cmd.exe boxes flashing around screen on startup
Page 1 of 2 12 LastLast
Results 1 to 10 of 12

Thread: cmd.exe boxes flashing around screen on startup

  1. #1
    Junior Member
    Join Date
    Sep 2006
    Posts
    5

    cmd.exe boxes flashing around screen on startup

    It just says C:\Windows\system32\cmd.exe, no message just that line that I guess just says it's running. Multiple prompt boxes open and close across the screen, then one stays put for a few seconds and closes. I've already done a lot with my virus/spyware stuff, spybot s&d, online scans, lspfix etc. Here the latest hijackthis log. Thanks.

    Logfile of HijackThis v1.99.1
    Scan saved at 7:49:46 PM, on 9/30/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\arservice.exe
    C:\WINDOWS\system32\CTsvcCDA.EXE
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Acceleration Software\StopSignProducts\Firewall\fwservice.exe
    C:\WINDOWS\runservice.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    c:\program files\mcafee.com\agent\mcdetect.exe
    c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\eAcceleration\OnAccess\scan.exe
    C:\Program Files\eAcceleration\Station\station.exe
    C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe
    C:\Program Files\McAfee.com\VSO\mcvsshld.exe
    c:\progra~1\mcafee.com\vso\mcvsescn.exe
    c:\program files\mcafee.com\agent\mcagent.exe
    C:\Program Files\eAcceleration\OnAccess\OnAccess.exe
    C:\Program Files\eAcceleration\OnAccess\dguard.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Acceleration Software\SystemPatcher\sys_alert.exe
    C:\Program Files\CE\nmSvc.exe
    C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    c:\progra~1\mcafee.com\vso\mcvsftsn.exe
    C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
    c:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\HP_Administrator\Desktop\hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer presented by Comcast
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
    O2 - BHO: (no name) - {B753C7C5-0942-4b7f-BC27-942B52BDAC66} - C:\PROGRA~1\ACCELE~1\StopSign\webcbrowse.dll
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [SoftwareStation] "C:\Program Files\eAcceleration\Station\station.exe" /b Startup
    O4 - HKLM\..\Run: [webscan] "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k
    O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
    O4 - HKLM\..\Run: [OnAccess] "C:\Program Files\eAcceleration\OnAccess\OnAccess.exe" -e
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
    O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
    O4 - HKLM\..\Run: [StopSignSsTsMon] Rundll32.exe "C:\Program Files\Acceleration Software\Anti-Virus\sstsmon.dll",VerifyStatus
    O4 - HKLM\..\Run: [StopSignSsFwMon] Rundll32.exe "C:\Program Files\Acceleration Software\StopSignProducts\Firewall\ssfwmon.dll",VerifyStatus
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [eanth_system_patcher] "C:\Program Files\Acceleration Software\SystemPatcher\sys_alert.exe" /Startup
    O4 - HKLM\..\Run: [NMSVC] C:\Program Files\CE\nmSvc.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
    O9 - Extra button: (no name) - {24BE56F9-F0B6-4ac7-97F1-8CACEDA9A427} - C:\PROGRA~1\ACCELE~1\StopSign\webcbrowse.dll
    O9 - Extra 'Tools' menuitem: Block This Page - {24BE56F9-F0B6-4ac7-97F1-8CACEDA9A427} - C:\PROGRA~1\ACCELE~1\StopSign\webcbrowse.dll
    O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
    O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
    O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Broken Internet access because of LSP provider 'cespy.dll' missing
    O15 - Trusted Zone: http://*.trymedia.com (HKLM)
    O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/sh...1/mcinsctl.cab
    O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/pro...nner371030.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/sh...26/mcgdmgr.cab
    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15026/CTPID.cab
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: FWService - eAcceleration Corp. - C:\Program Files\Acceleration Software\StopSignProducts\Firewall\fwservice.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
    O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

  2. #2
    AO's MMA Fanatic! Computernerd22's Avatar
    Join Date
    Mar 2003
    Location
    Miami, FL
    Posts
    769
    Check this out: Cut and paste the output into this link:

    http://www.hijackthis.de/#anl

    A couple of things you should check out.

    O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
    Unnecessarily Unknown buttons or entries in the 'Extras'-menu should be fixed.
    To be fixed if the entry 'ComcastHSI ' is unknown.
    Unnecessary (deactivated) entry that can be fixed.
    O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
    Unnecessarily Unknown buttons or entries in the 'Extras'-menu should be fixed.
    To be fixed if the entry 'Support ' is unknown.
    Unnecessary (deactivated) entry that can be fixed.
    and

    O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEB utton\support.htm
    Possibly nasty Unknown buttons or entries in the 'Extras'-menu should be fixed.
    To be fixed if the entry 'Internet Connection Help ' is unknown.
    O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEB utton\support.htm
    Possibly nasty Unknown buttons or entries in the 'Extras'-menu should be fixed.
    To be fixed if the entry 'Internet Connection Help ' is unknown.

  3. #3
    Junior Member
    Join Date
    Sep 2006
    Posts
    5
    Thanks for the reply. I have been using hijackthis.de to guide me and already did some stuff with its help. I hadn't fixed these yet because it says it's ok if you recognize what it is. Think I should fix them anyway?

  4. #4
    Junior Member
    Join Date
    Sep 2006
    Posts
    5
    Here's the latest log. Does anyone see anything else? Apparently there was a backdoor trojan that ewido found since my first log was posted. I wonder if there's anything else that hijackthis.de isn't flagging or isn't even showing up on the log at all.

    Logfile of HijackThis v1.99.1
    Scan saved at 9:45:19 PM, on 9/30/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\arservice.exe
    C:\WINDOWS\system32\CTsvcCDA.EXE
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Acceleration Software\StopSignProducts\Firewall\fwservice.exe
    C:\WINDOWS\runservice.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    c:\program files\mcafee.com\agent\mcdetect.exe
    c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\eAcceleration\OnAccess\scan.exe
    C:\Program Files\eAcceleration\Station\station.exe
    C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe
    C:\Program Files\McAfee.com\VSO\mcvsshld.exe
    c:\progra~1\mcafee.com\vso\mcvsescn.exe
    c:\program files\mcafee.com\agent\mcagent.exe
    C:\Program Files\eAcceleration\OnAccess\OnAccess.exe
    C:\Program Files\eAcceleration\OnAccess\dguard.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Acceleration Software\SystemPatcher\sys_alert.exe
    C:\Program Files\CE\nmSvc.exe
    C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    c:\progra~1\mcafee.com\vso\mcvsftsn.exe
    C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
    c:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\HP_Administrator\Desktop\hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer presented by Comcast
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
    O2 - BHO: (no name) - {B753C7C5-0942-4b7f-BC27-942B52BDAC66} - C:\PROGRA~1\ACCELE~1\StopSign\webcbrowse.dll
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [SoftwareStation] "C:\Program Files\eAcceleration\Station\station.exe" /b Startup
    O4 - HKLM\..\Run: [webscan] "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k
    O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
    O4 - HKLM\..\Run: [OnAccess] "C:\Program Files\eAcceleration\OnAccess\OnAccess.exe" -e
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
    O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
    O4 - HKLM\..\Run: [StopSignSsTsMon] Rundll32.exe "C:\Program Files\Acceleration Software\Anti-Virus\sstsmon.dll",VerifyStatus
    O4 - HKLM\..\Run: [StopSignSsFwMon] Rundll32.exe "C:\Program Files\Acceleration Software\StopSignProducts\Firewall\ssfwmon.dll",VerifyStatus
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [eanth_system_patcher] "C:\Program Files\Acceleration Software\SystemPatcher\sys_alert.exe" /Startup
    O4 - HKLM\..\Run: [NMSVC] C:\Program Files\CE\nmSvc.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Broken Internet access because of LSP provider 'cespy.dll' missing
    O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/sh...1/mcinsctl.cab
    O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/pro...nner371030.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/sh...26/mcgdmgr.cab
    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15026/CTPID.cab
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: FWService - eAcceleration Corp. - C:\Program Files\Acceleration Software\StopSignProducts\Firewall\fwservice.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
    O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

  5. #5
    StOrM™
    Join Date
    Aug 2004
    Posts
    1,003
    Greeting's

    Why dont you generate only a starup list and post it. Hijackthis give's an option to do this. Is your anti-virus updated ?

    I would suggest that you do an online scant at microsoft. safety.live.com

    See if they detect anything..
    Parth Maniar,
    CISSP, CISM, CISA, SSCP

    *Thank you GOD*

    Greater the Difficulty, SWEETER the Victory.

    Believe in yourself.

  6. #6
    Super Moderator: GMT Zone nihil's Avatar
    Join Date
    Jul 2003
    Location
    United Kingdom: Bridlington
    Posts
    17,190
    Hi,

    It wasn't mentioned so I shall:

    1. Update all your scanners
    2. Reboot into safe mode and run them again
    3. Turn off system restore

    Incidentally, LSfix is not an antivirus tool, it is intended to repair corrupted LSP stacks in Winsock2. This would show as a failure to connect to the internet..................properly written malware actually wants you to connect to the internet so that it can own you or steal from you
    If you cannot do someone any good: don't do them any harm....
    As long as you did this to one of these, the least of my little ones............you did it unto Me.
    What profiteth a man if he gains the entire World at the expense of his immortal soul?

  7. #7
    Junior Member
    Join Date
    Sep 2006
    Posts
    5
    Originally posted here by ByTeWrangler
    Greeting's

    Why dont you generate only a starup list and post it. Hijackthis give's an option to do this. Is your anti-virus updated ?

    I would suggest that you do an online scant at microsoft. safety.live.com

    See if they detect anything..
    How do you do a startup hijackthis list? I don't see a specific option for that.

  8. #8
    Senior Member
    Join Date
    Dec 2003
    Location
    Pacific Northwest
    Posts
    1,675
    Good Day,

    StartupList: A simple tool that lists all and every auto starting program on your system. You might be surprised what it finds, this is way better than Msconfig. Commonly used to troubleshoot malfunctioning systems, trojan/viral infections, new spyware/malware breed and the likes.
    Compatible with: All Windows versions
    Currently at version: 2.01
    Go Here and click on a site you'd like to download it from.

    cheers
    Connection refused, try again later.

  9. #9
    Junior Member
    Join Date
    Sep 2006
    Posts
    5
    Here's what it gave. It's pretty huge.

    StartupList report, 10/1/2006, 2:37:59 PM
    StartupList version 2.01.0
    Started from: C:\Documents and Settings\HP_Administrator\Desktop\startuplist\StartupList.EXE
    Detected: Windows XP SP2 (WinNT 5.01.2600)
    Logged on as 'HP_Administrator' to 'SEAN'
    * Using default options (see end of log for possible options)
    ==================================================

    Running processes (43):

    [C:\Documents and Settings\HP_Administrator\Desktop\startuplist\StartupList.exe (45)]
    C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\IadHide5.dll
    c:\progra~1\mcafee.com\vso\McVSSkt.dll
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\asycfilt.dll
    C:\WINDOWS\system32\CLBCATQ.DLL
    C:\WINDOWS\system32\COMCTL32.dll
    C:\WINDOWS\system32\comdlg32.dll
    C:\WINDOWS\system32\COMRes.dll
    C:\WINDOWS\system32\DNSAPI.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\MSCOMCTL.OCX
    C:\WINDOWS\system32\MSCTF.dll
    C:\WINDOWS\system32\msctfime.ime
    C:\WINDOWS\system32\msi.dll
    C:\WINDOWS\system32\mslbui.dll
    C:\WINDOWS\system32\MSVBVM60.DLL
    C:\WINDOWS\system32\MSVCP60.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\NETAPI32.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\NTDSAPI.dll
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\PSAPI.DLL
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\Secur32.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\SXS.DLL
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\uxtheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\wbem\fastprox.dll
    C:\WINDOWS\system32\wbem\wbemcomn.dll
    C:\WINDOWS\system32\wbem\wbemdisp.dll
    C:\WINDOWS\system32\wbem\wbemprox.dll
    C:\WINDOWS\system32\wbem\wbemsvc.dll
    C:\WINDOWS\system32\wbem\wmiutils.dll
    C:\WINDOWS\system32\WLDAP32.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\system32\xpsp2res.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [c:\PROGRA~1\mcafee.com\agent\mctskshd.exe (23)]
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\comctl32.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\NETAPI32.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\NTMARTA.DLL
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\psapi.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\SAMLIB.dll
    C:\WINDOWS\system32\SETUPAPI.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\uxtheme.dll
    C:\WINDOWS\system32\WINSTA.dll
    C:\WINDOWS\system32\WLDAP32.dll
    C:\WINDOWS\system32\wtsapi32.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [c:\PROGRA~1\mcafee.com\vso\mcshield.exe (26)]
    c:\PROGRA~1\mcafee.com\vso\FTL.Dll
    c:\PROGRA~1\mcafee.com\vso\mytilus.dll
    c:\PROGRA~1\mcafee.com\vso\naiann.dll
    c:\PROGRA~1\mcafee.com\vso\RES00\McShield.DLL
    C:\Program Files\McAfee.com\VSO\MCSCAN32.DLL
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\LZ32.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\NETAPI32.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\psapi.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\Secur32.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\uxtheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\WINSTA.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\system32\wtsapi32.dll
    C:\WINDOWS\system32\xpsp2res.dll

    [c:\progra~1\mcafee.com\vso\mcvsescn.exe (37)]
    c:\progra~1\mcafee.com\vso\ashldres.dll
    c:\progra~1\mcafee.com\vso\EmScnRes.dll
    c:\progra~1\mcafee.com\vso\McVSSkt.dll
    c:\progra~1\mcafee.com\vso\McVsWorm.dll
    c:\progra~1\mcafee.com\vso\WormRes.dll
    C:\Program Files\McAfee.com\VSO\VsCfgW32.dll
    c:\program files\mcafee.com\vso\vsoupd.dll
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\CLBCATQ.DLL
    C:\WINDOWS\system32\comctl32.dll
    C:\WINDOWS\system32\COMRes.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\LZ32.dll
    C:\WINDOWS\system32\MSCTF.dll
    C:\WINDOWS\system32\msctfime.ime
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\NTMARTA.DLL
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\SAMLIB.dll
    C:\WINDOWS\system32\SETUPAPI.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\SXS.DLL
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\uxtheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\WINHTTP.dll
    C:\WINDOWS\system32\WLDAP32.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\system32\xpsp2res.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [c:\progra~1\mcafee.com\vso\mcvsftsn.exe (35)]
    c:\progra~1\mcafee.com\vso\McVSSkt.dll
    c:\program files\mcafee.com\agent\mcagntps.dll
    c:\program files\mcafee.com\agent\submgr\6,0,0,15\mcsubmgr.dll
    C:\Program Files\McAfee.com\VSO\VsCfgW32.dll
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\CLBCATQ.DLL
    C:\WINDOWS\system32\comctl32.dll
    C:\WINDOWS\system32\COMRes.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\MSCTF.dll
    C:\WINDOWS\system32\msctfime.ime
    C:\WINDOWS\system32\msi.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\msxml3.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\NTMARTA.DLL
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\SAMLIB.dll
    C:\WINDOWS\system32\SETUPAPI.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\SXS.DLL
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\uxtheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\WINHTTP.dll
    C:\WINDOWS\system32\WLDAP32.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\system32\xpsp2res.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe (36)]
    C:\Program Files\Acceleration Software\Anti-Virus\webctl.dll
    C:\WINDOWS\system32\ACTIVEDS.dll
    C:\WINDOWS\system32\adsldpc.dll
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\Apphelp.dll
    C:\WINDOWS\system32\ATL.DLL
    C:\WINDOWS\system32\COMCTL32.dll
    C:\WINDOWS\system32\comdlg32.dll
    C:\WINDOWS\system32\CRYPT32.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\imagehlp.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\MPRAPI.dll
    C:\WINDOWS\system32\MSASN1.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\NETAPI32.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\rtutils.dll
    C:\WINDOWS\system32\SAMLIB.dll
    C:\WINDOWS\system32\Secur32.dll
    C:\WINDOWS\system32\SETUPAPI.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\uxtheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\WININET.dll
    C:\WINDOWS\system32\WLDAP32.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\system32\WSOCK32.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [C:\Program Files\Acceleration Software\StopSignProducts\Firewall\fwservice.exe (50)]
    c:\progra~1\mcafee.com\vso\McVSSkt.dll
    C:\Program Files\Acceleration Software\StopSignProducts\Firewall\appinsp.dll
    C:\Program Files\Acceleration Software\StopSignProducts\Firewall\fwdriver.dll
    C:\Program Files\Acceleration Software\StopSignProducts\Firewall\fwobjs.dll
    C:\Program Files\Acceleration Software\StopSignProducts\Firewall\fwps.dll
    C:\Program Files\Acceleration Software\StopSignProducts\Firewall\PlgProtect.dll
    C:\Program Files\Acceleration Software\StopSignProducts\Firewall\psapi.dll
    C:\Program Files\Acceleration Software\StopSignProducts\Firewall\XMLConfig.dll
    C:\WINDOWS\system32\ACTIVEDS.dll
    C:\WINDOWS\system32\adsldpc.dll
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\ATL.DLL
    C:\WINDOWS\system32\CLBCATQ.DLL
    C:\WINDOWS\system32\COMRes.dll
    C:\WINDOWS\system32\CRYPT32.dll
    C:\WINDOWS\system32\cryptdlg.dll
    C:\WINDOWS\system32\cryptui.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMAGEHLP.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\MPRAPI.dll
    C:\WINDOWS\system32\MSASN1.dll
    C:\WINDOWS\system32\MSCTF.dll
    C:\WINDOWS\system32\msctfime.ime
    C:\WINDOWS\system32\MSVCP60.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\NETAPI32.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\RICHED20.dll
    C:\WINDOWS\system32\Riched32.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\rtutils.dll
    C:\WINDOWS\system32\SAMLIB.dll
    C:\WINDOWS\system32\SETUPAPI.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\uxtheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\WININET.dll
    C:\WINDOWS\system32\WINTRUST.dll
    C:\WINDOWS\system32\WLDAP32.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\system32\WSOCK32.dll
    C:\WINDOWS\system32\xpsp2res.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\COMCTL32.dll

    [C:\Program Files\Acceleration Software\SystemPatcher\sys_alert.exe (40)]
    C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\IadHide5.dll
    c:\progra~1\mcafee.com\vso\McVSSkt.dll
    C:\Program Files\Acceleration Software\SystemPatcher\sputils.dll
    C:\Program Files\Acceleration Software\SystemPatcher\updater.dll
    C:\WINDOWS\system32\ACTIVEDS.dll
    C:\WINDOWS\system32\adsldpc.dll
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\Apphelp.dll
    C:\WINDOWS\system32\ATL.DLL
    C:\WINDOWS\system32\COMCTL32.dll
    C:\WINDOWS\system32\CRYPT32.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\MPRAPI.dll
    C:\WINDOWS\system32\MSASN1.dll
    C:\WINDOWS\system32\MSCTF.dll
    C:\WINDOWS\system32\msctfime.ime
    C:\WINDOWS\system32\mslbui.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\NETAPI32.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\rtutils.dll
    C:\WINDOWS\system32\SAMLIB.dll
    C:\WINDOWS\system32\Secur32.dll
    C:\WINDOWS\system32\SETUPAPI.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\uxtheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\WININET.dll
    C:\WINDOWS\system32\WLDAP32.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\system32\WSOCK32.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [C:\Program Files\CE\nmSvc.exe (49)]
    c:\progra~1\mcafee.com\vso\McVSSkt.dll
    C:\Program Files\CE\nmsvc.dll
    C:\Program Files\CE\nmsvTree.dll
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\CESpy.dll
    C:\WINDOWS\system32\comdlg32.dll
    C:\WINDOWS\system32\CRYPT32.dll
    C:\WINDOWS\system32\DNSAPI.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\hnetcfg.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\iphlpapi.dll
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\MSASN1.dll
    C:\WINDOWS\system32\MSCTF.dll
    C:\WINDOWS\system32\msctfime.ime
    C:\WINDOWS\system32\msv1_0.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\MSVFW32.dll
    C:\WINDOWS\System32\mswsock.dll
    C:\WINDOWS\system32\NETAPI32.dll
    C:\WINDOWS\System32\nmNsp.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\rasadhlp.dll
    C:\WINDOWS\system32\RASAPI32.DLL
    C:\WINDOWS\system32\rasman.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\rtutils.dll
    C:\WINDOWS\system32\Secur32.dll
    C:\WINDOWS\system32\sensapi.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\SHFOLDER.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\TAPI32.dll
    C:\WINDOWS\system32\urlmon.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\USERENV.dll
    C:\WINDOWS\system32\uxtheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\WININET.dll
    C:\WINDOWS\system32\WINMM.dll
    C:\WINDOWS\system32\WINSPOOL.DRV
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\System32\wshtcpip.dll
    C:\WINDOWS\system32\wsock32.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\COMCTL32.dll

    [C:\Program Files\Common Files\LightScribe\LSSrvc.exe (14)]
    C:\Program Files\Common Files\LightScribe\MSVCP71.dll
    C:\Program Files\Common Files\LightScribe\MSVCR71.dll
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\comctl32.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (19)]
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\CLBCATQ.DLL
    C:\WINDOWS\system32\comctl32.dll
    C:\WINDOWS\system32\COMRes.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\psapi.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\xpsp2res.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe (32)]
    C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\IadHide5.dll
    c:\progra~1\mcafee.com\vso\McVSSkt.dll
    C:\Program Files\Creative\MediaSource\Detector\CTDetect.Crl
    C:\Program Files\Creative\MediaSource\Detector\CTIntrfc.dll
    C:\Program Files\Creative\MediaSource\Detector\Disc.det
    C:\Program Files\Creative\MediaSource\Detector\DtctrMgr.det
    C:\Program Files\Creative\MediaSource\Detector\Hdd.det
    C:\Program Files\Creative\Shared Files\CTIniF.dll
    C:\Program Files\Creative\Shared Files\ThmRes.DLL
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\comctl32.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\MFC42.DLL
    C:\WINDOWS\system32\MSCTF.dll
    C:\WINDOWS\system32\msctfime.ime
    C:\WINDOWS\system32\mslbui.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\uxtheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\WINMM.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [C:\Program Files\eAcceleration\OnAccess\dguard.exe (43)]
    C:\PROGRA~1\EACCEL~1\OnAccess\OnAccess.dll
    c:\progra~1\mcafee.com\vso\McVSSkt.dll
    C:\Program Files\Acceleration Software\Anti-Virus\drweb32.dll
    C:\Program Files\Acceleration Software\Anti-Virus\scancore.dll
    C:\Program Files\Acceleration Software\Anti-Virus\ScanCoreDLL.dll
    C:\Program Files\eAcceleration\OnAccess\vclnr.dll
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\appHelp.dll
    C:\WINDOWS\system32\ATL.DLL
    C:\WINDOWS\system32\CLBCATQ.DLL
    C:\WINDOWS\system32\comctl32.dll
    C:\WINDOWS\system32\COMRes.dll
    C:\WINDOWS\system32\CRYPT32.dll
    C:\WINDOWS\system32\CRYPTUI.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMAGEHLP.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\MSASN1.dll
    C:\WINDOWS\system32\MSCTF.dll
    C:\WINDOWS\system32\msctfime.ime
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\NETAPI32.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\ntshrui.dll
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\Secur32.dll
    C:\WINDOWS\system32\SETUPAPI.dll
    C:\WINDOWS\system32\shdocvw.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\USERENV.dll
    C:\WINDOWS\system32\uxtheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\WININET.dll
    C:\WINDOWS\system32\WINTRUST.dll
    C:\WINDOWS\system32\WLDAP32.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [C:\Program Files\eAcceleration\OnAccess\OnAccess.exe (24)]
    C:\PROGRA~1\EACCEL~1\OnAccess\OnAccess.dll
    c:\progra~1\mcafee.com\vso\McVSSkt.dll
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\CLBCATQ.DLL
    C:\WINDOWS\system32\comctl32.dll
    C:\WINDOWS\system32\COMRes.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\MSCTF.dll
    C:\WINDOWS\system32\msctfime.ime
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\uxtheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [C:\Program Files\eAcceleration\OnAccess\scan.exe (26)]
    c:\progra~1\mcafee.com\vso\McVSSkt.dll
    C:\Program Files\Acceleration Software\Anti-Virus\drweb32.dll
    C:\Program Files\Acceleration Software\Anti-Virus\scancore.dll
    C:\Program Files\Acceleration Software\Anti-Virus\ScanCoreDLL.dll
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\CLBCATQ.DLL
    C:\WINDOWS\system32\comctl32.dll
    C:\WINDOWS\system32\COMRes.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\MSCTF.dll
    C:\WINDOWS\system32\msctfime.ime
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\uxtheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [C:\Program Files\eAcceleration\Station\station.exe (45)]
    C:\PROGRA~1\COMMON~1\EACCEL~1\INSTAL~1\eaccelsetup0.dll
    C:\PROGRA~1\EACCEL~1\Station\sseng.dll
    c:\progra~1\mcafee.com\vso\McVSSkt.dll
    C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
    C:\WINDOWS\system32\ACTIVEDS.dll
    C:\WINDOWS\system32\adsldpc.dll
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\ATL.DLL
    C:\WINDOWS\system32\CLBCATQ.DLL
    C:\WINDOWS\system32\comctl32.dll
    C:\WINDOWS\system32\COMRes.dll
    C:\WINDOWS\system32\CRYPT32.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\mlang.dll
    C:\WINDOWS\system32\MPRAPI.dll
    C:\WINDOWS\system32\MSASN1.dll
    C:\WINDOWS\system32\MSCTF.dll
    C:\WINDOWS\system32\msctfime.ime
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\msxml3.dll
    C:\WINDOWS\system32\NETAPI32.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\rtutils.dll
    C:\WINDOWS\system32\SAMLIB.dll
    C:\WINDOWS\system32\Secur32.dll
    C:\WINDOWS\system32\SETUPAPI.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\urlmon.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\uxtheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\WINHTTP.dll
    C:\WINDOWS\system32\WININET.dll
    C:\WINDOWS\system32\WINMM.dll
    C:\WINDOWS\system32\WLDAP32.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\system32\WSOCK32.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe (55)]
    c:\progra~1\mcafee.com\vso\McVSSkt.dll
    C:\Program Files\CE\nmsvc.dll
    C:\Program Files\CE\nmsvTree.dll
    C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\res_en.dll
    C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\swg.dll
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\CESpy.dll
    C:\WINDOWS\system32\CLBCATQ.DLL
    C:\WINDOWS\system32\COMRes.dll
    C:\WINDOWS\system32\CRYPT32.dll
    C:\WINDOWS\system32\DNSAPI.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\hnetcfg.dll
    C:\WINDOWS\system32\IMAGEHLP.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\iphlpapi.dll
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\MSASN1.dll
    C:\WINDOWS\system32\MSCTF.dll
    C:\WINDOWS\system32\msctfime.ime
    C:\WINDOWS\system32\msi.dll
    C:\WINDOWS\system32\msv1_0.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\System32\mswsock.dll
    C:\WINDOWS\system32\NETAPI32.dll
    C:\WINDOWS\System32\nmNsp.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\PSAPI.DLL
    C:\WINDOWS\system32\rasadhlp.dll
    C:\WINDOWS\system32\RASAPI32.DLL
    C:\WINDOWS\system32\rasman.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\rtutils.dll
    C:\WINDOWS\system32\Secur32.dll
    C:\WINDOWS\system32\sensapi.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\SXS.DLL
    C:\WINDOWS\system32\TAPI32.dll
    C:\WINDOWS\system32\urlmon.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\USERENV.dll
    C:\WINDOWS\system32\uxtheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\WININET.dll
    C:\WINDOWS\system32\WINMM.dll
    C:\WINDOWS\system32\WINTRUST.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\System32\wshtcpip.dll
    C:\WINDOWS\system32\wsock32.dll
    C:\WINDOWS\system32\xpsp2res.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [c:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe (73)]
    C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\IadHide5.dll
    c:\progra~1\mcafee.com\vso\McVSSkt.dll
    C:\Program Files\Common Files\Microsoft Shared\INK\SKCHUI.DLL
    c:\Program Files\HP\Digital Imaging\bin\hpocxi08.dll
    c:\Program Files\HP\Digital Imaging\bin\hpodio08.dll
    c:\Program Files\HP\Digital Imaging\bin\hpqcob08.dll
    c:\Program Files\HP\Digital Imaging\bin\hpqcxm08.dll
    c:\Program Files\HP\Digital Imaging\bin\hpqmfc09.dll
    c:\Program Files\HP\Digital Imaging\bin\hpqsem08.rsc
    c:\Program Files\HP\Digital Imaging\bin\hpqSTE08.rsc
    c:\Program Files\HP\Digital Imaging\bin\hpqsti08.dll
    c:\Program Files\HP\Digital Imaging\bin\hpqstp08.dll
    c:\Program Files\HP\Digital Imaging\bin\hpqtap08.dll
    C:\WINDOWS\IME\SPGRMR.DLL
    C:\WINDOWS\ime\sptip.dll
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\appHelp.dll
    C:\WINDOWS\system32\CLBCATQ.DLL
    C:\WINDOWS\system32\COMCTL32.dll
    C:\WINDOWS\system32\COMRes.dll
    C:\WINDOWS\system32\CRYPT32.dll
    C:\WINDOWS\system32\CRYPTUI.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\hpzidr12.dll
    C:\WINDOWS\system32\hpzipr12.dll
    C:\WINDOWS\system32\IMAGEHLP.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\MFC42.DLL
    C:\WINDOWS\system32\mlang.dll
    C:\WINDOWS\system32\MSASN1.dll
    C:\WINDOWS\system32\MSCTF.dll
    C:\WINDOWS\system32\msctfime.ime
    C:\WINDOWS\system32\mshtml.dll
    C:\WINDOWS\system32\msi.dll
    C:\WINDOWS\system32\msimtf.dll
    C:\WINDOWS\system32\mslbui.dll
    C:\WINDOWS\system32\msls31.dll
    C:\WINDOWS\system32\MSVCP60.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\MSVFW32.dll
    C:\WINDOWS\system32\NETAPI32.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEACC.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\PSAPI.DLL
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\Secur32.dll
    C:\WINDOWS\system32\SETUPAPI.dll
    C:\WINDOWS\system32\shdoclc.dll
    C:\WINDOWS\system32\shdocvw.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\SHFOLDER.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\SXS.DLL
    C:\WINDOWS\system32\urlmon.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\USERENV.dll
    C:\WINDOWS\system32\uxtheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\WININET.dll
    C:\WINDOWS\system32\WINMM.dll
    C:\WINDOWS\system32\WINSPOOL.DRV
    C:\WINDOWS\system32\WINSTA.dll
    C:\WINDOWS\system32\WINTRUST.dll
    C:\WINDOWS\system32\WLDAP32.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\system32\WSOCK32.dll
    C:\WINDOWS\system32\WTSAPI32.DLL
    C:\WINDOWS\system32\xpsp2res.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (64)]
    C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\IadHide5.dll
    c:\progra~1\mcafee.com\vso\McVSSkt.dll
    c:\Program Files\HP\Digital Imaging\bin\hphtra08.dll
    C:\Program Files\HP\Digital Imaging\bin\hpoddcomm09.dll
    c:\Program Files\HP\Digital Imaging\bin\hpodio08.dll
    c:\Program Files\HP\Digital Imaging\bin\hpodvd09.dll
    c:\Program Files\HP\Digital Imaging\bin\hpotra08.dll
    c:\Program Files\HP\Digital Imaging\bin\hpotra08.rsc
    c:\Program Files\HP\Digital Imaging\bin\hpotradd.dll
    c:\Program Files\HP\Digital Imaging\bin\hpqcob08.dll
    c:\Program Files\HP\Digital Imaging\bin\hpqcxm08.dll
    c:\Program Files\HP\Digital Imaging\bin\hpqmif08.dll
    c:\Program Files\HP\Digital Imaging\bin\hpqtao08.dll
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.rsc
    c:\Program Files\HP\Digital Imaging\bin\hpquio08.dll
    c:\Program Files\HP\Digital Imaging\bin\HpqUtil.dll
    c:\Program Files\HP\Digital Imaging\Unload\hpiCamTA.dll
    c:\Program Files\HP\Digital Imaging\Unload\HpqUnRes.dll
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\ATL71.DLL
    C:\WINDOWS\system32\CFGMGR32.dll
    C:\WINDOWS\system32\CLBCATQ.DLL
    C:\WINDOWS\system32\COMCTL32.dll
    C:\WINDOWS\system32\COMRes.dll
    C:\WINDOWS\system32\CRYPT32.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\hpzidr12.dll
    C:\WINDOWS\system32\hpzipr12.dll
    C:\WINDOWS\system32\IMAGEHLP.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\MFC71.DLL
    C:\WINDOWS\system32\MFC71ENU.DLL
    C:\WINDOWS\system32\MPR.dll
    C:\WINDOWS\system32\MSASN1.dll
    C:\WINDOWS\system32\MSCTF.dll
    C:\WINDOWS\system32\msctfime.ime
    C:\WINDOWS\system32\msi.dll
    C:\WINDOWS\system32\MSVCP60.dll
    C:\WINDOWS\system32\MSVCP71.dll
    C:\WINDOWS\system32\MSVCR71.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\NETAPI32.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\SETUPAPI.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\SHFOLDER.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\SXS.DLL
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\uxtheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\WINSPOOL.DRV
    C:\WINDOWS\system32\WINSTA.dll
    C:\WINDOWS\system32\WINTRUST.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\system32\WSOCK32.dll
    C:\WINDOWS\system32\WTSAPI32.DLL
    C:\WINDOWS\system32\xpsp2res.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [c:\program files\mcafee.com\agent\mcagent.exe (32)]
    c:\progra~1\mcafee.com\vso\McVSSkt.dll
    c:\program files\mcafee.com\agent\mcagntps.dll
    c:\program files\mcafee.com\agent\SCRes.dll
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\CLBCATQ.DLL
    C:\WINDOWS\system32\comctl32.dll
    C:\WINDOWS\system32\COMRes.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\MSCTF.dll
    C:\WINDOWS\system32\msctfime.ime
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\msxml3.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\NTMARTA.DLL
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\SAMLIB.dll
    C:\WINDOWS\system32\SETUPAPI.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\uxtheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\WINHTTP.dll
    C:\WINDOWS\system32\WLDAP32.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\system32\xpsp2res.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [c:\program files\mcafee.com\agent\mcdetect.exe (27)]
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\CLBCATQ.DLL
    C:\WINDOWS\system32\COMRes.dll
    C:\WINDOWS\system32\DNSAPI.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\MSVCP60.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\NETAPI32.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\NTDSAPI.dll
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\Secur32.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\uxtheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\wbem\fastprox.dll
    C:\WINDOWS\system32\wbem\wbemcomn.dll
    C:\WINDOWS\system32\wbem\wbemprox.dll
    C:\WINDOWS\system32\wbem\wbemsvc.dll
    C:\WINDOWS\system32\WLDAP32.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\system32\xpsp2res.dll

    [C:\Program Files\McAfee.com\VSO\mcvsshld.exe (36)]
    c:\progra~1\mcafee.com\vso\McVSSkt.dll
    c:\program files\mcafee.com\agent\mcagntps.dll
    c:\program files\mcafee.com\agent\submgr\6,0,0,15\mcsubmgr.dll
    C:\Program Files\McAfee.com\VSO\ashldres.dll
    C:\Program Files\McAfee.com\VSO\VsCfgW32.dll
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\Apphelp.dll
    C:\WINDOWS\system32\CLBCATQ.DLL
    C:\WINDOWS\system32\comctl32.dll
    C:\WINDOWS\system32\COMRes.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\MSCTF.dll
    C:\WINDOWS\system32\msctfime.ime
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\msxml3.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\NTMARTA.DLL
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\SAMLIB.dll
    C:\WINDOWS\system32\Secur32.dll
    C:\WINDOWS\system32\SETUPAPI.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\uxtheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\WINHTTP.dll
    C:\WINDOWS\system32\WLDAP32.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\system32\xpsp2res.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [C:\Program Files\Messenger\msmsgs.exe (43)]
    c:\progra~1\mcafee.com\vso\McVSSkt.dll
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\Apphelp.dll
    C:\WINDOWS\system32\CLBCATQ.DLL
    C:\WINDOWS\system32\comdlg32.dll
    C:\WINDOWS\system32\COMRes.dll
    C:\WINDOWS\system32\credui.dll
    C:\WINDOWS\system32\CRYPT32.dll
    C:\WINDOWS\system32\cryptdll.dll
    C:\WINDOWS\system32\es.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\iphlpapi.dll
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\MSASN1.dll
    C:\WINDOWS\system32\MSCTF.dll
    C:\WINDOWS\system32\msctfime.ime
    C:\WINDOWS\system32\msi.dll
    C:\WINDOWS\system32\MSIMG32.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\NETAPI32.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\Secur32.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\SXS.DLL
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\uxtheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\WININET.dll
    C:\WINDOWS\system32\WINMM.dll
    C:\WINDOWS\system32\WINSTA.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\system32\WSOCK32.dll
    C:\WINDOWS\system32\wtsapi32.dll
    C:\WINDOWS\system32\XPOB2RES.DLL
    C:\WINDOWS\system32\xpsp2res.dll
    C:\WINDOWS\WinSxS\X86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\COMCTL32.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2180_x-ww_522f9f82\gdiplus.dll

    [C:\Program Files\Mozilla Firefox\firefox.exe (79)]
    C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\IadHide5.dll
    c:\progra~1\mcafee.com\vso\McVSSkt.dll
    C:\Program Files\CE\nmsvc.dll
    C:\Program Files\CE\nmsvTree.dll
    C:\Program Files\Mozilla Firefox\components\jar50.dll
    C:\Program Files\Mozilla Firefox\js3250.dll
    C:\Program Files\Mozilla Firefox\nspr4.dll
    C:\Program Files\Mozilla Firefox\nss3.dll
    C:\Program Files\Mozilla Firefox\nssckbi.dll
    C:\Program Files\Mozilla Firefox\plc4.dll
    C:\Program Files\Mozilla Firefox\plds4.dll
    C:\Program Files\Mozilla Firefox\plugins\NPSWF32.dll
    C:\Program Files\Mozilla Firefox\smime3.dll
    C:\Program Files\Mozilla Firefox\softokn3.dll
    C:\Program Files\Mozilla Firefox\ssl3.dll
    C:\Program Files\Mozilla Firefox\xpcom_compat.dll
    C:\Program Files\Mozilla Firefox\xpcom_core.dll
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\appHelp.dll
    C:\WINDOWS\system32\ATL.DLL
    C:\WINDOWS\system32\browseui.dll
    C:\WINDOWS\system32\CESpy.dll
    C:\WINDOWS\system32\CLBCATQ.DLL
    C:\WINDOWS\system32\comdlg32.dll
    C:\WINDOWS\system32\COMRes.dll
    C:\WINDOWS\system32\CRYPT32.dll
    C:\WINDOWS\system32\CRYPTUI.dll
    C:\WINDOWS\System32\CSCDLL.dll
    C:\WINDOWS\System32\cscui.dll
    C:\WINDOWS\system32\DNSAPI.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\hnetcfg.dll
    C:\WINDOWS\system32\IMAGEHLP.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\LINKINFO.dll
    C:\WINDOWS\system32\midimap.dll
    C:\WINDOWS\system32\mlang.dll
    C:\WINDOWS\system32\MSACM32.dll
    C:\WINDOWS\system32\msacm32.drv
    C:\WINDOWS\system32\MSASN1.dll
    C:\WINDOWS\system32\MSCTF.dll
    C:\WINDOWS\system32\msctfime.ime
    C:\WINDOWS\system32\msimg32.dll
    C:\WINDOWS\system32\msimtf.dll
    C:\WINDOWS\system32\mslbui.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\mswsock.dll
    C:\WINDOWS\system32\NETAPI32.dll
    C:\WINDOWS\System32\nmNsp.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\ntshrui.dll
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\rasadhlp.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\schannel.dll
    C:\WINDOWS\system32\Secur32.dll
    C:\WINDOWS\system32\SETUPAPI.dll
    C:\WINDOWS\system32\shdocvw.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\USERENV.dll
    C:\WINDOWS\system32\uxtheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\wdmaud.drv
    C:\WINDOWS\system32\WININET.dll
    C:\WINDOWS\system32\WINMM.dll
    C:\WINDOWS\System32\winrnr.dll
    C:\WINDOWS\system32\WINSPOOL.DRV
    C:\WINDOWS\system32\WINTRUST.dll
    C:\WINDOWS\system32\WLDAP32.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\System32\wshtcpip.dll
    C:\WINDOWS\system32\WSOCK32.dll
    C:\WINDOWS\system32\xpsp2res.dll
    C:\WINDOWS\WinSxS\X86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\COMCTL32.dll

    [C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe (74)]
    C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\IadHide5.dll
    c:\progra~1\mcafee.com\vso\McVSSkt.dll
    C:\PROGRA~1\UPDATE~1\9972322\632~1.116\program\EN\ClientRC.dll
    C:\Program Files\CE\nmsvc.dll
    C:\Program Files\CE\nmsvTree.dll
    C:\Program Files\Updates from HP\9972322\6.3.2.116-9972322\Program\BackWeb.dll
    C:\Program Files\Updates from HP\9972322\6.3.2.116-9972322\Program\BWfiles.dll
    C:\Program Files\Updates from HP\9972322\6.3.2.116-9972322\Program\bwsec.dll
    C:\Program Files\Updates from HP\9972322\6.3.2.116-9972322\Program\clntutil.dll
    C:\Program Files\Updates from HP\9972322\6.3.2.116-9972322\Program\frext.dll
    C:\Program Files\Updates from HP\9972322\Program\BWfiles-9972322.dll
    C:\Program Files\Updates from HP\9972322\Program\frext-9972322.dll
    C:\Program Files\Updates from HP\9972322\Program\HPClientExt.dll
    C:\WINDOWS\system32\ACTIVEDS.dll
    C:\WINDOWS\system32\adsldpc.dll
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\ATL.DLL
    C:\WINDOWS\system32\CESpy.dll
    C:\WINDOWS\system32\CLBCATQ.DLL
    C:\WINDOWS\system32\comctl32.dll
    C:\WINDOWS\system32\COMRes.dll
    C:\WINDOWS\system32\CRYPT32.dll
    C:\WINDOWS\system32\DNSAPI.dll
    C:\WINDOWS\system32\feclient.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\hnetcfg.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\inetmib1.dll
    C:\WINDOWS\system32\iphlpapi.dll
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\MFC42.DLL
    C:\WINDOWS\system32\MPR.dll
    C:\WINDOWS\system32\MPRAPI.dll
    C:\WINDOWS\system32\MSASN1.dll
    C:\WINDOWS\system32\MSCTF.dll
    C:\WINDOWS\system32\msctfime.ime
    C:\WINDOWS\system32\msi.dll
    C:\WINDOWS\system32\MSVCP60.dll
    C:\WINDOWS\system32\MSVCRT.dll
    C:\WINDOWS\system32\mswsock.dll
    C:\WINDOWS\system32\NETAPI32.dll
    C:\WINDOWS\System32\nmNsp.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\rasadhlp.dll
    C:\WINDOWS\system32\rasapi32.dll
    C:\WINDOWS\system32\rasman.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\rtutils.dll
    C:\WINDOWS\system32\SAMLIB.dll
    C:\WINDOWS\system32\Secur32.dll
    C:\WINDOWS\system32\SETUPAPI.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\snmpapi.dll
    C:\WINDOWS\system32\SXS.DLL
    C:\WINDOWS\system32\TAPI32.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\USERENV.dll
    C:\WINDOWS\system32\uxtheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\WININET.dll
    C:\WINDOWS\system32\WINMM.dll
    C:\WINDOWS\System32\winrnr.dll
    C:\WINDOWS\system32\WINSTA.dll
    C:\WINDOWS\system32\WLDAP32.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\System32\wshtcpip.dll
    C:\WINDOWS\system32\WSOCK32.dll
    C:\WINDOWS\system32\wtsapi32.dll
    C:\WINDOWS\system32\xpsp2res.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [C:\WINDOWS\arservice.exe (22)]
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\CRYPT32.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMAGEHLP.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\midimap.dll
    C:\WINDOWS\system32\MSACM32.dll
    C:\WINDOWS\system32\msacm32.drv
    C:\WINDOWS\system32\MSASN1.dll
    C:\WINDOWS\system32\msctfime.ime
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\POWRPROF.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\SETUPAPI.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\uxtheme.dll
    C:\WINDOWS\system32\wdmaud.drv
    C:\WINDOWS\system32\WINMM.dll
    C:\WINDOWS\system32\WINTRUST.dll

    [C:\WINDOWS\eHome\ehRecvr.exe (88)]
    C:\Documents and Settings\All Users\DRM\IndivBox.key
    C:\WINDOWS\eHome\ehTrace.dll
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\ATL.DLL
    C:\WINDOWS\system32\CLBCATQ.DLL
    C:\WINDOWS\system32\comctl32.dll
    C:\WINDOWS\system32\COMRes.dll
    C:\WINDOWS\system32\CRYPT32.dll
    C:\WINDOWS\system32\devenum.dll
    C:\WINDOWS\system32\drmv2clt.dll
    C:\WINDOWS\system32\dsound.dll
    C:\WINDOWS\system32\DVobSub.ax
    C:\WINDOWS\system32\encapi.dll
    C:\WINDOWS\system32\encdec.dll
    C:\WINDOWS\system32\faultrep.DLL
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\hcwCCnv2.ax
    C:\WINDOWS\system32\hcwECP.ax
    C:\WINDOWS\system32\hcwXDS.dll
    C:\WINDOWS\system32\IMAGEHLP.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\ksproxy.ax
    C:\WINDOWS\system32\kstvtune.ax
    C:\WINDOWS\system32\ksuser.dll
    C:\WINDOWS\system32\kswdmcap.ax
    C:\WINDOWS\system32\ksxbar.ax
    C:\WINDOWS\system32\MFC42.DLL
    C:\WINDOWS\system32\MFC42u.DLL
    C:\WINDOWS\system32\MFPlat.DLL
    C:\WINDOWS\system32\midimap.dll
    C:\WINDOWS\system32\mlang.dll
    C:\WINDOWS\system32\mpg2splt.ax
    C:\WINDOWS\system32\MSACM32.dll
    C:\WINDOWS\system32\msacm32.drv
    C:\WINDOWS\system32\msadds32.ax
    C:\WINDOWS\system32\MSASN1.dll
    C:\WINDOWS\system32\msdmo.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\msvidctl.dll
    C:\WINDOWS\system32\NETAPI32.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\NTMARTA.DLL
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\OLEPRO32.DLL
    C:\WINDOWS\system32\PSAPI.DLL
    C:\WINDOWS\system32\qasf.dll
    C:\WINDOWS\system32\quartz.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\SAMLIB.dll
    C:\WINDOWS\system32\sbe.dll
    C:\WINDOWS\system32\sbeio.dll
    C:\WINDOWS\system32\Secur32.dll
    C:\WINDOWS\system32\SETUPAPI.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\USERENV.dll
    C:\WINDOWS\system32\uxtheme.dll
    C:\WINDOWS\system32\VBICodec.ax
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\vidcap.ax
    C:\WINDOWS\system32\vobsub.dll
    C:\WINDOWS\system32\wdmaud.drv
    C:\WINDOWS\system32\WININET.dll
    C:\WINDOWS\system32\WINMM.dll
    C:\WINDOWS\system32\WINSTA.dll
    C:\WINDOWS\system32\WINTRUST.dll
    C:\WINDOWS\system32\WLDAP32.dll
    C:\WINDOWS\system32\wmadmod.dll
    C:\WINDOWS\system32\wmadmoe.dll
    C:\WINDOWS\system32\WMASF.DLL
    C:\WINDOWS\system32\WMDRMSDK.DLL
    C:\WINDOWS\system32\wmspdmoe.dll
    C:\WINDOWS\system32\wmv8ds32.ax
    C:\WINDOWS\system32\WMVCore.DLL
    C:\WINDOWS\system32\WMVDECOD.dll
    C:\WINDOWS\system32\wmvdmoe2.dll
    C:\WINDOWS\system32\wmvds32.ax
    C:\WINDOWS\system32\WMVENCOD.dll
    C:\WINDOWS\system32\WMVXENCD.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\system32\wsock32.dll
    C:\WINDOWS\system32\WTSAPI32.dll
    C:\WINDOWS\system32\xpsp2res.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [C:\WINDOWS\eHome\ehSched.exe (17)]
    C:\WINDOWS\eHome\ehProxy.dll
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\ATL.DLL
    C:\WINDOWS\system32\CLBCATQ.DLL
    C:\WINDOWS\system32\COMRes.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\uxtheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\xpsp2res.dll

    [C:\WINDOWS\Explorer.EXE (101)]
    C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\IadHide5.dll
    C:\PROGRA~1\ACCELE~1\StopSign\webcbrowse.dll
    C:\PROGRA~1\COMMON~1\EACCEL~1\INSTAL~1\eaccelsetup0.dll
    C:\PROGRA~1\EACCEL~1\OnAccess\sehk.dll
    c:\progra~1\mcafee.com\vso\mcvsshl.dll
    c:\progra~1\mcafee.com\vso\McVSSkt.dll
    c:\progra~1\mcafee.com\vso\ShlRes.dll
    C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    C:\Program Files\Acceleration Software\Anti-Virus\dsshell.dll
    C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
    C:\Program Files\BreakPoint Software\Hex Workshop 4.2\hwext.dll
    C:\WINDOWS\AppPatch\AcGenral.DLL
    C:\WINDOWS\system32\ACTXPRXY.DLL
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\appHelp.dll
    C:\WINDOWS\system32\ATL.DLL
    C:\WINDOWS\system32\BatMeter.dll
    C:\WINDOWS\system32\browselc.dll
    C:\WINDOWS\system32\BROWSEUI.dll
    C:\WINDOWS\system32\CLBCATQ.DLL
    C:\WINDOWS\system32\comctl32.dll
    C:\WINDOWS\system32\comdlg32.dll
    C:\WINDOWS\system32\COMRes.dll
    C:\WINDOWS\system32\credui.dll
    C:\WINDOWS\system32\CRYPT32.dll
    C:\WINDOWS\system32\CRYPTUI.dll
    C:\WINDOWS\System32\CSCDLL.dll
    C:\WINDOWS\System32\cscui.dll
    C:\WINDOWS\System32\davclnt.dll
    C:\WINDOWS\System32\drprov.dll
    C:\WINDOWS\system32\DUSER.dll
    C:\WINDOWS\system32\FXSAPI.dll
    C:\WINDOWS\system32\fxsst.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMAGEHLP.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\iphlpapi.dll
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\LINKINFO.dll
    C:\WINDOWS\system32\MPR.dll
    C:\WINDOWS\system32\MSACM32.dll
    C:\WINDOWS\system32\MSASN1.dll
    C:\WINDOWS\system32\MSCTF.dll
    C:\WINDOWS\system32\msctfime.ime
    C:\WINDOWS\system32\msi.dll
    C:\WINDOWS\system32\MSIMG32.dll
    C:\WINDOWS\system32\mslbui.dll
    C:\WINDOWS\system32\msutb.dll
    C:\WINDOWS\system32\MSVCR71.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\mydocs.dll
    C:\WINDOWS\system32\NETAPI32.dll
    C:\WINDOWS\System32\NETRAP.dll
    C:\WINDOWS\system32\NETSHELL.dll
    C:\WINDOWS\System32\NETUI0.dll
    C:\WINDOWS\System32\NETUI1.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\System32\ntlanman.dll
    C:\WINDOWS\system32\NTMARTA.DLL
    C:\WINDOWS\system32\ntshrui.dll
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\olepro32.dll
    C:\WINDOWS\system32\PortableDeviceApi.dll
    C:\WINDOWS\system32\PortableDeviceTypes.dll
    C:\WINDOWS\system32\POWRPROF.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\rsaenh.dll
    C:\WINDOWS\system32\rtutils.dll
    C:\WINDOWS\system32\SAMLIB.dll
    C:\WINDOWS\system32\Secur32.dll
    C:\WINDOWS\system32\SETUPAPI.dll
    C:\WINDOWS\system32\SHDOCVW.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\ShimEng.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\stobject.dll
    C:\WINDOWS\system32\SXS.DLL
    C:\WINDOWS\system32\themeui.dll
    C:\WINDOWS\system32\urlmon.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\USERENV.dll
    C:\WINDOWS\system32\UxTheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\webcheck.dll
    C:\WINDOWS\system32\WINHTTP.dll
    C:\WINDOWS\system32\WININET.dll
    C:\WINDOWS\system32\WINMM.dll
    C:\WINDOWS\system32\WINSPOOL.DRV
    C:\WINDOWS\system32\WINSTA.dll
    C:\WINDOWS\system32\WINTRUST.dll
    C:\WINDOWS\system32\WLDAP32.dll
    C:\WINDOWS\system32\WPDShServiceObj.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\system32\WSOCK32.dll
    C:\WINDOWS\system32\WTSAPI32.dll
    C:\WINDOWS\system32\xpsp2res.dll
    C:\WINDOWS\system32\zipfldr.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [C:\WINDOWS\runservice.exe (9)]
    C:\WINDOWS\mmfs.dll
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\USER32.dll

    [C:\WINDOWS\system32\ctfmon.exe (26)]
    c:\progra~1\mcafee.com\vso\McVSSkt.dll
    C:\WINDOWS\AppPatch\AcGenral.DLL
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\MSACM32.dll
    C:\WINDOWS\system32\MSCTF.dll
    C:\WINDOWS\system32\msctfime.ime
    C:\WINDOWS\system32\MSUTB.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\ShimEng.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\USERENV.dll
    C:\WINDOWS\system32\UxTheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\WINMM.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [C:\WINDOWS\system32\CTsvcCDA.EXE (7)]
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\USER32.dll

    [C:\WINDOWS\system32\dllhost.exe (40)]
    C:\WINDOWS\AppPatch\AcGenral.DLL
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\CLBCATQ.DLL
    C:\WINDOWS\system32\CLUSAPI.DLL
    C:\WINDOWS\system32\colbact.DLL
    C:\WINDOWS\system32\comctl32.dll
    C:\WINDOWS\system32\COMRes.dll
    C:\WINDOWS\system32\COMSVCS.DLL
    C:\WINDOWS\system32\ES.DLL
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\MSACM32.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\MTXCLU.DLL
    C:\WINDOWS\system32\NETAPI32.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\RESUTILS.DLL
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\rsaenh.dll
    C:\WINDOWS\system32\Secur32.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\ShimEng.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\SXS.DLL
    C:\WINDOWS\system32\txflog.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\USERENV.dll
    C:\WINDOWS\system32\UxTheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\WINMM.dll
    C:\WINDOWS\system32\WINSTA.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\system32\WSOCK32.dll
    C:\WINDOWS\system32\wtsapi32.dll
    C:\WINDOWS\system32\xpsp2res.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [C:\WINDOWS\system32\lsass.exe (58)]
    C:\WINDOWS\AppPatch\AcGenral.DLL
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\AUTHZ.dll
    C:\WINDOWS\system32\CESpy.dll
    C:\WINDOWS\system32\comctl32.dll
    C:\WINDOWS\system32\CRYPT32.dll
    C:\WINDOWS\system32\cryptdll.dll
    C:\WINDOWS\system32\DNSAPI.dll
    C:\WINDOWS\system32\dssenh.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\hnetcfg.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\iphlpapi.dll
    C:\WINDOWS\system32\ipsecsvc.dll
    C:\WINDOWS\system32\kerberos.dll
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\LSASRV.dll
    C:\WINDOWS\system32\MPR.dll
    C:\WINDOWS\system32\MSACM32.dll
    C:\WINDOWS\system32\MSASN1.dll
    C:\WINDOWS\system32\msprivs.dll
    C:\WINDOWS\system32\msv1_0.dll
    C:\WINDOWS\system32\MSVCP60.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\mswsock.dll
    C:\WINDOWS\system32\NETAPI32.dll
    C:\WINDOWS\system32\netlogon.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\NTDSAPI.dll
    C:\WINDOWS\system32\oakley.DLL
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\psbase.dll
    C:\WINDOWS\system32\pstorsvc.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\rsaenh.dll
    C:\WINDOWS\system32\SAMLIB.dll
    C:\WINDOWS\system32\SAMSRV.dll
    C:\WINDOWS\system32\scecli.dll
    C:\WINDOWS\system32\schannel.dll
    C:\WINDOWS\system32\Secur32.dll
    C:\WINDOWS\system32\setupapi.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\ShimEng.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\USERENV.dll
    C:\WINDOWS\system32\UxTheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\w32time.dll
    C:\WINDOWS\system32\wdigest.dll
    C:\WINDOWS\system32\WINIPSEC.DLL
    C:\WINDOWS\system32\WINMM.dll
    C:\WINDOWS\system32\WLDAP32.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\System32\wshtcpip.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [C:\WINDOWS\system32\nvsvc32.exe (33)]
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\Apphelp.dll
    C:\WINDOWS\system32\COMCTL32.dll
    C:\WINDOWS\system32\CRYPT32.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMAGEHLP.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\iphlpapi.dll
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\MSASN1.dll
    C:\WINDOWS\system32\msctfime.ime
    C:\WINDOWS\system32\msv1_0.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\NETAPI32.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\NTMARTA.DLL
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\POWRPROF.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\SAMLIB.dll
    C:\WINDOWS\system32\secur32.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\USERENV.dll
    C:\WINDOWS\system32\UxTheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\WINSTA.dll
    C:\WINDOWS\system32\WINTRUST.dll
    C:\WINDOWS\system32\WLDAP32.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\system32\wtsapi32.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [C:\WINDOWS\system32\RUNDLL32.EXE (28)]
    c:\progra~1\mcafee.com\vso\McVSSkt.dll
    C:\WINDOWS\AppPatch\AcGenral.DLL
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\comctl32.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMAGEHLP.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\MSACM32.dll
    C:\WINDOWS\system32\MSCTF.dll
    C:\WINDOWS\system32\msctfime.ime
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\NvMcTray.dll
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\ShimEng.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\USERENV.dll
    C:\WINDOWS\system32\UxTheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\WINMM.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [C:\WINDOWS\system32\services.exe (35)]
    C:\WINDOWS\AppPatch\AcGenral.DLL
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\Apphelp.dll
    C:\WINDOWS\system32\AUTHZ.dll
    C:\WINDOWS\system32\comctl32.dll
    C:\WINDOWS\system32\eventlog.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\MSACM32.dll
    C:\WINDOWS\system32\MSVCP60.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\NCObjAPI.DLL
    C:\WINDOWS\system32\NETAPI32.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\PSAPI.DLL
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\SCESRV.dll
    C:\WINDOWS\system32\secur32.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\ShimEng.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\umpnpmgr.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\USERENV.dll
    C:\WINDOWS\system32\UxTheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\WINMM.dll
    C:\WINDOWS\system32\WINSTA.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\system32\wtsapi32.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [C:\WINDOWS\System32\smss.exe (1)]
    C:\WINDOWS\system32\ntdll.dll

    [C:\WINDOWS\system32\spoolsv.exe (65)]
    C:\WINDOWS\AppPatch\AcGenral.DLL
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\CLBCATQ.DLL
    C:\WINDOWS\system32\CLUSAPI.dll
    C:\WINDOWS\system32\cnbjmon.dll
    C:\WINDOWS\system32\comctl32.dll
    C:\WINDOWS\system32\COMRes.dll
    C:\WINDOWS\system32\CRYPT32.dll
    C:\WINDOWS\system32\DNSAPI.dll
    C:\WINDOWS\system32\FXSEVENT.dll
    C:\WINDOWS\system32\FXSMON.DLL
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\hptcpmib.dll
    C:\WINDOWS\system32\HpTcpMon.dll
    C:\WINDOWS\system32\HPTcpMUI.dll
    C:\WINDOWS\system32\hpz3l3xu.dll
    C:\WINDOWS\system32\hpzjrd01.dll
    C:\WINDOWS\system32\IMAGEHLP.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\inetpp.dll
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\localspl.dll
    C:\WINDOWS\system32\mdimon.dll
    C:\WINDOWS\system32\mgmtapi.dll
    C:\WINDOWS\system32\MSACM32.dll
    C:\WINDOWS\system32\MSASN1.dll
    C:\WINDOWS\system32\msi.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\System32\mswsock.dll
    C:\WINDOWS\system32\netapi32.dll
    C:\WINDOWS\system32\NETRAP.dll
    C:\WINDOWS\System32\nmNsp.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\NTDSAPI.dll
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\pjlmon.dll
    C:\WINDOWS\system32\rasadhlp.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\Secur32.dll
    C:\WINDOWS\system32\sfc_os.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\ShimEng.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\snmpapi.dll
    C:\WINDOWS\System32\spool\PRTPROCS\W32X86\hpzpp3xu.dll
    C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll
    C:\WINDOWS\system32\SPOOLSS.DLL
    C:\WINDOWS\system32\tcpmon.dll
    C:\WINDOWS\system32\usbmon.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\USERENV.dll
    C:\WINDOWS\system32\UxTheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\win32spl.dll
    C:\WINDOWS\system32\WINMM.dll
    C:\WINDOWS\System32\winrnr.dll
    C:\WINDOWS\system32\winspool.drv
    C:\WINDOWS\system32\WINTRUST.dll
    C:\WINDOWS\system32\WLDAP32.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\system32\wsnmp32.dll
    C:\WINDOWS\system32\xpsp2res.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [C:\WINDOWS\System32\svchost.exe (148)]
    C:\WINDOWS\AppPatch\AcGenral.DLL
    c:\windows\pchealth\helpctr\binaries\pchsvc.dll
    C:\WINDOWS\System32\ACTIVEDS.dll
    C:\WINDOWS\System32\adsldpc.dll
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\System32\ADVPACK.dll
    C:\WINDOWS\system32\Apphelp.dll
    c:\windows\system32\ATL.DLL
    c:\windows\system32\audiosrv.dll
    c:\windows\system32\AUTHZ.dll
    c:\windows\system32\browser.dll
    C:\WINDOWS\System32\Cabinet.dll
    c:\windows\system32\certcli.dll
    C:\WINDOWS\System32\CESpy.dll
    C:\WINDOWS\System32\CLBCATQ.DLL
    C:\WINDOWS\System32\CLUSAPI.DLL
    C:\WINDOWS\system32\colbact.DLL
    C:\WINDOWS\system32\comctl32.dll
    C:\WINDOWS\System32\COMRes.dll
    C:\WINDOWS\system32\comsvcs.dll
    c:\windows\system32\credui.dll
    C:\WINDOWS\system32\CRYPT32.dll
    C:\WINDOWS\System32\cryptdll.dll
    c:\windows\system32\cryptsvc.dll
    C:\WINDOWS\system32\CRYPTUI.dll
    c:\windows\system32\dhcpcsvc.dll
    c:\windows\system32\dmserver.dll
    c:\windows\system32\DNSAPI.dll
    c:\windows\system32\ersvc.dll
    c:\windows\system32\es.dll
    c:\windows\system32\ESENT.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\System32\h323.tsp
    C:\WINDOWS\System32\HID.DLL
    C:\WINDOWS\System32\hidphone.tsp
    C:\WINDOWS\System32\hnetcfg.dll
    C:\WINDOWS\system32\IMAGEHLP.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\System32\ipconf.tsp
    c:\windows\system32\iphlpapi.dll
    c:\windows\system32\ipnathlp.dll
    C:\WINDOWS\system32\kerberos.dll
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\System32\kmddsp.tsp
    C:\WINDOWS\system32\modemui.dll
    C:\WINDOWS\System32\MPRAPI.dll
    C:\WINDOWS\System32\MSACM32.dll
    C:\WINDOWS\system32\MSASN1.dll
    c:\windows\system32\msi.dll
    C:\WINDOWS\System32\MSIDLE.DLL
    C:\WINDOWS\System32\mspatcha.dll
    C:\WINDOWS\system32\msv1_0.dll
    c:\windows\system32\MSVCP60.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\mswsock.dll
    C:\WINDOWS\system32\MTXCLU.DLL
    C:\WINDOWS\system32\NCObjAPI.DLL
    C:\WINDOWS\System32\ndptsp.tsp
    C:\WINDOWS\system32\NETAPI32.dll
    C:\WINDOWS\system32\netcfgx.dll
    c:\windows\system32\netman.dll
    c:\windows\system32\netshell.dll
    C:\WINDOWS\system32\ntdll.dll
    c:\windows\system32\NTDSAPI.dll
    C:\WINDOWS\System32\ntlsapi.dll
    C:\WINDOWS\System32\NTMARTA.DLL
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    c:\windows\system32\POWRPROF.dll
    c:\windows\system32\PSAPI.DLL
    C:\WINDOWS\System32\rasadhlp.dll
    C:\WINDOWS\System32\RASAPI32.dll
    C:\WINDOWS\System32\raschap.dll
    C:\WINDOWS\System32\RASDLG.dll
    C:\WINDOWS\System32\rasman.dll
    C:\WINDOWS\System32\rasmans.dll
    C:\WINDOWS\System32\rasppp.dll
    C:\WINDOWS\System32\rastapi.dll
    C:\WINDOWS\System32\rastls.dll
    C:\WINDOWS\System32\RESUTILS.DLL
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\System32\rsaenh.dll
    c:\windows\system32\rtutils.dll
    C:\WINDOWS\System32\SAMLIB.dll
    C:\WINDOWS\System32\SCHANNEL.dll
    c:\windows\system32\schedsvc.dll
    c:\windows\system32\seclogon.dll
    c:\windows\system32\Secur32.dll
    c:\windows\system32\sens.dll
    C:\WINDOWS\System32\SETUPAPI.dll
    C:\WINDOWS\System32\sfc.dll
    C:\WINDOWS\System32\sfc_os.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\System32\SHFOLDER.dll
    C:\WINDOWS\System32\ShimEng.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    c:\windows\system32\shsvcs.dll
    c:\windows\system32\srsvc.dll
    c:\windows\system32\srvsvc.dll
    C:\WINDOWS\system32\SSDPAPI.dll
    C:\WINDOWS\System32\SXS.DLL
    C:\WINDOWS\System32\TAPI32.dll
    c:\windows\system32\tapisrv.dll
    c:\windows\system32\trkwks.dll
    C:\WINDOWS\System32\unimdm.tsp
    C:\WINDOWS\System32\unimdmat.dll
    C:\WINDOWS\System32\uniplat.dll
    C:\WINDOWS\system32\upnp.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\USERENV.dll
    C:\WINDOWS\System32\UxTheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\VSSAPI.DLL
    c:\windows\system32\w32time.dll
    C:\WINDOWS\System32\Wbem\esscli.dll
    C:\WINDOWS\System32\Wbem\FastProx.dll
    C:\WINDOWS\system32\wbem\ncprov.dll
    C:\WINDOWS\system32\wbem\repdrvfs.dll
    C:\WINDOWS\system32\wbem\wbemcomn.dll
    C:\WINDOWS\System32\Wbem\wbemcore.dll
    C:\WINDOWS\system32\wbem\wbemess.dll
    C:\WINDOWS\system32\wbem\wbemsvc.dll
    C:\WINDOWS\system32\wbem\wmiprvsd.dll
    c:\windows\system32\wbem\wmisvc.dll
    C:\WINDOWS\system32\wbem\wmiutils.dll
    C:\WINDOWS\System32\WINHTTP.dll
    C:\WINDOWS\system32\WININET.dll
    C:\WINDOWS\System32\WINIPSEC.DLL
    C:\WINDOWS\System32\WINMM.dll
    C:\WINDOWS\System32\WinSCard.dll
    C:\WINDOWS\System32\WINSPOOL.DRV
    C:\WINDOWS\System32\WINSTA.dll
    C:\WINDOWS\system32\WINTRUST.dll
    c:\windows\system32\wkssvc.dll
    C:\WINDOWS\system32\WLDAP32.dll
    c:\windows\system32\WMI.dll
    c:\windows\system32\WS2_32.dll
    c:\windows\system32\WS2HELP.dll
    c:\windows\system32\wscsvc.dll
    C:\WINDOWS\System32\wshtcpip.dll
    C:\WINDOWS\system32\WSOCK32.dll
    c:\windows\system32\WTSAPI32.dll
    C:\WINDOWS\system32\wuaueng.dll
    c:\windows\system32\wuauserv.dll
    c:\windows\system32\WZCSAPI.DLL
    c:\windows\system32\wzcsvc.dll
    C:\WINDOWS\System32\xpsp2res.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [C:\WINDOWS\system32\svchost.exe (36)]
    C:\WINDOWS\AppPatch\AcGenral.DLL
    C:\WINDOWS\system32\ACTXPRXY.DLL
    C:\WINDOWS\system32\ADVAPI32.dll
    c:\windows\system32\CFGMGR32.dll
    C:\WINDOWS\system32\CLBCATQ.DLL
    C:\WINDOWS\system32\comctl32.dll
    C:\WINDOWS\system32\COMRes.dll
    C:\WINDOWS\system32\CRYPT32.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMAGEHLP.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\MSACM32.dll
    C:\WINDOWS\system32\MSASN1.dll
    c:\windows\system32\mscms.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\NETAPI32.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\RPCRT4.dll
    c:\windows\system32\setupapi.DLL
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\ShimEng.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\USERENV.dll
    C:\WINDOWS\system32\UxTheme.dll
    C:\WINDOWS\system32\VERSION.dll
    c:\windows\system32\wiaservc.dll
    C:\WINDOWS\system32\WINMM.dll
    c:\windows\system32\WINSPOOL.DRV
    c:\windows\system32\WINSTA.dll
    C:\WINDOWS\system32\WINTRUST.dll
    C:\WINDOWS\system32\xpsp2res.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [C:\WINDOWS\system32\svchost.exe (51)]
    C:\WINDOWS\AppPatch\AcGenral.DLL
    c:\windows\system32\ACTIVEDS.dll
    c:\windows\system32\adsldpc.dll
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\Apphelp.dll
    c:\windows\system32\ATL.DLL
    c:\windows\system32\AUTHZ.dll
    C:\WINDOWS\system32\CLBCATQ.DLL
    C:\WINDOWS\system32\comctl32.dll
    C:\WINDOWS\system32\COMRes.dll
    C:\WINDOWS\system32\CRYPT32.dll
    C:\WINDOWS\system32\GDI32.dll
    c:\windows\system32\ICAAPI.dll
    C:\WINDOWS\system32\IMAGEHLP.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\iphlpapi.dll
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\MSACM32.dll
    C:\WINDOWS\system32\MSASN1.dll
    c:\windows\system32\mstlsapi.dll
    C:\WINDOWS\system32\msv1_0.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\NETAPI32.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\NTMARTA.DLL
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\REGAPI.dll
    C:\WINDOWS\system32\RPCRT4.dll
    c:\windows\system32\rpcss.dll
    C:\WINDOWS\system32\rsaenh.dll
    C:\WINDOWS\system32\SAMLIB.dll
    c:\windows\system32\Secur32.dll
    c:\windows\system32\SETUPAPI.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\ShimEng.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    c:\windows\system32\termsrv.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\USERENV.dll
    C:\WINDOWS\system32\UxTheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\WINMM.dll
    C:\WINDOWS\system32\WINSTA.dll
    C:\WINDOWS\system32\WINTRUST.dll
    C:\WINDOWS\system32\WLDAP32.dll
    c:\windows\system32\WS2_32.dll
    c:\windows\system32\WS2HELP.dll
    C:\WINDOWS\system32\WTSAPI32.dll
    C:\WINDOWS\system32\xpsp2res.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    [C:\WINDOWS\system32\winlogon.exe (73)]
    C:\WINDOWS\system32\ADVAPI32.dll
    C:\WINDOWS\system32\Apphelp.dll
    C:\WINDOWS\system32\AUTHZ.dll
    C:\WINDOWS\system32\CLBCATQ.DLL
    C:\WINDOWS\system32\COMCTL32.dll
    C:\WINDOWS\system32\comdlg32.dll
    C:\WINDOWS\system32\COMRes.dll
    C:\WINDOWS\system32\CRYPT32.dll
    C:\WINDOWS\system32\cscdll.dll
    C:\WINDOWS\system32\cscui.dll
    C:\WINDOWS\system32\DNSAPI.dll
    C:\WINDOWS\system32\GDI32.dll
    C:\WINDOWS\system32\IMAGEHLP.dll
    C:\WINDOWS\system32\IMM32.DLL
    C:\WINDOWS\system32\iphlpapi.dll
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\midimap.dll
    C:\WINDOWS\system32\MPR.dll
    C:\WINDOWS\system32\MSACM32.dll
    C:\WINDOWS\system32\msacm32.drv
    C:\WINDOWS\system32\MSASN1.dll
    C:\WINDOWS\system32\msctfime.ime
    C:\WINDOWS\system32\MSGINA.dll
    C:\WINDOWS\system32\msv1_0.dll
    C:\WINDOWS\system32\MSVCP60.dll
    C:\WINDOWS\system32\msvcrt.dll
    C:\WINDOWS\system32\msxml3.dll
    C:\WINDOWS\system32\NDdeApi.dll
    C:\WINDOWS\system32\NETAPI32.dll
    C:\WINDOWS\system32\ntdll.dll
    C:\WINDOWS\system32\NTDSAPI.dll
    C:\WINDOWS\system32\NTMARTA.DLL
    C:\WINDOWS\system32\ODBC32.dll
    C:\WINDOWS\system32\odbcint.dll
    C:\WINDOWS\system32\ole32.dll
    C:\WINDOWS\system32\OLEAUT32.dll
    C:\WINDOWS\system32\PROFMAP.dll
    C:\WINDOWS\system32\PSAPI.DLL
    C:\WINDOWS\system32\REGAPI.dll
    C:\WINDOWS\system32\RPCRT4.dll
    C:\WINDOWS\system32\rsaenh.dll
    C:\WINDOWS\system32\SAMLIB.dll
    C:\WINDOWS\system32\Secur32.dll
    C:\WINDOWS\system32\SETUPAPI.dll
    C:\WINDOWS\system32\sfc.dll
    C:\WINDOWS\system32\sfc_os.dll
    C:\WINDOWS\system32\SHELL32.dll
    C:\WINDOWS\system32\SHLWAPI.dll
    C:\WINDOWS\system32\SHSVCS.dll
    C:\WINDOWS\system32\sxs.dll
    C:\WINDOWS\system32\USER32.dll
    C:\WINDOWS\system32\USERENV.dll
    C:\WINDOWS\system32\uxtheme.dll
    C:\WINDOWS\system32\VERSION.dll
    C:\WINDOWS\system32\wbem\fastprox.dll
    C:\WINDOWS\system32\wbem\wbemcomn.dll
    C:\WINDOWS\system32\wbem\wbemprox.dll
    C:\WINDOWS\system32\wbem\wbemsvc.dll
    C:\WINDOWS\system32\wdmaud.drv
    C:\WINDOWS\system32\WgaLogon.dll
    C:\WINDOWS\system32\WINHTTP.dll
    C:\WINDOWS\system32\WINMM.dll
    C:\WINDOWS\system32\WINSCARD.DLL
    C:\WINDOWS\system32\WINSPOOL.DRV
    C:\WINDOWS\system32\WINSTA.dll
    C:\WINDOWS\system32\WINTRUST.dll
    C:\WINDOWS\system32\WLDAP32.dll
    C:\WINDOWS\system32\WlNotify.dll
    C:\WINDOWS\system32\WS2_32.dll
    C:\WINDOWS\system32\WS2HELP.dll
    C:\WINDOWS\system32\WTSAPI32.dll
    C:\WINDOWS\system32\xpsp2res.dll
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

    --------------------

    Autostart folders:

    [Startup (1)]
    desktop.ini

    [User Startup (1)]
    desktop.ini

    [Common Startup (4)]
    Adobe Reader Speed Launch.lnk
    desktop.ini
    HP Digital Imaging Monitor.lnk
    Updates From HP.lnk

    [User Common Startup (4)]
    Adobe Reader Speed Launch.lnk
    desktop.ini
    HP Digital Imaging Monitor.lnk
    Updates From HP.lnk

    --------------------

    IniMapping values:

    System NT shell = explorer.exe
    User screensaver = C:\WINDOWS\system32\logon.scr

    --------------------

    Autorun.inf files:

    [D:\]
    ShellExecute=Info.exe protect.ed 480 480

    --------------------

    Autostarting batch files:

    [autoexec.bat]
    PATH=%PATH%;C:\PROGRA~1\COMMON~1\MUVEET~1\030625

    [autoexec.nt]
    @echo off
    lh %SystemRoot%\system32\mscdexnt.exe
    lh %SystemRoot%\system32\redir
    lh %SystemRoot%\system32\dosx
    SET BLASTER=A220 I5 D1 P330 T3

    [config.nt]
    dos=high, umb
    device=%SystemRoot%\system32\himem.sys
    files=40

    --------------------

    On-reboot actions:

    [Wininit.ini]
    [rename]
    NUL=C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\VIES3C30
    NUL=C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\VIES3FAF

    BootExecute = autocheck autochk *

    [PendingFileRenameOperations]
    C:\WINDOWS\system32\UpperHost.dll -> NULL

    --------------------

    Shell commands:

    .bat - MS-DOS Batch File - "%1" %*
    .cmd - Windows NT Command Script - "%1" %*
    .com - MS-DOS Application - "%1" %*
    .exe - Application - "%1" %*
    .hta - HTML Application - C:\WINDOWS\system32\mshta.exe "%1" %*
    .js - JScript Script File - C:\WINDOWS\System32\WScript.exe "%1" %*
    .jse - JScript Encoded Script File - C:\WINDOWS\System32\WScript.exe "%1" %*
    .pif - Shortcut to MS-DOS Program - "%1" %*
    .scr - Screen Saver - "%1" /S
    .txt - Text Document - C:\WINDOWS\system32\NOTEPAD.EXE %1
    .vbe - VBScript Encoded Script File - C:\WINDOWS\System32\WScript.exe "%1" %*
    .vbs - VBScript Script File - C:\WINDOWS\System32\WScript.exe "%1" %*
    .wsf - Windows Script File - C:\WINDOWS\System32\WScript.exe "%1" %*
    .wsh - Windows Script Host Settings File - C:\WINDOWS\System32\WScript.exe "%1" %*

    --------------------

    Services:

    [NT Services (49)]
    ARSVC = C:\WINDOWS\arservice.exe
    Automatic Updates = C:\WINDOWS\system32\svchost.exe -k netsvcs
    Computer Browser = C:\WINDOWS\system32\svchost.exe -k netsvcs
    Creative Service for CDROM Access = C:\WINDOWS\system32\CTsvcCDA.EXE
    Cryptographic Services = C:\WINDOWS\system32\svchost.exe -k netsvcs
    DCOM Server Process Launcher = C:\WINDOWS\system32\svchost -k DcomLaunch
    DHCP Client = C:\WINDOWS\system32\svchost.exe -k netsvcs
    Distributed Link Tracking Client = C:\WINDOWS\system32\svchost.exe -k netsvcs
    DNS Client = C:\WINDOWS\system32\svchost.exe -k NetworkService
    Error Reporting Service = C:\WINDOWS\System32\svchost.exe -k netsvcs
    Event Log = C:\WINDOWS\system32\services.exe
    FWService = C:\Program Files\Acceleration Software\StopSignProducts\Firewall\fwservice.exe -Service
    Help and Support = C:\WINDOWS\System32\svchost.exe -k netsvcs
    IPSEC Services = C:\WINDOWS\system32\lsass.exe
    LicCtrl Service = C:\WINDOWS\runservice.exe
    LightScribeService Direct Disc Labeling Service = "C:\Program Files\Common Files\LightScribe\LSSrvc.exe"
    Logical Disk Manager = C:\WINDOWS\System32\svchost.exe -k netsvcs
    Machine Debug Manager = "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
    McAfee Task Scheduler = c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    McAfee WSC Integration = c:\program files\mcafee.com\agent\mcdetect.exe
    McAfee.com McShield = c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    Media Center Extender Service = C:\WINDOWS\ehome\mcrdsvc.exe
    Media Center Receiver Service = C:\WINDOWS\eHome\ehRecvr.exe
    Media Center Scheduler Service = C:\WINDOWS\eHome\ehSched.exe
    NVIDIA Display Driver Service = C:\WINDOWS\system32\nvsvc32.exe
    Plug and Play = C:\WINDOWS\system32\services.exe
    Print Spooler = C:\WINDOWS\system32\spoolsv.exe
    Protected Storage = C:\WINDOWS\system32\lsass.exe
    Remote Procedure Call (RPC) = C:\WINDOWS\system32\svchost -k rpcss
    Remote Registry = C:\WINDOWS\system32\svchost.exe -k LocalService
    Secondary Logon = C:\WINDOWS\System32\svchost.exe -k netsvcs
    Security Accounts Manager = C:\WINDOWS\system32\lsass.exe
    Security Center = C:\WINDOWS\System32\svchost.exe -k netsvcs
    Server = C:\WINDOWS\system32\svchost.exe -k netsvcs
    Shell Hardware Detection = C:\WINDOWS\System32\svchost.exe -k netsvcs
    SSDP Discovery Service = C:\WINDOWS\system32\svchost.exe -k LocalService
    System Event Notification = C:\WINDOWS\system32\svchost.exe -k netsvcs
    System Restore Service = C:\WINDOWS\system32\svchost.exe -k netsvcs
    Task Scheduler = C:\WINDOWS\System32\svchost.exe -k netsvcs
    TCP/IP NetBIOS Helper = C:\WINDOWS\system32\svchost.exe -k LocalService
    Themes = C:\WINDOWS\System32\svchost.exe -k netsvcs
    WebClient = C:\WINDOWS\system32\svchost.exe -k LocalService
    Windows Audio = C:\WINDOWS\System32\svchost.exe -k netsvcs
    Windows Firewall/Internet Connection Sharing (ICS) = C:\WINDOWS\system32\svchost.exe -k netsvcs
    Windows Image Acquisition (WIA) = C:\WINDOWS\system32\svchost.exe -k imgsvc
    Windows Management Instrumentation = C:\WINDOWS\system32\svchost.exe -k netsvcs
    Windows Time = C:\WINDOWS\System32\svchost.exe -k netsvcs
    Wireless Zero Configuration = C:\WINDOWS\System32\svchost.exe -k netsvcs
    Workstation = C:\WINDOWS\system32\svchost.exe -k netsvcs

    [SafeBoot services (Minimal boot)]
    * CD-ROM Drive *
    {4D36E965-E325-11CE-BFC1-08002BE10318}

    * DiskDrive *
    {4D36E967-E325-11CE-BFC1-08002BE10318}

    * Driver *
    dmboot.sys
    dmio.sys
    dmload.sys
    sermouse.sys
    vga.sys
    vgasave.sys

    * Driver Group *
    Base
    Boot Bus Extender
    Boot file system
    File system
    Filter
    PCI Configuration
    PNP Filter
    Primary disk
    SCSI Class
    System Bus Extender

    * Floppy disk drive *
    {4D36E980-E325-11CE-BFC1-08002BE10318}

    * FSFilter System Recovery *
    sr.sys

    * Hdc *
    {4D36E96A-E325-11CE-BFC1-08002BE10318}

    * Human Interface Devices *
    {745A17A0-74D3-11D0-B6FE-00A0C90F57DA}

    * Keyboard *
    {4D36E96B-E325-11CE-BFC1-08002BE10318}

    * Mouse *
    {4D36E96F-E325-11CE-BFC1-08002BE10318}

    * PCMCIA Adapters *
    {4D36E977-E325-11CE-BFC1-08002BE10318}

    * SCSIAdapter *
    {4D36E97B-E325-11CE-BFC1-08002BE10318}

    * Service *
    AppMgmt
    CryptSvc
    DcomLaunch
    dmadmin
    dmserver
    EventLog
    HelpSvc
    Netlogon
    PlugPlay
    RpcSs
    SRService
    WinMgmt

    * Standard floppy disk controller *
    {4D36E969-E325-11CE-BFC1-08002BE10318}

    * System *
    {4D36E97D-E325-11CE-BFC1-08002BE10318}

    * Universal Serial Bus controllers *
    {36FC9E60-C465-11CF-8056-444553540000}

    * Volume *
    {71A27CDD-812A-11D0-BEC7-08002BE2092F}


    [SafeBoot services (Minimal boot + network support)]
    * CD-ROM Drive *
    {4D36E965-E325-11CE-BFC1-08002BE10318}

    * DiskDrive *
    {4D36E967-E325-11CE-BFC1-08002BE10318}

    * Driver *
    dmboot.sys
    dmio.sys
    dmload.sys
    ip6fw.sys
    ipnat.sys
    rdpcdd.sys
    rdpdd.sys
    rdpwd.sys
    sermouse.sys
    tdpipe.sys
    tdtcp.sys
    vga.sys
    vgasave.sys

    * Driver Group *
    Base
    Boot Bus Extender
    Boot file system
    File system
    Filter
    NDIS
    NDIS Wrapper
    NetBIOSGroup
    NetDDEGroup
    Network
    NetworkProvider
    PCI Configuration
    PNP Filter
    PNP_TDI
    Primary disk
    SCSI Class
    Streams Drivers
    System Bus Extender
    TDI

    * Floppy disk drive *
    {4D36E980-E325-11CE-BFC1-08002BE10318}

    * FSFilter System Recovery *
    sr.sys

    * Hdc *
    {4D36E96A-E325-11CE-BFC1-08002BE10318}

    * Human Interface Devices *
    {745A17A0-74D3-11D0-B6FE-00A0C90F57DA}

    * Keyboard *
    {4D36E96B-E325-11CE-BFC1-08002BE10318}

    * Mouse *
    {4D36E96F-E325-11CE-BFC1-08002BE10318}

    * Net *
    {4D36E972-E325-11CE-BFC1-08002BE10318}

    * NetClient *
    {4D36E973-E325-11CE-BFC1-08002BE10318}

    * NetService *
    {4D36E974-E325-11CE-BFC1-08002BE10318}

    * NetTrans *
    {4D36E975-E325-11CE-BFC1-08002BE10318}

    * PCMCIA Adapters *
    {4D36E977-E325-11CE-BFC1-08002BE10318}

    * SCSIAdapter *
    {4D36E97B-E325-11CE-BFC1-08002BE10318}

    * Service *
    AFD
    AppMgmt
    Browser
    CryptSvc
    DcomLaunch
    Dhcp
    dmadmin
    dmserver
    DnsCache
    EventLog
    HelpSvc
    LanmanServer
    LanmanWorkstation
    LmHosts
    Messenger
    Ndisuio
    NetBIOS
    NetBT
    Netlogon
    NetMan
    NtLmSsp
    PlugPlay
    rdsessmgr
    RpcSs
    SharedAccess
    SRService
    Tcpip
    termservice
    WinMgmt
    WZCSVC

    * Standard floppy disk controller *
    {4D36E969-E325-11CE-BFC1-08002BE10318}

    * System *
    {4D36E97D-E325-11CE-BFC1-08002BE10318}

    * Universal Serial Bus controllers *
    {36FC9E60-C465-11CF-8056-444553540000}

    * Volume *
    {71A27CDD-812A-11D0-BEC7-08002BE2092F}


    [SafeBoot: Alternate shell]
    cmd.exe (not enabled)

    --------------------

    Driver filters:

    [Class filters]
    * Disk drives *
    - Upper filters
    PartMgr.sys

    * DVD/CD-ROM drives *
    - Upper filters
    GEARAspiWDM.sys

    - Lower filters
    PxHelp20.sys

    * Human Interface Devices *
    - Upper filters
    arhidfltr.sys

    * Infrared devices *
    - Upper filters
    IRENUM.sys

    * Keyboards *
    - Upper filters
    kbdclass.sys
    arkbcfltr.sys

    * Mice and other pointing devices *
    - Upper filters
    mouclass.sys
    armoucfltr.sys

    * Storage volumes *
    - Upper filters
    VolSnap.sys

    * Tape drives *
    - Lower filters
    PxHelp20.sys



    [Device filters]
    * Agere Systems PCI-SV92PP Soft Modem *
    - Lower filters
    AgereSoftModem.sys

    * CD-ROM Drive *
    - Upper filters
    redbook.sys

    * CD-ROM Drive *
    - Upper filters
    redbook.sys

    - Lower filters
    imapi.sys

    * CD-ROM Drive *
    - Upper filters
    redbook.sys

    - Lower filters
    imapi.sys

    * Direct Parallel *
    - Lower filters
    PtiLink.sys

    * Enhanced Mulmedia PS/2 Keyboard *
    - Upper filters
    PS2.sys

    * Saitek P990 Dual Analog Pad (USB) *
    - Lower filters
    SaiU040B.sys

    * Saitek P990 Dual Analog Pad (USB) *
    - Lower filters
    SaiU040B.sys

    * Terminal Server Keyboard Driver *
    - Upper filters
    kbdclass.sys

    * Terminal Server Mouse Driver *
    - Upper filters
    mouclass.sys

    * WAN Miniport (IP) *
    - Lower filters
    NdisTapi.sys

    * WAN Miniport (PPPOE) *
    - Lower filters
    NdisTapi.sys

    * WAN Miniport (PPTP) *
    - Lower filters
    NdisTapi.sys



    --------------------

    Print monitors (9):

    BJ Language Monitor - cnbjmon.dll
    HP Standard TCP/IP Port - HpTcpMon.dll
    Language Monitor - hpz3l3xu.dll
    Local Port - localspl.dll
    Microsoft Document Imaging Writer Monitor - mdimon.dll
    Microsoft Shared Fax Monitor - FXSMON.DLL
    PJL Language Monitor - pjlmon.dll
    Standard TCP/IP Port - tcpmon.dll
    USB Monitor - usbmon.dll

    --------------------

    WinLogon autoruns:

    UserInit = C:\WINDOWS\system32\Userinit.exe
    VmApplet = rundll32 shell32,Control_RunDLL "sysdm.cpl"

    [Notify (10)]
    crypt32chain = crypt32.dll
    cryptnet = cryptnet.dll
    cscdll = cscdll.dll
    ScCertProp = wlnotify.dll
    Schedule = wlnotify.dll
    sclgntfy = sclgntfy.dll
    SensLogn = WlNotify.dll
    termsrv = wlnotify.dll
    WgaLogon = WgaLogon.dll
    wlballoon = wlnotify.dll

    [Group policy extensions (12)]
    Wireless = gptext.dll
    Folder Redirection = fdeploy.dll
    Microsoft Disk Quota = dskquota.dll
    QoS Packet Scheduler = gptext.dll
    Scripts = gptext.dll
    Internet Explorer Zonemapping = iedkcs32.dll
    Security = scecli.dll
    Internet Explorer Branding = iedkcs32.dll
    EFS recovery = scecli.dll
    Microsoft Offline Files = %SystemRoot%\System32\cscui.dll
    Software Installation = appmgmts.dll
    IP Security = gptext.dll

    --------------------

    Policies:

    [This user]
    * Alternate policies *
    - Software\Microsoft\Windows\CurrentVersion\policies\Explorer (1)
    NoDriveTypeAutoRun = dword: 145



    [All users]
    * Primary policies *
    - Software\Policies\Microsoft\Windows\Installer (1)
    EnableAdminTSRemote = dword: 1

    - Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecFilter{72385235-70fa-11d1-864c-14a300000000} (7)
    ClassName = ipsecFilter
    description = Matches all ICMP packets between this computer and any other computer.
    name = ipsecFilter{72385235-70fa-11d1-864c-14a300000000}
    ipsecName = All ICMP Traffic
    ipsecID = {72385235-70fa-11d1-864c-14a300000000}
    ipsecDataType = dword: 256
    whenChanged = dword: 1125464128

    - Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecFilter{7238523a-70fa-11d1-864c-14a300000000} (7)
    ClassName = ipsecFilter
    description = Matches all IP packets from this computer to any other computer, except broadcast, multicast, Kerberos, RSVP and ISAKMP (IKE).
    name = ipsecFilter{7238523a-70fa-11d1-864c-14a300000000}
    ipsecName = All IP Traffic
    ipsecID = {7238523a-70fa-11d1-864c-14a300000000}
    ipsecDataType = dword: 256
    whenChanged = dword: 1125464128

    - Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecISAKMPPolicy{72385231-70fa-11d1-864c-14a300000000} (5)
    ClassName = ipsecISAKMPPolicy
    name = ipsecISAKMPPolicy{72385231-70fa-11d1-864c-14a300000000}
    ipsecID = {72385231-70fa-11d1-864c-14a300000000}
    ipsecDataType = dword: 256
    whenChanged = dword: 1125464128

    - Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecISAKMPPolicy{72385234-70fa-11d1-864c-14a300000000} (5)
    ClassName = ipsecISAKMPPolicy
    name = ipsecISAKMPPolicy{72385234-70fa-11d1-864c-14a300000000}
    ipsecID = {72385234-70fa-11d1-864c-14a300000000}
    ipsecDataType = dword: 256
    whenChanged = dword: 1125464128

    - Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecISAKMPPolicy{72385237-70fa-11d1-864c-14a300000000} (5)
    ClassName = ipsecISAKMPPolicy
    name = ipsecISAKMPPolicy{72385237-70fa-11d1-864c-14a300000000}
    ipsecID = {72385237-70fa-11d1-864c-14a300000000}
    ipsecDataType = dword: 256
    whenChanged = dword: 1125464128

    - Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecISAKMPPolicy{7238523d-70fa-11d1-864c-14a300000000} (5)
    ClassName = ipsecISAKMPPolicy
    name = ipsecISAKMPPolicy{7238523d-70fa-11d1-864c-14a300000000}
    ipsecID = {7238523d-70fa-11d1-864c-14a300000000}
    ipsecDataType = dword: 256
    whenChanged = dword: 1125464128

    - Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNegotiationPolicy{700ddda2-8391-4603-a2b4-76501e88c4b9} (7)
    ClassName = ipsecNegotiationPolicy
    name = ipsecNegotiationPolicy{700ddda2-8391-4603-a2b4-76501e88c4b9}
    ipsecID = {700ddda2-8391-4603-a2b4-76501e88c4b9}
    ipsecNegotiationPolicyAction = {8a171dd3-77e3-11d1-8659-a04f00000000}
    ipsecNegotiationPolicyType = {62f49e13-6c37-11d1-864c-14a300000000}
    ipsecDataType = dword: 256
    whenChanged = dword: 1125464128

    - Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNegotiationPolicy{72385233-70fa-11d1-864c-14a300000000} (9)
    ClassName = ipsecNegotiationPolicy
    description = Accepts unsecured communication, but requests clients to establish trust and security methods. Will communicate insecurely to untrusted clients if they do not respond to request.
    name = ipsecNegotiationPolicy{72385233-70fa-11d1-864c-14a300000000}
    ipsecName = Request Security (Optional)
    ipsecID = {72385233-70fa-11d1-864c-14a300000000}
    ipsecNegotiationPolicyAction = {3f91a81a-7647-11d1-864d-d46a00000000}
    ipsecNegotiationPolicyType = {62f49e10-6c37-11d1-864c-14a300000000}
    ipsecDataType = dword: 256
    whenChanged = dword: 1125464128

    - Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNegotiationPolicy{7238523b-70fa-11d1-864c-14a300000000} (9)
    ClassName = ipsecNegotiationPolicy
    description = Permit unsecured IP packets to pass through.
    name = ipsecNegotiationPolicy{7238523b-70fa-11d1-864c-14a300000000}
    ipsecName = Permit
    ipsecID = {7238523b-70fa-11d1-864c-14a300000000}
    ipsecNegotiationPolicyAction = {8a171dd2-77e3-11d1-8659-a04f00000000}
    ipsecNegotiationPolicyType = {62f49e10-6c37-11d1-864c-14a300000000}
    ipsecDataType = dword: 256
    whenChanged = dword: 1125464128

    - Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNegotiationPolicy{7238523f-70fa-11d1-864c-14a300000000} (9)
    ClassName = ipsecNegotiationPolicy
    description = Accepts unsecured communication, but always requires clients to establish trust and security methods. Will NOT communicate with untrusted clients.
    name = ipsecNegotiationPolicy{7238523f-70fa-11d1-864c-14a300000000}
    ipsecName = Require Security
    ipsecID = {7238523f-70fa-11d1-864c-14a300000000}
    ipsecNegotiationPolicyAction = {3f91a81a-7647-11d1-864d-d46a00000000}
    ipsecNegotiationPolicyType = {62f49e10-6c37-11d1-864c-14a300000000}
    ipsecDataType = dword: 256
    whenChanged = dword: 1125464128

    - Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNegotiationPolicy{b640364d-5acf-4636-8ea0-7f75188b1fd2} (7)
    ClassName = ipsecNegotiationPolicy
    name = ipsecNegotiationPolicy{b640364d-5acf-4636-8ea0-7f75188b1fd2}
    ipsecID = {b640364d-5acf-4636-8ea0-7f75188b1fd2}
    ipsecNegotiationPolicyAction = {8a171dd3-77e3-11d1-8659-a04f00000000}
    ipsecNegotiationPolicyType = {62f49e13-6c37-11d1-864c-14a300000000}
    ipsecDataType = dword: 256
    whenChanged = dword: 1125464128

    - Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNegotiationPolicy{ef7b0aa6-b432-43c6-90ed-3a70ae1eb732} (7)
    ClassName = ipsecNegotiationPolicy
    name = ipsecNegotiationPolicy{ef7b0aa6-b432-43c6-90ed-3a70ae1eb732}
    ipsecID = {ef7b0aa6-b432-43c6-90ed-3a70ae1eb732}
    ipsecNegotiationPolicyAction = {8a171dd3-77e3-11d1-8659-a04f00000000}
    ipsecNegotiationPolicyType = {62f49e13-6c37-11d1-864c-14a300000000}
    ipsecDataType = dword: 256
    whenChanged = dword: 1125464128

    - Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNFA{79a4ee30-f787-49da-9ea6-eca90ae63dc8} (6)
    ClassName = ipsecNFA
    name = ipsecNFA{79a4ee30-f787-49da-9ea6-eca90ae63dc8}
    ipsecID = {79a4ee30-f787-49da-9ea6-eca90ae63dc8}
    ipsecDataType = dword: 256
    ipsecNegotiationPolicyReference = SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNegotiationPolicy{b640364d-5acf-4636-8ea0-7f75188b1fd2}
    whenChanged = dword: 1125464128

    - Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNFA{8a74a6ee-5556-47f9-92cb-f290f62d6f1a} (6)
    ClassName = ipsecNFA
    name = ipsecNFA{8a74a6ee-5556-47f9-92cb-f290f62d6f1a}
    ipsecID = {8a74a6ee-5556-47f9-92cb-f290f62d6f1a}
    ipsecDataType = dword: 256
    ipsecNegotiationPolicyReference = SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNegotiationPolicy{ef7b0aa6-b432-43c6-90ed-3a70ae1eb732}
    whenChanged = dword: 1125464128

    - Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNFA{9b0ad4c2-105c-46a0-aec6-0504d46b7172} (8)
    ClassName = ipsecNFA
    name = ipsecNFA{9b0ad4c2-105c-46a0-aec6-0504d46b7172}
    ipsecName = Require Security
    description = Accepts unsecured communication, but always requires clients to establish trust and security methods. Will NOT communicate with untrusted clients.
    ipsecID = {9b0ad4c2-105c-46a0-aec6-0504d46b7172}
    ipsecDataType = dword: 256
    ipsecNegotiationPolicyReference = SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNegotiationPolicy{7238523f-70fa-11d1-864c-14a300000000}
    whenChanged = dword: 1125464128

    - Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNFA{c23783f0-be75-4ab4-9fbf-603ec8772724} (8)
    ClassName = ipsecNFA
    name = ipsecNFA{c23783f0-be75-4ab4-9fbf-603ec8772724}
    ipsecName = Permit unsecure ICMP packets to pass through.
    description = Permit unsecure ICMP packets to pass through.
    ipsecID = {c23783f0-be75-4ab4-9fbf-603ec8772724}
    ipsecDataType = dword: 256
    ipsecNegotiationPolicyReference = SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNegotiationPolicy{7238523b-70fa-11d1-864c-14a300000000}
    whenChanged = dword: 1125464128

    - Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNFA{cab70199-2dd0-49f5-b95d-3dc4516c09d8} (8)
    ClassName = ipsecNFA
    name = ipsecNFA{cab70199-2dd0-49f5-b95d-3dc4516c09d8}
    ipsecName = Permit unsecure ICMP packets to pass through.
    description = Permit unsecure ICMP packets to pass through.
    ipsecID = {cab70199-2dd0-49f5-b95d-3dc4516c09d8}
    ipsecDataType = dword: 256
    ipsecNegotiationPolicyReference = SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNegotiationPolicy{7238523b-70fa-11d1-864c-14a300000000}
    whenChanged = dword: 1125464128

    - Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNFA{e7a923c5-b6d6-48bd-9ecd-1ff8a25a1fdb} (6)
    ClassName = ipsecNFA
    name = ipsecNFA{e7a923c5-b6d6-48bd-9ecd-1ff8a25a1fdb}
    ipsecID = {e7a923c5-b6d6-48bd-9ecd-1ff8a25a1fdb}
    ipsecDataType = dword: 256
    ipsecNegotiationPolicyReference = SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNegotiationPolicy{700ddda2-8391-4603-a2b4-76501e88c4b9}
    whenChanged = dword: 1125464128

    - Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNFA{fc39fce5-6d11-460f-97df-46c7d8912723} (8)
    ClassName = ipsecNFA
    name = ipsecNFA{fc39fce5-6d11-460f-97df-46c7d8912723}
    ipsecName = Request Security (Optional) Rule
    description = For all IP traffic, always request security using Kerberos trust. Allow unsecured communication with clients that do not respond to request.
    ipsecID = {fc39fce5-6d11-460f-97df-46c7d8912723}
    ipsecDataType = dword: 256
    ipsecNegotiationPolicyReference = SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNegotiationPolicy{72385233-70fa-11d1-864c-14a300000000}
    whenChanged = dword: 1125464128

    - Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecPolicy{72385230-70fa-11d1-864c-14a300000000} (8)
    ClassName = ipsecPolicy
    description = For all IP traffic, always request security using Kerberos trust. Allow unsecured communication with clients that do not respond to request.
    name = ipsecPolicy{72385230-70fa-11d1-864c-14a300000000}
    ipsecName = Server (Request Security)
    ipsecID = {72385230-70fa-11d1-864c-14a300000000}
    ipsecDataType = dword: 256
    ipsecISAKMPReference = SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecISAKMPPolicy{72385231-70fa-11d1-864c-14a300000000}
    whenChanged = dword: 1125464128

    - Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecPolicy{72385236-70fa-11d1-864c-14a300000000} (8)
    ClassName = ipsecPolicy
    description = Communicate normally (unsecured). Use the default response rule to negotiate with servers that request security. Only the requested protocol and port traffic with that server is secured.
    name = ipsecPolicy{72385236-70fa-11d1-864c-14a300000000}
    ipsecName = Client (Respond Only)
    ipsecID = {72385236-70fa-11d1-864c-14a300000000}
    ipsecDataType = dword: 256
    ipsecISAKMPReference = SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecISAKMPPolicy{72385237-70fa-11d1-864c-14a300000000}
    whenChanged = dword: 1125464128

    - Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecPolicy{7238523c-70fa-11d1-864c-14a300000000} (8)
    ClassName = ipsecPolicy
    description = For all IP traffic, always require security using Kerberos trust. Do NOT allow unsecured communication with untrusted clients.
    name = ipsecPolicy{7238523c-70fa-11d1-864c-14a300000000}
    ipsecName = Secure Server (Require Security)
    ipsecID = {7238523c-70fa-11d1-864c-14a300000000}
    ipsecDataType = dword: 256
    ipsecISAKMPReference = SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecISAKMPPolicy{7238523d-70fa-11d1-864c-14a300000000}
    whenChanged = dword: 1125464128

    - Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers (4)
    TransparentEnabled = dword: 1
    DefaultLevel = dword: 262144
    AuthenticodeEnabled = dword: 0
    PolicyScope = dword: 0

    - Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328} (4)
    Description = Stop the download of this file
    FriendlyName = Mdac11.cab
    SaferFlags = dword: 0
    HashAlg = dword: 32771

    - Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91} (4)
    Description = Stop the download of this file
    FriendlyName = mdac20.cab
    SaferFlags = dword: 0
    HashAlg = dword: 32771

    - Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f} (4)
    Description = Stop the download of this file
    FriendlyName = mdac20_a.cab
    SaferFlags = dword: 0
    HashAlg = dword: 32771

    - Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d} (4)
    Description = Stop the download of this file
    FriendlyName = _msadc10.cab
    SaferFlags = dword: 0
    HashAlg = dword: 32771

    - Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc} (4)
    Description = Stop the download of this file
    FriendlyName = msadc11.cab
    SaferFlags = dword: 0
    HashAlg = dword: 32771

    - Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33} (2)
    Description =
    SaferFlags = dword: 0

    - Software\Policies\Microsoft\WindowsMediaPlayer (1)
    DesktopShortcut = no

    * Alternate policies *
    - Software\Microsoft\Windows\CurrentVersion\policies\NonEnum (3)
    {BDEADF00-C265-11D0-BCED-00A0C90AB50F} = dword: 1
    {6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} = dword: 1073741857
    {0DF44EAA-FF21-4412-828E-260A8728E7F1} = dword: 32

    - Software\Microsoft\Windows\CurrentVersion\policies\system (5)
    dontdisplaylastusername = dword: 0
    legalnoticecaption =
    legalnoticetext =
    shutdownwithoutlogon = dword: 1
    undockwithoutlogon = dword: 1



    --------------------

    Browser Helper Objects (5):

    (no name) = {53707962-6F74-2D53-2644-206D7942484F} = C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    (no name) = {B753C7C5-0942-4b7f-BC27-942B52BDAC66} = C:\PROGRA~1\ACCELE~1\StopSign\webcbrowse.dll
    Adobe PDF Reader Link Helper = {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} = C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    Google Toolbar Helper = {AA58ED58-01DD-4d91-8333-CF10577473F7} = c:\program files\google\googletoolbar1.dll
    HpWebHelper = {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} = C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll

    --------------------

    ActiveX objects (17):

    BASEIE40_W2K - {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe
    DOTNETFRAMEWORKS - {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install
    Fax - {8b15971b-5355-4c82-8c07-7e181ea07608} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.Install.PerUser
    IE4Shell_NT - {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
    IEACCESS - {26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\shmgrate.exe OCInstallUserConfigIE
    IEUDINIT - {12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
    KB910393 - KB910393 - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\EasyCDBlock.inf,PerUserInstall
    MailNews - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
    Media Center Shortcut - {407408d4-94ed-4d86-ab69-a7f649d112ee} - C:\WINDOWS\System32\rundll32.exe setupapi,InstallHinfSection QuickLaunchShortcut 640 C:\WINDOWS\inf\mcdftreg.inf
    Messenger - {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
    Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub
    NetMeeting - {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
    OEACCESS - {881dd1c5-3dcf-431b-b061-f3f88e8be88a} - C:\WINDOWS\system32\shmgrate.exe OCInstallUserConfigOE
    Theme Component - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - C:\WINDOWS\system32\regsvr32.exe /s /n /i:/UserInstall C:\WINDOWS\system32\themeui.dll
    WAB - {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
    Windows Marketplace Link - {4b218e3e-bc98-4770-93d3-2731b9329278} - C:\WINDOWS\System32\rundll32.exe setupapi,InstallHinfSection MarketplaceLinkInstall 896 C:\WINDOWS\inf\ie.inf
    WMPACCESS - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP

    --------------------

    Internet Explorer toolbars:

    [All users (1)]
    McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll

    [This user]
    * ShellBrowser (3) *
    &Address - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll
    (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - (no file)
    &Google - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll

    * WebBrowser (3) *
    &Address - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll
    &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll
    &Google - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll


    --------------------

    Internet Explorer buttons/tools (4):

    Sun Java Console - {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBC} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
    Research - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    --------------------

    Internet Explorer menu extensions:

    [This user (1)]
    E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000

    --------------------

    Internet Explorer Bands (8):

    Search Band - {30D02401-6A81-11d0-8274-00C04FD5AE38} - C:\WINDOWS\system32\browseui.dll
    &Tip of the Day - {4D5C8C25-D075-11d0-B416-00C04FB90376} - C:\WINDOWS\system32\shdocvw.dll
    &Discuss - {BDEADE7F-C265-11D0-BCED-00A0C90AB50F} - shdocvw.dll
    File Search Explorer Band - {C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1} - C:\WINDOWS\system32\SHELL32.dll
    Favorites Band - {EFA24E61-B078-11d0-89E4-00C04FC9E26E} - C:\WINDOWS\system32\shdocvw.dll
    History Band - {EFA24E62-B078-11d0-89E4-00C04FC9E26E} - C:\WINDOWS\system32\shdocvw.dll
    Explorer Band - {EFA24E64-B078-11d0-89E4-00C04FC9E26E} - C:\WINDOWS\system32\shdocvw.dll
    &Research - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL

    --------------------

    Downloaded Program Files (11):

    Creative Software AutoUpdate - {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - C:\WINDOWS\DOWNLO~1\CTSUEng.ocx - http://www.creative.com/su/ocx/15026/CTSUEng.cab
    ewidoOnlineScan Control - {193C772A-87BE-4B19-A7BB-445B226FE9A1} - C:\WINDOWS\DOWNLO~1\EWIDOO~1.DLL - http://download.ewido.net/ewidoOnlineScan.cab
    McAfee.com Operating System Class - {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - C:\WINDOWS\system32\mcinsctl.dll - http://download.mcafee.com/molbin/sh...1/mcinsctl.cab
    Windows Live Safety Center Base Module - {5ED80217-570B-4DA9-BF44-BE107C0EC166} - C:\WINDOWS\Downloaded Program Files\wlscBase.dll - http://cdn.scan.safety.live.com/reso...lscbase969.cab
    ICSScanner Class - {7F8C8173-AD80-4807-AA75-5672F22B4582} - C:\WINDOWS\Downloaded Program Files\ICSScan.dll - http://download.zonelabs.com/bin/pro...nner371030.cab
    Java Runtime Environment 1.5.0 - {8AD9C840-044E-11D1-B3E9-00805F499D93} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll - http://java.sun.com/update/1.5.0/jin...ndows-i586.cab
    ActiveScan Installer Class - {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} - C:\WINDOWS\Downloaded Program Files\asinst.dll - http://acs.pandasoftware.com/actives...ree/asinst.cab
    DwnldGroupMgr Class - {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - C:\WINDOWS\system32\McGDMgr.dll - http://download.mcafee.com/molbin/sh...26/mcgdmgr.cab
    Java Runtime Environment 1.5.0 - {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll - http://java.sun.com/update/1.5.0/jin...ndows-i586.cab
    Shockwave Flash Object - {D27CDB6E-AE6D-11CF-96B8-444553540000} - C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx - http://fpdownload.macromedia.com/pub...sh/swflash.cab
    Creative Software AutoUpdate Support Package - {F6ACF75C-C32C-447B-9BEF-46B766368D29} - C:\WINDOWS\DOWNLO~1\CTPID.ocx - http://www.creative.com/su/ocx/15026/CTPID.cab

    --------------------

    URL search hooks:

    [This user (1)]
    Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\shdocvw.dll

    --------------------

    Explorer clones:

    C:\WINDOWS\explorer.exe

    --------------------

    Image File Execution Options (1):

    Your Image File Name Here without a path = ntsd -d

    --------------------

    ContextMenuHandlers:

    [* (7)]
    HexWorkshopContextMenu = {DB34D5DC-D41A-482E-A5EF-8FA0F88761DA} = C:\Program Files\BreakPoint Software\Hex Workshop 4.2\hwext.dll
    Offline Files = {750fdf0e-2a26-11d1-a3ea-080036587f03} = C:\WINDOWS\System32\cscui.dll
    Open With = {09799AFB-AD67-11d1-ABCD-00C04FC30936} = C:\WINDOWS\system32\SHELL32.dll
    Open With EncryptionMenu = {A470F8CF-A1E8-4f65-8335-227475AA5C46} = C:\WINDOWS\system32\SHELL32.dll
    Start Menu Pin = {a2a9545d-a0c2-42b4-9708-a0b2badd77c8} = C:\WINDOWS\system32\SHELL32.dll
    StopSignRCS = {BB83FD23-AC96-472D-8AA2-7D8560A61D1A} = C:\Program Files\Acceleration Software\Anti-Virus\dsshell.dll
    VSCContextMenu Class = {CFC7205E-2792-4378-9591-3879CC6C9022} = c:\progra~1\mcafee.com\vso\mcvsshl.dll

    [Drive (7)]
    Disk Copy Extension = {59099400-57FF-11CE-BD94-0020AF85B590} = diskcopy.dll
    HexWorkshopContextMenu = {DB34D5DC-D41A-482E-A5EF-8FA0F88761DA} = C:\Program Files\BreakPoint Software\Hex Workshop 4.2\hwext.dll
    Offline Files = {750fdf0e-2a26-11d1-a3ea-080036587f03} = C:\WINDOWS\System32\cscui.dll
    Portable Devices Menu = {D6791A63-E7E2-4fee-BF52-5DED8E86E9B8} = C:\WINDOWS\system32\wpdshext.dll
    Sharing = {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = ntshrui.dll
    ShellFolder for CD Burning = {fbeb8a05-beee-4442-804e-409d6c4515e9} = C:\WINDOWS\system32\SHELL32.dll
    VSCContextMenu Class = {CFC7205E-2792-4378-9591-3879CC6C9022} = c:\progra~1\mcafee.com\vso\mcvsshl.dll

    [Folder (2)]
    StopSignRCS = {BB83FD23-AC96-472D-8AA2-7D8560A61D1A} = C:\Program Files\Acceleration Software\Anti-Virus\dsshell.dll
    VSCContextMenu Class = {CFC7205E-2792-4378-9591-3879CC6C9022} = c:\progra~1\mcafee.com\vso\mcvsshl.dll

    [CompressedFolder (1)]
    Compressed (zipped) Folder Context Menu = {b8cdcb65-b1bf-4b42-9428-1dfdb7ee92af} = C:\WINDOWS\system32\zipfldr.dll

    [Directory (3)]
    EncryptionMenu = {A470F8CF-A1E8-4f65-8335-227475AA5C46} = C:\WINDOWS\system32\SHELL32.dll
    Offline Files = {750fdf0e-2a26-11d1-a3ea-080036587f03} = C:\WINDOWS\System32\cscui.dll
    Sharing = {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = ntshrui.dll

    [Directory\Background (3)]
    00nView = {1E9B04FB-F9E5-4718-997B-B8DA88302A48} = C:\WINDOWS\system32\nvshell.dll
    New = {D969A300-E7FF-11d0-A93B-00A0C90F2719} = C:\WINDOWS\system32\SHELL32.dll
    NvCplDesktopContext = {A70C977A-BF00-412C-90B7-034C51DA2439} = C:\WINDOWS\system32\nvcpl.dll

    [file (1)]
    VSCContextMenu Class = {CFC7205E-2792-4378-9591-3879CC6C9022} = c:\progra~1\mcafee.com\vso\mcvsshl.dll

    [ChannelShortcut (1)]
    Channel Menu Handler Object = {f3da0dc0-9cc8-11d0-a599-00c04fd64437} = C:\WINDOWS\system32\cdfview.dll

    [InternetShortcut (1)]
    Internet Shortcut = {FBF23B40-E3F0-101B-8488-00AA003E56F8} = shdocvw.dll

    [AllFileSystemObjects (1)]
    Send To = {7BA4C740-9E81-11CF-99D3-00AA004AE837} = C:\WINDOWS\system32\SHELL32.dll

    --------------------

    ColumnHandlers (5):

    (no name) - {0D2E74C4-3C34-11d2-A27E-00C04FC30871} - C:\WINDOWS\system32\SHELL32.dll
    (no name) - {24F14F01-7B1C-11d1-838f-0000F80461CF} - C:\WINDOWS\system32\SHELL32.dll
    (no name) - {24F14F02-7B1C-11d1-838f-0000F80461CF} - C:\WINDOWS\system32\SHELL32.dll
    (no name) - {66742402-F9B9-11D1-A202-0000F81FEDEE} - C:\WINDOWS\system32\SHELL32.dll
    PDF Shell Extension - {F9DB5320-233E-11D1-9F84-707F02C10627} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll

    --------------------

    ShellExecuteHooks (2):

    eAcceleration OnAccess = {1A42F606-3E21-4AB5-9565-E7C8EF6B0929} = C:\PROGRA~1\EACCEL~1\OnAccess\sehk.dll
    URL Exec Hook = {AEB6717E-7E19-11d0-97EE-00C04FD91972} = shell32.dll

    --------------------

    Approved Shell Extensions:

    [All users (191)]
    %DESC_PublishDropTarget% - {60fd46de-f830-4894-a628-6fa81bc0190d} - C:\WINDOWS\system32\photowiz.dll
    &Address - {01E04581-4EEE-11d0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll
    .CAB file viewer - {0CD7A5C0-9F37-11CE-AE65-08002B2E1262} - cabview.dll
    Accessible - {7e653215-fa25-46bd-a339-34a2790f3cb7} - C:\WINDOWS\system32\browseui.dll
    ActiveX Cache Folder - {88C6C381-2E85-11D0-94DE-444553540000} - C:\WINDOWS\system32\occache.dll
    Address EditBox - {A08C11D2-A228-11d0-825B-00AA005B4383} - C:\WINDOWS\system32\browseui.dll
    Administrative Tools - {D20EA4E1-3957-11d2-A40B-0C5020524153} - C:\WINDOWS\system32\shdocvw.dll
    Audio Media Properties Handler - {875CB1A1-0F29-45de-A1AE-CFB4950D0B78} - C:\WINDOWS\system32\shmedia.dll
    Augmented Shell Folder - {91EA3F8B-C99B-11d0-9815-00C04FD91972} - C:\WINDOWS\system32\browseui.dll
    Augmented Shell Folder 2 - {6413BA2C-B461-11d1-A18A-080036B11A03} - C:\WINDOWS\system32\browseui.dll
    Auto Update Property Sheet Extension - {5F327514-6C5E-4d60-8F16-D07FA08A78ED} - C:\WINDOWS\system32\wuaucpl.cpl
    Autoplay for SlideShow - {00E7B358-F65B-4dcf-83DF-CD026B94BFD4} -
    Avi Properties Handler - {87D62D94-71B3-4b9a-9489-5FE6850DC73E} - C:\WINDOWS\system32\shmedia.dll
    BandProxy - {F61FFEC1-754F-11d0-80CA-00AA005B4383} - C:\WINDOWS\system32\browseui.dll
    Briefcase - {85BBD920-42A0-1069-A2E4-08002B30309D} - syncui.dll
    CDF Extension Copy Hook - {67EA19A0-CCEF-11d0-8024-00C04FD75D13} - C:\WINDOWS\system32\shdocvw.dll
    Channel File - {f39a0dc0-9cc8-11d0-a599-00c04fd64433} - C:\WINDOWS\system32\cdfview.dll
    Channel Handler Object - {f3ba0dc0-9cc8-11d0-a599-00c04fd64435} - C:\WINDOWS\system32\cdfview.dll
    Channel Menu - {f3da0dc0-9cc8-11d0-a599-00c04fd64437} - C:\WINDOWS\system32\cdfview.dll
    Channel Properties - {f3ea0dc0-9cc8-11d0-a599-00c04fd64438} - C:\WINDOWS\system32\cdfview.dll
    Channel Shortcut - {f3aa0dc0-9cc8-11d0-a599-00c04fd64434} - C:\WINDOWS\system32\cdfview.dll
    Code Download Agent - {7D559C10-9FE9-11d0-93F7-00AA0059CE02} - C:\WINDOWS\system32\webcheck.dll
    Compatibility Page - {513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8} - SlayerXP.dll
    Compressed (zipped) Folder - {E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31} - C:\WINDOWS\system32\zipfldr.dll
    Compressed (zipped) Folder Right Drag Handler - {BD472F60-27FA-11cf-B8B4-444553540000} - C:\WINDOWS\system32\zipfldr.dll
    Compressed (zipped) Folder SendTo Target - {888DCA60-FC0A-11CF-8F0F-00C04FD7D062} - C:\WINDOWS\system32\zipfldr.dll
    ConnectionAgent - {E6CC6978-6B6E-11D0-BECA-00C04FD940BE} - C:\WINDOWS\system32\webcheck.dll
    Crypto PKO Extension - {7444C717-39BF-11D1-8CD9-00C04FC29D45} - C:\WINDOWS\system32\cryptext.dll
    Crypto Sign Extension - {7444C719-39BF-11D1-8CD9-00C04FC29D45} - C:\WINDOWS\system32\cryptext.dll
    Custom MRU AutoCompleted List - {6935DB93-21E8-4ccc-BEB9-9FE3C77A297A} - C:\WINDOWS\system32\browseui.dll
    Darwin App Publisher - {CFCCC7A0-A282-11D1-9082-006008059382} - C:\WINDOWS\system32\appwiz.cpl
    defscan - {46D570D9-71C8-44E5-A76C-AADFE94442CA} -
    Desktop Explorer - {1CDB2949-8F65-4355-8456-263E7C208A5D} - C:\WINDOWS\system32\nvshell.dll
    Desktop Explorer Menu - {1E9B04FB-F9E5-4718-997B-B8DA88302A47} - C:\WINDOWS\system32\nvshell.dll
    DfsShell - {ECCDF543-45CC-11CE-B9BF-0080C87CDBA6} - C:\WINDOWS\system32\dfsshlex.dll
    Directory Context Menu Verbs - {62AE1F9A-126A-11D0-A14B-0800361B1103} - C:\WINDOWS\system32\dsuiext.dll
    Directory Object Find - {163FDC20-2ABC-11d0-88F0-00A024AB2DBB} - C:\WINDOWS\system32\dsquery.dll
    Directory Property UI - {0D45D530-764B-11d0-A1CA-00AA00C16E65} - C:\WINDOWS\system32\dsuiext.dll
    Directory Query UI - {8A23E65E-31C2-11d0-891C-00A024AB2DBB} - C:\WINDOWS\system32\dsquery.dll
    Directory Start/Search Find - {F020E586-5264-11d1-A532-0000F8757D7E} - C:\WINDOWS\system32\dsquery.dll
    Disk Copy Extension - {59099400-57FF-11CE-BD94-0020AF85B590} - diskcopy.dll
    Disk Quota UI - {7988B573-EC89-11cf-9C00-00AA00A14F56} - dskquoui.dll
    Display Adapter CPL Extension - {42071712-76d4-11d1-8b24-00a0c9068ff3} - deskadp.dll
    Display Monitor CPL Extension - {42071713-76d4-11d1-8b24-00a0c9068ff3} - deskmon.dll
    Display Panning CPL Extension - {42071714-76d4-11d1-8b24-00a0c9068ff3} - deskpan.dll
    Display TroubleShoot CPL Extension - {f92e8c40-3d33-11d2-b1aa-080036a75b03} - deskperf.dll
    Download Status - {22BF0C20-6DA7-11D0-B373-00A0C9034938} - C:\WINDOWS\system32\browseui.dll
    DS Security Page - {4E40F770-369C-11d0-8922-00A024AB2DBB} - dssec.dll
    eLicense Control - {EB47FF00-225E-11D2-9E1D-00A0C9AB0EEE} - C:\WINDOWS\lcmmfu.cpl
    E-mail - {2559a1f5-21d7-11d4-bdaf-00c04f60b9f0} - C:\WINDOWS\system32\shdocvw.dll
    Encryption Context Menu - {853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} -
    Explorer Band - {EFA24E64-B078-11d0-89E4-00C04FC9E26E} - C:\WINDOWS\system32\shdocvw.dll
    Extensions Manager Folder - {692F0339-CBAA-47e6-B5B5-3B84DB604E87} - C:\WINDOWS\system32\extmgr.dll
    Favorites Band - {EFA24E61-B078-11d0-89E4-00C04FC9E26E} - C:\WINDOWS\system32\shdocvw.dll
    Fonts - {BD84B380-8CA2-1069-AB1D-08000948F534} - fontext.dll
    Fonts - {D20EA4E1-3957-11d2-A40B-0C5020524152} - C:\WINDOWS\system32\shdocvw.dll
    For &People... - {32714800-2E5F-11d0-8B85-00AA0044F941} - C:\Program Files\Outlook Express\wabfind.dll
    FTP Folders Webview - {63da6ec0-2e98-11cf-8d82-444553540000} - C:\WINDOWS\system32\msieftp.dll
    Fusion Cache - {1D2680C9-0E2A-469d-B787-065558BC7D43} - C:\WINDOWS\system32\mscoree.dll
    GDI+ file thumbnail extractor - {3F30C968-480A-4C6C-862D-EFC0897BB84B} - C:\WINDOWS\system32\shimgvw.dll
    Get a Passport Wizard - {58f1f272-9240-4f51-b6d4-fd63d1618591} - C:\WINDOWS\system32\netplwiz.dll
    Global Folder Settings - {EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} - C:\WINDOWS\system32\browseui.dll
    Help and Support - {2559a1f1-21d7-11d4-bdaf-00c04f60b9f0} - C:\WINDOWS\system32\shdocvw.dll
    Help and Support - {2559a1f2-21d7-11d4-bdaf-00c04f60b9f0} - C:\WINDOWS\system32\shdocvw.dll
    History - {FF393560-C2A7-11CF-BFF4-444553540000} - C:\WINDOWS\system32\shdocvw.dll
    HTML Thumbnail Extractor - {EAB841A0-9550-11cf-8C16-00805F1408F3} - C:\WINDOWS\system32\shimgvw.dll
    HyperTerminal Icon Ext - {88895560-9AA2-1069-930E-00AA0030EBC8} - C:\WINDOWS\system32\hticons.dll
    ICC Profile - {DBCE2480-C732-101B-BE72-BA78E9AD5B27} - C:\WINDOWS\system32\icmui.dll
    ICM Monitor Management - {5DB2625A-54DF-11D0-B6C4-0800091AA605} - C:\WINDOWS\System32\icmui.dll
    ICM Printer Management - {675F097E-4C4D-11D0-B6C1-0800091AA605} - C:\WINDOWS\system32\icmui.dll
    ICM Scanner Management - {176d6597-26d3-11d1-b350-080036a75b03} - icmui.dll
    IE4 Suite Splash Screen - {A2B0DD40-CC59-11d0-A3A5-00C04FD706EC} - C:\WINDOWS\system32\shdocvw.dll
    In-pane search - {169A0691-8DF9-11d1-A1C4-00C04FD75D13} - C:\WINDOWS\system32\browseui.dll
    Installed Apps Enumerator - {0B124F8F-91F0-11D1-B8B5-006008059382} - C:\WINDOWS\system32\appwiz.cpl
    Internet - {2559a1f4-21d7-11d4-bdaf-00c04f60b9f0} - C:\WINDOWS\system32\shdocvw.dll
    Internet Name Space - {871C5380-42A0-1069-A2EA-08002B30309D} - C:\WINDOWS\system32\shdocvw.dll
    InternetShortcut - {FBF23B40-E3F0-101B-8488-00AA003E56F8} - shdocvw.dll
    ISFBand OC - {131A6951-7F78-11D0-A979-00C04FD705A2} - C:\WINDOWS\system32\shdocvw.dll
    iTunes - {B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} - C:\Program Files\iTunes\iTunesMiniPlayer.dll
    MediaCenter Property Page - {DBFB267C-334F-4F19-A304-63B7130C20C7} - arpower.dll
    Microsoft Agent Character Property Sheet Handler - {143A62C8-C33B-11D1-84FE-00C04FA34A14} - C:\WINDOWS\msagent\agentpsh.dll
    Microsoft AutoComplete - {00BB2763-6A77-11D0-A535-00C04FD7D062} - C:\WINDOWS\system32\browseui.dll
    Microsoft Browser Architecture - {A5E46E3A-8849-11D1-9D8C-00C04FC99D61} - C:\WINDOWS\system32\shdocvw.dll
    Microsoft BrowserBand - {7BA4C742-9E81-11CF-99D3-00AA004AE837} - C:\WINDOWS\system32\browseui.dll
    Microsoft Data Link - {2206CDB2-19C1-11D1-89E0-00C04FD7A829} - C:\Program Files\Common Files\System\Ole DB\oledb32.dll
    Microsoft DocProp Inplace Calendar Control - {6A205B57-2567-4A2C-B881-F787FAB579A3} - C:\WINDOWS\system32\docprop2.dll
    Microsoft DocProp Inplace Droplist Combo Control - {0EEA25CC-4362-4A12-850B-86EE61B0D3EB} - C:\WINDOWS\system32\docprop2.dll
    Microsoft DocProp Inplace Edit Box Control - {A9CF0EAE-901A-4739-A481-E35B73E47F6D} - C:\WINDOWS\system32\docprop2.dll
    Microsoft DocProp Inplace ML Edit Box Control - {8EE97210-FD1F-4B19-91DA-67914005F020} - C:\WINDOWS\system32\docprop2.dll
    Microsoft DocProp Inplace Time Control - {28F8A4AC-BBB3-4D9B-B177-82BFC914FA33} - C:\WINDOWS\system32\docprop2.dll
    Microsoft DocProp Shell Ext - {883373C3-BF89-11D1-BE35-080036B11A03} - C:\WINDOWS\system32\docprop2.dll
    Microsoft History AutoComplete List - {00BB2764-6A77-11D0-A535-00C04FD7D062} - C:\WINDOWS\system32\browseui.dll
    Microsoft Internet Toolbar - {5E6AB780-7743-11CF-A12B-00AA004AE837} - C:\WINDOWS\system32\browseui.dll
    Microsoft Multiple AutoComplete List Container - {00BB2765-6A77-11D0-A535-00C04FD7D062} - C:\WINDOWS\system32\browseui.dll
    Microsoft Office HTML Icon Handler - {42042206-2D85-11D3-8CFF-005004838597} - C:\Program Files\Microsoft Office\OFFICE11\msohev.dll
    Microsoft Office Outlook Custom Icon Handler - {0006F045-0000-0000-C000-000000000046} - C:\PROGRA~1\MICROS~4\OFFICE11\OLKFSTUB.DLL
    Microsoft Office Outlook Desktop Icon Handler - {00020D75-0000-0000-C000-000000000046} - C:\PROGRA~1\MICROS~4\OFFICE11\MLSHEXT.DLL
    Microsoft Shell Folder AutoComplete List - {03C036F1-A186-11D0-824A-00AA005B4383} - C:\WINDOWS\system32\browseui.dll
    Microsoft Url History Service - {3C374A40-BAE4-11CF-BF7D-00AA006946EE} - C:\WINDOWS\system32\shdocvw.dll
    Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\shdocvw.dll
    Midi Properties Handler - {A6FD9E45-6E44-43f9-8644-08598F5A74D9} - C:\WINDOWS\system32\shmedia.dll
    MMC Icon Handler - {7A80E4A8-8005-11D2-BCF8-00C04F72C717} - C:\WINDOWS\System32\mmcshext.dll
    MRU AutoComplete List - {6756A641-DE71-11d0-831B-00AA005B4383} - C:\WINDOWS\system32\browseui.dll
    Multimedia File Property Sheet - {00022613-0000-0000-C000-000000000046} - mmsys.cpl
    MyDocs Copy Hook - {ECF03A33-103D-11d2-854D-006008059367} - C:\WINDOWS\system32\mydocs.dll
    MyDocs Drop Target - {ECF03A32-103D-11d2-854D-006008059367} - C:\WINDOWS\system32\mydocs.dll
    MyDocs Properties - {4a7ded0a-ad25-11d0-98a8-0800361b1103} - C:\WINDOWS\system32\mydocs.dll
    Network Connections - {7007ACC7-3202-11D1-AAD2-00805FC1270E} - C:\WINDOWS\system32\NETSHELL.dll
    Network Connections - {992CFFA0-F557-101A-88EC-00DD010CCC48} - C:\WINDOWS\system32\NETSHELL.dll
    NTFS Security Page - {1F2E5C40-9550-11CE-99D2-00AA006E086C} - rshx32.dll
    NvCpl DesktopContext Class - {A70C977A-BF00-412C-90B7-034C51DA2439} - C:\WINDOWS\system32\nvcpl.dll
    nView Desktop Context Menu - {1E9B04FB-F9E5-4718-997B-B8DA88302A48} - C:\WINDOWS\system32\nvshell.dll
    Offline Files Folder - {AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E} - C:\WINDOWS\System32\cscui.dll
    Offline Files Folder Options - {10CFC467-4392-11d2-8DB4-00C04FA31A66} - C:\WINDOWS\System32\cscui.dll
    Offline Files Menu - {750fdf0e-2a26-11d1-a3ea-080036587f03} - C:\WINDOWS\System32\cscui.dll
    OLE Docfile Property Page - {3EA48300-8CF6-101B-84FB-666CCB9BCD32} - docprop.dll
    Play on my TV helper - {FFB699E0-306A-11d3-8BD1-00104B6F7516} - C:\WINDOWS\system32\nvcpl.dll
    PlusPack CPL Extension - {41E300E0-78B6-11ce-849B-444553540000} - C:\WINDOWS\system32\themeui.dll
    Portable Devices - {35786D3C-B075-49b9-88DD-029876E11C01} - C:\WINDOWS\system32\wpdshext.dll
    Portable Devices Menu - {D6791A63-E7E2-4fee-BF52-5DED8E86E9B8} - C:\WINDOWS\system32\wpdshext.dll
    Portable Media Devices - {640167b4-59b0-47a6-b335-a6b3c0695aea} - C:\WINDOWS\system32\Audiodev.dll
    PostAgent - {D8BD2030-6FC9-11D0-864F-00AA006809D9} - C:\WINDOWS\system32\webcheck.dll
    Previous Versions - {9DB7A13C-F208-4981-8353-73CC61AE2783} - C:\WINDOWS\system32\twext.dll
    Previous Versions Property Page - {596AB062-B4D2-4215-9F74-E9109B0A8153} - C:\WINDOWS\system32\twext.dll
    Print Ordering via the Web - {add36aa8-751a-4579-a266-d66f5202ccbb} - C:\WINDOWS\system32\netplwiz.dll
    Printers Security Page - {F37C5810-4D3F-11d0-B4BF-00AA00BBB723} - rshx32.dll
    Registry Tree Options Utility - {AF4F6510-F982-11d0-8595-00AA004CD6D8} - C:\WINDOWS\system32\browseui.dll
    Remote Sessions CPL Extension - {F0152790-D56E-4445-850E-4F3117DB740C} - C:\WINDOWS\system32\remotepg.dll
    Run... - {2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} - C:\WINDOWS\system32\shdocvw.dll
    Scanners & Cameras - {3F953603-1008-4f6e-A73A-04AAC7A992F1} - wiashext.dll
    Scanners & Cameras - {83bbcbf3-b28a-4919-a5aa-73027445d672} - wiashext.dll
    Scanners & Cameras - {905667aa-acd6-11d2-8080-00805f6596d2} - wiashext.dll
    Scanners & Cameras - {E211B736-43FD-11D1-9EFB-0000F8757FCD} - wiashext.dll
    Scanners & Cameras - {FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD} - wiashext.dll
    Scheduled Tasks - {D6277990-4C6A-11CF-8D87-00AA0060F5BF} - C:\WINDOWS\system32\mstask.dll
    Search - {2559a1f0-21d7-11d4-bdaf-00c04f60b9f0} - C:\WINDOWS\system32\shdocvw.dll
    Search Assistant OC - {9461b922-3c5a-11d2-bf8b-00c04fb93661} - C:\WINDOWS\system32\shdocvw.dll
    Search Band - {30D02401-6A81-11d0-8274-00C04FD5AE38} - C:\WINDOWS\system32\browseui.dll
    Sendmail service - {9E56BE60-C50F-11CF-9A2C-00A0C90A90CE} - C:\WINDOWS\system32\sendmail.dll
    Sendmail service - {9E56BE61-C50F-11CF-9A2C-00A0C90A90CE} - C:\WINDOWS\system32\sendmail.dll
    Set Program Access and Defaults - {2559a1f7-21d7-11d4-bdaf-00c04f60b9f0} - C:\WINDOWS\system32\shdocvw.dll
    Shell Application Manager - {352EC2B7-8B9A-11D1-B8AE-006008059382} - C:\WINDOWS\system32\appwiz.cpl
    Shell Automation Inproc Service - {0A89A860-D7B1-11CE-8350-444553540000} - C:\WINDOWS\system32\shdocvw.dll
    Shell Band Site Menu - {ECD4FC4E-521C-11D0-B792-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    Shell DeskBar - {ECD4FC4C-521C-11D0-B792-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    Shell DeskBarApp - {3CCF8A41-5C85-11d0-9796-00AA00B90ADF} - C:\WINDOWS\system32\browseui.dll
    Shell DocObject Viewer - {E7E4BC40-E76A-11CE-A9BB-00AA004AE837} - C:\WINDOWS\system32\shdocvw.dll
    Shell extensions for file compression - {764BF0E1-F219-11ce-972D-00AA00A14F56} -
    Shell extensions for Microsoft Windows Network objects - {59be4990-f85c-11ce-aff7-00aa003ca9f6} - ntlanui2.dll
    Shell Extensions for RealOne Player - {F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} - C:\Program Files\Real\RealPlayer\rpshell.dll
    Shell extensions for sharing - {40dd6e20-7c17-11ce-a804-00aa003ca9f6} - ntshrui.dll
    Shell extensions for sharing - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} - ntshrui.dll
    Shell extensions for Windows Script Host - {60254CA5-953B-11CF-8C96-00AA00B8708C} - C:\WINDOWS\system32\wshext.dll
    Shell Image Data Factory - {66e4e4fb-f385-4dd0-8d74-a2efd1bc6178} - C:\WINDOWS\system32\shimgvw.dll
    Shell Image Property Handler - {eb9b1153-3b57-4e68-959a-a3266bc3d7fe} - C:\WINDOWS\system32\shimgvw.dll
    Shell Image Verbs - {e84fda7c-1d6a-45f6-b725-cb260c236066} - C:\WINDOWS\system32\shimgvw.dll
    Shell properties for a DS object - {9E51E0D0-6E0F-11d2-9601-00C04FA31A86} - C:\WINDOWS\system32\dsquery.dll
    Shell Publishing Wizard Object - {6b33163c-76a5-4b6c-bf21-45de9cd503a1} - C:\WINDOWS\system32\netplwiz.dll
    Shell Rebar BandSite - {ECD4FC4D-521C-11D0-B792-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    Shell Scrap DataHandler - {56117100-C0CD-101B-81E2-00AA004AE837} - shscrap.dll
    Shell Search Band - {21569614-B795-46b1-85F4-E737A8DC09AD} - C:\WINDOWS\system32\browseui.dll
    ShellViewRTF - {7F67036B-66F1-411A-AD85-759FB9C5B0DB} - C:\WINDOWS\system32\ShellvRTF.dll
    StopSignRCS - {BB83FD23-AC96-472D-8AA2-7D8560A61D1A} - C:\Program Files\Acceleration Software\Anti-Virus\dsshell.dll
    Subscription Folder - {F5175861-2688-11d0-9C5E-00AA00A45957} - C:\WINDOWS\system32\webcheck.dll
    Subscription Mgr - {ABBE31D0-6DAE-11D0-BECA-00C04FD940BE} - C:\WINDOWS\system32\webcheck.dll
    Summary Info Thumbnail handler (DOCFILES) - {9DBD2C50-62AD-11d0-B806-00C04FD706EC} - C:\WINDOWS\system32\shimgvw.dll
    Taskbar and Start Menu - {0DF44EAA-FF21-4412-828E-260A8728E7F1} -
    Tasks Folder Icon Handler - {DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF} - C:\WINDOWS\system32\mstask.dll
    Tasks Folder Shell Extension - {797F1E90-9EDD-11cf-8D8E-00AA0060F5BF} - C:\WINDOWS\system32\mstask.dll
    Temporary Internet Files - {7BD29E00-76C1-11CF-9DD0-00A0C9034933} - C:\WINDOWS\system32\shdocvw.dll
    Temporary Internet Files - {7BD29E01-76C1-11CF-9DD0-00A0C9034933} - C:\WINDOWS\system32\shdocvw.dll
    The Internet - {3DC7A020-0ACD-11CF-A9BB-00AA004AE837} - C:\WINDOWS\system32\shdocvw.dll
    Track Popup Bar - {acf35015-526e-4230-9596-becbe19f0ac9} - C:\WINDOWS\system32\browseui.dll
    TrayAgent - {E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7} - C:\WINDOWS\system32\webcheck.dll
    TridentImageExtractor - {7376D660-C583-11d0-A3A5-00C04FD706EC} - C:\WINDOWS\system32\browseui.dll
    User Accounts - {7A9D77BD-5403-11d2-8785-2E0420524153} -
    User Assist - {DD313E04-FEFF-11d1-8ECD-0000F87A470C} - C:\WINDOWS\system32\browseui.dll
    Video Media Properties Handler - {40C3D757-D6E4-4b49-BB41-0E5BBEA28817} - C:\WINDOWS\system32\shmedia.dll
    Video Thumbnail Extractor - {c5a40261-cd64-4ccf-84cb-c394da41d590} - C:\WINDOWS\system32\shmedia.dll
    Wav Properties Handler - {E4B29F9D-D390-480b-92FD-7DDB47101D71} - C:\WINDOWS\system32\shmedia.dll
    Web Folders - {BDEADF00-C265-11D0-BCED-00A0C90AB50F} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
    Web Printer Shell Extension - {77597368-7b15-11d0-a0c2-080036af3f03} - printui.dll
    Web Publishing Wizard - {CC6EEFFB-43F6-46c5-9619-51D571967F7D} - C:\WINDOWS\system32\netplwiz.dll
    Web Search - {07798131-AF23-11d1-9111-00A0C98BA67D} - C:\WINDOWS\system32\browseui.dll
    WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll
    WebCheck SyncMgr Handler - {7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB} - C:\WINDOWS\system32\webcheck.dll
    WebCheckChannelAgent - {E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB} - C:\WINDOWS\system32\webcheck.dll
    WebCheckWebCrawler - {08165EA0-E946-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll
    Windows Media Player Add to Playlist Context Menu Handler - {F1B9284F-E9DC-4e68-9D7E-42362A59F0FD} - C:\WINDOWS\system32\wmpshell.dll
    Windows Media Player Burn Audio CD Context Menu Handler - {CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C} - C:\WINDOWS\system32\wmpshell.dll
    Windows Media Player Play as Playlist Context Menu Handler - {8DD448E6-C188-4aed-AF92-44956194EB1F} - C:\WINDOWS\system32\wmpshell.dll

    [This user (1)]
    Web Folders - {BDEADF00-C265-11d0-BCED-00A0C90AB50F} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL

    --------------------

    Registry 'Run' keys:

    [User Run]
    Creative Detector = C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
    ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
    MSMSGS = "C:\Program Files\Messenger\msmsgs.exe" /background
    swg = C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe

    [System Run]
    amd_dc_opt = "C:\Program Files\AMD\amd_dc_opt\amd_dc_opt.exe"
    eanth_system_patcher = "C:\Program Files\Acceleration Software\SystemPatcher\sys_alert.exe" /Startup
    MCAgentExe = c:\PROGRA~1\mcafee.com\agent\McAgent.exe
    MCUpdateExe = C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
    NMSVC = C:\Program Files\CE\nmSvc.exe
    NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    NvMediaCenter = RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    nwiz = nwiz.exe /install
    OnAccess = "C:\Program Files\eAcceleration\OnAccess\OnAccess.exe" -e
    Recguard = C:\WINDOWS\SMINST\RECGUARD.EXE
    SoftwareStation = "C:\Program Files\eAcceleration\Station\station.exe" /b Startup
    StopSignSsFwMon = Rundll32.exe "C:\Program Files\Acceleration Software\StopSignProducts\Firewall\ssfwmon.dll",VerifyStatus
    StopSignSsTsMon = Rundll32.exe "C:\Program Files\Acceleration Software\Anti-Virus\sstsmon.dll",VerifyStatus
    VirusScan Online = C:\Program Files\McAfee.com\VSO\mcvsshld.exe
    VSOCheckTask = "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
    webscan = "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k

    --------------------

    Protocols:

    [Pluggable MIME filters (9)]
    application/octet-stream = {1E66F26B-79EE-11D2-8710-00C04F79ED0D} = C:\WINDOWS\system32\mscoree.dll
    application/x-complus = {1E66F26B-79EE-11D2-8710-00C04F79ED0D} = C:\WINDOWS\system32\mscoree.dll
    application/x-msdownload = {1E66F26B-79EE-11D2-8710-00C04F79ED0D} = C:\WINDOWS\system32\mscoree.dll
    Class Install Handler = {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} = C:\WINDOWS\system32\urlmon.dll
    deflate = {8f6b0360-b80d-11d0-a9b3-006097942311} = C:\WINDOWS\system32\urlmon.dll
    gzip = {8f6b0360-b80d-11d0-a9b3-006097942311} = C:\WINDOWS\system32\urlmon.dll
    lzdhtml = {8f6b0360-b80d-11d0-a9b3-006097942311} = C:\WINDOWS\system32\urlmon.dll
    text/webviewhtml = {733AC4CB-F1A4-11d0-B951-00A0C90312E1} = C:\WINDOWS\system32\SHELL32.dll
    text/xml = {807553E5-5146-11D5-A672-00B0D022E945} = C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL

    [Protocol handlers (22)]
    about = {3050F406-98B5-11CF-BB82-00AA00BDCE0B} = C:\WINDOWS\system32\mshtml.dll
    cdl = {3dd53d40-7b8b-11D0-b013-00aa0059ce02} = C:\WINDOWS\system32\urlmon.dll
    dvd = {12D51199-0DB5-46FE-A120-47A3D7D937CC} = C:\WINDOWS\system32\msvidctl.dll
    file = {79eac9e7-baf9-11ce-8c82-00aa004ba90b} = C:\WINDOWS\system32\urlmon.dll
    ftp = {79eac9e3-baf9-11ce-8c82-00aa004ba90b} = C:\WINDOWS\system32\urlmon.dll
    gopher = {79eac9e4-baf9-11ce-8c82-00aa004ba90b} = C:\WINDOWS\system32\urlmon.dll
    http = {79eac9e2-baf9-11ce-8c82-00aa004ba90b} = C:\WINDOWS\system32\urlmon.dll
    https = {79eac9e5-baf9-11ce-8c82-00aa004ba90b} = C:\WINDOWS\system32\urlmon.dll
    its = {9D148291-B9C8-11D0-A4CC-0000F80149F6} = C:\WINDOWS\system32\itss.dll
    javascript = {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} = C:\WINDOWS\system32\mshtml.dll
    local = {79eac9e7-baf9-11ce-8c82-00aa004ba90b} = C:\WINDOWS\system32\urlmon.dll
    mailto = {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} = C:\WINDOWS\system32\mshtml.dll
    mhtml = {05300401-BCBC-11d0-85E3-00C04FD85AB4} = C:\WINDOWS\system32\inetcomm.dll
    mk = {79eac9e6-baf9-11ce-8c82-00aa004ba90b} = C:\WINDOWS\system32\urlmon.dll
    ms-its = {9D148291-B9C8-11D0-A4CC-0000F80149F6} = C:\WINDOWS\system32\itss.dll
    ms-itss = {0A9007C0-4076-11D3-8789-0000F8105754} = c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
    mso-offdap11 = {32505114-5902-49B2-880A-1F7738E5A384} = C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
    res = {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} = C:\WINDOWS\system32\mshtml.dll
    sysimage = {76E67A63-06E9-11D2-A840-006008059382} = C:\WINDOWS\system32\mshtml.dll
    tv = {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} = C:\WINDOWS\system32\msvidctl.dll
    vbscript = {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} = C:\WINDOWS\system32\mshtml.dll
    wia = {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} = C:\WINDOWS\system32\wiascr.dll

    --------------------

    WOW compatibility:

    cmdline = C:\WINDOWS\system32\ntvdm.exe
    wowcmdline = C:\WINDOWS\system32\ntvdm.exe -a C:\WINDOWS\system32\krnl386

    [KnownDlls (16-bit) (40)]
    avicap.dll
    avifile.dll
    comm.drv
    commdlg.dll
    compobj.dll
    ctl3dv2.dll
    ddeml.dll
    keyboard.drv
    lanman.drv
    mapi.dll
    mciavi.drv
    mciseq.drv
    mciwave.drv
    mmsystem.dll
    mouse.drv
    msacm.dll
    msvideo.dll
    netapi.dll
    ole2.dll
    ole2disp.dll
    ole2nls.dll
    olecli.dll
    olesvr.dll
    pmspl.dll
    progman.exe
    rasapi16.dll
    shell.dll
    sound.drv
    storage.dll
    system.drv
    timer.drv
    toolhelp.dll
    typelib.dll
    vga.drv
    wfwnet.drv
    win87em.dll
    winoldap.mod
    winsock.dll
    winspool.exe
    wowdeb.exe

    [KnownDlls (32-bit) (20)]
    advapi32.dll
    comdlg32.dll
    gdi32.dll
    imagehlp.dll
    kernel32.dll
    lz32.dll
    ole32.dll
    oleaut32.dll
    olecli32.dll
    olecnv32.dll
    olesvr32.dll
    olethk32.dll
    rpcrt4.dll
    shell32.dll
    url.dll
    urlmon.dll
    user32.dll
    version.dll
    wininet.dll
    wldap32.dll

    --------------------

    ShellServiceObjectDelayLoad:

    [All users (5)]
    CDBurn = {fbeb8a05-beee-4442-804e-409d6c4515e9} = C:\WINDOWS\system32\SHELL32.dll
    PostBootReminder = {7849596a-48ea-486e-8937-a2a3009f31a9} = C:\WINDOWS\system32\SHELL32.dll
    SysTray = {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\system32\stobject.dll
    WebCheck = {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = C:\WINDOWS\system32\webcheck.dll
    WPDShServiceObj = {AAA288BA-9A4C-45B0-95D7-94D524869DB5} = C:\WINDOWS\system32\WPDShServiceObj.dll

    --------------------

    SharedTaskScheduler (2):

    Browseui preloader = {438755C2-A8BA-11D1-B96B-00A0C90312E1} = C:\WINDOWS\system32\browseui.dll
    Component Categories cache daemon = {8C7461EF-2B13-11d2-BE35-3078302C2030} = C:\WINDOWS\system32\browseui.dll

    --------------------

    Winsock LSP:

    [Protocols (22)]
    Covenant Eyes Monitoring over MSAFD Tcpip [TCP/IP] - {7F8FC09C-958B-4B73-8C91-AA0BDC30F9E8} - CESpy.dll
    Covenant Eyes Monitoring over MSAFD Tcpip [UDP/IP] - {C6605E85-A87B-417E-8976-FF2A225CB2BD} - CESpy.dll
    MSAFD Tcpip [TCP/IP] - {E70F1AA0-AB8B-11CF-8CA3-00805F48A192} - C:\WINDOWS\system32\mswsock.dll
    MSAFD Tcpip [UDP/IP] - {E70F1AA0-AB8B-11CF-8CA3-00805F48A192} - C:\WINDOWS\system32\mswsock.dll
    RSVP UDP Service Provider - {9D60A9E0-337A-11D0-BD88-0000C082E69A} - C:\WINDOWS\system32\rsvpsp.dll
    RSVP TCP Service Provider - {9D60A9E0-337A-11D0-BD88-0000C082E69A} - C:\WINDOWS\system32\rsvpsp.dll
    MSAFD NetBIOS [\Device\NetBT_Tcpip_{4350C64C-E472-4753-AA0C-9E0F9B317275}] SEQPACKET 4 - {8D5F1830-C273-11CF-95C8-00805F48A192} - C:\WINDOWS\system32\mswsock.dll
    MSAFD NetBIOS [\Device\NetBT_Tcpip_{4350C64C-E472-4753-AA0C-9E0F9B317275}] DATAGRAM 4 - {8D5F1830-C273-11CF-95C8-00805F48A192} - C:\WINDOWS\system32\mswsock.dll
    MSAFD NetBIOS [\Device\NetBT_Tcpip_{06EAE148-0958-4383-81F4-88EEE7E7ACAC}] SEQPACKET 1 - {8D5F1830-C273-11CF-95C8-00805F48A192} - C:\WINDOWS\system32\mswsock.dll
    MSAFD NetBIOS [\Device\NetBT_Tcpip_{06EAE148-0958-4383-81F4-88EEE7E7ACAC}] DATAGRAM 1 - {8D5F1830-C273-11CF-95C8-00805F48A192} - C:\WINDOWS\system32\mswsock.dll
    MSAFD NetBIOS [\Device\NetBT_Tcpip_{868451BA-34F8-48B6-AF2A-F2C2B562E0BF}] SEQPACKET 5 - {8D5F1830-C273-11CF-95C8-00805F48A192} - C:\WINDOWS\system32\mswsock.dll
    MSAFD NetBIOS [\Device\NetBT_Tcpip_{868451BA-34F8-48B6-AF2A-F2C2B562E0BF}] DATAGRAM 5 - {8D5F1830-C273-11CF-95C8-00805F48A192} - C:\WINDOWS\system32\mswsock.dll
    MSAFD NetBIOS [\Device\NetBT_Tcpip_{892900FC-9814-4488-99C0-81491C1EE93D}] SEQPACKET 0 - {8D5F1830-C273-11CF-95C8-00805F48A192} - C:\WINDOWS\system32\mswsock.dll
    MSAFD NetBIOS [\Device\NetBT_Tcpip_{892900FC-9814-4488-99C0-81491C1EE93D}] DATAGRAM 0 - {8D5F1830-C273-11CF-95C8-00805F48A192} - C:\WINDOWS\system32\mswsock.dll
    MSAFD NetBIOS [\Device\NetBT_Tcpip_{4D589907-2D53-4DBA-8511-D302D05BE3EB}] SEQPACKET 2 - {8D5F1830-C273-11CF-95C8-00805F48A192} - C:\WINDOWS\system32\mswsock.dll
    MSAFD NetBIOS [\Device\NetBT_Tcpip_{4D589907-2D53-4DBA-8511-D302D05BE3EB}] DATAGRAM 2 - {8D5F1830-C273-11CF-95C8-00805F48A192} - C:\WINDOWS\system32\mswsock.dll
    MSAFD NetBIOS [\Device\NetBT_Tcpip_{FECA2202-8AB9-4832-997F-0DA2317240A6}] SEQPACKET 3 - {8D5F1830-C273-11CF-95C8-00805F48A192} - C:\WINDOWS\system32\mswsock.dll
    MSAFD NetBIOS [\Device\NetBT_Tcpip_{FECA2202-8AB9-4832-997F-0DA2317240A6}] DATAGRAM 3 - {8D5F1830-C273-11CF-95C8-00805F48A192} - C:\WINDOWS\system32\mswsock.dll
    MSAFD NetBIOS [\Device\NetBT_Tcpip_{F595DF0A-7DFB-4AB9-9A6F-86C3290014D8}] SEQPACKET 6 - {8D5F1830-C273-11CF-95C8-00805F48A192} - C:\WINDOWS\system32\mswsock.dll
    MSAFD NetBIOS [\Device\NetBT_Tcpip_{F595DF0A-7DFB-4AB9-9A6F-86C3290014D8}] DATAGRAM 6 - {8D5F1830-C273-11CF-95C8-00805F48A192} - C:\WINDOWS\system32\mswsock.dll
    MSAFD NetBIOS [\Device\NetBT_Tcpip_{3D2699F4-613A-4463-9742-B51A91903B80}] SEQPACKET 7 - {8D5F1830-C273-11CF-95C8-00805F48A192} - C:\WINDOWS\system32\mswsock.dll
    MSAFD NetBIOS [\Device\NetBT_Tcpip_{3D2699F4-613A-4463-9742-B51A91903B80}] DATAGRAM 7 - {8D5F1830-C273-11CF-95C8-00805F48A192} - C:\WINDOWS\system32\mswsock.dll

    [Namespace Providers (4)]
    Tcpip - {22059D40-7E9E-11CF-AE5A-00AA00A7112B} - C:\WINDOWS\System32\mswsock.dll
    NTDS - {3B2637EE-E580-11CF-A555-00C04FD8D4AC} - C:\WINDOWS\System32\winrnr.dll
    Network Location Awareness (NLA) Namespace - {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83} - C:\WINDOWS\System32\mswsock.dll
    Covenant Eyes NSP for TCP services - {56A2BD9E-BB30-11D2-9166-00A0C9A786E8} - C:\WINDOWS\System32\nmNsp.dll

    --------------------

    Hijack points:

    [Reset web settings URLs]
    SearchAssistant =
    CustomizeSearch =
    START_PAGE_URL =
    SEARCH_PAGE_URL =
    MS_START_PAGE_URL =

    [Internet Explorer URLs]
    * This user *
    - Internet Explorer\Main (7)
    Default_Page_Url = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    Default_Search_Url = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    Local Page = C:\WINDOWS\system32\blank.htm
    Search Bar = http://www.google.com/ie
    Search Page = http://www.google.com
    Start Page = http://www.yahoo.com/
    Window Title = Microsoft Internet Explorer presented by Comcast

    - Internet Explorer\Desktop\General (2)
    BackupWallpaper = %USERPROFILE%\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    Wallpaper = %USERPROFILE%\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

    * All users *
    - Internet Explorer\Main (7)
    Default_Page_Url = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    Default_Search_Url = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    Local Page = %SystemRoot%\system32\blank.htm
    Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    Search Page = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    Start Page = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    Window Title = Microsoft Internet Explorer presented by Comcast

    - Internet Explorer\Search (2)
    CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
    SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop

    - Internet Explorer\AboutURLs (6)
    blank = res://mshtml.dll/blank.htm
    DesktopItemNavigationFailure = res://shdoclc.dll/navcancl.htm
    NavigationCanceled = res://shdoclc.dll/navcancl.htm
    NavigationFailure = res://shdoclc.dll/navcancl.htm
    OfflineInformation = res://shdoclc.dll/offcancl.htm
    PostNotCached = res://mshtml.dll/repost.htm



    [Default URL prefixes]
    default = http://
    ftp = ftp://
    gopher = gopher://
    home = http://
    mosaic = http://
    www = http://

    [Hosts file location]
    DatabasePath = C:\WINDOWS\System32\drivers\etc\hosts

    --------------------

    Protection & disabled items:

    [Hosts file (1)]
    * 127.0.0.1 *
    localhost


    [ActiveX killbits (149)]
    &Address - {01E04581-4EEE-11d0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll
    &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    (no name) - {083863F1-70DE-11d0-BD40-00A0C911CE86} - C:\WINDOWS\system32\devenum.dll
    (no name) - {283807b8-2c60-11d0-a31d-00aa00b92c03} - C:\WINDOWS\system32\danim.dll
    (no name) - {542FB453-5003-11CF-92A2-00AA00B8A733} - C:\WINDOWS\system32\danim.dll
    (no name) - {5DFB2651-9668-11D0-B17B-00C04FC2A0CA} - C:\WINDOWS\system32\danim.dll
    (no name) - {b4b3aecb-dfd6-11d1-9daa-00805f85cfe3} - C:\WINDOWS\system32\CLBCatQ.DLL
    (no name) - {e846f0a0-d367-11d1-8286-00a0c9231c29} - C:\WINDOWS\system32\clbcatex.dll
    9x8Resize - {BC0D69A8-0923-4EEE-9375-9239F5A38B92} - C:\Program Files\Movie Maker\wmm2filt.dll
    ACM Class Manager - {33d9a761-90c8-11d0-bd43-00a0c911ce86} - C:\WINDOWS\system32\devenum.dll
    ActiveXPlugin Object - {06DD38D3-D187-11CF-A80D-00C04FD74AD8} - C:\WINDOWS\system32\plugin.ocx
    ADODB.Stream - {00000566-0000-0010-8000-00AA006D2EA4} - C:\Program Files\Common Files\System\ado\msado15.dll
    AEPlugIn Class - {E8C31D11-6FD2-4659-AD75-155FA143F42B} - C:\PROGRA~1\MOVIEM~1\wmm2ae.dll
    Allocator Fix - {C0D076C5-E4C6-4561-8BF4-80DA8DB819D7} - C:\Program Files\Movie Maker\wmm2filt.dll
    AsyncMHandler Class - {3DA2AA3E-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\system32\msdxm.ocx
    Bitmap - {4F3E50BD-A9D7-4721-B0E1-00CB42A0A747} - C:\Program Files\Movie Maker\wmm2filt.dll
    Briefcase - {85bbd920-42a0-1069-a2e4-08002b30309d} - syncui.dll
    CEnroll Class - {43F8F289-7A20-11D0-8F06-00C04FC295E1} - C:\WINDOWS\system32\xenroll.dll
    cfw Class - {ecabafc0-7f19-11d2-978e-0000f8757e2a} - C:\WINDOWS\system32\comsvcs.dll
    CLSID_ApprenticeICW - {8ee42293-c315-11d0-8d6f-00a0c9a06e1f} - C:\WINDOWS\system32\inetcfg.dll
    CLSID_CCommAcctImport - {1aa06ba1-0e88-11d1-8391-00c04fbd7c09} - C:\WINDOWS\system32\msoeacct.dll
    CLSID_CDIDeviceActionConfigPage - {18ab439e-fcf4-40d4-90da-f79baa3b0655} - C:\WINDOWS\system32\diactfrm.dll
    CommunicationManager - {67dcc487-aa48-11d1-8f4f-00c04fb611c7} - C:\WINDOWS\system32\msdtctm.dll
    DirectControl Class - {39A2C2A6-4778-11D2-9BDB-204C4F4F5020} - C:\WINDOWS\system32\msdxm.ocx
    DirectX Transform Wrapper Property Page - {1B544C24-FD0B-11CE-8C63-00AA0044B520} - C:\Program Files\Movie Maker\wmm2filt.dll
    DiskManagement.Connection - {fd78d554-4c6e-11d0-970d-00a0c9191601} - C:\WINDOWS\System32\dmdskmgr.dll
    Dutch_Dutch Stemmer Resources - {860d28d0-8bf4-11ce-be59-00aa0051fe20} - infosoft.dll
    English_UK Stemmer Resources - {d99f7670-7f1a-11ce-be57-00aa0051fe20} - infosoft.dll
    English_US Stemmer Resources - {eeed4c20-7f1b-11ce-be57-00aa0051fe20} - infosoft.dll
    Frame Eater - {6C68955E-F965-4249-8E18-F0977B1D2899} - C:\Program Files\Movie Maker\wmm2filt.dll
    French_French Stemmer Resources - {2a6eb050-7f1c-11ce-be57-00aa0051fe20} - infosoft.dll
    FTP Folder Web View Automation - {210DA8A2-7445-11D1-91F7-006097DF5BD4} - C:\WINDOWS\system32\msieftp.dll
    German_German Stemmer Resources - {510a4910-7f1c-11ce-be57-00aa0051fe20} - infosoft.dll
    H323MSP Class - {0F1BE7F8-45CA-11D2-831F-00A0244D2298} - C:\WINDOWS\system32\h323msp.dll
    HHCtrl Object - {41B23C28-488E-4E5C-ACE2-BB0BBABE99E8} - C:\WINDOWS\system32\hhctrl.ocx
    HHCtrl Object - {ADB880A6-D8FF-11CF-9377-00AA003B7A11} - C:\WINDOWS\system32\hhctrl.ocx
    IAVIStream & IAVIFile Proxy - {0002000D-0000-0000-C000-000000000046} - avifil32.dll
    ICM Class Manager - {33d9a760-90c8-11d0-bd43-00a0c911ce86} - C:\WINDOWS\system32\devenum.dll
    IndexServer Simple Command Creator - {c7b6c04a-cbb5-11d0-bb4c-00c04fc2f410} - C:\WINDOWS\system32\query.dll
    InstallEngineCtl Object - {6E449683-C509-11CF-AAFA-00AA00B6015C} - C:\WINDOWS\system32\asctrls.ocx
    IPConfMSP Class - {0F1BE7F7-45CA-11D2-831F-00A0244D2298} - C:\WINDOWS\system32\confmsp.dll
    Italian_Italian Stemmer Resources - {6d36ce10-7f1c-11ce-be57-00aa0051fe20} - infosoft.dll
    LexRefStEsObject Class - {4CFB5280-800B-4367-848F-5A13EBF27F1D} - C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\ESEN\MSB1ESEN.DLL
    LexRefStFrObject Class - {B3E0E785-BD78-4366-9560-B7DABE2723BE} - C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\FREN\MSB1FREN.DLL
    LM Runtime Control - {183C259A-0480-11d1-87EA-00C04FC29D46} - C:\WINDOWS\system32\lmrt.dll
    Marquee Control - {250770f3-6af2-11cf-a915-008029e31fcd} - C:\Program Files\Microsoft Office\OFFICE11\HTML\HTMLMARQ.OCX
    MarshalableTI Class - {466d66fa-9616-11d2-9342-0000f875ae17} - C:\WINDOWS\system32\msconf.dll
    mbcontent Class - {52ca3bcf-3b9b-419e-a3d6-5d28c0b0b50c} - C:\WINDOWS\system32\browsewm.dll
    MDefControl Class - {459729AC-727D-4D97-B18A-72EE224EFEC0} - C:\Program Files\Acceleration Software\Anti-Virus\eac_mindef.dll
    Media Streaming Dynamic Terminal - {AED6483F-3304-11D2-86F1-006008B0E5D2} - C:\WINDOWS\system32\termmgr.dll
    MessageMover Class - {ecabb0bf-7f19-11d2-978e-0000f8757e2a} - C:\WINDOWS\system32\comsvcs.dll
    Microsoft Agent Control 1.5 - {F5BE8BD2-7DE6-11D0-91FE-00C04FD701A5} - C:\WINDOWS\msagent\agentctl.dll
    Microsoft Common Browser Architecture - {AF604EFE-8897-11D1-B944-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    Microsoft DocHost User Interface Handler - {7057e952-bd1b-11d1-8919-00c04fc2c836} - C:\WINDOWS\system32\shdocvw.dll
    Microsoft HTA Document 6.0 - {3050F5C8-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
    Microsoft Html Document for Popup Window - {3050F67D-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
    Microsoft Html Popup Window - {3050f667-98b5-11cf-bb82-00aa00bdce0b} - C:\WINDOWS\system32\mshtml.dll
    Microsoft HTML Window Security Proxy - {3050F391-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
    Microsoft Index Server Scope Administration Object - {3bc4f3a7-652a-11d1-b4d4-00c04fc2db8d} - C:\WINDOWS\system32\ciodm.dll
    Microsoft Movie Maker Age Filter - {ADEADEB8-E54B-11D1-9A72-0000F875EADE} - C:\PROGRA~1\MOVIEM~1\wmm2fxa.dll
    Microsoft MovieMaker Fade In Fade Out - {EC85D8F1-1C4E-46E4-A748-7AA04E7C0496} - C:\PROGRA~1\MOVIEM~1\wmm2fxa.dll
    Microsoft MPEG-4 Video Decompressor Property page - {598eba02-b49a-11d2-a1c1-00609778ea66} - C:\WINDOWS\system32\mpg4ds32.ax
    Microsoft MS Audio Decompressor Control Property page - {8FE7E181-BB96-11D2-A1CB-00609778EA66} - C:\WINDOWS\system32\msadds32.ax
    Microsoft NetShow Player - {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - C:\WINDOWS\system32\wmpdxm.dll
    Microsoft Office Free/Busy Registration - {f28d867a-ddb1-11d3-b8e8-00a0c981aeeb} - C:\PROGRA~1\MICROS~4\OFFICE11\MSOSVFBR.DLL
    Microsoft WBEM Event Subsystem - {5d08b586-343a-11d0-ad46-00c04fd8fdff} - C:\WINDOWS\system32\wbem\wbemess.dll
    MidiOut Class Manager - {4efe2452-168a-11d1-bc76-00c04fb9453b} - C:\WINDOWS\system32\devenum.dll
    MiniBugTransporterX Class - {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} - C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll
    MMStream Class - {49C47CE5-9BA4-11D0-8212-00C04FC32C45} - C:\WINDOWS\system32\amstream.dll
    Movie Maker Special Effect 1 Input - {B4DC8DD9-2CC1-4081-9B2B-20D7030234EF} - C:\PROGRA~1\MOVIEM~1\wmm2fxa.dll
    Movie Maker Special Effect 2 Inputs - {C63344D8-70D3-4032-9B32-7A3CAD5091A5} - C:\PROGRA~1\MOVIEM~1\wmm2fxa.dll
    Movie Maker Special Effect Inplace 1 Input - {353359C1-39E1-491b-9951-464FD8AB071C} - C:\PROGRA~1\MOVIEM~1\wmm2fxa.dll
    Movie Maker Video Adjustments - {5A20FD6F-F8FE-4A22-9EE7-307D72D09E6E} - C:\PROGRA~1\MOVIEM~1\wmm2fxa.dll
    MSP Class - {4DDB6D36-3BC1-11D2-86F2-006008B0E5D2} - C:\WINDOWS\system32\wavemsp.dll
    MTSEvents Class - {ecabb0ab-7f19-11d2-978e-0000f8757e2a} - C:\WINDOWS\system32\comsvcs.dll
    Multimedia File Property Sheet - {00022613-0000-0000-c000-000000000046} - mmsys.cpl
    NDFXArtEffects - {E673DCF2-C316-4C6F-AA96-4E4DC6DC291E} - C:\PROGRA~1\MOVIEM~1\wmm2fxb.dll
    Network Connections - {7007acc7-3202-11d1-aad2-00805fc1270e} - C:\WINDOWS\system32\NETSHELL.dll
    Network Connections - {992cffa0-f557-101a-88ec-00dd010ccc48} - C:\WINDOWS\system32\NETSHELL.dll
    Network Connections Tray - {7007ACCF-3202-11D1-AAD2-00805FC1270E} - C:\WINDOWS\system32\NETSHELL.dll
    Outlook Express Address Book - {233A9694-667E-11D1-9DFB-006097D50408} - %ProgramFiles%\Outlook Express\msoe.dll
    Outlook Progress Ctl - {0006F071-0000-0000-C000-000000000046} - C:\PROGRA~1\MICROS~4\OFFICE11\OUTLLIB.DLL
    PostBootReminder object - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\SHELL32.dll
    PSDispatch - {00020420-0000-0000-c000-000000000046} - oleaut32.dll
    PSEnumVariant - {00020421-0000-0000-C000-000000000046} - oleaut32.dll
    PSOAInterface - {00020424-0000-0000-c000-000000000046} - oleaut32.dll
    PSSupportErrorInfo - {DF0B3D60-548F-101B-8E65-08002B2BD119} - oleaut32.dll
    PSTypeComp - {00020425-0000-0000-C000-000000000046} - oleaut32.dll
    PSTypeInfo - {00020422-0000-0000-C000-000000000046} - oleaut32.dll
    PSTypeLib - {00020423-0000-0000-C000-000000000046} - oleaut32.dll
    Queued Components Recorder - {ecabafc2-7f19-11d2-978e-0000f8757e2a} - C:\WINDOWS\system32\comsvcs.dll
    Record Queue - {5B4B05EB-1F63-446B-AAD1-E10A34D650E0} - C:\Program Files\Movie Maker\wmm2filt.dll
    Redirect - {42B07B28-2280-4937-B035-0293FB812781} - C:\WINDOWS\system32\dxtmsft.dll
    RegWizCtrl - {50E5E3D1-C07E-11D0-B9FD-00A0249F6B00} - C:\WINDOWS\system32\regwizc.dll
    SafeWia Class - {0DAD5531-BF31-43AC-A513-1F8926BBF5EC} - C:\WINDOWS\system32\wiascr.dll
    Script Encoder Object - {32DA2B15-CFED-11D1-B747-00C04FC2B085} - C:\WINDOWS\system32\scrrun.dll
    SdpConferenceBlob Class - {9B2719DD-B696-11D0-A489-00C04FD91AC0} - C:\WINDOWS\system32\sdpblb.dll
    Search Assistant Control - {47c6c527-6204-4f91-849d-66e234dee015} - c:\windows\srchasst\srchui.dll
    ShellFolder for CD Burning - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\SHELL32.dll
    Shortcut - {00021401-0000-0000-c000-000000000046} - shell32.dll
    ShotDetect - {CFFB1FC7-270D-4986-B299-FECF3F0E42DB} - C:\Program Files\Movie Maker\wmm2filt.dll
    Spanish_Modern Stemmer Resources - {b0516ff0-7f1c-11ce-be57-00aa0051fe20} - infosoft.dll
    Start Menu - {4622ad11-ff23-11d0-8d34-00a0c90f2719} - C:\WINDOWS\system32\SHELL32.dll
    Stetch - {F44BB2D0-F070-463E-9433-B0CCF3CFD627} - C:\Program Files\Movie Maker\wmm2filt.dll
    Swedish_Default Stemmer Resources - {9478f640-7f1c-11ce-be57-00aa0051fe20} - infosoft.dll
    System Monitor Source Properties - {0CF32AA1-7571-11D0-93C4-00AA00A3DDEA} - C:\WINDOWS\system32\sysmon.ocx
    SysTray - {35cec8a3-2be6-11d2-8773-92e220524153} - C:\WINDOWS\system32\stobject.dll
    SysTrayInvoker - {730f6cdc-2c86-11d2-8773-92e220524153} - C:\WINDOWS\system32\stobject.dll
    TipGW Init - {F117831B-C052-11d1-B1C0-00C04FC2F3EF} - C:\WINDOWS\system32\msdtctm.dll
    Trident HTMLEditor - {3050f4f5-98b5-11cf-bb82-00aa00bdce0b} - C:\WINDOWS\system32\mshtmled.dll
    VFW Capture Class Manager - {860bb310-5d01-11d0-bd3b-00a0c911ce86} - C:\WINDOWS\system32\devenum.dll
    Video Effect (1 input) Class Manager - {cc7bfb42-f175-11d1-a392-00e0291f3959} - C:\WINDOWS\system32\qedit.dll
    Video Effect (2 input) Class Manager - {cc7bfb43-f175-11d1-a392-00e0291f3959} - C:\WINDOWS\system32\qedit.dll
    Video Mixing Renderer 9 - {51b4abf3-748f-4e3b-a276-c828330e926a} - C:\WINDOWS\system32\quartz.dll
    Video Render Dynamic Terminal - {AED6483E-3304-11D2-86F1-006008B0E5D2} - C:\WINDOWS\system32\termmgr.dll
    VideoPort Object - {ce292861-fc88-11d0-9e69-00c04fd7c15b} - C:\WINDOWS\system32\qdvd.dll
    VMR Allocator Presenter 9 - {2d2e24cb-0cd5-458f-86ea-3e6fa22c8e64} - C:\WINDOWS\system32\quartz.dll
    VMR ImageSync 9 - {e4979309-7a32-495e-8a92-7b014aad4961} - C:\WINDOWS\system32\quartz.dll
    WaveIn Class Manager - {33D9A762-90C8-11d0-BD43-00A0C911CE86} - C:\WINDOWS\system32\devenum.dll
    WaveOut and DSound Class Manager - {e0f158e1-cb04-11d0-bd4e-00a0c911ce86} - C:\WINDOWS\system32\devenum.dll
    Wbem Scripting Object Path - {172BDDF8-CEEA-11D1-8B05-00600806D9B6} - C:\WINDOWS\system32\wbem\wbemdisp.dll
    WDM Instance Provider - {d2d588b5-d081-11d0-99e0-00c04fc2f8ec} - C:\WINDOWS\system32\wbem\wmiprov.dll
    WIA FileSystem USD - {d2923b86-15f1-46ff-a19a-de825f919576} - C:\WINDOWS\system32\fsusd.dll
    WIA Video Preview Class - {457A23DF-6F2A-4684-91D0-317FB768D87C} - C:\WINDOWS\system32\camocx.dll
    Windows Media Video Decompressor Property page - {9AADA567-04E0-11D4-9148-00C04F610D24} - C:\WINDOWS\system32\wmv8ds32.ax
    WM Color Converter Filter - {CC45B0B0-72D8-4652-AE5F-5E3E266BE7ED} - C:\Program Files\Movie Maker\wmm2filt.dll
    WM TV Out Smooth Picture Filter - {41D2B841-7692-4C83-AFD3-F60E845341AF} - C:\Program Files\Movie Maker\wmm2filt.dll
    WM VIH2 Fix - {586FB486-5560-4FF3-96DF-1118C96AF456} - C:\Program Files\Movie Maker\wmm2filt.dll
    WMI ADSI Extension - {f0975afe-5c7f-11d2-8b74-00104b2afb41} - C:\WINDOWS\system32\wbem\wbemads.dll
    WMT Audio Analyzer - {1CB1623E-BBEC-4E8D-B2DF-DC08C6F4627C} - C:\Program Files\Movie Maker\wmm2filt.dll
    WMT Black Frame Generator - {2EA10031-0033-450E-8072-E27D9E768142} - C:\Program Files\Movie Maker\wmm2filt.dll
    WMT DeInterlace Filter - {C8F209F8-480E-454C-94A4-5392D88EBA0F} - C:\Program Files\Movie Maker\wmm2filt.dll
    WMT DeInterlace Prop Page - {A2EDA89A-0966-4B91-9C18-AB69F098187F} - C:\Program Files\Movie Maker\wmm2filt.dll
    WMT DirectX Transform Wrapper - {AECF5D2E-7A18-4DD2-BDCD-29B6F615B448} - C:\Program Files\Movie Maker\wmm2filt.dll
    WMT DV Extract Filter - {E476CBFF-E229-4524-B6B7-228A3129D1C7} - C:\Program Files\Movie Maker\wmm2filt.dll
    WMT FormatConversion - {2D20D4BB-B47E-4FB7-83BD-E3C2EE250D26} - C:\Program Files\Movie Maker\wmm2filt.dll
    WMT FormatConversion Prop Page - {E188F7A3-A04E-413E-99D1-D79A45F70305} - C:\Program Files\Movie Maker\wmm2filt.dll
    WMT Import Filter - {4D4C9FEF-ED80-47EA-A3FA-3215FDBB33AB} - C:\Program Files\Movie Maker\wmm2filt.dll
    WMT Interlacer - {C6CB1FE3-B05E-4F0E-818F-C83ED5A0332F} - C:\Program Files\Movie Maker\wmm2filt.dll
    WMT Log Filter - {92883667-E95C-443D-AC96-4CACA27BEB6E} - C:\Program Files\Movie Maker\wmm2filt.dll
    WMT MuxDeMux Filter - {01002B17-5D93-4551-81E4-831FEF780A53} - C:\Program Files\Movie Maker\wmm2filt.dll
    WMT Sample Info Filter - {7F1232EE-44D7-4494-AB8B-CC61B10E21A5} - C:\Program Files\Movie Maker\wmm2filt.dll
    WMT Screen capture Filter - {31087270-d348-432c-899e-2d2f38ff29a0} - C:\Program Files\Movie Maker\wmm2filt.dll
    WMT Screen Capture Filter Task Page - {679E132F-561B-42F8-846C-A70DBDC62999} - C:\Program Files\Movie Maker\wmm2filt.dll
    WMT Switch Filter - {EF105BC3-C064-45F1-AD53-6D8A8578D01B} - C:\Program Files\Movie Maker\wmm2filt.dll
    WMT Virtual Renderer - {930FD02C-BBE7-4EB9-91CF-FC45CC91E3E6} - C:\Program Files\Movie Maker\wmm2filt.dll
    WMT Virtual Source - {C44C65C7-FDF1-453D-89A5-BCC28F5D69F9} - C:\Program Files\Movie Maker\wmm2filt.dll
    WMT Volume - {EFEE43D6-BFE5-44B0-8063-AC3B2966AB2C} - C:\Program Files\Movie Maker\wmm2filt.dll
    WTHoster Class - {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} - C:\WINDOWS\wt\webdriver\4.1.1\wthostctl.dll

    [Zones]
    * This user *
    - Restricted sites (48)
    157.238.62.14
    193.125.201.50
    194.187.45.55
    195.255.177.28
    205.209.152.121
    205.209.178.251
    206.161.124.98
    207.226.162.34
    209.66.114.130
    213.131.225.2
    213.21.215.186
    216.152.240.10
    216.152.240.13
    216.152.240.14
    216.152.240.16
    216.255.179.234
    216.65.3.68
    221.130.176.199
    222.208.183.14
    24.244.71.239
    59.36.96.132
    61.129.75.124
    62.4.84.173
    64.124.84.191
    65.75.151.192
    66.117.14.138
    66.117.37.7
    66.197.100.83
    66.197.138.235
    66.230.175.129
    66.250.107.100
    66.250.107.101
    66.250.107.99
    66.250.130.194
    66.250.170.107
    66.250.57.26
    66.250.57.27
    66.250.57.28
    66.250.74.150
    66.40.16.198
    69.31.131.82
    69.31.81.82
    69.50.171.122
    82.146.60.36
    82.179.170.11
    82.179.170.82
    85.249.22.240
    85.255.117.243



    [Stopped/disabled NT Services]
    * Stopped (41) *
    Application Layer Gateway Service = C:\WINDOWS\System32\alg.exe
    Application Management = C:\WINDOWS\system32\svchost.exe -k netsvcs
    ASP.NET State Service = C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
    Background Intelligent Transfer Service = C:\WINDOWS\system32\svchost.exe -k netsvcs
    COM+ Event System = C:\WINDOWS\system32\svchost.exe -k netsvcs
    COM+ System Application = C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
    Fast User Switching Compatibility = C:\WINDOWS\System32\svchost.exe -k netsvcs
    Fax = C:\WINDOWS\system32\fxssvc.exe
    HTTP SSL = C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    IMAPI CD-Burning COM Service = C:\WINDOWS\system32\imapi.exe
    Indexing Service = C:\WINDOWS\system32\cisvc.exe
    InstallDriver Table Manager = "C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"
    iPodService = C:\Program Files\iPod\bin\iPodService.exe
    Logical Disk Manager Administrative Service = C:\WINDOWS\System32\dmadmin.exe /com
    McAfee SecurityCenter Update Manager = C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    MHN = C:\WINDOWS\System32\svchost.exe -k netsvcs
    MS Software Shadow Copy Provider = C:\WINDOWS\system32\dllhost.exe /Processid:{8DA84759-6C62-4695-9DB6-4789D64FAF43}
    Net Logon = C:\WINDOWS\system32\lsass.exe
    NetMeeting Remote Desktop Sharing = C:\WINDOWS\system32\mnmsrvc.exe
    Network Connections = C:\WINDOWS\System32\svchost.exe -k netsvcs
    Network Location Awareness (NLA) = C:\WINDOWS\system32\svchost.exe -k netsvcs
    Network Provisioning Service = C:\WINDOWS\System32\svchost.exe -k netsvcs
    NT LM Security Support Provider = C:\WINDOWS\system32\lsass.exe
    Office Source Engine = "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
    Performance Logs and Alerts = C:\WINDOWS\system32\smlogsvc.exe
    Portable Media Serial Number Service = C:\WINDOWS\System32\svchost.exe -k netsvcs
    QoS RSVP = C:\WINDOWS\system32\rsvp.exe
    Remote Access Connection Manager = C:\WINDOWS\system32\svchost.exe -k netsvcs
    Remote Desktop Help Session Manager = C:\WINDOWS\system32\sessmgr.exe
    Remote Procedure Call (RPC) Locator = C:\WINDOWS\system32\locator.exe
    Smart Card = C:\WINDOWS\System32\SCardSvr.exe
    Telephony = C:\WINDOWS\System32\svchost.exe -k netsvcs
    Terminal Services = C:\WINDOWS\System32\svchost -k DComLaunch
    Uninterruptible Power Supply = C:\WINDOWS\System32\ups.exe
    Universal Plug and Play Device Host = C:\WINDOWS\system32\svchost.exe -k LocalService
    Volume Shadow Copy = C:\WINDOWS\System32\vssvc.exe
    Windows Driver Foundation - User-mode Driver Framework = C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
    Windows Installer = C:\WINDOWS\system32\msiexec.exe /V
    Windows Management Instrumentation Driver Extensions = C:\WINDOWS\System32\svchost.exe -k netsvcs
    Windows Media Player Network Sharing Service = C:\Program Files\Windows Media Player\WMPNetwk.exe
    WMI Performance Adapter = C:\WINDOWS\system32\wbem\wmiapsrv.exe

    * Stopped & disabled (10) *
    Alerter = C:\WINDOWS\system32\svchost.exe -k LocalService
    ClipBook = C:\WINDOWS\system32\clipsrv.exe
    Human Interface Device Access = C:\WINDOWS\System32\svchost.exe -k netsvcs
    Messenger = C:\WINDOWS\system32\svchost.exe -k netsvcs
    Network DDE = C:\WINDOWS\system32\netdde.exe
    Network DDE DSDM = C:\WINDOWS\system32\netdde.exe
    Remote Access Auto Connection Manager = C:\WINDOWS\system32\svchost.exe -k netsvcs
    Removable Storage = C:\WINDOWS\system32\svchost.exe -k netsvcs
    Routing and Remote Access = C:\WINDOWS\system32\svchost.exe -k netsvcs
    Telnet = C:\WINDOWS\system32\tlntsvr.exe


    [Windows XP Security]
    * Security Center *
    - This user
    FirstRun = dword: 1

    - All users
    FirstRunDisabled = dword: 1
    AntiVirusDisableNotify = dword: 1
    FirewallDisableNotify = dword: 1
    UpdatesDisableNotify = dword: 0
    AntiVirusOverride = dword: 0
    FirewallOverride = dword: 0

    * System Restore *
    - All users
    DisableSR = dword: 0
    CreateFirstRunRp = dword: 1
    DSMin = dword: 200
    DSMax = dword: 400
    RPSessionInterval = dword: 0
    RPGlobalInterval = dword: 86400
    RPLifeInterval = dword: 7776000
    CompressionBurst = dword: 60
    TimerInterval = dword: 120
    DiskPercent = dword: 12
    ThawInterval = dword: 900
    RestoreDiskSpaceError = dword: 0
    RestoreStatus = dword: 0



    ==================================================
    = Other users on this computer: Default user =
    ==================================================
    --------------------

    Autostart folders:

    [Startup]
    desktop.ini
    Pin.lnk

    [User Startup]
    desktop.ini

    --------------------

    IniMapping values:

    User screensaver = logon.scr

    --------------------

    Policies:

    [Alternate policies]
    * Software\Microsoft\Windows\CurrentVersion\policies\Explorer (1) *
    NoDriveTypeAutoRun = dword: 145


    --------------------

    Hijack points:

    [Internet Explorer URLs]
    * Internet Explorer\Main (5) *
    Default_Page_Url = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    Default_Search_Url = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    Search Page = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    Start Page = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop


    --------------------

    Protection & disabled items:

    [Zones]
    * Restricted sites (48) *
    157.238.62.14
    193.125.201.50
    194.187.45.55
    195.255.177.28
    205.209.152.121
    205.209.178.251
    206.161.124.98
    207.226.162.34
    209.66.114.130
    213.131.225.2
    213.21.215.186
    216.152.240.10
    216.152.240.13
    216.152.240.14
    216.152.240.16
    216.255.179.234
    216.65.3.68
    221.130.176.199
    222.208.183.14
    24.244.71.239
    59.36.96.132
    61.129.75.124
    62.4.84.173
    64.124.84.191
    65.75.151.192
    66.117.14.138
    66.117.37.7
    66.197.100.83
    66.197.138.235
    66.230.175.129
    66.250.107.100
    66.250.107.101
    66.250.107.99
    66.250.130.194
    66.250.170.107
    66.250.57.26
    66.250.57.27
    66.250.57.28
    66.250.74.150
    66.40.16.198
    69.31.131.82
    69.31.81.82
    69.50.171.122
    82.146.60.36
    82.179.170.11
    82.179.170.82
    85.249.22.240
    85.255.117.243



    ==================================================
    = Other users on this computer: LOCAL SERVICE =
    ==================================================
    --------------------

    Autostart folders:

    [User Startup]
    desktop.ini

    --------------------

    IniMapping values:

    User screensaver = C:\WINDOWS\System32\logon.scr

    --------------------

    Policies:

    [Alternate policies]
    * Software\Microsoft\Windows\CurrentVersion\policies\Explorer (1) *
    NoDriveTypeAutoRun = dword: 145


    --------------------

    Protection & disabled items:

    [Zones]
    * Restricted sites (48) *
    157.238.62.14
    193.125.201.50
    194.187.45.55
    195.255.177.28
    205.209.152.121
    205.209.178.251
    206.161.124.98
    207.226.162.34
    209.66.114.130
    213.131.225.2
    213.21.215.186
    216.152.240.10
    216.152.240.13
    216.152.240.14
    216.152.240.16
    216.255.179.234
    216.65.3.68
    221.130.176.199
    222.208.183.14
    24.244.71.239
    59.36.96.132
    61.129.75.124
    62.4.84.173
    64.124.84.191
    65.75.151.192
    66.117.14.138
    66.117.37.7
    66.197.100.83
    66.197.138.235
    66.230.175.129
    66.250.107.100
    66.250.107.101
    66.250.107.99
    66.250.130.194
    66.250.170.107
    66.250.57.26
    66.250.57.27
    66.250.57.28
    66.250.74.150
    66.40.16.198
    69.31.131.82
    69.31.81.82
    69.50.171.122
    82.146.60.36
    82.179.170.11
    82.179.170.82
    85.249.22.240
    85.255.117.243



    ==================================================
    = Other users on this computer: NETWORK SERVICE =
    ==================================================
    --------------------

    Autostart folders:

    [User Startup]
    desktop.ini

    --------------------

    IniMapping values:

    User screensaver = C:\WINDOWS\System32\logon.scr

    --------------------

    Policies:

    [Alternate policies]
    * Software\Microsoft\Windows\CurrentVersion\policies\Explorer (1) *
    NoDriveTypeAutoRun = dword: 145


    --------------------

    Protection & disabled items:

    [Zones]
    * Restricted sites (48) *
    157.238.62.14
    193.125.201.50
    194.187.45.55
    195.255.177.28
    205.209.152.121
    205.209.178.251
    206.161.124.98
    207.226.162.34
    209.66.114.130
    213.131.225.2
    213.21.215.186
    216.152.240.10
    216.152.240.13
    216.152.240.14
    216.152.240.16
    216.255.179.234
    216.65.3.68
    221.130.176.199
    222.208.183.14
    24.244.71.239
    59.36.96.132
    61.129.75.124
    62.4.84.173
    64.124.84.191
    65.75.151.192
    66.117.14.138
    66.117.37.7
    66.197.100.83
    66.197.138.235
    66.230.175.129
    66.250.107.100
    66.250.107.101
    66.250.107.99
    66.250.130.194
    66.250.170.107
    66.250.57.26
    66.250.57.27
    66.250.57.28
    66.250.74.150
    66.40.16.198
    69.31.131.82
    69.31.81.82
    69.50.171.122
    82.146.60.36
    82.179.170.11
    82.179.170.82
    85.249.22.240
    85.255.117.243



    ==================================================
    = Other users on this computer: SYSTEM =
    ==================================================
    --------------------

    Autostart folders:

    [Startup]
    desktop.ini
    Pin.lnk

    [User Startup]
    desktop.ini

    --------------------

    IniMapping values:

    User screensaver = logon.scr

    --------------------

    Policies:

    [Alternate policies]
    * Software\Microsoft\Windows\CurrentVersion\policies\Explorer (1) *
    NoDriveTypeAutoRun = dword: 145


    --------------------

    Hijack points:

    [Internet Explorer URLs]
    * Internet Explorer\Main (5) *
    Default_Page_Url = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    Default_Search_Url = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    Search Page = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    Start Page = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop


    --------------------

    Protection & disabled items:

    [Zones]
    * Restricted sites (48) *
    157.238.62.14
    193.125.201.50
    194.187.45.55
    195.255.177.28
    205.209.152.121
    205.209.178.251
    206.161.124.98
    207.226.162.34
    209.66.114.130
    213.131.225.2
    213.21.215.186
    216.152.240.10
    216.152.240.13
    216.152.240.14
    216.152.240.16
    216.255.179.234
    216.65.3.68
    221.130.176.199
    222.208.183.14
    24.244.71.239
    59.36.96.132
    61.129.75.124
    62.4.84.173
    64.124.84.191
    65.75.151.192
    66.117.14.138
    66.117.37.7
    66.197.100.83
    66.197.138.235
    66.230.175.129
    66.250.107.100
    66.250.107.101
    66.250.107.99
    66.250.130.194
    66.250.170.107
    66.250.57.26
    66.250.57.27
    66.250.57.28
    66.250.74.150
    66.40.16.198
    69.31.131.82
    69.31.81.82
    69.50.171.122
    82.146.60.36
    82.179.170.11
    82.179.170.82
    85.249.22.240
    85.255.117.243



    ==================================================
    = Other hardware configurations: Last known good =
    ==================================================
    --------------------

    On-reboot actions:

    BootExecute = autocheck autochk *

    --------------------

    Services:

    [NT Services (49)]
    ARSVC = C:\WINDOWS\arservice.exe
    Automatic Updates = C:\WINDOWS\system32\svchost.exe -k netsvcs
    Computer Browser = C:\WINDOWS\system32\svchost.exe -k netsvcs
    Creative Service for CDROM Access = C:\WINDOWS\system32\CTsvcCDA.EXE
    Cryptographic Services = C:\WINDOWS\system32\svchost.exe -k netsvcs
    DCOM Server Process Launcher = C:\WINDOWS\system32\svchost -k DcomLaunch
    DHCP Client = C:\WINDOWS\system32\svchost.exe -k netsvcs
    Distributed Link Tracking Client = C:\WINDOWS\system32\svchost.exe -k netsvcs
    DNS Client = C:\WINDOWS\system32\svchost.exe -k NetworkService
    Error Reporting Service = C:\WINDOWS\System32\svchost.exe -k netsvcs
    Event Log = C:\WINDOWS\system32\services.exe
    FWService = C:\Program Files\Acceleration Software\StopSignProducts\Firewall\fwservice.exe -Service
    Help and Support = C:\WINDOWS\System32\svchost.exe -k netsvcs
    IPSEC Services = C:\WINDOWS\system32\lsass.exe
    LicCtrl Service = C:\WINDOWS\runservice.exe
    LightScribeService Direct Disc Labeling Service = "C:\Program Files\Common Files\LightScribe\LSSrvc.exe"
    Logical Disk Manager = C:\WINDOWS\System32\svchost.exe -k netsvcs
    Machine Debug Manager = "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
    McAfee Task Scheduler = c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    McAfee WSC Integration = c:\program files\mcafee.com\agent\mcdetect.exe
    McAfee.com McShield = c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    Media Center Extender Service = C:\WINDOWS\ehome\mcrdsvc.exe
    Media Center Receiver Service = C:\WINDOWS\eHome\ehRecvr.exe
    Media Center Scheduler Service = C:\WINDOWS\eHome\ehSched.exe
    NVIDIA Display Driver Service = C:\WINDOWS\system32\nvsvc32.exe
    Plug and Play = C:\WINDOWS\system32\services.exe
    Print Spooler = C:\WINDOWS\system32\spoolsv.exe
    Protected Storage = C:\WINDOWS\system32\lsass.exe
    Remote Procedure Call (RPC) = C:\WINDOWS\system32\svchost -k rpcss
    Remote Registry = C:\WINDOWS\system32\svchost.exe -k LocalService
    Secondary Logon = C:\WINDOWS\System32\svchost.exe -k netsvcs
    Security Accounts Manager = C:\WINDOWS\system32\lsass.exe
    Security Center = C:\WINDOWS\System32\svchost.exe -k netsvcs
    Server = C:\WINDOWS\system32\svchost.exe -k netsvcs
    Shell Hardware Detection = C:\WINDOWS\System32\svchost.exe -k netsvcs
    SSDP Discovery Service = C:\WINDOWS\system32\svchost.exe -k LocalService
    System Event Notification = C:\WINDOWS\system32\svchost.exe -k netsvcs
    System Restore Service = C:\WINDOWS\system32\svchost.exe -k netsvcs
    Task Scheduler = C:\WINDOWS\System32\svchost.exe -k netsvcs
    TCP/IP NetBIOS Helper = C:\WINDOWS\system32\svchost.exe -k LocalService
    Themes = C:\WINDOWS\System32\svchost.exe -k netsvcs
    WebClient = C:\WINDOWS\system32\svchost.exe -k LocalService
    Windows Audio = C:\WINDOWS\System32\svchost.exe -k netsvcs
    Windows Firewall/Internet Connection Sharing (ICS) = C:\WINDOWS\system32\svchost.exe -k netsvcs
    Windows Image Acquisition (WIA) = C:\WINDOWS\system32\svchost.exe -k imgsvc
    Windows Management Instrumentation = C:\WINDOWS\system32\svchost.exe -k netsvcs
    Windows Time = C:\WINDOWS\System32\svchost.exe -k netsvcs
    Wireless Zero Configuration = C:\WINDOWS\System32\svchost.exe -k netsvcs
    Workstation = C:\WINDOWS\system32\svchost.exe -k netsvcs

    [SafeBoot services (Minimal boot)]
    * CD-ROM Drive *
    {4D36E965-E325-11CE-BFC1-08002BE10318}

    * DiskDrive *
    {4D36E967-E325-11CE-BFC1-08002BE10318}

    * Driver *
    dmboot.sys
    dmio.sys
    dmload.sys
    sermouse.sys
    vga.sys
    vgasave.sys

    * Driver Group *
    Base
    Boot Bus Extender
    Boot file system
    File system
    Filter
    PCI Configuration
    PNP Filter
    Primary disk
    SCSI Class
    System Bus Extender

    * Floppy disk drive *
    {4D36E980-E325-11CE-BFC1-08002BE10318}

    * FSFilter System Recovery *
    sr.sys

    * Hdc *
    {4D36E96A-E325-11CE-BFC1-08002BE10318}

    * Human Interface Devices *
    {745A17A0-74D3-11D0-B6FE-00A0C90F57DA}

    * Keyboard *
    {4D36E96B-E325-11CE-BFC1-08002BE10318}

    * Mouse *
    {4D36E96F-E325-11CE-BFC1-08002BE10318}

    * PCMCIA Adapters *
    {4D36E977-E325-11CE-BFC1-08002BE10318}

    * SCSIAdapter *
    {4D36E97B-E325-11CE-BFC1-08002BE10318}

    * Service *
    AppMgmt
    CryptSvc
    DcomLaunch
    dmadmin
    dmserver
    EventLog
    HelpSvc
    Netlogon
    PlugPlay
    RpcSs
    SRService
    WinMgmt

    * Standard floppy disk controller *
    {4D36E969-E325-11CE-BFC1-08002BE10318}

    * System *
    {4D36E97D-E325-11CE-BFC1-08002BE10318}

    * Universal Serial Bus controllers *
    {36FC9E60-C465-11CF-8056-444553540000}

    * Volume *
    {71A27CDD-812A-11D0-BEC7-08002BE2092F}


    [SafeBoot services (Minimal boot + network support)]
    * CD-ROM Drive *
    {4D36E965-E325-11CE-BFC1-08002BE10318}

    * DiskDrive *
    {4D36E967-E325-11CE-BFC1-08002BE10318}

    * Driver *
    dmboot.sys
    dmio.sys
    dmload.sys
    ip6fw.sys
    ipnat.sys
    rdpcdd.sys
    rdpdd.sys
    rdpwd.sys
    sermouse.sys
    tdpipe.sys
    tdtcp.sys
    vga.sys
    vgasave.sys

    * Driver Group *
    Base
    Boot Bus Extender
    Boot file system
    File system
    Filter
    NDIS
    NDIS Wrapper
    NetBIOSGroup
    NetDDEGroup
    Network
    NetworkProvider
    PCI Configuration
    PNP Filter
    PNP_TDI
    Primary disk
    SCSI Class
    Streams Drivers
    System Bus Extender
    TDI

    * Floppy disk drive *
    {4D36E980-E325-11CE-BFC1-08002BE10318}

    * FSFilter System Recovery *
    sr.sys

    * Hdc *
    {4D36E96A-E325-11CE-BFC1-08002BE10318}

    * Human Interface Devices *
    {745A17A0-74D3-11D0-B6FE-00A0C90F57DA}

    * Keyboard *
    {4D36E96B-E325-11CE-BFC1-08002BE10318}

    * Mouse *
    {4D36E96F-E325-11CE-BFC1-08002BE10318}

    * Net *
    {4D36E972-E325-11CE-BFC1-08002BE10318}

    * NetClient *
    {4D36E973-E325-11CE-BFC1-08002BE10318}

    * NetService *
    {4D36E974-E325-11CE-BFC1-08002BE10318}

    * NetTrans *
    {4D36E975-E325-11CE-BFC1-08002BE10318}

    * PCMCIA Adapters *
    {4D36E977-E325-11CE-BFC1-08002BE10318}

    * SCSIAdapter *
    {4D36E97B-E325-11CE-BFC1-08002BE10318}

    * Service *
    AFD
    AppMgmt
    Browser
    CryptSvc
    DcomLaunch
    Dhcp
    dmadmin
    dmserver
    DnsCache
    EventLog
    HelpSvc
    LanmanServer
    LanmanWorkstation
    LmHosts
    Messenger
    Ndisuio
    NetBIOS
    NetBT
    Netlogon
    NetMan
    NtLmSsp
    PlugPlay
    rdsessmgr
    RpcSs
    SharedAccess
    SRService
    Tcpip
    termservice
    WinMgmt
    WZCSVC

    * Standard floppy disk controller *
    {4D36E969-E325-11CE-BFC1-08002BE10318}

    * System *
    {4D36E97D-E325-11CE-BFC1-08002BE10318}

    * Universal Serial Bus controllers *
    {36FC9E60-C465-11CF-8056-444553540000}

    * Volume *
    {71A27CDD-812A-11D0-BEC7-08002BE2092F}


    [SafeBoot: Alternate shell]
    cmd.exe (not enabled)

    --------------------

    Driver filters:

    [Class filters]
    * Human Interface Devices *
    - Upper filters
    arhidfltr.sys

    * Infrared devices *
    - Upper filters
    IRENUM.sys

    * Storage volumes *
    - Upper filters
    VolSnap.sys

    * Tape drives *
    - Lower filters
    PxHelp20.sys



    [Device filters]
    * Agere Systems PCI-SV92PP Soft Modem *
    - Lower filters
    AgereSoftModem.sys

    * CD-ROM Drive *
    - Upper filters
    redbook.sys

    * CD-ROM Drive *
    - Upper filters
    redbook.sys

    - Lower filters
    imapi.sys

    * CD-ROM Drive *
    - Upper filters
    redbook.sys

    - Lower filters
    imapi.sys

    * Direct Parallel *
    - Lower filters
    PtiLink.sys

    * Enhanced Mulmedia PS/2 Keyboard *
    - Upper filters
    PS2.sys

    * Saitek P990 Dual Analog Pad (USB) *
    - Lower filters
    SaiU040B.sys

    * Saitek P990 Dual Analog Pad (USB) *
    - Lower filters
    SaiU040B.sys

    * Terminal Server Keyboard Driver *
    - Upper filters
    kbdclass.sys

    * Terminal Server Mouse Driver *
    - Upper filters
    mouclass.sys

    * WAN Miniport (IP) *
    - Lower filters
    NdisTapi.sys

    * WAN Miniport (PPPOE) *
    - Lower filters
    NdisTapi.sys

    * WAN Miniport (PPTP) *
    - Lower filters
    NdisTapi.sys



    --------------------

    Print monitors (9):

    BJ Language Monitor - cnbjmon.dll
    HP Standard TCP/IP Port - HpTcpMon.dll
    Language Monitor - hpz3l3xu.dll
    Local Port - localspl.dll
    Microsoft Document Imaging Writer Monitor - mdimon.dll
    Microsoft Shared Fax Monitor - FXSMON.DLL
    PJL Language Monitor - pjlmon.dll
    Standard TCP/IP Port - tcpmon.dll
    USB Monitor - usbmon.dll

    --------------------

    WOW compatibility:

    cmdline = C:\WINDOWS\system32\ntvdm.exe
    wowcmdline = C:\WINDOWS\system32\ntvdm.exe -a C:\WINDOWS\system32\krnl386

    [KnownDlls (16-bit) (40)]
    avicap.dll
    avifile.dll
    comm.drv
    commdlg.dll
    compobj.dll
    ctl3dv2.dll
    ddeml.dll
    keyboard.drv
    lanman.drv
    mapi.dll
    mciavi.drv
    mciseq.drv
    mciwave.drv
    mmsystem.dll
    mouse.drv
    msacm.dll
    msvideo.dll
    netapi.dll
    ole2.dll
    ole2disp.dll
    ole2nls.dll
    olecli.dll
    olesvr.dll
    pmspl.dll
    progman.exe
    rasapi16.dll
    shell.dll
    sound.drv
    storage.dll
    system.drv
    timer.drv
    toolhelp.dll
    typelib.dll
    vga.drv
    wfwnet.drv
    win87em.dll
    winoldap.mod
    winsock.dll
    winspool.exe
    wowdeb.exe

    [KnownDlls (32-bit) (20)]
    advapi32.dll
    comdlg32.dll
    gdi32.dll
    imagehlp.dll
    kernel32.dll
    lz32.dll
    ole32.dll
    oleaut32.dll
    olecli32.dll
    olecnv32.dll
    olesvr32.dll
    olethk32.dll
    rpcrt4.dll
    shell32.dll
    url.dll
    urlmon.dll
    user32.dll
    version.dll
    wininet.dll
    wldap32.dll


    --------------------------------------------------
    End of report, 172,995 bytes

    Commandline options:
    /showempty - Show empty sections
    /showcmts - Show comments in .bat files
    /noshowclsids - Hide class IDs
    /noshowprivate - Hide usernames and computer name
    /noshowusers - Hide entries from other users
    /noshowhardware - Hide entries from other hardware configurations
    /showlargehosts - Show hosts file even when more than 1000 lines are in it
    /showlargezones - Show Zones even when more than 1000 domains are in them
    /autosave - Run hidden, automatically save a report and quit

  10. #10
    Junior Member
    Join Date
    Jan 2013
    Posts
    1
    For the past year or so I had this problem and it finally went away.

    It went away when I could not access the Internet. My trouble shooting revealed invalid IP address and invalid network. The Uverse repair came out to the house and reset the system. The poroblem was fixed as I was able to get on the Internet. And as an added bonus, the cmd screen upon computer start-up did not come back.

    My opinion, and its only an opinion, has to do with the network I was accessing in the past, it was called network2. After the repair, I noticed I now accessed network 3 to get on the Internet. No more cmd screen when I fired up the computer.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •