Page 8 of 9 FirstFirst ... 456789 LastLast
Results 71 to 80 of 88

Thread: Codec Problems - can only work in safe mode?

  1. #71
    Senior Member
    Join Date
    Mar 2006
    Posts
    114

    Default

    \StubPath = "C:\WINDOWS\inf\unregmp2.exe /ShowWMP" [MS]

    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
    -> {HKLM...CLSID} = "AcroIEHlprObj Class"
    \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
    {9394EDE7-C8B5-483E-8773-474BF36AF6E4}\(Default) = (no title provided)
    -> {HKLM...CLSID} = "ST"
    \InProcServer32\(Default) = "C:\Program Files\MSN Apps\ST\01.02.3000.1001\en-xu\stmain.dll" [MS]
    {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}\(Default) = (no title provided)
    -> {HKLM...CLSID} = "MSNToolBandBHO"
    \InProcServer32\(Default) = "C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-gb\msntb.dll" [MS]

    HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
    "{00022613-0000-0000-C000-000000000046}" = "Multimedia File Property Sheet"
    -> {HKLM...CLSID} = "Multimedia File Property Sheet"
    \InProcServer32\(Default) = "mmsys.cpl" [MS]
    "{176d6597-26d3-11d1-b350-080036a75b03}" = "ICM Scanner Management"
    -> {HKLM...CLSID} = "ICM Scanner Management"
    \InProcServer32\(Default) = "icmui.dll" [MS]
    "{1F2E5C40-9550-11CE-99D2-00AA006E086C}" = "NTFS Security Page"
    -> {HKLM...CLSID} = "Security Shell Extension"
    \InProcServer32\(Default) = "rshx32.dll" [MS]
    "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}" = "OLE Docfile Property Page"
    -> {HKLM...CLSID} = "OLE Docfile Property Page"
    \InProcServer32\(Default) = "docprop.dll" [MS]
    "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}" = "Shell extensions for sharing"
    -> {HKLM...CLSID} = "Shell extensions for sharing"
    \InProcServer32\(Default) = "ntshrui.dll" [MS]
    "{41E300E0-78B6-11ce-849B-444553540000}" = "PlusPack CPL Extension"
    -> {HKLM...CLSID} = "PlusPack CPL Extension"
    \InProcServer32\(Default) = "plustab.dll" [MS]
    "{42071712-76d4-11d1-8b24-00a0c9068ff3}" = "Display Adapter CPL Extension"
    -> {HKLM...CLSID} = "Display Adapter CPL Extension"
    \InProcServer32\(Default) = "deskadp.dll" [MS]
    "{42071713-76d4-11d1-8b24-00a0c9068ff3}" = "Display Monitor CPL Extension"
    -> {HKLM...CLSID} = "Display Monitor CPL Extension"
    \InProcServer32\(Default) = "deskmon.dll" [MS]
    "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"
    -> {HKLM...CLSID} = "Display Panning CPL Extension"
    \InProcServer32\(Default) = "deskpan.dll" [file not found]
    "{4E40F770-369C-11d0-8922-00A024AB2DBB}" = "DS Security Page"
    -> {HKLM...CLSID} = "Security Shell Extension"
    \InProcServer32\(Default) = "dssec.dll" [MS]
    "{56117100-C0CD-101B-81E2-00AA004AE837}" = "Shell Scrap DataHandler"
    -> {HKLM...CLSID} = "Shell Scrap DataHandler"
    \InProcServer32\(Default) = "shscrap.dll" [MS]
    "{59099400-57FF-11CE-BD94-0020AF85B590}" = "Disk Copy Extension"
    -> {HKLM...CLSID} = "Disk Copy Extension"
    \InProcServer32\(Default) = "diskcopy.dll" [MS]
    "{59be4990-f85c-11ce-aff7-00aa003ca9f6}" = "Shell extensions for Microsoft Windows Network objects"
    -> {HKLM...CLSID} = "Shell extensions for Microsoft Windows Network objects"
    \InProcServer32\(Default) = "ntlanui2.dll" [MS]
    "{5DB2625A-54DF-11D0-B6C4-0800091AA605}" = "ICM Monitor Management"
    -> {HKLM...CLSID} = "ICM Monitor Management"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\icmui.dll" [MS]
    "{675F097E-4C4D-11D0-B6C1-0800091AA605}" = "ICM Printer Management"
    -> {HKLM...CLSID} = "ICM Printer Management"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\icmui.dll" [MS]
    "{77597368-7b15-11d0-a0c2-080036af3f03}" = "Web Printer Shell Extension"
    -> {HKLM...CLSID} = "Web Printer Shell Extension"
    \InProcServer32\(Default) = "printui.dll" [MS]
    "{7988B573-EC89-11cf-9C00-00AA00A14F56}" = "Disk Quota UI"
    -> {HKLM...CLSID} = "Microsoft Disk Quota UI"
    \InProcServer32\(Default) = "dskquoui.dll" [MS]
    "{85BBD920-42A0-1069-A2E4-08002B30309D}" = "Briefcase"
    -> {HKLM...CLSID} = "Briefcase"
    \InProcServer32\(Default) = "syncui.dll" [MS]
    "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
    -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
    "{BD84B380-8CA2-1069-AB1D-08000948F534}" = "Fonts"
    -> {HKLM...CLSID} = "Fonts"
    \InProcServer32\(Default) = "fontext.dll" [MS]
    "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}" = "ICC Profile"
    -> {HKLM...CLSID} = "ICC Profile"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\icmui.dll" [MS]
    "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}" = "Printers Security Page"
    -> {HKLM...CLSID} = "Security Shell Extension"
    \InProcServer32\(Default) = "rshx32.dll" [MS]
    "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}" = "Shell extensions for sharing"
    -> {HKLM...CLSID} = "Shell extensions for sharing"
    \InProcServer32\(Default) = "ntshrui.dll" [MS]
    "{f92e8c40-3d33-11d2-b1aa-080036a75b03}" = "Display TroubleShoot CPL Extension"
    -> {HKLM...CLSID} = "Display TroubleShoot CPL Extension"
    \InProcServer32\(Default) = "deskperf.dll" [MS]
    "{60254CA5-953B-11CF-8C96-00AA00B8708C}" = "Shell extensions for Windows Script Host"
    -> {HKLM...CLSID} = "Shell Extension For Windows Script Host"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\wshext.dll" [MS]
    "{7444C717-39BF-11D1-8CD9-00C04FC29D45}" = "Crypto PKO Extension"
    -> {HKLM...CLSID} = "CryptPKO Class"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\cryptext.dll" [MS]
    "{7444C719-39BF-11D1-8CD9-00C04FC29D45}" = "Crypto Sign Extension"
    -> {HKLM...CLSID} = "CryptSig Class"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\cryptext.dll" [MS]
    "{7007ACC7-3202-11D1-AAD2-00805FC1270E}" = "Network and Dial-up Connections"
    -> {HKLM...CLSID} = "Network and Dial-up Connections"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\NETSHELL.dll" [MS]
    "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}" = "Tasks Folder Icon Handler"
    -> {HKLM...CLSID} = "Scheduling UI icon handler"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\mstask.dll" [MS]
    "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}" = "Tasks Folder Shell Extension"
    -> {HKLM...CLSID} = "Scheduling UI property sheet handler"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\mstask.dll" [MS]
    "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}" = "Scheduled Tasks"
    -> {HKLM...CLSID} = "Scheduled Tasks"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\mstask.dll" [MS]
    "{1A9BA3A0-143A-11CF-8350-444553540000}" = "Shell Favorite Folder"
    -> {HKLM...CLSID} = "Shell Favorite Folder"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]
    "{20D04FE0-3AEA-1069-A2D8-08002B30309D}" = "My Computer"
    -> {HKLM...CLSID} = "My Computer"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]
    "{86747AC0-42A0-1069-A2E6-08002B30309D}" = "Briefcase Folder"
    -> {HKLM...CLSID} = "Shell Moniker"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]
    "{0AFACED1-E828-11D1-9187-B532F1E9575D}" = "Folder Shortcut"
    -> {HKLM...CLSID} = "Folder Shortcut"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]
    "{12518493-00B2-11d2-9FA5-9E3420524153}" = "Mounted Volume"
    -> {HKLM...CLSID} = "Mounted Volume"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]
    "{21B22460-3AEA-1069-A2DC-08002B30309D}" = "File Property Page Extension"
    -> {HKLM...CLSID} = "File system attributes"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]
    "{B091E540-83E3-11CF-A713-0020AFD79762}" = "File Types Page"
    -> {HKLM...CLSID} = "File Types Page"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]
    "{FBF23B41-E3F0-101B-8488-00AA003E56F8}" = "MIME File Types Hook"
    -> {HKLM...CLSID} = "MIME File Types Hook"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]
    "{C2FBB630-2971-11d1-A18C-00C04FD75D13}" = "Microsoft CopyTo Service"
    -> {HKLM...CLSID} = "Microsoft CopyTo Service"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]

  2. #72
    Senior Member
    Join Date
    Mar 2006
    Posts
    114

    Default

    "{C2FBB631-2971-11d1-A18C-00C04FD75D13}" = "Microsoft MoveTo Service"
    -> {HKLM...CLSID} = "Microsoft MoveTo Service"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]
    "{13709620-C279-11CE-A49E-444553540000}" = "Shell Automation Service"
    -> {HKLM...CLSID} = "Shell Automation Service"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]
    "{62112AA1-EBE4-11cf-A5FB-0020AFE7292D}" = "Shell Automation Folder View"
    -> {HKLM...CLSID} = "Shell Automation Folder View"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]
    "{4622AD11-FF23-11d0-8D34-00A0C90F2719}" = "Start Menu"
    -> {HKLM...CLSID} = "Start Menu"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]
    "{7BA4C740-9E81-11CF-99D3-00AA004AE837}" = "Microsoft SendTo Service"
    -> {HKLM...CLSID} = "Microsoft SendTo Service"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]
    "{D969A300-E7FF-11d0-A93B-00A0C90F2719}" = "Microsoft New Object Service"
    -> {HKLM...CLSID} = "Microsoft New Object Service"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]
    "{09799AFB-AD67-11d1-ABCD-00C04FC30936}" = "Open With Context Menu Handler"
    -> {HKLM...CLSID} = "Open With Context Menu Handler"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]
    "{3FC0B520-68A9-11D0-8D77-00C04FD70822}" = "Display Control Panel HTML Extensions"
    -> {HKLM...CLSID} = "Display Control Panel HTML Extensions"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]
    "{75048700-EF1F-11D0-9888-006097DEACF9}" = "ActiveDesktop"
    -> {HKLM...CLSID} = "ActiveDesktop"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]
    "{6D5313C0-8C62-11D1-B2CD-006097DF8C11}" = "Folder Options Property Page Extension"
    -> {HKLM...CLSID} = "Folder Options Property Page Extension"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]
    "{57651662-CE3E-11D0-8D77-00C04FC99D61}" = "CmdFileIcon"
    -> {HKLM...CLSID} = "CmdFileIcon"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]
    "{4657278A-411B-11d2-839A-00C04FD918D0}" = "Shell Drag and Drop helper"
    -> {HKLM...CLSID} = "Shell Drag and Drop helper"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]
    "{A470F8CF-A1E8-4f65-8335-227475AA5C46}" = "Add encryption item to context menus in explorer"
    -> {HKLM...CLSID} = "Add encryption item to context menus in explorer"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]
    "{5E6AB780-7743-11CF-A12B-00AA004AE837}" = "Microsoft Internet Toolbar"
    -> {HKLM...CLSID} = "Microsoft Internet Toolbar"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{22BF0C20-6DA7-11D0-B373-00A0C9034938}" = "Download Status"
    -> {HKLM...CLSID} = "Download Status"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{568804CA-CBD7-11d0-9816-00C04FD91972}" = "Menu Shell Folder"
    -> {HKLM...CLSID} = "Menu Shell Folder"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{5b4dae26-b807-11d0-9815-00c04fd91972}" = "Menu Band"
    -> {HKLM...CLSID} = "Menu Band"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{8278F931-2A3E-11d2-838F-00C04FD918D0}" = "Tracking Shell Menu"
    -> {HKLM...CLSID} = "Tracking Shell Menu"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{E13EF4E4-D2F2-11d0-9816-00C04FD91972}" = "Menu Site"
    -> {HKLM...CLSID} = "Menu Site"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{ECD4FC4F-521C-11D0-B792-00A0C90312E1}" = "Menu Desk Bar"
    -> {HKLM...CLSID} = "Menu Desk Bar"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{91EA3F8B-C99B-11d0-9815-00C04FD91972}" = "Augmented Shell Folder"
    -> {HKLM...CLSID} = "Augmented Shell Folder"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{6413BA2C-B461-11d1-A18A-080036B11A03}" = "Augmented Shell Folder 2"
    -> {HKLM...CLSID} = "Augmented Shell Folder 2"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{F61FFEC1-754F-11d0-80CA-00AA005B4383}" = "BandProxy"
    -> {HKLM...CLSID} = "BandProxy"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{D82BE2B0-5764-11D0-A96E-00C04FD705A2}" = "IShellFolderBand"
    -> {HKLM...CLSID} = "IShellFolderBand"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{7BA4C742-9E81-11CF-99D3-00AA004AE837}" = "Microsoft BrowserBand"
    -> {HKLM...CLSID} = "Microsoft BrowserBand"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{30D02401-6A81-11d0-8274-00C04FD5AE38}" = "Search Band"
    -> {HKLM...CLSID} = "Search Band"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}" = "In-pane search"
    -> {HKLM...CLSID} = "In-pane search"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{07798131-AF23-11d1-9111-00A0C98BA67D}" = "Web Search"
    -> {HKLM...CLSID} = "Web Search"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{0E5CBF21-D15F-11d0-8301-00AA005B4383}" = "&Links"
    -> {HKLM...CLSID} = "&Links"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{AF4F6510-F982-11d0-8595-00AA004CD6D8}" = "Registry Tree Options Utility"
    -> {HKLM...CLSID} = "Registry Tree Options Utility"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{01E04581-4EEE-11d0-BFE9-00AA005B4383}" = "&Address"
    -> {HKLM...CLSID} = "&Address"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{A08C11D2-A228-11d0-825B-00AA005B4383}" = "Address EditBox"
    -> {HKLM...CLSID} = "Address EditBox"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{00BB2763-6A77-11D0-A535-00C04FD7D062}" = "Microsoft AutoComplete"
    -> {HKLM...CLSID} = "Microsoft AutoComplete"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{7487cd30-f71a-11d0-9ea7-00805f714772}" = "Thumbnail Image"
    -> {HKLM...CLSID} = "Thumbnail Image"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{7376D660-C583-11d0-A3A5-00C04FD706EC}" = "TridentImageExtractor"
    -> {HKLM...CLSID} = "TridentImageExtractor"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{6756A641-DE71-11d0-831B-00AA005B4383}" = "MRU AutoComplete List"
    -> {HKLM...CLSID} = "MRU AutoComplete List"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{00BB2764-6A77-11D0-A535-00C04FD7D062}" = "Microsoft History AutoComplete List"
    -> {HKLM...CLSID} = "Microsoft History AutoComplete List"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{03C036F1-A186-11D0-824A-00AA005B4383}" = "Microsoft Shell Folder AutoComplete List"
    -> {HKLM...CLSID} = "Microsoft Shell Folder AutoComplete List"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{00BB2765-6A77-11D0-A535-00C04FD7D062}" = "Microsoft Multiple AutoComplete List Container"
    -> {HKLM...CLSID} = "Microsoft Multiple AutoComplete List Container"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}" = "Shell Band Site Menu"
    -> {HKLM...CLSID} = "Shell Band Site Menu"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}" = "Shell DeskBarApp"
    -> {HKLM...CLSID} = "Shell DeskBarApp"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}" = "Shell DeskBar"
    -> {HKLM...CLSID} = "Shell DeskBar"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}" = "Shell Rebar BandSite"
    -> {HKLM...CLSID} = "Shell Rebar BandSite"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}" = "User Assist"
    -> {HKLM...CLSID} = "User Assist"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}" = "Global Folder Settings"
    -> {HKLM...CLSID} = "Global Folder Settings"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}" = "Favorites Band"
    -> {HKLM...CLSID} = "Favorites Band"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
    "{0A89A860-D7B1-11CE-8350-444553540000}" = "Shell Automation Inproc Service"
    -> {HKLM...CLSID} = "Shell Automation Inproc Service"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
    "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}" = "Shell DocObject Viewer"
    -> {HKLM...CLSID} = "Shell DocObject Viewer"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
    "{FBF23B40-E3F0-101B-8488-00AA003E56F8}" = "InternetShortcut"
    -> {HKLM...CLSID} = "Internet Shortcut"
    \InProcServer32\(Default) = "shdocvw.dll" [MS]
    "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}" = "Microsoft Url History Service"
    -> {HKLM...CLSID} = "Microsoft Url History Service"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
    "{FF393560-C2A7-11CF-BFF4-444553540000}" = "History"
    -> {HKLM...CLSID} = "History"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
    "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}" = "Temporary Internet Files"
    -> {HKLM...CLSID} = "Temporary Internet Files"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
    "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" = "Microsoft Url Search Hook"
    -> {HKLM...CLSID} = "Microsoft Url Search Hook"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
    "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}" = "IE4 Suite Splash Screen"
    -> {HKLM...CLSID} = "IE4 Suite Splash Screen"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
    "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}" = "CDF Extension Copy Hook"
    -> {HKLM...CLSID} = "CDF Extension Copy Hook"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
    "{131A6951-7F78-11D0-A979-00C04FD705A2}" = "ISFBand OC"
    -> {HKLM...CLSID} = "ISFBand OC"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
    "{9461b922-3c5a-11d2-bf8b-00c04fb93661}" = "Search Assistant OC"
    -> {HKLM...CLSID} = "Search Assistant OC"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
    "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}" = "The Internet"
    -> {HKLM...CLSID} = "The Internet"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
    "{871C5380-42A0-1069-A2EA-08002B30309D}" = "Internet Name Space"
    -> {HKLM...CLSID} = "Internet Explorer"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
    "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}" = "Sendmail service"
    -> {HKLM...CLSID} = (no title provided)
    \InProcServer32\(Default) = "C:\WINDOWS\System32\sendmail.dll" [MS]
    "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}" = "Sendmail service"
    -> {HKLM...CLSID} = (no title provided)
    \InProcServer32\(Default) = "C:\WINDOWS\System32\sendmail.dll" [MS]
    "{88C6C381-2E85-11D0-94DE-444553540000}" = "ActiveX Cache Folder"
    -> {HKLM...CLSID} = "ActiveX Cache Folder"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\occache.dll" [MS]
    "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" = "WebCheck"
    -> {HKLM...CLSID} = "WebCheck"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\webcheck.dll" [MS]
    "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}" = "Subscription Mgr"
    -> {HKLM...CLSID} = "Subscription Mgr"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\webcheck.dll" [MS]
    "{F5175861-2688-11d0-9C5E-00AA00A45957}" = "Subscription Folder"
    -> {HKLM...CLSID} = "Subscription Folder"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\webcheck.dll" [MS]
    "{08165EA0-E946-11CF-9C87-00AA005127ED}" = "WebCheckWebCrawler"
    -> {HKLM...CLSID} = "WebCheckWebCrawler"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\webcheck.dll" [MS]
    "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}" = "WebCheckChannelAgent"
    -> {HKLM...CLSID} = "WebCheckChannelAgent"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\webcheck.dll" [MS]
    "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}" = "TrayAgent"
    -> {HKLM...CLSID} = "TrayAgent"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\webcheck.dll" [MS]
    "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}" = "Code Download Agent"
    -> {HKLM...CLSID} = "Code Download Agent"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\webcheck.dll" [MS]
    "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}" = "ConnectionAgent"
    -> {HKLM...CLSID} = "ConnectionAgent"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\webcheck.dll" [MS]
    "{D8BD2030-6FC9-11D0-864F-00AA006809D9}" = "PostAgent"
    -> {HKLM...CLSID} = "PostAgent"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\webcheck.dll" [MS]
    "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}" = "WebCheck SyncMgr Handler"
    -> {HKLM...CLSID} = "WebCheck SyncMgr Handler"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\webcheck.dll" [MS]
    "{8BEBB290-52D0-11D0-B7F4-00C04FD706EC}" = "Thumbnails"
    -> {HKLM...CLSID} = "Thumbnails"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\thumbvw.dll" [MS]
    "{EAB841A0-9550-11CF-8C16-00805F1408F3}" = "HTML Thumbnail Extractor"
    -> {HKLM...CLSID} = "HTML Thumbnail Extractor"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\thumbvw.dll" [MS]
    "{1AEB1360-5AFC-11D0-B806-00C04FD706EC}" = "Office Graphics Filters Thumbnail Extractor"
    -> {HKLM...CLSID} = "Office Graphics Filters Thumbnail Extractor"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\thumbvw.dll" [MS]
    "{9DBD2C50-62AD-11D0-B806-00C04FD706EC}" = "Summary Info Thumbnail handler (DOCFILES)"
    -> {HKLM...CLSID} = "Summary Info Thumbnail handler (DOCFILES)"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\thumbvw.dll" [MS]
    "{500202A0-731E-11D0-B829-00C04FD706EC}" = "LNK file thumbnail interface delegator"
    -> {HKLM...CLSID} = "LNK file thumbnail interface delegator"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\thumbvw.dll" [MS]
    "{352EC2B7-8B9A-11D1-B8AE-006008059382}" = "Shell Application Manager"
    -> {HKLM...CLSID} = "%DESC_AppMgr%"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\appwiz.cpl" [MS]
    "{0B124F8C-91F0-11D1-B8B5-006008059382}" = "Installed Apps Enumerator"
    -> {HKLM...CLSID} = "Installed Apps Enumerator"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\appwiz.cpl" [MS]
    "{CFCCC7A0-A282-11D1-9082-006008059382}" = "Darwin App Publisher"
    -> {HKLM...CLSID} = "Darwin App Publisher"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\appwiz.cpl" [MS]
    "{fe1290f0-cfbd-11cf-a330-00aa00c16e65}" = "Directory Namespace"
    -> {HKLM...CLSID} = "Directory"
    \InProcServer32\(Default) = "dsfolder.dll" [MS]
    "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}" = "Shell properties for a DS object"
    -> {HKLM...CLSID} = (no title provided)
    \InProcServer32\(Default) = "dsfolder.dll" [MS]
    "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}" = "Directory Query UI"
    -> {HKLM...CLSID} = (no title provided)
    \InProcServer32\(Default) = "dsquery.dll" [MS]
    "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}" = "Directory Object Find"
    -> {HKLM...CLSID} = (no title provided)
    \InProcServer32\(Default) = "dsquery.dll" [MS]
    "{F020E586-5264-11d1-A532-0000F8757D7E}" = "Directory Start/Search Find"
    -> {HKLM...CLSID} = (no title provided)
    \InProcServer32\(Default) = "dsquery.dll" [MS]
    "{0D45D530-764B-11d0-A1CA-00AA00C16E65}" = "Directory Property UI"
    -> {HKLM...CLSID} = (no title provided)
    \InProcServer32\(Default) = "dsuiext.dll" [MS]
    "{62AE1F9A-126A-11D0-A14B-0800361B1103}" = "Directory Context Menu Verbs"
    -> {HKLM...CLSID} = (no title provided)
    \InProcServer32\(Default) = "dsuiext.dll" [MS]
    "{450D8FBA-AD25-11D0-98A8-0800361B1103}" = "MyDocs Folder"
    -> {HKLM...CLSID} = "My Documents"
    \InProcServer32\(Default) = "mydocs.dll" [MS]
    "{ECF03A33-103D-11d2-854D-006008059367}" = "MyDocs Copy Hook"
    -> {HKLM...CLSID} = (no title provided)
    \InProcServer32\(Default) = "mydocs.dll" [MS]
    "{ECF03A32-103D-11d2-854D-006008059367}" = "MyDocs Drop Target"
    -> {HKLM...CLSID} = "MyDocs Drop Target"
    \InProcServer32\(Default) = "mydocs.dll" [MS]
    "{4a7ded0a-ad25-11d0-98a8-0800361b1103}" = "MyDocs Properties"
    -> {HKLM...CLSID} = "MyDocs menu and properties"
    \InProcServer32\(Default) = "mydocs.dll" [MS]
    "{750fdf0e-2a26-11d1-a3ea-080036587f03}" = "Offline Files Menu"
    -> {HKLM...CLSID} = "Offline Files Menu"
    \InProcServer32\(Default) = "cscui.dll" [MS]
    "{10CFC467-4392-11d2-8DB4-00C04FA31A66}" = "Offline Files Folder Options"
    -> {HKLM...CLSID} = "Offline Files Folder Options"
    \InProcServer32\(Default) = "cscui.dll" [MS]
    "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}" = "Offline Files Folder"
    -> {HKLM...CLSID} = "Offline Files Folder"
    \InProcServer32\(Default) = "cscui.dll" [MS]
    "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}" = "MMC Icon Handler"
    -> {HKLM...CLSID} = "ExtractIcon Class"
    \InProcServer32\(Default) = "mmcshext.dll" [MS]
    "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}" = ".CAB file viewer"
    -> {HKLM...CLSID} = "Cabinet"
    \InProcServer32\(Default) = "cabview.dll" [MS]
    "{7D688A77-C613-11D0-999B-00C04FD655E1}" = "SlowFile Icon Overlay"
    -> {HKLM...CLSID} = "SlowFile Icon Overlay"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\SHELL32.DLL" [MS]
    "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
    -> {HKLM...CLSID} = "Outlook File Icon Extension"
    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office\OLKFSTUB.DLL" [MS]
    "{32683183-48a0-441b-a342-7c2a440a9478}" = "Media Band"
    -> {HKLM...CLSID} = "Media Band"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}" = "Custom MRU AutoCompleted List"
    -> {HKLM...CLSID} = "Custom MRU AutoCompleted List"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]

  3. #73
    Senior Member
    Join Date
    Mar 2006
    Posts
    114

    Default

    "{7e653215-fa25-46bd-a339-34a2790f3cb7}" = "Accessible"
    -> {HKLM...CLSID} = "Accessible"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{acf35015-526e-4230-9596-becbe19f0ac9}" = "Track Popup Bar"
    -> {HKLM...CLSID} = "Track Popup Bar"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{E0E11A09-5CB8-4B6C-8332-E00720A168F2}" = "Address Bar Parser"
    -> {HKLM...CLSID} = "Address Bar Parser"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}" = "Microsoft Browser Architecture"
    -> {HKLM...CLSID} = "Microsoft Browser Architecture"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
    "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}" = "Temporary Internet Files"
    -> {HKLM...CLSID} = "Temporary Internet Files"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
    "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}" = "Explorer Band"
    -> {HKLM...CLSID} = "Explorer Band"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
    "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}" = "Channel File"
    -> {HKLM...CLSID} = "Channel"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\cdfview.dll" [MS]
    "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}" = "Channel Shortcut"
    -> {HKLM...CLSID} = "Channel Shortcut"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\cdfview.dll" [MS]
    "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}" = "Channel Handler Object"
    -> {HKLM...CLSID} = "Channel Handler Object"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\cdfview.dll" [MS]
    "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}" = "Channel Menu"
    -> {HKLM...CLSID} = "Channel Menu Handler Object"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\cdfview.dll" [MS]
    "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}" = "Channel Properties"
    -> {HKLM...CLSID} = "Channel Shortcut Property Pages"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\cdfview.dll" [MS]
    "{32714800-2E5F-11d0-8B85-00AA0044F941}" = "For &People..."
    -> {HKLM...CLSID} = "For &People..."
    \InProcServer32\(Default) = "C:\PROGRA~1\OUTLOO~1\wabfind.dll" [MS]
    "{46505a60-4be9-11d2-922c-0060978f9b72}" = "XDC8 Shell Extension"
    -> {HKLM...CLSID} = "XDC8 Shell Extension"
    \InProcServer32\(Default) = "XDC8LMON.DLL" ["Xerox"]
    "{acb4a560-3606-11d3-aef4-00104bd0f92d}" = "KodakShellExtension"
    -> {HKLM...CLSID} = "KodakShellExtension"
    \InProcServer32\(Default) = "C:\Program Files\Common Files\KODAK\IFSCore\kodakshx.dll" ["Eastman Kodak Company"]
    "{E0D79304-84BE-11CE-9641-444553540000}" = "WinZip"
    -> {HKLM...CLSID} = "WinZip"
    \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing LP"]
    "{E0D79305-84BE-11CE-9641-444553540000}" = "WinZip"
    -> {HKLM...CLSID} = "WinZip"
    \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing LP"]
    "{E0D79306-84BE-11CE-9641-444553540000}" = "WinZip"
    -> {HKLM...CLSID} = "WinZip"
    \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing LP"]
    "{E0D79307-84BE-11CE-9641-444553540000}" = "WinZip"
    -> {HKLM...CLSID} = "WinZip"
    \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing LP"]
    "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Shell Extension"
    -> {HKLM...CLSID} = "AVG7 Shell Extension Class"
    \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
    "{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Find Extension"
    -> {HKLM...CLSID} = "AVG7 Find Extension Class"
    \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
    "{40950107-FEA6-4d53-A65F-B2DCBA57DD58}" = "Nokia Phone Browser"
    -> {HKLM...CLSID} = "Nokia Phone Browser"
    \InProcServer32\(Default) = "C:\Program Files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll" ["Nokia"]
    "{FBFE7864-D495-41f0-B7DC-4BB601CC295E}" = "Contact View"
    -> {HKLM...CLSID} = "Contact View"
    \InProcServer32\(Default) = "C:\Program Files\Nokia\Nokia PC Suite 6\ContactView.dll" ["Nokia"]
    "{C0C4375A-5B72-4efe-929D-3B848C3A1E91}" = "Message View"
    -> {HKLM...CLSID} = "Message View"
    \InProcServer32\(Default) = "C:\Program Files\Nokia\Nokia PC Suite 6\MessageView.dll" ["Nokia"]

    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\
    "{438755C2-A8BA-11D1-B96B-00A0C90312E1}" = "Browseui preloader"
    -> {HKLM...CLSID} = "Browseui preloader"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{8C7461EF-2B13-11d2-BE35-3078302C2030}" = "Component Categories cache daemon"
    -> {HKLM...CLSID} = "Component Categories cache daemon"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]

  4. #74
    Senior Member
    Join Date
    Mar 2006
    Posts
    114

    Default

    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
    "{AEB6717E-7E19-11d0-97EE-00C04FD91972}" = (no title provided)
    -> {HKLM...CLSID} = "URL Exec Hook"
    \InProcServer32\(Default) = "shell32.dll" [MS]
    <<!>> "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}" = "AVG Anti-Spyware 7.5"
    -> {HKLM...CLSID} = "CShellExecuteHookImpl Object"
    \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" ["Anti-Malware Development a.s."]

    HKCU\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\

    HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
    "Network.ConnectionTray" = "{7007ACCF-3202-11D1-AAD2-00805FC1270E}"
    -> {HKLM...CLSID} = "Network Connections Tray"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\NETSHELL.dll" [MS]
    "WebCheck" = "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
    -> {HKLM...CLSID} = "WebCheck"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\webcheck.dll" [MS]
    "SysTray" = "{35CEC8A3-2BE6-11D2-8773-92E220524153}"
    -> {HKLM...CLSID} = "SysTray"
    \InProcServer32\(Default) = "stobject.dll" [MS]

    HKCU\Software\Microsoft\Command Processor\
    "AutoRun" = (value not found)

    HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\
    "Shell" = (value not found)

    HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\
    "load" = (empty string)
    "run" = (value not found)

    HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\
    "Shell" = (value not found)

    HKLM\Software\Microsoft\Command Processor\
    "AutoRun" = (empty string)

    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\
    "AppInit_DLLs" = (empty string)

    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\
    "GinaDLL" = (value not found)
    "Shell" = "Explorer.exe" [MS]
    "Taskman" = (value not found)
    "Userinit" = "C:\WINDOWS\system32\userinit.exe," [MS]
    "System" = (empty string)

    HKLM\System\CurrentControlSet\Control\SafeBoot\Option\
    "UseAlternateShell" = (value not found)

    HKLM\System\CurrentControlSet\Control\SecurityProviders\
    "SecurityProviders" = "msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

    HKLM\System\CurrentControlSet\Control\Session Manager\
    "BootExecute" = "autocheck autochk *"

    HKLM\System\CurrentControlSet\Control\WOW\
    "cmdline" = "C:\WINDOWS\system32\ntvdm.exe" [MS]
    "wowcmdline" = "C:\WINDOWS\system32\ntvdm.exe -a C:\WINDOWS\system32\krnl386" [MS]

    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
    crypt32chain\DLLName = "crypt32.dll" [MS]
    cryptnet\DLLName = "cryptnet.dll" [MS]
    cscdll\DLLName = "cscdll.dll" [MS]
    sclgntfy\DLLName = "sclgntfy.dll" [MS]
    SensLogn\DLLName = "WlNotify.dll" [MS]
    wzcnotif\DLLName = "wzcdlg.dll" [MS]

    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\
    Your Image File Name Here without a path\Debugger = "ntsd -d" [MS]

    HKCU\Software\Policies\Microsoft\Windows\System\Scripts\

    HKLM\Software\Policies\Microsoft\Windows\System\Scripts\

    HKLM\Software\Classes\PROTOCOLS\Filter\
    Class Install Handler\CLSID = "{32B533BB-EDAE-11d0-BD5A-00AA00B92AF1}"
    -> {HKLM...CLSID} = "AP Class Install Handler filter"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\urlmon.dll" [MS]
    deflate\CLSID = "{8f6b0360-b80d-11d0-a9b3-006097942311}"
    -> {HKLM...CLSID} = "AP lzdhtml encoding/decoding Filter"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\urlmon.dll" [MS]
    gzip\CLSID = "{8f6b0360-b80d-11d0-a9b3-006097942311}"
    -> {HKLM...CLSID} = "AP lzdhtml encoding/decoding Filter"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\urlmon.dll" [MS]
    lzdhtml\CLSID = "{8f6b0360-b80d-11d0-a9b3-006097942311}"
    -> {HKLM...CLSID} = "AP lzdhtml encoding/decoding Filter"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\urlmon.dll" [MS]
    text/webviewhtml\CLSID = "{733AC4CB-F1A4-11d0-B951-00A0C90312E1}"
    -> {HKLM...CLSID} = "WebView MIME Filter"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]

    HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
    {0D2E74C4-3C34-11d2-A27E-00C04FC30871}\(Default) = (no title provided)
    -> {HKLM...CLSID} = (no title provided)
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]
    {24F14F01-7B1C-11d1-838f-0000F80461CF}\(Default) = (no title provided)
    -> {HKLM...CLSID} = (no title provided)
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]
    {24F14F02-7B1C-11d1-838f-0000F80461CF}\(Default) = (no title provided)
    -> {HKLM...CLSID} = (no title provided)
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]
    {66742402-F9B9-11D1-A202-0000F81FEDEE}\(Default) = "Version Column Provider"
    -> {HKLM...CLSID} = "Version Column Provider"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\docprop2.dll" [MS]
    {7f9609be-af9a-11d1-83e0-00c04fb6e984}\(Default) = "Fax Tiff Data Column Provider"
    -> {HKLM...CLSID} = "Fax Tiff Data Column Provider"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\faxshell.dll" [MS]
    {884EA37B-37C0-11d2-BE3F-00A0C9A83DA1}\(Default) = (no title provided)
    -> {HKLM...CLSID} = "ShAVColumnProvider class"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\docprop2.dll" [MS]

    HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
    AVG Anti-Spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
    -> {HKLM...CLSID} = "CContextScan Object"
    \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll" ["Anti-Malware Development a.s."]
    AVG7 Shell Extension\(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"
    -> {HKLM...CLSID} = "AVG7 Shell Extension Class"
    \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
    BriefcaseMenu\(Default) = "{85BBD920-42A0-1069-A2E4-08002B30309D}"
    -> {HKLM...CLSID} = "Briefcase"
    \InProcServer32\(Default) = "syncui.dll" [MS]
    Offline Files\(Default) = "{750fdf0e-2a26-11d1-a3ea-080036587f03}"
    -> {HKLM...CLSID} = "Offline Files Menu"
    \InProcServer32\(Default) = "cscui.dll" [MS]
    Open With\(Default) = "{09799AFB-AD67-11d1-ABCD-00C04FC30936}"
    -> {HKLM...CLSID} = "Open With Context Menu Handler"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]
    Open With EncryptionMenu\(Default) = "{A470F8CF-A1E8-4f65-8335-227475AA5C46}"
    -> {HKLM...CLSID} = "Add encryption item to context menus in explorer"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]
    WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
    -> {HKLM...CLSID} = "WinZip"
    \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing LP"]
    ZipItFast!\(Default) = "{00000001-0001-0001-0001-000000000019}"
    -> {HKLM...CLSID} = "ZipItFast! - Add to archive..."
    \InProcServer32\(Default) = "C:\zipitpro\zShellAd.dll" ["MicroSmarts Enterprise"]

    HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
    AVG Anti-Spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
    -> {HKLM...CLSID} = "CContextScan Object"
    \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll" ["Anti-Malware Development a.s."]
    Offline Files\(Default) = "{750fdf0e-2a26-11d1-a3ea-080036587f03}"
    -> {HKLM...CLSID} = "Offline Files Menu"
    \InProcServer32\(Default) = "cscui.dll" [MS]
    Open With EncryptionMenu\(Default) = "{A470F8CF-A1E8-4f65-8335-227475AA5C46}"
    -> {HKLM...CLSID} = "Add encryption item to context menus in explorer"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]
    Sharing\(Default) = "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"
    -> {HKLM...CLSID} = "Shell extensions for sharing"
    \InProcServer32\(Default) = "ntshrui.dll" [MS]
    WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
    -> {HKLM...CLSID} = "WinZip"
    \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing LP"]
    ZipItFast!\(Default) = "{00000001-0001-0001-0001-000000000019}"
    -> {HKLM...CLSID} = "ZipItFast! - Add to archive..."
    \InProcServer32\(Default) = "C:\zipitpro\zShellAd.dll" ["MicroSmarts Enterprise"]

    HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
    AVG7 Shell Extension\(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"
    -> {HKLM...CLSID} = "AVG7 Shell Extension Class"
    \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
    BriefcaseMenu\(Default) = "{85BBD920-42A0-1069-A2E4-08002B30309D}"
    -> {HKLM...CLSID} = "Briefcase"
    \InProcServer32\(Default) = "syncui.dll" [MS]
    WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
    -> {HKLM...CLSID} = "WinZip"
    \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing LP"]
    ZipItFast!\(Default) = "{00000001-0001-0001-0001-000000000019}"
    -> {HKLM...CLSID} = "ZipItFast! - Add to archive..."
    \InProcServer32\(Default) = "C:\zipitpro\zShellAd.dll" ["MicroSmarts Enterprise"]

    HKLM\Software\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\
    Send To\(Default) = "{7BA4C740-9E81-11CF-99D3-00AA004AE837}"
    -> {HKLM...CLSID} = "Microsoft SendTo Service"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]

  5. #75
    Senior Member
    Join Date
    Mar 2006
    Posts
    114

    Default

    Default executables:
    --------------------

    HKLM\Software\Classes\.bat\(Default) = "batfile"
    HKLM\Software\Classes\batfile\shell\open\command\(Default) = ""%1" %*"

    HKLM\Software\Classes\.cmd\(Default) = "cmdfile"
    HKLM\Software\Classes\cmdfile\shell\open\command\(Default) = ""%1" %*"

    HKLM\Software\Classes\.com\(Default) = "comfile"
    HKLM\Software\Classes\comfile\shell\open\command\(Default) = ""%1" %*"

    HKLM\Software\Classes\.exe\(Default) = "exefile"
    HKLM\Software\Classes\exefile\shell\open\command\(Default) = ""%1" %*"

    HKLM\Software\Classes\.hta\(Default) = "htafile"
    HKLM\Software\Classes\htafile\shell\open\command\(Default) = "C:\WINDOWS\System32\mshta.exe "%1" %*"

    HKLM\Software\Classes\.pif\(Default) = "piffile"
    HKLM\Software\Classes\piffile\shell\open\command\(Default) = ""%1" %*"

    HKLM\Software\Classes\.scr\(Default) = "scrfile"
    HKLM\Software\Classes\scrfile\shell\open\command\(Default) = ""%1" /S"


    Group Policies {GPedit.msc branch and setting}:
    -----------------------------------------------

    Note: detected settings may not have any effect.

    HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\

    HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\

    HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\

    HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\

    "NoDriveTypeAutoRun" = (REG_DWORD) hex:0x00000095
    {User Configuration|Administrative Templates|Windows Components|AutoPlay Policies|
    Turn off Autoplay}

    "CDRAutoRun" = (REG_DWORD) hex:0x00000000
    {unrecognized setting}

    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\

    HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowCpl\

    HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\

    "DisableRegistryTools" = (REG_DWORD) hex:0x00000000
    {User Configuration|Administrative Templates|System|
    Disable registry editing tools}

    HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\WindowsUpdate\

    HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\

    HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel\

    HKCU\Software\Policies\Microsoft\Internet Explorer\Download\

    HKLM\Software\Policies\Microsoft\Internet Explorer\Download\

    HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\

    HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\

    HKCU\Software\Policies\Microsoft\Internet Explorer\Main\

    HKLM\Software\Policies\Microsoft\Internet Explorer\Main\

    HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\

    HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\

    HKCU\Software\Policies\Microsoft\Internet Explorer\PhishingFilter\

    HKLM\Software\Policies\Microsoft\Internet Explorer\PhishingFilter\

    HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\

    HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions\

    HKCU\Software\Policies\Microsoft\Internet Explorer\Security\

    HKLM\Software\Policies\Microsoft\Internet Explorer\Security\

    HKCU\Software\Policies\Microsoft\MMC\{8FC0B734-A0E1-11D1-A7D3-0000F87571E3}\

    HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2\

    HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2\

    HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3\

    HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3\

    HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4\

    HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4\

    HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\

    HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\

    HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\

    HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\

    HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\

    HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\

    HKCU\Software\Policies\Microsoft\Windows\Network Connections\

    HKCU\Software\Policies\Microsoft\Windows\System\

    HKCU\Software\Policies\Microsoft\Windows\Task Scheduler5.0\

    HKLM\Software\Policies\Microsoft\Windows\Task Scheduler5.0\

    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\

    "dontdisplaylastusername" = (REG_DWORD) hex:0x00000000
    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
    Interactive logon: Do not display last user name}

    "shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
    Shutdown: Allow system to be shut down without having to log on}


    Active Desktop and Wallpaper:
    -----------------------------

    Active Desktop may be enabled at this entry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

    Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
    HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
    "Wallpaper" = "E:\My Documents\My Pictures\Kodak Pictures\Sea Side 2006-07-03\02-07-06_15231.jpg"

    Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
    HKCU\Control Panel\Desktop\
    "Wallpaper" = "C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp"


    Enabled Screen Saver:
    ---------------------

    HKCU\Control Panel\Desktop\
    "SCRNSAVE.EXE" = (value not set)


    Autostart via AUTORUN.INF on local fixed drives:
    ------------------------------------------------

    C:\
    AUTORUN.INF -> (file not found)

    E:\
    AUTORUN.INF -> (file not found)


    DESKTOP.INI DLL launch in local fixed drive directories:
    --------------------------------------------------------

    C:\WINDOWS\FONTS\DESKTOP.INI
    [.ShellClassInfo]
    UICLSID={BD84B380-8CA2-1069-AB1D-08000948F534}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "fontext.dll" [MS]

    C:\WINDOWS\TASKS\DESKTOP.INI
    [.ShellClassInfo]
    CLSID={d6277990-4c6a-11cf-8d87-00aa0060f5bf}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\mstask.dll" [MS]

    C:\WINDOWS\Downloaded Program Files\DESKTOP.INI
    [.ShellClassInfo]
    CLSID={88C6C381-2E85-11d0-94DE-444553540000}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\occache.dll" [MS]

    C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\DESKTOP.INI
    [.ShellClassInfo]
    UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\DESKTOP.INI
    [.ShellClassInfo]
    UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\8HUNG567\DESKTOP.INI
    [.ShellClassInfo]
    UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\WRGJY1ML\DESKTOP.INI
    [.ShellClassInfo]
    UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\OTA349IB\DESKTOP.INI
    [.ShellClassInfo]
    UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\WDIJKPUF\DESKTOP.INI
    [.ShellClassInfo]
    UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    C:\Documents and Settings\Default User\Local Settings\History\DESKTOP.INI
    [.ShellClassInfo]
    UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
    CLSID={FF393560-C2A7-11CF-BFF4-444553540000}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    C:\Documents and Settings\Default User\Local Settings\History\History.IE5\DESKTOP.INI
    [.ShellClassInfo]
    UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
    CLSID={FF393560-C2A7-11CF-BFF4-444553540000}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    C:\Documents and Settings\bester\Local Settings\History\DESKTOP.INI
    [.ShellClassInfo]
    UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
    CLSID={FF393560-C2A7-11CF-BFF4-444553540000}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    C:\Documents and Settings\bester\Local Settings\History\History.IE5\DESKTOP.INI
    [.ShellClassInfo]
    UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
    CLSID={FF393560-C2A7-11CF-BFF4-444553540000}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    C:\Documents and Settings\bester\Local Settings\Temporary Internet Files\DESKTOP.INI
    [.ShellClassInfo]
    UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    C:\Documents and Settings\bester\Local Settings\Temporary Internet Files\Content.IE5\DESKTOP.INI
    [.ShellClassInfo]
    UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    C:\Documents and Settings\bester\Local Settings\Temporary Internet Files\Content.IE5\XP83A7Y3\DESKTOP.INI
    [.ShellClassInfo]
    UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    C:\Documents and Settings\bester\Local Settings\Temporary Internet Files\Content.IE5\4XMVOH6J\DESKTOP.INI
    [.ShellClassInfo]
    UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    C:\Documents and Settings\bester\Local Settings\Temporary Internet Files\Content.IE5\89I7K9UZ\DESKTOP.INI
    [.ShellClassInfo]
    UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    C:\Documents and Settings\bester\Local Settings\Temporary Internet Files\Content.IE5\DCISZW80\DESKTOP.INI
    [.ShellClassInfo]
    UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    C:\Documents and Settings\Administrator\Local Settings\History\DESKTOP.INI
    [.ShellClassInfo]
    UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
    CLSID={FF393560-C2A7-11CF-BFF4-444553540000}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\DESKTOP.INI
    [.ShellClassInfo]
    UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
    CLSID={FF393560-C2A7-11CF-BFF4-444553540000}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\DESKTOP.INI
    [.ShellClassInfo]
    UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\DESKTOP.INI
    [.ShellClassInfo]
    UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\INPZKUG0\DESKTOP.INI
    [.ShellClassInfo]
    UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\ARXJAPQO\DESKTOP.INI
    [.ShellClassInfo]
    UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2Z2LCD4N\DESKTOP.INI
    [.ShellClassInfo]
    UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\KN8P2BML\DESKTOP.INI
    [.ShellClassInfo]
    UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\QQUM02JU\DESKTOP.INI
    [.ShellClassInfo]
    UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\92BZJBP7\DESKTOP.INI
    [.ShellClassInfo]
    UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\MR07Q5Y3\DESKTOP.INI
    [.ShellClassInfo]
    UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
    -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    E: (no DLL launch points found)

    Startup items in "Administrator" & "All Users" startup folders:
    ---------------------------------------------------------------

    C:\Documents and Settings\Administrator\Start Menu\Programs\Startup
    "Freecom Personal Media Suite" -> shortcut to: "C:\Program Files\Freecom Personal Media Suite\FCPMS.exe" ["Freecom"]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup
    "Adobe Gamma Loader" -> shortcut to: "C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe" ["Adobe Systems, Inc."]
    "Kodak EasyShare software" -> shortcut to: "C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe -h" ["Eastman Kodak Company"]
    "WinZip Quick Pick" -> shortcut to: "C:\Program Files\WinZip\WZQKPICK.EXE" ["WinZip Computing LP"]
    "BlueSoleil" -> shortcut to: "C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe" ["IVT Corporation"]


    Enabled Scheduled Tasks:
    ------------------------

    "Tune-up Application Start" -> launches: "walign" [file not found]


    Winsock2 Service Provider DLLs:
    -------------------------------

    Namespace Service Providers

    HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
    000000000001\LibraryPath = "%SystemRoot%\System32\rnr20.dll" [MS]
    000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]

    Transport Service Providers

    HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
    00000000000#\PackedCatalogItem (contains) DLL [Company Name], (at) # range:
    %SystemRoot%\system32\msafd.dll [MS], 1 - 3
    %SystemRoot%\system32\rsvpsp.dll [MS], 4 - 5


    Toolbars, Explorer Bars, Extensions:
    ------------------------------------

    Toolbars

    HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\
    "{01E04581-4EEE-11D0-BFE9-00AA005B4383}"
    -> {HKLM...CLSID} = "&Address"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{0E5CBF21-D15F-11D0-8301-00AA005B4383}"
    -> {HKLM...CLSID} = "&Links"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]

    HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
    "{01E04581-4EEE-11D0-BFE9-00AA005B4383}"
    -> {HKLM...CLSID} = "&Address"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{0E5CBF21-D15F-11D0-8301-00AA005B4383}"
    -> {HKLM...CLSID} = "&Links"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    "{FE6BC4EF-5676-484B-88AE-883323913256}"
    -> {HKLM...CLSID} = "Starware"
    \InProcServer32\(Default) = "C:\PROGRA~1\COMETS~1\Platform\Bin\csietb.dll" [file not found]
    "{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}"
    -> {HKLM...CLSID} = "MSN"
    \InProcServer32\(Default) = "C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-gb\msntb.dll" [MS]

    HKLM\Software\Microsoft\Internet Explorer\Toolbar\
    "{8E718888-423F-11D2-876E-00A0C9082467}" = (no title provided)
    -> {HKLM...CLSID} = "&Radio"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\msdxm.ocx" [MS]
    "{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" = "0"
    -> {HKLM...CLSID} = "MSN"
    \InProcServer32\(Default) = "C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-gb\msntb.dll" [MS]
    Explorer Bars

    HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\
    {30D02401-6A81-11D0-8274-00C04FD5AE38}\(Default) = (no title provided)
    -> {HKLM...CLSID} = "Search Band"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    {32683183-48A0-441B-A342-7C2A440A9478}\(Default) = (no title provided)
    -> {HKLM...CLSID} = "Media Band"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\browseui.dll" [MS]
    {C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\(Default) = (no title provided)
    -> {HKLM...CLSID} = "File and Folders Search ActiveX Control"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shell32.dll" [MS]
    {EFA24E61-B078-11D0-89E4-00C04FC9E26E}\(Default) = (no title provided)
    -> {HKLM...CLSID} = "Favorites Band"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
    {EFA24E62-B078-11D0-89E4-00C04FC9E26E}\(Default) = (no title provided)
    -> {HKLM...CLSID} = "History Band"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\
    {4D5C8C25-D075-11D0-B416-00C04FB90376}\(Default) = (no title provided)
    -> {HKLM...CLSID} = "&Tip of the Day"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    HKLM\Software\Classes\CLSID\{90C61707-C8F8-43DB-A25C-C1F4B18EE41E}\(Default) = "Horizontal Bar"
    Implemented Categories\{00021494-0000-0000-C000-000000000046}\ [horizontal bar]
    InProcServer32\(Default) = "C:\PROGRA~1\COMETS~1\Platform\Bin\csband.dll" [file not found]

    HKLM\Software\Classes\CLSID\{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}\(Default) = "&Discuss"
    Implemented Categories\{00021494-0000-0000-C000-000000000046}\ [horizontal bar]
    InProcServer32\(Default) = "shdocvw.dll" [MS]

    HKLM\Software\Classes\CLSID\{EDC4193F-34AD-4D07-AA87-E3FDB89E3E76}\(Default) = "Vertical Bar"
    Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
    InProcServer32\(Default) = "C:\PROGRA~1\COMETS~1\Platform\Bin\csband.dll" [file not found]

  6. #76
    Senior Member
    Join Date
    Mar 2006
    Posts
    114

    Default

    HKLM\Software\Classes\CLSID\{EFA24E64-B078-11D0-89E4-00C04FC9E26E}\(Default) = "Explorer Band"
    Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
    InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    Extensions (Tools menu items, main toolbar menu buttons)

    HKCU\Software\Microsoft\Internet Explorer\Extensions\

    HKLM\Software\Microsoft\Internet Explorer\Extensions\


    Internet Explorer Address Prefixes:
    -----------------------------------

    Prefix for bare domain ("domain-name-here.com")

    HKLM\Software\Microsoft\Windows\CurrentVersion\URL\Default Prefix\
    (Default) = "http://"

    Prefix for specific service (i.e., "www")

    HKLM\Software\Microsoft\Windows\CurrentVersion\URL\Prefixes\
    "ftp" = "ftp://"
    "gopher" = "gopher://"
    "home" = "http://"
    "mosaic" = "http://"
    "www" = "http://"

    Miscellaneous IE Hijack Points
    ------------------------------

    C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings" -- no anomalies found)

    HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\
    "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" = (no title provided)
    -> {HKLM...CLSID} = "Microsoft Url Search Hook"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    HKLM\Software\Microsoft\Internet Explorer\AboutURLs\
    "NavigationFailure" = "res://shdoclc.dll/navcancl.htm" [MS]
    "DesktopItemNavigationFailure" = "res://shdoclc.dll/navcancl.htm" [MS]
    "NavigationCanceled" = "res://shdoclc.dll/navcancl.htm" [MS]
    "OfflineInformation" = "res://shdoclc.dll/offcancl.htm" [MS]
    "Home" = hex:0x0000010E
    "blank" = "res://mshtml.dll/blank.htm" [MS]
    "PostNotCached" = "res://mshtml.dll/repost.htm" [MS]
    "mozilla" = "res://mshtml.dll/about.moz" [MS]


    HOSTS file
    ----------

    HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\
    "DataBasePath" = "C:\WINDOWS\System32\drivers\etc"

    C:\WINDOWS\System32\drivers\etc\HOSTS

    maps: 1 domain name to an IP address,
    and this is the localhost IP address

    All Running Services (Display Name, Service Name, Path {Service DLL}):
    ----------------------------------------------------------------------

    Automatic Updates, wuauserv, "C:\WINDOWS\system32\svchost.exe -k wugroup" {"C:\WINDOWS\system32\wuauserv.dll" [MS]}
    AVG Anti-Spyware Guard, AVG Anti-Spyware Guard, "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe" ["Anti-Malware Development a.s."]
    AVG E-mail Scanner, AVGEMS, "C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe" ["GRISOFT, s.r.o."]
    AVG7 Alert Manager Server, Avg7Alrt, "C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe" ["GRISOFT, s.r.o."]
    AVG7 Update Service, Avg7UpdSvc, "C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe" ["GRISOFT, s.r.o."]
    Background Intelligent Transfer Service, BITS, "C:\WINDOWS\System32\svchost.exe -k BITSgroup" {"C:\WINDOWS\System32\qmgr.dll" [MS]}
    BlueSoleil Hid Service, BlueSoleil Hid Service, "C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe" [null data]
    COM+ Event System, EventSystem, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\es.dll" [MS]}
    DHCP Client, Dhcp, "C:\WINDOWS\System32\services.exe" [MS]
    Distributed Link Tracking Client, TrkWks, "C:\WINDOWS\system32\services.exe" [MS]
    DNS Client, Dnscache, "C:\WINDOWS\System32\services.exe" [MS]
    Event Log, Eventlog, "C:\WINDOWS\system32\services.exe" [MS]
    Indexing Service, cisvc, "C:\WINDOWS\System32\cisvc.exe" [MS]
    iPodService, iPodService, "C:\Program Files\iPod\bin\iPodService.exe" ["Apple Computer, Inc."]
    Kodak Camera Connection Software, KodakCCS, "C:\WINDOWS\system32\drivers\KodakCCS.exe" ["Eastman Kodak Company"]
    LexBce Server, LexBceS, "C:\WINDOWS\system32\LEXBCES.EXE" ["Lexmark International, Inc."]
    Logical Disk Manager, dmserver, "C:\WINDOWS\System32\services.exe" [MS]
    Network Connections, Netman, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\netman.dll" [MS]}
    Plug and Play, PlugPlay, "C:\WINDOWS\system32\services.exe" [MS]
    Print Spooler, Spooler, "C:\WINDOWS\system32\spoolsv.exe" [MS]
    Protected Storage, ProtectedStorage, "C:\WINDOWS\system32\services.exe" [MS]
    ptssvc, ptssvc, "C:\Program Files\Kodak\Kodak EasyShare software\bin\ptssvc.exe" ["KODAK"]
    Remote Access Connection Manager, RasMan, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\rasmans.dll" [MS]}
    Remote Procedure Call (RPC), RpcSs, "C:\WINDOWS\system32\svchost -k rpcss" {"C:\WINDOWS\system32\rpcss.dll" [MS]}
    Removable Storage, NtmsSvc, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\NtmsSvc.dll" [MS]}
    RunAs Service, seclogon, "C:\WINDOWS\system32\services.exe" [MS]
    ScsiAccess, ScsiAccess, "C:\WINDOWS\system32\ScsiAccess.EXE" [null data]
    Security Accounts Manager, SamSs, "C:\WINDOWS\system32\lsass.exe" [MS]
    Still Image Service, StiSvc, "C:\WINDOWS\system32\stisvc.exe" [MS]
    System Event Notification, SENS, "C:\WINDOWS\system32\svchost.exe -k netsvcs" {"C:\WINDOWS\system32\sens.dll" [MS]}
    Task Scheduler, Schedule, "C:\WINDOWS\system32\MSTask.exe" [MS]
    TCP/IP NetBIOS Helper Service, LmHosts, "C:\WINDOWS\System32\services.exe" [MS]
    Telephony, TapiSrv, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\tapisrv.dll" [MS]}
    Windows Management Instrumentation, WinMgmt, "C:\WINDOWS\System32\WBEM\WinMgmt.exe" [MS]
    Windows Management Instrumentation Driver Extensions, Wmi, "C:\WINDOWS\system32\Services.exe" [MS]


    Keyboard Driver Filters:
    ------------------------

    HKLM\System\CurrentControlSet\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}\
    "UpperFilters" = "kbdclass" [MS]


    Print Monitors:
    ---------------

    HKLM\System\CurrentControlSet\Control\Print\Monitors\
    BJ Language Monitor\Driver = "cnbjmon.dll" [MS]
    Lexmark Network Port\Driver = "LEXLMPM.DLL" ["Lexmark International, Inc."]
    Local Port\Driver = "localspl.dll" [MS]
    PJL Language Monitor\Driver = "pjlmon.dll" [MS]
    Standard TCP/IP Port\Driver = "tcpmon.dll" [MS]
    USB Monitor\Driver = "usbmon.dll" [MS]
    Windows NT Fax Monitor\Driver = "msfaxmon.dll" [MS]


    -- (total run time: 212 seconds)
    <<!>>: Suspicious data at a malware launch point.


    This is the end of the report!!

  7. #77
    Esteemed Security Expert: Emeritus
    Join Date
    Feb 2006
    Posts
    367

    Default

    Let's see if you can repair Internet Explorer. Go to Add Remove programs in control panel

    Find internet Explorer on the list and click
    Remove. If available, 3 options should appear. Select Repair. Let me know what happens please. If you can't repair, don't remove IE.



    May I see a hijackthis log please?

    I want to see your running tasks.


    Then we'll do some more maintenance.


    I take it you saw no problem devices in Device Manager?

  8. #78
    Senior Member
    Join Date
    Mar 2006
    Posts
    114

    Default

    Hmm, Can't find Internet Explorer in Add / Remove programs unless it's under a diferent name. I have something called Broadband Client Foundation and I don't know what that is (Unless it;s something to do with my service provider).

    In Device Manager I did find some errors:- From 24/12/06 they are files names Windows Event Manager & SAM. Before that date they were DCOM, Service Ctrl Mgr & SAM.

    Here's HJT:-

    Logfile of HijackThis v1.99.1
    Scan saved at 9:11:23 PM, on 1/10/2007
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
    C:\WINDOWS\System32\cisvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\drivers\KodakCCS.exe
    C:\Program Files\Kodak\Kodak EasyShare software\bin\ptssvc.exe
    C:\WINDOWS\system32\MSTask.exe
    C:\WINDOWS\system32\ScsiAccess.EXE
    C:\WINDOWS\system32\stisvc.exe
    C:\WINDOWS\System32\WBEM\WinMgmt.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\cidaemon.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe
    C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-gb\msnappau.exe
    C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
    C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\BroadJump\Client Foundation\CFD.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
    C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
    C:\Program Files\Freecom Personal Media Suite\FCPMS.exe
    C:\PROGRA~1\INCRED~1\bin\IMAPP.EXE
    C:\Antispyware\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ntlworld.com
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1001\en-xu\stmain.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-gb\msntb.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-gb\msntb.dll
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
    O4 - HKLM\..\Run: [MPFTray] C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-gb\msnappau.exe"
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
    O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
    O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5
    O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
    O4 - HKCU\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
    O4 - Startup: Freecom Personal Media Suite.lnk = C:\Program Files\Freecom Personal Media Suite\FCPMS.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
    O15 - Trusted Zone: http://www.freewebs.com
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1130231909123
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1131100914278
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/ms...downloader.cab
    O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www5.incredimail.com/contents...r/imloader.cab
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINDOWS\System32\dmadmin.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: ptssvc - KODAK - C:\Program Files\Kodak\Kodak EasyShare software\bin\ptssvc.exe
    O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE

  9. #79
    Esteemed Security Expert: Emeritus
    Join Date
    Feb 2006
    Posts
    367

    Default

    You have too many startups. Many are not needed.

    Plus you're running a service which is notorious for slowing a computer to a crawl.
    The indexing service.
    Let's set it to manual and see if that helps a bit.



    Go to Start >Run
    Type services.msc
    Press enter.
    When the services Panel loads, Find Indexing service on the list.
    Double click on it.
    This will bring up its properties page.
    Look for Startup Type and set it to manual.
    Stop the service.
    Click the ok button. Close the page.


    **If you use MS Office, it may get turned back on. Watch your Task Manager to see if it does.
    **Look for cidaemon in task manager.

    -------------------------

    Now for the hijackthis fixes: (we may do more later)


    These are not needed startups. Let's fix them using Hijackthis. If you want to start them do it manually. Hijackthis will create backups for these entries in its backup folder. So don't delete that in the event you change your mind about these entries.


    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-gb\msnappau.exe"
    O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
    O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5

    ---------------

    This too. It looks like a leftover from McAfee.

    O4 - HKLM\..\Run: [MPFTray] C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE


    And finally, let's remove this from the trusted zone:
    O15 - Trusted Zone: http://www.freewebs.com


    ------------------------

    Often you don't have Internet Explorer listed in Add Remove Programs running win2k.

    We'll get back to that later.

    For now, you have several scanners running in the background. So stopping the indexing servcie will help. But if you have just recently installed the AVG antispyware program, you are going to notice a bit of a slowdown. I'm guessing you're short on RAM.
    Let's start with this and see how it goes.

    You are just running so much Software, we'll have to see what your system will support at any one given time. Anything you don't need can be started manually. Look at it and see if you really need the other startups.


    --------------------

    Info on Broadband Client Foundation
    http://www.bleepingcomputer.com/star...D.exe-777.html



    But something really important is missing. You are not running a firewall.

    There will likely be more to do.
    Last edited by Mosaic1; 2007-01-10 at 23:35.

  10. #80
    Senior Member
    Join Date
    Mar 2006
    Posts
    114

    Default

    Hi,

    Sos about the delay I was away for the day yesterday.

    I stopped The Indexing Service, fixed the HJT items and looked at the Broadband Client info and followed instructions to remove that. I'm not usre how to change the other systems we have to run manually, I'm not even sure of half the stuff on here.

    One thing I havenoticed is that the computer name has taken the name of my Bluetooth and I tried to download some pictures from my phone the last two days & I am unable to connect, I'm not sure if the two are related but I never had any problems with the Bluetooth before the computer ceized.

    I wasn't sure if you needed another HJT log, you haven't asked so I haven't done one...

    With the firewall, we had one with McAfee, but I presumed that we were still ok with AVG etc after we uninstalled McAfee. I didn't realise we didn't have one...

    Speak soon.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •