Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Проблем със скайп вирус [РЕШЕН]

Featured Replies

Добре,добре. Съжалявам.

Редактирано от M1st3r_X (преглед на промените)

  • Отговори 174
  • Прегледи 26,7k
  • Създадено
  • Последен отговор

Потребители с най-много отговори

Най-популярни публикации

  • Добре,добре. Съжалявам.

  • Стартирайте отново Autoruns => придвижете се до колонката => Scheduled Tasks => посочете следния ред => + "WGASetup.job" "Windows Genuine Advantage Notifications Setup" "Microsoft Co

  • Спрете автоматичните актуализации. Десен бутон на My Computer => Properties => Automatic Updates => сложете радио-бутона на "Turn off Automatic Updates" Ако продължи да излиза

Оуууу къде отидохте, бе?!

Брат, преинсталирай скайпа и си готов. Това с линка е само скриптче, вие му заразихте компа с болести, хакери, а у... Чааааакайте малко. Все едно не знаете, че има доста такива скриптове. Даже ако искате да ви пратя и сорса да видите що е скайп "вирус".

Не пишете глупости след като не разбирате !

Компютъра беше сериозно инфектиран, но неопитните потребители трудно биха видяли това !!!

  • Автор

Ето лог-а от Combofix.exe от СТЪПКА 2

ComboFix 09-11-16.05 - Dron445 11.2009 г. 21:07..2 - FAT32x86

Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.2046.1176 [GMT 2:00]

Running from: c:\documents and settings\Dron445\Desktop\ComboFix.exe

AV: avast! antivirus 4.8.1356 [VPS 091116-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

.

((((((((((((((((((((((((( Files Created from 2009-10-16 to 2009-11-16 )))))))))))))))))))))))))))))))

.

2009-11-16 15:47 . 2007-02-16 02:27 44928 ----a-w- c:\windows\system32\drivers\jraid.sys

2009-11-16 15:47 . 2008-04-13 22:10 96512 ------w- c:\windows\system32\drivers\atapi.sys

2009-11-16 13:55 . 2004-08-03 23:56 221184 ----a-w- c:\windows\system32\wmpns.dll

2009-11-16 13:38 . 2008-04-14 03:41 4255 ------w- c:\windows\system32\drivers\adv01nt5.dll

2009-11-16 13:00 . 2009-11-16 13:00 -------- d-----w- c:\windows\system32\KB905474

2009-11-16 13:00 . 2009-03-10 20:26 1403264 ----a-w- c:\windows\system32\KB905474\wganotifypackageinner.exe

2009-11-16 13:00 . 2009-03-10 20:18 453512 ----a-w- c:\windows\system32\KB905474\wgasetup.exe

2009-11-16 12:57 . 2009-11-16 13:39 -------- d-----w- c:\windows\ServicePackFiles

2009-11-16 12:56 . 2009-11-16 12:56 -------- d-----w- c:\program files\MSXML 6.0

2009-11-15 21:55 . 2009-11-15 21:55 -------- d-----w- c:\program files\MSXML 4.0

2009-11-15 21:55 . 2009-11-16 13:01 -------- d--h--w- c:\windows\$hf_mig$

2009-11-15 17:08 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\drivers\bthport.sys

2009-11-15 16:13 . 2009-09-15 11:54 52368 ----a-w- c:\windows\system32\drivers\aswTdi.sys

2009-11-15 16:13 . 2009-09-15 11:54 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys

2009-11-15 16:13 . 2009-09-15 11:53 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys

2009-11-15 16:13 . 2009-09-15 11:56 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys

2009-11-15 16:13 . 2009-09-15 11:56 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys

2009-11-15 16:13 . 2009-09-15 11:55 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys

2009-11-15 16:13 . 2009-09-15 11:55 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys

2009-11-15 16:13 . 2009-09-15 11:53 97480 ----a-w- c:\windows\system32\AvastSS.scr

2009-11-15 16:12 . 2009-09-15 11:59 1279968 ----a-w- c:\windows\system32\aswBoot.exe

2009-11-15 16:12 . 2009-11-15 16:12 -------- d-----w- c:\program files\Alwil Software

2009-11-15 15:43 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll

2009-11-15 11:18 . 2009-11-15 11:18 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes

2009-11-14 13:06 . 2009-11-14 13:06 -------- d-----w- c:\documents and settings\Administrator\Application Data\TuneUp Software

2009-11-14 13:06 . 2009-11-14 13:06 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla

2009-11-14 11:01 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2009-11-14 11:01 . 2009-11-16 13:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2009-11-14 11:01 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2009-11-13 23:25 . 2009-11-16 18:58 -------- d-----w- c:\documents and settings\Dron445\Application Data\Skype

2009-11-13 23:25 . 2009-11-13 23:25 -------- d-----w- c:\program files\Common Files\Skype

2009-11-09 09:54 . 2009-11-09 09:54 -------- d-----w- c:\program files\Common Files\PCSuite

2009-11-09 09:54 . 2009-11-09 09:54 -------- d-----w- c:\program files\Common Files\Nokia

2009-11-09 09:54 . 2009-11-09 09:54 -------- d-----w- c:\program files\PC Connectivity Solution

2009-11-09 09:53 . 2009-02-09 06:37 7808 ----a-w- c:\windows\system32\drivers\usbser_lowerfltj.sys

2009-11-09 09:53 . 2009-02-09 06:37 7808 ----a-w- c:\windows\system32\drivers\usbser_lowerflt.sys

2009-11-09 09:53 . 2009-02-09 06:37 22016 ----a-w- c:\windows\system32\drivers\ccdcmbo.sys

2009-11-09 09:53 . 2009-02-09 06:37 659968 ----a-w- c:\windows\system32\nmwcdcocls.dll

2009-11-09 09:53 . 2009-02-09 06:37 17664 ----a-w- c:\windows\system32\drivers\ccdcmb.sys

2009-11-09 09:53 . 2009-02-09 06:32 1112288 ----a-w- c:\windows\system32\wdfcoinstaller01007.dll

2009-11-09 09:53 . 2009-11-09 09:52 33773208 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Nokia_PC_Suite_7_1_30_9_eng.exe

2009-11-09 09:52 . 2009-11-09 09:52 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\pcswpcsi.exe

2009-11-09 09:52 . 2009-11-09 09:52 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstCCD.exe

2009-11-09 09:52 . 2009-11-09 09:52 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCSFEMsi.exe

2009-11-09 09:52 . 2009-11-09 09:52 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCS.exe

2009-11-08 10:37 . 2009-11-08 10:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Blizzard Entertainment

2009-11-07 16:07 . 2009-11-07 16:07 -------- d-----w- c:\documents and settings\Dron445\Patches

2009-11-02 13:29 . 2009-11-12 13:58 -------- d-----w- c:\program files\GRETECH

2009-10-30 12:23 . 2009-10-30 12:23 -------- d-----w- C:\ProgramData

2009-10-30 12:23 . 2009-10-30 12:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Electronic Arts

2009-10-29 16:07 . 2009-10-29 16:07 -------- d-----w- c:\program files\Electronic Arts

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-11-16 19:01 . 2009-10-01 20:05 -------- d-----w- c:\program files\YouTube Downloader

2009-11-16 19:01 . 2009-10-01 20:03 -------- d-----w- c:\program files\Xvid

2009-11-16 19:01 . 2009-07-02 17:48 -------- d-----w- c:\program files\Garena

2009-11-16 19:01 . 2008-10-03 17:29 -------- d-----w- c:\program files\PhotoScape

2009-11-16 19:01 . 2007-12-25 14:16 -------- d-----w- c:\program files\FlashGet

2009-11-16 19:01 . 2007-12-20 13:15 -------- d-----w- c:\program files\Dict05t1Full.zip

2009-11-16 19:01 . 2007-12-20 09:50 -------- d-----w- c:\program files\Windows Media Connect 2

2009-11-16 19:01 . 2008-03-23 20:49 -------- d-----w- c:\program files\AGEIA Technologies

2009-11-16 15:53 . 2007-12-25 10:43 -------- d-----w- c:\documents and settings\Dron445\Application Data\skypePM

2009-11-16 13:57 . 2007-12-20 11:35 181000 ----a-w- c:\documents and settings\Dron445\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2009-11-16 13:29 . 2009-07-01 20:34 -------- d-----w- c:\program files\Google

2009-11-16 13:18 . 2009-06-10 18:46 -------- d-----w- c:\program files\Winamp

2009-11-16 13:18 . 2007-12-25 15:02 -------- d-----w- c:\program files\Valve

2009-11-16 13:18 . 2007-12-20 13:07 -------- d-----w- c:\program files\ABBYY FineReader 8.0 Professional Edition

2009-11-16 13:18 . 2007-12-20 13:24 -------- d-----w- c:\documents and settings\Dron445\Application Data\uTorrent

2009-11-15 15:02 . 2007-12-20 11:07 15600 ----a-w- c:\windows\gdrv.sys

2009-11-13 23:25 . 2007-12-20 13:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype

2009-11-13 23:25 . 2009-06-29 19:05 -------- d-----r- c:\program files\Skype

2009-11-13 23:03 . 2009-06-10 18:46 -------- d-----w- c:\program files\Winamp Toolbar

2009-11-09 22:36 . 2009-11-09 22:36 0 ---ha-w- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf

2009-11-09 22:36 . 2009-11-09 22:36 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf

2009-11-09 19:53 . 2009-07-27 11:55 -------- d-----w- c:\documents and settings\Dron445\Application Data\Nokia

2009-11-09 10:18 . 2008-05-06 08:24 -------- d-----w- c:\program files\Common Files\Teleca Shared

2009-11-09 09:54 . 2009-07-27 11:54 -------- d-----w- c:\program files\Nokia

2009-11-09 09:54 . 2009-07-27 11:54 -------- d-----w- c:\program files\DIFX

2009-11-09 09:52 . 2009-07-27 11:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations

2009-11-08 09:53 . 2008-01-26 19:57 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment

2009-11-04 20:09 . 2007-12-20 11:41 -------- d-----w- c:\documents and settings\Dron445\Application Data\BSplayer PRO

2009-10-26 21:01 . 2008-10-19 14:40 -------- d-----w- c:\documents and settings\All Users\Application Data\KONAMI

2009-10-18 17:51 . 2009-07-27 11:55 -------- d-----w- c:\documents and settings\Dron445\Application Data\PC Suite

2009-10-15 16:17 . 2007-12-20 11:43 444952 ----a-w- c:\windows\system32\wrap_oal.dll

2009-10-15 16:17 . 2007-12-20 11:43 109080 ----a-w- c:\windows\system32\OpenAL32.dll

2009-10-13 19:04 . 2007-12-20 11:10 -------- d--h--w- c:\program files\InstallShield Installation Information

2009-09-21 18:54 . 2007-12-20 13:22 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard

2009-09-09 14:46 . 2009-09-22 12:12 52224 ----a-w- c:\documents and settings\Dron445\Application Data\Mozilla\Firefox\Profiles\jetnxlm2.default\extensions\{127d5117-dcc8-4856-8288-9baa89e57c21}\components\FFExternalAlert.dll

2009-09-09 14:46 . 2009-09-22 12:12 114688 ----a-w- c:\documents and settings\Dron445\Application Data\Mozilla\Firefox\Profiles\jetnxlm2.default\extensions\{127d5117-dcc8-4856-8288-9baa89e57c21}\components\npmozax.dll

2009-08-26 08:16 . 2007-07-22 11:16 247326 ----a-w- c:\windows\system32\strmdll.dll

2009-08-18 20:03 . 2008-05-24 13:28 142265 ----a-w- c:\windows\War3Unin.dat

2008-10-21 19:16 . 2007-12-20 12:59 2516 --sha-w- c:\windows\system32\KGyGaAvL.sys

.

((((((((((((((((((((((((((((( SnapShot_2009-11-16_14.05.03 )))))))))))))))))))))))))))))))))))))))))

.

+ 2009-11-16 19:03 . 2009-11-16 19:03 16384 c:\windows\temp\Perflib_Perfdata_668.dat

+ 2007-07-22 11:17 . 2008-04-14 03:42 666112 c:\windows\system32\wininet.dll

+ 2007-07-22 11:15 . 2008-04-14 03:42 3066880 c:\windows\system32\mshtml.dll

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-09-03 3342336]

"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-06-25 1414144]

"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-09-23 21755688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"JMB36X IDE Setup"="c:\windows\JM\JMInsIDE.exe" [2006-10-30 36864]

"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe" [2007-12-21 4382720]

"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]

"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 249856]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]

"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]

"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-09-15 81000]

"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-04-12 16132608]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

FlexType 2K.lnk - c:\program files\Datecs\FlexType 2K\FType2K.exe [2007-12-20 95232]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"RichVideo"=2 (0x2)

"ose"=3 (0x3)

"idsvc"=3 (0x3)

"Adobe LM Service"=3 (0x3)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]

"Comrade.exe"=c:\program files\GameSpy\Comrade\Comrade.exe

"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]

"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe"

"Device Detector"=DevDetect.exe -autorun

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

"36X Raid Configurer"=c:\windows\system32\JMRaidSetup.exe boot

"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup

"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" -start

"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_01\bin\jusched.exe"

"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000001

"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\uTorrent\\utorrent.exe"=

"e:\\Games\\area51\\Binaries\\BlackSite.exe"=

"c:\\WINDOWS\\system32\\PnkBstrA.exe"=

"c:\\WINDOWS\\system32\\PnkBstrB.exe"=

"f:\\Games\\Crysis\\Bin32\\Crysis.exe"=

"f:\\Games\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=

"f:\\Games\\Warcraft III\\War3.exe"=

"f:\\Games\\Colin McRae DIRT\\DiRT.exe"=

"f:\\Games\\Assassin's CREED\\AssassinsCreed_Dx9.exe"=

"f:\\Games\\Assassin's CREED\\AssassinsCreed_Dx10.exe"=

"f:\\Games\\Assassin's CREED\\AssassinsCreed_Launcher.exe"=

"f:\\Games\\Cs 1.6\\hl.exe"=

"c:\\Program Files\\FlashGet\\FlashGet.exe"=

"f:\\Games\\FIFA 2009\\FIFA09.exe"=

"f:\\Games\\Cs 1.6\\hlds.exe"=

"c:\\Documents and Settings\\Dron445\\Desktop\\GaMeZzZ\\BELOT.EXE"=

"c:\\Program Files\\Valve\\04196913627172813654.exe"=

"f:\\Games\\cs 1.6\\52737450093923891757.exe"=

"f:\\Games\\cs 1.6\\85579586784859229411.exe"=

"f:\\Games\\cs 1.6\\02166227819973012660.exe"=

"f:\\Games\\cs 1.6\\90101726394596593518.exe"=

"f:\\Games\\cs 1.6\\09042378460279316935.exe"=

"f:\\Games\\cs 1.6\\29842430326340412015.exe"=

"f:\\Games\\cs 1.6\\21638571832561326646.exe"=

"f:\\Games\\cs 1.6\\69549157885926792444.exe"=

"f:\\Games\\cs 1.6\\49168354399811303324.exe"=

"c:\\Program Files\\Garena\\Garena.exe"=

"f:\\Games\\Street Fighter 4\\StreetFighterIV.exe"=

"c:\\Program Files\\Valve\\43962100680366902911.exe"=

"f:\\Games\\PES 2010\\pes2010.exe"=

"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=

"e:\\Games\\World of Warcraft\\World of Warcraft\\WoW-3.2.0-enUS-downloader.exe"=

"e:\\Games\\World of Warcraft\\World of Warcraft\\Launcher.exe"=

"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [11/15/2009 6:13 PM 114768]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [11/15/2009 6:13 PM 20560]

S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\Dron445\LOCALS~1\Temp\SLN24.tmp --> c:\docume~1\Dron445\LOCALS~1\Temp\SLN24.tmp [?]

--- Other Services/Drivers In Memory ---

*Deregistered* - mbr

*Deregistered* - PROCEXP113

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

UxTuneUp

.

Contents of the 'Scheduled Tasks' folder

2009-11-13 c:\windows\Tasks\1-Click Maintenance.job

- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 14:53]

2009-11-16 c:\windows\Tasks\User_Feed_Synchronization-{132E3A99-374B-420F-B7FE-679B47B2FD89}.job

- c:\windows\system32\msfeedssync.exe [2007-12-20 19:18]

2009-11-16 c:\windows\Tasks\WGASetup.job

- c:\windows\system32\KB905474\wgasetup.exe [2009-11-16 20:18]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://google.bg/

uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7

mStart Page = hxxp://www.yahoo.com

IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm

IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm

IE: &Winamp Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

FF - ProfilePath - c:\documents and settings\Dron445\Application Data\Mozilla\Firefox\Profiles\jetnxlm2.default\

FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2307307&SearchSource=3&q={searchTerms}

FF - prefs.js: browser.search.selectedEngine - Liverpoolfctv Customized Web Search

FF - prefs.js: browser.startup.homepage - yahoo.com

FF - component: c:\documents and settings\Dron445\Application Data\Mozilla\Firefox\Profiles\jetnxlm2.default\extensions\{127d5117-dcc8-4856-8288-9baa89e57c21}\components\FFExternalAlert.dll

FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll

FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll

---- FIREFOX POLICIES ----

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

.

**************************************************************************

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files:

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]

"ImagePath"="\??\c:\docume~1\Dron445\LOCALS~1\Temp\SLN24.tmp"

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(632)

c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(132)

c:\windows\system32\wpdshserviceobj.dll

c:\windows\system32\portabledevicetypes.dll

c:\windows\system32\portabledeviceapi.dll

.

Completion time: 2009-11-16 21:13

ComboFix-quarantined-files.txt 2009-11-16 19:12

ComboFix2.txt 2009-11-16 15:55

ComboFix3.txt 2009-11-16 14:06

ComboFix4.txt 2009-11-15 19:04

ComboFix5.txt 2009-11-16 19:06

Pre-Run: 940 716 032 bytes free

Post-Run: 900 997 120 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 9F4BC293770F4F896B119B2F6BAE21B7

Сега продължавам с останалите стъпки и ще поствам след малко.

СТЪПКА 3

Ето го и линка на qoobox.rar http://rapidshare.de/files/48691668/Qoobox.rar.html

А да попитам за стъпка 5 и ESET online scanner трябва ли да изтрия моят awast! предварително ?

Редактирано от prandzhev (преглед на промените)

А да попитам за стъпка 5 и ESET online scanner трябва ли да изтрия моят awast! предварително ?

Не, не е необходимо. Това е само онлайн скенер, без защита в реално време. След това ще го деинсталираме. :)

  • Автор

И още 1 въпрос въведох в Run командата дадох Ок и Комбо фикс започна да сканира пак и ми изкара нов лог файл.Така ли трябва да е ?

И още 1 въпрос въведох в Run командата дадох Ок и Комбо фикс започна да сканира пак и ми изкара нов лог файл.Така ли трябва да е ?

Не, трябва да се деинсталира. Сигурни ли сте, че сте оставили празно място между Combofix и /u

Пробвайте със следната команда => Start => Run => напишете => Combofix /UNINSTALL

Ако не се деинсталира...ми кажете и ще го махнем по алтернативен начин.

  • Автор
' date='16 ноември 2009 - 21:29 ' timestamp='1258399772' post='1560433']

Не трябва да се деинсталира. Сигурни ли сте, че сте оставили празно място между Combofix и /u

Пробвайте със следната команда => Start => Run => напишете => Combofix /UNINSTALL

Ако не се деинсталира...ми кажете и ще го махнем по алтернативен начин.

Uninstallna се :) Сега ще довърша със сканирането.

  • Автор

Ето лог-а от сканирането.Съжелявам за забавянето ,но отне час и половина.

ESETSmartInstaller@High as downloader log:

all ok

ESETSmartInstaller@High as downloader log:

all ok

esets_scanner_update returned -1 esets_gle=53251

# version=7

# OnlineScannerApp.exe=1.0.0.1

# OnlineScanner.ocx=1.0.0.6211

# api_version=3.0.2

# EOSSerial=8c61e0de71466d4cb8699d31c60a15d4

# end=finished

# remove_checked=true

# archives_checked=true

# unwanted_checked=true

# unsafe_checked=true

# antistealth_checked=true

# utc_time=2009-11-16 09:23:27

# local_time=2009-11-16 11:23:27 (+0200, FLE Standard Time)

# country="Bulgaria"

# lang=1033

# osver=5.1.2600 NT Service Pack 3

# compatibility_mode=512 16777215 100 0 0 0 0 0

# compatibility_mode=769 16775125 100 98 3716 194678496 8589 0

# compatibility_mode=8192 67108863 100 0 4508 4508 0 0

# scanned=141740

# found=2

# cleaned=2

# scan_time=5665

E:\Games\World of Warcraft\la_whi.dll probably a variant of Win32/Agent trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

E:\My Documents\Children\Goshko\Programs\Felix_21.EXE Win32/Joke.ScreenMate application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

Единият файл го знам Felix.exe ,едно коте дето ти ходи по ПСто то седи от година на ПСто.

И да попитам как да премахна това ?

Постоянно давам Cancel при пускане на ПС и когато дам Shut Down започва да слага някакви ъпдейти и аз спирам Пс от копчето като го задържа.

Спрете автоматичните актуализации.

Десен бутон на My Computer => Properties => Automatic Updates => сложете радио-бутона на "Turn off Automatic Updates"

automatic-updates.png

Ако продължи да излиза изтеглете това и го премахнете с него:

http://www.softpedia.com/get/Tweak/Uninstallers/RemoveWGA.shtml

Мисля, че вече системата ви е чиста, но искам да направим една финална проверка с този инструмент.

Моля, изтеглете mbr.exe и го запазете C:\ . (Важно е да го направите!).

  • Отворете Start -> Run и напишете: cmd.exe
  • Потвърдете с OK.
  • В Command Prompt, напишете: C:\mbr.exe -f (Забележете, че има разстояние преди -f)
  • Потвърдете с клавишния бутон Enter
  • Излезте от Command Prompt

Публикувайте лог файла.

  • Автор

Добре ще го направя ,но най-вероятно утре ,защото сега лягам ,че ме чака училище :D и затова ви казвам да не очаквате сега отговор :) Лека нощ,утре ще пост-на лог файла :) Благодаря.

Редактирано от prandzhev (преглед на промените)

Добре ще го направя ,но най-вероятно утре ,защото сега лягам ,че ме чака училище :D и затова ви казвам да не очаквате сега отговор :) Лека нощ,утре ще пост-на лог файла :) Благодаря.

Няма проблеми. И утре е ден. :)

Поздрави :)

  • Автор

Имам два въпроса.Първият е защо се появява този прозорец ,когато натисна кошчето или при друго действие не знам точно какво ? 1)

И вторият е свързан с cmd.exe.Свалям го в C пиша командата в Run давам Ок и ми излиза следното 2) Къде да да напиша това от стъпката " В Command Prompt, напишете: C:\mbr.exe -f (Забележете, че има разстояние преди -f)" след Dron445 ли пиша C:\mbr.exe ? Пробвах да го напиша след Dron4445 и излиза ,че файлът не е разпознан. ?

Отговор на въпрос 1:

Изтеглете тази програмка => Windows Installer CleanUp Utility и я инсталирайте. Намерете от списъка ABBYY FineReader 8 Professional и натиснете Remove.

Би трябвало проблема да се реши. Ако се появи нов със самата програма => ABBYY FineReader 8 Professional => просто я преинсталирайте.

Отговор на въпрос 2:

Сигурен ли сте, че сте запазили файла - mbr.exe в свободната директория на дял C:\ ?

Ако не сте, копирайте файла там.

Да, точно в Command Prompt (след Dron445) трябва да въведете C:\mbr.exe -f (има разстояние преди -f).

  • Автор

Оправих по първия въпрос.За cmd.exe къде трябва да се запази лог-а ?

Оправих по първия въпрос.За cmd.exe къде трябва да се запази лог-а ?

Въведете тази команда: (пак след Dron445)

c:\mbr.log

Проверете в свободната на C:\ за лог файл и го публикувайте.

Благодаря за снимката. Информацията след първата команда ми бе достатъчна.

СТЪПКА 1:

Време е да почистим инструментите които сме изпозвали.

Изтеглете OTM.exe и я запазете на десктопа. Стартирайте я и натиснете CleanUp! (както е показано на снимката)

oft2.png

Позволете на компютъра Ви да се рестартира ако програмата Ви попита.

СТЪПКА 2:

Не е зле да се имунизирате срещу страници с "печална" слава.

1.Изтеглете си тази програма hpHosts и я инсталирайте. На последното прозорче сложете отметка на DISABLE Windows DNS Client (Recommended).

2.Идва ред и на Spyware Blaster 4.2.Oтидeте на Updates и посочете бутона Check for updates.Остава само да отидете в Protection Status и да изберете Enable All Protection.

Разбира се, няма да е зле да използвате алтернативен браузър...

С Mozilla Firefox получавате възможността да го закрепите с редица добавки от рода на AdBlock Plus, NoScript, Flashblock.

Във версия 3 има има модул за разпознаване на опасните сайтове => но все пак аз препоръчвам инсталирането на една от следните добавки (особено WoT) Mcafee SiteAdvisor, SITEHOUND, WoT (web of Trust)

Разбира се, добър избор са и Opera, Safari, Google Chrome, че дори и последната версия на Internet Explorer 8.

За финал, можете да обновите антивирусната си програма и да направите пълна проверка на системата си.

Безопасно сърфиране и внимавайте какво приемата и стартирате по Скайп занапред. (а и по принцип) :)

  • Автор

Инсталирах hpHosts цъкнах на Recomended и нищо повече не стана,преполагам,че така трябва да е :D Свалих spyware blaster и да попитам ще си пречат ли с Ad-aware 2009 ?И инсталирах препоръчания от вас Wot ,тъй като ползвам само Mozilla и много рядко Експлорер-а.Това достатъчно ли е ? И да попитам за Нод32 от сайта ли да я сваля ,тъй като се чудя коя да ползвам нея или аваст!А също това продължава да се появява при всяко пускане на ПС -

Инсталирах hpHosts цъкнах на Recomended и нищо повече не стана,преполагам,че така трябва да е :cool: Свалих spyware blaster и да попитам ще си пречат ли с Ad-aware 2009 ?И инсталирах препоръчания от вас Wot ,тъй като ползвам само Mozilla и много рядко Експлорер-а.Това достатъчно ли е ? И да попитам за Нод32 от сайта ли да я сваля ,тъй като се чудя коя да ползвам нея или аваст!А също това продължава да се появява при всяко пускане на ПС -

Да, с Hphosts точно това трябва да се случи. Той имунизира hosts.ini и по-този начин, ако въведете сайт с опасно съдържание, което се съдържа в базата данни на hosts.ini, Windows няма да позволи неговото отваряне (разглеждане). Имайте напредвид, че са блокирани и доста торенти и други хакрески/кракерски портали. За да ги разблокирате ще ви трябва програмката HostsXpert 4.3. Как се работи с нея обаче ще пиша после, защото съм на работа в момента. (следете темата). :)

SpywareBlaster не е анти-шпионска програма в типичния смисъл на думата. Тя имунизира компютъра и няма модул за сканиране и предпазване в реално време. Т.е. не си пречи с никоя друга програма.

Препоръчвам Ви да деинсталирате морално остарялото решение Ad-aware. Освен, че си имате Malwarebytes' Anit-Malware, Ad-aware използва антивирусния енджин на Avira и са възможни потенциални конфликти. По-добре я разкарайте.

Не, WoT не е достатъчна добавка. Тя само ще ви подсказва кои сайтове са с опасно съдържание. Препоръчвам инсталирането на поне следните добавки - NoScript и AdBlock, за да се предпазите от различни атаки и експлоити на браузърите и вероятността от зараза с Virut, Sality, Parity и други пачващи вируси (заразяващи всички *.exe файлове) използващи iFrame за разпространение ще бъдат сведени до минимум.

Винаги антивирусните програми (и изобщо програмите за сигурност) трябва да се теглят САМО и ЕДИНСТВЕНО от официалните страници на производителите. Но ако използвате NOD32 имайте предвид, че е платена. Избийте си от главата идеята да ползвате кракната версия, защото много скоро пак ще отворите нова тема с подобен проблем !

За последния проблем проверете кои са стартиращите програми от Start => Run => напишете => msconfig => отидете на => startup и разгледайте кои програми се стартират.

Също така:

Изтеглете Autoruns:

1) стартирайте програмата;

2) от менюте File -> Save -> запазете файла с някакво име и разширение *.txt (НE *.ARN)

3) копирайте съдържанието на лога в следващия си пост

  • Автор

Сложих си Adblock i NoScript,но последната забранява скриптове на всеки сайт дори и на калдата.Не ,че ми пречи да ги отварям ,но все пак им давам allow на тези ,които използвам ?

Иначе ето лог файла :

"HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms" "" "" ""

+ "rdpclip" "RDP Clip Monitor" "Microsoft Corporation" "c:\windows\system32\rdpclip.exe"

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit" "" "" ""

+ "C:\WINDOWS\system32\userinit.exe" "Userinit Logon Application" "Microsoft Corporation" "c:\windows\system32\userinit.exe"

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell" "" "" ""

+ "Explorer.exe" "Windows Explorer" "Microsoft Corporation" "c:\windows\explorer.exe"

"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" "" "" ""

+ "Adobe Reader Speed Launcher" "Adobe Acrobat SpeedLauncher" "Adobe Systems Incorporated" "c:\program files\adobe\reader 8.0\reader\reader_sl.exe"

+ "avast!" "avast! service GUI component" "ALWIL Software" "c:\program files\alwil software\avast4\ashdisp.exe"

+ "ISUSPM Startup" "InstallShield Update Service Update Manager" "Macrovision Corporation" "c:\program files\common files\installshield\updateservice\isuspm.exe"

+ "JMB36X IDE Setup" "" "" "c:\windows\jm\jminside.exe"

+ "Malwarebytes Anti-Malware (reboot)" "Malwarebytes' Anti-Malware" "Malwarebytes Corporation" "c:\program files\malwarebytes' anti-malware\mbam.exe"

+ "MSConfig" "System Configuration Utility" "Microsoft Corporation" "c:\windows\pchealth\helpctr\binaries\msconfig.exe"

+ "RTHDCPL" "Realtek HD Audio Control Panel" "Realtek Semiconductor Corp." "c:\windows\rthdcpl.exe"

+ "StartCCC" "" "" "c:\program files\ati technologies\ati.ace\core-static\clistart.exe"

"C:\Documents and Settings\All Users\Start Menu\Programs\Startup" "" "" ""

+ "FlexType 2K.lnk" "" "" "c:\program files\datecs\flextype 2k\ftype2k.exe"

"HKCU\Software\Microsoft\Windows\CurrentVersion\Run" "" "" ""

+ "PC Suite Tray" "Nokia Launch Application" "Nokia" "c:\program files\nokia\nokia pc suite 7\pcsuite.exe"

+ "Skype" "Skype" "Skype Technologies S.A." "c:\program files\skype\phone\skype.exe"

"HKLM\SOFTWARE\Classes\Protocols\Filter" "" "" ""

+ "application/octet-stream" "Microsoft .NET Runtime Execution Engine" "Microsoft Corporation" "c:\windows\system32\mscoree.dll"

+ "application/x-complus" "Microsoft .NET Runtime Execution Engine" "Microsoft Corporation" "c:\windows\system32\mscoree.dll"

+ "application/x-msdownload" "Microsoft .NET Runtime Execution Engine" "Microsoft Corporation" "c:\windows\system32\mscoree.dll"

+ "deflate" "OLE32 Extensions for Win32" "Microsoft Corporation" "c:\windows\system32\urlmon.dll"

+ "gzip" "OLE32 Extensions for Win32" "Microsoft Corporation" "c:\windows\system32\urlmon.dll"

+ "text/webviewhtml" "Windows Shell Common Dll" "Microsoft Corporation" "c:\windows\system32\shell32.dll"

+ "text/xml" "Microsoft Office XML MIME Filter" "Microsoft Corporation" "c:\program files\common files\microsoft shared\office11\msoxmlmf.dll"

"HKLM\SOFTWARE\Classes\Protocols\Handler" "" "" ""

+ "about" "Microsoft ® HTML Viewer" "Microsoft Corporation" "c:\windows\system32\mshtml.dll"

+ "cdl" "OLE32 Extensions for Win32" "Microsoft Corporation" "c:\windows\system32\urlmon.dll"

+ "dvd" "ActiveX control for streaming video" "Microsoft Corporation" "c:\windows\system32\msvidctl.dll"

+ "file" "OLE32 Extensions for Win32" "Microsoft Corporation" "c:\windows\system32\urlmon.dll"

+ "ftp" "OLE32 Extensions for Win32" "Microsoft Corporation" "c:\windows\system32\urlmon.dll"

+ "gopher" "OLE32 Extensions for Win32" "Microsoft Corporation" "c:\windows\system32\urlmon.dll"

+ "http" "OLE32 Extensions for Win32" "Microsoft Corporation" "c:\windows\system32\urlmon.dll"

+ "https" "OLE32 Extensions for Win32" "Microsoft Corporation" "c:\windows\system32\urlmon.dll"

+ "its" "Microsoft® InfoTech Storage System Library" "Microsoft Corporation" "c:\windows\system32\itss.dll"

+ "javascript" "Microsoft ® HTML Viewer" "Microsoft Corporation" "c:\windows\system32\mshtml.dll"

+ "local" "OLE32 Extensions for Win32" "Microsoft Corporation" "c:\windows\system32\urlmon.dll"

+ "mailto" "Microsoft ® HTML Viewer" "Microsoft Corporation" "c:\windows\system32\mshtml.dll"

+ "mhtml" "Microsoft Internet Messaging API" "Microsoft Corporation" "c:\windows\system32\inetcomm.dll"

+ "mk" "OLE32 Extensions for Win32" "Microsoft Corporation" "c:\windows\system32\urlmon.dll"

+ "ms-its" "Microsoft® InfoTech Storage System Library" "Microsoft Corporation" "c:\windows\system32\itss.dll"

+ "ms-itss" "Microsoft® InfoTech Storage System Library" "Microsoft Corporation" "c:\program files\common files\microsoft shared\information retrieval\msitss.dll"

+ "mso-offdap" "Microsoft Office XP Web Components" "Microsoft Corporation" "c:\program files\common files\microsoft shared\web components\10\owc10.dll"

+ "mso-offdap11" "Microsoft Office Web Components 2003" "Microsoft Corporation" "c:\program files\common files\microsoft shared\web components\11\owc11.dll"

+ "res" "Microsoft ® HTML Viewer" "Microsoft Corporation" "c:\windows\system32\mshtml.dll"

+ "skype4com" "Skype for COM API" "Skype Technologies" "c:\program files\common files\skype\skype4com.dll"

+ "tv" "ActiveX control for streaming video" "Microsoft Corporation" "c:\windows\system32\msvidctl.dll"

+ "vbscript" "Microsoft ® HTML Viewer" "Microsoft Corporation" "c:\windows\system32\mshtml.dll"

+ "wia" "WIA Scripting Layer" "Microsoft Corporation" "c:\windows\system32\wiascr.dll"

"HKCU\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components" "" "" ""

+ "0" "" "" "File not found: About:Home"

"HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components" "" "" ""

+ "Address Book 6" "Outlook Express Setup Library" "Microsoft Corporation" "c:\program files\outlook express\setup50.exe"

+ "Browser Customizations" "IEAK branding" "Microsoft Corporation" "c:\windows\system32\iedkcs32.dll"

+ "Browser Customizations" "IEAK branding" "Microsoft Corporation" "c:\windows\system32\iedkcs32.dll"

+ "IE7 Uninstall Stub" "IE Per User Active Setup Uninstall Utility" "Microsoft Corporation" "c:\windows\system32\ieudinit.exe"

+ "Internet Explorer" "Windows NT User Data Migration Tool" "Microsoft Corporation" "c:\windows\system32\shmgrate.exe"

+ "Internet Explorer" "IE Per-User Initialization Utility" "Microsoft Corporation" "c:\windows\system32\ie4uinit.exe"

+ "Microsoft Outlook Express 6" "Outlook Express Setup Library" "Microsoft Corporation" "c:\program files\outlook express\setup50.exe"

+ "Microsoft Windows Media Player" "ADVPACK" "Microsoft Corporation" "c:\windows\system32\advpack.dll"

+ "n/a" "Microsoft .NET IE SECURITY REGISTRATION" "Microsoft Corporation" "c:\windows\system32\mscories.dll"

+ "NetMeeting 3.01" "ADVPACK" "Microsoft Corporation" "c:\windows\system32\advpack.dll"

+ "Outlook Express" "Windows NT User Data Migration Tool" "Microsoft Corporation" "c:\windows\system32\shmgrate.exe"

+ "Themes Setup" "Windows Theme API" "Microsoft Corporation" "c:\windows\system32\themeui.dll"

+ "Windows Desktop Update" "Windows Shell Common Dll" "Microsoft Corporation" "c:\windows\system32\shell32.dll"

+ "Windows Media Player" "Microsoft Windows Media Player Setup Utility" "Microsoft Corporation" "c:\windows\inf\unregmp2.exe"

+ "Windows Messenger 4.7" "ADVPACK" "Microsoft Corporation" "c:\windows\system32\advpack.dll"

"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler" "" "" ""

+ "Browseui preloader" "Shell Browser UI Library" "Microsoft Corporation" "c:\windows\system32\browseui.dll"

+ "Component Categories cache daemon" "Shell Browser UI Library" "Microsoft Corporation" "c:\windows\system32\browseui.dll"

"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad" "" "" ""

+ "CDBurn" "Windows Shell Common Dll" "Microsoft Corporation" "c:\windows\system32\shell32.dll"

+ "PostBootReminder" "Windows Shell Common Dll" "Microsoft Corporation" "c:\windows\system32\shell32.dll"

+ "SysTray" "Systray shell service object" "Microsoft Corporation" "c:\windows\system32\stobject.dll"

+ "WebCheck" "Web Site Monitor" "Microsoft Corporation" "c:\windows\system32\webcheck.dll"

+ "WPDShServiceObj" "Windows Portable Device Shell Service Object" "Microsoft Corporation" "c:\windows\system32\wpdshserviceobj.dll"

"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks" "" "" ""

+ "URL Exec Hook" "Windows Shell Common Dll" "Microsoft Corporation" "c:\windows\system32\shell32.dll"

"HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers" "" "" ""

+ "avast" "avast! Shell Extension" "ALWIL Software" "c:\program files\alwil software\avast4\ashshell.dll"

+ "LavasoftShellExt" "" "" "File not found: C:\Program Files\Lavasoft\Ad-Aware\ShellExt.dll"

+ "Offline Files" "Client Side Caching UI" "Microsoft Corporation" "c:\windows\system32\cscui.dll"

+ "Open With" "Windows Shell Common Dll" "Microsoft Corporation" "c:\windows\system32\shell32.dll"

+ "Open With EncryptionMenu" "Windows Shell Common Dll" "Microsoft Corporation" "c:\windows\system32\shell32.dll"

+ "Start Menu Pin" "Windows Shell Common Dll" "Microsoft Corporation" "c:\windows\system32\shell32.dll"

+ "TuneUp Shredder Shell Extension" "TuneUp Shredder Shellerweiterung" "TuneUp Software GmbH" "c:\program files\tuneup utilities 2007\sdshelex-win32.dll"

+ "WinRAR" "" "" "c:\program files\winrar\rarext.dll"

"HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers" "" "" ""

+ "MBAMShlExt" "Malwarebytes' Anti-Malware" "Malwarebytes Corporation" "c:\program files\malwarebytes' anti-malware\mbamext.dll"

+ "Send To" "Windows Shell Common Dll" "Microsoft Corporation" "c:\windows\system32\shell32.dll"

"HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers" "" "" ""

+ "CMenuExtender" "CMenuExtender" "Revenger inc." "c:\windows\bricopacks\vista inspirat 2\icolorfolder\cmext.dll"

+ "EncryptionMenu" "Windows Shell Common Dll" "Microsoft Corporation" "c:\windows\system32\shell32.dll"

+ "Offline Files" "Client Side Caching UI" "Microsoft Corporation" "c:\windows\system32\cscui.dll"

+ "Sharing" "Shell extensions for sharing" "Microsoft Corporation" "c:\windows\system32\ntshrui.dll"

+ "TuneUp Shredder Shell Extension" "TuneUp Shredder Shellerweiterung" "TuneUp Software GmbH" "c:\program files\tuneup utilities 2007\sdshelex-win32.dll"

+ "WinRAR" "" "" "c:\program files\winrar\rarext.dll"

"HKLM\Software\Classes\Directory\Shellex\DragDropHandlers" "" "" ""

+ "WinRAR" "" "" "c:\program files\winrar\rarext.dll"

"HKLM\Software\Classes\Directory\Shellex\PropertySheetHandlers" "" "" ""

+ "DfsShell Class" "Distributed File System shell extension" "Microsoft Corporation" "c:\windows\system32\dfsshlex.dll"

+ "Folder Customization Tab" "Windows Shell Common Dll" "Microsoft Corporation" "c:\windows\system32\shell32.dll"

+ "Previous Versions Property Page" "Previous Versions property page" "Microsoft Corporation" "c:\windows\system32\twext.dll"

+ "Security Shell Extension" "Security Shell Extension" "Microsoft Corporation" "c:\windows\system32\rshx32.dll"

+ "Sharing" "Shell extensions for sharing" "Microsoft Corporation" "c:\windows\system32\ntshrui.dll"

"HKLM\Software\Classes\Directory\Shellex\CopyHookHandlers" "" "" ""

+ "CDF" "Shell Doc Object and Control Library" "Microsoft Corporation" "c:\windows\system32\shdocvw.dll"

+ "FileSystem" "Windows Shell Common Dll" "Microsoft Corporation" "c:\windows\system32\shell32.dll"

+ "MyDocuments" "My Documents Folder UI" "Microsoft Corporation" "c:\windows\system32\mydocs.dll"

+ "Nokia" "Phone Browser" "Nokia" "c:\program files\nokia\nokia pc suite 7\phonebrowser.dll"

+ "Sharing" "Shell extensions for sharing" "Microsoft Corporation" "c:\windows\system32\ntshrui.dll"

"HKLM\Software\Classes\Folder\Shellex\ColumnHandlers" "" "" ""

+ "PDF Shell Extension" "PDF Shell Extension" "Adobe Systems, Inc." "c:\program files\common files\adobe\acrobat\activex\pdfshell.dll"

+ "{0D2E74C4-3C34-11d2-A27E-00C04FC30871}" "Windows Shell Common Dll" "Microsoft Corporation" "c:\windows\system32\shell32.dll"

+ "{24F14F01-7B1C-11d1-838f-0000F80461CF}" "Windows Shell Common Dll" "Microsoft Corporation" "c:\windows\system32\shell32.dll"

+ "{24F14F02-7B1C-11d1-838f-0000F80461CF}" "Windows Shell Common Dll" "Microsoft Corporation" "c:\windows\system32\shell32.dll"

+ "{66742402-F9B9-11D1-A202-0000F81FEDEE}" "Windows Shell Common Dll" "Microsoft Corporation" "c:\windows\system32\shell32.dll"

"HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers" "" "" ""

+ "avast" "avast! Shell Extension" "ALWIL Software" "c:\program files\alwil software\avast4\ashshell.dll"

+ "FineReader8" "Windows Explorer context menu handler" "ABBYY Software" "c:\program files\abbyy finereader 8.0 professional edition\fecmenu.dll"

+ "LavasoftShellExt" "" "" "File not found: C:\Program Files\Lavasoft\Ad-Aware\ShellExt.dll"

+ "MBAMShlExt" "Malwarebytes' Anti-Malware" "Malwarebytes Corporation" "c:\program files\malwarebytes' anti-malware\mbamext.dll"

+ "WinRAR" "" "" "c:\program files\winrar\rarext.dll"

"HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers" "" "" ""

+ "New" "Windows Shell Common Dll" "Microsoft Corporation" "c:\windows\system32\shell32.dll"

"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers" "" "" ""

+ "Offline Files" "Client Side Caching UI" "Microsoft Corporation" "c:\windows\system32\cscui.dll"

"HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" "" "" ""

+ "%DESC_PublishDropTarget%" "Photo Printing Wizard" "Microsoft Corporation" "c:\windows\system32\photowiz.dll"

+ "&Address" "Shell Browser UI Library" "Microsoft Corporation" "c:\windows\system32\browseui.dll"

+ "&Links" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ ".CAB file viewer" "Cabinet File Viewer Shell Extension" "Microsoft Corporation" "c:\windows\system32\cabview.dll"

+ "Accessible" "Shell Browser UI Library" "Microsoft Corporation" "c:\windows\system32\browseui.dll"

+ "ActiveX Cache Folder" "Object Control Viewer" "Microsoft Corporation" "c:\windows\system32\occache.dll"

+ "Address EditBox" "Shell Browser UI Library" "Microsoft Corporation" "c:\windows\system32\browseui.dll"

+ "Administrative Tools" "Shell Doc Object and Control Library" "Microsoft Corporation" "c:\windows\system32\shdocvw.dll"

+ "Audio Media Properties Handler" "Media File Property Extractor Shell Extension" "Microsoft Corporation" "c:\windows\system32\shmedia.dll"

+ "Augmented Shell Folder" "Shell Browser UI Library" "Microsoft Corporation" "c:\windows\system32\browseui.dll"

+ "Augmented Shell Folder 2" "Shell Browser UI Library" "Microsoft Corporation" "c:\windows\system32\browseui.dll"

+ "Auto Update Property Sheet Extension" "Automatic Updates Control Panel" "Microsoft Corporation" "c:\windows\system32\wuaucpl.cpl"

+ "avast" "avast! Shell Extension" "ALWIL Software" "c:\program files\alwil software\avast4\ashshell.dll"

+ "Avi Properties Handler" "Media File Property Extractor Shell Extension" "Microsoft Corporation" "c:\windows\system32\shmedia.dll"

+ "BandProxy" "Shell Browser UI Library" "Microsoft Corporation" "c:\windows\system32\browseui.dll"

+ "Briefcase" "Windows Briefcase" "Microsoft Corporation" "c:\windows\system32\syncui.dll"

+ "CDF Extension Copy Hook" "Shell Doc Object and Control Library" "Microsoft Corporation" "c:\windows\system32\shdocvw.dll"

+ "CMenuExtender" "CMenuExtender" "Revenger inc." "c:\windows\bricopacks\vista inspirat 2\icolorfolder\cmext.dll"

+ "Code Download Agent" "Web Site Monitor" "Microsoft Corporation" "c:\windows\system32\webcheck.dll"

+ "Compatibility Page" "Compatibility Tab Shell Extension DLL" "Microsoft Corporation" "c:\windows\system32\slayerxp.dll"

+ "Compressed (zipped) Folder" "Compressed (zipped) Folders" "Microsoft Corporation" "c:\windows\system32\zipfldr.dll"

+ "Compressed (zipped) Folder Right Drag Handler" "Compressed (zipped) Folders" "Microsoft Corporation" "c:\windows\system32\zipfldr.dll"

+ "Compressed (zipped) Folder SendTo Target" "Compressed (zipped) Folders" "Microsoft Corporation" "c:\windows\system32\zipfldr.dll"

+ "Crypto PKO Extension" "Crypto Shell Extensions" "Microsoft Corporation" "c:\windows\system32\cryptext.dll"

+ "Crypto Sign Extension" "Crypto Shell Extensions" "Microsoft Corporation" "c:\windows\system32\cryptext.dll"

+ "Custom MRU AutoCompleted List" "Shell Browser UI Library" "Microsoft Corporation" "c:\windows\system32\browseui.dll"

+ "Darwin App Publisher" "Shell Application Manager" "Microsoft Corporation" "c:\windows\system32\appwiz.cpl"

+ "DfsShell" "Distributed File System shell extension" "Microsoft Corporation" "c:\windows\system32\dfsshlex.dll"

+ "Directory Context Menu Verbs" "Directory Service Common UI" "Microsoft Corporation" "c:\windows\system32\dsuiext.dll"

+ "Directory Object Find" "Directory Service Find" "Microsoft Corporation" "c:\windows\system32\dsquery.dll"

+ "Directory Property UI" "Directory Service Common UI" "Microsoft Corporation" "c:\windows\system32\dsuiext.dll"

+ "Directory Query UI" "Directory Service Find" "Microsoft Corporation" "c:\windows\system32\dsquery.dll"

+ "Directory Start/Search Find" "Directory Service Find" "Microsoft Corporation" "c:\windows\system32\dsquery.dll"

+ "Disk Copy Extension" "Windows DiskCopy" "Microsoft Corporation" "c:\windows\system32\diskcopy.dll"

+ "Disk Quota UI" "Windows Shell Disk Quota UI DLL" "Microsoft Corporation" "c:\windows\system32\dskquoui.dll"

+ "Display Adapter CPL Extension" "Advanced display adapter properties" "Microsoft Corporation" "c:\windows\system32\deskadp.dll"

+ "Display Monitor CPL Extension" "Advanced display monitor properties" "Microsoft Corporation" "c:\windows\system32\deskmon.dll"

+ "Display Panning CPL Extension" "" "" "File not found: deskpan.dll"

+ "Display TroubleShoot CPL Extension" "Advanced display performance properties" "Microsoft Corporation" "c:\windows\system32\deskperf.dll"

+ "Download Status" "Shell Browser UI Library" "Microsoft Corporation" "c:\windows\system32\browseui.dll"

+ "DS Security Page" "Directory Service Security UI" "Microsoft Corporation" "c:\windows\system32\dssec.dll"

+ "E-mail" "Shell Doc Object and Control Library" "Microsoft Corporation" "c:\windows\system32\shdocvw.dll"

+ "Explorer Band" "Shell Doc Object and Control Library" "Microsoft Corporation" "c:\windows\system32\shdocvw.dll"

+ "Extensions Manager Folder" "Extensions Manager" "Microsoft Corporation" "c:\windows\system32\extmgr.dll"

+ "Favorites Band" "Shell Doc Object and Control Library" "Microsoft Corporation" "c:\windows\system32\shdocvw.dll"

+ "Fonts" "Windows Font Folder" "Microsoft Corporation" "c:\windows\system32\fontext.dll"

+ "Fonts" "Shell Doc Object and Control Library" "Microsoft Corporation" "c:\windows\system32\shdocvw.dll"

+ "For &People..." "Find People" "Microsoft Corporation" "c:\program files\outlook express\wabfind.dll"

+ "FTP Folders Webview" "Microsoft Internet Explorer FTP Folder Shell Extension" "Microsoft Corporation" "c:\windows\system32\msieftp.dll"

+ "GDI+ file thumbnail extractor" "Windows Picture and Fax Viewer" "Microsoft Corporation" "c:\windows\system32\shimgvw.dll"

+ "Get a Passport Wizard" "Map Network Drives/Network Places Wizard" "Microsoft Corporation" "c:\windows\system32\netplwiz.dll"

+ "Global Folder Settings" "Shell Browser UI Library" "Microsoft Corporation" "c:\windows\system32\browseui.dll"

+ "Help and Support" "Shell Doc Object and Control Library" "Microsoft Corporation" "c:\windows\system32\shdocvw.dll"

+ "Help and Support" "Shell Doc Object and Control Library" "Microsoft Corporation" "c:\windows\system32\shdocvw.dll"

+ "History" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "History Band" "Shell Doc Object and Control Library" "Microsoft Corporation" "c:\windows\system32\shdocvw.dll"

+ "HTML Thumbnail Extractor" "Windows Picture and Fax Viewer" "Microsoft Corporation" "c:\windows\system32\shimgvw.dll"

+ "HyperTerminal Icon Ext" "HyperTerminal Applet Library" "Hilgraeve, Inc." "c:\windows\system32\hticons.dll"

+ "ICC Profile" "Microsoft Color Matching System User Interface DLL" "Microsoft Corporation" "c:\windows\system32\icmui.dll"

+ "ICM Monitor Management" "Microsoft Color Matching System User Interface DLL" "Microsoft Corporation" "c:\windows\system32\icmui.dll"

+ "ICM Printer Management" "Microsoft Color Matching System User Interface DLL" "Microsoft Corporation" "c:\windows\system32\icmui.dll"

+ "ICM Scanner Management" "Microsoft Color Matching System User Interface DLL" "Microsoft Corporation" "c:\windows\system32\icmui.dll"

+ "IE AutoComplete" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "IE BandProxy" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "IE Custom MRU AutoCompleted List" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "IE Fade Task" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "IE IShellFolderBand" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "IE Menu Band" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "IE Menu Desk Bar" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "IE Menu Site" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "IE Microsoft BrowserBand" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "IE Microsoft History AutoComplete List" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "IE Microsoft Multiple AutoComplete List Container" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "IE Microsoft Shell Folder AutoComplete List" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "IE MRU AutoComplete List" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "IE Navigation Bar" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "IE Registry Tree Options Utility" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "IE RSS Feeder Folder" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "IE Search Band" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "IE Shell Band Site Menu" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "IE Shell Rebar BandSite" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "IE Tracking Shell Menu" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "IE User Assist" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "IE4 Suite Splash Screen" "Shell Doc Object and Control Library" "Microsoft Corporation" "c:\windows\system32\shdocvw.dll"

+ "In-pane search" "Shell Browser UI Library" "Microsoft Corporation" "c:\windows\system32\browseui.dll"

+ "Installed Apps Enumerator" "Shell Application Manager" "Microsoft Corporation" "c:\windows\system32\appwiz.cpl"

+ "Internet" "Shell Doc Object and Control Library" "Microsoft Corporation" "c:\windows\system32\shdocvw.dll"

+ "Internet Name Space" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "InternetShortcut" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "ISFBand OC" "Shell Doc Object and Control Library" "Microsoft Corporation" "c:\windows\system32\shdocvw.dll"

+ "Microsoft Agent Character Property Sheet Handler" "Microsoft Agent Property Sheet Handler" "Microsoft Corporation" "c:\windows\msagent\agentpsh.dll"

+ "Microsoft Browser Architecture" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "Microsoft Browser Architecture" "Shell Doc Object and Control Library" "Microsoft Corporation" "c:\windows\system32\shdocvw.dll"

+ "Microsoft BrowserBand" "Shell Browser UI Library" "Microsoft Corporation" "c:\windows\system32\browseui.dll"

+ "Microsoft Data Link" "Microsoft Data Access - OLE DB Core Services" "Microsoft Corporation" "c:\program files\common files\system\ole db\oledb32.dll"

+ "Microsoft DocProp Inplace Calendar Control" "Microsoft DocProp Shell Ext" "Microsoft Corporation" "c:\windows\system32\docprop2.dll"

+ "Microsoft DocProp Inplace Droplist Combo Control" "Microsoft DocProp Shell Ext" "Microsoft Corporation" "c:\windows\system32\docprop2.dll"

+ "Microsoft DocProp Inplace Edit Box Control" "Microsoft DocProp Shell Ext" "Microsoft Corporation" "c:\windows\system32\docprop2.dll"

+ "Microsoft DocProp Inplace ML Edit Box Control" "Microsoft DocProp Shell Ext" "Microsoft Corporation" "c:\windows\system32\docprop2.dll"

+ "Microsoft DocProp Inplace Time Control" "Microsoft DocProp Shell Ext" "Microsoft Corporation" "c:\windows\system32\docprop2.dll"

+ "Microsoft DocProp Shell Ext" "Microsoft DocProp Shell Ext" "Microsoft Corporation" "c:\windows\system32\docprop2.dll"

+ "Microsoft History AutoComplete List" "Shell Browser UI Library" "Microsoft Corporation" "c:\windows\system32\browseui.dll"

+ "Microsoft Internet Toolbar" "Shell Browser UI Library" "Microsoft Corporation" "c:\windows\system32\browseui.dll"

+ "Microsoft Multiple AutoComplete List Container" "Shell Browser UI Library" "Microsoft Corporation" "c:\windows\system32\browseui.dll"

+ "Microsoft Office HTML Icon Handler" "Microsoft Office 2003 component" "Microsoft Corporation" "c:\program files\microsoft office\office11\msohev.dll"

+ "Microsoft Office Metadata Handler" "Microsoft Office Shell Extension Handlers" "Microsoft Corporation" "c:\program files\common files\microsoft shared\office12\msoshext.dll"

+ "Microsoft Office Outlook Custom Icon Handler" "Outlook Shell Hook for Start/Find" "Microsoft Corporation" "c:\program files\microsoft office\office11\olkfstub.dll"

+ "Microsoft Office Outlook Desktop Icon Handler" "Microsoft Shell Extension Library" "Microsoft Corporation" "c:\program files\microsoft office\office11\mlshext.dll"

+ "Microsoft Office Thumbnail Handler" "Microsoft Office Shell Extension Handlers" "Microsoft Corporation" "c:\program files\common files\microsoft shared\office12\msoshext.dll"

+ "Microsoft Shell Folder AutoComplete List" "Shell Browser UI Library" "Microsoft Corporation" "c:\windows\system32\browseui.dll"

+ "Microsoft Url History Service" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "Microsoft Url Search Hook" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "Microsoft.XPS.Shell.Metadata.1" "Package Document Shell Extension Handler" "Microsoft Corporation" "c:\windows\system32\xpsshhdr.dll"

+ "Microsoft.XPS.Shell.Thumbnail.1" "Package Document Shell Extension Handler" "Microsoft Corporation" "c:\windows\system32\xpsshhdr.dll"

+ "Midi Properties Handler" "Media File Property Extractor Shell Extension" "Microsoft Corporation" "c:\windows\system32\shmedia.dll"

+ "MMC Icon Handler" "MMC Shell Extension DLL" "Microsoft Corporation" "c:\windows\system32\mmcshext.dll"

+ "MRU AutoComplete List" "Shell Browser UI Library" "Microsoft Corporation" "c:\windows\system32\browseui.dll"

+ "Multimedia File Property Sheet" "Control Panel Drivers Applet" "Microsoft Corporation" "c:\windows\system32\mmsys.cpl"

+ "MyDocs Copy Hook" "My Documents Folder UI" "Microsoft Corporation" "c:\windows\system32\mydocs.dll"

+ "MyDocs Drop Target" "My Documents Folder UI" "Microsoft Corporation" "c:\windows\system32\mydocs.dll"

+ "MyDocs Properties" "My Documents Folder UI" "Microsoft Corporation" "c:\windows\system32\mydocs.dll"

+ "Network Connections" "Network Connections Shell" "Microsoft Corporation" "c:\windows\system32\netshell.dll"

+ "Network Connections" "Network Connections Shell" "Microsoft Corporation" "c:\windows\system32\netshell.dll"

+ "Nokia Phone Browser" "Phone Browser" "Nokia" "c:\program files\nokia\nokia pc suite 7\phonebrowser.dll"

+ "NTFS Security Page" "Security Shell Extension" "Microsoft Corporation" "c:\windows\system32\rshx32.dll"

+ "Offline Files Folder" "Client Side Caching UI" "Microsoft Corporation" "c:\windows\system32\cscui.dll"

+ "Offline Files Folder Options" "Client Side Caching UI" "Microsoft Corporation" "c:\windows\system32\cscui.dll"

+ "Offline Files Menu" "Client Side Caching UI" "Microsoft Corporation" "c:\windows\system32\cscui.dll"

+ "OLE Docfile Property Page" "OLE DocFile Property Page" "Microsoft Corporation" "c:\windows\system32\docprop.dll"

+ "PlusPack CPL Extension" "Windows Theme API" "Microsoft Corporation" "c:\windows\system32\themeui.dll"

+ "Portable Devices" "Portable Devices Shell Extension" "Microsoft Corporation" "c:\windows\system32\wpdshext.dll"

+ "Portable Devices Menu" "Portable Devices Shell Extension" "Microsoft Corporation" "c:\windows\system32\wpdshext.dll"

+ "Portable Media Devices" "Portable Media Devices Shell Extension" "Microsoft Corporation" "c:\windows\system32\audiodev.dll"

+ "Previous Versions" "Previous Versions property page" "Microsoft Corporation" "c:\windows\system32\twext.dll"

+ "Previous Versions Property Page" "Previous Versions property page" "Microsoft Corporation" "c:\windows\system32\twext.dll"

+ "Print Ordering via the Web" "Map Network Drives/Network Places Wizard" "Microsoft Corporation" "c:\windows\system32\netplwiz.dll"

+ "Printers Security Page" "Security Shell Extension" "Microsoft Corporation" "c:\windows\system32\rshx32.dll"

+ "Registry Tree Options Utility" "Shell Browser UI Library" "Microsoft Corporation" "c:\windows\system32\browseui.dll"

+ "Remote Sessions CPL Extension" "Remote Sessions CPL Extension" "Microsoft Corporation" "c:\windows\system32\remotepg.dll"

+ "Run..." "Shell Doc Object and Control Library" "Microsoft Corporation" "c:\windows\system32\shdocvw.dll"

+ "Scanners & Cameras" "Imaging Devices Shell Folder UI" "Microsoft Corporation" "c:\windows\system32\wiashext.dll"

+ "Scanners & Cameras" "Imaging Devices Shell Folder UI" "Microsoft Corporation" "c:\windows\system32\wiashext.dll"

+ "Scanners & Cameras" "Imaging Devices Shell Folder UI" "Microsoft Corporation" "c:\windows\system32\wiashext.dll"

+ "Scanners & Cameras" "Imaging Devices Shell Folder UI" "Microsoft Corporation" "c:\windows\system32\wiashext.dll"

+ "Scanners & Cameras" "Imaging Devices Shell Folder UI" "Microsoft Corporation" "c:\windows\system32\wiashext.dll"

+ "Scheduled Tasks" "Task Scheduler interface DLL" "Microsoft Corporation" "c:\windows\system32\mstask.dll"

+ "Search" "Shell Doc Object and Control Library" "Microsoft Corporation" "c:\windows\system32\shdocvw.dll"

+ "Search Assistant OC" "Shell Doc Object and Control Library" "Microsoft Corporation" "c:\windows\system32\shdocvw.dll"

+ "Sendmail service" "Send Mail" "Microsoft Corporation" "c:\windows\system32\sendmail.dll"

+ "Sendmail service" "Send Mail" "Microsoft Corporation" "c:\windows\system32\sendmail.dll"

+ "Set Program Access and Defaults" "Shell Doc Object and Control Library" "Microsoft Corporation" "c:\windows\system32\shdocvw.dll"

+ "Shell Application Manager" "Shell Application Manager" "Microsoft Corporation" "c:\windows\system32\appwiz.cpl"

+ "Shell Automation Inproc Service" "Shell Doc Object and Control Library" "Microsoft Corporation" "c:\windows\system32\shdocvw.dll"

+ "Shell Band Site Menu" "Shell Browser UI Library" "Microsoft Corporation" "c:\windows\system32\browseui.dll"

+ "Shell DeskBar" "Shell Browser UI Library" "Microsoft Corporation" "c:\windows\system32\browseui.dll"

+ "Shell DeskBarApp" "Shell Browser UI Library" "Microsoft Corporation" "c:\windows\system32\browseui.dll"

+ "Shell DocObject Viewer" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "Shell extensions for Microsoft Windows Network objects" "Network object shell UI" "Microsoft Corporation" "c:\windows\system32\ntlanui2.dll"

+ "Shell extensions for sharing" "Shell extensions for sharing" "Microsoft Corporation" "c:\windows\system32\ntshrui.dll"

+ "Shell extensions for sharing" "Shell extensions for sharing" "Microsoft Corporation" "c:\windows\system32\ntshrui.dll"

+ "Shell extensions for Windows Script Host" "Microsoft ® Shell Extension for Windows Script Host" "Microsoft Corporation" "c:\windows\system32\wshext.dll"

+ "Shell Icon Handler for Application References" "Application Deployment Support Library" "Microsoft Corporation" "c:\windows\system32\dfshim.dll"

+ "Shell Image Data Factory" "Windows Picture and Fax Viewer" "Microsoft Corporation" "c:\windows\system32\shimgvw.dll"

+ "Shell Image Property Handler" "Windows Picture and Fax Viewer" "Microsoft Corporation" "c:\windows\system32\shimgvw.dll"

+ "Shell Image Verbs" "Windows Picture and Fax Viewer" "Microsoft Corporation" "c:\windows\system32\shimgvw.dll"

+ "Shell Microsoft AutoComplete" "Shell Browser UI Library" "Microsoft Corporation" "c:\windows\system32\browseui.dll"

+ "Shell properties for a DS object" "Directory Service Find" "Microsoft Corporation" "c:\windows\system32\dsquery.dll"

+ "Shell Publishing Wizard Object" "Map Network Drives/Network Places Wizard" "Microsoft Corporation" "c:\windows\system32\netplwiz.dll"

+ "Shell Rebar BandSite" "Shell Browser UI Library" "Microsoft Corporation" "c:\windows\system32\browseui.dll"

+ "Shell Scrap DataHandler" "Shell scrap object handler" "Microsoft Corporation" "c:\windows\system32\shscrap.dll"

+ "Shell Search Band" "Shell Browser UI Library" "Microsoft Corporation" "c:\windows\system32\browseui.dll"

+ "ShellLink for Application References" "Application Deployment Support Library" "Microsoft Corporation" "c:\windows\system32\dfshim.dll"

+ "Subscription Folder" "Web Site Monitor" "Microsoft Corporation" "c:\windows\system32\webcheck.dll"

+ "Subscription Mgr" "Web Site Monitor" "Microsoft Corporation" "c:\windows\system32\webcheck.dll"

+ "Summary Info Thumbnail handler (DOCFILES)" "Windows Picture and Fax Viewer" "Microsoft Corporation" "c:\windows\system32\shimgvw.dll"

+ "Taskbar and Start Menu" "Windows Shell Common Dll" "Microsoft Corporation" "c:\windows\system32\shell32.dll"

+ "Tasks Folder Icon Handler" "Task Scheduler interface DLL" "Microsoft Corporation" "c:\windows\system32\mstask.dll"

+ "Tasks Folder Shell Extension" "Task Scheduler interface DLL" "Microsoft Corporation" "c:\windows\system32\mstask.dll"

+ "Temporary Internet Files" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "Temporary Internet Files" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "The Internet" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

+ "Track Popup Bar" "Shell Browser UI Library" "Microsoft Corporation" "c:\windows\system32\browseui.dll"

+ "TridentImageExtractor" "Shell Browser UI Library" "Microsoft Corporation" "c:\windows\system32\browseui.dll"

+ "TuneUp Shredder Shell Extension" "TuneUp Shredder Shellerweiterung" "TuneUp Software GmbH" "c:\program files\tuneup utilities 2007\sdshelex-win32.dll"

+ "TuneUp Theme Extension" "TuneUp Designerweiterung" "TuneUp Software GmbH" "c:\windows\system32\uxtuneup.dll"

+ "User Accounts" "Map Network Drives/Network Places Wizard" "Microsoft Corporation" "c:\windows\system32\netplwiz.dll"

+ "User Assist" "Shell Browser UI Library" "Microsoft Corporation" "c:\windows\system32\browseui.dll"

+ "Video Media Properties Handler" "Media File Property Extractor Shell Extension" "Microsoft Corporation" "c:\windows\system32\shmedia.dll"

+ "Video Thumbnail Extractor" "Media File Property Extractor Shell Extension" "Microsoft Corporation" "c:\windows\system32\shmedia.dll"

+ "Wav Properties Handler" "Media File Property Extractor Shell Extension" "Microsoft Corporation" "c:\windows\system32\shmedia.dll"

+ "Web Folders" "Microsoft Web Folders" "Microsoft Corporation" "c:\program files\common files\microsoft shared\web folders\msonsext.dll"

+ "Web Printer Shell Extension" "Print UI DLL" "Microsoft Corporation" "c:\windows\system32\printui.dll"

+ "Web Publishing Wizard" "Map Network Drives/Network Places Wizard" "Microsoft Corporation" "c:\windows\system32\netplwiz.dll"

+ "Web Search" "Shell Browser UI Library" "Microsoft Corporation" "c:\windows\system32\browseui.dll"

+ "WebCheck" "Web Site Monitor" "Microsoft Corporation" "c:\windows\system32\webcheck.dll"

+ "WebCheck SyncMgr Handler" "Web Site Monitor" "Microsoft Corporation" "c:\windows\system32\webcheck.dll"

+ "WebCheckWebCrawler" "Web Site Monitor" "Microsoft Corporation" "c:\windows\system32\webcheck.dll"

+ "Windows Media Player Add to Playlist Context Menu Handler" "Windows Media Player Launcher" "Microsoft Corporation" "c:\windows\system32\wmpshell.dll"

+ "Windows Media Player Burn Audio CD Context Menu Handler" "Windows Media Player Launcher" "Microsoft Corporation" "c:\windows\system32\wmpshell.dll"

+ "Windows Media Player Play as Playlist Context Menu Handler" "Windows Media Player Launcher" "Microsoft Corporation" "c:\windows\system32\wmpshell.dll"

+ "WinRAR shell extension" "" "" "c:\program files\winrar\rarext.dll"

"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" "" "" ""

+ "Adobe PDF Reader Link Helper" "" "" "File not found: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll"

+ "FGCatchUrl" "Flashget CatchUrl Module" "www.flashget.com" "c:\program files\flashget\jccatch.dll"

+ "FlashGet GetFlash Class" "Flashget GetFlash Module" "www.flashget.com" "c:\program files\flashget\getflash.dll"

+ "SSVHelper Class" "Java Platform SE binary" "Sun Microsystems, Inc." "c:\program files\java\jre1.6.0_01\bin\ssv.dll"

"HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks" "" "" ""

+ "Microsoft Url Search Hook" "Internet Explorer" "Microsoft Corporation" "c:\windows\system32\ieframe.dll"

"HKLM\Software\Microsoft\Internet Explorer\Extensions" "" "" ""

+ "Diagnose Connection Problems..." "Network Diagnostic for Windows XP" "Microsoft Corporation" "c:\windows\network diagnostic\xpnetdiag.exe"

+ "FlashGet" "FlashGet" "FlashGet.com" "c:\program files\flashget\flashget.exe"

+ "Windows Messenger" "Windows Messenger" "Microsoft Corporation" "c:\program files\messenger\msmsgs.exe"

"Task Scheduler" "" "" ""

+ "1-Click Maintenance.job" "TuneUp System Optimizer" "TuneUp Software GmbH" "c:\program files\tuneup utilities 2007\systemoptimizer.exe"

+ "Ad-Aware Update (Weekly).job" "" "" "File not found: C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe update all silent"

+ "User_Feed_Synchronization-{132E3A99-374B-420F-B7FE-679B47B2FD89}.job" "Microsoft Feeds Synchronization" "Microsoft Corporation" "c:\windows\system32\msfeedssync.exe"

+ "WGASetup.job" "Windows Genuine Advantage Notifications Setup" "Microsoft Corporation" "c:\windows\system32\kb905474\wgasetup.exe"

"HKLM\System\CurrentControlSet\Services" "" "" ""

+ "ALG" "Provides support for 3rd party protocol plug-ins for Internet Connection Sharing and the Windows Firewall." "Microsoft Corporation" "c:\windows\system32\alg.exe"

+ "AppMgmt" "Provides software installation services such as Assign, Publish, and Remove." "Microsoft Corporation" "c:\windows\system32\appmgmts.dll"

+ "aspnet_state" "Provides support for out-of-process session states for ASP.NET. If this service is stopped, out-of-process requests will not be processed. If this service is disabled, any services that explicitly depend on it will fail to start." "Microsoft Corporation" "c:\windows\microsoft.net\framework\v2.0.50727\aspnet_state.exe"

+ "aswUpdSv" "Осигурява авотматични обновявания на компонентите на avast!." "ALWIL Software" "c:\program files\alwil software\avast4\aswupdsv.exe"

+ "Ati HotKey Poller" "ATI External Event Utility EXE Module" "ATI Technologies Inc." "c:\windows\system32\ati2evxx.exe"

+ "ATI Smart" "ATI Smart" "" "c:\windows\system32\ati2sgag.exe"

+ "AudioSrv" "Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start." "Microsoft Corporation" "c:\windows\system32\audiosrv.dll"

+ "avast! Antivirus" "Управлява и изпълнява антивирусните услуги на avast! на този компютър. Това включва резидентна защита, клетката за вируси и планировчика." "ALWIL Software" "c:\program files\alwil software\avast4\ashserv.exe"

+ "avast! Mail Scanner" "Изпълнява проверка на ел.поща за avast! ." "ALWIL Software" "c:\program files\alwil software\avast4\ashmaisv.exe"

+ "avast! Web Scanner" "Изпълнява интернет (HTTP) сканиране за avast!." "ALWIL Software" "c:\program files\alwil software\avast4\ashwebsv.exe"

+ "BITS" "Transfers files in the background using idle network bandwidth. If the service is stopped, features such as Windows Update, and MSN Explorer will be unable to automatically download programs and other information. If this service is disabled, any services that explicitly depend on it may fail to transfer files if they do not have a fail safe mechanism to transfer files directly through IE in case BITS has been disabled." "Microsoft Corporation" "c:\windows\system32\qmgr.dll"

+ "Browser" "Maintains an updated list of computers on the network and supplies this list to computers designated as browsers. If this service is stopped, this list will not be updated or maintained. If this service is disabled, any services that explicitly depend on it will fail to start." "Microsoft Corporation" "c:\windows\system32\browser.dll"

+ "CiSvc" "Indexes contents and properties of files on local and remote computers; provides rapid access to files through flexible querying language." "Microsoft Corporation" "c:\windows\system32\cisvc.exe"

+ "ClipSrv" "Enables ClipBook Viewer to store information and share it with remote computers. If the service is stopped, ClipBook Viewer will not be able to share information with remote computers. If this service is disabled, any services that explicitly depend on it will fail to start." "Microsoft Corporation" "c:\windows\system32\clipsrv.exe"

+ "clr_optimization_v2.0.50727_32" "Microsoft .NET Framework NGEN" "Microsoft Corporation" "c:\windows\microsoft.net\framework\v2.0.50727\mscorsvw.exe"

+ "COMSysApp" "Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start." "Microsoft Corporation" "c:\windows\system32\dllhost.exe"

+ "CryptSvc" "Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Key Service, which helps enroll this computer for certificates. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start." "Microsoft Corporation" "c:\windows\system32\cryptsvc.dll"

+ "DcomLaunch" "Provides launch functionality for DCOM services." "Microsoft Corporation" "c:\windows\system32\rpcss.dll"

+ "Dhcp" "Manages network configuration by registering and updating IP addresses and DNS names." "Microsoft Corporation" "c:\windows\system32\dhcpcsvc.dll"

+ "dmadmin" "Configures hard disk drives and volumes. The service only runs for configuration processes and then stops." "Microsoft Corp., Veritas Software" "c:\windows\system32\dmadmin.exe"

+ "dmserver" "Detects and monitors new hard disk drives and sends disk volume information to Logical Disk Manager Administrative Service for configuration. If this service is stopped, dynamic disk status and configuration information may become out of date. If this service is disabled, any services that explicitly depend on it will fail to start." "" "File not found: C:\WINDOWS\System32\dmserver.dll"

+ "Dot3svc" "This service performs IEEE 802.1X authentication on Ethernet interfaces" "Microsoft Corporation" "c:\windows\system32\dot3svc.dll"

+ "EapHost" "Provides windows clients Extensible Authentication Protocol Service" "Microsoft Corporation" "c:\windows\system32\eapsvc.dll"

+ "ERSvc" "Allows error reporting for services and applictions running in non-standard environments." "Microsoft Corporation" "c:\windows\system32\ersvc.dll"

+ "Eventlog" "Enables event log messages issued by Windows-based programs and components to be viewed in Event Viewer. This service cannot be stopped." "Microsoft Corporation" "c:\windows\system32\services.exe"

+ "EventSystem" "Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start." "Microsoft Corporation" "c:\windows\system32\es.dll"

+ "FastUserSwitchingCompatibility" "Provides management for applications that require assistance in a multiple user environment." "Microsoft Corporation" "c:\windows\system32\shsvcs.dll"

+ "FontCache3.0.0.0" "Optimizes performance of Windows Presentation Foundation (WPF) applications by caching commonly used font data. WPF applications will start this service if it is not already running. It can be disabled, though doing so will degrade the performance of WPF applications." "Microsoft Corporation" "c:\windows\microsoft.net\framework\v3.0\wpf\presentationfontcache.exe"

+ "helpsvc" "Enables Help and Support Center to run on this computer. If this service is stopped, Help and Support Center will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "Microsoft Corporation" "c:\windows\pchealth\helpctr\binaries\pchsvc.dll"

+ "HidServ" "Enables generic input access to Human Interface Devices (HID), which activates and maintains the use of predefined hot buttons on keyboards, remote controls, and other multimedia devices. If this service is stopped, hot buttons controlled by this service will no longer function. If this service is disabled, any services that explicitly depend on it will fail to start." "Microsoft Corporation" "c:\windows\system32\hidserv.dll"

+ "hkmsvc" "Manages health certificates and keys (used by NAP)" "Microsoft Corporation" "c:\windows\system32\kmsvc.dll"

+ "HTTPFilter" "This service implements the secure hypertext transfer protocol (HTTPS) for the HTTP service, using the Secure Socket Layer (SSL). If this service is disabled, any services that explicitly depend on it will fail to start." "Microsoft Corporation" "c:\windows\system32\w3ssl.dll"

+ "IDriverT" "Provides support for the Running Object Table for InstallShield Drivers" "Macrovision Corporation" "c:\program files\common files\installshield\driver\1150\intel 32\idrivert.exe"

+ "ImapiService" "Manages CD recording using Image Mastering Applications Programming Interface (IMAPI). If this service is stopped, this computer will be unable to record CDs. If this service is disabled, any services that explicitly depend on it will fail to start." "Microsoft Corporation" "c:\windows\system32\imapi.exe"

+ "lanmanserver" "Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "Microsoft Corporation" "c:\windows\system32\srvsvc.dll"

+ "lanmanworkstation" "Creates and maintains client network connections to remote servers. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "Microsoft Corporation" "c:\windows\system32\wkssvc.dll"

+ "LmHosts" "Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution." "Microsoft Corporation" "c:\windows\system32\lmhsvc.dll"

+ "MDM" "Supports local and remote debugging for Visual Studio and script debuggers. If this service is stopped, the debuggers will not function properly." "Microsoft Corporation" "c:\program files\common files\microsoft shared\vs7debug\mdm.exe"

+ "mnmsrvc" "Enables an authorized user to access this computer remotely by using NetMeeting over a corporate intranet. If this service is stopped, remote desktop sharing will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "Microsoft Corporation" "c:\windows\system32\mnmsrvc.exe"

+ "MSDTC" "Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will not occur. If this service is disabled, any services that explicitly depend on it will fail to start. " "Microsoft Corporation" "c:\windows\system32\msdtc.exe"

+ "MSIServer" "Adds, modifies, and removes applications provided as a Windows Installer (*.msi) package. If this service is disabled, any services that explicitly depend on it will fail to start." "Microsoft Corporation" "c:\windows\system32\msiexec.exe"

+ "napagent" "Allows windows clients to participate in Network Access Protection" "Microsoft Corporation" "c:\windows\system32\qagentrt.dll"

+ "Netlogon" "Supports pass-through authentication of account logon events for computers in a domain." "Microsoft Corporation" "c:\windows\system32\lsass.exe"

+ "Netman" "Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections." "Microsoft Corporation" "c:\windows\system32\netman.dll"

+ "Nla" "Collects and stores network configuration and location information, and notifies applications when this information changes." "Microsoft Corporation" "c:\windows\system32\mswsock.dll"

+ "NtLmSsp" "Provides security to remote procedure call (RPC) programs that use transports other than named pipes." "Microsoft Corporation" "c:\windows\system32\lsass.exe"

+ "NtmsSvc" "Removable Storage Manager" "Microsoft Corporation" "c:\windows\system32\ntmssvc.dll"

+ "PlugPlay" "Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability." "Microsoft Corporation" "c:\windows\system32\services.exe"

+ "PnkBstrA" "PunkBuster Service Component [v1029] http://www.evenbalance.com" "" "c:\windows\system32\pnkbstra.exe"

+ "PnkBstrB" "PunkBuster Service Component [v2.57 COD2] http://www.evenbalance.com" "" "c:\windows\system32\pnkbstrb.exe"

+ "PolicyAgent" "Manages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver." "Microsoft Corporation" "c:\windows\system32\lsass.exe"

+ "ProtectedStorage" "Provides protected storage for sensitive data, such as private keys, to prevent access by unauthorized services, processes, or users." "Microsoft Corporation" "c:\windows\system32\lsass.exe"

+ "RasAuto" "Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address." "Microsoft Corporation" "c:\windows\system32\rasauto.dll"

+ "RasMan" "Creates a network connection." "Microsoft Corporation" "c:\windows\system32\rasmans.dll"

+ "RDSessMgr" "Manages and controls Remote Assistance. If this service is stopped, Remote Assistance will be unavailable. Before stopping this service, see the Dependencies tab of the Properties dialog box." "Microsoft Corporation" "c:\windows\system32\sessmgr.exe"

+ "RemoteRegistry" "Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start." "Microsoft Corporation" "c:\windows\system32\regsvc.dll"

+ "RpcLocator" "Manages the RPC name service database." "Microsoft Corporation" "c:\windows\system32\locator.exe"

+ "RpcSs" "Provides the endpoint mapper and other miscellaneous RPC services." "Microsoft Corporation" "c:\windows\system32\rpcss.dll"

+ "RSVP" "Provides network signaling and local traffic control setup functionality for QoS-aware programs and control applets." "Microsoft Corporation" "c:\windows\system32\rsvp.exe"

+ "SamSs" "Stores security information for local user accounts." "Microsoft Corporation" "c:\windows\system32\lsass.exe"

+ "SCardSvr" "Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start." "Microsoft Corporation" "c:\windows\system32\scardsvr.exe"

+ "Schedule" "Enables a user to configure and schedule automated tasks on this computer. If this service is stopped, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start." "Microsoft Corporation" "c:\windows\system32\schedsvc.dll"

+ "seclogon" "Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "Microsoft Corporation" "c:\windows\system32\seclogon.dll"

+ "SENS" "Tracks system events such as Windows logon, network, and power events. Notifies COM+ Event System subscribers of these events." "Microsoft Corporation" "c:\windows\system32\sens.dll"

+ "ServiceLayer" "ServiceLayer Module" "Nokia." "c:\program files\pc connectivity solution\servicelayer.exe"

+ "SharedAccess" "Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network." "Microsoft Corporation" "c:\windows\system32\ipnathlp.dll"

+ "ShellHWDetection" "Provides notifications for AutoPlay hardware events." "Microsoft Corporation" "c:\windows\system32\shsvcs.dll"

+ "Spooler" "Loads files to memory for later printing." "Microsoft Corporation" "c:\windows\system32\spoolsv.exe"

+ "srservice" "Performs system restore functions. To stop service, turn off System Restore from the System Restore tab in My Computer->Properties" "Microsoft Corporation" "c:\windows\system32\srsvc.dll"

+ "SSDPSRV" "Enables discovery of UPnP devices on your home network." "Microsoft Corporation" "c:\windows\system32\ssdpsrv.dll"

+ "stisvc" "Provides image acquisition services for scanners and cameras." "Microsoft Corporation" "c:\windows\system32\wiaservc.dll"

+ "SwPrv" "Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start." "Microsoft Corporation" "c:\windows\system32\dllhost.exe"

+ "SysmonLog" "Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start." "Microsoft Corporation" "c:\windows\system32\smlogsvc.exe"

+ "TapiSrv" "Provides Telephony API (TAPI) support for programs that control telephony devices and IP based voice connections on the local computer and, through the LAN, on servers that are also running the service." "Microsoft Corporation" "c:\windows\system32\tapisrv.dll"

+ "TermService" "Allows multiple users to be connected interactively to a machine as well as the display of desktops and applications to remote computers. The underpinning of Remote Desktop (including RD for Administrators), Fast User Switching, Remote Assistance, and Terminal Server." "Microsoft Corporation" "c:\windows\system32\termsrv.dll"

+ "Themes" "Provides user experience theme management." "Microsoft Corporation" "c:\windows\system32\shsvcs.dll"

+ "TrkWks" "Maintains links between NTFS files within a computer or across computers in a network domain." "Microsoft Corporation" "c:\windows\system32\trkwks.dll"

+ "upnphost" "Provides support to host Universal Plug and Play devices." "Microsoft Corporation" "c:\windows\system32\upnphost.dll"

+ "UPS" "Manages an uninterruptible power supply (UPS) connected to the computer." "Microsoft Corporation" "c:\windows\system32\ups.exe"

+ "UxTuneUp" "Allows for the use of designs without a Microsoft Visual Style signature." "TuneUp Software GmbH" "c:\windows\system32\uxtuneup.dll"

+ "VSS" "Manages and implements Volume Shadow Copies used for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start." "Microsoft Corporation" "c:\windows\system32\vssvc.exe"

+ "W32Time" "Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start." "Microsoft Corporation" "c:\windows\system32\w32time.dll"

+ "WebClient" "Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start." "Microsoft Corporation" "c:\windows\system32\webclnt.dll"

+ "winmgmt" "Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start." "Microsoft Corporation" "c:\windows\system32\wbem\wmisvc.dll"

+ "WmdmPmSN" "Retrieves the serial number of any portable media player connected to this computer. If this service is stopped, protected content might not be down loaded to the device." "Microsoft Corporation" "c:\windows\system32\mspmsnsv.dll"

+ "Wmi" "Provides systems management information to and from drivers." "Microsoft Corporation" "c:\windows\system32\advapi32.dll"

+ "WmiApSrv" "Provides performance library information from WMI HiPerf providers." "Microsoft Corporation" "c:\windows\system32\wbem\wmiapsrv.exe"

+ "WMPNetworkSvc" "Shares Windows Media Player libraries to other networked players and media devices using Universal Plug and Play" "Microsoft Corporation" "c:\program files\windows media player\wmpnetwk.exe"

+ "wscsvc" "Monitors system security settings and configurations." "Microsoft Corporation" "c:\windows\system32\wscsvc.dll"

+ "wuauserv" "Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site." "Microsoft Corporation" "c:\windows\system32\wuauserv.dll"

+ "WudfSvc" "Manages user-mode driver host processes" "Microsoft Corporation" "c:\windows\system32\wudfsvc.dll"

+ "WZCSVC" "Provides automatic configuration for the 802.11 adapters" "Microsoft Corporation" "c:\windows\system32\wzcsvc.dll"

+ "xmlprov" "Manages XML configuration files on a domain basis for automatic network provisioning." "Microsoft Corporation" "c:\windows\system32\xmlprov.dll"

"HKLM\System\CurrentControlSet\Services" "" "" ""

+ "Aavmker4" "avast! Base Kernel-Mode Device Driver for Windows NT/2000/XP" "ALWIL Software" "c:\windows\system32\drivers\aavmker4.sys"

+ "ACPI" "ACPI Driver for NT" "Microsoft Corporation" "c:\windows\system32\drivers\acpi.sys"

+ "Ad-Watch Connect Filter" "" "" "File not found: C:\WINDOWS\system32\drivers\NSDriver.sys"

+ "Ad-Watch Real-Time Scanner" "" "" "File not found: C:\WINDOWS\system32\drivers\AWRTPD.sys"

+ "Ad-Watch Registry Filter" "" "" "File not found: C:\WINDOWS\system32\drivers\AWRTRD.sys"

+ "aec" "Microsoft Acoustic Echo Canceller" "Microsoft Corporation" "c:\windows\system32\drivers\aec.sys"

+ "AFD" "AFD Networking Support Environment" "Microsoft Corporation" "c:\windows\system32\drivers\afd.sys"

+ "aswFsBlk" "avast! mini-filter driver (aswFsBlk)" "ALWIL Software" "c:\windows\system32\drivers\aswfsblk.sys"

+ "aswMon2" "avast! File System Filter Driver for Windows XP" "ALWIL Software" "c:\windows\system32\drivers\aswmon2.sys"

+ "aswRdr" "avast! TDI RDR Driver" "ALWIL Software" "c:\windows\system32\drivers\aswrdr.sys"

+ "aswSP" "avast! self protection module" "ALWIL Software" "c:\windows\system32\drivers\aswsp.sys"

+ "aswTdi" "avast! TDI Filter Driver" "ALWIL Software" "c:\windows\system32\drivers\aswtdi.sys"

+ "AsyncMac" "RAS Asynchronous Media Driver" "Microsoft Corporation" "c:\windows\system32\drivers\asyncmac.sys"

+ "atapi" "IDE/ATAPI Port Driver" "Microsoft Corporation" "c:\windows\system32\drivers\atapi.sys"

+ "ati2mtag" "ATI Radeon WindowsNT Miniport Driver" "ATI Technologies Inc." "c:\windows\system32\drivers\ati2mtag.sys"

+ "Atmarpc" "ATM ARP Client Protocol" "Microsoft Corporation" "c:\windows\system32\drivers\atmarpc.sys"

+ "audstub" "AudStub Driver" "Microsoft Corporation" "c:\windows\system32\drivers\audstub.sys"

+ "Beep" "BEEP Driver" "Microsoft Corporation" "c:\windows\system32\drivers\beep.sys"

+ "Cdaudio" "CD-ROM Audio Filter Driver" "Microsoft Corporation" "c:\windows\system32\drivers\cdaudio.sys"

+ "Cdrom" "SCSI CD-ROM Driver" "Microsoft Corporation" "c:\windows\system32\drivers\cdrom.sys"

+ "Changer" "" "" "File not found: C:\WINDOWS\System32\Drivers\Changer.sys"

+ "Disk" "PnP Disk Driver" "Microsoft Corporation" "c:\windows\system32\drivers\disk.sys"

+ "dmio" "NT Disk Manager I/O Driver" "Microsoft Corp., Veritas Software" "c:\windows\system32\drivers\dmio.sys"

+ "dmload" "NT Disk Manager Startup Driver" "Microsoft Corp., Veritas Software." "c:\windows\system32\drivers\dmload.sys"

+ "DMusic" "Microsoft Kernel DLS Synthesizer" "Microsoft Corporation" "c:\windows\system32\drivers\dmusic.sys"

+ "drmkaud" "Microsoft Kernel DRM Audio Descrambler Filter" "Microsoft Corporation" "c:\windows\system32\drivers\drmkaud.sys"

+ "ENTECH" "" "EnTech Taiwan" "c:\windows\system32\drivers\entech.sys"

+ "Fdc" "Floppy Disk Controller Driver" "Microsoft Corporation" "c:\windows\system32\drivers\fdc.sys"

+ "Fips" "FIPS Crypto Driver" "Microsoft Corporation" "c:\windows\system32\drivers\fips.sys"

+ "Flpydisk" "Floppy Driver" "Microsoft Corporation" "c:\windows\system32\drivers\flpydisk.sys"

+ "FltMgr" "File System Filter Manager Driver" "Microsoft Corporation" "c:\windows\system32\drivers\fltmgr.sys"

+ "Ftdisk" "FT Disk Driver" "Microsoft Corporation" "c:\windows\system32\drivers\ftdisk.sys"

+ "GarenaPEngine" "" "" "File not found: C:\DOCUME~1\Dron445\LOCALS~1\Temp\SLN24.tmp"

+ "gdrv" "GIGABYTE Tools" "Windows ® 2000 DDK provider" "c:\windows\gdrv.sys"

+ "Gpc" "Generic Packet Classifier" "Microsoft Corporation" "c:\windows\system32\drivers\msgpc.sys"

+ "hamachi" "Hamachi Virtual Network Interface Driver" "LogMeIn, Inc." "c:\windows\system32\drivers\hamachi.sys"

+ "HdAudAddService" "Ati High Definition Audio Function Driver" "ATI Research Inc." "c:\windows\system32\drivers\atihdaud.sys"

+ "HDAudBus" "High Definition Audio Bus Driver v1.0a" "Windows ® Server 2003 DDK provider" "c:\windows\system32\drivers\hdaudbus.sys"

+ "hidusb" "USB Miniport Driver for Input Devices" "Microsoft Corporation" "c:\windows\system32\drivers\hidusb.sys"

+ "HTTP" "This service implements the hypertext transfer protocol (HTTP). If this service is disabled, any services that explicitly depend on it will fail to start." "Microsoft Corporation" "c:\windows\system32\drivers\http.sys"

+ "i2omgmt" "" "" "File not found: C:\WINDOWS\System32\Drivers\i2omgmt.sys"

+ "i8042prt" "i8042 Port Driver" "Microsoft Corporation" "c:\windows\system32\drivers\i8042prt.sys"

+ "Imapi" "IMAPI Kernel Driver" "Microsoft Corporation" "c:\windows\system32\drivers\imapi.sys"

+ "IntcAzAudAddService" "Realtek® High Definition Audio Function Driver" "Realtek Semiconductor Corp." "c:\windows\system32\drivers\rtkhdaud.sys"

+ "intelppm" "Processor Device Driver" "Microsoft Corporation" "c:\windows\system32\drivers\intelppm.sys"

+ "Ip6Fw" "Provides intrusion prevention service for a home or small office network." "Microsoft Corporation" "c:\windows\system32\drivers\ip6fw.sys"

+ "IpFilterDriver" "IP Traffic Filter Driver" "Microsoft Corporation" "c:\windows\system32\drivers\ipfltdrv.sys"

+ "IpInIp" "IP in IP Tunnel Driver" "Microsoft Corporation" "c:\windows\system32\drivers\ipinip.sys"

+ "IpNat" "IP Network Address Translator" "Microsoft Corporation" "c:\windows\system32\drivers\ipnat.sys"

+ "IPSec" "IPSEC driver" "Microsoft Corporation" "c:\windows\system32\drivers\ipsec.sys"

+ "IRENUM" "Infra-Red Bus Enumerator" "Microsoft Corporation" "c:\windows\system32\drivers\irenum.sys"

+ "isapnp" "PNP ISA Bus Driver" "Microsoft Corporation" "c:\windows\system32\drivers\isapnp.sys"

+ "JGOGO" "SCSI Port upper filter driver" "JMicron " "c:\windows\system32\drivers\jgogo.sys"

+ "JRAID" "JMicron JMB36X RAID Driver" "JMicron Technology Corp." "c:\windows\system32\drivers\jraid.sys"

+ "k750bus" "Sony Ericsson 750 Driver" "MCCI" "c:\windows\system32\drivers\k750bus.sys"

+ "k750mdfl" "Sony Ericsson 750 USB WMC Modem Filter" "MCCI" "c:\windows\system32\drivers\k750mdfl.sys"

+ "k750mdm" "Sony Ericsson 750 USB WMC Modem Drivers" "MCCI" "c:\windows\system32\drivers\k750mdm.sys"

+ "k750mgmt" "Sony Ericsson 750 USB WMC Device Management Drivers" "MCCI" "c:\windows\system32\drivers\k750mgmt.sys"

+ "k750obex" "Sony Ericsson 750 USB WMC OBEX Interface Drivers" "MCCI" "c:\windows\system32\drivers\k750obex.sys"

+ "Kbdclass" "Keyboard Class Driver" "Microsoft Corporation" "c:\windows\system32\drivers\kbdclass.sys"

+ "kbdhid" "HID Mouse Filter Driver" "Microsoft Corporation" "c:\windows\system32\drivers\kbdhid.sys"

+ "kmixer" "Kernel Mode Audio Mixer" "Microsoft Corporation" "c:\windows\system32\drivers\kmixer.sys"

+ "KSecDD" "Kernel Security Support Provider Interface" "Microsoft Corporation" "c:\windows\system32\drivers\ksecdd.sys"

+ "lbrtfdc" "" "" "File not found: C:\WINDOWS\System32\Drivers\lbrtfdc.sys"

+ "mnmdd" "Frame buffer simulator" "Microsoft Corporation" "c:\windows\system32\drivers\mnmdd.sys"

+ "Modem" "Modem Device Driver" "Microsoft Corporation" "c:\windows\system32\drivers\modem.sys"

+ "Mouclass" "Mouse Class Driver" "Microsoft Corporation" "c:\windows\system32\drivers\mouclass.sys"

+ "MountMgr" "Mount Manager" "Microsoft Corporation" "c:\windows\system32\drivers\mountmgr.sys"

+ "MRxDAV" "WebDav Client Redirector" "Microsoft Corporation" "c:\windows\system32\drivers\mrxdav.sys"

+ "MRxSmb" "MRXSMB" "Microsoft Corporation" "c:\windows\system32\drivers\mrxsmb.sys"

+ "Msfs" "Mailslot driver" "Microsoft Corporation" "c:\windows\system32\drivers\msfs.sys"

+ "MSKSSRV" "MS KS Server" "Microsoft Corporation" "c:\windows\system32\drivers\mskssrv.sys"

+ "MSPCLOCK" "MS Proxy Clock" "Microsoft Corporation" "c:\windows\system32\drivers\mspclock.sys"

+ "MSPQM" "MS Proxy Quality Manager" "Microsoft Corporation" "c:\windows\system32\drivers\mspqm.sys"

+ "mssmbios" "System Management BIOS Driver" "Microsoft Corporation" "c:\windows\system32\drivers\mssmbios.sys"

+ "Mup" "Multiple UNC Provider driver" "Microsoft Corporation" "c:\windows\system32\drivers\mup.sys"

+ "NDIS" "NDIS 5.1 wrapper driver" "Microsoft Corporation" "c:\windows\system32\drivers\ndis.sys"

+ "NdisTapi" "Remote Access NDIS TAPI Driver" "Microsoft Corporation" "c:\windows\system32\drivers\ndistapi.sys"

+ "Ndisuio" "NDIS Usermode I/O Protocol" "Microsoft Corporation" "c:\windows\system32\drivers\ndisuio.sys"

+ "NdisWan" "Remote Access NDIS WAN Driver" "Microsoft Corporation" "c:\windows\system32\drivers\ndiswan.sys"

+ "NDProxy" "NDIS Proxy" "Microsoft Corporation" "c:\windows\system32\drivers\ndproxy.sys"

+ "NetBIOS" "NetBIOS Interface" "Microsoft Corporation" "c:\windows\system32\drivers\netbios.sys"

+ "NetBT" "NetBios over Tcpip" "Microsoft Corporation" "c:\windows\system32\drivers\netbt.sys"

+ "nmwcd" "Nokia USB Phone Bus Driver" "Nokia" "c:\windows\system32\drivers\ccdcmb.sys"

+ "nmwcdc" "Nokia USB Phone Bus Driver" "Nokia" "c:\windows\system32\drivers\ccdcmbo.sys"

+ "Npfs" "NPFS Driver" "Microsoft Corporation" "c:\windows\system32\drivers\npfs.sys"

+ "Null" "NULL Driver" "Microsoft Corporation" "c:\windows\system32\drivers\null.sys"

+ "NwlnkFlt" "IPX Traffic Filter Driver" "Microsoft Corporation" "c:\windows\system32\drivers\nwlnkflt.sys"

+ "NwlnkFwd" "IPX Traffic Forwarder Driver" "Microsoft Corporation" "c:\windows\system32\drivers\nwlnkfwd.sys"

+ "Parport" "Parallel Port Driver" "Microsoft Corporation" "c:\windows\system32\drivers\parport.sys"

+ "PartMgr" "Partition Manager" "Microsoft Corporation" "c:\windows\system32\drivers\partmgr.sys"

+ "ParVdm" "VDM Parallel Driver" "Microsoft Corporation" "c:\windows\system32\drivers\parvdm.sys"

+ "pccsmcfd" "PCCS Mode Change Filter Driver" "Nokia" "c:\windows\system32\drivers\pccsmcfd.sys"

+ "PCI" "NT Plug and Play PCI Enumerator" "Microsoft Corporation" "c:\windows\system32\drivers\pci.sys"

+ "PCIDump" "" "" "File not found: C:\WINDOWS\System32\Drivers\PCIDump.sys"

+ "PCIIde" "Generic PCI IDE Bus Driver" "Microsoft Corporation" "c:\windows\system32\drivers\pciide.sys"

+ "PDCOMP" "" "" "File not found: C:\WINDOWS\System32\Drivers\PDCOMP.sys"

+ "PDFRAME" "" "" "File not found: C:\WINDOWS\System32\Drivers\PDFRAME.sys"

+ "PDRELI" "" "" "File not found: C:\WINDOWS\System32\Drivers\PDRELI.sys"

+ "PDRFRAME" "" "" "File not found: C:\WINDOWS\System32\Drivers\PDRFRAME.sys"

+ "PptpMiniport" "WAN Miniport (PPTP)" "Microsoft Corporation" "c:\windows\system32\drivers\raspptp.sys"

+ "PSched" "QoS Packet Scheduler" "Microsoft Corporation" "c:\windows\system32\drivers\psched.sys"

+ "Ptilink" "Direct Parallel Link Driver" "Parallel Technologies, Inc." "c:\windows\system32\drivers\ptilink.sys"

+ "PxHelp20" "Px Engine Device Driver for Windows 2000/XP" "Sonic Solutions" "c:\windows\system32\drivers\pxhelp20.sys"

+ "RasAcd" "Remote Access Auto Connection Driver" "Microsoft Corporation" "c:\windows\system32\drivers\rasacd.sys"

+ "Rasl2tp" "WAN Miniport (L2TP)" "Microsoft Corporation" "c:\windows\system32\drivers\rasl2tp.sys"

+ "RasPppoe" "Remote Access PPPOE Driver" "Microsoft Corporation" "c:\windows\system32\drivers\raspppoe.sys"

+ "Raspti" "Direct Parallel" "Microsoft Corporation" "c:\windows\system32\drivers\raspti.sys"

+ "Rdbss" "Rdbss" "Microsoft Corporation" "c:\windows\system32\drivers\rdbss.sys"

+ "RDPCDD" "RDP Miniport" "Microsoft Corporation" "c:\windows\system32\drivers\rdpcdd.sys"

+ "rdpdr" "Microsoft RDP Device redirector" "Microsoft Corporation" "c:\windows\system32\drivers\rdpdr.sys"

+ "RDPWD" "RDP Terminal Stack Driver (US/Canada Only, Not for Export)" "Microsoft Corporation" "c:\windows\system32\drivers\rdpwd.sys"

+ "redbook" "Redbook Audio Filter Driver" "Microsoft Corporation" "c:\windows\system32\drivers\redbook.sys"

+ "rspndr" "Allows this PC to be discovered and located on the network." "Microsoft Corporation" "c:\windows\system32\drivers\rspndr.sys"

+ "RTLE8023xp" "Realtek 10/100/1000 NDIS 5.1 Driver " "Realtek Semiconductor Corporation " "c:\windows\system32\drivers\rtenicxp.sys"

+ "se45bus" "Sony Ericsson Device 069 Driver" "MCCI" "c:\windows\system32\drivers\se45bus.sys"

+ "se45mdfl" "Sony Ericsson Device 069 USB WMC Modem Filter" "MCCI" "c:\windows\system32\drivers\se45mdfl.sys"

+ "se45mdm" "Sony Ericsson Device 069 USB WMC Modem Driver" "MCCI" "c:\windows\system32\drivers\se45mdm.sys"

+ "se45mgmt" "Sony Ericsson Device 069 USB WMC Device Management Drivers (WDM)" "MCCI" "c:\windows\system32\drivers\se45mgmt.sys"

+ "se45nd5" "Sony Ericsson Device 069 USB Ethernet Emulation (NDIS 5 Miniport)" "MCCI" "c:\windows\system32\drivers\se45nd5.sys"

+ "se45obex" "Sony Ericsson Device 069 USB WMC OBEX Interface" "MCCI" "c:\windows\system32\drivers\se45obex.sys"

+ "se45unic" "Sony Ericsson Device 069 USB Ethernet Emulation" "MCCI" "c:\windows\system32\drivers\se45unic.sys"

+ "Secdrv" "SafeDisc driver" "Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K." "c:\windows\system32\drivers\secdrv.sys"

+ "serenum" "Serial Port Enumerator" "Microsoft Corporation" "c:\windows\system32\drivers\serenum.sys"

+ "Serial" "Serial Device Driver" "Microsoft Corporation" "c:\windows\system32\drivers\serial.sys"

+ "Sfloppy" "SCSI Floppy Driver" "Microsoft Corporation" "c:\windows\system32\drivers\sfloppy.sys"

+ "SONYPVU1" "Sony USB Lower Filter driver" "Sony Corporation" "c:\windows\system32\drivers\sonypvu1.sys"

+ "splitter" "Microsoft Kernel Audio Splitter" "Microsoft Corporation" "c:\windows\system32\drivers\splitter.sys"

+ "sr" "System Restore Filesystem Filter Driver" "Microsoft Corporation" "c:\windows\system32\drivers\sr.sys"

+ "Srv" "Srv" "Microsoft Corporation" "c:\windows\system32\drivers\srv.sys"

+ "ssm_bus" "SAMSUNG Mobile USB Device II 1.0 Driver" "MCCI" "c:\windows\system32\drivers\ssm_bus.sys"

+ "ssm_mdfl" "SAMSUNG Mobile USB Modem II 1.0 Filter" "MCCI" "c:\windows\system32\drivers\ssm_mdfl.sys"

+ "ssm_mdm" "SAMSUNG Mobile USB Modem II 1.0 Drivers" "MCCI" "c:\windows\system32\drivers\ssm_mdm.sys"

+ "swenum" "Plug and Play Software Device Enumerator" "Microsoft Corporation" "c:\windows\system32\drivers\swenum.sys"

+ "swmidi" "Microsoft GS Wavetable Synthesizer" "Microsoft Corporation" "c:\windows\system32\drivers\swmidi.sys"

+ "sysaudio" "System Audio WDM Filter" "Microsoft Corporation" "c:\windows\system32\drivers\sysaudio.sys"

+ "Tcpip" "TCP/IP Protocol Driver" "Microsoft Corporation" "c:\windows\system32\drivers\tcpip.sys"

+ "TDPIPE" "Named Pipe Transport Driver" "Microsoft Corporation" "c:\windows\system32\drivers\tdpipe.sys"

+ "TDTCP" "TCP Transport Driver" "Microsoft Corporation" "c:\windows\system32\drivers\tdtcp.sys"

+ "TermDD" "Terminal Server Driver" "Microsoft Corporation" "c:\windows\system32\drivers\termdd.sys"

+ "Update" "Update Driver" "Microsoft Corporation" "c:\windows\system32\drivers\update.sys"

+ "upperdev" "Filter Driver for Nokia USB Phone Bus Driver" "Nokia" "c:\windows\system32\drivers\usbser_lowerflt.sys"

+ "usbccgp" "USB Common Class Generic Parent Driver" "Microsoft Corporation" "c:\windows\system32\drivers\usbccgp.sys"

+ "usbehci" "EHCI eUSB Miniport Driver" "Microsoft Corporation" "c:\windows\system32\drivers\usbehci.sys"

+ "usbhub" "Default Hub Driver for USB" "Microsoft Corporation" "c:\windows\system32\drivers\usbhub.sys"

+ "usbser" "USB Modem Driver" "Microsoft Corporation" "c:\windows\system32\drivers\usbser.sys"

+ "UsbserFilt" "Filter Driver for Nokia USB Phone Bus Driver" "Nokia" "c:\windows\system32\drivers\usbser_lowerfltj.sys"

+ "USBSTOR" "USB Mass Storage Class Driver" "Microsoft Corporation" "c:\windows\system32\drivers\usbstor.sys"

+ "usbuhci" "UHCI USB Miniport Driver" "Microsoft Corporation" "c:\windows\system32\drivers\usbuhci.sys"

+ "VgaSave" "Controls the VGA display adapter to provide basic display capabilities." "Microsoft Corporation" "c:\windows\system32\drivers\vga.sys"

+ "VolSnap" "Volume Shadow Copy Driver" "Microsoft Corporation" "c:\windows\system32\drivers\volsnap.sys"

+ "Wanarp" "Remote Access IP ARP Driver" "Microsoft Corporation" "c:\windows\system32\drivers\wanarp.sys"

+ "Wdf01000" "WDF Dynamic" "Microsoft Corporation" "c:\windows\system32\drivers\wdf01000.sys"

+ "WDICA" "" "" "File not found: C:\WINDOWS\System32\Drivers\WDICA.sys"

+ "wdmaud" "MMSYSTEM Wave/Midi API mapper" "Microsoft Corporation" "c:\windows\system32\drivers\wdmaud.sys"

+ "WpdUsb" "WPD USB Driver" "Microsoft Corporation" "c:\windows\system32\drivers\wpdusb.sys"

+ "WS2IFSL" "Winsock2 IFS Layer" "Microsoft Corporation" "c:\windows\system32\drivers\ws2ifsl.sys"

+ "WudfPf" "Provide communciation services for UMDF components." "Microsoft Corporation" "c:\windows\system32\drivers\wudfpf.sys"

+ "WudfRd" "Reflect device requests to user-mode driver drivers" "Microsoft Corporation" "c:\windows\system32\drivers\wudfrd.sys"

"HKCU\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" "" "" ""

+ "vidc.ffds" "" "" "File not found: -"

"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" "" "" ""

+ "aux" "WDM Audio driver mapper" "Microsoft Corporation" "c:\windows\system32\wdmaud.drv"

+ "aux1" "WDM Audio driver mapper" "Microsoft Corporation" "c:\windows\system32\wdmaud.drv"

+ "midi" "WDM Audio driver mapper" "Microsoft Corporation" "c:\windows\system32\wdmaud.drv"

+ "midi1" "WDM Audio driver mapper" "Microsoft Corporation" "c:\windows\system32\wdmaud.drv"

+ "midimapper" "Microsoft MIDI Mapper" "Microsoft Corporation" "c:\windows\system32\midimap.dll"

+ "mixer" "WDM Audio driver mapper" "Microsoft Corporation" "c:\windows\system32\wdmaud.drv"

+ "mixer1" "WDM Audio driver mapper" "Microsoft Corporation" "c:\windows\system32\wdmaud.drv"

+ "msacm.ac3acm" "AC-3 ACM Codec" "fccHandler" "c:\windows\system32\ac3acm.acm"

+ "msacm.iac2" "Indeo® audio software" "Intel Corporation" "c:\windows\system32\iac25_32.ax"

+ "msacm.imaadpcm" "IMA ADPCM CODEC for MSACM" "Microsoft Corporation" "c:\windows\system32\imaadp32.acm"

+ "msacm.l3acm" "MPEG Layer-3 Audio Codec for MSACM" "Fraunhofer Institut Integrierte Schaltungen IIS" "c:\windows\system32\l3codeca.acm"

+ "msacm.lameacm" "Lame MP3 codec engine" "http://www.mp3dev.org/" "c:\windows\system32\lameacm.acm"

+ "msacm.msadpcm" "Microsoft ADPCM CODEC for MSACM" "Microsoft Corporation" "c:\windows\system32\msadp32.acm"

+ "msacm.msaudio1" "Windows Media Audio" "Microsoft Corporation" "c:\windows\system32\msaud32.acm"

+ "msacm.msg711" "Microsoft CCITT G.711 (A-Law and u-Law) CODEC for MSACM" "Microsoft Corporation" "c:\windows\system32\msg711.acm"

+ "msacm.msg723" "Microsoft G.723.1 CODEC for MSACM" "Microsoft Corporation" "c:\windows\system32\msg723.acm"

+ "msacm.msgsm610" "Microsoft GSM 6.10 Audio CODEC for MSACM" "Microsoft Corporation" "c:\windows\system32\msgsm32.acm"

+ "msacm.sl_anet" "Audio codec for MS ACM" "Sipro Lab Telecom Inc." "c:\windows\system32\sl_anet.acm"

+ "msacm.trspch" "DSP Group TrueSpeech Audio Codec for MSACM V3.50" "DSP GROUP, INC." "c:\windows\system32\tssoft32.acm"

+ "vidc.cvid" "Cinepak® Codec" "Radius Inc." "c:\windows\system32\iccvid.dll"

+ "VIDC.DIVX" "DivX" "DivX, Inc." "c:\windows\system32\divx.dll"

+ "VIDC.FPS1" "Fraps" "Beepa P/L" "c:\windows\system32\frapsvid.dll"

+ "vidc.I420" "Microsoft H.263 ICM Driver" "Microsoft Corporation" "c:\windows\system32\msh263.drv"

+ "vidc.iv31" "" "" "c:\windows\system32\ir32_32.dll"

+ "vidc.iv32" "" "" "c:\windows\system32\ir32_32.dll"

+ "vidc.iv41" "Intel Indeo® Video 4.5" "Intel Corporation" "c:\windows\system32\ir41_32.ax"

+ "vidc.iv50" "Intel Indeo® video 5.10" "Intel Corporation" "c:\windows\system32\ir50_32.dll"

+ "vidc.iyuv" "Intel Indeo® Video YUV Codec" "Microsoft Corporation" "c:\windows\system32\iyuv_32.dll"

+ "vidc.M261" "Microsoft H.261 ICM Driver" "Microsoft Corporation" "c:\windows\system32\msh261.drv"

+ "vidc.M263" "Microsoft H.263 ICM Driver" "Microsoft Corporation" "c:\windows\system32\msh263.drv"

+ "VIDC.MP42" "Microsoft MPEG-4 Video Codec" "Microsoft Corporation" "c:\windows\system32\mpg4c32.dll"

+ "VIDC.MPG4" "Microsoft MPEG-4 Video Codec" "Microsoft Corporation" "c:\windows\system32\mpg4c32.dll"

+ "vidc.mrle" "Microsoft RLE Compressor" "Microsoft Corporation" "c:\windows\system32\msrle32.dll"

+ "vidc.msvc" "Microsoft Video 1 Compressor" "Microsoft Corporation" "c:\windows\system32\msvidc32.dll"

+ "vidc.uyvy" "Microsoft UYVY Video Decompressor" "Microsoft Corporation" "c:\windows\system32\msyuv.dll"

+ "vidc.VP60" "VP6 VIDEO FOR WINDOWS CODEC " "On2.com" "c:\windows\system32\vp6vfw.dll"

+ "vidc.VP61" "VP6 VIDEO FOR WINDOWS CODEC " "On2.com" "c:\windows\system32\vp6vfw.dll"

+ "VIDC.XVID" "" "" "c:\windows\system32\xvidvfw.dll"

+ "vidc.yuy2" "Microsoft UYVY Video Decompressor" "Microsoft Corporation" "c:\windows\system32\msyuv.dll"

+ "VIDC.YV12" "Helix YV12 YUV Codec" "www.helixcommunity.org" "c:\windows\system32\yv12vfw.dll"

+ "vidc.yvu9" "Toshiba Video Codec" "Microsoft Corporation" "c:\windows\system32\tsbyuv.dll"

+ "vidc.yvyu" "Microsoft UYVY Video Decompressor" "Microsoft Corporation" "c:\windows\system32\msyuv.dll"

+ "wave" "WDM Audio driver mapper" "Microsoft Corporation" "c:\windows\system32\wdmaud.drv"

+ "wave1" "WDM Audio driver mapper" "Microsoft Corporation" "c:\windows\system32\wdmaud.drv"

+ "wavemapper" "Microsoft Sound Mapper" "Microsoft Corporation" "c:\windows\system32\msacm32.drv"

"HKLM\Software\Classes\Filter" "" "" ""

+ "Indeo® video 4.4 Compression Filter" "Intel Indeo® Video 4.5" "Intel Corporation" "c:\windows\system32\ir41_32.ax"

+ "Indeo® video 4.4 Decompression Filter" "Intel Indeo® Video 4.5" "Intel Corporation" "c:\windows\system32\ir41_32.ax"

"HKLM\Software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance" "" "" ""

+ ".RAM Parser" "Windows Media Player Filter Shim" "Microsoft Corporation" "c:\windows\system32\wmpasf.dll"

+ "9x8Resize" "Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"

+ "AC3 Parser Filter" "DirectShow MPEG-2 Splitter." "Microsoft Corporation" "c:\windows\system32\mpg2splt.ax"

+ "AC3File" "" "" "c:\program files\k-lite codec pack\filters\ac3file.ax"

+ "ACDEncodeQT" "ACD QuickTime Encoder" "ACD Systems" "c:\program files\common files\acd systems\video\acdencodeqt.ax"

+ "ACDFX Filter" "ACDFX DirectShow Transform Filter" "ACD Systems" "c:\program files\common files\acd systems\acdfx.ax"

+ "ACELP.net Audio Decoder" "ACELP.net Audio Decoder" "Sipro Lab Telecom Inc." "c:\windows\system32\acelpdec.ax"

+ "ACM Wrapper" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\quartz.dll"

+ "Allocator Fix" "Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"

+ "ASF ACM Handler" "Windows Media Player Filter Shim" "Microsoft Corporation" "c:\windows\system32\wmpasf.dll"

+ "ASF Animation Handler" "Windows Media Player Filter Shim" "Microsoft Corporation" "c:\windows\system32\wmpasf.dll"

+ "ASF DIB Handler" "Windows Media Player Filter Shim" "Microsoft Corporation" "c:\windows\system32\wmpasf.dll"

+ "ASF DJPEG Handler" "Windows Media Player Filter Shim" "Microsoft Corporation" "c:\windows\system32\wmpasf.dll"

+ "ASF ICM Handler" "Windows Media Player Filter Shim" "Microsoft Corporation" "c:\windows\system32\wmpasf.dll"

+ "ASF JPEG Handler" "Windows Media Player Filter Shim" "Microsoft Corporation" "c:\windows\system32\wmpasf.dll"

+ "ASF URL Handler" "Windows Media Player Filter Shim" "Microsoft Corporation" "c:\windows\system32\wmpasf.dll"

+ "ASX File Parser" "Windows Media Player Filter Shim" "Microsoft Corporation" "c:\windows\system32\wmpasf.dll"

+ "ASX v.2 File Parser" "Windows Media Player Filter Shim" "Microsoft Corporation" "c:\windows\system32\wmpasf.dll"

+ "ATI Audio Delay Filter" "ATI Digital VCR" "ATI Technologies, Inc." "c:\program files\common files\ati technologies\multimedia\atidvcr.dll"

+ "ATI Audio Pitch Correction Filter" "ATI Digital VCR" "ATI Technologies, Inc." "c:\program files\common files\ati technologies\multimedia\atidvcr.dll"

+ "ATI CC Multiplexer" "ATI Digital VCR" "ATI Technologies, Inc." "c:\program files\common files\ati technologies\multimedia\atidvcr.dll"

+ "ATI CC Splitter" "ATI Digital VCR" "ATI Technologies, Inc." "c:\program files\common files\ati technologies\multimedia\atidvcr.dll"

+ "ATI EZShare Client" "ATI Digital VCR" "ATI Technologies, Inc." "c:\program files\common files\ati technologies\multimedia\atidvcr.dll"

+ "ATI EZShare Server" "ATI Digital VCR" "ATI Technologies, Inc." "c:\program files\common files\ati technologies\multimedia\atidvcr.dll"

+ "ATI FM-On-Demand Filter" "ATI Digital VCR" "ATI Technologies, Inc." "c:\program files\common files\ati technologies\multimedia\atidvcr.dll"

+ "ATI Media Center Audio Encoder" "ATI Media Center Encoder" "ATI Technologies, Inc." "c:\program files\common files\ati technologies\multimedia\atimcenc.dll"

+ "ATI Media Center Multiplexer" "ATI Media Center Encoder" "ATI Technologies, Inc." "c:\program files\common files\ati technologies\multimedia\atimcenc.dll"

+ "ATI Media Center Video Encoder" "ATI Media Center Encoder" "ATI Technologies, Inc." "c:\program files\common files\ati technologies\multimedia\atimcenc.dll"

+ "ATI MPEG Audio Decoder" "ATI Digital VCR" "ATI Technologies, Inc." "c:\program files\common files\ati technologies\multimedia\atidvcr.dll"

+ "ATI MPEG Audio Encoder" "ATI Digital VCR" "ATI Technologies, Inc." "c:\program files\common files\ati technologies\multimedia\atidvcr.dll"

+ "ATI MPEG File Writer" "ATI Digital VCR" "ATI Technologies, Inc." "c:\program files\common files\ati technologies\multimedia\atidvcr.dll"

+ "ATI MPEG Multiplexer" "ATI Digital VCR" "ATI Technologies, Inc." "c:\program files\common files\ati technologies\multimedia\atidvcr.dll"

+ "ATI MPEG Video Decoder" "ATI Digital VCR" "ATI Technologies, Inc." "c:\program files\common files\ati technologies\multimedia\atidvcr.dll"

+ "ATI MPEG Video Encoder" "ATI Digital VCR" "ATI Technologies, Inc." "c:\program files\common files\ati technologies\multimedia\atidvcr.dll"

+ "ATI Noise Reduction Filter" "ATI Digital VCR" "ATI Technologies, Inc." "c:\program files\common files\ati technologies\multimedia\atidvcr.dll"

+ "ATI Ticker" "" "" "c:\program files\ati technologies\ati.ace\graphics-previews-common\ticker.ax"

+ "ATI Time Shift Reader" "ATI Digital VCR" "ATI Technologies, Inc." "c:\program files\common files\ati technologies\multimedia\atidvcr.dll"

+ "ATI Time Shift Splitter" "ATI Digital VCR" "ATI Technologies, Inc." "c:\program files\common files\ati technologies\multimedia\atidvcr.dll"

+ "ATI VCR Stream Sink" "ATI Digital VCR" "ATI Technologies, Inc." "c:\program files\common files\ati technologies\multimedia\atidvcr.dll"

+ "ATI VCR Stream Source" "ATI Digital VCR" "ATI Technologies, Inc." "c:\program files\common files\ati technologies\multimedia\atidvcr.dll"

+ "ATI VCR Video Converter" "ATI Digital VCR" "ATI Technologies, Inc." "c:\program files\common files\ati technologies\multimedia\atidvcr.dll"

+ "ATI Video Format Converter" "ATI Digital VCR" "ATI Technologies, Inc." "c:\program files\common files\ati technologies\multimedia\atidvcr.dll"

+ "ATI Video Rotation Filter" "ATI Digital VCR" "ATI Technologies, Inc." "c:\program files\common files\ati technologies\multimedia\atidvcr.dll"

+ "ATI Video Scaler Filter" "ATI Digital VCR" "ATI Technologies, Inc." "c:\program files\common files\ati technologies\multimedia\atidvcr.dll"

+ "AVI Decompressor" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\quartz.dll"

+ "AVI Draw Filter" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\quartz.dll"

+ "AVI mux" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\qcap.dll"

+ "AVI Splitter" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\quartz.dll"

+ "AVI/WAV File Source" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\quartz.dll"

+ "Bitmap" "Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"

+ "Color Space Converter" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\quartz.dll"

+ "CoreVorbis Audio Decoder" "CoreVorbis" "-" "c:\program files\k-lite codec pack\filters\corevorbis.ax"

+ "CyberLink Audio Decoder (PDVD7 UPnP)" "CyberLink Audio Decoder Filter" "CyberLink Corp." "c:\program files\cyberlink\powerdvd\upnp\claud.ax"

+ "CyberLink Audio Decoder (PDVD7)" "CyberLink Audio Decoder Filter" "CyberLink Corp." "c:\program files\cyberlink\powerdvd\audiofilter\claud.ax"

+ "CyberLink Audio Effect (PDVD7)" "CyberLink Audio Effect Filter" "CyberLink Corporation" "c:\program files\cyberlink\powerdvd\audiofilter\claudfx.ax"

+ "CyberLink Audio Spectrum Analyzer (PDVD7)" "CLAudSpa.ax" "CyberLink Corp." "c:\program files\cyberlink\powerdvd\audiofilter\claudspa.ax"

+ "CyberLink AudioCD Filter (PDVD7)" "CyberLink AudioCD Filter" "CyberLink Corp." "c:\program files\cyberlink\powerdvd\audiofilter\claudiocd.ax"

+ "CyberLink Demux (PDVD7 UPnP)" "MPEG-2 Dempltiplexer" "CyberLink Corp." "c:\program files\cyberlink\powerdvd\upnp\cldemuxer.ax"

+ "CyberLink Demux (PDVD7)" "MPEG-2 Dempltiplexer" "CyberLink Corp." "c:\program files\cyberlink\powerdvd\navfilter\cldemuxer.ax"

+ "CyberLink DVD Navigator (PDVD7)" "CyberLink DVD Navigation Filter" "CyberLink Corp." "c:\program files\cyberlink\powerdvd\navfilter\clnavx.ax"

+ "CyberLink H.264/AVC Decoder (PDVD7)" "CyberLink 264 Decoder Filter" "CyberLink Corp." "c:\program files\cyberlink\powerdvd\videofilter\cl264dec.ax"

+ "CyberLink Line21 Decoder (PDVD7)" "CyberLink Line21 Decoder Filter" "CyberLink Corp." "c:\program files\cyberlink\powerdvd\videofilter\clline21.ax"

+ "CyberLink MPEG Splitter(Scramble)" "CyberLink MPEG Splitter" "CyberLink Corp." "c:\program files\cyberlink\powerdvd\upnp\clsplter.ax"

+ "CyberLink MPEG-4 Splitter (PDVD7)" "CyberLink MPEG-4 Splitter" "CyberLink Corp." "c:\program files\cyberlink\powerdvd\navfilter\clm4splt.ax"

+ "CyberLink Push-Mode CLStream (PDVD7)" "CLStream" "CyberLink" "c:\program files\cyberlink\powerdvd\upnp\clstream(pushmode).ax"

+ "CyberLink SAC Video Decoder(PDVD7 HomeNetwork)" "CyberLink Video/SP Filter" "CyberLink Corp." "c:\program files\cyberlink\powerdvd\upnp\clvsd.ax"

+ "CyberLink Streamming Filter (PDVD7)" "Cyberlink Streaming Source Filter(Scramble)" "CyberLink Corp." "c:\program files\cyberlink\powerdvd\upnp\clstream.ax"

+ "Cyberlink SubTitle Importor (PDVD7)" "CLSubTitle.ax" "CyberLink Corp." "c:\program files\cyberlink\powerdvd\videofilter\clsubtitle.ax"

+ "CyberLink TimeStretch Filter (PDVD7)" "CLAuTS.ax" "CyberLink Corp." "c:\program files\cyberlink\powerdvd\audiofilter\clauts.ax"

+ "CyberLink Video/SP Decoder (PDVD7)" "CyberLink Video/SP Filter" "CyberLink Corp." "c:\program files\cyberlink\powerdvd\videofilter\clvsd.ax"

+ "DC-Bass Source" "DirectShow™ Audio Decoder" "http://www.dsp-worx.de" "c:\program files\k-lite codec pack\filters\dcbasssource.ax"

+ "Default Video Renderer" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\quartz.dll"

+ "DirectVobSub" "VobSub & TextSub filter for DirectShow/VirtualDub/Avisynth" "Gabest" "c:\program files\k-lite codec pack\filters\vsfilter.dll"

+ "DirectVobSub (auto-loading version)" "VobSub & TextSub filter for DirectShow/VirtualDub/Avisynth" "Gabest" "c:\program files\k-lite codec pack\filters\vsfilter.dll"

+ "DivX Decoder Filter" "DivX® Decoder Filter" "DivX, Inc." "c:\program files\k-lite codec pack\filters\divxdec.ax"

+ "DivX for Blizzard Decoder Filter" "DivX Decoder Filter" "DivXNetworks, Inc." "f:\games\warcraft iii\blizzard.ax"

+ "DV Muxer" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\qdv.dll"

+ "DV Splitter" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\qdv.dll"

+ "DV Video Decoder" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\qdv.dll"

+ "DVD Navigator" "DirectShow DVD PlayBack Runtime." "Microsoft Corporation" "c:\windows\system32\qdvd.dll"

+ "Emuzed AAC/AAC+ Decoder TFilter" "Emuzed AAC/AAC+ Decoder Filter" "Emuzed Inc. " "c:\program files\common files\nokia\codecs\emzaacdecfilter.dll"

+ "Emuzed AMR/3GPP/MP4/MP3 Multiplexer-Filter" "Emuzed MP4/3GP2/AMR/QCP Multiplexer/Sink Filter" "Emuzed Inc. " "c:\program files\common files\nokia\codecs\ezdmp4muxfilter.dll"

+ "Emuzed AMR/QCP/3GPP/MP4/3G2 Source Filter" "Emuzed MP4/3GP2/AMR/QCP Source Filter" "Emuzed Inc. " "c:\program files\common files\nokia\codecs\emzmp4source.dll"

+ "Emuzed H264 Video Decoder-Filter" "Emuzed H.264 Video Transform Filter" "Emuzed Inc. " "c:\program files\common files\nokia\codecs\ezdh264dectfilter.dll"

+ "Emuzed MP3 Source/Decoder Filter" "Emuzed MP3 Source/Decoder Filter" "Emuzed Inc. " "c:\program files\common files\nokia\codecs\emzmp3sourcefilter.dll"

+ "Emuzed MP4SP/H263 Video Decoder-Filter" "Emuzed MP4SP/H.263 Video Transform Filter" "Emuzed Inc. " "c:\program files\common files\nokia\codecs\emzdecmp4_h263.dll"

+ "File Source (Async.)" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\quartz.dll"

+ "File Source (Monkey Audio)" "" "" "c:\program files\k-lite codec pack\filters\monkeysource.ax"

+ "File Source (URL)" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\quartz.dll"

+ "File stream renderer" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\quartz.dll"

+ "File Writer" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\qcap.dll"

+ "Frame Eater" "Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"

+ "Full Screen Renderer" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\quartz.dll"

+ "FunBox MPEG Decoder Filter" "FunBox Decoder Filter" "Mobile Leader" "c:\windows\system32\fundecfilter.ax"

+ "FunBox MPEG Encoder Filter" "FunBox Encoder Filter" "Mobile Leader" "c:\windows\system32\funencfilter.ax"

+ "G.711 Codec" "Intel G711 CODEC" "Microsoft Corporation" "c:\windows\system32\g711codc.ax"

+ "Haali Video Renderer" "" "" "c:\program files\k-lite codec pack\filters\haali\dxr.dll"

+ "Indeo® audio software" "Indeo® audio software" "Intel Corporation" "c:\windows\system32\iac25_32.ax"

+ "Indeo® video 5.10 Compression Filter" "Intel Indeo® video 5.10" "Intel Corporation" "c:\windows\system32\ir50_32.dll"

+ "Indeo® video 5.10 Decompression Filter" "Intel Indeo® video 5.10" "Intel Corporation" "c:\windows\system32\ir50_32.dll"

+ "Infinite Pin Tee Filter" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\qcap.dll"

+ "Internal Text Renderer" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\quartz.dll"

+ "Line 21 Decoder" "DirectShow DVD PlayBack Runtime." "Microsoft Corporation" "c:\windows\system32\qdvd.dll"

+ "Line 21 Decoder 2" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\quartz.dll"

+ "madFlac Decoder" "DirectShow FLAC Decoder" "www.madshi.net" "c:\program files\k-lite codec pack\filters\madflac.ax"

+ "madFlac Source" "DirectShow FLAC Decoder" "www.madshi.net" "c:\program files\k-lite codec pack\filters\madflac.ax"

+ "MainConcept MPEG Encoder" "MPEG Encoder and Muxer" "MainConcept AG" "c:\program files\acd systems\acdsee\10.0\mcesmpeg.ax"

+ "Microsoft MPEG-4 Video Decompressor" "Microsoft MPEG-4 Video Decompressor" "Microsoft Corporation" "c:\windows\system32\mp4sds32.ax"

+ "Microsoft MPEG-4 Video Decompressor" "Microsoft MPEG-4 Video Decompressor" "Microsoft Corporation" "c:\windows\system32\mpg4ds32.ax"

+ "Microsoft Screen Video Decompressor" "Microsoft Screen Video Decompressor" "Microsoft Corporation" "c:\windows\system32\msscds32.ax"

+ "MIDI Parser" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\quartz.dll"

+ "MJPEG Decompressor" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\quartz.dll"

+ "MMACE Deinterlace" "" "" "c:\program files\ati technologies\ati.ace\graphics-previews-common\mmacefilters.dll"

+ "MMACE ProcAmp" "" "" "c:\program files\ati technologies\ati.ace\graphics-previews-common\mmacefilters.dll"

+ "MMACE SoftEmu" "" "" "c:\program files\ati technologies\ati.ace\graphics-previews-common\mmacefilters.dll"

+ "MPEG Audio Codec" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\quartz.dll"

+ "MPEG Layer-3 Decoder" "MPEG Layer-3 Audio Decoder" "Fraunhofer Institut Integrierte Schaltungen IIS" "c:\program files\k-lite codec pack\filters\l3codecx.ax"

+ "Mpeg Source" "Mpeg Splitter" "Gabest" "c:\program files\k-lite codec pack\filters\mpegsplitter.ax"

+ "Mpeg Splitter" "Mpeg Splitter" "Gabest" "c:\program files\k-lite codec pack\filters\mpegsplitter.ax"

+ "MPEG Video Codec" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\quartz.dll"

+ "MPEG-2 Demultiplexer" "DirectShow MPEG-2 Splitter." "Microsoft Corporation" "c:\windows\system32\mpg2splt.ax"

+ "MPEG-2 Sections and Tables" "Microsoft MPEG-2 Section and Table Acquisition Module" "Microsoft Corporation" "c:\windows\system32\mpeg2data.ax"

+ "MPEG-2 Splitter" "DirectShow MPEG-2 Splitter." "Microsoft Corporation" "c:\windows\system32\mpg2splt.ax"

+ "Mpeg-2 Video Stream Analysis" "DirectShow Stream Buffer Filter." "Microsoft Corporation" "c:\windows\system32\sbe.dll"

+ "MPEG-I Stream Splitter" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\quartz.dll"

+ "Multi-file Parser" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\quartz.dll"

+ "Nero Audio Source" "Nero Library" "Nero AG" "c:\program files\common files\ahead\dsfilter\nerender.ax"

+ "Nero Audio Stream Renderer" "Nero Library" "Nero AG" "c:\program files\common files\ahead\dsfilter\nerender.ax"

+ "Nero Audio Stream Renderer" "Nero Library" "Nero AG" "c:\program files\common files\ahead\dsfilter\nerender.ax"

+ "Nero Digital Parser" "NeroDigital / mp4 / avi / mov parser" "Nero AG" "c:\program files\common files\ahead\dsfilter\ndparser.ax"

+ "Nero DVD Decoder" "MPEG-1/2/4 & AVC video decoder w/ DxVA" "Nero AG" "c:\program files\common files\ahead\dsfilter\nevideo.ax"

+ "Nero ES Video Reader" "NeroDigital / mp4 / avi / mov parser" "Nero AG" "c:\program files\common files\ahead\dsfilter\ndparser.ax"

+ "Nero QuickTime Audio Decoder" "QuickTime Decoder Wrapper" "Nero AG" "c:\program files\common files\ahead\dsfilter\neqtdec.ax"

+ "Nero QuickTime Video Decoder" "QuickTime Decoder Wrapper" "Nero AG" "c:\program files\common files\ahead\dsfilter\neqtdec.ax"

+ "Nero Video Decoder" "MPEG-1/2/4 & AVC video decoder w/ DxVA" "Nero AG" "c:\program files\common files\ahead\dsfilter\nevideo.ax"

+ "Nero Video Source" "Nero Library" "Nero AG" "c:\program files\common files\ahead\dsfilter\nerender.ax"

+ "NSC File Parser" "Windows Media Player Filter Shim" "Microsoft Corporation" "c:\windows\system32\wmpasf.dll"

+ "Null Renderer" "DirectShow Editing." "Microsoft Corporation" "c:\windows\system32\qedit.dll"

+ "Overlay Mixer" "DirectShow DVD PlayBack Runtime." "Microsoft Corporation" "c:\windows\system32\qdvd.dll"

+ "Overlay Mixer2" "DirectShow DVD PlayBack Runtime." "Microsoft Corporation" "c:\windows\system32\qdvd.dll"

+ "QT Decompressor" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\quartz.dll"

+ "QuickTime Movie Parser" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\quartz.dll"

+ "Record Queue" "Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"

+ "SAMI (CC) Reader" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\quartz.dll"

+ "Sample Grabber" "DirectShow Editing." "Microsoft Corporation" "c:\windows\system32\qedit.dll"

+ "ShotDetect" "Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"

+ "Smart Tee Filter" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\qcap.dll"

+ "Stetch" "Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"

+ "StreamBufferSink" "DirectShow Stream Buffer Filter." "Microsoft Corporation" "c:\windows\system32\sbe.dll"

+ "StreamBufferSource" "DirectShow Stream Buffer Filter." "Microsoft Corporation" "c:\windows\system32\sbe.dll"

+ "T" "VP6 Decompression Filter" "On2.com Inc." "c:\program files\k-lite codec pack\filters\vp6dec.ax"

+ "T" "VP7 Decompression Filter" "On2.com Inc." "c:\program files\k-lite codec pack\filters\vp7dec.ax"

+ "VBI Surface Allocator" "VBI Surface Allocator Filter" "Microsoft Corporation" "c:\windows\system32\vbisurf.ax"

+ "VGA 16 color ditherer" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\quartz.dll"

+ "Video Mixing Renderer 9" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\quartz.dll"

+ "Video Port Manager" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\quartz.dll"

+ "Video Renderer" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\quartz.dll"

+ "WAV Dest" "WAVDest Filter (Sample)" "Microsoft Corporation" "c:\windows\system32\samsung pc studio codecs\wavdest.ax"

+ "Wave Parser" "DirectShow Runtime." "Microsoft Corporation" "c:\windows\system32\quartz.dll"

+ "WIA Stream Snapshot Filter" "WIA Stream Snapshot Filter" "MyCompanyName" "c:\windows\system32\wiasf.ax"

+ "Windows Media Audio Decoder" "Windows Media Audio Decoder" "Microsoft Corporation" "c:\windows\system32\msadds32.ax"

+ "Windows Media Multiplexer" "Windows Media Player Filter Shim" "Microsoft Corporation" "c:\windows\system32\wmpasf.dll"

+ "Windows Media splitter" "Windows Media Player Filter Shim" "Microsoft Corporation" "c:\windows\system32\wmpasf.dll"

+ "Windows Media Update" "Windows Media Player Filter Shim" "Microsoft Corporation" "c:\windows\system32\wmpasf.dll"

+ "Windows Media URL File Source" "Windows Media Player Filter Shim" "Microsoft Corporation" "c:\windows\system32\wmpasf.dll"

+ "Windows Media Video Decoder" "Windows Media Video Decoder" "Microsoft Corporation" "c:\windows\system32\wmvds32.ax"

+ "Windows Media Video Decoder" "Windows Media Video Decoder V8" "Microsoft Corporation" "c:\windows\system32\wmv8ds32.ax"

+ "WM ASF Reader" "DirectShow ASF Support" "Microsoft Corporation" "c:\windows\system32\qasf.dll"

+ "WM ASF Writer" "DirectShow ASF Support" "Microsoft Corporation" "c:\windows\system32\qasf.dll"

+ "WM VIH2 Fix" "Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"

+ "WMEnc Screen Capture Filter" "WMPSrcWp Module" "Microsoft Corporation" "c:\windows\system32\wmpsrcwp.dll"

+ "WMT Audio Analyzer" "Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"

+ "WMT Black Frame Generator" "Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"

+ "WMT DirectX Transform Wrapper" "Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"

+ "WMT DV Extract Filter" "Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"

+ "WMT FormatConversion" "Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"

+ "WMT Import Filter" "Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"

+ "WMT Interlacer" "Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"

+ "WMT Log Filter" "Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"

+ "WMT MuxDeMux Filter" "Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"

+ "WMT Sample Info Filter" "Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"

+ "WMT Screen capture Filter" "Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"

+ "WMT Switch Filter" "Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"

+ "WMT Virtual Renderer" "Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"

+ "WMT Virtual Source" "Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"

+ "WMT Volume" "Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"

+ "World Standard Teletext Decoder" "WST Decoder Filter" "Microsoft Corporation" "c:\windows\system32\wstdecod.dll"

+ "XML-based ASX Parser" "Windows Media Player Filter Shim" "Microsoft Corporation" "c:\windows\system32\wmpasf.dll"

+ "Xvid MPEG-4 Video Decoder" "" "" "c:\windows\system32\xvid.ax"

"HKLM\Software\Classes\CLSID\{AC757296-3522-4E11-9862-C17BE5A1767E}\Instance" "" "" ""

+ "{0131BE10-2001-4C5F-A9B0-CC88FAB64CE8}" "Microsoft Windows Codecs Library" "Microsoft Corporation" "c:\windows\system32\windowscodecs.dll"

+ "{114F5598-0B22-40A0-86A1-C83EA495ADBD}" "Microsoft Windows Codecs Library" "Microsoft Corporation" "c:\windows\system32\windowscodecs.dll"

+ "{1A34F5C1-4A5A-46DC-B644-1F4567E7A676}" "Microsoft Windows Codecs Library" "Microsoft Corporation" "c:\windows\system32\windowscodecs.dll"

+ "{27949969-876A-41D7-9447-568F6A35A4DC}" "Microsoft Windows Codecs Library" "Microsoft Corporation" "c:\windows\system32\windowscodecs.dll"

+ "{69BE8BB4-D66D-47C8-865A-ED1589433782}" "Microsoft Windows Codecs Library" "Microsoft Corporation" "c:\windows\system32\windowscodecs.dll"

+ "{AC4CE3CB-E1C1-44CD-8215-5A1665509EC2}" "Windows Media Photo Codec" "Microsoft Corporation" "c:\windows\system32\wmphoto.dll"

"HKLM\Software\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance" "" "" ""

+ "{381DDA3C-9CE9-4834-A23E-1F98F8FC52BE}" "Microsoft Windows Codecs Library" "Microsoft Corporation" "c:\windows\system32\windowscodecs.dll"

+ "{389EA17B-5078-4CDE-B6EF-25C15175C751}" "Microsoft Windows Codecs Library" "Microsoft Corporation" "c:\windows\system32\windowscodecs.dll"

+ "{6B462062-7CBF-400D-9FDB-813DD10F2778}" "Microsoft Windows Codecs Library" "Microsoft Corporation" "c:\windows\system32\windowscodecs.dll"

+ "{9456A480-E88B-43EA-9E73-0B2D9B71B1CA}" "Microsoft Windows Codecs Library" "Microsoft Corporation" "c:\windows\system32\windowscodecs.dll"

+ "{A26CEC36-234C-4950-AE16-E34AACE71D0D}" "Windows Media Photo Codec" "Microsoft Corporation" "c:\windows\system32\wmphoto.dll"

+ "{B54E85D9-FE23-499F-8B88-6ACEA713752B}" "Microsoft Windows Codecs Library" "Microsoft Corporation" "c:\windows\system32\windowscodecs.dll"

+ "{C61BFCDF-2E0F-4AAD-A8D7-E06BAFEBCDFE}" "Microsoft Windows Codecs Library" "Microsoft Corporation" "c:\windows\system32\windowscodecs.dll"

"HKLM\Software\Classes\CLSID\{ABE3B9A4-257D-4B97-BD1A-294AF496222E}\Instance" "" "" ""

+ "{00108226-EE41-44A2-9E9C-4BE4D5B1D2CD}" "Microsoft Windows Codecs Library" "Microsoft Corporation" "c:\windows\system32\windowscodecs.dll"

+ "{076C2A6C-F78F-4C46-A723-3583E70876EA}" "Microsoft Windows Codecs Extended Library" "Microsoft Corporation" "c:\windows\system32\windowscodecsext.dll"

+ "{122EC645-CD7E-44D8-B186-2C8C20C3B50F}" "Microsoft Windows Codecs Library" "Microsoft Corporation" "c:\windows\system32\windowscodecs.dll"

+ "{1249B20C-5DD0-44FE-B0B3-8F92C8E6D080}" "Microsoft Windows Codecs Library" "Microsoft Corporation" "c:\windows\system32\windowscodecs.dll"

+ "{1765E14E-1BD4-462E-B6B1-590BF1262AC6}" "Microsoft Windows Codecs Extended Library" "Microsoft Corporation" "c:\windows\system32\windowscodecsext.dll"

+ "{22C21F93-7DDB-411C-9B17-C5B7BD064ABC}" "Microsoft Windows Codecs Extended Library" "Microsoft Corporation" "c:\windows\system32\windowscodecsext.dll"

+ "{5C5C1935-0235-4434-80BC-251BC1EC39C6}" "Microsoft Windows Codecs Library" "Microsoft Corporation" "c:\windows\system32\windowscodecs.dll"

+ "{6D68D1DE-D432-4B0F-923A-091183A9BDA7}" "Microsoft Windows Codecs Extended Library" "Microsoft Corporation" "c:\windows\system32\windowscodecsext.dll"

+ "{7B19A919-A9D6-49E5-BD45-02C34E4E4CD5}" "Microsoft Windows Codecs Library" "Microsoft Corporation" "c:\windows\system32\windowscodecs.dll"

+ "{8ADE5386-8E9B-4F4C-ACF2-F0008706B238}" "Microsoft Windows Codecs Library" "Microsoft Corporation" "c:\windows\system32\windowscodecs.dll"

+ "{A09CCA86-27BA-4F39-9053-121FA4DC08FC}" "Microsoft Windows Codecs Library" "Microsoft Corporation" "c:\windows\system32\windowscodecs.dll"

+ "{B1EBFC28-C9BD-47A2-8D33-B948769777A7}" "Microsoft Windows Codecs Library" "Microsoft Corporation" "c:\windows\system32\windowscodecs.dll"

+ "{B5EBAFB9-253E-4A72-A744-0762D2685683}" "Microsoft Windows Codecs Library" "Microsoft Corporation" "c:\windows\system32\windowscodecs.dll"

+ "{C9A14CDA-C339-460B-9078-D4DEBCFABE91}" "Microsoft Windows Codecs Library" "Microsoft Corporation" "c:\windows\system32\windowscodecs.dll"

+ "{CB8C13E4-62B5-4C96-A48B-6BA6ACE39C76}" "Microsoft Windows Codecs Library" "Microsoft Corporation" "c:\windows\system32\windowscodecs.dll"

+ "{D049B20C-5DD0-44FE-B0B3-8F92C8E6D080}" "Microsoft Windows Codecs Library" "Microsoft Corporation" "c:\windows\system32\windowscodecs.dll"

+ "{ED822C8C-D6BE-4301-A631-0E1416BAD28F}" "Microsoft Windows Codecs Extended Library" "Microsoft Corporation" "c:\windows\system32\windowscodecsext.dll"

+ "{EE366069-1832-420F-B381-0479AD066F19}" "Microsoft Windows Codecs Library" "Microsoft Corporation" "c:\windows\system32\windowscodecs.dll"

+ "{F3C633A2-46C8-498E-8FBB-CC6F721BBCDE}" "Microsoft Windows Codecs Library" "Microsoft Corporation" "c:\windows\system32\windowscodecs.dll"

"HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute" "" "" ""

+ "autocheck autochk *" "Auto Check Utility" "Microsoft Corporation" "c:\windows\system32\autochk.exe"

"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options" "" "" ""

+ "Your Image File Name Here without a path" "Symbolic Debugger for Windows 2000" "Microsoft Corporation" "c:\windows\system32\ntsd.exe"

"HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls" "" "" ""

+ "advapi32" "Advanced Windows 32 Base API" "Microsoft Corporation" "c:\windows\system32\advapi32.dll"

+ "comdlg32" "Common Dialogs DLL" "Microsoft Corporation" "c:\windows\system32\comdlg32.dll"

+ "gdi32" "GDI Client DLL" "Microsoft Corporation" "c:\windows\system32\gdi32.dll"

+ "imagehlp" "Windows NT Image Helper" "Microsoft Corporation" "c:\windows\system32\imagehlp.dll"

+ "kernel32" "Windows NT BASE API Client DLL" "Microsoft Corporation" "c:\windows\system32\kernel32.dll"

+ "lz32" "LZ Expand/Compress API DLL" "Microsoft Corporation" "c:\windows\system32\lz32.dll"

+ "ole32" "Microsoft OLE for Windows" "Microsoft Corporation" "c:\windows\system32\ole32.dll"

+ "oleaut32" "" "Microsoft Corporation" "c:\windows\system32\oleaut32.dll"

+ "olecli32" "Object Linking and Embedding Client Library" "Microsoft Corporation" "c:\windows\system32\olecli32.dll"

+ "olecnv32" "Microsoft OLE for Windows" "Microsoft Corporation" "c:\windows\system32\olecnv32.dll"

+ "olesvr32" "Object Linking and Embedding Server Library" "Microsoft Corporation" "c:\windows\system32\olesvr32.dll"

+ "olethk32" "Microsoft OLE for Windows" "Microsoft Corporation" "c:\windows\system32\olethk32.dll"

+ "rpcrt4" "Remote Procedure Call Runtime" "Microsoft Corporation" "c:\windows\system32\rpcrt4.dll"

+ "shell32" "Windows Shell Common Dll" "Microsoft Corporation" "c:\windows\system32\shell32.dll"

+ "url" "Internet Shortcut Shell Extension DLL" "Microsoft Corporation" "c:\windows\system32\url.dll"

+ "urlmon" "OLE32 Extensions for Win32" "Microsoft Corporation" "c:\windows\system32\urlmon.dll"

+ "user32" "Windows XP USER API Client DLL" "Microsoft Corporation" "c:\windows\system32\user32.dll"

+ "version" "Version Checking and File Installation Libraries" "Microsoft Corporation" "c:\windows\system32\version.dll"

+ "wininet" "Internet Extensions for Win32" "Microsoft Corporation" "c:\windows\system32\wininet.dll"

+ "wldap32" "Win32 LDAP API DLL" "Microsoft Corporation" "c:\windows\system32\wldap32.dll"

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UIHost" "" "" ""

+ "LogonUI.EXE" "Windows Logon UI" "Microsoft Corporation" "c:\windows\system32\logonui.exe"

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify" "" "" ""

+ "AtiExtEvent" "ATI External Event Utility DLL Module" "ATI Technologies Inc." "c:\windows\system32\ati2evxx.dll"

+ "crypt32chain" "Crypto API32" "Microsoft Corporation" "c:\windows\system32\crypt32.dll"

+ "cryptnet" "Crypto Network Related API" "Microsoft Corporation" "c:\windows\system32\cryptnet.dll"

+ "cscdll" "Offline Network Agent" "Microsoft Corporation" "c:\windows\system32\cscdll.dll"

+ "dimsntfy" "DIMS Notification Handler" "Microsoft Corporation" "c:\windows\system32\dimsntfy.dll"

+ "ScCertProp" "Common DLL to receive Winlogon notifications" "Microsoft Corporation" "c:\windows\system32\wlnotify.dll"

+ "Schedule" "Common DLL to receive Winlogon notifications" "Microsoft Corporation" "c:\windows\system32\wlnotify.dll"

+ "sclgntfy" "Secondary Logon Service Notification DLL" "Microsoft Corporation" "c:\windows\system32\sclgntfy.dll"

+ "SensLogn" "Common DLL to receive Winlogon notifications" "Microsoft Corporation" "c:\windows\system32\wlnotify.dll"

+ "termsrv" "Common DLL to receive Winlogon notifications" "Microsoft Corporation" "c:\windows\system32\wlnotify.dll"

+ "wlballoon" "Common DLL to receive Winlogon notifications" "Microsoft Corporation" "c:\windows\system32\wlnotify.dll"

"HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries" "" "" ""

+ "000000000001" "Microsoft Windows Sockets 2.0 Service Provider" "Microsoft Corporation" "c:\windows\system32\mswsock.dll"

+ "000000000002" "Microsoft Windows Sockets 2.0 Service Provider" "Microsoft Corporation" "c:\windows\system32\mswsock.dll"

+ "000000000003" "Microsoft Windows Sockets 2.0 Service Provider" "Microsoft Corporation" "c:\windows\system32\mswsock.dll"

+ "000000000004" "Microsoft Windows Rsvp 1.0 Service Provider" "Microsoft Corporation" "c:\windows\system32\rsvpsp.dll"

+ "000000000005" "Microsoft Windows Rsvp 1.0 Service Provider" "Microsoft Corporation" "c:\windows\system32\rsvpsp.dll"

+ "000000000006" "Microsoft Windows Sockets 2.0 Service Provider" "Microsoft Corporation" "c:\windows\system32\mswsock.dll"

+ "000000000007" "Microsoft Windows Sockets 2.0 Service Provider" "Microsoft Corporation" "c:\windows\system32\mswsock.dll"

+ "000000000008" "Microsoft Windows Sockets 2.0 Service Provider" "Microsoft Corporation" "c:\windows\system32\mswsock.dll"

+ "000000000009" "Microsoft Windows Sockets 2.0 Service Provider" "Microsoft Corporation" "c:\windows\system32\mswsock.dll"

+ "000000000010" "Microsoft Windows Sockets 2.0 Service Provider" "Microsoft Corporation" "c:\windows\system32\mswsock.dll"

+ "000000000011" "Microsoft Windows Sockets 2.0 Service Provider" "Microsoft Corporation" "c:\windows\system32\mswsock.dll"

+ "000000000012" "Microsoft Windows Sockets 2.0 Service Provider" "Microsoft Corporation" "c:\windows\system32\mswsock.dll"

+ "000000000013" "Microsoft Windows Sockets 2.0 Service Provider" "Microsoft Corporation" "c:\windows\system32\mswsock.dll"

"HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries" "" "" ""

+ "Network Location Awareness (NLA) Namespace" "Microsoft Windows Sockets 2.0 Service Provider" "Microsoft Corporation" "c:\windows\system32\mswsock.dll"

+ "NTDS" "LDAP RnR Provider DLL" "Microsoft Corporation" "c:\windows\system32\winrnr.dll"

+ "Tcpip" "Microsoft Windows Sockets 2.0 Service Provider" "Microsoft Corporation" "c:\windows\system32\mswsock.dll"

"HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors" "" "" ""

+ "BJ Language Monitor" "Langage Monitor for Canon Bubble-Jet Printer" "Microsoft Corporation" "c:\windows\system32\cnbjmon.dll"

+ "Local Port" "Local Spooler DLL" "Microsoft Corporation" "c:\windows\system32\localspl.dll"

+ "Microsoft Document Imaging Writer Monitor" "Microsoft® Document Imaging" "Microsoft Corporation" "c:\windows\system32\mdimon.dll"

+ "PJL Language Monitor" "PJL Language monitor" "Microsoft Corporation" "c:\windows\system32\pjlmon.dll"

+ "Standard TCP/IP Port" "Standard TCP/IP Port Monitor DLL" "Microsoft Corporation" "c:\windows\system32\tcpmon.dll"

+ "USB Monitor" "Standard Dynamic Printing Port Monitor DLL" "Microsoft Corporation" "c:\windows\system32\usbmon.dll"

"HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProviders" "" "" ""

+ "digest.dll" "Digest SSPI Authentication Package" "Microsoft Corporation" "c:\windows\system32\digest.dll"

+ "msapsspc.dll" "DPA Client for 32 bit platforms" "Microsoft Corporation" "c:\windows\system32\msapsspc.dll"

+ "msnsspc.dll" "MSN Internet Access" "Microsoft Corporation" "c:\windows\system32\msnsspc.dll"

+ "schannel.dll" "TLS / SSL Security Provider" "Microsoft Corporation" "c:\windows\system32\schannel.dll"

"HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages" "" "" ""

+ "msv1_0" "Microsoft Authentication Package v1.0" "Microsoft Corporation" "c:\windows\system32\msv1_0.dll"

"HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Notification Packages" "" "" ""

+ "scecli" "Windows Security Configuration Editor Client Engine" "Microsoft Corporation" "c:\windows\system32\scecli.dll"

"HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Security Packages" "" "" ""

+ "kerberos" "Kerberos Security Package" "Microsoft Corporation" "c:\windows\system32\kerberos.dll"

+ "msv1_0" "Microsoft Authentication Package v1.0" "Microsoft Corporation" "c:\windows\system32\msv1_0.dll"

+ "schannel" "TLS / SSL Security Provider" "Microsoft Corporation" "c:\windows\system32\schannel.dll"

+ "wdigest" "Microsoft Digest Access" "Microsoft Corporation" "c:\windows\system32\wdigest.dll"

"HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order" "" "" ""

+ "LanmanWorkstation" "Microsoft Windows Network" "Microsoft Corporation" "c:\windows\system32\ntlanman.dll"

+ "RDPNP" "Microsoft Terminal Services" "Microsoft Corporation" "c:\windows\system32\drprov.dll"

+ "WebClient" "Web Client Network" "Microsoft Corporation" "c:\windows\system32\davclnt.dll"

Стартирайте отново Autoruns => придвижете се до колонката => Scheduled Tasks => посочете следния ред =>

+ "WGASetup.job" "Windows Genuine Advantage Notifications Setup" "Microsoft Corporation" "c:\windows\system32\kb905474\wgasetup.exe"

Натиснете клавиша Del от клавиатурата и потвърдете с YES.

След това ръчно намерете и изтрийте файла:

c:\windows\system32\kb905474\wgasetup.exe

Това трябва да реши проблема. :cool:

  • Автор

Да стана с тази програма :) Имам и 1 последен въпрос и няма да ви измъчвам повече :cheers: да направа ли ,каквото се казва в прозореца или да дам Don´t show ?

Да стана с тази програма :whist: Имам и 1 последен въпрос и няма да ви измъчвам повече :yanim: да направа ли ,каквото се казва в прозореца или да дам Don´t show ?

Да, сложете отметката и натиснете ОК.

Оправихте ли се със стъпките от предишния ми пост ?

Как се държи сега машината ?

От снимката също виждам, че не сте деинсталирали уязвимото приложение => Adobe Reader 8.

Моля деинсталирайте го от Control Panel-a => Add/Remove Programs

И го заменете с Foxit Reader

И още нещо. Добре е да преинсталирате Skype, като използвате следните настройки:

(описанието е взето от Night_Raven)

Деинсталирай Skype и го инсталирай без диспечера на на екстрите. Те позволяват на Skype да ползва разни допълнения - детектори на лъжата, допълнения за настроения и всякакви други шарении. Инсталацията на екстрите води и до инсталиране на SkypePM.exe, който се вижда в Task Manager и някои хора се чудят какво е, защото понякога гълта доста памет. Именно с тези екстри се инсталира и Skype4COM протокола, чрез който тази гадинка и всичкия спам, който циркулира в Skype, се разпространява. Традиционния метод е следния: даден потребител е залъган да изтегли и стартира дадена програма, която обещава да добави икони/да разбие парола/нещо друго. Тази програма обаче не е нищо повече от скрипт (VBS в повечето случаи), който не прави нищо от обещаното, а използва споменатия по-горе протокол да се разпрати на всички абонати в списъка.

Ако този протокол го няма, дори и да се стартира подобен спам-скрипт, той няма да може да разпрати нищо.

Ето графична илюстрация как да НЕ се инсталират екстрите:

z5pvs.png

2zgx8gp.png

  • Автор

За Adobe Reader 8 не бях прочел ,че трябва да го изрия :angry: Иначе си качих Foxit Reader-a ,направих това със скайп.Нямал съм никакви оплаквания явно вече съм напълно изчистен !

B-boy[styLe] искам да ти благодаря много ! Без теб щях да изкарам 1 месец най-много ,докато се разбие тотално и сега щях да съм с преинсталиран уиндоус.Благодаря за отделеното време ,което не беше въобще малко ,а напротив,както и за всички съвети благодарение ,на които си оправих машината.Хиляди благодарности отново ,супер си :speak::yanim: и естествено... само kaldata.com :whist:

  • 3 седмици по-късно...

И аз имам същия проблем само ,че като тръгна да свалям каквато и да било програма ме изхвърля от мозилата ...

Значи пратиха ми някакъв линк в скайп аз взех ,че влезнах и ми прееба компа.Преинсталирах никакъв ефект няма ..

В Task managera има няколко измислени ненужни процеса.. Някой ако има идея кво да правя да казва,че си ебало мамата..

e3085f92705c8a14.JPG

ComboFix 09-12-09.04 - Vladimir 12.2009 г. 19:00:55.2.1 - x86

Microsoft Windows XP Professional 5.1.2600.2.1251.359.1033.18.1023.524 [GMT 2:00]

Running from: c:\documents and settings\Vladimir\Desktop\ComboFix.exe

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

C:\autorun.inf

C:\errdmbjlv.bat

C:\ofjzmfrxlydxe.bat

C:\shjxizjnzkn.bat

D:\autorun.inf

D:\errdmbjlv.bat

D:\ofjzmfrxlydxe.bat

D:\shjxizjnzkn.bat

E:\Autorun.inf

E:\errdmbjlv.bat

E:\ofjzmfrxlydxe.bat

E:\shjxizjnzkn.bat

F:\Autorun.inf

F:\errdmbjlv.bat

F:\ofjzmfrxlydxe.bat

F:\shjxizjnzkn.bat

G:\autorun.inf

G:\errdmbjlv.bat

G:\ofjzmfrxlydxe.bat

G:\shjxizjnzkn.bat

.

((((((((((((((((((((((((( Files Created from 2009-11-10 to 2009-12-10 )))))))))))))))))))))))))))))))

.

2009-12-10 16:21 . 2009-12-10 16:21 13432 ----a-w- c:\documents and settings\Vladimir\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-12-10 17:03 . 2009-12-10 14:51 -------- d-----w- c:\documents and settings\Vladimir\Application Data\Skype

2009-12-10 17:00 . 2009-12-10 14:07 2408 ---h--w- c:\program files\xlmzjzilwgizdmwutopdjovqknbcpzpy.mwy

2009-12-10 17:00 . 2009-12-10 13:59 272 ---h--w- c:\program files\bfwzzfexyyqxrqqetevzvq.yib

2009-12-10 16:59 . 2009-12-10 14:07 316 ---h--w- c:\program files\ofjzmfrxlydxeqdegeiziqayvbswmzsekyl.krd

2009-12-10 16:36 . 2009-12-10 15:39 -------- d-----w- c:\program files\NortonInstaller

2009-12-10 16:31 . 2009-12-10 15:39 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller

2009-12-10 16:25 . 2009-12-10 15:09 -------- d-----w- c:\documents and settings\Vladimir\Application Data\uTorrent

2009-12-10 15:26 . 2009-12-10 14:07 138 ---h--w- c:\program files\phmdrlyfuiojresuxwbtdmxwubtypdxkrgua.dqe

2009-12-10 15:14 . 2009-12-10 15:10 -------- d-----w- c:\documents and settings\Vladimir\Application Data\Winamp

2009-12-10 15:14 . 2009-12-10 15:10 -------- d-----w- c:\program files\Winamp

2009-12-10 15:02 . 2009-12-10 14:44 -------- d-----w- c:\program files\The KMPlayer

2009-12-10 15:00 . 2009-12-10 15:00 -------- d-----w- c:\program files\utorrent

2009-12-10 14:56 . 2009-12-10 14:56 56 ---ha-w- c:\windows\system32\ezsidmv.dat

2009-12-10 14:56 . 2009-12-10 14:56 -------- d-----w- c:\documents and settings\Vladimir\Application Data\skypePM

2009-12-10 14:51 . 2009-12-10 14:51 -------- d-----w- c:\program files\Skype

2009-12-10 14:51 . 2009-12-10 14:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype

2009-12-10 14:51 . 2009-12-10 14:51 -------- d-----w- c:\program files\Common Files\Skype

2009-12-10 14:44 . 2009-12-10 14:44 0 ----a-w- c:\windows\nsreg.dat

2009-12-10 14:35 . 2009-12-10 13:49 22720 ----a-w- c:\windows\system32\emptyregdb.dat

2009-12-10 14:08 . 2009-12-10 14:08 -------- d-----w- c:\program files\Realtek Sound Manager

2009-12-10 14:08 . 2009-12-10 14:08 -------- d-----w- c:\program files\AvRack

2009-12-10 14:08 . 2009-12-10 14:07 -------- d--h--w- c:\program files\InstallShield Installation Information

2009-12-10 14:08 . 2009-12-10 13:59 -------- d-----w- c:\program files\Common Files\InstallShield

2009-12-10 14:07 . 2009-12-10 14:07 -------- d-----w- c:\program files\AMD

2009-12-10 14:04 . 2009-12-10 14:04 -------- d-----w- c:\program files\Datecs

2009-12-10 14:02 . 2009-12-10 14:02 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles

2009-12-10 13:59 . 2009-12-10 13:59 4008 ---ha-w- c:\program files\shjxizjnzknfkufeeacryemidhwymxoyc.zcu

2009-12-10 13:53 . 2009-12-10 13:53 -------- d-----w- c:\program files\microsoft frontpage

2009-12-10 13:52 . 2009-12-10 13:52 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat

.

((((((((((((((((((((((((((((( SnapShot@2009-12-10_15.34.42 )))))))))))))))))))))))))))))))))))))))))

.

- 2009-12-10 15:41 . 2009-12-10 14:41 96664 c:\windows\system32\FNTCACHE.DAT

+ 2009-12-10 15:41 . 2009-12-10 16:30 96664 c:\windows\system32\FNTCACHE.DAT

+ 2009-12-10 13:59 . 2009-12-10 17:01 507904 c:\windows\yvfbutlxrkvviataimw.exe

- 2009-12-10 13:59 . 2009-12-10 15:31 507904 c:\windows\yvfbutlxrkvviataimw.exe

+ 2009-12-10 13:59 . 2009-12-10 17:01 507904 c:\windows\xryrhdsbsiqnxmcg.exe

- 2009-12-10 13:59 . 2009-12-10 15:31 507904 c:\windows\xryrhdsbsiqnxmcg.exe

+ 2009-12-10 13:59 . 2009-12-10 17:01 507904 c:\windows\system32\yvfbutlxrkvviataimw.exe

- 2009-12-10 13:59 . 2009-12-10 15:31 507904 c:\windows\system32\yvfbutlxrkvviataimw.exe

+ 2009-12-10 13:59 . 2009-12-10 17:01 507904 c:\windows\system32\xryrhdsbsiqnxmcg.exe

- 2009-12-10 13:59 . 2009-12-10 15:31 507904 c:\windows\system32\xryrhdsbsiqnxmcg.exe

+ 2009-12-10 13:59 . 2009-12-10 17:01 507904 c:\windows\system32\rredzbwliesvlgcmxerrja.exe

- 2009-12-10 13:59 . 2009-12-10 15:31 507904 c:\windows\system32\rredzbwliesvlgcmxerrja.exe

+ 2009-12-10 13:59 . 2009-12-10 17:01 507904 c:\windows\system32\njsnfdufyqazlcuahk.exe

- 2009-12-10 13:59 . 2009-12-10 15:31 507904 c:\windows\system32\njsnfdufyqazlcuahk.exe

- 2009-12-10 13:59 . 2009-12-10 15:31 507904 c:\windows\system32\ljurllermgsthauclqbz.exe

+ 2009-12-10 13:59 . 2009-12-10 17:01 507904 c:\windows\system32\ljurllermgsthauclqbz.exe

- 2009-12-10 13:59 . 2009-12-10 15:31 507904 c:\windows\system32\ezhbspfphyhfqgxci.exe

+ 2009-12-10 13:59 . 2009-12-10 17:01 507904 c:\windows\system32\ezhbspfphyhfqgxci.exe

+ 2009-12-10 13:59 . 2009-12-10 17:01 507904 c:\windows\system32\azljefznjerticxgqwihy.exe

- 2009-12-10 13:59 . 2009-12-10 15:31 507904 c:\windows\system32\azljefznjerticxgqwihy.exe

+ 2009-12-10 13:59 . 2009-12-10 17:01 507904 c:\windows\rredzbwliesvlgcmxerrja.exe

- 2009-12-10 13:59 . 2009-12-10 15:31 507904 c:\windows\rredzbwliesvlgcmxerrja.exe

+ 2009-12-10 13:59 . 2009-12-10 17:01 507904 c:\windows\njsnfdufyqazlcuahk.exe

- 2009-12-10 13:59 . 2009-12-10 15:31 507904 c:\windows\njsnfdufyqazlcuahk.exe

- 2009-12-10 13:59 . 2009-12-10 15:31 507904 c:\windows\ljurllermgsthauclqbz.exe

+ 2009-12-10 13:59 . 2009-12-10 17:01 507904 c:\windows\ljurllermgsthauclqbz.exe

+ 2009-12-10 13:59 . 2009-12-10 17:01 507904 c:\windows\ezhbspfphyhfqgxci.exe

- 2009-12-10 13:59 . 2009-12-10 15:31 507904 c:\windows\ezhbspfphyhfqgxci.exe

- 2009-12-10 13:59 . 2009-12-10 15:31 507904 c:\windows\azljefznjerticxgqwihy.exe

+ 2009-12-10 13:59 . 2009-12-10 17:01 507904 c:\windows\azljefznjerticxgqwihy.exe

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"errdmbjlv"="yvfbutlxrkvviataimw.exe" [2009-12-10 507904]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

"yjhrylr"="c:\docume~1\Vladimir\LOCALS~1\Temp\xryrhdsbsiqnxmcg.exe ." [X]

"xlmzjzilwg"="njsnfdufyqazlcuahk.exe" [2009-12-10 507904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"lvsbht"="njsnfdufyqazlcuahk.exe" [2009-12-10 507904]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-07-20 7110656]

"nwiz"="nwiz.exe" [2005-07-20 1519616]

"NVRaidService"="c:\windows\system32\nvraidservice.exe" [2004-06-11 83968]

"SoundMan"="SOUNDMAN.EXE" [2004-12-22 77824]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-07-20 86016]

"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

"shjxizjnzkn"="c:\docume~1\Vladimir\LOCALS~1\Temp\yvfbutlxrkvviataimw.exe ." [X]

"yjhrylr"="xryrhdsbsiqnxmcg.exe" [2009-12-10 507904]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

"errdmbjlv"="njsnfdufyqazlcuahk.exe" [2009-12-10 507904]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"yjhrylr"="c:\windows\TEMP\azljefznjerticxgqwihy.exe ." [X]

"xlmzjzilwg"="yvfbutlxrkvviataimw.exe" [2009-12-10 507904]

"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-04 44544]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]

"nzyjrfmn"="xryrhdsbsiqnxmcg.exe" [2009-12-10 507904]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

FlexType 2K.lnk - c:\program files\Datecs\FlexType 2K\FType2K.exe [2009-12-10 95232]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 0 (0x0)

"ConsentPromptBehaviorUser"= 0 (0x0)

"EnableInstallerDetection"= 0 (0x0)

"EnableSecureUIAPaths"= 0 (0x0)

"EnableVirtualization"= 0 (0x0)

"PromptOnSecureDesktop"= 0 (0x0)

SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]

@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]

@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]

@="DiskDrive"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]

@="Hdc"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]

@="Keyboard"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]

@="Mouse"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]

@="System"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]

@="Volume"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

.

------- Supplementary Scan -------

.

FF - ProfilePath - c:\documents and settings\Vladimir\Application Data\Mozilla\Firefox\Profiles\j4026pxg.default\

.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-12-10 19:03

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

Completion time: 2009-12-10 19:04:46

ComboFix-quarantined-files.txt 2009-12-10 17:04

ComboFix2.txt 2009-12-10 15:35

Pre-Run: 9 060 462 592 bytes free

Post-Run: 9 038 155 776 bytes free

- - End Of File - - 2BA9EF355DCE96967C096DF956E2E8CC

След сканирането от ComboFix

Гост
Тази тема е заключена за нови отговори.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.