• Announcements

    • LS.Andy

      Support for other products than adaware, ad block, web protection and Web Companion   05/05/2017

      Support for the following products is handled by the Lavasoft support team: Lavasoft Tuneup Kit Lavasoft PC Optimizer Lavasoft Driver Updater Lavasoft Registry Tuner Lavasoft Privacy Toolbox Lavasoft File Shredder Lavasoft Digital Lock

      For help with these products, contact the support team here: http://www.lavasoft.com/support/supportcenter/
       
Sign in to follow this  
Followers 0
leila

Help!

9 posts in this topic

hi yesterday i managed to rid my laptop of the torpig and possibly vundo trojans using xoftspy se but i still have annoying random popups which popup blockers dont block.

all my virus scans come up with nothing.

heres my hijack this log

 

thanks everyone in advance :mellow:

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 12:34:37, on 25/07/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe

C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe

C:\PROGRA~1\Grisoft\AVG7\avgemc.exe

C:\WINDOWS\system32\cisvc.exe

C:\Program Files\Kontiki\KService.exe

C:\WINDOWS\system32\tcpsvcs.exe

C:\WINDOWS\System32\snmp.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\MSN Messenger\msnmsgr.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe

C:\Program Files\MSN Messenger\usnsvc.exe

C:\WINDOWS\system32\cidaemon.exe

C:\Documents and Settings\NEW USER\My Documents\HiJackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.myspace.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.myspace.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Orange UK

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;<local>

O2 - BHO: (no name) - {04364200-F86B-4B42-ABCB-4EAAB6EDFF1E} - C:\WINDOWS\system32\mljklmj.dll (file missing)

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll

O2 - BHO: (no name) - {B1F2C4F1-F036-4823-A4F6-693D9C7372AF} - C:\WINDOWS\system32\efedb.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll

O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll

O4 - HKLM\..\Run: [XoftSpySE] C:\Program Files\XoftSpySE\xoftspy.exe -s

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html

O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612...ex/qtplugin.cab

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll

O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.co.uk/SnapfishUKActivia.cab

O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB...l_v1-0-3-48.cab

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by122w.bay122.mail.live.com/mail/re...es/MsnPUpld.cab

O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1164066532038

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1145451077770

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {A8482EAF-A1F3-4934-AE3F-56EB195A50BF} (DeskUpdate - Activex Control) - http://support.fujitsu-siemens.de/DeskUpda...api/activex.cab

O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.telewest.co.uk/motive/files/MotivePreQual.cab

O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://eu.download.games.yahoo.com/zylom/a...zylomloader.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://213.129.66.245/activex/AMC.cab

O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave.com/content/bejeweled...ploader_v10.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab

O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab

O20 - Winlogon Notify: efedb - C:\WINDOWS\system32\efedb.dll

O20 - Winlogon Notify: mljklmj - mljklmj.dll (file missing)

O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe

O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: KService - Unknown owner - C:\Program Files\Kontiki\KService.exe

 

--

End of file - 8728 bytes

Edited by leila

Share this post


Link to post
Share on other sites

Hi

 

1. Download this file -

combofix.exe

2. Double click combofix.exe & follow the prompts.

3. When finished, it shall produce a log for you. Post that log in your

next reply with a fresh hjt log.

 

Note:

Do not mouseclick combofix's window whilst it's running. That may cause

it to stall

Share this post


Link to post
Share on other sites

okay the vundo and torpig torjans are back i had to attempt to remove them so i could post on here as they crash my internet.

 

well heres the first log

 

"NEW USER" - 2007-07-25 16:22:10 - ComboFix 07-07-23.6 - Service Pack 2 NTFS

 

 

(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))

 

 

C:\WINDOWS\system32\efedb.dll

C:\WINDOWS\system32\bdefe.bak1

C:\WINDOWS\system32\bdefe.ini

C:\WINDOWS\system32\bdefe.ini2

C:\WINDOWS\system32\bdefe.tmp

C:\WINDOWS\system32\bdefe.bak1

C:\WINDOWS\system32\bdefe.ini

C:\WINDOWS\system32\bdefe.ini2

C:\WINDOWS\system32\bdefe.tmp

C:\WINDOWS\system32\bdefe.bak1

C:\WINDOWS\system32\bdefe.ini

C:\WINDOWS\system32\bdefe.ini2

C:\WINDOWS\system32\bdefe.tmp

 

 

* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *

 

 

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

 

 

C:\WINDOWS\system32\drivers\core.cache.dsk

C:\WINDOWS\system32\drivers\core.sys

 

 

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

 

 

-------\LEGACY_CORE

-------\LEGACY_IPRIP

-------\LEGACY_NTMLSVC

-------\asc3550u

-------\core

-------\Iprip

 

 

((((((((((((((((((((((((( Files Created from 2007-06-25 to 2007-07-25 )))))))))))))))))))))))))))))))

 

 

2007-07-25 16:21 51,200 --a------ C:\WINDOWS\nircmd.exe

2007-07-25 15:25 <DIR> d-------- C:\Program Files\Lavasoft

2007-07-25 15:25 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft

2007-07-25 15:22 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard

2007-07-25 13:25 <DIR> d-------- C:\DOCUME~1\NEWUSE~1\APPLIC~1\IDM

2007-07-25 13:24 <DIR> d-------- C:\Program Files\Internet Download Manager

2007-07-24 23:01 <DIR> d-------- C:\Program Files\XoftSpySE

2007-07-24 22:59 <DIR> d-------- C:\Program Files\Alwil Software

2007-07-24 15:01 192,622 --a------ C:\WINDOWS\system32\owinkodt.exe

2007-07-20 03:44 0 --a------ C:\WINDOWS\nsreg.dat

2007-07-15 03:02 <DIR> d-------- C:\DOCUME~1\NEWUSE~1\APPLIC~1\MySpace

2007-07-15 01:19 <DIR> d-------- C:\Program Files\Apple Software Update

2007-07-15 01:19 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple

2007-07-02 01:31 <DIR> d-------- C:\Program Files\eBay

2007-07-02 01:31 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\WholeSecurity

2007-06-29 13:00 <DIR> d-------- C:\Program Files\Axis Communications

2007-06-27 02:16 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom

2007-06-26 01:58 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\PopCap

2007-06-26 01:31 <DIR> d-------- C:\DOCUME~1\NEWUSE~1\APPLIC~1\PlayFirst

2007-06-26 01:31 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia

2007-06-26 01:31 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst

 

 

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

 

2007-07-25 15:32:58 -------- d-----w C:\DOCUME~1\NEWUSE~1\APPLIC~1\DMCache

2007-07-25 15:32:56 24,176 ----a-w C:\WINDOWS\system32\dxdllreg.exe

2007-07-25 14:23:45 -------- d-----w C:\DOCUME~1\NEWUSE~1\APPLIC~1\Lavasoft

2007-07-25 12:29:25 -------- d-----w C:\DOCUME~1\NEWUSE~1\APPLIC~1\Azureus

2007-07-25 00:15:21 -------- d-----w C:\Program Files\DivX

2007-07-15 00:23:26 -------- d-----w C:\Program Files\QuickTime

2007-07-02 00:31:20 -------- d--h--w C:\Program Files\InstallShield Installation Information

2007-06-24 19:12:21 -------- d-----w C:\Program Files\Azureus

2007-06-23 17:49:56 -------- d-----w C:\Program Files\Google

2007-06-23 17:46:46 -------- d-----w C:\DOCUME~1\NEWUSE~1\APPLIC~1\Google

2007-06-19 13:22:09 202,424 ----a-w C:\WINDOWS\system32\idmmbc.dll

2007-06-14 19:02:21 -------- d-----w C:\Program Files\Yahoo!

2007-06-06 00:29:36 -------- d-----w C:\Program Files\Illustrate

2007-06-06 00:29:21 4,112,760 ----a-w C:\WINDOWS\system32\SpoonUninstall.exe

2007-06-04 14:18:48 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys

2007-06-04 14:17:02 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys

2007-06-04 14:14:56 6,272 ----a-w C:\WINDOWS\system32\drivers\AWRTPD.sys

2007-05-31 16:13:08 -------- d-----w C:\DOCUME~1\NEWUSE~1\APPLIC~1\WinRAR

2007-05-31 16:12:38 -------- d-----w C:\Program Files\Windows Media Bonus Pack for Windows XP

2007-05-31 14:56:59 56 --sh--r C:\WINDOWS\system32\C7284D9832.sys

2007-05-31 14:56:59 12,208 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys

2007-05-31 06:45:07 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe

2007-05-31 06:44:55 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll

2007-05-31 06:44:54 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll

2007-05-31 06:44:54 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll

2007-05-31 06:44:54 740,442 ----a-w C:\WINDOWS\system32\DivX.dll

2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll

2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll

2006-06-09 22:57:45 278,528 -c--a-w C:\Program Files\Common Files\FDEUnInstaller.exe

 

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

 

 

*Note* empty entries & legit default entries are not shown

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"XoftSpySE"="-C:\Program Files\XoftSpySE\xoftspy.exe" []

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="-C:\Program Files\MSN Messenger\msnmsgr.exe" []

"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00]

"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [2007-07-25 13:35]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]

"DisableTaskMgr"=1 (0x1)

"DisableRegistryTools"=1 (0x1)

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"NoClose"=1 (0x1)

"NoRun"=1 (0x1)

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljklmj]

mljklmj.dll

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]

path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk

backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ZDWLan Utility.lnk]

path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ZDWLan Utility.lnk

backup=C:\WINDOWS\pss\ZDWLan Utility.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NEW USER^Start Menu^Programs^Startup^TA_Start.lnk]

path=C:\Documents and Settings\NEW USER\Start Menu\Programs\Startup\TA_Start.lnk

backup=C:\WINDOWS\pss\TA_Start.lnkStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NEW USER^Start Menu^Programs^Startup^Yahoo! Widget Engine.lnk]

path=C:\Documents and Settings\NEW USER\Start Menu\Programs\Startup\Yahoo! Widget Engine.lnk

backup=C:\WINDOWS\pss\Yahoo! Widget Engine.lnkStartup

 

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4oD]

"C:\Program Files\Kontiki\KHost.exe" -all

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]

AGRSMMSG.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]

C:\Program Files\Apoint2K\Apoint.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]

C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]

"C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]

rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]

C:\WINDOWS\system32\ctfmon.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eBayToolbar]

C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]

"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kdx]

C:\Program Files\Kontiki\KHost.exe -all

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]

%systemroot%\system32\dumprep 0 -k

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MemoryManager]

rundll32.exe "C:\WINDOWS\system32\kifmdswc.dll",forkonce

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]

"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

C:\WINDOWS\system32\NeroCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ProgramPath]

C:\Program Files\Power Manager\PM.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

"C:\Program Files\QuickTime\qttask.exe" -atboottime

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]

"C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]

SOUNDMAN.EXE

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]

"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]

VTTimer.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTrayp]

VTtrayp.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]

"C:\Program Files\Windows Defender\MSASCui.exe" -hide

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{43-33-3E-E1-ZN}]

C:\windows\system32\njdsregs.exe OLI001

 

R0 uagp35;Microsoft AGPv3.5 Filter;C:\WINDOWS\system32\DRIVERS\uagp35.sys

R1 Tcpip6;Microsoft IPv6 Protocol Driver;C:\WINDOWS\system32\DRIVERS\tcpip6.sys

R2 6to4;IPv6 Helper Service;C:\WINDOWS\system32\svchost.exe -k netsvcs

R2 BthServ;Bluetooth Support Service;C:\WINDOWS\system32\svchost.exe -k bthsvcs

R2 SimpTcp;Simple TCP/IP Services;C:\WINDOWS\system32\tcpsvcs.exe

R2 SNMP;SNMP Service;C:\WINDOWS\System32\snmp.exe

R2 STEC3;STEC3;\??\C:\WINDOWS\system32\STEC3.sys

R3 ApfiltrService;Alps Pointing-device Filter Driver;C:\WINDOWS\system32\DRIVERS\Apfiltr.sys

R3 EKBfltr;ENE Keyboard Controller;C:\WINDOWS\system32\DRIVERS\EKBfltr.sys

R3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5b.sys

R3 tunmp;Microsoft Tun Miniport Adapter Driver;C:\WINDOWS\system32\DRIVERS\tunmp.sys

R3 viagfx;viagfx;C:\WINDOWS\system32\DRIVERS\vtmini.sys

S2 Fax;Fax;C:\WINDOWS\system32\fxssvc.exe

S3 AdWatchDrv;AW Realtime Driver;\??\C:\WINDOWS\system32\drivers\AWRTPD.sys

S3 BRGSp50;BRGSp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\BRGSp50.sys

S3 BthEnum;Bluetooth Request Block Driver;C:\WINDOWS\system32\DRIVERS\BthEnum.sys

S3 BTHMODEM;Bluetooth Serial Communications Driver;C:\WINDOWS\system32\DRIVERS\bthmodem.sys

S3 BthPan;Bluetooth Device (Personal Area Network);C:\WINDOWS\system32\DRIVERS\bthpan.sys

S3 BTHPORT;Bluetooth Port Driver;C:\WINDOWS\system32\Drivers\BTHport.sys

S3 BTHUSB;Bluetooth Radio USB Driver;C:\WINDOWS\system32\Drivers\BTHUSB.sys

S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\fetnd5.sys

S3 HidBth;Microsoft Bluetooth HID Miniport;C:\WINDOWS\system32\DRIVERS\hidbth.sys

S3 k600bus;Sony Ericsson 600i driver (WDM);C:\WINDOWS\system32\DRIVERS\k600bus.sys

S3 LPDSVC;TCP/IP Print Server;C:\WINDOWS\system32\tcpsvcs.exe

S3 ovt519;EyeToy;C:\WINDOWS\system32\Drivers\ov519vid.sys

S3 p2pgasvc;Peer Networking Group Authentication;C:\WINDOWS\system32\svchost.exe -k p2psvc

S3 p2pimsvc;Peer Networking Identity Manager;C:\WINDOWS\system32\svchost.exe -k p2psvc

S3 p2psvc;Peer Networking;C:\WINDOWS\system32\svchost.exe -k p2psvc

S3 PNRPSvc;Peer Name Resolution Protocol;C:\WINDOWS\system32\svchost.exe -k p2psvc

S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI);C:\WINDOWS\system32\DRIVERS\rfcomm.sys

S3 SNMPTRAP;SNMP Trap Service;C:\WINDOWS\System32\snmptrap.exe

S3 umtsbus;WCDMA Handset USB Composite Device driver (WDM);C:\WINDOWS\system32\DRIVERS\umtsbus.sys

S3 umtsmdfl;WCDMA Handset Filter;C:\WINDOWS\system32\DRIVERS\umtsmdfl.sys

S3 umtsmdm;WCDMA Handset Drivers;C:\WINDOWS\system32\DRIVERS\umtsmdm.sys

S3 umtsserd;WCDMA Handset Diagnostic Serial Port (WDM);C:\WINDOWS\system32\DRIVERS\umtsserd.sys

S3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys

S3 ZDPSp50;ZDPSp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\ZDPSp50.sys

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

p2psvc p2psvc p2pimsvc p2pgasvc PNRPSvc

bthsvcs BthServ

 

 

Contents of the 'Scheduled Tasks' folder

2007-07-16 09:18:14 C:\WINDOWS\tasks\AppleSoftwareUpdate.job

2007-07-25 15:32:29 C:\WINDOWS\tasks\XoftSpySE 2.job

2007-07-25 00:17:21 C:\WINDOWS\tasks\XoftSpySE.job

 

**************************************************************************

 

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2007-07-25 16:32:49

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

C:\WINDOWS\system32\protector.exe [3416] 0x852F6020

 

 

scanning hidden registry entries ...

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]

"TracesProcessed"=dword:00000208

"TracesSuccessful"=dword:0000002c

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{115A6D1B-9CB4-B6CD-E452-6669B9837ED9}]

"bbbgohccjjdnbffbpgpagnekhidhlnbghaan"=hex:6a,61,6d,6d,65,68,61,66,63,61,66,6d,64,69,70,6a,69,66,6d,68,00,..

"abhfejdbodajgmmbinflffjegjhpgkcjac"=hex:6a,61,6d,6d,65,68,61,66,63,61,66,6d,64,69,70,6a,69,66,6d,68,00,..

"iabgohccjjdnbffbpg"=hex:61,61,00,01

"hahfejdbodajgmmb"=hex:61,61,00,01

"iangoionmihmpmbjgk"=hex:61,61,00,01

 

scanning hidden files ...

 

**************************************************************************

 

Completion time: 2007-07-25 16:36:57 - machine was rebooted

C:\ComboFix-quarantined-files.txt ... 2007-07-25 16:34

 

--- E O F ---

 

 

 

and heres a new hijack one

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 16:59:58, on 25/07/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

C:\WINDOWS\system32\tcpsvcs.exe

C:\WINDOWS\System32\snmp.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Internet Download Manager\IEMonitor.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\notepad.exe

C:\WINDOWS\system32\rundll32.exe

C:\WINDOWS\system32\taskmgr.exe

C:\Program Files\XoftSpySE\XoftSpy.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32Info.exe

C:\Documents and Settings\NEW USER\My Documents\HiJackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.myspace.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.myspace.com

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;<local>

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll

O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll

O4 - HKLM\..\Run: [XoftSpySE] -C:\Program Files\XoftSpySE\xoftspy.exe -s

O4 - HKLM\..\Run: [MemoryManager] rundll32.exe "C:\WINDOWS\system32\lppmldpi.dll",forkonce

O4 - HKCU\..\Run: [msnmsgr] -"C:\Program Files\MSN Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [iDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: TA_Start.lnk = C:\Documents and Settings\NEW USER\Local Settings\Temp\bundle.exe

O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html

O8 - Extra context menu item: Download All Links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm

O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm

O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612...ex/qtplugin.cab

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll

O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.co.uk/SnapfishUKActivia.cab

O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB...l_v1-0-3-48.cab

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by122w.bay122.mail.live.com/mail/re...es/MsnPUpld.cab

O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1164066532038

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1145451077770

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {A8482EAF-A1F3-4934-AE3F-56EB195A50BF} (DeskUpdate - Activex Control) - http://support.fujitsu-siemens.de/DeskUpda...api/activex.cab

O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.telewest.co.uk/motive/files/MotivePreQual.cab

O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://eu.download.games.yahoo.com/zylom/a...zylomloader.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://213.129.66.245/activex/AMC.cab

O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave.com/content/bejeweled...ploader_v10.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab

O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab

O20 - AppInit_DLLs: ??\windows\system32\ldcore.dll c:\windows\system32\ldcore.dll

O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

O23 - Service: Adobe LM Service - Unknown owner - -"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe" (file missing)

O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - Unknown owner - -C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe (file missing)

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - Unknown owner - -C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe (file missing)

O23 - Service: AVG E-mail Scanner (AVGEMS) - Unknown owner - -C:\PROGRA~1\Grisoft\AVG7\avgemc.exe (file missing)

O23 - Service: Google Updater Service (gusvc) - Unknown owner - -"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" (file missing)

O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - -"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe" (file missing)

O23 - Service: KService - Unknown owner - -"C:\Program Files\Kontiki\KService.exe" (file missing)

O23 - Service: Messenger Sharing Folders USN Journal Reader service (usnjsvc) - Unknown owner - -"C:\Program Files\MSN Messenger\usnsvc.exe" (file missing)

O23 - Service: Windows Media Player Network Sharing Service (WMPNetworkSvc) - Unknown owner - -C:\Program Files\Windows Media Player\WMPNetwk.exe (file missing)

 

--

End of file - 8787 bytes

 

i hope someone can help me this is driving me mad!

 

thanks again

Share this post


Link to post
Share on other sites

Start hjt, click do a system scan only, check:

O4 - HKLM\..\Run: [MemoryManager] rundll32.exe "C:\WINDOWS\system32\lppmldpi.dll",forkonce

O4 - Startup: TA_Start.lnk = C:\Documents and Settings\NEW USER\Local Settings\Temp\bundle.exe

O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://eu.download.games.yahoo.com/zylom/a...zylomloader.cab

O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave.com/content/bejeweled...ploader_v10.cab

O20 - AppInit_DLLs: ??\windows\system32\ldcore.dll c:\windows\system32\ldcore.dll

Close browsers and other windows. Click fix checked.

 

 

Show hidden files

-----------------

* Click Start.

* Open My Computer.

* Select the Tools menu and click Folder Options.

* Select the View Tab.

* Under the Hidden files and folders heading select Show hidden files and folders.

* Uncheck the Hide protected operating system files (recommended) option.

* Click Yes to confirm.

* Click OK.

 

Delete following files (if found):

C:\WINDOWS\system32\lppmldpi.dll

C:\Documents and Settings\NEW USER\Local Settings\Temp\bundle.exe

c:\windows\system32\ldcore.dll

C:\WINDOWS\system32\protector.exe

 

 

Open notepad and copy/paste the text in the quotebox below into it:

 

File::
C:\WINDOWS\system32\owinkodt.exe
C:\WINDOWS\system32\SpoonUninstall.exe

Folder::
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom
C:\DOCUME~1\ALLUSE~1\APPLIC~1\PopCap
C:\DOCUME~1\NEWUSE~1\APPLIC~1\PlayFirst
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
C:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst

DirLook:: 
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WholeSecurity

 

 

Save this as

CFScript

 

 

CFScript.gif

 

Refering to the picture above, drag CFScript into ComboFix.exe

Then post the resultant log and a fresh hjt log.

Share this post


Link to post
Share on other sites

okay thanks ive done that

except i could only find one of the files and it said it couldnt be deleted. anyway heres my new combofix

 

thanks again :)

 

"NEW USER" - 2007-07-25 22:49:00 - ComboFix 07-07-23.6 - Service Pack 2 NTFS

Command switches used :: C:\Documents and Settings\NEW USER\Desktop\CFScript.txt

 

 

(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))

 

 

C:\WINDOWS\system32\sfyntrmf.dll

C:\WINDOWS\system32\kvntqhdh.dll

C:\WINDOWS\system32\winqeo32.dll

C:\WINDOWS\system32\nqrqr.bak1

C:\WINDOWS\system32\nqrqr.ini

C:\WINDOWS\system32\nqrqr.bak1

C:\WINDOWS\system32\nqrqr.ini

C:\WINDOWS\system32\rqrqn.dll

C:\WINDOWS\system32\vtutspp.dll

 

 

* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *

 

 

 

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

 

 

C:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst

C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia

C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia\data\{1AC5392E-F1BD-7AA9-725E-08450701B17F}

C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia\data\{2EAAFC8D-73F6-0213-8F01-B812AA86AEF4}

C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia\data\{B50687DE-FE73-8FA0-15D6-EE84CDC609D8}

C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia\data\{BEF397BA-CC6D-DD73-1239-C81C02147B17}

C:\DOCUME~1\NEWUSE~1\APPLIC~1.\.rdr.ini

C:\DOCUME~1\NEWUSE~1\APPLIC~1\PlayFirst

C:\DOCUME~1\NEWUSE~1\APPLIC~1\PlayFirst\chocolatier\hiscore.dat

C:\DOCUME~1\NEWUSE~1\APPLIC~1\PlayFirst\chocolatier\logfile.txt

C:\DOCUME~1\NEWUSE~1\APPLIC~1\PlayFirst\chocolatier\prefs.dat

C:\Program Files\Common Files\ymbols~1

C:\Program Files\Common Files\ymbols~1\dllhost.exe

C:\Program Files\TTC.dll

C:\WINDOWS\system32\b06FdUe

C:\WINDOWS\system32\b06FdUe\b06FdUe1083.exe

C:\WINDOWS\system32\config\systemprofile\application data\.rdr.ini

C:\WINDOWS\system32\dnsersnd.dll

C:\WINDOWS\system32\drivers\core.cache.dsk

C:\WINDOWS\system32\drivers\core.sys

C:\WINDOWS\system32\krvrjiaq.exe

C:\WINDOWS\system32\ldcore.dll

C:\WINDOWS\system32\owinkodt.exe

C:\WINDOWS\system32\SpoonUninstall.exe

C:\WINDOWS\system32\U0

C:\WINDOWS\system32\U1

C:\WINDOWS\system32\U2

C:\WINDOWS\system32\win

 

 

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

 

 

-------\LEGACY_NTIO256

-------\LEGACY_NTMLSVC

-------\asc3550u

 

 

((((((((((((((((((((((((( Files Created from 2007-06-25 to 2007-07-25 )))))))))))))))))))))))))))))))

 

 

2007-07-25 22:27 93,696 --a------ C:\WINDOWS\system32\drvlot.dll

2007-07-25 22:27 31,254 --a------ C:\WINDOWS\system32\yayvusp.dll

2007-07-25 16:49 70,312 --a------ C:\Program Files\codec_setup.exe

2007-07-25 16:45 125,972 --a------ C:\WINDOWS\system32\lppmldpi.dll

2007-07-25 16:37 31,254 --a------ C:\WINDOWS\system32\vtuvutt.dll

2007-07-25 16:37 <DIR> d-------- C:\Tempc2

2007-07-25 16:36 <DIR> d-------- C:\Temp\brr

2007-07-25 16:36 <DIR> d-------- C:\Temp

2007-07-25 16:35 6,689 --a------ C:\WINDOWS\system32\ldcore.dll

2007-07-25 16:21 51,200 --a------ C:\WINDOWS\nircmd.exe

2007-07-25 15:25 <DIR> d-------- C:\Program Files\Lavasoft

2007-07-25 15:25 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft

2007-07-25 15:22 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard

2007-07-25 13:25 <DIR> d-------- C:\DOCUME~1\NEWUSE~1\APPLIC~1\IDM

2007-07-25 13:24 <DIR> d-------- C:\Program Files\Internet Download Manager

2007-07-24 23:01 <DIR> d-------- C:\Program Files\XoftSpySE

2007-07-24 22:59 <DIR> d-------- C:\Program Files\Alwil Software

2007-07-20 03:44 0 --a------ C:\WINDOWS\nsreg.dat

2007-07-15 03:02 <DIR> d-------- C:\DOCUME~1\NEWUSE~1\APPLIC~1\MySpace

2007-07-15 01:19 <DIR> d-------- C:\Program Files\Apple Software Update

2007-07-15 01:19 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple

2007-07-02 01:31 <DIR> d-------- C:\Program Files\eBay

2007-07-02 01:31 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\WholeSecurity

2007-06-29 13:00 <DIR> d-------- C:\Program Files\Axis Communications

 

 

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

 

2007-07-25 21:24:30 -------- d-----w C:\DOCUME~1\NEWUSE~1\APPLIC~1\DMCache

2007-07-25 14:23:45 -------- d-----w C:\DOCUME~1\NEWUSE~1\APPLIC~1\Lavasoft

2007-07-25 12:29:25 -------- d-----w C:\DOCUME~1\NEWUSE~1\APPLIC~1\Azureus

2007-07-25 00:15:21 -------- d-----w C:\Program Files\DivX

2007-07-15 00:23:26 -------- d-----w C:\Program Files\QuickTime

2007-07-02 00:31:20 -------- d--h--w C:\Program Files\InstallShield Installation Information

2007-06-24 19:12:21 -------- d-----w C:\Program Files\Azureus

2007-06-23 17:49:56 -------- d-----w C:\Program Files\Google

2007-06-23 17:46:46 -------- d-----w C:\DOCUME~1\NEWUSE~1\APPLIC~1\Google

2007-06-19 13:22:09 202,424 ----a-w C:\WINDOWS\system32\idmmbc.dll

2007-06-14 19:02:21 -------- d-----w C:\Program Files\Yahoo!

2007-06-14 09:22:13 2,231 ----a-w C:\Program Files\folder.js

2007-06-06 00:29:36 -------- d-----w C:\Program Files\Illustrate

2007-06-04 14:18:48 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys

2007-06-04 14:17:02 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys

2007-06-04 14:14:56 6,272 ----a-w C:\WINDOWS\system32\drivers\AWRTPD.sys

2007-05-31 16:13:08 -------- d-----w C:\DOCUME~1\NEWUSE~1\APPLIC~1\WinRAR

2007-05-31 16:12:38 -------- d-----w C:\Program Files\Windows Media Bonus Pack for Windows XP

2007-05-31 14:56:59 56 --sh--r C:\WINDOWS\system32\C7284D9832.sys

2007-05-31 14:56:59 12,208 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys

2007-05-31 06:45:07 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe

2007-05-31 06:44:55 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll

2007-05-31 06:44:54 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll

2007-05-31 06:44:54 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll

2007-05-31 06:44:54 740,442 ----a-w C:\WINDOWS\system32\DivX.dll

2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll

2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll

2006-06-09 22:57:45 278,528 -c--a-w C:\Program Files\Common Files\FDEUnInstaller.exe

 

 

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))

 

 

---- Directory of C:\DOCUME~1\ALLUSE~1\APPLIC~1\WholeSecurity ----

 

2007-07-25 22:26 7374 --a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\WholeSecurity\wcid0.log

2007-07-25 22:20 154690 --a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\WholeSecurity\wsa18.zip

 

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

 

 

*Note* empty entries & legit default entries are not shown

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"XoftSpySE"="-C:\Program Files\XoftSpySE\xoftspy.exe" []

"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="-C:\Program Files\MSN Messenger\msnmsgr.exe" []

"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00]

"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [2007-07-25 13:35]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"NoClose"=1 (0x1)

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljklmj]

mljklmj.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winrzf32]

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]

path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk

backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ZDWLan Utility.lnk]

path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ZDWLan Utility.lnk

backup=C:\WINDOWS\pss\ZDWLan Utility.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NEW USER^Start Menu^Programs^Startup^TA_Start.lnk]

path=C:\Documents and Settings\NEW USER\Start Menu\Programs\Startup\TA_Start.lnk

backup=C:\WINDOWS\pss\TA_Start.lnkStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^NEW USER^Start Menu^Programs^Startup^Yahoo! Widget Engine.lnk]

path=C:\Documents and Settings\NEW USER\Start Menu\Programs\Startup\Yahoo! Widget Engine.lnk

backup=C:\WINDOWS\pss\Yahoo! Widget Engine.lnkStartup

 

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4oD]

"C:\Program Files\Kontiki\KHost.exe" -all

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]

AGRSMMSG.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]

C:\Program Files\Apoint2K\Apoint.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]

C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]

"C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]

rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]

C:\WINDOWS\system32\ctfmon.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eBayToolbar]

C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]

"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kdx]

C:\Program Files\Kontiki\KHost.exe -all

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]

%systemroot%\system32\dumprep 0 -k

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MemoryManager]

rundll32.exe "C:\WINDOWS\system32\kifmdswc.dll",forkonce

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]

"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

C:\WINDOWS\system32\NeroCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ProgramPath]

C:\Program Files\Power Manager\PM.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

"C:\Program Files\QuickTime\qttask.exe" -atboottime

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]

"C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]

SOUNDMAN.EXE

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]

"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]

VTTimer.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTrayp]

VTtrayp.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]

"C:\Program Files\Windows Defender\MSASCui.exe" -hide

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{43-33-3E-E1-ZN}]

C:\windows\system32\njdsregs.exe OLI001

 

R0 uagp35;Microsoft AGPv3.5 Filter;C:\WINDOWS\system32\DRIVERS\uagp35.sys

R1 Tcpip6;Microsoft IPv6 Protocol Driver;C:\WINDOWS\system32\DRIVERS\tcpip6.sys

R2 6to4;IPv6 Helper Service;C:\WINDOWS\system32\svchost.exe -k netsvcs

R2 BthServ;Bluetooth Support Service;C:\WINDOWS\system32\svchost.exe -k bthsvcs

R2 SimpTcp;Simple TCP/IP Services;C:\WINDOWS\system32\tcpsvcs.exe

R2 SNMP;SNMP Service;C:\WINDOWS\System32\snmp.exe

R2 STEC3;STEC3;\??\C:\WINDOWS\system32\STEC3.sys

R3 ApfiltrService;Alps Pointing-device Filter Driver;C:\WINDOWS\system32\DRIVERS\Apfiltr.sys

R3 EKBfltr;ENE Keyboard Controller;C:\WINDOWS\system32\DRIVERS\EKBfltr.sys

R3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5b.sys

R3 tunmp;Microsoft Tun Miniport Adapter Driver;C:\WINDOWS\system32\DRIVERS\tunmp.sys

R3 viagfx;viagfx;C:\WINDOWS\system32\DRIVERS\vtmini.sys

S2 Fax;Fax;C:\WINDOWS\system32\fxssvc.exe

S3 AdWatchDrv;AW Realtime Driver;\??\C:\WINDOWS\system32\drivers\AWRTPD.sys

S3 BRGSp50;BRGSp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\BRGSp50.sys

S3 BthEnum;Bluetooth Request Block Driver;C:\WINDOWS\system32\DRIVERS\BthEnum.sys

S3 BTHMODEM;Bluetooth Serial Communications Driver;C:\WINDOWS\system32\DRIVERS\bthmodem.sys

S3 BthPan;Bluetooth Device (Personal Area Network);C:\WINDOWS\system32\DRIVERS\bthpan.sys

S3 BTHPORT;Bluetooth Port Driver;C:\WINDOWS\system32\Drivers\BTHport.sys

S3 BTHUSB;Bluetooth Radio USB Driver;C:\WINDOWS\system32\Drivers\BTHUSB.sys

S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\fetnd5.sys

S3 HidBth;Microsoft Bluetooth HID Miniport;C:\WINDOWS\system32\DRIVERS\hidbth.sys

S3 k600bus;Sony Ericsson 600i driver (WDM);C:\WINDOWS\system32\DRIVERS\k600bus.sys

S3 LPDSVC;TCP/IP Print Server;C:\WINDOWS\system32\tcpsvcs.exe

S3 ovt519;EyeToy;C:\WINDOWS\system32\Drivers\ov519vid.sys

S3 p2pgasvc;Peer Networking Group Authentication;C:\WINDOWS\system32\svchost.exe -k p2psvc

S3 p2pimsvc;Peer Networking Identity Manager;C:\WINDOWS\system32\svchost.exe -k p2psvc

S3 p2psvc;Peer Networking;C:\WINDOWS\system32\svchost.exe -k p2psvc

S3 PNRPSvc;Peer Name Resolution Protocol;C:\WINDOWS\system32\svchost.exe -k p2psvc

S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI);C:\WINDOWS\system32\DRIVERS\rfcomm.sys

S3 SNMPTRAP;SNMP Trap Service;C:\WINDOWS\System32\snmptrap.exe

S3 umtsbus;WCDMA Handset USB Composite Device driver (WDM);C:\WINDOWS\system32\DRIVERS\umtsbus.sys

S3 umtsmdfl;WCDMA Handset Filter;C:\WINDOWS\system32\DRIVERS\umtsmdfl.sys

S3 umtsmdm;WCDMA Handset Drivers;C:\WINDOWS\system32\DRIVERS\umtsmdm.sys

S3 umtsserd;WCDMA Handset Diagnostic Serial Port (WDM);C:\WINDOWS\system32\DRIVERS\umtsserd.sys

S3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys

S3 ZDPSp50;ZDPSp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\ZDPSp50.sys

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

p2psvc p2psvc p2pimsvc p2pgasvc PNRPSvc

bthsvcs BthServ

 

*Newly Created Service* - NTIO256

 

Contents of the 'Scheduled Tasks' folder

2007-07-16 09:18:14 C:\WINDOWS\tasks\AppleSoftwareUpdate.job

2007-07-25 22:05:06 C:\WINDOWS\tasks\XoftSpySE 2.job

2007-07-25 22:02:20 C:\WINDOWS\tasks\XoftSpySE.job

 

**************************************************************************

 

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2007-07-25 23:06:25

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

C:\WINDOWS\system32\cmd.exe [2360] 0x8531A6D8

C:\WINDOWS\system32\protector.exe [1872] 0x84D47C08

 

 

scanning hidden registry entries ...

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Permissions\App_LocalResources\"=""

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_LocalResources\"=""

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_Data\"=""

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Roles\"=""

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Roles\App_LocalResources\"=""

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MSBuild\"=""

"C:\Program Files\Internet Explorer\MUI409\"=""

"C:\Program Files\Internet Explorer\MUI\"=""

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MUI409\"=""

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MUI\"=""

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\App_LocalResources\"=""

"C:\Program Files\Common Files\Microsoft Shared\DW\1025\"=""

"C:\Program Files\Common Files\Microsoft Shared\DW\1028\"=""

"C:\Program Files\Common Files\Microsoft Shared\DW\1031\"=""

"C:\Program Files\Common Files\Microsoft Shared\DW\1036\"=""

"C:\Program Files\Common Files\Microsoft Shared\DW\1040\"=""

"C:\Program Files\Common Files\Microsoft Shared\DW\1041\"=""

"C:\Program Files\Common Files\Microsoft Shared\DW\1042\"=""

"C:\Program Files\Common Files\Microsoft Shared\DW\2052\"=""

"C:\Program Files\Common Files\Microsoft Shared\DW\3082\"=""

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\"=""

"C:\WINDOWS\winsxs\x86_Microsoft.VC80.DebugMFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_c8452471\"=""

"C:\WINDOWS\winsxs\Policies\x86_policy.8.0.Microsoft.VC80.DebugMFC_1fc8b3b9a1e18e3b_x-ww_a193936f\"=""

"C:\WINDOWS\winsxs\x86_Microsoft.VC80.DebugCRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_f75eb16c\"=""

"C:\WINDOWS\winsxs\Policies\x86_policy.8.0.Microsoft.VC80.DebugCRT_1fc8b3b9a1e18e3b_x-ww_09e017b4\"=""

"C:\Program Files\Channel4\4oD\"="1"

"C:\Program Files\Channel4\"="1"

"C:\Documents and Settings\All Users\Application Data\Kontiki\"="1"

"C:\Documents and Settings\All Users\Documents\My Deliveries\4od1\tmpcache\"="1"

"C:\Documents and Settings\All Users\Documents\My Deliveries\4od1\"="1"

"C:\Documents and Settings\All Users\Documents\My Deliveries\"="1"

"C:\Program Files\Kontiki\"=""

"C:\DOCUME~1\NEWUSE~1\LOCALS~1\Temp\Kontiki4oDInstall\"=""

"C:\Program Files\Kontiki\4od1\cache\"=""

"C:\Program Files\Kontiki\4od1\"=""

"C:\Documents and Settings\All Users\Start Menu\Programs\Channel 4\4oD\"=""

"C:\Documents and Settings\All Users\Start Menu\Programs\Channel 4\"=""

"C:\WINDOWS\Installer\{68D88FD1-C7BA-4BC9-B6A6-9685FAECD7EE}\"=""

"C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_10.b03\"=""

"C:\Program Files\Java\jre1.5.0_10\"=""

"C:\Program Files\Java\jre1.5.0_10\bin\"=""

"C:\WINDOWS\Installer\{3248F0A8-6813-11D6-A77B-00B0D0150100}\"=""

"C:\Program Files\Adobe\Acrobat 7.0\ActiveX\"="1"

"C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\"="1"

"C:\Program Files\Adobe\Acrobat 7.0\Reader\"="1"

"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\VDKHome\ENU\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\VDKHome\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\AcroForm\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\WebSearch\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\AcroForm\PMP\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Multimedia\MPP\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Multimedia\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Help\ENU\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Help\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\Howto\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\OLS\Locale\ENU\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\OLS\Locale\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\OLS\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\Templates\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\Howto\images\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\Updater\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Resource\CMap\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Resource\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Resource\Font\PFM\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Resource\Font\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\Optional\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Annotations\Stamps\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Annotations\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Annotations\Stamps\ENU\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\HowTo\ENU\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\HowTo\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\HowTo\ENU\Images\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\SPPlugins\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Esl\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\Javascripts\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\Legal\Adobe Reader\7.0.0\en_US\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\Legal\Adobe Reader\7.0.0\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\Legal\Adobe Reader\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\Legal\"=""

"C:\Documents and Settings\All Users\Application Data\Adobe\Acrobat\7.0\Replicate\Security\"=""

"C:\Documents and Settings\All Users\Application Data\Adobe\Acrobat\7.0\Replicate\"=""

"C:\Documents and Settings\All Users\Application Data\Adobe\Acrobat\7.0\"=""

"C:\Documents and Settings\All Users\Application Data\Adobe\Acrobat\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\Messages\ENU\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\Messages\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\ImageViewer\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\ImageViewer\en_US\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins3d\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Resource\Linguistics\Providers\Proximity\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Resource\Linguistics\Providers\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Resource\Linguistics\"=""

"C:\Program Files\Adobe\Acrobat 7.0\Resource\Linguistics\LanguageNames\"=""

"C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A70900000002}\"=""

"C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_11.b03\"=""

"C:\Program Files\Java\jre1.5.0_11\"=""

"C:\Program Files\Java\jre1.5.0_11\bin\"=""

"C:\WINDOWS\Installer\{3248F0A8-6813-11D6-A77B-00B0D0150110}\"=""

"C:\Program Files\Common Files\Microsoft Shared\DW\1033\"=""

"C:\Documents and Settings\All Users\Application Data\Microsoft\IdentityCRL\production\"=""

"C:\Program Files\MSN Messenger\Device Manager\Loc\18\"=""

"C:\Program Files\MSN Messenger\Device Manager\Loc\8\"=""

"C:\Program Files\MSN Messenger\Device Manager\Loc\25\"=""

"C:\Program Files\MSN Messenger\Device Manager\Loc\7\"=""

"C:\Program Files\MSN Messenger\Device Manager\Loc\1046\"=""

"C:\Program Files\MSN Messenger\Device Manager\Loc\17\"=""

"C:\Program Files\MSN Messenger\Device Manager\Loc\4\"=""

"C:\Program Files\MSN Messenger\Device Manager\Loc\1028\"=""

"C:\Program Files\MSN Messenger\Device Manager\Loc\10\"=""

"C:\Program Files\MSN Messenger\Device Manager\Loc\12\"=""

"C:\Program Files\MSN Messenger\Device Manager\Loc\11\"=""

"C:\Program Files\MSN Messenger\Device Manager\Loc\20\"=""

"C:\Program Files\MSN Messenger\Device Manager\Loc\9\"=""

"C:\Program Files\MSN Messenger\Device Manager\Loc\16\"=""

"C:\Program Files\MSN Messenger\Device Manager\Loc\29\"=""

"C:\Program Files\MSN Messenger\Device Manager\Loc\6\"=""

"C:\Program Files\MSN Messenger\Device Manager\Loc\31\"=""

"C:\Program Files\MSN Messenger\Device Manager\Loc\22\"=""

"C:\Program Files\MSN Messenger\Device Manager\Loc\19\"=""

"C:\WINDOWS\Installer\{571700F0-DB9D-4B3A-B03D-35A14BB5939F}\"=""

"C:\Program Files\Windows Journal Viewer\"=""

"C:\Program Files\Common Files\Microsoft Shared\Ink\"=""

"C:\WINDOWS\Installer\{43DCF766-6838-4F9A-8C91-D92DA586DFA8}\"=""

"C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\"=""

"C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_01.b06\"=""

"C:\Program Files\Java\jre1.6.0_01\"=""

"C:\Program Files\Java\jre1.6.0_01\bin\"=""

"C:\WINDOWS\Installer\{3248F0A8-6813-11D6-A77B-00B0D0160010}\"=""

"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\"=""

"C:\Documents and Settings\All Users\Application Data\Apple\Installer Cache\Apple Software Update 2.0.0.21\"="1"

"C:\Documents and Settings\All Users\Application Data\Apple\Installer Cache\"="1"

"C:\Documents and Settings\All Users\Application Data\Apple\"="1"

"C:\Program Files\Apple Software Update\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\da.lproj\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\de.lproj\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\en.lproj\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\es.lproj\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\fi.lproj\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\fr.lproj\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\it.lproj\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\ja.lproj\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\ko.lproj\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\nb.lproj\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\nl.lproj\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\ru.lproj\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\sv.lproj\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\zh_CN.lproj\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\zh_TW.lproj\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\da.lproj\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\de.lproj\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\en.lproj\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\es.lproj\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\fi.lproj\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\fr.lproj\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\it.lproj\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\ja.lproj\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\ko.lproj\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\nb.lproj\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\nl.lproj\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\ru.lproj\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\sv.lproj\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\zh_CN.lproj\"=""

"C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\zh_TW.lproj\"=""

"C:\Program Files\Apple Software Update\plugins\"=""

"C:\WINDOWS\Installer\{74EC78BC-B379-4E29-9006-8F161DCAABA6}\"=""

"C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\QuickTime 7.2.0.240\"=""

"C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\"=""

"C:\Program Files\QuickTime\QTComponents\"="1"

"C:\Program Files\QuickTime\QTSystem\"="1"

"C:\Program Files\QuickTime\PropertyPanels\"=""

"C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\"=""

"C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\da.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\de.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\en.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\es.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\fi.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\fr.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\it.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\ja.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\ko.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\nb.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\nl.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\ru.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\sv.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\zh_CN.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\zh_TW.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\"=""

"C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\da.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\de.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\en.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\es.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\fi.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\fr.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\it.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\ja.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\ko.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\nb.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\nl.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\ru.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\sv.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\zh_CN.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\zh_TW.lproj\"=""

"C:\Program Files\QuickTime\PictureViewer.Resources\"=""

"C:\Program Files\QuickTime\PictureViewer.Resources\da.lproj\"=""

"C:\Program Files\QuickTime\PictureViewer.Resources\de.lproj\"=""

"C:\Program Files\QuickTime\PictureViewer.Resources\en.lproj\"=""

"C:\Program Files\QuickTime\PictureViewer.Resources\es.lproj\"=""

"C:\Program Files\QuickTime\PictureViewer.Resources\fi.lproj\"=""

"C:\Program Files\QuickTime\PictureViewer.Resources\fr.lproj\"=""

"C:\Program Files\QuickTime\PictureViewer.Resources\it.lproj\"=""

"C:\Program Files\QuickTime\PictureViewer.Resources\ja.lproj\"=""

"C:\Program Files\QuickTime\PictureViewer.Resources\ko.lproj\"=""

"C:\Program Files\QuickTime\PictureViewer.Resources\nb.lproj\"=""

"C:\Program Files\QuickTime\PictureViewer.Resources\nl.lproj\"=""

"C:\Program Files\QuickTime\PictureViewer.Resources\ru.lproj\"=""

"C:\Program Files\QuickTime\PictureViewer.Resources\sv.lproj\"=""

"C:\Program Files\QuickTime\PictureViewer.Resources\zh_CN.lproj\"=""

"C:\Program Files\QuickTime\PictureViewer.Resources\zh_TW.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\"=""

"C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\da.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\de.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\en.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\es.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\fi.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\fr.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\it.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\ja.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\ko.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\nb.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\nl.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\ru.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\sv.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\zh_CN.lproj\"=""

"C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\zh_TW.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\da.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\de.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\en.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\es.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\fi.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\fr.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\it.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\ja.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\ko.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\nb.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\nl.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\ru.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\sv.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\zh_CN.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\zh_TW.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\da.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\de.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\en.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\es.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\fi.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\fr.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\it.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\ja.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\ko.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\nb.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\nl.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\ru.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\sv.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\zh_CN.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\zh_TW.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\da.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\de.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\en.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\es.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\fi.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\fr.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\it.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\ja.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\ko.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\nb.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\nl.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\ru.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\sv.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\zh_CN.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\zh_TW.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\da.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\de.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\en.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\es.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\fi.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\fr.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\it.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\ja.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\ko.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\nb.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\nl.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\ru.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\sv.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\zh_CN.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\zh_TW.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\da.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\de.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\en.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\es.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\fi.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\fr.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\it.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\ja.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\ko.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\nb.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\nl.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\ru.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\sv.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\zh_CN.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\zh_TW.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\da.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\de.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\en.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\es.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\fi.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\fr.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\it.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\ja.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\ko.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\nb.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\nl.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\ru.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\sv.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\zh_CN.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.Resources\zh_TW.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.Resources\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.Resources\da.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.Resources\de.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.Resources\en.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.Resources\es.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.Resources\fi.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.Resources\fr.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.Resources\it.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.Resources\ja.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.Resources\ko.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.Resources\nb.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.Resources\nl.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.Resources\ru.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.Resources\sv.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.Resources\zh_CN.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.Resources\zh_TW.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEssentials.Resources\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEssentials.Resources\da.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEssentials.Resources\de.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEssentials.Resources\en.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEssentials.Resources\es.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEssentials.Resources\fi.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEssentials.Resources\fr.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEssentials.Resources\it.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEssentials.Resources\ja.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEssentials.Resources\ko.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEssentials.Resources\nb.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEssentials.Resources\nl.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEssentials.Resources\ru.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEssentials.Resources\sv.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEssentials.Resources\zh_CN.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeEssentials.Resources\zh_TW.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\da.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\de.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\en.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\es.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\fi.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\fr.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\it.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\ja.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\ko.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\nb.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\nl.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\ru.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\sv.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\zh_CN.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\zh_TW.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeImage.Resources\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeImage.Resources\da.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeImage.Resources\de.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeImage.Resources\en.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeImage.Resources\es.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeImage.Resources\fi.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeImage.Resources\fr.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeImage.Resources\it.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeImage.Resources\ja.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeImage.Resources\ko.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeImage.Resources\nb.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeImage.Resources\nl.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeImage.Resources\ru.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeImage.Resources\sv.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeImage.Resources\zh_CN.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeImage.Resources\zh_TW.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\da.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\de.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\en.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\es.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\fi.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\fr.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\it.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\ja.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\ko.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\nb.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\nl.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\ru.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\sv.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\zh_CN.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\zh_TW.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG.Resources\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG.Resources\da.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG.Resources\de.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG.Resources\en.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG.Resources\es.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG.Resources\fi.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG.Resources\fr.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG.Resources\it.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG.Resources\ja.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG.Resources\ko.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG.Resources\nb.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG.Resources\nl.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG.Resources\ru.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG.Resources\sv.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG.Resources\zh_CN.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG.Resources\zh_TW.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\da.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\de.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\en.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\es.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\fi.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\fr.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\it.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\ja.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\ko.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\nb.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\nl.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\ru.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\sv.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\zh_CN.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\zh_TW.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\da.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\de.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\en.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\es.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\fi.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\fr.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\it.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\ja.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\ko.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\nb.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\nl.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\ru.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\sv.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\zh_CN.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\zh_TW.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMusic.Resources\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMusic.Resources\da.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMusic.Resources\de.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMusic.Resources\en.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMusic.Resources\es.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMusic.Resources\fi.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMusic.Resources\fr.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMusic.Resources\it.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMusic.Resources\ja.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMusic.Resources\ko.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMusic.Resources\nb.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMusic.Resources\nl.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMusic.Resources\ru.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMusic.Resources\sv.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMusic.Resources\zh_CN.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeMusic.Resources\zh_TW.lproj\"=""

"C:\Program Files\QuickTime\QuickTimePlayer.Resources\"=""

"C:\Program Files\QuickTime\QuickTimePlayer.Resources\da.lproj\"=""

"C:\Program Files\QuickTime\QuickTimePlayer.Resources\de.lproj\"=""

"C:\Program Files\QuickTime\QuickTimePlayer.Resources\en.lproj\"=""

"C:\Program Files\QuickTime\QuickTimePlayer.Resources\es.lproj\"=""

"C:\Program Files\QuickTime\QuickTimePlayer.Resources\fi.lproj\"=""

"C:\Program Files\QuickTime\QuickTimePlayer.Resources\fr.lproj\"=""

"C:\Program Files\QuickTime\QuickTimePlayer.Resources\it.lproj\"=""

"C:\Program Files\QuickTime\QuickTimePlayer.Resources\ja.lproj\"=""

"C:\Program Files\QuickTime\QuickTimePlayer.Resources\ko.lproj\"=""

"C:\Program Files\QuickTime\QuickTimePlayer.Resources\nb.lproj\"=""

"C:\Program Files\QuickTime\QuickTimePlayer.Resources\nl.lproj\"=""

"C:\Program Files\QuickTime\QuickTimePlayer.Resources\ru.lproj\"=""

"C:\Program Files\QuickTime\QuickTimePlayer.Resources\sv.lproj\"=""

"C:\Program Files\QuickTime\QuickTimePlayer.Resources\zh_CN.lproj\"=""

"C:\Program Files\QuickTime\QuickTimePlayer.Resources\zh_TW.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeQD3D.Resources\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeQD3D.Resources\da.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeQD3D.Resources\de.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeQD3D.Resources\en.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeQD3D.Resources\es.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeQD3D.Resources\fi.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeQD3D.Resources\fr.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeQD3D.Resources\it.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeQD3D.Resources\ja.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeQD3D.Resources\ko.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeQD3D.Resources\nb.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeQD3D.Resources\nl.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeQD3D.Resources\ru.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeQD3D.Resources\sv.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeQD3D.Resources\zh_CN.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeQD3D.Resources\zh_TW.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreaming.Resources\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreaming.Resources\da.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreaming.Resources\de.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreaming.Resources\en.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreaming.Resources\es.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreaming.Resources\fi.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreaming.Resources\fr.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreaming.Resources\it.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreaming.Resources\ja.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreaming.Resources\ko.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreaming.Resources\nb.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreaming.Resources\nl.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreaming.Resources\ru.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreaming.Resources\sv.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreaming.Resources\zh_CN.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreaming.Resources\zh_TW.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\da.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\de.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\en.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\es.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\fi.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\fr.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\it.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\ja.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\ko.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\nb.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\nl.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\ru.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\sv.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\zh_CN.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\zh_TW.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\da.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\de.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\en.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\es.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\fi.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\fr.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\it.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\ja.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\ko.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\nb.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\nl.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\ru.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\sv.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\zh_CN.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\zh_TW.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVR.Resources\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVR.Resources\da.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVR.Resources\de.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVR.Resources\en.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVR.Resources\es.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVR.Resources\fi.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVR.Resources\fr.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVR.Resources\it.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVR.Resources\ja.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVR.Resources\ko.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVR.Resources\nb.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVR.Resources\nl.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVR.Resources\ru.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVR.Resources\sv.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVR.Resources\zh_CN.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVR.Resources\zh_TW.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\da.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\de.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\en.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\es.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\fi.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\fr.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\it.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\ja.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\ko.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\nb.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\nl.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\ru.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\sv.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\zh_CN.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\zh_TW.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\da.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\de.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\en.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\es.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\fi.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\fr.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\it.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\ja.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\ko.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\nb.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\nl.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\ru.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\sv.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\zh_CN.lproj\"=""

"C:\Program Files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\zh_TW.lproj\"=""

"C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime\"=""

"C:\WINDOWS\Installer\{95A890AA-B3B1-44B6-9C18-A8F7AB3EE7FC}\"=""

"C:\Program Files\Dealio\"="1"

"C:\Program Files\Dealio\kb106\"="1"

"C:\Program Files\Dealio\kb106\rules\"="1"

"C:\Program Files\Dealio\kb106\temp\"="1"

"C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware 2007\logs\"="1"

"C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware 2007\"="1"

"C:\Documents and Settings\All Users\Application Data\Lavasoft\"="1"

"C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware 2007\update\"="1"

"C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware 2007\update\backup\"="1"

"C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware 2007\update\new\"="1"

"C:\Program Files\Lavasoft\Ad-Aware 2007\"=""

"C:\Program Files\Lavasoft\"=""

"C:\Program Files\Lavasoft\Ad-Aware 2007\Skin\"=""

"C:\Program Files\Lavasoft\Ad-Aware 2007\Lang\"=""

"C:\Program Files\Lavasoft\Ad-Aware 2007\Help\"=""

"C:\Program Files\Lavasoft\Ad-Aware 2007\Registration\"=""

"C:\Documents and Settings\All Users\Start Menu\Programs\Lavasoft\Ad-Aware 2007\"=""

"C:\Documents and Settings\All Users\Start Menu\Programs\Lavasoft\"=""

"C:\WINDOWS\Installer\{E31C348B-63A9-4CBF-8D7F-D932ABB63244}\"=""

"C:\Config.Msi\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]

"C:\Documents and Settings\All Users\Application Data\Teleca\Capability Manager\NetworkOperatorTemplate.xml"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Connection Wizard\LangResourceDll.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\MMS Home Studio\mmscomposer.exe"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\MMS Home Studio\mmscomposer.ini"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\MMS Home Studio\mmscomposer.xml"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\ECSCM07Q.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\MSVCRTD.DLL"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\PhoneNameDB_object.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\ShowMfcDialog.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\anubisps.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\anubisutils.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\cabmain.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\caleditatl.exe"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\catcheventatl.exe"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\cellphone_object.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\closedbgout.exe"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\db_objects.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\dbgout.exe"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\dbgout_capman.txt"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\dbgout_init.txt"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\dbgout_ocs.txt"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\ecscmbts.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\ecscmext.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\ecscmirc.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\ecscmskt.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\ecscmtpi.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\ecsepm.cpl"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\ecsmoddata.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\ecsnwext.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\ecsphext.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epm.h"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\enableirsocketutil.exe"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epm_util.exe"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epoc_object.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\esirsock_object.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\ms98irsock_object.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\msirsock_object.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\msmeirsock_object.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\msvcr71d.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\obex_object.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\obexsyncreq_object.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\phonebook_object.dll"=dword:00000001

"C:\WINDOWS\system32\psapi.dll"=dword:00000002

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\setdbgout.exe"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\setregsecurity.exe"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\settings_object.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\sms_object.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\status_object.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\widcommbt_object.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\xpbtsock_2_object.dll"=dword:00000001

"C:\Program Files\Common Files\Teleca Shared\File Manager\TC File Mgmt.dll"=dword:00000001

"C:\Documents and Settings\All Users\Application Data\Teleca\Capability Manager\Applications\FileManager.xml"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\File Manager\FMObex.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\File Manager\fmobexsrv.exe"=dword:00000001

"C:\Program Files\Common Files\Teleca Shared\Generic.exe"=dword:00000001

"C:\Program Files\Common Files\Teleca Shared\SpecificUSB.dll"=dword:00000001

"C:\Program Files\Common Files\Teleca Shared\TC Device Mgmt.dll"=dword:00000001

"C:\Program Files\Common Files\Teleca Shared\TC Device Mgmt Internal.dll"=dword:00000001

"C:\Program Files\Common Files\Teleca Shared\TC Device Mgmt Service.dll"=dword:00000001

"C:\Documents and Settings\All Users\Application Data\Teleca\DM\DEVREP\devrep.xml"=dword:00000001

"C:\Documents and Settings\All Users\Application Data\Teleca\DM\DEVREP\devrepSchema.xdr"=dword:00000001

"C:\Program Files\Common Files\Teleca Shared\graphicbuttoniii.ocx"=dword:00000002

"C:\Program Files\Sony Ericsson\Mobile2\Image Editor\imagepickerdll.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Image Editor\irsendfiledll.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Image Editor\mmdownload.exe"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Image Editor\phonemanagerdll.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Image Editor\mmdownloadlg.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Networking Wizard\mnguiimg.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Mobile Networking Wizard\mnguilg.dll"=dword:00000001

"C:\Documents and Settings\All Users\Application Data\Teleca\Capability Manager\Applications\OCS.xml"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\OCS\ObexAuthenticationServiceDll.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\OCS\ObexAuthenticationServiceDllLg.dll"=dword:00000001

"C:\Program Files\Common Files\Teleca Shared\ObexHeaderServiceDll.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\OCS\ObexOperationDll.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\File Manager\fmgrguil.dll"=dword:00000001

"C:\Program Files\Common Files\Teleca Shared\tlib\cfg\tlib_logging_CA5.cfg"=dword:00000001

"C:\Program Files\Common Files\Teleca Shared\tlib\cfg\tlib_logging_CA6.cfg"=dword:00000001

"C:\Program Files\Common Files\Teleca Shared\tlib\cfg\tlib_logging_GE.cfg"=dword:00000001

"C:\WINDOWS\system32\msxml4.dll"=dword:00000004

"C:\WINDOWS\system32\msxml4r.dll"=dword:00000004

"C:\WINDOWS\system32\msvcr71.dll"=dword:00000004

"C:\WINDOWS\system32\mfc71u.dll"=dword:00000001

"C:\WINDOWS\system32\mfc71.dll"=dword:00000001

"C:\WINDOWS\system32\msvcp71.dll"=dword:00000004

"C:\WINDOWS\system32\comcat.dll"=dword:00000004

"C:\WINDOWS\system32\comdlg32.ocx"=dword:00000003

"C:\WINDOWS\system32\mscomct2.ocx"=dword:00000003

"C:\WINDOWS\system32\mscomctl.ocx"=dword:00000003

"C:\WINDOWS\system32\msvbvm60.dll"=dword:00000004

"C:\Program Files\Common Files\Teleca Shared\viewerIII.ocx"=dword:00000001

"C:\Program Files\Common Files\Teleca Shared\mmstimer.dll"=dword:00000001

"C:\Program Files\Common Files\Teleca Shared\win.tlb"=dword:00000001

"C:\Program Files\Common Files\Teleca Shared\ObexCommunication.exe"=dword:00000001

"C:\Program Files\Common Files\Teleca Shared\IrCommunication.exe"=dword:00000001

"C:\Program Files\Common Files\Teleca Shared\IrSockDll.dll"=dword:00000001

"C:\WINDOWS\system32\olepro32.dll"=dword:00000004

"C:\WINDOWS\system32\stdole2.tlb"=dword:00000004

"C:\WINDOWS\system32\sysinfo.ocx"=dword:00000002

"C:\WINDOWS\system32\msvcr70.dll"=dword:00000001

"C:\WINDOWS\system32\mfc70u.dll"=dword:00000001

"C:\WINDOWS\system32\mfc70.dll"=dword:00000001

"C:\WINDOWS\system32\msvcp70.dll"=dword:00000001

"C:\WINDOWS\system32\msvci70.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Sync Station\DXP Pim.exe"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Sync Station\DXP SyncML.exe"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Sync Station\DeviceCustomisation.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Sync Station\NotesPim.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Sync Station\NotesPimAdaptorLoader.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Sync Station\ObexTransport.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Sync Station\OutlookExtension.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Sync Station\OutlookPim.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Sync Station\Progress.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Sync Station\SyncController.exe"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Sync Station\SyncEngineApp.exe"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Sync Station\SyncEngineAppps.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Sync Station\SyncMLDesktopServer.exe"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Sync Station\SyncStarter.exe"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Sync Station\WABPim.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Sync Station\lcppn24.dll"=dword:00000001

"C:\Program Files\Sony Ericsson\Mobile2\Sync Station\nnotespwdhook.dll"=dword:00000001

"C:\WINDOWS\system32\asycfilt.dll"=dword:00000003

"C:\WINDOWS\system32\CDDBControl.dll"=dword:00000001

"C:\WINDOWS\system32\CDDBUI.dll"=dword:00000001

"C:\WINDOWS\system32\CddbLangDE.dll"=dword:00000001

"C:\WINDOWS\system32\CddbLangES.dll"=dword:00000001

"C:\WINDOWS\system32\CddbLangFR.dll"=dword:00000001

"C:\WINDOWS\system32\CddbLangIT.dll"=dword:00000001

"C:\WINDOWS\system32\CddbLangJA.dll"=dword:00000001

"C:\WINDOWS\system32\CddbLangKO.dll"=dword:00000001

"C:\WINDOWS\system32\CddbLangNL.dll"=dword:00000001

"C:\WINDOWS\system32\CddbLangPT_BR.dll"=dword:00000001

"C:\WINDOWS\system32\CddbLangSV.dll"=dword:00000001

"C:\WINDOWS\system32\CddbLangTH.dll"=dword:00000001

"C:\WINDOWS\system32\CddbLangZH.dll"=dword:00000001

"C:\WINDOWS\system32\CddbLangZT.dll"=dword:00000001

"C:\WINDOWS\Downloaded Program Files\minesweeper.dll"=dword:00000001

"C:\WINDOWS\Downloaded Program Files\messengerstatsclient.dll"=dword:00000001

"C:\WINDOWS\Downloaded Program Files\solitaireshowdown.dll"=dword:00000001

"C:\WINDOWS\Downloaded Program Files\PURen-us.dll"=dword:00000001

"C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll"=dword:00000001

"C:\Program Files\Common Files\InstallShield\Driver\7\Intel 32\IDriver.exe"=dword:00000001

"C:\Program Files\Common Files\InstallShield\Driver\7\Intel 32\objps7.dll"=dword:00000001

"C:\Program Files\Common Files\InstallShield\Driver\7\Intel 32\IUser7.dll"=dword:00000001

"C:\Program Files\Common Files\InstallShield\Driver\7\Intel 32\IScript7.dll"=dword:00000001

"C:\Documents and Settings\All Users\Application Data\Adobe\Photoshop Album\Catalogs\My Catalog.psa"=dword:00000001

"C:\WINDOWS\system32\atl71.dll"=dword:00000002

"C:\WINDOWS\system32\mfc42.dll"=dword:00000002

"C:\Program Files\Common Files\Real\Codecs\14_43260.dll"=dword:00000001

"C:\Program Files\Common Files\Real\Codecs\28_83260.dll"=dword:00000001

"C:\WINDOWS\system32\xvidcore.dll"=dword:00000001

"C:\WINDOWS\system32\xvidvfw.dll"=dword:00000001

"C:\WINDOWS\system32\xvid.ax"=dword:00000001

"C:\WINDOWS\system32\VFWUI.dll"=dword:00000001

"C:\WINDOWS\system32\DSUI.ax"=dword:00000001

"C:\Program Files\Movie Maker\WMM2AE.dll"=dword:00000002

"C:\Program Files\Movie Maker\WMM2FXB.dll"=dword:00000002

"C:\Program Files\Movie Maker\WMM2FXA.dll"=dword:00000002

"C:\Program Files\Movie Maker\Shared\Sample2.jpg"=dword:00000002

"C:\Program Files\Movie Maker\Shared\Sample1.jpg"=dword:00000002

"C:\Program Files\Movie Maker\Shared\paint.png"=dword:00000002

"C:\Program Files\Movie Maker\Shared\news.png"=dword:00000002

"C:\Program Files\Movie Maker\1033\WMM2RES.dll"=dword:00000001

"C:\Program Files\Movie Maker\1033\WMM2ERES.dll"=dword:00000001

"C:\Program Files\Movie Maker\1033\MovieMk.chm"=dword:00000001

"C:\Program Files\Movie Maker\WMM2EXT.dll"=dword:00000002

"C:\Program Files\Movie Maker\sample.wmv"=dword:00000001

"C:\Program Files\Movie Maker\WMM2FILT.dll"=dword:00000002

"C:\Program Files\Movie Maker\1033\license.txt"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.tlb"=dword:00000002

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.tlb"=dword:00000002

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.JScript.tlb"=dword:00000002

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscoree.tlb"=dword:00000002

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorlib.tlb"=dword:00000002

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.tlb"=dword:00000002

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.tlb"=dword:00000002

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Drawing.tlb"=dword:00000002

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.tlb"=dword:00000002

"C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\System.Windows.Forms.tlb"=dword:00001000

"C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\System.EnterpriseServices.tlb"=dword:00001000

"C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\Microsoft.JScript.tlb"=dword:00001000

"C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\Microsoft.Vsa.tlb"=dword:00001000

"C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\System.Drawing.tlb"=dword:00001000

"C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\mscoree.tlb"=dword:00001000

"C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\mscorlib.tlb"=dword:00001000

"C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\System.tlb"=dword:00001000

"C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\Microsoft.Vsa.Vb.CodeDOMProcessor.tlb"=dword:00001000

"C:\WINDOWS\system32\wuweb.dll"=dword:00000001

"C:\WINDOWS\system32\CMDLGFR.DLL"=dword:00000001

"C:\WINDOWS\system32\Mscc2fr.dll"=dword:00000001

"C:\WINDOWS\system32\MSCMCFR.DLL"=dword:00000001

"C:\WINDOWS\system32\TABCTFR.DLL"=dword:00000001

"C:\WINDOWS\system32\TABCTL32.OCX"=dword:00000001

"C:\WINDOWS\system32\VB6FR.DLL"=dword:00000001

"C:\WINDOWS\system32\VB6STKIT.DLL"=dword:00000001

"C:\Program Files\Free Audio Pack\FreeConverter\AudFile.dll"=dword:00000001

"C:\Program Files\Free Audio Pack\FreeConverter\AudioInfos.dll"=dword:00000001

"C:\Program Files\Free Audio Pack\FreeConverter\AudioTrans.dll"=dword:00000001

"C:\Program Files\Free Audio Pack\FreeConverter\AudPlayer.dll"=dword:00000001

"C:\Program Files\Free Audio Pack\FreeConverter\WMAFile.dll"=dword:00000001

"C:\Program Files\Free Audio Pack\FreeConverter\ControlActiveX.ocx"=dword:00000001

"C:\Program Files\Free Audio Pack\FreeConverter\MusicExplorer.ocx"=dword:00000001

"C:\Program Files\Free Audio Pack\FreeConverter\HookMenu.ocx"=dword:00000001

"C:\Program Files\Free Audio Pack\FreeConverter\libfaac.dll"=dword:00000001

"C:\Program Files\Free Audio Pack\FreeConverter\libfaad2.dll"=dword:00000001

"C:\Program Files\Free Audio Pack\FreeConverter\AACencoder.ocx"=dword:00000001

"C:\Program Files\Free Audio Pack\FreeConverter\AACdecoder.ocx"=dword:00000001

"C:\Program Files\Free Audio Pack\FreeConverter\M4ADecoder.ocx"=dword:00000001

"C:\Program Files\Free Audio Pack\FreeConverter\Flac_Codec.ocx"=dword:00000001

"C:\WINDOWS\system32\COMCT232.OCX"=dword:00000001

"C:\Program Files\Kontiki\kdx.inf"=dword:00000001

"C:\Program Files\Kontiki\4od1\cache\c4_grass.jpg"=dword:00000001

"C:\Program Files\Kontiki\4od1\cache\4od.swf"=dword:00000001

"C:\Program Files\Kontiki\4od1\cache\4odmedium.swf"=dword:00000001

"C:\Program Files\Kontiki\4od1\cache\c4_background.jpg"=dword:00000001

"C:\Program Files\Kontiki\4od1\cache\c4_btn_dlg.gif"=dword:00000001

"C:\Program Files\Kontiki\4od1\cache\c4_button-close.gif"=dword:00000001

"C:\Program Files\Kontiki\4od1\cache\c4_button-downloads.gif"=dword:00000001

"C:\Program Files\Kontiki\4od1\cache\c4_complete.html"=dword:00000001

"C:\Program Files\Kontiki\4od1\cache\c4_eventDefault.html"=dword:00000001

"C:\Program Files\Kontiki\4od1\cache\c4_home.html"=dword:00000001

"C:\Program Files\Kontiki\4od1\cache\c4_menuTray.html"=dword:00000001

"C:\Program Files\Kontiki\4od1\cache\c4_offline.html"=dword:00000001

"C:\Program Files\Kontiki\4od1\cache\c4_popuplogo.gif"=dword:00000001

"C:\Program Files\Kontiki\4od1\cache\c4_script.js"=dword:00000001

"C:\Program Files\Kontiki\4od1\cache\c4_spacer.gif"=dword:00000001

"C:\Program Files\Kontiki\4od1\cache\c4_styles.css"=dword:00000001

"C:\Program Files\Kontiki\4od1\cache\c4_tray0.ico"=dword:00000001

"C:\Program Files\Kontiki\4od1\cache\c4_tray1.ico"=dword:00000001

"C:\Program Files\Kontiki\4od1\cache\c4_tray2.ico"=dword:00000001

"C:\Program Files\Kontiki\4od1\cache\c4_button-continue.gif"=dword:00000001

"C:\Program Files\Kontiki\4od1\cache\c4_lowdiskspace.html"=dword:00000001

"C:\Program Files\Channel4\4oD\C4Com.dll"=dword:00000001

"C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx"=dword:00000002

"C:\WINDOWS\system32\Macromed\Flash\GetFlash.exe"=dword:00000002

"C:\WINDOWS\system32\Macromed\Flash\UninstFl.exe"=dword:00000002

"C:\Program Files\Common Files\Ahead\DSFilter\NeResize.ax"=dword:00000001

"C:\Program Files\Common Files\Ahead\Lib\specialoffer.exe"=dword:00000001

"C:\Program Files\Ahead\CoverDesigner\Templates\Audio_Content.nct"=dword:00000001

"C:\Program Files\Ahead\CoverDesigner\covered-jpn.nls"=dword:00000001

"C:\Program Files\Ahead\Nero StartSmart\NeroStartSmart_jpn.chm"=dword:00000001

"C:\Program Files\Ahead\Nero BackItUp\BackItUp-Jpn.nls"=dword:00000001

"C:\WINDOWS\Downloaded Program Files\activex.ocx"=dword:00000001

"C:\WINDOWS\system32\pxafs.dll"=dword:00000004

"C:\WINDOWS\system32\drivers\cdralw2k.sys"=dword:00000004

"C:\WINDOWS\system32\drivers\cdr4_xp.sys"=dword:00000004

"C:\WINDOWS\Downloaded Program Files\EPUWALcontrol.dll"=dword:00000001

"C:\WINDOWS\Downloaded Program Files\GAME_UNO1.dll"=dword:00000001

"C:\WINDOWS\system32\sirenacm.dll"=dword:00000001

"C:\WINDOWS\Downloaded Program Files\MessengerStatsPAClient.dll"=dword:00000001

"C:\Program Files\Windows Journal Viewer\JVNBDoc.dll"=dword:00000001

"C:\Program Files\Windows Journal Viewer\JVVWCTL.DLL"=dword:00000001

"C:\WINDOWS\Help\JntView.chm"=dword:00000001

"C:\Program Files\Windows Journal Viewer\jvintl.dll"=dword:00000001

"C:\Program Files\Windows Journal Viewer\jvinkseg.dll"=dword:00000001

"C:\WINDOWS\system32\inked.dll"=dword:00000001

"C:\Program Files\Common Files\Microsoft Shared\Ink\inkobj.dll"=dword:00000001

"C:\Program Files\Common Files\Microsoft Shared\Ink\tpcps.dll"=dword:00000001

"C:\WINDOWS\system32\wisptis.exe"=dword:00000001

"C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\other.zip"=dword:00000001

"C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\core1.zip"=dword:00000001

"C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\core2.zip"=dword:00000001

"C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\core3.zip"=dword:00000001

"C:\WINDOWS\Downloaded Program Files\popcaploader.dll"=dword:00000001

"C:\WINDOWS\Downloaded Program Files\zylomloader.dll"=dword:00000001

"C:\Program Files\Common Files\InstallShield\Professional\RunTime91\Intel32\iKernel.dll"=dword:00000001

"C:\Program Files\Common Files\InstallShield\Professional\RunTime91\Intel32\Setup.dll"=dword:00000001

"C:\Program Files\Common Files\InstallShield\Professional\RunTime91\Intel32\DotNetInstaller.exe"=dword:00000001

"C:\Program Files\Common Files\InstallShield\Professional\RunTime91\Intel32\iscript.dll"=dword:00000001

"C:\Program Files\Common Files\InstallShield\Professional\RunTime91\Intel32\ctor.dll"=dword:00000001

"C:\Program Files\Common Files\InstallShield\Professional\RunTime91\Intel32\iuser.dll"=dword:00000001

"C:\Program Files\Common Files\InstallShield\Professional\RunTime91\Intel32\IGDI.dll"=dword:00000001

"C:\WINDOWS\Downloaded Program Files\CONFLICT.1\MineSweeper.dll"=dword:00000001

"C:\WINDOWS\Downloaded Program Files\CONFLICT.1\SolitaireShowdown.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\Vsavb7rtUI.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\VsaVb7rt.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Vsa.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft_VsaVb.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ndpsetup.ico"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dv_aspnetmmc.chm"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallCommon.sql"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Aspnet.config"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\DefaultWsdlHelpGenerator.aspx"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_filter.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallPersistSqlState.sql"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallSqlStateTemplate.sql"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallMembership.sql"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MmcAspExt.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AspNetMMCExt.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet.mof"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Aspnet_perf.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_perf.h"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\UninstallPersonalization.sql"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallProfile.SQL"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\Browsers\goAmerica.browser"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regiis.exe"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Aspnet_regsql.exe.config"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\UninstallRoles.sql"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state_perf.h"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.tlb"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\UninstallPersistSqlState.sql"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\UninstallSqlStateTemplate.sql"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\web.config"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallWebEventSqlProvider.sql"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\web_mediumtrust.config.default"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\web_mediumtrust.config"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\web_minimaltrust.config.default"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\web_minimaltrust.config"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallSqlState.sql"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\UninstallSqlState.sql"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\webengine.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\web_hightrust.config"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\web_hightrust.config.default"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\web_lowtrust.config"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\web_lowtrust.config.default"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_perf.ini"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state_perf.ini"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\AppConfig\App_LocalResources\SmtpSettings.aspx.resx"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_LocalResources\error.aspx.resx"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Permissions\App_LocalResources\createPermission.aspx.resx"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Providers\App_LocalResources\providerList.ascx.resx"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_GlobalResources\AppConfigCommon.resx"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Roles\App_LocalResources\manageSingleRole.aspx.resx"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\App_LocalResources\setUpAuthentication.aspx.resx"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Users\App_LocalResources\editUser.aspx.resx"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Wizard\App_LocalResources\wizardAddUser.ascx.resx"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_Data\GroupedProviders.xml"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\navigationBar.ascx"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\AppConfig\SmtpSettings.aspx"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_Code\WebAdminPage.cs"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\WebAdminHelp.aspx"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\requiredBang.gif"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Permissions\managePermissions.aspx"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Providers\ProviderList.ascx"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Roles\manageSingleRole.aspx"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\security.aspx"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Users\addUser.aspx"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Wizard\wizardAddUser.ascx"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\alinkui.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\alink.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfdll.dll"=dword:00000001

"C:\WINDOWS\system32\dfshim.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Deployment.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\gacutil.exe.config"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ieexec.exe.config"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\csc.exe.config"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\cscompui.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cscompmgd.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\csc.exe"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cscomp.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cvtres.exe"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\CvtResUI.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.JScript.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\jsc.exe"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MSBuild.rsp"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Common.Tasks"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.CSharp.targets"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Engine.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Framework.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Tasks.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Utilities.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MSBuild\Microsoft.Build.Commontypes.xsd"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MSBuild\Microsoft.Build.Core.xsd"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.xsd"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\fusion.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsn.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\peverify.dll"=dword:00000001

"C:\Program Files\Internet Explorer\MUI409\mscorier.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Accessibility.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AdoNetDiag.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RedistList\FrameworkList.xml"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CasPol.exe"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ilasm.exe"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CLR.mof"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Thunk.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Security.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CORPerfMonExt.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CORPerfMonSymbols.h"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Culture.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CustomMarshalers.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\_dataperfcounters_shared12_neutral.h"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\_NetworkingPerfCounters.h"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Configuration.Install.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.Protocols.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Drawing.Design.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.ServiceProcess.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.RegularExpressions.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.Services.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.XML.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Design.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEExec.exe"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEExecRemote.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEHost.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IIEHost.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallUtilLib.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ISymWrapper.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordbc.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordbi.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorie.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorld.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorpe.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvc.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscortim.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\netfxsbs12.hkf"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ngen.exe"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\normalization.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\PerfCounter.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\sbscmp20_mscorwks.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\sbscmp20_perfcounter.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\SharedReg12.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\shfusion.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\SOS.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.OracleClient.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\_DataOracleClientPerfCounters_shared12_neutral.h"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.SqlXml.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Management.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Remoting.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\sysglobl.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.configuration.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Drawing.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Messaging.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Transactions.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.Mobile.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\TLBREF.DLL"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\WMINet_Utils.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\XPThemes.manifest"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\corperfmonsymbols.ini"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\_dataperfcounters_shared12_neutral.ini"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\_Networkingperfcounters.ini"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\_DataOracleClientPerfCounters_shared12_neutral.ini"=dword:00000001

"C:\WINDOWS\system32\MUI409\mscorees.dll"=dword:00000002

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MUI409\mscorsecr.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\shfusion.chm"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ShFusRes.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\regtlibv12.exe"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\vbc7ui.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\vbc.exe"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\vbc.exe.config"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualC.Dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.ldo"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorlib.ldo"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Web.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorie.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorld.dll"=dword:00000001

"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll"=dword:00000001

"C:\WINDOWS\system32\QuickTime.qts"=dword:00000001

"C:\WINDOWS\system32\QuickTimeVR.qtx"=dword:00000001

"C:\Program Files\QuickTime\QTSystem\Ir41_qc.dll"=dword:00000001

"C:\Program Files\QuickTime\QTSystem\Ir41_qcx.dll"=dword:00000001

"C:\WINDOWS\Downloaded Program Files\msgrchkr.dll"=dword:00000001

"C:\WINDOWS\system32\lsdelete.exe"=dword:00000001

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\UserChosenExecuteHandlers]

"H:\\?\IDE#CdRomPHILIPS_DVD+-RW_SDVD8431________________LX51____#5&e7f7ea4&0&0.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}+ShowPicturesOnArrival"="MSOpenFolder\\x4a0\xba5f\x3c1f\x1c7\"

"H:\\?\IDE#CdRomPHILIPS_DVD+-RW_SDVD8431________________LX51____#5&e7f7ea4&0&0.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}+PlayVideoFilesOnArrival"="MSOpenFolder\\x71d0\xba91\x3c1f\x1c7\"

"H:\\?\IDE#CdRomPHILIPS_DVD+-RW_SDVD8431________________LX51____#5&e7f7ea4&0&0.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}+PlayCDAudioOnArrival"="MSOpenFolder\\x9150\xbace\x3c1f\x1c7\"

"H:\\?\IDE#CdRomPHILIPS_DVD+-RW_SDVD8431________________LX51____#5&e7f7ea4&0&0.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}+HandleCDBurningOnArrival"="NeroAutoPlay2DataDisc\\xce0\xbb04\x3c1f\x1c7\"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\UserDefaults]

"H:\\?\IDE#CdRomPHILIPS_DVD+-RW_SDVD8431________________LJ41____#5&e7f7ea4&0&0.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}+PlayDVDMovieOnArrival"="IviDVDEventHandler"

"H:\\?\IDE#CdRomPHILIPS_DVD+-RW_SDVD8431________________LJ41____#5&e7f7ea4&0&0.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}+PlayVideoFilesOnArrival"="IviVideoCDHandler"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{115A6D1B-9CB4-B6CD-E452-6669B9837ED9}]

"bbbgohccjjdnbffbpgpagnekhidhlnbghaan"=hex:6a,61,6d,6d,65,68,61,66,63,61,66,6d,64,69,70,6a,69,66,6d,68,00,..

"abhfejdbodajgmmbinflffjegjhpgkcjac"=hex:6a,61,6d,6d,65,68,61,66,63,61,66,6d,64,69,70,6a,69,66,6d,68,00,..

"iabgohccjjdnbffbpg"=hex:61,61,00,01

"hahfejdbodajgmmb"=hex:61,61,00,01

"iangoionmihmpmbjgk"=hex:61,61,00,01

 

scanning hidden files ...

 

C:\WINDOWS\system32\protector.exe

C:\WINDOWS\system32\ntio256.sys

 

scan completed successfully

hidden files: 2

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\ntio256]

"ImagePath"="\??\C:\WINDOWS\system32\ntio256.sys"

 

Completion time: 2007-07-25 23:07:33 - machine was rebooted

C:\ComboFix-quarantined-files.txt ... 2007-07-25 23:07

C:\ComboFix2.txt ... 2007-07-25 16:37

 

--- E O F ---

 

 

and heres a hijack one

 

 

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 23:11:53, on 25/07/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

C:\WINDOWS\system32\tcpsvcs.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\System32\snmp.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\QuickTime\qttask.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Internet Download Manager\IDMan.exe

C:\Program Files\Internet Download Manager\IEMonitor.exe

C:\WINDOWS\system32\notepad.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe

C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32Info.exe

C:\Documents and Settings\NEW USER\My Documents\HiJackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.myspace.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;<local>

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll

O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll

O4 - HKLM\..\Run: [XoftSpySE] -C:\Program Files\XoftSpySE\xoftspy.exe -s

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKCU\..\Run: [msnmsgr] -"C:\Program Files\MSN Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [iDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html

O8 - Extra context menu item: Download All Links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm

O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm

O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612...ex/qtplugin.cab

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll

O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.co.uk/SnapfishUKActivia.cab

O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB...l_v1-0-3-48.cab

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by122w.bay122.mail.live.com/mail/re...es/MsnPUpld.cab

O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1164066532038

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1145451077770

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {A8482EAF-A1F3-4934-AE3F-56EB195A50BF} (DeskUpdate - Activex Control) - http://support.fujitsu-siemens.de/DeskUpda...api/activex.cab

O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.telewest.co.uk/motive/files/MotivePreQual.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://213.129.66.245/activex/AMC.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab

O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab

O20 - Winlogon Notify: mljklmj - mljklmj.dll (file missing)

O20 - Winlogon Notify: winrzf32 - C:\WINDOWS\

O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

O23 - Service: Adobe LM Service - Unknown owner - -"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe" (file missing)

O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - Unknown owner - -C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe (file missing)

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - Unknown owner - -C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe (file missing)

O23 - Service: AVG E-mail Scanner (AVGEMS) - Unknown owner - -C:\PROGRA~1\Grisoft\AVG7\avgemc.exe (file missing)

O23 - Service: Google Updater Service (gusvc) - Unknown owner - -"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" (file missing)

O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - -"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe" (file missing)

O23 - Service: KService - Unknown owner - -"C:\Program Files\Kontiki\KService.exe" (file missing)

O23 - Service: Messenger Sharing Folders USN Journal Reader service (usnjsvc) - Unknown owner - -"C:\Program Files\MSN Messenger\usnsvc.exe" (file missing)

O23 - Service: Windows Media Player Network Sharing Service (WMPNetworkSvc) - Unknown owner - -C:\Program Files\Windows Media Player\WMPNetwk.exe (file missing)

 

--

End of file - 9167 bytes

 

 

Share this post


Link to post
Share on other sites

oh and in my start menu my shut down button has disappeared and all i have is a log off button, when im the only user on here!

Share this post


Link to post
Share on other sites

Hi

 

One or more of the identified infections is a backdoor trojan.

 

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

 

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

 

Though the Trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

 

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

When Should I Format, How Should I Reinstall

 

However, if you do not have the resources to reinstall your computer and would like me to attempt to clean it, I will be happy to do so.

Should you have any questions, please feel free to ask.

 

Please let us know what you have decided to do in your next post.

Share this post


Link to post
Share on other sites

hi yeah im gonna attempt to back up my musis and movies and pictures then im gonna reinstall windows.

good job i dont keep personal info on my laptop

thanks for all your help

 

Leila

Share this post


Link to post
Share on other sites

Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

 

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

 

Everyone else please begin a New Topic.

Share this post


Link to post
Share on other sites
Guest
This topic is now closed to further replies.
Sign in to follow this  
Followers 0