I think i did it properly (read/execute permissions, it still does not work, just in case can somebody give me the precedure anyways?
Main Topics
Browse All TopicsI have a an exe. file that won't open normal mode, but will open in safe mode. In normal mode i get this error "Windows cannot access the specified device, path, or file. You may not have the appropriate permission to access the item."
I already followed instructions on how to take ownership, still won't open in normal mode.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
If you right-click on the .exe file, select Properties -> Security
you should see your name in the "Users and Groups" box, and when you click on your name to highlight it, in the lower part of the window you should see that the various permissions that are highlighted. If your name is not there then click on "Add" and add it.
Another possibility is that the executable might need some dll that is missing. Does the error message mention anything like that, e.g. in the title bar of the error message window?
Ok as per your instructions it is set, and no, the file may need some dll file but the the complete error message is as follows "Windows cannot access the specified device, path, or file. You may not have the appropriate permission to access the item."
Be advised it works perfect in safe mode, and on my other machine perfectly all together. Thank you for quick response!
use this command in dos mode ..to get access and change permissions of any file
CACLS "path to file" /T /P Administrators:F
Also read this link ..you'll understand how to use the above command accordingly
http://www.netadmintools.c
what it says when u try to do system restore??...have you tried system restore by start ->run->msconfig -> launch system restore
Did u install any software before this problem occured ??..
It's possible this problem can happen with any program attempting to load twice. Microsoft recognizes this problem as well
http://support.microsoft.c
check this out ..this guy got the similar problem (go to the end of the page)...
http://www.computing.net/w
hope this helps
"the fact that it works in safe mode, does that exclude a registry problem?"
That is a hard one to answer since I don't know what the root cause of the problem is. In general terms, safe mode means that the system leaves out non-essential drivers, services, startups etc. Any one of those extra items could be causing a problem. But, the information about what to start in normal mode is also saved in the Registry itself, so a problem with the Registry could in principle cause the problem.
So the short answer is, most likely the Registry is not to blame, but it can't be ruled out.
That last link by sundeepgopal is very interesting. I had never heard of something like that causing this problem, so please do check if that applies here.
A quick way to see what is starting from the Registry is with Autoruns:
(1) Download Autoruns from: http://www.sysinternals.co
(2) Run the program. It lists a bunch of things that start when Windows starts.
(3) From the menu bar, select Options, and uncheck "Include Empty Locations" and "check" "Hide Microsoft Entries"
then click on the Refresh icon.
(4) This will give you a shorter, more meaningful list.
(5) Examine that list and disable anything suspicious by un-checking it. Then reboot and see if it helped.
(6) If not, or if not sure, you can use the File -> Save as.. option in Autoruns to save the list to a text file and then copy and paste it here.
Autorun results, i have no idea what this stuff is, please help.
HKLM\System\CurrentControl
+ rdpclip RDP Clip Monitor Microsoft Corporation c:\windows\system32\rdpcli
HKLM\SOFTWARE\Microsoft\Wi
+ C:\WINDOWS\system32\userin
HKLM\SOFTWARE\Microsoft\Wi
+ Explorer.exe Windows Explorer Microsoft Corporation c:\windows\explorer.exe
HKLM\SOFTWARE\Classes\Prot
+ application/octet-stream Microsoft .NET Runtime Execution Engine Microsoft Corporation c:\windows\system32\mscore
+ application/x-complus Microsoft .NET Runtime Execution Engine Microsoft Corporation c:\windows\system32\mscore
+ application/x-msdownload Microsoft .NET Runtime Execution Engine Microsoft Corporation c:\windows\system32\mscore
+ Class Install Handler OLE32 Extensions for Win32 Microsoft Corporation c:\windows\system32\urlmon
+ deflate OLE32 Extensions for Win32 Microsoft Corporation c:\windows\system32\urlmon
+ gzip OLE32 Extensions for Win32 Microsoft Corporation c:\windows\system32\urlmon
+ lzdhtml OLE32 Extensions for Win32 Microsoft Corporation c:\windows\system32\urlmon
+ text/webviewhtml Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell3
HKLM\SOFTWARE\Classes\Prot
+ about Microsoft (R) HTML Viewer Microsoft Corporation c:\windows\system32\mshtml
+ cdl OLE32 Extensions for Win32 Microsoft Corporation c:\windows\system32\urlmon
+ dvd ActiveX control for streaming video Microsoft Corporation c:\windows\system32\msvidc
+ file OLE32 Extensions for Win32 Microsoft Corporation c:\windows\system32\urlmon
+ ftp OLE32 Extensions for Win32 Microsoft Corporation c:\windows\system32\urlmon
+ gopher OLE32 Extensions for Win32 Microsoft Corporation c:\windows\system32\urlmon
+ http OLE32 Extensions for Win32 Microsoft Corporation c:\windows\system32\urlmon
+ https OLE32 Extensions for Win32 Microsoft Corporation c:\windows\system32\urlmon
+ its Microsoft® InfoTech Storage System Library Microsoft Corporation c:\windows\system32\itss.d
+ javascript Microsoft (R) HTML Viewer Microsoft Corporation c:\windows\system32\mshtml
+ local OLE32 Extensions for Win32 Microsoft Corporation c:\windows\system32\urlmon
+ mailto Microsoft (R) HTML Viewer Microsoft Corporation c:\windows\system32\mshtml
+ mhtml Microsoft Internet Messaging API Microsoft Corporation c:\windows\system32\inetco
+ mk OLE32 Extensions for Win32 Microsoft Corporation c:\windows\system32\urlmon
+ ms-its Microsoft® InfoTech Storage System Library Microsoft Corporation c:\windows\system32\itss.d
+ res Microsoft (R) HTML Viewer Microsoft Corporation c:\windows\system32\mshtml
+ sysimage Microsoft (R) HTML Viewer Microsoft Corporation c:\windows\system32\mshtml
+ tv ActiveX control for streaming video Microsoft Corporation c:\windows\system32\msvidc
+ vbscript Microsoft (R) HTML Viewer Microsoft Corporation c:\windows\system32\mshtml
+ wia WIA Scripting Layer Microsoft Corporation c:\windows\system32\wiascr
HKLM\SOFTWARE\Microsoft\Ac
+ Address Book 6 Outlook Express Setup Library Microsoft Corporation c:\program files\outlook express\setup50.exe
+ Browser Customizations Microsoft Internet Explorer Customization DLL Microsoft Corporation c:\windows\system32\iedkcs
+ Internet Explorer Windows NT User Data Migration Tool Microsoft Corporation c:\windows\system32\shmgra
+ Internet Explorer Windows Setup API Microsoft Corporation c:\windows\system32\setupa
+ Internet Explorer 6 IE 5.0 Per-User Install Utility Microsoft Corporation c:\windows\system32\ie4uin
+ Microsoft Outlook Express 6 Outlook Express Setup Library Microsoft Corporation c:\program files\outlook express\setup50.exe
+ Microsoft Windows Media Player ADVPACK Microsoft Corporation c:\windows\system32\advpac
+ NetMeeting 3.01 ADVPACK Microsoft Corporation c:\windows\system32\advpac
+ Outlook Express Windows NT User Data Migration Tool Microsoft Corporation c:\windows\system32\shmgra
+ Themes Setup Microsoft(C) Register Server Microsoft Corporation c:\windows\system32\regsvr
+ Windows Desktop Update Microsoft(C) Register Server Microsoft Corporation c:\windows\system32\regsvr
+ Windows Media Player Microsoft Windows Media Player Setup Utility Microsoft Corporation c:\windows\inf\unregmp2.ex
+ Windows Messenger 4.7 ADVPACK Microsoft Corporation c:\windows\system32\advpac
HKLM\SOFTWARE\Microsoft\Wi
+ Browseui preloader Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
+ Component Categories cache daemon Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
HKLM\SOFTWARE\Microsoft\Wi
+ CDBurn Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell3
+ PostBootReminder Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell3
+ SysTray Systray shell service object Microsoft Corporation c:\windows\system32\stobje
+ WebCheck Web Site Monitor Microsoft Corporation c:\windows\system32\webche
HKLM\Software\Microsoft\Wi
+ shell32.dll Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell3
HKLM\Software\Microsoft\Wi
+ %DESC_PublishDropTarget% Photo Printing Wizard Microsoft Corporation c:\windows\system32\photow
+ &Address Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
+ .CAB file viewer Cabinet File Viewer Shell Extension Microsoft Corporation c:\windows\system32\cabvie
+ Accessible Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
+ ActiveX Cache Folder Object Control Viewer Microsoft Corporation c:\windows\system32\occach
+ Address Bar Parser Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
+ Address EditBox Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
+ Administrative Tools Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocv
+ America Online AOL Shell Extension America Online, Inc. c:\program files\common files\aolshare\shell\us\sh
+ AOL Broadband AOL Shell Extension America Online, Inc. c:\program files\common files\aolshare\shell\shell
+ Audio Media Properties Handler Media File Property Extractor Shell Extension Microsoft Corporation c:\windows\system32\shmedi
+ Augmented Shell Folder Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
+ Augmented Shell Folder 2 Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
+ Auto Update Property Sheet Extension Automatic Updates Control Panel Microsoft Corporation c:\windows\system32\wuaucp
+ AVG7 Find Extension AVG Shell Extension GRISOFT, s.r.o. c:\program files\grisoft\avg free\avgse.dll
+ AVG7 Shell Extension AVG Shell Extension GRISOFT, s.r.o. c:\program files\grisoft\avg free\avgse.dll
+ Avi Properties Handler Media File Property Extractor Shell Extension Microsoft Corporation c:\windows\system32\shmedi
+ BandProxy Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
+ Briefcase Windows Briefcase Microsoft Corporation c:\windows\system32\syncui
+ CD Copy Shell Extension IDisc Shellextension Pinnacle Systems, Inc. c:\windows\system32\shelle
+ CD Wizard Shell Extension IDisc Shellextension Pinnacle Systems, Inc. c:\windows\system32\shelle
+ CDF Extension Copy Hook Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocv
+ Channel File Channel Definition File Viewer Microsoft Corporation c:\windows\system32\cdfvie
+ Channel Handler Object Channel Definition File Viewer Microsoft Corporation c:\windows\system32\cdfvie
+ Channel Menu Channel Definition File Viewer Microsoft Corporation c:\windows\system32\cdfvie
+ Channel Properties Channel Definition File Viewer Microsoft Corporation c:\windows\system32\cdfvie
+ Channel Shortcut Channel Definition File Viewer Microsoft Corporation c:\windows\system32\cdfvie
+ Code Download Agent Web Site Monitor Microsoft Corporation c:\windows\system32\webche
+ Compatibility Page Compatibility Tab Shell Extension DLL Microsoft Corporation c:\windows\system32\slayer
+ Compressed (zipped) Folder Compressed (zipped) Folders Microsoft Corporation c:\windows\system32\zipfld
+ Compressed (zipped) Folder Right Drag Handler Compressed (zipped) Folders Microsoft Corporation c:\windows\system32\zipfld
+ Compressed (zipped) Folder SendTo Target Compressed (zipped) Folders Microsoft Corporation c:\windows\system32\zipfld
+ ConnectionAgent Web Site Monitor Microsoft Corporation c:\windows\system32\webche
+ Crypto PKO Extension Crypto Shell Extensions Microsoft Corporation c:\windows\system32\crypte
+ Crypto Sign Extension Crypto Shell Extensions Microsoft Corporation c:\windows\system32\crypte
+ Custom MRU AutoCompleted List Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
+ Darwin App Publisher Shell Application Manager Microsoft Corporation c:\windows\system32\appwiz
+ DfsShell Distributed File System shell extension Microsoft Corporation c:\windows\system32\dfsshl
+ Directory Context Menu Verbs Directory Service Common UI Microsoft Corporation c:\windows\system32\dsuiex
+ Directory Object Find Directory Service Find Microsoft Corporation c:\windows\system32\dsquer
+ Directory Property UI Directory Service Common UI Microsoft Corporation c:\windows\system32\dsuiex
+ Directory Query UI Directory Service Find Microsoft Corporation c:\windows\system32\dsquer
+ Directory Start/Search Find Directory Service Find Microsoft Corporation c:\windows\system32\dsquer
+ Disk Copy Extension Windows DiskCopy Microsoft Corporation c:\windows\system32\diskco
+ Disk Quota UI Windows Shell Disk Quota UI DLL Microsoft Corporation c:\windows\system32\dskquo
+ Display Adapter CPL Extension Advanced display adapter properties Microsoft Corporation c:\windows\system32\deskad
+ Display Monitor CPL Extension Advanced display monitor properties Microsoft Corporation c:\windows\system32\deskmo
+ Display TroubleShoot CPL Extension Advanced display performance properties Microsoft Corporation c:\windows\system32\deskpe
+ Download Status Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
+ DS Security Page Directory Service Security UI Microsoft Corporation c:\windows\system32\dssec.
+ E-mail Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocv
+ Explorer Band Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocv
+ Extensions Manager Folder Extensions Manager Microsoft Corporation c:\windows\system32\extmgr
+ Favorites Band Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocv
+ Fonts Windows Font Folder Microsoft Corporation c:\windows\system32\fontex
+ Fonts Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocv
+ For &People... Find People Microsoft Corporation c:\program files\outlook express\wabfind.dll
+ FTP Folders Webview Microsoft Internet Explorer FTP Folder Shell Extension Microsoft Corporation c:\windows\system32\msieft
+ Fusion Cache Microsoft .NET Runtime Execution Engine Microsoft Corporation c:\windows\system32\mscore
+ GDI+ file thumbnail extractor Windows Picture and Fax Viewer Microsoft Corporation c:\windows\system32\shimgv
+ Get a Passport Wizard Map Network Drives/Network Places Wizard Microsoft Corporation c:\windows\system32\netplw
+ Global Folder Settings Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
+ Help and Support Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocv
+ Help and Support Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocv
+ History Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocv
+ HTML Thumbnail Extractor Windows Picture and Fax Viewer Microsoft Corporation c:\windows\system32\shimgv
+ HyperTerminal Icon Ext HyperTerminal Applet Library Hilgraeve, Inc. c:\windows\system32\hticon
+ ICC Profile Microsoft Color Matching System User Interface DLL Microsoft Corporation c:\windows\system32\icmui.
+ ICM Monitor Management Microsoft Color Matching System User Interface DLL Microsoft Corporation c:\windows\system32\icmui.
+ ICM Printer Management Microsoft Color Matching System User Interface DLL Microsoft Corporation c:\windows\system32\icmui.
+ ICM Scanner Management Microsoft Color Matching System User Interface DLL Microsoft Corporation c:\windows\system32\icmui.
+ IE4 Suite Splash Screen Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocv
+ In-pane search Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
+ Installed Apps Enumerator Shell Application Manager Microsoft Corporation c:\windows\system32\appwiz
+ InstantWrite Shellextension InstantWrite Shellextension VOB Computersysteme GmbH c:\windows\system32\shelle
+ Internet Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocv
+ Internet Name Space Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocv
+ InternetShortcut Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocv
+ ISFBand OC Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocv
+ Microsoft Agent Character Property Sheet Handler Microsoft Agent Property Sheet Handler Microsoft Corporation c:\windows\msagent\agentps
+ Microsoft AutoComplete Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
+ Microsoft Browser Architecture Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocv
+ Microsoft BrowserBand Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
+ Microsoft Data Link Microsoft Data Access - OLE DB Core Services Microsoft Corporation c:\program files\common files\system\ole db\oledb32.dll
+ Microsoft DocProp Inplace Calendar Control Microsoft DocProp Shell Ext Microsoft Corporation c:\windows\system32\docpro
+ Microsoft DocProp Inplace Droplist Combo Control Microsoft DocProp Shell Ext Microsoft Corporation c:\windows\system32\docpro
+ Microsoft DocProp Inplace Edit Box Control Microsoft DocProp Shell Ext Microsoft Corporation c:\windows\system32\docpro
+ Microsoft DocProp Inplace ML Edit Box Control Microsoft DocProp Shell Ext Microsoft Corporation c:\windows\system32\docpro
+ Microsoft DocProp Inplace Time Control Microsoft DocProp Shell Ext Microsoft Corporation c:\windows\system32\docpro
+ Microsoft DocProp Shell Ext Microsoft DocProp Shell Ext Microsoft Corporation c:\windows\system32\docpro
+ Microsoft History AutoComplete List Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
+ Microsoft Internet Toolbar Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
+ Microsoft Multiple AutoComplete List Container Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
+ Microsoft Shell Folder AutoComplete List Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
+ Microsoft Url History Service Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocv
+ Microsoft Url Search Hook Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocv
+ Midi Properties Handler Media File Property Extractor Shell Extension Microsoft Corporation c:\windows\system32\shmedi
+ MMC Icon Handler MMC Shell Extension DLL Microsoft Corporation c:\windows\system32\mmcshe
+ MRU AutoComplete List Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
+ Multimedia File Property Sheet Control Panel Drivers Applet Microsoft Corporation c:\windows\system32\mmsys.
+ MyDocs Copy Hook My Documents Folder UI Microsoft Corporation c:\windows\system32\mydocs
+ MyDocs Drop Target My Documents Folder UI Microsoft Corporation c:\windows\system32\mydocs
+ MyDocs Properties My Documents Folder UI Microsoft Corporation c:\windows\system32\mydocs
+ Network Connections Network Connections Shell Microsoft Corporation c:\windows\system32\netshe
+ Network Connections Network Connections Shell Microsoft Corporation c:\windows\system32\netshe
+ NTFS Security Page Security Shell Extension Microsoft Corporation c:\windows\system32\rshx32
+ Offline Files Folder Client Side Caching UI Microsoft Corporation c:\windows\system32\cscui.
+ Offline Files Folder Options Client Side Caching UI Microsoft Corporation c:\windows\system32\cscui.
+ Offline Files Menu Client Side Caching UI Microsoft Corporation c:\windows\system32\cscui.
+ OLE Docfile Property Page OLE DocFile Property Page Microsoft Corporation c:\windows\system32\docpro
+ PlusPack CPL Extension Windows Theme API Microsoft Corporation c:\windows\system32\themeu
+ PostAgent Web Site Monitor Microsoft Corporation c:\windows\system32\webche
+ Previous Versions Previous Versions property page Microsoft Corporation c:\windows\system32\twext.
+ Previous Versions Property Page Previous Versions property page Microsoft Corporation c:\windows\system32\twext.
+ Print Ordering via the Web Map Network Drives/Network Places Wizard Microsoft Corporation c:\windows\system32\netplw
+ Printers Security Page Security Shell Extension Microsoft Corporation c:\windows\system32\rshx32
+ Registry Tree Options Utility Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
+ Remote Sessions CPL Extension Remote Sessions CPL Extension Microsoft Corporation c:\windows\system32\remote
+ Run... Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocv
+ Scanners & Cameras Imaging Devices Shell Folder UI Microsoft Corporation c:\windows\system32\wiashe
+ Scanners & Cameras Imaging Devices Shell Folder UI Microsoft Corporation c:\windows\system32\wiashe
+ Scanners & Cameras Imaging Devices Shell Folder UI Microsoft Corporation c:\windows\system32\wiashe
+ Scanners & Cameras Imaging Devices Shell Folder UI Microsoft Corporation c:\windows\system32\wiashe
+ Scanners & Cameras Imaging Devices Shell Folder UI Microsoft Corporation c:\windows\system32\wiashe
+ Scheduled Tasks Task Scheduler interface DLL Microsoft Corporation c:\windows\system32\mstask
+ Search Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocv
+ Search Assistant OC Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocv
+ Search Band Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
+ Sendmail service Send Mail Microsoft Corporation c:\windows\system32\sendma
+ Sendmail service Send Mail Microsoft Corporation c:\windows\system32\sendma
+ Set Program Access and Defaults Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocv
+ Shell Application Manager Shell Application Manager Microsoft Corporation c:\windows\system32\appwiz
+ Shell Automation Inproc Service Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocv
+ Shell Band Site Menu Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
+ Shell DeskBar Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
+ Shell DeskBarApp Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
+ Shell DocObject Viewer Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocv
+ Shell extensions for Microsoft Windows Network objects Network object shell UI Microsoft Corporation c:\windows\system32\ntlanu
+ Shell Extensions for RealOne Player RealPlayer Shell Extensions RealNetworks, Inc. c:\program files\real\realplayer\rpsh
+ Shell extensions for sharing Shell extensions for sharing Microsoft Corporation c:\windows\system32\ntshru
+ Shell extensions for sharing Shell extensions for sharing Microsoft Corporation c:\windows\system32\ntshru
+ Shell extensions for Windows Script Host Microsoft (r) Shell Extension for Windows Script Host Microsoft Corporation c:\windows\system32\wshext
+ Shell Image Data Factory Windows Picture and Fax Viewer Microsoft Corporation c:\windows\system32\shimgv
+ Shell Image Property Handler Windows Picture and Fax Viewer Microsoft Corporation c:\windows\system32\shimgv
+ Shell Image Verbs Windows Picture and Fax Viewer Microsoft Corporation c:\windows\system32\shimgv
+ Shell properties for a DS object Directory Service Find Microsoft Corporation c:\windows\system32\dsquer
+ Shell Publishing Wizard Object Map Network Drives/Network Places Wizard Microsoft Corporation c:\windows\system32\netplw
+ Shell Rebar BandSite Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
+ Shell Scrap DataHandler Shell scrap object handler Microsoft Corporation c:\windows\system32\shscra
+ Subscription Folder Web Site Monitor Microsoft Corporation c:\windows\system32\webche
+ Subscription Mgr Web Site Monitor Microsoft Corporation c:\windows\system32\webche
+ Summary Info Thumbnail handler (DOCFILES) Windows Picture and Fax Viewer Microsoft Corporation c:\windows\system32\shimgv
+ Taskbar and Start Menu Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell3
+ Tasks Folder Icon Handler Task Scheduler interface DLL Microsoft Corporation c:\windows\system32\mstask
+ Tasks Folder Shell Extension Task Scheduler interface DLL Microsoft Corporation c:\windows\system32\mstask
+ Temporary Internet Files Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocv
+ Temporary Internet Files Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocv
+ The Internet Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocv
+ Track Popup Bar Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
+ TrayAgent Web Site Monitor Microsoft Corporation c:\windows\system32\webche
+ TridentImageExtractor Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
+ Trojan Remover Shell Extension Trojan Remover Shell Extension Simply Super Software c:\program files\trojan remover\trshlex.dll
+ User Accounts Map Network Drives/Network Places Wizard Microsoft Corporation c:\windows\system32\netplw
+ User Assist Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
+ Video Media Properties Handler Media File Property Extractor Shell Extension Microsoft Corporation c:\windows\system32\shmedi
+ Video Thumbnail Extractor Media File Property Extractor Shell Extension Microsoft Corporation c:\windows\system32\shmedi
+ Wav Properties Handler Media File Property Extractor Shell Extension Microsoft Corporation c:\windows\system32\shmedi
+ Web Printer Shell Extension Print UI DLL Microsoft Corporation c:\windows\system32\printu
+ Web Publishing Wizard Map Network Drives/Network Places Wizard Microsoft Corporation c:\windows\system32\netplw
+ Web Search Shell Browser UI Library Microsoft Corporation c:\windows\system32\browse
+ WebCheck Web Site Monitor Microsoft Corporation c:\windows\system32\webche
+ WebCheck SyncMgr Handler Web Site Monitor Microsoft Corporation c:\windows\system32\webche
+ WebCheckChannelAgent Web Site Monitor Microsoft Corporation c:\windows\system32\webche
+ WebCheckWebCrawler Web Site Monitor Microsoft Corporation c:\windows\system32\webche
+ Windows Media Player Add to Playlist Context Menu Handler Windows Media Player Launcher Microsoft Corporation c:\windows\system32\wmpshe
+ Windows Media Player Burn Audio CD Context Menu Handler Windows Media Player Launcher Microsoft Corporation c:\windows\system32\wmpshe
+ Windows Media Player Play as Playlist Context Menu Handler Windows Media Player Launcher Microsoft Corporation c:\windows\system32\wmpshe
HKLM\Software\Classes\Fold
+ {0D2E74C4-3C34-11d2-A27E-0
+ {24F14F01-7B1C-11d1-838f-0
+ {24F14F02-7B1C-11d1-838f-0
+ {66742402-F9B9-11D1-A202-0
HKLM\Software\Microsoft\Wi
+ AcroIEHlprObj Class AcroIEHelper Module c:\program files\adobe\acrobat 5.0\reader\activex\acroieh
+ Google Toolbar Helper Google IE Client Toolbar Google Inc. c:\program files\google\googletoolbar
+ SSVHelper Class Java(TM) 2 Platform Standard Edition binary Sun Microsystems, Inc. c:\program files\java\jre1.5.0_06\bin
+ {53707962-6F74-2D53-2644-2
HKCU\Software\Microsoft\In
+ shdocvw.dll Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocv
HKLM\Software\Microsoft\In
+ googletoolbar2.dll Google IE Client Toolbar Google Inc. c:\program files\google\googletoolbar
+ yt.dll Yahoo! Toolbar Yahoo! Inc. c:\program files\yahoo!\companion\ins
HKLM\Software\Microsoft\In
+ Uninstall BitDefender Online Scanner v8 c:\windows\bdoscandel.exe
+ Windows Messenger Windows Messenger Microsoft Corporation c:\program files\messenger\msmsgs.exe
HKLM\System\CurrentControl
+ AOL ACS AOL Connectivity Service America Online, Inc. c:\program files\common files\aol\acs\aolacsd.exe
+ Ati HotKey Poller c:\windows\system32\ati2ev
+ ATI Smart ATI Smart c:\windows\system32\ati2sg
+ AudioSrv Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchos
+ Avg7Alrt AVG Alert Manager GRISOFT, s.r.o. c:\program files\grisoft\avg free\avgamsvr.exe
+ Avg7UpdSvc AVG Update Service GRISOFT, s.r.o. c:\program files\grisoft\avg free\avgupsvc.exe
+ Browser Maintains an updated list of computers on the network and supplies this list to computers designated as browsers. If this service is stopped, this list will not be updated or maintained. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchos
+ CryptSvc Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Key Service, which helps enroll this computer for certificates. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchos
+ DcomLaunch Provides launch functionality for DCOM services. Microsoft Corporation c:\windows\system32\svchos
+ Dhcp Manages network configuration by registering and updating IP addresses and DNS names. Microsoft Corporation c:\windows\system32\svchos
+ dmserver Detects and monitors new hard disk drives and sends disk volume information to Logical Disk Manager Administrative Service for configuration. If this service is stopped, dynamic disk status and configuration information may become out of date. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchos
+ Dnscache Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchos
+ ERSvc Allows error reporting for services and applictions running in non-standard environments. Microsoft Corporation c:\windows\system32\svchos
+ Eventlog Enables event log messages issued by Windows-based programs and components to be viewed in Event Viewer. This service cannot be stopped. Microsoft Corporation c:\windows\system32\servic
+ helpsvc Enables Help and Support Center to run on this computer. If this service is stopped, Help and Support Center will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchos
+ lanmanserver Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchos
+ lanmanworkstation Creates and maintains client network connections to remote servers. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchos
+ LmHosts Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution. Microsoft Corporation c:\windows\system32\svchos
+ PlugPlay Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability. Microsoft Corporation c:\windows\system32\servic
+ PolicyAgent Manages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver. Microsoft Corporation c:\windows\system32\lsass.
+ ProtectedStorage Provides protected storage for sensitive data, such as private keys, to prevent access by unauthorized services, processes, or users. Microsoft Corporation c:\windows\system32\lsass.
+ RemoteRegistry Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchos
+ RpcSs Provides the endpoint mapper and other miscellaneous RPC services. Microsoft Corporation c:\windows\system32\svchos
+ SamSs Stores security information for local user accounts. Microsoft Corporation c:\windows\system32\lsass.
+ Schedule Enables a user to configure and schedule automated tasks on this computer. If this service is stopped, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchos
+ seclogon Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchos
+ SENS Tracks system events such as Windows logon, network, and power events. Notifies COM+ Event System subscribers of these events. Microsoft Corporation c:\windows\system32\svchos
+ SharedAccess Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network. Microsoft Corporation c:\windows\system32\svchos
+ ShellHWDetection Generic Host Process for Win32 Services Microsoft Corporation c:\windows\system32\svchos
+ Spooler Loads files to memory for later printing. Microsoft Corporation c:\windows\system32\spools
+ srservice Performs system restore functions. To stop service, turn off System Restore from the System Restore tab in My Computer->Properties Microsoft Corporation c:\windows\system32\svchos
+ Themes Provides user experience theme management. Microsoft Corporation c:\windows\system32\svchos
+ TrkWks Maintains links between NTFS files within a computer or across computers in a network domain. Microsoft Corporation c:\windows\system32\svchos
+ W32Time Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
Microsoft Corporation c:\windows\system32\svchos
+ WANMiniportService Wan Miniport (ATW) Service America Online, Inc. c:\windows\wanmpsvc.exe
+ WebClient Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchos
+ winmgmt Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchos
+ wscsvc Monitors system security settings and configurations. Microsoft Corporation c:\windows\system32\svchos
+ wuauserv Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site. Microsoft Corporation c:\windows\system32\svchos
+ WZCSVC Provides automatic configuration for the 802.11 adapters Microsoft Corporation c:\windows\system32\svchos
HKLM\System\CurrentControl
+ ACPI ACPI Driver for NT Microsoft Corporation c:\windows\system32\driver
+ aec Microsoft Acoustic Echo Canceller Microsoft Corporation c:\windows\system32\driver
+ AFD AFD Networking Support Environment Microsoft Corporation c:\windows\system32\driver
+ agp440 440 NT AGP Filter Microsoft Corporation c:\windows\system32\driver
+ ASAPIW2K ASAPI Pinnacle Systems GmbH c:\windows\system32\driver
+ AsyncMac RAS Asynchronous Media Driver Microsoft Corporation c:\windows\system32\driver
+ atapi IDE/ATAPI Port Driver Microsoft Corporation c:\windows\system32\driver
+ ati2mtag ATI Radeon WindowsNT Miniport Driver ATI Technologies Inc. c:\windows\system32\driver
+ Atmarpc ATM ARP Client Protocol Microsoft Corporation c:\windows\system32\driver
+ audstub AudStub Driver Microsoft Corporation c:\windows\system32\driver
+ Avg7Core AVG Scanning Engine GRISOFT, s.r.o. c:\windows\system32\driver
+ Avg7RsW AVG Resident Shield Unload Helper GRISOFT, s.r.o. c:\windows\system32\driver
+ Avg7RsXP AVG Resident Anti-Virus Shield GRISOFT, s.r.o. c:\windows\system32\driver
+ AvgTdi AVG Network connection watcher GRISOFT, s.r.o. c:\windows\system32\driver
+ cdrdrv InstantWrite Recorder driver Pinnacle Systems GmbH c:\windows\system32\driver
+ Cdrom SCSI CD-ROM Driver Microsoft Corporation c:\windows\system32\driver
+ CO_Mon c:\windows\system32\driver
+ ctac32k Creative AC3 SW Decoder Device Driver (WDM) Creative Technology Ltd c:\windows\system32\driver
+ ctaud2k Creative WDM Audio Device Driver Creative Technology Ltd c:\windows\system32\driver
+ ctljystk Creative Joyport Enabler Creative Technology Ltd. c:\windows\system32\driver
+ ctprxy2k Creative Proxy Device Driver (WDM) Creative Technology Ltd c:\windows\system32\driver
+ ctsfm2k SoundFont(R) Manager (WDM) Creative Technology Ltd c:\windows\system32\driver
+ Disk PnP Disk Driver Microsoft Corporation c:\windows\system32\driver
+ dmio NT Disk Manager I/O Driver Microsoft Corp., Veritas Software c:\windows\system32\driver
+ dmload NT Disk Manager Startup Driver Microsoft Corp., Veritas Software. c:\windows\system32\driver
+ DMusic Microsoft Kernel DLS Synthesizer Microsoft Corporation c:\windows\system32\driver
+ drmkaud Microsoft Kernel DRM Audio Descrambler Filter Microsoft Corporation c:\windows\system32\driver
+ EL90XBC 3Com EtherLink PCI Driver 3Com Corporation c:\windows\system32\driver
+ emu10k Creative SB Live! Adapter Driver Creative Technology Ltd. c:\windows\system32\driver
+ emu10k1 Creative SB Live! Interface Driver Creative Technology Ltd. c:\windows\system32\driver
+ emupia E-mu Plug-in Architecture Driver (WDM) Creative Technology Ltd c:\windows\system32\driver
+ Fdc Floppy Disk Controller Driver Microsoft Corporation c:\windows\system32\driver
+ Flpydisk Floppy Driver Microsoft Corporation c:\windows\system32\driver
+ Ftdisk FT Disk Driver Microsoft Corporation c:\windows\system32\driver
+ gameenum Game Port Enumerator Microsoft Corporation c:\windows\system32\driver
+ Gpc Generic Packet Classifier Microsoft Corporation c:\windows\system32\driver
+ ha10kx2k Creative EMU10KX HAL (WDM) Creative Technology Ltd c:\windows\system32\driver
+ HCF_MSFT Modem Conexant c:\windows\system32\driver
+ HTTP This service implements the hypertext transfer protocol (HTTP). If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\driver
+ i8042prt i8042 Port Driver Microsoft Corporation c:\windows\system32\driver
+ i81x Miniport Driver for Intel Graphics Driver Intel(R) Corporation c:\windows\system32\driver
+ iAimFP0 Digital Display Minidriver for Intel(R) Graphics Driver Intel(R) Corporation c:\windows\system32\driver
+ iAimFP1 Digital Display Minidriver for Intel(R) Graphics Driver Intel(R) Corporation c:\windows\system32\driver
+ iAimFP2 Digital Display Minidriver for Intel(R) Graphics Driver Intel(R) Corporation c:\windows\system32\driver
+ iAimFP3 Digital Display Minidriver for Intel(R) Graphics Driver Intel(R) Corporation c:\windows\system32\driver
+ iAimFP4 Local Flat Panel Display Minidriver for Intel(R) Graphics Driver Intel(R) Corporation c:\windows\system32\driver
+ iAimTV0 Digital Display Minidriver for Intel(R) Graphics Driver Intel(R) Corporation c:\windows\system32\driver
+ iAimTV1 Digital Display Minidriver for Intel(R) Graphics Driver Intel(R) Corporation c:\windows\system32\driver
+ iAimTV3 Digital Display Minidriver for Intel(R) Graphics Driver Intel(R) Corporation c:\windows\system32\driver
+ iAimTV4 Digital Display Minidriver for Intel(R) Graphics Driver Intel(R) Corporation c:\windows\system32\driver
+ Imapi IMAPI Kernel Driver Microsoft Corporation c:\windows\system32\driver
+ IntelIde Intel PCI IDE Driver Microsoft Corporation c:\windows\system32\driver
+ ip6fw Provides intrusion prevention service for a home or small office network. Microsoft Corporation c:\windows\system32\driver
+ IpFilterDriver IP Traffic Filter Driver Microsoft Corporation c:\windows\system32\driver
+ IpInIp IP in IP Tunnel Driver Microsoft Corporation c:\windows\system32\driver
+ IpNat IP Network Address Translator Microsoft Corporation c:\windows\system32\driver
+ IPSec IPSEC driver Microsoft Corporation c:\windows\system32\driver
+ IRENUM Infra-Red Bus Enumerator Microsoft Corporation c:\windows\system32\driver
+ isapnp PNP ISA Bus Driver Microsoft Corporation c:\windows\system32\driver
+ Kbdclass Keyboard Class Driver Microsoft Corporation c:\windows\system32\driver
+ kmixer Kernel Mode Audio Mixer Microsoft Corporation c:\windows\system32\driver
+ Mouclass Mouse Class Driver Microsoft Corporation c:\windows\system32\driver
+ MSKSSRV MS KS Server Microsoft Corporation c:\windows\system32\driver
+ MSPCLOCK MS Proxy Clock Microsoft Corporation c:\windows\system32\driver
+ MSPQM MS Proxy Quality Manager Microsoft Corporation c:\windows\system32\driver
+ mssmbios System Management BIOS Driver Microsoft Corporation c:\windows\system32\driver
+ NdisTapi Remote Access NDIS TAPI Driver Microsoft Corporation c:\windows\system32\driver
+ Ndisuio NDIS Usermode I/O Protocol Microsoft Corporation c:\windows\system32\driver
+ NdisWan Remote Access NDIS WAN Driver Microsoft Corporation c:\windows\system32\driver
+ NetBT NetBios over Tcpip Microsoft Corporation c:\windows\system32\driver
+ NwlnkFlt IPX Traffic Filter Driver Microsoft Corporation c:\windows\system32\driver
+ NwlnkFwd IPX Traffic Forwarder Driver Microsoft Corporation c:\windows\system32\driver
+ ossrv Creative OS Services Driver (WDM) Creative Technology Ltd. c:\windows\system32\driver
+ P3 Processor Device Driver Microsoft Corporation c:\windows\system32\driver
+ Parport Parallel Port Driver Microsoft Corporation c:\windows\system32\driver
+ PCI NT Plug and Play PCI Enumerator Microsoft Corporation c:\windows\system32\driver
+ PptpMiniport WAN Miniport (PPTP) Microsoft Corporation c:\windows\system32\driver
+ PSched QoS Packet Scheduler Microsoft Corporation c:\windows\system32\driver
+ Ptilink Direct Parallel Link Driver Parallel Technologies, Inc. c:\windows\system32\driver
+ RasAcd Remote Access Auto Connection Driver Microsoft Corporation c:\windows\system32\driver
+ Rasl2tp WAN Miniport (L2TP) Microsoft Corporation c:\windows\system32\driver
+ RasPppoe Remote Access PPPOE Driver Microsoft Corporation c:\windows\system32\driver
+ Raspti Direct Parallel Microsoft Corporation c:\windows\system32\driver
+ RDPCDD RDP Miniport Microsoft Corporation c:\windows\system32\driver
+ rdpdr Microsoft RDP Device redirector Microsoft Corporation c:\windows\system32\driver
+ redbook Redbook Audio Filter Driver Microsoft Corporation c:\windows\system32\driver
+ Secdrv SafeDisc driver c:\windows\system32\driver
+ serenum Serial Port Enumerator Microsoft Corporation c:\windows\system32\driver
+ Serial Serial Device Driver Microsoft Corporation c:\windows\system32\driver
+ sfman SoundFont(R) Manager Creative Technology Ltd. c:\windows\system32\driver
+ splitter Microsoft Kernel Audio Splitter Microsoft Corporation c:\windows\system32\driver
+ swenum Plug and Play Software Device Enumerator Microsoft Corporation c:\windows\system32\driver
+ swmidi Microsoft GS Wavetable Synthesizer Microsoft Corporation c:\windows\system32\driver
+ sysaudio System Audio WDM Filter Microsoft Corporation c:\windows\system32\driver
+ Tcpip TCP/IP Protocol Driver Microsoft Corporation c:\windows\system32\driver
+ TermDD Terminal Server Driver Microsoft Corporation c:\windows\system32\driver
+ Update Update Driver Microsoft Corporation c:\windows\system32\driver
+ usbhub Default Hub Driver for USB Microsoft Corporation c:\windows\system32\driver
+ usbprint USB Printer driver Microsoft Corporation c:\windows\system32\driver
+ usbuhci UHCI USB Miniport Driver Microsoft Corporation c:\windows\system32\driver
+ VgaSave Controls the VGA display adapter to provide basic display capabilities. Microsoft Corporation c:\windows\system32\driver
+ VOBID InstantDrive Pinnacle Systems c:\windows\system32\driver
+ Wanarp Remote Access IP ARP Driver Microsoft Corporation c:\windows\system32\driver
+ wanatw Wan Miniport (ATW) America Online, Inc. c:\windows\system32\driver
+ wdmaud MMSYSTEM Wave/Midi API mapper Microsoft Corporation c:\windows\system32\driver
HKLM\System\CurrentControl
+ File not found:
+ autocheck autochk * Auto Check Utility Microsoft Corporation c:\windows\system32\autoch
+ SsiEfr.e File not found: SsiEfr.e
+ SsiEfr.e File not found: SsiEfr.e
HKLM\Software\Microsoft\Wi
+ Your Image File Name Here without a path Symbolic Debugger for Windows 2000 Microsoft Corporation c:\windows\system32\ntsd.e
HKLM\System\CurrentControl
+ advapi32 Advanced Windows 32 Base API Microsoft Corporation c:\windows\system32\advapi
+ comdlg32 Common Dialogs DLL Microsoft Corporation c:\windows\system32\comdlg
+ gdi32 GDI Client DLL Microsoft Corporation c:\windows\system32\gdi32.
+ imagehlp Windows NT Image Helper Microsoft Corporation c:\windows\system32\imageh
+ kernel32 Windows NT BASE API Client DLL Microsoft Corporation c:\windows\system32\kernel
+ lz32 LZ Expand/Compress API DLL Microsoft Corporation c:\windows\system32\lz32.d
+ ole32 Microsoft OLE for Windows Microsoft Corporation c:\windows\system32\ole32.
+ oleaut32 Microsoft Corporation c:\windows\system32\oleaut
+ olecli32 Object Linking and Embedding Client Library Microsoft Corporation c:\windows\system32\olecli
+ olecnv32 Microsoft OLE for Windows Microsoft Corporation c:\windows\system32\olecnv
+ olesvr32 Object Linking and Embedding Server Library Microsoft Corporation c:\windows\system32\olesvr
+ olethk32 Microsoft OLE for Windows Microsoft Corporation c:\windows\system32\olethk
+ rpcrt4 Remote Procedure Call Runtime Microsoft Corporation c:\windows\system32\rpcrt4
+ shell32 Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell3
+ url Internet Shortcut Shell Extension DLL Microsoft Corporation c:\windows\system32\url.dl
+ urlmon OLE32 Extensions for Win32 Microsoft Corporation c:\windows\system32\urlmon
+ user32 Windows XP USER API Client DLL Microsoft Corporation c:\windows\system32\user32
+ version Version Checking and File Installation Libraries Microsoft Corporation c:\windows\system32\versio
+ wininet Internet Extensions for Win32 Microsoft Corporation c:\windows\system32\winine
+ wldap32 Win32 LDAP API DLL Microsoft Corporation c:\windows\system32\wldap3
HKLM\SOFTWARE\Microsoft\Wi
+ logonui.exe Windows Logon UI Microsoft Corporation c:\windows\system32\logonu
HKLM\SOFTWARE\Microsoft\Wi
+ AtiExtEvent c:\windows\system32\ati2ev
+ crypt32chain Crypto API32 Microsoft Corporation c:\windows\system32\crypt3
+ cryptnet Crypto Network Related API Microsoft Corporation c:\windows\system32\cryptn
+ cscdll Offline Network Agent Microsoft Corporation c:\windows\system32\cscdll
+ ScCertProp Common DLL to receive Winlogon notifications Microsoft Corporation c:\windows\system32\wlnoti
+ Schedule Common DLL to receive Winlogon notifications Microsoft Corporation c:\windows\system32\wlnoti
+ sclgntfy Secondary Logon Service Notification DLL Microsoft Corporation c:\windows\system32\sclgnt
+ SensLogn Common DLL to receive Winlogon notifications Microsoft Corporation c:\windows\system32\wlnoti
+ termsrv Common DLL to receive Winlogon notifications Microsoft Corporation c:\windows\system32\wlnoti
+ wlballoon Common DLL to receive Winlogon notifications Microsoft Corporation c:\windows\system32\wlnoti
+ WRNotifier Spy Sweeper SDK Webroot Software, Inc. c:\windows\system32\wrlogo
HKLM\System\CurrentControl
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{3CA0
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{3CA0
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{7389
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{7389
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{7973
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{7973
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{CC61
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{CC61
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{E17B
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{E17B
+ MSAFD Tcpip [RAW/IP] Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsoc
+ MSAFD Tcpip [TCP/IP] Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsoc
+ MSAFD Tcpip [UDP/IP] Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsoc
+ RSVP TCP Service Provider Microsoft Windows Rsvp 1.0 Service Provider Microsoft Corporation c:\windows\system32\rsvpsp
+ RSVP UDP Service Provider Microsoft Windows Rsvp 1.0 Service Provider Microsoft Corporation c:\windows\system32\rsvpsp
HKLM\SYSTEM\CurrentControl
+ BJ Language Monitor Langage Monitor for Canon Bubble-Jet Printer Microsoft Corporation c:\windows\system32\cnbjmo
+ hpzlnt04 HP c:\windows\system32\hpzlnt
+ Local Port Local Spooler DLL Microsoft Corporation c:\windows\system32\locals
+ PJL Language Monitor PJL Language monitor Microsoft Corporation c:\windows\system32\pjlmon
+ Standard TCP/IP Port Standard TCP/IP Port Monitor DLL Microsoft Corporation c:\windows\system32\tcpmon
+ USB Monitor Standard Dynamic Printing Port Monitor DLL Microsoft Corporation c:\windows\system32\usbmon
HKLM\SYSTEM\CurrentControl
+ msv1_0 Microsoft Authentication Package v1.0 Microsoft Corporation c:\windows\system32\msv1_0
HKLM\SYSTEM\CurrentControl
+ scecli Windows Security Configuration Editor Client Engine Microsoft Corporation c:\windows\system32\scecli
HKLM\SYSTEM\CurrentControl
+ kerberos Kerberos Security Package Microsoft Corporation c:\windows\system32\kerber
+ msv1_0 Microsoft Authentication Package v1.0 Microsoft Corporation c:\windows\system32\msv1_0
+ schannel TLS / SSL Security Provider Microsoft Corporation c:\windows\system32\schann
+ wdigest Microsoft Digest Access Microsoft Corporation c:\windows\system32\wdiges
What file exactly is it? can you please let us know where it is located? just curious.
I'm also curious what the entries in your hijackthis log would show, probably a very long shot.
Please download HijackThis 1.99.1
http://www.cyberanswers.or
Open Hijackthis, click "Do a system scan and save a logfile" don't fix anything.
Notepad will also open, copy its contents and paste it to either these sites:
http://www.rafb.net/paste/
then at the bottom left corner click "paste"
Copy the address/url and post it here:
Or paste the log at --> http://www.hijackthis.de/
and click "Analyse", click "Save". Post the link to the saved list here.
Hijackthis log...
Logfile of HijackThis v1.99.1
Scan saved at 4:08:01 AM, on 6/8/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\System32\Ati2ev
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\spools
C:\PROGRA~1\COMMON~1\AOL\A
C:\PROGRA~1\Grisoft\AVGFRE
C:\PROGRA~1\Grisoft\AVGFRE
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\Ati2ev
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTHELP
C:\Program Files\Java\jre1.5.0_06\bin
C:\Program Files\Real\RealPlayer\Real
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\devldr
C:\WINDOWS\System32\spool\
C:\Program Files\Error Nuker\bin\ErrorNuker.exe
C:\PROGRA~1\Grisoft\AVGFRE
C:\PROGRA~1\Grisoft\AVGFRE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\A
C:\Program Files\Yahoo!\Messenger\ypa
C:\Program Files\ProxyWay\proxyway.ex
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Pinnacle\InstantCDDV
C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETra
C:\WINDOWS\system32\wuaucl
C:\Program Files\Common Files\Real\Update_OB\reals
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\hijackthis\HijackThi
R0 - HKCU\Software\Microsoft\In
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.ex
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\Real
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORT
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TI
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TI
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCh
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PI
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dump
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROG
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IM
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\
O4 - HKLM\..\Run: [Error Nuker] C:\Program Files\Error Nuker\bin\ErrorNuker.exe autostart
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypa
O4 - HKCU\..\Run: [ProxyWay] C:\Program Files\ProxyWay\proxyway.ex
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
O4 - HKCU\..\Run: [IW_Drop_Icon] C:\Program Files\Pinnacle\InstantCDDV
O4 - HKCU\..\Run: [InstantTray] C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETra
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0b\aoltray.exe
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-0
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugi
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9
O16 - DPF: {15589FA1-C456-11CE-BF01-0
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-0
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D
O16 - DPF: {6414512B-B978-451D-A0D8-F
O16 - DPF: {644E432F-49D3-41A1-8DD5-E
O16 - DPF: {6E32070A-766D-4EE6-879C-D
O16 - DPF: {6E5A37BF-FD42-463A-877C-4
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5
O16 - DPF: {EF791A6B-FC12-4C68-99EF-F
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogo
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\A
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2ev
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sg
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
I solved the issue, when I downloaded the file, I scanned
the file with AVG a Virus was shown but I ignored it and I did not take any action against the file, I let it be. Apparently it did something not allowing me to access it. I didn't know how to disable AVG other then, going through System Configuration Utility, so I uninstalled it, and guess what it works now. Now my question is, can I reinstall AVG if I want to keep
running this file? It's really not harmful to my machine, but I am gonna check with some experts on that shortly. So in recapping, I could not get this file to run with the exception of running it in safe mode which meant some file in normal mode was preventing the execution of this file, it basically was a process of elimination. I uninstalled the following AVG Free Edition, Spysweeper, and Zone Alarm, but it was AVG Free Edition that was the culprit.
So, now my question is, can I reinstall AVG Free edition, and if so, what if it disables my exe file again, how can I disable or prevent that? Also where can I send this file to expert for analizing, and get a quick response?
That's good news. I think it makes sense now that you explained it. The AV program was the one denying access to the file.
If you reinstall AVG you will have the same problem, but most AV programs have an "exclude" option in the settings where you can exclude specific files/folders from being scanned. Not sure where that setting is in AVG but you should be able to find it.
But first, you should make sure the AVG warning really is a false positive. One way is to submit your file to: http://www.virustotal.com/
HE-HE-HE, PROBABLY THE FILE YOUR OPENING HAS A VIRUS, BUT IF YOU ARE SURE THAT THE FILE IS NOT A VIRUS OR NOT INFECTED, JUST TURN OFF OR DISABLE THE MEMORY/RESIDENT SHIELD OF THE ANTI VIRUS YOU ARE USING, THEN OPEN THE FILE AGAIN. (^_~,,,,,,,,,,,,,FORGIVE ME, I'M JUST A NEWBIE ON THIS SITE,,,,,HELLO GURU AND GENIUSES. (~_^)
I know this has already been closed but I found the Solution to my problem.
Right Click on the file, go to properties, general tab. It will probably
say "file has come from another computer and is being blocked". Click the
unblock button and you should be ok.
Ive never seen this before, looks like something new.
"InvestecPrivateBank
01.09.2009 at 04:54AM PST, ID: 23334972
I know this has already been closed but I found the Solution to my problem.
Right Click on the file, go to properties, general tab. It will probably
say "file has come from another computer and is being blocked". Click the
unblock button and you should be ok.
Ive never seen this before, looks like something new. "
This is what fixed my problem..
Blocked File Protection Control is what it is called.
Thanks for this additional comment in this forum.
Business Accounts
Answer for Membership
by: r-kPosted on 2006-06-07 at 15:17:48ID: 16857190
Taking ownership may not be enough. You also have to give yourself read/execute permissions.