If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.
»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Microsoft Windows XP Current Build: Service Pack 2 Current Build Number: 2600
Internet Explorer Version: 6.0.2900.2180
»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»
Checking %SystemDrive% folder...
UPX! 4/30/2005 2:10:22 PM 95744 C:\adlinstallwin32.exe
Checking %ProgramFilesDir% folder...
Checking %WinDir% folder...
SAHAgent 5/11/2005 5:12:04 PM 49664 C:\WINDOWS\3vjhr1g9.exe
PEC2 9/11/2005 10:27:24 AM 1440054 C:\WINDOWS\Alicia Keys.bmp
SAHAgent 6/8/2005 10:16:02 AM 50176 C:\WINDOWS\coqm8krf.exe
SAHAgent 6/8/2005 10:16:02 AM 50176 C:\WINDOWS\nvr1liqm.exe
aspack 7/15/2005 6:34:48 PM 38400 C:\WINDOWS\shop1004.exe
UPX! 7/16/2005 9:22:10 AM 45312 C:\WINDOWS\tct101.dll
UPX! 7/15/2005 6:31:46 PM 65024 C:\WINDOWS\thin-114-1-x-x.exe
UPX! 9/14/2005 6:28:42 PM 226536 C:\WINDOWS\whCC-GIANT.exe
Checking %System% folder...
UPX! 4/11/2005 3:17:10 PM 60928 C:\WINDOWS\SYSTEM32\1800414.dll
UPX! 4/11/2005 3:17:10 PM 60928 C:\WINDOWS\SYSTEM32\180621.dll
SAHAgent 5/18/2005 3:42:40 PM 35 C:\WINDOWS\SYSTEM32\3vjhr1g9.ini
UPX! 5/1/2005 6:47:56 PM 95744 C:\WINDOWS\SYSTEM32\adlinstallwin32.exe
UPX! 5/4/2005 1:00:44 PM 98816 C:\WINDOWS\SYSTEM32\better0503.dll
UPX! 5/4/2005 1:00:44 PM 98816 C:\WINDOWS\SYSTEM32\better621.dll
UPX! 6/2/2005 12:45:14 PM 37888 C:\WINDOWS\SYSTEM32\blizstarluck.dll
UPX! 4/18/2005 9:11:20 AM 168960 C:\WINDOWS\SYSTEM32\blizzard.dll
UPX! 4/18/2005 9:11:20 AM 168960 C:\WINDOWS\SYSTEM32\blizzard621.dll
UPX! 6/21/2005 4:45:02 PM 35328 C:\WINDOWS\SYSTEM32\captain.dll
aspack 9/11/2005 9:37:18 AM 197120 C:\WINDOWS\SYSTEM32\CiaraSS6.scr
SAHAgent 9/1/2005 2:04:26 PM 35 C:\WINDOWS\SYSTEM32\coqm8krf.ini
SAHAgent 10/4/2005 8:42:18 PM 3379 C:\WINDOWS\SYSTEM32\dcbctuaa.ini
UPX! 4/6/2005 12:23:56 PM 51712 C:\WINDOWS\SYSTEM32\delfin0414.dll
UPX! 4/6/2005 12:23:56 PM 51712 C:\WINDOWS\SYSTEM32\delfin621.dll
PEC2 8/18/2001 10:00:00 AM 41397 C:\WINDOWS\SYSTEM32\dfrg.msc
SAHAgent 5/11/2005 3:33:50 PM 30720 C:\WINDOWS\SYSTEM32\dr350o9m.exe
SAHAgent 9/1/2005 2:04:26 PM 35 C:\WINDOWS\SYSTEM32\dr350o9m.ini
69.59.186.63 10/4/2005 8:41:00 PM 133120 C:\WINDOWS\SYSTEM32\fkrml.dll
209.66.67.134 10/4/2005 8:41:00 PM 133120 C:\WINDOWS\SYSTEM32\fkrml.dll
web-nex 10/4/2005 8:41:00 PM 133120 C:\WINDOWS\SYSTEM32\fkrml.dll
winsync 10/4/2005 8:41:00 PM 133120 C:\WINDOWS\SYSTEM32\fkrml.dll
UPX! 5/13/2005 1:36:00 PM 66560 C:\WINDOWS\SYSTEM32\golden513.dll
UPX! 5/13/2005 1:36:00 PM 66560 C:\WINDOWS\SYSTEM32\golden621.dll
UPX! 4/6/2005 12:23:58 PM 61440 C:\WINDOWS\SYSTEM32\goldnew2b0414.dll
SAHAgent 5/11/2005 3:33:50 PM 30720 C:\WINDOWS\SYSTEM32\gsdbd6g4.exe
SAHAgent 5/18/2005 3:42:40 PM 35 C:\WINDOWS\SYSTEM32\gsdbd6g4.ini
SAHAgent 5/11/2005 3:33:50 PM 30720 C:\WINDOWS\SYSTEM32\gvhbr57h.exe
SAHAgent 9/14/2005 6:29:52 PM 35 C:\WINDOWS\SYSTEM32\gvhbr57h.ini
SAHAgent 6/17/2005 3:21:42 PM 204288 C:\WINDOWS\SYSTEM32\h8s7vs91.exe
SAHAgent 9/10/2005 4:33:46 PM 3534 C:\WINDOWS\SYSTEM32\h8s7vs91.ini
FSG! 3/30/2005 9:43:14 PM 398742 C:\WINDOWS\SYSTEM32\Iidtvtk1.xml
69.59.186.63 10/4/2005 8:40:58 PM 181760 C:\WINDOWS\SYSTEM32\iltcoic.dll
209.66.67.134 10/4/2005 8:40:58 PM 181760 C:\WINDOWS\SYSTEM32\iltcoic.dll
web-nex 10/4/2005 8:40:58 PM 181760 C:\WINDOWS\SYSTEM32\iltcoic.dll
winsync 10/4/2005 8:40:58 PM 181760 C:\WINDOWS\SYSTEM32\iltcoic.dll
69.59.186.63 9/6/2005 5:13:10 PM 10240 C:\WINDOWS\SYSTEM32\jeoab.dll
209.66.67.134 9/6/2005 5:13:10 PM 10240 C:\WINDOWS\SYSTEM32\jeoab.dll
web-nex 9/6/2005 5:13:10 PM 10240 C:\WINDOWS\SYSTEM32\jeoab.dll
winsync 9/6/2005 5:13:10 PM 10240 C:\WINDOWS\SYSTEM32\jeoab.dll
UPX! 8/16/2005 8:04:42 AM 121433 C:\WINDOWS\SYSTEM32\mc-110-12-0000079.exe
UPX! 5/25/2005 6:45:14 PM 119229 C:\WINDOWS\SYSTEM32\mc-58-12-0000079.exe
UPX! 6/26/2005 6:00:18 AM 20992 C:\WINDOWS\SYSTEM32\msclock32.dll
UPX! 8/22/2001 8:00:00 PM 193024 C:\WINDOWS\SYSTEM32\mskceo.dll
UPX! 8/22/2001 8:00:00 PM 209920 C:\WINDOWS\SYSTEM32\mskhhe.dll
UPX! 6/12/2005 10:01:52 AM 20992 C:\WINDOWS\SYSTEM32\msplock32.dll
UPX! 8/15/2005 6:56:46 PM 25105 C:\WINDOWS\SYSTEM32\MTE2ODM6ODoxNg.exe
aspack 8/4/2004 3:56:36 AM 708096 C:\WINDOWS\SYSTEM32\ntdll.dll
SAHAgent 9/14/2005 6:29:52 PM 35 C:\WINDOWS\SYSTEM32\nvr1liqm.ini
SAHAgent 5/11/2005 8:11:20 AM 202240 C:\WINDOWS\SYSTEM32\p6js2sqb.exe
SAHAgent 6/26/2005 11:38:32 AM 3517 C:\WINDOWS\SYSTEM32\p6js2sqb.ini
UPX! 5/24/2005 3:54:52 PM 73728 C:\WINDOWS\SYSTEM32\Qool.exe
qoologic 5/24/2005 3:54:52 PM 73728 C:\WINDOWS\SYSTEM32\Qool.exe
ad-beh 5/24/2005 3:54:52 PM 73728 C:\WINDOWS\SYSTEM32\Qool.exe
ad-behNior.com 5/24/2005 3:54:52 PM 73728 C:\WINDOWS\SYSTEM32\Qool.exe
KavSvc 5/24/2005 3:54:52 PM 73728 C:\WINDOWS\SYSTEM32\Qool.exe
69.59.186.63 5/24/2005 3:54:52 PM 73728 C:\WINDOWS\SYSTEM32\Qool.exe
209.66.67.134 5/24/2005 3:54:52 PM 73728 C:\WINDOWS\SYSTEM32\Qool.exe
66.63.167.97 5/24/2005 3:54:52 PM 73728 C:\WINDOWS\SYSTEM32\Qool.exe
66.63.167.77 5/24/2005 3:54:52 PM 73728 C:\WINDOWS\SYSTEM32\Qool.exe
yourkey 5/24/2005 3:54:52 PM 73728 C:\WINDOWS\SYSTEM32\Qool.exe
Umonitor 8/4/2004 3:56:44 AM 657920 C:\WINDOWS\SYSTEM32\rasdlg.dll
UPX! 6/21/2005 4:40:30 PM 36352 C:\WINDOWS\SYSTEM32\riverbelle.dll
abetterinternet.com 6/26/2005 11:34:36 AM 283774 C:\WINDOWS\SYSTEM32\saie.log
UPX! 3/30/2005 12:30:22 PM 125440 C:\WINDOWS\SYSTEM32\saie1108.exe
aspack 6/26/2005 10:11:48 AM 11292241 C:\WINDOWS\SYSTEM32\saie_kyf.dat
PTech 6/26/2005 10:11:48 AM 11292241 C:\WINDOWS\SYSTEM32\saie_kyf.dat
UPX! 4/11/2005 5:47:48 PM 22016 C:\WINDOWS\SYSTEM32\searchdll.dll
69.59.186.63 9/6/2005 5:13:10 PM 46080 C:\WINDOWS\SYSTEM32\sfksgss.dll
209.66.67.134 9/6/2005 5:13:10 PM 46080 C:\WINDOWS\SYSTEM32\sfksgss.dll
web-nex 9/6/2005 5:13:10 PM 46080 C:\WINDOWS\SYSTEM32\sfksgss.dll
winsync 9/6/2005 5:13:10 PM 46080 C:\WINDOWS\SYSTEM32\sfksgss.dll
UPX! 8/5/2005 10:04:38 PM 65024 C:\WINDOWS\SYSTEM32\thin-138-1-x-x.exe
UPX! 4/2/2005 9:36:08 AM 69120 C:\WINDOWS\SYSTEM32\tksrv99.exe
UPX! 4/2/2005 9:39:14 AM 143360 C:\WINDOWS\SYSTEM32\ucsi.exe
winsync 8/18/2001 10:00:00 AM 1309184 C:\WINDOWS\SYSTEM32\wbdbase.deu
Checking %System%\Drivers folder and sub-folders...
PTech 8/4/2004 1:41:38 AM 1309184 C:\WINDOWS\SYSTEM32\drivers\mtlstrm.sys
Items found in C:\WINDOWS\SYSTEM32\drivers\etc\HOSTS
Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
10/5/2005 5:28:04 PM S 2048 C:\WINDOWS\bootstat.dat
10/2/2005 3:31:08 PM HS 219136 C:\WINDOWS\Thumbs.db
10/3/2005 7:38:20 AM H 0 C:\WINDOWS\inf\oem45.inf
10/2/2005 10:55:16 PM RHS 286777 C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_10.cab
10/5/2005 5:30:14 PM H 1024 C:\WINDOWS\system32\config\default.LOG
10/5/2005 5:29:18 PM H 1024 C:\WINDOWS\system32\config\SAM.LOG
10/5/2005 5:29:48 PM H 1024 C:\WINDOWS\system32\config\SECURITY.LOG
10/5/2005 6:13:20 PM H 1024 C:\WINDOWS\system32\config\software.LOG
10/5/2005 6:13:20 PM H 1024 C:\WINDOWS\system32\config\system.LOG
10/5/2005 5:29:28 PM HS 192 C:\WINDOWS\Tasks\RUTASK.job
10/5/2005 5:28:12 PM H 6 C:\WINDOWS\Tasks\SA.DAT
Checking for CPL files...
Microsoft Corporation 8/4/2004 3:56:58 AM 68608 C:\WINDOWS\SYSTEM32\access.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 549888 C:\WINDOWS\SYSTEM32\appwiz.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 110592 C:\WINDOWS\SYSTEM32\bthprops.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 135168 C:\WINDOWS\SYSTEM32\desk.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 80384 C:\WINDOWS\SYSTEM32\firewall.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 155136 C:\WINDOWS\SYSTEM32\hdwwiz.cpl
Ahead Software AG 5/26/2003 7:12:14 AM 57344 C:\WINDOWS\SYSTEM32\ImageDrive.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 358400 C:\WINDOWS\SYSTEM32\inetcpl.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 129536 C:\WINDOWS\SYSTEM32\intl.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 380416 C:\WINDOWS\SYSTEM32\irprops.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 68608 C:\WINDOWS\SYSTEM32\joy.cpl
Microsoft Corporation 8/18/2001 10:00:00 AM 187904 C:\WINDOWS\SYSTEM32\main.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 618496 C:\WINDOWS\SYSTEM32\mmsys.cpl
Microsoft Corporation 8/18/2001 10:00:00 AM 35840 C:\WINDOWS\SYSTEM32\ncpa.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 25600 C:\WINDOWS\SYSTEM32\netsetup.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 257024 C:\WINDOWS\SYSTEM32\nusrmgr.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 32768 C:\WINDOWS\SYSTEM32\odbccp32.cpl
Sun Microsystems 5/6/2001 2:14:22 PM 24665 C:\WINDOWS\SYSTEM32\plugincpl131.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 114688 C:\WINDOWS\SYSTEM32\powercfg.cpl
Apple Computer, Inc. 1/6/2004 4:02:36 PM 323072 C:\WINDOWS\SYSTEM32\QuickTime.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 298496 C:\WINDOWS\SYSTEM32\sysdm.cpl
Microsoft Corporation 8/18/2001 10:00:00 AM 28160 C:\WINDOWS\SYSTEM32\telephon.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 94208 C:\WINDOWS\SYSTEM32\timedate.cpl
Microsoft Corporation 9/24/2005 10:42:38 PM 106544 C:\WINDOWS\SYSTEM32\TWEAKUI.CPL
Compaq Computer Corporation 4/8/2002 9:00:28 PM 106496 C:\WINDOWS\SYSTEM32\UICONFIG.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 148480 C:\WINDOWS\SYSTEM32\wscui.cpl
Microsoft Corporation 5/26/2005 4:16:30 AM 174360 C:\WINDOWS\SYSTEM32\wuaucpl.cpl
Microsoft Corporation 8/18/2001 10:00:00 AM 35840 C:\WINDOWS\SYSTEM32\dllcache\ncpa.cpl
Microsoft Corporation 8/18/2001 10:00:00 AM 28160 C:\WINDOWS\SYSTEM32\dllcache\telephon.cpl
»»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»
Checking files in %ALLUSERSPROFILE%\Startup folder...
9/17/2001 12:56:56 AM HS 84 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini
Checking files in %ALLUSERSPROFILE%\Application Data folder...
9/17/2001 12:47:10 AM HS 62 C:\Documents and Settings\All Users\Application Data\desktop.ini
8/25/2005 1:57:42 PM 5704 C:\Documents and Settings\All Users\Application Data\ypinfo.bin
Checking files in %USERPROFILE%\Startup folder...
9/17/2001 12:56:56 AM HS 84 C:\Documents and Settings\Jay\Start Menu\Programs\Startup\desktop.ini
Checking files in %USERPROFILE%\Application Data folder...
9/17/2001 12:47:10 AM HS 62 C:\Documents and Settings\Jay\Application Data\desktop.ini
10/4/2005 9:20:02 AM 462647 C:\Documents and Settings\Jay\Application Data\Sskknwrd.dll
»»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»»
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
=
acc=marketingsector =
SV1 =
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
[HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\BriefcaseMenu
{85BBD920-42A0-1069-A2E4-08002B30309D} = syncui.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\CA_AntiVirus
{1CE2AA40-1317-11D3-9922-00104B0AD431} = C:\WINDOWS\avshlext.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ewido
{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E} = C:\Program Files\ewido\security suite\context.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\fmtyqfyk
{70c43dea-a59b-4060-bca8-4b63dda808c0} = C:\WINDOWS\System32\fkrml.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
{09799AFB-AD67-11d1-ABCD-00C04FC30936} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Yahoo! Mail
{5464D816-CF16-4784-B9F3-75C0DB52B499} = C:\Program Files\Yahoo!\Common\ymmapi.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
Start Menu Pin = %SystemRoot%\system32\SHELL32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\BriefcaseMenu
{85BBD920-42A0-1069-A2E4-08002B30309D} = syncui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\CA_AntiVirus
{1CE2AA40-1317-11D3-9922-00104B0AD431} = C:\WINDOWS\avshlext.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\ewido
{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E} = C:\Program Files\ewido\security suite\context.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Sharing
{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = ntshrui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{6EC11407-5B2E-4E25-8BDF-77445B52AB37}
= C:\WINDOWS\system32\wuauclt.dll
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA356D79-679B-4b4c-8E49-5AF97014F4C1}
Starware = C:\Program Files\Starware\bin\Starware.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{12EE7A5E-0674-42f9-A76B-000000004D00}
Search = C:\WINDOWS\System32\stlb2.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4528BBE0-4E08-11D5-AD55-00010333D0AD}
&Yahoo! Messenger = C:\Program Files\Yahoo!\Messenger\yhexbmesus.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
&Tip of the Day = %SystemRoot%\System32\shdocvw.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{FE54FA40-D68C-11d2-98FA-00C0F0318AFE}
Real.com = C:\WINDOWS\System32\Shdocvw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping
MenuText = :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{2499216C-4BA5-11D5-BD9C-000103C116D5}
ButtonText = Yahoo! Login :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{4528BBE0-4E08-11D5-AD55-00010333D0AD}
ButtonText = Messenger :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45}
ButtonText = AIM : C:\Program Files\AIM95\aim.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
ButtonText = Real.com :
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478}
=
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{4528BBE0-4E08-11D5-AD55-00010333D0AD}
&Yahoo! Messenger = C:\Program Files\Yahoo!\Messenger\yhexbmesus.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}
File Search Explorer Band = %SystemRoot%\system32\SHELL32.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E62-B078-11D0-89E4-00C04FC9E26E}
History Band = %SystemRoot%\System32\shdocvw.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E64-B078-11D0-89E4-00C04FC9E26E}
Explorer Band = %SystemRoot%\System32\shdocvw.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\System32\browseui.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
{0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links : %SystemRoot%\system32\SHELL32.dll
{825CF5BD-8862-4430-B771-0C15C5CA8DEF} = &EliteBar : C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll
{77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} = :
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\System32\browseui.dll
{D49E9D35-254C-4C6A-9D17-95018D228FF5} = Starware : C:\Program Files\Starware\bin\Starware.dll
{9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} = Related Page : C:\WINDOWS\System32\WinNB57.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
TkBellExe C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
QuickTime Task "C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
1 C:\WINDOWS\system32\cmd.exe /c erase "c:\winnt\temp\acsuninstall.exe"
2 C:\WINDOWS\system32\cmd.exe /c erase "c:\winnt\temp\AcsUninstallRes.dll"
3 C:\WINDOWS\system32\cmd.exe /c erase "c:\winnt\temp\shfolder.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Creative Detector "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
AIM C:\Program Files\AIM95\aim.exe -cnetwait.odl
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk
path C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
location Common Startup
command C:\PROGRA~1\AMERIC~1.0\aoltray.exe -check
item America Online 9.0 Tray Icon
path C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
location Common Startup
command C:\PROGRA~1\AMERIC~1.0\aoltray.exe -check
item America Online 9.0 Tray Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Exif Launcher.lnk
path C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Exif Launcher.lnk
backup C:\WINDOWS\pss\Exif Launcher.lnkCommon Startup
location Common Startup
command C:\PROGRA~1\FINEPI~1\QuickDCF.exe
item Exif Launcher
path C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Exif Launcher.lnk
backup C:\WINDOWS\pss\Exif Launcher.lnkCommon Startup
location Common Startup
command C:\PROGRA~1\FINEPI~1\QuickDCF.exe
item Exif Launcher
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp psc 2000 Series.lnk
path C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp psc 2000 Series.lnk
backup C:\WINDOWS\pss\hp psc 2000 Series.lnkCommon Startup
location Common Startup
command C:\PROGRA~1\HEWLET~1\DIGITA~1\bin\hpobnz08.exe
item hp psc 2000 Series
path C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp psc 2000 Series.lnk
backup C:\WINDOWS\pss\hp psc 2000 Series.lnkCommon Startup
location Common Startup
command C:\PROGRA~1\HEWLET~1\DIGITA~1\bin\hpobnz08.exe
item hp psc 2000 Series
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk
path C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup C:\WINDOWS\pss\Microsoft Works Calendar Reminders.lnkCommon Startup
location Common Startup
command C:\PROGRA~1\COMMON~1\MICROS~1\WORKSS~1\wkcalrem.exe
item Microsoft Works Calendar Reminders
path C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup C:\WINDOWS\pss\Microsoft Works Calendar Reminders.lnkCommon Startup
location Common Startup
command C:\PROGRA~1\COMMON~1\MICROS~1\WORKSS~1\wkcalrem.exe
item Microsoft Works Calendar Reminders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^nrpa.exe
path C:\Documents and Settings\All Users\Start Menu\Programs\Startup\nrpa.exe
backup C:\WINDOWS\pss\nrpa.exeCommon Startup
location Common Startup
command C:\Documents and Settings\All Users\Start Menu\Programs\Startup\nrpa.exe
item nrpa
path C:\Documents and Settings\All Users\Start Menu\Programs\Startup\nrpa.exe
backup C:\WINDOWS\pss\nrpa.exeCommon Startup
location Common Startup
command C:\Documents and Settings\All Users\Start Menu\Programs\Startup\nrpa.exe
item nrpa
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^officejet 6100.lnk
path C:\Documents and Settings\All Users\Start Menu\Programs\Startup\officejet 6100.lnk
backup C:\WINDOWS\pss\officejet 6100.lnkCommon Startup
location Common Startup
command C:\PROGRA~1\HEWLET~1\DIGITA~1\bin\hposol08.exe
item officejet 6100
path C:\Documents and Settings\All Users\Start Menu\Programs\Startup\officejet 6100.lnk
backup C:\WINDOWS\pss\officejet 6100.lnkCommon Startup
location Common Startup
command C:\PROGRA~1\HEWLET~1\DIGITA~1\bin\hposol08.exe
item officejet 6100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk
path C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
location Common Startup
command C:\PROGRA~1\WinZip\WZQKPICK.EXE
item WinZip Quick Pick
path C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
location Common Startup
command C:\PROGRA~1\WinZip\WZQKPICK.EXE
item WinZip Quick Pick
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\5eb0c15fe81c
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item bitsprx3
hkey HKLM
command C:\WINDOWS\System32\bitsprx3.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item bitsprx3
hkey HKLM
command C:\WINDOWS\System32\bitsprx3.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\98D0CE0C16B1
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item rundll32
hkey HKLM
command rundll32.exe D0CE0C16B1,D0CE0C16B1
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item rundll32
hkey HKLM
command rundll32.exe D0CE0C16B1,D0CE0C16B1
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\A70F6A1D-0195-42a2-934C-D8AC0F7C08EB
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item rundll32
hkey HKLM
command rundll32.exe E6F1873B.DLL,D9EBC318C
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item rundll32
hkey HKLM
command rundll32.exe E6F1873B.DLL,D9EBC318C
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AIM
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item aim
hkey HKCU
command C:\Program Files\AIM95\aim.exe -cnetwait.odl
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item aim
hkey HKCU
command C:\Program Files\AIM95\aim.exe -cnetwait.odl
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AOL Spyware Protection
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item AOLSP Scheduler
hkey HKLM
command "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item AOLSP Scheduler
hkey HKLM
command "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AOLDialer
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item AOLDial
hkey HKLM
command C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item AOLDial
hkey HKLM
command C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AtxBrw
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item IEXPLOR
hkey HKLM
command C:\WINDOWS\IEXPLOR.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item IEXPLOR
hkey HKLM
command C:\WINDOWS\IEXPLOR.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AUNPS2
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item RUNDLL32 AUNPS2
hkey HKLM
command RUNDLL32 AUNPS2.DLL,_Run@16
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item RUNDLL32 AUNPS2
hkey HKLM
command RUNDLL32 AUNPS2.DLL,_Run@16
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AutoUpdater
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item AutoUpdate
hkey HKLM
command "C:\Program Files\AutoUpdate\AutoUpdate.exe"
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item AutoUpdate
hkey HKLM
command "C:\Program Files\AutoUpdate\AutoUpdate.exe"
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BJCFD
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item CFD
hkey HKLM
command C:\Program Files\BroadJump\Client Foundation\CFD.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item CFD
hkey HKLM
command C:\Program Files\BroadJump\Client Foundation\CFD.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BMan
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item BMan1
hkey HKLM
command C:\Documents and Settings\All Users\Application Data\msw\BMan1.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item BMan1
hkey HKLM
command C:\Documents and Settings\All Users\Application Data\msw\BMan1.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\bO²ù4g’ywæ^ÜœMÅC:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\bO²ù4g’ywæ^ÜœMÅC:\Program Files
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\bO²ùõh‚²ÑÀßÇ[bx¹C:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\bO²ùõh‚²ÑÀßÇ[bx¹C:\Program Files
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\bO²ùõv‚²ÑÀßÆßöÈ[C:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\bO²ùõv‚²ÑÀßÆßöÈ[C:\Program Files
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\bO²ùõv‚²ÑÀßÆÇ[bb¹C:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\bO²ùõv‚²ÑÀßÆÇ[bb¹C:\Program Files
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\bO²ùõv‚²ÑÀßÆÇ[bb‡C:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\bO²ùõv‚²ÑÀßÆÇ[bb‡C:\Program Files
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\bO²ùõîo!²uÆßÞ#
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\bO²ùõîo!²uÆßÞ#\bˆ»C:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\bO²ùõîo!²uÆßÞ#\ûÆ´C:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\bO²ùõÚ)–²%)ßfÏNb½¾C:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\bO²ùõÚ)–²%)ßfÏNb½¾C:\Program Files
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\bO²ùõ”¬‚²ÑÀßöÈ[b„¸C:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\bO²ùõ”¬‚²ÑÀßöÈ[b„¸C:\Program Files
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\bO²ùõ•¬‚²ÑÀßîÈ[b‡¸C:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\bO²ùõ•¬‚²ÑÀßîÈ[b‡¸C:\Program Files
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BullsEye Network
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item bargains
hkey HKLM
command C:\Program Files\BullsEye Network\bin\bargains.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item bargains
hkey HKLM
command C:\Program Files\BullsEye Network\bin\bargains.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\C:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\C:\WINDOWS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CaAvTray
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item CAVTray
hkey HKLM
command "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item CAVTray
hkey HKLM
command "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CARPService
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item carpserv
hkey HKLM
command carpserv.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item carpserv
hkey HKLM
command carpserv.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CAS Client
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item casclient
hkey HKCU
command "C:\Program Files\Cas\Client\casclient.exe"
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item casclient
hkey HKCU
command "C:\Program Files\Cas\Client\casclient.exe"
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CAVRID
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item CAVRID
hkey HKLM
command "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item CAVRID
hkey HKLM
command "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\cepvenc
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item cepvenc
hkey HKLM
command C:\WINDOWS\cepvenc.EXE
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item cepvenc
hkey HKLM
command C:\WINDOWS\cepvenc.EXE
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\cfgmgr52
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item cfgmgr52
hkey HKLM
command RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item cfgmgr52
hkey HKLM
command RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\checkrun
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item elitelgw32
hkey HKLM
command C:\windows\system32\elitelgw32.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item elitelgw32
hkey HKLM
command C:\windows\system32\elitelgw32.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\cisrgmi
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item riqgjq
hkey HKLM
command c:\windows\system32\riqgjq.exe r
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item riqgjq
hkey HKLM
command c:\windows\system32\riqgjq.exe r
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\cjlgnf
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item cjlgnf
hkey HKLM
command c:\windows\system32\cjlgnf.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item cjlgnf
hkey HKLM
command c:\windows\system32\cjlgnf.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CookiePatrol
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item CookiePatrol
hkey HKLM
command C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item CookiePatrol
hkey HKLM
command C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CPQEASYACC
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item StartEAK
hkey HKLM
command C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item StartEAK
hkey HKLM
command C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\dc619edbd9a4
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item bootvid1
hkey HKLM
command C:\WINDOWS\System32\bootvid1.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item bootvid1
hkey HKLM
command C:\WINDOWS\System32\bootvid1.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\emqe
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ncadapth
hkey HKLM
command C:\WINDOWS\ncadapth.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ncadapth
hkey HKLM
command C:\WINDOWS\ncadapth.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\exp
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item exp
hkey HKLM
command C:\WINDOWS\System32\exp
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item exp
hkey HKLM
command C:\WINDOWS\System32\exp
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\exp.exe
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item exp
hkey HKLM
command C:\WINDOWS\System32\exp.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item exp
hkey HKLM
command C:\WINDOWS\System32\exp.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\farmmext
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item farmmext
hkey HKLM
command C:\WINDOWS\farmmext.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item farmmext
hkey HKLM
command C:\WINDOWS\farmmext.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\fcdud
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item fcdud
hkey HKLM
command C:\WINDOWS\fcdud.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item fcdud
hkey HKLM
command C:\WINDOWS\fcdud.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Fdrcaxo
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item Ffwwos
hkey HKLM
command C:\Program Files\Jnfrl\Ffwwos.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item Ffwwos
hkey HKLM
command C:\Program Files\Jnfrl\Ffwwos.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\FlaCPY
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item flacpy
hkey HKLM
command "C:\Program Files\Common Files\Java\flacpy.exe"
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item flacpy
hkey HKLM
command "C:\Program Files\Common Files\Java\flacpy.exe"
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\FtkCPY
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ftkcpy
hkey HKLM
command "C:\Program Files\Common Files\Java\ftkcpy.exe"
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ftkcpy
hkey HKLM
command "C:\Program Files\Common Files\Java\ftkcpy.exe"
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\G3
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item GSMedia3
hkey HKLM
command C:\WINDOWS\System32\GSMedia3.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item GSMedia3
hkey HKLM
command C:\WINDOWS\System32\GSMedia3.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\h8s7vs91
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item h8s7vs91
hkey HKLM
command C:\WINDOWS\System32\h8s7vs91.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item h8s7vs91
hkey HKLM
command C:\WINDOWS\System32\h8s7vs91.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\hah
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item hah
hkey HKLM
command C:\WINDOWS\hah.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item hah
hkey HKLM
command C:\WINDOWS\hah.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\hneuni
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item hneuni
hkey HKCU
command C:\WINDOWS\System32\hneuni.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item hneuni
hkey HKCU
command C:\WINDOWS\System32\hneuni.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\hozvpqwlc
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item hozvpqwlc
hkey HKLM
command c:\windows\system32\hozvpqwlc.exe -start
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item hozvpqwlc
hkey HKLM
command c:\windows\system32\hozvpqwlc.exe -start
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Internet Optimizer
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item optimize
hkey HKLM
command "C:\Program Files\Internet Optimizer\optimize.exe"
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item optimize
hkey HKLM
command "C:\Program Files\Internet Optimizer\optimize.exe"
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\IST Service
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item istsvc
hkey HKLM
command C:\Program Files\ISTsvc\istsvc.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item istsvc
hkey HKLM
command C:\Program Files\ISTsvc\istsvc.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KavSvc
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item rhnamr
hkey HKLM
command C:\WINDOWS\System32\rhnamr.exe reg_run
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item rhnamr
hkey HKLM
command C:\WINDOWS\System32\rhnamr.exe reg_run
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Media Access
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item MediaAccK
hkey HKLM
command C:\Program Files\Media Access\MediaAccK.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item MediaAccK
hkey HKLM
command C:\Program Files\Media Access\MediaAccK.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Media Gateway
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item MediaGateway
hkey HKLM
command C:\Program Files\Media Gateway\MediaGateway.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item MediaGateway
hkey HKLM
command C:\Program Files\Media Gateway\MediaGateway.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Microsoft Works Portfolio
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item WksSb
hkey HKLM
command C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item WksSb
hkey HKLM
command C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Microsoft Works Update Detection
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item WkDetect
hkey HKLM
command C:\Program Files\Microsoft Works\WkDetect.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item WkDetect
hkey HKLM
command C:\Program Files\Microsoft Works\WkDetect.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\mprpmo
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item mprpmo
hkey HKCU
command C:\WINDOWS\System32\mprpmo.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item mprpmo
hkey HKCU
command C:\WINDOWS\System32\mprpmo.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ms044108851350
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ms044108851350
hkey HKLM
command C:\WINDOWS\ms044108851350.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ms044108851350
hkey HKLM
command C:\WINDOWS\ms044108851350.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\msmc
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item mskkk
hkey HKLM
command C:\WINDOWS\System32\mskkk.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item mskkk
hkey HKLM
command C:\WINDOWS\System32\mskkk.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MSMSGS
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item msmsgs
hkey HKCU
command "C:\Program Files\Messenger\msmsgs.exe" /background
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item msmsgs
hkey HKCU
command "C:\Program Files\Messenger\msmsgs.exe" /background
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NeroCheck
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item NeroCheck
hkey HKLM
command C:\WINDOWS\system32\NeroCheck.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item NeroCheck
hkey HKLM
command C:\WINDOWS\system32\NeroCheck.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Nsv
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item nsvsvc
hkey HKLM
command C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item nsvsvc
hkey HKLM
command C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NvCplDaemon
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item RUNDLL32
hkey HKLM
command RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item RUNDLL32
hkey HKLM
command RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
inimapping 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\OSS
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item rlvknlg
hkey HKLM
command C:\windows\rlvknlg.exe -boot
inimappin