Logfile created on: 10/09/2006 22:20 WinPFind2 by OldTimer - Version 1.0.10 Folder = C:\Documents and Settings\Frank Wilson\Desktop\WinPFind2\ Microsoft Windows XP (Version = Service Pack 2) Internet Explorer (Version - 6.0.2900.2180) [Start Post #1] Processes Image Name---------------ProcessID--Thread Count--Parent ID--Base Priority-- #Full Path ##(Version Info) smss.exe-----------------000552-----0003----------000004-----Normal--------- #\systemroot\system32\smss.exe ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 50688 bytes | Date = 08/04/2004 13:00 | Attr = ]) csrss.exe----------------000600-----0013----------000552-----Normal--------- #\??\c:\windows\system32\csrss.exe ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 6144 bytes | Date = 08/04/2004 13:00 | Attr = ]) winlogon.exe-------------000624-----0016----------000552-----High----------- #\??\c:\windows\system32\winlogon.exe ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 502272 bytes | Date = 08/04/2004 13:00 | Attr = ]) services.exe-------------000668-----0016----------000624-----Normal--------- #c:\windows\system32\services.exe ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 108032 bytes | Date = 08/04/2004 13:00 | Attr = ]) lsass.exe----------------000680-----0020----------000624-----Normal--------- #c:\windows\system32\lsass.exe ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 13312 bytes | Date = 08/04/2004 13:00 | Attr = ]) svchost.exe--------------000832-----0017----------000668-----Normal--------- #c:\windows\system32\svchost.exe [C:\WINDOWS\SYSTEM32\SVCHOST -K DCOMLAUNCH] ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(DcomLaunch) C:\WINDOWS\system32\rpcss.dll ##(Microsoft Corporation [Ver = 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528) | Size = 397824 bytes | Date = 07/26/2005 05:39 | Attr = ]) ---------------------------------------------------------------------------- #(TermService) C:\WINDOWS\System32\termsrv.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 295424 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(TermService) C:\WINDOWS\System32\termsrv.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 295424 bytes | Date = 08/04/2004 13:00 | Attr = ]) svchost.exe--------------000888-----0009----------000668-----Normal--------- #c:\windows\system32\svchost.exe [C:\WINDOWS\SYSTEM32\SVCHOST -K RPCSS] ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(RpcSs) C:\WINDOWS\system32\rpcss.dll ##(Microsoft Corporation [Ver = 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528) | Size = 397824 bytes | Date = 07/26/2005 05:39 | Attr = ]) svchost.exe--------------001012-----0068----------000668-----Normal--------- #c:\windows\system32\svchost.exe [C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS] ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(AppMgmt) C:\WINDOWS\System32\appmgmts.dll ##(File not found) ---------------------------------------------------------------------------- #(AudioSrv) C:\WINDOWS\System32\audiosrv.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 42496 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(BITS) C:\WINDOWS\system32\qmgr.dll ##(Microsoft Corporation [Ver = 6.6.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 382464 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(Browser) C:\WINDOWS\System32\browser.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 77312 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(CryptSvc) C:\WINDOWS\System32\cryptsvc.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 60416 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(Dhcp) C:\WINDOWS\System32\dhcpcsvc.dll ##(Microsoft Corporation [Ver = 5.1.2600.2912 (xpsp_sp2_gdr.060519-0003) | Size = 111616 bytes | Date = 05/19/2006 13:59 | Attr = ]) ---------------------------------------------------------------------------- #(dmserver) C:\WINDOWS\System32\dmserver.dll ##(Microsoft Corp. [Ver = 2600.2180.503.0 | Size = 23552 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(ERSvc) C:\WINDOWS\System32\ersvc.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 23040 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(EventSystem) C:\WINDOWS\system32\es.dll ##(Microsoft Corporation [Ver = 2001.12.4414.308 | Size = 243200 bytes | Date = 07/26/2005 05:39 | Attr = ]) ---------------------------------------------------------------------------- #(FastUserSwitchingCompatibility) C:\WINDOWS\System32\shsvcs.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 134656 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(helpsvc) %WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll ##(File not found) ---------------------------------------------------------------------------- #(HidServ) C:\WINDOWS\System32\hidserv.dll ##(File not found) ---------------------------------------------------------------------------- #(lanmanserver) C:\WINDOWS\System32\srvsvc.dll ##(Microsoft Corporation [Ver = 5.1.2600.2577 (xpsp_sp2_gdr.041130-1729) | Size = 96768 bytes | Date = 12/07/2004 20:32 | Attr = ]) ---------------------------------------------------------------------------- #(lanmanworkstation) C:\WINDOWS\System32\wkssvc.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 132096 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(Messenger) C:\WINDOWS\System32\msgsvc.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 33792 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(Netman) C:\WINDOWS\System32\netman.dll ##(Microsoft Corporation [Ver = 5.1.2600.2743 (xpsp_sp2_gdr.050819-1525) | Size = 197632 bytes | Date = 08/22/2005 19:29 | Attr = ]) ---------------------------------------------------------------------------- #(Nla) C:\WINDOWS\System32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 245248 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(NtmsSvc) C:\WINDOWS\system32\ntmssvc.dll ##(Microsoft Corporation [Ver = 5.1.2400.2180 | Size = 435200 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(RasAuto) C:\WINDOWS\System32\rasauto.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 89088 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(RasMan) C:\WINDOWS\System32\rasmans.dll ##(Microsoft Corporation [Ver = 5.1.2600.2908 (xpsp_sp2_gdr.060513-0343) | Size = 181248 bytes | Date = 05/14/2006 09:44 | Attr = ]) ---------------------------------------------------------------------------- #(RemoteAccess) C:\WINDOWS\System32\mprdim.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 49152 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(Schedule) C:\WINDOWS\system32\schedsvc.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 190976 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(seclogon) C:\WINDOWS\System32\seclogon.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 18944 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(SENS) C:\WINDOWS\system32\sens.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 38912 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(SharedAccess) C:\WINDOWS\System32\ipnathlp.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 331264 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(ShellHWDetection) C:\WINDOWS\System32\shsvcs.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 134656 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(srservice) C:\WINDOWS\system32\srsvc.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 170496 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(TapiSrv) C:\WINDOWS\System32\tapisrv.dll ##(Microsoft Corporation [Ver = 5.1.2600.2716 (xpsp_sp2_gdr.050707-1657) | Size = 249344 bytes | Date = 07/08/2005 17:27 | Attr = ]) ---------------------------------------------------------------------------- #(Themes) C:\WINDOWS\System32\shsvcs.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 134656 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(TrkWks) C:\WINDOWS\system32\trkwks.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 90624 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(W32Time) C:\WINDOWS\system32\w32time.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 174592 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(winmgmt) C:\WINDOWS\system32\wbem\WMIsvc.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 144896 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(WmdmPmSN) C:\WINDOWS\system32\MsPMSNSv.dll ##(Microsoft Corporation [Ver = 10.0.3790.3646 | Size = 25088 bytes | Date = 09/22/2004 19:45 | Attr = ]) ---------------------------------------------------------------------------- #(wscsvc) C:\WINDOWS\system32\wscsvc.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 81408 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(wuauserv) C:\WINDOWS\system32\wuauserv.dll ##(Microsoft Corporation [Ver = 5.4.3790.2180 (xpsp_sp2_rtm.040803-2158) | Size = 6656 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(WZCSVC) C:\WINDOWS\System32\wzcsvc.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 359936 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(xmlprov) C:\WINDOWS\System32\xmlprov.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 129536 bytes | Date = 08/04/2004 13:00 | Attr = ]) svchost.exe--------------001056-----0004----------000668-----Normal--------- #c:\windows\system32\svchost.exe [C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE] ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(Dnscache) C:\WINDOWS\System32\dnsrslvr.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 45568 bytes | Date = 08/04/2004 13:00 | Attr = ]) svchost.exe--------------001112-----0023----------000668-----Normal--------- #c:\windows\system32\svchost.exe [C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE] ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(Alerter) C:\WINDOWS\system32\alrsvc.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 17408 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(LmHosts) C:\WINDOWS\System32\lmhsvc.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 13824 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(SSDPSRV) C:\WINDOWS\System32\ssdpsrv.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 71680 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(upnphost) C:\WINDOWS\System32\upnphost.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 185344 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(WebClient) C:\WINDOWS\System32\webclnt.dll ##(Microsoft Corporation [Ver = 5.1.2600.2821 (xpsp_sp2_gdr.060103-1536) | Size = 68096 bytes | Date = 01/04/2006 04:35 | Attr = ]) spoolsv.exe--------------001400-----0010----------000668-----Normal--------- #c:\windows\system32\spoolsv.exe ##(Microsoft Corporation [Ver = 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519) | Size = 57856 bytes | Date = 06/11/2005 00:53 | Attr = ]) schedul2.exe-------------001584-----0004----------000668-----Normal--------- #c:\program files\common files\acronis\schedule2\schedul2.exe ##(Acronis [Ver = 1,0,0,216 | Size = 172032 bytes | Date = 12/27/2005 12:32 | Attr = ]) guard.exe----------------001596-----0008----------000668-----Normal--------- #c:\program files\grisoft\avg anti-spyware 7.5\guard.exe ##(Anti-Malware Development a.s. [Ver = 7, 5, 0, 47 | Size = 204800 bytes | Date = 09/28/2006 15:13 | Attr = ]) avgamsvr.exe-------------001616-----0009----------000668-----Normal--------- #c:\progra~1\grisoft\avg7\avgamsvr.exe ##(GRISOFT, s.r.o. [Ver = 7,1,0,364 | Size = 330291 bytes | Date = 12/06/2005 08:22 | Attr = ]) avgupsvc.exe-------------001636-----0003----------000668-----Normal--------- #c:\progra~1\grisoft\avg7\avgupsvc.exe ##(GRISOFT, s.r.o. [Ver = 7,0,0,346 | Size = 39987 bytes | Date = 10/21/2005 07:23 | Attr = ]) svchost.exe--------------001652-----0003----------000668-----Normal--------- #c:\windows\system32\svchost.exe [C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K BTHSVCS] ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(BthServ) C:\WINDOWS\System32\bthserv.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 30208 bytes | Date = 08/04/2004 13:00 | Attr = ]) mdm.exe------------------001728-----0004----------000668-----Normal--------- #c:\program files\common files\microsoft shared\vs7debug\mdm.exe ##(Microsoft Corporation [Ver = 7.00.9466 | Size = 322120 bytes | Date = 06/20/2003 00:25 | Attr = ]) svchost.exe--------------001824-----0007----------000668-----Normal--------- #c:\windows\system32\svchost.exe [C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K IMGSVC] ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(stisvc) C:\WINDOWS\system32\wiaservc.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 333312 bytes | Date = 08/04/2004 13:00 | Attr = ]) wdfmgr.exe---------------001884-----0004----------000668-----Normal--------- #c:\windows\system32\wdfmgr.exe ##(Microsoft Corporation [Ver = 5.2.3790.1230 built by: DNSRV(bld4act) | Size = 38912 bytes | Date = 09/22/2004 19:46 | Attr = ]) alg.exe------------------000936-----0005----------000668-----Normal--------- #c:\windows\system32\alg.exe ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 44544 bytes | Date = 08/04/2004 13:00 | Attr = ]) svchost.exe--------------001992-----0008----------000668-----Normal--------- #c:\windows\system32\svchost.exe [C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K HTTPFILTER] ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(HTTPFilter) C:\WINDOWS\System32\w3ssl.dll ##(Microsoft Corporation [Ver = 6.0.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 15872 bytes | Date = 08/04/2004 13:00 | Attr = ]) wscntfy.exe--------------001344-----0001----------001012-----Normal--------- #c:\windows\system32\wscntfy.exe ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 13824 bytes | Date = 08/04/2004 13:00 | Attr = ]) center.exe---------------002364-----0002----------002160-----Normal--------- #c:\program files\asus\wlan card utilities\center.exe ##(ASUSTeK COMPUTER INC. [Ver = 1.9.8.7 | Size = 1459200 bytes | Date = 05/05/2004 15:18 | Attr = ]) soundman.exe-------------002372-----0002----------002160-----Normal--------- #c:\windows\soundman.exe ##(Realtek Semiconductor Corp. [Ver = 5.1.0.24 | Size = 65024 bytes | Date = 02/26/2004 09:53 | Attr = ]) avgcc.exe----------------002392-----0006----------002160-----Normal--------- #c:\progra~1\grisoft\avg7\avgcc.exe ##(GRISOFT, s.r.o. [Ver = 7,1,0,404 | Size = 358447 bytes | Date = 08/07/2006 18:33 | Attr = ]) type32.exe---------------002448-----0003----------002160-----Normal--------- #c:\program files\microsoft intellitype pro\type32.exe ##(Microsoft Corporation [Ver = 5.20.413.0 | Size = 172032 bytes | Date = 06/03/2004 02:51 | Attr = ]) jusched.exe--------------002504-----0001----------002160-----Normal--------- #c:\program files\java\jre1.5.0_06\bin\jusched.exe ##(Sun Microsystems, Inc. [Ver = 5.0.60.5 | Size = 36975 bytes | Date = 11/10/2005 14:03 | Attr = ]) qttask.exe---------------002512-----0002----------002160-----Normal--------- #c:\program files\quicktime\qttask.exe ##(Apple Computer, Inc. [Ver = 6.5 | Size = 98304 bytes | Date = 02/26/2005 22:11 | Attr = ]) rundll32.exe-------------002536-----0004----------002160-----Normal--------- #c:\windows\system32\rundll32.exe ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 33280 bytes | Date = 08/04/2004 13:00 | Attr = ]) trueimagemonitor.exe-----002572-----0004----------002160-----Normal--------- #c:\program files\acronis\trueimage\trueimagemonitor.exe ##(Acronis [Ver = 9,0,0,2337 | Size = 988736 bytes | Date = 12/27/2005 12:32 | Attr = ]) schedhlp.exe-------------002580-----0001----------002160-----Normal--------- #c:\program files\common files\acronis\schedule2\schedhlp.exe ##(Acronis [Ver = 1,0,0,216 | Size = 118784 bytes | Date = 12/27/2005 12:32 | Attr = ]) launch~1.exe-------------002620-----0003----------002160-----Normal--------- #c:\progra~1\nokia\nokiap~1\launch~1.exe ##(Nokia [Ver = 6, 80, 53, 3 | Size = 237568 bytes | Date = 04/26/2006 08:29 | Attr = ]) avgas.exe----------------002652-----0014----------002160-----Normal--------- #c:\program files\grisoft\avg anti-spyware 7.5\avgas.exe ##(Anti-Malware Development a.s. [Ver = 7, 5, 0, 47 | Size = 6266880 bytes | Date = 09/28/2006 15:13 | Attr = ]) ctfmon.exe---------------002704-----0001----------002160-----Normal--------- #c:\windows\system32\ctfmon.exe ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 15360 bytes | Date = 08/04/2004 13:00 | Attr = ]) mnyexpr.exe--------------002712-----0001----------002160-----Normal--------- #c:\program files\microsoft money\system\mnyexpr.exe ##(Microsoft Corporation [Ver = 11.00.0716 | Size = 200767 bytes | Date = 07/17/2002 12:00 | Attr = ]) nmbgmonitor.exe----------002724-----0004----------002160-----Normal--------- #c:\program files\common files\ahead\lib\nmbgmonitor.exe ##(Nero AG [Ver = 1, 0, 0, 0 | Size = 94208 bytes | Date = 09/03/2005 15:18 | Attr = ]) googletoolbarnotifier.exe002740-----0006----------002160-----Normal--------- #c:\program files\google\googletoolbarnotifier\1.0.720.3640\googletoolbarnotifier.exe ##(Google Inc. [Ver = 1, 0, 720, 3640 | Size = 155896 bytes | Date = 09/13/2006 08:05 | Attr = ]) servicelayer.exe---------002796-----0013----------000668-----Normal--------- #c:\program files\common files\pcsuite\services\servicelayer.exe ##(Nokia. [Ver = 6, 80, 56, 4 | Size = 176640 bytes | Date = 04/12/2006 11:36 | Attr = ]) msnmsgr.exe--------------003136-----0018----------002160-----Normal--------- #c:\program files\msn messenger\msnmsgr.exe ##(Microsoft Corporation [Ver = 8.0.0812.00 | Size = 5354792 bytes | Date = 07/29/2006 19:34 | Attr = ]) wisptis.exe--------------003176-----0003----------000832-----High----------- #c:\windows\system32\wisptis.exe ##(Microsoft Corporation [Ver = 1.0.2201.0 (xpsp1.020820-1800) | Size = 189952 bytes | Date = 08/21/2002 06:13 | Attr = ]) svchost.exe--------------003456-----0003----------000668-----Normal--------- #c:\windows\system32\svchost.exe [C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K USNSVC] ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) ---------------------------------------------------------------------------- #(usnsvc) C:\Program Files\MSN Messenger\usnsvc.dll ##(Microsoft Corporation [Ver = 8.0.0812.00 | Size = 117544 bytes | Date = 07/29/2006 19:34 | Attr = ]) explorer.exe-------------003888-----0014----------000624-----Normal--------- #c:\windows\explorer.exe ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 1032192 bytes | Date = 08/04/2004 13:00 | Attr = ]) iexplore.exe-------------003848-----0009----------001440-----Normal--------- #c:\program files\internet explorer\iexplore.exe ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 93184 bytes | Date = 08/04/2004 13:00 | Attr = ]) winpfind2.exe------------001448-----0001----------003888-----Normal--------- #c:\documents and settings\frank wilson\desktop\winpfind2\winpfind2.exe ##(OldTimer Tools [Ver = 1.0.10.0 | Size = 392704 bytes | Date = 09/17/2006 11:39 | Attr = ]) Registry Entries #Value ##(Version Info) <<< >> Internet Explorer Settings << >>> HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page #http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home ## HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page #http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ## HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL #http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome ## HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Search_URL #http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ## HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page #%SystemRoot%\system32\blank.htm ## HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page #http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome ## HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Bar #http://www.google.com/ie ## HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page #http://www.google.com ## HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page #C:\WINDOWS\system32\blank.htm ## HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\CustomizeSearch #http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm ## HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant #http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm ## HKCU\Software\Microsoft\Internet Explorer\urlSearchHooks\\{CFBFAE00-17A6-11D0-99CB-00C04FD64497} #Microsoft Url Search Hook = %SystemRoot%\system32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1494016 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable #0 ## <<< >> BHO's << >>> HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} #AcroIEHlprObj Class = C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll ##(Adobe Systems Incorporated [Ver = 6.0.0.2003051500 | Size = 50376 bytes | Date = 05/15/2003 01:47 | Attr = ]) HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{243B17DE-77C7-46BF-B94B-0B5F309A0E64} #Reg Data missing or invalid = C:\Program Files\Microsoft Money\System\mnyside.dll ##(Microsoft Corporation [Ver = 11.00.0716 | Size = 163906 bytes | Date = 07/17/2002 12:00 | Attr = ]) HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F} # = C:\PROGRA~1\SPYBOT~1\SDHelper.dll ##(Safer Networking Limited [Ver = 1, 4, 0, 0 | Size = 853672 bytes | Date = 05/31/2005 01:04 | Attr = ]) HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} #SSVHelper Class = C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll ##(Sun Microsystems, Inc. [Ver = 5.0.60.5 | Size = 184423 bytes | Date = 11/10/2005 14:22 | Attr = ]) HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7} #Google Toolbar Helper = c:\program files\google\googletoolbar1.dll ##(Google Inc. [Ver = 4, 0, 1019, 5266 | Size = 2018368 bytes | Date = 08/09/2006 17:52 | Attr = R ]) HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDD3B846-8D59-4ffb-8758-209B6AD74ACC} #Reg Data missing or invalid = Reg Data missing or invalid ##(File not found) <<< >> Internet Explorer Bars, Toolbars and Extensions << >>> <<< HKLM-> Internet Explorer Bars >>> HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376} #&Tip of the Day = %SystemRoot%\system32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1494016 bytes | Date = 06/23/2006 12:02 | Attr = ]) <<< HKCU-> Internet Explorer Bars >>> HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{EFA24E64-B078-11D0-89E4-00C04FC9E26E} #Explorer Band = %SystemRoot%\system32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1494016 bytes | Date = 06/23/2006 12:02 | Attr = ]) <<< HKCU-> Internet Explorer ToolBars >>> HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} #&Google = c:\program files\google\googletoolbar1.dll ##(Google Inc. [Ver = 4, 0, 1019, 5266 | Size = 2018368 bytes | Date = 08/09/2006 17:52 | Attr = R ]) HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{01E04581-4EEE-11D0-BFE9-00AA005B4383} #&Address = %SystemRoot%\system32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1022976 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383} #&Links = %SystemRoot%\system32\SHELL32.dll ##(Microsoft Corporation [Ver = 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009) | Size = 8453632 bytes | Date = 07/13/2006 14:33 | Attr = ]) HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} #&Google = c:\program files\google\googletoolbar1.dll ##(Google Inc. [Ver = 4, 0, 1019, 5266 | Size = 2018368 bytes | Date = 08/09/2006 17:52 | Attr = R ]) <<< HKCU-> Internet Explorer CmdMapping >>> HKCU\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} #8194 - Sun Java Console ## HKCU\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} #8193 - Reg Data missing or invalid ## HKCU\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{E023F504-0C5A-4750-A1E7-A9046DEA8A21} #8195 - Reg Data missing or invalid ## HKCU\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} #8192 - Windows Messenger ## HKCU\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\NextId #8196 ## <<< HKLM-> Internet Explorer Extensions >>> HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} #MenuText: Sun Java Console = C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll ##(Sun Microsystems, Inc. [Ver = 5.0.60.5 | Size = 69746 bytes | Date = 11/10/2005 14:22 | Attr = ]) HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} #MenuText: Sun Java Console = C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll ##(Sun Microsystems, Inc. [Ver = 5.0.60.5 | Size = 184423 bytes | Date = 11/10/2005 14:22 | Attr = ]) HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{92780B25-18CC-41C8-B9BE-3C9C571A8263} #ButtonText: Research = Reg Data missing or invalid ##(File not found) HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{E023F504-0C5A-4750-A1E7-A9046DEA8A21} #ButtonText: MoneySide = Reg Data missing or invalid ##(File not found) HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683} #ButtonText: Messenger = C:\Program Files\Messenger\msmsgs.exe ##(Microsoft Corporation [Ver = 4.7.3001 | Size = 1694208 bytes | Date = 10/13/2004 17:24 | Attr = ]) <<< HKCU-> Internet Explorer Menu Extensions >>> HKCU\Software\Microsoft\Internet Explorer\MenuExt\E&xport to Microsoft Excel #res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 ##(Microsoft Corporation [Ver = 11.0.8033 | Size = 10196752 bytes | Date = 06/23/2006 12:38 | Attr = ]) <<< >> All Approved Shell Extensions << >>> <<< HKLM-> Approved Shell Extensions >>> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{00020D75-0000-0000-C000-000000000046} #Microsoft Office Outlook Desktop Icon Handler = C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL ##(Microsoft Corporation [Ver = 11.0.6550 | Size = 30408 bytes | Date = 03/17/2005 22:09 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{00022613-0000-0000-C000-000000000046} #Multimedia File Property Sheet = mmsys.cpl ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 618496 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{0006F045-0000-0000-C000-000000000046} #Microsoft Office Outlook Custom Icon Handler = C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL ##(Microsoft Corporation [Ver = 11.0.5510 | Size = 232512 bytes | Date = 07/14/2003 23:46 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{00BB2763-6A77-11D0-A535-00C04FD7D062} #Microsoft AutoComplete = %SystemRoot%\system32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1022976 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{00BB2764-6A77-11D0-A535-00C04FD7D062} #Microsoft History AutoComplete List = %SystemRoot%\system32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1022976 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{00BB2765-6A77-11D0-A535-00C04FD7D062} #Microsoft Multiple AutoComplete List Container = %SystemRoot%\system32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1022976 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} #Autoplay for SlideShow = Reg Data missing or invalid ##(File not found) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{01E04581-4EEE-11d0-BFE9-00AA005B4383} #&Address = %SystemRoot%\system32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1022976 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{03C036F1-A186-11D0-824A-00AA005B4383} #Microsoft Shell Folder AutoComplete List = %SystemRoot%\system32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1022976 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{07798131-AF23-11d1-9111-00A0C98BA67D} #Web Search = %SystemRoot%\system32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1022976 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{08165EA0-E946-11CF-9C87-00AA005127ED} #WebCheckWebCrawler = %SystemRoot%\system32\webcheck.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 276480 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{0A89A860-D7B1-11CE-8350-444553540000} #Shell Automation Inproc Service = %SystemRoot%\system32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1494016 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{0B124F8F-91F0-11D1-B8B5-006008059382} #Installed Apps Enumerator = %SystemRoot%\system32\appwiz.cpl ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 549888 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{0CD7A5C0-9F37-11CE-AE65-08002B2E1262} #.CAB file viewer = cabview.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 84480 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{0D45D530-764B-11d0-A1CA-00AA00C16E65} #Directory Property UI = %SystemRoot%\system32\dsuiext.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 113152 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{0DF44EAA-FF21-4412-828E-260A8728E7F1} #Taskbar and Start Menu = Reg Data missing or invalid ##(File not found) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{0EEA25CC-4362-4A12-850B-86EE61B0D3EB} #Microsoft DocProp Inplace Droplist Combo Control = C:\WINDOWS\system32\docprop2.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 48128 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{10CFC467-4392-11d2-8DB4-00C04FA31A66} #Offline Files Folder Options = %SystemRoot%\System32\cscui.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 326656 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{111D8120-25EB-4E1C-A4DF-C9EE5FCA35CB} #IntelliType Pro Scrolling Control Panel Property Page = "C:\Program Files\Microsoft IntelliType Pro\itcplwhl.dll" ##(Microsoft Corporation [Ver = 5.20.413.0 | Size = 229376 bytes | Date = 06/03/2004 02:51 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{131A6951-7F78-11D0-A979-00C04FD705A2} #ISFBand OC = %SystemRoot%\system32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1494016 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{143A62C8-C33B-11D1-84FE-00C04FA34A14} #Microsoft Agent Character Property Sheet Handler = C:\WINDOWS\msagent\agentpsh.dll ##(Microsoft Corporation [Ver = 2.00.0.3422 | Size = 24064 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{163FDC20-2ABC-11d0-88F0-00A024AB2DBB} #Directory Object Find = %SystemRoot%\system32\dsquery.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 239104 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{169A0691-8DF9-11d1-A1C4-00C04FD75D13} #In-pane search = %SystemRoot%\system32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1022976 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{176d6597-26d3-11d1-b350-080036a75b03} #ICM Scanner Management = icmui.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 54784 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{1F2E5C40-9550-11CE-99D2-00AA006E086C} #NTFS Security Page = rshx32.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 39936 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{21569614-B795-46b1-85F4-E737A8DC09AD} #Shell Search Band = %SystemRoot%\system32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1022976 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2206CDB2-19C1-11D1-89E0-00C04FD7A829} #Microsoft Data Link = C:\Program Files\Common Files\System\Ole DB\oledb32.dll ##(Microsoft Corporation [Ver = 2.81.1117.0 (xpsp_sp2_rtm.040803-2158) | Size = 487424 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{22BF0C20-6DA7-11D0-B373-00A0C9034938} #Download Status = %SystemRoot%\system32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1022976 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0} #Search = %SystemRoot%\system32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1494016 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0} #Help and Support = %SystemRoot%\system32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1494016 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0} #Help and Support = %SystemRoot%\system32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1494016 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} #Run... = %SystemRoot%\system32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1494016 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0} #Internet = %SystemRoot%\system32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1494016 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0} #E-mail = %SystemRoot%\system32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1494016 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0} #Set Program Access and Defaults = %SystemRoot%\system32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1494016 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33} #Microsoft DocProp Inplace Time Control = C:\WINDOWS\system32\docprop2.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 48128 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{30D02401-6A81-11d0-8274-00C04FD5AE38} #Search Band = %SystemRoot%\system32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1022976 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{32714800-2E5F-11d0-8B85-00AA0044F941} #For &People... = C:\Program Files\Outlook Express\wabfind.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 32768 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{352EC2B7-8B9A-11D1-B8AE-006008059382} #Shell Application Manager = %SystemRoot%\system32\appwiz.cpl ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 549888 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{3C374A40-BAE4-11CF-BF7D-00AA006946EE} #Microsoft Url History Service = %SystemRoot%\system32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1494016 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{3CCF8A41-5C85-11d0-9796-00AA00B90ADF} #Shell DeskBarApp = %SystemRoot%\system32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1022976 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{3DC7A020-0ACD-11CF-A9BB-00AA004AE837} #The Internet = %SystemRoot%\system32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1494016 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{3EA48300-8CF6-101B-84FB-666CCB9BCD32} #OLE Docfile Property Page = docprop.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 46080 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{3F30C968-480A-4C6C-862D-EFC0897BB84B} #GDI+ file thumbnail extractor = C:\WINDOWS\system32\shimgvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 438272 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{3F953603-1008-4f6e-A73A-04AAC7A992F1} #Scanners & Cameras = wiashext.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 589312 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{40C3D757-D6E4-4b49-BB41-0E5BBEA28817} #Video Media Properties Handler = %SystemRoot%\system32\shmedia.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 151552 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{40dd6e20-7c17-11ce-a804-00aa003ca9f6} #Shell extensions for sharing = ntshrui.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 143872 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{416651E4-9C3C-11D9-8BDE-F66BAD1E3F3A} #PhoneBrowser = C:\Program Files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll ##(Nokia [Ver = 6, 80, 37, 4 | Size = 532480 bytes | Date = 04/10/2006 10:07 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{41E300E0-78B6-11ce-849B-444553540000} #PlusPack CPL Extension = %SystemRoot%\system32\themeui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 385536 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{42042206-2D85-11D3-8CFF-005004838597} #Microsoft Office HTML Icon Handler = C:\Program Files\Microsoft Office\OFFICE11\msohev.dll ##(Microsoft Corporation [Ver = 11.0.5510 | Size = 67128 bytes | Date = 07/14/2003 23:52 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{42071712-76d4-11d1-8b24-00a0c9068ff3} #Display Adapter CPL Extension = deskadp.dll ##(Microsoft Corporation [Ver = 6.00.2600.0000 (xpclient.010817-1148) | Size = 16384 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{42071713-76d4-11d1-8b24-00a0c9068ff3} #Display Monitor CPL Extension = deskmon.dll ##(Microsoft Corporation [Ver = 6.00.2600.0000 (xpclient.010817-1148) | Size = 16896 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{42071714-76d4-11d1-8b24-00a0c9068ff3} #Display Panning CPL Extension = deskpan.dll ##(File not found) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{4a7ded0a-ad25-11d0-98a8-0800361b1103} #MyDocs Properties = %SystemRoot%\system32\mydocs.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 90624 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{4E40F770-369C-11d0-8922-00A024AB2DBB} #DS Security Page = dssec.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 51200 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8} #Compatibility Page = SlayerXP.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 25088 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{56117100-C0CD-101B-81E2-00AA004AE837} #Shell Scrap DataHandler = shscrap.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 27648 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{58f1f272-9240-4f51-b6d4-fd63d1618591} #Get a Passport Wizard = %SystemRoot%\system32\netplwiz.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 875008 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{59099400-57FF-11CE-BD94-0020AF85B590} #Disk Copy Extension = diskcopy.dll ##(Microsoft Corporation [Ver = 6.00.2600.0000 (xpclient.010817-1148) | Size = 1501696 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{596AB062-B4D2-4215-9F74-E9109B0A8153} #Previous Versions Property Page = %SystemRoot%\system32\twext.dll ##(Microsoft Corporation [Ver = 6.00.3800.2180 (xpsp_sp2_rtm.040803-2158) | Size = 44032 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{59be4990-f85c-11ce-aff7-00aa003ca9f6} #Shell extensions for Microsoft Windows Network objects = ntlanui2.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5DB2625A-54DF-11D0-B6C4-0800091AA605} #ICM Monitor Management = %SystemRoot%\System32\icmui.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 54784 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5E6AB780-7743-11CF-A12B-00AA004AE837} #Microsoft Internet Toolbar = %SystemRoot%\system32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1022976 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5F327514-6C5E-4d60-8F16-D07FA08A78ED} #Auto Update Property Sheet Extension = C:\WINDOWS\system32\wuaucpl.cpl ##(Microsoft Corporation [Ver = 5.8.0.2469 built by: lab01_n(wmbla) | Size = 174360 bytes | Date = 05/26/2005 04:16 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{60254CA5-953B-11CF-8C96-00AA00B8708C} #Shell extensions for Windows Script Host = C:\WINDOWS\system32\wshext.dll ##(Microsoft Corporation [Ver = 5.6.0.8820 | Size = 65536 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{60fd46de-f830-4894-a628-6fa81bc0190d} #%DESC_PublishDropTarget% = %SystemRoot%\system32\photowiz.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 176128 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{62AE1F9A-126A-11D0-A14B-0800361B1103} #Directory Context Menu Verbs = %SystemRoot%\system32\dsuiext.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 113152 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{63da6ec0-2e98-11cf-8d82-444553540000} #FTP Folders Webview = C:\WINDOWS\system32\msieftp.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 248832 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{640167b4-59b0-47a6-b335-a6b3c0695aea} #Portable Media Devices = %SystemRoot%\system32\Audiodev.dll ##(Microsoft Corporation [Ver = 5.2.3790.3646 built by: DNSRV(bld4act) | Size = 480768 bytes | Date = 09/22/2004 19:45 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{6413BA2C-B461-11d1-A18A-080036B11A03} #Augmented Shell Folder 2 = %SystemRoot%\system32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1022976 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178} #Shell Image Data Factory = %SystemRoot%\system32\shimgvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 438272 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{6756A641-DE71-11d0-831B-00AA005B4383} #MRU AutoComplete List = %SystemRoot%\system32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1022976 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{675F097E-4C4D-11D0-B6C1-0800091AA605} #ICM Printer Management = %SystemRoot%\system32\icmui.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 54784 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{67EA19A0-CCEF-11d0-8024-00C04FD75D13} #CDF Extension Copy Hook = %SystemRoot%\system32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1494016 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{692F0339-CBAA-47e6-B5B5-3B84DB604E87} #Extensions Manager Folder = %SystemRoot%\system32\extmgr.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 55808 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A} #Custom MRU AutoCompleted List = %SystemRoot%\system32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1022976 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{6A205B57-2567-4A2C-B881-F787FAB579A3} #Microsoft DocProp Inplace Calendar Control = C:\WINDOWS\system32\docprop2.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 48128 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{6b33163c-76a5-4b6c-bf21-45de9cd503a1} #Shell Publishing Wizard Object = %SystemRoot%\system32\netplwiz.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 875008 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7007ACC7-3202-11D1-AAD2-00805FC1270E} #Network Connections = C:\WINDOWS\system32\NETSHELL.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 1708032 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7376D660-C583-11d0-A3A5-00C04FD706EC} #TridentImageExtractor = %SystemRoot%\system32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1022976 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7444C717-39BF-11D1-8CD9-00C04FC29D45} #Crypto PKO Extension = C:\WINDOWS\system32\cryptext.dll ##(Microsoft Corporation [Ver = 5.131.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 53760 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7444C719-39BF-11D1-8CD9-00C04FC29D45} #Crypto Sign Extension = C:\WINDOWS\system32\cryptext.dll ##(Microsoft Corporation [Ver = 5.131.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 53760 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{750fdf0e-2a26-11d1-a3ea-080036587f03} #Offline Files Menu = %SystemRoot%\System32\cscui.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 326656 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{764BF0E1-F219-11ce-972D-00AA00A14F56} #Shell extensions for file compression = Reg Data missing or invalid ##(File not found) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{77597368-7b15-11d0-a0c2-080036af3f03} #Web Printer Shell Extension = printui.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 560640 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF} #Tasks Folder Shell Extension = C:\WINDOWS\system32\mstask.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 274944 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7988B573-EC89-11cf-9C00-00AA00A14F56} #Disk Quota UI = dskquoui.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 144384 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7A80E4A8-8005-11D2-BCF8-00C04F72C717} #MMC Icon Handler = %SystemRoot%\System32\mmcshext.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 50688 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7A9D77BD-5403-11d2-8785-2E0420524153} #User Accounts = Reg Data missing or invalid ##(File not found) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7BA4C742-9E81-11CF-99D3-00AA004AE837} #Microsoft BrowserBand = %SystemRoot%\system32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1022976 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7BD29E00-76C1-11CF-9DD0-00A0C9034933} #Temporary Internet Files = %SystemRoot%\system32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1494016 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7BD29E01-76C1-11CF-9DD0-00A0C9034933} #Temporary Internet Files = %SystemRoot%\system32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1494016 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7D559C10-9FE9-11d0-93F7-00AA0059CE02} #Code Download Agent = %SystemRoot%\system32\webcheck.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 276480 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7e653215-fa25-46bd-a339-34a2790f3cb7} #Accessible = %SystemRoot%\system32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1022976 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7F1CF152-04F8-453A-B34C-E609530A9DC8} #NeroDigitalPropSheetHandler = C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll ##(Nero AG [Ver = 2, 0, 0, 7 | Size = 1802240 bytes | Date = 09/03/2005 13:58 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB} #WebCheck SyncMgr Handler = %SystemRoot%\system32\webcheck.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 276480 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{83bbcbf3-b28a-4919-a5aa-73027445d672} #Scanners & Cameras = wiashext.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 589312 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} #Encryption Context Menu = Reg Data missing or invalid ##(File not found) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{85BBD920-42A0-1069-A2E4-08002B30309D} #Briefcase = syncui.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 191488 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{871C5380-42A0-1069-A2EA-08002B30309D} #Internet Name Space = %SystemRoot%\system32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1494016 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{875CB1A1-0F29-45de-A1AE-CFB4950D0B78} #Audio Media Properties Handler = %SystemRoot%\system32\shmedia.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 151552 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{87D62D94-71B3-4b9a-9489-5FE6850DC73E} #Avi Properties Handler = %SystemRoot%\system32\shmedia.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 151552 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{883373C3-BF89-11D1-BE35-080036B11A03} #Microsoft DocProp Shell Ext = C:\WINDOWS\system32\docprop2.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 48128 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{88895560-9AA2-1069-930E-00AA0030EBC8} #HyperTerminal Icon Ext = C:\WINDOWS\system32\hticons.dll ##(Hilgraeve, Inc. [Ver = 5.1.2600.0 | Size = 44544 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{888DCA60-FC0A-11CF-8F0F-00C04FD7D062} #Compressed (zipped) Folder SendTo Target = %SystemRoot%\system32\zipfldr.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 337920 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{88C6C381-2E85-11D0-94DE-444553540000} #ActiveX Cache Folder = %SystemRoot%\system32\occache.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 96256 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8A23E65E-31C2-11d0-891C-00A024AB2DBB} #Directory Query UI = %SystemRoot%\system32\dsquery.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 239104 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8DD448E6-C188-4aed-AF92-44956194EB1F} #Windows Media Player Play as Playlist Context Menu Handler = C:\WINDOWS\system32\wmpshell.dll ##(Microsoft Corporation [Ver = 10.00.00.3646 | Size = 86016 bytes | Date = 09/22/2004 19:46 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8EE97210-FD1F-4B19-91DA-67914005F020} #Microsoft DocProp Inplace ML Edit Box Control = C:\WINDOWS\system32\docprop2.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 48128 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{905667aa-acd6-11d2-8080-00805f6596d2} #Scanners & Cameras = wiashext.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 589312 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{91EA3F8B-C99B-11d0-9815-00C04FD91972} #Augmented Shell Folder = %SystemRoot%\system32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1022976 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{9461b922-3c5a-11d2-bf8b-00c04fb93661} #Search Assistant OC = %SystemRoot%\system32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1494016 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{97FA8AA2-EE77-4FF2-9449-424D8924EF21} #IntelliType Pro Zooming Control Panel Property Page = "C:\Program Files\Microsoft IntelliType Pro\itcplzm.dll" ##(Microsoft Corporation [Ver = 5.20.413.0 | Size = 204800 bytes | Date = 06/03/2004 02:51 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{992CFFA0-F557-101A-88EC-00DD010CCC48} #Network Connections = C:\WINDOWS\system32\NETSHELL.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 1708032 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{9DB7A13C-F208-4981-8353-73CC61AE2783} #Previous Versions = %SystemRoot%\system32\twext.dll ##(Microsoft Corporation [Ver = 6.00.3800.2180 (xpsp_sp2_rtm.040803-2158) | Size = 44032 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{9DBD2C50-62AD-11d0-B806-00C04FD706EC} #Summary Info Thumbnail handler (DOCFILES) = C:\WINDOWS\system32\shimgvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 438272 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{9E51E0D0-6E0F-11d2-9601-00C04FA31A86} #Shell properties for a DS object = %SystemRoot%\system32\dsquery.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 239104 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE} #Sendmail service = C:\WINDOWS\system32\sendmail.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 55296 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE} #Sendmail service = C:\WINDOWS\system32\sendmail.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 55296 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} #AVG7 Shell Extension = C:\Program Files\Grisoft\AVG7\avgse.dll ##(GRISOFT, s.r.o. [Ver = 7,0,0,337 | Size = 29743 bytes | Date = 10/21/2005 07:23 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{9F97547E-460A-42C5-AE0C-81C61FFAEBC3} #AVG7 Find Extension = C:\Program Files\Grisoft\AVG7\avgse.dll ##(GRISOFT, s.r.o. [Ver = 7,0,0,337 | Size = 29743 bytes | Date = 10/21/2005 07:23 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A08C11D2-A228-11d0-825B-00AA005B4383} #Address EditBox = %SystemRoot%\system32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1022976 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A2569D1F-4E06-43EC-9825-0088B471BE47} #IntelliType Pro Wireless Control Panel Property Page = "C:\Program Files\Microsoft IntelliType Pro\itcplwir.dll" ##(Microsoft Corporation [Ver = 5.20.413.0 | Size = 200704 bytes | Date = 06/03/2004 02:51 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC} #IE4 Suite Splash Screen = %SystemRoot%\system32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1494016 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A5E46E3A-8849-11D1-9D8C-00C04FC99D61} #Microsoft Browser Architecture = %SystemRoot%\system32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1494016 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A6FD9E45-6E44-43f9-8644-08598F5A74D9} #Midi Properties Handler = %SystemRoot%\system32\shmedia.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 151552 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A9CF0EAE-901A-4739-A481-E35B73E47F6D} #Microsoft DocProp Inplace Edit Box Control = C:\WINDOWS\system32\docprop2.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 48128 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE} #Subscription Mgr = %SystemRoot%\system32\webcheck.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 276480 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{acf35015-526e-4230-9596-becbe19f0ac9} #Track Popup Bar = %SystemRoot%\system32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1022976 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{add36aa8-751a-4579-a266-d66f5202ccbb} #Print Ordering via the Web = %SystemRoot%\system32\netplwiz.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 875008 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{AF4F6510-F982-11d0-8595-00AA004CD6D8} #Registry Tree Options Utility = %SystemRoot%\system32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1022976 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E} #Offline Files Folder = %SystemRoot%\System32\cscui.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 326656 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{B327765E-D724-4347-8B16-78AE18552FC3} #NeroDigitalIconHandler = C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll ##(Nero AG [Ver = 2, 0, 0, 7 | Size = 1802240 bytes | Date = 09/03/2005 13:58 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{BD472F60-27FA-11cf-B8B4-444553540000} #Compressed (zipped) Folder Right Drag Handler = %SystemRoot%\system32\zipfldr.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 337920 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{BD84B380-8CA2-1069-AB1D-08000948F534} #Fonts = fontext.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 382976 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} #Web Folders = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL ##(Microsoft Corporation [Ver = 11.0.5510.0 | Size = 1292872 bytes | Date = 07/11/2003 03:15 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{c5a40261-cd64-4ccf-84cb-c394da41d590} #Video Thumbnail Extractor = %SystemRoot%\system32\shmedia.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 151552 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{CC6EEFFB-43F6-46c5-9619-51D571967F7D} #Web Publishing Wizard = %SystemRoot%\system32\netplwiz.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 875008 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{cc86590a-b60a-48e6-996b-41d25ed39a1e} #Portable Media Devices Menu = %SystemRoot%\system32\Audiodev.dll ##(Microsoft Corporation [Ver = 5.2.3790.3646 built by: DNSRV(bld4act) | Size = 480768 bytes | Date = 09/22/2004 19:45 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C} #Windows Media Player Burn Audio CD Context Menu Handler = C:\WINDOWS\system32\wmpshell.dll ##(Microsoft Corporation [Ver = 10.00.00.3646 | Size = 86016 bytes | Date = 09/22/2004 19:46 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{CFBFAE00-17A6-11D0-99CB-00C04FD64497} #Microsoft Url Search Hook = %SystemRoot%\system32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1494016 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{CFCCC7A0-A282-11D1-9082-006008059382} #Darwin App Publisher = %SystemRoot%\system32\appwiz.cpl ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 549888 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D20EA4E1-3957-11d2-A40B-0C5020524152} #Fonts = %SystemRoot%\system32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1494016 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D20EA4E1-3957-11d2-A40B-0C5020524153} #Administrative Tools = %SystemRoot%\system32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1494016 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D6277990-4C6A-11CF-8D87-00AA0060F5BF} #Scheduled Tasks = C:\WINDOWS\system32\mstask.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 274944 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D8BD2030-6FC9-11D0-864F-00AA006809D9} #PostAgent = %SystemRoot%\system32\webcheck.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 276480 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DBCE2480-C732-101B-BE72-BA78E9AD5B27} #ICC Profile = %SystemRoot%\system32\icmui.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 54784 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF} #Tasks Folder Icon Handler = C:\WINDOWS\system32\mstask.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 274944 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DD313E04-FEFF-11d1-8ECD-0000F87A470C} #User Assist = %SystemRoot%\system32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1022976 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E211B736-43FD-11D1-9EFB-0000F8757FCD} #Scanners & Cameras = wiashext.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 589312 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB} #WebCheckChannelAgent = %SystemRoot%\system32\webcheck.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 276480 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E4B29F9D-D390-480b-92FD-7DDB47101D71} #Wav Properties Handler = %SystemRoot%\system32\shmedia.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 151552 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{e57ce731-33e8-4c51-8354-bb4de9d215d1} #Universal Plug and Play Devices = C:\WINDOWS\system32\upnpui.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 239616 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E6CC6978-6B6E-11D0-BECA-00C04FD940BE} #ConnectionAgent = %SystemRoot%\system32\webcheck.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 276480 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E6FB5E20-DE35-11CF-9C87-00AA005127ED} #WebCheck = %SystemRoot%\system32\webcheck.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 276480 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} #Shell DocObject Viewer = %SystemRoot%\system32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1494016 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{e84fda7c-1d6a-45f6-b725-cb260c236066} #Shell Image Verbs = %SystemRoot%\system32\shimgvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 438272 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31} #Compressed (zipped) Folder = %SystemRoot%\system32\zipfldr.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 337920 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7} #TrayAgent = %SystemRoot%\system32\webcheck.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 276480 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{EAB841A0-9550-11cf-8C16-00805F1408F3} #HTML Thumbnail Extractor = C:\WINDOWS\system32\shimgvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 438272 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{eb9b1153-3b57-4e68-959a-a3266bc3d7fe} #Shell Image Property Handler = %SystemRoot%\system32\shimgvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 438272 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6} #DfsShell = C:\WINDOWS\system32\dfsshlex.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 28672 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{ECD4FC4C-521C-11D0-B792-00A0C90312E1} #Shell DeskBar = %SystemRoot%\system32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1022976 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{ECD4FC4D-521C-11D0-B792-00A0C90312E1} #Shell Rebar BandSite = %SystemRoot%\system32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1022976 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{ECD4FC4E-521C-11D0-B792-00A0C90312E1} #Shell Band Site Menu = %SystemRoot%\system32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1022976 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{ECF03A32-103D-11d2-854D-006008059367} #MyDocs Drop Target = %SystemRoot%\system32\mydocs.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 90624 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{ECF03A33-103D-11d2-854D-006008059367} #MyDocs Copy Hook = %SystemRoot%\system32\mydocs.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 90624 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{ED6E87C6-8A83-43aa-8208-8DBC8247F4D2} #IntelliType Pro Key Settings Control Panel Property Page = "C:\Program Files\Microsoft IntelliType Pro\itcplkey.dll" ##(Microsoft Corporation [Ver = 5.20.413.0 | Size = 352256 bytes | Date = 06/03/2004 02:51 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} #Global Folder Settings = %SystemRoot%\system32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1022976 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{EFA24E61-B078-11d0-89E4-00C04FC9E26E} #Favorites Band = %SystemRoot%\system32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1494016 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{EFA24E64-B078-11d0-89E4-00C04FC9E26E} #Explorer Band = %SystemRoot%\system32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1494016 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{F0152790-D56E-4445-850E-4F3117DB740C} #Remote Sessions CPL Extension = C:\WINDOWS\system32\remotepg.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 60416 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{F020E586-5264-11d1-A532-0000F8757D7E} #Directory Start/Search Find = %SystemRoot%\system32\dsquery.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 239104 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} #Shell Extensions for RealOne Player = C:\Program Files\Real\RealPlayer\rpshell.dll ##(RealNetworks, Inc. [Ver = 1.0.1.2237 | Size = 49198 bytes | Date = 04/28/2006 10:44 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD} #Windows Media Player Add to Playlist Context Menu Handler = C:\WINDOWS\system32\wmpshell.dll ##(Microsoft Corporation [Ver = 10.00.00.3646 | Size = 86016 bytes | Date = 09/22/2004 19:46 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{F37C5810-4D3F-11d0-B4BF-00AA00BBB723} #Printers Security Page = rshx32.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 39936 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{f39a0dc0-9cc8-11d0-a599-00c04fd64433} #Channel File = %SystemRoot%\system32\cdfview.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 151040 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{f3aa0dc0-9cc8-11d0-a599-00c04fd64434} #Channel Shortcut = %SystemRoot%\system32\cdfview.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 151040 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{f3ba0dc0-9cc8-11d0-a599-00c04fd64435} #Channel Handler Object = %SystemRoot%\system32\cdfview.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 151040 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{f3da0dc0-9cc8-11d0-a599-00c04fd64437} #Channel Menu = %SystemRoot%\system32\cdfview.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 151040 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{f3ea0dc0-9cc8-11d0-a599-00c04fd64438} #Channel Properties = %SystemRoot%\system32\cdfview.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 151040 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{F5175861-2688-11d0-9C5E-00AA00A45957} #Subscription Folder = %SystemRoot%\system32\webcheck.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 276480 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{F61FFEC1-754F-11d0-80CA-00AA005B4383} #BandProxy = %SystemRoot%\system32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1022976 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} #Shell extensions for sharing = ntshrui.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 143872 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{f92e8c40-3d33-11d2-b1aa-080036a75b03} #Display TroubleShoot CPL Extension = deskperf.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 18432 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD} #Scanners & Cameras = wiashext.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 589312 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{FBF23B40-E3F0-101B-8488-00AA003E56F8} #InternetShortcut = shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1494016 bytes | Date = 06/23/2006 12:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D} #Messenger Sharing Folders = C:\Program Files\MSN Messenger\fsshext.8.0.0812.00.dll ##(Microsoft Corporation [Ver = 8.0.0812.00 | Size = 186664 bytes | Date = 07/29/2006 19:34 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{FF393560-C2A7-11CF-BFF4-444553540000} #History = %SystemRoot%\system32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2900.2937 (xpsp_sp2_gdr.060623-0002) | Size = 1494016 bytes | Date = 06/23/2006 12:02 | Attr = ]) <<< >> All ContextMenuHandlers << >>> <<< HKLM-> ContextMenuHandlers >>> HKLM\Software\Classes\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8} #Start Menu Pin = C:\WINDOWS\system32\SHELL32.dll ##(Microsoft Corporation [Ver = 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009) | Size = 8453632 bytes | Date = 07/13/2006 14:33 | Attr = ]) HKLM\Software\Classes\*\shellex\ContextMenuHandlers\{EB4D3CFE-E2AA-4C6E-B2FE-2A749F95D208} #Reg Data missing or invalid = C:\Program Files\Nero\Nero 7\Nero BackItUp\NBShell.dll ##(Nero AG [Ver = 2, 0, 0, 0 | Size = 114688 bytes | Date = 09/05/2005 10:37 | Attr = ]) HKLM\Software\Classes\*\shellex\ContextMenuHandlers\AVG Anti-Spyware #{8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll ##(Anti-Malware Development a.s. [Ver = 7, 5, 0, 47 | Size = 98304 bytes | Date = 09/28/2006 15:13 | Attr = ]) HKLM\Software\Classes\*\shellex\ContextMenuHandlers\AVG7 Shell Extension #{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG7\avgse.dll ##(GRISOFT, s.r.o. [Ver = 7,0,0,337 | Size = 29743 bytes | Date = 10/21/2005 07:23 | Attr = ]) HKLM\Software\Classes\*\shellex\ContextMenuHandlers\Offline Files #{750fdf0e-2a26-11d1-a3ea-080036587f03} = C:\WINDOWS\System32\cscui.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 326656 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\Software\Classes\*\shellex\ContextMenuHandlers\Open With #{09799AFB-AD67-11d1-ABCD-00C04FC30936} = C:\WINDOWS\system32\SHELL32.dll ##(Microsoft Corporation [Ver = 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009) | Size = 8453632 bytes | Date = 07/13/2006 14:33 | Attr = ]) HKLM\Software\Classes\*\shellex\ContextMenuHandlers\Open With EncryptionMenu #{A470F8CF-A1E8-4f65-8335-227475AA5C46} = C:\WINDOWS\system32\SHELL32.dll ##(Microsoft Corporation [Ver = 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009) | Size = 8453632 bytes | Date = 07/13/2006 14:33 | Attr = ]) HKLM\Software\Classes\*\shellex\ContextMenuHandlers\WS_FTP #{797F3885-5429-11D4-8823-0050DA59922B} = C:\Program Files\Ipswitch\WS_FTP Professional\wsftpsi.dll ##(Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington, MA 02421 [Ver = 2006,0,1,0 | Size = 245760 bytes | Date = 08/19/2005 11:11 | Attr = ]) HKLM\SOFTWARE\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\Send To #{7BA4C740-9E81-11CF-99D3-00AA004AE837} = C:\WINDOWS\system32\SHELL32.dll ##(Microsoft Corporation [Ver = 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009) | Size = 8453632 bytes | Date = 07/13/2006 14:33 | Attr = ]) HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\AVG Anti-Spyware #{8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll ##(Anti-Malware Development a.s. [Ver = 7, 5, 0, 47 | Size = 98304 bytes | Date = 09/28/2006 15:13 | Attr = ]) HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\EncryptionMenu #{A470F8CF-A1E8-4f65-8335-227475AA5C46} = C:\WINDOWS\system32\SHELL32.dll ##(Microsoft Corporation [Ver = 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009) | Size = 8453632 bytes | Date = 07/13/2006 14:33 | Attr = ]) HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Offline Files #{750fdf0e-2a26-11d1-a3ea-080036587f03} = C:\WINDOWS\System32\cscui.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 326656 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Sharing #{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = C:\WINDOWS\SYSTEM32\ntshrui.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 143872 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Classes\Directory\BackGround\shellex\ContextMenuHandlers\New #{D969A300-E7FF-11d0-A93B-00A0C90F2719} = C:\WINDOWS\system32\SHELL32.dll ##(Microsoft Corporation [Ver = 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009) | Size = 8453632 bytes | Date = 07/13/2006 14:33 | Attr = ]) HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\{EB4D3CFE-E2AA-4C6E-B2FE-2A749F95D208} #Reg Data missing or invalid = C:\Program Files\Nero\Nero 7\Nero BackItUp\NBShell.dll ##(Nero AG [Ver = 2, 0, 0, 0 | Size = 114688 bytes | Date = 09/05/2005 10:37 | Attr = ]) HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\AVG7 Shell Extension #{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG7\avgse.dll ##(GRISOFT, s.r.o. [Ver = 7,0,0,337 | Size = 29743 bytes | Date = 10/21/2005 07:23 | Attr = ]) HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\WS_FTP #{797F3885-5429-11D4-8823-0050DA59922B} = C:\Program Files\Ipswitch\WS_FTP Professional\wsftpsi.dll ##(Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington, MA 02421 [Ver = 2006,0,1,0 | Size = 245760 bytes | Date = 08/19/2005 11:11 | Attr = ]) <<< >> All ColumnHandlers << >>> <<< HKLM-> ColumnHandlers >>> HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871} #Reg Data missing or invalid = %SystemRoot%\system32\SHELL32.dll ##(Microsoft Corporation [Ver = 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009) | Size = 8453632 bytes | Date = 07/13/2006 14:33 | Attr = ]) HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF} #Reg Data missing or invalid = %SystemRoot%\system32\SHELL32.dll ##(Microsoft Corporation [Ver = 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009) | Size = 8453632 bytes | Date = 07/13/2006 14:33 | Attr = ]) HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF} #Reg Data missing or invalid = %SystemRoot%\system32\SHELL32.dll ##(Microsoft Corporation [Ver = 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009) | Size = 8453632 bytes | Date = 07/13/2006 14:33 | Attr = ]) HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE} #Reg Data missing or invalid = %SystemRoot%\system32\SHELL32.dll ##(Microsoft Corporation [Ver = 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009) | Size = 8453632 bytes | Date = 07/13/2006 14:33 | Attr = ]) HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{7D4D6379-F301-4311-BEBA-E26EB0561882} #NeroDigitalColumnHandler Class = C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll ##(Nero AG [Ver = 2, 0, 0, 7 | Size = 1802240 bytes | Date = 09/03/2005 13:58 | Attr = ]) <<< >> File Associations Keys << >>> HKLM\SOFTWARE\Classes\.bat\\'' #batfile ## HKLM\SOFTWARE\Classes\batfile\shell\open\command\\'' #"%1" %* ## HKLM\SOFTWARE\Classes\.cmd\\'' #cmdfile ## HKLM\SOFTWARE\Classes\cmdfile\shell\open\command\\'' #"%1" %* ## HKLM\SOFTWARE\Classes\.com\\'' #comfile ## HKLM\SOFTWARE\Classes\comfile\shell\open\command\\'' #"%1" %* ## HKLM\SOFTWARE\Classes\.exe\\'' #exefile ## HKLM\SOFTWARE\Classes\exefile\shell\open\command\\'' #"%1" %* ## HKLM\SOFTWARE\Classes\.hta\\'' #htafile ## HKLM\SOFTWARE\Classes\htafile\shell\open\command\\'' #C:\WINDOWS\system32\mshta.exe "%1" %* ## HKLM\SOFTWARE\Classes\.js\\'' #JSFile ## HKLM\SOFTWARE\Classes\jsfile\shell\open\command\\'' #"C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe" "%1" ## HKLM\SOFTWARE\Classes\.jse\\'' #JSEFile ## HKLM\SOFTWARE\Classes\jsefile\shell\open\command\\'' #%SystemRoot%\System32\WScript.exe "%1" %* ## HKLM\SOFTWARE\Classes\.scr\\'' #scrfile ## HKLM\SOFTWARE\Classes\scrfile\shell\open\command\\'' #"%1" /S ## HKLM\SOFTWARE\Classes\.vbe\\'' #VBEFile ## HKLM\SOFTWARE\Classes\vbefile\shell\open\command\\'' #%SystemRoot%\System32\WScript.exe "%1" %* ## HKLM\SOFTWARE\Classes\.vbs\\'' #VBSFile ## HKLM\SOFTWARE\Classes\vbsfile\shell\open\command\\'' #%SystemRoot%\System32\WScript.exe "%1" %* ## HKLM\SOFTWARE\Classes\.wsf\\'' #WSFFile ## HKLM\SOFTWARE\Classes\wsffile\shell\open\command\\'' #%SystemRoot%\System32\WScript.exe "%1" %* ## HKLM\SOFTWARE\Classes\.wsh\\'' #WSHFile ## HKLM\SOFTWARE\Classes\wshfile\shell\open\command\\'' #%SystemRoot%\System32\WScript.exe "%1" %* ## HKLM\SOFTWARE\Classes\.txt\\'' #txtfile ## HKLM\SOFTWARE\Classes\txtfile\shell\open\command\\'' #%SystemRoot%\system32\NOTEPAD.EXE %1 ## <<< >> Registry Run Keys << >>> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\!AVG Anti-Spyware #"C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized ##(Anti-Malware Development a.s. [Ver = 7, 5, 0, 47 | Size = 6266880 bytes | Date = 09/28/2006 15:13 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Acronis Scheduler2 Service #"C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" ##(Acronis [Ver = 1,0,0,216 | Size = 118784 bytes | Date = 12/27/2005 12:32 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\AVG7_CC #C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP ##(GRISOFT, s.r.o. [Ver = 7,1,0,404 | Size = 358447 bytes | Date = 08/07/2006 18:33 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\BluetoothAuthenticationAgent #rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 33280 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Control Center #C:\Program Files\ASUS\WLAN Card Utilities\Center.exe ##(ASUSTeK COMPUTER INC. [Ver = 1.9.8.7 | Size = 1459200 bytes | Date = 05/05/2004 15:18 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\MSConfig #C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 158208 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\NeroFilterCheck #C:\WINDOWS\system32\NeroCheck.exe ##(Ahead Software Gmbh [Ver = 1, 0, 0, 2 | Size = 155648 bytes | Date = 07/09/2001 11:50 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\OSSelectorReinstall #C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall.exe ##( [Ver = | Size = 1544099 bytes | Date = 12/27/2005 19:01 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\PCSuiteTrayApplication #C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup ##(Nokia [Ver = 6, 80, 53, 3 | Size = 237568 bytes | Date = 04/26/2006 08:29 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task #"C:\Program Files\QuickTime\qttask.exe" -atboottime ##(Apple Computer, Inc. [Ver = 6.5 | Size = 98304 bytes | Date = 02/26/2005 22:11 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\SoundMan #SOUNDMAN.EXE ##(Realtek Semiconductor Corp. [Ver = 5.1.0.24 | Size = 65024 bytes | Date = 02/26/2004 09:53 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched #C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe ##(Sun Microsystems, Inc. [Ver = 5.0.60.5 | Size = 36975 bytes | Date = 11/10/2005 14:03 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\TrueImageMonitor.exe #C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe ##(Acronis [Ver = 9,0,0,2337 | Size = 988736 bytes | Date = 12/27/2005 12:32 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\type32 #"C:\Program Files\Microsoft IntelliType Pro\type32.exe" ##(Microsoft Corporation [Ver = 5.20.413.0 | Size = 172032 bytes | Date = 06/03/2004 02:51 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL #Installed = 1 ## HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI #Installed = 1 ## HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS #Installed = 1 ## HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} #"C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" ##(Nero AG [Ver = 1, 0, 0, 0 | Size = 94208 bytes | Date = 09/03/2005 15:18 | Attr = ]) HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\CTFMON.EXE #C:\WINDOWS\system32\ctfmon.exe ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 15360 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\MoneyAgent #"C:\Program Files\Microsoft Money\System\mnyexpr.exe" ##(Microsoft Corporation [Ver = 11.00.0716 | Size = 200767 bytes | Date = 07/17/2002 12:00 | Attr = ]) HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\MsnMsgr #"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background ##(Microsoft Corporation [Ver = 8.0.0812.00 | Size = 5354792 bytes | Date = 07/29/2006 19:34 | Attr = ]) HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\swg #C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe ##(Google Inc. [Ver = 1, 0, 720, 3640 | Size = 155896 bytes | Date = 09/13/2006 08:05 | Attr = ]) <<< >> Miscellaneous Startup Keys << >>> <<< AppInit DLLs >>> HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs # ##(File not found) <<< Image File Execution Options >>> HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path #Debugger = ntsd -d ## <<< Shell Service Object Delay Load >>> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\CDBurn #{fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll ##(Microsoft Corporation [Ver = 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009) | Size = 8453632 bytes | Date = 07/13/2006 14:33 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\PostBootReminder #{7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll ##(Microsoft Corporation [Ver = 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009) | Size = 8453632 bytes | Date = 07/13/2006 14:33 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\SysTray #{35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\system32\stobject.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 121856 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\UPnPMonitor #{e57ce738-33e8-4c51-8354-bb4de9d215d1} = C:\WINDOWS\system32\upnpui.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 239616 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck #{E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\system32\webcheck.dll ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 276480 bytes | Date = 08/04/2004 13:00 | Attr = ]) <<< Shell Execute Hooks >>> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{57B86673-276A-48B2-BAE7-C6DBB3020EB8} #CShellExecuteHookImpl Object = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll ##(Anti-Malware Development a.s. [Ver = 7, 5, 0, 47 | Size = 73728 bytes | Date = 09/28/2006 15:13 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} #URL Exec Hook = shell32.dll ##(Microsoft Corporation [Ver = 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009) | Size = 8453632 bytes | Date = 07/13/2006 14:33 | Attr = ]) <<< Shared Task Scheduler >>> <<< SafeBoot Option >>> <<< HKLM Command Processor AutoRun >>> HKLM\SOFTWARE\Microsoft\Command Processor\\AutoRun # ## <<< HKCU Command Processor AutoRun >>> <<< Security Providers >>> HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders #msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll ## <<< BootExecute >>> HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\\BootExecute #autocheck autochk *; ## <<< PendingFileRenameOperations >>> <<< FileRenameOperations >>> <<< ExcludeFromKnownDlls >>> HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\\ExcludeFromKnownDlls # ## <<< >> Disabled MSConfig Items << >>> HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpFolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HotSync Manager.lnk #HotSync Manager = C:\PROGRA~1\Palm\HOTSYNC.EXE ##(File not found) HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpFolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk #InterVideo WinCinema Manager = C:\PROGRA~1\INTERV~1\Common\Bin\WINCIN~1.EXE ##(InterVideo Inc. [Ver = 1.7.1 | Size = 114688 bytes | Date = 12/27/2004 20:34 | Attr = ]) HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpFolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package Menu.lnk #Picture Package Menu = C:\PROGRA~1\SONYCO~1\PICTUR~1\PICTUR~3\SonyTray.exe ##(Sony Corporation [Ver = 1, 0, 31121, 1 | Size = 151552 bytes | Date = 11/21/2003 22:02 | Attr = ]) HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpFolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package VCD Maker.lnk #Picture Package VCD Maker = C:\PROGRA~1\SONYCO~1\PICTUR~1\PICTUR~1\RESIDE~1.EXE -h ##(Sony Corporation. [Ver = 1, 0, 0, 1 | Size = 106496 bytes | Date = 07/08/2004 17:13 | Attr = ]) HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpFolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk #QuickBooks Update Agent = C:\PROGRA~1\COMMON~1\Intuit\QUICKB~1\QBUpdate\qbupdate.exe ##(Intuit, Inc. [Ver = 13.0 R1 | Size = 724992 bytes | Date = 10/25/2003 06:44 | Attr = ]) <<< >> User Agent Post Platform << >>> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\\SV1 # ## <<< >> Winlogon << >>> HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit #C:\WINDOWS\system32\userinit.exe, ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 24576 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell #Explorer.exe ##(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 1032192 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\System # ##(File not found) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet #rundll32 shell32,Control_RunDLL "sysdm.cpl" ## HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain #crypt32.dll ##(Microsoft Corporation [Ver = 5.131.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 597504 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet #cryptnet.dll ##(Microsoft Corporation [Ver = 5.131.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 63488 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll #cscdll.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 101888 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp #wlnotify.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 92672 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule #wlnotify.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 92672 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy #sclgntfy.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 20992 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn #WlNotify.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 92672 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv #wlnotify.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 92672 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon #WgaLogon.dll ##(Microsoft Corporation [Ver = 1.5.0540.0 | Size = 702768 bytes | Date = 06/19/2006 16:20 | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon #wlnotify.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 92672 bytes | Date = 08/04/2004 13:00 | Attr = ]) <<< >> DNS Name Servers << >>> HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{09663769-C9E9-4707-B7A1-C206A8B404A3} # () ## HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{5EB2B428-261E-4D45-94C8-AADC02D380D2} # (ASUS 802.11b/g Wireless LAN Card) ## HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{7DD83CE5-D063-4C31-8F9F-E39A220E9860} # (1394 Net Adapter) ## HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8D1DEFFC-C74D-4E05-8DD2-40C0E3419D92} # () ## HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{93434890-27C5-42DC-ADB2-783E91E45987} # () ## HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{FD6283AA-942D-4D1A-89C2-D9C87C1EE601} #213.130.128.32,213.130.128.33 (Marvell Yukon 88E8001/8003/8010 PCI Gigabit Ethernet Controller) ## <<< >> All Winsock2 Catalogs << >>> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001 #%SystemRoot%\System32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 245248 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002 #%SystemRoot%\System32\winrnr.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 16896 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003 #%SystemRoot%\System32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 245248 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004 #%SystemRoot%\system32\wshbth.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 108032 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 245248 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 245248 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 245248 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004 #%SystemRoot%\system32\rsvpsp.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 90112 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005 #%SystemRoot%\system32\rsvpsp.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 90112 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 245248 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 245248 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 245248 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 245248 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 245248 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 245248 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 245248 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 245248 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 245248 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 245248 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000016 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 245248 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000017 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 245248 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000018 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 245248 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000019 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 245248 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000020 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 245248 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000021 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 245248 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000022 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 245248 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000023 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 245248 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000024 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 245248 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000025 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 245248 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000026 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 245248 bytes | Date = 08/04/2004 13:00 | Attr = ]) <<< >> All Protocol Handlers << >>> HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\about #%SystemRoot%\system32\mshtml.dll ##(Microsoft Corporation [Ver = 6.00.2900.2963 (xpsp_sp2_gdr.060727-2358) | Size = 3054080 bytes | Date = 07/28/2006 12:28 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\cdl #C:\WINDOWS\system32\urlmon.dll ##(Microsoft Corporation [Ver = 6.00.2900.2960 (xpsp_sp2_gdr.060725-0055) | Size = 613888 bytes | Date = 07/25/2006 21:33 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\dvd #C:\WINDOWS\system32\msvidctl.dll ##(Microsoft Corporation [Ver = 6.05.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 1428480 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\file #C:\WINDOWS\system32\urlmon.dll ##(Microsoft Corporation [Ver = 6.00.2900.2960 (xpsp_sp2_gdr.060725-0055) | Size = 613888 bytes | Date = 07/25/2006 21:33 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\ftp #C:\WINDOWS\system32\urlmon.dll ##(Microsoft Corporation [Ver = 6.00.2900.2960 (xpsp_sp2_gdr.060725-0055) | Size = 613888 bytes | Date = 07/25/2006 21:33 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\gopher #C:\WINDOWS\system32\urlmon.dll ##(Microsoft Corporation [Ver = 6.00.2900.2960 (xpsp_sp2_gdr.060725-0055) | Size = 613888 bytes | Date = 07/25/2006 21:33 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\http #C:\WINDOWS\system32\urlmon.dll ##(Microsoft Corporation [Ver = 6.00.2900.2960 (xpsp_sp2_gdr.060725-0055) | Size = 613888 bytes | Date = 07/25/2006 21:33 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\http\0x00000001 #C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll ##(Microsoft Corporation [Ver = 11.0.5510.0 | Size = 842816 bytes | Date = 07/11/2003 03:25 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\http\oledb #C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll ##(Microsoft Corporation [Ver = 11.0.5510.0 | Size = 842816 bytes | Date = 07/11/2003 03:25 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\https #C:\WINDOWS\system32\urlmon.dll ##(Microsoft Corporation [Ver = 6.00.2900.2960 (xpsp_sp2_gdr.060725-0055) | Size = 613888 bytes | Date = 07/25/2006 21:33 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\https\0x00000001 #C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll ##(Microsoft Corporation [Ver = 11.0.5510.0 | Size = 842816 bytes | Date = 07/11/2003 03:25 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\https\oledb #C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll ##(Microsoft Corporation [Ver = 11.0.5510.0 | Size = 842816 bytes | Date = 07/11/2003 03:25 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\ipp # ##(File not found) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\ipp\0x00000001 #C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll ##(Microsoft Corporation [Ver = 11.0.5510.0 | Size = 842816 bytes | Date = 07/11/2003 03:25 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\its #C:\WINDOWS\system32\itss.dll ##(Microsoft Corporation [Ver = 5.2.3790.2453 (srv03_sp1_gdr.050525-1542) | Size = 137216 bytes | Date = 05/27/2005 03:04 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\javascript #%SystemRoot%\system32\mshtml.dll ##(Microsoft Corporation [Ver = 6.00.2900.2963 (xpsp_sp2_gdr.060727-2358) | Size = 3054080 bytes | Date = 07/28/2006 12:28 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\livecall #C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL ##(Microsoft Corporation [Ver = 8.0.0812.00 | Size = 53032 bytes | Date = 07/29/2006 19:32 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\local #C:\WINDOWS\system32\urlmon.dll ##(Microsoft Corporation [Ver = 6.00.2900.2960 (xpsp_sp2_gdr.060725-0055) | Size = 613888 bytes | Date = 07/25/2006 21:33 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\mailto #%SystemRoot%\system32\mshtml.dll ##(Microsoft Corporation [Ver = 6.00.2900.2963 (xpsp_sp2_gdr.060727-2358) | Size = 3054080 bytes | Date = 07/28/2006 12:28 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\mhtml #%SystemRoot%\system32\inetcomm.dll ##(Microsoft Corporation [Ver = 6.00.2900.2962 (xpsp_sp2_gdr.060727-0051) | Size = 679424 bytes | Date = 07/27/2006 14:24 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\mk #C:\WINDOWS\system32\urlmon.dll ##(Microsoft Corporation [Ver = 6.00.2900.2960 (xpsp_sp2_gdr.060725-0055) | Size = 613888 bytes | Date = 07/25/2006 21:33 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp # ##(File not found) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\0x00000001 #C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll ##(Microsoft Corporation [Ver = 11.0.5510.0 | Size = 842816 bytes | Date = 07/11/2003 03:25 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\oledb #C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll ##(Microsoft Corporation [Ver = 11.0.5510.0 | Size = 842816 bytes | Date = 07/11/2003 03:25 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\ms-its #C:\WINDOWS\system32\itss.dll ##(Microsoft Corporation [Ver = 5.2.3790.2453 (srv03_sp1_gdr.050525-1542) | Size = 137216 bytes | Date = 05/27/2005 03:04 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\ms-itss #C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL ##(Microsoft Corporation [Ver = 05.02.9336.01 | Size = 520117 bytes | Date = 04/19/2000 19:47 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\msnim #C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL ##(Microsoft Corporation [Ver = 8.0.0812.00 | Size = 53032 bytes | Date = 07/29/2006 19:32 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\mso-offdap11 #C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL ##(Microsoft Corporation [Ver = 11.0.6555 | Size = 8071360 bytes | Date = 04/25/2005 21:29 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\res #%SystemRoot%\system32\mshtml.dll ##(Microsoft Corporation [Ver = 6.00.2900.2963 (xpsp_sp2_gdr.060727-2358) | Size = 3054080 bytes | Date = 07/28/2006 12:28 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\sysimage #%SystemRoot%\system32\mshtml.dll ##(Microsoft Corporation [Ver = 6.00.2900.2963 (xpsp_sp2_gdr.060727-2358) | Size = 3054080 bytes | Date = 07/28/2006 12:28 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\tv #C:\WINDOWS\system32\msvidctl.dll ##(Microsoft Corporation [Ver = 6.05.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 1428480 bytes | Date = 08/04/2004 13:00 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\vbscript #%SystemRoot%\system32\mshtml.dll ##(Microsoft Corporation [Ver = 6.00.2900.2963 (xpsp_sp2_gdr.060727-2358) | Size = 3054080 bytes | Date = 07/28/2006 12:28 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\wia #C:\WINDOWS\system32\wiascr.dll ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 75776 bytes | Date = 08/04/2004 13:00 | Attr = ]) <<< >> All Protocol Filters << >>> HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\Class Install Handler #C:\WINDOWS\system32\urlmon.dll ##(Microsoft Corporation [Ver = 6.00.2900.2960 (xpsp_sp2_gdr.060725-0055) | Size = 613888 bytes | Date = 07/25/2006 21:33 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\deflate #C:\WINDOWS\system32\urlmon.dll ##(Microsoft Corporation [Ver = 6.00.2900.2960 (xpsp_sp2_gdr.060725-0055) | Size = 613888 bytes | Date = 07/25/2006 21:33 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\gzip #C:\WINDOWS\system32\urlmon.dll ##(Microsoft Corporation [Ver = 6.00.2900.2960 (xpsp_sp2_gdr.060725-0055) | Size = 613888 bytes | Date = 07/25/2006 21:33 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\lzdhtml #C:\WINDOWS\system32\urlmon.dll ##(Microsoft Corporation [Ver = 6.00.2900.2960 (xpsp_sp2_gdr.060725-0055) | Size = 613888 bytes | Date = 07/25/2006 21:33 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\text/webviewhtml #%SystemRoot%\system32\SHELL32.dll ##(Microsoft Corporation [Ver = 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009) | Size = 8453632 bytes | Date = 07/13/2006 14:33 | Attr = ]) HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\text/xml #C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL ##(Microsoft Corporation [Ver = 11.0.5510 | Size = 39488 bytes | Date = 07/14/2003 23:45 | Attr = ]) [Start Post #2] Services Name--Internal Name--Startup Type--State--Service Type-- #Path ##(Version Info) Acronis Scheduler2 Service--AcrSch2Svc--Automatic--Running--Win32, running in it's own process-- #"C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe" ##(Acronis [Ver = 1,0,0,216 | Size = 172032 bytes | Date = 12/27/2005 12:32 | Attr = ]) Application Layer Gateway Service--ALG--On Demand--Running--Win32, running in it's own process-- #C:\WINDOWS\System32\alg.exe ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 44544 bytes | Date = 08/04/2004 13:00 | Attr = ]) Windows Audio--AudioSrv--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\System32\svchost.exe -k netsvcs ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) AVG Anti-Spyware Guard--AVG Anti-Spyware Guard--Automatic--Running--Win32, running in it's own process-- #C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe ##(Anti-Malware Development a.s. [Ver = 7, 5, 0, 47 | Size = 204800 bytes | Date = 09/28/2006 15:13 | Attr = ]) AVG7 Alert Manager Server--Avg7Alrt--Automatic--Running--Win32, running in it's own process-- #C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe ##(GRISOFT, s.r.o. [Ver = 7,1,0,364 | Size = 330291 bytes | Date = 12/06/2005 08:22 | Attr = ]) AVG7 Update Service--Avg7UpdSvc--Automatic--Running--Win32, running in it's own process-- #C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe ##(GRISOFT, s.r.o. [Ver = 7,0,0,346 | Size = 39987 bytes | Date = 10/21/2005 07:23 | Attr = ]) Computer Browser--Browser--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\system32\svchost.exe -k netsvcs ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) Bluetooth Support Service--BthServ--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\system32\svchost.exe -k bthsvcs ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) Cryptographic Services--CryptSvc--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\system32\svchost.exe -k netsvcs ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) DCOM Server Process Launcher--DcomLaunch--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\system32\svchost -k DcomLaunch ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) DHCP Client--Dhcp--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\system32\svchost.exe -k netsvcs ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) DNS Client--Dnscache--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\system32\svchost.exe -k NetworkService ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) Error Reporting Service--ERSvc--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\System32\svchost.exe -k netsvcs ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) Event Log--Eventlog--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\system32\services.exe ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 108032 bytes | Date = 08/04/2004 13:00 | Attr = ]) COM+ Event System--EventSystem--On Demand--Running--Win32, running in a shared process-- #C:\WINDOWS\system32\svchost.exe -k netsvcs ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) Fast User Switching Compatibility--FastUserSwitchingCompatibility--On Demand--Running--Win32, running in a shared process-- #C:\WINDOWS\System32\svchost.exe -k netsvcs ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) Help and Support--helpsvc--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\System32\svchost.exe -k netsvcs ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) HTTP SSL--HTTPFilter--On Demand--Running--Win32, running in a shared process-- #C:\WINDOWS\System32\svchost.exe -k HTTPFilter ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) Server--lanmanserver--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\system32\svchost.exe -k netsvcs ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) Workstation--lanmanworkstation--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\system32\svchost.exe -k netsvcs ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) TCP/IP NetBIOS Helper--LmHosts--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\system32\svchost.exe -k LocalService ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) Machine Debug Manager--MDM--Automatic--Running--Win32, running in it's own process-- #"C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" ##(Microsoft Corporation [Ver = 7.00.9466 | Size = 322120 bytes | Date = 06/20/2003 00:25 | Attr = ]) Network Connections--Netman--On Demand--Running--Win32, running in a shared process-- #C:\WINDOWS\System32\svchost.exe -k netsvcs ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) Network Location Awareness (NLA)--Nla--On Demand--Running--Win32, running in a shared process-- #C:\WINDOWS\system32\svchost.exe -k netsvcs ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) Plug and Play--PlugPlay--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\system32\services.exe ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 108032 bytes | Date = 08/04/2004 13:00 | Attr = ]) IPSEC Services--PolicyAgent--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\system32\lsass.exe ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 13312 bytes | Date = 08/04/2004 13:00 | Attr = ]) Protected Storage--ProtectedStorage--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\system32\lsass.exe ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 13312 bytes | Date = 08/04/2004 13:00 | Attr = ]) Remote Access Auto Connection Manager--RasAuto--On Demand--Running--Win32, running in a shared process-- #C:\WINDOWS\system32\svchost.exe -k netsvcs ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) Remote Access Connection Manager--RasMan--On Demand--Running--Win32, running in a shared process-- #C:\WINDOWS\system32\svchost.exe -k netsvcs ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) Remote Procedure Call (RPC)--RpcSs--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\system32\svchost -k rpcss ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) Security Accounts Manager--SamSs--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\system32\lsass.exe ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 13312 bytes | Date = 08/04/2004 13:00 | Attr = ]) Task Scheduler--Schedule--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\System32\svchost.exe -k netsvcs ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) Secondary Logon--seclogon--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\System32\svchost.exe -k netsvcs ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) System Event Notification--SENS--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\system32\svchost.exe -k netsvcs ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) ServiceLayer--ServiceLayer--On Demand--Running--Win32, running in it's own process-- #"C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe" ##(Nokia. [Ver = 6, 80, 56, 4 | Size = 176640 bytes | Date = 04/12/2006 11:36 | Attr = ]) Windows Firewall/Internet Connection Sharing (ICS)--SharedAccess--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\system32\svchost.exe -k netsvcs ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) Shell Hardware Detection--ShellHWDetection--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\System32\svchost.exe -k netsvcs ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) Print Spooler--Spooler--Automatic--Running--Win32, running in it's own process-- #C:\WINDOWS\system32\spoolsv.exe ##(Microsoft Corporation [Ver = 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519) | Size = 57856 bytes | Date = 06/11/2005 00:53 | Attr = ]) System Restore Service--srservice--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\system32\svchost.exe -k netsvcs ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) SSDP Discovery Service--SSDPSRV--On Demand--Running--Win32, running in a shared process-- #C:\WINDOWS\system32\svchost.exe -k LocalService ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) Windows Image Acquisition (WIA)--stisvc--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\system32\svchost.exe -k imgsvc ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) Telephony--TapiSrv--On Demand--Running--Win32, running in a shared process-- #C:\WINDOWS\System32\svchost.exe -k netsvcs ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) Terminal Services--TermService--On Demand--Running--Win32, running in a shared process-- #C:\WINDOWS\System32\svchost -k DComLaunch ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) Themes--Themes--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\System32\svchost.exe -k netsvcs ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) Distributed Link Tracking Client--TrkWks--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\system32\svchost.exe -k netsvcs ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) Windows User Mode Driver Framework--UMWdf--Automatic--Running--Win32, running in it's own process-- #C:\WINDOWS\system32\wdfmgr.exe ##(Microsoft Corporation [Ver = 5.2.3790.1230 built by: DNSRV(bld4act) | Size = 38912 bytes | Date = 09/22/2004 19:46 | Attr = ]) Universal Plug and Play Device Host--upnphost--On Demand--Running--Win32, running in a shared process-- #C:\WINDOWS\system32\svchost.exe -k LocalService ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) Messenger Sharing USN Journal Reader service--usnsvc--On Demand--Running--Win32, running in it's own process-- #C:\WINDOWS\system32\svchost.exe -k usnsvc ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) Windows Time--W32Time--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\System32\svchost.exe -k netsvcs ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) WebClient--WebClient--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\system32\svchost.exe -k LocalService ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) Windows Management Instrumentation--winmgmt--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\system32\svchost.exe -k netsvcs ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) Security Center--wscsvc--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\System32\svchost.exe -k netsvcs ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) Automatic Updates--wuauserv--Automatic--Running--Win32, running in a shared process-- #C:\WINDOWS\system32\svchost.exe -k netsvcs ##(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Date = 08/04/2004 13:00 | Attr = ]) Files Full Path #Details %SystemDrive% # %ProgramFilesDir% # %WinDir% # %System% # C:\WINDOWS\SYSTEM32\ALSNDMGR.CPL #WSUD (Realtek Semiconductor Corp. [Ver = 2.2.22 | Size = 14250496 bytes | Date = 03/19/2004 03:44 | Attr = ]) C:\WINDOWS\SYSTEM32\dfrg.msc #PEC2 ( [Ver = | Size = 41397 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\KillBox.exe #UPX! (Option^Explicit Software vbtechcd@gmail.com [Ver = 2.00.0881 | Size = 92672 bytes | Date = 10/05/2006 11:37 | Attr = ]) C:\WINDOWS\SYSTEM32\LegitCheckControl.dll #PTech (Microsoft Corporation [Ver = 1.5.0540.0 | Size = 571184 bytes | Date = 06/19/2006 16:19 | Attr = ]) C:\WINDOWS\SYSTEM32\MRT.exe #PECompact2 (Microsoft Corporation [Ver = 1.20.1625.0 | Size = 8960936 bytes | Date = 09/11/2006 18:37 | Attr = ]) C:\WINDOWS\SYSTEM32\MRT.exe #aspack (Microsoft Corporation [Ver = 1.20.1625.0 | Size = 8960936 bytes | Date = 09/11/2006 18:37 | Attr = ]) C:\WINDOWS\SYSTEM32\ntdll.dll #aspack (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 708096 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\nusrmgr.cpl #WSUD (Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 257024 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\rasdlg.dll #Umonitor (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 657920 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\wbdbase.deu #winsync ( [Ver = | Size = 1309184 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\WgaTray.exe #PTech (Microsoft Corporation [Ver = 1.5.0540.0 | Size = 304944 bytes | Date = 06/19/2006 16:19 | Attr = ]) %System%\Drivers folder and sub-folders # C:\WINDOWS\SYSTEM32\drivers\avg7core.sys #UPX! (GRISOFT, s.r.o. [Ver = 7,1,0,407 | Size = 778656 bytes | Date = 09/20/2006 20:00 | Attr = ]) C:\WINDOWS\SYSTEM32\drivers\avg7core.sys #FSG! (GRISOFT, s.r.o. [Ver = 7,1,0,407 | Size = 778656 bytes | Date = 09/20/2006 20:00 | Attr = ]) C:\WINDOWS\SYSTEM32\drivers\avg7core.sys #PEC2 (GRISOFT, s.r.o. [Ver = 7,1,0,407 | Size = 778656 bytes | Date = 09/20/2006 20:00 | Attr = ]) C:\WINDOWS\SYSTEM32\drivers\avg7core.sys #aspack (GRISOFT, s.r.o. [Ver = 7,1,0,407 | Size = 778656 bytes | Date = 09/20/2006 20:00 | Attr = ]) %windir% + sub-dirs for System or Hidden files less than 60 days old # C:\WINDOWS\bootstat.dat # ( [Ver = | Size = 2048 bytes | Date = 10/09/2006 07:29 | Attr = S]) C:\WINDOWS\QTFont.qfn # ( [Ver = | Size = 54156 bytes | Date = 10/09/2006 20:59 | Attr = H ]) C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB922582.cat # ( [Ver = | Size = 11749 bytes | Date = 08/21/2006 14:00 | Attr = S]) C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB925486.cat # ( [Ver = | Size = 8847 bytes | Date = 09/18/2006 15:40 | Attr = S]) C:\WINDOWS\system32\config\default.LOG # ( [Ver = | Size = 1024 bytes | Date = 10/09/2006 19:25 | Attr = H ]) C:\WINDOWS\system32\config\SAM.LOG # ( [Ver = | Size = 1024 bytes | Date = 10/09/2006 10:01 | Attr = H ]) C:\WINDOWS\system32\config\SECURITY.LOG # ( [Ver = | Size = 1024 bytes | Date = 10/09/2006 07:39 | Attr = H ]) C:\WINDOWS\system32\config\software.LOG # ( [Ver = | Size = 1024 bytes | Date = 10/09/2006 22:17 | Attr = H ]) C:\WINDOWS\system32\config\system.LOG # ( [Ver = | Size = 1024 bytes | Date = 10/09/2006 20:46 | Attr = H ]) C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG # ( [Ver = | Size = 1024 bytes | Date = 09/13/2006 22:22 | Attr = H ]) C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Content\303572DF538EDD8B1D606185F1D559B8 # ( [Ver = | Size = 341 bytes | Date = 10/06/2006 11:47 | Attr = S]) C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Content\79841F8EF00FBA86D33CC5A47696F165 # ( [Ver = | Size = 413 bytes | Date = 10/06/2006 11:47 | Attr = S]) C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaData\303572DF538EDD8B1D606185F1D559B8 # ( [Ver = | Size = 126 bytes | Date = 10/06/2006 11:47 | Attr = S]) C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaData\79841F8EF00FBA86D33CC5A47696F165 # ( [Ver = | Size = 98 bytes | Date = 10/06/2006 11:47 | Attr = S]) C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\6cb103b5-d513-495e-9d78-4b98288cc59f # ( [Ver = | Size = 388 bytes | Date = 08/30/2006 06:24 | Attr = HS]) C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\Preferred # ( [Ver = | Size = 24 bytes | Date = 08/30/2006 06:24 | Attr = HS]) C:\WINDOWS\Tasks\SA.DAT # ( [Ver = | Size = 6 bytes | Date = 10/09/2006 07:29 | Attr = H ]) CPL files # C:\WINDOWS\SYSTEM32\access.cpl # (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 68608 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\ALSNDMGR.CPL # (Realtek Semiconductor Corp. [Ver = 2.2.22 | Size = 14250496 bytes | Date = 03/19/2004 03:44 | Attr = ]) C:\WINDOWS\SYSTEM32\appwiz.cpl # (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 549888 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\BDEADMIN.CPL # ( [Ver = | Size = 183808 bytes | Date = 11/12/1999 05:11 | Attr = ]) C:\WINDOWS\SYSTEM32\bthprops.cpl # (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 110592 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\ClientCpl.cpl # ( [Ver = | Size = 141824 bytes | Date = 10/09/2003 20:38 | Attr = ]) C:\WINDOWS\SYSTEM32\desk.cpl # (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 135168 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\firewall.cpl # (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 80384 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\hdwwiz.cpl # (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 155136 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\inetcpl.cpl # (Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 358400 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\intl.cpl # (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 129536 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\irprops.cpl # (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 380416 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\joy.cpl # (Microsoft Corporation [Ver = 5.03.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 68608 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\jpicpl32.cpl # (Sun Microsystems, Inc. [Ver = 5.0.60.5 | Size = 49265 bytes | Date = 11/10/2005 14:03 | Attr = ]) C:\WINDOWS\SYSTEM32\main.cpl # (Microsoft Corporation [Ver = 5.1.2403.1 | Size = 187904 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\mmsys.cpl # (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 618496 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\ncpa.cpl # (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 35840 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\netsetup.cpl # (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 25600 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\nusrmgr.cpl # (Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 257024 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\odbccp32.cpl # (Microsoft Corporation [Ver = 3.525.1117.0 (xpsp_sp2_rtm.040803-2158) | Size = 32768 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\powercfg.cpl # (Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 114688 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\QuickTime.cpl # (Apple Computer, Inc. [Ver = 6.5 | Size = 323072 bytes | Date = 12/14/2003 10:20 | Attr = ]) C:\WINDOWS\SYSTEM32\sysdm.cpl # (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 298496 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\telephon.cpl # (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 28160 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\timedate.cpl # (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 94208 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\wscui.cpl # (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 148480 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\wuaucpl.cpl # (Microsoft Corporation [Ver = 5.8.0.2469 built by: lab01_n(wmbla) | Size = 174360 bytes | Date = 05/26/2005 04:16 | Attr = ]) C:\WINDOWS\SYSTEM32\dllcache\access.cpl # (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 68608 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\dllcache\appwiz.cpl # (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 549888 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\dllcache\desk.cpl # (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 135168 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\dllcache\firewall.cpl # (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 80384 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\dllcache\hdwwiz.cpl # (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 155136 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\dllcache\inetcpl.cpl # (Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 358400 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\dllcache\intl.cpl # (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 129536 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\dllcache\joy.cpl # (Microsoft Corporation [Ver = 5.03.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 68608 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\dllcache\main.cpl # (Microsoft Corporation [Ver = 5.1.2403.1 | Size = 187904 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\dllcache\mmsys.cpl # (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 618496 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\dllcache\ncpa.cpl # (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 35840 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\dllcache\netsetup.cpl # (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 25600 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\dllcache\nusrmgr.cpl # (Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 257024 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\dllcache\odbccp32.cpl # (Microsoft Corporation [Ver = 3.525.1117.0 (xpsp_sp2_rtm.040803-2158) | Size = 32768 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\dllcache\powercfg.cpl # (Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 114688 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\dllcache\sapi.cpl # (Microsoft Corporation [Ver = 5.1.4111.00 (xpsp_sp2_rtm.040803-2158) | Size = 155648 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\dllcache\sysdm.cpl # (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 298496 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\dllcache\telephon.cpl # (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 28160 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\dllcache\timedate.cpl # (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 94208 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\dllcache\wscui.cpl # (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 148480 bytes | Date = 08/04/2004 13:00 | Attr = ]) C:\WINDOWS\SYSTEM32\dllcache\wuaucpl.cpl # (Microsoft Corporation [Ver = 5.8.0.2469 built by: lab01_n(wmbla) | Size = 174360 bytes | Date = 05/26/2005 04:16 | Attr = ]) Auto-Start Folders # HKLM->Explorer\Shell Folders\\Common Startup # = C:\Documents and Settings\All Users\Start Menu\Programs\Startup C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini #( [Ver = | Size = 84 bytes | Date = 02/02/2005 15:33 | Attr = HS]) HKLM->Explorer\User Shell Folders\\Common Startup # = %ALLUSERSPROFILE%\Start Menu\Programs\Startup HKLM->Explorer\Shell Folders\\Startup # = C:\Documents and Settings\Frank Wilson\Start Menu\Programs\Startup C:\Documents and Settings\Frank Wilson\Start Menu\Programs\Startup\desktop.ini #( [Ver = | Size = 84 bytes | Date = 02/02/2005 15:33 | Attr = HS]) HKCU->Explorer\User Shell Folders\\Startup # = %USERPROFILE%\Start Menu\Programs\Startup Miscellaneous Auto-Start Files # System.ini->[Boot]\\Shell #Explorer.exe Config.nt: Line 1 #REM Windows MS-DOS Startup File Config.nt: Line 2 #REM Config.nt: Line 3 #REM CONFIG.SYS vs CONFIG.NT Config.nt: Line 4 #REM CONFIG.SYS is not used to initialize the MS-DOS environment. Config.nt: Line 5 #REM CONFIG.NT is used to initialize the MS-DOS environment unless a Config.nt: Line 6 #REM different startup file is specified in an application's PIF. Config.nt: Line 7 #REM Config.nt: Line 8 #REM ECHOCONFIG Config.nt: Line 9 #REM By default, no information is displayed when the MS-DOS environment Config.nt: Line 10 #REM is initialized. To display CONFIG.NT/AUTOEXEC.NT information, add Config.nt: Line 11 #REM the command echoconfig to CONFIG.NT or other startup file. Config.nt: Line 12 #REM Config.nt: Line 13 #REM NTCMDPROMPT Config.nt: Line 14 #REM When you return to the command prompt from a TSR or while running an Config.nt: Line 15 #REM MS-DOS-based application, Windows runs COMMAND.COM. This allows the Config.nt: Line 16 #REM TSR to remain active. To run CMD.EXE, the Windows command prompt, Config.nt: Line 17 #REM rather than COMMAND.COM, add the command ntcmdprompt to CONFIG.NT or Config.nt: Line 18 #REM other startup file. Config.nt: Line 19 #REM Config.nt: Line 20 #REM DOSONLY Config.nt: Line 21 #REM By default, you can start any type of application when running Config.nt: Line 22 #REM COMMAND.COM. If you start an application other than an MS-DOS-based Config.nt: Line 23 #REM application, any running TSR may be disrupted. To ensure that only Config.nt: Line 24 #REM MS-DOS-based applications can be started, add the command dosonly to Config.nt: Line 25 #REM CONFIG.NT or other startup file. Config.nt: Line 26 #REM Config.nt: Line 27 #REM EMM Config.nt: Line 28 #REM You can use EMM command line to configure EMM(Expanded Memory Manager). Config.nt: Line 29 #REM The syntax is: Config.nt: Line 30 #REM Config.nt: Line 31 #REM EMM = [A=AltRegSets] [B=BaseSegment] [RAM] Config.nt: Line 32 #REM Config.nt: Line 33 #REM AltRegSets Config.nt: Line 34 #REM specifies the total Alternative Mapping Register Sets you Config.nt: Line 35 #REM want the system to support. 1 <= AltRegSets <= 255. The Config.nt: Line 36 #REM default value is 8. Config.nt: Line 37 #REM BaseSegment Config.nt: Line 38 #REM specifies the starting segment address in the Dos conventional Config.nt: Line 39 #REM memory you want the system to allocate for EMM page frames. Config.nt: Line 40 #REM The value must be given in Hexdecimal. Config.nt: Line 41 #REM 0x1000 <= BaseSegment <= 0x4000. The value is rounded down to Config.nt: Line 42 #REM 16KB boundary. The default value is 0x4000 Config.nt: Line 43 #REM RAM Config.nt: Line 44 #REM specifies that the system should only allocate 64Kb address Config.nt: Line 45 #REM space from the Upper Memory Block(UMB) area for EMM page frames Config.nt: Line 46 #REM and leave the rests(if available) to be used by DOS to support Config.nt: Line 47 #REM loadhigh and devicehigh commands. The system, by default, would Config.nt: Line 48 #REM allocate all possible and available UMB for page frames. Config.nt: Line 49 #REM Config.nt: Line 50 #REM The EMM size is determined by pif file(either the one associated Config.nt: Line 51 #REM with your application or _default.pif). If the size from PIF file Config.nt: Line 52 #REM is zero, EMM will be disabled and the EMM line will be ignored. Config.nt: Line 53 #REM Config.nt: Line 54 #dos=high, umb Config.nt: Line 55 #device=%SystemRoot%\system32\himem.sys Config.nt: Line 56 #files=40 AutoExec.nt: Line 1 #@echo off AutoExec.nt: Line 3 #REM AUTOEXEC.BAT is not used to initialize the MS-DOS environment. AutoExec.nt: Line 4 #REM AUTOEXEC.NT is used to initialize the MS-DOS environment unless a AutoExec.nt: Line 5 #REM different startup file is specified in an application's PIF. AutoExec.nt: Line 7 #REM Install CD ROM extensions AutoExec.nt: Line 8 #lh %SystemRoot%\system32\mscdexnt.exe AutoExec.nt: Line 10 #REM Install network redirector (load before dosx.exe) AutoExec.nt: Line 11 #lh %SystemRoot%\system32\redir AutoExec.nt: Line 13 #REM Install DPMI support AutoExec.nt: Line 14 #lh %SystemRoot%\system32\dosx AutoExec.nt: Line 16 #REM The following line enables Sound Blaster 2.0 support on NTVDM. AutoExec.nt: Line 17 #REM The command for setting the BLASTER environment is as follows: AutoExec.nt: Line 18 #REM SET BLASTER=A220 I5 D1 P330 AutoExec.nt: Line 19 #REM where: AutoExec.nt: Line 20 #REM A specifies the sound blaster's base I/O port AutoExec.nt: Line 21 #REM I specifies the interrupt request line AutoExec.nt: Line 22 #REM D specifies the 8-bit DMA channel AutoExec.nt: Line 23 #REM P specifies the MPU-401 base I/O port AutoExec.nt: Line 24 #REM T specifies the type of sound blaster card AutoExec.nt: Line 25 #REM 1 - Sound Blaster 1.5 AutoExec.nt: Line 26 #REM 2 - Sound Blaster Pro I AutoExec.nt: Line 27 #REM 3 - Sound Blaster 2.0 AutoExec.nt: Line 28 #REM 4 - Sound Blaster Pro II AutoExec.nt: Line 29 #REM 6 - SOund Blaster 16/AWE 32/32/64 AutoExec.nt: Line 30 #REM AutoExec.nt: Line 31 #REM The default value is A220 I5 D1 T3 and P330. If any of the switches is AutoExec.nt: Line 32 #REM left unspecified, the default value will be used. (NOTE, since all the AutoExec.nt: Line 33 #REM ports are virtualized, the information provided here does not have to AutoExec.nt: Line 34 #REM match the real hardware setting.) NTVDM supports Sound Blaster 2.0 only. AutoExec.nt: Line 35 #REM The T switch must be set to 3, if specified. AutoExec.nt: Line 36 #SET BLASTER=A220 I5 D1 P330 T3 AutoExec.nt: Line 38 #REM To disable the sound blaster 2.0 support on NTVDM, specify an invalid AutoExec.nt: Line 39 #REM SB base I/O port address. For example: AutoExec.nt: Line 40 #REM SET BLASTER=A0 AutoExec.bat: Line 1 #PATH=%PATH%;C:\PROGRA~1\COMMON~1\MUVEET~1\030625 Miscellaneous Folders # AllUsers ApplicationData Folder # C:\Documents and Settings\All Users\Application Data\desktop.ini # ( [Ver = | Size = 62 bytes | Date = 02/02/2005 15:18 | Attr = HS]) CurrentUser ApplicationData Folder # C:\Documents and Settings\Frank Wilson\Application Data\desktop.ini # ( [Ver = | Size = 62 bytes | Date = 02/02/2005 15:18 | Attr = HS]) Program Files Folder # Common Files Folder # DPF files # {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} #CKAVWebScan Object - CodeBase = http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab {166B1BCA-3F9C-11CF-8075-444553540000} #Shockwave ActiveX Control - CodeBase = http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab {17492023-C23A-453E-A040-C7C580BBF700} #Windows Genuine Advantage Validation Tool - CodeBase = http://go.microsoft.com/fwlink/?linkid=39204 {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} #Office Update Installation Engine - CodeBase = http://office.microsoft.com/officeupdate/content/opuc.cab {56336BCB-3D8A-11D6-A00B-0050DA18DE71} # - CodeBase = http://software-dl.real.com/256c8b649e32dc99ad16/netzip/RdxIE601.cab {6414512B-B978-451D-A0D8-FCFDF33E833C} #WUWebControl Class - CodeBase = http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1107391929781 {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} #MUWebControl Class - CodeBase = http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1136729356812 {8AD9C840-044E-11D1-B3E9-00805F499D93} #Java Plug-in 1.5.0_06 - CodeBase = http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab {9D190AE6-C81E-4039-8061-978EBAD10073} #F-Secure Online Scanner 3.0 - CodeBase = http://support.f-secure.com/ols3/fscax.cab {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} #Java Plug-in 1.5.0_01 - CodeBase = http://java.sun.com/update/1.5.0/jinstall-1_5_0_01-windows-i586.cab {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} #Java Plug-in 1.5.0_02 - CodeBase = http://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} #Java Plug-in 1.5.0_04 - CodeBase = http://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} #Java Plug-in 1.5.0_06 - CodeBase = http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} #Java Plug-in 1.5.0_06 - CodeBase = http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab {D27CDB6E-AE6D-11CF-96B8-444553540000} # - CodeBase = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Hosts file = 1264 bytes. Reading all entries. #C:\WINDOWS\System32\drivers\etc\Hosts # Copyright (c) 1993-1999 Microsoft Corp. # # # # This is a sample HOSTS file used by Microsoft TCP/IP for Windows. # # # # This file contains the mappings of IP addresses to host names. Each # # entry should be kept on an individual line. The IP address should # # be placed in the first column followed by the corresponding host name. # # The IP address and the host name should be separated by at least one # # space. # # # # Additionally, comments (such as these) may be inserted on individual # # lines or following the machine name denoted by a '#' symbol. # # # # For example: # # # # 102.54.94.97 rhino.acme.com # source server # # 38.25.63.10 x.acme.com # x client host # # 127.0.0.1 localhost # 10.0.0.1 netgear #router firewall # 10.0.0.11 notebook #notebook win98 # 10.0.0.12 musicstation #pentium p500 win98 # 10.0.0.14 miffy #nec pentium xp home # 10.0.0.15 debian #debian compaq server # 10.0.0.15 mompctest #musiconmypc test server # 10.0.0.16 toshiba #toshiba laptop # 10.0.0.17 franksdesk #athlon64 # 10.0.0.18 piebox #pentium p3 redhat machine # 10.0.0.18 mompc #musiconmypc test site # 10.0.0.18 vanilla #vanilla oscommerce test site # 10.0.0.18 dudetest #dudespot test site # 10.0.0.18 monkeytest #monkeybooks test site # 10.0.0.18 sscctest #sscctest # 127.0.0.1 localhost #