Page 8 of 10 FirstFirst ... 45678910 LastLast
Results 71 to 80 of 99

Thread: Command Service

  1. #71
    Member
    Join Date
    May 2006
    Posts
    87

    Default

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winsock2 - Google Desktop Search Backup Before Last Install\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005]
    "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\
    6d,33,32,5c,72,73,76,70,73,70,2e,64,6c,6c,00,00,09,2a,86,48,86,f7,0d,01,01,\
    05,05,00,30,81,8b,31,0b,30,09,06,03,55,04,06,13,02,5a,41,31,15,30,13,06,03,\
    55,04,08,13,0c,57,65,73,74,65,72,6e,20,43,61,70,65,31,14,30,12,06,03,55,04,\
    07,13,0b,44,75,72,62,61,6e,76,69,6c,6c,65,31,0f,30,0d,06,03,55,04,0a,13,06,\
    54,68,61,77,74,65,31,1d,30,1b,06,03,55,04,0b,13,14,54,68,61,77,74,65,20,43,\
    65,72,74,69,66,69,63,61,74,69,6f,6e,31,1f,30,1d,06,03,55,04,03,13,16,54,68,\
    61,77,74,65,20,54,69,6d,65,73,74,61,6d,70,69,6e,67,20,43,41,30,1e,17,0d,30,\
    33,31,32,30,34,30,30,30,30,30,30,5a,17,0d,31,33,31,32,30,33,32,33,35,39,35,\
    39,5a,30,53,31,0b,30,09,06,03,55,04,06,13,02,55,53,31,17,30,15,06,03,55,04,\
    0a,13,0e,56,65,72,69,53,69,67,6e,2c,20,49,6e,63,2e,66,20,02,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,08,00,00,00,e0,a9,60,9d,7a,33,d0,11,bd,88,00,00,c0,\
    82,e6,9a,ed,03,00,00,01,00,00,00,88,01,1c,00,00,00,1c,00,00,00,c3,00,00,00,\
    00,00,8c,fb,56,01,5c,0d,91,7c,00,00,1c,00,06,00,00,00,02,00,00,00,10,00,00,\
    00,10,00,00,00,01,00,00,00,06,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,52,00,53,00,56,00,50,00,20,00,54,00,43,00,50,00,20,\
    00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,20,00,50,00,72,00,6f,00,76,00,\
    69,00,64,00,65,00,72,00,00,00,18,9a,28,00,00,00,00,00,10,00,00,00,50,fb,56,\
    01,88,01,1c,00,40,00,00,00,d8,c4,a9,01,e8,01,1c,00,f4,fb,56,01,10,9a,28,00,\
    68,fb,56,01,46,0f,91,7c,02,00,00,00,08,00,00,00,00,00,1c,00,00,00,c3,00,00,\
    00,00,00,3c,fc,56,01,5c,0d,91,7c,00,00,1c,00,91,0e,91,7c,08,06,1c,00,6d,05,\
    91,7c,b8,99,28,00,00,00,00,00,b8,99,28,00,00,00,c3,00,01,00,00,00,b0,99,28,\
    00,02,00,00,00,e8,01,1c,00,80,bc,e5,02,0b,6e,60,75,b8,99,28,00,f8,fb,56,01,\
    25,c2,60,75,88,bc,e5,02,00,00,00,00,c8,0b,1d,00,14,00,00,00,60,fa,28,00,40,\
    00,00,00,58,ae,dd,02,0c,00,00,00,e8,01,1c,00,00,c0,0a,18,60,00,00,00,88,01,\
    1c,00,20,9a,28,00,10,00,00,00,b0,99,28,00,5c,01,1c,00,00,00,00,00,61,a8,91,\
    7c,02,00,00,00,f0,03,1c,00,00,00,1c,00,00,00,1c,00,d4,99,28,00,60,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,01,01,3d,fb,90,7c,00,00,00,00,bc,e7,90,7c,86,\
    d5,90,7c,00,00,1c,00,e8,e4,28,00,00,00,00,00,10,fd,56,01,5c,0d,91,7c,00,00,\
    1c,00,91,0e,91,7c,08,06,1c,00,6d,05,91,7c,94,a8,e1,02,00,00,00,00,90,41,ce,\
    01,00,00,c3,00,c0,d7,dd,77,e8,e4,28,00,00,00,00,00,00,00,00,00,f4,0a,00,00,\
    00,00,00,00,f0,e4,28,00,00,00,00,00,00,00,00,00,00,00,00,00,f4,0a,00,00,dc,\
    fc,56,01,f8,e8,f1,02,f4,0a,00,00,b8,fc,56,01,03,00,00,00,f0,e4,28,00,f0,03,\
    1c,00,94,a8,e1,02,78,02,00,00,90,41,ce,01,0c,00,0e,00,3c,56,5f,75,00,00,00,\
    00,ac,fc,56,01,90,41,ce,01,00,00,00,00,94,a8,e1,02,04,fd,56,01,6c,fb,90,7c,\
    71,fb,90,7c,94,a8,e1,02,00,00,00,00,90,41,ce,01,e0,fc,56,01

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winsock2 - Google Desktop Search Backup Before Last Install\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006]
    "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\
    6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,09,2a,86,48,86,f7,0d,01,01,\
    05,05,00,30,81,8b,31,0b,30,09,06,03,55,04,06,13,02,5a,41,31,15,30,13,06,03,\
    55,04,08,13,0c,57,65,73,74,65,72,6e,20,43,61,70,65,31,14,30,12,06,03,55,04,\
    07,13,0b,44,75,72,62,61,6e,76,69,6c,6c,65,31,0f,30,0d,06,03,55,04,0a,13,06,\
    54,68,61,77,74,65,31,1d,30,1b,06,03,55,04,0b,13,14,54,68,61,77,74,65,20,43,\
    65,72,74,69,66,69,63,61,74,69,6f,6e,31,1f,30,1d,06,03,55,04,03,13,16,54,68,\
    61,77,74,65,20,54,69,6d,65,73,74,61,6d,70,69,6e,67,20,43,41,30,1e,17,0d,30,\
    33,31,32,30,34,30,30,30,30,30,30,5a,17,0d,31,33,31,32,30,33,32,33,35,39,35,\
    39,5a,30,53,31,0b,30,09,06,03,55,04,06,13,02,55,53,31,17,30,15,06,03,55,04,\
    0a,13,0e,56,65,72,69,53,69,67,6e,2c,20,49,6e,63,2e,0e,00,02,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\
    48,a1,92,f8,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\
    00,14,00,00,00,05,00,00,00,fd,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\
    00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\
    65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\
    00,5f,00,7b,00,43,00,45,00,35,00,46,00,41,00,30,00,44,00,30,00,2d,00,33,00,\
    38,00,34,00,44,00,2d,00,34,00,33,00,38,00,37,00,2d,00,39,00,45,00,34,00,37,\
    00,2d,00,44,00,32,00,35,00,31,00,38,00,34,00,30,00,33,00,30,00,44,00,39,00,\
    39,00,7d,00,5d,00,20,00,53,00,45,00,51,00,50,00,41,00,43,00,4b,00,45,00,54,\
    00,20,00,33,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winsock2 - Google Desktop Search Backup Before Last Install\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007]
    "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\
    6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,09,2a,86,48,86,f7,0d,01,01,\
    05,05,00,30,81,8b,31,0b,30,09,06,03,55,04,06,13,02,5a,41,31,15,30,13,06,03,\
    55,04,08,13,0c,57,65,73,74,65,72,6e,20,43,61,70,65,31,14,30,12,06,03,55,04,\
    07,13,0b,44,75,72,62,61,6e,76,69,6c,6c,65,31,0f,30,0d,06,03,55,04,0a,13,06,\
    54,68,61,77,74,65,31,1d,30,1b,06,03,55,04,0b,13,14,54,68,61,77,74,65,20,43,\
    65,72,74,69,66,69,63,61,74,69,6f,6e,31,1f,30,1d,06,03,55,04,03,13,16,54,68,\
    61,77,74,65,20,54,69,6d,65,73,74,61,6d,70,69,6e,67,20,43,41,30,1e,17,0d,30,\
    33,31,32,30,34,30,30,30,30,30,30,5a,17,0d,31,33,31,32,30,33,32,33,35,39,35,\
    39,5a,30,53,31,0b,30,09,06,03,55,04,06,13,02,55,53,31,17,30,15,06,03,55,04,\
    0a,13,0e,56,65,72,69,53,69,67,6e,2c,20,49,6e,63,2e,09,02,02,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\
    48,a1,92,f9,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\
    00,14,00,00,00,02,00,00,00,fd,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\
    00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\
    65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\
    00,5f,00,7b,00,43,00,45,00,35,00,46,00,41,00,30,00,44,00,30,00,2d,00,33,00,\
    38,00,34,00,44,00,2d,00,34,00,33,00,38,00,37,00,2d,00,39,00,45,00,34,00,37,\
    00,2d,00,44,00,32,00,35,00,31,00,38,00,34,00,30,00,33,00,30,00,44,00,39,00,\
    39,00,7d,00,5d,00,20,00,44,00,41,00,54,00,41,00,47,00,52,00,41,00,4d,00,20,\
    00,33,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winsock2 - Google Desktop Search Backup Before Last Install\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008]
    "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\
    6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,09,2a,86,48,86,f7,0d,01,01,\
    05,05,00,30,81,8b,31,0b,30,09,06,03,55,04,06,13,02,5a,41,31,15,30,13,06,03,\
    55,04,08,13,0c,57,65,73,74,65,72,6e,20,43,61,70,65,31,14,30,12,06,03,55,04,\
    07,13,0b,44,75,72,62,61,6e,76,69,6c,6c,65,31,0f,30,0d,06,03,55,04,0a,13,06,\
    54,68,61,77,74,65,31,1d,30,1b,06,03,55,04,0b,13,14,54,68,61,77,74,65,20,43,\
    65,72,74,69,66,69,63,61,74,69,6f,6e,31,1f,30,1d,06,03,55,04,03,13,16,54,68,\
    61,77,74,65,20,54,69,6d,65,73,74,61,6d,70,69,6e,67,20,43,41,30,1e,17,0d,30,\
    33,31,32,30,34,30,30,30,30,30,30,5a,17,0d,31,33,31,32,30,33,32,33,35,39,35,\
    39,5a,30,53,31,0b,30,09,06,03,55,04,06,13,02,55,53,31,17,30,15,06,03,55,04,\
    0a,13,0e,56,65,72,69,53,69,67,6e,2c,20,49,6e,63,2e,0e,00,02,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,08,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\
    48,a1,92,fa,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\
    00,14,00,00,00,05,00,00,00,00,00,00,80,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\
    00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\
    65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\
    00,5f,00,7b,00,41,00,45,00,43,00,38,00,31,00,34,00,31,00,31,00,2d,00,42,00,\
    45,00,31,00,45,00,2d,00,34,00,44,00,45,00,31,00,2d,00,42,00,42,00,37,00,39,\
    00,2d,00,44,00,37,00,39,00,32,00,36,00,31,00,37,00,38,00,32,00,33,00,33,00,\
    33,00,7d,00,5d,00,20,00,53,00,45,00,51,00,50,00,41,00,43,00,4b,00,45,00,54,\
    00,20,00,30,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winsock2 - Google Desktop Search Backup Before Last Install\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009]
    "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\
    6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,09,2a,86,48,86,f7,0d,01,01,\
    05,05,00,30,81,8b,31,0b,30,09,06,03,55,04,06,13,02,5a,41,31,15,30,13,06,03,\
    55,04,08,13,0c,57,65,73,74,65,72,6e,20,43,61,70,65,31,14,30,12,06,03,55,04,\
    07,13,0b,44,75,72,62,61,6e,76,69,6c,6c,65,31,0f,30,0d,06,03,55,04,0a,13,06,\
    54,68,61,77,74,65,31,1d,30,1b,06,03,55,04,0b,13,14,54,68,61,77,74,65,20,43,\
    65,72,74,69,66,69,63,61,74,69,6f,6e,31,1f,30,1d,06,03,55,04,03,13,16,54,68,\
    61,77,74,65,20,54,69,6d,65,73,74,61,6d,70,69,6e,67,20,43,41,30,1e,17,0d,30,\
    33,31,32,30,34,30,30,30,30,30,30,5a,17,0d,31,33,31,32,30,33,32,33,35,39,35,\
    39,5a,30,53,31,0b,30,09,06,03,55,04,06,13,02,55,53,31,17,30,15,06,03,55,04,\
    0a,13,0e,56,65,72,69,53,69,67,6e,2c,20,49,6e,63,2e,09,02,02,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,08,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\
    48,a1,92,fb,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\
    00,14,00,00,00,02,00,00,00,00,00,00,80,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\
    00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\
    65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\
    00,5f,00,7b,00,41,00,45,00,43,00,38,00,31,00,34,00,31,00,31,00,2d,00,42,00,\
    45,00,31,00,45,00,2d,00,34,00,44,00,45,00,31,00,2d,00,42,00,42,00,37,00,39,\
    00,2d,00,44,00,37,00,39,00,32,00,36,00,31,00,37,00,38,00,32,00,33,00,33,00,\
    33,00,7d,00,5d,00,20,00,44,00,41,00,54,00,41,00,47,00,52,00,41,00,4d,00,20,\
    00,30,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winsock2 - Google Desktop Search Backup Before Last Install\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010]
    "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\
    6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,09,2a,86,48,86,f7,0d,01,01,\
    05,05,00,30,81,8b,31,0b,30,09,06,03,55,04,06,13,02,5a,41,31,15,30,13,06,03,\
    55,04,08,13,0c,57,65,73,74,65,72,6e,20,43,61,70,65,31,14,30,12,06,03,55,04,\
    07,13,0b,44,75,72,62,61,6e,76,69,6c,6c,65,31,0f,30,0d,06,03,55,04,0a,13,06,\
    54,68,61,77,74,65,31,1d,30,1b,06,03,55,04,0b,13,14,54,68,61,77,74,65,20,43,\
    65,72,74,69,66,69,63,61,74,69,6f,6e,31,1f,30,1d,06,03,55,04,03,13,16,54,68,\
    61,77,74,65,20,54,69,6d,65,73,74,61,6d,70,69,6e,67,20,43,41,30,1e,17,0d,30,\
    33,31,32,30,34,30,30,30,30,30,30,5a,17,0d,31,33,31,32,30,33,32,33,35,39,35,\
    39,5a,30,53,31,0b,30,09,06,03,55,04,06,13,02,55,53,31,17,30,15,06,03,55,04,\
    0a,13,0e,56,65,72,69,53,69,67,6e,2c,20,49,6e,63,2e,0e,00,02,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,

  2. #72
    Member
    Join Date
    May 2006
    Posts
    87

    Default

    5f,\
    48,a1,92,fc,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\
    00,14,00,00,00,05,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\
    00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\
    65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\
    00,5f,00,7b,00,45,00,46,00,41,00,41,00,31,00,41,00,32,00,30,00,2d,00,31,00,\
    31,00,33,00,36,00,2d,00,34,00,41,00,31,00,33,00,2d,00,41,00,35,00,33,00,43,\
    00,2d,00,42,00,31,00,45,00,34,00,45,00,34,00,43,00,35,00,32,00,43,00,42,00,\
    45,00,7d,00,5d,00,20,00,53,00,45,00,51,00,50,00,41,00,43,00,4b,00,45,00,54,\
    00,20,00,31,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winsock2 - Google Desktop Search Backup Before Last Install\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011]
    "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\
    6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,09,2a,86,48,86,f7,0d,01,01,\
    05,05,00,30,81,8b,31,0b,30,09,06,03,55,04,06,13,02,5a,41,31,15,30,13,06,03,\
    55,04,08,13,0c,57,65,73,74,65,72,6e,20,43,61,70,65,31,14,30,12,06,03,55,04,\
    07,13,0b,44,75,72,62,61,6e,76,69,6c,6c,65,31,0f,30,0d,06,03,55,04,0a,13,06,\
    54,68,61,77,74,65,31,1d,30,1b,06,03,55,04,0b,13,14,54,68,61,77,74,65,20,43,\
    65,72,74,69,66,69,63,61,74,69,6f,6e,31,1f,30,1d,06,03,55,04,03,13,16,54,68,\
    61,77,74,65,20,54,69,6d,65,73,74,61,6d,70,69,6e,67,20,43,41,30,1e,17,0d,30,\
    33,31,32,30,34,30,30,30,30,30,30,5a,17,0d,31,33,31,32,30,33,32,33,35,39,35,\
    39,5a,30,53,31,0b,30,09,06,03,55,04,06,13,02,55,53,31,17,30,15,06,03,55,04,\
    0a,13,0e,56,65,72,69,53,69,67,6e,2c,20,49,6e,63,2e,09,02,02,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\
    48,a1,92,fd,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\
    00,14,00,00,00,02,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\
    00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\
    65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\
    00,5f,00,7b,00,45,00,46,00,41,00,41,00,31,00,41,00,32,00,30,00,2d,00,31,00,\
    31,00,33,00,36,00,2d,00,34,00,41,00,31,00,33,00,2d,00,41,00,35,00,33,00,43,\
    00,2d,00,42,00,31,00,45,00,34,00,45,00,34,00,43,00,35,00,32,00,43,00,42,00,\
    45,00,7d,00,5d,00,20,00,44,00,41,00,54,00,41,00,47,00,52,00,41,00,4d,00,20,\
    00,31,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00





    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winsock2 - Google Desktop Search Backup Before Last Install\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012]
    "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\
    6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,09,2a,86,48,86,f7,0d,01,01,\
    05,05,00,30,81,8b,31,0b,30,09,06,03,55,04,06,13,02,5a,41,31,15,30,13,06,03,\
    55,04,08,13,0c,57,65,73,74,65,72,6e,20,43,61,70,65,31,14,30,12,06,03,55,04,\
    07,13,0b,44,75,72,62,61,6e,76,69,6c,6c,65,31,0f,30,0d,06,03,55,04,0a,13,06,\
    54,68,61,77,74,65,31,1d,30,1b,06,03,55,04,0b,13,14,54,68,61,77,74,65,20,43,\
    65,72,74,69,66,69,63,61,74,69,6f,6e,31,1f,30,1d,06,03,55,04,03,13,16,54,68,\
    61,77,74,65,20,54,69,6d,65,73,74,61,6d,70,69,6e,67,20,43,41,30,1e,17,0d,30,\
    33,31,32,30,34,30,30,30,30,30,30,5a,17,0d,31,33,31,32,30,33,32,33,35,39,35,\
    39,5a,30,53,31,0b,30,09,06,03,55,04,06,13,02,55,53,31,17,30,15,06,03,55,04,\
    0a,13,0e,56,65,72,69,53,69,67,6e,2c,20,49,6e,63,2e,0e,00,02,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\
    48,a1,92,fe,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\
    00,14,00,00,00,05,00,00,00,fe,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\
    00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\
    65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\
    00,5f,00,7b,00,39,00,35,00,42,00,42,00,43,00,34,00,35,00,35,00,2d,00,30,00,\
    43,00,42,00,41,00,2d,00,34,00,45,00,44,00,33,00,2d,00,42,00,39,00,44,00,38,\
    00,2d,00,32,00,41,00,46,00,43,00,45,00,31,00,38,00,43,00,34,00,39,00,45,00,\
    37,00,7d,00,5d,00,20,00,53,00,45,00,51,00,50,00,41,00,43,00,4b,00,45,00,54,\
    00,20,00,32,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winsock2 - Google Desktop Search Backup Before Last Install\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013]
    "PackedCatalogItem"=hex:25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,\
    6d,33,32,5c,6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,09,2a,86,48,86,f7,0d,01,01,\
    05,05,00,30,81,8b,31,0b,30,09,06,03,55,04,06,13,02,5a,41,31,15,30,13,06,03,\
    55,04,08,13,0c,57,65,73,74,65,72,6e,20,43,61,70,65,31,14,30,12,06,03,55,04,\
    07,13,0b,44,75,72,62,61,6e,76,69,6c,6c,65,31,0f,30,0d,06,03,55,04,0a,13,06,\
    54,68,61,77,74,65,31,1d,30,1b,06,03,55,04,0b,13,14,54,68,61,77,74,65,20,43,\
    65,72,74,69,66,69,63,61,74,69,6f,6e,31,1f,30,1d,06,03,55,04,03,13,16,54,68,\
    61,77,74,65,20,54,69,6d,65,73,74,61,6d,70,69,6e,67,20,43,41,30,1e,17,0d,30,\
    33,31,32,30,34,30,30,30,30,30,30,5a,17,0d,31,33,31,32,30,33,32,33,35,39,35,\
    39,5a,30,53,31,0b,30,09,06,03,55,04,06,13,02,55,53,31,17,30,15,06,03,55,04,\
    0a,13,0e,56,65,72,69,53,69,67,6e,2c,20,49,6e,63,2e,09,02,02,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,30,18,5f,8d,73,c2,cf,11,95,c8,00,80,5f,\
    48,a1,92,ff,03,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,11,00,00,00,14,00,00,\
    00,14,00,00,00,02,00,00,00,fe,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,fa,00,00,00,00,00,00,4d,00,53,00,41,00,46,00,44,00,20,00,4e,00,65,00,74,\
    00,42,00,49,00,4f,00,53,00,20,00,5b,00,5c,00,44,00,65,00,76,00,69,00,63,00,\
    65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,\
    00,5f,00,7b,00,39,00,35,00,42,00,42,00,43,00,34,00,35,00,35,00,2d,00,30,00,\
    43,00,42,00,41,00,2d,00,34,00,45,00,44,00,33,00,2d,00,42,00,39,00,44,00,38,\
    00,2d,00,32,00,41,00,46,00,43,00,45,00,31,00,38,00,43,00,34,00,39,00,45,00,\
    37,00,7d,00,5d,00,20,00,44,00,41,00,54,00,41,00,47,00,52,00,41,00,4d,00,20,\
    00,32,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinTrust]

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinTrust\SubjectPackages]

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinTrust\SubjectPackages\MS Subjects 1]
    "$DLL"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,33,32,\
    5c,4d,73,53,69,70,31,2e,64,6c,6c,00

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinTrust\SubjectPackages\MS Subjects 2]
    "$DLL"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,33,32,\
    5c,4d,73,53,69,70,32,2e,64,6c,6c,00

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinTrust\SubjectPackages\MS Subjects 3]
    "$DLL"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,33,32,\
    5c,4d,73,53,69,70,33,2e,64,6c,6c,00

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinTrust\TrustProviders]

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinTrust\TrustProviders\Software Publisher]
    "$DLL"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,33,32,\
    5c,53,6f,66,74,50,75,62,2e,64,6c,6c,00

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WmdmPmSN]
    "Type"=dword:00000020
    "Start"=dword:00000003
    "ErrorControl"=dword:00000001
    "ImagePath"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,33,\
    32,5c,73,76,63,68,6f,73,74,2e,65,78,65,20,2d,6b,20,6e,65,74,73,76,63,73,00
    "DisplayName"="Portable Media Serial Number Service"
    "ObjectName"="LocalSystem"
    "Description"="Retrieves the serial number of any portable media player connected to this computer. If this service is stopped, protected content might not be down loaded to the device."

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WmdmPmSN\Parameters]
    "ServiceDll"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,73,79,73,74,65,6d,33,32,\
    5c,4d,73,50,4d,53,4e,53,76,2e,64,6c,6c,00

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WmdmPmSN\Security]
    "Security"=hex:01,00,14,80,a4,00,00,00,b0,00,00,00,14,00,00,00,30,00,00,00,02,\
    00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
    00,00,02,00,74,00,05,00,00,00,00,00,14,00,10,00,00,00,01,01,00,00,00,00,00,\
    05,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,\
    00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,00,\
    00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,00,18,00,fd,01,\
    02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,00,00,00,00,00,\
    05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

  3. #73
    Member
    Join Date
    May 2006
    Posts
    87

    Default

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Wmi]
    "Description"="Provides systems management information to and from drivers."
    "DisplayName"="Windows Management Instrumentation Driver Extensions"
    "ErrorControl"=dword:00000001
    "ImagePath"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,33,\
    32,5c,73,76,63,68,6f,73,74,2e,65,78,65,20,2d,6b,20,6e,65,74,73,76,63,73,00
    "ObjectName"="LocalSystem"
    "Start"=dword:00000003
    "Type"=dword:00000020

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Wmi\Parameters]
    "ServiceDll"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,\
    33,32,5c,61,64,76,61,70,69,33,32,2e,64,6c,6c,00
    "ServiceMain"="WdmWmiServiceMain"

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Wmi\Security]
    "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
    00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
    00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
    05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
    20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
    00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
    00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WmiApRpl]

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WmiApRpl\Performance]
    "Library"="C:\\WINDOWS\\system32\\wbem\\wmiaprpl.dll"
    "Open"="WmiOpenPerfData"
    "Collect"="WmiCollectPerfData"
    "Close"="WmiClosePerfData"
    "Last Counter"=dword:000008e4
    "Last Help"=dword:000008e5
    "First Counter"=dword:000008e0
    "First Help"=dword:000008e1
    "Object List"="2272 2272"

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WmiApSrv]
    "Type"=dword:00000010
    "Start"=dword:00000003
    "ErrorControl"=dword:00000001
    "ImagePath"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,73,79,73,74,65,6d,33,32,5c,\
    77,62,65,6d,5c,77,6d,69,61,70,73,72,76,2e,65,78,65,00
    "DisplayName"="WMI Performance Adapter"
    "DependOnService"=hex(7):52,50,43,53,53,00,00
    "DependOnGroup"=hex(7):00
    "ObjectName"="LocalSystem"
    "Description"="Provides performance library information from WMI HiPerf providers."

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WmiApSrv\Security]
    "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
    00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
    00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
    05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
    20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
    00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
    00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WS2IFSL]
    "Start"=dword:00000001

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wscsvc]
    "Type"=dword:00000020
    "Start"=dword:00000002
    "ErrorControl"=dword:00000001
    "ImagePath"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,33,\
    32,5c,73,76,63,68,6f,73,74,2e,65,78,65,20,2d,6b,20,6e,65,74,73,76,63,73,00
    "DisplayName"="Security Center"
    "DependOnService"=hex(7):52,70,63,53,73,00,77,69,6e,6d,67,6d,74,00,00
    "ObjectName"="LocalSystem"
    "Description"="Monitors system security settings and configurations."

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wscsvc\Parameters]
    "ServiceDll"=hex(2):25,53,59,53,54,45,4d,52,4f,4f,54,25,5c,73,79,73,74,65,6d,\
    33,32,5c,77,73,63,73,76,63,2e,64,6c,6c,00

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wscsvc\Security]
    "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
    00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
    00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
    05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
    20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
    00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
    00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wscsvc\Enum]
    "0"="Root\\LEGACY_WSCSVC\\0000"
    "Count"=dword:00000001
    "NextInstance"=dword:00000001

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wuauserv]
    "Type"=dword:00000020
    "Start"=dword:00000002
    "ErrorControl"=dword:00000001
    "ImagePath"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,65,6d,33,\
    32,5c,73,76,63,68,6f,73,74,2e,65,78,65,20,2d,6b,20,6e,65,74,73,76,63,73,00
    "DisplayName"="Automatic Updates"
    "ObjectName"="LocalSystem"
    "Description"="Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site."

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wuauserv\Parameters]
    "ServiceDll"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,73,79,73,74,65,6d,33,32,\
    5c,77,75,61,75,73,65,72,76,2e,64,6c,6c,00

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wuauserv\Security]
    "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
    00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
    00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
    05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
    20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
    00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
    00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wuauserv\Enum]
    "0"="Root\\LEGACY_WUAUSERV\\0000"
    "Count"=dword:00000001
    "NextInstance"=dword:00000001

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WZCSVC]
    "Type"=dword:00000020
    "Start"=dword:00000002
    "ErrorControl"=dword:00000001
    "ImagePath"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,33,\
    32,5c,73,76,63,68,6f,73,74,2e,65,78,65,20,2d,6b,20,6e,65,74,73,76,63,73,00
    "DisplayName"="Wireless Zero Configuration"
    "Group"="TDI"
    "DependOnService"=hex(7):52,70,63,53,73,00,4e,64,69,73,75,69,6f,00,00
    "DependOnGroup"=hex(7):00
    "ObjectName"="LocalSystem"
    "Description"="Provides automatic configuration for the 802.11 adapters"

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WZCSVC\Parameters]
    "ServiceDll"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,\
    33,32,5c,77,7a,63,73,76,63,2e,64,6c,6c,00
    "ServiceMain"="WZCSvcMain"
    "ServiceDllUnloadOnStop"=dword:00000001

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WZCSVC\Security]
    "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
    00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
    00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
    05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
    20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
    00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
    00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WZCSVC\Enum]
    "0"="Root\\LEGACY_WZCSVC\\0000"
    "Count"=dword:00000001
    "NextInstance"=dword:00000001

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov]
    "DependOnService"=hex(7):52,70,63,53,73,00,00
    "Description"="Manages XML configuration files on a domain basis for automatic network provisioning."
    "DisplayName"="Network Provisioning Service"
    "ErrorControl"=dword:00000001
    "ImagePath"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,33,\
    32,5c,73,76,63,68,6f,73,74,2e,65,78,65,20,2d,6b,20,6e,65,74,73,76,63,73,00
    "ObjectName"="LocalSystem"
    "Start"=dword:00000003
    "Type"=dword:00000020

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov\Parameters]
    "ServiceDll"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,\
    33,32,5c,78,6d,6c,70,72,6f,76,2e,64,6c,6c,00

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov\Parameters\SchemaGroups]

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov\Parameters\SchemaGroups\Branding]

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov\Parameters\SchemaGroups\Branding\http://www.microsoft.com/provisioning/Branding]
    "QueryAlias"="branding"
    "SchemaFile"="branding.xdr"

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov\Parameters\SchemaGroups\Connection]

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov\Parameters\SchemaGroups\Connection\http://www.microsoft.com/provisionin...nPropertiesV1]
    "QueryAlias"="baseeapconnectionpropertiesv1"
    "SchemaFile"="baseeapconnectionpropertiesv1.xdr"

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov\Parameters\SchemaGroups\Connection\http://www.microsoft.com/provisionin...nPropertiesV1]
    "QueryAlias"="eapconnectionpropertiesv1"
    "SchemaFile"="eapconnectionpropertiesv1.xdr"

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov\Parameters\SchemaGroups\Connection\http://www.microsoft.com/provisionin...nPropertiesV1]
    "QueryAlias"="mschapv2connectionpropertiesv1"
    "SchemaFile"="mschapv2connectionpropertiesv1.xdr"

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov\Parameters\SchemaGroups\Connection\http://www.microsoft.com/provisionin...nPropertiesV1]
    "QueryAlias"="mspeapconnectionpropertiesv1"
    "SchemaFile"="mspeapconnectionpropertiesv1.xdr"

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov\Parameters\SchemaGroups\Help]

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov\Parameters\SchemaGroups\Help\http://www.microsoft.com/provisioning/Help]
    "QueryAlias"="help"
    "SchemaFile"="help.xdr"

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov\Parameters\SchemaGroups\Locations]

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov\Parameters\SchemaGroups\Locations\http://www.microsoft.com/provisioning/Locations]
    "QueryAlias"="locations"
    "SchemaFile"="locations.xdr"

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov\Parameters\SchemaGroups\Master]

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov\Parameters\SchemaGroups\Master\http://www.microsoft.com/provisioning/Master]
    "QueryAlias"="master"
    "SchemaFile"="masterfile.xdr"

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov\Parameters\SchemaGroups\Register]

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov\Parameters\SchemaGroups\Register\http://www.microsoft.com/provisioning/Register]
    "QueryAlias"="register"
    "SchemaFile"="register.xdr"

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov\Parameters\SchemaGroups\SSID]

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov\Parameters\SchemaGroups\SSID\http://www.microsoft.com/provisioning/SSID]
    "QueryAlias"="ssid"
    "SchemaFile"="ssid.xdr"

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov\Parameters\SchemaGroups\User]

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov\Parameters\SchemaGroups\User\http://www.microsoft.com/provisionin...rPropertiesV1]
    "QueryAlias"="baseeapuserpropertiesv1"
    "SchemaFile"="baseeapuserpropertiesv1.xdr"

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov\Parameters\SchemaGroups\User\http://www.microsoft.com/provisionin...rPropertiesV1]
    "QueryAlias"="eapuserpropertiesv1"
    "SchemaFile"="eapuserpropertiesv1.xdr"

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov\Parameters\SchemaGroups\User\http://www.microsoft.com/provisionin...rPropertiesV1]
    "QueryAlias"="mschapv2userpropertiesv1"
    "SchemaFile"="mschapv2userpropertiesv1.xdr"

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov\Parameters\SchemaGroups\User\http://www.microsoft.com/provisionin...rPropertiesV1]
    "QueryAlias"="mspeapuserpropertiesv1"
    "SchemaFile"="mspeapuserpropertiesv1.xdr"

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov\Parameters\SchemaGroups\WirelessProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmlprov\Parameters\SchemaGroups\WirelessProfile\http://www.microsoft.com/provisioning/WirelessProfile]
    "QueryAlias"="wirelessprofile"
    "SchemaFile"="wirelessprofile.xdr"

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{AEC81411-BE1E-4DE1-BB79-D79261782333}]

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{AEC81411-BE1E-4DE1-BB79-D79261782333}\Parameters]

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{AEC81411-BE1E-4DE1-BB79-D79261782333}\Parameters\Tcpip]
    "EnableDHCP"=dword:00000001
    "IPAddress"=hex(7):30,2e,30,2e,30,2e,30,00,00
    "SubnetMask"=hex(7):30,2e,30,2e,30,2e,30,00,00
    "DefaultGateway"=hex(7):00
    "DhcpIPAddress"="192.168.0.73"
    "DhcpSubnetMask"="255.255.255.0"
    "DhcpServer"="192.168.0.1"
    "Lease"=dword:00093a80
    "LeaseObtainedTime"=dword:422dfc27
    "T1"=dword:422dfd53
    "T2"=dword:4234e807
    "LeaseTerminatesTime"=dword:423736a7

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{CE5FA0D0-384D-4387-9E47-D25184030D99}]

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{CE5FA0D0-384D-4387-9E47-D25184030D99}\Parameters]

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{CE5FA0D0-384D-4387-9E47-D25184030D99}\Parameters\Tcpip]
    "EnableDHCP"=dword:00000001
    "IPAddress"=hex(7):30,2e,30,2e,30,2e,30,00,00
    "SubnetMask"=hex(7):30,2e,30,2e,30,2e,30,00,00
    "DefaultGateway"=hex(7):00
    "DhcpIPAddress"="82.32.104.229"
    "DhcpSubnetMask"="255.255.248.0"
    "DhcpServer"="62.30.64.114"
    "Lease"=dword:00015180
    "LeaseObtainedTime"=dword:46548214
    "T1"=dword:46552ad4
    "T2"=dword:4655a964
    "LeaseTerminatesTime"=dword:4655d394
    "DhcpDefaultGateway"=hex(7):38,32,2e,33,32,2e,31,30,34,2e,31,00,00
    "DhcpSubnetMaskOpt"=hex(7):32,35,35,2e,32,35,35,2e,32,34,38,2e,30,00,00

  4. #74
    Member
    Join Date
    May 2006
    Posts
    87

    Default

    This is all from regkey. Regperms was empty.

  5. #75
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi

    Let's try this next:

    Download registrar lite and install it -> http://www.majorgeeks.com/download469.html

    Copy this to address field and press Go:

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CMDSERVICE

    Right-click key and choose properties. Click "Take ownership". After that, delete it (right-click -> delete)

    If no success, try things above to subkey(s) first, that one below considering that particular key:

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CMDSERVICE\0000

    Repeat steps for keys below.

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdService
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CMDSERVICE
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdService

    Run another search for cmdService with registry search tool and post results.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  6. #76
    Member
    Join Date
    May 2006
    Posts
    87

    Default

    1&2 deleted OK. 3 was 'Access Denied'. 4&5 didn't appear.

    REGEDIT4
    ; RegSrch.vbs © Bill James

    ; Registry search results for string "cmdService" 24/05/2007 19:02:08

    ; NOTE: This file will be deleted when you close WordPad.
    ; You must manually save this file to a new location if you want to refer to it again later.
    ; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CMDSERVICE]

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CMDSERVICE\0000]

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CMDSERVICE\0000]
    "Service"="cmdService"

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\cmdService]

    [HKEY_USERS\S-1-5-21-1606980848-1547161642-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit]
    "LastKey"="My Computer\\HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\cmdService"

    [HKEY_USERS\S-1-5-21-1606980848-1547161642-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\zip]
    "a"="C:\\Documents and Settings\\PHIL\\Desktop\\delcmdservice.zip"

    [HKEY_USERS\S-1-5-21-1606980848-1547161642-1801674531-1003\Software\Resplendence Sp\Registrar Lite\Settings]
    "LastOpenedKey"="HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet002\\Enum\\Root\\LEGACY_CMDSERVICE"

    [HKEY_USERS\S-1-5-21-1606980848-1547161642-1801674531-1003\Software\WinRAR\ArcHistory]
    "2"="C:\\Documents and Settings\\PHIL\\Desktop\\delcmdservice.zip"

    "3"="C:\\Documents and Settings\\PHIL\\Local Settings\\Temporary Internet Files\\Content.IE5\\WLIRO5U3\\delcmdservice[1].zip"

  7. #77
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi

    Great, some progress

    Then next try same steps as above for:

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CMDSERVICE
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\cmdService

    If no success, try things above to subkey(s) first, that one below considering that particular key:

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CMDSERVICE\0000

    Run another search for cmdService with registry search tool and post results.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  8. #78
    Member
    Join Date
    May 2006
    Posts
    87

    Default

    All done?

    REGEDIT4
    ; RegSrch.vbs © Bill James

    ; Registry search results for string "cmdService" 24/05/2007 20:56:02

    ; NOTE: This file will be deleted when you close WordPad.
    ; You must manually save this file to a new location if you want to refer to it again later.
    ; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


    [HKEY_USERS\S-1-5-21-1606980848-1547161642-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit]
    "LastKey"="My Computer\\HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\cmdService"

    [HKEY_USERS\S-1-5-21-1606980848-1547161642-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\zip]
    "a"="C:\\Documents and Settings\\PHIL\\Desktop\\delcmdservice.zip"

    [HKEY_USERS\S-1-5-21-1606980848-1547161642-1801674531-1003\Software\WinRAR\ArcHistory]
    "2"="C:\\Documents and Settings\\PHIL\\Desktop\\delcmdservice.zip"

    "3"="C:\\Documents and Settings\\PHIL\\Local Settings\\Temporary Internet Files\\Content.IE5\\WLIRO5U3\\delcmdservice[1].zip"

  9. #79
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi

    Yes, it looks like so

    Let's run one online scan:

    Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
    • The program will launch and then start to download the latest definition files.
    • Once the scanner is installed and the definitions downloaded, click Next.
    • Now click on Scan Settings
    • In the scan settings make sure that the following are selected:

      o Scan using the following Anti-Virus database:

      + Extended (If available otherwise Standard)

      o Scan Options:

      + Scan Archives
      + Scan Mail Bases
    • Click OK
    • Now under select a target to scan select My Computer
    • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button
    • Save the file to your desktop.
    • Copy and paste that information in your next post.


    Post:

    - a fresh HijackThis log
    - kaspersky report
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  10. #80
    Member
    Join Date
    May 2006
    Posts
    87

    Default

    I can't install it as I apparently haven't got administrator rights.

    Don't understand why not as this is a home pc.

    What do I need to do?

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •