1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Major Internet Slowdown - Please HElp

Discussion in 'Virus & Other Malware Removal' started by rmalina, Jul 18, 2007.

Thread Status:
Not open for further replies.
Advertisement
  1. rmalina

    rmalina Thread Starter

    Joined:
    Jul 18, 2007
    Messages:
    14
    Hi, I am new to the site, but a fairly intermediate computer user.

    I have had a major internet slowdown just recently. I have used a myriad of programs to try to get rid of the issue. I have run SuperAntiSpyware, ewido anti-spyware, AdAware, and Spybot: Search and Destroy, but nothing has fixed it. I have also been running AVG's free anti-virus.

    Here is my HJT log:

    Logfile of Trend Micro HijackThis v2.0.0 (BETA)
    Scan saved at 12:27:23 PM, on 7/18/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\SYSTEM32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\WINDOWS\System32\CTsvcCDA.exe
    C:\WINDOWS\System32\inetsrv\inetinfo.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\Program Files\Linksys Wireless-G USB Wireless Network

    Monitor\WLService.exe
    C:\Program Files\Linksys Wireless-G USB Wireless Network

    Monitor\WUSB54Gv2.exe
    C:\WINDOWS\SYSTEM32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Microsoft IntelliType Pro\type32.exe
    C:\program files\steam\steam.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\John\Desktop\HiJackThis_v2.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

    http://www.dellnet.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

    http://www.realgm.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

    http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

    http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

    http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

    http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =

    http://www.dellnet.com/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet

    Settings,ProxyOverride = http://localhost;
    R3 - URLSearchHook: (no name) - <default> - (no file)
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1

    \SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {5e96925f-7c67-48f2-a9ca-a7a2595469f6} -

    C:\WINDOWS\SYSTEM32\kbd234.dll (file missing)
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType

    Pro\type32.exe"
    O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program

    Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe

    /RUNONCE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe

    /RUNONCE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe

    /RUNONCE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe

    /RUNONCE (User 'Default user')
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program

    Files\HP\Digital Imaging\bin\hpqtra08.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1

    \MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

    C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-

    00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -

    C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program

    Files\AIM95\aim.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %

    windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7

    -f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

    C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-

    00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) -

    http://rd1.surfernetwork.com/surferplugin.ocx
    O16 - DPF: {483EB14D-AF1C-4951-81B0-4E2B41829FF6} (QOLCheck Control) -

    https://www.qwizonline.com/cabs/QOLCheck.ocx
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating

    System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-

    us/4,0,0,84/mcinsctl.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) -

    http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -

    http://www.shockwave.com/content/bejeweled2/sis/popcaploader_v10.cab
    O20 - Winlogon Notify: kbd234 - kbd234.dll (file missing)
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-

    00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-

    2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program

    Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. -

    C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. -

    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. -

    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd -

    C:\WINDOWS\System32\CTsvcCDA.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision

    Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32

    \IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program

    Files\iPod\bin\iPodService.exe
    O23 - Service: mental ray 3.5 Satellite (32-bit) (mi-raysat_3dsmax9_32) -

    Unknown owner - C:\Program Files\Autodesk\3ds Max 9

    \mentalray\satellite\raysat_3dsmax9_32server.exe (file missing)
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation -

    C:\Program Files\Intel\NCS\Sync\NetSvc.exe
    O23 - Service: OpcMessengerService - Unknown owner -

    C:\Accounts\AutoSol\OpcMessenger\OpcMessengerService\Debug\OpcMessengerServic

    e.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: WUSB54Gv2SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G

    USB Wireless Network Monitor\WLService.exe

    --
    End of file - 7175 bytes

    Thank you in advance for your help.

    Rob
     
  2. cybertech

    cybertech Retired Moderator

    Joined:
    Apr 16, 2002
    Messages:
    72,115
    Hi, Welcome to TSG!!


    Download ComboFix from Here or Here to your Desktop.
    • Double click combofix.exe and follow the prompts.
    • When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
    Note: Do not mouseclick combofix's window while its running. That may cause it to stall
     
  3. rmalina

    rmalina Thread Starter

    Joined:
    Jul 18, 2007
    Messages:
    14
    Here is the HJT log:

    Logfile of Trend Micro HijackThis v2.0.0 (BETA)
    Scan saved at 2:12:09 PM, on 7/21/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\SYSTEM32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\WINDOWS\System32\CTsvcCDA.exe
    C:\WINDOWS\System32\inetsrv\inetinfo.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
    C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv2.exe
    C:\WINDOWS\SYSTEM32\Ati2evxx.exe
    C:\Program Files\Microsoft IntelliType Pro\type32.exe
    C:\Program Files\Spyware Nuker\swnxt.exe
    C:\program files\steam\steam.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\AIM6\aim6.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\AIM6\aolsoftware.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\System32\dllhost.exe
    C:\WINDOWS\SYSTEM32\taskmgr.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\regedit.exe
    C:\Documents and Settings\John\Desktop\HiJackThis_v2.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.realgm.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost;
    R3 - URLSearchHook: (no name) - <default> - (no file)
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {5e96925f-7c67-48f2-a9ca-a7a2595469f6} - C:\WINDOWS\SYSTEM32\kbd234.dll (file missing)
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [SWN2] C:\Program Files\Spyware Nuker\swnxt.exe /h
    O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - http://rd1.surfernetwork.com/surferplugin.ocx
    O16 - DPF: {483EB14D-AF1C-4951-81B0-4E2B41829FF6} (QOLCheck Control) - https://www.qwizonline.com/cabs/QOLCheck.ocx
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave.com/content/bejeweled2/sis/popcaploader_v10.cab
    O20 - Winlogon Notify: kbd234 - kbd234.dll (file missing)
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: mental ray 3.5 Satellite (32-bit) (mi-raysat_3dsmax9_32) - Unknown owner - C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe (file missing)
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
    O23 - Service: OpcMessengerService - Unknown owner - C:\Accounts\AutoSol\OpcMessenger\OpcMessengerService\Debug\OpcMessengerService.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: WUSB54Gv2SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe

    --
    End of file - 7305 bytes
     
  4. rmalina

    rmalina Thread Starter

    Joined:
    Jul 18, 2007
    Messages:
    14
    Here is the Combofix Log:

    "Rob" - 2007-07-21 13:55:59 - ComboFix 07-07-17.8 - Service Pack 2 NTFS


    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


    C:\DOCUME~1\John\MYDOCU~1.\sembly~1
    C:\WINDOWS\pppatc~1


    ((((((((((((((((((((((((( Files Created from 2007-06-21 to 2007-07-21 )))))))))))))))))))))))))))))))


    2007-07-21 13:55 51,200 --a------ C:\WINDOWS\nircmd.exe
    2007-07-18 15:22 67,645 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\pshook11.sys
    2007-07-18 15:22 <DIR> d-------- C:\Program Files\Spyware Nuker
    2007-07-18 15:22 <DIR> d-------- C:\Program Files\INAC
    2007-07-18 14:34 271,224 --a------ C:\WINDOWS\SYSTEM32\mucltui.dll
    2007-07-18 14:34 208,248 --a------ C:\WINDOWS\SYSTEM32\muweb.dll
    2007-07-18 12:19 0 --a------ C:\WINDOWS\ORUN32.EXE
    2007-07-18 12:18 0 --a------ C:\WINDOWS\SYSTEM32\CMMGR32.EXE
    2007-07-18 10:43 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
    2007-07-18 10:42 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
    2007-07-18 10:42 <DIR> d-------- C:\DOCUME~1\John\APPLIC~1\SUPERAntiSpyware.com
    2007-07-18 03:48 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
    2007-07-18 03:03 <DIR> d-------- C:\Program Files\MSXML 6.0
    2007-07-18 03:01 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
    2007-07-17 17:06 <DIR> d-------- C:\WINDOWS\network diagnostic
    2007-07-17 16:42 <DIR> d----c--- C:\WINDOWS\SYSTEM32\DRVSTORE
    2007-07-17 16:29 <DIR> d-------- C:\Program Files\RAMBooster.Net
    2007-07-17 16:25 <DIR> d-------- C:\Program Files\CleanCache 3.0
    2007-07-15 01:26 <DIR> d-------- C:\Program Files\uTorrent
    2007-07-15 01:26 <DIR> d-------- C:\DOCUME~1\John\APPLIC~1\uTorrent
    2007-06-24 11:40 <DIR> d-------- C:\Program Files\Common Files\Autodesk Shared
    2007-06-24 11:40 <DIR> d-------- C:\Program Files\Autodesk
    2007-06-24 11:38 2,297,552 --a------ C:\WINDOWS\SYSTEM32\d3dx9_26.dll
    2007-06-21 14:53 <DIR> d-------- C:\DOCUME~1\John\APPLIC~1\Ulead Systems
    2007-06-21 14:50 <DIR> d-------- C:\Program Files\Ulead Systems
    2007-06-21 14:50 <DIR> d-------- C:\Program Files\Common Files\Ulead Systems
    2007-06-21 14:50 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ulead Systems


    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

    2007-07-21 17:53:22 -------- d-----w C:\Program Files\Steam
    2007-07-19 07:11:08 384 ----a-w C:\WINDOWS\system32\DVCStateBkp-{00000002-00000000-00000001-00001102-00000004-10031102}.dat
    2007-07-19 07:11:08 384 ----a-w C:\WINDOWS\system32\DVCState-{00000002-00000000-00000001-00001102-00000004-10031102}.dat
    2007-07-18 15:07:19 -------- d-----w C:\Program Files\ewido anti-spyware 4.0
    2007-07-18 14:42:21 -------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
    2007-07-18 07:48:52 -------- d-----w C:\Program Files\Lavasoft
    2007-07-18 07:48:49 -------- d-----w C:\DOCUME~1\John\APPLIC~1\Lavasoft
    2007-07-18 07:17:28 -------- d-----w C:\Program Files\Microsoft Works
    2007-07-18 07:07:57 -------- d-----w C:\Program Files\Microsoft SQL Server
    2007-07-18 06:56:18 -------- d-----w C:\Program Files\HLSW
    2007-07-18 06:30:01 -------- d-----w C:\Program Files\mIRC
    2007-07-18 03:29:34 -------- d-----w C:\Program Files\Warcraft III
    2007-07-17 20:29:45 -------- d--h--w C:\Program Files\InstallShield Installation Information
    2007-07-16 04:54:56 -------- d-----w C:\Program Files\Starcraft
    2007-07-16 04:54:29 -------- d-----w C:\Program Files\LimeWire
    2007-07-16 04:46:15 -------- d-----w C:\Program Files\SopCast
    2007-06-27 16:50:45 -------- d-----w C:\DOCUME~1\John\APPLIC~1\MSN6
    2007-06-21 18:50:28 -------- d-----w C:\Program Files\Common Files\InstallShield
    2007-06-14 18:56:01 -------- d-----w C:\Program Files\AIM6
    2007-06-04 19:18:48 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
    2007-06-04 19:17:02 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
    2007-06-04 19:14:56 6,272 ----a-w C:\WINDOWS\system32\drivers\AWRTPD.sys
    2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
    2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
    2006-07-21 21:39:50 0 ----a-w C:\DOCUME~1\John\APPLIC~1\internaldb41.dat
    2003-11-11 03:54:39 544 ----a-w C:\Program Files\Shortcut to Online Services.lnk
    2005-05-03 19:54:34 56 --sh--r C:\WINDOWS\SYSTEM32\D010A75F27.sys
    2005-04-14 20:48:09 11,690 --sha-w C:\WINDOWS\SYSTEM32\KGyGaAvL.sys
     
  5. rmalina

    rmalina Thread Starter

    Joined:
    Jul 18, 2007
    Messages:
    14
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


    *Note* empty entries & legit default entries are not shown

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
    2004-05-12 03:03 744960 --a------ C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5e96925f-7c67-48f2-a9ca-a7a2595469f6}]
    C:\WINDOWS\SYSTEM32\kbd234.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "type32"="C:\Program Files\Microsoft IntelliType Pro\type32.exe" [2005-03-15 05:46]
    "SWN2"="C:\Program Files\Spyware Nuker\swnxt.exe" [2006-06-09 12:11]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Steam"="c:\program files\steam\steam.exe" [2007-07-04 23:38]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]
    "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-02-27 11:39]
    "Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-04-27 17:17]

    C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup
    HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-12 00:23:26]
     
  6. rmalina

    rmalina Thread Starter

    Joined:
    Jul 18, 2007
    Messages:
    14
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"="C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 12:55]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\kbd234]
    kbd234.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
    C:\Program Files\AIM95\aim.exe -cnetwait.odl

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
    Ati2mdxx.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cleanup]
    C:\DOCUME~1\John\LOCALS~1\Temp\2005226224530_mcappins.exe /v=3 /cleanup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
    CTHELPER.EXE

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
    "C:\Program Files\D-Tools\daemon.exe" -lang 1033

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DIGStream]
    C:\Program Files\DIGStream\digstream.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Utility]
    Logi_MwX.Exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msci]
    C:\DOCUME~1\John\LOCALS~1\Temp\2005226224530_mcinfo.exe /insfin

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
    "C:\Program Files\MSN Messenger\msnmsgr.exe" /background

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
    "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
    C:\Program Files\Winamp\winampa.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WUSB54Gv2]
    C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\InvokeSvc3.exe


    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
    AutoRun\command- D:\autoplay.exe


    **************************************************************************

    catchme 0.3.1040 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-07-21 14:02:04
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden registry entries ...

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Hearts]
    "name"="Robbie"
    "p1name"="Shilo"
    "p2name"="Rory"
    "p3name"="Calvin"
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\General-Bar3]
    "MRUDockID"=dword:00000000
    "MRUDockLeftPos"=dword:00000000
    "MRUDockTopPos"=dword:00000000
    "MRUDockRightPos"=dword:00000000
    "MRUDockBottomPos"=dword:00000000
    "MRUFloatXPos"=dword:80000000
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\General-Bar4]
    "MRUFloatXPos"=dword:80000000
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List]
    "File1"="C:\Documents and Settings\Robert Malina\Desktop\IMG_0071.JPG"
    "File2"="C:\Documents and Settings\Robert Malina\My Documents\My Pictures\wowimwasted.jpg"
    "File3"="C:\Documents and Settings\Robert Malina\Desktop\kristin.jpg"
    "File4"="C:\Documents and Settings\Robert Malina\My Documents\download\noobstAr\justtakethem.jpg"
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Text]
    "PointSize"=dword:00000008
    "PositionX"=dword:00000046
    "PositionY"=dword:0000005a
    "TypeFaceName"="NSimSun"
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\View]
    "BMPWidth"=dword:0000027d
    "BMPHeight"=dword:00000245
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit]
    "LastKey"="My Computer\HKEY_CURRENT_USER\Software\Valve\Half-Life\Settings"
    "FindFlags"=dword:0000000e
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Sound Recorder]
    "X"=dword:000000b0
    "Y"=dword:000000e8
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Volume Control\SB Audigy Audio [CF00]]
    "X"=dword:000000cf
    "Y"=dword:00000198
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad\Recent File List]
    "File1"="C:\Documents and Settings\Robert Malina\Desktop\Problem Solving Guide Chapter 16.doc"
    "File2"="C:\Documents and Settings\Robert Malina\Desktop\study guide part 1.rtf"
    "File3"="C:\Documents and Settings\Robert Malina\Local Settings\Temporary Internet Files\OLK3F7\study guide part 1.doc"
    "File4"="C:\Documents and Settings\Robert Malina\Desktop\Problem Solving Guide.doc"
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Device Installer]
    "SearchOptions"=dword:00000212
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer]
    "Logon User Name"="Robert Malina"
    "CleanShutdown"=dword:00000001

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
    "Hidden"=dword:00000002
    "HideFileExt"=dword:00000001
    "TaskbarGlomming"=dword:00000000
    "CascadeNetworkConnections"="YES"
    "Start_ShowRecentDocs"=dword:00000002
    "Start_ShowNetConn_ShouldShow"=dword:00000042

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlersDefaultSelection]
    "ShowPicturesOnArrival"="MSOpenFolder"
    "PlayMusicFilesOnArrival"="MSOpenFolder"
    "PlayVideoFilesOnArrival"="MSPlayMediaOnArrival"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\UserChosenExecuteHandlers]
    "H:\\?\IDE#CdRomSAMSUNG_DVD-ROM_SD-616T_________________F310____#5&1ffe4a08&0&0.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}+PlayCDAudioOnArrival"="MSTakeNoAction\0\0\xbeaa\x9b86\x61df\x1c3\0"
    "H:\\?\IDE#CdRom_NEC_DVD+RW_ND-1100A____________________10FD____#5&1ffe4a08&0&0.1.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}+PlayCDAudioOnArrival"="MSTakeNoAction\0\0\xcce4\x5d7a\x6209\x1c3\0"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\BrowseNewProcess]
    "BrowseNewProcess"="yes"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning]
    "Auto Close"=dword:00000000
    "Close Factor"=dword:00000140

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning\Drives\Volume{d069f85e-a038-11d7-a1dc-806d6172696f}]
    "Drive Type"=dword:00000002

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU]
    "MRUList"="ojmkduaycipbtlfxwvesqrgnh"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\dsm"
    "MRUList"="fedcbajihg"
    "b"="C:\Documents and Settings\Robert Malina\Desktop\dsm2"
    "c"="C:\Documents and Settings\Robert Malina\Desktop\Picture\Laura2"
    "d"="C:\Documents and Settings\Robert Malina\Desktop\wtffatty"
    "e"="C:\Documents and Settings\Robert Malina\Desktop\mertalk"
    "f"="C:\Documents and Settings\Robert Malina\Desktop\kristin"
    "g"="C:\Documents and Settings\Robert Malina\My Documents\MER1"
    "h"="C:\Documents and Settings\Robert Malina\My Documents\MER2"
    "i"="C:\Documents and Settings\Robert Malina\My Documents\gg"
    "j"="C:\Documents and Settings\Robert Malina\Desktop\ELFTHINGER"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\Problem Solving Guide.doc"
    "MRUList"="cgaihdfbej"
    "b"="C:\Program Files\LimeWire\Shared\Adam Sandler - LunchLady Song.mp3"
    "c"="C:\Documents and Settings\Robert Malina\Desktop\oregondlx\Picture\promzilla.jpg"
    "d"="C:\Program Files\LimeWire\Shared\Notorious BIG - Juicy.mp3"
    "e"="C:\Program Files\LimeWire\Shared\Mark Anthony - You Sang To Me.mp3"
    "f"="C:\Documents and Settings\Robert Malina\Desktop\kristin"
    "g"="C:\Documents and Settings\Robert Malina\Desktop\study guide part 1.rtf"
    "h"="C:\Documents and Settings\Robert Malina\My Documents\My Pictures\wowimwasted.jpg"
    "i"="C:\Documents and Settings\Robert Malina\Desktop\Problem Solving Guide Chapter 16.doc"
    "j"="C:\Program Files\LimeWire\Shared\Hansonn-MMBop.mp3"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\avi]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\ozone3.avi"
    "MRUList"="ajihgfedcb"
    "b"="C:\Documents and Settings\Robert Malina\Desktop\pilsl-retaliation.avi"
    "c"="C:\Documents and Settings\Robert Malina\Desktop\gijoe.avi"
    "d"="C:\Documents and Settings\Robert Malina\Desktop\boooze.avi"
    "e"="C:\Documents and Settings\Robert Malina\My Documents\My Pictures\wmv_big.avi"
    "f"="C:\Documents and Settings\Robert Malina\My Documents\My Pictures\wmv_big2.avi"
    "g"="C:\Documents and Settings\Robert Malina\My Documents\My Pictures\wmv_big3.avi"
    "h"="C:\Documents and Settings\Robert Malina\My Documents\My Pictures\wmv_big4.avi"
    "i"="C:\Documents and Settings\Robert Malina\My Documents\My Pictures\wmv_big5.avi"
    "j"="C:\Documents and Settings\Robert Malina\Desktop\JoeMan- Prodigy.avi"
     
  7. rmalina

    rmalina Thread Starter

    Joined:
    Jul 18, 2007
    Messages:
    14
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\b4s]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\BluesTravelerPlayList.b4s"
    "MRUList"="dcba"
    "b"="C:\Documents and Settings\Robert Malina\Desktop\2pizzle.b4s"
    "c"="C:\Documents and Settings\Robert Malina\Desktop\rapzilla.b4s"
    "d"="C:\Documents and Settings\Robert Malina\Desktop\Other\Rap_Playlist.b4s"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\bmp]
    "a"="C:\Documents and Settings\Robert Malina\My Documents\My Pictures\untitled.bmp"
    "MRUList"="jihgfedcba"
    "b"="C:\SIERRA\Half-Life\de_comrade_3rdroute0001.bmp"
    "c"="C:\SIERRA\Half-Life\de_comrade_3rdroute0002.bmp"
    "d"="C:\SIERRA\Half-Life\de_cpl_mill0005.bmp"
    "e"="C:\SIERRA\Half-Life\de_cpl_mill0012.bmp"
    "f"="C:\Documents and Settings\Robert Malina\Desktop\wtf.bmp"
    "g"="C:\Documents and Settings\Robert Malina\Desktop\wtf2.bmp"
    "h"="C:\Documents and Settings\Robert Malina\My Documents\My Pictures\weiner.bmp"
    "i"="C:\Documents and Settings\Robert Malina\Desktop\Picture\group1.bmp"
    "j"="C:\Documents and Settings\Robert Malina\Desktop\Picture\group1.jpg.bmp"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\bsp]
    "a"="C:\Program Files\Steam\SteamApps\[email protected]\counter-strike\cstrike\maps\de_cpl_fire.bsp"
    "MRUList"="ba"
    "b"="C:\Program Files\Steam\SteamApps\[email protected]\counter-strike\cstrike\maps\de_cpl_mill.bsp"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\cfg]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\john.cfg"
    "MRUList"="hgfedcba"
    "b"="C:\Documents and Settings\Robert Malina\My Documents\HOLYSHIT.CFG"
    "c"="C:\Program Files\Steam\SteamApps\[email protected]\counter-strike\cstrike\john.cfg"
    "d"="C:\Program Files\Steam\SteamApps\[email protected]\counter-strike\cstrike\cal.cfg"
    "e"="C:\Documents and Settings\Robert Malina\Desktop\frag.cfg"
    "f"="C:\Documents and Settings\Robert Malina\Desktop\Wolf_CFG.cfg"
    "g"="C:\Program Files\Steam\SteamApps\lilmoney73456\counter-strike\cstrike\shibby.cfg"
    "h"="C:\Documents and Settings\Robert Malina\Desktop\cal.cfg"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\chm]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\helpstudio.chm"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\cl5]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\MJNELLY.cl5"
    "MRUList"="cba"
    "b"="C:\Documents and Settings\Robert Malina\Desktop\Country Mix.cl5"
    "c"="C:\Documents and Settings\Robert Malina\Desktop\stupidbrent.cl5"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\cpp]
    "a"="C:\Accounts\Metadynamics\eCurfew\eCurfewDR\eCurfewDR.cpp"
    "MRUList"="gfedcba"
    "b"="C:\Documents and Settings\All Users\Documents\SetThreadAbsolutePriority.cpp"
    "c"="C:\Accounts\Metadynamics\eCurfew\eCurfewDR\SetThreadAbsolutePriority.cpp"
    "d"="C:\Accounts\Metadynamics\eCurfew\eCurfewNTPTest\StdAfx.cpp"
    "e"="C:\Accounts\Metadynamics\eCurfew\eCurfewDR\SntpRequest.cpp"
    "f"="C:\Accounts\Metadynamics\eCurfew\eCurfewDR\SchedulerTest\Schedule.cpp"
    "g"="C:\Accounts\Metadynamics\eCurfew\eCurfewDR\SchedulerTest\Scheduler.cpp"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\dem]
    "a"="C:\SIERRA\Half-Life\cstrike\demo1.dem"
    "MRUList"="eadcb"
    "b"="C:\SIERRA\Half-Life\cstrike\zExest1.dem"
    "c"="C:\SIERRA\Half-Life\cstrike\SKvsMatrix1.dem"
    "d"="C:\Documents and Settings\Robert Malina\Desktop\wood-vs-mv-ct.dem"
    "e"="C:\SIERRA\Half-Life\cstrike\menacescrim.dem"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\dll]
    "a"="C:\Documents and Settings\Robert Malina\My Documents\OpcMessenger Libraries\MathFunctions.dll"
    "MRUList"="edcba"
    "b"="C:\Documents and Settings\Robert Malina\My Documents\OpcMessenger Libraries\FBLIB1.dll"
    "c"="C:\Accounts\AutoSol\OpcMessenger\OpcMessengerMqcAddIn\OpcMessengerMQCAddIn.dll"
    "d"="C:\Accounts\AutoSol\OpcMessenger\ASMQClient\Debug\ASMQClient.dll"
    "e"="C:\Accounts\AutoSol\OpcMessenger\OpcMessengerASMQAddIn\OpcMessengerASMQAddIn.dll"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\doc]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\letters.doc"
    "MRUList"="edcabjihgf"
    "b"="C:\Documents and Settings\Robert Malina\My Documents\Phi Kappa Theta Mud Splash 2004.doc"
    "c"="C:\Documents and Settings\Robert Malina\Desktop\Generating Revenue for Student Activities.doc"
    "d"="C:\Documents and Settings\Robert Malina\Desktop\Problem Solving Guide Chapter 16.doc"
    "e"="C:\Documents and Settings\Robert Malina\Desktop\Problem Solving Guide.doc"
    "f"="C:\Documents and Settings\Robert Malina\My Documents\reSeRch.doc"
    "g"="C:\Documents and Settings\Robert Malina\Desktop\research proposal.doc"
    "h"="C:\Documents and Settings\Robert Malina\Desktop\glossary8_f03.doc"
    "i"="C:\Documents and Settings\Robert Malina\My Documents\NewsPresentationOUtline.doc"
    "j"="C:\Documents and Settings\Robert Malina\My Documents\Experiment E4.doc"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\dsp]
    "a"="C:\Accounts\AutoSol\OpcMessenger\ASMQClient\ASMQClient.dsp"
    "MRUList"="ajihgfedcb"
    "b"="C:\Accounts\AutoSol\OpcMessenger\ASMQ\ASMQ.dsp"
    "c"="C:\Accounts\AutoSol\OpcMessenger\FBCOM\FBCOM.dsp"
    "d"="C:\Accounts\AutoSol\OpcMessenger\JMS\JMS.dsp"
    "e"="C:\Accounts\AutoSol\OpcMessenger\MQC\MQC.dsp"
    "f"="C:\Accounts\AutoSol\OpcMessenger\OpcDA\OpcDA.dsp"
    "g"="C:\Accounts\AutoSol\OpcMessenger\OpcMessengerService\OpcMessengerService.dsp"
    "h"="C:\Accounts\AutoSol\OpcMessenger\SQL\Sql.dsp"
    "i"="C:\Accounts\AutoSol\OpcMessenger\TimeService\TimeService.dsp"
    "j"="C:\Accounts\AutoSol\OpcMessenger\FB\FBCOM.dsp"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\dsw]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\timetest\timeproject\SetTime.dsw"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\exe]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\sdat4375.exe"
    "MRUList"="ebdcjighaf"
    "b"="C:\Documents and Settings\Robert Malina\Desktop\LimeWireWin.exe"
    "c"="C:\Documents and Settings\Robert Malina\Desktop\stinger.exe"
    "d"="C:\Documents and Settings\Robert Malina\Desktop\titan4shuk.exe"
    "e"="C:\Documents and Settings\Robert Malina\Desktop\IconDrop2.0.exe"
    "f"="C:\Documents and Settings\Robert Malina\Desktop\ssfsetup347.exe"
    "g"="C:\Documents and Settings\Robert Malina\Desktop\HijackThis.exe"
    "h"="C:\Documents and Settings\Robert Malina\Desktop\vbrun60sp5.exe"
    "i"="C:\Documents and Settings\Robert Malina\Desktop\CWShredder.exe"
    "j"="C:\Documents and Settings\Robert Malina\Desktop\noadware.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\fbl]
    "a"="C:\Documents and Settings\Robert Malina\My Documents\OpcMessenger Libraries\MathFunctions.fbl"
    "MRUList"="ba"
    "b"="C:\Documents and Settings\Robert Malina\My Documents\OpcMessenger Libraries\FBLIB1.fbl"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\fla]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\Flash\Untitled-1.fla"
    "MRUList"="ba"
    "b"="C:\Documents and Settings\Robert Malina\Desktop\Flash\Bushido.fla"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\gba]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\Yu-Gi-Oh! Eternal Duelist Soul.gba"
    "MRUList"="cab"
    "b"="C:\Documents and Settings\Robert Malina\Desktop\Yu-Gi-Oh! World Wide Edition.gba"
    "c"="C:\Documents and Settings\Robert Malina\Desktop\VBOY\0165 - MegaMan Battle Network (U)(Venom).www.grn.dl.am.gba"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\gbc]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\Yu-Gi-Oh! Dark Duel Stories.gbc"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\gcf]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\counter-strike.gcf"
    "MRUList"="ba"
    "b"="C:\Documents and Settings\Robert Malina\Desktop\half-life.gcf"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\gif]
    "a"="A:\benharper1.gif"
    "MRUList"="gfedcba"
    "b"="A:\maroon5.gif"
    "c"="A:\pinkfloyd.gif"
    "d"="A:\rbf.gif"
    "e"="C:\Documents and Settings\Robert Malina\My Documents\My Pictures\wtfux0r.gif"
    "f"="C:\Documents and Settings\Robert Malina\Desktop\Bushido\BushidoZeichen_small1.gif"
    "g"="C:\Documents and Settings\Robert Malina\Desktop\Bushido\Sonne.gif"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\h]
    "a"="C:\Accounts\Metadynamics\eCurfew\eCurfewDR\ShadowThread.h"
    "MRUList"="fgedcba"
    "b"="C:\Accounts\Metadynamics\eCurfew\eCurfewNTPTest\StdAfx.h"
    "c"="C:\Accounts\Metadynamics\eCurfew\eCurfewDR\SntpRequest.h"
    "d"="C:\Accounts\Metadynamics\eCurfew\eCurfewDR\Scheduler.h"
    "e"="C:\Accounts\Metadynamics\eCurfew\eCurfewDR\SchedulerTest\WatchdogHelper.h"
    "f"="C:\Accounts\Metadynamics\eCurfew\eCurfewDR\SchedulerTest\Scheduler.h"
    "g"="C:\Accounts\Metadynamics\eCurfew\eCurfewDR\SchedulerTest\Schedule.h"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\hif]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\robpc.hif"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\hta]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\fix.hta"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\htm]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\Present Order.htm"
    "MRUList"="fedcba"
    "b"="C:\Documents and Settings\Robert Malina\Desktop\random.htm"
    "c"="C:\Documents and Settings\Robert Malina\Desktop\ENGR 106 Engineering Problem Solving and Computer Tools - Fall 2003 - WebCT 3_7_4.htm"
    "d"="C:\Documents and Settings\Robert Malina\Desktop\w.htm"
    "e"="C:\Documents and Settings\Robert Malina\Desktop\SSINFO.htm"
    "f"="C:\Documents and Settings\Robert Malina\Desktop\mertalk.htm"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\ico]
    "a"="C:\Accounts\Metadynamics\OPC\Metadynamics.OPC.OpcServerXAE.NET\TestApp\Resources\icon_mdc.ico"
    "MRUList"="ba"
    "b"="C:\Program Files\LimeWire\3.3.5\LimeWire.ico"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\jpg]
    "a"="C:\Documents and Settings\Robert Malina\My Documents\My Pictures\wowimwasted.jpg"
    "MRUList"="bajidhcgfe"
    "b"="C:\Documents and Settings\Robert Malina\Desktop\oregondlx\Picture\promzilla.jpg"
    "c"="C:\Documents and Settings\Robert Malina\Desktop\steelRain2.jpg"
    "d"="C:\Documents and Settings\Robert Malina\Desktop\oregondlx\Picture\Rob_1.jpg"
    "e"="C:\Documents and Settings\Robert Malina\Desktop\oregondlx\Picture\shotgunnedberz.jpg"
    "f"="C:\Documents and Settings\Robert Malina\My Documents\My Pictures\wowimwasted2.jpg"
    "g"="C:\Documents and Settings\Robert Malina\Desktop\bootyforyou.jpg"
    "h"="C:\Documents and Settings\Robert Malina\Desktop\scan.jpg"
    "i"="C:\Documents and Settings\Robert Malina\Desktop\oregondlx\Picture\Rob_2.jpg"
    "j"="C:\Documents and Settings\Robert Malina\Desktop\oregondlx\Picture\Rob_3.jpg"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\log]
    "a"="C:\Documents and Settings\Robert Malina\My Documents\hijackthis.log"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\m]
    "a"="H:\ENGR 106\PROJECT2_dush\nanorough.m"
    "MRUList"="dcabjihgfe"
    "b"="H:\ENGR 106\PROJECT2_dush\load_data.m"
    "c"="H:\ENGR 106\PROJECT2_dush\random_point.m"
    "d"="H:\ENGR 106\PROJECT2_dush\slope.m"
    "e"="C:\Documents and Settings\Robert Malina\My Documents\afm2matrix.m"
    "f"="C:\Documents and Settings\Robert Malina\My Documents\afm_dimensions.m"
    "g"="C:\Documents and Settings\Robert Malina\Desktop\rand_point.m"
    "h"="H:\ENGR 106\PROJECT2_dush\afm2image.m"
    "i"="H:\ENGR 106\PROJECT2_dush\afm2matrix.m"
    "j"="H:\ENGR 106\PROJECT2_dush\afm_dimensions.m"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\mov]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\gijoecarnival.mov"
    "MRUList"="cdba"
    "b"="C:\Documents and Settings\Robert Malina\Desktop\gijoeice.mov"
    "c"="C:\Documents and Settings\Robert Malina\Desktop\gijoenosebleed.mov"
    "d"="C:\Documents and Settings\Robert Malina\Desktop\GijoeBobyMassagefensler.mov"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\mp3]
    "a"="C:\Program Files\LimeWire\Shared\Mark Anthony - You Sang To Me.mp3"
    "MRUList"="bjaegfchdi"
    "b"="C:\Program Files\LimeWire\Shared\Notorious BIG - Juicy.mp3"
    "c"="C:\Program Files\LimeWire\Shared\Robyn - Show Me Love.mp3"
    "d"="C:\Program Files\LimeWire\Shared\t.A.T.u - Malchik Gay.mp3"
    "e"="C:\Program Files\LimeWire\Shared\Hansonn-MMBop.mp3"
    "f"="C:\Program Files\LimeWire\Shared\Backstreet Boys - Everybody.mp3"
    "g"="C:\Program Files\LimeWire\Shared\here in my room-crow left of the murder_incubus.mp3"
    "h"="C:\Program Files\LimeWire\Shared\(Madonna) - Like a Prayer.mp3"
    "i"="C:\Program Files\LimeWire\Shared\Tag Team - Whoop There It Is.mp3"
    "j"="C:\Program Files\LimeWire\Shared\Adam Sandler - LunchLady Song.mp3"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\mpeg]
    "a"="C:\Program Files\LimeWire\Shared\Freestyle Friday - Jin and Posterboy (2).mpeg"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\mpg]
    "a"="C:\Documents and Settings\Robert Malina\My Documents\download\mature natural riding.mpg"
    "MRUList"="cba"
    "b"="C:\Documents and Settings\Robert Malina\Desktop\Monty Python - Spam.mpg"
    "c"="C:\Documents and Settings\Robert Malina\Desktop\YESSSS.mpg"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\mpga]
    "a"="C:\Documents and Settings\Robert Malina\My Documents\downloadin.mpga"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\Msi]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\MsnMsgs.Msi"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\mwBase]
    "a"="C:\Program Files\Magic Workstation\weehee.mwBase"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\mwDeck]
    "a"="C:\Program Files\Magic Workstation\RedDeath.mwDeck"
    "MRUList"="acb"
    "b"="C:\Program Files\Magic Workstation\DropThoseCards.mwDeck"
    "c"="C:\Program Files\Magic Workstation\Sacrificial Bam.mwDeck"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\nes]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\FCE\Little Nemo - The Dream Master (E).nes"
    "MRUList"="jihgfedacb"
    "b"="C:\Documents and Settings\Robert Malina\Desktop\FCE\Rockin' Kats (PC10) [!].nes"
    "c"="C:\Documents and Settings\Robert Malina\Desktop\FCE\megaman5.nes"
    "d"="C:\Documents and Settings\Robert Malina\Desktop\FCE\BOMBMAN2.NES"
    "e"="C:\Documents and Settings\Robert Malina\Desktop\FCE\DW4.NES"
    "f"="C:\Documents and Settings\Robert Malina\Desktop\FCE\TSPRBOWL.NES"
    "g"="C:\Documents and Settings\Robert Malina\Desktop\FCE\MEGAMAN6.NES"
    "h"="C:\Documents and Settings\Robert Malina\Desktop\FCE\DRAGONW3.NES"
    "i"="C:\Documents and Settings\Robert Malina\Desktop\FCE\DUCKTA~1.NES"
    "j"="C:\Documents and Settings\Robert Malina\Desktop\FCE\NINJA_GA.NES"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\omd]
    "a"="C:\Documents and Settings\Robert Malina\My Documents\OpcMessenger Libraries\Test\Project1.omd"
    "MRUList"="dcba"
    "b"="C:\Documents and Settings\Robert Malina\My Documents\OpcMessenger Libraries\pubsub.omd"
    "c"="C:\Documents and Settings\Robert Malina\My Documents\OpcMessenger Libraries\Project1.omd"
    "d"="C:\Documents and Settings\Robert Malina\My Documents\OpcMessenger Libraries\moobob.omd"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\pdf]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\03SL_Bucks1.pdf"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\rar]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\Steam-HL.and.CS.Install.Files.rar"
    "MRUList"="hgfedcba"
    "b"="C:\Documents and Settings\Robert Malina\Desktop\wov1.rar"
    "c"="C:\Documents and Settings\Robert Malina\Desktop\dev-cod.rar"
    "d"="C:\Documents and Settings\Robert Malina\Desktop\3d_cal_week_7.rar"
    "e"="C:\Documents and Settings\Robert Malina\Desktop\3D_CAL_Week_8.rar"
    "f"="C:\Documents and Settings\Robert Malina\Desktop\RETURN.rar"
    "g"="C:\Documents and Settings\Robert Malina\Desktop\JoeMan1.4.rar"
    "h"="C:\Documents and Settings\Robert Malina\Desktop\32268-3D_CAL_PLAYOFFS.rar"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\rtf]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\study guide part 1.rtf"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\SGM]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\woohah.SGM"
    "MRUList"="ba"
    "b"="C:\Documents and Settings\Robert Malina\Desktop\Yu-Gi-Oh! Eternal Duelist Soul.sgm"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\swf]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\Flash\Bushido.swf"
    "MRUList"="ba"
    "b"="C:\Documents and Settings\Robert Malina\Desktop\this_land_mov.swf"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\torrent]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\cali-s8-playoffs-final.zip.torrent"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\txt]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\newaccount.txt"
    "MRUList"="gefdcbajih"
    "b"="C:\Documents and Settings\Robert Malina\Desktop\merchat.txt"
    "c"="C:\Documents and Settings\Robert Malina\Desktop\New Health Insurance.txt"
    "d"="C:\Documents and Settings\Robert Malina\Desktop\kristynnubmer.txt"
    "e"="C:\Documents and Settings\Robert Malina\Desktop\merhome.txt"
    "f"="C:\Documents and Settings\Robert Malina\Desktop\Brothersyesterday.txt"
    "g"="C:\Documents and Settings\Robert Malina\Desktop\woopwoop.txt"
    "h"="C:\Documents and Settings\Robert Malina\Desktop\brentnewcell.txt"
    "i"="C:\Documents and Settings\Robert Malina\Desktop\vector directions.txt"
    "j"="C:\Documents and Settings\Robert Malina\Desktop\eastbay.txt"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\vbp]
    "a"="C:\Documents and Settings\Robert Malina\My Documents\OpcMessenger Libraries\MathFunctions.vbp"
    "MRUList"="dcba"
    "b"="C:\Documents and Settings\Robert Malina\My Documents\OpcMessenger Libraries\FBLIB1.vbp"
    "c"="C:\Accounts\AutoSol\OpcMessenger\OpcMessengerASMQAddIn\OpcMessengerASMQ.vbp"
    "d"="C:\Accounts\AutoSol\OpcMessenger\OpcMessengerMqcAddIn\OpcMessengerMQCAddIn.vbp"
     
  8. rmalina

    rmalina Thread Starter

    Joined:
    Jul 18, 2007
    Messages:
    14
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\wad]
    "a"="C:\Program Files\Steam\SteamApps\blackice-theoriginal\counter-strike\cstrike\de_vegas.wad"
    "MRUList"="cba"
    "b"="C:\Program Files\Steam\SteamApps\lilmoney73456\counter-strike\cstrike\de_vegas.wad"
    "c"="C:\Program Files\Steam\SteamApps\lilmoney73456\counter-strike\cstrike\as_tundra.wad"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\wav]
    "a"="C:\Program Files\AIM95\Sounds\moo.wav"
    "MRUList"="ba"
    "b"="C:\Documents and Settings\Robert Malina\Desktop\cuppycake.wav"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\wma]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\02 Holidae In ft. Ludacris & Snoo.wma"
    "MRUList"="cba"
    "b"="C:\Documents and Settings\Robert Malina\Desktop\05 Track 5.wma"
    "c"="C:\Program Files\LimeWire\Shared\XSO Drive - Can I Get It Back - You Got Served Soundtrack.wma"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\wmv]
    "a"="C:\Documents and Settings\Robert Malina\My Documents\My Pictures\cj_27288.wmv"
    "MRUList"="fgedcbajih"
    "b"="C:\Documents and Settings\Robert Malina\Desktop\reloadedparody.wmv"
    "c"="C:\Documents and Settings\Robert Malina\My Documents\My Pictures\tgpvid.wmv"
    "d"="C:\Documents and Settings\Robert Malina\My Documents\My Pictures\cj_31450.wmv"
    "e"="C:\Documents and Settings\Robert Malina\My Documents\My Pictures\cj_32587.wmv"
    "f"="C:\Documents and Settings\Robert Malina\Desktop\CS source.wmv"
    "g"="C:\Documents and Settings\Robert Malina\My Documents\My Pictures\cj_33792.wmv"
    "h"="C:\Documents and Settings\Robert Malina\Desktop\cj_24326.wmv"
    "i"="C:\Documents and Settings\Robert Malina\My Documents\My Pictures\cj_25441.wmv"
    "j"="C:\Documents and Settings\Robert Malina\My Documents\My Pictures\cj_24343.wmv"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\wsz]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\Rockman_and_Forte_Amp.wsz"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\xls]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\hmwk2_4.xls"
    "MRUList"="ihgfdecba"
    "b"="H:\ENGR 106\EXCEL\coaster_droptime.xls"
    "c"="H:\ENGR 106\EXCEL\eng-traffic.xls"
    "d"="H:\ENGR 106\EXCEL\hw6_part3.xls"
    "e"="H:\ENGR 106\EXCEL\hw6_part5.xls"
    "f"="C:\Documents and Settings\Robert Malina\Desktop\team1_0103_light2calcs.xls"
    "g"="H:\ENGR 106\initialanalysis.revised.xls"
    "h"="C:\Documents and Settings\Robert Malina\Desktop\hmwk10_t3.xls"
    "i"="C:\Documents and Settings\Robert Malina\My Documents\My Pictures\contact list spring 04.xls"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\zip]
    "a"="C:\Documents and Settings\Robert Malina\Desktop\a_few_good_geniuses.zip"
    "MRUList"="jihcgfebda"
    "b"="C:\Documents and Settings\Robert Malina\Desktop\Ripacrombie 1.0.zip"
    "c"="C:\Accounts\Metadynamics\eCurfew\eCurfew.zip"
    "d"="C:\Documents and Settings\Robert Malina\Desktop\v1.5-r3sys[06-13].zip"
    "e"="C:\Documents and Settings\Robert Malina\Desktop\reflist.zip"
    "f"="C:\Documents and Settings\Robert Malina\Desktop\[GB]LEE_movie.zip"
    "g"="C:\Documents and Settings\Robert Malina\Desktop\costa.zip"
    "h"="C:\Documents and Settings\Robert Malina\Desktop\VisualBoyAdvance-1.7.2.zip"
    "i"="C:\Documents and Settings\Robert Malina\Desktop\1554.zip"
    "j"="C:\Documents and Settings\Robert Malina\Desktop\0165.zip"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComputerDescriptions]
    "richm-gx110"=""
    "richm-t30"=""
    "CAITYM-XL3"=""
    "timm-t30"=""
    "LUKE"="Lukes school computer"
    "STEVE-DELL"="Steve"
    "FRANNY"=""
    "YOJI"=""
    "SKYLER"="skyler's dohicky"
    "XPS"="Andrew Gates"
    "DANSLAPTOP"=""
    "ACE"="Owen 432"
    "RUGABUG"="Laptop"
    "COREY"=""
    "GLOIN"=""
    "INSPIRED"="Clark's Dell"
    "ANDREW"="Andrew's Computer"
    "BRAD"=""
    "BRIANSCOMPUTER"=""
    "CHARLES"=""
    "CPT-AMERICA"=""
    "D1GZBW21"="Scott's Computer"
    "D3NPVT21"="Peter's Computer"
    "D41ZCY21"="Christopher J King"
    "D42XM631"="Dorm Room computer"
    "D496C231"="John's Laptop"
    "D5L8M431"=""
    "D9BW3631"="Josh's computer"
    "DADDY"=""
    "DAVID"=""
    "DC1WDC21"=""
    "DCXQL331"="Michael Still"
    "DF805831"="Taylor's Computer"
    "DIMENSION4600"=""
    "GARRETT"=""
    "GRAHAM"="graham's silver wonder"
    "GREEN"=""
    "GORDON"=""
    "ADAM2006"="Adam's Computer"
    "ADAMH"="Adam"
    "BERIC"=""
    "DAVIDLABTOP"="College"
    "JONATHAN"="jroom"
    "MDWALING"=""
    "WPRINCE"="wprince"
    "SWRDOFTRTH"=""
    "JOHNREEVES"="John Reeves's Laptop"
    "GAVIN"="My little Friend"
    "NERV"="Room"
    "ACESFULL"=""
    "BLACKMAGEJR"=""
    "BLAKE-3Y8USEGB1"=""
    "BOBRINKO"="Bobrinko's Baby"
    "BRADSROOM"="Brad's Breast of a Computer"
    "BRANDONP4"=""
    "CHASER"=""
    "COLE"=""
    "CPQ11808144252"=""
    "CPQ27240217939"=""
    "CPQ47403191915"=""
    "D14MK831"=""
    "D575N631"="Paul's Computer"
    "D7N3B531"=""
    "D873VW21"="JEA's Dell Laptop"
    "DARRENSDELL"="Darren's Computer- That's About It"
    "DAVEALBERS"=""
    "DFGXT731"=""
    "ELWOOD"=""
    "ENTERPRISE"="The coolest trek computer ever!"
    "ERIC"="Eric's Notebook"
    "GARY_316"="College Hizzi-fer-chizzy"
    "GCM"=""
    "HEWLETT-LYDTPEP"="Fish Four's Mad CPU"
    "IROC"="IROC"
    "JASON"="Jason's Machine"
    "JASONBECKMAN"=""
    "JBITNER"=""
    "JEFFHARRIS"=""
    "JOE"=""
    "JOES"="Joe's College Computer"
    "OWENSE300GORDON"=""
    "DB09H231"=""
    "DORMCOMP1"=""
    "DAVEPC"="Dave's Computer"
    "JEFF"="Jeff"
    "JOHN-HQP8SOXLSJ"="John's Computer"
    "JOHN-NEW"="John's Computer"
    "MAGICMACHINE"=""
    "MATT"=""
    "MATTHEW-6AKYWIH"="Matt's Computer"
    "MICHAEL-FAST"=""
    "rosetta.ics.purdue.edu"="ICS Home Directory Server"
    "ADMINISTRATOR"=""
    "MR_ORANGE_JUICE"="Styna's Dell"
    "NAHNAH"="lap top"
    "RYAN"="Ryan"
    "TOURNEY"=""
    "SP3CIALK2285"=""
    "HP-63WY6J1"=""
    "ICEMAN"="iceman's sweet computer"
    "TUBBY2"="Shawn"
    "INSTIGATOR"="T.J.'s Personal Computer"
    "NICK"="Nick's Computer"
    "PATRICK"=""
    "MICHAEL-095BB1N"=""
    "GORDON300"=""
    "BENSSEXYMACHINE"=""
    "BRIAN-6XJQB4M4T"=""
    "DAN-L7FAOEUO2OD"=""
    "JOHNB"=""
    "JOHNPETER"=""
    "BALCHIK"="432"
    "MAIN"="Joe's"
    "YOGI"=""
    "ZACHARY"="Franny"
    "S0023813328"=""
    "BLAKE-8E5L4383W"=""
    "OWEN432"="Balchik"
    "DANIEL"="Daniel"
    "MCS"=""
    "TOSHIBA-STEVE"="Laptop"
    "CPQ25783215786"="Steve B"
    "D845HQ11"=""
    "BRIANJREED"="Brian J Reed Computer"
    "128.210.10.81"="ICS Home Directory Server"
    "JOHN-TTMJFGNY8A"=""
    "MICHAEL-SHW08RP"=""
    "MISTERFUNK"=""
    "SNOOPY"="Workplace of the Cosme"
    "BRADS"=""
    "WOODSTOCK"="Scott's Computer"
    "PIECE_OF_****"="HP of crap"
    "RICHARSONPD"="THE MACHINE "
    "MATTINGLY"="Purdue University- West Lafayette"
    "ROSS"=""
    "SAMIR-50E32JC0K"="Samir's computer"
    "SCHOOLCOMPUTER"="HP of crap"
    "TYLER"="Tyler's entertainment"
    "D1N42611"=""
    "PAVILION"="Eric's Computer"
    "WAK-2802"="I ain't afraid of no ghost!"
    "KEN"="Mother of All Porn"
    "PETER"=""
    "COMPUTERIZZLE"=""
    "GREG-ACRQ071SU5"=""
    "KBERG"="Mother of All Porn"
    "JORDAN"=""
    "SCOPE"="Brad"
    "JOHN-CWPSNA05ZG"="Phoenix"
    "FOOL"=""
    "JP0NZ01"="Mike's Computer"
    "DELLD600"=""

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\CleanupWiz]
    "NoRun"=dword:00000000

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew]
    "Briefcase"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,42,00,72,00,69,00,65,..
    "Bitmap Image"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,42,00,69,00,74,00,6d,..
    "Microsoft Word Document"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,..
    "OPC Messenger Document"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,4f,00,50,00,43,00,20,..
    "Microsoft PowerPoint Presentation"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,..
    "Quattro Pro 10 Notebook"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,51,00,75,00,61,00,74,..
    "WinRAR archive"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,57,00,69,00,6e,00,52,..
    "Corel Presentations 10 Show"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,43,00,6f,00,72,00,65,..
    "Text Document"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,54,00,65,00,78,00,74,..
    "WordPerfect 10 Document"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,57,00,6f,00,72,00,64,..
    "Corel Presentations 10 Drawing"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,43,00,6f,00,72,00,65,..
    "Microsoft Excel Worksheet"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,..
    "WinRAR ZIP archive"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,57,00,69,00,6e,00,52,..
    "~reserved~"=hex:18,00,00,00,01,00,01,00,d4,07,09,00,04,00,09,00,10,00,18,00,1d,..
    "Language"=dword:00000409
     
  9. rmalina

    rmalina Thread Starter

    Joined:
    Jul 18, 2007
    Messages:
    14
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.001]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.001\OpenWithList]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.002]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.002\OpenWithList]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.005]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.005\OpenWithList]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.1st]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.1st\OpenWithList]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\OpenWithProgids]
    "MediaSource.aiffFile"=hex(0):

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asf\OpenWithList]
    "b"="realplay.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\OpenWithList]
    "a"="RealPlay.exe"
    "MRUList"="cab"
    "b"="iexplore.exe"
    "c"="wmplayer.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi]
    "Application"=""

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi\OpenWithList]
    "a"="DivX Player 2.1.exe"
    "MRUList"="becda"
    "b"="wmplayer.exe"
    "c"="RealPlay.exe"
    "d"="iexplore.exe"
    "e"="aim.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.b4s\OpenWithList]
    "a"="studio.exe"
    "MRUList"="ab"
    "b"="winamp3.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\OpenWithList]
    "MRUList"="bdac"
    "c"="aim.exe"
    "d"="iexplore.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bsp\OpenWithList]
    "a"="aim.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cda\OpenWithList]
    "a"="mmjblaunch.exe"
    "MRUList"="cba"
    "b"="RealPlay.exe"
    "c"="wmplayer.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cfg\OpenWithList]
    "MRUList"="abcd"
    "d"="mirc.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.chm]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.chm\OpenWithList]
    "a"="iexplore.exe"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.chm\OpenWithProgids]
    "chm.file"=hex(0):

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.clw]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.clw\OpenWithList]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cpp\OpenWithList]
    "a"="devenv.exe"
    "MRUList"="bacd"
    "b"="NOTEPAD.EXE"
    "c"="MSDEV.EXE"
    "d"="iexplore.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dem\OpenWithList]
    "a"="geekplay.exe"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.DLL\OpenWithList]
    "a"="vb6.exe"
    "MRUList"="ba"
    "b"="REGSVR32.EXE"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.doc]
    "Progid"="WordPad.Document.1"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.doc\OpenWithList]
    "a"="Wpwin10.exe"
    "MRUList"="ebdca"
    "b"="WINWORD.EXE"
    "c"="aim.exe"
    "d"="iexplore.exe"
    "e"="WORDPAD.EXE"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dsp\OpenWithList]
    "a"="MSDEV.EXE"
    "MRUList"="acb"
    "b"="devenv.exe"
    "c"="NOTEPAD.EXE"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dsw\OpenWithList]
    "a"="devenv.exe"
    "MRUList"="cbad"
    "b"="NOTEPAD.EXE"
    "c"="MSDEV.EXE"
    "d"="iexplore.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fbl]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fbl\OpenWithList]
    "a"="OpcMessenger.exe"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gbc]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gbc\OpenWithList]
    "a"="VisualBoyAdvance.exe"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gcf]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gcf\OpenWithList]
    "a"="aim.exe"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\OpenWithList]
    "a"="iexplore.exe"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.h\OpenWithList]
    "a"="devenv.exe"
    "MRUList"="bacd"
    "b"="NOTEPAD.EXE"
    "c"="msdev.exe"
    "d"="iexplore.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hif]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hif\OpenWithList]
    "a"="DISCInfo.exe"
    "MRUList"="ba"
    "b"="iexplore.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hta]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hta\OpenWithList]
    "a"="iexplore.exe"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hta\OpenWithProgids]
    "htafile"=hex(0):

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\OpenWithList]
    "a"="iexplore.exe"
    "MRUList"="ab"
    "b"="aim.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\OpenWithList]
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ica]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ica\OpenWithList]
    "a"="wfica32.exe"
    "MRUList"="ba"
    "b"="iexplore.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ica\OpenWithProgids]
    "WinFrameICA"=hex(0):

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ico\OpenWithList]
    "a"="devenv.exe"
    "MRUList"="ba"
    "b"="mspaint.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\OpenWithList]
    "a"="dellix.exe"
    "MRUList"="ebgacdf"
    "c"="iexplore.exe"
    "d"="aim.exe"
    "e"="msnmsgr.exe"
    "f"="mirc.exe"
    "g"="shimgvw.dll"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.likew0t[1]]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.likew0t[1]\OpenWithList]
    "a"="iexplore.exe"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.log\OpenWithList]
    "b"="HijackThis.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m\OpenWithList]
    "a"="iexplore.exe"
    "MRUList"="bac"
    "b"="NOTEPAD.EXE"
    "c"="aim.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1v]
    "Application"=""

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2v]
    "Application"=""

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\OpenWithList]
    "a"="iexplore.exe"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\OpenWithProgids]
    "mhtmlfile"=hex(0):

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mov\OpenWithList]
    "a"="aim.exe"
    "MRUList"="bca"
    "b"="QuickTimePlayer.exe"
    "c"="iexplore.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2]
    "Application"=""

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\OpenWithList]
    "a"="mmjblaunch.exe"
    "MRUList"="dbefac"
    "b"="aim.exe"
    "c"="iexplore.exe"
    "d"="winamp3.exe"
    "e"="studio.exe"
    "f"="mirc.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4\OpenWithProgids]
    "RealPlayer.MP4.6"=hex(0):

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpa]
    "Application"=""

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpe]
    "Application"=""

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg]
    "Application"=""

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg\OpenWithList]
    "a"="RealPlay.exe"
    "MRUList"="ebadc"
    "c"="studio.exe"
    "d"="iexplore.exe"
    "e"="CTCMS.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpg]
    "Application"=""

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpg\OpenWithList]
    "a"="RealPlay.exe"
    "MRUList"="fdbaec"
    "c"="aim.exe"
    "d"="wmplayer.exe"
    "e"="PowerDVD.exe"
    "f"="CTCMS.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpga\OpenWithList]
    "a"="aim.exe"
    "MRUList"="ba"
    "b"="RealPlay.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mps]
    "Application"=""

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv]
    "Application"=""

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv\OpenWithProgids]
    "MediaSource.mpvFile"=hex(0):

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mwBase]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mwBase\OpenWithList]
    "a"="MagicWorkstation.exe"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mwDeck]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mwDeck\OpenWithList]
    "a"="MagicWorkstation.exe"
    "MRUList"="ba"
    "b"="mwsplay.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ncb]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ncb\OpenWithList]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ncb\OpenWithProgids]
    "VisualStudio.ncb.7.1"=hex(0):

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nes]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nes\OpenWithList]
    "a"="fceu.exe"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.new]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.new\OpenWithList]
    "a"="WINWORD.EXE"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.new\OpenWithProgids]
    "new_auto_file"=hex(0):

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ocx\OpenWithList]
    "a"="REGSVR32.EXE"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.omd]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.omd\OpenWithList]
    "a"="OpcMessenger.exe"
    "MRUList"="ab"
    "b"="OPCMES~1.EXE"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.omd\OpenWithProgids]
    "OpcMessenger.Document"=hex(0):

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.original]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.original\OpenWithList]
    "a"="NOTEPAD.EXE"
    "MRUList"="ba"
    "b"="WINWORD.EXE"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.original\OpenWithProgids]
    "original_auto_file"=hex(0):

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf\OpenWithList]
    "a"="iexplore.exe"
    "MRUList"="ba"
    "b"="AcroRd32.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=110&id=2&actionID=113&mime=a25e43be5b619809490a49a3c828f867]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=110&id=2&actionID=113&mime=a25e43be5b619809490a49a3c828f867\OpenWithList]
    "a"="WINWORD.EXE"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=122&id=2&actionID=113&mime=b7ab83d574590cd54562b5150d4c1b8e]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=122&id=2&actionID=113&mime=b7ab83d574590cd54562b5150d4c1b8e\OpenWithList]
    "a"="WINWORD.EXE"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=149&id=2&actionID=113&mime=37bd438d83a73568d173c1c1a4890f87]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=149&id=2&actionID=113&mime=37bd438d83a73568d173c1c1a4890f87\OpenWithList]
    "a"="WINWORD.EXE"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=160&id=2&actionID=113&mime=282bbac62c905f67b9a64ca78631228b]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=160&id=2&actionID=113&mime=282bbac62c905f67b9a64ca78631228b\OpenWithList]
    "a"="WINWORD.EXE"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=233&id=2&actionID=113&mime=4ca97acb88081baa32e1793fb4f37e1e]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=233&id=2&actionID=113&mime=4ca97acb88081baa32e1793fb4f37e1e\OpenWithList]
    "a"="WINWORD.EXE"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=255&id=2&actionID=113&mime=a18fbc8c78de02fe3c4810258f1b494f]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=255&id=2&actionID=113&mime=a18fbc8c78de02fe3c4810258f1b494f\OpenWithList]
    "a"="WINWORD.EXE"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=255&id=3&actionID=113&mime=1118bf83d353949fe7032fa05548a732]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=255&id=3&actionID=113&mime=1118bf83d353949fe7032fa05548a732\OpenWithList]
    "a"="WINWORD.EXE"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=258&id=2&actionID=113&mime=f6d0f48d52323c88e3c5e3222a8b8239]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=258&id=2&actionID=113&mime=f6d0f48d52323c88e3c5e3222a8b8239\OpenWithList]
    "a"="WINWORD.EXE"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=323&id=3&actionID=113&mime=53433b319f3c5608df8ccfb7df120522]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=323&id=3&actionID=113&mime=53433b319f3c5608df8ccfb7df120522\OpenWithList]
    "a"="WINWORD.EXE"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=325&id=2&actionID=113&mime=26441a298d1a9780743831f5b0ea794f]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=325&id=2&actionID=113&mime=26441a298d1a9780743831f5b0ea794f\OpenWithList]
    "a"="WINWORD.EXE"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=391&id=2&actionID=113&mime=d8e5eaa4f5e5639eaff49ea0979a5800]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=391&id=2&actionID=113&mime=d8e5eaa4f5e5639eaff49ea0979a5800\OpenWithList]
    "a"="WINWORD.EXE"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=397&id=2&actionID=113&mime=37093a9ddbf5c2ae70a3c3032b00f3c1]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=397&id=2&actionID=113&mime=37093a9ddbf5c2ae70a3c3032b00f3c1\OpenWithList]
    "a"="WINWORD.EXE"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=51&id=2&actionID=113&mime=7344099f08d23b52ebfe6690305b2f00]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=51&id=2&actionID=113&mime=7344099f08d23b52ebfe6690305b2f00\OpenWithList]
    "a"="WINWORD.EXE"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=52&id=2&actionID=113&mime=5a0664ecde93638ee6b5e654b4a79514]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=52&id=2&actionID=113&mime=5a0664ecde93638ee6b5e654b4a79514\OpenWithList]
    "a"="WINWORD.EXE"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=529&id=2&actionID=113&mime=c96c20ece753449ab4f565c7e041fb39]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=529&id=2&actionID=113&mime=c96c20ece753449ab4f565c7e041fb39\OpenWithList]
    "a"="WINWORD.EXE"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=659&id=2&actionID=113&mime=e05a5768c6c481f0c8837760a12cfabe]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=659&id=2&actionID=113&mime=e05a5768c6c481f0c8837760a12cfabe\OpenWithList]
    "a"="WINWORD.EXE"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=97&id=2&actionID=113&mime=55f3f465e403c6874faf557206722ec0]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php?thismailbox=INBOX&index=97&id=2&actionID=113&mime=55f3f465e403c6874faf557206722ec0\OpenWithList]
    "a"="WINWORD.EXE"
    "MRUList"="a"
     
  10. rmalina

    rmalina Thread Starter

    Joined:
    Jul 18, 2007
    Messages:
    14
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.plg\OpenWithList]
    "a"="iexplore.exe"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pls\OpenWithList]
    "a"="mmjblaunch.exe"
    "MRUList"="bca"
    "c"="RealPlay.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pls\OpenWithProgids]
    "MMJB.PLS"=hex(0):

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\OpenWithList]
    "a"="shimgvw.dll"
    "MRUList"="ba"
    "b"="mspaint.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppt\OpenWithList]
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qdat]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qdat\OpenWithList]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qdat\OpenWithProgids]
    "QuickTimeInstallCache"=hex(0):

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ram\OpenWithList]
    "MRUList"="ab"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rar\OpenWithList]
    "a"="btdownloadgui.exe"
    "MRUList"="cba"
    "b"="iexplore.exe"
    "c"="WinRAR.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rc\OpenWithList]
    "a"="devenv.exe"
    "MRUList"="ab"
    "b"="NOTEPAD.EXE"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.res]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.res\OpenWithList]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgi]
    "Application"=""

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rm\OpenWithList]
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rnx\OpenWithList]
    "a"="rnxproc.exe"
    "MRUList"="ba"
    "b"="RealPlay.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rnx\OpenWithProgids]
    "RealPlayer.RP.6"=hex(0):

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rtf\OpenWithList]
    "MRUList"="ab"
    "b"="WORDPAD.EXE"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sav]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sav\OpenWithList]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sln\OpenWithList]
    "a"="devenv.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sln\OpenWithProgids]
    "VisualStudio.Solution.7.1"=hex(0):
    "VisualStudio.Solution"=hex(0):

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smi\OpenWithList]
    "a"="RealPlay.exe"
    "MRUList"="ba"
    "b"="iexplore.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.SWF\OpenWithList]
    "MRUList"="edbca"
    "d"="mirc.exe"
    "e"="iexplore.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.torrent\OpenWithList]
    "MRUList"="cab"
    "c"="Shareaza.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tra]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tra\OpenWithList]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.txt\OpenWithList]
    "MRUList"="acedb"
    "b"="MSDEV.EXE"
    "c"="iexplore.exe"
    "d"="EXCEL.EXE"
    "e"="aim.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.user\OpenWithList]
    "a"="devenv.exe"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.user\OpenWithProgids]
    "Microsoft.userfile.7.1"=hex(0):

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vb\OpenWithList]
    "a"="devenv.exe"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vb\OpenWithProgids]
    "Microsoft.vb.7.1"=hex(0):

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vbg]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vbg\OpenWithList]
    "a"="vb6.exe"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vbg\OpenWithProgids]
    "VisualBasic.ProjectGroup"=hex(0):

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vbp\OpenWithList]
    "a"="vb6.exe"
    "MRUList"="ab"
    "b"="OpcMessenger.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vbp\OpenWithProgids]
    "VisualBasic.Project"=hex(0):

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vbproj\OpenWithList]
    "a"="devenv.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vbproj\OpenWithProgids]
    "Microsoft.vbproj.7.1"=hex(0):

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vbs]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vbs\OpenWithList]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vbs\OpenWithProgids]
    "VBSFile"=hex(0):

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vdf]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vdf\OpenWithList]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vf1]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vf1\OpenWithList]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vf2]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vf2\OpenWithList]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.VOB]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.VOB\OpenWithList]
    "a"="PowerDVD.exe"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.VOB\OpenWithProgids]
    "PDVDmpgfile"=hex(0):

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wad]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wad\OpenWithList]
    "a"="iexplore.exe"
    "MRUList"="a"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wal]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wal\OpenWithList]
    "a"="winamp3.exe"
    "MRUList"="ba"
    "b"="iexplore.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wal\OpenWithProgids]
    "Winamp3.SkinZip"=hex(0):

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\OpenWithList]
    "a"="mmjblaunch.exe"
    "MRUList"="dcba"
    "b"="iexplore.exe"
    "c"="aim.exe"
    "d"="CTCMS.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\OpenWithList]
    "a"="mmjblaunch.exe"
    "MRUList"="dcab"
    "b"="aim.exe"
    "c"="iexplore.exe"
    "d"="winamp3.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv\OpenWithList]
    "a"="wmplayer.exe"
    "MRUList"="acdb"
    "b"="iexplore.exe"
    "c"="aim.exe"
    "d"="realplay.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wsz\OpenWithList]
    "a"="iexplore.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xls\OpenWithList]
    "a"="EXCEL.EXE"
    "MRUList"="abc"
    "b"="aim.exe"
    "c"="iexplore.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip\OpenWithList]
    "a"="iexplore.exe"
    "MRUList"="eacbd"
    "b"="winzip32.exe"
    "c"="aim.exe"
    "d"="btdownloadgui.exe"
    "e"="WinRAR.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip\OpenWithProgids]
    "WinZip"=hex(0):

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]
    "{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=dword:00000000
    "{208D2C60-3AEA-1069-A2D7-08002B30309D}"=dword:00000000

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Map Network Drive MRU]
    "a"="\\rosetta.ics.purdue.edu\rmalina"
    "MRUList"="ba"
    "b"="\\128.210.10.81\burnsml"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\America Online]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Britannica]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Britannica\Ready Reference]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Call of Duty]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Call of Duty\Call of Duty Help]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Creative]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Crimsonland]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\EA GAMES\Medal of Honor Allied Assault]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\IOS]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Lavasoft Ad-aware 6]
     
  11. rmalina

    rmalina Thread Starter

    Joined:
    Jul 18, 2007
    Messages:
    14
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\McAfee.com]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Metadynamics OPC ServerX AE .NET]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Metadynamics OpcClientX-AE]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Metadynamics OpcServerX]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Metadynamics OpcServerX-AE]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Microsoft .NET Framework SDK v1.1]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Microsoft Visual Studio .NET 2003]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Microsoft Visual Studio .NET 2003\Visual Studio .NET Enterprise Features]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Microsoft Visual Studio .NET 2003\Visual Studio .NET Tools]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Microsoft Visual Studio 6.0]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Microsoft Visual Studio 6.0\Microsoft Visual SourceSafe]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Microsoft Visual Studio 6.0\Microsoft Visual Studio 6.0 Enterprise Tools]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Microsoft Visual Studio 6.0\Microsoft Visual Studio 6.0 Tools]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Microsoft Web Publishing]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Network Associates]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\PCFriendly]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\PopCap Games]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\PopCap Games\Dynomite Deluxe]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Porrasturvat]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Quicken]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Real\Games]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Real\RealOne Arcade]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Real\RealOne Player]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Ricochet Xtreme]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Shareaza]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\shockwave.com]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\shockwave.com\QBeez]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Sonic]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Sonic\MyDVD]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Sonic\MyDVD\Documentation]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Steam]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Tierra]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Truck Dismount]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Unreal Tournament 2003]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Winamp3]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\WordPerfect Office 2002\Technical Support]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\XviD]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##128.210.10.81#burnsml]
    "BaseClass"="Drive"
    "_CommentFromDesktopINI"=""
    "_LabelFromDesktopINI"=""
    "_AutorunStatus"=hex:01,df,df,00,df,01,00,01,01,ee,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##rosetta.ics.purdue.edu#rmalina]
    "BaseClass"="Drive"
    "_CommentFromDesktopINI"=""
    "_LabelFromDesktopINI"=""
    "_AutorunStatus"=hex:01,df,df,00,df,01,00,01,01,ee,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4ea62de7-35d4-11d8-a246-0007e96af49a}]
    "BaseClass"="Drive"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fe8a87ff-19e6-11d8-a23e-0007e96af49a}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,df,df,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fe8a87ff-19e6-11d8-a23e-0007e96af49a}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fe8a87ff-19e6-11d8-a23e-0007e96af49a}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fe8a87ff-19e6-11d8-a23e-0007e96af49a}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.ASF]
    "MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
    "0"=hex:38,00,74,00,68,00,20,00,53,00,74,00,72,00,65,00,65,00,74,00,20,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.au]
    "0"=hex:7a,00,6f,00,6b,00,5b,00,31,00,5d,00,2e,00,61,00,75,00,00,00,46,..
    "MRUListEx"=hex:04,00,00,00,02,00,00,00,01,00,00,00,00,00,00,00,ff,ff,ff,ff
    "1"=hex:74,00,68,00,75,00,6e,00,64,00,72,00,6f,00,5b,00,31,00,5d,00,2e,..
    "2"=hex:7a,00,6f,00,6b,00,5b,00,31,00,5d,00,28,00,31,00,29,00,2e,00,61,..
    "4"=hex:69,00,67,00,6f,00,6f,00,5b,00,31,00,5d,00,2e,00,61,00,75,00,00,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.cda]
    "0"=hex:54,00,72,00,61,00,63,00,6b,00,30,00,31,00,2e,00,63,00,64,00,61,..
    "MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.cfg]
    "MRUListEx"=hex:05,00,00,00,00,00,00,00,06,00,00,00,07,00,00,00,04,00,00,00,02,..
    "2"=hex:48,00,4f,00,4c,00,59,00,53,00,48,00,49,00,54,00,2e,00,43,00,46,..
    "5"=hex:63,00,6e,00,70,00,73,00,65,00,2e,00,63,00,66,00,67,00,00,00,42,..
    "3"=hex:61,00,75,00,74,00,6f,00,65,00,78,00,65,00,63,00,2e,00,63,00,66,..
    "1"=hex:63,00,76,00,61,00,72,00,73,00,2e,00,63,00,66,00,67,00,00,00,42,..
    "9"=hex:4e,00,4d,00,2e,00,43,00,46,00,47,00,00,00,3a,00,32,00,00,00,00,..
    "4"=hex:63,00,6f,00,6e,00,66,00,69,00,67,00,2e,00,63,00,66,00,67,00,00,..
    "7"=hex:73,00,68,00,69,00,62,00,62,00,79,00,2e,00,63,00,66,00,67,00,00,..
    "6"=hex:66,00,72,00,61,00,67,00,2e,00,63,00,66,00,67,00,00,00,40,00,32,..
    "0"=hex:63,00,61,00,6c,00,2e,00,63,00,66,00,67,00,00,00,3c,00,32,00,00,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.chm]
    "0"=hex:68,00,65,00,6c,00,70,00,73,00,74,00,75,00,64,00,69,00,6f,00,2e,..
    "MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.cl5]
    "MRUListEx"=hex:03,00,00,00,01,00,00,00,00,00,00,00,ff,ff,ff,ff
    "0"=hex:4d,00,4a,00,4e,00,45,00,4c,00,4c,00,59,00,2e,00,63,00,6c,00,35,..
    "1"=hex:43,00,6f,00,75,00,6e,00,74,00,72,00,79,00,20,00,4d,00,69,00,78,..
    "3"=hex:73,00,74,00,75,00,70,00,69,00,64,00,62,00,72,00,65,00,6e,00,74,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.cpp]
    "MRUListEx"=hex:00,00,00,00,09,00,00,00,02,00,00,00,07,00,00,00,08,00,00,00,06,..
    "4"=hex:53,00,65,00,74,00,54,00,68,00,72,00,65,00,61,00,64,00,41,00,62,..
    "3"=hex:54,00,63,00,70,00,43,00,6c,00,69,00,65,00,6e,00,74,00,2e,00,63,..
    "5"=hex:53,00,74,00,64,00,41,00,66,00,78,00,2e,00,63,00,70,00,70,00,00,..
    "6"=hex:54,00,68,00,72,00,65,00,61,00,64,00,54,00,65,00,73,00,74,00,2e,..
    "8"=hex:50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,4d,00,61,00,6e,00,61,..
    "7"=hex:53,00,65,00,72,00,76,00,69,00,63,00,65,00,43,00,6f,00,6e,00,74,..
    "2"=hex:53,00,6e,00,74,00,70,00,52,00,65,00,71,00,75,00,65,00,73,00,74,..
    "9"=hex:53,00,63,00,68,00,65,00,64,00,75,00,6c,00,65,00,72,00,2e,00,63,..
    "0"=hex:53,00,63,00,68,00,65,00,64,00,75,00,6c,00,65,00,2e,00,63,00,70,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.dsp]
    "0"=hex:4b,00,45,00,59,00,49,00,44,00,2e,00,64,00,73,00,70,00,00,00,42,..
    "MRUListEx"=hex:02,00,00,00,00,00,00,00,09,00,00,00,08,00,00,00,07,00,00,00,06,..
    "1"=hex:41,00,53,00,4d,00,51,00,2e,00,64,00,73,00,70,00,00,00,40,00,32,..
    "3"=hex:4a,00,4d,00,53,00,2e,00,64,00,73,00,70,00,00,00,3c,00,32,00,00,..
    "4"=hex:4d,00,51,00,43,00,2e,00,64,00,73,00,70,00,00,00,3c,00,32,00,00,..
    "5"=hex:4f,00,70,00,63,00,44,00,41,00,2e,00,64,00,73,00,70,00,00,00,42,..
    "6"=hex:4f,00,70,00,63,00,4d,00,65,00,73,00,73,00,65,00,6e,00,67,00,65,..
    "7"=hex:53,00,71,00,6c,00,2e,00,64,00,73,00,70,00,00,00,3c,00,32,00,00,..
    "8"=hex:54,00,69,00,6d,00,65,00,53,00,65,00,72,00,76,00,69,00,63,00,65,..
    "9"=hex:46,00,42,00,43,00,4f,00,4d,00,2e,00,64,00,73,00,70,00,00,00,42,..
    "2"=hex:41,00,53,00,4d,00,51,00,43,00,6c,00,69,00,65,00,6e,00,74,00,2e,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.dsw]
    "MRUListEx"=hex:07,00,00,00,00,00,00,00,06,00,00,00,09,00,00,00,08,00,00,00,05,..
    "2"=hex:4f,00,70,00,63,00,53,00,65,00,72,00,76,00,65,00,72,00,58,00,2e,..
    "1"=hex:4f,00,70,00,63,00,4d,00,65,00,73,00,73,00,65,00,6e,00,67,00,65,..
    "3"=hex:4f,00,50,00,43,00,20,00,4d,00,65,00,73,00,73,00,65,00,6e,00,67,..
    "5"=hex:74,00,65,00,73,00,74,00,73,00,6e,00,74,00,70,00,2e,00,64,00,73,..
    "8"=hex:4e,00,54,00,50,00,54,00,65,00,73,00,74,00,2e,00,64,00,73,00,77,..
    "9"=hex:45,00,6e,00,75,00,6d,00,50,00,72,00,6f,00,63,00,2e,00,64,00,73,..
    "6"=hex:53,00,65,00,74,00,54,00,69,00,6d,00,65,00,2e,00,64,00,73,00,77,..
    "0"=hex:53,00,63,00,68,00,65,00,64,00,75,00,6c,00,65,00,72,00,54,00,65,..
    "7"=hex:65,00,43,00,75,00,72,00,66,00,65,00,77,00,44,00,52,00,2e,00,64,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.fla]
    "0"=hex:55,00,6e,00,74,00,69,00,74,00,6c,00,65,00,64,00,2d,00,31,00,2e,..
    "MRUListEx"=hex:01,00,00,00,00,00,00,00,ff,ff,ff,ff
    "1"=hex:42,00,75,00,73,00,68,00,69,00,64,00,6f,00,2e,00,66,00,6c,00,61,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.h]
    "0"=hex:53,00,68,00,61,00,64,00,6f,00,77,00,54,00,68,00,72,00,65,00,61,..
    "MRUListEx"=hex:06,00,00,00,08,00,00,00,07,00,00,00,05,00,00,00,04,00,00,00,03,..
    "1"=hex:54,00,63,00,70,00,43,00,6c,00,69,00,65,00,6e,00,74,00,2e,00,68,..
    "2"=hex:53,00,74,00,64,00,41,00,66,00,78,00,2e,00,68,00,00,00,4c,00,32,..
    "3"=hex:50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,4d,00,61,00,6e,00,61,..
    "4"=hex:53,00,6e,00,74,00,70,00,52,00,65,00,71,00,75,00,65,00,73,00,74,..
    "5"=hex:57,00,61,00,74,00,63,00,68,00,64,00,6f,00,67,00,48,00,65,00,6c,..
    "7"=hex:46,00,69,00,72,00,65,00,77,00,61,00,6c,00,6c,00,54,00,68,00,72,..
    "8"=hex:53,00,63,00,68,00,65,00,64,00,75,00,6c,00,65,00,2e,00,68,00,00,..
    "6"=hex:53,00,63,00,68,00,65,00,64,00,75,00,6c,00,65,00,72,00,2e,00,68,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.hta]
    "MRUListEx"=hex:01,00,00,00,00,00,00,00,ff,ff,ff,ff
    "0"=hex:66,00,69,00,78,00,2e,00,68,00,74,00,61,00,00,00,3c,00,32,00,00,..
    "1"=hex:66,00,69,00,78,00,2e,00,65,00,78,00,65,00,2e,00,68,00,74,00,61,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.ico]
    "MRUListEx"=hex:05,00,00,00,06,00,00,00,04,00,00,00,00,00,00,00,03,00,00,00,02,..
    "1"=hex:4f,00,70,00,63,00,45,00,78,00,70,00,6c,00,6f,00,72,00,65,00,72,..
    "2"=hex:69,00,63,00,6f,00,6e,00,5f,00,6d,00,64,00,63,00,5f,00,6f,00,6c,..
    "3"=hex:6d,00,64,00,63,00,32,00,2e,00,69,00,63,00,6f,00,00,00,40,00,32,..
    "0"=hex:4d,00,65,00,74,00,61,00,64,00,79,00,6e,00,61,00,6d,00,69,00,63,..
    "4"=hex:69,00,63,00,6f,00,6e,00,5f,00,6d,00,64,00,63,00,2e,00,69,00,63,..
    "6"=hex:4b,00,45,00,59,00,49,00,44,00,2e,00,69,00,63,00,6f,00,00,00,4e,..
    "5"=hex:63,00,6f,00,75,00,6e,00,74,00,65,00,72,00,2d,00,73,00,74,00,72,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.inf]
    "MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
    "0"=hex:61,00,75,00,74,00,6f,00,72,00,75,00,6e,00,2e,00,69,00,6e,00,66,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.m]
    "0"=hex:61,00,66,00,6d,00,32,00,6d,00,61,00,74,00,72,00,69,00,78,00,2e,..
    "MRUListEx"=hex:06,00,00,00,00,00,00,00,09,00,00,00,08,00,00,00,07,00,00,00,02,..
    "1"=hex:68,00,6d,00,77,00,6b,00,39,00,5f,00,74,00,61,00,73,00,6b,00,33,..
    "3"=hex:72,00,61,00,6e,00,64,00,5f,00,70,00,6f,00,69,00,6e,00,74,00,2e,..
    "6"=hex:61,00,66,00,6d,00,32,00,69,00,6d,00,61,00,67,00,65,00,2e,00,6d,..
    "4"=hex:61,00,66,00,6d,00,5f,00,64,00,69,00,6d,00,65,00,6e,00,73,00,69,..
    "2"=hex:6c,00,6f,00,61,00,64,00,5f,00,64,00,61,00,74,00,61,00,2e,00,6d,..
    "7"=hex:6e,00,61,00,6e,00,6f,00,72,00,6f,00,75,00,67,00,68,00,2e,00,6d,..
    "8"=hex:72,00,61,00,6e,00,64,00,6f,00,6d,00,5f,00,70,00,6f,00,69,00,6e,..
    "9"=hex:73,00,6c,00,6f,00,70,00,65,00,2e,00,6d,00,00,00,42,00,32,00,00,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.mov]
    "MRUListEx"=hex:02,00,00,00,00,00,00,00,03,00,00,00,04,00,00,00,ff,ff,ff,ff
    "2"=hex:47,00,69,00,6a,00,6f,00,65,00,42,00,6f,00,62,00,79,00,4d,00,61,..
    "0"=hex:67,00,69,00,6a,00,6f,00,65,00,63,00,61,00,72,00,6e,00,69,00,76,..
    "3"=hex:67,00,69,00,6a,00,6f,00,65,00,69,00,63,00,65,00,2e,00,6d,00,6f,..
    "4"=hex:67,00,69,00,6a,00,6f,00,65,00,6e,00,6f,00,73,00,65,00,62,00,6c,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.mpeg]
    "MRUListEx"=hex:07,00,00,00,00,00,00,00,03,00,00,00,05,00,00,00,06,00,00,00,01,..
    "6"=hex:47,00,72,00,6f,00,75,00,70,00,20,00,53,00,65,00,78,00,20,00,2d,..
    "3"=hex:48,00,6f,00,75,00,73,00,65,00,77,00,69,00,66,00,65,00,20,00,2d,..
    "0"=hex:31,00,36,00,20,00,79,00,6f,00,2d,00,63,00,68,00,65,00,65,00,72,..
    "2"=hex:59,00,55,00,4d,00,4d,00,59,00,4d,00,41,00,4d,00,41,00,20,00,2d,..
    "8"=hex:50,00,6f,00,72,00,6e,00,6f,00,20,00,42,00,6c,00,6f,00,6f,00,70,..
    "1"=hex:50,00,6f,00,72,00,6e,00,20,00,2d,00,20,00,47,00,61,00,67,00,67,..
    "5"=hex:34,00,5b,00,31,00,5d,00,2e,00,6d,00,70,00,65,00,67,00,00,00,40,..
    "9"=hex:54,00,65,00,65,00,6e,00,20,00,67,00,69,00,72,00,6c,00,20,00,72,..
    "7"=hex:48,00,61,00,6e,00,64,00,6a,00,6f,00,62,00,20,00,48,00,75,00,6e,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.mpga]
    "0"=hex:64,00,6f,00,77,00,6e,00,6c,00,6f,00,61,00,64,00,69,00,6e,00,2e,..
    "MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.mwDeck]
    "MRUListEx"=hex:00,00,00,00,02,00,00,00,01,00,00,00,ff,ff,ff,ff
    "1"=hex:44,00,72,00,6f,00,70,00,54,00,68,00,6f,00,73,00,65,00,43,00,61,..
    "2"=hex:53,00,61,00,63,00,72,00,69,00,66,00,69,00,63,00,69,00,61,00,6c,..
    "0"=hex:52,00,65,00,64,00,44,00,65,00,61,00,74,00,68,00,2e,00,6d,00,77,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.new]
    "MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
    "0"=hex:6d,00,79,00,65,00,6e,00,67,00,72,00,31,00,30,00,36,00,2e,00,6e,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.nfo]
    "MRUListEx"=hex:01,00,00,00,00,00,00,00,ff,ff,ff,ff
    "0"=hex:64,00,65,00,76,00,69,00,61,00,6e,00,63,00,65,00,2e,00,6e,00,66,..
    "1"=hex:72,00,7a,00,72,00,2d,00,77,00,63,00,33,00,2e,00,6e,00,66,00,6f,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.omd]
    "MRUListEx"=hex:01,00,00,00,00,00,00,00,02,00,00,00,ff,ff,ff,ff
    "2"=hex:70,00,75,00,62,00,73,00,75,00,62,00,2e,00,6f,00,6d,00,64,00,00,..
    "0"=hex:50,00,72,00,6f,00,6a,00,65,00,63,00,74,00,31,00,2e,00,6f,00,6d,..
    "1"=hex:6d,00,6f,00,6f,00,62,00,6f,00,62,00,2e,00,6f,00,6d,00,64,00,00,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.original]
    "MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
    "0"=hex:6d,00,79,00,65,00,6e,00,67,00,72,00,31,00,30,00,36,00,2e,00,6f,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.plg]
    "0"=hex:45,00,6e,00,75,00,6d,00,50,00,72,00,6f,00,63,00,2e,00,70,00,6c,..
    "MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.PLS]
    "0"=hex:44,00,65,00,66,00,61,00,75,00,6c,00,74,00,2e,00,50,00,4c,00,53,..
    "MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.PNG]
    "0"=hex:4d,00,53,00,32,00,37,00,2e,00,50,00,4e,00,47,00,00,00,40,00,32,..
    "MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.ppt]
    "MRUListEx"=hex:02,00,00,00,00,00,00,00,ff,ff,ff,ff
    "0"=hex:52,00,65,00,64,00,75,00,6e,00,64,00,61,00,6e,00,63,00,79,00,20,..
    "2"=hex:52,00,4f,00,42,00,2e,00,70,00,70,00,74,00,00,00,3c,00,32,00,00,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.ram]
    "0"=hex:6a,00,69,00,6e,00,5f,00,77,00,65,00,65,00,6b,00,31,00,5f,00,76,..
    "MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.rm]
    "0"=hex:53,00,6f,00,75,00,74,00,68,00,20,00,50,00,61,00,72,00,6b,00,20,..
    "MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.rtf]
    "0"=hex:53,00,70,00,72,00,69,00,6e,00,67,00,20,00,32,00,30,00,30,00,34,..
    "MRUListEx"=hex:01,00,00,00,00,00,00,00,ff,ff,ff,ff
    "1"=hex:73,00,74,00,75,00,64,00,79,00,20,00,67,00,75,00,69,00,64,00,65,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.swf]
    "MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
    "0"=hex:42,00,75,00,73,00,68,00,69,00,64,00,6f,00,2e,00,73,00,77,00,66,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.vb]
    "0"=hex:4f,00,70,00,63,00,53,00,65,00,72,00,76,00,65,00,72,00,58,00,41,..
    "MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.vbg]
    "MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
    "0"=hex:4f,00,70,00,63,00,4d,00,65,00,73,00,73,00,65,00,6e,00,67,00,65,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.vbp]
    "MRUListEx"=hex:08,00,00,00,07,00,00,00,05,00,00,00,02,00,00,00,06,00,00,00,04,..
    "0"=hex:4f,00,70,00,63,00,41,00,6c,00,61,00,72,00,6d,00,45,00,78,00,70,..
    "3"=hex:4f,00,70,00,63,00,45,00,78,00,70,00,6c,00,6f,00,72,00,65,00,72,..
    "1"=hex:50,00,72,00,6f,00,6a,00,65,00,63,00,74,00,34,00,2e,00,76,00,62,..
    "4"=hex:50,00,72,00,6f,00,6a,00,65,00,63,00,74,00,31,00,2e,00,76,00,62,..
    "6"=hex:46,00,42,00,4c,00,49,00,42,00,31,00,2e,00,76,00,62,00,70,00,00,..
    "2"=hex:4d,00,61,00,74,00,68,00,46,00,75,00,6e,00,63,00,74,00,69,00,6f,..
    "5"=hex:4f,00,70,00,63,00,4d,00,65,00,73,00,73,00,65,00,6e,00,67,00,65,..
    "7"=hex:4f,00,70,00,63,00,4d,00,65,00,73,00,73,00,65,00,6e,00,67,00,65,..
    "8"=hex:4b,00,65,00,70,00,77,00,61,00,72,00,65,00,53,00,61,00,6d,00,70,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.vbs]
    "MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
    "0"=hex:74,00,65,00,73,00,74,00,2e,00,76,00,62,00,73,00,00,00,4c,00,32,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.VOB]
    "0"=hex:56,00,49,00,44,00,45,00,4f,00,5f,00,54,00,53,00,2e,00,56,00,4f,..
    "MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.wav]
    "0"=hex:6d,00,6f,00,6f,00,2e,00,77,00,61,00,76,00,00,00,3c,00,32,00,00,..
    "MRUListEx"=hex:01,00,00,00,00,00,00,00,ff,ff,ff,ff
    "1"=hex:63,00,75,00,70,00,70,00,79,00,63,00,61,00,6b,00,65,00,2e,00,77,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.wma]
    "MRUListEx"=hex:02,00,00,00,04,00,00,00,03,00,00,00,01,00,00,00,00,00,00,00,ff,..
    "0"=hex:30,00,35,00,2e,00,77,00,6d,00,61,00,00,00,3a,00,32,00,00,00,00,..
    "1"=hex:30,00,39,00,2e,00,77,00,6d,00,61,00,00,00,3a,00,32,00,00,00,00,..
    "3"=hex:30,00,32,00,20,00,48,00,6f,00,6c,00,69,00,64,00,61,00,65,00,20,..
    "4"=hex:30,00,35,00,20,00,54,00,72,00,61,00,63,00,6b,00,20,00,35,00,2e,..
    "2"=hex:58,00,53,00,4f,00,20,00,44,00,72,00,69,00,76,00,65,00,20,00,2d,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU]
    "MRUList"="fbdeac"
    "b"="calc\1"
    "c"="regedit\1"
    "d"="command\1"
    "e"="\\1"
    "f"="explorer\1"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "AppData"="C:\Documents and Settings\Robert Malina\Application Data"
    "Cookies"="C:\Documents and Settings\Robert Malina\Cookies"
    "Desktop"="C:\Documents and Settings\Robert Malina\Desktop"
    "Favorites"="C:\Documents and Settings\Robert Malina\Favorites"
    "NetHood"="C:\Documents and Settings\Robert Malina\NetHood"
    "Personal"="C:\Documents and Settings\Robert Malina\My Documents"
    "PrintHood"="C:\Documents and Settings\Robert Malina\PrintHood"
    "Recent"="C:\Documents and Settings\Robert Malina\Recent"
    "SendTo"="C:\Documents and Settings\Robert Malina\SendTo"
    "Start Menu"="C:\Documents and Settings\Robert Malina\Start Menu"
    "Templates"="C:\Documents and Settings\Robert Malina\Templates"
    "Programs"="C:\Documents and Settings\Robert Malina\Start Menu\Programs"
    "Startup"="C:\Documents and Settings\Robert Malina\Start Menu\Programs\Startup"
    "Local Settings"="C:\Documents and Settings\Robert Malina\Local Settings"
    "Local AppData"="C:\Documents and Settings\Robert Malina\Local Settings\Application Data"
    "Cache"="C:\Documents and Settings\Robert Malina\Local Settings\Temporary Internet Files"
    "History"="C:\Documents and Settings\Robert Malina\Local Settings\History"
    "My Pictures"="C:\Documents and Settings\Robert Malina\My Documents\My Pictures"
    "My Music"="C:\Documents and Settings\Robert Malina\My Documents\My Music"
    "Administrative Tools"="C:\Documents and Settings\Robert Malina\Start Menu\Programs\Administrative Tools"
    "CD Burning"="C:\Documents and Settings\Robert Malina\Local Settings\Application Data\Microsoft\CD Burning"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage]
    "FavoritesChanges"=dword:00000015

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams\14]
    "ViewView2"=hex:1c,00,00,00,06,00,00,00,00,00,00,00,00,00,90,00,00,00,00,00,01,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams\15]
    "ViewView2"=hex:1c,00,00,00,06,00,00,00,00,00,04,00,00,00,9c,00,00,00,00,00,01,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams\16]
    "ViewView2"=hex:1c,00,00,00,06,00,00,00,00,00,00,00,00,00,9c,00,00,00,00,00,01,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams\17]
    "ViewView2"=hex:1c,00,00,00,06,00,00,00,00,00,00,00,00,00,9c,00,00,00,00,00,01,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams\18]
    "ViewView2"=hex:1c,00,00,00,06,00,00,00,00,00,00,00,00,00,90,00,00,00,00,00,01,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams\19]
    "ViewView2"=hex:1c,00,00,00,05,00,00,00,00,00,00,00,00,00,64,00,00,00,00,00,01,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams\20]
    "ViewView2"=hex:1c,00,00,00,06,00,00,00,00,00,00,00,00,00,90,00,00,00,00,00,01,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams\21]
    "ViewView2"=hex:1c,00,00,00,05,00,00,00,00,00,00,00,00,00,64,00,00,00,00,00,01,..

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\tips]
    "DisplayInitialTipWindow"=dword:00000000

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\WebView\BarricadedFolders]
    "shell:ControlPanelFolder"=dword:00000000

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\WorkgroupCrawler\Printers]
    "a"="\\MAGGIE-T22\hpoj-fax"
    "MRUList"="mjihgonbalkfedc"
    "b"="\\MAGGIE-T22\hpojd145"
    "c"="\\RICHM-GX110\HPOJ630"
    "d"="\\LUKE\Printer"
    "e"="\\STEVE-DELL\Printer"
    "f"="\\ACE\Printer"
    "g"="\\JOES\Printer"
    "h"="\\MDWALING\Printer2"
    "i"="\\MDWALING\Printer"
    "j"="\\WPRINCE\PRINTER"
    "k"="\\BRIANJREED\hppsc2110"
    "l"="\\DELL\hpdeskje"
    "m"="\\NERV\Printer"
    "n"="\\SNOOPY\Printer"
    "o"="\\WOODSTOCK\Printer"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\WorkgroupCrawler\Shares\ACE/SharedDocs]
     
  12. rmalina

    rmalina Thread Starter

    Joined:
    Jul 18, 2007
    Messages:
    14
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\WorkgroupCrawler\Shares\FRANNY/SIERRA]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\WorkgroupCrawler\Shares\STEVE-DELL/MP3]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\WorkgroupCrawler\Shares\STEVE-DELL/mp39]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\WorkgroupCrawler\Shares\STEVE-DELL/SharedDocs]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Extensions]
    "xls"="C:\PROGRA~1\MICROS~3\Office\EXCEL.EXE"
    "mdb"="C:\PROGRA~1\MICROS~3\Office\MSACCESS.EXE"
    "mda"="C:\PROGRA~1\MICROS~3\Office\MSACCESS.EXE"
    "dot"="C:\PROGRA~1\MICROS~3\Office\WINWORD.EXE ^.dot"
    "rtf"="C:\PROGRA~1\MICROS~3\Office\WINWORD.EXE ^.rtf"
    "doc"="C:\PROGRA~1\MICROS~3\Office\WINWORD.EXE ^.doc"
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy\GroupMembership]
    "Group2"="S-1-5-21-2514620231-3486209139-2801333607-1008"
    "Group3"="S-1-5-21-2514620231-3486209139-2801333607-1010"
    "Group4"="S-1-5-21-2514620231-3486209139-2801333607-1001"
    "Group5"="S-1-5-32-544"
    "Group6"="S-1-5-32-545"
    "Group7"="S-1-5-32-556"
    "Group8"="S-1-2-0"
    "Group9"="S-1-5-4"
    "Group10"="S-1-5-11"
    "Count"=dword:0000000b
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "User Agent"="Mozilla/4.0 (compatible; MSIE 6.0; Win32)"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012004112320041124]
    "CachePath"=str(2):"USERPROFILE\Local Settings\History\History.IE5\MSHist012004112320041124\"
    "CachePrefix"=":2004112320041124: "
    "CacheLimit"=dword:00002000
    "CacheOptions"=dword:0000000b
    "CacheRepair"=dword:00000000

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012004112420041125]
    "CachePath"=str(2):"USERPROFILE\Local Settings\History\History.IE5\MSHist012004112420041125\"
    "CachePrefix"=":2004112420041125: "
    "CacheLimit"=dword:00002000
    "CacheOptions"=dword:0000000b
    "CacheRepair"=dword:00000000

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Passport\DAMap]
    "@hotmail.com"="https://loginnet.passport.com/login2.srf?lc=1033"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1]
    "Flags"=dword:000000db

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2]
    "1001"=dword:00000000
    "1004"=dword:00000001
    "1201"=dword:00000001
    "1406"=dword:00000000
    "1407"=dword:00000000
    "1607"=dword:00000000
    "1800"=dword:00000000
    "1804"=dword:00000000
    "1805"=dword:00000000
    "1A00"=dword:00000000
    "1A04"=dword:00000000
    "1A05"=dword:00000000
    "1C00"=dword:00030000
    "1E05"=dword:00030000
    "1206"=dword:00000000

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3]
    "CurrentLevel"=dword:00012000
    "1407"=dword:00000000
    "1607"=dword:00000000
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Multimedia\MIDIMap]
    "DeviceInterface"="\\?\PCI#VEN_1102&DEV_0004&SUBSYS_10031102&REV_04#4&1c660dd6&0&08F0#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\SynthA"
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
    "NoDriveTypeAutoRun"=dword:00000091
    "SpecifyDefaultButtons"=dword:00000000
    "Btn_Search"=dword:00000000
    "NoBandCustomize"=dword:00000000
    "NoToolbarCustomize"=dword:00000000
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "Steam"=""
    "AIM"="C:\Program Files\AIM95\aim.exe -cnetwait.odl"
    "msnmsgr"=""C:\Program Files\MSN Messenger\msnmsgr.exe" /background"
    "AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE"
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
    "{BDEADF00-C265-11d0-BCED-00A0C90AB50F}"="Web Folders"
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ThemeManager]
    "DllName"=str(2):"scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    Completion time: 2007-07-21 14:04:15

    --- E O F ---
     
  13. rmalina

    rmalina Thread Starter

    Joined:
    Jul 18, 2007
    Messages:
    14
    That Combofix log was uncomfortably long to post.
     
  14. cybertech

    cybertech Retired Moderator

    Joined:
    Apr 16, 2002
    Messages:
    72,115
    Indeed! One of the longest logs I've seen!

    Run SUPERAntiSpyware now and post the log from that.
     
  15. rmalina

    rmalina Thread Starter

    Joined:
    Jul 18, 2007
    Messages:
    14
    How do I get SAS to report a log?
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/597335

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice