Help! Can't Get Rid Of Win32.Agent.yr!!

Discussion in 'Windows - Virus and spyware problems' started by tmr250z, Feb 27, 2007.

  1. tmr250z

    tmr250z Guest

    I scanned with Spybot Search and Destory and found Win32.Agent.yr, so I clicked fix problem and it said it was fixed then I rebooted my computer. When I scanned again it's still there! Some please help me get rid of it.

    Here's my HijackThis log:

    Logfile of HijackThis v1.99.1
    Scan saved at 3:31:55 PM, on 2/27/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Unlocker\UnlockerAssistant.exe
    C:\Program Files\Eset\nod32kui.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
    C:\Program Files\PeerGuardian2\pg2.exe
    C:\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
    C:\Program Files\Rainlendar\Rainlendar.exe
    C:\Program Files\Eset\nod32krn.exe
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
    C:\WINDOWS\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe
    C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
    C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\HijackThis\HijackThis.exe

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [DiskeeperSystray] C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe
    O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
    O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
    O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
    O4 - HKCU\..\Run: [AVEDESK] "C:\Program Files\AveDesk\AVEDESK.EXE"
    O4 - HKCU\..\Run: [RocketDock] "C:\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe"
    O4 - Startup: Rainlendar.lnk = C:\Program Files\Rainlendar\Rainlendar.exe
    O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1162767866359
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
    O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
    O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
     
  2. tmr250z

    tmr250z Guest

    Some help please?
     
  3. KotaGuy

    KotaGuy Regular member

    Joined:
    Feb 14, 2007
    Messages:
    485
    Likes Received:
    0
    Trophy Points:
    26
    Your HJT log isn't showing anything.

    Is spybot detecting a file or registry entry?
     
  4. tmr250z

    tmr250z Guest

    It's detecting a registry entry:
    Win32.Agent.yr: Settings (Registry value, nothing done)
    HKEY_USERS\S-1-5-21-602162358-838170752-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\*\keygen.exe

    But I deleted all those off my computer, so why is it still showing up?

     
    Last edited by a moderator: Feb 27, 2007
  5. KotaGuy

    KotaGuy Regular member

    Joined:
    Feb 14, 2007
    Messages:
    485
    Likes Received:
    0
    Trophy Points:
    26
    Ahhh... ok... looks like a leftover registry entry... nothing too serious.

    By "all those" I'm assuming you mean keygen.exe?

    Try this for me please...

    Copy/paste the following quote box into a new notepad document...



    Save it to your Desktop as fixme.reg. Save it as File Type All Files(not as a text documnet or it won't work).

    Double click fixme.reg and answer yes when asked to merge it into the registry.

    Reboot and see if Spybot is still picking it up.
     
  6. tmr250z

    tmr250z Guest

    I did what you said, Copy, save, merge, reboot, but Spybot is still picking it up. What now?
     
  7. KotaGuy

    KotaGuy Regular member

    Joined:
    Feb 14, 2007
    Messages:
    485
    Likes Received:
    0
    Trophy Points:
    26
    OK... open new notepad document and copy/paste the following bolded text into it...

    ------------------------------------

    regedit /e /a "HKEY_USERS\S-1-5-21-602162358-838170752-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache"

    start notepad look.txt


    ------------------------------------

    Save it to your Desktop as peek.bat. Save it File Type All Files(not as a text document or it won't work.

    Double click peek.bat... notpepad should open up.

    Copy/paste the contents of that into your next reply please.
     
  8. tmr250z

    tmr250z Guest

  9. KotaGuy

    KotaGuy Regular member

    Joined:
    Feb 14, 2007
    Messages:
    485
    Likes Received:
    0
    Trophy Points:
    26
    OK... we'll do this the hard way then.

    Click Start>Run, type in regedit and hit Enter.

    In the left Pane browse to HKEY_USERS\S-1-5-21-602162358-838170752-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache.

    Right click on the MUICache folder and choose Export.

    Save it to your Desktop as look.reg. Right click on look.reg and choose Edit.

    Copy/Paste the contents of the reg file in your reply.

    Thanks.
     
  10. tmr250z

    tmr250z Guest

    Alright, here it is:

    Windows Registry Editor Version 5.00

    [HKEY_USERS\S-1-5-21-602162358-838170752-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache]
    "LangID"=hex:09,04
    "@shell32.dll,-12691"="My Recent Documents"
    "C:\\Program Files\\CCleaner\\ccleaner.exe"="CCleaner"
    "C:\\Program Files\\uTorrent\\utorrent.exe"="utorrent"
    "@shell32.dll,-31233"="File and Folder Tasks"
    "@shell32.dll,-31236"="Make a new folder"
    "@shell32.dll,-31260"="Publish this folder to the Web"
    "@shell32.dll,-31374"="Share this folder"
    "@shell32.dll,-31272"="Other Places"
    "@C:\\WINDOWS\\system32\\SHELL32.dll,-9227"="My Documents"
    "@shell32.dll,-21785"="Shared Documents"
    "@C:\\WINDOWS\\system32\\SHELL32.dll,-9216"="My Computer"
    "@C:\\WINDOWS\\system32\\SHELL32.dll,-9217"="My Network Places"
    "@shell32.dll,-31274"="Details"
    "C:\\WINDOWS\\Explorer.EXE"="Windows Explorer"
    "@shell32.dll,-31242"="Rename this file"
    "@shell32.dll,-31244"="Move this file"
    "@shell32.dll,-31246"="Copy this file"
    "@shell32.dll,-31248"="Publish this file to the Web"
    "@shell32.dll,-31370"="E-mail this file"
    "@shell32.dll,-31252"="Delete this file"
    "C:\\Program Files\\Windows Media Player\\wmplayer.exe"="Windows Media Player"
    "@shell32.dll,-31264"="Move the selected items"
    "@shell32.dll,-31266"="Copy the selected items"
    "@shell32.dll,-31362"="E-mail the selected items"
    "@shell32.dll,-31270"="Delete the selected items"
    "C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe"="AVG Anti-Spyware"
    "C:\\Program Files\\Eset\\nod32.exe"="NOD32 - on-demand scanner"
    "@C:\\WINDOWS\\system32\\SHELL32.dll,-22914"="Contains letters, reports, and other documents and files."
    "@shell32.dll,-21790"="My Music"
    "@shell32.dll,-21779"="My Pictures"
    "@shell32.dll,-31254"="Rename this folder"
    "@shell32.dll,-31256"="Move this folder"
    "@shell32.dll,-31258"="Copy this folder"
    "@shell32.dll,-31380"="E-mail this folder's files"
    "@shell32.dll,-31262"="Delete this folder"
    "C:\\Documents and Settings\\Keela\\My Documents\\Downloads\\iColorFolder 1.4.2 AiO [vertigo173]\\iColorFolder 1.4.2 AiO.exe"="AutoPlay Application"
    "@shell32.dll,-31371"="Sends an e-mail message with copies of the selected files, or the files within a selected folder."
    "@explorer.exe,-7024"="Internet"
    "@explorer.exe,-7025"="E-mail"
    "C:\\WINDOWS\\System32\\WScript.exe"="Microsoft (r) Windows Based Script Host"
    "@C:\\WINDOWS\\system32\\SHELL32.dll,-9319"="Printers and Faxes"
    "@explorer.exe,-7020"="&Search"
    "@explorer.exe,-7023"="&Run..."
    "@xpsp1res.dll,-11004"="Outlook Express"
    "@C:\\WINDOWS\\system32\\rcbdyctl.dll,-152"="Remote Assistance"
    "@shell32.dll,-22017"="Address Book"
    "@shell32.dll,-22022"="Command Prompt"
    "@shell32.dll,-22051"="Notepad"
    "@C:\\WINDOWS\\system32\\tourstart.exe,-1"="Tour Windows XP"
    "@shell32.dll,-22041"="Magnifier"
    "@shell32.dll,-22048"="Narrator"
    "@shell32.dll,-22052"="On-Screen Keyboard"
    "@shell32.dll,-22065"="Utility Manager"
    "@C:\\WINDOWS\\system32\\xpsp1res.dll,-10077"="Set Program Access and Defaults"
    "@C:\\PROGRA~1\\MOVIEM~1\\wmm2res.dll,-61446"="Windows Movie Maker"
    "@shell32.dll,-22019"="Calculator"
    "@shell32.dll,-22054"="Paint"
    "@shell32.dll,-22069"="WordPad"
    "@shell32.dll,-22016"="Accessibility Wizard"
    "@shell32.dll,-22031"="HyperTerminal"
    "@C:\\WINDOWS\\system32\\mstsc.exe,-4000"="Remote Desktop Connection"
    "@shell32.dll,-22061"="Sound Recorder"
    "@shell32.dll,-22018"="Backup"
    "@shell32.dll,-22021"="Character Map"
    "@shell32.dll,-22026"="Disk Cleanup"
    "@C:\\WINDOWS\\system32\\usmt\\migwiz.exe,-202"="Files and Settings Transfer Wizard"
    "@shell32.dll,-22063"="System Information"
    "@C:\\WINDOWS\\system32\\restore\\rstrui.exe,-2048"="System Restore"
    "@C:\\WINDOWS\\system32\\comres.dll,-661"="Component Services"
    "@shell32.dll,-22023"="Computer Management"
    "@shell32.dll,-22025"="Data Sources (ODBC)"
    "@shell32.dll,-22029"="Event Viewer"
    "@shell32.dll,-22040"="Local Security Policy"
    "@shell32.dll,-22055"="Performance"
    "@shell32.dll,-22059"="Services"
    "@shell32.dll,-22030"="FreeCell"
    "@C:\\WINDOWS\\system32\\mshearts.exe,-413"="Hearts"
    "@C:\\PROGRA~1\\MSNGAM~1\\Windows\\bckgres.dll,-1212"="Internet Backgammon"
    "@C:\\PROGRA~1\\MSNGAM~1\\Windows\\chkrres.dll,-1212"="Internet Checkers"
    "@C:\\PROGRA~1\\MSNGAM~1\\Windows\\hrtzres.dll,-1212"="Internet Hearts"
    "@C:\\PROGRA~1\\MSNGAM~1\\Windows\\rvseres.dll,-1212"="Internet Reversi"
    "@C:\\PROGRA~1\\MSNGAM~1\\Windows\\shvlres.dll,-1212"="Internet Spades"
    "@shell32.dll,-22045"="Minesweeper"
    "@shell32.dll,-22057"="Pinball"
    "@shell32.dll,-22060"="Solitaire"
    "@C:\\WINDOWS\\system32\\spider.exe,-56"="Spider Solitaire"
    "@shell32.dll,-21762"="Administrative Tools"
    "@shell32.dll,-21761"="Accessories"
    "@shell32.dll,-21787"="Startup"
    "@shell32.dll,-21772"="Entertainment"
    "@shell32.dll,-21760"="Accessibility"
    "@shell32.dll,-22062"="Synchronize"
    "@C:\\WINDOWS\\system32\\compatUI.dll,-115"="Program Compatibility Wizard"
    "@shell32.dll,-22067"="Windows Explorer"
    "@shell32.dll,-22075"="Windows Catalog"
    "@shell32.dll,-21773"="Games"
    "@shell32.dll,-21768"="Communications"
    "@shell32.dll,-21788"="System Tools"
    "@C:\\WINDOWS\\system32\\hnetwiz.dll,-3085"="Network Setup Wizard"
    "@C:\\WINDOWS\\system32\\netshell.dll,-1200"="Network Connections"
    "@C:\\WINDOWS\\System32\\xpsp2res.dll,-16201"="Wireless Network Setup Wizard"
    "@C:\\WINDOWS\\system32\\netshell.dll,-1010"="New Connection Wizard"
    "@shell32.dll,-22066"="Volume Control"
    "@shell32.dll,-22058"="Scheduled Tasks"
    "@C:\\WINDOWS\\System32\\xpsp2res.dll,-6103"="Security Center"
    "C:\\Program Files\\Winamp\\winampa.exe"="winampa"
    "C:\\Program Files\\Diskeeper Corporation\\Diskeeper\\DkIcon.exe"="DKICON.EXE"
    "C:\\Program Files\\Unlocker\\UnlockerAssistant.exe"="UnlockerAssistant"
    "C:\\Program Files\\Eset\\nod32kui.exe"="NOD32 Control Center GUI"
    "C:\\Program Files\\BillP Studios\\WinPatrol\\winpatrol.exe"="WinPatrol System Monitor"
    "C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"="TouchPad Driver Helper Application"
    "C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"="Synaptics TouchPad Enhancements"
    "C:\\Program Files\\YourWare Solutions\\FreeRAM XP Pro\\FreeRAM XP Pro.exe"="FreeRAM XP Pro (YourWare Solutions)"
    "C:\\Program Files\\PeerGuardian2\\pg2.exe"="PeerGuardian 2"
    "@C:\\WINDOWS\\system32\\SHELL32.dll,-8964"="Recycle Bin"
    "@C:\\WINDOWS\\system32\\notepad.exe,-469"="Text Document"
    "C:\\Program Files\\Lavasoft\\Ad-Aware SE Professional\\Ad-Aware.exe"="Ad-Aware SE Core application"
    "C:\\Program Files\\Spybot - Search & Destroy\\SpybotSD.exe"="Spybot - Search & Destroy"
    "C:\\Program Files\\SpywareBlaster\\spywareblaster.exe"="SpywareBlaster"
    "C:\\Program Files\\BillP Studios\\WinPatrol\\WinPatrolEx.exe "="WinPatrol Explorer"
    "C:\\Program Files\\BillP Studios\\WinPatrol\\WinPatrolEx.exe"="WinPatrol Explorer"
    "@shell32.dll,-31317"="System Tasks"
    "@shell32.dll,-31321"="Hide the contents of this drive"
    "@shell32.dll,-31327"="Add or remove programs"
    "@shell32.dll,-31292"="Search for files or folders"
    "@shell32.dll,-31328"="Provides the steps necessary to add a new program, or to change or remove an existing program."
    "@shell32.dll,-21765"="Application Data"
    "@shell32.dll,-12693"="Favorites"
    "@shell32.dll,-21786"="Start Menu"
    "@shell32.dll,-31237"="Creates a new, empty folder in the folder you have open."
    "@shell32.dll,-31243"="Gives this file or folder a new label that you type for it."
    "@shell32.dll,-31245"="Moves the selected items to a place you choose."
    "@\"C:\\Program Files\\Windows NT\\Accessories\\WORDPAD.EXE\",-190"="Rich Text Document"
    "@shell32.dll,-31249"="Transfers copies of the selected items to a public Web page so that you can share them with other people."
    "@shell32.dll,-31250"="Print this file"
    "C:\\Program Files\\Windows NT\\Accessories\\WORDPAD.EXE"="WordPad"
    "C:\\Program Files\\Mozilla Firefox\\firefox.exe"="Firefox"
    "C:\\WINDOWS\\system32\\taskmgr.exe"="Windows TaskManager"
    "C:\\WINDOWS\\regedit.exe"="Registry Editor"
    "C:\\Program Files\\TechSmith\\SnagIt 8\\SnagIt32.exe"="SnagIt 8"
    "C:\\Program Files\\TechSmith\\SnagIt 8\\TSCHelp.exe"="TechSmith HTML Help Helper"
    "C:\\Program Files\\TechSmith\\SnagIt 8\\SnagPriv.exe"="SnagIt RPC Helper"
    "@shell32.dll,-21782"="Programs"
    "@C:\\WINDOWS\\system32\\SHELL32.dll,-8503"="S&earch..."
    "@C:\\WINDOWS\\system32\\mycomput.dll,-400"="Mana&ge"
    "@shell32.dll,-31232"="System Tasks"
    "@shell32.dll,-31294"="View system information"
    "@shell32.dll,-31312"="Change a setting"
    "@C:\\WINDOWS\\system32\\SHELL32.dll,-22913"="Shows the disk drives and hardware connected to this computer."
    "@shell32.dll,-31325"="Hide the contents of this folder"
    "@shell32.dll,-31283"="Picture Tasks"
    "@shell32.dll,-31287"="View as a slide show"
    "@shell32.dll,-31313"="Order prints online"
    "@shell32.dll,-31391"="Print pictures"
    "@shell32.dll,-31288"="Arranges all the pictures in this folder into a slide show."
    "@shell32.dll,-31247"="Copies the selected items to a place you choose."
    "@C:\\WINDOWS\\System32\\wshext.dll,-4804"="JScript Script File"
    "@shell32.dll,-31234"="These tasks apply to the files and folders you select."
    "@shell32.dll,-31293"="The Search Companion helps you find files, folders, printers, and people."
    "@C:\\Program Files\\NetMeeting\\conf.exe,-12345"="H.323 Internet Telephony"
    "@C:\\WINDOWS\\system32\\accwiz.exe,-16"="Accessibility Wizard settings"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9903"="AIFF Format Sound"
    "@C:\\WINDOWS\\system32\\SHELL32.dll,-22978"="Briefcase"
    "@C:\\WINDOWS\\System32\\ntbackup.exe,-40"="Windows Backup File"
    "@C:\\WINDOWS\\System32\\pdh.dll,-10023"="Performance Monitor File"
    "@C:\\WINDOWS\\System32\\cryptext.dll,-6145"="Security Catalog"
    "@C:\\WINDOWS\\System32\\cdfview.dll,-4610"="Channel File"
    "@C:\\WINDOWS\\System32\\cryptext.dll,-6108"="Security Certificate"
    "@C:\\Program Files\\NetMeeting\\conf.exe,-12346"="SpeedDial"
    "@C:\\WINDOWS\\System32\\cryptext.dll,-6110"="Certificate Revocation List"
    "@C:\\WINDOWS\\system32\\shimgvw.dll,-304"="Bitmap Image"
    "@\"C:\\Program Files\\Windows NT\\Accessories\\WORDPAD.EXE\",-209"="Wordpad Document"
    "@C:\\WINDOWS\\system32\\netshell.dll,-1300"="Dialup Networking File"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9927"="Microsoft Recorded TV Show"
    "@C:\\WINDOWS\\system32\\shimgvw.dll,-301"="EMF Image"
    "@C:\\Program Files\\NetMeeting\\conf.exe,-12347"="Intel IPhone Compatible"
    "@C:\\WINDOWS\\System32\\setupapi.dll,-2000"="Setup Information"
    "@C:\\Program Files\\Internet Explorer\\Connection Wizard\\icwres.dll,-20003"="Internet Communication Settings"
    "@C:\\WINDOWS\\system32\\shimgvw.dll,-303"="JPEG Image"
    "@C:\\WINDOWS\\System32\\wshext.dll,-4805"="JScript Encoded Script File"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9902"="Movie Clip"
    "@C:\\WINDOWS\\system32\\mmcbase.dll,-130"="Microsoft Common Console Document"
    "@C:\\WINDOWS\\System32\\msi.dll,-34"="Windows Installer Package"
    "@C:\\WINDOWS\\System32\\msi.dll,-35"="Windows Installer Patch"
    "@C:\\WINDOWS\\System32\\RCBdyctl.dll,-150"="Microsoft Remote Assistance Incident"
    "@C:\\Program Files\\Movie Maker\\wmm2res.dll,-63097"="Windows Movie Maker Project"
    "@C:\\Program Files\\NetMeeting\\nmwb.dll,-1234"="Microsoft NetMeeting T126 Compatible Whiteboard Document"
    "@C:\\WINDOWS\\System32\\cryptext.dll,-6111"="PKCS #7 Certificates"
    "@C:\\WINDOWS\\System32\\cryptext.dll,-6113"="PKCS #7 Signature"
    "@C:\\WINDOWS\\System32\\scrobj.dll,-8192"="Windows Script Component"
    "@C:\\WINDOWS\\system32\\shscrap.dll,-258"="Scrap object"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9904"="AU Format Sound"
    "@C:\\WINDOWS\\System32\\cryptext.dll,-6112"="Microsoft Serialized Certificate Store"
    "@C:\\WINDOWS\\System32\\cryptext.dll,-6109"="Certificate Trust List"
    "@C:\\WINDOWS\\system32\\shimgvw.dll,-306"="TIF Image"
    "@C:\\WINDOWS\\System32\\wshext.dll,-4803"="VBScript Encoded Script File"
    "@C:\\WINDOWS\\System32\\wshext.dll,-4802"="VBScript Script File"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9911"="Windows Media Audio shortcut"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9909"="Windows Media Audio/Video file"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9920"="Windows Media Player Download Package"
    "@C:\\WINDOWS\\system32\\shimgvw.dll,-307"="WMF Image"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9915"="Windows Media Player Skin File"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9910"="Windows Media Audio/Video playlist"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9916"="Windows Media Player Skin Package"
    "@\"C:\\Program Files\\Windows NT\\Accessories\\WORDPAD.EXE\",-208"="Write Document"
    "@C:\\WINDOWS\\System32\\wshext.dll,-4801"="Windows Script File"
    "@C:\\WINDOWS\\System32\\wshext.dll,-4800"="Windows Script Host Settings File"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9913"="Windows Media Audio/Video playlist"
    "@C:\\WINDOWS\\system32\\msxml3r.dll,-1"="XML Document"
    "@C:\\WINDOWS\\system32\\msxml3r.dll,-2"="XSL Stylesheet"
    "@shell32.dll,-31314"="Starts the Online Print Ordering Wizard, which helps you order prints of your digital pictures."
    "@shell32.dll,-31390"="Print this picture"
    "@shell32.dll,-31289"="Set as desktop background"
    "@shell32.dll,-31315"="Print the selected pictures"
    "@shell32.dll,-31268"="Publish the selected items to the Web"
    "C:\\Program Files\\FastStone Image Viewer\\FSViewer.exe"="FSViewer"
    "C:\\WINDOWS\\system32\\mspaint.exe"="Paint"
    "C:\\WINDOWS\\system32\\shimgvw.dll"="Windows Picture and Fax Viewer"
    "C:\\PROGRA~1\\TECHSM~1\\SNAGIT~1\\SnagIt32.exe"="SnagIt 8"
    "C:\\PROGRA~1\\MOZILL~1\\FIREFOX.EXE"="Firefox"
    "C:\\Program Files\\Internet Explorer\\iexplore.exe"="Internet Explorer"
    "C:\\Program Files\\Notepad2\\Notepad2.exe"="Notepad2"
    "C:\\WINDOWS\\System32\\NOTEPAD.EXE"="Notepad"
    "@shell32.dll,-31284"="These tasks apply to the picture files and folders you select."
    "@explorer.exe,-7004"="Opens your Internet browser."
    "@shell32.dll,-12704"="Internet P&roperties"
    "@shell32.dll,-12705"="&Browse the Internet"
    "C:\\PROGRA~1\\DAMNNF~1\\DAMNNF~1.EXE"="DAMN NFO Viewer"
    "C:\\Program Files\\Unlocker\\Unlocker.exe"="Unlocker"
    "@shell32.dll,-31322"="Hides the files and folders stored on this drive to protect them from being changed or deleted."
    "@shell32.dll,-31326"="Hides the items stored in this folder to protect them from being changed or deleted."
    "@shell32.dll,-31253"="Moves the selected items to the Recycle Bin. If you want to recover them later, go to the Recycle Bin."
    "@C:\\WINDOWS\\system32\\SHELL32.dll,-22923"="Schedule computer tasks to run automatically."
    "@explorer.exe,-7000"="Opens a window where you can pick search options and work with search results."
    "@shell32.dll,-12708"="Sear&ch"
    "@shell32.dll,-31366"="Results Tasks"
    "@C:\\WINDOWS\\system32\\SHELL32.dll,-30520"="Search Results"
    "@C:\\WINDOWS\\system32\\main.cpl,-2000"="Animated Cursor"
    "@C:\\Program Files\\Common Files\\System\\Ole DB\\msdasqlr.dll,-2323"="Data Source Name"
    "@C:\\WINDOWS\\System32\\icmui.dll,-45"="ICC Profile"
    "@C:\\WINDOWS\\System32\\cryptext.dll,-6148"="Personal Information Exchange"
    "@shell32.dll,-21774"="Local Settings"
    "@C:\\WINDOWS\\system32\\mstsc.exe,-4004"="Remote Desktop Connection"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9924"="Windows Media Library"
    "@zipfldr.dll,-10148"="Compressed (zipped) Folder"
    "@sendmail.dll,-21"="Desktop (create shortcut)"
    "@sendmail.dll,-4"="Mail Recipient"
    "@shell32.dll,-28995"="Shared Music"
    "@shell32.dll,-28997"="Shared Pictures"
    "@shell32.dll,-28996"="Shared Video"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-161"="Sample Playlists"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-162"="Sync Playlists"
    "@xpsp2res.dll,-6100"="Show Desktop"
    "C:\\Program Files\\Kerio\\Personal Firewall 4\\kpf4gui.exe"="Kerio Personal Firewall 4 - GUI"
    "C:\\Program Files\\RegSupreme Pro\\RegSupremePro.exe"="RegSupreme Professional"
    "C:\\Program Files\\Registry Mechanic\\RegMech.exe"="Registry Mechanic 6.0"
    "C:\\Program Files\\TuneUp Utilities 2007\\OneClickMaintenance.exe"="TuneUp OCM"
    "C:\\Program Files\\TuneUp Utilities 2007\\SystemOptimizer.exe"="TuneUp System Optimizer"
    "C:\\Program Files\\TuneUp Utilities 2007\\RegistryCleaner.exe"="TuneUp RegistryCleaner"
    "C:\\WINDOWS\\BricoPacks\\Crystal Clear\\RocketDock\\RocketDock.exe"="RocketDock"
    "C:\\Program Files\\WinRAR\\WinRAR.exe"="WinRAR archiver"
    "@shell32.dll,-31375"="Makes the selected folder available to computers on a network so that other people can view it."
    "@shell32.dll,-31251"="Sends the selected file to the printer."
    "C:\\WINDOWS\\BricoPacks\\Crystal Clear\\RocketDock\\unins000.exe"="Setup/Uninstall"
    "@C:\\WINDOWS\\system32\\SHELL32.dll,-32517"="Taskbar and Start Menu"
    "@C:\\WINDOWS\\system32\\Audiodev.dll,-510"="Portable Media Devices"
    "@C:\\WINDOWS\\system32\\SHELL32.dll,-22985"="Folder Options"
    "@C:\\WINDOWS\\system32\\SHELL32.dll,-22981"="Fonts"
    "@C:\\WINDOWS\\system32\\SHELL32.dll,-22982"="Administrative Tools"
    "@C:\\WINDOWS\\system32\\mstask.dll,-3408"="Scheduled Tasks"
    "@C:\\WINDOWS\\system32\\wiashext.dll,-331"="Scanners and Cameras"
    "@shell32.dll,-8504"="Auto&Play"
    "C:\\WINDOWS\\system32\\rundll32.exe"="Run a DLL as an App"
    "C:\\WINDOWS\\system32\\sndvol32.exe"="Volume Control"
    "C:\\WINDOWS\\system32\\control.exe"="Windows Control Panel"
    "C:\\WINDOWS\\BricoPacks\\Crystal Clear\\RocketDock\\Shortcuts\\Hide Taskbar.exe"="Hide Taskbar"
    "C:\\Program Files\\Winamp\\winamp.exe"="Winamp"
    "C:\\WINDOWS\\BricoPacks\\Crystal Clear\\iColorFolder\\iColorFolder.exe"="iColorFolder main executable"
    "@shdoclc.dll,-880"="Internet Explorer"
    "@shell32.dll,-31361"="Provides options for you to customize the appearance and functionality of your computer."
    "C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avg.as.7.5.0.50-crack.exe"="avg.as.7.5.0.50-crack"
    "@explorer.exe,-7003"="Opens a program, folder, document, or Web site."
    "@shell32.dll,-12710"="&Run"
    "C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe"="System Configuration Utility"
    "@shell32.dll,-31396"="Video Tasks"
    "@shell32.dll,-31278"="Play all"
    "@shell32.dll,-31295"="Shows information about your computer, such as the processor speed and the amount of installed memory."
    "@Shell32.dll,-12690"="Contains movies and other video files."
    "@Shell32.dll,-12689"="Contains music and other audio files."
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9905"="Video Clip"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9914"="Windows Media Audio/Video file"
    "@C:\\WINDOWS\\System32\\setupapi.dll,-2001"="Precompiled Setup Information"
    "@shell32.dll,-31368"="Open the folder that contains this item"
    "C:\\Program Files\\Rainlendar\\Rainlendar.exe"="Rainlendar"
    "C:\\WINDOWS\\BricoPacks\\Crystal Clear\\Panel.exe"="Panel"
    "C:\\Documents and Settings\\Keela\\My Documents\\Downloads\\How To Make a Pre-Patched Reflexive Arcade Game Installer AiO [vertigo173]\\How To Make a Pre-Patched Reflexive Arcade Game Installer AiO.exe"="AutoPlay Application"
    "C:\\Documents and Settings\\Keela\\My Documents\\PNGs.exe"="PNGs"
    "C:\\Program Files\\K-Lite Codec Pack\\Media Player Classic\\mplayerc.exe"="Media Player Classic"
    "C:\\WINDOWS\\BricoPacks\\Crystal Clear\\UberIcon\\UberIcon Manager.exe"="UberIcon Manager"
    "@themeui.dll,-2037"="{Tahoma, 8 pt}"
    "@themeui.dll,-2038"="{Tahoma, 8 pt}"
    "@themeui.dll,-2039"="{Tahoma, 8 pt}"
    "@themeui.dll,-2040"="{Tahoma, 8 pt}"
    "@themeui.dll,-2041"="{Tahoma, 8 pt}"
    "@themeui.dll,-2042"="{Tahoma, 8 pt}"
    "@themeui.dll,-2017"="Windows XP"
    "@themeui.dll,-2016"="Windows Classic"
    "@themeui.dll,-2015"="More themes online..."
    "@shell32.dll,-31398"="Plays all or the selected video files in this folder."
    "@shell32.dll,-31276"="Music Tasks"
    "@shell32.dll,-31281"="Shop for music online"
    "@shell32.dll,-31277"="These tasks apply to the music files and folders you select."
    "C:\\Documents and Settings\\Keela\\My Documents\\Downloads\\StyleBuilder.2.021000-Patch_CiM\\CRACK.EXE"="CRACK"
    "C:\\Documents and Settings\\Keela\\My Documents\\Software\\Apps\\TuneUp.Utilities.2007.v6.0.1255.Incl.Keygen-FYSP\\Keygen.exe"="Keygen"
    "C:\\Documents and Settings\\Keela\\My Documents\\Software\\Apps\\Nero 6.6.0.18\\Keygen.exe"="Keygen"
    "C:\\Documents and Settings\\Keela\\My Documents\\Software\\Apps\\WinRAR 3.62 + SND Cracker Edition Patch 1.62 by MaRKuS TH-DJM\\WinRAR Patch.exe"="WinRAR Patch"
    "C:\\Documents and Settings\\Keela\\My Documents\\Software\\Apps\\Nullsoft.WinAmp.Pro.v5.33.Incl.KeyMaker-DVT\\DVT\\KeyMaker.exe"="KeyMaker"
    "@C:\\WINDOWS\\system32\\SHELL32.dll,-12696"="Shows installed printers and fax printers and helps you add new ones."
    "C:\\Program Files\\blbeta\\blbeta.exe"="F-Secure BlackLight"
    "C:\\Program Files\\HijackThis\\HijackThis.exe"="HijackThis"
    "@shell32.dll,-31279"="Play selection"
    "@%SystemRoot%\\system32\\shell32.dll,-22534"="Performs text-based (command-line) functions."
    "@inetcplc.dll,-4774"="ActiveX controls and plug-ins"
    "@inetcplc.dll,-4775"="Run ActiveX controls and plug-ins"
    "@inetcplc.dll,-4803"="Enable"
    "@inetcplc.dll,-4806"="Administrator approved"
    "@inetcplc.dll,-4805"="Disable"
    "@inetcplc.dll,-4804"="Prompt"
    "@xpsp2res.dll,-4889"="Automatic prompting for ActiveX controls"
    "@xpsp2res.dll,-4881"="Binary and script behaviors"
    "@inetcplc.dll,-4776"="Download signed ActiveX controls"
    "@inetcplc.dll,-4783"="Initialize and script ActiveX controls not marked as safe"
    "@inetcplc.dll,-4784"="Script ActiveX controls marked safe for scripting"
    "@inetcplc.dll,-4777"="Download unsigned ActiveX controls"
    "@inetcplc.dll,-4788"="User Authentication"
    "@inetcplc.dll,-4790"="Logon"
    "@inetcplc.dll,-4807"="Anonymous logon"
    "@inetcplc.dll,-4808"="Prompt for user name and password"
    "@inetcplc.dll,-4810"="Automatic logon only in Intranet zone"
    "@inetcplc.dll,-4809"="Automatic logon with current username and password"
    "@mscorier.dll,-1001"=".NET Framework-reliant components"
    "@mscorier.dll,-1006"="Run components signed with Authenticode"
    "@mscorier.dll,-1004"="Enable"
    "@mscorier.dll,-1003"="Disable"
    "@mscorier.dll,-1005"="Prompt"
    "@mscorier.dll,-1002"="Run components not signed with Authenticode"
    "@inetcplc.dll,-4791"="Downloads"
    "@xpsp2res.dll,-4890"="Automatic prompting for file downloads"
    "@inetcplc.dll,-4792"="File download"
    "@inetcplc.dll,-4793"="Font download"
    "@inetcplc.dll,-4794"="Miscellaneous"
    "@inetcplc.dll,-4862"="Don't prompt for client certificate selection when no certificates or only one certificate exists"
    "@inetcplc.dll,-4785"="Access data sources across domains"
    "@inetcplc.dll,-4796"="Drag and drop or copy and paste files"
    "@inetcplc.dll,-4797"="Submit nonencrypted form data"
    "@inetcplc.dll,-4795"="Installation of desktop items"
    "@inetcplc.dll,-4798"="Launching programs and files in an IFRAME"
    "@inetcplc.dll,-4870"="Allow META REFRESH"
    "@xpsp2res.dll,-4885"="Open files based on content, not file extension"
    "@inetcplc.dll,-4872"="Display mixed content"
    "@xpsp2res.dll,-4883"="Use Pop-up Blocker"
    "@xpsp2res.dll,-5786"="Allow Web pages to use restricted protocols for active content"
    "@inetcplc.dll,-4830"="Software channel permissions"
    "@inetcplc.dll,-4816"="High safety"
    "@inetcplc.dll,-4814"="Low safety"
    "@inetcplc.dll,-4815"="Medium safety"
    "@inetcplc.dll,-4855"="Navigate sub-frames across different domains"
    "@inetcplc.dll,-4853"="Userdata persistence"
    "@xpsp2res.dll,-4900"="Allow scripting of Internet Explorer Webbrowser control"
    "@xpsp2res.dll,-4887"="Allow script-initiated windows without size or position constraints"
    "@xpsp2res.dll,-4886"="Web sites in less privileged web content zone can navigate into this zone"
    "@inetcplc.dll,-4782"="Scripting"
    "@inetcplc.dll,-4786"="Active scripting"
    "@inetcplc.dll,-4787"="Scripting of Java applets"
    "@inetcplc.dll,-4854"="Allow paste operations via script"
    "@C:\\Program Files\\Internet Explorer\\iexplore.exe,-702"="Internet Explorer"
    "@%SystemRoot%\\system32\\shell32.dll,-22572"="Begins the Solitaire card game."
    "C:\\WINDOWS\\system32\\sol.exe"="Solitaire Game Applet"
    "@%SystemRoot%\\system32\\spider.exe,-57"="Begins the Spider Solitaire card game."
    "C:\\WINDOWS\\system32\\spider.exe"="Spider"
    "C:\\Documents and Settings\\Keela\\My Documents\\AveDesk11.exe"="AveDesk Setup "
    "@zipfldr.dll,-10300"="Folder Tasks"
    "@zipfldr.dll,-10302"="Extract all files"
    "C:\\Documents and Settings\\Keela\\My Documents\\Software\\Apps\\Alcohol 120% 1.9.5.3105\\Alcohol 120% 1.9.5.3105 crack.exe"="Alcohol 120% 1.9.5.3105 crack"
    "C:\\Documents and Settings\\Keela\\My Documents\\Software\\Apps\\Clock.Tray.Skins.v3.5.WinNT2kXP.Cracked-ViRiLiTY\\Crack\\crack.exe"="crack"
    "C:\\Documents and Settings\\Keela\\My Documents\\Software\\Apps\\Net Transport 2.02.307\\Patch 2.xx.exe"="Patch 2.xx"
    "C:\\Documents and Settings\\Keela\\My Documents\\Software\\Apps\\Firewalls\\Kerio Personal Firewall v4.2.1.Build.911+Patch\\Linezer0\\Keriokey.exe"="Keriokey"
    "C:\\Documents and Settings\\Keela\\My Documents\\Software\\Apps\\Firewalls\\Kerio.Personal.Firewall.v4.2.3.Incl.Keygen-Lz0\\crack\\keriokey.exe"="keriokey"
    "C:\\Documents and Settings\\Keela\\My Documents\\Software\\Apps\\Firewalls\\Sygate Personal Firewall Pro v 5.5 Build 2710 ultimate pack\\Sygate registration crack\\keygen.exe"="keygen"
    "C:\\Documents and Settings\\Keela\\My Documents\\Software\\Apps\\Firewalls\\Sygate.Personal.Firewall.Pro.v5.6.3408.Debug.Build.Incl.Keygen\\Keygen\\keygen.exe"="keygen"
    "C:\\Documents and Settings\\Keela\\My Documents\\Software\\Apps\\Stardock Apps\\IconPackager 3.10 Enhanced\\snd-stardock iconpackager enhanced 3.10 patch\\stardock.iconpackager.enhanced.3.10-patch.exe"="stardock.iconpackager.enhanced.3.10-patch"
    "C:\\Documents and Settings\\Keela\\My Documents\\Downloads\\AVG.Anti-Spyware lazzy\\avg.as.7.5.0.50-crack.exe"="avg.as.7.5.0.50-crack"
    "C:\\Documents and Settings\\Keela\\My Documents\\Downloads\\WinPatrol.PLUS.v11.1.2007.WinALL+Keygen (Works on Vista)\\keygen.exe"="keygen"
    "C:\\Documents and Settings\\Keela\\My Documents\\Software\\AiOs\\VMware - Inside & Out AiO [vertigo173]\\VMware - Inside & Out AiO.exe"="AutoPlay Application"
    "C:\\DOCUME~1\\Keela\\LOCALS~1\\Temp\\ir_ext_temp_0\\autorun.exe"="AutoPlay Application"
    "C:\\Documents and Settings\\Keela\\Desktop\\VMware Workstation 5.5.1.19175\\Keygen.exe"="Keygen"
    "C:\\Documents and Settings\\Keela\\My Documents\\Software\\AiOs\\Windows Vista Transformation AiO 2006 [vertigo173]\\Windows Vista Transformation AiO 2006.exe"="AutoPlay Application"
    "C:\\DOCUME~1\\Keela\\LOCALS~1\\Temp\\ir_ext_temp_0\\AutoPlay\\Docs\\Windows Vista Transformation AiO 2006.exe"="AutoPlay Application"
    "C:\\DOCUME~1\\Keela\\LOCALS~1\\Temp\\ir_ext_temp_1\\autorun.exe"="AutoPlay Application"
    "@shell32.dll,-31316"="Starts the Photo Printing Wizard, which helps you format and print your digital pictures."
    "@shell32.dll,-31280"="Plays all or the selected music files in this folder."
    "C:\\DOCUME~1\\Keela\\LOCALS~1\\Temp\\ir_ext_temp_1\\AutoPlay\\Docs\\Windows Vista Transformation AiO 2006.exe"="AutoPlay Application"
    "C:\\DOCUME~1\\Keela\\LOCALS~1\\Temp\\ir_ext_temp_2\\autorun.exe"="AutoPlay Application"
    "@shell32.dll,-31282"="Connects you to the Windows Media Web site where you can find music to download and buy."
    "@Shell32.dll,-12692"="Shows recently opened files and folders."
    "@C:\\Program Files\\Movie Maker\\wmm2res.dll,-63096"="Capture and edit digital media on your computer and then share your saved movies by e-mail, the Internet, recordable CD, or on a DV video tape."
    "C:\\Documents and Settings\\Keela\\Desktop\\peek.bat"="peek"
    "C:\\WINDOWS\\system32\\cmd.exe"="Windows Command Processor"
    "@%SystemRoot%\\system32\\shell32.dll,-22563"="Creates and edits text files using basic text formatting."
    "C:\\PROGRA~1\\FOXITS~1\\FOXITR~1\\FOXITR~1.EXE"="Foxit Reader, Best Reader for Everyday Use!"
    "C:\\PROGRA~1\\Ahead\\nero\\nero.exe"="Nero Burning ROM"
    "C:\\Program Files\\QuickSFV\\QuickSFV.EXE"="QuickSFV"
    "C:\\Program Files\\TuneUp Utilities 2007\\WinStyler.exe"="TuneUp Styler 2"
    "@%SystemRoot%\\system32\\shell32.dll,-22566"="Creates and edits drawings, and displays and edits scanned photos."
    "C:\\Documents and Settings\\Keela\\My Documents\\klcp_update_20070228.exe"="KLCP Update Setup "
    "C:\\DOCUME~1\\Keela\\LOCALS~1\\Temp\\is-CI7O7.tmp\\is-GRCKN.tmp"="Setup/Uninstall"
    "C:\\DOCUME~1\\Keela\\LOCALS~1\\Temp\\is-07H4M.tmp\\is-EPIIL.tmp"="is-EPIIL"
    "C:\\Program Files\\AveDesk\\AveDesk.exe"="AveDesk"

     
  11. KotaGuy

    KotaGuy Regular member

    Joined:
    Feb 14, 2007
    Messages:
    485
    Likes Received:
    0
    Trophy Points:
    26
    Someone's been playing with cracks :)

    Anyways... these registry entries aren't anything to worry about... they are harmless as they are.

    I'll be back in a while with a regfix that I'll ask you to run that should get rid of them.
     
  12. tmr250z

    tmr250z Guest

    Okay, I will wait then.

    But I have a couple of questions:

    1. If this registry entry is harmless as you say, then why is Spybot picking it up as spyware?

    2. Does this mean that one of the "cracks" I had on my computer was or contained spyware or trojans even though when scanned it came up as being clean?
     
    Last edited by a moderator: Feb 28, 2007
  13. KotaGuy

    KotaGuy Regular member

    Joined:
    Feb 14, 2007
    Messages:
    485
    Likes Received:
    0
    Trophy Points:
    26
    1. Spybot is detecting it because the registry entry is in its definition files. Just so you know... the entries in the MUICache Key are created when files are run. They are put there by the Windows Shell(explorer.exe). So the entries there are harmless as they really don't do anything.

    2. A lot of cracks/keygens have malware in them. And just because your AV scanner didn't pick it up doesn't mean they are clean. Its best to scan things with multiple scanners as what one scanner may miss another may catch. One of my favorite sites to scan suspicious files is VirusTotal:

    http://www.virustotal.com/en/indexf.html

    Uploading a file there will result in it being scanned by a lot of different scanners. Its a very good tool.

    Now... for the regfix...

    Copy/paste the following quote into a new notepad document...

    Save it to your Desktop as fixme.reg. Save it as File Type All Files(not as a text document or it won't work.

    Double click fixme.reg and answer yes when asked to merge it into the registry.

    Reboot and do another scan with Spybot... let me know how it goes.
     
  14. tmr250z

    tmr250z Guest

    Ok, Success!! It's gone!! Thank you so much for all your help and the info you have given me. You're truly gracious and brilliant!
     
  15. KotaGuy

    KotaGuy Regular member

    Joined:
    Feb 14, 2007
    Messages:
    485
    Likes Received:
    0
    Trophy Points:
    26
    Good to hear... glad I was able to help :)
     
  16. dkkoen

    dkkoen Member

    Joined:
    Mar 8, 2007
    Messages:
    7
    Likes Received:
    0
    Trophy Points:
    11
    Kotaguy.

    i have the same problem, is it possible you can help me to?

    thnks in advance

    dkkoen
     
  17. KotaGuy

    KotaGuy Regular member

    Joined:
    Feb 14, 2007
    Messages:
    485
    Likes Received:
    0
    Trophy Points:
    26
    Hi dkkoen.

    Let me know exactly where Spybot is picking this up please.
     
  18. dkkoen

    dkkoen Member

    Joined:
    Mar 8, 2007
    Messages:
    7
    Likes Received:
    0
    Trophy Points:
    11
    HKEY_USERS\S-1-5-21-515967899-1229272821-12292272821-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\*\keygen.exe

    here spybot is picking it up. but sometimes i repair it with spybot and it is gone, and a l day later it is back. is it hiding? and is it also harmlees?

    i think i know what keygen was the problem(W genuine) and i scanned it in virus total as you recommend. there it found with ikarus : Backdoor.Tagent.E of 30 scanners this was the only one picking up!

    is this the same as what spy bot found or, is there more what spybot doesn't find?

    thanks a lot you wonna help me!!

    dkkoen
     
  19. KotaGuy

    KotaGuy Regular member

    Joined:
    Feb 14, 2007
    Messages:
    485
    Likes Received:
    0
    Trophy Points:
    26
    Click Start>Run, type in regedit and hit Enter.

    In the left Pane browse to HKEY_USERS\S-1-5-21-515967899-1229272821-12292272821-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache

    Right click on the MUICache folder and choose Export.

    Save it to your Desktop as look.reg. Right click on look.reg and choose Edit.

    Copy/Paste the contents of the reg file in your reply.

    Thanks.
     
  20. dkkoen

    dkkoen Member

    Joined:
    Mar 8, 2007
    Messages:
    7
    Likes Received:
    0
    Trophy Points:
    11
    Windows Registry Editor Version 5.00

    [HKEY_USERS\S-1-5-21-515967899-1229272821-725345543-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache]
    "LangID"=hex:13,04
    "C:\\Program Files\\NewsLeecher\\newsLeecher.exe"="newsLeecher"
    "@explorer.exe,-7024"="Internet"
    "@explorer.exe,-7025"="E-mail"
    "@explorer.exe,-7023"="&Uitvoeren..."
    "@explorer.exe,-7020"="&Zoeken"
    "@explorer.exe,-7021"="&Help en ondersteuning"
    "@C:\\WINDOWS\\system32\\SHELL32.dll,-9319"="Printers en faxapparaten"
    "@xpsp1res.dll,-10077"="Programmatoegang en -instellingen"
    "@C:\\WINDOWS\\system32\\SHELL32.dll,-9217"="Mijn netwerklocaties"
    "@C:\\WINDOWS\\system32\\SHELL32.dll,-9216"="Deze computer"
    "@shell32.dll,-21790"="Mijn muziek"
    "@shell32.dll,-21779"="Mijn afbeeldingen"
    "@C:\\WINDOWS\\system32\\SHELL32.dll,-9227"="Mijn documenten"
    "@C:\\WINDOWS\\system32\\rcbdyctl.dll,-152"="Hulp op afstand"
    "@C:\\WINDOWS\\system32\\xpsp1res.dll,-10077"="Programmatoegang en -instellingen"
    "@shell32.dll,-22075"="Windows-catalogus"
    "@shell32.dll,-21761"="Bureau-accessoires"
    "@C:\\PROGRA~1\\MOVIEM~1\\wmm2res.dll,-61446"="Windows Movie Maker"
    "@shell32.dll,-21773"="Ontspanning"
    "@shell32.dll,-21787"="Opstarten"
    "C:\\Program Files\\CA\\eTrust Internet Security Suite\\eTrust PestPatrol Anti-Spyware\\cauninst.exe"="cauninst"
    "C:\\WINDOWS\\system32\\MsiExec.exe"="Windows® installer"
    "C:\\PROGRA~1\\MOZILL~1\\FIREFOX.EXE"="Firefox"
    "@shell32.dll,-21762"="Systeembeheer"
    "@shell32.dll,-21768"="Communicatie"
    "@shell32.dll,-21788"="Systeemwerkset"
    "@shell32.dll,-22019"="Rekenmachine"
    "@shell32.dll,-22054"="Paint"
    "@shell32.dll,-22069"="WordPad"
    "@C:\\WINDOWS\\system32\\sti_ci.dll,-11"="Wizard Scanner en camera"
    "@C:\\WINDOWS\\system32\\mstsc.exe,-4000"="Verbinding met extern bureaublad"
    "@C:\\WINDOWS\\system32\\netshell.dll,-1200"="Netwerkverbindingen"
    "@shell32.dll,-22031"="HyperTerminal"
    "@C:\\WINDOWS\\System32\\xpsp2res.dll,-16201"="Draadloos netwerk instellen"
    "@C:\\WINDOWS\\system32\\xpsp2res.dll,-2303"="Wizard Bestandsoverdracht via Bluetooth"
    "@C:\\WINDOWS\\system32\\netshell.dll,-1010"="Wizard Nieuwe verbinding"
    "@C:\\WINDOWS\\system32\\hnetwiz.dll,-3085"="Wizard Netwerk instellen"
    "@shell32.dll,-22066"="Volumeregeling"
    "@shell32.dll,-22061"="Geluidsrecorder"
    "@C:\\WINDOWS\\System32\\xpsp2res.dll,-6103"="Beveiligingscentrum"
    "@shell32.dll,-22018"="Back-up"
    "@shell32.dll,-22027"="Schijfdefragmentatie"
    "@shell32.dll,-22058"="Geplande taken"
    "@shell32.dll,-22021"="Speciale tekens"
    "@shell32.dll,-22026"="Schijfopruiming"
    "@C:\\WINDOWS\\system32\\usmt\\migwiz.exe,-202"="Wizard Bestanden en instellingen overzetten"
    "@shell32.dll,-22063"="Systeeminfo"
    "@C:\\WINDOWS\\system32\\restore\\rstrui.exe,-2048"="Systeemherstel"
    "@C:\\PROGRA~1\\MSNGAM~1\\Windows\\chkrres.dll,-1212"="Dammen op het Internet"
    "@C:\\PROGRA~1\\MSNGAM~1\\Windows\\bckgres.dll,-1212"="Backgammon op het Internet"
    "@C:\\WINDOWS\\system32\\mshearts.exe,-413"="Hartenjagen"
    "@shell32.dll,-21792"="Documenten van %s"
    "@shell32.dll,-21785"="Gedeelde documenten"
    "@C:\\PROGRA~1\\MSNGAM~1\\Windows\\hrtzres.dll,-1212"="Hartenjagen op het Internet"
    "@shell32.dll,-22030"="FreeCell"
    "@shell32.dll,-22057"="Pinball"
    "@shell32.dll,-22060"="Patience"
    "@shell32.dll,-22045"="Mijnenveger"
    "@C:\\WINDOWS\\system32\\spider.exe,-56"="Spider Solitaire"
    "@C:\\PROGRA~1\\MSNGAM~1\\Windows\\shvlres.dll,-1212"="Spades op het Internet"
    "@C:\\PROGRA~1\\MSNGAM~1\\Windows\\rvseres.dll,-1212"="Reversi op het Internet"
    "@shell32.dll,-22023"="Computerbeheer"
    "@C:\\WINDOWS\\system32\\comres.dll,-661"="Component Services"
    "@shell32.dll,-22029"="Logboeken"
    "@shell32.dll,-22025"="Gegevensbronnen (ODBC)"
    "@shell32.dll,-22040"="Lokaal beveiligingsbeleid"
    "@shell32.dll,-22059"="Services"
    "@shell32.dll,-22055"="Prestaties"
    "@shell32.dll,-12693"="Favorieten"
    "@shell32.dll,-21786"="Menu Start"
    "C:\\DOCUME~1\\Karel\\LOCALS~1\\Temp\\cacu_001.exe"="cacu_001"
    "@shell32.dll,-22017"="Adresboek"
    "@shell32.dll,-22051"="Kladblok"
    "@shell32.dll,-22022"="Opdrachtprompt"
    "@C:\\WINDOWS\\system32\\tourstart.exe,-1"="Rondleiding door Windows XP"
    "@shell32.dll,-22065"="Hulpprogrammabeheer"
    "@shell32.dll,-22052"="Schermtoetsenbord"
    "@shell32.dll,-22041"="Vergrootglas"
    "@shell32.dll,-22016"="Wizard Toegankelijkheid"
    "@shell32.dll,-21760"="Toegankelijkheid"
    "@shell32.dll,-21772"="Entertainment"
    "@shell32.dll,-22062"="Synchroniseren"
    "@C:\\WINDOWS\\system32\\compatUI.dll,-115"="Wizard Programmacompatibiliteit"
    "@shell32.dll,-22067"="Windows Verkenner"
    "C:\\WINDOWS\\SiSUSBrg.exe"="SiSUSBrg"
    "C:\\WINDOWS\\system32\\sistray.EXE"="SiS Compatible Super VGA Tray Application"
    "C:\\WINDOWS\\system32\\keyhook.exe"="SiS Compatible Super VGA Keyboard Daemon"
    "C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe"="AVG Control Center"
    "C:\\Program Files\\Tiny Firewall Pro\\Quarantine\\jusched.exe"="Java(TM) 2 Platform Standard Edition binary"
    "C:\\WINDOWS\\system32\\LVCOMSX.EXE"="LVCom Server"
    "C:\\WINDOWS\\system32\\RunDll32.exe"="Een DLL-bestand als toepassing starten"
    "C:\\WINDOWS\\KHALMNPR.EXE"="Logitech KHAL Main Process"
    "C:\\Program Files\\Windows Defender\\MSASCui.exe"="Windows Defender User Interface"
    "C:\\WINDOWS\\system32\\ctfmon.exe"="CTF Loader"
    "C:\\Program Files\\Tiny Firewall Pro\\amon.exe"="Tiny Activity Monitor"
    "C:\\Program Files\\Logitech\\SetPoint\\SetPoint.exe"="Logitech SetPoint Event Manager (UNICODE)"
    "@C:\\WINDOWS\\ime\\sptip.dll,-600"="Spraakherkenning"
    "@%SystemRoot%\\system32\\input.dll,-5053"="Bulgaars"
    "@%SystemRoot%\\system32\\input.dll,-5031"="Tsjechisch"
    "@%SystemRoot%\\system32\\input.dll,-5007"="Deens"
    "@%SystemRoot%\\system32\\input.dll,-5011"="Duits"
    "@%SystemRoot%\\system32\\input.dll,-5046"="Grieks"
    "@%SystemRoot%\\system32\\input.dll,-5000"="Verenigde Staten"
    "@%SystemRoot%\\system32\\input.dll,-5020"="Spaans"
    "@%SystemRoot%\\system32\\input.dll,-5009"="Fins"
    "@%SystemRoot%\\system32\\input.dll,-5010"="Frans"
    "@%SystemRoot%\\system32\\input.dll,-5033"="Hongaars"
    "@%SystemRoot%\\system32\\input.dll,-5013"="IJslands"
    "@%SystemRoot%\\system32\\input.dll,-5015"="Italiaans"
    "@%SystemRoot%\\system32\\input.dll,-5008"="Nederlands"
    "@%SystemRoot%\\system32\\input.dll,-5018"="Noors"
    "@%SystemRoot%\\system32\\input.dll,-5035"="Pools (programmeurs)"
    "@%SystemRoot%\\system32\\input.dll,-5003"="Portugees (Braziliaans ABNT)"
    "@%SystemRoot%\\system32\\input.dll,-5037"="Roemeens"
    "@%SystemRoot%\\system32\\input.dll,-5055"="Russisch"
    "@%SystemRoot%\\system32\\input.dll,-5030"="Kroatisch"
    "@%SystemRoot%\\system32\\input.dll,-5039"="Slowaaks"
    "@%SystemRoot%\\system32\\input.dll,-5029"="Albanees"
    "@%SystemRoot%\\system32\\input.dll,-5022"="Zweeds"
    "@%SystemRoot%\\system32\\input.dll,-5060"="Turks (Q)"
    "@%SystemRoot%\\system32\\input.dll,-5058"="Oekraïens"
    "@%SystemRoot%\\system32\\input.dll,-5052"="Wit-Russisch"
    "@%SystemRoot%\\system32\\input.dll,-5041"="Sloveens"
    "@%SystemRoot%\\system32\\input.dll,-5042"="Ests"
    "@%SystemRoot%\\system32\\input.dll,-5043"="Lets"
    "@%SystemRoot%\\system32\\input.dll,-5045"="Litouws (IBM)"
    "@%SystemRoot%\\system32\\input.dll,-5117"="Azeri (Latijn)"
    "@%SystemRoot%\\system32\\input.dll,-5109"="Macedonisch (Macedonië)"
    "@%SystemRoot%\\system32\\input.dll,-5108"="Faeröers"
    "@%SystemRoot%\\system32\\xpsp2res.dll,-5105"="Maltees 47-toetsen"
    "@%SystemRoot%\\system32\\xpsp2res.dll,-5111"="Noors met Sami"
    "@%SystemRoot%\\system32\\input.dll,-5113"="Kazachstaans"
    "@%SystemRoot%\\system32\\input.dll,-5128"="Kyrgisisch (Cyrillic)"
    "@%SystemRoot%\\system32\\input.dll,-5116"="Tataars"
    "@%SystemRoot%\\system32\\input.dll,-5127"="Mongools (Cyrillisch)"
    "@%SystemRoot%\\system32\\xpsp2res.dll,-5104"="Verenigd Koninkrijk Uitgebreid"
    "@%SystemRoot%\\system32\\xpsp2res.dll,-5107"="Maori"
    "@%SystemRoot%\\system32\\input.dll,-5024"="Duits (Zwitserland)"
    "@%SystemRoot%\\system32\\input.dll,-5025"="Verenigd Koninkrijk"
    "@%SystemRoot%\\system32\\input.dll,-5017"="Latijns-Amerikaans"
    "@%SystemRoot%\\system32\\input.dll,-5002"="Frans (België)"
    "@%SystemRoot%\\system32\\input.dll,-5001"="Belgisch (punt)"
    "@%SystemRoot%\\system32\\input.dll,-5019"="Portugees"
    "@%SystemRoot%\\system32\\input.dll,-5038"="Servisch (Latijns)"
    "@%SystemRoot%\\system32\\input.dll,-5115"="Azeri (Cyrillisch)"
    "@%SystemRoot%\\system32\\xpsp2res.dll,-5109"="Zweeds met Sami"
    "@%SystemRoot%\\system32\\input.dll,-5114"="Oezbeeks (Cyrillisch)"
    "@%SystemRoot%\\system32\\input.dll,-5005"="Canada (Frans, verouderd)"
    "@%SystemRoot%\\system32\\input.dll,-5057"="Servisch (Cyrillisch)"
    "@%SystemRoot%\\system32\\input.dll,-5004"="Frans (Canada)"
    "@%SystemRoot%\\system32\\input.dll,-5023"="Frans (Zwitserland)"
    "@%SystemRoot%\\system32\\xpsp2res.dll,-5108"="Bosnisch"
    "@%SystemRoot%\\system32\\input.dll,-5014"="Iers"
    "@%SystemRoot%\\system32\\input.dll,-5054"="Bulgaars (Latijn)"
    "@%SystemRoot%\\system32\\input.dll,-5032"="Tsjechisch (Qwerty)"
    "@%SystemRoot%\\system32\\input.dll,-5012"="Duits (IBM)"
    "@%SystemRoot%\\system32\\input.dll,-5048"="Grieks (220)"
    "@%SystemRoot%\\system32\\input.dll,-5092"="Verenigde Staten (Dvorak)"
    "@%SystemRoot%\\system32\\input.dll,-5021"="Spaans (variatie)"
    "@%SystemRoot%\\system32\\input.dll,-5034"="Hongaars (101 toetsen)"
    "@%SystemRoot%\\system32\\input.dll,-5016"="Italiaans (142)"
    "@%SystemRoot%\\system32\\input.dll,-5036"="Pools (214)"
    "@%SystemRoot%\\system32\\input.dll,-5126"="Portugees (Braziliaans ABNT2)"
    "@%SystemRoot%\\system32\\input.dll,-5056"="Russisch (Schrijfmachine)"
    "@%SystemRoot%\\system32\\input.dll,-5040"="Slowaaks (QWERTY)"
    "@%SystemRoot%\\system32\\input.dll,-5059"="Turks (F)"
    "@%SystemRoot%\\system32\\input.dll,-5044"="Lets (QWERTY)"
    "@%SystemRoot%\\system32\\input.dll,-5088"="Litouws"
    "@%SystemRoot%\\system32\\xpsp2res.dll,-5106"="Maltees 48-toetsen"
    "@%SystemRoot%\\system32\\xpsp2res.dll,-5113"="Sami uitgebreid Noorwegen"
    "@%SystemRoot%\\system32\\input.dll,-5089"="Belgisch (komma)"
    "@%SystemRoot%\\system32\\xpsp2res.dll,-5110"="Fins met Sami"
    "@%SystemRoot%\\system32\\input.dll,-5110"="Canada (meertalig, standaard)"
    "@%SystemRoot%\\system32\\input.dll,-5125"="Gaelic"
    "@%SystemRoot%\\system32\\input.dll,-5087"="Tsjechisch (programmeurs)"
    "@%SystemRoot%\\system32\\input.dll,-5049"="Grieks (319)"
    "@%SystemRoot%\\system32\\input.dll,-5026"="Verenigde Staten (internationaal)"
    "@%SystemRoot%\\system32\\xpsp2res.dll,-5112"="Sami uitgebreid Finland-Zweden"
    "@%SystemRoot%\\system32\\input.dll,-5050"="Grieks (220, Latijn)"
    "@%SystemRoot%\\system32\\input.dll,-5027"="Verenigde Staten (Dvorak linkshandig)"
    "@%SystemRoot%\\system32\\input.dll,-5051"="Grieks (319, Latijn)"
    "@%SystemRoot%\\system32\\input.dll,-5028"="Verenigde Staten (Dvorak rechtshandig)"
    "@%SystemRoot%\\system32\\input.dll,-5047"="Grieks (Latijn)"
    "@%SystemRoot%\\system32\\input.dll,-5122"="Grieks (polytoon)"
    "C:\\Program Files\\Logitech\\SetPoint\\SetPointUpdate.exe"="Logitech Updater (UNICODE)"
    "C:\\WINDOWS\\system32\\regsvr32.exe"="Microsoft(C) Register Server"
    "@shdoclc.dll,-880"="Internet Explorer"
    "C:\\Program Files\\Mozilla Firefox\\firefox.exe"="Firefox"
    "@shell32.dll,-31233"="Bestands- en maptaken"
    "@shell32.dll,-31260"="Deze map op het web publiceren"
    "@shell32.dll,-31374"="Deze map delen"
    "@shell32.dll,-31272"="Andere locaties"
    "@shell32.dll,-31274"="Details"
    "C:\\WINDOWS\\Explorer.EXE"="Windows Verkenner"
    "@shell32.dll,-31242"="Dit bestand een andere naam geven"
    "@shell32.dll,-31244"="Dit bestand verplaatsen"
    "@shell32.dll,-31246"="Dit bestand kopiëren"
    "@shell32.dll,-31248"="Dit bestand op het web publiceren"
    "@shell32.dll,-31370"="Dit bestand per e-mail verzenden"
    "@shell32.dll,-31250"="Dit bestand afdrukken"
    "@shell32.dll,-31252"="Dit bestand verwijderen"
    "@C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\msinfo.dll,-391"="MSInfo-document"
    "@shell32.dll,-31264"="De geselecteerde items verplaatsen"
    "@shell32.dll,-31266"="De geselecteerde items kopiëren"
    "@shell32.dll,-31268"="De geselecteerde items op het web publiceren"
    "@shell32.dll,-31362"="De geselecteerde items per e-mail verzenden"
    "@shell32.dll,-31270"="De geselecteerde items verwijderen"
    "C:\\Program Files\\QuickPar\\QuickPar.exe"="QuickPar (Dutch)"
    "C:\\Program Files\\Soldier of Fortune II - Double Helix\\SoF2MP.exe"="SoF2MP"
    "@explorer.exe,-7000"="Hiermee kunt u een pagina openen waarin u zoekopties kunt instellen en met de resultaten van een zoekopdracht kunt werken"
    "@xpsp1res.dll,-11005"="Hiermee kunt u e-mail en nieuwsgroepberichten verzenden en ontvangen"
    "C:\\Program Files\\Outlook Express\\msimn.exe"="Outlook Express"
    "C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe"="AVG Anti-Spyware"
    "C:\\Program Files\\WinRAR\\WinRAR.exe"="WinRAR"
    "C:\\Program Files\\Internet Explorer\\iexplore.exe"="Internet Explorer"
    "C:\\Program Files\\Alcohol Soft\\Alcohol 120\\Alcohol.exe"="Alcohol 120%"
    "C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe"="AVG 7.5 Launcher"
    "@shell32.dll,-31254"="Deze map een andere naam geven"
    "@shell32.dll,-31256"="Deze map verplaatsen"
    "@shell32.dll,-31258"="Deze map kopiëren"
    "@shell32.dll,-31380"="De bestanden in deze map per e-mail verzenden"
    "@shell32.dll,-31262"="Deze map verwijderen"
    "@shell32.dll,-31236"="Een nieuwe map maken"
    "@C:\\WINDOWS\\system32\\notepad.exe,-469"="Tekstdocument"
    "@C:\\WINDOWS\\system32\\shimgvw.dll,-303"="JPEG-afbeelding"
    "C:\\WINDOWS\\system32\\NOTEPAD.EXE"="Kladblok"
    "C:\\Program Files\\Windows NT\\Bureau-accessoires\\WORDPAD.EXE"="Wordpad MFC-toepassing"
    "C:\\WINDOWS\\system32\\shimgvw.dll"="Windows-viewer voor afbeeldingen en faxen"
    "C:\\WINDOWS\\system32\\mspaint.exe"="Paint"
    "C:\\Program Files\\Microsoft Office\\Office\\WINWORD.EXE"="Microsoft Word for Windows"
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqthb08.exe"="HP Image Zone"
    "C:\\PROGRA~1\\MICROS~2\\OFFICE11\\OIS.EXE"="Microsoft Office Picture Manager"
    "@shimgvw.dll,-550"="&Voorbeeld"
    "@shell32.dll,-31234"="Deze taken hebben betrekking op geselecteerde mappen en bestanden"
    "@shell32.dll,-31245"="Hiermee kunt u de geselecteerde items naar een door uzelf te bepalen locatie verplaatsen"
    "C:\\PROGRA~1\\WINZIP\\winzip32.exe"="WinZip Executable"
    "C:\\WINDOWS\\system32\\zipfldr.dll"="Gecomprimeerde mappen"
    "@C:\\WINDOWS\\System32\\msi.dll,-34"="Windows Installer-pakket"
    "C:\\Program Files\\JediSoft\\SOF2Playerz2\\SOF2Playerz.exe"="SOF2Playerz"
    "@shell32.dll,-12691"="Onlangs geopend"
    "C:\\Program Files\\JediSoft\\SOF2Playerz2\\soF2mp_min.exe"="SoF2_mp Minimizer"
    "C:\\Program Files\\Norton SystemWorks\\OBC.exe"="One Button Checkup"
    "@%SystemRoot%\\system32\\xpsp1res.dll,-10078"="Hiermee kunt u standaardprogramma's voor bepaalde activiteiten kiezen, zoals surfen en het verzenden van e-mail, en bepalen welke programma's via het menu Start, het bureaublad en andere locaties toegankelijk zijn"
    "@%SystemRoot%\\system32\\shell32.dll,-22580"="Hiermee krijgt u toegang tot een website waar u de nieuwste updates kunt downloaden om uw computer beter te beveiligen, en apparaatstuurprogramma's en andere software aantreft die Microsoft voor uw Windows-computer beschikbaar heeft gesteld"
    "@%SystemRoot%\\system32\\shell32.dll,-22587"="Hiermee kunt u naar producten zoeken die voor Windows zijn ontworpen"
    "@C:\\Program Files\\Movie Maker\\wmm2res.dll,-63096"="Digitale media op de computer vastleggen en bewerken en de opgeslagen films met anderen delen via e-mail, Internet, opneembare cd's of digitale videobanden."
    "@%SystemRoot%\\system32\\shell32.dll,-22566"="Hiermee kunt u tekeningen maken en bewerken, en gescande foto's weergeven en bewerken"
    "@%SystemRoot%\\system32\\shell32.dll,-22531"="Hiermee kunt u normale wiskundige taken op het scherm uitvoeren"
    "@C:\\WINDOWS\\system32\\sti_ci.dll,-13"="Hiermee kunt u afbeeldingen uit een scanner of digitale camera ophalen"
    "@%SystemRoot%\\system32\\shell32.dll,-22581"="Hiermee kunt u tekstdocumenten met uitgebreide indeling maken en bewerken"
    "@%SystemRoot%\\system32\\shell32.dll,-22543"="Hiermee kunt u via een modem of nulmodemkabel verbinding maken met andere computers, Internet Telnet-sites, bulletinboard-systemen, on line services en host-computers"
    "@%systemroot%\\system32\\netshell.dll,-1201"="Hiermee kunt u verbinding met andere computers, netwerken en het Internet maken"
    "@C:\\WINDOWS\\system32\\mstsc.exe,-4001"="Hiermee kan vanaf andere locaties verbinding met deze computer worden gemaakt en kunnen lokale toepassingen op afstand worden uitgevoerd alsof u lokaal op deze computer werkt"
    "@C:\\WINDOWS\\system32\\xpsp2res.dll,-2305"="Hiermee worden bestanden tussen apparaten of computers met behulp van draadloze Bluetooth-technologie."
    "@%SystemRoot%\\system32\\xpsp2res.dll,-16202"="Draadloos netwerk voor uw huis of klein bedrijf instellen"
    "@%systemroot%\\system32\\hnetwiz.dll,-3086"="Hiermee kunt u een netwerk voor een thuisnetwerk of klein bedrijfsnetwerk instellen."
    "@%systemroot%\\system32\\netshell.dll,-1011"="Hiermee kunt u een nieuwe Internet-verbinding maken, verbinding met een particulier netwerk maken en een thuisnetwerk of klein bedrijfsnetwerk instellen."
    "@%SystemRoot%\\system32\\shell32.dll,-22573"="Hiermee kunt u geluiden opnemen als er een microfoon en geluidskaart zijn geïnstalleerd"
    "@%SystemRoot%\\system32\\shell32.dll,-22578"="Hiermee kunt u het volumeniveau van opgenomen en af te spelen geluiden regelen"
    "@%SystemRoot%\\system32\\shell32.dll,-22530"="Hiermee kunt u gegevens archiveren om deze tegen niet-bedoelde verwijdering te beschermen"
    "@%SystemRoot%\\system32\\xpsp2res.dll,-6104"="Beveiligingsstatus en toegang tot belangrijke instellingen voor het beter beveiligen van uw computer."
    "@%SystemRoot%\\system32\\shell32.dll,-22570"="Hiermee wordt Taakplanner gestart, waarmee u computertaken kunt automatiseren"
    "@%SystemRoot%\\system32\\shell32.dll,-22539"="Hiermee kunt u volumes defragmenteren zodat de computer sneller en efficiënter werkt"
    "@%SystemRoot%\\system32\\shell32.dll,-22538"="Hiermee kunt u onnodige bestanden van deze schijf verwijderen"
    "@%SystemRoot%\\system32\\shell32.dll,-22533"="Hiermee kunt u speciale tekens selecteren en deze naar uw document kopiëren"
    "@%systemroot%\\system32\\restore\\rstrui.exe,-2078"="Hiermee kunt u het systeem naar een bepaald herstelpunt herstellen"
    "@%SystemRoot%\\system32\\shell32.dll,-22575"="Hiermee wordt de huidige systeeminformatie weergegeven"
    "@%SystemRoot%\\system32\\usmt\\migwiz.exe,-203"="Hiermee kunt u bestanden en instellingen van een computer naar een andere computer kopiëren"
    "@%SystemRoot%\\system32\\shell32.dll,-22528"="Hiermee wordt de wizard Toegankelijkheid gestart, waarmee u de computer kunt configureren voor gebruikers met visuele, auditieve en mobiliteitsproblemen"
    "@C:\\Program Files\\MSN Gaming Zone\\Windows\\bckgres.dll,-1213"="Het bordspel Backgammon tegen een ander via het Internet spelen."
    "@C:\\Program Files\\MSN Gaming Zone\\Windows\\chkrres.dll,-1213"="Het bordspel dammen tegen een ander via het Internet spelen."
    "@%SystemRoot%\\system32\\shell32.dll,-22542"="Hiermee wordt Freecell gestart"
    "@C:\\Program Files\\MSN Gaming Zone\\Windows\\hrtzres.dll,-1213"="Speel het kaartspel Hartenjagen tegen andere mensen uit de hele wereld."
    "@%SystemRoot%\\system32\\mshearts.exe,-414"="Hiermee wordt Hartenjagen gestart"
    "@%SystemRoot%\\system32\\shell32.dll,-22557"="Hiermee wordt Mijnenveger gestart"
    "@%SystemRoot%\\system32\\shell32.dll,-22572"="Hiermee wordt Patience gestart"
    "@%SystemRoot%\\system32\\shell32.dll,-22569"="Hiermee wordt 3D Pinball gestart"
    "@C:\\Program Files\\MSN Gaming Zone\\Windows\\rvseres.dll,-1213"="Het bordspel Reversi tegen iemand op het Internet spelen."
    "@C:\\Program Files\\MSN Gaming Zone\\Windows\\shvlres.dll,-1213"="Het kaartspel Spades tegen andere mensen van over de hele wereld spelen."
    "@%SystemRoot%\\system32\\spider.exe,-57"="Hiermee wordt het kaartspel Spider Solitaire gestart."
    "@C:\\WINDOWS\\system32\\comres.dll,-662"="Hiermee worden COM+-toepassingen geconfigureerd en beheerd"
    "@%SystemRoot%\\system32\\shell32.dll,-22535"="Hiermee kunt u schijven beheren en andere hulpprogramma's de mogelijkheid geven om lokale en externe computers te beheren"
    "@%SystemRoot%\\system32\\shell32.dll,-22537"="Hiermee kunt u Open Database Connectivity (ODBC)-gegevensbronnen en -stuurprogramma's toevoegen, verwijderen en configureren"
    "@%SystemRoot%\\system32\\shell32.dll,-22541"="Hiermee kunt u controle- en foutberichten van Windows en andere programma's weergeven"
    "@%SystemRoot%\\system32\\shell32.dll,-22552"="Hiermee kunt u lokaal beveiligingsbeleid, zoals gebruikersrechten en controlebeleid, weergeven en wijzigen"
    "@%SystemRoot%\\system32\\shell32.dll,-22567"="Hiermee kunt u grafieken met systeemprestaties weergeven en gegevenslogboeken en -signalen configureren"
    "@%SystemRoot%\\system32\\shell32.dll,-22571"="Hiermee kunt u services starten en stoppen"
    "@%SystemRoot%\\inf\\unregmp2.exe,-155"="Hiermee kunt u digitale media afspelen zoals muziek, videoclips, cd's, dvd's en Internet-radio."
    "@xpsp1res.dll,-11002"="Hiermee kunt u gegevens en websites op het Internet zoeken en weergeven"
    "@%systemroot%\\system32\\rcbdyctl.dll,-151"="Iemand uitnodigen om een verbinding met uw computer te maken als u hulp nodig hebt bij het oplossen van problemen"
    "@%SystemRoot%\\system32\\shell32.dll,-22529"="Hiermee kunt u uw contactpersonen beheren, en mensen, bedrijven en instellingen zoeken"
    "@%SystemRoot%\\system32\\shell32.dll,-22563"="Hiermee kunt u tekstbestanden met standaardtekstindeling maken en bewerken"
    "@%SystemRoot%\\system32\\shell32.dll,-22534"="Hiermee wordt een venster geopend waarin u tekstfuncties vanaf een opdrachtregel kunt uitvoeren"
    "@%SystemRoot%\\system32\\tourstart.exe,-2"="Hiermee wordt de Rondleiding door Windows XP gestart. Ontdek de geheel nieuwe gebruikerservaring en de vele nieuwe functies en voorzieningen in Windows XP."
    "@%SystemRoot%\\system32\\shell32.dll,-22574"="Hiermee wordt de kopie van bestanden, zoals documenten, kalenders en e-mailberichten, bijgewerkt die off line zijn gebruikt"
    "@%SystemRoot%\\system32\\shell32.dll,-22579"="Hiermee kunt u de bestanden en mappen op deze computer weergeven"
    "@%systemRoot%\\system32\\compatUI.dll,-117"="Hiermee wordt de wizard Programmacompatibiliteit gestart, waarmee u oudere programma's in Windows XP kunt uitvoeren"
    "@%SystemRoot%\\system32\\shell32.dll,-22577"="Hiermee worden hulpprogramma's voor toegankelijkheid vanuit een venster gestart en geconfigureerd"
    "@%SystemRoot%\\system32\\shell32.dll,-22564"="Hiermee kunt u een toetsenbord weergeven dat met een muis of invoerapparaat met schakelaars wordt bestuurd"
    "@%SystemRoot%\\system32\\shell32.dll,-22553"="Hiermee worden geselecteerde tekst en andere schermitems vergroot zodat deze gemakkelijker zijn te lezen en zien"
    "C:\\Documents and Settings\\Karel\\Bureaublad\\shootthemessenger.exe"="Windows Messenger Service Enable/Disable."
    "@C:\\Program Files\\NetMeeting\\conf.exe,-12345"="H.323 Internet-telefonie"
    "@C:\\WINDOWS\\system32\\accwiz.exe,-16"="Instellingen voor de wizard Toegankelijkheid"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9903"="Geluid in aiff-indeling"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9909"="Audio-/videobestand van Windows Media"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9910"="Audio-/video-afspeellijst van Windows Media"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9904"="Geluid in au-indeling"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9905"="Videofragment"
    "@C:\\WINDOWS\\system32\\SHELL32.dll,-22978"="Werkmap"
    "@C:\\WINDOWS\\System32\\ntbackup.exe,-40"="Back-upbestand van Windows"
    "@C:\\WINDOWS\\System32\\pdh.dll,-10023"="Prestatiemeterbestand"
    "@C:\\WINDOWS\\system32\\shimgvw.dll,-304"="Bitmapafbeelding"
    "@C:\\WINDOWS\\System32\\cryptext.dll,-6145"="Beveiligingscatalogus"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9918"="Cd-audionummer"
    "@C:\\WINDOWS\\System32\\cdfview.dll,-4610"="Kanaal-bestand"
    "@C:\\WINDOWS\\System32\\cryptext.dll,-6108"="Beveiligingscertificaat"
    "@C:\\Program Files\\NetMeeting\\conf.exe,-12346"="Snelkeuze"
    "@C:\\WINDOWS\\System32\\cryptext.dll,-6110"="Certificaatintrekkingslijst"
    "@C:\\WINDOWS\\system32\\netshell.dll,-1300"="Inbelnetwerkbestand"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9927"="TV-programma dat door Microsoft is opgenomen"
    "@C:\\WINDOWS\\system32\\shimgvw.dll,-301"="EMF-afbeelding"
    "@C:\\WINDOWS\\system32\\shimgvw.dll,-302"="GIF-afbeelding"
    "@C:\\Program Files\\NetMeeting\\conf.exe,-12347"="Compatibel met Intel IPhone"
    "@C:\\WINDOWS\\System32\\setupapi.dll,-2000"="Setup-gegevens"
    "@C:\\Program Files\\Internet Explorer\\Connection Wizard\\icwres.dll,-20003"="Instellingen voor Internet-communicatie"
    "@C:\\WINDOWS\\System32\\wshext.dll,-4804"="JScript Script File"
    "@C:\\WINDOWS\\System32\\wshext.dll,-4805"="JScript Encoded Script File"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9902"="Filmfragment"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9926"="M3u-bestand"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9907"="Midi-sequentie"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9925"="Geluid met mp3-indeling"
    "@C:\\WINDOWS\\system32\\mmcbase.dll,-130"="Microsoft Common Console-document"
    "@C:\\WINDOWS\\System32\\msi.dll,-35"="Windows Installer-patch"
    "@C:\\WINDOWS\\System32\\RCBdyctl.dll,-150"="Incident van Microsoft Hulp op afstand"
    "@C:\\Program Files\\Movie Maker\\wmm2res.dll,-63097"="Windows Movie Maker-project"
    "@C:\\Program Files\\NetMeeting\\nmwb.dll,-1234"="Microsoft Netmeeting T126-compatibel Whiteboard-document"
    "@C:\\WINDOWS\\System32\\cryptext.dll,-6111"="PKCS nr. 7-certificaten"
    "@C:\\WINDOWS\\System32\\cryptext.dll,-6113"="PKCS nr. 7-handtekening"
    "@C:\\WINDOWS\\system32\\shimgvw.dll,-305"="PNG-afbeelding"
    "@C:\\WINDOWS\\System32\\scrobj.dll,-8192"="Windows Script Component"
    "@C:\\WINDOWS\\system32\\shscrap.dll,-258"="Scrab-object"
    "@C:\\WINDOWS\\System32\\cryptext.dll,-6112"="Microsoft-archief met van serienummer voorziene certificaten"
    "@C:\\WINDOWS\\System32\\cryptext.dll,-6109"="Certificaatvertrouwenslijst"
    "@C:\\WINDOWS\\System32\\wshext.dll,-4803"="VBScript Encoded Script File"
    "@C:\\WINDOWS\\System32\\wshext.dll,-4802"="VBScript Script File"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9908"="Wave-geluid"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9911"="Snelkoppeling naar Windows Media-geluid"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9912"="Windows Media-geluidsbestand"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9920"="Windows Media Player-downloadpakket"
    "@C:\\WINDOWS\\system32\\shimgvw.dll,-307"="WMF-afbeelding"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9915"="Windows Media Player-weergavebestand"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9914"="Audio-/videobestand van Windows Media"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9916"="Windows Media Player-weergavepakket"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9923"="Windows Media-afspeellijst"
    "@\"C:\\Program Files\\Windows NT\\Bureau-accessoires\\WORDPAD.EXE\",-208"="Write-document"
    "@C:\\WINDOWS\\System32\\wshext.dll,-4801"="Windows Script File"
    "@C:\\WINDOWS\\System32\\wshext.dll,-4800"="Windows Script Host Settings File"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9913"="Audio-/video-afspeellijst van Windows Media"
    "@C:\\WINDOWS\\system32\\msxml3r.dll,-1"="XML-document"
    "@C:\\WINDOWS\\system32\\msxml3r.dll,-2"="XSL-opmaakmodel"
    "@explorer.exe,-7004"="Hiermee wordt de browser gestart, zodat u op het Internet kunt surfen"
    "@shell32.dll,-12704"="Ei&genschappen voor het Internet"
    "@shell32.dll,-12705"="Op het &Internet surfen"
    "C:\\Program Files\\Microsoft Office\\Office\\EXCEL.EXE"="Microsoft Excel for Windows"
    "C:\\Program Files\\Microsoft Office\\OFFICE11\\MSPUB.EXE"="Microsoft Office Publisher"
    "@shell32.dll,-31275"="Hier wordt informatie over het geselecteerde bestand of de geselecteerde map weergeven, zoals de naam, en de grootte en het type van de map of het bestand"
    "C:\\Program Files\\Ahead\\Nero StartSmart\\NeroStartSmart.exe"="Nero StartSmart"
    "C:\\Program Files\\Ahead\\nero\\nero.exe"="Nero Burning ROM"
    "@shell32.dll,-31232"="Systeemtaken"
    "@shell32.dll,-31294"="Systeeminformatie weergeven"
    "@shell32.dll,-31327"="Programma's installeren of verwijderen"
    "@shell32.dll,-31312"="Een instelling wijzigen"
    "@C:\\WINDOWS\\system32\\SHELL32.dll,-22913"="Hiermee kunt u stations op lokale vaste schijven en andere op deze computer aangesloten apparaten weergeven"
    "@C:\\WINDOWS\\system32\\SHELL32.dll,-22912"="Hiermee kan toegang worden gezocht tot websites, andere computers en FTP-sites"
    "@C:\\WINDOWS\\system32\\SHELL32.dll,-12695"="Hierin bevinden zich bestanden en mappen die door de gebruikers van deze computer zijn gedeeld"
    "@C:\\WINDOWS\\system32\\SHELL32.dll,-22914"="Dit is de locatie waar u brieven, rapporten, documenten en andere bestanden kunt opslaan"
    "@shell32.dll,-31273"="Hiermee kunt u via snelkoppelingen snel toegang tot nuttige locaties zoeken"
    "@shell32.dll,-31375"="Hiermee wordt de geselecteerde map beschikbaar gesteld aan computers in het netwerk, zodat anderen deze kunnen bekijken"
    "@shell32.dll,-31249"="Hiermee wordt een kopie van de geselecteerde bestanden naar een openbare webpagina verplaatst, zodat de bestanden voor anderen toegankelijk zijn"
    "C:\\Program Files\\Spybot - Search & Destroy\\SpybotSD.exe"="Spybot - Search & Destroy"
    "C:\\WINDOWS\\system32\\taskmgr.exe"="Windows Taakbeheer"
    "C:\\Program Files\\Common Files\\Symantec Shared\\Nmain.exe"="Symantec Integrator"
    "C:\\Program Files\\Norton SystemWorks\\Norton Utilities\\Speed Disk\\SDNTC.EXE"="SDNTC"
    "@explorer.exe,-7003"="Hiermee kunt u een programma starten, map openen of een website bezoeken"
    "@shell32.dll,-12710"="&Uitvoeren"
    "C:\\WINDOWS\\regedit.exe"="Register-editor"
    "@shell32.dll,-31283"="Afbeeldingstaken"
    "@shell32.dll,-31287"="Als diavoorstelling weergeven"
    "@shell32.dll,-31313"="On line afdrukken bestellen"
    "@shell32.dll,-31391"="Afbeeldingen afdrukken"
    "@shell32.dll,-31314"="Hiermee wordt de wizard On line afdrukken bestellen gestart, waarmee u een order kunt plaatsen voor afdrukken van foto's die u met een digitale camera hebt gemaakt"
    "@shell32.dll,-31288"="Hiermee kunt u alle afbeeldingen of foto's in deze map in de vorm van een diavoorstelling weergeven"
    "@shell32.dll,-31285"="Afbeeldingen bij een camera of scanner ophalen"
    "@shell32.dll,-31396"="Videotaken"
    "@shell32.dll,-31278"="Alles afspelen"
    "@shell32.dll,-31397"="Deze taken zijn van toepassing op de videobestanden en mappen die u selecteert."
    "C:\\Program Files\\Windows Media Player\\wmplayer.exe"="Windows Media Player"
    "C:\\Program Files\\DivX\\DivX Player\\DivX Player.exe"="DivX Player"
    "C:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"="PowerDVD"
    "C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avginet.exe"="AVG Update downloader"
    "@shell32.dll,-12708"="&Zoeken"
    "@shell32.dll,-31366"="Resultaattaken"
    "@C:\\WINDOWS\\system32\\SHELL32.dll,-30520"="Zoekresultaten"
    "@C:\\WINDOWS\\system32\\main.cpl,-2000"="Bewegende aanwijzer"
    "@C:\\Program Files\\Common Files\\System\\Ole DB\\msdasqlr.dll,-2323"="Naam van gegevensbron"
    "@C:\\WINDOWS\\System32\\icmui.dll,-45"="ICC-profiel"
    "@C:\\WINDOWS\\System32\\cryptext.dll,-6148"="Personal Information Exchange"
    "@C:\\WINDOWS\\system32\\mstsc.exe,-4004"="Verbinding met extern bureaublad"
    "@C:\\WINDOWS\\inf\\unregmp2.exe,-9924"="Windows Mediabibliotheek"
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgalry.exe"=" "
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="HP CUE-Scanning Flow Component"
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="hpqscnvw"
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqimvac.exe"=" "
    "@Shell32.dll,-12689"="Dit is de locatie waar u muziek en andere audiobestanden kunt opslaan"
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqdstcp.exe"="Destination Component"
    "@C:\\WINDOWS\\system32\\SHELL32.dll,-12696"="Hiermee kunt u geïnstalleerde printers en faxprinters weergeven en nieuwe printers en faxprinters toevoegen"
    "C:\\Program Files\\Skype\\Phone\\Skype.exe"="Skype. The whole world can talk for free."
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="Messenger"
    "@shell32.dll,-12706"="&E-mail lezen"
    "C:\\Program Files\\CCleaner\\ccleaner.exe"="CCleaner"
    "C:\\Program Files\\SpywareBlaster\\spywareblaster.exe"="SpywareBlaster"
    "C:\\Program Files\\coolpro2\\coolpro2.exe"="Cool Edit Pro"
    "@shell32.dll,-31243"="Hiermee kunt u dit bestand of deze map een door uzelf te typen naam geven"
    "@shell32.dll,-31279"="Selectie afspelen"
    "@shell32.dll,-31247"="Hiermee kunt u de geselecteerde items naar een door uzelf te bepalen locatie kopiëren"
    "C:\\Program Files\\Windows Media Player\\setup_wm.exe"="Hulpprogramma voor de configuratie van Microsoft Windows Media"
    "@shell32.dll,-31368"="De map openen waarin zich dit onderdeel bevindt"
    "C:\\Program Files\\Grisoft\\AVG Free\\avgw.exe"="AVG 7.5 Launcher"
    "C:\\Program Files\\Grisoft\\AVG Free\\avgwb.dat"="AVG Basic Interface"
    "C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"="AVG Update downloader"
    "C:\\Program Files\\Grisoft\\AVG Free\\avgscan.exe"="AVG Command-line Scanning Utility"
    "C:\\WINDOWS\\system32\\shell32.dll"="Gemeenschappelijk DLL-bestand van Windows Shell"
    "@C:\\WINDOWS\\system32\\SHELL32.dll,-8503"="&Zoeken..."
    "@C:\\WINDOWS\\system32\\mycomput.dll,-400"="&Beheren"
    "@shell32.dll,-31317"="Systeemtaken"
    "@shell32.dll,-31321"="De inhoud van dit station verbergen"
    "@shell32.dll,-31292"="Bestanden of mappen zoeken"
    "@shell32.dll,-31325"="De inhoud van deze map verbergen"
    "@shell32.dll,-31371"="Hiermee wordt een e-mail met een kopie van de geselecteerde bestanden of de bestanden van een geselecteerde map verzonden"
    "@shell32.dll,-31237"="Hiermee wordt een nieuwe, lege map in de door u geopende map gemaakt"
    "@shell32.dll,-31390"="Deze afbeelding afdrukken"
    "@shell32.dll,-31289"="Als bureaubladachtergrond gebruiken"
    "@shell32.dll,-31315"="De geselecteerde foto's of afbeeldingen afdrukken"
    "C:\\WINDOWS\\system32\\wuauclt.exe"="Automatische updates"
    "C:\\Documents and Settings\\Karel\\Bureaublad\\SOF2Playerz071UpdateOnly\\SOF2Playerz071UpdateOnly.exe"="SOF2Playerz071UpdateOnly"
    "@C:\\WINDOWS\\system32\\SHELL32.dll,-22915"="Hierin worden verwijderde mappen en bestanden opgeslagen totdat u deze definitief van de computer verwijdert"
    "C:\\Program Files\\Elaborate Bytes\\CloneDVD2\\CloneDVD2.exe"="CloneDVD Application"
    "@shell32.dll,-12590"="Bestanden die klaar zijn om op cd te worden gezet"
    "@wmploc.dll,-6504"="Dvd afspelen"
    "@wmploc.dll,-6502"="Windows Media Player"
    "@%SystemRoot%\\system32\\SHELL32.dll,-17154"="Map openen en bestanden weergeven"
    "@%SystemRoot%\\system32\\SHELL32.dll,-17155"="Windows Verkenner"
    "@%SystemRoot%\\system32\\SHELL32.dll,-17168"="Geen actie ondernemen"
    "C:\\Documents and Settings\\Karel\\Bureaublad\\SoF2mp_min\\SoF2mp_min.exe"="SoF2_mp Minimizer"
    "@shell32.dll,-21782"="Programma's"
    "@themeui.dll,-2037"="{Tahoma, 8 pt}"
    "@themeui.dll,-2038"="{Tahoma, 8 pt}"
    "@themeui.dll,-2039"="{Tahoma, 8 pt}"
    "@themeui.dll,-2040"="{Tahoma, 8 pt}"
    "@themeui.dll,-2041"="{Tahoma, 8 pt}"
    "@themeui.dll,-2042"="{Tahoma, 8 pt}"
    "@themeui.dll,-2017"="Windows XP"
    "@themeui.dll,-2016"="Windows-klassiek"
    "@themeui.dll,-2015"="Meer thema's on line..."
    "C:\\Program Files\\Deskshare\\My Screen Recorder Pro\\My Screen Recorder Pro.exe"="My Screen Recorder Pro"
    "C:\\WINDOWS\\system32\\sstext3d.scr"="Direct3D-schermbeveiliging 3D Tekst"
    "C:\\Documents and Settings\\Karel\\Bureaublad\\sof2minimizer\\SoF2 Minimizer.exe"="SoF2 Minimizer"

    here it is thanks!!!!
     

Share This Page