get.whitesmoke.com(Trojan Downloader hosted with United States Sunnyvale Qwest Communications Company Llc)

DNS Lookup
Host Name IP Address
get.whitesmoke.com
get.whitesmoke.com 63.236.35.30
c0004553.cdn2.cloudfiles.rackspacecloud.com
c0004553.cdn2.cloudfiles.rackspacecloud.com 87.248.217.253
Download URLs
http://63.236.35.30/offerbox/OfferBoxSetup_FR.exe (get.whitesmoke.com)
http://63.236.35.30/WriterTools/WhiteSmokeWriter.exe (get.whitesmoke.com)
http://87.248.217.253/WhiteSmokeWriter.exe (c0004553.cdn2.cloudfiles.rackspacecloud.com)

Outgoing connection to remote server: get.whitesmoke.com TCP port 80
Outgoing connection to remote server: c0004553.cdn2.cloudfiles.rackspacecloud.com TCP port 80DNS Lookup
Host Name IP Address
download.bandoo.com
download.bandoo.com 207.232.22.25
download.cdn.bandoo.com
download.cdn.bandoo.com 212.201.100.171
Download URLs
http://207.232.22.25/o/0/r/63/Fun4IMV6.exe (download.bandoo.com)
http://212.201.100.171/cdn/o/0/r/63/Fun4IMV6.exe (download.cdn.bandoo.com)

Outgoing connection to remote server: download.bandoo.com TCP port 80
Outgoing connection to remote server: download.cdn.bandoo.com TCP port 80DNS Lookup
Host Name IP Address
app.offerbox.com 188.165.1.14
Download URLs
http://188.165.1.14/download_short_setup.php (app.offerbox.com)

Outgoing connection to remote server: app.offerbox.com TCP port 80DNS Lookup
Host Name IP Address
app.offerbox.com 188.165.1.14
app.offerbox.com
Download URLs
http://188.165.1.14/dconfig.php (app.offerbox.com)
Data posted to URLs
http://188.165.1.14/aconfig.php (app.offerbox.com)

Outgoing connection to remote server: app.offerbox.com TCP port 80

Registry Changes by all processes
Create or Open
Changes HKEY_LOCAL_MACHINESOFTWAREWhiteSmoke “DistID” = [REG_DWORD, value: 0000145E]
HKEY_CURRENT_USERSoftwareWhiteSmoke “DistID” = [REG_DWORD, value: 0000145E]
HKEY_CURRENT_USERSoftwareOfferBox “Patched Data” = IE2880app.offerbox.com

    DE

1058220101004http://www.offerbox.com/en/software/install/?campaign=10582&eme=&tracker=&ms=5&timestamp=1286183972075495http://app.offerbox.com/remove.php?campaign=10582&eme=&tracker=&ms=5&ul=en&idate=20101004&timestamp=1286183972075495
HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerLow RightsElevationPolicy{37F4A335-D085-423e-A425-0370799166FB} “Policy” = [REG_DWORD, value: 00000003]
HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerLow RightsElevationPolicy{37F4A335-D085-423e-A425-0370799166FB} “AppName” = OfferBox.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerLow RightsElevationPolicy{37F4A335-D085-423e-A425-0370799166FB} “AppPath” = [REG_EXPAND_SZ, value: C:ProgrammeOfferBox]
HKEY_LOCAL_MACHINESOFTWAREMozillaFirefoxExtensions “offerboxffx@offerbox.com” = C:ProgrammeOfferBoxofferboxffx@offerbox.com
HKEY_LOCAL_MACHINESOFTWAREGoogleChromeExtensionsbjeikeheijdjdfjbmknpefojickbkmom “path” = C:ProgrammeOfferBoxOfferBoxChromeExtension.crx
HKEY_LOCAL_MACHINESOFTWAREGoogleChromeExtensionsbjeikeheijdjdfjbmknpefojickbkmom “version” = 2.1.3304.104
HKEY_LOCAL_MACHINESOFTWAREOfferBox “ul” = DE
HKEY_LOCAL_MACHINESOFTWAREOfferBox “CAMPAIGN” = 10582
HKEY_LOCAL_MACHINESOFTWAREOfferBox “LID” = 14650916621645945550
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallOfferBox Browser “DisplayName” = OfferBox Browser
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallOfferBox Browser “UninstallString” = C:ProgrammeOfferBoxuninst.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallOfferBox Browser “DisplayIcon” = C:ProgrammeOfferBoxOfferBox.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallOfferBox Browser “URLInfoAbout” = http://www.offerbox.com
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallOfferBox Browser “Publisher” = Secure Digital Services Limited
HKEY_LOCAL_MACHINESOFTWAREClassesOfferBox.OfferBoxServer.1 “” = OfferBoxServer Class
HKEY_LOCAL_MACHINESOFTWAREClassesOfferBox.OfferBoxServer.1CLSID “” = {A7E8C343-7860-4A95-9AA8-AAF30D0F6D1E}
HKEY_LOCAL_MACHINESOFTWAREClassesOfferBox.OfferBoxServer “” = OfferBoxServer Class
HKEY_LOCAL_MACHINESOFTWAREClassesOfferBox.OfferBoxServerCLSID “” = {A7E8C343-7860-4A95-9AA8-AAF30D0F6D1E}
HKEY_LOCAL_MACHINESOFTWAREClassesOfferBox.OfferBoxServerCurVer “” = OfferBox.OfferBoxServer.1
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{A7E8C343-7860-4A95-9AA8-AAF30D0F6D1E} “” = OfferBoxServer Class
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{A7E8C343-7860-4A95-9AA8-AAF30D0F6D1E}ProgID “” = OfferBox.OfferBoxServer.1
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{A7E8C343-7860-4A95-9AA8-AAF30D0F6D1E}VersionIndependentProgID “” = OfferBox.OfferBoxServer
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{A7E8C343-7860-4A95-9AA8-AAF30D0F6D1E}LocalServer32 “” = “C:ProgrammeOfferBoxOfferBox.exe”
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{A7E8C343-7860-4A95-9AA8-AAF30D0F6D1E}TypeLib “” = {ED85AEBE-F834-4088-B5D3-97EB2478A6CD}
HKEY_LOCAL_MACHINESOFTWAREClassesTypeLib{ED85AEBE-F834-4088-B5D3-97EB2478A6CD}1.0 “” = OfferBox
HKEY_LOCAL_MACHINESOFTWAREClassesTypeLib{ED85AEBE-F834-4088-B5D3-97EB2478A6CD}1.0FLAGS “” = 0
HKEY_LOCAL_MACHINESOFTWAREClassesTypeLib{ED85AEBE-F834-4088-B5D3-97EB2478A6CD}1.0win32 “” = C:ProgrammeOfferBoxOfferBox.exe
HKEY_LOCAL_MACHINESOFTWAREClassesTypeLib{ED85AEBE-F834-4088-B5D3-97EB2478A6CD}1.0HELPDIR “” = C:ProgrammeOfferBox
HKEY_LOCAL_MACHINESOFTWAREClassesInterface{6612AFDD-34AD-4B89-A236-7E6D07C3FDCD} “” = IOfferBoxServer
HKEY_LOCAL_MACHINESOFTWAREClassesInterface{6612AFDD-34AD-4B89-A236-7E6D07C3FDCD}ProxyStubClsid “” = {00020424-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINESOFTWAREClassesInterface{6612AFDD-34AD-4B89-A236-7E6D07C3FDCD}ProxyStubClsid32 “” = {00020424-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINESOFTWAREClassesInterface{6612AFDD-34AD-4B89-A236-7E6D07C3FDCD}TypeLib “” = {ED85AEBE-F834-4088-B5D3-97EB2478A6CD}
HKEY_LOCAL_MACHINESOFTWAREClassesInterface{6612AFDD-34AD-4B89-A236-7E6D07C3FDCD}TypeLib “Version” = 1.0
HKEY_CURRENT_USERSoftwareOfferBox “last_CONFIG” = [REG_DWORD, value: 00000000]
HKEY_CURRENT_USERSoftwareOfferBox “next_CONFIG” = [REG_DWORD, value: 00000030]
HKEY_CURRENT_USERSoftwareOfferBox “last_SOFT” = [REG_DWORD, value: 00000000]
HKEY_CURRENT_USERSoftwareOfferBox “next_SOFT” = [REG_DWORD, value: 00000030]
HKEY_CURRENT_USERSoftwareOfferBox “last_DATA” = [REG_DWORD, value: 00000000]
HKEY_CURRENT_USERSoftwareOfferBox “next_DATA” = [REG_DWORD, value: 00000030]
HKEY_CURRENT_USERSoftwareOfferBox “CID” = [REG_DWORD, value: 00000000]
HKEY_CURRENT_USERSoftwareOfferBox “EME_prefix” =
HKEY_CURRENT_USERSoftwareOfferBox “start_o” = [REG_DWORD, value: 00000000]
HKEY_CURRENT_USERSoftwareOfferBox “nc_wait” = [REG_DWORD, value: 0000012C]
HKEY_CURRENT_USERSoftwareOfferBox “last_CONFIG” = [REG_DWORD, value: 4D07E5D1]
HKEY_CURRENT_USERSoftwareOfferBox “next_CONFIG” = [REG_DWORD, value: 00000030]
HKEY_CURRENT_USERSoftwareOfferBox “last_SOFT” = [REG_DWORD, value: 00000000]
HKEY_CURRENT_USERSoftwareOfferBox “next_SOFT” = [REG_DWORD, value: 00000030]
HKEY_CURRENT_USERSoftwareOfferBox “last_DATA” = [REG_DWORD, value: 00000000]
HKEY_CURRENT_USERSoftwareOfferBox “next_DATA” = [REG_DWORD, value: 00000030]
HKEY_CURRENT_USERSoftwareOfferBox “CID” = [REG_DWORD, value: 00000000]
HKEY_CURRENT_USERSoftwareOfferBox “EME_prefix” =
HKEY_CURRENT_USERSoftwareOfferBox “start_o” = [REG_DWORD, value: 00000000]
HKEY_CURRENT_USERSoftwareOfferBox “nc_wait” = [REG_DWORD, value: 0000012C]
HKEY_CURRENT_USERSoftwareOfferBox “next_CONFIG” = [REG_DWORD, value: 00000018]
HKEY_CURRENT_USERSoftwareOfferBox “CID” = [REG_DWORD, value: 00B57890]
HKEY_CURRENT_USERSoftwareOfferBox “EME_prefix” = O0AAMDE1CE11892880
HKEY_CURRENT_USERSoftwareOfferBox “last_DATA” = [REG_DWORD, value: 4D07E5D6]
HKEY_CURRENT_USERSoftwareOfferBox “start_o” = [REG_DWORD, value: 4D0A88E1]
HKEY_LOCAL_MACHINESOFTWARESearchquMediabarTb “Folder” = C:ProgrammeWindows Searchqu ToolbarToolBar
Reads HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTFSystemShared “CUAS”
HKEY_CURRENT_USERKeyboard LayoutToggle “Language Hotkey”
HKEY_CURRENT_USERKeyboard LayoutToggle “Layout Hotkey”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTF “EnableAnchorContext”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlSession ManagerAppCompatibility “DisableAppCompat”
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{871C5380-42A0-1069-A2EA-08002B30309D}InProcServer32 “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionApp PathsIEXPLORE.EXE “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerSetup “IExploreLastModifiedLow”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerSetup “IExploreLastModifiedHigh”
HKEY_LOCAL_MACHINESOFTWAREClassesInterface{EAB22AC1-30C1-11CF-A7EB-0000C05BAE0B}TypeLib “”
HKEY_LOCAL_MACHINESOFTWAREClassesInterface{B722BCCB-4E68-101B-A2BC-00AA00404770}ProxyStubClsid32 “”
HKEY_LOCAL_MACHINESOFTWAREClassesInterface{79EAC9C4-BAF9-11CE-8C82-00AA004BA90B}ProxyStubClsid32 “”
HKEY_LOCAL_MACHINESOFTWAREClassesInterface{000214E6-0000-0000-C000-000000000046}ProxyStubClsid32 “”
HKEY_LOCAL_MACHINESOFTWAREClassesInterface{93F2F68C-1D1B-11D3-A30E-00C04F79ABD1}ProxyStubClsid32 “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerMainFeatureControlFEATURE_INTERNET_SHELL_FOLDERS “sk14fr0.exe”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerMainFeatureControlFEATURE_INTERNET_SHELL_FOLDERS “*”
HKEY_LOCAL_MACHINESOFTWAREClassesHTTP “ShellFolder”
HKEY_LOCAL_MACHINESYSTEMWPAMediaCenter “Installed”
HKEY_LOCAL_MACHINESYSTEMWPAMediaCenter “Installed”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftRpcSecurityService “10”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlSecurityProviders “SecurityProviders”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Name”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Comment”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Capabilities”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “RpcId”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Version”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Type”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “TokenSize”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Name”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Comment”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Capabilities”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “RpcId”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Version”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Type”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “TokenSize”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Name”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Comment”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Capabilities”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “RpcId”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Version”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Type”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “TokenSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftRpcSecurityService “DefaultAuthLevel”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTFSystemShared “CUAS”
HKEY_CURRENT_USERKeyboard LayoutToggle “Language Hotkey”
HKEY_CURRENT_USERKeyboard LayoutToggle “Layout Hotkey”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTF “EnableAnchorContext”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionIMM “Ime File”
HKEY_CURRENT_USERSoftwareMicrosoftCTF “Disable Thread Input Manager”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftRpcSecurityService “10”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlSecurityProviders “SecurityProviders”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Name”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Comment”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Capabilities”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “RpcId”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Version”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Type”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “TokenSize”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Name”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Comment”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Capabilities”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “RpcId”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Version”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Type”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “TokenSize”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Name”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Comment”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Capabilities”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “RpcId”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Version”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Type”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “TokenSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftRpcSecurityService “DefaultAuthLevel”
HKEY_LOCAL_MACHINESYSTEMWPAMediaCenter “Installed”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTFSystemShared “CUAS”
HKEY_CURRENT_USERKeyboard LayoutToggle “Language Hotkey”
HKEY_CURRENT_USERKeyboard LayoutToggle “Layout Hotkey”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTF “EnableAnchorContext”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet Settings “ProxyEnable”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftRpcSecurityService “DefaultAuthLevel”
HKEY_LOCAL_MACHINESYSTEMWPAMediaCenter “Installed”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTFSystemShared “CUAS”
HKEY_CURRENT_USERKeyboard LayoutToggle “Language Hotkey”
HKEY_CURRENT_USERKeyboard LayoutToggle “Layout Hotkey”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTF “EnableAnchorContext”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersion “ProgramFilesDir”
HKEY_LOCAL_MACHINESYSTEMWPAMediaCenter “Installed”
HKEY_CURRENT_USERSoftwareOfferBox “Patched Data”
HKEY_CLASSES_ROOT “NetworkSharingHandler”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlProductOptions “ProductType”
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesLanmanServerDefaultSecurity “SrvsvcDefaultShareInfo”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer “NoRun”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer “NoDrives”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer “RestrictRun”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer “NoNetConnectDisconnect”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer “NoRecentDocsHistory”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer “NoClose”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTFSystemShared “CUAS”
HKEY_CURRENT_USERKeyboard LayoutToggle “Language Hotkey”
HKEY_CURRENT_USERKeyboard LayoutToggle “Layout Hotkey”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTF “EnableAnchorContext”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionIMM “Ime File”
HKEY_CURRENT_USERSoftwareMicrosoftCTF “Disable Thread Input Manager”
HKEY_LOCAL_MACHINESOFTWAREClassesTypeLib{ED85AEBE-F834-4088-B5D3-97EB2478A6CD}1.0 “”
HKEY_LOCAL_MACHINESOFTWAREClassesTypeLib{ED85AEBE-F834-4088-B5D3-97EB2478A6CD}1.0FLAGS “”
HKEY_LOCAL_MACHINESOFTWAREClassesTypeLib{ED85AEBE-F834-4088-B5D3-97EB2478A6CD}1.0win32 “”
HKEY_LOCAL_MACHINESOFTWAREClassesTypeLib{ED85AEBE-F834-4088-B5D3-97EB2478A6CD}1.0HELPDIR “”
HKEY_LOCAL_MACHINESOFTWAREClassesInterface{6612AFDD-34AD-4B89-A236-7E6D07C3FDCD} “”
HKEY_LOCAL_MACHINESOFTWAREClassesInterface{6612AFDD-34AD-4B89-A236-7E6D07C3FDCD}ProxyStubClsid “”
HKEY_LOCAL_MACHINESOFTWAREClassesInterface{6612AFDD-34AD-4B89-A236-7E6D07C3FDCD}ProxyStubClsid32 “”
HKEY_LOCAL_MACHINESOFTWAREClassesInterface{6612AFDD-34AD-4B89-A236-7E6D07C3FDCD}TypeLib “”
HKEY_LOCAL_MACHINESOFTWAREClassesInterface{6612AFDD-34AD-4B89-A236-7E6D07C3FDCD}TypeLib “Version”
HKEY_CURRENT_USERSoftwareOfferBox “last_CONFIG”
HKEY_CURRENT_USERSoftwareOfferBox “next_CONFIG”
HKEY_CURRENT_USERSoftwareOfferBox “last_SOFT”
HKEY_CURRENT_USERSoftwareOfferBox “next_SOFT”
HKEY_CURRENT_USERSoftwareOfferBox “last_DATA”
HKEY_CURRENT_USERSoftwareOfferBox “next_DATA”
HKEY_CURRENT_USERSoftwareOfferBox “iP”
HKEY_CURRENT_USERSoftwareOfferBox “start_o”
HKEY_CURRENT_USERSoftwareOfferBox “CID”
HKEY_CURRENT_USERSoftwareOfferBox “EME_prefix”
HKEY_CURRENT_USERSoftwareOfferBox “nc_wait”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTFSystemShared “CUAS”
HKEY_CURRENT_USERKeyboard LayoutToggle “Language Hotkey”
HKEY_CURRENT_USERKeyboard LayoutToggle “Layout Hotkey”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTF “EnableAnchorContext”
HKEY_CLASSES_ROOT “Interface{6612AFDD-34AD-4B89-A236-7E6D07C3FDCD}ProxyStubClsid32”
HKEY_CLASSES_ROOT “Interface{6612AFDD-34AD-4B89-A236-7E6D07C3FDCD}Forward”
HKEY_LOCAL_MACHINESOFTWAREClassesInterface{6612AFDD-34AD-4B89-A236-7E6D07C3FDCD}TypeLib “”
HKEY_LOCAL_MACHINESOFTWAREClassesInterface{6612AFDD-34AD-4B89-A236-7E6D07C3FDCD}TypeLib “Version”
HKEY_LOCAL_MACHINESOFTWAREClassesTypeLib{ED85AEBE-F834-4088-B5D3-97EB2478A6CD}1.0win32 “”
HKEY_LOCAL_MACHINESOFTWAREClassesTypeLib{00020430-0000-0000-C000-000000000046}2.0 “win32”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftRpc “UDTAlignmentPolicy”
HKEY_LOCAL_MACHINESOFTWAREOfferBox “campaign”
HKEY_LOCAL_MACHINESOFTWAREOfferBox “eme”
HKEY_LOCAL_MACHINESOFTWAREOfferBox “ul”
HKEY_LOCAL_MACHINESOFTWAREOfferBox “LID”
HKEY_LOCAL_MACHINESOFTWAREOfferBox “sbp”
HKEY_LOCAL_MACHINESOFTWAREOfferBox “subid”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer “NoRun”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer “NoDrives”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer “RestrictRun”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer “NoNetConnectDisconnect”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer “NoRecentDocsHistory”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer “NoClose”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTFSystemShared “CUAS”
HKEY_CURRENT_USERKeyboard LayoutToggle “Language Hotkey”
HKEY_CURRENT_USERKeyboard LayoutToggle “Layout Hotkey”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTF “EnableAnchorContext”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionIMM “Ime File”
HKEY_CURRENT_USERSoftwareMicrosoftCTF “Disable Thread Input Manager”
HKEY_CLASSES_ROOT “Interface{6612AFDD-34AD-4B89-A236-7E6D07C3FDCD}ProxyStubClsid32”
HKEY_CLASSES_ROOT “Interface{6612AFDD-34AD-4B89-A236-7E6D07C3FDCD}Forward”
HKEY_LOCAL_MACHINESOFTWAREClassesInterface{6612AFDD-34AD-4B89-A236-7E6D07C3FDCD}TypeLib “”
HKEY_LOCAL_MACHINESOFTWAREClassesInterface{6612AFDD-34AD-4B89-A236-7E6D07C3FDCD}TypeLib “Version”
HKEY_LOCAL_MACHINESOFTWAREClassesTypeLib{ED85AEBE-F834-4088-B5D3-97EB2478A6CD}1.0win32 “”
HKEY_LOCAL_MACHINESOFTWAREClassesTypeLib{00020430-0000-0000-C000-000000000046}2.0 “win32”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftRpc “UDTAlignmentPolicy”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet Explorer “Version”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftRpcSecurityService “10”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlSecurityProviders “SecurityProviders”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Name”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Comment”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Capabilities”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “RpcId”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Version”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Type”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “TokenSize”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Name”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Comment”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Capabilities”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “RpcId”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Version”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Type”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “TokenSize”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Name”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Comment”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Capabilities”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “RpcId”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Version”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Type”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “TokenSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftRpcSecurityService “DefaultAuthLevel”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTFSystemShared “CUAS”
HKEY_CURRENT_USERKeyboard LayoutToggle “Language Hotkey”
HKEY_CURRENT_USERKeyboard LayoutToggle “Layout Hotkey”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTF “EnableAnchorContext”
HKEY_LOCAL_MACHINESYSTEMWPAMediaCenter “Installed”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTFSystemShared “CUAS”
HKEY_CURRENT_USERKeyboard LayoutToggle “Language Hotkey”
HKEY_CURRENT_USERKeyboard LayoutToggle “Layout Hotkey”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTF “EnableAnchorContext”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersion “ProgramFilesDir”
HKEY_LOCAL_MACHINESYSTEMWPAMediaCenter “Installed”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionIMM “Ime File”
HKEY_CURRENT_USERSoftwareMicrosoftCTF “Disable Thread Input Manager”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTFSystemShared “CUAS”
HKEY_CURRENT_USERKeyboard LayoutToggle “Language Hotkey”
HKEY_CURRENT_USERKeyboard LayoutToggle “Layout Hotkey”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTF “EnableAnchorContext”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionIMM “Ime File”
HKEY_CURRENT_USERSoftwareMicrosoftCTF “Disable Thread Input Manager”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionSetup “SharedDir”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionSharedDlls “C:Dokumente und EinstellungenAdministratorLokale EinstellungenTempGLF2F1.tmp”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionSharedDlls “C:Dokumente und EinstellungenAdministratorLokale EinstellungenTempFun4IMFilesfiles.exe”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlSession ManagerAppCompatibility “DisableAppCompat”
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{56F9679E-7826-4C84-81F3-532071A8BCC5}InprocServer32 “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows SearchProtocolHandlersFile “ProgID”
HKEY_LOCAL_MACHINESOFTWAREClassesfile “ShellFolder”
HKEY_LOCAL_MACHINESOFTWAREClassesMapi “ShellFolder”
HKEY_LOCAL_MACHINESOFTWAREClassesOutlookexpress “ShellFolder”
HKEY_LOCAL_MACHINESOFTWAREClassesOTFS “ShellFolder”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersDefault “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersDefault “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersDefault “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersDefault “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.bmp “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.bmp “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.bmp “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.bmp “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.c “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.c “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.c “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.c “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.cpp “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.cpp “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.cpp “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.cpp “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.cs “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.cs “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.cs “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.cs “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.cxx “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.cxx “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.cxx “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.cxx “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.doc “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.doc “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.doc “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.doc “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.dot “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.dot “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.dot “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.dot “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.emf “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.emf “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.emf “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.emf “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.eml “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.eml “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.eml “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.eml “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.err “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.err “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.err “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.err “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.gif “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.gif “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.gif “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.gif “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.h “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.h “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.h “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.h “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.htm “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.htm “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.htm “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.htm “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.html “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.html “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.html “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.html “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.hxx “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.hxx “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.hxx “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.hxx “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.idl “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.idl “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.idl “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.idl “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.jpeg “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.jpeg “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.jpeg “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.jpeg “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.jpg “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.jpg “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.jpg “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.jpg “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.jsl “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.jsl “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.jsl “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.jsl “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.mht “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.mht “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.mht “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.mht “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.mhtml “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.mhtml “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.mhtml “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.mhtml “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.nws “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.nws “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.nws “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.nws “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.pdf “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.pdf “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.pdf “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.pdf “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.png “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.png “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.png “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.png “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.pot “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.pot “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.pot “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.pot “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.pps “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.pps “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.pps “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.pps “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.ppt “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.ppt “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.ppt “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.ppt “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.rtf “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.rtf “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.rtf “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.rtf “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.txt “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.txt “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.txt “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.txt “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.vb “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.vb “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.vb “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.vb “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.wmf “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.wmf “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.wmf “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.wmf “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.wrn “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.wrn “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.wrn “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.wrn “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.xls “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.xls “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.xls “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.xls “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.xlt “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.xlt “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.xlt “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.xlt “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.xml “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.xml “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.xml “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.xml “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.xsd “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.xsd “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.xsd “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension.xsd “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypecalendar “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypecalendar “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypecalendar “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypecalendar “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypecommunications “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypecommunications “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypecommunications “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypecommunications “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypecontact “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypecontact “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypecontact “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypecontact “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypedocument “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypedocument “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypedocument “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypedocument “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypeemail “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypeemail “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypeemail “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypeemail “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypefavorite “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypefavorite “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypefavorite “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypefavorite “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypefolder “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypefolder “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypefolder “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypefolder “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypeim “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypeim “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypeim “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypeim “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypeimages “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypeimages “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypeimages “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypeimages “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypemusic “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypemusic “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypemusic “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypemusic “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypenote “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypenote “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypenote “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypenote “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypepicture “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypepicture “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypepicture “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypepicture “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypepresentation “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypepresentation “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypepresentation “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypepresentation “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypeprogram “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypeprogram “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypeprogram “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypeprogram “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypespreadsheet “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypespreadsheet “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypespreadsheet “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypespreadsheet “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypetext “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypetext “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypetext “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypetext “ScriptOk”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypevideo “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypevideo “ContentType”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypevideo “TemplateUrl”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedTypevideo “ScriptOk”
HKEY_LOCAL_MACHINESYSTEMWPAMediaCenter “Installed”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionSharedDlls “C:Dokumente und EinstellungenAdministratorLokale EinstellungenTempGLF365.tmp”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersion “ProgramFilesDir”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionSharedDlls “C:Dokumente und EinstellungenAdministratorLokale EinstellungenTempSetupDataMngr_Searchqu.exe”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShell Folders “Common AppData”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionSharedDlls “C:ProgrammeFun4IMInstallerHelper.dll”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTFSystemShared “CUAS”
HKEY_CURRENT_USERKeyboard LayoutToggle “Language Hotkey”
HKEY_CURRENT_USERKeyboard LayoutToggle “Layout Hotkey”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTF “EnableAnchorContext”
HKEY_LOCAL_MACHINESOFTWAREClientsStartMenuInternet “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet Explorer “Version”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindows “AppInit_DLLs”
Enums HKEY_LOCAL_MACHINESOFTWAREClassesTypeLib{ED85AEBE-F834-4088-B5D3-97EB2478A6CD}
HKEY_LOCAL_MACHINESOFTWAREClassesTypeLib{ED85AEBE-F834-4088-B5D3-97EB2478A6CD}1.0
HKEY_LOCAL_MACHINESOFTWAREClassesTypeLib{ED85AEBE-F834-4088-B5D3-97EB2478A6CD}
HKEY_LOCAL_MACHINESOFTWAREClassesTypeLib{ED85AEBE-F834-4088-B5D3-97EB2478A6CD}1.0
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows SearchProtocolHandlers
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows SearchProtocolHandlersFile
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersExtension
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows Desktop SearchPreviewersPerceivedType

File Changes by all processes
New Files C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpwsget.exe
C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpboost.ico
C:Dokumente und EinstellungenAdministratorDesktopImprove Your PC.lnk
C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmp~data.tmp
C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpmosquito.exe
C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpmosquito.exe.part
DeviceTcp
DeviceIp
DeviceIp
DeviceRasAcd
C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpOfferBoxSetup_FR.exe
C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpOfferBoxSetup_FR.exe.part
C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpWhiteSmokeWriter.exe
C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpWhiteSmokeWriter.exe.part
C:DOKUME~1ADMINI~1LOKALE~1TempnsfD.tmpinetc.dll
C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpnspB.tmp
DeviceTcp
DeviceIp
DeviceIp
DeviceRasAcd
C:DOKUME~1ADMINI~1LOKALE~1Tempnsy28.tmpNsisPluginOB.dll
C:DOKUME~1ADMINI~1LOKALE~1Tempnsy28.tmpNSISdl.dll
C:DOKUME~1ADMINI~1LOKALE~1TempOB.exe
DeviceRasAcd
C:DOKUME~1ADMINI~1LOKALE~1TempnswBB.tmp
C:ProgrammeOfferBoxOfferBoxLauncher.exe
C:ProgrammeOfferBoxOfferBox.exe
C:ProgrammeOfferBoxOfferBoxEngine.dll
C:ProgrammeOfferBoxreslanguage.xml
C:ProgrammeOfferBoxresloader.gif
C:ProgrammeOfferBoxOfferBoxBHO.dll
C:ProgrammeOfferBoxofferboxffx@offerbox.comchrome.manifest
C:ProgrammeOfferBoxofferboxffx@offerbox.cominstall.rdf
C:ProgrammeOfferBoxofferboxffx@offerbox.comchromecontentevents.js
C:ProgrammeOfferBoxofferboxffx@offerbox.comchromecontentoverlay.xul
C:ProgrammeOfferBoxofferboxffx@offerbox.comcomponentsOfferBoxXpCom.dll
C:ProgrammeOfferBoxofferboxffx@offerbox.comcomponentsOfferBoxXpCom.xpt
C:ProgrammeOfferBoxOfferBoxChromeExtension.crx
C:DOKUME~1ADMINI~1LOKALE~1Tempnsx146.tmpNsisPluginOB.dll
C:DOKUME~1ADMINI~1LOKALE~1Tempnsx146.tmpNsisPluginOB.dll
C:Dokumente und EinstellungenAll UsersStartmenüProgrammeOfferBox Browser.lnk
C:ProgrammeOfferBoxuninst.exe
C:Dokumente und EinstellungenAdministratorAnwendungsdatenOfferBoxconfig.xml
DeviceRasAcd
DeviceTcp
DeviceIp
DeviceIp
C:Dokumente und EinstellungenAdministratorAnwendungsdatenOfferBoxconfig.tmp
C:Dokumente und EinstellungenAdministratorAnwendungsdatenOfferBoxconfig.dat
C:DOKUME~1ADMINI~1LOKALE~1Tempnsm2CF.tmpUAC.dll
C:DOKUME~1ADMINI~1LOKALE~1Tempnsj2D5.tmp.exe
C:DOKUME~1ADMINI~1LOKALE~1Tempnsm2CF.tmpSystem.dll
C:DOKUME~1ADMINI~1LOKALE~1Tempnsj2D7.tmp
C:DOKUME~1ADMINI~1LOKALE~1TempWhiteSmokeMicrosoft.VC80.CRT.manifest
C:DOKUME~1ADMINI~1LOKALE~1TempWhiteSmokemsvcp80.dll
C:DOKUME~1ADMINI~1LOKALE~1TempWhiteSmokemsvcr80.dll
C:DOKUME~1ADMINI~1LOKALE~1TempWhiteSmokeCheckLockedWsFiles.exe
C:DOKUME~1ADMINI~1LOKALE~1TempGLJ2E7.tmp
C:DOKUME~1ADMINI~1LOKALE~1TempGLK2EA.tmp
C:DOKUME~1ADMINI~1LOKALE~1TempGLG2EF.tmp
C:DOKUME~1ADMINI~1LOKALE~1Temp~GLH0000.TMP
C:DOKUME~1ADMINI~1LOKALE~1TempGLF2F1.tmp
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFiles~GLH0001.TMP
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesfiles.exe
C:DOKUME~1ADMINI~1LOKALE~1Temp~GLH0002.TMP
C:DOKUME~1ADMINI~1LOKALE~1TempGLF365.tmp
C:DOKUME~1ADMINI~1LOKALE~1Temp~GLH0003.TMP
C:DOKUME~1ADMINI~1LOKALE~1TempSetupDataMngr_Searchqu.exe
C:ProgrammeFun4IM~GLH0004.TMP
C:ProgrammeFun4IMInstallerHelper.dll
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1001.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1001.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1001.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1002.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1002.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1002.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1003.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1003.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1003.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1004.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1004.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1005.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1005.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1006.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1006Fun4IM.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1006Fun4IM.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1011.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1011.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1012.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1012.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1013.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1013.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1014.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1014.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1051.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1052.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1053.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1054.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1055.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1056.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1057.dat
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagesbottomBg.gif
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagesclose.gif
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagescontentBg.gif
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesdownloadingFun4IM.gif
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagesFun4IMstartMenuTopText.gif
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagestopBg.gif
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimageswhat_next.gif
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsIEHTMLblank.html
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNHTMLblank.html
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEHTMLblank.html
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooHTMLblank.html
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsIEHTMLerror.html
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNHTMLerror.html
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEHTMLerror.html
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooHTMLerror.html
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialtutorial.html
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesPlugins.ini
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagesscreen.jpg
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEimageswink_play.jpg
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsIEbandoo.js
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticlicenseFun4IM.rtf
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcessearchpluginsWebSearch.src
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagesFun4IMinstallation_page_frame.swf
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge0.wav
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge1.wav
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge2.wav
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge3.wav
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge4.wav
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge5.wav
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesBandooMessages.xml
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarBandooToolbar.xml
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarBandooToolbar.xml
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarBandooToolbar.xml
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarBandooToolbarV9.xml
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcessearchpluginsWebSearch.xml
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticWPSubsystems.xml
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBandooRes.dll
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBndHook.dll
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinCrashRpt.dll
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinFlashAnimator.dll
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinGIFAnimator.dll
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinieplugin.dll
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinInstallerHelper.dll
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticlibungif4.dll
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinmsnplugin.dll
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinOEPlugin.dll
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticuitools.dll
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinYahooPlugin.dll
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBandoo.exe
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBandooGo.exe
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBandooUI.exe
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBndCore.exe
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinExtensionsManager.exe
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinFFoxPackage.exe
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticFFSettings.exe
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinPreUninstall.exe
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticSetupDataMngr_Searchqu.exe
C:DOKUME~1ADMINI~1LOKALE~1Tempnsv36C.tmpSystem.dll
C:DOKUME~1ADMINI~1LOKALE~1Tempnsv36C.tmpSystem.dll
C:DOKUME~1ADMINI~1LOKALE~1Tempnsv36C.tmpGetVersion.dll
C:DOKUME~1ADMINI~1LOKALE~1TempSearchqu_DMDataMngr.dll
C:DOKUME~1ADMINI~1LOKALE~1TempSearchqu_DMDataMngrUI.exe
C:DOKUME~1ADMINI~1LOKALE~1TempSearchqu_DMInstallHelper.dll
C:DOKUME~1ADMINI~1LOKALE~1TempSearchqu_DMWebSearch.xml
C:DOKUME~1ADMINI~1LOKALE~1TempSearchqu_DMSearchquMediaBar.exe
C:DOKUME~1ADMINI~1LOKALE~1Tempnsv36C.tmpKillProcDLL.dll
C:DOKUME~1ADMINI~1LOKALE~1Tempnsv36C.tmpKillProcDLL.dll
Opened Files C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmp~data.tmp
C:WINDOWSRegistrationR000000000007.clb
C:WINDOWSsystem32ieframe.dll
C:ProgrammeInternet ExplorerIEXPLORE.EXE
.PIPElsarpc
.PIPEwkssvc
C:WINDOWSAppPatchsysmain.sdb
C:WINDOWSAppPatchsystest.sdb
DeviceNamedPipeShimViewer
C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmp
C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpOfferBoxSetup_FR.exe.part
C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpmosquito.exe.part
C:WINDOWSAppPatchsysmain.sdb
C:WINDOWSAppPatchsystest.sdb
DeviceNamedPipeShimViewer
C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmp
.PIPEROUTER
.PIPElsarpc
c:autoexec.bat
.Ip
C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpWhiteSmokeWriter.exe.part
.PIPElsarpc
C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpmosquito.exe
.PIPEROUTER
c:autoexec.bat
.Ip
C:WINDOWSAppPatchsysmain.sdb
C:WINDOWSAppPatchsystest.sdb
DeviceNamedPipeShimViewer
C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmp
.PIPElsarpc
C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpOfferBoxSetup_FR.exe
C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpOfferBoxSetup_FR.exe
C:WINDOWSAppPatchsysmain.sdb
C:WINDOWSAppPatchsystest.sdb
DeviceNamedPipeShimViewer
C:DOKUME~1ADMINI~1LOKALE~1Temp
.PIPElsarpc
C:DOKUME~1ADMINI~1LOKALE~1TempOB.exe
C:WINDOWSAppPatchsysmain.sdb
C:WINDOWSAppPatchsystest.sdb
DeviceNamedPipeShimViewer
C:ProgrammeOfferBox
C:WINDOWSRegistrationR000000000007.clb
C:Dokumente und EinstellungenAdministratorAnwendungsdatenOfferBoxconfig.xml
.PIPEsrvsvc
.PIPEwkssvc
C:WINDOWSRegistrationR000000000007.clb
.PIPElsarpc
C:ProgrammeOfferBoxOfferBox.exe
C:Dokumente und EinstellungenAdministratorAnwendungsdatenOfferBoxconfig.xml
C:Dokumente und EinstellungenAdministratorAnwendungsdatenOfferBoxconfig.xml
C:WINDOWSRegistrationR000000000007.clb
.PIPElsarpc
C:ProgrammeOfferBoxOfferBox.exe
C:WINDOWSsystem32stdole2.tlb
C:WINDOWSRegistrationR000000000007.clb
.PIPElsarpc
C:ProgrammeOfferBoxOfferBox.exe
C:WINDOWSsystem32stdole2.tlb
C:Dokumente und EinstellungenAdministratorAnwendungsdatenOfferBoxconfig.xml
C:Dokumente und EinstellungenAdministratorAnwendungsdatenOfferBoxconfig.xml
.PIPEROUTER
c:autoexec.bat
.Ip
C:Dokumente und EinstellungenAdministratorAnwendungsdatenOfferBoxconfig.tmp
.PIPElsarpc
C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpnspB.tmp
C:WINDOWSAppPatchsysmain.sdb
C:WINDOWSAppPatchsystest.sdb
DeviceNamedPipeShimViewer
C:DOKUME~1ADMINI~1LOKALE~1Temp
.PIPElsarpc
C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpWhiteSmokeWriter.exe
C:WINDOWSAppPatchsysmain.sdb
C:WINDOWSAppPatchsystest.sdb
DeviceNamedPipeShimViewer
C:DOKUME~1ADMINI~1LOKALE~1TempWhiteSmoke
C:DOKUME~1ADMINI~1LOKALE~1Tempnsj2D5.tmp.exe
.PIPEwkssvc
.PIPElsarpc
C:ProgrammeWindows Desktop SearchMSNLNamespaceMgr.dll
C:WINDOWSRegistrationR000000000007.clb
C:WINDOWSAppPatchsysmain.sdb
C:WINDOWSAppPatchsystest.sdb
DeviceNamedPipeShimViewer
C:DOKUME~1ADMINI~1LOKALE~1TempFUN4IM~1
C:DOKUME~1ADMINI~1LOKALE~1TempFUN4IM~1BinINSTAL~1.DLL
C:DOKUME~1ADMINI~1LOKALE~1TempFUN4IM~1StaticSETUPD~1.EXE
C:DOKUME~1ADMINI~1LOKALE~1Temp
Bandoo.exe
C:DOKUME~1ADMINI~1LOKALE~1TempFUN4IM~1files.exe
.PIPElsarpc
C:DOKUME~1ADMINI~1LOKALE~1TempSETUPD~1.EXE
.PIPEwkssvc
Deleted Files C:DOKUME~1ADMINI~1LOKALE~1Tempnsp9.tmp
C:DOKUME~1ADMINI~1LOKALE~1TempnsfD.tmp
C:DOKUME~1ADMINI~1LOKALE~1TempnsfD.tmpinetc.dll
C:DOKUME~1ADMINI~1LOKALE~1Tempnsy26.tmp
C:DOKUME~1ADMINI~1LOKALE~1Tempnsy28.tmp
C:DOKUME~1ADMINI~1LOKALE~1Tempnsy28.tmpNSISdl.dll
C:DOKUME~1ADMINI~1LOKALE~1Tempnsy28.tmpNsisPluginOB.dll
C:DOKUME~1ADMINI~1LOKALE~1TempnsrB9.tmp
C:DOKUME~1ADMINI~1LOKALE~1Tempnsx146.tmp
C:DOKUME~1ADMINI~1LOKALE~1Tempnsx146.tmpNsisPluginOB.dll
C:DOKUME~1ADMINI~1LOKALE~1Tempnsh2CD.tmp
C:DOKUME~1ADMINI~1LOKALE~1Tempnsm2CF.tmp
C:DOKUME~1ADMINI~1LOKALE~1Tempnsj2D3.tmp
C:DOKUME~1ADMINI~1LOKALE~1TempGLB2ED.tmp
C:DOKUME~1ADMINI~1LOKALE~1TempGLF2F1.tmp
C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesfiles.exe
C:DOKUME~1ADMINI~1LOKALE~1TempGLF365.tmp
C:DOKUME~1ADMINI~1LOKALE~1TempSetupDataMngr_Searchqu.exe
C:ProgrammeFun4IMInstallerHelper.dll
C:DOKUME~1ADMINI~1LOKALE~1Tempnsa36A.tmp
C:DOKUME~1ADMINI~1LOKALE~1Tempnsv36C.tmp
Chronological Order Open File: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmp~data.tmp (OPEN_EXISTING)
Create File: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpwsget.exe
Get File Attributes: C:WINDOWSRegistration Flags: (SECURITY_ANONYMOUS)
Open File: C:WINDOWSRegistrationR000000000007.clb (OPEN_EXISTING)
Get File Attributes: C:Dokumente und EinstellungenAdministratorDesktopImprove Your PC.lnk Flags: (SECURITY_ANONYMOUS)
Create File: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpboost.ico
Open File: C:WINDOWSsystem32ieframe.dll (OPEN_EXISTING)
Open File: C:ProgrammeInternet ExplorerIEXPLORE.EXE (OPEN_EXISTING)
Create File: C:Dokumente und EinstellungenAdministratorDesktopImprove Your PC.lnk
Get File Attributes: C:WINDOWS Flags: (SECURITY_ANONYMOUS)
Open File: .PIPElsarpc (OPEN_EXISTING)
Get File Attributes: C:Dokumente und EinstellungenAdministratorStartmenüdesktop.ini Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:Dokumente und EinstellungenAll UsersStartmenüdesktop.ini Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:Dokumente und EinstellungenAll UsersAnwendungsdatendesktop.ini Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:Dokumente und EinstellungenAdministratorAnwendungsdatendesktop.ini Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:Dokumente und EinstellungenAdministratorEigene Dateiendesktop.ini Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:Dokumente und EinstellungenAdministratorEigene DateienEigene Bilderdesktop.ini Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:Programmedesktop.ini Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:Dokumente und EinstellungenAll UsersDokumentedesktop.ini Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:Dokumente und EinstellungenAll UsersDokumenteEigene Bilderdesktop.ini Flags: (SECURITY_ANONYMOUS)
Open File: .PIPEwkssvc (OPEN_EXISTING)
Get File Attributes: C:Dokumente und EinstellungenAll UsersDokumenteEigene Musikdesktop.ini Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:Dokumente und EinstellungenAll UsersDokumenteEigene Videosdesktop.ini Flags: (SECURITY_ANONYMOUS)
Open File: C:WINDOWSAppPatchsysmain.sdb (OPEN_EXISTING)
Open File: C:WINDOWSAppPatchsystest.sdb (OPEN_EXISTING)
Open File: DeviceNamedPipeShimViewer (OPEN_EXISTING)
Open File: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmp ()
Find File: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpwsget.exe
Create File: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmp~data.tmp
Create File: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpmosquito.exe
Open File: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpOfferBoxSetup_FR.exe.part (OPEN_EXISTING)
Open File: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpmosquito.exe.part (OPEN_EXISTING)
Create File: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpmosquito.exe.part
Open File: C:WINDOWSAppPatchsysmain.sdb (OPEN_EXISTING)
Open File: C:WINDOWSAppPatchsystest.sdb (OPEN_EXISTING)
Open File: DeviceNamedPipeShimViewer (OPEN_EXISTING)
Open File: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmp ()
Find File: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpmosquito.exe
Open File: .PIPEROUTER (OPEN_EXISTING)
Open File: .PIPElsarpc (OPEN_EXISTING)
Get File Attributes: c:autoexec.bat Flags: (SECURITY_ANONYMOUS)
Open File: c:autoexec.bat (OPEN_EXISTING)
Find File: C:Dokumente und EinstellungenAll UsersAnwendungsdatenMicrosoftNetworkConnectionsPbk*.pbk
Find File: C:WINDOWSsystem32Ras*.pbk
Create/Open File: DeviceTcp (OPEN_ALWAYS)
Create/Open File: DeviceIp (OPEN_ALWAYS)
Create/Open File: DeviceIp (OPEN_ALWAYS)
Open File: .Ip (OPEN_EXISTING)
Find File: C:Dokumente und EinstellungenAdministratorAnwendungsdatenMicrosoftNetworkConnectionsPbk*.pbk
Create/Open File: DeviceRasAcd (OPEN_ALWAYS)
Create/Open File: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpOfferBoxSetup_FR.exe (OPEN_ALWAYS)
Create File: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpOfferBoxSetup_FR.exe.part
Open File: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpWhiteSmokeWriter.exe.part (OPEN_EXISTING)
Find File: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpOfferBoxSetup_FR.exe
Create/Open File: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpWhiteSmokeWriter.exe (OPEN_ALWAYS)
Create File: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpWhiteSmokeWriter.exe.part
Find File: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpWhiteSmokeWriter.exe
Get File Attributes: C:WINDOWS Flags: (SECURITY_ANONYMOUS)
Open File: .PIPElsarpc (OPEN_EXISTING)
Delete File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsp9.tmp
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpmosquito.exe Flags: (SECURITY_ANONYMOUS)
Open File: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpmosquito.exe (OPEN_EXISTING)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempnsfD.tmp
Delete File: C:DOKUME~1ADMINI~1LOKALE~1TempnsfD.tmp
Get File Attributes: C:DOKUME~1 Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1 Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1 Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Temp Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempnsfD.tmpinetc.dll Flags: (SECURITY_ANONYMOUS)
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempnsfD.tmpinetc.dll
Create File: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpnspB.tmp
Open File: .PIPEROUTER (OPEN_EXISTING)
Get File Attributes: c:autoexec.bat Flags: (SECURITY_ANONYMOUS)
Open File: c:autoexec.bat (OPEN_EXISTING)
Find File: C:Dokumente und EinstellungenAll UsersAnwendungsdatenMicrosoftNetworkConnectionsPbk*.pbk
Find File: C:WINDOWSsystem32Ras*.pbk
Create/Open File: DeviceTcp (OPEN_ALWAYS)
Create/Open File: DeviceIp (OPEN_ALWAYS)
Create/Open File: DeviceIp (OPEN_ALWAYS)
Open File: .Ip (OPEN_EXISTING)
Find File: C:Dokumente und EinstellungenAdministratorAnwendungsdatenMicrosoftNetworkConnectionsPbk*.pbk
Create/Open File: DeviceRasAcd (OPEN_ALWAYS)
Open File: C:WINDOWSAppPatchsysmain.sdb (OPEN_EXISTING)
Open File: C:WINDOWSAppPatchsystest.sdb (OPEN_EXISTING)
Open File: DeviceNamedPipeShimViewer (OPEN_EXISTING)
Open File: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmp ()
Find File: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpnspB.tmp
Find File: C:DOKUME~1ADMINI~1LOKALE~1Temp
Find File: C:DOKUME~1ADMINI~1LOKALE~1
Find File: C:DOKUME~1ADMINI~1
Find File: C:DOKUME~1
Get File Attributes: C: Flags: (SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempnsfD.tmp*.*
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempnsfD.tmpinetc.dll Flags: (FILE_ATTRIBUTE_ARCHIVE FILE_ATTRIBUTE_COMPRESSED FILE_ATTRIBUTE_COMPRESSED SECURITY_ANONYMOUS)
Delete File: C:DOKUME~1ADMINI~1LOKALE~1TempnsfD.tmpinetc.dll
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempnsfD.tmp Flags: (SECURITY_ANONYMOUS)
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempnsfD.tmp Flags: (FILE_ATTRIBUTE_COMPRESSED FILE_ATTRIBUTE_COMPRESSED SECURITY_ANONYMOUS)
Get File Attributes: C:WINDOWS Flags: (SECURITY_ANONYMOUS)
Open File: .PIPElsarpc (OPEN_EXISTING)
Delete File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsy26.tmp
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpOfferBoxSetup_FR.exe Flags: (SECURITY_ANONYMOUS)
Open File: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpOfferBoxSetup_FR.exe (OPEN_EXISTING)
Find File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsy28.tmp
Delete File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsy28.tmp
Get File Attributes: C:DOKUME~1 Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1 Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1 Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Temp Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Tempnsy28.tmpNsisPluginOB.dll Flags: (SECURITY_ANONYMOUS)
Create File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsy28.tmpNsisPluginOB.dll
Open File: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpOfferBoxSetup_FR.exe (OPEN_EXISTING)
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Tempnsy28.tmpNSISdl.dll Flags: (SECURITY_ANONYMOUS)
Create File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsy28.tmpNSISdl.dll
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempOB.exe
Create/Open File: DeviceRasAcd (OPEN_ALWAYS)
Open File: C:WINDOWSAppPatchsysmain.sdb (OPEN_EXISTING)
Open File: C:WINDOWSAppPatchsystest.sdb (OPEN_EXISTING)
Open File: DeviceNamedPipeShimViewer (OPEN_EXISTING)
Open File: C:DOKUME~1ADMINI~1LOKALE~1Temp ()
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempOB.exe
Find File: C:DOKUME~1ADMINI~1LOKALE~1Temp
Find File: C:DOKUME~1ADMINI~1LOKALE~1
Find File: C:DOKUME~1ADMINI~1
Find File: C:DOKUME~1
Get File Attributes: C: Flags: (SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsy28.tmp*.*
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Tempnsy28.tmpNSISdl.dll Flags: (FILE_ATTRIBUTE_ARCHIVE FILE_ATTRIBUTE_COMPRESSED FILE_ATTRIBUTE_COMPRESSED SECURITY_ANONYMOUS)
Delete File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsy28.tmpNSISdl.dll
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Tempnsy28.tmpNsisPluginOB.dll Flags: (FILE_ATTRIBUTE_ARCHIVE FILE_ATTRIBUTE_COMPRESSED FILE_ATTRIBUTE_COMPRESSED SECURITY_ANONYMOUS)
Delete File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsy28.tmpNsisPluginOB.dll
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Tempnsy28.tmp Flags: (SECURITY_ANONYMOUS)
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Tempnsy28.tmp Flags: (FILE_ATTRIBUTE_COMPRESSED FILE_ATTRIBUTE_COMPRESSED SECURITY_ANONYMOUS)
Get File Attributes: C:WINDOWS Flags: (SECURITY_ANONYMOUS)
Open File: .PIPElsarpc (OPEN_EXISTING)
Delete File: C:DOKUME~1ADMINI~1LOKALE~1TempnsrB9.tmp
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempOB.exe Flags: (SECURITY_ANONYMOUS)
Open File: C:DOKUME~1ADMINI~1LOKALE~1TempOB.exe (OPEN_EXISTING)
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempnswBB.tmp
Get File Attributes: C:Programme Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:ProgrammeOfferBoxOfferBoxLauncher.exe Flags: (SECURITY_ANONYMOUS)
Create File: C:ProgrammeOfferBoxOfferBoxLauncher.exe
Set File Time: C:ProgrammeOfferBoxOfferBoxLauncher.exe
Get File Attributes: C:ProgrammeOfferBoxOfferBox.exe Flags: (SECURITY_ANONYMOUS)
Create File: C:ProgrammeOfferBoxOfferBox.exe
Set File Time: C:ProgrammeOfferBoxOfferBox.exe
Get File Attributes: C:ProgrammeOfferBoxOfferBoxEngine.dll Flags: (SECURITY_ANONYMOUS)
Create File: C:ProgrammeOfferBoxOfferBoxEngine.dll
Set File Time: C:ProgrammeOfferBoxOfferBoxEngine.dll
Get File Attributes: C:ProgrammeOfferBox Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:ProgrammeOfferBoxreslanguage.xml Flags: (SECURITY_ANONYMOUS)
Create File: C:ProgrammeOfferBoxreslanguage.xml
Set File Time: C:ProgrammeOfferBoxreslanguage.xml
Get File Attributes: C:ProgrammeOfferBoxresloader.gif Flags: (SECURITY_ANONYMOUS)
Create File: C:ProgrammeOfferBoxresloader.gif
Set File Time: C:ProgrammeOfferBoxresloader.gif
Open File: C:WINDOWSAppPatchsysmain.sdb (OPEN_EXISTING)
Open File: C:WINDOWSAppPatchsystest.sdb (OPEN_EXISTING)
Open File: DeviceNamedPipeShimViewer (OPEN_EXISTING)
Open File: C:ProgrammeOfferBox ()
Find File: C:ProgrammeOfferBoxOfferBox.exe
Get File Attributes: C:ProgrammeOfferBoxOfferBoxBHO.dll Flags: (SECURITY_ANONYMOUS)
Create File: C:ProgrammeOfferBoxOfferBoxBHO.dll
Set File Time: C:ProgrammeOfferBoxOfferBoxBHO.dll
Find File: C:ProgrammeOfferBoxofferboxffx@offerbox.com
Find File: C:ProgrammeOfferBox
Find File: C:Programme
Get File Attributes: C: Flags: (SECURITY_ANONYMOUS)
Find File: C:ProgrammeOfferBoxofferboxffx@offerbox.com*.*
Get File Attributes: C:ProgrammeOfferBoxofferboxffx@offerbox.comchrome.manifest Flags: (SECURITY_ANONYMOUS)
Create File: C:ProgrammeOfferBoxofferboxffx@offerbox.comchrome.manifest
Set File Time: C:ProgrammeOfferBoxofferboxffx@offerbox.comchrome.manifest
Get File Attributes: C:ProgrammeOfferBoxofferboxffx@offerbox.cominstall.rdf Flags: (SECURITY_ANONYMOUS)
Create File: C:ProgrammeOfferBoxofferboxffx@offerbox.cominstall.rdf
Set File Time: C:ProgrammeOfferBoxofferboxffx@offerbox.cominstall.rdf
Get File Attributes: C:ProgrammeOfferBoxofferboxffx@offerbox.com Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:ProgrammeOfferBoxofferboxffx@offerbox.comchrome Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:ProgrammeOfferBoxofferboxffx@offerbox.comchromecontentevents.js Flags: (SECURITY_ANONYMOUS)
Create File: C:ProgrammeOfferBoxofferboxffx@offerbox.comchromecontentevents.js
Set File Time: C:ProgrammeOfferBoxofferboxffx@offerbox.comchromecontentevents.js
Get File Attributes: C:ProgrammeOfferBoxofferboxffx@offerbox.comchromecontentoverlay.xul Flags: (SECURITY_ANONYMOUS)
Create File: C:ProgrammeOfferBoxofferboxffx@offerbox.comchromecontentoverlay.xul
Set File Time: C:ProgrammeOfferBoxofferboxffx@offerbox.comchromecontentoverlay.xul
Get File Attributes: C:ProgrammeOfferBoxofferboxffx@offerbox.comcomponentsOfferBoxXpCom.dll Flags: (SECURITY_ANONYMOUS)
Create File: C:ProgrammeOfferBoxofferboxffx@offerbox.comcomponentsOfferBoxXpCom.dll
Set File Time: C:ProgrammeOfferBoxofferboxffx@offerbox.comcomponentsOfferBoxXpCom.dll
Get File Attributes: C:ProgrammeOfferBoxofferboxffx@offerbox.comcomponentsOfferBoxXpCom.xpt Flags: (SECURITY_ANONYMOUS)
Create File: C:ProgrammeOfferBoxofferboxffx@offerbox.comcomponentsOfferBoxXpCom.xpt
Set File Time: C:ProgrammeOfferBoxofferboxffx@offerbox.comcomponentsOfferBoxXpCom.xpt
Get File Attributes: C:ProgrammeOfferBoxOfferBoxChromeExtension.crx Flags: (SECURITY_ANONYMOUS)
Create File: C:ProgrammeOfferBoxOfferBoxChromeExtension.crx
Set File Time: C:ProgrammeOfferBoxOfferBoxChromeExtension.crx
Find File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsx146.tmp
Delete File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsx146.tmp
Get File Attributes: C:DOKUME~1 Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1 Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1 Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Temp Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Tempnsx146.tmpNsisPluginOB.dll Flags: (SECURITY_ANONYMOUS)
Create File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsx146.tmpNsisPluginOB.dll
Get File Attributes: C:WINDOWSRegistration Flags: (SECURITY_ANONYMOUS)
Open File: C:WINDOWSRegistrationR000000000007.clb (OPEN_EXISTING)
Open File: C:Dokumente und EinstellungenAdministratorAnwendungsdatenOfferBoxconfig.xml (OPEN_EXISTING)
Create File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsx146.tmpNsisPluginOB.dll
Get File Attributes: C:Programmedesktop.ini Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:Dokumente und EinstellungenAdministratorEigene Dateiendesktop.ini Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:Dokumente und EinstellungenAll UsersDokumentedesktop.ini Flags: (SECURITY_ANONYMOUS)
Open File: .PIPEsrvsvc (OPEN_EXISTING)
Get File Attributes: C:Dokumente und EinstellungenAll UsersStartmenüProgrammeOfferBox Browser.lnk Flags: (SECURITY_ANONYMOUS)
Create File: C:Dokumente und EinstellungenAll UsersStartmenüProgrammeOfferBox Browser.lnk
Get File Attributes: C:Dokumente und EinstellungenAdministratorStartmenüdesktop.ini Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:Dokumente und EinstellungenAll UsersStartmenüdesktop.ini Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:Dokumente und EinstellungenAll UsersAnwendungsdatendesktop.ini Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:Dokumente und EinstellungenAdministratorAnwendungsdatendesktop.ini Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:Dokumente und EinstellungenAdministratorEigene DateienEigene Bilderdesktop.ini Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:Dokumente und EinstellungenAll UsersDokumenteEigene Bilderdesktop.ini Flags: (SECURITY_ANONYMOUS)
Open File: .PIPEwkssvc (OPEN_EXISTING)
Get File Attributes: C:Dokumente und EinstellungenAll UsersDokumenteEigene Musikdesktop.ini Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:Dokumente und EinstellungenAll UsersDokumenteEigene Videosdesktop.ini Flags: (SECURITY_ANONYMOUS)
Find File: C:ProgrammeOfferBoxOfferBoxLauncher.exe
Get File Attributes: C:ProgrammeOfferBoxuninst.exe Flags: (SECURITY_ANONYMOUS)
Create File: C:ProgrammeOfferBoxuninst.exe
Find File: C:DOKUME~1ADMINI~1LOKALE~1Temp
Find File: C:DOKUME~1ADMINI~1LOKALE~1
Find File: C:DOKUME~1ADMINI~1
Find File: C:DOKUME~1
Find File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsx146.tmp*.*
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Tempnsx146.tmpNsisPluginOB.dll Flags: (FILE_ATTRIBUTE_ARCHIVE FILE_ATTRIBUTE_COMPRESSED FILE_ATTRIBUTE_COMPRESSED SECURITY_ANONYMOUS)
Delete File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsx146.tmpNsisPluginOB.dll
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Tempnsx146.tmp Flags: (SECURITY_ANONYMOUS)
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Tempnsx146.tmp Flags: (FILE_ATTRIBUTE_COMPRESSED FILE_ATTRIBUTE_COMPRESSED SECURITY_ANONYMOUS)
Get File Attributes: C:WINDOWSRegistration Flags: (SECURITY_ANONYMOUS)
Open File: C:WINDOWSRegistrationR000000000007.clb (OPEN_EXISTING)
Open File: .PIPElsarpc (OPEN_EXISTING)
Open File: C:ProgrammeOfferBoxOfferBox.exe (OPEN_EXISTING)
Open File: C:Dokumente und EinstellungenAdministratorAnwendungsdatenOfferBoxconfig.xml (OPEN_EXISTING)
Open File: C:Dokumente und EinstellungenAdministratorAnwendungsdatenOfferBoxconfig.xml (OPEN_EXISTING)
Create File: C:Dokumente und EinstellungenAdministratorAnwendungsdatenOfferBoxconfig.xml
Get File Attributes: C:WINDOWSRegistration Flags: (SECURITY_ANONYMOUS)
Open File: C:WINDOWSRegistrationR000000000007.clb (OPEN_EXISTING)
Open File: .PIPElsarpc (OPEN_EXISTING)
Open File: C:ProgrammeOfferBoxOfferBox.exe (OPEN_EXISTING)
Open File: C:WINDOWSsystem32stdole2.tlb (OPEN_EXISTING)
Get File Attributes: C:WINDOWSRegistration Flags: (SECURITY_ANONYMOUS)
Open File: C:WINDOWSRegistrationR000000000007.clb (OPEN_EXISTING)
Open File: .PIPElsarpc (OPEN_EXISTING)
Open File: C:ProgrammeOfferBoxOfferBox.exe (OPEN_EXISTING)
Open File: C:WINDOWSsystem32stdole2.tlb (OPEN_EXISTING)
Open File: C:Dokumente und EinstellungenAdministratorAnwendungsdatenOfferBoxconfig.xml (OPEN_EXISTING)
Open File: C:Dokumente und EinstellungenAdministratorAnwendungsdatenOfferBoxconfig.xml (OPEN_EXISTING)
Get File Attributes: C:Dokumente und EinstellungenAdministratorLokale EinstellungenAnwendungsdatenGoogleChromeApplicationchrome.exe Flags: (SECURITY_ANONYMOUS)
Create/Open File: DeviceRasAcd (OPEN_ALWAYS)
Open File: .PIPEROUTER (OPEN_EXISTING)
Get File Attributes: c:autoexec.bat Flags: (SECURITY_ANONYMOUS)
Open File: c:autoexec.bat (OPEN_EXISTING)
Create/Open File: DeviceTcp (OPEN_ALWAYS)
Create/Open File: DeviceIp (OPEN_ALWAYS)
Find File: C:Dokumente und EinstellungenAll UsersAnwendungsdatenMicrosoftNetworkConnectionsPbk*.pbk
Find File: C:WINDOWSsystem32Ras*.pbk
Create/Open File: DeviceIp (OPEN_ALWAYS)
Open File: .Ip (OPEN_EXISTING)
Find File: C:Dokumente und EinstellungenAdministratorAnwendungsdatenMicrosoftNetworkConnectionsPbk*.pbk
Create File: C:Dokumente und EinstellungenAdministratorAnwendungsdatenOfferBoxconfig.tmp
Open File: C:Dokumente und EinstellungenAdministratorAnwendungsdatenOfferBoxconfig.tmp (OPEN_EXISTING)
Move File: C:Dokumente und EinstellungenAdministratorAnwendungsdatenOfferBoxconfig.tmp to C:Dokumente und EinstellungenAdministratorAnwendungsdatenOfferBoxconfig.dat
Get File Attributes: C:WINDOWS Flags: (SECURITY_ANONYMOUS)
Open File: .PIPElsarpc (OPEN_EXISTING)
Delete File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsh2CD.tmp
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpnspB.tmp Flags: (SECURITY_ANONYMOUS)
Open File: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpnspB.tmp (OPEN_EXISTING)
Find File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsm2CF.tmp
Delete File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsm2CF.tmp
Get File Attributes: C:DOKUME~1 Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1 Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1 Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Temp Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Tempnsm2CF.tmpUAC.dll Flags: (SECURITY_ANONYMOUS)
Create File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsm2CF.tmpUAC.dll
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Tempnsj2D5.tmp.exe Flags: (SECURITY_ANONYMOUS)
Create File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsj2D5.tmp.exe
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1Tempnsj2D5.tmp.exe
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Tempnsm2CF.tmpSystem.dll Flags: (SECURITY_ANONYMOUS)
Create File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsm2CF.tmpSystem.dll
Open File: C:WINDOWSAppPatchsysmain.sdb (OPEN_EXISTING)
Open File: C:WINDOWSAppPatchsystest.sdb (OPEN_EXISTING)
Open File: DeviceNamedPipeShimViewer (OPEN_EXISTING)
Open File: C:DOKUME~1ADMINI~1LOKALE~1Temp ()
Find File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsj2D5.tmp.exe
Get File Attributes: C:WINDOWS Flags: (SECURITY_ANONYMOUS)
Open File: .PIPElsarpc (OPEN_EXISTING)
Delete File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsj2D3.tmp
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpWhiteSmokeWriter.exe Flags: (SECURITY_ANONYMOUS)
Open File: C:DOKUME~1ADMINI~1LOKALE~1Temp~nsuobw.tmpWhiteSmokeWriter.exe (OPEN_EXISTING)
Create File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsj2D7.tmp
Get File Attributes: C:DOKUME~1 Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1 Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1 Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Temp Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempWhiteSmokeMicrosoft.VC80.CRT.manifest Flags: (SECURITY_ANONYMOUS)
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempWhiteSmokeMicrosoft.VC80.CRT.manifest
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempWhiteSmokeMicrosoft.VC80.CRT.manifest
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempWhiteSmokemsvcp80.dll Flags: (SECURITY_ANONYMOUS)
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempWhiteSmokemsvcp80.dll
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempWhiteSmokemsvcp80.dll
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempWhiteSmokemsvcr80.dll Flags: (SECURITY_ANONYMOUS)
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempWhiteSmokemsvcr80.dll
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempWhiteSmokemsvcr80.dll
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempWhiteSmokeCheckLockedWsFiles.exe Flags: (SECURITY_ANONYMOUS)
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempWhiteSmokeCheckLockedWsFiles.exe
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempWhiteSmokeCheckLockedWsFiles.exe
Open File: C:WINDOWSAppPatchsysmain.sdb (OPEN_EXISTING)
Open File: C:WINDOWSAppPatchsystest.sdb (OPEN_EXISTING)
Open File: DeviceNamedPipeShimViewer (OPEN_EXISTING)
Open File: C:DOKUME~1ADMINI~1LOKALE~1TempWhiteSmoke ()
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempWhiteSmokeCheckLockedWsFiles.exe
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempGLJ2E7.tmp
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempGLK2EA.tmp
Delete File: C:DOKUME~1ADMINI~1LOKALE~1TempGLB2ED.tmp
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempGLG2EF.tmp
Open File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsj2D5.tmp.exe (OPEN_EXISTING)
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempGLF2F1.tmp Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Temp~GLH0000.TMP Flags: (SECURITY_ANONYMOUS)
Create File: C:DOKUME~1ADMINI~1LOKALE~1Temp~GLH0000.TMP
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1Temp~GLH0000.TMP
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempGLF2F1.tmp Flags: (SECURITY_ANONYMOUS)
Delete File: C:DOKUME~1ADMINI~1LOKALE~1TempGLF2F1.tmp
Move File: C:DOKUME~1ADMINI~1LOKALE~1Temp~GLH0000.TMP to C:DOKUME~1ADMINI~1LOKALE~1TempGLF2F1.tmp
Find File: C:DOKUME~1
Find File: C:Dokumente und EinstellungenADMINI~1
Find File: C:Dokumente und EinstellungenAdministratorLOKALE~1
Find File: C:Dokumente und EinstellungenAdministratorLokale EinstellungenTemp
Find File: C:Dokumente und EinstellungenAdministratorLokale EinstellungenTempGLF2F1.tmp
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesfiles.exe Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFiles~GLH0001.TMP Flags: (SECURITY_ANONYMOUS)
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFiles~GLH0001.TMP
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFiles~GLH0001.TMP
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesfiles.exe Flags: (SECURITY_ANONYMOUS)
Delete File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesfiles.exe
Move File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFiles~GLH0001.TMP to C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesfiles.exe
Find File: C:Dokumente und EinstellungenAdministratorLokale EinstellungenTempFun4IMFiles
Find File: C:Dokumente und EinstellungenAdministratorLokale EinstellungenTempFun4IMFilesfiles.exe
Find File: C:DOKUME~1ADMINI~1
Find File: C:DOKUME~1ADMINI~1LOKALE~1
Find File: C:DOKUME~1ADMINI~1LOKALE~1Temp
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFiles
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFUN4IM~1files.exe
Open File: .PIPEwkssvc (OPEN_EXISTING)
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFUN4IM~1 Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFUN4IM~1files.exe Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:WINDOWS Flags: (SECURITY_ANONYMOUS)
Open File: .PIPElsarpc (OPEN_EXISTING)
Get File Attributes: C:Dokumente und EinstellungenAdministratorEigene Dateiendesktop.ini Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:Dokumente und EinstellungenAll UsersDokumentedesktop.ini Flags: (SECURITY_ANONYMOUS)
Open File: C:ProgrammeWindows Desktop SearchMSNLNamespaceMgr.dll (OPEN_EXISTING)
Get File Attributes: C:WINDOWSRegistration Flags: (SECURITY_ANONYMOUS)
Open File: C:WINDOWSRegistrationR000000000007.clb (OPEN_EXISTING)
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFUN4IM~1files.exe:Zone.Identifier Flags: (SECURITY_ANONYMOUS)
Open File: C:WINDOWSAppPatchsysmain.sdb (OPEN_EXISTING)
Open File: C:WINDOWSAppPatchsystest.sdb (OPEN_EXISTING)
Open File: DeviceNamedPipeShimViewer (OPEN_EXISTING)
Open File: C:DOKUME~1ADMINI~1LOKALE~1TempFUN4IM~1 ()
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempGLF365.tmp Flags: (SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFUN4IM~1bin
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFUN4IM~1BinInstallerHelper.dll
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Temp~GLH0002.TMP Flags: (SECURITY_ANONYMOUS)
Open File: C:DOKUME~1ADMINI~1LOKALE~1TempFUN4IM~1BinINSTAL~1.DLL (OPEN_EXISTING)
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Temp~GLH0002.TMP Flags: (SECURITY_ANONYMOUS)
Create File: C:DOKUME~1ADMINI~1LOKALE~1Temp~GLH0002.TMP
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1Temp~GLH0002.TMP
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempGLF365.tmp Flags: (SECURITY_ANONYMOUS)
Delete File: C:DOKUME~1ADMINI~1LOKALE~1TempGLF365.tmp
Move File: C:DOKUME~1ADMINI~1LOKALE~1Temp~GLH0002.TMP to C:DOKUME~1ADMINI~1LOKALE~1TempGLF365.tmp
Find File: C:Dokumente und EinstellungenAdministratorLokale EinstellungenTempGLF365.tmp
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempOptions.ini Flags: (SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempSetupDataMngr_Searchqu.exe
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempSearchqu.ini
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempSearchqu.ini Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempSetupDataMngr_Searchqu.exe Flags: (SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFUN4IM~1Static
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFUN4IM~1StaticSetupDataMngr_Searchqu.exe
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Temp~GLH0003.TMP Flags: (SECURITY_ANONYMOUS)
Open File: C:DOKUME~1ADMINI~1LOKALE~1TempFUN4IM~1StaticSETUPD~1.EXE (OPEN_EXISTING)
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Temp~GLH0003.TMP Flags: (SECURITY_ANONYMOUS)
Create File: C:DOKUME~1ADMINI~1LOKALE~1Temp~GLH0003.TMP
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1Temp~GLH0003.TMP
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempSetupDataMngr_Searchqu.exe Flags: (SECURITY_ANONYMOUS)
Delete File: C:DOKUME~1ADMINI~1LOKALE~1TempSetupDataMngr_Searchqu.exe
Move File: C:DOKUME~1ADMINI~1LOKALE~1Temp~GLH0003.TMP to C:DOKUME~1ADMINI~1LOKALE~1TempSetupDataMngr_Searchqu.exe
Find File: C:Dokumente und EinstellungenAdministratorLokale EinstellungenTempSetupDataMngr_Searchqu.exe
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempSETUPD~1.EXE Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempSETUPD~1.EXE:Zone.Identifier Flags: (SECURITY_ANONYMOUS)
Open File: C:DOKUME~1ADMINI~1LOKALE~1Temp ()
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempSETUPD~1.EXE
Find File: C:Programme
Find File: C:ProgrammeFun4IM
Find File: C:ProgrammeFun4IMINSTALL.LOG
Find File: Bandoo.exe
Open File: Bandoo.exe (OPEN_EXISTING)
Get File Attributes: C:ProgrammeFun4IMInstallerHelper.dll Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:ProgrammeFun4IM~GLH0004.TMP Flags: (SECURITY_ANONYMOUS)
Set File Attributes: C:ProgrammeFun4IM~GLH0004.TMP Flags: (SECURITY_ANONYMOUS)
Create File: C:ProgrammeFun4IM~GLH0004.TMP
Set File Time: C:ProgrammeFun4IM~GLH0004.TMP
Set File Attributes: C:ProgrammeFun4IMInstallerHelper.dll Flags: (SECURITY_ANONYMOUS)
Delete File: C:ProgrammeFun4IMInstallerHelper.dll
Move File: C:ProgrammeFun4IM~GLH0004.TMP to C:ProgrammeFun4IMInstallerHelper.dll
Find File: C:ProgrammeFun4IMInstallerHelper.dll
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFUN4IM~1files.exe
Open File: C:DOKUME~1ADMINI~1LOKALE~1TempFUN4IM~1files.exe (OPEN_EXISTING)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFiles
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBin Flags: (SECURITY_ANONYMOUS)
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresources Flags: (SECURITY_ANONYMOUS)
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesplugins Flags: (SECURITY_ANONYMOUS)
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsIE Flags: (SECURITY_ANONYMOUS)
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsIEHTML Flags: (SECURITY_ANONYMOUS)
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSN Flags: (SECURITY_ANONYMOUS)
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNHTML Flags: (SECURITY_ANONYMOUS)
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbar Flags: (SECURITY_ANONYMOUS)
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages Flags: (SECURITY_ANONYMOUS)
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOE Flags: (SECURITY_ANONYMOUS)
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEHTML Flags: (SECURITY_ANONYMOUS)
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEimages Flags: (SECURITY_ANONYMOUS)
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbar Flags: (SECURITY_ANONYMOUS)
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages Flags: (SECURITY_ANONYMOUS)
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahoo Flags: (SECURITY_ANONYMOUS)
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooHTML Flags: (SECURITY_ANONYMOUS)
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbar Flags: (SECURITY_ANONYMOUS)
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages Flags: (SECURITY_ANONYMOUS)
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcessearchplugins Flags: (SECURITY_ANONYMOUS)
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorial Flags: (SECURITY_ANONYMOUS)
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimages Flags: (SECURITY_ANONYMOUS)
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagesFun4IM Flags: (SECURITY_ANONYMOUS)
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStatic Flags: (SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1001.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1001.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1001.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1001.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1001.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1001.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1001.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1001.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1001.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1001.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1001.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1001.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1002.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1002.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1002.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1002.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1002.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1002.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1002.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1002.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1002.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1002.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1002.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1002.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1003.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1003.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1003.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1003.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1003.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1003.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1003.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1003.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1003.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1003.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1003.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1003.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1004.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1004.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1004.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1004.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1004.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1004.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1004.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1004.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1005.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1005.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1005.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1005.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1005.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1005.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1005.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1005.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1006.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1006.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1006.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1006.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1006Fun4IM.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1006Fun4IM.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1006Fun4IM.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1006Fun4IM.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1006Fun4IM.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1006Fun4IM.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1006Fun4IM.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1006Fun4IM.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1011.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1011.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1011.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1011.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1011.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1011.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1011.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1011.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1012.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1012.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1012.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1012.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1012.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1012.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1012.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1012.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1013.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1013.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1013.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1013.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1013.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1013.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1013.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1013.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1014.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1014.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1014.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarImages1014.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1014.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1014.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1014.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarImages1014.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1051.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1051.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1051.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1051.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1052.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1052.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1052.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1052.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1053.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1053.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1053.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1053.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1054.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1054.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1054.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1054.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1055.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1055.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1055.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1055.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1056.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1056.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1056.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1056.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1057.dat
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1057.dat
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1057.dat
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarImages1057.dat Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagesbottomBg.gif
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagesbottomBg.gif
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagesbottomBg.gif
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagesbottomBg.gif Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagesclose.gif
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagesclose.gif
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagesclose.gif
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagesclose.gif Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagescontentBg.gif
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagescontentBg.gif
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagescontentBg.gif
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagescontentBg.gif Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesdownloadingFun4IM.gif
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesdownloadingFun4IM.gif
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesdownloadingFun4IM.gif
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesdownloadingFun4IM.gif Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagesFun4IMstartMenuTopText.gif
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagesFun4IMstartMenuTopText.gif
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagesFun4IMstartMenuTopText.gif
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagesFun4IMstartMenuTopText.gif Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagestopBg.gif
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagestopBg.gif
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagestopBg.gif
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagestopBg.gif Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimageswhat_next.gif
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimageswhat_next.gif
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimageswhat_next.gif
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimageswhat_next.gif Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsIEHTMLblank.html
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsIEHTMLblank.html
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsIEHTMLblank.html
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsIEHTMLblank.html Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNHTMLblank.html
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNHTMLblank.html
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNHTMLblank.html
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNHTMLblank.html Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEHTMLblank.html
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEHTMLblank.html
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEHTMLblank.html
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEHTMLblank.html Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooHTMLblank.html
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooHTMLblank.html
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooHTMLblank.html
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooHTMLblank.html Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsIEHTMLerror.html
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsIEHTMLerror.html
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsIEHTMLerror.html
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsIEHTMLerror.html Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNHTMLerror.html
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNHTMLerror.html
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNHTMLerror.html
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNHTMLerror.html Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEHTMLerror.html
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEHTMLerror.html
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEHTMLerror.html
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEHTMLerror.html Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooHTMLerror.html
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooHTMLerror.html
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooHTMLerror.html
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooHTMLerror.html Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialtutorial.html
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialtutorial.html
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialtutorial.html
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialtutorial.html Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesPlugins.ini
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesPlugins.ini
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesPlugins.ini
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesPlugins.ini Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagesscreen.jpg
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagesscreen.jpg
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagesscreen.jpg
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagesscreen.jpg Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEimageswink_play.jpg
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEimageswink_play.jpg
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEimageswink_play.jpg
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEimageswink_play.jpg Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsIEbandoo.js
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsIEbandoo.js
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsIEbandoo.js
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsIEbandoo.js Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticlicenseFun4IM.rtf
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticlicenseFun4IM.rtf
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticlicenseFun4IM.rtf
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticlicenseFun4IM.rtf Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcessearchpluginsWebSearch.src
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcessearchpluginsWebSearch.src
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcessearchpluginsWebSearch.src
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcessearchpluginsWebSearch.src Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagesFun4IMinstallation_page_frame.swf
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagesFun4IMinstallation_page_frame.swf
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagesFun4IMinstallation_page_frame.swf
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcestutorialimagesFun4IMinstallation_page_frame.swf Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge0.wav
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge0.wav
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge0.wav
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge0.wav Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge1.wav
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge1.wav
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge1.wav
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge1.wav Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge2.wav
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge2.wav
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge2.wav
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge2.wav Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge3.wav
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge3.wav
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge3.wav
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge3.wav Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge4.wav
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge4.wav
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge4.wav
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge4.wav Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge5.wav
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge5.wav
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge5.wav
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesnudge5.wav Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesBandooMessages.xml
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesBandooMessages.xml
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesBandooMessages.xml
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcesBandooMessages.xml Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarBandooToolbar.xml
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarBandooToolbar.xml
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarBandooToolbar.xml
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsMSNToolbarBandooToolbar.xml Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarBandooToolbar.xml
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarBandooToolbar.xml
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarBandooToolbar.xml
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarBandooToolbar.xml Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarBandooToolbar.xml
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarBandooToolbar.xml
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarBandooToolbar.xml
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsOEToolbarBandooToolbar.xml Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarBandooToolbarV9.xml
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarBandooToolbarV9.xml
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarBandooToolbarV9.xml
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcespluginsYahooToolbarBandooToolbarV9.xml Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcessearchpluginsWebSearch.xml
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcessearchpluginsWebSearch.xml
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcessearchpluginsWebSearch.xml
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinresourcessearchpluginsWebSearch.xml Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticWPSubsystems.xml
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticWPSubsystems.xml
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticWPSubsystems.xml
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticWPSubsystems.xml Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBandooRes.dll
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBandooRes.dll
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBandooRes.dll
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBandooRes.dll Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBndHook.dll
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBndHook.dll
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBndHook.dll
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBndHook.dll Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinCrashRpt.dll
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinCrashRpt.dll
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinCrashRpt.dll
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinCrashRpt.dll Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinFlashAnimator.dll
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinFlashAnimator.dll
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinFlashAnimator.dll
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinFlashAnimator.dll Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinGIFAnimator.dll
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinGIFAnimator.dll
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinGIFAnimator.dll
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinGIFAnimator.dll Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinieplugin.dll
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinieplugin.dll
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinieplugin.dll
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinieplugin.dll Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinInstallerHelper.dll
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinInstallerHelper.dll
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinInstallerHelper.dll
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinInstallerHelper.dll Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticlibungif4.dll
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticlibungif4.dll
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticlibungif4.dll
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticlibungif4.dll Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinmsnplugin.dll
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinmsnplugin.dll
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinmsnplugin.dll
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinmsnplugin.dll Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinOEPlugin.dll
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinOEPlugin.dll
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinOEPlugin.dll
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinOEPlugin.dll Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticuitools.dll
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticuitools.dll
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticuitools.dll
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticuitools.dll Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinYahooPlugin.dll
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinYahooPlugin.dll
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinYahooPlugin.dll
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinYahooPlugin.dll Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBandoo.exe
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBandoo.exe
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBandoo.exe
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBandoo.exe Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBandooGo.exe
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBandooGo.exe
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBandooGo.exe
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBandooGo.exe Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBandooUI.exe
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBandooUI.exe
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBandooUI.exe
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBandooUI.exe Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBndCore.exe
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBndCore.exe
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBndCore.exe
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinBndCore.exe Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinExtensionsManager.exe
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinExtensionsManager.exe
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinExtensionsManager.exe
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinExtensionsManager.exe Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinFFoxPackage.exe
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinFFoxPackage.exe
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinFFoxPackage.exe
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinFFoxPackage.exe Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticFFSettings.exe
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticFFSettings.exe
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticFFSettings.exe
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticFFSettings.exe Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinPreUninstall.exe
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinPreUninstall.exe
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinPreUninstall.exe
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesBinPreUninstall.exe Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticSetupDataMngr_Searchqu.exe
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticSetupDataMngr_Searchqu.exe
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticSetupDataMngr_Searchqu.exe
Set File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempFun4IMFilesStaticSetupDataMngr_Searchqu.exe Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Get File Attributes: C:WINDOWS Flags: (SECURITY_ANONYMOUS)
Open File: .PIPElsarpc (OPEN_EXISTING)
Delete File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsa36A.tmp
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempSETUPD~1.EXE Flags: (SECURITY_ANONYMOUS)
Open File: C:DOKUME~1ADMINI~1LOKALE~1TempSETUPD~1.EXE (OPEN_EXISTING)
Find File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsv36C.tmp
Delete File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsv36C.tmp
Get File Attributes: C:DOKUME~1 Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1 Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1 Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Temp Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Tempnsv36C.tmpSystem.dll Flags: (SECURITY_ANONYMOUS)
Create File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsv36C.tmpSystem.dll
Create File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsv36C.tmpSystem.dll
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempSearchqu.ini
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Tempnsv36C.tmpGetVersion.dll Flags: (SECURITY_ANONYMOUS)
Create File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsv36C.tmpGetVersion.dll
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempSearchqu_DMDataMngr.dll Flags: (SECURITY_ANONYMOUS)
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempSearchqu_DMDataMngr.dll
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempSearchqu_DMDataMngr.dll
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempSearchqu_DMDataMngrUI.exe Flags: (SECURITY_ANONYMOUS)
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempSearchqu_DMDataMngrUI.exe
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempSearchqu_DMDataMngrUI.exe
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempSearchqu_DMInstallHelper.dll Flags: (SECURITY_ANONYMOUS)
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempSearchqu_DMInstallHelper.dll
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempSearchqu_DMInstallHelper.dll
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempSearchqu_DMWebSearch.xml Flags: (SECURITY_ANONYMOUS)
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempSearchqu_DMWebSearch.xml
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempSearchqu_DMWebSearch.xml
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1TempSearchqu_DMSearchquMediaBar.exe Flags: (SECURITY_ANONYMOUS)
Create File: C:DOKUME~1ADMINI~1LOKALE~1TempSearchqu_DMSearchquMediaBar.exe
Set File Time: C:DOKUME~1ADMINI~1LOKALE~1TempSearchqu_DMSearchquMediaBar.exe
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempSearchqu_DMinstallhelper.dll
Find File: C:Program FilesInternet Exploreriexplore.exe
Find File:
Find File: C:DOKUME~1ADMINI~1LOKALE~1TempSearchqu_DMSearchquMediaBar.exe
Find File: C:ProgrammeWindows Searchqu ToolbarDatamngrdatamngr.dll
Find File: C:ProgrammeWindows Searchqu ToolbarDatamngrdatamngrUI.exe
Find File: C:ProgrammeWindows Searchqu ToolbarSearchquUninstBho.exe
Find File: C:ProgrammeWindows Searchqu ToolbarDatamngrIEBHO.dll
Get File Attributes: C:Programme Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:DOKUME~1ADMINI~1LOKALE~1Tempnsv36C.tmpKillProcDLL.dll Flags: (SECURITY_ANONYMOUS)
Create File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsv36C.tmpKillProcDLL.dll
Create File: C:DOKUME~1ADMINI~1LOKALE~1Tempnsv36C.tmpKillProcDLL.dll
Get File Attributes: C:ProgrammeWindows Searchqu Toolbar Flags: (SECURITY_ANONYMOUS)
Find File: C:ProgrammeWindows Searchqu ToolbarToolBar
Open File: .PIPEwkssvc (OPEN_EXISTING)
Get File Attributes: C:Dokumente und EinstellungenAdministratorEigene Dateiendesktop.ini Flags: (SECURITY_ANONYMOUS)
Get File Attributes: C:Dokumente und EinstellungenAll UsersDokumentedesktop.ini Flags: (SECURITY_ANONYMOUS)

infos about hoster:
http://whois.domaintools.com/63.236.35.30

Categories: Uncategorized