Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Wrong icons on my desktop and start menu

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Wrong icons on my desktop and start menu

Unread postby fhqwhgads » December 31st, 2008, 3:22 pm

Hello there. Thanks for helping. I have a strange issue. I ran this program that a website said I had to run to view it correctly (I don't remember which site) and as soon as I did, my start menu and icons on my desktop went away. I was able to reboot and now none of the icons on my desktop are there anymore and instead there are a bunch of different ones. I had a lot of stuff I needed in my desktop. A bunch of windows pop up when Windows turns on now and I am also having a hard time running things because none of my programs are in my start menu.

I have Symantec Antivirus installed and updated and I ran a scan but it didn't find anything. I am at a loss. I would be most grateful if you could help me.

Here is my HijackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:06:47 AM, on 12/31/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\SMINST\Scheduler.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\MSN\MSNIA\msniasvc.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://my.guaranty.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F2 - REG:system.ini: Shell=Explorer.exe, cmd /c C:\WINDOWS\System32\DontDelete.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard.exe
O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Scheduler] C:\WINDOWS\SMINST\Scheduler.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - .DEFAULT User Startup: amipro.sam (User 'Default user')
O4 - .DEFAULT User Startup: excel.xls (User 'Default user')
O4 - .DEFAULT User Startup: excel4.xls (User 'Default user')
O4 - .DEFAULT User Startup: lotus.wk4 (User 'Default user')
O4 - .DEFAULT User Startup: powerpnt.ppt (User 'Default user')
O4 - .DEFAULT User Startup: presenta.shw (User 'Default user')
O4 - .DEFAULT User Startup: quattro.wb2 (User 'Default user')
O4 - .DEFAULT User Startup: sndrec.wav (User 'Default user')
O4 - .DEFAULT User Startup: winword.doc (User 'Default user')
O4 - .DEFAULT User Startup: winword2.doc (User 'Default user')
O4 - .DEFAULT User Startup: wordpfct.wpd (User 'Default user')
O4 - .DEFAULT User Startup: wordpfct.wpg (User 'Default user')
O4 - Startup: Accessories
O4 - Startup: AccuTerm 2k2.lnk = ?
O4 - Startup: Administrative Tools
O4 - Startup: Adobe Reader 7.0.lnk = ?
O4 - Startup: AntiPhishing
O4 - Startup: Broadcom
O4 - Startup: Games
O4 - Startup: HP Backup & Recovery
O4 - Startup: HP Cool Tools
O4 - Startup: Intel(R) Matrix Storage Manager
O4 - Startup: Microsoft Office
O4 - Startup: MSN.lnk = C:\Program Files\MSN\MSNCoreFiles\Install\msnsusii.exe
O4 - Startup: Powertoys for Windows XP
O4 - Startup: Roxio
O4 - Startup: Startup
O4 - Startup: Symantec Client Security
O4 - Startup: Windows Desktop Search
O4 - Startup: Windows Messenger.lnk = ?
O4 - Startup: Windows Movie Maker.lnk = C:\Program Files\Movie Maker\moviemk.exe
O4 - Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O4 - Global Startup: Adobe
O4 - Global Startup: InstallShield
O4 - Global Startup: Microsoft
O4 - Global Startup: Microsoft Update.lnk = C:\WINDOWS\system32\rundll32.exe
O4 - Global Startup: Programs
O4 - Global Startup: Set Program Access and Defaults.lnk = C:\WINDOWS\system32\control.exe
O4 - Global Startup: Symantec
O4 - Global Startup: Windows Catalog.lnk = ?
O4 - Global Startup: Windows Desktop Search
O4 - Global Startup: Windows Genuine Advantage
O4 - Global Startup: Windows Update.lnk = C:\WINDOWS\system32\wupdmgr.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftup ... 0740883281
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 0740878109
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: .NET Runtime Optimization Service v2.0.50727_X86 (clr_optimization_v2.0.50727_32) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (file missing)
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

--
End of file - 8182 bytes
fhqwhgads
Active Member
 
Posts: 9
Joined: December 31st, 2008, 3:11 pm
Advertisement
Register to Remove

Re: Wrong icons on my desktop and start menu

Unread postby Rodav » January 7th, 2009, 7:15 pm

Hello! :hello2: and welcome to the Malware Removal forums.
I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research so please be patient while I work on your log and I will post back here with any recommendations.

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
User avatar
Rodav
MRU Master Emeritus
 
Posts: 1480
Joined: April 19th, 2007, 6:44 am
Location: Here, there and yonder.

Re: Wrong icons on my desktop and start menu

Unread postby Rodav » January 7th, 2009, 7:19 pm

Step 1:
We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix


* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Please include the C:\ComboFix.txt in your next reply for further review.


Step 2:
Run HijackThis, do a system scan and post the following:
  • The ComboFix report (C:\ComboFix.txt)
  • The new HijackThis log
User avatar
Rodav
MRU Master Emeritus
 
Posts: 1480
Joined: April 19th, 2007, 6:44 am
Location: Here, there and yonder.

Re: Wrong icons on my desktop and start menu

Unread postby fhqwhgads » January 7th, 2009, 10:04 pm

Hello, Rodav. Thank you very much for helping me. I've tried following the instructions on there but am having difficulty right from the get-go. I am able to click the download link, click Save, select Desktop on the left and save it, but it doesn't appear on my desktop. When I try downloading it again, I see it on my desktop in that window. There are also different icons on my desktop than what show up in the Save As window. Here, I'll post a screenshot:

Image

Do you want me to try to run it from inside that window by right-clicking it and clicking Open?
fhqwhgads
Active Member
 
Posts: 9
Joined: December 31st, 2008, 3:11 pm

Re: Wrong icons on my desktop and start menu

Unread postby Rodav » January 7th, 2009, 10:52 pm

Try saving combofix.exe to the C drive root (C:\ComboFix.exe). Save As > My Computer > Local Disk (C:) > save.

If that works you can continue with the rest of the instructions otherwise let me know.
User avatar
Rodav
MRU Master Emeritus
 
Posts: 1480
Joined: April 19th, 2007, 6:44 am
Location: Here, there and yonder.

Re: Wrong icons on my desktop and start menu

Unread postby fhqwhgads » January 8th, 2009, 5:47 pm

Okay, that worked. I made sure to disable Symantec Antivirus first.

Here are the contents of C:\ComboFix.txt:

ComboFix 09-01-08.01 - Jason 2009-01-08 13:40:06.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.591 [GMT -8:00]
Running from: C:\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated)
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\templates\1099Correction Note to customer.doc.lnk
c:\documents and settings\All Users\templates\2007 DEMOS.xlsx.lnk
c:\documents and settings\All Users\templates\ADS-DEMOS-INT 1099.xlsx.lnk
c:\documents and settings\All Users\templates\BOFA0408.xlsx.lnk
c:\documents and settings\All Users\templates\Camping World Invoices Open.xls.lnk
c:\documents and settings\All Users\templates\City of Coburg-Palm Harbor.xlsx.lnk
c:\documents and settings\All Users\templates\ClearChannelOutdoor letter.docx.lnk
c:\documents and settings\All Users\templates\Cmpg Wrld Open Invoces.xlsx.lnk
c:\documents and settings\All Users\templates\COMPANY VEHICLE LIST OCT07.xlsx.lnk
c:\documents and settings\All Users\templates\DEMO VEHICLES.xls.lnk
c:\documents and settings\All Users\templates\FAX COVER.xls.lnk
c:\documents and settings\All Users\templates\Fax Coversheet Master.doc.lnk
c:\documents and settings\All Users\templates\GUARANTY RV CFN GAS-CARD LISTING.xls.lnk
c:\documents and settings\All Users\templates\IconCache.db
c:\documents and settings\All Users\templates\index.dat
c:\documents and settings\All Users\templates\Lebanon Show River Center Apri 25 2008.docx.lnk
c:\documents and settings\All Users\templates\LETTERHEAD.doc.lnk
c:\documents and settings\All Users\templates\Local Settings.lnk
c:\documents and settings\All Users\templates\My Pictures.lnk
c:\documents and settings\All Users\templates\Northwood Mfg Letter.doc.lnk
c:\documents and settings\All Users\templates\Northwood Mfg.xlsx.lnk
c:\documents and settings\All Users\templates\NWnaturalGas1.xlsx.lnk
c:\documents and settings\All Users\templates\NWNGas-EPUD.xlsx.lnk
c:\documents and settings\All Users\templates\PALM HABOR LETTER-2.docx.lnk
c:\documents and settings\All Users\templates\PALM HABOR LETTER.docx.lnk
c:\documents and settings\All Users\templates\PALM HABOR LETTER0723.docx.lnk
c:\documents and settings\All Users\templates\Parts Visa 042808.pdf.lnk
c:\documents and settings\All Users\templates\PAYROLL - 2008 ee count (2).xls.lnk
c:\documents and settings\All Users\templates\PAYROLL IDS NUMBERS 2008.xls.lnk
c:\documents and settings\All Users\templates\POSTAGE SUMMARY.xls.lnk
c:\documents and settings\All Users\templates\Privacy Rules - HIPPA.pdf.lnk
c:\documents and settings\All Users\templates\prof4.pdf.lnk
c:\documents and settings\All Users\templates\RENT-DAWN BROWN.xlsx.lnk
c:\documents and settings\All Users\templates\RENTS.xlsx.lnk
c:\documents and settings\All Users\templates\Sample.jpg (2).lnk
c:\documents and settings\All Users\templates\Sample.jpg.lnk
c:\documents and settings\All Users\templates\SEDieselElectrictyAllocation.xls.lnk
c:\documents and settings\All Users\templates\SEdieselNote.docx.lnk
c:\documents and settings\All Users\templates\UPDATED SHOW CODES.xls.lnk
c:\documents and settings\All Users\templates\UTILITIES - HERB.xls.lnk
c:\documents and settings\All Users\templates\VENDOR LIST.xls.lnk
c:\documents and settings\All Users\templates\virginia.ferguson's Documents.lnk
c:\documents and settings\All Users\templates\Xmas Angel.gif (2).lnk
c:\documents and settings\All Users\templates\Xmas Angel.gif.lnk
c:\documents and settings\All Users\templates\YUMA AND QUARTZITE VENDOR LIST.xlsx.lnk
c:\documents and settings\All Users\templates\ZIEGLER ALLOCATION.xlsx.lnk
c:\documents and settings\Jason\Local Settings\Temporary Internet Files\HJTInstall.exe
c:\documents and settings\Jason\Local Settings\Temporary Internet Files\IconCache.db
c:\documents and settings\NetworkService\Cookies\IconCache.db

.
((((((((((((((((((((((((( Files Created from 2008-12-08 to 2009-01-08 )))))))))))))))))))))))))))))))
.

2009-01-08 13:35 . 2009-01-08 13:35 <DIR> d-------- c:\documents and settings\Jason\Start Menu\Programs\Startup\InstallShield
2009-01-08 13:27 . 2009-01-08 13:27 <DIR> d-------- c:\documents and settings\Jason\Start Menu\Programs\Symantec
2009-01-08 13:27 . 2009-01-08 13:27 <DIR> d--h----- c:\documents and settings\Jason\Start Menu\Programs\Startup\Content.Word
2009-01-08 13:27 . 2009-01-08 13:27 <DIR> d--h----- c:\documents and settings\Jason\Start Menu\Programs\Startup\Content.MSO
2009-01-08 09:43 . 2009-01-08 09:43 768 --a------ c:\windows\system32\d3d8caps.dat
2009-01-08 08:27 . 2009-01-08 13:38 2,913,557 -ra------ C:\ComboFix.exe
2009-01-07 17:47 . 2009-01-07 17:47 <DIR> d-------- c:\documents and settings\Jason\Start Menu\Programs\Startup\AntiPhishing
2009-01-07 17:45 . <DIR> \\.\prn
2009-01-07 17:45 . 2009-01-07 17:45 16,384 --ahs---- c:\documents and settings\Jason\Start Menu\Programs\index.dat
2009-01-07 17:35 . 2009-01-07 17:35 <DIR> d--h----- c:\windows\PIF
2009-01-07 16:50 . 2009-01-07 16:50 <DIR> d-------- c:\documents and settings\Jason\Start Menu\Programs\Startup\Symantec
2009-01-06 23:52 . 2009-01-06 23:52 <DIR> d-------- c:\documents and settings\Jason\Start Menu\Programs\Startup\AdobeUM
2009-01-06 13:03 . 2009-01-06 13:03 <DIR> d--hs---- c:\documents and settings\Jason\Start Menu\Programs\Startup\Content.IE5
2009-01-06 13:01 . 2009-01-06 13:01 <DIR> d-------- c:\documents and settings\Jason\Start Menu\Programs\Windows Desktop Search
2009-01-06 13:01 . 2009-01-06 13:01 <DIR> d-------- c:\documents and settings\Jason\Start Menu\Programs\AdobeUM
2009-01-06 12:19 . 2008-04-14 04:00 1,033,728 --a------ c:\windows\system32\dllcache\explorer.exe
2009-01-06 12:19 . 2008-04-14 04:00 1,033,728 --a------ c:\windows\explorer.exe
2009-01-06 11:03 . 2008-04-14 04:00 146,432 --a------ c:\windows\system32\dllcache\regedit.exe
2009-01-06 11:03 . 2008-04-14 04:00 146,432 --a------ c:\windows\regedit.exe
2009-01-06 10:58 . 2009-01-06 10:58 <DIR> d-------- c:\windows\All Users
2009-01-05 18:48 . 2009-01-05 18:48 <DIR> d-------- c:\documents and settings\Jason\Start Menu\Programs\Startup\Windows Desktop Search
2009-01-05 17:50 . 2009-01-05 17:53 <DIR> d--h----- c:\documents and settings\Jason\Start Menu\Programs\Content.Word
2009-01-05 17:50 . 2009-01-05 17:53 <DIR> d--h----- c:\documents and settings\Jason\Start Menu\Programs\Content.MSO
2009-01-05 17:33 . 2009-01-05 17:33 <DIR> d--hs---- c:\documents and settings\Jason\Start Menu\Programs\Content.IE5
2009-01-03 07:18 . 2009-01-08 13:35 32,768 --ahs---- c:\documents and settings\Jason\Start Menu\Programs\Startup\index.dat
2008-12-31 12:19 . 2008-12-31 12:19 <DIR> d-------- C:\rsit
2008-12-31 12:03 . 2008-12-31 12:03 <DIR> d-------- c:\documents and settings\LocalService\Application Data\Symantec
2008-12-31 11:05 . 2008-12-31 11:05 <DIR> d-------- c:\program files\Trend Micro
2008-12-31 10:04 . 2008-12-31 10:04 <DIR> d--hs---- c:\documents and settings\Jason\Start Menu\Programs\Startup\History.IE5
2008-12-31 09:51 . 2008-12-31 09:51 <DIR> d--hs---- C:\$RECYCLE.BIN
2008-12-31 09:21 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
2008-12-31 09:21 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2008-12-31 09:14 . 2009-01-08 13:36 <DIR> d-------- c:\program files\Symantec AntiVirus
2008-12-31 09:14 . 2008-12-31 09:14 <DIR> d-------- c:\program files\Symantec
2008-12-31 09:14 . 2008-12-31 09:14 <DIR> d-------- c:\program files\Common Files\Symantec Shared
2008-12-31 09:14 . 2008-12-31 09:14 110,952 --a------ c:\windows\system32\drivers\SYMEVENT.SYS
2008-12-31 09:14 . 2008-12-31 09:14 48,768 --a------ c:\windows\system32\S32EVNT1.DLL
2008-12-31 09:14 . 2008-12-31 09:14 8,014 --a------ c:\windows\system32\drivers\SYMEVENT.CAT
2008-12-31 09:14 . 2008-12-31 09:14 805 --a------ c:\windows\system32\drivers\SYMEVENT.INF
2008-12-31 09:04 . 2008-12-31 09:04 <DIR> d-------- c:\program files\Microsoft Silverlight
2008-12-31 09:02 . 2008-12-31 10:06 <DIR> d-------- c:\windows\system32\GroupPolicy
2008-12-31 09:02 . 2008-12-31 09:02 <DIR> d-------- c:\program files\Windows Desktop Search
2008-12-31 09:02 . 2008-03-07 09:02 192,000 --a------ c:\windows\system32\dllcache\offfilt.dll
2008-12-31 09:02 . 2008-03-07 09:02 98,304 --a------ c:\windows\system32\dllcache\nlhtml.dll
2008-12-31 09:02 . 2008-03-07 09:02 29,696 --a------ c:\windows\system32\dllcache\mimefilt.dll
2008-12-31 08:59 . 2008-12-31 08:59 <DIR> d-------- c:\program files\Windows Media Connect 2
2008-12-31 08:58 . 2008-12-31 10:06 <DIR> d-------- c:\windows\system32\LogFiles
2008-12-31 08:58 . 2008-12-31 08:58 <DIR> d-------- c:\windows\system32\drivers\UMDF
2008-12-31 08:56 . 2008-12-31 08:56 <DIR> d-------- c:\program files\Microsoft CAPICOM 2.1.0.2
2008-12-31 08:36 . 2008-12-31 08:36 <DIR> d-------- c:\windows\system32\scripting
2008-12-31 08:36 . 2008-12-31 08:36 <DIR> d-------- c:\windows\system32\en
2008-12-31 08:36 . 2008-12-31 08:36 <DIR> d-------- c:\windows\system32\bits
2008-12-31 08:36 . 2008-12-31 08:36 <DIR> d-------- c:\windows\l2schemas
2008-12-31 08:35 . 2008-12-31 10:06 <DIR> d-------- c:\windows\ServicePackFiles
2008-12-31 08:28 . 2008-10-16 14:07 23,576 --a------ c:\windows\system32\wuapi.dll.mui
2008-12-30 17:04 . 2008-12-30 17:04 0 --a------ c:\windows\vpc32.INI
2008-12-30 17:03 . 2009-01-08 13:35 <DIR> d--hs---- c:\documents and settings\Jason\Start Menu\Programs\Startup
2008-12-30 17:03 . 2008-12-30 17:08 <DIR> dr------- c:\documents and settings\Jason\Start Menu\Programs\Accessories
2008-12-30 17:03 . 2009-01-06 17:15 <DIR> d-------- c:\documents and settings\Jason

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-06 18:58 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-31 16:41 --------- d-----w c:\program files\Google
2008-12-13 06:40 3,593,216 ----a-w c:\windows\system32\dllcache\mshtml.dll
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\dllcache\gdi32.dll
2008-10-16 22:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 22:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 22:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 22:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 22:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 22:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 22:12 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 22:12 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 22:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 22:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 22:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 22:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 22:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 22:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 22:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 22:07 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-16 13:11 70,656 ----a-w c:\windows\system32\dllcache\ie4uinit.exe
2008-10-16 13:11 13,824 ----a-w c:\windows\system32\dllcache\ieudinit.exe
2008-10-15 16:34 337,408 ----a-w c:\windows\system32\dllcache\netapi32.dll
2008-10-15 07:06 633,632 ----a-w c:\windows\system32\dllcache\iexplore.exe
2008-10-15 07:04 161,792 ----a-w c:\windows\system32\dllcache\ieakui.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

c:\documents and settings\NetworkService\Templates\Microsoft\Internet Explorer\UserData
index.dat [2009-01-06 32768]

c:\documents and settings\NetworkService\Templates\Microsoft\Internet Explorer\UserData\NRXTBFTY
oWindowsUpdate[1].xml [2009-01-06 10:59:21 28]

c:\documents and settings\LocalService\Start Menu\Programs\Startup\AntiPhishing
B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat [2009-01-06 78924]

c:\documents and settings\LocalService\Start Menu\Programs\Startup\Content.IE5
index.dat [2009-01-06 49152]

c:\documents and settings\LocalService\Start Menu\Programs\Startup\Content.IE5\4SD4Q2EN
2006-082416-2803-99.1[1].gif [2009-01-06 13:16:07 12185]
chevronOR2[1].gif [2009-01-06 13:16:07 97]
globalheadernav[1].gif [2009-01-06 13:16:01 152]
popup_icon[1].gif [2009-01-06 13:16:01 60]
rate[1].gif [2009-01-06 13:16:01 3066]
spacer[1].gif [2009-01-06 13:16:01 43]
symantec[1].gif [2009-01-06 13:16:00 2328]
symantec[1].js [2009-01-06 13:16:00 31187]
threatExpHdrBG[1].gif [2009-01-06 13:16:01 156]
writeup[1].htm [2009-01-06 13:16:00 29989]

c:\documents and settings\LocalService\Start Menu\Programs\Startup\Content.IE5\KM6PM318
arrowButton[1].gif [2009-01-06 13:16:01 216]
cart[1].gif [2009-01-06 13:16:00 463]
om_code[1].js [2009-01-06 13:16:00 3594]
print[1].gif [2009-01-06 13:16:01 73]
squareBL[1].gif [2009-01-06 13:16:01 44]
sym-search-arrow[1].gif [2009-01-06 13:16:01 266]
symantec[1].css [2009-01-06 13:16:00 65174]
writeup[1].htm [2009-01-06 13:16:07 41539]

c:\documents and settings\LocalService\Start Menu\Programs\Startup\Content.IE5\UQB7DA99
download[1].gif [2009-01-06 13:16:01 211]
ent-vista_sec_mktgpromo[1].jpg [2009-01-06 13:16:01 15376]
globalnavrgtCnr[1].gif [2009-01-06 13:16:01 310]
gradient_background[1].gif [2009-01-06 13:16:00 442]
n-09nisnav-promo-sky[1].jpg [2009-01-06 13:16:01 53360]
oo_engine[1].js [2009-01-06 13:16:00 1445]
sym-dropdown-arrow[1].gif [2009-01-06 13:16:01 188]
s_code[1].js [2009-01-06 13:16:01 22096]
threatExpBdyBG[1].gif [2009-01-06 13:16:01 274]
threatExpFtrBG[1].gif [2009-01-06 13:16:01 272]

c:\documents and settings\LocalService\Start Menu\Programs\Startup\Content.IE5\VYJPR529
chevron_bold.en-us[1].gif [2009-01-06 13:16:01 188]
clear[1].gif [2009-01-06 13:16:00 49]
favicon[1].ico [2009-01-06 13:16:02 894]
globalnavlftCnr[1].gif [2009-01-06 13:16:01 326]
global[1].css [2009-01-06 13:16:00 3985]
squareOR[1].gif [2009-01-06 13:16:01 44]
swfobject[1].js [2009-01-06 13:16:00 6887]
threatExpHdrBGon[1].gif [2009-01-06 13:16:01 255]
writeup[1].htm [2009-01-06 13:16:45 31583]

c:\documents and settings\LocalService\Start Menu\Programs\Startup\Symantec\LiveUpdate
1.Configuration.Log.LiveUpdate [2009-01-07 577]
1.Product.Inventory.LiveUpdate [2009-01-08 1688]
1.Settings.LiveUpdate [2009-01-08 22224]
2.Configuration.Log.LiveUpdate [2009-01-07 589]
2.Product.Inventory.LiveUpdate [2009-01-08 1688]
2.Settings.LiveUpdate [2009-01-08 22224]
3.Configuration.Log.LiveUpdate [2009-01-06 583]
3.Product.Inventory.LiveUpdate [2009-01-08 1688]
3.Settings.LiveUpdate [2009-01-08 22224]
4.Configuration.Log.LiveUpdate [2009-01-06 605]
5.Configuration.Log.LiveUpdate [2009-01-02 604]
Configuration.Log.LiveUpdate [2009-01-08 605]
Log.LiveUpdate [2009-01-08 301363]
LUInstall.LiveUpdate [2008-12-31 215911]
Product.Inventory.LastGood.LiveUpdate [2009-01-08 1688]
Product.Inventory.LiveUpdate [2009-01-08 1688]
Settings.LiveUpdate [2009-01-08 24341]

c:\documents and settings\LocalService\Start Menu\Programs\Startup\Symantec\LiveUpdate\Downloads
1231429965jtun_sav10en90107002.m25.full.zip [2009-01-08 385878]
automatic$20liveupdate_3.2.0.67_english_livetri.zip [2009-01-08 2783]
avenge$20microdefs25$20savcorp10_microdefsb.curdefs_symalllanguages_livetri.zip [2009-01-08 3539]
avenge$20microdefs25$20savcorp10_microdefsb.dec_symalllanguages_livetri.zip [2009-01-08 2734]
minitri.flg [2009-01-08 1]

c:\documents and settings\LocalService\Start Menu\Programs\Startup\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs
01072009.Log [2009-01-07 3924]
01082009.Log [2009-01-08 1892]

c:\documents and settings\All Users\Favorites\Adobe\Acrobat\7.0
AdobeCMapFnt07.lst [2009-01-05 496]
AdobeSysFnt07.lst [2009-01-05 72138]
JSADM.exv [2009-01-05 294]
UserCache.bin [2009-01-05 71473]

c:\documents and settings\All Users\Favorites\Adobe\Acrobat\7.0\Cache
AcroFnt07.lst [2009-01-05 7466]

c:\documents and settings\All Users\Favorites\Adobe\Acrobat\7.0\Collab
RSS [2009-01-05 103]

c:\documents and settings\All Users\Favorites\Adobe\Acrobat\7.0\JavaScripts
glob.settings.js [2009-01-05 10]

c:\documents and settings\All Users\Favorites\Adobe\Acrobat\7.0\Updater
udlog.txt [2009-01-05 13623]
udstore.js [2009-01-05 145487]

c:\documents and settings\All Users\Favorites\HEWLETT-PACKARD Recommended Sites
Buy from HP.URL [2007-01-17 70]
Buy software.URL [2007-01-17 84]
Chat with support.URL [2007-01-17 83]
Contact HP.URL [2007-01-17 76]
Diagnostics - On-line.URL [2007-01-17 83]
Get Driver and Support alerts.URL [2007-01-17 102]
Graphics programs.URL [2007-01-17 96]
Hewlett-Packard.URL [2007-01-17 43]
Parts - Find or Buy.URL [2007-01-17 75]
Support resources.URL [2007-01-17 159]
Technical Specifications.URL [2007-01-17 92]

c:\documents and settings\All Users\Favorites\History.IE5
index.dat [2009-01-08 49152]

c:\documents and settings\All Users\Favorites\Microsoft\CryptnetUrlCache\Content
7B2238AACCEDC3F1FFE8E7EB5F575EC9 [2009-01-03 552]

c:\documents and settings\All Users\Favorites\Microsoft\CryptnetUrlCache\MetaData
7B2238AACCEDC3F1FFE8E7EB5F575EC9 [2009-01-03 132]

c:\documents and settings\All Users\Favorites\Microsoft\Internet Explorer
MSIMGSIZ.DAT [2009-01-05 16384]

c:\documents and settings\All Users\Favorites\Microsoft\Movie Maker
MEDIATAB.DAT [2009-01-05 4608]

c:\documents and settings\All Users\Favorites\Microsoft\Office
Excel12.pip [2009-01-05 1544]
MSO1033.acl [2009-01-05 37814]
Word12.pip [2009-01-05 1684]

c:\documents and settings\Jason\Local Settings\Application Data\
1099Correction Note to customer.doc.lnk - c:\documents and settings\Jason\My Documents\1099Correction Note to customer.doc [2008-07-07 29696]
2007 DEMOS.xlsx.lnk - c:\documents and settings\Jason\My Documents\2007 DEMOS.xlsx [2008-07-07 10077]
ADS-DEMOS-INT 1099.xlsx.lnk - c:\documents and settings\Jason\My Documents\ADS-DEMOS-INT 1099.xlsx [2008-07-07 16321]
ADVERTISING LISTING.pdf.lnk - c:\documents and settings\Jason\My Documents\ADVERTISING LISTING.pdf [2008-07-07 535798]
AVIAD #160.pdf.lnk - c:\documents and settings\Jason\My Documents\AVIAD #160.pdf [2008-07-07 68757]
AVIAD #161.pdf.lnk - c:\documents and settings\Jason\My Documents\AVIAD #161.pdf [2008-07-07 69113]
BOFA0408.xlsx.lnk - c:\documents and settings\Jason\My Documents\BOFA0408.xlsx [2008-07-07 13082]
Camping World Invoices Open.xls.lnk - c:\documents and settings\Jason\My Documents\Camping World Invoices Open.xls [2008-07-07 20992]
City of Coburg-Palm Harbor.xlsx.lnk - c:\documents and settings\Jason\My Documents\City of Coburg-Palm Harbor.xlsx [2008-07-07 10774]
ClearChannelOutdoor letter.docx.lnk - c:\documents and settings\Jason\My Documents\ClearChannelOutdoor letter.docx [2008-07-07 15281]
Cmpg Wrld Open Invoces.xlsx.lnk - c:\documents and settings\Jason\My Documents\Cmpg Wrld Open Invoces.xlsx [2008-07-07 9857]
COMPANY VEHICLE LIST OCT07.xlsx.lnk - c:\documents and settings\Jason\My Documents\COMPANY VEHICLE LIST OCT07.xlsx [2008-07-07 73745]
concompform.pdf.lnk - c:\documents and settings\Jason\My Documents\concompform.pdf [2008-07-07 752957]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Shell"="Explorer.exe cmd /c c:\windows\system32\DontDelete.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2467663144-3723592425-691012227-1186\Scripts\Logon\0\0]
"Script"=\\vnc.guaranty.com\PUBLIC\GP\Wallpaper\userwallpaper.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2467663144-3723592425-691012227-1186\Scripts\Logon\0\1]
"Script"=\\vnc.guaranty.com\PUBLIC\GP\icons\default.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2467663144-3723592425-691012227-1614\Scripts\Logon\0\0]
"Script"=\\vnc.guaranty.com\PUBLIC\GP\Wallpaper\userwallpaper.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2467663144-3723592425-691012227-1614\Scripts\Logon\0\1]
"Script"=\\vnc.guaranty.com\PUBLIC\GP\icons\default.bat

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\SMINST\\Scheduler.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-12-31 99376]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2007-10-07 116664]
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-procexp90.Sys


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mDefault_Page_URL = hxxp://my.guaranty.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-08 13:41:08
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.NET CLR Data]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.NET CLR Networking]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.NET Data Provider for Oracle]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.NET Data Provider for SqlServer]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.NETFramework]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Abiosdsk]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\abp480n5]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ac97intc]
"ImagePath"="system32\drivers\ac97intc.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ACPI]
"ImagePath"="system32\DRIVERS\ACPI.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ACPIEC]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\adpu160m]
"ImagePath"="\SystemRoot\system32\DRIVERS\adpu160m.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\adpu320]
"ImagePath"="\SystemRoot\system32\DRIVERS\adpu320.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aec]
"ImagePath"="system32\drivers\aec.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AFD]
"ImagePath"="\SystemRoot\System32\drivers\afd.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Aha154x]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aic78u2]
"ImagePath"="\SystemRoot\system32\DRIVERS\aic78u2.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aic78xx]
"ImagePath"="\SystemRoot\system32\DRIVERS\aic78xx.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Alerter]
"ServiceDll"="%SystemRoot%\system32\alrsvc.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ALG]
"ImagePath"="%SystemRoot%\System32\alg.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AliIde]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\amsint]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AppMgmt]
"ServiceDll"="%SystemRoot%\System32\appmgmts.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\asc]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\asc3350p]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\asc3550]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASP.NET]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASP.NET_1.1.4322]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASP.NET_2.0.50727]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aspnet_state]
"ImagePath"="%SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AsyncMac]
"ImagePath"="system32\DRIVERS\asyncmac.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\atapi]
"ImagePath"="system32\DRIVERS\atapi.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Atdisk]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Atmarpc]
"ImagePath"="system32\DRIVERS\atmarpc.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AudioSrv]
"ServiceDll"="%SystemRoot%\System32\audiosrv.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\audstub]
"ImagePath"="system32\DRIVERS\audstub.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\b57w2k]
"ImagePath"="system32\DRIVERS\b57xp32.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\BattC]
"MofImagePath"="System32\Drivers\battc.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Beep]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\BITS]
"ServiceDll"="c:\windows\system32\qmgr.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Blfp]
"ImagePath"="system32\DRIVERS\baspxp32.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Browser]
"ServiceDll"="%SystemRoot%\System32\browser.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cbidf2k]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ccEvtMgr]
"ImagePath"="\"c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe\""

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ccSetMgr]
"ImagePath"="\"c:\program files\Common Files\Symantec Shared\ccSetMgr.exe\""

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cd20xrnt]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Cdaudio]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Cdfs]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Cdrom]
"ImagePath"="system32\DRIVERS\cdrom.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Changer]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CiSvc]
"ImagePath"="%SystemRoot%\system32\cisvc.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ClipSrv]
"ImagePath"="%SystemRoot%\system32\clipsrv.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\clr_optimization_v2.0.50727_32]
"ImagePath"="c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CmdIde]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\COMSysApp]
"ImagePath"="c:\windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ContentFilter]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ContentIndex]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Cpqarray]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CryptSvc]
"ServiceDll"="%SystemRoot%\System32\cryptsvc.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dac2w2k]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dac960nt]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DcomLaunch]
"ServiceDll"="%SystemRoot%\system32\rpcss.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DefWatch]
"ImagePath"="\"c:\program files\Symantec AntiVirus\DefWatch.exe\""

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Dhcp]
"ServiceDll"="%SystemRoot%\System32\dhcpcsvc.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Disk]
"ImagePath"="system32\DRIVERS\disk.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DLABOIOM]
"ImagePath"="System32\DLA\DLABOIOM.SYS"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DLACDBHM]
"ImagePath"="System32\Drivers\DLACDBHM.SYS"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DLADResN]
"ImagePath"="System32\DLA\DLADResN.SYS"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DLAIFS_M]
"ImagePath"="System32\DLA\DLAIFS_M.SYS"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DLAOPIOM]
"ImagePath"="System32\DLA\DLAOPIOM.SYS"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DLAPoolM]
"ImagePath"="System32\DLA\DLAPoolM.SYS"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DLARTL_N]
"ImagePath"="System32\Drivers\DLARTL_N.SYS"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DLAUDFAM]
"ImagePath"="System32\DLA\DLAUDFAM.SYS"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DLAUDF_M]
"ImagePath"="System32\DLA\DLAUDF_M.SYS"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmadmin]
"ImagePath"="%SystemRoot%\System32\dmadmin.exe /com"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmboot]
"ImagePath"="System32\drivers\dmboot.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmio]
"ImagePath"="System32\drivers\dmio.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmload]
"ImagePath"="System32\drivers\dmload.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dmserver]
"ServiceDll"="%SystemRoot%\System32\dmserver.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DMusic]
"ImagePath"="system32\drivers\DMusic.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Dnscache]
"ServiceDll"="%SystemRoot%\System32\dnsrslvr.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Dot3svc]
"ServiceDll"="%SystemRoot%\System32\dot3svc.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dpti2o]
"ImagePath"="\SystemRoot\system32\DRIVERS\dpti2o.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\drmkaud]
"ImagePath"="system32\drivers\drmkaud.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DRVMCDB]
"ImagePath"="System32\Drivers\DRVMCDB.SYS"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DRVNCDB]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DRVNDDM]
"ImagePath"="System32\Drivers\DRVNDDM.SYS"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\E100B]
"ImagePath"="system32\DRIVERS\e100b325.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EapHost]
"ServiceDll"="%SystemRoot%\System32\eapsvc.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\eeCtrl]
"ImagePath"="\??\c:\program files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EraserUtilRebootDrv]
"ImagePath"="\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ERSvc]
"ServiceDll"="%SystemRoot%\System32\ersvc.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Eventlog]
"ImagePath"="%SystemRoot%\system32\services.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EventSystem]
"ServiceDll"="c:\windows\system32\es.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Fastfat]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FastUserSwitchingCompatibility]
"ServiceDll"="%SystemRoot%\System32\shsvcs.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Fdc]
"ImagePath"="system32\DRIVERS\fdc.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Fips]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Flpydisk]
"ImagePath"="system32\DRIVERS\flpydisk.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FltMgr]
"ImagePath"="system32\drivers\fltmgr.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Fs_Rec]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ftdisk]
"ImagePath"="system32\DRIVERS\ftdisk.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Gpc]
"ImagePath"="system32\DRIVERS\msgpc.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HDAudBus]
"ImagePath"="system32\DRIVERS\HDAudBus.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\helpsvc]
"ServiceDll"="%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HidServ]
"ServiceDll"="%SystemRoot%\System32\hidserv.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HidUsb]
"ImagePath"="system32\DRIVERS\hidusb.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\hkmsvc]
"ServiceDll"="%SystemRoot%\System32\kmsvc.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\hpn]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HTTP]
"ImagePath"="System32\Drivers\HTTP.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HTTPFilter]
"ServiceDll"="%SystemRoot%\System32\w3ssl.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i2omgmt]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i2omp]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i8042prt]
"ImagePath"="system32\DRIVERS\i8042prt.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i81x]
"ImagePath"="system32\DRIVERS\i81xnt5.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iAimFP0]
"ImagePath"="system32\DRIVERS\wADV01nt.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iAimFP1]
"ImagePath"="system32\DRIVERS\wADV02NT.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iAimFP2]
"ImagePath"="system32\DRIVERS\wADV05NT.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iAimFP3]
"ImagePath"="system32\DRIVERS\wSiINTxx.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iAimFP4]
"ImagePath"="system32\DRIVERS\wVchNTxx.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iAimFP5]
"ImagePath"="system32\DRIVERS\wADV07nt.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iAimFP6]
"ImagePath"="system32\DRIVERS\wADV08nt.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iAimFP7]
"ImagePath"="system32\DRIVERS\wADV09nt.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iAimTV0]
"ImagePath"="system32\DRIVERS\wATV01nt.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iAimTV1]
"ImagePath"="system32\DRIVERS\wATV02NT.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iAimTV3]
"ImagePath"="system32\DRIVERS\wATV04nt.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iAimTV4]
"ImagePath"="system32\DRIVERS\wCh7xxNT.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iAimTV5]
"ImagePath"="system32\DRIVERS\wATV10nt.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iAimTV6]
"ImagePath"="system32\DRIVERS\wATV06nt.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iaStor]
"ImagePath"="System32\DRIVERS\iaStor.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Imapi]
"ImagePath"="system32\DRIVERS\imapi.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ImapiService]
"ImagePath"="c:\windows\system32\imapi.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\inetaccs]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ini910u]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Inport]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IntcAzAudAddService]
"ImagePath"="system32\drivers\RtkHDAud.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IntelIde]
"ImagePath"="\SystemRoot\system32\DRIVERS\intelide.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\intelppm]
"ImagePath"="system32\DRIVERS\intelppm.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ip6Fw]
"ImagePath"="system32\drivers\ip6fw.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IpFilterDriver]
"ImagePath"="system32\DRIVERS\ipfltdrv.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IpInIp]
"ImagePath"="system32\DRIVERS\ipinip.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IpNat]
"ImagePath"="system32\DRIVERS\ipnat.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IPSec]
"ImagePath"="system32\DRIVERS\ipsec.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IRENUM]
"ImagePath"="system32\DRIVERS\irenum.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ISAPISearch]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\isapnp]
"ImagePath"="system32\DRIVERS\isapnp.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Kbdclass]
"ImagePath"="system32\DRIVERS\kbdclass.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\kbdhid]
"ImagePath"="system32\DRIVERS\kbdhid.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\kmixer]
"ImagePath"="system32\drivers\kmixer.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\KSecDD]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\lanmanserver]
"ServiceDll"="%SystemRoot%\System32\srvsvc.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\lanmanworkstation]
"ServiceDll"="%SystemRoot%\System32\wkssvc.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\lbrtfdc]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ldap]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LicenseService]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LiveUpdate]
"ImagePath"="\"c:\progra~1\Symantec\LIVEUP~1\LUCOMS~1.EXE\""

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LmHosts]
"ServiceDll"="%SystemRoot%\System32\lmhsvc.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Messenger]
"ServiceDll"="%SystemRoot%\System32\msgsvc.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mnmdd]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mnmsrvc]
"ImagePath"="c:\windows\system32\mnmsrvc.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Modem]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Mouclass]
"ImagePath"="system32\DRIVERS\mouclass.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mouhid]
"ImagePath"="system32\DRIVERS\mouhid.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MountMgr]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mraid35x]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MRxDAV]
"ImagePath"="system32\DRIVERS\mrxdav.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MRxSmb]
"ImagePath"="system32\DRIVERS\mrxsmb.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSDTC]
"ImagePath"="c:\windows\system32\msdtc.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Msfs]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSIServer]
"ImagePath"="c:\windows\system32\msiexec.exe /V"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSKSSRV]
"ImagePath"="system32\drivers\MSKSSRV.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSPCLOCK]
"ImagePath"="system32\drivers\MSPCLOCK.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSPQM]
"ImagePath"="system32\drivers\MSPQM.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSSCNTRS]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mssmbios]
"ImagePath"="system32\DRIVERS\mssmbios.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Mup]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\napagent]
"ServiceDll"="%SystemRoot%\System32\qagentrt.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NAVENG]
"ImagePath"="\??\c:\progra~1\COMMON~1\SYMANT~1\VIRUSD~1\20090108.007\naveng.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NAVEX15]
"ImagePath"="\??\c:\progra~1\COMMON~1\SYMANT~1\VIRUSD~1\20090108.007\navex15.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NDIS]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NdisTapi]
"ImagePath"="system32\DRIVERS\ndistapi.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ndisuio]
"ImagePath"="system32\DRIVERS\ndisuio.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NdisWan]
"ImagePath"="system32\DRIVERS\ndiswan.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NDProxy]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetBIOS]
"ImagePath"="system32\DRIVERS\netbios.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetBT]
"ImagePath"="system32\DRIVERS\netbt.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetDDE]
"ImagePath"="%SystemRoot%\system32\netdde.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetDDEdsdm]
"ImagePath"="%SystemRoot%\system32\netdde.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Netlogon]
"ImagePath"="%SystemRoot%\system32\lsass.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Netman]
"ServiceDll"="%SystemRoot%\System32\netman.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Nla]
"ServiceDll"="%SystemRoot%\System32\mswsock.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Npfs]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ntfs]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NtLmSsp]
"ImagePath"="%SystemRoot%\system32\lsass.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NtmsSvc]
"ServiceDll"="%SystemRoot%\system32\ntmssvc.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Null]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nv]
"ImagePath"="system32\DRIVERS\nv4_mini.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NVSvc]
"ImagePath"="%SystemRoot%\system32\nvsvc32.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NwlnkFlt]
"ImagePath"="system32\DRIVERS\nwlnkflt.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NwlnkFwd]
"ImagePath"="system32\DRIVERS\nwlnkfwd.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\odserv]
"ImagePath"="\"c:\program files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE\""

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ose]
"ImagePath"="\"c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE\""

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Outlook]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\P3]
"ImagePath"="system32\DRIVERS\p3.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Parport]
"ImagePath"="system32\DRIVERS\parport.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PartMgr]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ParVdm]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCA]
"ImagePath"="c:\windows\SMINST\PCAngel.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCI]
"ImagePath"="system32\DRIVERS\pci.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCIDump]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCIIde]
"ImagePath"="system32\DRIVERS\pciide.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Pcmcia]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PDCOMP]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PDFRAME]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PDRELI]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PDRFRAME]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\perc2]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\perc2hib]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PerfDisk]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PerfNet]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PerfOS]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PerfProc]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PlugPlay]
"ImagePath"="%SystemRoot%\system32\services.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PolicyAgent]
"ImagePath"="%SystemRoot%\system32\lsass.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PptpMiniport]
"ImagePath"="system32\DRIVERS\raspptp.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PQNTDrv]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ProtectedStorage]
"ImagePath"="%SystemRoot%\system32\lsass.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PSched]
"ImagePath"="system32\DRIVERS\psched.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ptilink]
"ImagePath"="system32\DRIVERS\ptilink.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PxHelp20]
"ImagePath"="System32\Drivers\PxHelp20.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ql1080]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ql10wnt]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ql12160]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ql1240]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ql1280]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RasAcd]
"ImagePath"="system32\DRIVERS\rasacd.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RasAuto]
"ServiceDll"="%SystemRoot%\System32\rasauto.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Rasl2tp]
"ImagePath"="system32\DRIVERS\rasl2tp.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RasMan]
"ServiceDll"="%SystemRoot%\System32\rasmans.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RasPppoe]
"ImagePath"="system32\DRIVERS\raspppoe.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Raspti]
"ImagePath"="system32\DRIVERS\raspti.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Rdbss]
"ImagePath"="system32\DRIVERS\rdbss.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RDPCDD]
"ImagePath"="System32\DRIVERS\RDPCDD.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RDPDD]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\rdpdr]
"ImagePath"="system32\DRIVERS\rdpdr.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RDPNP]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RDPWD]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RDSessMgr]
"ImagePath"="c:\windows\system32\sessmgr.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\redbook]
"ImagePath"="system32\DRIVERS\redbook.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RemoteAccess]
"ServiceDll"="%SystemRoot%\System32\mprdim.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RemoteRegistry]
"ServiceDll"="%SystemRoot%\system32\regsvc.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RpcLocator]
"ImagePath"="%SystemRoot%\system32\locator.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RpcSs]
"ServiceDll"="%SystemRoot%\system32\rpcss.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RSVP]
"ImagePath"="%SystemRoot%\system32\rsvp.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SamSs]
"ImagePath"="%SystemRoot%\system32\lsass.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SavRoam]
"ImagePath"="\"c:\program files\Symantec AntiVirus\SavRoam.exe\""

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SAVRT]
"ImagePath"="\??\c:\program files\Symantec AntiVirus\savrt.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SAVRTPEL]
"ImagePath"="\??\c:\program files\Symantec AntiVirus\Savrtpel.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SCardSvr]
"ImagePath"="%SystemRoot%\System32\SCardSvr.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Schedule]
"ServiceDll"="%SystemRoot%\system32\schedsvc.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ScsiPort]
"ImagePath"="%SystemRoot%\system32\drivers\scsiport.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Secdrv]
"ImagePath"="system32\DRIVERS\secdrv.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\seclogon]
"ServiceDll"="%SystemRoot%\System32\seclogon.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SENS]
"ServiceDll"="%SystemRoot%\system32\sens.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\serenum]
"ImagePath"="system32\DRIVERS\serenum.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Serial]
"ImagePath"="system32\DRIVERS\serial.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Sfloppy]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess]
"ServiceDll"="%SystemRoot%\System32\ipnathlp.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ShellHWDetection]
"ServiceDll"="%SystemRoot%\System32\shsvcs.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Simbad]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SNDSrvc]
"ImagePath"="\"c:\program files\Common Files\Symantec Shared\SNDSrvc.exe\""

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Sparrow]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SPBBCDrv]
"ImagePath"="\??\c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SPBBCSvc]
"ImagePath"="\"c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe\""

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\splitter]
"ImagePath"="system32\drivers\splitter.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Spooler]
"ImagePath"="%SystemRoot%\system32\spoolsv.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sr]
"ImagePath"="system32\DRIVERS\sr.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\srservice]
"ServiceDll"="c:\windows\system32\srsvc.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Srv]
"ImagePath"="system32\DRIVERS\srv.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SSDPSRV]
"ServiceDll"="%SystemRoot%\System32\ssdpsrv.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\stisvc]
"ServiceDll"="%SystemRoot%\system32\wiaservc.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\swenum]
"ImagePath"="system32\DRIVERS\swenum.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\swmidi]
"ImagePath"="system32\drivers\swmidi.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SwPrv]
"ImagePath"="c:\windows\system32\dllhost.exe /Processid:{E5098927-E5AD-46FE-8F8E-8A03F1E2CA7E}"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\swwd]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Symantec AntiVirus]
"ImagePath"="\"c:\program files\Symantec AntiVirus\Rtvscan.exe\""

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\symc810]
"ImagePath"="\SystemRoot\system32\DRIVERS\symc810.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\symc8xx]
"ImagePath"="\SystemRoot\system32\DRIVERS\symc8xx.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SymEvent]
"ImagePath"="\??\c:\windows\system32\Drivers\SYMEVENT.SYS"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Symmpi]
"ImagePath"="\SystemRoot\system32\DRIVERS\symmpi.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SYMREDRV]
"ImagePath"="\SystemRoot\System32\Drivers\SYMREDRV.SYS"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SYMTDI]
"ImagePath"="\SystemRoot\System32\Drivers\SYMTDI.SYS"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sym_hi]
"ImagePath"="\SystemRoot\system32\DRIVERS\sym_hi.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sym_u3]
"ImagePath"="\SystemRoot\system32\DRIVERS\sym_u3.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sysaudio]
"ImagePath"="system32\drivers\sysaudio.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SysmonLog]
"ImagePath"="%SystemRoot%\system32\smlogsvc.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TapiSrv]
"ServiceDll"="%SystemRoot%\System32\tapisrv.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip]
"ImagePath"="system32\DRIVERS\tcpip.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TDPIPE]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TDTCP]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TermDD]
"ImagePath"="system32\DRIVERS\termdd.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TermService]
"ServiceDll"="%SystemRoot%\System32\termsrv.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Themes]
"ServiceDll"="%SystemRoot%\System32\shsvcs.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TlntSvr]
"ImagePath"="c:\windows\system32\tlntsvr.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TosIde]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TrkWks]
"ServiceDll"="%SystemRoot%\system32\trkwks.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TSDDD]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Udfs]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\UGatherer]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\UGTHRSVC]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ultra]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Update]
"ImagePath"="system32\DRIVERS\update.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\upnphost]
"ServiceDll"="%SystemRoot%\System32\upnphost.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\UPS]
"ImagePath"="%SystemRoot%\System32\ups.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\usb]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\usbccgp]
"ImagePath"="system32\DRIVERS\usbccgp.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\usbehci]
"ImagePath"="system32\DRIVERS\usbehci.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\usbhub]
"ImagePath"="system32\DRIVERS\usbhub.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\USBSTOR]
"ImagePath"="system32\DRIVERS\USBSTOR.SYS"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\usbuhci]
"ImagePath"="system32\DRIVERS\usbuhci.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\VgaSave]
"ImagePath"="\SystemRoot\System32\drivers\vga.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ViaIde]
"ImagePath"="\SystemRoot\system32\DRIVERS\viaide.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\VolSnap]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\VSS]
"ImagePath"="%SystemRoot%\System32\vssvc.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\W32Time]
"ServiceDll"="c:\windows\system32\w32time.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\W3SVC]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Wanarp]
"ImagePath"="system32\DRIVERS\wanarp.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WDICA]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wdmaud]
"ImagePath"="system32\drivers\wdmaud.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WebClient]
"ServiceDll"="%SystemRoot%\System32\webclnt.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\winmgmt]
"ServiceDll"="%SystemRoot%\system32\wbem\WMIsvc.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Winsock]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WinSock2]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WinTrust]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WmdmPmSN]
"ServiceDll"="c:\windows\system32\MsPMSNSv.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Wmi]
"ServiceDll"="%SystemRoot%\System32\advapi32.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WmiAcpi]
"ImagePath"="system32\DRIVERS\wmiacpi.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WmiApRpl]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WmiApSrv]
"ImagePath"="c:\windows\system32\wbem\wmiapsrv.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WMPNetworkSvc]
"ImagePath"="\"c:\program files\Windows Media Player\WMPNetwk.exe\""

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WS2IFSL]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wscsvc]
"ServiceDll"="%SYSTEMROOT%\system32\wscsvc.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WSearch]
"ImagePath"="%systemroot%\system32\SearchIndexer.exe /Embedding"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WSearchIdxPi]

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wuauserv]
"ServiceDll"="c:\windows\system32\wuauserv.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfPf]
"ImagePath"="system32\DRIVERS\WudfPf.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfRd]
"ImagePath"="system32\DRIVERS\wudfrd.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfSvc]
"ServiceDll"="%SystemRoot%\System32\WUDFSvc.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WZCSVC]
"ServiceDll"="%SystemRoot%\System32\wzcsvc.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\xmlprov]
"ServiceDll"="%SystemRoot%\System32\xmlprov.dll"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{B7066BE0-4C4D-44DB-99C0-DB2F934B3E04}]
.
Completion time: 2009-01-08 13:41:56
ComboFix-quarantined-files.txt 2009-01-08 21:41:53

Pre-Run: 143,762,075,648 bytes free
Post-Run: 143,809,736,704 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

937 --- E O F --- 2009-01-08 21:29:23

Here is the new HijackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:46:58 PM, on 1/8/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\SMINST\Scheduler.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://my.guaranty.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F2 - REG:system.ini: Shell=Explorer.exe cmd /c C:\WINDOWS\system32\DontDelete.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard.exe
O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Scheduler] C:\WINDOWS\SMINST\Scheduler.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - S-1-5-19 Startup: AntiPhishing (User 'LOCAL SERVICE')
O4 - S-1-5-19 Startup: Content.IE5 (User 'LOCAL SERVICE')
O4 - S-1-5-19 Startup: Symantec (User 'LOCAL SERVICE')
O4 - S-1-5-18 Startup: Identities (User 'SYSTEM')
O4 - S-1-5-18 Startup: Microsoft (User 'SYSTEM')
O4 - .DEFAULT Startup: Identities (User 'Default user')
O4 - .DEFAULT Startup: Microsoft (User 'Default user')
O4 - Startup: Adobe
O4 - Startup: AdobeUM
O4 - Startup: Asent
O4 - Startup: Content.IE5
O4 - Startup: HEWLETT-PACKARD Recommended Sites
O4 - Startup: History.IE5
O4 - Startup: Microsoft
O4 - Startup: Symantec
O4 - Startup: Windows Desktop Search
O4 - Startup: WMTools Downloaded Files
O4 - Global Startup: 1099Correction Note to customer.doc.lnk = C:\Documents and Settings\Jason\My Documents\1099Correction Note to customer.doc
O4 - Global Startup: 2007 DEMOS.xlsx.lnk = ?
O4 - Global Startup: Adobe
O4 - Global Startup: ADS-DEMOS-INT 1099.xlsx.lnk = ?
O4 - Global Startup: ADVERTISING LISTING.pdf.lnk = C:\Documents and Settings\Jason\My Documents\ADVERTISING LISTING.pdf
O4 - Global Startup: AntiPhishing
O4 - Global Startup: ApplicationHistory
O4 - Global Startup: Asent
O4 - Global Startup: AVIAD #160.pdf.lnk = C:\Documents and Settings\Jason\My Documents\AVIAD #160.pdf
O4 - Global Startup: AVIAD #161.pdf.lnk = C:\Documents and Settings\Jason\My Documents\AVIAD #161.pdf
O4 - Global Startup: BOFA0408.xlsx.lnk = ?
O4 - Global Startup: Camping World Invoices Open.xls.lnk = C:\Documents and Settings\Jason\My Documents\Camping World Invoices Open.xls
O4 - Global Startup: City of Coburg-Palm Harbor.xlsx.lnk = ?
O4 - Global Startup: ClearChannelOutdoor letter.docx.lnk = ?
O4 - Global Startup: Cmpg Wrld Open Invoces.xlsx.lnk = ?
O4 - Global Startup: COMPANY VEHICLE LIST OCT07.xlsx.lnk = ?
O4 - Global Startup: concompform.pdf.lnk = C:\Documents and Settings\Jason\My Documents\concompform.pdf
O4 - Global Startup: Content.IE5
O4 - Global Startup: Cookies.lnk = ?
O4 - Global Startup: Corrected 1099s for ACTA & Herb.pdf.lnk = C:\Documents and Settings\Jason\My Documents\Corrected 1099s for ACTA & Herb.pdf
O4 - Global Startup: DEMO VEHICLES.xls.lnk = C:\Documents and Settings\Jason\My Documents\DEMO VEHICLES.xls
O4 - Global Startup: excel.xls.lnk = C:\Documents and Settings\Jason\Templates\excel.xls
O4 - Global Startup: excel4.xls.lnk = C:\Documents and Settings\Jason\Templates\excel4.xls
O4 - Global Startup: ext list 011608.xlsx.lnk = ?
O4 - Global Startup: FAX COVER.xls.lnk = C:\Documents and Settings\Jason\My Documents\FAX COVER.xls
O4 - Global Startup: Fax Coversheet Master.doc.lnk = C:\Documents and Settings\Jason\My Documents\Fax Coversheet Master.doc
O4 - Global Startup: GARLIC FARM ANNEX 2005.xlsx.lnk = ?
O4 - Global Startup: GDIPFONTCACHEV1.DAT
O4 - Global Startup: Google
O4 - Global Startup: GUARANTY RV CFN GAS-CARD LISTING.xls.lnk = C:\Documents and Settings\Jason\My Documents\GUARANTY RV CFN GAS-CARD LISTING.xls
O4 - Global Startup: History.IE5
O4 - Global Startup: IconCache.db
O4 - Global Startup: Identities
O4 - Global Startup: index.dat
O4 - Global Startup: InstallShield
O4 - Global Startup: jason@2o7[1].txt.lnk = C:\Documents and Settings\Jason\Cookies\jason@2o7[1].txt
O4 - Global Startup: jason@google[1].txt.lnk = C:\Documents and Settings\Jason\Cookies\jason@google[1].txt
O4 - Global Startup: jason@google[2].txt.lnk = C:\Documents and Settings\Jason\Cookies\jason@google[2].txt
O4 - Global Startup: jason@m.webtrends[2].txt.lnk = C:\Documents and Settings\Jason\Cookies\jason@m.webtrends[2].txt
O4 - Global Startup: jason@microsoft[1].txt.lnk = C:\Documents and Settings\Jason\Cookies\jason@microsoft[1].txt
O4 - Global Startup: jason@office.microsoft[2].txt.lnk = C:\Documents and Settings\Jason\Cookies\jason@office.microsoft[2].txt
O4 - Global Startup: jason@sdc.windowsmarketplace[1].txt.lnk = C:\Documents and Settings\Jason\SendTo\jason@sdc.windowsmarketplace[1].txt
O4 - Global Startup: jason@sdc.windowsmarketplace[2].txt.lnk = C:\Documents and Settings\Jason\SendTo\jason@sdc.windowsmarketplace[2].txt
O4 - Global Startup: jason@windowsmarketplace[1].txt.lnk = C:\Documents and Settings\Jason\SendTo\jason@windowsmarketplace[1].txt
O4 - Global Startup: jason@www.microsoft[2].txt.lnk = C:\Documents and Settings\Jason\Cookies\jason@www.microsoft[2].txt
O4 - Global Startup: JERRY BROWN 20410.xlsx.lnk = ?
O4 - Global Startup: JERRY BROWN CARD HOLDERS MAR08.xlsx.lnk = ?
O4 - Global Startup: Local Settings.lnk = ?
O4 - Global Startup: Microsoft
O4 - Global Startup: Microsoft Help
O4 - Global Startup: Normal.dotm.lnk = ?
O4 - Global Startup: powerpnt.ppt.lnk = C:\Documents and Settings\Jason\Templates\powerpnt.ppt
O4 - Global Startup: screen.PNG.lnk = C:\screen.PNG
O4 - Global Startup: SendTo.lnk = ?
O4 - Global Startup: Symantec
O4 - Global Startup: t.txt.lnk = C:\t.txt
O4 - Global Startup: Templates.lnk = ?
O4 - Global Startup: virginia.ferguson's Documents.lnk = ?
O4 - Global Startup: Windows Genuine Advantage
O4 - Global Startup: winword.doc.lnk = C:\Documents and Settings\Jason\Templates\winword.doc
O4 - Global Startup: winword2.doc.lnk = C:\Documents and Settings\Jason\Templates\winword2.doc
O4 - Global Startup: XW4400 (C) (2).lnk = ?
O4 - Global Startup: XW4400 (C).lnk = ?
O4 - Global Startup: {3248F0A6-6813-11D6-A77B-00B0D0150000}
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftup ... 0740883281
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 0740878109
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: .NET Runtime Optimization Service v2.0.50727_X86 (clr_optimization_v2.0.50727_32) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (file missing)
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

--
End of file - 11395 bytes
fhqwhgads
Active Member
 
Posts: 9
Joined: December 31st, 2008, 3:11 pm

Re: Wrong icons on my desktop and start menu

Unread postby Rodav » January 8th, 2009, 9:28 pm

Hi fhqwhgads,

Is this a business pc?
Do you know this site guaranty.com?
User avatar
Rodav
MRU Master Emeritus
 
Posts: 1480
Joined: April 19th, 2007, 6:44 am
Location: Here, there and yonder.

Re: Wrong icons on my desktop and start menu

Unread postby fhqwhgads » January 8th, 2009, 10:26 pm

Hey Rodav,

This is a computer I bought from where I work. Guaranty.com is their main site. I've asked the IT guys there and they won't fix it for free since it is my computer now. They said I bought it as-is. It isn't connected to their network anymore and has worked fine until just recently.
fhqwhgads
Active Member
 
Posts: 9
Joined: December 31st, 2008, 3:11 pm

Re: Wrong icons on my desktop and start menu

Unread postby Rodav » January 9th, 2009, 9:23 am

Step 1:
  • Run HijackThis
  • Click on the Scan button
  • Put a check beside all of the items listed below (if present):

    F2 - REG:system.ini: Shell=Explorer.exe cmd /c C:\WINDOWS\system32\DontDelete.exe
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1


  • Close all open windows and browsers/email, etc...
  • Click on the "Fix Checked" button
  • When completed, close the application and Restart your computer.

Step 2:
Please download ATF cleaner
Make sure that all browser windows are closed.
    Double-click ATF-Cleaner.exe to run the program.
    Under Main choose: Select All
    Deselect Cookies
    Click the Empty Selected button.
    You can select cookies but you will have to re enter your login details to websites you frequent.
If you use Firefox browser
    Click Firefox at the top and choose: Select All
    Deselect Firefox Cookies
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
    Click Opera at the top and choose: Select All
    Deselect Opera Cookies
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

Step 3:
Please download OTScanIt2 from Geeks to Go or Bleeping Computer. Save it to your desktop.

  1. Double click on OTScanIt2.exe to run it.
  2. Click on Extract. Once done, you will be prompted. Click OK and click Close.
  3. Double click on the OTScanIt2 folder. Double click on OTScanIt2.exe to run it.
  4. Click on Run Scan at the top left hand corner.
  5. When done, Notepad will open. Please post this log in your next reply.
User avatar
Rodav
MRU Master Emeritus
 
Posts: 1480
Joined: April 19th, 2007, 6:44 am
Location: Here, there and yonder.

Re: Wrong icons on my desktop and start menu

Unread postby fhqwhgads » January 9th, 2009, 1:34 pm

Okay, I did exactly as you said except I saved OTScanIt to C:\ instead of the desktop like you said to do with ComboFix. Here is the OTScanIt.Txt log:

Code: Select all
OTScanIt2 logfile created on: 1/9/2009 9:26:23 AM - Run 1
OTScanIt2 by OldTimer - Version 1.0.6.2     Folder = C:\OTScanIt2
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
1023.36 Mb Total Physical Memory | 555.02 Mb Available Physical Memory | 54.23% Memory free
2.90 Gb Paging File | 2.55 Gb Available in Paging File | 87.95% Paging File free
Paging file location(s): C:\pagefile.sys 2048 2048;
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 134.00 Gb Free Space | 89.91% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: UNTITLED
Current User Name: Jason
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Whitelist: On
File Age = 30 Days
 
[Processes - Safe List]
ccapp.exe -> %CommonProgramFiles%\Symantec Shared\ccApp.exe -> [2007/05/29 16:33:22 | 00,052,840 | ---- | M] (Symantec Corporation)
ccevtmgr.exe -> %CommonProgramFiles%\Symantec Shared\ccEvtMgr.exe -> [2007/05/29 16:33:26 | 00,192,104 | ---- | M] (Symantec Corporation)
ccsetmgr.exe -> %CommonProgramFiles%\Symantec Shared\ccSetMgr.exe -> [2007/05/29 16:33:36 | 00,169,576 | ---- | M] (Symantec Corporation)
defwatch.exe -> %ProgramFiles%\Symantec AntiVirus\DefWatch.exe -> [2007/10/07 20:48:24 | 00,031,160 | ---- | M] (Symantec Corporation)
dlactrlw.exe -> %SystemRoot%\system32\DLA\DLACTRLW.EXE -> [2006/02/16 05:10:00 | 00,122,940 | ---- | M] (Sonic Solutions)
iexplore.exe -> %ProgramFiles%\Internet Explorer\iexplore.exe -> [2008/10/14 23:06:26 | 00,633,632 | ---- | M] (Microsoft Corporation)
issch.exe -> %CommonProgramFiles%\InstallShield\UpdateService\issch.exe -> [2004/07/27 16:50:18 | 00,081,920 | ---- | M] (InstallShield Software Corporation)
msmsgs.exe -> %ProgramFiles%\Messenger\msmsgs.exe -> [2008/04/13 16:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
nvsvc32.exe -> %SystemRoot%\system32\nvsvc32.exe -> [2006/05/27 02:41:00 | 00,143,428 | ---- | M] (NVIDIA Corporation)
otscanit2.exe -> %SystemDrive%\OTScanIt2\OTScanIt2.exe -> [2009/01/09 09:03:22 | 00,485,376 | ---- | M] (OldTimer Tools)
rthdcpl.exe -> %SystemRoot%\RTHDCPL.EXE -> [2007/08/20 07:38:02 | 16,384,512 | ---- | M] (Realtek Semiconductor Corp.)
rtvscan.exe -> %ProgramFiles%\Symantec AntiVirus\Rtvscan.exe -> [2007/10/07 20:48:32 | 01,822,648 | ---- | M] (Symantec Corporation)
scheduler.exe -> %SystemRoot%\SMINST\Scheduler.exe -> [2006/07/10 11:53:08 | 00,872,448 | ---- | M] ()
searchindexer.exe -> %SystemRoot%\system32\searchindexer.exe -> [2008/05/26 22:18:44 | 00,439,808 | ---- | M] (Microsoft Corporation)
spbbcsvc.exe -> %CommonProgramFiles%\Symantec Shared\SPBBC\SPBBCSvc.exe -> [2007/07/26 19:25:20 | 01,181,016 | ---- | M] (Symantec Corporation)
vptray.exe -> %ProgramFiles%\Symantec AntiVirus\VPTray.exe -> [2007/10/07 20:48:40 | 00,125,368 | ---- | M] (Symantec Corporation)
wmiprvse.exe -> %SystemRoot%\system32\wbem\wmiprvse.exe -> [2008/04/13 16:12:40 | 00,218,112 | ---- | M] (Microsoft Corporation)
wuauclt.exe -> %SystemRoot%\system32\wuauclt.exe -> [2008/10/16 14:09:44 | 00,051,224 | ---- | M] (Microsoft Corporation)
 
[Win32 Services - Safe List]
(aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] ->  -> File not found
(ccEvtMgr) Symantec Event Manager [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\ccEvtMgr.exe -> [2007/05/29 16:33:26 | 00,192,104 | ---- | M] (Symantec Corporation)
(ccSetMgr) Symantec Settings Manager [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\ccSetMgr.exe -> [2007/05/29 16:33:36 | 00,169,576 | ---- | M] (Symantec Corporation)
(clr_optimization_v2.0.50727_32) .NET Runtime Optimization Service v2.0.50727_X86 [Win32_Own | Auto | Stopped] ->  -> File not found
(DefWatch) Symantec AntiVirus Definition Watcher [Win32_Own | Auto | Running] -> %ProgramFiles%\Symantec AntiVirus\DefWatch.exe -> [2007/10/07 20:48:24 | 00,031,160 | ---- | M] (Symantec Corporation)
(LiveUpdate) LiveUpdate [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Symantec\LiveUpdate\LuComServer_3_2.EXE -> [2007/08/28 19:04:25 | 02,999,664 | ---- | M] (Symantec Corporation)
(NVSvc) NVIDIA Display Driver Service [Win32_Own | Auto | Running] -> %SystemRoot%\system32\nvsvc32.exe -> [2006/05/27 02:41:00 | 00,143,428 | ---- | M] (NVIDIA Corporation)
(odserv) Microsoft Office Diagnostics Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Microsoft Shared\OFFICE12\ODSERV.EXE -> [2007/08/24 03:19:12 | 00,443,776 | ---- | M] (Microsoft Corporation)
(ose) Office Source Engine [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Microsoft Shared\Source Engine\OSE.EXE -> [2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation)
(PCA) PC Angel [Win32_Own | Auto | Stopped] -> %SystemRoot%\SMINST\PCAngel.exe -> [2006/06/13 16:39:58 | 00,364,544 | ---- | M] (SoftThinks)
(SavRoam) SavRoam [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Symantec AntiVirus\SavRoam.exe -> [2007/10/07 20:48:36 | 00,116,664 | ---- | M] (symantec)
(SNDSrvc) Symantec Network Drivers Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Symantec Shared\SNDSrvc.exe -> [2007/08/27 17:14:00 | 00,214,408 | ---- | M] (Symantec Corporation)
(SPBBCSvc) Symantec SPBBCSvc [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\SPBBC\SPBBCSvc.exe -> [2007/07/26 19:25:20 | 01,181,016 | ---- | M] (Symantec Corporation)
(Symantec AntiVirus) Symantec AntiVirus [Win32_Own | Auto | Running] -> %ProgramFiles%\Symantec AntiVirus\Rtvscan.exe -> [2007/10/07 20:48:32 | 01,822,648 | ---- | M] (Symantec Corporation)
(WMPNetworkSvc) Windows Media Player Network Sharing Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Windows Media Player\wmpnetwk.exe -> [2006/10/18 20:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation)
(WSearch) Windows Search [Win32_Own | Auto | Running] -> %SystemRoot%\system32\searchindexer.exe -> [2008/05/26 22:18:44 | 00,439,808 | ---- | M] (Microsoft Corporation)
 
[Driver Services - Safe List]
(ac97intc) Intel(r) 82801 Audio Driver Install Service (WDM) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ac97intc.sys -> [2001/08/16 23:20:04 | 00,096,256 | ---- | M] (Intel Corporation)
(adpu320) adpu320 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\adpu320.sys -> [2002/05/08 09:44:42 | 00,105,472 | ---- | M] (Adaptec, Inc.)
(b57w2k) Broadcom NetXtreme Gigabit Ethernet [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\b57xp32.sys -> [2007/07/22 21:41:06 | 00,161,792 | ---- | M] (Broadcom Corporation)
(Blfp) Broadcom Advanced Server Program Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\baspxp32.sys -> [2006/04/07 14:19:32 | 00,067,584 | ---- | M] (Broadcom Corporation)
(DLABOIOM) DLABOIOM [File_System | Auto | Running] -> %SystemRoot%\system32\DLA\DLABOIOM.SYS -> [2006/02/16 05:10:00 | 00,025,628 | ---- | M] (Sonic Solutions)
(DLACDBHM) DLACDBHM [File_System | System | Running] -> %SystemRoot%\system32\drivers\DLACDBHM.SYS -> [2005/07/07 09:03:34 | 00,005,628 | ---- | M] (Sonic Solutions)
(DLADResN) DLADResN [File_System | Auto | Running] -> %SystemRoot%\system32\DLA\DLADResN.SYS -> [2006/02/16 05:10:00 | 00,002,496 | ---- | M] (Sonic Solutions)
(DLAIFS_M) DLAIFS_M [File_System | Auto | Running] -> %SystemRoot%\system32\DLA\DLAIFS_M.SYS -> [2006/02/16 05:10:00 | 00,086,524 | ---- | M] (Sonic Solutions)
(DLAOPIOM) DLAOPIOM [File_System | Auto | Running] -> %SystemRoot%\system32\DLA\DLAOPIOM.SYS -> [2006/02/16 05:10:00 | 00,014,684 | ---- | M] (Sonic Solutions)
(DLAPoolM) DLAPoolM [File_System | Auto | Running] -> %SystemRoot%\system32\DLA\DLAPoolM.SYS -> [2006/02/16 05:10:00 | 00,006,364 | ---- | M] (Sonic Solutions)
(DLARTL_N) DLARTL_N [File_System | System | Running] -> %SystemRoot%\system32\drivers\DLARTL_N.SYS -> [2005/07/07 09:02:56 | 00,022,684 | ---- | M] (Sonic Solutions)
(DLAUDFAM) DLAUDFAM [File_System | Auto | Running] -> %SystemRoot%\system32\DLA\DLAUDFAM.SYS -> [2006/02/16 05:10:00 | 00,092,700 | ---- | M] (Sonic Solutions)
(DLAUDF_M) DLAUDF_M [File_System | Auto | Running] -> %SystemRoot%\system32\DLA\DLAUDF_M.SYS -> [2006/02/16 05:10:00 | 00,087,004 | ---- | M] (Sonic Solutions)
(DRVMCDB) DRVMCDB [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\DRVMCDB.SYS -> [2005/07/28 03:30:00 | 00,088,704 | ---- | M] (Sonic Solutions)
(DRVNDDM) DRVNDDM [File_System | Auto | Running] -> %SystemRoot%\system32\drivers\DRVNDDM.SYS -> [2005/07/07 05:10:00 | 00,040,544 | ---- | M] (Sonic Solutions)
(E100B) Intel(R) PRO Adapter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\e100b325.sys -> [2001/08/16 23:12:10 | 00,117,760 | ---- | M] (Intel Corporation)
(eeCtrl) Symantec Eraser Control driver [Kernel | System | Running] -> %CommonProgramFiles%\Symantec Shared\EENGINE\eeCtrl.sys -> [2008/12/17 08:35:52 | 00,371,248 | ---- | M] (Symantec Corporation)
(EraserUtilRebootDrv) EraserUtilRebootDrv [Kernel | On_Demand | Running] -> %CommonProgramFiles%\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -> [2008/12/17 08:35:52 | 00,099,376 | ---- | M] (Symantec Corporation)
(HDAudBus) Microsoft UAA Bus Driver for High Definition Audio [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\hdaudbus.sys -> [2008/04/13 08:36:05 | 00,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider)
(i81x) i81x [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\i81xnt5.sys -> [2004/08/03 09:29:38 | 00,161,020 | ---- | M] (Intel(R) Corporation)
(iAimFP0) iAimFP0 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wADV01nt.sys -> [2004/08/03 09:29:38 | 00,012,415 | ---- | M] (Intel(R) Corporation)
(iAimFP1) iAimFP1 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wADV02NT.sys -> [2004/08/03 09:29:38 | 00,012,127 | ---- | M] (Intel(R) Corporation)
(iAimFP2) iAimFP2 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wADV05NT.sys -> [2004/08/03 09:29:38 | 00,011,775 | ---- | M] (Intel(R) Corporation)
(iAimFP3) iAimFP3 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wSiINTxx.sys -> [2004/08/03 09:29:48 | 00,012,063 | ---- | M] (Intel(R) Corporation)
(iAimFP4) iAimFP4 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wVchNTxx.sys -> [2004/08/03 09:29:50 | 00,019,455 | ---- | M] (Intel(R) Corporation)
(iAimFP5) iAimFP5 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wADV07nt.sys -> [2004/08/03 09:29:40 | 00,011,807 | ---- | M] (Intel(R) Corporation)
(iAimFP6) iAimFP6 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wADV08NT.sys -> [2004/08/03 09:29:40 | 00,011,295 | ---- | M] (Intel(R) Corporation)
(iAimFP7) iAimFP7 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wADV09NT.sys -> [2004/08/03 09:29:42 | 00,011,871 | ---- | M] (Intel(R) Corporation)
(iAimTV0) iAimTV0 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wATV01nt.sys -> [2004/08/03 09:29:42 | 00,029,311 | ---- | M] (Intel(R) Corporation)
(iAimTV1) iAimTV1 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wATV02NT.sys -> [2004/08/03 09:29:44 | 00,019,551 | ---- | M] (Intel(R) Corporation)
(iAimTV3) iAimTV3 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wATV04nt.sys -> [2004/08/03 09:29:44 | 00,033,599 | ---- | M] (Intel(R) Corporation)
(iAimTV4) iAimTV4 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wCh7xxNT.sys -> [2004/08/03 09:29:46 | 00,023,615 | ---- | M] (Intel(R) Corporation)
(iAimTV5) iAimTV5 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wATV10nt.sys -> [2004/08/03 09:29:46 | 00,025,471 | ---- | M] (Intel(R) Corporation)
(iAimTV6) iAimTV6 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wATV06nt.sys -> [2004/08/03 09:29:46 | 00,022,271 | ---- | M] (Intel(R) Corporation)
(iaStor) Intel RAID Controller [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\iaStor.sys -> [2006/01/16 14:12:16 | 00,824,960 | ---- | M] (Intel Corporation)
(IntcAzAudAddService) Service for Realtek HD Audio (WDM) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\RtkHDAud.sys -> [2007/08/28 08:55:10 | 04,609,024 | ---- | M] (Realtek Semiconductor Corp.)
(kbdhid) Keyboard HID Driver [Kernel | System | Stopped] -> %SystemRoot%\system32\drivers\kbdhid.sys -> [2008/04/13 10:39:48 | 00,014,592 | ---- | M] (Microsoft Corporation)
(NAVENG) NAVENG [Kernel | On_Demand | Running] -> %CommonProgramFiles%\Symantec Shared\VirusDefs\20090108.007\NAVENG.SYS -> [2008/12/17 08:35:52 | 00,089,104 | ---- | M] (Symantec Corporation)
(NAVEX15) NAVEX15 [Kernel | On_Demand | Running] -> %CommonProgramFiles%\Symantec Shared\VirusDefs\20090108.007\NAVEX15.SYS -> [2008/12/17 08:35:52 | 00,876,112 | ---- | M] (Symantec Corporation)
(nv) nv [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\nv4_mini.sys -> [2006/05/27 02:41:00 | 03,655,936 | ---- | M] (NVIDIA Corporation)
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ptilink.sys -> [2006/02/27 18:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.)
(PxHelp20) PxHelp20 [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\pxhelp20.sys -> [2005/04/25 02:03:00 | 00,020,640 | ---- | M] (Sonic Solutions)
(SAVRT) SAVRT [Kernel | System | Running] -> %ProgramFiles%\Symantec AntiVirus\savrt.sys -> [2006/09/06 14:41:20 | 00,337,592 | ---- | M] (Symantec Corporation)
(SAVRTPEL) SAVRTPEL [Kernel | System | Running] -> %ProgramFiles%\Symantec AntiVirus\Savrtpel.sys -> [2006/09/06 14:41:20 | 00,054,968 | ---- | M] (Symantec Corporation)
(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\secdrv.sys -> [2007/11/13 02:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(SPBBCDrv) SPBBCDrv [Kernel | System | Running] -> %CommonProgramFiles%\Symantec Shared\SPBBC\SPBBCDrv.sys -> [2007/07/26 19:25:18 | 00,400,216 | ---- | M] (Symantec Corporation)
(symc810) symc810 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\symc810.sys -> [2001/08/17 08:07:34 | 00,016,256 | ---- | M] (Symbios Logic Inc.)
(symc8xx) symc8xx [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\symc8xx.sys -> [2001/08/17 08:07:36 | 00,032,640 | ---- | M] (LSI Logic)
(SymEvent) SymEvent [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\SYMEVENT.SYS -> [2008/12/31 09:14:24 | 00,110,952 | ---- | M] (Symantec Corporation)
(Symmpi) Symmpi [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\symmpi.sys -> [2002/04/03 21:32:06 | 00,028,416 | R--- | M] (LSI Logic)
(SYMREDRV) SYMREDRV [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\symredrv.sys -> [2007/08/27 17:13:32 | 00,023,944 | ---- | M] (Symantec Corporation)
(SYMTDI) SYMTDI [Kernel | System | Running] -> %SystemRoot%\system32\drivers\symtdi.sys -> [2007/08/27 17:13:36 | 00,189,320 | ---- | M] (Symantec Corporation)
(sym_hi) sym_hi [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\sym_hi.sys -> [2001/08/17 08:07:40 | 00,028,384 | ---- | M] (LSI Logic)
(sym_u3) sym_u3 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\sym_u3.sys -> [2001/08/17 08:07:42 | 00,030,688 | ---- | M] (LSI Logic)
(WmiAcpi) Microsoft Windows Management Interface for ACPI [Kernel | System | Running] -> %SystemRoot%\system32\drivers\wmiacpi.sys -> [2008/04/13 10:36:38 | 00,008,832 | ---- | M] (Microsoft Corporation)
 
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://my.guaranty.com/ -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" ->  -> 
HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons -> 
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm -> 
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk -> 
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://go.microsoft.com/fwlink/?LinkId=69157 -> 
HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> 
HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> 
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> 
HKEY_CURRENT_USER\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm -> 
HKEY_CURRENT_USER\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> 
HKEY_CURRENT_USER\: Main\\"Start Page" -> http://www.google.com/ -> 
HKEY_CURRENT_USER\: "ProxyEnable" -> 0 -> 
Hosts file not found -> -> 
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> 
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> %ProgramFiles%\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> [2006/01/12 20:38:22 | 00,063,128 | ---- | M] (Adobe Systems Incorporated)
{5CA3D70E-1895-11CF-8E15-001234567890} [HKLM] -> %SystemRoot%\system32\DLA\DLASHX_W.DLL [DriveLetterAccess] -> [2006/02/16 05:10:00 | 00,110,652 | ---- | M] (Sonic Solutions)
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"ccApp" -> %CommonProgramFiles%\Symantec Shared\ccApp.exe ["C:\Program Files\Common Files\Symantec Shared\ccApp.exe"] -> [2007/05/29 16:33:22 | 00,052,840 | ---- | M] (Symantec Corporation)
"DLA" -> %SystemRoot%\system32\DLA\DLACTRLW.EXE [C:\WINDOWS\System32\DLA\DLACTRLW.EXE] -> [2006/02/16 05:10:00 | 00,122,940 | ---- | M] (Sonic Solutions)
"ISUSPM Startup" -> %CommonProgramFiles%\InstallShield\UpdateService\ISUSPM.exe [C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup] -> [2004/07/27 16:50:42 | 00,221,184 | ---- | M] (InstallShield Software Corporation)
"ISUSScheduler" -> %CommonProgramFiles%\InstallShield\UpdateService\issch.exe ["C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start] -> [2004/07/27 16:50:18 | 00,081,920 | ---- | M] (InstallShield Software Corporation)
"NvCplDaemon" -> %SystemRoot%\system32\nvcpl.dll [RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup] -> [2006/05/27 02:41:00 | 07,561,216 | ---- | M] (NVIDIA Corporation)
"nwiz" -> %SystemRoot%\system32\nwiz.exe [nwiz.exe /installquiet] -> [2006/05/27 02:41:00 | 01,519,616 | ---- | M] ()
"Recguard" -> %SystemRoot%\SMINST\Recguard.exe [C:\WINDOWS\Sminst\Recguard.exe] -> [2006/05/12 12:50:16 | 01,138,688 | ---- | M] ()
"Reminder" -> %SystemRoot%\CREATOR\Remind_XP.exe [C:\WINDOWS\Creator\Remind_XP.exe] -> [2006/03/31 14:44:26 | 00,761,856 | ---- | M] ()
"RTHDCPL" -> %SystemRoot%\RTHDCPL.EXE [RTHDCPL.EXE] -> [2007/08/20 07:38:02 | 16,384,512 | ---- | M] (Realtek Semiconductor Corp.)
"Scheduler" -> %SystemRoot%\SMINST\Scheduler.exe [C:\WINDOWS\SMINST\Scheduler.exe] -> [2006/07/10 11:53:08 | 00,872,448 | ---- | M] ()
"vptray" -> %ProgramFiles%\Symantec AntiVirus\VPTray.exe [C:\PROGRA~1\SYMANT~1\VPTray.exe] -> [2007/10/07 20:48:40 | 00,125,368 | ---- | M] (Symantec Corporation)
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"MSMSGS" -> %ProgramFiles%\Messenger\msmsgs.exe ["C:\Program Files\Messenger\msmsgs.exe" /background] -> [2008/04/13 16:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
< Jason Startup Folder > -> C:\Documents and Settings\Jason\Local Settings\Application Data -> 
%UserProfile%\Local Settings\Application Data\1099Correction Note to customer.doc.lnk -> %UserProfile%\virginia.ferguson's Documents\1099Correction Note to customer.doc -> File not found
%UserProfile%\Local Settings\Application Data\2007 DEMOS.xlsx.lnk -> %UserProfile%\virginia.ferguson's Documents\2007 DEMOS.xlsx -> File not found
 -> %UserProfile%\Local Settings\Application Data\Adobe -> [2009/01/06 13:01:27 | 00,000,000 | ---D | M]
%UserProfile%\Local Settings\Application Data\ADS-DEMOS-INT 1099.xlsx.lnk -> %UserProfile%\virginia.ferguson's Documents\ADS-DEMOS-INT 1099.xlsx -> File not found
%UserProfile%\Local Settings\Application Data\ADVERTISING LISTING.pdf.lnk -> %UserProfile%\virginia.ferguson's Documents\ADVERTISING LISTING.pdf -> File not found
 -> %UserProfile%\Local Settings\Application Data\AntiPhishing -> [2009/01/05 19:02:46 | 00,000,000 | ---D | M]
 -> %UserProfile%\Local Settings\Application Data\ApplicationHistory -> [2006/11/11 04:16:26 | 00,000,000 | ---D | M]
 -> %UserProfile%\Local Settings\Application Data\Asent -> [2008/07/07 06:45:05 | 00,000,000 | ---D | M]
%UserProfile%\Local Settings\Application Data\AVIAD #160.pdf.lnk -> %UserProfile%\virginia.ferguson's Documents\AVIAD #160.pdf -> File not found
%UserProfile%\Local Settings\Application Data\AVIAD #161.pdf.lnk -> %UserProfile%\virginia.ferguson's Documents\AVIAD #161.pdf -> File not found
%UserProfile%\Local Settings\Application Data\BOFA0408.xlsx.lnk -> %UserProfile%\virginia.ferguson's Documents\BOFA0408.xlsx -> File not found
%UserProfile%\Local Settings\Application Data\Camping World Invoices Open.xls.lnk -> %UserProfile%\virginia.ferguson's Documents\Camping World Invoices Open.xls -> File not found
%UserProfile%\Local Settings\Application Data\City of Coburg-Palm Harbor.xlsx.lnk -> %UserProfile%\virginia.ferguson's Documents\City of Coburg-Palm Harbor.xlsx -> File not found
%UserProfile%\Local Settings\Application Data\ClearChannelOutdoor letter.docx.lnk -> %UserProfile%\virginia.ferguson's Documents\ClearChannelOutdoor letter.docx -> File not found
%UserProfile%\Local Settings\Application Data\Cmpg Wrld Open Invoces.xlsx.lnk -> %UserProfile%\virginia.ferguson's Documents\Cmpg Wrld Open Invoces.xlsx -> File not found
%UserProfile%\Local Settings\Application Data\COMPANY VEHICLE LIST OCT07.xlsx.lnk -> %UserProfile%\virginia.ferguson's Documents\COMPANY VEHICLE LIST OCT07.xlsx -> File not found
%UserProfile%\Local Settings\Application Data\concompform.pdf.lnk -> %UserProfile%\virginia.ferguson's Documents\concompform.pdf -> File not found
 -> %UserProfile%\Local Settings\Application Data\Content.IE5 -> [2009/01/05 19:02:45 | 00,000,000 | -HSD | M]
%UserProfile%\Local Settings\Application Data\Cookies.lnk -> %UserProfile%\Local Settings -> [2009/01/07 17:59:05 | 00,000,000 | -HSD | M]
%UserProfile%\Local Settings\Application Data\Corrected 1099s for ACTA & Herb.pdf.lnk -> %UserProfile%\virginia.ferguson's Documents\Corrected 1099s for ACTA & Herb.pdf -> File not found
%UserProfile%\Local Settings\Application Data\DEMO VEHICLES.xls.lnk -> %UserProfile%\virginia.ferguson's Documents\DEMO VEHICLES.xls -> File not found
%UserProfile%\Local Settings\Application Data\excel.xls.lnk -> %UserProfile%\Templates\excel.xls -> File not found
%UserProfile%\Local Settings\Application Data\excel4.xls.lnk -> %UserProfile%\Templates\excel4.xls -> File not found
%UserProfile%\Local Settings\Application Data\ext list 011608.xlsx.lnk -> %UserProfile%\virginia.ferguson's Documents\ext list 011608.xlsx -> File not found
%UserProfile%\Local Settings\Application Data\FAX COVER.xls.lnk -> %UserProfile%\virginia.ferguson's Documents\FAX COVER.xls -> File not found
%UserProfile%\Local Settings\Application Data\Fax Coversheet Master.doc.lnk -> %UserProfile%\virginia.ferguson's Documents\Fax Coversheet Master.doc -> File not found
%UserProfile%\Local Settings\Application Data\GARLIC FARM ANNEX 2005.xlsx.lnk -> %UserProfile%\virginia.ferguson's Documents\GARLIC FARM ANNEX 2005.xlsx -> File not found
 -> %UserProfile%\Local Settings\Application Data\GDIPFONTCACHEV1.DAT -> [2009/01/05 17:50:32 | 00,071,320 | ---- | M] ()
 -> %UserProfile%\Local Settings\Application Data\Google -> [2008/12/31 08:25:57 | 00,000,000 | ---D | M]
%UserProfile%\Local Settings\Application Data\GUARANTY RV CFN GAS-CARD LISTING.xls.lnk -> %UserProfile%\virginia.ferguson's Documents\GUARANTY RV CFN GAS-CARD LISTING.xls -> File not found
 -> %UserProfile%\Local Settings\Application Data\History.IE5 -> [2009/01/06 12:47:11 | 00,000,000 | -HSD | M]
 -> %UserProfile%\Local Settings\Application Data\IconCache.db -> [2009/01/09 09:13:57 | 04,303,748 | -H-- | M] ()
 -> %UserProfile%\Local Settings\Application Data\Identities -> [2008/12/31 09:03:07 | 00,000,000 | ---D | M]
 -> %UserProfile%\Local Settings\Application Data\index.dat -> [2009/01/06 13:03:34 | 00,016,384 | -HS- | M] ()
 -> %UserProfile%\Local Settings\Application Data\InstallShield -> [2009/01/04 01:10:37 | 00,000,000 | ---D | M]
%UserProfile%\Local Settings\Application Data\jason@2o7[1].txt.lnk -> %UserProfile%\Cookies\jason@2o7[1].txt -> File not found
%UserProfile%\Local Settings\Application Data\jason@google[1].txt.lnk -> %UserProfile%\Cookies\jason@google[1].txt -> File not found
%UserProfile%\Local Settings\Application Data\jason@google[2].txt.lnk -> %UserProfile%\Cookies\jason@google[2].txt -> File not found
%UserProfile%\Local Settings\Application Data\jason@m.webtrends[2].txt.lnk -> %UserProfile%\Cookies\jason@m.webtrends[2].txt -> File not found
%UserProfile%\Local Settings\Application Data\jason@microsoft[1].txt.lnk -> %UserProfile%\Cookies\jason@microsoft[1].txt -> File not found
%UserProfile%\Local Settings\Application Data\jason@office.microsoft[2].txt.lnk -> %UserProfile%\Cookies\jason@office.microsoft[2].txt -> File not found
%UserProfile%\Local Settings\Application Data\jason@sdc.windowsmarketplace[1].txt.lnk -> %UserProfile%\Local Settings\jason@sdc.windowsmarketplace[1].txt -> File not found
%UserProfile%\Local Settings\Application Data\jason@sdc.windowsmarketplace[2].txt.lnk -> %UserProfile%\Local Settings\jason@sdc.windowsmarketplace[2].txt -> File not found
%UserProfile%\Local Settings\Application Data\jason@windowsmarketplace[1].txt.lnk -> %UserProfile%\Local Settings\jason@windowsmarketplace[1].txt -> File not found
%UserProfile%\Local Settings\Application Data\jason@www.microsoft[2].txt.lnk -> %UserProfile%\Cookies\jason@www.microsoft[2].txt -> File not found
%UserProfile%\Local Settings\Application Data\JERRY BROWN 20410.xlsx.lnk -> %UserProfile%\virginia.ferguson's Documents\JERRY BROWN 20410.xlsx -> File not found
%UserProfile%\Local Settings\Application Data\JERRY BROWN CARD HOLDERS MAR08.xlsx.lnk -> %UserProfile%\virginia.ferguson's Documents\JERRY BROWN CARD HOLDERS MAR08.xlsx -> File not found
%UserProfile%\Local Settings\Application Data\Local Settings.lnk -> %UserProfile%\Local Settings -> [2009/01/07 17:59:05 | 00,000,000 | -HSD | M]
 -> %UserProfile%\Local Settings\Application Data\Microsoft -> [2008/12/31 09:12:59 | 00,000,000 | ---D | M]
 -> %UserProfile%\Local Settings\Application Data\Microsoft -> [2008/12/31 09:12:59 | 00,000,000 | ---D | M]
%UserProfile%\Local Settings\Application Data\Normal.dotm.lnk -> %AppData%\Microsoft\Templates\Normal.dotm -> [2009/01/06 13:03:06 | 00,015,259 | ---- | M] ()
%UserProfile%\Local Settings\Application Data\powerpnt.ppt.lnk -> %UserProfile%\Local Settings\powerpnt.ppt -> File not found
%UserProfile%\Local Settings\Application Data\screen.PNG.lnk -> %SystemDrive%\screen.PNG -> File not found
%UserProfile%\Local Settings\Application Data\SendTo.lnk -> %UserProfile%\Local Settings -> [2009/01/07 17:59:05 | 00,000,000 | -HSD | M]
 -> %UserProfile%\Local Settings\Application Data\Symantec -> [2008/12/30 17:04:06 | 00,000,000 | ---D | M]
%UserProfile%\Local Settings\Application Data\t.txt.lnk -> %SystemDrive%\t.txt -> File not found
%UserProfile%\Local Settings\Application Data\Templates.lnk -> %AppData%\Microsoft\Templates -> [2009/01/09 09:20:43 | 00,000,000 | ---D | M]
%UserProfile%\Local Settings\Application Data\virginia.ferguson's Documents.lnk ->  -> File not found
 ->  -> File not found
%UserProfile%\Local Settings\Application Data\winword.doc.lnk -> %UserProfile%\Local Settings\winword.doc -> File not found
%UserProfile%\Local Settings\Application Data\winword2.doc.lnk -> %UserProfile%\Local Settings\winword2.doc -> File not found
%UserProfile%\Local Settings\Application Data\XW4400 (C) (2).lnk ->  -> File not found
%UserProfile%\Local Settings\Application Data\XW4400 (C).lnk ->  -> File not found
 -> %UserProfile%\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150000} -> [2006/11/11 04:17:29 | 00,000,000 | ---D | M]
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"dontdisplaylastusername" ->  [0] -> File not found
\\"legalnoticecaption" ->  [] -> File not found
\\"legalnoticetext" ->  [] -> File not found
\\"shutdownwithoutlogon" ->  [1] -> File not found
\\"undockwithoutlogon" ->  [1] -> File not found
< CurrentVersion Policy Settings - Explorer [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [145] -> File not found
< CurrentVersion Policy Settings - System [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> 
< Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> 
E&xport to Microsoft Excel -> %ProgramFiles%\Microsoft Office\Office12\EXCEL.EXE [res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000] -> [2008/10/18 18:30:22 | 17,931,616 | ---- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> 
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC} [HKLM] -> %ProgramFiles%\Java\jre1.5.0\bin\NPJPI150.dll [Menu: Sun Java Console] -> [2006/11/11 04:17:31 | 00,069,740 | ---- | M] (Sun Microsystems, Inc.)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> %ProgramFiles%\Microsoft Office\Office12\REFIEBAR.DLL [Button: Research] -> [2006/10/26 20:12:22 | 00,040,424 | ---- | M] (Microsoft Corporation)
{e2e2dd38-d088-4134-82b7-f2ba38496583}:Exec [HKLM] -> %SystemRoot%\network diagnostic\xpnetdiag.exe [Menu: @xpsp3res.dll,-20001] -> [2008/04/13 10:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Button: Messenger] -> [2008/04/13 16:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Menu: Windows Messenger] -> [2008/04/13 16:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> 
PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> 
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> 
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. -> 
1 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> 
{6414512B-B978-451D-A0D8-FCFDF33E833C} [HKLM] -> http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1230740883281 [WUWebControl Class] -> 
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} [HKLM] -> http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1230740878109 [MUWebControl Class] -> 
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab [Java Plug-in 1.5.0] -> 
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} [HKLM] -> http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab [Reg Error: Key does not exist or could not be opened.] -> 
{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab [Java Plug-in 1.5.0] -> 
{D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab [Shockwave Flash Object] -> 
< DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> 
{B7066BE0-4C4D-44DB-99C0-DB2F934B3E04} ->    (Broadcom NetXtreme Gigabit Ethernet) -> 
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell -> 
cmd -> %SystemRoot%\system32\cmd.exe -> [2008/04/13 16:12:14 | 00,389,120 | ---- | M] (Microsoft Corporation)
/c ->  -> File not found
C:\WINDOWS\system32\DontDelete.exe -> %SystemRoot%\system32\DontDelete.exe -> File not found
*MultiFile Done* -> -> 
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> 
NavLogon -> %SystemRoot%\system32\NavLogon.dll -> [2007/10/07 20:48:46 | 00,043,448 | ---- | M] (Symantec Corporation)
< ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks -> 
"{56F9679E-7826-4C84-81F3-532071A8BCC5}" [HKLM] -> %ProgramFiles%\Windows Desktop Search\MSNLNamespaceMgr.dll [] -> [2008/05/26 22:19:02 | 00,304,128 | ---- | M] (Microsoft Corporation)
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List -> 
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\network diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 10:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/13 16:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation)
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List -> 
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\network diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 10:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/13 16:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" -> C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE [C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook] -> [2008/05/21 04:37:24 | 12,844,576 | ---- | M] (Microsoft Corporation)
"C:\WINDOWS\SMINST\Scheduler.exe" -> C:\WINDOWS\SMINST\Scheduler.exe [C:\WINDOWS\SMINST\Scheduler.exe:*:Enabled:Scheduler ] -> [2006/07/10 11:53:08 | 00,872,448 | ---- | M] ()
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot -> 
"AlternateShell" -> cmd.exe -> 
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 -> 
"DisplayName" -> CD-ROM Driver -> 
"ImagePath" -> %SystemRoot%\system32\drivers\cdrom.sys [system32\DRIVERS\cdrom.sys] -> [2008/04/13 10:40:46 | 00,062,976 | ---- | M] (Microsoft Corporation)
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 -> 
 
 
[Files/Folders - Created Within 30 Days]
1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 
1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> 
prn -> %SystemRoot%\System32\prn -> [2099/01/01 12:00:00 | 00,000,000 | ---- | C] ()
prn -> %SystemRoot%\System32\drivers\prn -> [2099/01/01 12:00:00 | 00,000,000 | ---- | C] ()
prn -> %SystemDrive%\prn -> [2099/01/01 12:00:00 | 00,000,000 | ---- | C] ()
OTScanIt2 -> %SystemDrive%\OTScanIt2 -> [2009/01/09 09:24:05 | 00,000,000 | ---D | C]
OTScanIt2.exe -> %SystemDrive%\OTScanIt2.exe -> [2009/01/09 09:23:20 | 00,656,730 | ---- | C] ()
temp -> %AppData%\temp -> [2009/01/09 09:09:50 | 00,000,000 | ---D | C]
ComboFix -> %SystemDrive%\ComboFix -> [2009/01/08 17:38:31 | 00,000,000 | ---D | C]
Boot.bak -> %SystemDrive%\Boot.bak -> [2009/01/08 13:39:48 | 00,000,211 | ---- | C] ()
cmldr -> %SystemDrive%\cmldr -> [2009/01/08 13:39:45 | 00,260,272 | ---- | C] ()
cmdcons -> %SystemDrive%\cmdcons -> [2009/01/08 13:39:45 | 00,000,000 | RHSD | C]
SWXCACLS.exe -> %SystemRoot%\SWXCACLS.exe -> [2009/01/08 13:38:33 | 00,212,480 | ---- | C] (SteelWerX)
SWREG.exe -> %SystemRoot%\SWREG.exe -> [2009/01/08 13:38:33 | 00,161,792 | ---- | C] (SteelWerX)
SWSC.exe -> %SystemRoot%\SWSC.exe -> [2009/01/08 13:38:33 | 00,136,704 | ---- | C] (SteelWerX)
sed.exe -> %SystemRoot%\sed.exe -> [2009/01/08 13:38:33 | 00,098,816 | ---- | C] ()
fdsv.exe -> %SystemRoot%\fdsv.exe -> [2009/01/08 13:38:33 | 00,089,504 | ---- | C] (Smallfrogs Studio)
grep.exe -> %SystemRoot%\grep.exe -> [2009/01/08 13:38:33 | 00,080,412 | ---- | C] ()
zip.exe -> %SystemRoot%\zip.exe -> [2009/01/08 13:38:33 | 00,068,096 | ---- | C] ()
VFIND.exe -> %SystemRoot%\VFIND.exe -> [2009/01/08 13:38:33 | 00,049,152 | ---- | C] ()
NIRCMD.exe -> %SystemRoot%\NIRCMD.exe -> [2009/01/08 13:38:33 | 00,028,672 | ---- | C] (NirSoft)
Qoobox -> %SystemDrive%\Qoobox -> [2009/01/08 13:37:51 | 00,000,000 | ---D | C]
ERDNT -> %SystemRoot%\ERDNT -> [2009/01/08 13:37:51 | 00,000,000 | ---D | C]
InstallShield -> %AppData%\Startup\InstallShield -> [2009/01/08 13:35:44 | 00,000,000 | ---D | C]
IconCache.db -> %AppData%\IconCache.db -> [2009/01/08 13:28:35 | 03,787,872 | -H-- | C] ()
Symantec -> %AppData%\Symantec -> [2009/01/08 13:27:47 | 00,000,000 | ---D | C]
Content.Word -> %AppData%\Startup\Content.Word -> [2009/01/08 13:27:10 | 00,000,000 | -H-D | C]
Content.MSO -> %AppData%\Startup\Content.MSO -> [2009/01/08 13:27:07 | 00,000,000 | -H-D | C]
Microsoft -> %UserProfile%\Start Menu\Microsoft -> [2009/01/08 13:27:04 | 00,000,000 | ---D | C]
Symantec -> %UserProfile%\Start Menu\Symantec -> [2009/01/08 13:27:00 | 00,000,000 | ---D | C]
Normal.dotm.lnk -> %UserProfile%\Local Settings\Application Data\Normal.dotm.lnk -> [2009/01/08 09:43:59 | 00,001,004 | ---- | C] ()
Templates.lnk -> %UserProfile%\Local Settings\Application Data\Templates.lnk -> [2009/01/08 09:43:59 | 00,000,760 | ---- | C] ()
d3d8caps.dat -> %SystemRoot%\System32\d3d8caps.dat -> [2009/01/08 09:43:45 | 00,000,768 | ---- | C] ()
winword2.doc.lnk -> %UserProfile%\Local Settings\Application Data\winword2.doc.lnk -> [2009/01/08 09:43:37 | 00,000,782 | ---- | C] ()
winword.doc.lnk -> %UserProfile%\Local Settings\Application Data\winword.doc.lnk -> [2009/01/08 09:43:37 | 00,000,775 | ---- | C] ()
SendTo.lnk -> %UserProfile%\Local Settings\Application Data\SendTo.lnk -> [2009/01/08 09:43:37 | 00,000,546 | ---- | C] ()
powerpnt.ppt.lnk -> %UserProfile%\Local Settings\Application Data\powerpnt.ppt.lnk -> [2009/01/08 09:42:17 | 00,000,782 | ---- | C] ()
excel4.xls.lnk -> %UserProfile%\Local Settings\Application Data\excel4.xls.lnk -> [2009/01/08 09:42:17 | 00,000,770 | ---- | C] ()
Local Settings.lnk -> %UserProfile%\Local Settings\Application Data\Local Settings.lnk -> [2009/01/08 09:42:17 | 00,000,583 | ---- | C] ()
excel.xls.lnk -> %UserProfile%\Local Settings\Application Data\excel.xls.lnk -> [2009/01/08 09:42:16 | 00,000,763 | ---- | C] ()
AdobeUM -> %UserProfile%\SendTo\AdobeUM -> [2009/01/08 08:39:17 | 00,000,000 | ---D | C]
JERRY BROWN CARD HOLDERS MAR08.xlsx.lnk -> %UserProfile%\Local Settings\Application Data\JERRY BROWN CARD HOLDERS MAR08.xlsx.lnk -> [2009/01/08 08:39:14 | 00,000,944 | ---- | C] ()
JERRY BROWN 20410.xlsx.lnk -> %UserProfile%\Local Settings\Application Data\JERRY BROWN 20410.xlsx.lnk -> [2009/01/08 08:39:14 | 00,000,879 | ---- | C] ()
GUARANTY RV CFN GAS-CARD LISTING.xls.lnk -> %UserProfile%\Local Settings\Application Data\GUARANTY RV CFN GAS-CARD LISTING.xls.lnk -> [2009/01/08 08:39:13 | 00,000,949 | ---- | C] ()
Cookies.lnk -> %UserProfile%\Local Settings\Application Data\Cookies.lnk -> [2009/01/08 08:39:13 | 00,000,551 | ---- | C] ()
GARLIC FARM ANNEX 2005.xlsx.lnk -> %UserProfile%\Local Settings\Application Data\GARLIC FARM ANNEX 2005.xlsx.lnk -> [2009/01/08 08:39:12 | 00,000,904 | ---- | C] ()
Fax Coversheet Master.doc.lnk -> %UserProfile%\Local Settings\Application Data\Fax Coversheet Master.doc.lnk -> [2009/01/08 08:39:12 | 00,000,894 | ---- | C] ()
ext list 011608.xlsx.lnk -> %UserProfile%\Local Settings\Application Data\ext list 011608.xlsx.lnk -> [2009/01/08 08:39:12 | 00,000,869 | ---- | C] ()
FAX COVER.xls.lnk -> %UserProfile%\Local Settings\Application Data\FAX COVER.xls.lnk -> [2009/01/08 08:39:12 | 00,000,834 | ---- | C] ()
DEMO VEHICLES.xls.lnk -> %UserProfile%\Local Settings\Application Data\DEMO VEHICLES.xls.lnk -> [2009/01/08 08:39:11 | 00,000,854 | ---- | C] ()
Corrected 1099s for ACTA & Herb.pdf.lnk -> %UserProfile%\Local Settings\Application Data\Corrected 1099s for ACTA & Herb.pdf.lnk -> [2009/01/08 08:39:09 | 00,000,944 | ---- | C] ()
COMPANY VEHICLE LIST OCT07.xlsx.lnk -> %UserProfile%\Local Settings\Application Data\COMPANY VEHICLE LIST OCT07.xlsx.lnk -> [2009/01/08 08:38:58 | 00,000,924 | ---- | C] ()
ADS-DEMOS-INT 1099.xlsx.lnk -> %UserProfile%\Local Settings\Application Data\ADS-DEMOS-INT 1099.xlsx.lnk -> [2009/01/08 08:38:58 | 00,000,884 | ---- | C] ()
concompform.pdf.lnk -> %UserProfile%\Local Settings\Application Data\concompform.pdf.lnk -> [2009/01/08 08:38:58 | 00,000,844 | ---- | C] ()
Cmpg Wrld Open Invoces.xlsx.lnk -> %UserProfile%\Local Settings\Application Data\Cmpg Wrld Open Invoces.xlsx.lnk -> [2009/01/08 08:38:43 | 00,000,904 | ---- | C] ()
ClearChannelOutdoor letter.docx.lnk -> %UserProfile%\Local Settings\Application Data\ClearChannelOutdoor letter.docx.lnk -> [2009/01/08 08:38:31 | 00,000,924 | ---- | C] ()
City of Coburg-Palm Harbor.xlsx.lnk -> %UserProfile%\Local Settings\Application Data\City of Coburg-Palm Harbor.xlsx.lnk -> [2009/01/08 08:38:29 | 00,000,924 | ---- | C] ()
Camping World Invoices Open.xls.lnk -> %UserProfile%\Local Settings\Application Data\Camping World Invoices Open.xls.lnk -> [2009/01/08 08:38:29 | 00,000,924 | ---- | C] ()
AVIAD #161.pdf.lnk -> %UserProfile%\Local Settings\Application Data\AVIAD #161.pdf.lnk -> [2009/01/08 08:38:29 | 00,000,839 | ---- | C] ()
BOFA0408.xlsx.lnk -> %UserProfile%\Local Settings\Application Data\BOFA0408.xlsx.lnk -> [2009/01/08 08:38:29 | 00,000,834 | ---- | C] ()
ADVERTISING LISTING.pdf.lnk -> %UserProfile%\Local Settings\Application Data\ADVERTISING LISTING.pdf.lnk -> [2009/01/08 08:38:28 | 00,000,884 | ---- | C] ()
AVIAD #160.pdf.lnk -> %UserProfile%\Local Settings\Application Data\AVIAD #160.pdf.lnk -> [2009/01/08 08:38:28 | 00,000,839 | ---- | C] ()
2007 DEMOS.xlsx.lnk -> %UserProfile%\Local Settings\Application Data\2007 DEMOS.xlsx.lnk -> [2009/01/08 08:38:27 | 00,000,844 | ---- | C] ()
1099Correction Note to customer.doc.lnk -> %UserProfile%\Local Settings\Application Data\1099Correction Note to customer.doc.lnk -> [2009/01/08 08:38:24 | 00,000,944 | ---- | C] ()
virginia.ferguson's Documents.lnk -> %UserProfile%\Local Settings\Application Data\virginia.ferguson's Documents.lnk -> [2009/01/08 08:38:24 | 00,000,624 | ---- | C] ()
pss -> %SystemRoot%\pss -> [2009/01/08 08:28:29 | 00,000,000 | ---D | C]
ComboFix.exe -> %SystemDrive%\ComboFix.exe -> [2009/01/08 08:27:37 | 02,913,912 | R--- | C] ()
XW4400 (C) (2).lnk -> %UserProfile%\Local Settings\Application Data\XW4400 (C) (2).lnk -> [2009/01/08 08:25:28 | 00,000,305 | ---- | C] ()
screen.PNG.lnk -> %UserProfile%\Local Settings\Application Data\screen.PNG.lnk -> [2009/01/07 18:02:39 | 00,000,415 | ---- | C] ()
XW4400 (C).lnk -> %UserProfile%\Local Settings\Application Data\XW4400 (C).lnk -> [2009/01/07 18:02:39 | 00,000,305 | ---- | C] ()
Adobe -> %AllUsersProfile%\desktop\Adobe -> [2009/01/07 18:01:59 | 00,000,000 | ---D | C]
ComboFix.exe -> %UserProfile%\Start Menu\ComboFix.exe -> [2009/01/07 17:50:52 | 02,912,710 | ---- | C] ()
AntiPhishing -> %AppData%\Startup\AntiPhishing -> [2009/01/07 17:47:43 | 00,000,000 | ---D | C]
index.dat -> %AppData%\index.dat -> [2009/01/07 17:45:50 | 00,016,384 | -HS- | C] ()
PIF -> %SystemRoot%\PIF -> [2009/01/07 17:35:52 | 00,000,000 | -H-D | C]
Symantec -> %AppData%\Startup\Symantec -> [2009/01/07 16:50:10 | 00,000,000 | ---D | C]
Windows Desktop Search -> %AllUsersProfile%\desktop\Windows Desktop Search -> [2009/01/07 00:40:41 | 00,000,000 | ---D | C]
Macromedia -> %AppData%\Startup\Macromedia -> [2009/01/06 23:58:26 | 00,000,000 | ---D | C]
AdobeUM -> %AppData%\Startup\AdobeUM -> [2009/01/06 23:52:06 | 00,000,000 | ---D | C]
Adobe -> %AppData%\Startup\Adobe -> [2009/01/06 23:51:33 | 00,000,000 | ---D | C]
Content.MSO -> %AllUsersProfile%\desktop\Content.MSO -> [2009/01/06 23:51:06 | 00,000,000 | -H-D | C]
Content.Word -> %AllUsersProfile%\desktop\Content.Word -> [2009/01/06 23:51:01 | 00,000,000 | -H-D | C]
AntiPhishing -> %AllUsersProfile%\desktop\AntiPhishing -> [2009/01/06 23:50:42 | 00,000,000 | ---D | C]
HijackThis.lnk -> %AppData%\Startup\HijackThis.lnk -> [2009/01/06 17:15:49 | 00,000,649 | ---- | C] ()
Local Settings.lnk -> %AppData%\Startup\Local Settings.lnk -> [2009/01/06 17:15:48 | 00,000,577 | ---- | C] ()
Adobe -> %AllUsersProfile%\Start Menu\Programs\Startup\Adobe -> [2009/01/06 17:14:33 | 00,000,000 | ---D | C]
IconCache.db -> %AllUsersProfile%\Start Menu\Programs\Startup\IconCache.db -> [2009/01/06 17:14:15 | 01,631,134 | -H-- | C] ()
Xmas Angel.gif.lnk -> %AllUsersProfile%\Start Menu\Programs\Startup\Xmas Angel.gif.lnk -> [2009/01/06 17:03:45 | 00,001,009 | ---- | C] ()
Sample.jpg.lnk -> %AllUsersProfile%\Start Menu\Programs\Startup\Sample.jpg.lnk -> [2009/01/06 17:03:44 | 00,000,987 | ---- | C] ()
My Pictures.lnk -> %AllUsersProfile%\Start Menu\Programs\Startup\My Pictures.lnk -> [2009/01/06 17:03:44 | 00,000,770 | ---- | C] ()
HijackThis.lnk -> %AllUsersProfile%\Start Menu\Programs\Startup\HijackThis.lnk -> [2009/01/06 17:03:41 | 00,000,649 | ---- | C] ()
Local Settings.lnk -> %UserProfile%\Start Menu\Local Settings.lnk -> [2009/01/06 16:55:03 | 00,000,581 | ---- | C] ()
History.IE5 -> %AllUsersProfile%\desktop\History.IE5 -> [2009/01/06 16:55:01 | 00,000,000 | -HSD | C]
IconCache.db -> %AllUsersProfile%\desktop\IconCache.db -> [2009/01/06 16:54:50 | 01,575,096 | -H-- | C] ()
desktop.ini -> %AllUsersProfile%\desktop\desktop.ini -> [2009/01/06 16:06:47 | 00,000,067 | -HS- | C] ()
Content.IE5 -> %AllUsersProfile%\desktop\Content.IE5 -> [2009/01/06 16:06:47 | 00,000,000 | -HSD | C]
Content.IE5 -> %AppData%\Startup\Content.IE5 -> [2009/01/06 13:03:37 | 00,000,000 | -HSD | C]
AdobeUM -> %AppData%\AdobeUM -> [2009/01/06 13:01:46 | 00,000,000 | ---D | C]
Adobe -> %UserProfile%\Local Settings\Application Data\Adobe -> [2009/01/06 13:01:24 | 00,000,000 | ---D | C]
Adobe -> %AppData%\Adobe -> [2009/01/06 13:01:24 | 00,000,000 | ---D | C]
Microsoft -> %AppData%\Microsoft -> [2009/01/06 13:01:06 | 00,000,000 | --SD | C]
History.IE5 -> %UserProfile%\SendTo\History.IE5 -> [2009/01/06 13:01:06 | 00,000,000 | -HSD | C]
Windows Desktop Search -> %AppData%\Windows Desktop Search -> [2009/01/06 13:01:06 | 00,000,000 | ---D | C]
InstallShield -> %UserProfile%\Start Menu\InstallShield -> [2009/01/06 12:54:26 | 00,000,000 | ---D | C]
Windows Genuine Advantage -> %UserProfile%\Start Menu\Windows Genuine Advantage -> [2009/01/06 12:54:22 | 00,000,000 | ---D | C]
History.IE5 -> %UserProfile%\Local Settings\Application Data\History.IE5 -> [2009/01/06 12:47:11 | 00,000,000 | -HSD | C]
Adobe -> %UserProfile%\SendTo\Adobe -> [2009/01/06 12:20:05 | 00,000,000 | ---D | C]
index.dat -> %UserProfile%\Local Settings\Application Data\index.dat -> [2009/01/06 12:20:01 | 00,016,384 | -HS- | C] ()
explorer.exe -> %SystemRoot%\System32\dllcache\explorer.exe -> [2009/01/06 12:19:48 | 01,033,728 | ---- | C] (Microsoft Corporation)
explorer.exe -> %SystemRoot%\explorer.exe -> [2009/01/06 12:19:48 | 01,033,728 | ---- | C] (Microsoft Corporation)
Windows Genuine Advantage -> %AppData%\Startup\Windows Genuine Advantage -> [2009/01/06 12:01:04 | 00,000,000 | ---D | C]
regedit.exe -> %SystemRoot%\System32\dllcache\regedit.exe -> [2009/01/06 11:03:23 | 00,146,432 | ---- | C] ()
regedit.exe -> %SystemRoot%\regedit.exe -> [2009/01/06 11:03:23 | 00,146,432 | ---- | C] ()
All Users -> %SystemRoot%\All Users -> [2009/01/06 10:58:40 | 00,000,000 | ---D | C]
WMTools Downloaded Files -> %AllUsersProfile%\favorites\WMTools Downloaded Files -> [2009/01/05 19:03:26 | 00,000,000 | ---D | C]
Asent -> %AllUsersProfile%\favorites\Asent -> [2009/01/05 19:02:48 | 00,000,000 | ---D | C]
AntiPhishing -> %UserProfile%\Local Settings\Application Data\AntiPhishing -> [2009/01/05 19:02:46 | 00,000,000 | ---D | C]
desktop.ini -> %UserProfile%\Local Settings\Application Data\desktop.ini -> [2009/01/05 19:02:45 | 00,000,110 | -HS- | C] ()
History.IE5 -> %UserProfile%\Start Menu\History.IE5 -> [2009/01/05 19:02:45 | 00,000,000 | -HSD | C]
Content.IE5 -> %UserProfile%\Local Settings\Application Data\Content.IE5 -> [2009/01/05 19:02:45 | 00,000,000 | -HSD | C]
Symantec -> %AllUsersProfile%\favorites\Symantec -> [2009/01/05 19:02:44 | 00,000,000 | ---D | C]
Windows Desktop Search -> %AppData%\Startup\Windows Desktop Search -> [2009/01/05 18:48:50 | 00,000,000 | ---D | C]
Microsoft -> %AppData%\Startup\Microsoft -> [2009/01/05 18:20:48 | 00,000,000 | --SD | C]
Content.IE5 -> %UserProfile%\Start Menu\Content.IE5 -> [2009/01/05 18:20:36 | 00,000,000 | -HSD | C]
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [2009/01/05 18:20:25 | 10,731,47904 | -HS- | C] ()
AdobeUM -> %AllUsersProfile%\favorites\AdobeUM -> [2009/01/05 17:50:30 | 00,000,000 | ---D | C]
Content.Word -> %AppData%\Content.Word -> [2009/01/05 17:50:29 | 00,000,000 | -H-D | C]
Adobe -> %AllUsersProfile%\favorites\Adobe -> [2009/01/05 17:50:04 | 00,000,000 | ---D | C]
Content.MSO -> %AppData%\Content.MSO -> [2009/01/05 17:50:00 | 00,000,000 | -H-D | C]
Microsoft -> %AllUsersProfile%\desktop\Microsoft -> [2009/01/05 17:33:55 | 00,000,000 | --SD | C]
Content.IE5 -> %AppData%\Content.IE5 -> [2009/01/05 17:33:01 | 00,000,000 | -HSD | C]
Symantec -> %AllUsersProfile%\desktop\Symantec -> [2009/01/05 17:19:24 | 00,000,000 | ---D | C]
InstallShield -> %AllUsersProfile%\desktop\InstallShield -> [2009/01/05 17:19:22 | 00,000,000 | ---D | C]
Windows Genuine Advantage -> %AllUsersProfile%\desktop\Windows Genuine Advantage -> [2009/01/05 16:48:11 | 00,000,000 | ---D | C]
HijackThis.lnk -> %AllUsersProfile%\desktop\HijackThis.lnk -> [2009/01/04 22:34:57 | 00,000,637 | ---- | C] ()
XW4400 (C).lnk -> %AllUsersProfile%\desktop\XW4400 (C).lnk -> [2009/01/04 20:08:45 | 00,000,299 | ---- | C] ()
MSDOS.SYS -> %SystemDrive%\MSDOS.SYS -> [2009/01/04 11:12:58 | 00,000,000 | RHS- | C] ()
IO.SYS -> %SystemDrive%\IO.SYS -> [2009/01/04 11:12:58 | 00,000,000 | RHS- | C] ()
desktop.ini -> %AllUsersProfile%\favorites\desktop.ini -> [2009/01/04 11:10:06 | 00,000,067 | -HS- | C] ()
Content.IE5 -> %AllUsersProfile%\favorites\Content.IE5 -> [2009/01/04 11:10:06 | 00,000,000 | -HSD | C]
InstallShield -> %UserProfile%\Local Settings\Application Data\InstallShield -> [2009/01/04 01:10:37 | 00,000,000 | ---D | C]
Windows Genuine Advantage -> %UserProfile%\Local Settings\Application Data\Windows Genuine Advantage -> [2009/01/04 01:10:33 | 00,000,000 | ---D | C]
Microsoft -> %AllUsersProfile%\favorites\Microsoft -> [2009/01/03 07:19:33 | 00,000,000 | ---D | C]
index.dat -> %AppData%\Startup\index.dat -> [2009/01/03 07:18:01 | 00,032,768 | -HS- | C] ()
XW4400 (C).lnk -> %AppData%\Startup\XW4400 (C).lnk -> [2009/01/03 00:53:52 | 00,000,311 | ---- | C] ()
Xmas Angel.gif.lnk -> %AppData%\Startup\Xmas Angel.gif.lnk -> [2009/01/03 00:53:03 | 00,000,975 | ---- | C] ()
Sample.jpg.lnk -> %AppData%\Startup\Sample.jpg.lnk -> [2009/01/03 00:52:59 | 00,000,953 | ---- | C] ()
My Pictures.lnk -> %AppData%\Startup\My Pictures.lnk -> [2009/01/03 00:52:59 | 00,000,736 | ---- | C] ()
InstallShield -> %AllUsersProfile%\Start Menu\Programs\Startup\InstallShield -> [2009/01/03 00:52:56 | 00,000,000 | ---D | C]
Windows Genuine Advantage -> %AllUsersProfile%\Start Menu\Programs\Startup\Windows Genuine Advantage -> [2009/01/03 00:52:51 | 00,000,000 | ---D | C]
History.IE5 -> %AllUsersProfile%\favorites\History.IE5 -> [2009/01/02 20:00:37 | 00,000,000 | -HSD | C]
Symantec -> %AllUsersProfile%\Start Menu\Programs\Startup\Symantec -> [2009/01/02 20:00:35 | 00,000,000 | ---D | C]
Windows Desktop Search -> %AllUsersProfile%\favorites\Windows Desktop Search -> [2009/01/02 12:33:31 | 00,000,000 | ---D | C]
Content.IE5 -> %UserProfile%\SendTo\Content.IE5 -> [2009/01/01 19:13:10 | 00,000,000 | -HSD | C]
Windows Desktop Search -> %AllUsersProfile%\Start Menu\Programs\Startup\Windows Desktop Search -> [2009/01/01 19:13:08 | 00,000,000 | ---D | C]
index.dat -> %UserProfile%\SendTo\index.dat -> [2009/01/01 19:11:03 | 00,032,768 | -HS- | C] ()
Microsoft -> %AllUsersProfile%\Start Menu\Programs\Startup\Microsoft -> [2009/01/01 18:55:58 | 00,000,000 | ---D | C]
rsit -> %SystemDrive%\rsit -> [2008/12/31 12:19:04 | 00,000,000 | ---D | C]
Trend Micro -> %ProgramFiles%\Trend Micro -> [2008/12/31 11:05:22 | 00,000,000 | ---D | C]
Symantec -> %UserProfile%\SendTo\Symantec -> [2008/12/31 11:00:43 | 00,000,000 | ---D | C]
index.dat -> %AllUsersProfile%\desktop\index.dat -> [2008/12/31 11:00:33 | 00,016,384 | -HS- | C] ()
IconCache.db -> %UserProfile%\SendTo\IconCache.db -> [2008/12/31 10:59:34 | 01,612,304 | -H-- | C] ()
Microsoft -> %UserProfile%\SendTo\Microsoft -> [2008/12/31 10:55:30 | 00,000,000 | ---D | C]
History.IE5 -> %AppData%\Startup\History.IE5 -> [2008/12/31 10:04:27 | 00,000,000 | -HSD | C]
$RECYCLE.BIN -> %SystemDrive%\$RECYCLE.BIN -> [2008/12/31 09:51:52 | 00,000,000 | -HSD | C]
mucltui.dll -> %SystemRoot%\System32\mucltui.dll -> [2008/12/31 09:21:25 | 00,268,648 | ---- | C] (Microsoft Corporation)
mucltui.dll.mui -> %SystemRoot%\System32\mucltui.dll.mui -> [2008/12/31 09:21:25 | 00,027,496 | ---- | C] (Microsoft Corporation)
SYMEVENT.SYS -> %SystemRoot%\System32\drivers\SYMEVENT.SYS -> [2008/12/31 09:14:19 | 00,110,952 | ---- | C] (Symantec Corporation)
S32EVNT1.DLL -> %SystemRoot%\System32\S32EVNT1.DLL -> [2008/12/31 09:14:19 | 00,048,768 | ---- | C] (Symantec Corporation)
SYMEVENT.CAT -> %SystemRoot%\System32\drivers\SYMEVENT.CAT -> [2008/12/31 09:14:19 | 00,008,014 | ---- | C] ()
SYMEVENT.INF -> %SystemRoot%\System32\drivers\SYMEVENT.INF -> [2008/12/31 09:14:19 | 00,000,805 | ---- | C] ()
Symantec -> %ProgramFiles%\Symantec -> [2008/12/31 09:14:16 | 00,000,000 | ---D | C]
Symantec Shared -> %CommonProgramFiles%\Symantec Shared -> [2008/12/31 09:14:10 | 00,000,000 | ---D | C]
Symantec AntiVirus -> %ProgramFiles%\Symantec AntiVirus -> [2008/12/31 09:14:10 | 00,000,000 | ---D | C]
Microsoft Silverlight -> %ProgramFiles%\Microsoft Silverlight -> [2008/12/31 09:04:38 | 00,000,000 | ---D | C]
Identities -> %UserProfile%\Local Settings\Application Data\Identities -> [2008/12/31 09:03:07 | 00,000,000 | ---D | C]
Windows Search.lnk -> %AllUsersProfile%\Start Menu\Programs\Startup\Windows Search.lnk -> [2008/12/31 09:02:47 | 00,001,793 | ---- | C] ()
Windows Desktop Search -> %ProgramFiles%\Windows Desktop Search -> [2008/12/31 09:02:41 | 00,000,000 | ---D | C]
GroupPolicy -> %SystemRoot%\System32\GroupPolicy -> [2008/12/31 09:02:41 | 00,000,000 | ---D | C]
offfilt.dll -> %SystemRoot%\System32\dllcache\offfilt.dll -> [2008/12/31 09:02:20 | 00,192,000 | ---- | C] (Microsoft Corporation)
nlhtml.dll -> %SystemRoot%\System32\dllcache\nlhtml.dll -> [2008/12/31 09:02:20 | 00,098,304 | ---- | C] (Microsoft Corporation)
mimefilt.dll -> %SystemRoot%\System32\dllcache\mimefilt.dll -> [2008/12/31 09:02:20 | 00,029,696 | ---- | C] (Microsoft Corporation)
Microsoft Help -> %UserProfile%\Local Settings\Application Data\Microsoft Help -> [2008/12/31 09:01:07 | 00,000,000 | ---D | C]
spmsg.dll -> %SystemRoot%\System32\spmsg.dll -> [2008/12/31 08:59:23 | 00,016,760 | ---- | C] (Microsoft Corporation)
Windows Media Connect 2 -> %ProgramFiles%\Windows Media Connect 2 -> [2008/12/31 08:59:13 | 00,000,000 | ---D | C]
MsftWdf_user_01_00_00.Wdf -> %SystemRoot%\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf -> [2008/12/31 08:58:31 | 00,000,000 | -H-- | C] ()
UMDF -> %SystemRoot%\System32\drivers\UMDF -> [2008/12/31 08:58:29 | 00,000,000 | ---D | C]
LogFiles -> %SystemRoot%\System32\LogFiles -> [2008/12/31 08:58:29 | 00,000,000 | ---D | C]
Microsoft CAPICOM 2.1.0.2 -> %ProgramFiles%\Microsoft CAPICOM 2.1.0.2 -> [2008/12/31 08:56:55 | 00,000,000 | ---D | C]
Prefetch -> %SystemRoot%\Prefetch -> [2008/12/31 08:42:01 | 00,000,000 | ---D | C]
scripting -> %SystemRoot%\System32\scripting -> [2008/12/31 08:36:59 | 00,000,000 | ---D | C]
l2schemas -> %SystemRoot%\l2schemas -> [2008/12/31 08:36:59 | 00,000,000 | ---D | C]
en -> %SystemRoot%\System32\en -> [2008/12/31 08:36:59 | 00,000,000 | ---D | C]
bits -> %SystemRoot%\System32\bits -> [2008/12/31 08:36:59 | 00,000,000 | ---D | C]
ServicePackFiles -> %SystemRoot%\ServicePackFiles -> [2008/12/31 08:35:47 | 00,000,000 | ---D | C]
$NtServicePackUninstall$ -> %SystemRoot%\$NtServicePackUninstall$ -> [2008/12/31 08:33:08 | 00,000,000 | -H-D | C]
GDIPFONTCACHEV1.DAT -> %UserProfile%\Local Settings\Application Data\GDIPFONTCACHEV1.DAT -> [2008/12/31 08:30:34 | 00,071,320 | ---- | C] ()
appmgmt -> %SystemRoot%\System32\appmgmt -> [2008/12/31 08:29:07 | 00,000,000 | ---D | C]
wuapi.dll.mui -> %SystemRoot%\System32\wuapi.dll.mui -> [2008/12/31 08:28:20 | 00,023,576 | ---- | C] (Microsoft Corporation)
vpc32.INI -> %SystemRoot%\vpc32.INI -> [2008/12/30 17:04:17 | 00,000,000 | ---- | C] ()
Symantec -> %UserProfile%\Local Settings\Application Data\Symantec -> [2008/12/30 17:04:06 | 00,000,000 | ---D | C]
Windows Media Player.lnk -> %AppData%\Windows Media Player.lnk -> [2008/12/30 17:04:01 | 00,000,794 | ---- | C] ()
IconCache.db -> %UserProfile%\Local Settings\Application Data\IconCache.db -> [2008/12/30 17:03:56 | 04,303,748 | -H-- | C] ()
NTUSER.DAT -> %UserProfile%\NTUSER.DAT -> [2008/12/30 17:03:56 | 02,621,440 | -H-- | C] ()
Remote Assistance.lnk -> %AppData%\Remote Assistance.lnk -> [2008/12/30 17:03:56 | 00,001,605 | ---- | C] ()
Internet Explorer.lnk -> %AppData%\Internet Explorer.lnk -> [2008/12/30 17:03:56 | 00,000,809 | ---- | C] ()
Outlook Express.lnk -> %AppData%\Outlook Express.lnk -> [2008/12/30 17:03:56 | 00,000,744 | ---- | C] ()
desktop.ini -> %UserProfile%\SendTo\desktop.ini -> [2008/12/30 17:03:56 | 00,000,243 | -HS- | C] ()
desktop.ini -> %AppData%\desktop.ini -> [2008/12/30 17:03:56 | 00,000,234 | -HS- | C] ()
ntuser.ini -> %UserProfile%\ntuser.ini -> [2008/12/30 17:03:56 | 00,000,178 | -HS- | C] ()
desktop.ini -> %UserProfile%\Start Menu\desktop.ini -> [2008/12/30 17:03:56 | 00,000,062 | -HS- | C] ()
desktop.ini -> %AppData%\Startup\desktop.ini -> [2008/12/30 17:03:56 | 00,000,062 | -HS- | C] ()
Accessories -> %AppData%\Accessories -> [2008/12/30 17:03:56 | 00,000,000 | R--D | C]
Templates -> %UserProfile%\Templates -> [2008/12/30 17:03:56 | 00,000,000 | -HSD | C]
Startup -> %AppData%\Startup -> [2008/12/30 17:03:56 | 00,000,000 | -HSD | C]
Start Menu -> %UserProfile%\Start Menu -> [2008/12/30 17:03:56 | 00,000,000 | -HSD | C]
SendTo -> %UserProfile%\SendTo -> [2008/12/30 17:03:56 | 00,000,000 | -HSD | C]
PrintHood -> %UserProfile%\PrintHood -> [2008/12/30 17:03:56 | 00,000,000 | -HSD | C]
NetHood -> %UserProfile%\NetHood -> [2008/12/30 17:03:56 | 00,000,000 | -HSD | C]
My Documents -> %UserProfile%\My Documents -> [2008/12/30 17:03:56 | 00,000,000 | -HSD | C]
Local Settings -> %UserProfile%\Local Settings -> [2008/12/30 17:03:56 | 00,000,000 | -HSD | C]
Desktop -> %UserProfile%\Desktop -> [2008/12/30 17:03:56 | 00,000,000 | -HSD | C]
Cookies -> %UserProfile%\Cookies -> [2008/12/30 17:03:56 | 00,000,000 | -HSD | C]
Application Data -> %UserProfile%\Application Data -> [2008/12/30 17:03:56 | 00,000,000 | -HSD | C]
Recent -> %UserProfile%\Recent -> [2008/12/30 17:03:56 | 00,000,000 | -H-D | C]
Programs -> %AppData% -> [2008/12/30 17:03:56 | 00,000,000 | -H-D | C]
Favorites -> %UserProfile%\Favorites -> [2008/12/30 17:03:56 | 00,000,000 | -H-D | C]
Microsoft -> %UserProfile%\Local Settings\Application Data\Microsoft -> [2008/12/30 17:03:56 | 00,000,000 | ---D | C]
Google -> %UserProfile%\Local Settings\Application Data\Google -> [2008/12/30 17:03:56 | 00,000,000 | ---D | C]
ApplicationHistory -> %UserProfile%\Local Settings\Application Data\ApplicationHistory -> [2008/12/30 17:03:56 | 00,000,000 | ---D | C]
{3248F0A6-6813-11D6-A77B-00B0D0150000} -> %UserProfile%\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150000} -> [2008/12/30 17:03:56 | 00,000,000 | ---D | C]
My Documents.mydocs -> %UserProfile%\SendTo\My Documents.mydocs -> [2008/12/30 17:03:56 | 00,000,000 | ---- | C] ()
Mail Recipient.MAPIMail -> %UserProfile%\SendTo\Mail Recipient.MAPIMail -> [2008/12/30 17:03:56 | 00,000,000 | ---- | C] ()
Desktop (create shortcut).DeskLink -> %UserProfile%\SendTo\Desktop (create shortcut).DeskLink -> [2008/12/30 17:03:56 | 00,000,000 | ---- | C] ()
Compressed (zipped) Folder.ZFSendToTarget -> %UserProfile%\SendTo\Compressed (zipped) Folder.ZFSendToTarget -> [2008/12/30 17:03:56 | 00,000,000 | ---- | C] ()
 
[Files/Folders - Modified Within 30 Days]
1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 
1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> 
OTScanIt2.exe -> %SystemDrive%\OTScanIt2.exe -> [2009/01/09 09:23:23 | 00,656,730 | ---- | M] ()
PerfStringBackup.INI -> %SystemRoot%\System32\PerfStringBackup.INI -> [2009/01/09 09:21:15 | 00,510,896 | ---- | M] ()
perfh009.dat -> %SystemRoot%\System32\perfh009.dat -> [2009/01/09 09:21:15 | 00,430,606 | ---- | M] ()
perfc009.dat -> %SystemRoot%\System32\perfc009.dat -> [2009/01/09 09:21:15 | 00,071,630 | ---- | M] ()
wpa.dbl -> %SystemRoot%\System32\wpa.dbl -> [2009/01/09 09:19:56 | 00,001,158 | ---- | M] ()
bootstat.dat -> %SystemRoot%\bootstat.dat -> [2009/01/09 09:14:40 | 00,002,048 | --S- | M] ()
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [2009/01/09 09:14:38 | 10,731,47904 | -HS- | M] ()
NTUSER.DAT -> %UserProfile%\NTUSER.DAT -> [2009/01/09 09:14:02 | 02,621,440 | -H-- | M] ()
ntuser.ini -> %UserProfile%\ntuser.ini -> [2009/01/09 09:14:02 | 00,000,178 | -HS- | M] ()
IconCache.db -> %UserProfile%\Local Settings\Application Data\IconCache.db -> [2009/01/09 09:13:57 | 04,303,748 | -H-- | M] ()
system.ini -> %SystemRoot%\system.ini -> [2009/01/09 09:09:00 | 00,000,227 | ---- | M] ()
ComboFix.exe -> %SystemDrive%\ComboFix.exe -> [2009/01/08 17:38:15 | 02,913,912 | R--- | M] ()
boot.ini -> %SystemDrive%\boot.ini -> [2009/01/08 13:39:48 | 00,000,281 | RHS- | M] ()
index.dat -> %AppData%\Startup\index.dat -> [2009/01/08 13:35:33 | 00,032,768 | -HS- | M] ()
desktop.ini -> %AppData%\desktop.ini -> [2009/01/08 13:35:32 | 00,000,234 | -HS- | M] ()
IconCache.db -> %AppData%\IconCache.db -> [2009/01/08 13:34:40 | 03,787,872 | -H-- | M] ()
SendTo.lnk -> %UserProfile%\Local Settings\Application Data\SendTo.lnk -> [2009/01/08 13:27:10 | 00,000,546 | ---- | M] ()
winword2.doc.lnk -> %UserProfile%\Local Settings\Application Data\winword2.doc.lnk -> [2009/01/08 13:27:09 | 00,000,782 | ---- | M] ()
winword.doc.lnk -> %UserProfile%\Local Settings\Application Data\winword.doc.lnk -> [2009/01/08 13:27:09 | 00,000,775 | ---- | M] ()
Local Settings.lnk -> %UserProfile%\Local Settings\Application Data\Local Settings.lnk -> [2009/01/08 13:27:09 | 00,000,583 | ---- | M] ()
excel4.xls.lnk -> %UserProfile%\Local Settings\Application Data\excel4.xls.lnk -> [2009/01/08 13:27:07 | 00,000,770 | ---- | M] ()
powerpnt.ppt.lnk -> %UserProfile%\Local Settings\Application Data\powerpnt.ppt.lnk -> [2009/01/08 13:27:06 | 00,000,782 | ---- | M] ()
excel.xls.lnk -> %UserProfile%\Local Settings\Application Data\excel.xls.lnk -> [2009/01/08 13:27:06 | 00,000,763 | ---- | M] ()
desktop.ini -> %AppData%\Startup\desktop.ini -> [2009/01/08 13:26:57 | 00,000,062 | -HS- | M] ()
Normal.dotm.lnk -> %UserProfile%\Local Settings\Application Data\Normal.dotm.lnk -> [2009/01/08 09:43:59 | 00,001,004 | ---- | M] ()
Templates.lnk -> %UserProfile%\Local Settings\Application Data\Templates.lnk -> [2009/01/08 09:43:59 | 00,000,760 | ---- | M] ()
d3d8caps.dat -> %SystemRoot%\System32\d3d8caps.dat -> [2009/01/08 09:43:45 | 00,000,768 | ---- | M] ()
JERRY BROWN CARD HOLDERS MAR08.xlsx.lnk -> %UserProfile%\Local Settings\Application Data\JERRY BROWN CARD HOLDERS MAR08.xlsx.lnk -> [2009/01/08 08:39:14 | 00,000,944 | ---- | M] ()
JERRY BROWN 20410.xlsx.lnk -> %UserProfile%\Local Settings\Application Data\JERRY BROWN 20410.xlsx.lnk -> [2009/01/08 08:39:14 | 00,000,879 | ---- | M] ()
virginia.ferguson's Documents.lnk -> %UserProfile%\Local Settings\Application Data\virginia.ferguson's Documents.lnk -> [2009/01/08 08:39:14 | 00,000,624 | ---- | M] ()
Cookies.lnk -> %UserProfile%\Local Settings\Application Data\Cookies.lnk -> [2009/01/08 08:39:14 | 00,000,551 | ---- | M] ()
GUARANTY RV CFN GAS-CARD LISTING.xls.lnk -> %UserProfile%\Local Settings\Application Data\GUARANTY RV CFN GAS-CARD LISTING.xls.lnk -> [2009/01/08 08:39:13 | 00,000,949 | ---- | M] ()
GARLIC FARM ANNEX 2005.xlsx.lnk -> %UserProfile%\Local Settings\Application Data\GARLIC FARM ANNEX 2005.xlsx.lnk -> [2009/01/08 08:39:12 | 00,000,904 | ---- | M] ()
Fax Coversheet Master.doc.lnk -> %UserProfile%\Local Settings\Application Data\Fax Coversheet Master.doc.lnk -> [2009/01/08 08:39:12 | 00,000,894 | ---- | M] ()
ext list 011608.xlsx.lnk -> %UserProfile%\Local Settings\Application Data\ext list 011608.xlsx.lnk -> [2009/01/08 08:39:12 | 00,000,869 | ---- | M] ()
FAX COVER.xls.lnk -> %UserProfile%\Local Settings\Application Data\FAX COVER.xls.lnk -> [2009/01/08 08:39:12 | 00,000,834 | ---- | M] ()
DEMO VEHICLES.xls.lnk -> %UserProfile%\Local Settings\Application Data\DEMO VEHICLES.xls.lnk -> [2009/01/08 08:39:11 | 00,000,854 | ---- | M] ()
Corrected 1099s for ACTA & Herb.pdf.lnk -> %UserProfile%\Local Settings\Application Data\Corrected 1099s for ACTA & Herb.pdf.lnk -> [2009/01/08 08:39:09 | 00,000,944 | ---- | M] ()
COMPANY VEHICLE LIST OCT07.xlsx.lnk -> %UserProfile%\Local Settings\Application Data\COMPANY VEHICLE LIST OCT07.xlsx.lnk -> [2009/01/08 08:38:58 | 00,000,924 | ---- | M] ()
ADS-DEMOS-INT 1099.xlsx.lnk -> %UserProfile%\Local Settings\Application Data\ADS-DEMOS-INT 1099.xlsx.lnk -> [2009/01/08 08:38:58 | 00,000,884 | ---- | M] ()
concompform.pdf.lnk -> %UserProfile%\Local Settings\Application Data\concompform.pdf.lnk -> [2009/01/08 08:38:58 | 00,000,844 | ---- | M] ()
2007 DEMOS.xlsx.lnk -> %UserProfile%\Local Settings\Application Data\2007 DEMOS.xlsx.lnk -> [2009/01/08 08:38:58 | 00,000,844 | ---- | M] ()
BOFA0408.xlsx.lnk -> %UserProfile%\Local Settings\Application Data\BOFA0408.xlsx.lnk -> [2009/01/08 08:38:58 | 00,000,834 | ---- | M] ()
City of Coburg-Palm Harbor.xlsx.lnk -> %UserProfile%\Local Settings\Application Data\City of Coburg-Palm Harbor.xlsx.lnk -> [2009/01/08 08:38:57 | 00,000,924 | ---- | M] ()
Camping World Invoices Open.xls.lnk -> %UserProfile%\Local Settings\Application Data\Camping World Invoices Open.xls.lnk -> [2009/01/08 08:38:57 | 00,000,924 | ---- | M] ()
Cmpg Wrld Open Invoces.xlsx.lnk -> %UserProfile%\Local Settings\Application Data\Cmpg Wrld Open Invoces.xlsx.lnk -> [2009/01/08 08:38:47 | 00,000,904 | ---- | M] ()
ClearChannelOutdoor letter.docx.lnk -> %UserProfile%\Local Settings\Application Data\ClearChannelOutdoor letter.docx.lnk -> [2009/01/08 08:38:31 | 00,000,924 | ---- | M] ()
AVIAD #161.pdf.lnk -> %UserProfile%\Local Settings\Application Data\AVIAD #161.pdf.lnk -> [2009/01/08 08:38:29 | 00,000,839 | ---- | M] ()
ADVERTISING LISTING.pdf.lnk -> %UserProfile%\Local Settings\Application Data\ADVERTISING LISTING.pdf.lnk -> [2009/01/08 08:38:28 | 00,000,884 | ---- | M] ()
AVIAD #160.pdf.lnk -> %UserProfile%\Local Settings\Application Data\AVIAD #160.pdf.lnk -> [2009/01/08 08:38:28 | 00,000,839 | ---- | M] ()
1099Correction Note to customer.doc.lnk -> %UserProfile%\Local Settings\Application Data\1099Correction Note to customer.doc.lnk -> [2009/01/08 08:38:24 | 00,000,944 | ---- | M] ()
IconCache.db -> %AllUsersProfile%\desktop\IconCache.db -> [2009/01/08 08:28:57 | 01,575,096 | -H-- | M] ()
XW4400 (C) (2).lnk -> %UserProfile%\Local Settings\Application Data\XW4400 (C) (2).lnk -> [2009/01/08 08:25:28 | 00,000,305 | ---- | M] ()
screen.PNG.lnk -> %UserProfile%\Local Settings\Application Data\screen.PNG.lnk -> [2009/01/07 18:02:39 | 00,000,415 | ---- | M] ()
XW4400 (C).lnk -> %UserProfile%\Local Settings\Application Data\XW4400 (C).lnk -> [2009/01/07 18:02:39 | 00,000,305 | ---- | M] ()
ComboFix.exe -> %UserProfile%\Start Menu\ComboFix.exe -> [2009/01/07 17:51:05 | 02,912,710 | ---- | M] ()
index.dat -> %AppData%\index.dat -> [2009/01/07 17:45:52 | 00,016,384 | -HS- | M] ()
desktop.ini -> %UserProfile%\SendTo\desktop.ini -> [2009/01/07 00:44:22 | 00,000,243 | -HS- | M] ()
index.dat -> %AllUsersProfile%\desktop\index.dat -> [2009/01/07 00:40:35 | 00,016,384 | -HS- | M] ()
desktop.ini -> %UserProfile%\Local Settings\Application Data\desktop.ini -> [2009/01/07 00:40:03 | 00,000,110 | -HS- | M] ()
index.dat -> %AppData%\Startup\Microsoft\Office\Recent\index.dat -> [2009/01/06 23:54:17 | 00,000,648 | -H-- | M] ()
HijackThis.lnk -> %AppData%\Startup\HijackThis.lnk -> [2009/01/06 17:15:49 | 00,000,649 | ---- | M] ()
Local Settings.lnk -> %AppData%\Startup\Local Settings.lnk -> [2009/01/06 17:15:49 | 00,000,577 | ---- | M] ()
IconCache.db -> %AllUsersProfile%\Start Menu\Programs\Startup\IconCache.db -> [2009/01/06 17:14:59 | 01,631,134 | -H-- | M] ()
Xmas Angel.gif.lnk -> %AllUsersProfile%\Start Menu\Programs\Startup\Xmas Angel.gif.lnk -> [2009/01/06 17:10:05 | 00,001,009 | ---- | M] ()
My Pictures.lnk -> %AllUsersProfile%\Start Menu\Programs\Startup\My Pictures.lnk -> [2009/01/06 17:10:05 | 00,000,770 | ---- | M] ()
Sample.jpg.lnk -> %AllUsersProfile%\Start Menu\Programs\Startup\Sample.jpg.lnk -> [2009/01/06 17:10:04 | 00,000,987 | ---- | M] ()
HijackThis.lnk -> %AllUsersProfile%\Start Menu\Programs\Startup\HijackThis.lnk -> [2009/01/06 17:10:01 | 00,000,649 | ---- | M] ()
Local Settings.lnk -> %UserProfile%\Start Menu\Local Settings.lnk -> [2009/01/06 16:55:04 | 00,000,581 | ---- | M] ()
desktop.ini -> %AllUsersProfile%\desktop\desktop.ini -> [2009/01/06 16:06:47 | 00,000,067 | -HS- | M] ()
index.dat -> %UserProfile%\Local Settings\Application Data\index.dat -> [2009/01/06 13:03:34 | 00,016,384 | -HS- | M] ()
index.dat -> %UserProfile%\SendTo\index.dat -> [2009/01/05 18:01:22 | 00,032,768 | -HS- | M] ()
GDIPFONTCACHEV1.DAT -> %UserProfile%\Local Settings\Application Data\GDIPFONTCACHEV1.DAT -> [2009/01/05 17:50:32 | 00,071,320 | ---- | M] ()
Remote Assistance.lnk -> %AppData%\Remote Assistance.lnk -> [2009/01/05 17:19:27 | 00,001,605 | ---- | M] ()
IconCache.db -> %UserProfile%\SendTo\IconCache.db -> [2009/01/05 12:06:28 | 01,612,304 | -H-- | M] ()
HijackThis.lnk -> %AllUsersProfile%\desktop\HijackThis.lnk -> [2009/01/04 22:39:44 | 00,000,637 | ---- | M] ()
XW4400 (C).lnk -> %AllUsersProfile%\desktop\XW4400 (C).lnk -> [2009/01/04 20:08:45 | 00,000,299 | ---- | M] ()
MSDOS.SYS -> %SystemDrive%\MSDOS.SYS -> [2009/01/04 11:12:58 | 00,000,000 | RHS- | M] ()
IO.SYS -> %SystemDrive%\IO.SYS -> [2009/01/04 11:12:58 | 00,000,000 | RHS- | M] ()
desktop.ini -> %AllUsersProfile%\favorites\desktop.ini -> [2009/01/04 11:10:06 | 00,000,067 | -HS- | M] ()
Xmas Angel.gif.lnk -> %AppData%\Startup\Xmas Angel.gif.lnk -> [2009/01/03 01:18:21 | 00,000,975 | ---- | M] ()
My Pictures.lnk -> %AppData%\Startup\My Pictures.lnk -> [2009/01/03 01:18:21 | 00,000,736 | ---- | M] ()
Sample.jpg.lnk -> %AppData%\Startup\Sample.jpg.lnk -> [2009/01/03 01:18:17 | 00,000,953 | ---- | M] ()
XW4400 (C).lnk -> %AppData%\Startup\XW4400 (C).lnk -> [2009/01/03 00:53:52 | 00,000,311 | ---- | M] ()
FNTCACHE.DAT -> %SystemRoot%\System32\FNTCACHE.DAT -> [2008/12/31 10:04:05 | 00,270,192 | ---- | M] ()
imsins.BAK -> %SystemRoot%\imsins.BAK -> [2008/12/31 09:18:48 | 00,001,393 | ---- | M] ()
SYMEVENT.SYS -> %SystemRoot%\System32\drivers\SYMEVENT.SYS -> [2008/12/31 09:14:24 | 00,110,952 | ---- | M] (Symantec Corporation)
S32EVNT1.DLL -> %SystemRoot%\System32\S32EVNT1.DLL -> [2008/12/31 09:14:24 | 00,048,768 | ---- | M] (Symantec Corporation)
SYMEVENT.CAT -> %SystemRoot%\System32\drivers\SYMEVENT.CAT -> [2008/12/31 09:14:24 | 00,008,014 | ---- | M] ()
SYMEVENT.INF -> %SystemRoot%\System32\drivers\SYMEVENT.INF -> [2008/12/31 09:14:24 | 00,000,805 | ---- | M] ()
Windows Search.lnk -> %AllUsersProfile%\Start Menu\Programs\Startup\Windows Search.lnk -> [2008/12/31 09:02:47 | 00,001,793 | ---- | M] ()
win.ini -> %SystemRoot%\win.ini -> [2008/12/31 09:01:49 | 00,000,582 | ---- | M] ()
Windows Media Player.lnk -> %AppData%\Windows Media Player.lnk -> [2008/12/31 08:59:19 | 00,000,794 | ---- | M] ()
nscompat.tlb -> %SystemRoot%\System32\nscompat.tlb -> [2008/12/31 08:59:18 | 00,023,392 | ---- | M] ()
amcompat.tlb -> %SystemRoot%\System32\amcompat.tlb -> [2008/12/31 08:59:18 | 00,016,832 | ---- | M] ()
MsftWdf_user_01_00_00.Wdf -> %SystemRoot%\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf -> [2008/12/31 08:58:31 | 00,000,000 | -H-- | M] ()
WMSysPr9.prx -> %SystemRoot%\WMSysPr9.prx -> [2008/12/31 08:42:42 | 00,316,640 | ---- | M] ()
Outlook Express.lnk -> %AppData%\Outlook Express.lnk -> [2008/12/31 08:42:32 | 00,000,744 | ---- | M] ()
ntldr -> %SystemDrive%\ntldr -> [2008/12/31 08:34:48 | 00,250,048 | RHS- | M] ()
vpc32.INI -> %SystemRoot%\vpc32.INI -> [2008/12/30 17:04:17 | 00,000,000 | ---- | M] ()
ntuser.pol -> %AllUsersProfile%\ntuser.pol -> [2008/12/30 17:00:02 | 00,000,008 | RHS- | M] ()
mshtml.dll -> %SystemRoot%\System32\mshtml.dll -> [2008/12/12 22:40:02 | 03,593,216 | ---- | M] (Microsoft Corporation)
mshtml.dll -> %SystemRoot%\System32\dllcache\mshtml.dll -> [2008/12/12 22:40:02 | 03,593,216 | ---- | M] (Microsoft Corporation)
< End of report >


Also, I forgot to mention that around the time of your first response, Auto-Protect came up and had detected something called Trojan.LinkOptimizer and removed it.

Also, when I was trying to follow your instructions today, several times my start menu bar would go away and I'd get a message that said "Error: [number]: Windows has encountered a virus." I only wrote down the number of 2 of them. They were 0x80010242 and 0x80013181. It hasn't happened since running OTScanIt, though.

Also, I get a lot of popups whenever I start Windows and it takes a while to close out of all of them.
fhqwhgads
Active Member
 
Posts: 9
Joined: December 31st, 2008, 3:11 pm

Re: Wrong icons on my desktop and start menu

Unread postby Rodav » January 9th, 2009, 4:31 pm

Step 1:
Start OTScanIt2. Copy/Paste the information in the codebox below into the pane where it says "Paste fix here" and then click the Run Fix button.

Code: Select all
[Registry - Safe List]
< Jason Startup Folder > -> C:\Documents and Settings\Jason\Local Settings\Application Data
YN -> %UserProfile%\Local Settings\Application Data\1099Correction Note to customer.doc.lnk -> %UserProfile%\virginia.ferguson's Documents\1099Correction Note to customer.doc
YN -> %UserProfile%\Local Settings\Application Data\2007 DEMOS.xlsx.lnk -> %UserProfile%\virginia.ferguson's Documents\2007 DEMOS.xlsx
YN -> ~EmptyValue -> %UserProfile%\Local Settings\Application Data\Adobe
YN -> %UserProfile%\Local Settings\Application Data\ADS-DEMOS-INT 1099.xlsx.lnk -> %UserProfile%\virginia.ferguson's Documents\ADS-DEMOS-INT 1099.xlsx
YN -> %UserProfile%\Local Settings\Application Data\ADVERTISING LISTING.pdf.lnk -> %UserProfile%\virginia.ferguson's Documents\ADVERTISING LISTING.pdf
YN -> ~EmptyValue -> %UserProfile%\Local Settings\Application Data\AntiPhishing
YN -> ~EmptyValue -> %UserProfile%\Local Settings\Application Data\ApplicationHistory
YN -> ~EmptyValue -> %UserProfile%\Local Settings\Application Data\Asent
YN -> %UserProfile%\Local Settings\Application Data\AVIAD #160.pdf.lnk -> %UserProfile%\virginia.ferguson's Documents\AVIAD #160.pdf
YN -> %UserProfile%\Local Settings\Application Data\AVIAD #161.pdf.lnk -> %UserProfile%\virginia.ferguson's Documents\AVIAD #161.pdf
YN -> %UserProfile%\Local Settings\Application Data\BOFA0408.xlsx.lnk -> %UserProfile%\virginia.ferguson's Documents\BOFA0408.xlsx
YN -> %UserProfile%\Local Settings\Application Data\Camping World Invoices Open.xls.lnk -> %UserProfile%\virginia.ferguson's Documents\Camping World Invoices Open.xls
YN -> %UserProfile%\Local Settings\Application Data\City of Coburg-Palm Harbor.xlsx.lnk -> %UserProfile%\virginia.ferguson's Documents\City of Coburg-Palm Harbor.xlsx
YN -> %UserProfile%\Local Settings\Application Data\ClearChannelOutdoor letter.docx.lnk -> %UserProfile%\virginia.ferguson's Documents\ClearChannelOutdoor letter.docx
YN -> %UserProfile%\Local Settings\Application Data\Cmpg Wrld Open Invoces.xlsx.lnk -> %UserProfile%\virginia.ferguson's Documents\Cmpg Wrld Open Invoces.xlsx
YN -> %UserProfile%\Local Settings\Application Data\COMPANY VEHICLE LIST OCT07.xlsx.lnk -> %UserProfile%\virginia.ferguson's Documents\COMPANY VEHICLE LIST OCT07.xlsx
YN -> %UserProfile%\Local Settings\Application Data\concompform.pdf.lnk -> %UserProfile%\virginia.ferguson's Documents\concompform.pdf
YN -> ~EmptyValue -> %UserProfile%\Local Settings\Application Data\Content.IE5
YN -> %UserProfile%\Local Settings\Application Data\Cookies.lnk -> %UserProfile%\Local Settings
YN -> %UserProfile%\Local Settings\Application Data\Corrected 1099s for ACTA & Herb.pdf.lnk -> %UserProfile%\virginia.ferguson's Documents\Corrected 1099s for ACTA & Herb.pdf
YN -> %UserProfile%\Local Settings\Application Data\DEMO VEHICLES.xls.lnk -> %UserProfile%\virginia.ferguson's Documents\DEMO VEHICLES.xls
YN -> %UserProfile%\Local Settings\Application Data\excel.xls.lnk -> %UserProfile%\Templates\excel.xls
YN -> %UserProfile%\Local Settings\Application Data\excel4.xls.lnk -> %UserProfile%\Templates\excel4.xls
YN -> %UserProfile%\Local Settings\Application Data\ext list 011608.xlsx.lnk -> %UserProfile%\virginia.ferguson's Documents\ext list 011608.xlsx
YN -> %UserProfile%\Local Settings\Application Data\FAX COVER.xls.lnk -> %UserProfile%\virginia.ferguson's Documents\FAX COVER.xls
YN -> %UserProfile%\Local Settings\Application Data\Fax Coversheet Master.doc.lnk -> %UserProfile%\virginia.ferguson's Documents\Fax Coversheet Master.doc
YN -> %UserProfile%\Local Settings\Application Data\GARLIC FARM ANNEX 2005.xlsx.lnk -> %UserProfile%\virginia.ferguson's Documents\GARLIC FARM ANNEX 2005.xlsx
YN -> ~EmptyValue -> %UserProfile%\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
YN -> ~EmptyValue -> %UserProfile%\Local Settings\Application Data\Google
YN -> %UserProfile%\Local Settings\Application Data\GUARANTY RV CFN GAS-CARD LISTING.xls.lnk -> %UserProfile%\virginia.ferguson's Documents\GUARANTY RV CFN GAS-CARD LISTING.xls
YN -> ~EmptyValue -> %UserProfile%\Local Settings\Application Data\History.IE5
YN -> ~EmptyValue -> %UserProfile%\Local Settings\Application Data\IconCache.db
YN -> ~EmptyValue -> %UserProfile%\Local Settings\Application Data\Identities
YN -> ~EmptyValue -> %UserProfile%\Local Settings\Application Data\index.dat
YN -> ~EmptyValue -> %UserProfile%\Local Settings\Application Data\InstallShield
YN -> %UserProfile%\Local Settings\Application Data\jason@2o7[1].txt.lnk -> %UserProfile%\Cookies\jason@2o7[1].txt
YN -> %UserProfile%\Local Settings\Application Data\jason@google[1].txt.lnk -> %UserProfile%\Cookies\jason@google[1].txt
YN -> %UserProfile%\Local Settings\Application Data\jason@google[2].txt.lnk -> %UserProfile%\Cookies\jason@google[2].txt
YN -> %UserProfile%\Local Settings\Application Data\jason@m.webtrends[2].txt.lnk -> %UserProfile%\Cookies\jason@m.webtrends[2].txt
YN -> %UserProfile%\Local Settings\Application Data\jason@microsoft[1].txt.lnk -> %UserProfile%\Cookies\jason@microsoft[1].txt
YN -> %UserProfile%\Local Settings\Application Data\jason@office.microsoft[2].txt.lnk -> %UserProfile%\Cookies\jason@office.microsoft[2].txt
YN -> %UserProfile%\Local Settings\Application Data\jason@sdc.windowsmarketplace[1].txt.lnk -> %UserProfile%\Local Settings\jason@sdc.windowsmarketplace[1].txt
YN -> %UserProfile%\Local Settings\Application Data\jason@sdc.windowsmarketplace[2].txt.lnk -> %UserProfile%\Local Settings\jason@sdc.windowsmarketplace[2].txt
YN -> %UserProfile%\Local Settings\Application Data\jason@windowsmarketplace[1].txt.lnk -> %UserProfile%\Local Settings\jason@windowsmarketplace[1].txt
YN -> %UserProfile%\Local Settings\Application Data\jason@www.microsoft[2].txt.lnk -> %UserProfile%\Cookies\jason@www.microsoft[2].txt
YN -> %UserProfile%\Local Settings\Application Data\JERRY BROWN 20410.xlsx.lnk -> %UserProfile%\virginia.ferguson's Documents\JERRY BROWN 20410.xlsx
YN -> %UserProfile%\Local Settings\Application Data\JERRY BROWN CARD HOLDERS MAR08.xlsx.lnk -> %UserProfile%\virginia.ferguson's Documents\JERRY BROWN CARD HOLDERS MAR08.xlsx
YN -> %UserProfile%\Local Settings\Application Data\Local Settings.lnk -> %UserProfile%\Local Settings
YN -> ~EmptyValue -> %UserProfile%\Local Settings\Application Data\Microsoft
YN -> ~EmptyValue -> %UserProfile%\Local Settings\Application Data\Microsoft
YN -> %UserProfile%\Local Settings\Application Data\Normal.dotm.lnk -> %AppData%\Microsoft\Templates\Normal.dotm
YN -> %UserProfile%\Local Settings\Application Data\powerpnt.ppt.lnk -> %UserProfile%\Local Settings\powerpnt.ppt
YN -> %UserProfile%\Local Settings\Application Data\screen.PNG.lnk -> %SystemDrive%\screen.PNG
YN -> %UserProfile%\Local Settings\Application Data\SendTo.lnk -> %UserProfile%\Local Settings
YN -> ~EmptyValue -> %UserProfile%\Local Settings\Application Data\Symantec
YN -> %UserProfile%\Local Settings\Application Data\t.txt.lnk -> %SystemDrive%\t.txt
YN -> %UserProfile%\Local Settings\Application Data\Templates.lnk -> %AppData%\Microsoft\Templates
YN -> %UserProfile%\Local Settings\Application Data\virginia.ferguson's Documents.lnk -> 
YN -> %UserProfile%\Local Settings\Application Data\winword.doc.lnk -> %UserProfile%\Local Settings\winword.doc
YN -> %UserProfile%\Local Settings\Application Data\winword2.doc.lnk -> %UserProfile%\Local Settings\winword2.doc
YN -> %UserProfile%\Local Settings\Application Data\XW4400 (C) (2).lnk -> 
YN -> %UserProfile%\Local Settings\Application Data\XW4400 (C).lnk -> 
YN -> ~EmptyValue -> %UserProfile%\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150000}
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell
YN -> cmd -> %SystemRoot%\system32\cmd.exe
YN -> /c -> 
YY -> C:\WINDOWS\system32\DontDelete.exe -> %SystemRoot%\system32\DontDelete.exe
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon


The fix should only take a very short time. When the fix is completed a message box will popup either telling you that it is finished, or that a reboot is needed to complete the fix. If the fix is complete, click the Ok button and Notepad will open with a log of actions taken during the fix. Post that log back here in your next reply.

If a reboot is required, click the "Yes" button to reboot the machine. After the reboot, OTScanIt2 will finish moving any files that could not be moved during the fix and NotePad will open with the final results at that time. Post that log back here in your next reply.


Step 2:
Please download Malwarebytes' Anti-Malware to your desktop or to C: drive.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Post that log back here.


Step 3:
Please download DirLook by jpshortstuff from one of the following mirrors:
Link 1
Link 2
Link 3
  • Double-click DirLook.exe to run it.
  • Ensure that Show Hidden Files/Folders and BBCode Ouput are both checked.
  • Copy the content of the following codebox into the main textfield:

    Code: Select all
    C:\System32\prn /s
    C:\System32\drivers\prn /s
    C:\prn /s

  • Click the DirLook button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply. (Note: The log can also be found at C:\DirLook.txt)
Note: Scanning may take longer for large folders.


Step 4:
Run OTScanIT2 like before and post the log it produces along with the reports from Dirlook and Malwarebytes. Also let me know how your computer is running.
User avatar
Rodav
MRU Master Emeritus
 
Posts: 1480
Joined: April 19th, 2007, 6:44 am
Location: Here, there and yonder.

Re: Wrong icons on my desktop and start menu

Unread postby fhqwhgads » January 9th, 2009, 9:28 pm

C:\OTScanIt2\01092009_163846.log

[Registry - Safe List]
C:\Documents and Settings\Jason\Local Settings\Application Data\1099Correction Note to customer.doc.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\1099Correction Note to customer.doc.lnk not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\2007 DEMOS.xlsx.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\2007 DEMOS.xlsx.lnk not found.
File ~EmptyValue not found.
File ~EmptyValue not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\ADS-DEMOS-INT 1099.xlsx.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\ADS-DEMOS-INT 1099.xlsx.lnk not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\ADVERTISING LISTING.pdf.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\ADVERTISING LISTING.pdf.lnk not found.
File ~EmptyValue not found.
File ~EmptyValue not found.
File ~EmptyValue not found.
File ~EmptyValue not found.
File ~EmptyValue not found.
File ~EmptyValue not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\AVIAD #160.pdf.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\AVIAD #160.pdf.lnk not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\AVIAD #161.pdf.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\AVIAD #161.pdf.lnk not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\BOFA0408.xlsx.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\BOFA0408.xlsx.lnk not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\Camping World Invoices Open.xls.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\Camping World Invoices Open.xls.lnk not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\City of Coburg-Palm Harbor.xlsx.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\City of Coburg-Palm Harbor.xlsx.lnk not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\ClearChannelOutdoor letter.docx.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\ClearChannelOutdoor letter.docx.lnk not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\Cmpg Wrld Open Invoces.xlsx.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\Cmpg Wrld Open Invoces.xlsx.lnk not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\COMPANY VEHICLE LIST OCT07.xlsx.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\COMPANY VEHICLE LIST OCT07.xlsx.lnk not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\concompform.pdf.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\concompform.pdf.lnk not found.
File ~EmptyValue not found.
File ~EmptyValue not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\Cookies.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\Cookies.lnk not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\Corrected 1099s for ACTA & Herb.pdf.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\Corrected 1099s for ACTA & Herb.pdf.lnk not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\DEMO VEHICLES.xls.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\DEMO VEHICLES.xls.lnk not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\excel.xls.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\excel.xls.lnk not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\excel4.xls.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\excel4.xls.lnk not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\ext list 011608.xlsx.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\ext list 011608.xlsx.lnk not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\FAX COVER.xls.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\FAX COVER.xls.lnk not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\Fax Coversheet Master.doc.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\Fax Coversheet Master.doc.lnk not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\GARLIC FARM ANNEX 2005.xlsx.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\GARLIC FARM ANNEX 2005.xlsx.lnk not found.
File ~EmptyValue not found.
File ~EmptyValue not found.
File ~EmptyValue not found.
File ~EmptyValue not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\GUARANTY RV CFN GAS-CARD LISTING.xls.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\GUARANTY RV CFN GAS-CARD LISTING.xls.lnk not found.
File ~EmptyValue not found.
File ~EmptyValue not found.
File ~EmptyValue not found.
File ~EmptyValue not found.
File ~EmptyValue not found.
File ~EmptyValue not found.
File ~EmptyValue not found.
File ~EmptyValue not found.
File ~EmptyValue not found.
File ~EmptyValue not found.
File C:\Documents and Settings\Jason\Local Settings\Application Data\jason@2o7 not found.
File C:\Documents and Settings\Jason\Local Settings\Application Data\jason@2o7 not found.
File C:\Documents and Settings\Jason\Local Settings\Application Data\jason@google not found.
File C:\Documents and Settings\Jason\Local Settings\Application Data\jason@google not found.
File C:\Documents and Settings\Jason\Local Settings\Application Data\jason@google not found.
File C:\Documents and Settings\Jason\Local Settings\Application Data\jason@google not found.
File C:\Documents and Settings\Jason\Local Settings\Application Data\jason@m.webtrends not found.
File C:\Documents and Settings\Jason\Local Settings\Application Data\jason@m.webtrends not found.
File C:\Documents and Settings\Jason\Local Settings\Application Data\jason@microsoft not found.
File C:\Documents and Settings\Jason\Local Settings\Application Data\jason@microsoft not found.
File C:\Documents and Settings\Jason\Local Settings\Application Data\jason@office.microsoft not found.
File C:\Documents and Settings\Jason\Local Settings\Application Data\jason@office.microsoft not found.
File C:\Documents and Settings\Jason\Local Settings\Application Data\jason@sdc.windowsmarketplace not found.
File C:\Documents and Settings\Jason\Local Settings\Application Data\jason@sdc.windowsmarketplace not found.
File C:\Documents and Settings\Jason\Local Settings\Application Data\jason@sdc.windowsmarketplace not found.
File C:\Documents and Settings\Jason\Local Settings\Application Data\jason@sdc.windowsmarketplace not found.
File C:\Documents and Settings\Jason\Local Settings\Application Data\jason@windowsmarketplace not found.
File C:\Documents and Settings\Jason\Local Settings\Application Data\jason@windowsmarketplace not found.
File C:\Documents and Settings\Jason\Local Settings\Application Data\jason@www.microsoft not found.
File C:\Documents and Settings\Jason\Local Settings\Application Data\jason@www.microsoft not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\JERRY BROWN 20410.xlsx.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\JERRY BROWN 20410.xlsx.lnk not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\JERRY BROWN CARD HOLDERS MAR08.xlsx.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\JERRY BROWN CARD HOLDERS MAR08.xlsx.lnk not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\Local Settings.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\Local Settings.lnk not found.
File ~EmptyValue not found.
File ~EmptyValue not found.
File ~EmptyValue not found.
File ~EmptyValue not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\Normal.dotm.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\Normal.dotm.lnk not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\powerpnt.ppt.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\powerpnt.ppt.lnk not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\screen.PNG.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\screen.PNG.lnk not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\SendTo.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\SendTo.lnk not found.
File ~EmptyValue not found.
File ~EmptyValue not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\t.txt.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\t.txt.lnk not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\Templates.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\Templates.lnk not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\virginia.ferguson's Documents.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\virginia.ferguson's Documents.lnk not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\winword.doc.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\winword.doc.lnk not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\winword2.doc.lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\winword2.doc.lnk not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\XW4400 (C) (2).lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\XW4400 (C) (2).lnk not found.
C:\Documents and Settings\Jason\Local Settings\Application Data\XW4400 (C).lnk moved successfully.
File C:\Documents and Settings\Jason\Local Settings\Application Data\XW4400 (C).lnk not found.
File ~EmptyValue not found.
File ~EmptyValue not found.
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:cmd scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:/c scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:C:\WINDOWS\system32\DontDelete.exe scheduled to be deleted on reboot.
File C:\WINDOWS\system32\DontDelete.exe not found.
< End of fix log >
OTScanIt2 by OldTimer - Version 1.0.6.2 fix logfile created on 01092009_163846

Files moved on Reboot...

Registry entries deleted on Reboot...
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:cmd scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:/c scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:C:\WINDOWS\system32\DontDelete.exe scheduled to be deleted on reboot.

mbam-log
Malwarebytes' Anti-Malware 1.32
Database version: 1636
Windows 5.1.2600 Service Pack 3

2009-01-09 17:13:41
mbam-log-2009-01-09 (17-13-41).txt

Scan type: Full Scan (C:\|)
Objects scanned: 103025
Time elapsed: 25 minute(s), 35 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

DirLook.txt
DirLook.exe v2.0 by jpshortstuff
Log created at 17:15 on 09/01/2009
==================================
Contents of "C:\System32\prn"

Unable to find directory.

==================================
Contents of "C:\System32\drivers\prn"

Unable to find directory.

==================================
Contents of "C:\prn"

Unable to find directory.

==================================
=EOF=

As far as OTScanIt, it came up with an error message that says:
'1/1/2099 12' is not a valid date and time.
When I click OK, it just sits there for a long time doing nothing. I says "Running" in the task manager and I can close out of it fine, so it hasn't frozen up. The status bar says "Looking for newly created files : C:\prn..." and doesn't do anything after that. Do you want me to just let it sit there overnight? I have no idea what C:\prn... is. Should I delete it?
fhqwhgads
Active Member
 
Posts: 9
Joined: December 31st, 2008, 3:11 pm

Re: Wrong icons on my desktop and start menu

Unread postby Rodav » January 10th, 2009, 10:41 am

You can stop OTScanIt2 if it is still hanging. I don't like the look of those prn folders, I would like a rootkit scan to double check things.

Step 1:
Please download gmer.zip from Gmer and save it to your desktop.

  1. Right click on gmer.zip and select Extract All....
  2. Click Next on seeing the Welcome to the Compressed (zipped) Folders Extraction Wizard.
  3. Click on the Browse button. Click on Desktop. Then click OK.
  4. Click Next. It will start extracting.
  5. Once done, check (tick) the Show extracted files box and click Finish.

Double click on gmer.exe to run it. It will start running a scan. If it detects rootkit activity, you will receive a prompt to run a full scan. Click Yes.

  • When done, you may receive another notice. Click OK.
  • Click on Save ... to save a log.
  • Copy and paste in Gmer.txt and click Save.
  • Close Gmer.

If you receive no notice, click on the Scan button.

  • It will start scanning again.
  • When done, click on Save ... to save a log.
  • Copy and paste in Gmer.txt and click Save.
  • Close Gmer.

Note: Do not run any programs while Gmer is running.
User avatar
Rodav
MRU Master Emeritus
 
Posts: 1480
Joined: April 19th, 2007, 6:44 am
Location: Here, there and yonder.

Re: Wrong icons on my desktop and start menu

Unread postby fhqwhgads » January 10th, 2009, 1:22 pm

Since getting on the computer this morning I've gotten 3 messages saying "Windows encountered a virus." and with different numbers. The one up right now says 0x80032399. Each time, my start menu bar goes away and any windows I have open where I am browsing files. It just happened again and this one says 0x80000023. Next one said 0x80000219. It's really hard for me to get to the gmer program with it keep closing out of the window.

I ran that gmer program and here is the log:

GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2009-01-10 09:19:55
Windows 5.1.2600 Service Pack 3


---- System - GMER 1.0.14 ----

SSDT 8647CB98 ZwAlertResumeThread
SSDT 864B27C8 ZwAlertThread
SSDT 863ACDE0 ZwAllocateVirtualMemory
SSDT 862FD4A0 ZwConnectPort
SSDT 863890E8 ZwCreateMutant
SSDT 85F271F0 ZwCreateThread
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xEC521350]
SSDT 862C2518 ZwFreeVirtualMemory
SSDT 863B0190 ZwImpersonateAnonymousToken
SSDT 863A85D0 ZwImpersonateThread
SSDT 864A40E8 ZwMapViewOfSection
SSDT 86392C98 ZwOpenEvent
SSDT 863AE910 ZwOpenProcessToken
SSDT 86394DC0 ZwOpenThreadToken
SSDT 863B9568 ZwQueryValueKey
SSDT 863AF588 ZwResumeThread
SSDT 865996B8 ZwSetContextThread
SSDT 8639E0A8 ZwSetInformationProcess
SSDT 865BBE30 ZwSetInformationThread
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xEC521580]
SSDT 86399CB0 ZwSuspendProcess
SSDT 8651CE28 ZwSuspendThread
SSDT 863AF088 ZwTerminateProcess
SSDT 864F49B8 ZwTerminateThread
SSDT 862CE518 ZwUnmapViewOfSection
SSDT 865575C0 ZwWriteVirtualMemory

---- User code sections - GMER 1.0.14 ----

.text C:\WINDOWS\SMINST\Scheduler.exe[636] USER32.dll!GetSysColor 7E418E78 5 Bytes JMP 004170D0 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[636] USER32.dll!GetSysColorBrush 7E418EAB 5 Bytes JMP 00417140 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[636] USER32.dll!SetScrollInfo 7E419056 7 Bytes JMP 00416FC0 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[636] USER32.dll!GetScrollInfo 7E42DFE2 7 Bytes JMP 00416F10 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[636] USER32.dll!ShowScrollBar 7E42F2F2 5 Bytes JMP 00417090 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[636] USER32.dll!GetScrollPos 7E42F704 5 Bytes JMP 00416F50 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[636] USER32.dll!SetScrollPos 7E42F750 5 Bytes JMP 00417000 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[636] USER32.dll!GetScrollRange 7E42F787 5 Bytes JMP 00416F80 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[636] USER32.dll!SetScrollRange 7E42F99B 5 Bytes JMP 00417040 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\SMINST\Scheduler.exe[636] USER32.dll!EnableScrollBar 7E468005 7 Bytes JMP 00416ED0 C:\WINDOWS\SMINST\Scheduler.exe
.text C:\WINDOWS\system32\SearchIndexer.exe[1928] kernel32.dll!WriteFile 7C810E17 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3824] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 42F0F301 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3824] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 430A179F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3824] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 430A1720 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3824] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 430A1764 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3824] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 430A16AC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3824] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 430A16E6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3824] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 430A17DA C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3824] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 42F316B6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)

---- Devices - GMER 1.0.14 ----

AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)

---- Registry - GMER 1.0.14 ----

Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AccuTerm 2K2
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AccuTerm 2K2@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AccuTerm 2K2@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Adobe Flash Player ActiveX
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Adobe Flash Player ActiveX@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Adobe Flash Player ActiveX@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\HijackThis
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\HijackThis@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\HijackThis@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ie7
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ie7@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ie7@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB815304
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB815304@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB815304@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB873339
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB873339@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB873339@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB885222
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB885222@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB885222@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB885270
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB885270@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB885270@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB885835
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB885835@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB885835@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB885836
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB885836@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB885836@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB886185
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB886185@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB886185@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB887472
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB887472@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB887472@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB888111WXPSP2
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB888111WXPSP2@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB888111WXPSP2@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB888302
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB888302@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB888302@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB889673
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB889673@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB889673@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB890859
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB890859@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB890859@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB891781
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB891781@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB891781@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB892130
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB892130@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB892130@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB893756
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB893756@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB893756@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB893803v2
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB893803v2@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB893803v2@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB894391
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB894391@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB894391@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB896358
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB896358@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB896358@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB896423
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB896423@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB896423@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB896424
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB896424@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB896424@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB896428
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB896428@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB896428@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB898461
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB898461@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB898461@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB899587
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB899587@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB899587@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB899591
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB899591@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB899591@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB900485
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB900485@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB900485@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB900725
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB900725@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB900725@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB901017
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB901017@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB901017@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB901214
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB901214@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB901214@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB902400
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB902400@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB902400@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB904706
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB904706@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB904706@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB904942
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB904942@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB904942@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB905414
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB905414@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB905414@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB905749
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB905749@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB905749@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB908519
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB908519@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB908519@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB908531
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB908531@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB908531@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB909095
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB909095@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB909095@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB910437
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB910437@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB910437@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB911280
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB911280@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB911280@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB911562
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB911562@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB911562@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB911564
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB911564@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB911564@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB911927
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB911927@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB911927@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB912919
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB912919@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB912919@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB913580
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB913580@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB913580@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB914388
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB914388@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB914388@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB914389
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB914389@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB914389@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB914440
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB914440@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB914440@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB915800-v4
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB915800-v4@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB915800-v4@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB916595
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB916595@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB916595@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB917422
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB917422@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB917422@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB917734_WMP9
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB917734_WMP9@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB917734_WMP9@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB917953
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB917953@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB917953@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB918118
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB918118@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB918118@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB918439
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB918439@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB918439@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB919007
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB919007@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB919007@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB920213
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB920213@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB920213@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB920670
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB920670@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB920670@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB920683
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB920683@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB920683@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB920685
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB920685@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB920685@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB920872
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB920872@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB920872@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB921398
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB921398@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB921398@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB921503
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB921503@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB921503@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB922582
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB922582@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB922582@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB922616
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB922616@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB922616@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB922819
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB922819@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB922819@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB923191
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB923191@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB923191@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB923414
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB923414@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB923414@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB923689
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB923689@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB923689@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB923694
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB923694@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB923694@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB923789
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB923789@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB923789@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB923980
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB923980@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB923980@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB924191
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB924191@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB924191@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB924270
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB924270@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB924270@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB924667
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB924667@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB924667@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB925398_WMP64
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB925398_WMP64@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB925398_WMP64@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB925902
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB925902@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB925902@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB926255
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB926255@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB926255@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB926436
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB926436@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB926436@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB927779
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB927779@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB927779@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB927802
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB927802@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB927802@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB927891
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB927891@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB927891@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB928090-IE7
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB928090-IE7@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB928090-IE7@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB928255
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB928255@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB928255@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB928843
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB928843@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB928843@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB929123
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB929123@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB929123@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB929338
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB929338@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB929338@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB929399
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB929399@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB929399@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB930178
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB930178@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB930178@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB930916
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB930916@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB930916@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB931261
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB931261@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB931261@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB931768-IE7
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB931768-IE7@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB931768-IE7@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB931784
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB931784@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB931784@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB931836
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB931836@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB931836@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB931906
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB931906@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB931906@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB932168
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB932168@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB932168@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB932823-v3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB932823-v3@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB932823-v3@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB933360
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB933360@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB933360@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB933566-IE7
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB933566-IE7@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB933566-IE7@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB933729
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB933729@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB933729@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB935448
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB935448@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB935448@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB935839
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB935839@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB935839@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB935840
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB935840@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB935840@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB936021
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB936021@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB936021@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB936357
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB936357@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB936357@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB936782_WMP11
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB936782_WMP11@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB936782_WMP11@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB936782_WMP9
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB936782_WMP9@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB936782_WMP9@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB937143-IE7
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB937143-IE7@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB937143-IE7@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB937894
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB937894@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB937894@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB938127-IE7
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB938127-IE7@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB938127-IE7@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB938464
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB938464@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB938464@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB938828
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB938828@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB938828@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB938829
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB938829@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB938829@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB939653-IE7
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB939653-IE7@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB939653-IE7@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB939683
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB939683@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB939683@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB940157
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB940157@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB940157@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB941202
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB941202@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB941202@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB941568
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB941568@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB941568@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB941569
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB941569@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB941569@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB941644
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB941644@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB941644@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB941693
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB941693@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB941693@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB942615-IE7
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB942615-IE7@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB942615-IE7@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB942763
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB942763@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB942763@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB943055
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB943055@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB943055@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB943460
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB943460@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB943460@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB943485
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB943485@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB943485@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB943729
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB943729@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB943729@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB944533-IE7
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB944533-IE7@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB944533-IE7@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB944653
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB944653@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB944653@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB945553
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB945553@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB945553@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB946026
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB946026@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB946026@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB946648
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB946648@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB946648@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB947864-IE7
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB947864-IE7@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB947864-IE7@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB948590
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB948590@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB948590@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB948881
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB948881@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB948881@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB950749
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB950749@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB950749@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB950759-IE7
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB950759-IE7@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB950759-IE7@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB950760
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB950760@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB950760@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB950762
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB950762@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB950762@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB950974
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB950974@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB950974@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB951066
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB951066@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB951066@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB951072-v2
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB951072-v2@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB951072-v2@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB951376
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB951376@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB951376@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB951376-v2
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB951376-v2@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB951376-v2@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB951698
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB951698@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB951698@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB951748
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB951748@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB951748@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB951978
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB951978@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB951978@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB952069_WM9
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB952069_WM9@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB952069_WM9@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB952287
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB952287@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB952287@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB952954
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB952954@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB952954@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB953838-IE7
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB953838-IE7@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB953838-IE7@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB953839
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB953839@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB953839@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB954154_WM11
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB954154_WM11@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB954154_WM11@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB954211
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB954211@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB954211@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB954459
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB954459@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB954459@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB954600
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB954600@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB954600@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB955069
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB955069@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB955069@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB955839
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB955839@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB955839@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB956390-IE7
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB956390-IE7@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB956390-IE7@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB956391
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB956391@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB956391@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB956802
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB956802@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB956802@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB956803
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB956803@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB956803@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB956841
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB956841@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB956841@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB957095
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB957095@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB957095@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB957097
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB957097@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB957097@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB958215-IE7
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB958215-IE7@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB958215-IE7@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB958644
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB958644@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB958644@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB960714-IE7
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB960714-IE7@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB960714-IE7@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\LiveUpdate
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\LiveUpdate@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\LiveUpdate@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\M886903
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\M886903@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\M886903@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\M928366
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\M928366@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\M928366@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Microsoft .NET Framework 1.1 (1033)
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Microsoft .NET Framework 1.1 (1033)@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Microsoft .NET Framework 1.1 (1033)@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MSCompPackV1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MSCompPackV1@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MSCompPackV1@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MSNINST
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MSNINST@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MSNINST@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\NVIDIA Drivers
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\NVIDIA Drivers@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\NVIDIA Drivers@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\PROPLUS
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\PROPLUS@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\PROPLUS@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\WGA
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\WGA@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\WGA@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\WgaNotify
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\WgaNotify@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\WgaNotify@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Windows Media Format Runtime
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Windows Media Format Runtime@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Windows Media Format Runtime@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Windows Media Player
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Windows Media Player@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Windows Media Player@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Windows XP Service Pack
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Windows XP Service Pack@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Windows XP Service Pack@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Wudf01000
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Wudf01000@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Wudf01000@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{075473F5-846A-448B-BCB3-104AA1760205}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{075473F5-846A-448B-BCB3-104AA1760205}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{075473F5-846A-448B-BCB3-104AA1760205}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{125F0ACC-D3FC-402B-8D96-27F6E46D00D5}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{125F0ACC-D3FC-402B-8D96-27F6E46D00D5}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{125F0ACC-D3FC-402B-8D96-27F6E46D00D5}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{1CB92574-96F2-467B-B793-5CEB35C40C29}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{1CB92574-96F2-467B-B793-5CEB35C40C29}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{1CB92574-96F2-467B-B793-5CEB35C40C29}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{2085C617-589C-40F8-BE40-EDBC9E2CA2EB}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{2085C617-589C-40F8-BE40-EDBC9E2CA2EB}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{2085C617-589C-40F8-BE40-EDBC9E2CA2EB}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{26792CA7-D87A-4DBE-896B-C2F66B344511}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{26792CA7-D87A-4DBE-896B-C2F66B344511}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{26792CA7-D87A-4DBE-896B-C2F66B344511}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{30465B6C-B53F-49A1-9EBA-A3F187AD502E}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{30465B6C-B53F-49A1-9EBA-A3F187AD502E}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{3248F0A8-6813-11D6-A77B-00B0D0150000}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{3248F0A8-6813-11D6-A77B-00B0D0150000}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{3248F0A8-6813-11D6-A77B-00B0D0150000}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{4362D7D1-6C84-47AC-A173-1391EB4F149A}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{4362D7D1-6C84-47AC-A173-1391EB4F149A}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{4362D7D1-6C84-47AC-A173-1391EB4F149A}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{45D68F08-56A0-4412-BB0F-8492BE978AC7}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{45D68F08-56A0-4412-BB0F-8492BE978AC7}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{45D68F08-56A0-4412-BB0F-8492BE978AC7}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{46B63F23-2B4A-4525-A827-688026BE5E40}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{46B63F23-2B4A-4525-A827-688026BE5E40}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{46B63F23-2B4A-4525-A827-688026BE5E40}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{558CD0A7-0548-4220-88FE-01CC1477DF61}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{558CD0A7-0548-4220-88FE-01CC1477DF61}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{558CD0A7-0548-4220-88FE-01CC1477DF61}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{5AC9F44E-06C7-41E3-A464-37177AB9105D}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{5AC9F44E-06C7-41E3-A464-37177AB9105D}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{5AC9F44E-06C7-41E3-A464-37177AB9105D}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{7C3E3706-8FBD-4169-9726-0A47FBF9D32A}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{7C3E3706-8FBD-4169-9726-0A47FBF9D32A}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{7C3E3706-8FBD-4169-9726-0A47FBF9D32A}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{808E5AB1-E98F-4362-AB10-B5B69CB2301C}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{808E5AB1-E98F-4362-AB10-B5B69CB2301C}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{808E5AB1-E98F-4362-AB10-B5B69CB2301C}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{4551666D-0FD6-4C69-8A81-1C6F2E64517C}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{4551666D-0FD6-4C69-8A81-1C6F2E64517C}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{4551666D-0FD6-4C69-8A81-1C6F2E64517C}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{4AD3A076-427C-491F-A5B7-7D1DE788A756}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{4AD3A076-427C-491F-A5B7-7D1DE788A756}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{4AD3A076-427C-491F-A5B7-7D1DE788A756}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{558B709B-821B-4FC5-90FC-9A8890641E77}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{558B709B-821B-4FC5-90FC-9A8890641E77}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{558B709B-821B-4FC5-90FC-9A8890641E77}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{5F7F6FFF-395D-480E-8450-64F385D82C5F}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{5F7F6FFF-395D-480E-8450-64F385D82C5F}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{5F7F6FFF-395D-480E-8450-64F385D82C5F}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{648FC016-2D6B-4A16-8D87-404533642F4B}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{648FC016-2D6B-4A16-8D87-404533642F4B}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{648FC016-2D6B-4A16-8D87-404533642F4B}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6491B8AA-D11C-4648-A461-6234B31EB7E2}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6491B8AA-D11C-4648-A461-6234B31EB7E2}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6491B8AA-D11C-4648-A461-6234B31EB7E2}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{797AE457-BA17-4BBC-B501-25FB3A0103C7}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{797AE457-BA17-4BBC-B501-25FB3A0103C7}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{797AE457-BA17-4BBC-B501-25FB3A0103C7}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{79B301C1-DBC0-467C-AFDA-2A6CDAFA4302}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{79B301C1-DBC0-467C-AFDA-2A6CDAFA4302}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{79B301C1-DBC0-467C-AFDA-2A6CDAFA4302}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{885E081B-72BD-4E76-8E98-30B4BE468FAC}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{885E081B-72BD-4E76-8E98-30B4BE468FAC}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{885E081B-72BD-4E76-8E98-30B4BE468FAC}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{A420F522-7395-4872-9882-C591B4B92278}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{A420F522-7395-4872-9882-C591B4B92278}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{A420F522-7395-4872-9882-C591B4B92278}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{B243E9A5-ED77-4F1B-B338-2486FD82DC85}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{B243E9A5-ED77-4F1B-B338-2486FD82DC85}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{B243E9A5-ED77-4F1B-B338-2486FD82DC85}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{D670F9B9-3E84-47B5-8A4A-618B65DB1593}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{D670F9B9-3E84-47B5-8A4A-618B65DB1593}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{D670F9B9-3E84-47B5-8A4A-618B65DB1593}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{51864046-74C8-487B-97CD-6167A4B1DB56}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{51864046-74C8-487B-97CD-6167A4B1DB56}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{51864046-74C8-487B-97CD-6167A4B1DB56}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{B20E2C59-EEC5-4102-9E50-5DBB2093C37D}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{B20E2C59-EEC5-4102-9E50-5DBB2093C37D}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{B20E2C59-EEC5-4102-9E50-5DBB2093C37D}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{4E140A5A-4A90-404A-B955-10C2D98CD3EE}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{4E140A5A-4A90-404A-B955-10C2D98CD3EE}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{4E140A5A-4A90-404A-B955-10C2D98CD3EE}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{6F0E4983-E419-4591-B7DD-EFB0073D3E47}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{6F0E4983-E419-4591-B7DD-EFB0073D3E47}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{6F0E4983-E419-4591-B7DD-EFB0073D3E47}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{54DF3345-0720-4224-9740-C7E00303F565}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{54DF3345-0720-4224-9740-C7E00303F565}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{54DF3345-0720-4224-9740-C7E00303F565}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{766DF26B-5F03-48ED-9307-5326F2790ED0}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{766DF26B-5F03-48ED-9307-5326F2790ED0}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{766DF26B-5F03-48ED-9307-5326F2790ED0}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{C8C72583-C907-4D20-8973-C3858D96BD9E}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{C8C72583-C907-4D20-8973-C3858D96BD9E}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{C8C72583-C907-4D20-8973-C3858D96BD9E}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{F21BF703-548C-47B2-B92A-6876E9566C42}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{F21BF703-548C-47B2-B92A-6876E9566C42}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{F21BF703-548C-47B2-B92A-6876E9566C42}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{901C63FD-6673-47A6-9B5F-B13E3EBFA470}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{901C63FD-6673-47A6-9B5F-B13E3EBFA470}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{901C63FD-6673-47A6-9B5F-B13E3EBFA470}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{AB708C9B-97C8-4AC9-899B-DBF226AC9382}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{AB708C9B-97C8-4AC9-899B-DBF226AC9382}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{AC76BA86-7AD7-1033-7B44-A70800000002}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{AC76BA86-7AD7-1033-7B44-A70800000002}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{AC76BA86-7AD7-1033-7B44-A70800000002}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{AFB4DC8C-22CF-483C-8A55-CD9C4A749BAC}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{AFB4DC8C-22CF-483C-8A55-CD9C4A749BAC}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{AFB4DC8C-22CF-483C-8A55-CD9C4A749BAC}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{B12665F4-4E93-4AB4-B7FC-37053B524629}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{B12665F4-4E93-4AB4-B7FC-37053B524629}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{B12665F4-4E93-4AB4-B7FC-37053B524629}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{B508B3F1-A24A-32C0-B310-85786919EF28}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{B508B3F1-A24A-32C0-B310-85786919EF28}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{B508B3F1-A24A-32C0-B310-85786919EF28}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{C3CE4CED-46B0-407E-A703-7A83AAE02A36}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{C3CE4CED-46B0-407E-A703-7A83AAE02A36}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{C3CE4CED-46B0-407E-A703-7A83AAE02A36}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{DBE84DB2-1794-4244-9859-9B720CA89B4D}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{DBE84DB2-1794-4244-9859-9B720CA89B4D}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{DBE84DB2-1794-4244-9859-9B720CA89B4D}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{F68E3631-68ED-4970-8D77-B81FE83AA6A1}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{F68E3631-68ED-4970-8D77-B81FE83AA6A1}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{F68E3631-68ED-4970-8D77-B81FE83AA6A1}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{FB64BF25-3593-4E4E-AA85-84AEF1D1475F}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{FB64BF25-3593-4E4E-AA85-84AEF1D1475F}@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{FB64BF25-3593-4E4E-AA85-84AEF1D1475F}@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\javaws.exe@ C:\Program Files\Java\jre1.5.0\bin\javaws.exe
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\javaws.exe@Path C:\Program Files\Java\jre1.5.0\bin
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls\inetcpl.cpl@RunLevel 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:ACRAD52:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0004,3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:ACRAD52:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0004,3\1024x768 x 60Hz
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:ACRAD52:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0004,3\1024x768 x 60Hz@32 bpp 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:ACRAD52:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0004,3\1440x900 x 60Hz
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:ACRAD52:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0004,3\1440x900 x 60Hz@32 bpp 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:ACRAD52:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0004,3\640x480 x 60Hz
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:ACRAD52:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0004,3\640x480 x 60Hz@8 bpp 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0001,0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0001,0\1024x768 x 60Hz
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0001,0\1024x768 x 60Hz@32 bpp 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0001,0\1280x1024 x 60Hz
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0001,0\1280x1024 x 60Hz@32 bpp 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0001,0\1280x768 x 60Hz
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0001,0\1280x768 x 60Hz@32 bpp 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0001,0\1440x900 x 60Hz
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0001,0\1440x900 x 60Hz@32 bpp 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0001,0\640x480 x 60Hz
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0001,0\640x480 x 60Hz@8 bpp 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0001,0\800x600 x 60Hz
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0001,0\800x600 x 60Hz@32 bpp 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0002,1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0002,1\1024x768 x 60Hz
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0002,1\1024x768 x 60Hz@32 bpp 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0002,1\1280x1024 x 60Hz
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0002,1\1280x1024 x 60Hz@32 bpp 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0002,1\1280x768 x 60Hz
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0002,1\1280x768 x 60Hz@32 bpp 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0002,1\1440x900 x 60Hz
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0002,1\1440x900 x 60Hz@32 bpp 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0002,1\640x480 x 60Hz
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0002,1\640x480 x 60Hz@8 bpp 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0002,1\800x600 x 60Hz
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0002,1\800x600 x 60Hz@32 bpp 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0003,2
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0003,2\1024x768 x 60Hz
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0003,2\1024x768 x 60Hz@32 bpp 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0003,2\1280x1024 x 60Hz
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0003,2\1280x1024 x 60Hz@32 bpp 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0003,2\1280x768 x 60Hz
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0003,2\1280x768 x 60Hz@32 bpp 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0003,2\1440x900 x 60Hz
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0003,2\1440x900 x 60Hz@32 bpp 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0003,2\640x480 x 60Hz
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0003,2\640x480 x 60Hz@8 bpp 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0003,2\800x600 x 60Hz
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:Default_Monitor:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0003,2\800x600 x 60Hz@32 bpp 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:GWY1B66:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0000,3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:GWY1B66:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0000,3\1024x768 x 60Hz
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:GWY1B66:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0000,3\1024x768 x 60Hz@32 bpp 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:GWY1B66:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0000,3\640x480 x 60Hz
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:GWY1B66:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0000,3\640x480 x 60Hz@8 bpp 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:GWY1B66:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0000,3\800x600 x 60Hz
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:GWY1B66:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0000,3\800x600 x 60Hz@32 bpp 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:NEC65EE:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0005,3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:NEC65EE:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0005,3\1280x1024 x 60Hz
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:NEC65EE:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0005,3\1280x1024 x 60Hz@32 bpp 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:NEC65EE:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0005,3\1280x768 x 60Hz
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:NEC65EE:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0005,3\1280x768 x 60Hz@32 bpp 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:NEC65EE:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0005,3\640x480 x 60Hz
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings\Video\PCI:VEN_10DE&DEV_0165&SUBSYS_033410DE&REV_A1\Monitor:NEC65EE:{4D36E96E-E325-11CE-BFC1-08002BE10318}:0005,3\640x480 x 60Hz@8 bpp 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}@AutoStart
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Extensions@.ini notepad.exe ^.ini
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Extensions@.txt notepad.exe ^.txt
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Extensions@.wtx notepad.exe ^.wtx
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Hints\Administrator@
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\NoFileLifetimeExtension@.pub
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\NoFileLifetimeExtension@.vsi
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ACTIVEX_OPTIN@Bitmap C:\WINDOWS\system32\inetcpl.cpl,1321
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ACTIVEX_OPTIN@PlugUIText @inetcpl.cpl,-4897
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ACTIVEX_OPTIN@Text Allow previously unused ActiveX controls to run without prompt
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ACTIVEX_OPTIN@Type group
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ACTIVEX_OPTIN\DISABLE
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ACTIVEX_OPTIN\DISABLE@CheckedValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ACTIVEX_OPTIN\DISABLE@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ACTIVEX_OPTIN\DISABLE@PlugUIText @inetcpl.cpl,-4805
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ACTIVEX_OPTIN\DISABLE@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ACTIVEX_OPTIN\DISABLE@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ACTIVEX_OPTIN\DISABLE@Text Disable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ACTIVEX_OPTIN\DISABLE@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ACTIVEX_OPTIN\DISABLE@ValueName 1208
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ACTIVEX_OPTIN\ENABLE
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ACTIVEX_OPTIN\ENABLE@CheckedValue 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ACTIVEX_OPTIN\ENABLE@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ACTIVEX_OPTIN\ENABLE@PlugUIText @inetcpl.cpl,-4803
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ACTIVEX_OPTIN\ENABLE@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ACTIVEX_OPTIN\ENABLE@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ACTIVEX_OPTIN\ENABLE@Text Enable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ACTIVEX_OPTIN\ENABLE@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ACTIVEX_OPTIN\ENABLE@ValueName 1208
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO@Bitmap C:\WINDOWS\system32\inetcpl.cpl,1321
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO@PlugUIText @inetcpl.cpl,-4899
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO@Text Display video and animation on a webpage that does not use external media player
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO@Type group
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\DISABLE
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\DISABLE@CheckedValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\DISABLE@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\DISABLE@PlugUIText @inetcpl.cpl,-4805
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\DISABLE@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\DISABLE@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\DISABLE@Text Disable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\DISABLE@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\DISABLE@ValueName 120A
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\ENABLE
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\ENABLE@CheckedValue 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\ENABLE@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\ENABLE@PlugUIText @inetcpl.cpl,-4803
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\ENABLE@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\ENABLE@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\ENABLE@Text Enable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\ENABLE@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\ENABLE@ValueName 120A
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN@Bitmap C:\WINDOWS\system32\inetcpl.cpl,1321
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN@PlugUIText @inetcpl.cpl,-4780
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN@Text Allow Scriptlets
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN@Type group
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN\ALLOW
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN\ALLOW@CheckedValue 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN\ALLOW@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN\ALLOW@PlugUIText @inetcpl.cpl,-4803
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN\ALLOW@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN\ALLOW@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN\ALLOW@Text Enable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN\ALLOW@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN\ALLOW@ValueName 1209
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN\DENY
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN\DENY@CheckedValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN\DENY@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN\DENY@PlugUIText @inetcpl.cpl,-4805
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN\DENY@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN\DENY@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN\DENY@Text Disable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN\DENY@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN\DENY@ValueName 1209
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN\QUERY
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN\QUERY@CheckedValue 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN\QUERY@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN\QUERY@PlugUIText @inetcpl.cpl,-4804
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN\QUERY@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN\QUERY@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN\QUERY@Text Prompt
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN\QUERY@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\ACTIVE_CONTENT\SCRIPTLETRUN\QUERY@ValueName 1209
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\FORCE_ADDRESS_BAR@Bitmap C:\WINDOWS\system32\inetcpl.cpl,4443
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\FORCE_ADDRESS_BAR@PlugUIText @inetcpl.cpl,-4898
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\FORCE_ADDRESS_BAR@Text Allow web sites to open windows without address or status bars
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\FORCE_ADDRESS_BAR@Type group
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\FORCE_ADDRESS_BAR\DISABLE
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\FORCE_ADDRESS_BAR\DISABLE@CheckedValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\FORCE_ADDRESS_BAR\DISABLE@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\FORCE_ADDRESS_BAR\DISABLE@PlugUIText @inetcpl.cpl,-4805
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\FORCE_ADDRESS_BAR\DISABLE@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\FORCE_ADDRESS_BAR\DISABLE@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\FORCE_ADDRESS_BAR\DISABLE@Text Disable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\FORCE_ADDRESS_BAR\DISABLE@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\FORCE_ADDRESS_BAR\DISABLE@ValueName 2104
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\FORCE_ADDRESS_BAR\ENABLE
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\FORCE_ADDRESS_BAR\ENABLE@CheckedValue 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\FORCE_ADDRESS_BAR\ENABLE@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\FORCE_ADDRESS_BAR\ENABLE@PlugUIText @inetcpl.cpl,-4803
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\FORCE_ADDRESS_BAR\ENABLE@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\FORCE_ADDRESS_BAR\ENABLE@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\FORCE_ADDRESS_BAR\ENABLE@Text Enable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\FORCE_ADDRESS_BAR\ENABLE@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\FORCE_ADDRESS_BAR\ENABLE@ValueName 2104
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\INC_UPLOAD_FILEPATH@Bitmap C:\WINDOWS\system32\inetcpl.cpl,4443
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\INC_UPLOAD_FILEPATH@PlugUIText @inetcpl.cpl,-4911
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\INC_UPLOAD_FILEPATH@Text Include local directory path when uploading files to a server
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\INC_UPLOAD_FILEPATH@Type group
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\INC_UPLOAD_FILEPATH\DISABLE
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\INC_UPLOAD_FILEPATH\DISABLE@CheckedValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\INC_UPLOAD_FILEPATH\DISABLE@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\INC_UPLOAD_FILEPATH\DISABLE@PlugUIText @inetcpl.cpl,-4805
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\INC_UPLOAD_FILEPATH\DISABLE@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\INC_UPLOAD_FILEPATH\DISABLE@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\INC_UPLOAD_FILEPATH\DISABLE@Text Disable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\INC_UPLOAD_FILEPATH\DISABLE@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\INC_UPLOAD_FILEPATH\DISABLE@ValueName 160A
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\INC_UPLOAD_FILEPATH\ENABLE
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\INC_UPLOAD_FILEPATH\ENABLE@CheckedValue 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\INC_UPLOAD_FILEPATH\ENABLE@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\INC_UPLOAD_FILEPATH\ENABLE@PlugUIText @inetcpl.cpl,-4803
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\INC_UPLOAD_FILEPATH\ENABLE@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\INC_UPLOAD_FILEPATH\ENABLE@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\INC_UPLOAD_FILEPATH\ENABLE@Text Enable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\INC_UPLOAD_FILEPATH\ENABLE@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\INC_UPLOAD_FILEPATH\ENABLE@ValueName 160A
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\PHISHINGFILTER@Bitmap C:\WINDOWS\system32\inetcpl.cpl,4443
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\PHISHINGFILTER@PlugUIText @inetcpl.cpl,-5368
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\PHISHINGFILTER@Text Use Phishing Filter
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\PHISHINGFILTER@Type group
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\PHISHINGFILTER\ALLOW
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\PHISHINGFILTER\ALLOW@CheckedValue 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\PHISHINGFILTER\ALLOW@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\PHISHINGFILTER\ALLOW@PlugUIText @inetcpl.cpl,-4803
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\PHISHINGFILTER\ALLOW@RegPath Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\PHISHINGFILTER\ALLOW@RegPoliciesPath Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\PHISHINGFILTER\ALLOW@Text Enable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\PHISHINGFILTER\ALLOW@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\PHISHINGFILTER\ALLOW@ValueName 2301
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\PHISHINGFILTER\DENY
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\PHISHINGFILTER\DENY@CheckedValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\PHISHINGFILTER\DENY@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\PHISHINGFILTER\DENY@PlugUIText @inetcpl.cpl,-4805
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\PHISHINGFILTER\DENY@RegPath Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\PHISHINGFILTER\DENY@RegPoliciesPath Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\PHISHINGFILTER\DENY@Text Disable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\PHISHINGFILTER\DENY@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\PHISHINGFILTER\DENY@ValueName 2301
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC@Bitmap C:\WINDOWS\system32\inetcpl.cpl,4443
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC@PlugUIText @inetcpl.cpl,-4864
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC@Text Launching programs and unsafe files
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC@Type group
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC\ALLOW
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC\ALLOW@CheckedValue 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC\ALLOW@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC\ALLOW@PlugUIText @inetcpl.cpl,-4803
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC\ALLOW@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC\ALLOW@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC\ALLOW@Text Enable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC\ALLOW@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC\ALLOW@ValueName 1806
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC\DENY
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC\DENY@CheckedValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC\DENY@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC\DENY@PlugUIText @inetcpl.cpl,-4805
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC\DENY@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC\DENY@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC\DENY@Text Disable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC\DENY@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC\DENY@ValueName 1806
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC\QUERY
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC\QUERY@CheckedValue 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC\QUERY@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC\QUERY@PlugUIText @inetcpl.cpl,-4804
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC\QUERY@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC\QUERY@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC\QUERY@Text Prompt
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC\QUERY@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\MISC\SHELLEXEC\QUERY@ValueName 1806
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTPROMPT@Bitmap C:\WINDOWS\system32\inetcpl.cpl,4485
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTPROMPT@PlugUIText @inetcpl.cpl,-4912
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTPROMPT@Text Allow websites to prompt for information using scripted windows
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTPROMPT@Type group
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTPROMPT\ALLOW
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTPROMPT\ALLOW@CheckedValue 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTPROMPT\ALLOW@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTPROMPT\ALLOW@PlugUIText @inetcpl.cpl,-4803
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTPROMPT\ALLOW@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTPROMPT\ALLOW@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTPROMPT\ALLOW@Text Enable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTPROMPT\ALLOW@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTPROMPT\ALLOW@ValueName 2105
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTPROMPT\DENY
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTPROMPT\DENY@CheckedValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTPROMPT\DENY@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTPROMPT\DENY@PlugUIText @inetcpl.cpl,-4805
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTPROMPT\DENY@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTPROMPT\DENY@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTPROMPT\DENY@Text Disable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTPROMPT\DENY@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTPROMPT\DENY@ValueName 2105
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTSTATUS@Bitmap C:\WINDOWS\system32\inetcpl.cpl,4485
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTSTATUS@PlugUIText @inetcpl.cpl,-4867
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTSTATUS@Text Allow status bar updates via script
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTSTATUS@Type group
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTSTATUS\ALLOW
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTSTATUS\ALLOW@CheckedValue 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTSTATUS\ALLOW@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTSTATUS\ALLOW@PlugUIText @inetcpl.cpl,-4803
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTSTATUS\ALLOW@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTSTATUS\ALLOW@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTSTATUS\ALLOW@Text Enable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTSTATUS\ALLOW@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTSTATUS\ALLOW@ValueName 2103
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTSTATUS\DENY
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTSTATUS\DENY@CheckedValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTSTATUS\DENY@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTSTATUS\DENY@PlugUIText @inetcpl.cpl,-4805
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTSTATUS\DENY@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTSTATUS\DENY@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTSTATUS\DENY@Text Disable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTSTATUS\DENY@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTSTATUS\DENY@ValueName 2103
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX@Bitmap C:\WINDOWS\system32\inetcpl.cpl,4486
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX@PlugUIText @inetcpl.cpl,-6400
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX@Text .NET Framework
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX@Type group
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML@Bitmap C:\WINDOWS\system32\inetcpl.cpl,4486
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML@PlugUIText @inetcpl.cpl,-6401
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML@Text Loose XAML
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML@Type group
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML\DISABLE
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML\DISABLE@CheckedValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML\DISABLE@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML\DISABLE@PlugUIText @inetcpl.cpl,-4805
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML\DISABLE@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML\DISABLE@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML\DISABLE@Text Disable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML\DISABLE@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML\DISABLE@ValueName 2402
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML\ENABLE
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML\ENABLE@CheckedValue 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML\ENABLE@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML\ENABLE@PlugUIText @inetcpl.cpl,-4803
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML\ENABLE@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML\ENABLE@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML\ENABLE@Text Enable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML\ENABLE@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML\ENABLE@ValueName 2402
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML\QUERY
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML\QUERY@CheckedValue 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML\QUERY@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML\QUERY@PlugUIText @inetcpl.cpl,-4804
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML\QUERY@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML\QUERY@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML\QUERY@Text Prompt
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML\QUERY@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\LOOSE_XAML\QUERY@ValueName 2402
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS@Bitmap C:\WINDOWS\system32\inetcpl.cpl,4486
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS@PlugUIText @inetcpl.cpl,-6403
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS@Text Windows Browser Applications
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS@Type group
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS\DISABLE
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS\DISABLE@CheckedValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS\DISABLE@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS\DISABLE@PlugUIText @inetcpl.cpl,-4805
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS\DISABLE@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS\DISABLE@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS\DISABLE@Text Disable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS\DISABLE@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS\DISABLE@ValueName 2400
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS\ENABLE
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS\ENABLE@CheckedValue 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS\ENABLE@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS\ENABLE@PlugUIText @inetcpl.cpl,-4803
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS\ENABLE@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS\ENABLE@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS\ENABLE@Text Enable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS\ENABLE@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS\ENABLE@ValueName 2400
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS\QUERY
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS\QUERY@CheckedValue 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS\QUERY@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS\QUERY@PlugUIText @inetcpl.cpl,-4804
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS\QUERY@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS\QUERY@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS\QUERY@Text Prompt
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS\QUERY@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\WINDOWS_BROWSER_APPLICATIONS\QUERY@ValueName 2400
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS@Bitmap C:\WINDOWS\system32\inetcpl.cpl,4486
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS@PlugUIText @inetcpl.cpl,-6402
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS@Text XPS documents
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS@Type group
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS\DISABLE
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS\DISABLE@CheckedValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS\DISABLE@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS\DISABLE@PlugUIText @inetcpl.cpl,-4805
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS\DISABLE@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS\DISABLE@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS\DISABLE@Text Disable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS\DISABLE@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS\DISABLE@ValueName 2401
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS\ENABLE
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS\ENABLE@CheckedValue 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS\ENABLE@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS\ENABLE@PlugUIText @inetcpl.cpl,-4803
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS\ENABLE@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS\ENABLE@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS\ENABLE@Text Enable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS\ENABLE@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS\ENABLE@ValueName 2401
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS\QUERY
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS\QUERY@CheckedValue 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS\QUERY@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS\QUERY@PlugUIText @inetcpl.cpl,-4804
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS\QUERY@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS\QUERY@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS\QUERY@Text Prompt
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS\QUERY@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WINFX\XPS_DOCUMENTS\QUERY@ValueName 2401
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WinFXSetup@Bitmap C:\WINDOWS\system32\inetcpl.cpl,4486
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WinFXSetup@PlugUIText @inetcpl.cpl,-5440
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WinFXSetup@Text Enable .NET Framework setup
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WinFXSetup@Type group
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WinFXSetup\DISABLE
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WinFXSetup\DISABLE@CheckedValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WinFXSetup\DISABLE@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WinFXSetup\DISABLE@PlugUIText @inetcpl.cpl,-4805
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WinFXSetup\DISABLE@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WinFXSetup\DISABLE@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WinFXSetup\DISABLE@Text Disable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WinFXSetup\DISABLE@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WinFXSetup\DISABLE@ValueName 2600
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WinFXSetup\ENABLE
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WinFXSetup\ENABLE@CheckedValue 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WinFXSetup\ENABLE@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WinFXSetup\ENABLE@PlugUIText @inetcpl.cpl,-4803
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WinFXSetup\ENABLE@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WinFXSetup\ENABLE@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WinFXSetup\ENABLE@Text Enable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WinFXSetup\ENABLE@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\WinFXSetup\ENABLE@ValueName 2600
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ACTIVEX_OPTIN@Bitmap C:\WINDOWS\system32\inetcpl.cpl,1321
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ACTIVEX_OPTIN@PlugUIText @inetcpl.cpl,-4897
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ACTIVEX_OPTIN@Text Allow previously unused ActiveX controls to run without prompt
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ACTIVEX_OPTIN@Type group
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ACTIVEX_OPTIN\DISABLE
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ACTIVEX_OPTIN\DISABLE@CheckedValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ACTIVEX_OPTIN\DISABLE@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ACTIVEX_OPTIN\DISABLE@PlugUIText @inetcpl.cpl,-4805
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ACTIVEX_OPTIN\DISABLE@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ACTIVEX_OPTIN\DISABLE@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ACTIVEX_OPTIN\DISABLE@Text Disable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ACTIVEX_OPTIN\DISABLE@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ACTIVEX_OPTIN\DISABLE@ValueName 1208
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ACTIVEX_OPTIN\ENABLE
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ACTIVEX_OPTIN\ENABLE@CheckedValue 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ACTIVEX_OPTIN\ENABLE@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ACTIVEX_OPTIN\ENABLE@PlugUIText @inetcpl.cpl,-4803
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ACTIVEX_OPTIN\ENABLE@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ACTIVEX_OPTIN\ENABLE@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ACTIVEX_OPTIN\ENABLE@Text Enable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ACTIVEX_OPTIN\ENABLE@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ACTIVEX_OPTIN\ENABLE@ValueName 1208
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO@Bitmap C:\WINDOWS\system32\inetcpl.cpl,1321
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO@PlugUIText @inetcpl.cpl,-4899
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO@Text Display video and animation on a webpage that does not use external media player
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO@Type group
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\DISABLE
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\DISABLE@CheckedValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\DISABLE@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\DISABLE@PlugUIText @inetcpl.cpl,-4805
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\DISABLE@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\DISABLE@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\DISABLE@Text Disable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\DISABLE@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\DISABLE@ValueName 120A
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\ENABLE
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\ENABLE@CheckedValue 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\ENABLE@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\ENABLE@PlugUIText @inetcpl.cpl,-4803
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\ENABLE@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\ENABLE@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\ENABLE@Text Enable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\ENABLE@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\ALLOW_DYNSRC_VIDEO\ENABLE@ValueName 120A
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN@Bitmap C:\WINDOWS\system32\inetcpl.cpl,1321
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN@PlugUIText @inetcpl.cpl,-4780
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN@Text Allow Scriptlets
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN@Type group
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN\ALLOW
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN\ALLOW@CheckedValue 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN\ALLOW@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN\ALLOW@PlugUIText @inetcpl.cpl,-4803
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN\ALLOW@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN\ALLOW@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN\ALLOW@Text Enable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN\ALLOW@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN\ALLOW@ValueName 1209
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN\DENY
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN\DENY@CheckedValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN\DENY@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN\DENY@PlugUIText @inetcpl.cpl,-4805
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN\DENY@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN\DENY@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN\DENY@Text Disable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN\DENY@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN\DENY@ValueName 1209
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN\QUERY
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN\QUERY@CheckedValue 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN\QUERY@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN\QUERY@PlugUIText @inetcpl.cpl,-4804
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN\QUERY@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN\QUERY@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN\QUERY@Text Prompt
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN\QUERY@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\ACTIVE_CONTENT\SCRIPTLETRUN\QUERY@ValueName 1209
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\FORCE_ADDRESS_BAR@Bitmap C:\WINDOWS\system32\inetcpl.cpl,4443
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\FORCE_ADDRESS_BAR@PlugUIText @inetcpl.cpl,-4898
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\FORCE_ADDRESS_BAR@Text Allow script-opened windows without an address bar
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\FORCE_ADDRESS_BAR@Type group
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\FORCE_ADDRESS_BAR\DISABLE
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\FORCE_ADDRESS_BAR\DISABLE@CheckedValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\FORCE_ADDRESS_BAR\DISABLE@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\FORCE_ADDRESS_BAR\DISABLE@PlugUIText @inetcpl.cpl,-4805
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\FORCE_ADDRESS_BAR\DISABLE@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\FORCE_ADDRESS_BAR\DISABLE@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\FORCE_ADDRESS_BAR\DISABLE@Text Disable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\FORCE_ADDRESS_BAR\DISABLE@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\FORCE_ADDRESS_BAR\DISABLE@ValueName 2104
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\FORCE_ADDRESS_BAR\ENABLE
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\FORCE_ADDRESS_BAR\ENABLE@CheckedValue 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\FORCE_ADDRESS_BAR\ENABLE@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\FORCE_ADDRESS_BAR\ENABLE@PlugUIText @inetcpl.cpl,-4803
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\FORCE_ADDRESS_BAR\ENABLE@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\FORCE_ADDRESS_BAR\ENABLE@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\FORCE_ADDRESS_BAR\ENABLE@Text Enable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\FORCE_ADDRESS_BAR\ENABLE@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\FORCE_ADDRESS_BAR\ENABLE@ValueName 2104
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC@Bitmap C:\WINDOWS\system32\inetcpl.cpl,4443
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC@PlugUIText @inetcpl.cpl,-4864
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC@Text Launching programs and unsafe files
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC@Type group
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC\ALLOW
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC\ALLOW@CheckedValue 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC\ALLOW@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC\ALLOW@PlugUIText @inetcpl.cpl,-4803
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC\ALLOW@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC\ALLOW@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC\ALLOW@Text Enable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC\ALLOW@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC\ALLOW@ValueName 1806
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC\DENY
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC\DENY@CheckedValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC\DENY@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC\DENY@PlugUIText @inetcpl.cpl,-4805
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC\DENY@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC\DENY@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC\DENY@Text Disable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC\DENY@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC\DENY@ValueName 1806
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC\QUERY
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC\QUERY@CheckedValue 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC\QUERY@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC\QUERY@PlugUIText @inetcpl.cpl,-4804
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC\QUERY@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC\QUERY@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC\QUERY@Text Prompt
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC\QUERY@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\MISC\SHELLEXEC\QUERY@ValueName 1806
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\SCRIPTING\SCRIPTSTATUS@Bitmap C:\WINDOWS\system32\inetcpl.cpl,4485
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\SCRIPTING\SCRIPTSTATUS@PlugUIText @inetcpl.cpl,-4867
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\SCRIPTING\SCRIPTSTATUS@Text Allow status bar updates via script
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\SCRIPTING\SCRIPTSTATUS@Type group
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\SCRIPTING\SCRIPTSTATUS\ALLOW
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\SCRIPTING\SCRIPTSTATUS\ALLOW@CheckedValue 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\SCRIPTING\SCRIPTSTATUS\ALLOW@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\SCRIPTING\SCRIPTSTATUS\ALLOW@PlugUIText @inetcpl.cpl,-4803
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\SCRIPTING\SCRIPTSTATUS\ALLOW@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\SCRIPTING\SCRIPTSTATUS\ALLOW@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\SCRIPTING\SCRIPTSTATUS\ALLOW@Text Enable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\SCRIPTING\SCRIPTSTATUS\ALLOW@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\SCRIPTING\SCRIPTSTATUS\ALLOW@ValueName 2103
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\SCRIPTING\SCRIPTSTATUS\DENY
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\SCRIPTING\SCRIPTSTATUS\DENY@CheckedValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\SCRIPTING\SCRIPTSTATUS\DENY@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\SCRIPTING\SCRIPTSTATUS\DENY@PlugUIText @inetcpl.cpl,-4805
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\SCRIPTING\SCRIPTSTATUS\DENY@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\SCRIPTING\SCRIPTSTATUS\DENY@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\SCRIPTING\SCRIPTSTATUS\DENY@Text Disable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\SCRIPTING\SCRIPTSTATUS\DENY@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\SCRIPTING\SCRIPTSTATUS\DENY@ValueName 2103
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX@Bitmap C:\WINDOWS\system32\inetcpl.cpl,4486
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX@PlugUIText @inetcpl.cpl,-6400
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX@Text WinFX
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX@Type group
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML@Bitmap C:\WINDOWS\system32\inetcpl.cpl,4486
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML@PlugUIText @inetcpl.cpl,-6401
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML@Text Loose XAML
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML@Type group
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML\ALLOW
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML\ALLOW@CheckedValue 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML\ALLOW@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML\ALLOW@PlugUIText @inetcpl.cpl,-4803
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML\ALLOW@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML\ALLOW@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML\ALLOW@Text Enable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML\ALLOW@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML\ALLOW@ValueName 2402
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML\DISABLE
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML\DISABLE@CheckedValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML\DISABLE@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML\DISABLE@PlugUIText @inetcpl.cpl,-4805
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML\DISABLE@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML\DISABLE@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML\DISABLE@Text Disable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML\DISABLE@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML\DISABLE@ValueName 2402
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML\QUERY
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML\QUERY@CheckedValue 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML\QUERY@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML\QUERY@PlugUIText @inetcpl.cpl,-4804
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML\QUERY@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML\QUERY@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML\QUERY@Text Prompt
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML\QUERY@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\LOOSE_XAML\QUERY@ValueName 2402
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS@Bitmap C:\WINDOWS\system32\inetcpl.cpl,4486
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS@PlugUIText @inetcpl.cpl,-6403
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS@Text windows Browser Applications
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS@Type group
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS\ALLOW
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS\ALLOW@CheckedValue 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS\ALLOW@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS\ALLOW@PlugUIText @inetcpl.cpl,-4803
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS\ALLOW@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS\ALLOW@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS\ALLOW@Text Enable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS\ALLOW@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS\ALLOW@ValueName 2400
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS\DISABLE
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS\DISABLE@CheckedValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS\DISABLE@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS\DISABLE@PlugUIText @inetcpl.cpl,-4805
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS\DISABLE@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS\DISABLE@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS\DISABLE@Text Disable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS\DISABLE@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS\DISABLE@ValueName 2400
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS\QUERY
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS\QUERY@CheckedValue 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS\QUERY@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS\QUERY@PlugUIText @inetcpl.cpl,-4804
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS\QUERY@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS\QUERY@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS\QUERY@Text Prompt
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS\QUERY@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\WINDOWS_BROWSER_APPLICATIONS\QUERY@ValueName 2400
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS@Bitmap C:\WINDOWS\system32\inetcpl.cpl,4486
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS@PlugUIText @inetcpl.cpl,-6402
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS@Text XPS documents
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS@Type group
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS\ALLOW
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS\ALLOW@CheckedValue 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS\ALLOW@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS\ALLOW@PlugUIText @inetcpl.cpl,-4803
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS\ALLOW@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS\ALLOW@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS\ALLOW@Text Enable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS\ALLOW@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS\ALLOW@ValueName 2401
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS\DISABLE
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS\DISABLE@CheckedValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS\DISABLE@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS\DISABLE@PlugUIText @inetcpl.cpl,-4805
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS\DISABLE@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS\DISABLE@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS\DISABLE@Text Disable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS\DISABLE@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS\DISABLE@ValueName 2401
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS\QUERY
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS\QUERY@CheckedValue 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS\QUERY@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS\QUERY@PlugUIText @inetcpl.cpl,-4804
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS\QUERY@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS\QUERY@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS\QUERY@Text Prompt
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS\QUERY@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WINFX\XPS_DOCUMENTS\QUERY@ValueName 2401
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WinFXSetup@Bitmap C:\WINDOWS\system32\inetcpl.cpl,4486
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WinFXSetup@PlugUIText @inetcpl.cpl,-5440
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WinFXSetup@Text Enable WinFX Runtime Components Setup
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WinFXSetup@Type group
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WinFXSetup\ALLOW
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WinFXSetup\ALLOW@CheckedValue 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WinFXSetup\ALLOW@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WinFXSetup\ALLOW@PlugUIText @inetcpl.cpl,-4803
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WinFXSetup\ALLOW@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WinFXSetup\ALLOW@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WinFXSetup\ALLOW@Text Enable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WinFXSetup\ALLOW@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WinFXSetup\ALLOW@ValueName 2600
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WinFXSetup\DISABLE
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WinFXSetup\DISABLE@CheckedValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WinFXSetup\DISABLE@DefaultValue 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WinFXSetup\DISABLE@PlugUIText @inetcpl.cpl,-4805
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WinFXSetup\DISABLE@RegPath SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WinFXSetup\DISABLE@RegPoliciesPath SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%s
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WinFXSetup\DISABLE@Text Disable
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WinFXSetup\DISABLE@Type radio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\WinFXSetup\DISABLE@ValueName 2600
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1001 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1004 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1200 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1201 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1206 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1207 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1208 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1209 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@120A 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1400 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1402 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1405 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1406 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1407 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1408 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1601 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1604 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1605 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1606 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1607 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1608 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1609 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@160A 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1800 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1802 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1803 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1804 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1806 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1809 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1A00 131072
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1A02 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1A03 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1A04 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1A05 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1A06 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1C00 65536
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@1E05 131072
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@2000 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@2100 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@2101 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@2102 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@2103 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@2104 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@2105 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@2200 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@2201 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@2300 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@2301 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@2400 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@2401 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@2402 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@2600 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@Description Help prevent malware from accessing your computer.
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@DisplayName Internet recommended safety (medium high security)
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@Icon wininet.dll#00001206
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@TemplateIndex 70912
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@2001 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@2004 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies\MedHigh@2007 65536
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\PropertySystem\PropertyHandlers\.url@ {FBF23B40-E3F0-101B-8488-00AA003E56F8}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\PropertySystem\PropertyHandlers\.url@DisableProcessIsolation 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0000
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0000@DeviceDesc Intel(R) 82801 PCI Bridge - 244E
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0000@DisplayName Intel(R) 82801 PCI Bridge - 244E
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0000@Mfg Intel
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0000@ProviderName Microsoft
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0000@DeviceInstanceIds PCI\VEN_8086&DEV_244E&SUBSYS_00000000&REV_E1\3&B1BFB68&0&F0?
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0000@ReinstallString C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\machine.inf
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0001
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0001@DeviceDesc PCI standard ISA bridge
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0001@DisplayName PCI standard ISA bridge
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0001@Mfg (Standard system devices)
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0001@ProviderName Microsoft
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0001@DeviceInstanceIds PCI\VEN_8086&DEV_27B8&SUBSYS_00000000&REV_01\3&B1BFB68&0&F8?
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0001@ReinstallString C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\machine.inf
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0002
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0002@DeviceDesc Standard Universal PCI to USB Host Controller
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0002@DisplayName Standard Universal PCI to USB Host Controller
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0002@Mfg (Standard USB Host Controller)
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0002@ProviderName Microsoft
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0002@DeviceInstanceIds PCI\VEN_8086&DEV_27C8&SUBSYS_280C103C&REV_01\3&B1BFB68&0&E8?
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0002@ReinstallString C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\usbport.inf
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0003
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0003@DeviceDesc Standard Universal PCI to USB Host Controller
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0003@DisplayName Standard Universal PCI to USB Host Controller
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0003@Mfg (Standard USB Host Controller)
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0003@ProviderName Microsoft
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0003@DeviceInstanceIds PCI\VEN_8086&DEV_27C9&SUBSYS_280C103C&REV_01\3&B1BFB68&0&E9?
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0003@ReinstallString C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\usbport.inf
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0004
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0004@DeviceDesc Standard Universal PCI to USB Host Controller
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0004@DisplayName Standard Universal PCI to USB Host Controller
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0004@Mfg (Standard USB Host Controller)
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0004@ProviderName Microsoft
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0004@DeviceInstanceIds PCI\VEN_8086&DEV_27CA&SUBSYS_280C103C&REV_01\3&B1BFB68&0&EA?
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0004@ReinstallString C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\usbport.inf
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0005
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0005@DeviceDesc Standard Universal PCI to USB Host Controller
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0005@DisplayName Standard Universal PCI to USB Host Controller
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0005@Mfg (Standard USB Host Controller)
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0005@ProviderName Microsoft
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0005@DeviceInstanceIds PCI\VEN_8086&DEV_27CB&SUBSYS_280C103C&REV_01\3&B1BFB68&0&EB?
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0005@ReinstallString C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\usbport.inf
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0006
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0006@DeviceDesc Standard Enhanced PCI to USB Host Controller
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0006@DisplayName Standard Enhanced PCI to USB Host Controller
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0006@Mfg (Standard USB Host Controller)
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0006@ProviderName Microsoft
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0006@DeviceInstanceIds PCI\VEN_8086&DEV_27CC&SUBSYS_280C103C&REV_01\3&B1BFB68&0&EF?
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0006@ReinstallString C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\usbport.inf
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0007
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0007@DeviceDesc PCI standard PCI-to-PCI bridge
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0007@DisplayName PCI standard PCI-to-PCI bridge
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0007@Mfg (Standard system devices)
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0007@ProviderName Microsoft
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0007@DeviceInstanceIds PCI\VEN_8086&DEV_27D0&SUBSYS_00000000&REV_01\3&B1BFB68&0&E0?
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0007@ReinstallString C:\WINDOWS\system32\ReinstallBackups\0007\DriverFiles\machine.inf
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0008
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0008@DeviceDesc Standard Dual Channel PCI IDE Controller
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0008@DisplayName Standard Dual Channel PCI IDE Controller
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0008@Mfg (Standard IDE ATA/ATAPI controllers)
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0008@ProviderName Microsoft
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0008@DeviceInstanceIds PCI\VEN_8086&DEV_27DF&SUBSYS_280C103C&REV_01\3&B1BFB68&0&F9?
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0008@ReinstallString C:\WINDOWS\system32\ReinstallBackups\0008\DriverFiles\mshdc.inf
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0009
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0009@DeviceDesc PCI standard PCI-to-PCI bridge
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0009@DisplayName PCI standard PCI-to-PCI bridge
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0009@Mfg (Standard system devices)
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0009@ProviderName Microsoft
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0009@DeviceInstanceIds PCI\VEN_8086&DEV_27E0&SUBSYS_00000000&REV_01\3&B1BFB68&0&E4?
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0009@ReinstallString C:\WINDOWS\system32\ReinstallBackups\0009\DriverFiles\machine.inf
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0010
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0010@DeviceDesc PCI standard PCI-to-PCI bridge
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0010@DisplayName PCI standard PCI-to-PCI bridge
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0010@Mfg (Standard system devices)
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0010@ProviderName Microsoft
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0010@DeviceInstanceIds PCI\VEN_8086&DEV_27E2&SUBSYS_00000000&REV_01\3&B1BFB68&0&E5?
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0010@ReinstallString C:\WINDOWS\system32\ReinstallBackups\0010\DriverFiles\machine.inf
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0011
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0011@DeviceDesc Intel Processor
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0011@DisplayName Intel(R) Core(TM)2 CPU 6300 @ 1.86GHz
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0011@Mfg Intel
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0011@ProviderName Microsoft
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0011@DeviceInstanceIds ACPI\GENUINEINTEL_-_X86_FAMILY_6_MODEL_15\_0?
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0011@ReinstallString C:\WINDOWS\system32\ReinstallBackups\0011\DriverFiles\cpu.inf
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0012
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0012@DeviceDesc Intel Processor
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0012@DisplayName Intel(R) Core(TM)2 CPU 6300 @ 1.86GHz
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0012@Mfg Intel
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0012@ProviderName Microsoft
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0012@DeviceInstanceIds ACPI\GENUINEINTEL_-_X86_FAMILY_6_MODEL_15\_1?
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0012@ReinstallString C:\WINDOWS\system32\ReinstallBackups\0012\DriverFiles\cpu.inf
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0013
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0013@DeviceDesc Microsoft UAA Bus Driver for High Definition Audio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0013@DisplayName Microsoft UAA Bus Driver for High Definition Audio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0013@Mfg Microsoft
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0013@ProviderName Microsoft
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0013@DeviceInstanceIds PCI\VEN_8086&DEV_27D8&SUBSYS_280C103C&REV_01\3&B1BFB68&0&D8?
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0013@ReinstallString C:\WINDOWS\system32\ReinstallBackups\0013\DriverFiles\hdaudbus.inf
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0014@DeviceDesc Plug and Play Monitor
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0014@DisplayName Plug and Play Monitor
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0014@Mfg (Standard monitor types)
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0014@ProviderName Microsoft
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0014@DeviceInstanceIds DISPLAY\NEC65EE\5&10062F5F&0&11335577&01&00?
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0014@ReinstallString C:\WINDOWS\system32\ReinstallBackups\0014\DriverFiles\monitor.inf
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0015
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0015@DeviceDesc Broadcom NetXtreme Gigabit Ethernet
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0015@DisplayName Broadcom NetXtreme Gigabit Ethernet
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0015@Mfg Broadcom
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0015@ProviderName Broadcom
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0015@DeviceInstanceIds PCI\VEN_14E4&DEV_167B&SUBSYS_280C103C&REV_02\4&27454EAD&0&00E5?
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0015@ReinstallString C:\WINDOWS\system32\ReinstallBackups\0015\DriverFiles\b57win32.inf
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0016
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0016@DeviceDesc Realtek High Definition Audio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0016@DisplayName Realtek High Definition Audio
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0016@Mfg Realtek
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0016@ProviderName Realtek Semiconductor Corp.
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0016@DeviceInstanceIds HDAUDIO\FUNC_01&VEN_10EC&DEV_0262&SUBSYS_103C280C&REV_1001\4&4F15376&0&0001?
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\0016@ReinstallString C:\WINDOWS\system32\ReinstallBackups\0016\DriverFiles\hdahpbpc.inf
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached@{750FDF0E-2A26-11D1-A3EA-080036587F03} {000214E8-0000-0000-C000-000000000046} 0x401 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached@{1e9b04fb-f9e5-4718-997b-b8da88302a47} {000214e8-0000-0000-c000-000000000046} 0x401 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached@{1e9b04fb-f9e5-4718-997b-b8da88302a48} {000214e8-0000-0000-c000-000000000046} 0x401 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached@{1cdb2949-8f65-4355-8456-263e7c208a5d} {000214e6-0000-0000-c000-000000000046} 0x401 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached@{A4DF5659-0801-4A60-9607-1C48695EFDA9} {000214E6-0000-0000-C000-000000000046} 0x401 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}@PINDLL
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03@Identity Microsoft.Windows.Common-Controls,processorArchitecture="x86",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.2600.2982"
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03@Catalog 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03@ShortName X86_MI~1.298
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03@ShortCatalogName X81F46~1.CAT
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03@ShortManifestName X8FADC~1.MAN
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03@Codebase C:\WINDOWS\ServicePackFiles\i386/controls.man
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\Codebases
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\Codebases\U_KB923191
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\Codebases\U_KB923191@Prompt Windows XP KB923191 Source Files
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\Codebases\U_KB923191@URL C:\WINDOWS\ServicePackFiles\i386/controls.man
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\Files
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\Files\0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\Files\0@ comctl32.dll
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\Files\0@SHA1 0x9D 0xBF 0xB9 0xE1 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\References
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\References@U_KB923191
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ef752e68@Identity policy.6.0.Microsoft.Windows.Common-Controls,processorArchitecture="x86",publicKeyToken="6595b64144ccf1df",type="win32-policy",version="6.0.2600.2982"
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ef752e68@Catalog 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ef752e68@ShortName 602600~2.POL
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ef752e68@ShortCatalogName 602600~2.CAT
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ef752e68@ShortManifestName 602600~2.POL
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ef752e68@Codebase C:\WINDOWS\ServicePackFiles\i386/comctl.man
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ef752e68\Codebases
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ef752e68\Codebases\U_KB923191
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ef752e68\Codebases\U_KB923191@Prompt Windows XP KB923191 Source Files
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ef752e68\Codebases\U_KB923191@URL C:\WINDOWS\ServicePackFiles\i386/comctl.man
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ef752e68\Files
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ef752e68\References
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ef752e68\References@U_KB923191
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AccuTerm 2K2@DisplayName AccuTerm 2K2
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AccuTerm 2K2@UninstallString C:\PROGRA~1\atwin\\UNWISE.EXE C:\PROGRA~1\atwin\\INSTALL.LOG
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX@DisplayName Adobe Flash Player 10 ActiveX
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX@DisplayVersion 10.0.12.36
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX@Publisher Adobe Systems Incorporated
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX@URLInfoAbout http://www.adobe.com/go/getflashplayer
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX@VersionMajor 10
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX@VersionMinor 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX@HelpLink http://www.adobe.com/go/flashplayer_support/
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX@URLUpdateInfo http://www.adobe.com/go/flashplayer/
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX@DisplayIcon C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX@UninstallString C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX@RequiresIESysFile 4.70.0.1155
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX@NoModify 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX@NoRepair 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IDNMitigationAPIs@DisplayName Microsoft Internationalized Domain Names Mitigation APIs
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IDNMitigationAPIs@UninstallString "C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IDNMitigationAPIs@TSAware 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IDNMitigationAPIs@NoModify 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IDNMitigationAPIs@InstallDate 20070117
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IDNMitigationAPIs@Publisher Microsoft Corporation
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IDNMitigationAPIs@NoRepair 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IDNMitigationAPIs@HiddenByIE7Setup 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IDNMitigationAPIs@SystemComponent 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ie7@DisplayName Windows Internet Explorer 7
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ie7@UninstallString
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ie7@TSAware 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ie7@NoModify 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ie7@InstallDate 20070117
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ie7@Publisher Microsoft Corporation
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ie7@NoRepair 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ie7@HelpLink http://www.microsoft.com/ie
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ie7@URLInfoAbout http://www.microsoft.com/ie
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ie7@DisplayVersion 20061107.210142
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ie7@DisplayIcon C:\Program Files\Internet Explorer\iexplore.exe
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ie7@NoRemove 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB888111@NoRemove 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB888111@NoModify 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB888111@UninstallString
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB888111WXPSP2@DisplayName High Definition Audio Driver Package - KB888111
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB888111WXPSP2@UninstallString "C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB888111WXPSP2@TSAware 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB888111WXPSP2@NoModify 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB888111WXPSP2@Publisher Microsoft Corporation
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB888111WXPSP2@NoRepair 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB888111WXPSP2@HelpLink http://support.microsoft.com?kbid=KB888111
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB888111WXPSP2@URLInfoAbout http://support.microsoft.com
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB888111WXPSP2@DisplayVersion 20040219.000000
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB911564@DisplayName Security Update for Windows Media Player (KB911564)
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB911564@TSAware 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB911564@NoModify 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB911564@InstallDate 20070117
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB911564@Publisher Microsoft Corporation
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB911564@NoRepair 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB911564@HelpLink http://support.microsoft.com/?kbid=911564
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB911564@URLInfoAbout http://support.microsoft.com
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB911564@DisplayIcon "%ProgramFiles%\windows media player\wmplayer.exe"
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB911564@ParentKeyName OperatingSystem
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB911564@SystemComponent 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB917734_WMP9@DisplayName Security Update for Windows Media Player 9 (KB917734)
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB917734_WMP9@UninstallString "C:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\spuninst.exe"
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB917734_WMP9@TSAware 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB917734_WMP9@NoModify 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB917734_WMP9@InstallDate 20070117
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB917734_WMP9@Publisher Microsoft Corporation
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB917734_WMP9@NoRepair 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB917734_WMP9@HelpLink http://support.microsoft.com/?kbid=917734
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB917734_WMP9@URLInfoAbout http://support.microsoft.com
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB917734_WMP9@DisplayIcon "%ProgramFiles%\windows media player\wmplayer.exe"
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB917734_WMP9@ParentKeyName OperatingSystem
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB917734_WMP9@SystemComponent 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB923689@DisplayName Security Update for Windows XP (KB923689)
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB923689@TSAware 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB923689@NoModify 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB923689@InstallDate 20070117
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB923689@Publisher Microsoft Corporation
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB923689@NoRepair 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB923689@HelpLink http://support.microsoft.com?kbid=923689
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB923689@URLInfoAbout http://support.microsoft.com
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB923689@RegistryLocation HKLM\SOFTWARE\Microsoft\Updates\Windows XP\KB923689
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB923689@ReleaseType Security Update
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB923689@ParentKeyName OperatingSystem
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB923789@DisplayName Security Update for Windows XP (KB923789)
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB923789@ParentKeyName OperatingSystem
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB923789@ParentDisplayName Windows XP - Software Updates
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB923789@UninstallString C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB923789@HelpLink http://support.microsoft.com?kbid=923789
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB923789@URLInfoAbout http://support.microsoft.com
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB923789@Publisher Microsoft Corporation
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB923789@NoModify 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB923789@NoRepair 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB925398_WMP64@DisplayName Security Update for Windows Media Player 6.4 (KB925398)
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB925398_WMP64@TSAware 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB925398_WMP64@NoModify 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB925398_WMP64@InstallDate 20070117
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB925398_WMP64@Publisher Microsoft Corporation
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB925398_WMP64@NoRepair 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB925398_WMP64@HelpLink http://support.microsoft.com/?kbid=925398
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB925398_WMP64@URLInfoAbout http://support.microsoft.com
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB925398_WMP64@RegistryLocation HKLM\SOFTWARE\Microsoft\Updates\Windows Media Player 6.4\KB925398_WMP64
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB925398_WMP64@ReleaseType Security Update
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB925398_WMP64@DisplayIcon "%ProgramFiles%\windows media player\mplayer2.exe"
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB925398_WMP64@ParentKeyName OperatingSystem
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB929969@DisplayName Security Update for Windows Internet Explorer 7 (KB929969)
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB929969@UninstallString
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB929969@TSAware 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB929969@NoModify 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB929969@InstallDate 20070117
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB929969@Publisher Microsoft Corporation
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB929969@NoRepair 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB929969@HelpLink http://support.microsoft.com?kbid=929969
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB929969@URLInfoAbout http://support.microsoft.com
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB929969@DisplayVersion 20061222.120000
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB929969@ParentKeyName ie7Hotfix
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB929969@ParentDisplayName Windows Internet Explorer 7 - Software Updates
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB929969@ReleaseType Security Update
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB929969@RegistryLocation HKLM\SOFTWARE\Microsoft\Updates\Windows XP\SP0\KB929969
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB929969@HiddenByIE7Setup 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB929969@SystemComponent 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB929969@NoRemove 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB929969@NoRemoveInitialValue 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB929969@DisplayIcon C:\Program Files\internet explorer\iexplore.exe
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB929969@RemoveOnIE7Uninstall 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NLSDownlevelMapping@DisplayName Microsoft National Language Support Downlevel APIs
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NLSDownlevelMapping@UninstallString "C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NLSDownlevelMapping@TSAware 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NLSDownlevelMapping@NoModify 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NLSDownlevelMapping@InstallDate 20070117
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NLSDownlevelMapping@Publisher Microsoft Corporation
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NLSDownlevelMapping@NoRepair 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NLSDownlevelMapping@HiddenByIE7Setup 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NLSDownlevelMapping@SystemComponent 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NVIDIA Drivers@DisplayName NVIDIA Drivers
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NVIDIA Drivers@UninstDataVerified 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NVIDIA Drivers@UninstallString C:\WINDOWS\system32\nvudisp.exe UninstallGUI
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NVIDIA Drivers\SubComponents
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NVIDIA Drivers\SubComponents@nvdisp.nvu NVIDIA Display Driver
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShockwaveFlash@DisplayVersion 9.0.124.0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}@UninstallString RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}\setup.exe" -l0x9 -uninst -removeonly
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}@LogFile C:\Program Files\InstallShield Installation Information\{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}\setup.ilg
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}@InstallLocation C:\WINDOWS\
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}@InstallSource C:\SWSetup\HP Backup and Recovery Manager\
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}@ProductGuid {3F9F7336-6DF8-476F-ABF6-C70A17FAF619}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}@DisplayName HP Backup and Recovery Manager
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}@Publisher Hewlett-Packard Company
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}@URLInfoAbout http://www.hp.com
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}@HelpLink http://www.hp.com
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}@RegCompany Your Company Name
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}@RegOwner Your User Name
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}@NoModify 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}@NoRemove 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}@NoRepair 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}@InstallDate 20061111
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}@Language 9
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}@DisplayVersion 2.3j2
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}@Version 33751040
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}@MajorVersion 2
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}@MinorVersion 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}@LogMode 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}@DisplayIcon C:\WINDOWS\Creator\Recovery Wizard.exe,0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{808E5AB1-E98F-4362-AB10-B5B69CB2301C}@UninstallString RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{808E5AB1-E98F-4362-AB10-B5B69CB2301C}\SETUP.exe" -l0x9 -removeonly
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{808E5AB1-E98F-4362-AB10-B5B69CB2301C}@LogFile C:\Program Files\InstallShield Installation Information\{808E5AB1-E98F-4362-AB10-B5B69CB2301C}\setup.ilg
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{808E5AB1-E98F-4362-AB10-B5B69CB2301C}@InstallLocation C:\Program Files\Hewlett-Packard Company\HP Workstation User Guides
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{808E5AB1-E98F-4362-AB10-B5B69CB2301C}@InstallSource C:\compaq\WKS_Docs\
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{808E5AB1-E98F-4362-AB10-B5B69CB2301C}@ProductGuid {808E5AB1-E98F-4362-AB10-B5B69CB2301C}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{808E5AB1-E98F-4362-AB10-B5B69CB2301C}@DisplayName HP Workstation User Guides
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{808E5AB1-E98F-4362-AB10-B5B69CB2301C}@Publisher Hewlett-Packard Company
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{808E5AB1-E98F-4362-AB10-B5B69CB2301C}@URLInfoAbout http://www.hp.com
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{808E5AB1-E98F-4362-AB10-B5B69CB2301C}@RegCompany Your Company Name
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{808E5AB1-E98F-4362-AB10-B5B69CB2301C}@RegOwner Your User Name
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{808E5AB1-E98F-4362-AB10-B5B69CB2301C}@NoModify 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{808E5AB1-E98F-4362-AB10-B5B69CB2301C}@NoRemove 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{808E5AB1-E98F-4362-AB10-B5B69CB2301C}@NoRepair 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{808E5AB1-E98F-4362-AB10-B5B69CB2301C}@InstallDate 20061111
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{808E5AB1-E98F-4362-AB10-B5B69CB2301C}@Language 9
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{808E5AB1-E98F-4362-AB10-B5B69CB2301C}@DisplayVersion 1.03.0000
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{808E5AB1-E98F-4362-AB10-B5B69CB2301C}@Version 16973824
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{808E5AB1-E98F-4362-AB10-B5B69CB2301C}@MajorVersion 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{808E5AB1-E98F-4362-AB10-B5B69CB2301C}@MinorVersion 3
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{808E5AB1-E98F-4362-AB10-B5B69CB2301C}@LogMode 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}@UninstallString RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}\SETUP.exe" -l0x9 -removeonly
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}@LogFile C:\Program Files\InstallShield Installation Information\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}\setup.ilg
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}@InstallLocation C:\Program Files\HPQ\HP Help and Support
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}@InstallSource C:\Compaq\Help_Support\
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}@ProductGuid {A93C4E94-1005-489D-BEAA-B873C1AA6CFC}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}@DisplayName HP Help and Support
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}@Publisher HPQ
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}@URLInfoAbout http://www.hp.com
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}@RegCompany Your Company Name
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}@RegOwner Your User Name
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}@NoModify 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}@NoRemove 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}@NoRepair 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}@InstallDate 20061111
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}@Language 9
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}@DisplayVersion 4.2.0010
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}@Version 67239946
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}@MajorVersion 4
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}@MinorVersion 2
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}@LogMode 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}@DisplayName Realtek High Definition Audio Driver
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}@UninstallString RtlUpd.exe -r -m
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}@LogFile C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.ilg
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}@InstallLocation C:\Program Files\Realtek\InstallShield\
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}@ProductGuid {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}@InstallSource C:\Compaq\AUDIO\RealTek\
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}@Publisher Realtek Semiconductor Corp.
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}@RegCompany Your Company Name
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}@RegOwner Your User Name
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}@DisplayIcon C:\WINDOWS\Rtlupd.exe
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}@NoModify 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}@NoRemove 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}@NoRepair 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}@InstallDate 20061111
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}@Language 9
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}@DisplayVersion 5.10.0.5288
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}@Version 34537472
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}@MajorVersion 2
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}@MinorVersion 15
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}@LogMode 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}@BackUnString RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\SETUP.exe" -l0x9 -removeonly
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB888111WXPSP2@Installed 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB888111WXPSP2@Comments High Definition Audio Driver - KB888111
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB888111WXPSP2@Backup Dir
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB888111WXPSP2@Fix Description High Definition Audio Driver - KB888111
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB888111WXPSP2@Installed By
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB888111WXPSP2@Installed On
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB888111WXPSP2@Service Pack 10
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB888111WXPSP2@Valid 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB888111WXPSP2\File 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB888111WXPSP2\File 1@Flags
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB888111WXPSP2\File 1@New File
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB888111WXPSP2\File 1@New Link Date
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB888111WXPSP2\File 1@Old Link Date
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB911564@Installed 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB911564@Comments Security Update for Windows Media Player (KB911564)
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB917734_WMP9@Installed 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB917734_WMP9@Comments Security Update for Windows Media Player 9 (KB917734)
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB923689@Installed 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB923689@Comments Security Update for Windows XP (KB923689)
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB925398_WMP64@Installed 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB925398_WMP64@Comments Security Update for Windows Media Player 6.4 (KB925398)
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB929969@Installed 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB929969@Comments Security Update for Windows Internet Explorer 7 (KB929969)
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB929969@Backup Dir
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB929969@Fix Description Security Update for Windows Internet Explorer 7 (KB929969)
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB929969@Installed By
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB929969@Installed On
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB929969@Service Pack 20
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB929969@Valid 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB929969@IE Service Pack 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB929969@RemoveOnIE7Uninstall 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB929969\File 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB929969\File 1@Flags
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB929969\File 1@New File
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB929969\File 1@New Link Date
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB929969\File 1@Old Link Date
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\OpenGLDrivers\RIVATNT@Version 2
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\OpenGLDrivers\RIVATNT@DriverVersion 65536
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\OpenGLDrivers\RIVATNT@Dll nvoglnt
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\OpenGLDrivers\RIVATNT@Flags 1

---- EOF - GMER 1.0.14 ----
fhqwhgads
Active Member
 
Posts: 9
Joined: December 31st, 2008, 3:11 pm

Re: Wrong icons on my desktop and start menu

Unread postby Rodav » January 10th, 2009, 5:55 pm

Hi,

Are you sure the error messages you are seeing are "Windows encountered a virus." and not "Windows encountered a problem." or something similar.

There is still nothing obvious jumping out, often when a computer is infected with malware like yours was, there can be some damage leftover even after all the malware has been removed. Settings, profiles...etc. can get messed up along the way and it's almost impossible to hunt down all the errors as there are just too many variables. It could be days or weeks even before we could fix everything to how it should be and even then it may never seem the same as it was before you got infected.

Sometimes the easiest option is to reformat and perform a clean install of the operating system. If you were to save your data, reformat and reinstall your OS then restore your data and applications, your machine could up and running again in a few hours like a new computer with intact settings.

If you want to continue please do the following:

Run Eset NOD32 Online AntiVirus
http://www.eset.eu/online-scanner
Note: You will need to use Internet Explorer for this scan.
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your current Antivirus software. You can usually do this with its Notfication Tray icon near the clock.
  • Click Start
  • Make sure that the option "Remove found threats" is Un-checked, and the option "Scan unwanted applications" is checked
  • Click Scan
  • Wait for the scan to finish
  • Re-enable your Anvirisus software.
  • A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. Please include this on your post along with a new OTScanIt log.
User avatar
Rodav
MRU Master Emeritus
 
Posts: 1480
Joined: April 19th, 2007, 6:44 am
Location: Here, there and yonder.
Advertisement
Register to Remove

Next

  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 12 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware