Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Yieldmanager Problem


  • This topic is locked This topic is locked
24 replies to this topic

#1 woodyatwork

woodyatwork

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:08:51 PM

Posted 23 July 2008 - 11:41 AM

I rarely use IE on my work laptop, but sometimes I have to. And randomly the page will switch to this yield manager thing.

I certainly appreciate your help, and hope I have followed the instructions completely.

As a sidenote, I think something is screwed up beyond this malware thing. Windows Media player no longer works. Perhaps registry corruption? Likely out of scope, but thought I would throw it out there.

Deckard's System Scanner v20071014.68
Run by sw185041 on 2008-07-23 11:30:59
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
40: 2008-07-23 16:31:06 UTC - RP410 - Deckard's System Scanner Restore Point
39: 2008-07-23 16:01:10 UTC - RP409 - Removed SUPERAntiSpyware Free Edition
38: 2008-07-21 02:31:19 UTC - RP408 - Installed SUPERAntiSpyware Free Edition
37: 2008-07-03 17:35:36 UTC - RP407 - Software Distribution Service 2.0
36: 2008-06-16 19:25:50 UTC - RP406 - Installed Windows XP KB926239.


-- First Restore Point --
1: 2008-03-03 16:13:04 UTC - RP371 - Removed Infuzer


Backed up registry hives.
Performed disk cleanup.

Percentage of Memory in Use: 80% (more than 75%).
System Drive C: has 4.92 GiB (less than 15%) free.


-- HijackThis (run as sw185041.exe) --------------------------------------------

Unable to find log (file not found); running clone.
-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-07-23 11:33:36
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\NCR\Tdat\TGTW\06.01.00.12\bin\gtwrsrvtdmst.exe
C:\WINDOWS\system32\WLTRYSVC.EXE
C:\WINDOWS\system32\BCMWLTRY.EXE
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\BAsfIpM.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\NCR\BYNET\blmsvc.exe
C:\Program Files\ENDFORCE\AgentAPI.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe
C:\Program Files\Common Files\Trend Micro\OfficeScan Client\NTRtScan.exe
C:\Program Files\NCR\Tdat\PDE\06.01.00.12\bin\pdeinetd.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Trend Micro\OfficeScan Client\TmListen.exe
C:\Program Files\VMware\VMware Player\vmware-authd.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\Program Files\Common Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\TEMP\YL2E5.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\WLTRAY.EXE
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Common Files\Trend Micro\OfficeScan Client\PccNTMon.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\VMware\VMware Player\hqtray.exe
C:\Program Files\ENDFORCE\AgntTray.exe
C:\Program Files\Boingo\GoBoingo\GoBoingo.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Secway\SimpLite-MSN 2.2\SimpLite-MSN.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Microsoft ActiveSync\rapimgr.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Common Files\Trend Micro\OfficeScan Client\PccNTUpd.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
C:\WINDOWS\system32\calc.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Microsoft Office\OFFICE11\POWERPNT.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Nortel Networks\Extranet_serv.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\sw185041\My Documents\My Videos\dss.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\HijackThis\sw185041.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&client=dell-rel
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/keyword/%s
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://rpc1720.daytonoh.ncr.com/registration.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy-mem60fw.network.fedex.com:3128
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.google.com/ig/dell?hl=en&client=dell-rel
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O1 - Hosts: 199.228.192.159 EDWPRDcop1
O1 - Hosts: 199.228.5.48 EDWDEVcop1
O1 - Hosts: 153.64.20.231 partnerscop1 partners
O1 - Hosts: 153.64.208.9 figcop1 fig
O1 - Hosts: 67.187.169.237 PDLinuxcop1 PDLinux
O1 - Hosts: 106.1.1.74 hekyl hekylcop1
O1 - Hosts: 106.1.1.71 jekyl jekylcop1
O1 - Hosts: 153.65.185.116 ceres05 ceres05cop1
O1 - Hosts: 153.65.185.117 ceres05 ceres05cop2
O1 - Hosts: 153.65.185.118 ceres05 ceres05cop3
O1 - Hosts: 153.65.185.119 ceres05 ceres05cop4
O1 - Hosts: 106.1.1.79 mcqueen mcqueencop1
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\GoogleToolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\GoogleAFE\GoogleAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\GoogleToolbar1.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [NCR-Netmeeting Check] C:\WINDOWS\NMTRepair.EXE
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Common Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [VMware hqtray] "C:\Program Files\VMware\VMware Player\hqtray.exe"
O4 - HKLM\..\Run: [ENDFORCEAgent] "C:\Program Files\ENDFORCE\AgntTray.exe"
O4 - HKLM\..\Run: [GoBoingo] C:\Program Files\Boingo\GoBoingo\GoBoingo.lnk
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Simp] C:\Program Files\Secway\SimpLite-MSN 2.2\SimpLite-MSN.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O4 - Global Startup: Bluetooth Manager.lnk = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: Status Monitor.lnk = ?
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: (no name) - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - (file missing)
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\sw185041\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.Teradata.com (HKCU)
O16 - DPF: {0B0F4127-1B3E-467A-B6C8-571807562DDC} (AuthenticationTD.Authenticate) - http://web.teradatanet.teradata.com/cab/validateTD.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1E1BC012-AC2A-403F-AEE4-A32E1F18986D} (Logoff Class) - https://www.passwordmanager.ncr.com/psynch/docs/pslogoff.dll
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} (Shockwave ActiveX Control) - http://fpdownload.macromedia.com/get/shock...director/sw.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} () - http://download.microsoft.com/download/F/6...922/wmv9VCM.CAB
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {4E67B0DB-1CAE-11D2-AD10-02608CA0806B} (NCRVersionControl Class) - http://web.ncrnet.ncr.com/cab/NCRFile.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.infuzer.com/IDC/client/player/isetup1.cab
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/67/install/gtdownls.cab
O16 - DPF: {AA3AE90C-F60E-4FD9-85E0-A00B61AE49B0} (ChangepointMailTools.WebDownload) - https://myc3.gateway.ncr.com/core/wizards/P...ntMailTools.CAB
O16 - DPF: {BA2A9829-8040-4BF3-BDB6-51512826B68B} (Authentication.Authenticate) - http://web.ncr.com/cab/phonebook.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {DD3D661B-E8FA-11D2-A018-00A0C9AD89DF} (Phonebook.Application) - http://web.ncrnet.ncr.com/cab/phonebook.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://ncruniversity.webex.com/client/v_my...ing/ieatgpc.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://myc.gateway.ncr.com/Site0129/dana-c...perSetupSP1.cab
O16 - DPF: {F5131C24-E56D-11CF-B78A-444553540000} (Ikonic Menu Control) - https://myb.gateway.ncr.com/Site0008/html/B...ix/ikcntrls.cab
O17 - HKLM\Software\..\Telephony: DomainName = TD.teradata.com
O17 - HKLM\SYSTEM\CCS\Services\Tcpip\..\{2EE55E33-D66C-42BD-B989-E7D895F794B9}: NameServer = 153.65.2.12,153.65.2.111
O17 - HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: Domain = corp.ncr.com
O17 - HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: SearchList = corp.ncr.com,elsegundoca.ncr.com,sandiegoca.ncr.com
O17 - HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: Domain = TD.teradata.com
O17 - HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: SearchList = corp.ncr.com,elsegundoca.ncr.com,sandiegoca.ncr.com
O17 - HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: Domain = TD.teradata.com
O17 - HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: SearchList = corp.ncr.com,elsegundoca.ncr.com,sandiegoca.ncr.com
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL
O18 - Protocol: x-excid - {9D6CC632-1337-4a33-9214-2DA092E776F4} - c:\WINDOWS\Downloaded Program Files\mimectl.dll (file missing)
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O20 - Winlogon Notify: AtiExtEvent - C:\WINDOWS\system32\Ati2evxx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\ati2evxx.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\BAsfIpM.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\system32\Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: bynet - NCR Corporation - C:\Program Files\NCR\BYNET\blmsvc.exe
O23 - Service: ENDFORCE Agent API - ENDFORCE, Inc. - C:\Program Files\ENDFORCE\AgentAPI.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: Teradata GTW Reserve Port (GtwRsrvTdmst) - NCR - C:\Program Files\NCR\Tdat\TGTW\06.01.00.12\bin\gtwrsrvtdmst.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Teradata Manager Service (ISService) - Teradata, a division of NCR - C:\Program Files\NCR\Teradata Manager 7.2\Bin\isservice.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Common Files\Trend Micro\OfficeScan Client\NTRtScan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Common Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: Teradata inetd Service (PdeinetdService) - NCR - C:\Program Files\NCR\Tdat\PDE\06.01.00.12\bin\pdeinetd.exe
O23 - Service: Teradata RDBMS Initiator (recond) - NCR - C:\Program Files\NCR\Tdat\PDE\06.01.00.12\bin\recond.exe
O23 - Service: TQS Server (TdqmServerService) - Teradata, a division of NCR - C:\Program Files\NCR\Teradata Query Scheduler 12.0\server\tdqmserv.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Common Files\Trend Micro\OfficeScan Client\TmListen.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Player\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\system32\WLTRYSVC.EXE


--
End of file - 19229 bytes

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R0 bynetpnp (NCR Bynet Interconnect) - c:\windows\system32\drivers\bynetpnp.sys <Not Verified; NCR Corporation; BYNET Software>
R0 ncrbynet (NCR Bynet Low Latency Interface) - c:\windows\system32\drivers\ncrbynet.sys <Not Verified; NCR Corporation; BYNET Software>
R1 APPDRV - c:\windows\system32\drivers\appdrv.sys <Not Verified; Dell Inc; Application Driver>
R1 NEOFLTR_530_11531 (Juniper Networks TDI Filter Driver (NEOFLTR_530_11531)) - c:\windows\system32\drivers\neofltr_530_11531.sys <Not Verified; Neoteris; Secure Application Manager>
R1 omci (OMCI WDM Device Driver) - c:\windows\system32\drivers\omci.sys <Not Verified; Dell Inc; OMCI Driver>
R1 Tosrfcom (Bluetooth RFCOMM from TOSHIBA) - c:\windows\system32\drivers\tosrfcom.sys <Not Verified; TOSHIBA Corporation; Bluetooth RFCOMM Driver>
R2 TM_CFW (Common Firewall Driver) - c:\program files\common files\trend micro\officescan client\tm_cfw.sys <Not Verified; Trend Micro Inc.; Trend Micro Common Firewall Module 1.2>
R3 Eacfilt (Eacfilt Miniport) - c:\windows\system32\drivers\eacfilt.sys <Not Verified; Nortel Networks; Filter Driver for CVC>
R3 GTIPCI21 - c:\windows\system32\drivers\gtipci21.sys <Not Verified; Texas Instruments; Texas Instruments PCI GemCore Based SmartCard Interface>
R3 IPSECSHM (Nortel IPSECSHM Adapter) - c:\windows\system32\drivers\ipsecw2k.sys <Not Verified; Nortel Networks NA, Inc.; Contivity VPN Client>
R3 PCASp50 (PCASp50 NDIS Protocol Driver) - c:\windows\system32\drivers\pcasp50.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
R3 tosporte (Bluetooth Port Driver from Toshiba) - c:\windows\system32\drivers\tosporte.sys <Not Verified; TOSHIBA Corporation; TOSHIBA Bluetooth Port Emulation Driver>

S3 FreshIO - c:\program files\freshdevices\freshdiagnose\freshio.sys (file missing)
S3 IPSECEXT (Nortel Extranet Access Protocol) - c:\windows\system32\drivers\ipsecw2k.sys <Not Verified; Nortel Networks NA, Inc.; Contivity VPN Client>
S3 Jukebox3 - c:\windows\system32\drivers\ctpdusb.sys (file missing)
S3 Pdesys (PDE Sys Driver) - c:\windows\system32\drivers\pdesys.sys <Not Verified; NCR; opnpde>
S3 toshidpt (TOSHIBA Bluetooth HID port driver) - c:\windows\system32\drivers\toshidpt.sys <Not Verified; TOSHIBA Corporation.; TOSHIBA Bluetooth HID Mini Port Driver>
S3 Tosrfbd (Bluetooth RFBUS from TOSHIBA) - c:\windows\system32\drivers\tosrfbd.sys <Not Verified; TOSHIBA CORPORATION; Bluetooth BUS Driver(WindowsXP,Windows2000)>
S3 Tosrfbnp (Bluetooth RFBNEP from TOSHIBA) - c:\windows\system32\drivers\tosrfbnp.sys <Not Verified; TOSHIBA Corporation; Bluetooth RFBNEP Driver from TOSHIBA>
S3 Tosrfhid (Bluetooth RFHID from TOSHIBA) - c:\windows\system32\drivers\tosrfhid.sys <Not Verified; TOSHIBA Corporation.; Bluetooth HID Driver from TOSHIBA>
S3 tosrfnds (Bluetooth Personal Area Network from TOSHIBA) - c:\windows\system32\drivers\tosrfnds.sys <Not Verified; TOSHIBA Corporation.; Bluetooth BNEP Driver from TOSHIBA>
S3 TosRfSnd (Bluetooth Audio Device (WDM) from TOSHIBA) - c:\windows\system32\drivers\tosrfsnd.sys <Not Verified; TOSHIBA Corporation; Bluetooth Audio Driver>
S3 Tosrfusb (Bluetooth USB Controller) - c:\windows\system32\drivers\tosrfusb.sys <Not Verified; TOSHIBA CORPORATION; Microsoft® Windows NT® Operating System>


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 BAsfIpM (Broadcom ASF IP monitoring service v6.0.4) - c:\windows\system32\basfipm.exe <Not Verified; Broadcom Corp.; Broadcom ASF IP monitoring service>
R2 bynet - "c:\program files\ncr\bynet\blmsvc.exe" <Not Verified; NCR Corporation; BYNET Software>
R2 ENDFORCE Agent API - "c:\program files\endforce\agentapi.exe" <Not Verified; ENDFORCE, Inc.; ENDFORCE Enterprise>
R2 GtwRsrvTdmst (Teradata GTW Reserve Port) - "c:\program files\ncr\tdat\tgtw\06.01.00.12\bin\gtwrsrvtdmst.exe" <Not Verified; NCR; gateway>
R2 NICCONFIGSVC - c:\program files\dell\nicconfigsvc\nicconfigsvc.exe <Not Verified; Dell Inc.; NicConfigSvc>
R2 ntrtscan (OfficeScanNT RealTime Scan) - "c:\program files\common files\trend micro\officescan client\ntrtscan.exe" <Not Verified; Trend Micro Inc.; Trend Micro OfficeScan>
R2 OfcPfwSvc (OfficeScanNT Personal Firewall) - "c:\program files\common files\trend micro\officescan client\ofcpfwsvc.exe" <Not Verified; Trend Micro Inc.; Trend Micro OfficeScan>
R2 PdeinetdService (Teradata inetd Service) - "c:\program files\ncr\tdat\pde\06.01.00.12\bin\pdeinetd.exe" <Not Verified; NCR; opnpde>
R2 tmlisten (OfficeScanNT Listener) - "c:\program files\common files\trend micro\officescan client\tmlisten.exe" <Not Verified; Trend Micro Inc.; Trend Micro OfficeScan>
R3 ExtranetAccess (Contivity VPN Service) - "c:\program files\nortel networks\extranet_serv.exe" <Not Verified; Nortel Networks NA, Inc.; Nortel Networks Contivity VPN Client>

S3 ISService (Teradata Manager Service) - "c:\program files\ncr\teradata manager 7.2\bin\isservice.exe" <Not Verified; Teradata, a division of NCR; Teradata Manager>
S3 recond (Teradata RDBMS Initiator) - "c:\program files\ncr\tdat\pde\06.01.00.12\bin\recond.exe" "-s" <Not Verified; NCR; opnpde>
S3 TdqmServerService (TQS Server) - "c:\program files\ncr\teradata query scheduler 12.0\server\tdqmserv.exe" <Not Verified; Teradata, a division of NCR; Teradata Query Scheduler>


-- Device Manager: Disabled ----------------------------------------------------

Class GUID: {6BDD1FC5-810F-11D0-BEC7-08002BE2092F}
Description: SMC IrCC - Fast Infrared Port
Device ID: ACPI\SMCF010\4&15F2F7D1&0
Manufacturer: SMC
Name: SMC IrCC - Fast Infrared Port
PNP Device ID: ACPI\SMCF010\4&15F2F7D1&0
Service: SMCIRDA


-- Scheduled Tasks -------------------------------------------------------------

2008-05-23 11:12:23 398 --a------ C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job
2008-05-23 11:12:23 276 --a------ C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job


-- Files created between 2008-06-23 and 2008-07-23 -----------------------------

2008-07-23 11:11:58 0 d-------- C:\Program Files\Panda Security
2008-07-23 11:11:57 0 d-------- C:\WINDOWS\LastGood
2008-07-20 21:31:37 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-20 21:31:21 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-07-20 21:31:21 0 d-------- C:\Documents and Settings\sw185041\Application Data\SUPERAntiSpyware.com
2008-07-20 11:50:42 0 dr-h----- C:\Documents and Settings\sw185041\Recent
2008-07-07 18:20:59 0 d-------- C:\Program Files\Add-in Express
2008-07-03 12:40:16 0 d-------- C:\1a9971f6bd2e8183471164


-- Find3M Report ---------------------------------------------------------------

2008-07-23 11:01:46 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-23 10:58:13 0 d-------- C:\Program Files\eMusic Download Manager
2008-07-23 10:57:19 0 d-------- C:\Program Files\Yahoo!
2008-07-23 08:03:14 0 d-------- C:\Program Files\ENDFORCE
2008-07-17 13:52:33 0 d-------- C:\Program Files\oneworldflights
2008-07-03 10:32:26 0 d-------- C:\Documents and Settings\sw185041\Application Data\uTorrent
2008-06-16 12:05:53 12 --a------ C:\WINDOWS\bthservsdp.dat
2008-06-09 18:31:57 0 d-------- C:\Documents and Settings\sw185041\Application Data\Winamp
2008-06-09 18:31:52 0 d-------- C:\Program Files\Winamp
2008-06-09 18:31:10 0 d-------- C:\Program Files\Winamp Remote
2008-06-06 11:31:41 0 d-------- C:\Program Files\Boingo
2008-06-02 19:15:33 0 d-------- C:\Program Files\Java
2008-06-02 19:01:45 0 d-------- C:\Program Files\Google
2008-06-02 18:58:23 0 d-------- C:\Program Files\IDM Computer Solutions
2008-06-02 17:27:25 0 d-------- C:\Program Files\Creative
2008-06-02 17:26:52 0 d-------- C:\Program Files\SiriuCE2
2008-06-02 17:26:38 0 d-------- C:\Program Files\Common Files
2008-06-02 17:25:34 0 d-------- C:\Program Files\ACROPhoni
2008-05-28 16:02:31 0 d-------- C:\Documents and Settings\sw185041\Application Data\skypePM
2008-05-23 13:51:43 0 d-------- C:\Program Files\FreshDevices
2008-05-23 11:18:18 0 d-------- C:\Documents and Settings\sw185041\Application Data\Uniblue
2008-04-23 18:29:51 73216 --a------ C:\WINDOWS\ST6UNST.EXE <Not Verified; Microsoft Corporation; Microsoft® Visual Basic for Windows>


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [05/12/2005 10:00 PM]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [09/01/2005 06:24 PM]
"Dell Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" []
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [04/26/2004 09:04 AM]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [12/06/2004 02:05 AM]
"@"="" []
"NCR-Netmeeting Check"="C:\WINDOWS\NMTRepair.EXE" [01/03/2006 02:41 PM]
"ControlCenter2.0"="C:\Program Files\Brother\ControlCenter2\brctrcen.exe" [07/20/2004 09:34 AM]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [07/19/2005 05:32 PM]
"OfficeScanNT Monitor"="C:\Program Files\Common Files\Trend Micro\OfficeScan Client\pccntmon.exe" [01/08/2007 07:20 PM]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [03/23/2005 06:26 PM]
"BluetoothAuthenticationAgent"="bthprops.cpl" [08/04/2004 06:00 AM C:\WINDOWS\system32\bthprops.cpl]
"VMware hqtray"="C:\Program Files\VMware\VMware Player\hqtray.exe" [05/01/2007 10:46 PM]
"ENDFORCEAgent"="C:\Program Files\ENDFORCE\AgntTray.exe" [06/27/2007 11:35 PM]
"GoBoingo"="C:\Program Files\Boingo\GoBoingo\GoBoingo.lnk" [07/18/2008 01:15 PM]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [04/01/2008 01:49 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 06:00 AM]
"Simp"="C:\Program Files\Secway\SimpLite-MSN 2.2\SimpLite-MSN.exe" [08/28/2007 07:29 PM]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" [11/13/2006 01:39 PM]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [07/07/2008 09:42 AM]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [03/01/2007 10:37 AM]

C:\Documents and Settings\sw185041\Start Menu\Programs\Startup\
Yahoo! Widgets.lnk - C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe [12/11/2007 5:34:48 PM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [6/16/2005 11:11:42 AM]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [3/6/2006 1:25:01 AM]
Status Monitor.lnk - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe [4/7/2006 8:36:48 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoMSAppLogo5ChannelNotify"=1 (0x1)
"NoToolbarCustomize"=0 (0x0)
"NoBandCustomize"=0 (0x0)
"NoWindowsUpdate"=1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoWindowsUpdate"=1 (0x1)
"ClearRecentDocsOnExit"=01000000
"NoRecentDocsHistory"=01000000
"NoRecentDocsNetHood"=01000000
"NoSMMyPictures"=01000000
"NoRecentDocsMenu"=01000000

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktop"=0 (0x0)
"NoActiveDesktopChanges"=0 (0x0)
"NoInternetIcon"=0 (0x0)
"NoDesktop"=0 (0x0)
"Btn_Back"=0 (0x0)
"Btn_Forward"=0 (0x0)
"Btn_Stop"=0 (0x0)
"Btn_Refresh"=0 (0x0)
"Btn_Home"=0 (0x0)
"Btn_Search"=0 (0x0)
"Btn_History"=0 (0x0)
"Btn_Favorites"=0 (0x0)
"Btn_Media"=0 (0x0)
"Btn_Folders"=0 (0x0)
"Btn_Fullscreen"=0 (0x0)
"Btn_Tools"=0 (0x0)
"Btn_MailNews"=0 (0x0)
"Btn_Size"=0 (0x0)
"Btn_Print"=0 (0x0)
"Btn_Edit"=0 (0x0)
"Btn_Discussions"=0 (0x0)
"Btn_Cut"=0 (0x0)
"Btn_Copy"=0 (0x0)
"Btn_Paste"=0 (0x0)
"Btn_Encoding"=0 (0x0)
"Btn_PrintPreview"=0 (0x0)
"NoWindowsUpdate"=1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rstrui.exe]
debugger=C:\WINDOWS\system32\Restore\profhlp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
C:\Program Files\Apoint\Apoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
"C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
"C:\Program Files\Logitech\Video\ManifestEngine.exe" boot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
C:\Program Files\Logitech\Video\ISStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
C:\Program Files\Logitech\Video\LogiTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
"C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
"C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
AutoRun\command- E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{15ba22fe-81d3-11dc-b14b-0016ce0b2c30}]
AutoRun\command- E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6847d974-c525-11db-b11a-444553544200}]
AutoRun\command- setupSNK.exe




-- Hosts -----------------------------------------------------------------------

127.0.0.1 localhost TDLTCOP1
199.228.192.159 EDWPRDcop1
199.228.5.48 EDWDEVcop1
153.64.20.231 partnerscop1 partners
153.64.208.9 figcop1 fig
67.187.169.237 PDLinuxcop1 PDLinux
106.1.1.74 hekyl hekylcop1
106.1.1.71 jekyl jekylcop1
153.65.185.116 ceres05 ceres05cop1
153.65.185.117 ceres05 ceres05cop2

2 more entries in hosts file.


-- End of Deckard's System Scanner: finished at 2008-07-23 11:34:47 ------------

Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: Intel® Pentium® M processor 1.73GHz
Percentage of Memory in Use: 75%
Physical Memory (total/avail): 1023.36 MiB / 254.54 MiB
Pagefile Memory (total/avail): 2462.46 MiB / 1636.29 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1919.27 MiB

C: is Fixed (NTFS) - 37.18 GiB total, 4.92 GiB free.
D: is CDROM (No Media)

\\.\PHYSICALDRIVE0 - Hitachi HTS541040G9AT00 - 37.26 GiB - 2 partitions
\PARTITION0 - Unknown - 62.72 MiB
\PARTITION1 (bootable) - Installable File System - 37.18 GiB - C:



-- Security Center -------------------------------------------------------------

AUOptions is disabled.
AUState says computer has updates disabled.
Windows Internal Firewall is enabled.

FirstRunDisabled is set.

FW: Trend Micro OfficeScan Enterprise Client Firewall v7.3 (TrendFirewall)

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\Yahoo!\\Yahoo! Music Engine\\YahooMusicEngine.exe"="C:\\Program Files\\Yahoo!\\Yahoo! Music Engine\\YahooMusicEngine.exe:*:Enabled:Yahoo! Music Engine"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\sw185041\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.6.0_02\lib\ext\QTJava.zip
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=WUSSW185041-HZ6
ComSpec=C:\WINDOWS\system32\cmd.exe
COPLIB=C:\Program Files\NCR\Teradata Client\cliv2\
DataConnectorLibPath=C:\WINDOWS\system32\
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\sw185041
LOGONSERVER=\\SUSSAN140
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\Program Files\Mozilla Firefox;C:\Program Files\NCR\Teradata Parallel Transporter\8.1\bin;C:\Program Files\NCR\Teradata Parallel Transporter\8.1\msg;C:\Program Files\NCR\Teradata Client\WinCLI-Runtime\;C:\Program Files\NCR\Teradata Client\DevKit\;C:\Program Files\NCR\Teradata Client\Bin;C:\WINDOWS\system32\;C:\WINDOWS\system32\;C:\Program Files\NCR\Teradata Client\cliv2\;C:\Program Files\NCR\Common Files\Shared ICU Libraries for Teradata\lib;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\NCR\BYNET\;C:\Program Files\NCR\Tdat\LPDE\bin;C:\Program Files\Common Files\GTK\2.0\bin;C:\WINDOWS\system32\;C:\Program Files\QuickTime\QTSystem\;C:\ORAWIN95\BIN
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 13 Stepping 8, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0d08
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.6.0_02\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\sw185041\LOCALS~1\Temp
TMP=C:\DOCUME~1\sw185041\LOCALS~1\Temp
TWB_ROOT=C:\Program Files\NCR\Teradata Parallel Transporter\8.1
USERDNSDOMAIN=TD.TERADATA.COM
USERDOMAIN=TD
USERNAME=sw185041
USERPROFILE=C:\Documents and Settings\sw185041
VCToolkitInstallDir=C:\Program Files\Microsoft Visual C++ Toolkit 2003\
windir=C:\WINDOWS
_MSGCATLOCATION=C:\Program Files\NCR\Teradata Parallel Transporter\8.1\msg


-- User Profiles ---------------------------------------------------------------

sw185041 (admin)
sw185041 (new local, admin)
migtd (new local)
Administrator (admin)
sw185041 (admin)


-- Add/Remove Programs ---------------------------------------------------------

--> C:\WINDOWS\system32CPMailUninstall.exe changepointmailtools.dll {AA3AE90C-F60E-4FD9-85E0-A00B61AE49B0}
_Teradata License for Microsoft Office 2003 Standard --> Not available
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 8.1.2 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
Changepoint Mail Tools --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7090BD99-CCD0-43B5-A211-E7FEBBB4C988}\setup.exe" -l0x9 -uninst -removeonly
Cisco MeetingPlace for Outlook --> RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\MPOUTL.INF, DefaultUninstall.ntx86
Compatibility Pack for the 2007 Office system --> MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
Easy PC Asset Information --> Not Available
GoBoingo! --> MsiExec.exe /X{12723C3A-0FF8-4A0C-8BD3-DC958F388F67}
HijackThis 1.99.1 --> C:\Program Files\HijackThis\HijackThis.exe /uninstall
Java™ 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java™ 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Microsoft ActiveSync --> MsiExec.exe /I{99052DB7-9592-4522-A558-5417BBAD48EE}
Microsoft MSDN 2005 Express Edition - ENU --> C:\Program Files\Microsoft Visual Studio 8\Microsoft MSDN 2005 Express Edition - ENU\install.exe
Microsoft Office Live Meeting 2007 --> MsiExec.exe /I{7DB92914-0A00-48C6-8DBB-F8E9D02B78B1}
Microsoft Office Standard Edition 2003 --> MsiExec.exe /I{90120409-6000-11D3-8CFE-0150048383C9}
Microsoft Visual Basic 2005 Express Edition - ENU --> C:\Program Files\Microsoft Visual Studio 8\Microsoft Visual Basic 2005 Express Edition - ENU\setup.exe
Microsoft Visual Basic 2005 Express Edition - ENU --> MsiExec.exe /X{577AD794-8B34-40B4-9E7A-BE4CFFE396E6}
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Mozilla Firefox (2.0.0.16) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
My Sirius Studio --> C:\Program Files\Sirius\MySiriusStudio\Uninstall.exe
oggcodecs 0.71.0946 --> C:\Program Files\illiminable\oggcodecs\uninst.exe
Panda ActiveScan 2.0 --> C:\Program Files\Panda Security\ActiveScan 2.0\as2uninst.exe
QuickTime --> MsiExec.exe /I{E0D51394-1D45-460A-B62D-383BC4F8B335}
Spybot - Search & Destroy --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Teradata Screensaver Screensaver --> C:\Program Files\MainSail\Teradata Screensaver\Uninstall.exe
Trim Spaces for Microsoft Excel 1.1 --> "C:\Program Files\Add-in Express\AddIns\Trim Spaces for Excel\unins000.exe"
Winamp --> "C:\Program Files\Winamp\UninstWA.exe"
Winamp Remote --> "C:\Program Files\Winamp Remote\uninstall.exe"
Windows Driver Package - Microsoft Corporation (usbvideo) Image (05/25/2007 1.0.3656.0) --> rundll32.exe C:\PROGRA~1\DIFX\7AA84A78695B31A503D9537A76801D74E0FD14BD\DIFxAppA.dll, DIFxARPUninstallDriverPackage C:\WINDOWS\system32\DRVSTORE\RoundTable_F29D632BDCC1844B9B7688A0A4B4DA9E716B76FF\RoundTable.inf
Windows Imaging Component --> "C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Yahoo! Install Manager --> C:\WINDOWS\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL
Yahoo! Widgets --> C:\PROGRA~1\Yahoo!\Widgets\uninstall.exe


-- Application Event Log -------------------------------------------------------

Event Record #/Type23711 / Error
Event Submitted/Written: 07/23/2008 08:34:24 AM
Event ID/Source: 15 / AutoEnrollment
Event Description:
Automatic certificate enrollment for local system failed to contact the active directory (0x8007054b). The specified domain either does not exist or could not be contacted.
Enrollment will not be performed.

Event Record #/Type23709 / Error
Event Submitted/Written: 07/23/2008 00:34:24 AM
Event ID/Source: 15 / AutoEnrollment
Event Description:
Automatic certificate enrollment for local system failed to contact the active directory (0x8007054b). The specified domain either does not exist or could not be contacted.
Enrollment will not be performed.

Event Record #/Type23708 / Error
Event Submitted/Written: 07/22/2008 04:34:24 PM
Event ID/Source: 15 / AutoEnrollment
Event Description:
Automatic certificate enrollment for local system failed to contact the active directory (0x8007054b). The specified domain either does not exist or could not be contacted.
Enrollment will not be performed.

Event Record #/Type23705 / Error
Event Submitted/Written: 07/22/2008 05:51:44 AM
Event ID/Source: 15 / AutoEnrollment
Event Description:
Automatic certificate enrollment for local system failed to contact the active directory (0x8007054b). The specified domain either does not exist or could not be contacted.
Enrollment will not be performed.

Event Record #/Type23704 / Error
Event Submitted/Written: 07/21/2008 09:51:44 PM
Event ID/Source: 15 / AutoEnrollment
Event Description:
Automatic certificate enrollment for local system failed to contact the active directory (0x8007054b). The specified domain either does not exist or could not be contacted.
Enrollment will not be performed.



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type110027 / Error
Event Submitted/Written: 07/23/2008 09:09:02 AM
Event ID/Source: 10005 / DCOM
Event Description:
DCOM got error "%%1058" attempting to start the service usnjsvc with arguments ""
in order to run the server:
{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}

Event Record #/Type110026 / Error
Event Submitted/Written: 07/23/2008 09:08:51 AM
Event ID/Source: 10005 / DCOM
Event Description:
DCOM got error "%%1058" attempting to start the service usnjsvc with arguments ""
in order to run the server:
{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}

Event Record #/Type110025 / Error
Event Submitted/Written: 07/23/2008 09:08:41 AM
Event ID/Source: 10005 / DCOM
Event Description:
DCOM got error "%%1058" attempting to start the service usnjsvc with arguments ""
in order to run the server:
{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}

Event Record #/Type110024 / Error
Event Submitted/Written: 07/23/2008 09:08:30 AM
Event ID/Source: 10005 / DCOM
Event Description:
DCOM got error "%%1058" attempting to start the service usnjsvc with arguments ""
in order to run the server:
{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}

Event Record #/Type110022 / Error
Event Submitted/Written: 07/23/2008 09:03:55 AM
Event ID/Source: 10005 / DCOM
Event Description:
DCOM got error "%%1058" attempting to start the service usnjsvc with arguments ""
in order to run the server:
{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}



-- End of Deckard's System Scanner: finished at 2008-07-23 11:34:47 ------------

Thank you

BC AdBot (Login to Remove)

 


#2 woodyatwork

woodyatwork
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:08:51 PM

Posted 29 July 2008 - 07:52 AM

Just an update.

I ran that Kasperspy (or whatever it is called) scan. It took over 4 hours but found nothing.

Thanks.

#3 SNOWHITE

SNOWHITE

    missy malware magnet


  • Members
  • 2,676 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Bitola, Macedonia
  • Local time:02:51 AM

Posted 07 August 2008 - 12:57 PM

Hello and welcome to BC

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. We aim to provide the valuable service known to come from BC to every member we can, but sometimes it takes just a little longer to get to every request for help.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

Upon completing the steps below a staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.

Thanks and again sorry for the delay.

Please download Deckard's System Scanner (DSS) and save to your Desktop.
alternate download site

DSS will do the following:
  • Create a new System Restore point in Windows XP and Vista.
  • Clean your Temporary Files, Downloaded Program Files, Internet Cache Files, and empty the Recycle Bin on all drives.
  • Check some important areas of your system and produce a report for an analyst to review.
  • Automatically run HijackThis. It will also install and place a shortcut to HijackThis on your desktop if you do not already have it installed. So if HijackThis is not installed and DSS prompts you to download it, please answer yes.
You must be logged onto an account with administrator privileges when using.
  • Close all applications and windows.
  • Double-click on dss.exe to run it and follow the prompts.
  • If your anti-virus or firewall complains, please allow this script to run as it is not
    malicious.
  • When the scan is complete, two text files will open in Notepad:
    • main.txt <- this one will be maximized
    • extra.txt <- this one will be minimized
  • If not, they both can be found in the C:\Deckard\System Scanner folder.
  • Please copy (Ctrl+C) and paste (Ctrl+V) the contents of main.txt and extra.txt in your next reply.
-- When running DSS, some firewalls may warn that it is trying to access the Internet especially if your asked to download the most current version of HijackThis. Please ensure that you allow it permission to do so.
-- If you get a warning from your anti-virus while DSS is scanning, please allow DSS to continue as the scan is not harmful.


If you already preformed the steps above We still need to see the current state of the machine fresh scan and logs are still necessary

click on Start, click on Run
copy and paste the following in bold in the open window and then click OK
"%userprofile%\desktop\dss.exe" /config
This will open up DSS configuration
click on Check All
click Scan
DSS will now run again when finished
Please post back both logs that open in notepad
Main txt and extra txt



Next
Please do a scan with Kaspersky Online Scanner

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Please post back with dss reports main.txt, extra.txt and Kaspersky report.

Regards
SNOWHITE
Posted Image

#4 woodyatwork

woodyatwork
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:08:51 PM

Posted 07 August 2008 - 06:44 PM

Here is the first output from DSS.EXE. There was only this one file created.

Deckard's System Scanner v20071014.68
Run by sw185041 on 2008-08-07 18:34:09
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as sw185041.exe) --------------------------------------------

Unable to find log (file not found); running clone.
-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-08-07 18:34:51
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\NCR\Tdat\TGTW\06.01.00.12\bin\gtwrsrvtdmst.exe
C:\WINDOWS\system32\WLTRYSVC.EXE
C:\WINDOWS\system32\BCMWLTRY.EXE
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\BAsfIpM.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\NCR\BYNET\blmsvc.exe
C:\Program Files\ENDFORCE\AgentAPI.exe
C:\Program Files\Teradata\Teradata Manager 13.0\Bin\isservice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe
C:\Program Files\Common Files\Trend Micro\OfficeScan Client\NTRtScan.exe
C:\Program Files\NCR\Tdat\PDE\06.01.00.12\bin\pdeinetd.exe
C:\Program Files\NCR\NCRput\bin\wfxrd.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Common Files\Trend Micro\OfficeScan Client\PccNTMon.exe
C:\Program Files\NCR\NCRput\bin\putjobd.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\NCR\NCRput\bin\portmgmt.exe
C:\Program Files\VMware\VMware Player\hqtray.exe
C:\Program Files\ENDFORCE\AgntTray.exe
C:\Program Files\Boingo\GoBoingo\GoBoingo.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Secway\SimpLite-MSN 2.2\SimpLite-MSN.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Common Files\Trend Micro\OfficeScan Client\TmListen.exe
C:\Program Files\Microsoft ActiveSync\rapimgr.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
C:\Program Files\VMware\VMware Player\vmware-authd.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\Temp\TKA37A.EXE
C:\Program Files\Common Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\Program Files\Teradata\Teradata Dynamic Workload Manager 13.0\tdwm.exe
C:\Program Files\TechSmith\SnagIt 9\SnagIt32.exe
C:\Program Files\TechSmith\SnagIt 9\TscHelp.exe
C:\Program Files\TechSmith\SnagIt 9\SnagPriv.exe
C:\Program Files\TechSmith\SnagIt 9\SnagItEditor.exe
C:\Documents and Settings\sw185041\My Documents\My Videos\dss.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&client=dell-rel
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/keyword/%s
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://rpc1720.daytonoh.ncr.com/registration.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy-mem60fw.network.fedex.com:3128
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.google.com/ig/dell?hl=en&client=dell-rel
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O1 - Hosts: 199.228.192.159 EDWPRDcop1
O1 - Hosts: 199.228.5.48 EDWDEVcop1
O1 - Hosts: 153.64.20.231 partnerscop1 partners
O1 - Hosts: 153.64.208.9 figcop1 fig
O1 - Hosts: 67.161.162.46 PDLinuxcop1 PDLinux
O1 - Hosts: 153.64.209.130 Tobacop1 Toba
O1 - Hosts: 106.1.1.74 hekyl hekylcop1
O1 - Hosts: 106.1.1.71 jekyl jekylcop1
O1 - Hosts: 153.65.185.116 ceres05 ceres05cop1
O1 - Hosts: 153.65.185.117 ceres05 ceres05cop2
O1 - Hosts: 153.65.185.118 ceres05 ceres05cop3
O1 - Hosts: 153.65.185.119 ceres05 ceres05cop4
O1 - Hosts: 106.1.1.79 mcqueen mcqueencop1
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 9\SnagItBHO.dll
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\GoogleToolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\GoogleAFE\GoogleAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\GoogleToolbar1.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 9\SnagItIEAddin.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [NCR-Netmeeting Check] C:\WINDOWS\NMTRepair.EXE
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Common Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [VMware hqtray] "C:\Program Files\VMware\VMware Player\hqtray.exe"
O4 - HKLM\..\Run: [ENDFORCEAgent] "C:\Program Files\ENDFORCE\AgntTray.exe"
O4 - HKLM\..\Run: [GoBoingo] C:\Program Files\Boingo\GoBoingo\GoBoingo.lnk
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Simp] C:\Program Files\Secway\SimpLite-MSN 2.2\SimpLite-MSN.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O4 - Global Startup: Bluetooth Manager.lnk = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: Status Monitor.lnk = ?
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: (no name) - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - (file missing)
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\sw185041\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.Teradata.com (HKCU)
O16 - DPF: {0B0F4127-1B3E-467A-B6C8-571807562DDC} (AuthenticationTD.Authenticate) - http://web.teradatanet.teradata.com/cab/validateTD.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} () - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1E1BC012-AC2A-403F-AEE4-A32E1F18986D} () - https://www.passwordmanager.ncr.com/psynch/docs/pslogoff.dll
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} (Shockwave ActiveX Control) - http://fpdownload.macromedia.com/get/shock...director/sw.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} () - http://download.microsoft.com/download/F/6...922/wmv9VCM.CAB
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} () - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {4E67B0DB-1CAE-11D2-AD10-02608CA0806B} () - http://web.ncrnet.ncr.com/cab/NCRFile.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1216999819520
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} () - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} () - http://www.infuzer.com/IDC/client/player/isetup1.cab
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/67/install/gtdownls.cab
O16 - DPF: {AA3AE90C-F60E-4FD9-85E0-A00B61AE49B0} () - https://myc3.gateway.ncr.com/core/wizards/P...ntMailTools.CAB
O16 - DPF: {BA2A9829-8040-4BF3-BDB6-51512826B68B} (Authentication.Authenticate) - http://web.ncr.com/cab/phonebook.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {DD3D661B-E8FA-11D2-A018-00A0C9AD89DF} (Phonebook.Application) - http://web.ncrnet.ncr.com/cab/phonebook.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} () - https://ncruniversity.webex.com/client/v_my...ing/ieatgpc.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://sslgateway.teradata.com/dana-cached...perSetupSP1.cab
O16 - DPF: {F5131C24-E56D-11CF-B78A-444553540000} () - https://myb.gateway.ncr.com/Site0008/html/B...ix/ikcntrls.cab
O17 - HKLM\Software\..\Telephony: DomainName = TD.teradata.com
O17 - HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: Domain = corp.ncr.com
O17 - HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: SearchList = corp.ncr.com,elsegundoca.ncr.com,sandiegoca.ncr.com
O17 - HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: Domain = TD.teradata.com
O17 - HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: SearchList = corp.ncr.com,elsegundoca.ncr.com,sandiegoca.ncr.com
O17 - HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: Domain = TD.teradata.com
O17 - HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: SearchList = corp.ncr.com,elsegundoca.ncr.com,sandiegoca.ncr.com
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL
O18 - Protocol: x-excid - {9D6CC632-1337-4a33-9214-2DA092E776F4} - (no file)
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: AtiExtEvent - C:\WINDOWS\system32\Ati2evxx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\ati2evxx.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\BAsfIpM.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\system32\Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: bynet - NCR Corporation - C:\Program Files\NCR\BYNET\blmsvc.exe
O23 - Service: ENDFORCE Agent API - ENDFORCE, Inc. - C:\Program Files\ENDFORCE\AgentAPI.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Teradata GTW Reserve Port (GtwRsrvTdmst) - NCR - C:\Program Files\NCR\Tdat\TGTW\06.01.00.12\bin\gtwrsrvtdmst.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Teradata Manager Service (ISService) - Teradata Corporation - C:\Program Files\Teradata\Teradata Manager 13.0\Bin\isservice.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Common Files\Trend Micro\OfficeScan Client\NTRtScan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Common Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: Teradata inetd Service (PdeinetdService) - NCR - C:\Program Files\NCR\Tdat\PDE\06.01.00.12\bin\pdeinetd.exe
O23 - Service: NCR PUT File Service (PUTFileSvc) - Unknown owner - C:\Program Files\NCR\NCRput\bin\wfxrd.exe
O23 - Service: NCR PUT Job Service (PUTJobSvc) - Unknown owner - C:\Program Files\NCR\NCRput\bin\putjobd.exe
O23 - Service: NCR PUT Port Manager Service (PUTPortMgrSvc) - Unknown owner - C:\Program Files\NCR\NCRput\bin\portmgmt.exe
O23 - Service: Teradata RDBMS Initiator (recond) - NCR - C:\Program Files\NCR\Tdat\PDE\06.01.00.12\bin\recond.exe
O23 - Service: TQS Server (TdqmServerService) - Teradata, a division of NCR - C:\Program Files\NCR\Teradata Query Scheduler 12.0\server\tdqmserv.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Common Files\Trend Micro\OfficeScan Client\TmListen.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Player\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\system32\WLTRYSVC.EXE


--
End of file - 20249 bytes

-- Files created between 2008-07-07 and 2008-08-07 -----------------------------

2008-08-07 11:59:27 0 d-------- C:\MyWorkData
2008-08-07 09:13:47 0 dr-h----- C:\Documents and Settings\sw185041\Recent
2008-08-06 13:07:36 0 d-------- C:\Documents and Settings\All Users\Application Data\Teradata
2008-08-06 11:34:11 25600 --a------ C:\WINDOWS\system32\drivers\pnmgr.sys <Not Verified; NCR; Parallel Upgrade Tool>
2008-08-06 11:14:52 0 d-------- C:\td12software
2008-08-06 10:35:08 0 d-------- C:\Program Files\Teradata
2008-07-30 11:52:42 0 d-------- C:\Documents and Settings\sw185041\Application Data\acccore
2008-07-30 11:51:02 0 d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-07-30 11:50:58 0 d-------- C:\Program Files\Viewpoint
2008-07-30 11:50:53 0 d-------- C:\Documents and Settings\All Users\Application Data\acccore
2008-07-30 11:49:41 0 d-------- C:\Documents and Settings\All Users\Application Data\AOL
2008-07-30 11:49:41 0 d-------- C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-07-30 11:48:19 0 d-------- C:\Program Files\Common Files\AOL
2008-07-30 11:48:04 0 d-------- C:\Program Files\AIM6
2008-07-30 11:19:10 0 d-------- C:\Program Files\Trillian
2008-07-25 12:52:59 0 d-------- C:\Documents and Settings\sw185041\Application Data\WinRAR
2008-07-25 10:54:36 0 d-------- C:\Documents and Settings\sw185041\Application Data\Media Player Classic
2008-07-25 10:48:53 0 d-------- C:\Program Files\XP Codec Pack
2008-07-25 07:21:44 0 d-------- C:\Documents and Settings\All Users\Application Data\TechSmith
2008-07-25 07:21:34 0 d-------- C:\Program Files\TechSmith
2008-07-24 16:58:48 0 d-------- C:\Program Files\ToniArts
2008-07-24 16:34:21 0 d-------- C:\Program Files\RegScrubXP
2008-07-23 11:11:58 0 d-------- C:\Program Files\Panda Security
2008-07-20 21:31:37 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-20 21:31:21 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-07-07 18:20:59 0 d-------- C:\Program Files\Add-in Express


-- Find3M Report ---------------------------------------------------------------

2008-08-07 18:08:07 0 d-------- C:\Program Files\ENDFORCE
2008-08-07 17:39:39 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-08-07 14:43:36 0 d-------- C:\Program Files\oneworldflights
2008-08-06 19:05:06 0 d-------- C:\Program Files\NCR
2008-08-06 16:20:49 12 --a------ C:\WINDOWS\bthservsdp.dat
2008-08-01 02:00:03 0 d-------- C:\Documents and Settings\sw185041\Application Data\Mozilla
2008-07-30 11:48:19 0 d-------- C:\Program Files\Common Files
2008-07-25 14:16:20 0 d-------- C:\Documents and Settings\sw185041\Application Data\uTorrent
2008-07-25 07:20:00 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-24 10:22:09 0 d-------- C:\Program Files\Google
2008-07-23 15:20:12 0 d-------- C:\Documents and Settings\sw185041\Application Data\VMware
2008-07-23 12:48:51 0 d-------- C:\Documents and Settings\sw185041\Application Data\Yahoo!
2008-07-23 10:57:19 0 d-------- C:\Program Files\Yahoo!
2008-07-05 05:14:48 456192 --a------ C:\WINDOWS\system32\libmplayer.dll
2008-07-05 05:14:44 3591168 --a------ C:\WINDOWS\system32\libavcodec.dll
2008-07-05 05:13:16 708096 --a------ C:\WINDOWS\system32\ff_x264.dll
2008-06-22 11:34:00 177664 --a------ C:\WINDOWS\system32\ff_theora.dll
2008-06-13 05:39:38 23552 --a------ C:\WINDOWS\system32\ff_wmv9.dll
2008-06-12 12:36:38 7680 --a------ C:\WINDOWS\system32\ff_vfw.dll
2008-06-12 11:25:06 962560 --a------ C:\WINDOWS\system32\VSFilter.dll <Not Verified; Gabest; VSFilter>


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [05/12/2005 10:00 PM]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [09/01/2005 06:24 PM]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [04/26/2004 09:04 AM]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [12/06/2004 02:05 AM]
"NCR-Netmeeting Check"="C:\WINDOWS\NMTRepair.EXE" [01/03/2006 02:41 PM]
"ControlCenter2.0"="C:\Program Files\Brother\ControlCenter2\brctrcen.exe" [07/20/2004 09:34 AM]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [07/19/2005 05:32 PM]
"OfficeScanNT Monitor"="C:\Program Files\Common Files\Trend Micro\OfficeScan Client\pccntmon.exe" [01/08/2007 07:20 PM]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [03/23/2005 06:26 PM]
"BluetoothAuthenticationAgent"="bthprops.cpl" [08/04/2004 06:00 AM C:\WINDOWS\system32\bthprops.cpl]
"VMware hqtray"="C:\Program Files\VMware\VMware Player\hqtray.exe" [05/01/2007 10:46 PM]
"ENDFORCEAgent"="C:\Program Files\ENDFORCE\AgntTray.exe" [06/27/2007 11:35 PM]
"GoBoingo"="C:\Program Files\Boingo\GoBoingo\GoBoingo.lnk" [08/06/2008 04:30 PM]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" []
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [07/24/2008 10:22 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 06:00 AM]
"Simp"="C:\Program Files\Secway\SimpLite-MSN 2.2\SimpLite-MSN.exe" [08/28/2007 07:29 PM]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" [11/13/2006 01:39 PM]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [07/07/2008 09:42 AM]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [06/19/2008 12:51 PM]

C:\Documents and Settings\sw185041\Start Menu\Programs\Startup\
Yahoo! Widgets.lnk - C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe [12/11/2007 5:34:48 PM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [6/16/2005 11:11:42 AM]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [3/6/2006 1:25:01 AM]
Status Monitor.lnk - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe [4/7/2006 8:36:48 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoMSAppLogo5ChannelNotify"=1 (0x1)
"NoToolbarCustomize"=0 (0x0)
"NoBandCustomize"=0 (0x0)
"NoWindowsUpdate"=1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoWindowsUpdate"=1 (0x1)
"ClearRecentDocsOnExit"=01000000
"NoRecentDocsHistory"=01000000
"NoRecentDocsNetHood"=01000000
"NoSMMyPictures"=01000000
"NoRecentDocsMenu"=01000000

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktop"=0 (0x0)
"NoActiveDesktopChanges"=0 (0x0)
"NoInternetIcon"=0 (0x0)
"NoDesktop"=0 (0x0)
"Btn_Back"=0 (0x0)
"Btn_Forward"=0 (0x0)
"Btn_Stop"=0 (0x0)
"Btn_Refresh"=0 (0x0)
"Btn_Home"=0 (0x0)
"Btn_Search"=0 (0x0)
"Btn_History"=0 (0x0)
"Btn_Favorites"=0 (0x0)
"Btn_Media"=0 (0x0)
"Btn_Folders"=0 (0x0)
"Btn_Fullscreen"=0 (0x0)
"Btn_Tools"=0 (0x0)
"Btn_MailNews"=0 (0x0)
"Btn_Size"=0 (0x0)
"Btn_Print"=0 (0x0)
"Btn_Edit"=0 (0x0)
"Btn_Discussions"=0 (0x0)
"Btn_Cut"=0 (0x0)
"Btn_Copy"=0 (0x0)
"Btn_Paste"=0 (0x0)
"Btn_Encoding"=0 (0x0)
"Btn_PrintPreview"=0 (0x0)
"NoWindowsUpdate"=1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rstrui.exe]
debugger=C:\WINDOWS\system32\Restore\profhlp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
C:\Program Files\Apoint\Apoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
"C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
"C:\Program Files\Logitech\Video\ManifestEngine.exe" boot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
C:\Program Files\Logitech\Video\ISStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
C:\Program Files\Logitech\Video\LogiTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
"C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
"C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{15ba22fe-81d3-11dc-b14b-0016ce0b2c30}]
AutoRun\command- E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6847d974-c525-11db-b11a-444553544200}]
AutoRun\command- setupSNK.exe




-- End of Deckard's System Scanner: finished at 2008-08-07 18:35:22 ------------



Here is the main.txt from the DSS.EXE run with check all:

Deckard's System Scanner v20071014.68
Run by sw185041 on 2008-08-07 18:38:08
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
38: 2008-08-07 23:38:20 UTC - RP443 - Deckard's System Scanner Restore Point
37: 2008-08-07 22:41:42 UTC - RP442 - Configured .NET Data Provider for Teradata
36: 2008-08-07 22:35:19 UTC - RP441 - Installed .NET Data Provider for Teradata
35: 2008-08-07 00:06:36 UTC - RP440 - Installed Teradata GSS Client nt-i386
34: 2008-08-06 23:57:08 UTC - RP439 - Removed Teradata GSS Client nt-i386


-- First Restore Point --
1: 2008-06-16 19:25:50 UTC - RP406 - Installed Windows XP KB926239.


Performed disk cleanup.



-- HijackThis (run as sw185041.exe) --------------------------------------------

Unable to find log (file not found); running clone.
-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-08-07 18:39:05
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\NCR\Tdat\TGTW\06.01.00.12\bin\gtwrsrvtdmst.exe
C:\WINDOWS\system32\WLTRYSVC.EXE
C:\WINDOWS\system32\BCMWLTRY.EXE
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\BAsfIpM.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\NCR\BYNET\blmsvc.exe
C:\Program Files\ENDFORCE\AgentAPI.exe
C:\Program Files\Teradata\Teradata Manager 13.0\Bin\isservice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe
C:\Program Files\Common Files\Trend Micro\OfficeScan Client\NTRtScan.exe
C:\Program Files\NCR\Tdat\PDE\06.01.00.12\bin\pdeinetd.exe
C:\Program Files\NCR\NCRput\bin\wfxrd.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Common Files\Trend Micro\OfficeScan Client\PccNTMon.exe
C:\Program Files\NCR\NCRput\bin\putjobd.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\NCR\NCRput\bin\portmgmt.exe
C:\Program Files\VMware\VMware Player\hqtray.exe
C:\Program Files\ENDFORCE\AgntTray.exe
C:\Program Files\Boingo\GoBoingo\GoBoingo.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Secway\SimpLite-MSN 2.2\SimpLite-MSN.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Common Files\Trend Micro\OfficeScan Client\TmListen.exe
C:\Program Files\Microsoft ActiveSync\rapimgr.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
C:\Program Files\VMware\VMware Player\vmware-authd.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\TEMP\TKA37A.EXE
C:\Program Files\Common Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\Program Files\Teradata\Teradata Dynamic Workload Manager 13.0\tdwm.exe
C:\Program Files\TechSmith\SnagIt 9\SnagIt32.exe
C:\Program Files\TechSmith\SnagIt 9\TscHelp.exe
C:\Program Files\TechSmith\SnagIt 9\SnagPriv.exe
C:\Program Files\TechSmith\SnagIt 9\SnagItEditor.exe
C:\Documents and Settings\sw185041\Desktop\dss.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&client=dell-rel
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/keyword/%s
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://rpc1720.daytonoh.ncr.com/registration.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy-mem60fw.network.fedex.com:3128
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.google.com/ig/dell?hl=en&client=dell-rel
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O1 - Hosts: 199.228.192.159 EDWPRDcop1
O1 - Hosts: 199.228.5.48 EDWDEVcop1
O1 - Hosts: 153.64.20.231 partnerscop1 partners
O1 - Hosts: 153.64.208.9 figcop1 fig
O1 - Hosts: 67.161.162.46 PDLinuxcop1 PDLinux
O1 - Hosts: 153.64.209.130 Tobacop1 Toba
O1 - Hosts: 106.1.1.74 hekyl hekylcop1
O1 - Hosts: 106.1.1.71 jekyl jekylcop1
O1 - Hosts: 153.65.185.116 ceres05 ceres05cop1
O1 - Hosts: 153.65.185.117 ceres05 ceres05cop2
O1 - Hosts: 153.65.185.118 ceres05 ceres05cop3
O1 - Hosts: 153.65.185.119 ceres05 ceres05cop4
O1 - Hosts: 106.1.1.79 mcqueen mcqueencop1
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 9\SnagItBHO.dll
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\GoogleToolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\GoogleAFE\GoogleAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\GoogleToolbar1.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 9\SnagItIEAddin.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [NCR-Netmeeting Check] C:\WINDOWS\NMTRepair.EXE
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Common Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [VMware hqtray] "C:\Program Files\VMware\VMware Player\hqtray.exe"
O4 - HKLM\..\Run: [ENDFORCEAgent] "C:\Program Files\ENDFORCE\AgntTray.exe"
O4 - HKLM\..\Run: [GoBoingo] C:\Program Files\Boingo\GoBoingo\GoBoingo.lnk
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Simp] C:\Program Files\Secway\SimpLite-MSN 2.2\SimpLite-MSN.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O4 - Global Startup: Bluetooth Manager.lnk = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: Status Monitor.lnk = ?
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: (no name) - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - (file missing)
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\sw185041\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.Teradata.com (HKCU)
O16 - DPF: {0B0F4127-1B3E-467A-B6C8-571807562DDC} (AuthenticationTD.Authenticate) - http://web.teradatanet.teradata.com/cab/validateTD.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} () - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1E1BC012-AC2A-403F-AEE4-A32E1F18986D} () - https://www.passwordmanager.ncr.com/psynch/docs/pslogoff.dll
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} (Shockwave ActiveX Control) - http://fpdownload.macromedia.com/get/shock...director/sw.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} () - http://download.microsoft.com/download/F/6...922/wmv9VCM.CAB
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} () - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {4E67B0DB-1CAE-11D2-AD10-02608CA0806B} () - http://web.ncrnet.ncr.com/cab/NCRFile.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1216999819520
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} () - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} () - http://www.infuzer.com/IDC/client/player/isetup1.cab
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/67/install/gtdownls.cab
O16 - DPF: {AA3AE90C-F60E-4FD9-85E0-A00B61AE49B0} () - https://myc3.gateway.ncr.com/core/wizards/P...ntMailTools.CAB
O16 - DPF: {BA2A9829-8040-4BF3-BDB6-51512826B68B} (Authentication.Authenticate) - http://web.ncr.com/cab/phonebook.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {DD3D661B-E8FA-11D2-A018-00A0C9AD89DF} (Phonebook.Application) - http://web.ncrnet.ncr.com/cab/phonebook.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} () - https://ncruniversity.webex.com/client/v_my...ing/ieatgpc.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://sslgateway.teradata.com/dana-cached...perSetupSP1.cab
O16 - DPF: {F5131C24-E56D-11CF-B78A-444553540000} () - https://myb.gateway.ncr.com/Site0008/html/B...ix/ikcntrls.cab
O17 - HKLM\Software\..\Telephony: DomainName = TD.teradata.com
O17 - HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: Domain = corp.ncr.com
O17 - HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: SearchList = corp.ncr.com,elsegundoca.ncr.com,sandiegoca.ncr.com
O17 - HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: Domain = TD.teradata.com
O17 - HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: SearchList = corp.ncr.com,elsegundoca.ncr.com,sandiegoca.ncr.com
O17 - HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: Domain = TD.teradata.com
O17 - HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: SearchList = corp.ncr.com,elsegundoca.ncr.com,sandiegoca.ncr.com
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL
O18 - Protocol: x-excid - {9D6CC632-1337-4a33-9214-2DA092E776F4} - (no file)
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: AtiExtEvent - C:\WINDOWS\system32\Ati2evxx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\ati2evxx.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\BAsfIpM.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\system32\Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: bynet - NCR Corporation - C:\Program Files\NCR\BYNET\blmsvc.exe
O23 - Service: ENDFORCE Agent API - ENDFORCE, Inc. - C:\Program Files\ENDFORCE\AgentAPI.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Teradata GTW Reserve Port (GtwRsrvTdmst) - NCR - C:\Program Files\NCR\Tdat\TGTW\06.01.00.12\bin\gtwrsrvtdmst.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Teradata Manager Service (ISService) - Teradata Corporation - C:\Program Files\Teradata\Teradata Manager 13.0\Bin\isservice.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Common Files\Trend Micro\OfficeScan Client\NTRtScan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Common Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: Teradata inetd Service (PdeinetdService) - NCR - C:\Program Files\NCR\Tdat\PDE\06.01.00.12\bin\pdeinetd.exe
O23 - Service: NCR PUT File Service (PUTFileSvc) - Unknown owner - C:\Program Files\NCR\NCRput\bin\wfxrd.exe
O23 - Service: NCR PUT Job Service (PUTJobSvc) - Unknown owner - C:\Program Files\NCR\NCRput\bin\putjobd.exe
O23 - Service: NCR PUT Port Manager Service (PUTPortMgrSvc) - Unknown owner - C:\Program Files\NCR\NCRput\bin\portmgmt.exe
O23 - Service: Teradata RDBMS Initiator (recond) - NCR - C:\Program Files\NCR\Tdat\PDE\06.01.00.12\bin\recond.exe
O23 - Service: TQS Server (TdqmServerService) - Teradata, a division of NCR - C:\Program Files\NCR\Teradata Query Scheduler 12.0\server\tdqmserv.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Common Files\Trend Micro\OfficeScan Client\TmListen.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Player\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\system32\WLTRYSVC.EXE


--
End of file - 20234 bytes

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R0 bynetpnp (NCR Bynet Interconnect) - c:\windows\system32\drivers\bynetpnp.sys <Not Verified; NCR Corporation; BYNET Software>
R0 ncrbynet (NCR Bynet Low Latency Interface) - c:\windows\system32\drivers\ncrbynet.sys <Not Verified; NCR Corporation; BYNET Software>
R1 APPDRV - c:\windows\system32\drivers\appdrv.sys <Not Verified; Dell Inc; Application Driver>
R1 NEOFLTR_530_11531 (Juniper Networks TDI Filter Driver (NEOFLTR_530_11531)) - c:\windows\system32\drivers\neofltr_530_11531.sys <Not Verified; Neoteris; Secure Application Manager>
R1 omci (OMCI WDM Device Driver) - c:\windows\system32\drivers\omci.sys <Not Verified; Dell Inc; OMCI Driver>
R1 Tosrfcom (Bluetooth RFCOMM from TOSHIBA) - c:\windows\system32\drivers\tosrfcom.sys <Not Verified; TOSHIBA Corporation; Bluetooth RFCOMM Driver>
R2 PnMgr - c:\windows\system32\drivers\pnmgr.sys <Not Verified; NCR; Parallel Upgrade Tool>
R2 TM_CFW (Common Firewall Driver) - c:\program files\common files\trend micro\officescan client\tm_cfw.sys <Not Verified; Trend Micro Inc.; Trend Micro Common Firewall Module 1.2>
R3 Eacfilt (Eacfilt Miniport) - c:\windows\system32\drivers\eacfilt.sys <Not Verified; Nortel Networks; Filter Driver for CVC>
R3 GTIPCI21 - c:\windows\system32\drivers\gtipci21.sys <Not Verified; Texas Instruments; Texas Instruments PCI GemCore Based SmartCard Interface>
R3 IPSECSHM (Nortel IPSECSHM Adapter) - c:\windows\system32\drivers\ipsecw2k.sys <Not Verified; Nortel Networks NA, Inc.; Contivity VPN Client>
R3 PCASp50 (PCASp50 NDIS Protocol Driver) - c:\windows\system32\drivers\pcasp50.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
R3 tosporte (Bluetooth Port Driver from Toshiba) - c:\windows\system32\drivers\tosporte.sys <Not Verified; TOSHIBA Corporation; TOSHIBA Bluetooth Port Emulation Driver>

S3 FreshIO - c:\program files\freshdevices\freshdiagnose\freshio.sys (file missing)
S3 IPSECEXT (Nortel Extranet Access Protocol) - c:\windows\system32\drivers\ipsecw2k.sys <Not Verified; Nortel Networks NA, Inc.; Contivity VPN Client>
S3 Jukebox3 - c:\windows\system32\drivers\ctpdusb.sys (file missing)
S3 Pdesys (PDE Sys Driver) - c:\windows\system32\drivers\pdesys.sys <Not Verified; NCR; opnpde>
S3 toshidpt (TOSHIBA Bluetooth HID port driver) - c:\windows\system32\drivers\toshidpt.sys <Not Verified; TOSHIBA Corporation.; TOSHIBA Bluetooth HID Mini Port Driver>
S3 Tosrfbd (Bluetooth RFBUS from TOSHIBA) - c:\windows\system32\drivers\tosrfbd.sys <Not Verified; TOSHIBA CORPORATION; Bluetooth BUS Driver(WindowsXP,Windows2000)>
S3 Tosrfbnp (Bluetooth RFBNEP from TOSHIBA) - c:\windows\system32\drivers\tosrfbnp.sys <Not Verified; TOSHIBA Corporation; Bluetooth RFBNEP Driver from TOSHIBA>
S3 Tosrfhid (Bluetooth RFHID from TOSHIBA) - c:\windows\system32\drivers\tosrfhid.sys <Not Verified; TOSHIBA Corporation.; Bluetooth HID Driver from TOSHIBA>
S3 tosrfnds (Bluetooth Personal Area Network from TOSHIBA) - c:\windows\system32\drivers\tosrfnds.sys <Not Verified; TOSHIBA Corporation.; Bluetooth BNEP Driver from TOSHIBA>
S3 TosRfSnd (Bluetooth Audio Device (WDM) from TOSHIBA) - c:\windows\system32\drivers\tosrfsnd.sys <Not Verified; TOSHIBA Corporation; Bluetooth Audio Driver>
S3 Tosrfusb (Bluetooth USB Controller) - c:\windows\system32\drivers\tosrfusb.sys <Not Verified; TOSHIBA CORPORATION; Microsoft® Windows NT® Operating System>


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 BAsfIpM (Broadcom ASF IP monitoring service v6.0.4) - c:\windows\system32\basfipm.exe <Not Verified; Broadcom Corp.; Broadcom ASF IP monitoring service>
R2 bynet - "c:\program files\ncr\bynet\blmsvc.exe" <Not Verified; NCR Corporation; BYNET Software>
R2 ENDFORCE Agent API - "c:\program files\endforce\agentapi.exe" <Not Verified; ENDFORCE, Inc.; ENDFORCE Enterprise>
R2 GtwRsrvTdmst (Teradata GTW Reserve Port) - "c:\program files\ncr\tdat\tgtw\06.01.00.12\bin\gtwrsrvtdmst.exe" <Not Verified; NCR; gateway>
R2 ISService (Teradata Manager Service) - "c:\program files\teradata\teradata manager 13.0\bin\isservice.exe" <Not Verified; Teradata Corporation; Teradata Manager>
R2 NICCONFIGSVC - c:\program files\dell\nicconfigsvc\nicconfigsvc.exe <Not Verified; Dell Inc.; NicConfigSvc>
R2 ntrtscan (OfficeScanNT RealTime Scan) - "c:\program files\common files\trend micro\officescan client\ntrtscan.exe" <Not Verified; Trend Micro Inc.; Trend Micro OfficeScan>
R2 OfcPfwSvc (OfficeScanNT Personal Firewall) - "c:\program files\common files\trend micro\officescan client\ofcpfwsvc.exe" <Not Verified; Trend Micro Inc.; Trend Micro OfficeScan>
R2 PdeinetdService (Teradata inetd Service) - "c:\program files\ncr\tdat\pde\06.01.00.12\bin\pdeinetd.exe" <Not Verified; NCR; opnpde>
R2 PUTFileSvc (NCR PUT File Service) - "c:\program files\ncr\ncrput\bin\wfxrd.exe"
R2 PUTJobSvc (NCR PUT Job Service) - "c:\program files\ncr\ncrput\bin\putjobd.exe"
R2 PUTPortMgrSvc (NCR PUT Port Manager Service) - "c:\program files\ncr\ncrput\bin\portmgmt.exe"
R2 tmlisten (OfficeScanNT Listener) - "c:\program files\common files\trend micro\officescan client\tmlisten.exe" <Not Verified; Trend Micro Inc.; Trend Micro OfficeScan>
R2 Viewpoint Manager Service - "c:\program files\viewpoint\common\viewpointservice.exe" <Not Verified; Viewpoint Corporation; Viewpoint Manager>

S3 ExtranetAccess (Contivity VPN Service) - "c:\program files\nortel networks\extranet_serv.exe" <Not Verified; Nortel Networks NA, Inc.; Nortel Networks Contivity VPN Client>
S3 recond (Teradata RDBMS Initiator) - "c:\program files\ncr\tdat\pde\06.01.00.12\bin\recond.exe" "-s" <Not Verified; NCR; opnpde>
S3 TdqmServerService (TQS Server) - "c:\program files\ncr\teradata query scheduler 12.0\server\tdqmserv.exe" <Not Verified; Teradata, a division of NCR; Teradata Query Scheduler>


-- Device Manager: Disabled ----------------------------------------------------

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Dell Wireless 1370 WLAN Mini-PCI Card
Device ID: PCI\VEN_14E4&DEV_4318&SUBSYS_00051028&REV_02\4&2FA23535&0&18F0
Manufacturer: Broadcom
Name: Dell Wireless 1370 WLAN Mini-PCI Card
PNP Device ID: PCI\VEN_14E4&DEV_4318&SUBSYS_00051028&REV_02\4&2FA23535&0&18F0
Service: BCM43XX

Class GUID: {6BDD1FC5-810F-11D0-BEC7-08002BE2092F}
Description: SMC IrCC - Fast Infrared Port
Device ID: ACPI\SMCF010\4&15F2F7D1&0
Manufacturer: SMC
Name: SMC IrCC - Fast Infrared Port
PNP Device ID: ACPI\SMCF010\4&15F2F7D1&0
Service: SMCIRDA


-- Process Modules -------------------------------------------------------------

C:\WINDOWS\system32\winlogon.exe (pid 748)
2005-05-13 03:43:54 46080 --a------ C:\WINDOWS\system32\ati2evxx.dll <Not Verified; ATI Technologies Inc.; ATI External Event Utility for NT, W2K and W9X>

C:\WINDOWS\explorer.exe (pid 252)
2008-07-24 10:22:39 162816 --a------ C:\Program Files\Google\Google Desktop Search\GoogleDesktopDeskbar2.dll <Not Verified; Google; Google Desktop>
2008-07-24 10:22:18 566784 --a------ C:\Program Files\Google\Google Desktop Search\GoogleDesktopResources_en.dll <Not Verified; Google; Google Desktop>
2008-07-24 10:22:39 203776 --a------ C:\Program Files\Google\Google Desktop Search\GoogleDesktopCommon.dll <Not Verified; Google; Google Desktop>
2008-07-24 10:22:39 135168 --a------ C:\Program Files\Google\Google Desktop Search\GoogleDesktopHyper.dll <Not Verified; Google; Google Desktop>
2007-03-10 05:39:52 98304 --a------ C:\Program Files\Secway\SimpLite-MSN 2.2\Plugins\WinsockHookDLL.dll
2005-07-26 19:46:42 69632 --a------ C:\Program Files\Dell\QuickSet\dadkeyb.dll
2005-09-23 06:28:38 83456 --a------ C:\WINDOWS\system32\dfshim.dll <Not Verified; Microsoft Corporation; Microsoft® .NET Framework>
2007-04-13 02:21:14 271360 --a------ C:\WINDOWS\system32\mscoree.dll <Not Verified; Microsoft Corporation; Microsoft® .NET Framework>
2005-09-23 06:28:56 107520 --a------ C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\shfusion.dll <Not Verified; Microsoft Corporation; Microsoft® .NET Framework>
2005-09-23 06:28:50 9216 --a------ C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\fusion.dll <Not Verified; Microsoft Corporation; Microsoft® .NET Framework>
2005-09-23 06:28:58 17920 --a------ C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Culture.dll <Not Verified; Microsoft Corporation; Microsoft® .NET Framework>
2005-09-23 06:29:00 85504 --a------ C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ShFusRes.dll <Not Verified; Microsoft Corporation; Microsoft® .NET Framework>
2004-08-16 08:00:00 5120 --a------ C:\Program Files\WINZIP\WZSHLSTB.DLL <Not Verified; WinZip Computing, Inc.; WinZip>

C:\WINDOWS\system32\rundll32.exe (pid 2196)
2007-03-10 05:39:52 98304 --a------ C:\Program Files\Secway\SimpLite-MSN 2.2\Plugins\WinsockHookDLL.dll


-- Scheduled Tasks -------------------------------------------------------------

2008-05-23 11:12:23 398 --a------ C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job
2008-05-23 11:12:23 276 --a------ C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job


-- Files created between 2008-07-07 and 2008-08-07 -----------------------------

2008-08-07 11:59:27 0 d-------- C:\MyWorkData
2008-08-07 09:13:47 0 dr-h----- C:\Documents and Settings\sw185041\Recent
2008-08-06 13:07:36 0 d-------- C:\Documents and Settings\All Users\Application Data\Teradata
2008-08-06 11:34:11 25600 --a------ C:\WINDOWS\system32\drivers\pnmgr.sys <Not Verified; NCR; Parallel Upgrade Tool>
2008-08-06 11:14:52 0 d-------- C:\td12software
2008-08-06 10:35:08 0 d-------- C:\Program Files\Teradata
2008-07-30 11:52:42 0 d-------- C:\Documents and Settings\sw185041\Application Data\acccore
2008-07-30 11:51:02 0 d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-07-30 11:50:58 0 d-------- C:\Program Files\Viewpoint
2008-07-30 11:50:53 0 d-------- C:\Documents and Settings\All Users\Application Data\acccore
2008-07-30 11:49:41 0 d-------- C:\Documents and Settings\All Users\Application Data\AOL
2008-07-30 11:49:41 0 d-------- C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-07-30 11:48:19 0 d-------- C:\Program Files\Common Files\AOL
2008-07-30 11:48:04 0 d-------- C:\Program Files\AIM6
2008-07-30 11:19:10 0 d-------- C:\Program Files\Trillian
2008-07-25 12:52:59 0 d-------- C:\Documents and Settings\sw185041\Application Data\WinRAR
2008-07-25 10:54:36 0 d-------- C:\Documents and Settings\sw185041\Application Data\Media Player Classic
2008-07-25 10:48:53 0 d-------- C:\Program Files\XP Codec Pack
2008-07-25 07:21:44 0 d-------- C:\Documents and Settings\All Users\Application Data\TechSmith
2008-07-25 07:21:34 0 d-------- C:\Program Files\TechSmith
2008-07-24 16:58:48 0 d-------- C:\Program Files\ToniArts
2008-07-24 16:34:21 0 d-------- C:\Program Files\RegScrubXP
2008-07-23 11:11:58 0 d-------- C:\Program Files\Panda Security
2008-07-20 21:31:37 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-20 21:31:21 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-07-07 18:20:59 0 d-------- C:\Program Files\Add-in Express


-- Find3M Report ---------------------------------------------------------------

2008-08-07 18:08:07 0 d-------- C:\Program Files\ENDFORCE
2008-08-07 17:39:39 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-08-07 14:43:36 0 d-------- C:\Program Files\oneworldflights
2008-08-06 19:05:06 0 d-------- C:\Program Files\NCR
2008-08-06 16:20:49 12 --a------ C:\WINDOWS\bthservsdp.dat
2008-08-01 02:00:03 0 d-------- C:\Documents and Settings\sw185041\Application Data\Mozilla
2008-07-30 11:48:19 0 d-------- C:\Program Files\Common Files
2008-07-25 14:16:20 0 d-------- C:\Documents and Settings\sw185041\Application Data\uTorrent
2008-07-25 07:20:00 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-24 10:22:09 0 d-------- C:\Program Files\Google
2008-07-23 15:20:12 0 d-------- C:\Documents and Settings\sw185041\Application Data\VMware
2008-07-23 12:48:51 0 d-------- C:\Documents and Settings\sw185041\Application Data\Yahoo!
2008-07-23 10:57:19 0 d-------- C:\Program Files\Yahoo!
2008-07-05 05:14:48 456192 --a------ C:\WINDOWS\system32\libmplayer.dll
2008-07-05 05:14:44 3591168 --a------ C:\WINDOWS\system32\libavcodec.dll
2008-07-05 05:13:16 708096 --a------ C:\WINDOWS\system32\ff_x264.dll
2008-06-22 11:34:00 177664 --a------ C:\WINDOWS\system32\ff_theora.dll
2008-06-13 05:39:38 23552 --a------ C:\WINDOWS\system32\ff_wmv9.dll
2008-06-12 12:36:38 7680 --a------ C:\WINDOWS\system32\ff_vfw.dll
2008-06-12 11:25:06 962560 --a------ C:\WINDOWS\system32\VSFilter.dll <Not Verified; Gabest; VSFilter>


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [05/12/2005 10:00 PM]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [09/01/2005 06:24 PM]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [04/26/2004 09:04 AM]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [12/06/2004 02:05 AM]
"NCR-Netmeeting Check"="C:\WINDOWS\NMTRepair.EXE" [01/03/2006 02:41 PM]
"ControlCenter2.0"="C:\Program Files\Brother\ControlCenter2\brctrcen.exe" [07/20/2004 09:34 AM]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [07/19/2005 05:32 PM]
"OfficeScanNT Monitor"="C:\Program Files\Common Files\Trend Micro\OfficeScan Client\pccntmon.exe" [01/08/2007 07:20 PM]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [03/23/2005 06:26 PM]
"BluetoothAuthenticationAgent"="bthprops.cpl" [08/04/2004 06:00 AM C:\WINDOWS\system32\bthprops.cpl]
"VMware hqtray"="C:\Program Files\VMware\VMware Player\hqtray.exe" [05/01/2007 10:46 PM]
"ENDFORCEAgent"="C:\Program Files\ENDFORCE\AgntTray.exe" [06/27/2007 11:35 PM]
"GoBoingo"="C:\Program Files\Boingo\GoBoingo\GoBoingo.lnk" [08/06/2008 04:30 PM]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" []
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [07/24/2008 10:22 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 06:00 AM]
"Simp"="C:\Program Files\Secway\SimpLite-MSN 2.2\SimpLite-MSN.exe" [08/28/2007 07:29 PM]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" [11/13/2006 01:39 PM]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [07/07/2008 09:42 AM]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [06/19/2008 12:51 PM]

C:\Documents and Settings\sw185041\Start Menu\Programs\Startup\
Yahoo! Widgets.lnk - C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe [12/11/2007 5:34:48 PM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [6/16/2005 11:11:42 AM]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [3/6/2006 1:25:01 AM]
Status Monitor.lnk - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe [4/7/2006 8:36:48 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoMSAppLogo5ChannelNotify"=1 (0x1)
"NoToolbarCustomize"=0 (0x0)
"NoBandCustomize"=0 (0x0)
"NoWindowsUpdate"=1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoWindowsUpdate"=1 (0x1)
"ClearRecentDocsOnExit"=01000000
"NoRecentDocsHistory"=01000000
"NoRecentDocsNetHood"=01000000
"NoSMMyPictures"=01000000
"NoRecentDocsMenu"=01000000

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktop"=0 (0x0)
"NoActiveDesktopChanges"=0 (0x0)
"NoInternetIcon"=0 (0x0)
"NoDesktop"=0 (0x0)
"Btn_Back"=0 (0x0)
"Btn_Forward"=0 (0x0)
"Btn_Stop"=0 (0x0)
"Btn_Refresh"=0 (0x0)
"Btn_Home"=0 (0x0)
"Btn_Search"=0 (0x0)
"Btn_History"=0 (0x0)
"Btn_Favorites"=0 (0x0)
"Btn_Media"=0 (0x0)
"Btn_Folders"=0 (0x0)
"Btn_Fullscreen"=0 (0x0)
"Btn_Tools"=0 (0x0)
"Btn_MailNews"=0 (0x0)
"Btn_Size"=0 (0x0)
"Btn_Print"=0 (0x0)
"Btn_Edit"=0 (0x0)
"Btn_Discussions"=0 (0x0)
"Btn_Cut"=0 (0x0)
"Btn_Copy"=0 (0x0)
"Btn_Paste"=0 (0x0)
"Btn_Encoding"=0 (0x0)
"Btn_PrintPreview"=0 (0x0)
"NoWindowsUpdate"=1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rstrui.exe]
debugger=C:\WINDOWS\system32\Restore\profhlp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
C:\Program Files\Apoint\Apoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
"C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
"C:\Program Files\Logitech\Video\ManifestEngine.exe" boot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
C:\Program Files\Logitech\Video\ISStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
C:\Program Files\Logitech\Video\LogiTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
"C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
"C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{15ba22fe-81d3-11dc-b14b-0016ce0b2c30}]
AutoRun\command- E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6847d974-c525-11db-b11a-444553544200}]
AutoRun\command- setupSNK.exe




-- Hosts -----------------------------------------------------------------------

127.0.0.1 localhost TDLTCOP1
199.228.192.159 EDWPRDcop1
199.228.5.48 EDWDEVcop1
153.64.20.231 partnerscop1 partners
153.64.208.9 figcop1 fig
67.161.162.46 PDLinuxcop1 PDLinux
153.64.209.130 Tobacop1 Toba
106.1.1.74 hekyl hekylcop1
106.1.1.71 jekyl jekylcop1
153.65.185.116 ceres05 ceres05cop1

3 more entries in hosts file.


-- End of Deckard's System Scanner: finished at 2008-08-07 18:40:37 ------------



Here is the extra.txt from dss.exe run with check all:

Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: Intel® Pentium® M processor 1.73GHz
Percentage of Memory in Use: 57%
Physical Memory (total/avail): 1023.36 MiB / 437.11 MiB
Pagefile Memory (total/avail): 2462.69 MiB / 1747.29 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1903.33 MiB

C: is Fixed (NTFS) - 37.18 GiB total, 5.94 GiB free.
D: is CDROM (No Media)
T: is Network (NTFS)

\\.\PHYSICALDRIVE0 - Hitachi HTS541040G9AT00 - 37.26 GiB - 2 partitions
\PARTITION0 - Unknown - 62.72 MiB
\PARTITION1 (bootable) - Installable File System - 37.18 GiB - C:



-- Security Center -------------------------------------------------------------

AUOptions is disabled.
AUState says computer has updates disabled.
Windows Internal Firewall is enabled.

FirstRunDisabled is set.

FW: Trend Micro OfficeScan Enterprise Client Firewall v7.3 (TrendFirewall)

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\Yahoo!\\Yahoo! Music Engine\\YahooMusicEngine.exe"="C:\\Program Files\\Yahoo!\\Yahoo! Music Engine\\YahooMusicEngine.exe:*:Enabled:Yahoo! Music Engine"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\\Program Files\\Neoteris\\Secure Application Manager\\dsSamProxy.exe"="C:\\Program Files\\Neoteris\\Secure Application Manager\\dsSamProxy.exe:*:Enabled:Secure Application Manager Proxy"
"C:\\Program Files\\Microsoft Office\\OFFICE11\\POWERPNT.EXE"="C:\\Program Files\\Microsoft Office\\OFFICE11\\POWERPNT.EXE:*:Enabled:Microsoft Office PowerPoint"
"C:\\Program Files\\Secway\\SimpLite-MSN 2.2\\SimpLite-MSN.exe"="C:\\Program Files\\Secway\\SimpLite-MSN 2.2\\SimpLite-MSN.exe:*:Enabled:SimpLite-MSN"
"C:\\Documents and Settings\\sw185041\\My Documents\\My Videos\\utorrent.exe"="C:\\Documents and Settings\\sw185041\\My Documents\\My Videos\\utorrent.exe:*:Enabled:µTorrent"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\AIM6\\aim6.exe"="C:\\Program Files\\AIM6\\aim6.exe:*:Enabled:AIM"
"C:\\Documents and Settings\\sw185041\\Local Settings\\Temp\\install\\Setup.exe"="C:\\Documents and Settings\\sw185041\\Local Settings\\Temp\\install\\Setup.exe:*:Enabled:Setup"
"C:\\linksys\\Setup.exe"="C:\\linksys\\Setup.exe:*:Enabled:Setup"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\sw185041\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.6.0_02\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=WUSSW185041-HZ6
ComSpec=C:\WINDOWS\system32\cmd.exe
COPLIB=C:\Program Files\Teradata\Client\13.0\CLIv2\
DataConnectorLibPath=C:\WINDOWS\system32\
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\sw185041
LOGONSERVER=\\SUSSAN140
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\Program Files\Teradata\Client\13.0\ODBC Driver for Teradata\Lib;C:\Program Files\Teradata\Client\13.0\CLIv2\;C:\Program Files\NCR\Teradata Parallel Transporter\8.1\bin;C:\Program Files\NCR\Teradata Parallel Transporter\8.1\msg;C:\Program Files\NCR\Teradata Client\WinCLI-Runtime\;C:\Program Files\NCR\Teradata Client\DevKit\;C:\Program Files\NCR\Teradata Client\Bin;C:\WINDOWS\system32\;C:\WINDOWS\system32\;C:\Program Files\NCR\Teradata Client\cliv2\;C:\Program Files\NCR\Common Files\Shared ICU Libraries for Teradata\lib;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\NCR\BYNET\;C:\Program Files\NCR\Tdat\LPDE\bin;C:\Program Files\Common Files\GTK\2.0\bin;C:\WINDOWS\system32\;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Teradata\Client\13.0\Shared ICU Libraries for Teradata\lib\;C:\ORAWIN95\BIN
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 13 Stepping 8, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0d08
ProgramFiles=C:\Program Files
PROMPT=$P$G
PutRootDir=C:\Program Files\NCR\NCRput\
QTJAVA=C:\Program Files\Java\jre1.6.0_02\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\sw185041\LOCALS~1\Temp
TMP=C:\DOCUME~1\sw185041\LOCALS~1\Temp
TWB_ROOT=C:\Program Files\NCR\Teradata Parallel Transporter\8.1
USERDNSDOMAIN=TD.TERADATA.COM
USERDOMAIN=TD
USERNAME=sw185041
USERPROFILE=C:\Documents and Settings\sw185041
VCToolkitInstallDir=C:\Program Files\Microsoft Visual C++ Toolkit 2003\
windir=C:\WINDOWS
_MSGCATLOCATION=C:\Program Files\NCR\Teradata Parallel Transporter\8.1\msg


-- User Profiles ---------------------------------------------------------------

sw185041 (admin)
sw185041 (new local, admin)
migtd (new local)
Administrator (admin)
sw185041 (admin)


-- Add/Remove Programs ---------------------------------------------------------

--> C:\WINDOWS\system32CPMailUninstall.exe changepointmailtools.dll {AA3AE90C-F60E-4FD9-85E0-A00B61AE49B0}
.NET Data Provider for Teradata 12.00.00.01 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{1457B3F3-289F-40E4-9C37-7A8519E1AABF} /l1033
.Net Data Provider For Teradata Help --> MsiExec.exe /I{F64898F5-FCCD-449F-9BD2-4D33FF700960}
_Teradata License for Microsoft Office 2003 Standard --> Not available
Abacast Client --> C:\Documents and Settings\sw185041\Local Settings\Application Data\Abacast\uninst.exe
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 8.1.2 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
AIM 6 --> C:\Program Files\AIM6\uninst.exe
Changepoint Mail Tools --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7090BD99-CCD0-43B5-A211-E7FEBBB4C988}\setup.exe" -l0x9 -uninst -removeonly
Cisco MeetingPlace for Outlook --> RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\MPOUTL.INF, DefaultUninstall.ntx86
Compatibility Pack for the 2007 Office system --> MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
Easy PC Asset Information --> Not Available
EasyCleaner --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F5346614-B7C4-4E94-826A-E2363155233D}\setup.exe" -l0x9 -removeonly
GoBoingo! --> MsiExec.exe /X{12723C3A-0FF8-4A0C-8BD3-DC958F388F67}
Google Desktop --> C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
HijackThis 1.99.1 --> C:\Program Files\HijackThis\HijackThis.exe /uninstall
Java™ 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java™ 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Microsoft ActiveSync --> MsiExec.exe /I{99052DB7-9592-4522-A558-5417BBAD48EE}
Microsoft MSDN 2005 Express Edition - ENU --> C:\Program Files\Microsoft Visual Studio 8\Microsoft MSDN 2005 Express Edition - ENU\install.exe
Microsoft Office Live Meeting 2005 --> MsiExec.exe /I{25A0133B-8BAC-4E61-8F43-DC6D9D9FE80B}
Microsoft Office Live Meeting 2007 --> MsiExec.exe /I{7DB92914-0A00-48C6-8DBB-F8E9D02B78B1}
Microsoft Office Standard Edition 2003 --> MsiExec.exe /I{90120409-6000-11D3-8CFE-0150048383C9}
Microsoft Visual Basic 2005 Express Edition - ENU --> C:\Program Files\Microsoft Visual Studio 8\Microsoft Visual Basic 2005 Express Edition - ENU\setup.exe
Microsoft Visual Basic 2005 Express Edition - ENU --> MsiExec.exe /X{577AD794-8B34-40B4-9E7A-BE4CFFE396E6}
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Mozilla Firefox (2.0.0.16) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
My Sirius Studio --> C:\Program Files\Sirius\MySiriusStudio\Uninstall.exe
NCRput --> MsiExec.exe /I{989B0C1F-8BDC-46BF-B122-FDCC7C35A2CE}
ODBC Driver for Teradata 13g.0 --> MsiExec.exe /I{BA8904B8-B5B1-47FE-A243-EFABA06EBC56}
oggcodecs 0.71.0946 --> C:\Program Files\illiminable\oggcodecs\uninst.exe
Panda ActiveScan 2.0 --> C:\Program Files\Panda Security\ActiveScan 2.0\as2uninst.exe
QuickTime --> MsiExec.exe /I{E0D51394-1D45-460A-B62D-383BC4F8B335}
RegScrubXP 3.25 --> "C:\Program Files\RegScrubXP\unins000.exe"
Shared ICU Libraries for Teradata 13e.0 --> MsiExec.exe /I{7AACD0B1-74BB-4DF1-869C-15767BB8C573}
SnagIt 9 --> MsiExec.exe /I{59991D18-A988-45AB-B1BF-5ADE6E64CD3F}
Spybot - Search & Destroy --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Teradata Administrator 13.0 --> MsiExec.exe /I{3A7CCC8B-F674-4577-9128-2A5B1AA53584}
Teradata CLIv2 13h.0 --> MsiExec.exe /I{0DF8B969-B0F6-4675-848A-ABED5CD2418D}
Teradata Data Connector 12.0.0.2 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{69FE15A5-550A-406D-83A9-DD23F960BEBF}
Teradata Dynamic Workload Manager --> MsiExec.exe /I{E9573FBB-208E-4B70-9788-EB28291A05F1}
Teradata Dynamic Workload Manager 13.0 --> "C:\Program Files\InstallShield Installation Information\{E9573FBB-208E-4B70-9788-EB28291A05F1}\setup.exe" -runfromtemp -l0x0409 -removeonly
Teradata GSS Client nt-i386 --> MsiExec.exe /I{839F0FD8-78AC-4314-BF32-998CD5A522F9}
Teradata Manager --> MsiExec.exe /I{34322408-B4AE-44DD-BBAD-3895A88D9198}
Teradata Manager 13.0 --> "C:\Program Files\InstallShield Installation Information\{34322408-B4AE-44DD-BBAD-3895A88D9198}\setup.exe" -runfromtemp -l0x0409 -removeonly
Teradata Screensaver Screensaver --> C:\Program Files\MainSail\Teradata Screensaver\Uninstall.exe
Teradata WinCLI Runtime Interface 3.2.11f --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{780AE91E-5004-45BB-9688-999A29584CF6}
Teradata Workload Analyzer --> MsiExec.exe /I{BC0E7108-A233-408B-90E1-C9BFCED41162}
Teradata Workload Analyzer 13.0 --> "C:\Program Files\InstallShield Installation Information\{BC0E7108-A233-408B-90E1-C9BFCED41162}\setup.exe" -runfromtemp -l0x0409 -removeonly
Trim Spaces for Microsoft Excel 1.1 --> "C:\Program Files\Add-in Express\AddIns\Trim Spaces for Excel\unins000.exe"
Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /u
Windows Driver Package - Microsoft Corporation (usbvideo) Image (05/25/2007 1.0.3656.0) --> rundll32.exe C:\PROGRA~1\DIFX\7AA84A78695B31A503D9537A76801D74E0FD14BD\DIFxAppA.dll, DIFxARPUninstallDriverPackage C:\WINDOWS\system32\DRVSTORE\RoundTable_F29D632BDCC1844B9B7688A0A4B4DA9E716B76FF\RoundTable.inf
Windows Imaging Component --> "C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
XP Codec Pack --> C:\Program Files\XP Codec Pack\Uninstall.exe
Yahoo! Install Manager --> C:\WINDOWS\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL
Yahoo! Widgets --> C:\PROGRA~1\Yahoo!\Widgets\uninstall.exe


-- Application Event Log -------------------------------------------------------

Event Record #/Type24296 / Warning
Event Submitted/Written: 08/07/2008 05:58:24 PM
Event ID/Source: 25 / Outlook
Event Description:
Cannot start the reminder service. Unable to show reminders.

Event Record #/Type24292 / Error
Event Submitted/Written: 08/07/2008 05:41:12 PM
Event ID/Source: 10005 / MsiInstaller
Event Description:
Product: .NET Data Provider for Teradata 12.0.0.1 Visual Studio 2008 Integration -- This package has a dependency on Microsoft Visual Studio 2008. Please install Visual Studio 2008 first.

Event Record #/Type24285 / Error
Event Submitted/Written: 08/07/2008 01:09:29 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application si.exe, version 13.0.0.0, faulting module msvcr80.dll, version 8.0.50727.762, fault address 0x000150e6.
Processing media-specific event for [si.exe!ws!]

Event Record #/Type24282 / Error
Event Submitted/Written: 08/07/2008 08:33:53 AM
Event ID/Source: 15 / AutoEnrollment
Event Description:
Automatic certificate enrollment for local system failed to contact the active directory (0x8007054b). The specified domain either does not exist or could not be contacted.
Enrollment will not be performed.

Event Record #/Type24281 / Error
Event Submitted/Written: 08/07/2008 00:33:53 AM
Event ID/Source: 15 / AutoEnrollment
Event Description:
Automatic certificate enrollment for local system failed to contact the active directory (0x8007054b). The specified domain either does not exist or could not be contacted.
Enrollment will not be performed.



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type111540 / Error
Event Submitted/Written: 08/07/2008 11:19:19 AM
Event ID/Source: 7016 / Service Control Manager
Event Description:
The BrSplService service has reported an invalid current state 0.

Event Record #/Type111539 / Error
Event Submitted/Written: 08/07/2008 09:59:16 AM
Event ID/Source: 10005 / DCOM
Event Description:
DCOM got error "%%1058" attempting to start the service usnjsvc with arguments ""
in order to run the server:
{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}

Event Record #/Type111538 / Error
Event Submitted/Written: 08/07/2008 09:59:04 AM
Event ID/Source: 10005 / DCOM
Event Description:
DCOM got error "%%1058" attempting to start the service usnjsvc with arguments ""
in order to run the server:
{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}

Event Record #/Type111537 / Error
Event Submitted/Written: 08/07/2008 09:58:53 AM
Event ID/Source: 10005 / DCOM
Event Description:
DCOM got error "%%1058" attempting to start the service usnjsvc with arguments ""
in order to run the server:
{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}

Event Record #/Type111536 / Error
Event Submitted/Written: 08/07/2008 09:58:39 AM
Event ID/Source: 10005 / DCOM
Event Description:
DCOM got error "%%1058" attempting to start the service usnjsvc with arguments ""
in order to run the server:
{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}



-- End of Deckard's System Scanner: finished at 2008-08-07 18:40:37 ------------



Do you really need that Kasperspy thing again? It took over 4 hours last time and found nothing. I can run it tonight if needed.

Thanks for your help.

#5 woodyatwork

woodyatwork
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:08:51 PM

Posted 08 August 2008 - 08:02 AM

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Friday, August 8, 2008
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Friday, August 08, 2008 02:22:23
Records in database: 1068436
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
T:\

Scan statistics:
Files scanned: 109630
Threat name: 1
Infected objects: 2
Suspicious objects: 0
Duration of the scan: 05:13:07


File name / Threat name / Threats count
C:\Documents and Settings\sw185041\Application Data\Sun\Java\Deployment\cache\6.0\22\10453ed6-687f686f Infected: Exploit.Java.Gimsh.b 1
C:\Documents and Settings\sw185041\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-3ad601a5-7d6dc4b1.zip Infected: Exploit.Java.Gimsh.b 1

The selected area was scanned.

#6 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:06:51 PM

Posted 10 August 2008 - 01:42 AM

Hello, woodyatwork.
Viewpoint is considered foistware instead of malware because it is installed without users approval, but doesn't spy or do anything "bad". You may like to read this article about the potential of this Viewpoint software here:
http://www.clickz.com/news/article.php/3561546

I suggest you remove the program now. Click on Start > Run... > and then paste the following into the "Open" field: "appwiz.cpl" and press OK. From within Add or Remove Programs uninstall the following if they exist: Viewpoint, Viewpoint Manager, and/or Viewpoint Media Player.

Your log shows that you have never used HiJack This. To ensure that backups made when items are fixed are secure, we need to get HijackThis set up properly.
  • Please download the self-extracting version of HijackThis from here: HijackThis Installer Download
  • Save HJTInstall.exe to your desktop.
  • Double-click the file then click the Install button.
    • The file will be extracted to C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
  • A shortcut for future use will also be created on your desktop and the Intro Frame of HijackThis will open.
    Please use the shortcut to run the extracted HijackThis.exe from now on.
We have to remove some entries in HiJack This
  • Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below:
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://rpc1720.daytonoh.ncr.com/registration.html
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy-mem60fw.network.fedex.com:3128
    O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
    O9 - Extra button: (no name) - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - (file missing)
    O18 - Protocol: x-excid - {9D6CC632-1337-4a33-9214-2DA092E776F4} - (no file)
  • Close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.
We need to move some files
Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    FreshIO <delete service>
    Jukebox3 <delete service>
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\\NoMSAppLogo5ChannelNotify
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\\NoWindowsUpdate
    HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\\NoWindowsUpdate
    C:\Documents and Settings\sw185041\Application Data\Sun\Java\Deployment\cache\6.0\22\10453ed6-687f686f
    C:\Documents and Settings\sw185041\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-3ad601a5-7d6dc4b1.zip
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt2
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Scroll down to where it says "Java Runtime Environment (JRE)6 Update 7...allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-Language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u7-windows-i586-p.exe
  • Follow the on screen instructions to install the latest Java version.
I would like us to use ESET (NOD32)'s Online Scanner
  • Please go to ESET OnlineScan (NOD32)
  • You will then see the Terms of Use, tick the check-box infront of YES, I accept the Terms of Use
  • Now click Start
  • Should you face a Security Warning that asks if you want to install and run a file called "OnlineScanner.cab", click Yes
  • Click Start
    • Note: (the Onlinescanner will now prepare itself for running on your pc)
  • To do a full-scan, tick: "Remove found threats" and "Scan potentially unwanted applications"
  • Press Scan
  • The Onlinescan will now start and scan your pc (this could take a while)
  • When the scan has finished, it will show a screen with two tabs "overview" and "details" and the option to get information or buy software, just close the window
  • Click Start >> Run... >> type: C:\Program Files\EsetOnlineScanner\log.txt
  • The Scanresults will now open in Notepad
  • Click into the text area, right-click and chose "select all" (or use +A)
  • Right-click again and chose "Copy" (or +C)
  • Close/Exit Notepad
  • Navigate to this thread and post your log along with anything else requested from us, by right-clicking and "paste" (or ctrl+v) in the text area of the reply post you just created.
Note: For Vista Users: Eset is compatible but Internet Explorer must be run as Administrator. To do this, right-click on the IE icon in the Start Menu or Quick Launch Bar on the Taskbar and select "Run as Administrator" from the context menu.)

Your Microsoft Windows installation is out of date.
Whenever a security problem in its software is found, Microsoft will usually create a patch for it. After the patch is installed, attackers can't use the vulnerability to install malicious software on your PC, so keeping up with these patches will help to prevent malicious software being installed on your PC
Go here to check for & install updates to Microsoft applications.
Note: The update process uses ActiveX, so you will need to use Internet Explorer for it, and allow the ActiveX control that it wants to install.

Please reboot and repeat the update process until there are no more updates to install.

Please let me know of any problems you may have encountered.

Please run Deckard's System Scanner again, this time using these instructions:
(In the event you lost your copy, you can download a new one from here: Deckard's System Scanner)
  • Click on Start, click on Run
  • Copy and paste the following in the open window and then click OK:
    "%userprofile%\desktop\dss.exe" /config
  • This will open up DSS configuration
  • Click on Check All.
  • Click Scan.
    DSS will now run again.
  • Please post back both logs that open in notepad.
    Main.txt and Extra.txt
In your next reply, please include the following:
  • OTMoveIt2's Log
  • ESET OnlineScan's Log
  • DSS's Main.txt
  • DSS's Extra.txt

Billy3

Edited by Billy O'Neal, 10 August 2008 - 01:42 AM.

Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#7 woodyatwork

woodyatwork
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:08:51 PM

Posted 10 August 2008 - 11:06 AM

Malware, Foistware. It should be called "p@ss me the h3ll off ware!".

I can't believe it was a simple uninstall to remove that. The company I work for has a program called viewpoint, so I never thought twice about that.

Hey, I'm going down through the list. I have done the MoveIt. The log is below.

But, when removing the Java stuff I hit a snag. Some of my components in add/remove programs are missing the option to remove them. I run into this alot on this computer. I think a tumble down the stairs may fix it, and that is on my list of things to try.

At this point, I can't remove the following:

J2SE Runtime Environment 5.0 Update 6
Java 2 Runtime Environment, SE v1.4.2_03
Java™ 6 Update 2

In the past for work stuff, I have had to manually delete the files and hack the registry to remove entries.

Please advise, as I don't think I should go further until I hear from you.

Here is the MoveIt log.

Thanks a TON for your help and patience.

FreshIO service deleted successfully.
Jukebox3 service deleted successfully.
< HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\\NoMSAppLogo5ChannelNotify >
Registry value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\\NoMSAppLogo5ChannelNotify deleted successfully.
< HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\\NoWindowsUpdate >
Registry value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\\NoWindowsUpdate deleted successfully.
< HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\\NoWindowsUpdate >
Registry value HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\\NoWindowsUpdate deleted successfully.
C:\Documents and Settings\sw185041\Application Data\Sun\Java\Deployment\cache\6.0\22\10453ed6-687f686f moved successfully.
C:\Documents and Settings\sw185041\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-3ad601a5-7d6dc4b1.zip moved successfully.

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08102008_105109

#8 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:06:51 PM

Posted 10 August 2008 - 11:57 AM

Hello, woodyatwork.

Alright... we'll remove some of those bits manually.

1. Launch Notepad, and copy/paste the contents of the quote box below into a new Notepad file. Save it with file name options.txt and save as file type: All files to your desktop.

RegSearch Options File

[Search]
Java
[Exclude]

[Options]
Filter=KVDLUI


2. Download Registry Search to your desktop.
  • Right-click on the compressed RegSearch folder, and choose Extract All. In the box that pops open, click Next, then Next again, and then Finish. You now have another RegSearch folder on your desktop.
  • Open the new folder, and double click on regsearch.exe.
  • Click Import in the lower left corner and browse to the options.txt file that you just saved on your desktop. Do not choose the one in the RegSearch folder itself.
  • Click OK and Registry Search will scan your registry for the file(s). A Notepad box will open with a report, please save the report on your desktop.
Please post the RegSearch report in your next reply.

In your next reply, please include the following:
  • Regsearch's log

Billy3

Edited by Billy O'Neal, 10 August 2008 - 11:57 AM.
BBCode

Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#9 woodyatwork

woodyatwork
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:08:51 PM

Posted 10 August 2008 - 01:05 PM

Thanks again for your help and fast reply. Here is the requested information. Getting an error it is too long, so I will create 2 msgs.

Windows Registry Editor Version 5.00

; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.5.0

; Results at 8/10/2008 12:57:45 PM for strings:
; 'java'
; Strings excluded from search:
; (None)
; Search in:
; Registry Keys Registry Values Registry Data
; HKEY_LOCAL_MACHINE HKEY_USERS


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.java]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.jnlp]
"Content Type"="application/x-java-jnlp-file"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{004CE610-CCD1-11D0-A9BA-00A0C908DB5E}]
@="Configuration Object for Java"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{004CE610-CCD1-11D0-A9BA-00A0C908DB5E}\InprocServer32]
@="C:\\WINDOWS\\system32\\msjava.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03D9F3F2-B0E3-11D2-B081-006008039BF0}\InprocServer32]
@="C:\\WINDOWS\\system32\\javaprxy.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}\InstalledVersion]
"Path"="C:\\WINDOWS\\system32\\msjava.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\InprocServer32]
@="C:\\WINDOWS\\system32\\msjava.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\ProgID]
@="MSJava"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{275D9D50-5FF5-11CF-A5E1-00AA006BBF16}]
@="Remote Debug Manager for Java"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{275D9D51-5FF5-11CF-A5E1-00AA006BBF16}]
@="Private Debug Manager for Java"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3050F3B2-98B5-11CF-BB82-00AA00BDCE0B}]
@="Microsoft HTML Javascript Pluggable Protocol"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3EFB1800-C2A1-11CF-960C-0080C7C2BA87}]
@="Execute Object for Java"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3EFB1800-C2A1-11CF-960C-0080C7C2BA87}\InprocServer32]
@="C:\\WINDOWS\\system32\\msjava.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5852F5ED-8BF4-11D4-A245-0080C6F74284}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\wsdetect.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5852F5ED-8BF4-11D4-A245-0080C6F74284}\ProgID]
@="JavaWebStart.isInstalled.1.6.0.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5852F5ED-8BF4-11D4-A245-0080C6F74284}\VersionIndependentProgID]
@="JavaWebStart.isInstalled"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
@="Java Plug-in 1.6.0_02"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\npjpi160_02.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E26BFC1-AFD6-11CF-BFFC-00AA003CFDFC}]
@="Helper Object for Java"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AC680B41-CDA0-11D1-A936-0080C7C575C0}]
@="Module Manager for Java"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AC680B41-CDA0-11D1-A936-0080C7C575C0}\InprocServer32]
@="C:\\WINDOWS\\system32\\msjava.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B98AC5E0-DE20-11d1-A7CE-0000F81E8509}]
@="Java Class: com.ms.wfc.html.DhModule"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B98AC5E0-DE20-11d1-A7CE-0000F81E8509}\InprocServer32]
@="C:\\WINDOWS\\system32\\msjava.dll"
"JavaClass"="com.ms.wfc.html.DhModule"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BC5F0300-F7BC-11d0-B9ED-40A708C10000}\InprocServer32]
@="MSJAVA.DLL"
"JavaClass"="com.ms.directX.DxSecurity"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-FFFF-ABCDEFFEDCBA}]
@="Java Plug-in"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-FFFF-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_03\\bin\\ssv.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_03"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\j2re1.4.2_03\\bin\\npjpi142_03.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_03 <applet> redirector"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\j2re1.4.2_03\\bin\\npjpi142_03.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-FFFF-ABCDEFFEDCBA}]
@="Java Plug-in"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-FFFF-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_06"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\npjpi150_06.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_06 <applet> redirector"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\npjpi150_06.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_06"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\npjpi150_06.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-FFFF-ABCDEFFEDCBA}]
@="Java Plug-in"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-FFFF-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}]
@="Java Plug-in 1.6.0_02"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\npjpi160_02.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBB}]
@="Java Plug-in 1.6.0_02"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\npjpi160_02.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}]
@="Java Plug-in 1.6.0_02"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\npjpi160_02.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-FFFF-ABCDEFFEDCBA}]
@="Java Plug-in"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-FFFF-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}]
@="Java Plug-in 1.6.0_02"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\npjpi160_02.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2029F40-8AB3-11CF-85FB-00401C608501}\InProcServer32]
@="C:\\WINDOWS\\system32\\javaprxy.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2073C44-AB4F-11D0-A732-00A0C9082637}]
@="Java Package Manager"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2073C44-AB4F-11D0-A732-00A0C9082637}\InprocServer32]
@="C:\\WINDOWS\\system32\\msjava.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB57B100-853B-11D0-AF95-0080C71F7993}]
@="java:"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB57B100-853B-11D0-AF95-0080C71F7993}\InprocServer32]
@="C:\\WINDOWS\\system32\\msjava.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB57B100-853B-11D0-AF95-0080C71F7993}\ProgID]
@="java"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DF3D9C23-AB4E-11D0-A732-00A0C9082637}\InprocServer32]
@="C:\\WINDOWS\\system32\\msjava.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FC7D9F01-3F9E-11D3-93C0-00C04F72DAF7}]
@="SignedJavaScript Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FC7D9F01-3F9E-11D3-93C0-00C04F72DAF7}\ProgID]
@="\"SignedJavaScript\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFD709F0-AF39-11D2-B854-0000F81E8872}]
@="Java Class: com.ms.wfc.html.DhComponentWrapper$DhInnerSafeControl"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFD709F0-AF39-11D2-B854-0000F81E8872}\InprocServer32]
@="msjava.dll"
"JavaClass"="com.ms.wfc.html.DhComponentWrapper$DhInnerSafeControl"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DhModule]
@="Java Class: com.ms.wfc.html.DhModule"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\49315D0E54D1A0646BD283B34C8F3B53]
"QuickTimeForJava"="QuickTimeEssentials"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\8A0F841731866D117AB7000B0D410203]
"ProductName"="Java 2 Runtime Environment, SE v1.4.2_03"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\8A0F841731866D117AB7000B0D410203\SourceList]
"PackageName"="Java 2 Runtime Environment, SE v1.4.2_03.msi"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610002]
"ProductName"="Java™ 6 Update 2"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610002\SourceList]
; Contents of value:
; u;1;http://javadl.sun.com/webapps/download/GetFile/1.6.0_02-b06/windows-i586/
"LastUsedSource"=hex(2):75,00,3b,00,31,00,3b,00,68,00,74,00,74,00,70,00,3a,00,\
2f,00,2f,00,6a,00,61,00,76,00,61,00,64,00,6c,00,2e,00,73,00,75,00,6e,00,2e,\
00,63,00,6f,00,6d,00,2f,00,77,00,65,00,62,00,61,00,70,00,70,00,73,00,2f,00,\
64,00,6f,00,77,00,6e,00,6c,00,6f,00,61,00,64,00,2f,00,47,00,65,00,74,00,46,\
00,69,00,6c,00,65,00,2f,00,31,00,2e,00,36,00,2e,00,30,00,5f,00,30,00,32,00,\
2d,00,62,00,30,00,36,00,2f,00,77,00,69,00,6e,00,64,00,6f,00,77,00,73,00,2d,\
00,69,00,35,00,38,00,36,00,2f,00,00,00

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610002\SourceList\URL]
; Contents of value:
; http://javadl.sun.com/webapps/download/Get...6/windows-i586/
"1"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,6a,00,61,00,76,00,61,00,\
64,00,6c,00,2e,00,73,00,75,00,6e,00,2e,00,63,00,6f,00,6d,00,2f,00,77,00,65,\
00,62,00,61,00,70,00,70,00,73,00,2f,00,64,00,6f,00,77,00,6e,00,6c,00,6f,00,\
61,00,64,00,2f,00,47,00,65,00,74,00,46,00,69,00,6c,00,65,00,2f,00,31,00,2e,\
00,36,00,2e,00,30,00,5f,00,30,00,32,00,2d,00,62,00,30,00,36,00,2f,00,77,00,\
69,00,6e,00,64,00,6f,00,77,00,73,00,2d,00,69,00,35,00,38,00,36,00,2f,00,00,\
00

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{275D9DC0-5FF5-11CF-A5E1-00AA006BBF16}]
@="IJavaDebugManager"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{65E432A6-ABCD-11D0-B83F-00A0244A1DE2}]
@="IJavaLEDebugManager"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CB33C082-16E6-11D0-ACBB-00401C608501}]
@="IJavaEnumLINEINFO"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CB33C083-16E6-11D0-ACBB-00401C608501}]
@="IJavaEnumRemoteField"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CB33C084-16E6-11D0-ACBB-00401C608501}]
@="IJavaEnumRemoteObject"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CB33C086-16E6-11D0-ACBB-00401C608501}]
@="IJavaEnumRemoteBooleanValue"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CB33C087-16E6-11D0-ACBB-00401C608501}]
@="IJavaEnumRemoteByteValue"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CB33C088-16E6-11D0-ACBB-00401C608501}]
@="IJavaEnumRemoteCharValue"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CB33C089-16E6-11D0-ACBB-00401C608501}]
@="IJavaEnumRemoteDoubleValue"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CB33C08A-16E6-11D0-ACBB-00401C608501}]
@="IJavaEnumRemoteFloatValue"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CB33C08B-16E6-11D0-ACBB-00401C608501}]
@="IJavaEnumRemoteIntValue"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CB33C08C-16E6-11D0-ACBB-00401C608501}]
@="IJavaEnumRemoteLongValue"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CB33C08D-16E6-11D0-ACBB-00401C608501}]
@="IJavaEnumRemoteShortValue"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CB33C08E-16E6-11D0-ACBB-00401C608501}]
@="IJavaEnumRemoteThreadGroup"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CB33C08F-16E6-11D0-ACBB-00401C608501}]
@="IJavaEnumRemoteThread"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CB33C090-16E6-11D0-ACBB-00401C608501}]
@="IJavaEnumRemoteProcess"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\jarfile\shell\open\command]
@="\"C:\\Program Files\\Java\\jre1.6.0_02\\bin\\javaw.exe\" -jar \"%1\" %*"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\java]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\java]
@="java:"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\java\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaPlugin]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaPlugin\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaPlugin.142_03]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaPlugin.142_03\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaPlugin.150_06]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaPlugin.150_06\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaPlugin.160_02]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaPlugin.160_02\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaPlugin.FamilyVersionSupport]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaPlugin.FamilyVersionSupport\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaScript]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaScript\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaScript\OLEScript]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaScript Author]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaScript Author\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaScript Author\OLEScript]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaScript1.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaScript1.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaScript1.1\OLEScript]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaScript1.1 Author]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaScript1.1 Author\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaScript1.1 Author\OLEScript]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaScript1.2]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaScript1.2\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaScript1.2\OLEScript]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaScript1.2 Author]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaScript1.2 Author\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaScript1.2 Author\OLEScript]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaScript1.3]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaScript1.3\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaScript1.3\OLEScript]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaWebStart.isInstalled]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaWebStart.isInstalled\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaWebStart.isInstalled\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaWebStart.isInstalled\CurVer]
@="JavaWebStart.isInstalled.1.6.0.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaWebStart.isInstalled.1.4.2.0]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaWebStart.isInstalled.1.4.2.0\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaWebStart.isInstalled.1.6.0.0]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JavaWebStart.isInstalled.1.6.0.0\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JNLPFile\Shell\Open\Command]
@="\"C:\\Program Files\\Java\\jre1.6.0_02\\bin\\javaws.exe\" \"%1\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-java-jnlp-file]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSJava]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSJava\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\javascript]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SignedJavaScript]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SignedJavaScript]
@="Trusted Scripts Wrapper for JavaScript"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SignedJavaScript\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SignedJavaScript\OLEScript]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{5852F5E0-8BF4-11D4-A245-0080C6F74284}\1.0]
@="JavaWebStart 1.0 Type Library"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{5852F5E0-8BF4-11D4-A245-0080C6F74284}\1.0\0\win32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\wsdetect.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{5852F5E0-8BF4-11D4-A245-0080C6F74284}\1.0\HELPDIR]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Clients\JavaVM]

[HKEY_LOCAL_MACHINE\SOFTWARE\Clients\JavaVM\MSJavaVM]

[HKEY_LOCAL_MACHINE\SOFTWARE\Clients\JavaVM\MSJavaVM\InstallInfo]

[HKEY_LOCAL_MACHINE\SOFTWARE\Clients\JavaVM\MSJavaVM\InstallInfo]
; Contents of value:
; %systemroot%\system32\msjava.dll
"VerifyFile"=hex(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,00,6f,\
00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
6d,00,73,00,6a,00,61,00,76,00,61,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft]

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Plug-in]

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Plug-in\1.4.2_03]

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Plug-in\1.4.2_03]
"JavaHome"="C:\\Program Files\\Java\\j2re1.4.2_03"
"UseJava2IExplorer"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Plug-in\1.5.0_06]

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Plug-in\1.5.0_06]
"JavaHome"="C:\\Program Files\\Java\\jre1.5.0_06"
"UseJava2IExplorer"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Plug-in\1.6.0_02]

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Plug-in\1.6.0_02]
"JavaHome"="C:\\Program Files\\Java\\jre1.6.0_02"
"UseJava2IExplorer"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Runtime Environment]

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Runtime Environment]
"BrowserJavaVersion"="1.6.0_02"

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Runtime Environment\1.4]

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Runtime Environment\1.4]
"JavaHome"="C:\\Program Files\\Java\\j2re1.4.2_03"
"RuntimeLib"="C:\\Program Files\\Java\\j2re1.4.2_03\\bin\\client\\jvm.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Runtime Environment\1.4.2_03]

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Runtime Environment\1.4.2_03]
"JavaHome"="C:\\Program Files\\Java\\j2re1.4.2_03"
"RuntimeLib"="C:\\Program Files\\Java\\j2re1.4.2_03\\bin\\client\\jvm.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Runtime Environment\1.5]

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Runtime Environment\1.5]
"JavaHome"="C:\\Program Files\\Java\\jre1.5.0_06"
"RuntimeLib"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\client\\jvm.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Runtime Environment\1.5.0_06]

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Runtime Environment\1.5.0_06]
"JavaHome"="C:\\Program Files\\Java\\jre1.5.0_06"
"RuntimeLib"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\client\\jvm.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Runtime Environment\1.6]

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Runtime Environment\1.6]
"JavaHome"="C:\\Program Files\\Java\\jre1.6.0_02"
"RuntimeLib"="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\client\\jvm.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_02]

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_02]
"JavaHome"="C:\\Program Files\\Java\\jre1.6.0_02"
"RuntimeLib"="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\client\\jvm.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_02\MSI]

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_02\MSI]
"INSTALLDIR"="C:\\Program Files\\Java\\jre1.6.0_02\\"
"JAVAUPDATE"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Update]

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Update\Policy]

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Update\Policy]
"EnableJavaUpdate"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Web Start]

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Web Start\1.0.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Web Start\1.0.1]
"Home"="C:\\Program Files\\Java\\jre1.6.0_02\\bin"

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Web Start\1.0.1_02]

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Web Start\1.0.1_02]
"Home"="C:\\Program Files\\Java\\jre1.6.0_02\\bin"

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Web Start\1.0.1_03]

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Web Start\1.0.1_03]
"Home"="C:\\Program Files\\Java\\jre1.6.0_02\\bin"

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Web Start\1.0.1_04]

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Web Start\1.0.1_04]
"Home"="C:\\Program Files\\Java\\jre1.6.0_02\\bin"

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Web Start\1.2]

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Web Start\1.2]
"Home"="C:\\Program Files\\Java\\jre1.6.0_02\\bin"

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Web Start\1.2.0_01]

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Web Start\1.2.0_01]
"Home"="C:\\Program Files\\Java\\jre1.6.0_02\\bin"

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Web Start\1.4.2_03]

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Web Start\1.4.2_03]
"Home"="C:\\Program Files\\Java\\j2re1.4.2_03\\javaws"

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Web Start\1.5.0_06]

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Web Start\1.5.0_06]
"Home"="C:\\Program Files\\Java\\jre1.5.0_06\\bin"

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Web Start\1.6.0_02]

[HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Web Start\1.6.0_02]
"Home"="C:\\Program Files\\Java\\jre1.6.0_02\\bin"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}]
"ComponentID"="JAVAVM"
"KeyFileName"="C:\\WINDOWS\\system32\\msjava.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}]
@="Dynamic HTML Data Binding for Java"
"ComponentID"="TridataJava"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{4f216970-c90c-11d1-b5c7-0000f8051515}]
@="DirectAnimation Java Classes"
"ComponentID"="DAJava"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ASP.NET\2.0.50727.0]
"SupportedExts"=".asax,1,.ascx,1,.ashx,0,.asmx,0,.aspx,0,.axd,0,.vsdisco,0,.rem,0,.soap,0,.config,1,.cs,1,.csproj,1,.vb,1,.vbproj,1,.webinfo,1,.licx,1,.resx,1,.resources,1,.master,1,.skin,1,.compiled,1,.browser,1,.mdb,1,.jsl,1,.vjsproj,1,.sitemap,1,.msgx,0,.ad,1,.dd,1,.ldd,1,.sd,1,.cd,1,.adprototype,1,.lddprototype,1,.sdm,1,.sdmDocument,1,.ldb,1,.svc,0,.mdf,1,.ldf,1,.java,1,.exclude,1,.refresh,1,"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java]
@="Microsoft XML Parser for Java"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\Contains]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\Contains\Java]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\DownloadInformation]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\DownloadInformation]
"CODEBASE"="file://C:\\WINDOWS\\Java\\classes\\xmldso.cab"
"OSD"="C:\\WINDOWS\\Downloaded Program Files\\Microsoft XML Parser for Java.osd"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\InstalledVersion]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
@="Java Runtime Environment 1.6.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\DownloadInformation]
"CODEBASE"="http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}]
@="Java Runtime Environment 1.4.2"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\DownloadInformation]
"CODEBASE"="http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}]
@="Java Runtime Environment 1.5.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\DownloadInformation]
"CODEBASE"="http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}]
@="Java Runtime Environment 1.6.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\DownloadInformation]
"CODEBASE"="http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}]
@="Java Runtime Environment 1.6.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\DownloadInformation]
"CODEBASE"="http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\activeX]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\activeX]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\applet]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\applet]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\awt]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\awt]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\awt\image]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\awt\image]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\awt\peer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\awt\peer]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\beans]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\beans]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\beans\infos]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\beans\infos]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\com]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\com]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\debug]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\debug]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\directX]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\directX]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\4XJFJ1NF.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\B5N3Z33N.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\dll]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\dll]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\fx]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\fx]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\io]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\io]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\io\clientstorage]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\io\clientstorage]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\io\console]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\io\console]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\jdbc]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\jdbc\odbc]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\jdbc\odbc]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\IFB53LRN.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\YNLJ3LR5.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\lang]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\lang]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\license]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\license]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\net]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\net\wininet]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\net\wininet]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\net\wininet\http]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\net\wininet\http]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\net\www]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\net\www\protocol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\net\www\protocol\loaderresource]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\net\www\protocol\loaderresource]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\net\www\protocol\systemresource]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\net\www\protocol\systemresource]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\object]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\object]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\object\dragdrop]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\object\dragdrop]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\osp]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\osp]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\AKL79FZ3.ZIP"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\packagemanager]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\packagemanager]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\security]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\security]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\security\auditing]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\security\auditing]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\security\management]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\security\management]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\security\management\ui]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\security\management\ui]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\security\permissions]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\security\permissions]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\ui]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\ui]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\ui\event]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\ui\event]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\ui\icons]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\ui\icons]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\ui\resource]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\ui\resource]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\ui\windowmanager]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\ui\windowmanager]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\util]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\util]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\util\cab]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\util\cab]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\util\ini]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\util\ini]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\util\InputMethod]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\util\InputMethod]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\util\xml]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\util\xml]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\util\zip]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\util\zip]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\vm]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\vm]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\vm\loader]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\vm\loader]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\vm\wfc]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\vm\wfc]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\app]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\app]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\NFHZLZL3.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\D75ZJTBZ.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\ax]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\ax]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\NFHZLZL3.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\D75ZJTBZ.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\core]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\core]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\NFHZLZL3.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\D75ZJTBZ.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\data]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\data]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\NFHZLZL3.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\D75ZJTBZ.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\data\adodb]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\data\adodb]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\NFHZLZL3.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\D75ZJTBZ.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\data\dsl]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\data\dsl]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\NFHZLZL3.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\D75ZJTBZ.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\data\rds]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\data\rds]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\NFHZLZL3.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\D75ZJTBZ.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\data\ui]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\data\ui]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\NFHZLZL3.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\D75ZJTBZ.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\html]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\html]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\NFHZLZL3.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\D75ZJTBZ.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\html\event]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\html\event]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\NFHZLZL3.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\D75ZJTBZ.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\html\om]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\html\om]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\NFHZLZL3.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\D75ZJTBZ.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\html\om\shdocvw]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\html\om\shdocvw]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\NFHZLZL3.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\D75ZJTBZ.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\html\om\shdocvw\WebBrowser]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\html\om\shdocvw\WebBrowser]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\NFHZLZL3.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\D75ZJTBZ.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\io]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\io]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\NFHZLZL3.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\D75ZJTBZ.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\ole32]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\ole32]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\NFHZLZL3.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\D75ZJTBZ.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\ui]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\ui]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\NFHZLZL3.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\D75ZJTBZ.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\util]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\util]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\NFHZLZL3.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\D75ZJTBZ.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\win32]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\wfc\win32]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\NFHZLZL3.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\D75ZJTBZ.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\win32]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\win32]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\xml]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\xml\dso]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\xml\dso]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\NDNT39JX.ZIP"
"Capabilities"="C:\\WINDOWS\\JAVA\\Packages\\Data\\ISQ1VHFJ.DAT"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\3PZB7L3J.DAT"
"DistributionUnit"="Microsoft XML Parser for Java"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\xml\om]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\xml\om]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\NDNT39JX.ZIP"
"Capabilities"="C:\\WINDOWS\\JAVA\\Packages\\Data\\ISQ1VHFJ.DAT"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\3PZB7L3J.DAT"
"DistributionUnit"="Microsoft XML Parser for Java"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\xml\parser]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\xml\parser]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\NDNT39JX.ZIP"
"Capabilities"="C:\\WINDOWS\\JAVA\\Packages\\Data\\ISQ1VHFJ.DAT"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\3PZB7L3J.DAT"
"DistributionUnit"="Microsoft XML Parser for Java"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\xml\util]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\com\ms\xml\util]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\NDNT39JX.ZIP"
"Capabilities"="C:\\WINDOWS\\JAVA\\Packages\\Data\\ISQ1VHFJ.DAT"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\3PZB7L3J.DAT"
"DistributionUnit"="Microsoft XML Parser for Java"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\applet]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\applet]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\awt]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\awt]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\awt\datatransfer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\awt\datatransfer]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\awt\event]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\awt\event]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\awt\image]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\awt\image]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\awt\peer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\awt\peer]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\beans]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\beans]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\io]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\io]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\lang]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\lang]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\lang\reflect]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\lang\reflect]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\math]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\math]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\net]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\net]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\security]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\security]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\security\acl]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\security\acl]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\security\interfaces]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\security\interfaces]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\sql]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\sql]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\text]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\text]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\text\resources]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\text\resources]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\util]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\util]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\util\zip]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\java\util\zip]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\netscape]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\netscape\javascript]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\netscape\javascript]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\audio]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\audio]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\awt]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\awt\image]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\awt\image]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\beans]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\beans\editors]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\beans\editors]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\beans\infos]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\beans\infos]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\io]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\io]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\misc]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\misc]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\net]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\net]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\net\ftp]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\net\ftp]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\net\nntp]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\net\nntp]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\net\smtp]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\net\smtp]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\net\www]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\net\www]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\net\www\content]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\net\www\content\image]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\net\www\content\image]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\net\www\content\text]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\net\www\content\text]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\net\www\http]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\net\www\http]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\net\www\protocol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\net\www\protocol\doc]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\net\www\protocol\doc]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\net\www\protocol\file]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\net\www\protocol\file]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\net\www\protocol\ftp]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\net\www\protocol\ftp]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\net\www\protocol\http]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\net\www\protocol\http]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\DVTJ7XFP.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\Z5VRXB7P.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\security]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\security\acl]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\security\acl]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\CR57P3FB.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\7Z3LZZZ1.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\security\pkcs]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\security\pkcs]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\CR57P3FB.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\7Z3LZZZ1.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\security\provider]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\security\provider]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\CR57P3FB.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\7Z3LZZZ1.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\security\util]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\security\util]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\CR57P3FB.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\7Z3LZZZ1.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\security\x509]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\security\x509]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\CR57P3FB.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\7Z3LZZZ1.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\tools]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\tools\jar]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Global Namespace\Java Packages\sun\tools\jar]
"Path"="C:\\WINDOWS\\JAVA\\Packages\\CR57P3FB.ZIP"
"Signer"="C:\\WINDOWS\\JAVA\\Packages\\Data\\7Z3LZZZ1.DAT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{E6F795B1-F738-11D0-A72F-00A0C903B83D}]
"$DLL"="javacypt.dll"
"$Function"="JavaPolicyProvider"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{E6F795B2-F738-11D0-A72F-00A0C903B83D}]
"$DLL"="javacypt.dll"
"$Function"="JavaCheckPolicy"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\JAVA_SUN]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\JAVA_SUN]
"Text"="Java (Sun)"
"Bitmap"="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\regutils.dll,1000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\JAVA_SUN\SELECT]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\JAVA_SUN\SELECT]
"RegPath"="Software\\JavaSoft\\Java Plug-in\\1.6.0_02"
"ValueName"="UseJava2IExplorer"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\JAVA_VM]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\JAVA_VM\CONSOLE]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\JAVA_VM\CONSOLE]
"RegPoliciesPath"="SOFTWARE\\Policies\\Microsoft\\Java VM"
"Text"="Java console enabled (requires restart)"
"RegPath"="SOFTWARE\\Microsoft\\Java VM"
"ValueName"="EnableJavaConsole"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\JAVA_VM\JIT]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\JAVA_VM\JIT]
"RegPoliciesPath"="SOFTWARE\\Policies\\Microsoft\\Java VM"
"RegPath"="SOFTWARE\\Microsoft\\Java VM"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\JAVA_VM\LOGGING]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\JAVA_VM\LOGGING]
"RegPoliciesPath"="SOFTWARE\\Policies\\Microsoft\\Java VM"
"Text"="Java logging enabled"
"RegPath"="SOFTWARE\\Microsoft\\Java VM"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}]
"MenuText"="Sun Java Console"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Java VM]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Java VM]
"Classpath"="C:\\WINDOWS\\java\\classes;."
"TrustedLibsDirectory"="C:\\WINDOWS\\java\\trustlib"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Java VM\RNIModuleFlags]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Java VM\RNIModuleFlags]
; Contents of value:
; 
"mtxjava.dll"=hex:01,00,00,00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Java VM\Security]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Java VM\System Properties]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SMS\Mobile Client\Software Distribution\Execution History\System\ZZZ0027E\7f5362d8-cbed-11db-b11a-444553544200]
"_ProgramID"="Install Java Update (silent/admin)"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\javaws.exe]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\javaws.exe]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\javaws.exe"
"Path"="C:\\Program Files\\Java\\jre1.6.0_02\\bin"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\Downloaded Program Files]
"Description"="Downloaded Program Files are ActiveX controls and Java applets downloaded automatically from the Internet when you view certain pages. They are temporarily stored in the Downloaded Program Files folder on your hard disk."

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Common Files\\Java\\Update\\Base Images\\j2re1.4.2-b28\\"=""
"C:\\Program Files\\Common Files\\Java\\Update\\Base Images\\"=""
"C:\\Program Files\\Common Files\\Java\\Update\\"=""
"C:\\Program Files\\Common Files\\Java\\"=""
"C:\\Program Files\\Java\\j2re1.4.2_03\\"=""
"C:\\Program Files\\Java\\"=""
"C:\\Program Files\\Common Files\\Java\\Update\\Base Images\\j2re1.4.2-b28\\patch-j2re1.4.2_03-b02\\"=""
"C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.00\\java\\"="1"
"C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.00\\java\\lib\\applet\\"="1"
"C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.00\\java\\lib\\"="1"
"C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.00\\java\\lib\\ext\\"="1"
"C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.00\\java\\lib\\images\\"="1"
"C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.00\\java\\bin\\"=""
"C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.00\\java\\bin\\hotspot\\"=""
"C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.00\\java\\lib\\cmm\\"=""
"C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.00\\java\\lib\\fonts\\"=""
"C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.00\\java\\lib\\images\\cursors\\"=""
"C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.00\\java\\lib\\security\\"=""
"C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.00\\lib\\java\\"=""
"C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.00\\tcl\\lib\\tcllib1.3\\javascript\\"=""
"C:\\Program Files\\NCR\\Tdat\\TDGSS\\06.01.00.00\\lib\\java\\"=""
"C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.12\\java\\"="1"
"C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.12\\java\\lib\\applet\\"="1"
"C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.12\\java\\lib\\"="1"
"C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.12\\java\\lib\\ext\\"="1"
"C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.12\\java\\lib\\images\\"="1"
"C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.12\\java\\bin\\"=""
"C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.12\\java\\bin\\hotspot\\"=""
"C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.12\\java\\lib\\cmm\\"=""
"C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.12\\java\\lib\\fonts\\"=""
"C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.12\\java\\lib\\images\\cursors\\"=""
"C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.12\\java\\lib\\security\\"=""
"C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.12\\lib\\java\\"=""
"C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.12\\tcl\\lib\\tcllib1.3\\javascript\\"=""
"C:\\Program Files\\NCR\\Tdat\\TDGSS\\06.01.00.12\\lib\\java\\"=""
"C:\\Program Files\\NCR\\Teradata GSS\\nt-i386\\06.01.00.00\\lib\\java\\"=""
"C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 6.1\\Help\\ENU\\wwhelp\\wwhimpl\\java\\"="1"
"C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 6.1\\Help\\ENU\\wwhelp\\wwhimpl\\java\\html\\"=""
"C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 6.1\\Help\\ENU\\wwhelp\\wwhimpl\\java\\scripts\\"=""
"C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 6.1\\Help\\ENU\\wwhelp\\wwhimpl\\java\\private\\"=""
"C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 6.1\\Help\\ENU\\wwhdata\\java\\"=""
"C:\\Program Files\\NCR\\Teradata Visual Explain 3.3\\Help\\enu\\wwhelp\\wwhimpl\\java\\"="1"
"C:\\Program Files\\NCR\\Teradata Visual Explain 3.3\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\"=""
"C:\\Program Files\\NCR\\Teradata Visual Explain 3.3\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\"=""
"C:\\Program Files\\NCR\\Teradata Visual Explain 3.3\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\"=""
"C:\\Program Files\\NCR\\Teradata Visual Explain 3.3\\Help\\enu\\wwhdata\\java\\"=""
"C:\\Program Files\\NCR\\Teradata System Emulation Tool 2.3\\Help\\enu\\wwhelp\\wwhimpl\\java\\"="1"
"C:\\Program Files\\NCR\\Teradata System Emulation Tool 2.3\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\"=""
"C:\\Program Files\\NCR\\Teradata System Emulation Tool 2.3\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\"=""
"C:\\Program Files\\NCR\\Teradata System Emulation Tool 2.3\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\"=""
"C:\\Program Files\\NCR\\Teradata System Emulation Tool 2.3\\Help\\enu\\wwhdata\\java\\"=""
"C:\\Program Files\\NCR\\Teradata Index Wizard 1.3\\Help\\enu\\wwhelp\\wwhimpl\\java\\"="1"
"C:\\Program Files\\NCR\\Teradata Index Wizard 1.3\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\"=""
"C:\\Program Files\\NCR\\Teradata Index Wizard 1.3\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\"=""
"C:\\Program Files\\NCR\\Teradata Index Wizard 1.3\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\"=""
"C:\\Program Files\\NCR\\Teradata Index Wizard 1.3\\Help\\enu\\wwhdata\\java\\"=""
"C:\\Program Files\\NCR\\Teradata Statistics Wizard 1.3\\Help\\ENU\\wwhelp\\wwhimpl\\java\\"="1"
"C:\\Program Files\\NCR\\Teradata Statistics Wizard 1.3\\Help\\ENU\\wwhelp\\wwhimpl\\java\\html\\"=""
"C:\\Program Files\\NCR\\Teradata Statistics Wizard 1.3\\Help\\ENU\\wwhelp\\wwhimpl\\java\\scripts\\"=""
"C:\\Program Files\\NCR\\Teradata Statistics Wizard 1.3\\Help\\ENU\\wwhelp\\wwhimpl\\java\\private\\"=""
"C:\\Program Files\\NCR\\Teradata Statistics Wizard 1.3\\Help\\ENU\\wwhdata\\java\\"=""
"C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\Help\\enu\\wwhelp\\wwhimpl\\java\\"="1"
"C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\"=""
"C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\"=""
"C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\"=""
"C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\Help\\enu\\wwhdata\\java\\"=""
"C:\\Program Files\\Common Files\\Java\\Update\\Base Images\\jre1.5.0.b64\\"=""
"C:\\Program Files\\Common Files\\Java\\Update\\Base Images\\jre1.5.0.b64\\patch-jre1.5.0_06.b05\\"=""
"C:\\Program Files\\Java\\jre1.5.0_06\\"=""
"C:\\Program Files\\Java\\jre1.5.0_06\\bin\\"=""
"C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\Help\\enu\\wwhelp\\wwhimpl\\java\\"="1"
"C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\"=""
"C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\"=""
"C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\"=""
"C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\Help\\enu\\wwhdata\\java\\"=""
"C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\"="1"
"C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\HTML\\ENU\\wwhdata\\java\\"=""
"C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\html\\"=""
"C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\private\\"=""
"C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\scripts\\"=""
"C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\"="1"
"C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\HTML\\ENU\\wwhdata\\java\\"=""
"C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\html\\"=""
"C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\private\\"=""
"C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\scripts\\"=""
"C:\\Program Files\\Common Files\\Java\\Update\\Base Images\\jre1.6.0.b105\\"=""
"C:\\Program Files\\Common Files\\Java\\Update\\Base Images\\jre1.6.0.b105\\patch-jre1.6.0_02.b06\\"=""
"C:\\Program Files\\Java\\jre1.6.0_02\\"=""
"C:\\Program Files\\Java\\jre1.6.0_02\\bin\\"=""
"C:\\Program Files\\NCR\\Teradata GSS\\nt-i386\\12.00.00.00\\lib\\java\\"=""
"C:\\Program Files\\NCR\\Teradata Visual Explain 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\"="1"
"C:\\Program Files\\NCR\\Teradata Visual Explain 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\"=""
"C:\\Program Files\\NCR\\Teradata Visual Explain 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\"=""
"C:\\Program Files\\NCR\\Teradata Visual Explain 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\"=""
"C:\\Program Files\\NCR\\Teradata Visual Explain 12.0\\Help\\enu\\wwhdata\\java\\"=""
"C:\\Program Files\\NCR\\Teradata System Emulation Tool 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\"="1"
"C:\\Program Files\\NCR\\Teradata System Emulation Tool 12.0\\Help\\enu\\wwhdata\\java\\"=""
"C:\\Program Files\\NCR\\Teradata System Emulation Tool 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\"=""
"C:\\Program Files\\NCR\\Teradata System Emulation Tool 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\"=""
"C:\\Program Files\\NCR\\Teradata System Emulation Tool 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\"=""
"C:\\Program Files\\NCR\\Teradata Index Wizard 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\"="1"
"C:\\Program Files\\NCR\\Teradata Index Wizard 12.0\\Help\\enu\\wwhdata\\java\\"=""
"C:\\Program Files\\NCR\\Teradata Index Wizard 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\"=""
"C:\\Program Files\\NCR\\Teradata Index Wizard 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\"=""
"C:\\Program Files\\NCR\\Teradata Index Wizard 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\"=""
"C:\\Program Files\\NCR\\Teradata Statistics Wizard 12.0\\Help\\ENU\\wwhelp\\wwhimpl\\java\\"="1"
"C:\\Program Files\\NCR\\Teradata Statistics Wizard 12.0\\Help\\ENU\\wwhdata\\java\\"=""
"C:\\Program Files\\NCR\\Teradata Statistics Wizard 12.0\\Help\\ENU\\wwhelp\\wwhimpl\\java\\html\\"=""
"C:\\Program Files\\NCR\\Teradata Statistics Wizard 12.0\\Help\\ENU\\wwhelp\\wwhimpl\\java\\private\\"=""
"C:\\Program Files\\NCR\\Teradata Statistics Wizard 12.0\\Help\\ENU\\wwhelp\\wwhimpl\\java\\scripts\\"=""
"C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 12.0\\Help\\ENU\\wwhelp\\wwhimpl\\java\\"="1"
"C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 12.0\\Help\\ENU\\Output\\wwhelp\\wwhimpl\\java\\"="1"
"C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 12.0\\Help\\ENU\\wwhdata\\java\\"=""
"C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 12.0\\Help\\ENU\\wwhelp\\wwhimpl\\java\\private\\"=""
"C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 12.0\\Help\\ENU\\wwhelp\\wwhimpl\\java\\scripts\\"=""
"C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 12.0\\Help\\ENU\\wwhelp\\wwhimpl\\java\\html\\"=""
"C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 12.0\\Help\\ENU\\Output\\wwhelp\\wwhimpl\\java\\html\\"=""
"C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 12.0\\Help\\ENU\\Output\\wwhelp\\wwhimpl\\java\\scripts\\"=""
"C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 12.0\\Help\\ENU\\Output\\wwhelp\\wwhimpl\\java\\private\\"=""
"C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 12.0\\Help\\ENU\\Output\\wwhdata\\java\\"=""
"C:\\Program Files\\NCR\\Teradata Query Scheduler 12.0\\Help\\ENU\\wwhelp\\wwhimpl\\java\\"="1"
"C:\\Program Files\\NCR\\Teradata Query Scheduler 12.0\\Help\\ENU\\Output\\wwhelp\\wwhimpl\\java\\"="1"
"C:\\Program Files\\NCR\\Teradata Query Scheduler 12.0\\Help\\ENU\\wwhdata\\java\\"=""
"C:\\Program Files\\NCR\\Teradata Query Scheduler 12.0\\Help\\ENU\\wwhelp\\wwhimpl\\java\\html\\"=""
"C:\\Program Files\\NCR\\Teradata Query Scheduler 12.0\\Help\\ENU\\wwhelp\\wwhimpl\\java\\private\\"=""
"C:\\Program Files\\NCR\\Teradata Query Scheduler 12.0\\Help\\ENU\\wwhelp\\wwhimpl\\java\\scripts\\"=""
"C:\\Program Files\\NCR\\Teradata Query Scheduler 12.0\\Help\\ENU\\Output\\wwhelp\\wwhimpl\\java\\html\\"=""
"C:\\Program Files\\NCR\\Teradata Query Scheduler 12.0\\Help\\ENU\\Output\\wwhelp\\wwhimpl\\java\\scripts\\"=""
"C:\\Program Files\\NCR\\Teradata Query Scheduler 12.0\\Help\\ENU\\Output\\wwhelp\\wwhimpl\\java\\private\\"=""
"C:\\Program Files\\NCR\\Teradata Query Scheduler 12.0\\Help\\ENU\\Output\\wwhdata\\java\\"=""
"C:\\Program Files\\NCR\\Teradata Manager 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\"="1"
"C:\\Program Files\\NCR\\Teradata Manager 12.0\\Help\\enu\\wwhdata\\java\\"=""
"C:\\Program Files\\NCR\\Teradata Manager 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\"=""
"C:\\Program Files\\NCR\\Teradata Manager 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\"=""
"C:\\Program Files\\NCR\\Teradata Manager 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\"=""
"C:\\Program Files\\NCR\\Teradata Workload Analyzer 12.0\\help\\enu\\wwhelp\\wwhimpl\\java\\"="1"
"C:\\Program Files\\NCR\\Teradata Workload Analyzer 12.0\\help\\enu\\wwhdata\\java\\"=""
"C:\\Program Files\\NCR\\Teradata Workload Analyzer 12.0\\help\\enu\\wwhelp\\wwhimpl\\java\\html\\"=""
"C:\\Program Files\\NCR\\Teradata Workload Analyzer 12.0\\help\\enu\\wwhelp\\wwhimpl\\java\\private\\"=""
"C:\\Program Files\\NCR\\Teradata Workload Analyzer 12.0\\help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\"=""
"C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\"="1"
"C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 12.0\\Help\\enu\\wwhdata\\java\\"=""
"C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\"=""
"C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\"=""
"C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\"=""
"C:\\Program Files\\NCR\\Teradata Manager 7.1\\Help\\enu\\wwhelp\\wwhimpl\\java\\"="1"
"C:\\Program Files\\NCR\\Teradata Manager 7.1\\Help\\enu\\wwhdata\\java\\"=""
"C:\\Program Files\\NCR\\Teradata Manager 7.1\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\"=""
"C:\\Program Files\\NCR\\Teradata Manager 7.1\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\"=""
"C:\\Program Files\\NCR\\Teradata Manager 7.1\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\"=""
"C:\\Program Files\\NCR\\Teradata Manager 7.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\"="1"
"C:\\Program Files\\NCR\\Teradata Manager 7.0\\Help\\enu\\wwhdata\\java\\"=""
"C:\\Program Files\\NCR\\Teradata Manager 7.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\"=""
"C:\\Program Files\\NCR\\Teradata Manager 7.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\"=""
"C:\\Program Files\\NCR\\Teradata Manager 7.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\"=""
"C:\\Program Files\\NCR\\Teradata Manager 7.2\\Help\\enu\\wwhelp\\wwhimpl\\java\\"="1"
"C:\\Program Files\\NCR\\Teradata Manager 7.2\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\"=""
"C:\\Program Files\\NCR\\Teradata Manager 7.2\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\"=""
"C:\\Program Files\\NCR\\Teradata Manager 7.2\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\"=""
"C:\\Program Files\\NCR\\Teradata Manager 7.2\\Help\\enu\\wwhdata\\java\\"=""
"C:\\Program Files\\Adobe\\Reader 8.0\\Reader\\Javascripts\\"=""
"C:\\Program Files\\Teradata\\Teradata Dynamic Workload Manager 13.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\"="1"
"C:\\Program Files\\Teradata\\Teradata Dynamic Workload Manager 13.0\\Help\\enu\\wwhdata\\java\\"=""
"C:\\Program Files\\Teradata\\Teradata Dynamic Workload Manager 13.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\"=""
"C:\\Program Files\\Teradata\\Teradata Dynamic Workload Manager 13.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\"=""
"C:\\Program Files\\Teradata\\Teradata Dynamic Workload Manager 13.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\"=""
"C:\\Program Files\\Teradata\\Teradata Manager 13.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\"="1"
"C:\\Program Files\\Teradata\\Teradata Manager 13.0\\Help\\enu\\wwhdata\\java\\"=""
"C:\\Program Files\\Teradata\\Teradata Manager 13.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\"=""
"C:\\Program Files\\Teradata\\Teradata Manager 13.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\"=""
"C:\\Program Files\\Teradata\\Teradata Manager 13.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\"=""
"C:\\Program Files\\Teradata\\Teradata Workload Analyzer 13.0\\help\\enu\\wwhelp\\wwhimpl\\java\\"="1"
"C:\\Program Files\\Teradata\\Teradata Workload Analyzer 13.0\\help\\enu\\wwhdata\\java\\"=""
"C:\\Program Files\\Teradata\\Teradata Workload Analyzer 13.0\\help\\enu\\wwhelp\\wwhimpl\\java\\html\\"=""
"C:\\Program Files\\Teradata\\Teradata Workload Analyzer 13.0\\help\\enu\\wwhelp\\wwhimpl\\java\\private\\"=""
"C:\\Program Files\\Teradata\\Teradata Workload Analyzer 13.0\\help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\"=""
"C:\\Program Files\\Teradata\\Client\\13.0\\ODBC Driver for Teradata\\Help\\wwhelp\\wwhimpl\\java\\"="1"
"C:\\Program Files\\Teradata\\Client\\13.0\\ODBC Driver for Teradata\\Help\\wwhdata\\java\\"=""
"C:\\Program Files\\Teradata\\Client\\13.0\\ODBC Driver for Teradata\\Help\\wwhelp\\wwhimpl\\java\\html\\"=""
"C:\\Program Files\\Teradata\\Client\\13.0\\ODBC Driver for Teradata\\Help\\wwhelp\\wwhimpl\\java\\private\\"=""
"C:\\Program Files\\Teradata\\Client\\13.0\\ODBC Driver for Teradata\\Help\\wwhelp\\wwhimpl\\java\\scripts\\"=""
"C:\\Program Files\\Teradata\\Teradata GSS\\nt-i386\\13m.00.00.00\\lib\\java\\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\082C2E47E5F53954297D74D1948A27EF]
"F1C0B989CDB8FB641B22DFCCC7532AEC"="C:\\Program Files\\NCR\\NCRput\\web\\jre\\bin\\javaw.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0B9C7F4ECA1C076419DB32A74A901C38]
"6F56A51429D52A74FA4E04055C7923BF"="C:\\Program Files\\NCR\\Teradata Workload Analyzer 1.0\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0C0D9B0AA930092E096C1FA0787F575B]
"BBF3759EE80207B47988BE8292A1501F"="C:\\Program Files\\Teradata\\Teradata Dynamic Workload Manager 13.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CD6E37F8EED5D74B84FF0CC5EE74DCB]
"BE36B32E0013FB0459392FBE6FC16742"="C:\\Program Files\\NCR\\Teradata Manager 7.2\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0DE828546C8967B488AADA5A5753491E]
"BED3D6BECD315EC45A208429D093A610"="C:\\Program Files\\NCR\\Teradata System Emulation Tool 2.3\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\12365AB3166636F4594568EE61FAAAAE]
"0E3868DA15CA5444C91621998E7E1676"="C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.12\\java\\lib\\cmm\\CIEXYZ.pf"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\13BC4517151A0D948873FE2B1A7C4BA5]
"6F56A51429D52A74FA4E04055C7923BF"="C:\\Program Files\\NCR\\Teradata Workload Analyzer 1.0\\HTML\\ENU\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\13E01F3357813EB4BBE30D50AEF20490]
"C463911B6C5A31249B8E3FF29DB0AE7D"="C:\\Program Files\\NCR\\Teradata Query Scheduler 12.0\\Help\\ENU\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\14537C9D034B0F7409301BB4C9324DE9]
"0667E56E71DCE234A9B67BCDBE2C239C"="C:\\Program Files\\NCR\\Teradata Workload Analyzer 1.1\\help\\enu\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\14BCFF41AA91B0BB81E2F41B87B6D30E]
"8B4098AB1B5BEF742A34FEBA0AE6CB65"="C:\\Program Files\\Teradata\\Client\\13.0\\ODBC Driver for Teradata\\Help\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\155CCB773E069DE47B438F5F04E6980F]
"0E3868DA15CA5444C91621998E7E1676"="C:\\Program Files\\NCR\\Tdat\\TDGSS\\06.01.00.12\\lib\\java\\Login.config"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\156AB2EB900079344BD509C687DD8A5F]
"AFEC3B47B91BA3944B4C90A328DB3AD2"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\HTML\\ENU\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\174F24D2636B04F4A902D44B680DF9BE]
"0667E56E71DCE234A9B67BCDBE2C239C"="C:\\Program Files\\NCR\\Teradata Workload Analyzer 1.1\\help\\enu\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19C189631E56FEE42B3D5FE56CE60009]
"8A3D68ECA95F3464C8F01B2FB2324216"="C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.00\\java\\bin\\ActPanel.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1AF78F443A927574C86EAAB5F0CC8DC1]
"963F990C72DC5A14A8FE075EDCA707CB"="C:\\Program Files\\NCR\\Teradata Index Wizard 1.3\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1D2660106419AD245AF1291BF0E577E9]
"0667E56E71DCE234A9B67BCDBE2C239C"="C:\\Program Files\\NCR\\Teradata Workload Analyzer 1.1\\help\\enu\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1EA905510EA44BF40B90AD3D74AB1198]
"AA2AB84896CD8B6469B0D25E75503E7C"="C:\\Program Files\\NCR\\Teradata Statistics Wizard 1.3\\Help\\ENU\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F76DB659558F2A4683EFC3ADD3CD4B9]
"9DB735DF61597CF4FB7DA1189C05B388"="C:\\Program Files\\NCR\\Teradata Manager 7.0\\Help\\enu\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\203E21193A4AFFB419CC75AA1D738B5F]
"963F990C72DC5A14A8FE075EDCA707CB"="C:\\Program Files\\NCR\\Teradata Index Wizard 1.3\\Help\\enu\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2086125D67F9C2A418B2A38587B74A8A]
"C463911B6C5A31249B8E3FF29DB0AE7D"="C:\\Program Files\\NCR\\Teradata Query Scheduler 12.0\\Help\\ENU\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\23385D1C4D4AE4841A7EA477FAD19E64]
"8A3D68ECA95F3464C8F01B2FB2324216"="C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.00\\java\\lib\\ext\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\23B05123E6D18D74FA6711404FCAC1B8]
"8A0F842331866D117AB7000B0D510006"="C:\\Program Files\\Common Files\\Java\\Update\\Base Images\\jre1.5.0.b64\\patch-jre1.5.0_06.b05\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\23B06123E6D18D74FA6711404FCAC1B8]
"8A0F842331866D117AB7000B0D610002"="C:\\Program Files\\Common Files\\Java\\Update\\Base Images\\jre1.6.0.b105\\patch-jre1.6.0_02.b06\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\23BC96BDE6D18D74FA6711404FCAC1B8]
"8A0F841731866D117AB7000B0D410203"="C:\\Program Files\\Common Files\\Java\\Update\\Base Images\\j2re1.4.2-b28\\patch-j2re1.4.2_03-b02\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\245691AFFB24EF44EA5261B94243EBED]
"AFEC3B47B91BA3944B4C90A328DB3AD2"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2706347CC3C04CB43B06B851E0A6719D]
"F1C0B989CDB8FB641B22DFCCC7532AEC"="C:\\Program Files\\NCR\\NCRput\\web\\jre\\bin\\NPJava11.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2A592A7D234DF3140A9E68598487C326]
"E2A554CBD3083FC45829BB4B7FA31CCF"="C:\\Program Files\\NCR\\Teradata GSS\\nt-i386\\06.01.00.00\\lib\\java\\Login.config"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2A90B20A3C2776D48B83C4AD44639464]
"C463911B6C5A31249B8E3FF29DB0AE7D"="C:\\Program Files\\NCR\\Teradata Query Scheduler 12.0\\Help\\ENU\\Output\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2ECB3D7C9B73E5741B140CCED67E4D2E]
"C8704B98C58050C42B5FED43BBB19218"="C:\\Program Files\\NCR\\Teradata Manager 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2F4CCA73B769BC3498368978B141A9CC]
"D62B031B938208A489F1F2A4656FCBBD"="C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 12.0\\Help\\ENU\\Output\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2F6A0FB43B995D041B09239BA90607D5]
"6F56A51429D52A74FA4E04055C7923BF"="C:\\Program Files\\NCR\\Teradata Workload Analyzer 1.0\\help\\enu\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2FCC7362A1E0E6143AD4AFFF68FCC806]
"8D8EFA9EE993FEB48BDF05F65372A890"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\Help\\enu\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\304A844D1703F38478EA568B2BA80052]
"072F0661C4E441A4CB3AC068461DB915"="C:\\Program Files\\NCR\\Teradata Index Wizard 12.0\\Help\\enu\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\30C5541171C186F418CF0AFB0B55277B]
"6F56A51429D52A74FA4E04055C7923BF"="C:\\Program Files\\NCR\\Teradata Workload Analyzer 1.0\\help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\322253B6DBF881943A645A13420B09FF]
"BE36B32E0013FB0459392FBE6FC16742"="C:\\Program Files\\NCR\\Teradata Manager 7.2\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\32C6C9A4B26232E419C102E37B8CF99F]
"072F0661C4E441A4CB3AC068461DB915"="C:\\Program Files\\NCR\\Teradata Index Wizard 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\32D90227047A63146968616F98065A17]
"8D8EFA9EE993FEB48BDF05F65372A890"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3464730E7E030AD43BF48A08B3E623CA]
"8A3D68ECA95F3464C8F01B2FB2324216"="C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.00\\java\\lib\\fonts\\LucidaSansRegular.ttf"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\360C70C1093030445A6A55A8F60D8CD1]
"F1C0B989CDB8FB641B22DFCCC7532AEC"="C:\\Program Files\\NCR\\NCRput\\web\\jre\\bin\\java.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3661DBBDE1BF962468185571F67410A5]
"8D8EFA9EE993FEB48BDF05F65372A890"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\Help\\enu\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\38439D8687C7D254F9F154AF5D6FB8AB]
"F1C0B989CDB8FB641B22DFCCC7532AEC"="C:\\Program Files\\NCR\\NCRput\\web\\jre\\bin\\java.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\384E2D76C10CBBD48828229EECBC8FA8]
"AFEC3B47B91BA3944B4C90A328DB3AD2"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\Help\\enu\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3907FB144E4EEB04FBE86F2BAEAEF3AB]
"0667E56E71DCE234A9B67BCDBE2C239C"="C:\\Program Files\\NCR\\Teradata Workload Analyzer 1.1\\help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3A02C7FE6802A3842ABF00378F2CC9DE]
"D62B031B938208A489F1F2A4656FCBBD"="C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 12.0\\Help\\ENU\\Output\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3A1B770049AAE524FAB17B8665158AA8]
"8D8EFA9EE993FEB48BDF05F65372A890"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\HTML\\ENU\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3BE0541ED2B748540A007D17F41C98DD]
"9E331A1F624B1C44A8D0D91752642623"="C:\\Program Files\\NCR\\Teradata Visual Explain 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3C305418DA7DDC643940937FE33C78DB]
"963F990C72DC5A14A8FE075EDCA707CB"="C:\\Program Files\\NCR\\Teradata Index Wizard 1.3\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3C4C4F27D77F36E47BB6D50489EE42C5]
"C8704B98C58050C42B5FED43BBB19218"="C:\\Program Files\\NCR\\Teradata Manager 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3D9B1D404754CA84C95339F73FF5B3F6]
"D62B031B938208A489F1F2A4656FCBBD"="C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 12.0\\Help\\ENU\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3DAAACCA5A26C0B45A671011C4383B68]
"0725BA35EE76B40448D4FA8E1552AD6E"="C:\\Program Files\\NCR\\Teradata System Emulation Tool 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3E4DEB4BF8930A94DA8CC3928EECA7C8]
"AFEC3B47B91BA3944B4C90A328DB3AD2"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3EDB383A5EA118E4E81431D089E24D55]
"D62B031B938208A489F1F2A4656FCBBD"="C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 12.0\\Help\\ENU\\Output\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3FD2B2E4C1E9A4647BDA6154C08E5592]
"0E3868DA15CA5444C91621998E7E1676"="C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.12\\java\\bin\\ActPanel.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\41C4C40BA1780A540ABD4A0BEF2C0C7A]
"0667E56E71DCE234A9B67BCDBE2C239C"="C:\\Program Files\\NCR\\Teradata Workload Analyzer 1.1\\HTML\\ENU\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4210D39FE9C0D214DA66C66F9C686753]
"68AB67CA7DA73301B7448A2100000030"="C:\\Program Files\\Adobe\\Reader 8.0\\Reader\\Javascripts\\JSByteCodeWin.bin"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\421C8F9C0D07D1B43A020CB08477D14B]
"6F56A51429D52A74FA4E04055C7923BF"="C:\\Program Files\\NCR\\Teradata Workload Analyzer 1.0\\help\\enu\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\425D120B1D7132D479C49AF14C03A483]
"BE36B32E0013FB0459392FBE6FC16742"="C:\\Program Files\\NCR\\Teradata Manager 7.2\\Help\\enu\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\431A829983C93BC44A853BA4719561FC]
"8D8EFA9EE993FEB48BDF05F65372A890"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\43BF11E638C64E646A94A6045AD2E99C]
"C8704B98C58050C42B5FED43BBB19218"="C:\\Program Files\\NCR\\Teradata Manager 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\45073309018741341922C6144FA3CF16]
"85405BE5FFE4FBE49B7C3C606B058133"="C:\\Program Files\\NCR\\Teradata Workload Analyzer 12.0\\help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\452D475669673BE47BA7485D60182101]
"AFEC3B47B91BA3944B4C90A328DB3AD2"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4536F82560BD0E44AA2D8655CD2677E0]
"D62B031B938208A489F1F2A4656FCBBD"="C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 12.0\\Help\\ENU\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\46C1FBA869EA52E46A1522B8255E3465]
"305B9564D1F30364AA0B6A9E5F730780"="C:\\Program Files\\NCR\\Teradata Manager 7.1\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\490EB586E1E715B4298D0D2324D2E868]
"072F0661C4E441A4CB3AC068461DB915"="C:\\Program Files\\NCR\\Teradata Index Wizard 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\498AA37C722CE97418B8C507030A8987]
"AFEC3B47B91BA3944B4C90A328DB3AD2"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4B02C497604949F47B8A6DDF0E6614A7]
"AFEC3B47B91BA3944B4C90A328DB3AD2"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4FAA91168BD564B408370A522C41820E]
"AA2AB84896CD8B6469B0D25E75503E7C"="C:\\Program Files\\NCR\\Teradata Statistics Wizard 1.3\\Help\\ENU\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\51482A353D01A6C4791C6336D34969AE]
"934038F96EFC53446A24E1E3965DAB53"="C:\\Program Files\\NCR\\Teradata Visual Explain 3.3\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\51C81874B8BE5A94AA372FE25C0968C1]
"B322EE079CDB2CB4B8B22D218D0096E4"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53B99EB039C42484CAA64620F2EE84BE]
"85405BE5FFE4FBE49B7C3C606B058133"="C:\\Program Files\\NCR\\Teradata Workload Analyzer 12.0\\help\\enu\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\54D5EE3428A38BD41956823245FEB4ED]
"F1C0B989CDB8FB641B22DFCCC7532AEC"="C:\\Program Files\\NCR\\NCRput\\web\\jre\\bin\\NPJava12.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5507DAF1DD918544685F215968BFEA78]
"92C02E94C4BD45342B18544491F79220"="C:\\Program Files\\NCR\\Teradata Statistics Wizard 12.0\\Help\\ENU\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\557B853878C546D8D3DF50554AF58FD2]
"8B4098AB1B5BEF742A34FEBA0AE6CB65"="C:\\Program Files\\Teradata\\Client\\13.0\\ODBC Driver for Teradata\\Help\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\570E29347AF560D804F905002A39D3AB]
"80422343EA4BDD44BBDA83598AD81989"="C:\\Program Files\\Teradata\\Teradata Manager 13.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\59732B19C3D3A2D4C8AF619CB780DE47]
"8D8EFA9EE993FEB48BDF05F65372A890"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5B6D795D290568213533D5E0523266AB]
"BBF3759EE80207B47988BE8292A1501F"="C:\\Program Files\\Teradata\\Teradata Dynamic Workload Manager 13.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5CD8DB16544BF914DB9AFC98B50E9921]
"305B9564D1F30364AA0B6A9E5F730780"="C:\\Program Files\\NCR\\Teradata Manager 7.1\\Help\\enu\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5CF5591D12EF4CC4486059542FE686EB]
"8D8EFA9EE993FEB48BDF05F65372A890"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5DA6D13191AF27F4DBCE452E285BC037]
"0725BA35EE76B40448D4FA8E1552AD6E"="C:\\Program Files\\NCR\\Teradata System Emulation Tool 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\604C63AC834A20A4397B96A1FFCE36F5]
"0667E56E71DCE234A9B67BCDBE2C239C"="C:\\Program Files\\NCR\\Teradata Workload Analyzer 1.1\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\60FBB19E8A9CE4E4E935389B372D2E9E]
"E3F5B8CE13C22204B8F7260942647ADF"="C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 6.1\\Help\\ENU\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\61DD3E3E623EE2D4E92220D975769688]
"8D8EFA9EE993FEB48BDF05F65372A890"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\Help\\enu\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6277523A4439C0645A1F02B494618BE8]
"85405BE5FFE4FBE49B7C3C606B058133"="C:\\Program Files\\NCR\\Teradata Workload Analyzer 12.0\\help\\enu\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\64330C7B977B43A45B0CBC5FDA8347EF]
"072F0661C4E441A4CB3AC068461DB915"="C:\\Program Files\\NCR\\Teradata Index Wizard 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\64F2CCCBD78C7044DB6C89075F3571BE]
"963F990C72DC5A14A8FE075EDCA707CB"="C:\\Program Files\\NCR\\Teradata Index Wizard 1.3\\Help\\enu\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\66AB792CC670AC14EBA5AFB365064B3B]
"963F990C72DC5A14A8FE075EDCA707CB"="C:\\Program Files\\NCR\\Teradata Index Wizard 1.3\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\672419F528FF9564482D78B88EFEABAC]
"0E3868DA15CA5444C91621998E7E1676"="C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.12\\java\\lib\\images\\cursors\\cursors.properties"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6782792247842804B91C68BEAF7776E6]
"AFEC3B47B91BA3944B4C90A328DB3AD2"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\67C172AFD38A5704CBE0919AEB113155]
"AA2AB84896CD8B6469B0D25E75503E7C"="C:\\Program Files\\NCR\\Teradata Statistics Wizard 1.3\\Help\\ENU\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\67DCE3788EA3E5442B8BC5DB71CA64C5]
"0667E56E71DCE234A9B67BCDBE2C239C"="C:\\Program Files\\NCR\\Teradata Workload Analyzer 1.1\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\690CC83208DE49D4BB00FE2842085A0D]
"C8704B98C58050C42B5FED43BBB19218"="C:\\Program Files\\NCR\\Teradata Manager 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6944A4B4C4DB74C4CB3E061DE1632148]
"9E331A1F624B1C44A8D0D91752642623"="C:\\Program Files\\NCR\\Teradata Visual Explain 12.0\\Help\\enu\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6A69D2EF3691BAA4CA4F6C0DAD56387D]
"E3F5B8CE13C22204B8F7260942647ADF"="C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 6.1\\Help\\ENU\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6C0C439B49F63E230AA6283ED12FEB11]
"8017E0CB332AB804091E9CFBEC4D1126"="C:\\Program Files\\Teradata\\Teradata Workload Analyzer 13.0\\help\\enu\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\702BF33B07378324984EC3C673E4CFE7]
"0E3868DA15CA5444C91621998E7E1676"="C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.12\\java\\lib\\ext\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\71DBD0404F6D69045AE3287599C09F8D]
"D62B031B938208A489F1F2A4656FCBBD"="C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 12.0\\Help\\ENU\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\721C1120277D9614C99243075717578A]
"D62B031B938208A489F1F2A4656FCBBD"="C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 12.0\\Help\\ENU\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\731680BD6413BD54DB7575381AB370BC]
"934038F96EFC53446A24E1E3965DAB53"="C:\\Program Files\\NCR\\Teradata Visual Explain 3.3\\Help\\enu\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7369264B08652E1419478732B7D2E521]
"8A3D68ECA95F3464C8F01B2FB2324216"="C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.00\\java\\lib\\security\\cacerts"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\73BD528A880CB5541AD1775E53791AE8]
"AFEC3B47B91BA3944B4C90A328DB3AD2"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\76B2CD04E92095340A06F4F39096196F]
"AFEC3B47B91BA3944B4C90A328DB3AD2"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\Help\\enu\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\772EF6A046F998143AEBFFF530CBE331]
"49315D0E54D1A0646BD283B34C8F3B53"="C:\\Program Files\\QuickTime\\QTSystem\\QuickTimeJavaExtras.qtx"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\78290A12D5ACC274EB49F2582C139F52]
"6F56A51429D52A74FA4E04055C7923BF"="C:\\Program Files\\NCR\\Teradata Workload Analyzer 1.0\\help\\enu\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7918FA1605E954C488723B522119C003]
"C463911B6C5A31249B8E3FF29DB0AE7D"="C:\\Program Files\\NCR\\Teradata Query Scheduler 12.0\\Help\\ENU\\Output\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7CBA75CFA83D8CF48A316372805071A7]
"305B9564D1F30364AA0B6A9E5F730780"="C:\\Program Files\\NCR\\Teradata Manager 7.1\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\801930E39A6875DFEB4975CF743A9FF0]
"8B4098AB1B5BEF742A34FEBA0AE6CB65"="C:\\Program Files\\Teradata\\Client\\13.0\\ODBC Driver for Teradata\\Help\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8150FF3690542A64F95DD4A76E6E9CF2]
"8A3D68ECA95F3464C8F01B2FB2324216"="C:\\Program Files\\NCR\\Tdat\\TDGSS\\06.01.00.00\\lib\\java\\Login.config"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\81FC4F63308B4784D9B4C7FF58FC677D]
"0E3868DA15CA5444C91621998E7E1676"="C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.12\\java\\lib\\images\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8436D211A9D32E14CAD1C3E55C15EC0B]
"9DB735DF61597CF4FB7DA1189C05B388"="C:\\Program Files\\NCR\\Teradata Manager 7.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86695CFF26CAD3D47A6A35619C5202EF]
"0725BA35EE76B40448D4FA8E1552AD6E"="C:\\Program Files\\NCR\\Teradata System Emulation Tool 12.0\\Help\\enu\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86E496240328BEC422D1EA6BC821F830]
"BBF3759EE80207B47988BE8292A1501F"="C:\\Program Files\\Teradata\\Teradata Dynamic Workload Manager 13.0\\Help\\enu\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\87B8DD8A10EC4514BA39A088612D2974]
"85405BE5FFE4FBE49B7C3C606B058133"="C:\\Program Files\\NCR\\Teradata Workload Analyzer 12.0\\help\\enu\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8836F3CBDDFCDB14BBC52E2AD2569C87]
"8D8EFA9EE993FEB48BDF05F65372A890"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\Help\\enu\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CBE8790F9FD794499D42D3422E04DAD]
"92C02E94C4BD45342B18544491F79220"="C:\\Program Files\\NCR\\Teradata Statistics Wizard 12.0\\Help\\ENU\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8D2B15C0128AB92409CAE5F1873350C6]
"B322EE079CDB2CB4B8B22D218D0096E4"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 12.0\\Help\\enu\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8EDE4A66AFC8052C9208A037BF5B52DB]
"80422343EA4BDD44BBDA83598AD81989"="C:\\Program Files\\Teradata\\Teradata Manager 13.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F09859F525BC6C4C90C2B722494823A]
"8D8EFA9EE993FEB48BDF05F65372A890"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F72AEA10EE85DA8E24A2BAE8229A2FE]
"BBF3759EE80207B47988BE8292A1501F"="C:\\Program Files\\Teradata\\Teradata Dynamic Workload Manager 13.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8FECD8BC16ACB4042BD1900A29D60245]
"9DB735DF61597CF4FB7DA1189C05B388"="C:\\Program Files\\NCR\\Teradata Manager 7.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\917DA3F4D5393134FA84BC77140B9F76]
"8017E0CB332AB804091E9CFBEC4D1126"="C:\\Program Files\\Teradata\\Teradata Workload Analyzer 13.0\\help\\enu\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\91D1F6B56E29AD554CDB704458D05908]
"80422343EA4BDD44BBDA83598AD81989"="C:\\Program Files\\Teradata\\Teradata Manager 13.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\92A3F85FE8918C34A9D4FFD1A696095D]
"D62B031B938208A489F1F2A4656FCBBD"="C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 12.0\\Help\\ENU\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9350B84C7C4DE1E42A0C10BFFFAF87DA]
"B322EE079CDB2CB4B8B22D218D0096E4"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\94188F71DEF0C5E40B2203C186BCD993]
"0E3868DA15CA5444C91621998E7E1676"="C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.12\\lib\\java\\PdeUtilJar.jar"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9639CD4E59CF15844AB740F150D65208]
"8D8EFA9EE993FEB48BDF05F65372A890"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\965FB6D405E9697EDEA544D4B6D3AF36]
"8B4098AB1B5BEF742A34FEBA0AE6CB65"="C:\\Program Files\\Teradata\\Client\\13.0\\ODBC Driver for Teradata\\Help\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\96A460D69DB4F62408AD0433E4C08A48]
"0667E56E71DCE234A9B67BCDBE2C239C"="C:\\Program Files\\NCR\\Teradata Workload Analyzer 1.1\\help\\enu\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\998B72B246D1FCB438ABEE81A929CB3E]
"8A0F841731866D117AB7000B0D410203"="C?\\Program Files\\Common Files\\Java\\Update\\Base Images\\j2re1.4.2-b28\\extra.zip"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\99AA48621DE23684E9B8580670C8CF89]
"8A3D68ECA95F3464C8F01B2FB2324216"="C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.00\\java\\lib\\applet\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\99B4E4FE988607C42843A6BD1FED1F76]
"305B9564D1F30364AA0B6A9E5F730780"="C:\\Program Files\\NCR\\Teradata Manager 7.1\\Help\\enu\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9B1A5D54E8C7DA240A476DDB979C6D01]
"92C02E94C4BD45342B18544491F79220"="C:\\Program Files\\NCR\\Teradata Statistics Wizard 12.0\\Help\\ENU\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9B36072673DA86E40A43CDAB8246C92F]
"92C02E94C4BD45342B18544491F79220"="C:\\Program Files\\NCR\\Teradata Statistics Wizard 12.0\\Help\\ENU\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9B882387886FE3541A8720F0D7ED935E]
"0E3868DA15CA5444C91621998E7E1676"="C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.12\\java\\lib\\applet\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9C8A06F8DF13C2A4D81C30C02B1A2549]
"D62B031B938208A489F1F2A4656FCBBD"="C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 12.0\\Help\\ENU\\Output\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9C9789C7F23A9F04C9473F6A6F87C4FF]
"6F56A51429D52A74FA4E04055C7923BF"="C:\\Program Files\\NCR\\Teradata Workload Analyzer 1.0\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9CC4134C9C611D3438E03216DA3B39FE]
"934038F96EFC53446A24E1E3965DAB53"="C:\\Program Files\\NCR\\Teradata Visual Explain 3.3\\Help\\enu\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D17DC7407397FE4D91CCEBE73C9A90A]
"8B4098AB1B5BEF742A34FEBA0AE6CB65"="C:\\Program Files\\Teradata\\Client\\13.0\\ODBC Driver for Teradata\\Help\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9E5B9BA17FD00284596D6092645FFC85]
"49315D0E54D1A0646BD283B34C8F3B53"="C:\\Program Files\\Java\\jre1.6.0_02\\lib\\ext\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A14CA708AC6F56A41AEAA9663323419B]
"8A3D68ECA95F3464C8F01B2FB2324216"="C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.00\\lib\\java\\PdeUtilJar.jar"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A1B29A77D7B0F8042A2CB9603D3B7DEC]
"0E3868DA15CA5444C91621998E7E1676"="C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.12\\java\\lib\\security\\cacerts"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A35068DD4A9BD4C48B64282D26A0B245]
"0E3868DA15CA5444C91621998E7E1676"="C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.12\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A43D7A7785FA61595CD414C5B940B931]
"8017E0CB332AB804091E9CFBEC4D1126"="C:\\Program Files\\Teradata\\Teradata Workload Analyzer 13.0\\help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A4F5F37CE3DAAAF4AA214259E9740B74]
"AA2AB84896CD8B6469B0D25E75503E7C"="C:\\Program Files\\NCR\\Teradata Statistics Wizard 1.3\\Help\\ENU\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A4FB3FFC971949045926374FD4D7EF6D]
"8A3D68ECA95F3464C8F01B2FB2324216"="C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.00\\java\\bin\\hotspot\\Xusage.txt"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A66237BC02AEB1A449C329AFA6AB02CF]
"AE11A35A5900F39468AF1AE5A8684A50"="C:\\Program Files\\VMware\\VMware Player\\help\\wwhelp\\wwhimpl\\js\\scripts\\javascpt.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A6D29195AD9C91B4BABE8B86EC92D510]
"AFEC3B47B91BA3944B4C90A328DB3AD2"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A727AACD30A1072479614BFB1BF101D4]
"8D8EFA9EE993FEB48BDF05F65372A890"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\HTML\\ENU\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A75191E03DE0C7D4FACB5E5F3DBCAD49]
"8A3D68ECA95F3464C8F01B2FB2324216"="C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.00\\tcl\\lib\\tcllib1.3\\javascript\\javascript.tcl"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A8BF0220FF76038409421633016EA49F]
"C463911B6C5A31249B8E3FF29DB0AE7D"="C:\\Program Files\\NCR\\Teradata Query Scheduler 12.0\\Help\\ENU\\Output\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A906E164155A8C1C238DC415EE4659B4]
"80422343EA4BDD44BBDA83598AD81989"="C:\\Program Files\\Teradata\\Teradata Manager 13.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A9BED28972858334C9EECB1CBF7B9EB2]
"6F56A51429D52A74FA4E04055C7923BF"="C:\\Program Files\\NCR\\Teradata Workload Analyzer 1.0\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AA0844BC2719810438951DD056A7F109]
"305B9564D1F30364AA0B6A9E5F730780"="C:\\Program Files\\NCR\\Teradata Manager 7.1\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AC8A187C1275F4E47AD66AD4B0AB461F]
"BED3D6BECD315EC45A208429D093A610"="C:\\Program Files\\NCR\\Teradata System Emulation Tool 2.3\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACB0512318A96D117A58000B0D97FA46]
"8A0F842331866D117AB7000B0D510006"="C?\\Program Files\\Common Files\\Java\\Update\\Base Images\\jre1.5.0.b64\\core1.zip"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACB0512318A96D117A58000B0D97FA56]
"8A0F842331866D117AB7000B0D510006"="C?\\Program Files\\Common Files\\Java\\Update\\Base Images\\jre1.5.0.b64\\core2.zip"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACB0512318A96D117A58000B0D97FA66]
"8A0F842331866D117AB7000B0D510006"="C?\\Program Files\\Common Files\\Java\\Update\\Base Images\\jre1.5.0.b64\\core3.zip"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACB0612318A96D117A58000B0D97FA46]
"8A0F842331866D117AB7000B0D610002"="C?\\Program Files\\Common Files\\Java\\Update\\Base Images\\jre1.6.0.b105\\core1.zip"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACB0612318A96D117A58000B0D97FA56]
"8A0F842331866D117AB7000B0D610002"="C?\\Program Files\\Common Files\\Java\\Update\\Base Images\\jre1.6.0.b105\\core2.zip"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACB0612318A96D117A58000B0D97FA66]
"8A0F842331866D117AB7000B0D610002"="C?\\Program Files\\Common Files\\Java\\Update\\Base Images\\jre1.6.0.b105\\core3.zip"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACB9B14518A96D117A58000B0D410203]
"8A0F841731866D117AB7000B0D410203"="C:\\Program Files\\Java\\j2re1.4.2_03\\COPYRIGHT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACB9B14518A96D117A58000B0D97FA46]
"8A0F841731866D117AB7000B0D410203"="C?\\Program Files\\Common Files\\Java\\Update\\Base Images\\j2re1.4.2-b28\\core1.zip"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACB9B14518A96D117A58000B0D97FA56]
"8A0F841731866D117AB7000B0D410203"="C?\\Program Files\\Common Files\\Java\\Update\\Base Images\\j2re1.4.2-b28\\core2.zip"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACB9B14518A96D117A58000B0D97FA66]
"8A0F841731866D117AB7000B0D410203"="C?\\Program Files\\Common Files\\Java\\Update\\Base Images\\j2re1.4.2-b28\\core3.zip"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D510006]
"8A0F842331866D117AB7000B0D510006"="C:\\Program Files\\Java\\jre1.5.0_06\\COPYRIGHT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610002]
"8A0F842331866D117AB7000B0D610002"="C:\\Program Files\\Java\\jre1.6.0_02\\COPYRIGHT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ADA49677A1ED21245856CCEF5E3BC9A0]
"BED3D6BECD315EC45A208429D093A610"="C:\\Program Files\\NCR\\Teradata System Emulation Tool 2.3\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AE16BC9836579784E99F1B57D15FA368]
"8D8EFA9EE993FEB48BDF05F65372A890"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AEA48E188466756419F70063CA335C23]
"0E3868DA15CA5444C91621998E7E1676"="C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.12\\java\\bin\\hotspot\\Xusage.txt"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF6D727A726A6D117A78000B0D97FA46]
"8A0F841731866D117AB7000B0D410203"="C?\\Program Files\\Common Files\\Java\\Update\\Base Images\\j2re1.4.2-b28\\other.zip"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AFEC98132A1E82446BE1D853FE504F27]
"AFEC3B47B91BA3944B4C90A328DB3AD2"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B50E16772F2E1C44BB48BC63E89F2724]
"92C02E94C4BD45342B18544491F79220"="C:\\Program Files\\NCR\\Teradata Statistics Wizard 12.0\\Help\\ENU\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B835D31A23EC7E24A858719E50AEB968]
"9E331A1F624B1C44A8D0D91752642623"="C:\\Program Files\\NCR\\Teradata Visual Explain 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B85BF13E3A4AABD4787F37EEC0440A06]
"C8704B98C58050C42B5FED43BBB19218"="C:\\Program Files\\NCR\\Teradata Manager 12.0\\Help\\enu\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B8F5C2E8A7A61044D84CC4B0A6D42E38]
"AFEC3B47B91BA3944B4C90A328DB3AD2"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BBD4E175D66B7F4A4BB15FA3430568E6]
"8B4098AB1B5BEF742A34FEBA0AE6CB65"="C:\\Program Files\\Teradata\\Client\\13.0\\ODBC Driver for Teradata\\Help\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BBE32809058B9D848B33F6CF289CEBE6]
"F1C0B989CDB8FB641B22DFCCC7532AEC"="C:\\Program Files\\NCR\\NCRput\\web\\jre\\bin\\NPJava13.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BC53850033FBFB8468020D02943838D3]
"0E3868DA15CA5444C91621998E7E1676"="C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.12\\tcl\\lib\\tcllib1.3\\javascript\\javascript.tcl"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BC6784EC837DBDA459834C4F7F54DCDC]
"8A3D68ECA95F3464C8F01B2FB2324216"="C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.00\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BEAB5D0EFCCBF2144934625B7AC469AD]
"6F56A51429D52A74FA4E04055C7923BF"="C:\\Program Files\\NCR\\Teradata Workload Analyzer 1.0\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C0BF1A5C3EDFC0B4587EFCC9A1B24F03]
"AFEC3B47B91BA3944B4C90A328DB3AD2"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C3875074B86085444AE1FE29A2599B4B]
"8DF0F938CA874134FB2399C85D5A229F"="C:\\Program Files\\Teradata\\Teradata GSS\\nt-i386\\13m.00.00.00\\lib\\java\\Login.config"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C38F8B03B76ADA44F9592F1FA45C6BB6]
"8D8EFA9EE993FEB48BDF05F65372A890"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C3CF802D9DDF0654E9AA704401491EAC]
"C463911B6C5A31249B8E3FF29DB0AE7D"="C:\\Program Files\\NCR\\Teradata Query Scheduler 12.0\\Help\\ENU\\Output\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C5BBF177F8FA25F42A412BA9DB4A5DC0]
"8A3D68ECA95F3464C8F01B2FB2324216"="C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.00\\java\\lib\\images\\cursors\\cursors.properties"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C6C241A75E375414F85F3BA4F93ED721]
"6F56A51429D52A74FA4E04055C7923BF"="C:\\Program Files\\NCR\\Teradata Workload Analyzer 1.0\\help\\enu\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C75513FB3A1B7DD4BA6D81218EB8C857]
"072F0661C4E441A4CB3AC068461DB915"="C:\\Program Files\\NCR\\Teradata Index Wizard 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C94E4121C3BCDBB66CB78E408B705E18]
"80422343EA4BDD44BBDA83598AD81989"="C:\\Program Files\\Teradata\\Teradata Manager 13.0\\Help\\enu\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA5D1BE087617F2418F8D90E8334C7F6]
"0667E56E71DCE234A9B67BCDBE2C239C"="C:\\Program Files\\NCR\\Teradata Workload Analyzer 1.1\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB2E17DCBDDC8D41155F8FDE127F34CE]
"8B4098AB1B5BEF742A34FEBA0AE6CB65"="C:\\Program Files\\Teradata\\Client\\13.0\\ODBC Driver for Teradata\\Help\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CC23685D87705834EB8D262756E6F7F6]
"AFEC3B47B91BA3944B4C90A328DB3AD2"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CEE5119EA71AE974BBB89E1A68FBAA18]
"0667E56E71DCE234A9B67BCDBE2C239C"="C:\\Program Files\\NCR\\Teradata Workload Analyzer 1.1\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CF7B36D1780488A449E3B6E3EDED6440]
"0E3868DA15CA5444C91621998E7E1676"="C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.12\\java\\lib\\content-types.properties"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D00F82958984BC74D98E638560671ED6]
"9DB735DF61597CF4FB7DA1189C05B388"="C:\\Program Files\\NCR\\Teradata Manager 7.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D099833696A49DA4F9C7DF1E2EF8AC41]
"8A3D68ECA95F3464C8F01B2FB2324216"="C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.00\\java\\lib\\content-types.properties"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D162C3C17F8801B4EB4D3B6E59B5F62D]
"C463911B6C5A31249B8E3FF29DB0AE7D"="C:\\Program Files\\NCR\\Teradata Query Scheduler 12.0\\Help\\ENU\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D23F31A23B4D7A8DEB477C3A07737B0D]
"8B4098AB1B5BEF742A34FEBA0AE6CB65"="C:\\Program Files\\Teradata\\Client\\13.0\\ODBC Driver for Teradata\\Help\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2B776FEBAF76564DA937FEAE535E28E]
"8A3D68ECA95F3464C8F01B2FB2324216"="C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.00\\java\\lib\\images\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D4EC336A1898DCE43A72BF3634B58EE5]
"8A3D68ECA95F3464C8F01B2FB2324216"="C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.00\\java\\lib\\cmm\\CIEXYZ.pf"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D7416EC557D282A45BD280A3096E640E]
"49315D0E54D1A0646BD283B34C8F3B53"="C:\\Program Files\\QuickTime\\QTSystem\\QTJavaNative.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DA4D922C942ECA143BC0CCA699A8E401]
"A7BADDF8D11B9ED4AAC0A59C4FA076E6"="C:\\Program Files\\NCR\\Teradata GSS\\nt-i386\\12.00.00.00\\lib\\java\\Login.config"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB15D7FA6A3D26484B1658C1F34AB2F7]
"8B4098AB1B5BEF742A34FEBA0AE6CB65"="C:\\Program Files\\Teradata\\Client\\13.0\\ODBC Driver for Teradata\\Help\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DBD7B829090E5AE44ADF62860543D354]
"D62B031B938208A489F1F2A4656FCBBD"="C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 12.0\\Help\\ENU\\Output\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD65DEC73FAB0D242945B8671BBF9543]
"F1C0B989CDB8FB641B22DFCCC7532AEC"="C:\\Program Files\\NCR\\NCRput\\web\\jre\\bin\\NPJava14.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DF0EBA5E13AD50EBAA0F9603560EA792]
"8017E0CB332AB804091E9CFBEC4D1126"="C:\\Program Files\\Teradata\\Teradata Workload Analyzer 13.0\\help\\enu\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DF2BF130EA388364BA3F5099164B3393]
"8D8EFA9EE993FEB48BDF05F65372A890"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E11C6982CB5841C468FAC5693310CC6B]
"8D8EFA9EE993FEB48BDF05F65372A890"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E19A9CFDFA5AFF04F88E4B34219C95BF]
"C463911B6C5A31249B8E3FF29DB0AE7D"="C:\\Program Files\\NCR\\Teradata Query Scheduler 12.0\\Help\\ENU\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E3C666D6AE679214197A416A56120A8F]
"E3F5B8CE13C22204B8F7260942647ADF"="C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 6.1\\Help\\ENU\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E3C740AA2A700C649A8663C4155127BA]
"9E331A1F624B1C44A8D0D91752642623"="C:\\Program Files\\NCR\\Teradata Visual Explain 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E51FE8080BA607145908EB1E846A7A10]
"AFEC3B47B91BA3944B4C90A328DB3AD2"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E848BD6D4D13952428078D0A4F2A6FD2]
"B322EE079CDB2CB4B8B22D218D0096E4"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E866C35A035815749B8547856F178CD6]
"8D8EFA9EE993FEB48BDF05F65372A890"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E8F4F3A2A91E6304393E34E7899F1677]
"F1C0B989CDB8FB641B22DFCCC7532AEC"="C:\\Program Files\\NCR\\NCRput\\web\\jre\\bin\\NPJava32.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E95D04BFFF4967D438F2B82E733E44CF]
"AFEC3B47B91BA3944B4C90A328DB3AD2"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\Help\\enu\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E9819C53EC5BB5B4E97E3D542F4E4B69]
"85405BE5FFE4FBE49B7C3C606B058133"="C:\\Program Files\\NCR\\Teradata Workload Analyzer 12.0\\help\\enu\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EA04874A496E2838A6FC946E3C7C3B7C]
"BBF3759EE80207B47988BE8292A1501F"="C:\\Program Files\\Teradata\\Teradata Dynamic Workload Manager 13.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EB29C407EEFADBB4E9AE3949A210CE32]
"8D8EFA9EE993FEB48BDF05F65372A890"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EC96DB73373CB9743ADA2687D11FCCEA]
"AFEC3B47B91BA3944B4C90A328DB3AD2"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\Help\\enu\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED1BD373244484346AC95CB49566AF4C]
"BE36B32E0013FB0459392FBE6FC16742"="C:\\Program Files\\NCR\\Teradata Manager 7.2\\Help\\enu\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED23290A277E9AFBF1263FBB93CDAC6E]
"8B4098AB1B5BEF742A34FEBA0AE6CB65"="C:\\Program Files\\Teradata\\Client\\13.0\\ODBC Driver for Teradata\\Help\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EFC13D00055E57342ACB3A99A2A24659]
"934038F96EFC53446A24E1E3965DAB53"="C:\\Program Files\\NCR\\Teradata Visual Explain 3.3\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F247BDB0091F516EFA8C0A217DE7EDBD]
"8017E0CB332AB804091E9CFBEC4D1126"="C:\\Program Files\\Teradata\\Teradata Workload Analyzer 13.0\\help\\enu\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F3011EBACD270F74F8DF8292D42FB20E]
"934038F96EFC53446A24E1E3965DAB53"="C:\\Program Files\\NCR\\Teradata Visual Explain 3.3\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F5849B34C27EEBC49B32DF72EB847965]
"9E331A1F624B1C44A8D0D91752642623"="C:\\Program Files\\NCR\\Teradata Visual Explain 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F5BCDC2A2AE5DEE4FAE0DD4F37E3F83C]
"BED3D6BECD315EC45A208429D093A610"="C:\\Program Files\\NCR\\Teradata System Emulation Tool 2.3\\Help\\enu\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F69B25489D3ACD941BF82E3840B9791D]
"E3F5B8CE13C22204B8F7260942647ADF"="C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 6.1\\Help\\ENU\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F823A06509D811743AF1021C33528D6D]
"0725BA35EE76B40448D4FA8E1552AD6E"="C:\\Program Files\\NCR\\Teradata System Emulation Tool 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F8375DD0711ED6E48AC096173A430BA3]
"BED3D6BECD315EC45A208429D093A610"="C:\\Program Files\\NCR\\Teradata System Emulation Tool 2.3\\Help\\enu\\wwhelp\\wwhimpl\\java\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F848FA371D1269F41B52728C22DA7EE7]
"8D8EFA9EE993FEB48BDF05F65372A890"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F914811DFA5A9F44F833B9A49271C6E6]
"AA2AB84896CD8B6469B0D25E75503E7C"="C:\\Program Files\\NCR\\Teradata Statistics Wizard 1.3\\Help\\ENU\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F9EA0868F747E604FB9BA4CC73E1CD3A]
"BE36B32E0013FB0459392FBE6FC16742"="C:\\Program Files\\NCR\\Teradata Manager 7.2\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA241A8E6F004CB428C4A79774EEE2D4]
"B322EE079CDB2CB4B8B22D218D0096E4"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA66B6543A4FB4F439D8AEB56642B8FE]
"E3F5B8CE13C22204B8F7260942647ADF"="C:\\Program Files\\NCR\\Teradata Query Scheduler Admin 6.1\\Help\\ENU\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FAC9EAD86528C554FB4D8E4E3F4D0A4E]
"C463911B6C5A31249B8E3FF29DB0AE7D"="C:\\Program Files\\NCR\\Teradata Query Scheduler 12.0\\Help\\ENU\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FBEA3B10419547E48AFB0E98E8284B2F]
"AFEC3B47B91BA3944B4C90A328DB3AD2"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\HTML\\ENU\\wwhdata\\java\\files.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FC5C9F89572A6374DAF9914A035C4FBE]
"9DB735DF61597CF4FB7DA1189C05B388"="C:\\Program Files\\NCR\\Teradata Manager 7.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\html\\explore6.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FD44377E0CE84824A80E1CA3BDFEF69D]
"C463911B6C5A31249B8E3FF29DB0AE7D"="C:\\Program Files\\NCR\\Teradata Query Scheduler 12.0\\Help\\ENU\\Output\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FDBBBD408A11B674A9884F71693B1E8C]
"0725BA35EE76B40448D4FA8E1552AD6E"="C:\\Program Files\\NCR\\Teradata System Emulation Tool 12.0\\Help\\enu\\wwhelp\\wwhimpl\\java\\private\\books.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE217F182D9CFA84DAE00F9D353AC378]
"0E3868DA15CA5444C91621998E7E1676"="C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.12\\java\\lib\\fonts\\LucidaSansRegular.ttf"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FEDF8F6FF9A37994F89615AF8AF69E9D]
"8D8EFA9EE993FEB48BDF05F65372A890"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.2\\HTML\\ENU\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FF326D58EC9F62D409486BE61E4B90BC]
"AFEC3B47B91BA3944B4C90A328DB3AD2"="C:\\Program Files\\NCR\\Teradata Dynamic Workload Manager 6.1\\Help\\enu\\wwhelp\\wwhimpl\\java\\scripts\\handler.js"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\49315D0E54D1A0646BD283B34C8F3B53\Features]
"QuickTimeForJava"="}cRYjqXZM=+&FBLrWSBFRhtqE9@to?MDG`6rr~)qQx-F&L7K(9?rYqF5(i3)F@,Z+@IH3?oGm313a9VDQuickTimeEssentials"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F841731866D117AB7000B0D410203\InstallProperties]
"Comments"="http://www.java.com"
"Contact"="http://www.java.com"
; Contents of value:
; http://www.java.com
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,77,00,77,00,\
2e,00,6a,00,61,00,76,00,61,00,2e,00,63,00,6f,00,6d,00,00,00
"HelpTelephone"="http://www.java.com"
"URLInfoAbout"="http://www.java.com"
"URLUpdateInfo"="http://java.sun.com"
"DisplayName"="Java 2 Runtime Environment, SE v1.4.2_03"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D510006\InstallProperties]
"Contact"="http://java.com"
; Contents of value:
; http://java.com
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,6a,00,61,00,76,00,\
61,00,2e,00,63,00,6f,00,6d,00,00,00
; Contents of value:
; C:\Program Files\Java\jre1.5.0_06\README.txt
"Readme"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,20,\
00,46,00,69,00,6c,00,65,00,73,00,5c,00,4a,00,61,00,76,00,61,00,5c,00,6a,00,\
72,00,65,00,31,00,2e,00,35,00,2e,00,30,00,5f,00,30,00,36,00,5c,00,52,00,45,\
00,41,00,44,00,4d,00,45,00,2e,00,74,00,78,00,74,00,00,00
"URLInfoAbout"="http://java.com"
"URLUpdateInfo"="http://java.sun.com"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610002\InstallProperties]
"Contact"="http://java.com"
; Contents of value:
; http://java.com
"HelpLink"=hex(2):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,6a,00,61,00,76,00,\
61,00,2e,00,63,00,6f,00,6d,00,00,00
"InstallSource"="http://javadl.sun.com/webapps/download/GetFile/1.6.0_02-b06/windows-i586/"
; Contents of value:
; C:\Program Files\Java\jre1.6.0_02\README.txt
"Readme"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,20,\
00,46,00,69,00,6c,00,65,00,73,00,5c,00,4a,00,61,00,76,00,61,00,5c,00,6a,00,\
72,00,65,00,31,00,2e,00,36,00,2e,00,30,00,5f,00,30,00,32,00,5c,00,52,00,45,\
00,41,00,44,00,4d,00,45,00,2e,00,74,00,78,00,74,00,00,00
"URLInfoAbout"="http://java.com"
"URLUpdateInfo"="http://java.sun.com"
"DisplayName"="Java™ 6 Update 2"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\JAVAPER]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\JAVAPER]
"Text"="Java VM"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\JAVAPER\JAVA]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\JAVAPER\JAVA]
"Text"="Java permissions"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\JAVAPER\JAVA\CUSTOM]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\JAVAPER\JAVA\DISABLE]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\JAVAPER\JAVA\DISABLE]
"Text"="Disable Java"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\JAVAPER\JAVA\HIGH]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\JAVAPER\JAVA\LOW]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\JAVAPER\JAVA\MEDIUM]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTJAVA]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTJAVA]
"Text"="Scripting of Java applets"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTJAVA\ALLOW]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTJAVA\DENY]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO\SCRIPTING\SCRIPTJAVA\QUERY]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\JAVAPER]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\JAVAPER]
"Text"="Java VM"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\JAVAPER\JAVA]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\JAVAPER\JAVA]
"Text"="Java permissions"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\JAVAPER\JAVA\CUSTOM]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\JAVAPER\JAVA\DISABLE]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\JAVAPER\JAVA\DISABLE]
"Text"="Disable Java"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\JAVAPER\JAVA\HIGH]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\JAVAPER\JAVA\LOW]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\JAVAPER\JAVA\MEDIUM]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\SCRIPTING\SCRIPTJAVA]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\SCRIPTING\SCRIPTJAVA]
"Text"="Scripting of Java applets"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\SCRIPTING\SCRIPTJAVA\ALLOW]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\SCRIPTING\SCRIPTJAVA\DENY]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK\SCRIPTING\SCRIPTJAVA\QUERY]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_02\\bin\\jusched.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Common Files\\Java\\Update\\Base Images\\j2re1.4.2-b28\\other.zip"=dword:00000001
"C:\\Program Files\\Common Files\\Java\\Update\\Base Images\\j2re1.4.2-b28\\extra.zip"=dword:00000001
"C:\\Program Files\\Common Files\\Java\\Update\\Base Images\\j2re1.4.2-b28\\core1.zip"=dword:00000001
"C:\\Program Files\\Common Files\\Java\\Update\\Base Images\\j2re1.4.2-b28\\core2.zip"=dword:00000001
"C:\\Program Files\\Common Files\\Java\\Update\\Base Images\\j2re1.4.2-b28\\core3.zip"=dword:00000001
"C:\\Program Files\\Common Files\\Java\\Update\\Base Images\\jre1.5.0.b64\\core1.zip"=dword:00000001
"C:\\Program Files\\Common Files\\Java\\Update\\Base Images\\jre1.5.0.b64\\core2.zip"=dword:00000001
"C:\\Program Files\\Common Files\\Java\\Update\\Base Images\\jre1.5.0.b64\\core3.zip"=dword:00000001
"C:\\Program Files\\Common Files\\Java\\Update\\Base Images\\jre1.6.0.b105\\core1.zip"=dword:00000001
"C:\\Program Files\\Common Files\\Java\\Update\\Base Images\\jre1.6.0.b105\\core2.zip"=dword:00000001
"C:\\Program Files\\Common Files\\Java\\Update\\Base Images\\jre1.6.0.b105\\core3.zip"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts]
"Lucida Sans Regular (TrueType)"="C:\\Program Files\\NCR\\Tdat\\PDE\\06.01.00.12\\java\\lib\\fonts\\LucidaSansRegular.ttf"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\javai.dll]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msjava.dll]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Scripting Host\Script Extensions\.JS]
@="JavaScript Script File"
"EngineID"="JavaScript"

[HKEY_LOCAL_MACHINE\SOFTWARE\NCR\Teradata Parallel Transporter Wizard 8.1]
"VisualInterfaceJavaBinariesDir"="C:\\Program Files\\NCR\\Teradata Parallel Transporter\\8.1\\tptwizard\\jars"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment]
; Contents of value:
; .;C:\Program Files\Java\j2re1.4.2_03\lib\ext\QTJava.zip
"CLASSPATH"=hex(2):2e,00,3b,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\
61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4a,00,61,00,76,00,61,\
00,5c,00,6a,00,32,00,72,00,65,00,31,00,2e,00,34,00,2e,00,32,00,5f,00,30,00,\
33,00,5c,00,6c,00,69,00,62,00,5c,00,65,00,78,00,74,00,5c,00,51,00,54,00,4a,\
00,61,00,76,00,61,00,2e,00,7a,00,69,00,70,00,00,00
; Contents of value:
; C:\Program Files\Java\j2re1.4.2_03\lib\ext\QTJava.zip
"QTJAVA"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,20,\
00,46,00,69,00,6c,00,65,00,73,00,5c,00,4a,00,61,00,76,00,61,00,5c,00,6a,00,\
32,00,72,00,65,00,31,00,2e,00,34,00,2e,00,32,00,5f,00,30,00,33,00,5c,00,6c,\
00,69,00,62,00,5c,00,65,00,78,00,74,00,5c,00,51,00,54,00,4a,00,61,00,76,00,\
61,00,2e,00,7a,00,69,00,70,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application]
; Contents of value:
; MSDMine
; WSH
; WMIAdapter
; WmdmPmSN
; wltrysvc
; WinMgmt
; Winlogon
; Windows Product Activation
; Windows 3.1 Migration
; WebClient
; VSS
; VBRuntime
; Userinit
; Userenv
; Tlntsvr
; TISMessages
; Teradata
; TdatTools
; SysmonLog
; Starter
; SpoolerCtrs
; Software Restriction Policies
; Software Installation
; SmsClient
; SecurityCenter
; SclgNtfy
; SceSrv
; SceCli
; safrslv
; SAFrdms
; Remote Assistance
; PerfProc
; PerfOS
; PerfNet
; Perfmon
; Perflib
; PerfDisk
; Perfctrs
; Outlook
; Offline Files
; Oakley
; ntbackup
; MSSQLSERVER/MSDE
; MSSOAP
; MsiInstaller
; MSDTC Client
; MSDTC
; mnmsrvc
; Microsoft Office Document Imaging
; Microsoft Office 11
; Microsoft H.323 Telephony Service Provider
; Microsoft Fax
; LOGITECH
; LoadPerf
; Java VM
; HelpSvc
; GtwRsrvTdmst
; Folder Redirection
; File Deployment
; expclient
; EventSystem
; ESENT
; DrWatson
; DiskQuota
; crypt32
; Creative Service for CDROM Access
; COM+
; COM
; Ci
; Chkdsk
; AutoEnrollment
; Autochk
; ASP.NET 1.1.4322.0
; Application Management
; Application Hang
; Application Error
; AegisP
; .NET Runtime
; Application
;


"Sources"=hex(7):4d,00,53,00,44,00,4d,00,69,00,6e,00,65,00,00,00,57,00,53,00,\
48,00,00,00,57,00,4d,00,49,00,41,00,64,00,61,00,70,00,74,00,65,00,72,00,00,\
00,57,00,6d,00,64,00,6d,00,50,00,6d,00,53,00,4e,00,00,00,77,00,6c,00,74,00,\
72,00,79,00,73,00,76,00,63,00,00,00,57,00,69,00,6e,00,4d,00,67,00,6d,00,74,\
00,00,00,57,00,69,00,6e,00,6c,00,6f,00,67,00,6f,00,6e,00,00,00,57,00,69,00,\
6e,00,64,00,6f,00,77,00,73,00,20,00,50,00,72,00,6f,00,64,00,75,00,63,00,74,\
00,20,00,41,00,63,00,74,00,69,00,76,00,61,00,74,00,69,00,6f,00,6e,00,00,00,\
57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,20,00,33,00,2e,00,31,00,20,00,4d,\
00,69,00,67,00,72,00,61,00,74,00,69,00,6f,00,6e,00,00,00,57,00,65,00,62,00,\
43,00,6c,00,69,00,65,00,6e,00,74,00,00,00,56,00,53,00,53,00,00,00,56,00,42,\
00,52,00,75,00,6e,00,74,00,69,00,6d,00,65,00,00,00,55,00,73,00,65,00,72,00,\
69,00,6e,00,69,00,74,00,00,00,55,00,73,00,65,00,72,00,65,00,6e,00,76,00,00,\
00,54,00,6c,00,6e,00,74,00,73,00,76,00,72,00,00,00,54,00,49,00,53,00,4d,00,\
65,00,73,00,73,00,61,00,67,00,65,00,73,00,00,00,54,00,65,00,72,00,61,00,64,\
00,61,00,74,00,61,00,00,00,54,00,64,00,61,00,74,00,54,00,6f,00,6f,00,6c,00,\
73,00,00,00,53,00,79,00,73,00,6d,00,6f,00,6e,00,4c,00,6f,00,67,00,00,00,53,\
00,74,00,61,00,72,00,74,00,65,00,72,00,00,00,53,00,70,00,6f,00,6f,00,6c,00,\
65,00,72,00,43,00,74,00,72,00,73,00,00,00,53,00,6f,00,66,00,74,00,77,00,61,\
00,72,00,65,00,20,00,52,00,65,00,73,00,74,00,72,00,69,00,63,00,74,00,69,00,\
6f,00,6e,00,20,00,50,00,6f,00,6c,00,69,00,63,00,69,00,65,00,73,00,00,00,53,\
00,6f,00,66,00,74,00,77,00,61,00,72,00,65,00,20,00,49,00,6e,00,73,00,74,00,\
61,00,6c,00,6c,00,61,00,74,00,69,00,6f,00,6e,00,00,00,53,00,6d,00,73,00,43,\
00,6c,00,69,00,65,00,6e,00,74,00,00,00,53,00,65,00,63,00,75,00,72,00,69,00,\
74,00,79,00,43,00,65,00,6e,00,74,00,65,00,72,00,00,00,53,00,63,00,6c,00,67,\
00,4e,00,74,00,66,00,79,00,00,00,53,00,63,00,65,00,53,00,72,00,76,00,00,00,\
53,00,63,00,65,00,43,00,6c,00,69,00,00,00,73,00,61,00,66,00,72,00,73,00,6c,\
00,76,00,00,00,53,00,41,00,46,00,72,00,64,00,6d,00,73,00,00,00,52,00,65,00,\
6d,00,6f,00,74,00,65,00,20,00,41,00,73,00,73,00,69,00,73,00,74,00,61,00,6e,\
00,63,00,65,00,00,00,50,00,65,00,72,00,66,00,50,00,72,00,6f,00,63,00,00,00,\
50,00,65,00,72,00,66,00,4f,00,53,00,00,00,50,00,65,00,72,00,66,00,4e,00,65,\
00,74,00,00,00,50,00,65,00,72,00,66,00,6d,00,6f,00,6e,00,00,00,50,00,65,00,\
72,00,66,00,6c,00,69,00,62,00,00,00,50,00,65,00,72,00,66,00,44,00,69,00,73,\
00,6b,00,00,00,50,00,65,00,72,00,66,00,63,00,74,00,72,00,73,00,00,00,4f,00,\
75,00,74,00,6c,00,6f,00,6f,00,6b,00,00,00,4f,00,66,00,66,00,6c,00,69,00,6e,\
00,65,00,20,00,46,00,69,00,6c,00,65,00,73,00,00,00,4f,00,61,00,6b,00,6c,00,\
65,00,79,00,00,00,6e,00,74,00,62,00,61,00,63,00,6b,00,75,00,70,00,00,00,4d,\
00,53,00,53,00,51,00,4c,00,53,00,45,00,52,00,56,00,45,00,52,00,2f,00,4d,00,\
53,00,44,00,45,00,00,00,4d,00,53,00,53,00,4f,00,41,00,50,00,00,00,4d,00,73,\
00,69,00,49,00,6e,00,73,00,74,00,61,00,6c,00,6c,00,65,00,72,00,00,00,4d,00,\
53,00,44,00,54,00,43,00,20,00,43,00,6c,00,69,00,65,00,6e,00,74,00,00,00,4d,\
00,53,00,44,00,54,00,43,00,00,00,6d,00,6e,00,6d,00,73,00,72,00,76,00,63,00,\
00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,4f,00,66,\
00,66,00,69,00,63,00,65,00,20,00,44,00,6f,00,63,00,75,00,6d,00,65,00,6e,00,\
74,00,20,00,49,00,6d,00,61,00,67,00,69,00,6e,00,67,00,00,00,4d,00,69,00,63,\
00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,4f,00,66,00,66,00,69,00,63,00,\
65,00,20,00,31,00,31,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,\
00,74,00,20,00,48,00,2e,00,33,00,32,00,33,00,20,00,54,00,65,00,6c,00,65,00,\
70,00,68,00,6f,00,6e,00,79,00,20,00,53,00,65,00,72,00,76,00,69,00,63,00,65,\
00,20,00,50,00,72,00,6f,00,76,00,69,00,64,00,65,00,72,00,00,00,4d,00,69,00,\
63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,46,00,61,00,78,00,00,00,4c,\
00,4f,00,47,00,49,00,54,00,45,00,43,00,48,00,00,00,4c,00,6f,00,61,00,64,00,\
50,00,65,00,72,00,66,00,00,00,4a,00,61,00,76,00,61,00,20,00,56,00,4d,00,00,\
00,48,00,65,00,6c,00,70,00,53,00,76,00,63,00,00,00,47,00,74,00,77,00,52,00,\
73,00,72,00,76,00,54,00,64,00,6d,00,73,00,74,00,00,00,46,00,6f,00,6c,00,64,\
00,65,00,72,00,20,00,52,00,65,00,64,00,69,00,72,00,65,00,63,00,74,00,69,00,\
6f,00,6e,00,00,00,46,00,69,00,6c,00,65,00,20,00,44,00,65,00,70,00,6c,00,6f,\
00,79,00,6d,00,65,00,6e,00,74,00,00,00,65,00,78,00,70,00,63,00,6c,00,69,00,\
65,00,6e,00,74,00,00,00,45,00,76,00,65,00,6e,00,74,00,53,00,79,00,73,00,74,\
00,65,00,6d,00,00,00,45,00,53,00,45,00,4e,00,54,00,00,00,44,00,72,00,57,00,\
61,00,74,00,73,00,6f,00,6e,00,00,00,44,00,69,00,73,00,6b,00,51,00,75,00,6f,\
00,74,00,61,00,00,00,63,00,72,00,79,00,70,00,74,00,33,00,32,00,00,00,43,00,\
72,00,65,00,61,00,74,00,69,00,76,00,65,00,20,00,53,00,65,00,72,00,76,00,69,\
00,63,00,65,00,20,00,66,00,6f,00,72,00,20,00,43,00,44,00,52,00,4f,00,4d,00,\
20,00,41,00,63,00,63,00,65,00,73,00,73,00,00,00,43,00,4f,00,4d,00,2b,00,00,\
00,43,00,4f,00,4d,00,00,00,43,00,69,00,00,00,43,00,68,00,6b,00,64,00,73,00,\
6b,00,00,00,41,00,75,00,74,00,6f,00,45,00,6e,00,72,00,6f,00,6c,00,6c,00,6d,\
00,65,00,6e,00,74,00,00,00,41,00,75,00,74,00,6f,00,63,00,68,00,6b,00,00,00,\
41,00,53,00,50,00,2e,00,4e,00,45,00,54,00,20,00,31,00,2e,00,31,00,2e,00,34,\
00,33,00,32,00,32,00,2e,00,30,00,00,00,41,00,70,00,70,00,6c,00,69,00,63,00,\
61,00,74,00,69,00,6f,00,6e,00,20,00,4d,00,61,00,6e,00,61,00,67,00,65,00,6d,\
00,65,00,6e,00,74,00,00,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,\
69,00,6f,00,6e,00,20,00,48,00,61,00,6e,00,67,00,00,00,41,00,70,00,70,00,6c,\
00,69,00,63,00,61,00,74,00,69,00,6f,00,6e,00,20,00,45,00,72,00,72,00,6f,00,\
72,00,00,00,41,00,65,00,67,00,69,00,73,00,50,00,00,00,2e,00,4e,00,45,00,54,\
00,20,00,52,00,75,00,6e,00,74,00,69,00,6d,00,65,00,00,00,41,00,70,00,70,00,\
6c,00,69,00,63,00,61,00,74,00,69,00,6f,00,6e,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\Java VM]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VXD\JAVASUP]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VXD\JAVASUP]
"StaticVxD"="JAVASUP.VXD"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Session Manager\Environment]
"CLASSPATH"=".;C:\\Program Files\\Java\\jre1.6.0_02\\lib\\ext\\QTJava.zip"
"QTJAVA"="C:\\Program Files\\Java\\jre1.6.0_02\\lib\\ext\\QTJava.zip"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application]
; Contents of value:
; WSH
; WMIAdapter
; WmdmPmSN
; wltrysvc
; WinMgmt
; Winlogon
; Windows Product Activation
; Windows 3.1 Migration
; WebClient
; VSS
; VMware Virtual Mount Service Extended
; VMware NAT Service
; vmauthd
; Visual Studio - VsTemplate
; VBRuntime
; vbexpress
; usnjsvc
; Userinit
; Userenv
; Tlntsvr
; TISMessages
; Teradata
; TdatTools
; SysmonLog
; Starter
; SpoolerCtrs
; Software Restriction Policies
; Software Installation
; SmsClient
; SecurityCenter
; SclgNtfy
; SceSrv
; SceCli
; safrslv
; SAFrdms
; Remote Assistance
; PUTPortMgrSvc
; PUTJobSvc
; PUTFileSvc
; PerfProc
; PerfOS
; PerfNet
; Perfmon
; Perflib
; PerfDisk
; Perfctrs
; Outlook
; Offline Files
; Oakley
; ntbackup
; NCRput
; MSSQLSERVER/MSDE
; MSSOAP
; MsiInstaller
; MSDTC Client
; MSDTC
; MSDMine
; mnmsrvc
; Microsoft Visual Basic Express Edition
; Microsoft Office Document Imaging
; Microsoft Office 11
; Microsoft H.323 Telephony Service Provider
; Microsoft Fax
; Microsoft Document Explorer
; Microsoft ® Visual C# 2005 Compiler
; Microsoft ® Visual Basic Compiler
; MDM
; LOGITECH
; LoadPerf
; LiveMeeting
; Java VM
; IntelliPoint
; HelpSvc
; GtwRsrvTdmst
; Folder Redirection
; File Deployment
; expclient
; EventSystem
; ESENT
; ENDFORCE Agent API
; DrWatson
; DiskQuota
; crypt32
; Creative Service for CDROM Access
; COM+
; COM
; Ci
; Chkdsk
; AutoEnrollment
; Autochk
; ASP.NET 2.0.50727.0
; ASP.NET 1.1.4322.0
; Application Management
; Application Hang
; Application Error
; AegisP
; .NET Runtime Optimization Service
; .NET Runtime 2.0 Error Reporting
; .NET Runtime
; Application
;
"Sources"=hex(7):57,00,53,00,48,00,00,00,57,00,4d,00,49,00,41,00,64,00,61,00,\
70,00,74,00,65,00,72,00,00,00,57,00,6d,00,64,00,6d,00,50,00,6d,00,53,00,4e,\
00,00,00,77,00,6c,00,74,00,72,00,79,00,73,00,76,00,63,00,00,00,57,00,69,00,\
6e,00,4d,00,67,00,6d,00,74,00,00,00,57,00,69,00,6e,00,6c,00,6f,00,67,00,6f,\
00,6e,00,00,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,20,00,50,00,72,00,\
6f,00,64,00,75,00,63,00,74,00,20,00,41,00,63,00,74,00,69,00,76,00,61,00,74,\
00,69,00,6f,00,6e,00,00,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,20,00,\
33,00,2e,00,31,00,20,00,4d,00,69,00,67,00,72,00,61,00,74,00,69,00,6f,00,6e,\
00,00,00,57,00,65,00,62,00,43,00,6c,00,69,00,65,00,6e,00,74,00,00,00,56,00,\
53,00,53,00,00,00,56,00,4d,00,77,00,61,00,72,00,65,00,20,00,56,00,69,00,72,\
00,74,00,75,00,61,00,6c,00,20,00,4d,00,6f,00,75,00,6e,00,74,00,20,00,53,00,\
65,00,72,00,76,00,69,00,63,00,65,00,20,00,45,00,78,00,74,00,65,00,6e,00,64,\
00,65,00,64,00,00,00,56,00,4d,00,77,00,61,00,72,00,65,00,20,00,4e,00,41,00,\
54,00,20,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00,76,00,6d,00,61,\
00,75,00,74,00,68,00,64,00,00,00,56,00,69,00,73,00,75,00,61,00,6c,00,20,00,\
53,00,74,00,75,00,64,00,69,00,6f,00,20,00,2d,00,20,00,56,00,73,00,54,00,65,\
00,6d,00,70,00,6c,00,61,00,74,00,65,00,00,00,56,00,42,00,52,00,75,00,6e,00,\
74,00,69,00,6d,00,65,00,00,00,76,00,62,00,65,00,78,00,70,00,72,00,65,00,73,\
00,73,00,00,00,75,00,73,00,6e,00,6a,00,73,00,76,00,63,00,00,00,55,00,73,00,\
65,00,72,00,69,00,6e,00,69,00,74,00,00,00,55,00,73,00,65,00,72,00,65,00,6e,\
00,76,00,00,00,54,00,6c,00,6e,00,74,00,73,00,76,00,72,00,00,00,54,00,49,00,\
53,00,4d,00,65,00,73,00,73,00,61,00,67,00,65,00,73,00,00,00,54,00,65,00,72,\
00,61,00,64,00,61,00,74,00,61,00,00,00,54,00,64,00,61,00,74,00,54,00,6f,00,\
6f,00,6c,00,73,00,00,00,53,00,79,00,73,00,6d,00,6f,00,6e,00,4c,00,6f,00,67,\
00,00,00,53,00,74,00,61,00,72,00,74,00,65,00,72,00,00,00,53,00,70,00,6f,00,\
6f,00,6c,00,65,00,72,00,43,00,74,00,72,00,73,00,00,00,53,00,6f,00,66,00,74,\
00,77,00,61,00,72,00,65,00,20,00,52,00,65,00,73,00,74,00,72,00,69,00,63,00,\
74,00,69,00,6f,00,6e,00,20,00,50,00,6f,00,6c,00,69,00,63,00,69,00,65,00,73,\
00,00,00,53,00,6f,00,66,00,74,00,77,00,61,00,72,00,65,00,20,00,49,00,6e,00,\
73,00,74,00,61,00,6c,00,6c,00,61,00,74,00,69,00,6f,00,6e,00,00,00,53,00,6d,\
00,73,00,43,00,6c,00,69,00,65,00,6e,00,74,00,00,00,53,00,65,00,63,00,75,00,\
72,00,69,00,74,00,79,00,43,00,65,00,6e,00,74,00,65,00,72,00,00,00,53,00,63,\
00,6c,00,67,00,4e,00,74,00,66,00,79,00,00,00,53,00,63,00,65,00,53,00,72,00,\
76,00,00,00,53,00,63,00,65,00,43,00,6c,00,69,00,00,00,73,00,61,00,66,00,72,\
00,73,00,6c,00,76,00,00,00,53,00,41,00,46,00,72,00,64,00,6d,00,73,00,00,00,\
52,00,65,00,6d,00,6f,00,74,00,65,00,20,00,41,00,73,00,73,00,69,00,73,00,74,\
00,61,00,6e,00,63,00,65,00,00,00,50,00,55,00,54,00,50,00,6f,00,72,00,74,00,\
4d,00,67,00,72,00,53,00,76,00,63,00,00,00,50,00,55,00,54,00,4a,00,6f,00,62,\
00,53,00,76,00,63,00,00,00,50,00,55,00,54,00,46,00,69,00,6c,00,65,00,53,00,\
76,00,63,00,00,00,50,00,65,00,72,00,66,00,50,00,72,00,6f,00,63,00,00,00,50,\
00,65,00,72,00,66,00,4f,00,53,00,00,00,50,00,65,00,72,00,66,00,4e,00,65,00,\
74,00,00,00,50,00,65,00,72,00,66,00,6d,00,6f,00,6e,00,00,00,50,00,65,00,72,\
00,66,00,6c,00,69,00,62,00,00,00,50,00,65,00,72,00,66,00,44,00,69,00,73,00,\
6b,00,00,00,50,00,65,00,72,00,66,00,63,00,74,00,72,00,73,00,00,00,4f,00,75,\
00,74,00,6c,00,6f,00,6f,00,6b,00,00,00,4f,00,66,00,66,00,6c,00,69,00,6e,00,\
65,00,20,00,46,00,69,00,6c,00,65,00,73,00,00,00,4f,00,61,00,6b,00,6c,00,65,\
00,79,00,00,00,6e,00,74,00,62,00,61,00,63,00,6b,00,75,00,70,00,00,00,4e,00,\
43,00,52,00,70,00,75,00,74,00,00,00,4d,00,53,00,53,00,51,00,4c,00,53,00,45,\
00,52,00,56,00,45,00,52,00,2f,00,4d,00,53,00,44,00,45,00,00,00,4d,00,53,00,\
53,00,4f,00,41,00,50,00,00,00,4d,00,73,00,69,00,49,00,6e,00,73,00,74,00,61,\
00,6c,00,6c,00,65,00,72,00,00,00,4d,00,53,00,44,00,54,00,43,00,20,00,43,00,\
6c,00,69,00,65,00,6e,00,74,00,00,00,4d,00,53,00,44,00,54,00,43,00,00,00,4d,\
00,53,00,44,00,4d,00,69,00,6e,00,65,00,00,00,6d,00,6e,00,6d,00,73,00,72,00,\
76,00,63,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,\
00,56,00,69,00,73,00,75,00,61,00,6c,00,20,00,42,00,61,00,73,00,69,00,63,00,\
20,00,45,00,78,00,70,00,72,00,65,00,73,00,73,00,20,00,45,00,64,00,69,00,74,\
00,69,00,6f,00,6e,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,\
74,00,20,00,4f,00,66,00,66,00,69,00,63,00,65,00,20,00,44,00,6f,00,63,00,75,\
00,6d,00,65,00,6e,00,74,00,20,00,49,00,6d,00,61,00,67,00,69,00,6e,00,67,00,\
00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,4f,00,66,\
00,66,00,69,00,63,00,65,00,20,00,31,00,31,00,00,00,4d,00,69,00,63,00,72,00,\
6f,00,73,00,6f,00,66,00,74,00,20,00,48,00,2e,00,33,00,32,00,33,00,20,00,54,\
00,65,00,6c,00,65,00,70,00,68,00,6f,00,6e,00,79,00,20,00,53,00,65,00,72,00,\
76,00,69,00,63,00,65,00,20,00,50,00,72,00,6f,00,76,00,69,00,64,00,65,00,72,\
00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,46,00,\
61,00,78,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,\
00,44,00,6f,00,63,00,75,00,6d,00,65,00,6e,00,74,00,20,00,45,00,78,00,70,00,\
6c,00,6f,00,72,00,65,00,72,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,\
00,66,00,74,00,20,00,28,00,52,00,29,00,20,00,56,00,69,00,73,00,75,00,61,00,\
6c,00,20,00,43,00,23,00,20,00,32,00,30,00,30,00,35,00,20,00,43,00,6f,00,6d,\
00,70,00,69,00,6c,00,65,00,72,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,\
6f,00,66,00,74,00,20,00,28,00,52,00,29,00,20,00,56,00,69,00,73,00,75,00,61,\
00,6c,00,20,00,42,00,61,00,73,00,69,00,63,00,20,00,43,00,6f,00,6d,00,70,00,\
69,00,6c,00,65,00,72,00,00,00,4d,00,44,00,4d,00,00,00,4c,00,4f,00,47,00,49,\
00,54,00,45,00,43,00,48,00,00,00,4c,00,6f,00,61,00,64,00,50,00,65,00,72,00,\
66,00,00,00,4c,00,69,00,76,00,65,00,4d,00,65,00,65,00,74,00,69,00,6e,00,67,\
00,00,00,4a,00,61,00,76,00,61,00,20,00,56,00,4d,00,00,00,49,00,6e,00,74,00,\
65,00,6c,00,6c,00,69,00,50,00,6f,00,69,00,6e,00,74,00,00,00,48,00,65,00,6c,\
00,70,00,53,00,76,00,63,00,00,00,47,00,74,00,77,00,52,00,73,00,72,00,76,00,\
54,00,64,00,6d,00,73,00,74,00,00,00,46,00,6f,00,6c,00,64,00,65,00,72,00,20,\
00,52,00,65,00,64,00,69,00,72,00,65,00,63,00,74,00,69,00,6f,00,6e,00,00,00,\
46,00,69,00,6c,00,65,00,20,00,44,00,65,00,70,00,6c,00,6f,00,79,00,6d,00,65,\
00,6e,00,74,00,00,00,65,00,78,00,70,00,63,00,6c,00,69,00,65,00,6e,00,74,00,\
00,00,45,00,76,00,65,00,6e,00,74,00,53,00,79,00,73,00,74,00,65,00,6d,00,00,\
00,45,00,53,00,45,00,4e,00,54,00,00,00,45,00,4e,00,44,00,46,00,4f,00,52,00,\
43,00,45,00,20,00,41,00,67,00,65,00,6e,00,74,00,20,00,41,00,50,00,49,00,00,\
00,44,00,72,00,57,00,61,00,74,00,73,00,6f,00,6e,00,00,00,44,00,69,00,73,00,\
6b,00,51,00,75,00,6f,00,74,00,61,00,00,00,63,00,72,00,79,00,70,00,74,00,33,\
00,32,00,00,00,43,00,72,00,65,00,61,00,74,00,69,00,76,00,65,00,20,00,53,00,\
65,00,72,00,76,00,69,00,63,00,65,00,20,00,66,00,6f,00,72,00,20,00,43,00,44,\
00,52,00,4f,00,4d,00,20,00,41,00,63,00,63,00,65,00,73,00,73,00,00,00,43,00,\
4f,00,4d,00,2b,00,00,00,43,00,4f,00,4d,00,00,00,43,00,69,00,00,00,43,00,68,\
00,6b,00,64,00,73,00,6b,00,00,00,41,00,75,00,74,00,6f,00,45,00,6e,00,72,00,\
6f,00,6c,00,6c,00,6d,00,65,00,6e,00,74,00,00,00,41,00,75,00,74,00,6f,00,63,\
00,68,00,6b,00,00,00,41,00,53,00,50,00,2e,00,4e,00,45,00,54,00,20,00,32,00,\
2e,00,30,00,2e,00,35,00,30,00,37,00,32,00,37,00,2e,00,30,00,00,00,41,00,53,\
00,50,00,2e,00,4e,00,45,00,54,00,20,00,31,00,2e,00,31,00,2e,00,34,00,33,00,\
32,00,32,00,2e,00,30,00,00,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,\
00,69,00,6f,00,6e,00,20,00,4d,00,61,00,6e,00,61,00,67,00,65,00,6d,00,65,00,\
6e,00,74,00,00,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,00,6f,\
00,6e,00,20,00,48,00,61,00,6e,00,67,00,00,00,41,00,70,00,70,00,6c,00,69,00,\
63,00,61,00,74,00,69,00,6f,00,6e,00,20,00,45,00,72,00,72,00,6f,00,72,00,00,\
00,41,00,65,00,67,00,69,00,73,00,50,00,00,00,2e,00,4e,00,45,00,54,00,20,00,\
52,00,75,00,6e,00,74,00,69,00,6d,00,65,00,20,00,4f,00,70,00,74,00,69,00,6d,\
00,69,00,7a,00,61,00,74,00,69,00,6f,00,6e,00,20,00,53,00,65,00,72,00,76,00,\
69,00,63,00,65,00,00,00,2e,00,4e,00,45,00,54,00,20,00,52,00,75,00,6e,00,74,\
00,69,00,6d,00,65,00,20,00,32,00,2e,00,30,00,20,00,45,00,72,00,72,00,6f,00,\
72,00,20,00,52,00,65,00,70,00,6f,00,72,00,74,00,69,00,6e,00,67,00,00,00,2e,\
00,4e,00,45,00,54,00,20,00,52,00,75,00,6e,00,74,00,69,00,6d,00,65,00,00,00,\
41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,00,6f,00,6e,00,00,00,00,\
00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\Java VM]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\VXD\JAVASUP]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\VXD\JAVASUP]
"StaticVxD"="JAVASUP.VXD"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Session Manager\Environment]
"CLASSPATH"=".;C:\\Program Files\\Java\\jre1.6.0_02\\lib\\ext\\QTJava.zip"
"QTJAVA"="C:\\Program Files\\Java\\jre1.6.0_02\\lib\\ext\\QTJava.zip"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\Application]
; Contents of value:
; WSH
; WMIAdapter
; WmdmPmSN
; wltrysvc
; WinMgmt
; Winlogon
; Windows Product Activation
; Windows 3.1 Migration
; WebClient
; VSS
; VMware Virtual Mount Service Extended
; VMware NAT Service
; vmauthd
; Visual Studio - VsTemplate
; VBRuntime
; vbexpress
; usnjsvc
; Userinit
; Userenv
; Tlntsvr
; TISMessages
; Teradata
; TdatTools
; SysmonLog
; Starter
; SpoolerCtrs
; Software Restriction Policies
; Software Installation
; SmsClient
; SecurityCenter
; SclgNtfy
; SceSrv
; SceCli
; safrslv
; SAFrdms
; Remote Assistance
; PUTPortMgrSvc
; PUTJobSvc
; PUTFileSvc
; PerfProc
; PerfOS
; PerfNet
; Perfmon
; Perflib
; PerfDisk
; Perfctrs
; Outlook
; Offline Files
; Oakley
; ntbackup
; NCRput
; MSSQLSERVER/MSDE
; MSSOAP
; MsiInstaller
; MSDTC Client
; MSDTC
; MSDMine
; mnmsrvc
; Microsoft Visual Basic Express Edition
; Microsoft Office Document Imaging
; Microsoft Office 11
; Microsoft H.323 Telephony Service Provider
; Microsoft Fax
; Microsoft Document Explorer
; Microsoft ® Visual C# 2005 Compiler
; Microsoft ® Visual Basic Compiler
; MDM
; LOGITECH
; LoadPerf
; LiveMeeting
; Java VM
; IntelliPoint
; HelpSvc
; GtwRsrvTdmst
; Folder Redirection
; File Deployment
; expclient
; EventSystem
; ESENT
; ENDFORCE Agent API
; DrWatson
; DiskQuota
; crypt32
; Creative Service for CDROM Access
; COM+
; COM
; Ci
; Chkdsk
; AutoEnrollment
; Autochk
; ASP.NET 2.0.50727.0
; ASP.NET 1.1.4322.0
; Application Management
; Application Hang
; Application Error
; AegisP
; .NET Runtime Optimization Service
; .NET Runtime 2.0 Error Reporting
; .NET Runtime
; Application
;
"Sources"=hex(7):57,00,53,00,48,00,00,00,57,00,4d,00,49,00,41,00,64,00,61,00,\
70,00,74,00,65,00,72,00,00,00,57,00,6d,00,64,00,6d,00,50,00,6d,00,53,00,4e,\
00,00,00,77,00,6c,00,74,00,72,00,79,00,73,00,76,00,63,00,00,00,57,00,69,00,\
6e,00,4d,00,67,00,6d,00,74,00,00,00,57,00,69,00,6e,00,6c,00,6f,00,67,00,6f,\
00,6e,00,00,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,20,00,50,00,72,00,\
6f,00,64,00,75,00,63,00,74,00,20,00,41,00,63,00,74,00,69,00,76,00,61,00,74,\
00,69,00,6f,00,6e,00,00,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,20,00,\
33,00,2e,00,31,00,20,00,4d,00,69,00,67,00,72,00,61,00,74,00,69,00,6f,00,6e,\
00,00,00,57,00,65,00,62,00,43,00,6c,00,69,00,65,00,6e,00,74,00,00,00,56,00,\
53,00,53,00,00,00,56,00,4d,00,77,00,61,00,72,00,65,00,20,00,56,00,69,00,72,\
00,74,00,75,00,61,00,6c,00,20,00,4d,00,6f,00,75,00,6e,00,74,00,20,00,53,00,\
65,00,72,00,76,00,69,00,63,00,65,00,20,00,45,00,78,00,74,00,65,00,6e,00,64,\
00,65,00,64,00,00,00,56,00,4d,00,77,00,61,00,72,00,65,00,20,00,4e,00,41,00,\
54,00,20,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00,76,00,6d,00,61,\
00,75,00,74,00,68,00,64,00,00,00,56,00,69,00,73,00,75,00,61,00,6c,00,20,00,\
53,00,74,00,75,00,64,00,69,00,6f,00,20,00,2d,00,20,00,56,00,73,00,54,00,65,\
00,6d,00,70,00,6c,00,61,00,74,00,65,00,00,00,56,00,42,00,52,00,75,00,6e,00,\
74,00,69,00,6d,00,65,00,00,00,76,00,62,00,65,00,78,00,70,00,72,00,65,00,73,\
00,73,00,00,00,75,00,73,00,6e,00,6a,00,73,00,76,00,63,00,00,00,55,00,73,00,\
65,00,72,00,69,00,6e,00,69,00,74,00,00,00,55,00,73,00,65,00,72,00,65,00,6e,\
00,76,00,00,00,54,00,6c,00,6e,00,74,00,73,00,76,00,72,00,00,00,54,00,49,00,\
53,00,4d,00,65,00,73,00,73,00,61,00,67,00,65,00,73,00,00,00,54,00,65,00,72,\
00,61,00,64,00,61,00,74,00,61,00,00,00,54,00,64,00,61,00,74,00,54,00,6f,00,\
6f,00,6c,00,73,00,00,00,53,00,79,00,73,00,6d,00,6f,00,6e,00,4c,00,6f,00,67,\
00,00,00,53,00,74,00,61,00,72,00,74,00,65,00,72,00,00,00,53,00,70,00,6f,00,\
6f,00,6c,00,65,00,72,00,43,00,74,00,72,00,73,00,00,00,53,00,6f,00,66,00,74,\
00,77,00,61,00,72,00,65,00,20,00,52,00,65,00,73,00,74,00,72,00,69,00,63,00,\
74,00,69,00,6f,00,6e,00,20,00,50,00,6f,00,6c,00,69,00,63,00,69,00,65,00,73,\
00,00,00,53,00,6f,00,66,00,74,00,77,00,61,00,72,00,65,00,20,00,49,00,6e,00,\
73,00,74,00,61,00,6c,00,6c,00,61,00,74,00,69,00,6f,00,6e,00,00,00,53,00,6d,\
00,73,00,43,00,6c,00,69,00,65,00,6e,00,74,00,00,00,53,00,65,00,63,00,75,00,\
72,00,69,00,74,00,79,00,43,00,65,00,6e,00,74,00,65,00,72,00,00,00,53,00,63,\
00,6c,00,67,00,4e,00,74,00,66,00,79,00,00,00,53,00,63,00,65,00,53,00,72,00,\
76,00,00,00,53,00,63,00,65,00,43,00,6c,00,69,00,00,00,73,00,61,00,66,00,72,\
00,73,00,6c,00,76,00,00,00,53,00,41,00,46,00,72,00,64,00,6d,00,73,00,00,00,\
52,00,65,00,6d,00,6f,00,74,00,65,00,20,00,41,00,73,00,73,00,69,00,73,00,74,\
00,61,00,6e,00,63,00,65,00,00,00,50,00,55,00,54,00,50,00,6f,00,72,00,74,00,\
4d,00,67,00,72,00,53,00,76,00,63,00,00,00,50,00,55,00,54,00,4a,00,6f,00,62,\
00,53,00,76,00,63,00,00,00,50,00,55,00,54,00,46,00,69,00,6c,00,65,00,53,00,\
76,00,63,00,00,00,50,00,65,00,72,00,66,00,50,00,72,00,6f,00,63,00,00,00,50,\
00,65,00,72,00,66,00,4f,00,53,00,00,00,50,00,65,00,72,00,66,00,4e,00,65,00,\
74,00,00,00,50,00,65,00,72,00,66,00,6d,00,6f,00,6e,00,00,00,50,00,65,00,72,\
00,66,00,6c,00,69,00,62,00,00,00,50,00,65,00,72,00,66,00,44,00,69,00,73,00,\
6b,00,00,00,50,00,65,00,72,00,66,00,63,00,74,00,72,00,73,00,00,00,4f,00,75,\
00,74,00,6c,00,6f,00,6f,00,6b,00,00,00,4f,00,66,00,66,00,6c,00,69,00,6e,00,\
65,00,20,00,46,00,69,00,6c,00,65,00,73,00,00,00,4f,00,61,00,6b,00,6c,00,65,\
00,79,00,00,00,6e,00,74,00,62,00,61,00,63,00,6b,00,75,00,70,00,00,00,4e,00,\
43,00,52,00,70,00,75,00,74,00,00,00,4d,00,53,00,53,00,51,00,4c,00,53,00,45,\
00,52,00,56,00,45,00,52,00,2f,00,4d,00,53,00,44,00,45,00,00,00,4d,00,53,00,\
53,00,4f,00,41,00,50,00,00,00,4d,00,73,00,69,00,49,00,6e,00,73,00,74,00,61,\
00,6c,00,6c,00,65,00,72,00,00,00,4d,00,53,00,44,00,54,00,43,00,20,00,43,00,\
6c,00,69,00,65,00,6e,00,74,00,00,00,4d,00,53,00,44,00,54,00,43,00,00,00,4d,\
00,53,00,44,00,4d,00,69,00,6e,00,65,00,00,00,6d,00,6e,00,6d,00,73,00,72,00,\
76,00,63,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,\
00,56,00,69,00,73,00,75,00,61,00,6c,00,20,00,42,00,61,00,73,00,69,00,63,00,\
20,00,45,00,78,00,70,00,72,00,65,00,73,00,73,00,20,00,45,00,64,00,69,00,74,\
00,69,00,6f,00,6e,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,\
74,00,20,00,4f,00,66,00,66,00,69,00,63,00,65,00,20,00,44,00,6f,00,63,00,75,\
00,6d,00,65,00,6e,00,74,00,20,00,49,00,6d,00,61,00,67,00,69,00,6e,00,67,00,\
00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,4f,00,66,\
00,66,00,69,00,63,00,65,00,20,00,31,00,31,00,00,00,4d,00,69,00,63,00,72,00,\
6f,00,73,00,6f,00,66,00,74,00,20,00,48,00,2e,00,33,00,32,00,33,00,20,00,54,\
00,65,00,6c,00,65,00,70,00,68,00,6f,00,6e,00,79,00,20,00,53,00,65,00,72,00,\
76,00,69,00,63,00,65,00,20,00,50,00,72,00,6f,00,76,00,69,00,64,00,65,00,72,\
00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,46,00,\
61,00,78,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,\
00,44,00,6f,00,63,00,75,00,6d,00,65,00,6e,00,74,00,20,00,45,00,78,00,70,00,\
6c,00,6f,00,72,00,65,00,72,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,\
00,66,00,74,00,20,00,28,00,52,00,29,00,20,00,56,00,69,00,73,00,75,00,61,00,\
6c,00,20,00,43,00,23,00,20,00,32,00,30,00,30,00,35,00,20,00,43,00,6f,00,6d,\
00,70,00,69,00,6c,00,65,00,72,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,\
6f,00,66,00,74,00,20,00,28,00,52,00,29,00,20,00,56,00,69,00,73,00,75,00,61,\
00,6c,00,20,00,42,00,61,00,73,00,69,00,63,00,20,00,43,00,6f,00,6d,00,70,00,\
69,00,6c,00,65,00,72,00,00,00,4d,00,44,00,4d,00,00,00,4c,00,4f,00,47,00,49,\
00,54,00,45,00,43,00,48,00,00,00,4c,00,6f,00,61,00,64,00,50,00,65,00,72,00,\
66,00,00,00,4c,00,69,00,76,00,65,00,4d,00,65,00,65,00,74,00,69,00,6e,00,67,\
00,00,00,4a,00,61,00,76,00,61,00,20,00,56,00,4d,00,00,00,49,00,6e,00,74,00,\
65,00,6c,00,6c,00,69,00,50,00,6f,00,69,00,6e,00,74,00,00,00,48,00,65,00,6c,\
00,70,00,53,00,76,00,63,00,00,00,47,00,74,00,77,00,52,00,73,00,72,00,76,00,\
54,00,64,00,6d,00,73,00,74,00,00,00,46,00,6f,00,6c,00,64,00,65,00,72,00,20,\
00,52,00,65,00,64,00,69,00,72,00,65,00,63,00,74,00,69,00,6f,00,6e,00,00,00,\
46,00,69,00,6c,00,65,00,20,00,44,00,65,00,70,00,6c,00,6f,00,79,00,6d,00,65,\
00,6e,00,74,00,00,00,65,00,78,00,70,00,63,00,6c,00,69,00,65,00,6e,00,74,00,\
00,00,45,00,76,00,65,00,6e,00,74,00,53,00,79,00,73,00,74,00,65,00,6d,00,00,\
00,45,00,53,00,45,00,4e,00,54,00,00,00,45,00,4e,00,44,00,46,00,4f,00,52,00,\
43,00,45,00,20,00,41,00,67,00,65,00,6e,00,74,00,20,00,41,00,50,00,49,00,00,\
00,44,00,72,00,57,00,61,00,74,00,73,00,6f,00,6e,00,00,00,44,00,69,00,73,00,\
6b,00,51,00,75,00,6f,00,74,00,61,00,00,00,63,00,72,00,79,00,70,00,74,00,33,\
00,32,00,00,00,43,00,72,00,65,00,61,00,74,00,69,00,76,00,65,00,20,00,53,00,\
65,00,72,00,76,00,69,00,63,00,65,00,20,00,66,00,6f,00,72,00,20,00,43,00,44,\
00,52,00,4f,00,4d,00,20,00,41,00,63,00,63,00,65,00,73,00,73,00,00,00,43,00,\
4f,00,4d,00,2b,00,00,00,43,00,4f,00,4d,00,00,00,43,00,69,00,00,00,43,00,68,\
00,6b,00,64,00,73,00,6b,00,00,00,41,00,75,00,74,00,6f,00,45,00,6e,00,72,00,\
6f,00,6c,00,6c,00,6d,00,65,00,6e,00,74,00,00,00,41,00,75,00,74,00,6f,00,63,\
00,68,00,6b,00,00,00,41,00,53,00,50,00,2e,00,4e,00,45,00,54,00,20,00,32,00,\
2e,00,30,00,2e,00,35,00,30,00,37,00,32,00,37,00,2e,00,30,00,00,00,41,00,53,\
00,50,00,2e,00,4e,00,45,00,54,00,20,00,31,00,2e,00,31,00,2e,00,34,00,33,00,\
32,00,32,00,2e,00,30,00,00,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,\
00,69,00,6f,00,6e,00,20,00,4d,00,61,00,6e,00,61,00,67,00,65,00,6d,00,65,00,\
6e,00,74,00,00,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,00,6f,\
00,6e,00,20,00,48,00,61,00,6e,00,67,00,00,00,41,00,70,00,70,00,6c,00,69,00,\
63,00,61,00,74,00,69,00,6f,00,6e,00,20,00,45,00,72,00,72,00,6f,00,72,00,00,\
00,41,00,65,00,67,00,69,00,73,00,50,00,00,00,2e,00,4e,00,45,00,54,00,20,00,\
52,00,75,00,6e,00,74,00,69,00,6d,00,65,00,20,00,4f,00,70,00,74,00,69,00,6d,\
00,69,00,7a,00,61,00,74,00,69,00,6f,00,6e,00,20,00,53,00,65,00,72,00,76,00,\
69,00,63,00,65,00,00,00,2e,00,4e,00,45,00,54,00,20,00,52,00,75,00,6e,00,74,\
00,69,00,6d,00,65,00,20,00,32,00,2e,00,30,00,20,00,45,00,72,00,72,00,6f,00,\
72,00,20,00,52,00,65,00,70,00,6f,00,72,00,74,00,69,00,6e,00,67,00,00,00,2e,\
00,4e,00,45,00,54,00,20,00,52,00,75,00,6e,00,74,00,69,00,6d,00,65,00,00,00,\
41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,00,6f,00,6e,00,00,00,00,\
00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\Application\Java VM]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\VXD\JAVASUP]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\VXD\JAVASUP]
"StaticVxD"="JAVASUP.VXD"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment]
"CLASSPATH"=".;C:\\Program Files\\Java\\jre1.6.0_02\\lib\\ext\\QTJava.zip"
"QTJAVA"="C:\\Program Files\\Java\\jre1.6.0_02\\lib\\ext\\QTJava.zip"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application]
; Contents of value:
; WSH
; WMIAdapter
; WmdmPmSN
; wltrysvc
; WinMgmt
; Winlogon
; Windows Product Activation
; Windows 3.1 Migration
; WebClient
; VSS
; VMware Virtual Mount Service Extended
; VMware NAT Service
; vmauthd
; Visual Studio - VsTemplate
; VBRuntime
; vbexpress
; usnjsvc
; Userinit
; Userenv
; Tlntsvr
; TISMessages
; Teradata
; TdatTools
; SysmonLog
; Starter
; SpoolerCtrs
; Software Restriction Policies
; Software Installation
; SmsClient
; SecurityCenter
; SclgNtfy
; SceSrv
; SceCli
; safrslv
; SAFrdms
; Remote Assistance
; PUTPortMgrSvc
; PUTJobSvc
; PUTFileSvc
; PerfProc
; PerfOS
; PerfNet
; Perfmon
; Perflib
; PerfDisk
; Perfctrs
; Outlook
; Offline Files
; Oakley
; ntbackup
; NCRput
; MSSQLSERVER/MSDE
; MSSOAP
; MsiInstaller
; MSDTC Client
; MSDTC
; MSDMine
; mnmsrvc
; Microsoft Visual Basic Express Edition
; Microsoft Office Document Imaging
; Microsoft Office 11
; Microsoft H.323 Telephony Service Provider
; Microsoft Fax
; Microsoft Document Explorer
; Microsoft ® Visual C# 2005 Compiler
; Microsoft ® Visual Basic Compiler
; MDM
; LOGITECH
; LoadPerf
; LiveMeeting
; Java VM
; IntelliPoint
; HelpSvc
; GtwRsrvTdmst
; Folder Redirection
; File Deployment
; expclient
; EventSystem
; ESENT
; ENDFORCE Agent API
; DrWatson
; DiskQuota
; crypt32
; Creative Service for CDROM Access
; COM+
; COM
; Ci
; Chkdsk
; AutoEnrollment
; Autochk
; ASP.NET 2.0.50727.0
; ASP.NET 1.1.4322.0
; Application Management
; Application Hang
; Application Error
; AegisP
; .NET Runtime Optimization Service
; .NET Runtime 2.0 Error Reporting
; .NET Runtime
; Application
;
"Sources"=hex(7):57,00,53,00,48,00,00,00,57,00,4d,00,49,00,41,00,64,00,61,00,\
70,00,74,00,65,00,72,00,00,00,57,00,6d,00,64,00,6d,00,50,00,6d,00,53,00,4e,\
00,00,00,77,00,6c,00,74,00,72,00,79,00,73,00,76,00,63,00,00,00,57,00,69,00,\
6e,00,4d,00,67,00,6d,00,74,00,00,00,57,00,69,00,6e,00,6c,00,6f,00,67,00,6f,\
00,6e,00,00,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,20,00,50,00,72,00,\
6f,00,64,00,75,00,63,00,74,00,20,00,41,00,63,00,74,00,69,00,76,00,61,00,74,\
00,69,00,6f,00,6e,00,00,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,20,00,\
33,00,2e,00,31,00,20,00,4d,00,69,00,67,00,72,00,61,00,74,00,69,00,6f,00,6e,\
00,00,00,57,00,65,00,62,00,43,00,6c,00,69,00,65,00,6e,00,74,00,00,00,56,00,\
53,00,53,00,00,00,56,00,4d,00,77,00,61,00,72,00,65,00,20,00,56,00,69,00,72,\
00,74,00,75,00,61,00,6c,00,20,00,4d,00,6f,00,75,00,6e,00,74,00,20,00,53,00,\
65,00,72,00,76,00,69,00,63,00,65,00,20,00,45,00,78,00,74,00,65,00,6e,00,64,\
00,65,00,64,00,00,00,56,00,4d,00,77,00,61,00,72,00,65,00,20,00,4e,00,41,00,\
54,00,20,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00,76,00,6d,00,61,\
00,75,00,74,00,68,00,64,00,00,00,56,00,69,00,73,00,75,00,61,00,6c,00,20,00,\
53,00,74,00,75,00,64,00,69,00,6f,00,20,00,2d,00,20,00,56,00,73,00,54,00,65,\
00,6d,00,70,00,6c,00,61,00,74,00,65,00,00,00,56,00,42,00,52,00,75,00,6e,00,\
74,00,69,00,6d,00,65,00,00,00,76,00,62,00,65,00,78,00,70,00,72,00,65,00,73,\
00,73,00,00,00,75,00,73,00,6e,00,6a,00,73,00,76,00,63,00,00,00,55,00,73,00,\
65,00,72,00,69,00,6e,00,69,00,74,00,00,00,55,00,73,00,65,00,72,00,65,00,6e,\
00,76,00,00,00,54,00,6c,00,6e,00,74,00,73,00,76,00,72,00,00,00,54,00,49,00,\
53,00,4d,00,65,00,73,00,73,00,61,00,67,00,65,00,73,00,00,00,54,00,65,00,72,\
00,61,00,64,00,61,00,74,00,61,00,00,00,54,00,64,00,61,00,74,00,54,00,6f,00,\
6f,00,6c,00,73,00,00,00,53,00,79,00,73,00,6d,00,6f,00,6e,00,4c,00,6f,00,67,\
00,00,00,53,00,74,00,61,00,72,00,74,00,65,00,72,00,00,00,53,00,70,00,6f,00,\
6f,00,6c,00,65,00,72,00,43,00,74,00,72,00,73,00,00,00,53,00,6f,00,66,00,74,\
00,77,00,61,00,72,00,65,00,20,00,52,00,65,00,73,00,74,00,72,00,69,00,63,00,\
74,00,69,00,6f,00,6e,00,20,00,50,00,6f,00,6c,00,69,00,63,00,69,00,65,00,73,\
00,00,00,53,00,6f,00,66,00,74,00,77,00,61,00,72,00,65,00,20,00,49,00,6e,00,\
73,00,74,00,61,00,6c,00,6c,00,61,00,74,00,69,00,6f,00,6e,00,00,00,53,00,6d,\
00,73,00,43,00,6c,00,69,00,65,00,6e,00,74,00,00,00,53,00,65,00,63,00,75,00,\
72,00,69,00,74,00,79,00,43,00,65,00,6e,00,74,00,65,00,72,00,00,00,53,00,63,\
00,6c,00,67,00,4e,00,74,00,66,00,79,00,00,00,53,00,63,00,65,00,53,00,72,00,\
76,00,00,00,53,00,63,00,65,00,43,00,6c,00,69,00,00,00,73,00,61,00,66,00,72,\
00,73,00,6c,00,76,00,00,00,53,00,41,00,46,00,72,00,64,00,6d,00,73,00,00,00,\
52,00,65,00,6d,00,6f,00,74,00,65,00,20,00,41,00,73,00,73,00,69,00,73,00,74,\
00,61,00,6e,00,63,00,65,00,00,00,50,00,55,00,54,00,50,00,6f,00,72,00,74,00,\
4d,00,67,00,72,00,53,00,76,00,63,00,00,00,50,00,55,00,54,00,4a,00,6f,00,62,\
00,53,00,76,00,63,00,00,00,50,00,55,00,54,00,46,00,69,00,6c,00,65,00,53,00,\
76,00,63,00,00,00,50,00,65,00,72,00,66,00,50,00,72,00,6f,00,63,00,00,00,50,\
00,65,00,72,00,66,00,4f,00,53,00,00,00,50,00,65,00,72,00,66,00,4e,00,65,00,\
74,00,00,00,50,00,65,00,72,00,66,00,6d,00,6f,00,6e,00,00,00,50,00,65,00,72,\
00,66,00,6c,00,69,00,62,00,00,00,50,00,65,00,72,00,66,00,44,00,69,00,73,00,\
6b,00,00,00,50,00,65,00,72,00,66,00,63,00,74,00,72,00,73,00,00,00,4f,00,75,\
00,74,00,6c,00,6f,00,6f,00,6b,00,00,00,4f,00,66,00,66,00,6c,00,69,00,6e,00,\
65,00,20,00,46,00,69,00,6c,00,65,00,73,00,00,00,4f,00,61,00,6b,00,6c,00,65,\
00,79,00,00,00,6e,00,74,00,62,00,61,00,63,00,6b,00,75,00,70,00,00,00,4e,00,\
43,00,52,00,70,00,75,00,74,00,00,00,4d,00,53,00,53,00,51,00,4c,00,53,00,45,\
00,52,00,56,00,45,00,52,00,2f,00,4d,00,53,00,44,00,45,00,00,00,4d,00,53,00,\
53,00,4f,00,41,00,50,00,00,00,4d,00,73,00,69,00,49,00,6e,00,73,00,74,00,61,\
00,6c,00,6c,00,65,00,72,00,00,00,4d,00,53,00,44,00,54,00,43,00,20,00,43,00,\
6c,00,69,00,65,00,6e,00,74,00,00,00,4d,00,53,00,44,00,54,00,43,00,00,00,4d,\
00,53,00,44,00,4d,00,69,00,6e,00,65,00,00,00,6d,00,6e,00,6d,00,73,00,72,00,\
76,00,63,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,\
00,56,00,69,00,73,00,75,00,61,00,6c,00,20,00,42,00,61,00,73,00,69,00,63,00,\
20,00,45,00,78,00,70,00,72,00,65,00,73,00,73,00,20,00,45,00,64,00,69,00,74,\
00,69,00,6f,00,6e,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,\
74,00,20,00,4f,00,66,00,66,00,69,00,63,00,65,00,20,00,44,00,6f,00,63,00,75,\
00,6d,00,65,00,6e,00,74,00,20,00,49,00,6d,00,61,00,67,00,69,00,6e,00,67,00,\
00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,4f,00,66,\
00,66,00,69,00,63,00,65,00,20,00,31,00,31,00,00,00,4d,00,69,00,63,00,72,00,\
6f,00,73,00,6f,00,66,00,74,00,20,00,48,00,2e,00,33,00,32,00,33,00,20,00,54,\
00,65,00,6c,00,65,00,70,00,68,00,6f,00,6e,00,79,00,20,00,53,00,65,00,72,00,\
76,00,69,00,63,00,65,00,20,00,50,00,72,00,6f,00,76,00,69,00,64,00,65,00,72,\
00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,46,00,\
61,00,78,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,\
00,44,00,6f,00,63,00,75,00,6d,00,65,00,6e,00,74,00,20,00,45,00,78,00,70,00,\
6c,00,6f,00,72,00,65,00,72,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,\
00,66,00,74,00,20,00,28,00,52,00,29,00,20,00,56,00,69,00,73,00,75,00,61,00,\
6c,00,20,00,43,00,23,00,20,00,32,00,30,00,30,00,35,00,20,00,43,00,6f,00,6d,\
00,70,00,69,00,6c,00,65,00,72,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,\
6f,00,66,00,74,00,20,00,28,00,52,00,29,00,20,00,56,00,69,00,73,00,75,00,61,\
00,6c,00,20,00,42,00,61,00,73,00,69,00,63,00,20,00,43,00,6f,00,6d,00,70,00,\
69,00,6c,00,65,00,72,00,00,00,4d,00,44,00,4d,00,00,00,4c,00,4f,00,47,00,49,\
00,54,00,45,00,43,00,48,00,00,00,4c,00,6f,00,61,00,64,00,50,00,65,00,72,00,\
66,00,00,00,4c,00,69,00,76,00,65,00,4d,00,65,00,65,00,74,00,69,00,6e,00,67,\
00,00,00,4a,00,61,00,76,00,61,00,20,00,56,00,4d,00,00,00,49,00,6e,00,74,00,\
65,00,6c,00,6c,00,69,00,50,00,6f,00,69,00,6e,00,74,00,00,00,48,00,65,00,6c,\
00,70,00,53,00,76,00,63,00,00,00,47,00,74,00,77,00,52,00,73,00,72,00,76,00,\
54,00,64,00,6d,00,73,00,74,00,00,00,46,00,6f,00,6c,00,64,00,65,00,72,00,20,\
00,52,00,65,00,64,00,69,00,72,00,65,00,63,00,74,00,69,00,6f,00,6e,00,00,00,\
46,00,69,00,6c,00,65,00,20,00,44,00,65,00,70,00,6c,00,6f,00,79,00,6d,00,65,\
00,6e,00,74,00,00,00,65,00,78,00,70,00,63,00,6c,00,69,00,65,00,6e,00,74,00,\
00,00,45,00,76,00,65,00,6e,00,74,00,53,00,79,00,73,00,74,00,65,00,6d,00,00,\
00,45,00,53,00,45,00,4e,00,54,00,00,00,45,00,4e,00,44,00,46,00,4f,00,52,00,\
43,00,45,00,20,00,41,00,67,00,65,00,6e,00,74,00,20,00,41,00,50,00,49,00,00,\
00,44,00,72,00,57,00,61,00,74,00,73,00,6f,00,6e,00,00,00,44,00,69,00,73,00,\
6b,00,51,00,75,00,6f,00,74,00,61,00,00,00,63,00,72,00,79,00,70,00,74,00,33,\
00,32,00,00,00,43,00,72,00,65,00,61,00,74,00,69,00,76,00,65,00,20,00,53,00,\
65,00,72,00,76,00,69,00,63,00,65,00,20,00,66,00,6f,00,72,00,20,00,43,00,44,\
00,52,00,4f,00,4d,00,20,00,41,00,63,00,63,00,65,00,73,00,73,00,00,00,43,00,\
4f,00,4d,00,2b,00,00,00,43,00,4f,00,4d,00,00,00,43,00,69,00,00,00,43,00,68,\
00,6b,00,64,00,73,00,6b,00,00,00,41,00,75,00,74,00,6f,00,45,00,6e,00,72,00,\
6f,00,6c,00,6c,00,6d,00,65,00,6e,00,74,00,00,00,41,00,75,00,74,00,6f,00,63,\
00,68,00,6b,00,00,00,41,00,53,00,50,00,2e,00,4e,00,45,00,54,00,20,00,32,00,\
2e,00,30,00,2e,00,35,00,30,00,37,00,32,00,37,00,2e,00,30,00,00,00,41,00,53,\
00,50,00,2e,00,4e,00,45,00,54,00,20,00,31,00,2e,00,31,00,2e,00,34,00,33,00,\
32,00,32,00,2e,00,30,00,00,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,\
00,69,00,6f,00,6e,00,20,00,4d,00,61,00,6e,00,61,00,67,00,65,00,6d,00,65,00,\
6e,00,74,00,00,00,41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,00,6f,\
00,6e,00,20,00,48,00,61,00,6e,00,67,00,00,00,41,00,70,00,70,00,6c,00,69,00,\
63,00,61,00,74,00,69,00,6f,00,6e,00,20,00,45,00,72,00,72,00,6f,00,72,00,00,\
00,41,00,65,00,67,00,69,00,73,00,50,00,00,00,2e,00,4e,00,45,00,54,00,20,00,\
52,00,75,00,6e,00,74,00,69,00,6d,00,65,00,20,00,4f,00,70,00,74,00,69,00,6d,\
00,69,00,7a,00,61,00,74,00,69,00,6f,00,6e,00,20,00,53,00,65,00,72,00,76,00,\
69,00,63,00,65,00,00,00,2e,00,4e,00,45,00,54,00,20,00,52,00,75,00,6e,00,74,\
00,69,00,6d,00,65,00,20,00,32,00,2e,00,30,00,20,00,45,00,72,00,72,00,6f,00,\
72,00,20,00,52,00,65,00,70,00,6f,00,72,00,74,00,69,00,6e,00,67,00,00,00,2e,\
00,4e,00,45,00,54,00,20,00,52,00,75,00,6e,00,74,00,69,00,6d,00,65,00,00,00,\
41,00,70,00,70,00,6c,00,69,00,63,00,61,00,74,00,69,00,6f,00,6e,00,00,00,00,\
00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Java VM]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VXD\JAVASUP]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VXD\JAVASUP]
"StaticVxD"="JAVASUP.VXD"

[HKEY_CURRENT_USER\Software\ATT\RoamingClient\Acceleration]
"JavascriptEmail"=dword:00000001
"JavascriptWeb"=dword:00000001

[HKEY_CURRENT_USER\Software\ej-technologies\exe4j\jvms\c:/program files/java/j2re1.4.2_03/bin/java.exe]

[HKEY_CURRENT_USER\Software\ej-technologies\exe4j\jvms\c:/program files/java/jre1.5.0_06/bin/java.exe]

[HKEY_CURRENT_USER\Software\Helios\TextPad 4\Document Classes\Java]

[HKEY_CURRENT_USER\Software\Helios\TextPad 4\Document Classes\Java]
; Contents of value:
; *.JAV
; *.JAVA
;
"Members"=hex(7):2a,00,2e,00,4a,00,41,00,56,00,00,00,2a,00,2e,00,4a,00,41,00,\
56,00,41,00,00,00,00,00
"SyntaxFile"="C:\\Program Files\\TextPad 4\\System\\JAVA.SYN"

[HKEY_CURRENT_USER\Software\Helios\TextPad 4\Tools\0]
"MenuText"="Compile Java"
"Command"="javac.exe"

[HKEY_CURRENT_USER\Software\Helios\TextPad 4\Tools\1]
"MenuText"="Run Java Application"
"Command"="java.exe"

[HKEY_CURRENT_USER\Software\Helios\TextPad 4\Tools\2]
"MenuText"="Run Java Applet"

[HKEY_CURRENT_USER\Software\JavaSoft]

[HKEY_CURRENT_USER\Software\JavaSoft\Java Runtime Environment]

[HKEY_CURRENT_USER\Software\JavaSoft\Java Runtime Environment\1.4.2_03]

[HKEY_CURRENT_USER\Software\JavaSoft\Java Runtime Environment\1.5.0_06]

[HKEY_CURRENT_USER\Software\JavaSoft\Java Runtime Environment\1.6.0_02]

[HKEY_CURRENT_USER\Software\JavaSoft\Java Update]

[HKEY_CURRENT_USER\Software\JavaSoft\Java Update\Policy]

[HKEY_CURRENT_USER\Software\JavaSoft\Java2D]

[HKEY_CURRENT_USER\Software\JavaSoft\Java2D\1.5.0_06]

[HKEY_CURRENT_USER\Software\JavaSoft\Java2D\1.5.0_06\Drivers]

[HKEY_CURRENT_USER\Software\JavaSoft\Java2D\1.5.0_06\Drivers\.DISPLAY1 ATI MOBILITY RADEON X300 ]

[HKEY_CURRENT_USER\Software\JavaSoft\Java2D\1.5.0_06\Drivers\.DISPLAY1 ATI MOBILITY RADEON X300 \16]

[HKEY_CURRENT_USER\Software\JavaSoft\Java2D\1.5.0_06\Drivers\.DISPLAY1 ATI MOBILITY RADEON X300 \32]

[HKEY_CURRENT_USER\Software\JavaSoft\Java2D\1.5.0_06\Drivers\.DISPLAYV1 NetMeeting driver]

[HKEY_CURRENT_USER\Software\JavaSoft\Java2D\1.5.0_06\Drivers\.DISPLAYV1 NetMeeting driver\24]

[HKEY_CURRENT_USER\Software\JavaSoft\Java2D\1.6.0_02]

[HKEY_CURRENT_USER\Software\JavaSoft\Java2D\1.6.0_02\Drivers]

[HKEY_CURRENT_USER\Software\JavaSoft\Java2D\1.6.0_02\Drivers\.DISPLAY1 ATI MOBILITY RADEON X300 ]

[HKEY_CURRENT_USER\Software\JavaSoft\Java2D\1.6.0_02\Drivers\.DISPLAY1 ATI MOBILITY RADEON X300 \16]

[HKEY_CURRENT_USER\Software\JavaSoft\Java2D\1.6.0_02\Drivers\.DISPLAY1 ATI MOBILITY RADEON X300 \32]

[HKEY_CURRENT_USER\Software\JavaSoft\Java2D\1.6.0_02\Drivers\.DISPLAY2 ATI MOBILITY RADEON X300 ]

[HKEY_CURRENT_USER\Software\JavaSoft\Java2D\1.6.0_02\Drivers\.DISPLAY2 ATI MOBILITY RADEON X300 \32]

[HKEY_CURRENT_USER\Software\Microsoft\Java VM]

[HKEY_CURRENT_USER\Software\Microsoft\Java VM]
"EnableJavaConsole"=dword:00000000

[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Java\\jre1.6.0_05\\bin\\jusched.exe"="Java™ Platform SE binary"
"C:\\Program Files\\Java\\jre1.6.0_05\\bin\\jucheck.exe"="Java™ Update Checker"

[HKEY_CURRENT_USER\Software\Netscape\Netscape Navigator\User Trusted External Applications]
"\"C:\\Program Files\\Java\\j2re1.4.2_03\\javaws\\javaws.exe\""="Yes"
"\"C:\\Program Files\\Java\\jre1.5.0_06\\bin\\javaws.exe\""="Yes"
"\"C:\\Program Files\\Java\\jre1.6.0_02\\bin\\javaws.exe\""="Yes"

[HKEY_CURRENT_USER\Software\Netscape\Netscape Navigator\Viewers]
"TYPE33"="application/x-java-jnlp-file"
"application/x-java-jnlp-file"="\"C:\\Program Files\\Java\\jre1.6.0_02\\bin\\javaws.exe\""

[HKEY_CURRENT_USER\Software\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
@="Java Plug-in 1.6.0_02"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.0_03"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.0_04"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.0_05"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_01"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_01"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_02"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_02"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_03"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_03"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_04"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_04"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_05"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_05"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_06"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_06"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_07"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_07"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_08"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_08"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_09"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_09"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_10"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_10"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_11"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_11"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_12"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_12"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_13"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_13"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_14"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_14"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_15"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_15"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_16"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_16"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_17"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_17"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_18"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_18"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_19"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_19"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_20"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_20"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_21"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_21"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_22"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_22"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_23"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_23"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_24"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_24"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_25"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_25"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_26"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_26"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_27"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_27"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_28"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_28"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_29"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_29"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}]
@="Java Plug-in 1.3.1_30"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}]
@="Java Plug-in 1.3.1_30"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.0"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.0"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.0_01"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.0_01"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.0_02"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.0_02"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.0_03"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.0_03"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.0_04"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.0_04"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.1"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.1"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.1_01"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.1_01"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.1_02"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.1_02"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.1_03"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.1_03"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.1_04"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.1_04"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.1_05"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.1_05"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.1_06"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.1_06"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.1_07"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.1_07"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_01"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_01"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_02"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_02"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_03"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_03"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_04"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_04"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_05"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_05"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_06"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_06"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_07"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_07"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_08"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_08"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_09"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_09"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_10"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_10"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_11"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_11"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_12"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_12"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_13"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_13"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_14"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_14"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_15"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_15"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_16"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_16"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_17"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_17"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_18"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_18"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_19"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_19"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_20"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_20"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_21"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_21"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_22"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_22"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_23"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_23"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_24"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_24"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_25"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_25"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_26"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_26"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_27"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_27"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_28"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_28"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_29"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_29"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBA}]
@="Java Plug-in 1.4.2_30"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBB}]
@="Java Plug-in 1.4.2_30"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_01"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_01"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_01"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_02"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_02"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_02"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_03"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_03"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_03"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_04"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_04"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_04"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_05"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_05"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_05"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_06"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_06"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_06"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_07"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_07"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_07"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_08"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_08"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_08"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_09"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_09"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_09"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_10"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_10"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_10"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_11"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_11"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_11"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_12"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_12"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_12"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_13"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_13"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_13"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_14"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_14"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_14"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_15"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_15"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_15"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_16"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_16"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_16"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_17"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_17"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_17"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_18"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_18"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_18"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_19"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_19"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_19"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_20"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_20"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_20"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_21"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_21"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_21"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_22"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_22"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_22"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_23"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_23"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_23"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_24"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_24"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_24"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_25"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_25"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_25"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_26"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_26"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_26"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_27"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_27"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_27"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_28"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_28"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_28"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_29"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_29"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_29"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBA}]
@="Java Plug-in 1.5.0_30"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBB}]
@="Java Plug-in 1.5.0_30"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBC}]
@="Java Plug-in 1.5.0_30"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}]
@="Java Plug-in 1.6.0"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBB}]
@="Java Plug-in 1.6.0"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC}]
@="Java Plug-in 1.6.0"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}]
@="Java Plug-in 1.6.0_01"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBB}]
@="Java Plug-in 1.6.0_01"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC}]
@="Java Plug-in 1.6.0_01"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}]
@="Java Plug-in 1.6.0_02"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBB}]
@="Java Plug-in 1.6.0_02"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}]
@="Java Plug-in 1.6.0_02"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{E19F9331-3110-11D4-991C-005004D3B3DB}]
@="Java Plug-in 1.3.0_02"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{E19F9331-3110-11D4-991C-005004D3B3DB}\InprocServer32]
@="C:\\Program Files\\Java\\jre1.6.0_02\\bin\\ssv.dll"

[HKEY_CURRENT_USER\Software\Classes\JavaPlugin.142_03]

[HKEY_CURRENT_USER\Software\Classes\JavaPlugin.142_03\CLSID]

[HKEY_CURRENT_USER\Software\Classes\JavaPlugin.150_06]

[HKEY_CURRENT_USER\Software\Classes\JavaPlugin.150_06\CLSID]

[HKEY_CURRENT_USER\Software\Classes\JavaPlugin.160_02]

[HKEY_CURRENT_USER\Software\Classes\JavaPlugin.160_02\CLSID]

; End Of The Log...

#10 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:06:51 PM

Posted 10 August 2008 - 01:54 PM

Hello, woodyatwork.
Alright.. at this point, don't worry about uninstalling the old versions. We'll delete the files manually and reinstall a fresh copy.

We need to move some files
Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    C:\Program Files\Java\
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt2
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Scroll down to where it says "Java Runtime Environment (JRE)6 Update 7...allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-Language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Reboot your computer.
  • Then from your desktop double-click on jre-6u7-windows-i586-p.exe
  • Follow the on screen instructions to install the latest Java version.
I would like us to use ESET (NOD32)'s Online Scanner
  • Please go to ESET OnlineScan (NOD32)
  • You will then see the Terms of Use, tick the check-box infront of YES, I accept the Terms of Use
  • Now click Start
  • Should you face a Security Warning that asks if you want to install and run a file called "OnlineScanner.cab", click Yes
  • Click Start
    • Note: (the Onlinescanner will now prepare itself for running on your pc)
  • To do a full-scan, tick: "Remove found threats" and "Scan potentially unwanted applications"
  • Press Scan
  • The Onlinescan will now start and scan your pc (this could take a while)
  • When the scan has finished, it will show a screen with two tabs "overview" and "details" and the option to get information or buy software, just close the window
  • Click Start >> Run... >> type: C:\Program Files\EsetOnlineScanner\log.txt
  • The Scanresults will now open in Notepad
  • Click into the text area, right-click and chose "select all" (or use <Control>+A)
  • Right-click again and chose "Copy" (or <Control>+C)
  • Close/Exit Notepad
  • Navigate to this thread and post your log along with anything else requested from us, by right-clicking and "paste" (or ctrl+v) in the text area of the reply post you just created.
Note: For Vista Users: Eset is compatible but Internet Explorer must be run as Administrator. To do this, right-click on the IE icon in the Start Menu or Quick Launch Bar on the Taskbar and select "Run as Administrator" from the context menu.)

Please run Deckard's System Scanner again, this time using these instructions:
(In the event you lost your copy, you can download a new one from here: Deckard's System Scanner)
  • Click on Start, click on Run
  • Copy and paste the following in the open window and then click OK:
    "%userprofile%\desktop\dss.exe" /config
  • This will open up DSS configuration
  • Click on Check All.
  • Click Scan.
    DSS will now run again.
  • Please post back both logs that open in notepad.
    Main.txt and Extra.txt
In your next reply, please include the following:
  • OTMoveIt2's Log
  • ESET OnlineScan's Log
  • DSS's Main.txt
  • DSS's Extra.txt

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#11 woodyatwork

woodyatwork
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:08:51 PM

Posted 10 August 2008 - 08:32 PM

Ok. Here's the deal I ran the eset scanner, but accidentally ended it near the end. It had found and fixed 3 things.

I started it again, and after a couple of hours it was at or near the end and I got a blue screen. It found nothing to fix this time.

There is no log.txt file. I'm going to guess you want me to try again?

Appreciate your help today. Here is everything else you requested.



O2MoveIt2 log

C:\Program Files\Java\jre1.6.0_02\lib\zi\SystemV moved successfully.
C:\Program Files\Java\jre1.6.0_02\lib\zi\Pacific moved successfully.
C:\Program Files\Java\jre1.6.0_02\lib\zi\Indian moved successfully.
C:\Program Files\Java\jre1.6.0_02\lib\zi\Europe moved successfully.
C:\Program Files\Java\jre1.6.0_02\lib\zi\Etc moved successfully.
C:\Program Files\Java\jre1.6.0_02\lib\zi\Australia moved successfully.
C:\Program Files\Java\jre1.6.0_02\lib\zi\Atlantic moved successfully.
C:\Program Files\Java\jre1.6.0_02\lib\zi\Asia moved successfully.
C:\Program Files\Java\jre1.6.0_02\lib\zi\Antarctica moved successfully.
C:\Program Files\Java\jre1.6.0_02\lib\zi\America\North_Dakota moved successfully.
C:\Program Files\Java\jre1.6.0_02\lib\zi\America\Kentucky moved successfully.
C:\Program Files\Java\jre1.6.0_02\lib\zi\America\Indiana moved successfully.
C:\Program Files\Java\jre1.6.0_02\lib\zi\America\Argentina moved successfully.
C:\Program Files\Java\jre1.6.0_02\lib\zi\America moved successfully.
C:\Program Files\Java\jre1.6.0_02\lib\zi\Africa moved successfully.
C:\Program Files\Java\jre1.6.0_02\lib\zi moved successfully.
C:\Program Files\Java\jre1.6.0_02\lib\security moved successfully.
C:\Program Files\Java\jre1.6.0_02\lib\management moved successfully.
C:\Program Files\Java\jre1.6.0_02\lib\images\cursors moved successfully.
C:\Program Files\Java\jre1.6.0_02\lib\images moved successfully.
C:\Program Files\Java\jre1.6.0_02\lib\im moved successfully.
C:\Program Files\Java\jre1.6.0_02\lib\i386 moved successfully.
C:\Program Files\Java\jre1.6.0_02\lib\fonts moved successfully.
C:\Program Files\Java\jre1.6.0_02\lib\ext moved successfully.
C:\Program Files\Java\jre1.6.0_02\lib\deploy moved successfully.
C:\Program Files\Java\jre1.6.0_02\lib\cmm moved successfully.
C:\Program Files\Java\jre1.6.0_02\lib\applet moved successfully.
C:\Program Files\Java\jre1.6.0_02\lib moved successfully.
C:\Program Files\Java\jre1.6.0_02\bin\client moved successfully.
C:\Program Files\Java\jre1.6.0_02\bin moved successfully.
C:\Program Files\Java\jre1.6.0_02 moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2006p\SystemV moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2006p\Pacific moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2006p\Indian moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2006p\Europe moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2006p\Etc moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2006p\Australia moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2006p\Atlantic moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2006p\Asia moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2006p\Antarctica moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2006p\America\North_Dakota moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2006p\America\Kentucky moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2006p\America\Indiana moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2006p\America\Argentina moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2006p\America moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2006p\Africa moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2006p moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2005m\Pacific moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2005m\Indian moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2005m\Europe moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2005m\Etc moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2005m\Australia moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2005m\Atlantic moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2005m\Asia moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2005m\Antarctica moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2005m\America\North_Dakota moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2005m\America\Kentucky moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2005m\America\Indiana moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2005m\America\Argentina moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2005m\America moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2005m\Africa moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi.tzdata2005m moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi\SystemV moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi\Pacific moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi\Indian moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi\Europe moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi\Etc moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi\Australia moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi\Atlantic moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi\Asia moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi\Antarctica moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi\America\North_Dakota moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi\America\Kentucky moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi\America\Indiana moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi\America\Argentina moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi\America moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi\Africa moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\zi moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\security moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\management moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\javaws moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\images\cursors moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\images moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\im moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\i386 moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\fonts moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\ext moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\cmm moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib\applet moved successfully.
C:\Program Files\Java\jre1.5.0_06\lib moved successfully.
C:\Program Files\Java\jre1.5.0_06\bin\client moved successfully.
C:\Program Files\Java\jre1.5.0_06\bin moved successfully.
C:\Program Files\Java\jre1.5.0_06 moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\zi.tzdata2003a\Pacific moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\zi.tzdata2003a\Indian moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\zi.tzdata2003a\Europe moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\zi.tzdata2003a\Etc moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\zi.tzdata2003a\Australia moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\zi.tzdata2003a\Atlantic moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\zi.tzdata2003a\Asia moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\zi.tzdata2003a\Antarctica moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\zi.tzdata2003a\America\North_Dakota moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\zi.tzdata2003a\America\Kentucky moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\zi.tzdata2003a\America\Indiana moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\zi.tzdata2003a\America moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\zi.tzdata2003a\Africa moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\zi.tzdata2003a moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\zi\Pacific moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\zi\Indian moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\zi\Europe moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\zi\Etc moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\zi\Australia moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\zi\Atlantic moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\zi\Asia moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\zi\Antarctica moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\zi\America\North_Dakota moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\zi\America\Kentucky moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\zi\America\Indiana moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\zi\America\Argentina moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\zi\America moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\zi\Africa moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\zi moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\security moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\images\cursors moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\images moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\im moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\i386 moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\fonts moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\ext moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\cmm moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\audio moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib\applet moved successfully.
C:\Program Files\Java\j2re1.4.2_03\lib moved successfully.
C:\Program Files\Java\j2re1.4.2_03\javaws\resources moved successfully.
C:\Program Files\Java\j2re1.4.2_03\javaws moved successfully.
C:\Program Files\Java\j2re1.4.2_03\bin\client moved successfully.
C:\Program Files\Java\j2re1.4.2_03\bin moved successfully.
C:\Program Files\Java\j2re1.4.2_03 moved successfully.
C:\Program Files\Java moved successfully.

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08102008_142747


DSS main.txt

Deckard's System Scanner v20071014.68
Run by sw185041 on 2008-08-10 20:19:33
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
44: 2008-08-11 01:20:18 UTC - RP449 - Deckard's System Scanner Restore Point
43: 2008-08-10 19:41:01 UTC - RP448 - Installed Java™ 6 Update 7
42: 2008-08-10 15:59:19 UTC - RP447 - Removed Java™ 6 Update 3
41: 2008-08-10 15:57:52 UTC - RP446 - Removed Java™ 6 Update 5
40: 2008-08-09 02:57:52 UTC - RP445 - Installed Nokia Connectivity Adapter Cable DKU-5


-- First Restore Point --
1: 2008-06-16 19:25:50 UTC - RP406 - Installed Windows XP KB926239.


Performed disk cleanup.



-- HijackThis (run as sw185041.exe) --------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:22:14 PM, on 8/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\NCR\Tdat\TGTW\06.01.00.12\bin\GtwRsrvTdmst.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\basfipm.exe
C:\WINDOWS\system32\bmwebcfg.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\NCR\BYNET\blmsvc.exe
C:\Program Files\ENDFORCE\AgentAPI.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Teradata\Teradata Manager 13.0\Bin\isservice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Common Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\Program Files\NCR\Tdat\PDE\06.01.00.12\bin\pdeinetd.exe
C:\Program Files\NCR\NCRput\bin\wfxrd.exe
C:\Program Files\NCR\NCRput\bin\putjobd.exe
C:\Program Files\NCR\NCRput\bin\portmgmt.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Common Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\VMware\VMware Player\hqtray.exe
C:\Program Files\ENDFORCE\AgntTray.exe
C:\Program Files\VMware\VMware Player\vmware-authd.exe
C:\Program Files\Boingo\GoBoingo\GoBoingo.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\AT&T\Communication Manager\ATTCM.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Secway\SimpLite-MSN 2.2\SimpLite-MSN.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\TEMP\XYF540.EXE
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Common Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\AT&T\Communication Manager\RcAppSvc.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Common Files\Trend Micro\OfficeScan Client\pccntupd.exe
C:\Program Files\AT&T\Communication Manager\bmctl.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Documents and Settings\sw185041\desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\sw185041.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy-mem60fw.network.fedex.com:3128
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O1 - Hosts: 199.228.192.159 EDWPRDcop1
O1 - Hosts: 199.228.5.48 EDWDEVcop1
O1 - Hosts: 153.64.20.231 partnerscop1 partners
O1 - Hosts: 153.64.208.9 figcop1 fig
O1 - Hosts: 67.161.162.46 PDLinuxcop1 PDLinux
O1 - Hosts: 153.64.209.130 Tobacop1 Toba
O1 - Hosts: 106.1.1.74 hekyl hekylcop1
O1 - Hosts: 106.1.1.71 jekyl jekylcop1
O1 - Hosts: 153.65.185.116 ceres05 ceres05cop1
O1 - Hosts: 153.65.185.117 ceres05 ceres05cop2
O1 - Hosts: 153.65.185.118 ceres05 ceres05cop3
O1 - Hosts: 153.65.185.119 ceres05 ceres05cop4
O1 - Hosts: 106.1.1.79 mcqueen mcqueencop1
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 9\SnagItBHO.dll
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 9\SnagItIEAddin.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [NCR-Netmeeting Check] C:\WINDOWS\NMTRepair.EXE
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Common Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [VMware hqtray] "C:\Program Files\VMware\VMware Player\hqtray.exe"
O4 - HKLM\..\Run: [ENDFORCEAgent] "C:\Program Files\ENDFORCE\AgntTray.exe"
O4 - HKLM\..\Run: [GoBoingo] C:\Program Files\Boingo\GoBoingo\GoBoingo.lnk
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [AT&T Communication Manager] "C:\Program Files\AT&T\Communication Manager\ATTCM.exe" -a
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Simp] C:\Program Files\Secway\SimpLite-MSN 2.2\SimpLite-MSN.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\sw185041\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O14 - IERESET.INF: START_PAGE_URL=http://iis.ncrnet.ncr.com/ncrnet
O15 - Trusted Zone: *.Teradata.com
O15 - ESC Trusted Zone: http://*.ncr.com (HKLM)
O15 - ESC Trusted Zone: http://*.teradata.com (HKLM)
O16 - DPF: {0B0F4127-1B3E-467A-B6C8-571807562DDC} (AuthenticationTD.Authenticate) - http://web.teradatanet.teradata.com/cab/validateTD.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1E1BC012-AC2A-403F-AEE4-A32E1F18986D} - https://www.passwordmanager.ncr.com/psynch/docs/pslogoff.dll
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {4E67B0DB-1CAE-11D2-AD10-02608CA0806B} - http://web.ncrnet.ncr.com/cab/NCRFile.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1216999819520
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} - http://www.infuzer.com/IDC/client/player/isetup1.cab
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/67/install/gtdownls.cab
O16 - DPF: {AA3AE90C-F60E-4FD9-85E0-A00B61AE49B0} - https://myc3.gateway.ncr.com/core/wizards/P...ntMailTools.CAB
O16 - DPF: {BA2A9829-8040-4BF3-BDB6-51512826B68B} (Authentication.Authenticate) - http://web.ncr.com/cab/phonebook.cab
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Plug-in 1.6.0_03) -
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} (Java Plug-in 1.6.0_05) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O16 - DPF: {DD3D661B-E8FA-11D2-A018-00A0C9AD89DF} (Phonebook.Application) - http://web.ncrnet.ncr.com/cab/phonebook.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - https://ncruniversity.webex.com/client/v_my...ing/ieatgpc.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://sslgateway.teradata.com/dana-cached...perSetupSP1.cab
O16 - DPF: {F5131C24-E56D-11CF-B78A-444553540000} - https://myb.gateway.ncr.com/Site0008/html/B...ix/ikcntrls.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = TD.teradata.com
O17 - HKLM\Software\..\Telephony: DomainName = TD.teradata.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = corp.ncr.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = corp.ncr.com,elsegundoca.ncr.com,sandiegoca.ncr.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = TD.teradata.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = corp.ncr.com,elsegundoca.ncr.com,sandiegoca.ncr.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = TD.teradata.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = corp.ncr.com,elsegundoca.ncr.com,sandiegoca.ncr.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = corp.ncr.com,elsegundoca.ncr.com,sandiegoca.ncr.com
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AT&T RcAppSvc (ATTRcAppSvc) - PCTEL - C:\Program Files\AT&T\Communication Manager\RcAppSvc.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\basfipm.exe
O23 - Service: Bytemobile Web Configurator (bmwebcfg) - Bytemobile, Inc. - C:\WINDOWS\system32\bmwebcfg.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\system32\Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Bynet (bynet) - NCR Corporation - C:\Program Files\NCR\BYNET\blmsvc.exe
O23 - Service: ENDFORCE Agent API - ENDFORCE, Inc. - C:\Program Files\ENDFORCE\AgentAPI.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Teradata GTW Reserve Port (GtwRsrvTdmst) - NCR - C:\Program Files\NCR\Tdat\TGTW\06.01.00.12\bin\GtwRsrvTdmst.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Teradata Manager Service (ISService) - Teradata Corporation - C:\Program Files\Teradata\Teradata Manager 13.0\Bin\isservice.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Common Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Common Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: Teradata inetd Service (PdeinetdService) - NCR - C:\Program Files\NCR\Tdat\PDE\06.01.00.12\bin\pdeinetd.exe
O23 - Service: NCR PUT File Service (PUTFileSvc) - Unknown owner - C:\Program Files\NCR\NCRput\bin\wfxrd.exe
O23 - Service: NCR PUT Job Service (PUTJobSvc) - Unknown owner - C:\Program Files\NCR\NCRput\bin\putjobd.exe
O23 - Service: NCR PUT Port Manager Service (PUTPortMgrSvc) - Unknown owner - C:\Program Files\NCR\NCRput\bin\portmgmt.exe
O23 - Service: Teradata RDBMS Initiator (recond) - NCR - C:\Program Files\NCR\Tdat\PDE\06.01.00.12\bin\recond.exe
O23 - Service: TQS Server (TdqmServerService) - Teradata, a division of NCR - C:\Program Files\NCR\Teradata Query Scheduler 12.0\server\tdqmserv.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Common Files\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Player\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

--
End of file - 19112 bytes

-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------

backup-20080810-104357-118 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
backup-20080810-104357-296 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
backup-20080810-104357-306 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy-mem60fw.network.fedex.com:3128
backup-20080810-104357-389 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://rpc1720.daytonoh.ncr.com/registration.html
backup-20080810-104357-481 O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
backup-20080810-104358-287 O9 - Extra button: (no name) - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\system32\shdocvw.dll

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R0 bynetpnp (NCR Bynet Interconnect) - c:\windows\system32\drivers\bynetpnp.sys <Not Verified; NCR Corporation; BYNET Software>
R0 ncrbynet (NCR Bynet Low Latency Interface) - c:\windows\system32\drivers\ncrbynet.sys <Not Verified; NCR Corporation; BYNET Software>
R1 APPDRV - c:\windows\system32\drivers\appdrv.sys <Not Verified; Dell Inc; Application Driver>
R1 NEOFLTR_530_11531 (Juniper Networks TDI Filter Driver (NEOFLTR_530_11531)) - c:\windows\system32\drivers\neofltr_530_11531.sys <Not Verified; Neoteris; Secure Application Manager>
R1 omci (OMCI WDM Device Driver) - c:\windows\system32\drivers\omci.sys <Not Verified; Dell Inc; OMCI Driver>
R1 tcpipBM (Bytemobile Kernel Network Provider) - c:\windows\system32\drivers\tcpipbm.sys <Not Verified; Bytemobile, Inc.; Bytemobile Optimization Client>
R1 Tosrfcom (Bluetooth RFCOMM from TOSHIBA) - c:\windows\system32\drivers\tosrfcom.sys <Not Verified; TOSHIBA Corporation; Bluetooth RFCOMM Driver>
R2 mdmxsdk - c:\windows\system32\drivers\mdmxsdk.sys <Not Verified; Conexant; Diagnostic Interface>
R2 PnMgr - c:\windows\system32\drivers\pnmgr.sys <Not Verified; NCR; Parallel Upgrade Tool>
R2 TM_CFW (Common Firewall Driver) - c:\program files\common files\trend micro\officescan client\tm_cfw.sys <Not Verified; Trend Micro Inc.; Trend Micro Common Firewall Module 1.2>
R3 Eacfilt (Eacfilt Miniport) - c:\windows\system32\drivers\eacfilt.sys <Not Verified; Nortel Networks; Filter Driver for CVC>
R3 GTIPCI21 - c:\windows\system32\drivers\gtipci21.sys <Not Verified; Texas Instruments; Texas Instruments PCI GemCore Based SmartCard Interface>
R3 HSF_DP - c:\windows\system32\drivers\hsf_dp.sys <Not Verified; Conexant Systems, Inc.; SoftK56 Modem Driver>
R3 HSFHWICH - c:\windows\system32\drivers\hsfhwich.sys <Not Verified; Conexant Systems, Inc.; SoftK56 Modem Driver>
R3 IPSECSHM (Nortel IPSECSHM Adapter) - c:\windows\system32\drivers\ipsecw2k.sys <Not Verified; Nortel Networks NA, Inc.; Contivity VPN Client>
R3 PCASp50 (PCASp50 NDIS Protocol Driver) - c:\windows\system32\drivers\pcasp50.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
R3 STAC97 (SigmaTel C-Major Audio) - c:\windows\system32\drivers\stac97.sys <Not Verified; SigmaTel, Inc.; AC'97 Audio Controller with SigmaTel CODEC device driver.>
R3 tosporte (Bluetooth Port Driver from Toshiba) - c:\windows\system32\drivers\tosporte.sys <Not Verified; TOSHIBA Corporation; TOSHIBA Bluetooth Port Emulation Driver>
R3 winachsf - c:\windows\system32\drivers\hsf_cnxt.sys <Not Verified; Conexant Systems, Inc.; SoftK56 Modem Driver>

S3 BrScnUsb (Brother USB Still Image driver) - c:\windows\system32\drivers\brscnusb.sys <Not Verified; Brother Industries Ltd.; Brother MFC Scanner>
S3 BrSerIf (Brother MFC Serial Port Interface WDM Driver) - c:\windows\system32\drivers\brserif.sys <Not Verified; Brother Industries Ltd.; Windows ® Server 2003 DDK driver>
S3 IPSECEXT (Nortel Extranet Access Protocol) - c:\windows\system32\drivers\ipsecw2k.sys <Not Verified; Nortel Networks NA, Inc.; Contivity VPN Client>
S3 Pdesys (PDE Sys Driver) - c:\windows\system32\drivers\pdesys.sys <Not Verified; NCR; opnpde>
S3 toshidpt (TOSHIBA Bluetooth HID port driver) - c:\windows\system32\drivers\toshidpt.sys <Not Verified; TOSHIBA Corporation.; TOSHIBA Bluetooth HID Mini Port Driver>
S3 Tosrfbd (Bluetooth RFBUS from TOSHIBA) - c:\windows\system32\drivers\tosrfbd.sys <Not Verified; TOSHIBA CORPORATION; Bluetooth BUS Driver(WindowsXP,Windows2000)>
S3 Tosrfbnp (Bluetooth RFBNEP from TOSHIBA) - c:\windows\system32\drivers\tosrfbnp.sys <Not Verified; TOSHIBA Corporation; Bluetooth RFBNEP Driver from TOSHIBA>
S3 Tosrfhid (Bluetooth RFHID from TOSHIBA) - c:\windows\system32\drivers\tosrfhid.sys <Not Verified; TOSHIBA Corporation.; Bluetooth HID Driver from TOSHIBA>
S3 tosrfnds (Bluetooth Personal Area Network from TOSHIBA) - c:\windows\system32\drivers\tosrfnds.sys <Not Verified; TOSHIBA Corporation.; Bluetooth BNEP Driver from TOSHIBA>
S3 TosRfSnd (Bluetooth Audio Device (WDM) from TOSHIBA) - c:\windows\system32\drivers\tosrfsnd.sys <Not Verified; TOSHIBA Corporation; Bluetooth Audio Driver>
S3 Tosrfusb (Bluetooth USB Controller) - c:\windows\system32\drivers\tosrfusb.sys <Not Verified; TOSHIBA CORPORATION; Microsoft® Windows NT® Operating System>


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 BAsfIpM (Broadcom ASF IP monitoring service v6.0.4) - c:\windows\system32\basfipm.exe <Not Verified; Broadcom Corp.; Broadcom ASF IP monitoring service>
R2 bmwebcfg (Bytemobile Web Configurator) - "c:\windows\system32\bmwebcfg.exe" <Not Verified; Bytemobile, Inc.; Bytemobile Optimization Client>
R2 bynet - "c:\program files\ncr\bynet\blmsvc.exe" <Not Verified; NCR Corporation; BYNET Software>
R2 ENDFORCE Agent API - "c:\program files\endforce\agentapi.exe" <Not Verified; ENDFORCE, Inc.; ENDFORCE Enterprise>
R2 GtwRsrvTdmst (Teradata GTW Reserve Port) - "c:\program files\ncr\tdat\tgtw\06.01.00.12\bin\gtwrsrvtdmst.exe" <Not Verified; NCR; gateway>
R2 ISService (Teradata Manager Service) - "c:\program files\teradata\teradata manager 13.0\bin\isservice.exe" <Not Verified; Teradata Corporation; Teradata Manager>
R2 NICCONFIGSVC - c:\program files\dell\nicconfigsvc\nicconfigsvc.exe <Not Verified; Dell Inc.; NicConfigSvc>
R2 ntrtscan (OfficeScanNT RealTime Scan) - "c:\program files\common files\trend micro\officescan client\ntrtscan.exe" <Not Verified; Trend Micro Inc.; Trend Micro OfficeScan>
R2 OfcPfwSvc (OfficeScanNT Personal Firewall) - "c:\program files\common files\trend micro\officescan client\ofcpfwsvc.exe" <Not Verified; Trend Micro Inc.; Trend Micro OfficeScan>
R2 PdeinetdService (Teradata inetd Service) - "c:\program files\ncr\tdat\pde\06.01.00.12\bin\pdeinetd.exe" <Not Verified; NCR; opnpde>
R2 PUTFileSvc (NCR PUT File Service) - "c:\program files\ncr\ncrput\bin\wfxrd.exe"
R2 PUTJobSvc (NCR PUT Job Service) - "c:\program files\ncr\ncrput\bin\putjobd.exe"
R2 PUTPortMgrSvc (NCR PUT Port Manager Service) - "c:\program files\ncr\ncrput\bin\portmgmt.exe"
R2 tmlisten (OfficeScanNT Listener) - "c:\program files\common files\trend micro\officescan client\tmlisten.exe" <Not Verified; Trend Micro Inc.; Trend Micro OfficeScan>
R3 ATTRcAppSvc (AT&T RcAppSvc) - "c:\program files\at&t\communication manager\rcappsvc.exe" /n "attrcappsvc" <Not Verified; PCTEL; RcAppSvc>

S3 ExtranetAccess (Contivity VPN Service) - "c:\program files\nortel networks\extranet_serv.exe" <Not Verified; Nortel Networks NA, Inc.; Nortel Networks Contivity VPN Client>
S3 recond (Teradata RDBMS Initiator) - "c:\program files\ncr\tdat\pde\06.01.00.12\bin\recond.exe" "-s" <Not Verified; NCR; opnpde>
S3 TdqmServerService (TQS Server) - "c:\program files\ncr\teradata query scheduler 12.0\server\tdqmserv.exe" <Not Verified; Teradata, a division of NCR; Teradata Query Scheduler>


-- Device Manager: Disabled ----------------------------------------------------

Class GUID: {6BDD1FC5-810F-11D0-BEC7-08002BE2092F}
Description: SMC IrCC - Fast Infrared Port
Device ID: ACPI\SMCF010\4&15F2F7D1&0
Manufacturer: SMC
Name: SMC IrCC - Fast Infrared Port
PNP Device ID: ACPI\SMCF010\4&15F2F7D1&0
Service: SMCIRDA


-- Process Modules -------------------------------------------------------------

C:\WINDOWS\system32\winlogon.exe (pid 700)
2005-05-13 03:43:54 46080 --a------ C:\WINDOWS\system32\ati2evxx.dll <Not Verified; ATI Technologies Inc.; ATI External Event Utility for NT, W2K and W9X>

C:\WINDOWS\system32\svchost.exe (pid 236)
2008-03-06 16:01:36 421888 --a------ C:\WINDOWS\system32\bmnet.dll <Not Verified; Bytemobile, Inc.; Bytemobile Optimization Client>

C:\WINDOWS\explorer.exe (pid 1604)
2008-07-24 10:22:39 162816 --a------ C:\Program Files\Google\Google Desktop Search\GoogleDesktopDeskbar2.dll <Not Verified; Google; Google Desktop>
2008-07-24 10:22:18 566784 --a------ C:\Program Files\Google\Google Desktop Search\GoogleDesktopResources_en.dll <Not Verified; Google; Google Desktop>
2008-07-24 10:22:39 203776 --a------ C:\Program Files\Google\Google Desktop Search\GoogleDesktopCommon.dll <Not Verified; Google; Google Desktop>
2008-07-24 10:22:39 135168 --a------ C:\Program Files\Google\Google Desktop Search\GoogleDesktopHyper.dll <Not Verified; Google; Google Desktop>
2007-03-10 05:39:52 98304 --a------ C:\Program Files\Secway\SimpLite-MSN 2.2\Plugins\WinsockHookDLL.dll
2005-07-26 19:46:42 69632 --a------ C:\Program Files\Dell\QuickSet\dadkeyb.dll

C:\WINDOWS\system32\rundll32.exe (pid 3816)
2007-03-10 05:39:52 98304 --a------ C:\Program Files\Secway\SimpLite-MSN 2.2\Plugins\WinsockHookDLL.dll


-- Scheduled Tasks -------------------------------------------------------------

2008-05-23 11:12:23 398 --a------ C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job
2008-05-23 11:12:23 276 --a------ C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job


-- Files created between 2008-07-10 and 2008-08-10 -----------------------------

2008-08-10 14:47:53 0 d-------- C:\Program Files\EsetOnlineScanner
2008-08-10 14:41:12 0 d-------- C:\Program Files\Java
2008-08-10 14:32:30 0 dr-h----- C:\Documents and Settings\sw185041\Recent
2008-08-10 12:56:34 0 d-------- C:\regsearch
2008-08-10 10:37:38 0 d-------- C:\Program Files\Trend Micro
2008-08-08 22:03:58 0 d-------- C:\Documents and Settings\sw185041\Application Data\AT&T
2008-08-08 22:01:51 0 d-------- C:\Documents and Settings\NetworkService\Application Data\Bytemobile
2008-08-08 21:58:01 0 d-------- C:\Documents and Settings\LocalService\Application Data\Bytemobile
2008-08-08 21:57:53 89728 --a------ C:\WINDOWS\system32\drivers\usbvsp.sys <Not Verified; Atmel Corporation; Atmel USB Serial Adapter>
2008-08-08 21:57:36 0 d-------- C:\Documents and Settings\sw185041\Application Data\DBUpdater
2008-08-08 21:52:35 0 d-------- C:\Program Files\Common Files\Research in Motion
2008-08-08 21:52:34 0 d-------- C:\Program Files\AT&T
2008-08-08 21:52:34 0 d-------- C:\Documents and Settings\All Users\Application Data\AT&T
2008-08-08 21:51:36 0 d-------- C:\Program Files\Option
2008-08-08 21:50:50 0 d-------- C:\Program Files\Common Files\Motorola Shared
2008-08-08 21:48:42 0 d-------- C:\Program Files\Sierra Wireless Inc
2008-08-08 21:48:42 0 d-------- C:\Documents and Settings\sw185041\Application Data\Sierra Wireless
2008-08-07 11:59:27 0 d-------- C:\MyWorkData
2008-08-06 13:07:36 0 d-------- C:\Documents and Settings\All Users\Application Data\Teradata
2008-08-06 11:34:11 25600 --a------ C:\WINDOWS\system32\drivers\pnmgr.sys <Not Verified; NCR; Parallel Upgrade Tool>
2008-08-06 11:14:52 0 d-------- C:\td12software
2008-08-06 10:35:08 0 d-------- C:\Program Files\Teradata
2008-07-30 11:52:42 0 d-------- C:\Documents and Settings\sw185041\Application Data\acccore
2008-07-30 11:51:02 0 d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-07-30 11:50:53 0 d-------- C:\Documents and Settings\All Users\Application Data\acccore
2008-07-30 11:49:41 0 d-------- C:\Documents and Settings\All Users\Application Data\AOL
2008-07-30 11:49:41 0 d-------- C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-07-30 11:48:19 0 d-------- C:\Program Files\Common Files\AOL
2008-07-30 11:48:04 0 d-------- C:\Program Files\AIM6
2008-07-30 11:19:10 0 d-------- C:\Program Files\Trillian
2008-07-25 12:52:59 0 d-------- C:\Documents and Settings\sw185041\Application Data\WinRAR
2008-07-25 10:54:36 0 d-------- C:\Documents and Settings\sw185041\Application Data\Media Player Classic
2008-07-25 10:48:53 0 d-------- C:\Program Files\XP Codec Pack
2008-07-25 07:21:44 0 d-------- C:\Documents and Settings\All Users\Application Data\TechSmith
2008-07-25 07:21:34 0 d-------- C:\Program Files\TechSmith
2008-07-24 16:58:48 0 d-------- C:\Program Files\ToniArts
2008-07-24 16:34:21 0 d-------- C:\Program Files\RegScrubXP
2008-07-23 11:11:58 0 d-------- C:\Program Files\Panda Security
2008-07-20 21:31:37 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-20 21:31:21 0 d-------- C:\Program Files\SUPERAntiSpyware


-- Find3M Report ---------------------------------------------------------------

2008-08-10 19:14:53 0 d-------- C:\Program Files\ENDFORCE
2008-08-10 14:33:09 12 --a------ C:\WINDOWS\bthservsdp.dat
2008-08-08 21:57:52 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-08-08 21:52:35 0 d-------- C:\Program Files\Common Files
2008-08-07 14:43:36 0 d-------- C:\Program Files\oneworldflights
2008-08-06 19:05:06 0 d-------- C:\Program Files\NCR
2008-08-01 02:00:03 0 d-------- C:\Documents and Settings\sw185041\Application Data\Mozilla
2008-07-25 14:16:20 0 d-------- C:\Documents and Settings\sw185041\Application Data\uTorrent
2008-07-25 07:20:00 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-24 10:22:09 0 d-------- C:\Program Files\Google
2008-07-23 15:20:12 0 d-------- C:\Documents and Settings\sw185041\Application Data\VMware
2008-07-23 12:48:51 0 d-------- C:\Documents and Settings\sw185041\Application Data\Yahoo!
2008-07-23 10:57:19 0 d-------- C:\Program Files\Yahoo!
2008-07-07 18:20:59 0 d-------- C:\Program Files\Add-in Express
2008-07-05 05:14:48 456192 --a------ C:\WINDOWS\system32\libmplayer.dll
2008-07-05 05:14:44 3591168 --a------ C:\WINDOWS\system32\libavcodec.dll
2008-07-05 05:13:16 708096 --a------ C:\WINDOWS\system32\ff_x264.dll
2008-06-22 11:34:00 177664 --a------ C:\WINDOWS\system32\ff_theora.dll
2008-06-13 05:39:38 23552 --a------ C:\WINDOWS\system32\ff_wmv9.dll
2008-06-12 12:36:38 7680 --a------ C:\WINDOWS\system32\ff_vfw.dll
2008-06-12 11:25:06 962560 --a------ C:\WINDOWS\system32\VSFilter.dll <Not Verified; Gabest; VSFilter>


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [05/12/2005 10:00 PM]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [09/01/2005 06:24 PM]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [04/26/2004 09:04 AM]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [12/06/2004 02:05 AM]
"NCR-Netmeeting Check"="C:\WINDOWS\NMTRepair.EXE" [01/03/2006 02:41 PM]
"ControlCenter2.0"="C:\Program Files\Brother\ControlCenter2\brctrcen.exe" [07/20/2004 09:34 AM]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [07/19/2005 05:32 PM]
"OfficeScanNT Monitor"="C:\Program Files\Common Files\Trend Micro\OfficeScan Client\pccntmon.exe" [01/08/2007 07:20 PM]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [03/23/2005 06:26 PM]
"BluetoothAuthenticationAgent"="bthprops.cpl" [08/04/2004 06:00 AM C:\WINDOWS\system32\bthprops.cpl]
"VMware hqtray"="C:\Program Files\VMware\VMware Player\hqtray.exe" [05/01/2007 10:46 PM]
"ENDFORCEAgent"="C:\Program Files\ENDFORCE\AgntTray.exe" [06/27/2007 11:35 PM]
"GoBoingo"="C:\Program Files\Boingo\GoBoingo\GoBoingo.lnk" [08/10/2008 07:12 PM]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" []
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [07/24/2008 10:22 AM]
"@"="" []
"AT&T Communication Manager"="C:\Program Files\AT&T\Communication Manager\ATTCM.exe" [05/01/2008 10:06 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [06/10/2008 04:27 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 06:00 AM]
"Simp"="C:\Program Files\Secway\SimpLite-MSN 2.2\SimpLite-MSN.exe" [08/28/2007 07:29 PM]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" [11/13/2006 01:39 PM]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [07/07/2008 09:42 AM]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [06/19/2008 12:51 PM]

C:\Documents and Settings\sw185041\Start Menu\Programs\Startup\
Yahoo! Widgets.lnk - C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe [12/11/2007 5:34:48 PM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [6/16/2005 11:11:42 AM]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [3/6/2006 1:25:01 AM]
Status Monitor.lnk - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe [4/7/2006 8:36:48 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoToolbarCustomize"=0 (0x0)
"NoBandCustomize"=0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoWindowsUpdate"=1 (0x1)
"ClearRecentDocsOnExit"=01000000
"NoRecentDocsHistory"=01000000
"NoRecentDocsNetHood"=01000000
"NoSMMyPictures"=01000000
"NoRecentDocsMenu"=01000000

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktop"=0 (0x0)
"NoActiveDesktopChanges"=0 (0x0)
"NoInternetIcon"=0 (0x0)
"NoDesktop"=0 (0x0)
"Btn_Back"=0 (0x0)
"Btn_Forward"=0 (0x0)
"Btn_Stop"=0 (0x0)
"Btn_Refresh"=0 (0x0)
"Btn_Home"=0 (0x0)
"Btn_Search"=0 (0x0)
"Btn_History"=0 (0x0)
"Btn_Favorites"=0 (0x0)
"Btn_Media"=0 (0x0)
"Btn_Folders"=0 (0x0)
"Btn_Fullscreen"=0 (0x0)
"Btn_Tools"=0 (0x0)
"Btn_MailNews"=0 (0x0)
"Btn_Size"=0 (0x0)
"Btn_Print"=0 (0x0)
"Btn_Edit"=0 (0x0)
"Btn_Discussions"=0 (0x0)
"Btn_Cut"=0 (0x0)
"Btn_Copy"=0 (0x0)
"Btn_Paste"=0 (0x0)
"Btn_Encoding"=0 (0x0)
"Btn_PrintPreview"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rstrui.exe]
debugger=C:\WINDOWS\system32\Restore\profhlp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
C:\Program Files\Apoint\Apoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
"C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
"C:\Program Files\Logitech\Video\ManifestEngine.exe" boot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
C:\Program Files\Logitech\Video\ISStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
C:\Program Files\Logitech\Video\LogiTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
"C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
"C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{15ba22fe-81d3-11dc-b14b-0016ce0b2c30}]
AutoRun\command- E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{38ff5f1b-64d1-11dd-b169-005056c00008}]
AutoRun\command- E:\WIN\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6847d974-c525-11db-b11a-444553544200}]
AutoRun\command- setupSNK.exe




-- Hosts -----------------------------------------------------------------------

127.0.0.1 localhost TDLTCOP1
199.228.192.159 EDWPRDcop1
199.228.5.48 EDWDEVcop1
153.64.20.231 partnerscop1 partners
153.64.208.9 figcop1 fig
67.161.162.46 PDLinuxcop1 PDLinux
153.64.209.130 Tobacop1 Toba
106.1.1.74 hekyl hekylcop1
106.1.1.71 jekyl jekylcop1
153.65.185.116 ceres05 ceres05cop1

3 more entries in hosts file.


-- End of Deckard's System Scanner: finished at 2008-08-10 20:24:22 ------------



DSS extra.txt

Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: Intel® Pentium® M processor 1.73GHz
Percentage of Memory in Use: 58%
Physical Memory (total/avail): 1023.36 MiB / 420.98 MiB
Pagefile Memory (total/avail): 2462.69 MiB / 1837.13 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1893.91 MiB

C: is Fixed (NTFS) - 37.18 GiB total, 5.53 GiB free.
D: is CDROM (No Media)
T: is Network (Unformatted)

\\.\PHYSICALDRIVE0 - Hitachi HTS541040G9AT00 - 37.26 GiB - 2 partitions
\PARTITION0 - Unknown - 62.72 MiB
\PARTITION1 (bootable) - Installable File System - 37.18 GiB - C:



-- Security Center -------------------------------------------------------------

AUOptions is disabled.
AUState says computer has updates disabled.
Windows Internal Firewall is enabled.

FirstRunDisabled is set.

FW: Trend Micro OfficeScan Enterprise Client Firewall v7.3 (TrendFirewall)

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\Yahoo!\\Yahoo! Music Engine\\YahooMusicEngine.exe"="C:\\Program Files\\Yahoo!\\Yahoo! Music Engine\\YahooMusicEngine.exe:*:Enabled:Yahoo! Music Engine"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\\Program Files\\Neoteris\\Secure Application Manager\\dsSamProxy.exe"="C:\\Program Files\\Neoteris\\Secure Application Manager\\dsSamProxy.exe:*:Enabled:Secure Application Manager Proxy"
"C:\\Program Files\\Microsoft Office\\OFFICE11\\POWERPNT.EXE"="C:\\Program Files\\Microsoft Office\\OFFICE11\\POWERPNT.EXE:*:Enabled:Microsoft Office PowerPoint"
"C:\\Program Files\\Secway\\SimpLite-MSN 2.2\\SimpLite-MSN.exe"="C:\\Program Files\\Secway\\SimpLite-MSN 2.2\\SimpLite-MSN.exe:*:Enabled:SimpLite-MSN"
"C:\\Documents and Settings\\sw185041\\My Documents\\My Videos\\utorrent.exe"="C:\\Documents and Settings\\sw185041\\My Documents\\My Videos\\utorrent.exe:*:Enabled:µTorrent"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\AIM6\\aim6.exe"="C:\\Program Files\\AIM6\\aim6.exe:*:Enabled:AIM"
"C:\\Documents and Settings\\sw185041\\Local Settings\\Temp\\install\\Setup.exe"="C:\\Documents and Settings\\sw185041\\Local Settings\\Temp\\install\\Setup.exe:*:Enabled:Setup"
"C:\\linksys\\Setup.exe"="C:\\linksys\\Setup.exe:*:Enabled:Setup"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\sw185041\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.6.0_02\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=WUSSW185041-HZ6
ComSpec=C:\WINDOWS\system32\cmd.exe
COPLIB=C:\Program Files\Teradata\Client\13.0\CLIv2\
DataConnectorLibPath=C:\WINDOWS\system32\
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\sw185041
LOGONSERVER=\\SUSSAN140
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\Program Files\Teradata\Client\13.0\ODBC Driver for Teradata\Lib;C:\Program Files\Teradata\Client\13.0\CLIv2\;C:\Program Files\NCR\Teradata Parallel Transporter\8.1\bin;C:\Program Files\NCR\Teradata Parallel Transporter\8.1\msg;C:\Program Files\NCR\Teradata Client\WinCLI-Runtime\;C:\Program Files\NCR\Teradata Client\DevKit\;C:\Program Files\NCR\Teradata Client\Bin;C:\WINDOWS\system32\;C:\WINDOWS\system32\;C:\Program Files\NCR\Teradata Client\cliv2\;C:\Program Files\NCR\Common Files\Shared ICU Libraries for Teradata\lib;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\NCR\BYNET\;C:\Program Files\NCR\Tdat\LPDE\bin;C:\Program Files\Common Files\GTK\2.0\bin;C:\WINDOWS\system32\;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Teradata\Client\13.0\Shared ICU Libraries for Teradata\lib\;C:\ORAWIN95\BIN
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 13 Stepping 8, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0d08
ProgramFiles=C:\Program Files
PROMPT=$P$G
PutRootDir=C:\Program Files\NCR\NCRput\
QTJAVA=C:\Program Files\Java\jre1.6.0_02\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\sw185041\LOCALS~1\Temp
TMP=C:\DOCUME~1\sw185041\LOCALS~1\Temp
TWB_ROOT=C:\Program Files\NCR\Teradata Parallel Transporter\8.1
USERDNSDOMAIN=TD.TERADATA.COM
USERDOMAIN=TD
USERNAME=sw185041
USERPROFILE=C:\Documents and Settings\sw185041
VCToolkitInstallDir=C:\Program Files\Microsoft Visual C++ Toolkit 2003\
windir=C:\WINDOWS
_MSGCATLOCATION=C:\Program Files\NCR\Teradata Parallel Transporter\8.1\msg


-- User Profiles ---------------------------------------------------------------

sw185041 (admin)
sw185041 (new local, admin)
migtd (new local)
Administrator (admin)
sw185041 (admin)


-- Add/Remove Programs ---------------------------------------------------------

--> C:\WINDOWS\system32CPMailUninstall.exe changepointmailtools.dll {AA3AE90C-F60E-4FD9-85E0-A00B61AE49B0}
.NET Data Provider for Teradata 12.00.00.01 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{1457B3F3-289F-40E4-9C37-7A8519E1AABF} /l1033
.Net Data Provider For Teradata Help --> MsiExec.exe /I{F64898F5-FCCD-449F-9BD2-4D33FF700960}
_Teradata License for Microsoft Office 2003 Standard --> Not available
Abacast Client --> C:\Documents and Settings\sw185041\Local Settings\Application Data\Abacast\uninst.exe
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 8.1.2 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
AIM 6 --> C:\Program Files\AIM6\uninst.exe
AT&T Communication Manager --> MsiExec.exe /X{443027F6-2A85-4ACE-B4E8-5F44C02EA301}
Changepoint Mail Tools --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7090BD99-CCD0-43B5-A211-E7FEBBB4C988}\setup.exe" -l0x9 -uninst -removeonly
Cisco MeetingPlace for Outlook --> RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\MPOUTL.INF, DefaultUninstall.ntx86
Compatibility Pack for the 2007 Office system --> MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
Driver Installer --> MsiExec.exe /X{753D852A-D86D-42C9-9978-40AE66FB8985}
Easy PC Asset Information --> Not Available
EasyCleaner --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F5346614-B7C4-4E94-826A-E2363155233D}\setup.exe" -l0x9 -removeonly
ESET Online Scanner --> C:\WINDOWS\system32\OnlineScannerUninstaller.exe
GoBoingo! --> MsiExec.exe /X{12723C3A-0FF8-4A0C-8BD3-DC958F388F67}
Google Desktop --> C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Java™ 6 Update 7 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Microsoft ActiveSync --> MsiExec.exe /I{99052DB7-9592-4522-A558-5417BBAD48EE}
Microsoft MSDN 2005 Express Edition - ENU --> C:\Program Files\Microsoft Visual Studio 8\Microsoft MSDN 2005 Express Edition - ENU\install.exe
Microsoft Office Live Meeting 2005 --> MsiExec.exe /I{25A0133B-8BAC-4E61-8F43-DC6D9D9FE80B}
Microsoft Office Live Meeting 2007 --> MsiExec.exe /I{7DB92914-0A00-48C6-8DBB-F8E9D02B78B1}
Microsoft Office Standard Edition 2003 --> MsiExec.exe /I{90120409-6000-11D3-8CFE-0150048383C9}
Microsoft Visual Basic 2005 Express Edition - ENU --> C:\Program Files\Microsoft Visual Studio 8\Microsoft Visual Basic 2005 Express Edition - ENU\setup.exe
Microsoft Visual Basic 2005 Express Edition - ENU --> MsiExec.exe /X{577AD794-8B34-40B4-9E7A-BE4CFFE396E6}
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Motorola Driver Installation --> MsiExec.exe /I{9579E862-5FC7-4337-B1CC-5E37451524C5}
Mozilla Firefox (2.0.0.16) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
My Sirius Studio --> C:\Program Files\Sirius\MySiriusStudio\Uninstall.exe
NCRput --> MsiExec.exe /I{989B0C1F-8BDC-46BF-B122-FDCC7C35A2CE}
Nokia Connectivity Adapter Cable DKU-5 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F1BA3CD5-89DC-4273-8603-A75F33E9B335}\Setup.exe" -l0x9
ODBC Driver for Teradata 13g.0 --> MsiExec.exe /I{BA8904B8-B5B1-47FE-A243-EFABA06EBC56}
oggcodecs 0.71.0946 --> C:\Program Files\illiminable\oggcodecs\uninst.exe
Panda ActiveScan 2.0 --> C:\Program Files\Panda Security\ActiveScan 2.0\as2uninst.exe
QuickTime --> MsiExec.exe /I{E0D51394-1D45-460A-B62D-383BC4F8B335}
RegScrubXP 3.25 --> "C:\Program Files\RegScrubXP\unins000.exe"
Shared ICU Libraries for Teradata 13e.0 --> MsiExec.exe /I{7AACD0B1-74BB-4DF1-869C-15767BB8C573}
SnagIt 9 --> MsiExec.exe /I{59991D18-A988-45AB-B1BF-5ADE6E64CD3F}
Spybot - Search & Destroy --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Teradata Administrator 13.0 --> MsiExec.exe /I{3A7CCC8B-F674-4577-9128-2A5B1AA53584}
Teradata CLIv2 13h.0 --> MsiExec.exe /I{0DF8B969-B0F6-4675-848A-ABED5CD2418D}
Teradata Data Connector 12.0.0.2 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{69FE15A5-550A-406D-83A9-DD23F960BEBF}
Teradata Dynamic Workload Manager --> MsiExec.exe /I{E9573FBB-208E-4B70-9788-EB28291A05F1}
Teradata Dynamic Workload Manager 13.0 --> "C:\Program Files\InstallShield Installation Information\{E9573FBB-208E-4B70-9788-EB28291A05F1}\setup.exe" -runfromtemp -l0x0409 -removeonly
Teradata GSS Client nt-i386 --> MsiExec.exe /I{839F0FD8-78AC-4314-BF32-998CD5A522F9}
Teradata Manager --> MsiExec.exe /I{34322408-B4AE-44DD-BBAD-3895A88D9198}
Teradata Manager 13.0 --> "C:\Program Files\InstallShield Installation Information\{34322408-B4AE-44DD-BBAD-3895A88D9198}\setup.exe" -runfromtemp -l0x0409 -removeonly
Teradata Screensaver Screensaver --> C:\Program Files\MainSail\Teradata Screensaver\Uninstall.exe
Teradata WinCLI Runtime Interface 3.2.11f --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{780AE91E-5004-45BB-9688-999A29584CF6}
Teradata Workload Analyzer --> MsiExec.exe /I{BC0E7108-A233-408B-90E1-C9BFCED41162}
Teradata Workload Analyzer 13.0 --> "C:\Program Files\InstallShield Installation Information\{BC0E7108-A233-408B-90E1-C9BFCED41162}\setup.exe" -runfromtemp -l0x0409 -removeonly
Trim Spaces for Microsoft Excel 1.1 --> "C:\Program Files\Add-in Express\AddIns\Trim Spaces for Excel\unins000.exe"
Windows Driver Package - Microsoft Corporation (usbvideo) Image (05/25/2007 1.0.3656.0) --> rundll32.exe C:\PROGRA~1\DIFX\7AA84A78695B31A503D9537A76801D74E0FD14BD\DIFxAppA.dll, DIFxARPUninstallDriverPackage C:\WINDOWS\system32\DRVSTORE\RoundTable_F29D632BDCC1844B9B7688A0A4B4DA9E716B76FF\RoundTable.inf
Windows Imaging Component --> "C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
XP Codec Pack --> C:\Program Files\XP Codec Pack\Uninstall.exe
Yahoo! Install Manager --> C:\WINDOWS\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL
Yahoo! Widgets --> C:\PROGRA~1\Yahoo!\Widgets\uninstall.exe


-- Application Event Log -------------------------------------------------------

Event Record #/Type24362 / Error
Event Submitted/Written: 08/10/2008 07:13:12 PM
Event ID/Source: 15 / AutoEnrollment
Event Description:
Automatic certificate enrollment for local system failed to contact the active directory (0x8007054b). The specified domain either does not exist or could not be contacted.
Enrollment will not be performed.

Event Record #/Type24358 / Error
Event Submitted/Written: 08/10/2008 07:12:01 PM
Event ID/Source: 1054 / Userenv
Event Description:
Windows cannot obtain the domain controller name for your computer network. (The specified domain either does not exist or could not be contacted. ). Group Policy processing aborted.

Event Record #/Type24357 / Error
Event Submitted/Written: 08/10/2008 07:12:01 PM
Event ID/Source: 1054 / Userenv
Event Description:
Windows cannot obtain the domain controller name for your computer network. (The specified domain either does not exist or could not be contacted. ). Group Policy processing aborted.

Event Record #/Type24347 / Error
Event Submitted/Written: 08/10/2008 02:36:00 PM
Event ID/Source: 15 / AutoEnrollment
Event Description:
Automatic certificate enrollment for local system failed to contact the active directory (0x8007054b). The specified domain either does not exist or could not be contacted.
Enrollment will not be performed.

Event Record #/Type24342 / Error
Event Submitted/Written: 08/10/2008 02:34:51 PM
Event ID/Source: 1054 / Userenv
Event Description:
Windows cannot obtain the domain controller name for your computer network. (The specified domain either does not exist or could not be contacted. ). Group Policy processing aborted.



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type111985 / Error
Event Submitted/Written: 08/10/2008 08:22:49 PM
Event ID/Source: 7016 / Service Control Manager
Event Description:
The BrSplService service has reported an invalid current state 0.

Event Record #/Type111984 / Error
Event Submitted/Written: 08/10/2008 08:04:13 PM
Event ID/Source: 29 / W32Time
Event Description:
The time provider NtpClient is configured to acquire time from one or more
time sources, however none of the sources are currently accessible.
No attempt to contact a source will be made for 59 minutes.
NtpClient has no source of accurate time.

Event Record #/Type111983 / Warning
Event Submitted/Written: 08/10/2008 08:04:13 PM
Event ID/Source: 14 / W32Time
Event Description:
The time provider NtpClient was unable to find a domain controller to use as a time
source. NtpClient will try again in 60 minutes.

Event Record #/Type111982 / Error
Event Submitted/Written: 08/10/2008 07:34:13 PM
Event ID/Source: 29 / W32Time
Event Description:
The time provider NtpClient is configured to acquire time from one or more
time sources, however none of the sources are currently accessible.
No attempt to contact a source will be made for 29 minutes.
NtpClient has no source of accurate time.

Event Record #/Type111981 / Warning
Event Submitted/Written: 08/10/2008 07:34:13 PM
Event ID/Source: 14 / W32Time
Event Description:
The time provider NtpClient was unable to find a domain controller to use as a time
source. NtpClient will try again in 30 minutes.



-- End of Deckard's System Scanner: finished at 2008-08-10 20:24:22 ------------

#12 woodyatwork

woodyatwork
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:08:51 PM

Posted 11 August 2008 - 06:42 AM

Eset ran last night:

# version=4
# OnlineScanner.ocx=1.0.0.635
# OnlineScannerDLLA.dll=1, 0, 0, 79
# OnlineScannerDLLW.dll=1, 0, 0, 78
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3344 (20080810)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.066 (20070917)
# EOSSerial=4599038eaf2f63488402506585991565
# end=finished
# remove_checked=true
# unwanted_checked=true
# utc_time=2008-08-11 06:58:38
# local_time=2008-08-11 01:58:38 (-0600, Central Daylight Time)
# country="United States"
# osver=5.1.2600 NT Service Pack 2
# scanned=3314526
# found=0
# scan_time=13969

#13 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:06:51 PM

Posted 11 August 2008 - 08:51 AM

Hello, woodyatwork.

Almost there :thumbsup:

You appear to have a Registry Cleaner installed!
The following is referring to EasyCleaner, RegScrubXP 3.25
Please be aware that bleepingcomputer staff do not recommend the usage of registry cleaners / tools due to the following facts:
  • Registry tools can cause irreparable damage to your Operating System
  • Registry tools can, as a result of the above, render your pc to be inoperable.
This is done, assuming that the major audience here at this board might be inexperienced users and thus a suggested safeguard from our side.
If you feel you have the need for a registry cleaner, then you are just as welcome to keep it. This is what we refer to an "optional fix" and is up to the user, so just take this as a recommendation from my side.

We have to remove some entries in HiJack This
  • Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below:
    O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Plug-in 1.6.0_03) -
    O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} (Java Plug-in 1.6.0_05) -
    O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
  • Close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.
We need to move some files
Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\NoWindowsUpdate
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\ClearRecentDocsOnExit
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\NoRecentDocsHistory
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\NoRecentDocsNetHood
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\NoSMMyPictures
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\NoRecentDocsMenu
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt2
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Your Microsoft Windows installation is out of date.
Whenever a security problem in its software is found, Microsoft will usually create a patch for it. After the patch is installed, attackers can't use the vulnerability to install malicious software on your PC, so keeping up with these patches will help to prevent malicious software being installed on your PC
Go here to check for & install updates to Microsoft applications.
Note: The update process uses ActiveX, so you will need to use Internet Explorer for it, and allow the ActiveX control that it wants to install.

Please reboot and repeat the update process until there are no more updates to install.

Please let me know of any problems you may have encountered.

In your next reply, please include the following:
  • OTMoveIt2's Log
  • A new Hijack this log

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#14 woodyatwork

woodyatwork
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:08:51 PM

Posted 12 August 2008 - 06:59 PM

Appreciate all of your help. Sorry this took so long. Work got in the way!

I can't do the Windows Update. I follow the link, and it does the ActiveX thing. Then it says I can check by using the Windows Update option on my start menu. But, there is none there.

Here is the requested information.

o2moveit2

< HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\NoWindowsUpdate >
Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\NoWindowsUpdate deleted successfully.
< HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\ClearRecentDocsOnExit >
Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\ClearRecentDocsOnExit deleted successfully.
< HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\NoRecentDocsHistory >
Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\NoRecentDocsHistory deleted successfully.
< HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\NoRecentDocsNetHood >
Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\NoRecentDocsNetHood deleted successfully.
< HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\NoSMMyPictures >
Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\NoSMMyPictures deleted successfully.
< HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\NoRecentDocsMenu >
Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\NoRecentDocsMenu deleted successfully.

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08122008_184046


HiJackThis


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:48:55 PM, on 8/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\NCR\Tdat\TGTW\06.01.00.12\bin\GtwRsrvTdmst.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\basfipm.exe
C:\WINDOWS\system32\bmwebcfg.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\NCR\BYNET\blmsvc.exe
C:\Program Files\ENDFORCE\AgentAPI.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Teradata\Teradata Manager 13.0\Bin\isservice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Common Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\Program Files\NCR\Tdat\PDE\06.01.00.12\bin\pdeinetd.exe
C:\Program Files\NCR\NCRput\bin\wfxrd.exe
C:\Program Files\NCR\NCRput\bin\putjobd.exe
C:\Program Files\NCR\NCRput\bin\portmgmt.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Common Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\VMware\VMware Player\hqtray.exe
C:\Program Files\ENDFORCE\AgntTray.exe
C:\Program Files\VMware\VMware Player\vmware-authd.exe
C:\Program Files\Boingo\GoBoingo\GoBoingo.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Secway\SimpLite-MSN 2.2\SimpLite-MSN.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\TEMP\XYF540.EXE
C:\WINDOWS\system32\vmnetdhcp.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Common Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Common Files\Trend Micro\OfficeScan Client\pccntupd.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy-mem60fw.network.fedex.com:3128
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O1 - Hosts: 199.228.192.159 EDWPRDcop1
O1 - Hosts: 199.228.5.48 EDWDEVcop1
O1 - Hosts: 153.64.20.231 partnerscop1 partners
O1 - Hosts: 153.64.208.9 figcop1 fig
O1 - Hosts: 67.161.162.46 PDLinuxcop1 PDLinux
O1 - Hosts: 153.64.209.130 Tobacop1 Toba
O1 - Hosts: 106.1.1.74 hekyl hekylcop1
O1 - Hosts: 106.1.1.71 jekyl jekylcop1
O1 - Hosts: 153.65.185.116 ceres05 ceres05cop1
O1 - Hosts: 153.65.185.117 ceres05 ceres05cop2
O1 - Hosts: 153.65.185.118 ceres05 ceres05cop3
O1 - Hosts: 153.65.185.119 ceres05 ceres05cop4
O1 - Hosts: 106.1.1.79 mcqueen mcqueencop1
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 9\SnagItBHO.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 9\SnagItIEAddin.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [NCR-Netmeeting Check] C:\WINDOWS\NMTRepair.EXE
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Common Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [VMware hqtray] "C:\Program Files\VMware\VMware Player\hqtray.exe"
O4 - HKLM\..\Run: [ENDFORCEAgent] "C:\Program Files\ENDFORCE\AgntTray.exe"
O4 - HKLM\..\Run: [GoBoingo] C:\Program Files\Boingo\GoBoingo\GoBoingo.lnk
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [AT&T Communication Manager] "C:\Program Files\AT&T\Communication Manager\ATTCM.exe" -a
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Simp] C:\Program Files\Secway\SimpLite-MSN 2.2\SimpLite-MSN.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKUS\S-1-5-21-3060894454-1813951241-3909198807-1013\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (User '?')
O4 - HKUS\S-1-5-21-3060894454-1813951241-3909198807-1013\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-3060894454-1813951241-3909198807-1013\..\RunOnce: [!CleanupNetMeetingDispDriver] "C:\WINDOWS\system32\rundll32.exe" msconf.dll,CleanupNetMeetingDispDriver 0 (User '?')
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (file missing)
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\sw185041\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O14 - IERESET.INF: START_PAGE_URL=http://iis.ncrnet.ncr.com/ncrnet
O15 - Trusted Zone: *.Teradata.com
O15 - ESC Trusted Zone: http://*.ncr.com (HKLM)
O15 - ESC Trusted Zone: http://*.teradata.com (HKLM)
O16 - DPF: {0B0F4127-1B3E-467A-B6C8-571807562DDC} (AuthenticationTD.Authenticate) - http://web.teradatanet.teradata.com/cab/validateTD.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1E1BC012-AC2A-403F-AEE4-A32E1F18986D} - https://www.passwordmanager.ncr.com/psynch/docs/pslogoff.dll
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {4E67B0DB-1CAE-11D2-AD10-02608CA0806B} - http://web.ncrnet.ncr.com/cab/NCRFile.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1216999819520
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1218584545140
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} - http://www.infuzer.com/IDC/client/player/isetup1.cab
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/67/install/gtdownls.cab
O16 - DPF: {AA3AE90C-F60E-4FD9-85E0-A00B61AE49B0} - https://myc3.gateway.ncr.com/core/wizards/P...ntMailTools.CAB
O16 - DPF: {BA2A9829-8040-4BF3-BDB6-51512826B68B} (Authentication.Authenticate) - http://web.ncr.com/cab/phonebook.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {DD3D661B-E8FA-11D2-A018-00A0C9AD89DF} (Phonebook.Application) - http://web.ncrnet.ncr.com/cab/phonebook.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - https://ncruniversity.webex.com/client/v_my...ing/ieatgpc.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://sslgateway.teradata.com/dana-cached...perSetupSP1.cab
O16 - DPF: {F5131C24-E56D-11CF-B78A-444553540000} - https://myb.gateway.ncr.com/Site0008/html/B...ix/ikcntrls.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = TD.teradata.com
O17 - HKLM\Software\..\Telephony: DomainName = TD.teradata.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = corp.ncr.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = corp.ncr.com,elsegundoca.ncr.com,sandiegoca.ncr.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = TD.teradata.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = corp.ncr.com,elsegundoca.ncr.com,sandiegoca.ncr.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = TD.teradata.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = corp.ncr.com,elsegundoca.ncr.com,sandiegoca.ncr.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = corp.ncr.com,elsegundoca.ncr.com,sandiegoca.ncr.com
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AT&T RcAppSvc (ATTRcAppSvc) - PCTEL - C:\Program Files\AT&T\Communication Manager\RcAppSvc.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\basfipm.exe
O23 - Service: Bytemobile Web Configurator (bmwebcfg) - Bytemobile, Inc. - C:\WINDOWS\system32\bmwebcfg.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\system32\Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Bynet (bynet) - NCR Corporation - C:\Program Files\NCR\BYNET\blmsvc.exe
O23 - Service: ENDFORCE Agent API - ENDFORCE, Inc. - C:\Program Files\ENDFORCE\AgentAPI.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Teradata GTW Reserve Port (GtwRsrvTdmst) - NCR - C:\Program Files\NCR\Tdat\TGTW\06.01.00.12\bin\GtwRsrvTdmst.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Teradata Manager Service (ISService) - Teradata Corporation - C:\Program Files\Teradata\Teradata Manager 13.0\Bin\isservice.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Common Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Common Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: Teradata inetd Service (PdeinetdService) - NCR - C:\Program Files\NCR\Tdat\PDE\06.01.00.12\bin\pdeinetd.exe
O23 - Service: NCR PUT File Service (PUTFileSvc) - Unknown owner - C:\Program Files\NCR\NCRput\bin\wfxrd.exe
O23 - Service: NCR PUT Job Service (PUTJobSvc) - Unknown owner - C:\Program Files\NCR\NCRput\bin\putjobd.exe
O23 - Service: NCR PUT Port Manager Service (PUTPortMgrSvc) - Unknown owner - C:\Program Files\NCR\NCRput\bin\portmgmt.exe
O23 - Service: Teradata RDBMS Initiator (recond) - NCR - C:\Program Files\NCR\Tdat\PDE\06.01.00.12\bin\recond.exe
O23 - Service: TQS Server (TdqmServerService) - Teradata, a division of NCR - C:\Program Files\NCR\Teradata Query Scheduler 12.0\server\tdqmserv.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Common Files\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Player\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

--
End of file - 19265 bytes

#15 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:06:51 PM

Posted 13 August 2008 - 01:08 AM

You can launch Windows Update manually by going to Start -> Run.. and typing in:
iexplore.exe http://update.microsoft.com/

If you are still having problems, at a bare minimum you should download and install the standalone Service Pack 3 install located here:
http://www.microsoft.com/downloads/details...;displaylang=en

After you have done one of those actions, please post a new HJT log if you sucessfully updated.

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users