C:\WINNT\SYSTEM32\DESK.CPL - (Microsoft Corporation [Ver = 5.00.2195.6601 | Size = 237328 bytes | Date = 06/19/2003 13:05 | Attr = ])
C:\WINNT\SYSTEM32\fax.cpl - (Microsoft Corporation [Ver = 5.00.2134.1 | Size = 31504 bytes | Date = 05/08/2001 06:00 | Attr = ])
C:\WINNT\SYSTEM32\hdwwiz.cpl - (Microsoft Corporation [Ver = 5.00.2134.1 | Size = 128272 bytes | Date = 05/08/2001 06:00 | Attr = ])
C:\WINNT\SYSTEM32\inetcpl.cpl - (Microsoft Corporation [Ver = 6.00.2600.0000 | Size = 294912 bytes | Date = 08/17/2001 22:43 | Attr = ])
C:\WINNT\SYSTEM32\intl.cpl - (Microsoft Corporation [Ver = 5.00.2134.1 | Size = 118032 bytes | Date = 05/08/2001 06:00 | Attr = ])
C:\WINNT\SYSTEM32\irprops.cpl - (Microsoft Corporation [Ver = 5.00.2167.1 | Size = 36112 bytes | Date = 05/08/2001 06:00 | Attr = ])
C:\WINNT\SYSTEM32\joy.cpl - (Microsoft Corporation [Ver = 5.1.2258.400 built by: Lab06_N(mmbuild) | Size = 327680 bytes | Date = 11/07/2000 15:16 | Attr = ])
C:\WINNT\SYSTEM32\jpicpl32.cpl - (Sun Microsystems, Inc. [Ver = 5.0.60.5 | Size = 49265 bytes | Date = 11/10/2005 12:03 | Attr = ])
C:\WINNT\SYSTEM32\main.cpl - (Microsoft Corporation [Ver = 5.00.2134.1 | Size = 122128 bytes | Date = 05/08/2001 06:00 | Attr = ])
C:\WINNT\SYSTEM32\mmsys.cpl - (Microsoft Corporation [Ver = 5.00.2161.1 | Size = 303888 bytes | Date = 05/08/2001 06:00 | Attr = ])
C:\WINNT\SYSTEM32\ncpa.cpl - (Microsoft Corporation [Ver = 5.00.2176.1 | Size = 17168 bytes | Date = 05/08/2001 06:00 | Attr = ])
C:\WINNT\SYSTEM32\nwc.cpl - (Microsoft Corporation [Ver = 5.00.2134.1 | Size = 41232 bytes | Date = 05/08/2001 06:00 | Attr = ])
C:\WINNT\SYSTEM32\odbccp32.cpl - (Microsoft Corporation [Ver = 3.520.6200.0 | Size = 41232 bytes | Date = 06/19/2003 13:05 | Attr = ])
C:\WINNT\SYSTEM32\powercfg.cpl - (Microsoft Corporation [Ver = 5.00.3502.6601 | Size = 90896 bytes | Date = 06/19/2003 13:05 | Attr = ])
C:\WINNT\SYSTEM32\prefscpl.cpl - (RealNetworks, Inc. [Ver = 6.0.9.573 | Size = 24576 bytes | Date = 11/25/2004 18:28 | Attr = ])
C:\WINNT\SYSTEM32\QuickTime.cpl - (Apple Computer, Inc. [Ver = 6.5 | Size = 323072 bytes | Date = 01/06/2004 16:02 | Attr = ])
C:\WINNT\SYSTEM32\sticpl.cpl - (Microsoft Corporation [Ver = 5.00.2195.6656 | Size = 83216 bytes | Date = 06/19/2003 13:05 | Attr = ])
C:\WINNT\SYSTEM32\SYSDM.CPL - (Microsoft Corporation [Ver = 5.00.2195.6601 | Size = 125712 bytes | Date = 06/19/2003 13:05 | Attr = ])
C:\WINNT\SYSTEM32\telephon.cpl - (Microsoft Corporation [Ver = 5.00.2143.1 | Size = 5904 bytes | Date = 05/08/2001 06:00 | Attr = ])
C:\WINNT\SYSTEM32\timedate.cpl - (Microsoft Corporation [Ver = 5.00.2137.1 | Size = 61200 bytes | Date = 05/08/2001 06:00 | Attr = ])
C:\WINNT\SYSTEM32\wuaucpl.cpl - (Microsoft Corporation [Ver = 5.8.0.2469 built by: lab01_n(wmbla) | Size = 174360 bytes | Date = 05/26/2005 03:16 | Attr = ])
C:\WINNT\SYSTEM32\dllcache\inetcpl.cpl - (Microsoft Corporation [Ver = 6.00.2600.0000 | Size = 294912 bytes | Date = 08/17/2001 22:43 | Attr = ])
C:\WINNT\SYSTEM32\dllcache\msmq.cpl - (Microsoft Corporation [Ver = 5.00.0748 | Size = 64784 bytes | Date = 01/12/2005 13:40 | Attr = ])
C:\WINNT\SYSTEM32\dllcache\mwcpa32.cpl - (IBM Corporation [Ver = 2.60.35.0 | Size = 94208 bytes | Date = 09/23/1999 18:44 | Attr = ])
C:\WINNT\SYSTEM32\dllcache\nwc.cpl - (Microsoft Corporation [Ver = 5.00.2134.1 | Size = 41232 bytes | Date = 05/08/2001 06:00 | Attr = ])
C:\WINNT\SYSTEM32\dllcache\wuaucpl.cpl - (Microsoft Corporation [Ver = 5.8.0.2469 built by: lab01_n(wmbla) | Size = 174360 bytes | Date = 05/26/2005 03:16 | Attr = ])
Auto-Start Folders
HKLM->Explorer\Shell Folders\\Common Startup = C:\Documents and Settings\All Users.WINNT\Start Menu\Programs\Startup
C:\Documents and Settings\All Users.WINNT\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc. [Ver = 1, 0, 0, 1 | Size = 113664 bytes | Date = 11/04/1999 14:06 | Attr = ])
C:\Documents and Settings\All Users.WINNT\Start Menu\Programs\Startup\EPSON CardMonitor.lnk - C:\Program Files\EPSON\EPSON CardMonitor\EPSON CardMonitor1.1.exe (SEIKO EPSON CORPORATION [Ver = 1.1.0.8 | Size = 258048 bytes | Date = 07/25/2003 01:00 | Attr = ])
C:\Documents and Settings\All Users.WINNT\Start Menu\Programs\Startup\Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation [Ver = 10.0.2609 | Size = 83360 bytes | Date = 02/13/2001 01:01 | Attr = ])
HKLM->Explorer\User Shell Folders\\Common Startup = %ALLUSERSPROFILE%\Start Menu\Programs\Startup
HKLM->Explorer\Shell Folders\\Startup = C:\Documents and Settings\Lawrence Luecke\Start Menu\Programs\Startup
HKCU->Explorer\User Shell Folders\\Startup = %USERPROFILE%\Start Menu\Programs\Startup
Miscellaneous Auto-Start Files
System.ini->[Boot]\\Shell - explorer.exe
Wininit.ini: Line 1 - [RENAME]
Wininit.ini: Line 2 - NUL=C:\DOCUME~1\LAWREN~1\LOCALS~1\Temp\nstmp\uninstall.exe
Wininit.ini: Line 3 - NUL=C:\DOCUME~1\LAWREN~1\LOCALS~1\Temp\nstmp\uninstall.ini
Wininit.ini: Line 4 - NUL=C:\DOCUME~1\LAWREN~1\LOCALS~1\Temp\nstmp
Config.nt: Line 54 - dos=high, umb
Config.nt: Line 55 - device=%SystemRoot%\system32\himem.sys
Config.nt: Line 56 - files=40
AutoExec.nt: Line 1 - @echo off
AutoExec.nt: Line 8 - lh %SystemRoot%\system32\mscdexnt.exe
AutoExec.nt: Line 11 - lh %SystemRoot%\system32\redir
AutoExec.nt: Line 14 - lh %SystemRoot%\system32\dosx
Miscellaneous Folders
AllUsers ApplicationData Folder
CurrentUser ApplicationData Folder
Program Files Folder
C:\Program Files\desktop.ini - ( [Ver = | Size = 271 bytes | Date = 01/27/2003 13:13 | Attr = H ])
C:\Program Files\folder.htt - ( [Ver = | Size = 21952 bytes | Date = 01/27/2003 13:13 | Attr = H ])
Common Files Folder
C:\Program Files\Common Files\tppupd2k.dll - (In-System Design, Inc. [Ver = 5.04.1150.0 | Size = 21866 bytes | Date = 10/05/2001 12:53 | Attr = ])
DPF files
{0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} - CKAVWebScan Object - CodeBase = http://www.kaspersky...can_unicode.cab
{215B8138-A3CF-44C5-803F-8226143CFC0A} - Trend Micro ActiveX Scan Agent 6.5 - CodeBase = http://housecall65.t...ivex/hcImpl.cab
{33564D57-0000-0010-8000-00AA00389B71} - - CodeBase = http://download.micr...922/wmv9VCM.CAB
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - MUWebControl Class - CodeBase = http://update.micros...b?1143225708926
{8AD9C840-044E-11D1-B3E9-00805F499D93} - Java Plug-in 1.5.0_06 - CodeBase = http://java.sun.com/...indows-i586.cab
{9A9307A0-7DA4-4DAF-B042-5009F29E09E1} - ActiveScan Installer Class - CodeBase = http://acs.pandasoft...free/asinst.cab
{9F1C11AA-197B-4942-BA54-47A8489BB47F} - - CodeBase = http://v4.windowsupd...AB?37850.515625
{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - Java Plug-in 1.5.0_06 - CodeBase = http://java.sun.com/...indows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - Java Plug-in 1.5.0_06 - CodeBase = http://java.sun.com/...indows-i586.cab
{D27CDB6E-AE6D-11CF-96B8-444553540000} - Shockwave Flash Object - CodeBase = http://fpdownload.ma...ash/swflash.cab
{F00F4763-7355-4725-82F7-0DA94A256D46} - IMDownloader Class - CodeBase = http://www2.incredim...er/imloader.cab
DirectAnimation Java Classes - - CodeBase = file://C:\WINNT\Java\classes\dajava.cab
Microsoft XML Parser for Java - - CodeBase = file://C:\WINNT\Java\classes\xmldso.cab
Hosts file = 0 bytes. Reading all entries. C:\WINNT\System32\drivers\etc\Hosts
< Add On's >
>>>>Output for AddOn file HKCU_IEDesktop.def<<<<
KEY - HKCU\Software\Microsoft\Internet Explorer\Desktop - Include SUBKEYS
HKCU\Software\Microsoft\Internet Explorer\Desktop -
Desktop\Components -
Desktop\Components\\DeskHtmlVersion - 272
Desktop\Components\\DeskHtmlMinorVersion - 3
Desktop\Components\\Settings - 1
Desktop\Components\\GeneralFlags - 1
Desktop\Components\0 -
Desktop\Components\0\\Source - About:Home
Desktop\Components\0\\SubscribedURL - About:Home
Desktop\Components\0\\FriendlyName - My Current Home Page
Desktop\Components\0\\Flags - 2
Desktop\Components\0\\Position - 2C 00 00 00 A0 00 00 00 00 00 00 00 80 02 00 00 3C 02 00 00 00 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00
Desktop\Components\0\\CurrentState - 1073741828
Desktop\Components\0\\OriginalStateInfo - 18 00 00 00 FF FF 00 00 FF FF 00 00 FF FF FF FF FF FF FF FF 04 00 00 00
Desktop\Components\0\\RestoredStateInfo - 18 00 00 00 10 03 00 00 1F 00 00 00 E0 00 00 00 D6 00 00 00 01 00 00 00
Desktop\General -
Desktop\General\\WallpaperFileTime - 00 00 00 00 00 00 00 00
Desktop\General\\WallpaperLocalFileTime - 00 90 65 B5 CD FF FF FF
Desktop\General\\ComponentsPositioned - 1
Desktop\General\\TileWallpaper - 0
Desktop\General\\WallpaperStyle - 2
Desktop\General\\Wallpaper -
Desktop\General\\BackupWallpaper -
Desktop\Old WorkAreas -
Desktop\Old WorkAreas\\NoOfOldWorkAreas - 1
Desktop\Old WorkAreas\\OldWorkAreaRects - 00 00 00 00 00 00 00 00 00 04 00 00 E4 02 00 00
Desktop\SafeMode -
Desktop\SafeMode\Components -
Desktop\SafeMode\Components\\DeskHtmlVersion - 272
Desktop\SafeMode\Components\\DeskHtmlMinorVersion - 3
Desktop\SafeMode\Components\\Settings - 1
Desktop\SafeMode\Components\\GeneralFlags - 0
Desktop\SafeMode\General -
Desktop\SafeMode\General\\Wallpaper - %SystemRoot%\Web\SafeMode.htt
Desktop\SafeMode\General\\VisitGallery - 0
Desktop\Scheme -
Desktop\Scheme\\Edit -
Desktop\Scheme\\Display - SafeMode
>>>>Output for AddOn file Policies.def<<<<
KEY - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies - Include SUBKEYS
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies -
policies\ActiveDesktop -
policies\ActiveDesktop\AdminComponent -
policies\explorer -
policies\explorer\run -
policies\NonEnum -
policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} - 1
policies\Ratings -
policies\system -
policies\system\\dontdisplaylastusername - 0
policies\system\\legalnoticecaption -
policies\system\\legalnoticetext -
policies\system\\shutdownwithoutlogon - 1
KEY - HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer - Include SUBKEYS
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer not found. -
KEY - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies - Include SUBKEYS
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies -
policies\Associations -
policies\Explorer -
policies\Explorer\\NoDriveTypeAutoRun - 149
policies\Explorer\Run -
policies\System -
policies\System\\DisableRegistryTools - 0
KEY - HKCU\SOFTWARE\Policies\Microsoft\Internet Explorer - Include SUBKEYS
HKCU\SOFTWARE\Policies\Microsoft\Internet Explorer -
Internet Explorer\Control Panel -
Internet Explorer\Control Panel\\Connwiz Admin Lock - 0
>>>>Output for AddOn file SID_Run_Policies.def<<<<
KEY - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run - No SUBKEYS
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run -
Run\\Ms Update WinServices NT/XP - winservnt32.exe
Run\\Ms Java for Windows NT - mguard.exe
Run\\ziiw - C:\PROGRA~1\COMMON~1\ziiw\ziiwm.exe
Run\\xqnyq - C:\WINNT\system32\cddgpq.exe reg_run
KEY - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run - No SUBKEYS
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run not found. -
KEY - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies - Include SUBKEYS
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies -
Policies\Explorer -
Policies\Explorer\\NoDriveTypeAutoRun - 149
KEY - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies - Include SUBKEYS
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies not found. -
< End of report >