This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Help Me Please~

48 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My comp started to lag few days ago. Sometimes Windows will crash when I open a game or so. I can't do much stuff with this lagness. So Please help~~ Thanks alot in advance!!

Logfile of HijackThis v1.99.1
Scan saved at 01:58:08, on 18/08/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Twain_32\ScanWiz5\SDetect.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\WINDOWS\System32\spoolsvv.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\UAService7.exe
C:\Program Files\mIRC\mirc.exe
C:\Documents and Settings\user\Desktop\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.maplesea.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: 87.117.202.117 nprotect.roseonlinegame.com
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O4 - HKLM\..\Run: [SDetect.exe] C:\WINDOWS\Twain_32\ScanWiz5\SDetect.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RegSvr32] C:\WINDOWS\System32\msmsgs.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [spoolsvv] C:\WINDOWS\System32\spoolsvv.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Image Transfer.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Add to AMV Convert Tool… - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\user\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by24fd.bay24.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1123676113109
O16 - DPF: {7606693A-C18D-4567-AF85-6194FF70761E} (GomWeb Control) - http://app.ipop.co.kr/gom/GomWeb.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/gamedownlo…GPlugin9USA.cab
O16 - DPF: {D0FD5E32-CABD-4A6E-BD0F-94ACE89CCE03} (HGPluginJP23 Class) - http://down.hangame.co.jp/jp/dist/hgstart/HGPluginJP23.cab
O18 - Protocol hijack: http - {7PHANMH5-HW{PH11GE-8{PH-00HAIH4{PH0M}
O18 - Protocol hijack: its - >IT14H2N1HBIH8-1HT0GAIT{-H000H8IH49PH}
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL (file missing)
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL (file missing)
O18 - Protocol hijack: tv - {HBIH08PH-MG4I-11H2-MHDIH00PH4MGBIT6P}
O18 - Protocol hijack: wia - >I3{3HANMH9IH7-4H0MGAI76-H2NMHAIHW{PH}
O20 - Winlogon Notify: botreg - C:\Documents and Settings\All Users\Documents\Settings\bot.dll
O20 - Winlogon Notify: cfgmngr32 - C:\WINDOWS\system32\hk.dll
O20 - Winlogon Notify: partnershipreg - C:\Documents and Settings\All Users\Documents\Settings\partnership.dll
O20 - Winlogon Notify: rpcc - C:\WINDOWS\System32\rpcc.dll
O20 - Winlogon Notify: st3 - C:\WINDOWS\system32\st3.dll
O20 - Winlogon Notify: style32 - C:\WINDOWS\q277796.dll
O20 - Winlogon Notify: winsys2freg - C:\Documents and Settings\All Users\Documents\Settings\winsys2f.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\System32\UAService7.exe
Hello DrakeBlaze and welcome to the SpywareSupport Forums

My name is Trevuren and I will be helping you with your problem.


Download haxfix.exe
and save it to your desktop.
  • Double click on haxfix.exe to install haxfix. (standard installation path is c:\program Files\haxfix)
  • Checkmark "Create a desktop icon"
  • Click "Next"
  • When the installation is completed, make sure that the checkmark "Launch HaxFix" is placed
  • Click "Finish"
A red "dos window" (dos box) will open with options:
1. Make logfile
2. Run auto fix
3. Run manual fix
E. Exit Haxfix
  • Select option 1. Make logfile by typing 1 and then pressing Enter
  • Haxfix will start scanning the computer. When it is finished a logfile will open: haxlog.txt
  • Copy the contents of that logfile and paste it into this thread. (c:\haxfix.txt)
DO NOT run any other options unless directed to do do

Regards,

Trevuren
Thanks alot for the quick response. Below is the logfile. Kinda long though…

HAXFIX logfile - by Marckie

version 4.50
18/08/2007 10:22:19.45

— Checking for Haxdoor —

checking for a3d files
a3d files not found

checking for matching notify keys
no matching notify keys found

checking for matching services
matching services found
ASPI32

checking for matching safeboot services
no matching safeboot services found

checking for other Haxdoor-files
no other Haxdoor-files found


— Checking for Goldun —

checking for SSODL keys
no ssodl keys found

checking for notify keys
no notify keys found

checking for services
no services found

checking for other Goldun-files
no other Goldun-files found

checking iexplore.exe
iexplore.exe is not infected


— Catchme logfile - thank you Gmer —

catchme 0.3.1066 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-18 10:22:19
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden services & system hive …

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ntio256]
"Type"=dword:00000001
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=str(2):"\??\C:\WINDOWS\System32\ntio256.sys"
"DisplayName"="Input and output operations"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\pe386]
"Type"=dword:00000001
"Start"=dword:00000001
"ErrorControl"=dword:00000000
"ImagePath"=str(2):"\??\C:\WINDOWS\System32:lzx32.sys"
"DisplayName"="Win23 lzx files loader"
"Group"="Base"
"ExtParam"=hex:e8,db,98,ac,2a,4e,c1,32,7e,7b,de,6e,46,51,f6,3e
"Checked"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\pe386\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{BA318D17-4033-4A9B-9AEE-C358124E5998}]
"LeaseObtainedTime"=dword:46c65782
"T1"=dword:46c65801
"T2"=dword:46c65861
"LeaseTerminatesTime"=dword:46c65881
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{BA318D17-4033-4A9B-9AEE-C358124E5998}\Parameters\Tcpip]
"LeaseObtainedTime"=dword:46c65782
"T1"=dword:46c65801
"T2"=dword:46c65861
"LeaseTerminatesTime"=dword:46c65881
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ntio256]
"Type"=dword:00000001
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=str(2):"\??\C:\WINDOWS\System32\ntio256.sys"
"DisplayName"="Input and output operations"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\pe386]
"Type"=dword:00000001
"Start"=dword:00000001
"ErrorControl"=dword:00000000
"ImagePath"=str(2):"\??\C:\WINDOWS\System32:lzx32.sys"
"DisplayName"="Win23 lzx files loader"
"Group"="Base"
"ExtParam"=hex:e8,db,98,ac,2a,4e,c1,32,7e,7b,de,6e,46,51,f6,3e
"Checked"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\pe386\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,..

scanning hidden registry entries …

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\Documents and Settings\user\Start Menu\Programs\Windows XP Creativity Fun Packs\Windows Movie Maker 2\"=""
"C:\Documents and Settings\user\Application Data\Microsoft\Installer\{3C26E039-BE18-4B5E-A723-45390C451819}\"=""
"C:\Documents and Settings\user\Application Data\Microsoft\Installer\"=""
"C:\Program Files\Sports Interactive\Football Manager 2005\data\"="1"
"C:\Program Files\Sports Interactive\Football Manager 2005\"="1"
"C:\Program Files\Sports Interactive\"="1"
"C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\"="1"
"C:\Program Files\Adobe\Acrobat 7.0\Reader\"="1"
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\VDKHome\ENU\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\VDKHome\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\"=""
"C:\Program Files\Adobe\Acrobat 7.0\ActiveX\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\AcroForm\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\WebSearch\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\AcroForm\PMP\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Multimedia\MPP\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Multimedia\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Help\ENU\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Help\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\Howto\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\OLS\Locale\ENU\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\OLS\Locale\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\OLS\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\Templates\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\Howto\images\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\Updater\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Resource\CMap\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Resource\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Resource\Font\PFM\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Resource\Font\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\Optional\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Annotations\Stamps\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Annotations\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Annotations\Stamps\ENU\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\HowTo\ENU\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\HowTo\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\HowTo\ENU\Images\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\SPPlugins\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Esl\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\Javascripts\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\Legal\Adobe Reader\7.0.0\en_US\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\Legal\Adobe Reader\7.0.0\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\Legal\Adobe Reader\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\Legal\"=""
"C:\Documents and Settings\All Users\Application Data\Adobe\Acrobat\7.0\Replicate\Security\"=""
"C:\Documents and Settings\All Users\Application Data\Adobe\Acrobat\7.0\Replicate\"=""
"C:\Documents and Settings\All Users\Application Data\Adobe\Acrobat\7.0\"=""
"C:\Documents and Settings\All Users\Application Data\Adobe\Acrobat\"=""
"C:\Documents and Settings\All Users\Application Data\Adobe\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\Messages\ENU\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\Messages\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\ImageViewer\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\ImageViewer\en_US\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins3d\"=""
"C:\Program Files\Common Files\Adobe\TypeSpt\Unicode\Mappings\Mac\"=""
"C:\Program Files\Common Files\Adobe\TypeSpt\Unicode\Mappings\"=""
"C:\Program Files\Common Files\Adobe\TypeSpt\Unicode\"=""
"C:\Program Files\Common Files\Adobe\TypeSpt\"=""
"C:\Program Files\Common Files\Adobe\"=""
"C:\Program Files\Common Files\Adobe\TypeSpt\Unicode\Mappings\Adobe\"=""
"C:\Program Files\Common Files\Adobe\TypeSpt\Unicode\Mappings\win\"=""
"C:\Program Files\Common Files\Adobe\TypeSpt\Unicode\ICU\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Resource\Linguistics\LanguageNames\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Resource\Linguistics\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Resource\Linguistics\Providers\Proximity\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Resource\Linguistics\Providers\"=""
"C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A70000000000}\"=""
"C:\WINDOWS\Installer\{ABEB838C-A1A7-4C5D-B7E1-8B4314600429}\"=""
"C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\"="1"
"C:\Program Files\Common Files\InstallShield\Driver\8\"="1"
"C:\Program Files\Common Files\InstallShield\Driver\"="1"
"C:\Program Files\KONAMI\Winning Eleven 7I\dat\"=""
"C:\Program Files\KONAMI\Winning Eleven 7I\"=""
"C:\Program Files\KONAMI\"=""
"C:\Documents and Settings\All Users\Start Menu\Programs\KONAMI\Winning Eleven 7 INTERNATIONAL\"=""
"C:\Documents and Settings\All Users\Start Menu\Programs\KONAMI\"=""
"C:\WINDOWS\Installer\{71493403-7C93-48CC-BF19-C73DB1DB7B17}\"=""
"C:\Program Files\Common Files\InstallShield\Driver\10\Intel 32\"="1"
"C:\Program Files\Common Files\InstallShield\Driver\10\"="1"
"C:\Program Files\GAMEFLIER\TSONLINE\"="1"
"C:\Program Files\GAMEFLIER\"="1"
"C:\Program Files\Common Files\InstallShield\UpdateService\"="1"
"C:\Program Files\Common Files\InstallShield\UpdateService\images\"="1"
"C:\Program Files\GAMEFLIER\TSONLINE\user\"=""
"C:\Program Files\Windows Journal Viewer\"=""
"C:\Program Files\Common Files\Microsoft Shared\Ink\"=""
"C:\Program Files\Movie Maker\Shared\Profiles\"="1"
"C:\Program Files\Movie Maker\Shared\"="1"
"C:\Program Files\Movie Maker\1033\"=""
"C:\WINDOWS\Installer\{49FC50FC-F965-40D9-89B4-CBFF80941033}\"=""
"C:\Program Files\GameShadow\"="1"
"C:\Program Files\Microsoft AntiSpyware\"=""
"C:\Documents and Settings\All Users\Application Data\Apple Computer\iTunes\SC Info\"="1"
"C:\Documents and Settings\All Users\Application Data\Apple Computer\iTunes\"="1"
"C:\Documents and Settings\All Users\Application Data\Apple Computer\"="1"
"C:\Documents and Settings\All Users\Application Data\Microsoft\IdentityCRL\"=""
"C:\Program Files\Sports Interactive\Football Manager 2006\data\"="1"
"C:\Program Files\Sports Interactive\Football Manager 2006\"="1"
"C:\Program Files\Sports Interactive\Football Manager 2006\data\graphics\pictures\"="1"
"C:\Program Files\Sports Interactive\Football Manager 2006\data\graphics\"="1"
"C:\Program Files\Sports Interactive\Football Manager 2006\data\graphics\pictures\players\"="1"
"C:\Program Files\Sports Interactive\Football Manager 2006\data\graphics\pictures\players\eng\"="1"
"C:\Program Files\Sports Interactive\Football Manager 2006\data\graphics\pictures\players\eng\league one\"="1"
"C:\Program Files\Sports Interactive\Football Manager 2006\data\graphics\pictures\players\sco\"="1"
"C:\Program Files\Sports Interactive\Football Manager 2006\data\graphics\pictures\players\sco\spl\"="1"
"C:\Program Files\Sports Interactive\Football Manager 2006\data\languages\"=""
"C:\Documents and Settings\user\Application Data\Jasc Software Inc\Paint Shop Pro 8\Cache\"="1"
"C:\Documents and Settings\user\Application Data\Jasc Software Inc\Paint Shop Pro 8\"="1"
"C:\Documents and Settings\user\Application Data\Jasc Software Inc\"="1"
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\"="1"
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\CMYK Profiles\"="1"
"C:\Documents and Settings\user\My Documents\My PSP8 Files\"="1"
"C:\Documents and Settings\user\My Documents\My PSP8 Files\Scripts-Restricted\"="1"
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\PlugIns\"="1"
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\"="1"
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\"="1"
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\"="1"
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\"="1"
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\"="1"
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\"="1"
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\TCL\"="1"
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\"="1"
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Brushes\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Bump Maps\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Deformation Maps\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Environment Maps\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Gradients\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Masks\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Palettes\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Patterns\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Picture Frames\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Picture Tubes\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Preset Shapes\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Presets\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Print Templates\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Assign a keyboard shortcut - An example\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Assign a keyboard shortcut - An example\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Assign a keyboard shortcut - An example\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Basic scripting\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Basic scripting\CSS\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Basic scripting\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Basic scripting\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a custom toolbar\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a custom toolbar\CSS\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a custom toolbar\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a custom toolbar\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a dialog Preset - An example\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a dialog Preset - An example\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a dialog Preset - An example\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a dialog Preset - An example\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a tool Preset - An example\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a tool Preset - An example\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a tool Preset - An example\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a tool Preset - An example\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Rename multiple files simultaneously\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Rename multiple files simultaneously\CSS\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Rename multiple files simultaneously\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Rename multiple files simultaneously\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Run a script on multiple files\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Run a script on multiple files\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Run a script on multiple files\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Separate a tool from its flyout\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Separate a tool from its flyout\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Separate a tool from its flyout\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Create a new image\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Create a new image\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Create a new image\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Create a new image\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Crop an image\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Crop an image\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Crop an image\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Crop an image\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\E-mail an image\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\E-mail an image\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\E-mail an image\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\E-mail an image\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Open a saved image\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Open a saved image\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Open a saved image\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Open a saved image\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Resize an image\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Resize an image\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Resize an image\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Resize an image\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Rotate a photo\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Rotate a photo\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Rotate a photo\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Rotate a photo\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take a Window screen capture\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take a Window screen capture\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take a Window screen capture\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take a Window screen capture\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take an Area screen capture\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take an Area screen capture\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take an Area screen capture\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take an Area screen capture\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Correct perspective distortion\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Correct perspective distortion\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Correct perspective distortion\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Correct perspective distortion\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Fix a photo\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Fix a photo\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Fix a photo\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Fix a photo\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Remove red-eye\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Remove red-eye\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Remove red-eye\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Remove red-eye\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Straighten a crooked photo\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Straighten a crooked photo\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Straighten a crooked photo\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Straighten a crooked photo\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add a drop shadow and caption\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add a drop shadow and caption\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add a drop shadow and caption\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add a picture frame\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add a picture frame\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add a picture frame\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add a picture frame\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a path - An example\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a path - An example\CSS\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a path - An example\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a path - An example\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a separate layer\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a separate layer\CSS\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a separate layer\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a separate layer\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Create a seamless tiled image\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Create a seamless tiled image\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Create a seamless tiled image\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Create a seamless tiled image\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Convert a photo into a greeting card\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Convert a photo into a greeting card\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Convert a photo into a greeting card\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Convert a photo into a greeting card\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create depth of field\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create depth of field\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create depth of field\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create depth of field\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 1\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 1\CSS\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 1\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 1\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 2\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 2\CSS\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 2\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 2\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Erase an image background\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Erase an image background\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Erase an image background\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Erase an image background\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a photo look old\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a photo look old\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a photo look old\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a photo look old\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a selection greyscale\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a selection greyscale\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a selection greyscale\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a selection greyscale\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Modify a photo via blend modes\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Modify a photo via blend modes\CSS\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Modify a photo via blend modes\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Modify a photo via blend modes\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Upload photos to a PhotoSharing site\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Upload photos to a PhotoSharing site\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Upload photos to a PhotoSharing site\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Upload photos to a PhotoSharing site\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Basic\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Basic\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Basic\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Basic\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Intermediate\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Intermediate\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Intermediate\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Intermediate\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Sample Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Scripts-Restricted\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Scripts-Trusted\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Selections\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Styled Lines\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Swatches\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Textures\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Learning Center\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\PostScript Resources\Fonts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\PostScript Resources\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Commands\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Workspaces\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\PhotoServices\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\DLLs\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\Lib\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\Lib\compiler\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\Lib\distutils\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\Lib\distutils\command\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\Lib\email\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\Lib\encodings\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\Lib\hotshot\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\Lib\lib-old\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\Lib\lib-tk\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\Lib\site-packages\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\Lib\xml\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\Lib\xml\dom\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\Lib\xml\parsers\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\Lib\xml\sax\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\TCL\tcl8.3\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\TCL\tcl8.3\dde1.1\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\TCL\tcl8.3\encoding\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\TCL\tcl8.3\http1.0\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\TCL\tcl8.3\http2.3\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\TCL\tcl8.3\msgcat1.0\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\TCL\tcl8.3\opt0.4\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\TCL\tcl8.3\reg1.0\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\TCL\tcl8.3\tcltest1.0\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\TCL\tk8.3\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\TCL\tk8.3\demos\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\TCL\tk8.3\demos\images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\TCL\tk8.3\images\"=""
"C:\Documents and Settings\All Users\Start Menu\Programs\Jasc Software\"=""
"C:\WINDOWS\Installer\{81A34902-9D0B-4920-A25C-4CDC5D14B328}\"=""
"C:\Config.Msi\"=""
"C:\Program Files\MP3 Player Utilities 4.00\"="1"
"C:\Program Files\MP3 Player Utilities 4.00\RDiskUtility\sys\"=""
"C:\Program Files\MP3 Player Utilities 4.00\RDiskUtility\"=""
"C:\Program Files\MP3 Player Utilities 4.00\AMVPlayer\skin\xpstyle\"=""
"C:\Program Files\MP3 Player Utilities 4.00\AMVPlayer\skin\"=""
"C:\Program Files\MP3 Player Utilities 4.00\AMVPlayer\"=""
"C:\Program Files\MP3 Player Utilities 4.00\MediaManager\"=""
"C:\Program Files\MP3 Player Utilities 4.00\MediaManager\help\"=""
"C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\skin\xpstyle\"=""
"C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\skin\"=""
"C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\"=""
"C:\Program Files\MP3 Player Utilities 4.00\Windows98Drv\"=""
"C:\Program Files\MP3 Player Utilities 4.00\RDiskUpdate\"=""
"C:\Program Files\MP3 Player Utilities 4.00\RDiskUpdate\driver\"=""
"C:\Documents and Settings\user\Start Menu\Programs\MP3 Player Utilities 4.00\"=""
"C:\Documents and Settings\user\Application Data\Microsoft\Installer\{7784A172-61F1-445E-8368-601607E0DD22}\"=""
"C:\Program Files\BillP Studios\WinPatrol\"="1"
"C:\Program Files\BillP Studios\"="1"
"C:\Program Files\BillP Studios\WinPatrol\kbase\"=""
"C:\Documents and Settings\All Users\Start Menu\Programs\WinPatrol\"=""
"C:\WINDOWS\Installer\{3205A978-4A7A-403B-A4B9-D48E6BAFB73B}\"=""
"C:\WINDOWS\PCHEALTH\ERRORREP\"="1"
"C:\WINDOWS\PCHEALTH\ERRORREP\QHEADLES\"="1"
"C:\WINDOWS\PCHEALTH\ERRORREP\QSIGNOFF\"="1"
"C:\Program Files\Common Files\Microsoft Shared\DW\"=""
"C:\WINDOWS\winsxs\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\"=""
"C:\WINDOWS\winsxs\Policies\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_77c24773\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\"=""
"C:\Program Files\MSN Messenger\Device Manager\"=""
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\"=""
"C:\WINDOWS\Installer\{43DCF766-6838-4F9A-8C91-D92DA586DFA8}\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\"="1"
"C:\WINDOWS\Microsoft.NET\Framework\"="1"
"C:\WINDOWS\Microsoft.NET\"="1"
"C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\"=""
"C:\WINDOWS\winsxs\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\"=""
"C:\WINDOWS\Installer\{40ABF1E0-8B6F-4D32-B343-E19FA2F04B3C}\"=""
"C:\Program Files\Common Files\Microsoft Shared\DW\1033\"=""
"C:\Documents and Settings\All Users\Application Data\Microsoft\IdentityCRL\production\"=""
"C:\WINDOWS\Installer\{FCE50DB8-C610-4C42-BE5C-193F46C6F812}\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\18\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\8\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\25\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\7\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\1046\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\17\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\4\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\1028\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\10\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\12\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\11\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\20\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\9\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\16\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\29\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\6\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\31\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\22\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\19\"=""
"C:\WINDOWS\Installer\{571700F0-DB9D-4B3A-B03D-35A14BB5939F}\"=""
"C:\Documents and Settings\user\Application Data\Microsoft\Installer\{F58E04CD-6E76-43C8-AAF1-482225C2910E}\"=""
"C:\Program Files\MindFusion Limited\Xml Viewer\"=""
"C:\Program Files\MindFusion Limited\"=""
"C:\Documents and Settings\user\Start Menu\Programs\XML Viewer\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Users\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Users\App_LocalResources\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_GlobalResources\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\AppConfig\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\AppConfig\App_LocalResources\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_Code\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RedistList\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\Browsers\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Providers\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Providers\App_LocalResources\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Wizard\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Wizard\App_LocalResources\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Permissions\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Permissions\App_LocalResources\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_LocalResources\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_Data\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Roles\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Roles\App_LocalResources\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MSBuild\"=""
"C:\WINDOWS\System32\MUI409\"=""
"C:\Program Files\Internet Explorer\MUI409\"=""
"C:\Program Files\Internet Explorer\MUI\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MUI409\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MUI\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\App_LocalResources\"=""
"C:\Program Files\Common Files\Microsoft Shared\DW\1025\"=""
"C:\Program Files\Common Files\Microsoft Shared\DW\1028\"=""
"C:\Program Files\Common Files\Microsoft Shared\DW\1031\"=""
"C:\Program Files\Common Files\Microsoft Shared\DW\1036\"=""
"C:\Program Files\Common Files\Microsoft Shared\DW\1040\"=""
"C:\Program Files\Common Files\Microsoft Shared\DW\1041\"=""
"C:\Program Files\Common Files\Microsoft Shared\DW\1042\"=""
"C:\Program Files\Common Files\Microsoft Shared\DW\2052\"=""
"C:\Program Files\Common Files\Microsoft Shared\DW\3082\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\"=""
"C:\Documents and Settings\user\Start Menu\Programs\XML Notepad 2007\"="1"
"C:\Program Files\XML Notepad 2007\Samples\"=""
"C:\Program Files\XML Notepad 2007\"=""
"C:\Documents and Settings\user\Application Data\Microsoft\Installer\{259B9457-855A-4FA1-8AFE-3613ADF11973}\"=""
"C:\WINDOWS\Installer\{C0B0FA55-D4E9-4374-9871-BBFBF2AEF0D1}\"=""
"C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\"=""
"C:\Program Files\Common Files\Java\Update\Base Images\"=""
"C:\Program Files\Common Files\Java\Update\"=""
"C:\Program Files\Common Files\Java\"=""
"C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_01.b06\"=""
"C:\Program Files\Java\jre1.6.0_01\"=""
"C:\Program Files\Java\"=""
"C:\Program Files\Java\jre1.6.0_01\bin\"=""
"C:\WINDOWS\Installer\{3248F0A8-6813-11D6-A77B-00B0D0160010}\"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\TempPackages]
"C:\WINDOWS\Installer\{40ABF1E0-8B6F-4D32-B343-E19FA2F04B3C}\NewShortcut3_7D8636620AB440BDAD9FA2ED548C3187.exe"=dword:00000001
"C:\WINDOWS\Installer\{40ABF1E0-8B6F-4D32-B343-E19FA2F04B3C}\NewShortcut5_7D8636620AB440BDAD9FA2ED548C3187.exe"=dword:00000001
"C:\WINDOWS\Installer\{40ABF1E0-8B6F-4D32-B343-E19FA2F04B3C}\NewShortcut6_7D8636620AB440BDAD9FA2ED548C3187.exe"=dword:00000001
"C:\WINDOWS\Installer\{40ABF1E0-8B6F-4D32-B343-E19FA2F04B3C}\NewShortcut1_7D8636620AB440BDAD9FA2ED548C3187.exe"=dword:00000001
"C:\WINDOWS\Installer\94838.msi"=dword:00000000
"C:\WINDOWS\Installer\{FCE50DB8-C610-4C42-BE5C-193F46C6F812}\MsblIco.Exe"=dword:00000001
"C:\WINDOWS\Installer\179b29.msi"=dword:00000000
"C:\Documents and Settings\user\Application Data\Microsoft\Installer\{F58E04CD-6E76-43C8-AAF1-482225C2910E}\_294823.exe"=dword:00000001
"C:\Documents and Settings\user\Application Data\Microsoft\Installer\{F58E04CD-6E76-43C8-AAF1-482225C2910E}\_18be6784.exe"=dword:00000001
"C:\WINDOWS\Installer\502c10.msi"=dword:00000000
"C:\WINDOWS\Installer\{C0B0FA55-D4E9-4374-9871-BBFBF2AEF0D1}\ARPPRODUCTICON.exe"=dword:00000001
"C:\WINDOWS\Installer\{C0B0FA55-D4E9-4374-9871-BBFBF2AEF0D1}\_8EC6B7AB_355B_462C_9D83_9BC4542FE459"=dword:00000001
"C:\WINDOWS\Installer\{C0B0FA55-D4E9-4374-9871-BBFBF2AEF0D1}\_F624FE6F_E3BC_4809_964E_021BF257D72D"=dword:00000001
"C:\WINDOWS\Installer\{C0B0FA55-D4E9-4374-9871-BBFBF2AEF0D1}\pando.exe_ED0ECD11C6AB405E9A06D25E96BD6FD7.exe"=dword:00000001
"C:\WINDOWS\Installer\{C0B0FA55-D4E9-4374-9871-BBFBF2AEF0D1}\pando.exe1_ED0ECD11C6AB405E9A06D25E96BD6FD7.exe"=dword:00000001
"C:\WINDOWS\Installer\{C0B0FA55-D4E9-4374-9871-BBFBF2AEF0D1}\NewShortcut4_C0B0FA55D4E943749871BBFBF2AEF0D1.exe"=dword:00000001
"C:\WINDOWS\Installer\{C0B0FA55-D4E9-4374-9871-BBFBF2AEF0D1}\NewShortcut3_C0B0FA55D4E943749871BBFBF2AEF0D1.exe"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs]
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Print Templates\MIPTemplate_Print_3.5 x 5 + Mini Wallet.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Assign a keyboard shortcut - An example\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Assign a keyboard shortcut - An example\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Assign a keyboard shortcut - An example\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Basic scripting\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Basic scripting\CSS\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Basic scripting\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Basic scripting\Scripts\start_prod_tour_10.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a custom toolbar\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a custom toolbar\CSS\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a custom toolbar\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a custom toolbar\Scripts\start_prod_tour_7.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a dialog Preset - An example\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a dialog Preset - An example\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a dialog Preset - An example\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a dialog Preset - An example\Scripts\NewImage_dialog.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a tool Preset - An example\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a tool Preset - An example\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a tool Preset - An example\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a tool Preset - An example\Scripts\Text.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Rename multiple files simultaneously\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Rename multiple files simultaneously\CSS\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Rename multiple files simultaneously\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Rename multiple files simultaneously\Scripts\start_prod_tour_12.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Run a script on multiple files\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Run a script on multiple files\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Run a script on multiple files\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Separate a tool from its flyout\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Separate a tool from its flyout\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Separate a tool from its flyout\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Create a new image\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Create a new image\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Create a new image\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Create a new image\Scripts\NewImage_dialog.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Crop an image\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Crop an image\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Crop an image\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Crop an image\Scripts\crop.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\E-mail an image\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\E-mail an image\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\E-mail an image\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\E-mail an image\Scripts\Send_dialog.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Open a saved image\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Open a saved image\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Open a saved image\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Open a saved image\Scripts\Browser_dialog.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Resize an image\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Resize an image\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Resize an image\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Resize an image\Scripts\Resize_dialog.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Rotate a photo\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Rotate a photo\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Rotate a photo\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Rotate a photo\Scripts\Rotate_dialog.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take a Window screen capture\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take a Window screen capture\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take a Window screen capture\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take a Window screen capture\Scripts\OpenCapSetup_dialog.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take an Area screen capture\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take an Area screen capture\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take an Area screen capture\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take an Area screen capture\Scripts\OpenCapSetup_dialog.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Correct perspective distortion\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Correct perspective distortion\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Correct perspective distortion\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Correct perspective distortion\Scripts\PerspectiveTransform.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Fix a photo\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Fix a photo\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Fix a photo\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Fix a photo\Scripts\Choose_OSPF.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Remove red-eye\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Remove red-eye\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Remove red-eye\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Remove red-eye\Scripts\RedEye_dialog.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Straighten a crooked photo\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Straighten a crooked photo\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Straighten a crooked photo\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Straighten a crooked photo\Scripts\Straighten.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add a drop shadow and caption\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add a drop shadow and caption\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add a drop shadow and caption\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add a picture frame\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add a picture frame\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add a picture frame\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add a picture frame\Scripts\PicFrame.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a path - An example\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a path - An example\CSS\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a path - An example\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a path - An example\Scripts\CenterInCanvas.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a separate layer\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a separate layer\CSS\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a separate layer\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a separate layer\Scripts\Text.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Create a seamless tiled image\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Create a seamless tiled image\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Create a seamless tiled image\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Create a seamless tiled image\Scripts\SeamTile.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Convert a photo into a greeting card\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Convert a photo into a greeting card\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Convert a photo into a greeting card\Images\AddBorders_icon.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Convert a photo into a greeting card\Scripts\AddBorders_dialog.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create depth of field\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create depth of field\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create depth of field\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create depth of field\Scripts\FreehandSelection.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 1\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 1\CSS\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 1\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 1\Scripts\BrightContrast.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 2\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 2\CSS\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 2\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 2\Scripts\SoftFocus_dialog.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Erase an image background\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Erase an image background\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Erase an image background\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Erase an image background\Scripts\BackgroundEraser.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a photo look old\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a photo look old\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a photo look old\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a photo look old\Scripts\AddNoiseUni15Mono.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a selection greyscale\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a selection greyscale\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a selection greyscale\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a selection greyscale\Scripts\SelNone.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Modify a photo via blend modes\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Modify a photo via blend modes\CSS\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Modify a photo via blend modes\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Modify a photo via blend modes\Scripts\ChooseOverlay.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Upload photos to a PhotoSharing site\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Upload photos to a PhotoSharing site\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Upload photos to a PhotoSharing site\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Upload photos to a PhotoSharing site\Scripts\StartBrowser.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Basic\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Basic\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Basic\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Basic\Scripts\PaintBrush.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Intermediate\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Intermediate\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Intermediate\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Intermediate\Scripts\BrightContrast.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Sample Images\Flatiron Building.jpg"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Scripts-Restricted\BevelSelection.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Scripts-Trusted\AutoTuber.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Selections\1024 x 768.PspSelection"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Styled Lines\+Solid.PspStyledLine"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Swatches\Swatch_Animal_zebra.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Textures\Asphalt 01.bmp"=dword:00000001
"C:\WINDOWS\System32\mfc42.dll"=dword:00000003
"C:\WINDOWS\System32\msvcirt.dll"=dword:00000003
"C:\Program Files\Common Files\Ulead Systems\DVD\LDCdBldr.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\DVD\LdrtBurn.dll"=dword:00000002
"C:\Program Files\Common Files\Ulead Systems\DVD\LdvdRec.dll"=dword:00000002
"C:\Program Files\Common Files\Ulead Systems\DVD\LudfRdr.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\DVD\LudfWrtr.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\DVD\LXBurnCom.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRDrv.dll"=dword:00000002
"C:\Program Files\Common Files\Ulead Systems\DVD\UCDCfg.dat"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\AutoDetector\DetMethod.dll"=dword:00000002
"C:\Program Files\Common Files\Ulead Systems\AutoDetector\Monitor.exe"=dword:00000002
"C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRDrvRc.dll"=dword:00000002
"C:\Program Files\Common Files\Ulead Systems\AutoDetector\AutoDetector.chm"=dword:00000002
"C:\Program Files\Common Files\Ulead Systems\AutoDetector\Monitor_Res.dll"=dword:00000002
"C:\Program Files\Common Files\Ulead Systems\AutoDetector\u32Comm.dll"=dword:00000002
"C:\Program Files\Common Files\Ulead Systems\Mpeg\ac3aout.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\MCMpgDec.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\MPEGIN.DLL"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\MPGAOUT.DLL"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\mpgaparse.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\mpgcap32.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\mpgcheck.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\mpgmux.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\mpgvout.001"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\mpgvout.002"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\mpgvout.003"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\mpgvout.004"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\MPGVOUT.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\mpgvparse.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\mpg_dlg.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\pcmaout.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\uldsmpeg.ax"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\ulesmpeg.ax"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\ulmxmpeg.ax"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\ulspmpeg.ax"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\uvsc.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\DVD\LdrtDisc.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\DVD\LdvdEng.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\DVD\XDiscLayer.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\DVD\XLogUtil.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\DVD\XDiscLayerRC.dll"=dword:00000001
"C:\WINDOWS\System32\MSVCRTD.DLL"=dword:00000001
"C:\WINDOWS\Downloaded Program Files\messengerstatsclient.dll"=dword:00000001
"C:\Program Files\Common Files\InstallShield\Professional\RunTime91\Intel32\iKernel.dll"=dword:00000018
"C:\Program Files\Common Files\InstallShield\Professional\RunTime91\Intel32\Setup.dll"=dword:00000018
"C:\Program Files\Common Files\InstallShield\Professional\RunTime91\Intel32\DotNetInstaller.exe"=dword:00000018
"C:\Program Files\Common Files\InstallShield\Professional\RunTime91\Intel32\iscript.dll"=dword:00000018
"C:\Program Files\Common Files\InstallShield\Professional\RunTime91\Intel32\ctor.dll"=dword:00000018
"C:\Program Files\Common Files\InstallShield\Professional\RunTime91\Intel32\iuser.dll"=dword:00000018
"C:\Program Files\Common Files\InstallShield\Professional\RunTime91\Intel32\IGDI.dll"=dword:00000018
"C:\Documents and Settings\All Users\Application Data\Microsoft\IdentityCRL\production\ppcrlconfig.dll"=dword:00000002
"C:\Program Files\Windows Journal Viewer\JVNBDoc.dll"=dword:00000001
"C:\Program Files\Windows Journal Viewer\JVVWCTL.DLL"=dword:00000001
"C:\WINDOWS\Help\JntView.chm"=dword:00000001
"C:\Program Files\Windows Journal Viewer\jvintl.dll"=dword:00000001
"C:\Program Files\Windows Journal Viewer\jvinkseg.dll"=dword:00000001
"C:\WINDOWS\System32\inked.dll"=dword:00000001
"C:\Program Files\Common Files\Microsoft Shared\Ink\inkobj.dll"=dword:00000001
"C:\Program Files\Common Files\Microsoft Shared\Ink\tpcps.dll"=dword:00000001
"C:\WINDOWS\System32\wisptis.exe"=dword:00000001
"C:\WINDOWS\Downloaded Program Files\istactivex.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.tlb"=dword:00000002
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.tlb"=dword:00000002
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.JScript.tlb"=dword:00000002
"C:\WINDOWS\System32\mscories.dll"=dword:00000002
"C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\mscormmc.dll"=dword:00000002
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscoree.tlb"=dword:00000002
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorlib.tlb"=dword:00000002
"C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\mscormmc.cfg"=dword:00000002
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.tlb"=dword:00000002
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.tlb"=dword:00000002
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Drawing.tlb"=dword:00000002
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.tlb"=dword:00000002
"C:\Program Files\Opera\Program\Plugins\\NPSWF32.dll"=dword:00000003
"C:\WINDOWS\Downloaded Program Files\GomWeb3.dll"=dword:00000001
"C:\WINDOWS\System32\sirenacm.dll"=dword:00000001
"C:\WINDOWS\System32\msxml4.dll"=dword:00000001
"C:\WINDOWS\System32\msxml4r.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\Vsavb7rtUI.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\VsaVb7rt.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Vsa.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft_VsaVb.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ndpsetup.ico"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dv_aspnetmmc.chm"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallCommon.sql"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Aspnet.config"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\DefaultWsdlHelpGenerator.aspx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_filter.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallPersistSqlState.sql"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallSqlStateTemplate.sql"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallMembership.sql"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MmcAspExt.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AspNetMMCExt.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet.mof"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Aspnet_perf.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_perf.h"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\UninstallPersonalization.sql"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallProfile.SQL"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\Browsers\goAmerica.browser"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regiis.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Aspnet_regsql.exe.config"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\UninstallRoles.sql"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state_perf.h"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.tlb"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\UninstallPersistSqlState.sql"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\UninstallSqlStateTemplate.sql"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\web.config"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallWebEventSqlProvider.sql"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\web_mediumtrust.config.default"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\web_mediumtrust.config"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\web_minimaltrust.config.default"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\web_minimaltrust.config"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallSqlState.sql"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\UninstallSqlState.sql"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\webengine.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\web_hightrust.config"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\web_hightrust.config.default"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\web_lowtrust.config"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\web_lowtrust.config.default"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_perf.ini"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state_perf.ini"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\AppConfig\App_LocalResources\SmtpSettings.aspx.resx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_LocalResources\error.aspx.resx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Permissions\App_LocalResources\createPermission.aspx.resx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Providers\App_LocalResources\providerList.ascx.resx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_GlobalResources\AppConfigCommon.resx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Roles\App_LocalResources\manageSingleRole.aspx.resx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\App_LocalResources\setUpAuthentication.aspx.resx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Users\App_LocalResources\editUser.aspx.resx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Wizard\App_LocalResources\wizardAddUser.ascx.resx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_Data\GroupedProviders.xml"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\navigationBar.ascx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\AppConfig\SmtpSettings.aspx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_Code\WebAdminPage.cs"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\WebAdminHelp.aspx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\requiredBang.gif"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Permissions\managePermissions.aspx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Providers\ProviderList.ascx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Roles\manageSingleRole.aspx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\security.aspx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Users\addUser.aspx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Wizard\wizardAddUser.ascx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\alinkui.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\alink.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfdll.dll"=dword:00000001
"C:\WINDOWS\System32\dfshim.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Deployment.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\gacutil.exe.config"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\regsvcs.exe.config"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ieexec.exe.config"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\csc.exe.config"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\cscompui.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cscompmgd.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\csc.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cscomp.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cvtres.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\CvtResUI.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.JScript.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\jsc.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MSBuild.rsp"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Common.Tasks"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.CSharp.targets"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Engine.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Framework.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Tasks.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Utilities.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MSBuild\Microsoft.Build.Commontypes.xsd"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MSBuild\Microsoft.Build.Core.xsd"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.xsd"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\fusion.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsn.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\peverify.dll"=dword:00000001
"C:\Program Files\Internet Explorer\MUI409\mscorier.dll"=dword:00000001
"C:\WINDOWS\System32\mscoree.dll"=dword:00000001
"C:\WINDOWS\System32\mscorier.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\NETFXSBS10.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\sbscmp10.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Accessibility.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AdoNetDiag.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RedistList\FrameworkList.xml"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CasPol.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ilasm.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CLR.mof"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Thunk.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Security.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CORPerfMonExt.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CORPerfMonSymbols.h"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Culture.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CustomMarshalers.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\_dataperfcounters_shared12_neutral.h"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll"=dword:00000001
"C:\WINDOWS\System32\netfxperf.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\_NetworkingPerfCounters.h"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Configuration.Install.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.Protocols.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Drawing.Design.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.ServiceProcess.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.RegularExpressions.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.Services.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.XML.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Design.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEExec.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEExecRemote.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEHost.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IIEHost.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\installutil.exe.config"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallUtilLib.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ISymWrapper.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordbc.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordbi.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorie.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorld.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorpe.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvc.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscortim.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\netfxsbs12.hkf"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ngen.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\normalization.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\PerfCounter.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\sbscmp20_mscorwks.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\sbscmp20_perfcounter.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\SharedReg12.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\shfusion.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\SOS.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.OracleClient.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\_DataOracleClientPerfCounters_shared12_neutral.h"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.SqlXml.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Management.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Remoting.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\sysglobl.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.configuration.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Drawing.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Messaging.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Transactions.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.Mobile.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\TLBREF.DLL"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\WMINet_Utils.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\XPThemes.manifest"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\corperfmonsymbols.ini"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\_dataperfcounters_shared12_neutral.ini"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\_Networkingperfcounters.ini"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\_DataOracleClientPerfCounters_shared12_neutral.ini"=dword:00000001 "C:\WINDOWS\System32\MUI409\mscorees.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MUI409\mscorsecr.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\shfusion.chm"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ShFusRes.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\regtlibv12.exe"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\sbs_diasymreader.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\sbs_iehost.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\sbs_microsoft.jscript.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\sbs_microsoft.vsa.vb.codedomprocessor.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\sbs_mscordbi.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\sbs_mscorrc.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\sbs_mscorsec.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\sbs_system.configuration.install.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\sbs_system.data.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\sbs_system.enterpriseservices.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\sbs_VsaVb7rt.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\sbs_wminet_utils.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\vbc7ui.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\vbc.exe"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\vbc.exe.config"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualC.Dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\System.Windows.Forms.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Windows.Forms.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorlib.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscoree.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Drawing.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\System.EnterpriseServices.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\Microsoft.JScript.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\Microsoft.Vsa.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\System.Drawing.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\mscoree.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.EnterpriseServices.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Microsoft.JScript.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Microsoft.Vsa.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Microsoft.Vsa.Vb.CodeDOMProcessor.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\mscorlib.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\System.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\Microsoft.Vsa.Vb.CodeDOMProcessor.tlb"=dword:00001000 "C:\WINDOWS\feedingfrenzy.scr"=dword:00000001 "C:\WINDOWS\Downloaded Program Files\HGStart9USA.exe"=dword:00000001 "C:\WINDOWS\Downloaded Program Files\HGPlugin9USA.dll"=dword:00000001 "C:\WINDOWS\Downloaded Program Files\hgstartjp23.exe"=dword:00000001 "C:\WINDOWS\Downloaded Program Files\hgnotifyjp23.exe"=dword:00000001 "C:\WINDOWS\Downloaded Program Files\HGPluginJP23.dll"=dword:00000001 "C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\other.zip"=dword:00000001 "C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\core1.zip"=dword:00000001 "C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\core2.zip"=dword:00000001 "C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\core3.zip"=dword:00000001 "C:\WINDOWS\System32\OggDS.dll"=dword:00000001 "C:\Program Files\Creative\Shared Files\MtpManU.dll"=dword:00000006 "C:\Program Files\Creative\Shared Files\VFSvrps.dll"=dword:00000006 "C:\Program Files\Creative\Shared Files\VFSvrU.exe"=dword:00000006 "C:\Program Files\Creative\Shared Files\OpaQManU.exe"=dword:00000004 "C:\Program Files\Creative\Shared Files\OpqManps.dll"=dword:00000004 "C:\Program Files\Creative\Shared Files\CTXMLPsu.dll"=dword:00000006 "C:\Program Files\Creative\Shared Files\CDDBControlCreative.dll"=dword:00000002 "C:\Program Files\Creative\Shared Files\CDDBUICreative.dll"=dword:00000002 "C:\Program Files\Creative\Shared Files\CTFRConv.ax"=dword:00000005 "C:\Program Files\Creative\Shared Files\CTQTSF.ax"=dword:00000005 "C:\Program Files\Creative\Shared Files\Mp3Dump.ax"=dword:00000005 "C:\Program Files\Creative\Shared Files\VidProcU.ax"=dword:00000005 "C:\Program Files\Creative\Shared Files\WavTrans.ax"=dword:00000005 "C:\Program Files\Creative\ZENcast Organizer\AVSrcU.dll"=dword:00000001 "C:\Program Files\Creative\ZENcast Organizer\CTIntrfu.dll"=dword:00000001 "C:\Program Files\Creative\ZENcast Organizer\CTRegSvu.exe"=dword:00000001 "C:\Program Files\Creative\Shared Files\PlayManU.dll"=dword:00000001 "C:\Program Files\Creative\ZENcast Organizer\Id3Tagu.mft"=dword:00000001 "C:\Program Files\Creative\ZENcast Organizer\TagMgru.mft"=dword:00000001 "C:\Program Files\Creative\ZENcast Organizer\WmaTagu.mft"=dword:00000001 "C:\Program Files\Creative\ZENcast Organizer\Tag.crl"=dword:00000001 "C:\Program Files\Creative\ZENcast Organizer\AVConvU.dll"=dword:00000001 "C:\Program Files\Creative\Shared Files\CTRegSvr.exe"=dword:00000004 "C:\Program Files\Creative\Shared Files\PDEJB.pid"=dword:00000003 "C:\Program Files\Creative\Shared Files\PdtIdMgr.pid"=dword:00000004 "C:\Program Files\Common Files\Creative\Installation\Brazil\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Common\Common.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Common\Error.ini"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Common\RegEdit.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Common\_setup.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Danish\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Dutch\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\English\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Finnish\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\French\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\German\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Italian\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Japanese\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Korean\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Norwegian\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\PChinese\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Port\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Spanish\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Swedish\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\TChinese\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Turkish\_IsUser.dll"=dword:00000006 "C:\Program Files\Creative\MediaSource5\CTIntrfc.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTIntrfu.dll"=dword:0000000b "C:\Program Files\Creative\MediaSource5\CTLogDBu.dll"=dword:00000003 "C:\Program Files\Creative\MediaSource5\CTRegSvu.exe"=dword:0000000b "C:\Program Files\Creative\MediaSource5\HookWndU.dll"=dword:00000002 "C:\WINDOWS\System32\CTSVCCDA.EXE"=dword:00000001 "C:\WINDOWS\System32\CTSVCCTL.EXE"=dword:00000001 "C:\Program Files\Creative\Shared Files\MDAQMGRU.DLL"=dword:00000001 "C:\Program Files\Creative\Shared Files\CDAsvc.exe"=dword:00000001 "C:\Program Files\Creative\ShareDLL\CADI\ctaudspi.dll"=dword:00000001 "C:\Program Files\Creative\ShareDLL\CADI\ctcadi.dll"=dword:00000001 "C:\Program Files\Creative\ShareDLL\CADI\ctdmzspi.dll"=dword:00000001 "C:\Program Files\Creative\ShareDLL\CADI\ctksspi.dll"=dword:00000001 "C:\Program Files\Creative\ShareDLL\CADI\ctmbspi.dll"=dword:00000001 "C:\Program Files\Creative\ShareDLL\CADI\ctphme.dat"=dword:00000001 "C:\Program Files\Creative\ShareDLL\CADI\CTPLang.dat"=dword:00000001 "C:\Program Files\Creative\ShareDLL\CADI\CTPreset.dll"=dword:00000001 "C:\Program Files\Creative\ShareDLL\CADI\ctpxspi.dll"=dword:00000001 "C:\Program Files\Creative\ShareDLL\CADI\ctsf.dll"=dword:00000001 "C:\Program Files\Creative\ShareDLL\CADI\DBACS.dll"=dword:00000001 "C:\Program Files\Creative\ShareDLL\CADI\NotiMan.dll"=dword:00000001 "C:\Program Files\Creative\ShareDLL\CADI\NotiMan.exe"=dword:00000001 "C:\Program Files\Creative\ShareDLL\CADI\P0005_01.dat"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTDBEngu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTMetaDu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTNJBDBu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTXMLPsu.dll"=dword:00000002 "C:\Program Files\Creative\MediaSource5\Id3Tagu.mft"=dword:00000003 "C:\Program Files\Creative\MediaSource5\TagMgru.mft"=dword:00000003 "C:\Program Files\Creative\MediaSource5\WmaTagu.mft"=dword:00000003 "C:\Program Files\Creative\MediaSource5\Tag.crl"=dword:00000003 "C:\Program Files\Creative\Shared Files\AC3Srcu.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\AuChnMap.dll"=dword:00000001 "C:\Program Files\Creative\Shared Files\AudGain.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\CDDA.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\CMSS3.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\CTDAE.dll"=dword:00000001 "C:\Program Files\Creative\Shared Files\CTIntrfu.dll"=dword:00000001 "C:\Program Files\Creative\Shared Files\CTNeo6.dll"=dword:00000001 "C:\Program Files\Creative\Shared Files\CTRegSvu.exe"=dword:00000001 "C:\Program Files\Creative\Shared Files\DSCompr.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\InetSrcu.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\Karaoke.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\LiveRecu.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\MetaBPMu.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\MetaSVMu.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\MlpSrcu.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\MP3Write.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\NoisRedu.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\NvfSrcu.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\PDP.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\RawWritu.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\TimeScal.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\Upsample.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\Virtual.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\WavWrite.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\WmaSrc.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\WMAWrite.ax"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CDRipu.scm"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CodcMgru.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CrBufEnu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTDRMUIu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTPlyQ2U.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTSPB.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\EffcMgru.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\FilWritu.flt"=dword:00000001 "C:\Program Files\Creative\MediaSource5\FmtQuryu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\Karaokeu.flt"=dword:00000001 "C:\Program Files\Creative\MediaSource5\MFInfou.dll"=dword:00000004 "C:\Program Files\Creative\MediaSource5\NmdPlayu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\NoisRdcu.flt"=dword:00000001 "C:\Program Files\Creative\MediaSource5\Playbaku.scm"=dword:00000001 "C:\Program Files\Creative\MediaSource5\PlxCmnu.plu"=dword:00000001 "C:\Program Files\Creative\MediaSource5\PlxCoreu.plu"=dword:00000001 "C:\Program Files\Creative\MediaSource5\PlxGrphu.plu"=dword:00000001 "C:\Program Files\Creative\MediaSource5\PlxLoadu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\RecEnumu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\Recordu.scm"=dword:00000001 "C:\Program Files\Creative\MediaSource5\SVMu.flt"=dword:00000001 "C:\Program Files\Creative\MediaSource5\TimeSclu.flt"=dword:00000001 "C:\Program Files\Creative\MediaSource5\Transcou.scm"=dword:00000001 "C:\Program Files\Creative\MediaSource5\VDJPlayu.dll"=dword:00000001 "C:\Program Files\Creative\Shared Files\MetaBPMu.crl"=dword:00000001 "C:\Program Files\Creative\Shared Files\MetaSVMu.crl"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTDRMRes.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTIniFu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CtrlSrcu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTThemeu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\GDICtrl.sku"=dword:00000001 "C:\Program Files\Creative\MediaSource5\GDICtrl2.sku"=dword:00000001 "C:\Program Files\Creative\MediaSource5\GDICtrl3.sku"=dword:00000001 "C:\Program Files\Creative\MediaSource5\PopUpMu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\RtxCtrl.sku"=dword:00000001 "C:\Program Files\Creative\MediaSource5\ThmResu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\WizCPLu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\WndTrnsU.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTMEMDBu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTWMPEnu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\Help\CMSPDEU.chm"=dword:00000001 "C:\Program Files\Creative\MediaSource5\AVSrcU.dll"=dword:00000002 "C:\Program Files\Creative\MediaSource5\bubble.bff"=dword:00000001 "C:\Program Files\Creative\MediaSource5\Muce.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTImpt3U.bff"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTImpt3u.exe"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTImpt3u.crl"=dword:00000001 "C:\Program Files\Creative\MediaSource5\AVConvU.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTCDDBu.nco"=dword:00000001 "C:\Program Files\Creative\MediaSource5\NetCoMgu.nco"=dword:00000001 "C:\WINDOWS\Ctregrun.exe"=dword:00000001 "C:\Program Files\Creative\Creative ZEN Vision M Series\ZEN Vision M Series Media Explorer\AVSrcU.dll"=dword:00000001 "C:\Program Files\Creative\Creative ZEN Vision M Series\ZEN Vision M Series Media Explorer\CTIntrfu.dll"=dword:00000001 "C:\Program Files\Creative\Creative ZEN Vision M Series\ZEN Vision M Series Media Explorer\CTRegSvu.exe"=dword:00000001 "C:\Program Files\Creative\Creative ZEN Vision M Series\ZEN Vision M Series Media Explorer\HookWndU.dll"=dword:00000001 "C:\Program Files\Creative\Creative ZEN Vision M Series\ZEN Vision M Series Media Explorer\MFInfou.dll"=dword:00000001 "C:\Program Files\Creative\Shared Files\MtpAutRc.dll"=dword:00000001 "C:\Program Files\Creative\Shared Files\MtpCtxRc.dll"=dword:00000001 "C:\Program Files\Creative\Shared Files\QueManps.dll"=dword:00000001 "C:\Program Files\Creative\Shared Files\QueManU.exe"=dword:00000001 "C:\Program Files\Creative\Shared Files\StrmPlay.dll"=dword:00000001 "C:\Program Files\Creative\Shared Files\ProgHlpU.dll"=dword:00000001 "C:\Program Files\Creative\Shared Files\CTMtpAut.exe"=dword:00000001 "C:\Program Files\Creative\Shared Files\CtCmeCtx.dll"=dword:00000001 "C:\Program Files\Creative\Shared Files\FileRead.ax"=dword:00000001 "C:\Program Files\Creative\CD Ripping Wizard Unicode 2\CTIntrfu.dll"=dword:00000001 "C:\Program Files\Creative\CD Ripping Wizard Unicode 2\CTXMLPsu.dll"=dword:00000001 "C:\Program Files\Creative\CD Ripping Wizard Unicode 2\CTRegSvu.exe"=dword:00000001 "C:\Program Files\Creative\CD Ripping Wizard Unicode 2\Id3Tagu.mft"=dword:00000001 "C:\Program Files\Creative\CD Ripping Wizard Unicode 2\TagMgru.mft"=dword:00000001 "C:\Program Files\Creative\CD Ripping Wizard Unicode 2\WmaTagu.mft"=dword:00000001 "C:\Program Files\Creative\CD Ripping Wizard Unicode 2\Tag.crl"=dword:00000001 "C:\Program Files\Creative\CD Ripping Wizard Unicode 2\CTCDDBu.nco"=dword:00000001 "C:\Program Files\Creative\CD Ripping Wizard Unicode 2\NetCoMgu.nco"=dword:00000001 "C:\Program Files\Creative\CD Ripping Wizard Unicode 2\CTDBEngu.dll"=dword:00000001 "C:\Program Files\Creative\CD Ripping Wizard Unicode 2\CTLogDBu.dll"=dword:00000001 "C:\Program Files\Creative\CD Ripping Wizard Unicode 2\CTMetaDu.dll"=dword:00000001 "C:\Program Files\Creative\CD Ripping Wizard Unicode 2\CTNJBDBu.dll"=dword:00000001 "C:\Program Files\Creative\Sync Manager Unicode\CTIntrfu.dll"=dword:00000002 "C:\Program Files\Creative\Sync Manager Unicode\CTRegSvu.exe"=dword:00000001 "C:\Program Files\Creative\Sync Manager Unicode\Id3Tagu.mft"=dword:00000001 "C:\Program Files\Creative\Sync Manager Unicode\TagMgru.mft"=dword:00000001 "C:\Program Files\Creative\Sync Manager Unicode\WmaTagu.mft"=dword:00000001 "C:\Program Files\Creative\Sync Manager Unicode\Tag.crl"=dword:00000001 "C:\Program Files\Creative\Sync Manager Unicode\CTDBEngu.dll"=dword:00000001 "C:\Program Files\Creative\Sync Manager Unicode\CTLogDBu.dll"=dword:00000001 "C:\Program Files\Creative\Sync Manager Unicode\CTMetaDu.dll"=dword:00000001 "C:\Program Files\Creative\Sync Manager Unicode\CTNJBDBu.dll"=dword:00000001 "C:\Program Files\Creative\Sync Manager Unicode\CTXMLPsu.dll"=dword:00000001 "C:\Program Files\Creative\Sync Manager Unicode\AVConvU.dll"=dword:00000001 "C:\Program Files\Creative\Video Converter\AVConvU.dll"=dword:00000001 "C:\Program Files\Creative\Creative ZEN Vision M Series\ZEN Vision M Series Media Explorer\Id3Tagu.mft"=dword:00000001 "C:\Program Files\Creative\Creative ZEN Vision M Series\ZEN Vision M Series Media Explorer\TagMgru.mft"=dword:00000001 "C:\Program Files\Creative\Creative ZEN Vision M Series\ZEN Vision M Series Media Explorer\WmaTagu.mft"=dword:00000001 "C:\Program Files\Creative\Creative ZEN Vision M Series\ZEN Vision M Series Media Explorer\Tag.crl"=dword:00000001 "C:\Program Files\Creative\Creative ZEN Vision M Series\ZEN Vision M Series Media Explorer\CTImpt3U.bff"=dword:00000001 "C:\Program Files\Creative\Creative ZEN Vision M Series\ZEN Vision M Series Media Explorer\CTImpt3u.exe"=dword:00000001 "C:\Program Files\Creative\Creative ZEN Vision M Series\ZEN Vision M Series Media Explorer\CTImpt3u.crl"=dword:00000001 "C:\Program Files\Creative\Creative ZEN Vision M Series\ZEN Vision M Series Media Explorer\AVConvU.dll"=dword:00000001 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\UserChosenExecuteHandlers] "H:\\?\IDE#CdRomGIGABYTE_GO-R5232C______________________48S2____#5&35d4fab1&0&0.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}+PlayCDAudioOnArrival"="MSRipCDAudioOnArrival\\xdae8\x6399\x9e4d\x1c5\" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Nero\\x00e60\x00fc0\x00b60\x00fc0\x00ac0\x00a40\x00c90] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\\x2019\1l] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\\x2019\1l\\x2019\1\34 ] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\\x2019\1l\\x2019\1\34 \\x2019\1\x81] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\\x00cd0\x00af0\x00bd0\x00f30] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\\x00cd0\x00af0\x00bd0\x00f30\\x00e10\x00a40\x00d70\x00eb0\x00b90\x00c80\x00fc0\x00ea0\x00fc0] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{FFAD0956-2035-C64A-C01F-CA77DFADE3CA}] "dbfmnhjoamhopbelghmanjbgfacphnoghghmngla"=hex:6b,61,70,6e,66,66,6f,6c,67,65,70,6b,63,61,69,6e,67,61,63,64,6d,.. [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache] "C:\Documents and Settings\user\Desktop\moonshell171_with_dpgtools13\moonshell171_with_dpgtools13\Setup.exe"="Setup" "@C:\WINDOWS\system32\SHELL32.dll,-22915"="Contains the files and folders that you have deleted." "@C:\WINDOWS\system32\SHELL32.dll,-8503"="S&earch…" "@C:\WINDOWS\system32\mycomput.dll,-400"="Mana&ge" "@shell32.dll,-31232"="System Tasks" "@shell32.dll,-31294"="View system information" "@shell32.dll,-31327"="Add or remove programs" "@shell32.dll,-31312"="Change a setting" "@shell32.dll,-31272"="Other Places" "@C:\WINDOWS\system32\SHELL32.dll,-9217"="My Network Places" "@C:\WINDOWS\system32\SHELL32.dll,-9227"="My Documents" "@shell32.dll,-21785"="Shared Documents" "@shell32.dll,-31274"="Details" "@C:\WINDOWS\system32\SHELL32.dll,-9216"="My Computer" "@shell32.dll,-31291"="These tasks apply to your computer or the selected hardware device." "@C:\WINDOWS\system32\SHELL32.dll,-22913"="Shows the disk drives and hardware connected to this computer." "@shell32.dll,-31382"="Eject this disk" "@shell32.dll,-8504"="Auto&Play" "@shell32.dll,-31233"="File and Folder Tasks" "@shell32.dll,-31236"="Make a new folder" "@shell32.dll,-31260"="Publish this folder to the Web" "@shell32.dll,-31374"="Share this folder" "@shell32.dll,-31254"="Rename this folder" "@shell32.dll,-31256"="Move this folder" "@shell32.dll,-31258"="Copy this folder" "@shell32.dll,-31380"="E-mail this folder's files" "@shell32.dll,-31262"="Delete this folder" "@shell32.dll,-31242"="Rename this file" "@shell32.dll,-31244"="Move this file" "@shell32.dll,-31246"="Copy this file" "@shell32.dll,-31248"="Publish this file to the Web" "@shell32.dll,-31370"="E-mail this file" "@shell32.dll,-31252"="Delete this file" "@shell32.dll,-31264"="Move the selected items" "@shell32.dll,-31266"="Copy the selected items" "@shell32.dll,-31268"="Publish the selected items to the Web" "@shell32.dll,-31362"="E-mail the selected items" "@shell32.dll,-31270"="Delete the selected items" "@explorer.exe,-7024"="Internet" "@explorer.exe,-7025"="E-mail" "@C:\Program Files\NetMeeting\conf.exe,-12345"="H.323 Internet Telephony" "@C:\WINDOWS\system32\accwiz.exe,-16"="Accessibility Wizard settings" "@C:\WINDOWS\system32\SHELL32.dll,-22978"="Briefcase" "@C:\WINDOWS\System32\ntbackup.exe,-40"="Windows Backup File" "@C:\WINDOWS\System32\pdh.dll,-10023"="Performance Monitor File" "@C:\WINDOWS\System32\cryptext.dll,-6145"="Security Catalog" "@C:\WINDOWS\System32\cdfview.dll,-4610"="Channel File" "@C:\WINDOWS\System32\cryptext.dll,-6108"="Security Certificate" "@C:\Program Files\NetMeeting\conf.exe,-12346"="SpeedDial" "@C:\WINDOWS\System32\cryptext.dll,-6110"="Certificate Revocation List" "@C:\WINDOWS\System32\shimgvw.dll,-304"="Bitmap Image" "@C:\WINDOWS\system32\notepad.exe,-469"="Text Document" "@C:\WINDOWS\system32\netshell.dll,-1300"="Dialup Networking File" "@C:\WINDOWS\inf\unregmp2.exe,-9927"="Microsoft Recorded TV Show" "@C:\WINDOWS\System32\shimgvw.dll,-301"="EMF Image" "@C:\WINDOWS\System32\shimgvw.dll,-302"="GIF Image" "@C:\Program Files\NetMeeting\conf.exe,-12347"="Intel IPhone Compatible" "@C:\WINDOWS\System32\setupapi.dll,-2000"="Setup Information" "@C:\Program Files\Internet Explorer\Connection Wizard\icwres.dll,-20003"="Internet Communication Settings" "@C:\WINDOWS\System32\shimgvw.dll,-303"="JPEG Image" "@C:\WINDOWS\System32\wshext.dll,-4804"="JScript Script File" "@C:\WINDOWS\System32\wshext.dll,-4805"="JScript Encoded Script File" "@C:\WINDOWS\inf\unregmp2.exe,-10003"="Movie file (mpeg)" "@C:\WINDOWS\system32\mmcbase.dll,-130"="Microsoft Common Console Document" "@C:\WINDOWS\System32\msi.dll,-34"="Windows Installer Package" "@C:\WINDOWS\System32\msi.dll,-35"="Windows Installer Patch" "@C:\WINDOWS\System32\RCBdyctl.dll,-150"="Microsoft Remote Assistance Incident" "@C:\Program Files\Movie Maker\1033\wmm2res.dll,-63097"="Windows Movie Maker Project" "@C:\WINDOWS\PCHealth\HelpCtr\Binaries\msinfo.dll,-391"="MSInfo Document" "@C:\Program Files\NetMeeting\nmwb.dll,-1234"="Microsoft NetMeeting T126 Compatible Whiteboard Document" "@C:\WINDOWS\System32\cryptext.dll,-6111"="PKCS #7 Certificates" "@C:\WINDOWS\System32\cryptext.dll,-6113"="PKCS #7 Signature" "@C:\WINDOWS\System32\shimgvw.dll,-305"="PNG Image" "@C:\WINDOWS\System32\scrobj.dll,-8192"="Windows Script Component" "@C:\WINDOWS\system32\shscrap.dll,-258"="Scrap object" "@C:\WINDOWS\System32\cryptext.dll,-6112"="Microsoft Serialized Certificate Store" "@C:\WINDOWS\System32\cryptext.dll,-6109"="Certificate Trust List" "@C:\WINDOWS\System32\wshext.dll,-4803"="VBScript Encoded Script File" "@C:\WINDOWS\System32\wshext.dll,-4802"="VBScript Script File" "@C:\WINDOWS\inf\unregmp2.exe,-9909"="Windows Media Audio/Video file" "@C:\WINDOWS\inf\unregmp2.exe,-9920"="Windows Media Player Download Package" "@C:\WINDOWS\System32\shimgvw.dll,-307"="WMF Image" "@C:\WINDOWS\inf\unregmp2.exe,-9915"="Windows Media Player Skin File" "@C:\WINDOWS\inf\unregmp2.exe,-9910"="Windows Media Audio/Video playlist" "@C:\WINDOWS\inf\unregmp2.exe,-9916"="Windows Media Player Skin Package" "@C:\WINDOWS\inf\unregmp2.exe,-9923"="Windows Media playlist" "@"C:\Program Files\Windows NT\Accessories\WORDPAD.EXE",-208"="Write Document" "@C:\WINDOWS\System32\wshext.dll,-4801"="Windows Script File" "@C:\WINDOWS\System32\wshext.dll,-4800"="Windows Script Host Settings File" "@C:\WINDOWS\System32\msxml3r.dll,-1"="XML Document" "@C:\WINDOWS\System32\msxml3r.dll,-2"="XSL Stylesheet" "@shell32.dll,-31275"="This section displays the size, file type, and other information about a selected item." "C:\Program Files\Winamp\Winamp.exe"="Winamp" "C:\Program Files\Real\RealPlayer\RealPlay.exe"="RealPlayer" "C:\Program Files\Internet Explorer\iexplore.exe"="Internet Explorer" "C:\Program Files\Windows Media Player\wmplayer.exe"="Windows Media Player" "C:\Program Files\Movie Maker\moviemk.exe"="Windows Movie Maker" "C:\Program Files\VideoLAN\VLC\vlc.exe"="VLC media player" "@shell32.dll,-31273"="These links open other folders and take you quickly to useful places." "@shell32.dll,-31234"="These tasks apply to the files and folders you select." "C:\Documents and Settings\user\Desktop\moonshell11\moonshell11\Setup.exe"="Setup" "C:\WINDOWS\Explorer.EXE"="Windows Explorer" "@shell32.dll,-31250"="Print this file" "C:\WINDOWS\system32\NOTEPAD.EXE"="Notepad" "C:\Program Files\Windows NT\Accessories\WORDPAD.EXE"="WordPad" "C:\Program Files\UltraISO\UltraISO.exe"="UltraISO" "@shell32.dll,-31295"="Shows information about your computer, such as the processor speed and the amount of installed memory." "@shell32.dll,-31328"="Provides the steps necessary to add a new program, or to change or remove an existing program." "@shell32.dll,-31361"="Provides options for you to customize the appearance and functionality of your computer." "@C:\WINDOWS\system32\SHELL32.dll,-22912"="Shows shortcuts to Web sites, network computers, and FTP sites." "@C:\WINDOWS\system32\SHELL32.dll,-22914"="Contains letters, reports, and other documents and files." "@shell32.dll,-21779"="My Pictures" "@shell32.dll,-21791"="My Videos" "C:\Program Files\WinRAR\WinRAR.exe"="WinRAR archiver" "C:\Program Files\Mozilla Firefox\firefox.exe"="Firefox" "@C:\WINDOWS\system32\SHELL32.dll,-8964"="Recycle Bin" "@shdoclc.dll,-880"="Internet Explorer" "@explorer.exe,-7023"="&Run…" "@explorer.exe,-7020"="&Search" "@explorer.exe,-7021"="&Help and Support" "@C:\WINDOWS\system32\SHELL32.dll,-9319"="Printers and Faxes" "@xpsp1res.dll,-11001"="Internet Explorer" "@C:\WINDOWS\system32\xpsp1res.dll,-10077"="Set Program Access and Defaults" "@C:\WINDOWS\system32\rcbdyctl.dll,-152"="Remote Assistance" "@xpsp1res.dll,-11004"="Outlook Express" "@C:\WINDOWS\inf\unregmp2.exe,-4"="Windows Media Player" "@shell32.dll,-21761"="Accessories" "@shell32.dll,-22075"="Windows Catalog" "@shell32.dll,-21773"="Games" "@shell32.dll,-21787"="Startup" "@Shell32.dll,-12689"="Contains music and other audio files." "@shell32.dll,-31276"="Music Tasks" "@shell32.dll,-31278"="Play all" "@shell32.dll,-31281"="Shop for music online" "@shell32.dll,-28995"="Shared Music" "@shell32.dll,-31279"="Play selection" "@shell32.dll,-31372"="Copy to audio CD" "@shell32.dll,-31277"="These tasks apply to the music files and folders you select." "@shell32.dll,-31282"="Connects you to the Windows Media Web site where you can find music to download and buy." "@shell32.dll,-31280"="Plays all or the selected music files in this folder." "C:\Documents and Settings\user\Desktop\moonshell171_with_dpgtools13\moonshell171_with_dpgtools13\CreateThumbnail.exe"="CreateThumbnail" "@shell32.dll,-12691"="My Recent Documents" "@shell32.dll,-31283"="Picture Tasks" "@shell32.dll,-31287"="View as a slide show" "@shell32.dll,-31313"="Order prints online" "@shell32.dll,-31391"="Print pictures" "@shell32.dll,-31379"="Copy all items to CD" "@C:\WINDOWS\system32\SHELL32.dll,-12695"="Contains files and folders shared between users of this computer." "C:\WINDOWS\System32\cmd.exe"="Windows Command Processor" "C:\Program Files\YoungMX\YoungMX.exe"="YoungMX Media Player" "@shell32.dll,-31390"="Print this picture" "@shell32.dll,-31289"="Set as desktop background" "@shell32.dll,-31352"="Copy to CD" "@shell32.dll,-31290"="Uses the selected picture, pattern, or HTML document as the background for your computer screen." "@shell32.dll,-31316"="Starts the Photo Printing Wizard, which helps you format and print your digital pictures." "@shell32.dll,-31314"="Starts the Online Print Ordering Wizard, which helps you order prints of your digital pictures." "@shell32.dll,-31288"="Arranges all the pictures in this folder into a slide show." "@shell32.dll,-31284"="These tasks apply to the picture files and folders you select." "@shell32.dll,-31243"="Gives this file or folder a new label that you type for it." "C:\WINDOWS\System32\fontview.exe"="Windows Font Viewer" "@C:\Program Files\Internet Explorer\iexplore.exe,-702"="Internet Explorer" "@xpsp1res.dll,-11003"="Launch Internet Explorer Browser" "@C:\WINDOWS\system32\netshell.dll,-1200"="Network Connections" "@shell32.dll,-22017"="Address Book" "@shell32.dll,-22022"="Command Prompt" "@shell32.dll,-22051"="Notepad" "@C:\WINDOWS\system32\tourstart.exe,-1"="Tour Windows XP" "@shell32.dll,-22041"="Magnifier" "@shell32.dll,-22048"="Narrator" "@shell32.dll,-22052"="On-Screen Keyboard" "@shell32.dll,-22065"="Utility Manager" "@shell32.dll,-22019"="Calculator" "@shell32.dll,-22054"="Paint" "@shell32.dll,-22069"="WordPad" "@shell32.dll,-22016"="Accessibility Wizard" "@shell32.dll,-22031"="HyperTerminal" "@C:\WINDOWS\System32\mstsc.exe,-4000"="Remote Desktop Connection" "@shell32.dll,-22061"="Sound Recorder" "@shell32.dll,-22018"="Backup" "@shell32.dll,-22021"="Character Map" "@shell32.dll,-22026"="Disk Cleanup" "@shell32.dll,-22027"="Disk Defragmenter" "@C:\WINDOWS\system32\usmt\migwiz.exe,-202"="Files and Settings Transfer Wizard" "@shell32.dll,-22063"="System Information" "@C:\WINDOWS\system32\restore\rstrui.exe,-2048"="System Restore" "@C:\WINDOWS\System32\comres.dll,-661"="Component Services" "@shell32.dll,-22023"="Computer Management" "@shell32.dll,-22025"="Data Sources (ODBC)" "@shell32.dll,-22029"="Event Viewer" "@shell32.dll,-22040"="Local Security Policy" "@shell32.dll,-22055"="Performance" "@shell32.dll,-22059"="Services" "@shell32.dll,-22030"="FreeCell" "@C:\WINDOWS\system32\mshearts.exe,-413"="Hearts" "@C:\PROGRA~1\MSNGAM~1\Windows\bckgres.dll,-1212"="Internet Backgammon" "@C:\PROGRA~1\MSNGAM~1\Windows\chkrres.dll,-1212"="Internet Checkers" "@C:\PROGRA~1\MSNGAM~1\Windows\hrtzres.dll,-1212"="Internet Hearts" "@C:\PROGRA~1\MSNGAM~1\Windows\rvseres.dll,-1212"="Internet Reversi" "@C:\PROGRA~1\MSNGAM~1\Windows\shvlres.dll,-1212"="Internet Spades" "@shell32.dll,-22045"="Minesweeper" "@shell32.dll,-22057"="Pinball" "@shell32.dll,-22060"="Solitaire" "@C:\WINDOWS\system32\spider.exe,-56"="Spider Solitaire" "@shell32.dll,-21772"="Entertainment" "@shell32.dll,-21760"="Accessibility" "@shell32.dll,-22062"="Synchronize" "@C:\WINDOWS\system32\compatUI.dll,-115"="Program Compatibility Wizard" "@shell32.dll,-22067"="Windows Explorer" "@shell32.dll,-21762"="Administrative Tools" "@shell32.dll,-21768"="Communications" "@shell32.dll,-21788"="System Tools" "@C:\WINDOWS\system32\netshell.dll,-1010"="New Connection Wizard" "@C:\WINDOWS\system32\hnetwiz.dll,-3085"="Network Setup Wizard" "@shell32.dll,-22066"="Volume Control" "@shell32.dll,-22058"="Scheduled Tasks" "C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe"="AutoDetector" "C:\WINDOWS\Twain_32\ScanWiz5\SDetect.exe"="Microtek Scanner Detector" "C:\Program Files\MSN Messenger\MsnMsgr.Exe"="Messenger" "C:\Program Files\mIRC\mirc.exe"="mIRC" "C:\Program Files\Opera\opera.exe"="Opera Internet Browser" "@Shell32.dll,-12690"="Contains movies and other video files." "@shell32.dll,-31317"="System Tasks" "@shell32.dll,-31321"="Hide the contents of this drive" "@shell32.dll,-31292"="Search for files or folders" "@shell32.dll,-31325"="Hide the contents of this folder" "@shell32.dll,-31318"="These tasks apply to your computer and to this protected folder." "@shell32.dll,-31322"="Hides the files and folders stored on this drive to protect them from being changed or deleted." "@shell32.dll,-31383"="Copies the selected items to the CD-R folder so that you can burn them on a compact disc." "C:\PROGRA~1\COMMON~1\MICROS~1\DW\DW20.EXE"="Microsoft Application Error Reporting" "C:\Documents and Settings\user\My Documents\moonshell16\moonshell16\Setup.exe"="Setup" "C:\Documents and Settings\user\My Documents\DPGPlay_v3.2\dpgplay.exe"="dpgplay" "C:\Documents and Settings\user\My Documents\DPGPlay_v3.2\mplayer.exe"="MPlayer/MEncoder - Movie Player" "C:\Documents and Settings\user\Desktop\reinmoon05\20060804_reinmoon05\Setup.exe"="Setup" "@Shell32.dll,-12688"="Contains digital photos, images, and graphic files." "C:\Program Files\GRETECH\GomPlayer\GOM.exe"="GOM Player" "C:\PROGRA~1\GRETECH\GOMPLA~1\GOM.exe"="GOM Player" "C:\WINDOWS\System32\logon.scr"="Logon Screen Saver" "@shell32.dll,-31396"="Video Tasks" "@shell32.dll,-31397"="These tasks apply to the video files and folders you select." "C:\WINDOWS\notepad.exe"="Notepad" "C:\Program Files\Microsoft Office\Office\WINWORD.EXE"="Microsoft Word for Windows" "C:\WINDOWS\System32\zipfldr.dll"="Compressed (zipped) Folders" "C:\Documents and Settings\user\Desktop\20060908_reinmoon06\20060908_reinmoon06\Setup.exe"="Setup" "E:\ReinMoonMakeIcon.exe"="ReinMoonMakeIcon" "@shell32.dll,-31329"="Recycle Bin Tasks" "@shell32.dll,-31331"="Empty the Recycle Bin" "@shell32.dll,-31333"="Restore all items" "@shell32.dll,-31330"="These tasks apply to the files and folders that you have deleted." "@shell32.dll,-31336"="Moves the selected items to the places they were before they were put in the Recycle Bin." "C:\Documents and Settings\user\Desktop\moonshell10_dpgtools\moonshell10_dpgtools\dpgdec.exe"="dpgdec" "C:\Documents and Settings\user\Desktop\moonshell10_dpgtools\moonshell10_dpgtools\dpgenc.exe"="dpgenc" "@shell32.dll,-12704"="Internet P&roperties" "@shell32.dll,-12705"="&Browse the Internet" "C:\DOCUME~1\user\LOCALS~1\Temp\~nsu.tmp\Au_.exe"="Au_" "C:\Program Files\NJStar Communicator\Njcom32.exe"="NJCOM32 - NJStar Communicator for WIN32" "@shell32.dll,-31375"="Makes the selected folder available to computers on a network so that other people can view it." "@shell32.dll,-31249"="Transfers copies of the selected items to a public Web page so that you can share them with other people." "@shell32.dll,-31237"="Creates a new, empty folder in the folder you have open." "@zipfldr.dll,-10300"="Folder Tasks" "@zipfldr.dll,-10302"="Extract all files" "@shell32.dll,-21765"="Application Data" "@shell32.dll,-12693"="Favorites" "@shell32.dll,-21786"="Start Menu" "c:\progra~1\common~1\instal~1\update~1\isuspm.exe"="InstallShield Update Service Update Manager" "@explorer.exe,-7004"="Opens your Internet browser." "C:\Program Files\Microsoft Office\Office\POWERPNT.EXE"="Microsoft PowerPoint for Windows" "@shell32.dll,-12589"="Files Currently on the CD" "@shell32.dll,-12590"="Files Ready to Be Written to the CD" "C:\Program Files\MindFusion Limited\Xml Viewer\XMLViewer.exe"="XML Viewer" "C:\PROGRA~1\MINDMA~1\MindManP.exe"="The Creative MindManager" "C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe"="Adobe Reader 7.0" "@inetcplc.dll,-4746"="Accessibility" "@inetcplc.dll,-4731"="Always expand ALT text for images" "@inetcplc.dll,-4732"="Move system caret with focus/selection changes" "@inetcplc.dll,-4745"="Browsing" "@inetcplc.dll,-4852"="Use inline AutoComplete" "@inetcplc.dll,-4856"="Enable Personalized Favorites Menu" "@inetcplc.dll,-4866"="Force offscreen compositing even under Terminal Server (requires restart)" "@inetcplc.dll,-4833"="Show friendly HTTP error messages" "@inetcplc.dll,-4734"="Show friendly URLs" "@inetcplc.dll,-4743"="Use Passive FTP (for firewall and DSL modem compatibility)" "@inetcplc.dll,-4737"="Enable folder view for FTP sites" "@inetcplc.dll,-4840"="Show Go button in Address bar" "@inetcplc.dll,-4837"="Automatically check for Internet Explorer updates" "@inetcplc.dll,-4836"="Enable Install On Demand (Internet Explorer)" "@inetcplc.dll,-4835"="Notify when downloads complete" "@inetcplc.dll,-4838"="Close unused folders in History and Favorites (requires restart)" "@inetcplc.dll,-4829"="Enable page transitions" "@inetcplc.dll,-4861"="Reuse windows for launching shortcuts" "@inetcplc.dll,-4736"="Enable offline items to be synchronized on a schedule" "@inetcplc.dll,-4831"="Disable script debugging" "@inetcplc.dll,-4832"="Display a notification about every script error" "@inetcplc.dll,-4735"="Use smooth scrolling" "@inetcplc.dll,-4828"="Underline links" "@inetcplc.dll,-4825"="Always" "@inetcplc.dll,-4827"="Hover" "@inetcplc.dll,-4826"="Never" "@inetcplc.dll,-4874"="Enable third-party browser extensions (requires restart)" "@inetcplc.dll,-4873"="Enable visual styles on buttons and controls in web pages" "@inetcplc.dll,-4839"="Always send URLs as UTF-8 (requires restart)" "@inetcplc.dll,-4875"="Enable Install On Demand (Other)" "@inetcplc.dll,-4747"="Security" "@inetcplc.dll,-4750"="Empty Temporary Internet Files folder when browser is closed" "@inetcplc.dll,-4749"="Do not save encrypted pages to disk" "@inetcplc.dll,-4761"="Check for publisher's certificate revocation" "@inetcplc.dll,-4762"="Check for signatures on downloaded programs" "@inetcplc.dll,-4863"="Enable Integrated Windows Authentication (requires restart)" "@inetcplc.dll,-4756"="Enable Profile Assistant" "@inetcplc.dll,-4757"="Warn if changing between secure and not secure mode" "@inetcplc.dll,-4759"="Warn about invalid site certificates" "@inetcplc.dll,-4752"="Use SSL 2.0" "@inetcplc.dll,-4753"="Use SSL 3.0" "@inetcplc.dll,-4760"="Check for server certificate revocation (requires restart)" "@inetcplc.dll,-4758"="Warn if forms submittal is being redirected" "@inetcplc.dll,-4754"="Use TLS 1.0" "@inetcplc.dll,-4822"="HTTP 1.1 settings" "@inetcplc.dll,-4823"="Use HTTP 1.1" "@inetcplc.dll,-4824"="Use HTTP 1.1 through proxy connections" "@vmhelper.dll,-4000"="Java console enabled (requires restart)" "@vmhelper.dll,-4001"="JIT compiler for virtual machine enabled (requires restart)" "@vmhelper.dll,-4002"="Java logging enabled" "@inetcplc.dll,-4744"="Multimedia" "@inetcplc.dll,-4741"="Play animations in web pages" "@inetcplc.dll,-4871"="Enable Automatic Image Resizing" "@inetcplc.dll,-4876"="Don't display online media content in the media bar" "@inetcplc.dll,-4865"="Enable Image Toolbar (requires restart)" "@inetcplc.dll,-4742"="Show pictures" "@inetcplc.dll,-4843"="Show image download placeholders" "@inetcplc.dll,-4738"="Smart image dithering" "@inetcplc.dll,-4739"="Play sounds in web pages" "@inetcplc.dll,-4740"="Play videos in web pages" "@inetcplc.dll,-4769"="Printing" "@inetcplc.dll,-4770"="Print background colors and images" "@inetcplc.dll,-4771"="Search from the Address bar" "@inetcplc.dll,-4844"="When searching" "@inetcplc.dll,-4845"="Display results, and go to the most likely site" "@inetcplc.dll,-4847"="Just display the results in the main window" "@inetcplc.dll,-4846"="Just go to the most likely site" "@inetcplc.dll,-4848"="Do not search from the Address bar" "@zipfldr.dll,-10148"="Compressed (zipped) Folder" "@sendmail.dll,-21"="Desktop (create shortcut)" "@sendmail.dll,-4"="Mail Recipient" "@C:\Program Files\Movie Maker\1033\wmm2res.dll,-63096"="Capture and edit digital media on your computer and then share your saved movies by e-mail, the Internet, recordable CD, or on a DV video tape." "@(null)ystemRoot\system32\shell32.dll,-22581"="Creates and edits text documents with complex formatting." "@xpsp1res.dll,-11002"="Finds and displays information and Web sites on the Internet." "C:\Documents and Settings\user\Desktop\cyloxmlp\Setup.Exe"="Setup" "C:\WINDOWS\System32\taskmgr.exe"="Windows TaskManager" "C:\Program Files\Microsoft Office\Office\MSACCESS.EXE"="Microsoft Access for Windows" "C:\WINDOWS\System32\msiexec.exe"="Windows\xae installer" "@C:\WINDOWS\System32\msi.dll,-36"="&Install" "@C:\WINDOWS\System32\msi.dll,-37"="Re&pair" "@C:\WINDOWS\System32\msi.dll,-38"="&Uninstall" "C:\Documents and Settings\user\Desktop\dotnetfx.exe"="IExpress Setup" "C:\DOCUME~1\user\LOCALS~1\Temp\IXP000.TMP\Install.exe"="External Installer" "C:\Program Files\XML Notepad 2007\XmlNotepad.exe"="XML Notepad 2007" "C:\Program Files\EA SPORTS\TOTAL CLUB MANAGER 2005\TCM2005.EXE"="TCM2005" "C:\Program Files\Ulead Systems\Ulead PhotoImpact 10 TBYB\Iedit.exe"="PhotoImpact" "C:\WINDOWS\system32\mspaint.exe"="Paint" "C:\Program Files\Ulead Systems\Ulead PhotoImpact 10\Iedit.exe"="PhotoImpact" "C:\WINDOWS\System32\shimgvw.dll"="Windows Picture and Fax Viewer" "@shell32.dll,-31353"="CD Writing Tasks" "@shell32.dll,-31355"="Write these files to CD" "@C:\WINDOWS\system32\SHELL32.dll,-32517"="Taskbar and Start Menu" "@C:\WINDOWS\System32\Audiodev.dll,-510"="Portable Media Devices" "@C:\WINDOWS\system32\SHELL32.dll,-22985"="Folder Options" "@C:\WINDOWS\system32\SHELL32.dll,-22981"="Fonts" "@C:\WINDOWS\system32\SHELL32.dll,-22982"="Administrative Tools" "@C:\WINDOWS\System32\mstask.dll,-3408"="Scheduled Tasks" "@C:\WINDOWS\system32\wiashext.dll,-331"="Scanners and Cameras" "@C:\WINDOWS\System32\Audiodev.dll,-51"="View the portable media devices connected to your computer." "@mmsys.cpl,-5856"="Windows" "@mmsys.cpl,-5824"="Default Beep" "@mmsys.cpl,-5825"="Program error" "@mmsys.cpl,-5826"="Close program" "@mmsys.cpl,-5827"="Critical Battery Alarm" "@mmsys.cpl,-5828"="Device Connect" "@mmsys.cpl,-5829"="Device Disconnect" "@mmsys.cpl,-5830"="Device Failed to Connect" "@mmsys.cpl,-5832"="Low Battery Alarm" "@mmsys.cpl,-5837"="New Mail Notification" "@mmsys.cpl,-5833"="Maximize" "@mmsys.cpl,-5834"="Menu command" "@mmsys.cpl,-5835"="Menu popup" "@mmsys.cpl,-5836"="Minimize" "@mmsys.cpl,-5839"="Open program" "@mmsys.cpl,-5840"="Print Complete" "@mmsys.cpl,-5841"="Restore Down" "@mmsys.cpl,-5842"="Restore Up" "@mmsys.cpl,-5843"="Asterisk" "@mmsys.cpl,-5845"="Exclamation" "@mmsys.cpl,-5846"="Exit Windows" "@mmsys.cpl,-5847"="Critical Stop" "@mmsys.cpl,-5848"="System Notification" "@mmsys.cpl,-5849"="Question" "@mmsys.cpl,-5850"="Start Windows" "@mmsys.cpl,-5852"="Windows Logoff" "@mmsys.cpl,-5853"="Windows Logon" "@mmsys.cpl,-5854"="Windows Explorer" "@mmsys.cpl,-5831"="Empty Recycle Bin" "@mmsys.cpl,-5838"="Start Navigation" "C:\WINDOWS\System32\SNDVOL32.EXE"="Volume Control" "C:\Program Files\mIRC\download\chasseur.exe"="Flash Player 5.0 r30" "C:\PROGRA~1\MOZILL~1\FIREFOX.EXE"="Firefox" "@shimgvw.dll,-550"="Pre&view" "C:\Documents and Settings\user\Desktop\SCIONS_OF_FATE_V5_0126_2007.exe"="SCIONS_OF_FATE_V5_0126_2007" "C:\PROGRA~1\Ahead\nero\nero.exe"="Nero Burning ROM" "C:\Program Files\BitComet\BitComet.exe"="BitComet - a BitTorrent Client" "@shell32.dll,-31335"="Restore the selected items" "@C:\WINDOWS\system32\SHELL32.dll,-31361"="Provides options for you to customize the appearance and functionality of your computer." "C:\Program Files\mIRC\download\Warcraft_III_-_The_Frozen_Throne\Warcraft III - The Frozen Throne [Disk 1].iso\install.exe"="Warcraft III Installer" "C:\Program Files\Warcraft III\BNUpdate.exe"="BNUpdate" "C:\Program Files\mIRC\download\Warcraft_III_-_The_Frozen_Throne\Warcraft III - The Frozen Throne [Disk2]\install.exe"="Frozen Throne Installer" "C:\Program Files\Warcraft III\Warcraft III.exe"="Warcraft III" "C:\Program Files\Warcraft III\Frozen Throne.exe"="Frozen Throne" "C:\Program Files\Common Files\Microsoft Shared\MSInfo\MSInfo32.exe"="System Information" "C:\WINDOWS\pchealth\helpctr\binaries\helpctr.exe"="Microsoft Help and Support Center" "@shell32.dll,-31334"="Restore this item" "@shell32.dll,-31332"="Permanently removes all items in the Recycle Bin and frees up disk space." "@shell32.dll,-31326"="Hides the items stored in this folder to protect them from being changed or deleted." "C:\Documents and Settings\user\Desktop\zion-3-setup.exe"="zion-3-setup" "@C:\Program Files\Messenger\msgslang.dll,-61144"="Windows Messenger" "@wmploc.dll,-1800"="Play" "@wmploc.dll,-6502"="Windows Media Player" "@(null)ystemRoot\system32\SHELL32.dll,-17154"="Open folder to view files" "@(null)ystemRoot\system32\SHELL32.dll,-17155"="Windows Explorer" "@(null)ystemRoot\system32\SHELL32.dll,-17168"="Take no action" "C:\Program Files\Warcraft III\Frozen_Throne.exe"="Frozen Throne" "C:\Program Files\Ulead Systems\Ulead PhotoImpact 10\anygif\ga_main.exe"="Ulead GIF Animator" "@netshell.dll,-1501"="Network Tasks" "@netshell.dll,-1585"="Create a new connection" "@netshell.dll,-1520"="Set up a home or small office network" "@netshell.dll,-1503"="See Also" "@netshell.dll,-1525"="Network Troubleshooter" "@C:\WINDOWS\system32\netshell.dll,-1201"="Connects to other computers, networks, and the Internet." "C:\Documents and Settings\user\Local Settings\Application Data\Mozilla\Firefox\Mozilla Firefox\updates\updater.exe"="Software Updater" "@shell32.dll,-31354"="These tasks apply to the files already on or about to be written to a CD." "@shell32.dll,-31253"="Moves the selected items to the Recycle Bin. If you want to recover them later, go to the Recycle Bin." "@shell32.dll,-31371"="Sends an e-mail message with copies of the selected files, or the files within a selected folder." "@shell32.dll,-31356"="Copies and writes the files you select onto a recordable CD." "C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\G5FDELY8\feedingfrenzy_ridecpa1_stub[1].exe"="RealArcade Download Manager" "C:\DOCUME~1\user\LOCALS~1\Temp\__ArcadeDownloadFoler__feedingfrenzy_EN_1apcedir\RealOneArcadeBundle.exe"="Shell executable of Setup program" "C:\DOCUME~1\user\LOCALS~1\Temp\~rnsetup\GoogleInstApp.exe"="GoogleInst Application" "C:\Program Files\Real\RealArcade\RNArcade.exe"="RealArcade" "C:\WINDOWS\regedit.exe"="Registry Editor" "C:\Documents and Settings\user\My Documents\Koon Long\paradise_heights_2\paradise2\RAKUEN2.EXE"="RAKUEN2" "C:\Documents and Settings\user\My Documents\Koon Long\true_love\truelove\T_LOVE95.EXE"=" " "C:\Documents and Settings\user\My Documents\Koon Long\paradiseheights1\Rakuen.exe"="Rakuen" "C:\Documents and Settings\user\My Documents\Koon Long\paradiseheights1\MOTV95_T.EXE"="ParadiseHeights Setup" "C:\WINDOWS\System32\winhlp32.exe"="Windows Winhlp32 Stub" "C:\WINDOWS\winhlp32.exe"="Microsoft\xae Help" "C:\paradise_heights1\paradiseheights1\MOTV95_T.EXE"="ParadiseHeights Setup" "C:\paradise_heights1\MOTV95_T.EXE"="ParadiseHeights Setup" "C:\paradise_heights1\RAKUEN.EXE"="RAKUEN" "C:\Program Files\FOSTER\ParadiseHeights\RAKUEN.EXE"="RAKUEN" "C:\Program Files\Unreal3.2\unins000.exe"="Setup/Uninstall" "C:\Program Files\Warcraft III\War3.exe"="Warcraft III" "C:\Program Files\MP3 Player Utilities 4.00\AMVPlayer\amvplayer.exe"="looksingle Microsoft \x57fa\x7840\x7c7b\x5e94\x7528\x7a0b\x5e8f" "C:\Program Files\QuickPar\QuickPar.exe"="QuickPar" "C:\PROGRA~1\QUICKT~1\QuickTimePlayer.exe"="QuickTime Player" "C:\Program Files\Course Technology\SAM 2003\Sam11.exe"="SAM xp Shell" "C:\WINDOWS\system32\sdbinst.exe"="AppFix & AppHelp Installer" "C:\Program Files\Warcraft III\World Editor.exe"="World Editor" "D:\vcd_play.exe"="VideoDisc Player" "C:\Program Files\Ahead\Nero StartSmart\NeroStartSmart.exe"="Nero StartSmart" "C:\Program Files\Ahead\nero\nero.exe"="Nero Burning ROM" "@(null)ystemRoot\system32\SHELL32.dll,-17169"="Open writable CD folder" "@(null)ystemRoot\system32\SHELL32.dll,-17170"="Windows Explorer" "@wmploc.dll,-6505"="Burn a CD" "C:\Program Files\Sony Corporation\Image Transfer\SONYCOPY.EXE"="Image Transfer" "C:\Program Files\PIXELA\ImageMixer\ImxInput.exe"="ImageMixer" "@shell32.dll,-31315"="Print the selected pictures" "@shell32.dll,-31378"="Copy all items to audio CD" "@shell32.dll,-31373"="Starts the Windows Media Player so you can copy music files to a CD recorder." "C:\Program Files\Warcraft III\War2Patch_202.exe"="War2Patch_202" "@themeui.dll,-2037"="{Tahoma, 8 pt}" "@themeui.dll,-2038"="{Tahoma, 8 pt}" "@themeui.dll,-2039"="{Tahoma, 8 pt}" "@themeui.dll,-2040"="{Tahoma, 8 pt}" "@themeui.dll,-2041"="{Tahoma, 8 pt}" "@themeui.dll,-2042"="{Tahoma, 8 pt}" "@themeui.dll,-2017"="Windows XP" "@themeui.dll,-2016"="Windows Classic" "@themeui.dll,-2015"="More themes online…" "@explorer.exe,-7005"="Opens your e-mail program so you can send or read a message." "C:\Program Files\Real\RealArcade\Update\rnuninst.exe"="Uninstaller Shell executable" "C:\Documents and Settings\user\Desktop\MapleSEA_MSSetup070309a.exe"="Setup.exe" "@C:\WINDOWS\system32\SHELL32.dll,-12696"="Shows installed printers and fax printers and helps you add new ones." "C:\DOCUME~1\user\LOCALS~1\Temp\set39.tmp"="Setup.exe" "C:\Program Files\Messenger\msmsgs.exe"="Messenger" "@(null)ystemRoot\system32\shell32.dll,-22563"="Creates and edits text files using basic text formatting." "C:\Program Files\QuickTime\QuickTimePlayer.exe"="QuickTime Player" "C:\WINDOWS\hh.exe"="Microsoft\xae HTML Help Executable" "C:\Program Files\DivX\DivX Player\DivX Player.exe"="DivX Player" "C:\Documents and Settings\user\Desktop\BannedStory Full (1.60).exe"="BannedStory Full (1.60)" "C:\Program Files\BannedStory\characterSimulator.exe"="Macromedia Flash Player 8.0 r22" "@explorer.exe,-7001"="Opens a central location for Help topics, tutorials, troubleshooting, and other support services." "C:\Documents and Settings\user\Desktop\GetLink.exe"="GetLink" "C:\Documents and Settings\user\Desktop\fgen_305.exe"="fgen_305" "C:\Program Files\FlashGet\FlashGet.exe"="FlashGet" "@(null)ystemRoot\inf\unregmp2.exe,-155"="Plays your digital media including music, videos, CDs, DVDs, and Internet Radio." "@shell32.dll,-31293"="The Search Companion helps you find files, folders, printers, and people." "C:\PROGRA~1\FlashGet\flashget.exe"="FlashGet" "@(null)ystemRoot\system32\SHELL32.dll,-17158"="Print the pictures" "@(null)ystemRoot\system32\SHELL32.dll,-17159"="Photo Printing Wizard" "@(null)ystemRoot\system32\SHELL32.dll,-17156"="View a slideshow of the images" "@(null)ystemRoot\system32\SHELL32.dll,-17157"="Windows Picture and Fax Viewer" "@(null)ystemroot\System32\wiaacmgr.exe,-276"="Copy pictures to a folder on my computer" "@(null)ystemroot\System32\wiaacmgr.exe,-101"="Microsoft Scanner and Camera Wizard" "@shell32.dll,-31247"="Copies the selected items to a place you choose." "@shell32.dll,-31245"="Moves the selected items to a place you choose." "@explorer.exe,-7000"="Opens a window where you can pick search options and work with search results." "C:\DOCUME~1\user\LOCALS~1\Temp\Set24.tmp"="InstallShield ® Setup Launcher" "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe"="External Installer" "C:\DOCUME~1\user\LOCALS~1\Temp\EAUninstall.exe"="Uninstall" "C:\WINDOWS\system32\calc.exe"="Windows Calculator" "@Shell32.dll,-12692"="Shows recently opened files and folders." "C:\Documents and Settings\user\Desktop\U_SFInstaller.exe"="Setup.exe" "C:\Documents and Settings\user\Desktop\U_SFInstaller(2).exe"="Setup.exe" "@shdoclc.dll,-867"="&Tip of the Day" "@shdoclc.dll,-868"="Shows the Tip of the Day." "C:\DOCUME~1\user\LOCALS~1\Temp\IXP000.TMP\ie6wzd.exe"="Internet Explorer Setup Progman" "C:\Documents and Settings\user\Desktop\flashget182en.exe"="flashget182en" "C:\DOCUME~1\user\LOCALS~1\Temp\_isE4.exe"="Setup.exe" "@C:\WINDOWS\ime\imkr6_1\imekrcic.dll,-22"="Korean Input System (IME 2002)" "@C:\WINDOWS\ime\sptip.dll,-600"="Speech Recognition" "@PINTLGNT.IME,-61697"="Chinese (Simplified) - Microsoft Pinyin IME 3.0" "C:\Downloads\MS_MY_Client_v07041702.exe"="MS_MY_Client_v07041702" "@C:\WINDOWS\system32\ulib.dll,-1000"="Recovered File Fragments" "C:\Downloads\fullpaktrickster\FullPakTrickster.exe"="FullPakTrickster" "C:\Program Files\Trickster Online\splash.dmy"="Launcher MFC \xc751\xc6a9 \xd504\xb85c\xadf8\xb7a8" "@inetcplc.dll,-4774"="ActiveX controls and plug-ins" "@inetcplc.dll,-4775"="Run ActiveX controls and plug-ins" "@inetcplc.dll,-4803"="Enable" "@inetcplc.dll,-4806"="Administrator approved" "@inetcplc.dll,-4805"="Disable" "@inetcplc.dll,-4804"="Prompt" "@inetcplc.dll,-4776"="Download signed ActiveX controls" "@inetcplc.dll,-4783"="Initialize and script ActiveX controls not marked as safe" "@inetcplc.dll,-4784"="Script ActiveX controls marked safe for scripting" "@inetcplc.dll,-4777"="Download unsigned ActiveX controls" "@inetcplc.dll,-4788"="User Authentication" "@inetcplc.dll,-4790"="Logon" "@inetcplc.dll,-4807"="Anonymous logon" "@inetcplc.dll,-4808"="Prompt for user name and password" "@inetcplc.dll,-4810"="Automatic logon only in Intranet zone" "@inetcplc.dll,-4809"="Automatic logon with current username and password" "@mscorier.dll,-1001"=".NET Framework-reliant components" "@mscorier.dll,-1006"="Run components signed with Authenticode" "@mscorier.dll,-1004"="Enable" "@mscorier.dll,-1003"="Disable" "@mscorier.dll,-1005"="Prompt" "@mscorier.dll,-1002"="Run components not signed with Authenticode" "@inetcplc.dll,-4791"="Downloads" "@inetcplc.dll,-4792"="File download" "@inetcplc.dll,-4793"="Font download" "@vmhelper.dll,-4003"="Java permissions" "@vmhelper.dll,-4004"="Custom" "@vmhelper.dll,-4005"="Disable Java" "@vmhelper.dll,-4006"="High safety" "@vmhelper.dll,-4007"="Low safety" "@vmhelper.dll,-4008"="Medium safety" "@inetcplc.dll,-4794"="Miscellaneous" "@inetcplc.dll,-4862"="Don't prompt for client certificate selection when no certificates or only one certificate exists" "@inetcplc.dll,-4785"="Access data sources across domains" "@inetcplc.dll,-4796"="Drag and drop or copy and paste files" "@inetcplc.dll,-4797"="Submit nonencrypted form data" "@inetcplc.dll,-4795"="Installation of desktop items" "@inetcplc.dll,-4798"="Launching programs and files in an IFRAME" "@inetcplc.dll,-4870"="Allow META REFRESH" "@inetcplc.dll,-4872"="Display mixed content" "@inetcplc.dll,-4830"="Software channel permissions" "@inetcplc.dll,-4816"="High safety" "@inetcplc.dll,-4814"="Low safety" "@inetcplc.dll,-4815"="Medium safety" "@inetcplc.dll,-4855"="Navigate sub-frames across different domains" "@inetcplc.dll,-4853"="Userdata persistence" "@inetcplc.dll,-4782"="Scripting" "@inetcplc.dll,-4786"="Active scripting" "@inetcplc.dll,-4787"="Scripting of Java applets" "@inetcplc.dll,-4854"="Allow paste operations via script" "C:\Downloads\SFSetup.exe"="Setup.exe" "c:\program files\common files\installshield\updateservice\isuspm.exe"="InstallShield Update Service Update Manager" "C:\Downloads\MapleSEA_MSSetup070411a.exe"="Setup.exe" "C:\Program Files\WIZET\MapleStory\Setup.exe"="Setup" "C:\DOCUME~1\user\LOCALS~1\Temp\set13.tmp"="Setup.exe" "C:\Downloads\nogg.exe"="nogg" "C:\DOCUME~1\user\LOCALS~1\Temp\set6.tmp"="Setup.exe" "C:\Downloads\rose_139_139_na_evo\rose_139_139_na_evo.exe"="Setup.exe" "C:\Program Files\Triggersoft\Rose Online Evolution\RRose-Patch.exe"="RRose-Patch" "C:\Program Files\Triggersoft\Rose Online Evolution\Rose Reborn Online Launcher.exe"="Rose Reborn Online Launcher" "C:\Program Files\Triggersoft\Rose Online Evolution\Trose.exe"="Client" "C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe"="WinPatrol System Monitor" "C:\Program Files\Triggersoft\Rose Online Evolution\TriggerDetect.exe"="TODO: <\xd30c\xc77c \xc124\xba85>" "C:\Program Files\Triggersoft\Rose Online Evolution\ROSEonline.exe"="R.O.S.E Launcher" "C:\DOCUME~1\user\LOCALS~1\Temp\setA0.tmp"="Setup.exe" "C:\Program Files\Triggersoft\Rose Online Evolution\RoUpdate.exe"="S.H.O Launcher" "C:\Documents and Settings\user\Desktop\idman509b4.exe"="Internet Download Manager installer" "C:\Documents and Settings\user\Local Settings\Temp\IDM_Setup_Temp\IDM1.tmp"="Internet Download Manager installer" "C:\Program Files\Internet Download Manager\IDMan.exe"="Internet Download Manager (IDM)" "C:\Program Files\Internet Download Manager\Uninstall.exe"="Internet Download Manager installer" "C:\DOCUME~1\user\LOCALS~1\Temp\set5.tmp"="Setup.exe" "C:\Program Files\mIRC\download\XilerROFull.exe"="XilerROFull" "C:\Program Files\Gravity\RO\XiLeRO.exe"="Ragnarok Online patch client" "C:\Program Files\Gravity\RO\setup.exe"="Setup MFC \xc751\xc6a9 \xd504\xb85c\xadf8\xb7a8" "C:\Program Files\Gravity\RO\XiLeRO!.exe"="XiLeRO!" "C:\DOCUME~1\user\LOCALS~1\Temp\is-LGBP6.tmp\is-68T6K.tmp"="Setup/Uninstall" "C:\Program Files\Free Audio Pack\FreeConverter\FreeConverter.exe"="Free Audio Converter" "C:\DOCUME~1\user\LOCALS~1\Temp\is-D0NTP.tmp\is-S7EN5.tmp"="Setup/Uninstall" "C:\Program Files\Power MP3 WMA Converter\PowerConverter.exe"="Power MP3 WMA Converter" "C:\Program Files\Pando Networks\Pando\pando.exe"="pando" "C:\Program Files\Free Audio Pack\unins000.exe"="Setup/Uninstall" "C:\DOCUME~1\user\LOCALS~1\Temp\_iu14D2N.tmp"="Setup/Uninstall" "C:\DOCUME~1\user\LOCALS~1\Temp\setup0533.exe"="setup0533" "@(null)ystemRoot\system32\shell32.dll,-22566"="Creates and edits drawings, and displays and edits scanned photos." "@(null)ystemRoot\system32\shell32.dll,-22531"="Performs basic arithmetic tasks with an on-screen calculator." "@netshell.dll,-1570"="Disable this network device" "@netshell.dll,-1550"="Rename this connection" "@netshell.dll,-1575"="Change settings of this connection" "@netcfgx.dll,-50002"="Allows your computer to access resources on a Microsoft network." "@netcfgx.dll,-50003"="Allows other computers to access resources on your computer using a Microsoft network." "@netcfgx.dll,-50015"="Quality of Service Packet Scheduler. This component provides network traffic control, including rate-of-flow and prioritization services." "@netcfgx.dll,-50001"="Transmission Control Protocol/Internet Protocol. The default wide area network protocol that provides communication across diverse interconnected networks." "@wmploc.dll,-6506"="Rip music from CD" "@explorer.exe,-7003"="Opens a program, folder, document, or Web site." "C:\Documents and Settings\user\My Documents\O2Jam_v3.50(Standard)_20051208.exe"="InstallShield ® Setup Launcher" "C:\Program Files\e-Games\O2Jam\O2JamLauncher.exe"="O2Jam Launcher (e-Games)" "C:\Program Files\e-Games\O2Jam\O2Jam.exe"="O2Jam" "C:\Program Files\e-Games\O2Jam\O2JamPatchClient.exe"="O2JamPatcher" "C:\Program Files\e-Games\O2Jam\OTwo.exe"="OTwo" "@shell32.dll,-31235"="Folder Tasks" "@shell32.dll,-31389"="These tasks apply to the items and folders you select." "C:\DOCUME~1\user\LOCALS~1\Temp\is-C5K20.tmp\is-6O8UV.tmp"="Setup/Uninstall" "C:\DOCUME~1\user\LOCALS~1\Temp\_Riva FLV Encoder.exe"="_Riva FLV Encoder" "C:\DOCUME~1\user\LOCALS~1\Temp\_Riva FLV Player.exe"="_Riva FLV Player" "C:\Program Files\Riva\Riva FLV Encoder 2.0\Riva FLV Player.exe"="Riva FLV Player" "C:\DOCUME~1\user\LOCALS~1\Temp\is-H1ONC.tmp\is-K2PB2.tmp"="Setup/Uninstall" "C:\Program Files\ezvideotools.com\EZ WMV TO MPEG Converter\EZ WMV TO MPEG Converter.exe"="EZ WMV TO MPEG Converter" "C:\Program Files\ezvideotools.com\EZ WMV TO MPEG Converter\unins000.exe"="Setup/Uninstall" "C:\DOCUME~1\user\LOCALS~1\Temp\SetB4.tmp"="InstallShield ® Setup Launcher" "C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\iKernel.exe"="InstallShield ® Setup Engine" "C:\DOCUME~1\user\LOCALS~1\Temp\is-K1L3N.tmp\is-23A4V.tmp"="Setup/Uninstall" "C:\My Games\Feeding Frenzy\ffr.exe"="Feeding Frenzy" "C:\Documents and Settings\user\Desktop\O2Jamnxsongpack1_041213.exe"="InstallShield ® Setup Launcher" "C:\Documents and Settings\user\Desktop\O2Jamnxsongpack2_041213.exe"="InstallShield ® Setup Launcher" "C:\Documents and Settings\user\Desktop\O2Jamnxsongpack3_041213.exe"="InstallShield ® Setup Launcher" "@shell32.dll,-28997"="Shared Pictures" "@shell32.dll,-31398"="Plays all or the selected video files in this folder." "@shell32.dll,-28996"="Shared Video" "C:\DOCUME~1\user\LOCALS~1\Temp\xpinstall.exe"="Java™ Platform SE binary" "C:\DOCUME~1\user\LOCALS~1\Temp\is-RB9BE.tmp\is-C8A74.tmp"="Setup/Uninstall" "C:\Program Files\Ultra Flash Video FLV Converter\Ultra Flash Video FLV Converter.exe"="avconverter" "C:\Program Files\Ultra Flash Video FLV Converter\unins000.exe"="Setup/Uninstall" "C:\DOCUME~1\user\LOCALS~1\Temp\is-LLQ33.tmp\is-BOL3K.tmp"="Setup/Uninstall" "c:\Program Files\MMshall\FLV MP4 Video Converter\FLVMP4Converter.exe"="FLV MP4 Video Converter" "C:\DOCUME~1\user\LOCALS~1\Temp\is-696V9.tmp\is-CNRP1.tmp"="Setup/Uninstall" "C:\DOCUME~1\user\LOCALS~1\Temp\is-QI0VL.tmp\is-QPSD0.tmp"="Setup/Uninstall" "C:\Program Files\Moyea\FLV to Video Pro\FLV2Video.exe"="FLV2Video" "C:\Program Files\Moyea\FLV to Video Pro\unins000.exe"="Setup/Uninstall" "C:\Program Files\Moyea\FLV Downloader\unins000.exe"="Setup/Uninstall" "C:\Program Files\InstallShield Installation Information\{D5CD3E08-6B73-471A-93D1-63C7F32118C1}\setup.exe"="InstallShield ® Setup Launcher" "C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe"="InstallDriver Module" "C:\Program Files\BitComet\Downloads\MapleSEA_MaplePatch25to26.exe"="Patcher MFC ?? ????" "C:\Program Files\PIXELA\ImageMixer\ImageMix.exe"="ImageMixer" "@netshell.dll,-1540"="Repair this connection" "@netshell.dll,-1555"="View status of this connection" "C:\DOCUME~1\user\LOCALS~1\Temp\is-HCTDH.tmp\is-VUSL1.tmp"="Setup/Uninstall" "C:\Program Files\a-squared Anti-Malware\a2wizard.exe"="a-squared Security Wizard" "C:\Program Files\a-squared Anti-Malware\a2guard.exe"="a-squared Guard" "C:\Program Files\a-squared Anti-Malware\a2start.exe"="a-squared Security Center" "C:\Program Files\a-squared Anti-Malware\a2scan.exe"="a-squared Malware Scanner" "C:\Downloads\MapleSEA_MSSetup070619a.exe"="Setup.exe" "@shell32.dll,-12710"="&Run" "C:\WINDOWS\System32\dxdiag.exe"="Microsoft DirectX Diagnostic Tool" "C:\Program Files\a-squared Anti-Malware\unins000.exe"="Setup/Uninstall" "@xpsp1res.dll,-11005"="Sends and receives e-mail and newsgroup messages." "C:\DOCUME~1\user\LOCALS~1\Temp\IXP000.TMP\PluginInstaller.exe"="Windows Genuine Advantage validation plug-in installer" "@themeui.dll,-850"="Brick" "@themeui.dll,-851"="Desert" "@themeui.dll,-852"="Eggplant" "@themeui.dll,-853"="High Contrast #1" "@themeui.dll,-856"="High Contrast #2" "@themeui.dll,-859"="High Contrast Black" "@themeui.dll,-862"="High Contrast White" "@themeui.dll,-865"="Lilac" "@themeui.dll,-867"="Maple" "@themeui.dll,-868"="Marine (high color)" "@themeui.dll,-869"="Plum (high color)" "@themeui.dll,-870"="Pumpkin" "@themeui.dll,-872"="Rainy Day" "@themeui.dll,-873"="Red, White, and Blue (VGA)" "@themeui.dll,-874"="Rose" "@themeui.dll,-876"="Slate" "@themeui.dll,-877"="Spruce" "@themeui.dll,-878"="Storm (VGA)" "@themeui.dll,-879"="Teal (VGA)" "@themeui.dll,-871"="Wheat" "@themeui.dll,-880"="Windows Classic" "@themeui.dll,-883"="Windows Standard" "@themeui.dll,-2019"="Normal" "@themeui.dll,-2021"="Extra Large" "@themeui.dll,-2020"="Large" "C:\Program Files\Outlook Express\msimn.exe"="Outlook Express" "C:\Documents and Settings\user\My Documents\My Received Files\Automouse(1)\Automouse(1).exe"="jola MFC \xc751\xc6a9 \xd504\xb85c\xadf8\xb7a8" "C:\Documents and Settings\user\Desktop\HamachiSetup-1.0.1.5-en.exe"="Hamachi Setup" "C:\Program Files\Hamachi\nicmgr.exe"="nicmgr" "@browselc.dll,-13137"="&Address" "@browselc.dll,-13138"="&Links" "@(null)ystemRoot\System32\msutb.dll,-325"="Language bar" "C:\Program Files\Hamachi\hamachi.exe"="Hamachi Client" "C:\DOCUME~1\user\LOCALS~1\Temp\hamachi-update-1.0.2.2.exe"="Hamachi Setup" "@(null)ystemRoot\system32\shell32.dll,-22573"="Records sounds if a microphone and sound card are installed." "C:\WINDOWS\system32\winmine.exe"="Entertainment Pack Minesweeper Game" "@(null)ystemRoot\system32\compatUI.dll,-117"="Starts the Program Compatibility Wizard, which helps you configure older programs to run on Windows XP" "C:\Program Files\NJStar Communicator\minismtp.exe"="NJStar Mini SMTP Server" "C:\Program Files\NJStar Communicator\NJSIME.EXE"="NJStar Chinese Input Method Editor" "C:\DOCUME~1\user\LOCALS~1\Temp\is-Q0E0J.tmp\is-6MFE3.tmp"="Setup/Uninstall" "C:\DOCUME~1\user\LOCALS~1\Temp\set14.tmp"="Setup.exe" "@shell32.dll,-12709"="&Help and Support" "C:\Downloads\Lunia_Installer_200707301704.exe"="Lunia_Installer_200707301704" "C:\DOCUME~1\user\LOCALS~1\Temp\Lunia.exe"="Lunia" "C:\LuniaGSP\LuniaClient.exe"="LuniaClient" "C:\LuniaGSP\reporter.exe"="reporter" "@(null)ystemRoot\system32\mshearts.exe,-414"="Begins the Hearts card game." "C:\Program Files\Microsoft Office\Office\EXCEL.EXE"="Microsoft Excel for Windows" "C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.5\Pex.exe"="Ulead Photo Explorer" "D:\ctrun\demo32.exe"="DemoShield Player" "D:\PDE\SETUP\SETUP.EXE"="Setup.exe" "D:\CMS\SETUP\SETUP.EXE"="Setup.exe" "D:\AUDIBLE\SETUP\SETUP.EXE"="Setup.exe" "D:\Audible\ActiveSetupRSDK.exe"="ActiveSetup Module" "D:\CTSHARED\LAUNCHEX\PIDINST\SETUP.EXE"="Setup.exe" "D:\REGISTER\SETUP.EXE"="Setup.exe" "D:\PDE\MTPrompt\SETUP.EXE"="Setup.exe" "C:\Program Files\Creative\MediaSource5\Startmsu.exe"="StartMS" "C:\Program Files\Creative\Product Registration\English\RegFlash.exe"="Macromedia Flash Player 7.0 r19" "C:\Program Files\Creative\Product Registration\English\InetReg.exe"="Product Registration Program" "C:\Program Files\Creative\DiskManager\ctpdemgr.exe"="Creative Removable Disk Manager" "@C:\WINDOWS\system32\wiashext.dll,-330"="Add, remove, and configure scanners and cameras." "C:\Program Files\Creative\Support\System Information\CTSI.exe"="Creative System Information" "@C:\Program Files\Creative\MediaSource5\CTCMS.crl,-14345"="Creative MediaSource 5 Player" "C:\Documents and Settings\user\Desktop\HijackThis.exe"="HijackThis" "C:\DOCUME~1\user\LOCALS~1\Temp\is-GRI1G.tmp\is-3AQ8C.tmp"="Setup/Uninstall" "C:\Program Files\HaxFix\catchme.exe"="catchme" scanning hidden files … C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{96613235-38DD-7E7B-CB29-8A6D65484E2D}1\13-{96613235-38DD-7E7B-CB29-8A6D65484E2D}-v1-{266986D6-E43A-4AFA-8839-BD5C0F4B8AE9}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{96613235-38DD-7E7B-CB29-8A6D65484E2D}\59\59-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v59-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v59-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1877844 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{96613235-38DD-7E7B-CB29-8A6D65484E2D}\59\59-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v59-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v59-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 132222 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{96613235-38DD-7E7B-CB29-8A6D65484E2D}\59\59-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v59-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v59-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.3 9156 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{96613235-38DD-7E7B-CB29-8A6D65484E2D}\59\59-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v59-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v59-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 208520 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{96613235-38DD-7E7B-CB29-8A6D65484E2D}\60\60-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v60-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v60-Partial.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 95610 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{96613235-38DD-7E7B-CB29-8A6D65484E2D}\60\60-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v60-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v60-Partial.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 6582 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{96613235-38DD-7E7B-CB29-8A6D65484E2D}\60\60-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v60-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v60-Partial.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.3 480 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{96613235-38DD-7E7B-CB29-8A6D65484E2D}\60\60-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v60-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v60-Partial.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 10656 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{96613235-38DD-7E7B-CB29-8A6D65484E2D}\63\63-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v63-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v63-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1878204 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{96613235-38DD-7E7B-CB29-8A6D65484E2D}\63\63-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v63-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v63-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 132258 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{96613235-38DD-7E7B-CB29-8A6D65484E2D}\63\63-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v63-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v63-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.3 9246 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{96613235-38DD-7E7B-CB29-8A6D65484E2D}\63\63-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v63-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v63-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 208552 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{96613235-38DD-7E7B-CB29-8A6D65484E2D}\64\64-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v64-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v64-Partial.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1953534 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{96613235-38DD-7E7B-CB29-8A6D65484E2D}\64\64-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v64-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v64-Partial.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 138126 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{96613235-38DD-7E7B-CB29-8A6D65484E2D}\64\64-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v64-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v64-Partial.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.3 9102 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{96613235-38DD-7E7B-CB29-8A6D65484E2D}\64\64-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v64-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v64-Partial.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 70504 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{96613235-38DD-7E7B-CB29-8A6D65484E2D}\74\74-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v74-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v74-Partial.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 611508 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{96613235-38DD-7E7B-CB29-8A6D65484E2D}\74\74-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v74-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v74-Partial.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 43086 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{96613235-38DD-7E7B-CB29-8A6D65484E2D}\74\74-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v74-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v74-Partial.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.3 3144 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{96613235-38DD-7E7B-CB29-8A6D65484E2D}\74\74-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v74-{69E8F9A2-E97E-4E03-B5E3-F8FD1914A253}-v74-Partial.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 67912 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{518084E3-B156-E9F2-1AFF-8EB3B8A73D53}1\20-{518084E3-B156-E9F2-1AFF-8EB3B8A73D53}-v1-{266986D6-E43A-4AFA-8839-BD5C0F4B8AE9}-v20-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{518084E3-B156-E9F2-1AFF-8EB3B8A73D53}\18\18-{9C509C81-4BF1-495D-A6B8-6401700D5872}-v18-{9C509C81-4BF1-495D-A6B8-6401700D5872}-v18-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 3243342 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{518084E3-B156-E9F2-1AFF-8EB3B8A73D53}\18\18-{9C509C81-4BF1-495D-A6B8-6401700D5872}-v18-{9C509C81-4BF1-495D-A6B8-6401700D5872}-v18-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 226884 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{518084E3-B156-E9F2-1AFF-8EB3B8A73D53}\18\18-{9C509C81-4BF1-495D-A6B8-6401700D5872}-v18-{9C509C81-4BF1-495D-A6B8-6401700D5872}-v18-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.3 15888 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{518084E3-B156-E9F2-1AFF-8EB3B8A73D53}\18\18-{9C509C81-4BF1-495D-A6B8-6401700D5872}-v18-{9C509C81-4BF1-495D-A6B8-6401700D5872}-v18-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 359760 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{85FC51BA-107E-3A7A-6836-2DFF9CDDF2B8}1\12-{85FC51BA-107E-3A7A-6836-2DFF9CDDF2B8}-v1-{266986D6-E43A-4AFA-8839-BD5C0F4B8AE9}-v12-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{85FC51BA-107E-3A7A-6836-2DFF9CDDF2B8}\11\11-{B2A55559-2637-40FD-A431-48B516718AA7}-v11-{B2A55559-2637-40FD-A431-48B516718AA7}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1264 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{85FC51BA-107E-3A7A-6836-2DFF9CDDF2B8}\12\12-{B2A55559-2637-40FD-A431-48B516718AA7}-v12-{B2A55559-2637-40FD-A431-48B516718AA7}-v12-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1168 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{85FC51BA-107E-3A7A-6836-2DFF9CDDF2B8}\13\13-{B2A55559-2637-40FD-A431-48B516718AA7}-v13-{B2A55559-2637-40FD-A431-48B516718AA7}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1160 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{85FC51BA-107E-3A7A-6836-2DFF9CDDF2B8}\14\14-{B2A55559-2637-40FD-A431-48B516718AA7}-v14-{B2A55559-2637-40FD-A431-48B516718AA7}-v14-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1264 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{85FC51BA-107E-3A7A-6836-2DFF9CDDF2B8}\44\544-{CFD25007-4596-4234-A793-862A2420CD0E}-v544-{CFD25007-4596-4234-A793-862A2420CD0E}-v544-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1965234 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{85FC51BA-107E-3A7A-6836-2DFF9CDDF2B8}\44\544-{CFD25007-4596-4234-A793-862A2420CD0E}-v544-{CFD25007-4596-4234-A793-862A2420CD0E}-v544-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 139386 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{85FC51BA-107E-3A7A-6836-2DFF9CDDF2B8}\44\544-{CFD25007-4596-4234-A793-862A2420CD0E}-v544-{CFD25007-4596-4234-A793-862A2420CD0E}-v544-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.3 9984 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{85FC51BA-107E-3A7A-6836-2DFF9CDDF2B8}\44\544-{CFD25007-4596-4234-A793-862A2420CD0E}-v544-{CFD25007-4596-4234-A793-862A2420CD0E}-v544-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 220280 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{67810714-F437-607C-45F1-76C5C57E6490}1\21-{67810714-F437-607C-45F1-76C5C57E6490}-v1-{266986D6-E43A-4AFA-8839-BD5C0F4B8AE9}-v21-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{EBC013D0-8A8D-E2B8-99AF-E379F308C88B}1\10-{EBC013D0-8A8D-E2B8-99AF-E379F308C88B}-v1-{266986D6-E43A-4AFA-8839-BD5C0F4B8AE9}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{EBC013D0-8A8D-E2B8-99AF-E379F308C88B}\11\11-{266986D6-E43A-4AFA-8839-BD5C0F4B8AE9}-v11-{266986D6-E43A-4AFA-8839-BD5C0F4B8AE9}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 689736 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{EBC013D0-8A8D-E2B8-99AF-E379F308C88B}\11\11-{266986D6-E43A-4AFA-8839-BD5C0F4B8AE9}-v11-{266986D6-E43A-4AFA-8839-BD5C0F4B8AE9}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 48000 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{EBC013D0-8A8D-E2B8-99AF-E379F308C88B}\11\11-{266986D6-E43A-4AFA-8839-BD5C0F4B8AE9}-v11-{266986D6-E43A-4AFA-8839-BD5C0F4B8AE9}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.3 3576 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{EBC013D0-8A8D-E2B8-99AF-E379F308C88B}\11\11-{266986D6-E43A-4AFA-8839-BD5C0F4B8AE9}-v11-{266986D6-E43A-4AFA-8839-BD5C0F4B8AE9}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 76584 bytes hidden from API C:\WINDOWS\system32:lzx32.sys 65568 bytes executable hidden from API C:\WINDOWS\system32\protector.exe C:\WINDOWS\system32\ntio256.sys scan completed successfully hidden processes: 0 hidden files: 44 — Analysing Catchme logfile — matching service found: ntio256 Finished!
Sorry for the delay but I had some res2arch to do. I am afraid that I have some bad news for you concerning your computer

You have a "rootkit" infection.

Rootkits overwrite critical system files, so that deleting the files will cause system instability. We have tools which can remove rootkits without destroying the file itself.

HOWEVER, even if the rootkit is removed, there is no guarantee that the computer is no longer compromised.

Your next step, from another computer that is not infected, is to IMMEDIATELY change passwords to online banking websites, sensitive files, or other websites where your sensitive data is held.

Afterwards, you have a choice. You can continue on, as-is, and we will help you clean your machine, or you can reformat your system. The choice is yours. Let me remind you, however, that there is NO guarantee that your computer is compromised. that the computer is no longer compromised.

Awaiting your decision, I will ask you to run the following tool to help us better identify the rootkits that we are dealing with:


Download this tool to your desktop:
http://www.uploads.ejvindh.net/rootchk.exe
Run the program. After a short time a logfile will turn up. Copy the contents of the log into the thread.
Don't run any tools suggested in the log if any. I need to see its contents first.

Trevuren
I understand that and I've decided not to reformat my computer.

********************************* ROOTCHK-(15-08-07)-LOG, by ejvindh
18/08/2007 12:45:32.65

Driver Driver (visible) is present. Run COMBOFIX by sUBs or SDFIX by AndyManchesta.
Driver MZU_RK (visible) is present. Run COMBOFIX by sUBs or SDFIX by AndyManchesta.
Driver ntio256 (visible) is present. Run COMBOFIX by sUBs or SDFIX by AndyManchesta.
Driver pe386 (hidden) is present. Run RUSTBFIX by ejvindh, COMBOFIX by sUBs or SDFIX by AndyManchesta.

********************************* ROOTCHK-LOG-end


catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-18 12:45:33
Windows 5.1.2600 Service Pack 1
scanning hidden processes …

scanning hidden services & system hive …
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ntio256]
"Type"=dword:00000001
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=str(2):"\??\C:\WINDOWS\System32\ntio256.sys"
"DisplayName"="Input and output operations"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\pe386]
"Type"=dword:00000001
"Start"=dword:00000001
"ErrorControl"=dword:00000000
"ImagePath"=str(2):"\??\C:\WINDOWS\System32:lzx32.sys"
"DisplayName"="Win23 lzx files loader"
"Group"="Base"
"ExtParam"=hex:e8,db,98,ac,2a,4e,c1,32,7e,7b,de,6e,46,51,f6,3e
"Checked"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\pe386\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{BA318D17-4033-4A9B-9AEE-C358124E5998}]
"LeaseObtainedTime"=dword:46c678ff
"T1"=dword:46c6797e
"T2"=dword:46c679de
"LeaseTerminatesTime"=dword:46c679fe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{BA318D17-4033-4A9B-9AEE-C358124E5998}\Parameters\Tcpip]
"LeaseObtainedTime"=dword:46c678ff
"T1"=dword:46c6797e
"T2"=dword:46c679de
"LeaseTerminatesTime"=dword:46c679fe
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ntio256]
"Type"=dword:00000001
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=str(2):"\??\C:\WINDOWS\System32\ntio256.sys"
"DisplayName"="Input and output operations"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\pe386]
"Type"=dword:00000001
"Start"=dword:00000001
"ErrorControl"=dword:00000000
"ImagePath"=str(2):"\??\C:\WINDOWS\System32:lzx32.sys"
"DisplayName"="Win23 lzx files loader"
"Group"="Base"
"ExtParam"=hex:e8,db,98,ac,2a,4e,c1,32,7e,7b,de,6e,46,51,f6,3e
"Checked"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\pe386\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,..

scanning hidden registry entries …
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\Documents and Settings\user\Start Menu\Programs\Windows XP Creativity Fun Packs\Windows Movie Maker 2\"=""
"C:\Documents and Settings\user\Application Data\Microsoft\Installer\{3C26E039-BE18-4B5E-A723-45390C451819}\"=""
"C:\Documents and Settings\user\Application Data\Microsoft\Installer\"=""
"C:\Program Files\Sports Interactive\Football Manager 2005\data\"="1"
"C:\Program Files\Sports Interactive\Football Manager 2005\"="1"
"C:\Program Files\Sports Interactive\"="1"
"C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\"="1"
"C:\Program Files\Adobe\Acrobat 7.0\Reader\"="1"
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\VDKHome\ENU\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\VDKHome\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\"=""
"C:\Program Files\Adobe\Acrobat 7.0\ActiveX\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\AcroForm\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\WebSearch\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\AcroForm\PMP\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Multimedia\MPP\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Multimedia\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Help\ENU\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Help\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\Howto\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\OLS\Locale\ENU\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\OLS\Locale\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\OLS\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\Templates\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\Howto\images\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\Updater\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Resource\CMap\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Resource\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Resource\Font\PFM\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Resource\Font\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\Optional\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Annotations\Stamps\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Annotations\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Annotations\Stamps\ENU\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\HowTo\ENU\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\HowTo\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\HowTo\ENU\Images\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\SPPlugins\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Esl\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\Javascripts\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\Legal\Adobe Reader\7.0.0\en_US\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\Legal\Adobe Reader\7.0.0\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\Legal\Adobe Reader\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\Legal\"=""
"C:\Documents and Settings\All Users\Application Data\Adobe\Acrobat\7.0\Replicate\Security\"=""
"C:\Documents and Settings\All Users\Application Data\Adobe\Acrobat\7.0\Replicate\"=""
"C:\Documents and Settings\All Users\Application Data\Adobe\Acrobat\7.0\"=""
"C:\Documents and Settings\All Users\Application Data\Adobe\Acrobat\"=""
"C:\Documents and Settings\All Users\Application Data\Adobe\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\Messages\ENU\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\Messages\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\ImageViewer\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\ImageViewer\en_US\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins3d\"=""
"C:\Program Files\Common Files\Adobe\TypeSpt\Unicode\Mappings\Mac\"=""
"C:\Program Files\Common Files\Adobe\TypeSpt\Unicode\Mappings\"=""
"C:\Program Files\Common Files\Adobe\TypeSpt\Unicode\"=""
"C:\Program Files\Common Files\Adobe\TypeSpt\"=""
"C:\Program Files\Common Files\Adobe\"=""
"C:\Program Files\Common Files\Adobe\TypeSpt\Unicode\Mappings\Adobe\"=""
"C:\Program Files\Common Files\Adobe\TypeSpt\Unicode\Mappings\win\"=""
"C:\Program Files\Common Files\Adobe\TypeSpt\Unicode\ICU\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Resource\Linguistics\LanguageNames\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Resource\Linguistics\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Resource\Linguistics\Providers\Proximity\"=""
"C:\Program Files\Adobe\Acrobat 7.0\Resource\Linguistics\Providers\"=""
"C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A70000000000}\"=""
"C:\WINDOWS\Installer\{ABEB838C-A1A7-4C5D-B7E1-8B4314600429}\"=""
"C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\"="1"
"C:\Program Files\Common Files\InstallShield\Driver\8\"="1"
"C:\Program Files\Common Files\InstallShield\Driver\"="1"
"C:\Program Files\KONAMI\Winning Eleven 7I\dat\"=""
"C:\Program Files\KONAMI\Winning Eleven 7I\"=""
"C:\Program Files\KONAMI\"=""
"C:\Documents and Settings\All Users\Start Menu\Programs\KONAMI\Winning Eleven 7 INTERNATIONAL\"=""
"C:\Documents and Settings\All Users\Start Menu\Programs\KONAMI\"=""
"C:\WINDOWS\Installer\{71493403-7C93-48CC-BF19-C73DB1DB7B17}\"=""
"C:\Program Files\Common Files\InstallShield\Driver\10\Intel 32\"="1"
"C:\Program Files\Common Files\InstallShield\Driver\10\"="1"
"C:\Program Files\GAMEFLIER\TSONLINE\"="1"
"C:\Program Files\GAMEFLIER\"="1"
"C:\Program Files\Common Files\InstallShield\UpdateService\"="1"
"C:\Program Files\Common Files\InstallShield\UpdateService\images\"="1"
"C:\Program Files\GAMEFLIER\TSONLINE\user\"=""
"C:\Program Files\Windows Journal Viewer\"=""
"C:\Program Files\Common Files\Microsoft Shared\Ink\"=""
"C:\Program Files\Movie Maker\Shared\Profiles\"="1"
"C:\Program Files\Movie Maker\Shared\"="1"
"C:\Program Files\Movie Maker\1033\"=""
"C:\WINDOWS\Installer\{49FC50FC-F965-40D9-89B4-CBFF80941033}\"=""
"C:\Program Files\GameShadow\"="1"
"C:\Program Files\Microsoft AntiSpyware\"=""
"C:\Documents and Settings\All Users\Application Data\Apple Computer\iTunes\SC Info\"="1"
"C:\Documents and Settings\All Users\Application Data\Apple Computer\iTunes\"="1"
"C:\Documents and Settings\All Users\Application Data\Apple Computer\"="1"
"C:\Documents and Settings\All Users\Application Data\Microsoft\IdentityCRL\"=""
"C:\Program Files\Sports Interactive\Football Manager 2006\data\"="1"
"C:\Program Files\Sports Interactive\Football Manager 2006\"="1"
"C:\Program Files\Sports Interactive\Football Manager 2006\data\graphics\pictures\"="1"
"C:\Program Files\Sports Interactive\Football Manager 2006\data\graphics\"="1"
"C:\Program Files\Sports Interactive\Football Manager 2006\data\graphics\pictures\players\"="1"
"C:\Program Files\Sports Interactive\Football Manager 2006\data\graphics\pictures\players\eng\"="1"
"C:\Program Files\Sports Interactive\Football Manager 2006\data\graphics\pictures\players\eng\league one\"="1"
"C:\Program Files\Sports Interactive\Football Manager 2006\data\graphics\pictures\players\sco\"="1"
"C:\Program Files\Sports Interactive\Football Manager 2006\data\graphics\pictures\players\sco\spl\"="1"
"C:\Program Files\Sports Interactive\Football Manager 2006\data\languages\"=""
"C:\Documents and Settings\user\Application Data\Jasc Software Inc\Paint Shop Pro 8\Cache\"="1"
"C:\Documents and Settings\user\Application Data\Jasc Software Inc\Paint Shop Pro 8\"="1"
"C:\Documents and Settings\user\Application Data\Jasc Software Inc\"="1"
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\"="1"
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\CMYK Profiles\"="1"
"C:\Documents and Settings\user\My Documents\My PSP8 Files\"="1"
"C:\Documents and Settings\user\My Documents\My PSP8 Files\Scripts-Restricted\"="1"
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\PlugIns\"="1"
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\"="1"
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\"="1"
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\"="1"
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\"="1"
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\"="1"
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\"="1"
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\TCL\"="1"
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\"="1"
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Brushes\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Bump Maps\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Deformation Maps\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Environment Maps\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Gradients\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Masks\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Palettes\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Patterns\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Picture Frames\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Picture Tubes\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Preset Shapes\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Presets\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Print Templates\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Assign a keyboard shortcut - An example\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Assign a keyboard shortcut - An example\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Assign a keyboard shortcut - An example\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Basic scripting\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Basic scripting\CSS\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Basic scripting\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Basic scripting\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a custom toolbar\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a custom toolbar\CSS\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a custom toolbar\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a custom toolbar\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a dialog Preset - An example\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a dialog Preset - An example\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a dialog Preset - An example\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a dialog Preset - An example\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a tool Preset - An example\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a tool Preset - An example\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a tool Preset - An example\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a tool Preset - An example\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Rename multiple files simultaneously\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Rename multiple files simultaneously\CSS\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Rename multiple files simultaneously\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Rename multiple files simultaneously\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Run a script on multiple files\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Run a script on multiple files\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Run a script on multiple files\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Separate a tool from its flyout\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Separate a tool from its flyout\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Separate a tool from its flyout\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Create a new image\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Create a new image\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Create a new image\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Create a new image\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Crop an image\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Crop an image\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Crop an image\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Crop an image\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\E-mail an image\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\E-mail an image\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\E-mail an image\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\E-mail an image\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Open a saved image\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Open a saved image\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Open a saved image\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Open a saved image\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Resize an image\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Resize an image\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Resize an image\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Resize an image\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Rotate a photo\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Rotate a photo\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Rotate a photo\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Rotate a photo\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take a Window screen capture\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take a Window screen capture\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take a Window screen capture\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take a Window screen capture\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take an Area screen capture\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take an Area screen capture\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take an Area screen capture\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take an Area screen capture\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Correct perspective distortion\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Correct perspective distortion\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Correct perspective distortion\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Correct perspective distortion\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Fix a photo\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Fix a photo\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Fix a photo\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Fix a photo\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Remove red-eye\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Remove red-eye\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Remove red-eye\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Remove red-eye\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Straighten a crooked photo\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Straighten a crooked photo\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Straighten a crooked photo\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Straighten a crooked photo\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add a drop shadow and caption\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add a drop shadow and caption\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add a drop shadow and caption\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add a picture frame\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add a picture frame\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add a picture frame\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add a picture frame\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a path - An example\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a path - An example\CSS\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a path - An example\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a path - An example\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a separate layer\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a separate layer\CSS\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a separate layer\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a separate layer\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Create a seamless tiled image\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Create a seamless tiled image\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Create a seamless tiled image\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Create a seamless tiled image\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Convert a photo into a greeting card\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Convert a photo into a greeting card\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Convert a photo into a greeting card\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Convert a photo into a greeting card\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create depth of field\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create depth of field\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create depth of field\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create depth of field\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 1\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 1\CSS\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 1\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 1\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 2\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 2\CSS\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 2\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 2\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Erase an image background\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Erase an image background\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Erase an image background\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Erase an image background\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a photo look old\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a photo look old\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a photo look old\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a photo look old\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a selection greyscale\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a selection greyscale\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a selection greyscale\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a selection greyscale\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Modify a photo via blend modes\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Modify a photo via blend modes\CSS\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Modify a photo via blend modes\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Modify a photo via blend modes\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Upload photos to a PhotoSharing site\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Upload photos to a PhotoSharing site\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Upload photos to a PhotoSharing site\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Upload photos to a PhotoSharing site\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Basic\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Basic\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Basic\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Basic\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Intermediate\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Intermediate\css\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Intermediate\Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Intermediate\Scripts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Sample Images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Scripts-Restricted\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Scripts-Trusted\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Selections\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Styled Lines\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Swatches\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Textures\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Learning Center\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\PostScript Resources\Fonts\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\PostScript Resources\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Commands\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Workspaces\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\PhotoServices\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\DLLs\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\Lib\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\Lib\compiler\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\Lib\distutils\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\Lib\distutils\command\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\Lib\email\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\Lib\encodings\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\Lib\hotshot\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\Lib\lib-old\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\Lib\lib-tk\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\Lib\site-packages\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\Lib\xml\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\Lib\xml\dom\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\Lib\xml\parsers\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\Lib\xml\sax\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\TCL\tcl8.3\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\TCL\tcl8.3\dde1.1\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\TCL\tcl8.3\encoding\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\TCL\tcl8.3\http1.0\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\TCL\tcl8.3\http2.3\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\TCL\tcl8.3\msgcat1.0\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\TCL\tcl8.3\opt0.4\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\TCL\tcl8.3\reg1.0\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\TCL\tcl8.3\tcltest1.0\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\TCL\tk8.3\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\TCL\tk8.3\demos\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\TCL\tk8.3\demos\images\"=""
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Python Libraries\TCL\tk8.3\images\"=""
"C:\Documents and Settings\All Users\Start Menu\Programs\Jasc Software\"=""
"C:\WINDOWS\Installer\{81A34902-9D0B-4920-A25C-4CDC5D14B328}\"=""
"C:\Config.Msi\"=""
"C:\Program Files\MP3 Player Utilities 4.00\"="1"
"C:\Program Files\MP3 Player Utilities 4.00\RDiskUtility\sys\"=""
"C:\Program Files\MP3 Player Utilities 4.00\RDiskUtility\"=""
"C:\Program Files\MP3 Player Utilities 4.00\AMVPlayer\skin\xpstyle\"=""
"C:\Program Files\MP3 Player Utilities 4.00\AMVPlayer\skin\"=""
"C:\Program Files\MP3 Player Utilities 4.00\AMVPlayer\"=""
"C:\Program Files\MP3 Player Utilities 4.00\MediaManager\"=""
"C:\Program Files\MP3 Player Utilities 4.00\MediaManager\help\"=""
"C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\skin\xpstyle\"=""
"C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\skin\"=""
"C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\"=""
"C:\Program Files\MP3 Player Utilities 4.00\Windows98Drv\"=""
"C:\Program Files\MP3 Player Utilities 4.00\RDiskUpdate\"=""
"C:\Program Files\MP3 Player Utilities 4.00\RDiskUpdate\driver\"=""
"C:\Documents and Settings\user\Start Menu\Programs\MP3 Player Utilities 4.00\"=""
"C:\Documents and Settings\user\Application Data\Microsoft\Installer\{7784A172-61F1-445E-8368-601607E0DD22}\"=""
"C:\Program Files\BillP Studios\WinPatrol\"="1"
"C:\Program Files\BillP Studios\"="1"
"C:\Program Files\BillP Studios\WinPatrol\kbase\"=""
"C:\Documents and Settings\All Users\Start Menu\Programs\WinPatrol\"=""
"C:\WINDOWS\Installer\{3205A978-4A7A-403B-A4B9-D48E6BAFB73B}\"=""
"C:\WINDOWS\PCHEALTH\ERRORREP\"="1"
"C:\WINDOWS\PCHEALTH\ERRORREP\QHEADLES\"="1"
"C:\WINDOWS\PCHEALTH\ERRORREP\QSIGNOFF\"="1"
"C:\Program Files\Common Files\Microsoft Shared\DW\"=""
"C:\WINDOWS\winsxs\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\"=""
"C:\WINDOWS\winsxs\Policies\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_77c24773\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\"=""
"C:\Program Files\MSN Messenger\Device Manager\"=""
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\"=""
"C:\WINDOWS\Installer\{43DCF766-6838-4F9A-8C91-D92DA586DFA8}\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\"="1"
"C:\WINDOWS\Microsoft.NET\Framework\"="1"
"C:\WINDOWS\Microsoft.NET\"="1"
"C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\"=""
"C:\WINDOWS\winsxs\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\"=""
"C:\WINDOWS\Installer\{40ABF1E0-8B6F-4D32-B343-E19FA2F04B3C}\"=""
"C:\Program Files\Common Files\Microsoft Shared\DW\1033\"=""
"C:\Documents and Settings\All Users\Application Data\Microsoft\IdentityCRL\production\"=""
"C:\WINDOWS\Installer\{FCE50DB8-C610-4C42-BE5C-193F46C6F812}\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\18\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\8\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\25\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\7\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\1046\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\17\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\4\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\1028\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\10\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\12\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\11\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\20\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\9\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\16\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\29\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\6\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\31\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\22\"=""
"C:\Program Files\MSN Messenger\Device Manager\Loc\19\"=""
"C:\WINDOWS\Installer\{571700F0-DB9D-4B3A-B03D-35A14BB5939F}\"=""
"C:\Documents and Settings\user\Application Data\Microsoft\Installer\{F58E04CD-6E76-43C8-AAF1-482225C2910E}\"=""
"C:\Program Files\MindFusion Limited\Xml Viewer\"=""
"C:\Program Files\MindFusion Limited\"=""
"C:\Documents and Settings\user\Start Menu\Programs\XML Viewer\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Users\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Users\App_LocalResources\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_GlobalResources\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\AppConfig\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\AppConfig\App_LocalResources\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_Code\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RedistList\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\Browsers\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Providers\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Providers\App_LocalResources\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Wizard\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Wizard\App_LocalResources\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Permissions\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Permissions\App_LocalResources\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_LocalResources\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_Data\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Roles\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Roles\App_LocalResources\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MSBuild\"=""
"C:\WINDOWS\System32\MUI409\"=""
"C:\Program Files\Internet Explorer\MUI409\"=""
"C:\Program Files\Internet Explorer\MUI\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MUI409\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MUI\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\App_LocalResources\"=""
"C:\Program Files\Common Files\Microsoft Shared\DW\1025\"=""
"C:\Program Files\Common Files\Microsoft Shared\DW\1028\"=""
"C:\Program Files\Common Files\Microsoft Shared\DW\1031\"=""
"C:\Program Files\Common Files\Microsoft Shared\DW\1036\"=""
"C:\Program Files\Common Files\Microsoft Shared\DW\1040\"=""
"C:\Program Files\Common Files\Microsoft Shared\DW\1041\"=""
"C:\Program Files\Common Files\Microsoft Shared\DW\1042\"=""
"C:\Program Files\Common Files\Microsoft Shared\DW\2052\"=""
"C:\Program Files\Common Files\Microsoft Shared\DW\3082\"=""
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\"=""
"C:\Documents and Settings\user\Start Menu\Programs\XML Notepad 2007\"="1"
"C:\Program Files\XML Notepad 2007\Samples\"=""
"C:\Program Files\XML Notepad 2007\"=""
"C:\Documents and Settings\user\Application Data\Microsoft\Installer\{259B9457-855A-4FA1-8AFE-3613ADF11973}\"=""
"C:\WINDOWS\Installer\{C0B0FA55-D4E9-4374-9871-BBFBF2AEF0D1}\"=""
"C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\"=""
"C:\Program Files\Common Files\Java\Update\Base Images\"=""
"C:\Program Files\Common Files\Java\Update\"=""
"C:\Program Files\Common Files\Java\"=""
"C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_01.b06\"=""
"C:\Program Files\Java\jre1.6.0_01\"=""
"C:\Program Files\Java\"=""
"C:\Program Files\Java\jre1.6.0_01\bin\"=""
"C:\WINDOWS\Installer\{3248F0A8-6813-11D6-A77B-00B0D0160010}\"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\TempPackages]
"C:\WINDOWS\Installer\{40ABF1E0-8B6F-4D32-B343-E19FA2F04B3C}\NewShortcut3_7D8636620AB440BDAD9FA2ED548C3187.exe"=dword:00000001
"C:\WINDOWS\Installer\{40ABF1E0-8B6F-4D32-B343-E19FA2F04B3C}\NewShortcut5_7D8636620AB440BDAD9FA2ED548C3187.exe"=dword:00000001
"C:\WINDOWS\Installer\{40ABF1E0-8B6F-4D32-B343-E19FA2F04B3C}\NewShortcut6_7D8636620AB440BDAD9FA2ED548C3187.exe"=dword:00000001
"C:\WINDOWS\Installer\{40ABF1E0-8B6F-4D32-B343-E19FA2F04B3C}\NewShortcut1_7D8636620AB440BDAD9FA2ED548C3187.exe"=dword:00000001
"C:\WINDOWS\Installer\94838.msi"=dword:00000000
"C:\WINDOWS\Installer\{FCE50DB8-C610-4C42-BE5C-193F46C6F812}\MsblIco.Exe"=dword:00000001
"C:\WINDOWS\Installer\179b29.msi"=dword:00000000
"C:\Documents and Settings\user\Application Data\Microsoft\Installer\{F58E04CD-6E76-43C8-AAF1-482225C2910E}\_294823.exe"=dword:00000001
"C:\Documents and Settings\user\Application Data\Microsoft\Installer\{F58E04CD-6E76-43C8-AAF1-482225C2910E}\_18be6784.exe"=dword:00000001
"C:\WINDOWS\Installer\502c10.msi"=dword:00000000
"C:\WINDOWS\Installer\{C0B0FA55-D4E9-4374-9871-BBFBF2AEF0D1}\ARPPRODUCTICON.exe"=dword:00000001
"C:\WINDOWS\Installer\{C0B0FA55-D4E9-4374-9871-BBFBF2AEF0D1}\_8EC6B7AB_355B_462C_9D83_9BC4542FE459"=dword:00000001
"C:\WINDOWS\Installer\{C0B0FA55-D4E9-4374-9871-BBFBF2AEF0D1}\_F624FE6F_E3BC_4809_964E_021BF257D72D"=dword:00000001
"C:\WINDOWS\Installer\{C0B0FA55-D4E9-4374-9871-BBFBF2AEF0D1}\pando.exe_ED0ECD11C6AB405E9A06D25E96BD6FD7.exe"=dword:00000001
"C:\WINDOWS\Installer\{C0B0FA55-D4E9-4374-9871-BBFBF2AEF0D1}\pando.exe1_ED0ECD11C6AB405E9A06D25E96BD6FD7.exe"=dword:00000001
"C:\WINDOWS\Installer\{C0B0FA55-D4E9-4374-9871-BBFBF2AEF0D1}\NewShortcut4_C0B0FA55D4E943749871BBFBF2AEF0D1.exe"=dword:00000001
"C:\WINDOWS\Installer\{C0B0FA55-D4E9-4374-9871-BBFBF2AEF0D1}\NewShortcut3_C0B0FA55D4E943749871BBFBF2AEF0D1.exe"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs]
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Print Templates\MIPTemplate_Print_3.5 x 5 + Mini Wallet.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Assign a keyboard shortcut - An example\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Assign a keyboard shortcut - An example\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Assign a keyboard shortcut - An example\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Basic scripting\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Basic scripting\CSS\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Basic scripting\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Basic scripting\Scripts\start_prod_tour_10.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a custom toolbar\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a custom toolbar\CSS\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a custom toolbar\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a custom toolbar\Scripts\start_prod_tour_7.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a dialog Preset - An example\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a dialog Preset - An example\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a dialog Preset - An example\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a dialog Preset - An example\Scripts\NewImage_dialog.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a tool Preset - An example\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a tool Preset - An example\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a tool Preset - An example\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Create a tool Preset - An example\Scripts\Text.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Rename multiple files simultaneously\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Rename multiple files simultaneously\CSS\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Rename multiple files simultaneously\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Rename multiple files simultaneously\Scripts\start_prod_tour_12.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Run a script on multiple files\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Run a script on multiple files\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Run a script on multiple files\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Separate a tool from its flyout\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Separate a tool from its flyout\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Automation and Customization\Separate a tool from its flyout\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Create a new image\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Create a new image\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Create a new image\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Create a new image\Scripts\NewImage_dialog.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Crop an image\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Crop an image\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Crop an image\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Crop an image\Scripts\crop.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\E-mail an image\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\E-mail an image\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\E-mail an image\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\E-mail an image\Scripts\Send_dialog.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Open a saved image\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Open a saved image\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Open a saved image\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Open a saved image\Scripts\Browser_dialog.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Resize an image\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Resize an image\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Resize an image\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Resize an image\Scripts\Resize_dialog.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Rotate a photo\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Rotate a photo\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Rotate a photo\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Rotate a photo\Scripts\Rotate_dialog.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take a Window screen capture\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take a Window screen capture\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take a Window screen capture\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take a Window screen capture\Scripts\OpenCapSetup_dialog.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take an Area screen capture\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take an Area screen capture\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take an Area screen capture\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Basic Tasks\Take an Area screen capture\Scripts\OpenCapSetup_dialog.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Correct perspective distortion\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Correct perspective distortion\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Correct perspective distortion\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Correct perspective distortion\Scripts\PerspectiveTransform.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Fix a photo\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Fix a photo\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Fix a photo\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Fix a photo\Scripts\Choose_OSPF.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Remove red-eye\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Remove red-eye\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Remove red-eye\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Remove red-eye\Scripts\RedEye_dialog.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Straighten a crooked photo\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Straighten a crooked photo\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Straighten a crooked photo\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Correcting Photos\Straighten a crooked photo\Scripts\Straighten.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add a drop shadow and caption\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add a drop shadow and caption\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add a drop shadow and caption\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add a picture frame\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add a picture frame\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add a picture frame\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add a picture frame\Scripts\PicFrame.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a path - An example\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a path - An example\CSS\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a path - An example\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a path - An example\Scripts\CenterInCanvas.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a separate layer\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a separate layer\CSS\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a separate layer\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Add text on a separate layer\Scripts\Text.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Create a seamless tiled image\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Create a seamless tiled image\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Create a seamless tiled image\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Graphics Projects\Create a seamless tiled image\Scripts\SeamTile.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Convert a photo into a greeting card\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Convert a photo into a greeting card\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Convert a photo into a greeting card\Images\AddBorders_icon.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Convert a photo into a greeting card\Scripts\AddBorders_dialog.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create depth of field\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create depth of field\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create depth of field\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create depth of field\Scripts\FreehandSelection.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 1\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 1\CSS\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 1\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 1\Scripts\BrightContrast.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 2\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 2\CSS\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 2\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Create soft focus - Method 2\Scripts\SoftFocus_dialog.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Erase an image background\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Erase an image background\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Erase an image background\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Erase an image background\Scripts\BackgroundEraser.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a photo look old\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a photo look old\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a photo look old\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a photo look old\Scripts\AddNoiseUni15Mono.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a selection greyscale\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a selection greyscale\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a selection greyscale\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Make a selection greyscale\Scripts\SelNone.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Modify a photo via blend modes\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Modify a photo via blend modes\CSS\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Modify a photo via blend modes\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Modify a photo via blend modes\Scripts\ChooseOverlay.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Upload photos to a PhotoSharing site\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Upload photos to a PhotoSharing site\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Upload photos to a PhotoSharing site\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Upload photos to a PhotoSharing site\Scripts\StartBrowser.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Basic\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Basic\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Basic\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Basic\Scripts\PaintBrush.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Intermediate\Index.htm"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Intermediate\css\BPStyles.css"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Intermediate\Images\Back_active.gif"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Quick Guides\Photo Projects\Using Mask Layers - Intermediate\Scripts\BrightContrast.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Sample Images\Flatiron Building.jpg"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Scripts-Restricted\BevelSelection.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Scripts-Trusted\AutoTuber.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Selections\1024 x 768.PspSelection"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Styled Lines\+Solid.PspStyledLine"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Swatches\Swatch_Animal_zebra.PspScript"=dword:00000001
"C:\Program Files\Jasc Software Inc\Paint Shop Pro 8\Textures\Asphalt 01.bmp"=dword:00000001
"C:\WINDOWS\System32\mfc42.dll"=dword:00000003
"C:\WINDOWS\System32\msvcirt.dll"=dword:00000003
"C:\Program Files\Common Files\Ulead Systems\DVD\LDCdBldr.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\DVD\LdrtBurn.dll"=dword:00000002
"C:\Program Files\Common Files\Ulead Systems\DVD\LdvdRec.dll"=dword:00000002
"C:\Program Files\Common Files\Ulead Systems\DVD\LudfRdr.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\DVD\LudfWrtr.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\DVD\LXBurnCom.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRDrv.dll"=dword:00000002
"C:\Program Files\Common Files\Ulead Systems\DVD\UCDCfg.dat"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\AutoDetector\DetMethod.dll"=dword:00000002
"C:\Program Files\Common Files\Ulead Systems\AutoDetector\Monitor.exe"=dword:00000002
"C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRDrvRc.dll"=dword:00000002
"C:\Program Files\Common Files\Ulead Systems\AutoDetector\AutoDetector.chm"=dword:00000002
"C:\Program Files\Common Files\Ulead Systems\AutoDetector\Monitor_Res.dll"=dword:00000002
"C:\Program Files\Common Files\Ulead Systems\AutoDetector\u32Comm.dll"=dword:00000002
"C:\Program Files\Common Files\Ulead Systems\Mpeg\ac3aout.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\MCMpgDec.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\MPEGIN.DLL"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\MPGAOUT.DLL"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\mpgaparse.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\mpgcap32.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\mpgcheck.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\mpgmux.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\mpgvout.001"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\mpgvout.002"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\mpgvout.003"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\mpgvout.004"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\MPGVOUT.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\mpgvparse.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\mpg_dlg.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\pcmaout.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\uldsmpeg.ax"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\ulesmpeg.ax"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\ulmxmpeg.ax"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\ulspmpeg.ax"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\Mpeg\uvsc.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\DVD\LdrtDisc.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\DVD\LdvdEng.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\DVD\XDiscLayer.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\DVD\XLogUtil.dll"=dword:00000001
"C:\Program Files\Common Files\Ulead Systems\DVD\XDiscLayerRC.dll"=dword:00000001
"C:\WINDOWS\System32\MSVCRTD.DLL"=dword:00000001
"C:\WINDOWS\Downloaded Program Files\messengerstatsclient.dll"=dword:00000001
"C:\Program Files\Common Files\InstallShield\Professional\RunTime91\Intel32\iKernel.dll"=dword:00000018
"C:\Program Files\Common Files\InstallShield\Professional\RunTime91\Intel32\Setup.dll"=dword:00000018
"C:\Program Files\Common Files\InstallShield\Professional\RunTime91\Intel32\DotNetInstaller.exe"=dword:00000018
"C:\Program Files\Common Files\InstallShield\Professional\RunTime91\Intel32\iscript.dll"=dword:00000018
"C:\Program Files\Common Files\InstallShield\Professional\RunTime91\Intel32\ctor.dll"=dword:00000018
"C:\Program Files\Common Files\InstallShield\Professional\RunTime91\Intel32\iuser.dll"=dword:00000018
"C:\Program Files\Common Files\InstallShield\Professional\RunTime91\Intel32\IGDI.dll"=dword:00000018
"C:\Documents and Settings\All Users\Application Data\Microsoft\IdentityCRL\production\ppcrlconfig.dll"=dword:00000002
"C:\Program Files\Windows Journal Viewer\JVNBDoc.dll"=dword:00000001
"C:\Program Files\Windows Journal Viewer\JVVWCTL.DLL"=dword:00000001
"C:\WINDOWS\Help\JntView.chm"=dword:00000001
"C:\Program Files\Windows Journal Viewer\jvintl.dll"=dword:00000001
"C:\Program Files\Windows Journal Viewer\jvinkseg.dll"=dword:00000001
"C:\WINDOWS\System32\inked.dll"=dword:00000001
"C:\Program Files\Common Files\Microsoft Shared\Ink\inkobj.dll"=dword:00000001
"C:\Program Files\Common Files\Microsoft Shared\Ink\tpcps.dll"=dword:00000001
"C:\WINDOWS\System32\wisptis.exe"=dword:00000001
"C:\WINDOWS\Downloaded Program Files\istactivex.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.tlb"=dword:00000002
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.tlb"=dword:00000002
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.JScript.tlb"=dword:00000002
"C:\WINDOWS\System32\mscories.dll"=dword:00000002
"C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\mscormmc.dll"=dword:00000002
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscoree.tlb"=dword:00000002
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorlib.tlb"=dword:00000002
"C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\mscormmc.cfg"=dword:00000002
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.tlb"=dword:00000002
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.tlb"=dword:00000002
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Drawing.tlb"=dword:00000002
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.tlb"=dword:00000002
"C:\Program Files\Opera\Program\Plugins\\NPSWF32.dll"=dword:00000003
"C:\WINDOWS\Downloaded Program Files\GomWeb3.dll"=dword:00000001
"C:\WINDOWS\System32\sirenacm.dll"=dword:00000001
"C:\WINDOWS\System32\msxml4.dll"=dword:00000001
"C:\WINDOWS\System32\msxml4r.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\Vsavb7rtUI.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\VsaVb7rt.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Vsa.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft_VsaVb.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ndpsetup.ico"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dv_aspnetmmc.chm"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallCommon.sql"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Aspnet.config"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\DefaultWsdlHelpGenerator.aspx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_filter.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallPersistSqlState.sql"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallSqlStateTemplate.sql"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallMembership.sql"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MmcAspExt.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AspNetMMCExt.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet.mof"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Aspnet_perf.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_perf.h"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\UninstallPersonalization.sql"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallProfile.SQL"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\Browsers\goAmerica.browser"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regiis.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Aspnet_regsql.exe.config"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\UninstallRoles.sql"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state_perf.h"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.tlb"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\UninstallPersistSqlState.sql"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\UninstallSqlStateTemplate.sql"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\web.config"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallWebEventSqlProvider.sql"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\web_mediumtrust.config.default"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\web_mediumtrust.config"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\web_minimaltrust.config.default"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\web_minimaltrust.config"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallSqlState.sql"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\UninstallSqlState.sql"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\webengine.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\web_hightrust.config"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\web_hightrust.config.default"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\web_lowtrust.config"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\web_lowtrust.config.default"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_perf.ini"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state_perf.ini"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\AppConfig\App_LocalResources\SmtpSettings.aspx.resx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_LocalResources\error.aspx.resx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Permissions\App_LocalResources\createPermission.aspx.resx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Providers\App_LocalResources\providerList.ascx.resx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_GlobalResources\AppConfigCommon.resx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Roles\App_LocalResources\manageSingleRole.aspx.resx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\App_LocalResources\setUpAuthentication.aspx.resx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Users\App_LocalResources\editUser.aspx.resx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Wizard\App_LocalResources\wizardAddUser.ascx.resx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_Data\GroupedProviders.xml"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\navigationBar.ascx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\AppConfig\SmtpSettings.aspx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_Code\WebAdminPage.cs"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\WebAdminHelp.aspx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\requiredBang.gif"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Permissions\managePermissions.aspx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Providers\ProviderList.ascx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Roles\manageSingleRole.aspx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\security.aspx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Users\addUser.aspx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Wizard\wizardAddUser.ascx"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\alinkui.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\alink.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfdll.dll"=dword:00000001
"C:\WINDOWS\System32\dfshim.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Deployment.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\gacutil.exe.config"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\regsvcs.exe.config"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ieexec.exe.config"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\csc.exe.config"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\cscompui.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cscompmgd.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\csc.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cscomp.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cvtres.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\CvtResUI.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.JScript.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\jsc.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MSBuild.rsp"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Common.Tasks"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.CSharp.targets"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Engine.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Framework.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Tasks.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Utilities.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MSBuild\Microsoft.Build.Commontypes.xsd"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MSBuild\Microsoft.Build.Core.xsd"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.xsd"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\fusion.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsn.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\peverify.dll"=dword:00000001
"C:\Program Files\Internet Explorer\MUI409\mscorier.dll"=dword:00000001
"C:\WINDOWS\System32\mscoree.dll"=dword:00000001
"C:\WINDOWS\System32\mscorier.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\NETFXSBS10.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\sbscmp10.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Accessibility.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AdoNetDiag.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RedistList\FrameworkList.xml"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CasPol.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ilasm.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CLR.mof"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Thunk.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Security.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CORPerfMonExt.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CORPerfMonSymbols.h"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Culture.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CustomMarshalers.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\_dataperfcounters_shared12_neutral.h"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll"=dword:00000001
"C:\WINDOWS\System32\netfxperf.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\_NetworkingPerfCounters.h"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Configuration.Install.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.Protocols.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Drawing.Design.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.ServiceProcess.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.RegularExpressions.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.Services.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.XML.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Design.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEExec.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEExecRemote.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEHost.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IIEHost.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\installutil.exe.config"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallUtilLib.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ISymWrapper.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordbc.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordbi.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorie.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorld.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorpe.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvc.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscortim.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\netfxsbs12.hkf"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ngen.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\normalization.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\PerfCounter.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\sbscmp20_mscorwks.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\sbscmp20_perfcounter.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\SharedReg12.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\shfusion.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\SOS.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.OracleClient.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\_DataOracleClientPerfCounters_shared12_neutral.h"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.SqlXml.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Management.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Remoting.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\sysglobl.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.configuration.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Drawing.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Messaging.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Transactions.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.Mobile.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\TLBREF.DLL"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\WMINet_Utils.dll"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\XPThemes.manifest"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\corperfmonsymbols.ini"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\_dataperfcounters_shared12_neutral.ini"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\_Networkingperfcounters.ini"=dword:00000001
"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\_DataOracleClientPerfCounters_shared12_neutral.ini"=dword:00000001
"C:\WINDOWS\System32\MUI409\mscorees.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MUI409\mscorsecr.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\shfusion.chm"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ShFusRes.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\regtlibv12.exe"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\sbs_diasymreader.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\sbs_iehost.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\sbs_microsoft.jscript.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\sbs_microsoft.vsa.vb.codedomprocessor.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\sbs_mscordbi.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\sbs_mscorrc.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\sbs_mscorsec.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\sbs_system.configuration.install.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\sbs_system.data.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\sbs_system.enterpriseservices.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\sbs_VsaVb7rt.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\sbs_wminet_utils.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\vbc7ui.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\vbc.exe"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\vbc.exe.config"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualC.Dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll"=dword:00000001 "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\System.Windows.Forms.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Windows.Forms.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorlib.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscoree.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Drawing.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\System.EnterpriseServices.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\Microsoft.JScript.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\Microsoft.Vsa.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\System.Drawing.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\mscoree.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.EnterpriseServices.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Microsoft.JScript.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Microsoft.Vsa.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Microsoft.Vsa.Vb.CodeDOMProcessor.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\mscorlib.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\System.tlb"=dword:00001000 "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\Microsoft.Vsa.Vb.CodeDOMProcessor.tlb"=dword:00001000 "C:\WINDOWS\feedingfrenzy.scr"=dword:00000001 "C:\WINDOWS\Downloaded Program Files\HGStart9USA.exe"=dword:00000001 "C:\WINDOWS\Downloaded Program Files\HGPlugin9USA.dll"=dword:00000001 "C:\WINDOWS\Downloaded Program Files\hgstartjp23.exe"=dword:00000001 "C:\WINDOWS\Downloaded Program Files\hgnotifyjp23.exe"=dword:00000001 "C:\WINDOWS\Downloaded Program Files\HGPluginJP23.dll"=dword:00000001 "C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\other.zip"=dword:00000001 "C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\core1.zip"=dword:00000001 "C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\core2.zip"=dword:00000001 "C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\core3.zip"=dword:00000001 "C:\WINDOWS\System32\OggDS.dll"=dword:00000001 "C:\Program Files\Creative\Shared Files\MtpManU.dll"=dword:00000006 "C:\Program Files\Creative\Shared Files\VFSvrps.dll"=dword:00000006 "C:\Program Files\Creative\Shared Files\VFSvrU.exe"=dword:00000006 "C:\Program Files\Creative\Shared Files\OpaQManU.exe"=dword:00000004 "C:\Program Files\Creative\Shared Files\OpqManps.dll"=dword:00000004 "C:\Program Files\Creative\Shared Files\CTXMLPsu.dll"=dword:00000006 "C:\Program Files\Creative\Shared Files\CDDBControlCreative.dll"=dword:00000002 "C:\Program Files\Creative\Shared Files\CDDBUICreative.dll"=dword:00000002 "C:\Program Files\Creative\Shared Files\CTFRConv.ax"=dword:00000005 "C:\Program Files\Creative\Shared Files\CTQTSF.ax"=dword:00000005 "C:\Program Files\Creative\Shared Files\Mp3Dump.ax"=dword:00000005 "C:\Program Files\Creative\Shared Files\VidProcU.ax"=dword:00000005 "C:\Program Files\Creative\Shared Files\WavTrans.ax"=dword:00000005 "C:\Program Files\Creative\ZENcast Organizer\AVSrcU.dll"=dword:00000001 "C:\Program Files\Creative\ZENcast Organizer\CTIntrfu.dll"=dword:00000001 "C:\Program Files\Creative\ZENcast Organizer\CTRegSvu.exe"=dword:00000001 "C:\Program Files\Creative\Shared Files\PlayManU.dll"=dword:00000001 "C:\Program Files\Creative\ZENcast Organizer\Id3Tagu.mft"=dword:00000001 "C:\Program Files\Creative\ZENcast Organizer\TagMgru.mft"=dword:00000001 "C:\Program Files\Creative\ZENcast Organizer\WmaTagu.mft"=dword:00000001 "C:\Program Files\Creative\ZENcast Organizer\Tag.crl"=dword:00000001 "C:\Program Files\Creative\ZENcast Organizer\AVConvU.dll"=dword:00000001 "C:\Program Files\Creative\Shared Files\CTRegSvr.exe"=dword:00000004 "C:\Program Files\Creative\Shared Files\PDEJB.pid"=dword:00000003 "C:\Program Files\Creative\Shared Files\PdtIdMgr.pid"=dword:00000004 "C:\Program Files\Common Files\Creative\Installation\Brazil\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Common\Common.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Common\Error.ini"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Common\RegEdit.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Common\_setup.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Danish\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Dutch\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\English\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Finnish\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\French\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\German\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Italian\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Japanese\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Korean\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Norwegian\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\PChinese\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Port\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Spanish\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Swedish\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\TChinese\_IsUser.dll"=dword:00000006 "C:\Program Files\Common Files\Creative\Installation\Turkish\_IsUser.dll"=dword:00000006 "C:\Program Files\Creative\MediaSource5\CTIntrfc.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTIntrfu.dll"=dword:0000000b "C:\Program Files\Creative\MediaSource5\CTLogDBu.dll"=dword:00000003 "C:\Program Files\Creative\MediaSource5\CTRegSvu.exe"=dword:0000000b "C:\Program Files\Creative\MediaSource5\HookWndU.dll"=dword:00000002 "C:\WINDOWS\System32\CTSVCCDA.EXE"=dword:00000001 "C:\WINDOWS\System32\CTSVCCTL.EXE"=dword:00000001 "C:\Program Files\Creative\Shared Files\MDAQMGRU.DLL"=dword:00000001 "C:\Program Files\Creative\Shared Files\CDAsvc.exe"=dword:00000001 "C:\Program Files\Creative\ShareDLL\CADI\ctaudspi.dll"=dword:00000001 "C:\Program Files\Creative\ShareDLL\CADI\ctcadi.dll"=dword:00000001 "C:\Program Files\Creative\ShareDLL\CADI\ctdmzspi.dll"=dword:00000001 "C:\Program Files\Creative\ShareDLL\CADI\ctksspi.dll"=dword:00000001 "C:\Program Files\Creative\ShareDLL\CADI\ctmbspi.dll"=dword:00000001 "C:\Program Files\Creative\ShareDLL\CADI\ctphme.dat"=dword:00000001 "C:\Program Files\Creative\ShareDLL\CADI\CTPLang.dat"=dword:00000001 "C:\Program Files\Creative\ShareDLL\CADI\CTPreset.dll"=dword:00000001 "C:\Program Files\Creative\ShareDLL\CADI\ctpxspi.dll"=dword:00000001 "C:\Program Files\Creative\ShareDLL\CADI\ctsf.dll"=dword:00000001 "C:\Program Files\Creative\ShareDLL\CADI\DBACS.dll"=dword:00000001 "C:\Program Files\Creative\ShareDLL\CADI\NotiMan.dll"=dword:00000001 "C:\Program Files\Creative\ShareDLL\CADI\NotiMan.exe"=dword:00000001 "C:\Program Files\Creative\ShareDLL\CADI\P0005_01.dat"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTDBEngu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTMetaDu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTNJBDBu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTXMLPsu.dll"=dword:00000002 "C:\Program Files\Creative\MediaSource5\Id3Tagu.mft"=dword:00000003 "C:\Program Files\Creative\MediaSource5\TagMgru.mft"=dword:00000003 "C:\Program Files\Creative\MediaSource5\WmaTagu.mft"=dword:00000003 "C:\Program Files\Creative\MediaSource5\Tag.crl"=dword:00000003 "C:\Program Files\Creative\Shared Files\AC3Srcu.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\AuChnMap.dll"=dword:00000001 "C:\Program Files\Creative\Shared Files\AudGain.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\CDDA.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\CMSS3.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\CTDAE.dll"=dword:00000001 "C:\Program Files\Creative\Shared Files\CTIntrfu.dll"=dword:00000001 "C:\Program Files\Creative\Shared Files\CTNeo6.dll"=dword:00000001 "C:\Program Files\Creative\Shared Files\CTRegSvu.exe"=dword:00000001 "C:\Program Files\Creative\Shared Files\DSCompr.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\InetSrcu.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\Karaoke.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\LiveRecu.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\MetaBPMu.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\MetaSVMu.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\MlpSrcu.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\MP3Write.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\NoisRedu.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\NvfSrcu.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\PDP.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\RawWritu.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\TimeScal.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\Upsample.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\Virtual.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\WavWrite.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\WmaSrc.ax"=dword:00000001 "C:\Program Files\Creative\Shared Files\WMAWrite.ax"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CDRipu.scm"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CodcMgru.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CrBufEnu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTDRMUIu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTPlyQ2U.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTSPB.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\EffcMgru.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\FilWritu.flt"=dword:00000001 "C:\Program Files\Creative\MediaSource5\FmtQuryu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\Karaokeu.flt"=dword:00000001 "C:\Program Files\Creative\MediaSource5\MFInfou.dll"=dword:00000004 "C:\Program Files\Creative\MediaSource5\NmdPlayu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\NoisRdcu.flt"=dword:00000001 "C:\Program Files\Creative\MediaSource5\Playbaku.scm"=dword:00000001 "C:\Program Files\Creative\MediaSource5\PlxCmnu.plu"=dword:00000001 "C:\Program Files\Creative\MediaSource5\PlxCoreu.plu"=dword:00000001 "C:\Program Files\Creative\MediaSource5\PlxGrphu.plu"=dword:00000001 "C:\Program Files\Creative\MediaSource5\PlxLoadu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\RecEnumu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\Recordu.scm"=dword:00000001 "C:\Program Files\Creative\MediaSource5\SVMu.flt"=dword:00000001 "C:\Program Files\Creative\MediaSource5\TimeSclu.flt"=dword:00000001 "C:\Program Files\Creative\MediaSource5\Transcou.scm"=dword:00000001 "C:\Program Files\Creative\MediaSource5\VDJPlayu.dll"=dword:00000001 "C:\Program Files\Creative\Shared Files\MetaBPMu.crl"=dword:00000001 "C:\Program Files\Creative\Shared Files\MetaSVMu.crl"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTDRMRes.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTIniFu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CtrlSrcu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTThemeu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\GDICtrl.sku"=dword:00000001 "C:\Program Files\Creative\MediaSource5\GDICtrl2.sku"=dword:00000001 "C:\Program Files\Creative\MediaSource5\GDICtrl3.sku"=dword:00000001 "C:\Program Files\Creative\MediaSource5\PopUpMu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\RtxCtrl.sku"=dword:00000001 "C:\Program Files\Creative\MediaSource5\ThmResu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\WizCPLu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\WndTrnsU.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTMEMDBu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTWMPEnu.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\Help\CMSPDEU.chm"=dword:00000001 "C:\Program Files\Creative\MediaSource5\AVSrcU.dll"=dword:00000002 "C:\Program Files\Creative\MediaSource5\bubble.bff"=dword:00000001 "C:\Program Files\Creative\MediaSource5\Muce.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTImpt3U.bff"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTImpt3u.exe"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTImpt3u.crl"=dword:00000001 "C:\Program Files\Creative\MediaSource5\AVConvU.dll"=dword:00000001 "C:\Program Files\Creative\MediaSource5\CTCDDBu.nco"=dword:00000001 "C:\Program Files\Creative\MediaSource5\NetCoMgu.nco"=dword:00000001 "C:\WINDOWS\Ctregrun.exe"=dword:00000001 "C:\Program Files\Creative\Creative ZEN Vision M Series\ZEN Vision M Series Media Explorer\AVSrcU.dll"=dword:00000001 "C:\Program Files\Creative\Creative ZEN Vision M Series\ZEN Vision M Series Media Explorer\CTIntrfu.dll"=dword:00000001 "C:\Program Files\Creative\Creative ZEN Vision M Series\ZEN Vision M Series Media Explorer\CTRegSvu.exe"=dword:00000001 "C:\Program Files\Creative\Creative ZEN Vision M Series\ZEN Vision M Series Media Explorer\HookWndU.dll"=dword:00000001 "C:\Program Files\Creative\Creative ZEN Vision M Series\ZEN Vision M Series Media Explorer\MFInfou.dll"=dword:00000001 "C:\Program Files\Creative\Shared Files\MtpAutRc.dll"=dword:00000001 "C:\Program Files\Creative\Shared Files\MtpCtxRc.dll"=dword:00000001 "C:\Program Files\Creative\Shared Files\QueManps.dll"=dword:00000001 "C:\Program Files\Creative\Shared Files\QueManU.exe"=dword:00000001 "C:\Program Files\Creative\Shared Files\StrmPlay.dll"=dword:00000001 "C:\Program Files\Creative\Shared Files\ProgHlpU.dll"=dword:00000001 "C:\Program Files\Creative\Shared Files\CTMtpAut.exe"=dword:00000001 "C:\Program Files\Creative\Shared Files\CtCmeCtx.dll"=dword:00000001 "C:\Program Files\Creative\Shared Files\FileRead.ax"=dword:00000001 "C:\Program Files\Creative\CD Ripping Wizard Unicode 2\CTIntrfu.dll"=dword:00000001 "C:\Program Files\Creative\CD Ripping Wizard Unicode 2\CTXMLPsu.dll"=dword:00000001 "C:\Program Files\Creative\CD Ripping Wizard Unicode 2\CTRegSvu.exe"=dword:00000001 "C:\Program Files\Creative\CD Ripping Wizard Unicode 2\Id3Tagu.mft"=dword:00000001 "C:\Program Files\Creative\CD Ripping Wizard Unicode 2\TagMgru.mft"=dword:00000001 "C:\Program Files\Creative\CD Ripping Wizard Unicode 2\WmaTagu.mft"=dword:00000001 "C:\Program Files\Creative\CD Ripping Wizard Unicode 2\Tag.crl"=dword:00000001 "C:\Program Files\Creative\CD Ripping Wizard Unicode 2\CTCDDBu.nco"=dword:00000001 "C:\Program Files\Creative\CD Ripping Wizard Unicode 2\NetCoMgu.nco"=dword:00000001 "C:\Program Files\Creative\CD Ripping Wizard Unicode 2\CTDBEngu.dll"=dword:00000001 "C:\Program Files\Creative\CD Ripping Wizard Unicode 2\CTLogDBu.dll"=dword:00000001 "C:\Program Files\Creative\CD Ripping Wizard Unicode 2\CTMetaDu.dll"=dword:00000001 "C:\Program Files\Creative\CD Ripping Wizard Unicode 2\CTNJBDBu.dll"=dword:00000001 "C:\Program Files\Creative\Sync Manager Unicode\CTIntrfu.dll"=dword:00000002 "C:\Program Files\Creative\Sync Manager Unicode\CTRegSvu.exe"=dword:00000001 "C:\Program Files\Creative\Sync Manager Unicode\Id3Tagu.mft"=dword:00000001 "C:\Program Files\Creative\Sync Manager Unicode\TagMgru.mft"=dword:00000001 "C:\Program Files\Creative\Sync Manager Unicode\WmaTagu.mft"=dword:00000001 "C:\Program Files\Creative\Sync Manager Unicode\Tag.crl"=dword:00000001 "C:\Program Files\Creative\Sync Manager Unicode\CTDBEngu.dll"=dword:00000001 "C:\Program Files\Creative\Sync Manager Unicode\CTLogDBu.dll"=dword:00000001 "C:\Program Files\Creative\Sync Manager Unicode\CTMetaDu.dll"=dword:00000001 "C:\Program Files\Creative\Sync Manager Unicode\CTNJBDBu.dll"=dword:00000001 "C:\Program Files\Creative\Sync Manager Unicode\CTXMLPsu.dll"=dword:00000001 "C:\Program Files\Creative\Sync Manager Unicode\AVConvU.dll"=dword:00000001 "C:\Program Files\Creative\Video Converter\AVConvU.dll"=dword:00000001 "C:\Program Files\Creative\Creative ZEN Vision M Series\ZEN Vision M Series Media Explorer\Id3Tagu.mft"=dword:00000001 "C:\Program Files\Creative\Creative ZEN Vision M Series\ZEN Vision M Series Media Explorer\TagMgru.mft"=dword:00000001 "C:\Program Files\Creative\Creative ZEN Vision M Series\ZEN Vision M Series Media Explorer\WmaTagu.mft"=dword:00000001 "C:\Program Files\Creative\Creative ZEN Vision M Series\ZEN Vision M Series Media Explorer\Tag.crl"=dword:00000001 "C:\Program Files\Creative\Creative ZEN Vision M Series\ZEN Vision M Series Media Explorer\CTImpt3U.bff"=dword:00000001 "C:\Program Files\Creative\Creative ZEN Vision M Series\ZEN Vision M Series Media Explorer\CTImpt3u.exe"=dword:00000001 "C:\Program Files\Creative\Creative ZEN Vision M Series\ZEN Vision M Series Media Explorer\CTImpt3u.crl"=dword:00000001 "C:\Program Files\Creative\Creative ZEN Vision M Series\ZEN Vision M Series Media Explorer\AVConvU.dll"=dword:00000001 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\UserChosenExecuteHandlers] "H:\\?\IDE#CdRomGIGABYTE_GO-R5232C______________________48S2____#5&35d4fab1&0&0.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}+PlayCDAudioOnArrival"="MSRipCDAudioOnArrival\\xdae8\x6399\x9e4d\x1c5\" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Nero\\x00e60\x00fc0\x00b60\x00fc0\x00ac0\x00a40\x00c90] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\\x2019\1l] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\\x2019\1l\\x2019\1\34 ] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\\x2019\1l\\x2019\1\34 \\x2019\1\x81] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\\x00cd0\x00af0\x00bd0\x00f30] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\\x00cd0\x00af0\x00bd0\x00f30\\x00e10\x00a40\x00d70\x00eb0\x00b90\x00c80\x00fc0\x00ea0\x00fc0] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{FFAD0956-2035-C64A-C01F-CA77DFADE3CA}] "dbfmnhjoamhopbelghmanjbgfacphnoghghmngla"=hex:6b,61,70,6e,66,66,6f,6c,67,65,70,6b,63,61,69,6e,67,61,63,64,6d,.. [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache] "C:\Documents and Settings\user\Desktop\moonshell171_with_dpgtools13\moonshell171_with_dpgtools13\Setup.exe"="Setup" "@C:\WINDOWS\system32\SHELL32.dll,-22915"="Contains the files and folders that you have deleted." "@C:\WINDOWS\system32\SHELL32.dll,-8503"="S&earch…" "@C:\WINDOWS\system32\mycomput.dll,-400"="Mana&ge" "@shell32.dll,-31232"="System Tasks" "@shell32.dll,-31294"="View system information" "@shell32.dll,-31327"="Add or remove programs" "@shell32.dll,-31312"="Change a setting" "@shell32.dll,-31272"="Other Places" "@C:\WINDOWS\system32\SHELL32.dll,-9217"="My Network Places" "@C:\WINDOWS\system32\SHELL32.dll,-9227"="My Documents" "@shell32.dll,-21785"="Shared Documents" "@shell32.dll,-31274"="Details" "@C:\WINDOWS\system32\SHELL32.dll,-9216"="My Computer" "@shell32.dll,-31291"="These tasks apply to your computer or the selected hardware device." "@C:\WINDOWS\system32\SHELL32.dll,-22913"="Shows the disk drives and hardware connected to this computer." "@shell32.dll,-31382"="Eject this disk" "@shell32.dll,-8504"="Auto&Play" "@shell32.dll,-31233"="File and Folder Tasks" "@shell32.dll,-31236"="Make a new folder" "@shell32.dll,-31260"="Publish this folder to the Web" "@shell32.dll,-31374"="Share this folder" "@shell32.dll,-31254"="Rename this folder" "@shell32.dll,-31256"="Move this folder" "@shell32.dll,-31258"="Copy this folder" "@shell32.dll,-31380"="E-mail this folder's files" "@shell32.dll,-31262"="Delete this folder" "@shell32.dll,-31242"="Rename this file" "@shell32.dll,-31244"="Move this file" "@shell32.dll,-31246"="Copy this file" "@shell32.dll,-31248"="Publish this file to the Web" "@shell32.dll,-31370"="E-mail this file" "@shell32.dll,-31252"="Delete this file" "@shell32.dll,-31264"="Move the selected items" "@shell32.dll,-31266"="Copy the selected items" "@shell32.dll,-31268"="Publish the selected items to the Web" "@shell32.dll,-31362"="E-mail the selected items" "@shell32.dll,-31270"="Delete the selected items" "@explorer.exe,-7024"="Internet" "@explorer.exe,-7025"="E-mail" "@C:\Program Files\NetMeeting\conf.exe,-12345"="H.323 Internet Telephony" "@C:\WINDOWS\system32\accwiz.exe,-16"="Accessibility Wizard settings" "@C:\WINDOWS\system32\SHELL32.dll,-22978"="Briefcase" "@C:\WINDOWS\System32\ntbackup.exe,-40"="Windows Backup File" "@C:\WINDOWS\System32\pdh.dll,-10023"="Performance Monitor File" "@C:\WINDOWS\System32\cryptext.dll,-6145"="Security Catalog" "@C:\WINDOWS\System32\cdfview.dll,-4610"="Channel File" "@C:\WINDOWS\System32\cryptext.dll,-6108"="Security Certificate" "@C:\Program Files\NetMeeting\conf.exe,-12346"="SpeedDial" "@C:\WINDOWS\System32\cryptext.dll,-6110"="Certificate Revocation List" "@C:\WINDOWS\System32\shimgvw.dll,-304"="Bitmap Image" "@C:\WINDOWS\system32\notepad.exe,-469"="Text Document" "@C:\WINDOWS\system32\netshell.dll,-1300"="Dialup Networking File" "@C:\WINDOWS\inf\unregmp2.exe,-9927"="Microsoft Recorded TV Show" "@C:\WINDOWS\System32\shimgvw.dll,-301"="EMF Image" "@C:\WINDOWS\System32\shimgvw.dll,-302"="GIF Image" "@C:\Program Files\NetMeeting\conf.exe,-12347"="Intel IPhone Compatible" "@C:\WINDOWS\System32\setupapi.dll,-2000"="Setup Information" "@C:\Program Files\Internet Explorer\Connection Wizard\icwres.dll,-20003"="Internet Communication Settings" "@C:\WINDOWS\System32\shimgvw.dll,-303"="JPEG Image" "@C:\WINDOWS\System32\wshext.dll,-4804"="JScript Script File" "@C:\WINDOWS\System32\wshext.dll,-4805"="JScript Encoded Script File" "@C:\WINDOWS\inf\unregmp2.exe,-10003"="Movie file (mpeg)" "@C:\WINDOWS\system32\mmcbase.dll,-130"="Microsoft Common Console Document" "@C:\WINDOWS\System32\msi.dll,-34"="Windows Installer Package" "@C:\WINDOWS\System32\msi.dll,-35"="Windows Installer Patch" "@C:\WINDOWS\System32\RCBdyctl.dll,-150"="Microsoft Remote Assistance Incident" "@C:\Program Files\Movie Maker\1033\wmm2res.dll,-63097"="Windows Movie Maker Project" "@C:\WINDOWS\PCHealth\HelpCtr\Binaries\msinfo.dll,-391"="MSInfo Document" "@C:\Program Files\NetMeeting\nmwb.dll,-1234"="Microsoft NetMeeting T126 Compatible Whiteboard Document" "@C:\WINDOWS\System32\cryptext.dll,-6111"="PKCS #7 Certificates" "@C:\WINDOWS\System32\cryptext.dll,-6113"="PKCS #7 Signature" "@C:\WINDOWS\System32\shimgvw.dll,-305"="PNG Image" "@C:\WINDOWS\System32\scrobj.dll,-8192"="Windows Script Component" "@C:\WINDOWS\system32\shscrap.dll,-258"="Scrap object" "@C:\WINDOWS\System32\cryptext.dll,-6112"="Microsoft Serialized Certificate Store" "@C:\WINDOWS\System32\cryptext.dll,-6109"="Certificate Trust List" "@C:\WINDOWS\System32\wshext.dll,-4803"="VBScript Encoded Script File" "@C:\WINDOWS\System32\wshext.dll,-4802"="VBScript Script File" "@C:\WINDOWS\inf\unregmp2.exe,-9909"="Windows Media Audio/Video file" "@C:\WINDOWS\inf\unregmp2.exe,-9920"="Windows Media Player Download Package" "@C:\WINDOWS\System32\shimgvw.dll,-307"="WMF Image" "@C:\WINDOWS\inf\unregmp2.exe,-9915"="Windows Media Player Skin File" "@C:\WINDOWS\inf\unregmp2.exe,-9910"="Windows Media Audio/Video playlist" "@C:\WINDOWS\inf\unregmp2.exe,-9916"="Windows Media Player Skin Package" "@C:\WINDOWS\inf\unregmp2.exe,-9923"="Windows Media playlist" "@"C:\Program Files\Windows NT\Accessories\WORDPAD.EXE",-208"="Write Document" "@C:\WINDOWS\System32\wshext.dll,-4801"="Windows Script File" "@C:\WINDOWS\System32\wshext.dll,-4800"="Windows Script Host Settings File" "@C:\WINDOWS\System32\msxml3r.dll,-1"="XML Document" "@C:\WINDOWS\System32\msxml3r.dll,-2"="XSL Stylesheet" "@shell32.dll,-31275"="This section displays the size, file type, and other information about a selected item." "C:\Program Files\Winamp\Winamp.exe"="Winamp" "C:\Program Files\Real\RealPlayer\RealPlay.exe"="RealPlayer" "C:\Program Files\Internet Explorer\iexplore.exe"="Internet Explorer" "C:\Program Files\Windows Media Player\wmplayer.exe"="Windows Media Player" "C:\Program Files\Movie Maker\moviemk.exe"="Windows Movie Maker" "C:\Program Files\VideoLAN\VLC\vlc.exe"="VLC media player" "@shell32.dll,-31273"="These links open other folders and take you quickly to useful places." "@shell32.dll,-31234"="These tasks apply to the files and folders you select." "C:\Documents and Settings\user\Desktop\moonshell11\moonshell11\Setup.exe"="Setup" "C:\WINDOWS\Explorer.EXE"="Windows Explorer" "@shell32.dll,-31250"="Print this file" "C:\WINDOWS\system32\NOTEPAD.EXE"="Notepad" "C:\Program Files\Windows NT\Accessories\WORDPAD.EXE"="WordPad" "C:\Program Files\UltraISO\UltraISO.exe"="UltraISO" "@shell32.dll,-31295"="Shows information about your computer, such as the processor speed and the amount of installed memory." "@shell32.dll,-31328"="Provides the steps necessary to add a new program, or to change or remove an existing program." "@shell32.dll,-31361"="Provides options for you to customize the appearance and functionality of your computer." "@C:\WINDOWS\system32\SHELL32.dll,-22912"="Shows shortcuts to Web sites, network computers, and FTP sites." "@C:\WINDOWS\system32\SHELL32.dll,-22914"="Contains letters, reports, and other documents and files." "@shell32.dll,-21779"="My Pictures" "@shell32.dll,-21791"="My Videos" "C:\Program Files\WinRAR\WinRAR.exe"="WinRAR archiver" "C:\Program Files\Mozilla Firefox\firefox.exe"="Firefox" "@C:\WINDOWS\system32\SHELL32.dll,-8964"="Recycle Bin" "@shdoclc.dll,-880"="Internet Explorer" "@explorer.exe,-7023"="&Run…" "@explorer.exe,-7020"="&Search" "@explorer.exe,-7021"="&Help and Support" "@C:\WINDOWS\system32\SHELL32.dll,-9319"="Printers and Faxes" "@xpsp1res.dll,-11001"="Internet Explorer" "@C:\WINDOWS\system32\xpsp1res.dll,-10077"="Set Program Access and Defaults" "@C:\WINDOWS\system32\rcbdyctl.dll,-152"="Remote Assistance" "@xpsp1res.dll,-11004"="Outlook Express" "@C:\WINDOWS\inf\unregmp2.exe,-4"="Windows Media Player" "@shell32.dll,-21761"="Accessories" "@shell32.dll,-22075"="Windows Catalog" "@shell32.dll,-21773"="Games" "@shell32.dll,-21787"="Startup" "@Shell32.dll,-12689"="Contains music and other audio files." "@shell32.dll,-31276"="Music Tasks" "@shell32.dll,-31278"="Play all" "@shell32.dll,-31281"="Shop for music online" "@shell32.dll,-28995"="Shared Music" "@shell32.dll,-31279"="Play selection" "@shell32.dll,-31372"="Copy to audio CD" "@shell32.dll,-31277"="These tasks apply to the music files and folders you select." "@shell32.dll,-31282"="Connects you to the Windows Media Web site where you can find music to download and buy." "@shell32.dll,-31280"="Plays all or the selected music files in this folder." "C:\Documents and Settings\user\Desktop\moonshell171_with_dpgtools13\moonshell171_with_dpgtools13\CreateThumbnail.exe"="CreateThumbnail" "@shell32.dll,-12691"="My Recent Documents" "@shell32.dll,-31283"="Picture Tasks" "@shell32.dll,-31287"="View as a slide show" "@shell32.dll,-31313"="Order prints online" "@shell32.dll,-31391"="Print pictures" "@shell32.dll,-31379"="Copy all items to CD" "@C:\WINDOWS\system32\SHELL32.dll,-12695"="Contains files and folders shared between users of this computer." "C:\WINDOWS\System32\cmd.exe"="Windows Command Processor" "C:\Program Files\YoungMX\YoungMX.exe"="YoungMX Media Player" "@shell32.dll,-31390"="Print this picture" "@shell32.dll,-31289"="Set as desktop background" "@shell32.dll,-31352"="Copy to CD" "@shell32.dll,-31290"="Uses the selected picture, pattern, or HTML document as the background for your computer screen." "@shell32.dll,-31316"="Starts the Photo Printing Wizard, which helps you format and print your digital pictures." "@shell32.dll,-31314"="Starts the Online Print Ordering Wizard, which helps you order prints of your digital pictures." "@shell32.dll,-31288"="Arranges all the pictures in this folder into a slide show." "@shell32.dll,-31284"="These tasks apply to the picture files and folders you select." "@shell32.dll,-31243"="Gives this file or folder a new label that you type for it." "C:\WINDOWS\System32\fontview.exe"="Windows Font Viewer" "@C:\Program Files\Internet Explorer\iexplore.exe,-702"="Internet Explorer" "@xpsp1res.dll,-11003"="Launch Internet Explorer Browser" "@C:\WINDOWS\system32\netshell.dll,-1200"="Network Connections" "@shell32.dll,-22017"="Address Book" "@shell32.dll,-22022"="Command Prompt" "@shell32.dll,-22051"="Notepad" "@C:\WINDOWS\system32\tourstart.exe,-1"="Tour Windows XP" "@shell32.dll,-22041"="Magnifier" "@shell32.dll,-22048"="Narrator" "@shell32.dll,-22052"="On-Screen Keyboard" "@shell32.dll,-22065"="Utility Manager" "@shell32.dll,-22019"="Calculator" "@shell32.dll,-22054"="Paint" "@shell32.dll,-22069"="WordPad" "@shell32.dll,-22016"="Accessibility Wizard" "@shell32.dll,-22031"="HyperTerminal" "@C:\WINDOWS\System32\mstsc.exe,-4000"="Remote Desktop Connection" "@shell32.dll,-22061"="Sound Recorder" "@shell32.dll,-22018"="Backup" "@shell32.dll,-22021"="Character Map" "@shell32.dll,-22026"="Disk Cleanup" "@shell32.dll,-22027"="Disk Defragmenter" "@C:\WINDOWS\system32\usmt\migwiz.exe,-202"="Files and Settings Transfer Wizard" "@shell32.dll,-22063"="System Information" "@C:\WINDOWS\system32\restore\rstrui.exe,-2048"="System Restore" "@C:\WINDOWS\System32\comres.dll,-661"="Component Services" "@shell32.dll,-22023"="Computer Management" "@shell32.dll,-22025"="Data Sources (ODBC)" "@shell32.dll,-22029"="Event Viewer" "@shell32.dll,-22040"="Local Security Policy" "@shell32.dll,-22055"="Performance" "@shell32.dll,-22059"="Services" "@shell32.dll,-22030"="FreeCell" "@C:\WINDOWS\system32\mshearts.exe,-413"="Hearts" "@C:\PROGRA~1\MSNGAM~1\Windows\bckgres.dll,-1212"="Internet Backgammon" "@C:\PROGRA~1\MSNGAM~1\Windows\chkrres.dll,-1212"="Internet Checkers" "@C:\PROGRA~1\MSNGAM~1\Windows\hrtzres.dll,-1212"="Internet Hearts" "@C:\PROGRA~1\MSNGAM~1\Windows\rvseres.dll,-1212"="Internet Reversi" "@C:\PROGRA~1\MSNGAM~1\Windows\shvlres.dll,-1212"="Internet Spades" "@shell32.dll,-22045"="Minesweeper" "@shell32.dll,-22057"="Pinball" "@shell32.dll,-22060"="Solitaire" "@C:\WINDOWS\system32\spider.exe,-56"="Spider Solitaire" "@shell32.dll,-21772"="Entertainment" "@shell32.dll,-21760"="Accessibility" "@shell32.dll,-22062"="Synchronize" "@C:\WINDOWS\system32\compatUI.dll,-115"="Program Compatibility Wizard" "@shell32.dll,-22067"="Windows Explorer" "@shell32.dll,-21762"="Administrative Tools" "@shell32.dll,-21768"="Communications" "@shell32.dll,-21788"="System Tools" "@C:\WINDOWS\system32\netshell.dll,-1010"="New Connection Wizard" "@C:\WINDOWS\system32\hnetwiz.dll,-3085"="Network Setup Wizard" "@shell32.dll,-22066"="Volume Control" "@shell32.dll,-22058"="Scheduled Tasks" "C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe"="AutoDetector" "C:\WINDOWS\Twain_32\ScanWiz5\SDetect.exe"="Microtek Scanner Detector" "C:\Program Files\MSN Messenger\MsnMsgr.Exe"="Messenger" "C:\Program Files\mIRC\mirc.exe"="mIRC" "C:\Program Files\Opera\opera.exe"="Opera Internet Browser" "@Shell32.dll,-12690"="Contains movies and other video files." "@shell32.dll,-31317"="System Tasks" "@shell32.dll,-31321"="Hide the contents of this drive" "@shell32.dll,-31292"="Search for files or folders" "@shell32.dll,-31325"="Hide the contents of this folder" "@shell32.dll,-31318"="These tasks apply to your computer and to this protected folder." "@shell32.dll,-31322"="Hides the files and folders stored on this drive to protect them from being changed or deleted." "@shell32.dll,-31383"="Copies the selected items to the CD-R folder so that you can burn them on a compact disc." "C:\PROGRA~1\COMMON~1\MICROS~1\DW\DW20.EXE"="Microsoft Application Error Reporting" "C:\Documents and Settings\user\My Documents\moonshell16\moonshell16\Setup.exe"="Setup" "C:\Documents and Settings\user\My Documents\DPGPlay_v3.2\dpgplay.exe"="dpgplay" "C:\Documents and Settings\user\My Documents\DPGPlay_v3.2\mplayer.exe"="MPlayer/MEncoder - Movie Player" "C:\Documents and Settings\user\Desktop\reinmoon05\20060804_reinmoon05\Setup.exe"="Setup" "@Shell32.dll,-12688"="Contains digital photos, images, and graphic files." "C:\Program Files\GRETECH\GomPlayer\GOM.exe"="GOM Player" "C:\PROGRA~1\GRETECH\GOMPLA~1\GOM.exe"="GOM Player" "C:\WINDOWS\System32\logon.scr"="Logon Screen Saver" "@shell32.dll,-31396"="Video Tasks" "@shell32.dll,-31397"="These tasks apply to the video files and folders you select." "C:\WINDOWS\notepad.exe"="Notepad" "C:\Program Files\Microsoft Office\Office\WINWORD.EXE"="Microsoft Word for Windows" "C:\WINDOWS\System32\zipfldr.dll"="Compressed (zipped) Folders" "C:\Documents and Settings\user\Desktop\20060908_reinmoon06\20060908_reinmoon06\Setup.exe"="Setup" "E:\ReinMoonMakeIcon.exe"="ReinMoonMakeIcon" "@shell32.dll,-31329"="Recycle Bin Tasks" "@shell32.dll,-31331"="Empty the Recycle Bin" "@shell32.dll,-31333"="Restore all items" "@shell32.dll,-31330"="These tasks apply to the files and folders that you have deleted." "@shell32.dll,-31336"="Moves the selected items to the places they were before they were put in the Recycle Bin." "C:\Documents and Settings\user\Desktop\moonshell10_dpgtools\moonshell10_dpgtools\dpgdec.exe"="dpgdec" "C:\Documents and Settings\user\Desktop\moonshell10_dpgtools\moonshell10_dpgtools\dpgenc.exe"="dpgenc" "@shell32.dll,-12704"="Internet P&roperties" "@shell32.dll,-12705"="&Browse the Internet" "C:\DOCUME~1\user\LOCALS~1\Temp\~nsu.tmp\Au_.exe"="Au_" "C:\Program Files\NJStar Communicator\Njcom32.exe"="NJCOM32 - NJStar Communicator for WIN32" "@shell32.dll,-31375"="Makes the selected folder available to computers on a network so that other people can view it." "@shell32.dll,-31249"="Transfers copies of the selected items to a public Web page so that you can share them with other people." "@shell32.dll,-31237"="Creates a new, empty folder in the folder you have open." "@zipfldr.dll,-10300"="Folder Tasks" "@zipfldr.dll,-10302"="Extract all files" "@shell32.dll,-21765"="Application Data" "@shell32.dll,-12693"="Favorites" "@shell32.dll,-21786"="Start Menu" "c:\progra~1\common~1\instal~1\update~1\isuspm.exe"="InstallShield Update Service Update Manager" "@explorer.exe,-7004"="Opens your Internet browser." "C:\Program Files\Microsoft Office\Office\POWERPNT.EXE"="Microsoft PowerPoint for Windows" "@shell32.dll,-12589"="Files Currently on the CD" "@shell32.dll,-12590"="Files Ready to Be Written to the CD" "C:\Program Files\MindFusion Limited\Xml Viewer\XMLViewer.exe"="XML Viewer" "C:\PROGRA~1\MINDMA~1\MindManP.exe"="The Creative MindManager" "C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe"="Adobe Reader 7.0" "@inetcplc.dll,-4746"="Accessibility" "@inetcplc.dll,-4731"="Always expand ALT text for images" "@inetcplc.dll,-4732"="Move system caret with focus/selection changes" "@inetcplc.dll,-4745"="Browsing" "@inetcplc.dll,-4852"="Use inline AutoComplete" "@inetcplc.dll,-4856"="Enable Personalized Favorites Menu" "@inetcplc.dll,-4866"="Force offscreen compositing even under Terminal Server (requires restart)" "@inetcplc.dll,-4833"="Show friendly HTTP error messages" "@inetcplc.dll,-4734"="Show friendly URLs" "@inetcplc.dll,-4743"="Use Passive FTP (for firewall and DSL modem compatibility)" "@inetcplc.dll,-4737"="Enable folder view for FTP sites" "@inetcplc.dll,-4840"="Show Go button in Address bar" "@inetcplc.dll,-4837"="Automatically check for Internet Explorer updates" "@inetcplc.dll,-4836"="Enable Install On Demand (Internet Explorer)" "@inetcplc.dll,-4835"="Notify when downloads complete" "@inetcplc.dll,-4838"="Close unused folders in History and Favorites (requires restart)" "@inetcplc.dll,-4829"="Enable page transitions" "@inetcplc.dll,-4861"="Reuse windows for launching shortcuts" "@inetcplc.dll,-4736"="Enable offline items to be synchronized on a schedule" "@inetcplc.dll,-4831"="Disable script debugging" "@inetcplc.dll,-4832"="Display a notification about every script error" "@inetcplc.dll,-4735"="Use smooth scrolling" "@inetcplc.dll,-4828"="Underline links" "@inetcplc.dll,-4825"="Always" "@inetcplc.dll,-4827"="Hover" "@inetcplc.dll,-4826"="Never" "@inetcplc.dll,-4874"="Enable third-party browser extensions (requires restart)" "@inetcplc.dll,-4873"="Enable visual styles on buttons and controls in web pages" "@inetcplc.dll,-4839"="Always send URLs as UTF-8 (requires restart)" "@inetcplc.dll,-4875"="Enable Install On Demand (Other)" "@inetcplc.dll,-4747"="Security" "@inetcplc.dll,-4750"="Empty Temporary Internet Files folder when browser is closed" "@inetcplc.dll,-4749"="Do not save encrypted pages to disk" "@inetcplc.dll,-4761"="Check for publisher's certificate revocation" "@inetcplc.dll,-4762"="Check for signatures on downloaded programs" "@inetcplc.dll,-4863"="Enable Integrated Windows Authentication (requires restart)" "@inetcplc.dll,-4756"="Enable Profile Assistant" "@inetcplc.dll,-4757"="Warn if changing between secure and not secure mode" "@inetcplc.dll,-4759"="Warn about invalid site certificates" "@inetcplc.dll,-4752"="Use SSL 2.0" "@inetcplc.dll,-4753"="Use SSL 3.0" "@inetcplc.dll,-4760"="Check for server certificate revocation (requires restart)" "@inetcplc.dll,-4758"="Warn if forms submittal is being redirected" "@inetcplc.dll,-4754"="Use TLS 1.0" "@inetcplc.dll,-4822"="HTTP 1.1 settings" "@inetcplc.dll,-4823"="Use HTTP 1.1" "@inetcplc.dll,-4824"="Use HTTP 1.1 through proxy connections" "@vmhelper.dll,-4000"="Java console enabled (requires restart)" "@vmhelper.dll,-4001"="JIT compiler for virtual machine enabled (requires restart)" "@vmhelper.dll,-4002"="Java logging enabled" "@inetcplc.dll,-4744"="Multimedia" "@inetcplc.dll,-4741"="Play animations in web pages" "@inetcplc.dll,-4871"="Enable Automatic Image Resizing" "@inetcplc.dll,-4876"="Don't display online media content in the media bar" "@inetcplc.dll,-4865"="Enable Image Toolbar (requires restart)" "@inetcplc.dll,-4742"="Show pictures" "@inetcplc.dll,-4843"="Show image download placeholders" "@inetcplc.dll,-4738"="Smart image dithering" "@inetcplc.dll,-4739"="Play sounds in web pages" "@inetcplc.dll,-4740"="Play videos in web pages" "@inetcplc.dll,-4769"="Printing" "@inetcplc.dll,-4770"="Print background colors and images" "@inetcplc.dll,-4771"="Search from the Address bar" "@inetcplc.dll,-4844"="When searching" "@inetcplc.dll,-4845"="Display results, and go to the most likely site" "@inetcplc.dll,-4847"="Just display the results in the main window" "@inetcplc.dll,-4846"="Just go to the most likely site" "@inetcplc.dll,-4848"="Do not search from the Address bar" "@zipfldr.dll,-10148"="Compressed (zipped) Folder" "@sendmail.dll,-21"="Desktop (create shortcut)" "@sendmail.dll,-4"="Mail Recipient" "@C:\Program Files\Movie Maker\1033\wmm2res.dll,-63096"="Capture and edit digital media on your computer and then share your saved movies by e-mail, the Internet, recordable CD, or on a DV video tape." "@(null)ystemRoot\system32\shell32.dll,-22581"="Creates and edits text documents with complex formatting." "@xpsp1res.dll,-11002"="Finds and displays information and Web sites on the Internet." "C:\Documents and Settings\user\Desktop\cyloxmlp\Setup.Exe"="Setup" "C:\WINDOWS\System32\taskmgr.exe"="Windows TaskManager" "C:\Program Files\Microsoft Office\Office\MSACCESS.EXE"="Microsoft Access for Windows" "C:\WINDOWS\System32\msiexec.exe"="Windows\xae installer" "@C:\WINDOWS\System32\msi.dll,-36"="&Install" "@C:\WINDOWS\System32\msi.dll,-37"="Re&pair" "@C:\WINDOWS\System32\msi.dll,-38"="&Uninstall" "C:\Documents and Settings\user\Desktop\dotnetfx.exe"="IExpress Setup" "C:\DOCUME~1\user\LOCALS~1\Temp\IXP000.TMP\Install.exe"="External Installer" "C:\Program Files\XML Notepad 2007\XmlNotepad.exe"="XML Notepad 2007" "C:\Program Files\EA SPORTS\TOTAL CLUB MANAGER 2005\TCM2005.EXE"="TCM2005" "C:\Program Files\Ulead Systems\Ulead PhotoImpact 10 TBYB\Iedit.exe"="PhotoImpact" "C:\WINDOWS\system32\mspaint.exe"="Paint" "C:\Program Files\Ulead Systems\Ulead PhotoImpact 10\Iedit.exe"="PhotoImpact" "C:\WINDOWS\System32\shimgvw.dll"="Windows Picture and Fax Viewer" "@shell32.dll,-31353"="CD Writing Tasks" "@shell32.dll,-31355"="Write these files to CD" "@C:\WINDOWS\system32\SHELL32.dll,-32517"="Taskbar and Start Menu" "@C:\WINDOWS\System32\Audiodev.dll,-510"="Portable Media Devices" "@C:\WINDOWS\system32\SHELL32.dll,-22985"="Folder Options" "@C:\WINDOWS\system32\SHELL32.dll,-22981"="Fonts" "@C:\WINDOWS\system32\SHELL32.dll,-22982"="Administrative Tools" "@C:\WINDOWS\System32\mstask.dll,-3408"="Scheduled Tasks" "@C:\WINDOWS\system32\wiashext.dll,-331"="Scanners and Cameras" "@C:\WINDOWS\System32\Audiodev.dll,-51"="View the portable media devices connected to your computer." "@mmsys.cpl,-5856"="Windows" "@mmsys.cpl,-5824"="Default Beep" "@mmsys.cpl,-5825"="Program error" "@mmsys.cpl,-5826"="Close program" "@mmsys.cpl,-5827"="Critical Battery Alarm" "@mmsys.cpl,-5828"="Device Connect" "@mmsys.cpl,-5829"="Device Disconnect" "@mmsys.cpl,-5830"="Device Failed to Connect" "@mmsys.cpl,-5832"="Low Battery Alarm" "@mmsys.cpl,-5837"="New Mail Notification" "@mmsys.cpl,-5833"="Maximize" "@mmsys.cpl,-5834"="Menu command" "@mmsys.cpl,-5835"="Menu popup" "@mmsys.cpl,-5836"="Minimize" "@mmsys.cpl,-5839"="Open program" "@mmsys.cpl,-5840"="Print Complete" "@mmsys.cpl,-5841"="Restore Down" "@mmsys.cpl,-5842"="Restore Up" "@mmsys.cpl,-5843"="Asterisk" "@mmsys.cpl,-5845"="Exclamation" "@mmsys.cpl,-5846"="Exit Windows" "@mmsys.cpl,-5847"="Critical Stop" "@mmsys.cpl,-5848"="System Notification" "@mmsys.cpl,-5849"="Question" "@mmsys.cpl,-5850"="Start Windows" "@mmsys.cpl,-5852"="Windows Logoff" "@mmsys.cpl,-5853"="Windows Logon" "@mmsys.cpl,-5854"="Windows Explorer" "@mmsys.cpl,-5831"="Empty Recycle Bin" "@mmsys.cpl,-5838"="Start Navigation" "C:\WINDOWS\System32\SNDVOL32.EXE"="Volume Control" "C:\Program Files\mIRC\download\chasseur.exe"="Flash Player 5.0 r30" "C:\PROGRA~1\MOZILL~1\FIREFOX.EXE"="Firefox" "@shimgvw.dll,-550"="Pre&view" "C:\Documents and Settings\user\Desktop\SCIONS_OF_FATE_V5_0126_2007.exe"="SCIONS_OF_FATE_V5_0126_2007" "C:\PROGRA~1\Ahead\nero\nero.exe"="Nero Burning ROM" "C:\Program Files\BitComet\BitComet.exe"="BitComet - a BitTorrent Client" "@shell32.dll,-31335"="Restore the selected items" "@C:\WINDOWS\system32\SHELL32.dll,-31361"="Provides options for you to customize the appearance and functionality of your computer." "C:\Program Files\mIRC\download\Warcraft_III_-_The_Frozen_Throne\Warcraft III - The Frozen Throne [Disk 1].iso\install.exe"="Warcraft III Installer" "C:\Program Files\Warcraft III\BNUpdate.exe"="BNUpdate" "C:\Program Files\mIRC\download\Warcraft_III_-_The_Frozen_Throne\Warcraft III - The Frozen Throne [Disk2]\install.exe"="Frozen Throne Installer" "C:\Program Files\Warcraft III\Warcraft III.exe"="Warcraft III" "C:\Program Files\Warcraft III\Frozen Throne.exe"="Frozen Throne" "C:\Program Files\Common Files\Microsoft Shared\MSInfo\MSInfo32.exe"="System Information" "C:\WINDOWS\pchealth\helpctr\binaries\helpctr.exe"="Microsoft Help and Support Center" "@shell32.dll,-31334"="Restore this item" "@shell32.dll,-31332"="Permanently removes all items in the Recycle Bin and frees up disk space." "@shell32.dll,-31326"="Hides the items stored in this folder to protect them from being changed or deleted." "C:\Documents and Settings\user\Desktop\zion-3-setup.exe"="zion-3-setup" "@C:\Program Files\Messenger\msgslang.dll,-61144"="Windows Messenger" "@wmploc.dll,-1800"="Play" "@wmploc.dll,-6502"="Windows Media Player" "@(null)ystemRoot\system32\SHELL32.dll,-17154"="Open folder to view files" "@(null)ystemRoot\system32\SHELL32.dll,-17155"="Windows Explorer" "@(null)ystemRoot\system32\SHELL32.dll,-17168"="Take no action" "C:\Program Files\Warcraft III\Frozen_Throne.exe"="Frozen Throne" "C:\Program Files\Ulead Systems\Ulead PhotoImpact 10\anygif\ga_main.exe"="Ulead GIF Animator" "@netshell.dll,-1501"="Network Tasks" "@netshell.dll,-1585"="Create a new connection" "@netshell.dll,-1520"="Set up a home or small office network" "@netshell.dll,-1503"="See Also" "@netshell.dll,-1525"="Network Troubleshooter" "@C:\WINDOWS\system32\netshell.dll,-1201"="Connects to other computers, networks, and the Internet." "C:\Documents and Settings\user\Local Settings\Application Data\Mozilla\Firefox\Mozilla Firefox\updates\updater.exe"="Software Updater" "@shell32.dll,-31354"="These tasks apply to the files already on or about to be written to a CD." "@shell32.dll,-31253"="Moves the selected items to the Recycle Bin. If you want to recover them later, go to the Recycle Bin." "@shell32.dll,-31371"="Sends an e-mail message with copies of the selected files, or the files within a selected folder." "@shell32.dll,-31356"="Copies and writes the files you select onto a recordable CD." "C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\G5FDELY8\feedingfrenzy_ridecpa1_stub[1].exe"="RealArcade Download Manager" "C:\DOCUME~1\user\LOCALS~1\Temp\__ArcadeDownloadFoler__feedingfrenzy_EN_1apcedir\RealOneArcadeBundle.exe"="Shell executable of Setup program" "C:\DOCUME~1\user\LOCALS~1\Temp\~rnsetup\GoogleInstApp.exe"="GoogleInst Application" "C:\Program Files\Real\RealArcade\RNArcade.exe"="RealArcade" "C:\WINDOWS\regedit.exe"="Registry Editor" "C:\Documents and Settings\user\My Documents\Koon Long\paradise_heights_2\paradise2\RAKUEN2.EXE"="RAKUEN2" "C:\Documents and Settings\user\My Documents\Koon Long\true_love\truelove\T_LOVE95.EXE"=" " "C:\Documents and Settings\user\My Documents\Koon Long\paradiseheights1\Rakuen.exe"="Rakuen" "C:\Documents and Settings\user\My Documents\Koon Long\paradiseheights1\MOTV95_T.EXE"="ParadiseHeights Setup" "C:\WINDOWS\System32\winhlp32.exe"="Windows Winhlp32 Stub" "C:\WINDOWS\winhlp32.exe"="Microsoft\xae Help" "C:\paradise_heights1\paradiseheights1\MOTV95_T.EXE"="ParadiseHeights Setup" "C:\paradise_heights1\MOTV95_T.EXE"="ParadiseHeights Setup" "C:\paradise_heights1\RAKUEN.EXE"="RAKUEN" "C:\Program Files\FOSTER\ParadiseHeights\RAKUEN.EXE"="RAKUEN" "C:\Program Files\Unreal3.2\unins000.exe"="Setup/Uninstall" "C:\Program Files\Warcraft III\War3.exe"="Warcraft III" "C:\Program Files\MP3 Player Utilities 4.00\AMVPlayer\amvplayer.exe"="looksingle Microsoft \x57fa\x7840\x7c7b\x5e94\x7528\x7a0b\x5e8f" "C:\Program Files\QuickPar\QuickPar.exe"="QuickPar" "C:\PROGRA~1\QUICKT~1\QuickTimePlayer.exe"="QuickTime Player" "C:\Program Files\Course Technology\SAM 2003\Sam11.exe"="SAM xp Shell" "C:\WINDOWS\system32\sdbinst.exe"="AppFix & AppHelp Installer" "C:\Program Files\Warcraft III\World Editor.exe"="World Editor" "D:\vcd_play.exe"="VideoDisc Player" "C:\Program Files\Ahead\Nero StartSmart\NeroStartSmart.exe"="Nero StartSmart" "C:\Program Files\Ahead\nero\nero.exe"="Nero Burning ROM" "@(null)ystemRoot\system32\SHELL32.dll,-17169"="Open writable CD folder" "@(null)ystemRoot\system32\SHELL32.dll,-17170"="Windows Explorer" "@wmploc.dll,-6505"="Burn a CD" "C:\Program Files\Sony Corporation\Image Transfer\SONYCOPY.EXE"="Image Transfer" "C:\Program Files\PIXELA\ImageMixer\ImxInput.exe"="ImageMixer" "@shell32.dll,-31315"="Print the selected pictures" "@shell32.dll,-31378"="Copy all items to audio CD" "@shell32.dll,-31373"="Starts the Windows Media Player so you can copy music files to a CD recorder." "C:\Program Files\Warcraft III\War2Patch_202.exe"="War2Patch_202" "@themeui.dll,-2037"="{Tahoma, 8 pt}" "@themeui.dll,-2038"="{Tahoma, 8 pt}" "@themeui.dll,-2039"="{Tahoma, 8 pt}" "@themeui.dll,-2040"="{Tahoma, 8 pt}" "@themeui.dll,-2041"="{Tahoma, 8 pt}" "@themeui.dll,-2042"="{Tahoma, 8 pt}" "@themeui.dll,-2017"="Windows XP" "@themeui.dll,-2016"="Windows Classic" "@themeui.dll,-2015"="More themes online…" "@explorer.exe,-7005"="Opens your e-mail program so you can send or read a message." "C:\Program Files\Real\RealArcade\Update\rnuninst.exe"="Uninstaller Shell executable" "C:\Documents and Settings\user\Desktop\MapleSEA_MSSetup070309a.exe"="Setup.exe" "@C:\WINDOWS\system32\SHELL32.dll,-12696"="Shows installed printers and fax printers and helps you add new ones." "C:\DOCUME~1\user\LOCALS~1\Temp\set39.tmp"="Setup.exe" "C:\Program Files\Messenger\msmsgs.exe"="Messenger" "@(null)ystemRoot\system32\shell32.dll,-22563"="Creates and edits text files using basic text formatting." "C:\Program Files\QuickTime\QuickTimePlayer.exe"="QuickTime Player" "C:\WINDOWS\hh.exe"="Microsoft\xae HTML Help Executable" "C:\Program Files\DivX\DivX Player\DivX Player.exe"="DivX Player" "C:\Documents and Settings\user\Desktop\BannedStory Full (1.60).exe"="BannedStory Full (1.60)" "C:\Program Files\BannedStory\characterSimulator.exe"="Macromedia Flash Player 8.0 r22" "@explorer.exe,-7001"="Opens a central location for Help topics, tutorials, troubleshooting, and other support services." "C:\Documents and Settings\user\Desktop\GetLink.exe"="GetLink" "C:\Documents and Settings\user\Desktop\fgen_305.exe"="fgen_305" "C:\Program Files\FlashGet\FlashGet.exe"="FlashGet" "@(null)ystemRoot\inf\unregmp2.exe,-155"="Plays your digital media including music, videos, CDs, DVDs, and Internet Radio." "@shell32.dll,-31293"="The Search Companion helps you find files, folders, printers, and people." "C:\PROGRA~1\FlashGet\flashget.exe"="FlashGet" "@(null)ystemRoot\system32\SHELL32.dll,-17158"="Print the pictures" "@(null)ystemRoot\system32\SHELL32.dll,-17159"="Photo Printing Wizard" "@(null)ystemRoot\system32\SHELL32.dll,-17156"="View a slideshow of the images" "@(null)ystemRoot\system32\SHELL32.dll,-17157"="Windows Picture and Fax Viewer" "@(null)ystemroot\System32\wiaacmgr.exe,-276"="Copy pictures to a folder on my computer" "@(null)ystemroot\System32\wiaacmgr.exe,-101"="Microsoft Scanner and Camera Wizard" "@shell32.dll,-31247"="Copies the selected items to a place you choose." "@shell32.dll,-31245"="Moves the selected items to a place you choose." "@explorer.exe,-7000"="Opens a window where you can pick search options and work with search results." "C:\DOCUME~1\user\LOCALS~1\Temp\Set24.tmp"="InstallShield ® Setup Launcher" "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe"="External Installer" "C:\DOCUME~1\user\LOCALS~1\Temp\EAUninstall.exe"="Uninstall" "C:\WINDOWS\system32\calc.exe"="Windows Calculator" "@Shell32.dll,-12692"="Shows recently opened files and folders." "C:\Documents and Settings\user\Desktop\U_SFInstaller.exe"="Setup.exe" "C:\Documents and Settings\user\Desktop\U_SFInstaller(2).exe"="Setup.exe" "@shdoclc.dll,-867"="&Tip of the Day" "@shdoclc.dll,-868"="Shows the Tip of the Day." "C:\DOCUME~1\user\LOCALS~1\Temp\IXP000.TMP\ie6wzd.exe"="Internet Explorer Setup Progman" "C:\Documents and Settings\user\Desktop\flashget182en.exe"="flashget182en" "C:\DOCUME~1\user\LOCALS~1\Temp\_isE4.exe"="Setup.exe" "@C:\WINDOWS\ime\imkr6_1\imekrcic.dll,-22"="Korean Input System (IME 2002)" "@C:\WINDOWS\ime\sptip.dll,-600"="Speech Recognition" "@PINTLGNT.IME,-61697"="Chinese (Simplified) - Microsoft Pinyin IME 3.0" "C:\Downloads\MS_MY_Client_v07041702.exe"="MS_MY_Client_v07041702" "@C:\WINDOWS\system32\ulib.dll,-1000"="Recovered File Fragments" "C:\Downloads\fullpaktrickster\FullPakTrickster.exe"="FullPakTrickster" "C:\Program Files\Trickster Online\splash.dmy"="Launcher MFC \xc751\xc6a9 \xd504\xb85c\xadf8\xb7a8" "@inetcplc.dll,-4774"="ActiveX controls and plug-ins" "@inetcplc.dll,-4775"="Run ActiveX controls and plug-ins" "@inetcplc.dll,-4803"="Enable" "@inetcplc.dll,-4806"="Administrator approved" "@inetcplc.dll,-4805"="Disable" "@inetcplc.dll,-4804"="Prompt" "@inetcplc.dll,-4776"="Download signed ActiveX controls" "@inetcplc.dll,-4783"="Initialize and script ActiveX controls not marked as safe" "@inetcplc.dll,-4784"="Script ActiveX controls marked safe for scripting" "@inetcplc.dll,-4777"="Download unsigned ActiveX controls" "@inetcplc.dll,-4788"="User Authentication" "@inetcplc.dll,-4790"="Logon" "@inetcplc.dll,-4807"="Anonymous logon" "@inetcplc.dll,-4808"="Prompt for user name and password" "@inetcplc.dll,-4810"="Automatic logon only in Intranet zone" "@inetcplc.dll,-4809"="Automatic logon with current username and password" "@mscorier.dll,-1001"=".NET Framework-reliant components" "@mscorier.dll,-1006"="Run components signed with Authenticode" "@mscorier.dll,-1004"="Enable" "@mscorier.dll,-1003"="Disable" "@mscorier.dll,-1005"="Prompt" "@mscorier.dll,-1002"="Run components not signed with Authenticode" "@inetcplc.dll,-4791"="Downloads" "@inetcplc.dll,-4792"="File download" "@inetcplc.dll,-4793"="Font download" "@vmhelper.dll,-4003"="Java permissions" "@vmhelper.dll,-4004"="Custom" "@vmhelper.dll,-4005"="Disable Java" "@vmhelper.dll,-4006"="High safety" "@vmhelper.dll,-4007"="Low safety" "@vmhelper.dll,-4008"="Medium safety" "@inetcplc.dll,-4794"="Miscellaneous" "@inetcplc.dll,-4862"="Don't prompt for client certificate selection when no certificates or only one certificate exists" "@inetcplc.dll,-4785"="Access data sources across domains" "@inetcplc.dll,-4796"="Drag and drop or copy and paste files" "@inetcplc.dll,-4797"="Submit nonencrypted form data" "@inetcplc.dll,-4795"="Installation of desktop items" "@inetcplc.dll,-4798"="Launching programs and files in an IFRAME" "@inetcplc.dll,-4870"="Allow META REFRESH" "@inetcplc.dll,-4872"="Display mixed content" "@inetcplc.dll,-4830"="Software channel permissions" "@inetcplc.dll,-4816"="High safety" "@inetcplc.dll,-4814"="Low safety" "@inetcplc.dll,-4815"="Medium safety" "@inetcplc.dll,-4855"="Navigate sub-frames across different domains" "@inetcplc.dll,-4853"="Userdata persistence" "@inetcplc.dll,-4782"="Scripting" "@inetcplc.dll,-4786"="Active scripting" "@inetcplc.dll,-4787"="Scripting of Java applets" "@inetcplc.dll,-4854"="Allow paste operations via script" "C:\Downloads\SFSetup.exe"="Setup.exe" "c:\program files\common files\installshield\updateservice\isuspm.exe"="InstallShield Update Service Update Manager" "C:\Downloads\MapleSEA_MSSetup070411a.exe"="Setup.exe" "C:\Program Files\WIZET\MapleStory\Setup.exe"="Setup" "C:\DOCUME~1\user\LOCALS~1\Temp\set13.tmp"="Setup.exe" "C:\Downloads\nogg.exe"="nogg" "C:\DOCUME~1\user\LOCALS~1\Temp\set6.tmp"="Setup.exe" "C:\Downloads\rose_139_139_na_evo\rose_139_139_na_evo.exe"="Setup.exe" "C:\Program Files\Triggersoft\Rose Online Evolution\RRose-Patch.exe"="RRose-Patch" "C:\Program Files\Triggersoft\Rose Online Evolution\Rose Reborn Online Launcher.exe"="Rose Reborn Online Launcher" "C:\Program Files\Triggersoft\Rose Online Evolution\Trose.exe"="Client" "C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe"="WinPatrol System Monitor" "C:\Program Files\Triggersoft\Rose Online Evolution\TriggerDetect.exe"="TODO: <\xd30c\xc77c \xc124\xba85>" "C:\Program Files\Triggersoft\Rose Online Evolution\ROSEonline.exe"="R.O.S.E Launcher" "C:\DOCUME~1\user\LOCALS~1\Temp\setA0.tmp"="Setup.exe" "C:\Program Files\Triggersoft\Rose Online Evolution\RoUpdate.exe"="S.H.O Launcher" "C:\Documents and Settings\user\Desktop\idman509b4.exe"="Internet Download Manager installer" "C:\Documents and Settings\user\Local Settings\Temp\IDM_Setup_Temp\IDM1.tmp"="Internet Download Manager installer" "C:\Program Files\Internet Download Manager\IDMan.exe"="Internet Download Manager (IDM)" "C:\Program Files\Internet Download Manager\Uninstall.exe"="Internet Download Manager installer" "C:\DOCUME~1\user\LOCALS~1\Temp\set5.tmp"="Setup.exe" "C:\Program Files\mIRC\download\XilerROFull.exe"="XilerROFull" "C:\Program Files\Gravity\RO\XiLeRO.exe"="Ragnarok Online patch client" "C:\Program Files\Gravity\RO\setup.exe"="Setup MFC \xc751\xc6a9 \xd504\xb85c\xadf8\xb7a8" "C:\Program Files\Gravity\RO\XiLeRO!.exe"="XiLeRO!" "C:\DOCUME~1\user\LOCALS~1\Temp\is-LGBP6.tmp\is-68T6K.tmp"="Setup/Uninstall" "C:\Program Files\Free Audio Pack\FreeConverter\FreeConverter.exe"="Free Audio Converter" "C:\DOCUME~1\user\LOCALS~1\Temp\is-D0NTP.tmp\is-S7EN5.tmp"="Setup/Uninstall" "C:\Program Files\Power MP3 WMA Converter\PowerConverter.exe"="Power MP3 WMA Converter" "C:\Program Files\Pando Networks\Pando\pando.exe"="pando" "C:\Program Files\Free Audio Pack\unins000.exe"="Setup/Uninstall" "C:\DOCUME~1\user\LOCALS~1\Temp\_iu14D2N.tmp"="Setup/Uninstall" "C:\DOCUME~1\user\LOCALS~1\Temp\setup0533.exe"="setup0533" "@(null)ystemRoot\system32\shell32.dll,-22566"="Creates and edits drawings, and displays and edits scanned photos." "@(null)ystemRoot\system32\shell32.dll,-22531"="Performs basic arithmetic tasks with an on-screen calculator." "@netshell.dll,-1570"="Disable this network device" "@netshell.dll,-1550"="Rename this connection" "@netshell.dll,-1575"="Change settings of this connection" "@netcfgx.dll,-50002"="Allows your computer to access resources on a Microsoft network." "@netcfgx.dll,-50003"="Allows other computers to access resources on your computer using a Microsoft network." "@netcfgx.dll,-50015"="Quality of Service Packet Scheduler. This component provides network traffic control, including rate-of-flow and prioritization services." "@netcfgx.dll,-50001"="Transmission Control Protocol/Internet Protocol. The default wide area network protocol that provides communication across diverse interconnected networks." "@wmploc.dll,-6506"="Rip music from CD" "@explorer.exe,-7003"="Opens a program, folder, document, or Web site." "C:\Documents and Settings\user\My Documents\O2Jam_v3.50(Standard)_20051208.exe"="InstallShield ® Setup Launcher" "C:\Program Files\e-Games\O2Jam\O2JamLauncher.exe"="O2Jam Launcher (e-Games)" "C:\Program Files\e-Games\O2Jam\O2Jam.exe"="O2Jam" "C:\Program Files\e-Games\O2Jam\O2JamPatchClient.exe"="O2JamPatcher" "C:\Program Files\e-Games\O2Jam\OTwo.exe"="OTwo" "@shell32.dll,-31235"="Folder Tasks" "@shell32.dll,-31389"="These tasks apply to the items and folders you select." "C:\DOCUME~1\user\LOCALS~1\Temp\is-C5K20.tmp\is-6O8UV.tmp"="Setup/Uninstall" "C:\DOCUME~1\user\LOCALS~1\Temp\_Riva FLV Encoder.exe"="_Riva FLV Encoder" "C:\DOCUME~1\user\LOCALS~1\Temp\_Riva FLV Player.exe"="_Riva FLV Player" "C:\Program Files\Riva\Riva FLV Encoder 2.0\Riva FLV Player.exe"="Riva FLV Player" "C:\DOCUME~1\user\LOCALS~1\Temp\is-H1ONC.tmp\is-K2PB2.tmp"="Setup/Uninstall" "C:\Program Files\ezvideotools.com\EZ WMV TO MPEG Converter\EZ WMV TO MPEG Converter.exe"="EZ WMV TO MPEG Converter" "C:\Program Files\ezvideotools.com\EZ WMV TO MPEG Converter\unins000.exe"="Setup/Uninstall" "C:\DOCUME~1\user\LOCALS~1\Temp\SetB4.tmp"="InstallShield ® Setup Launcher" "C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\iKernel.exe"="InstallShield ® Setup Engine" "C:\DOCUME~1\user\LOCALS~1\Temp\is-K1L3N.tmp\is-23A4V.tmp"="Setup/Uninstall" "C:\My Games\Feeding Frenzy\ffr.exe"="Feeding Frenzy" "C:\Documents and Settings\user\Desktop\O2Jamnxsongpack1_041213.exe"="InstallShield ® Setup Launcher" "C:\Documents and Settings\user\Desktop\O2Jamnxsongpack2_041213.exe"="InstallShield ® Setup Launcher" "C:\Documents and Settings\user\Desktop\O2Jamnxsongpack3_041213.exe"="InstallShield ® Setup Launcher" "@shell32.dll,-28997"="Shared Pictures" "@shell32.dll,-31398"="Plays all or the selected video files in this folder." "@shell32.dll,-28996"="Shared Video" "C:\DOCUME~1\user\LOCALS~1\Temp\xpinstall.exe"="Java™ Platform SE binary" "C:\DOCUME~1\user\LOCALS~1\Temp\is-RB9BE.tmp\is-C8A74.tmp"="Setup/Uninstall" "C:\Program Files\Ultra Flash Video FLV Converter\Ultra Flash Video FLV Converter.exe"="avconverter" "C:\Program Files\Ultra Flash Video FLV Converter\unins000.exe"="Setup/Uninstall" "C:\DOCUME~1\user\LOCALS~1\Temp\is-LLQ33.tmp\is-BOL3K.tmp"="Setup/Uninstall" "c:\Program Files\MMshall\FLV MP4 Video Converter\FLVMP4Converter.exe"="FLV MP4 Video Converter" "C:\DOCUME~1\user\LOCALS~1\Temp\is-696V9.tmp\is-CNRP1.tmp"="Setup/Uninstall" "C:\DOCUME~1\user\LOCALS~1\Temp\is-QI0VL.tmp\is-QPSD0.tmp"="Setup/Uninstall" "C:\Program Files\Moyea\FLV to Video Pro\FLV2Video.exe"="FLV2Video" "C:\Program Files\Moyea\FLV to Video Pro\unins000.exe"="Setup/Uninstall" "C:\Program Files\Moyea\FLV Downloader\unins000.exe"="Setup/Uninstall" "C:\Program Files\InstallShield Installation Information\{D5CD3E08-6B73-471A-93D1-63C7F32118C1}\setup.exe"="InstallShield ® Setup Launcher" "C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe"="InstallDriver Module" "C:\Program Files\BitComet\Downloads\MapleSEA_MaplePatch25to26.exe"="Patcher MFC ?? ????" "C:\Program Files\PIXELA\ImageMixer\ImageMix.exe"="ImageMixer" "@netshell.dll,-1540"="Repair this connection" "@netshell.dll,-1555"="View status of this connection" "C:\DOCUME~1\user\LOCALS~1\Temp\is-HCTDH.tmp\is-VUSL1.tmp"="Setup/Uninstall" "C:\Program Files\a-squared Anti-Malware\a2wizard.exe"="a-squared Security Wizard" "C:\Program Files\a-squared Anti-Malware\a2guard.exe"="a-squared Guard" "C:\Program Files\a-squared Anti-Malware\a2start.exe"="a-squared Security Center" "C:\Program Files\a-squared Anti-Malware\a2scan.exe"="a-squared Malware Scanner" "C:\Downloads\MapleSEA_MSSetup070619a.exe"="Setup.exe" "@shell32.dll,-12710"="&Run" "C:\WINDOWS\System32\dxdiag.exe"="Microsoft DirectX Diagnostic Tool" "C:\Program Files\a-squared Anti-Malware\unins000.exe"="Setup/Uninstall" "@xpsp1res.dll,-11005"="Sends and receives e-mail and newsgroup messages." "C:\DOCUME~1\user\LOCALS~1\Temp\IXP000.TMP\PluginInstaller.exe"="Windows Genuine Advantage validation plug-in installer" "@themeui.dll,-850"="Brick" "@themeui.dll,-851"="Desert" "@themeui.dll,-852"="Eggplant" "@themeui.dll,-853"="High Contrast #1" "@themeui.dll,-856"="High Contrast #2" "@themeui.dll,-859"="High Contrast Black" "@themeui.dll,-862"="High Contrast White" "@themeui.dll,-865"="Lilac" "@themeui.dll,-867"="Maple" "@themeui.dll,-868"="Marine (high color)" "@themeui.dll,-869"="Plum (high color)" "@themeui.dll,-870"="Pumpkin" "@themeui.dll,-872"="Rainy Day" "@themeui.dll,-873"="Red, White, and Blue (VGA)" "@themeui.dll,-874"="Rose" "@themeui.dll,-876"="Slate" "@themeui.dll,-877"="Spruce" "@themeui.dll,-878"="Storm (VGA)" "@themeui.dll,-879"="Teal (VGA)" "@themeui.dll,-871"="Wheat" "@themeui.dll,-880"="Windows Classic" "@themeui.dll,-883"="Windows Standard" "@themeui.dll,-2019"="Normal" "@themeui.dll,-2021"="Extra Large" "@themeui.dll,-2020"="Large" "C:\Program Files\Outlook Express\msimn.exe"="Outlook Express" "C:\Documents and Settings\user\My Documents\My Received Files\Automouse(1)\Automouse(1).exe"="jola MFC \xc751\xc6a9 \xd504\xb85c\xadf8\xb7a8" "C:\Documents and Settings\user\Desktop\HamachiSetup-1.0.1.5-en.exe"="Hamachi Setup" "C:\Program Files\Hamachi\nicmgr.exe"="nicmgr" "@browselc.dll,-13137"="&Address" "@browselc.dll,-13138"="&Links" "@(null)ystemRoot\System32\msutb.dll,-325"="Language bar" "C:\Program Files\Hamachi\hamachi.exe"="Hamachi Client" "C:\DOCUME~1\user\LOCALS~1\Temp\hamachi-update-1.0.2.2.exe"="Hamachi Setup" "@(null)ystemRoot\system32\shell32.dll,-22573"="Records sounds if a microphone and sound card are installed." "C:\WINDOWS\system32\winmine.exe"="Entertainment Pack Minesweeper Game" "@(null)ystemRoot\system32\compatUI.dll,-117"="Starts the Program Compatibility Wizard, which helps you configure older programs to run on Windows XP" "C:\Program Files\NJStar Communicator\minismtp.exe"="NJStar Mini SMTP Server" "C:\Program Files\NJStar Communicator\NJSIME.EXE"="NJStar Chinese Input Method Editor" "C:\DOCUME~1\user\LOCALS~1\Temp\is-Q0E0J.tmp\is-6MFE3.tmp"="Setup/Uninstall" "C:\DOCUME~1\user\LOCALS~1\Temp\set14.tmp"="Setup.exe" "@shell32.dll,-12709"="&Help and Support" "C:\Downloads\Lunia_Installer_200707301704.exe"="Lunia_Installer_200707301704" "C:\DOCUME~1\user\LOCALS~1\Temp\Lunia.exe"="Lunia" "C:\LuniaGSP\LuniaClient.exe"="LuniaClient" "C:\LuniaGSP\reporter.exe"="reporter" "@(null)ystemRoot\system32\mshearts.exe,-414"="Begins the Hearts card game." "C:\Program Files\Microsoft Office\Office\EXCEL.EXE"="Microsoft Excel for Windows" "C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.5\Pex.exe"="Ulead Photo Explorer" "D:\ctrun\demo32.exe"="DemoShield Player" "D:\PDE\SETUP\SETUP.EXE"="Setup.exe" "D:\CMS\SETUP\SETUP.EXE"="Setup.exe" "D:\AUDIBLE\SETUP\SETUP.EXE"="Setup.exe" "D:\Audible\ActiveSetupRSDK.exe"="ActiveSetup Module" "D:\CTSHARED\LAUNCHEX\PIDINST\SETUP.EXE"="Setup.exe" "D:\REGISTER\SETUP.EXE"="Setup.exe" "D:\PDE\MTPrompt\SETUP.EXE"="Setup.exe" "C:\Program Files\Creative\MediaSource5\Startmsu.exe"="StartMS" "C:\Program Files\Creative\Product Registration\English\RegFlash.exe"="Macromedia Flash Player 7.0 r19" "C:\Program Files\Creative\Product Registration\English\InetReg.exe"="Product Registration Program" "C:\Program Files\Creative\DiskManager\ctpdemgr.exe"="Creative Removable Disk Manager" "@C:\WINDOWS\system32\wiashext.dll,-330"="Add, remove, and configure scanners and cameras." "C:\Program Files\Creative\Support\System Information\CTSI.exe"="Creative System Information" "@C:\Program Files\Creative\MediaSource5\CTCMS.crl,-14345"="Creative MediaSource 5 Player" "C:\Documents and Settings\user\Desktop\HijackThis.exe"="HijackThis" "C:\DOCUME~1\user\LOCALS~1\Temp\is-GRI1G.tmp\is-3AQ8C.tmp"="Setup/Uninstall" "C:\Program Files\HaxFix\catchme.exe"="catchme" "@wmploc.dll,-29300"="Synchronize media files to this device" scanning hidden files … C:\WINDOWS\system32:lzx32.sys 65568 bytes executable hidden from API hidden processes: 0 hidden files: 1
Please download this file - combofix.exe by sUBs
  • Save it to your Desktop
  • Now physically disconnect from the internet and STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields)
  • Click on your START button and choose Run. Then copy/paste the entire content of the following quotebox (Including the "" marks and the Symbols) into the run box.

    "%userprofile%\desktop\ComboFix.exe" /KillAll



    [external image: Posted Image]

  • Click OK and this will start ComboFix in a special way.
  • When finished, it will produce a log. Please save that log to a Notepad File to post in your next reply along with a fresh HJT log.
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

* After you have saved the logs, restart your system to re-enable all the programs that were disabled during the running of ComboFix.

* Reconnect to the internet

* Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
Really thanks a lot for the help! Below are the logfiles. Is there anything else i need to do?

ComboFix 07-08-17.2 - "user" 2007-08-18 23:43:26.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.1.1252.1.1033.18.326 [GMT 8:00]
Command switches used :: /KillAll
* Created a new restore point

Rootkit driver pe386 is present. … attempting disinfection
pe386 …… driver unloaded successfully.
ADS removed - system32: deleted 65568 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Documents and Settings\All Users.\documents\settings
C:\Documents and Settings\All Users.\documents\settings\bot.dll
C:\Documents and Settings\All Users.\documents\settings\desktop.ini
C:\Documents and Settings\All Users.\documents\settings\partnership.dll
C:\Documents and Settings\All Users.\documents\settings\winsys2f.dll
C:\WINDOWS\Casino.ico
C:\WINDOWS\comdlj32.dll
C:\WINDOWS\system32\1.txt
C:\WINDOWS\system32\2.txt
C:\WINDOWS\system32\kernels8.exe
C:\WINDOWS\system32\rpcc.dll
C:\WINDOWS\system32\spoolsvv.exe
C:\WINDOWS\system32\spoolsvv.sys


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_NTIO256
——-\Driver
——-\MZU_RK


((((((((((((((((((((((((( Files Created from 2007-07-18 to 2007-08-18 )))))))))))))))))))))))))))))))


2007-08-18 23:39 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-18 10:22 90,112 –a—— C:\WINDOWS\system32\RegDACL.exe
2007-08-18 10:22 9,006 –a—— C:\clean.bat
2007-08-18 10:22 53,248 –a—— C:\WINDOWS\system32\process.exe
2007-08-18 10:22 4,096 –a—— C:\WINDOWS\system32\reboot.exe
2007-08-14 16:18 229,376 –a—— C:\DOCUME~1\LOCALS~1\ntuser.dat
2007-08-11 23:13 d——– C:\DOCUME~1\user\APPLIC~1\Creative
2007-08-11 22:48 6,758,400 –a—— C:\DOCUME~1\user\ntuser.dat
2007-08-11 22:20 41,984 ——— C:\WINDOWS\Ctregrun.exe
2007-08-11 22:17 44,032 ——— C:\WINDOWS\system32\CTSVCCDA.EXE
2007-08-11 22:17 25,088 ——— C:\WINDOWS\system32\CTSVCCTL.EXE
2007-08-11 22:17 d–h—– C:\Program Files\Creative Installation Information
2007-08-11 22:17 d——– C:\Program Files\Common Files\Creative
2007-08-11 22:16 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Creative
2007-08-11 22:15 d——– C:\Program Files\Creative
2007-08-03 00:59 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nexon


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-18 13:42 ——— d——– C:\Program Files\FlashGet
2007-08-18 13:13 ——— d——– C:\Program Files\mIRC
2007-08-18 11:43 ——— d——– C:\Program Files\Warcraft III
2007-08-18 00:25 ——— d——– C:\Program Files\NJStar Communicator
2007-08-17 20:54 7168 –a—— C:\WINDOWS\comdlj32(2)(2).dll
2007-08-11 22:21 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-07-28 21:19 ——— d——– C:\Program Files\Opera
2007-07-17 20:52 ——— d——– C:\DOCUME~1\user\APPLIC~1\Hamachi
2007-07-17 20:29 25544 –a—— C:\WINDOWS\system32\drivers\hamachi.sys
2007-07-17 20:25 ——— d——– C:\Program Files\Hamachi
2007-06-30 00:34 ——— d——– C:\Program Files\WIZET
2007-03-27 15:35 774144 –a—— C:\Program Files\RngInterstitial.dll
2005-10-09 17:32 29 –a—— C:\Program Files\PaintBox.sbd
2005-10-09 17:32 15182 –a—— C:\Program Files\PaintBox.rfp
2005-09-09 07:20 1613824 –a—— C:\Program Files\PaintBox.exe
2005-07-31 10:36 377 –a—— C:\Program Files\readme.txt
2005-06-05 15:57 82934272 –a—— C:\Program Files\upi10_ustbyb.exe
2005-06-02 20:26 11014144 –a—— C:\Program Files\UGA5TBYB_E_USG.exe
2004-07-22 10:51 3432656 –a—— C:\Program Files\ManagedDX.CAB
2004-07-19 22:58 1156363 –a—— C:\Program Files\BDANT.cab
2004-07-19 22:53 976020 –a—— C:\Program Files\BDAXP.cab
2004-07-09 14:17 13265040 –a—— C:\Program Files\dxnt.cab
2004-07-09 09:13 703080 –a—— C:\Program Files\BDA.cab
2004-07-09 09:13 15493481 –a—— C:\Program Files\DirectX.cab
2004-01-29 15:50 17280 –a—— C:\Program Files\SETUP.LST
2004-01-29 15:40 1533663 –a—— C:\Program Files\dogwaffle.ex_
2004-01-27 17:49 47473 –a—— C:\Program Files\Splash.jp_
2004-01-07 11:00 5718 –a—— C:\Program Files\Grid_pm.ex_
2004-01-03 12:28 3276 –a—— C:\Program Files\ExploreTempDir_pm.ex_
2004-01-02 22:59 23230 –a—— C:\Program Files\Drpaint.dl_
2003-12-20 14:49 4287 –a—— C:\Program Files\Sepia_pf.ex_
2003-12-20 12:48 389 –a—— C:\Program Files\Def_Res.tx_
2003-11-29 15:47 23514 –a—— C:\Program Files\Store_Alpha_pm.ex_
2003-11-25 13:25 16674 –a—— C:\Program Files\Zoom_pf.ex_
2003-11-13 13:15 5053 –a—— C:\Program Files\Key_Shrink_pb.ex_
2003-11-13 12:48 5545 –a—— C:\Program Files\Key_Grow_pb.ex_
2003-11-04 12:22 17663 –a—— C:\Program Files\drbrush.dl_
2003-11-04 10:45 45953 –a—— C:\Program Files\drfilter.dl_
2003-10-28 07:43 4058 –a—— C:\Program Files\antique2.gr_
2003-10-28 07:42 3942 –a—— C:\Program Files\antique1.gr_
2003-10-27 08:53 1363 –a—— C:\Program Files\DogWeb.ht_
2003-10-26 10:36 2467 –a—— C:\Program Files\Keyboard_Document.rt_
2003-10-26 10:15 13880 –a—— C:\Program Files\drFloodfill.dl_
2003-10-25 12:15 512 –a—— C:\Program Files\TabletSupport.rt_
2003-10-17 11:49 25398 –a—— C:\Program Files\Thumb_Book.gi_
2003-10-06 19:07 23758 –a—— C:\Program Files\screenshot2-300.jp_
2003-06-23 20:49 13491 –a—— C:\Program Files\WinterBranches.op_
2003-06-23 20:42 12712 –a—— C:\Program Files\Grass.op_
2003-06-22 19:10 12008 –a—— C:\Program Files\Garland.op_
2003-06-22 16:33 12575 –a—— C:\Program Files\DogWillow.op_
2003-06-05 21:01 97631 –a—— C:\Program Files\VBTablet.dl_
2003-05-01 22:50 12113 –a—— C:\Program Files\Fancyful.op_
2003-05-01 22:44 12118 –a—— C:\Program Files\Hivey.op_
2003-05-01 22:40 12121 –a—— C:\Program Files\Brainy.op_
2003-05-01 22:37 12178 –a—— C:\Program Files\Spiro.op_
2002-12-29 14:29 3913 –a—— C:\Program Files\ChangeDPI_px.ex_
2002-11-13 16:34 243 –a—— C:\Program Files\ReadMe.tx_
2002-11-10 14:13 5499 –a—— C:\Program Files\Clipboard_Import_pb.ex_
2002-11-03 12:33 6796 –a—— C:\Program Files\Paint_on_alpha_pm.ex_
2002-11-03 12:24 3826 –a—— C:\Program Files\printerPrefs_generic_px.ex_
2002-11-01 14:13 3676 –a—— C:\Program Files\KeyToLuminance_pb.ex_
2002-11-01 14:11 3383 –a—— C:\Program Files\KeyInvert_pb.ex_
2002-11-01 14:10 3675 –a—— C:\Program Files\KeyToBlack_pb.ex_
2002-10-08 15:06 3188 –a—— C:\Program Files\Skys.gr_
2002-10-08 14:53 4885 –a—— C:\Program Files\Reds.gr_
2002-10-08 14:46 3435 –a—— C:\Program Files\Vents.gr_
2002-10-08 14:42 2895 –a—— C:\Program Files\Warnings.gr_
2002-10-08 14:33 3969 –a—— C:\Program Files\GunMetals.gr_
2002-09-23 11:29 10655 –a—— C:\Program Files\MotionBlur_pf.ex_
2002-09-20 04:40 10701 –a—— C:\Program Files\print_generic_px.ex_
2002-09-20 04:11 4207 –a—— C:\Program Files\ScaleAlpha_pm.ex_
2002-09-05 04:01 7260 –a—— C:\Program Files\Store_Brush_pb.ex_
2002-09-05 02:44 12899 –a—— C:\Program Files\Store_Buffer_pm.ex_
2002-09-03 04:27 5735 –a—— C:\Program Files\Clipboard_Export_pb.ex_
2002-08-23 04:04 66779 –a—— C:\Program Files\def_mdiform_bitmap.jp_
2002-08-21 08:41 17460 –a—— C:\Program Files\Def_Wallpaper.bm_
2002-08-09 06:44 520 –a—— C:\Program Files\Test1.w_
2002-03-29 12:00 520 –a—— C:\Program Files\Study.w_
2002-03-29 11:45 469 –a—— C:\Program Files\Earthy.w_
2002-02-12 04:45 1745 –a—— C:\Program Files\readme.rt_
2002-02-09 07:53 4837 –a—— C:\Program Files\AverageFrames_pm.ex_
2002-02-08 11:06 4986 –a—— C:\Program Files\FrameFromClipboard_pm.ex_
2002-01-30 08:24 12268 –a—— C:\Program Files\Pine_Branches.op_
2002-01-30 08:18 12270 –a—— C:\Program Files\Trees.op_
2002-01-30 08:08 11613 –a—— C:\Program Files\Brocolly_Trails.op_
2002-01-25 13:36 4462 –a—— C:\Program Files\cellular_pf.ex_
2002-01-24 18:25 4981 –a—— C:\Program Files\Mysticvision_pf.ex_
2002-01-24 18:20 4409 –a—— C:\Program Files\Minimize_pf.ex_
2002-01-24 18:19 4619 –a—— C:\Program Files\Maximize_pf.ex_
2002-01-22 17:18 4697 –a—— C:\Program Files\Crystalize_pf.ex_
2002-01-21 04:37 5287 –a—— C:\Program Files\iff_px.ex_
2002-01-21 03:42 5684 –a—— C:\Program Files\Median_pf.ex_
2001-12-31 07:17 66388 –a—— C:\Program Files\Artmap.da_
2001-08-14 18:35 11040 –a—— C:\Program Files\copying.tx_
2001-07-13 03:22 22094 –a—— C:\Program Files\DR_BUTTON_CONTROLL.OC_
2001-07-13 03:00 15303 –a—— C:\Program Files\HPROP.OC_
2001-06-13 00:02 23327 –a—— C:\Program Files\DR_MX_BUTTON_CONTROLL.OC_
2001-06-11 02:54 4987 –a—— C:\Program Files\OptimizedPaletteTest_pf.ex_
2001-06-11 02:45 5536 –a—— C:\Program Files\12_bit_dither_pf.ex_
2001-06-09 07:20 422 –a—— C:\Program Files\GoldenAge_well.w_
2006-03-06 12:00:28 61,952 –sh–r C:\WINDOWS\win32ssr.exe
2002-08-28 19:41:24 226,816 –sh–r C:\WINDOWS\system32\MNSQ.exe
2002-08-28 19:41:24 118,784 –sh–r C:\WINDOWS\system32\scorti.exe
2002-08-28 19:41:24 247,808 –sh–r C:\WINDOWS\system32\servza.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SDetect.exe"="C:\WINDOWS\Twain_32\ScanWiz5\SDetect.exe" [2000-02-25 13:57]
"SoundMan"="SOUNDMAN.EXE" [2004-09-16 20:39 C:\WINDOWS\SOUNDMAN.EXE]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-01-22 08:51]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-04-17 12:41]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 06:07]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-05-24 19:02]
"Ulead AutoDetector v2"="C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe" [2004-08-27 19:22]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"RegSvr32"="C:\WINDOWS\System32\msmsgs.exe" []
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2005-11-16 03:31]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2006-08-11 21:43]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2006-08-11 21:43]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2006-10-01 13:03]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-06-12 14:32]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runservices]
"Compaq Service Drivers"=winsvcs.exe

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Compaq Service Drivers"=winsvcs.exe

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06]
EPSON Status Monitor 3 Environment Check 2.lnk - C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2005-03-07 17:43:27]
Image Transfer.lnk - C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe [2005-01-17 19:55:57]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-18 04:05:56]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{7A7E6D97-B492-4884-9ABB-C31281DCC4F2}"= C:\WINDOWS\q277796.dll [2005-10-12 16:20 70144]
"{B29BE267-3A64-4F7E-8A57-75FB5E900506}"= C:\WINDOWS\system32\hk.dll [2006-04-06 00:44 52256]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cfgmngr32]
C:\WINDOWS\system32\hk.dll 2006-04-06 00:44 52256 C:\WINDOWS\system32\hk.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\style32]
C:\WINDOWS\q277796.dll 2005-10-12 16:20 70144 C:\WINDOWS\q277796.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BootWarn]
C:\Program Files\Norton AntiVirus\BootWarn.exe /a

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NAV CfgWiz]
"C:\Program Files\Norton AntiVirus\CfgWiz.exe" /GUID {0D7956A2-5A08-4ec2-A72C-DF8495A66016} /MODE CfgWiz /CMDLINE "REBOOT"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSC_UserPrompt]
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe

S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;C:\WINDOWS\System32\DRIVERS\ADM8511.SYS
S3 dump_wmimmc;dump_wmimmc;\??\C:\Program Files\WIZET\MapleStory\GameGuard\dump_wmimmc.sys
S3 GMSIPCI;GMSIPCI;\??\D:\INSTALL\GMSIPCI.SYS
S3 sonypvs1;Sony Digital Imaging Video2;C:\WINDOWS\System32\DRIVERS\sonypvs1.sys
S3 XTrapD12;XTrapD12;\??\C:\WINDOWS\System32\XTrapD12.sys
S4 Win32Sr;Win32Sr;"C:\WINDOWS\win32ssr.exe"

*Newly Created Service* - NTIO256

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-18 23:57:18
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

C:\WINDOWS\system32\protector.exe [1668] 0x81DAB530


scanning hidden autostart entries …

scanning hidden files …

C:\WINDOWS\system32\protector.exe
C:\WINDOWS\system32\ntio256.sys

scan completed successfully
hidden files: 2

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ntio256]
"ImagePath"="\??\C:\WINDOWS\System32\ntio256.sys"

Completion time: 2007-08-18 23:59:05 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-08-18 23:58

— E O F —
the new HJT logfile requested.

Logfile of HijackThis v1.99.1
Scan saved at 00:02:07, on 19/08/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\UAService7.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\user\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.maplesea.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O4 - HKLM\..\Run: [SDetect.exe] C:\WINDOWS\Twain_32\ScanWiz5\SDetect.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RegSvr32] C:\WINDOWS\System32\msmsgs.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Image Transfer.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Add to AMV Convert Tool… - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\user\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by24fd.bay24.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1123676113109
O16 - DPF: {7606693A-C18D-4567-AF85-6194FF70761E} (GomWeb Control) - http://app.ipop.co.kr/gom/GomWeb.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/gamedownlo…GPlugin9USA.cab
O16 - DPF: {D0FD5E32-CABD-4A6E-BD0F-94ACE89CCE03} (HGPluginJP23 Class) - http://down.hangame.co.jp/jp/dist/hgstart/HGPluginJP23.cab
O18 - Protocol hijack: http - {7PHANMH5-HW{PH11GE-8{PH-00HAIH4{PH0M}
O18 - Protocol hijack: its - >IT14H2N1HBIH8-1HT0GAIT{-H000H8IH49PH}
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL (file missing)
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL (file missing)
O18 - Protocol hijack: tv - {HBIH08PH-MG4I-11H2-MHDIH00PH4MGBIT6P}
O18 - Protocol hijack: wia - >I3{3HANMH9IH7-4H0MGAI76-H2NMHAIHW{PH}
O20 - Winlogon Notify: cfgmngr32 - C:\WINDOWS\system32\hk.dll
O20 - Winlogon Notify: style32 - C:\WINDOWS\q277796.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\System32\UAService7.exe
A. Please RUN HijackThis
  • Click the SCAN button to produce a log.

  • Place a check mark beside each one of the following items:

    O18 - Protocol hijack: http - {7PHANMH5-HW{PH11GE-8{PH-00HAIH4{PH0M}
    O18 - Protocol hijack: its - >IT14H2N1HBIH8-1HT0GAIT{-H000H8IH49PH}
    O18 - Protocol hijack: tv - {HBIH08PH-MG4I-11H2-MHDIH00PH4MGBIT6P}



  • Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window.
B. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

http://forums.tomcoyote.org/Help_Please_t82361.html&pid=395540#entry395540

Collect::
C:\WINDOWS\comdlj32(2)(2).dll
C:\Program Files\PaintBox.sbd
C:\Program Files\PaintBox.rfp
C:\Program Files\PaintBox.exe
C:\Program Files\dogwaffle.ex_
C:\Program Files\Splash.jp_
C:\Program Files\Grid_pm.ex_
C:\Program Files\ExploreTempDir_pm.ex_
C:\Program Files\Drpaint.dl_
C:\Program Files\Sepia_pf.ex_
C:\Program Files\Def_Res.tx_
C:\Program Files\Store_Alpha_pm.ex_
C:\Program Files\Zoom_pf.ex_
C:\Program Files\Key_Shrink_pb.ex_
C:\Program Files\Key_Grow_pb.ex_
C:\Program Files\drbrush.dl_
C:\Program Files\drfilter.dl_
C:\Program Files\antique2.gr_
C:\Program Files\antique1.gr_
C:\Program Files\DogWeb.ht_
C:\Program Files\Keyboard_Document.rt_
C:\Program Files\drFloodfill.dl_
C:\Program Files\TabletSupport.rt_
C:\Program Files\Thumb_Book.gi_
C:\Program Files\screenshot2-300.jp_
C:\Program Files\WinterBranches.op_
C:\Program Files\Grass.op_
C:\Program Files\Garland.op_
C:\Program Files\DogWillow.op_
C:\Program Files\VBTablet.dl_
C:\Program Files\Fancyful.op_
C:\Program Files\Hivey.op_
C:\Program Files\Brainy.op_
C:\Program Files\Spiro.op_
C:\Program Files\ChangeDPI_px.ex_
C:\Program Files\ReadMe.tx_
C:\Program Files\Clipboard_Import_pb.ex_
C:\Program Files\Paint_on_alpha_pm.ex_
C:\Program Files\printerPrefs_generic_px.ex_
C:\Program Files\KeyToLuminance_pb.ex_
C:\Program Files\KeyInvert_pb.ex_
C:\Program Files\KeyToBlack_pb.ex_
C:\Program Files\Skys.gr_
C:\Program Files\Reds.gr_
C:\Program Files\Vents.gr_
C:\Program Files\Warnings.gr_
C:\Program Files\GunMetals.gr_
C:\Program Files\MotionBlur_pf.ex_
C:\Program Files\print_generic_px.ex_
C:\Program Files\ScaleAlpha_pm.ex_
C:\Program Files\Store_Brush_pb.ex_
C:\Program Files\Store_Buffer_pm.ex_
C:\Program Files\Clipboard_Export_pb.ex_
C:\Program Files\def_mdiform_bitmap.jp_
C:\Program Files\Def_Wallpaper.bm_
C:\Program Files\Test1.w_
C:\Program Files\Study.w_
C:\Program Files\Earthy.w_
C:\Program Files\readme.rt_
C:\Program Files\AverageFrames_pm.ex_
C:\Program Files\FrameFromClipboard_pm.ex_
C:\Program Files\Pine_Branches.op_
C:\Program Files\Trees.op_
C:\Program Files\Brocolly_Trails.op_
C:\Program Files\cellular_pf.ex_
C:\Program Files\Mysticvision_pf.ex_
C:\Program Files\Minimize_pf.ex_
C:\Program Files\Maximize_pf.ex_
C:\Program Files\Crystalize_pf.ex_
C:\Program Files\iff_px.ex_
C:\Program Files\Median_pf.ex_
C:\Program Files\Artmap.da_
C:\Program Files\copying.tx_
C:\Program Files\DR_BUTTON_CONTROLL.OC_
C:\Program Files\HPROP.OC_
C:\Program Files\DR_MX_BUTTON_CONTROLL.OC_
C:\Program Files\OptimizedPaletteTest_pf.ex_
C:\Program Files\12_bit_dither_pf.ex_
C:\Program Files\GoldenAge_well.w_
C:\WINDOWS\win32ssr.exe
C:\WINDOWS\system32\MNSQ.exe
C:\WINDOWS\system32\scorti.exe
C:\WINDOWS\system32\servza.exe
C:\WINDOWS\System32\msmsgs.exe
C:\Windows\Services32\winsvcs.exe
C:\WINDOWS\q277796.dll
C:\WINDOWS\system32\hk.dll
C:\WINDOWS\win32ssr.exe
C:\WINDOWS\System32\XTrapD12.sys

Folder::
C:\Program Files\WIZET

Rootkit::
C:\WINDOWS\system32\protector.exe
C:\WINDOWS\system32\ntio256.sys

Driver::
Win32Sr
NTIO256
XTrapD12
dump_wmimmc

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RegSvr32"=-
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runservices]
"Compaq Service Drivers"=-
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Compaq Service Drivers"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{7A7E6D97-B492-4884-9ABB-C31281DCC4F2}"=- 
"{B29BE267-3A64-4F7E-8A57-75FB5E900506}"=-
[-HKEY_CLASSES_ROOT\CLSID\{7A7E6D97-B492-4884-9ABB-C31281DCC4F2}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{7A7E6D97-B492-4884-9ABB-C31281DCC4F2}]
 [-HKEY_CLASSES_ROOT\CLSID\{B29BE267-3A64-4F7E-8A57-75FB5E900506}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{B29BE267-3A64-4F7E-8A57-75FB5E900506}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cfgmngr32]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\style32]
[-HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ntio256]

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. Additonally, ComboFix will generate the following files on your desktop
  • A zipped file on your desktop called Submit [Date Time].zip
  • And another file named - CF-Submit.htm
6. ComboFix may need to reboot to finish its work. Let it.

7. When CF has finished running, it will generate the ComboFix.log which will appear on your screen.

8. Next, a window will popup prompting you to "Submit Files for further analysis". Click "OK"

9. Your system's browser will automatically respond by loading the CF-Submit.htm file and open a window :
  • Click the "Browse" button and locate the Submit [Date Time].zip file on your desktop.
  • Click on the file to Select it.
  • Submit the file by clicking "OK"
10. Once the file has been submitted, you may DELETE both files on your desktop.

11. Post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
Combofix log

ComboFix 07-08-17.2 - "user" 2007-08-19 11:16:07.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.1.1252.1.1033.18.313 [GMT 8:00]
Command switches used :: C:\Documents and Settings\user\Desktop\CFScript.txt
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\12_bit_dither_pf.ex_
C:\Program Files\antique1.gr_
C:\Program Files\antique2.gr_
C:\Program Files\Artmap.da_
C:\Program Files\AverageFrames_pm.ex_
C:\Program Files\Brainy.op_
C:\Program Files\Brocolly_Trails.op_
C:\Program Files\cellular_pf.ex_
C:\Program Files\ChangeDPI_px.ex_
C:\Program Files\Clipboard_Export_pb.ex_
C:\Program Files\Clipboard_Import_pb.ex_
C:\Program Files\copying.tx_
C:\Program Files\Crystalize_pf.ex_
C:\Program Files\def_mdiform_bitmap.jp_
C:\Program Files\Def_Res.tx_
C:\Program Files\Def_Wallpaper.bm_
C:\Program Files\dogwaffle.ex_
C:\Program Files\DogWeb.ht_
C:\Program Files\DogWillow.op_
C:\Program Files\DR_BUTTON_CONTROLL.OC_
C:\Program Files\DR_MX_BUTTON_CONTROLL.OC_
C:\Program Files\drbrush.dl_
C:\Program Files\drfilter.dl_
C:\Program Files\drFloodfill.dl_
C:\Program Files\Drpaint.dl_
C:\Program Files\Earthy.w_
C:\Program Files\ExploreTempDir_pm.ex_
C:\Program Files\Fancyful.op_
C:\Program Files\FrameFromClipboard_pm.ex_
C:\Program Files\Garland.op_
C:\Program Files\GoldenAge_well.w_
C:\Program Files\Grass.op_
C:\Program Files\Grid_pm.ex_
C:\Program Files\GunMetals.gr_
C:\Program Files\Hivey.op_
C:\Program Files\HPROP.OC_
C:\Program Files\iff_px.ex_
C:\Program Files\Key_Grow_pb.ex_
C:\Program Files\Key_Shrink_pb.ex_
C:\Program Files\Keyboard_Document.rt_
C:\Program Files\KeyInvert_pb.ex_
C:\Program Files\KeyToBlack_pb.ex_
C:\Program Files\KeyToLuminance_pb.ex_
C:\Program Files\Maximize_pf.ex_
C:\Program Files\Median_pf.ex_
C:\Program Files\Minimize_pf.ex_
C:\Program Files\MotionBlur_pf.ex_
C:\Program Files\Mysticvision_pf.ex_
C:\Program Files\OptimizedPaletteTest_pf.ex_
C:\Program Files\Paint_on_alpha_pm.ex_
C:\Program Files\PaintBox.exe
C:\Program Files\PaintBox.rfp
C:\Program Files\PaintBox.sbd
C:\Program Files\Pine_Branches.op_
C:\Program Files\print_generic_px.ex_
C:\Program Files\printerPrefs_generic_px.ex_
C:\Program Files\readme.rt_
C:\Program Files\ReadMe.tx_
C:\Program Files\Reds.gr_
C:\Program Files\ScaleAlpha_pm.ex_
C:\Program Files\screenshot2-300.jp_
C:\Program Files\Sepia_pf.ex_
C:\Program Files\Skys.gr_
C:\Program Files\Spiro.op_
C:\Program Files\Splash.jp_
C:\Program Files\Store_Alpha_pm.ex_
C:\Program Files\Store_Brush_pb.ex_
C:\Program Files\Store_Buffer_pm.ex_
C:\Program Files\Study.w_
C:\Program Files\TabletSupport.rt_
C:\Program Files\Test1.w_
C:\Program Files\Thumb_Book.gi_
C:\Program Files\Trees.op_
C:\Program Files\VBTablet.dl_
C:\Program Files\Vents.gr_
C:\Program Files\Warnings.gr_
C:\Program Files\WinterBranches.op_
C:\Program Files\WIZET
C:\Program Files\WIZET\MapleStory\Base.wz
C:\Program Files\WIZET\MapleStory\Canvas.dll
C:\Program Files\WIZET\MapleStory\Character.wz
C:\Program Files\WIZET\MapleStory\Effect.wz
C:\Program Files\WIZET\MapleStory\Etc.wz
C:\Program Files\WIZET\MapleStory\GameGuard.des
C:\Program Files\WIZET\MapleStory\GameGuard\GameGuard.ver
C:\Program Files\WIZET\MapleStory\GameGuard\GameMon.des
C:\Program Files\WIZET\MapleStory\GameGuard\MapleStorySG.ini
C:\Program Files\WIZET\MapleStory\GameGuard\npgg.erl
C:\Program Files\WIZET\MapleStory\GameGuard\npgg9x.des
C:\Program Files\WIZET\MapleStory\GameGuard\npggNT.des
C:\Program Files\WIZET\MapleStory\GameGuard\npgl.erl
C:\Program Files\WIZET\MapleStory\GameGuard\npgm.erl
C:\Program Files\WIZET\MapleStory\GameGuard\npgmup.des
C:\Program Files\WIZET\MapleStory\GameGuard\npgmup.des.new
C:\Program Files\WIZET\MapleStory\GameGuard\npgmup.erl
C:\Program Files\WIZET\MapleStory\GameGuard\npsc.des
C:\Program Files\WIZET\MapleStory\GameGuard\npsc.erl
C:\Program Files\WIZET\MapleStory\GameGuard\NPSCAN.DES
C:\Program Files\WIZET\MapleStory\GameGuard\Splash.jpg
C:\Program Files\WIZET\MapleStory\Gr2D_DX8.dll
C:\Program Files\WIZET\MapleStory\ijl15.dll
C:\Program Files\WIZET\MapleStory\Item.wz
C:\Program Files\WIZET\MapleStory\l3codeca.acm
C:\Program Files\WIZET\MapleStory\Map.wz
C:\Program Files\WIZET\MapleStory\MapleStory.exe
C:\Program Files\WIZET\MapleStory\MapleStorySG.ini
C:\Program Files\WIZET\MapleStory\Mob.wz
C:\Program Files\WIZET\MapleStory\Morph.wz
C:\Program Files\WIZET\MapleStory\NameSpace.dll
C:\Program Files\WIZET\MapleStory\Npc.wz
C:\Program Files\WIZET\MapleStory\npkcnt4.sys
C:\Program Files\WIZET\MapleStory\npkcrypt.dll
C:\Program Files\WIZET\MapleStory\npkcrypt.sys
C:\Program Files\WIZET\MapleStory\npkcrypt.vxd
C:\Program Files\WIZET\MapleStory\npkcusb.sys
C:\Program Files\WIZET\MapleStory\npkpdb.dll
C:\Program Files\WIZET\MapleStory\Patcher.exe
C:\Program Files\WIZET\MapleStory\PCOM.dll
C:\Program Files\WIZET\MapleStory\Quest.wz
C:\Program Files\WIZET\MapleStory\Reactor.wz
C:\Program Files\WIZET\MapleStory\ResMan.dll
C:\Program Files\WIZET\MapleStory\Setup.exe
C:\Program Files\WIZET\MapleStory\Shape2D.dll
C:\Program Files\WIZET\MapleStory\Skill.wz
C:\Program Files\WIZET\MapleStory\Sound.wz
C:\Program Files\WIZET\MapleStory\Sound_DX8.dll
C:\Program Files\WIZET\MapleStory\String.wz
C:\Program Files\WIZET\MapleStory\TamingMob.wz
C:\Program Files\WIZET\MapleStory\UI.wz
C:\Program Files\WIZET\MapleStory\WzFlashRenderer.dll
C:\Program Files\WIZET\MapleStory\ZLZ.dll
C:\Program Files\Zoom_pf.ex_
C:\WINDOWS\comdlj32(2)(2).dll
C:\WINDOWS\q277796.dll
C:\WINDOWS\system32\hk.dll
C:\WINDOWS\system32\MNSQ.exe
C:\WINDOWS\system32\ntio256.sys
C:\WINDOWS\system32\protector.exe
C:\WINDOWS\system32\scorti.exe
C:\WINDOWS\system32\servza.exe
C:\WINDOWS\win32ssr.exe


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_DUMP_WMIMMC
——-\LEGACY_NTIO256
——-\LEGACY_WIN32SR
——-\LEGACY_XTRAPD12
——-\Win32Sr
——-\XTrapD12


((((((((((((((((((((((((( Files Created from 2007-07-19 to 2007-08-19 )))))))))))))))))))))))))))))))


2007-08-18 23:39 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-18 10:22 90,112 –a—— C:\WINDOWS\system32\RegDACL.exe
2007-08-18 10:22 9,006 –a—— C:\clean.bat
2007-08-18 10:22 53,248 –a—— C:\WINDOWS\system32\process.exe
2007-08-18 10:22 4,096 –a—— C:\WINDOWS\system32\reboot.exe
2007-08-14 16:18 229,376 –a—— C:\DOCUME~1\LOCALS~1\ntuser.dat
2007-08-11 23:13 d——– C:\DOCUME~1\user\APPLIC~1\Creative
2007-08-11 22:48 6,758,400 –a—— C:\DOCUME~1\user\ntuser.dat
2007-08-11 22:20 41,984 ——— C:\WINDOWS\Ctregrun.exe
2007-08-11 22:17 44,032 ——— C:\WINDOWS\system32\CTSVCCDA.EXE
2007-08-11 22:17 25,088 ——— C:\WINDOWS\system32\CTSVCCTL.EXE
2007-08-11 22:17 d–h—– C:\Program Files\Creative Installation Information
2007-08-11 22:17 d——– C:\Program Files\Common Files\Creative
2007-08-11 22:16 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Creative
2007-08-11 22:15 d——– C:\Program Files\Creative
2007-08-03 00:59 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nexon


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-19 11:12 ——— d——– C:\Program Files\mIRC
2007-08-19 01:01 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-19 00:35 ——— d——– C:\Program Files\NJStar Communicator
2007-08-19 00:35 ——— d——– C:\Program Files\FlashGet
2007-08-18 11:43 ——— d——– C:\Program Files\Warcraft III
2007-07-28 21:19 ——— d——– C:\Program Files\Opera
2007-07-17 20:52 ——— d——– C:\DOCUME~1\user\APPLIC~1\Hamachi
2007-07-17 20:29 25544 –a—— C:\WINDOWS\system32\drivers\hamachi.sys
2007-07-17 20:25 ——— d——– C:\Program Files\Hamachi
2007-03-27 15:35 774144 –a—— C:\Program Files\RngInterstitial.dll
2005-07-31 10:36 377 –a—— C:\Program Files\readme.txt
2005-06-05 15:57 82934272 –a—— C:\Program Files\upi10_ustbyb.exe
2005-06-02 20:26 11014144 –a—— C:\Program Files\UGA5TBYB_E_USG.exe
2004-07-22 10:51 3432656 –a—— C:\Program Files\ManagedDX.CAB
2004-07-19 22:58 1156363 –a—— C:\Program Files\BDANT.cab
2004-07-19 22:53 976020 –a—— C:\Program Files\BDAXP.cab
2004-07-09 14:17 13265040 –a—— C:\Program Files\dxnt.cab
2004-07-09 09:13 703080 –a—— C:\Program Files\BDA.cab
2004-07-09 09:13 15493481 –a—— C:\Program Files\DirectX.cab
2004-01-29 15:50 17280 –a—— C:\Program Files\SETUP.LST
2001-06-09 07:18 4906 –a—— C:\Program Files\PaletteToWells_pm.ex_
2001-06-08 05:59 405 –a—— C:\Program Files\Daisys.w_
2001-06-07 04:56 371 –a—— C:\Program Files\OakBark.w_
2001-06-07 04:49 407 –a—— C:\Program Files\Africa.w_
2001-06-07 04:47 381 –a—— C:\Program Files\Sand.w_
2001-06-07 04:46 367 –a—— C:\Program Files\Sky.w_
2001-06-07 04:43 400 –a—— C:\Program Files\Valencia.w_
2001-06-07 04:35 366 –a—— C:\Program Files\ForestGreens.w_
2001-06-07 04:27 393 –a—— C:\Program Files\CloudySky.w_
2001-06-07 04:26 385 –a—— C:\Program Files\Pumpkin.w_
2001-06-07 04:23 382 –a—— C:\Program Files\Midnight.w_
2001-06-07 04:22 383 –a—— C:\Program Files\Countryside.w_
2001-06-06 12:06 5477 –a—— C:\Program Files\OptimizedPalette_pf.ex_
2001-05-27 16:33 4098 –a—— C:\Program Files\Gradient_To_VB_pm.ex_
2001-05-13 18:22 452 –a—— C:\Program Files\Def_well.w_
2001-04-25 23:33 8507 –a—— C:\Program Files\BEVELBOX.OC_
2001-04-18 16:33 4534 –a—— C:\Program Files\Metals.gr_
2001-04-18 01:48 3969 –a—— C:\Program Files\Def_Gradient.gr_
2001-04-08 11:33 5395 –a—— C:\Program Files\Globe_pf.ex_
2001-03-11 14:58 4090 –a—— C:\Program Files\Alpha_Grow_pm.ex_
2001-03-11 14:54 4108 –a—— C:\Program Files\Alpha_Shrink_pm.ex_
2001-02-09 14:57 4964 –a—— C:\Program Files\IM_MOD_RL_histogram_.dl_
2001-01-11 15:02 794624 –a—— C:\WINDOWS\inf\OTHER\AUDIO3D.DLL
2000-11-19 15:02 4605 –a—— C:\Program Files\Mirrage_pf.ex_
2000-11-19 14:55 5264 –a—— C:\Program Files\MaxMin_pf.ex_
2000-11-19 14:54 4737 –a—— C:\Program Files\Mosaic_pf.ex_
2000-11-19 14:35 6334 –a—— C:\Program Files\MinMax_pf.ex_
2000-11-05 08:54 4817 –a—— C:\Program Files\bmp_save_pb.ex_
2000-11-04 23:05 6253 –a—— C:\Program Files\bmp_load_pb.ex_
2000-05-22 00:00 315877 –a—— C:\Program Files\COMCTL32.OC_
1999-12-07 12:00 865616 –a—— C:\Program Files\MSVBVM50.dl_
1999-05-07 00:00 74707 –a—— C:\Program Files\COMDLG32.OC_
1998-11-03 10:45 48479 –a—— C:\Program Files\MsStkPrp.dl_
1998-06-24 00:00 117028 –a—— C:\Program Files\RICHTX32.OC_
1998-02-27 15:28 267 –a—— C:\Program Files\Close.IC_
1997-05-19 08:08 74553 –a—— C:\Program Files\AsycFilt.dl_
1997-05-19 08:08 7134 –a—— C:\Program Files\StdOle2.tl_
1997-05-19 08:08 67142 –a—— C:\Program Files\OlePro32.dl_
1997-05-19 08:08 320739 –a—— C:\Program Files\OleAut32.dl_
1997-03-05 17:11 73501 –a—— C:\Program Files\setup1.ex_
1997-01-16 00:00 89600 –a—— C:\Program Files\SETUP.EXE
1997-01-16 00:00 37850 –a—— C:\Program Files\ST5UNST.EX_
1997-01-16 00:00 16457 –a—— C:\Program Files\VB5StKit.dl_
1997-01-13 00:00 126780 –a—— C:\Program Files\RichEd32.dl_
1996-10-31 00:00 10146 –a—— C:\Program Files\ComCat.dl_
1996-08-21 00:00 15600 –a—— C:\Program Files\Ctl3d32.dl_
C:\StashIMAPI.bin


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SDetect.exe"="C:\WINDOWS\Twain_32\ScanWiz5\SDetect.exe" [2000-02-25 13:57]
"SoundMan"="SOUNDMAN.EXE" [2004-09-16 20:39 C:\WINDOWS\SOUNDMAN.EXE]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-01-22 08:51]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-04-17 12:41]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 06:07]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-05-24 19:02]
"Ulead AutoDetector v2"="C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe" [2004-08-27 19:22]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2005-11-16 03:31]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2006-08-11 21:43]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2006-08-11 21:43]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2006-10-01 13:03]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-06-12 14:32]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06]
EPSON Status Monitor 3 Environment Check 2.lnk - C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2005-03-07 17:43:27]
Image Transfer.lnk - C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe [2005-01-17 19:55:57]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-18 04:05:56]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BootWarn]
C:\Program Files\Norton AntiVirus\BootWarn.exe /a

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NAV CfgWiz]
"C:\Program Files\Norton AntiVirus\CfgWiz.exe" /GUID {0D7956A2-5A08-4ec2-A72C-DF8495A66016} /MODE CfgWiz /CMDLINE "REBOOT"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSC_UserPrompt]
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe

R3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;C:\WINDOWS\System32\DRIVERS\ADM8511.SYS
S3 GMSIPCI;GMSIPCI;\??\D:\INSTALL\GMSIPCI.SYS
S3 sonypvs1;Sony Digital Imaging Video2;C:\WINDOWS\System32\DRIVERS\sonypvs1.sys


**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-19 11:22:50
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-19 11:24:23 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-08-19 11:24
C:\ComboFix2.txt … 2007-08-18 23:59

— E O F —
HJT log

Logfile of HijackThis v1.99.1
Scan saved at 11:29:07, on 19/08/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\UAService7.exe
C:\WINDOWS\system32\notepad.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\user\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.maplesea.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O4 - HKLM\..\Run: [SDetect.exe] C:\WINDOWS\Twain_32\ScanWiz5\SDetect.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Image Transfer.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Add to AMV Convert Tool… - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\user\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by24fd.bay24.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1123676113109
O16 - DPF: {7606693A-C18D-4567-AF85-6194FF70761E} (GomWeb Control) - http://app.ipop.co.kr/gom/GomWeb.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/gamedownlo…GPlugin9USA.cab
O16 - DPF: {D0FD5E32-CABD-4A6E-BD0F-94ACE89CCE03} (HGPluginJP23 Class) - http://down.hangame.co.jp/jp/dist/hgstart/HGPluginJP23.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL (file missing)
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\System32\UAService7.exe
It is starting to look much better:

1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

http://forums.tomcoyote.org/Help_Please_t82361.html&pid=395540#entry395540

Collect::
C:\Program Files\Metals.gr_
C:\Program Files\Def_Gradient.gr_
C:\Program Files\Globe_pf.ex_
C:\Program Files\Alpha_Grow_pm.ex_
C:\Program Files\Alpha_Shrink_pm.ex_
C:\Program Files\IM_MOD_RL_histogram_.dl_
C:\Program Files\Mirrage_pf.ex_
C:\Program Files\MaxMin_pf.ex_
C:\Program Files\Mosaic_pf.ex_
C:\Program Files\MinMax_pf.ex_
C:\Program Files\bmp_save_pb.ex_
C:\Program Files\bmp_load_pb.ex_
C:\Program Files\COMCTL32.OC_
C:\Program Files\MSVBVM50.dl_
C:\Program Files\COMDLG32.OC_
C:\Program Files\MsStkPrp.dl_
C:\Program Files\RICHTX32.OC_
C:\Program Files\Close.IC_
C:\Program Files\AsycFilt.dl_
C:\Program Files\StdOle2.tl_
C:\Program Files\OlePro32.dl_
C:\Program Files\OleAut32.dl_
C:\Program Files\setup1.ex_
C:\Program Files\SETUP.EXE
C:\Program Files\ST5UNST.EX_
C:\Program Files\VB5StKit.dl_
C:\Program Files\RichEd32.dl_
C:\Program Files\ComCat.dl_
C:\Program Files\Ctl3d32.dl_

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. Additonally, ComboFix will generate the following files on your desktop
  • A zipped file on your desktop called Submit [Date Time].zip
  • And another file named - CF-Submit.htm
6. ComboFix may need to reboot to finish its work. Let it.

7. When CF has finished running, it will generate the ComboFix.log which will appear on your screen.

8. Next, a window will popup prompting you to "Submit Files for further analysis". Click "OK"

9. Your system's browser will automatically respond by loading the CF-Submit.htm file and open a window :
  • Click the "Browse" button and locate the Submit [Date Time].zip file on your desktop.
  • Click on the file to Select it.
  • Submit the file by clicking "OK"
10. Once the file has been submitted, you may DELETE both files on your desktop.

11. Post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
thanks alot of the quick response!

ComboFix 07-08-17.2 - "user" 2007-08-19 12:57:15.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.1.1252.1.1033.18.299 [GMT 8:00]
Command switches used :: C:\Documents and Settings\user\Desktop\CFScript.txt
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\Alpha_Grow_pm.ex_
C:\Program Files\Alpha_Shrink_pm.ex_
C:\Program Files\AsycFilt.dl_
C:\Program Files\bmp_load_pb.ex_
C:\Program Files\bmp_save_pb.ex_
C:\Program Files\Close.IC_
C:\Program Files\ComCat.dl_
C:\Program Files\COMCTL32.OC_
C:\Program Files\COMDLG32.OC_
C:\Program Files\Ctl3d32.dl_
C:\Program Files\Def_Gradient.gr_
C:\Program Files\Globe_pf.ex_
C:\Program Files\IM_MOD_RL_histogram_.dl_
C:\Program Files\MaxMin_pf.ex_
C:\Program Files\Metals.gr_
C:\Program Files\MinMax_pf.ex_
C:\Program Files\Mirrage_pf.ex_
C:\Program Files\Mosaic_pf.ex_
C:\Program Files\MsStkPrp.dl_
C:\Program Files\MSVBVM50.dl_
C:\Program Files\OleAut32.dl_
C:\Program Files\OlePro32.dl_
C:\Program Files\RichEd32.dl_
C:\Program Files\RICHTX32.OC_
C:\Program Files\SETUP.EXE
C:\Program Files\setup1.ex_
C:\Program Files\ST5UNST.EX_
C:\Program Files\StdOle2.tl_
C:\Program Files\VB5StKit.dl_


((((((((((((((((((((((((( Files Created from 2007-07-19 to 2007-08-19 )))))))))))))))))))))))))))))))


2007-08-19 11:40 d——– C:\Program Files\WIZET
2007-08-18 23:39 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-18 10:22 90,112 –a—— C:\WINDOWS\system32\RegDACL.exe
2007-08-18 10:22 9,006 –a—— C:\clean.bat
2007-08-18 10:22 53,248 –a—— C:\WINDOWS\system32\process.exe
2007-08-18 10:22 4,096 –a—— C:\WINDOWS\system32\reboot.exe
2007-08-14 16:18 229,376 –a—— C:\DOCUME~1\LOCALS~1\ntuser.dat
2007-08-11 23:13 d——– C:\DOCUME~1\user\APPLIC~1\Creative
2007-08-11 22:48 6,758,400 –a—— C:\DOCUME~1\user\ntuser.dat
2007-08-11 22:20 41,984 ——— C:\WINDOWS\Ctregrun.exe
2007-08-11 22:17 44,032 ——— C:\WINDOWS\system32\CTSVCCDA.EXE
2007-08-11 22:17 25,088 ——— C:\WINDOWS\system32\CTSVCCTL.EXE
2007-08-11 22:17 d–h—– C:\Program Files\Creative Installation Information
2007-08-11 22:17 d——– C:\Program Files\Common Files\Creative
2007-08-11 22:16 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Creative
2007-08-11 22:15 d——– C:\Program Files\Creative
2007-08-03 00:59 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nexon


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-19 11:40 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-19 11:31 ——— d——– C:\Program Files\mIRC
2007-08-19 00:35 ——— d——– C:\Program Files\NJStar Communicator
2007-08-19 00:35 ——— d——– C:\Program Files\FlashGet
2007-08-18 11:43 ——— d——– C:\Program Files\Warcraft III
2007-07-28 21:19 ——— d——– C:\Program Files\Opera
2007-07-17 20:52 ——— d——– C:\DOCUME~1\user\APPLIC~1\Hamachi
2007-07-17 20:29 25544 –a—— C:\WINDOWS\system32\drivers\hamachi.sys
2007-07-17 20:25 ——— d——– C:\Program Files\Hamachi
2007-03-27 15:35 774144 –a—— C:\Program Files\RngInterstitial.dll
2005-07-31 10:36 377 –a—— C:\Program Files\readme.txt
2005-06-05 15:57 82934272 –a—— C:\Program Files\upi10_ustbyb.exe
2005-06-02 20:26 11014144 –a—— C:\Program Files\UGA5TBYB_E_USG.exe
2004-07-22 10:51 3432656 –a—— C:\Program Files\ManagedDX.CAB
2004-07-19 22:58 1156363 –a—— C:\Program Files\BDANT.cab
2004-07-19 22:53 976020 –a—— C:\Program Files\BDAXP.cab
2004-07-09 14:17 13265040 –a—— C:\Program Files\dxnt.cab
2004-07-09 09:13 703080 –a—— C:\Program Files\BDA.cab
2004-07-09 09:13 15493481 –a—— C:\Program Files\DirectX.cab
2004-01-29 15:50 17280 –a—— C:\Program Files\SETUP.LST
2001-06-09 07:18 4906 –a—— C:\Program Files\PaletteToWells_pm.ex_
2001-06-08 05:59 405 –a—— C:\Program Files\Daisys.w_
2001-06-07 04:56 371 –a—— C:\Program Files\OakBark.w_
2001-06-07 04:49 407 –a—— C:\Program Files\Africa.w_
2001-06-07 04:47 381 –a—— C:\Program Files\Sand.w_
2001-06-07 04:46 367 –a—— C:\Program Files\Sky.w_
2001-06-07 04:43 400 –a—— C:\Program Files\Valencia.w_
2001-06-07 04:35 366 –a—— C:\Program Files\ForestGreens.w_
2001-06-07 04:27 393 –a—— C:\Program Files\CloudySky.w_
2001-06-07 04:26 385 –a—— C:\Program Files\Pumpkin.w_
2001-06-07 04:23 382 –a—— C:\Program Files\Midnight.w_
2001-06-07 04:22 383 –a—— C:\Program Files\Countryside.w_
2001-06-06 12:06 5477 –a—— C:\Program Files\OptimizedPalette_pf.ex_
2001-05-27 16:33 4098 –a—— C:\Program Files\Gradient_To_VB_pm.ex_
2001-05-13 18:22 452 –a—— C:\Program Files\Def_well.w_
2001-04-25 23:33 8507 –a—— C:\Program Files\BEVELBOX.OC_
2001-01-11 15:02 794624 –a—— C:\WINDOWS\inf\OTHER\AUDIO3D.DLL


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SDetect.exe"="C:\WINDOWS\Twain_32\ScanWiz5\SDetect.exe" [2000-02-25 13:57]
"SoundMan"="SOUNDMAN.EXE" [2004-09-16 20:39 C:\WINDOWS\SOUNDMAN.EXE]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-01-22 08:51]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-04-17 12:41]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 06:07]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-05-24 19:02]
"Ulead AutoDetector v2"="C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe" [2004-08-27 19:22]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2005-11-16 03:31]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2006-08-11 21:43]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2006-08-11 21:43]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2006-10-01 13:03]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-06-12 14:32]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06]
EPSON Status Monitor 3 Environment Check 2.lnk - C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2005-03-07 17:43:27]
Image Transfer.lnk - C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe [2005-01-17 19:55:57]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-18 04:05:56]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BootWarn]
C:\Program Files\Norton AntiVirus\BootWarn.exe /a

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NAV CfgWiz]
"C:\Program Files\Norton AntiVirus\CfgWiz.exe" /GUID {0D7956A2-5A08-4ec2-A72C-DF8495A66016} /MODE CfgWiz /CMDLINE "REBOOT"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSC_UserPrompt]
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe

R3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;C:\WINDOWS\System32\DRIVERS\ADM8511.SYS
S3 GMSIPCI;GMSIPCI;\??\D:\INSTALL\GMSIPCI.SYS
S3 sonypvs1;Sony Digital Imaging Video2;C:\WINDOWS\System32\DRIVERS\sonypvs1.sys


**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-19 13:02:12
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-19 13:02:49
C:\ComboFix-quarantined-files.txt … 2007-08-19 13:02
C:\ComboFix2.txt … 2007-08-19 11:24
C:\ComboFix3.txt … 2007-08-18 23:59

— E O F —

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI