This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HijackThis logs

122 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, well not quite…it is still not going…can't delete the folder 'Avenger' becoz the 'pctools-0.dll' cannot be deleted. The same problem with when it was in OTMoveIt folder. Any more idea of how to deal with it? Sorry for this persistant problem. :)
Hi, when I click on the winlogon.exe, it will become blue right. I did that the same last time but let me know if I got it wrong again. Anyway, here is the log: Process PID CPU Description Company Name System Idle Process 0 81.19 Interrupts n/a Hardware Interrupts DPCs n/a Deferred Procedure Calls System 4 smss.exe 1424 Windows NT Session Manager Microsoft Corporation csrss.exe 1484 Client Server Runtime Process Microsoft Corporation winlogon.exe 1516 Windows NT Logon Application Microsoft Corporation services.exe 1572 9.90 Services and Controller app Microsoft Corporation svchost.exe 1744 Generic Host Process for Win32 Services Microsoft Corporation FxSvr2.exe 3016 QuickCam Framework Server Logitech Inc. svchost.exe 1852 Generic Host Process for Win32 Services Microsoft Corporation svchost.exe 1924 Generic Host Process for Win32 Services Microsoft Corporation wuauclt.exe 2216 Automatic Updates Microsoft Corporation svchost.exe 316 Generic Host Process for Win32 Services Microsoft Corporation svchost.exe 528 Generic Host Process for Win32 Services Microsoft Corporation ccSetMgr.exe 856 Symantec Settings Manager Service Symantec Corporation ccEvtMgr.exe 1096 Symantec Event Manager Service Symantec Corporation SPBBCSvc.exe 1300 SPBBC Service Symantec Corporation spoolsv.exe 764 Spooler SubSystem App Microsoft Corporation AluSchedulerSvc.exe 884 Automatic LiveUpdate Scheduler Service Symantec Corporation guard.exe 908 AVG Anti-Spyware guard Anti-Malware Development a.s. CFSvcs.exe 932 Service of ConfigFree. TOSHIBA CORPORATION cvpnd.exe 1000 Cisco Systems VPN Client Cisco Systems, Inc. DefWatch.exe 1048 Virus Definition Daemon Symantec Corporation lmgrd.exe 1260 Macrovision Corporation ERDAS.exe 1348 nchgbios2svc.exe 360 NCHGBIOS2SVC TOSHIBA Corporation RichVideo.exe 660 RichVideo Module svchost.exe 728 2.97 Generic Host Process for Win32 Services Microsoft Corporation Rtvscan.exe 976 Symantec AntiVirus Symantec Corporation wdfmgr.exe 1716 Windows User Mode Driver Manager Microsoft Corporation alg.exe 2972 Application Layer Gateway Service Microsoft Corporation lsass.exe 1584 LSA Shell (Export Version) Microsoft Corporation explorer.exe 604 Windows Explorer Microsoft Corporation Thanks. :)
Hi again :)

Sorry, my bad.

Let's try again. Run Process Explorer and on the left hand side, click on Explorer.exe so that it gets highlighted. You could actually doubleclick it just to be sure. When you click on it, there should appear info on the lower part of the window. That info should also be on the log file.

Then click on File -> Save As -> Save the text file to your deskop and post it's contents to here.

Sorry for the inconvenience.
Hi… I hope I got it right this time. This is by clicking on the Explorer.exe (not winlogon.exe): Process PID CPU Description Company Name System Idle Process 0 98.02 Interrupts n/a Hardware Interrupts DPCs n/a Deferred Procedure Calls System 4 explorer.exe 604 Windows Explorer Microsoft Corporation igfxtray.exe 1788 igfxTray Module Intel Corporation hkcmd.exe 440 hkcmd Module Intel Corporation SmoothView.exe 456 SmoothView TOSHIBA Corporation stacmon.exe 524 SigmaTel Inc. ccApp.exe 608 Symantec User Session Symantec Corporation VPTray.exe 624 Symantec AntiVirus Symantec Corporation PadExe.exe 1972 PadTouch Main TOSHIBA 00THotkey.exe 812 THotkey TOSHIBA Corporation LVCOMSX.EXE 1180 LVCom Server Logitech Inc. LogiTray.exe 2104 ImageStudio Tray Application Logitech Inc. qttask.exe 2220 Apple Computer, Inc. VM_STI.EXE 2232 Vimicro Vimicro UnlockerAssistant.exe 2248 ctfmon.exe 2340 CTF Loader Microsoft Corporation Skype.exe 3564 Skype. The whole world can talk for free. Skype Technologies S.A. iexplore.exe 1076 Internet Explorer Microsoft Corporation procexp.exe 2064 0.99 Sysinternals Process Explorer Sysinternals Thanks :)
Hi :)

That didn't include the info I needed, let's try with a different tool :)

Open HijackThis.
  • Open the Misc Tools section
  • Open process manager
  • On the upper right corner, checkmark Show DLLs, a new field should appear.
  • Then select C:\WINDOWS\Explorer.EXE on the upper list
  • The lower list should now show many dll files
  • Click on the Save list to file… (floppy disk button)
  • Save the list to your desktop.
  • Close HijackThis and post the list to here
Hi, here we go: Process list saved on 7:05:51 PM, on 2/22/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) [pid] [full path to filename] [file version] [company name] 1424 C:\WINDOWS\System32\smss.exe 5.1.2600.2180 Microsoft Corporation 1516 C:\WINDOWS\system32\winlogon.exe 5.1.2600.2180 Microsoft Corporation 1572 C:\WINDOWS\system32\services.exe 5.1.2600.2180 Microsoft Corporation 1584 C:\WINDOWS\system32\lsass.exe 5.1.2600.2180 Microsoft Corporation 1744 C:\WINDOWS\system32\svchost.exe 5.1.2600.2180 Microsoft Corporation 1924 C:\WINDOWS\System32\svchost.exe 5.1.2600.2180 Microsoft Corporation 856 C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe 104.0.8.3 Symantec Corporation 1096 C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe 104.0.8.3 Symantec Corporation 1300 C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe 2.2.0.7 Symantec Corporation 764 C:\WINDOWS\system32\spoolsv.exe 5.1.2600.2696 Microsoft Corporation 884 C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe 3.0.0.166 Symantec Corporation 908 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe 7.5.0.47 Anti-Malware Development a.s. 932 C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe 5.0.0.7 TOSHIBA CORPORATION 1000 C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe 0.0.0.0 Cisco Systems, Inc. 1048 C:\Program Files\Symantec AntiVirus\DefWatch.exe 10.1.4.4000 Symantec Corporation 1260 C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\lmgrd.exe 9.0.0.0 Macrovision Corporation 1348 C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\ERDAS.exe 360 C:\New Folder\NCHGBIOS2SVC.exe 5.0.0.0 TOSHIBA Corporation 604 C:\WINDOWS\Explorer.EXE 6.0.2900.2180 Microsoft Corporation 660 C:\Program Files\CyberLink\Shared files\RichVideo.exe 1.1.0.808 728 C:\WINDOWS\system32\svchost.exe 5.1.2600.2180 Microsoft Corporation 976 C:\Program Files\Symantec AntiVirus\Rtvscan.exe 10.1.4.4000 Symantec Corporation 1788 C:\WINDOWS\system32\igfxtray.exe 3.0.0.2331 Intel Corporation 440 C:\WINDOWS\system32\hkcmd.exe 3.0.0.2331 Intel Corporation 456 C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe 2.0.0.18 TOSHIBA Corporation 524 C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe 1.0.0.3 SigmaTel Inc. 608 C:\Program Files\Common Files\Symantec Shared\ccApp.exe 104.0.8.3 Symantec Corporation 624 C:\PROGRA~1\SYMANT~1\VPTray.exe 10.1.4.4000 Symantec Corporation 1972 C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe 1.2.4.0 TOSHIBA 812 C:\WINDOWS\system32\00THotkey.exe 1.0.0.24 TOSHIBA Corporation 1180 C:\WINDOWS\system32\LVCOMSX.EXE 8.4.7.1036 Logitech Inc. 2104 C:\Program Files\Logitech\Video\LogiTray.exe 8.4.7.1034 Logitech Inc. 2220 C:\Program Files\QuickTime\qttask.exe 6.5.1.17 Apple Computer, Inc. 2232 C:\WINDOWS\VM_STI.EXE 4.2.1225.6 Vimicro 2248 C:\Program Files\Unlocker\UnlockerAssistant.exe 2340 C:\WINDOWS\system32\ctfmon.exe 5.1.2600.2180 Microsoft Corporation 3016 C:\Program Files\Logitech\Video\FxSvr2.exe 8.4.7.1034 Logitech Inc. 3564 C:\Program Files\Skype\Phone\Skype.exe 2.0.0.103 2756 C:\Program Files\Internet Explorer\iexplore.exe 7.0.6000.16414 Microsoft Corporation 2888 C:\Program Files\Microsoft Office\Office\EXCEL.EXE 9.0.0.8957 Microsoft Corporation 1040 C:\Program Files\Hijackthis\HijackThis.exe 1.99.0.1 Soeperman Enterprises Ltd. DLLs loaded by process C:\WINDOWS\Explorer.EXE: [full path to filename] [file version] [company name] C:\WINDOWS\system32\ntdll.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\kernel32.dll 5.1.2600.2945 Microsoft Corporation C:\WINDOWS\system32\msvcrt.dll 7.0.2600.2180 Microsoft Corporation C:\WINDOWS\system32\ADVAPI32.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\RPCRT4.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\GDI32.dll 5.1.2600.2818 Microsoft Corporation C:\WINDOWS\system32\USER32.dll 5.1.2600.2622 Microsoft Corporation C:\WINDOWS\system32\SHLWAPI.dll 6.0.2900.2995 Microsoft Corporation C:\WINDOWS\system32\SHELL32.dll 6.0.2900.3051 Microsoft Corporation C:\WINDOWS\system32\ole32.dll 5.1.2600.2726 Microsoft Corporation C:\WINDOWS\system32\OLEAUT32.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\BROWSEUI.dll 6.0.2900.2995 Microsoft Corporation C:\WINDOWS\system32\SHDOCVW.dll 6.0.2900.2987 Microsoft Corporation C:\WINDOWS\system32\CRYPT32.dll 5.131.2600.2180 Microsoft Corporation C:\WINDOWS\system32\MSASN1.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\CRYPTUI.dll 5.131.2600.2180 Microsoft Corporation C:\WINDOWS\system32\WINTRUST.dll 5.131.2600.2180 Microsoft Corporation C:\WINDOWS\system32\IMAGEHLP.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\NETAPI32.dll 5.1.2600.2976 Microsoft Corporation C:\WINDOWS\system32\WININET.dll 7.0.6000.16414 Microsoft Corporation C:\WINDOWS\system32\Normaliz.dll 6.0.5441.0 Microsoft Corporation C:\WINDOWS\system32\iertutil.dll 7.0.6000.16414 Microsoft Corporation C:\WINDOWS\system32\WLDAP32.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\VERSION.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\UxTheme.dll 6.0.2900.2180 Microsoft Corporation C:\WINDOWS\system32\ShimEng.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\AppPatch\AcGenral.DLL 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\WINMM.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\MSACM32.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\USERENV.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\IMM32.DLL 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\LPK.DLL 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\USP10.dll 1.420.2600.2180 Microsoft Corporation C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll 6.0.2900.2982 Microsoft Corporation C:\WINDOWS\system32\comctl32.dll 5.82.2900.2982 Microsoft Corporation C:\WINDOWS\system32\msctfime.ime 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\appHelp.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\CLBCATQ.DLL 2001.12.4414.308 Microsoft Corporation C:\WINDOWS\system32\COMRes.dll 2001.12.4414.258 Microsoft Corporation C:\WINDOWS\System32\cscui.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\System32\CSCDLL.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\themeui.dll 6.0.2900.2180 Microsoft Corporation C:\WINDOWS\system32\Secur32.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\MSIMG32.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\xpsp2res.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\actxprxy.dll 6.0.2900.2180 Microsoft Corporation C:\WINDOWS\system32\msutb.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\MSCTF.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\LINKINFO.dll 5.1.2600.2751 Microsoft Corporation C:\WINDOWS\system32\ntshrui.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\ATL.DLL 3.5.2284.0 Microsoft Corporation C:\WINDOWS\system32\urlmon.dll 7.0.6000.16414 Microsoft Corporation C:\WINDOWS\system32\ieframe.dll 7.0.6000.16414 Microsoft Corporation C:\WINDOWS\system32\PSAPI.DLL 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\WINSTA.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\webcheck.dll 7.0.6000.16414 Microsoft Corporation C:\WINDOWS\system32\stobject.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\BatMeter.dll 6.0.2900.2180 Microsoft Corporation C:\WINDOWS\system32\POWRPROF.dll 6.0.2900.2180 Microsoft Corporation C:\WINDOWS\system32\SETUPAPI.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\WTSAPI32.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\wdmaud.drv 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\msacm32.drv 5.1.2600.0 Microsoft Corporation C:\WINDOWS\system32\midimap.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\NETSHELL.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\rtutils.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\credui.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\WS2_32.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\WS2HELP.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\iphlpapi.dll 5.1.2600.2912 Microsoft Corporation C:\WINDOWS\system32\msi.dll 3.1.4000.2435 Microsoft Corporation C:\WINDOWS\system32\MLANG.dll 6.0.2900.2180 Microsoft Corporation C:\WINDOWS\system32\MPR.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\System32\drprov.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\System32\ntlanman.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\System32\NETUI0.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\System32\NETUI1.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\System32\NETRAP.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\System32\SAMLIB.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\System32\davclnt.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\rsaenh.dll 5.1.2600.2161 Microsoft Corporation C:\Program Files\Unlocker\UnlockerHook.dll C:\WINDOWS\system32\WZCSAPI.DLL 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\mslbui.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\SXS.DLL 5.1.2600.3019 Microsoft Corporation C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll 7.0.0.0 Adobe Systems, Inc. C:\WINDOWS\system32\browselc.dll 6.0.2900.2180 Microsoft Corporation C:\WINDOWS\system32\RASAPI32.DLL 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\rasman.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\TAPI32.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\DUSER.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2180_x-ww_522f9f82\gdiplus.dll 5.1.3102.2180 Microsoft Corporation C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll 7.5.0.47 Anti-Malware Development a.s. C:\WINDOWS\system32\comdlg32.dll 6.0.2900.2180 Microsoft Corporation C:\WINDOWS\system32\WINSPOOL.DRV 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\shscrap.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\shdoclc.dll 6.0.2900.2180 Microsoft Corporation C:\WINDOWS\system32\wzcdlg.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\WINHTTP.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\mscms.dll 5.1.2600.2709 Microsoft Corporation C:\WINDOWS\system32\NTMARTA.DLL 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\MSGINA.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\ODBC32.dll 3.525.1117.0 Microsoft Corporation C:\WINDOWS\system32\odbcint.dll 3.525.1117.0 Microsoft Corporation C:\WINDOWS\system32\mydocs.dll 6.0.2900.2180 Microsoft Corporation C:\Program Files\Microsoft Office\OFFICE11\msohev.dll 11.0.5510.0 Microsoft Corporation C:\WINDOWS\system32\wiashext.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\sti.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\CFGMGR32.dll 5.1.2600.2180 Microsoft Corporation C:\WINDOWS\system32\shimgvw.dll 6.0.2900.2180 Microsoft Corporation Thanks. :)
Ok let's try with another way :)

At first, please download handle.zip to your desktop.
Unzip the file, handle.exe to the root of your C-drive. (C:\handle.exe)

Go to Start >Run and type "Notepad" without the quotes
Copy the text from the quotebox to Notepad.
Go to the menu at the top of the Notepad file and Save as:
  • Name the file check.bat
  • Save as Type: All files
  • Select the desktop icon on the left to save it on the desktop.
Double click on check.bat and let it run.
When finished it will open a file in Notepad.
That file will be named explorer.txt
Please post the contents of explorer.txt into your next reply here.

@echo off
C:\handle.exe -p explorer >> C:\explorer.txt
Notepad C:\explorer.txt


:thumbup:
Hi, here is the log: Handle v3.2 Copyright © 1997-2006 Mark Russinovich Sysinternals - www.sysinternals.com —————————————————————————— explorer.exe pid: 604 LAM-LAP\Lam C: File (RW-) C:\Documents and Settings\Lam 3C: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 44: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 88: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 94: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 98: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 C4: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 D8: Section \BaseNamedObjects\ShimSharedMemory 168: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 180: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 1C0: Section \BaseNamedObjects\Yahoo_CCS_Buffer_1_1 1C4: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.ED.FBIODC 21C: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2180_x-ww_522f9f82 24C: File (RWD) C:\Documents and Settings\Lam\Desktop 250: File (RWD) C:\Documents and Settings\All Users\Desktop 254: File (RWD) C:\Documents and Settings\Lam\Local Settings\Application Data\Microsoft\CD Burning 26C: Section \BaseNamedObjects\CiceroSharedMemDefaultS-1-5-21-2583212256-3795527658-1728786790-1005 2A0: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 2DC: File (RWD) C:\Documents and Settings\Lam\Start Menu 2F8: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.EP.CEGDFGB 300: File (R–) C:\WINDOWS\system32\stdole2.tlb 31C: Section \BaseNamedObjects\Yahoo_CCS_Buffer_1_1 33C: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 36C: Section \BaseNamedObjects\UrlZonesSM_Lam 378: File (RWD) C:\Documents and Settings\Lam\Application Data\Microsoft\Internet Explorer\Quick Launch 37C: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 39C: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 3E4: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 3E8: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 3F8: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.B.NEIEE 414: Section \BaseNamedObjects\mmGlobalPnpInfo 424: Section \BaseNamedObjects\WDMAUD_Callbacks 458: File (RWD) C:\Documents and Settings\Lam\PrintHood 45C: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 48C: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 490: Section \BaseNamedObjects\C:_Documents and Settings_Lam_Local Settings_Temporary Internet Files_Content.IE5_index.dat_1703936 4A4: Section \BaseNamedObjects\windows_shell_global_counters 4B4: Section \BaseNamedObjects\MSCTF.GCompartListSFM.DefaultS-1-5-21-2583212256-3795527658-1728786790-1005 4D4: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 4E0: File (RW-) C:\Documents and Settings\Lam\Local Settings\Temporary Internet Files\Content.IE5\index.dat 4E4: File (RW-) C:\Documents and Settings\Lam\Cookies\index.dat 4EC: Section \BaseNamedObjects\C:_Documents and Settings_Lam_Cookies_index.dat_49152 4F0: File (RW-) C:\Documents and Settings\Lam\Local Settings\History\History.IE5\index.dat 4FC: Section \BaseNamedObjects\C:_Documents and Settings_Lam_Local Settings_History_History.IE5_index.dat_6127616 524: File (—) \Dfs 538: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 558: Section \BaseNamedObjects\MSCTF.Shared.SFM.IN 560: Section \BaseNamedObjects\MSCTF.Shared.SFM.IN 56C: Section \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-2583212256-3795527658-1728786790-1005SFM.DefaultS-1-5-21-2583212256-3795527658-1728786790-1005 594: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.JBB.OFLBIHB 598: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.JD.BCAJFC 59C: Section \BaseNamedObjects\MSCTF.Shared.SFM.ENB 614: Section \BaseNamedObjects\RotHintTable 630: Section \BaseNamedObjects\MSCTF.Shared.SFM.IN 668: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.AJB.INKEFDC 6BC: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 6D8: Section \BaseNamedObjects\Yahoo_CCS_Buffer_1_1 6E0: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 6E4: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.GKB.DMDHGEC 720: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.IMB.AKKMJEC 73C: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.KMB.AKKMJEC 764: Section \BaseNamedObjects\MSCTF.Shared.SFM.EFK 77C: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.BMB.IMOHIEC 788: Section \BaseNamedObjects\MSCTF.Shared.SFM.AJM 79C: File (RWD) C:\Documents and Settings\Lam\Favorites 7A0: Section \BaseNamedObjects\MSCTF.Shared.SFM.AJJ 7A4: Section \BaseNamedObjects\Yahoo_CCS_Buffer_1_1 7C8: Section \BaseNamedObjects\DfSharedHeap8C16E9 7F0: Section \BaseNamedObjects\MSCTF.Shared.SFM.ECM 82C: Section \BaseNamedObjects\MSCTF.Shared.SFM.AIC 838: Section \BaseNamedObjects\MSCTF.Shared.SFM.IN 840: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.JMB.AKKMJEC 844: Section \BaseNamedObjects\MSCTF.Shared.SFM.AJM 84C: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.OD.ENCPFC 88C: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.LLB.IMOHIEC 8AC: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.NBB.OFLBIHB 8F0: Section \BaseNamedObjects\MSCTF.Shared.SFM.ENB 92C: Section \BaseNamedObjects\MSCTF.Shared.SFM.MHC 930: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.IBB.OFLBIHB 94C: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.OLB.IMOHIEC 970: File (RW-) C:\Documents and Settings\Lam\Local Settings\History\History.IE5\MSHist012007022220070223\index.dat 9B0: Section \BaseNamedObjects\Yahoo_CCS_Buffer_1_1 9B8: Section \BaseNamedObjects\C:_Documents and Settings_Lam_Local Settings_History_History.IE5_MSHist012007022220070223_index.dat_81920 9D0: Section \BaseNamedObjects\MSCTF.Shared.SFM.IN 9EC: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.HF.LABMBG A14: Section \BaseNamedObjects\MSCTF.Shared.SFM.INP A24: Section \BaseNamedObjects\MSCTF.Shared.SFM.AJG A2C: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.MBB.OFLBIHB A34: File (R–) C:\WINDOWS\system32\atl.dll A48: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.HMB.AKKMJEC A68: Section \BaseNamedObjects\MSCTF.Shared.SFM.AGH A78: Section \BaseNamedObjects\MSCTF.Shared.SFM.MGI A80: Section \BaseNamedObjects\MSCTF.Shared.SFM.EGK A94: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.AMB.IMOHIEC A98: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.OBB.OFLBIHB AB8: Section \BaseNamedObjects\MSCTF.Shared.SFM.AGH ACC: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.GLB.IMOHIEC ADC: Section \BaseNamedObjects\Yahoo_CCS_Buffer_1_1 AE8: Section \BaseNamedObjects\MSCTF.Shared.SFM.EIP AF4: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.HLB.IMOHIEC AFC: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.KLB.IMOHIEC B00: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.LBB.OFLBIHB B14: File (RW-) C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 B2C: Section \BaseNamedObjects\MSCTF.Shared.SFM.IN B30: Section \BaseNamedObjects\MSCTF.Shared.SFM.AJP B48: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.NK.GFJPCCB B58: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.MLB.IMOHIEC B70: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.HL.LEJHDCB B78: Section \BaseNamedObjects\Yahoo_CCS_Buffer_1_1 BA4: File (RWD) C:\Documents and Settings\All Users\Start Menu BD8: Section \BaseNamedObjects\MSCTF.Shared.SFM.IN C18: Section \BaseNamedObjects\MSCTF.Shared.SFM.AGN C28: Section \BaseNamedObjects\Yahoo_CCS_Buffer_1_1 C30: Section \BaseNamedObjects\MSCTF.Shared.SFM.MPL C44: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.ML.NBKJDCB C50: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.NLB.IMOHIEC C54: Section \BaseNamedObjects\MSCTF.Shared.SFM.IN C70: Section \BaseNamedObjects\MSCTF.Shared.SFM.ICP C78: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.LMB.AKKMJEC C88: Section \BaseNamedObjects\Yahoo_CCS_Buffer_1_1 C8C: Section \BaseNamedObjects\MSCTF.Shared.SFM.MGI CF0: Section \BaseNamedObjects\Yahoo_CCS_Buffer_1_1 D08: Section \BaseNamedObjects\MSCTF.Shared.SFM.MIG D0C: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.DMB.ENKMIEC D28: Section \BaseNamedObjects\MSCTF.Shared.SFM.IN D2C: Section \BaseNamedObjects\MSCTF.Shared.SFM.IN D30: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.PLB.IMOHIEC D44: Section \BaseNamedObjects\Yahoo_CCS_Buffer_1_1 D4C: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.ILB.IMOHIEC D54: Section \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IN.JLB.IMOHIEC D68: Section \BaseNamedObjects\MSCTF.Shared.SFM.MHC D94: Section \BaseNamedObjects\MSCTF.Shared.SFM.IBK Hope it will help. :)
Hello :)

Ok the list you posted was correct but didn't show anything new. You have tried to delete the file after a reboot?

Have you tried to use Unlocker directly to that pctools-0.dll file? Does it give you an error?

Some more research… Run Process Explorer -> Find button -> Type this to the "Handle or DLL substring"-field: pctools -> Click on Search and wait for the results. Copy these results to here if something is found.

:thumbup:
Hi, tried deleting it again, still can't. Even using Unlocker directly on 'pctools-0.dll' can't delete it. And the search using Handle or DLL substring through Process Explorer returns no result. :scratch: Thanks. :)
Hmm :scratch: maybe there is still something hiding from us…these chinese infections can be nasty

Make a new folder in the C:\drive called silentrunners
Download 'silent runners" from here: (direct download)
http://www.silentrunners.org/Silent%20Runners.vbs
Save it to your silentrunners folder.

Click start> run> type cmd and hit enter
Type the following exactly and hit enter after each line.
cd c:\silentrunners and hit enter
"silent runners.vbs" -all and hit enter

Wait until it pops up saying its completed, then post the resulting logfile here
It will be very large. You may need several posts to include everything

Download F-Secure Blacklight and save it to your desktop.

Doubleclick blbeta.exe, accept the agreement, click Scan, then click Next

You'll see a list what have been found. A log will appear to your desktop, it is named fsbl.xxxxxxx.log (xxxxxxx will be random numbers).

DON'T choose Rename if something was found!

Post the contents of fsbl.xxxx.log to here (blacklight log from your desktop)
Hi, here is the long log:

"Silent Runners.vbs", revision R50, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output of all locations checked and all values found.


Startup items buried in registry:
———————————

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
"ctfmon.exe" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
"Skype" = ""C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized" ["Skype Technologies S.A."]
"LogitechSoftwareUpdate" = ""C:\Program Files\Logitech\Video\ManifestEngine.exe" boot" ["Logitech Inc."]

HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\

HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx\

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
"IgfxTray" = "C:\WINDOWS\system32\igfxtray.exe" ["Intel Corporation"]
"HotKeysCmds" = "C:\WINDOWS\system32\hkcmd.exe" ["Intel Corporation"]
"SmoothView" = "C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" ["TOSHIBA Corporation"]
"SigmaTel StacMon" = "C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe" ["SigmaTel Inc."]
"Symantec NetDriver Monitor" = "C:\PROGRA~1\SYMNET~1\SNDMon.exe /Enterprise" ["Symantec Corporation"]
"ccApp" = ""C:\Program Files\Common Files\Symantec Shared\ccApp.exe"" ["Symantec Corporation"]
"vptray" = "C:\PROGRA~1\SYMANT~1\VPTray.exe" ["Symantec Corporation"]
"PadTouch" = "C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" ["TOSHIBA"]
"00THotkey" = "C:\WINDOWS\system32\00THotkey.exe" ["TOSHIBA Corporation"]
"LVCOMSX" = "C:\WINDOWS\system32\LVCOMSX.EXE" ["Logitech Inc."]
"LogitechVideoRepair" = "C:\Program Files\Logitech\Video\ISStart.exe" ["Logitech Inc."]
"pdfFactory Pro Dispatcher v2" = ""C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" /runonce" ["FinePrint Software, LLC"]
"LogitechVideoTray" = "C:\Program Files\Logitech\Video\LogiTray.exe" ["Logitech Inc."]
"QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."]
"KernelFaultCheck" = "%systemroot%\system32\dumprep 0 -k" [MS]
"BigDogPath" = "C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera" ["Vimicro"]
"UnlockerAssistant" = ""C:\Program Files\Unlocker\UnlockerAssistant.exe"" [null data]

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx\

HKLM\Software\Microsoft\Active Setup\Installed Components\
>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\(Default) = "Microsoft Windows Media Player"
\StubPath = "C:\WINDOWS\inf\unregmp2.exe /ShowWMP" [MS]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{02478D38-C3F9-4EFB-9B51-7695ECA05670}\(Default) = (no title provided)
-> {HKLM…CLSID} = "Yahoo! Toolbar Helper"
\InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll" ["Yahoo! Inc."]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
-> {HKLM…CLSID} = "Adobe PDF Reader Link Helper"
\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
{F156768E-81EF-470C-9057-481BA8380DBA}\(Default) = (no title provided)
-> {HKLM…CLSID} = "gFlash Class"
\InProcServer32\(Default) = "C:\PROGRA~1\FlashGet\getflash.dll" [null data]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{00022613-0000-0000-C000-000000000046}" = "Multimedia File Property Sheet"
-> {HKLM…CLSID} = "Multimedia File Property Sheet"
\InProcServer32\(Default) = "mmsys.cpl" [MS]
"{176d6597-26d3-11d1-b350-080036a75b03}" = "ICM Scanner Management"
-> {HKLM…CLSID} = "ICM Scanner Management"
\InProcServer32\(Default) = "icmui.dll" [MS]
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}" = "NTFS Security Page"
-> {HKLM…CLSID} = "Security Shell Extension"
\InProcServer32\(Default) = "rshx32.dll" [MS]
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}" = "OLE Docfile Property Page"
-> {HKLM…CLSID} = "OLE Docfile Property Page"
\InProcServer32\(Default) = "docprop.dll" [MS]
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}" = "Shell extensions for sharing"
-> {HKLM…CLSID} = "Shell extensions for sharing"
\InProcServer32\(Default) = "ntshrui.dll" [MS]
"{41E300E0-78B6-11ce-849B-444553540000}" = "PlusPack CPL Extension"
-> {HKLM…CLSID} = "PlusPack CPL Extension"
\InProcServer32\(Default) = "C:\WINDOWS\system32\themeui.dll" [MS]
"{42071712-76d4-11d1-8b24-00a0c9068ff3}" = "Display Adapter CPL Extension"
-> {HKLM…CLSID} = "Display Adapter CPL Extension"
\InProcServer32\(Default) = "deskadp.dll" [MS]
"{42071713-76d4-11d1-8b24-00a0c9068ff3}" = "Display Monitor CPL Extension"
-> {HKLM…CLSID} = "Display Monitor CPL Extension"
\InProcServer32\(Default) = "deskmon.dll" [MS]
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"
-> {HKLM…CLSID} = "Display Panning CPL Extension"
\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{4E40F770-369C-11d0-8922-00A024AB2DBB}" = "DS Security Page"
-> {HKLM…CLSID} = "Security Shell Extension"
\InProcServer32\(Default) = "dssec.dll" [MS]
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}" = "Compatibility Page"
-> {HKLM…CLSID} = "Compatibility Page"
\InProcServer32\(Default) = "SlayerXP.dll" [MS]
"{56117100-C0CD-101B-81E2-00AA004AE837}" = "Shell Scrap DataHandler"
-> {HKLM…CLSID} = "Shell Scrap DataHandler"
\InProcServer32\(Default) = "shscrap.dll" [MS]
"{59099400-57FF-11CE-BD94-0020AF85B590}" = "Disk Copy Extension"
-> {HKLM…CLSID} = "Disk Copy Extension"
\InProcServer32\(Default) = "diskcopy.dll" [MS]
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}" = "Shell extensions for Microsoft Windows Network objects"
-> {HKLM…CLSID} = "Shell extensions for Microsoft Windows Network objects"
\InProcServer32\(Default) = "ntlanui2.dll" [MS]
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}" = "ICM Monitor Management"
-> {HKLM…CLSID} = "ICM Monitor Management"
\InProcServer32\(Default) = "C:\WINDOWS\System32\icmui.dll" [MS]
"{675F097E-4C4D-11D0-B6C1-0800091AA605}" = "ICM Printer Management"
-> {HKLM…CLSID} = "ICM Printer Management"
\InProcServer32\(Default) = "C:\WINDOWS\system32\icmui.dll" [MS]
"{77597368-7b15-11d0-a0c2-080036af3f03}" = "Web Printer Shell Extension"
-> {HKLM…CLSID} = "Web Printer Shell Extension"
\InProcServer32\(Default) = "printui.dll" [MS]
"{7988B573-EC89-11cf-9C00-00AA00A14F56}" = "Disk Quota UI"
-> {HKLM…CLSID} = "Microsoft Disk Quota UI"
\InProcServer32\(Default) = "dskquoui.dll" [MS]
"{85BBD920-42A0-1069-A2E4-08002B30309D}" = "Briefcase"
-> {HKLM…CLSID} = "Briefcase"
\InProcServer32\(Default) = "syncui.dll" [MS]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
-> {HKLM…CLSID} = "HyperTerminal Icon Ext"
\InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]
"{BD84B380-8CA2-1069-AB1D-08000948F534}" = "Fonts"
-> {HKLM…CLSID} = "Fonts"
\InProcServer32\(Default) = "fontext.dll" [MS]
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}" = "ICC Profile"
-> {HKLM…CLSID} = "ICC Profile"
\InProcServer32\(Default) = "C:\WINDOWS\system32\icmui.dll" [MS]
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}" = "Printers Security Page"
-> {HKLM…CLSID} = "Security Shell Extension"
\InProcServer32\(Default) = "rshx32.dll" [MS]
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}" = "Shell extensions for sharing"
-> {HKLM…CLSID} = "Shell extensions for sharing"
\InProcServer32\(Default) = "ntshrui.dll" [MS]
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}" = "Display TroubleShoot CPL Extension"
-> {HKLM…CLSID} = "Display TroubleShoot CPL Extension"
\InProcServer32\(Default) = "deskperf.dll" [MS]
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}" = "Crypto PKO Extension"
-> {HKLM…CLSID} = "CryptPKO Class"
\InProcServer32\(Default) = "C:\WINDOWS\system32\cryptext.dll" [MS]
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}" = "Crypto Sign Extension"
-> {HKLM…CLSID} = "CryptSig Class"
\InProcServer32\(Default) = "C:\WINDOWS\system32\cryptext.dll" [MS]
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}" = "Network Connections"
-> {HKLM…CLSID} = "Network Connections"
\InProcServer32\(Default) = "C:\WINDOWS\system32\NETSHELL.dll" [MS]
"{992CFFA0-F557-101A-88EC-00DD010CCC48}" = "Network Connections"
-> {HKLM…CLSID} = "Network Connections"
\InProcServer32\(Default) = "C:\WINDOWS\system32\NETSHELL.dll" [MS]
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}" = "Scanners & Cameras"
-> {HKLM…CLSID} = "Scanners & Cameras"
\InProcServer32\(Default) = "wiashext.dll" [MS]
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}" = "Scanners & Cameras"
-> {HKLM…CLSID} = "Scanners & Cameras"
\InProcServer32\(Default) = "wiashext.dll" [MS]
"{905667aa-acd6-11d2-8080-00805f6596d2}" = "Scanners & Cameras"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "wiashext.dll" [MS]
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}" = "Scanners & Cameras"
-> {HKLM…CLSID} = "Scanners & Cameras"
\InProcServer32\(Default) = "wiashext.dll" [MS]
"{83bbcbf3-b28a-4919-a5aa-73027445d672}" = "Scanners & Cameras"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "wiashext.dll" [MS]
"{F0152790-D56E-4445-850E-4F3117DB740C}" = "Remote Sessions CPL Extension"
-> {HKLM…CLSID} = "Remote Sessions CPL Extension"
\InProcServer32\(Default) = "C:\WINDOWS\system32\remotepg.dll" [MS]
"{60254CA5-953B-11CF-8C96-00AA00B8708C}" = "Shell extensions for Windows Script Host"
-> {HKLM…CLSID} = "Shell Extension For Windows Script Host"
\InProcServer32\(Default) = "C:\WINDOWS\system32\wshext.dll" [MS]
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}" = "Microsoft Data Link"
-> {HKLM…CLSID} = "Microsoft OLE DB Service Component Data Links"
\InProcServer32\(Default) = "C:\Program Files\Common Files\System\Ole DB\oledb32.dll" [MS]
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}" = "Tasks Folder Icon Handler"
-> {HKLM…CLSID} = "Scheduling UI icon handler"
\InProcServer32\(Default) = "C:\WINDOWS\system32\mstask.dll" [MS]
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}" = "Tasks Folder Shell Extension"
-> {HKLM…CLSID} = "Scheduling UI property sheet handler"
\InProcServer32\(Default) = "C:\WINDOWS\system32\mstask.dll" [MS]
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}" = "Scheduled Tasks"
-> {HKLM…CLSID} = "Scheduled Tasks"
\InProcServer32\(Default) = "C:\WINDOWS\system32\mstask.dll" [MS]
"{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}" = "Set Program Access and Defaults"
-> {HKLM…CLSID} = "Set Program Access and Defaults"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}" = "Auto Update Property Sheet Extension"
-> {HKLM…CLSID} = "Auto Update Property Sheet Extension"
\InProcServer32\(Default) = "C:\WINDOWS\system32\wuaucpl.cpl" [MS]
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}" = "Search"
-> {HKLM…CLSID} = "Search"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}" = "Help and Support"
-> {HKLM…CLSID} = "Help and Support"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}" = "Help and Support"
-> {HKLM…CLSID} = "Windows Security"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}" = "Run…"
-> {HKLM…CLSID} = "Run…"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}" = "Internet"
-> {HKLM…CLSID} = "Internet"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}" = "E-mail"
-> {HKLM…CLSID} = "E-mail"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
"{D20EA4E1-3957-11d2-A40B-0C5020524152}" = "Fonts"
-> {HKLM…CLSID} = "Fonts"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
"{D20EA4E1-3957-11d2-A40B-0C5020524153}" = "Administrative Tools"
-> {HKLM…CLSID} = "Administrative Tools"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
"{596AB062-B4D2-4215-9F74-E9109B0A8153}" = "Previous Versions Property Page"
-> {HKLM…CLSID} = "Previous Versions Property Page"
\InProcServer32\(Default) = "C:\WINDOWS\system32\twext.dll" [MS]
"{9DB7A13C-F208-4981-8353-73CC61AE2783}" = "Previous Versions"
-> {HKLM…CLSID} = "Previous Versions"
\InProcServer32\(Default) = "C:\WINDOWS\system32\twext.dll" [MS]
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}" = "Audio Media Properties Handler"
-> {HKLM…CLSID} = "Audio Media Properties Handler"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shmedia.dll" [MS]
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}" = "Video Media Properties Handler"
-> {HKLM…CLSID} = "Video Media Properties Handler"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shmedia.dll" [MS]
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}" = "Wav Properties Handler"
-> {HKLM…CLSID} = "Wav Properties Handler"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shmedia.dll" [MS]
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}" = "Avi Properties Handler"
-> {HKLM…CLSID} = "Avi Properties Handler"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shmedia.dll" [MS]
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}" = "Midi Properties Handler"
-> {HKLM…CLSID} = "Midi Properties Handler"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shmedia.dll" [MS]
"{c5a40261-cd64-4ccf-84cb-c394da41d590}" = "Video Thumbnail Extractor"
-> {HKLM…CLSID} = "Video Thumbnail Extractor"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shmedia.dll" [MS]
"{5E6AB780-7743-11CF-A12B-00AA004AE837}" = "Microsoft Internet Toolbar"
-> {HKLM…CLSID} = "Microsoft Internet Toolbar"
\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}" = "Download Status"
-> {HKLM…CLSID} = "Download Status"
\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}" = "Augmented Shell Folder"
-> {HKLM…CLSID} = "Augmented Shell Folder"
\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{6413BA2C-B461-11d1-A18A-080036B11A03}" = "Augmented Shell Folder 2"
-> {HKLM…CLSID} = "Augmented Shell Folder 2"
\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}" = "BandProxy"
-> {HKLM…CLSID} = "BandProxy"
\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}" = "Microsoft BrowserBand"
-> {HKLM…CLSID} = "Microsoft BrowserBand"
\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{30D02401-6A81-11d0-8274-00C04FD5AE38}" = "IE Search Band"
-> {HKLM…CLSID} = "IE Search Band"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}" = "In-pane search"
-> {HKLM…CLSID} = "In-pane search"
\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{07798131-AF23-11d1-9111-00A0C98BA67D}" = "Web Search"
-> {HKLM…CLSID} = "Web Search"
\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}" = "Registry Tree Options Utility"
-> {HKLM…CLSID} = "Registry Tree Options Utility"
\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}" = "&Address"
-> {HKLM…CLSID} = "&Address"
\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{A08C11D2-A228-11d0-825B-00AA005B4383}" = "Address EditBox"
-> {HKLM…CLSID} = "Address EditBox"
\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{00BB2763-6A77-11D0-A535-00C04FD7D062}" = "Microsoft AutoComplete"
-> {HKLM…CLSID} = "Microsoft AutoComplete"
\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{7376D660-C583-11d0-A3A5-00C04FD706EC}" = "TridentImageExtractor"
-> {HKLM…CLSID} = "TridentImageExtractor"
\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{6756A641-DE71-11d0-831B-00AA005B4383}" = "MRU AutoComplete List"
-> {HKLM…CLSID} = "MRU AutoComplete List"
\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}" = "Custom MRU AutoCompleted List"
-> {HKLM…CLSID} = "Custom MRU AutoCompleted List"
\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{7e653215-fa25-46bd-a339-34a2790f3cb7}" = "Accessible"
-> {HKLM…CLSID} = "Accessible"
\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{acf35015-526e-4230-9596-becbe19f0ac9}" = "Track Popup Bar"
-> {HKLM…CLSID} = "Track Popup Bar"
\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{00BB2764-6A77-11D0-A535-00C04FD7D062}" = "Microsoft History AutoComplete List"
-> {HKLM…CLSID} = "Microsoft History AutoComplete List"
\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{03C036F1-A186-11D0-824A-00AA005B4383}" = "Microsoft Shell Folder AutoComplete List"
-> {HKLM…CLSID} = "Microsoft Shell Folder AutoComplete List"
\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{00BB2765-6A77-11D0-A535-00C04FD7D062}" = "Microsoft Multiple AutoComplete List Container"
-> {HKLM…CLSID} = "Microsoft Multiple AutoComplete List Container"
\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}" = "Shell Band Site Menu"
-> {HKLM…CLSID} = "Shell Band Site Menu"
\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}" = "Shell DeskBarApp"
-> {HKLM…CLSID} = "Shell DeskBarApp"
\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}" = "Shell DeskBar"
-> {HKLM…CLSID} = "Shell DeskBar"
\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}" = "Shell Rebar BandSite"
-> {HKLM…CLSID} = "Shell Rebar BandSite"
\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}" = "User Assist"
-> {HKLM…CLSID} = "User Assist"
\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}" = "Global Folder Settings"
-> {HKLM…CLSID} = "Global Folder Settings"
\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}" = "Favorites Band"
-> {HKLM…CLSID} = "Favorites Band"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
"{0A89A860-D7B1-11CE-8350-444553540000}" = "Shell Automation Inproc Service"
-> {HKLM…CLSID} = "Shell Automation Inproc Service"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}" = "Shell DocObject Viewer"
-> {HKLM…CLSID} = "Shell DocObject Viewer"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}" = "Microsoft Browser Architecture"
-> {HKLM…CLSID} = "Microsoft Browser Architecture"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}" = "InternetShortcut"
-> {HKLM…CLSID} = "Internet Shortcut"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}" = "Microsoft Url History Service"
-> {HKLM…CLSID} = "Microsoft Url History Service"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{FF393560-C2A7-11CF-BFF4-444553540000}" = "History"
-> {HKLM…CLSID} = "History"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}" = "Temporary Internet Files"
-> {HKLM…CLSID} = "Temporary Internet Files"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}" = "Temporary Internet Files"
-> {HKLM…CLSID} = "Temporary Internet Files"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" = "Microsoft Url Search Hook"
-> {HKLM…CLSID} = "Microsoft Url Search Hook"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}" = "IE4 Suite Splash Screen"
-> {HKLM…CLSID} = "IE4 Suite Splash Screen"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}" = "CDF Extension Copy Hook"
-> {HKLM…CLSID} = "CDF Extension Copy Hook"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
"{131A6951-7F78-11D0-A979-00C04FD705A2}" = "ISFBand OC"
-> {HKLM…CLSID} = "ISFBand OC"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}" = "Search Assistant OC"
-> {HKLM…CLSID} = "Search Assistant OC"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}" = "The Internet"
-> {HKLM…CLSID} = "The Internet"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{871C5380-42A0-1069-A2EA-08002B30309D}" = "Internet Name Space"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}" = "Explorer Band"
-> {HKLM…CLSID} = "Explorer Band"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}" = "Sendmail service"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\system32\sendmail.dll" [MS]
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}" = "Sendmail service"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\system32\sendmail.dll" [MS]
"{88C6C381-2E85-11D0-94DE-444553540000}" = "ActiveX Cache Folder"
-> {HKLM…CLSID} = "ActiveX Cache Folder"
\InProcServer32\(Default) = "C:\WINDOWS\system32\occache.dll" [MS]
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" = "WebCheck"
-> {HKLM…CLSID} = "WebCheck"
\InProcServer32\(Default) = "C:\WINDOWS\system32\webcheck.dll" [MS]
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}" = "Subscription Mgr"
-> {HKLM…CLSID} = "Subscription Mgr"
\InProcServer32\(Default) = "C:\WINDOWS\system32\webcheck.dll" [MS]
"{F5175861-2688-11d0-9C5E-00AA00A45957}" = "Subscription Folder"
-> {HKLM…CLSID} = "Subscription Folder"
\InProcServer32\(Default) = "C:\WINDOWS\system32\webcheck.dll" [MS]
"{08165EA0-E946-11CF-9C87-00AA005127ED}" = "WebCheckWebCrawler"
-> {HKLM…CLSID} = "WebCheckWebCrawler"
\InProcServer32\(Default) = "C:\WINDOWS\system32\webcheck.dll" [MS]
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}" = "WebCheckChannelAgent"
-> {HKLM…CLSID} = "WebCheckChannelAgent"
\InProcServer32\(Default) = "C:\WINDOWS\system32\webcheck.dll" [MS]
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}" = "TrayAgent"
-> {HKLM…CLSID} = "TrayAgent"
\InProcServer32\(Default) = "C:\WINDOWS\system32\webcheck.dll" [MS]
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}" = "Code Download Agent"
-> {HKLM…CLSID} = "Code Download Agent"
\InProcServer32\(Default) = "C:\WINDOWS\system32\webcheck.dll" [MS]
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}" = "ConnectionAgent"
-> {HKLM…CLSID} = "ConnectionAgent"
\InProcServer32\(Default) = "C:\WINDOWS\system32\webcheck.dll" [MS]
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}" = "PostAgent"
-> {HKLM…CLSID} = "PostAgent"
\InProcServer32\(Default) = "C:\WINDOWS\system32\webcheck.dll" [MS]
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}" = "WebCheck SyncMgr Handler"
-> {HKLM…CLSID} = "WebCheck SyncMgr Handler"
\InProcServer32\(Default) = "C:\WINDOWS\system32\webcheck.dll" [MS]
"{352EC2B7-8B9A-11D1-B8AE-006008059382}" = "Shell Application Manager"
-> {HKLM…CLSID} = "Shell Application Manager"
\InProcServer32\(Default) = "C:\WINDOWS\system32\appwiz.cpl" [MS]
"{0B124F8F-91F0-11D1-B8B5-006008059382}" = "Installed Apps Enumerator"
-> {HKLM…CLSID} = "Installed Apps Enumerator"
\InProcServer32\(Default) = "C:\WINDOWS\system32\appwiz.cpl" [MS]
"{CFCCC7A0-A282-11D1-9082-006008059382}" = "Darwin App Publisher"
-> {HKLM…CLSID} = "Darwin App Publisher"
\InProcServer32\(Default) = "C:\WINDOWS\system32\appwiz.cpl" [MS]
"{e84fda7c-1d6a-45f6-b725-cb260c236066}" = "Shell Image Verbs"
-> {HKLM…CLSID} = "Shell Image Verbs"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shimgvw.dll" [MS]
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}" = "Shell Image Data Factory"
-> {HKLM…CLSID} = "Shell Image Data Factory"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shimgvw.dll" [MS]
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}" = "GDI+ file thumbnail extractor"
-> {HKLM…CLSID} = "GDI+ file thumbnail extractor"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shimgvw.dll" [MS]
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}" = "Summary Info Thumbnail handler (DOCFILES)"
-> {HKLM…CLSID} = "Summary Info Thumbnail handler (DOCFILES)"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shimgvw.dll" [MS]
"{EAB841A0-9550-11cf-8C16-00805F1408F3}" = "HTML Thumbnail Extractor"
-> {HKLM…CLSID} = "HTML Thumbnail Extractor"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shimgvw.dll" [MS]
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}" = "Shell Image Property Handler"
-> {HKLM…CLSID} = "Shell Image Property Handler"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shimgvw.dll" [MS]
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}" = "Web Publishing Wizard"
-> {HKLM…CLSID} = "Web Publishing Wizard"
\InProcServer32\(Default) = "C:\WINDOWS\system32\netplwiz.dll" [MS]
"{add36aa8-751a-4579-a266-d66f5202ccbb}" = "Print Ordering via the Web"
-> {HKLM…CLSID} = "Print Ordering via the Web"
\InProcServer32\(Default) = "C:\WINDOWS\system32\netplwiz.dll" [MS]
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}" = "Shell Publishing Wizard Object"
-> {HKLM…CLSID} = "Shell Publishing Wizard Object"
\InProcServer32\(Default) = "C:\WINDOWS\system32\netplwiz.dll" [MS]
"{58f1f272-9240-4f51-b6d4-fd63d1618591}" = "Get a Passport Wizard"
-> {HKLM…CLSID} = "Get a Passport Wizard"
\InProcServer32\(Default) = "C:\WINDOWS\system32\netplwiz.dll" [MS]
"{E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31}" = "Compressed (zipped) Folder"
-> {HKLM…CLSID} = "CompressedFolder"
\InProcServer32\(Default) = "C:\WINDOWS\system32\zipfldr.dll" [MS]
"{BD472F60-27FA-11cf-B8B4-444553540000}" = "Compressed (zipped) Folder Right Drag Handler"
-> {HKLM…CLSID} = "Compressed (zipped) Folder Right Drag Handler"
\InProcServer32\(Default) = "C:\WINDOWS\system32\zipfldr.dll" [MS]
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}" = "Compressed (zipped) Folder SendTo Target"
-> {HKLM…CLSID} = "Compressed (zipped) Folder SendTo Target"
\InProcServer32\(Default) = "C:\WINDOWS\system32\zipfldr.dll" [MS]
"{692F0339-CBAA-47e6-B5B5-3B84DB604E87}" = "Extensions Manager Folder"
-> {HKLM…CLSID} = "Extensions Manager Folder"
\InProcServer32\(Default) = "C:\WINDOWS\system32\extmgr.dll" [MS]
"{63da6ec0-2e98-11cf-8d82-444553540000}" = "FTP Folders Webview"
-> {HKLM…CLSID} = "Microsoft FTP Folder"
\InProcServer32\(Default) = "C:\WINDOWS\system32\msieftp.dll" [MS]
"{883373C3-BF89-11D1-BE35-080036B11A03}" = "Microsoft DocProp Shell Ext"
-> {HKLM…CLSID} = "Microsoft DocProp Shell Ext"
\InProcServer32\(Default) = "C:\WINDOWS\system32\docprop2.dll" [MS]
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}" = "Microsoft DocProp Inplace Edit Box Control"
-> {HKLM…CLSID} = "Microsoft DocProp Inplace Edit Box Control"
\InProcServer32\(Default) = "C:\WINDOWS\system32\docprop2.dll" [MS]
"{8EE97210-FD1F-4B19-91DA-67914005F020}" = "Microsoft DocProp Inplace ML Edit Box Control"
-> {HKLM…CLSID} = "Microsoft DocProp Inplace ML Edit Box Control"
\InProcServer32\(Default) = "C:\WINDOWS\system32\docprop2.dll" [MS]
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}" = "Microsoft DocProp Inplace Droplist Combo Control"
-> {HKLM…CLSID} = "Microsoft DocProp Inplace Droplist Combo Control"
\InProcServer32\(Default) = "C:\WINDOWS\system32\docprop2.dll" [MS]
"{6A205B57-2567-4A2C-B881-F787FAB579A3}" = "Microsoft DocProp Inplace Calendar Control"
-> {HKLM…CLSID} = "Microsoft DocProp Inplace Calendar Control"
\InProcServer32\(Default) = "C:\WINDOWS\system32\docprop2.dll" [MS]
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}" = "Microsoft DocProp Inplace Time Control"
-> {HKLM…CLSID} = "Microsoft DocProp Inplace Time Control"
\InProcServer32\(Default) = "C:\WINDOWS\system32\docprop2.dll" [MS]
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}" = "Directory Query UI"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\system32\dsquery.dll" [MS]
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}" = "Shell properties for a DS object"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\system32\dsquery.dll" [MS]
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}" = "Directory Object Find"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\system32\dsquery.dll" [MS]
"{F020E586-5264-11d1-A532-0000F8757D7E}" = "Directory Start/Search Find"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\system32\dsquery.dll" [MS]
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}" = "Directory Property UI"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\system32\dsuiext.dll" [MS]
"{62AE1F9A-126A-11D0-A14B-0800361B1103}" = "Directory Context Menu Verbs"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\system32\dsuiext.dll" [MS]
"{ECF03A33-103D-11d2-854D-006008059367}" = "MyDocs Copy Hook"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\system32\mydocs.dll" [MS]
"{ECF03A32-103D-11d2-854D-006008059367}" = "MyDocs Drop Target"
-> {HKLM…CLSID} = "MyDocs Drop Target"
\InProcServer32\(Default) = "C:\WINDOWS\system32\mydocs.dll" [MS]
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}" = "MyDocs Properties"
-> {HKLM…CLSID} = "MyDocs menu and properties"
\InProcServer32\(Default) = "C:\WINDOWS\system32\mydocs.dll" [MS]
"{750fdf0e-2a26-11d1-a3ea-080036587f03}" = "Offline Files Menu"
-> {HKLM…CLSID} = "Offline Files Menu"
\InProcServer32\(Default) = "C:\WINDOWS\System32\cscui.dll" [MS]
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}" = "Offline Files Folder Options"
-> {HKLM…CLSID} = "Offline Files Folder Options"
\InProcServer32\(Default) = "C:\WINDOWS\System32\cscui.dll" [MS]
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}" = "Offline Files Folder"
-> {HKLM…CLSID} = "Offline Files Folder"
\InProcServer32\(Default) = "C:\WINDOWS\System32\cscui.dll" [MS]
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}" = "Microsoft Agent Character Property Sheet Handler"
-> {HKLM…CLSID} = "Microsoft Agent Character Property Sheet Handler"
\InProcServer32\(Default) = "C:\WINDOWS\msagent\agentpsh.dll" [MS]
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}" = "DfsShell"
-> {HKLM…CLSID} = "DfsShell Class"
\InProcServer32\(Default) = "C:\WINDOWS\system32\dfsshlex.dll" [MS]
"{60fd46de-f830-4894-a628-6fa81bc0190d}" = "%DESC_PublishDropTarget%"
-> {HKLM…CLSID} = "DropTarget Object for Photo Printing Wizard"
\InProcServer32\(Default) = "C:\WINDOWS\system32\photowiz.dll" [MS]
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}" = "MMC Icon Handler"
-> {HKLM…CLSID} = "ExtractIcon Class"
\InProcServer32\(Default) = "C:\WINDOWS\System32\mmcshext.dll" [MS]
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}" = ".CAB file viewer"
-> {HKLM…CLSID} = "Cabinet File"
\InProcServer32\(Default) = "cabview.dll" [MS]
"{32714800-2E5F-11d0-8B85-00AA0044F941}" = "For &People…"
-> {HKLM…CLSID} = "For &People…"
\InProcServer32\(Default) = "C:\Program Files\Outlook Express\wabfind.dll" [MS]
"{8DD448E6-C188-4aed-AF92-44956194EB1F}" = "Windows Media Player Play as Playlist Context Menu Handler"
-> {HKLM…CLSID} = "WMP Burn Audio CD Launcher"
\InProcServer32\(Default) = "C:\WINDOWS\system32\wmpshell.dll" [MS]
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}" = "Windows Media Player Burn Audio CD Context Menu Handler"
-> {HKLM…CLSID} = "WMP Play As Playlist Launcher"
\InProcServer32\(Default) = "C:\WINDOWS\system32\wmpshell.dll" [MS]
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}" = "Windows Media Player Add to Playlist Context Menu Handler"
-> {HKLM…CLSID} = "WMP Add To Playlist Launcher"
\InProcServer32\(Default) = "C:\WINDOWS\system32\wmpshell.dll" [MS]
"{1D2680C9-0E2A-469d-B787-065558BC7D43}" = "Fusion Cache"
-> {HKLM…CLSID} = "Fusion Cache"
\InProcServer32\(Default) = "C:\WINDOWS\system32\mscoree.dll" [MS]
"{BDEADF00-C265-11D0-BCED-00A0C90AB50F}" = "Web Folders"
-> {HKLM…CLSID} = "Web Folders"
\InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL" [MS]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\OFFICE11\msohev.dll" [MS]
"{C4213067-97B3-4929-9B98-B5600FBBBA13}" = "TouchED"
-> {HKLM…CLSID} = "TouchShellExt Class"
\InProcServer32\(Default) = "C:\Program Files\TOSHIBA\TouchED\TouchED.dll" ["TOSHIBA Corporation"]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
-> {HKLM…CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
-> {HKLM…CLSID} = "Outlook File Icon Extension"
\InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office\OLKFSTUB.DLL" [MS]
"{21569614-B795-46b1-85F4-E737A8DC09AD}" = "Shell Search Band"
-> {HKLM…CLSID} = "Shell Search Band"
\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
-> {HKLM…CLSID} = "RealOne Player Context Menu Class"
\InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpshell.dll" ["RealNetworks, Inc."]
"{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices"
-> {HKLM…CLSID} = "Portable Media Devices"
\InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
-> {HKLM…CLSID} = "Portable Media Devices Menu"
\InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]
"{e82a2d71-5b2f-43a0-97b8-81be15854de8}" = "ShellLink for Application References"
-> {HKLM…CLSID} = "ShellLink for Application References"
\InProcServer32\(Default) = "C:\WINDOWS\system32\dfshim.dll" [MS]
"{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75}" = "Shell Icon Handler for Application References"
-> {HKLM…CLSID} = "Shell Icon Handler for Application References"
\InProcServer32\(Default) = "C:\WINDOWS\system32\dfshim.dll" [MS]
"{BDA77241-42F6-11d0-85E2-00AA001FE28C}" = "LDVP Shell Extensions"
-> {HKLM…CLSID} = "VpshellEx Class"
\InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll" ["Symantec Corporation"]
"{400CFEE2-39D0-46DC-96DF-E0BB5A4324B3}" = "My Logitech Pictures"
-> {HKLM…CLSID} = "My Logitech Pictures"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Video\Namespc2.dll" ["Logitech Inc."]
"{07C45BB1-4A8C-4642-A1F5-237E7215FF66}" = "IE Microsoft BrowserBand"
-> {HKLM…CLSID} = "IE Microsoft BrowserBand"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{1C1EDB47-CE22-4bbb-B608-77B48F83C823}" = "IE Fade Task"
-> {HKLM…CLSID} = "IE Fade Task"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{205D7A97-F16D-4691-86EF-F3075DCCA57D}" = "IE Menu Desk Bar"
-> {HKLM…CLSID} = "IE Menu Desk Bar"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{3028902F-6374-48b2-8DC6-9725E775B926}" = "IE AutoComplete"
-> {HKLM…CLSID} = "IE AutoComplete"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{43886CD5-6529-41c4-A707-7B3C92C05E68}" = "IE Navigation Bar"
-> {HKLM…CLSID} = "IE Navigation Bar"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{44C76ECD-F7FA-411c-9929-1B77BA77F524}" = "IE Menu Site"
-> {HKLM…CLSID} = "IE Menu Site"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{4B78D326-D922-44f9-AF2A-07805C2A3560}" = "IE Menu Band"
-> {HKLM…CLSID} = "IE Menu Band"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{6038EF75-ABFC-4e59-AB6F-12D397F6568D}" = "IE Microsoft History AutoComplete List"
-> {HKLM…CLSID} = "IE Microsoft History AutoComplete List"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE}" = "IE Tracking Shell Menu"
-> {HKLM…CLSID} = "IE Tracking Shell Menu"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{6CF48EF8-44CD-45d2-8832-A16EA016311B}" = "IE IShellFolderBand"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{73CFD649-CD48-4fd8-A272-2070EA56526B}" = "IE BandProxy"
-> {HKLM…CLSID} = "IE BandProxy"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8}" = "IE MRU AutoComplete List"
-> {HKLM…CLSID} = "IE MRU AutoComplete List"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E}" = "IE RSS Feeder Folder"
-> {HKLM…CLSID} = "IE RSS Feeds Folder"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{9D958C62-3954-4b44-8FAB-C4670C1DB4C2}" = "IE Microsoft Shell Folder AutoComplete List"
-> {HKLM…CLSID} = "IE Microsoft Shell Folder AutoComplete List"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{B31C5FAE-961F-415b-BAF0-E697A5178B94}" = "IE Microsoft Multiple AutoComplete List Container"
-> {HKLM…CLSID} = "IE Microsoft Multiple AutoComplete List Container"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{BC476F4C-D9D7-4100-8D4E-E043F6DEC409}" = "Microsoft Browser Architecture"
-> {HKLM…CLSID} = "Microsoft Browser Architecture"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A}" = "IE Shell Rebar BandSite"
-> {HKLM…CLSID} = "IE Shell Rebar BandSite"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{E6EE9AAC-F76B-4947-8260-A9F136138E11}" = "IE Shell Band Site Menu"
-> {HKLM…CLSID} = "IE Shell Band Site Menu"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{F2CF5485-4E02-4f68-819C-B92DE9277049}" = "&Links"
-> {HKLM…CLSID} = "&Links"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E}" = "IE Registry Tree Options Utility"
-> {HKLM…CLSID} = "IE Registry Tree Options Utility"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75}" = "IE User Assist"
-> {HKLM…CLSID} = "IE User Assist"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{FDE7673D-2E19-4145-8376-BBD58C4BC7BA}" = "IE Custom MRU AutoCompleted List"
-> {HKLM…CLSID} = "IE Custom MRU AutoCompleted List"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{e57ce731-33e8-4c51-8354-bb4de9d215d1}" = "Universal Plug and Play Devices"
-> {HKLM…CLSID} = "Universal Plug and Play Devices"
\InProcServer32\(Default) = "C:\WINDOWS\system32\upnpui.dll" [MS]
"{97F68CE3-7146-45FF-BE24-D9A7DD7CB8A2}" = "NeroCoverEd Live Icons"
-> {HKLM…CLSID} = "NeroCoverEdLiveIcons Class"
\InProcServer32\(Default) = "C:\Program Files\Nero\Nero 7\Nero CoverDesigner\CoverEdExtension.dll" ["Nero AG"]
"{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}" = "UnlockerShellExtension"
-> {HKLM…CLSID} = "UnlockerShellExtension"
\InProcServer32\(Default) = "C:\Program Files\Unlocker\UnlockerCOM.dll" [null data]
continued: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\ "{438755C2-A8BA-11D1-B96B-00A0C90312E1}" = "Browseui preloader" -> {HKLM…CLSID} = "Browseui preloader" \InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS] "{8C7461EF-2B13-11d2-BE35-3078302C2030}" = "Component Categories cache daemon" -> {HKLM…CLSID} = "Component Categories cache daemon" \InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS] HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\ "{AEB6717E-7E19-11d0-97EE-00C04FD91972}" = (no title provided) -> {HKLM…CLSID} = "URL Exec Hook" \InProcServer32\(Default) = "shell32.dll" [MS] <> "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}" = "AVG Anti-Spyware 7.5" -> {HKLM…CLSID} = "CShellExecuteHookImpl Object" \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" ["Anti-Malware Development a.s."] HKCU\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ "PostBootReminder" = "{7849596a-48ea-486e-8937-a2a3009f31a9}" -> {HKLM…CLSID} = "PostBootReminder object" \InProcServer32\(Default) = "C:\WINDOWS\system32\SHELL32.dll" [MS] "WebCheck" = "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" -> {HKLM…CLSID} = "WebCheck" \InProcServer32\(Default) = "C:\WINDOWS\system32\webcheck.dll" [MS] "SysTray" = "{35CEC8A3-2BE6-11D2-8773-92E220524153}" -> {HKLM…CLSID} = "SysTray" \InProcServer32\(Default) = "C:\WINDOWS\system32\stobject.dll" [MS] HKCU\Software\Microsoft\Command Processor\ "AutoRun" = (value not found) HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\ "Shell" = (value not found) HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\ "load" = (value not found) "run" = (value not found) HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\ "Shell" = (value not found) HKLM\Software\Microsoft\Command Processor\ "AutoRun" = (empty string) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\ "AppInit_DLLs" = (value not found) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\ "GinaDLL" = (value not found) "Shell" = "Explorer.exe" [MS] "Taskman" = (value not found) "Userinit" = "C:\WINDOWS\system32\userinit.exe," [MS] "System" = (empty string) HKLM\System\CurrentControlSet\Control\SafeBoot\Option\ "UseAlternateShell" = (value not found) HKLM\System\CurrentControlSet\Control\SecurityProviders\ "SecurityProviders" = "msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" HKLM\System\CurrentControlSet\Control\Session Manager\ "BootExecute" = "autocheck autochk *" HKLM\System\CurrentControlSet\Control\WOW\ "cmdline" = "C:\WINDOWS\system32\ntvdm.exe" [MS] "wowcmdline" = "C:\WINDOWS\system32\ntvdm.exe -a C:\WINDOWS\system32\krnl386" [MS] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ crypt32chain\DLLName = "crypt32.dll" [MS] cryptnet\DLLName = "cryptnet.dll" [MS] cscdll\DLLName = "cscdll.dll" [MS] <> igfxcui\DLLName = "igfxsrvc.dll" ["Intel Corporation"] <> NavLogon\DLLName = "C:\WINDOWS\system32\NavLogon.dll" ["Symantec Corporation"] ScCertProp\DLLName = "wlnotify.dll" [MS] Schedule\DLLName = "wlnotify.dll" [MS] sclgntfy\DLLName = "sclgntfy.dll" [MS] SensLogn\DLLName = "WlNotify.dll" [MS] termsrv\DLLName = "wlnotify.dll" [MS] WgaLogon\DLLName = "WgaLogon.dll" [MS] wlballoon\DLLName = "wlnotify.dll" [MS] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ Your Image File Name Here without a path\Debugger = "ntsd -d" [MS] HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logon\ HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logoff\ HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Startup\ HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Shutdown\ HKLM\Software\Classes\PROTOCOLS\Filter\ application/octet-stream\CLSID = "{1E66F26B-79EE-11D2-8710-00C04F79ED0D}" -> {HKLM…CLSID} = "Cor MIME Filter, CorFltr, CorFltr 1" \InProcServer32\(Default) = "mscoree.dll" [MS] application/x-complus\CLSID = "{1E66F26B-79EE-11D2-8710-00C04F79ED0D}" -> {HKLM…CLSID} = "Cor MIME Filter, CorFltr, CorFltr 1" \InProcServer32\(Default) = "mscoree.dll" [MS] application/x-msdownload\CLSID = "{1E66F26B-79EE-11D2-8710-00C04F79ED0D}" -> {HKLM…CLSID} = "Cor MIME Filter, CorFltr, CorFltr 1" \InProcServer32\(Default) = "mscoree.dll" [MS] Class Install Handler\CLSID = "{32B533BB-EDAE-11d0-BD5A-00AA00B92AF1}" -> {HKLM…CLSID} = "AP Class Install Handler filter" \InProcServer32\(Default) = "C:\WINDOWS\system32\urlmon.dll" [MS] deflate\CLSID = "{8f6b0360-b80d-11d0-a9b3-006097942311}" -> {HKLM…CLSID} = "AP encoding/decoding Filters" \InProcServer32\(Default) = "C:\WINDOWS\system32\urlmon.dll" [MS] gzip\CLSID = "{8f6b0360-b80d-11d0-a9b3-006097942311}" -> {HKLM…CLSID} = "AP encoding/decoding Filters" \InProcServer32\(Default) = "C:\WINDOWS\system32\urlmon.dll" [MS] lzdhtml\CLSID = "{8f6b0360-b80d-11d0-a9b3-006097942311}" -> {HKLM…CLSID} = "AP encoding/decoding Filters" \InProcServer32\(Default) = "C:\WINDOWS\system32\urlmon.dll" [MS] text/webviewhtml\CLSID = "{733AC4CB-F1A4-11d0-B951-00A0C90312E1}" -> {HKLM…CLSID} = "WebView MIME Filter" \InProcServer32\(Default) = "C:\WINDOWS\system32\SHELL32.dll" [MS] <> text/xml\CLSID = "{807553E5-5146-11D5-A672-00B0D022E945}" -> {HKLM…CLSID} = (no title provided) \InProcServer32\(Default) = "C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL" [MS] HKLM\Software\Classes\Folder\shellex\ColumnHandlers\ {0D2E74C4-3C34-11d2-A27E-00C04FC30871}\(Default) = (no title provided) -> {HKLM…CLSID} = (no title provided) \InProcServer32\(Default) = "C:\WINDOWS\system32\SHELL32.dll" [MS] {24F14F01-7B1C-11d1-838f-0000F80461CF}\(Default) = (no title provided) -> {HKLM…CLSID} = (no title provided) \InProcServer32\(Default) = "C:\WINDOWS\system32\SHELL32.dll" [MS] {24F14F02-7B1C-11d1-838f-0000F80461CF}\(Default) = (no title provided) -> {HKLM…CLSID} = (no title provided) \InProcServer32\(Default) = "C:\WINDOWS\system32\SHELL32.dll" [MS] {66742402-F9B9-11D1-A202-0000F81FEDEE}\(Default) = (no title provided) -> {HKLM…CLSID} = (no title provided) \InProcServer32\(Default) = "C:\WINDOWS\system32\SHELL32.dll" [MS] {F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info" -> {HKLM…CLSID} = "PDF Shell Extension" \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."] HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ AVG Anti-Spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}" -> {HKLM…CLSID} = "CContextScan Object" \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll" ["Anti-Malware Development a.s."] Cover Designer\(Default) = "{73FCA462-9BD5-4065-A73F-A8E5F6904EF7}" -> {HKLM…CLSID} = "NeroCoverEdContextMenu Class" \InProcServer32\(Default) = "C:\Program Files\Nero\Nero 7\Nero CoverDesigner\CoverEdExtension.dll" ["Nero AG"] LDVPMenu\(Default) = "{BDA77241-42F6-11d0-85E2-00AA001FE28C}" -> {HKLM…CLSID} = "VpshellEx Class" \InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll" ["Symantec Corporation"] Offline Files\(Default) = "{750fdf0e-2a26-11d1-a3ea-080036587f03}" -> {HKLM…CLSID} = "Offline Files Menu" \InProcServer32\(Default) = "C:\WINDOWS\System32\cscui.dll" [MS] Open With\(Default) = "{09799AFB-AD67-11d1-ABCD-00C04FC30936}" -> {HKLM…CLSID} = "Open With Context Menu Handler" \InProcServer32\(Default) = "C:\WINDOWS\system32\SHELL32.dll" [MS] Open With EncryptionMenu\(Default) = "{A470F8CF-A1E8-4f65-8335-227475AA5C46}" -> {HKLM…CLSID} = "Encryption Context Menu" \InProcServer32\(Default) = "C:\WINDOWS\system32\SHELL32.dll" [MS] VIDEOTRANS\(Default) = "{548773BA-874E-4C02-9DC7-B7A096772C7D}" -> {HKLM…CLSID} = "CountLines Class" \InProcServer32\(Default) = "C:\Program Files\MP3 Player Utilities 3.57\AMVTools\SrcCount.dll" [empty string] WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" -> {HKLM…CLSID} = "WinRAR" \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data] WS_FTP\(Default) = "{797F3885-5429-11D4-8823-0050DA59922B}" -> {HKLM…CLSID} = "RtClkCtxMenu Class" \InProcServer32\(Default) = "C:\Program Files\Ipswitch\WS_FTP Professional\wsftpsi.dll" ["Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington, MA 02421"] HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ AVG Anti-Spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}" -> {HKLM…CLSID} = "CContextScan Object" \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll" ["Anti-Malware Development a.s."] EncryptionMenu\(Default) = "{A470F8CF-A1E8-4f65-8335-227475AA5C46}" -> {HKLM…CLSID} = "Encryption Context Menu" \InProcServer32\(Default) = "C:\WINDOWS\system32\SHELL32.dll" [MS] Offline Files\(Default) = "{750fdf0e-2a26-11d1-a3ea-080036587f03}" -> {HKLM…CLSID} = "Offline Files Menu" \InProcServer32\(Default) = "C:\WINDOWS\System32\cscui.dll" [MS] Sharing\(Default) = "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}" -> {HKLM…CLSID} = "Shell extensions for sharing" \InProcServer32\(Default) = "ntshrui.dll" [MS] WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" -> {HKLM…CLSID} = "WinRAR" \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data] HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ LDVPMenu\(Default) = "{BDA77241-42F6-11d0-85E2-00AA001FE28C}" -> {HKLM…CLSID} = "VpshellEx Class" \InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll" ["Symantec Corporation"] UnlockerShellExtension\(Default) = "{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}" -> {HKLM…CLSID} = "UnlockerShellExtension" \InProcServer32\(Default) = "C:\Program Files\Unlocker\UnlockerCOM.dll" [null data] WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" -> {HKLM…CLSID} = "WinRAR" \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data] WS_FTP\(Default) = "{797F3885-5429-11D4-8823-0050DA59922B}" -> {HKLM…CLSID} = "RtClkCtxMenu Class" \InProcServer32\(Default) = "C:\Program Files\Ipswitch\WS_FTP Professional\wsftpsi.dll" ["Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington, MA 02421"] HKLM\Software\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\ Send To\(Default) = "{7BA4C740-9E81-11CF-99D3-00AA004AE837}" -> {HKLM…CLSID} = "Microsoft SendTo Service" \InProcServer32\(Default) = "C:\WINDOWS\system32\SHELL32.dll" [MS] UnlockerShellExtension\(Default) = "{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}" -> {HKLM…CLSID} = "UnlockerShellExtension" \InProcServer32\(Default) = "C:\Program Files\Unlocker\UnlockerCOM.dll" [null data] Default executables: ——————– HKLM\Software\Classes\.bat\(Default) = "batfile" HKLM\Software\Classes\batfile\shell\open\command\(Default) = ""%1" %*" HKLM\Software\Classes\.cmd\(Default) = "cmdfile" HKLM\Software\Classes\cmdfile\shell\open\command\(Default) = ""%1" %*" HKLM\Software\Classes\.com\(Default) = "comfile" HKLM\Software\Classes\comfile\shell\open\command\(Default) = ""%1" %*" HKLM\Software\Classes\.exe\(Default) = "exefile" HKLM\Software\Classes\exefile\shell\open\command\(Default) = ""%1" %*" HKLM\Software\Classes\.hta\(Default) = "htafile" HKLM\Software\Classes\htafile\shell\open\command\(Default) = "C:\WINDOWS\system32\mshta.exe "%1" %*" HKLM\Software\Classes\.pif\(Default) = "piffile" HKLM\Software\Classes\piffile\shell\open\command\(Default) = ""%1" %*" HKLM\Software\Classes\.scr\(Default) = "scrfile" HKLM\Software\Classes\scrfile\shell\open\command\(Default) = ""%1" /S" Group Policies {GPedit.msc branch and setting}: ———————————————– Note: detected settings may not have any effect. HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\ HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\ HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\ HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ "NoDriveTypeAutoRun" = (REG_DWORD) hex:0x00000091 {User Configuration|Administrative Templates|Windows Components|AutoPlay Policies| Turn off Autoplay} HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowCpl\ HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\ HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\WindowsUpdate\ HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\ HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel\ HKCU\Software\Policies\Microsoft\Internet Explorer\Download\ HKLM\Software\Policies\Microsoft\Internet Explorer\Download\ HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\ HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\ HKCU\Software\Policies\Microsoft\Internet Explorer\Main\ HKLM\Software\Policies\Microsoft\Internet Explorer\Main\ HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\ HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\ HKCU\Software\Policies\Microsoft\Internet Explorer\PhishingFilter\ HKLM\Software\Policies\Microsoft\Internet Explorer\PhishingFilter\ HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\ HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions\ HKCU\Software\Policies\Microsoft\Internet Explorer\Security\ HKLM\Software\Policies\Microsoft\Internet Explorer\Security\ HKCU\Software\Policies\Microsoft\MMC\{8FC0B734-A0E1-11D1-A7D3-0000F87571E3}\ HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2\ HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2\ HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3\ HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3\ HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4\ HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4\ HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\ HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\ HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\ HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\ HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\ HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\ HKCU\Software\Policies\Microsoft\Windows\Network Connections\ HKCU\Software\Policies\Microsoft\Windows\System\ HKCU\Software\Policies\Microsoft\Windows\Task Scheduler5.0\ HKLM\Software\Policies\Microsoft\Windows\Task Scheduler5.0\ HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\ "dontdisplaylastusername" = (REG_DWORD) hex:0x00000000 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| Interactive logon: Do not display last user name} "legalnoticetext" = (REG_SZ) (empty string) {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| Interactive logon: Message text for users attempting to log on} "shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| Shutdown: Allow system to be shut down without having to log on} "undockwithoutlogon" = (REG_DWORD) hex:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| Devices: Allow undock without having to log on} HKLM\Software\Policies\Microsoft\Windows NT\SystemRestore\ Active Desktop and Wallpaper: —————————– Active Desktop may be disabled at this entry: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState Displayed if Active Desktop enabled and wallpaper not set by Group Policy: HKCU\Software\Microsoft\Internet Explorer\Desktop\General\ "Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Wallpaper1.bmp" Displayed if Active Desktop disabled and wallpaper not set by Group Policy: HKCU\Control Panel\Desktop\ "Wallpaper" = "C:\Documents and Settings\Lam\Local Settings\Application Data\Microsoft\Wallpaper1.bmp" Enabled Screen Saver: ——————— HKCU\Control Panel\Desktop\ "SCRNSAVE.EXE" = (value not set) DESKTOP.INI DLL launch in local fixed drive directories: ——————————————————– C:\Documents and Settings\Administrator\Local Settings\History\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] CLSID={FF393560-C2A7-11CF-BFF4-444553540000} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] CLSID={FF393560-C2A7-11CF-BFF4-444553540000} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\Lam\Local Settings\Application Data\Microsoft\Feeds Cache\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\Lam\Local Settings\Application Data\Microsoft\Feeds Cache\4O3L02TJ\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\Lam\Local Settings\Application Data\Microsoft\Feeds Cache\GYMLKZKU\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\Lam\Local Settings\Application Data\Microsoft\Feeds Cache\LBBX6WD7\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\Lam\Local Settings\Application Data\Microsoft\Feeds Cache\RENX9BB8\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\Lam\Local Settings\History\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] CLSID={FF393560-C2A7-11CF-BFF4-444553540000} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\Lam\Local Settings\History\History.IE5\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] CLSID={FF393560-C2A7-11CF-BFF4-444553540000} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\Lam\Local Settings\Temporary Internet Files\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\Lam\Local Settings\Temporary Internet Files\Content.IE5\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\Lam\Local Settings\Temporary Internet Files\Content.IE5\23FDTHVD\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\Lam\Local Settings\Temporary Internet Files\Content.IE5\BO08TSYD\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\Lam\Local Settings\Temporary Internet Files\Content.IE5\DD279C9S\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\Lam\Local Settings\Temporary Internet Files\Content.IE5\LJQT492B\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\Lam\Local Settings\Temporary Internet Files\Content.IE5\LQVBV6XF\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\Lam\Local Settings\Temporary Internet Files\Content.IE5\RHIOM9PK\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\Lam\Local Settings\Temporary Internet Files\Content.IE5\VKPZSBVO\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\Lam\Local Settings\Temporary Internet Files\Content.IE5\YNPMVEVR\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Feeds Cache\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Feeds Cache\0KOPMNMD\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Feeds Cache\ADKZXR22\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Feeds Cache\GX6Z4JWL\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Feeds Cache\VQ8H8UBP\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\LocalService\Local Settings\History\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] CLSID={FF393560-C2A7-11CF-BFF4-444553540000} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] CLSID={FF393560-C2A7-11CF-BFF4-444553540000} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] CLSID={FF393560-C2A7-11CF-BFF4-444553540000} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\Suk Mei\Local Settings\History\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] CLSID={FF393560-C2A7-11CF-BFF4-444553540000} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\Suk Mei\Local Settings\History\History.IE5\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] CLSID={FF393560-C2A7-11CF-BFF4-444553540000} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\Documents and Settings\Suk Mei\Local Settings\Temporary Internet Files\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\WINDOWS\assembly\DESKTOP.INI [.ShellClassInfo] CLSID={1D2680C9-0E2A-469d-B787-065558BC7D43} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\mscoree.dll" [MS] C:\WINDOWS\Downloaded Program Files\DESKTOP.INI [.ShellClassInfo] CLSID={88C6C381-2E85-11d0-94DE-444553540000} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\occache.dll" [MS] C:\WINDOWS\Fonts\DESKTOP.INI [.ShellClassInfo] UICLSID={BD84B380-8CA2-1069-AB1D-08000948F534} -> {HKLM…CLSID}\InProcServer32\(Default) = "fontext.dll" [MS] C:\WINDOWS\system32\config\systemprofile\Local Settings\History\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] CLSID={FF393560-C2A7-11CF-BFF4-444553540000} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\DESKTOP.INI [.ShellClassInfo] UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] CLSID={FF393560-C2A7-11CF-BFF4-444553540000} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] C:\WINDOWS\Tasks\DESKTOP.INI [.ShellClassInfo] CLSID={d6277990-4c6a-11cf-8d87-00aa0060f5bf} -> {HKLM…CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\mstask.dll" [MS] Startup items in "Lam" & "All Users" startup folders: —————————————————– C:\Documents and Settings\Lam\Start Menu\Programs\Startup C:\Documents and Settings\All Users\Start Menu\Programs\Startup "Adobe Reader Speed Launch" -> shortcut to: "C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe" ["Adobe Systems Incorporated"] "Microsoft Office" -> shortcut to: "C:\Program Files\Microsoft Office\Office\OSA9.EXE -b -l" [MS] Enabled Scheduled Tasks: ———————— Winsock2 Service Provider DLLs: ——————————- Namespace Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS] 000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS] 000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS] Transport Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 19 %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05 Toolbars, Explorer Bars, Extensions: ———————————— Toolbars HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\ "{01E04581-4EEE-11D0-BFE9-00AA005B4383}" -> {HKLM…CLSID} = "&Address" \InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS] HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\ "{01E04581-4EEE-11D0-BFE9-00AA005B4383}" -> {HKLM…CLSID} = "&Address" \InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS] "{0E5CBF21-D15F-11D0-8301-00AA005B4383}" -> {HKLM…CLSID} = "&Links" \InProcServer32\(Default) = "C:\WINDOWS\system32\SHELL32.dll" [MS] "{4064EA35-578D-4073-A834-C96D82CBCF40}" -> {HKLM…CLSID} = "&Save Flash" \InProcServer32\(Default) = "C:\Program Files\Save Flash\SaveFlash.dll" ["TODO: "] "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" -> {HKLM…CLSID} = "Yahoo! Toolbar" \InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll" ["Yahoo! Inc."] HKLM\Software\Microsoft\Internet Explorer\Toolbar\ "{E0E899AB-F487-11D5-8D29-0050BA6940E3}" = "FlashGet Bar" -> {HKLM…CLSID} = "FlashGet Bar" \InProcServer32\(Default) = "C:\PROGRA~1\FlashGet\fgiebar.dll" ["Amaze Soft"] "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = (no title provided) -> {HKLM…CLSID} = "Yahoo! Toolbar" \InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll" ["Yahoo! Inc."] "{4064EA35-578D-4073-A834-C96D82CBCF40}" = (no title provided) -> {HKLM…CLSID} = "&Save Flash" \InProcServer32\(Default) = "C:\Program Files\Save Flash\SaveFlash.dll" ["TODO: "] Explorer Bars HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\ {EFA24E62-B078-11D0-89E4-00C04FC9E26E}\(Default) = (no title provided) -> {HKLM…CLSID} = "History Band" \InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS] {EFA24E64-B078-11D0-89E4-00C04FC9E26E}\(Default) = (no title provided) -> {HKLM…CLSID} = "Explorer Band" \InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS] HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\ {4D5C8C25-D075-11D0-B416-00C04FB90376}\(Default) = (no title provided) -> {HKLM…CLSID} = "&Tip of the Day" \InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS] HKLM\Software\Classes\CLSID\{30D02401-6A81-11D0-8274-00C04FD5AE38}\(Default) = "IE Search Band" Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar] InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] HKLM\Software\Classes\CLSID\{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}\(Default) = "&Discuss" Implemented Categories\{00021494-0000-0000-C000-000000000046}\ [horizontal bar] InProcServer32\(Default) = "shdocvw.dll" [MS] HKLM\Software\Classes\CLSID\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\(Default) = "File Search Explorer Band" Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar] InProcServer32\(Default) = "C:\WINDOWS\system32\SHELL32.dll" [MS] HKLM\Software\Classes\CLSID\{EFA24E61-B078-11D0-89E4-00C04FC9E26E}\(Default) = "Favorites Band" Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar] InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS] HKLM\Software\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = "&Research" Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar] InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL" [MS] Extensions (Tools menu items, main toolbar menu buttons) HKCU\Software\Microsoft\Internet Explorer\Extensions\ {C1F0024B-8278-4999-B7E6-2718426D9FE6}\ "CLSIDExtension" = "{E36884E3-42E9-4A8E-A7F8-6DE700903E5C}" -> {HKLM…CLSID} = "CaiFuCOM Class" \InProcServer32\(Default) = "C:\Program Files\***\caifu.dll" (unwritable string) [file not found] HKLM\Software\Microsoft\Internet Explorer\Extensions\ Internet Explorer Address Prefixes: ———————————– Prefix for bare domain ("domain-name-here.com") HKLM\Software\Microsoft\Windows\CurrentVersion\URL\Default Prefix\ (Default) = "http://" Prefix for specific service (i.e., "www") HKLM\Software\Microsoft\Windows\CurrentVersion\URL\Prefixes\ "ftp" = "ftp://" "gopher" = "gopher://" "home" = "http://" "mosaic" = "http://" "www" = "http://" Miscellaneous IE Hijack Points —————————— HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\ "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" = (no title provided) -> {HKLM…CLSID} = "Microsoft Url Search Hook" \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS] HKLM\Software\Microsoft\Internet Explorer\AboutURLs\ "NavigationFailure" = "res://ieframe.dll/navcancl.htm" [MS] "DesktopItemNavigationFailure" = "res://ieframe.dll/navcancl.htm" [MS] "NavigationCanceled" = "res://ieframe.dll/navcancl.htm" [MS] "OfflineInformation" = "res://ieframe.dll/offcancl.htm" [MS] "Home" = hex:0x0000010E "blank" = "res://mshtml.dll/blank.htm" [MS] "PostNotCached" = "res://ieframe.dll/repost.htm" [MS] "NoAdd-ons" = "res://ieframe.dll/noaddon.htm" [MS] "NoAdd-onsInfo" = "res://ieframe.dll/noaddoninfo.htm" [MS] "SecurityRisk" = "res://ieframe.dll/securityatrisk.htm" [MS] "Tabs" = "res://ieframe.dll/tabswelcome.htm" [MS] HOSTS file ———- HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\ "DataBasePath" = "C:\WINDOWS\System32\drivers\etc" C:\WINDOWS\System32\drivers\etc\HOSTS maps: 1 domain name to an IP address, and this is the localhost IP address All Running Services (Display Name, Service Name, Path {Service DLL}): ———————————————————————- Application Layer Gateway Service, ALG, "C:\WINDOWS\System32\alg.exe" [MS] Automatic LiveUpdate Scheduler, Automatic LiveUpdate Scheduler, ""C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe"" ["Symantec Corporation"] Automatic Updates, wuauserv, "C:\WINDOWS\system32\svchost.exe -k netsvcs" {"C:\WINDOWS\system32\wuauserv.dll" [MS]} AVG Anti-Spyware Guard, AVG Anti-Spyware Guard, "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe" ["Anti-Malware Development a.s."] Cisco Systems, Inc. VPN Service, CVPND, ""C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe"" ["Cisco Systems, Inc."] COM+ Event System, EventSystem, "C:\WINDOWS\system32\svchost.exe -k netsvcs" {"C:\WINDOWS\system32\es.dll" [MS]} Computer Browser, Browser, "C:\WINDOWS\system32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\browser.dll" [MS]} ConfigFree Service, CFSvcs, "C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe" ["TOSHIBA CORPORATION"] Cryptographic Services, CryptSvc, "C:\WINDOWS\system32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\cryptsvc.dll" [MS]} Cyberlink RichVideo Service(CRVS), RichVideo, ""C:\Program Files\CyberLink\Shared files\RichVideo.exe"" [empty string] DCOM Server Process Launcher, DcomLaunch, "C:\WINDOWS\system32\svchost -k DcomLaunch" {"C:\WINDOWS\system32\rpcss.dll" [MS]} DHCP Client, Dhcp, "C:\WINDOWS\system32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\dhcpcsvc.dll" [MS]} Distributed Link Tracking Client, TrkWks, "C:\WINDOWS\system32\svchost.exe -k netsvcs" {"C:\WINDOWS\system32\trkwks.dll" [MS]} DNS Client, Dnscache, "C:\WINDOWS\system32\svchost.exe -k NetworkService" {"C:\WINDOWS\System32\dnsrslvr.dll" [MS]} Erdas, Erdas, "C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\lmgrd.exe" ["Macrovision Corporation"] Error Reporting Service, ERSvc, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\ersvc.dll" [MS]} Event Log, Eventlog, "C:\WINDOWS\system32\services.exe" [MS] Fast User Switching Compatibility, FastUserSwitchingCompatibility, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\shsvcs.dll" [MS]} Help and Support, helpsvc, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll" [MS]} HID Input Service, HidServ, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\hidserv.dll" [MS]} IPSEC Services, PolicyAgent, "C:\WINDOWS\system32\lsass.exe" [MS] Logical Disk Manager, dmserver, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\dmserver.dll" [MS]} NCHGBIOS2SVC, NCHGBIOS2SVC, "C:\New Folder\NCHGBIOS2SVC.exe" ["TOSHIBA Corporation"] Network Connections, Netman, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\netman.dll" [MS]} Network Location Awareness (NLA), Nla, "C:\WINDOWS\system32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\mswsock.dll" [MS]} Plug and Play, PlugPlay, "C:\WINDOWS\system32\services.exe" [MS] Print Spooler, Spooler, "C:\WINDOWS\system32\spoolsv.exe" [MS] Protected Storage, ProtectedStorage, "C:\WINDOWS\system32\lsass.exe" [MS] Remote Access Connection Manager, RasMan, "C:\WINDOWS\system32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\rasmans.dll" [MS]} Remote Procedure Call (RPC), RpcSs, "C:\WINDOWS\system32\svchost -k rpcss" {"C:\WINDOWS\System32\rpcss.dll" [MS]} Remote Registry, RemoteRegistry, "C:\WINDOWS\system32\svchost.exe -k LocalService" {"C:\WINDOWS\system32\regsvc.dll" [MS]} Secondary Logon, seclogon, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\seclogon.dll" [MS]} Security Accounts Manager, SamSs, "C:\WINDOWS\system32\lsass.exe" [MS] Security Center, wscsvc, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\system32\wscsvc.dll" [MS]} Server, lanmanserver, "C:\WINDOWS\system32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\srvsvc.dll" [MS]} Shell Hardware Detection, ShellHWDetection, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\shsvcs.dll" [MS]} SSDP Discovery Service, SSDPSRV, "C:\WINDOWS\system32\svchost.exe -k LocalService" {"C:\WINDOWS\System32\ssdpsrv.dll" [MS]} Symantec AntiVirus, Symantec AntiVirus, ""C:\Program Files\Symantec AntiVirus\Rtvscan.exe"" ["Symantec Corporation"] Symantec AntiVirus Definition Watcher, DefWatch, ""C:\Program Files\Symantec AntiVirus\DefWatch.exe"" ["Symantec Corporation"] Symantec Event Manager, ccEvtMgr, ""C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"" ["Symantec Corporation"] Symantec Settings Manager, ccSetMgr, ""C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"" ["Symantec Corporation"] Symantec SPBBCSvc, SPBBCSvc, ""C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe"" ["Symantec Corporation"] System Event Notification, SENS, "C:\WINDOWS\system32\svchost.exe -k netsvcs" {"C:\WINDOWS\system32\sens.dll" [MS]} System Restore Service, srservice, "C:\WINDOWS\system32\svchost.exe -k netsvcs" {"C:\WINDOWS\system32\srsvc.dll" [MS]} Task Scheduler, Schedule, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\system32\schedsvc.dll" [MS]} TCP/IP NetBIOS Helper, LmHosts, "C:\WINDOWS\system32\svchost.exe -k LocalService" {"C:\WINDOWS\System32\lmhsvc.dll" [MS]} Telephony, TapiSrv, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\tapisrv.dll" [MS]} Terminal Services, TermService, "C:\WINDOWS\System32\svchost -k DComLaunch" {"C:\WINDOWS\System32\termsrv.dll" [MS]} Themes, Themes, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\shsvcs.dll" [MS]} WebClient, WebClient, "C:\WINDOWS\system32\svchost.exe -k LocalService" {"C:\WINDOWS\System32\webclnt.dll" [MS]} Windows Audio, AudioSrv, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\audiosrv.dll" [MS]} Windows Firewall/Internet Connection Sharing (ICS), SharedAccess, "C:\WINDOWS\system32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\ipnathlp.dll" [MS]} Windows Image Acquisition (WIA), stisvc, "C:\WINDOWS\system32\svchost.exe -k imgsvc" {"C:\WINDOWS\system32\wiaservc.dll" [MS]} Windows Management Instrumentation, winmgmt, "C:\WINDOWS\system32\svchost.exe -k netsvcs" {"C:\WINDOWS\system32\wbem\WMIsvc.dll" [MS]} Windows Time, W32Time, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\system32\w32time.dll" [MS]} Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\system32\wdfmgr.exe" [MS] Wireless Zero Configuration, WZCSVC, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\wzcsvc.dll" [MS]} Workstation, lanmanworkstation, "C:\WINDOWS\system32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\wkssvc.dll" [MS]} Keyboard Driver Filters: ———————— HKLM\System\CurrentControlSet\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}\ "UpperFilters" = "kbdclass" [MS] Print Monitors: ————— HKLM\System\CurrentControlSet\Control\Print\Monitors\ BJ Language Monitor\Driver = "cnbjmon.dll" [MS] FPP2:\Driver = "fppmon2.dll" ["FinePrint Software, LLC"] HP LaserJet 5 Language Monitor\Driver = "HPDCMON.DLL" ["Hewlett-Packard"] Local Port\Driver = "localspl.dll" [MS] PJL Language Monitor\Driver = "pjlmon.dll" [MS] Standard TCP/IP Port\Driver = "tcpmon.dll" [MS] USB Monitor\Driver = "usbmon.dll" [MS] – (total run time: 63 seconds) <>: Suspicious data at a malware launch point.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI