Hallo,
folgendes Problem: Explorer.Exe verursacht 100% CPU Auslastung beim Öffnen vom Ordner Eigene Datein. Wer kann mir dabei helfen, habe schon rumgegoogelt ohne Ende aber noch nicht das Richtige gefunden. Füge mein Hijack.log bei.
Danke.
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 13:53:12, on 11.07.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\cisvc.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkUFind.exe
C:\Programme\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe
C:\Programme\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
C:\Programme\QuickTime\qttask.exe
C:\Programme\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\carpserv.exe
C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programme\Microsoft IntelliType Pro\itype.exe
C:\Programme\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\Spamihilator\spamihilator.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe
C:\Programme\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Spybot - Search & Destroy\TeaTimer.exe
C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexingService.exe
C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexStoreSvr.exe
C:\Dokumente und Einstellungen\Jörgel\Eigene Dateien\HiJackThis_v2.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.t-online.de/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.t-online.de
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.t-online.de
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer bereitgestellt von T-Online
O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programme\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [PMCS] C:\Programme\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe -host -clearDebug
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [PMCRemote] C:\Programme\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programme\Gemeinsame Dateien\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [avgnt] "C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [itype] "c:\Programme\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Programme\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Programme\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Spamihilator] "C:\Programme\Spamihilator\spamihilator.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [swg] C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/german/par ... nicode.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/house ... hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/Shar ... vSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.c ... 040510.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.johannrain-softwareentwicklu ... oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 4826135370
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 4826469182
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan ... asinst.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsup ... mAData.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsup ... veData.cab
O16 - DPF: {F7DC2A2E-FC34-11D3-B1D9-00A0C99B41BB} (Zoom Class) - http://www.zoomify.com/download/zoomify305.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: AntiVir PersonalEdition Classic Planer (AntiVirScheduler) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Pinnacle Systems tvtv Spooler (EpgSpooler) - - c:\progra~1\pinnacle\mediac~1\epgspo~2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Programme\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - c:\programme\pinnacle\shared files\programs\mediaserver\pmshost.exe
O24 - Desktop Component 1: (no name) - http://speedmanager.t-com-dsl.de/
--
End of file - 10688 bytes
Für die Hilfe schonmal ein Danke vorweg.
Gruß JW1
Warum kostenlos registrieren?
Nur als registriertes Mitglied hast Du vollen Zugriff auf alle Funktionen unserer Website. So kannst Du eigene Fragen stellen und hast die volle Übersicht über neue interessante Themen im Forum.
Jetzt kostenlos registrieren.
Login
Explorer.exe verursacht 100% CPU Auslastung
14 Beiträge • Seite 1 von 1
öffne das HijackThis -- Button "scan" -- vor diese Einträge ein Häkchen setzen -- Button "Fix checked" anklicken – PC nun neustarten
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
O16 - DPF: {F7DC2A2E-FC34-11D3-B1D9-00A0C99B41BB} (Zoom Class) - http://www.zoomify.com/download/zoomify305.cab
Counterspy V2 anwenden
http://research.sunbelt-software.com/download.aspx
* Installation
* CounterSpywird geupdatet
Nicht Scannen.
Neustart F8 drücken, abgesicherter Modus starten
im abgesicherten Modus:
Counterspy starten
* Klicke: "Run a Spyware Scan Now"
* nach dem Scan muss man sich entscheiden für:
*Ignore
*Remove --> Status: Deleted
*Quarantaine
wähle immer Remove und starte den PC neu
Nach Neustart in Normalmodus
poste das log von Counterspy
Hinweis:
Scanreport finden:
klicke : View details
diesen Report kann man abkopieren: [mit der linken Maus-Taste über den Text fahren -> rechte Maustaste -> kopieren -> hier im Thread -> rechte Maustaste -> einfügen]
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
O16 - DPF: {F7DC2A2E-FC34-11D3-B1D9-00A0C99B41BB} (Zoom Class) - http://www.zoomify.com/download/zoomify305.cab
Counterspy V2 anwenden
http://research.sunbelt-software.com/download.aspx
* Installation
* CounterSpywird geupdatet
Nicht Scannen.
Neustart F8 drücken, abgesicherter Modus starten
im abgesicherten Modus:
Counterspy starten
* Klicke: "Run a Spyware Scan Now"
* nach dem Scan muss man sich entscheiden für:
*Ignore
*Remove --> Status: Deleted
*Quarantaine
wähle immer Remove und starte den PC neu
Nach Neustart in Normalmodus
poste das log von Counterspy
Hinweis:
Scanreport finden:
klicke : View details
diesen Report kann man abkopieren: [mit der linken Maus-Taste über den Text fahren -> rechte Maustaste -> kopieren -> hier im Thread -> rechte Maustaste -> einfügen]
- Humdinger
- Mitarbeiter
- Beiträge: 896
- Registriert: 22.03.2006, 14:22
- Wohnort: Mainz
Hallo,
nachstehend den Report von CounterSpy:
[code]
Scan History Details
Start Date: 11.07.2007 20:47:35
End Date: 11.07.2007 22:11:56
Total Time: 84 Min 21 Sec
Detected security risks
BearShare P2P Program more information...
Details: BearShare is a peer-to-peer (P2P) application that allows its users to join together in a network via the Internet and share files from each other's hard drives.
Status: Deleted
Registry entries detected
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\AuxUserType
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\AuxUserType
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\AuxUserType\2
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\AuxUserType\2
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\AuxUserType\3
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\AuxUserType\3
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion\Readable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion\Readable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion\Readable\Main
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion\Readable\Main
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion\Readwritable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion\Readwritable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion\Readwritable\Main
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion\Readwritable\Main
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\DefaultFile
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\DefaultFile
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\0
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\0
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\1
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\1
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\2
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\2
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\3
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\3
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\4
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\4
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DefaultExtension
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DefaultExtension
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DefaultIcon
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DefaultIcon
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DocObject
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DocObject
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Implemented Categories
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Implemented Categories
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Implemented Categories\{000C0118-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Implemented Categories\{000C0118-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\InprocHandler32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\InprocHandler32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Insertable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Insertable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\MiscStatus
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\MiscStatus
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\OfficeCompliant
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\OfficeCompliant
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\PersistentHandler
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\PersistentHandler
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Printable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Printable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\ProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\ProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Typelib
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Typelib
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Verb
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Verb
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Verb\0
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Verb\0
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Verb\1
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Verb\1
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Version
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Version
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\ACTIVE SETUP\INSTALLED COMPONENTS\{5F95E1AF-2620-4F15-BDF9-7FDCE4607E17}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\ACTIVE SETUP\INSTALLED COMPONENTS\{5F95E1AF-2620-4F15-BDF9-7FDCE4607E17}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\ACTIVE SETUP\INSTALLED COMPONENTS\{5F95E1AF-2620-4F15-BDF9-7FDCE4607E17}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\ACTIVE SETUP\INSTALLED COMPONENTS\{5F95E1AF-2620-4F15-BDF9-7FDCE4607E17}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\ACTIVE SETUP\INSTALLED COMPONENTS\{5F95E1AF-2620-4F15-BDF9-7FDCE4607E17}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\ACTIVE SETUP\INSTALLED COMPONENTS\{5F95E1AF-2620-4F15-BDF9-7FDCE4607E17}
HKEY_USERS\S-1-5-21-2760978244-3742667488-1603439836-1005\APPEVENTS\EVENTLABELS\BEARSHARECHATNOTIFYMSG
HKEY_USERS\S-1-5-21-2760978244-3742667488-1603439836-1005\APPEVENTS\EVENTLABELS\BEARSHARECHATNOTIFYMSG
HKEY_USERS\S-1-5-21-2760978244-3742667488-1603439836-1005\APPEVENTS\SCHEMES\APPS\BEARSHARE
HKEY_USERS\S-1-5-21-2760978244-3742667488-1603439836-1005\APPEVENTS\SCHEMES\APPS\BEARSHARE
HKEY_USERS\S-1-5-21-2760978244-3742667488-1603439836-1005\APPEVENTS\SCHEMES\APPS\BEARSHARE\BearShareChatNotifyMsg
HKEY_USERS\S-1-5-21-2760978244-3742667488-1603439836-1005\APPEVENTS\SCHEMES\APPS\BEARSHARE\BearShareChatNotifyMsg
HKEY_USERS\S-1-5-21-2760978244-3742667488-1603439836-1005\APPEVENTS\SCHEMES\APPS\BEARSHARE\BearShareChatNotifyMsg\.Current
Invisible Keylogger Commercial Key Logger more information...
Status: Deleted
Files detected
C:\WINDOWS\WINDOWS\Thumbs.db:encryptable
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\expsrv.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msexch40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msexcl40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msjet40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msjetol1.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msjetoledb40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msjtes40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msltus40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\mspbde40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msrd2x40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msrepl40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\mstext40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msxbde40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\spuninst\spuninst.bat
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\6to4svc.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\iphlpapi.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\ipv6.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\ipv6mon.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\netip6.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\netoc.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\netoc.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\wship6.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB820291$\appwiz.cpl
C:\WINDOWS\WINDOWS\$NtUninstallKB820291$\explorer.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB820291$\shmgrate.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB820291$\spuninst\spuninst.bat
C:\WINDOWS\WINDOWS\$NtUninstallKB820291$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB820291$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB821253$\dwwin.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB821253$\faultrep.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB821253$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB821253$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB821557$\shell32.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB821557$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB821557$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB822603$\hccoin.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB822603$\spuninst\spuninst.bat
C:\WINDOWS\WINDOWS\$NtUninstallKB822603$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB822603$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB823559$\html32.cnv
C:\WINDOWS\WINDOWS\$NtUninstallKB823559$\spuninst\spuninst.bat
C:\WINDOWS\WINDOWS\$NtUninstallKB823559$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB823559$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB823980$\ole32.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB823980$\rpcrt4.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB823980$\rpcss.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB823980$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB823980$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB824105$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB824105$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB824146$\ole32.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB824146$\rpcrt4.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB824146$\rpcss.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB824146$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB824146$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ322011$\fxsclnt.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ322011$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ322011$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ327979$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ327979$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ328310$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ328310$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ328310$\sysmain.sdb
C:\WINDOWS\WINDOWS\$NtUninstallQ328310$\user32.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ328310$\win32k.sys
C:\WINDOWS\WINDOWS\$NtUninstallQ328310$\winsrv.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ329048$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ329048$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ329048$\zipfldr.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ329115$\crypt32.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ329115$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ329115$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ329170$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ329170$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ329390$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ329390$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ329441$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ329441$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ329441$\srrstr.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ329834$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ329834$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\hhctrl.ocx
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\hhsetup.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\itircl.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\itss.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\migwiz.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\osk.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\pchshell.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\spuninst\spuninst.bat
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ810577$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ810577$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ810833$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ810833$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ811493$\ntkrnlpa.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ811493$\ntoskrnl.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ811493$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ811493$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ814033$\newdev.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ814033$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ814033$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ814995$\acgenral.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ814995$\apph_sp.sdb
C:\WINDOWS\WINDOWS\$NtUninstallQ814995$\apphelp.sdb
C:\WINDOWS\WINDOWS\$NtUninstallQ814995$\apps.chm
C:\WINDOWS\WINDOWS\$NtUninstallQ814995$\apps_sp.chm
C:\WINDOWS\WINDOWS\$NtUninstallQ814995$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ814995$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ814995$\sysmain.sdb
C:\WINDOWS\WINDOWS\$NtUninstallQ815021$\ntdll.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ815021$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ815021$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ815485$\netshell.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ815485$\reg00003
C:\WINDOWS\WINDOWS\$NtUninstallQ815485$\spuninst\spuninst.bat
C:\WINDOWS\WINDOWS\$NtUninstallQ815485$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ815485$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ815485$\wzcdlg.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ815485$\wzcsapi.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ815485$\wzcsvc.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ817606$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ817606$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\Angler.bmp
C:\WINDOWS\WINDOWS\AppPatch\acgenral.dll
C:\WINDOWS\WINDOWS\AppPatch\AcLayers.dll
C:\WINDOWS\WINDOWS\AppPatch\AcLua.dll
C:\WINDOWS\WINDOWS\AppPatch\AcSpecfc.dll
C:\WINDOWS\WINDOWS\AppPatch\AcVerfyr.dll
C:\WINDOWS\WINDOWS\AppPatch\AcXtrnal.dll
C:\WINDOWS\WINDOWS\AppPatch\apph_sp.sdb
C:\WINDOWS\WINDOWS\AppPatch\apphelp.sdb
C:\WINDOWS\WINDOWS\AppPatch\drvmain.sdb
C:\WINDOWS\WINDOWS\AppPatch\msimain.sdb
C:\WINDOWS\WINDOWS\AppPatch\sysmain.sdb
C:\WINDOWS\WINDOWS\Blaue Spitzen 16.bmp
C:\WINDOWS\WINDOWS\bootstat.dat
C:\WINDOWS\WINDOWS\clock.avi
C:\WINDOWS\WINDOWS\control.ini
C:\WINDOWS\WINDOWS\Cursors\3dgarro.cur
C:\WINDOWS\WINDOWS\Cursors\3dgmove.cur
C:\WINDOWS\WINDOWS\Cursors\3dgnesw.cur
C:\WINDOWS\WINDOWS\Cursors\3dgno.cur
C:\WINDOWS\WINDOWS\Cursors\3dgns.cur
C:\WINDOWS\WINDOWS\Cursors\3dgnwse.cur
C:\WINDOWS\WINDOWS\Cursors\3dgwe.cur
C:\WINDOWS\WINDOWS\Cursors\3dsmove.cur
C:\WINDOWS\WINDOWS\Cursors\3dsns.cur
C:\WINDOWS\WINDOWS\Cursors\3dsnwse.cur
C:\WINDOWS\WINDOWS\Cursors\3dwarro.cur
C:\WINDOWS\WINDOWS\Cursors\3dwmove.cur
C:\WINDOWS\WINDOWS\Cursors\3dwnesw.cur
C:\WINDOWS\WINDOWS\Cursors\3dwno.cur
C:\WINDOWS\WINDOWS\Cursors\3dwns.cur
C:\WINDOWS\WINDOWS\Cursors\3dwnwse.cur
C:\WINDOWS\WINDOWS\Cursors\3dwwe.cur
C:\WINDOWS\WINDOWS\Cursors\appstar2.ani
C:\WINDOWS\WINDOWS\Cursors\appstar3.ani
C:\WINDOWS\WINDOWS\Cursors\appstart.ani
C:\WINDOWS\WINDOWS\Cursors\arrow_i.cur
C:\WINDOWS\WINDOWS\Cursors\arrow_il.cur
C:\WINDOWS\WINDOWS\Cursors\arrow_im.cur
C:\WINDOWS\WINDOWS\Cursors\arrow_l.cur
C:\WINDOWS\WINDOWS\Cursors\arrow_m.cur
C:\WINDOWS\WINDOWS\Cursors\arrow_r.cur
C:\WINDOWS\WINDOWS\Cursors\arrow_rl.cur
C:\WINDOWS\WINDOWS\Cursors\arrow_rm.cur
C:\WINDOWS\WINDOWS\Cursors\banana.ani
C:\WINDOWS\WINDOWS\Cursors\barber.ani
C:\WINDOWS\WINDOWS\Cursors\beam_i.cur
C:\WINDOWS\WINDOWS\Cursors\beam_il.cur
C:\WINDOWS\WINDOWS\Cursors\beam_im.cur
C:\WINDOWS\WINDOWS\Cursors\beam_l.cur
C:\WINDOWS\WINDOWS\Cursors\beam_m.cur
C:\WINDOWS\WINDOWS\Cursors\beam_r.cur
C:\WINDOWS\WINDOWS\Cursors\beam_rl.cur
C:\WINDOWS\WINDOWS\Cursors\beam_rm.cur
C:\WINDOWS\WINDOWS\Cursors\busy_i.cur
C:\WINDOWS\WINDOWS\Cursors\busy_il.cur
C:\WINDOWS\WINDOWS\Cursors\busy_im.cur
C:\WINDOWS\WINDOWS\Cursors\busy_l.cur
C:\WINDOWS\WINDOWS\Cursors\busy_m.cur
C:\WINDOWS\WINDOWS\Cursors\busy_r.cur
C:\WINDOWS\WINDOWS\Cursors\busy_rl.cur
C:\WINDOWS\WINDOWS\Cursors\busy_rm.cur
C:\WINDOWS\WINDOWS\Cursors\coin.ani
C:\WINDOWS\WINDOWS\Cursors\counter.ani
C:\WINDOWS\WINDOWS\Cursors\cross.cur
C:\WINDOWS\WINDOWS\Cursors\cross_i.cur
C:\WINDOWS\WINDOWS\Cursors\cross_il.cur
C:\WINDOWS\WINDOWS\Cursors\cross_im.cur
C:\WINDOWS\WINDOWS\Cursors\cross_l.cur
C:\WINDOWS\WINDOWS\Cursors\cross_m.cur
C:\WINDOWS\WINDOWS\Cursors\cross_r.cur
C:\WINDOWS\WINDOWS\Cursors\cross_rl.cur
C:\WINDOWS\WINDOWS\Cursors\cross_rm.cur
C:\WINDOWS\WINDOWS\Cursors\dinosau2.ani
C:\WINDOWS\WINDOWS\Cursors\dinosaur.ani
C:\WINDOWS\WINDOWS\Cursors\drum.ani
C:\WINDOWS\WINDOWS\Cursors\fillitup.ani
C:\WINDOWS\WINDOWS\Cursors\hand.ani
C:\WINDOWS\WINDOWS\Cursors\handapst.ani
C:\WINDOWS\WINDOWS\Cursors\handnesw.ani
C:\WINDOWS\WINDOWS\Cursors\handno.ani
C:\WINDOWS\WINDOWS\Cursors\handns.ani
C:\WINDOWS\WINDOWS\Cursors\handnwse.ani
C:\WINDOWS\WINDOWS\Cursors\handwait.ani
C:\WINDOWS\WINDOWS\Cursors\handwe.ani
C:\WINDOWS\WINDOWS\Cursors\harrow.cur
C:\WINDOWS\WINDOWS\Cursors\hcross.cur
C:\WINDOWS\WINDOWS\Cursors\help_i.cur
C:\WINDOWS\WINDOWS\Cursors\help_il.cur
C:\WINDOWS\WINDOWS\Cursors\help_im.cur
C:\WINDOWS\WINDOWS\Cursors\help_l.cur
C:\WINDOWS\WINDOWS\Cursors\help_m.cur
C:\WINDOWS\WINDOWS\Cursors\help_r.cur
C:\WINDOWS\WINDOWS\Cursors\help_rl.cur
C:\WINDOWS\WINDOWS\Cursors\help_rm.cur
C:\WINDOWS\WINDOWS\Cursors\hibeam.cur
C:\WINDOWS\WINDOWS\Cursors\hmove.cur
C:\WINDOWS\WINDOWS\Cursors\hnesw.cur
C:\WINDOWS\WINDOWS\Cursors\hnodrop.cur
C:\WINDOWS\WINDOWS\Cursors\hns.cur
C:\WINDOWS\WINDOWS\Cursors\hnwse.cur
C:\WINDOWS\WINDOWS\Cursors\horse.ani
C:\WINDOWS\WINDOWS\Cursors\hourgla2.ani
C:\WINDOWS\WINDOWS\Cursors\hourgla3.ani
C:\WINDOWS\WINDOWS\Cursors\hourglas.ani
C:\WINDOWS\WINDOWS\Cursors\hwe.cur
C:\WINDOWS\WINDOWS\Cursors\lappstrt.cur
C:\WINDOWS\WINDOWS\Cursors\larrow.cur
C:\WINDOWS\WINDOWS\Cursors\lcross.cur
C:\WINDOWS\WINDOWS\Cursors\libeam.cur
C:\WINDOWS\WINDOWS\Cursors\lmove.cur
C:\WINDOWS\WINDOWS\Cursors\lnesw.cur
C:\WINDOWS\WINDOWS\Cursors\lnodrop.cur
C:\WINDOWS\WINDOWS\Cursors\lns.cur
C:\WINDOWS\WINDOWS\Cursors\lnwse.cur
C:\WINDOWS\WINDOWS\Cursors\lwait.cur
C:\WINDOWS\WINDOWS\Cursors\lwe.cur
C:\WINDOWS\WINDOWS\Cursors\metronom.ani
C:\WINDOWS\WINDOWS\Cursors\move_i.cur
C:\WINDOWS\WINDOWS\Cursors\move_il.cur
C:\WINDOWS\WINDOWS\Cursors\move_im.cur
C:\WINDOWS\WINDOWS\Cursors\move_l.cur
C:\WINDOWS\WINDOWS\Cursors\move_m.cur
C:\WINDOWS\WINDOWS\Cursors\move_r.cur
C:\WINDOWS\WINDOWS\Cursors\move_rl.cur
C:\WINDOWS\WINDOWS\Cursors\move_rm.cur
C:\WINDOWS\WINDOWS\Cursors\no_i.cur
C:\WINDOWS\WINDOWS\Cursors\no_il.cur
C:\WINDOWS\WINDOWS\Cursors\no_im.cur
C:\WINDOWS\WINDOWS\Cursors\no_l.cur
C:\WINDOWS\WINDOWS\Cursors\no_m.cur
C:\WINDOWS\WINDOWS\Cursors\no_r.cur
C:\WINDOWS\WINDOWS\Cursors\no_rl.cur
C:\WINDOWS\WINDOWS\Cursors\no_rm.cur
C:\WINDOWS\WINDOWS\Cursors\pen_i.cur
C:\WINDOWS\WINDOWS\Cursors\pen_il.cur
C:\WINDOWS\WINDOWS\Cursors\pen_im.cur
C:\WINDOWS\WINDOWS\Cursors\pen_l.cur
C:\WINDOWS\WINDOWS\Cursors\pen_m.cur
C:\WINDOWS\WINDOWS\Cursors\pen_r.cur
C:\WINDOWS\WINDOWS\Cursors\pen_rl.cur
C:\WINDOWS\WINDOWS\Cursors\pen_rm.cur
C:\WINDOWS\WINDOWS\Cursors\piano.ani
C:\WINDOWS\WINDOWS\Cursors\rainbow.ani
C:\WINDOWS\WINDOWS\Cursors\raindrop.ani
C:\WINDOWS\WINDOWS\Cursors\size1_i.cur
C:\WINDOWS\WINDOWS\Cursors\size1_il.cur
C:\WINDOWS\WINDOWS\Cursors\size1_im.cur
C:\WINDOWS\WINDOWS\Cursors\size1_l.cur
C:\WINDOWS\WINDOWS\Cursors\size1_m.cur
C:\WINDOWS\WINDOWS\Cursors\size1_r.cur
C:\WINDOWS\WINDOWS\Cursors\size1_rl.cur
C:\WINDOWS\WINDOWS\Cursors\size1_rm.cur
C:\WINDOWS\WINDOWS\Cursors\size2_i.cur
C:\WINDOWS\WINDOWS\Cursors\size2_il.cur
C:\WINDOWS\WINDOWS\Cursors\size2_im.cur
C:\WINDOWS\WINDOWS\Cursors\size2_l.cur
C:\WINDOWS\WINDOWS\Cursors\size2_m.cur
C:\WINDOWS\WINDOWS\Cursors\size2_r.cur
C:\WINDOWS\WINDOWS\Cursors\size2_rl.cur
C:\WINDOWS\WINDOWS\Cursors\size2_rm.cur
C:\WINDOWS\WINDOWS\Cursors\size3_i.cur
C:\WINDOWS\WINDOWS\Cursors\size3_il.cur
C:\WINDOWS\WINDOWS\Cursors\size3_im.cur
C:\WINDOWS\WINDOWS\Cursors\size3_l.cur
C:\WINDOWS\WINDOWS\Cursors\size3_m.cur
C:\WINDOWS\WINDOWS\Cursors\size3_r.cur
C:\WINDOWS\WINDOWS\Cursors\size3_rl.cur
C:\WINDOWS\WINDOWS\Cursors\size3_rm.cur
C:\WINDOWS\WINDOWS\Cursors\size4_i.cur
C:\WINDOWS\WINDOWS\Cursors\size4_il.cur
C:\WINDOWS\WINDOWS\Cursors\size4_im.cur
C:\WINDOWS\WINDOWS\Cursors\size4_l.cur
C:\WINDOWS\WINDOWS\Cursors\size4_m.cur
C:\WINDOWS\WINDOWS\Cursors\size4_r.cur
C:\WINDOWS\WINDOWS\Cursors\size4_rl.cur
C:\WINDOWS\WINDOWS\Cursors\size4_rm.cur
C:\WINDOWS\WINDOWS\Cursors\sizenesw.ani
C:\WINDOWS\WINDOWS\Cursors\sizens.ani
C:\WINDOWS\WINDOWS\Cursors\sizenwse.ani
C:\WINDOWS\WINDOWS\Cursors\sizewe.ani
C:\WINDOWS\WINDOWS\Cursors\stopwtch.ani
C:\WINDOWS\WINDOWS\Cursors\up_i.cur
C:\WINDOWS\WINDOWS\Cursors\up_il.cur
C:\WINDOWS\WINDOWS\Cursors\up_im.cur
C:\WINDOWS\WINDOWS\Cursors\up_l.cur
C:\WINDOWS\WINDOWS\Cursors\up_m.cur
C:\WINDOWS\WINDOWS\Cursors\up_r.cur
C:\WINDOWS\WINDOWS\Cursors\up_rl.cur
C:\WINDOWS\WINDOWS\Cursors\up_rm.cur
C:\WINDOWS\WINDOWS\Cursors\vanisher.ani
C:\WINDOWS\WINDOWS\Cursors\wagtail.ani
C:\WINDOWS\WINDOWS\Cursors\wait_i.cur
C:\WINDOWS\WINDOWS\Cursors\wait_il.cur
C:\WINDOWS\WINDOWS\Cursors\wait_im.cur
C:\WINDOWS\WINDOWS\Cursors\wait_l.cur
C:\WINDOWS\WINDOWS\Cursors\wait_m.cur
C:\WINDOWS\WINDOWS\Cursors\wait_r.cur
C:\WINDOWS\WINDOWS\Cursors\wait_rl.cur
C:\WINDOWS\WINDOWS\Cursors\wait_rm.cur
C:\WINDOWS\WINDOWS\Debug\oakley.log
C:\WINDOWS\WINDOWS\Debug\PASSWD.LOG
C:\WINDOWS\WINDOWS\Downloaded Program Files\desktop.ini
C:\WINDOWS\WINDOWS\Driver Cache\i386\bdaplgin.ax
C:\WINDOWS\WINDOWS\Driver Cache\i386\driver.cab
C:\WINDOWS\WINDOWS\Driver Cache\i386\explorer.exe
C:\WINDOWS\WINDOWS\Driver Cache\i386\ipsink.ax
C:\WINDOWS\WINDOWS\Driver Cache\i386\ksolay.ax
C:\WINDOWS\WINDOWS\Driver Cache\i386\ksproxy.ax
C:\WINDOWS\WINDOWS\Driver Cache\i386\kstvtune.ax
C:\WINDOWS\WINDOWS\Driver Cache\i386\kswdmcap.ax
C:\WINDOWS\WINDOWS\Driver Cache\i386\ksxbar.ax
C:\WINDOWS\WINDOWS\Driver Cache\i386\msdvbnp.ax
C:\WINDOWS\WINDOWS\Driver Cache\i386\ndis.sys
C:\WINDOWS\WINDOWS\Driver Cache\i386\ndisuio.sys
C:\WINDOWS\WINDOWS\Driver Cache\i386\ntkrnlmp.exe
C:\WINDOWS\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
C:\WINDOWS\WINDOWS\Driver Cache\i386\ntkrpamp.exe
C:\WINDOWS\WINDOWS\Driver Cache\i386\ntoskrnl.exe
C:\WINDOWS\WINDOWS\Driver Cache\i386\psisrndr.ax
C:\WINDOWS\WINDOWS\Driver Cache\i386\sp1.cab
C:\WINDOWS\WINDOWS\explorer.exe
C:\WINDOWS\WINDOWS\explorer.scf
C:\WINDOWS\WINDOWS\Feder.bmp
C:\WINDOWS\WINDOWS\Fonts\8514fix.fon
C:\WINDOWS\WINDOWS\Fonts\8514fixe.fon
C:\WINDOWS\WINDOWS\Fonts\8514fixg.fon
C:\WINDOWS\WINDOWS\Fonts\8514fixr.fon
C:\WINDOWS\WINDOWS\Fonts\8514fixt.fon
C:\WINDOWS\WINDOWS\Fonts\8514oem.fon
C:\WINDOWS\WINDOWS\Fonts\8514oeme.fon
C:\WINDOWS\WINDOWS\Fonts\8514oemg.fon
C:\WINDOWS\WINDOWS\Fonts\8514oemr.fon
C:\WINDOWS\WINDOWS\Fonts\8514oemt.fon
C:\WINDOWS\WINDOWS\Fonts\8514sys.fon
C:\WINDOWS\WINDOWS\Fonts\8514syse.fon
C:\WINDOWS\WINDOWS\Fonts\8514sysg.fon
C:\WINDOWS\WINDOWS\Fonts\8514sysr.fon
C:\WINDOWS\WINDOWS\Fonts\8514syst.fon
C:\WINDOWS\WINDOWS\Fonts\85775.fon
C:\WINDOWS\WINDOWS\Fonts\85855.fon
C:\WINDOWS\WINDOWS\Fonts\85f1257.fon
C:\WINDOWS\WINDOWS\Fonts\85s1257.fon
C:\WINDOWS\WINDOWS\Fonts\ABAC.TTF
C:\WINDOWS\WINDOWS\Fonts\ABAEXBC.TTF
C:\WINDOWS\WINDOWS\Fonts\ABALC.TTF
C:\WINDOWS\WINDOWS\Fonts\Absalom_.TTF
C:\WINDOWS\WINDOWS\Fonts\AgencyB.TTF
C:\WINDOWS\WINDOWS\Fonts\AgencyR.TTF
C:\WINDOWS\WINDOWS\Fonts\ALGER.TTF
C:\WINDOWS\WINDOWS\Fonts\Alibi___.TTF
C:\WINDOWS\WINDOWS\Fonts\Andyb.TTF
C:\WINDOWS\WINDOWS\Fonts\ANTQUAB.TTF
C:\WINDOWS\WINDOWS\Fonts\ANTQUABI.TTF
C:\WINDOWS\WINDOWS\Fonts\ANTQUAI.TTF
C:\WINDOWS\WINDOWS\Fonts\app775.fon
C:\WINDOWS\WINDOWS\Fonts\app850.fon
C:\WINDOWS\WINDOWS\Fonts\app852.fon
C:\WINDOWS\WINDOWS\Fonts\app855.fon
C:\WINDOWS\WINDOWS\Fonts\app857.fon
C:\WINDOWS\WINDOWS\Fonts\app866.fon
C:\WINDOWS\WINDOWS\Fonts\ARBLI___.TTF
C:\WINDOWS\WINDOWS\Fonts\arial.ttf
C:\WINDOWS\WINDOWS\Fonts\arialbd.ttf
C:\WINDOWS\WINDOWS\Fonts\arialbi.ttf
C:\WINDOWS\WINDOWS\Fonts\ariali.ttf
C:\WINDOWS\WINDOWS\Fonts\arialn.ttf
C:\WINDOWS\WINDOWS\Fonts\ArialNb.TTF
C:\WINDOWS\WINDOWS\Fonts\ArialNbi.TTF
C:\WINDOWS\WINDOWS\Fonts\ArialNi.TTF
C:\WINDOWS\WINDOWS\Fonts\ariblk.ttf
C:\WINDOWS\WINDOWS\Fonts\ARLRDBD.TTF
C:\WINDOWS\WINDOWS\Fonts\BASKVILL.TTF
C:\WINDOWS\WINDOWS\Fonts\Batavia_.TTF
C:\WINDOWS\WINDOWS\Fonts\BAUHS93.TTF
C:\WINDOWS\WINDOWS\Fonts\Beesknee.ttf
C:\WINDOWS\WINDOWS\Fonts\BERNHC.TTF
C:\WINDOWS\WINDOWS\Fonts\BicklySc.ttf
C:\WINDOWS\WINDOWS\Fonts\BKANT.TTF
C:\WINDOWS\WINDOWS\Fonts\BOOKOS.TTF
C:\WINDOWS\WINDOWS\Fonts\BOOKOSB.TTF
C:\WINDOWS\WINDOWS\Fonts\BOOKOSBI.TTF
C:\WINDOWS\WINDOWS\Fonts\BOOKOSI.TTF
C:\WINDOWS\WINDOWS\Fonts\BradhITC.TTF
C:\WINDOWS\WINDOWS\Fonts\BRAGGA.TTF
C:\WINDOWS\WINDOWS\Fonts\BRITANIC.TTF
C:\WINDOWS\WINDOWS\Fonts\BROADW.TTF
C:\WINDOWS\WINDOWS\Fonts\BRUSHSCI.TTF
C:\WINDOWS\WINDOWS\Fonts\CALIST.TTF
C:\WINDOWS\WINDOWS\Fonts\CALISTB.TTF
C:\WINDOWS\WINDOWS\Fonts\CALISTBI.TTF
C:\WINDOWS\WINDOWS\Fonts\CALISTI.TTF
C:\WINDOWS\WINDOWS\Fonts\casmira_.TTF
C:\WINDOWS\WINDOWS\Fonts\CASTELAR.TTF
C:\WINDOWS\WINDOWS\Fonts\cga40737.fon
C:\WINDOWS\WINDOWS\Fonts\cga40850.fon
C:\WINDOWS\WINDOWS\Fonts\cga40852.fon
C:\WINDOWS\WINDOWS\Fonts\cga40857.fon
C:\WINDOWS\WINDOWS\Fonts\cga40866.fon
C:\WINDOWS\WINDOWS\Fonts\cga40869.fon
C:\WINDOWS\WINDOWS\Fonts\cga40woa.fon
C:\WINDOWS\WINDOWS\Fonts\cga80737.fon
C:\WINDOWS\WINDOWS\Fonts\cga80850.fon
C:\WINDOWS\WINDOWS\Fonts\cga80852.fon
C:\WINDOWS\WINDOWS\Fonts\cga80857.fon
C:\WINDOWS\WINDOWS\Fonts\cga80866.fon
C:\WINDOWS\WINDOWS\Fonts\cga80869.fon
C:\WINDOWS\WINDOWS\Fonts\cga80woa.fon
C:\WINDOWS\WINDOWS\Fonts\Chiller.ttf
C:\WINDOWS\WINDOWS\Fonts\comic.ttf
C:\WINDOWS\WINDOWS\Fonts\comicbd.ttf
C:\WINDOWS\WINDOWS\Fonts\COOPBL.TTF
C:\WINDOWS\WINDOWS\Fonts\Coprgtb.TTF
C:\WINDOWS\WINDOWS\Fonts\Coprgtl.TTF
C:\WINDOWS\WINDOWS\Fonts\coue1257.fon
C:\WINDOWS\WINDOWS\Fonts\couf1257.fon
C:\WINDOWS\WINDOWS\Fonts\cour.ttf
C:\WINDOWS\WINDOWS\Fonts\courbd.ttf
C:\WINDOWS\WINDOWS\Fonts\courbi.ttf
C:\WINDOWS\WINDOWS\Fonts\coure.fon
C:\WINDOWS\WINDOWS\Fonts\couree.fon
C:\WINDOWS\WINDOWS\Fonts\coureg.fon
C:\WINDOWS\WINDOWS\Fonts\courer.fon
C:\WINDOWS\WINDOWS\Fonts\couret.fon
C:\WINDOWS\WINDOWS\Fonts\courf.fon
C:\WINDOWS\WINDOWS\Fonts\courfe.fon
C:\WINDOWS\WINDOWS\Fonts\courfg.fon
C:\WINDOWS\WINDOWS\Fonts\courfr.fon
C:\WINDOWS\WINDOWS\Fonts\courft.fon
C:\WINDOWS\WINDOWS\Fonts\couri.ttf
C:\WINDOWS\WINDOWS\Fonts\Curlz___.TTF
C:\WINDOWS\WINDOWS\Fonts\desktop.ini
C:\WINDOWS\WINDOWS\Fonts\dos737.fon
C:\WINDOWS\WINDOWS\Fonts\dosapp.fon
C:\WINDOWS\WINDOWS\Fonts\EDDA.TTF
C:\WINDOWS\WINDOWS\Fonts\ega40737.fon
C:\WINDOWS\WINDOWS\Fonts\ega40850.fon
C:\WINDOWS\WINDOWS\Fonts\ega40852.fon
C:\WINDOWS\WINDOWS\Fonts\ega40857.fon
C:\WINDOWS\WINDOWS\Fonts\ega40866.fon
C:\WINDOWS\WINDOWS\Fonts\ega40869.fon
C:\WINDOWS\WINDOWS\Fonts\ega40woa.fon
C:\WINDOWS\WINDOWS\Fonts\ega80737.fon
C:\WINDOWS\WINDOWS\Fonts\ega80850.fon
C:\WINDOWS\WINDOWS\Fonts\ega80852.fon
C:\WINDOWS\WINDOWS\Fonts\ega80857.fon
C:\WINDOWS\WINDOWS\Fonts\ega80866.fon
C:\WINDOWS\WINDOWS\Fonts\ega80869.fon
C:\WINDOWS\WINDOWS\Fonts\ega80woa.fon
C:\WINDOWS\WINDOWS\Fonts\Elegance.TTF
C:\WINDOWS\WINDOWS\Fonts\ELEPHNT.TTF
C:\WINDOWS\WINDOWS\Fonts\ELEPHNTI.TTF
C:\WINDOWS\WINDOWS\Fonts\Ellis___.TTF
C:\WINDOWS\WINDOWS\Fonts\Engr.TTF
C:\WINDOWS\WINDOWS\Fonts\Engrb.TTF
C:\WINDOWS\WINDOWS\Fonts\Enviro.ttf
C:\WINDOWS\WINDOWS\Fonts\Erasdemi.TTF
C:\WINDOWS\WINDOWS\Fonts\Eraslght.TTF
C:\WINDOWS\WINDOWS\Fonts\estre.ttf
C:\WINDOWS\WINDOWS\Fonts\Eurosti.TTF
C:\WINDOWS\WINDOWS\Fonts\Eurostib.TTF
C:\WINDOWS\WINDOWS\Fonts\Excess__.TTF
C:\WINDOWS\WINDOWS\Fonts\Felixti.TTF
C:\WINDOWS\WINDOWS\Fonts\FineHand.ttf
C:\WINDOWS\WINDOWS\Fonts\Frabk.TTF
C:\WINDOWS\WINDOWS\Fonts\Frabkit.TTF
C:\WINDOWS\WINDOWS\Fonts\Fradm.TTF
C:\WINDOWS\WINDOWS\Fonts\FRADMCN.TTF
C:\WINDOWS\WINDOWS\Fonts\Fradmit.TTF
C:\WINDOWS\WINDOWS\Fonts\FRAHV.TTF
C:\WINDOWS\WINDOWS\Fonts\FRAHVIT.TTF
C:\WINDOWS\WINDOWS\Fonts\framd.ttf
C:\WINDOWS\WINDOWS\Fonts\Framdcn.TTF
C:\WINDOWS\WINDOWS\Fonts\framdit.ttf
C:\WINDOWS\WINDOWS\Fonts\FreeScpt.ttf
C:\WINDOWS\WINDOWS\Fonts\Frscript.TTF
C:\WINDOWS\WINDOWS\Fonts\GARA.TTF
C:\WINDOWS\WINDOWS\Fonts\GARABD.TTF
C:\WINDOWS\WINDOWS\Fonts\GARAIT.TTF
C:\WINDOWS\WINDOWS\Fonts\gautami.ttf
C:\WINDOWS\WINDOWS\Fonts\Genuine_.TTF
C:\WINDOWS\WINDOWS\Fonts\georgia.ttf
C:\WINDOWS\WINDOWS\Fonts\georgiab.ttf
C:\WINDOWS\WINDOWS\Fonts\georgiai.ttf
C:\WINDOWS\WINDOWS\Fonts\georgiaz.ttf
C:\WINDOWS\WINDOWS\Fonts\Gigi.ttf
C:\WINDOWS\WINDOWS\Fonts\Gil_____.TTF
C:\WINDOWS\WINDOWS\Fonts\Gilb____.TTF
C:\WINDOWS\WINDOWS\Fonts\Gilbi___.TTF
C:\WINDOWS\WINDOWS\Fonts\Gilc____.TTF
C:\WINDOWS\WINDOWS\Fonts\Gilcb___.TTF
C:\WINDOWS\WINDOWS\Fonts\Gili____.TTF
C:\WINDOWS\WINDOWS\Fonts\Gilsanub.TTF
C:\WINDOWS\WINDOWS\Fonts\Gothic.TTF
C:\WINDOWS\WINDOWS\Fonts\Gothicb.TTF
C:\WINDOWS\WINDOWS\Fonts\Gothicbi.TTF
C:\WINDOWS\WINDOWS\Fonts\Gothici.TTF
C:\WINDOWS\WINDOWS\Fonts\GOUDOS.TTF
C:\WINDOWS\WINDOWS\Fonts\GOUDOSB.TTF
C:\WINDOWS\WINDOWS\Fonts\GOUDOSI.TTF
C:\WINDOWS\WINDOWS\Fonts\Goudysto.ttf
C:\WINDOWS\WINDOWS\Fonts\GRGAREF.TTF
C:\WINDOWS\WINDOWS\Fonts\HARLOWSI.TTF
C:\WINDOWS\WINDOWS\Fonts\HARNGTON.TTF
C:\WINDOWS\WINDOWS\Fonts\Helte___.TTF
C:\WINDOWS\WINDOWS\Fonts\Herman__.TTF
C:\WINDOWS\WINDOWS\Fonts\impact.ttf
C:\WINDOWS\WINDOWS\Fonts\IMPRISHA.TTF
C:\WINDOWS\WINDOWS\Fonts\InfRoman.ttf
C:\WINDOWS\WINDOWS\Fonts\Isabelle.TTF
C:\WINDOWS\WINDOWS\Fonts\ITCBlkad.TTF
C:\WINDOWS\WINDOWS\Fonts\ITCEdscr.TTF
C:\WINDOWS\WINDOWS\Fonts\ITCKrist.TTF
C:\WINDOWS\WINDOWS\Fonts\Joan____.TTF
C:\WINDOWS\WINDOWS\Fonts\Jokerman.ttf
C:\WINDOWS\WINDOWS\Fonts\JUICE___.TTF
C:\WINDOWS\WINDOWS\Fonts\Justice_.TTF
C:\WINDOWS\WINDOWS\Fonts\KINO.TTF
C:\WINDOWS\WINDOWS\Fonts\Kunstler.ttf
C:\WINDOWS\WINDOWS\Fonts\l_10646.ttf
C:\WINDOWS\WINDOWS\Fonts\latha.ttf
C:\WINDOWS\WINDOWS\Fonts\LATINWD.TTF
C:\WINDOWS\WINDOWS\Fonts\LCALLIG.TTF
C:\WINDOWS\WINDOWS\Fonts\LHANDW.TTF
C:\WINDOWS\WINDOWS\Fonts\Lsans.TTF
C:\WINDOWS\WINDOWS\Fonts\Lsansd.TTF
C:\WINDOWS\WINDOWS\Fonts\Lsansdi.TTF
C:\WINDOWS\WINDOWS\Fonts\Lsansi.TTF
C:\WINDOWS\WINDOWS\Fonts\lsansuni.ttf
C:\WINDOWS\WINDOWS\Fonts\lucon.ttf
C:\WINDOWS\WINDOWS\Fonts\Maian.TTF
C:\WINDOWS\WINDOWS\Fonts\Maiandb.TTF
C:\WINDOWS\WINDOWS\Fonts\Maiandit.TTF
C:\WINDOWS\WINDOWS\Fonts\Mandela_.TTF
C:\WINDOWS\WINDOWS\Fonts\mangal.ttf
C:\WINDOWS\WINDOWS\Fonts\marlett.ttf
C:\WINDOWS\WINDOWS\Fonts\matisse_.ttf
C:\WINDOWS\WINDOWS\Fonts\Matte___.TTF
C:\WINDOWS\WINDOWS\Fonts\MATURASC.TTF
C:\WINDOWS\WINDOWS\Fonts\Microdot.TTF
C:\WINDOWS\WINDOWS\Fonts\micross.ttf
C:\WINDOWS\WINDOWS\Fonts\Mistral.TTF
C:\WINDOWS\WINDOWS\Fonts\MOD20.TTF
C:\WINDOWS\WINDOWS\Fonts\modern.fon
C:\WINDOWS\WINDOWS\Fonts\MSREF1.TTF
C:\WINDOWS\WINDOWS\Fonts\MSREF2.TTF
C:\WINDOWS\WINDOWS\Fonts\MTCORSVA.TTF
C:\WINDOWS\WINDOWS\Fonts\mvboli.ttf
C:\WINDOWS\WINDOWS\Fonts\Natur___.TTF
C:\WINDOWS\WINDOWS\Fonts\Neolith_.TTF
C:\WINDOWS\WINDOWS\Fonts\Nina.ttf
C:\WINDOWS\WINDOWS\Fonts\Ninab.ttf
C:\WINDOWS\WINDOWS\Fonts\Ninabi.ttf
C:\WINDOWS\WINDOWS\Fonts\Ninai.ttf
C:\WINDOWS\WINDOWS\Fonts\OCRB.TTF
C:\WINDOWS\WINDOWS\Fonts\OLDENGL.TTF
C:\WINDOWS\WINDOWS\Fonts\ONYX.TTF
C:\WINDOWS\WINDOWS\Fonts\Openc___.TTF
C:\WINDOWS\WINDOWS\Fonts\pala.ttf
C:\WINDOWS\WINDOWS\Fonts\palab.ttf
C:\WINDOWS\WINDOWS\Fonts\palabi.ttf
C:\WINDOWS\WINDOWS\Fonts\palai.ttf
C:\WINDOWS\WINDOWS\Fonts\PALSCRI.TTF
C:\WINDOWS\WINDOWS\Fonts\papyrus.ttf
C:\WINDOWS\WINDOWS\Fonts\PARADE.TTF
C:\WINDOWS\WINDOWS\Fonts\PARCHM.TTF
C:\WINDOWS\WINDOWS\Fonts\PEPITA.TTF
C:\WINDOWS\WINDOWS\Fonts\Per_____.TTF
C:\WINDOWS\WINDOWS\Fonts\Perb____.TTF
C:\WINDOWS\WINDOWS\Fonts\Perbi___.TTF
C:\WINDOWS\WINDOWS\Fonts\Peri____.TTF
C:\WINDOWS\WINDOWS\Fonts\PERTIBD.TTF
C:\WINDOWS\WINDOWS\Fonts\PERTILI.TTF
C:\WINDOWS\WINDOWS\Fonts\PHONETIC.FON
C:\WINDOWS\WINDOWS\Fonts\PLACCOND.TTF
C:\WINDOWS\WINDOWS\Fonts\PLAYBILL.TTF
C:\WINDOWS\WINDOWS\Fonts\POORICH.TTF
C:\WINDOWS\WINDOWS\Fonts\Pretext_.TTF
C:\WINDOWS\WINDOWS\Fonts\Pristina.ttf
C:\WINDOWS\WINDOWS\Fonts\Puppy___.TTF
C:\WINDOWS\WINDOWS\Fonts\raavi.ttf
C:\WINDOWS\WINDOWS\Fonts\Radagund.TTF
C:\WINDOWS\WINDOWS\Fonts\Rage.ttf
C:\WINDOWS\WINDOWS\Fonts\Realv___.TTF
C:\WINDOWS\WINDOWS\Fonts\REF_ICON.FON
C:\WINDOWS\WINDOWS\Fonts\REFSAN.TTF
C:\WINDOWS\WINDOWS\Fonts\REFSANB.TTF
C:\WINDOWS\WINDOWS\Fonts\REFSANBI.TTF
C:\WINDOWS\WINDOWS\Fonts\REFSANI.TTF
C:\WINDOWS\WINDOWS\Fonts\REFSER.TTF
C:\WINDOWS\WINDOWS\Fonts\REFSERB.TTF
C:\WINDOWS\WINDOWS\Fonts\REFSERBI.TTF
C:\WINDOWS\WINDOWS\Fonts\REFSERI.TTF
C:\WINDOWS\WINDOWS\Fonts\REFSPCL.TTF
C:\WINDOWS\WINDOWS\Fonts\REFSPEC.TTF
C:\WINDOWS\WINDOWS\Fonts\ROCK.TTF
C:\WINDOWS\WINDOWS\Fonts\ROCKB.TTF
C:\WINDOWS\WINDOWS\Fonts\ROCKBI.TTF
C:\WINDOWS\WINDOWS\Fonts\Rockeb.TTF
C:\WINDOWS\WINDOWS\Fonts\ROCKI.TTF
C:\WINDOWS\WINDOWS\Fonts\roman.fon
C:\WINDOWS\WINDOWS\Fonts\RUNICCN.TTF
C:\WINDOWS\WINDOWS\Fonts\script.fon
C:\WINDOWS\WINDOWS\Fonts\SCRIPTBL.TTF
C:\WINDOWS\WINDOWS\Fonts\sere1257.fon
C:\WINDOWS\WINDOWS\Fonts\serf1257.fon
C:\WINDOWS\WINDOWS\Fonts\serife.fon
C:\WINDOWS\WINDOWS\Fonts\serifee.fon
C:\WINDOWS\WINDOWS\Fonts\serifeg.fon
C:\WINDOWS\WINDOWS\Fonts\serifer.fon
C:\WINDOWS\WINDOWS\Fonts\serifet.fon
C:\WINDOWS\WINDOWS\Fonts\seriff.fon
C:\WINDOWS\WINDOWS\Fonts\seriffe.fon
C:\WINDOWS\WINDOWS\Fonts\seriffg.fon
C:\WINDOWS\WINDOWS\Fonts\seriffr.fon
C:\WINDOWS\WINDOWS\Fonts\serifft.fon
C:\WINDOWS\WINDOWS\Fonts\Shelman_.TTF
C:\WINDOWS\WINDOWS\Fonts\shruti.ttf
C:\WINDOWS\WINDOWS\Fonts\smae1257.fon
C:\WINDOWS\WINDOWS\Fonts\smaf1257.fon
C:\WINDOWS\WINDOWS\Fonts\smalle.fon
C:\WINDOWS\WINDOWS\Fonts\smallee.fon
C:\WINDOWS\WINDOWS\Fonts\smalleg.fon
C:\WINDOWS\WINDOWS\Fonts\smaller.fon
C:\WINDOWS\WINDOWS\Fonts\smallet.fon
C:\WINDOWS\WINDOWS\Fonts\smallf.fon
C:\WINDOWS\WINDOWS\Fonts\smallfe.fon
C:\WINDOWS\WINDOWS\Fonts\smallfg.fon
C:\WINDOWS\WINDOWS\Fonts\smallfr.fon
C:\WINDOWS\WINDOWS\Fonts\smallft.fon
C:\WINDOWS\WINDOWS\Fonts\SNAP____.TTF
C:\WINDOWS\WINDOWS\Fonts\ssee1257.fon
C:\WINDOWS\WINDOWS\Fonts\ssef1257.fon
C:\WINDOWS\WINDOWS\Fonts\sserife.fon
C:\WINDOWS\WINDOWS\Fonts\sserifee.fon
C:\WINDOWS\WINDOWS\Fonts\sserifeg.fon
C:\WINDOWS\WINDOWS\Fonts\sserifer.fon
C:\WINDOWS\WINDOWS\Fonts\sserifet.fon
C:\WINDOWS\WINDOWS\Fonts\sseriff.fon
C:\WINDOWS\WINDOWS\Fonts\sseriffe.fon
C:\WINDOWS\WINDOWS\Fonts\sseriffg.fon
C:\WINDOWS\WINDOWS\Fonts\sseriffr.fon
C:\WINDOWS\WINDOWS\Fonts\sserifft.fon
C:\WINDOWS\WINDOWS\Fonts\sylfaen.ttf
C:\WINDOWS\WINDOWS\Fonts\symbol.ttf
C:\WINDOWS\WINDOWS\Fonts\symbole.fon
C:\WINDOWS\WINDOWS\Fonts\tahoma.ttf
C:\WINDOWS\WINDOWS\Fonts\tahomabd.ttf
C:\WINDOWS\WINDOWS\Fonts\TempsITC.TTF
C:\WINDOWS\WINDOWS\Fonts\times.ttf
C:\WINDOWS\WINDOWS\Fonts\timesbd.ttf
C:\WINDOWS\WINDOWS\Fonts\timesbi.ttf
C:\WINDOWS\WINDOWS\Fonts\timesi.ttf
C:\WINDOWS\WINDOWS\Fonts\trebuc.ttf
C:\WINDOWS\WINDOWS\Fonts\trebucbd.ttf
C:\WINDOWS\WINDOWS\Fonts\trebucbi.ttf
C:\WINDOWS\WINDOWS\Fonts\trebucit.ttf
C:\WINDOWS\WINDOWS\Fonts\Trendy__.TTF
C:\WINDOWS\WINDOWS\Fonts\tunga.ttf
C:\WINDOWS\WINDOWS\Fonts\verdana.ttf
C:\WINDOWS\WINDOWS\Fonts\verdanab.ttf
C:\WINDOWS\WINDOWS\Fonts\verdanai.ttf
C:\WINDOWS\WINDOWS\Fonts\verdanaz.ttf
C:\WINDOWS\WINDOWS\Fonts\VERDREF.TTF
C:\WINDOWS\WINDOWS\Fonts\vga737.fon
C:\WINDOWS\WINDOWS\Fonts\vga775.fon
C:\WINDOWS\WINDOWS\Fonts\vga850.fon
C:\WINDOWS\WINDOWS\Fonts\vga852.fon
C:\WINDOWS\WINDOWS\Fonts\vga855.fon
C:\WINDOWS\WINDOWS\Fonts\vga857.fon
C:\WINDOWS\WINDOWS\Fonts\vga860.fon
C:\WINDOWS\WINDOWS\Fonts\vga863.fon
C:\WINDOWS\WINDOWS\Fonts\vga865.fon
C:\WINDOWS\WINDOWS\Fonts\vga866.fon
C:\WINDOWS\WINDOWS\Fonts\vga869.fon
C:\WINDOWS\WINDOWS\Fonts\vgaf1257.fon
C:\WINDOWS\WINDOWS\Fonts\vgafix.fon
C:\WINDOWS\WINDOWS\Fonts\vgafixe.fon
C:\WINDOWS\WINDOWS\Fonts\vgafixg.fon
C:\WINDOWS\WINDOWS\Fonts\vgafixr.fon
C:\WINDOWS\WINDOWS\Fonts\vgafixt.fon
C:\WINDOWS\WINDOWS\Fonts\vgaoem.fon
C:\WINDOWS\WINDOWS\Fonts\vgas1257.fon
C:\WINDOWS\WINDOWS\Fonts\vgasys.fon
C:\WINDOWS\WINDOWS\Fonts\vgasyse.fon
C:\WINDOWS\WINDOWS\Fonts\vgasysg.fon
C:\WINDOWS\WINDOWS\Fonts\vgasysr.fon
C:\WINDOWS\WINDOWS\Fonts\vgasyst.fon
C:\WINDOWS\WINDOWS\Fonts\VINERITC.TTF
C:\WINDOWS\WINDOWS\Fonts\Vivaldii.TTF
C:\WINDOWS\WINDOWS\Fonts\Vladimir.ttf
C:\WINDOWS\WINDOWS\Fonts\webdings.ttf
C:\WINDOWS\WINDOWS\Fonts\wingding.ttf
C:\WINDOWS\WINDOWS\Fonts\WINGDNG2.TTF
C:\WINDOWS\WINDOWS\Fonts\WINGDNG3.TTF
C:\WINDOWS\WINDOWS\Fonts\wst_czec.fon
C:\WINDOWS\WINDOWS\Fonts\wst_engl.fon
C:\WINDOWS\WINDOWS\Fonts\wst_fren.fon
C:\WINDOWS\WINDOWS\Fonts\wst_germ.fon
C:\WINDOWS\WINDOWS\Fonts\wst_ital.fon
C:\WINDOWS\WINDOWS\Fonts\wst_span.fon
C:\WINDOWS\WINDOWS\Fonts\wst_swed.fon
C:\WINDOWS\WINDOWS\Fächer.bmp
C:\WINDOWS\WINDOWS\Granit.bmp
C:\WINDOWS\WINDOWS\GRAPPLER.INI
C:\WINDOWS\WINDOWS\HBCIKRNL.INI
C:\WINDOWS\WINDOWS\Help\acc_dis.chm
C:\WINDOWS\WINDOWS\Help\accessib.chm
C:\WINDOWS\WINDOWS\Help\aclui.hlp
C:\WINDOWS\WINDOWS\Help\admtools.chm
C:\WINDOWS\WINDOWS\Help\apps.chm
C:\WINDOWS\WINDOWS\Help\apps_sp.chm
C:\WINDOWS\WINDOWS\Help\certmgr.chm
C:\WINDOWS\WINDOWS\Help\ciadmin.htm
C:\WINDOWS\WINDOWS\Help\ciquery.htm
C:\WINDOWS\WINDOWS\Help\cmconcepts.chm
C:\WINDOWS\WINDOWS\Help\conf.cnt
C:\WINDOWS\WINDOWS\Help\connect.cnt
C:\WINDOWS\WINDOWS\Help\cpanel.chm
C:\WINDOWS\WINDOWS\Help\cpanel.chq
C:\WINDOWS\WINDOWS\Help\diskmgmt.chm
C:\WINDOWS\WINDOWS\Help\display.chm
C:\WINDOWS\WINDOWS\Help\filefold.chm
C:\WINDOWS\WINDOWS\Help\find.chm
C:\WINDOWS\WINDOWS\Help\Glossary.chm
C:\WINDOWS\WINDOWS\Help\hardware.hlp
C:\WINDOWS\WINDOWS\Help\howto.chm
C:\WINDOWS\WINDOWS\Help\hschelp.chm
C:\WINDOWS\WINDOWS\Help\iesupp.chm
C:\WINDOWS\WINDOWS\Help\iewebhlp.chm
C:\WINDOWS\WINDOWS\Help\input.chm
C:\WINDOWS\WINDOWS\Help\input.hlp
C:\WINDOWS\WINDOWS\Help\ipsecconcepts.chm
C:\WINDOWS\WINDOWS\Help\ipsecsnp.chm
C:\WINDOWS\WINDOWS\Help\ixqlang.htm
C:\WINDOWS\WINDOWS\Help\JntView.chm
C:\WINDOWS\WINDOWS\Help\langbar.chm
C:\WINDOWS\WINDOWS\Help\license.chm
C:\WINDOWS\WINDOWS\Help\migwiz.htm
C:\WINDOWS\WINDOWS\Help\migwiz2.htm
C:\WINDOWS\WINDOWS\Help\misc.chm
C:\WINDOWS\WINDOWS\Help\mpconcepts.chm
C:\WINDOWS\WINDOWS\Help\mplayer2.cnt
C:\WINDOWS\WINDOWS\Help\mshearts.cnt
C:\WINDOWS\WINDOWS\Help\msnauth.cnt
C:\WINDOWS\WINDOWS\Help\NAV.chm
C:\WINDOWS\WINDOWS\Help\netcfg.chm
C:\WINDOWS\WINDOWS\Help\network.chm
C:\WINDOWS\WINDOWS\Help\nocontnt.cnt
C:\WINDOWS\WINDOWS\Help\ntart.chm
C:\WINDOWS\WINDOWS\Help\ntcmds.chm
C:\WINDOWS\WINDOWS\Help\ntdef.chm
C:\WINDOWS\WINDOWS\Help\nusrmgr.chm
C:\WINDOWS\WINDOWS\Help\nvcpar.hlp
C:\WINDOWS\WINDOWS\Help\nvcpcs.hlp
C:\WINDOWS\WINDOWS\Help\nvcpda.hlp
C:\WINDOWS\WINDOWS\Help\nvcpde.hlp
C:\WINDOWS\WINDOWS\Help\nvcpel.hlp
C:\WINDOWS\WINDOWS\Help\nvcpeng.hlp
C:\WINDOWS\WINDOWS\Help\nvcpes.hlp
C:\WINDOWS\WINDOWS\Help\nvcpesm.hlp
C:\WINDOWS\WINDOWS\Help\nvcpfi.hlp
C:\WINDOWS\WINDOWS\Help\nvcpfr.hlp
C:\WINDOWS\WINDOWS\Help\nvcphe.hlp
C:\WINDOWS\WINDOWS\Help\nvcphu.hlp
C:\WINDOWS\WINDOWS\Help\nvcpit.hlp
C:\WINDOWS\WINDOWS\Help\nvcpja.hlp
C:\WINDOWS\WINDOWS\Help\nvcpko.hlp
C:\WINDOWS\WINDOWS\Help\nvcpl.hlp
C:\WINDOWS\WINDOWS\Help\nvcpnl.hlp
C:\WINDOWS\WINDOWS\Help\nvcpno.hlp
C:\WINDOWS\WINDOWS\Help\nvcppl.hlp
C:\WINDOWS\WINDOWS\Help\nvcppt.hlp
C:\WINDOWS\WINDOWS\Help\nvcpptb.hlp
C:\WINDOWS\WINDOWS\Help\nvcpru.hlp
C:\WINDOWS\WINDOWS\Help\nvcpsk.hlp
C:\WINDOWS\WINDOWS\Help\nvcpsl.hlp
C:\WINDOWS\WINDOWS\Help\nvcpsv.hlp
C:\WINDOWS\WINDOWS\Help\nvcpth.hlp
C:\WINDOWS\WINDOWS\Help\nvcptr.hlp
C:\WINDOWS\WINDOWS\Help\nvcpzhc.hlp
C:\WINDOWS\WINDOWS\Help\nvcpzht.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpcs.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpda.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpde.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpel.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpeng.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpes.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpesm.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpfi.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpfr.hlp
C:\WINDOWS\WINDOWS\Help\nvwcphu.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpit.hlp
C:\WINDOWS\WINDOWS\Help\nvwcplen.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpnl.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpno.hlp
C:\WINDOWS\WINDOWS\Help\nvwcppl.hlp
C:\WINDOWS\WINDOWS\Help\nvwcppt.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpptb.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpru.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpsk.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpsl.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpsv.hlp
C:\WINDOWS\WINDOWS\Help\nvwcptr.hlp
C:\WINDOWS\WINDOWS\Help\nwdoc.chm
C:\WINDOWS\WINDOWS\Help\password.chm
C:\WINDOWS\WINDOWS\Help\plyr_err.chm
C:\WINDOWS\WINDOWS\Help\printing.chm
C:\WINDOWS\WINDOWS\Help\progman.cnt
C:\WINDOWS\WINDOWS\Help\pwrmn.chm
C:\WINDOWS\WINDOWS\Help\ratings.cnt
C:\WINDOWS\WINDOWS\Help\regopt.chm
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\bookmrk.CDX
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\bookmrk.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Groups.cdx
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Groups.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Grpsyll.cdx
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Grpsyll.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Prgrss2.cdx
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Prgrss2.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Progress.cdx
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Progress.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Settings.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Syllabi2.cdx
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Syllabi2.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Syllabus.cdx
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Syllabus.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Usergrp.cdx
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Usergrp.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Users.cdx
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Users.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\WXPPera.toc
C:\WINDOWS\WINDOWS\Help\SBSI\Training\engine.ini
C:\WINDOWS\WINDOWS\Help\SBSI\Training\lsingle.cnt
C:\WINDOWS\WINDOWS\Help\SBSI\Training\LSINGLE.HLP
C:\WINDOWS\WINDOWS\Help\SBSI\Training\orun32.exe
C:\WINDOWS\WINDOWS\Help\SBSI\Training\ounins32_s.exe
C:\WINDOWS\WINDOWS\Help\SBSI\Training\startmenu.cbo
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\CBO\hsc_add.vbs
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\CBO\hsc_del.vbs
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\CBO\wxpper.chm
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\CBO\wxppera.cab
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L10_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L10_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L10_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L10_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L10_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L10_Fa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L11_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L11_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L11_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L11_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L12_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L12_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L12_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L12_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L12_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L13_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L13_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L13_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L13_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L13_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L13_Fa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L14_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L14_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L14_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L14_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L14_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L15_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L15_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L15_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L15_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L15_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L15_Fa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L16_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L16_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L16_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L16_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L16_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L17_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L17_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L17_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L17_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L17_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L1_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L2_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L2_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L2_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L2_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L2_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L2_Fa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L2_Ga.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L2_Ha.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L2_Ia.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L3_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L3_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L3_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L3_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L3_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L4_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L4_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L4_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L4_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L4_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L4_Fa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L4_Ga.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L4_Ha.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L5_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L5_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L5_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L5_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L5_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L5_Fa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L5_Ga.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L5_Ha.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L6_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L6_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L6_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L6_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L6_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L7_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L7_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L7_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L7_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L7_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L7_Fa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L8_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L8_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L8_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L8_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L8_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L9_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L9_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L9_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L9_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L9_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L9_Fa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\fin_shot.SWF
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L10_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L10_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L10_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L10_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L10_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L10_F.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L11_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L11_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L11_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L11_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L12_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L12_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L12_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L12_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L12_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L13_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L13_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L13_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L13_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L13_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L13_F.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L14_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L14_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L14_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L14_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L14_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L15_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L15_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L15_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L15_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L15_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L15_F.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L16_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L16_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L16_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L16_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L16_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L17_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L17_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L17_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L17_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L17_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L1_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L2_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L2_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L2_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L2_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L2_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L2_F.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L2_G.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L2_H.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L2_I.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L3_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L3_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L3_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L3_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L3_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L4_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L4_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L4_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L4_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L4_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L4_F.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L4_G.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L4_H.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L5_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L5_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L5_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L5_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L5_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L5_F.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L5_G.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L5_H.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L6_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L6_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L6_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L6_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L6_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L7_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L7_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L7_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L7_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L7_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L7_F.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L8_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L8_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L8_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L8_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L8_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L9_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L9_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L9_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L9_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L9_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L9_F.LDZ
C:\WI
nachstehend den Report von CounterSpy:
[code]
Scan History Details
Start Date: 11.07.2007 20:47:35
End Date: 11.07.2007 22:11:56
Total Time: 84 Min 21 Sec
Detected security risks
BearShare P2P Program more information...
Details: BearShare is a peer-to-peer (P2P) application that allows its users to join together in a network via the Internet and share files from each other's hard drives.
Status: Deleted
Registry entries detected
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\AuxUserType
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\AuxUserType
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\AuxUserType\2
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\AuxUserType\2
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\AuxUserType\3
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\AuxUserType\3
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion\Readable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion\Readable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion\Readable\Main
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion\Readable\Main
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion\Readwritable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion\Readwritable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion\Readwritable\Main
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion\Readwritable\Main
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\DefaultFile
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\DefaultFile
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\0
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\0
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\1
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\1
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\2
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\2
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\3
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\3
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\4
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\4
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DefaultExtension
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DefaultExtension
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DefaultIcon
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DefaultIcon
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DocObject
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DocObject
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Implemented Categories
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Implemented Categories
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Implemented Categories\{000C0118-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Implemented Categories\{000C0118-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\InprocHandler32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\InprocHandler32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Insertable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Insertable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\MiscStatus
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\MiscStatus
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\OfficeCompliant
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\OfficeCompliant
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\PersistentHandler
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\PersistentHandler
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Printable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Printable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\ProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\ProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Typelib
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Typelib
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Verb
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Verb
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Verb\0
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Verb\0
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Verb\1
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Verb\1
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Version
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Version
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\ACTIVE SETUP\INSTALLED COMPONENTS\{5F95E1AF-2620-4F15-BDF9-7FDCE4607E17}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\ACTIVE SETUP\INSTALLED COMPONENTS\{5F95E1AF-2620-4F15-BDF9-7FDCE4607E17}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\ACTIVE SETUP\INSTALLED COMPONENTS\{5F95E1AF-2620-4F15-BDF9-7FDCE4607E17}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\ACTIVE SETUP\INSTALLED COMPONENTS\{5F95E1AF-2620-4F15-BDF9-7FDCE4607E17}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\ACTIVE SETUP\INSTALLED COMPONENTS\{5F95E1AF-2620-4F15-BDF9-7FDCE4607E17}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\ACTIVE SETUP\INSTALLED COMPONENTS\{5F95E1AF-2620-4F15-BDF9-7FDCE4607E17}
HKEY_USERS\S-1-5-21-2760978244-3742667488-1603439836-1005\APPEVENTS\EVENTLABELS\BEARSHARECHATNOTIFYMSG
HKEY_USERS\S-1-5-21-2760978244-3742667488-1603439836-1005\APPEVENTS\EVENTLABELS\BEARSHARECHATNOTIFYMSG
HKEY_USERS\S-1-5-21-2760978244-3742667488-1603439836-1005\APPEVENTS\SCHEMES\APPS\BEARSHARE
HKEY_USERS\S-1-5-21-2760978244-3742667488-1603439836-1005\APPEVENTS\SCHEMES\APPS\BEARSHARE
HKEY_USERS\S-1-5-21-2760978244-3742667488-1603439836-1005\APPEVENTS\SCHEMES\APPS\BEARSHARE\BearShareChatNotifyMsg
HKEY_USERS\S-1-5-21-2760978244-3742667488-1603439836-1005\APPEVENTS\SCHEMES\APPS\BEARSHARE\BearShareChatNotifyMsg
HKEY_USERS\S-1-5-21-2760978244-3742667488-1603439836-1005\APPEVENTS\SCHEMES\APPS\BEARSHARE\BearShareChatNotifyMsg\.Current
Invisible Keylogger Commercial Key Logger more information...
Status: Deleted
Files detected
C:\WINDOWS\WINDOWS\Thumbs.db:encryptable
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\expsrv.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msexch40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msexcl40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msjet40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msjetol1.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msjetoledb40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msjtes40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msltus40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\mspbde40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msrd2x40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msrepl40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\mstext40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msxbde40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\spuninst\spuninst.bat
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\6to4svc.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\iphlpapi.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\ipv6.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\ipv6mon.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\netip6.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\netoc.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\netoc.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\wship6.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB820291$\appwiz.cpl
C:\WINDOWS\WINDOWS\$NtUninstallKB820291$\explorer.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB820291$\shmgrate.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB820291$\spuninst\spuninst.bat
C:\WINDOWS\WINDOWS\$NtUninstallKB820291$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB820291$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB821253$\dwwin.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB821253$\faultrep.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB821253$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB821253$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB821557$\shell32.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB821557$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB821557$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB822603$\hccoin.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB822603$\spuninst\spuninst.bat
C:\WINDOWS\WINDOWS\$NtUninstallKB822603$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB822603$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB823559$\html32.cnv
C:\WINDOWS\WINDOWS\$NtUninstallKB823559$\spuninst\spuninst.bat
C:\WINDOWS\WINDOWS\$NtUninstallKB823559$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB823559$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB823980$\ole32.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB823980$\rpcrt4.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB823980$\rpcss.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB823980$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB823980$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB824105$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB824105$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB824146$\ole32.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB824146$\rpcrt4.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB824146$\rpcss.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB824146$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB824146$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ322011$\fxsclnt.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ322011$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ322011$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ327979$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ327979$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ328310$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ328310$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ328310$\sysmain.sdb
C:\WINDOWS\WINDOWS\$NtUninstallQ328310$\user32.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ328310$\win32k.sys
C:\WINDOWS\WINDOWS\$NtUninstallQ328310$\winsrv.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ329048$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ329048$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ329048$\zipfldr.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ329115$\crypt32.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ329115$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ329115$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ329170$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ329170$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ329390$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ329390$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ329441$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ329441$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ329441$\srrstr.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ329834$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ329834$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\hhctrl.ocx
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\hhsetup.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\itircl.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\itss.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\migwiz.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\osk.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\pchshell.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\spuninst\spuninst.bat
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ810577$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ810577$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ810833$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ810833$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ811493$\ntkrnlpa.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ811493$\ntoskrnl.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ811493$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ811493$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ814033$\newdev.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ814033$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ814033$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ814995$\acgenral.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ814995$\apph_sp.sdb
C:\WINDOWS\WINDOWS\$NtUninstallQ814995$\apphelp.sdb
C:\WINDOWS\WINDOWS\$NtUninstallQ814995$\apps.chm
C:\WINDOWS\WINDOWS\$NtUninstallQ814995$\apps_sp.chm
C:\WINDOWS\WINDOWS\$NtUninstallQ814995$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ814995$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ814995$\sysmain.sdb
C:\WINDOWS\WINDOWS\$NtUninstallQ815021$\ntdll.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ815021$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ815021$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ815485$\netshell.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ815485$\reg00003
C:\WINDOWS\WINDOWS\$NtUninstallQ815485$\spuninst\spuninst.bat
C:\WINDOWS\WINDOWS\$NtUninstallQ815485$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ815485$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ815485$\wzcdlg.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ815485$\wzcsapi.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ815485$\wzcsvc.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ817606$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ817606$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\Angler.bmp
C:\WINDOWS\WINDOWS\AppPatch\acgenral.dll
C:\WINDOWS\WINDOWS\AppPatch\AcLayers.dll
C:\WINDOWS\WINDOWS\AppPatch\AcLua.dll
C:\WINDOWS\WINDOWS\AppPatch\AcSpecfc.dll
C:\WINDOWS\WINDOWS\AppPatch\AcVerfyr.dll
C:\WINDOWS\WINDOWS\AppPatch\AcXtrnal.dll
C:\WINDOWS\WINDOWS\AppPatch\apph_sp.sdb
C:\WINDOWS\WINDOWS\AppPatch\apphelp.sdb
C:\WINDOWS\WINDOWS\AppPatch\drvmain.sdb
C:\WINDOWS\WINDOWS\AppPatch\msimain.sdb
C:\WINDOWS\WINDOWS\AppPatch\sysmain.sdb
C:\WINDOWS\WINDOWS\Blaue Spitzen 16.bmp
C:\WINDOWS\WINDOWS\bootstat.dat
C:\WINDOWS\WINDOWS\clock.avi
C:\WINDOWS\WINDOWS\control.ini
C:\WINDOWS\WINDOWS\Cursors\3dgarro.cur
C:\WINDOWS\WINDOWS\Cursors\3dgmove.cur
C:\WINDOWS\WINDOWS\Cursors\3dgnesw.cur
C:\WINDOWS\WINDOWS\Cursors\3dgno.cur
C:\WINDOWS\WINDOWS\Cursors\3dgns.cur
C:\WINDOWS\WINDOWS\Cursors\3dgnwse.cur
C:\WINDOWS\WINDOWS\Cursors\3dgwe.cur
C:\WINDOWS\WINDOWS\Cursors\3dsmove.cur
C:\WINDOWS\WINDOWS\Cursors\3dsns.cur
C:\WINDOWS\WINDOWS\Cursors\3dsnwse.cur
C:\WINDOWS\WINDOWS\Cursors\3dwarro.cur
C:\WINDOWS\WINDOWS\Cursors\3dwmove.cur
C:\WINDOWS\WINDOWS\Cursors\3dwnesw.cur
C:\WINDOWS\WINDOWS\Cursors\3dwno.cur
C:\WINDOWS\WINDOWS\Cursors\3dwns.cur
C:\WINDOWS\WINDOWS\Cursors\3dwnwse.cur
C:\WINDOWS\WINDOWS\Cursors\3dwwe.cur
C:\WINDOWS\WINDOWS\Cursors\appstar2.ani
C:\WINDOWS\WINDOWS\Cursors\appstar3.ani
C:\WINDOWS\WINDOWS\Cursors\appstart.ani
C:\WINDOWS\WINDOWS\Cursors\arrow_i.cur
C:\WINDOWS\WINDOWS\Cursors\arrow_il.cur
C:\WINDOWS\WINDOWS\Cursors\arrow_im.cur
C:\WINDOWS\WINDOWS\Cursors\arrow_l.cur
C:\WINDOWS\WINDOWS\Cursors\arrow_m.cur
C:\WINDOWS\WINDOWS\Cursors\arrow_r.cur
C:\WINDOWS\WINDOWS\Cursors\arrow_rl.cur
C:\WINDOWS\WINDOWS\Cursors\arrow_rm.cur
C:\WINDOWS\WINDOWS\Cursors\banana.ani
C:\WINDOWS\WINDOWS\Cursors\barber.ani
C:\WINDOWS\WINDOWS\Cursors\beam_i.cur
C:\WINDOWS\WINDOWS\Cursors\beam_il.cur
C:\WINDOWS\WINDOWS\Cursors\beam_im.cur
C:\WINDOWS\WINDOWS\Cursors\beam_l.cur
C:\WINDOWS\WINDOWS\Cursors\beam_m.cur
C:\WINDOWS\WINDOWS\Cursors\beam_r.cur
C:\WINDOWS\WINDOWS\Cursors\beam_rl.cur
C:\WINDOWS\WINDOWS\Cursors\beam_rm.cur
C:\WINDOWS\WINDOWS\Cursors\busy_i.cur
C:\WINDOWS\WINDOWS\Cursors\busy_il.cur
C:\WINDOWS\WINDOWS\Cursors\busy_im.cur
C:\WINDOWS\WINDOWS\Cursors\busy_l.cur
C:\WINDOWS\WINDOWS\Cursors\busy_m.cur
C:\WINDOWS\WINDOWS\Cursors\busy_r.cur
C:\WINDOWS\WINDOWS\Cursors\busy_rl.cur
C:\WINDOWS\WINDOWS\Cursors\busy_rm.cur
C:\WINDOWS\WINDOWS\Cursors\coin.ani
C:\WINDOWS\WINDOWS\Cursors\counter.ani
C:\WINDOWS\WINDOWS\Cursors\cross.cur
C:\WINDOWS\WINDOWS\Cursors\cross_i.cur
C:\WINDOWS\WINDOWS\Cursors\cross_il.cur
C:\WINDOWS\WINDOWS\Cursors\cross_im.cur
C:\WINDOWS\WINDOWS\Cursors\cross_l.cur
C:\WINDOWS\WINDOWS\Cursors\cross_m.cur
C:\WINDOWS\WINDOWS\Cursors\cross_r.cur
C:\WINDOWS\WINDOWS\Cursors\cross_rl.cur
C:\WINDOWS\WINDOWS\Cursors\cross_rm.cur
C:\WINDOWS\WINDOWS\Cursors\dinosau2.ani
C:\WINDOWS\WINDOWS\Cursors\dinosaur.ani
C:\WINDOWS\WINDOWS\Cursors\drum.ani
C:\WINDOWS\WINDOWS\Cursors\fillitup.ani
C:\WINDOWS\WINDOWS\Cursors\hand.ani
C:\WINDOWS\WINDOWS\Cursors\handapst.ani
C:\WINDOWS\WINDOWS\Cursors\handnesw.ani
C:\WINDOWS\WINDOWS\Cursors\handno.ani
C:\WINDOWS\WINDOWS\Cursors\handns.ani
C:\WINDOWS\WINDOWS\Cursors\handnwse.ani
C:\WINDOWS\WINDOWS\Cursors\handwait.ani
C:\WINDOWS\WINDOWS\Cursors\handwe.ani
C:\WINDOWS\WINDOWS\Cursors\harrow.cur
C:\WINDOWS\WINDOWS\Cursors\hcross.cur
C:\WINDOWS\WINDOWS\Cursors\help_i.cur
C:\WINDOWS\WINDOWS\Cursors\help_il.cur
C:\WINDOWS\WINDOWS\Cursors\help_im.cur
C:\WINDOWS\WINDOWS\Cursors\help_l.cur
C:\WINDOWS\WINDOWS\Cursors\help_m.cur
C:\WINDOWS\WINDOWS\Cursors\help_r.cur
C:\WINDOWS\WINDOWS\Cursors\help_rl.cur
C:\WINDOWS\WINDOWS\Cursors\help_rm.cur
C:\WINDOWS\WINDOWS\Cursors\hibeam.cur
C:\WINDOWS\WINDOWS\Cursors\hmove.cur
C:\WINDOWS\WINDOWS\Cursors\hnesw.cur
C:\WINDOWS\WINDOWS\Cursors\hnodrop.cur
C:\WINDOWS\WINDOWS\Cursors\hns.cur
C:\WINDOWS\WINDOWS\Cursors\hnwse.cur
C:\WINDOWS\WINDOWS\Cursors\horse.ani
C:\WINDOWS\WINDOWS\Cursors\hourgla2.ani
C:\WINDOWS\WINDOWS\Cursors\hourgla3.ani
C:\WINDOWS\WINDOWS\Cursors\hourglas.ani
C:\WINDOWS\WINDOWS\Cursors\hwe.cur
C:\WINDOWS\WINDOWS\Cursors\lappstrt.cur
C:\WINDOWS\WINDOWS\Cursors\larrow.cur
C:\WINDOWS\WINDOWS\Cursors\lcross.cur
C:\WINDOWS\WINDOWS\Cursors\libeam.cur
C:\WINDOWS\WINDOWS\Cursors\lmove.cur
C:\WINDOWS\WINDOWS\Cursors\lnesw.cur
C:\WINDOWS\WINDOWS\Cursors\lnodrop.cur
C:\WINDOWS\WINDOWS\Cursors\lns.cur
C:\WINDOWS\WINDOWS\Cursors\lnwse.cur
C:\WINDOWS\WINDOWS\Cursors\lwait.cur
C:\WINDOWS\WINDOWS\Cursors\lwe.cur
C:\WINDOWS\WINDOWS\Cursors\metronom.ani
C:\WINDOWS\WINDOWS\Cursors\move_i.cur
C:\WINDOWS\WINDOWS\Cursors\move_il.cur
C:\WINDOWS\WINDOWS\Cursors\move_im.cur
C:\WINDOWS\WINDOWS\Cursors\move_l.cur
C:\WINDOWS\WINDOWS\Cursors\move_m.cur
C:\WINDOWS\WINDOWS\Cursors\move_r.cur
C:\WINDOWS\WINDOWS\Cursors\move_rl.cur
C:\WINDOWS\WINDOWS\Cursors\move_rm.cur
C:\WINDOWS\WINDOWS\Cursors\no_i.cur
C:\WINDOWS\WINDOWS\Cursors\no_il.cur
C:\WINDOWS\WINDOWS\Cursors\no_im.cur
C:\WINDOWS\WINDOWS\Cursors\no_l.cur
C:\WINDOWS\WINDOWS\Cursors\no_m.cur
C:\WINDOWS\WINDOWS\Cursors\no_r.cur
C:\WINDOWS\WINDOWS\Cursors\no_rl.cur
C:\WINDOWS\WINDOWS\Cursors\no_rm.cur
C:\WINDOWS\WINDOWS\Cursors\pen_i.cur
C:\WINDOWS\WINDOWS\Cursors\pen_il.cur
C:\WINDOWS\WINDOWS\Cursors\pen_im.cur
C:\WINDOWS\WINDOWS\Cursors\pen_l.cur
C:\WINDOWS\WINDOWS\Cursors\pen_m.cur
C:\WINDOWS\WINDOWS\Cursors\pen_r.cur
C:\WINDOWS\WINDOWS\Cursors\pen_rl.cur
C:\WINDOWS\WINDOWS\Cursors\pen_rm.cur
C:\WINDOWS\WINDOWS\Cursors\piano.ani
C:\WINDOWS\WINDOWS\Cursors\rainbow.ani
C:\WINDOWS\WINDOWS\Cursors\raindrop.ani
C:\WINDOWS\WINDOWS\Cursors\size1_i.cur
C:\WINDOWS\WINDOWS\Cursors\size1_il.cur
C:\WINDOWS\WINDOWS\Cursors\size1_im.cur
C:\WINDOWS\WINDOWS\Cursors\size1_l.cur
C:\WINDOWS\WINDOWS\Cursors\size1_m.cur
C:\WINDOWS\WINDOWS\Cursors\size1_r.cur
C:\WINDOWS\WINDOWS\Cursors\size1_rl.cur
C:\WINDOWS\WINDOWS\Cursors\size1_rm.cur
C:\WINDOWS\WINDOWS\Cursors\size2_i.cur
C:\WINDOWS\WINDOWS\Cursors\size2_il.cur
C:\WINDOWS\WINDOWS\Cursors\size2_im.cur
C:\WINDOWS\WINDOWS\Cursors\size2_l.cur
C:\WINDOWS\WINDOWS\Cursors\size2_m.cur
C:\WINDOWS\WINDOWS\Cursors\size2_r.cur
C:\WINDOWS\WINDOWS\Cursors\size2_rl.cur
C:\WINDOWS\WINDOWS\Cursors\size2_rm.cur
C:\WINDOWS\WINDOWS\Cursors\size3_i.cur
C:\WINDOWS\WINDOWS\Cursors\size3_il.cur
C:\WINDOWS\WINDOWS\Cursors\size3_im.cur
C:\WINDOWS\WINDOWS\Cursors\size3_l.cur
C:\WINDOWS\WINDOWS\Cursors\size3_m.cur
C:\WINDOWS\WINDOWS\Cursors\size3_r.cur
C:\WINDOWS\WINDOWS\Cursors\size3_rl.cur
C:\WINDOWS\WINDOWS\Cursors\size3_rm.cur
C:\WINDOWS\WINDOWS\Cursors\size4_i.cur
C:\WINDOWS\WINDOWS\Cursors\size4_il.cur
C:\WINDOWS\WINDOWS\Cursors\size4_im.cur
C:\WINDOWS\WINDOWS\Cursors\size4_l.cur
C:\WINDOWS\WINDOWS\Cursors\size4_m.cur
C:\WINDOWS\WINDOWS\Cursors\size4_r.cur
C:\WINDOWS\WINDOWS\Cursors\size4_rl.cur
C:\WINDOWS\WINDOWS\Cursors\size4_rm.cur
C:\WINDOWS\WINDOWS\Cursors\sizenesw.ani
C:\WINDOWS\WINDOWS\Cursors\sizens.ani
C:\WINDOWS\WINDOWS\Cursors\sizenwse.ani
C:\WINDOWS\WINDOWS\Cursors\sizewe.ani
C:\WINDOWS\WINDOWS\Cursors\stopwtch.ani
C:\WINDOWS\WINDOWS\Cursors\up_i.cur
C:\WINDOWS\WINDOWS\Cursors\up_il.cur
C:\WINDOWS\WINDOWS\Cursors\up_im.cur
C:\WINDOWS\WINDOWS\Cursors\up_l.cur
C:\WINDOWS\WINDOWS\Cursors\up_m.cur
C:\WINDOWS\WINDOWS\Cursors\up_r.cur
C:\WINDOWS\WINDOWS\Cursors\up_rl.cur
C:\WINDOWS\WINDOWS\Cursors\up_rm.cur
C:\WINDOWS\WINDOWS\Cursors\vanisher.ani
C:\WINDOWS\WINDOWS\Cursors\wagtail.ani
C:\WINDOWS\WINDOWS\Cursors\wait_i.cur
C:\WINDOWS\WINDOWS\Cursors\wait_il.cur
C:\WINDOWS\WINDOWS\Cursors\wait_im.cur
C:\WINDOWS\WINDOWS\Cursors\wait_l.cur
C:\WINDOWS\WINDOWS\Cursors\wait_m.cur
C:\WINDOWS\WINDOWS\Cursors\wait_r.cur
C:\WINDOWS\WINDOWS\Cursors\wait_rl.cur
C:\WINDOWS\WINDOWS\Cursors\wait_rm.cur
C:\WINDOWS\WINDOWS\Debug\oakley.log
C:\WINDOWS\WINDOWS\Debug\PASSWD.LOG
C:\WINDOWS\WINDOWS\Downloaded Program Files\desktop.ini
C:\WINDOWS\WINDOWS\Driver Cache\i386\bdaplgin.ax
C:\WINDOWS\WINDOWS\Driver Cache\i386\driver.cab
C:\WINDOWS\WINDOWS\Driver Cache\i386\explorer.exe
C:\WINDOWS\WINDOWS\Driver Cache\i386\ipsink.ax
C:\WINDOWS\WINDOWS\Driver Cache\i386\ksolay.ax
C:\WINDOWS\WINDOWS\Driver Cache\i386\ksproxy.ax
C:\WINDOWS\WINDOWS\Driver Cache\i386\kstvtune.ax
C:\WINDOWS\WINDOWS\Driver Cache\i386\kswdmcap.ax
C:\WINDOWS\WINDOWS\Driver Cache\i386\ksxbar.ax
C:\WINDOWS\WINDOWS\Driver Cache\i386\msdvbnp.ax
C:\WINDOWS\WINDOWS\Driver Cache\i386\ndis.sys
C:\WINDOWS\WINDOWS\Driver Cache\i386\ndisuio.sys
C:\WINDOWS\WINDOWS\Driver Cache\i386\ntkrnlmp.exe
C:\WINDOWS\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
C:\WINDOWS\WINDOWS\Driver Cache\i386\ntkrpamp.exe
C:\WINDOWS\WINDOWS\Driver Cache\i386\ntoskrnl.exe
C:\WINDOWS\WINDOWS\Driver Cache\i386\psisrndr.ax
C:\WINDOWS\WINDOWS\Driver Cache\i386\sp1.cab
C:\WINDOWS\WINDOWS\explorer.exe
C:\WINDOWS\WINDOWS\explorer.scf
C:\WINDOWS\WINDOWS\Feder.bmp
C:\WINDOWS\WINDOWS\Fonts\8514fix.fon
C:\WINDOWS\WINDOWS\Fonts\8514fixe.fon
C:\WINDOWS\WINDOWS\Fonts\8514fixg.fon
C:\WINDOWS\WINDOWS\Fonts\8514fixr.fon
C:\WINDOWS\WINDOWS\Fonts\8514fixt.fon
C:\WINDOWS\WINDOWS\Fonts\8514oem.fon
C:\WINDOWS\WINDOWS\Fonts\8514oeme.fon
C:\WINDOWS\WINDOWS\Fonts\8514oemg.fon
C:\WINDOWS\WINDOWS\Fonts\8514oemr.fon
C:\WINDOWS\WINDOWS\Fonts\8514oemt.fon
C:\WINDOWS\WINDOWS\Fonts\8514sys.fon
C:\WINDOWS\WINDOWS\Fonts\8514syse.fon
C:\WINDOWS\WINDOWS\Fonts\8514sysg.fon
C:\WINDOWS\WINDOWS\Fonts\8514sysr.fon
C:\WINDOWS\WINDOWS\Fonts\8514syst.fon
C:\WINDOWS\WINDOWS\Fonts\85775.fon
C:\WINDOWS\WINDOWS\Fonts\85855.fon
C:\WINDOWS\WINDOWS\Fonts\85f1257.fon
C:\WINDOWS\WINDOWS\Fonts\85s1257.fon
C:\WINDOWS\WINDOWS\Fonts\ABAC.TTF
C:\WINDOWS\WINDOWS\Fonts\ABAEXBC.TTF
C:\WINDOWS\WINDOWS\Fonts\ABALC.TTF
C:\WINDOWS\WINDOWS\Fonts\Absalom_.TTF
C:\WINDOWS\WINDOWS\Fonts\AgencyB.TTF
C:\WINDOWS\WINDOWS\Fonts\AgencyR.TTF
C:\WINDOWS\WINDOWS\Fonts\ALGER.TTF
C:\WINDOWS\WINDOWS\Fonts\Alibi___.TTF
C:\WINDOWS\WINDOWS\Fonts\Andyb.TTF
C:\WINDOWS\WINDOWS\Fonts\ANTQUAB.TTF
C:\WINDOWS\WINDOWS\Fonts\ANTQUABI.TTF
C:\WINDOWS\WINDOWS\Fonts\ANTQUAI.TTF
C:\WINDOWS\WINDOWS\Fonts\app775.fon
C:\WINDOWS\WINDOWS\Fonts\app850.fon
C:\WINDOWS\WINDOWS\Fonts\app852.fon
C:\WINDOWS\WINDOWS\Fonts\app855.fon
C:\WINDOWS\WINDOWS\Fonts\app857.fon
C:\WINDOWS\WINDOWS\Fonts\app866.fon
C:\WINDOWS\WINDOWS\Fonts\ARBLI___.TTF
C:\WINDOWS\WINDOWS\Fonts\arial.ttf
C:\WINDOWS\WINDOWS\Fonts\arialbd.ttf
C:\WINDOWS\WINDOWS\Fonts\arialbi.ttf
C:\WINDOWS\WINDOWS\Fonts\ariali.ttf
C:\WINDOWS\WINDOWS\Fonts\arialn.ttf
C:\WINDOWS\WINDOWS\Fonts\ArialNb.TTF
C:\WINDOWS\WINDOWS\Fonts\ArialNbi.TTF
C:\WINDOWS\WINDOWS\Fonts\ArialNi.TTF
C:\WINDOWS\WINDOWS\Fonts\ariblk.ttf
C:\WINDOWS\WINDOWS\Fonts\ARLRDBD.TTF
C:\WINDOWS\WINDOWS\Fonts\BASKVILL.TTF
C:\WINDOWS\WINDOWS\Fonts\Batavia_.TTF
C:\WINDOWS\WINDOWS\Fonts\BAUHS93.TTF
C:\WINDOWS\WINDOWS\Fonts\Beesknee.ttf
C:\WINDOWS\WINDOWS\Fonts\BERNHC.TTF
C:\WINDOWS\WINDOWS\Fonts\BicklySc.ttf
C:\WINDOWS\WINDOWS\Fonts\BKANT.TTF
C:\WINDOWS\WINDOWS\Fonts\BOOKOS.TTF
C:\WINDOWS\WINDOWS\Fonts\BOOKOSB.TTF
C:\WINDOWS\WINDOWS\Fonts\BOOKOSBI.TTF
C:\WINDOWS\WINDOWS\Fonts\BOOKOSI.TTF
C:\WINDOWS\WINDOWS\Fonts\BradhITC.TTF
C:\WINDOWS\WINDOWS\Fonts\BRAGGA.TTF
C:\WINDOWS\WINDOWS\Fonts\BRITANIC.TTF
C:\WINDOWS\WINDOWS\Fonts\BROADW.TTF
C:\WINDOWS\WINDOWS\Fonts\BRUSHSCI.TTF
C:\WINDOWS\WINDOWS\Fonts\CALIST.TTF
C:\WINDOWS\WINDOWS\Fonts\CALISTB.TTF
C:\WINDOWS\WINDOWS\Fonts\CALISTBI.TTF
C:\WINDOWS\WINDOWS\Fonts\CALISTI.TTF
C:\WINDOWS\WINDOWS\Fonts\casmira_.TTF
C:\WINDOWS\WINDOWS\Fonts\CASTELAR.TTF
C:\WINDOWS\WINDOWS\Fonts\cga40737.fon
C:\WINDOWS\WINDOWS\Fonts\cga40850.fon
C:\WINDOWS\WINDOWS\Fonts\cga40852.fon
C:\WINDOWS\WINDOWS\Fonts\cga40857.fon
C:\WINDOWS\WINDOWS\Fonts\cga40866.fon
C:\WINDOWS\WINDOWS\Fonts\cga40869.fon
C:\WINDOWS\WINDOWS\Fonts\cga40woa.fon
C:\WINDOWS\WINDOWS\Fonts\cga80737.fon
C:\WINDOWS\WINDOWS\Fonts\cga80850.fon
C:\WINDOWS\WINDOWS\Fonts\cga80852.fon
C:\WINDOWS\WINDOWS\Fonts\cga80857.fon
C:\WINDOWS\WINDOWS\Fonts\cga80866.fon
C:\WINDOWS\WINDOWS\Fonts\cga80869.fon
C:\WINDOWS\WINDOWS\Fonts\cga80woa.fon
C:\WINDOWS\WINDOWS\Fonts\Chiller.ttf
C:\WINDOWS\WINDOWS\Fonts\comic.ttf
C:\WINDOWS\WINDOWS\Fonts\comicbd.ttf
C:\WINDOWS\WINDOWS\Fonts\COOPBL.TTF
C:\WINDOWS\WINDOWS\Fonts\Coprgtb.TTF
C:\WINDOWS\WINDOWS\Fonts\Coprgtl.TTF
C:\WINDOWS\WINDOWS\Fonts\coue1257.fon
C:\WINDOWS\WINDOWS\Fonts\couf1257.fon
C:\WINDOWS\WINDOWS\Fonts\cour.ttf
C:\WINDOWS\WINDOWS\Fonts\courbd.ttf
C:\WINDOWS\WINDOWS\Fonts\courbi.ttf
C:\WINDOWS\WINDOWS\Fonts\coure.fon
C:\WINDOWS\WINDOWS\Fonts\couree.fon
C:\WINDOWS\WINDOWS\Fonts\coureg.fon
C:\WINDOWS\WINDOWS\Fonts\courer.fon
C:\WINDOWS\WINDOWS\Fonts\couret.fon
C:\WINDOWS\WINDOWS\Fonts\courf.fon
C:\WINDOWS\WINDOWS\Fonts\courfe.fon
C:\WINDOWS\WINDOWS\Fonts\courfg.fon
C:\WINDOWS\WINDOWS\Fonts\courfr.fon
C:\WINDOWS\WINDOWS\Fonts\courft.fon
C:\WINDOWS\WINDOWS\Fonts\couri.ttf
C:\WINDOWS\WINDOWS\Fonts\Curlz___.TTF
C:\WINDOWS\WINDOWS\Fonts\desktop.ini
C:\WINDOWS\WINDOWS\Fonts\dos737.fon
C:\WINDOWS\WINDOWS\Fonts\dosapp.fon
C:\WINDOWS\WINDOWS\Fonts\EDDA.TTF
C:\WINDOWS\WINDOWS\Fonts\ega40737.fon
C:\WINDOWS\WINDOWS\Fonts\ega40850.fon
C:\WINDOWS\WINDOWS\Fonts\ega40852.fon
C:\WINDOWS\WINDOWS\Fonts\ega40857.fon
C:\WINDOWS\WINDOWS\Fonts\ega40866.fon
C:\WINDOWS\WINDOWS\Fonts\ega40869.fon
C:\WINDOWS\WINDOWS\Fonts\ega40woa.fon
C:\WINDOWS\WINDOWS\Fonts\ega80737.fon
C:\WINDOWS\WINDOWS\Fonts\ega80850.fon
C:\WINDOWS\WINDOWS\Fonts\ega80852.fon
C:\WINDOWS\WINDOWS\Fonts\ega80857.fon
C:\WINDOWS\WINDOWS\Fonts\ega80866.fon
C:\WINDOWS\WINDOWS\Fonts\ega80869.fon
C:\WINDOWS\WINDOWS\Fonts\ega80woa.fon
C:\WINDOWS\WINDOWS\Fonts\Elegance.TTF
C:\WINDOWS\WINDOWS\Fonts\ELEPHNT.TTF
C:\WINDOWS\WINDOWS\Fonts\ELEPHNTI.TTF
C:\WINDOWS\WINDOWS\Fonts\Ellis___.TTF
C:\WINDOWS\WINDOWS\Fonts\Engr.TTF
C:\WINDOWS\WINDOWS\Fonts\Engrb.TTF
C:\WINDOWS\WINDOWS\Fonts\Enviro.ttf
C:\WINDOWS\WINDOWS\Fonts\Erasdemi.TTF
C:\WINDOWS\WINDOWS\Fonts\Eraslght.TTF
C:\WINDOWS\WINDOWS\Fonts\estre.ttf
C:\WINDOWS\WINDOWS\Fonts\Eurosti.TTF
C:\WINDOWS\WINDOWS\Fonts\Eurostib.TTF
C:\WINDOWS\WINDOWS\Fonts\Excess__.TTF
C:\WINDOWS\WINDOWS\Fonts\Felixti.TTF
C:\WINDOWS\WINDOWS\Fonts\FineHand.ttf
C:\WINDOWS\WINDOWS\Fonts\Frabk.TTF
C:\WINDOWS\WINDOWS\Fonts\Frabkit.TTF
C:\WINDOWS\WINDOWS\Fonts\Fradm.TTF
C:\WINDOWS\WINDOWS\Fonts\FRADMCN.TTF
C:\WINDOWS\WINDOWS\Fonts\Fradmit.TTF
C:\WINDOWS\WINDOWS\Fonts\FRAHV.TTF
C:\WINDOWS\WINDOWS\Fonts\FRAHVIT.TTF
C:\WINDOWS\WINDOWS\Fonts\framd.ttf
C:\WINDOWS\WINDOWS\Fonts\Framdcn.TTF
C:\WINDOWS\WINDOWS\Fonts\framdit.ttf
C:\WINDOWS\WINDOWS\Fonts\FreeScpt.ttf
C:\WINDOWS\WINDOWS\Fonts\Frscript.TTF
C:\WINDOWS\WINDOWS\Fonts\GARA.TTF
C:\WINDOWS\WINDOWS\Fonts\GARABD.TTF
C:\WINDOWS\WINDOWS\Fonts\GARAIT.TTF
C:\WINDOWS\WINDOWS\Fonts\gautami.ttf
C:\WINDOWS\WINDOWS\Fonts\Genuine_.TTF
C:\WINDOWS\WINDOWS\Fonts\georgia.ttf
C:\WINDOWS\WINDOWS\Fonts\georgiab.ttf
C:\WINDOWS\WINDOWS\Fonts\georgiai.ttf
C:\WINDOWS\WINDOWS\Fonts\georgiaz.ttf
C:\WINDOWS\WINDOWS\Fonts\Gigi.ttf
C:\WINDOWS\WINDOWS\Fonts\Gil_____.TTF
C:\WINDOWS\WINDOWS\Fonts\Gilb____.TTF
C:\WINDOWS\WINDOWS\Fonts\Gilbi___.TTF
C:\WINDOWS\WINDOWS\Fonts\Gilc____.TTF
C:\WINDOWS\WINDOWS\Fonts\Gilcb___.TTF
C:\WINDOWS\WINDOWS\Fonts\Gili____.TTF
C:\WINDOWS\WINDOWS\Fonts\Gilsanub.TTF
C:\WINDOWS\WINDOWS\Fonts\Gothic.TTF
C:\WINDOWS\WINDOWS\Fonts\Gothicb.TTF
C:\WINDOWS\WINDOWS\Fonts\Gothicbi.TTF
C:\WINDOWS\WINDOWS\Fonts\Gothici.TTF
C:\WINDOWS\WINDOWS\Fonts\GOUDOS.TTF
C:\WINDOWS\WINDOWS\Fonts\GOUDOSB.TTF
C:\WINDOWS\WINDOWS\Fonts\GOUDOSI.TTF
C:\WINDOWS\WINDOWS\Fonts\Goudysto.ttf
C:\WINDOWS\WINDOWS\Fonts\GRGAREF.TTF
C:\WINDOWS\WINDOWS\Fonts\HARLOWSI.TTF
C:\WINDOWS\WINDOWS\Fonts\HARNGTON.TTF
C:\WINDOWS\WINDOWS\Fonts\Helte___.TTF
C:\WINDOWS\WINDOWS\Fonts\Herman__.TTF
C:\WINDOWS\WINDOWS\Fonts\impact.ttf
C:\WINDOWS\WINDOWS\Fonts\IMPRISHA.TTF
C:\WINDOWS\WINDOWS\Fonts\InfRoman.ttf
C:\WINDOWS\WINDOWS\Fonts\Isabelle.TTF
C:\WINDOWS\WINDOWS\Fonts\ITCBlkad.TTF
C:\WINDOWS\WINDOWS\Fonts\ITCEdscr.TTF
C:\WINDOWS\WINDOWS\Fonts\ITCKrist.TTF
C:\WINDOWS\WINDOWS\Fonts\Joan____.TTF
C:\WINDOWS\WINDOWS\Fonts\Jokerman.ttf
C:\WINDOWS\WINDOWS\Fonts\JUICE___.TTF
C:\WINDOWS\WINDOWS\Fonts\Justice_.TTF
C:\WINDOWS\WINDOWS\Fonts\KINO.TTF
C:\WINDOWS\WINDOWS\Fonts\Kunstler.ttf
C:\WINDOWS\WINDOWS\Fonts\l_10646.ttf
C:\WINDOWS\WINDOWS\Fonts\latha.ttf
C:\WINDOWS\WINDOWS\Fonts\LATINWD.TTF
C:\WINDOWS\WINDOWS\Fonts\LCALLIG.TTF
C:\WINDOWS\WINDOWS\Fonts\LHANDW.TTF
C:\WINDOWS\WINDOWS\Fonts\Lsans.TTF
C:\WINDOWS\WINDOWS\Fonts\Lsansd.TTF
C:\WINDOWS\WINDOWS\Fonts\Lsansdi.TTF
C:\WINDOWS\WINDOWS\Fonts\Lsansi.TTF
C:\WINDOWS\WINDOWS\Fonts\lsansuni.ttf
C:\WINDOWS\WINDOWS\Fonts\lucon.ttf
C:\WINDOWS\WINDOWS\Fonts\Maian.TTF
C:\WINDOWS\WINDOWS\Fonts\Maiandb.TTF
C:\WINDOWS\WINDOWS\Fonts\Maiandit.TTF
C:\WINDOWS\WINDOWS\Fonts\Mandela_.TTF
C:\WINDOWS\WINDOWS\Fonts\mangal.ttf
C:\WINDOWS\WINDOWS\Fonts\marlett.ttf
C:\WINDOWS\WINDOWS\Fonts\matisse_.ttf
C:\WINDOWS\WINDOWS\Fonts\Matte___.TTF
C:\WINDOWS\WINDOWS\Fonts\MATURASC.TTF
C:\WINDOWS\WINDOWS\Fonts\Microdot.TTF
C:\WINDOWS\WINDOWS\Fonts\micross.ttf
C:\WINDOWS\WINDOWS\Fonts\Mistral.TTF
C:\WINDOWS\WINDOWS\Fonts\MOD20.TTF
C:\WINDOWS\WINDOWS\Fonts\modern.fon
C:\WINDOWS\WINDOWS\Fonts\MSREF1.TTF
C:\WINDOWS\WINDOWS\Fonts\MSREF2.TTF
C:\WINDOWS\WINDOWS\Fonts\MTCORSVA.TTF
C:\WINDOWS\WINDOWS\Fonts\mvboli.ttf
C:\WINDOWS\WINDOWS\Fonts\Natur___.TTF
C:\WINDOWS\WINDOWS\Fonts\Neolith_.TTF
C:\WINDOWS\WINDOWS\Fonts\Nina.ttf
C:\WINDOWS\WINDOWS\Fonts\Ninab.ttf
C:\WINDOWS\WINDOWS\Fonts\Ninabi.ttf
C:\WINDOWS\WINDOWS\Fonts\Ninai.ttf
C:\WINDOWS\WINDOWS\Fonts\OCRB.TTF
C:\WINDOWS\WINDOWS\Fonts\OLDENGL.TTF
C:\WINDOWS\WINDOWS\Fonts\ONYX.TTF
C:\WINDOWS\WINDOWS\Fonts\Openc___.TTF
C:\WINDOWS\WINDOWS\Fonts\pala.ttf
C:\WINDOWS\WINDOWS\Fonts\palab.ttf
C:\WINDOWS\WINDOWS\Fonts\palabi.ttf
C:\WINDOWS\WINDOWS\Fonts\palai.ttf
C:\WINDOWS\WINDOWS\Fonts\PALSCRI.TTF
C:\WINDOWS\WINDOWS\Fonts\papyrus.ttf
C:\WINDOWS\WINDOWS\Fonts\PARADE.TTF
C:\WINDOWS\WINDOWS\Fonts\PARCHM.TTF
C:\WINDOWS\WINDOWS\Fonts\PEPITA.TTF
C:\WINDOWS\WINDOWS\Fonts\Per_____.TTF
C:\WINDOWS\WINDOWS\Fonts\Perb____.TTF
C:\WINDOWS\WINDOWS\Fonts\Perbi___.TTF
C:\WINDOWS\WINDOWS\Fonts\Peri____.TTF
C:\WINDOWS\WINDOWS\Fonts\PERTIBD.TTF
C:\WINDOWS\WINDOWS\Fonts\PERTILI.TTF
C:\WINDOWS\WINDOWS\Fonts\PHONETIC.FON
C:\WINDOWS\WINDOWS\Fonts\PLACCOND.TTF
C:\WINDOWS\WINDOWS\Fonts\PLAYBILL.TTF
C:\WINDOWS\WINDOWS\Fonts\POORICH.TTF
C:\WINDOWS\WINDOWS\Fonts\Pretext_.TTF
C:\WINDOWS\WINDOWS\Fonts\Pristina.ttf
C:\WINDOWS\WINDOWS\Fonts\Puppy___.TTF
C:\WINDOWS\WINDOWS\Fonts\raavi.ttf
C:\WINDOWS\WINDOWS\Fonts\Radagund.TTF
C:\WINDOWS\WINDOWS\Fonts\Rage.ttf
C:\WINDOWS\WINDOWS\Fonts\Realv___.TTF
C:\WINDOWS\WINDOWS\Fonts\REF_ICON.FON
C:\WINDOWS\WINDOWS\Fonts\REFSAN.TTF
C:\WINDOWS\WINDOWS\Fonts\REFSANB.TTF
C:\WINDOWS\WINDOWS\Fonts\REFSANBI.TTF
C:\WINDOWS\WINDOWS\Fonts\REFSANI.TTF
C:\WINDOWS\WINDOWS\Fonts\REFSER.TTF
C:\WINDOWS\WINDOWS\Fonts\REFSERB.TTF
C:\WINDOWS\WINDOWS\Fonts\REFSERBI.TTF
C:\WINDOWS\WINDOWS\Fonts\REFSERI.TTF
C:\WINDOWS\WINDOWS\Fonts\REFSPCL.TTF
C:\WINDOWS\WINDOWS\Fonts\REFSPEC.TTF
C:\WINDOWS\WINDOWS\Fonts\ROCK.TTF
C:\WINDOWS\WINDOWS\Fonts\ROCKB.TTF
C:\WINDOWS\WINDOWS\Fonts\ROCKBI.TTF
C:\WINDOWS\WINDOWS\Fonts\Rockeb.TTF
C:\WINDOWS\WINDOWS\Fonts\ROCKI.TTF
C:\WINDOWS\WINDOWS\Fonts\roman.fon
C:\WINDOWS\WINDOWS\Fonts\RUNICCN.TTF
C:\WINDOWS\WINDOWS\Fonts\script.fon
C:\WINDOWS\WINDOWS\Fonts\SCRIPTBL.TTF
C:\WINDOWS\WINDOWS\Fonts\sere1257.fon
C:\WINDOWS\WINDOWS\Fonts\serf1257.fon
C:\WINDOWS\WINDOWS\Fonts\serife.fon
C:\WINDOWS\WINDOWS\Fonts\serifee.fon
C:\WINDOWS\WINDOWS\Fonts\serifeg.fon
C:\WINDOWS\WINDOWS\Fonts\serifer.fon
C:\WINDOWS\WINDOWS\Fonts\serifet.fon
C:\WINDOWS\WINDOWS\Fonts\seriff.fon
C:\WINDOWS\WINDOWS\Fonts\seriffe.fon
C:\WINDOWS\WINDOWS\Fonts\seriffg.fon
C:\WINDOWS\WINDOWS\Fonts\seriffr.fon
C:\WINDOWS\WINDOWS\Fonts\serifft.fon
C:\WINDOWS\WINDOWS\Fonts\Shelman_.TTF
C:\WINDOWS\WINDOWS\Fonts\shruti.ttf
C:\WINDOWS\WINDOWS\Fonts\smae1257.fon
C:\WINDOWS\WINDOWS\Fonts\smaf1257.fon
C:\WINDOWS\WINDOWS\Fonts\smalle.fon
C:\WINDOWS\WINDOWS\Fonts\smallee.fon
C:\WINDOWS\WINDOWS\Fonts\smalleg.fon
C:\WINDOWS\WINDOWS\Fonts\smaller.fon
C:\WINDOWS\WINDOWS\Fonts\smallet.fon
C:\WINDOWS\WINDOWS\Fonts\smallf.fon
C:\WINDOWS\WINDOWS\Fonts\smallfe.fon
C:\WINDOWS\WINDOWS\Fonts\smallfg.fon
C:\WINDOWS\WINDOWS\Fonts\smallfr.fon
C:\WINDOWS\WINDOWS\Fonts\smallft.fon
C:\WINDOWS\WINDOWS\Fonts\SNAP____.TTF
C:\WINDOWS\WINDOWS\Fonts\ssee1257.fon
C:\WINDOWS\WINDOWS\Fonts\ssef1257.fon
C:\WINDOWS\WINDOWS\Fonts\sserife.fon
C:\WINDOWS\WINDOWS\Fonts\sserifee.fon
C:\WINDOWS\WINDOWS\Fonts\sserifeg.fon
C:\WINDOWS\WINDOWS\Fonts\sserifer.fon
C:\WINDOWS\WINDOWS\Fonts\sserifet.fon
C:\WINDOWS\WINDOWS\Fonts\sseriff.fon
C:\WINDOWS\WINDOWS\Fonts\sseriffe.fon
C:\WINDOWS\WINDOWS\Fonts\sseriffg.fon
C:\WINDOWS\WINDOWS\Fonts\sseriffr.fon
C:\WINDOWS\WINDOWS\Fonts\sserifft.fon
C:\WINDOWS\WINDOWS\Fonts\sylfaen.ttf
C:\WINDOWS\WINDOWS\Fonts\symbol.ttf
C:\WINDOWS\WINDOWS\Fonts\symbole.fon
C:\WINDOWS\WINDOWS\Fonts\tahoma.ttf
C:\WINDOWS\WINDOWS\Fonts\tahomabd.ttf
C:\WINDOWS\WINDOWS\Fonts\TempsITC.TTF
C:\WINDOWS\WINDOWS\Fonts\times.ttf
C:\WINDOWS\WINDOWS\Fonts\timesbd.ttf
C:\WINDOWS\WINDOWS\Fonts\timesbi.ttf
C:\WINDOWS\WINDOWS\Fonts\timesi.ttf
C:\WINDOWS\WINDOWS\Fonts\trebuc.ttf
C:\WINDOWS\WINDOWS\Fonts\trebucbd.ttf
C:\WINDOWS\WINDOWS\Fonts\trebucbi.ttf
C:\WINDOWS\WINDOWS\Fonts\trebucit.ttf
C:\WINDOWS\WINDOWS\Fonts\Trendy__.TTF
C:\WINDOWS\WINDOWS\Fonts\tunga.ttf
C:\WINDOWS\WINDOWS\Fonts\verdana.ttf
C:\WINDOWS\WINDOWS\Fonts\verdanab.ttf
C:\WINDOWS\WINDOWS\Fonts\verdanai.ttf
C:\WINDOWS\WINDOWS\Fonts\verdanaz.ttf
C:\WINDOWS\WINDOWS\Fonts\VERDREF.TTF
C:\WINDOWS\WINDOWS\Fonts\vga737.fon
C:\WINDOWS\WINDOWS\Fonts\vga775.fon
C:\WINDOWS\WINDOWS\Fonts\vga850.fon
C:\WINDOWS\WINDOWS\Fonts\vga852.fon
C:\WINDOWS\WINDOWS\Fonts\vga855.fon
C:\WINDOWS\WINDOWS\Fonts\vga857.fon
C:\WINDOWS\WINDOWS\Fonts\vga860.fon
C:\WINDOWS\WINDOWS\Fonts\vga863.fon
C:\WINDOWS\WINDOWS\Fonts\vga865.fon
C:\WINDOWS\WINDOWS\Fonts\vga866.fon
C:\WINDOWS\WINDOWS\Fonts\vga869.fon
C:\WINDOWS\WINDOWS\Fonts\vgaf1257.fon
C:\WINDOWS\WINDOWS\Fonts\vgafix.fon
C:\WINDOWS\WINDOWS\Fonts\vgafixe.fon
C:\WINDOWS\WINDOWS\Fonts\vgafixg.fon
C:\WINDOWS\WINDOWS\Fonts\vgafixr.fon
C:\WINDOWS\WINDOWS\Fonts\vgafixt.fon
C:\WINDOWS\WINDOWS\Fonts\vgaoem.fon
C:\WINDOWS\WINDOWS\Fonts\vgas1257.fon
C:\WINDOWS\WINDOWS\Fonts\vgasys.fon
C:\WINDOWS\WINDOWS\Fonts\vgasyse.fon
C:\WINDOWS\WINDOWS\Fonts\vgasysg.fon
C:\WINDOWS\WINDOWS\Fonts\vgasysr.fon
C:\WINDOWS\WINDOWS\Fonts\vgasyst.fon
C:\WINDOWS\WINDOWS\Fonts\VINERITC.TTF
C:\WINDOWS\WINDOWS\Fonts\Vivaldii.TTF
C:\WINDOWS\WINDOWS\Fonts\Vladimir.ttf
C:\WINDOWS\WINDOWS\Fonts\webdings.ttf
C:\WINDOWS\WINDOWS\Fonts\wingding.ttf
C:\WINDOWS\WINDOWS\Fonts\WINGDNG2.TTF
C:\WINDOWS\WINDOWS\Fonts\WINGDNG3.TTF
C:\WINDOWS\WINDOWS\Fonts\wst_czec.fon
C:\WINDOWS\WINDOWS\Fonts\wst_engl.fon
C:\WINDOWS\WINDOWS\Fonts\wst_fren.fon
C:\WINDOWS\WINDOWS\Fonts\wst_germ.fon
C:\WINDOWS\WINDOWS\Fonts\wst_ital.fon
C:\WINDOWS\WINDOWS\Fonts\wst_span.fon
C:\WINDOWS\WINDOWS\Fonts\wst_swed.fon
C:\WINDOWS\WINDOWS\Fächer.bmp
C:\WINDOWS\WINDOWS\Granit.bmp
C:\WINDOWS\WINDOWS\GRAPPLER.INI
C:\WINDOWS\WINDOWS\HBCIKRNL.INI
C:\WINDOWS\WINDOWS\Help\acc_dis.chm
C:\WINDOWS\WINDOWS\Help\accessib.chm
C:\WINDOWS\WINDOWS\Help\aclui.hlp
C:\WINDOWS\WINDOWS\Help\admtools.chm
C:\WINDOWS\WINDOWS\Help\apps.chm
C:\WINDOWS\WINDOWS\Help\apps_sp.chm
C:\WINDOWS\WINDOWS\Help\certmgr.chm
C:\WINDOWS\WINDOWS\Help\ciadmin.htm
C:\WINDOWS\WINDOWS\Help\ciquery.htm
C:\WINDOWS\WINDOWS\Help\cmconcepts.chm
C:\WINDOWS\WINDOWS\Help\conf.cnt
C:\WINDOWS\WINDOWS\Help\connect.cnt
C:\WINDOWS\WINDOWS\Help\cpanel.chm
C:\WINDOWS\WINDOWS\Help\cpanel.chq
C:\WINDOWS\WINDOWS\Help\diskmgmt.chm
C:\WINDOWS\WINDOWS\Help\display.chm
C:\WINDOWS\WINDOWS\Help\filefold.chm
C:\WINDOWS\WINDOWS\Help\find.chm
C:\WINDOWS\WINDOWS\Help\Glossary.chm
C:\WINDOWS\WINDOWS\Help\hardware.hlp
C:\WINDOWS\WINDOWS\Help\howto.chm
C:\WINDOWS\WINDOWS\Help\hschelp.chm
C:\WINDOWS\WINDOWS\Help\iesupp.chm
C:\WINDOWS\WINDOWS\Help\iewebhlp.chm
C:\WINDOWS\WINDOWS\Help\input.chm
C:\WINDOWS\WINDOWS\Help\input.hlp
C:\WINDOWS\WINDOWS\Help\ipsecconcepts.chm
C:\WINDOWS\WINDOWS\Help\ipsecsnp.chm
C:\WINDOWS\WINDOWS\Help\ixqlang.htm
C:\WINDOWS\WINDOWS\Help\JntView.chm
C:\WINDOWS\WINDOWS\Help\langbar.chm
C:\WINDOWS\WINDOWS\Help\license.chm
C:\WINDOWS\WINDOWS\Help\migwiz.htm
C:\WINDOWS\WINDOWS\Help\migwiz2.htm
C:\WINDOWS\WINDOWS\Help\misc.chm
C:\WINDOWS\WINDOWS\Help\mpconcepts.chm
C:\WINDOWS\WINDOWS\Help\mplayer2.cnt
C:\WINDOWS\WINDOWS\Help\mshearts.cnt
C:\WINDOWS\WINDOWS\Help\msnauth.cnt
C:\WINDOWS\WINDOWS\Help\NAV.chm
C:\WINDOWS\WINDOWS\Help\netcfg.chm
C:\WINDOWS\WINDOWS\Help\network.chm
C:\WINDOWS\WINDOWS\Help\nocontnt.cnt
C:\WINDOWS\WINDOWS\Help\ntart.chm
C:\WINDOWS\WINDOWS\Help\ntcmds.chm
C:\WINDOWS\WINDOWS\Help\ntdef.chm
C:\WINDOWS\WINDOWS\Help\nusrmgr.chm
C:\WINDOWS\WINDOWS\Help\nvcpar.hlp
C:\WINDOWS\WINDOWS\Help\nvcpcs.hlp
C:\WINDOWS\WINDOWS\Help\nvcpda.hlp
C:\WINDOWS\WINDOWS\Help\nvcpde.hlp
C:\WINDOWS\WINDOWS\Help\nvcpel.hlp
C:\WINDOWS\WINDOWS\Help\nvcpeng.hlp
C:\WINDOWS\WINDOWS\Help\nvcpes.hlp
C:\WINDOWS\WINDOWS\Help\nvcpesm.hlp
C:\WINDOWS\WINDOWS\Help\nvcpfi.hlp
C:\WINDOWS\WINDOWS\Help\nvcpfr.hlp
C:\WINDOWS\WINDOWS\Help\nvcphe.hlp
C:\WINDOWS\WINDOWS\Help\nvcphu.hlp
C:\WINDOWS\WINDOWS\Help\nvcpit.hlp
C:\WINDOWS\WINDOWS\Help\nvcpja.hlp
C:\WINDOWS\WINDOWS\Help\nvcpko.hlp
C:\WINDOWS\WINDOWS\Help\nvcpl.hlp
C:\WINDOWS\WINDOWS\Help\nvcpnl.hlp
C:\WINDOWS\WINDOWS\Help\nvcpno.hlp
C:\WINDOWS\WINDOWS\Help\nvcppl.hlp
C:\WINDOWS\WINDOWS\Help\nvcppt.hlp
C:\WINDOWS\WINDOWS\Help\nvcpptb.hlp
C:\WINDOWS\WINDOWS\Help\nvcpru.hlp
C:\WINDOWS\WINDOWS\Help\nvcpsk.hlp
C:\WINDOWS\WINDOWS\Help\nvcpsl.hlp
C:\WINDOWS\WINDOWS\Help\nvcpsv.hlp
C:\WINDOWS\WINDOWS\Help\nvcpth.hlp
C:\WINDOWS\WINDOWS\Help\nvcptr.hlp
C:\WINDOWS\WINDOWS\Help\nvcpzhc.hlp
C:\WINDOWS\WINDOWS\Help\nvcpzht.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpcs.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpda.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpde.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpel.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpeng.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpes.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpesm.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpfi.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpfr.hlp
C:\WINDOWS\WINDOWS\Help\nvwcphu.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpit.hlp
C:\WINDOWS\WINDOWS\Help\nvwcplen.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpnl.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpno.hlp
C:\WINDOWS\WINDOWS\Help\nvwcppl.hlp
C:\WINDOWS\WINDOWS\Help\nvwcppt.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpptb.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpru.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpsk.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpsl.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpsv.hlp
C:\WINDOWS\WINDOWS\Help\nvwcptr.hlp
C:\WINDOWS\WINDOWS\Help\nwdoc.chm
C:\WINDOWS\WINDOWS\Help\password.chm
C:\WINDOWS\WINDOWS\Help\plyr_err.chm
C:\WINDOWS\WINDOWS\Help\printing.chm
C:\WINDOWS\WINDOWS\Help\progman.cnt
C:\WINDOWS\WINDOWS\Help\pwrmn.chm
C:\WINDOWS\WINDOWS\Help\ratings.cnt
C:\WINDOWS\WINDOWS\Help\regopt.chm
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\bookmrk.CDX
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\bookmrk.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Groups.cdx
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Groups.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Grpsyll.cdx
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Grpsyll.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Prgrss2.cdx
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Prgrss2.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Progress.cdx
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Progress.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Settings.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Syllabi2.cdx
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Syllabi2.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Syllabus.cdx
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Syllabus.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Usergrp.cdx
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Usergrp.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Users.cdx
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Users.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\WXPPera.toc
C:\WINDOWS\WINDOWS\Help\SBSI\Training\engine.ini
C:\WINDOWS\WINDOWS\Help\SBSI\Training\lsingle.cnt
C:\WINDOWS\WINDOWS\Help\SBSI\Training\LSINGLE.HLP
C:\WINDOWS\WINDOWS\Help\SBSI\Training\orun32.exe
C:\WINDOWS\WINDOWS\Help\SBSI\Training\ounins32_s.exe
C:\WINDOWS\WINDOWS\Help\SBSI\Training\startmenu.cbo
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\CBO\hsc_add.vbs
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\CBO\hsc_del.vbs
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\CBO\wxpper.chm
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\CBO\wxppera.cab
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L10_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L10_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L10_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L10_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L10_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L10_Fa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L11_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L11_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L11_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L11_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L12_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L12_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L12_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L12_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L12_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L13_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L13_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L13_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L13_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L13_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L13_Fa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L14_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L14_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L14_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L14_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L14_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L15_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L15_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L15_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L15_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L15_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L15_Fa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L16_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L16_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L16_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L16_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L16_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L17_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L17_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L17_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L17_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L17_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L1_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L2_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L2_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L2_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L2_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L2_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L2_Fa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L2_Ga.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L2_Ha.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L2_Ia.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L3_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L3_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L3_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L3_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L3_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L4_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L4_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L4_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L4_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L4_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L4_Fa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L4_Ga.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L4_Ha.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L5_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L5_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L5_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L5_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L5_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L5_Fa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L5_Ga.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L5_Ha.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L6_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L6_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L6_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L6_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L6_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L7_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L7_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L7_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L7_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L7_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L7_Fa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L8_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L8_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L8_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L8_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L8_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L9_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L9_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L9_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L9_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L9_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L9_Fa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\fin_shot.SWF
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L10_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L10_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L10_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L10_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L10_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L10_F.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L11_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L11_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L11_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L11_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L12_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L12_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L12_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L12_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L12_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L13_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L13_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L13_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L13_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L13_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L13_F.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L14_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L14_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L14_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L14_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L14_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L15_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L15_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L15_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L15_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L15_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L15_F.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L16_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L16_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L16_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L16_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L16_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L17_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L17_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L17_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L17_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L17_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L1_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L2_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L2_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L2_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L2_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L2_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L2_F.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L2_G.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L2_H.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L2_I.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L3_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L3_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L3_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L3_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L3_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L4_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L4_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L4_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L4_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L4_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L4_F.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L4_G.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L4_H.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L5_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L5_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L5_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L5_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L5_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L5_F.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L5_G.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L5_H.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L6_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L6_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L6_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L6_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L6_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L7_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L7_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L7_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L7_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L7_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L7_F.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L8_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L8_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L8_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L8_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L8_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L9_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L9_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L9_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L9_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L9_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L9_F.LDZ
C:\WI
- JW1
- Beiträge: 11
- Registriert: 11.07.2007, 13:04
- Wohnort: im Norden
Hallo,
von CounterSpy bekomme ich den Report nicht komplett gepostet.
Gibt es eine Möglichkeit diesen zu komprimieren und hier einzustellen?
Den Hijackreport stelle ich hier rein:
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 08:17:57, on 12.07.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\cisvc.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkUFind.exe
C:\Programme\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe
C:\Programme\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
C:\Programme\QuickTime\qttask.exe
C:\Programme\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\carpserv.exe
C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programme\Microsoft IntelliType Pro\itype.exe
C:\Programme\Windows Defender\MSASCui.exe
C:\Programme\Sunbelt Software\CounterSpy\SBCSTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\Spamihilator\spamihilator.exe
C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Programme\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programme\Sunbelt Software\CounterSpy\SBCSSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexingService.exe
C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexStoreSvr.exe
C:\Programme\Internet Explorer\iexplore.exe
C:\Dokumente und Einstellungen\Jörgel\Eigene Dateien\HiJackThis_v2.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.t-online.de/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.t-online.de
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.t-online.de
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer bereitgestellt von T-Online
R3 - URLSearchHook: Yahoo! Toolbar mit Pop-Up-Blocker - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programme\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programme\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programme\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar mit Pop-Up-Blocker - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programme\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [PMCS] C:\Programme\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe -host -clearDebug
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [PMCRemote] C:\Programme\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programme\Gemeinsame Dateien\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [avgnt] "C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [itype] "c:\Programme\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Programme\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SBCSTray] C:\Programme\Sunbelt Software\CounterSpy\SBCSTray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Spamihilator] "C:\Programme\Spamihilator\spamihilator.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [swg] C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/german/par ... nicode.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/house ... hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/Shar ... vSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Programme\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.johannrain-softwareentwicklu ... oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 4826135370
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 4826469182
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan ... asinst.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsup ... mAData.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsup ... veData.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: AntiVir PersonalEdition Classic Planer (AntiVirScheduler) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Pinnacle Systems tvtv Spooler (EpgSpooler) - - c:\progra~1\pinnacle\mediac~1\epgspo~2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Programme\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - c:\programme\pinnacle\shared files\programs\mediaserver\pmshost.exe
O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Programme\Sunbelt Software\CounterSpy\SBCSSvc.exe
O24 - Desktop Component 1: (no name) - http://speedmanager.t-com-dsl.de/
--
End of file - 10585 bytes
So, die Explorer.Exe macht immer noch auf 100%.
Gruß JW1[/code]
von CounterSpy bekomme ich den Report nicht komplett gepostet.
Gibt es eine Möglichkeit diesen zu komprimieren und hier einzustellen?
Den Hijackreport stelle ich hier rein:
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 08:17:57, on 12.07.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\cisvc.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkUFind.exe
C:\Programme\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe
C:\Programme\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
C:\Programme\QuickTime\qttask.exe
C:\Programme\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\carpserv.exe
C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programme\Microsoft IntelliType Pro\itype.exe
C:\Programme\Windows Defender\MSASCui.exe
C:\Programme\Sunbelt Software\CounterSpy\SBCSTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\Spamihilator\spamihilator.exe
C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Programme\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programme\Sunbelt Software\CounterSpy\SBCSSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexingService.exe
C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexStoreSvr.exe
C:\Programme\Internet Explorer\iexplore.exe
C:\Dokumente und Einstellungen\Jörgel\Eigene Dateien\HiJackThis_v2.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.t-online.de/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.t-online.de
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.t-online.de
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer bereitgestellt von T-Online
R3 - URLSearchHook: Yahoo! Toolbar mit Pop-Up-Blocker - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programme\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programme\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programme\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar mit Pop-Up-Blocker - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programme\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [PMCS] C:\Programme\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe -host -clearDebug
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [PMCRemote] C:\Programme\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programme\Gemeinsame Dateien\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [avgnt] "C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [itype] "c:\Programme\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Programme\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SBCSTray] C:\Programme\Sunbelt Software\CounterSpy\SBCSTray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Spamihilator] "C:\Programme\Spamihilator\spamihilator.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [swg] C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/german/par ... nicode.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/house ... hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/Shar ... vSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Programme\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.johannrain-softwareentwicklu ... oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 4826135370
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 4826469182
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan ... asinst.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsup ... mAData.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsup ... veData.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: AntiVir PersonalEdition Classic Planer (AntiVirScheduler) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Pinnacle Systems tvtv Spooler (EpgSpooler) - - c:\progra~1\pinnacle\mediac~1\epgspo~2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Programme\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - c:\programme\pinnacle\shared files\programs\mediaserver\pmshost.exe
O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Programme\Sunbelt Software\CounterSpy\SBCSSvc.exe
O24 - Desktop Component 1: (no name) - http://speedmanager.t-com-dsl.de/
--
End of file - 10585 bytes
So, die Explorer.Exe macht immer noch auf 100%.
Gruß JW1[/code]
- JW1
- Beiträge: 11
- Registriert: 11.07.2007, 13:04
- Wohnort: im Norden
CCLEANER ausführen
Nun zuerst die
Systemwiederherstellung
http://support.microsoft.com/default.as ... ;de;310405
zuerst deaktivieren, dann wieder aktivieren
Totalscan ausführen:
http://www.nanoscan.com/as/v1/?
wähle:Full scan
(Warnmeldung von Antivir = ignorieren)
Bericht speichern und posten
Nun zuerst die
Systemwiederherstellung
http://support.microsoft.com/default.as ... ;de;310405
zuerst deaktivieren, dann wieder aktivieren
Totalscan ausführen:
http://www.nanoscan.com/as/v1/?
wähle:Full scan
(Warnmeldung von Antivir = ignorieren)
Bericht speichern und posten
- Humdinger
- Mitarbeiter
- Beiträge: 896
- Registriert: 22.03.2006, 14:22
- Wohnort: Mainz
Hat ein bisschen länger gedauert, da mein Rechner dreimal abgestürzt ist.
Hier nun der Report:
;***********************************************************************************************************************************************************************************
ANALYSIS: 2007-07-12 19:38:32
PROTECTIONS: 5
MALWARE: 4
SUSPECTS: 2
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
AntiVir PersonalEdition Classic Virenschutz 0.0.0.0 Yes No
Avira AntiVir PersonalEdition 6.39.0.131
Yes Yes
AntiVir PersonalEdition Classic Virenschutz 0.0.0.0 Yes Yes
AntiVir PersonalEdition Classic Virenschutz 6.38.1.19
Yes Yes
AntiVir PersonalEdition Classic Virenschutz 0.0.0.0 Yes Yes
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00035917 adware/ist.sidefind Adware No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10E42047-DEB9-4535-A118-B3F6EC39B807}
00042191 adware/ist.yoursitebar Adware No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{86227D9C-0EFE-4F8A-AA55-30386A3F5686}
00235842 Application/RealSpy HackTools No 0 Yes No C:\WINDOWS\system32\actskn45.ocx
01192348 Application/MyWebSearch HackTools No 0 No No C:\Dokumente und Einstellungen\Jörgel\Eigene Dateien\Bearbeitungstools\Nero-7.8.5.0_deu_update.exe[Toolbar.exe]
;===================================================================================================================================================================================
SUSPECTS
Location
;===================================================================================================================================================================================
C:\Dokumente und Einstellungen\Jörgel\Eigene Dateien\RegSeeker155.zip[RegSeeker\RegSeeker.exe]
C:\Dokumente und Einstellungen\Jörgel\Eigene Dateien\RegSeeker155\RegSeeker\RegSeeker.exe
;===================================================================================================================================================================================
Wie gehts weiter?
JW1
Hier nun der Report:
;***********************************************************************************************************************************************************************************
ANALYSIS: 2007-07-12 19:38:32
PROTECTIONS: 5
MALWARE: 4
SUSPECTS: 2
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
AntiVir PersonalEdition Classic Virenschutz 0.0.0.0 Yes No
Avira AntiVir PersonalEdition 6.39.0.131
Yes Yes
AntiVir PersonalEdition Classic Virenschutz 0.0.0.0 Yes Yes
AntiVir PersonalEdition Classic Virenschutz 6.38.1.19
Yes Yes
AntiVir PersonalEdition Classic Virenschutz 0.0.0.0 Yes Yes
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00035917 adware/ist.sidefind Adware No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10E42047-DEB9-4535-A118-B3F6EC39B807}
00042191 adware/ist.yoursitebar Adware No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{86227D9C-0EFE-4F8A-AA55-30386A3F5686}
00235842 Application/RealSpy HackTools No 0 Yes No C:\WINDOWS\system32\actskn45.ocx
01192348 Application/MyWebSearch HackTools No 0 No No C:\Dokumente und Einstellungen\Jörgel\Eigene Dateien\Bearbeitungstools\Nero-7.8.5.0_deu_update.exe[Toolbar.exe]
;===================================================================================================================================================================================
SUSPECTS
Location
;===================================================================================================================================================================================
C:\Dokumente und Einstellungen\Jörgel\Eigene Dateien\RegSeeker155.zip[RegSeeker\RegSeeker.exe]
C:\Dokumente und Einstellungen\Jörgel\Eigene Dateien\RegSeeker155\RegSeeker\RegSeeker.exe
;===================================================================================================================================================================================
Wie gehts weiter?
JW1
- JW1
- Beiträge: 11
- Registriert: 11.07.2007, 13:04
- Wohnort: im Norden
Alle Dateien anzeigen
Arbeitsplatz -> rechter Mausklick -->Windows Explorer -> "Extras/Ordneroptionen" ->
"Ansicht" -> Haken entfernen bei "Geschützte Systemdateien
ausblenden (empfohlen)" und "Alle Dateien und Ordner anzeigen"
aktivieren -> "OK"
abgesicherter Modus starten
lösche direkt
C:\WINDOWS\system32\actskn45.ocx
C:\Dokumente und Einstellungen\Jörgel\Eigene Dateien\Bearbeitungstools\Nero-7.8.5.0_deu_update.exe[Toolbar.exe]
weiter im abgesicherten Modus
start-ausführen: regedit
navigiere zu den Funden und lösche
Neustart Normalstart
Onlinescan vom gesamten System:
http://www.kaspersky.com/kos/german/par ... bscan.html
benötigt ActiveX --> IE ,
d.h. du mußt dafür Active X evtl. freigeben unter Interneteinstellungen.
Report vollständig posten.
Arbeitsplatz -> rechter Mausklick -->Windows Explorer -> "Extras/Ordneroptionen" ->
"Ansicht" -> Haken entfernen bei "Geschützte Systemdateien
ausblenden (empfohlen)" und "Alle Dateien und Ordner anzeigen"
aktivieren -> "OK"
abgesicherter Modus starten
lösche direkt
C:\WINDOWS\system32\actskn45.ocx
C:\Dokumente und Einstellungen\Jörgel\Eigene Dateien\Bearbeitungstools\Nero-7.8.5.0_deu_update.exe[Toolbar.exe]
weiter im abgesicherten Modus
start-ausführen: regedit
navigiere zu den Funden und lösche
00035917 adware/ist.sidefind Adware No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10E42047-DEB9-4535-A118-B3F6EC39B807}
00042191 adware/ist.yoursitebar Adware No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{86227D9C-0EFE-4F8A-AA55-30386A3F5686}
Neustart Normalstart
Onlinescan vom gesamten System:
http://www.kaspersky.com/kos/german/par ... bscan.html
benötigt ActiveX --> IE ,
d.h. du mußt dafür Active X evtl. freigeben unter Interneteinstellungen.
Report vollständig posten.
- Humdinger
- Mitarbeiter
- Beiträge: 896
- Registriert: 22.03.2006, 14:22
- Wohnort: Mainz