Warum kostenlos registrieren?

Nur als registriertes Mitglied hast Du vollen Zugriff auf alle Funktionen unserer Website. So kannst Du eigene Fragen stellen und hast die volle Übersicht über neue interessante Themen im Forum.
Jetzt kostenlos registrieren.

Login


Explorer.exe verursacht 100% CPU Auslastung

Warnungen vor Sicherheitslücken und Hilfe beim Enfernen von Viren, Würmern und Trojanern.

Explorer.exe verursacht 100% CPU Auslastung

Beitragvon JW1 am 11.07.2007, 14:12

Hallo,

folgendes Problem: Explorer.Exe verursacht 100% CPU Auslastung beim Öffnen vom Ordner Eigene Datein. Wer kann mir dabei helfen, habe schon rumgegoogelt ohne Ende aber noch nicht das Richtige gefunden. Füge mein Hijack.log bei.

Danke.

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 13:53:12, on 11.07.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\cisvc.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkUFind.exe
C:\Programme\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe
C:\Programme\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
C:\Programme\QuickTime\qttask.exe
C:\Programme\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\carpserv.exe
C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programme\Microsoft IntelliType Pro\itype.exe
C:\Programme\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\Spamihilator\spamihilator.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe
C:\Programme\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Spybot - Search & Destroy\TeaTimer.exe
C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexingService.exe
C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexStoreSvr.exe
C:\Dokumente und Einstellungen\Jörgel\Eigene Dateien\HiJackThis_v2.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.t-online.de/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.t-online.de
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.t-online.de
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer bereitgestellt von T-Online
O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programme\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [PMCS] C:\Programme\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe -host -clearDebug
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [PMCRemote] C:\Programme\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programme\Gemeinsame Dateien\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [avgnt] "C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [itype] "c:\Programme\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Programme\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Programme\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Spamihilator] "C:\Programme\Spamihilator\spamihilator.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [swg] C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/german/par ... nicode.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/house ... hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/Shar ... vSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.c ... 040510.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.johannrain-softwareentwicklu ... oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 4826135370
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 4826469182
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan ... asinst.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsup ... mAData.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsup ... veData.cab
O16 - DPF: {F7DC2A2E-FC34-11D3-B1D9-00A0C99B41BB} (Zoom Class) - http://www.zoomify.com/download/zoomify305.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: AntiVir PersonalEdition Classic Planer (AntiVirScheduler) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Pinnacle Systems tvtv Spooler (EpgSpooler) - - c:\progra~1\pinnacle\mediac~1\epgspo~2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Programme\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - c:\programme\pinnacle\shared files\programs\mediaserver\pmshost.exe
O24 - Desktop Component 1: (no name) - http://speedmanager.t-com-dsl.de/

--
End of file - 10688 bytes


Für die Hilfe schonmal ein Danke vorweg.

Gruß JW1
JW1
 
Beiträge: 11
Registriert: 11.07.2007, 13:04
Wohnort: im Norden


Beitragvon Humdinger am 11.07.2007, 17:40

öffne das HijackThis -- Button "scan" -- vor diese Einträge ein Häkchen setzen -- Button "Fix checked" anklicken – PC nun neustarten

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
O16 - DPF: {F7DC2A2E-FC34-11D3-B1D9-00A0C99B41BB} (Zoom Class) - http://www.zoomify.com/download/zoomify305.cab

Counterspy V2 anwenden
http://research.sunbelt-software.com/download.aspx

* Installation

* CounterSpywird geupdatet

Nicht Scannen.

Neustart F8 drücken, abgesicherter Modus starten

im abgesicherten Modus:

Counterspy starten

* Klicke: "Run a Spyware Scan Now"

* nach dem Scan muss man sich entscheiden für:

*Ignore
*Remove --> Status: Deleted
*Quarantaine

wähle immer Remove und starte den PC neu

Nach Neustart in Normalmodus

poste das log von Counterspy

Hinweis:
Scanreport finden:
klicke : View details

diesen Report kann man abkopieren: [mit der linken Maus-Taste über den Text fahren -> rechte Maustaste -> kopieren -> hier im Thread -> rechte Maustaste -> einfügen]
Humdinger
Mitarbeiter
 
Beiträge: 896
Registriert: 22.03.2006, 14:22
Wohnort: Mainz

Beitragvon JW1 am 11.07.2007, 19:14

Hallo,

danke für die Tips. Habe bis CounterSpy Update alles befolgt. Jetzt das große Problem. Mein PC will nicht in den abgesicherten Modus gehen. Muss das unbedingt sein? Oder geht der Scan auch im Normalmodus?

Gruß JW1
JW1
 
Beiträge: 11
Registriert: 11.07.2007, 13:04
Wohnort: im Norden

Beitragvon Humdinger am 11.07.2007, 19:28

scan im Normalmodus, wähle immer REMOVE, poste den REport

und auch einen neuen HijackThis log
Humdinger
Mitarbeiter
 
Beiträge: 896
Registriert: 22.03.2006, 14:22
Wohnort: Mainz

Beitragvon JW1 am 12.07.2007, 08:25

Hallo,

nachstehend den Report von CounterSpy:

[code]
Scan History Details
Start Date: 11.07.2007 20:47:35
End Date: 11.07.2007 22:11:56
Total Time: 84 Min 21 Sec
Detected security risks

BearShare P2P Program more information...
Details: BearShare is a peer-to-peer (P2P) application that allows its users to join together in a network via the Internet and share files from each other's hard drives.
Status: Deleted

Registry entries detected
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\AuxUserType
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\AuxUserType
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\AuxUserType\2
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\AuxUserType\2
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\AuxUserType\3
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\AuxUserType\3
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion\Readable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion\Readable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion\Readable\Main
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion\Readable\Main
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion\Readwritable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion\Readwritable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion\Readwritable\Main
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Conversion\Readwritable\Main
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\DefaultFile
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\DefaultFile
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\0
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\0
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\1
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\1
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\2
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\2
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\3
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\3
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\4
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DataFormats\GetSet\4
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DefaultExtension
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DefaultExtension
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DefaultIcon
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DefaultIcon
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DocObject
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\DocObject
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Implemented Categories
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Implemented Categories
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Implemented Categories\{000C0118-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Implemented Categories\{000C0118-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\InprocHandler32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\InprocHandler32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Insertable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Insertable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\MiscStatus
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\MiscStatus
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\OfficeCompliant
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\OfficeCompliant
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\PersistentHandler
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\PersistentHandler
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Printable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Printable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\ProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\ProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Typelib
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Typelib
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Verb
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Verb
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Verb\0
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Verb\0
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Verb\1
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Verb\1
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Version
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\Version
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\ACTIVE SETUP\INSTALLED COMPONENTS\{5F95E1AF-2620-4F15-BDF9-7FDCE4607E17}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\ACTIVE SETUP\INSTALLED COMPONENTS\{5F95E1AF-2620-4F15-BDF9-7FDCE4607E17}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\ACTIVE SETUP\INSTALLED COMPONENTS\{5F95E1AF-2620-4F15-BDF9-7FDCE4607E17}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\ACTIVE SETUP\INSTALLED COMPONENTS\{5F95E1AF-2620-4F15-BDF9-7FDCE4607E17}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\ACTIVE SETUP\INSTALLED COMPONENTS\{5F95E1AF-2620-4F15-BDF9-7FDCE4607E17}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\ACTIVE SETUP\INSTALLED COMPONENTS\{5F95E1AF-2620-4F15-BDF9-7FDCE4607E17}
HKEY_USERS\S-1-5-21-2760978244-3742667488-1603439836-1005\APPEVENTS\EVENTLABELS\BEARSHARECHATNOTIFYMSG
HKEY_USERS\S-1-5-21-2760978244-3742667488-1603439836-1005\APPEVENTS\EVENTLABELS\BEARSHARECHATNOTIFYMSG
HKEY_USERS\S-1-5-21-2760978244-3742667488-1603439836-1005\APPEVENTS\SCHEMES\APPS\BEARSHARE
HKEY_USERS\S-1-5-21-2760978244-3742667488-1603439836-1005\APPEVENTS\SCHEMES\APPS\BEARSHARE
HKEY_USERS\S-1-5-21-2760978244-3742667488-1603439836-1005\APPEVENTS\SCHEMES\APPS\BEARSHARE\BearShareChatNotifyMsg
HKEY_USERS\S-1-5-21-2760978244-3742667488-1603439836-1005\APPEVENTS\SCHEMES\APPS\BEARSHARE\BearShareChatNotifyMsg
HKEY_USERS\S-1-5-21-2760978244-3742667488-1603439836-1005\APPEVENTS\SCHEMES\APPS\BEARSHARE\BearShareChatNotifyMsg\.Current


Invisible Keylogger Commercial Key Logger more information...
Status: Deleted

Files detected
C:\WINDOWS\WINDOWS\Thumbs.db:encryptable
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\expsrv.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msexch40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msexcl40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msjet40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msjetol1.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msjetoledb40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msjtes40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msltus40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\mspbde40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msrd2x40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msrepl40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\mstext40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\msxbde40.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\spuninst\spuninst.bat
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB282010$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\6to4svc.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\iphlpapi.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\ipv6.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\ipv6mon.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\netip6.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\netoc.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\netoc.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB817778$\wship6.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB820291$\appwiz.cpl
C:\WINDOWS\WINDOWS\$NtUninstallKB820291$\explorer.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB820291$\shmgrate.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB820291$\spuninst\spuninst.bat
C:\WINDOWS\WINDOWS\$NtUninstallKB820291$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB820291$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB821253$\dwwin.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB821253$\faultrep.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB821253$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB821253$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB821557$\shell32.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB821557$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB821557$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB822603$\hccoin.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB822603$\spuninst\spuninst.bat
C:\WINDOWS\WINDOWS\$NtUninstallKB822603$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB822603$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB823559$\html32.cnv
C:\WINDOWS\WINDOWS\$NtUninstallKB823559$\spuninst\spuninst.bat
C:\WINDOWS\WINDOWS\$NtUninstallKB823559$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB823559$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB823980$\ole32.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB823980$\rpcrt4.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB823980$\rpcss.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB823980$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB823980$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB824105$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB824105$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallKB824146$\ole32.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB824146$\rpcrt4.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB824146$\rpcss.dll
C:\WINDOWS\WINDOWS\$NtUninstallKB824146$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallKB824146$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ322011$\fxsclnt.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ322011$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ322011$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ327979$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ327979$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ328310$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ328310$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ328310$\sysmain.sdb
C:\WINDOWS\WINDOWS\$NtUninstallQ328310$\user32.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ328310$\win32k.sys
C:\WINDOWS\WINDOWS\$NtUninstallQ328310$\winsrv.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ329048$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ329048$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ329048$\zipfldr.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ329115$\crypt32.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ329115$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ329115$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ329170$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ329170$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ329390$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ329390$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ329441$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ329441$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ329441$\srrstr.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ329834$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ329834$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\hhctrl.ocx
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\hhsetup.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\itircl.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\itss.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\migwiz.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\osk.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\pchshell.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\spuninst\spuninst.bat
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ810565$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ810577$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ810577$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ810833$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ810833$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ811493$\ntkrnlpa.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ811493$\ntoskrnl.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ811493$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ811493$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ814033$\newdev.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ814033$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ814033$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ814995$\acgenral.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ814995$\apph_sp.sdb
C:\WINDOWS\WINDOWS\$NtUninstallQ814995$\apphelp.sdb
C:\WINDOWS\WINDOWS\$NtUninstallQ814995$\apps.chm
C:\WINDOWS\WINDOWS\$NtUninstallQ814995$\apps_sp.chm
C:\WINDOWS\WINDOWS\$NtUninstallQ814995$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ814995$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ814995$\sysmain.sdb
C:\WINDOWS\WINDOWS\$NtUninstallQ815021$\ntdll.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ815021$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ815021$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ815485$\netshell.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ815485$\reg00003
C:\WINDOWS\WINDOWS\$NtUninstallQ815485$\spuninst\spuninst.bat
C:\WINDOWS\WINDOWS\$NtUninstallQ815485$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ815485$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\$NtUninstallQ815485$\wzcdlg.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ815485$\wzcsapi.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ815485$\wzcsvc.dll
C:\WINDOWS\WINDOWS\$NtUninstallQ817606$\spuninst\spuninst.exe
C:\WINDOWS\WINDOWS\$NtUninstallQ817606$\spuninst\spuninst.inf
C:\WINDOWS\WINDOWS\Angler.bmp
C:\WINDOWS\WINDOWS\AppPatch\acgenral.dll
C:\WINDOWS\WINDOWS\AppPatch\AcLayers.dll
C:\WINDOWS\WINDOWS\AppPatch\AcLua.dll
C:\WINDOWS\WINDOWS\AppPatch\AcSpecfc.dll
C:\WINDOWS\WINDOWS\AppPatch\AcVerfyr.dll
C:\WINDOWS\WINDOWS\AppPatch\AcXtrnal.dll
C:\WINDOWS\WINDOWS\AppPatch\apph_sp.sdb
C:\WINDOWS\WINDOWS\AppPatch\apphelp.sdb
C:\WINDOWS\WINDOWS\AppPatch\drvmain.sdb
C:\WINDOWS\WINDOWS\AppPatch\msimain.sdb
C:\WINDOWS\WINDOWS\AppPatch\sysmain.sdb
C:\WINDOWS\WINDOWS\Blaue Spitzen 16.bmp
C:\WINDOWS\WINDOWS\bootstat.dat
C:\WINDOWS\WINDOWS\clock.avi
C:\WINDOWS\WINDOWS\control.ini
C:\WINDOWS\WINDOWS\Cursors\3dgarro.cur
C:\WINDOWS\WINDOWS\Cursors\3dgmove.cur
C:\WINDOWS\WINDOWS\Cursors\3dgnesw.cur
C:\WINDOWS\WINDOWS\Cursors\3dgno.cur
C:\WINDOWS\WINDOWS\Cursors\3dgns.cur
C:\WINDOWS\WINDOWS\Cursors\3dgnwse.cur
C:\WINDOWS\WINDOWS\Cursors\3dgwe.cur
C:\WINDOWS\WINDOWS\Cursors\3dsmove.cur
C:\WINDOWS\WINDOWS\Cursors\3dsns.cur
C:\WINDOWS\WINDOWS\Cursors\3dsnwse.cur
C:\WINDOWS\WINDOWS\Cursors\3dwarro.cur
C:\WINDOWS\WINDOWS\Cursors\3dwmove.cur
C:\WINDOWS\WINDOWS\Cursors\3dwnesw.cur
C:\WINDOWS\WINDOWS\Cursors\3dwno.cur
C:\WINDOWS\WINDOWS\Cursors\3dwns.cur
C:\WINDOWS\WINDOWS\Cursors\3dwnwse.cur
C:\WINDOWS\WINDOWS\Cursors\3dwwe.cur
C:\WINDOWS\WINDOWS\Cursors\appstar2.ani
C:\WINDOWS\WINDOWS\Cursors\appstar3.ani
C:\WINDOWS\WINDOWS\Cursors\appstart.ani
C:\WINDOWS\WINDOWS\Cursors\arrow_i.cur
C:\WINDOWS\WINDOWS\Cursors\arrow_il.cur
C:\WINDOWS\WINDOWS\Cursors\arrow_im.cur
C:\WINDOWS\WINDOWS\Cursors\arrow_l.cur
C:\WINDOWS\WINDOWS\Cursors\arrow_m.cur
C:\WINDOWS\WINDOWS\Cursors\arrow_r.cur
C:\WINDOWS\WINDOWS\Cursors\arrow_rl.cur
C:\WINDOWS\WINDOWS\Cursors\arrow_rm.cur
C:\WINDOWS\WINDOWS\Cursors\banana.ani
C:\WINDOWS\WINDOWS\Cursors\barber.ani
C:\WINDOWS\WINDOWS\Cursors\beam_i.cur
C:\WINDOWS\WINDOWS\Cursors\beam_il.cur
C:\WINDOWS\WINDOWS\Cursors\beam_im.cur
C:\WINDOWS\WINDOWS\Cursors\beam_l.cur
C:\WINDOWS\WINDOWS\Cursors\beam_m.cur
C:\WINDOWS\WINDOWS\Cursors\beam_r.cur
C:\WINDOWS\WINDOWS\Cursors\beam_rl.cur
C:\WINDOWS\WINDOWS\Cursors\beam_rm.cur
C:\WINDOWS\WINDOWS\Cursors\busy_i.cur
C:\WINDOWS\WINDOWS\Cursors\busy_il.cur
C:\WINDOWS\WINDOWS\Cursors\busy_im.cur
C:\WINDOWS\WINDOWS\Cursors\busy_l.cur
C:\WINDOWS\WINDOWS\Cursors\busy_m.cur
C:\WINDOWS\WINDOWS\Cursors\busy_r.cur
C:\WINDOWS\WINDOWS\Cursors\busy_rl.cur
C:\WINDOWS\WINDOWS\Cursors\busy_rm.cur
C:\WINDOWS\WINDOWS\Cursors\coin.ani
C:\WINDOWS\WINDOWS\Cursors\counter.ani
C:\WINDOWS\WINDOWS\Cursors\cross.cur
C:\WINDOWS\WINDOWS\Cursors\cross_i.cur
C:\WINDOWS\WINDOWS\Cursors\cross_il.cur
C:\WINDOWS\WINDOWS\Cursors\cross_im.cur
C:\WINDOWS\WINDOWS\Cursors\cross_l.cur
C:\WINDOWS\WINDOWS\Cursors\cross_m.cur
C:\WINDOWS\WINDOWS\Cursors\cross_r.cur
C:\WINDOWS\WINDOWS\Cursors\cross_rl.cur
C:\WINDOWS\WINDOWS\Cursors\cross_rm.cur
C:\WINDOWS\WINDOWS\Cursors\dinosau2.ani
C:\WINDOWS\WINDOWS\Cursors\dinosaur.ani
C:\WINDOWS\WINDOWS\Cursors\drum.ani
C:\WINDOWS\WINDOWS\Cursors\fillitup.ani
C:\WINDOWS\WINDOWS\Cursors\hand.ani
C:\WINDOWS\WINDOWS\Cursors\handapst.ani
C:\WINDOWS\WINDOWS\Cursors\handnesw.ani
C:\WINDOWS\WINDOWS\Cursors\handno.ani
C:\WINDOWS\WINDOWS\Cursors\handns.ani
C:\WINDOWS\WINDOWS\Cursors\handnwse.ani
C:\WINDOWS\WINDOWS\Cursors\handwait.ani
C:\WINDOWS\WINDOWS\Cursors\handwe.ani
C:\WINDOWS\WINDOWS\Cursors\harrow.cur
C:\WINDOWS\WINDOWS\Cursors\hcross.cur
C:\WINDOWS\WINDOWS\Cursors\help_i.cur
C:\WINDOWS\WINDOWS\Cursors\help_il.cur
C:\WINDOWS\WINDOWS\Cursors\help_im.cur
C:\WINDOWS\WINDOWS\Cursors\help_l.cur
C:\WINDOWS\WINDOWS\Cursors\help_m.cur
C:\WINDOWS\WINDOWS\Cursors\help_r.cur
C:\WINDOWS\WINDOWS\Cursors\help_rl.cur
C:\WINDOWS\WINDOWS\Cursors\help_rm.cur
C:\WINDOWS\WINDOWS\Cursors\hibeam.cur
C:\WINDOWS\WINDOWS\Cursors\hmove.cur
C:\WINDOWS\WINDOWS\Cursors\hnesw.cur
C:\WINDOWS\WINDOWS\Cursors\hnodrop.cur
C:\WINDOWS\WINDOWS\Cursors\hns.cur
C:\WINDOWS\WINDOWS\Cursors\hnwse.cur
C:\WINDOWS\WINDOWS\Cursors\horse.ani
C:\WINDOWS\WINDOWS\Cursors\hourgla2.ani
C:\WINDOWS\WINDOWS\Cursors\hourgla3.ani
C:\WINDOWS\WINDOWS\Cursors\hourglas.ani
C:\WINDOWS\WINDOWS\Cursors\hwe.cur
C:\WINDOWS\WINDOWS\Cursors\lappstrt.cur
C:\WINDOWS\WINDOWS\Cursors\larrow.cur
C:\WINDOWS\WINDOWS\Cursors\lcross.cur
C:\WINDOWS\WINDOWS\Cursors\libeam.cur
C:\WINDOWS\WINDOWS\Cursors\lmove.cur
C:\WINDOWS\WINDOWS\Cursors\lnesw.cur
C:\WINDOWS\WINDOWS\Cursors\lnodrop.cur
C:\WINDOWS\WINDOWS\Cursors\lns.cur
C:\WINDOWS\WINDOWS\Cursors\lnwse.cur
C:\WINDOWS\WINDOWS\Cursors\lwait.cur
C:\WINDOWS\WINDOWS\Cursors\lwe.cur
C:\WINDOWS\WINDOWS\Cursors\metronom.ani
C:\WINDOWS\WINDOWS\Cursors\move_i.cur
C:\WINDOWS\WINDOWS\Cursors\move_il.cur
C:\WINDOWS\WINDOWS\Cursors\move_im.cur
C:\WINDOWS\WINDOWS\Cursors\move_l.cur
C:\WINDOWS\WINDOWS\Cursors\move_m.cur
C:\WINDOWS\WINDOWS\Cursors\move_r.cur
C:\WINDOWS\WINDOWS\Cursors\move_rl.cur
C:\WINDOWS\WINDOWS\Cursors\move_rm.cur
C:\WINDOWS\WINDOWS\Cursors\no_i.cur
C:\WINDOWS\WINDOWS\Cursors\no_il.cur
C:\WINDOWS\WINDOWS\Cursors\no_im.cur
C:\WINDOWS\WINDOWS\Cursors\no_l.cur
C:\WINDOWS\WINDOWS\Cursors\no_m.cur
C:\WINDOWS\WINDOWS\Cursors\no_r.cur
C:\WINDOWS\WINDOWS\Cursors\no_rl.cur
C:\WINDOWS\WINDOWS\Cursors\no_rm.cur
C:\WINDOWS\WINDOWS\Cursors\pen_i.cur
C:\WINDOWS\WINDOWS\Cursors\pen_il.cur
C:\WINDOWS\WINDOWS\Cursors\pen_im.cur
C:\WINDOWS\WINDOWS\Cursors\pen_l.cur
C:\WINDOWS\WINDOWS\Cursors\pen_m.cur
C:\WINDOWS\WINDOWS\Cursors\pen_r.cur
C:\WINDOWS\WINDOWS\Cursors\pen_rl.cur
C:\WINDOWS\WINDOWS\Cursors\pen_rm.cur
C:\WINDOWS\WINDOWS\Cursors\piano.ani
C:\WINDOWS\WINDOWS\Cursors\rainbow.ani
C:\WINDOWS\WINDOWS\Cursors\raindrop.ani
C:\WINDOWS\WINDOWS\Cursors\size1_i.cur
C:\WINDOWS\WINDOWS\Cursors\size1_il.cur
C:\WINDOWS\WINDOWS\Cursors\size1_im.cur
C:\WINDOWS\WINDOWS\Cursors\size1_l.cur
C:\WINDOWS\WINDOWS\Cursors\size1_m.cur
C:\WINDOWS\WINDOWS\Cursors\size1_r.cur
C:\WINDOWS\WINDOWS\Cursors\size1_rl.cur
C:\WINDOWS\WINDOWS\Cursors\size1_rm.cur
C:\WINDOWS\WINDOWS\Cursors\size2_i.cur
C:\WINDOWS\WINDOWS\Cursors\size2_il.cur
C:\WINDOWS\WINDOWS\Cursors\size2_im.cur
C:\WINDOWS\WINDOWS\Cursors\size2_l.cur
C:\WINDOWS\WINDOWS\Cursors\size2_m.cur
C:\WINDOWS\WINDOWS\Cursors\size2_r.cur
C:\WINDOWS\WINDOWS\Cursors\size2_rl.cur
C:\WINDOWS\WINDOWS\Cursors\size2_rm.cur
C:\WINDOWS\WINDOWS\Cursors\size3_i.cur
C:\WINDOWS\WINDOWS\Cursors\size3_il.cur
C:\WINDOWS\WINDOWS\Cursors\size3_im.cur
C:\WINDOWS\WINDOWS\Cursors\size3_l.cur
C:\WINDOWS\WINDOWS\Cursors\size3_m.cur
C:\WINDOWS\WINDOWS\Cursors\size3_r.cur
C:\WINDOWS\WINDOWS\Cursors\size3_rl.cur
C:\WINDOWS\WINDOWS\Cursors\size3_rm.cur
C:\WINDOWS\WINDOWS\Cursors\size4_i.cur
C:\WINDOWS\WINDOWS\Cursors\size4_il.cur
C:\WINDOWS\WINDOWS\Cursors\size4_im.cur
C:\WINDOWS\WINDOWS\Cursors\size4_l.cur
C:\WINDOWS\WINDOWS\Cursors\size4_m.cur
C:\WINDOWS\WINDOWS\Cursors\size4_r.cur
C:\WINDOWS\WINDOWS\Cursors\size4_rl.cur
C:\WINDOWS\WINDOWS\Cursors\size4_rm.cur
C:\WINDOWS\WINDOWS\Cursors\sizenesw.ani
C:\WINDOWS\WINDOWS\Cursors\sizens.ani
C:\WINDOWS\WINDOWS\Cursors\sizenwse.ani
C:\WINDOWS\WINDOWS\Cursors\sizewe.ani
C:\WINDOWS\WINDOWS\Cursors\stopwtch.ani
C:\WINDOWS\WINDOWS\Cursors\up_i.cur
C:\WINDOWS\WINDOWS\Cursors\up_il.cur
C:\WINDOWS\WINDOWS\Cursors\up_im.cur
C:\WINDOWS\WINDOWS\Cursors\up_l.cur
C:\WINDOWS\WINDOWS\Cursors\up_m.cur
C:\WINDOWS\WINDOWS\Cursors\up_r.cur
C:\WINDOWS\WINDOWS\Cursors\up_rl.cur
C:\WINDOWS\WINDOWS\Cursors\up_rm.cur
C:\WINDOWS\WINDOWS\Cursors\vanisher.ani
C:\WINDOWS\WINDOWS\Cursors\wagtail.ani
C:\WINDOWS\WINDOWS\Cursors\wait_i.cur
C:\WINDOWS\WINDOWS\Cursors\wait_il.cur
C:\WINDOWS\WINDOWS\Cursors\wait_im.cur
C:\WINDOWS\WINDOWS\Cursors\wait_l.cur
C:\WINDOWS\WINDOWS\Cursors\wait_m.cur
C:\WINDOWS\WINDOWS\Cursors\wait_r.cur
C:\WINDOWS\WINDOWS\Cursors\wait_rl.cur
C:\WINDOWS\WINDOWS\Cursors\wait_rm.cur
C:\WINDOWS\WINDOWS\Debug\oakley.log
C:\WINDOWS\WINDOWS\Debug\PASSWD.LOG
C:\WINDOWS\WINDOWS\Downloaded Program Files\desktop.ini
C:\WINDOWS\WINDOWS\Driver Cache\i386\bdaplgin.ax
C:\WINDOWS\WINDOWS\Driver Cache\i386\driver.cab
C:\WINDOWS\WINDOWS\Driver Cache\i386\explorer.exe
C:\WINDOWS\WINDOWS\Driver Cache\i386\ipsink.ax
C:\WINDOWS\WINDOWS\Driver Cache\i386\ksolay.ax
C:\WINDOWS\WINDOWS\Driver Cache\i386\ksproxy.ax
C:\WINDOWS\WINDOWS\Driver Cache\i386\kstvtune.ax
C:\WINDOWS\WINDOWS\Driver Cache\i386\kswdmcap.ax
C:\WINDOWS\WINDOWS\Driver Cache\i386\ksxbar.ax
C:\WINDOWS\WINDOWS\Driver Cache\i386\msdvbnp.ax
C:\WINDOWS\WINDOWS\Driver Cache\i386\ndis.sys
C:\WINDOWS\WINDOWS\Driver Cache\i386\ndisuio.sys
C:\WINDOWS\WINDOWS\Driver Cache\i386\ntkrnlmp.exe
C:\WINDOWS\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
C:\WINDOWS\WINDOWS\Driver Cache\i386\ntkrpamp.exe
C:\WINDOWS\WINDOWS\Driver Cache\i386\ntoskrnl.exe
C:\WINDOWS\WINDOWS\Driver Cache\i386\psisrndr.ax
C:\WINDOWS\WINDOWS\Driver Cache\i386\sp1.cab
C:\WINDOWS\WINDOWS\explorer.exe
C:\WINDOWS\WINDOWS\explorer.scf
C:\WINDOWS\WINDOWS\Feder.bmp
C:\WINDOWS\WINDOWS\Fonts\8514fix.fon
C:\WINDOWS\WINDOWS\Fonts\8514fixe.fon
C:\WINDOWS\WINDOWS\Fonts\8514fixg.fon
C:\WINDOWS\WINDOWS\Fonts\8514fixr.fon
C:\WINDOWS\WINDOWS\Fonts\8514fixt.fon
C:\WINDOWS\WINDOWS\Fonts\8514oem.fon
C:\WINDOWS\WINDOWS\Fonts\8514oeme.fon
C:\WINDOWS\WINDOWS\Fonts\8514oemg.fon
C:\WINDOWS\WINDOWS\Fonts\8514oemr.fon
C:\WINDOWS\WINDOWS\Fonts\8514oemt.fon
C:\WINDOWS\WINDOWS\Fonts\8514sys.fon
C:\WINDOWS\WINDOWS\Fonts\8514syse.fon
C:\WINDOWS\WINDOWS\Fonts\8514sysg.fon
C:\WINDOWS\WINDOWS\Fonts\8514sysr.fon
C:\WINDOWS\WINDOWS\Fonts\8514syst.fon
C:\WINDOWS\WINDOWS\Fonts\85775.fon
C:\WINDOWS\WINDOWS\Fonts\85855.fon
C:\WINDOWS\WINDOWS\Fonts\85f1257.fon
C:\WINDOWS\WINDOWS\Fonts\85s1257.fon
C:\WINDOWS\WINDOWS\Fonts\ABAC.TTF
C:\WINDOWS\WINDOWS\Fonts\ABAEXBC.TTF
C:\WINDOWS\WINDOWS\Fonts\ABALC.TTF
C:\WINDOWS\WINDOWS\Fonts\Absalom_.TTF
C:\WINDOWS\WINDOWS\Fonts\AgencyB.TTF
C:\WINDOWS\WINDOWS\Fonts\AgencyR.TTF
C:\WINDOWS\WINDOWS\Fonts\ALGER.TTF
C:\WINDOWS\WINDOWS\Fonts\Alibi___.TTF
C:\WINDOWS\WINDOWS\Fonts\Andyb.TTF
C:\WINDOWS\WINDOWS\Fonts\ANTQUAB.TTF
C:\WINDOWS\WINDOWS\Fonts\ANTQUABI.TTF
C:\WINDOWS\WINDOWS\Fonts\ANTQUAI.TTF
C:\WINDOWS\WINDOWS\Fonts\app775.fon
C:\WINDOWS\WINDOWS\Fonts\app850.fon
C:\WINDOWS\WINDOWS\Fonts\app852.fon
C:\WINDOWS\WINDOWS\Fonts\app855.fon
C:\WINDOWS\WINDOWS\Fonts\app857.fon
C:\WINDOWS\WINDOWS\Fonts\app866.fon
C:\WINDOWS\WINDOWS\Fonts\ARBLI___.TTF
C:\WINDOWS\WINDOWS\Fonts\arial.ttf
C:\WINDOWS\WINDOWS\Fonts\arialbd.ttf
C:\WINDOWS\WINDOWS\Fonts\arialbi.ttf
C:\WINDOWS\WINDOWS\Fonts\ariali.ttf
C:\WINDOWS\WINDOWS\Fonts\arialn.ttf
C:\WINDOWS\WINDOWS\Fonts\ArialNb.TTF
C:\WINDOWS\WINDOWS\Fonts\ArialNbi.TTF
C:\WINDOWS\WINDOWS\Fonts\ArialNi.TTF
C:\WINDOWS\WINDOWS\Fonts\ariblk.ttf
C:\WINDOWS\WINDOWS\Fonts\ARLRDBD.TTF
C:\WINDOWS\WINDOWS\Fonts\BASKVILL.TTF
C:\WINDOWS\WINDOWS\Fonts\Batavia_.TTF
C:\WINDOWS\WINDOWS\Fonts\BAUHS93.TTF
C:\WINDOWS\WINDOWS\Fonts\Beesknee.ttf
C:\WINDOWS\WINDOWS\Fonts\BERNHC.TTF
C:\WINDOWS\WINDOWS\Fonts\BicklySc.ttf
C:\WINDOWS\WINDOWS\Fonts\BKANT.TTF
C:\WINDOWS\WINDOWS\Fonts\BOOKOS.TTF
C:\WINDOWS\WINDOWS\Fonts\BOOKOSB.TTF
C:\WINDOWS\WINDOWS\Fonts\BOOKOSBI.TTF
C:\WINDOWS\WINDOWS\Fonts\BOOKOSI.TTF
C:\WINDOWS\WINDOWS\Fonts\BradhITC.TTF
C:\WINDOWS\WINDOWS\Fonts\BRAGGA.TTF
C:\WINDOWS\WINDOWS\Fonts\BRITANIC.TTF
C:\WINDOWS\WINDOWS\Fonts\BROADW.TTF
C:\WINDOWS\WINDOWS\Fonts\BRUSHSCI.TTF
C:\WINDOWS\WINDOWS\Fonts\CALIST.TTF
C:\WINDOWS\WINDOWS\Fonts\CALISTB.TTF
C:\WINDOWS\WINDOWS\Fonts\CALISTBI.TTF
C:\WINDOWS\WINDOWS\Fonts\CALISTI.TTF
C:\WINDOWS\WINDOWS\Fonts\casmira_.TTF
C:\WINDOWS\WINDOWS\Fonts\CASTELAR.TTF
C:\WINDOWS\WINDOWS\Fonts\cga40737.fon
C:\WINDOWS\WINDOWS\Fonts\cga40850.fon
C:\WINDOWS\WINDOWS\Fonts\cga40852.fon
C:\WINDOWS\WINDOWS\Fonts\cga40857.fon
C:\WINDOWS\WINDOWS\Fonts\cga40866.fon
C:\WINDOWS\WINDOWS\Fonts\cga40869.fon
C:\WINDOWS\WINDOWS\Fonts\cga40woa.fon
C:\WINDOWS\WINDOWS\Fonts\cga80737.fon
C:\WINDOWS\WINDOWS\Fonts\cga80850.fon
C:\WINDOWS\WINDOWS\Fonts\cga80852.fon
C:\WINDOWS\WINDOWS\Fonts\cga80857.fon
C:\WINDOWS\WINDOWS\Fonts\cga80866.fon
C:\WINDOWS\WINDOWS\Fonts\cga80869.fon
C:\WINDOWS\WINDOWS\Fonts\cga80woa.fon
C:\WINDOWS\WINDOWS\Fonts\Chiller.ttf
C:\WINDOWS\WINDOWS\Fonts\comic.ttf
C:\WINDOWS\WINDOWS\Fonts\comicbd.ttf
C:\WINDOWS\WINDOWS\Fonts\COOPBL.TTF
C:\WINDOWS\WINDOWS\Fonts\Coprgtb.TTF
C:\WINDOWS\WINDOWS\Fonts\Coprgtl.TTF
C:\WINDOWS\WINDOWS\Fonts\coue1257.fon
C:\WINDOWS\WINDOWS\Fonts\couf1257.fon
C:\WINDOWS\WINDOWS\Fonts\cour.ttf
C:\WINDOWS\WINDOWS\Fonts\courbd.ttf
C:\WINDOWS\WINDOWS\Fonts\courbi.ttf
C:\WINDOWS\WINDOWS\Fonts\coure.fon
C:\WINDOWS\WINDOWS\Fonts\couree.fon
C:\WINDOWS\WINDOWS\Fonts\coureg.fon
C:\WINDOWS\WINDOWS\Fonts\courer.fon
C:\WINDOWS\WINDOWS\Fonts\couret.fon
C:\WINDOWS\WINDOWS\Fonts\courf.fon
C:\WINDOWS\WINDOWS\Fonts\courfe.fon
C:\WINDOWS\WINDOWS\Fonts\courfg.fon
C:\WINDOWS\WINDOWS\Fonts\courfr.fon
C:\WINDOWS\WINDOWS\Fonts\courft.fon
C:\WINDOWS\WINDOWS\Fonts\couri.ttf
C:\WINDOWS\WINDOWS\Fonts\Curlz___.TTF
C:\WINDOWS\WINDOWS\Fonts\desktop.ini
C:\WINDOWS\WINDOWS\Fonts\dos737.fon
C:\WINDOWS\WINDOWS\Fonts\dosapp.fon
C:\WINDOWS\WINDOWS\Fonts\EDDA.TTF
C:\WINDOWS\WINDOWS\Fonts\ega40737.fon
C:\WINDOWS\WINDOWS\Fonts\ega40850.fon
C:\WINDOWS\WINDOWS\Fonts\ega40852.fon
C:\WINDOWS\WINDOWS\Fonts\ega40857.fon
C:\WINDOWS\WINDOWS\Fonts\ega40866.fon
C:\WINDOWS\WINDOWS\Fonts\ega40869.fon
C:\WINDOWS\WINDOWS\Fonts\ega40woa.fon
C:\WINDOWS\WINDOWS\Fonts\ega80737.fon
C:\WINDOWS\WINDOWS\Fonts\ega80850.fon
C:\WINDOWS\WINDOWS\Fonts\ega80852.fon
C:\WINDOWS\WINDOWS\Fonts\ega80857.fon
C:\WINDOWS\WINDOWS\Fonts\ega80866.fon
C:\WINDOWS\WINDOWS\Fonts\ega80869.fon
C:\WINDOWS\WINDOWS\Fonts\ega80woa.fon
C:\WINDOWS\WINDOWS\Fonts\Elegance.TTF
C:\WINDOWS\WINDOWS\Fonts\ELEPHNT.TTF
C:\WINDOWS\WINDOWS\Fonts\ELEPHNTI.TTF
C:\WINDOWS\WINDOWS\Fonts\Ellis___.TTF
C:\WINDOWS\WINDOWS\Fonts\Engr.TTF
C:\WINDOWS\WINDOWS\Fonts\Engrb.TTF
C:\WINDOWS\WINDOWS\Fonts\Enviro.ttf
C:\WINDOWS\WINDOWS\Fonts\Erasdemi.TTF
C:\WINDOWS\WINDOWS\Fonts\Eraslght.TTF
C:\WINDOWS\WINDOWS\Fonts\estre.ttf
C:\WINDOWS\WINDOWS\Fonts\Eurosti.TTF
C:\WINDOWS\WINDOWS\Fonts\Eurostib.TTF
C:\WINDOWS\WINDOWS\Fonts\Excess__.TTF
C:\WINDOWS\WINDOWS\Fonts\Felixti.TTF
C:\WINDOWS\WINDOWS\Fonts\FineHand.ttf
C:\WINDOWS\WINDOWS\Fonts\Frabk.TTF
C:\WINDOWS\WINDOWS\Fonts\Frabkit.TTF
C:\WINDOWS\WINDOWS\Fonts\Fradm.TTF
C:\WINDOWS\WINDOWS\Fonts\FRADMCN.TTF
C:\WINDOWS\WINDOWS\Fonts\Fradmit.TTF
C:\WINDOWS\WINDOWS\Fonts\FRAHV.TTF
C:\WINDOWS\WINDOWS\Fonts\FRAHVIT.TTF
C:\WINDOWS\WINDOWS\Fonts\framd.ttf
C:\WINDOWS\WINDOWS\Fonts\Framdcn.TTF
C:\WINDOWS\WINDOWS\Fonts\framdit.ttf
C:\WINDOWS\WINDOWS\Fonts\FreeScpt.ttf
C:\WINDOWS\WINDOWS\Fonts\Frscript.TTF
C:\WINDOWS\WINDOWS\Fonts\GARA.TTF
C:\WINDOWS\WINDOWS\Fonts\GARABD.TTF
C:\WINDOWS\WINDOWS\Fonts\GARAIT.TTF
C:\WINDOWS\WINDOWS\Fonts\gautami.ttf
C:\WINDOWS\WINDOWS\Fonts\Genuine_.TTF
C:\WINDOWS\WINDOWS\Fonts\georgia.ttf
C:\WINDOWS\WINDOWS\Fonts\georgiab.ttf
C:\WINDOWS\WINDOWS\Fonts\georgiai.ttf
C:\WINDOWS\WINDOWS\Fonts\georgiaz.ttf
C:\WINDOWS\WINDOWS\Fonts\Gigi.ttf
C:\WINDOWS\WINDOWS\Fonts\Gil_____.TTF
C:\WINDOWS\WINDOWS\Fonts\Gilb____.TTF
C:\WINDOWS\WINDOWS\Fonts\Gilbi___.TTF
C:\WINDOWS\WINDOWS\Fonts\Gilc____.TTF
C:\WINDOWS\WINDOWS\Fonts\Gilcb___.TTF
C:\WINDOWS\WINDOWS\Fonts\Gili____.TTF
C:\WINDOWS\WINDOWS\Fonts\Gilsanub.TTF
C:\WINDOWS\WINDOWS\Fonts\Gothic.TTF
C:\WINDOWS\WINDOWS\Fonts\Gothicb.TTF
C:\WINDOWS\WINDOWS\Fonts\Gothicbi.TTF
C:\WINDOWS\WINDOWS\Fonts\Gothici.TTF
C:\WINDOWS\WINDOWS\Fonts\GOUDOS.TTF
C:\WINDOWS\WINDOWS\Fonts\GOUDOSB.TTF
C:\WINDOWS\WINDOWS\Fonts\GOUDOSI.TTF
C:\WINDOWS\WINDOWS\Fonts\Goudysto.ttf
C:\WINDOWS\WINDOWS\Fonts\GRGAREF.TTF
C:\WINDOWS\WINDOWS\Fonts\HARLOWSI.TTF
C:\WINDOWS\WINDOWS\Fonts\HARNGTON.TTF
C:\WINDOWS\WINDOWS\Fonts\Helte___.TTF
C:\WINDOWS\WINDOWS\Fonts\Herman__.TTF
C:\WINDOWS\WINDOWS\Fonts\impact.ttf
C:\WINDOWS\WINDOWS\Fonts\IMPRISHA.TTF
C:\WINDOWS\WINDOWS\Fonts\InfRoman.ttf
C:\WINDOWS\WINDOWS\Fonts\Isabelle.TTF
C:\WINDOWS\WINDOWS\Fonts\ITCBlkad.TTF
C:\WINDOWS\WINDOWS\Fonts\ITCEdscr.TTF
C:\WINDOWS\WINDOWS\Fonts\ITCKrist.TTF
C:\WINDOWS\WINDOWS\Fonts\Joan____.TTF
C:\WINDOWS\WINDOWS\Fonts\Jokerman.ttf
C:\WINDOWS\WINDOWS\Fonts\JUICE___.TTF
C:\WINDOWS\WINDOWS\Fonts\Justice_.TTF
C:\WINDOWS\WINDOWS\Fonts\KINO.TTF
C:\WINDOWS\WINDOWS\Fonts\Kunstler.ttf
C:\WINDOWS\WINDOWS\Fonts\l_10646.ttf
C:\WINDOWS\WINDOWS\Fonts\latha.ttf
C:\WINDOWS\WINDOWS\Fonts\LATINWD.TTF
C:\WINDOWS\WINDOWS\Fonts\LCALLIG.TTF
C:\WINDOWS\WINDOWS\Fonts\LHANDW.TTF
C:\WINDOWS\WINDOWS\Fonts\Lsans.TTF
C:\WINDOWS\WINDOWS\Fonts\Lsansd.TTF
C:\WINDOWS\WINDOWS\Fonts\Lsansdi.TTF
C:\WINDOWS\WINDOWS\Fonts\Lsansi.TTF
C:\WINDOWS\WINDOWS\Fonts\lsansuni.ttf
C:\WINDOWS\WINDOWS\Fonts\lucon.ttf
C:\WINDOWS\WINDOWS\Fonts\Maian.TTF
C:\WINDOWS\WINDOWS\Fonts\Maiandb.TTF
C:\WINDOWS\WINDOWS\Fonts\Maiandit.TTF
C:\WINDOWS\WINDOWS\Fonts\Mandela_.TTF
C:\WINDOWS\WINDOWS\Fonts\mangal.ttf
C:\WINDOWS\WINDOWS\Fonts\marlett.ttf
C:\WINDOWS\WINDOWS\Fonts\matisse_.ttf
C:\WINDOWS\WINDOWS\Fonts\Matte___.TTF
C:\WINDOWS\WINDOWS\Fonts\MATURASC.TTF
C:\WINDOWS\WINDOWS\Fonts\Microdot.TTF
C:\WINDOWS\WINDOWS\Fonts\micross.ttf
C:\WINDOWS\WINDOWS\Fonts\Mistral.TTF
C:\WINDOWS\WINDOWS\Fonts\MOD20.TTF
C:\WINDOWS\WINDOWS\Fonts\modern.fon
C:\WINDOWS\WINDOWS\Fonts\MSREF1.TTF
C:\WINDOWS\WINDOWS\Fonts\MSREF2.TTF
C:\WINDOWS\WINDOWS\Fonts\MTCORSVA.TTF
C:\WINDOWS\WINDOWS\Fonts\mvboli.ttf
C:\WINDOWS\WINDOWS\Fonts\Natur___.TTF
C:\WINDOWS\WINDOWS\Fonts\Neolith_.TTF
C:\WINDOWS\WINDOWS\Fonts\Nina.ttf
C:\WINDOWS\WINDOWS\Fonts\Ninab.ttf
C:\WINDOWS\WINDOWS\Fonts\Ninabi.ttf
C:\WINDOWS\WINDOWS\Fonts\Ninai.ttf
C:\WINDOWS\WINDOWS\Fonts\OCRB.TTF
C:\WINDOWS\WINDOWS\Fonts\OLDENGL.TTF
C:\WINDOWS\WINDOWS\Fonts\ONYX.TTF
C:\WINDOWS\WINDOWS\Fonts\Openc___.TTF
C:\WINDOWS\WINDOWS\Fonts\pala.ttf
C:\WINDOWS\WINDOWS\Fonts\palab.ttf
C:\WINDOWS\WINDOWS\Fonts\palabi.ttf
C:\WINDOWS\WINDOWS\Fonts\palai.ttf
C:\WINDOWS\WINDOWS\Fonts\PALSCRI.TTF
C:\WINDOWS\WINDOWS\Fonts\papyrus.ttf
C:\WINDOWS\WINDOWS\Fonts\PARADE.TTF
C:\WINDOWS\WINDOWS\Fonts\PARCHM.TTF
C:\WINDOWS\WINDOWS\Fonts\PEPITA.TTF
C:\WINDOWS\WINDOWS\Fonts\Per_____.TTF
C:\WINDOWS\WINDOWS\Fonts\Perb____.TTF
C:\WINDOWS\WINDOWS\Fonts\Perbi___.TTF
C:\WINDOWS\WINDOWS\Fonts\Peri____.TTF
C:\WINDOWS\WINDOWS\Fonts\PERTIBD.TTF
C:\WINDOWS\WINDOWS\Fonts\PERTILI.TTF
C:\WINDOWS\WINDOWS\Fonts\PHONETIC.FON
C:\WINDOWS\WINDOWS\Fonts\PLACCOND.TTF
C:\WINDOWS\WINDOWS\Fonts\PLAYBILL.TTF
C:\WINDOWS\WINDOWS\Fonts\POORICH.TTF
C:\WINDOWS\WINDOWS\Fonts\Pretext_.TTF
C:\WINDOWS\WINDOWS\Fonts\Pristina.ttf
C:\WINDOWS\WINDOWS\Fonts\Puppy___.TTF
C:\WINDOWS\WINDOWS\Fonts\raavi.ttf
C:\WINDOWS\WINDOWS\Fonts\Radagund.TTF
C:\WINDOWS\WINDOWS\Fonts\Rage.ttf
C:\WINDOWS\WINDOWS\Fonts\Realv___.TTF
C:\WINDOWS\WINDOWS\Fonts\REF_ICON.FON
C:\WINDOWS\WINDOWS\Fonts\REFSAN.TTF
C:\WINDOWS\WINDOWS\Fonts\REFSANB.TTF
C:\WINDOWS\WINDOWS\Fonts\REFSANBI.TTF
C:\WINDOWS\WINDOWS\Fonts\REFSANI.TTF
C:\WINDOWS\WINDOWS\Fonts\REFSER.TTF
C:\WINDOWS\WINDOWS\Fonts\REFSERB.TTF
C:\WINDOWS\WINDOWS\Fonts\REFSERBI.TTF
C:\WINDOWS\WINDOWS\Fonts\REFSERI.TTF
C:\WINDOWS\WINDOWS\Fonts\REFSPCL.TTF
C:\WINDOWS\WINDOWS\Fonts\REFSPEC.TTF
C:\WINDOWS\WINDOWS\Fonts\ROCK.TTF
C:\WINDOWS\WINDOWS\Fonts\ROCKB.TTF
C:\WINDOWS\WINDOWS\Fonts\ROCKBI.TTF
C:\WINDOWS\WINDOWS\Fonts\Rockeb.TTF
C:\WINDOWS\WINDOWS\Fonts\ROCKI.TTF
C:\WINDOWS\WINDOWS\Fonts\roman.fon
C:\WINDOWS\WINDOWS\Fonts\RUNICCN.TTF
C:\WINDOWS\WINDOWS\Fonts\script.fon
C:\WINDOWS\WINDOWS\Fonts\SCRIPTBL.TTF
C:\WINDOWS\WINDOWS\Fonts\sere1257.fon
C:\WINDOWS\WINDOWS\Fonts\serf1257.fon
C:\WINDOWS\WINDOWS\Fonts\serife.fon
C:\WINDOWS\WINDOWS\Fonts\serifee.fon
C:\WINDOWS\WINDOWS\Fonts\serifeg.fon
C:\WINDOWS\WINDOWS\Fonts\serifer.fon
C:\WINDOWS\WINDOWS\Fonts\serifet.fon
C:\WINDOWS\WINDOWS\Fonts\seriff.fon
C:\WINDOWS\WINDOWS\Fonts\seriffe.fon
C:\WINDOWS\WINDOWS\Fonts\seriffg.fon
C:\WINDOWS\WINDOWS\Fonts\seriffr.fon
C:\WINDOWS\WINDOWS\Fonts\serifft.fon
C:\WINDOWS\WINDOWS\Fonts\Shelman_.TTF
C:\WINDOWS\WINDOWS\Fonts\shruti.ttf
C:\WINDOWS\WINDOWS\Fonts\smae1257.fon
C:\WINDOWS\WINDOWS\Fonts\smaf1257.fon
C:\WINDOWS\WINDOWS\Fonts\smalle.fon
C:\WINDOWS\WINDOWS\Fonts\smallee.fon
C:\WINDOWS\WINDOWS\Fonts\smalleg.fon
C:\WINDOWS\WINDOWS\Fonts\smaller.fon
C:\WINDOWS\WINDOWS\Fonts\smallet.fon
C:\WINDOWS\WINDOWS\Fonts\smallf.fon
C:\WINDOWS\WINDOWS\Fonts\smallfe.fon
C:\WINDOWS\WINDOWS\Fonts\smallfg.fon
C:\WINDOWS\WINDOWS\Fonts\smallfr.fon
C:\WINDOWS\WINDOWS\Fonts\smallft.fon
C:\WINDOWS\WINDOWS\Fonts\SNAP____.TTF
C:\WINDOWS\WINDOWS\Fonts\ssee1257.fon
C:\WINDOWS\WINDOWS\Fonts\ssef1257.fon
C:\WINDOWS\WINDOWS\Fonts\sserife.fon
C:\WINDOWS\WINDOWS\Fonts\sserifee.fon
C:\WINDOWS\WINDOWS\Fonts\sserifeg.fon
C:\WINDOWS\WINDOWS\Fonts\sserifer.fon
C:\WINDOWS\WINDOWS\Fonts\sserifet.fon
C:\WINDOWS\WINDOWS\Fonts\sseriff.fon
C:\WINDOWS\WINDOWS\Fonts\sseriffe.fon
C:\WINDOWS\WINDOWS\Fonts\sseriffg.fon
C:\WINDOWS\WINDOWS\Fonts\sseriffr.fon
C:\WINDOWS\WINDOWS\Fonts\sserifft.fon
C:\WINDOWS\WINDOWS\Fonts\sylfaen.ttf
C:\WINDOWS\WINDOWS\Fonts\symbol.ttf
C:\WINDOWS\WINDOWS\Fonts\symbole.fon
C:\WINDOWS\WINDOWS\Fonts\tahoma.ttf
C:\WINDOWS\WINDOWS\Fonts\tahomabd.ttf
C:\WINDOWS\WINDOWS\Fonts\TempsITC.TTF
C:\WINDOWS\WINDOWS\Fonts\times.ttf
C:\WINDOWS\WINDOWS\Fonts\timesbd.ttf
C:\WINDOWS\WINDOWS\Fonts\timesbi.ttf
C:\WINDOWS\WINDOWS\Fonts\timesi.ttf
C:\WINDOWS\WINDOWS\Fonts\trebuc.ttf
C:\WINDOWS\WINDOWS\Fonts\trebucbd.ttf
C:\WINDOWS\WINDOWS\Fonts\trebucbi.ttf
C:\WINDOWS\WINDOWS\Fonts\trebucit.ttf
C:\WINDOWS\WINDOWS\Fonts\Trendy__.TTF
C:\WINDOWS\WINDOWS\Fonts\tunga.ttf
C:\WINDOWS\WINDOWS\Fonts\verdana.ttf
C:\WINDOWS\WINDOWS\Fonts\verdanab.ttf
C:\WINDOWS\WINDOWS\Fonts\verdanai.ttf
C:\WINDOWS\WINDOWS\Fonts\verdanaz.ttf
C:\WINDOWS\WINDOWS\Fonts\VERDREF.TTF
C:\WINDOWS\WINDOWS\Fonts\vga737.fon
C:\WINDOWS\WINDOWS\Fonts\vga775.fon
C:\WINDOWS\WINDOWS\Fonts\vga850.fon
C:\WINDOWS\WINDOWS\Fonts\vga852.fon
C:\WINDOWS\WINDOWS\Fonts\vga855.fon
C:\WINDOWS\WINDOWS\Fonts\vga857.fon
C:\WINDOWS\WINDOWS\Fonts\vga860.fon
C:\WINDOWS\WINDOWS\Fonts\vga863.fon
C:\WINDOWS\WINDOWS\Fonts\vga865.fon
C:\WINDOWS\WINDOWS\Fonts\vga866.fon
C:\WINDOWS\WINDOWS\Fonts\vga869.fon
C:\WINDOWS\WINDOWS\Fonts\vgaf1257.fon
C:\WINDOWS\WINDOWS\Fonts\vgafix.fon
C:\WINDOWS\WINDOWS\Fonts\vgafixe.fon
C:\WINDOWS\WINDOWS\Fonts\vgafixg.fon
C:\WINDOWS\WINDOWS\Fonts\vgafixr.fon
C:\WINDOWS\WINDOWS\Fonts\vgafixt.fon
C:\WINDOWS\WINDOWS\Fonts\vgaoem.fon
C:\WINDOWS\WINDOWS\Fonts\vgas1257.fon
C:\WINDOWS\WINDOWS\Fonts\vgasys.fon
C:\WINDOWS\WINDOWS\Fonts\vgasyse.fon
C:\WINDOWS\WINDOWS\Fonts\vgasysg.fon
C:\WINDOWS\WINDOWS\Fonts\vgasysr.fon
C:\WINDOWS\WINDOWS\Fonts\vgasyst.fon
C:\WINDOWS\WINDOWS\Fonts\VINERITC.TTF
C:\WINDOWS\WINDOWS\Fonts\Vivaldii.TTF
C:\WINDOWS\WINDOWS\Fonts\Vladimir.ttf
C:\WINDOWS\WINDOWS\Fonts\webdings.ttf
C:\WINDOWS\WINDOWS\Fonts\wingding.ttf
C:\WINDOWS\WINDOWS\Fonts\WINGDNG2.TTF
C:\WINDOWS\WINDOWS\Fonts\WINGDNG3.TTF
C:\WINDOWS\WINDOWS\Fonts\wst_czec.fon
C:\WINDOWS\WINDOWS\Fonts\wst_engl.fon
C:\WINDOWS\WINDOWS\Fonts\wst_fren.fon
C:\WINDOWS\WINDOWS\Fonts\wst_germ.fon
C:\WINDOWS\WINDOWS\Fonts\wst_ital.fon
C:\WINDOWS\WINDOWS\Fonts\wst_span.fon
C:\WINDOWS\WINDOWS\Fonts\wst_swed.fon
C:\WINDOWS\WINDOWS\Fächer.bmp
C:\WINDOWS\WINDOWS\Granit.bmp
C:\WINDOWS\WINDOWS\GRAPPLER.INI
C:\WINDOWS\WINDOWS\HBCIKRNL.INI
C:\WINDOWS\WINDOWS\Help\acc_dis.chm
C:\WINDOWS\WINDOWS\Help\accessib.chm
C:\WINDOWS\WINDOWS\Help\aclui.hlp
C:\WINDOWS\WINDOWS\Help\admtools.chm
C:\WINDOWS\WINDOWS\Help\apps.chm
C:\WINDOWS\WINDOWS\Help\apps_sp.chm
C:\WINDOWS\WINDOWS\Help\certmgr.chm
C:\WINDOWS\WINDOWS\Help\ciadmin.htm
C:\WINDOWS\WINDOWS\Help\ciquery.htm
C:\WINDOWS\WINDOWS\Help\cmconcepts.chm
C:\WINDOWS\WINDOWS\Help\conf.cnt
C:\WINDOWS\WINDOWS\Help\connect.cnt
C:\WINDOWS\WINDOWS\Help\cpanel.chm
C:\WINDOWS\WINDOWS\Help\cpanel.chq
C:\WINDOWS\WINDOWS\Help\diskmgmt.chm
C:\WINDOWS\WINDOWS\Help\display.chm
C:\WINDOWS\WINDOWS\Help\filefold.chm
C:\WINDOWS\WINDOWS\Help\find.chm
C:\WINDOWS\WINDOWS\Help\Glossary.chm
C:\WINDOWS\WINDOWS\Help\hardware.hlp
C:\WINDOWS\WINDOWS\Help\howto.chm
C:\WINDOWS\WINDOWS\Help\hschelp.chm
C:\WINDOWS\WINDOWS\Help\iesupp.chm
C:\WINDOWS\WINDOWS\Help\iewebhlp.chm
C:\WINDOWS\WINDOWS\Help\input.chm
C:\WINDOWS\WINDOWS\Help\input.hlp
C:\WINDOWS\WINDOWS\Help\ipsecconcepts.chm
C:\WINDOWS\WINDOWS\Help\ipsecsnp.chm
C:\WINDOWS\WINDOWS\Help\ixqlang.htm
C:\WINDOWS\WINDOWS\Help\JntView.chm
C:\WINDOWS\WINDOWS\Help\langbar.chm
C:\WINDOWS\WINDOWS\Help\license.chm
C:\WINDOWS\WINDOWS\Help\migwiz.htm
C:\WINDOWS\WINDOWS\Help\migwiz2.htm
C:\WINDOWS\WINDOWS\Help\misc.chm
C:\WINDOWS\WINDOWS\Help\mpconcepts.chm
C:\WINDOWS\WINDOWS\Help\mplayer2.cnt
C:\WINDOWS\WINDOWS\Help\mshearts.cnt
C:\WINDOWS\WINDOWS\Help\msnauth.cnt
C:\WINDOWS\WINDOWS\Help\NAV.chm
C:\WINDOWS\WINDOWS\Help\netcfg.chm
C:\WINDOWS\WINDOWS\Help\network.chm
C:\WINDOWS\WINDOWS\Help\nocontnt.cnt
C:\WINDOWS\WINDOWS\Help\ntart.chm
C:\WINDOWS\WINDOWS\Help\ntcmds.chm
C:\WINDOWS\WINDOWS\Help\ntdef.chm
C:\WINDOWS\WINDOWS\Help\nusrmgr.chm
C:\WINDOWS\WINDOWS\Help\nvcpar.hlp
C:\WINDOWS\WINDOWS\Help\nvcpcs.hlp
C:\WINDOWS\WINDOWS\Help\nvcpda.hlp
C:\WINDOWS\WINDOWS\Help\nvcpde.hlp
C:\WINDOWS\WINDOWS\Help\nvcpel.hlp
C:\WINDOWS\WINDOWS\Help\nvcpeng.hlp
C:\WINDOWS\WINDOWS\Help\nvcpes.hlp
C:\WINDOWS\WINDOWS\Help\nvcpesm.hlp
C:\WINDOWS\WINDOWS\Help\nvcpfi.hlp
C:\WINDOWS\WINDOWS\Help\nvcpfr.hlp
C:\WINDOWS\WINDOWS\Help\nvcphe.hlp
C:\WINDOWS\WINDOWS\Help\nvcphu.hlp
C:\WINDOWS\WINDOWS\Help\nvcpit.hlp
C:\WINDOWS\WINDOWS\Help\nvcpja.hlp
C:\WINDOWS\WINDOWS\Help\nvcpko.hlp
C:\WINDOWS\WINDOWS\Help\nvcpl.hlp
C:\WINDOWS\WINDOWS\Help\nvcpnl.hlp
C:\WINDOWS\WINDOWS\Help\nvcpno.hlp
C:\WINDOWS\WINDOWS\Help\nvcppl.hlp
C:\WINDOWS\WINDOWS\Help\nvcppt.hlp
C:\WINDOWS\WINDOWS\Help\nvcpptb.hlp
C:\WINDOWS\WINDOWS\Help\nvcpru.hlp
C:\WINDOWS\WINDOWS\Help\nvcpsk.hlp
C:\WINDOWS\WINDOWS\Help\nvcpsl.hlp
C:\WINDOWS\WINDOWS\Help\nvcpsv.hlp
C:\WINDOWS\WINDOWS\Help\nvcpth.hlp
C:\WINDOWS\WINDOWS\Help\nvcptr.hlp
C:\WINDOWS\WINDOWS\Help\nvcpzhc.hlp
C:\WINDOWS\WINDOWS\Help\nvcpzht.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpcs.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpda.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpde.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpel.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpeng.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpes.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpesm.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpfi.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpfr.hlp
C:\WINDOWS\WINDOWS\Help\nvwcphu.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpit.hlp
C:\WINDOWS\WINDOWS\Help\nvwcplen.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpnl.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpno.hlp
C:\WINDOWS\WINDOWS\Help\nvwcppl.hlp
C:\WINDOWS\WINDOWS\Help\nvwcppt.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpptb.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpru.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpsk.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpsl.hlp
C:\WINDOWS\WINDOWS\Help\nvwcpsv.hlp
C:\WINDOWS\WINDOWS\Help\nvwcptr.hlp
C:\WINDOWS\WINDOWS\Help\nwdoc.chm
C:\WINDOWS\WINDOWS\Help\password.chm
C:\WINDOWS\WINDOWS\Help\plyr_err.chm
C:\WINDOWS\WINDOWS\Help\printing.chm
C:\WINDOWS\WINDOWS\Help\progman.cnt
C:\WINDOWS\WINDOWS\Help\pwrmn.chm
C:\WINDOWS\WINDOWS\Help\ratings.cnt
C:\WINDOWS\WINDOWS\Help\regopt.chm
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\bookmrk.CDX
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\bookmrk.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Groups.cdx
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Groups.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Grpsyll.cdx
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Grpsyll.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Prgrss2.cdx
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Prgrss2.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Progress.cdx
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Progress.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Settings.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Syllabi2.cdx
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Syllabi2.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Syllabus.cdx
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Syllabus.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Usergrp.cdx
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Usergrp.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Users.cdx
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\Users.dbf
C:\WINDOWS\WINDOWS\Help\SBSI\Training\Database\WXPPera.toc
C:\WINDOWS\WINDOWS\Help\SBSI\Training\engine.ini
C:\WINDOWS\WINDOWS\Help\SBSI\Training\lsingle.cnt
C:\WINDOWS\WINDOWS\Help\SBSI\Training\LSINGLE.HLP
C:\WINDOWS\WINDOWS\Help\SBSI\Training\orun32.exe
C:\WINDOWS\WINDOWS\Help\SBSI\Training\ounins32_s.exe
C:\WINDOWS\WINDOWS\Help\SBSI\Training\startmenu.cbo
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\CBO\hsc_add.vbs
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\CBO\hsc_del.vbs
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\CBO\wxpper.chm
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\CBO\wxppera.cab
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L10_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L10_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L10_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L10_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L10_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L10_Fa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L11_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L11_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L11_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L11_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L12_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L12_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L12_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L12_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L12_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L13_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L13_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L13_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L13_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L13_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L13_Fa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L14_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L14_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L14_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L14_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L14_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L15_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L15_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L15_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L15_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L15_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L15_Fa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L16_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L16_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L16_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L16_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L16_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L17_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L17_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L17_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L17_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L17_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L1_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L2_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L2_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L2_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L2_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L2_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L2_Fa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L2_Ga.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L2_Ha.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L2_Ia.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L3_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L3_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L3_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L3_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L3_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L4_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L4_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L4_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L4_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L4_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L4_Fa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L4_Ga.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L4_Ha.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L5_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L5_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L5_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L5_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L5_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L5_Fa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L5_Ga.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L5_Ha.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L6_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L6_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L6_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L6_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L6_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L7_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L7_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L7_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L7_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L7_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L7_Fa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L8_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L8_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L8_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L8_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L8_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L9_Aa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L9_Ba.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L9_Ca.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L9_Da.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L9_Ea.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Cbz\L9_Fa.CBZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\fin_shot.SWF
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L10_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L10_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L10_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L10_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L10_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L10_F.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L11_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L11_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L11_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L11_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L12_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L12_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L12_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L12_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L12_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L13_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L13_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L13_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L13_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L13_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L13_F.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L14_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L14_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L14_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L14_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L14_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L15_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L15_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L15_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L15_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L15_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L15_F.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L16_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L16_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L16_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L16_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L16_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L17_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L17_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L17_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L17_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L17_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L1_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L2_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L2_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L2_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L2_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L2_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L2_F.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L2_G.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L2_H.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L2_I.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L3_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L3_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L3_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L3_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L3_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L4_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L4_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L4_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L4_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L4_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L4_F.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L4_G.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L4_H.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L5_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L5_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L5_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L5_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L5_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L5_F.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L5_G.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L5_H.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L6_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L6_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L6_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L6_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L6_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L7_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L7_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L7_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L7_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L7_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L7_F.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L8_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L8_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L8_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L8_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L8_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L9_A.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L9_B.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L9_C.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L9_D.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L9_E.LDZ
C:\WINDOWS\WINDOWS\Help\SBSI\Training\WXPPer\Content\Lib\L9_F.LDZ
C:\WI
JW1
 
Beiträge: 11
Registriert: 11.07.2007, 13:04
Wohnort: im Norden

Beitragvon JW1 am 12.07.2007, 08:38

Hallo,

von CounterSpy bekomme ich den Report nicht komplett gepostet.

Gibt es eine Möglichkeit diesen zu komprimieren und hier einzustellen?


Den Hijackreport stelle ich hier rein:

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 08:17:57, on 12.07.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\cisvc.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkUFind.exe
C:\Programme\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe
C:\Programme\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
C:\Programme\QuickTime\qttask.exe
C:\Programme\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\carpserv.exe
C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programme\Microsoft IntelliType Pro\itype.exe
C:\Programme\Windows Defender\MSASCui.exe
C:\Programme\Sunbelt Software\CounterSpy\SBCSTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\Spamihilator\spamihilator.exe
C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Programme\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programme\Sunbelt Software\CounterSpy\SBCSSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexingService.exe
C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexStoreSvr.exe
C:\Programme\Internet Explorer\iexplore.exe
C:\Dokumente und Einstellungen\Jörgel\Eigene Dateien\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.t-online.de/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.t-online.de
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.t-online.de
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer bereitgestellt von T-Online
R3 - URLSearchHook: Yahoo! Toolbar mit Pop-Up-Blocker - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programme\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programme\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programme\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar mit Pop-Up-Blocker - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programme\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [PMCS] C:\Programme\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe -host -clearDebug
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [PMCRemote] C:\Programme\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programme\Gemeinsame Dateien\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [avgnt] "C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [itype] "c:\Programme\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Programme\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SBCSTray] C:\Programme\Sunbelt Software\CounterSpy\SBCSTray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Spamihilator] "C:\Programme\Spamihilator\spamihilator.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [swg] C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/german/par ... nicode.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/house ... hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/Shar ... vSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Programme\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.johannrain-softwareentwicklu ... oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 4826135370
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 4826469182
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan ... asinst.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsup ... mAData.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsup ... veData.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: AntiVir PersonalEdition Classic Planer (AntiVirScheduler) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Pinnacle Systems tvtv Spooler (EpgSpooler) - - c:\progra~1\pinnacle\mediac~1\epgspo~2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Programme\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - c:\programme\pinnacle\shared files\programs\mediaserver\pmshost.exe
O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Programme\Sunbelt Software\CounterSpy\SBCSSvc.exe
O24 - Desktop Component 1: (no name) - http://speedmanager.t-com-dsl.de/

--
End of file - 10585 bytes


So, die Explorer.Exe macht immer noch auf 100%.

Gruß JW1[/code]
JW1
 
Beiträge: 11
Registriert: 11.07.2007, 13:04
Wohnort: im Norden

Beitragvon Humdinger am 12.07.2007, 10:09

CCLEANER ausführen

Nun zuerst die
Systemwiederherstellung
http://support.microsoft.com/default.as ... ;de;310405
zuerst deaktivieren, dann wieder aktivieren


Totalscan
ausführen:
http://www.nanoscan.com/as/v1/?

wähle:Full scan

(Warnmeldung von Antivir = ignorieren)

Bericht speichern und posten
Humdinger
Mitarbeiter
 
Beiträge: 896
Registriert: 22.03.2006, 14:22
Wohnort: Mainz

Beitragvon JW1 am 12.07.2007, 21:09

Hat ein bisschen länger gedauert, da mein Rechner dreimal abgestürzt ist.

Hier nun der Report:

;***********************************************************************************************************************************************************************************
ANALYSIS: 2007-07-12 19:38:32
PROTECTIONS: 5
MALWARE: 4
SUSPECTS: 2
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
AntiVir PersonalEdition Classic Virenschutz 0.0.0.0 Yes No
Avira AntiVir PersonalEdition 6.39.0.131
Yes Yes
AntiVir PersonalEdition Classic Virenschutz 0.0.0.0 Yes Yes
AntiVir PersonalEdition Classic Virenschutz 6.38.1.19
Yes Yes
AntiVir PersonalEdition Classic Virenschutz 0.0.0.0 Yes Yes
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00035917 adware/ist.sidefind Adware No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10E42047-DEB9-4535-A118-B3F6EC39B807}
00042191 adware/ist.yoursitebar Adware No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{86227D9C-0EFE-4F8A-AA55-30386A3F5686}
00235842 Application/RealSpy HackTools No 0 Yes No C:\WINDOWS\system32\actskn45.ocx
01192348 Application/MyWebSearch HackTools No 0 No No C:\Dokumente und Einstellungen\Jörgel\Eigene Dateien\Bearbeitungstools\Nero-7.8.5.0_deu_update.exe[Toolbar.exe]
;===================================================================================================================================================================================
SUSPECTS
Location
;===================================================================================================================================================================================
C:\Dokumente und Einstellungen\Jörgel\Eigene Dateien\RegSeeker155.zip[RegSeeker\RegSeeker.exe]
C:\Dokumente und Einstellungen\Jörgel\Eigene Dateien\RegSeeker155\RegSeeker\RegSeeker.exe
;===================================================================================================================================================================================

Wie gehts weiter?

JW1
JW1
 
Beiträge: 11
Registriert: 11.07.2007, 13:04
Wohnort: im Norden

Beitragvon Humdinger am 13.07.2007, 12:20

Alle Dateien anzeigen
Arbeitsplatz -> rechter Mausklick -->Windows Explorer -> "Extras/Ordneroptionen" ->
"Ansicht" -> Haken entfernen bei "Geschützte Systemdateien
ausblenden (empfohlen)" und "Alle Dateien und Ordner anzeigen"
aktivieren -> "OK"


abgesicherter Modus starten

lösche direkt
C:\WINDOWS\system32\actskn45.ocx
C:\Dokumente und Einstellungen\Jörgel\Eigene Dateien\Bearbeitungstools\Nero-7.8.5.0_deu_update.exe[Toolbar.exe]

weiter im abgesicherten Modus

start-ausführen: regedit
navigiere zu den Funden und lösche
00035917 adware/ist.sidefind Adware No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10E42047-DEB9-4535-A118-B3F6EC39B807}
00042191 adware/ist.yoursitebar Adware No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{86227D9C-0EFE-4F8A-AA55-30386A3F5686}


Neustart Normalstart

Onlinescan vom gesamten System:
http://www.kaspersky.com/kos/german/par ... bscan.html
benötigt ActiveX --> IE ,
d.h. du mußt dafür Active X evtl. freigeben unter Interneteinstellungen.
Report vollständig posten.
Humdinger
Mitarbeiter
 
Beiträge: 896
Registriert: 22.03.2006, 14:22
Wohnort: Mainz