat
2010-12-22 08:47:57 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2478971.cat
2010-12-20 19:27:25 —S—- 31,754 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2482017-IE7.cat
2005-05-04 14:45:46 —S—- 29,493 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB893803v2_wxp.cat
2005-03-21 15:00:24 —S—- 29,491 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB893803_wxp.cat
2005-05-24 11:00:54 —S—- 8,817 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB898458.cat
2006-01-03 14:17:06 —S—- 8,792 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB911564.cat
2006-03-13 16:45:34 —S—- 7,898 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB911565.cat
2006-05-04 18:37:36 —S—- 7,898 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB917734.cat
2009-03-27 03:59:12 —S—- 13,937 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB923561.cat
2006-12-07 21:30:20 —S—- 9,057 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB923689.cat
2006-08-29 17:29:20 —S—- 8,824 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB923723.cat
2006-09-13 18:32:26 —S—- 9,090 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB925398.cat
2007-01-17 15:40:04 —S—- 18,377 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB928090-IE7.cat
2006-12-22 12:53:02 —S—- 7,894 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB929969.cat
2007-04-20 14:41:50 —S—- 30,145 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB931768-IE7.cat
2007-05-08 13:21:34 —S—- 29,530 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB933566-IE7.cat
2007-05-01 02:27:14 —S—- 10,335 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB936782.cat
2007-07-19 04:20:15 —S—- 29,530 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB937143-IE7.cat
2007-07-12 19:44:36 —S—- 11,284 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB938127-IE7.cat
2008-12-19 07:56:47 —S—- 10,074 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB938464-v2.cat
2008-04-15 14:51:51 —S—- 12,305 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB938464.cat
2007-08-21 01:41:29 —S—- 30,942 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB939653-IE7.cat
2007-10-27 18:16:40 —S—- 12,090 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB941569.cat
2007-10-30 23:30:41 —S—- 30,942 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB942615-IE7.cat
2008-01-11 08:11:14 —S—- 32,354 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB944533-IE7.cat
2008-05-02 11:01:37 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB946648.cat
2008-03-01 09:54:54 —S—- 32,354 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB947864-IE7.cat
2008-05-20 08:57:26 —S—- 32,215 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB950759-IE7.cat
2008-04-24 04:12:17 —S—- 10,439 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB950760.cat
2008-05-08 17:25:36 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB950762.cat
2008-07-07 16:59:03 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB950974.cat
2008-04-11 15:18:52 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB951066.cat
2008-07-15 05:34:26 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB951072-v2.cat
2008-06-16 16:12:03 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB951376-v2.cat
2008-04-14 12:54:14 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB951376.cat
2008-05-07 01:38:53 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB951698.cat
2008-06-21 06:36:26 —S—- 18,785 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB951748.cat
2008-06-19 05:25:51 —S—- 15,271 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB951978.cat
2008-06-12 11:35:43 —S—- 19,491 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB952004.cat
2008-11-10 23:51:22 —S—- 13,031 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB952069.cat
2008-05-01 11:30:31 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB952287.cat
2008-06-24 13:04:07 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB952954.cat
2008-06-26 14:16:04 —S—- 32,215 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB953838-IE7.cat
2008-06-23 15:26:19 —S—- 10,439 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB953839.cat
2009-05-27 09:51:12 —S—- 8,327 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB954155.cat
2008-09-15 12:17:16 —S—- 12,729 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB954211.cat
2008-09-09 21:31:57 —S—- 11,145 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB954459.cat
2008-07-06 08:06:56 —S—- 16,633 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB954550-v5.cat
2008-10-03 06:46:35 —S—- 10,200 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB954600.cat
2008-09-09 23:12:10 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB955069.cat
2009-11-21 13:03:06 —S—- 11,111 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB955759.cat
2008-10-23 15:58:30 —S—- 10,200 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB955839.cat
2008-10-03 14:49:47 —S—- 29,984 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB956390-IE7.cat
2008-10-03 11:27:13 —S—- 8,208 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB956391.cat
2009-03-06 14:33:08 —S—- 29,707 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB956572.cat
2009-06-19 01:31:17 —S—- 13,466 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB956744.cat
2008-10-23 09:26:07 —S—- 10,200 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB956802.cat
2008-08-14 11:33:08 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB956803.cat
2008-08-14 11:33:34 —S—- 17,099 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB956841.cat
2009-06-23 17:40:35 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB956844.cat
2008-09-08 10:49:46 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB957095.cat
2008-10-24 11:06:44 —S—- 10,200 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB957097.cat
2008-10-16 17:28:28 —S—- 29,984 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB958215-IE7.cat
2008-10-15 13:47:09 —S—- 10,200 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB958644.cat
2008-12-11 13:01:19 —S—- 10,200 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB958687.cat
2009-02-09 11:10:55 —S—- 10,511 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB958690.cat
2009-08-13 10:09:27 —S—- 8,021 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB958869.cat
2009-03-21 13:26:47 —S—- 11,612 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB959426.cat
2008-12-05 08:36:13 —S—- 10,200 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB960225.cat
2008-12-13 03:21:48 —S—- 8,914 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB960714-IE7.cat
2009-01-15 15:26:27 —S—- 8,208 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB960715.cat
2008-12-16 09:52:12 —S—- 10,200 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB960803.cat
2009-07-01 05:32:15 —S—- 10,795 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB960859.cat
2009-01-09 15:19:04 —S—- 8,208 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB961118.cat
2009-01-20 08:31:32 —S—- 29,984 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB961260-IE7.cat
2009-06-16 11:11:02 —S—- 10,782 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB961371.cat
2008-12-20 20:08:55 —S—- 10,200 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB961373.cat
2009-05-07 11:58:55 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB961501.cat
2009-03-02 21:26:55 —S—- 31,396 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB963027-IE7.cat
2009-02-10 16:48:41 —S—- 10,566 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB967715.cat
2009-07-02 09:37:45 —S—- 18,195 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB968389.cat
2009-04-19 16:40:09 —S—- 10,713 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB968537.cat
2009-06-15 14:34:24 —S—- 8,327 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB968816.cat
2009-07-17 12:52:43 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB969059.cat
2009-04-29 02:30:35 —S—- 31,624 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB969897-IE7.cat
2009-05-08 17:40:43 —S—- 7,378 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB969898.cat
2009-08-14 13:32:02 —S—- 9,681 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB969947.cat
2009-04-15 11:54:59 —S—- 10,511 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB970238.cat
2009-10-21 02:20:16 —S—- 12,194 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB970430.cat
2009-07-16 00:28:18 —S—- 7,394 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB970653-v3.cat
2009-07-27 20:02:24 —S—- 11,148 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB971029.cat
2010-01-04 14:00:28 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB971468.cat
2009-08-04 14:04:27 —S—- 14,051 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB971486.cat
2009-06-10 11:05:54 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB971557.cat
2009-06-03 15:43:52 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB971633.cat
2009-06-10 02:48:03 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB971657.cat
2009-08-25 05:59:29 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB971737.cat
2009-08-14 01:29:45 —S—- 8,097 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB971961.cat
2009-07-19 10:48:40 —S—- 31,272 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB972260-IE7.cat
2009-10-15 13:58:37 —S—- 10,782 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB972270.cat
2009-07-07 01:47:40 —S—- 7,378 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB973346.cat
2009-07-10 11:02:30 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB973354.cat
2009-07-17 17:21:45 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB973507.cat
2009-09-09 20:50:45 —S—- 7,378 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB973525.cat
2009-07-14 16:33:04 —S—- 8,625 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB973540.cat
2009-07-31 01:16:24 —S—- 10,076 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB973687.cat
2009-08-05 05:31:23 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB973815.cat
2009-07-27 19:53:52 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB973869.cat
2009-11-21 06:25:06 —S—- 10,999 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB973904.cat
2009-08-26 04:28:20 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB974112.cat
2009-10-12 10:08:11 —S—- 10,782 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB974318.cat
2009-10-13 07:23:13 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB974392.cat
2009-08-29 04:23:40 —S—- 31,285 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB974455-IE7.cat
2009-09-04 17:35:38 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB974571.cat
2009-09-01 10:55:13 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB975025.cat
2009-09-11 11:03:45 —S—- 9,723 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB975467.cat
2010-04-05 18:56:52 —S—- 8,303 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB975558.cat
2009-11-27 13:51:20 —S—- 10,795 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB975560.cat
2009-10-23 19:54:20 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB975561.cat
2010-04-07 12:36:59 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB975562.cat
2009-12-08 05:38:37 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB975713.cat
2009-10-28 22:21:12 —S—- 7,407 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB976098-v2.cat
2009-10-29 04:35:29 —S—- 31,272 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB976325-IE7.cat
2009-10-21 01:42:47 —S—- 8,084 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB976749-IE7.cat
2009-12-09 07:05:16 —S—- 14,051 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB977165.cat
2010-01-29 10:58:34 —S—- 8,803 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB977816.cat
2009-11-27 13:13:06 —S—- 15,031 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB977914.cat
2009-12-14 03:47:45 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB978037.cat
2010-01-05 07:08:01 —S—- 31,991 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB978207-IE7.cat
2009-12-07 01:43:53 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB978251.cat
2010-01-08 10:26:08 —S—- 7,391 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB978262.cat
2010-02-12 00:57:39 —S—- 10,795 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB978338.cat
2010-01-29 11:41:45 —S—- 10,795 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB978542.cat
2009-12-24 03:18:58 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB978601.cat
2010-04-14 10:38:16 —S—- 8,299 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB978695.cat
2009-12-17 04:22:05 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB978706.cat
2010-01-23 06:51:24 —S—- 7,407 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB979306.cat
2010-01-13 10:22:54 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB979309.cat
2010-03-05 11:26:23 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB979482.cat
2010-05-02 04:42:05 —S—- 9,442 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB979559.cat
2010-03-05 12:30:54 —S—- 14,349 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB979683.cat
2010-07-16 08:36:39 —S—- 8,862 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB979687.cat
2010-03-11 09:36:42 —S—- 31,991 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB980182-IE7.cat
2010-05-05 01:25:18 —S—- 7,152 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB980195.cat
2010-04-20 02:01:28 —S—- 9,144 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB980218.cat
2010-02-25 08:51:56 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB980232.cat
2010-06-30 08:42:32 —S—- 7,858 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB980436.cat
2010-07-15 09:10:50 —S—- 7,858 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB981322.cat
2010-03-09 07:49:33 —S—- 8,097 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB981349.cat
2010-04-22 18:33:04 —S—- 7,168 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB981793.cat
2010-06-18 02:43:52 —S—- 10,490 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB981852.cat
2010-09-01 12:21:54 —S—- 8,156 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB981957.cat
2010-06-21 11:04:43 —S—- 7,858 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB981997.cat
2010-08-27 04:30:36 —S—- 7,858 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB982132.cat
2010-06-21 13:36:18 —S—- 7,858 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB982214.cat
2010-05-04 14:45:23 —S—- 31,752 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB982381-IE7.cat
2010-06-17 10:12:41 —S—- 7,858 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB982665.cat
2010-07-23 02:18:53 —S—- 8,156 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB982802.cat
2004-08-04 07:00:00 —S—- 399,645 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\MAPIMIG.CAT
2008-04-13 22:04:36 —S—- 34,747 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\mediactr.cat
2005-01-28 14:44:28 —S—- 7,626 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\MPCD10.CAT
2005-01-28 14:44:28 —S—- 7,030 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\MPPRE10.CAT
2005-01-28 14:44:28 —S—- 7,626 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\MPSTUB10.CAT
2008-04-13 22:04:35 —S—- 12,363 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\msmsgs.cat
2008-04-13 22:04:35 —S—- 26,991 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\msn7.cat
2008-04-13 22:04:36 —S—- 14,433 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\msn9.cat
2008-04-13 22:04:36 —S—- 10,027 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\mstsweb.cat
2008-07-06 08:06:57 —S—- 10,929 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\msxpsdrv.CAT
2004-08-04 07:00:00 —S—- 37,484 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\MW770.CAT
2008-04-13 22:04:39 —S—- 144,484 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\netfx.cat
2006-06-28 19:00:54 —S—- 8,420 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\NLSDownlevelMapping.cat
2008-04-13 22:04:45 —S—- 2,144,487 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\nt5.cat
2004-08-04 07:00:00 —S—- 797,189 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\NT5IIS.CAT
2008-04-13 22:04:43 —S—- 522,220 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\nt5inf.cat
2009-01-09 15:19:28 —S—- 1,089,593 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\ntprint.cat
2004-09-09 11:09:42 —S—- 16,890 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem0.CAT
2004-04-06 12:25:08 —S—- 20,362 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem1.CAT
2003-01-10 18:13:04 —S—- 7,592 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem10.CAT
2002-04-02 20:57:06 —S—- 15,263 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem14.CAT
2008-08-18 06:35:14 —S—- 19,280 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem16.CAT
2004-06-29 15:43:56 —S—- 10,316 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem2.CAT
2007-03-07 11:02:32 —S—- 11,085 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem20.CAT
2007-04-16 22:58:18 —S—- 41,586 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem21.CAT
2007-04-16 22:56:46 —S—- 17,648 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem22.CAT
2007-07-30 19:36:28 —S—- 48,256 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem23.CAT
2007-07-30 19:35:04 —S—- 17,648 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem24.CAT
2008-07-18 22:26:06 —S—- 48,117 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem25.CAT
2008-07-18 22:24:52 —S—- 17,509 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem26.CAT
2008-10-16 15:24:30 —S—- 45,886 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem27.CAT
2008-10-16 15:22:38 —S—- 15,278 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem28.CAT
2009-08-06 19:37:06 —S—- 45,056 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem29.CAT
2004-04-27 23:15:10 —S—- 14,533 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem3.CAT
2009-08-06 19:36:40 —S—- 14,448 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem30.CAT
2009-08-06 20:36:54 —S—- 45,069 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem31.CAT
2004-05-25 11:43:50 —S—- 8,227 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem4.CAT
2004-05-25 11:43:50 —S—- 9,257 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem5.CAT
2004-05-25 11:43:50 —S—- 9,265 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem6.CAT
2004-05-25 11:43:50 —S—- 9,265 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem7.CAT
2002-03-13 10:50:36 —S—- 7,172 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem9.CAT
2004-08-11 12:31:24 —S—- 7,710 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\OEMBIOS.CAT
2004-08-04 07:00:00 —S—- 1,042,903 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\SP2.CAT
2008-04-14 07:40:48 —S—- 1,296,669 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\sp3.cat
2008-04-13 22:04:37 —S—- 36,549 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\spdelta.cat
2008-04-13 22:10:46 —S—- 112,918 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\tabletpc.cat
2009-03-10 22:18:28 —S—- 7,236 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\WgaNotify.cat
2005-01-28 14:44:28 —S—- 9,116 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\WMDM10.CAT
2004-08-04 07:00:00 —S—- 7,334 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\wmerrenu.cat
2005-01-28 14:44:28 —S—- 11,202 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\WMFSDK10.CAT
2005-01-28 14:44:28 —S—- 14,432 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\WMP10.CAT
2005-01-28 14:44:28 —S—- 7,328 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\WMSET10.CAT
2005-01-28 14:44:28 —S—- 10,598 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\WPD10.CAT
2009-03-10 22:18:28 —S—- 7,236 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\_000000_.cat
2010-04-18 09:04:39 A—H— 0 c:\windows\SYSTEM32\CONFIGe\DEFAULT.tmp.LOG
2010-04-18 09:04:39 A—H— 0 c:\windows\SYSTEM32\CONFIGe\SAM.tmp.LOG
2010-04-18 11:03:42 A—H— 8,192 c:\windows\SYSTEM32\CONFIGe\SECURITY.tmp.LOG
2010-04-18 09:04:38 A—H— 0 c:\windows\SYSTEM32\CONFIGe\SOFTWARE.tmp.LOG
2010-04-18 09:04:38 A—H— 0 c:\windows\SYSTEM32\CONFIGe\SYSTEM.tmp.LOG
2004-08-11 19:06:14 A—H— 1,024 c:\windows\SYSTEM32\CONFIGe\TempKey.LOG
2004-08-11 19:06:14 A—H— 1,024 c:\windows\SYSTEM32\CONFIGe\USERDIFF.LOG
2010-04-18 08:59:17 A—H— 1,024 c:\windows\SYSTEM32\CONFIG\systemprofilee\NTUSER.DAT.LOG
2004-08-11 19:07:12 A–SH— 62 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Datae\DESKTOP.INI
2010-09-22 10:01:51 A–S—- 30,704 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\0797C381B2F87EB5A1D5573BD15BA4F4
2010-06-09 16:21:23 A–S—- 2,202 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\0897206B35294097C3660E62BCDB227C
2010-09-20 09:44:21 A–S—- 2,594 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\23B523C9E7746F715D33C6527C18EB9D
2010-04-22 16:34:04 A–S—- 341 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\303572DF538EDD8B1D606185F1D559B8
2010-06-09 16:21:23 A–S—- 1,294 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\3C19F8F5C2A69BEC912EF5B953293907
2010-04-12 08:50:30 A–S—- 242,756 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\4DB1DABDF57ED9997FE8DCC77E93C04F
2010-06-09 16:20:54 A–S—- 781 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\696F3DE637E6DE85B458996D49D759AD
2010-04-22 16:34:04 A–S—- 413 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\79841F8EF00FBA86D33CC5A47696F165
2006-01-30 09:18:41 A–S—- 1,047 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\7C8A03C4580C6B04FDF34357F3474EDC
2010-06-09 16:20:54 A–S—- 597 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\A1377F7115F1F126A15360369B165211
2010-10-07 16:48:15 A–S—- 558 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\A44F4E7CB3133FF765C39A53AD8FCFDD
2006-01-30 09:18:41 A–S—- 1,370 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\B82262A5D5DA4DDACE9EDA7F787D0DEB
2007-04-06 08:04:04 A–S—- 1,039 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\CFC456E7E410D69E2C6F3E2DB75C7DB3
2010-09-20 09:44:21 A–S—- 1,310 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\D0F063B6B88A2B8BFE21C3993A613447
2009-08-10 08:22:45 A–S—- 574 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\E04822AD18D472EA5B582E6E6F8C6B9A
2010-04-13 09:03:29 A–S—- 2,148 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\F03FBEED31BB9347A2DDFF031058505F
2010-09-22 10:01:51 A–S—- 132 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\0797C381B2F87EB5A1D5573BD15BA4F4
2010-06-09 16:21:23 A–S—- 194 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\0897206B35294097C3660E62BCDB227C
2010-09-20 09:44:21 A–S—- 112 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\23B523C9E7746F715D33C6527C18EB9D
2010-04-22 16:34:04 A–S—- 126 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\303572DF538EDD8B1D606185F1D559B8
2010-06-09 16:21:23 A–S—- 126 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\3C19F8F5C2A69BEC912EF5B953293907
2010-04-12 08:50:30 A–S—- 98 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\4DB1DABDF57ED9997FE8DCC77E93C04F
2010-06-09 16:20:54 A–S—- 156 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\696F3DE637E6DE85B458996D49D759AD
2010-04-22 16:34:04 A–S—- 98 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\79841F8EF00FBA86D33CC5A47696F165
2006-01-30 09:18:41 A–S—- 126 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\7C8A03C4580C6B04FDF34357F3474EDC
2010-06-09 16:20:54 A–S—- 142 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\A1377F7115F1F126A15360369B165211
2010-10-07 16:48:15 A–S—- 146 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\A44F4E7CB3133FF765C39A53AD8FCFDD
2006-01-30 09:18:41 A–S—- 194 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\B82262A5D5DA4DDACE9EDA7F787D0DEB
2007-04-06 08:04:04 A–S—- 126 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\CFC456E7E410D69E2C6F3E2DB75C7DB3
2010-09-20 09:44:21 A–S—- 178 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\D0F063B6B88A2B8BFE21C3993A613447
2009-08-10 08:22:45 A–S—- 140 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\E04822AD18D472EA5B582E6E6F8C6B9A
2010-04-13 09:03:29 A–S—- 132 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\F03FBEED31BB9347A2DDFF031058505F
2004-08-11 19:20:34 A–SH— 2,570 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\Internet Explorere\Desktop.htt
2004-08-11 19:20:44 A–SH— 119 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\Internet Explorer\Quick Launche\DESKTOP.INI
2005-01-05 15:04:36 A–SH— 24 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\Protecte\CREDHIST
2005-01-05 15:04:36 A–SH— 388 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\Protect\S-1-5-21-4073680847-1405297832-2471763517-500e\202d2b84-66f5-4e75-b822-5327038c8418
2005-01-05 15:04:36 A–SH— 24 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\Protect\S-1-5-21-4073680847-1405297832-2471763517-500e\Preferred
2004-08-11 19:20:42 A–SH— 122 c:\windows\SYSTEM32\CONFIG\systemprofile\Favoritese\Desktop.ini
2005-01-05 15:12:38 A–SH— 62 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settingse\DESKTOP.INI
2005-01-05 15:13:11 A—H— 3,780,440 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Application Datae\IconCache.db
2005-01-05 15:13:16 A—H— 262,144 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Application Data\Microsoft\Windowse\UsrClass.dat
2010-09-22 09:36:43 A—H— 1,024 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Application Data\Microsoft\Windowse\UsrClass.dat.LOG
2004-08-11 19:20:42 A–SH— 84 c:\windows\SYSTEM32\CONFIG\systemprofile\My Documentse\DESKTOP.INI
2004-08-11 19:20:42 A–SH— 189 c:\windows\SYSTEM32\CONFIG\systemprofile\My Documents\My Musice\Desktop.ini
2004-08-11 19:20:42 A–SH— 191 c:\windows\SYSTEM32\CONFIG\systemprofile\My Documents\My Picturese\Desktop.ini
2004-08-11 19:20:42 A–SH— 150 c:\windows\SYSTEM32\CONFIG\systemprofile\Recente\Desktop.ini
2004-08-11 19:13:36 A–SH— 181 c:\windows\SYSTEM32\CONFIG\systemprofile\SendToe\DESKTOP.INI
2004-08-11 19:07:12 A–SH— 62 c:\windows\SYSTEM32\CONFIG\systemprofile\Start Menue\DESKTOP.INI
2004-08-11 19:20:44 A–SH— 234 c:\windows\SYSTEM32\CONFIG\systemprofile\Start Menu\Programse\DESKTOP.INI
2004-08-11 19:20:38 A–SH— 542 c:\windows\SYSTEM32\CONFIG\systemprofile\Start Menu\Programs\Accessoriese\DESKTOP.INI
2004-08-11 19:15:06 A–SH— 348 c:\windows\SYSTEM32\CONFIG\systemprofile\Start Menu\Programs\Accessories\Accessibilitye\DESKTOP.INI
2004-08-11 19:15:06 A–SH— 84 c:\windows\SYSTEM32\CONFIG\systemprofile\Start Menu\Programs\Accessories\Entertainmente\DESKTOP.INI
2004-08-11 19:15:06 A–SH— 84 c:\windows\SYSTEM32\CONFIG\systemprofile\Start Menu\Programs\Startupe\DESKTOP.INI
2007-02-25 12:10:48 A–S—- 5,376 c:\windows\SYSTEM32\DRIVERSe\dsunidrv.sys
2009-05-19 07:34:35 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\10a0dd3d-1243-413a-af4c-2700575aed74
2008-02-19 09:24:30 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\5155bff1-cf26-4a83-b1ef-daa19de0c2ef
2006-08-22 08:18:13 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\53e883ae-956c-45fc-b73b-296992ab389a
2007-08-21 08:10:38 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\59b8af98-e04a-447e-897d-b724c5371c7c
2010-05-18 07:46:01 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\5fb6150b-1e79-417e-8342-5cb2d7a11cd8
2010-11-15 08:39:32 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\5fc84818-3d64-4864-9045-51e2e75c9cdc
2007-02-20 09:25:13 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\69ce5cd2-5a40-403e-997f-7d4180998931
2009-08-17 07:56:08 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\8a97635a-97e9-41d5-8e74-b198f1cd7ed2
2008-05-20 12:10:45 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\9b7fedbe-d66b-4251-8f01-57c2e2c042dc
2009-11-16 08:56:40 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\a934cd14-fb0d-458f-9a4e-52585782fa41
2007-05-22 09:25:24 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\aefb63ba-1f72-4d43-9483-dbfa08dc0c7e
2008-11-17 08:49:23 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\c471253b-3b65-47e0-8fb9-662ed949d73b
2008-08-19 08:09:46 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\d26d0e97-5480-4696-89eb-f9dba0d75677
2007-11-19 09:12:04 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\dfe57563-88ba-4849-b0c7-be9a1f70ad0c
2010-02-16 08:57:47 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\e64e888d-ec07-46fb-ac7a-c6dcd87e0465
2006-11-20 09:20:10 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\ea4dbf83-82ac-4225-9f16-823237d49fd6
2010-08-17 07:38:41 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\f8f959af-8c6a-4384-8bdb-f419ea5e7e08
2009-02-17 08:52:28 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\fdef9a0b-550d-46d2-aa90-e6ae46e48aa8
2010-01-11 17:35:22 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\05bc76cd-4e7a-416f-9cd0-ed992ccf2f59
2010-04-12 16:30:36 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\091b4593-52ef-4a6a-a1e1-bd8e7f1fc02a
2006-07-06 08:08:40 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\0dd0d6bb-450d-48c9-9478-14444f798fca
2007-10-01 15:22:33 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\17ae5c58-ce18-45c9-aa11-40538c278e7e
2008-07-01 16:43:10 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\1a807fd2-2448-4763-b35d-3caac0bbf067
2006-10-05 08:13:06 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\1e169ea5-1596-4f1e-a132-69594f3c0f6c
2008-04-01 16:30:33 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\3c2955d7-efc9-426c-bcd4-c48148b8ef9e
2009-01-05 17:30:34 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\6d9d023e-4565-40c3-a6e8-5a0b07addb7b
2008-01-02 11:53:35 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\756d5e01-92c1-42ee-9159-52616698f301
2007-07-02 17:19:08 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\7f5d469c-51d8-4044-90d1-61fcb1c4b46e
2010-07-12 16:30:10 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\801f4ec4-52c1-43bd-8c38-6c19657f9087
2006-01-04 17:28:00 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\88436881-c4dc-454b-8944-4907c75a2715
2005-01-07 13:02:05 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\9802f62f-7131-40f8-9253-0d179a4f04a8
2005-01-07 13:02:05 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\b32bff2c-e984-4293-8eaa-1f752d57008e
2009-07-13 08:19:29 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\bbecb165-a411-4fa9-932e-6ed681f14b68
2005-10-06 15:06:58 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\be42e465-1bac-4c0b-a072-6449800fd309
2007-01-03 10:16:54 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\c8311a89-e381-4fb9-9ecb-fc44da3c1071
2005-04-07 17:03:01 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\ca79ec33-5d19-4a09-ab26-0a07e94c915c
2007-04-03 16:43:19 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\d7323d93-3aa4-429f-a503-ddf30494fa5e
2005-07-07 16:29:50 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\d8d82f1d-0933-4e3b-bca9-449c85451557
2008-09-30 16:33:00 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\e65c2b97-0284-426c-9644-49b15ea559d7
2010-10-12 07:59:24 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\eeafe90e-5355-4ecd-8995-1ebcb3c87e60
2005-01-07 13:02:05 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\ef583787-f66e-4878-b421-79f03e060f33
2009-10-13 16:29:33 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\f06a9100-141c-427a-b13d-f40857ccdbb7
2009-04-06 16:41:22 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\fab2f95c-37aa-48e9-a7ee-b67b65a2d184
2006-04-05 16:31:04 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\fe34b83d-fc01-4ecd-83a4-5a2ae3bb7204
2006-12-28 15:01:31 —SHR– 19,569 c:\windows\SYSTEM32\Restoree\filelist.xml
2004-08-04 07:00:00 —-HR– 65 c:\windows\Taskse\DESKTOP.INI
2008-01-08 13:15:07 A—H— 8,628 c:\windows\TWAIN_32\BrMfSc05\Lange\BrS04Usa.GID
============= FINISH: 16:06:04.64 ===============
DDS Log:
DDS (Ver_09-06-26.01) - FAT32x86
Run by [removed] at 16:04:51.39 on Fri 03/25/2011
internet explorer: 7.0.5730.11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2801 [GMT -4:00]
AV: CA Anti-Virus *On-access scanning enabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-5.1.18.0\QOELoader.exe
C:\WINDOWS\system32\CAPM1RSK.EXE
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\Documents and Settings\Amy\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\CAPPActiveProtection.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\TrayDay\TrayDay.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Brother\Brmfcmon\BrMfimon.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM1SWK.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\LxrSII1s.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPCtlPriv.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Documents and Settings\Amy\Desktop\dds.scr.scr
============== Pseudo HJT Report ===============
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
NoUpdateCheck REG_DWORD 1 (0x1)
NoJITSetup REG_DWORD 1 (0x1)
Disable Script Debugger REG_SZ no
Show_ChannelBand REG_SZ No
Anchor Underline REG_SZ yes
Cache_Update_Frequency REG_SZ Once_Per_Session
Display Inline Images REG_SZ yes
Do404Search REG_BINARY 01000000
Save_Session_History_On_Exit REG_SZ no
Show_FullURL REG_SZ no
Show_StatusBar REG_SZ yes
Show_ToolBar REG_SZ yes
Show_URLinStatusBar REG_SZ yes
Show_URLToolBar REG_SZ yes
Start Page REG_SZ http://my.yahoo.com/index.html
Use_DlgBox_Colors REG_SZ yes
Use Search Asst REG_SZ no
Use Custom Search URL REG_BINARY 01000000
FullScreen REG_SZ no
Window_Placement REG_BINARY 2c0000000000000001000000ffffffffffffffffffffffffffffffff1d0000001d0000003c030000
75020000
Use FormSuggest REG_SZ yes
StatusBarOther REG_DWORD 1 (0x1)
NotifyDownloadComplete REG_SZ yes
FavChevron_Complete REG_SZ 3
FavChevron_Failed REG_SZ 2
FavChevron_Error REG_SZ 4
AddToFavoritesExpanded REG_DWORD 1 (0x1)
Use_Combobox_DlgBox_Colors_Complete REG_SZ 3
Use_Combobox_DlgBox_Colors_Failed REG_SZ 4
Use_Combobox_DlgBox_Colors_Error REG_SZ 4
FormSuggest PW Ask REG_SZ no
Save Directory REG_SZ c:\Documents and Settings\Amy\My Documents\Word\Miscellaneous\Amy Misc\Patternse\
Error Dlg Displayed On Every Error REG_SZ no
XMLHTTP REG_DWORD 1 (0x1)
UseClearType REG_SZ yes
Enable Browser Extensions REG_SZ yes
Play_Background_Sounds REG_SZ yes
Play_Animations REG_SZ yes
CompatibilityFlags REG_DWORD 0 (0x0)
SearchMigrated REG_DWORD 1 (0x1)
RunOnceHasShown REG_DWORD 1 (0x1)
RunOnceComplete REG_DWORD 1 (0x1)
AlwaysShowMenus REG_DWORD 1 (0x1)
HistoryViewType REG_BINARY 0000
Enable_MyPics_Hoverbar REG_SZ no
ShowedCheckBrowser REG_SZ Yes
Check_Associations REG_SZ yes
HKEY_CURRENT_USER\software\microsoft\internet explorer\main\Default Feeds
HKEY_CURRENT_USER\software\microsoft\internet explorer\main\FeatureControl
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main
Enable_Disk_Cache REG_SZ yes
Cache_Percent_of_Disk REG_BINARY 0a000000
Delete_Temp_Files_On_Exit REG_SZ yes
Anchor_Visitation_Horizon REG_BINARY 01000000
Use_Async_DNS REG_SZ yes
Placeholder_Width REG_BINARY 1a000000
Placeholder_Height REG_BINARY 1a000000
CompanyName REG_SZ Microsoft Corporation
Custom_Key REG_SZ MICROSO
Wizard_Version REG_SZ 6.0.2600.0000
FullScreen REG_SZ no
Default_Secondary_Page_URL REG_MULTI_SZ \0
Extensions Off Page REG_SZ about:NoAdd-ons
Security Risk Page REG_SZ about:SecurityRisk
Check_Associations REG_SZ yes
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main\ErrorThresholds
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main\FeatureControl
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main\UrlTemplate
uinternet connection wizard,shellnext = hxxp://www.dell4me.com/myway
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings
User Agent REG_SZ Mozilla/4.0 (compatible; MSIE 7.0; Win32)
IE5_UA_Backup_Flag REG_SZ 5.0
NoNetAutodial REG_DWORD 0 (0x0)
MigrateProxy REG_DWORD 1 (0x1)
EmailName REG_SZ IEUser@
AutoConfigProxy REG_SZ wininet.dll
MimeExclusionListForCache REG_SZ multipart/mixed multipart/x-mixed-replace multipart/x-byteranges
WarnOnPost REG_BINARY 01000000
UseSchannelDirectly REG_BINARY 01000000
EnableHttp1_1 REG_DWORD 1 (0x1)
PrivacyAdvanced REG_DWORD 0 (0x0)
EnableNegotiate REG_DWORD 1 (0x1)
ProxyEnable REG_DWORD 0 (0x0)
GlobalUserOffline REG_DWORD 0 (0x0)
EnableAutodial REG_DWORD 0 (0x0)
PrivDiscUiShown REG_DWORD 1 (0x1)
WarnOnZoneCrossing REG_DWORD 0 (0x0)
UrlEncoding REG_DWORD 0 (0x0)
SecureProtocols REG_DWORD 160 (0xa0)
DisableCachingOfSSLPages REG_DWORD 0 (0x0)
WarnonBadCertRecving REG_DWORD 1 (0x1)
WarnOnPostRedirect REG_DWORD 0 (0x0)
WarnOnHTTPSToHTTPRedirect REG_DWORD 1 (0x1)
WarnOnIntranet REG_DWORD 0 (0x0)
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\5.0
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Cache
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Connections
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Lockdown_Zones
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\P3P
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Passport
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Protocols
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\TemplatePolicies
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Url History
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\ZoneMap
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Zones
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
Error: Key: software\microsoft\internet explorer\search does not exist!
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\search
SteelWerX Registry Console Tool 2.0URLSearchHooks: H - No File
Written by Bobbi Flekman 2006 ©URLSearchHooks: H - No File
HKEY_CURRENT_USER\software\microsoft\internet explorer\urlsearchhooksURLSearchHooks: H - No File
SteelWerX Registry Console Tool 2.0URLSearchHooks: H - No File
Written by Bobbi Flekman 2006 ©URLSearchHooks: H - No File
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\urlsearchhooksURLSearchHooks: H - No File
SteelWerX Registry Console Tool 2.0URLSearchHooks: H - No File
Written by Bobbi Flekman 2006 ©URLSearchHooks: H - No File
HKEY_USERS\.default\software\microsoft\internet explorer\urlsearchhooksURLSearchHooks: H - No File
{4D25F926-B9FE-4682-BF72-8AB8210D6D75}URLSearchHooks: H - No File
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon
AutoRestartShell REG_DWORD 1 (0x1)
DefaultUserName REG_SZ Amy
LegalNoticeCaption REG_SZ
LegalNoticeText REG_SZ
PowerdownAfterShutdown REG_SZ 0
ReportBootOk REG_SZ 1
Shell REG_SZ Explorer.exe
ShutdownWithoutLogon REG_SZ 0
System REG_SZ
Userinit REG_SZ c:\WINDOWS\system32e\userinit.exe,
VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
SfcQuota REG_DWORD -1 (0xffffffff)
allocatecdroms REG_SZ 0
allocatedasd REG_SZ 0
allocatefloppies REG_SZ 0
cachedlogonscount REG_SZ 10
forceunlocklogon REG_DWORD 0 (0x0)
passwordexpirywarning REG_DWORD 14 (0xe)
scremoveoption REG_SZ 0
AllowMultipleTSSessions REG_DWORD 1 (0x1)
UIHost REG_EXPAND_SZ logonui.exe
LogonType REG_DWORD 1 (0x1)
Background REG_SZ 0 0 0
DefaultPassword REG_SZ
DebugServerCommand REG_SZ no
SFCDisable REG_DWORD 0 (0x0)
WinStationsDisabled REG_SZ 0
HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
ShowLogonOptions REG_DWORD 0 (0x0)
AltDefaultUserName REG_SZ Amy
AltDefaultDomainName REG_SZ IRWINA
DefaultDomainName REG_SZ IRWINA
ChangePasswordUseKerberos REG_DWORD 1 (0x1)
Taskman REG_SZ
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\GPExtensions
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\Notify
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\SpecialAccounts
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\Credentials
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\winlogon
ParseAutoexec REG_SZ 1
ExcludeProfileDirs REG_SZ Local Settings;Temporary Internet Files;History;Temp;Local Settings\Application Data\Microsoft\Outlook
BuildNumber REG_DWORD 2600 (0xa28)
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows
DebugOptions REG_SZ 2048
Documents REG_SZ
DosPrint REG_SZ no
NetMessage REG_SZ no
NullPort REG_SZ None
Programs REG_SZ com exe bat pif cmd
Run REG_SZ
Load REG_SZ
Device REG_SZ Brother MFC-7840W Printer,winspool,Ne06:
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - No File
BHO: NoExplorer - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3} - No File
BHO: - No File
BHO: NoExplorer - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{53707962-6F74-2D53-2644-206D7942484F} - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5CA3D70E-1895-11CF-8E15-001234567890} - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7} - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} - No File
BHO: NoExplorer - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C} - No File
BHO: - No File
BHO: NoExplorer - No File
urun: [updateMgr] c:\Program Files\Adobe\Acrobat 7.0\Readere\AdobeUpdateManager.exe AcRdB7_0_9
urun: [LxrAutorun] c:\Documents and Settings\Amy\Local Settings\Application Data\Lexar Mediae\LxrAutorun.exe
urun: [ctfmon.exe] c:\WINDOWS\system32e\ctfmon.exe
urun: [swg] "c:\Program Files\Google\GoogleToolbarNotifiere\GoogleToolbarNotifier.exe"
mrun: [SunJavaUpdateSched] "c:\Program Files\Common Files\Java\Java Updatee\jusched.exe"
mrun: [ATIPTA] c:\Program Files\ATI Technologies\ATI Control Panele\atiptaxx.exe
mrun: [IntelMeM] c:\Program Files\Intel\Modem Event Monitore\IntelMEM.exe
mrun: [DVDLauncher] "c:\Program Files\CyberLink\PowerDVDe\DVDLauncher.exe"
mrun: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Managere\sgtray.exe" /r
mrun: [dla] c:\WINDOWS\system32\dlae\tfswctrl.exe
mrun: [QuickTime Task] "c:\Program Files\QuickTimee\qttask.exe" -atboottime
mrun: [SSBkgdUpdate] "c:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdatee\SSBkgdupdate.exe" -Embedding -boot
mrun: [ControlCenter2.0] c:\Program Files\Brother\ControlCenter2e\brctrcen.exe /autorun
mrun: [TkBellExe] "c:\Program Files\Common Files\Real\Update_OBe\realsched.exe" -osboot
mrun: [CAVRID] "c:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antiviruse\CAVRID.exe"
mrun: [cctray] "c:\Program Files\CA\CA Internet Security Suite\cctraye\cctray.exe"
mrun: [PaperPort PTD] "c:\Program Files\ScanSoft\PaperPorte\pptd40nt.exe"
mrun: [IndexSearch] "c:\Program Files\ScanSoft\PaperPorte\IndexSearch.exe"
mrun: [PPort11reminder] "c:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Erege\Ereg.ini"
mrun: [BrMfcWnd] c:\Program Files\Brother\Brmfcmone\BrMfcWnd.exe /AUTORUN
mrun: [ControlCenter3] c:\Program Files\Brother\ControlCenter3e\brctrcen.exe /autorun
mrun: [Adobe Reader Speed Launcher] "c:\Program Files\Adobe\Reader 9.0\Readere\Reader_sl.exe"
mrun: [Adobe ARM] "c:\Program Files\Common Files\Adobe\ARM\1.0e\AdobeARM.exe"
mrun: [QOELOADER] "c:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-5.1.18.0e\QOELoader.exe"
mrun: [Memeo Instant Backup] c:\Program Files\Memeo\AutoBackupe\MemeoLauncher2.exe –silent –no_ui
mrun: [Seagate Dashboard] c:\Program Files\Seagate\Seagate Dashboarde\MemeoLauncher.exe –silent –no_ui
c:\DOCUME~1\Amy\STARTM~1\Programs\Startup\TrayDay.lnk - C:\Program Files\TrayDaye\TrayDay.exe
c:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\QUICKB~1.LNK - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdatee\qbupdate.exe
ie: SteelWerX Registry Console Tool 2.0
ie: Written by Bobbi Flekman 2006 ©
ie: HKEY_CURRENT_USER\software\microsoft\internet explorer\menuext
ie: HKEY_CURRENT_USER\software\microsoft\internet explorer\menuext\E&xport to Microsoft Excel
ie: REG_SZ res://c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE/3000
ie: Contexts REG_DWORD 1 (0x1)
ie: HKEY_CURRENT_USER\software\microsoft\internet explorer\menuext\Google Sidewiki…
ie: REG_SZ res://c:\Program Files\Google\Google Toolbar\Componente\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
ie: Contexts REG_DWORD 19 (0x13)
ie: {SteelWerX Registry Console Tool 2.0
ie: {Written by Bobbi Flekman 2006 ©
ie: {HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions
ie: {HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{92780B25-18CC-41C8-B9BE-3C9C571A8263}
ie: { ButtonText - REG_SZ Research
ie: { Icon - REG_SZ c:\PROGRA~1\MICROS~2\OFFICE11e\REFBAR.ICO
ie: { Default Visible - REG_SZ Yes
ie: { HotIcon - REG_SZ c:\PROGRA~1\MICROS~2\OFFICE11e\REFBARH.ICO
ie: {HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
ie: { ButtonText - REG_SZ Real.com
ie: { HotIcon - REG_SZ c:\Program Files\Real\RealPlayere\eb_act.ico
ie: { Icon - REG_SZ c:\Program Files\Real\RealPlayere\eb_inact.ico
ie: { ToolTip - REG_SZ Real.com Explorer Bar
ie: { Default Visible - REG_SZ Yes
ie: {HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{e2e2dd38-d088-4134-82b7-f2ba38496583}
ie: { MenuText - REG_SZ @xpsp3res.dll,-20001
ie: { Exec - REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe
ie: {HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}
ie: { ButtonText - REG_SZ Messenger
ie: { Default Visible - REG_SZ Yes
ie: { Exec - REG_SZ c:\Program Files\Messengere\msmsgs.exe
ie: { HotIcon - REG_SZ c:\Program Files\Messengere\msmsgs.exe,302
ie: { Icon - REG_SZ c:\Program Files\Messengere\msmsgs.exe,301
ie: { MenuText - REG_SZ Windows Messenger
ie: { ToolTip - REG_SZ Windows Messenger
IE: { BandCLSID - REG_SZ {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - {ff059e31-cc5a-4e2e-bf3b-96e929d65503}\inprocserver32 does not exist!
IE: { CLSID - REG_SZ {E0DD6CAB-2D10-11D2-8F1A-0000F87ABD16} - {e0dd6cab-2d10-11d2-8f1a-0000f87abd16}\inprocserver32 does not exist!
IE: { CLSID - REG_SZ {E0DD6CAB-2D10-11D2-8F1A-0000F87ABD16} - {e0dd6cab-2d10-11d2-8f1a-0000f87abd16}\inprocserver32 does not exist!
IE: { BandCLSID - REG_SZ {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - {fe54fa40-d68c-11d2-98fa-00c0f0318afe}\inprocserver32 does not exist!
IE: { CLSID - REG_SZ {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} - {1fba04ee-3024-11d2-8f1f-0000f87abd16}\inprocserver32 does not exist!
IE: { CLSID - REG_SZ {1FBA04EE-3024-11D2-8F1F-0000F87ABD16} - {1fba04ee-3024-11d2-8f1f-0000f87abd16}\inprocserver32 does not exist!
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01010E00-5E80-11D8-9E86-0007E96C65AE}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01010E00-5E80-11D8-9E86-0007E96C65AE}\Contains
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01010E00-5E80-11D8-9E86-0007E96C65AE}\Contains\Files
c:\WINDOWS\Downloaded Program Filese\sdclicense.txt REG_SZ
c:\WINDOWS\Downloaded Program Filese\tgctlsi.dll REG_SZ
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01010E00-5E80-11D8-9E86-0007E96C65AE}\DownloadInformation
CODEBASE REG_SZ http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\tgctlsi.inf
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01010E00-5E80-11D8-9E86-0007E96C65AE}\InstalledVersion
REG_SZ 6,9,545,0
LastModified REG_SZ Tue, 21 Jun 2005 06:01:07 GMT
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01012101-5E80-11D8-9E86-0007E96C65AE}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01012101-5E80-11D8-9E86-0007E96C65AE}\Contains
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01012101-5E80-11D8-9E86-0007E96C65AE}\Contains\Files
c:\WINDOWS\Downloaded Program Filese\tgctlsr.dll REG_SZ
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01012101-5E80-11D8-9E86-0007E96C65AE}\DownloadInformation
CODEBASE REG_SZ http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\tgctlsr.inf
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01012101-5E80-11D8-9E86-0007E96C65AE}\InstalledVersion
REG_SZ 6,9,545,0
LastModified REG_SZ Tue, 21 Jun 2005 06:01:28 GMT
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{17492023-C23A-453E-A040-C7C580BBF700}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{17492023-C23A-453E-A040-C7C580BBF700}\Contains
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{17492023-C23A-453E-A040-C7C580BBF700}\Contains\Files
c:\WINDOWS\system32e\GWFSPidGen.DLL REG_SZ
c:\WINDOWS\system32e\LegitCheckControl.DLL REG_SZ
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{17492023-C23A-453E-A040-C7C580BBF700}\DownloadInformation
CODEBASE REG_SZ http://go.microsoft.com/fwlink/?linkid=39204
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\LegitCheckControl.inf
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{17492023-C23A-453E-A040-C7C580BBF700}\InstalledVersion
REG_SZ 1,4,389,0
LastModified REG_SZ Sat, 05 Nov 2005 00:53:56 GMT
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}\Contains
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}\Contains\Files
c:\WINDOWSe\opuc.dll REG_SZ
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}\DownloadInformation
CODEBASE REG_SZ http://office.microsoft.com/officeupdate/content/opuc.cab
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\opuc.inf
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}\InstalledVersion
REG_SZ 11,0,5626,0
LastModified REG_SZ Fri, 29 Aug 2003 19:59:02 GMT
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}\Contains
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}\Contains\Files
c:\WINDOWS\system32e\muweb.dll REG_SZ
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}\DownloadInformation
CODEBASE REG_SZ http://update.microsoft.com/microsoftupdat…b?1136553665781
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\muweb.inf
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}\InstalledVersion
REG_SZ 5,8,0,2469
LastModified REG_SZ Thu, 26 May 2005 11:40:19 GMT
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
REG_SZ Java Runtime Environment 1.6.0
Installer REG_SZ MSICD
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\Contains
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\DownloadInformation
CODEBASE REG_SZ http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
INF REG_SZ
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\InstalledVersion
REG_SZ 1.6.0.21
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{A762E064-A885-40E4-AC10-671BB62DC2B2}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{A762E064-A885-40E4-AC10-671BB62DC2B2}\Contains
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{A762E064-A885-40E4-AC10-671BB62DC2B2}\Contains\Files
c:\WINDOWS\system32e\OFMailX.dll REG_SZ
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{A762E064-A885-40E4-AC10-671BB62DC2B2}\DownloadInformation
CODEBASE REG_SZ http://www.eomniform.com/OF5/nsplugins/OFMailX.cab
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\OFMailX.inf
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{A762E064-A885-40E4-AC10-671BB62DC2B2}\InstalledVersion
REG_SZ 5,0,1,0
LastModified REG_SZ Sat, 19 Jan 2002 01:33:55 GMT
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
REG_SZ Java Runtime Environment 1.6.0
Installer REG_SZ MSICD
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\Contains
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\DownloadInformation
CODEBASE REG_SZ http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
INF REG_SZ
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\InstalledVersion
REG_SZ 1.6.0.21
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
REG_SZ Java Runtime Environment 1.6.0
Installer REG_SZ MSICD
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\Contains
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\DownloadInformation
CODEBASE REG_SZ http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
INF REG_SZ
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\InstalledVersion
REG_SZ 1.6.0.21
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CE28D5D2-60CF-4C7D-9FE8-0F47A3308078}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CE28D5D2-60CF-4C7D-9FE8-0F47A3308078}\Contains
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CE28D5D2-60CF-4C7D-9FE8-0F47A3308078}\Contains\Files
c:\WINDOWS\Downloaded Program Filese\SymAData.dll REG_SZ
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CE28D5D2-60CF-4C7D-9FE8-0F47A3308078}\DownloadInformation
CODEBASE REG_SZ http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CE28D5D2-60CF-4C7D-9FE8-0F47A3308078}\InstalledVersion
REG_SZ 2,6,0,0
LastModified REG_SZ Mon, 14 Nov 2005 22:15:51 GMT
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{DE22A7AB-A739-4C58-AD52-21F9CD6306B7}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{DE22A7AB-A739-4C58-AD52-21F9CD6306B7}\Contains
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{DE22A7AB-A739-4C58-AD52-21F9CD6306B7}\Contains\Files
c:\WINDOWS\Downloaded Program Filese\clearadjust.dll REG_SZ
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{DE22A7AB-A739-4C58-AD52-21F9CD6306B7}\DownloadInformation
CODEBASE REG_SZ http://download.microsoft.com/download/7/E…04/clearadj.cab
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\clearadj.inf
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{DE22A7AB-A739-4C58-AD52-21F9CD6306B7}\InstalledVersion
REG_SZ 1,0,0,4
LastModified REG_SZ Wed, 30 Apr 2003 01:12:15 GMT
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\Contains
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\Contains\Files
c:\WINDOWS\SYSTEM32e\atl.dll REG_SZ
c:\WINDOWS\Downloaded Program Filese\gp.ocx REG_SZ
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\DownloadInformation
CODEBASE REG_SZ http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\gp.inf
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\InstalledVersion
REG_SZ 1,6,2,91
LastModified REG_SZ Wed, 01 Sep 2010 22:53:46 GMT
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
Error: Value: "NameServer" does not exist!
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
d; /.* /!d; s//securityproviders: /
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
d;/^((authentication|notification) packages) .* /i!d; s//lsa: 1 = /
Authentication Packages REG_MULTI_SZ msv1_0
Bounds REG_BINARY 0030000000200000
d;/^((authentication|notification) packages) .* /i!d; s//lsa: 1 = /
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest
ImpersonatePrivilegeUpgradeToolHasRun REG_DWORD 1 (0x1)
LsaPid REG_DWORD 1816 (0x718)
SecureBoot REG_DWORD 1 (0x1)
auditbaseobjects REG_DWORD 0 (0x0)
crashonauditfail REG_DWORD 0 (0x0)
disabledomaincreds REG_DWORD 0 (0x0)
everyoneincludesanonymous REG_DWORD 0 (0x0)
fipsalgorithmpolicy REG_DWORD 0 (0x0)
forceguest REG_DWORD 1 (0x1)
fullprivilegeauditing REG_BINARY 00
limitblankpassworduse REG_DWORD 1 (0x1)
lmcompatibilitylevel REG_DWORD 0 (0x0)
nodefaultadminowner REG_DWORD 1 (0x1)
nolmhash REG_DWORD 0 (0x0)
restrictanonymous REG_DWORD 0 (0x0)
restrictanonymoussam REG_DWORD 1 (0x1)
d;/^((authentication|notification) packages) .* /i!d; s//lsa: 1 = /
Notification Packages REG_MULTI_SZ scecli
enabledcom REG_SZ y
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\AccessProviders
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\Audit
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\Data
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\GBG
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\JD
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\Kerberos
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\MSV1_0
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\Skew1
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\SSO
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\SspiCache
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager\subsystems
windows REG_EXPAND_SZ %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
============= SERVICES / DRIVERS ===============
R0 xmasbus;xmasbus;c:\WINDOWS\SYSTEM32\DRIVERSe\xmasbus.sys [2005-2-4 140800]
R0 xmasscsi;xmasscsi;c:\WINDOWS\SYSTEM32\DRIVERSe\xmasscsi.sys [2005-2-4 5504]
R1 VET-FILT;VET File System Filter;c:\WINDOWS\SYSTEM32\DRIVERSe\vet-filt.sys [2008-6-4 26352]
R1 VET-REC;VET File System Recognizer;c:\WINDOWS\SYSTEM32\DRIVERSe\vet-rec.sys [2008-6-4 21104]
R1 VETEFILE;VET File Scan Engine;c:\WINDOWS\SYSTEM32\DRIVERSe\vetefile.sys [2010-6-3 746216]
R1 VETFDDNT;VET Floppy Boot Sector Monitor;c:\WINDOWS\SYSTEM32\DRIVERSe\vetfddnt.sys [2008-6-4 21488]
R1 VETMONNT;VET File Monitor;c:\WINDOWS\SYSTEM32\DRIVERSe\vetmonnt.sys [2008-6-4 32240]
R2 CAISafe;CAISafe;c:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antiviruse\isafe.exe [2008-6-4 144960]
R2 LxrSII1d;Secure II Driver;c:\WINDOWS\SYSTEM32\DRIVERSe\LxrSII1d.sys [2008-5-13 72672]
R2 MemeoBackgroundService;MemeoBackgroundService;c:\Program Files\Memeo\AutoBackupe\MemeoBackgroundService.exe [2010-12-10 25824]
R2 RapidPortM1;RapidPortM1;c:\WINDOWS\SYSTEM32\DRIVERSe\CAPM1LP.SYS [2005-2-23 22912]
R2 SeagateDashboardService;Seagate Dashboard Service;c:\Program Files\Seagate\Seagate Dashboarde\SeagateDashboardService.exe [2010-12-14 14088]
R2 VETMSGNT;VET Message Service;c:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antiviruse\vetmsg.exe [2008-6-4 238928]
R3 PPCtlPriv;PPCtlPriv;c:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrole\PPCtlPriv.exe [2007-8-16 189704]
R3 VETEBOOT;VET Boot Scan Engine;c:\WINDOWS\SYSTEM32\DRIVERSe\veteboot.sys [2010-6-3 130280]
============== File Associations ===============
::RecordNow.GI="c:\Program Files\Sonic\RecordNow!e\RecordNow.exe" "%1"
::RecordNow.ISO="c:\Program Files\Sonic\RecordNow!e\RecordNow.exe" "%1"
::RecordNow.PXJ="c:\Program Files\Sonic\RecordNow!e\RecordNow.exe" "%1"
acrobat="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" /u "%1"
AcroExch.acrobatsecuritysettings.1="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" "%1"
AcroExch.Document="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" "%1"
AcroExch.Document.7="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" "%1"
AcroExch.FDFDoc="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" "%1"
AcroExch.pdfxml.1="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" "%1"
AcroExch.XDPDoc="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" "%1"
AcroExch.XFDFDoc="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" "%1"
acwfile=%SystemRoot%\system32\accwiz.exe %1
AIFFFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
AIR.InstallerPackage=c:\PROGRA~1\COMMON~1\ADOBEA~1\Versions\1.0e\ADOBEA~1.EXE "%1"
AnimationShop3.Animation="c:\Program Files\Jasc Software Inc\Animation Shop 3e\Anim.exe" /dde
AnimationShop3.WorkSpaceFile="c:\Program Files\Jasc Software Inc\Animation Shop 3e\Anim.exe" "/Workspace" "%1"
Application.Manifest=rundll32.exe dfshim.dll,ShOpenVerbApplication %1
Application.Reference=rundll32.exe dfshim.dll,ShOpenVerbShortcut %1|%2
ASFFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /prefetch:7 /Open "%L"
ASXFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
AUFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
AVIFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /prefetch:8 /Open "%L"
A_auto_file=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
!d
Briefcase=explorer.exe %1
callto=rundll32.exe msconf.dll,CallToProtocolHandler %l
CATFile=rundll32.exe cryptext.dll,CryptExtOpenCAT %1
cdafile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
CERFile=rundll32.exe cryptext.dll,CryptExtOpenCER %1
CertificateStoreFile=rundll32.exe cryptext.dll,CryptExtOpenSTR %1
certificate_wab_auto_file="c:\Program Files\Outlook Expresse\wab.exe" /certificate %1
cfxxefile="%1" %*
!d
clpfile=clipbrd.exe %1
!d
!d
CompressedFolder=rundll32.exe zipfldr.dll,RouteTheCall %L
ConferenceLink=rundll32.exe msconf.dll,OpenConfLink %l
Coverpage=%systemroot%\system32\fxscover.exe "%1"
CRLFile=rundll32.exe cryptext.dll,CryptExtOpenCRL %1
DBC.MPEG.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
desFile=c:\PROGRA~1\Intuit\QUICKB~1e\qbw32.exe "%1"
DocShortcut=rundll32 %SystemRoot%\System32\shscrap.dll,OpenScrap_RunDLL /r /x %1
dqyfile=c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE
dunfile=%SystemRoot%\system32\RUNDLL32.EXE NETSHELL.DLL,InvokeDunFile %1
emffile=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
Eudora.Mailbox=c:\PROGRA~1\Qualcomm\Eudorae\Eudora.exe "%1"
Eudora.Stationery=c:\PROGRA~1\Qualcomm\Eudorae\Eudora.exe "%1"
Excel.Addin="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.Backup="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.Chart=c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE /e
Excel.Chart.8="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.CSV="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.DIF="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.Macrosheet="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.Sheet.12="c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE" /e
Excel.Sheet.8="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.SheetBinaryMacroEnabled.12="c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE" /e
Excel.SheetMacroEnabled.12="c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE" /e
Excel.SLK="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.Template="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.Workspace="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.XLL="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excelhtmlfile="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE"
Excelhtmltemplate="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE"
!d
fndfile=%SystemRoot%\Explorer.exe
Folder=%SystemRoot%\Explorer.exe /idlist,%I,%L
fonfile=%SystemRoot%\System32\fontview.exe %1
ftp="c:\Program Files\Internet Explorere\IEXPLORE.EXE" %1
giffile=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
gopher="c:\Program Files\Internet Explorere\iexplore.exe" -nohome
h323file="rundll32.exe" msconf.dll,NewMediaPhone %l
HCP=%SystemRoot%\PCHEALTH\HELPCTR\Binaries\HelpCtr.exe -FromHCP -url "%1"
helpfile=winhlp32.exe %1
hlpfile=%SystemRoot%\System32\winhlp32.exe %1
holfile="c:\PROGRA~1\MICROS~2\OFFICE11e\OUTLOOK.EXE" /hol "%1"
htafile=c:\WINDOWS\system32e\mshta.exe "%1" %*
htfile="c:\Program Files\Windows NTe\HYPERTRM.EXE" %1
htmlfile="c:\Program Files\Internet Explorere\IEXPLORE.EXE" -nohome
HTTP="c:\Program Files\Internet Explorere\IEXPLORE.EXE" -nohome
https="c:\Program Files\Internet Explorere\IEXPLORE.EXE" -nohome
icsfile="c:\PROGRA~1\MICROS~2\OFFICE11e\OUTLOOK.EXE" /ical "%1"
ICY=c:\Program Files\Winampe\winamp.exe %1
iiifile="rundll32.exe" msconf.dll,NewMediaPhone %l
!d
!d
InternetShortcut=rundll32.exe ieframe.dll,OpenURL %l
iqyfile=c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE /e
ITS FILE="c:\Program Files\Internet Explorere\iexplore.exe" -nohome
jarfile="c:\Program Files\Java\jre6\bine\javaw.exe" -jar "%1" %*
JascPaintShopPhotoAlbumAlbum=c:\PROGRA~1\JASCSO~1\PAINTS~1e\pspa.exe "%1"
JascPaintShopPhotoAlbumAudio=c:\PROGRA~1\JASCSO~1\PAINTS~1e\pspa.exe "%1"
JascPaintShopPhotoAlbumImage=c:\PROGRA~1\JASCSO~1\PAINTS~1e\pspa.exe "%1"
JascPaintShopPhotoAlbumUploadAlbum=c:\PROGRA~1\JASCSO~1\PAINTS~1e\pspa.exe "%1"
JNLPFile="c:\Program Files\Java\jre6\bine\javaws.exe" "%1"
jpegfile=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
JSFile=%SystemRoot%\System32\WScript.exe "%1" %*
LDAP="c:\Program Files\Outlook Expresse\wab.exe" /ldap:%1
LiveUpdate.MIDI.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
m3ufile="c:\Program Files\Windows Media Playere\wmplayer.exe" /prefetch:6 /Open "%L"
MacromediaFlashPaper.MacromediaFlashPaper="c:\Program Files\Internet Explorere\IEXPLORE.EXE" -nohome "%1"
mailto=c:\PROGRA~1\Qualcomm\Eudorae\Eudora.exe /m %1
MediaPackageFile="c:\Program Files\Microsoft Office\OFFICE11e\MSTORE.EXE" "%1"
mhtmlfile="c:\Program Files\Internet Explorere\IEXPLORE.EXE" -nohome
Microsoft Internet Mail Message="%ProgramFiles%\Outlook Express\msimn.exe" /eml:%1
Microsoft Internet News Message="%ProgramFiles%\Outlook Express\msimn.exe" /nws:%1
Microsoft.InformationCard=c:\WINDOWS\system32\rundll32.exe c:\WINDOWS\system32e\infocardcpl.cpl,ImportInformationCard_RunDll %1
Microsoft.WindowsCardSpaceBackup=c:\WINDOWS\system32\rundll32.exe c:\WINDOWS\system32e\infocardcpl.cpl,ImportInformationCard_RunDll %1
MIDFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
MITrain.Document=c:\WINDOWS\Help\SBSI\Traininge\ORUN32.EXE -f "%1"
MMJB.AUDIOCD="c:\Program Files\Musicmatch\Musicmatch Jukeboxe\mmjblaunch.exe" /AudioCD "%1"
MMJB.BPP="c:\Program Files\Musicmatch\Musicmatch Jukeboxe\mmfwlaunch.exe" "%1"
MMJB.MMJB="c:\Program Files\Musicmatch\Musicmatch Jukeboxe\mmjblaunch.exe" "%1"
MMJB.MMO="c:\Program Files\Musicmatch\Musicmatch Jukeboxe\mmjblaunch.exe" "%1"
MMJB.MMZ="c:\Program Files\Musicmatch\Musicmatch Jukeboxe\mmjblaunch.exe" "%1"
MMS="c:\Program Files\Windows Media Playere\wmplayer.exe" "%L"
MMST="c:\Program Files\Windows Media Playere\wmplayer.exe" "%L"
MMSU="c:\Program Files\Windows Media Playere\wmplayer.exe" "%L"
mp3file="c:\Program Files\Windows Media Playere\wmplayer.exe" /prefetch:6 /Open "%L"
mpegfile="c:\Program Files\Windows Media Playere\wmplayer.exe" /prefetch:9 /Open "%L"
MPlayer=mplay32.exe /play /close "%L"
MS-ITSS FILE="c:\Program Files\Internet Explorere\iexplore.exe" -nohome ms-itss:%1::/
msbackupfile=%SystemRoot%\system32\ntbackup.exe
MSBD="c:\Program Files\Windows Media Playere\wmplayer.exe" "%L"
MSCFile=%SystemRoot%\system32\mmc.exe "%1" %*
MSDASC=Rundll32.exe c:\PROGRA~1\COMMON~1\System\OLEDB~1e\oledb32.dll,OpenDSLFile %1
msgfile="c:\Program Files\Microsoft Office\OFFICE11e\OUTLOOK.EXE" /f "%1"
Msi.Package="%SystemRoot%\System32\msiexec.exe" /i "%1" %*
Msi.Patch="%SystemRoot%\System32\msiexec.exe" /p "%1" %*
MSInfo.Document=c:\Program Files\Common Files\Microsoft Shared\MSInfoe\MSInfo32.exe /msinfo_file %1
MSPaper.Document="c:\Program Files\Common Files\Microsoft Shared\MODI\11.0e\MSPVIEW.EXE" "%1"
MSProgramGroup=c:\WINDOWS\system32e\grpconv.exe %1
MsRcIncident=%SystemRoot%\PCHealth\HelpCtr\Binaries\HelpCtr.exe -Mode "hcp://system/Remote%%20Assistance/RAClientLayout.xml" -url "hcp://system/Remote%%20Assistance/Interaction/Client/rctoolScreen1.htm" -ExtraArgument "IncidentFile=%1"
msstylesfile=%SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,Control_RunDLL %SystemRoot%\system32\desk.cpl desk,@Appearance /Action:OpenMSTheme /file:"%1"
news="%ProgramFiles%\Outlook Express\msimn.exe" /newsurl:"%1"
nntp="%ProgramFiles%\Outlook Express\msimn.exe" /newsurl:"%1"
Office.Binder="c:\PROGRA~1\MICROS~2\OFFICE11e\UNBIND.EXE" "%1"
Office.Binder.8="c:\PROGRA~1\MICROS~2\OFFICE11e\UNBIND.EXE" "%1"
Office.Binder.9="c:\Program Files\Microsoft Office\OFFICE11e\UNBIND.EXE" "%1"
Office.Binder.95="c:\PROGRA~1\MICROS~2\OFFICE11e\UNBIND.EXE" "%1"
Office.Binder.Template.9="c:\Program Files\Microsoft Office\OFFICE11e\UNBIND.EXE" "%1"
Office.Binder.Wizard.9="c:\Program Files\Microsoft Office\OFFICE11e\UNBIND.EXE" "%1"
OfficeBinder.Binder="c:\PROGRA~1\MICROS~2\OFFICE11e\UNBIND.EXE" "%1"
OfficeBinder.Binder.8="c:\PROGRA~1\MICROS~2\OFFICE11e\UNBIND.EXE" "%1"
OfficeBinder.Binder.9="c:\PROGRA~1\MICROS~2\OFFICE11e\UNBIND.EXE" "%1"
Oice.Excel.Addin=c:\PROGRA~1\MICROS~2\Office12e\Oice.exe "%1"
Oice.Excel.Sheet=c:\PROGRA~1\MICROS~2\Office12e\Oice.exe "%1"
Oice.Excel.Template=c:\PROGRA~1\MICROS~2\Office12e\Oice.exe "%1"
Oice.PowerPoint.Show=c:\PROGRA~1\MICROS~2\Office12e\Oice.exe "%1"
Oice.PowerPoint.SlideShow=c:\PROGRA~1\MICROS~2\Office12e\Oice.exe "%1"
Oice.PowerPoint.Template=c:\PROGRA~1\MICROS~2\Office12e\Oice.exe "%1"
Oice.Word.Document=c:\PROGRA~1\MICROS~2\Office12e\Oice.exe "%1"
oqyfile=c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE
ossfile="c:\Program Files\Microsoft Office\OFFICE11e\FINDER.EXE" /f "%1"
otffile=%SystemRoot%\System32\fontview.exe %1
outlook="c:\PROGRA~1\MICROS~2\OFFICE11e\OUTLOOK.EXE" /select "%1"
Outlook.NavigatorBarFile="c:\PROGRA~1\MICROS~2\OFFICE11e\OUTLOOK.EXE" /s "%1"
Outlook.Template="c:\Program Files\Microsoft Office\OFFICE11e\OUTLOOK.EXE" /t "%1"
P7RFile=rundll32.exe cryptext.dll,CryptExtOpenP7R %1
P7SFile=rundll32.exe cryptext.dll,CryptExtOpenPKCS7 %1
Paint.Picture=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
PaintShopPro8.BrowserCacheFile="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" "/Browse" "%1"
PaintShopPro8.Frame="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" /dde
PaintShopPro8.Image="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" /dde
PaintShopPro8.Mask="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" /dde
PaintShopPro8.PictureTube="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" /dde
PaintShopPro8.Script="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" "/Script" "%1"
PaintShopPro8.Shape="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" /dde
PaintShopPro8.WorkspaceFile="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" "/Workspace" "%1"
Panorama=c:\PROGRA~1\JASCSO~1\PAINTS~1e\pspa.exe "%1"
Paper.Document=c:\Program Files\ScanSoft\PaperPorte\PPPAGEVW.EXE "%1"
PaperPort.AutoplayHandler=c:\Program Files\ScanSoft\PaperPorte\PaprPort.exe /folder %L
pbkfile=%SystemRoot%\system32\rasphone.exe -f "%1"
PerfFile=%SystemRoot%\system32\perfmon.exe %1
pfmfile=%SystemRoot%\System32\fontview.exe %1
!d
pjpegfile=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
pngfile=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
pnm="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
PowerPoint.Show.12=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.Show.8=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.ShowMacroEnabled.12=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.SlideShow.12=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.SlideShow.8=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.SlideShowMacroEnabled.12=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.Template.12=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.Template.8=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.TemplateMacroEnabled.12=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
ppifile=%SystemRoot%\System32\msppcnfg.exe /Config %1
prffile="c:\Program Files\Microsoft Office\OFFICE11e\OUTLOOK.EXE" /PromptImportPRF "%1"
Publishing Folder=explorer.exe /idlist,%I,%L
qbofile=c:\Program Files\Intuit\QuickBooks Basice\qbw32.exe -X "%1"
qbwFile=c:\PROGRA~1\COMMON~1\Intuit\QUICKB~1e\qblaunch.exe "%1"
QuickTime.aif=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.aifc=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.aiff=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.cdda=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.dif=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.dv=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.mov=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.qt=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.qtl=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.qup=c:\PROGRA~1\QUICKT~1e\QuickTimeUpdater.exe "%1"
QuickTime.sd2=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
ratfile=rundll32.exe msrating.dll,ClickedOnRAT %1
RealJukebox.CDA.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealJukebox.RJS.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealJukebox.RJT.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealJukebox.RMJ.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealJukebox.RMP.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealJukebox.RMX.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealJukebox.wma.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.3GPP2.10="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.3GPP_AMR.10="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.AIFF.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.AMR.10="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.AMR_WB.10="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.AU.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.AutoPlay.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" /autoplay "%1"
RealPlayer.AVI.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.CDBurn.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" /burn "%1"
RealPlayer.DIVX.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.Flash.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" /m image/vnd.rn-realflash %1
RealPlayer.M4A.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MP1.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MP2.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MP3.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MP3PL.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MP4.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MPA.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MPEG.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MPGA.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.PIX.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.PLSPL.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.qt.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RA.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RAM.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RAX.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RM.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RMS.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RMVB.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RP.6="c:\Program Files\Common Files\Real\Update_OBe\rnxproc.exe" "%1"
RealPlayer.RSML.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RT.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RV.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RVX.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.SDP.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.SMIL.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.WAV.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.wax.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.wm.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.wmv.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.wmx.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.wvx.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
!d
!d
rlogin=rundll32.exe url.dll,TelnetProtocolHandler %l
rqyfile=c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE
rtffile="c:\Program Files\Windows NT\Accessoriese\WORDPAD.EXE" "%1"
rtsp="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
SavedDsQuery=rundll32 %SystemRoot%\system32\dsquery.dll,OpenSavedDsQuery %1
SC=c:\Program Files\Winampe\winamp.exe %1
SchedulePlus.Application.7="c:\Program Files\Microsoft Office\OFFICE11\1033e\SCHDPL32.EXE" '%1'
!d
scriptletfile="c:\WINDOWSe\NOTEPAD.EXE" "%1"
SHCmdFile=explorer.exe
Shell=%SystemRoot%\Explorer.exe /idlist,%I,%L
ShellScrap=rundll32 %SystemRoot%\system32\shscrap.dll,OpenScrap_RunDLL %1
SHOUT=c:\Program Files\Winampe\winamp.exe %1
SldSrtr.Document=c:\PROGRA~1\COMMON~1\MICROS~1\MODI\11.0e\MSPVIEW.EXE "%1"
snews="%ProgramFiles%\Outlook Express\msimn.exe" /newsurl:"%1"
SoundRec="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
SPCFile=rundll32.exe cryptext.dll,CryptExtOpenPKCS7 %1
SpybotSD.DisabledFile="c:\Program Files\Spybot - Search & Destroye\blindman.exe" "%1"
SpybotSD.SBEFile="c:\Program Files\Spybot - Search & Destroye\SpybotSD.exe" "%1"
SpybotSD.SBIFile="c:\Program Files\Spybot - Search & Destroye\SpybotSD.exe" "%1"
SpybotSD.SBSFile="c:\Program Files\Spybot - Search & Destroye\SpybotSD.exe" "%1"
SpybotSD.TInfoFile="c:\Program Files\Spybot - Search & Destroye\SpybotSD.exe" "%1"
SpybotSD.UTIFile="c:\Program Files\Spybot - Search & Destroye\SpybotSD.exe" "%1"
SpybotSD.UTSFile="c:\Program Files\Spybot - Search & Destroye\SpybotSD.exe" "%1"
SSM="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
STLFile=rundll32.exe cryptext.dll,CryptExtOpenCTL %1
stssync="c:\PROGRA~1\MICROS~2\OFFICE11e\OUTLOOK.EXE" /stssync "%1"
T126_Whiteboard="c:\Program Files\NetMeetinge\wb32.exe" - "%1"
telnet=rundll32.exe url.dll,TelnetProtocolHandler %l
themefile=%SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,Control_RunDLL %SystemRoot%\system32\desk.cpl desk,@Themes /Action:OpenTheme /file:"%1"
TIFImage.Document=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
tn3270=rundll32.exe url.dll,TelnetProtocolHandler %l
ttcfile=%SystemRoot%\System32\fontview.exe %1
ttffile=%SystemRoot%\System32\fontview.exe %1
!d
ulsfile="rundll32.exe" msconf.dll,NewMediaPhone %l
UVOX=c:\Program Files\Winampe\winamp.exe %1
vcard_wab_auto_file="c:\Program Files\Outlook Expresse\wab.exe" /vcard %1
vcffile="c:\PROGRA~1\MICROS~2\OFFICE11e\OUTLOOK.EXE" /v "%1"
vcsfile="c:\PROGRA~1\MICROS~2\OFFICE11e\OUTLOOK.EXE" /vcal "%1"
wab_auto_file="c:\Program Files\Outlook Expresse\wab.exe" %1
WAXFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
webcal=rundll32.exe c:\PROGRA~1\AMERIC~1.0e\WEBCAL~1.DLL,WebCalHandler %1
webpnpFile=%SystemRoot%\system32\wpnpinst.exe %1
Whiteboard="c:\Program Files\NetMeetinge\wb32.exe" "%1"
Winamp.File="c:\Program Files\Winampe\Winamp.exe" "%1"
Winamp.Playlist="c:\Program Files\Winampe\Winamp.exe" "%1"
Windows.CompositeFont="%WinDir%\System32\notepad.exe" "%1"
Windows.Movie.Maker="c:\Program Files\Movie Makere\moviemk.exe" %1
Windows.XamlDocument="c:\WINDOWS\system32e\PresentationHost.exe" "%1" %*
Windows.Xbap="c:\WINDOWS\system32e\PresentationHost.exe" "%1" %*
wmafile="c:\Program Files\Windows Media Playere\wmplayer.exe" /prefetch:5 /Open "%L"
WMDFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /WMPackage:"%L"
wmffile=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
WMP.DVR-MSFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
WMSFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /layout:"%L"
WMVFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /prefetch:7 /Open "%L"
WMZFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /layout:"%L"
Word.Backup.8="c:\Program Files\Microsoft Office\OFFICE11e\WINWORD.EXE" /n /dde
Word.Document.12="c:\PROGRA~1\MICROS~2\OFFICE11e\WINWORD.EXE" /n /dde
Word.Document.8="c:\Program Files\Microsoft Office\OFFICE11e\WINWORD.EXE" /n /dde
Word.DocumentMacroEnabled.12="c:\PROGRA~1\MICROS~2\OFFICE11e\WINWORD.EXE" /n /dde
Word.RTF.8="c:\Program Files\Microsoft Office\OFFICE11e\WINWORD.EXE" /n /dde
Word.Template.8="c:\Program Files\Microsoft Office\OFFICE11e\WINWORD.EXE" /n /dde
wordhtmlfile="c:\Program Files\Microsoft Office\OFFICE11e\WINWORD.EXE"
wordhtmltemplate="c:\Program Files\Microsoft Office\OFFICE11e\WINWORD.EXE"
Wordpad.Document.1="%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1"
WPLFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
wrifile="c:\Program Files\Windows NT\Accessoriese\WORDPAD.EXE" "%1"
WSFFile=%SystemRoot%\System32\WScript.exe "%1" %*
WSHFile=%SystemRoot%\System32\WScript.exe "%1" %*
WVXFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
x-eudora-option=c:\PROGRA~1\Qualcomm\Eudorae\Eudora.exe /m %1
x-internet-signup=%ProgramFiles%\Internet Explorer\Connection Wizard\ISIGNUP.EXE %1
XEV.FailSafeApp=%SystemRoot%\system32\NOTEPAD.EXE %1
XEV.GenericApp="c:\Program Files\Internet Explorere\iexplore.exe" -nohome
XEV.OriginalApp="c:\Program Files\Internet Explorere\iexplore.exe" -nohome
xmlfile="c:\Program Files\Common Files\Microsoft Shared\OFFICE11e\MSOXMLED.EXE" /verb open "%1"
xnkfile="c:\Program Files\Microsoft Office\OFFICE11e\OUTLOOK.EXE" /x "%1"
XPSViewer.Document.1="c:\WINDOWS\system32\XPSViewere\XPSViewer.exe" "%1" %*
xslfile="c:\Program Files\Internet Explorere\iexplore.exe" -nohome
ZAMailSafe="c:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewalle\ca.exe" -warning "%1"
zapfile=%SystemRoot%\system32\NOTEPAD.EXE %1
=============== Created Last 30 ================
2011-03-25 10:06:35 –D—– c:\docume~1\amy\applic~1e\F8825A71ED75651A8D57DC362A93BB58
!d
==================== Find3M ====================
2004-08-11 19:13:26 A—HR– 749 c:\windowse\WindowsShell.Manifest
2004-08-04 07:00:00 A–SH— 48,680 c:\windowse\WINNT.BMP
2004-08-04 07:00:00 A–SH— 48,680 c:\windowse\WINNT256.BMP
2004-08-11 19:21:56 A–SHR– 227 c:\windows\ASSEMBLYe\Desktop.ini
2010-10-05 13:50:04 A—HR– 0 c:\windows\ASSEMBLYe\PublisherPolicy.tme
2010-10-05 13:50:04 —-HR– 0 c:\windows\ASSEMBLYe\pubpol1.dat
2010-10-07 17:12:41 —-HR– 0 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32e\index63.dat
2010-10-08 16:40:31 —-HR– 0 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32e\indexe6.dat
2010-10-08 16:41:17 —-HR– 0 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32e\indexe7.dat
2010-09-21 11:05:44 A–S—- 64 c:\windows\CSCe\00000001
2010-09-20 10:22:46 A–S—- 64 c:\windows\CSCe\00000002
2010-04-15 12:15:25 A–S—- 64 c:\windows\CSCe\csc1.tmp
2004-08-11 19:13:34 A—H— 65 c:\windows\Downloaded Program Filese\DESKTOP.INI
2004-08-04 07:00:00 A—H— 10,976 c:\windows\Fontse\8514FIX.FON
2004-08-04 07:00:00 A—H— 10,976 c:\windows\Fontse\8514FIXE.FON
2004-08-04 07:00:00 A—H— 11,520 c:\windows\Fontse\8514FIXG.FON
2004-08-04 07:00:00 A—H— 10,976 c:\windows\Fontse\8514FIXR.FON
2004-08-04 07:00:00 A—H— 11,488 c:\windows\Fontse\8514FIXT.FON
2004-08-04 07:00:00 A—H— 12,288 c:\windows\Fontse\8514OEM.FON
2004-08-04 07:00:00 A—H— 13,248 c:\windows\Fontse\8514OEME.FON
2004-08-04 07:00:00 A—H— 12,800 c:\windows\Fontse\8514OEMG.FON
2004-08-04 07:00:00 A—H— 13,200 c:\windows\Fontse\8514OEMR.FON
2004-08-04 07:00:00 A—H— 12,720 c:\windows\Fontse\8514OEMT.FON
2004-08-04 07:00:00 A—H— 9,280 c:\windows\Fontse\8514SYS.FON
2004-08-04 07:00:00 A—H— 9,504 c:\windows\Fontse\8514SYSE.FON
2004-08-04 07:00:00 A—H— 9,856 c:\windows\Fontse\8514SYSG.FON
2004-08-04 07:00:00 A—H— 10,064 c:\windows\Fontse\8514SYSR.FON
2004-08-04 07:00:00 A—H— 9,792 c:\windows\Fontse\8514SYST.FON
2004-08-04 07:00:00 A—H— 12,304 c:\windows\Fontse\85775.FON
2004-08-04 07:00:00 A—H— 12,256 c:\windows\Fontse\85855.FON
2004-08-04 07:00:00 A—H— 10,976 c:\windows\Fontse\85F1257.FON
2004-08-04 07:00:00 A—H— 9,472 c:\windows\Fontse\85S1257.FON
2004-08-04 07:00:00 A—H— 35,808 c:\windows\Fontse\APP775.FON
2004-08-04 07:00:00 A—H— 36,672 c:\windows\Fontse\APP850.FON
2004-08-04 07:00:00 A—H— 36,656 c:\windows\Fontse\APP852.FON
2004-08-04 07:00:00 A—H— 37,296 c:\windows\Fontse\APP855.FON
2004-08-04 07:00:00 A—H— 36,672 c:\windows\Fontse\APP857.FON
2004-08-04 07:00:00 A—H— 37,472 c:\windows\Fontse\APP866.FON
2004-08-04 07:00:00 A—H— 7,216 c:\windows\Fontse\CGA40737.FON
2004-08-04 07:00:00 A—H— 6,352 c:\windows\Fontse\CGA40850.FON
2004-08-04 07:00:00 A—H— 6,672 c:\windows\Fontse\CGA40852.FON
2004-08-04 07:00:00 A—H— 6,672 c:\windows\Fontse\CGA40857.FON
2004-08-04 07:00:00 A—H— 7,232 c:\windows\Fontse\CGA40866.FON
2004-08-04 07:00:00 A—H— 7,216 c:\windows\Fontse\CGA40869.FON
2004-08-04 07:00:00 A—H— 6,336 c:\windows\Fontse\CGA40WOA.FON
2004-08-04 07:00:00 A—H— 5,168 c:\windows\Fontse\CGA80737.FON
2004-08-04 07:00:00 A—H— 4,320 c:\windows\Fontse\CGA80850.FON
2004-08-04 07:00:00 A—H— 5,200 c:\windows\Fontse\CGA80852.FON
2004-08-04 07:00:00 A—H— 4,640 c:\windows\Fontse\CGA80857.FON
2004-08-04 07:00:00 A—H— 5,168 c:\windows\Fontse\CGA80866.FON
2004-08-04 07:00:00 A—H— 5,168 c:\windows\Fontse\CGA80869.FON
2004-08-04 07:00:00 A—H— 4,304 c:\windows\Fontse\CGA80WOA.FON
2004-08-04 07:00:00 A—H— 23,440 c:\windows\Fontse\COUE1257.FON
2004-08-04 07:00:00 A—H— 31,760 c:\windows\Fontse\COUF1257.FON
2004-08-04 07:00:00 A—H— 23,408 c:\windows\Fontse\COURE.FON
2004-08-04 07:00:00 A—H— 23,440 c:\windows\Fontse\COUREE.FON
2004-08-04 07:00:00 A—H— 25,024 c:\windows\Fontse\COUREG.FON
2004-08-04 07:00:00 A—H— 23,440 c:\windows\Fontse\COURER.FON
2004-08-04 07:00:00 A—H— 25,024 c:\windows\Fontse\COURET.FON
2004-08-04 07:00:00 A—H— 31,712 c:\windows\Fontse\COURF.FON
2004-08-04 07:00:00 A—H— 31,776 c:\windows\Fontse\COURFE.FON
2004-08-04 07:00:00 A—H— 33,344 c:\windows\Fontse\COURFG.FON
2004-08-04 07:00:00 A—H— 31,808 c:\windows\Fontse\COURFR.FON
2004-08-04 07:00:00 A—H— 33,360 c:\windows\Fontse\COURFT.FON
2004-08-11 19:14:22 A–SH— 67 c:\windows\Fontse\DESKTOP.INI
2004-08-04 07:00:00 A—H— 36,336 c:\windows\Fontse\DOS737.FON
2004-08-04 07:00:00 A—H— 36,656 c:\windows\Fontse\DOSAPP.FON
2004-08-04 07:00:00 A—H— 9,248 c:\windows\Fontse\EGA40737.FON
2004-08-04 07:00:00 A—H— 8,384 c:\windows\Fontse\EGA40850.FON
2004-08-04 07:00:00 A—H— 8,368 c:\windows\Fontse\EGA40852.FON
2004-08-04 07:00:00 A—H— 8,704 c:\windows\Fontse\EGA40857.FON
2004-08-04 07:00:00 A—H— 9,232 c:\windows\Fontse\EGA40866.FON
2004-08-04 07:00:00 A—H— 9,248 c:\windows\Fontse\EGA40869.FON
2004-08-04 07:00:00 A—H— 8,368 c:\windows\Fontse\EGA40WOA.FON
2004-08-04 07:00:00 A—H— 6,192 c:\windows\Fontse\EGA80737.FON
2004-08-04 07:00:00 A—H— 5,328 c:\windows\Fontse\EGA80850.FON
2004-08-04 07:00:00 A—H— 5,344 c:\windows\Fontse\EGA80852.FON
2004-08-04 07:00:00 A—H— 5,648 c:\windows\Fontse\EGA80857.FON
2004-08-04 07:00:00 A—H— 5,280 c:\windows\Fontse\EGA80866.FON
2004-08-04 07:00:00 A—H— 6,192 c:\windows\Fontse\EGA80869.FON
2004-08-04 07:00:00 A—H— 5,312 c:\windows\Fontse\EGA80WOA.FON
2004-08-04 07:00:00 A—H— 24,124 c:\windows\Fontse\MARLETT.TTF
2004-08-04 07:00:00 A—H— 59,024 c:\windows\Fontse\SERE1257.FON
2004-08-04 07:00:00 A—H— 84,080 c:\windows\Fontse\SERF1257.FON
2004-08-04 07:00:00 A—H— 57,936 c:\windows\Fontse\SERIFE.FON
2004-08-04 07:00:00 A—H— 59,952 c:\windows\Fontse\SERIFEE.FON
2004-08-04 07:00:00 A—H— 60,752 c:\windows\Fontse\SERIFEG.FON
2004-08-04 07:00:00 A—H— 63,296 c:\windows\Fontse\SERIFER.FON
2004-08-04 07:00:00 A—H— 61,024 c:\windows\Fontse\SERIFET.FON
2004-08-04 07:00:00 A—H— 81,728 c:\windows\Fontse\SERIFF.FON
2004-08-04 07:00:00 A—H— 85,360 c:\windows\Fontse\SERIFFE.FON
2004-08-04 07:00:00 A—H— 86,256 c:\windows\Fontse\SERIFFG.FON
2004-08-04 07:00:00 A—H— 90,736 c:\windows\Fontse\SERIFFR.FON
2004-08-04 07:00:00 A—H— 84,848 c:\windows\Fontse\SERIFFT.FON
2004-08-04 07:00:00 A—H— 24,672 c:\windows\Fontse\SMAE1257.FON
2004-08-04 07:00:00 A—H— 19,904 c:\windows\Fontse\SMAF1257.FON
2004-08-04 07:00:00 A—H— 26,112 c:\windows\Fontse\SMALLE.FON
2004-08-04 07:00:00 A—H— 24,784 c:\windows\Fontse\SMALLEE.FON
2004-08-04 07:00:00 A—H— 28,912 c:\windows\Fontse\SMALLEG.FON
2004-08-04 07:00:00 A—H— 24,832 c:\windows\Fontse\SMALLER.FON
2004-08-04 07:00:00 A—H— 29,200 c:\windows\Fontse\SMALLET.FON
2004-08-04 07:00:00 A—H— 21,504 c:\windows\Fontse\SMALLF.FON
2004-08-04 07:00:00 A—H— 19,600 c:\windows\Fontse\SMALLFE.FON
2004-08-04 07:00:00 A—H— 23,120 c:\windows\Fontse\SMALLFG.FON
2004-08-04 07:00:00 A—H— 19,760 c:\windows\Fontse\SMALLFR.FON
2004-08-04 07:00:00 A—H— 23,008 c:\windows\Fontse\SMALLFT.FON
2004-08-04 07:00:00 A—H— 65,456 c:\windows\Fontse\SSEE1257.FON
2004-08-04 07:00:00 A—H— 90,336 c:\windows\Fontse\SSEF1257.FON
2004-08-04 07:00:00 A—H— 64,656 c:\windows\Fontse\SSERIFE.FON
2004-08-04 07:00:00 A—H— 66,464 c:\windows\Fontse\SSERIFEE.FON
2004-08-04 07:00:00 A—H— 65,328 c:\windows\Fontse\SSERIFEG.FON
2004-08-04 07:00:00 A—H— 68,848 c:\windows\Fontse\SSERIFER.FON
2004-08-04 07:00:00 A—H— 64,400 c:\windows\Fontse\SSERIFET.FON
2004-08-04 07:00:00 A—H— 89,856 c:\windows\Fontse\SSERIFF.FON
2004-08-04 07:00:00 A—H— 92,032 c:\windows\Fontse\SSERIFFE.FON
2004-08-04 07:00:00 A—H— 90,288 c:\windows\Fontse\SSERIFFG.FON
2004-08-04 07:00:00 A—H— 98,256 c:\windows\Fontse\SSERIFFR.FON
2004-08-04 07:00:00 A—H— 89,456 c:\windows\Fontse\SSERIFFT.FON
2004-08-04 07:00:00 A—H— 56,336 c:\windows\Fontse\SYMBOLE.FON
2004-08-04 07:00:00 A—H— 5,168 c:\windows\Fontse\VGA737.FON
2004-08-04 07:00:00 A—H— 5,168 c:\windows\Fontse\VGA775.FON
2004-08-04 07:00:00 A—H— 5,232 c:\windows\Fontse\VGA850.FON
2004-08-04 07:00:00 A—H— 6,160 c:\windows\Fontse\VGA852.FON
2004-08-04 07:00:00 A—H— 5,120 c:\windows\Fontse\VGA855.FON
2004-08-04 07:00:00 A—H— 5,552 c:\windows\Fontse\VGA857.FON
2004-08-04 07:00:00 A—H— 5,184 c:\windows\Fontse\VGA860.FON
2004-08-04 07:00:00 A—H— 5,200 c:\windows\Fontse\VGA863.FON
2004-08-04 07:00:00 A—H— 5,184 c:\windows\Fontse\VGA865.FON
2004-08-04 07:00:00 A—H— 6,128 c:\windows\Fontse\VGA866.FON
2004-08-04 07:00:00 A—H— 5,184 c:\windows\Fontse\VGA869.FON
2004-08-04 07:00:00 A—H— 5,376 c:\windows\Fontse\VGAF1257.FON
2004-08-04 07:00:00 A—H— 5,360 c:\windows\Fontse\VGAFIX.FON
2004-08-04 07:00:00 A—H— 5,376 c:\windows\Fontse\VGAFIXE.FON
2004-08-04 07:00:00 A—H— 6,112 c:\windows\Fontse\VGAFIXG.FON
2004-08-04 07:00:00 A—H— 5,600 c:\windows\Fontse\VGAFIXR.FON
2004-08-04 07:00:00 A—H— 6,112 c:\windows\Fontse\VGAFIXT.FON
2004-08-04 07:00:00 A—H— 5,168 c:\windows\Fontse\VGAOEM.FON
2004-08-04 07:00:00 A—H— 6,656 c:\windows\Fontse\VGAS1257.FON
2004-08-04 07:00:00 A—H— 7,280 c:\windows\Fontse\VGASYS.FON
2004-08-04 07:00:00 A—H— 6,608 c:\windows\Fontse\VGASYSE.FON
2004-08-04 07:00:00 A—H— 7,008 c:\windows\Fontse\VGASYSG.FON
2004-08-04 07:00:00 A—H— 6,912 c:\windows\Fontse\VGASYSR.FON
2004-08-04 07:00:00 A—H— 6,912 c:\windows\Fontse\VGASYST.FON
2005-04-29 13:54:17 A—H— 10,820 c:\windows\Helpe\update.GID
2007-02-25 12:10:46 A–S—- 2,372 c:\windows\INFe\oem20.inf
2004-08-11 19:13:34 A—H— 65 c:\windows\Offline Web Pagese\DESKTOP.INI
2004-08-04 07:00:00 A–SHR– 2,737,914 c:\windows\PCHEALTH\HELPCTR\PackageStoree\instance_Professional_32_1033.cab
2004-08-11 19:14:00 A–SHR– 727 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_1.cab
2005-01-05 14:57:43 —SHR– 21,378 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_10.cab
2005-01-05 14:57:48 —SHR– 71,564 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_11.cab
2005-01-05 14:57:55 —SHR– 657,089 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_12.cab
2005-01-05 14:58:16 —SHR– 364,090 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_13.cab
2009-08-10 08:22:44 —SHR– 309,519 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_14.cab
2009-08-10 08:24:16 —SHR– 68,704 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_15.cab
2004-08-11 19:14:00 A–SHR– 19,854 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_2.cab
2004-08-11 19:14:00 A–SHR– 244,933 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_3.cab
2004-08-04 07:00:00 A–SHR– 7,068 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_4.cab
2004-08-04 07:00:00 A–SHR– 68,327 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_5.cab
2004-08-04 07:00:00 A–SHR– 305,145 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_6.cab
2004-08-11 19:24:40 A–SHR– 68,704 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_7.cab
2005-01-05 14:56:28 —SHR– 7,166 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_8.cab
2005-01-05 14:56:43 —SHR– 7,351 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_9.cab
2004-08-11 19:15:08 A—H— 229,376 c:\windows\REPAIRe\NTUSER.DAT
2005-04-04 18:38:50 —-H— 0 c:\windows\SYSTEMe\TSCNTDWN.80
2004-08-11 19:13:26 A—HR– 749 c:\windows\SYSTEM32e\cdplayer.exe.manifest
2004-08-11 19:13:34 A—HR– 488 c:\windows\SYSTEM32e\logonui.exe.manifest
1999-09-09 22:06:38 A–S—- 252,688 c:\windows\SYSTEM32e\msexcl35.dll
1999-09-28 21:42:48 A–S—- 1,050,896 c:\windows\SYSTEM32e\msjet35.dll
1999-06-10 09:34:04 A–S—- 123,664 c:\windows\SYSTEM32e\msjint35.dll
1999-06-10 09:34:04 A–S—- 24,848 c:\windows\SYSTEM32e\msjter35.dll
1999-09-09 22:06:38 A–S—- 168,720 c:\windows\SYSTEM32e\msltus35.dll
1999-06-07 18:59:34 A–S—- 250,128 c:\windows\SYSTEM32e\mspdox35.dll
1999-04-25 17:00:00 A–S—- 252,176 c:\windows\SYSTEM32e\Msrd2x35.dll
1999-08-25 14:57:26 A–S—- 415,504 c:\windows\SYSTEM32e\msrepl35.dll
1999-09-30 19:21:24 A–S—- 166,672 c:\windows\SYSTEM32e\mstext35.dll
1999-04-25 17:00:00 A–S—- 287,504 c:\windows\SYSTEM32e\Msxbse35.dll
2004-08-11 19:13:26 A—HR– 749 c:\windows\SYSTEM32e\ncpa.cpl.manifest
2004-08-11 19:13:26 A—HR– 749 c:\windows\SYSTEM32e\nwc.cpl.manifest
2004-08-11 19:13:26 A—HR– 749 c:\windows\SYSTEM32e\sapi.cpl.manifest
1999-04-25 17:00:00 A–S—- 368,912 c:\windows\SYSTEM32e\Vbar332.dll
2004-08-11 19:13:34 A—HR– 488 c:\windows\SYSTEM32e\WindowsLogon.manifest
2004-08-11 19:13:26 A—HR– 749 c:\windows\SYSTEM32e\wuaucpl.cpl.manifest
2007-01-15 16:36:25 A—H— 4,212 c:\windows\SYSTEM32e\zllictbl_cpy.dat
2005-01-28 14:44:28 —S—- 8,520 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\codecs10.CAT
2005-01-28 14:44:28 —S—- 8,818 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\DRM10.CAT
2008-04-13 22:04:37 —S—- 34,063 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\fp4.cat
2004-08-04 07:00:00 —S—- 13,472 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\HPCRDP.CAT
2004-08-04 07:00:00 —S—- 8,574 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\IASNT4.CAT
2006-06-29 09:11:06 —S—- 10,181 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\IDNMitigationAPIs.cat
2006-11-07 22:04:24 —S—- 42,340 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\ie7.cat
2008-04-13 22:04:34 —S—- 16,535 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\ims.cat
2010-07-15 03:28:23 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2079403.cat
2010-06-15 12:43:45 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2115168.cat
2010-06-18 13:56:32 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2121546.cat
2010-08-04 05:40:48 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2141007.cat
2010-06-22 21:03:17 —S—- 7,170 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2158563.cat
2010-06-28 06:41:05 —S—- 8,158 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2160329.cat
2010-06-24 08:46:40 —S—- 31,754 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2183461-IE7.cat
2010-06-15 12:37:34 —S—- 9,146 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2229593.cat
2010-06-28 06:55:54 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2259922.cat
2010-09-01 12:21:44 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2279986.cat
2010-07-27 02:46:39 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2286198.cat
2010-08-23 12:36:18 —S—- 8,150 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2296011.cat
2010-10-28 09:20:08 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2296199.cat
2010-09-07 07:12:29 —S—- 8,864 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2345886.cat
2010-08-17 10:30:39 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2347290.cat
2010-09-09 10:09:06 —S—- 31,754 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2360131-IE7.cat
2010-08-16 05:01:08 —S—- 8,158 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2360937.cat
2010-09-06 16:20:42 —S—- 7,470 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2378111.cat
2010-09-18 03:26:24 —S—- 9,965 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2387149.cat
2010-12-09 11:29:31 —S—- 11,198 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2393802.cat
2010-11-05 20:57:46 —S—- 31,754 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2416400-IE7.cat
2010-11-09 11:09:15 —S—- 14,920 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2419632.cat
2010-10-20 09:08:05 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2423089.cat
2010-10-26 10:24:13 —S—- 8,158 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2436673.cat
2010-11-03 14:50:34 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2440591.cat
2010-11-19 01:32:06 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2443105.cat
2010-11-05 10:13:09 —S—- 7,170 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2443685.cat
2010-11-20 08:08:00 —S—- 7,154 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2467659.cat
2010-12-09 10:37:58 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2476687.cat
2010-12-20 13:30:43 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2478960.cat
2010-12-22 08:47:57 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2478971.cat
2010-12-20 19:27:25 —S—- 31,754 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2482017-IE7.cat
2005-05-04 14:45:46 —S—- 29,493 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB893803v2_wxp.cat
2005-03-21 15:00:24 —S—- 29,491 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB893803_wxp.cat
2005-05-24 11:00:54 —S—- 8,817 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB898458.cat
2006-01-03 14:17:06 —S—- 8,792 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB911564.cat
2006-03-13 16:45:34 —S—- 7,898 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB911565.cat
2006-05-04 18:37:36 —S—- 7,898 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB917734.cat
2009-03-27 03:59:12 —S—- 13,937 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB923561.cat
2006-12-07 21:30:20 —S—- 9,057 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB923689.cat
2006-08-29 17:29:20 —S—- 8,824 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB923723.cat
2006-09-13 18:32:26 —S—- 9,090 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB925398.cat
2007-01-17 15:40:04 —S—- 18,377 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB928090-IE7.cat
2006-12-22 12:53:02 —S—- 7,894 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB929969.cat
2007-04-20 14:41:50 —S—- 30,145 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB931768-IE7.cat
2007-05-08 13:21:34 —S—- 29,530 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB933566-IE7.cat
2007-05-01 02:27:14 —S—- 10,335 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB936782.cat
2007-07-19 04:20:15 —S—- 29,530 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB937143-IE7.cat
2007-07-12 19:44:36 —S—- 11,284 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB938127-IE7.cat
2008-12-19 07:56:47 —S—- 10,074 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB938464-v2.cat
2008-04-15 14:51:51 —S—- 12,305 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB938464.cat
2007-08-21 01:41:29 —S—- 30,942 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB939653-IE7.cat
2007-10-27 18:16:40 —S—- 12,090 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB941569.cat
2007-10-30 23:30:41 —S—- 30,942 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB942615-IE7.cat
2008-01-11 08:11:14 —S—- 32,354 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB944533-IE7.cat
2008-05-02 11:01:37 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB946648.cat
2008-03-01 09:54:54 —S—- 32,354 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB947864-IE7.cat
2008-05-20 08:57:26 —S—- 32,215 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB950759-IE7.cat
2008-04-24 04:12:17 —S—- 10,439 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB950760.cat
2008-05-08 17:25:36 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB950762.cat
2008-07-07 16:59:03 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB950974.cat
2008-04-11 15:18:52 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB951066.cat
2008-07-15 05:34:26 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB951072-v2.cat
2008-06-16 16:12:03 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB951376-v2.cat
2008-04-14 12:54:14 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB951376.cat
2008-05-07 01:38:53 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB951698.cat
2008-06-21 06:36:26 —S—- 18,785 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB951748.cat
2008-06-19 05:25:51 —S—- 15,271 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB951978.cat
2008-06-12 11:35:43 —S—- 19,491 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB952004.cat
2008-11-10 23:51:22 —S—- 13,031 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB952069.cat
2008-05-01 11:30:31 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB952287.cat
2008-06-24 13:04:07 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB952954.cat
2008-06-26 14:16:04 —S—- 32,215 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB953838-IE7.cat
2008-06-23 15:26:19 —S—- 10,439 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB953839.cat
2009-05-27 09:51:12 —S—- 8,327 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB954155.cat
2008-09-15 12:17:16 —S—- 12,729 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB954211.cat
2008-09-09 21:31:57 —S—- 11,145 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB954459.cat
2008-07-06 08:06:56 —S—- 16,633 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB954550-v5.cat
2008-10-03 06:46:35 —S—- 10,200 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB954600.cat
2008-09-09 23:12:10 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB955069.cat
2009-11-21 13:03:06 —S—- 11,111 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB955759.cat
2008-10-23 15:58:30 —S—- 10,200 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB955839.cat
2008-10-03 14:49:47 —S—- 29,984 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB956390-IE7.cat
2008-10-03 11:27:13 —S—- 8,208 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB956391.cat
2009-03-06 14:33:08 —S—- 29,707 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB956572.cat
2009-06-19 01:31:17 —S—- 13,466 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB956744.cat
2008-10-23 09:26:07 —S—- 10,200 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB956802.cat
2008-08-14 11:33:08 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB956803.cat
2008-08-14 11:33:34 —S—- 17,099 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB956841.cat
2009-06-23 17:40:35 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB956844.cat
2008-09-08 10:49:46 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB957095.cat
2008-10-24 11:06:44 —S—- 10,200 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB957097.cat
2008-10-16 17:28:28 —S—- 29,984 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB958215-IE7.cat
2008-10-15 13:47:09 —S—- 10,200 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB958644.cat
2008-12-11 13:01:19 —S—- 10,200 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB958687.cat
2009-02-09 11:10:55 —S—- 10,511 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB958690.cat
2009-08-13 10:09:27 —S—- 8,021 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB958869.cat
2009-03-21 13:26:47 —S—- 11,612 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB959426.cat
2008-12-05 08:36:13 —S—- 10,200 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB960225.cat
2008-12-13 03:21:48 —S—- 8,914 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB960714-IE7.cat
2009-01-15 15:26:27 —S—- 8,208 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB960715.cat
2008-12-16 09:52:12 —S—- 10,200 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB960803.cat
2009-07-01 05:32:15 —S—- 10,795 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB960859.cat
2009-01-09 15:19:04 —S—- 8,208 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB961118.cat
2009-01-20 08:31:32 —S—- 29,984 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB961260-IE7.cat
2009-06-16 11:11:02 —S—- 10,782 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB961371.cat
2008-12-20 20:08:55 —S—- 10,200 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB961373.cat
2009-05-07 11:58:55 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB961501.cat
2009-03-02 21:26:55 —S—- 31,396 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB963027-IE7.cat
2009-02-10 16:48:41 —S—- 10,566 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB967715.cat
2009-07-02 09:37:45 —S—- 18,195 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB968389.cat
2009-04-19 16:40:09 —S—- 10,713 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB968537.cat
2009-06-15 14:34:24 —S—- 8,327 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB968816.cat
2009-07-17 12:52:43 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB969059.cat
2009-04-29 02:30:35 —S—- 31,624 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB969897-IE7.cat
2009-05-08 17:40:43 —S—- 7,378 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB969898.cat
2009-08-14 13:32:02 —S—- 9,681 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB969947.cat
2009-04-15 11:54:59 —S—- 10,511 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB970238.cat
2009-10-21 02:20:16 —S—- 12,194 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB970430.cat
2009-07-16 00:28:18 —S—- 7,394 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB970653-v3.cat
2009-07-27 20:02:24 —S—- 11,148 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB971029.cat
2010-01-04 14:00:28 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB971468.cat
2009-08-04 14:04:27 —S—- 14,051 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB971486.cat
2009-06-10 11:05:54 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB971557.cat
2009-06-03 15:43:52 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB971633.cat
2009-06-10 02:48:03 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB971657.cat
2009-08-25 05:59:29 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB971737.cat
2009-08-14 01:29:45 —S—- 8,097 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB971961.cat
2009-07-19 10:48:40 —S—- 31,272 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB972260-IE7.cat
2009-10-15 13:58:37 —S—- 10,782 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB972270.cat
2009-07-07 01:47:40 —S—- 7,378 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB973346.cat
2009-07-10 11:02:30 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB973354.cat
2009-07-17 17:21:45 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB973507.cat
2009-09-09 20:50:45 —S—- 7,378 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB973525.cat
2009-07-14 16:33:04 —S—- 8,625 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB973540.cat
2009-07-31 01:16:24 —S—- 10,076 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB973687.cat
2009-08-05 05:31:23 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB973815.cat
2009-07-27 19:53:52 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB973869.cat
2009-11-21 06:25:06 —S—- 10,999 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB973904.cat
2009-08-26 04:28:20 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB974112.cat
2009-10-12 10:08:11 —S—- 10,782 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB974318.cat
2009-10-13 07:23:13 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB974392.cat
2009-08-29 04:23:40 —S—- 31,285 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB974455-IE7.cat
2009-09-04 17:35:38 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB974571.cat
2009-09-01 10:55:13 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB975025.cat
2009-09-11 11:03:45 —S—- 9,723 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB975467.cat
2010-04-05 18:56:52 —S—- 8,303 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB975558.cat
2009-11-27 13:51:20 —S—- 10,795 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB975560.cat
2009-10-23 19:54:20 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB975561.cat
2010-04-07 12:36:59 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB975562.cat
2009-12-08 05:38:37 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB975713.cat
2009-10-28 22:21:12 —S—- 7,407 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB976098-v2.cat
2009-10-29 04:35:29 —S—- 31,272 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB976325-IE7.cat
2009-10-21 01:42:47 —S—- 8,084 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB976749-IE7.cat
2009-12-09 07:05:16 —S—- 14,051 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB977165.cat
2010-01-29 10:58:34 —S—- 8,803 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB977816.cat
2009-11-27 13:13:06 —S—- 15,031 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB977914.cat
2009-12-14 03:47:45 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB978037.cat
2010-01-05 07:08:01 —S—- 31,991 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB978207-IE7.cat
2009-12-07 01:43:53 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB978251.cat
2010-01-08 10:26:08 —S—- 7,391 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB978262.cat
2010-02-12 00:57:39 —S—- 10,795 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB978338.cat
2010-01-29 11:41:45 —S—- 10,795 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB978542.cat
2009-12-24 03:18:58 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB978601.cat
2010-04-14 10:38:16 —S—- 8,299 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB978695.cat
2009-12-17 04:22:05 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB978706.cat
2010-01-23 06:51:24 —S—- 7,407 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB979306.cat
2010-01-13 10:22:54 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB979309.cat
2010-03-05 11:26:23 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB979482.cat
2010-05-02 04:42:05 —S—- 9,442 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB979559.cat
2010-03-05 12:30:54 —S—- 14,349 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB979683.cat
2010-07-16 08:36:39 —S—- 8,862 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB979687.cat
2010-03-11 09:36:42 —S—- 31,991 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB980182-IE7.cat
2010-05-05 01:25:18 —S—- 7,152 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB980195.cat
2010-04-20 02:01:28 —S—- 9,144 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB980218.cat
2010-02-25 08:51:56 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB980232.cat
2010-06-30 08:42:32 —S—- 7,858 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB980436.cat
2010-07-15 09:10:50 —S—- 7,858 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB981322.cat
2010-03-09 07:49:33 —S—- 8,097 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB981349.cat
2010-04-22 18:33:04 —S—- 7,168 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB981793.cat
2010-06-18 02:43:52 —S—- 10,490 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB981852.cat
2010-09-01 12:21:54 —S—- 8,156 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB981957.cat
2010-06-21 11:04:43 —S—- 7,858 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB981997.cat
2010-08-27 04:30:36 —S—- 7,858 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB982132.cat
2010-06-21 13:36:18 —S—- 7,858 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB982214.cat
2010-05-04 14:45:23 —S—- 31,752 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB982381-IE7.cat
2010-06-17 10:12:41 —S—- 7,858 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB982665.cat
2010-07-23 02:18:53 —S—- 8,156 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB982802.cat
2004-08-04 07:00:00 —S—- 399,645 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\MAPIMIG.CAT
2008-04-13 22:04:36 —S—- 34,747 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\mediactr.cat
2005-01-28 14:44:28 —S—- 7,626 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\MPCD10.CAT
2005-01-28 14:44:28 —S—- 7,030 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\MPPRE10.CAT
2005-01-28 14:44:28 —S—- 7,626 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\MPSTUB10.CAT
2008-04-13 22:04:35 —S—- 12,363 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\msmsgs.cat
2008-04-13 22:04:35 —S—- 26,991 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\msn7.cat
2008-04-13 22:04:36 —S—- 14,433 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\msn9.cat
2008-04-13 22:04:36 —S—- 10,027 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\mstsweb.cat
2008-07-06 08:06:57 —S—- 10,929 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\msxpsdrv.CAT
2004-08-04 07:00:00 —S—- 37,484 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\MW770.CAT
2008-04-13 22:04:39 —S—- 144,484 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\netfx.cat
2006-06-28 19:00:54 —S—- 8,420 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\NLSDownlevelMapping.cat
2008-04-13 22:04:45 —S—- 2,144,487 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\nt5.cat
2004-08-04 07:00:00 —S—- 797,189 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\NT5IIS.CAT
2008-04-13 22:04:43 —S—- 522,220 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\nt5inf.cat
2009-01-09 15:19:28 —S—- 1,089,593 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\ntprint.cat
2004-09-09 11:09:42 —S—- 16,890 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem0.CAT
2004-04-06 12:25:08 —S—- 20,362 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem1.CAT
2003-01-10 18:13:04 —S—- 7,592 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem10.CAT
2002-04-02 20:57:06 —S—- 15,263 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem14.CAT
2008-08-18 06:35:14 —S—- 19,280 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem16.CAT
2004-06-29 15:43:56 —S—- 10,316 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem2.CAT
2007-03-07 11:02:32 —S—- 11,085 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem20.CAT
2007-04-16 22:58:18 —S—- 41,586 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem21.CAT
2007-04-16 22:56:46 —S—- 17,648 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem22.CAT
2007-07-30 19:36:28 —S—- 48,256 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem23.CAT
2007-07-30 19:35:04 —S—- 17,648 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem24.CAT
2008-07-18 22:26:06 —S—- 48,117 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem25.CAT
2008-07-18 22:24:52 —S—- 17,509 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem26.CAT
2008-10-16 15:24:30 —S—- 45,886 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem27.CAT
2008-10-16 15:22:38 —S—- 15,278 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem28.CAT
2009-08-06 19:37:06 —S—- 45,056 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem29.CAT
2004-04-27 23:15:10 —S—- 14,533 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem3.CAT
2009-08-06 19:36:40 —S—- 14,448 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem30.CAT
2009-08-06 20:36:54 —S—- 45,069 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem31.CAT
2004-05-25 11:43:50 —S—- 8,227 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem4.CAT
2004-05-25 11:43:50 —S—- 9,257 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem5.CAT
2004-05-25 11:43:50 —S—- 9,265 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem6.CAT
2004-05-25 11:43:50 —S—- 9,265 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem7.CAT
2002-03-13 10:50:36 —S—- 7,172 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem9.CAT
2004-08-11 12:31:24 —S—- 7,710 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\OEMBIOS.CAT
2004-08-04 07:00:00 —S—- 1,042,903 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\SP2.CAT
2008-04-14 07:40:48 —S—- 1,296,669 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\sp3.cat
2008-04-13 22:04:37 —S—- 36,549 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\spdelta.cat
2008-04-13 22:10:46 —S—- 112,918 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\tabletpc.cat
2009-03-10 22:18:28 —S—- 7,236 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\WgaNotify.cat
2005-01-28 14:44:28 —S—- 9,116 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\WMDM10.CAT
2004-08-04 07:00:00 —S—- 7,334 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\wmerrenu.cat
2005-01-28 14:44:28 —S—- 11,202 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\WMFSDK10.CAT
2005-01-28 14:44:28 —S—- 14,432 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\WMP10.CAT
2005-01-28 14:44:28 —S—- 7,328 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\WMSET10.CAT
2005-01-28 14:44:28 —S—- 10,598 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\WPD10.CAT
2009-03-10 22:18:28 —S—- 7,236 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\_000000_.cat
2010-04-18 09:04:39 A—H— 0 c:\windows\SYSTEM32\CONFIGe\DEFAULT.tmp.LOG
2010-04-18 09:04:39 A—H— 0 c:\windows\SYSTEM32\CONFIGe\SAM.tmp.LOG
2010-04-18 11:03:42 A—H— 8,192 c:\windows\SYSTEM32\CONFIGe\SECURITY.tmp.LOG
2010-04-18 09:04:38 A—H— 0 c:\windows\SYSTEM32\CONFIGe\SOFTWARE.tmp.LOG
2010-04-18 09:04:38 A—H— 0 c:\windows\SYSTEM32\CONFIGe\SYSTEM.tmp.LOG
2004-08-11 19:06:14 A—H— 1,024 c:\windows\SYSTEM32\CONFIGe\TempKey.LOG
2004-08-11 19:06:14 A—H— 1,024 c:\windows\SYSTEM32\CONFIGe\USERDIFF.LOG
2010-04-18 08:59:17 A—H— 1,024 c:\windows\SYSTEM32\CONFIG\systemprofilee\NTUSER.DAT.LOG
2004-08-11 19:07:12 A–SH— 62 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Datae\DESKTOP.INI
2010-09-22 10:01:51 A–S—- 30,704 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\0797C381B2F87EB5A1D5573BD15BA4F4
2010-06-09 16:21:23 A–S—- 2,202 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\0897206B35294097C3660E62BCDB227C
2010-09-20 09:44:21 A–S—- 2,594 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\23B523C9E7746F715D33C6527C18EB9D
2010-04-22 16:34:04 A–S—- 341 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\303572DF538EDD8B1D606185F1D559B8
2010-06-09 16:21:23 A–S—- 1,294 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\3C19F8F5C2A69BEC912EF5B953293907
2010-04-12 08:50:30 A–S—- 242,756 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\4DB1DABDF57ED9997FE8DCC77E93C04F
2010-06-09 16:20:54 A–S—- 781 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\696F3DE637E6DE85B458996D49D759AD
2010-04-22 16:34:04 A–S—- 413 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\79841F8EF00FBA86D33CC5A47696F165
2006-01-30 09:18:41 A–S—- 1,047 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\7C8A03C4580C6B04FDF34357F3474EDC
2010-06-09 16:20:54 A–S—- 597 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\A1377F7115F1F126A15360369B165211
2010-10-07 16:48:15 A–S—- 558 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\A44F4E7CB3133FF765C39A53AD8FCFDD
2006-01-30 09:18:41 A–S—- 1,370 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\B82262A5D5DA4DDACE9EDA7F787D0DEB
2007-04-06 08:04:04 A–S—- 1,039 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\CFC456E7E410D69E2C6F3E2DB75C7DB3
2010-09-20 09:44:21 A–S—- 1,310 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\D0F063B6B88A2B8BFE21C3993A613447
2009-08-10 08:22:45 A–S—- 574 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\E04822AD18D472EA5B582E6E6F8C6B9A
2010-04-13 09:03:29 A–S—- 2,148 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\F03FBEED31BB9347A2DDFF031058505F
2010-09-22 10:01:51 A–S—- 132 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\0797C381B2F87EB5A1D5573BD15BA4F4
2010-06-09 16:21:23 A–S—- 194 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\0897206B35294097C3660E62BCDB227C
2010-09-20 09:44:21 A–S—- 112 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\23B523C9E7746F715D33C6527C18EB9D
2010-04-22 16:34:04 A–S—- 126 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\303572DF538EDD8B1D606185F1D559B8
2010-06-09 16:21:23 A–S—- 126 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\3C19F8F5C2A69BEC912EF5B953293907
2010-04-12 08:50:30 A–S—- 98 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\4DB1DABDF57ED9997FE8DCC77E93C04F
2010-06-09 16:20:54 A–S—- 156 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\696F3DE637E6DE85B458996D49D759AD
2010-04-22 16:34:04 A–S—- 98 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\79841F8EF00FBA86D33CC5A47696F165
2006-01-30 09:18:41 A–S—- 126 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\7C8A03C4580C6B04FDF34357F3474EDC
2010-06-09 16:20:54 A–S—- 142 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\A1377F7115F1F126A15360369B165211
2010-10-07 16:48:15 A–S—- 146 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\A44F4E7CB3133FF765C39A53AD8FCFDD
2006-01-30 09:18:41 A–S—- 194 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\B82262A5D5DA4DDACE9EDA7F787D0DEB
2007-04-06 08:04:04 A–S—- 126 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\CFC456E7E410D69E2C6F3E2DB75C7DB3
2010-09-20 09:44:21 A–S—- 178 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\D0F063B6B88A2B8BFE21C3993A613447
2009-08-10 08:22:45 A–S—- 140 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\E04822AD18D472EA5B582E6E6F8C6B9A
2010-04-13 09:03:29 A–S—- 132 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\F03FBEED31BB9347A2DDFF031058505F
2004-08-11 19:20:34 A–SH— 2,570 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\Internet Explorere\Desktop.htt
2004-08-11 19:20:44 A–SH— 119 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\Internet Explorer\Quick Launche\DESKTOP.INI
2005-01-05 15:04:36 A–SH— 24 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\Protecte\CREDHIST
2005-01-05 15:04:36 A–SH— 388 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\Protect\S-1-5-21-4073680847-1405297832-2471763517-500e\202d2b84-66f5-4e75-b822-5327038c8418
2005-01-05 15:04:36 A–SH— 24 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\Protect\S-1-5-21-4073680847-1405297832-2471763517-500e\Preferred
2004-08-11 19:20:42 A–SH— 122 c:\windows\SYSTEM32\CONFIG\systemprofile\Favoritese\Desktop.ini
2005-01-05 15:12:38 A–SH— 62 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settingse\DESKTOP.INI
2005-01-05 15:13:11 A—H— 3,780,440 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Application Datae\IconCache.db
2005-01-05 15:13:16 A—H— 262,144 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Application Data\Microsoft\Windowse\UsrClass.dat
2010-09-22 09:36:43 A—H— 1,024 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Application Data\Microsoft\Windowse\UsrClass.dat.LOG
2004-08-11 19:20:42 A–SH— 84 c:\windows\SYSTEM32\CONFIG\systemprofile\My Documentse\DESKTOP.INI
2004-08-11 19:20:42 A–SH— 189 c:\windows\SYSTEM32\CONFIG\systemprofile\My Documents\My Musice\Desktop.ini
2004-08-11 19:20:42 A–SH— 191 c:\windows\SYSTEM32\CONFIG\systemprofile\My Documents\My Picturese\Desktop.ini
2004-08-11 19:20:42 A–SH— 150 c:\windows\SYSTEM32\CONFIG\systemprofile\Recente\Desktop.ini
2004-08-11 19:13:36 A–SH— 181 c:\windows\SYSTEM32\CONFIG\systemprofile\SendToe\DESKTOP.INI
2004-08-11 19:07:12 A–SH— 62 c:\windows\SYSTEM32\CONFIG\systemprofile\Start Menue\DESKTOP.INI
2004-08-11 19:20:44 A–SH— 234 c:\windows\SYSTEM32\CONFIG\systemprofile\Start Menu\Programse\DESKTOP.INI
2004-08-11 19:20:38 A–SH— 542 c:\windows\SYSTEM32\CONFIG\systemprofile\Start Menu\Programs\Accessoriese\DESKTOP.INI
2004-08-11 19:15:06 A–SH— 348 c:\windows\SYSTEM32\CONFIG\systemprofile\Start Menu\Programs\Accessories\Accessibilitye\DESKTOP.INI
2004-08-11 19:15:06 A–SH— 84 c:\windows\SYSTEM32\CONFIG\systemprofile\Start Menu\Programs\Accessories\Entertainmente\DESKTOP.INI
2004-08-11 19:15:06 A–SH— 84 c:\windows\SYSTEM32\CONFIG\systemprofile\Start Menu\Programs\Startupe\DESKTOP.INI
2007-02-25 12:10:48 A–S—- 5,376 c:\windows\SYSTEM32\DRIVERSe\dsunidrv.sys
2009-05-19 07:34:35 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\10a0dd3d-1243-413a-af4c-2700575aed74
2008-02-19 09:24:30 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\5155bff1-cf26-4a83-b1ef-daa19de0c2ef
2006-08-22 08:18:13 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\53e883ae-956c-45fc-b73b-296992ab389a
2007-08-21 08:10:38 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\59b8af98-e04a-447e-897d-b724c5371c7c
2010-05-18 07:46:01 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\5fb6150b-1e79-417e-8342-5cb2d7a11cd8
2010-11-15 08:39:32 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\5fc84818-3d64-4864-9045-51e2e75c9cdc
2007-02-20 09:25:13 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\69ce5cd2-5a40-403e-997f-7d4180998931
2009-08-17 07:56:08 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\8a97635a-97e9-41d5-8e74-b198f1cd7ed2
2008-05-20 12:10:45 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\9b7fedbe-d66b-4251-8f01-57c2e2c042dc
2009-11-16 08:56:40 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\a934cd14-fb0d-458f-9a4e-52585782fa41
2007-05-22 09:25:24 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\aefb63ba-1f72-4d43-9483-dbfa08dc0c7e
2008-11-17 08:49:23 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\c471253b-3b65-47e0-8fb9-662ed949d73b
2008-08-19 08:09:46 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\d26d0e97-5480-4696-89eb-f9dba0d75677
2007-11-19 09:12:04 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\dfe57563-88ba-4849-b0c7-be9a1f70ad0c
2010-02-16 08:57:47 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\e64e888d-ec07-46fb-ac7a-c6dcd87e0465
2006-11-20 09:20:10 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\ea4dbf83-82ac-4225-9f16-823237d49fd6
2010-08-17 07:38:41 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\f8f959af-8c6a-4384-8bdb-f419ea5e7e08
2009-02-17 08:52:28 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\fdef9a0b-550d-46d2-aa90-e6ae46e48aa8
2010-01-11 17:35:22 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\05bc76cd-4e7a-416f-9cd0-ed992ccf2f59
2010-04-12 16:30:36 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\091b4593-52ef-4a6a-a1e1-bd8e7f1fc02a
2006-07-06 08:08:40 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\0dd0d6bb-450d-48c9-9478-14444f798fca
2007-10-01 15:22:33 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\17ae5c58-ce18-45c9-aa11-40538c278e7e
2008-07-01 16:43:10 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\1a807fd2-2448-4763-b35d-3caac0bbf067
2006-10-05 08:13:06 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\1e169ea5-1596-4f1e-a132-69594f3c0f6c
2008-04-01 16:30:33 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\3c2955d7-efc9-426c-bcd4-c48148b8ef9e
2009-01-05 17:30:34 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\6d9d023e-4565-40c3-a6e8-5a0b07addb7b
2008-01-02 11:53:35 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\756d5e01-92c1-42ee-9159-52616698f301
2007-07-02 17:19:08 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\7f5d469c-51d8-4044-90d1-61fcb1c4b46e
2010-07-12 16:30:10 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\801f4ec4-52c1-43bd-8c38-6c19657f9087
2006-01-04 17:28:00 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\88436881-c4dc-454b-8944-4907c75a2715
2005-01-07 13:02:05 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\9802f62f-7131-40f8-9253-0d179a4f04a8
2005-01-07 13:02:05 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\b32bff2c-e984-4293-8eaa-1f752d57008e
2009-07-13 08:19:29 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\bbecb165-a411-4fa9-932e-6ed681f14b68
2005-10-06 15:06:58 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\be42e465-1bac-4c0b-a072-6449800fd309
2007-01-03 10:16:54 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\c8311a89-e381-4fb9-9ecb-fc44da3c1071
2005-04-07 17:03:01 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\ca79ec33-5d19-4a09-ab26-0a07e94c915c
2007-04-03 16:43:19 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\d7323d93-3aa4-429f-a503-ddf30494fa5e
2005-07-07 16:29:50 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\d8d82f1d-0933-4e3b-bca9-449c85451557
2008-09-30 16:33:00 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\e65c2b97-0284-426c-9644-49b15ea559d7
2010-10-12 07:59:24 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\eeafe90e-5355-4ecd-8995-1ebcb3c87e60
2005-01-07 13:02:05 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\ef583787-f66e-4878-b421-79f03e060f33
2009-10-13 16:29:33 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\f06a9100-141c-427a-b13d-f40857ccdbb7
2009-04-06 16:41:22 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\fab2f95c-37aa-48e9-a7ee-b67b65a2d184
2006-04-05 16:31:04 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\fe34b83d-fc01-4ecd-83a4-5a2ae3bb7204
2006-12-28 15:01:31 —SHR– 19,569 c:\windows\SYSTEM32\Restoree\filelist.xml
2004-08-04 07:00:00 —-HR– 65 c:\windows\Taskse\DESKTOP.INI
2008-01-08 13:15:07 A—H— 8,628 c:\windows\TWAIN_32\BrMfSc05\Lange\BrS04Usa.GID
============= FINISH: 16:06:04.64 ===============