Volledige versie bekijken : problemen



drareg
2 February 2006, 22:23
Kan er me iemand dit logje nakijken ,
op voorhand bedankt.
Logfile of HijackThis v1.99.1
Scan saved at 21:18:55, on 2/02/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\explorer.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFREE.EXE
C:\Program Files\Java\jre1.5.0_05\bin\jucheck.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\AntiVir PersonalEdition Classic\avcenter.exe
C:\Program Files\AntiVir PersonalEdition Classic\avscan.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\JORDY~1.JOR\LOCALS~1\Temp\Rar$EX03.312 \HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00004.exe"
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFREE.EXE"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O16 - DPF: RaptisoftGameLoader - http://www.raptisoft.com/webgames/raptisoftgameloader.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/supergerball/miniclipGameLoader.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} (Sinstaller Class) - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B467A3AF-E45B-4B1B-9983-C035D988FB0F} (VacPro.belgio_ver10) - http://66.194.38.28/dialer/belgio_ver10.CAB
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/4h/player.virtools.com/downloads/player/Install3.0/Installer.exe
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spyspotter/SpSp29952.41optYplkOmji/SpySpotterCabInstall.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Filter: text/html - (no CLSID) - (no file)
O20 - Winlogon Notify: iexplore - ae14e.dll (file missing)
O20 - Winlogon Notify: policies - C:\WINDOWS\system32\i0600ajmedoa0.dll
O23 - Service: AntiVir Scheduler (AntiVirScheduler) - H+BEDV Datentechnik GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

nojs
3 February 2006, 16:15
dag drareg,

ik zie dat je HijackThis gebruikt vanuit een tijdelijke map
maak een nieuwe map aan vb: c:\hjt\hjt.exe

plaats dan een nieuw logje

drareg
7 February 2006, 20:27
oja ,het probleem is dat er contstant popups openen zelf als er geen browser open is ,hier is dan een nieuwe log.
Logfile of HijackThis v1.99.1
Scan saved at 19:23:56, on 02/07/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Java\jre1.5.0_05\bin\jucheck.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\hijhack\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00004.exe"
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKCU\..\Run: [Ldiwy] C:\Program Files\Tkmcmet\Lfsts.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [MNI.UWFX5_0001_MNI] "C:\Documents and Settings\Jordy.JORDY-LI0DOKP1N\Local Settings\Temporary Internet Files\Content.IE5\M9A5CHS7\WinFixer2005ScannerInst all[1].exe"
O4 - HKCU\..\Run: [NI.UWFX5_0001_NI530211] "C:\Documents and Settings\Laura.JORDY-LI0DOKP1N\Local Settings\Temporary Internet Files\Content.IE5\R4OUCHGD\WinFixerScannerInstall[1].exe" -nag
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Spyware Cleaner] "C:\Program Files\Spyware Cleaner\SpywareCleaner.Exe" /boot
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZNxdm414YYBE
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O16 - DPF: RaptisoftGameLoader - http://www.raptisoft.com/webgames/raptisoftgameloader.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/supergerball/miniclipGameLoader.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} (Sinstaller Class) - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B467A3AF-E45B-4B1B-9983-C035D988FB0F} (VacPro.belgio_ver10) - http://66.194.38.28/dialer/belgio_ver10.CAB
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/4h/player.virtools.com/downloads/player/Install3.0/Installer.exe
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spyspotter/SpSp29952.41optYplkOmji/SpySpotterCabInstall.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Filter: text/html - (no CLSID) - (no file)
O20 - Winlogon Notify: iexplore - ae14e.dll (file missing)
O20 - Winlogon Notify: SMDEn - C:\WINDOWS\system32\en4ol1h31.dll (file missing)
O23 - Service: AntiVir Scheduler (AntiVirScheduler) - H+BEDV Datentechnik GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

nojs
10 February 2006, 19:46
* download CCleaner (www.ccleaner.com) en installeer het maar gebruik het nog niet.

* open HijackThis, klik op "do a systemscan only" en vink de volgende regels aan

F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00004.exe"
O4 - HKCU\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKCU\..\Run: [Ldiwy] C:\Program Files\Tkmcmet\Lfsts.exe
O4 - HKCU\..\Run: [Spyware Cleaner] "C:\Program Files\Spyware Cleaner\SpywareCleaner.Exe" /boot
O4 - HKCU\..\Run: [MNI.UWFX5_0001_MNI] "C:\Documents and Settings\Jordy.JORDY-LI0DOKP1N\Local Settings\Temporary Internet Files\Content.IE5\M9A5CHS7\WinFixer2005ScannerInst all[1].exe"
O4 - HKCU\..\Run: [NI.UWFX5_0001_NI530211] "C:\Documents and Settings\Laura.JORDY-LI0DOKP1N\Local Settings\Temporary Internet Files\Content.IE5\R4OUCHGD\WinFixerScannerInstall[1].exe" -nag
O4 - HKCU\..\Run: [Ldiwy] C:\Program Files\Tkmcmet\Lfsts.exe
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} (Sinstaller Class) - http://dm.screensavers.com/dm/instal...sinstaller.cab
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spysp...CabInstall.cab
O18 - Filter: text/html - (no CLSID) - (no file)
O20 - Winlogon Notify: iexplore - ae14e.dll (file missing)
O20 - Winlogon Notify: policies - C:\WINDOWS\system32\i0600ajmedoa0.dll

sluit nu al je andere vensters en browsers behalve hijackThis en klik op "fix checked"


* herstart nu je pc in veilige modus (http://users.pandora.be/marcvn/spyware/1378056.htm) en verwijder de volgende mappen indien aanwezig:

C:\Program Files\Internet Optimizer
C:\Program Files\Tkmcmet\
C:\Program Files\Spyware Cleaner\
C:\Program Files\Tkmcmet\
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00004.exe

als je dit gedaan hebt, start je Ccleaner op en druk je rechtsonder op "opschonen"

* Herstart je pc

* Download de L2Mfix hier (http://www.atribune.org/downloads/l2mfix.exe).
Plaats het bestand op je buroblad. Klik op l2mfix.exe.
Klik op "Accept". Zorg dat de l2mfix-map op je bureaublad geplaatst wordt. Klik op "Install".
Op je bureaublad open je de map l2mfix.
Klik op l2fix.bat.
Klik op "1" om optie te 1 selecteren: Run Find Log.
Dit gaat even duren. Na een tijdje wordt er een kladblokbestand geopend.
Kopieer en plak de inhoud van dit bestand in je volgende post.

Let op: Gebruik GEEN andere bestanden uit de map l2mfix!

post dan een nieuw HijackThis logje en het logje van L2Mfix

robbedoeske_007
10 February 2006, 21:17
amaai nojs hoe doe jij dat ??

nojs
10 February 2006, 21:30
als je dat wil weten voeg mij toe op msn
maar niet in dit topic aub!

oja: je leert dat gewoon hoor op SWI ;)

drareg
14 February 2006, 21:18
hier dan de logjes
Groeten

L2MFIX find log 010406
These are the registry keys present
************************************************** ********************************
Winlogon/notify:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00, 2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00, 74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00, 79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00, 79,00,2e,00,64,00,\
6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SMDEn]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\g440lehm1h4a.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00, 79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
************************************************** ********************************
useragent:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Internet Settings\User Agent\Post Platform]
"{15CBFC49-630D-8472-388D-602DBEF75482}"=""
************************************************** ********************************
Shell Extension key:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Eigenschappenvenster van multimediabestand"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM-scannerbeheer"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="Het tabblad Beveiliging"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="Eigenschappenblad voor OLE-docbestand"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell-uitbreidingen voor delen"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Configuratiescherm-uitbreiding Beeldschermadapter"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Configuratiescherm-uitbreiding Monitor"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Configuratiescherm-uitbreiding Beeldscherm-panning"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="Het tabblad Beveiliging"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibiliteitspagina"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Knipselgegevensverwerker van shell"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Schijfkopieer-uitbreiding"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell-uitbreidingen voor Microsoft Windows Network-objecten"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM-monitorbeheer"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM-printerbeheer"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell-uitbreidingen voor bestandscompressie"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Shell-uitbreiding voor Web Printer"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Snelmenu Codering"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Werkmap"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal-pictogramuitbreiding"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC-profiel"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Het tabblad Beveiliging voor printers"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell-uitbreidingen voor delen"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO-extensie"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto-handtekeningextensie"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Netwerkverbindingen"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Netwerkverbindingen"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners en camera's"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners en camera's"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners en camera's"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners en camera's"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners en camera's"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell-uitbreidingen voor Windows Script Host"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Geplande taken"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taakbalk en menu Start"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Zoeken"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help en ondersteuning"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help en ondersteuning"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Uitvoeren..."
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Lettertypen"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Systeembeheer"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet-werkbalk"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Downloadstatus"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Uitgebreide shell-map"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Uitgebreide shell-map 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft-browserbalk"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Zoekbalk"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Mediabalk"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="Zoeken binnen deelvenster"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Zoeken op het web"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Hulpprogramma met opties voor registerboomstructuur"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Adres"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoAanvullen"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU-lijst voor AutoAanvullen"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Aangepaste MRU-lijst voor AutoAanvullen"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Toegankelijk"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Pop-upbalk Volgen"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Parser voor adresbalk"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Lijst voor AutoAanvullen: Microsoft Geschiedenis"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Lijst voor AutoAanvullen: Microsoft Shell-map"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft-container met meervoudige lijst voor AutoAanvullen"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Sitemenu van shell-band"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="Gebruikersondersteuning"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Globale mapinstellingen"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url-geschiedenisservice"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="Geschiedenis"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Tijdelijke Internet-bestanden"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Tijdelijke Internet-bestanden"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url-zoeken Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite-welkomstscherm"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="Het Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer-band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="Cachemap van ActiveX"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Map met abonnementen"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Toepassingsbeheer"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Programma voor inventarisatie van geā€¹nstalleerde toepassingen"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI- en bestandsextractieprogramma voor miniaturen"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Informatie over de handler voor miniatuurweergaven (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML-extractie voor miniatuurweergaven"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Wizard Webpublicaties"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Afdrukken via het web bestellen"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell-object voor publicatiewizard"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Wizard Passport"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="Gebruikersaccounts"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Kanaal-bestand"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Kanaal-snelkoppeling"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Handler-object voor kanalen"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Map Off line bestanden"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="&Personen..."
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
"{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Webmappen"
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
"{0006F045-0000-0000-C000-000000000046}"="Microsoft Outlook Custom Icon Handler"
"{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
"{A70C977A-BF00-412C-90B7-034C51DA2439}"="NvCpl DesktopContext Class"
"{FFB699E0-306A-11d3-8BD1-00104B6F7516}"="Play on my TV helper"
"{1CDB2949-8F65-4355-8456-263E7C208A5D}"="Desktop Explorer"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}"="Desktop Explorer Menu"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A48}"="nView Desktop Context Menu"
"{B6FBC5CC-862D-455E-8BE0-853D046492FF}"=""
"{2704655D-57CB-4010-9AF6-61BF600B4E84}"=""
"{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
"{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
"{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
"{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
"{63D6D65A-3EBA-4DA6-B950-88A79C74B325}"=""
"{5E2121EE-0300-11D4-8D3B-444553540000}"="st"
"{386870CC-D4A7-4B82-B26B-8910F33D8361}"=""
"{05C19BF2-D79D-464A-AED2-F8E8A7E23633}"=""
"{04B2EEC1-2498-40D4-9D53-982A70AACB84}"=""
"{B1CAD395-0BAF-4340-9749-7817EAC0CF19}"=""
"{D3772E58-0B35-4C14-A275-838BA8FBC224}"=""
"{A3C30D7D-89AA-4E60-90EC-330FBD6A4874}"=""
"{1EFA3CD3-D163-4148-B561-3EE823CD05D6}"=""
"{48B4BC5B-AAF5-4341-A017-05906FD7191E}"=""
"{45F25CB5-C564-470F-A5EC-282D1E0A782A}"=""
"{23FD58A0-B3A1-4815-80C9-E52156ECBB1B}"=""
"{63178059-912F-4429-901E-44C69966E00C}"=""
"{673B66E4-70BD-48C3-9B64-58DFB8088062}"=""
"{E47F14A5-4C48-4C7B-B747-64D49B917B2D}"=""
"{21569614-B795-46b1-85F4-E737A8DC09AD}"="Shell Search Band"
"{9837B45F-B00F-449A-8273-E3D09D11C9C5}"=""
"{3DF59A91-6C0E-47FE-9559-C38CE8D67E50}"=""
"{453958F9-AB2B-4F89-AEA2-16D37F17BE2F}"=""
"{05BAAD44-2ADF-4584-BE30-11013779F63B}"=""
"{7FA417B8-2AF9-49BD-998D-E0C59FC6EF72}"=""
"{C4536B7A-0860-4612-9938-85B2E772028F}"=""
"{DAC516A5-D499-4A3F-B49D-C6AD69774AE0}"=""
"{7E1360CC-1786-4321-AEFF-D4D000825D60}"=""
"{838D1330-C461-447C-80AD-7160FC94A0FF}"=""
"{EBC62502-57FA-4239-A601-70E26110E65F}"=""
"{53CAC740-DC52-4F53-9203-D82D90872611}"=""
"{48A9EB19-E907-47D8-8AE8-5AE89A66572F}"=""
"{8A0CC9B4-C0C8-400E-9CFB-77083A284988}"=""
"{F9ED3EE1-7F08-41CB-92AD-772CDDDF0D46}"=""
"{190EF3D1-7D5D-439B-A65E-4EA4A6EDC6FD}"=""
"{DDBD2897-91F7-4449-A92A-34603F31C853}"=""
"{020A0DEB-5CCA-467F-B291-5D317542147F}"=""
"{23816C02-FFD3-4CF3-8D46-F6295A23987A}"=""
"{3244A359-225A-4D90-A62A-F08B42CC0C60}"=""
"{4C1EB535-DC08-4E98-B654-D17E26E645B5}"=""
"{42399C51-EC31-4EE2-ADDE-6BFF0AA2023C}"=""
"{C57D2707-1397-4829-8A96-10031AD51CCA}"=""
"{EA005036-3FB9-4DC4-A377-3999F9760C76}"=""
"{A7AB5D1C-8062-4DD4-A413-F17C9AD91B86}"=""
"{99FE5495-2E14-429D-95D8-96E5EF6582C2}"=""
"{914D0392-D10B-443E-AA72-70284A30DED0}"=""
"{EA0B92ED-4979-4D6E-A452-86D10102B10D}"=""
"{A7CE548B-EBF2-4708-ACC4-9954BF4D8428}"=""
"{8C7CF032-89DB-471A-A889-D229FDF53C68}"=""
"{9DCD4AA4-2668-444B-9F62-ED7874514B39}"=""
"{3849C970-A85A-47CC-BF89-9E539C76C2A6}"=""
"{248155AF-6F8E-4148-95A9-CC14C8A9F49D}"=""
"{EC5CC6E2-EA5B-4699-BC8F-CCF3E2A7C9EA}"=""
"{CA775FA8-B2FA-44D7-9FB3-4607D99A8BD5}"=""
"{B06654B1-8C98-4C33-B619-581BFABACE7D}"=""
"{5355C5BE-01D6-4DBE-A40A-6FAF01789560}"=""
"{A1202C04-3329-417D-9403-0701F86DA55E}"=""
"{1C2989EE-A216-447D-878C-E3A106D84F1A}"=""
"{45AC2688-0253-4ED8-97DE-B5370FA7D48A}"="Shell Extension for Malware scanning"
"{423CA5D7-001E-4BE9-9D8E-6CB43361D60E}"=""
"{F0DD2E29-32D0-4DA6-9948-49C57DE896BF}"=""
"{BD636763-DD14-4E73-8E6E-C77C667A7F27}"=""
"{2F995F7E-3B55-40C9-B8A5-357E8FE43833}"=""
"{42227601-B106-43BB-8E57-15A59F5F28F9}"=""
"{F8409000-90B3-417A-86B4-1329AC0FABB6}"=""
"{BB6C23F1-6C33-4475-ABE0-7023CEB7E4D1}"=""
"{A67498EC-F29C-4A90-BBD8-7E68383EB54D}"=""
"{44A9AAB5-94D7-45AD-9B2A-0577056FCD90}"=""
"{65B74A34-447A-48BF-A76A-94704A182470}"=""
"{83220702-C7AB-41FD-A506-1B817B530ABA}"=""
"{97FEAB8E-A66D-4B4D-9DFE-16CAE99D58F5}"=""
"{3233A6CA-2EB8-43F3-8A61-95F05B1FDA51}"=""
"{C2302906-4C06-40FE-9B2E-8D9DFA9064D9}"=""
"{BC1116B8-DFD6-4A29-A789-964FA2E6F4BF}"=""
"{C3F67278-2199-4D38-BF50-B70E633D7B73}"=""
************************************************** ********************************
HKEY ROOT CLASSIDS:
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{B6FBC5CC-862D-455E-8BE0-853D046492FF}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{B6FBC5CC-862D-455E-8BE0-853D046492FF}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{B6FBC5CC-862D-455E-8BE0-853D046492FF}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{B6FBC5CC-862D-455E-8BE0-853D046492FF}\InprocServer32]
@="C:\\WINDOWS\\system32\\ko1394.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{2704655D-57CB-4010-9AF6-61BF600B4E84}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{2704655D-57CB-4010-9AF6-61BF600B4E84}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{2704655D-57CB-4010-9AF6-61BF600B4E84}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{2704655D-57CB-4010-9AF6-61BF600B4E84}\InprocServer32]
@="C:\\WINDOWS\\system32\\mericons.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{63D6D65A-3EBA-4DA6-B950-88A79C74B325}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{63D6D65A-3EBA-4DA6-B950-88A79C74B325}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{63D6D65A-3EBA-4DA6-B950-88A79C74B325}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{63D6D65A-3EBA-4DA6-B950-88A79C74B325}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{386870CC-D4A7-4B82-B26B-8910F33D8361}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{386870CC-D4A7-4B82-B26B-8910F33D8361}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{386870CC-D4A7-4B82-B26B-8910F33D8361}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{386870CC-D4A7-4B82-B26B-8910F33D8361}\InprocServer32]
@="C:\\WINDOWS\\system32\\kirberos.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{05C19BF2-D79D-464A-AED2-F8E8A7E23633}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{05C19BF2-D79D-464A-AED2-F8E8A7E23633}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{05C19BF2-D79D-464A-AED2-F8E8A7E23633}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{05C19BF2-D79D-464A-AED2-F8E8A7E23633}\InprocServer32]
@="C:\\WINDOWS\\system32\\ajdiosrv.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{04B2EEC1-2498-40D4-9D53-982A70AACB84}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{04B2EEC1-2498-40D4-9D53-982A70AACB84}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{04B2EEC1-2498-40D4-9D53-982A70AACB84}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{04B2EEC1-2498-40D4-9D53-982A70AACB84}\InprocServer32]
@="C:\\WINDOWS\\system32\\qtartz.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{B1CAD395-0BAF-4340-9749-7817EAC0CF19}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{B1CAD395-0BAF-4340-9749-7817EAC0CF19}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{B1CAD395-0BAF-4340-9749-7817EAC0CF19}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{B1CAD395-0BAF-4340-9749-7817EAC0CF19}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{D3772E58-0B35-4C14-A275-838BA8FBC224}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{D3772E58-0B35-4C14-A275-838BA8FBC224}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{D3772E58-0B35-4C14-A275-838BA8FBC224}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{D3772E58-0B35-4C14-A275-838BA8FBC224}\InprocServer32]
@="C:\\WINDOWS\\system32\\wmcsapi.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{A3C30D7D-89AA-4E60-90EC-330FBD6A4874}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{A3C30D7D-89AA-4E60-90EC-330FBD6A4874}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{A3C30D7D-89AA-4E60-90EC-330FBD6A4874}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{A3C30D7D-89AA-4E60-90EC-330FBD6A4874}\InprocServer32]
@="C:\\WINDOWS\\system32\\scvsvc.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{1EFA3CD3-D163-4148-B561-3EE823CD05D6}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{1EFA3CD3-D163-4148-B561-3EE823CD05D6}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{1EFA3CD3-D163-4148-B561-3EE823CD05D6}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{1EFA3CD3-D163-4148-B561-3EE823CD05D6}\InprocServer32]
@="C:\\WINDOWS\\system32\\mdvcirt.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{48B4BC5B-AAF5-4341-A017-05906FD7191E}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{48B4BC5B-AAF5-4341-A017-05906FD7191E}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{48B4BC5B-AAF5-4341-A017-05906FD7191E}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{48B4BC5B-AAF5-4341-A017-05906FD7191E}\InprocServer32]
@="C:\\WINDOWS\\system32\\cIbview.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{45F25CB5-C564-470F-A5EC-282D1E0A782A}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{45F25CB5-C564-470F-A5EC-282D1E0A782A}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{45F25CB5-C564-470F-A5EC-282D1E0A782A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{45F25CB5-C564-470F-A5EC-282D1E0A782A}\InprocServer32]
@="C:\\WINDOWS\\system32\\uaiplat.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{23FD58A0-B3A1-4815-80C9-E52156ECBB1B}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{23FD58A0-B3A1-4815-80C9-E52156ECBB1B}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{23FD58A0-B3A1-4815-80C9-E52156ECBB1B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{23FD58A0-B3A1-4815-80C9-E52156ECBB1B}\InprocServer32]
@="C:\\WINDOWS\\system32\\pnchdprf.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{63178059-912F-4429-901E-44C69966E00C}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{63178059-912F-4429-901E-44C69966E00C}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{63178059-912F-4429-901E-44C69966E00C}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{63178059-912F-4429-901E-44C69966E00C}\InprocServer32]
@="C:\\WINDOWS\\system32\\mtexch40.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{673B66E4-70BD-48C3-9B64-58DFB8088062}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{673B66E4-70BD-48C3-9B64-58DFB8088062}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{673B66E4-70BD-48C3-9B64-58DFB8088062}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{673B66E4-70BD-48C3-9B64-58DFB8088062}\InprocServer32]
@="C:\\WINDOWS\\system32\\avstream.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{E47F14A5-4C48-4C7B-B747-64D49B917B2D}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{E47F14A5-4C48-4C7B-B747-64D49B917B2D}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{E47F14A5-4C48-4C7B-B747-64D49B917B2D}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{E47F14A5-4C48-4C7B-B747-64D49B917B2D}\InprocServer32]
@="C:\\WINDOWS\\system32\\sinceng.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{9837B45F-B00F-449A-8273-E3D09D11C9C5}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{9837B45F-B00F-449A-8273-E3D09D11C9C5}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{9837B45F-B00F-449A-8273-E3D09D11C9C5}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{9837B45F-B00F-449A-8273-E3D09D11C9C5}\InprocServer32]
@="C:\\WINDOWS\\system32\\mdxml2.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{3DF59A91-6C0E-47FE-9559-C38CE8D67E50}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{3DF59A91-6C0E-47FE-9559-C38CE8D67E50}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{3DF59A91-6C0E-47FE-9559-C38CE8D67E50}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{3DF59A91-6C0E-47FE-9559-C38CE8D67E50}\InprocServer32]
@="C:\\WINDOWS\\system32\\sqrwvdrv.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{453958F9-AB2B-4F89-AEA2-16D37F17BE2F}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{453958F9-AB2B-4F89-AEA2-16D37F17BE2F}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{453958F9-AB2B-4F89-AEA2-16D37F17BE2F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{453958F9-AB2B-4F89-AEA2-16D37F17BE2F}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{05BAAD44-2ADF-4584-BE30-11013779F63B}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{05BAAD44-2ADF-4584-BE30-11013779F63B}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{05BAAD44-2ADF-4584-BE30-11013779F63B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{05BAAD44-2ADF-4584-BE30-11013779F63B}\InprocServer32]
@="C:\\WINDOWS\\system32\\cqrpol.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{7FA417B8-2AF9-49BD-998D-E0C59FC6EF72}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{7FA417B8-2AF9-49BD-998D-E0C59FC6EF72}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{7FA417B8-2AF9-49BD-998D-E0C59FC6EF72}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{7FA417B8-2AF9-49BD-998D-E0C59FC6EF72}\InprocServer32]
@="C:\\WINDOWS\\system32\\afmpvcno.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{C4536B7A-0860-4612-9938-85B2E772028F}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{C4536B7A-0860-4612-9938-85B2E772028F}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{C4536B7A-0860-4612-9938-85B2E772028F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{C4536B7A-0860-4612-9938-85B2E772028F}\InprocServer32]
@="C:\\WINDOWS\\system32\\mdrle32.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{DAC516A5-D499-4A3F-B49D-C6AD69774AE0}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{DAC516A5-D499-4A3F-B49D-C6AD69774AE0}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{DAC516A5-D499-4A3F-B49D-C6AD69774AE0}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{DAC516A5-D499-4A3F-B49D-C6AD69774AE0}\InprocServer32]
@="C:\\WINDOWS\\system32\\dgsrslvr.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{7E1360CC-1786-4321-AEFF-D4D000825D60}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{7E1360CC-1786-4321-AEFF-D4D000825D60}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{7E1360CC-1786-4321-AEFF-D4D000825D60}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{7E1360CC-1786-4321-AEFF-D4D000825D60}\InprocServer32]
@="C:\\WINDOWS\\system32\\cpmaddin.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{838D1330-C461-447C-80AD-7160FC94A0FF}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{838D1330-C461-447C-80AD-7160FC94A0FF}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{838D1330-C461-447C-80AD-7160FC94A0FF}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{838D1330-C461-447C-80AD-7160FC94A0FF}\InprocServer32]
@="C:\\WINDOWS\\system32\\mhvcirt.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{EBC62502-57FA-4239-A601-70E26110E65F}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{EBC62502-57FA-4239-A601-70E26110E65F}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{EBC62502-57FA-4239-A601-70E26110E65F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{EBC62502-57FA-4239-A601-70E26110E65F}\InprocServer32]
@="C:\\WINDOWS\\system32\\pxlstore.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{53CAC740-DC52-4F53-9203-D82D90872611}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{53CAC740-DC52-4F53-9203-D82D90872611}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{53CAC740-DC52-4F53-9203-D82D90872611}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{53CAC740-DC52-4F53-9203-D82D90872611}\InprocServer32]
@="C:\\WINDOWS\\system32\\cqsetacl.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{48A9EB19-E907-47D8-8AE8-5AE89A66572F}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{48A9EB19-E907-47D8-8AE8-5AE89A66572F}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{48A9EB19-E907-47D8-8AE8-5AE89A66572F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{48A9EB19-E907-47D8-8AE8-5AE89A66572F}\InprocServer32]
@="C:\\WINDOWS\\system32\\mevcirt.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{8A0CC9B4-C0C8-400E-9CFB-77083A284988}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{8A0CC9B4-C0C8-400E-9CFB-77083A284988}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{8A0CC9B4-C0C8-400E-9CFB-77083A284988}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{8A0CC9B4-C0C8-400E-9CFB-77083A284988}\InprocServer32]
@="C:\\WINDOWS\\system32\\syesrv.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{F9ED3EE1-7F08-41CB-92AD-772CDDDF0D46}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F9ED3EE1-7F08-41CB-92AD-772CDDDF0D46}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F9ED3EE1-7F08-41CB-92AD-772CDDDF0D46}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F9ED3EE1-7F08-41CB-92AD-772CDDDF0D46}\InprocServer32]
@="C:\\WINDOWS\\system32\\merepl40.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{190EF3D1-7D5D-439B-A65E-4EA4A6EDC6FD}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{190EF3D1-7D5D-439B-A65E-4EA4A6EDC6FD}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{190EF3D1-7D5D-439B-A65E-4EA4A6EDC6FD}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{190EF3D1-7D5D-439B-A65E-4EA4A6EDC6FD}\InprocServer32]
@="C:\\WINDOWS\\system32\\mwident.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{DDBD2897-91F7-4449-A92A-34603F31C853}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{DDBD2897-91F7-4449-A92A-34603F31C853}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{DDBD2897-91F7-4449-A92A-34603F31C853}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{DDBD2897-91F7-4449-A92A-34603F31C853}\InprocServer32]
@="C:\\WINDOWS\\system32\\itmontr.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{020A0DEB-5CCA-467F-B291-5D317542147F}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{020A0DEB-5CCA-467F-B291-5D317542147F}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{020A0DEB-5CCA-467F-B291-5D317542147F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{020A0DEB-5CCA-467F-B291-5D317542147F}\InprocServer32]
@="C:\\WINDOWS\\system32\\unrcntra.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{23816C02-FFD3-4CF3-8D46-F6295A23987A}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{23816C02-FFD3-4CF3-8D46-F6295A23987A}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{23816C02-FFD3-4CF3-8D46-F6295A23987A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{23816C02-FFD3-4CF3-8D46-F6295A23987A}\InprocServer32]
@="C:\\WINDOWS\\system32\\tfpmib.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{3244A359-225A-4D90-A62A-F08B42CC0C60}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{3244A359-225A-4D90-A62A-F08B42CC0C60}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{3244A359-225A-4D90-A62A-F08B42CC0C60}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{3244A359-225A-4D90-A62A-F08B42CC0C60}\InprocServer32]
@="C:\\WINDOWS\\system32\\oqedlg.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{4C1EB535-DC08-4E98-B654-D17E26E645B5}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{4C1EB535-DC08-4E98-B654-D17E26E645B5}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{4C1EB535-DC08-4E98-B654-D17E26E645B5}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{4C1EB535-DC08-4E98-B654-D17E26E645B5}\InprocServer32]
@="C:\\WINDOWS\\system32\\mqorc32r.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{42399C51-EC31-4EE2-ADDE-6BFF0AA2023C}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{42399C51-EC31-4EE2-ADDE-6BFF0AA2023C}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{42399C51-EC31-4EE2-ADDE-6BFF0AA2023C}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{42399C51-EC31-4EE2-ADDE-6BFF0AA2023C}\InprocServer32]
@="C:\\WINDOWS\\system32\\djtrans.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{C57D2707-1397-4829-8A96-10031AD51CCA}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{C57D2707-1397-4829-8A96-10031AD51CCA}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{C57D2707-1397-4829-8A96-10031AD51CCA}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{C57D2707-1397-4829-8A96-10031AD51CCA}\InprocServer32]
@="C:\\WINDOWS\\system32\\smnike.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{EA005036-3FB9-4DC4-A377-3999F9760C76}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{EA005036-3FB9-4DC4-A377-3999F9760C76}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{EA005036-3FB9-4DC4-A377-3999F9760C76}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{EA005036-3FB9-4DC4-A377-3999F9760C76}\InprocServer32]
@="C:\\WINDOWS\\system32\\samedia.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{A7AB5D1C-8062-4DD4-A413-F17C9AD91B86}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{A7AB5D1C-8062-4DD4-A413-F17C9AD91B86}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{A7AB5D1C-8062-4DD4-A413-F17C9AD91B86}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{A7AB5D1C-8062-4DD4-A413-F17C9AD91B86}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{99FE5495-2E14-429D-95D8-96E5EF6582C2}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{99FE5495-2E14-429D-95D8-96E5EF6582C2}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{99FE5495-2E14-429D-95D8-96E5EF6582C2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{99FE5495-2E14-429D-95D8-96E5EF6582C2}\InprocServer32]
@="C:\\WINDOWS\\system32\\sjorprop.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{914D0392-D10B-443E-AA72-70284A30DED0}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{914D0392-D10B-443E-AA72-70284A30DED0}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{914D0392-D10B-443E-AA72-70284A30DED0}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{914D0392-D10B-443E-AA72-70284A30DED0}\InprocServer32]
@="C:\\WINDOWS\\system32\\wlnsrv.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{EA0B92ED-4979-4D6E-A452-86D10102B10D}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{EA0B92ED-4979-4D6E-A452-86D10102B10D}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{EA0B92ED-4979-4D6E-A452-86D10102B10D}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{EA0B92ED-4979-4D6E-A452-86D10102B10D}\InprocServer32]
@="C:\\WINDOWS\\system32\\wuvdmoe2.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{A7CE548B-EBF2-4708-ACC4-9954BF4D8428}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{A7CE548B-EBF2-4708-ACC4-9954BF4D8428}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{A7CE548B-EBF2-4708-ACC4-9954BF4D8428}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{A7CE548B-EBF2-4708-ACC4-9954BF4D8428}\InprocServer32]
@="C:\\WINDOWS\\system32\\futlib.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{8C7CF032-89DB-471A-A889-D229FDF53C68}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{8C7CF032-89DB-471A-A889-D229FDF53C68}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{8C7CF032-89DB-471A-A889-D229FDF53C68}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{8C7CF032-89DB-471A-A889-D229FDF53C68}\InprocServer32]
@="C:\\WINDOWS\\system32\\wwninet.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{9DCD4AA4-2668-444B-9F62-ED7874514B39}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{9DCD4AA4-2668-444B-9F62-ED7874514B39}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{9DCD4AA4-2668-444B-9F62-ED7874514B39}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{9DCD4AA4-2668-444B-9F62-ED7874514B39}\InprocServer32]
@="C:\\WINDOWS\\system32\\dyj0011me.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{3849C970-A85A-47CC-BF89-9E539C76C2A6}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{3849C970-A85A-47CC-BF89-9E539C76C2A6}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{3849C970-A85A-47CC-BF89-9E539C76C2A6}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{3849C970-A85A-47CC-BF89-9E539C76C2A6}\InprocServer32]
@="C:\\WINDOWS\\system32\\woadmod.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{248155AF-6F8E-4148-95A9-CC14C8A9F49D}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{248155AF-6F8E-4148-95A9-CC14C8A9F49D}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{248155AF-6F8E-4148-95A9-CC14C8A9F49D}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{248155AF-6F8E-4148-95A9-CC14C8A9F49D}\InprocServer32]
@="C:\\WINDOWS\\system32\\scnceng.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{EC5CC6E2-EA5B-4699-BC8F-CCF3E2A7C9EA}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{EC5CC6E2-EA5B-4699-BC8F-CCF3E2A7C9EA}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{EC5CC6E2-EA5B-4699-BC8F-CCF3E2A7C9EA}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{EC5CC6E2-EA5B-4699-BC8F-CCF3E2A7C9EA}\InprocServer32]
@="C:\\WINDOWS\\system32\\sdorprop.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{CA775FA8-B2FA-44D7-9FB3-4607D99A8BD5}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{CA775FA8-B2FA-44D7-9FB3-4607D99A8BD5}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{CA775FA8-B2FA-44D7-9FB3-4607D99A8BD5}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{CA775FA8-B2FA-44D7-9FB3-4607D99A8BD5}\InprocServer32]
@="C:\\WINDOWS\\system32\\jidw400.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{B06654B1-8C98-4C33-B619-581BFABACE7D}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{B06654B1-8C98-4C33-B619-581BFABACE7D}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{B06654B1-8C98-4C33-B619-581BFABACE7D}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{B06654B1-8C98-4C33-B619-581BFABACE7D}\InprocServer32]
@="C:\\WINDOWS\\system32\\VXAME.DLL"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{5355C5BE-01D6-4DBE-A40A-6FAF01789560}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{5355C5BE-01D6-4DBE-A40A-6FAF01789560}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{5355C5BE-01D6-4DBE-A40A-6FAF01789560}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{5355C5BE-01D6-4DBE-A40A-6FAF01789560}\InprocServer32]
@="C:\\WINDOWS\\system32\\mvcpxl32.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{A1202C04-3329-417D-9403-0701F86DA55E}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{A1202C04-3329-417D-9403-0701F86DA55E}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{A1202C04-3329-417D-9403-0701F86DA55E}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{A1202C04-3329-417D-9403-0701F86DA55E}\InprocServer32]
@="C:\\WINDOWS\\system32\\abcups.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{1C2989EE-A216-447D-878C-E3A106D84F1A}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{1C2989EE-A216-447D-878C-E3A106D84F1A}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{1C2989EE-A216-447D-878C-E3A106D84F1A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{1C2989EE-A216-447D-878C-E3A106D84F1A}\InprocServer32]
@="C:\\WINDOWS\\system32\\mxc40loc.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{423CA5D7-001E-4BE9-9D8E-6CB43361D60E}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{423CA5D7-001E-4BE9-9D8E-6CB43361D60E}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{423CA5D7-001E-4BE9-9D8E-6CB43361D60E}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{423CA5D7-001E-4BE9-9D8E-6CB43361D60E}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{F0DD2E29-32D0-4DA6-9948-49C57DE896BF}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F0DD2E29-32D0-4DA6-9948-49C57DE896BF}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F0DD2E29-32D0-4DA6-9948-49C57DE896BF}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F0DD2E29-32D0-4DA6-9948-49C57DE896BF}\InprocServer32]
@="C:\\WINDOWS\\system32\\wcv9vcm.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{BD636763-DD14-4E73-8E6E-C77C667A7F27}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{BD636763-DD14-4E73-8E6E-C77C667A7F27}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{BD636763-DD14-4E73-8E6E-C77C667A7F27}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{BD636763-DD14-4E73-8E6E-C77C667A7F27}\InprocServer32]
@="C:\\WINDOWS\\system32\\wldmtp.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{2F995F7E-3B55-40C9-B8A5-357E8FE43833}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{2F995F7E-3B55-40C9-B8A5-357E8FE43833}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{2F995F7E-3B55-40C9-B8A5-357E8FE43833}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{2F995F7E-3B55-40C9-B8A5-357E8FE43833}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{42227601-B106-43BB-8E57-15A59F5F28F9}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{42227601-B106-43BB-8E57-15A59F5F28F9}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{42227601-B106-43BB-8E57-15A59F5F28F9}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{42227601-B106-43BB-8E57-15A59F5F28F9}\InprocServer32]
@="C:\\WINDOWS\\system32\\kndcan.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{F8409000-90B3-417A-86B4-1329AC0FABB6}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F8409000-90B3-417A-86B4-1329AC0FABB6}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F8409000-90B3-417A-86B4-1329AC0FABB6}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F8409000-90B3-417A-86B4-1329AC0FABB6}\InprocServer32]
@="C:\\WINDOWS\\system32\\dcnwsock.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{BB6C23F1-6C33-4475-ABE0-7023CEB7E4D1}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{BB6C23F1-6C33-4475-ABE0-7023CEB7E4D1}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{BB6C23F1-6C33-4475-ABE0-7023CEB7E4D1}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{BB6C23F1-6C33-4475-ABE0-7023CEB7E4D1}\InprocServer32]
@="C:\\WINDOWS\\system32\\wopsrcwp.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{A67498EC-F29C-4A90-BBD8-7E68383EB54D}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{A67498EC-F29C-4A90-BBD8-7E68383EB54D}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{A67498EC-F29C-4A90-BBD8-7E68383EB54D}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{A67498EC-F29C-4A90-BBD8-7E68383EB54D}\InprocServer32]
@="C:\\WINDOWS\\system32\\iertrmgr.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{44A9AAB5-94D7-45AD-9B2A-0577056FCD90}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{44A9AAB5-94D7-45AD-9B2A-0577056FCD90}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{44A9AAB5-94D7-45AD-9B2A-0577056FCD90}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{44A9AAB5-94D7-45AD-9B2A-0577056FCD90}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{65B74A34-447A-48BF-A76A-94704A182470}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{65B74A34-447A-48BF-A76A-94704A182470}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{65B74A34-447A-48BF-A76A-94704A182470}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{65B74A34-447A-48BF-A76A-94704A182470}\InprocServer32]
@="C:\\WINDOWS\\system32\\mddsrv32.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{83220702-C7AB-41FD-A506-1B817B530ABA}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{83220702-C7AB-41FD-A506-1B817B530ABA}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{83220702-C7AB-41FD-A506-1B817B530ABA}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{83220702-C7AB-41FD-A506-1B817B530ABA}\InprocServer32]
@="C:\\WINDOWS\\system32\\ahmlib.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{97FEAB8E-A66D-4B4D-9DFE-16CAE99D58F5}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{97FEAB8E-A66D-4B4D-9DFE-16CAE99D58F5}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{97FEAB8E-A66D-4B4D-9DFE-16CAE99D58F5}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{97FEAB8E-A66D-4B4D-9DFE-16CAE99D58F5}\InprocServer32]
@="C:\\WINDOWS\\system32\\tlbyuv.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{3233A6CA-2EB8-43F3-8A61-95F05B1FDA51}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{3233A6CA-2EB8-43F3-8A61-95F05B1FDA51}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{3233A6CA-2EB8-43F3-8A61-95F05B1FDA51}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{3233A6CA-2EB8-43F3-8A61-95F05B1FDA51}\InprocServer32]
@="C:\\WINDOWS\\system32\\sLfrdm.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{C2302906-4C06-40FE-9B2E-8D9DFA9064D9}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{C2302906-4C06-40FE-9B2E-8D9DFA9064D9}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{C2302906-4C06-40FE-9B2E-8D9DFA9064D9}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{C2302906-4C06-40FE-9B2E-8D9DFA9064D9}\InprocServer32]
@="C:\\WINDOWS\\system32\\jkdw400.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{BC1116B8-DFD6-4A29-A789-964FA2E6F4BF}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{BC1116B8-DFD6-4A29-A789-964FA2E6F4BF}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{BC1116B8-DFD6-4A29-A789-964FA2E6F4BF}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{BC1116B8-DFD6-4A29-A789-964FA2E6F4BF}\InprocServer32]
@="C:\\WINDOWS\\system32\\cnb.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{C3F67278-2199-4D38-BF50-B70E633D7B73}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{C3F67278-2199-4D38-BF50-B70E633D7B73}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{C3F67278-2199-4D38-BF50-B70E633D7B73}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{C3F67278-2199-4D38-BF50-B70E633D7B73}\InprocServer32]
@="C:\\WINDOWS\\system32\\nttid.dll"
"ThreadingModel"="Apartment"
************************************************** ********************************
Files Found are not all bad files:
C:\WINDOWS\SYSTEM32\
avsda.dll Wed 18 Jan 2006 13:06:02 A.... 57.344 56,00 K
cnb.dll Tue 14 Feb 2006 19:58:40 ..S.R 236.944 231,39 K
mshtml.dll Thu 24 Nov 2005 1:39:22 A.... 3.013.632 2,87 M
nttid.dll Tue 14 Feb 2006 20:04:16 ..S.R 235.317 229,80 K
browseui.dll Thu 24 Nov 2005 1:39:20 A.... 1.022.464 998,50 K
ktj2l7~1.dll Tue 7 Feb 2006 16:27:48 ..S.R 233.856 228,38 K
sporder.dll Fri 18 Nov 2005 0:25:12 A.... 8.464 8,27 K
mvjsl9~1.dll Wed 8 Feb 2006 17:43:20 ..S.R 236.985 231,43 K
ir84l5~1.dll Thu 9 Feb 2006 21:44:04 ..S.R 233.990 228,50 K
hr4o05~1.dll Sun 12 Feb 2006 11:54:00 ..S.R 235.380 229,86 K
k2pm0c~1.dll Sat 11 Feb 2006 23:36:38 ..S.R 235.272 229,76 K
f62mlg~1.dll Tue 14 Feb 2006 20:04:16 ..S.R 236.443 230,90 K
g440le~1.dll Tue 14 Feb 2006 19:42:10 ..S.R 235.317 229,80 K
shdocvw.dll Thu 1 Dec 2005 4:33:22 A.... 1.492.480 1,42 M
gdi32.dll Thu 29 Dec 2005 3:56:06 A.... 280.064 273,50 K
mvcpxl32.dll Thu 2 Feb 2006 19:37:02 ..S.R 234.960 229,45 K
16 items found: 16 files (10 H/S), 0 directories.
Total of file sizes: 8.228.912 bytes 7,85 M
Locate .tmp files:
No matches found.
************************************************** ********************************
Directory Listing of system files:
Het volume in station C heeft geen naam.
Het volumenummer is 0556-15EB
Map van C:\WINDOWS\System32
02/14/2006 20:04 235.317 nttid.dll
02/14/2006 20:04 236.443 f62mlgf1162.dll
02/14/2006 19:58 236.944 cnb.dll
02/14/2006 19:42 235.317 g440lehm1h4a.dll
02/12/2006 11:54 235.380 hr4o05h3e.dll
02/11/2006 23:36 235.272 k2pm0c71ef.dll
02/09/2006 21:44 233.990 ir84l5lq1.dll
02/08/2006 17:43 236.985 mvjsl9171.dll
02/07/2006 16:27 233.856 ktj2l71o1.dll
02/02/2006 19:37 234.960 mvcpxl32.dll
05/05/2005 11:50 56 95A015951C.sys
05/05/2005 11:50 3.350 KGyGaAvL.sys
03/08/2005 21:15 <DIR> Microsoft
03/05/2005 10:36 <DIR> dllcache
12 bestand(en) 2.357.870 bytes
2 map(pen) 56.837.439.488 bytes beschikbaar
Logfile of HijackThis v1.99.1
Scan saved at 20:13:39, on 02/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Java\jre1.5.0_05\bin\jucheck.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\HistoryKill\histkill.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HistoryKill\hkPopupKiller.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\hijhack\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [MNI.UWFX5_0001_MNI] "C:\Documents and Settings\Jordy.JORDY-LI0DOKP1N\Local Settings\Temporary Internet Files\Content.IE5\M9A5CHS7\WinFixer2005ScannerInst all[1].exe"
O4 - HKCU\..\Run: [NI.UWFX5_0001_NI530211] "C:\Documents and Settings\Laura.JORDY-LI0DOKP1N\Local Settings\Temporary Internet Files\Content.IE5\R4OUCHGD\WinFixerScannerInstall[1].exe" -nag
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [HistoryKill] C:\Program Files\HistoryKill\histkill.exe /startup
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O16 - DPF: RaptisoftGameLoader - http://www.raptisoft.com/webgames/raptisoftgameloader.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/supergerball/miniclipGameLoader.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B467A3AF-E45B-4B1B-9983-C035D988FB0F} (VacPro.belgio_ver10) - http://66.194.38.28/dialer/belgio_ver10.CAB
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/4h/player.virtools.com/downloads/player/Install3.0/Installer.exe
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: SMDEn - C:\WINDOWS\system32\g440lehm1h4a.dll
O23 - Service: AntiVir Scheduler (AntiVirScheduler) - H+BEDV Datentechnik GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

nojs
15 February 2006, 13:53
beste drareg

Sluit alle openstaande programma's.
Dubbelklik op l2mfix.bat.
Klik op "2" om optie 2 te selecteren: Run Fix.
Druk op Enter.
De iconen op je bureaublad zullen verdwijnen en de L2Mfix gaat je computer scannen. Als het scannen klaar is, zal de computer aangeven dat hij opnieuw gaat opstarten.
Druk op Enter en de pc zal automatisch herstarten.
Als de computer opnieuw gestart is, opent er een kladblokbestandje.