Warum kostenlos registrieren?

Nur als registriertes Mitglied hast Du vollen Zugriff auf alle Funktionen unserer Website. So kannst Du eigene Fragen stellen und hast die volle Übersicht über neue interessante Themen im Forum.
Jetzt kostenlos registrieren.

Login


viren und trojaner auf dem rechner

Warnungen vor Sicherheitslücken und Hilfe beim Enfernen von Viren, Würmern und Trojanern.

viren und trojaner auf dem rechner

Beitragvon vivi am 24.10.2007, 20:10

hallo, mithilfe von Avira AntiVir PersonalEdition Classic habe ich 28 Viren/Trojaner/usw. gefunden. Nun will ich sie entfernen und habe hier mal mit HiJackThis einen log erstellt:


Code: Alles auswählen
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:59:15, on 24.10.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\csrss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Programme\Ahead\InCD\InCDsrv.exe
C:\windows\System32\svchost.exe
C:\windows\System32\svchost.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe
C:\windows\system32\spoolsv.exe
C:\windows\System32\SCardSvr.exe
C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Programme\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Inetd\inetd32.exe
C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Jconfig\jconfigdnt.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Jconfig\hjavaw.exe
C:\Programme\mpich.1.2.5\mpd\bin\mpd.exe
C:\Programme\Java\jre1.6.0_02\bin\javaw.exe
C:\windows\system32\ntkrnl.exe
C:\Programme\Citrix\ICA Client\ssonsvr.exe
C:\WINDOWS\system32\nutsrv4.exe
C:\Programme\Symantec AntiVirus\SavRoam.exe
C:\PROGRA~1\MKSTOO~1\bin\snmptrapd.exe
C:\Programme\Analog Devices\SoundMAX\SMAgent.exe
C:\windows\System32\svchost.exe
C:\Programme\Symantec AntiVirus\Rtvscan.exe
C:\windows\system32\Ati2evxx.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\windows\Explorer.EXE
C:\windows\System32\alg.exe
C:\windows\system32\Rundll32.exe
C:\Programme\Synaptics\SynTP\SynTPLpr.exe
C:\Programme\Synaptics\SynTP\SynTPEnh.exe
C:\windows\SOUNDMAN.EXE
C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programme\ltmoh\Ltmoh.exe
C:\Programme\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Programme\Ahead\InCD\InCD.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~2\VPTray.exe
C:\Programme\Java\jre1.6.0_02\bin\jusched.exe
C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\windows\system32\ctfmon.exe
C:\windows\system32\wuauclt.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\Programme\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com.cn
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com.cn
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://seek.yisou.com/srchasst.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://seek.yisou.com/srchcust.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.fzk.de/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=proxy.fzk.de:8000;gopher=proxy.fzk.de:8000;http=proxy.fzk.de:8000;https=proxy.fzk.de:443
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fzk.de;141.52.*;192.168.24.*;sapwgate;localhost;127.0.0.1
R3 - URLSearchHook: ÑÅ»¢ÖúÊÖ - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: UkxHdvzb Class - {B19D80C2-ECE8-1787-7B51-100F1B3169AD} - C:\WINDOWS\DOWNLO~1\acjki.dll (file missing)
O2 - BHO: Flash 8 ocx  - {B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD} - C:\WINDOWS\flash8.dll (file missing)
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\DOWNLO~1\CnsHook.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: ÑÅ»¢ÖúÊÖ - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Programme\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programme\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [LtMoh] C:\Programme\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [NuTCSetupEnviron] C:\PROGRA~1\MKSTOO~1\bin\ncoeenv.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Programme\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [InCD] C:\Programme\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [IMSCMIG40W] C:\PROGRA~1\GEMEIN~1\MICROS~1\IME\IMSC40W\IMSCMIG.EXE /SetPreload /Log
O4 - HKLM\..\Run: [ccApp] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: ???? - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246
O8 - Extra context menu item: Ìí¼Óµ½ÑÅ»¢¶©ÔÄ(&Y) - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll/YRSSMENUEXT
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Yahoo 1G mail - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail (file missing)
O9 - Extra button: E bazar - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://adtaobao.allyes.com/main/adfclick?db=adtaobao&bid=138,140,18&cid=816,8,1&sid=5042&show=ignore&url=http://www.taobao.com/vertical/mall/pro.php?allyesPara=816 (file missing)
O9 - Extra button: Chinese Navigation - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~2\CNNIC\Cdn\cdnforie.dll (file missing)
O9 - Extra 'Tools' menuitem: Chinese Navigation - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~2\CNNIC\Cdn\cdnforie.dll (file missing)
O9 - Extra button: Yahoo Assistant - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist (file missing)
O9 - Extra button: (no name) - {6354ABE6-05F1-49ed-B850-E423120EC338} - http://cn.widget.yahoo.com/index.htm?source=Cns (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Instant Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - Extra 'Tools' menuitem: Repair Browser - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O9 - Extra 'Tools' menuitem: Clean Internet access record - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O11 - Options group: [!CNS]  Chinese keywords
O17 - HKLM\System\CCS\Services\Tcpip\..\{315E0DDA-66CB-457D-AC57-7F1ACC4A9473}: NameServer = 202.120.2.101,202.120.2.100,141.52.92.151,141.52.92.152,141.52.92.153
O17 - HKLM\System\CCS\Services\Tcpip\..\{AD2B02C7-5359-4653-8F3E-8DB753F0D052}: NameServer = 141.52.3.3,141.52.8.18,141.52.92.151,141.52.92.152,141.52.92.153
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = fzk.de,ka.fzk.de
O17 - HKLM\System\CS1\Services\Tcpip\..\{315E0DDA-66CB-457D-AC57-7F1ACC4A9473}: NameServer = 202.120.2.101,202.120.2.100,141.52.92.151,141.52.92.152,141.52.92.153
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = fzk.de,ka.fzk.de
O17 - HKLM\System\CS2\Services\Tcpip\..\{315E0DDA-66CB-457D-AC57-7F1ACC4A9473}: NameServer = 202.120.2.101,202.120.2.100,141.52.92.151,141.52.92.152,141.52.92.153
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = fzk.de,ka.fzk.de
O23 - Service: AntiVir PersonalEdition Classic Planer (AntiVirScheduler) - Avira GmbH - C:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\windows\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Programme\Symantec AntiVirus\DefWatch.exe
O23 - Service: Hummingbird INETD (HCLInetd) - Hummingbird Ltd. - C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Inetd\inetd32.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Programme\Ahead\InCD\InCDsrv.exe
O23 - Service: Hummingbird Jconfig-Dämon (Jconfigd) - Hummingbird Ltd. - C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Jconfig\jconfigdnt.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MPICH Daemon (C) 2001 Argonne National Lab (mpich_mpd) - Unknown owner - C:\Programme\mpich.1.2.5\mpd\bin\mpd.exe
O23 - Service: Windows Desktop Multimedia (ntkrnl) - Unknown owner - C:\windows\SYSTEM32\ntkrnl.exe
O23 - Service: NuTCRACKER Service (NuTCRACKERService) - DataFocus, Inc. - C:\WINDOWS\system32\nutsrv4.exe
O23 - Service: Portmap - Unknown owner - C:\windows\system32\portmap.exe
O23 - Service: SAVRoam - symantec - C:\Programme\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\SNDSrvc.exe
O23 - Service: SNMPTrapd Service (SNMPTrapdService) - DataFocus, Inc. - C:\PROGRA~1\MKSTOO~1\bin\snmptrapd.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programme\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Programme\Symantec AntiVirus\Rtvscan.exe

--
End of file - 12468 bytes


Könntet ihr mir helfen? Vielen Dank im Vorraus.
vivi
 
Beiträge: 35
Registriert: 24.07.2006, 19:05


Beitragvon Humdinger am 25.10.2007, 17:53

Hallo

Zwei Virenscanner sind einer zuviel.

Deinstalliere Antivir.
PC Neustart

Sagt dir dies was???:

202.120.2.101
address: Room 224, Main Building
address: Tsinghua University
address: Beijing 100084, China
address: 1954 Huashan Rd.
address: Shanghai Jiaotong University
address: Shanghai, 200030, CN
address: 1954 Huashan Rd.
address: Shanghai Jiaotong University
address: Shanghai, 200030, CN


Poste einen neuen HijackThis log

Lade dir Navilog1.zip,auf dem Desktop speichern & entpacken,danach wird einen Ordner Navilog1 auf dem Desktop erstellt.Nun muss du dieser Ordner öffnen,dann Doppelklick auf Navilog1.bat,dann Sprache Auswahl F|f-->Französisch & E|e-->Englisch,den Anweisungen auf dem Bildschirm folgen,immer eine beliebige Taste druecken bis ein Auswahl Fenster erscheint,dann die Taste 1,den Anweisungen auf dem Bildschirm folgen & am Ende den Inhalt von fixnavi.txt hier posten.

Hinweis

(Evtl. geben einige Antivirenprogramme eine Warnmeldung – diese übergehen/ignorieren, Scan zulassen)

WindowsScan laden,
ausführen, Report posten
Humdinger
Moderator
 
Beiträge: 1079
Registriert: 22.03.2006, 14:22
Wohnort: Mainz

Beitragvon vivi am 26.10.2007, 14:42

HiJackThis:

Code: Alles auswählen
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:28:19, on 26.10.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\csrss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Programme\Ahead\InCD\InCDsrv.exe
C:\windows\System32\svchost.exe
C:\windows\System32\svchost.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe
C:\windows\system32\spoolsv.exe
C:\windows\System32\SCardSvr.exe
C:\Programme\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Inetd\inetd32.exe
C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Jconfig\jconfigdnt.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Jconfig\hjavaw.exe
C:\Programme\mpich.1.2.5\mpd\bin\mpd.exe
C:\windows\system32\ntkrnl.exe
C:\Programme\Java\jre1.6.0_03\bin\javaw.exe
C:\Programme\Citrix\ICA Client\ssonsvr.exe
C:\WINDOWS\system32\nutsrv4.exe
C:\Programme\Symantec AntiVirus\SavRoam.exe
C:\PROGRA~1\MKSTOO~1\bin\snmptrapd.exe
C:\Programme\Analog Devices\SoundMAX\SMAgent.exe
C:\windows\System32\svchost.exe
C:\Programme\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\Explorer.EXE
C:\windows\System32\alg.exe
C:\windows\system32\Rundll32.exe
C:\Programme\Synaptics\SynTP\SynTPLpr.exe
C:\Programme\Synaptics\SynTP\SynTPEnh.exe
C:\windows\SOUNDMAN.EXE
C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programme\ltmoh\Ltmoh.exe
C:\Programme\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Programme\Ahead\InCD\InCD.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~2\VPTray.exe
C:\Programme\Java\jre1.6.0_03\bin\jusched.exe
C:\windows\system32\ctfmon.exe
C:\Programme\Symantec AntiVirus\DoScan.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\windows\system32\wuauclt.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Programme\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com.cn
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com.cn
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://seek.yisou.com/srchasst.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://seek.yisou.com/srchcust.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.fzk.de/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer =

ftp=proxy.fzk.de:8000;gopher=proxy.fzk.de:8000;http=proxy.fzk.de:8000;https=proxy.fzk.de:443
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =

*.fzk.de;141.52.*;192.168.24.*;sapwgate;localhost;127.0.0.1
R3 - URLSearchHook: ÑÅ»¢ÖúÊÖ - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: UkxHdvzb Class - {B19D80C2-ECE8-1787-7B51-100F1B3169AD} - C:\WINDOWS\DOWNLO~1\acjki.dll (file missing)
O2 - BHO: Flash 8 ocx  - {B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD} - C:\WINDOWS\flash8.dll (file missing)
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\DOWNLO~1\CnsHook.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: ÑÅ»¢ÖúÊÖ - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Programme\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programme\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [LtMoh] C:\Programme\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [NuTCSetupEnviron] C:\PROGRA~1\MKSTOO~1\bin\ncoeenv.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Programme\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [InCD] C:\Programme\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [IMSCMIG40W] C:\PROGRA~1\GEMEIN~1\MICROS~1\IME\IMSC40W\IMSCMIG.EXE /SetPreload /Log
O4 - HKLM\..\Run: [ccApp] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: ???? - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246
O8 - Extra context menu item: Ìí¼Óµ½ÑÅ»¢¶©ÔÄ(&Y) - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll/YRSSMENUEXT
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Yahoo 1G mail - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail

(file missing)
O9 - Extra button: E bazar - {59BC54A2-56B3-44a0-93E5-432D58746E26} -

http://adtaobao.allyes.com/main/adfclick?db=adtaobao&bid=138,140,18&cid=816,8,1&sid=5042&show=ignore&url=http://www.taobao.com/vertical/ma

ll/pro.php?allyesPara=816 (file missing)
O9 - Extra button: Chinese Navigation - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~2\CNNIC\Cdn\cdnforie.dll (file missing)
O9 - Extra 'Tools' menuitem: Chinese Navigation - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~2\CNNIC\Cdn\cdnforie.dll (file

missing)
O9 - Extra button: Yahoo Assistant - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist

(file missing)
O9 - Extra button: (no name) - {6354ABE6-05F1-49ed-B850-E423120EC338} - http://cn.widget.yahoo.com/index.htm?source=Cns (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Instant Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} -

http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file

missing)
O9 - Extra 'Tools' menuitem: Repair Browser - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} -

http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file

missing)
O9 - Extra 'Tools' menuitem: Clean Internet access record - {FD00D911-7529-4084-9946-A29F1BDF4FE5} -

http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O11 - Options group: [!CNS]  Chinese keywords
O17 - HKLM\System\CCS\Services\Tcpip\..\{315E0DDA-66CB-457D-AC57-7F1ACC4A9473}: NameServer =

202.120.2.101,202.120.2.100,141.52.92.151,141.52.92.152,141.52.92.153
O17 - HKLM\System\CCS\Services\Tcpip\..\{AD2B02C7-5359-4653-8F3E-8DB753F0D052}: NameServer =

141.52.3.3,141.52.8.18,141.52.92.151,141.52.92.152,141.52.92.153
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = fzk.de,ka.fzk.de
O17 - HKLM\System\CS1\Services\Tcpip\..\{315E0DDA-66CB-457D-AC57-7F1ACC4A9473}: NameServer =

202.120.2.101,202.120.2.100,141.52.92.151,141.52.92.152,141.52.92.153
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = fzk.de,ka.fzk.de
O17 - HKLM\System\CS2\Services\Tcpip\..\{315E0DDA-66CB-457D-AC57-7F1ACC4A9473}: NameServer =

202.120.2.101,202.120.2.100,141.52.92.151,141.52.92.152,141.52.92.153
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = fzk.de,ka.fzk.de
O23 - Service: Ati HotKey Poller - Unknown owner - C:\windows\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Programme\Symantec AntiVirus\DefWatch.exe
O23 - Service: Hummingbird INETD (HCLInetd) - Hummingbird Ltd. - C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Inetd\inetd32.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Programme\Ahead\InCD\InCDsrv.exe
O23 - Service: Hummingbird Jconfig-Dämon (Jconfigd) - Hummingbird Ltd. -

C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Jconfig\jconfigdnt.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MPICH Daemon (C) 2001 Argonne National Lab (mpich_mpd) - Unknown owner - C:\Programme\mpich.1.2.5\mpd\bin\mpd.exe
O23 - Service: Windows Desktop Multimedia (ntkrnl) - Unknown owner - C:\windows\SYSTEM32\ntkrnl.exe
O23 - Service: NuTCRACKER Service (NuTCRACKERService) - DataFocus, Inc. - C:\WINDOWS\system32\nutsrv4.exe
O23 - Service: Portmap - Unknown owner - C:\windows\system32\portmap.exe
O23 - Service: SAVRoam - symantec - C:\Programme\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec

Shared\SNDSrvc.exe
O23 - Service: SNMPTrapd Service (SNMPTrapdService) - DataFocus, Inc. - C:\PROGRA~1\MKSTOO~1\bin\snmptrapd.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programme\Analog

Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Programme\Symantec AntiVirus\Rtvscan.exe

--
End of file - 11930 bytes


Und bezüglich des Zitates: Ich weiß nur, dass es chinesische unis sind...abba des wars dann auch schon :shock:

Und ähm ich hab alles gemacht, Navilog entzippt in Desktopordner Navilog1, abba wenn ich auf die bat datei klick, sagts mir, dass es des net finden konnte...
vivi
 
Beiträge: 35
Registriert: 24.07.2006, 19:05

Beitragvon Humdinger am 26.10.2007, 16:42

Starte diese Batchdatei datfind.bat
danach öffnet sich ein Notepad/Editor Fenster.
Kopiere diese erstellte Textdatei ab . (rechtsklick mit der Maus -> den Text markieren -> kopieren -> einfügen) Sie ist nach Datum geordnet.
(kürze die Textdatei je Verzeichnis auf die letzten 3 Monate !)
Humdinger
Moderator
 
Beiträge: 1079
Registriert: 22.03.2006, 14:22
Wohnort: Mainz

Beitragvon vivi am 27.10.2007, 10:35

also ich weiß nicht warum, aber ich habe diese bat datei gespeichert, es gestartet und dann kam wieder dieselbe fehlermeldung wie bei Navilog. Es konnte diese Datei nicht finden...

Also irgendwie werde ich das Gefühl nicht los, dass da irgendwas faul ist...könnte dies mit den viren zusammenhängen?
vivi
 
Beiträge: 35
Registriert: 24.07.2006, 19:05

Beitragvon Humdinger am 27.10.2007, 16:11

Hallo

Mach folgendes in dieser Reihenfolge:

Nun zuerst die
Systemwiederherstellung
http://support.microsoft.com/default.as ... ;de;310405
zuerst deaktivieren

Avenger laden
und so ausführen:
http://virus-protect.org/artikel/tools/avenger.html

kopiere
so rein:

Files to delete:
C:\windows\system32\ntkrnl.exe
C:\WINDOWS\DOWNLO~1\CnsHook.dll

Klicke die grüne Ampel
das Script wird nun ausgeführt, dann wird der PC automatisch neustarten

**
nach dem neustart wird ein Log vom avenger erscheinen - poste es hier

C:\avenger\backup.zip --> nun direkt löschen

Papierkorb leeren

Clean up ausführen
http://virus-protect.org/cleanup.html

CounterSpy anwenden
Laden, installieren, Update, NICHT SCANNEN
http://www.paules-pc-infothek.de/ppf2/v ... php?t=1201

Boote nun in den abgesicherten Modus (bei Neustart F8 drücken)
http://www2.tu-berlin.de/www/software/v ... mode.shtml

Starte CounterSpy, voller Scan, alle Funde löschen, dazu wähle immer REMOVE


Neustart Normalstart

Poste nun den Report von CounterSpy

Hinweis:
Scanreport finden:
klicke : View details

diesen Report kann man abkopieren: [mit der linken Maus-Taste über den Text fahren -> rechte Maustaste -> kopieren -> hier im Thread -> rechte Maustaste -> einfügen]

Lade dir Fixwareout.exe
http://www.bleepingcomputer.com/files/l ... areout.exe
auf dem Desktop speichern & doppelklick auf sie,klicke auf Next, dann Install,Run fixit muss markiert werden und klicke dann auf Finish. Inhalt der Datei C:\fixwareout\report.txt posten


Lade dir Registry Search auf dem Desktop speichern & entpacken,doppelklick auf RegSearch.exe

Oben klicke auf search strings eingeben oder reinkopieren 202.120.2.101 dann klicke auf OK,am Ende Scan Report speichern & hier posten

ComboFix

Doppelklicken auf: combofix.exe

schreibe nun "Y"

Die Datenträgerbereinigung abwarten
mit der rechten Maustaste den Text markieren -> kopieren -> vollständig posten


CCLEANER ausführen

Onlinescan vom gesamten System (wähle Arbeitsplatz):
Kaspersky Online Scanner
benötigt ActiveX --> IE ,
d.h. du mußt dafür Active X evtl. freigeben unter Interneteinstellungen.
Report vollständig posten.

Neuen HijackThis log posten.
Humdinger
Moderator
 
Beiträge: 1079
Registriert: 22.03.2006, 14:22
Wohnort: Mainz

Beitragvon vivi am 27.10.2007, 16:55

Okay, hier kommt der avenger.txt

Code: Alles auswählen
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\tmbiakiy

*******************

Script file located at: \??\C:\windows\egfjdcag.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

File C:\windows\system32\ntkrnl.exe deleted successfully.
File C:\WINDOWS\DOWNLO~1\CnsHook.dll deleted successfully.

Completed script processing.

*******************

Finished!  Terminate.


btw, es gab keine backup.zip datei unter avenger...
ich reboote nun meinen compi im abgesicherten modus. der post wird also nochmal editiert wenn ich den log von counterspy habe.
vivi
 
Beiträge: 35
Registriert: 24.07.2006, 19:05

Beitragvon Humdinger am 27.10.2007, 17:01

Okay, alles machen, am Schluss sehen wir was dann noch zu tun ist.
Humdinger
Moderator
 
Beiträge: 1079
Registriert: 22.03.2006, 14:22
Wohnort: Mainz

Beitragvon vivi am 27.10.2007, 18:02

part1 counterspy
Code: Alles auswählen
Scan History Details
Start Date: 27.10.2007 17:03:28
End Date: 27.10.2007 17:29:54
Total Time: 26 Min 26 Sec
Detected security risks

BDPlugin Browser Plug-in  more information...
Status: Deleted

Registry entries detected
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{BC207F7D-3E63-4ACA-99B5-FB5F8428200C}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{BC207F7D-3E63-4ACA-99B5-FB5F8428200C}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{BC207F7D-3E63-4ACA-99B5-FB5F8428200C}\Implemented Categories


3721 Chinese Keywords (CNSMin) Browser Plug-in  more information...
Details: 3721 Chinese Keywords, also known as CNSMin or Adware.CDN, is keyword-lookup provider that takes over the search feature of IE's address bar. It is aimed at providing keywords using Chinese characters.
Status: Deleted

Files detected
C:\PROGRAMME\3721\alliveex.dll
C:\PROGRAMME\3721\alrex.dll
C:\PROGRAMME\3721\autolive.dll
C:\PROGRAMME\3721\autolive.ini
C:\PROGRAMME\3721\autolvsw.ini
C:\PROGRAMME\3721\cns01.dat
C:\PROGRAMME\3721\cns03.dat
C:\PROGRAMME\3721\CNSMIN.DAT
C:\PROGRAMME\3721\patch05.dll
C:\PROGRAMME\3721\patch06.dll
C:\PROGRAMME\3721\scrblock.dll
c:\Programme\Yahoo!\Assistant\Assist\yangling.dll
C:\Programme\Yahoo!\Assistant\Assist\yassist.dll
c:\Programme\Yahoo!\Assistant\Assist\yphtb.dll
C:\WINDOWS\DOWNLOADED PROGRAM FILES\3721\ListInfo.dat
C:\WINDOWS\Downloaded Program Files\CnsHint.cab
C:\WINDOWS\Downloaded Program Files\cnshint.dll
C:\WINDOWS\Downloaded Program Files\cnsio.dll
C:\WINDOWS\Downloaded Program Files\CnsMin.dll
C:\WINDOWS\Downloaded Program Files\CnsMin.ini
C:\WINDOWS\Downloaded Program Files\CnsMinAL.cab
C:\WINDOWS\Downloaded Program Files\CnsMinCg.ini
C:\WINDOWS\Downloaded Program Files\CnsMinDT.cab
C:\WINDOWS\Downloaded Program Files\CnsMinDT.dll
C:\WINDOWS\Downloaded Program Files\CnsMinEx.dll
C:\WINDOWS\Downloaded Program Files\CnsMinEx.ini
C:\WINDOWS\Downloaded Program Files\CnsMinHK.cab
C:\WINDOWS\Downloaded Program Files\CnsMinIO.cab
C:\WINDOWS\Downloaded Program Files\CnsMinIO.dll
C:\WINDOWS\Downloaded Program Files\CnsMinUp.cab
C:\WINDOWS\Downloaded Program Files\cnsplus.dll
C:\WINDOWS\Downloaded Program Files\CnsUp.ini
C:\WINDOWS\Downloaded Program Files\keepmain.dll
C:\WINDOWS\Downloaded Program Files\sms.ico
C:\WINDOWS\Downloaded Program Files\taobao.ico
C:\WINDOWS\system32\cns.dat
C:\WINDOWS\system32\cns.dll
C:\WINDOWS\system32\cns.exe
C:\WINDOWS\system32\drivers\CnsMinKP.sys
C:\PROGRAMME\3721
C:\WINDOWS\DOWNLOADED PROGRAM FILES\3721

Registry entries detected
HKEY_LOCAL_MACHINE\SOFTWARE\3721
HKEY_LOCAL_MACHINE\SOFTWARE\3721
HKEY_LOCAL_MACHINE\SOFTWARE\3721
HKEY_LOCAL_MACHINE\SOFTWARE\3721\Assist
HKEY_LOCAL_MACHINE\SOFTWARE\3721\Assist\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\3721\Assist\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive\scrblock
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive\scrblock
HKEY_LOCAL_MACHINE\SOFTWARE\3721\AutoLive\scrblock
HKEY_LOCAL_MACHINE\SOFTWARE\3721
HKEY_LOCAL_MACHINE\SOFTWARE\3721
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin\CnsMinEx
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin\CnsMinEx
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin\CnsMinEx
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin\CnsMinEx
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin\CnsMinEx
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin\CnsMinEx
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin\CnsMinEx
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin\CnsMinEx
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin\CnsMinEx
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin\CnsMinEx
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin\CnsMinEx
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin\CnsMinEx
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin\CnsMinEx
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin\CnsMinEx
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin\CnsMinEx
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin\CnsMinEx
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin\CnsMinEx
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin\Variant
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMin
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMinCg
HKEY_LOCAL_MACHINE\SOFTWARE\3721\CnsMinCg
HKEY_LOCAL_MACHINE\Software\Classes\AUTOLIVE.LIVE
HKEY_LOCAL_MACHINE\Software\Classes\AUTOLIVE.LIVE
HKEY_LOCAL_MACHINE\Software\Classes\AUTOLIVE.LIVE.1
HKEY_LOCAL_MACHINE\Software\Classes\AUTOLIVE.LIVE.1
HKEY_LOCAL_MACHINE\Software\Classes\AUTOLIVE.LIVE.1\CLSID
HKEY_LOCAL_MACHINE\Software\Classes\AUTOLIVE.LIVE.1\CLSID
HKEY_LOCAL_MACHINE\Software\Classes\AUTOLIVE.LIVE\CLSID
HKEY_LOCAL_MACHINE\Software\Classes\AUTOLIVE.LIVE\CLSID
HKEY_LOCAL_MACHINE\Software\Classes\AUTOLIVE.LIVE\CurVer
HKEY_LOCAL_MACHINE\Software\Classes\AUTOLIVE.LIVE\CurVer
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{33BBE430-0E42-4F12-B075-8D21ACB10DCB}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{33BBE430-0E42-4F12-B075-8D21ACB10DCB}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{33BBE430-0E42-4F12-B075-8D21ACB10DCB}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{33BBE430-0E42-4F12-B075-8D21ACB10DCB}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{33BBE430-0E42-4F12-B075-8D21ACB10DCB}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{38928D50-8A48-44C2-945F-D2F23F771410}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{38928D50-8A48-44C2-945F-D2F23F771410}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{38928D50-8A48-44C2-945F-D2F23F771410}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{38928D50-8A48-44C2-945F-D2F23F771410}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{38928D50-8A48-44C2-945F-D2F23F771410}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{38928D50-8A48-44C2-945F-D2F23F771410}\ProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{38928D50-8A48-44C2-945F-D2F23F771410}\ProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{38928D50-8A48-44C2-945F-D2F23F771410}\Programmable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{38928D50-8A48-44C2-945F-D2F23F771410}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{38928D50-8A48-44C2-945F-D2F23F771410}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{7CA83CF1-3AEA-42D0-A4E3-1594FC6E48B2}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{7CA83CF1-3AEA-42D0-A4E3-1594FC6E48B2}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{7CA83CF1-3AEA-42D0-A4E3-1594FC6E48B2}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{7CA83CF1-3AEA-42D0-A4E3-1594FC6E48B2}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{7CA83CF1-3AEA-42D0-A4E3-1594FC6E48B2}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{ABEC6103-F6AC-43A3-834F-FB03FBA339A2}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{ABEC6103-F6AC-43A3-834F-FB03FBA339A2}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{ABEC6103-F6AC-43A3-834F-FB03FBA339A2}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{ABEC6103-F6AC-43A3-834F-FB03FBA339A2}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{ABEC6103-F6AC-43A3-834F-FB03FBA339A2}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\Control
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\Implemented Categories
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\Implemented Categories
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\Insertable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\MiscStatus
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\MiscStatus
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\MiscStatus\1
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\MiscStatus\1
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\ProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\ProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\Programmable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\ToolboxBitmap32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\ToolboxBitmap32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\Version
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\Version
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{D157330A-9EF3-49F8-9A67-4141AC41ADD4}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{D157330A-9EF3-49F8-9A67-4141AC41ADD4}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{D157330A-9EF3-49F8-9A67-4141AC41ADD4}\Implemented Categories
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{D157330A-9EF3-49F8-9A67-4141AC41ADD4}\Implemented Categories
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{D157330A-9EF3-49F8-9A67-4141AC41ADD4}\Implemented Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{D157330A-9EF3-49F8-9A67-4141AC41ADD4}\Implemented Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{D157330A-9EF3-49F8-9A67-4141AC41ADD4}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{D157330A-9EF3-49F8-9A67-4141AC41ADD4}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{D157330A-9EF3-49F8-9A67-4141AC41ADD4}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{D157330A-9EF3-49F8-9A67-4141AC41ADD4}\ProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{D157330A-9EF3-49F8-9A67-4141AC41ADD4}\ProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{D157330A-9EF3-49F8-9A67-4141AC41ADD4}\Programmable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{D157330A-9EF3-49F8-9A67-4141AC41ADD4}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{D157330A-9EF3-49F8-9A67-4141AC41ADD4}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{D157330A-9EF3-49F8-9A67-4141AC41ADD4}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{D157330A-9EF3-49F8-9A67-4141AC41ADD4}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\Software\Classes\CNSHELPER.CH
HKEY_LOCAL_MACHINE\Software\Classes\CNSHELPER.CH
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CnsHelper.CH.1
HKEY_LOCAL_MACHINE\Software\Classes\CNSHELPER.CH.1
HKEY_LOCAL_MACHINE\Software\Classes\CNSHELPER.CH.1\CLSID
HKEY_LOCAL_MACHINE\Software\Classes\CNSHELPER.CH.1\CLSID
HKEY_LOCAL_MACHINE\Software\Classes\CNSHELPER.CH\CLSID
HKEY_LOCAL_MACHINE\Software\Classes\CNSHELPER.CH\CLSID
HKEY_LOCAL_MACHINE\Software\Classes\CNSHELPER.CH\CurVer
HKEY_LOCAL_MACHINE\Software\Classes\CNSHELPER.CH\CurVer
HKEY_LOCAL_MACHINE\Software\Classes\CNSMINHK.CNSHOOK
HKEY_LOCAL_MACHINE\Software\Classes\CNSMINHK.CNSHOOK
HKEY_LOCAL_MACHINE\Software\Classes\CNSMINHK.CNSHOOK.1
HKEY_LOCAL_MACHINE\Software\Classes\CNSMINHK.CNSHOOK.1
HKEY_LOCAL_MACHINE\Software\Classes\CNSMINHK.CNSHOOK.1\CLSID
HKEY_LOCAL_MACHINE\Software\Classes\CNSMINHK.CNSHOOK.1\CLSID
HKEY_LOCAL_MACHINE\Software\Classes\CNSMINHK.CNSHOOK\CLSID
HKEY_LOCAL_MACHINE\Software\Classes\CNSMINHK.CNSHOOK\CLSID
HKEY_LOCAL_MACHINE\Software\Classes\CNSMINHK.CNSHOOK\CurVer
HKEY_LOCAL_MACHINE\Software\Classes\CNSMINHK.CNSHOOK\CurVer
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{48E688C8-609F-4B08-944E-3C7FAB99CD08}
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{48E688C8-609F-4B08-944E-3C7FAB99CD08}
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{48E688C8-609F-4B08-944E-3C7FAB99CD08}\ProxyStubClsid
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{48E688C8-609F-4B08-944E-3C7FAB99CD08}\ProxyStubClsid
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{48E688C8-609F-4B08-944E-3C7FAB99CD08}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{48E688C8-609F-4B08-944E-3C7FAB99CD08}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{48E688C8-609F-4B08-944E-3C7FAB99CD08}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{48E688C8-609F-4B08-944E-3C7FAB99CD08}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{48E688C8-609F-4B08-944E-3C7FAB99CD08}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{924F5B3A-7A27-484A-B873-E855C9708667}
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{924F5B3A-7A27-484A-B873-E855C9708667}
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{924F5B3A-7A27-484A-B873-E855C9708667}\ProxyStubClsid
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{924F5B3A-7A27-484A-B873-E855C9708667}\ProxyStubClsid
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{924F5B3A-7A27-484A-B873-E855C9708667}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{924F5B3A-7A27-484A-B873-E855C9708667}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{924F5B3A-7A27-484A-B873-E855C9708667}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{924F5B3A-7A27-484A-B873-E855C9708667}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{924F5B3A-7A27-484A-B873-E855C9708667}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{BE08F6BC-C3E6-4149-BEB1-CB449E1B372E}
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{BE08F6BC-C3E6-4149-BEB1-CB449E1B372E}
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{BE08F6BC-C3E6-4149-BEB1-CB449E1B372E}\ProxyStubClsid
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{BE08F6BC-C3E6-4149-BEB1-CB449E1B372E}\ProxyStubClsid
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{BE08F6BC-C3E6-4149-BEB1-CB449E1B372E}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{BE08F6BC-C3E6-4149-BEB1-CB449E1B372E}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{BE08F6BC-C3E6-4149-BEB1-CB449E1B372E}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{BE08F6BC-C3E6-4149-BEB1-CB449E1B372E}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{BE08F6BC-C3E6-4149-BEB1-CB449E1B372E}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{DF692509-D9EF-48A0-9CD0-3AA5B81F6F68}
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{DF692509-D9EF-48A0-9CD0-3AA5B81F6F68}
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{DF692509-D9EF-48A0-9CD0-3AA5B81F6F68}\ProxyStubClsid
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{DF692509-D9EF-48A0-9CD0-3AA5B81F6F68}\ProxyStubClsid
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{DF692509-D9EF-48A0-9CD0-3AA5B81F6F68}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{DF692509-D9EF-48A0-9CD0-3AA5B81F6F68}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{DF692509-D9EF-48A0-9CD0-3AA5B81F6F68}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{DF692509-D9EF-48A0-9CD0-3AA5B81F6F68}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{DF692509-D9EF-48A0-9CD0-3AA5B81F6F68}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{4158DB95-DE71-41FF-BEA1-2C3D1C679DF1}
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{4158DB95-DE71-41FF-BEA1-2C3D1C679DF1}\1.0
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{4158DB95-DE71-41FF-BEA1-2C3D1C679DF1}\1.0
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{4158DB95-DE71-41FF-BEA1-2C3D1C679DF1}\1.0\0
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{4158DB95-DE71-41FF-BEA1-2C3D1C679DF1}\1.0\0\win32
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{4158DB95-DE71-41FF-BEA1-2C3D1C679DF1}\1.0\0\win32
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{4158DB95-DE71-41FF-BEA1-2C3D1C679DF1}\1.0\FLAGS
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{4158DB95-DE71-41FF-BEA1-2C3D1C679DF1}\1.0\FLAGS
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{4158DB95-DE71-41FF-BEA1-2C3D1C679DF1}\1.0\HELPDIR
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{4158DB95-DE71-41FF-BEA1-2C3D1C679DF1}\1.0\HELPDIR
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{A5ADEAE7-A8B4-4F94-9128-BF8D8DB5E927}
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{A5ADEAE7-A8B4-4F94-9128-BF8D8DB5E927}\1.0
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{A5ADEAE7-A8B4-4F94-9128-BF8D8DB5E927}\1.0
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{A5ADEAE7-A8B4-4F94-9128-BF8D8DB5E927}\1.0\0
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{A5ADEAE7-A8B4-4F94-9128-BF8D8DB5E927}\1.0\0\win32
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{A5ADEAE7-A8B4-4F94-9128-BF8D8DB5E927}\1.0\0\win32
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{A5ADEAE7-A8B4-4F94-9128-BF8D8DB5E927}\1.0\FLAGS
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{A5ADEAE7-A8B4-4F94-9128-BF8D8DB5E927}\1.0\FLAGS
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{A5ADEAE7-A8B4-4F94-9128-BF8D8DB5E927}\1.0\HELPDIR
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{A5ADEAE7-A8B4-4F94-9128-BF8D8DB5E927}\1.0\HELPDIR
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{AAB6BCE3-1DF6-4930-9B14-9CA79DC8C267}
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{AAB6BCE3-1DF6-4930-9B14-9CA79DC8C267}\1.0
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{AAB6BCE3-1DF6-4930-9B14-9CA79DC8C267}\1.0
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{AAB6BCE3-1DF6-4930-9B14-9CA79DC8C267}\1.0\0
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{AAB6BCE3-1DF6-4930-9B14-9CA79DC8C267}\1.0\0\win32
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{AAB6BCE3-1DF6-4930-9B14-9CA79DC8C267}\1.0\0\win32
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{AAB6BCE3-1DF6-4930-9B14-9CA79DC8C267}\1.0\FLAGS
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{AAB6BCE3-1DF6-4930-9B14-9CA79DC8C267}\1.0\FLAGS
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{AAB6BCE3-1DF6-4930-9B14-9CA79DC8C267}\1.0\HELPDIR
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{AAB6BCE3-1DF6-4930-9B14-9CA79DC8C267}\1.0\HELPDIR
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{F9AD9D67-EFA8-480E-8291-0163F3960DE7}
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{F9AD9D67-EFA8-480E-8291-0163F3960DE7}\1.0
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{F9AD9D67-EFA8-480E-8291-0163F3960DE7}\1.0
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{F9AD9D67-EFA8-480E-8291-0163F3960DE7}\1.0\0
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{F9AD9D67-EFA8-480E-8291-0163F3960DE7}\1.0\0\win32
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{F9AD9D67-EFA8-480E-8291-0163F3960DE7}\1.0\0\win32
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{F9AD9D67-EFA8-480E-8291-0163F3960DE7}\1.0\FLAGS
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{F9AD9D67-EFA8-480E-8291-0163F3960DE7}\1.0\FLAGS
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{F9AD9D67-EFA8-480E-8291-0163F3960DE7}\1.0\HELPDIR
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{F9AD9D67-EFA8-480E-8291-0163F3960DE7}\1.0\HELPDIR
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\AutoUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\AutoUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\AutoUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\AutoUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\AutoUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\AutoUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\AutoUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\AutoUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\AutoUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Enable
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Enable
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Enable
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Enable
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Enable
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Enable
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Enable
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Enable
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Enable
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Hint
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Hint
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Hint
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Hint
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Hint
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Hint
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Hint
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Hint
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Hint
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\List
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\List
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\List
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\List
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\List
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\List
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\List
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\List
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\List
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\List
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Reset
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Reset
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Reset
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Reset
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Reset
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Reset
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Reset
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Reset
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Reset
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Reset
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\ResetCatch
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\ResetCatch
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\ResetCatch
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\ResetCatch
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\ResetCatch
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\ResetCatch
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\ResetCatch
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\ResetCatch
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\ResetCatch
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Tips
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Tips
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Tips
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Tips
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Tips
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Tips
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Tips
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Tips
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Tips
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS\Tips
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ADVANCEDOPTIONS\!CNS
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{507F9113-CD77-4866-BA92-0E86DA3D0B97}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{507F9113-CD77-4866-BA92-0E86DA3D0B97}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{507F9113-CD77-4866-BA92-0E86DA3D0B97}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{507F9113-CD77-4866-BA92-0E86DA3D0B97}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{507F9113-CD77-4866-BA92-0E86DA3D0B97}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{507F9113-CD77-4866-BA92-0E86DA3D0B97}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{507F9113-CD77-4866-BA92-0E86DA3D0B97}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{59BC54A2-56B3-44A0-93E5-432D58746E26}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{59BC54A2-56B3-44A0-93E5-432D58746E26}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{59BC54A2-56B3-44A0-93E5-432D58746E26}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{59BC54A2-56B3-44A0-93E5-432D58746E26}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{59BC54A2-56B3-44A0-93E5-432D58746E26}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{59BC54A2-56B3-44A0-93E5-432D58746E26}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{59BC54A2-56B3-44A0-93E5-432D58746E26}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{5D73EE86-05F1-49ED-B850-E423120EC338}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{5D73EE86-05F1-49ED-B850-E423120EC338}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{5D73EE86-05F1-49ED-B850-E423120EC338}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{5D73EE86-05F1-49ED-B850-E423120EC338}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{5D73EE86-05F1-49ED-B850-E423120EC338}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{5D73EE86-05F1-49ED-B850-E423120EC338}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{5D73EE86-05F1-49ED-B850-E423120EC338}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{ECF2E268-F28C-48D2-9AB7-8F69C11CCB71}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{ECF2E268-F28C-48D2-9AB7-8F69C11CCB71}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{ECF2E268-F28C-48D2-9AB7-8F69C11CCB71}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{ECF2E268-F28C-48D2-9AB7-8F69C11CCB71}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{ECF2E268-F28C-48D2-9AB7-8F69C11CCB71}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{FD00D911-7529-4084-9946-A29F1BDF4FE5}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{FD00D911-7529-4084-9946-A29F1BDF4FE5}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{FD00D911-7529-4084-9946-A29F1BDF4FE5}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{FD00D911-7529-4084-9946-A29F1BDF4FE5}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{FD00D911-7529-4084-9946-A29F1BDF4FE5}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP MANAGEMENT\ARPCACHE\CNSMIN
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP MANAGEMENT\ARPCACHE\CNSMIN
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP MANAGEMENT\ARPCACHE\CNSMIN
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{38928D50-8A48-44C2-945F-D2F23F771410}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{38928D50-8A48-44C2-945F-D2F23F771410}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{D157330A-9EF3-49F8-9A67-4141AC41ADD4}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{D157330A-9EF3-49F8-9A67-4141AC41ADD4}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\CDNCLIENT
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\CDNCLIENT
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\CDNCLIENT
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\CNSMIN
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\CNSMIN
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\CNSMIN
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\CDNPROT
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\CDNPROT
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\CNSMINKP
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\CNSMINKP
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\CNSMINKP
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\CNSMINKP
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\CNSMINKP\Enum
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\CNSMINKP\Enum
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\CNSMINKP\Enum
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\CNSMINKP\Enum
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\CNSMINKP
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\CNSMINKP
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\CNSMINKP
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\CNSMINKP
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\CNSMINKP
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\CNSMINKP
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\CNSMINKP
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\CNSMINKP
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\CNSMINKP\Security
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\CNSMINKP\Security
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\CNSMINKP
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\CNSMINKP
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\CNSMINKP
HKEY_USERS\.DEFAULT\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\CMDMAPPING
HKEY_USERS\.DEFAULT\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\CMDMAPPING
HKEY_USERS\.DEFAULT\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\CMDMAPPING
HKEY_USERS\.DEFAULT\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\CMDMAPPING
HKEY_USERS\.DEFAULT\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\CMDMAPPING
HKEY_USERS\S-1-5-18\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\CMDMAPPING
HKEY_USERS\S-1-5-18\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\CMDMAPPING
HKEY_USERS\S-1-5-18\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\CMDMAPPING
HKEY_USERS\S-1-5-18\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\CMDMAPPING
HKEY_USERS\S-1-5-18\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\CMDMAPPING
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\CnsMin
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\CnsMin
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\CnsMin
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\CnsMin
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\CnsMin
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\CnsMin
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\CnsMin
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\CnsMin
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\CnsMin
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\CnsMin
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\CnsMin
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\CnsMin
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\CnsMin
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\CnsMin
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\CnsMin\Variant
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\CnsMin\Variant
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\CnsMin\Variant
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\CnsMin\Variant
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\CnsUrl
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\3721\InputCns
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\CMDMAPPING
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\CMDMAPPING
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\CMDMAPPING
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\CMDMAPPING
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\CMDMAPPING
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN
HKEY_USERS\S-1-5-21-660157039-1264387650-1008150880-1028\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN
Zuletzt geändert von vivi am 27.10.2007, 18:15, insgesamt 4-mal geändert.
vivi
 
Beiträge: 35
Registriert: 24.07.2006, 19:05

Beitragvon vivi am 27.10.2007, 18:09

Fortsetzung

Code: Alles auswählen
Virtual-IE.MsMovies Adware (General)  more information...
Status: Deleted

Files detected
C:\WINDOWS\system32\cmd.com


DesktopMedia Adware (General)  more information...
Details: Desktop Media Cast is an adware program that displays pop-up ads.
Status: Deleted

Files detected
C:\WINDOWS\system32\config\systemprofile\Vorlagen\6b8f42f\4.dll

Registry entries detected
HKEY_LOCAL_MACHINE\SOFTWARE\CLUBMEMBER
HKEY_LOCAL_MACHINE\SOFTWARE\CLUBMEMBER\cast
HKEY_LOCAL_MACHINE\SOFTWARE\CLUBMEMBER\cast\dmclient
HKEY_LOCAL_MACHINE\SOFTWARE\CLUBMEMBER\cast\dmclient


SearchNet Browser Plug-in  more information...
Status: Deleted

Registry entries detected
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ZSXZ
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ZSXZ


AdMedia Browser Plug-in  more information...
Status: Deleted

Files detected
C:\WINDOWS\system32\ext\dtsm.dll
C:\WINDOWS\xtrestmd.dll

Registry entries detected
HKEY_LOCAL_MACHINE\SOFTWARE\AP SYSTEMS
HKEY_LOCAL_MACHINE\SOFTWARE\AP SYSTEMS
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{5375AF10-2F77-4E74-B693-4668F6381999}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{5375AF10-2F77-4E74-B693-4668F6381999}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{5375AF10-2F77-4E74-B693-4668F6381999}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{5375AF10-2F77-4E74-B693-4668F6381999}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{5375AF10-2F77-4E74-B693-4668F6381999}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{5375AF10-2F77-4E74-B693-4668F6381999}\ProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{5375AF10-2F77-4E74-B693-4668F6381999}\ProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{5375AF10-2F77-4E74-B693-4668F6381999}\Programmable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{5375AF10-2F77-4E74-B693-4668F6381999}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{5375AF10-2F77-4E74-B693-4668F6381999}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{5375AF10-2F77-4E74-B693-4668F6381999}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{5375AF10-2F77-4E74-B693-4668F6381999}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD}\ProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD}\ProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD}\Programmable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\Software\Classes\DTAP.ADCONFIG
HKEY_LOCAL_MACHINE\Software\Classes\DTAP.ADCONFIG
HKEY_LOCAL_MACHINE\Software\Classes\DTAP.ADCONFIG.1
HKEY_LOCAL_MACHINE\Software\Classes\DTAP.ADCONFIG.1
HKEY_LOCAL_MACHINE\Software\Classes\DTAP.ADCONFIG.1\CLSID
HKEY_LOCAL_MACHINE\Software\Classes\DTAP.ADCONFIG.1\CLSID
HKEY_LOCAL_MACHINE\Software\Classes\DTAP.ADCONFIG\CLSID
HKEY_LOCAL_MACHINE\Software\Classes\DTAP.ADCONFIG\CLSID
HKEY_LOCAL_MACHINE\Software\Classes\DTAP.ADCONFIG\CurVer
HKEY_LOCAL_MACHINE\Software\Classes\DTAP.ADCONFIG\CurVer
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{221F3103-3DB3-4EF5-9725-CFB481481F46}
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{221F3103-3DB3-4EF5-9725-CFB481481F46}
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{221F3103-3DB3-4EF5-9725-CFB481481F46}\ProxyStubClsid
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{221F3103-3DB3-4EF5-9725-CFB481481F46}\ProxyStubClsid
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{221F3103-3DB3-4EF5-9725-CFB481481F46}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{221F3103-3DB3-4EF5-9725-CFB481481F46}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{221F3103-3DB3-4EF5-9725-CFB481481F46}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{221F3103-3DB3-4EF5-9725-CFB481481F46}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{221F3103-3DB3-4EF5-9725-CFB481481F46}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{E520194F-15A3-46DC-976B-9987E6039DCD}
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{E520194F-15A3-46DC-976B-9987E6039DCD}
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{E520194F-15A3-46DC-976B-9987E6039DCD}\ProxyStubClsid
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{E520194F-15A3-46DC-976B-9987E6039DCD}\ProxyStubClsid
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{E520194F-15A3-46DC-976B-9987E6039DCD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{E520194F-15A3-46DC-976B-9987E6039DCD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{E520194F-15A3-46DC-976B-9987E6039DCD}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{E520194F-15A3-46DC-976B-9987E6039DCD}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{E520194F-15A3-46DC-976B-9987E6039DCD}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\MACROMEDIAPD.CAP
HKEY_LOCAL_MACHINE\Software\Classes\MACROMEDIAPD.CAP
HKEY_LOCAL_MACHINE\Software\Classes\MACROMEDIAPD.CAP.1
HKEY_LOCAL_MACHINE\Software\Classes\MACROMEDIAPD.CAP.1
HKEY_LOCAL_MACHINE\Software\Classes\MACROMEDIAPD.CAP.1\CLSID
HKEY_LOCAL_MACHINE\Software\Classes\MACROMEDIAPD.CAP.1\CLSID
HKEY_LOCAL_MACHINE\Software\Classes\MACROMEDIAPD.CAP\CLSID
HKEY_LOCAL_MACHINE\Software\Classes\MACROMEDIAPD.CAP\CLSID
HKEY_LOCAL_MACHINE\Software\Classes\MACROMEDIAPD.CAP\CurVer
HKEY_LOCAL_MACHINE\Software\Classes\MACROMEDIAPD.CAP\CurVer
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{8698090C-E0E7-42E0-BCA1-5681A1ACEB1E}
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{8698090C-E0E7-42E0-BCA1-5681A1ACEB1E}\1.0
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{8698090C-E0E7-42E0-BCA1-5681A1ACEB1E}\1.0
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{8698090C-E0E7-42E0-BCA1-5681A1ACEB1E}\1.0\0
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{8698090C-E0E7-42E0-BCA1-5681A1ACEB1E}\1.0\0\win32
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{8698090C-E0E7-42E0-BCA1-5681A1ACEB1E}\1.0\0\win32
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{8698090C-E0E7-42E0-BCA1-5681A1ACEB1E}\1.0\FLAGS
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{8698090C-E0E7-42E0-BCA1-5681A1ACEB1E}\1.0\FLAGS
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{8698090C-E0E7-42E0-BCA1-5681A1ACEB1E}\1.0\HELPDIR
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{8698090C-E0E7-42E0-BCA1-5681A1ACEB1E}\1.0\HELPDIR
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{A474BD59-F29A-4559-95B9-B4E13FA51FAA}
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{A474BD59-F29A-4559-95B9-B4E13FA51FAA}\1.0
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{A474BD59-F29A-4559-95B9-B4E13FA51FAA}\1.0
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{A474BD59-F29A-4559-95B9-B4E13FA51FAA}\1.0\0
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{A474BD59-F29A-4559-95B9-B4E13FA51FAA}\1.0\0\win32
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{A474BD59-F29A-4559-95B9-B4E13FA51FAA}\1.0\0\win32
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{A474BD59-F29A-4559-95B9-B4E13FA51FAA}\1.0\FLAGS
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{A474BD59-F29A-4559-95B9-B4E13FA51FAA}\1.0\FLAGS
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{A474BD59-F29A-4559-95B9-B4E13FA51FAA}\1.0\HELPDIR
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{A474BD59-F29A-4559-95B9-B4E13FA51FAA}\1.0\HELPDIR
HKEY_LOCAL_MACHINE\SOFTWARE\DONGTIAN
HKEY_LOCAL_MACHINE\SOFTWARE\DONGTIAN\3d
HKEY_LOCAL_MACHINE\SOFTWARE\DONGTIAN\3d
HKEY_LOCAL_MACHINE\SOFTWARE\DONGTIAN\3d
HKEY_LOCAL_MACHINE\SOFTWARE\DONGTIAN\3d
HKEY_LOCAL_MACHINE\SOFTWARE\DONGTIAN\3d
HKEY_LOCAL_MACHINE\SOFTWARE\DONGTIAN
HKEY_LOCAL_MACHINE\SOFTWARE\DONGTIAN
HKEY_LOCAL_MACHINE\SOFTWARE\DONGTIAN
HKEY_LOCAL_MACHINE\SOFTWARE\DONGTIAN
HKEY_LOCAL_MACHINE\SOFTWARE\DONGTIAN\Service
HKEY_LOCAL_MACHINE\SOFTWARE\DONGTIAN\Service
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD}


Chaxun.EyeOnBrowser Hijacker  more information...
Status: Deleted

Registry entries detected
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{951A869A-1003-4897-948F-D55E570871DB}
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{951A869A-1003-4897-948F-D55E570871DB}
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{951A869A-1003-4897-948F-D55E570871DB}\ProxyStubClsid
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{951A869A-1003-4897-948F-D55E570871DB}\ProxyStubClsid
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{951A869A-1003-4897-948F-D55E570871DB}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{951A869A-1003-4897-948F-D55E570871DB}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{951A869A-1003-4897-948F-D55E570871DB}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{951A869A-1003-4897-948F-D55E570871DB}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\INTERFACE\{951A869A-1003-4897-948F-D55E570871DB}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{C24A5A5C-0874-4386-85C7-E669F90997A9}
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{C24A5A5C-0874-4386-85C7-E669F90997A9}\1.0
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{C24A5A5C-0874-4386-85C7-E669F90997A9}\1.0
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{C24A5A5C-0874-4386-85C7-E669F90997A9}\1.0\0
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{C24A5A5C-0874-4386-85C7-E669F90997A9}\1.0\0\win32
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{C24A5A5C-0874-4386-85C7-E669F90997A9}\1.0\0\win32
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{C24A5A5C-0874-4386-85C7-E669F90997A9}\1.0\FLAGS
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{C24A5A5C-0874-4386-85C7-E669F90997A9}\1.0\FLAGS
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{C24A5A5C-0874-4386-85C7-E669F90997A9}\1.0\HELPDIR
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{C24A5A5C-0874-4386-85C7-E669F90997A9}\1.0\HELPDIR


Trojan.ZSKiller.B Trojan  more information...
Status: Deleted

Files detected
c:\Programme\3721\autolive.dll
c:\Programme\Yahoo!\Assistant\Assist\yasbar.dll
c:\Programme\Yahoo!\Assistant\yalive.dll
c:\WINDOWS\downloaded program files\CnsMin.dll

Registry entries detected
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{406F94F0-504F-4A40-8DFD-58B0666ABEBD}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{406F94F0-504F-4A40-8DFD-58B0666ABEBD}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{406F94F0-504F-4A40-8DFD-58B0666ABEBD}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{406F94F0-504F-4A40-8DFD-58B0666ABEBD}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{406F94F0-504F-4A40-8DFD-58B0666ABEBD}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{406F94F0-504F-4A40-8DFD-58B0666ABEBD}\ProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{406F94F0-504F-4A40-8DFD-58B0666ABEBD}\ProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{406F94F0-504F-4A40-8DFD-58B0666ABEBD}\Programmable
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{406F94F0-504F-4A40-8DFD-58B0666ABEBD}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{406F94F0-504F-4A40-8DFD-58B0666ABEBD}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{406F94F0-504F-4A40-8DFD-58B0666ABEBD}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{406F94F0-504F-4A40-8DFD-58B0666ABEBD}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{57421194-58FB-49AE-9B4F-FD48869B9AD4}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{57421194-58FB-49AE-9B4F-FD48869B9AD4}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{57421194-58FB-49AE-9B4F-FD48869B9AD4}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{57421194-58FB-49AE-9B4F-FD48869B9AD4}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{57421194-58FB-49AE-9B4F-FD48869B9AD4}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{7CA83CF1-3AEA-42D0-A4E3-1594FC6E48B2}\INPROCSERVER32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{7CA83CF1-3AEA-42D0-A4E3-1594FC6E48B2}\INPROCSERVER32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{7CA83CF1-3AEA-42D0-A4E3-1594FC6E48B2}\INPROCSERVER32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\CONTROL
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\IMPLEMENTED CATEGORIES
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\IMPLEMENTED CATEGORIES
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\INPROCSERVER32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\INPROCSERVER32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\INPROCSERVER32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\INSERTABLE
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\MISCSTATUS
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\MISCSTATUS
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\MISCSTATUS\1
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\MISCSTATUS\1
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\PROGID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\PROGID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\PROGRAMMABLE
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\TOOLBOXBITMAP32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\TOOLBOXBITMAP32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\TYPELIB
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\TYPELIB
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\VERSIONINDEPENDENTPROGID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}\VERSIONINDEPENDENTPROGID
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{4158DB95-DE71-41FF-BEA1-2C3D1C679DF1}\1.0
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{4158DB95-DE71-41FF-BEA1-2C3D1C679DF1}\1.0
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{4158DB95-DE71-41FF-BEA1-2C3D1C679DF1}\1.0\0
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{4158DB95-DE71-41FF-BEA1-2C3D1C679DF1}\1.0\0\win32
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{4158DB95-DE71-41FF-BEA1-2C3D1C679DF1}\1.0\0\win32
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{4158DB95-DE71-41FF-BEA1-2C3D1C679DF1}\1.0\FLAGS
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\{4158DB95-DE71-41FF-BEA1-2C3D1C679DF1}\1.0\FLAGS
HKEY_LOCAL_MACHINE\Software\Classes\TYPELIB\&#