Tech Support Forum banner

HJT Log report help

3944 Views 31 Replies 2 Participants Last post by  Aaflac
My computer was resently infected with hldrrr.exe

when I tried to restart in safemode the computer only gave me the blue screen of death:
stop: 0x0000007B (0xF8955528, 0xC0000034,0x00000000, 0x00000000)

The system will not reboot without a win-xp boot disk from A: drive
which I downloaded with my other computer from www.bootdisk.com

I had to rename HJT program to (Help.exe.bak) in order to get it to work
otherwise the virus would recognize the program and shut it down.

The computer is off line and will not allow any anti-virus software or anti-spyware to load or run.

Below is the HTJ Log, any help would be greatly appreciated.

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 5:55:37 PM, on 08/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Bell\Security Manager\Fws.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
C:\Program Files\Dantz\Retrospect\retrorun.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe
C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ezSP_Px.exe
C:\WINDOWS\system32\TPWRTRAY.EXE
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe
C:\Program Files\TOSHIBA\TME3\TMESBS32.EXE
C:\WINDOWS\system32\TFNF5.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Bell\Security Manager\Rps.exe
C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe
C:\WINDOWS\MXOALDR.EXE
C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\System32\00THotkey.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\Program Files\Orbitdownloader\orbitdm.exe
C:\Program Files\Bell\Security Manager\rpsupdaterR.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\Orbitdownloader\orbitnet.exe
C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
C:\Program Files\ePrompter\ePrompter.exe
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
C:\Documents and Settings\Jay\Desktop\Help.exe.bak.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ca.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Bell\Security Manager\pkR.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [TosHKCW.exe] "C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe"
O4 - HKLM\..\Run: [TMESBS.EXE] C:\Program Files\TOSHIBA\TME3\TMESBS32.EXE /Client
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe /Type 28
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Sympatico Security Manager] "C:\Program Files\Bell\Security Manager\Rps.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SSA.exe] "C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe" /AUTORUN
O4 - HKLM\..\Run: [PmProxy] C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [Drag'n Drop CD] C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe /StartUp
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [-FreedomNeedsReboot] "C:\Program Files\Bell\Security Manager\ZkRunOnceR.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\RunOnce: [IndexCleaner] "C:\Program Files\Bell\Security Manager\IdxClnR.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\RunOnce: [IndexCleaner] "C:\Program Files\Bell\Security Manager\IdxClnR.exe"
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: ePrompter.lnk = C:\Program Files\ePrompter\ePrompter.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Orbit.lnk = C:\Program Files\Orbitdownloader\orbitdm.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O4 - Global Startup: WordWeb Pro.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - Global Startup: ZDWLan Utility.lnk = C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\system32\wweb32.dll/lookup.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1195746499328
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u3-windows-i586-jc.cab
O16 - DPF: {C4847596-972C-11D0-9567-00A0C9273C2A} (Crystal Report Viewer Control) - http://web1.dillon.ca/viewer/activeXViewer/activexviewer.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: intu-qt2007 - {026BF40D-BA05-467B-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll
O20 - AppInit_DLLs:
O20 - Winlogon Notify: pagecnt32 - C:\WINDOWS\SYSTEM32\pagecnt32.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\retrorun.exe
O23 - Service: Sympatico Security Manager Update Service (RPSUpdaterR) - Radialpoint Inc. - C:\Program Files\Bell\Security Manager\rpsupdaterR.exe
O23 - Service: Sympatico Security Manager Firewall (RP_FWS) - Bell Sympatico - C:\Program Files\Bell\Security Manager\Fws.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Tmesbs32 (Tmesbs) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe

--
End of file - 12752 bytes
See less See more
Status
Not open for further replies.
1 - 20 of 32 Posts
Apologies for the delay in responding.

The workload on this forum is intense, and sometimes it is not possible to respond to every
inquiry.


Please read the following carefully before downloading the program indicated. If this procedure is not done as directed, it does not work!!
Also, in the event you already downloaded ComboFix, this is a new version, so please remove the version you have.


Download ComboFix
Save to the Desktop <<< Important!!
  • During the download, rename Combofix to Combo-Fix as follows:


  • Please do not rename ComboFix to any other name, but only to the one indicated: Combo-Fix
  • Close any open browsers, and close/disable your AntiVirus and any AntiSpyware programs so they do not interfere with the running of Combo-Fix.
  • Double click on Combo-Fix.exe and follow the prompts.
    [*]Combo-Fix disconnects the computer from the Internet as soon as it starts
    [*]Please do not attempt to re-connect to the Internet until Combo-Fix has completely finished.
    [*]If there is no Internet connection after running Combo-Fix, then restart the computer to restore the connection.​
  • Do not click on the window while the program is running, it may cause the system to stall.
  • When finished, the program produces a report: C:\Combo-Fix.txt

~~~~
Run HijackThis once again to obtain a new log.

~~~~
Please post the Combo-Fix.txt, and a new HijackThis log in your reply.
See less See more
ComboFix 08-03-22.1 - Admin 2008-03-22 11:45:13.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.184 [GMT -4:00]
Running from: C:\Documents and Settings\Admin\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-02-22 to 2008-03-22 )))))))))))))))))))))))))))))))
.

2008-03-22 12:01 . 2008-03-22 12:01 6,736 --a------ C:\WINDOWS\system32\drivers\PROCEXP90.SYS
2008-03-21 19:20 . 2008-03-21 19:20 <DIR> d-------- C:\Program Files\Acesoft
2008-03-21 19:20 . 2007-01-23 00:43 277,504 --a------ C:\WINDOWS\system32\oestore.dll
2008-03-21 19:20 . 2004-03-09 00:00 224,016 --a------ C:\WINDOWS\system32\TabCtl32.ocx
2008-03-21 13:11 . 2008-03-21 13:13 <DIR> d-------- C:\Program Files\StorageCrypt v2.0
2008-03-17 17:13 . 2008-03-17 17:24 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-17 17:10 . 2008-03-17 18:18 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-03-17 17:10 . 2004-03-09 00:00 132,880 --a------ C:\WINDOWS\system32\msinet.ocx
2008-03-17 15:41 . 2008-03-17 15:41 <DIR> d-------- C:\Program Files\COMODO
2008-03-17 15:41 . 2008-03-17 16:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\comodo
2008-03-17 15:41 . 2008-03-17 15:41 <DIR> d-------- C:\Documents and Settings\Admin\Application Data\Comodo
2008-03-17 15:41 . 2008-03-17 15:41 139,008 --a------ C:\WINDOWS\system32\guard32.dll
2008-03-17 15:41 . 2008-03-17 15:41 85,112 --a------ C:\WINDOWS\system32\drivers\cmdguard.sys
2008-03-17 15:41 . 2008-03-17 15:41 23,800 --a------ C:\WINDOWS\system32\drivers\cmdhlp.sys
2008-03-16 22:00 . 2008-03-16 22:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-03-16 22:00 . 2004-04-27 04:40 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2008-03-16 22:00 . 2008-03-16 22:02 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-03-16 21:59 . 2008-03-17 16:52 <DIR> d-------- C:\WINDOWS\system32\ZoneLabs
2008-03-16 21:57 . 2008-03-17 16:52 <DIR> d-------- C:\WINDOWS\Internet Logs
2008-03-16 18:54 . 2008-03-22 11:45 <DIR> d-------- C:\QUARANTINE
2008-03-16 18:35 . 2008-03-16 18:35 <DIR> d-------- C:\Program Files\Common Files\Cisco Systems
2008-03-16 18:35 . 2008-03-16 18:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-03-16 18:35 . 2006-12-19 15:06 1,495,552 --a------ C:\WINDOWS\system32\epoPGPsdk.dll
2008-03-16 18:35 . 2006-11-30 08:50 72,264 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-03-16 18:35 . 2006-11-30 08:50 64,360 --a------ C:\WINDOWS\system32\drivers\mfeapfk.sys
2008-03-16 18:35 . 2006-11-30 08:50 34,152 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2008-03-16 18:35 . 2006-12-19 15:06 280 --a------ C:\WINDOWS\system32\epoPGPsdk.dll.sig
2008-03-16 18:34 . 2008-03-16 18:35 <DIR> d-------- C:\Program Files\McAfee
2008-03-16 18:34 . 2008-03-16 18:34 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-03-16 18:34 . 2007-02-22 20:50 170,408 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2008-03-16 18:34 . 2006-11-30 08:50 52,136 --a------ C:\WINDOWS\system32\drivers\mfetdik.sys
2008-03-16 14:07 . 2008-03-16 14:07 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-03-16 13:57 . 2008-03-16 14:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Raxco(2)
2008-03-16 13:02 . 2007-12-01 18:01 1,291,880 --a------ C:\WINDOWS\wweb32.dll
2008-03-16 11:02 . 2008-03-16 13:05 <DIR> d-------- C:\Documents and Settings\Admin\Application Data\WordWeb
2008-03-16 10:49 . 2008-03-16 10:49 0 --a------ C:\hpfr5550.xml
2008-03-16 10:47 . 2008-03-16 21:23 <DIR> d-------- C:\Program Files\hp deskjet 5550 series
2008-03-16 10:47 . 2008-03-16 21:23 811 --a------ C:\WINDOWS\hpinfo.lnk
2008-03-16 10:46 . 2002-12-09 20:19 147,512 --a------ C:\WINDOWS\system32\hpzlnt07.dll
2008-03-16 00:10 . 2008-03-16 21:47 <DIR> d-------- C:\Program Files\Xvid
2008-03-16 00:10 . 2007-06-28 18:52 765,952 --a------ C:\WINDOWS\system32\xvidcore.dll
2008-03-16 00:10 . 2007-06-28 18:54 180,224 --a------ C:\WINDOWS\system32\xvidvfw.dll
2008-03-16 00:10 . 2007-06-28 18:55 77,824 --a------ C:\WINDOWS\system32\xvid.ax
2008-03-13 19:36 . 2008-03-13 19:36 <DIR> d-------- C:\Program Files\QuickTime
2008-03-11 17:24 . 2008-03-12 20:07 <DIR> d-------- C:\Documents and Settings\Admin\Application Data\AdobeUM
2008-03-11 09:05 . 2007-04-09 13:23 28,040 --a------ C:\WINDOWS\system32\mdimon.dll
2008-03-11 09:05 . 2008-03-11 09:05 376 --a------ C:\WINDOWS\ODBC.INI
2008-03-11 09:04 . 2008-03-11 09:04 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-03-11 09:04 . 2008-03-11 09:04 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-03-11 09:02 . 2008-03-11 09:04 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-03-11 09:00 . 2008-03-11 09:00 <DIR> dr-h----- C:\MSOCache
2008-03-11 08:49 . 2008-03-11 08:49 <DIR> d-------- C:\Program Files\PowerISO
2008-03-10 22:48 . 2008-03-10 22:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Azureus
2008-03-10 22:47 . 2008-03-21 19:19 <DIR> d-------- C:\Documents and Settings\Admin\Application Data\Azureus
2008-03-10 22:20 . 2008-03-16 14:07 <DIR> d-------- C:\Program Files\WordWeb
2008-03-10 22:12 . 2008-03-10 22:12 <DIR> d-------- C:\Documents and Settings\Admin\Application Data\Media Player Classic
2008-03-10 22:07 . 2008-03-22 11:33 <DIR> d-------- C:\Program Files\ePrompter
2008-03-10 22:07 . 2008-03-22 11:32 16,215 --a------ C:\WINDOWS\ePrompter.ini
2008-03-10 22:06 . 2008-03-10 23:00 <DIR> d-------- C:\Downloads
2008-03-10 21:24 . 2008-03-10 21:24 <DIR> d-------- C:\Program Files\Lavasoft
2008-03-10 21:24 . 2008-03-10 21:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-10 21:23 . 2008-03-10 21:23 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-10 21:18 . 2008-03-10 21:18 <DIR> d-------- C:\Program Files\Eltima Software
2008-03-10 21:18 . 2008-03-10 21:18 <DIR> d-------- C:\Documents and Settings\Admin\Application Data\Eltima Software
2008-03-10 21:12 . 2008-03-10 21:12 <DIR> d-------- C:\Program Files\eRightSoft
2008-03-10 21:02 . 2008-03-10 21:02 <DIR> d-------- C:\Program Files\AviSynth 2.5
2008-03-10 21:02 . 2004-02-22 11:11 719,872 --a------ C:\WINDOWS\system32\devil.dll
2008-03-10 21:02 . 2006-10-07 18:43 502,784 --a------ C:\WINDOWS\x2.64.exe
2008-03-10 21:02 . 2007-11-13 10:31 399,360 --a------ C:\WINDOWS\system32\Smab.dll
2008-03-10 21:02 . 2007-05-17 18:30 318,976 --a------ C:\WINDOWS\system32\avisynth.dll
2008-03-10 21:02 . 2005-02-28 14:16 240,128 --a------ C:\WINDOWS\system32\x.264.exe
2008-03-10 21:02 . 2006-04-12 10:47 217,073 --a------ C:\WINDOWS\meta4.exe
2008-03-10 21:02 . 2004-01-25 01:00 70,656 --a------ C:\WINDOWS\system32\yv12vfw.dll
2008-03-10 21:02 . 2004-01-25 01:00 70,656 --a------ C:\WINDOWS\system32\i420vfw.dll
2008-03-10 21:02 . 2006-04-05 09:09 66,560 --a------ C:\WINDOWS\MOTA113.exe
2008-03-10 21:02 . 2005-07-14 13:31 27,648 --a------ C:\WINDOWS\system32\AVSredirect.dll
2008-03-10 21:01 . 2005-02-12 19:00 186,880 -r-hs---- C:\WINDOWS\system32\RLOgg.ax
2008-03-10 21:01 . 2005-01-17 19:26 179,200 -r-hs---- C:\WINDOWS\system32\DiracSplitter.ax
2008-03-10 21:01 . 2006-08-16 10:53 175,104 -r-hs---- C:\WINDOWS\system32\CoreAAC.ax
2008-03-10 21:01 . 2005-02-05 19:00 92,672 -r-hs---- C:\WINDOWS\system32\RLVorbisDec.ax
2008-03-10 21:01 . 2005-02-22 12:55 81,920 -r-hs---- C:\WINDOWS\system32\aac_parser.ax
2008-03-10 21:01 . 2005-02-12 19:00 67,584 -r-hs---- C:\WINDOWS\system32\RLTheoraDec.ax
2008-03-10 21:01 . 2005-02-12 19:00 51,712 -r-hs---- C:\WINDOWS\system32\RLSpeexDec.ax
2008-03-10 20:54 . 2008-03-10 21:37 <DIR> d-------- C:\Program Files\Orbitdownloader
2008-03-10 20:54 . 2008-03-21 18:31 <DIR> d-------- C:\Documents and Settings\Admin\Application Data\Orbit
2008-03-10 20:45 . 2008-03-10 20:45 <DIR> d-------- C:\Program Files\Azureus
2008-03-10 20:39 . 2008-03-12 00:47 <DIR> d-------- C:\Program Files\Real Alternative
2008-03-10 20:20 . 2008-03-10 20:20 <DIR> d-------- C:\Program Files\Dantz
2008-03-10 20:08 . 2008-03-10 20:08 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-03-10 20:08 . 2008-03-10 20:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-03-10 19:51 . 2008-03-10 19:51 <DIR> d-------- C:\Program Files\Hewlett-Packard
2008-03-10 19:50 . 2002-12-09 20:19 270,336 --a------ C:\WINDOWS\system32\hpzcon07.dll
2008-03-10 19:50 . 2002-12-09 20:19 208,896 --a------ C:\WINDOWS\system32\hpzcoi07.dll
2008-03-10 19:44 . 2006-10-04 10:06 1,197,294 -----c--- C:\WINDOWS\system32\dllcache\sysmain.sdb
2008-03-10 19:44 . 2006-10-04 10:06 764,868 -----c--- C:\WINDOWS\system32\dllcache\apph_sp.sdb
2008-03-10 19:44 . 2006-10-04 10:06 217,118 -----c--- C:\WINDOWS\system32\dllcache\apphelp.sdb
2008-03-10 19:43 . 2008-03-10 19:43 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-03-10 19:41 . 2008-03-10 19:41 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-03-10 19:41 . 2008-03-10 19:42 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-03-10 19:03 . 2008-03-10 19:03 <DIR> d-------- C:\Program Files\Password 2000

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-16 22:29 --------- d-----w C:\Program Files\InstallShield Installation Information
2008-03-11 00:06 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-10 22:44 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-03-10 15:36 --------- d-----w C:\Program Files\Toshiba
2008-02-04 19:26 151,040 --sh--w C:\WINDOWS\system32\VistaUltm.dll
2006-05-03 10:06 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll
2007-02-21 11:47 31,232 --sh--r C:\WINDOWS\system32\msfDX.dll
2007-12-17 13:43 27,648 --sh--w C:\WINDOWS\system32\Smab0.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-03-10 11:41 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"00THotkey"="C:\WINDOWS\System32\00THotkey.exe" [2002-12-24 15:28 253952]
"000StTHK"="000StTHK.exe" [2001-06-24 00:28 24576 C:\WINDOWS\system32\000StTHK.exe]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2002-12-04 01:22 126976]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2002-12-04 01:21 569344]
"Tpwrtray"="TPWRTRAY.EXE" [2002-12-10 14:49 237568 C:\WINDOWS\system32\TPWRTRAY.EXE]
"TouchED"="C:\Program Files\TOSHIBA\TouchED\TouchED.Exe" [2002-07-31 15:41 126976]
"TFncKy"="TFncKy.exe" []
"TosHKCW.exe"="C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe" [2002-09-09 19:07 49152]
"NDSTray.exe"="C:\Program Files\Toshiba\ConfigFree\NDSTray.exe" [2002-12-11 11:42 450560]
"TMESBS.EXE"="C:\Program Files\TOSHIBA\TME3\TMESBS32.exe" [2002-09-05 20:08 77824]
"TFNF5"="TFNF5.exe" [2001-08-03 04:08 73728 C:\WINDOWS\system32\TFNF5.exe]
"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [2002-08-19 21:29 40960]
"Drag'n Drop CD"="C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe" [2002-11-13 22:10 802816]
"NvCplDaemon"="NvQTwk" []
"nwiz"="nwiz.exe" [2002-12-12 17:17 438272 C:\WINDOWS\system32\nwiz.exe]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2002-11-24 21:23 172032]
"MaxtorOneTouch"="C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe" [2003-05-21 16:30 45056]
"MXO Auto Loader"="C:\WINDOWS\MXOALDR.EXE" [2003-04-07 19:09 118784]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2005-03-23 19:26 217088]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2006-01-12 20:52 483328]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-13 19:36 385024]
"ShStatEXE"="C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.exe" [2007-02-22 20:50 112216]
"McAfeeUpdaterUI"="C:\Program Files\McAfee\Common Framework\UdaterUI.exe" [2006-12-19 11:27 136768]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2002-12-09 20:19 188416]
"COMODO Firewall Pro"="C:\Program Files\COMODO\Firewall\cfp.exe" [2008-03-17 15:41 1503488]

C:\Documents and Settings\Admin\Start Menu\Programs\Startup\
ePrompter.lnk - C:\Program Files\ePrompter\ePrompter.exe [2008-03-10 22:07:36 782336]
WordWeb Pro.lnk - C:\Program Files\WordWeb\wweb32.exe [2008-03-16 13:02:50 44384]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2008-03-10 20:08:02 25214]
LUMIX Simple Viewer.lnk - C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe [2008-03-10 18:44:25 57344]
Orbit.lnk - C:\Program Files\Orbitdownloader\orbitdm.exe [2008-03-10 20:54:44 1674440]
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2003-01-06 20:14:17 151552]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= C:\WINDOWS\system32\guard32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PmProxy]
--a------ 2002-11-13 21:04 40960 C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"C:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=

R0 TVALG;Toshiba Value Added Logical and General Purpose Device Driver;C:\WINDOWS\system32\DRIVERS\TVALG.SYS [2001-09-13 23:53]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2008-03-17 15:41]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2008-03-17 15:41]
R2 Tmesbs;Tmesbs32;"C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe" /Service []
R3 tsdhd;TOSHIBA SD Card Host Controller Driver;C:\WINDOWS\system32\DRIVERS\tsdhd.sys [2002-11-05 07:02]
S3 pciSd;pciSd;C:\WINDOWS\system32\DRIVERS\tossdpci.sys [2002-10-08 22:18]
S3 tosrfec;Bluetooth ACPI from TOSHIBA;C:\WINDOWS\system32\DRIVERS\tosrfec.sys [2002-12-13 04:16]
S3 wlags48b;Wireless LAN PCCard Driver;C:\WINDOWS\system32\DRIVERS\wlags48b.sys [2002-06-27 19:29]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-22 12:03:43
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\guard32.dll

PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\WINDOWS\system32\guard32.dll
.
Completion time: 2008-03-22 12:04:46
ComboFix-quarantined-files.txt 2008-03-22 16:04:35
.
2008-03-12 14:08:47 --- E O F ---


Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 12:08:35 PM, on 22/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe
C:\WINDOWS\System32\00THotkey.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\TPWRTRAY.EXE
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\TME3\TMESBS32.EXE
C:\WINDOWS\system32\TFNF5.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
C:\WINDOWS\MXOALDR.EXE
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\Program Files\Orbitdownloader\orbitdm.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\ePrompter\ePrompter.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Orbitdownloader\orbitnet.exe
C:\WINDOWS\explorer.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\Documents and Settings\Admin\Desktop\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ca.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe /Type 28
O4 - HKLM\..\Run: [TosHKCW.exe] "C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe"
O4 - HKLM\..\Run: [NDSTray.exe] "C:\Program Files\Toshiba\ConfigFree\NDSTray.exe"
O4 - HKLM\..\Run: [TMESBS.EXE] C:\Program Files\TOSHIBA\TME3\TMESBS32.EXE /Client
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Drag'n Drop CD] C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe /StartUp
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: ePrompter.lnk = C:\Program Files\ePrompter\ePrompter.exe
O4 - Startup: WordWeb Pro.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
O4 - Global Startup: Orbit.lnk = C:\Program Files\Orbitdownloader\orbitdm.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\system32\wweb32.dll/lookup.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1205163774112
O16 - DPF: {C4847596-972C-11D0-9567-00A0C9273C2A} (Crystal Report Viewer Control) - http://web1.dillon.ca/viewer/activeXViewer/activexviewer.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Tmesbs32 (Tmesbs) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe

--
End of file - 11017 bytes
See less See more
Please open Notepad (Start > Run > in the Open field type: notepad)
Click: OK
  • Copy/paste all the content of the code box below:
  • Save it as Options.txt , on your Desktop, and as type"All Files"

RegSearch Options File

[Search]
hldrrr
srosa
drvsyskit
wintems
FirstRRRun
Down
mdelk

[Exclude]

[Options]
Filter=KVDLU
Next, download Registry Search.zip
Save to the Desktop.
  • Right-click and select: Extract all…
  • Click on the Registry Search icon on your desktop to open the program.
  • Click regsearch.exe to start the program.
  • Click on "Import" and Select the file "Options.txt" that you created above, located on the Desktop.
  • Click "OK" and Registry Search will search the Registry and report what it finds.
Please post the Registry Search results in your reply.
See less See more
Windows Registry Editor Version 5.00

; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.5.0

; Results at 22/03/2008 2:48:39 PM for strings:
; 'hldrrr'
; 'srosa'
; 'drvsyskit'
; 'wintems'
; 'firstrrrun'
; 'down'
; 'mdelk'
; Strings excluded from search:
; (None)
; Search in:
; Registry Keys Registry Values Registry Data
; HKEY_LOCAL_MACHINE HKEY_USERS


[HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Adobe Acrobat\7.0\FeatureLockDown]

[HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Adobe Acrobat\7.0\FeatureLockDown\cDefaultLaunchAttachmentPerms]

[HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Adobe Acrobat\7.0\FeatureLockDown\cDefaultLaunchURLPerms]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.dll]
"Content Type"="application/x-msdownload"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe]
"Content Type"="application/x-msdownload"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Adobe.AcroIEBackgroundDownloadEventSi.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Adobe.AcroIEBackgroundDownloadEventSi.1]
@="AcroIEBackgroundDownloadEventSink Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Adobe.AcroIEBackgroundDownloadEventSi.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Adobe.AcroIEBackgroundDownloadEventSin]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Adobe.AcroIEBackgroundDownloadEventSin]
@="AcroIEBackgroundDownloadEventSink Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Adobe.AcroIEBackgroundDownloadEventSin\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Adobe.AcroIEBackgroundDownloadEventSin\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Adobe.AcroIEBackgroundDownloadEventSin\CurVer]
@="Adobe.AcroIEBackgroundDownloadEventSi.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Azureus]
@="Azureus Vuze Download"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000123B4-9B42-4900-B3F7-F4B073EFC214}\InprocServer32]
@="C:\\Program Files\\Orbitdownloader\\orbitcth.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0FDF6D6B-D672-463B-846E-C6FF49109662}]
@="RealPlayer Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0FDF6D6B-D672-463B-846E-C6FF49109662}\ProgID]
@="rmocx.RealPlayer Download Handler.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0FDF6D6B-D672-463B-846E-C6FF49109662}\VersionIndependentProgID]
@="rmocx.RealPlayer Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{13FA5947-561C-11D1-BE3F-00A0C95A6A5C}\InprocServer32]
@="C:\\WINDOWS\\Downloaded Program Files\\CRViewer.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20EDB660-7CDD-11CF-8DAB-00AA006C1A01}]
@="Internet Explorer Ratings Downloader"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{224E833B-2CC6-42D9-AE39-90B6A38A4FA2}]
@="RealPlayer SMIL Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{224E833B-2CC6-42D9-AE39-90B6A38A4FA2}\ProgID]
@="rmocx.RealPlayer SMIL Download Handler.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{224E833B-2CC6-42D9-AE39-90B6A38A4FA2}\VersionIndependentProgID]
@="rmocx.RealPlayer SMIL Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{22BF0C20-6DA7-11D0-B373-00A0C9034938}]
@="Download Status"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93}]
@="RealPlayer RAM Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93}\ProgID]
@="rmocx.RealPlayer RAM Download Handler.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93}\VersionIndependentProgID]
@="rmocx.RealPlayer RAM Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3050f5be-98b5-11cf-bb82-00aa00bdce0b}]
@="DownloadBehavior Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3050f5be-98b5-11cf-bb82-00aa00bdce0b}\ProgID]
@="DownloadBehavior.DownloadBehavior.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3050f5be-98b5-11cf-bb82-00aa00bdce0b}\VersionIndependentProgID]
@="DownloadBehavior.DownloadBehavior"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3B5E0503-DE28-4BE8-919C-76E0E894A3C2}]
@="RealPlayer RNX Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3B5E0503-DE28-4BE8-919C-76E0E894A3C2}\ProgID]
@="rmocx.RealPlayer RNX Download Handler.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3B5E0503-DE28-4BE8-919C-76E0E894A3C2}\VersionIndependentProgID]
@="rmocx.RealPlayer RNX Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F1D494B-0CEF-4468-96C9-386E2E4DEC90}\InprocServer32]
@="C:\\Program Files\\Orbitdownloader\\orbitmxt.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{44CCBCEB-BA7E-4C99-A078-9F683832D493}]
@="RealPlayer RMP Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{44CCBCEB-BA7E-4C99-A078-9F683832D493}\ProgID]
@="rmocx.RealPlayer RMP Download Handler.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{44CCBCEB-BA7E-4C99-A078-9F683832D493}\VersionIndependentProgID]
@="rmocx.RealPlayer RMP Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5BAF654A-5A07-4264-A255-9FF54C7151E7}]
@="UpdateDownloader Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5BAF654A-5A07-4264-A255-9FF54C7151E7}\ProgID]
@="Microsoft.Update.Downloader.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5BAF654A-5A07-4264-A255-9FF54C7151E7}\VersionIndependentProgID]
@="Microsoft.Update.Downloader"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71C140F3-1A84-430b-9035-68815582DC79}\InprocServer32]
@="C:\\WINDOWS\\Downloaded Program Files\\reportparameterdialog.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71C140F3-1A84-430b-9035-68815582DC79}\ToolboxBitmap32]
@="C:\\WINDOWS\\Downloaded Program Files\\reportparameterdialog.dll, 101"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{75347086-7260-11D1-BE46-00A0C95A6A5C}\InprocServer32]
@="C:\\WINDOWS\\Downloaded Program Files\\CRViewer.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{75C66E66-8949-11D2-BF6D-00A0C9DA4FA2}\InprocServer32]
@="C:\\WINDOWS\\Downloaded Program Files\\CRViewer.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{75C66E68-8949-11D2-BF6D-00A0C9DA4FA2}\InprocServer32]
@="C:\\WINDOWS\\Downloaded Program Files\\CRViewer.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7854F00C-DC77-477E-A10E-603F48442D3B}]
@="Customdown Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7854F00C-DC77-477E-A10E-603F48442D3B}\InprocServer32]
@="C:\\Program Files\\Orbitdownloader\\orbitcth.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7854F00C-DC77-477E-A10E-603F48442D3B}\ProgID]
@="Orbitcth.Customdown.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7854F00C-DC77-477E-A10E-603F48442D3B}\VersionIndependentProgID]
@="Orbitcth.Customdown"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7D559C10-9FE9-11d0-93F7-00AA0059CE02}]
@="Code Download Agent"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8369AB20-56C9-11D0-94E8-00AA0059CE02}]
@="Cleaner for Downloaded Program Files"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9FB78BEE-4BCB-4627-8672-86B64B8AED5A}]
@="AcroIEBackgroundDownloadEventSink Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9FB78BEE-4BCB-4627-8672-86B64B8AED5A}\ProgID]
@="Adobe.AcroIEBackgroundDownloadEventSi.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9FB78BEE-4BCB-4627-8672-86B64B8AED5A}\VersionIndependentProgID]
@="Adobe.AcroIEBackgroundDownloadEventSin"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A0E5F37E-CA67-11D1-A817-00A0C92784CD}\InprocServer32]
@="C:\\WINDOWS\\Downloaded Program Files\\CRViewer.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3E41207-BE04-492A-AFF0-19E880FF7545}]
@="WMI instrumentation: Win32_ComputerShutdownEvent"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B9BE4CB0-3A20-11D3-A5F0-00A0C9A40F1D}\InprocServer32]
@="C:\\WINDOWS\\Downloaded Program Files\\reportparameterdialog.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BD10A9C1-07CC-11D2-BEFF-00A0C95A6A5C}\InprocServer32]
@="C:\\WINDOWS\\Downloaded Program Files\\sviewhlp.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BFC880F1-7484-11d0-8309-00AA00B6015C}]
@="Download Site Manager"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4847596-972C-11D0-9567-00A0C9273C2A}\InprocServer32]
@="C:\\WINDOWS\\Downloaded Program Files\\CRViewer.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4847596-972C-11D0-9567-00A0C9273C2A}\ToolboxBitmap32]
@="C:\\WINDOWS\\Downloaded Program Files\\CRViewer.dll, 1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C69E8F40-D5C8-11D0-A520-145405C10000}]
@="Indeo Video (r) 5.1 Progressive Download Source"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C69E8F41-D5C8-11D0-A520-145405C10000}]
@="Indeo Video (r) 5.1 Progressive Download Source About"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C69E8F42-D5C8-11D0-A520-145405C10000}]
@="Indeo Video (r) 5.1 Progressive Download Source Static Info"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C69E8F43-D5C8-11D0-A520-145405C10000}]
@="Indeo Video (r) 5.1 Progressive Download Source Dynamic Info"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F2CA2115-C8D2-11D1-BEBD-00A0C95A6A5C}\InprocServer32]
@="C:\\WINDOWS\\Downloaded Program Files\\swebrs.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F2CA2119-C8D2-11D1-BEBD-00A0C95A6A5C}\InprocServer32]
@="C:\\WINDOWS\\Downloaded Program Files\\swebrs.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DownloadBehavior.DownloadBehavior]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DownloadBehavior.DownloadBehavior]
@="DownloadBehavior Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DownloadBehavior.DownloadBehavior\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DownloadBehavior.DownloadBehavior\CurVer]
@="DownloadBehavior.DownloadBehavior.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DownloadBehavior.DownloadBehavior.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DownloadBehavior.DownloadBehavior.1]
@="DownloadBehavior Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DownloadBehavior.DownloadBehavior.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\FDF19CE3A9EF5D34694CA8C942735200\SourceList]
; Contents of value:
; n;1;C:\WINDOWS\Downloaded Installations\{BB90C5EA-6B3A-4AB2-A040-3B416E91787A}\
"LastUsedSource"=hex(2):6e,00,3b,00,31,00,3b,00,43,00,3a,00,5c,00,57,00,49,00,\
4e,00,44,00,4f,00,57,00,53,00,5c,00,44,00,6f,00,77,00,6e,00,6c,00,6f,00,61,\
00,64,00,65,00,64,00,20,00,49,00,6e,00,73,00,74,00,61,00,6c,00,6c,00,61,00,\
74,00,69,00,6f,00,6e,00,73,00,5c,00,7b,00,42,00,42,00,39,00,30,00,43,00,35,\
00,45,00,41,00,2d,00,36,00,42,00,33,00,41,00,2d,00,34,00,41,00,42,00,32,00,\
2d,00,41,00,30,00,34,00,30,00,2d,00,33,00,42,00,34,00,31,00,36,00,45,00,39,\
00,31,00,37,00,38,00,37,00,41,00,7d,00,5c,00,00,00

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\FDF19CE3A9EF5D34694CA8C942735200\SourceList\Net]
; Contents of value:
; C:\WINDOWS\Downloaded Installations\{BB90C5EA-6B3A-4AB2-A040-3B416E91787A}\
"1"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,5c,00,\
44,00,6f,00,77,00,6e,00,6c,00,6f,00,61,00,64,00,65,00,64,00,20,00,49,00,6e,\
00,73,00,74,00,61,00,6c,00,6c,00,61,00,74,00,69,00,6f,00,6e,00,73,00,5c,00,\
7b,00,42,00,42,00,39,00,30,00,43,00,35,00,45,00,41,00,2d,00,36,00,42,00,33,\
00,41,00,2d,00,34,00,41,00,42,00,32,00,2d,00,41,00,30,00,34,00,30,00,2d,00,\
33,00,42,00,34,00,31,00,36,00,45,00,39,00,31,00,37,00,38,00,37,00,41,00,7d,\
00,5c,00,00,00

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}]
@="IRundown"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0002088B-0000-0000-C000-000000000046}]
@="DropDown"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0002088C-0000-0000-C000-000000000046}]
@="DropDowns"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{000208C6-0000-0000-C000-000000000046}]
@="DownBars"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00020925-0000-0000-C000-000000000046}]
@="DropDown"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00024703-0000-0000-C000-000000000046}]
@="DownBars"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{094B316F-7C55-404E-A0C2-17A589FA7A2E}]
@="ISusDownloadCallback"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0A319C7F-85F9-436C-B88E-82FD88000E1C}]
@="IWMPDownloadCollection"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{14170A90-183E-415A-A16D-9FBDFE76FF75}]
@="IWMDownloadDestinationInfo"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{203C06F8-5C88-4073-ABD5-12FD4F41E4E2}]
@="IWMDownloadCallback"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3050F5BD-98B5-11CF-BB82-00AA00BDCE0B}]
@="IDownloadBehavior"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{324FF2C6-4981-4B04-9412-57481745AB24}]
@="IDownloadProgressChangedCallbackArgs"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3CD141F4-3C6A-11D2-BCAA-00C04FD929DB}]
@="IAutoCompleteDropDown"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{48FF3109-A366-4B56-B340-01FAE758BA64}]
@="_IWmiProviderAbnormalShutdown"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4AD6A88B-AAEB-4234-AD09-9B0E449313E0}]
@="IWMDownload"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{54A2CB2D-9A0C-48B6-8A50-9ABB69EE2D02}]
@="IUpdateDownloadContent"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5B945024-DC8C-4C06-B262-E29A10AE15ED}]
@="IWMDownloadMgr"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{68F1C6F9-7ECC-4666-A464-247FE12496C3}]
@="IUpdateDownloader"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{77254866-9F5B-4C8E-B9E2-C77A8530D64B}]
@="IDownloadCompletedCallback"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{794A71CD-C835-4A19-ACAE-BA287D7942BE}]
@="IWMDownloadContext"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7AAA2D24-B37A-4E11-82C1-E071246463A4}]
@="IWMPDownloadCollection"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7CB647D7-F02A-4B13-A2FC-2E22BD0D45B5}]
@="IWMDownloadCore"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7FA5509F-B1E3-4CB5-BD4A-749018A96C5E}]
@="IAcroIEBackgroundDownloadEventSink"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8C3F1CDD-6173-4591-AEBD-A56A53CA77C1}]
@="IDownloadProgressChangedCallback"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9FBB3336-6DA3-479D-B8FF-67D46E20A987}]
@="IWMPDownloadItem2"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A26B97B2-A28D-4008-B034-FA1622E04C20}]
@="ICustomdown"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A91708E4-F1BD-463E-8E2D-C9101FA3DB37}]
@="IWMPBkgDownload"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A951B11A-C712-45B3-B884-2469A6243368}]
@="ITIMEMediaDownloader"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A976C28D-75A1-42AA-94AE-8AF8B872089A}]
@="IUpdateLockdown"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}]
@="IWbemShutdown"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BC5513C8-B3B8-4BF7-A4D4-361C0D8C88BA}]
@="IUpdateDownloadContentCollection"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BF99AF76-B575-42AD-8AA4-33CBB5477AF1}]
@="IUpdateDownloadResult"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C574DE85-7358-43F6-AAE8-8697E62D8BA7}]
@="IDownloadJob"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C9470E8E-3F6B-46A9-A0A9-452815C34297}]
@="IWMPDownloadItem"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C97AD11B-F257-420B-9D9F-377F733F6F68}]
@="IUpdateDownloadContent2"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CB8DD6DE-8A11-4FAE-B2AD-CD82D0CDCCDD}]
@="IWMDownload2"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D31A5BAC-F719-4178-9DBB-5E2CB47FD18A}]
@="IDownloadProgress"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DAA4FDD0-4727-4DBE-A1E7-745DCA317144}]
@="IDownloadResult"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DD8D4A1A-8187-41E9-AC76-5D128F0AA0F5}]
@="IAutoUpdateInstallAtShutdown"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E15E9AD1-8F20-4CC4-9EC7-1A328CA86A0D}]
@="IWMPDownloadManager"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FA565B23-498C-47A0-979D-E7D5B1813360}]
@="IDownloadCompletedCallbackArgs"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.Update.Downloader]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.Update.Downloader]
@="UpdateDownloader Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.Update.Downloader\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.Update.Downloader\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.Update.Downloader\CurVer]
@="Microsoft.Update.Downloader.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.Update.Downloader.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.Update.Downloader.1]
@="UpdateDownloader Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.Update.Downloader.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Orbitcth.Customdown]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Orbitcth.Customdown]
@="Customdown Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Orbitcth.Customdown\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Orbitcth.Customdown\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Orbitcth.Customdown\CurVer]
@="Orbitcth.Customdown.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Orbitcth.Customdown.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Orbitcth.Customdown.1]
@="Customdown Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Orbitcth.Customdown.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer Download Handler]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer Download Handler]
@="RealPlayer Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer Download Handler\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer Download Handler\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer Download Handler\CurVer]
@="rmocx.RealPlayer Download Handler.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer Download Handler.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer Download Handler.1]
@="RealPlayer Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer Download Handler.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RAM Download Handler]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RAM Download Handler]
@="RealPlayer RAM Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RAM Download Handler\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RAM Download Handler\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RAM Download Handler\CurVer]
@="rmocx.RealPlayer RAM Download Handler.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RAM Download Handler.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RAM Download Handler.1]
@="RealPlayer RAM Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RAM Download Handler.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RMP Download Handler]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RMP Download Handler]
@="RealPlayer RMP Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RMP Download Handler\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RMP Download Handler\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RMP Download Handler\CurVer]
@="rmocx.RealPlayer RMP Download Handler.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RMP Download Handler.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RMP Download Handler.1]
@="RealPlayer RMP Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RMP Download Handler.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RNX Download Handler]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RNX Download Handler]
@="RealPlayer RNX Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RNX Download Handler\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RNX Download Handler\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RNX Download Handler\CurVer]
@="rmocx.RealPlayer RNX Download Handler.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RNX Download Handler.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RNX Download Handler.1]
@="RealPlayer RNX Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RNX Download Handler.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer SMIL Download Handler]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer SMIL Download Handler]
@="RealPlayer SMIL Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer SMIL Download Handler\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer SMIL Download Handler\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer SMIL Download Handler\CurVer]
@="rmocx.RealPlayer SMIL Download Handler.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer SMIL Download Handler.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer SMIL Download Handler.1]
@="RealPlayer SMIL Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer SMIL Download Handler.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{1BEB5790-E4C7-11D3-A625-00A0C9A40F1D}\1.0\0\win32]
@="C:\\WINDOWS\\Downloaded Program Files\\reportparameterdialog.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{1BEB5790-E4C7-11D3-A625-00A0C9A40F1D}\1.0\HELPDIR]
@="C:\\WINDOWS\\Downloaded Program Files\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A0880527-DC28-4EBB-BA27-D22102F22A9F}\1.0\0\win32]
@="C:\\Program Files\\Orbitdownloader\\orbitmxt.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A0880527-DC28-4EBB-BA27-D22102F22A9F}\1.0\HELPDIR]
@="C:\\Program Files\\Orbitdownloader\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{BCDDE143-FAE3-4C57-B22B-C4E8678CFDC0}\1.0\0\win32]
@="C:\\Program Files\\Orbitdownloader\\orbitcth.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{BD10A9B3-07CC-11D2-BEFF-00A0C95A6A5C}\1.0\0\win32]
@="C:\\WINDOWS\\Downloaded Program Files\\sviewhlp.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{BD10A9B3-07CC-11D2-BEFF-00A0C95A6A5C}\1.0\HELPDIR]
@="C:\\WINDOWS\\Downloaded Program Files\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C4847593-972C-11D0-9567-00A0C9273C2A}\8.0\0\win32]
@="C:\\WINDOWS\\Downloaded Program Files\\CRViewer.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C4847593-972C-11D0-9567-00A0C9273C2A}\8.0\HELPDIR]
@="C:\\WINDOWS\\Downloaded Program Files\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F2CA2107-C8D2-11D1-BEBD-00A0C95A6A5C}\1.1\0\win32]
@="C:\\WINDOWS\\Downloaded Program Files\\swebrs.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F2CA2107-C8D2-11D1-BEBD-00A0C95A6A5C}\1.1\HELPDIR]
@="C:\\WINDOWS\\Downloaded Program Files\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WMDFile]
@="Windows Media Player Download Package"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore]
"LockDownEnabled"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\On Access Scanner\McShield\Configuration]
"bScanFloppyOnShutdown"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\DirectAnimation Java Classes\DownloadInformation]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\DirectAnimation Java Classes\DownloadInformation]
"OSD"="C:\\WINDOWS\\Downloaded Program Files\\DirectAnimation Java Classes.osd"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\DownloadInformation]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\DownloadInformation]
"OSD"="C:\\WINDOWS\\Downloaded Program Files\\Microsoft XML Parser for Java.osd"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}\DownloadInformation]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}\DownloadInformation]
"INF"="C:\\WINDOWS\\Downloaded Program Files\\QTPlugin.inf"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{6414512B-B978-451D-A0D8-FCFDF33E833C}\DownloadInformation]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{6414512B-B978-451D-A0D8-FCFDF33E833C}\DownloadInformation]
"INF"="C:\\WINDOWS\\Downloaded Program Files\\wuweb.inf"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\DownloadInformation]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\DownloadInformation]
"CODEBASE"="http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab"
"INF"="C:\\WINDOWS\\Downloaded Program Files\\erma.inf"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{C4847596-972C-11D0-9567-00A0C9273C2A}\Contains\Files]
"C:\\WINDOWS\\Downloaded Program Files\\reportparameterdialog.dll"=""
"C:\\WINDOWS\\Downloaded Program Files\\CRViewer.dll"=""
"C:\\WINDOWS\\Downloaded Program Files\\sviewhlp.dll"=""
"C:\\WINDOWS\\Downloaded Program Files\\swebrs.dll"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{C4847596-972C-11D0-9567-00A0C9273C2A}\DownloadInformation]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{C4847596-972C-11D0-9567-00A0C9273C2A}\DownloadInformation]
"INF"="C:\\WINDOWS\\Downloaded Program Files\\crviewer.inf"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{D41E4F1F-A407-11D1-8BC9-00C04FA30A41}]
"$Function"="CORLockDownProvider"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DownloadManager]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer]
"DownloadUI"="{7854F00C-DC77-477E-A10E-603F48442D3B}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\BROWSE\NOTIFYDOWNLOADCOMPLETE]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\BROWSE\NOTIFYDOWNLOADCOMPLETE]
"Text"="Notify when downloads complete"
"ValueName"="NotifyDownloadComplete"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\CRYPTO\CD_LMZ_LOCKDOWN]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\CRYPTO\CD_LMZ_LOCKDOWN]
"RegPath"="SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_LOCALMACHINE_LOCKDOWN\\Settings"
"RegPoliciesPath"="SOFTWARE\\Policies\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_LOCALMACHINE_LOCKDOWN\\Settings"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\CRYPTO\CHECK_SIG]
"RegPath"="SOFTWARE\\Microsoft\\Internet Explorer\\Download"
"Text"="Check for signatures on downloaded programs"
"RegPoliciesPath"="SOFTWARE\\Policies\\Microsoft\\Internet Explorer\\Download"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\CRYPTO\LMZ_LOCKDOWN]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\CRYPTO\LMZ_LOCKDOWN]
"RegPath"="SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_LOCALMACHINE_LOCKDOWN"
"RegPoliciesPath"="SOFTWARE\\Policies\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_LOCALMACHINE_LOCKDOWN"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\CRYPTO\RUN_INV_SIG]
"RegPath"="SOFTWARE\\Microsoft\\Internet Explorer\\Download"
"RegPoliciesPath"="SOFTWARE\\Policies\\Microsoft\\Internet Explorer\\Download"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\MULTIMEDIA\PLACEHOLDERS]
"Text"="Show image download placeholders"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Download]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\DragDrop\{2BDB5D05-9A0B-4256-80AF-A920F8C01AE1}}]
; Contents of value:
; C:\Program Files\Orbitdownloader
"AppPath"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,\
20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4f,00,72,00,62,00,69,00,74,00,64,\
00,6f,00,77,00,6e,00,6c,00,6f,00,61,00,64,00,65,00,72,00,00,00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer\Objects\DropDownPlaylist]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer\Objects\DropDownPlaylist\Column]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer\Objects\ItemsPlaylist]
"dropDownVisible"="false"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer\Objects\MuteButton]
"downToolTip"="res://wmploc.dll/RT_STRING/#1808"
"down"="wmpprop:player.settings.mute"
"onClick"="player.settings.mute=down;"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer\Objects\RepeatButton]
"downToolTip"="res://wmploc.dll/RT_STRING/#1817"
"down"="jscript:player.settings.GetMode(\"loop\");"
"onClick"="player.settings.setMode(\"loop\", down);"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer\Objects\SeekSlider]
"foregroundProgress"="wmpprop:player.network.downloadProgress"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer\Objects\ShuffleButton]
"downToolTip"="res://wmploc.dll/RT_STRING/#1815"
"down"="jscript:player.settings.GetMode(\"shuffle\");"
"onClick"="player.settings.setMode(\"shuffle\", down);"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer\Publish\{9AB5C98B-AA7B-4ff4-A8EB-9D8E23C0D59E}]
@="WMPlayer Downlevel CD Burn Publish Provider"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Devices\AudioCD]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Devices\DVD]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.aif]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.aifc]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.aiff]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.asf]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.asx]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.au]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.avi]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.cda]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.dvr-ms]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.m1v]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.m2v]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.m3u]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.mid]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.midi]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.mod]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.mp2]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.mp2v]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.mp3]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.mpa]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.mpe]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.mpeg]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.mpg]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.mpv2]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.rmi]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.snd]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.wav]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.wax]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.wm]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.wma]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.wmd]
"MediaType.Description"="Windows Media Player Download Package"
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.wmv]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.wmx]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.wmz]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.wpl]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.wvx]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\IEHardening]
"FEATURE_LOCALMACHINE_LOCKDOWN"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\application/vnd.ms-wpl]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\application/x-mplayer2]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\application/x-ms-wmd]
@="Windows Media Player Download Package"
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\application/x-ms-wmz]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/aiff]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/basic]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/mid]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/midi]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/mp3]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/mpeg]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/mpegurl]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/mpg]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/wav]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/x-aiff]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/x-mid]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/x-midi]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/x-mp3]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/x-mpeg]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/x-mpegurl]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/x-mpg]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/x-ms-wax]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/x-ms-wma]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/x-wav]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\midi/mid]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\video/avi]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\video/mpeg]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\video/mpg]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\video/msvideo]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\video/x-mpeg]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\video/x-mpeg2a]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\video/x-ms-asf]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\video/x-ms-asf-plugin]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\video/x-ms-wm]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\video/x-ms-wmv]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\video/x-ms-wmx]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\video/x-ms-wvx]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\video/x-msvideo]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Protocols\mms]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Protocols\mmst]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Protocols\mmsu]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Protocols\msbd]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\Internet]
"LocationOfComponents"="C:\\Documents and Settings\\Admin\\My Documents\\Azureus Downloads\\Microsoft Office 2003 Professional\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Delivery\{90110409-6000-11D3-8CFE-0150048383C9}]
"DownloadCode"="90000409-6000-11D3-8CFE-0150048383C9"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\PowerPoint\Translators]
"Downrev"="C:\\Program Files\\Microsoft Office\\OFFICE11\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Registration\{90110409-6000-11D3-8CFE-0150048383C9}]
"SmartSourceDir"="C:\\Documents and Settings\\Admin\\My Documents\\Azureus Downloads\\Microsoft Office 2003 Professional\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Properties]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\A2561405.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\A3561405.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\A4561405.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\AV561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\CC561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\CD561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\CF561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\CL561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\CM561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\CP561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\CR561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\CS561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\DW20.ADM_1033]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\DW20.EXE_0001]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\DWDCW20.DLL]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\DWINTL20.DLL_0001_1033]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\DWTRIG20.EXE]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\E2561410.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\E3561405.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\E4561410.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\EV561405.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\G3561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\GV561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\IJ561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\IS561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\IU561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\L2561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\L3561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\L4561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\L9561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\LV561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\M2561406.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\M3561404.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\M4561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\M9561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\MA561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\MC561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\MG561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\MH561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\MO561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\MT561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\O0561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\O1561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\O9561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\OCLEAN.DLL_1033]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\OCLNCORE.OPC_1033]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\OCLNCUST.OPC_1033]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\OCLNINTL.OPC_1033]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\OFFCLN.EXE_1033]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\OSE.EXE]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\P2561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\P3561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\P4561402.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\PA561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\PR103368.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\PR103678.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\PR308246.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\PRO11.MSI]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\PSS10O.CHM_1033]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\PSS10R.CHM_1033]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\PV561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\PW561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\Q2561405.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\Q3561405.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\Q4561405.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\QV561405.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\SETUP.CHM_1033]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\SKU011.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\SKU011.XML_0002_1033]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\TR103621.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\TR308222.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\V3561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\W2561405.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\W3561405.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\W4561405.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\WV561405.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\X2561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\X3561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\YA561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\YB561408.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\YC561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\YH561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\YI561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\YL561402.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\YM561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\YO561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\YS561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\YT561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZA561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZC561402.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZD561402.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZE561406.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZF561402.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZG561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZH561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZI561402.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZJ561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZK561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZM561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZN561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZO561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZQ561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZR561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZS561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZT561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZU561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZV561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZY561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZZ561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Sources]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Sources\90110409-6000-11D3-8CFE-0150048383C9]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Sources\90110409-6000-11D3-8CFE-0150048383C9]
"Path"="C:\\Documents and Settings\\Admin\\My Documents\\Azureus Downloads\\Microsoft Office 2003 Professional\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\microsoft.watson.alrtintl.data]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\microsoft.watson.alrtintl.data\Properties]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\microsoft.watson.alrtintl.data\Resources]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\microsoft.watson.alrtintl.data\Resources\AlrtIntl.dll]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\microsoft.watson.alrtintl.data\Sources]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\microsoft.watson.alrtintl.data\Sources\alrtintl1033]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\microsoft.watson.watsonrc.data]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\microsoft.watson.watsonrc.data\Properties]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\microsoft.watson.watsonrc.data\Resources]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\microsoft.watson.watsonrc.data\Resources\WatsonRC.dat]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\microsoft.watson.watsonrc.data\Sources]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\microsoft.watson.watsonrc.data\Sources\watsonrcsrc]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Updates\Windows\SP1\NLSDownlevelMapping]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Updates\Windows\SP1\NLSDownlevelMapping]
"PackageName"="Microsoft National Language Support Downlevel APIs"
"Description"="Microsoft National Language Support Downlevel APIs"
"ARPLink"="HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\NLSDownlevelMapping"
"UninstallCommand"="C:\\WINDOWS\\$NtServicePackUninstallNLSDownlevelMapping$\\spuninst\\spuninst.exe "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Updates\Windows\SP1\NLSDownlevelMapping\Filelist]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Updates\Windows\SP1\NLSDownlevelMapping\Filelist\0]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM]
; Contents of value:
; C:\WINDOWS\system32\WBEM\cimwin32.mof
; C:\WINDOWS\system32\WBEM\cimwin32.mfl
; C:\WINDOWS\system32\WBEM\system.mof
; C:\WINDOWS\system32\WBEM\wmipcima.mof
; C:\WINDOWS\system32\WBEM\wmipcima.mfl
; C:\WINDOWS\system32\WBEM\regevent.mof
; C:\WINDOWS\system32\WBEM\regevent.mfl
; C:\WINDOWS\system32\WBEM\ntevt.mof
; C:\WINDOWS\system32\WBEM\ntevt.mfl
; C:\WINDOWS\system32\WBEM\secrcw32.mof
; C:\WINDOWS\system32\WBEM\secrcw32.mfl
; C:\WINDOWS\system32\WBEM\dsprov.mof
; C:\WINDOWS\system32\WBEM\dsprov.mfl
; C:\WINDOWS\system32\WBEM\msi.mof
; C:\WINDOWS\system32\WBEM\msi.mfl
; C:\WINDOWS\system32\WBEM\subscrpt.mof
; C:\WINDOWS\system32\WBEM\wmi.mof
; C:\WINDOWS\system32\WBEM\wmi.mfl
; C:\WINDOWS\system32\WBEM\scm.mof
; C:\WINDOWS\system32\WBEM\fevprov.mof
; C:\WINDOWS\system32\WBEM\fevprov.mfl
; C:\WINDOWS\system32\WBEM\wmitimep.mof
; C:\WINDOWS\system32\WBEM\wmitimep.mfl
; C:\WINDOWS\system32\WBEM\wmipdskq.mof
; C:\WINDOWS\system32\WBEM\wmipdskq.mfl
; C:\WINDOWS\system32\WBEM\wmipicmp.mof
; C:\WINDOWS\system32\WBEM\wmipicmp.mfl
; C:\WINDOWS\system32\WBEM\wmipiprt.mof
; C:\WINDOWS\system32\WBEM\wmipiprt.mfl
; C:\WINDOWS\system32\WBEM\wmipjobj.mof
; C:\WINDOWS\system32\WBEM\wmipjobj.mfl
; C:\WINDOWS\system32\WBEM\wmipsess.mof
; C:\WINDOWS\system32\WBEM\wmipsess.mfl
; C:\WINDOWS\system32\WBEM\krnlprov.mof
; C:\WINDOWS\system32\WBEM\krnlprov.mfl
; C:\WINDOWS\system32\WBEM\tscfgwmi.mof
; C:\WINDOWS\system32\WBEM\tscfgwmi.mfl
; C:\WINDOWS\system32\WBEM\licwmi.mof
; C:\WINDOWS\system32\WBEM\licwmi.mfl
; C:\WINDOWS\system32\WBEM\evntrprv.mof
; C:\WINDOWS\system32\WBEM\hnetcfg.mof
; C:\WINDOWS\system32\WBEM\sr.mof
; C:\WINDOWS\system32\WBEM\dgnet.mof
; C:\WINDOWS\system32\WBEM\whqlprov.mof
; C:\WINDOWS\system32\WBEM\ieinfo5.mof
; c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\licwmi.mof
; C:\WINDOWS\system32\wbem\wscenter.mof
; C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\MSINFO\OINFOP11.MOF
See less See more
Windows Registry Editor Version 5.00

; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.5.0

; Results at 22/03/2008 2:48:39 PM for strings:
; 'hldrrr'
; 'srosa'
; 'drvsyskit'
; 'wintems'
; 'firstrrrun'
; 'down'
; 'mdelk'
; Strings excluded from search:
; (None)
; Search in:
; Registry Keys Registry Values Registry Data
; HKEY_LOCAL_MACHINE HKEY_USERS


[HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Adobe Acrobat\7.0\FeatureLockDown]

[HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Adobe Acrobat\7.0\FeatureLockDown\cDefaultLaunchAttachmentPerms]

[HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Adobe Acrobat\7.0\FeatureLockDown\cDefaultLaunchURLPerms]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.dll]
"Content Type"="application/x-msdownload"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe]
"Content Type"="application/x-msdownload"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Adobe.AcroIEBackgroundDownloadEventSi.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Adobe.AcroIEBackgroundDownloadEventSi.1]
@="AcroIEBackgroundDownloadEventSink Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Adobe.AcroIEBackgroundDownloadEventSi.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Adobe.AcroIEBackgroundDownloadEventSin]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Adobe.AcroIEBackgroundDownloadEventSin]
@="AcroIEBackgroundDownloadEventSink Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Adobe.AcroIEBackgroundDownloadEventSin\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Adobe.AcroIEBackgroundDownloadEventSin\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Adobe.AcroIEBackgroundDownloadEventSin\CurVer]
@="Adobe.AcroIEBackgroundDownloadEventSi.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Azureus]
@="Azureus Vuze Download"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000123B4-9B42-4900-B3F7-F4B073EFC214}\InprocServer32]
@="C:\\Program Files\\Orbitdownloader\\orbitcth.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0FDF6D6B-D672-463B-846E-C6FF49109662}]
@="RealPlayer Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0FDF6D6B-D672-463B-846E-C6FF49109662}\ProgID]
@="rmocx.RealPlayer Download Handler.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0FDF6D6B-D672-463B-846E-C6FF49109662}\VersionIndependentProgID]
@="rmocx.RealPlayer Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{13FA5947-561C-11D1-BE3F-00A0C95A6A5C}\InprocServer32]
@="C:\\WINDOWS\\Downloaded Program Files\\CRViewer.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20EDB660-7CDD-11CF-8DAB-00AA006C1A01}]
@="Internet Explorer Ratings Downloader"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{224E833B-2CC6-42D9-AE39-90B6A38A4FA2}]
@="RealPlayer SMIL Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{224E833B-2CC6-42D9-AE39-90B6A38A4FA2}\ProgID]
@="rmocx.RealPlayer SMIL Download Handler.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{224E833B-2CC6-42D9-AE39-90B6A38A4FA2}\VersionIndependentProgID]
@="rmocx.RealPlayer SMIL Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{22BF0C20-6DA7-11D0-B373-00A0C9034938}]
@="Download Status"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93}]
@="RealPlayer RAM Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93}\ProgID]
@="rmocx.RealPlayer RAM Download Handler.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93}\VersionIndependentProgID]
@="rmocx.RealPlayer RAM Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3050f5be-98b5-11cf-bb82-00aa00bdce0b}]
@="DownloadBehavior Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3050f5be-98b5-11cf-bb82-00aa00bdce0b}\ProgID]
@="DownloadBehavior.DownloadBehavior.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3050f5be-98b5-11cf-bb82-00aa00bdce0b}\VersionIndependentProgID]
@="DownloadBehavior.DownloadBehavior"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3B5E0503-DE28-4BE8-919C-76E0E894A3C2}]
@="RealPlayer RNX Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3B5E0503-DE28-4BE8-919C-76E0E894A3C2}\ProgID]
@="rmocx.RealPlayer RNX Download Handler.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3B5E0503-DE28-4BE8-919C-76E0E894A3C2}\VersionIndependentProgID]
@="rmocx.RealPlayer RNX Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F1D494B-0CEF-4468-96C9-386E2E4DEC90}\InprocServer32]
@="C:\\Program Files\\Orbitdownloader\\orbitmxt.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{44CCBCEB-BA7E-4C99-A078-9F683832D493}]
@="RealPlayer RMP Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{44CCBCEB-BA7E-4C99-A078-9F683832D493}\ProgID]
@="rmocx.RealPlayer RMP Download Handler.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{44CCBCEB-BA7E-4C99-A078-9F683832D493}\VersionIndependentProgID]
@="rmocx.RealPlayer RMP Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5BAF654A-5A07-4264-A255-9FF54C7151E7}]
@="UpdateDownloader Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5BAF654A-5A07-4264-A255-9FF54C7151E7}\ProgID]
@="Microsoft.Update.Downloader.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5BAF654A-5A07-4264-A255-9FF54C7151E7}\VersionIndependentProgID]
@="Microsoft.Update.Downloader"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71C140F3-1A84-430b-9035-68815582DC79}\InprocServer32]
@="C:\\WINDOWS\\Downloaded Program Files\\reportparameterdialog.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71C140F3-1A84-430b-9035-68815582DC79}\ToolboxBitmap32]
@="C:\\WINDOWS\\Downloaded Program Files\\reportparameterdialog.dll, 101"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{75347086-7260-11D1-BE46-00A0C95A6A5C}\InprocServer32]
@="C:\\WINDOWS\\Downloaded Program Files\\CRViewer.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{75C66E66-8949-11D2-BF6D-00A0C9DA4FA2}\InprocServer32]
@="C:\\WINDOWS\\Downloaded Program Files\\CRViewer.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{75C66E68-8949-11D2-BF6D-00A0C9DA4FA2}\InprocServer32]
@="C:\\WINDOWS\\Downloaded Program Files\\CRViewer.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7854F00C-DC77-477E-A10E-603F48442D3B}]
@="Customdown Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7854F00C-DC77-477E-A10E-603F48442D3B}\InprocServer32]
@="C:\\Program Files\\Orbitdownloader\\orbitcth.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7854F00C-DC77-477E-A10E-603F48442D3B}\ProgID]
@="Orbitcth.Customdown.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7854F00C-DC77-477E-A10E-603F48442D3B}\VersionIndependentProgID]
@="Orbitcth.Customdown"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7D559C10-9FE9-11d0-93F7-00AA0059CE02}]
@="Code Download Agent"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8369AB20-56C9-11D0-94E8-00AA0059CE02}]
@="Cleaner for Downloaded Program Files"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9FB78BEE-4BCB-4627-8672-86B64B8AED5A}]
@="AcroIEBackgroundDownloadEventSink Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9FB78BEE-4BCB-4627-8672-86B64B8AED5A}\ProgID]
@="Adobe.AcroIEBackgroundDownloadEventSi.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9FB78BEE-4BCB-4627-8672-86B64B8AED5A}\VersionIndependentProgID]
@="Adobe.AcroIEBackgroundDownloadEventSin"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A0E5F37E-CA67-11D1-A817-00A0C92784CD}\InprocServer32]
@="C:\\WINDOWS\\Downloaded Program Files\\CRViewer.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3E41207-BE04-492A-AFF0-19E880FF7545}]
@="WMI instrumentation: Win32_ComputerShutdownEvent"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B9BE4CB0-3A20-11D3-A5F0-00A0C9A40F1D}\InprocServer32]
@="C:\\WINDOWS\\Downloaded Program Files\\reportparameterdialog.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BD10A9C1-07CC-11D2-BEFF-00A0C95A6A5C}\InprocServer32]
@="C:\\WINDOWS\\Downloaded Program Files\\sviewhlp.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BFC880F1-7484-11d0-8309-00AA00B6015C}]
@="Download Site Manager"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4847596-972C-11D0-9567-00A0C9273C2A}\InprocServer32]
@="C:\\WINDOWS\\Downloaded Program Files\\CRViewer.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4847596-972C-11D0-9567-00A0C9273C2A}\ToolboxBitmap32]
@="C:\\WINDOWS\\Downloaded Program Files\\CRViewer.dll, 1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C69E8F40-D5C8-11D0-A520-145405C10000}]
@="Indeo Video (r) 5.1 Progressive Download Source"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C69E8F41-D5C8-11D0-A520-145405C10000}]
@="Indeo Video (r) 5.1 Progressive Download Source About"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C69E8F42-D5C8-11D0-A520-145405C10000}]
@="Indeo Video (r) 5.1 Progressive Download Source Static Info"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C69E8F43-D5C8-11D0-A520-145405C10000}]
@="Indeo Video (r) 5.1 Progressive Download Source Dynamic Info"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F2CA2115-C8D2-11D1-BEBD-00A0C95A6A5C}\InprocServer32]
@="C:\\WINDOWS\\Downloaded Program Files\\swebrs.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F2CA2119-C8D2-11D1-BEBD-00A0C95A6A5C}\InprocServer32]
@="C:\\WINDOWS\\Downloaded Program Files\\swebrs.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DownloadBehavior.DownloadBehavior]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DownloadBehavior.DownloadBehavior]
@="DownloadBehavior Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DownloadBehavior.DownloadBehavior\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DownloadBehavior.DownloadBehavior\CurVer]
@="DownloadBehavior.DownloadBehavior.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DownloadBehavior.DownloadBehavior.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DownloadBehavior.DownloadBehavior.1]
@="DownloadBehavior Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DownloadBehavior.DownloadBehavior.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\FDF19CE3A9EF5D34694CA8C942735200\SourceList]
; Contents of value:
; n;1;C:\WINDOWS\Downloaded Installations\{BB90C5EA-6B3A-4AB2-A040-3B416E91787A}\
"LastUsedSource"=hex(2):6e,00,3b,00,31,00,3b,00,43,00,3a,00,5c,00,57,00,49,00,\
4e,00,44,00,4f,00,57,00,53,00,5c,00,44,00,6f,00,77,00,6e,00,6c,00,6f,00,61,\
00,64,00,65,00,64,00,20,00,49,00,6e,00,73,00,74,00,61,00,6c,00,6c,00,61,00,\
74,00,69,00,6f,00,6e,00,73,00,5c,00,7b,00,42,00,42,00,39,00,30,00,43,00,35,\
00,45,00,41,00,2d,00,36,00,42,00,33,00,41,00,2d,00,34,00,41,00,42,00,32,00,\
2d,00,41,00,30,00,34,00,30,00,2d,00,33,00,42,00,34,00,31,00,36,00,45,00,39,\
00,31,00,37,00,38,00,37,00,41,00,7d,00,5c,00,00,00

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\FDF19CE3A9EF5D34694CA8C942735200\SourceList\Net]
; Contents of value:
; C:\WINDOWS\Downloaded Installations\{BB90C5EA-6B3A-4AB2-A040-3B416E91787A}\
"1"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,5c,00,\
44,00,6f,00,77,00,6e,00,6c,00,6f,00,61,00,64,00,65,00,64,00,20,00,49,00,6e,\
00,73,00,74,00,61,00,6c,00,6c,00,61,00,74,00,69,00,6f,00,6e,00,73,00,5c,00,\
7b,00,42,00,42,00,39,00,30,00,43,00,35,00,45,00,41,00,2d,00,36,00,42,00,33,\
00,41,00,2d,00,34,00,41,00,42,00,32,00,2d,00,41,00,30,00,34,00,30,00,2d,00,\
33,00,42,00,34,00,31,00,36,00,45,00,39,00,31,00,37,00,38,00,37,00,41,00,7d,\
00,5c,00,00,00

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}]
@="IRundown"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0002088B-0000-0000-C000-000000000046}]
@="DropDown"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0002088C-0000-0000-C000-000000000046}]
@="DropDowns"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{000208C6-0000-0000-C000-000000000046}]
@="DownBars"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00020925-0000-0000-C000-000000000046}]
@="DropDown"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00024703-0000-0000-C000-000000000046}]
@="DownBars"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{094B316F-7C55-404E-A0C2-17A589FA7A2E}]
@="ISusDownloadCallback"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0A319C7F-85F9-436C-B88E-82FD88000E1C}]
@="IWMPDownloadCollection"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{14170A90-183E-415A-A16D-9FBDFE76FF75}]
@="IWMDownloadDestinationInfo"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{203C06F8-5C88-4073-ABD5-12FD4F41E4E2}]
@="IWMDownloadCallback"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3050F5BD-98B5-11CF-BB82-00AA00BDCE0B}]
@="IDownloadBehavior"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{324FF2C6-4981-4B04-9412-57481745AB24}]
@="IDownloadProgressChangedCallbackArgs"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3CD141F4-3C6A-11D2-BCAA-00C04FD929DB}]
@="IAutoCompleteDropDown"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{48FF3109-A366-4B56-B340-01FAE758BA64}]
@="_IWmiProviderAbnormalShutdown"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4AD6A88B-AAEB-4234-AD09-9B0E449313E0}]
@="IWMDownload"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{54A2CB2D-9A0C-48B6-8A50-9ABB69EE2D02}]
@="IUpdateDownloadContent"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5B945024-DC8C-4C06-B262-E29A10AE15ED}]
@="IWMDownloadMgr"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{68F1C6F9-7ECC-4666-A464-247FE12496C3}]
@="IUpdateDownloader"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{77254866-9F5B-4C8E-B9E2-C77A8530D64B}]
@="IDownloadCompletedCallback"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{794A71CD-C835-4A19-ACAE-BA287D7942BE}]
@="IWMDownloadContext"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7AAA2D24-B37A-4E11-82C1-E071246463A4}]
@="IWMPDownloadCollection"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7CB647D7-F02A-4B13-A2FC-2E22BD0D45B5}]
@="IWMDownloadCore"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7FA5509F-B1E3-4CB5-BD4A-749018A96C5E}]
@="IAcroIEBackgroundDownloadEventSink"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8C3F1CDD-6173-4591-AEBD-A56A53CA77C1}]
@="IDownloadProgressChangedCallback"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9FBB3336-6DA3-479D-B8FF-67D46E20A987}]
@="IWMPDownloadItem2"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A26B97B2-A28D-4008-B034-FA1622E04C20}]
@="ICustomdown"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A91708E4-F1BD-463E-8E2D-C9101FA3DB37}]
@="IWMPBkgDownload"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A951B11A-C712-45B3-B884-2469A6243368}]
@="ITIMEMediaDownloader"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A976C28D-75A1-42AA-94AE-8AF8B872089A}]
@="IUpdateLockdown"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}]
@="IWbemShutdown"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BC5513C8-B3B8-4BF7-A4D4-361C0D8C88BA}]
@="IUpdateDownloadContentCollection"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BF99AF76-B575-42AD-8AA4-33CBB5477AF1}]
@="IUpdateDownloadResult"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C574DE85-7358-43F6-AAE8-8697E62D8BA7}]
@="IDownloadJob"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C9470E8E-3F6B-46A9-A0A9-452815C34297}]
@="IWMPDownloadItem"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C97AD11B-F257-420B-9D9F-377F733F6F68}]
@="IUpdateDownloadContent2"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CB8DD6DE-8A11-4FAE-B2AD-CD82D0CDCCDD}]
@="IWMDownload2"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D31A5BAC-F719-4178-9DBB-5E2CB47FD18A}]
@="IDownloadProgress"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DAA4FDD0-4727-4DBE-A1E7-745DCA317144}]
@="IDownloadResult"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DD8D4A1A-8187-41E9-AC76-5D128F0AA0F5}]
@="IAutoUpdateInstallAtShutdown"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E15E9AD1-8F20-4CC4-9EC7-1A328CA86A0D}]
@="IWMPDownloadManager"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FA565B23-498C-47A0-979D-E7D5B1813360}]
@="IDownloadCompletedCallbackArgs"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.Update.Downloader]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.Update.Downloader]
@="UpdateDownloader Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.Update.Downloader\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.Update.Downloader\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.Update.Downloader\CurVer]
@="Microsoft.Update.Downloader.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.Update.Downloader.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.Update.Downloader.1]
@="UpdateDownloader Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.Update.Downloader.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Orbitcth.Customdown]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Orbitcth.Customdown]
@="Customdown Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Orbitcth.Customdown\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Orbitcth.Customdown\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Orbitcth.Customdown\CurVer]
@="Orbitcth.Customdown.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Orbitcth.Customdown.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Orbitcth.Customdown.1]
@="Customdown Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Orbitcth.Customdown.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer Download Handler]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer Download Handler]
@="RealPlayer Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer Download Handler\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer Download Handler\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer Download Handler\CurVer]
@="rmocx.RealPlayer Download Handler.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer Download Handler.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer Download Handler.1]
@="RealPlayer Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer Download Handler.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RAM Download Handler]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RAM Download Handler]
@="RealPlayer RAM Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RAM Download Handler\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RAM Download Handler\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RAM Download Handler\CurVer]
@="rmocx.RealPlayer RAM Download Handler.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RAM Download Handler.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RAM Download Handler.1]
@="RealPlayer RAM Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RAM Download Handler.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RMP Download Handler]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RMP Download Handler]
@="RealPlayer RMP Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RMP Download Handler\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RMP Download Handler\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RMP Download Handler\CurVer]
@="rmocx.RealPlayer RMP Download Handler.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RMP Download Handler.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RMP Download Handler.1]
@="RealPlayer RMP Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RMP Download Handler.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RNX Download Handler]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RNX Download Handler]
@="RealPlayer RNX Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RNX Download Handler\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RNX Download Handler\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RNX Download Handler\CurVer]
@="rmocx.RealPlayer RNX Download Handler.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RNX Download Handler.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RNX Download Handler.1]
@="RealPlayer RNX Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer RNX Download Handler.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer SMIL Download Handler]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer SMIL Download Handler]
@="RealPlayer SMIL Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer SMIL Download Handler\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer SMIL Download Handler\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer SMIL Download Handler\CurVer]
@="rmocx.RealPlayer SMIL Download Handler.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer SMIL Download Handler.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer SMIL Download Handler.1]
@="RealPlayer SMIL Download Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\rmocx.RealPlayer SMIL Download Handler.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{1BEB5790-E4C7-11D3-A625-00A0C9A40F1D}\1.0\0\win32]
@="C:\\WINDOWS\\Downloaded Program Files\\reportparameterdialog.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{1BEB5790-E4C7-11D3-A625-00A0C9A40F1D}\1.0\HELPDIR]
@="C:\\WINDOWS\\Downloaded Program Files\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A0880527-DC28-4EBB-BA27-D22102F22A9F}\1.0\0\win32]
@="C:\\Program Files\\Orbitdownloader\\orbitmxt.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A0880527-DC28-4EBB-BA27-D22102F22A9F}\1.0\HELPDIR]
@="C:\\Program Files\\Orbitdownloader\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{BCDDE143-FAE3-4C57-B22B-C4E8678CFDC0}\1.0\0\win32]
@="C:\\Program Files\\Orbitdownloader\\orbitcth.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{BD10A9B3-07CC-11D2-BEFF-00A0C95A6A5C}\1.0\0\win32]
@="C:\\WINDOWS\\Downloaded Program Files\\sviewhlp.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{BD10A9B3-07CC-11D2-BEFF-00A0C95A6A5C}\1.0\HELPDIR]
@="C:\\WINDOWS\\Downloaded Program Files\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C4847593-972C-11D0-9567-00A0C9273C2A}\8.0\0\win32]
@="C:\\WINDOWS\\Downloaded Program Files\\CRViewer.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C4847593-972C-11D0-9567-00A0C9273C2A}\8.0\HELPDIR]
@="C:\\WINDOWS\\Downloaded Program Files\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F2CA2107-C8D2-11D1-BEBD-00A0C95A6A5C}\1.1\0\win32]
@="C:\\WINDOWS\\Downloaded Program Files\\swebrs.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F2CA2107-C8D2-11D1-BEBD-00A0C95A6A5C}\1.1\HELPDIR]
@="C:\\WINDOWS\\Downloaded Program Files\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WMDFile]
@="Windows Media Player Download Package"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore]
"LockDownEnabled"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\On Access Scanner\McShield\Configuration]
"bScanFloppyOnShutdown"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\DirectAnimation Java Classes\DownloadInformation]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\DirectAnimation Java Classes\DownloadInformation]
"OSD"="C:\\WINDOWS\\Downloaded Program Files\\DirectAnimation Java Classes.osd"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\DownloadInformation]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\DownloadInformation]
"OSD"="C:\\WINDOWS\\Downloaded Program Files\\Microsoft XML Parser for Java.osd"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}\DownloadInformation]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}\DownloadInformation]
"INF"="C:\\WINDOWS\\Downloaded Program Files\\QTPlugin.inf"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{6414512B-B978-451D-A0D8-FCFDF33E833C}\DownloadInformation]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{6414512B-B978-451D-A0D8-FCFDF33E833C}\DownloadInformation]
"INF"="C:\\WINDOWS\\Downloaded Program Files\\wuweb.inf"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\DownloadInformation]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\DownloadInformation]
"CODEBASE"="http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab"
"INF"="C:\\WINDOWS\\Downloaded Program Files\\erma.inf"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{C4847596-972C-11D0-9567-00A0C9273C2A}\Contains\Files]
"C:\\WINDOWS\\Downloaded Program Files\\reportparameterdialog.dll"=""
"C:\\WINDOWS\\Downloaded Program Files\\CRViewer.dll"=""
"C:\\WINDOWS\\Downloaded Program Files\\sviewhlp.dll"=""
"C:\\WINDOWS\\Downloaded Program Files\\swebrs.dll"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{C4847596-972C-11D0-9567-00A0C9273C2A}\DownloadInformation]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{C4847596-972C-11D0-9567-00A0C9273C2A}\DownloadInformation]
"INF"="C:\\WINDOWS\\Downloaded Program Files\\crviewer.inf"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{D41E4F1F-A407-11D1-8BC9-00C04FA30A41}]
"$Function"="CORLockDownProvider"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DownloadManager]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer]
"DownloadUI"="{7854F00C-DC77-477E-A10E-603F48442D3B}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\BROWSE\NOTIFYDOWNLOADCOMPLETE]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\BROWSE\NOTIFYDOWNLOADCOMPLETE]
"Text"="Notify when downloads complete"
"ValueName"="NotifyDownloadComplete"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\CRYPTO\CD_LMZ_LOCKDOWN]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\CRYPTO\CD_LMZ_LOCKDOWN]
"RegPath"="SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_LOCALMACHINE_LOCKDOWN\\Settings"
"RegPoliciesPath"="SOFTWARE\\Policies\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_LOCALMACHINE_LOCKDOWN\\Settings"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\CRYPTO\CHECK_SIG]
"RegPath"="SOFTWARE\\Microsoft\\Internet Explorer\\Download"
"Text"="Check for signatures on downloaded programs"
"RegPoliciesPath"="SOFTWARE\\Policies\\Microsoft\\Internet Explorer\\Download"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\CRYPTO\LMZ_LOCKDOWN]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\CRYPTO\LMZ_LOCKDOWN]
"RegPath"="SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_LOCALMACHINE_LOCKDOWN"
"RegPoliciesPath"="SOFTWARE\\Policies\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_LOCALMACHINE_LOCKDOWN"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\CRYPTO\RUN_INV_SIG]
"RegPath"="SOFTWARE\\Microsoft\\Internet Explorer\\Download"
"RegPoliciesPath"="SOFTWARE\\Policies\\Microsoft\\Internet Explorer\\Download"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\MULTIMEDIA\PLACEHOLDERS]
"Text"="Show image download placeholders"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Download]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\DragDrop\{2BDB5D05-9A0B-4256-80AF-A920F8C01AE1}}]
; Contents of value:
; C:\Program Files\Orbitdownloader
"AppPath"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,\
20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4f,00,72,00,62,00,69,00,74,00,64,\
00,6f,00,77,00,6e,00,6c,00,6f,00,61,00,64,00,65,00,72,00,00,00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer\Objects\DropDownPlaylist]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer\Objects\DropDownPlaylist\Column]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer\Objects\ItemsPlaylist]
"dropDownVisible"="false"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer\Objects\MuteButton]
"downToolTip"="res://wmploc.dll/RT_STRING/#1808"
"down"="wmpprop:player.settings.mute"
"onClick"="player.settings.mute=down;"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer\Objects\RepeatButton]
"downToolTip"="res://wmploc.dll/RT_STRING/#1817"
"down"="jscript:player.settings.GetMode(\"loop\");"
"onClick"="player.settings.setMode(\"loop\", down);"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer\Objects\SeekSlider]
"foregroundProgress"="wmpprop:player.network.downloadProgress"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer\Objects\ShuffleButton]
"downToolTip"="res://wmploc.dll/RT_STRING/#1815"
"down"="jscript:player.settings.GetMode(\"shuffle\");"
"onClick"="player.settings.setMode(\"shuffle\", down);"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer\Publish\{9AB5C98B-AA7B-4ff4-A8EB-9D8E23C0D59E}]
@="WMPlayer Downlevel CD Burn Publish Provider"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Devices\AudioCD]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Devices\DVD]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.aif]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.aifc]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.aiff]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.asf]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.asx]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.au]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.avi]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.cda]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.dvr-ms]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.m1v]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.m2v]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.m3u]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.mid]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.midi]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.mod]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.mp2]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.mp2v]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.mp3]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.mpa]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.mpe]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.mpeg]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.mpg]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.mpv2]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.rmi]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.snd]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.wav]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.wax]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.wm]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.wma]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.wmd]
"MediaType.Description"="Windows Media Player Download Package"
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.wmv]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.wmx]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.wmz]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.wpl]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.wvx]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\IEHardening]
"FEATURE_LOCALMACHINE_LOCKDOWN"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\application/vnd.ms-wpl]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\application/x-mplayer2]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\application/x-ms-wmd]
@="Windows Media Player Download Package"
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\application/x-ms-wmz]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/aiff]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/basic]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/mid]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/midi]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/mp3]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/mpeg]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/mpegurl]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/mpg]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/wav]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/x-aiff]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/x-mid]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/x-midi]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/x-mp3]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/x-mpeg]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/x-mpegurl]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/x-mpg]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/x-ms-wax]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/x-ms-wma]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\audio/x-wav]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\midi/mid]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\video/avi]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\video/mpeg]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\video/mpg]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\video/msvideo]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\video/x-mpeg]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\video/x-mpeg2a]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\video/x-ms-asf]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\video/x-ms-asf-plugin]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\video/x-ms-wm]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\video/x-ms-wmv]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\video/x-ms-wmx]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\video/x-ms-wvx]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\MIME Types\video/x-msvideo]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Protocols\mms]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Protocols\mmst]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Protocols\mmsu]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Protocols\msbd]
"UserApprovedOwning"="yes"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\Internet]
"LocationOfComponents"="C:\\Documents and Settings\\Admin\\My Documents\\Azureus Downloads\\Microsoft Office 2003 Professional\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Delivery\{90110409-6000-11D3-8CFE-0150048383C9}]
"DownloadCode"="90000409-6000-11D3-8CFE-0150048383C9"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\PowerPoint\Translators]
"Downrev"="C:\\Program Files\\Microsoft Office\\OFFICE11\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Registration\{90110409-6000-11D3-8CFE-0150048383C9}]
"SmartSourceDir"="C:\\Documents and Settings\\Admin\\My Documents\\Azureus Downloads\\Microsoft Office 2003 Professional\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Properties]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\A2561405.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\A3561405.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\A4561405.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\AV561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\CC561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\CD561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\CF561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\CL561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\CM561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\CP561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\CR561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\CS561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\DW20.ADM_1033]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\DW20.EXE_0001]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\DWDCW20.DLL]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\DWINTL20.DLL_0001_1033]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\DWTRIG20.EXE]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\E2561410.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\E3561405.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\E4561410.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\EV561405.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\G3561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\GV561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\IJ561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\IS561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\IU561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\L2561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\L3561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\L4561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\L9561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\LV561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\M2561406.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\M3561404.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\M4561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\M9561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\MA561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\MC561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\MG561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\MH561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\MO561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\MT561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\O0561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\O1561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\O9561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\OCLEAN.DLL_1033]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\OCLNCORE.OPC_1033]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\OCLNCUST.OPC_1033]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\OCLNINTL.OPC_1033]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\OFFCLN.EXE_1033]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\OSE.EXE]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\P2561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\P3561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\P4561402.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\PA561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\PR103368.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\PR103678.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\PR308246.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\PRO11.MSI]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\PSS10O.CHM_1033]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\PSS10R.CHM_1033]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\PV561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\PW561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\Q2561405.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\Q3561405.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\Q4561405.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\QV561405.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\SETUP.CHM_1033]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\SKU011.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\SKU011.XML_0002_1033]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\TR103621.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\TR308222.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\V3561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\W2561405.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\W3561405.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\W4561405.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\WV561405.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\X2561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\X3561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\YA561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\YB561408.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\YC561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\YH561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\YI561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\YL561402.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\YM561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\YO561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\YS561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\YT561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZA561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZC561402.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZD561402.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZE561406.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZF561402.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZG561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZH561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZI561402.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZJ561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZK561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZM561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZN561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZO561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZQ561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZR561403.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZS561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZT561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZU561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZV561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZY561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Resources\ZZ561401.CAB]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Sources]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Sources\90110409-6000-11D3-8CFE-0150048383C9]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\90000409-6000-11D3-8CFE-0150048383C9\Sources\90110409-6000-11D3-8CFE-0150048383C9]
"Path"="C:\\Documents and Settings\\Admin\\My Documents\\Azureus Downloads\\Microsoft Office 2003 Professional\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\microsoft.watson.alrtintl.data]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\microsoft.watson.alrtintl.data\Properties]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\microsoft.watson.alrtintl.data\Resources]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\microsoft.watson.alrtintl.data\Resources\AlrtIntl.dll]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\microsoft.watson.alrtintl.data\Sources]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\microsoft.watson.alrtintl.data\Sources\alrtintl1033]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\microsoft.watson.watsonrc.data]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\microsoft.watson.watsonrc.data\Properties]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\microsoft.watson.watsonrc.data\Resources]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\microsoft.watson.watsonrc.data\Resources\WatsonRC.dat]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\microsoft.watson.watsonrc.data\Sources]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Delivery\SourceEngine\Downloads\microsoft.watson.watsonrc.data\Sources\watsonrcsrc]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Updates\Windows\SP1\NLSDownlevelMapping]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Updates\Windows\SP1\NLSDownlevelMapping]
"PackageName"="Microsoft National Language Support Downlevel APIs"
"Description"="Microsoft National Language Support Downlevel APIs"
"ARPLink"="HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\NLSDownlevelMapping"
"UninstallCommand"="C:\\WINDOWS\\$NtServicePackUninstallNLSDownlevelMapping$\\spuninst\\spuninst.exe "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Updates\Windows\SP1\NLSDownlevelMapping\Filelist]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Updates\Windows\SP1\NLSDownlevelMapping\Filelist\0]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM]
; Contents of value:
; C:\WINDOWS\system32\WBEM\cimwin32.mof
; C:\WINDOWS\system32\WBEM\cimwin32.mfl
; C:\WINDOWS\system32\WBEM\system.mof
; C:\WINDOWS\system32\WBEM\wmipcima.mof
; C:\WINDOWS\system32\WBEM\wmipcima.mfl
; C:\WINDOWS\system32\WBEM\regevent.mof
; C:\WINDOWS\system32\WBEM\regevent.mfl
; C:\WINDOWS\system32\WBEM\ntevt.mof
; C:\WINDOWS\system32\WBEM\ntevt.mfl
; C:\WINDOWS\system32\WBEM\secrcw32.mof
; C:\WINDOWS\system32\WBEM\secrcw32.mfl
; C:\WINDOWS\system32\WBEM\dsprov.mof
; C:\WINDOWS\system32\WBEM\dsprov.mfl
; C:\WINDOWS\system32\WBEM\msi.mof
; C:\WINDOWS\system32\WBEM\msi.mfl
; C:\WINDOWS\system32\WBEM\subscrpt.mof
; C:\WINDOWS\system32\WBEM\wmi.mof
; C:\WINDOWS\system32\WBEM\wmi.mfl
; C:\WINDOWS\system32\WBEM\scm.mof
; C:\WINDOWS\system32\WBEM\fevprov.mof
; C:\WINDOWS\system32\WBEM\fevprov.mfl
; C:\WINDOWS\system32\WBEM\wmitimep.mof
; C:\WINDOWS\system32\WBEM\wmitimep.mfl
; C:\WINDOWS\system32\WBEM\wmipdskq.mof
; C:\WINDOWS\system32\WBEM\wmipdskq.mfl
; C:\WINDOWS\system32\WBEM\wmipicmp.mof
; C:\WINDOWS\system32\WBEM\wmipicmp.mfl
; C:\WINDOWS\system32\WBEM\wmipiprt.mof
; C:\WINDOWS\system32\WBEM\wmipiprt.mfl
; C:\WINDOWS\system32\WBEM\wmipjobj.mof
; C:\WINDOWS\system32\WBEM\wmipjobj.mfl
; C:\WINDOWS\system32\WBEM\wmipsess.mof
; C:\WINDOWS\system32\WBEM\wmipsess.mfl
; C:\WINDOWS\system32\WBEM\krnlprov.mof
; C:\WINDOWS\system32\WBEM\krnlprov.mfl
; C:\WINDOWS\system32\WBEM\tscfgwmi.mof
; C:\WINDOWS\system32\WBEM\tscfgwmi.mfl
; C:\WINDOWS\system32\WBEM\licwmi.mof
; C:\WINDOWS\system32\WBEM\licwmi.mfl
; C:\WINDOWS\system32\WBEM\evntrprv.mof
; C:\WINDOWS\system32\WBEM\hnetcfg.mof
; C:\WINDOWS\system32\WBEM\sr.mof
; C:\WINDOWS\system32\WBEM\dgnet.mof
; C:\WINDOWS\system32\WBEM\whqlprov.mof
; C:\WINDOWS\system32\WBEM\ieinfo5.mof
; c:\windows\softwaredistribution\download\16b2c96a0c41f4dfdb4d3cc228a4f819\licwmi.mof
; C:\WINDOWS\system32\wbem\wscenter.mof
; C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\MSINFO\OINFOP11.MOF
See less See more
2
Hldrrr.exe is part of the Trojan Bagle. It is notorious for disabling security related applications, and damaging other files in the system.

The characteristic files that show up with this Trojan are not presently showing in the reports provided.

You may be at a stage where you are dealing with damage recovery, and sometimes that is not possible.


Please open Notepad
Copy/paste the following text in the code box below to Notepad:

Code:
regedit /e mcshld.txt "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\McShield"
Save the file to the Desktop
Save as mcshld.bat
Choose to save as type: All files
Close out of Notepad

On the Desktop, double-click on mcshld.bat

Search for: mcshld.txt, and provide its contents in your reply.

~~~~
Also, use the Internet Explorer browser, and do an online scan with Kaspersky Online Scanner
Click Yes, when prompted to install its ActiveX component.
The program launches and downloads the latest definition files.
  • Once the files are downloaded click on Next
  • Click on Scan Settings and configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK and, under select a target to scan, select My Computer
When the scan is done, in the Scan is completed window (below), any infection is displayed. There is no option to clean/disinfect, however, we need to analyze the information on the report.





To obtain the report:
Click on: Save Report As (above - red blinking arrow)

Next, in the Save as prompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar
In Save as type, click the drop arrow and select: Text file [*.txt]
Then, click: Save

~~~~
Please provide the contents of mcshld.txt, and the Kaspersky Online Scanner Report in your reply.
See less See more
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Sunday, March 23, 2008 11:15:19 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 23/03/2008
Kaspersky Anti-Virus database records: 628931
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 92401
Number of viruses found: 0
Number of infected objects: 0
Number of suspicious objects: 0
Duration of the scan process: 01:43:29

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\comodo\Firewall Pro\cfplogdb.sdb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Pure Networks\Log\logfile.nmapp_exe.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Pure Networks\Log\logfile.nmctxth_exe.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Pure Networks\Log\logfile.nmsrvc_exe.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\SupportSoft\medicsp2\SYSTEM\state\logs\sprtcmd.log Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Admin\Application Data\user60.rdb Object is locked skipped
C:\Documents and Settings\Admin\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Admin\Local Settings\Application Data\SupportSoft\medicsp2\Admin\state\logs\sprtcmd.log Object is locked skipped
C:\Documents and Settings\Admin\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Admin\Local Settings\History\History.IE5\MSHist012008031320080314\index.dat Object is locked skipped
C:\Documents and Settings\Admin\Local Settings\History\History.IE5\MSHist012008031420080315\index.dat Object is locked skipped
C:\Documents and Settings\Admin\Local Settings\Temp\Perflib_Perfdata_8f8.dat Object is locked skipped
C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Admin\ntuser.dat Object is locked skipped
C:\Documents and Settings\Admin\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\PeerGuardian2\history.db Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{43C201A9-B0CB-4B55-BEC4-9A114F3F5B35}\RP12\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_510.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

Scan process completed.
See less See more
...will not allow any anti-virus software or anti-spyware to load or run.
Try re-installing these applications.

Their executable files were probably damaged by Trojan_Bagle.

Also, try rebooting to Safe Mode, and see if it works. If it does not, try the following:

Download SafeBootKeyRepair

Save it to the Desktop
Double-click to run it

It takes a short moment for it to finish running, and produces a log.
Please post the SafeBoot_Repair log in your reply.

Let us know how it goes.
See less See more
Reg export of SafeBoot key after repair:
========================

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot]
"AlternateShell"="cmd.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\AppMgmt]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Base]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Boot Bus Extender]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Boot file system]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\CryptSvc]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\DcomLaunch]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmadmin]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmboot.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmio.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmload.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmserver]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\EventLog]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\File system]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Filter]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\HelpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Netlogon]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PCI Configuration]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PlugPlay]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PNP Filter]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Primary disk]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PSEXESVC]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\RpcSs]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\SCSI Class]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\sermouse.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\sr.sys]
@="FSFilter System Recovery"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\SRService]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\System Bus Extender]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\vga.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\vgasave.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\WinMgmt]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}]
@="Universal Serial Bus controllers"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]
@="CD-ROM Drive"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
@="DiskDrive"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]
@="Standard floppy disk controller"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
@="Hdc"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
@="Keyboard"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
@="Mouse"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}]
@="PCMCIA Adapters"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
@="SCSIAdapter"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
@="System"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}]
@="Floppy disk drive"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
@="Volume"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
@="Human Interface Devices"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\AFD]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\AppMgmt]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Base]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Boot Bus Extender]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Boot file system]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Browser]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\CryptSvc]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\DcomLaunch]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Dhcp]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmadmin]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmboot.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmio.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmload.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmserver]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\DnsCache]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\EventLog]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\File system]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Filter]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\HelpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\ip6fw.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\ipnat.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\LanmanServer]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\LanmanWorkstation]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\LmHosts]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Messenger]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NDIS]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NDIS Wrapper]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Ndisuio]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetBIOS]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetBIOSGroup]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetBT]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetDDEGroup]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Netlogon]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetMan]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Network]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetworkProvider]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NtLmSsp]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PCI Configuration]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PlugPlay]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PNP Filter]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PNP_TDI]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Primary disk]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PSEXESVC]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdpcdd.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdpdd.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdpwd.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdsessmgr]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\RpcSs]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\SCSI Class]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\sermouse.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\sharedaccess]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\sr.sys]
@="FSFilter System Recovery"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\SRService]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Streams Drivers]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\System Bus Extender]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Tcpip]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\TDI]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\tdpipe.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\tdtcp.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\termservice]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\UploadMgr]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\vga.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\vgasave.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\WinMgmt]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\WZCSVC]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{36FC9E60-C465-11CF-8056-444553540000}]
@="Universal Serial Bus controllers"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}]
@="CD-ROM Drive"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}]
@="DiskDrive"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}]
@="Standard floppy disk controller"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
@="Hdc"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
@="Keyboard"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
@="Mouse"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}]
@="Net"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}]
@="NetClient"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}]
@="NetService"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}]
@="NetTrans"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}]
@="PCMCIA Adapters"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
@="SCSIAdapter"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
@="System"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}]
@="Floppy disk drive"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
@="Volume"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
@="Human Interface Devices"

========================

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\PSEXESVC
See less See more
Are you able to boot to Safe Mode now?
Try re-installing your anti-virus and anti-spyware applications. Use Start > Control Panel > Add Remove Programs to uninstall them before you install them anew.

Also, when done, run HijackThis, Scan, and post a new log.
Logfile of HijackThis v1.97.7
Scan saved at 9:40:31 PM, on 24/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\00THotkey.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\TPWRTRAY.EXE
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\TME3\TMESBS32.EXE
C:\WINDOWS\system32\TFNF5.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
C:\WINDOWS\MXOALDR.EXE
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Admin\Local Settings\Application Data\FolderShare\FolderShare.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\Program Files\Orbitdownloader\orbitdm.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\ePrompter\ePrompter.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\Orbitdownloader\orbitnet.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Admin\My Documents\My Shared Folder\My Software\HiJack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ca.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe /Type 28
O4 - HKLM\..\Run: [TosHKCW.exe] "C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe"
O4 - HKLM\..\Run: [NDSTray.exe] "C:\Program Files\Toshiba\ConfigFree\NDSTray.exe"
O4 - HKLM\..\Run: [TMESBS.EXE] C:\Program Files\TOSHIBA\TME3\TMESBS32.EXE /Client
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Drag'n Drop CD] C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe /StartUp
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Windows Live FolderShare] "C:\Documents and Settings\Admin\Local Settings\Application Data\FolderShare\FolderShare.exe" /background
O4 - Startup: ePrompter.lnk = C:\Program Files\ePrompter\ePrompter.exe
O4 - Startup: WordWeb Pro.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
O4 - Global Startup: Orbit.lnk = C:\Program Files\Orbitdownloader\orbitdm.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\system32\wweb32.dll/lookup.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research (HKLM)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1205163774112
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
O16 - DPF: {C4847596-972C-11D0-9567-00A0C9273C2A} (Crystal Report Viewer Control) - http://web1.dillon.ca/viewer/activeXViewer/activexviewer.cab
See less See more
Tha is one outdated verion of HijackThis!! The new version has greater detection capabilities.

Please remove the outdated version that is running, and download the HijackThis Installer
Save to the Desktop.
Double-click on HJTInstall.exe to install the program.
A prompt appears showing that, by default, it installs to C:\Program Files\Trend Micro\HijackThis
Click: Install

At the main screen of the program, click on: Do a system scan and save a log file
When done scanning, click Save log , and post it in your reply.
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 6:43:45 PM, on 25/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\00THotkey.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\TPWRTRAY.EXE
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\TME3\TMESBS32.EXE
C:\WINDOWS\system32\TFNF5.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
C:\WINDOWS\MXOALDR.EXE
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Admin\Local Settings\Application Data\FolderShare\FolderShare.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\Program Files\Orbitdownloader\orbitdm.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\ePrompter\ePrompter.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\Orbitdownloader\orbitnet.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Admin\Desktop\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ca.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe /Type 28
O4 - HKLM\..\Run: [TosHKCW.exe] "C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe"
O4 - HKLM\..\Run: [NDSTray.exe] "C:\Program Files\Toshiba\ConfigFree\NDSTray.exe"
O4 - HKLM\..\Run: [TMESBS.EXE] C:\Program Files\TOSHIBA\TME3\TMESBS32.EXE /Client
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Drag'n Drop CD] C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe /StartUp
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Windows Live FolderShare] "C:\Documents and Settings\Admin\Local Settings\Application Data\FolderShare\FolderShare.exe" /background
O4 - Startup: ePrompter.lnk = C:\Program Files\ePrompter\ePrompter.exe
O4 - Startup: WordWeb Pro.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
O4 - Global Startup: Orbit.lnk = C:\Program Files\Orbitdownloader\orbitdm.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\system32\wweb32.dll/lookup.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1205163774112
O16 - DPF: {C4847596-972C-11D0-9567-00A0C9273C2A} (Crystal Report Viewer Control) - http://web1.dillon.ca/viewer/activeXViewer/activexviewer.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Tmesbs32 (Tmesbs) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe

--
End of file - 11556 bytes
See less See more
1 - 20 of 32 Posts
Status
Not open for further replies.
Top