This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

baseline

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

… and the silent runner log. cheers mate

Silent Runners.vbs", revision 49, http://www.silentrunners.org/
Operating System: Windows 2000
Output of all locations checked and all values found.


Startup items buried in registry:
———————————

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
"internat.exe" = "internat.exe" [MS]
"H/PC Connection Agent" = ""C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"" [file not found]
"swg" = "C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe" ["Google Inc."]

HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\

HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx\

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
"Synchronization Manager" = "mobsync.exe /logon" [MS]
"Cmaudio" = "RunDll32 cmicnfg.cpl,CMICtrlWnd" [MS]
"AdaptecDirectCD" = ""C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"" [file not found]
"LWBMOUSE" = "C:\Program Files\Wireless Desktop\MOUSE32A.EXE" [file not found]
"NeroFilterCheck" = "C:\WINNT\system32\NeroCheck.exe" [file not found]
"SunJavaUpdateSched" = "C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe" [file not found]
"MaxtorOneTouch" = "C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe" [file not found]
"TkBellExe" = ""C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot" [file not found]
"Matrox Powerdesk" = "C:\WINNT\system32\PDesk\PDesk.exe /Autolaunch" [file not found]
"EPSON Stylus Photo R220 Series" = "C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_FATIAIE.EXE /P30 "EPSON Stylus Photo R220 Series" /O6 "USB002" /M "Stylus Photo R220"" [file not found]
"type32" = ""C:\Program Files\Microsoft IntelliType Pro\type32.exe"" [file not found]
"IntelliPoint" = ""C:\Program Files\Microsoft IntelliPoint\point32.exe"" [file not found]
"AVG7_CC" = "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP" ["GRISOFT, s.r.o."]
"Windows Defender" = ""C:\Program Files\Windows Defender\MSASCui.exe" -hide" [MS]
"Zone Labs Client" = ""C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"" ["Zone Labs, LLC"]
"iTunesHelper" = ""C:\Program Files\iTunes\iTunesHelper.exe"" ["Apple Computer, Inc."]
"QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."]

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx\

HKLM\Software\Microsoft\Active Setup\Installed Components\

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{02478D38-C3F9-4EFB-9B51-7695ECA05670}\(Default) = (no title provided)
-> {HKLM…CLSID} = "Yahoo! Toolbar Helper"
\InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll" ["Yahoo! Inc."]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
-> {HKLM…CLSID} = "AcroIEHlprObj Class"
\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
{35F7813A-AF74-4474-B1DC-7EE6FB6C43C6}\(Default) = (no title provided)
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINNT\system32\feilqsil.dll" [file not found]
{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]
{55E45B5E-F290-5893-C4A0-06D7F567DB37}\(Default) = (no title provided)
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINNT\system32\sozoexm.dll" [null data]
{AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = (no title provided)
-> {HKLM…CLSID} = "Google Toolbar Helper"
\InProcServer32\(Default) = "c:\program files\google\googletoolbar2.dll" ["Google Inc."]
{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A}\(Default) = (no title provided)
-> {HKLM…CLSID} = "EpsonToolBandKicker Class"
\InProcServer32\(Default) = "C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll" ["SEIKO EPSON CORPORATION"]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{00022613-0000-0000-C000-000000000046}" = "Multimedia File Property Sheet"
-> {HKLM…CLSID} = "Multimedia File Property Sheet"
\InProcServer32\(Default) = "mmsys.cpl" [MS]
"{176d6597-26d3-11d1-b350-080036a75b03}" = "ICM Scanner Management"
-> {HKLM…CLSID} = "ICM Scanner Management"
\InProcServer32\(Default) = "icmui.dll" [MS]
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}" = "NTFS Security Page"
-> {HKLM…CLSID} = "Security Shell Extension"
\InProcServer32\(Default) = "rshx32.dll" [MS]
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}" = "OLE Docfile Property Page"
-> {HKLM…CLSID} = "OLE Docfile Property Page"
\InProcServer32\(Default) = "docprop.dll" [MS]
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}" = "Shell extensions for sharing"
-> {HKLM…CLSID} = "Shell extensions for sharing"
\InProcServer32\(Default) = "ntshrui.dll" [MS]
"{41E300E0-78B6-11ce-849B-444553540000}" = "PlusPack CPL Extension"
-> {HKLM…CLSID} = "PlusPack CPL Extension"
\InProcServer32\(Default) = "plustab.dll" [MS]
"{42071712-76d4-11d1-8b24-00a0c9068ff3}" = "Display Adapter CPL Extension"
-> {HKLM…CLSID} = "Display Adapter CPL Extension"
\InProcServer32\(Default) = "deskadp.dll" [MS]
"{42071713-76d4-11d1-8b24-00a0c9068ff3}" = "Display Monitor CPL Extension"
-> {HKLM…CLSID} = "Display Monitor CPL Extension"
\InProcServer32\(Default) = "deskmon.dll" [MS]
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"
-> {HKLM…CLSID} = "Display Panning CPL Extension"
\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{4E40F770-369C-11d0-8922-00A024AB2DBB}" = "DS Security Page"
-> {HKLM…CLSID} = "Security Shell Extension"
\InProcServer32\(Default) = "dssec.dll" [MS]
"{56117100-C0CD-101B-81E2-00AA004AE837}" = "Shell Scrap DataHandler"
-> {HKLM…CLSID} = "Shell Scrap DataHandler"
\InProcServer32\(Default) = "shscrap.dll" [MS]
"{59099400-57FF-11CE-BD94-0020AF85B590}" = "Disk Copy Extension"
-> {HKLM…CLSID} = "Disk Copy Extension"
\InProcServer32\(Default) = "diskcopy.dll" [MS]
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}" = "Shell extensions for Microsoft Windows Network objects"
-> {HKLM…CLSID} = "Shell extensions for Microsoft Windows Network objects"
\InProcServer32\(Default) = "ntlanui2.dll" [MS]
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}" = "ICM Monitor Management"
-> {HKLM…CLSID} = "ICM Monitor Management"
\InProcServer32\(Default) = "C:\WINNT\System32\icmui.dll" [MS]
"{675F097E-4C4D-11D0-B6C1-0800091AA605}" = "ICM Printer Management"
-> {HKLM…CLSID} = "ICM Printer Management"
\InProcServer32\(Default) = "C:\WINNT\system32\icmui.dll" [MS]
"{77597368-7b15-11d0-a0c2-080036af3f03}" = "Web Printer Shell Extension"
-> {HKLM…CLSID} = "Web Printer Shell Extension"
\InProcServer32\(Default) = "printui.dll" [MS]
"{7988B573-EC89-11cf-9C00-00AA00A14F56}" = "Disk Quota UI"
-> {HKLM…CLSID} = "Microsoft Disk Quota UI"
\InProcServer32\(Default) = "dskquoui.dll" [MS]
"{85BBD920-42A0-1069-A2E4-08002B30309D}" = "Briefcase"
-> {HKLM…CLSID} = "Briefcase"
\InProcServer32\(Default) = "syncui.dll" [MS]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
-> {HKLM…CLSID} = "HyperTerminal Icon Ext"
\InProcServer32\(Default) = "C:\WINNT\System32\hticons.dll" ["Hilgraeve, Inc."]
"{BD84B380-8CA2-1069-AB1D-08000948F534}" = "Fonts"
-> {HKLM…CLSID} = "Fonts"
\InProcServer32\(Default) = "fontext.dll" [MS]
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}" = "ICC Profile"
-> {HKLM…CLSID} = "ICC Profile"
\InProcServer32\(Default) = "C:\WINNT\system32\icmui.dll" [MS]
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}" = "Printers Security Page"
-> {HKLM…CLSID} = "Security Shell Extension"
\InProcServer32\(Default) = "rshx32.dll" [MS]
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}" = "Shell extensions for sharing"
-> {HKLM…CLSID} = "Shell extensions for sharing"
\InProcServer32\(Default) = "ntshrui.dll" [MS]
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}" = "Display TroubleShoot CPL Extension"
-> {HKLM…CLSID} = "Display TroubleShoot CPL Extension"
\InProcServer32\(Default) = "deskperf.dll" [MS]
"{60254CA5-953B-11CF-8C96-00AA00B8708C}" = "Shell extensions for Windows Script Host"
-> {HKLM…CLSID} = "Shell Extension For Windows Script Host"
\InProcServer32\(Default) = "C:\WINNT\System32\wshext.dll" [MS]
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}" = "Crypto PKO Extension"
-> {HKLM…CLSID} = "CryptPKO Class"
\InProcServer32\(Default) = "C:\WINNT\system32\cryptext.dll" [MS]
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}" = "Crypto Sign Extension"
-> {HKLM…CLSID} = "CryptSig Class"
\InProcServer32\(Default) = "C:\WINNT\system32\cryptext.dll" [MS]
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}" = "Network and Dial-up Connections"
-> {HKLM…CLSID} = "Network and Dial-up Connections"
\InProcServer32\(Default) = "C:\WINNT\system32\NETSHELL.dll" [MS]
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}" = "Tasks Folder Icon Handler"
-> {HKLM…CLSID} = "Scheduling UI icon handler"
\InProcServer32\(Default) = "C:\WINNT\System32\mstask.dll" [MS]
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}" = "Tasks Folder Shell Extension"
-> {HKLM…CLSID} = "Scheduling UI property sheet handler"
\InProcServer32\(Default) = "C:\WINNT\System32\mstask.dll" [MS]
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}" = "Scheduled Tasks"
-> {HKLM…CLSID} = "Scheduled Tasks"
\InProcServer32\(Default) = "C:\WINNT\System32\mstask.dll" [MS]
"{1A9BA3A0-143A-11CF-8350-444553540000}" = "Shell Favorite Folder"
-> {HKLM…CLSID} = "Shell Favorite Folder"
\InProcServer32\(Default) = "C:\WINNT\system32\shell32.dll" [MS]
"{20D04FE0-3AEA-1069-A2D8-08002B30309D}" = "My Computer"
-> {HKLM…CLSID} = "My Computer"
\InProcServer32\(Default) = "C:\WINNT\system32\shell32.dll" [MS]
"{86747AC0-42A0-1069-A2E6-08002B30309D}" = "Briefcase Folder"
-> {HKLM…CLSID} = "Briefcase Folder"
\InProcServer32\(Default) = "C:\WINNT\system32\shell32.dll" [MS]
"{0AFACED1-E828-11D1-9187-B532F1E9575D}" = "Folder Shortcut"
-> {HKLM…CLSID} = "Folder Shortcut"
\InProcServer32\(Default) = "C:\WINNT\system32\shell32.dll" [MS]
"{12518493-00B2-11d2-9FA5-9E3420524153}" = "Mounted Volume"
-> {HKLM…CLSID} = "Mounted Volume"
\InProcServer32\(Default) = "C:\WINNT\system32\shell32.dll" [MS]
"{21B22460-3AEA-1069-A2DC-08002B30309D}" = "File Property Page Extension"
-> {HKLM…CLSID} = "File Property Page Extension"
\InProcServer32\(Default) = "C:\WINNT\system32\shell32.dll" [MS]
"{B091E540-83E3-11CF-A713-0020AFD79762}" = "File Types Page"
-> {HKLM…CLSID} = "File Types Page"
\InProcServer32\(Default) = "C:\WINNT\system32\shell32.dll" [MS]
"{FBF23B41-E3F0-101B-8488-00AA003E56F8}" = "MIME File Types Hook"
-> {HKLM…CLSID} = "MIME File Types Hook"
\InProcServer32\(Default) = "C:\WINNT\system32\shell32.dll" [MS]
"{C2FBB630-2971-11d1-A18C-00C04FD75D13}" = "Microsoft CopyTo Service"
-> {HKLM…CLSID} = "Microsoft CopyTo Service"
\InProcServer32\(Default) = "C:\WINNT\system32\shell32.dll" [MS]
"{C2FBB631-2971-11d1-A18C-00C04FD75D13}" = "Microsoft MoveTo Service"
-> {HKLM…CLSID} = "Microsoft MoveTo Service"
\InProcServer32\(Default) = "C:\WINNT\system32\shell32.dll" [MS]
"{13709620-C279-11CE-A49E-444553540000}" = "Shell Automation Service"
-> {HKLM…CLSID} = "Shell Automation Service"
\InProcServer32\(Default) = "C:\WINNT\system32\shell32.dll" [MS]
"{62112AA1-EBE4-11cf-A5FB-0020AFE7292D}" = "Shell Automation Folder View"
-> {HKLM…CLSID} = "Shell Automation Folder View"
\InProcServer32\(Default) = "C:\WINNT\system32\shell32.dll" [MS]
"{4622AD11-FF23-11d0-8D34-00A0C90F2719}" = "Start Menu"
-> {HKLM…CLSID} = "Start Menu"
\InProcServer32\(Default) = "C:\WINNT\system32\shell32.dll" [MS]
"{7BA4C740-9E81-11CF-99D3-00AA004AE837}" = "Microsoft SendTo Service"
-> {HKLM…CLSID} = "Microsoft SendTo Service"
\InProcServer32\(Default) = "C:\WINNT\system32\shell32.dll" [MS]
"{D969A300-E7FF-11d0-A93B-00A0C90F2719}" = "Microsoft New Object Service"
-> {HKLM…CLSID} = "Microsoft New Object Service"
\InProcServer32\(Default) = "C:\WINNT\system32\shell32.dll" [MS]
"{09799AFB-AD67-11d1-ABCD-00C04FC30936}" = "Open With Context Menu Handler"
-> {HKLM…CLSID} = "Open With Context Menu Handler"
\InProcServer32\(Default) = "C:\WINNT\system32\shell32.dll" [MS]
"{3FC0B520-68A9-11D0-8D77-00C04FD70822}" = "Display Control Panel HTML Extensions"
-> {HKLM…CLSID} = "Display Control Panel HTML Extensions"
\InProcServer32\(Default) = "C:\WINNT\system32\shell32.dll" [MS]
"{75048700-EF1F-11D0-9888-006097DEACF9}" = "ActiveDesktop"
-> {HKLM…CLSID} = "ActiveDesktop"
\InProcServer32\(Default) = "C:\WINNT\system32\shell32.dll" [MS]
"{6D5313C0-8C62-11D1-B2CD-006097DF8C11}" = "Folder Options Property Page Extension"
-> {HKLM…CLSID} = "Folder Options Property Page Extension"
\InProcServer32\(Default) = "C:\WINNT\system32\shell32.dll" [MS]
"{57651662-CE3E-11D0-8D77-00C04FC99D61}" = "CmdFileIcon"
-> {HKLM…CLSID} = "CmdFileIcon"
\InProcServer32\(Default) = "C:\WINNT\system32\shell32.dll" [MS]
"{4657278A-411B-11d2-839A-00C04FD918D0}" = "Shell Drag and Drop helper"
-> {HKLM…CLSID} = "Shell Drag and Drop helper"
\InProcServer32\(Default) = "C:\WINNT\system32\shell32.dll" [MS]
"{A470F8CF-A1E8-4f65-8335-227475AA5C46}" = "Add encryption item to context menus in explorer"
-> {HKLM…CLSID} = "Add encryption item to context menus in explorer"
\InProcServer32\(Default) = "C:\WINNT\system32\shell32.dll" [MS]
"{5E6AB780-7743-11CF-A12B-00AA004AE837}" = "Microsoft Internet Toolbar"
-> {HKLM…CLSID} = "Microsoft Internet Toolbar"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}" = "Download Status"
-> {HKLM…CLSID} = "Download Status"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{568804CA-CBD7-11d0-9816-00C04FD91972}" = "Menu Shell Folder"
-> {HKLM…CLSID} = "Menu Shell Folder"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{5b4dae26-b807-11d0-9815-00c04fd91972}" = "Menu Band"
-> {HKLM…CLSID} = "Menu Band"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{8278F931-2A3E-11d2-838F-00C04FD918D0}" = "Tracking Shell Menu"
-> {HKLM…CLSID} = "Tracking Shell Menu"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{E13EF4E4-D2F2-11d0-9816-00C04FD91972}" = "Menu Site"
-> {HKLM…CLSID} = "Menu Site"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{ECD4FC4F-521C-11D0-B792-00A0C90312E1}" = "Menu Desk Bar"
-> {HKLM…CLSID} = "Menu Desk Bar"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}" = "Augmented Shell Folder"
-> {HKLM…CLSID} = "Augmented Shell Folder"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{6413BA2C-B461-11d1-A18A-080036B11A03}" = "Augmented Shell Folder 2"
-> {HKLM…CLSID} = "Augmented Shell Folder 2"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}" = "BandProxy"
-> {HKLM…CLSID} = "BandProxy"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{D82BE2B0-5764-11D0-A96E-00C04FD705A2}" = "IShellFolderBand"
-> {HKLM…CLSID} = "IShellFolderBand"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}" = "Microsoft BrowserBand"
-> {HKLM…CLSID} = "Microsoft BrowserBand"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{30D02401-6A81-11d0-8274-00C04FD5AE38}" = "Search Band"
-> {HKLM…CLSID} = "Search Band"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}" = "In-pane search"
-> {HKLM…CLSID} = "In-pane search"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{07798131-AF23-11d1-9111-00A0C98BA67D}" = "Web Search"
-> {HKLM…CLSID} = "Web Search"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{0E5CBF21-D15F-11d0-8301-00AA005B4383}" = "&Links"
-> {HKLM…CLSID} = "&Links"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}" = "Registry Tree Options Utility"
-> {HKLM…CLSID} = "Registry Tree Options Utility"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}" = "&Address"
-> {HKLM…CLSID} = "&Address"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{A08C11D2-A228-11d0-825B-00AA005B4383}" = "Address EditBox"
-> {HKLM…CLSID} = "Address EditBox"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{00BB2763-6A77-11D0-A535-00C04FD7D062}" = "Microsoft AutoComplete"
-> {HKLM…CLSID} = "Microsoft AutoComplete"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{7487cd30-f71a-11d0-9ea7-00805f714772}" = "Thumbnail Image"
-> {HKLM…CLSID} = "Thumbnail Image"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{7376D660-C583-11d0-A3A5-00C04FD706EC}" = "TridentImageExtractor"
-> {HKLM…CLSID} = "TridentImageExtractor"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{6756A641-DE71-11d0-831B-00AA005B4383}" = "MRU AutoComplete List"
-> {HKLM…CLSID} = "MRU AutoComplete List"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{00BB2764-6A77-11D0-A535-00C04FD7D062}" = "Microsoft History AutoComplete List"
-> {HKLM…CLSID} = "Microsoft History AutoComplete List"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{03C036F1-A186-11D0-824A-00AA005B4383}" = "Microsoft Shell Folder AutoComplete List"
-> {HKLM…CLSID} = "Microsoft Shell Folder AutoComplete List"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{00BB2765-6A77-11D0-A535-00C04FD7D062}" = "Microsoft Multiple AutoComplete List Container"
-> {HKLM…CLSID} = "Microsoft Multiple AutoComplete List Container"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}" = "Shell Band Site Menu"
-> {HKLM…CLSID} = "Shell Band Site Menu"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}" = "Shell DeskBarApp"
-> {HKLM…CLSID} = "Shell DeskBarApp"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}" = "Shell DeskBar"
-> {HKLM…CLSID} = "Shell DeskBar"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}" = "Shell Rebar BandSite"
-> {HKLM…CLSID} = "Shell Rebar BandSite"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}" = "User Assist"
-> {HKLM…CLSID} = "User Assist"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}" = "Global Folder Settings"
-> {HKLM…CLSID} = "Global Folder Settings"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}" = "Favorites Band"
-> {HKLM…CLSID} = "Favorites Band"
\InProcServer32\(Default) = "C:\WINNT\system32\shdocvw.dll" [MS]
"{0A89A860-D7B1-11CE-8350-444553540000}" = "Shell Automation Inproc Service"
-> {HKLM…CLSID} = "Shell Automation Inproc Service"
\InProcServer32\(Default) = "C:\WINNT\system32\shdocvw.dll" [MS]
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}" = "Shell DocObject Viewer"
-> {HKLM…CLSID} = "Shell DocObject Viewer"
\InProcServer32\(Default) = "C:\WINNT\system32\shdocvw.dll" [MS]
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}" = "InternetShortcut"
-> {HKLM…CLSID} = "Internet Shortcut"
\InProcServer32\(Default) = "shdocvw.dll" [MS]
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}" = "Microsoft Url History Service"
-> {HKLM…CLSID} = "Microsoft Url History Service"
\InProcServer32\(Default) = "C:\WINNT\system32\shdocvw.dll" [MS]
"{FF393560-C2A7-11CF-BFF4-444553540000}" = "History"
-> {HKLM…CLSID} = "History"
\InProcServer32\(Default) = "C:\WINNT\system32\shdocvw.dll" [MS]
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}" = "Temporary Internet Files"
-> {HKLM…CLSID} = "Temporary Internet Files"
\InProcServer32\(Default) = "C:\WINNT\system32\shdocvw.dll" [MS]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" = "Microsoft Url Search Hook"
-> {HKLM…CLSID} = "Microsoft Url Search Hook"
\InProcServer32\(Default) = "C:\WINNT\system32\shdocvw.dll" [MS]
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}" = "IE4 Suite Splash Screen"
-> {HKLM…CLSID} = "IE4 Suite Splash Screen"
\InProcServer32\(Default) = "C:\WINNT\system32\shdocvw.dll" [MS]
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}" = "CDF Extension Copy Hook"
-> {HKLM…CLSID} = "CDF Extension Copy Hook"
\InProcServer32\(Default) = "C:\WINNT\system32\shdocvw.dll" [MS]
"{131A6951-7F78-11D0-A979-00C04FD705A2}" = "ISFBand OC"
-> {HKLM…CLSID} = "ISFBand OC"
\InProcServer32\(Default) = "C:\WINNT\system32\shdocvw.dll" [MS]
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}" = "Search Assistant OC"
-> {HKLM…CLSID} = "Search Assistant OC"
\InProcServer32\(Default) = "C:\WINNT\system32\shdocvw.dll" [MS]
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}" = "The Internet"
-> {HKLM…CLSID} = "The Internet"
\InProcServer32\(Default) = "C:\WINNT\system32\shdocvw.dll" [MS]
"{871C5380-42A0-1069-A2EA-08002B30309D}" = "Internet Name Space"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINNT\system32\shdocvw.dll" [MS]
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}" = "Sendmail service"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINNT\System32\sendmail.dll" [MS]
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}" = "Sendmail service"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINNT\System32\sendmail.dll" [MS]
"{88C6C381-2E85-11D0-94DE-444553540000}" = "ActiveX Cache Folder"
-> {HKLM…CLSID} = "ActiveX Cache Folder"
\InProcServer32\(Default) = "C:\WINNT\System32\occache.dll" [MS]
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" = "WebCheck"
-> {HKLM…CLSID} = "WebCheck"
\InProcServer32\(Default) = "C:\WINNT\System32\webcheck.dll" [MS]
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}" = "Subscription Mgr"
-> {HKLM…CLSID} = "Subscription Mgr"
\InProcServer32\(Default) = "C:\WINNT\System32\webcheck.dll" [MS]
"{F5175861-2688-11d0-9C5E-00AA00A45957}" = "Subscription Folder"
-> {HKLM…CLSID} = "Subscription Folder"
\InProcServer32\(Default) = "C:\WINNT\System32\webcheck.dll" [MS]
"{08165EA0-E946-11CF-9C87-00AA005127ED}" = "WebCheckWebCrawler"
-> {HKLM…CLSID} = "WebCheckWebCrawler"
\InProcServer32\(Default) = "C:\WINNT\System32\webcheck.dll" [MS]
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}" = "WebCheckChannelAgent"
-> {HKLM…CLSID} = "WebCheckChannelAgent"
\InProcServer32\(Default) = "C:\WINNT\System32\webcheck.dll" [MS]
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}" = "TrayAgent"
-> {HKLM…CLSID} = "TrayAgent"
\InProcServer32\(Default) = "C:\WINNT\System32\webcheck.dll" [MS]
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}" = "Code Download Agent"
-> {HKLM…CLSID} = "Code Download Agent"
\InProcServer32\(Default) = "C:\WINNT\System32\webcheck.dll" [MS]
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}" = "ConnectionAgent"
-> {HKLM…CLSID} = "ConnectionAgent"
\InProcServer32\(Default) = "C:\WINNT\System32\webcheck.dll" [MS]
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}" = "PostAgent"
-> {HKLM…CLSID} = "PostAgent"
\InProcServer32\(Default) = "C:\WINNT\System32\webcheck.dll" [MS]
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}" = "WebCheck SyncMgr Handler"
-> {HKLM…CLSID} = "WebCheck SyncMgr Handler"
\InProcServer32\(Default) = "C:\WINNT\System32\webcheck.dll" [MS]
"{8BEBB290-52D0-11D0-B7F4-00C04FD706EC}" = "Thumbnails"
-> {HKLM…CLSID} = "Thumbnails"
\InProcServer32\(Default) = "C:\WINNT\System32\thumbvw.dll" [MS]
"{EAB841A0-9550-11CF-8C16-00805F1408F3}" = "HTML Thumbnail Extractor"
-> {HKLM…CLSID} = "HTML Thumbnail Extractor"
\InProcServer32\(Default) = "C:\WINNT\System32\thumbvw.dll" [MS]
"{1AEB1360-5AFC-11D0-B806-00C04FD706EC}" = "Office Graphics Filters Thumbnail Extractor"
-> {HKLM…CLSID} = "Office Graphics Filters Thumbnail Extractor"
\InProcServer32\(Default) = "C:\WINNT\System32\thumbvw.dll" [MS]
"{9DBD2C50-62AD-11D0-B806-00C04FD706EC}" = "Summary Info Thumbnail handler (DOCFILES)"
-> {HKLM…CLSID} = "Summary Info Thumbnail handler (DOCFILES)"
\InProcServer32\(Default) = "C:\WINNT\System32\thumbvw.dll" [MS]
"{500202A0-731E-11D0-B829-00C04FD706EC}" = "LNK file thumbnail interface delegator"
-> {HKLM…CLSID} = "LNK file thumbnail interface delegator"
\InProcServer32\(Default) = "C:\WINNT\System32\thumbvw.dll" [MS]
"{352EC2B7-8B9A-11D1-B8AE-006008059382}" = "Shell Application Manager"
-> {HKLM…CLSID} = "%DESC_AppMgr%"
\InProcServer32\(Default) = "C:\WINNT\System32\appwiz.cpl" [MS]
"{0B124F8C-91F0-11D1-B8B5-006008059382}" = "Installed Apps Enumerator"
-> {HKLM…CLSID} = "Installed Apps Enumerator"
\InProcServer32\(Default) = "C:\WINNT\System32\appwiz.cpl" [MS]
"{CFCCC7A0-A282-11D1-9082-006008059382}" = "Darwin App Publisher"
-> {HKLM…CLSID} = "Darwin App Publisher"
\InProcServer32\(Default) = "C:\WINNT\System32\appwiz.cpl" [MS]
"{fe1290f0-cfbd-11cf-a330-00aa00c16e65}" = "Directory Namespace"
-> {HKLM…CLSID} = "Directory"
\InProcServer32\(Default) = "dsfolder.dll" [MS]
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}" = "Shell properties for a DS object"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "dsfolder.dll" [MS]
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}" = "Directory Query UI"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "dsquery.dll" [MS]
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}" = "Directory Object Find"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "dsquery.dll" [MS]
"{F020E586-5264-11d1-A532-0000F8757D7E}" = "Directory Start/Search Find"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "dsquery.dll" [MS]
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}" = "Directory Property UI"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "dsuiext.dll" [MS]
"{62AE1F9A-126A-11D0-A14B-0800361B1103}" = "Directory Context Menu Verbs"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "dsuiext.dll" [MS]
"{450D8FBA-AD25-11D0-98A8-0800361B1103}" = "MyDocs Folder"
-> {HKLM…CLSID} = "My Documents"
\InProcServer32\(Default) = "mydocs.dll" [MS]
"{ECF03A33-103D-11d2-854D-006008059367}" = "MyDocs Copy Hook"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "mydocs.dll" [MS]
"{ECF03A32-103D-11d2-854D-006008059367}" = "MyDocs Drop Target"
-> {HKLM…CLSID} = "MyDocs Drop Target"
\InProcServer32\(Default) = "mydocs.dll" [MS]
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}" = "MyDocs Properties"
-> {HKLM…CLSID} = "MyDocs menu and properties"
\InProcServer32\(Default) = "mydocs.dll" [MS]
"{750fdf0e-2a26-11d1-a3ea-080036587f03}" = "Offline Files Menu"
-> {HKLM…CLSID} = "Offline Files Menu"
\InProcServer32\(Default) = "cscui.dll" [MS]
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}" = "Offline Files Folder Options"
-> {HKLM…CLSID} = "Offline Files Folder Options"
\InProcServer32\(Default) = "cscui.dll" [MS]
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}" = "Offline Files Folder"
-> {HKLM…CLSID} = "Offline Files Folder"
\InProcServer32\(Default) = "cscui.dll" [MS]
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}" = "MMC Icon Handler"
-> {HKLM…CLSID} = "ExtractIcon Class"
\InProcServer32\(Default) = "mmcshext.dll" [MS]
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}" = ".CAB file viewer"
-> {HKLM…CLSID} = "Cabinet File"
\InProcServer32\(Default) = "cabview.dll" [MS]
"{E0D79304-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79305-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79306-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79307-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
-> {HKLM…CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
"{5E44E225-A408-11CF-B581-008029601108}" = "Adaptec DirectCD Shell Extension"
-> {HKLM…CLSID} = "Adaptec DirectCD Shell Extension"
\InProcServer32\(Default) = "C:\PROGRA~1\Roxio\EASYCD~1\DirectCD\Shellex.dll" ["Roxio"]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
-> {HKLM…CLSID} = "Outlook File Icon Extension"
\InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office\OLKFSTUB.DLL" [MS]
"{32683183-48a0-441b-a342-7c2a440a9478}" = "Media Band"
-> {HKLM…CLSID} = "Media Band"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}" = "Custom MRU AutoCompleted List"
-> {HKLM…CLSID} = "Custom MRU AutoCompleted List"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{7e653215-fa25-46bd-a339-34a2790f3cb7}" = "Accessible"
-> {HKLM…CLSID} = "Accessible"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{acf35015-526e-4230-9596-becbe19f0ac9}" = "Track Popup Bar"
-> {HKLM…CLSID} = "Track Popup Bar"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}" = "Address Bar Parser"
-> {HKLM…CLSID} = "Address Bar Parser"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}" = "Microsoft Browser Architecture"
-> {HKLM…CLSID} = "Microsoft Browser Architecture"
\InProcServer32\(Default) = "C:\WINNT\system32\shdocvw.dll" [MS]
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}" = "Temporary Internet Files"
-> {HKLM…CLSID} = "Temporary Internet Files"
\InProcServer32\(Default) = "C:\WINNT\system32\shdocvw.dll" [MS]
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}" = "Explorer Band"
-> {HKLM…CLSID} = "Explorer Band"
\InProcServer32\(Default) = "C:\WINNT\system32\shdocvw.dll" [MS]
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}" = "Channel File"
-> {HKLM…CLSID} = "Channel"
\InProcServer32\(Default) = "C:\WINNT\System32\cdfview.dll" [MS]
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}" = "Channel Shortcut"
-> {HKLM…CLSID} = "Channel Shortcut"
\InProcServer32\(Default) = "C:\WINNT\System32\cdfview.dll" [MS]
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}" = "Channel Handler Object"
-> {HKLM…CLSID} = "Channel Handler Object"
\InProcServer32\(Default) = "C:\WINNT\System32\cdfview.dll" [MS]
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}" = "Channel Menu"
-> {HKLM…CLSID} = "Channel Menu Handler Object"
\InProcServer32\(Default) = "C:\WINNT\System32\cdfview.dll" [MS]
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}" = "Channel Properties"
-> {HKLM…CLSID} = "Channel Shortcut Property Pages"
\InProcServer32\(Default) = "C:\WINNT\System32\cdfview.dll" [MS]
"{32714800-2E5F-11d0-8B85-00AA0044F941}" = "For &People…"
-> {HKLM…CLSID} = "For &People…"
\InProcServer32\(Default) = "C:\Program Files\Outlook Express\wabfind.dll" [MS]
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
-> {HKLM…CLSID} = "RealOne Player Context Menu Class"
\InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpshell.dll" ["RealNetworks, Inc."]
"{4A741382-48B4-11d2-AD84-00A024D24BF3}" = "Matrox PowerDesk Properties"
-> {HKLM…CLSID} = "Matrox PowerDesk Properties"
\InProcServer32\(Default) = "C:\WINNT\system32\PDesk\PDPAGES.DLL" ["Matrox Graphics Inc."]
"{6af09ec9-b429-11d4-a1fb-0090960218cb}" = "My Bluetooth Places"
-> {HKLM…CLSID} = "My Bluetooth Places"
\InProcServer32\(Default) = "C:\WINNT\system32\btneighborhood.dll" ["Broadcom Corporation"]
"{97FA8AA2-EE77-4FF2-9449-424D8924EF21}" = "IntelliType Pro Zooming Control Panel Property Page"
-> {HKLM…CLSID} = "IntelliType Pro Zooming Property Page"
\InProcServer32\(Default) = ""C:\Program Files\Microsoft IntelliType Pro\itcplzm.dll"" [MS]
"{111D8120-25EB-4E1C-A4DF-C9EE5FCA35CB}" = "IntelliType Pro Scrolling Control Panel Property Page"
-> {HKLM…CLSID} = "IntelliType Pro Scrolling Property Page"
\InProcServer32\(Default) = ""C:\Program Files\Microsoft IntelliType Pro\itcplwhl.dll"" [MS]
"{ED6E87C6-8A83-43aa-8208-8DBC8247F4D2}" = "IntelliType Pro Key Settings Control Panel Property Page"
-> {HKLM…CLSID} = "IntelliType Pro Key Settings Property Page"
\InProcServer32\(Default) = ""C:\Program Files\Microsoft IntelliType Pro\itcplkey.dll"" [MS]
"{A2569D1F-4E06-43EC-9825-0088B471BE47}" = "IntelliType Pro Wireless Control Panel Property Page"
-> {HKLM…CLSID} = "IntelliType Pro Wireless Control Panel Property Page"
\InProcServer32\(Default) = ""C:\Program Files\Microsoft IntelliType Pro\itcplwir.dll"" [MS]
"{20082881-FC36-4E47-9A7A-644C95FF749F}" = "IntelliPoint Wireless Control Panel Property Page"
-> {HKLM…CLSID} = "Wireless Property Page"
\InProcServer32\(Default) = ""C:\Program Files\Microsoft IntelliPoint\ipcplwir.dll"" [MS]
"{AF90F543-6A3A-4C1B-8B16-ECEC073E69BE}" = "IntelliPoint Wheel Control Panel Property Page"
-> {HKLM…CLSID} = "Wheel Property Page"
\InProcServer32\(Default) = ""C:\Program Files\Microsoft IntelliPoint\ipcplwhl.dll"" [MS]
"{653DCCC2-13DB-45B2-A389-427885776CFE}" = "IntelliPoint Activities Control Panel Property Page"
-> {HKLM…CLSID} = "Activities Property Page"
\InProcServer32\(Default) = ""C:\Program Files\Microsoft IntelliPoint\ipcplact.dll"" [MS]
"{124597D8-850A-41AE-849C-017A4FA99CA2}" = "IntelliPoint Buttons Control Panel Property Page"
-> {HKLM…CLSID} = "Buttons Property Page"
\InProcServer32\(Default) = ""C:\Program Files\Microsoft IntelliPoint\ipcplbtn.dll"" [MS]
"{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Shell Extension"
-> {HKLM…CLSID} = "AVG7 Shell Extension Class"
\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
"{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Find Extension"
-> {HKLM…CLSID} = "AVG7 Find Extension Class"
\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}" = "Browseui preloader"
-> {HKLM…CLSID} = "Browseui preloader"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]
"{8C7461EF-2B13-11d2-BE35-3078302C2030}" = "Component Categories cache daemon"
-> {HKLM…CLSID} = "Component Categories cache daemon"
\InProcServer32\(Default) = "C:\WINNT\System32\browseui.dll" [MS]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}" = (no title provided)
-> {HKLM…CLSID} = "URL Exec Hook"
\InProcServer32\(Default) = "shell32.dll" [MS]
<> "{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}" = "Microsoft AntiMalware ShellExecuteHook"
-> {HKLM…CLSID} = "Microsoft AntiMalware ShellExecuteHook"
\InProcServer32\(Default) = "C:\PROGRA~1\WINDOW~4\MpShHook.dll" [MS]
<> "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}" = "AVG Anti-Spyware 7.5"
-> {HKLM…CLSID} = "CShellExecuteHookImpl Object"
\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" ["Anti-Malware Development a.s."]

HKCU\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\

HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
"Network.ConnectionTray" = "{7007ACCF-3202-11D1-AAD2-00805FC1270E}"
-> {HKLM…CLSID} = "Network Connections Tray"
\InProcServer32\(Default) = "C:\WINNT\system32\NETSHELL.dll" [MS]
"WebCheck" = "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
-> {HKLM…CLSID} = "WebCheck"
\InProcServer32\(Default) = "C:\WINNT\System32\webcheck.dll" [MS]
"SysTray" = "{35CEC8A3-2BE6-11D2-8773-92E220524153}"
-> {HKLM…CLSID} = "SysTray"
\InProcServer32\(Default) = "stobject.dll" [MS]

HKCU\Software\Microsoft\Command Processor\
"AutoRun" = (value not found)

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\
"Shell" = (value not found)

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\
"load" = (empty string)
"run" = (value not found)

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\
"Shell" = (value not found)

HKLM\Software\Microsoft\Command Processor\
"AutoRun" = (empty string)

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\
"AppInit_DLLs" = " " [file not found]

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\
"GinaDLL" = (value not found)
"Shell" = "Explorer.exe" [MS]
"Taskman" = (value not found)
"Userinit" = "C:\WINNT\system32\userinit.exe," [MS]
"System" = (empty string)

HKLM\System\CurrentControlSet\Control\SafeBoot\Option\
"UseAlternateShell" = (value not found)

HKLM\System\CurrentControlSet\Control\SecurityProviders\
"SecurityProviders" = "msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

HKLM\System\CurrentControlSet\Control\Session Manager\
"BootExecute" = "autocheck autochk *"

HKLM\System\CurrentControlSet\Control\WOW\
"cmdline" = "C:\WINNT\system32\ntvdm.exe" [MS]
"wowcmdline" = "C:\WINNT\system32\ntvdm.exe -a C:\WINNT\system32\krnl386" [MS]

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
crypt32chain\DLLName = "crypt32.dll" [MS]
cryptnet\DLLName = "cryptnet.dll" [MS]
cscdll\DLLName = "cscdll.dll" [MS]
<> nwprovau\DLLName = "nwprovau.dll" [MS]
sclgntfy\DLLName = "sclgntfy.dll" [MS]
SensLogn\DLLName = "WlNotify.dll" [MS]
<> winetn32\DLLName = "winetn32.dll" [file not found]
wzcnotif\DLLName = "wzcdlg.dll" [MS]

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\
Your Image File Name Here without a path\Debugger = "ntsd -d" [MS]

HKCU\Software\Policies\Microsoft\Windows\System\Scripts\

HKLM\Software\Policies\Microsoft\Windows\System\Scripts\

HKLM\Software\Classes\PROTOCOLS\Filter\
Class Install Handler\CLSID = "{32B533BB-EDAE-11d0-BD5A-00AA00B92AF1}"
-> {HKLM…CLSID} = "AP Class Install Handler filter"
\InProcServer32\(Default) = "C:\WINNT\system32\urlmon.dll" [MS]
deflate\CLSID = "{8f6b0360-b80d-11d0-a9b3-006097942311}"
-> {HKLM…CLSID} = "AP lzdhtml encoding/decoding Filter"
\InProcServer32\(Default) = "C:\WINNT\system32\urlmon.dll" [MS]
gzip\CLSID = "{8f6b0360-b80d-11d0-a9b3-006097942311}"
-> {HKLM…CLSID} = "AP lzdhtml encoding/decoding Filter"
\InProcServer32\(Default) = "C:\WINNT\system32\urlmon.dll" [MS]
lzdhtml\CLSID = "{8f6b0360-b80d-11d0-a9b3-006097942311}"
-> {HKLM…CLSID} = "AP lzdhtml encoding/decoding Filter"
\InProcServer32\(Default) = "C:\WINNT\system32\urlmon.dll" [MS]
text/webviewhtml\CLSID = "{733AC4CB-F1A4-11d0-B951-00A0C90312E1}"
-> {HKLM…CLSID} = "WebView MIME Filter"
\InProcServer32\(Default) = "C:\WINNT\system32\shell32.dll" [MS]

HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
{0D2E74C4-3C34-11d2-A27E-00C04FC30871}\(Default) = (no title provided)
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINNT\system32\shell32.dll" [MS]
{24F14F01-7B1C-11d1-838f-0000F80461CF}\(Default) = (no title provided)
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINNT\system32\shell32.dll" [MS]
{24F14F02-7B1C-11d1-838f-0000F80461CF}\(Default) = (no title provided)
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINNT\system32\shell32.dll" [MS]
{66742402-F9B9-11D1-A202-0000F81FEDEE}\(Default) = "Version Column Provider"
-> {HKLM…CLSID} = "Version Column Provider"
\InProcServer32\(Default) = "C:\WINNT\System32\docprop2.dll" [MS]
{7f9609be-af9a-11d1-83e0-00c04fb6e984}\(Default) = "Fax Tiff Data Column Provider"
-> {HKLM…CLSID} = "Fax Tiff Data Column Provider"
\InProcServer32\(Default) = "C:\WINNT\system32\faxshell.dll" [MS]
{884EA37B-37C0-11d2-BE3F-00A0C9A83DA1}\(Default) = (no title provided)
-> {HKLM…CLSID} = "ShAVColumnProvider class"
\InProcServer32\(Default) = "C:\WINNT\System32\docprop2.dll" [MS]

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
AVG Anti-Spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
-> {HKLM…CLSID} = "CContextScan Object"
\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll" ["Anti-Malware Development a.s."]
AVG7 Shell Extension\(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"
-> {HKLM…CLSID} = "AVG7 Shell Extension Class"
\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
EPPShellEx\(Default) = "{509FE1AF-ADD5-49EC-BC55-7CF81FD16E78}"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\EPSON\Creativity Suite\Easy Photo Print\EPPShellEx.dll" ["SEIKO EPSON CORPORATION"]
Offline Files\(Default) = "{750fdf0e-2a26-11d1-a3ea-080036587f03}"
-> {HKLM…CLSID} = "Offline Files Menu"
\InProcServer32\(Default) = "cscui.dll" [MS]
Open With\(Default) = "{09799AFB-AD67-11d1-ABCD-00C04FC30936}"
-> {HKLM…CLSID} = "Open With Context Menu Handler"
\InProcServer32\(Default) = "C:\WINNT\system32\shell32.dll" [MS]
Open With EncryptionMenu\(Default) = "{A470F8CF-A1E8-4f65-8335-227475AA5C46}"
-> {HKLM…CLSID} = "Add encryption item to context menus in explorer"
\InProcServer32\(Default) = "C:\WINNT\system32\shell32.dll" [MS]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM…CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]

HKLM\Software\Classes\Directory\shellex\ContextMe
Hi pubby, As you can appreciate log has taken a bit of time to look at but hope to be back with you soon, just waiting for my work to be checked. Thanks dan
Hi pubby

Sorry it's been a couple of days since last reply,only there was a bit of work to do.
Take your time, read through and you will be fine.

Please download Suspicious file Packer from Safer-Networking.Org and unzip it to your desktop.

Run SFP.ex you downloaded earlier.
Locate SFP.exe and run it.

Copy and paste the following files :

C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iTunes\bak\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\QuickTime\bak\qttask.exe

then click "Continue".

Please upload the cab file to this site:

http://www.thespykiller.co.uk/forum/index.php?board=1.0

Start yourself a new topic
Put in topic title "Request by dan12"
Put in body of message the link to our thread here.
then press the browse button and then navigate to & select the cab file on desktop.
press Post to upload the file.

It is normal you will not see the file you just posted cus only approved members can see em to download them.

Let me know here when you have posted.
______________

Open notepad and copy and paste this text in it:

if exist "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" del /q "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
copy /y "C:\Program Files\Microsoft ActiveSync\bak\WCESCOMM.EXE" "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
if exist "C:\Program Files\Microsoft IntelliType Pro\type32.exe" del /q "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
copy /y "C:\Program Files\Microsoft IntelliType Pro\bak\type32.exe" "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
if exist "C:\Program Files\Microsoft IntelliPoint\point32.exe" del /q "C:\Program Files\Microsoft IntelliPoint\point32.exe"
copy /y "C:\Program Files\Microsoft IntelliPoint\bak\point32.exe" "C:\Program Files\Microsoft IntelliPoint\point32.exe"
if exist "C:\WINNT\system32\NeroCheck.exe" del /q "C:\WINNT\system32\NeroCheck.exe"
copy /y "C:\WINNT\system32\bak\NeroCheck.exe" "C:\WINNT\system32\NeroCheck.exe"
if exist "C:\WINNT\system32\PDesk\PDesk.exe" del /q "C:\WINNT\system32\PDesk\PDesk.exe"
copy /y "C:\WINNT\system32\PDesk\bak\PDesk.exe" "C:\WINNT\system32\PDesk\PDesk.exe"
if exist "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" del /q "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"
copy /y "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe" "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"
if exist "C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe" del /q "C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe"
copy /y "C:\Program Files\Java\j2re1.4.2_04\bin\bak\jusched.exe" "C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe"
if exist "C:\Program Files\Maxtor\OneTouch\Utils\OneTouch.exe" del /q "C:\Program Files\Maxtor\OneTouch\Utils\OneTouch.exe"
copy /y "C:\Program Files\Maxtor\OneTouch\Utils\bak\OneTouch.exe" "C:\Program Files\Maxtor\OneTouch\Utils\OneTouch.exe"
if exist "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" del /q "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
copy /y "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\bak\DirectCD.exe" "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
if exist "C:\WINNT\system32\spool\drivers\w32x86\3\E_FATIAIE.EXE" del /q "C:\WINNT\system32\spool\drivers\w32x86\3\E_FATIAIE.EXE"
copy /y "C:\WINNT\system32\spool\drivers\w32x86\3\bak\E_FATIAIE.EXE" "C:\WINNT\system32\spool\drivers\w32x86\3\E_FATIAIE.EXE"


Save this as fixme.bat , choose to save it as*all files and place it on your desktop.
_____________________________


Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it
    Right Click inside the listbox (white box) and click add more files
    Copy&Paste the entries below into the open boxes

    C:\WINNT\system32\eiqymbtu.exe
    C:\WINNT\system32\tzpnlkl.dll
    C:\WINNT\system32\sozoexm.dll
    C:\WINNT\system32\byxyyyy.dll

    Click Add Files and Click Close Window
    Click the Remove Vundo button.
    You will receive a prompt asking if you want to remove the files, click YES
    Once you click yes, your desktop will go blank as it starts removing Vundo.
    When completed, it will prompt that it will reboot your computer, click OK.
    Please post the contents of C:\vundofix.txt and a new HiJackThis log.
    Note: It is possible that VundoFix encountered a file it could not remove.

    In this case, VundoFix will run on reboot,allow the computer to reboot and VundoFix to load.

    Just add the very same files as before and Click Remove Vundo.


    _____________________________________


    Download http://www.mvps.org/winhelp2002/DelDomains.inf and place it on desktop

    Download: ResetProtocolDefaults.reg
    http://www.mvps.org/winhelp2002/ResetProtocolDefaults.reg
    unzip to desktop.
    ____________________________

    Locate DelDomains.inf on your desktop right click the file and select install, that will reset the zone settings that have been altered.

    Locate "Reset ProtocolDefaults.reg"
    Right-click and select: Merge (Ok the prompt)


    ____________________________

    down load latest smitfraudfix

    Please download SmitfraudFix (by S!Ri)
    dont use yet.
    ______________________

    We need to reveal system folders
    • Close all programs so that you are at your desktop.
    • Double-click on the My Computer icon.
    • Select the Tools menu and click Folder Options
    • After the new window appears select the View tab.
    • Place a checkmark in the checkbox labeled Display the contents of system folders
    • Under the Hidden files and folders section select the radio button labeled Show hidden files and folders
    • Remove the checkmark from the checkbox labeled Hide file extensions for known file types
    • Remove the checkmark from the checkbox labeled Hide protected operating system files
    • Press the Apply and then the ok button and shut down my computer
    • Now your computer is configured to show all hidden files.
    • For you and the tools to be able to see appropriate files we need to Show Hidden Files
    Re-boot into safe mode

    • Next, please reboot your computer in Safe Mode by doing the following:
    • Restart your computer
    • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
    • Instead of Windows loading as normal, a menu should appear use arrow up to highlight
    • Select the first option, to run Windows in Safe Mode hit enter.
    • For additional help in booting into Safe Mode, see the following site: HERE
    _________________________

    Run HijackThis, select Do a system scan only and place checks against the following entries (if they are still present)
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: (no name) - {35F7813A-AF74-4474-B1DC-7EE6FB6C43C6} - C:\WINNT\system32\feilqsil.dll
    O2 - BHO: (no name) - {55E45B5E-F290-5893-C4A0-06D7F567DB37} - C:\WINNT\system32\sozoexm.dll
    O2 - BHO: (no name) - {a43385f0-7113-496d-96d7-b9b550e3fcca} - C:\WINNT\system32\ixt2.dll
    O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Wireless Desktop\MOUSE32A.EXE <======looks like you deleted this program and this is a leftover
    O4 - HKLM\..\Run: [tzpnlkl.dll] C:\WINNT\system32\rundll32.exe C:\WINNT\system32\tzpnlkl.dll,zthfsie
    O20 - AppInit_DLLs:
    O20 - Winlogon Notify: winetn32 - winetn32.dll (file missing)
    O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - (no file)

    WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked and exit
    ______________________

    Double-click on SmitfraudFix.exe
    Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

    You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

    The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

    The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.
    A text file will appear on screen, with results from the cleaning process; please copy/paste the content of that report into your next reply.
    The report can also be found at the root of the system drive, usually at C:\rapport.txt

    Warning : running option #2 on a non infected computer will remove your Desktop background


    ______________________

    Right click start, In the drop down menu click "Explore" Then navigate to each file\ folder in the left hand pane, which will reveal its content in the right hand pane, highlight file or folder right click and Delete, if present:

    C:\WINNT\system32\winetn32.dll<==========This file
    C:\Program Files\Wireless Desktop <=======This folder
    can you also double check these for me:

    C:\WINNT\system32\eiqymbtu.exe
    C:\WINNT\system32\tzpnlkl.dll
    C:\WINNT\system32\sozoexm.dll
    C:\WINNT\system32\byxyyyy.dll

    ___________________________

    Run ATF cleaner
    • Double click ATF-Cleaner.exe to run the program.
    • Check the following boxes:
      • Windows Temp
      • Current User Temp
      • All Users Temp
      • Temporary Internet Files
      • Prefetch
      • Recycle Bin
      • Java Cache
    • The rest are optional - if you want to remove the lot, check Select All.
    • Now click Empty Selected.
    • When you get the Done Cleaning message, click OK.
    • If you use Firefox browser.
      • Click Firefox at the top and choose: Select All
      • If you would like to keep your saved passwords, please click No at the prompt.
      • Click the Empty Selected button.
    • If you use Opera browser.
      • Click Opera at the top and choose: Select All
      • If you would like to keep your saved passwords, please click No at the prompt.
      • Click the Empty Selected button.
    _______________

    Doubleclick fixme.bat Which you made and safed to the desktop
    ______________

    Reboot Normal mode

    Please include new HJT log, smitfraud report and vundo txt
    in your next post
    Thanks dan
This topic is being closed due to lack of response, if you need this topic reopened, please request this by sending an email to us at the following link:
(Click for address)


Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Kim

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI