This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Log Provided Please Advise

56 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My comp got the sniffles. Any help is greatly appreciated.

Logfile of HijackThis v1.99.1
Scan saved at 11:36:37 PM, on 2/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\system32\devldr32.exe
C:\Updater.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe
C:\Program Files\Logitech\Profiler\lwemon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Belkin\Nostromo\nost_LM.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Documents and Settings\Administrator\Desktop\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
O2 - BHO: Trend Micro Antifraud Toolbar - {06647158-359E-4D10-A8DE-E6145DA90BE9} - C:\PROGRA~1\TRENDM~1\INTERN~1\PccIeBar.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yvakt Class - {0DEADE31-9A37-48B2-921A-7825EA93D32A} - C:\WINDOWS\system32\wdc1n.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Trend Micro Antifraud Toolbar - {871F91FD-3A92-4988-A842-16AB2CFF5AF1} - C:\PROGRA~1\TRENDM~1\INTERN~1\PccIeBar.dll
O4 - HKCU\..\Run: [CU1] C:\Program Files\Common Files\VCClient\VCClient.exe
O4 - HKCU\..\Run: [CU2] C:\Program Files\Common Files\VCClient\VCMain.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O13 - DefaultPrefix:
O13 - WWW Prefix:
O13 - Home Prefix:
O13 - Mosaic Prefix:
O13 - FTP Prefix:
O13 - Gopher Prefix:
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.popuppers.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1131900569468
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O18 - Filter: text/html - {BA576CDE-9949-4473-A8F7-6C17C2A7E600} - C:\WINDOWS\system32\wdc1n.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)

I also did Ewido, and bought/ installed Trend, Spy Sweeper, and a full version of XP Pro this weekend. Most seems ok, but my start button still doesn't say start, and everytime I shutdown the computer it goes into a "dump physical memory" screen.


Hello Forced, welcome to the TC Forums.

Can you post a new HJT log along with the results of the Ewido and Spysweeper scans?
Logfile of HijackThis v1.99.1
Scan saved at 9:56:09 PM, on 3/6/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Logitech\Profiler\lwemon.exe
C:\Program Files\Belkin\Nostromo\nost_LM.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trillian\trillian.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Administrator\Desktop\Hijackthis\HijackThis.exe

O2 - BHO: Trend Micro Antifraud Toolbar - {06647158-359E-4D10-A8DE-E6145DA90BE9} - C:\PROGRA~1\TRENDM~1\INTERN~1\PccIeBar.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Trend Micro Antifraud Toolbar - {871F91FD-3A92-4988-A842-16AB2CFF5AF1} - C:\PROGRA~1\TRENDM~1\INTERN~1\PccIeBar.dll
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CU1] C:\Program Files\Common Files\VCClient\VCClient.exe
O4 - HKCU\..\Run: [CU2] C:\Program Files\Common Files\VCClient\VCMain.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1141513544069
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1131900569468
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)
I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove if listed:
VCClient



Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CU1] C:\Program Files\Common Files\VCClient\VCClient.exe
O4 - HKCU\..\Run: [CU2] C:\Program Files\Common Files\VCClient\VCMain.exe


Close ALL windows and browsers except HijackThis and click "Fix checked"


Delete these Files if listed:
C:\Program Files\Common Files\VCClient\VCClient.exe
C:\Program Files\Common Files\VCClient\VCMain.exe




Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
This program is for XP and Windows 2000 only
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
——————————————————— ewido anti-malware - Scan report ——————————————————— + Created on: 10:14:52 PM, 3/6/2006 + Report-Checksum: 125172B3 + Scan result: C:\Documents and Settings\Administrator\Cookies\administrator@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned with backup C:\Documents and Settings\Administrator\Cookies\administrator@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup ::Report End Spy Sweeper is still running. I will perform the tasks indicated above as soon as it gets done. As far as how the computer is running…. I was able to play BF2 tonight without a hitch. That is a plus. My start button doesn't say start. I think that is a remnant of the sniffles that the CPU caught…you know like a nice genital wart. My "My Computer" icon was replaced with a "My Network Places" icon, which was never left on my desktop. I always get rid of it when I do an install. The icons in my taskbar are huge. Going into the options and choosing "small icons" does nothing. Every once and a while my computer winds up for no reason…as if I were scanning, or doing a defrag. Wierd indeed. Oh Spy Sweep is done: no log file, but it found the same two cookies as Ewido. BRB after doin the stuff…
Logfile of HijackThis v1.99.1
Scan saved at 10:30:35 PM, on 3/6/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Logitech\Profiler\lwemon.exe
C:\Program Files\Belkin\Nostromo\nost_LM.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Administrator\Desktop\Hijackthis\HijackThis.exe

O2 - BHO: Trend Micro Antifraud Toolbar - {06647158-359E-4D10-A8DE-E6145DA90BE9} - C:\PROGRA~1\TRENDM~1\INTERN~1\PccIeBar.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Trend Micro Antifraud Toolbar - {871F91FD-3A92-4988-A842-16AB2CFF5AF1} - C:\PROGRA~1\TRENDM~1\INTERN~1\PccIeBar.dll
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1141513544069
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1131900569468
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)


VCC was not listed in the ADD/REMOVE Programs app

Just for giggles…what is it

and BTW….thanks a ton. You guys and gals are doing a great thing here
Name Status Filename Description
VCClient.exe Associated with the Surf Sidekick adware and should be removed. This file is located in the Program Files\Common Files\VCClient folder

Let me know if either one of these worked.

1. Click Start, and then click Control Panel.
2. Double-click Display, click the Desktop tab, and then click Customize Desktop.
3. Select Restore Defaults


1. Click Start, and then click Control Panel.
2. Double-click Display, click the Desktop tab, and then click Customize Desktop.
then click the web tab, then under the web pages to display on your desktop
if it has "security" you uncheck this and delete
Program Files\Common Files\VCClient folder <—— Not there Let me know if either one of these worked. <—— did not work, security not present
Please go to Task Manager > File > Run and and type copy/paste in this line:

regedit.exe /e c:\export.txt "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe"


Then hit enter.

Then use Notepad to go to c:\export.txt

If you cannot find the file, please let me know that fact.

Paste the results here.
copy and pasted entire string in "RUN" regedit.exe /e c:\export.txt "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe" no file located on C:
I did the export reg file the manula way Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options Class Name: Last Write Time: 3/4/2006 - 5:00 PM Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\apitrap.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ASSTE.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVSTE.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cleanup.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cqw32.exe Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: ApplicationGoo Type: REG_BINARY Data: 00000000 14 02 00 00 10 02 00 00 - 00 02 00 00 90 04 34 00 …………..4. 00000010 00 00 56 00 53 00 5f 00 - 56 00 45 00 52 00 53 00 ..V.S._.V.E.R.S. 00000020 49 00 4f 00 4e 00 5f 00 - 49 00 4e 00 46 00 4f 00 I.O.N._.I.N.F.O. 00000030 00 00 00 00 bd 04 ef fe - 00 00 01 00 00 00 07 00 ….½.ïþ…….. 00000040 0b 00 00 00 00 00 07 00 - 0b 00 00 00 3f 00 00 00 …………?… 00000050 02 00 00 00 04 00 01 00 - 01 00 00 00 00 00 00 00 ……………. 00000060 00 00 00 00 00 00 00 00 - 44 00 00 00 01 00 56 00 ……..D…..V. 00000070 61 00 72 00 46 00 69 00 - 6c 00 65 00 49 00 6e 00 a.r.F.i.l.e.I.n. 00000080 66 00 6f 00 00 00 00 00 - 24 00 04 00 00 00 54 00 f.o…..$…..T. 00000090 72 00 61 00 6e 00 73 00 - 6c 00 61 00 74 00 69 00 r.a.n.s.l.a.t.i. 000000a0 6f 00 6e 00 00 00 00 00 - 09 04 e4 04 f0 03 00 00 o.n….. .ä.ð… 000000b0 01 00 53 00 74 00 72 00 - 69 00 6e 00 67 00 46 00 ..S.t.r.i.n.g.F. 000000c0 69 00 6c 00 65 00 49 00 - 6e 00 66 00 6f 00 00 00 i.l.e.I.n.f.o… 000000d0 cc 03 00 00 01 00 30 00 - 34 00 30 00 39 00 30 00 Ì…..0.4.0.9.0. 000000e0 34 00 45 00 34 00 00 00 - 4a 00 19 00 01 00 43 00 4.E.4…J…..C. 000000f0 6f 00 6d 00 6d 00 65 00 - 6e 00 74 00 73 00 00 00 o.m.m.e.n.t.s… 00000100 43 00 72 00 79 00 73 00 - 74 00 61 00 6c 00 20 00 C.r.y.s.t.a.l. . 00000110 53 00 51 00 4c 00 20 00 - 44 00 65 00 73 00 69 00 S.Q.L. .D.e.s.i. 00000120 67 00 6e 00 65 00 72 00 - 20 00 37 00 2e 00 30 00 g.n.e.r. .7…0. 00000130 00 00 00 00 88 00 34 00 - 01 00 43 00 6f 00 6d 00 ……4…C.o.m. 00000140 70 00 61 00 6e 00 79 00 - 4e 00 61 00 6d 00 65 00 p.a.n.y.N.a.m.e. 00000150 00 00 00 00 53 00 65 00 - 61 00 67 00 61 00 74 00 ….S.e.a.g.a.t. 00000160 65 00 20 00 53 00 6f 00 - 66 00 74 00 77 00 61 00 e. .S.o.f.t.w.a. 00000170 72 00 65 00 20 00 49 00 - 6e 00 66 00 6f 00 72 00 r.e. .I.n.f.o.r. 00000180 6d 00 61 00 74 00 69 00 - 6f 00 6e 00 20 00 4d 00 m.a.t.i.o.n. .M. 00000190 61 00 6e 00 61 00 67 00 - 65 00 6d 00 65 00 6e 00 a.n.a.g.e.m.e.n. 000001a0 74 00 20 00 47 00 72 00 - 6f 00 75 00 70 00 2c 00 t. .G.r.o.u.p.,. 000001b0 20 00 49 00 6e 00 63 00 - 2e 00 00 00 ae 00 45 00 .I.n.c…..®.E. 000001c0 01 00 4c 00 65 00 67 00 - 61 00 6c 00 43 00 6f 00 ..L.e.g.a.l.C.o. 000001d0 70 00 79 00 72 00 69 00 - 67 00 68 00 74 00 00 00 p.y.r.i.g.h.t… 000001e0 43 00 6f 00 70 00 79 00 - 72 00 69 00 67 00 68 00 C.o.p.y.r.i.g.h. 000001f0 74 00 20 00 28 00 63 00 - 29 00 20 00 31 00 39 00 t. .(.c.). .1.9. 00000200 39 00 31 00 2d 00 31 00 - 39 00 39 00 10 00 00 00 9.1.-.1.9.9….. 00000210 00 00 00 00 …. Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divxdec.ax Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DJSMAR00.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DRMINST.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\enc98.EXE Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: DisableHeapLookAside Type: REG_SZ Data: 1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EncodeDivXExt.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EncryptPatchVer.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\front.exe Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: ApplicationGoo Type: REG_BINARY Data: 00000000 54 09 00 00 54 02 00 00 - 00 02 00 00 8c 03 34 00 T ..T………4. 00000010 00 00 56 00 53 00 5f 00 - 56 00 45 00 52 00 53 00 ..V.S._.V.E.R.S. 00000020 49 00 4f 00 4e 00 5f 00 - 49 00 4e 00 46 00 4f 00 I.O.N._.I.N.F.O. 00000030 00 00 00 00 bd 04 ef fe - 00 00 01 00 02 00 a8 11 ….½.ïþ……¨. 00000040 2e 04 00 00 02 00 a8 11 - 2e 04 00 00 3f 00 00 00 ……¨…..?… 00000050 20 00 00 00 04 00 00 00 - 01 00 00 00 00 00 00 00 …………… 00000060 00 00 00 00 00 00 00 00 - ec 02 00 00 01 00 53 00 ……..ì…..S. 00000070 74 00 72 00 69 00 6e 00 - 67 00 46 00 69 00 6c 00 t.r.i.n.g.F.i.l. 00000080 65 00 49 00 6e 00 66 00 - 6f 00 00 00 c8 02 00 00 e.I.n.f.o…È… 00000090 01 00 30 00 30 00 30 00 - 30 00 30 00 34 00 62 00 ..0.0.0.0.0.4.b. 000000a0 30 00 00 00 38 00 10 00 - 01 00 43 00 6f 00 6d 00 0…8…..C.o.m. 000000b0 6d 00 65 00 6e 00 74 00 - 73 00 00 00 4f 00 72 00 m.e.n.t.s…O.r. 000000c0 69 00 67 00 6e 00 61 00 - 6c 00 20 00 56 00 65 00 i.g.n.a.l. .V.e. 000000d0 72 00 73 00 69 00 6f 00 - 6e 00 00 00 42 00 11 00 r.s.i.o.n…B… 000000e0 01 00 43 00 6f 00 6d 00 - 70 00 61 00 6e 00 79 00 ..C.o.m.p.a.n.y. 000000f0 4e 00 61 00 6d 00 65 00 - 00 00 00 00 53 00 41 00 N.a.m.e…..S.A. 00000100 50 00 20 00 41 00 47 00 - 2c 00 20 00 57 00 61 00 P. .A.G.,. .W.a. 00000110 6c 00 6c 00 64 00 6f 00 - 72 00 66 00 00 00 00 00 l.l.d.o.r.f….. 00000120 5a 00 19 00 01 00 46 00 - 69 00 6c 00 65 00 44 00 Z…..F.i.l.e.D. 00000130 65 00 73 00 63 00 72 00 - 69 00 70 00 74 00 69 00 e.s.c.r.i.p.t.i. 00000140 6f 00 6e 00 00 00 00 00 - 53 00 41 00 50 00 20 00 o.n…..S.A.P. . 00000150 46 00 72 00 6f 00 6e 00 - 74 00 65 00 6e 00 64 00 F.r.o.n.t.e.n.d. 00000160 20 00 66 00 6f 00 72 00 - 20 00 57 00 69 00 6e 00 .f.o.r. .W.i.n. 00000170 64 00 6f 00 77 00 73 00 - 00 00 00 00 3c 00 0e 00 d.o.w.s…..<… 00000180 01 00 46 00 69 00 6c 00 - 65 00 56 00 65 00 72 00 ..F.i.l.e.V.e.r. 00000190 73 00 69 00 6f 00 6e 00 - 00 00 00 00 34 00 35 00 s.i.o.n…..4.5. 000001a0 32 00 30 00 2e 00 32 00 - 2e 00 30 00 2e 00 31 00 2.0…2…0…1. 000001b0 30 00 37 00 30 00 00 00 - 32 00 09 00 01 00 49 00 0.7.0…2. …I. 000001c0 6e 00 74 00 65 00 72 00 - 6e 00 61 00 6c 00 4e 00 n.t.e.r.n.a.l.N. 000001d0 61 00 6d 00 65 00 00 00 - 46 00 45 00 57 00 46 00 a.m.e…F.E.W.F. 000001e0 52 00 4f 00 4e 00 54 00 - 00 00 00 00 7a 00 2b 00 R.O.N.T…..z.+. 000001f0 01 00 4c 00 65 00 67 00 - 61 00 6c 00 43 00 6f 00 ..L.e.g.a.l.C.o. 00000200 70 00 79 00 72 00 69 00 - 67 00 68 00 02 00 00 00 p.y.r.i.g.h….. 00000210 00 00 00 00 01 00 00 00 - 4c 00 00 00 3c fd 06 00 ……..L…<ý.. 00000220 04 00 00 00 00 00 00 00 - 65 05 00 00 02 00 00 00 ……..e……. 00000230 03 00 00 00 00 00 01 00 - 53 00 65 00 72 00 76 00 ……..S.e.r.v. 00000240 69 00 63 00 65 00 20 00 - 50 00 61 00 63 00 6b 00 i.c.e. .P.a.c.k. 00000250 20 00 33 00 00 00 23 00 - 54 02 00 00 00 02 00 00 .3…#.T……. 00000260 8c 03 34 00 00 00 56 00 - 53 00 5f 00 56 00 45 00 ..4…V.S._.V.E. 00000270 52 00 53 00 49 00 4f 00 - 4e 00 5f 00 49 00 4e 00 R.S.I.O.N._.I.N. 00000280 46 00 4f 00 00 00 00 00 - bd 04 ef fe 00 00 01 00 F.O…..½.ïþ…. 00000290 03 00 9e 11 26 04 00 00 - 03 00 9e 11 26 04 00 00 ….&…….&… 000002a0 3f 00 00 00 20 00 00 00 - 04 00 00 00 01 00 00 00 ?… ……….. 000002b0 00 00 00 00 00 00 00 00 - 00 00 00 00 ec 02 00 00 …………ì… 000002c0 01 00 53 00 74 00 72 00 - 69 00 6e 00 67 00 46 00 ..S.t.r.i.n.g.F. 000002d0 69 00 6c 00 65 00 49 00 - 6e 00 66 00 6f 00 00 00 i.l.e.I.n.f.o… 000002e0 c8 02 00 00 01 00 30 00 - 30 00 30 00 30 00 30 00 È…..0.0.0.0.0. 000002f0 34 00 62 00 30 00 00 00 - 38 00 10 00 01 00 43 00 4.b.0…8…..C. 00000300 6f 00 6d 00 6d 00 65 00 - 6e 00 74 00 73 00 00 00 o.m.m.e.n.t.s… 00000310 4f 00 72 00 69 00 67 00 - 6e 00 61 00 6c 00 20 00 O.r.i.g.n.a.l. . 00000320 56 00 65 00 72 00 73 00 - 69 00 6f 00 6e 00 00 00 V.e.r.s.i.o.n… 00000330 42 00 11 00 01 00 43 00 - 6f 00 6d 00 70 00 61 00 B…..C.o.m.p.a. 00000340 6e 00 79 00 4e 00 61 00 - 6d 00 65 00 00 00 00 00 n.y.N.a.m.e….. 00000350 53 00 41 00 50 00 20 00 - 41 00 47 00 2c 00 20 00 S.A.P. .A.G.,. . 00000360 57 00 61 00 6c 00 6c 00 - 64 00 6f 00 72 00 66 00 W.a.l.l.d.o.r.f. 00000370 00 00 00 00 5a 00 19 00 - 01 00 46 00 69 00 6c 00 ….Z…..F.i.l. 00000380 65 00 44 00 65 00 73 00 - 63 00 72 00 69 00 70 00 e.D.e.s.c.r.i.p. 00000390 74 00 69 00 6f 00 6e 00 - 00 00 00 00 53 00 41 00 t.i.o.n…..S.A. 000003a0 50 00 20 00 46 00 72 00 - 6f 00 6e 00 74 00 65 00 P. .F.r.o.n.t.e. 000003b0 6e 00 64 00 20 00 66 00 - 6f 00 72 00 20 00 57 00 n.d. .f.o.r. .W. 000003c0 69 00 6e 00 64 00 6f 00 - 77 00 73 00 00 00 00 00 i.n.d.o.w.s….. 000003d0 3c 00 0e 00 01 00 46 00 - 69 00 6c 00 65 00 56 00 <…..F.i.l.e.V. 000003e0 65 00 72 00 73 00 69 00 - 6f 00 6e 00 00 00 00 00 e.r.s.i.o.n….. 000003f0 34 00 35 00 31 00 30 00 - 2e 00 33 00 2e 00 30 00 [removed]…3…0. 00000400 2e 00 31 00 30 00 36 00 - 32 00 00 00 32 00 09 00 ..[removed]…2. . 00000410 01 00 49 00 6e 00 74 00 - 65 00 72 00 6e 00 61 00 ..I.n.t.e.r.n.a. 00000420 6c 00 4e 00 61 00 6d 00 - 65 00 00 00 46 00 45 00 l.N.a.m.e…F.E. 00000430 57 00 46 00 52 00 4f 00 - 4e 00 54 00 00 00 00 00 W.F.R.O.N.T….. 00000440 7a 00 2b 00 01 00 4c 00 - 65 00 67 00 61 00 6c 00 z.+…L.e.g.a.l. 00000450 43 00 6f 00 70 00 79 00 - 72 00 69 00 67 00 68 00 C.o.p.y.r.i.g.h. 00000460 02 00 00 00 00 00 00 00 - 01 00 00 00 4c 00 00 00 …………L… 00000470 3c fd 06 00 04 00 00 00 - 00 00 00 00 65 05 00 00 <ý……….e… 00000480 02 00 00 00 03 00 00 00 - 00 00 01 00 53 00 65 00 …………S.e. 00000490 72 00 76 00 69 00 63 00 - 65 00 20 00 50 00 61 00 r.v.i.c.e. .P.a. 000004a0 63 00 6b 00 20 00 33 00 - 00 00 23 00 54 02 00 00 c.k. .3…#.T… 000004b0 00 02 00 00 20 03 34 00 - 00 00 56 00 53 00 5f 00 …. .4…V.S._. 000004c0 56 00 45 00 52 00 53 00 - 49 00 4f 00 4e 00 5f 00 V.E.R.S.I.O.N._. 000004d0 49 00 4e 00 46 00 4f 00 - 00 00 00 00 bd 04 ef fe I.N.F.O…..½.ïþ 000004e0 00 00 01 00 00 00 04 00 - f0 03 00 00 00 00 04 00 ……..ð……. 000004f0 f0 03 00 00 3f 00 00 00 - 00 00 00 00 04 00 01 00 ð…?……….. 00000500 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 00000510 7e 02 00 00 01 00 53 00 - 74 00 72 00 69 00 6e 00 ~…..S.t.r.i.n. 00000520 67 00 46 00 69 00 6c 00 - 65 00 49 00 6e 00 66 00 g.F.i.l.e.I.n.f. 00000530 6f 00 00 00 5a 02 00 00 - 01 00 30 00 34 00 30 00 o…Z…..0.4.0. 00000540 39 00 30 00 34 00 45 00 - 34 00 00 00 2e 00 07 00 9.0.4.E.4……. 00000550 01 00 43 00 6f 00 6d 00 - 70 00 61 00 6e 00 79 00 ..C.o.m.p.a.n.y. 00000560 4e 00 61 00 6d 00 65 00 - 00 00 00 00 53 00 41 00 N.a.m.e…..S.A. 00000570 50 00 20 00 41 00 47 00 - 00 00 00 00 5a 00 19 00 P. .A.G…..Z… 00000580 01 00 46 00 69 00 6c 00 - 65 00 44 00 65 00 73 00 ..F.i.l.e.D.e.s. 00000590 63 00 72 00 69 00 70 00 - 74 00 69 00 6f 00 6e 00 c.r.i.p.t.i.o.n. 000005a0 00 00 00 00 53 00 41 00 - 50 00 20 00 46 00 72 00 ….S.A.P. .F.r. 000005b0 6f 00 6e 00 74 00 65 00 - 6e 00 64 00 20 00 66 00 o.n.t.e.n.d. .f. 000005c0 6f 00 72 00 20 00 57 00 - 69 00 6e 00 64 00 6f 00 o.r. .W.i.n.d.o. 000005d0 77 00 73 00 00 00 00 00 - 36 00 0b 00 01 00 46 00 w.s…..6…..F. 000005e0 69 00 6c 00 65 00 56 00 - 65 00 72 00 73 00 69 00 i.l.e.V.e.r.s.i. 000005f0 6f 00 6e 00 00 00 00 00 - 34 00 2e 00 30 00 2e 00 o.n…..4…0… 00000600 30 00 2e 00 31 00 30 00 - 30 00 38 00 00 00 00 00 0…1.0.0.8….. 00000610 2c 00 06 00 01 00 49 00 - 6e 00 74 00 65 00 72 00 ,…..I.n.t.e.r. 00000620 6e 00 61 00 6c 00 4e 00 - 61 00 6d 00 65 00 00 00 n.a.l.N.a.m.e… 00000630 46 00 52 00 4f 00 4e 00 - 54 00 00 00 5e 00 1d 00 F.R.O.N.T…^… 00000640 01 00 4c 00 65 00 67 00 - 61 00 6c 00 43 00 6f 00 ..L.e.g.a.l.C.o. 00000650 70 00 79 00 72 00 69 00 - 67 00 68 00 74 00 00 00 p.y.r.i.g.h.t… 00000660 43 00 6f 00 70 00 79 00 - 72 00 69 00 67 00 68 00 C.o.p.y.r.i.g.h. 00000670 74 00 20 00 a9 00 20 00 - 31 00 39 00 39 00 33 00 t. .©. .[removed]. 00000680 2d 00 31 00 39 00 39 00 - 37 00 20 00 53 00 41 00 -.[removed]. .S.A. 00000690 50 00 20 00 41 00 47 00 - 00 00 00 00 28 00 00 00 P. .A.G…..(… 000006a0 01 00 4c 00 65 00 67 00 - 61 00 6c 00 54 00 72 00 ..L.e.g.a.l.T.r. 000006b0 61 00 64 00 02 00 00 00 - 00 00 00 00 01 00 00 00 a.d…………. 000006c0 4c 00 00 00 3c fd 06 00 - 04 00 00 00 00 00 00 00 L…<ý………. 000006d0 65 05 00 00 02 00 00 00 - 03 00 00 00 00 00 01 00 e…………… 000006e0 53 00 65 00 72 00 76 00 - 69 00 63 00 65 00 20 00 S.e.r.v.i.c.e. . 000006f0 50 00 61 00 63 00 6b 00 - 20 00 33 00 00 00 23 00 P.a.c.k. .3…#. 00000700 54 02 00 00 00 02 00 00 - 18 03 34 00 00 00 56 00 T………4…V. 00000710 53 00 5f 00 56 00 45 00 - 52 00 53 00 49 00 4f 00 S._.V.E.R.S.I.O. 00000720 4e 00 5f 00 49 00 4e 00 - 46 00 4f 00 00 00 00 00 N._.I.N.F.O….. 00000730 bd 04 ef fe 00 00 01 00 - 00 00 04 00 dd 03 00 00 ½.ïþ……..Ý… 00000740 00 00 04 00 dd 03 00 00 - 3f 00 00 00 00 00 00 00 ….Ý…?……. 00000750 04 00 01 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 00000760 00 00 00 00 78 02 00 00 - 01 00 53 00 74 00 72 00 ….x…..S.t.r. 00000770 69 00 6e 00 67 00 46 00 - 69 00 6c 00 65 00 49 00 i.n.g.F.i.l.e.I. 00000780 6e 00 66 00 6f 00 00 00 - 54 02 00 00 01 00 30 00 n.f.o…T…..0. 00000790 34 00 30 00 39 00 30 00 - 34 00 45 00 34 00 00 00 [removed].4.E.4… 000007a0 2e 00 07 00 01 00 43 00 - 6f 00 6d 00 70 00 61 00 ……C.o.m.p.a. 000007b0 6e 00 79 00 4e 00 61 00 - 6d 00 65 00 00 00 00 00 n.y.N.a.m.e….. 000007c0 53 00 41 00 50 00 20 00 - 41 00 47 00 00 00 00 00 S.A.P. .A.G….. 000007d0 5a 00 19 00 01 00 46 00 - 69 00 6c 00 65 00 44 00 Z…..F.i.l.e.D. 000007e0 65 00 73 00 63 00 72 00 - 69 00 70 00 74 00 69 00 e.s.c.r.i.p.t.i. 000007f0 6f 00 6e 00 00 00 00 00 - 53 00 41 00 50 00 20 00 o.n…..S.A.P. . 00000800 46 00 72 00 6f 00 6e 00 - 74 00 65 00 6e 00 64 00 F.r.o.n.t.e.n.d. 00000810 20 00 66 00 6f 00 72 00 - 20 00 57 00 69 00 6e 00 .f.o.r. .W.i.n. 00000820 64 00 6f 00 77 00 73 00 - 00 00 00 00 34 00 0a 00 d.o.w.s…..4… 00000830 01 00 46 00 69 00 6c 00 - 65 00 56 00 65 00 72 00 ..F.i.l.e.V.e.r. 00000840 73 00 69 00 6f 00 6e 00 - 00 00 00 00 34 00 2e 00 s.i.o.n…..4… 00000850 30 00 2e 00 30 00 2e 00 - 39 00 38 00 39 00 00 00 0…0…9.8.9… 00000860 2c 00 06 00 01 00 49 00 - 6e 00 74 00 65 00 72 00 ,…..I.n.t.e.r. 00000870 6e 00 61 00 6c 00 4e 00 - 61 00 6d 00 65 00 00 00 n.a.l.N.a.m.e… 00000880 46 00 52 00 4f 00 4e 00 - 54 00 00 00 5e 00 1d 00 F.R.O.N.T…^… 00000890 01 00 4c 00 65 00 67 00 - 61 00 6c 00 43 00 6f 00 ..L.e.g.a.l.C.o. 000008a0 70 00 79 00 72 00 69 00 - 67 00 68 00 74 00 00 00 p.y.r.i.g.h.t… 000008b0 43 00 6f 00 70 00 79 00 - 72 00 69 00 67 00 68 00 C.o.p.y.r.i.g.h. 000008c0 74 00 20 00 a9 00 20 00 - 31 00 39 00 39 00 33 00 t. .©. .[removed]. 000008d0 2d 00 31 00 39 00 39 00 - 37 00 20 00 53 00 41 00 -.[removed]. .S.A. 000008e0 50 00 20 00 41 00 47 00 - 00 00 00 00 28 00 00 00 P. .A.G…..(… 000008f0 01 00 4c 00 65 00 67 00 - 61 00 6c 00 54 00 72 00 ..L.e.g.a.l.T.r. 00000900 61 00 64 00 65 00 6d 00 - 02 00 00 00 00 00 00 00 a.d.e.m……… 00000910 01 00 00 00 4c 00 00 00 - 3c fd 06 00 04 00 00 00 ….L…<ý…… 00000920 00 00 00 00 65 05 00 00 - 02 00 00 00 03 00 00 00 ….e……….. 00000930 00 00 01 00 53 00 65 00 - 72 00 76 00 69 00 63 00 ….S.e.r.v.i.c. 00000940 65 00 20 00 50 00 61 00 - 63 00 6b 00 20 00 33 00 e. .P.a.c.k. .3. 00000950 00 00 23 00 ..#. Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fullsoft.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GBROWSER.DLL Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\htmlmarq.ocx Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\htmlmm.ocx Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\install.exe Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: ApplicationGoo Type: REG_BINARY Data: 00000000 58 02 00 00 54 02 00 00 - 00 02 00 00 6c 07 34 00 X…T…….l.4. 00000010 00 00 56 00 53 00 5f 00 - 56 00 45 00 52 00 53 00 ..V.S._.V.E.R.S. 00000020 49 00 4f 00 4e 00 5f 00 - 49 00 4e 00 46 00 4f 00 I.O.N._.I.N.F.O. 00000030 00 00 00 00 bd 04 ef fe - 00 00 01 00 05 00 05 00 ….½.ïþ…….. 00000040 07 00 a8 07 05 00 05 00 - 07 00 a8 07 3f 00 00 00 ..¨…….¨.?… 00000050 00 00 00 00 04 00 04 00 - 01 00 00 00 00 00 00 00 ……………. 00000060 00 00 00 00 00 00 00 00 - cc 06 00 00 01 00 53 00 ……..Ì…..S. 00000070 74 00 72 00 69 00 6e 00 - 67 00 46 00 69 00 6c 00 t.r.i.n.g.F.i.l. 00000080 65 00 49 00 6e 00 66 00 - 6f 00 00 00 54 03 00 00 e.I.n.f.o…T… 00000090 01 00 30 00 34 00 30 00 - 39 00 30 00 34 00 42 00 ..0.4.0.9.0.4.B. 000000a0 30 00 00 00 18 00 00 00 - 01 00 43 00 6f 00 6d 00 0………C.o.m. 000000b0 6d 00 65 00 6e 00 74 00 - 73 00 00 00 4c 00 16 00 m.e.n.t.s…L… 000000c0 01 00 43 00 6f 00 6d 00 - 70 00 61 00 6e 00 79 00 ..C.o.m.p.a.n.y. 000000d0 4e 00 61 00 6d 00 65 00 - 00 00 00 00 4d 00 69 00 N.a.m.e…..M.i. 000000e0 63 00 72 00 6f 00 73 00 - 6f 00 66 00 74 00 20 00 c.r.o.s.o.f.t. . 000000f0 43 00 6f 00 72 00 70 00 - 6f 00 72 00 61 00 74 00 C.o.r.p.o.r.a.t. 00000100 69 00 6f 00 6e 00 00 00 - 68 00 20 00 01 00 46 00 i.o.n…h. …F. 00000110 69 00 6c 00 65 00 44 00 - 65 00 73 00 63 00 72 00 i.l.e.D.e.s.c.r. 00000120 69 00 70 00 74 00 69 00 - 6f 00 6e 00 00 00 00 00 i.p.t.i.o.n….. 00000130 4d 00 69 00 63 00 72 00 - 6f 00 73 00 6f 00 66 00 M.i.c.r.o.s.o.f. 00000140 74 00 20 00 45 00 78 00 - 63 00 68 00 61 00 6e 00 t. .E.x.c.h.a.n. 00000150 67 00 65 00 20 00 53 00 - 65 00 72 00 76 00 65 00 g.e. .S.e.r.v.e. 00000160 72 00 20 00 53 00 65 00 - 74 00 75 00 70 00 00 00 r. .S.e.t.u.p… 00000170 36 00 0b 00 01 00 46 00 - 69 00 6c 00 65 00 56 00 6…..F.i.l.e.V. 00000180 65 00 72 00 73 00 69 00 - 6f 00 6e 00 00 00 00 00 e.r.s.i.o.n….. 00000190 35 00 2e 00 35 00 2e 00 - 31 00 39 00 36 00 30 00 5…5…[removed]. 000001a0 2e 00 37 00 00 00 00 00 - 2c 00 06 00 01 00 49 00 ..7…..,…..I. 000001b0 6e 00 74 00 65 00 72 00 - 6e 00 61 00 6c 00 4e 00 n.t.e.r.n.a.l.N. 000001c0 61 00 6d 00 65 00 00 00 - 53 00 65 00 74 00 75 00 a.m.e…S.e.t.u. 000001d0 70 00 00 00 9c 00 3c 00 - 01 00 4c 00 65 00 67 00 p…..<…L.e.g. 000001e0 61 00 6c 00 43 00 6f 00 - 70 00 79 00 72 00 69 00 a.l.C.o.p.y.r.i. 000001f0 67 00 68 00 74 00 00 00 - 43 00 6f 00 70 00 79 00 g.h.t…C.o.p.y. 00000200 72 00 69 00 67 00 68 00 - 74 00 20 00 02 00 00 00 r.i.g.h.t. ….. 00000210 00 00 00 00 01 00 00 00 - 4c 00 00 00 3c fd 06 00 ……..L…<ý.. 00000220 05 00 00 00 00 00 00 00 - 65 05 00 00 02 00 00 00 ……..e……. 00000230 03 00 00 00 02 00 00 00 - 53 00 65 00 72 00 76 00 ……..S.e.r.v. 00000240 69 00 63 00 65 00 20 00 - 50 00 61 00 63 00 6b 00 i.c.e. .P.a.c.k. 00000250 20 00 34 00 00 00 23 00 - .4…#. Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ishscan.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ISSTE.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\javai.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jvm.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jvm_g.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\main123w.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mngreg32.exe Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: ApplicationGoo Type: REG_BINARY Data: 00000000 58 02 00 00 54 02 00 00 - 00 02 00 00 44 02 34 00 X…T…….D.4. 00000010 00 00 56 00 53 00 5f 00 - 56 00 45 00 52 00 53 00 ..V.S._.V.E.R.S. 00000020 49 00 4f 00 4e 00 5f 00 - 49 00 4e 00 46 00 4f 00 I.O.N._.I.N.F.O. 00000030 00 00 00 00 bd 04 ef fe - 00 00 01 00 01 00 01 00 ….½.ïþ…….. 00000040 0c 00 00 00 01 00 01 00 - 0c 00 00 00 00 00 00 00 ……………. 00000050 00 00 00 00 04 00 00 00 - 01 00 00 00 00 00 00 00 ……………. 00000060 00 00 00 00 00 00 00 00 - 44 00 00 00 00 00 56 00 ……..D…..V. 00000070 61 00 72 00 46 00 69 00 - 6c 00 65 00 49 00 6e 00 a.r.F.i.l.e.I.n. 00000080 66 00 6f 00 00 00 00 00 - 24 00 04 00 00 00 54 00 f.o…..$…..T. 00000090 72 00 61 00 6e 00 73 00 - 6c 00 61 00 74 00 69 00 r.a.n.s.l.a.t.i. 000000a0 6f 00 6e 00 00 00 00 00 - 09 04 b0 04 a4 01 00 00 o.n….. .°.¤… 000000b0 01 00 53 00 74 00 72 00 - 69 00 6e 00 67 00 46 00 ..S.t.r.i.n.g.F. 000000c0 69 00 6c 00 65 00 49 00 - 6e 00 66 00 6f 00 00 00 i.l.e.I.n.f.o… 000000d0 80 01 00 00 01 00 30 00 - 34 00 30 00 39 00 30 00 ……0.4.0.9.0. 000000e0 34 00 42 00 30 00 00 00 - 40 00 20 00 01 00 43 00 4.B.0…@. …C. 000000f0 6f 00 6d 00 70 00 61 00 - 6e 00 79 00 4e 00 61 00 o.m.p.a.n.y.N.a. 00000100 6d 00 65 00 00 00 00 00 - 44 00 65 00 4c 00 6f 00 m.e…..D.e.L.o. 00000110 72 00 6d 00 65 00 20 00 - 4d 00 61 00 70 00 70 00 r.m.e. .M.a.p.p. 00000120 69 00 6e 00 67 00 00 00 - 44 00 22 00 01 00 50 00 i.n.g…D."…P. 00000130 72 00 6f 00 64 00 75 00 - 63 00 74 00 4e 00 61 00 r.o.d.u.c.t.N.a. 00000140 6d 00 65 00 00 00 00 00 - 52 00 65 00 67 00 20 00 m.e…..R.e.g. . 00000150 28 00 44 00 4c 00 69 00 - 62 00 62 00 79 00 5c 00 (.D.L.i.b.b.y.\. 00000160 6d 00 73 00 66 00 29 00 - 00 00 00 00 34 00 14 00 m.s.f.)…..4… 00000170 01 00 46 00 69 00 6c 00 - 65 00 56 00 65 00 72 00 ..F.i.l.e.V.e.r. 00000180 73 00 69 00 6f 00 6e 00 - 00 00 00 00 31 00 2e 00 s.i.o.n…..1… 00000190 30 00 31 00 2e 00 30 00 - 30 00 31 00 32 00 00 00 0.1…0.0.1.2… 000001a0 38 00 14 00 01 00 50 00 - 72 00 6f 00 64 00 75 00 8…..P.r.o.d.u. 000001b0 63 00 74 00 56 00 65 00 - 72 00 73 00 69 00 6f 00 c.t.V.e.r.s.i.o. 000001c0 6e 00 00 00 31 00 2e 00 - 30 00 31 00 2e 00 30 00 n…1…0.1…0. 000001d0 30 00 31 00 32 00 00 00 - 34 00 12 00 01 00 49 00 0.1.2…4…..I. 000001e0 6e 00 74 00 65 00 72 00 - 6e 00 61 00 6c 00 4e 00 n.t.e.r.n.a.l.N. 000001f0 61 00 6d 00 65 00 00 00 - 4d 00 4e 00 47 00 52 00 a.m.e…M.N.G.R. 00000200 45 00 47 00 33 00 32 00 - 00 00 00 00 02 00 00 00 E.G.3.2……… 00000210 00 00 00 00 01 00 00 00 - 4c 00 00 00 3c fd 06 00 ……..L…<ý.. 00000220 04 00 00 00 00 00 00 00 - 65 05 00 00 02 00 00 00 ……..e……. 00000230 03 00 00 00 00 00 01 00 - 53 00 65 00 72 00 76 00 ……..S.e.r.v. 00000240 69 00 63 00 65 00 20 00 - 50 00 61 00 63 00 6b 00 i.c.e. .P.a.c.k. 00000250 20 00 33 00 00 00 23 00 - .3…#. Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msci_uno.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscoree.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscorsvr.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscorwks.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msjava.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mso.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NAVOPTRF.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NeVideoFX.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NPMLIC.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NSWSTE.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\photohse.EXE Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: GlobalFlag Type: REG_SZ Data: 0x00200000 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PMSTE.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ppw32hlp.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\printhse.EXE Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: GlobalFlag Type: REG_SZ Data: 0x00200000 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\prwin8.EXE Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: DisableHeapLookAside Type: REG_SZ Data: 1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ps80.EXE Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: DisableHeapLookAside Type: REG_SZ Data: 1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\psdmt.exe Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: ApplicationGoo Type: REG_BINARY Data: 00000000 14 02 00 00 10 02 00 00 - 00 02 00 00 b4 02 34 00 …………´.4. 00000010 00 00 56 00 53 00 5f 00 - 56 00 45 00 52 00 53 00 ..V.S._.V.E.R.S. 00000020 49 00 4f 00 4e 00 5f 00 - 49 00 4e 00 46 00 4f 00 I.O.N._.I.N.F.O. 00000030 00 00 00 00 bd 04 ef fe - 00 00 01 00 35 00 07 00 ….½.ïþ….5… 00000040 00 00 00 00 35 00 07 00 - 00 00 00 00 3f 00 00 00 ….5…….?… 00000050 00 00 00 00 04 00 00 00 - 01 00 00 00 00 00 00 00 ……………. 00000060 00 00 00 00 00 00 00 00 - 12 02 00 00 01 00 53 00 …………..S. 00000070 74 00 72 00 69 00 6e 00 - 67 00 46 00 69 00 6c 00 t.r.i.n.g.F.i.l. 00000080 65 00 49 00 6e 00 66 00 - 6f 00 00 00 ee 01 00 00 e.I.n.f.o…î… 00000090 01 00 30 00 34 00 30 00 - 39 00 30 00 34 00 62 00 ..0.4.0.9.0.4.b. 000000a0 30 00 00 00 42 00 11 00 - 01 00 43 00 6f 00 6d 00 0…B…..C.o.m. 000000b0 70 00 61 00 6e 00 79 00 - 4e 00 61 00 6d 00 65 00 p.a.n.y.N.a.m.e. 000000c0 00 00 00 00 50 00 65 00 - 6f 00 70 00 6c 00 65 00 ….P.e.o.p.l.e. 000000d0 53 00 6f 00 66 00 74 00 - 2c 00 20 00 49 00 6e 00 S.o.f.t.,. .I.n. 000000e0 63 00 2e 00 00 00 00 00 - 28 00 00 00 01 00 46 00 c…….(…..F. 000000f0 69 00 6c 00 65 00 44 00 - 65 00 73 00 63 00 72 00 i.l.e.D.e.s.c.r. 00000100 69 00 70 00 74 00 69 00 - 6f 00 6e 00 00 00 00 00 i.p.t.i.o.n….. 00000110 2a 00 05 00 01 00 46 00 - 69 00 6c 00 65 00 56 00 *…..F.i.l.e.V. 00000120 65 00 72 00 73 00 69 00 - 6f 00 6e 00 00 00 00 00 e.r.s.i.o.n….. 00000130 37 00 2e 00 35 00 33 00 - 00 00 00 00 9c 00 3c 00 7…5.3…….<. 00000140 01 00 4c 00 65 00 67 00 - 61 00 6c 00 43 00 6f 00 ..L.e.g.a.l.C.o. 00000150 70 00 79 00 72 00 69 00 - 67 00 68 00 74 00 00 00 p.y.r.i.g.h.t… 00000160 43 00 6f 00 70 00 79 00 - 72 00 69 00 67 00 68 00 C.o.p.y.r.i.g.h. 00000170 74 00 20 00 a9 00 20 00 - 31 00 39 00 38 00 38 00 t. .©. .[removed]. 00000180 2d 00 31 00 39 00 39 00 - 38 00 20 00 50 00 65 00 -.[removed]. .P.e. 00000190 6f 00 70 00 6c 00 65 00 - 53 00 6f 00 66 00 74 00 o.p.l.e.S.o.f.t. 000001a0 2c 00 20 00 49 00 6e 00 - 63 00 2e 00 20 00 20 00 ,. .I.n.c… . . 000001b0 41 00 6c 00 6c 00 20 00 - 52 00 69 00 67 00 68 00 A.l.l. .R.i.g.h. 000001c0 74 00 73 00 20 00 52 00 - 65 00 73 00 65 00 72 00 t.s. .R.e.s.e.r. 000001d0 76 00 65 00 64 00 00 00 - 3c 00 0a 00 01 00 4f 00 v.e.d…<…..O. 000001e0 72 00 69 00 67 00 69 00 - 6e 00 61 00 6c 00 46 00 r.i.g.i.n.a.l.F. 000001f0 69 00 6c 00 65 00 6e 00 - 61 00 6d 00 65 00 00 00 i.l.e.n.a.m.e… 00000200 70 00 73 00 64 00 6d 00 - 74 00 2e 00 10 00 00 00 p.s.d.m.t……. 00000210 00 00 00 00 …. Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qfinder.EXE Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: DisableHeapLookAside Type: REG_SZ Data: 1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qpw.EXE Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: DisableHeapLookAside Type: REG_SZ Data: 1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Salwrap.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: ApplicationGoo Type: REG_BINARY Data: 00000000 00 07 00 00 54 02 00 00 - 00 02 00 00 84 07 34 00 ….T………4. 00000010 00 00 56 00 53 00 5f 00 - 56 00 45 00 52 00 53 00 ..V.S._.V.E.R.S. 00000020 49 00 4f 00 4e 00 5f 00 - 49 00 4e 00 46 00 4f 00 I.O.N._.I.N.F.O. 00000030 00 00 00 00 bd 04 ef fe - 00 00 01 00 05 00 05 00 ….½.ïþ…….. 00000040 07 00 a8 07 05 00 05 00 - 07 00 a8 07 3f 00 00 00 ..¨…….¨.?… 00000050 00 00 00 00 04 00 04 00 - 01 00 00 00 00 00 00 00 ……………. 00000060 00 00 00 00 00 00 00 00 - e4 06 00 00 01 00 53 00 ……..ä…..S. 00000070 74 00 72 00 69 00 6e 00 - 67 00 46 00 69 00 6c 00 t.r.i.n.g.F.i.l. 00000080 65 00 49 00 6e 00 66 00 - 6f 00 00 00 60 03 00 00 e.I.n.f.o…`… 00000090 01 00 30 00 34 00 30 00 - 39 00 30 00 34 00 42 00 ..0.4.0.9.0.4.B. 000000a0 30 00 00 00 18 00 00 00 - 01 00 43 00 6f 00 6d 00 0………C.o.m. 000000b0 6d 00 65 00 6e 00 74 00 - 73 00 00 00 4c 00 16 00 m.e.n.t.s…L… 000000c0 01 00 43 00 6f 00 6d 00 - 70 00 61 00 6e 00 79 00 ..C.o.m.p.a.n.y. 000000d0 4e 00 61 00 6d 00 65 00 - 00 00 00 00 4d 00 69 00 N.a.m.e…..M.i. 000000e0 63 00 72 00 6f 00 73 00 - 6f 00 66 00 74 00 20 00 c.r.o.s.o.f.t. . 000000f0 43 00 6f 00 72 00 70 00 - 6f 00 72 00 61 00 74 00 C.o.r.p.o.r.a.t. 00000100 69 00 6f 00 6e 00 00 00 - 68 00 20 00 01 00 46 00 i.o.n…h. …F. 00000110 69 00 6c 00 65 00 44 00 - 65 00 73 00 63 00 72 00 i.l.e.D.e.s.c.r. 00000120 69 00 70 00 74 00 69 00 - 6f 00 6e 00 00 00 00 00 i.p.t.i.o.n….. 00000130 4d 00 69 00 63 00 72 00 - 6f 00 73 00 6f 00 66 00 M.i.c.r.o.s.o.f. 00000140 74 00 20 00 45 00 78 00 - 63 00 68 00 61 00 6e 00 t. .E.x.c.h.a.n. 00000150 67 00 65 00 20 00 53 00 - 65 00 72 00 76 00 65 00 g.e. .S.e.r.v.e. 00000160 72 00 20 00 53 00 65 00 - 74 00 75 00 70 00 00 00 r. .S.e.t.u.p… 00000170 36 00 0b 00 01 00 46 00 - 69 00 6c 00 65 00 56 00 6…..F.i.l.e.V. 00000180 65 00 72 00 73 00 69 00 - 6f 00 6e 00 00 00 00 00 e.r.s.i.o.n….. 00000190 35 00 2e 00 35 00 2e 00 - 31 00 39 00 36 00 30 00 5…5…[removed]. 000001a0 2e 00 37 00 00 00 00 00 - 2c 00 06 00 01 00 49 00 ..7…..,…..I. 000001b0 6e 00 74 00 65 00 72 00 - 6e 00 61 00 6c 00 4e 00 n.t.e.r.n.a.l.N. 000001c0 61 00 6d 00 65 00 00 00 - 53 00 65 00 74 00 75 00 a.m.e…S.e.t.u. 000001d0 70 00 00 00 9e 00 3d 00 - 01 00 4c 00 65 00 67 00 p…..=…L.e.g. 000001e0 61 00 6c 00 43 00 6f 00 - 70 00 79 00 72 00 69 00 a.l.C.o.p.y.r.i. 000001f0 67 00 68 00 74 00 00 00 - 43 00 6f 00 70 00 79 00 g.h.t…C.o.p.y. 00000200 72 00 69 00 67 00 68 00 - 74 00 20 00 02 00 00 00 r.i.g.h.t. ….. 00000210 00 00 00 00 01 00 00 00 - 4c 00 00 00 3c fd 06 00 ……..L…<ý.. 00000220 05 00 00 00 00 00 00 00 - 65 05 00 00 02 00 00 00 ……..e……. 00000230 00 00 00 00 00 00 00 00 - 53 00 65 00 72 00 76 00 ……..S.e.r.v. 00000240 69 00 63 00 65 00 20 00 - 50 00 61 00 63 00 6b 00 i.c.e. .P.a.c.k. 00000250 20 00 33 00 00 00 24 00 - 54 02 00 00 00 02 00 00 .3…$.T……. 00000260 a4 08 34 00 00 00 56 00 - 53 00 5f 00 56 00 45 00 ¤.4…V.S._.V.E. 00000270 52 00 53 00 49 00 4f 00 - 4e 00 5f 00 49 00 4e 00 R.S.I.O.N._.I.N. 00000280 46 00 4f 00 00 00 00 00 - bd 04 ef fe 00 00 01 00 F.O…..½.ïþ…. 00000290 05 00 05 00 07 00 a8 07 - 05 00 05 00 07 00 a8 07 ……¨…….¨. 000002a0 3f 00 00 00 00 00 00 00 - 04 00 04 00 01 00 00 00 ?…………… 000002b0 00 00 00 00 00 00 00 00 - 00 00 00 00 04 08 00 00 ……………. 000002c0 01 00 53 00 74 00 72 00 - 69 00 6e 00 67 00 46 00 ..S.t.r.i.n.g.F. 000002d0 69 00 6c 00 65 00 49 00 - 6e 00 66 00 6f 00 00 00 i.l.e.I.n.f.o… 000002e0 f0 03 00 00 01 00 30 00 - 34 00 30 00 39 00 30 00 ð…..0.4.0.9.0. 000002f0 34 00 42 00 30 00 00 00 - 18 00 00 00 01 00 43 00 4.B.0………C. 00000300 6f 00 6d 00 6d 00 65 00 - 6e 00 74 00 73 00 00 00 o.m.m.e.n.t.s… 00000310 4c 00 16 00 01 00 43 00 - 6f 00 6d 00 70 00 61 00 L…..C.o.m.p.a. 00000320 6e 00 79 00 4e 00 61 00 - 6d 00 65 00 00 00 00 00 n.y.N.a.m.e….. 00000330 4d 00 69 00 63 00 72 00 - 6f 00 73 00 6f 00 66 00 M.i.c.r.o.s.o.f. 00000340 74 00 20 00 43 00 6f 00 - 72 00 70 00 6f 00 72 00 t. .C.o.r.p.o.r. 00000350 61 00 74 00 69 00 6f 00 - 6e 00 00 00 68 00 20 00 a.t.i.o.n…h. . 00000360 01 00 46 00 69 00 6c 00 - 65 00 44 00 65 00 73 00 ..F.i.l.e.D.e.s. 00000370 63 00 72 00 69 00 70 00 - 74 00 69 00 6f 00 6e 00 c.r.i.p.t.i.o.n. 00000380 00 00 00 00 4d 00 69 00 - 63 00 72 00 6f 00 73 00 ….M.i.c.r.o.s. 00000390 6f 00 66 00 74 00 20 00 - 45 00 78 00 63 00 68 00 o.f.t. .E.x.c.h. 000003a0 61 00 6e 00 67 00 65 00 - 20 00 53 00 65 00 72 00 a.n.g.e. .S.e.r. 000003b0 76 00 65 00 72 00 20 00 - 53 00 65 00 74 00 75 00 v.e.r. .S.e.t.u. 000003c0 70 00 00 00 36 00 0b 00 - 01 00 46 00 69 00 6c 00 p…6…..F.i.l. 000003d0 65 00 56 00 65 00 72 00 - 73 00 69 00 6f 00 6e 00 e.V.e.r.s.i.o.n. 000003e0 00 00 00 00 35 00 2e 00 - 35 00 2e 00 31 00 39 00 ….5…5…1.9. 000003f0 36 00 30 00 2e 00 37 00 - 00 00 00 00 2c 00 06 00 6.0…7…..,… 00000400 01 00 49 00 6e 00 74 00 - 65 00 72 00 6e 00 61 00 ..I.n.t.e.r.n.a. 00000410 6c 00 4e 00 61 00 6d 00 - 65 00 00 00 53 00 65 00 l.N.a.m.e…S.e. 00000420 74 00 75 00 70 00 00 00 - a6 00 41 00 01 00 4c 00 t.u.p…¦.A…L. 00000430 65 00 67 00 61 00 6c 00 - 43 00 6f 00 70 00 79 00 e.g.a.l.C.o.p.y. 00000440 72 00 69 00 67 00 68 00 - 74 00 00 00 43 00 6f 00 r.i.g.h.t…C.o. 00000450 70 00 79 00 72 00 69 00 - 67 00 68 00 74 00 20 00 p.y.r.i.g.h.t. . 00000460 02 00 00 00 00 00 00 00 - 01 00 00 00 4c 00 00 00 …………L… 00000470 3c fd 06 00 05 00 00 00 - 00 00 00 00 65 05 00 00 <ý……….e… 00000480 02 00 00 00 00 00 00 00 - 00 00 00 00 53 00 65 00 …………S.e. 00000490 72 00 76 00 69 00 63 00 - 65 00 20 00 50 00 61 00 r.v.i.c.e. .P.a. 000004a0 63 00 6b 00 20 00 33 00 - 00 00 24 00 54 02 00 00 c.k. .3…$.T… 000004b0 00 02 00 00 18 04 34 00 - 00 00 56 00 53 00 5f 00 ……4…V.S._. 000004c0 56 00 45 00 52 00 53 00 - 49 00 4f 00 4e 00 5f 00 V.E.R.S.I.O.N._. 000004d0 49 00 4e 00 46 00 4f 00 - 00 00 00 00 bd 04 ef fe I.N.F.O…..½.ïþ 000004e0 00 00 01 00 05 00 05 00 - 07 00 a8 07 05 00 05 00 ……….¨….. 000004f0 07 00 a8 07 3f 00 00 00 - 00 00 00 00 04 00 04 00 ..¨.?……….. 00000500 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 00000510 78 03 00 00 01 00 53 00 - 74 00 72 00 69 00 6e 00 x…..S.t.r.i.n. 00000520 67 00 46 00 69 00 6c 00 - 65 00 49 00 6e 00 66 00 g.F.i.l.e.I.n.f. 00000530 6f 00 00 00 54 03 00 00 - 01 00 30 00 34 00 30 00 o…T…..0.4.0. 00000540 39 00 30 00 34 00 42 00 - 30 00 00 00 18 00 00 00 9.0.4.B.0……. 00000550 01 00 43 00 6f 00 6d 00 - 6d 00 65 00 6e 00 74 00 ..C.o.m.m.e.n.t. 00000560 73 00 00 00 4c 00 16 00 - 01 00 43 00 6f 00 6d 00 s…L…..C.o.m. 00000570 70 00 61 00 6e 00 79 00 - 4e 00 61 00 6d 00 65 00 p.a.n.y.N.a.m.e. 00000580 00 00 00 00 4d 00 69 00 - 63 00 72 00 6f 00 73 00 ….M.i.c.r.o.s. 00000590 6f 00 66 00 74 00 20 00 - 43 00 6f 00 72 00 70 00 o.f.t. .C.o.r.p. 000005a0 6f 00 72 00 61 00 74 00 - 69 00 6f 00 6e 00 00 00 o.r.a.t.i.o.n… 000005b0 68 00 20 00 01 00 46 00 - 69 00 6c 00 65 00 44 00 h. …F.i.l.e.D. 000005c0 65 00 73 00 63 00 72 00 - 69 00 70 00 74 00 69 00 e.s.c.r.i.p.t.i. 000005d0 6f 00 6e 00 00 00 00 00 - 4d 00 69 00 63 00 72 00 o.n…..M.i.c.r. 000005e0 6f 00 73 00 6f 00 66 00 - 74 00 20 00 45 00 78 00 o.s.o.f.t. .E.x. 000005f0 63 00 68 00 61 00 6e 00 - 67 00 65 00 20 00 53 00 c.h.a.n.g.e. .S. 00000600 65 00 72 00 76 00 65 00 - 72 00 20 00 53 00 65 00 e.r.v.e.r. .S.e. 00000610 74 00 75 00 70 00 00 00 - 36 00 0b 00 01 00 46 00 t.u.p…6…..F. 00000620 69 00 6c 00 65 00 56 00 - 65 00 72 00 73 00 69 00 i.l.e.V.e.r.s.i. 00000630 6f 00 6e 00 00 00 00 00 - 35 00 2e 00 35 00 2e 00 o.n…..5…5… 00000640 31 00 39 00 36 00 30 00 - 2e 00 37 00 00 00 00 00 [removed]…7….. 00000650 2c 00 06 00 01 00 49 00 - 6e 00 74 00 65 00 72 00 ,…..I.n.t.e.r. 00000660 6e 00 61 00 6c 00 4e 00 - 61 00 6d 00 65 00 00 00 n.a.l.N.a.m.e… 00000670 53 00 65 00 74 00 75 00 - 70 00 00 00 9a 00 3b 00 S.e.t.u.p…..;. 00000680 01 00 4c 00 65 00 67 00 - 61 00 6c 00 43 00 6f 00 ..L.e.g.a.l.C.o. 00000690 70 00 79 00 72 00 69 00 - 67 00 68 00 74 00 00 00 p.y.r.i.g.h.t… 000006a0 43 00 6f 00 70 00 79 00 - 72 00 69 00 67 00 68 00 C.o.p.y.r.i.g.h. 000006b0 74 00 20 00 02 00 00 00 - 00 00 00 00 01 00 00 00 t. …………. 000006c0 4c 00 00 00 3c fd 06 00 - 05 00 00 00 00 00 00 00 L…<ý………. 000006d0 65 05 00 00 02 00 00 00 - 00 00 00 00 00 00 00 00 e…………… 000006e0 53 00 65 00 72 00 76 00 - 69 00 63 00 65 00 20 00 S.e.r.v.i.c.e. . 000006f0 50 00 61 00 63 00 6b 00 - 20 00 33 00 00 00 24 00 P.a.c.k. .3…$. Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup32.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: ApplicationGoo Type: REG_BINARY Data: 00000000 14 02 00 00 10 02 00 00 - 00 02 00 00 04 03 34 00 …………..4. 00000010 00 00 56 00 53 00 5f 00 - 56 00 45 00 52 00 53 00 ..V.S._.V.E.R.S. 00000020 49 00 4f 00 4e 00 5f 00 - 49 00 4e 00 46 00 4f 00 I.O.N._.I.N.F.O. 00000030 00 00 00 00 bd 04 ef fe - 00 00 01 00 1c 00 08 00 ….½.ïþ…….. 00000040 00 00 00 00 00 00 08 00 - 00 00 00 00 3f 00 00 00 …………?… 00000050 00 00 00 00 04 00 00 00 - 01 00 00 00 00 00 00 00 ……………. 00000060 00 00 00 00 00 00 00 00 - 64 02 00 00 01 00 53 00 ……..d…..S. 00000070 74 00 72 00 69 00 6e 00 - 67 00 46 00 69 00 6c 00 t.r.i.n.g.F.i.l. 00000080 65 00 49 00 6e 00 66 00 - 6f 00 00 00 40 02 00 00 e.I.n.f.o…@… 00000090 01 00 30 00 34 00 30 00 - 39 00 30 00 34 00 62 00 ..0.4.0.9.0.4.b. 000000a0 30 00 00 00 44 00 12 00 - 01 00 43 00 6f 00 6d 00 0…D…..C.o.m. 000000b0 70 00 61 00 6e 00 79 00 - 4e 00 61 00 6d 00 65 00 p.a.n.y.N.a.m.e. 000000c0 00 00 00 00 43 00 6f 00 - 72 00 65 00 6c 00 20 00 ….C.o.r.e.l. . 000000d0 43 00 6f 00 72 00 70 00 - 6f 00 72 00 61 00 74 00 C.o.r.p.o.r.a.t. 000000e0 69 00 6f 00 6e 00 00 00 - 4e 00 13 00 01 00 46 00 i.o.n…N…..F. 000000f0 69 00 6c 00 65 00 44 00 - 65 00 73 00 63 00 72 00 i.l.e.D.e.s.c.r. 00000100 69 00 70 00 74 00 69 00 - 6f 00 6e 00 00 00 00 00 i.p.t.i.o.n….. 00000110 43 00 6f 00 72 00 65 00 - 6c 00 20 00 53 00 65 00 C.o.r.e.l. .S.e. 00000120 74 00 75 00 70 00 20 00 - 57 00 69 00 7a 00 61 00 t.u.p. .W.i.z.a. 00000130 72 00 64 00 00 00 00 00 - 2c 00 06 00 01 00 46 00 r.d…..,…..F. 00000140 69 00 6c 00 65 00 56 00 - 65 00 72 00 73 00 69 00 i.l.e.V.e.r.s.i. 00000150 6f 00 6e 00 00 00 00 00 - 38 00 2e 00 30 00 32 00 o.n…..8…0.2. 00000160 38 00 00 00 46 00 13 00 - 01 00 49 00 6e 00 74 00 8…F…..I.n.t. 00000170 65 00 72 00 6e 00 61 00 - 6c 00 4e 00 61 00 6d 00 e.r.n.a.l.N.a.m. 00000180 65 00 00 00 43 00 6f 00 - 72 00 65 00 6c 00 20 00 e…C.o.r.e.l. . 00000190 53 00 65 00 74 00 75 00 - 70 00 20 00 57 00 69 00 S.e.t.u.p. .W.i. 000001a0 7a 00 61 00 72 00 64 00 - 00 00 00 00 6c 00 24 00 z.a.r.d…..l.$. 000001b0 01 00 4c 00 65 00 67 00 - 61 00 6c 00 43 00 6f 00 ..L.e.g.a.l.C.o. 000001c0 70 00 79 00 72 00 69 00 - 67 00 68 00 74 00 00 00 p.y.r.i.g.h.t… 000001d0 43 00 6f 00 70 00 79 00 - 72 00 69 00 67 00 68 00 C.o.p.y.r.i.g.h. 000001e0 74 00 20 00 a9 00 20 00 - 31 00 39 00 39 00 37 00 t. .©. .[removed]. 000001f0 2c 00 20 00 43 00 6f 00 - 72 00 65 00 6c 00 20 00 ,. .C.o.r.e.l. . 00000200 43 00 6f 00 72 00 70 00 - 6f 00 72 00 08 00 00 00 C.o.r.p.o.r….. 00000210 00 00 00 00 …. Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sevinst.exe Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: ApplicationGoo Type: REG_BINARY Data: 00000000 14 02 00 00 10 02 00 00 - 00 02 00 00 38 03 34 00 …………8.4. 00000010 00 00 56 00 53 00 5f 00 - 56 00 45 00 52 00 53 00 ..V.S._.V.E.R.S. 00000020 49 00 4f 00 4e 00 5f 00 - 49 00 4e 00 46 00 4f 00 I.O.N._.I.N.F.O. 00000030 00 00 00 00 bd 04 ef fe - 00 00 01 00 02 00 0a 00 ….½.ïþ…….. 00000040 01 00 0a 00 02 00 0a 00 - 01 00 0a 00 00 00 00 00 ……………. 00000050 00 00 00 00 04 00 01 00 - 01 00 00 00 00 00 00 00 ……………. 00000060 00 00 00 00 00 00 00 00 - 98 02 00 00 01 00 53 00 …………..S. 00000070 74 00 72 00 69 00 6e 00 - 67 00 46 00 69 00 6c 00 t.r.i.n.g.F.i.l. 00000080 65 00 49 00 6e 00 66 00 - 6f 00 00 00 74 02 00 00 e.I.n.f.o…t… 00000090 01 00 30 00 34 00 30 00 - 39 00 30 00 34 00 45 00 ..0.4.0.9.0.4.E. 000000a0 34 00 00 00 4a 00 15 00 - 01 00 43 00 6f 00 6d 00 4…J…..C.o.m. 000000b0 70 00 61 00 6e 00 79 00 - 4e 00 61 00 6d 00 65 00 p.a.n.y.N.a.m.e. 000000c0 00 00 00 00 53 00 79 00 - 6d 00 61 00 6e 00 74 00 ….S.y.m.a.n.t. 000000d0 65 00 63 00 20 00 43 00 - 6f 00 72 00 70 00 6f 00 e.c. .C.o.r.p.o. 000000e0 72 00 61 00 74 00 69 00 - 6f 00 6e 00 00 00 00 00 r.a.t.i.o.n….. 000000f0 60 00 1c 00 01 00 46 00 - 69 00 6c 00 65 00 44 00 `…..F.i.l.e.D. 00000100 65 00 73 00 63 00 72 00 - 69 00 70 00 74 00 69 00 e.s.c.r.i.p.t.i. 00000110 6f 00 6e 00 00 00 00 00 - 53 00 79 00 6d 00 61 00 o.n…..S.y.m.a. 00000120 6e 00 74 00 65 00 63 00 - 20 00 53 00 79 00 6d 00 n.t.e.c. .S.y.m. 00000130 65 00 76 00 65 00 6e 00 - 74 00 20 00 49 00 6e 00 e.v.e.n.t. .I.n. 00000140 73 00 74 00 61 00 6c 00 - 6c 00 65 00 72 00 00 00 s.t.a.l.l.e.r… 00000150 34 00 0a 00 01 00 46 00 - 69 00 6c 00 65 00 56 00 4…..F.i.l.e.V. 00000160 65 00 72 00 73 00 69 00 - 6f 00 6e 00 00 00 00 00 e.r.s.i.o.n….. 00000170 31 00 30 00 2e 00 32 00 - 2e 00 31 00 30 00 2e 00 1.0…2…1.0… 00000180 31 00 00 00 30 00 08 00 - 01 00 49 00 6e 00 74 00 1…0…..I.n.t. 00000190 65 00 72 00 6e 00 61 00 - 6c 00 4e 00 61 00 6d 00 e.r.n.a.l.N.a.m. 000001a0 65 00 00 00 53 00 45 00 - 56 00 49 00 4e 00 53 00 e…S.E.V.I.N.S. 000001b0 54 00 00 00 7e 00 2d 00 - 01 00 4c 00 65 00 67 00 T…~.-…L.e.g. 000001c0 61 00 6c 00 43 00 6f 00 - 70 00 79 00 72 00 69 00 a.l.C.o.p.y.r.i. 000001d0 67 00 68 00 74 00 00 00 - 43 00 6f 00 70 00 79 00 g.h.t…C.o.p.y. 000001e0 72 00 69 00 67 00 68 00 - 74 00 20 00 28 00 43 00 r.i.g.h.t. .(.C. 000001f0 29 00 20 00 53 00 79 00 - 6d 00 61 00 6e 00 74 00 ). .S.y.m.a.n.t. 00000200 65 00 63 00 20 00 43 00 - 6f 00 72 00 01 00 00 00 e.c. .C.o.r….. 00000210 00 00 00 00 …. Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\symlcnet.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tcore_ebook.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TFDTCTT8.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ua80.EXE Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: DisableHeapLookAside Type: REG_SZ Data: 1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\udtapi.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ums.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vb40032.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbe6.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wpwin8.EXE Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: DisableHeapLookAside Type: REG_SZ Data: 1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xlmlEN.dll Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: CheckAppHelp Type: REG_DWORD Data: 0x1 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xwsetup.EXE Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: ApplicationGoo Type: REG_BINARY Data: 00000000 14 02 00 00 10 02 00 00 - 00 02 00 00 7c 03 34 00 …………|.4. 00000010 00 00 56 00 53 00 5f 00 - 56 00 45 00 52 00 53 00 ..V.S._.V.E.R.S. 00000020 49 00 4f 00 4e 00 5f 00 - 49 00 4e 00 46 00 4f 00 I.O.N._.I.N.F.O. 00000030 00 00 00 00 bd 04 ef fe - 00 00 01 00 00 00 01 00 ….½.ïþ…….. 00000040 09 00 26 00 00 00 01 00 - 09 00 26 00 3f 00 00 00 .&….. .&.?… 00000050 00 00 00 00 04 00 00 00 - 01 00 00 00 00 00 00 00 ……………. 00000060 00 00 00 00 00 00 00 00 - dc 02 00 00 01 00 53 00 ……..Ü…..S. 00000070 74 00 72 00 69 00 6e 00 - 67 00 46 00 69 00 6c 00 t.r.i.n.g.F.i.l. 00000080 65 00 49 00 6e 00 66 00 - 6f 00 00 00 b8 02 00 00 e.I.n.f.o…¸… 00000090 01 00 30 00 34 00 30 00 - 39 00 30 00 34 00 62 00 ..0.4.0.9.0.4.b. 000000a0 30 00 00 00 66 00 27 00 - 01 00 43 00 6f 00 6d 00 0…f.'…C.o.m. 000000b0 6d 00 65 00 6e 00 74 00 - 73 00 00 00 42 00 75 00 m.e.n.t.s…B.u. 000000c0 73 00 69 00 6e 00 65 00 - 73 00 73 00 20 00 49 00 s.i.n.e.s.s. .I. 000000d0 6e 00 74 00 65 00 6c 00 - 6c 00 69 00 67 00 65 00 n.t.e.l.l.i.g.e. 000000e0 6e 00 63 00 65 00 20 00 - 6f 00 6e 00 20 00 45 00 n.c.e. .o.n. .E. 000000f0 76 00 65 00 72 00 79 00 - 20 00 44 00 65 00 73 00 v.e.r.y. .D.e.s. 00000100 6b 00 74 00 6f 00 70 00 - 00 00 00 00 48 00 14 00 k.t.o.p…..H… 00000110 01 00 43 00 6f 00 6d 00 - 70 00 61 00 6e 00 79 00 ..C.o.m.p.a.n.y. 00000120 4e 00 61 00 6d 00 65 00 - 00 00 00 00 43 00 6f 00 N.a.m.e…..C.o. 00000130 67 00 6e 00 6f 00 73 00 - 20 00 49 00 6e 00 63 00 g.n.o.s. .I.n.c. 00000140 6f 00 72 00 70 00 6f 00 - 72 00 61 00 74 00 65 00 o.r.p.o.r.a.t.e. 00000150 64 00 00 00 60 00 1c 00 - 01 00 46 00 69 00 6c 00 d…`…..F.i.l. 00000160 65 00 44 00 65 00 73 00 - 63 00 72 00 69 00 70 00 e.D.e.s.c.r.i.p. 00000170 74 00 69 00 6f 00 6e 00 - 00 00 00 00 43 00 6f 00 t.i.o.n…..C.o. 00000180 67 00 6e 00 6f 00 73 00 - 20 00 47 00 65 00 6e 00 g.n.o.s. .G.e.n. 00000190 65 00 72 00 69 00 63 00 - 20 00 49 00 6e 00 73 00 e.r.i.c. .I.n.s. 000001a0 74 00 61 00 6c 00 6c 00 - 61 00 74 00 69 00 6f 00 t.a.l.l.a.t.i.o. 000001b0 6e 00 00 00 38 00 0c 00 - 01 00 46 00 69 00 6c 00 n…8…..F.i.l. 000001c0 65 00 56 00 65 00 72 00 - 73 00 69 00 6f 00 6e 00 e.V.e.r.s.i.o.n. 000001d0 00 00 00 00 31 00 2c 00 - 20 00 30 00 2c 00 20 00 ….1.,. .0.,. . 000001e0 33 00 38 00 2c 00 20 00 - 39 00 00 00 30 00 08 00 3.8.,. .9…0… 000001f0 01 00 49 00 6e 00 74 00 - 65 00 72 00 6e 00 61 00 ..I.n.t.e.r.n.a. 00000200 6c 00 4e 00 61 00 6d 00 - 65 00 00 00 01 00 00 00 l.N.a.m.e……. 00000210 00 00 00 00 …. Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: Debugger Type: REG_SZ Data: ntsd -d Value 1 Name: GlobalFlag Type: REG_SZ Data: 0x000010F0 Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_INSTPGM.EXE Class Name: Last Write Time: 3/4/2006 - 5:00 PM Value 0 Name: ApplicationGoo Type: REG_BINARY Data: 00000000 14 02 00 00 1
I'm headed to bed, but try these.

#1
Click "Start", "Settings", and then click "Control Panel". Open the "Display" applet.
Click on "Desktop", "Customise Display…" and "Web".
In the box under "Web pages", select all the checkboxes and click "Delete".

If that didn't work:
#2
Next, launch Notepad (Start>All Programs>Accessories), and copy/paste the Quote REGEDIT below to it
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Desktop\General]
"WallpaperFileTime"=-
"WallpaperLocalFileTime"=-

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"NoDispAppearancePage"=-
"Wallpaper"=-
"WallpaperStyle"=-
"NoDispBackgroundPage"=-

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoActiveDesktopChanges"=-
"ForceActiveDesktopOn"=-

[HKEY_CURRENT_USER\Control Panel\Desktop]
"Wallpaper"=-
"WallpaperStyle"=-

[HKEY_CURRENT_USER\Control Panel\Colors]
"Background"="0 78 152"



On the desktop, doubleclick fix.reg and allow it to run. Let it merge.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI