-
and:
"C:\\Cloud9\\MTPLAY32.EXE"=dword:00000000
"C:\\Cloud9\\MOM32.LIB"=dword:00000000
"C:\\WINDOWS\\SYSTEM\\msvcr70.dll"=dword:00000003
"C:\\WINDOWS\\SYSTEM\\SCRRUN.DLL"=dword:00000001
"C:\\WINDOWS\\Downloaded Program Files\\Imbum.dll"=dword:00000001
"C:\\WINDOWS\\Downloaded Program Files\\CONFLICT.1\\Imbum.dll"=dword:00000001
"c:\\Program Files\\Rio\\Rio Music Manager\\CDDBControl.dll"=dword:00000001
"c:\\Program Files\\Rio\\Rio Music Manager\\RecDev.dll"=dword:00000001
"c:\\Program Files\\Rio\\Rio Music Manager\\CDDBUI.dll"=dword:00000001
"c:\\Program Files\\Rio\\Rio Music Manager\\device.wav"=dword:00000001
"c:\\Program Files\\Rio\\Rio Taxi\\riotaxi_en.chm"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\SBCM\\SBCMAUT.EXE"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\SBCM\\SBCMTMPL.MDB"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\SBCM\\CASA6X.DLL"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\SBCM\\CASA7X.DLL"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\SBCM\\MNYFILT.DLL"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\SBCM\\MYOBSBT.DLL"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\SBCM\\OLKFLT.DLL"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\SBCM\\USQB5X.DLL"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\SBCM\\USQB6X.DLL"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\SBCM\\MPBCMA.DLL"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\SBCM\\myob7x.dll"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\SBCM\\USPAW70.DLL"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\SBCM\\USPOA1X.DLL"=dword:00000001
"c:\\WINDOWS\\All Users\\Application Data\\SBT\\SBCM\\SBCM.MDB"=dword:00000001
"c:\\WINDOWS\\All Users\\Application Data\\SBT\\SBCM\\SBCMLIB.MDB"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBCMJRNL.DLL"=dword:00000001
"c:\\WINDOWS\\All Users\\Application Data\\SBT\\Databases\\Northwind Traders Sample Company.mdb"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBCMSEC.DLL"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\SBCM\\Templates\\General\\Label.pub"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\SBCM\\Templates\\Promotions\\Special Offer Postcard.pub"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\SBCM\\Templates\\Sales Followup\\Thank You Professional Letter.dot"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\SBFM\\anatools\\busicomp\\RMA.MDB"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\SBFM\\Charts\\Balance Sheet Composition.xls"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\SBFM\\What-If Workbook.xls"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\SBFM\\anatools\\projrepo\\Projection Assumptions.xls"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\SBFM\\anatools\\projwiz\\Projection.exe"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SBT\\SBFM\\Reports\\RATIOS.XLS"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\MSAAP.XLA"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Clipart\\Pub60Cor\\PUB60COR.MMC"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Clipart\\standard\\STANDARD.MMC"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\COMCTL32.OCA"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\COMDLG32.OCA"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\MSADODC.OCX"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\MSDATGRD.OCX"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\DDAO36.DLL"=dword:00000002
"c:\\Program Files\\Common Files\\Microsoft Shared\\MSDesigners98\\Resources\\1033\\MDT2DDUI.DLL"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\MSDesigners98\\Resources\\1033\\MDT2QDUI.DLL"=dword:00000001
"c:\\Program Files\\Common Files\\Microsoft Shared\\MSDesigners98\\Resources\\1033\\MDT2DBUI.DLL"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\SIGNER.DLL"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\CP_28605.NLS"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\PUBDLG.DLL"=dword:00000003
"c:\\Program Files\\Microsoft Office\\Office\\1033\\SBCMHELP.CHM"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\1033\\directmail.chm"=dword:00000001
"c:\\Program Files\\Microsoft Office\\Office\\1033\\AAP.CHM"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\REGOBJ.DLL"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\VB5DB.DLL"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\EMLCNS32.DLL"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\SBFM40.XLA"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\CP_1361.NLS"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\CP_20269.NLS"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\CP_28592.NLS"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\CP_28593.NLS"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\CP_28594.NLS"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\CP_28595.NLS"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\CP_28596.NLS"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\CP_28597.NLS"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\CP_28598.NLS"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\CP_28599.NLS"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\PUB3BRSH.ANI"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\ycomp4,0,2,10.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\l3codecx.acm"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\Shlwapi.dll"=dword:00000004
"c:\\WINDOWS\\SYSTEM\\iosubsys\\UdfReadr.vxd"=dword:00000001
"c:\\WINDOWS\\SYSTEM\\iosubsys\\Cdudf.vxd"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\comct232.ocx"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\msmask32.ocx"=dword:00000002
"C:\\Program Files\\Common Files\\Adaptec Shared\\CDEngine\\ACMWrapperV2.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Adaptec Shared\\CDEngine\\MediaPlayerV2.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Adaptec Shared\\CDEngine\\driversV2.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Adaptec Shared\\CDEngine\\CDEngine.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\empop3.dll"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\msxml3.dll"=dword:00000006
"c:\\WINDOWS\\SYSTEM\\msxml3a.dll"=dword:00000005
"c:\\WINDOWS\\SYSTEM\\msxml3r.dll"=dword:00000005
"C:\\WINDOWS\\SYSTEM\\IEHelperMiddleMan.dll"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\IEHelperMiddleMan.tlb"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\msimmsgr.dll"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\msimnetc.dll"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\Msinet.ocx"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\Mswinsck.ocx"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\Odkob32.dll"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\Racreg32.dll"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\Regicon.ocx"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\sstabs2.ocx"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\SSubTmr6.dll"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\UTDns.dll"=dword:00000002
"C:\\WINDOWS\\Downloaded Program Files\\RntX.dll"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Central\\CentNLD.dll"=dword:00000002
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Central\\CentPTB.dll"=dword:00000002
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Central\\CentSVE.dll"=dword:00000002
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Central\\CentKOR.dll"=dword:00000002
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Central\\CentPTG.dll"=dword:00000002
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Central\\CentCHS.dll"=dword:00000002
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Central\\CentCHT.dll"=dword:00000002
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Instant Updater\\RuComms.dll"=dword:00000002
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Instant Updater\\RUENU.dll"=dword:00000002
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Instant Updater\\RuLaunch.exe"=dword:00000002
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Instant Updater\\Rupdate.dll"=dword:00000002
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Instant Updater\\RUtil.dll"=dword:00000002
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Instant Updater\\RECAPI.dll"=dword:00000002
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Instant Updater\\PatchW32.dll"=dword:00000002
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Instant Updater\\McUrial.dll"=dword:00000002
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Instant Updater\\RupEnu.chm"=dword:00000002
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Instant Updater\\tlsxpand.dll"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\CsLsp.dll"=dword:00000002
"c:\\WINDOWS\\SYSTEM\\sporder.dll"=dword:00000002
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Guardian\\CMGrdian.exe"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Guardian\\newctl32.dll"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Guardian\\mcsched.dll"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Guardian\\schedprp.dll"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\Guardian\\schedwiz.exe"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\VisualTrace\\ExternalApps\\config.README"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\VisualTrace\\Help\\Img\\divider.gif"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\VisualTrace\\Data\\Sound\\Done.wav"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\VisualTrace\\ExternalApps\\ftp.config"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\VisualTrace\\Data\\Sound\\Error.wav"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\VisualTrace\\Data\\Sound\\Failure.wav"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\VisualTrace\\Data\\Sound\\RouteComplete.wav"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\VisualTrace\\Data\\Sound\\Start.wav"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\VisualTrace\\Data\\Sound\\Timeout.wav"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\VisualTrace\\Data\\Sound\\TraceComplete.wav"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\VisualTrace\\Help\\Img\\hdr_mcafee.gif"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\VisualTrace\\Help\\Img\\hdr_visualtrace.gif"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\VisualTrace\\Help\\HomeEnu.htm"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\VisualTrace\\Data\\neotrace.gdp"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\VisualTrace\\Data\\neotrace.loca"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\VisualTrace\\Help\\Img\\neotrace-helpsite_footer.gif"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\VisualTrace\\Help\\Img\\neotrace-helpsite_header.gif"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\VisualTrace\\Help\\Img\\neotrace-helpsite_header-left.gif"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\VisualTrace\\Help\\Img\\neotrace-helpsite_header-repeat.gif"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\VisualTrace\\NTXcontext.htm"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\VisualTrace\\NTXtoolbar.htm"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\VisualTrace\\ExternalApps\\ping.config"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\VisualTrace\\Data\\RIR.ini"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\VisualTrace\\Help\\Img\\shim.gif"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\VisualTrace\\ExternalApps\\telnet.config"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\VisualTrace\\NeoTrace.exe"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\VisualTrace\\VisTrEnu.dll"=dword:00000001
"c:\\Program Files\\McAfee\\McAfee Shared Components\\VisualTrace\\VtcEnu.chm"=dword:00000001
"c:\\PROGRA~1\\MCAFEE\\MCAFEE~2\\CENTRAL\\CENTESE.DLL"=dword:00000001
"c:\\PROGRA~1\\MCAFEE\\MCAFEE~2\\VISUAL~1\\HELP\\NTXCON~1.HTM"=dword:00000001
"c:\\PROGRA~1\\MCAFEE\\MCAFEE~2\\VISUAL~1\\HELP\\NTXTOO~1.HTM"=dword:00000001
"C:\\Program Files\\Common Files\\AOL\\Flasha.ocx"=dword:00000004
-
and:"C:\\WINDOWS\\SYSTEM\\ltann13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfxwd13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfXpm13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfXbm13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\ltkrn13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LTDIS13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LTWVC13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LTFIL13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LTIMG13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LTEFX13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfwpg13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfwmp13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\Lfwmf13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfwfx13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfvec13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lftif13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lftga13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LFSMP13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfshp13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfsgi13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfsct13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfRaw13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfras13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LFPTK13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfpsd13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LFPNM13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\Lfpng13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfplt13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfpdf13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfpcx13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\Lfpct13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfPCL13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfpcd13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfmsp13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfmpg13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfmac13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lflmb13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lflma13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfjbg13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LFJ2K13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfitg13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfimg13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfiff13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfica13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfgif13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfgbr13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lffpx13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfflc13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lffax13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfeps13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfdxf13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfdwg13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfdwf13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfdrw13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\Lfdgn13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfCUT13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LFCMW13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LFCMP13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfclp13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\Lfcgm13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfcal13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfbmp13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfawd13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfavi13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfani13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lfAFP13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LTAUT13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LTCLR13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LTCON13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\ltcry13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LTDic13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\ltdlg13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\ltisi13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\ltlst13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\ltpdg13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\Ltpnt13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LTRTN13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LTSCR13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\Ltsgm13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LTTLB13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lttls13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lttmb13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lttw213n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\lttwn13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\ltwen13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\LTWND13n.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\Lvkrn13n.dll"=dword:00000001
"C:\\Program Files\\Fellowes\\MediaFACE 4.0\\SetHook.exe"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\zip.exe"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\comct332.ocx"=dword:00000002
"C:\\WINDOWS\\SYSTEM\\mscomct2.ocx"=dword:00000002
"C:\\Program Files\\Common Files\\Real\\Update_OB\\rnqu3270.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Update_OB\\rnuninst.exe"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Update_OB\\rnup3270.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Update_OB\\upgr3270.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Update_OB\\upgrdhlp.exe"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Update_OB\\setu3270.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Update_OB\\twebbrowse.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Update_OB\\faus3270.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Update_OB\\athn3270.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Update_OB\\rnathchk.exe"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Update_OB\\realevent.exe"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Update_OB\\rnad3201.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Update_OB\\rnms3270.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Update_OB\\rnxproc.exe"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Update_OB\\nprfxins.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Common\\rpun3260.dll"=dword:00000002
"C:\\Program Files\\Common Files\\Real\\Plugins\\auth3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\basc3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\cdda3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\http3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\memf3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\ntau3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\pacp3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\plus3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\pnvi3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\pxcb3210.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\ramf3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\ramr3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\rmff3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\rn5a3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\sdpp3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\smlf3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\smlr3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\smmr3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Common\\pnen3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\smpl3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\zipf3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\pnxr3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\vsrc3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\vsrl3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Common\\pnrs3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Common\\pngu3267.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\pndx5016.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\pndx5032.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Common\\rppr3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\rare3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Codecs\\atrc3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Codecs\\cook3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Codecs\\sipr3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\rvre3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Codecs\\drv13260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Codecs\\drv23260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Codecs\\drv33260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Codecs\\rnlt3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Codecs\\rv103260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Codecs\\rv203260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Codecs\\rv303260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Codecs\\drv43260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Codecs\\rv403260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\swff3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\swfr3260.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\rmoc3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\rtff3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\rtre3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\imgr3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\ppff3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\mp3f3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\mp3r3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\mp3m3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Common\\rjbviz.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\stub3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Common\\objb3201.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\RCAPlugins\\gct23201.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\RCAPlugins\\gemc3201.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\RCAPlugins\\uisy3201.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\xmlp3261.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\RCAPlugins\\gema3201.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\RCAPlugins\\gemx3201.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\RCAPlugins\\xmlc3201.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\GToolbar\\BarControl.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\GToolbar\\GoogleToolbar.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\audp3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\vidp3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\mpgf3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\mpgr3260.dll"=dword:00000001
"C:\\Program Files\\Common Files\\xing shared\\mpeg encode\\xmencmp3.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Common\\security.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\security.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\rmxrend.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\rmxfpln.dll"=dword:00000001
"C:\\Program Files\\Common Files\\Real\\Plugins\\tfilesys.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\QuickTime\\QuickTimeJavaExtras.qtx"=dword:000003e7
"%JavaDir%\\QTJava.zip"=dword:000003e7
"C:\\WINDOWS\\SYSTEM\\QTJavaNative.dll"=dword:000003e7
"C:\\WINDOWS\\SYSTEM\\QTJava.dll"=dword:000003e7
"C:\\WINDOWS\\SYSTEM\\SENSAPI.DLL"=dword:00000002
"C:\\Program Files\\EarthLink 5.0\\mfc42.dll"=dword:00000001
"C:\\WINDOWS\\SYSTEM\\RNAPH.DLL"=dword:00000001
-
now these are the vxd files:
REGEDIT4
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\Winsock]
"IrSockets"="wsirda.vxd"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\VNETSUP]
"ComputerName"="HPPav"
"Workgroup"="Hewlettpackard"
"Comment"=""
"StaticVxD"="vnetsup.vxd"
"Start"=hex:00
"NetClean"=hex:01
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\NDIS]
"Start"=hex:00
"NetClean"=hex:01
"StaticVxD"="ndis.vxd,ndis2sup.vxd"
"DeviceVxDs"="ndiswmi.sys"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\JAVASUP]
"Start"=hex:00
"StaticVxD"="JAVASUP.VXD"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\CONFIGMG]
"StaticVxD"="*CONFIGMG"
"Start"=hex:00
"SysDM"="SYSDM.CPL"
"SysDMFunc"="DMSetupDevnode"
"Detect"="SYSDM.CPL"
"DetectFunc"="DMRedetect"
"Private"="SYSDM.CPL"
"PrivateFunc"="DMPrivateProblem"
"RemoveRomOkay"="SYSDM.CPL"
"RemoveRomOkayFunc"="DMRemoveRomOkay"
"AskForConfig"="SYSDM.CPL"
"AskForConfigFunc"="DMAskForConfig"
"AskForUndock"="SYSDM.CPL"
"AskForUndockFunc"="DMAskForUndock"
"DelayedInstall"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\CONFIGMG\SpannableBus]
"PCI"=hex:00
"ISAPNP"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\CONFIGMG\PnPBus]
"PCI"=hex:00
"BIOS"=hex:00
"EISA"=hex:00
"USB"=hex:00
"HID"=hex:00
"1394"=hex:00
"ISAPNP"=hex:00
"MF"=hex:00
"ACPI"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\CONFIGMG\PreInstall]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\CONFIGMG\PreInstall\1394_609E&10483]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\CONFIGMG\PreInstall\1394_609E&10483\Hardware]
"Class"="SBP2"
"DeviceDesc"="SBP2 Compliant IEEE 1394 device"
"UpperFilters"="ntmap.sys"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\CONFIGMG\PreInstall\1394_609E&10483\Software]
"DevLoader"="*NTKERN"
"NTMPDriver"="sbp2port.sys"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\CONFIGMG\PreInstall\SBP2_GenDisk]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\CONFIGMG\PreInstall\SBP2_GenDisk\Hardware]
"Class"="Storage"
"DeviceDesc"="1394/USB Disk"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\CONFIGMG\PreInstall\SBP2_GenDisk\Software]
"DevLoader"="*IOSNTKERN"
"PortDriver"="NTMAPHLP.PDR"
"PreloadDrivers"=""
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\NTKern]
"StaticVxD"="*NTKERN"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\VWIN32]
"StaticVxD"="*VWIN32"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\VFBACKUP]
"StaticVxD"="*VFBACKUP"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\VCOMM]
"StaticVxD"="*VCOMM"
"Start"=hex:00
"EnablePowerManagement"=hex:01,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\COMBUFF]
"StaticVxD"="*COMBUFF"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\IFSMGR]
"StaticVxD"="*IFSMGR"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\IOS]
"StaticVxD"="*IOS"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\MTRR]
"StaticVxD"="*mtrr"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\SPOOLER]
"StaticVxD"="*SPOOLER"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\UDF]
"StaticVxD"="*UDF"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\VFAT]
"StaticVxD"="*VFAT"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\VCACHE]
"StaticVxD"="*VCACHE"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\VCACHE\Lookup]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\VCACHE\Lookup\VREDIR_Names]
"Key0000"=hex:48,4f,42,42,53,5f,42,53
"Data0000"=hex:00,07,00,00,74,00,92,c2,a2,92,a3,c2,30,0e,fb,c0,f2
"NumElements"=hex:01,00,00,00
"MaxElements"=hex:1e,00,00,00
"Flags"=hex:00,00,01,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\VCACHE\Lookup\ServerNameCache]
"Key0000"=hex:5c,00,2a,00,2e,00,54,00,30,00,31,00
"Data0000"=hex:00,00,02,00
"Key0001"=hex:5c,00,48,00,50,00,44,00,50,00,43,00,36,00,30,00,35,00
"Data0001"=hex:00,00,02,00
"Key0002"=hex:5c,00,47,00,4c,00,4f,00,54,00,5f,00,52,00,4e,00,44,00,4e,00,54,\
00
"Data0002"=hex:00,00,02,00
"NumElements"=hex:03,00,00,00
"MaxElements"=hex:1e,00,00,00
"Flags"=hex:00,00,01,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\VCOND]
"StaticVxD"="*VCOND"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\VCDFSD]
"StaticVxD"="*VCDFSD"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\VXDLDR]
"StaticVxD"="*VXDLDR"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\VDEF]
"StaticVxD"="*VDEF"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\VPICD]
"StaticVxD"="*VPICD"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\VTD]
"StaticVxD"="*VTD"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\REBOOT]
"StaticVxD"="*REBOOT"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\VDMAD]
"StaticVxD"="*VDMAD"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\VSD]
"StaticVxD"="*VSD"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\V86MMGR]
"StaticVxD"="*V86MMGR"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PAGESWAP]
"StaticVxD"="*PAGESWAP"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\DOSMGR]
"StaticVxD"="*DOSMGR"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\VMPOLL]
"StaticVxD"="*VMPOLL"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\SHELL]
"StaticVxD"="*SHELL"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PARITY]
"StaticVxD"="*PARITY"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\BIOSXLAT]
"StaticVxD"="*BIOSXLAT"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\VMCPD]
"StaticVxD"="*VMCPD"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\VTDAPI]
"StaticVxD"="*VTDAPI"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PERF]
"StaticVxD"="*PERF"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\VRTWD]
"StaticVxD"="c:\\windows\\SYSTEM\\vrtwd.386"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\VFIXD]
"StaticVxD"="c:\\windows\\SYSTEM\\vfixd.vxd"
"Start"=hex:00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\VMM]
"VXDGroups"=hex:00,d0,27,c0,ff,ff,31,c0,50,43,4f,44,00,00,22,c0,00,10,22,c0,49,\
4e,54,32,00,10,22,c0,00,d0,22,c0,4c,4f,43,4b,00,d0,22,c0,00,f0,22,c0,53,59,\
53,45,00,f0,22,c0,00,f0,23,c0,52,41,52,45,00,f0,23,c0,00,20,24,c0,57,31,36,\
43,00,20,24,c0,00,40,24,c0,57,33,32,43,00,40,24,c0,00,80,24,c0,56,4d,43,52,\
00,80,24,c0,00,a0,24,c0,56,4d,44,45,00,a0,24,c0,00,c0,24,c0,54,48,43,52,00,\
c0,24,c0,00,d0,24,c0,54,48,44,45,00,d0,24,c0,00,e0,24,c0,56,4d,53,55,00,e0,\
24,c0,00,f0,24,c0,56,4d,52,45,00,f0,24,c0,00,60,25,c0,50,4e,50,43,00,60,25,\
c0,00,f0,25,c0,44,4f,53,56,00,f0,25,c0,00,00,26,c0,57,33,32,00,00,00,26,c0,\
00,30,27,c0,50,4e,50,00,00,30,27,c0,00,40,27,c0,5f,49,4e,49,00,40,27,c0,00,\
50,27,c0,44,42,4f,43,00,50,27,c0,00,60,27,c0,43,4f,44,45,00,60,27,c0,00,b0,\
27,c0,5f,46,49,4f,00,b0,27,c0,00,d0,27,c0,5f,42,52,57,00,d0,27,c0,00,d0,27,\
c0,00,00,00,00,00,d0,27,c0,00,d0,27,c0,00,00,00,00,00,d0,27,c0,00,d0,27,c0,\
00,00,00,00,00,d0,27,c0,00,d0,27,c0,00,00,00,00,00,d0,27,c0,00,d0,27,c0,00,\
00,00,00,00,d0,27,c0,00,d0,27,c0,00,00,00,00,00,d0,27,c0,00,d0,27,c0,00,00,\
00,00,00,d0,27,c0,00,d0,27,c0,00,00,00,00,00,d0,27,c0,00,d0,27,c0,00,00,00,\
00,00,d0,27,c0,00,d0,27,c0,00,00,00,00
"CleanedDefaults"=dword:00000001
"DOSPager"=hex:00
-
and....[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\VMD]
"MouseType"="PS2"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PPP]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PPP\CPList]
"Shiva SPAP Auth CP"="spap.vxd"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\VNETBIOS]
"StaticVxD"="vnetbios.vxd"
"Start"=hex:00
"NetClean"=hex:01
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI]
"Options"=hex:02,00,00,00
"C6211045"=hex:04,00,00,00
"06401095"=hex:04,00,00,00
"12308086"=hex:04,00,00,00
"70108086"=hex:04,00,00,00
"0140104B"=hex:08,00,00,00
"06031179"=hex:08,00,00,00
"10000E11"=hex:10,00,00,00
"20000E11"=hex:10,00,00,00
"04061039"=hex:10,00,00,00
"00088086"=hex:10,00,00,00
"00021014"=hex:10,00,00,00
"06001080"=hex:20,00,00,00
"11001013"=hex:40,00,00,00
"521910B9"=hex:80,00,00,00
"00011C1C"=hex:00,01,00,00
"00381097"=hex:00,01,00,00
"D001100B"=hex:00,04,00,00
"04A38086"=hex:00,08,00,00
"000010AA"=hex:00,08,00,00
"88D15333"=hex:00,08,00,00
"06051179"=hex:00,10,00,00
"11101013"=hex:00,20,00,00
"AC12104C"=hex:00,00,01,00
"04661180"=hex:00,00,01,00
"00471014"=hex:00,00,00,00
"00951014"=hex:00,00,00,00
"122E8086"=hex:00,00,08,00
"70008086"=hex:00,00,08,00
"71108086"=hex:00,00,08,00
"76008086"=hex:00,00,08,00
"47471002"=hex:00,00,40,00
"47541002"=hex:00,00,40,00
"89015333"=hex:00,00,40,00
"00D61013"=hex:00,00,40,00
"AC15104C"=hex:00,00,40,00
"0004110B"=hex:00,00,40,00
"000F1000"=hex:00,00,40,00
"AC17104C"=hex:00,00,40,00
"93971023"=hex:00,00,40,00
"12318086"=hex:00,00,00,01
"00021273"=hex:00,00,00,01
"007D1014"=hex:00,00,00,01
"01001285"=hex:00,00,00,01
"68361217"=hex:00,00,00,08
"68321217"=hex:00,00,00,08
"AC22104C"=hex:00,00,00,40
"C8141045"=hex:00,00,40,20
"3202100C"=hex:00,8a,00,00
"80021066"=hex:00,00,30,00
"00021066"=hex:00,00,30,00
"01021004"=hex:00,40,00,02
"IRQORT0605117908"=hex:03,04,00,00
"IRQORT0605117920"=hex:01,00,00,00
"IRQORT0605117940"=hex:03,04,01,02
"IRQORT0605117948"=hex:04,03,02,01
"IRQORT0605117960"=hex:02,01,04,03
"IRQORT0609117908"=hex:04,00,00,00
"IRQORT0609117920"=hex:01,02,00,00
"IRQORT0609117950"=hex:03,04,01,02
"IRQORT0609117958"=hex:02,03,04,01
"IRQORT0609117968"=hex:04,01,00,00
"IRQTableStatus"=hex:24,00,00,00
"IRQMiniportDataStatus"=hex:20,00,00,00
"IRQMINIPORTStatus"=hex:20,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\04828086]
"Name"="Intel 82375EB/SB"
"Path"="PCIMP.PCI"
"Instance"=hex:00,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\122E8086]
"Name"="Intel 82371FB"
"Path"="PCIMP.PCI"
"Instance"=hex:01,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\04848086]
"Name"="Intel 82378"
"Path"="PCIMP.PCI"
"Instance"=hex:01,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\12348086]
"Name"="Intel 82371MX"
"Path"="PCIMP.PCI"
"Instance"=hex:01,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\70008086]
"Name"="Intel 82371SB"
"Path"="PCIMP.PCI"
"Instance"=hex:01,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\71108086]
"Name"="Intel 82371AB/EB"
"Path"="PCIMP.PCI"
"Instance"=hex:01,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\76008086]
"Name"="Intel 82372FB"
"Path"="PCIMP.PCI"
"Instance"=hex:01,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\00061004]
"Name"="VLSI"
"Path"="PCIMP.PCI"
"Instance"=hex:02,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\C5581045]
"Name"="Opti Viper"
"Path"="PCIMP.PCI"
"Instance"=hex:03,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\C5681045]
"Name"="Opti Viper Max"
"Path"="PCIMP.PCI"
"Instance"=hex:03,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\00081039]
"Name"="SiS5503"
"Path"="PCIMP.PCI"
"Instance"=hex:04,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\01021004]
"Name"="VLSI Eagle"
"Path"="PCIMP.PCI"
"Instance"=hex:05,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\06021179]
"Name"="Toshiba"
"Path"="PCIMP.PCI"
"Instance"=hex:06,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\80021066]
"Name"="VESUVIUS PT86C523"
"Path"="PCIMP.PCI"
"Instance"=hex:07,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\00021066]
"Name"="VESUVIUS PT86C523"
"Path"="PCIMP.PCI"
"Instance"=hex:07,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\152310B9]
"Name"="ALi 1523"
"Path"="PCIMP.PCI"
"Instance"=hex:08,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\0011100B]
"Name"="NS 87560"
"Path"="PCIMP.PCI"
"Instance"=hex:09,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\AE290E11]
"Name"="Compaq MISC-3"
"Path"="PCIMP.PCI"
"Instance"=hex:0a,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\153310B9]
"Name"="ALi 1533"
"Path"="PCIMP.PCI"
"Instance"=hex:0b,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\c7001045]
"Name"="Opti Fire Star"
"Path"="PCIMP.PCI"
"Instance"=hex:0c,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\05861106]
"Name"="VT82C586B"
"Path"="PCIMP.PCI"
"Instance"=hex:0d,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\05961106]
"Name"="VT82C596"
"Path"="PCIMP.PCI"
"Instance"=hex:0d,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\06861106]
"Name"="VT82C686"
"Path"="PCIMP.PCI"
"Instance"=hex:0d,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\A0F30E11]
"Name"="Compaq OSB"
"Path"="PCIMP.PCI"
"Instance"=hex:0e,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\00020E11]
"Name"="Compaq CMC-2"
"Path"="PCIMP.PCI"
"Instance"=hex:0f,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\00021078]
"Name"="Cyrix 5520 Rev 1"
"Path"="PCIMP.PCI"
"Instance"=hex:10,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\00001078]
"Name"="Cyrix 5520 Rev 0"
"Path"="PCIMP.PCI"
"Instance"=hex:10,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\24108086]
"Name"="Intel 82801AA"
"Path"="PCIMP.PCI"
"Instance"=hex:01,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\24208086]
"Name"="Intel 82801AB"
"Path"="PCIMP.PCI"
"Instance"=hex:01,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQMiniports\71988086]
"Name"="Intel 82440MX"
"Path"="PCIMP.PCI"
"Instance"=hex:01,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IDEMiniports]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IDEMiniports\12308086]
"Name"="Intel 82371FB"
"Path"="PCIMP.PCI"
"Instance"=hex:00,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IDEMiniports\70108086]
"Name"="Intel 82371SB"
"Path"="PCIMP.PCI"
"Instance"=hex:00,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IDEMiniports\71118086]
"Name"="Intel 82371AB/EB"
"Path"="PCIMP.PCI"
"Instance"=hex:00,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IDEMiniports\76018086]
"Name"="Intel 82372FB"
"Path"="PCIMP.PCI"
"Instance"=hex:00,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IDEMiniports\C6211045]
"Name"="Opti 826612A or Viper-M/N+"
"Path"="PCIMP.PCI"
"Instance"=hex:01,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IDEMiniports\D7211045]
"Name"="Opti FireStar"
"Path"="PCIMP.PCI"
"Instance"=hex:01,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IDEMiniports\55131039]
"Name"="SiS 5513"
"Path"="PCIMP.PCI"
"Instance"=hex:02,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IDEMiniports\05971039]
"Name"="SiS 5513 C Stepping"
"Path"="PCIMP.PCI"
"Instance"=hex:02,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IDEMiniports\AE330E11]
"Name"="Compaq MISC L/E"
"Path"="PCIMP.PCI"
"Instance"=hex:03,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IDEMiniports\521910B9]
"Name"="ALi 5219"
"Path"="PCIMP.PCI"
"Instance"=hex:03,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IDEMiniports\522910B9]
"Name"="ALi 5229"
"Path"="PCIMP.PCI"
"Instance"=hex:03,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IDEMiniports\01031179]
"Name"="Toshiba EX-IDE Type-B"
"Path"="PCIMP.PCI"
"Instance"=hex:03,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IDEMiniports\D5681045]
"Name"="Opti Viper Max"
"Path"="PCIMP.PCI"
"Instance"=hex:04,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IDEMiniports\100B0002]
"Name"="Nat. Sem. PC87415"
"Path"="PCIMP.PCI"
"Instance"=hex:05,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IDEMiniports\05711106]
"Name"="VT82C586B PIPC"
"Path"="PCIMP.PCI"
"Instance"=hex:06,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IDEMiniports\24118086]
"Name"="Intel 82801AA"
"Path"="PCIMP.PCI"
"Instance"=hex:00,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IDEMiniports\24218086]
"Name"="Intel 82801AB"
"Path"="PCIMP.PCI"
"Instance"=hex:00,00,00,00
-
and the last one.....[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IDEMiniports\71998086]
"Name"="Intel 82440MX"
"Path"="PCIMP.PCI"
"Instance"=hex:00,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\GARTMiniports]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\GARTMiniports\71808086]
"Name"="Intel 440LX"
"Path"="PCIMP.PCI"
"Instance"=hex:00,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\GARTMiniports\71908086]
"Name"="Intel 440BX"
"Path"="PCIMP.PCI"
"Instance"=hex:00,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\GARTMiniports\71A08086]
"Name"="Intel 440GX"
"Path"="PCIMP.PCI"
"Instance"=hex:00,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\GARTMiniports\25008086]
"Name"="Intel 820 Chipset"
"Path"="PCIMP.PCI"
"Instance"=hex:00,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\GARTMiniports\05971106]
"Name"="VIA Tech 3045"
"Path"="PCIMP.PCI"
"Instance"=hex:01,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\GARTMiniports\05981106]
"Name"="VIA Tech VT82C598"
"Path"="PCIMP.PCI"
"Instance"=hex:01,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\GARTMiniports\06911106]
"Name"="VIA Tech VT82C691"
"Path"="PCIMP.PCI"
"Instance"=hex:01,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\GARTMiniports\05011106]
"Name"="VIA Tech VT501"
"Path"="PCIMP.PCI"
"Instance"=hex:01,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\GARTMiniports\154110B9]
"Name"="ALi M1541"
"Path"="PCIMP.PCI"
"Instance"=hex:02,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PCI\IRQRoutingTable]
"VLSI Sample"=hex:24,50,49,52,00,01,40,00,ff,ff,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,58,01,28,de,02,28,de,03,28,de,04,28,\
de,01,00,00,60,02,28,de,03,28,de,04,28,de,01,28,de,01,00
"IBM Mach, VLSI Chipset"=hex:24,50,49,52,00,01,40,00,ff,ff,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,58,01,28,de,03,28,de,02,\
28,de,01,28,de,01,00,00,60,02,28,de,01,28,de,03,28,de,02,28,de,01,00
"Dell 4 PCI slot"=hex:24,50,49,52,00,01,60,00,ff,ff,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,68,60,b8,0e,61,b8,0e,62,b8,0e,63,\
b8,0e,01,00,00,70,61,b8,0e,62,b8,0e,63,b8,0e,60,b8,0e,01,00,00,78,62,b8,0e,\
63,b8,0e,60,b8,0e,61,b8,0e,01,00,00,80,63,b8,0e,60,b8,0e,61,b8,0e,62,b8,0e,\
01,00
"Dell 2 PCI slot"=hex:24,50,49,52,00,01,40,00,ff,ff,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,60,60,b8,0e,61,08,8e,62,08,8e,63,\
b8,0e,01,00,00,68,62,b8,0e,63,08,8e,61,08,8e,60,b8,0e,01,00
"Gateway 2000 3 PCI slot"=hex:24,50,49,52,00,01,50,00,ff,ff,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,30,62,b8,8e,61,b8,8e,60,\
b8,8e,63,b8,8e,0a,00,00,70,61,b8,8e,60,b8,8e,62,b8,8e,63,b8,8e,0b,00,00,60,\
60,b8,8e,62,b8,8e,61,b8,8e,63,b8,8e,0c,00
"Intel 430MX Motherboard Sample"=hex:24,50,49,52,00,01,80,00,ff,ff,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,70,60,f8,de,61,f8,\
de,60,f8,de,61,f8,de,05,00,00,78,61,f8,de,60,f8,de,61,f8,de,60,f8,de,63,00,\
00,88,61,f8,de,60,f8,de,61,f8,de,60,f8,de,06,00,00,90,60,f8,de,61,f8,de,60,\
f8,de,61,f8,de,03,00,00,98,61,f8,de,60,f8,de,61,f8,de,60,f8,de,61,00,00,a0,\
60,b8,8e,62,b8,8e,61,b8,8e,63,b8,8e,01,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\ISAPNP]
"TCM5090"=hex:02,00,00,00
"TCM5091"=hex:02,00,00,00
"TCM5094"=hex:02,00,00,00
"TCM5095"=hex:02,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\MSTCP]
"LMHostFile"="c:\\windows\\lmhosts"
"LocalCopyMade"="1"
"EnableDNS"="1"
"Lanabase"="0"
"NodeType"="1"
"MaxDataRetries"="5"
"HostName"="jonesfamily"
"Domain"=""
"SearchList"=""
"NameServer"="207.69.188.185,207.69.188.186,207.69.188.187"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\MSTCP\Ndi]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\MSTCP\Ndi\params]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\MSTCP\Ndi\params\AllowATM]
"ParamDesc"="Allow Binding To ATM"
"default"="0"
"type"="enum"
@="0"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\MSTCP\Ndi\params\AllowATM\enum]
"0"="No"
"1"="Yes"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\MSTCP\Ndi\ATMDefaults]
"ARPServerList"="4700790001020000000000000000A03E00000200"
"MARServerList"="4700790001020000000000000000A03E00000200"
"SapSelector"=hex:01,00,00,00
"MTU"=hex:dc,23,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\MSTCP\Parameters]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\MSTCP\Parameters\Winsock]
"MaxSockAddrLength"=hex:10,00,00,00
"MinSockAddrLength"=hex:10,00,00,00
"HelperDllName"="%windir%\\system\\wsock32.dll"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\MSTCP\ServiceProvider]
"LocalPriority"=hex:f3,01,00,00
"HostsPriority"=hex:f4,01,00,00
"DnsPriority"=hex:d0,07,00,00
"NetbtPriority"=hex:d1,07,00,00
"Class"=hex:08,00,00,00
"ProviderPath"="%windir%\\system\\wsock32.dll"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\Winsock2]
"Ancillary Function Driver for Winsock"="afvxd.vxd"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\AFVXD]
"MSTCP Helper for Winsock"="wshtcp.vxd"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\VIAGART]
"StaticVxD"="viagart.vxd"
"Turbo"=hex:01,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\ASPIENUM]
"Start"=dword:00000000
"StaticVxD"="ASPIENUM.VXD"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\APIX]
"ExcludeMiniports"=""
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\DHCP]
"Version"=hex:02,00,00,00
"PopupFlag"=hex:00,00,00,00
"ReleaseLeaseOnShutdown"=dword:00000001
"01000C41092AA1"=hex:36,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,1a,cb,d7,\
2c,c0,a8,01,01,33,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,1a,cb,d7,2c,\
00,01,51,80,0f,00,00,00,00,00,00,00,0e,00,00,00,00,00,00,00,1a,cb,d7,2c,45,\
61,72,74,68,6c,69,6e,6b,2e,6e,65,74,00,00,00,06,00,00,00,00,00,00,00,0c,00,\
00,00,00,00,00,00,1a,cb,d7,2c,cf,45,bc,b9,cf,45,bc,ba,cf,45,bc,bb,03,00,00,\
00,00,00,00,00,04,00,00,00,00,00,00,00,1a,cb,d7,2c,c0,a8,01,01,01,00,00,00,\
00,00,00,00,04,00,00,00,00,00,00,00,1a,cb,d7,2c,ff,ff,ff,00,35,00,00,00,00,\
00,00,00,01,00,00,00,00,00,00,00,1a,cb,d7,2c,05,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\DHCP\DhcpInfo00]
"DhcpIndex"=dword:00000000
"DhcpIPAddress"=hex:00,00,00,00
"DhcpSubnetMask"=hex:ff,ff,00,00
"DhcpServer"=hex:ff,ff,ff,ff
"DhcpDesiredIPAddress"=hex:c0,a8,01,64
"Lease"=hex:ff,ff,ff,ff
"LeaseObtainedTime"=hex:1c,3a,b4,2d
"T1"=hex:ff,ff,ff,7f
"T2"=hex:4e,6d,e7,60
"LeaseTerminatesTime"=hex:ff,ff,ff,7f
"HardwareType"=hex:01
"HardwareAddress"=hex:00,05,5d,cf,56,70
"IPAutoconfigurationAddress"="169.254.117.97"
"IPAutoconfigurationSeed"=dword:be47c5f1
"AddressType"=dword:00000001
"OptionInfo"=hex:2e,04,01,00,00,00,ff,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\DHCP\DhcpInfo01]
"DhcpIndex"=dword:00000001
"DhcpIPAddress"=hex:c0,a8,01,65
"DhcpSubnetMask"=hex:ff,ff,ff,00
"DhcpServer"=hex:c0,a8,01,01
"DhcpDesiredIPAddress"=hex:c0,a8,01,65
"Lease"=hex:80,51,01,00
"LeaseObtainedTime"=hex:9a,79,d6,2c
"T1"=hex:5a,22,d7,2c
"T2"=hex:9a,87,d7,2c
"LeaseTerminatesTime"=hex:1a,cb,d7,2c
"HardwareType"=hex:01
"HardwareAddress"=hex:00,0c,41,09,2a,a1
"IPAutoconfigurationAddress"="0.0.0.0"
"IPAutoconfigurationSeed"=dword:476ca6f9
"AddressType"=dword:00000000
"OptionInfo"=hex:0f,0e,45,61,72,74,68,6c,69,6e,6b,2e,6e,65,74,00,06,0c,cf,45,\
bc,b9,cf,45,bc,ba,cf,45,bc,bb,03,04,c0,a8,01,01,01,04,ff,ff,ff,00,ff,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\DhcpOptions]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\DhcpOptions\010020E50100A0]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\DhcpOptions\010010B5066F44]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\DhcpOptions\0100104BCADE1C]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\DhcpOptions\010020E5010B9B]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\DhcpOptions\010020E5010B71]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\DhcpOptions\010020E5010EA8]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\DhcpOptions\01000625A7FFEA]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\DhcpOptions\010010B558E068]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\DhcpOptions\0100055DCF5670]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\DhcpOptions\01000C41092AA1]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\NETBEUI]
"sessions"="10"
"ncbs"="12"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\NETBEUI\Ndi]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\NETBEUI\Ndi\params]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\NETBEUI\Ndi\params\sessions]
"ParamDesc"="Maximum Sessions"
"default"="10"
"type"="int"
"min"="3"
"max"="117"
@="10"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\NETBEUI\Ndi\params\ncbs]
"ParamDesc"="NCBS"
"default"="12"
"type"="int"
"min"="7"
"max"="255"
@="12"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\VREDIR]
"StaticVxD"="vredir.vxd"
"Start"=hex:00
"NetClean"=hex:01
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\DFS]
"StaticVxD"="dfs.vxd"
"Start"=hex:00
"NetClean"=hex:01
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\TCAATDI]
"DoAdapterOpenOnBind"="FALSE"
"NDIS2MACS"="FALSE"
"LOWWATER"="5"
"HIGHWATER"="15"
"SENDDELAY"="5"
"Bound"="NO"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\TCAATDI\Ndi]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\TCAATDI\Ndi\params]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\TCAATDI\Ndi\params\DoAdapterOpenOnBind]
"ParamDesc"="DoAdapterOpenOnBind?"
@="FALSE"
"default"="FALSE"
"type"="enum"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\TCAATDI\Ndi\params\DoAdapterOpenOnBind\enum]
"FALSE"="FALSE"
"TRUE"="TRUE"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\TCAATDI\Ndi\params\NDIS2MACS]
"ParamDesc"="NDIS2MACS"
@="FALSE"
"default"="FALSE"
"type"="enum"
"optional"="1"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\TCAATDI\Ndi\params\NDIS2MACS\enum]
"FALSE"="FALSE"
"TRUE"="TRUE"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\TCAATDI\Ndi\params\LOWWATER]
"ParamDesc"="LOWWATER"
@="5"
"default"="5"
"type"="int"
"min"="1"
"max"="100"
"optional"="1"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\TCAATDI\Ndi\params\HIGHWATER]
"ParamDesc"="HIGHWATER"
@="15"
"default"="15"
"type"="int"
"min"="1"
"max"="100"
"optional"="1"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\TCAATDI\Ndi\params\SENDDELAY]
"ParamDesc"="SENDDELAY"
@="5"
"default"="5"
"type"="int"
"min"="1"
"max"="100"
"optional"="1"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\VSHINIT]
"StaticVxD"="c:\\WINDOWS\\SYSTEM\\VSHINIT.VXD"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\NDISWAN]
"Start"=hex:00
"NetClean"=hex:01
"StaticVxd"="ndiswan.vxd"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\PMOUSE]
"StaticVxD"="PELMOUSE.VxD"
-
Definitely not there. The only other place it could be is in the C:\Windows\System.Ini, use Notepad to open that file. Use ; to comment out the line or delete the reference.
-
I was able to find (CDaint2f.vxd) and delete it in sysedit, so now that problem is solved also. Thanks! Did you see the other questions I asked you before I sent all those regedit files? The problem about my internet homepage changing---could that be related to a program called Upload or Upfind or something like that? I have noticed that after I take it off the list of startup items in msconfig, it keeps coming up checked every time i restart my computer. I went to explorer and tried to delete it and through Run/Start/Find and thought I deleted it but it keeps coming back. How do you get rid of something like that? The file is named c:\programs\upload tonscake. I think there's another related one called c:\program~1\upload~1\antiholdbat.exe. Also need the name of the best free pop-up stopper. and I really am interested in getting the "sleep" feature to work again in Win 98. Thanks, if you have any ideas on any of these items
-
I missed the hijacked home page. First run CWShredder, using the Fix option. Then install SpyBot Search & Destroy, then do the update, then have it Scan for Problems. Have it remove everything already checked off. Then use HijackThis, have it scan and then post the log on here, don't Fix anything with HijackThis, yet.
98 is really bad with power management, but these things may be interferring with it.
-
ok, now I ran all those programs. The hijackThis log will follow.
Logfile of HijackThis v1.97.7
Scan saved at 9:23:59 PM, on 4/20/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSGLOOP.EXE
C:\WINDOWS\SYSTEM\MSG32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\MY DOCUMENTS\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://allaboutsearching.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://allaboutsearching.com/searchbar.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.earthlink.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink.net/partner/mor...on/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://allaboutsearching.com/searchbar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://rd.yahoo.com/customize/ymsgr/...//my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://allaboutsearching.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://allaboutsearching.com/searchbar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\TOOLBAR\TOOLBAR.DLL/sa
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://allaboutsearching.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Yahoo!
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://rd.yahoo.com/customize/ymsgr/.../www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 24.243.136.152
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\TOOLBAR\TOOLBAR.DLL/sa
R3 - Default URLSearchHook is missing
F1 - win.ini: run=hpfsched
O1 - Hosts: myRepeatArray[3] = "10";
O1 - Hosts: myRepeatArray[3] = "10";
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\VSCSHELLEXTENSION.DLL
O3 - Toolbar: (no name) - {224530A0-C9CB-4AEE-9C0F-54AC1B533211} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar.dll
O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\TOOLBAR\TOOLBAR.DLL
O3 - Toolbar: Vga Online Stupid - {04DFE8DA-0125-45E5-AFBF-D62C0ABA00A0} - C:\PROGRAM FILES\BORE JUMP\SOAP LOAD.DLL
O4 - HKLM\..\Run: [ConMgr.exe] "C:\PROGRAM FILES\EARTHLINK 5.0\CONMGR.EXE"
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe
O4 - Startup: Event Reminder.lnk = C:\pmw\PMREMIND.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmsearch.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmsimilar.html
O8 - Extra context menu item: Backward &Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmtrans.html
O9 - Extra button: AIM (HKLM)
O12 - Plugin for .mp3: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {50F65670-1729-11D2-A51F-0020AFE5D502} (ForumChat) - http://objects.compuserve.com/chat/RTCChat.cab
O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) -
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst.cab
O16 - DPF: {CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_02) -
O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - https://rr.esecurecare.net/rnt/rnl/java/RntX.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yaho...mmapi_0727.dll
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/downlo...22/wmv9VCM.CAB
O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.aimphuck.com/Imbum_bw.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...096.3690740741
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 207.69.188.185,207.69.188.186,207.69.188.187
-
Have all browser windows and Windows Explorer closed, and remove these items in HijackThis.
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://allaboutsearching.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://allaboutsearching.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://allaboutsearching.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://allaboutsearching.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://allaboutsearching.com/searchbar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\TOOLBAR\TOOLBAR.DLL/sa
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://allaboutsearching.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about :blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\TOOLBAR\TOOLBAR.DLL/sa
O1 - Hosts: myRepeatArray[3] = "10";
O1 - Hosts: myRepeatArray[3] = "10";
O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\TOOLBAR\TOOLBAR.DLL
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.aimphuck.com/Imbum_bw.cab
Delete the folder C:\Program Files\Toolbar, this folder has nothing to do with the Google toolbar.
Reboot, and you should be able to change your homepage.