-
problem booting up
My daughter has an HP, running Win 98, now all of a sudden when she boots up, it will go to the desktop then a series of windows start popping up that say "This program has performed an illegal function, etc..." The first box is headed Explorer, then P2P networking, then Explorer again, then Xaupdate, then GMT. After closing all those windows, it goes to the desktop but there are no icons at all, and no start button. You cannot shut down, have to turn it off at the unit. Help!
-
jj, run a virus scan then Adaware/Spybot then Scan Disk and Defrag then post back.
Take Care:)
-
Yes, you do have some spyware, GMT is Gator,and you may have more due to P2P networking. Something was installed, and it opened the gate to others.
Get SpyBot Search & Destroy, free. Install it, update it, then do the scan, remove all items checked off.
After Spybot is done, get HijackThis installed, then post the log on here, other bad things may exist or may be running.
-
thanks deltree and mark, I am working on those items you suggested and will post back.
-
ok, I think I'm stuck now. I ran disk defrag and disk cleanup, I was able to get to those from safe mode, but I can't run my cd-rom cause the driver doesn't load in safe mode. I copied the Spybot program onto cd cause it was too big to go on a floppy and now I can't use it cause of the cd-rom. What do I do now? jj
-
In Safe mode:
-Copy both the oakcdrom.sys file(located in C:\Windows\Command\EBD) and the mscdex.exe file
(located in C:\Windows\Command) to the root folder (C:\).
-Go to Start/Run, type sysedit in the box, click OK, type LH c:\mscdex.exe /D:IDECD1 in the autoexec.bat window, close the autoexec.bat window, type device=c:\oakcdrom.sys /D:IDECD1 in the config.sys window, and close System Config. Editor.
-Restart the computer, press and hold the CTRL key, select 'Command prompt only' from the startup menu, press Enter, at the C:\> prompt type win/d:m and press Enter to start Safe mode.
You should now be able to use your CD-ROM drive in Safe mode.
-
Thanks, i'll try it right now.
-
ok, question. I think the cd rom drive on that computer is designated as drive M. Does that change anything i should type? I did notice a line in the autoexec.bat that says rem mscdex.exe and the rest of that and it says L:M at the end. Doesn't that mean my cd rom is M? I am waiting to type the commands until I hear back. I have copied the files to c:\ jj
-
If only one hard drive(C) is shown in Safe mode and the letter M was not manually assigned to the CD-ROM drive, then use the letter D and see if that works.
If not, then try M
-
The hard drive went out once in this pc and i remember the repair guy saying that he partitioned the hard drive into c and d so that all info would not be lost (?) if it did that again. What would it say in the autoexec.bat or config.sys to determine if M is the cdrom? Lastdrive=M?
-
I'm not sure exactly what it will say in either file.
My system's autoexec.bat and config.sys files are both empty, and I've never used them for doing anything in Win 98.
One way to tell what the CD-ROM drive's letter is to start with a Windows boot floppy inserted, select 'Start With CD-ROM Support', and use the letter that's assigned to the CD-ROM drive.
If it does not work, then use the one that's alphabetically before it.
-
Since you've already got a line for Mscdex.exe in the Autoexec.bat file, you can use it.
Delete the REM from in front of the Mscdex.exe line, exit and save the changes.
Make sure the /D:xxxxx is the same in both the Autoexec.bat and Config.sys files.
The /L:M in your existing line in the Autoexec.bat file is to assign drive letter M to the CD-ROM drive. Without the /L:x switch in the Mscdex.exe command line the CD-ROM drive will automatically be assigned to the next available drive letter. For example, if you've got C: and D: assigned to the hard drive(s), the CD-ROM drive will be made the E: drive.
-
i'm confused now. I did determine that my cdrom drive is f. So that string of info that goes c:\mscdex.exe /d:xxxxxxx -- am i supposed to put d in there or f? I guess it worked ok cause i was able to read the directory of my f: drive from dos prompt, and it had Spybot.exe but my computer said it has to run under win 32 when I tried to open it up. When I boot up in safe mode, I still can't see the cd rom drive in MY Computer or Explorer. I must still be doing something wrong and I can't run Spybot until I am able to use my cdrom drive under Safe Mode.
-
Ok, since you've got the CD-ROM drive accessable, why not copy the file to the hard drive in DOS, then run the program in Windows.
To copy the file to a \Temp directory on the hard drive, use the following commands after booting from the boot disk:
MD C:\TEMP
COPY F:\SPYBOT.EXE C:\TEMP
Restart the computer, open Windows Explorer, go to the new \Temp directory, double click on the Spybot.exe file and see if it will run.
The command line for Mscdex.exe breaks down like this:
C:\MSCDEX.EXE /D:MSCD001 /L:M
C:\MSCDEX.EXE - That's the excecutable, the program itself.
/D:MSCD001 - That part is "naming" the CD-ROM device. The name can be anything you want up to 8 characters. The D: indicates Device Name, the MSCD001 is the name.
/L:M This part assigns the drive letter to the CD-ROM drive. This part is not required, unless you want to specify which drive letter the CD-ROM drive gets. In this case, the CD-ROM drive is being assigned drive letter M.
-
ok, hopefully this will work, but I have to leave for work right now, so I'll try it and post back in the morning some time. Thanks, jj
-
Well, I am making some progress. I was able to run Spybot and it eliminated some of the problems but I still have two windows that open titled Explorer, as soon as the desktop comes up. After closing them I still cant get any icons on the desktop or a start button. What could the problem be?
-
See if any more spyware can be removed with Ad-aware and CWShredder.
Also, run the AV program to remove any viruses.
If the problem still happens and it started within the last 5 days, then hold down the Ctrl key during startup, select 'Command prompt only', press Enter, type scanreg /restore at the C:\> prompt and press Enter, select a Registry that predates the problem, and press Enter.
If no luck, then reinstall Windows on top of itself.
-
2 questions,
can you only go to a predated registry if the problem happened in the last 5 days, cause it started longer ago than that.
and, if I reinstall Windows over itself, do I lose everything I have on the computer?
I thought I had made some progress, but i'm still having all those windows about illegal operation coming up when I boot up.
Would it do any good to take it in somewhere and have it looked at, or would they just do what I am getting from you guys.
I'm getting very frustrated.......
-
Unless previously changed, the registry is only saved for (5) days.
If you re-install Window$ over itself, you will not lose everything.
IF you do a FDISK or FORMAT, you WILL lose everything on the drive you FDISK or FORMAT.
If you take it somewhere, they will do the same things we suggest- except, they will probably format to get a clean install. And, there will go everything on your computer.
-
The only disk i can find is titled "Windows 98 SE update". Will that work or should I use the recovery disk that came with the HP computer?
-
Can you get Windows to start in safe mode? If so, you can use MSCONFIG to disable all non-windows programs that run at startup. Hopefully this would allow starting Windows normally. To start MSCONFIG, click on Start - Run and type in MSCONFIG. Go to the Startup tab and start taking check marks out of the boxes. You could take the check marks out of all the boxes and restart. If Windows starts normally, start putting the check marks back in one at a time (restarting after each one) to see which one is interfering.
The Windows Update CD probably won't work. It has to be run in Windows, and the system won't start Windows.
The Restore disks will most likely remove everything from the computer and put it back to the way is was when it left the factory - same as formating the hard drive. There may be an option on the Restore disk(s) to do a "repair" installation without wiping out everything on the drive.
Re-installing Windows over the existing installation (over-installing) may not fix the problems. If the problem is being caused by a program that's trying to run at Windows startup, the over-install isn't likely to stop the offending program from running at startup.
The files necessary to over-install Windows should be on the hard drive already, in the C:\Windows\Options\Cabs directory. The problem with using these files is that they are most likely for Windows 98 First Edition. If the Windows 98 Second Edition Updates CD was run & installed on this computer the computer is now running Windows 98SE. Mixing the two versions would not be a good idea.
Anytime you're installing/over-installing Windows there's a possibility of something going wrong, sometimes so wrong that everything on the drive is lost. I've done many over-installs, most of which have gone well, but there's always the possibility.
Any reputable shop you take the computer to would do pretty much what's been suggested here already. If you inform them that you do not want the drive formatted, they should not format it. A reputable shop would not format the drive without your permission.
-
ok, here is the status with my computer. I reran Spybot, adaware, cw shredder, and a virus scan. No change there. Then I tried disabling all startup items in msconfig and windows still will not start normally, but i did eliminate some of the illegal function windows that came up on startup. Now there are only two, and both are titled Explorer at the top. Got any more ideas? I guess my last resort would be to throw in the recovery disk and hope theres an option to repair without fomatting.
-
jj, you might try this in DOS:
scanreg /fix or scanreg /opt/fix or scanreg /? and see what you come up with? as of now it looks like you may have to do and f-disk etc.?
Take Care:)
https://discussions.virtualdr.com/
-
What will running scanreg accomplish?
-
jj, if you have a problem it may pick it up and help you with the problem.I would even run scanreg /troubleshoot for you have tried just about everything.
Take Care http://pages.prodigy.net/rogerlori1/...ns/CUSSING.GIF
-
Here's what I got from HijackThis. Does all this mean anything to anyone?
Logfile of HijackThis v1.97.7
Scan saved at 11:28:15 AM, on 4/1/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\EARTHLINK 5.0\CONMGR.EXE
C:\TEMP\HIJ_0003.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.earthlink.net/partner/mor...on/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.earthlink.net/partner/mor...on/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.zestyfind.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.earthlink.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink.net/partner/mor...on/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://rd.yahoo.com/customize/ymsgr/...//my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/ymsgr/...ch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.earthlink.net/partner/mor...on/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Yahoo!
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://rd.yahoo.com/customize/ymsgr/.../www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 24.243.136.152
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost;<local>
R3 - URLSearchHook: (no name) - {D6DFF6D8-B94B-4720-B730-1C38C7065C3B} - (no file)
F1 - win.ini: run=hpfsched
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\VSCSHELLEXTENSION.DLL
O3 - Toolbar: (no name) - {224530A0-C9CB-4AEE-9C0F-54AC1B533211} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Keyboard Manager] C:\Program Files\Netropa\One-touch Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [ConMgr.exe] "C:\PROGRAM FILES\EARTHLINK 5.0\CONMGR.EXE"
O4 - HKLM\..\Run: [WUSB11B.exe] C:\Program Files\WUSB11 WLAN Monitor\WUSB11B.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [P2P NETWORKING] C:\WINDOWS\SYSTEM\P2P NETWORKING\P2P NETWORKING.EXE /AUTOSTART
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE"
O4 - HKCU\..\Run: [Extreme Messenger for AIM] C:\PROGRAM FILES\EXTREME MESSENGER\EXTREMEMESSENGER.exe nosplash
O4 - Startup: Event Reminder.lnk = C:\pmw\PMREMIND.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmsearch.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmsimilar.html
O8 - Extra context menu item: Backward &Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmtrans.html
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O10 - Unknown file in Winsock LSP: c:\windows\system\inetadpt.dll
O10 - Unknown file in Winsock LSP: c:\windows\system\inetadpt.dll
O10 - Unknown file in Winsock LSP: c:\windows\system\inetadpt.dll
O10 - Unknown file in Winsock LSP: c:\windows\system\inetadpt.dll
O10 - Unknown file in Winsock LSP: c:\windows\system\inetadpt.dll
O10 - Unknown file in Winsock LSP: c:\windows\system\inetadpt.dll
O10 - Unknown file in Winsock LSP: c:\windows\system\inetadpt.dll
O12 - Plugin for .mp3: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {50F65670-1729-11D2-A51F-0020AFE5D502} (ForumChat) - http://objects.compuserve.com/chat/RTCChat.cab
O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) -
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst.cab
O16 - DPF: {CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_02) -
O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - https://rr.esecurecare.net/rnt/rnl/java/RntX.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yaho...mmapi_0727.dll
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/downlo...22/wmv9VCM.CAB
O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.aimphuck.com/Imbum_bw.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 207.69.188.185,207.69.188.186,207.69.188.187
-
To Cliffh, it looks like I am running 98 SE. Does that mean I could use the disk I have to reload windows?
-
Reinstalling windows will not help you, until you get rid of this file. You cannot delete this file while in windows [Safe Mode, either].
O10 - Unknown file in Winsock LSP: c:\windows\system\inetadpt.dll
Restart in Dos Mode and use this command.
del c:\windows\system\inetadpt.dll
Reboot and run LSPfix.Exe
-
And the winner is...............Markp62! That fixed it, deleting that file and then running LSPFix. Thank you so much. You guys really know your stuff! I have another problem now though, and it happens during startup. I think through the process of running the spyware programs I deleted something that I shouldn't have. Before Windows opens up, during the black screen part, it hangs up and says it can't find this file: CDAINT2F.VXD and it says to reinstall the program that is associated with it. When I went to Start...Find....and typed it in, it came up with tons of files with that extension, and it looked like they were all Windows files. What should I do to remedy this?
-
I believe that file was associated with C-Dilla [spyware]. Go to Start\Run, type in Regedit and press Enter. Navigate to this key.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD
Expand that Key and look for CDAINT2F on the left, when found delete it.
If, for some reason that it isn't there, and it should be, look here.
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SharedDLLs
If there, it will be listed on the right. Delete the entire line that has it.
-
boot up problem
Markp62, I just now got a chance to try looking for that file in regedit and could not find it at all. Is there anything else i can try?
-
I forgot to say that when I looked under the second option, there were TONS of files listed on the right and the first one was java something, then a couple of others (not the one i was looking for though) and then there were c:\program...... and then c:\windows...... Would it be one of those?
-
It could be. See that grey line at the top of Regedit, between the word Name and right next to the word Data, grab it with the mouse and you can move it over. You'll see more than just C:\Windows or C:\Program Files become visible.
Alternately in Regedit at the toolbar, go to Edit then Find, and let it search for CDAINT2F for you.
-
Finally I got a chance to look at regedit again, and I just don't see that file you talked about. Is there any way I could email a copy of all the files to you or should I post it on here so maybe you could see if something is wrong in there?
-
All of what you are about to do occurs in the left pane.
Navigate to this Key:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD
Make sure the VXD folder is highlighted on the left. Go to the toolbar of Regedit at Registry\Export Registry File. A file save window will open, give it the name "VXD" and click OK.
Do the same for the below, highlighting the SharedDLLS folder, give it the name "Shared" when Exporting;
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SharedDLLs
Now go to the folder where you saved them. Right click on them and select Edit, and each one will open in Notepad.
Copy and Paste both files onto here.
-
OK, i will send those regedit files now, but they will be in batches cause it was too large to send all at once. I have a couple more questions though. First, what is the best pop-up stopper to use? I have windows that pop up even when i'm not logged onto the internet. Is that possible? Second, my home page when i sign in on the internet, keeps changing when i don't want it to. I keep resetting it to yahoo, but it just changes at random. Why is that?
And last, how do you enable the windows feature so that the computer will "sleep" again. It hasn't done that for a long time, but I really would like to get that going again.
Here are the first set of files:
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SharedDLLs]
"c:\\windows\\SYSTEM\\mfc30.dll"=hex:01,00,00,00
"C:\\WINDOWS\\SYSTEM\\MFCANS32.DLL"=dword:00000005
"c:\\windows\\SYSTEM\\mfco30.dll"=hex:01,00,00,00
"c:\\windows\\SYSTEM\\mfcd30.dll"=hex:01,00,00,00
"c:\\windows\\SYSTEM\\cabinet.dll"=hex:01,00,00,00
"c:\\windows\\SYSTEM\\mfcn30.dll"=hex:01,00,00,00
"C:\\WINDOWS\\SYSTEM\\MFCUIA32.DLL"=dword:00000005
"c:\\WINDOWS\\SYSTEM\\mfc42.dll"=dword:0000001f
"c:\\WINDOWS\\SYSTEM\\riched32.dll"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\msvcrt.dll"=dword:00000024
"c:\\WINDOWS\\SYSTEM\\Msvcrt40.dll"=dword:00000009
"c:\\WINDOWS\\SYSTEM\\olepro32.dll"=dword:0000000f
"C:\\Program Files\\Common Files\\Microsoft Shared\\Triedit\\TRIEDIT.DLL"=dword:00002710
"C:\\Program Files\\Common Files\\Microsoft Shared\\Triedit\\DHTMLED.OCX"=dword:00002710
"C:\\WINDOWS\\SYSTEM\\DELMODEM.EXE"=dword:00000005
"C:\\WINDOWS\\Options\\Cabs\\LTCOM.VXD"=dword:00000006
"C:\\WINDOWS\\Options\\Cabs\\LTMODEM.VXD"=dword:00000006
"C:\\WINDOWS\\Options\\Cabs\\LTVCD.VXD"=dword:00000006
"C:\\WINDOWS\\Options\\Cabs\\LTHOMOL.EXE"=dword:00000003
"C:\\WINDOWS\\Options\\Cabs\\LTMSG.EXE"=dword:00000003
"C:\\WINDOWS\\Options\\Cabs\\LTREMOVE.EXE"=dword:0000000b
"C:\\WINDOWS\\Options\\Cabs\\DELMODEM.EXE"=dword:00000006
"C:\\WINDOWS\\SYSTEM\\LTCOM.VXD"=dword:00000005
"C:\\WINDOWS\\SYSTEM\\LTMODEM.VXD"=dword:00000005
"C:\\WINDOWS\\SYSTEM\\LTVCD.VXD"=dword:00000005
"C:\\WINDOWS\\SYSTEM\\LTHOMOL.EXE"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\LTMSG.EXE"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\LTREMOVE.EXE"=dword:0000000a
"C:\\WINDOWS\\INF\\LTDF.INF"=dword:00000003
"C:\\WINDOWS\\INF\\LTDFI.INF"=dword:00000003
"C:\\WINDOWS\\INF\\LTDFT.INF"=dword:00000003
"C:\\WINDOWS\\INF\\LTMODEM.INF"=dword:00000003
"C:\\WINDOWS\\INF\\LTPORTS.INF"=dword:00000003
"C:\\WINDOWS\\INF\\LTWAVE.INF"=dword:00000003
"c:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\WksCal.exe"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\Equation\\eqnedt32.exe"=dword:00000002
"C:\\Program Files\\Common Files\\Microsoft Shared\\msdraw\\MSDRAW.EXE"=dword:00000002
"c:\\Program Files\\Microsoft Works\\msworks.exe"=dword:00000001
"c:\\Program Files\\Microsoft Works\\1033\\WkGenLng.dll"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\1033\\nfmtlng.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\Textconv\\works432.cnv"=dword:00000003
"C:\\Program Files\\Common Files\\Microsoft Shared\\Textconv\\mswrd832.cnv"=dword:00000003
"c:\\Program Files\\Common Files\\Microsoft Shared\\Proof\\mssp2_ea.lex"=dword:00000002
"c:\\Program Files\\Common Files\\Microsoft Shared\\Proof\\mssp2_en.lex"=dword:00000002
"c:\\Program Files\\Common Files\\Microsoft Shared\\Proof\\MSSP232.DLL"=dword:00000003
"c:\\Program Files\\Common Files\\Microsoft Shared\\Proof\\MSSpell3.dll"=dword:00000004
"c:\\Program Files\\Common Files\\Microsoft Shared\\Proof\\MSsp3en.lex"=dword:00000004
"c:\\Program Files\\Common Files\\Microsoft Shared\\Proof\\MSsp3ena.lex"=dword:00000004
"c:\\Program Files\\Common Files\\Microsoft Shared\\Proof\\CSAPI3T1.DLL"=dword:00000005
"c:\\Program Files\\Common Files\\Microsoft Shared\\Proof\\MSTHES3.DLL"=dword:00000003
"c:\\Program Files\\Common Files\\Microsoft Shared\\Proof\\MSTH3AM.LEX"=dword:00000003
"c:\\Program Files\\Common Files\\Microsoft Shared\\Proof\\MSTH3BR.LEX"=dword:00000003
"c:\\Program Files\\Common Files\\Microsoft Shared\\Proof\\CTAPI3T2.DLL"=dword:00000003
"c:\\Program Files\\Common Files\\Microsoft Shared\\Proof\\msgren32.dll"=dword:00000002
"c:\\Program Files\\Common Files\\Microsoft Shared\\Proof\\msgr_en.lex"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\msvcp60.dll"=dword:0000000d
"c:\\WINDOWS\\SYSTEM\\comcat.dll"=dword:0000000c
"c:\\WINDOWS\\SYSTEM\\MSLS2.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\msls31.dll"=dword:00000007
"c:\\WINDOWS\\SYSTEM\\riched20.dll"=dword:00000008
"c:\\WINDOWS\\SYSTEM\\usp10.dll"=dword:00000007
"c:\\WINDOWS\\SYSTEM\\ochlp30e.dll"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\ochlp30t.dll"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\hlp95en.dll"=dword:00000002
"c:\\Program Files\\Microsoft Works\\Wkmmwdb.dll"=dword:00000001
"c:\\Program Files\\Microsoft Works\\WksGen.dll"=dword:00000001
"c:\\Program Files\\Microsoft Works\\wkmerge.dll"=dword:00000001
"c:\\Program Files\\Microsoft Works\\workssvc.dll"=dword:00000001
"c:\\Program Files\\Microsoft Works\\wklnps.dll"=dword:00000001
"c:\\Program Files\\Microsoft Works\\wklnac.dll"=dword:00000001
"c:\\Program Files\\Microsoft Works\\vswitch.wav"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\WkCalAc.dll"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\wkcalrem.exe"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\wkcalsvc.dll"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\WkCalOle.dll"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\WkCalPS.dll"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\Sound\\Banner.wav"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\WkCalVp.dll"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\WkCalImp.dll"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\HtmlLite.dll"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\1033\\WkGenLng.dll"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\WkCalPse.dll"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\WksCal.chm"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\wkscal.aw"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\mswkscal.hlp"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\WksGen.dll"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\1033\\WkCalHol.txt"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\1033\\WkCalLng.dll"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\1033\\WorksPSS.chm"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\note-it\\NOTE-IT.EXE"=dword:00000002
"c:\\Program Files\\Common Files\\Microsoft Shared\\Note-It\\note-it.hlp"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\EulaReg.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\wkerlang.dll"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\wks5eula.txt"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\wks5warr.htm"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\WordArt\\WRDART32.EXE"=dword:00000003
-
And...........
"c:\\WINDOWS\\SYSTEM\\pubole32.dll"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Grphflt\\Emfimp32.flt"=dword:00000002
"c:\\Program Files\\Common Files\\Microsoft Shared\\Grphflt\\fpx32.flt"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Grphflt\\Gifimp32.flt"=dword:00000004
"c:\\Program Files\\Common Files\\Microsoft Shared\\Grphflt\\Jpegim32.flt"=dword:00000004
"c:\\Program Files\\Common Files\\Microsoft Shared\\Grphflt\\Pcdimp32.flt"=dword:00000003
"c:\\Program Files\\Common Files\\Microsoft Shared\\Grphflt\\Pcximp32.flt"=dword:00000003
"c:\\Program Files\\Common Files\\Microsoft Shared\\Grphflt\\Png32.flt"=dword:00000002
"c:\\Program Files\\Common Files\\Microsoft Shared\\Grphflt\\Tiffim32.flt"=dword:00000005
"c:\\Program Files\\Common Files\\Microsoft Shared\\Grphflt\\Wmfimp32.flt"=dword:00000005
"c:\\Program Files\\Common Files\\Microsoft Shared\\Grphflt\\Bmpimp32.flt"=dword:00000005
"c:\\WINDOWS\\SYSTEM\\Pcdlib32.dll"=dword:00000004
"C:\\Program Files\\Common Files\\Microsoft Shared\\Textconv\\mswrd632.cnv"=dword:00000003
"C:\\Program Files\\Common Files\\Microsoft Shared\\textconv\\wpft532.cnv"=dword:00000003
"C:\\Program Files\\Common Files\\Microsoft Shared\\Textconv\\wpft632.cnv"=dword:00000003
"c:\\Program Files\\Common Files\\Microsoft Shared\\TextConv\\RECOVR32.CNV"=dword:00000004
"C:\\Program Files\\Common Files\\Microsoft Shared\\TextConv\\HTML32.CNV"=dword:00000004
"c:\\Program Files\\Common Files\\Microsoft Shared\\TextConv\\WRD6EX32.CNV"=dword:00000004
"C:\\Program Files\\Common Files\\Microsoft Shared\\Textconv\\works332.cnv"=dword:00000002
"c:\\Program Files\\Common Files\\Microsoft Shared\\Textconv\\Works532.cnv"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Textconv\\wkcvqd.dll"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Textconv\\wkcvqrtf.dll"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\DAO\\dao360.dll"=dword:00000004
"c:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\aw.dll"=dword:00000002
"c:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\NumFmt.dll"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\wkhlp.dll"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Artgalry\\ARTGALRY.DLL"=dword:00000002
"c:\\Program Files\\Common Files\\Microsoft Shared\\Artgalry\\ARTGALRY.EXE"=dword:00000005
"C:\\PROGRA~1\\COMMON~1\\MICROS~1\\MSInfo\\msinfo32.exe"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\oleaut32.dll"=dword:00000013
"C:\\WINDOWS\\SYSTEM\\ir50_32.dll"=dword:00000004
"C:\\WINDOWS\\SYSTEM\\ir32_32.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\l3codeca.acm"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\SHFOLDER.DLL"=dword:00000004
"C:\\WINDOWS\\SYSTEM\\pncrt.dll"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\COMCTL32.OCX"=dword:00000004
"C:\\WINDOWS\\SYSTEM\\COMDLG32.OCX"=dword:00000009
"C:\\WINDOWS\\SYSTEM\\CUEXML.OCX"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\FTP40.OCX"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\HTTP35.OCX"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\IPDAEM35.OCX"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\IPINFO35.OCX"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\MSMAPI32.OCX"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\msscript.ocx"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\NETCOD35.OCX"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\Richtx32.ocx"=dword:00000003
"C:\\WINDOWS\\SYSTEM\\SPIN32.OCX"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\TABCTL32.OCX"=dword:00000004
"C:\\WINDOWS\\SYSTEM\\THREED32.OCX"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\Inetwh32.dll"=dword:00000005
"C:\\Program Files\\Common Files\\Smith Micro Shared\\SMCCODE.INI"=dword:00000001
"C:\\Program Files\\Common Files\\Smith Micro Shared\\Smtele.ini"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\SMComm36.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Smith Micro Shared\\SMLOC32.DLL"=dword:00000001
"C:\\Program Files\\Common Files\\Smith Micro Shared\\SMTapi.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\Dao\\DAO350.DLL"=dword:00000004
"C:\\WINDOWS\\SYSTEM\\SNMPAPI.DLL"=dword:00000001
"c:\\windows\\system\\iosubsys\\Cdr4vsd.vxd"=dword:00000005
"C:\\WINDOWS\\SYSTEM\\CDR4DLL.DLL"=dword:00000005
"C:\\WINDOWS\\Options\\Cabs\\LTMDMUI.DLL"=dword:00000003
"C:\\WINDOWS\\Options\\Cabs\\LTMDM462.CAT"=dword:00000004
"C:\\WINDOWS\\SYSTEM\\LTMDMUI.DLL"=dword:00000003
"C:\\WINDOWS\\SYSTEM\\LTMDM462.CAT"=dword:00000003
"C:\\WINDOWS\\INF\\LTMDM462.INF"=dword:00000004
"C:\\WINDOWS\\Options\\Cabs\\LTDSLLAN.SYS"=dword:00000005
"C:\\WINDOWS\\Options\\Cabs\\LTDSP1.AA"=dword:00000005
"C:\\WINDOWS\\Options\\Cabs\\LTDSP1.E"=dword:00000005
"C:\\WINDOWS\\Options\\Cabs\\LTDSP2.AA"=dword:00000005
"C:\\WINDOWS\\Options\\Cabs\\LTDSP2.E"=dword:00000005
"C:\\WINDOWS\\Options\\Cabs\\DEL_MF.EXE"=dword:00000005
"C:\\WINDOWS\\Options\\Cabs\\LTLAN464.CAT"=dword:00000004
"C:\\WINDOWS\\INF\\LTLAN464.INF"=dword:00000004
"C:\\WINDOWS\\SYSTEM\\LTDAEMON.EXE"=dword:00000005
"C:\\WINDOWS\\SYSTEM\\WWAPPLET.CPL"=dword:00000005
"C:\\WINDOWS\\Options\\Cabs\\LTDSP22.E"=dword:00000003
"C:\\WINDOWS\\Options\\Cabs\\LTDSP22.AA"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\atl.dll"=dword:00000016
"C:\\WINDOWS\\SYSTEM\\REGSVR32.EXE"=dword:0000000f
"c:\\WINDOWS\\SYSTEM\\msvcrt20.dll"=dword:0000000c
"C:\\Program Files\\Creative\\ShareDLL\\CTPROP.DLL"=dword:00000007
"C:\\Program Files\\Creative\\ShareDLL\\CTRMENU.DLL"=dword:00000005
"C:\\Program Files\\Creative\\ShareDLL\\CTRES32.DLL"=dword:0000000b
"C:\\Program Files\\Creative\\ShareDLL\\CTPRORES.DLL"=dword:00000007
"C:\\Program Files\\Creative\\ShareDLL\\CTSKIN.DLL"=dword:00000007
"C:\\Program Files\\Creative\\ShareDLL\\CTSKINX.DLL"=dword:00000007
"C:\\Program Files\\Creative\\ShareDLL\\CTPROP.HLP"=dword:00000007
"C:\\Program Files\\Creative\\ShareDLL\\CTSPEA32.DLL"=dword:00000005
"C:\\WINDOWS\\SYSTEM\\clrviddc.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\decdnet.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\RA3214_4.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\ra3228_8.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\ra32clv1.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\ra32dnet.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\ra32rv10.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\ra32sipr.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\rarv1032.dll"=dword:00000001
"C:\\Program Files\\Creative\\ShareDLL\\CtNotify.exe"=dword:00000003
"C:\\Program Files\\Creative\\ShareDLL\\CtCdPwr.dll"=dword:00000003
"C:\\Program Files\\Creative\\ShareDLL\\MediaDet.exe"=dword:00000003
"C:\\WINDOWS\\SYSTEM\\CTDetect.cpl"=dword:00000004
"C:\\WINDOWS\\SYSTEM\\CTDetRes.dll"=dword:00000004
"C:\\Program Files\\Creative\\ShareDLL\\MediaDet.log"=dword:00000003
"C:\\WINDOWS\\SYSTEM\\CTDetect.hlp"=dword:00000003
"C:\\WINDOWS\\CTDEL.EXE"=dword:00000002
"C:\\WINDOWS\\CTCCW.DLL"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\CTL3D.DLL"=dword:00000004
"C:\\WINDOWS\\SYSTEM\\CTWFLT32.DLL"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\ctl3d32.dll"=dword:00000003
"C:\\WINDOWS\\CTRES.DLL"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\AUDIOHQ.CPL"=dword:00000002
"C:\\WINDOWS\\Media\\CTMELODY.WAV"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\Roboex32.dll"=dword:00000005
"C:\\WINDOWS\\Options\\Cabs\\LTLAN462.CAT"=dword:00000001
"C:\\WINDOWS\\INF\\LTMFL462.INF"=dword:00000001
"C:\\WINDOWS\\INF\\LTLAN462.INF"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\SFMAN.DAT"=dword:00000000
"C:\\WINDOWS\\SYSTEM\\SFCVRT32.DLL"=dword:00000000
"C:\\Program Files\\Creative\\ShareDLL\\PFMOD.DLL"=dword:00000000
"C:\\Program Files\\Creative\\ShareDLL\\PFMOD16.DLL"=dword:00000000
"C:\\WINDOWS\\CTRES32.DLL"=dword:00000000
"C:\\Program Files\\Creative\\ShareDLL\\AHQ\\CT8008.AHQ"=dword:00000000
"C:\\Program Files\\Creative\\ShareDLL\\AHQ\\CTKEYBD.AHQ"=dword:00000000
"C:\\Program Files\\Creative\\ShareDLL\\AHQ\\CTLED32.AHQ"=dword:00000000
"C:\\Program Files\\Creative\\ShareDLL\\AHQ\\CTLEDR32.DLL"=dword:00000000
"C:\\Program Files\\Creative\\ShareDLL\\AHQ\\CTP10RES.DLL"=dword:00000000
"C:\\Program Files\\Creative\\ShareDLL\\AHQ\\CTP8RES.DLL"=dword:00000000
"C:\\Program Files\\Creative\\ShareDLL\\AHQ\\CUSTRES.DLL"=dword:00000000
"C:\\Program Files\\Creative\\ShareDLL\\AHQ\\AHQKBRES.DLL"=dword:00000000
"C:\\Program Files\\Creative\\ShareDLL\\AHQ\\CTFX10K1.AHQ"=dword:00000000
"C:\\Program Files\\Creative\\ShareDLL\\AHQ\\CTAEARES.DLL"=dword:00000000
"C:\\Program Files\\Creative\\ShareDLL\\AHQ\\CTAUTOEA.AHQ"=dword:00000000
"C:\\Program Files\\Creative\\ShareDLL\\AHQ\\CTSURES.DLL"=dword:00000000
"C:\\Program Files\\Creative\\ShareDLL\\AHQ\\CTSUSPK.AHQ"=dword:00000000
"C:\\Program Files\\Creative\\ShareDLL\\AHQ\\CTEO10K1.AHQ"=dword:00000000
"C:\\Program Files\\Creative\\ShareDLL\\AHQ\\CTEORES.DLL"=dword:00000000
"C:\\Program Files\\Creative\\ShareDLL\\AHQ\\CTDEVCON.EXE"=dword:00000000
"C:\\Program Files\\Creative\\ShareDLL\\AHQ\\CTFX10K1.EXE"=dword:00000000
"C:\\Program Files\\Creative\\ShareDLL\\AHQ\\CTKEYBD.EXE"=dword:00000000
"C:\\Program Files\\Creative\\ShareDLL\\AHQ\\CTLED.EXE"=dword:00000000
"C:\\Program Files\\Creative\\ShareDLL\\AHQ\\CTSFONT.EXE"=dword:00000000
"C:\\Program Files\\Creative\\ShareDLL\\AHQ\\CTDIGIO.AHQ"=dword:00000000
"C:\\Program Files\\Creative\\ShareDLL\\AHQ\\CTDORES.DLL"=dword:00000000
"C:\\WINDOWS\\SYSTEM\\AHQCPRES.DLL"=dword:00000000
"C:\\Program Files\\Creative\\ShareDLL\\SBLIVE.DLL"=dword:00000000
"C:\\WINDOWS\\SYSTEM\\POPUP.OCX"=dword:00000004
"C:\\WINDOWS\\SYSTEM\\WINGDE.DLL"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\WING.DLL"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\DVA.386"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\WINGDIB.DRV"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\WINGPAL.WND"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\WING32.DLL"=dword:0000000a
"C:\\WINDOWS\\SYSTEM\\MSG711.ACM"=dword:00000003
"C:\\WINDOWS\\SYSTEM\\MSADP32.ACM"=dword:00000003
"C:\\WINDOWS\\SYSTEM\\IMAADP32.ACM"=dword:00000003
"C:\\WINDOWS\\SYSTEM\\MSGSM32.ACM"=dword:00000003
"C:\\WINDOWS\\SYSTEM\\TSSOFT32.ACM"=dword:00000003
"C:\\WINDOWS\\SYSTEM\\MSACM32.DLL"=dword:00000003
"C:\\WINDOWS\\SYSTEM\\MSACM.DLL"=dword:00000003
"C:\\WINDOWS\\SYSTEM\\MSACM.DRV"=dword:00000003
-
and.....
..."C:\\Program Files\\Sierra On-Line\\CPUINF32.DLL"=dword:00000006
"C:\\Program Files\\Sierra On-Line\\EREG.DLL"=dword:00000007
"C:\\Program Files\\Sierra On-Line\\EREG3201.DLL"=dword:00000007
"C:\\Program Files\\Sierra On-Line\\REDIRECT.EXE"=dword:00000004
"C:\\Program Files\\Sierra On-Line\\SIGSPAT.EXE"=dword:00000006
"C:\\Program Files\\Sierra On-Line\\SUTIL32.EXE"=dword:00000004
"C:\\Program Files\\Sierra On-Line\\UTDEL32.EXE"=dword:00000004
"C:\\WINDOWS\\SYSTEM\\SIERRANW.DLL"=dword:00000004
"C:\\WINDOWS\\SYSTEM\\SNWVALID.DLL"=dword:00000004
"C:\\WINDOWS\\SYSTEM\\SNWVALID.HLP"=dword:00000002
"C:\\Program Files\\Common Files\\InstallShield\\engine\\6\\Intel 32\\corecomp.ini"=dword:00000012
"C:\\Program Files\\Common Files\\InstallShield\\engine\\6\\Intel 32\\ctor.dll"=dword:00000012
"C:\\Program Files\\Common Files\\InstallShield\\engine\\6\\Intel 32\\objectps.dll"=dword:00000012
"C:\\Program Files\\Common Files\\InstallShield\\engine\\6\\Intel 32\\iuser.dll"=dword:00000012
"C:\\Program Files\\Common Files\\InstallShield\\IScript\\iscript.dll"=dword:00000012
"C:\\Program Files\\Common Files\\InstallShield\\engine\\6\\Intel 32\\iKernel.exe"=dword:00000012
"c:\\WINDOWS\\SYSTEM\\asycfilt.dll"=dword:0000000c
"C:\\WINDOWS\\SYSTEM\\lmoufrc.dll"=dword:00000001
"C:\\WINDOWS\\system32\\drivers\\LHIDUSB.SYS"=dword:00000001
"C:\\WINDOWS\\system32\\drivers\\LCCFLTR.SYS"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LMOUSE32.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LMOUSE16.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LOGILANG.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\COMNCTR.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LGUICOM.DLL"=dword:00000001
"C:\\Program Files\\Common Files\\Logitech\\WebColct\\WebColct.exe"=dword:00000001
"C:\\Program Files\\Common Files\\Logitech\\WebColct\\WebColps.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Logitech\\WebColct\\NS3.LGM"=dword:00000001
"C:\\Program Files\\Common Files\\Logitech\\WebColct\\IE4.LGM"=dword:00000001
"C:\\Program Files\\Common Files\\Logitech\\WebColct\\IE3.LGM"=dword:00000001
"C:\\Program Files\\Common Files\\Logitech\\WebColct\\Opera.lgm"=dword:00000001
"C:\\Program Files\\Common Files\\Logitech\\WebColct\\IE5.LGM"=dword:00000001
"C:\\Program Files\\Common Files\\Logitech\\WebColct\\NS4.LGM"=dword:00000001
"C:\\Program Files\\Common Files\\Logitech\\WebColct\\NeoPlnet.lgm"=dword:00000001
"C:\\Program Files\\Common Files\\Logitech\\CdlsHand\\CdlsHand.exe"=dword:00000001
"C:\\Program Files\\Common Files\\Logitech\\CdlsHand\\CdlsHdps.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Logitech\\CdlsHand\\Cdlsres.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\FEELIT.DLL"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\proof\\msth32.dll"=dword:00000002
"C:\\Program Files\\Common Files\\Microsoft Shared\\proof\\MSTH_AM.LEX"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\equation\\EQNEDT32.HLP"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\textconv\\wnwrd232.cnv"=dword:00000002
"C:\\Program Files\\Common Files\\Microsoft Shared\\textconv\\WRITE32.CNV"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\textconv\\DOSWRD32.CNV"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\grphflt\\cgmimp32.flt"=dword:00000002
"c:\\Program Files\\Common Files\\Microsoft Shared\\Grphflt\\EPSIMP32.FLT"=dword:00000004
"c:\\Program Files\\Common Files\\Microsoft Shared\\Grphflt\\Wpgimp32.flt"=dword:00000003
"C:\\Program Files\\ReadIRIS\\REGISTRY.DLL"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Grphflt\\Cdrimp32.flt"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Grphflt\\Drwimp32.flt"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Grphflt\\Dxfimp32.flt"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Grphflt\\pictim32.flt"=dword:00000003
"c:\\Program Files\\Common Files\\Microsoft Shared\\Grphflt\\tgaimp32.flt"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Proof\\custom.dic"=dword:00000002
"c:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\wkswab.dll"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\mswkscal.wcd"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\Msvcirt.dll"=dword:0000000b
"C:\\WINDOWS\\SYSTEM\\MSVCP50.DLL"=dword:00000003
"C:\\WINDOWS\\SYSTEM\\iac25_32.ax"=dword:00000003
"C:\\Program Files\\Common Files\\Microsoft Shared\\Dao\\DAO2535.TLB"=dword:00000003
"C:\\Program Files\\Sierra On-Line\\WININET.DLL"=dword:00000002
"C:\\Program Files\\Sierra On-Line\\SIGSPAT.HLP"=dword:00000006
"C:\\Program Files\\Sierra On-Line\\SUTIL32.HLP"=dword:00000004
"C:\\WINDOWS\\SYSTEM\\IR41_QC.DLL"=dword:000003e8
"C:\\WINDOWS\\SYSTEM\\IR41_QCX.DLL"=dword:000003e8
"C:\\WINDOWS\\SYSTEM\\QuickTime.cpl"=dword:000003e7
"C:\\WINDOWS\\SYSTEM\\QuickTime.qts"=dword:000003e7
"C:\\WINDOWS\\SYSTEM\\INDEO4.QTX"=dword:000003e8
"C:\\WINDOWS\\SYSTEM\\QuickTime\\QuickTimeAuthoring.qtx"=dword:000003e7
"C:\\WINDOWS\\SYSTEM\\QuickTime\\QuickTimeCapture.qtx"=dword:000003e7
"C:\\WINDOWS\\SYSTEM\\QuickTime\\QuickTimeEffects.qtx"=dword:000003e7
"C:\\WINDOWS\\SYSTEM\\QuickTime\\QuickTimeImage.qtx"=dword:000003e7
"C:\\WINDOWS\\SYSTEM\\QuickTime\\QuickTimeMusic.qtx"=dword:000003e7
"C:\\WINDOWS\\SYSTEM\\QuickTime\\QuickTimeStreaming.qtx"=dword:000003e7
"C:\\WINDOWS\\SYSTEM\\QuickTime\\QuickTimeInternetExtras.qtx"=dword:000003e7
"C:\\WINDOWS\\SYSTEM\\QuickTime\\QTUninst.dll"=dword:000003e7
"C:\\WINDOWS\\SYSTEM\\QuickTime\\QuickTimeStreamingExtras.qtx"=dword:000003e7
"C:\\WINDOWS\\SYSTEM\\QuickTime\\QuickTimeStreamingAuthoring.qtx"=dword:000003e7
"C:\\WINDOWS\\SYSTEM\\QuickTime\\QuickTimeWebHelper.qtx"=dword:000003e7
"C:\\WINDOWS\\unvise32qt.exe"=dword:00000009
"c:\\WINDOWS\\SYSTEM\\Wininet.dll"=dword:00000005
"C:\\Program Files"=dword:00000001
"C:\\WINDOWS\\Fonts\\TT0178A_.TTF"=dword:00000001
"C:\\WINDOWS\\Fonts\\TT0178B_.TTF"=dword:00000001
"C:\\WINDOWS\\Fonts\\TT0180A_.TTF"=dword:00000001
"C:\\WINDOWS\\Fonts\\TT0180B_.TTF"=dword:00000001
"C:\\WINDOWS\\Fonts\\TT0181A_.TTF"=dword:00000001
"C:\\WINDOWS\\Fonts\\TT0181B_.TTF"=dword:00000001
"C:\\WINDOWS\\Fonts\\TT0179A_.TTF"=dword:00000001
"C:\\WINDOWS\\Fonts\\TT0179B_.TTF"=dword:00000001
"C:\\WINDOWS\\Fonts\\INSIFDR.TTF"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\QuickTimeCheck.OCX"=dword:000003e7
"C:\\WINDOWS\\SYSTEM\\QuickTimeMusicalInstruments.qtx"=dword:000003e7
"C:\\WINDOWS\\SYSTEM\\QuickTimeVR.qtx"=dword:000003e7
"C:\\WINDOWS\\SYSTEM\\OIK32.OCX"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\OC30.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\CSFORM32.OCX"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\MCIWNDX.OCX"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\Reference Titles\\SHRPNL10.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\Reference Titles\\SHRL30.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\Reference Titles\\SFC10.OCX"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\Reference Titles\\A\\SFCR10.DLL"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\Reference Titles\\A\\ERS2000.EXE"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\Reference Titles\\A\\ERSR2000.DLL"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\MsInfoRf\\ImgWalk.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\MsInfoRf\\Msinf16h.exe"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\MsInfoRf\\Msinfo32.cnt"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\MsInfoRf\\MSInfo32.exe"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\MsInfoRf\\Msinfo32.hlp"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\Reference Titles\\treedata.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\Reference Titles\\RefJIC.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\Reference Titles\\RefSV.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\Reference Titles\\Wheel2EE.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\Reference Titles\\SfcSvr10.exe"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\Information Retrieval\\itcc51.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\Information Retrieval\\itircl51.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\Information Retrieval\\itss51.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\msir2jp.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\msir2jp.lex"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\Reference Titles\\RefReg.exe"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\CARDMA~1.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\CARDPL~1.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\emsmtp.dll"=dword:00000003
"C:\\WINDOWS\\SYSTEM\\JGA0500.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\JGA1500.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\JGAD500.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\JGAE500.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\JGAR500.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\JGAU500.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\JGDR500.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\JGDW500.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\JGEA500.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\JGED500.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\JGEM500.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\JGEW500.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\JGID500.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\JGIP500.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\JGIQ500.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\JGIT500.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\JGMC500.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\JGME500.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\JGMI500.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\JGMK500.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\JGMP500.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\JGOS500.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\JGPD500.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\JGPL500.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\JGPP500.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\JGS1500.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\JGSM500.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\JGST500.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\MSCOMCTL.OCX"=dword:0000000b
"C:\\WINDOWS\\SYSTEM\\SSCE4132.DLL"=dword:00000001
"C:\\WINDOWS\\TWAIN.DLL"=dword:00000003
"C:\\WINDOWS\\TWAIN_32.DLL"=dword:00000003
"C:\\WINDOWS\\TWUNK_16.EXE"=dword:00000003
"C:\\WINDOWS\\TWUNK_32.EXE"=dword:00000003
"C:\\WINDOWS\\SYSTEM\\LFBMP11N.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LFCMP11N.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LFEPS11N.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LFFAX11N.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LFGIF11N.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LFPCD11N.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LFPCX11N.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LFPNG11N.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LFPSD11N.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LFTIF11N.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LFWMF11N.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LFWPG11N.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LTDIS11N.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LTFIL11N.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LTIMG11N.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LTKRN11N.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LTVDD11W.DRV"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\CONNMGR.OCX"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\IMAGES~1.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\PRETZE~1.DLL"=dword:00000001
-
and...."C:\\Program Files\\Sierra On-Line\\SIERRA.ICO"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\GIF89.DLL"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\LFBMP70N.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LFCMP70N.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LFFAX70N.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LFFPX7.DLL"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\LFFPX70N.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LFKODAK.DLL"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\LFPCD70N.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LFPCX70N.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LFPNG70N.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LFPSD70N.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LFTGA70N.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LFTIF70N.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LTFIL70N.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LTKRN70N.DLL"=dword:00000001
"C:\\Program Files\\Sierra On-Line\\SETUP.ICO"=dword:00000002
"C:\\Program Files\\WON\\FaceMaker\\1000000.PRF"=dword:00000001
"C:\\Program Files\\WON\\FaceMaker\\FACEMA~1.INI"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\QUICKT~1.QTS"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\QUICKT~1.QTX"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\qd3d.dll"=dword:000003e7
"C:\\WINDOWS\\SYSTEM\\rave.dll"=dword:000003e7
"C:\\WINDOWS\\SYSTEM\\3DViewer.dll"=dword:000003e7
"C:\\WINDOWS\\SYSTEM\\qd3d_ir2.q3x"=dword:000003e7
"C:\\WINDOWS\\SYSTEM\\QD3DCU~1.Q3X"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\QUICKT~1.CPL"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\QUICKT~2.QTX"=dword:00000002
"C:\\Program Files\\Sierra On-Line\\OLEPRO32.DLL"=dword:00000001
"C:\\Program Files\\Sierra On-Line\\MFC42.DLL"=dword:00000001
"C:\\Program Files\\Sierra On-Line\\MSVCRT.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\Msvbvm60.dll"=dword:00000007
@=dword:00000001
"C:\\Program Files\\Common Files\\InstallShield\\engine\\6\\Intel 32\\ILog.dll"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\WSOCK32.DLL"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\CMDIALOG.VBX"=dword:00000003
"C:\\WINDOWS\\SYSTEM\\MCI.VBX"=dword:00000003
"C:\\WINDOWS\\SYSTEM\\MSMASKED.VBX"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\PICCLIP.VBX"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\THREED.VBX"=dword:00000003
"C:\\WINDOWS\\SYSTEM\\COMMDLG.DLL"=dword:00000003
"C:\\WINDOWS\\SYSTEM\\ANIBUTON.VBX"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\IC32.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\IC32.INI"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\SDE32.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\SDENSX32.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\TX4OLE.OCX"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\TX32.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\TXOBJ32.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\TXTLS32.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\TX_BMP32.FLT"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\TX_WMF32.FLT"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\WNDTLS32.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\FFASTLOG.TXT"=dword:00000001
"C:\\WINDOWS\\MSO97.ACL"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\proof\\msth_br.lex"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\COMMTB32.HLP"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\Textconv\\EXCEL32.CNV"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\PROOF\\MSWDS_EN.LEX"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\Textconv\\wrd6er32.cnv"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\grphflt\\WPGEXP32.FLT"=dword:00000003
"C:\\Program Files\\Common Files\\Microsoft Shared\\Textconv\\MSCONV97.DLL"=dword:00000005
"C:\\WINDOWS\\SYSTEM\\SELFREG.DLL"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\T2EMBED.DLL"=dword:00000004
"C:\\Program Files\\Common Files\\Microsoft Shared\\VBA\\FM20.HLP"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\vbar332.dll"=dword:00000005
"C:\\Program Files\\Common Files\\Microsoft Shared\\VBA\\VBA332.DLL"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\SCP32.DLL"=dword:00000004
"C:\\Program Files\\Common Files\\Microsoft Shared\\VBA\\VBE.DLL"=dword:00000001
"C:\\Program Files\\Common Files\\Microsoft Shared\\VBA\\VBEEXT1.OLB"=dword:00000001
"C:\\Program Files\\Microsoft Office\\Office\\Actors\\CLIPPIT.ACT"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Reference Titles\\MSREFTL.DLL"=dword:00000003
"C:\\WINDOWS\\SYSTEM\\inetcpl.cpl"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\QuickTime\\QuickTimeUpdateHelper.exe"=dword:000003e7
"C:\\WINDOWS\\SYSTEM\\QuickTime\\QuickTimeEssentials.qtx"=dword:000003e7
"C:\\WINDOWS\\SYSTEM\\QuickTime\\QuickTimeVRAuthoring.qtx"=dword:000003e7
"C:\\WINDOWS\\SYSTEM\\QuickTime\\QuickTimeMPEG.qtx"=dword:000003e7
"C:\\WINDOWS\\SYSTEM\\IVIMCI32.DLL"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\IVIMCI.DRV"=dword:00000001
"C:\\WINDOWS\\unvise32.exe"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\IMAGEHLP.DLL"=dword:0000000d
"C:\\Program Files\\Common Files\\Intuit\\Internet Client\\Certs\\OFXBRAND.CRT"=dword:00000001
"C:\\Program Files\\Common Files\\Intuit\\Internet Client\\Certs\\OFXCA.CRT"=dword:00000001
"C:\\Program Files\\Common Files\\Intuit\\Internet Client\\Certs\\OFXCAEXT.CRT"=dword:00000002
"C:\\Program Files\\Common Files\\Intuit\\Internet Client\\ASSIST.CHM"=dword:00000002
"C:\\Program Files\\Common Files\\Intuit\\Internet Client\\ASSIST.EXE"=dword:00000002
"C:\\Program Files\\Common Files\\Intuit\\Internet Client\\FSPUB.KEY"=dword:00000002
"C:\\Program Files\\Common Files\\Intuit\\Internet Client\\INETCLNT.CHM"=dword:00000002
"C:\\Program Files\\Common Files\\Intuit\\Internet Client\\LAUNCH32.DLL"=dword:00000002
"C:\\Program Files\\Common Files\\Intuit\\Internet Client\\MSDUN13.EXE"=dword:00000002
"C:\\Program Files\\Common Files\\Intuit\\Internet Client\\PUB.KEY"=dword:00000002
"C:\\Program Files\\Common Files\\Intuit\\Internet Client\\PUB2.KEY"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\INETCLNT.DLL"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\SENDMAIL.DLL"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\MSENCODE.DLL"=dword:00000002
"c:\\Program Files\\Microsoft Office\\Office\\GRAPH9.EXE"=dword:00000002
"c:\\Program Files\\Microsoft Office\\Office\\REFEDIT.DLL"=dword:00000002
"c:\\Program Files\\Microsoft Office\\Office\\MSO9.DLL"=dword:00000002
"c:\\Program Files\\Microsoft Office\\Office\\AW.DLL"=dword:00000002
"c:\\Program Files\\Common Files\\Microsoft Shared\\VGX\\VGX.DLL"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\VSFLEX3.OCX"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\MSSTDFMT.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\MSRTEDIT.DLL"=dword:00000003
"c:\\Program Files\\Common Files\\System\\Mapi\\1033\\95\\CNFNOT32.EXE"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\MSACCESS.EXE"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\msstkprp.dll"=dword:00000004
"c:\\Program Files\\Microsoft Office\\Office\\OUACTRL.OCX"=dword:00000002
"c:\\Program Files\\Microsoft Office\\Office\\MSCAL.OCX"=dword:00000002
"c:\\Program Files\\Common Files\\Designer\\MSADDNDR.DLL"=dword:00000002
"c:\\Program Files\\Microsoft Office\\Office\\MSACNV30.EXE"=dword:00000002
"c:\\Program Files\\Microsoft Office\\Office\\HLP95EN.DLL"=dword:00000002
"c:\\Program Files\\Common Files\\Microsoft Shared\\Clipart\\autoshap\\AUTOSHAP.MMC"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\Clipart\\CagCat50\\cagcat50.mmc"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\SQLWOA.DLL"=dword:00000004
"c:\\WINDOWS\\SYSTEM\\MSRD2X40.DLL"=dword:00000004
"c:\\WINDOWS\\SYSTEM\\MSJET40.DLL"=dword:00000004
"c:\\WINDOWS\\SYSTEM\\MSEXCH40.DLL"=dword:00000004
"c:\\WINDOWS\\SYSTEM\\MSJINT40.DLL"=dword:00000004
"c:\\WINDOWS\\SYSTEM\\MSJTES40.DLL"=dword:00000004
"C:\\WINDOWS\\SYSTEM\\Odbcconf.dll"=dword:00000004
"c:\\WINDOWS\\SYSTEM\\MSDAMG9X.DLL"=dword:00000004
"c:\\WINDOWS\\SYSTEM\\odbc32.dll"=dword:00000005
"c:\\WINDOWS\\SYSTEM\\odbcint.dll"=dword:00000005
"c:\\WINDOWS\\SYSTEM\\ODDBSE32.DLL"=dword:00000004
"c:\\WINDOWS\\SYSTEM\\ODBCJI32.DLL"=dword:00000004
"c:\\WINDOWS\\SYSTEM\\MSRDO20.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\MSORCL32.DLL"=dword:00000004
"c:\\WINDOWS\\SYSTEM\\MTXOCI.DLL"=dword:00000004
"c:\\WINDOWS\\SYSTEM\\dbnmpntw.dll"=dword:00000005
"c:\\WINDOWS\\SYSTEM\\odbcbcp.dll"=dword:00000005
"c:\\WINDOWS\\SYSTEM\\SQLSRV32.DLL"=dword:00000004
"c:\\WINDOWS\\SYSTEM\\DBMSSHRN.DLL"=dword:00000004
"c:\\WINDOWS\\SYSTEM\\VFPODBC.DLL"=dword:00000004
"c:\\WINDOWS\\SYSTEM\\FM20.DLL"=dword:00000004
"c:\\WINDOWS\\SYSTEM\\FM20ENU.DLL"=dword:00000004
"c:\\Program Files\\Common Files\\Microsoft Shared\\VBA\\VBA6\\1033\\FM20.CHM"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\1033\\GRINTL32.DLL"=dword:00000002
"c:\\Program Files\\Microsoft Office\\Office\\GRAPH9.OLB"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\MSRCLR40.DLL"=dword:00000004
"c:\\WINDOWS\\SYSTEM\\MSRECR40.DLL"=dword:00000004
"c:\\WINDOWS\\SYSTEM\\MSREPL40.DLL"=dword:00000004
"c:\\Program Files\\Common Files\\System\\Mapi\\1033\\95\\MLCFG32.CPL"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\FIXMAPI.EXE"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\MAPISTUB.DLL"=dword:00000003
"c:\\Program Files\\Common Files\\System\\Mapi\\1033\\95\\NEWPROF.EXE"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\MAPISRVR.EXE"=dword:00000002
"c:\\Program Files\\Common Files\\Microsoft Shared\\MSDesigners98\\MDT2DBNS.DLL"=dword:00000002
"c:\\Program Files\\Common Files\\Microsoft Shared\\MSDesigners98\\MDT2DD.DLL"=dword:00000002
"c:\\Program Files\\Common Files\\Microsoft Shared\\MSDesigners98\\Resources\\1033\\MDT2FWUI.DLL"=dword:00000002
"c:\\Program Files\\Common Files\\Microsoft Shared\\MSDesigners98\\MDT2G.DLL"=dword:00000002
"c:\\Program Files\\Common Files\\Microsoft Shared\\MSDesigners98\\MDT2QD.DLL"=dword:00000002
"c:\\Program Files\\Common Files\\Microsoft Shared\\MSDesigners98\\MDT2DB.DLL"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\MDT2FW95.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\IMESHARE.DLL"=dword:00000003
"c:\\Program Files\\Microsoft Office\\Office\\MSO7FTP.EXE"=dword:00000003
"c:\\Program Files\\Microsoft Office\\Office\\1033\\MSO9INTL.DLL"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\CP_950.NLS"=dword:00000003
"c:\\Program Files\\Microsoft Office\\Office\\MSO97FX.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\OUTLWAB.DLL"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\EXSEC32.DLL"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\MSIMRT.DLL"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\stdole2.tlb"=dword:0000000c
"c:\\Program Files\\Microsoft Office\\Office\\MSCAL.CNT"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\1033\\MSOHELP.EXE"=dword:00000002
"c:\\Program Files\\Microsoft Office\\Office\\1033\\OFMAIN9.CHM"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\VEN2232.OLB"=dword:00000004
"c:\\WINDOWS\\SYSTEM\\VBAEND32.OLB"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\VBAEN32.OLB"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\VBAME.DLL"=dword:00000003
"c:\\Program Files\\Common Files\\Microsoft Shared\\VBA\\VBA6\\VBACV10.DLL"=dword:00000002
"c:\\Program Files\\Common Files\\Microsoft Shared\\VBA\\VBA6\\VBE6.DLL"=dword:00000002
"c:\\Program Files\\Common Files\\Microsoft Shared\\VBA\\VBA6\\VBE6EXT.OLB"=dword:00000002
"c:\\Program Files\\Common Files\\Microsoft Shared\\VBA\\VBA6\\1033\\VBE6INTL.DLL"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\MFC42ENU.DLL"=dword:00000003
"c:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\MSOWS409.DLL"=dword:00000003
"c:\\Program Files\\Common Files\\System\\OLE DB\\MSDAIPP.DLL"=dword:00000004
"c:\\Program Files\\Common Files\\System\\OLE DB\\MSDAPML.DLL"=dword:00000004
"c:\\Program Files\\Common Files\\System\\OLE DB\\MSDAURL.DLL"=dword:00000004
"c:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\MSONSEXT.DLL"=dword:00000004
"c:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\RAGENT.DLL"=dword:00000004
-
and......"c:\\WINDOWS\\SYSTEM\\SQLWID.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\SQLSTR.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\MSRD3X40.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\MSJTER40.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\JETERR40.CHM"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\msjetoledb40.dll"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\MSEXCL40.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\MSLTUS40.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\MSPBDE40.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\MSTEXT40.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\MSXBDE40.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\MSWSTR10.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\EXPSRV.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\VBAJET32.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\MSWDAT10.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\MDACRDME.HTM"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\MSDART32.DLL"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\ODBCCONF.RSP"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\DS16GT.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\DS32GT.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\odbctrac.dll"=dword:00000004
"c:\\WINDOWS\\SYSTEM\\odbccu32.dll"=dword:00000004
"c:\\WINDOWS\\SYSTEM\\odbccr32.dll"=dword:00000004
"c:\\WINDOWS\\SYSTEM\\odbccp32.dll"=dword:00000004
"c:\\WINDOWS\\SYSTEM\\odbcad32.exe"=dword:00000004
"c:\\WINDOWS\\SYSTEM\\ODBC32GT.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\ODBC16GT.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\MTXDM.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\odbccp32.cpl"=dword:00000004
"c:\\WINDOWS\\SYSTEM\\DRVVFP.CHM"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\ODBCJET.CHM"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\ODBCINST.CHM"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\ODBCJT32.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\ODEXL32.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\ODPDX32.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\ODTEXT32.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\ODFOX32.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\RDOCURS.DLL"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\MSORCL32.CHM"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\MSDATSRC.TLB"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\DBMSVINN.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\dbmsspxn.dll"=dword:00000004
"c:\\WINDOWS\\SYSTEM\\dbmssocn.dll"=dword:00000004
"c:\\WINDOWS\\SYSTEM\\DBMSRPCN.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\CLICONFG.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\CLICONFG.EXE"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\SQLSOLDB.HLP"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\SQLSODBC.HLP"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\CLICONF.HLP"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\INSTCAT.SQL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\12520437.CPX"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\MSCPXL32.DLL"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\12520850.CPX"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\MSRPJT40.DLL"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\MAPI.DLL"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\CP_936.NLS"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\CP_949.NLS"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\CP_932.NLS"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\CP_874.NLS"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\CP_21866.NLS"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\CP_28591.NLS"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\CP_20866.NLS"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\CP_1258.NLS"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\CP_1257.NLS"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\CP_1256.NLS"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\CP_1255.NLS"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\CP_1254.NLS"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\CP_1253.NLS"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\CP_1252.NLS"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\CP_1251.NLS"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\CP_1250.NLS"=dword:00000003
"c:\\WINDOWS\\SYSTEM\\MSIMUSIC.DLL"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\MSIMRT32.DLL"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\MSIMRT16.DLL"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBCMSYNC.DLL"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\SBFM\\anatools\\buylease\\BVL.DLL"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\SBFM\\anatools\\buylease\\BVLUI.DLL"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\SBCM\\SBCMDWIZ.DLL"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\DMM\\FORM3553.DOT"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\EMDAZ32.DLL"=dword:00000002
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\DMM\\Templates\\Flyer Wizard.wiz"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\DMM\\Templates\\Letter Wizard.wiz"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\DMM\\Templates\\Postcard Wizard.wiz"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\DMM\\Templates\\Simple Form Letter.dot"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBCM.DLL"=dword:00000001
"C:\\WINDOWS\\Downloaded Program Files\\yinsthelper.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\ActPanel.dll"=dword:00000001
"C:\\WINDOWS\\Msagent\\chars\\Short.acs"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\Agentctl.dll"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\Autprx32.dll"=dword:00000002
"C:\\Program Files\\Common Files\\Intuit\\Internet Client\\Certs\\OFXCA-G2.CRT"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\FOLDER.DIR"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\CDAC11BA.VXD"=dword:0000ffff
"c:\\WINDOWS\\SYSTEM\\PMEM.VXD"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\lodbf13.dll"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\lodbf13.hlp"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\wingen.drv"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\comctl32.dll"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\mfc40.dll"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\lcmx10.dll"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\ole32.dll"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\aprxdist.exe"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\ivdrv09.cnt"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\ivdrv09.hlp"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\ivlo.lic"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\ivtrn09.dll"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\lobas09.dll"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\lobas13.dll"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\lodb213.dll"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\lodb213.hlp"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\lodrv13.cnt"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\lodrv13.hlp"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\loflt13.dll"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\loinf13.dll"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\loinf13.hlp"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\loinf913.dll"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\loinf913.hlp"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\loor713.dll"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\loor713.hlp"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\loor813.dll"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\loor813.hlp"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\lotrn13.dll"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\loutl09.dll"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\loutl13.dll"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\odbc.cnt"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\odbc.hlp"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\odbcinst.cnt"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\odbcinst.hlp"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\loss09.cnt"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\loss09.dll"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\loss09.hlp"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\loss609.cnt"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\loss613.dll"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\loss613.hlp"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\ntwdblib.dll"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\loidp13.dll"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\loidp13.hlp"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\losyb09.cnt"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\losyb13.dll"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\losyb13.hlp"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\lotxt13.dll"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\lotxt13.hlp"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\jre116.exe"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\Odbcconf.exe"=dword:00000002
"C:\\NotesSQL\\UninDrv.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\uninst.ico"=dword:00000001
"c:\\WINDOWS\\FONTS\\phonetic.fon"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee VirusScan\\Res00\\VsutlRes.dll"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee VirusScan\\Res00\\CC32Res.dll"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee VirusScan\\Res00\\Avsynmgr.dll"=dword:00000001
"c:\\Program Files\\Common Files\\Network Associates\\On Demand Scanner\\Scan32\\Res00\\advgui.dll"=dword:00000001
"c:\\Program Files\\Common Files\\Network Associates\\On Demand Scanner\\Scan32\\Res00\\basgui.dll"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee VirusScan\\Res00\\Vshwin32.dll"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee VirusScan\\Res00\\VsCfgRes.dll"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee VirusScan\\Res00\\MfldrRes.dll"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee VirusScan\\Res00\\Avsmcpa.dll"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee VirusScan\\Res00\\Vsstat.dll"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee VirusScan\\Res00\\WebScanX.dll"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee VirusScan\\Res00\\WbhkRes.dll"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee VirusScan\\Res00\\SemalRes.dll"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee VirusScan\\Res00\\SendVir.dll"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee VirusScan\\Res00\\Edisk.dll"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\dtune.386"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Safe&Sound\\CRTDIR32.dll"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Safe&Sound\\crtvol32.dll"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Safe&Sound\\Database.ini"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Safe&Sound\\fbmount.exe"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Safe&Sound\\fbwin95.vxd"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Safe&Sound\\fsdir95.vxd"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Safe&Sound\\fsvol95.vxd"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Safe&Sound\\rebuild.exe"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Safe&Sound\\retake.exe"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Safe&Sound\\SasEnu.Chm"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Safe&Sound\\fsshell.dll"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Safe&Sound\\ChkVol.dll"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Safe&Sound\\SafSnd32.dll"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Safe&Sound\\SasEnu.dll"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Safe&Sound\\ChkVol.exe"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Safe&Sound\\mcrtl32.dll"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Central\\CLaunch.exe"=dword:00000002
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Central\\Central.dll"=dword:00000002
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Central\\CentENU.dll"=dword:00000002
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Central\\CentDEU.dll"=dword:00000002
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Central\\CentITA.dll"=dword:00000002
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Central\\CentESP.dll"=dword:00000002
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Central\\CentFRA.dll"=dword:00000002
"c:\\Program Files\\McAfee\\McAfee Firewall\\McPie.dll"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Firewall\\hhupd.exe"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Guardian\\cmgrdEnu.dll"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Guardian\\MgdEnu.chm"=dword:00000001