DDS
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Thomas at 13:42:40.09 on 27/03/2011
internet explorer: 8.0.6001.19019
browserjavaversion: 1.6.0_23
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2046.949 [GMT 1:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\svchost.exe -k Akamai
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
C:\Windows\system32\libusbd-nt.exe
C:\Windows\system32\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Ralink\Common\RaRegistry.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
C:\Windows\system32\wbem\wmiprvse.exe
c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Common Files\Steam\SteamService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Thomas\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\nvvsvc.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\system32\SLsvc.exe
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
C:\Windows\system32\libusbd-nt.exe
C:\Windows\system32\PnkBstrA.exe
C:\Program Files\Ralink\Common\RaRegistry.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
C:\Windows\system32\wbem\wmiprvse.exe
c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Common Files\Steam\SteamService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Thomas\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\svchost.exe -k Akamai
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
.
============== Pseudo HJT Report ===============
.
.
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 (C)
.
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
Disable Script Debugger REG_SZ yes
Anchor Underline REG_SZ yes
Cache_Update_Frequency REG_SZ Once_Per_Session
Display Inline Images REG_SZ yes
Do404Search REG_BINARY 01000000
Save_Session_History_On_Exit REG_SZ no
Show_FullURL REG_SZ no
Show_StatusBar REG_SZ yes
Show_ToolBar REG_SZ yes
Show_URLinStatusBar REG_SZ yes
Show_URLToolBar REG_SZ yes
Use_DlgBox_Colors REG_SZ yes
XMLHTTP REG_DWORD 1 (0x1)
NoUpdateCheck REG_DWORD 1 (0x1)
UseClearType REG_SZ yes
Enable Browser Extensions REG_SZ yes
Play_Background_Sounds REG_SZ yes
Play_Animations REG_SZ yes
Start Page REG_SZ http://www.skip-search.com/?cfg=2-82-0- ... country=GB
SearchMigrated REG_DWORD 0 (0x0)
IE8RunOnceLastShown REG_DWORD 1 (0x1)
IE8RunOncePerInstallCompleted REG_DWORD 1 (0x1)
IE8RunOnceCompletionTime REG_BINARY bf944b35c3e8cb01
IE8TourShown REG_DWORD 1 (0x1)
IE8TourShownTime REG_BINARY 4f609fab42e7cb01
Use Search Asst REG_SZ no
StatusBarWeb REG_DWORD 1 (0x1)
SearchControlWidth REG_DWORD 300 (0x12c)
ForceGDIPlus REG_DWORD 0 (0x0)
AlwaysShowMenus REG_DWORD 0 (0x0)
SuppressScriptDebuggerDialog REG_DWORD 0 (0x0)
Page_Transitions REG_DWORD 1 (0x1)
CSS_Compat REG_SZ doctype
Expand Alt Text REG_SZ no
Display Inline Videos REG_DWORD 1 (0x1)
Print_Background REG_SZ no
Use Stylesheets REG_DWORD 1 (0x1)
SmoothScroll REG_DWORD 1 (0x1)
Show image placeholders REG_DWORD 0 (0x0)
DisableScriptDebuggerIE REG_SZ yes
Move System Caret REG_SZ no
Force Offscreen Composition REG_DWORD 0 (0x0)
Enable AutoImageResize REG_SZ yes
UseThemes REG_DWORD 1 (0x1)
UseHR REG_DWORD 0 (0x0)
Q300829 REG_DWORD 0 (0x0)
Cleanup HTCs REG_DWORD 0 (0x0)
XDomainRequest REG_DWORD 1 (0x1)
DOMStorage REG_DWORD 1 (0x1)
IE8TourNoShow REG_DWORD 0 (0x0)
FrameTabWindow REG_DWORD 1 (0x1)
AdminTabProcs REG_DWORD 1 (0x1)
SessionMerging REG_DWORD 1 (0x1)
FrameMerging REG_DWORD 1 (0x1)
HangResistantFrame REG_DWORD 0 (0x0)
TabShutdownDelay REG_DWORD 60000 (0xea60)
FrameShutdownDelay REG_DWORD 0 (0x0)
FullScreen REG_SZ no
Window_Placement REG_BINARY 2c00000002000000030000000083ffff0083ffffffffffffffffffffc40100002a000000160400003f030000
CompatibilityFlags REG_DWORD 0 (0x0)
IE8RunOnceLastShown_TIMESTAMP REG_BINARY 2fdadf22c3e8cb01
NotifyDownloadComplete REG_SZ yes
Use FormSuggest REG_SZ yes
Check_Associations REG_SZ no
Start Page Restore REG_SZ http://www.google.co.uk/
.
HKEY_CURRENT_USER\software\microsoft\internet explorer\main\Default Feeds
.
HKEY_CURRENT_USER\software\microsoft\internet explorer\main\FeatureControl
.
HKEY_CURRENT_USER\software\microsoft\internet explorer\main\Touch
.
HKEY_CURRENT_USER\software\microsoft\internet explorer\main\WindowsSearch
.
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 (C)
.
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main
AutoHide REG_SZ yes
Default_Secondary_Page_URL REG_MULTI_SZ \0\0
Extensions Off Page REG_SZ about:NoAdd-ons
Security Risk Page REG_SZ about:SecurityRisk
Enable_Disk_Cache REG_SZ yes
Cache_Percent_of_Disk REG_BINARY 0a000000
Delete_Temp_Files_On_Exit REG_SZ yes
Anchor_Visitation_Horizon REG_BINARY 01000000
Use_Async_DNS REG_SZ yes
Placeholder_Width REG_BINARY 1a000000
Placeholder_Height REG_BINARY 1a000000
Check_Associations REG_SZ yes
FrameAuto REG_DWORD 1 (0x1)
Enable Browser Extensions REG_SZ yes
Use Search Asst REG_SZ no
.
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main\ErrorThresholds
.
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main\FeatureControl
.
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main\UrlTemplate
.
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 (C)
.
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings
IE5_UA_Backup_Flag REG_SZ 5.0
User Agent REG_SZ Mozilla/4.0 (compatible; MSIE 8.0; Win32)
EmailName REG_SZ IEUser@
AutoConfigProxy REG_SZ wininet.dll
MimeExclusionListForCache REG_SZ multipart/mixed multipart/x-mixed-replace multipart/x-byteranges
UseSchannelDirectly REG_BINARY 01000000
EnableHttp1_1 REG_DWORD 1 (0x1)
PrivDiscUiShown REG_DWORD 1 (0x1)
WarnOnIntranet REG_DWORD 1 (0x1)
WarnOnPost REG_BINARY 01000000
UrlEncoding REG_DWORD 0 (0x0)
SecureProtocols REG_DWORD 160 (0xa0)
PrivacyAdvanced REG_DWORD 0 (0x0)
DisableCachingOfSSLPages REG_DWORD 0 (0x0)
WarnonZoneCrossing REG_DWORD 0 (0x0)
CertificateRevocation REG_DWORD 1 (0x1)
EnableNegotiate REG_DWORD 1 (0x1)
MigrateProxy REG_DWORD 1 (0x1)
ProxyEnable REG_DWORD 0 (0x0)
ProxyOverride REG_SZ *.local
ZonesSecurityUpgrade REG_BINARY 6aad9b52da93cb01
EnableAutodial REG_DWORD 0 (0x0)
NoNetAutodial REG_DWORD 0 (0x0)
GlobalUserOffline REG_DWORD 0 (0x0)
ReceiveTimeout REG_DWORD 90000 (0x15f90)
ProxyHttp1.1 REG_DWORD 1 (0x1)
EnablePunycode REG_DWORD 1 (0x1)
ShowPunycode REG_DWORD 0 (0x0)
CreateUriCacheSize REG_DWORD 80 (0x50)
CoInternetCombineIUriCacheSize REG_DWORD 80 (0x50)
SecurityIdIUriCacheSize REG_DWORD 30 (0x1e)
SpecialFoldersCacheSize REG_DWORD 8 (0x8)
SyncMode5 REG_DWORD 3 (0x3)
.
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\5.0
.
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Activities
.
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Cache
.
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Connections
.
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Http Filters
.
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Lockdown_Zones
.
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\P3P
.
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Passport
.
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Protocols
.
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Url History
.
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Wpad
.
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\ZoneMap
.
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Zones
.
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 (C)
.
Error: Key: software\microsoft\internet explorer\search does not exist!
.
.
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 (C)
.
Error: Key: software\microsoft\internet explorer\search does not exist!
.
SteelWerX Registry Console Tool 2.0URLSearchHooks: H - No File
Written by Bobbi Flekman 2006 (C)URLSearchHooks: H - No File
HKEY_CURRENT_USER\software\microsoft\internet explorer\urlsearchhooksURLSearchHooks: H - No File
SteelWerX Registry Console Tool 2.0URLSearchHooks: H - No File
Written by Bobbi Flekman 2006 (C)URLSearchHooks: H - No File
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\urlsearchhooksURLSearchHooks: H - No File
SteelWerX Registry Console Tool 2.0URLSearchHooks: H - No File
Written by Bobbi Flekman 2006 (C)URLSearchHooks: H - No File
Error: Key: .default\software\microsoft\internet explorer\urlsearchhooks does not exist!URLSearchHooks: H - No File
.
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 (C)
.
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon
ReportBootOk REG_SZ 1
Shell REG_SZ explorer.exe
Userinit REG_SZ c:\Windows\system32e\userinit.exe,
VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
AutoRestartShell REG_DWORD 1 (0x1)
LegalNoticeCaption REG_SZ
LegalNoticeText REG_SZ
PowerdownAfterShutdown REG_SZ 0
ShutdownWithoutLogon REG_SZ 0
cachedlogonscount REG_SZ 10
forceunlocklogon REG_DWORD 0 (0x0)
passwordexpirywarning REG_DWORD 14 (0xe)
Background REG_SZ 0 0 0
DebugServerCommand REG_SZ no
WinStationsDisabled REG_SZ 0
DisableCAD REG_DWORD 1 (0x1)
scremoveoption REG_SZ 0
ShutdownFlags REG_DWORD 43 (0x2b)
AutoAdminLogon REG_SZ 0
System REG_SZ
.
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\GPExtensions
.
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\Ralink
.
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\AutoLogonChecked
.
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 (C)
.
HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\winlogon
ExcludeProfileDirs REG_SZ AppData\Local;AppData\LocalLow;$Recycle.Bin
BuildNumber REG_DWORD 6002 (0x1772)
FirstLogon REG_DWORD 0 (0x0)
ParseAutoexec REG_SZ 1
.
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 (C)
.
HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows
DebugOptions REG_SZ 2048
Documents REG_SZ
DosPrint REG_SZ no
Load REG_SZ
NetMessage REG_SZ no
NullPort REG_SZ None
Programs REG_SZ com exe bat pif cmd
Device REG_SZ HP Deskjet 1050 J410 series,winspool,Ne01:
Run REG_SZ
BHO: <NO NAME> - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{000123B4-9B42-4900-B3F7-F4B073EFC214} - No File
BHO: <NO NAME> - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{0974BA1E-64EC-11DE-B2A5-E43756D89593} - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{28387537-e3f9-4ed7-860c-11e69af4a8a0} - No File
BHO: <NO NAME> - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6} - No File
BHO: NoExplorer - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} - No File
BHO: NoExplorer - No File
urun: [WMPNSCFG] c:\Program Files\Windows Media Playere\WMPNSCFG.exe
urun: [KPeerNexonEU] c:\Nexon\NEXON_EU_Downloadere\nxEULauncher.exe
urun: [cacaoweb] "c:\users\thomas\appdata\roaming\cacaowebe\cacaoweb.exe" -noplayer
mrun: [<NO NAME>]
mrun: [RtHDVCpl] c:\Program Files\Realtek\Audio\HDAe\RtHDVCpl.exe -s
mrun: [AppleSyncNotifier] c:\Program Files\Common Files\Apple\Mobile Device Supporte\AppleSyncNotifier.exe
mrun: [iTunesHelper] "c:\Program Files\iTunese\iTunesHelper.exe"
mrun: [Malwarebytes' Anti-Malware (reboot)] "c:\Program Files\Malwarebytes' Anti-Malwaree\mbam.exe" /runcleanupscript
mpolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mpolicies-system: EnableUIADesktopToggle = 0 (0x0)
.
ie: SteelWerX Registry Console Tool 2.0
ie: Written by Bobbi Flekman 2006 (C)
.
ie: HKEY_CURRENT_USER\software\microsoft\internet explorer\menuext
.
ie: HKEY_CURRENT_USER\software\microsoft\internet explorer\menuext\&Download by Orbit
ie: <NO NAME> REG_SZ res://c:\Program Files\Orbitdownloadere\orbitmxt.dll/201
ie: Contexts REG_DWORD 34 (0x22)
.
ie: HKEY_CURRENT_USER\software\microsoft\internet explorer\menuext\&Grab video by Orbit
ie: <NO NAME> REG_SZ res://c:\Program Files\Orbitdownloadere\orbitmxt.dll/204
ie: Contexts REG_DWORD 243 (0xf3)
.
ie: HKEY_CURRENT_USER\software\microsoft\internet explorer\menuext\Do&wnload selected by Orbit
ie: <NO NAME> REG_SZ res://c:\Program Files\Orbitdownloadere\orbitmxt.dll/203
ie: Contexts REG_DWORD 243 (0xf3)
.
ie: HKEY_CURRENT_USER\software\microsoft\internet explorer\menuext\Down&load all by Orbit
ie: <NO NAME> REG_SZ res://c:\Program Files\Orbitdownloadere\orbitmxt.dll/202
ie: Contexts REG_DWORD 243 (0xf3)
.
ie: {SteelWerX Registry Console Tool 2.0
ie: {Written by Bobbi Flekman 2006 (C)
.
ie: {HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
* REG_DWORD 2 (0x2)
* REG_DWORD 2 (0x2)
* REG_DWORD 2 (0x2)
* REG_DWORD 2 (0x2)
.
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 (C)
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{166B1BCA-3F9C-11CF-8075-444553540000}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{166B1BCA-3F9C-11CF-8075-444553540000}\Contains
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{166B1BCA-3F9C-11CF-8075-444553540000}\DownloadInformation
CODEBASE REG_SZ http://download.macromedia.com/pub/shoc ... tor/sw.cab
INF REG_SZ c:\Windows\Downloaded Program Filese\swdir.inf
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{166B1BCA-3F9C-11CF-8075-444553540000}\InstalledVersion
<NO NAME> REG_SZ 11,5,9,620
LastModified REG_SZ Tue, 15 Feb 2011 07:11:29 GMT
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{1E54D648-B804-468d-BC78-4AFFED8E262F}
<NO NAME> REG_SZ System Requirements Lab
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{1E54D648-B804-468d-BC78-4AFFED8E262F}\Contains
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{1E54D648-B804-468d-BC78-4AFFED8E262F}\Contains\Files
c:\Windows\Downloaded Program Filese\sysreqlab_nvd.dll REG_SZ
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{1E54D648-B804-468d-BC78-4AFFED8E262F}\Contains\FilesFlags
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{1E54D648-B804-468d-BC78-4AFFED8E262F}\Contains\FilesFlags\sysreqlab_nvd.dll
RedirectToHKCU REG_DWORD 0 (0x0)
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{1E54D648-B804-468d-BC78-4AFFED8E262F}\DownloadInformation
CODEBASE REG_SZ http://www.nvidia.com/content/DriverDow ... ab_nvd.cab
OSD REG_SZ c:\Windows\Downloaded Program Filese\sysreqlab.osd
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{1E54D648-B804-468d-BC78-4AFFED8E262F}\InstalledVersion
<NO NAME> REG_SZ 3,0,0,4
LastModified REG_SZ Fri, 03 Apr 2009 17:26:00 GMT
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{74DBCB52-F298-4110-951D-AD2FF67BC8AB}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{74DBCB52-F298-4110-951D-AD2FF67BC8AB}\Contains
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{74DBCB52-F298-4110-951D-AD2FF67BC8AB}\Contains\Files
c:\Windows\Downloaded Program Filese\NvidiaSmartScan.ocx REG_SZ
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{74DBCB52-F298-4110-951D-AD2FF67BC8AB}\Contains\FilesFlags
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{74DBCB52-F298-4110-951D-AD2FF67BC8AB}\Contains\FilesFlags\NvidiaSmartScan.ocx
RedirectToHKCU REG_DWORD 0 (0x0)
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{74DBCB52-F298-4110-951D-AD2FF67BC8AB}\DownloadInformation
CODEBASE REG_SZ http://www.nvidia.com/content/DriverDow ... rtScan.cab
INF REG_SZ c:\Windows\Downloaded Program Filese\NvidiaSmartScan.inf
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{74DBCB52-F298-4110-951D-AD2FF67BC8AB}\InstalledVersion
<NO NAME> REG_SZ 1,0,0,3
LastModified REG_SZ Thu, 18 Jun 2009 09:54:32 GMT
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
<NO NAME> REG_SZ Java Runtime Environment 1.6.0
Installer REG_SZ MSICD
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\Contains
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\DownloadInformation
CODEBASE REG_SZ http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
INF REG_SZ
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\InstalledVersion
<NO NAME> REG_SZ 1.6.0.23
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
<NO NAME> REG_SZ Java Runtime Environment 1.6.0
Installer REG_SZ MSICD
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\Contains
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\DownloadInformation
CODEBASE REG_SZ http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
INF REG_SZ
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\InstalledVersion
<NO NAME> REG_SZ 1.6.0.23
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
<NO NAME> REG_SZ Java Runtime Environment 1.6.0
Installer REG_SZ MSICD
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\Contains
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\DownloadInformation
CODEBASE REG_SZ http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
INF REG_SZ
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\InstalledVersion
<NO NAME> REG_SZ 1.6.0.23
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\Contains
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\Contains\Files
c:\Windows\Downloaded Program Filese\gp.ocx REG_SZ
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\DownloadInformation
CODEBASE REG_SZ http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
INF REG_SZ c:\Windows\Downloaded Program Filese\gp.inf
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\InstalledVersion
<NO NAME> REG_SZ 1,6,2,97
LastModified REG_SZ Mon, 29 Nov 2010 18:46:01 GMT
.
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 (C)
.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters
NameServer REG_SZ
.
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 (C)
.
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
d; /.* /!d; s//securityproviders: /
securityproviders REG_SZ credssp.dll
.
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 (C)
.
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
auditbaseobjects REG_DWORD 0 (0x0)
auditbasedirectories REG_DWORD 0 (0x0)
crashonauditfail REG_DWORD 0 (0x0)
fullprivilegeauditing REG_BINARY 00
Bounds REG_BINARY 0030000000200000
LimitBlankPasswordUse REG_DWORD 1 (0x1)
LmCompatibilityLevel REG_DWORD 3 (0x3)
NoLmHash REG_DWORD 1 (0x1)
d;/^((authentication|notification) packages) .* /i!d; s//lsa: 1 = /
Notification Packages REG_MULTI_SZ scecli
d;/^((authentication|notification) packages) .* /i!d; s//lsa: 1 = /
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg
d;/^((authentication|notification) packages) .* /i!d; s//lsa: 1 = /
Authentication Packages REG_MULTI_SZ msv1_0
LsaPid REG_DWORD 696 (0x2b8)
SecureBoot REG_DWORD 1 (0x1)
ProductType REG_DWORD 3 (0x3)
disabledomaincreds REG_DWORD 0 (0x0)
everyoneincludesanonymous REG_DWORD 0 (0x0)
forceguest REG_DWORD 0 (0x0)
restrictanonymous REG_DWORD 0 (0x0)
restrictanonymoussam REG_DWORD 1 (0x1)
.
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\AccessProviders
.
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\Audit
.
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\Credssp
.
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\Data
.
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\FipsAlgorithmPolicy
.
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\GBG
.
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\JD
.
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\Kerberos
.
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\MSV1_0
.
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\Skew1
.
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\SSO
.
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\SspiCache
.
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 (C)
.
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager\subsystems
windows REG_EXPAND_SZ %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\l8iw4m3r.defaulte\
# Mozilla User Preferences
.
/* Do not edit this file.
*
* If you make changes to this file while the application is running,
* the changes will be overwritten when the application exits.
*
* To make a manual change to preferences, you can visit the URL about:config
* For more information, see http://www.mozilla.org/unix/customizing.html#prefs
*/
.
user_pref("app.update.lastUpdateTime.addon-background-update-timer", 1301166114);
user_pref("app.update.lastUpdateTime.background-update-timer", 1301166354);
user_pref("app.update.lastUpdateTime.blocklist-background-update-timer", 1301166234);
user_pref("app.update.lastUpdateTime.microsummary-generator-update-timer", 1301079714);
user_pref("app.update.lastUpdateTime.search-engine-update-timer", 1301221744);
user_pref("browser.anchor_color", "#0000FF");
user_pref("browser.cache.disk.capacity", 1048576);
user_pref("browser.cache.disk.smart_size.first_run", false);
user_pref("browser.cache.disk.smart_size_cached_value", 1048576);
user_pref("browser.display.background_color", "#C0C0C0");
user_pref("browser.display.use_system_colors", true);
user_pref("browser.download.dir", "c:\\Users\\Thomas\e\Desktop");
user_pref("browser.download.folderList", 0);
user_pref("browser.download.manager.closeWhenDone", true);
user_pref("browser.migration.version", 5);
user_pref("browser.places.smartBookmarksVersion", 2);
user_pref("browser.preferences.advanced.selectedTabIndex", 0);
user_pref("browser.privatebrowsing.dont_prompt_on_enter", true);
user_pref("browser.rights.3.shown", true);
!d; s//ff - prefs.js: 1 - 2/; s.htt(p|ps)://.hxx1://.i; s/"//g
user_pref("browser.startup.homepage", "http://www.google.co.uk/");
user_pref("browser.startup.homepage_override.buildID", "20110318052756");
user_pref("browser.startup.homepage_override.mstone", "rv:2.0");
user_pref("browser.visited_color", "#800080");
user_pref("extensions.blocklist.pingCountTotal", 2);
user_pref("extensions.blocklist.pingCountVersion", 2);
user_pref("extensions.bootstrappedAddons", "{}");
user_pref("extensions.cacaoweb.firstRun", 0);
user_pref("extensions.databaseSchema", 3);
user_pref("extensions.enabledAddons", "{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13,{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15,{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}:6.0.18,{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20,{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23,{20a82645-c095-46ed-80e3-08825760534b}:0.0.0,cacaoweb@cacaoweb.org:1.0.11,{8F42A991-32E4-4D85-BDB5-7AA5DACC98A2}:1.9.1,{972ce4c6-7e08-4474-a285-3208198ce6fd}:4.0");
user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{20a82645-c095-46ed-80e3-08825760534b}\":{\"descriptor\":\"C:\\\\Windows\\\\Microsoft.NET\\\\Framework\\\\v3.5\\\\Windows Presentation Foundation\\\\DotNetAssistantExtension\",\"mtime\":1291475973751}}},{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program Files\\\\Mozilla Firefox\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"mtime\":1301079434627},\"{AB2CE124-6272-4b12-94A9-7303C7397BD1}\":{\"descriptor\":\"C:\\\\Program Files\\\\Mozilla Firefox\\\\extensions\\\\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\",\"mtime\":1275426469470},\"{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}\":{\"descriptor\":\"C:\\\\Program Files\\\\Mozilla Firefox\\\\extensions\\\\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}\",\"mtime\":1291822092032},\"{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}\":{\"descriptor\":\"C:\\\\Program Files\\\\Mozilla Firefox\\\\extensions\\\\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}\",\"mtime\":1291822092110},\"{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}\":{\"descriptor\":\"C:\\\\Program Files\\\\Mozilla Firefox\\\\extensions\\\\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}\",\"mtime\":1291822092203},\"{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\":{\"descriptor\":\"C:\\\\Program Files\\\\Mozilla Firefox\\\\extensions\\\\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\",\"mtime\":1275937390286},\"{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\":{\"descriptor\":\"C:\\\\Program Files\\\\Mozilla Firefox\\\\extensions\\\\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\",\"mtime\":1295460056857}}},{\"name\":\"winreg-app-user\",\"addons\":{\"{8F42A991-32E4-4D85-BDB5-7AA5DACC98A2}\":{\"descriptor\":\"C:\\\\Users\\\\Thomas\\\\AppData\\\\Local\\\\{8F42A991-32E4-4D85-BDB5-7AA5DACC98A2}\",\"mtime\":1301147356872}}},{\"name\":\"app-profile\",\"addons\":{\"cacaoweb@cacaoweb.org\":{\"descriptor\":\"C:\\\\Users\\\\Thomas\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\l8iw4m3r.default\\\\extensions\\\\cacaoweb@cacaoweb.org\",\"mtime\":1301146276695},\"SkipScreen@SkipScreen\":{\"descriptor\":\"C:\\\\Users\\\\Thomas\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\l8iw4m3r.default\\\\extensions\\\\SkipScreen@SkipScreen\",\"mtime\":1301145934025},\"{35379F86-8CCB-4724-AE33-4278DE266C70}\":{\"descriptor\":\"C:\\\\Program Files\\\\Orbitdownloader\\\\addons\\\\OneClickYouTubeDownloader\",\"mtimee\":1301079588898}}}]");
user_pref("extensions.lastAppVersion", "4.0");
user_pref("extensions.pendingOperations", false);
user_pref("general.warnOnAboutConfig", false);
user_pref("idle.lastDailyNotification", 1301147188);
user_pref("intl.charsetmenu.browser.cache", "windows-1254, ISO-8859-1, UTF-8");
user_pref("network.cookie.prefsMigrated", true);
user_pref("network.proxy.no_proxies_on", "*.local");
user_pref("network.proxy.type", 0);
user_pref("places.database.lastMaintenance", 1301147189);
user_pref("places.history.expiration.transient_current_max_pages", 64355);
user_pref("privacy.sanitize.migrateFx3Prefs", true);
user_pref("privacy.sanitize.timeSpan", 0);
user_pref("security.warn_viewing_mixed", false);
user_pref("services.sync.clients.lastSync", "0");
user_pref("services.sync.clients.lastSyncLocal", "0");
user_pref("services.sync.migrated", true);
user_pref("services.sync.tabs.lastSync", "0");
user_pref("services.sync.tabs.lastSyncLocal", "0");
user_pref("storage.vacuum.last.index", 0);
user_pref("storage.vacuum.last.places.sqlite", 1301147189);
user_pref("urlclassifier.keyupdatetime.https://sb-ssl.google.com/safebrowsing/newkey", 1303758802);
user_pref("xpinstall.whitelist.add", "");
user_pref("xpinstall.whitelist.add.36", "");
# Mozilla User Preferences
.
/* Do not edit this file.
*
* If you make changes to this file while the application is running,
* the changes will be overwritten when the application exits.
*
* To make a manual change to preferences, you can visit the URL about:config
* For more information, see http://www.mozilla.org/unix/customizing.html#prefs
*/
.
user_pref("app.update.lastUpdateTime.addon-background-update-timer", 1301166114);
user_pref("app.update.lastUpdateTime.background-update-timer", 1301166354);
user_pref("app.update.lastUpdateTime.blocklist-background-update-timer", 1301166234);
user_pref("app.update.lastUpdateTime.microsummary-generator-update-timer", 1301079714);
user_pref("app.update.lastUpdateTime.search-engine-update-timer", 1301221744);
user_pref("browser.anchor_color", "#0000FF");
user_pref("browser.cache.disk.capacity", 1048576);
user_pref("browser.cache.disk.smart_size.first_run", false);
user_pref("browser.cache.disk.smart_size_cached_value", 1048576);
user_pref("browser.display.background_color", "#C0C0C0");
user_pref("browser.display.use_system_colors", true);
user_pref("browser.download.dir", "c:\\Users\\Thomas\e\Desktop");
user_pref("browser.download.folderList", 0);
user_pref("browser.download.manager.closeWhenDone", true);
user_pref("browser.migration.version", 5);
user_pref("browser.places.smartBookmarksVersion", 2);
user_pref("browser.preferences.advanced.selectedTabIndex", 0);
user_pref("browser.privatebrowsing.dont_prompt_on_enter", true);
user_pref("browser.rights.3.shown", true);
user_pref("browser.startup.homepage", "http://www.google.co.uk/");
user_pref("browser.startup.homepage_override.buildID", "20110318052756");
user_pref("browser.startup.homepage_override.mstone", "rv:2.0");
user_pref("browser.visited_color", "#800080");
user_pref("extensions.blocklist.pingCountTotal", 2);
user_pref("extensions.blocklist.pingCountVersion", 2);
user_pref("extensions.bootstrappedAddons", "{}");
user_pref("extensions.cacaoweb.firstRun", 0);
user_pref("extensions.databaseSchema", 3);
user_pref("extensions.enabledAddons", "{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13,{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15,{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}:6.0.18,{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20,{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23,{20a82645-c095-46ed-80e3-08825760534b}:0.0.0,cacaoweb@cacaoweb.org:1.0.11,{8F42A991-32E4-4D85-BDB5-7AA5DACC98A2}:1.9.1,{972ce4c6-7e08-4474-a285-3208198ce6fd}:4.0");
user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{20a82645-c095-46ed-80e3-08825760534b}\":{\"descriptor\":\"C:\\\\Windows\\\\Microsoft.NET\\\\Framework\\\\v3.5\\\\Windows Presentation Foundation\\\\DotNetAssistantExtension\",\"mtime\":1291475973751}}},{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program Files\\\\Mozilla Firefox\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"mtime\":1301079434627},\"{AB2CE124-6272-4b12-94A9-7303C7397BD1}\":{\"descriptor\":\"C:\\\\Program Files\\\\Mozilla Firefox\\\\extensions\\\\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\",\"mtime\":1275426469470},\"{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}\":{\"descriptor\":\"C:\\\\Program Files\\\\Mozilla Firefox\\\\extensions\\\\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}\",\"mtime\":1291822092032},\"{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}\":{\"descriptor\":\"C:\\\\Program Files\\\\Mozilla Firefox\\\\extensions\\\\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}\",\"mtime\":1291822092110},\"{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}\":{\"descriptor\":\"C:\\\\Program Files\\\\Mozilla Firefox\\\\extensions\\\\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}\",\"mtime\":1291822092203},\"{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\":{\"descriptor\":\"C:\\\\Program Files\\\\Mozilla Firefox\\\\extensions\\\\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\",\"mtime\":1275937390286},\"{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\":{\"descriptor\":\"C:\\\\Program Files\\\\Mozilla Firefox\\\\extensions\\\\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\",\"mtime\":1295460056857}}},{\"name\":\"winreg-app-user\",\"addons\":{\"{8F42A991-32E4-4D85-BDB5-7AA5DACC98A2}\":{\"descriptor\":\"C:\\\\Users\\\\Thomas\\\\AppData\\\\Local\\\\{8F42A991-32E4-4D85-BDB5-7AA5DACC98A2}\",\"mtime\":1301147356872}}},{\"name\":\"app-profile\",\"addons\":{\"cacaoweb@cacaoweb.org\":{\"descriptor\":\"C:\\\\Users\\\\Thomas\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\l8iw4m3r.default\\\\extensions\\\\cacaoweb@cacaoweb.org\",\"mtime\":1301146276695},\"SkipScreen@SkipScreen\":{\"descriptor\":\"C:\\\\Users\\\\Thomas\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\l8iw4m3r.default\\\\extensions\\\\SkipScreen@SkipScreen\",\"mtime\":1301145934025},\"{35379F86-8CCB-4724-AE33-4278DE266C70}\":{\"descriptor\":\"C:\\\\Program Files\\\\Orbitdownloader\\\\addons\\\\OneClickYouTubeDownloader\",\"mtimee\":1301079588898}}}]");
user_pref("extensions.lastAppVersion", "4.0");
user_pref("extensions.pendingOperations", false);
user_pref("general.warnOnAboutConfig", false);
user_pref("idle.lastDailyNotification", 1301147188);
user_pref("intl.charsetmenu.browser.cache", "windows-1254, ISO-8859-1, UTF-8");
user_pref("network.cookie.prefsMigrated", true);
user_pref("network.proxy.no_proxies_on", "*.local");
!d; s//ff - prefs.js: 1/; s/", / - /; s/);//i; s/"//g
user_pref("network.proxy.type", 0);
user_pref("places.database.lastMaintenance", 1301147189);
user_pref("places.history.expiration.transient_current_max_pages", 64355);
user_pref("privacy.sanitize.migrateFx3Prefs", true);
user_pref("privacy.sanitize.timeSpan", 0);
user_pref("security.warn_viewing_mixed", false);
user_pref("services.sync.clients.lastSync", "0");
user_pref("services.sync.clients.lastSyncLocal", "0");
user_pref("services.sync.migrated", true);
user_pref("services.sync.tabs.lastSync", "0");
user_pref("services.sync.tabs.lastSyncLocal", "0");
user_pref("storage.vacuum.last.index", 0);
user_pref("storage.vacuum.last.places.sqlite", 1301147189);
user_pref("urlclassifier.keyupdatetime.https://sb-ssl.google.com/safebrowsing/newkey", 1303758802);
user_pref("xpinstall.whitelist.add", "");
user_pref("xpinstall.whitelist.add.36", "");
ff - plugin: c:\Program Files\Google\Update\1.2.183.39e\npGoogleOneClick8.dll
ff - plugin: c:\Program Files\Java\jre6\bin\new_plugine\npdeployJava1.dll
ff - plugin: c:\Program Files\Microsoft Silverlight\4.0.60129.0e\npctrlui.dll
ff - plugin: c:\Program Files\Mozilla Firefox\pluginse\npdeployJava1.dll
ff - plugin: c:\Program Files\NVIDIA Corporation\3D Visione\npnv3dv.dll
ff - plugin: c:\Program Files\NVIDIA Corporation\3D Visione\npnv3dvstreaming.dll
ff - plugin: c:\Program Files\Pando Networks\Media Boostere\npPandoWebPlugin.dll
ff - plugin: c:\ProgramData\NexonUS\NGMe\npNxGameUS.dll
ff - plugin: c:\Users\Thomas\AppData\Local\Microsoft\Internet Explorer\Downloaded Program Filese\npsoe.dll
ff - plugin: c:\Users\Thomas\AppData\LocalLow\Unity\WebPlayer\loadere\npUnity3D32.dll
ff - plugin: c:\Windows\system32e\npmproxy.dll
ff - plugin: c:\Windows\system32e\npOGPPlugin.dll
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;c:\Windows\System32\driverse\MpFilter.sys [2010-10-24 165264]
R1 MpKslb193e56c;MpKslb193e56c;c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{6BAC5ABA-EBFF-4A39-AF22-B259096BCE96}e\MpKslb193e56c.sys [2011-3-27 28752]
R2 Akamai;Akamai NetSession Interface;c:\Windows\System32e\svchost.exe -k Akamai [2010-12-11 21504]
R2 FontCache;Windows Font Cache Service;c:\Windows\system32e\svchost.exe -k LocalServiceAndNoImpersonation [2010-12-11 21504]
R2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;system32\libusbd-nt.exe --> system32\libusbd-nt.exe [?]
R2 RalinkRegistryWriter;Ralink Registry Writer;c:\Program Files\Ralink\Commone\RaRegistry.exe [2010-12-2 185632]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\Program Files\NVIDIA Corporation\3D Visione\nvSCPAPISvr.exe [2011-1-7 378984]
R3 3xHybrid;3xHybrid service;c:\Windows\System32\driverse\3xHybrid.sys [2007-4-20 674048]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\Windows\System32\driverse\libusb0.sys [2011-3-26 33792]
R3 netr28u;RT2870 USB Wireless LAN Card Driver for Vista;c:\Windows\System32\driverse\netr28u.sys [2010-12-2 798208]
R3 NisDrv;Microsoft Network Inspection System;c:\Windows\System32\driverse\NisDrvWFP.sys [2010-10-24 54144]
R3 NisSrv;Microsoft Network Inspection;c:\Program Files\Microsoft Security Client\Antimalwaree\NisSrv.exe [2010-11-11 206360]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\Windows\Microsoft.NET\Framework\v4.0.30319e\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\Program Files\Google\Updatee\GoogleUpdate.exe [2010-12-2 136176]
S3 EagleXNt;EagleXNt;c:\Windows\System32\driverse\EagleXNt.sys [2011-2-17 459616]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\Windows\System32\driverse\MpNWMon.sys [2010-10-24 43392]
S3 npggsvc;nProtect GameGuard Service;c:\Windows\system32\GameMon.des -service --> C:\Windows\system32e\GameMon.des -service [?]
S3 Ph3xIB32;Philips 713x Inbox PCI TV Card;c:\Windows\System32\driverse\Ph3xIB32.sys [2006-11-2 1083520]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\Windows\Microsoft.NET\Framework\v4.0.30319\WPFe\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== File Associations ===============
.
AIFFFile="%ProgramFiles%\Windows Media Player\wmplayer.exe" /Open "%L"
AIR.InstallerPackage=c:\PROGRA~1\COMMON~1\ADOBEA~1\Versions\1.0e\ADOBEA~1.EXE "%1"
Application.Manifest=rundll32.exe dfshim.dll,ShOpenVerbApplication %1
Application.Reference=rundll32.exe dfshim.dll,ShOpenVerbShortcut %1|%2
ASFFile="%ProgramFiles%\Windows Media Player\wmplayer.exe" /prefetch:7 /Open "%L"
ASXFile="%ProgramFiles%\Windows Media Player\wmplayer.exe" /Open "%L"
AUFile="%ProgramFiles%\Windows Media Player\wmplayer.exe" /Open "%L"
AVIFile="%ProgramFiles%\Windows Media Player\wmplayer.exe" /prefetch:8 /Open "%L"
!d
BitTorrent="c:\PROGRA~1\FlashGete\FlashGet.exe" "%1"
CATFile=%SystemRoot%\system32\rundll32.exe cryptext.dll,CryptExtOpenCAT %1
cclaunch="c:\Program Files\CCleanere\ccleaner.exe" /%1
cdafile="%ProgramFiles%\Windows Media Player\wmplayer.exe" /Open "%L"
CERFile=%SystemRoot%\system32\rundll32.exe cryptext.dll,CryptExtOpenCER %1
CertificateStoreFile=%SystemRoot%\system32\rundll32.exe cryptext.dll,CryptExtOpenSTR %1
certificate_wab_auto_file="%ProgramFiles%\Windows Mail\wab.exe" /certificate "%1"
cfxxefile="%1" %*
!d
!d
!d
CompressedFolder=%SystemRoot%\Explorer.exe /idlist,%I,%L
contact_wab_auto_file="%ProgramFiles%\Windows Mail\wab.exe" /contact "%1"
CRLFile=%SystemRoot%\system32\rundll32.exe cryptext.dll,CryptExtOpenCRL %1
daap=c:\Program Files\iTunese\iTunes.exe /url "%1"
dqyfile=c:\PROGRA~1\MICROS~3\Office12e\EXCEL.EXE
emffile="%systemroot%\system32\mspaint.exe" "%1"
evtfile=%SystemRoot%\system32\eventvwr.exe /l:"%1"
evtxfile=%SystemRoot%\system32\eventvwr.exe /l:"%1"
Excel.Addin="c:\Program Files\Microsoft Office\Office12e\EXCEL.EXE" /e
Excel.AddInMacroEnabled="c:\Program Files\Microsoft Office\Office12e\EXCEL.EXE" /e
Excel.Backup="c:\Program Files\Microsoft Office\Office12e\EXCEL.EXE" /e
Excel.Chart=c:\PROGRA~1\MICROS~3\Office12e\EXCEL.EXE /e
Excel.CSV="c:\Program Files\Microsoft Office\Office12e\EXCEL.EXE" /e
Excel.Macrosheet="c:\Program Files\Microsoft Office\Office12e\EXCEL.EXE" /e
Excel.OpenDocumentSpreadsheet.12="c:\Program Files\Microsoft Office\Office12e\EXCEL.EXE" /e
Excel.Sheet.12="c:\Program Files\Microsoft Office\Office12e\EXCEL.EXE" /e
Excel.Sheet.8="c:\Program Files\Microsoft Office\Office12e\EXCEL.EXE" /e
Excel.SheetBinaryMacroEnabled.12="c:\Program Files\Microsoft Office\Office12e\EXCEL.EXE" /e
Excel.SheetMacroEnabled.12="c:\Program Files\Microsoft Office\Office12e\EXCEL.EXE" /e
Excel.SLK="c:\Program Files\Microsoft Office\Office12e\EXCEL.EXE" /e
Excel.Template="c:\Program Files\Microsoft Office\Office12e\EXCEL.EXE" /e
Excel.Template.8="c:\Program Files\Microsoft Office\Office12e\EXCEL.EXE" /e
Excel.TemplateMacroEnabled="c:\Program Files\Microsoft Office\Office12e\EXCEL.EXE" /e
Excel.Workspace="c:\Program Files\Microsoft Office\Office12e\EXCEL.EXE" /e
Excel.XLL="c:\Program Files\Microsoft Office\Office12e\EXCEL.EXE" /e
Excelhtmlfile="c:\Program Files\Microsoft Office\Office12e\EXCEL.EXE"
Excelhtmltemplate="c:\Program Files\Microsoft Office\Office12e\EXCEL.EXE"
!d
Explorer.AssocProtocol.search-ms=%SystemRoot%\Explorer.exe /separate,/idlist,%I,%L
FirefoxHTML="c:\Program Files\Mozilla Firefoxe\firefox.exe" -requestPending -osint -url "%1"
FirefoxURL="c:\Program Files\Mozilla Firefoxe\firefox.exe" -requestPending -osint -url "%1"
FlashGet.Document=c:\PROGRA~1\FlashGete\FlashGet.exe "%1"
fndfile=%SystemRoot%\Explorer.exe
Folder=%SystemRoot%\Explorer.exe /separate,/idlist,%I,%L
fonfile=%SystemRoot%\System32\fontview.exe %1
ftp="c:\Program Files\Internet Explorere\IEXPLORE.EXE" %1
giffile="c:\Program Files\Internet Explorere\iexplore.exe" -nohome
group_wab_auto_file="%ProgramFiles%\Windows Mail\wab.exe" /Group "%1"
hlpfile=%SystemRoot%\winhlp32.exe %1
htafile=c:\Windows\system32e\mshta.exe "%1" %*
htmlfile="c:\Program Files\Internet Explorere\IEXPLORE.EXE" -nohome
http="c:\Program Files\Internet Explorere\IEXPLORE.EXE" -nohome
https="c:\Program Files\Internet Explorere\IEXPLORE.EXE" -nohome
icofile=%SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Gallery\PhotoViewer.dll", ImageView_Fullscreen %1
IE.AssocFile.HTM="c:\Program Files\Internet Explorere\iexplore.exe" -nohome
IE.AssocFile.MHT="c:\Program Files\Internet Explorere\iexplore.exe" -nohome
IE.AssocFile.URL="c:\Windows\System32\rundll32.exe" "C:\Windows\System32e\ieframe.dll",OpenURL %l
IE.FTP="c:\Program Files\Internet Explorere\iexplore.exe" %1
IE.HTTP="c:\Program Files\Internet Explorere\iexplore.exe" -nohome
IE.HTTPS="c:\Program Files\Internet Explorere\iexplore.exe" -nohome
!d
!d
InternetShortcut="c:\Windows\System32\rundll32.exe" "C:\Windows\System32e\ieframe.dll",OpenURL %l
iqyfile=c:\PROGRA~1\MICROS~3\Office12e\EXCEL.EXE /e
itls=c:\Program Files\iTunese\iTunes.exe /url "%1"
itms=c:\Program Files\iTunese\iTunes.exe /url "%1"
itmss=c:\Program Files\iTunese\iTunes.exe /url "%1"
itpc=c:\Program Files\iTunese\iTunes.exe /url "%1"
iTunes=c:\Program Files\iTunese\iTunes.exe /url "%1"
iTunes.aa="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.aax="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.aif="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.aifc="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.aiff="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.AssocProtocol.daap=c:\Program Files\iTunese\iTunes.exe /url "%1"
iTunes.AssocProtocol.itls=c:\Program Files\iTunese\iTunes.exe /url "%1"
iTunes.AssocProtocol.itms=c:\Program Files\iTunese\iTunes.exe /url "%1"
iTunes.AssocProtocol.itmss=c:\Program Files\iTunese\iTunes.exe /url "%1"
iTunes.AssocProtocol.itpc=c:\Program Files\iTunese\iTunes.exe /url "%1"
iTunes.AssocProtocol.pcast=c:\Program Files\iTunese\iTunes.exe /url "%1"
iTunes.cda="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.cdda="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.ipa="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.ipg="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.ipsw="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.itdb="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.ite="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.itl="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.itlp="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.itls="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.itms="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.itpc="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.m3u="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.m3u8="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.m4a="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.m4b="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.m4p="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.m4r="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.m4v="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.mov="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.mp2="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.mp3="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.mpeg="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.mpg="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.pcast="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.pls="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.rmp="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.wav="c:\Program Files\iTunese\iTunes.exe" /open "%L"
iTunes.wave="c:\Program Files\iTunese\iTunes.exe" /open "%L"
jarfile="c:\Program Files\Java\jre6\bine\javaw.exe" -jar "%1" %*
JNLPFile="c:\Program Files\Java\jre6\bine\javaws.exe" "%1"
jntfile="%ProgramFiles%\Windows Journal\Journal.exe" "%1"
jpegfile=%SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Gallery\PhotoViewer.dll", ImageView_Fullscreen %1
jpsfile="c:\Program Files\NVIDIA Corporation\3D Visione\NvStView.exe" "%1"
JSFile=c:\Windows\System32e\WScript.exe "%1" %*
jtpfile="%ProgramFiles%\Windows Journal\Journal.exe" "%1"
LDAP="%ProgramFiles%\Windows Mail\wab.exe" "/ldap:%1"
Logitech.VideoEffectPackageHandler=c:\PROGRA~1\COMMON~1\Logishrd\LQCVFXe\MODELF~1.EXE "%1"
m3ufile="%ProgramFiles%\Windows Media Player\wmplayer.exe" /prefetch:6 /Open "%L"
MacromediaFlashPaper.MacromediaFlashPaper="c:\Program Files\Internet Explorere\IEXPLORE.EXE" -nohome "%1"
mailto="%ProgramFiles%\Windows Mail\WinMail.exe" /mailurl:"%1"
MediaPackageFile="c:\Program Files\Microsoft Office\Office12e\MSTORE.EXE" "%1"
mhtmlfile="c:\Program Files\Internet Explorere\IEXPLORE.EXE" -nohome
Microsoft Internet Mail Message="%ProgramFiles%\Windows Mail\WinMail.exe" /eml:%1
Microsoft Internet News Message="%ProgramFiles%\Windows Mail\WinMail.exe" /nws:%1
Microsoft.InformationCard=c:\Windows\System32\rundll32.exe C:\Windows\System32e\infocardcpl.cpl,ImportInformationCard_RunDll %1
Microsoft.PowerShellConsole.1="c:\Windows\System32\WindowsPowerShell\v1.0e\powershell.exe" -p "%1"
Microsoft.PowerShellData.1="c:\Windows\System32e\notepad.exe" "%1"
Microsoft.PowerShellModule.1="c:\Windows\System32e\notepad.exe" "%1"
Microsoft.PowerShellScript.1="c:\Windows\System32e\notepad.exe" "%1"
Microsoft.System.Update.1="%systemroot%\system32\wusa.exe" "%1" %2 %3 %4
Microsoft.WindowsCardSpaceBackup=c:\Windows\System32\rundll32.exe C:\Windows\System32e\infocardcpl.cpl,ImportInformationCard_RunDll %1
MicrosoftChessTitansSaveFile="%ProgramFiles%\Microsoft Games\Chess\chess.exe" "%L"
MicrosoftComfyCakesSaveFile="%ProgramFiles%\Microsoft Games\Purble Place\PurblePlace.exe" "%L"
MicrosoftFreeCellSaveFile="%ProgramFiles%\Microsoft Games\FreeCell\FreeCell.exe" "%L"
MicrosoftHeartsSaveFile="%ProgramFiles%\Microsoft Games\Hearts\Hearts.exe" "%L"
MicrosoftMahjongTitansSaveFile="%ProgramFiles%\Microsoft Games\Mahjong\Mahjong.exe" "%L"
MicrosoftMinesweeperSaveFile="%ProgramFiles%\Microsoft Games\Minesweeper\minesweeper.exe" "%L"
MicrosoftPurblePairsSaveFile="%ProgramFiles%\Microsoft Games\Purble Place\PurblePlace.exe" "%L"
MicrosoftPurbleShopSaveFile="%ProgramFiles%\Microsoft Games\Purble Place\PurblePlace.exe" "%L"
MicrosoftSolitaireSaveFile="%ProgramFiles%\Microsoft Games\Solitaire\solitaire.exe" "%L"
MicrosoftSpiderSolitaireSaveFile="%ProgramFiles%\Microsoft Games\SpiderSolitaire\SpiderSolitaire.exe" "%L"
MIDFile="%ProgramFiles%\Windows Media Player\wmplayer.exe" /Open "%L"
migfile=c:\Windows\System32\migwize\migwiz.exe /Restore %1
MMS="%ProgramFiles%\Windows Media Player\wmplayer.exe" "%L"
mp3file="%ProgramFiles%\Windows Media Player\wmplayer.exe" /prefetch:6 /Open "%L"
mpegfile="%ProgramFiles%\Windows Media Player\wmplayer.exe" /prefetch:9 /Open "%L"
mpofile="c:\Program Files\NVIDIA Corporation\3D Visione\NvStView.exe" "%1"
mscfile=%SystemRoot%\system32\mmc.exe "%1" %*
MSDASC=Rundll32.exe "%CommonProgramFiles%\System\OLE DB\oledb32.dll",OpenDSLFile %1
msdigitallocker="%SystemRoot%\DigitalLocker\digitalx.exe" %1
MsdtManifest=%SystemRoot%\system32\msdt.exe /manifest "%1"
Msi.Package="%SystemRoot%\System32\msiexec.exe" /i "%1" %*
Msi.Patch="%SystemRoot%\System32\msiexec.exe" /p "%1" %*
MSInfoFile=%SystemRoot%\system32\msinfo32.exe "%1"
MSSLLFile="iexplore.exe" "%1"
MSSLPUFile=c:\Windows\system32\rundll32.exe C:\Windows\system32e\slcc.dll, OpenPackage %1
msstylesfile=%SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,Control_RunDLL %SystemRoot%\system32\desk.cpl desk,@Appearance /Action:OpenMSTheme /file:"%1"
MSWinCollab="%ProgramFiles%\Windows Collaboration\WinCollab.exe" -f "%1"
news="%ProgramFiles%\Windows Mail\WinMail.exe" /newsurl:"%1"
nntp="%ProgramFiles%\Windows Mail\WinMail.exe" /newsurl:"%1"
OfficeTheme.12="c:\Program Files\Microsoft Office\Office12e\POWERPNT.EXE" "%1"
OneNote=c:\PROGRA~1\MICROS~3\Office12e\ONENOTE.EXE /hyperlink "%1"
OneNote.Package="c:\Program Files\Microsoft Office\Office12e\ONENOTE.EXE" "%1"
OneNote.Section.1="c:\Program Files\Microsoft Office\Office12e\ONENOTE.EXE" "%1"
OneNote.TableOfContents="c:\Program Files\Microsoft Office\Office12e\ONENOTE.EXE" /navigate "%1"
OneNote.TableOfContents.12="c:\Program Files\Microsoft Office\Office12e\ONENOTE.EXE" /navigate "%1"
otffile=%SystemRoot%\System32\fontview.exe %1
P7RFile=%SystemRoot%\system32\rundll32.exe cryptext.dll,CryptExtOpenP7R %1
P7SFile=%SystemRoot%\system32\\rundll32.exe cryptext.dll,CryptExtOpenPKCS7 %1
Paint.Picture=%SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Gallery\PhotoViewer.dll", ImageView_Fullscreen %1
pbkfile=%SystemRoot%\system32\rasphone.exe -f "%1"
pcast=c:\Program Files\iTunese\iTunes.exe /url "%1"
PerfFile=%SystemRoot%\system32\mmc.exe %systemroot%\system32\perfmon.msc /F "%1"
pfmfile=%SystemRoot%\System32\fontview.exe %1
PhotoViewer.FileAssoc.Bitmap=%SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Gallery\PhotoViewer.dll", ImageView_Fullscreen %1
PhotoViewer.FileAssoc.JFIF=%SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Gallery\PhotoViewer.dll", ImageView_Fullscreen %1
PhotoViewer.FileAssoc.Jpeg=%SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Gallery\PhotoViewer.dll", ImageView_Fullscreen %1
PhotoViewer.FileAssoc.Png=%SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Gallery\PhotoViewer.dll", ImageView_Fullscreen %1
PhotoViewer.FileAssoc.Tiff=%SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Gallery\PhotoViewer.dll", ImageView_Fullscreen %1
PhotoViewer.FileAssoc.Wdp=%SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Gallery\PhotoViewer.dll", ImageView_Fullscreen %1
!d
pjpegfile=%SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Gallery\PhotoViewer.dll", ImageView_Fullscreen %1
pngfile=%SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Gallery\PhotoViewer.dll", ImageView_Fullscreen %1
pnsfile="c:\Program Files\NVIDIA Corporation\3D Visione\NvStView.exe" "%1"
PowerPoint.Addin.12="c:\Program Files\Microsoft Office\Office12e\POWERPNT.EXE" "%1"
PowerPoint.Addin.8="c:\Program Files\Microsoft Office\Office12e\POWERPNT.EXE" "%1"
PowerPoint.OpenDocumentPresentation.12="c:\Program Files\Microsoft Office\Office12e\POWERPNT.EXE" "%1"
PowerPoint.Show.12="c:\Program Files\Microsoft Office\Office12e\POWERPNT.EXE" "%1"
PowerPoint.Show.4=c:\PROGRA~1\MICROS~3\Office12e\POWERPNT.EXE "%1"
PowerPoint.Show.7=c:\PROGRA~1\MICROS~3\Office12e\POWERPNT.EXE "%1"
PowerPoint.Show.8="c:\Program Files\Microsoft Office\Office12e\POWERPNT.EXE" "%1"
PowerPoint.ShowMacroEnabled.12="c:\Program Files\Microsoft Office\Office12e\POWERPNT.EXE" "%1"
PowerPoint.Slide.12=c:\PROGRA~1\MICROS~3\Office12e\POWERPNT.EXE "%1"
PowerPoint.Slide.4=c:\PROGRA~1\MICROS~3\Office12e\POWERPNT.EXE "%1"
PowerPoint.Slide.7=c:\PROGRA~1\MICROS~3\Office12e\POWERPNT.EXE "%1"
PowerPoint.Slide.8=c:\PROGRA~1\MICROS~3\Office12e\POWERPNT.EXE "%1"
PowerPoint.SlideMacroEnabled.12=c:\PROGRA~1\MICROS~3\Office12e\POWERPNT.EXE "%1"
PowerPoint.SlideShow.12="c:\Program Files\Microsoft Office\Office12e\POWERPNT.EXE" /s "%1"
PowerPoint.SlideShow.8="c:\Program Files\Microsoft Office\Office12e\POWERPNT.EXE" /s "%1"
PowerPoint.SlideShowMacroEnabled.12="c:\Program Files\Microsoft Office\Office12e\POWERPNT.EXE" /s "%1"
PowerPoint.Template.12="c:\Program Files\Microsoft Office\Office12e\POWERPNT.EXE" "%1"
PowerPoint.Template.8="c:\Program Files\Microsoft Office\Office12e\POWERPNT.EXE" "%1"
PowerPoint.TemplateMacroEnabled.12="c:\Program Files\Microsoft Office\Office12e\POWERPNT.EXE" "%1"
PowerPoint.Wizard.8="c:\Program Files\Microsoft Office\Office12e\POWERPNT.EXE" "%1"
powerpointhtmlfile="c:\Program Files\Microsoft Office\Office12e\POWERPNT.EXE"
powerpointhtmltemplate="c:\Program Files\Microsoft Office\Office12e\POWERPNT.EXE"
powerpointxmlfile="c:\Program Files\Microsoft Office\Office12e\POWERPNT.EXE"
prffile="c:\Windows\System32\rundll32.exe" "C:\Windows\System32e\msrating.dll",ClickedOnPRF %1
QuickTime.3g2=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.3gp=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.3gp2=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.3gpp=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.aac=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.ac3=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.adts=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.aif=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.aifc=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.aiff=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.amc=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.AMR=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.au=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.avi=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.bmp=c:\Program Files\QuickTimee\PictureViewer.exe "%1"
QuickTime.bwf=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.caf=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.cdda=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.cel=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.dib=c:\Program Files\QuickTimee\PictureViewer.exe "%1"
QuickTime.dif=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.dv=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.flc=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.fli=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.gif=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.gsm=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.jp2=c:\Program Files\QuickTimee\PictureViewer.exe "%1"
QuickTime.jpe=c:\Program Files\QuickTimee\PictureViewer.exe "%1"
QuickTime.jpeg=c:\Program Files\QuickTimee\PictureViewer.exe "%1"
QuickTime.jpg=c:\Program Files\QuickTimee\PictureViewer.exe "%1"
QuickTime.kar=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.m15=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.m1a=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.m1s=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.m1v=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.m3u=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.m3url=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.m4a=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.m4b=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.m4p=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.m4v=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.m75=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.mac=c:\Program Files\QuickTimee\PictureViewer.exe "%1"
QuickTime.mid=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.midi=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.mov=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.mp2=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.mp3=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.mp4=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.mpa=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.mpeg=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.mpg=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.mpm=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.mpv=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.mqv=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.pct=c:\Program Files\QuickTimee\PictureViewer.exe "%1"
QuickTime.pic=c:\Program Files\QuickTimee\PictureViewer.exe "%1"
QuickTime.pict=c:\Program Files\QuickTimee\PictureViewer.exe "%1"
QuickTime.png=c:\Program Files\QuickTimee\PictureViewer.exe "%1"
QuickTime.pnt=c:\Program Files\QuickTimee\PictureViewer.exe "%1"
QuickTime.pntg=c:\Program Files\QuickTimee\PictureViewer.exe "%1"
QuickTime.psd=c:\Program Files\QuickTimee\PictureViewer.exe "%1"
QuickTime.qcp=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.qht=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.qhtm=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.qt=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.qti=c:\Program Files\QuickTimee\PictureViewer.exe "%1"
QuickTime.qtif=c:\Program Files\QuickTimee\PictureViewer.exe "%1"
QuickTime.qtl=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.rgb=c:\Program Files\QuickTimee\PictureViewer.exe "%1"
QuickTime.rts=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.rtsp=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.sd2=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.sdp=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.sdv=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.sgi=c:\Program Files\QuickTimee\PictureViewer.exe "%1"
QuickTime.smf=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.smi=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.smil=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.sml=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.snd=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.swa=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.targa=c:\Program Files\QuickTimee\PictureViewer.exe "%1"
QuickTime.tga=c:\Program Files\QuickTimee\PictureViewer.exe "%1"
QuickTime.tif=c:\Program Files\QuickTimee\PictureViewer.exe "%1"
QuickTime.tiff=c:\Program Files\QuickTimee\PictureViewer.exe "%1"
QuickTime.ulw=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.vfw=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
QuickTime.wav=c:\Program Files\QuickTimee\QuickTimePlayer.exe "%1"
ratfile="c:\Windows\System32\rundll32.exe" "C:\Windows\System32e\msrating.dll",ClickedOnRAT %1
!d
!d
RemoteAssistance.1="%systemRoot%\system32\msra.exe" -openfile "%1"
rlefile="%systemroot%\system32\mspaint.exe" "%1"
rlogin="c:\Windows\System32\rundll32.exe" "C:\Windows\System32e\url.dll",TelnetProtocolHandler %l
rtffile="%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1"
Safari.safariextz="c:\Program Files\Safarie\Safari.exe" "%1"
Safari.webarchive="c:\Program Files\Safarie\Safari.exe" "%1"
SafariDownload="c:\Program Files\Safarie\Safari.exe" -url "%1"
SafariHTML="c:\Program Files\Safarie\Safari.exe" -url "%1"
SafariURL="c:\Program Files\Safarie\Safari.exe" -url "%1"
SavedDsQuery=%SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\dsquery.dll,OpenSavedDsQuery %1
!d
scriptletfile="c:\Windows\system32e\NOTEPAD.EXE" "%1"
search=%SystemRoot%\Explorer.exe /separate,/idlist,%I,%L
search-ms=%SystemRoot%\Explorer.exe /separate,/idlist,%I,%L
SHCmdFile=%SystemRoot%\explorer.exe
SMUpdatePack=c:\Perfect World Entertainment\Forsaken Worlde\patcher.exe "/localupdate:%1"
snews="%ProgramFiles%\Windows Mail\WinMail.exe" /newsurl:"%1"
SoundRec="%ProgramFiles%\Windows Media Player\wmplayer.exe" /Open "%L"
SPCFile=%SystemRoot%\system32\rundll32.exe cryptext.dll,CryptExtOpenPKCS7 %1
steam="c:\Program Files\Steame\steam.exe" "%1"
STLFile=%SystemRoot%\system32\rundll32.exe cryptext.dll,CryptExtOpenCTL %1
telnet="c:\Windows\System32\rundll32.exe" "C:\Windows\System32e\url.dll",TelnetProtocolHandler %l
themefile=%SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,Control_RunDLL %SystemRoot%\system32\desk.cpl desk,@Themes /Action:OpenTheme /file:"%1"
TIFImage.Document=%SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Gallery\PhotoViewer.dll", ImageView_Fullscreen %1
tn3270="c:\Windows\System32\rundll32.exe" "C:\Windows\System32e\url.dll",TelnetProtocolHandler %l
ttcfile=%SystemRoot%\System32\fontview.exe %1
ttffile=%SystemRoot%\System32\fontview.exe %1
!d
vcard_wab_auto_file="%ProgramFiles%\Windows Mail\wab.exe" /vcard "%1"
VisioViewer.Viewer="c:\Program Files\Internet Explorere\iexplore.exe" -nohome
wab_auto_file="%ProgramFiles%\Windows Mail\wab.exe" /Import "%1"
WAXFile="%ProgramFiles%\Windows Media Player\wmplayer.exe" /Open "%L"
wbcatfile=%SystemRoot%\system32\sdclt.exe /restorepage
wdpfile=%SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Gallery\PhotoViewer.dll", ImageView_Fullscreen %1
WebAllowBlockList_wpc=%SystemRoot%\system32\wpcumi.EXE /import %1
webcal="%ProgramFiles%\Windows Calendar\wincal.exe" /webcal "%1"
webpnpFile=%SystemRoot%\system32\wpnpinst.exe %1
Windows.CompositeFont="%WinDir%\System32\notepad.exe" "%1"
Windows.DVD.Maker="%ProgramFiles%\Movie Maker\DVDMaker.exe" "%1"
Windows.gadget=%ProgramFiles%\Windows Sidebar\Sidebar.exe
Windows.Movie.Maker="%ProgramFiles%\Movie Maker\moviemk.exe" "%1"
Windows.XamlDocument="c:\Windows\System32e\PresentationHost.exe" "%1" %*
Windows.Xbap="c:\Windows\System32e\PresentationHost.exe" "%1" %*
WindowsCalendar.FileIcs.1="%ProgramFiles%\Windows Calendar\wincal.exe" /icsfile "%1"
WindowsCalendar.UrlWebcal.1="%ProgramFiles%\Windows Calendar\wincal.exe" /webcal "%1"
WindowsMail.Url.Mailto="%ProgramFiles%\Windows Mail\WinMail.exe" /mailurl:"%1"
WindowsMail.Url.news="%ProgramFiles%\Windows Mail\WinMail.exe" /newsurl:"%1"
WindowsMail.Url.nntp="%ProgramFiles%\Windows Mail\WinMail.exe" /newsurl:"%1"
WindowsMail.Url.snews="%ProgramFiles%\Windows Mail\WinMail.exe" /newsurl:"%1"
WinRAR="c:\Program Files\WinRARe\WinRAR.exe" "%1"
WinRAR.REV="c:\Program Files\WinRARe\WinRAR.exe" "%1"
WinRAR.ZIP="c:\Program Files\WinRARe\WinRAR.exe" "%1"
wmafile="%ProgramFiles%\Windows Media Player\wmplayer.exe" /prefetch:5 /Open "%L"
WMDFile="%ProgramFiles%\Windows Media Player\wmplayer.exe" /WMPackage:"%L"
wmffile="%systemroot%\system32\mspaint.exe" "%1"
WMP.DVR-MSFile="%ProgramFiles%\Windows Media Player\wmplayer.exe" /Open "%L"
WMP11.AssocFile.AIFF="%ProgramFiles%\Windows Media Player\wmplayer.exe" /Open "%L"
WMP11.AssocFile.ASF="%ProgramFiles%\Windows Media Player\wmplayer.exe" /prefetch:7 /Open "%L"
WMP11.AssocFile.ASX="%ProgramFiles%\Windows Media Player\wmplayer.exe" /Open "%L"
WMP11.AssocFile.AU="%ProgramFiles%\Windows Media Player\wmplayer.exe" /Open "%L"
WMP11.AssocFile.AVI="%ProgramFiles%\Windows Media Player\wmplayer.exe" /prefetch:8 /Open "%L"
WMP11.AssocFile.CDA="%ProgramFiles%\Windows Media Player\wmplayer.exe" /Open "%L"
WMP11.AssocFile.m3u="%ProgramFiles%\Windows Media Player\wmplayer.exe" /prefetch:6 /Open "%L"
WMP11.AssocFile.MIDI="%ProgramFiles%\Windows Media Player\wmplayer.exe" /Open "%L"
WMP11.AssocFile.MP3="%ProgramFiles%\Windows Media Player\wmplayer.exe" /prefetch:6 /Open "%L"
WMP11.AssocFile.MPEG="%ProgramFiles%\Windows Media Player\wmplayer.exe" /prefetch:9 /Open "%L"
WMP11.AssocFile.WAV="%ProgramFiles%\Windows Media Player\wmplayer.exe" /Open "%L"
WMP11.AssocFile.WAX="%ProgramFiles%\Windows Media Player\wmplayer.exe" /Open "%L"
WMP11.AssocFile.WMA="%ProgramFiles%\Windows Media Player\wmplayer.exe" /prefetch:5 /Open "%L"
WMP11.AssocFile.WMD="%ProgramFiles%\Windows Media Player\wmplayer.exe" /WMPackage:"%L"
WMP11.AssocFile.WMS="%ProgramFiles%\Windows Media Player\wmplayer.exe" /layout:"%L"
WMP11.AssocFile.WMV="%ProgramFiles%\Windows Media Player\wmplayer.exe" /prefetch:7 /Open "%L"
WMP11.AssocFile.WMZ="%ProgramFiles%\Windows Media Player\wmplayer.exe" /layout:"%L"
WMP11.AssocFile.WPL="%ProgramFiles%\Windows Media Player\wmplayer.exe" /Open "%L"
WMP11.AssocFile.WVX="%ProgramFiles%\Windows Media Player\wmplayer.exe" /Open "%L"
WMP11.AssocProtocol.MMS="%ProgramFiles%\Windows Media Player\wmplayer.exe" "%L"
WMSFile="%ProgramFiles%\Windows Media Player\wmplayer.exe" /layout:"%L"
WMVFile="%ProgramFiles%\Windows Media Player\wmplayer.exe" /prefetch:7 /Open "%L"
WMZFile="%ProgramFiles%\Windows Media Player\wmplayer.exe" /layout:"%L"
Word.Backup.8="c:\Program Files\Microsoft Office\Office12e\WINWORD.EXE" /n /dde
Word.Document.12="c:\Program Files\Microsoft Office\Office12e\WINWORD.EXE" /n /dde
Word.Document.8="c:\Program Files\Microsoft Office\Office12e\WINWORD.EXE" /n /dde
Word.DocumentMacroEnabled.12="c:\Program Files\Microsoft Office\Office12e\WINWORD.EXE" /n /dde
Word.OpenDocumentText.12="c:\Program Files\Microsoft Office\Office12e\WINWORD.EXE" /n /dde
Word.RTF.8="c:\Program Files\Microsoft Office\Office12e\WINWORD.EXE" /n /dde
Word.Template.12="c:\Program Files\Microsoft Office\Office12e\WINWORD.EXE" /n /dde
Word.Template.8="c:\Program Files\Microsoft Office\Office12e\WINWORD.EXE" /n /dde
Word.TemplateMacroEnabled.12="c:\Program Files\Microsoft Office\Office12e\WINWORD.EXE" /n /dde
wordhtmlfile="c:\Program Files\Microsoft Office\Office12e\WINWORD.EXE"
wordhtmltemplate="c:\Program Files\Microsoft Office\Office12e\WINWORD.EXE"
Wordpad.Document.1="%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1"
WPC=%systemroot%\system32\wpcer.exe %1
WPLFile="%ProgramFiles%\Windows Media Player\wmplayer.exe" /Open "%L"
WSFFile="%SystemRoot%\System32\WScript.exe" "%1" %*
WSHFile="%SystemRoot%\System32\WScript.exe" "%1" %*
WVXFile="%ProgramFiles%\Windows Media Player\wmplayer.exe" /Open "%L"
XEV.FailSafeApp=%SystemRoot%\system32\NOTEPAD.EXE %1
XEV.GenericApp="%ProgramFiles%\Internet Explorer\iexplore.exe" -nohome
XEV.OriginalApp="%ProgramFiles%\Internet Explorer\iexplore.exe" -nohome
xmlfile="c:\Program Files\Common Files\Microsoft Shared\OFFICE12e\MSOXMLED.EXE" /verb open "%1"
XPSViewer.Document.1="c:\Windows\System32\XPSViewere\XPSViewer.exe" "%1" %*
xslfile="%ProgramFiles%\Internet Explorer\iexplore.exe" -nohome
.bat
.cmd
.com
.exe
.scr
.reg
.txt
.
=============== Created Last 30 ================
.
2011-03-04 20:03:53 -------- d-----w- c:\Program Filese\Microsoft Security Client
.
==================== Find3M ====================
.
2010-12-28 15:55:03 413696 ----a-w- c:\Windows\system32e\odbc32.dll
.
============= FINISH: 13:43:37.03 ===============