- C:\WINDOWS\system32\drivers\wanatw4.sys (WAN Miniport (ATW))
030 HKLM\SOFTWARE\Classes\PROTOCOLS\Filter
c:\windows\system32\mscoree.dll (Microsoft Corporation) {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
c:\windows\system32\mscoree.dll (Microsoft Corporation) {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
c:\windows\system32\mscoree.dll (Microsoft Corporation) {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
031 HKLM\SOFTWARE\Classes\PROTOCOLS\Handler
c:\program files\common files\microsoft shared\information retrieval\msitss.dll (Microsoft Corporation) {0A9007C0-4076-11D3-8789-0000F8105754}
035 HKLM-HKCU\SOFTWARE\Microsoft\Active Setup\Installed Components
c:\windows\system32\mscories.dll (Microsoft Corporation) {89B4C1CD-B018-4511-B0A1-5476DBF70820}
041 HKLM-HKCU\Software\Microsoft\Internet Explorer\Toolbar
c:\progra~1\blstoo~1\blstoo~1.dll {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E}
c:\program files\canon\easy-webprint\toolband.dll {327C2873-E90D-4c37-AA9D-10AC9BABA46C}
045 HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
c:\progra~1\blstoo~1\blstoo~1.dll {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E}
047 Trusted zones
Zone: objects.aol.com : *.objects.aol.com
050 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
c:\program files\superantispyware\sasseh.dll (SuperAdBlocker.com) {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}
052 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
- c:\program files\adobe\acrobat 7.0\activex\acroiehelper.dll (Adobe Systems Incorporated) {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
c:\progra~1\blstoo~1\blstoo~1.dll {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E}
- c:\program files\java\jre1.6.0_01\bin\ssv.dll (Sun Microsystems, Inc.) {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
- c:\progra~1\spybot~1\sdhelper.dll (Safer Networking Limited) {53707962-6F74-2D53-2644-206D7942484F}
061 HKLM-HCKU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
- c:\program files\alwil software\avast4\ashshell.dll (ALWIL Software) {472083B0-C522-11CF-8763-00608CC02F24}
c:\windows\system32\nvshell.dll {1CDB2949-8F65-4355-8456-263E7C208A5D}
c:\windows\system32\nvshell.dll {1E9B04FB-F9E5-4718-997B-B8DA88302A47}
- deskpan.dll {42071714-76d4-11d1-8b24-00a0c9068ff3}
c:\windows\system32\mscoree.dll (Microsoft Corporation) {1D2680C9-0E2A-469d-B787-065558BC7D43}
- c:\windows\system32\hticons.dll (Hilgraeve, Inc.) {88895560-9AA2-1069-930E-00AA0030EBC8}
- c:\windows\system32\nvcpl.dll (NVIDIA Corporation) {A70C977A-BF00-412C-90B7-034C51DA2439}
c:\windows\system32\nvshell.dll {1E9B04FB-F9E5-4718-997B-B8DA88302A48}
- c:\windows\system32\nvcpl.dll (NVIDIA Corporation) {FFB699E0-306A-11d3-8BD1-00104B6F7516}
c:\windows\system32\shellvrtf.dll (XSS) {7F67036B-66F1-411A-AD85-759FB9C5B0DB}
062 HKLM-HKCU\Software\Classes\Folder\Shellex\ColumnHandlers
c:\program files\adobe\acrobat 7.0\activex\pdfshell.dll (Adobe Systems, Inc.) {F9DB5320-233E-11D1-9F84-707F02C10627}
067 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
c:\program files\superantispyware\saswinlo.dll (SUPERAntiSpyware.com)
069 HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
- C:\WINDOWS\system32\cnmlm75.dll (CANON INC.)
100 Internet Explorer settings
CustomizeSearch HKLM : http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
Default_Page_URL HKLM : http://www.aol.com
Default_Search_URL HKLM : http://www.google.com/ie
Search Page HKCU : http://www.google.com
Search Page HKLM : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchAssistant HKCU : http://www.google.com/ie
SearchAssistant HKLM : http://www.google.com/ie
SearchUrl HKCU : http://www.google.com/search?q=%s
ShellNext HKCU : iexplore
Start Page HKCU : http://securityresponse.symantec.com/avcenter/fix_homepage/
Start Page HKLM : http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
104 HKLM\Software\Microsoft\Code Store Database\Distribution Units
- c:\windows\system32\macromed\director\swdir.dll (Adobe Systems, Inc.) {166B1BCA-3F9C-11CF-8075-444553540000}
- c:\windows\downlo~1\ewidoo~1.dll (Anti-Malware Development a.s.) {193C772A-87BE-4B19-A7BB-445B226FE9A1}
- c:\program files\java\jre1.6.0_01\bin\npjpi160_01.dll (Sun Microsystems, Inc.) {8AD9C840-044E-11D1-B3E9-00805F499D93}
c:\program files\java\jre1.5.0_06\bin\npjpi150_06.dll (Sun Microsystems, Inc.) {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
- c:\windows\system32\macromed\flash\flash9.ocx (Adobe Systems, Inc.) {D27CDB6E-AE6D-11CF-96B8-444553540000}
105 HKCU\Software\Microsoft\Internet Explorer\MenuExt
&AOL Toolbar search : res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
E&xport to Microsoft Excel : res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Easy-WebPrint Add To Print List : res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
Easy-WebPrint High Speed Print : res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
Easy-WebPrint Preview : res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
Easy-WebPrint Print : res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
161 HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System
dontdisplaylastusername : 0
shutdownwithoutlogon : 1
undockwithoutlogon : 1
170 HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
{09826001-48e5-11da-bf8e-806d6172696f} : C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
{0992de21-e73c-11da-bfb3-0040ca8f2da5} : J:\setupSNK.exe
{1019e541-51ec-11da-9c61-806d6172696f} : C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
{815a0671-62bc-11da-b957-806d6172696f} : C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
J : J:\LaunchU3.exe -a
173 HKCR*\shellex\ContextMenuHandlers
- c:\program files\alwil software\avast4\ashshell.dll (ALWIL Software) {472083B0-C522-11CF-8763-00608CC02F24}
c:\program files\superantispyware\sasctxmn.dll (SUPERAntiSpyware.com) SUPERAntiSpyware Context Menu