File name | Status | Startup method | Description
C:\PROGRA~1\AIMP2\System\AIMP_S~1.DLL | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {1F77B17B-F531-44DB-ACA4-76ABB5010A28} | Delete C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {993BE281-6695-4BA5-8A2A-7AACBFAAB69E} | Delete C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} | Delete C:\PROGRA~1\MICROS~2\Office12\MLCFG32.CPL | Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, mlcfg32.cpl | Delete C:\PROGRA~1\MICROS~2\Office12\MLSHEXT.DLL | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {00020d75-0000-0000-c000-000000000046} | Delete C:\PROGRA~1\MICROS~2\Office12\OLKFSTUB.DLL | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {0006F045-0000-0000-C000-000000000046} | Delete C:\PROGRA~1\MICROS~2\Office12\ONFILTER.DLL | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C} | Delete C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\DesktopControlPanel.dll | Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {EC654325-1273-C2A9-2B7C-45D29BCE68FD} | Delete C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\DesktopControlPanel.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {EC654325-1273-C2A9-2B7C-45D29BCE68FD} | Delete C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\DreamControl.dll | Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {EC654325-1273-C2A9-2B7C-45D29BCE68FF} | Delete C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\DreamControl.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {EC654325-1273-C2A9-2B7C-45D29BCE68FF} | Delete C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\DreamThumbnails.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {D22F6E51-BD32-4b7d-A17D-DC89C7FDFF15} | Delete C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\deskscapes.dll | Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {EC654325-1273-C2A9-2B7C-45D29BCE68FB} | Delete C:\PROGRA~1\VSO\IMAGER~1\RSZShell.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {2BB59FC0-31E8-42DA-9D3C-E9A52953853B} | Delete C:\PROGRA~1\WI4EB4~1\wmpband.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {0a4286ea-e355-44fb-8086-af3df7645bd9} | Delete C:\Program Files\7-Zip\7-zip.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {23170F69-40C1-278A-1000-000100020000} | Delete C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, StartCCC | Delete C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {5E2121EE-0300-11D4-8D3B-444553540000} | Delete C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiamaxx.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {872A9397-E0D6-4e28-B64D-52B8D0A7EA35} | Delete C:\Program Files\Acronis\TrueImageHome\tishell.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {C539A15A-3AF9-4c92-B771-50CB78F5C751} | Delete C:\Program Files\Acronis\TrueImageHome\tishell.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {C539A15B-3AF9-4c92-B771-50CB78F5C751} | Delete C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.cpl | Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, Adobe Version Cue CS3 | Delete C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma.cpl | Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, Adobe Gamma | Delete C:\Program Files\Common Files\System\wab32.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {13D3C4B8-B179-4ebb-BF62-F704173E7448} | Delete C:\Program Files\ERUNT\AUTOBACK.EXE | Active | Shortcut in Startup folder | C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\, C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk,
| C:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\tssmpm.cpl | Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, TSSMPM | Delete C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {0561EC90-CE54-4f0c-9C55-E226110A740C} | Delete C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {5574006C-28F5-4a65-A28C-74DE6BFBE0BB} | Delete C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {327669A0-59A7-4be9-B99E-1C9F3A57611A} | Delete C:\Program Files\HashTab Shell Extension\HashTab.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {8A56567E-A333-4843-B6E1-C3A262E41D8C} | Delete C:\Program Files\Java\jre6\bin\jusched.exe | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, SunJavaUpdateSched | Delete C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {B5A7F190-DDA6-4420-B3BA-52453494E6CD} | Delete C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {72853161-30C5-4D22-B7F9-0BBC1D38A37E} | Delete C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {2A541AE1-5BF6-4665-A8A3-CFA9672E4291} | Delete C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {A449600E-1DC6-4232-B948-9BD794D62056} | Delete C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {B5A7F190-DDA6-4420-B3BA-52453494E6CD} | Delete C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {6C467336-8281-4E60-8204-430CED96822D} | Delete C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {387E725D-DC16-4D76-B310-2C93ED4752A0} | Delete C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {16F3DD56-1AF5-4347-846D-7C10C4192619} | Delete C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} | Delete C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} | Delete C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {99FD978C-D287-4F50-827F-B2C658EDA8E7} | Delete C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {920E6DB1-9907-4370-B3A0-BAFC03D81399} | Delete C:\Program Files\Microsoft Office\Office12\msohevi.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {42042206-2D85-11D3-8CFF-005004838597} | Delete C:\Program Files\Microsoft Security Essentials\msseces.exe | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, MSSE | Delete C:\Program Files\Microsoft Virtual PC\VPCShExH.DLL | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {8932AEFE-9DB6-4f43-AFB2-5682F55E773A} | Delete C:\Program Files\Nero\Nero8\Nero Toolkit\NeroBurnRights.cpl | Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, Nero BurnRights | Delete C:\Program Files\QT Lite\QTSystem\QuickTime.cpl | Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, QuickTime | Delete C:\Program Files\SUPERAntiSpyware\SASSEH.DLL | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} | Delete C:\Program Files\TeraCopy\TeraCopy.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {A7005AF0-D6E8-48AF-8DFA-023B1CF660A7} | Delete C:\Program Files\TeraCopy\TeraCopyExt.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {A8005AF0-D6E8-48AF-8DFA-023B1CF660A7} | Delete C:\Program Files\ThumbView_Lite 1.0\ThumbView_Lite.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {3B52CC4A-19E9-43F5-A626-F89267A5E43F} | Delete C:\Program Files\Windows Live\Mail\mailcomm.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {0563DB41-F538-4B37-A92D-4659049B7766} | Delete C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {00F33137-EE26-412F-8D71-F84E4C2C6625} | Delete C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {00F346CB-35A4-465B-8B8F-65A29DBAB1F6} | Delete C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} | Delete C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {00F30F90-3E96-453B-AFCD-D71989ECC2C7} | Delete C:\Program Files\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {06A2568A-CED6-4187-BB20-400B8C02BE5A} | Delete C:\Program Files\\Windows Defender\MSASCui.exe | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Windows Defender | Delete C:\Program Files\\Windows Defender\MpOav.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {2781761E-28E0-4109-99FE-B9D127C57AFE} | Delete C:\Program Files\\Windows Media Player\wmprph.exe | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {031EE060-67BC-460d-8847-E4A7C5E45A27} | Delete C:\Program Files\\Windows Photo Gallery\PhotoViewer.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {E598560B-28D5-46aa-A14A-8A3BEA34B576} | Delete C:\Program Files\\Windows Photo Gallery\PhotoViewer.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {FFE2A43C-56B9-4bf5-9A79-CC6D4285608A} | Delete C:\Program Files\\Windows Sidebar\sbdrop.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {6b9228da-9c15-419e-856c-19e768a13bdc} | Delete C:\Program Files\iTunes\iTunesMiniPlayer.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} | Delete C:\Windows\MSAgent\agentpsh.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {143A62C8-C33B-11D1-84FE-00C04FA34A14} | Delete C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll | Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\ASP.NET\2.0.50727.0, DllFullPath | Delete C:\Windows\RtHDVCpl.exe | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, RtHDVCpl | Delete C:\Windows\System32\Branding\folderbg\VistaFolderBackground.dll | Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {73526E5A-FD53-4BE7-B5E2-D3C89D7413DC} | Delete C:\Windows\System32\Branding\folderbg\VistaFolderBackground.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {73526E5A-FD53-4BE7-B5E2-D3C89D7413DC} | Delete C:\Windows\System32\DreamScene.dll | Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {E31004D1-A431-41B8-826F-E902F9D95C81} | Delete C:\Windows\System32\NcdProp.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {BC65FB43-1958-4349-971A-210290480130} | Delete C:\Windows\System32\Speech\SpeechUX\sapi.cpl | Active | Registry key | HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls, Speech | Delete C:\Windows\System32\SyncCenter.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {7A0F6AB7-ED84-46B6-B47E-02AA159A152B} | Delete C:\Windows\System32\SyncCenter.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {BC48B32F-5910-47F5-8570-5074A8A5636A} | Delete C:\Windows\System32\SyncCenter.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {E413D040-6788-4C22-957E-175D1C513A34} | Delete C:\Windows\System32\SyncCenter.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {4B534112-3AF6-4697-A77C-D62CE9B9E7CF} | Delete C:\Windows\System32\SyncCenter.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {F1390A9A-A3F4-4E5D-9C5F-98F3BD8D935C} | Delete C:\Windows\System32\SyncCenter.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {576C9E85-1300-4EF5-BF6B-D00509F4EDCD} | Delete C:\Windows\System32\SyncCenter.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {289978AC-A101-4341-A817-21EBA7FD046D} | Delete C:\Windows\System32\SyncCenter.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {71D99464-3B6B-475C-B241-E15883207529} | Delete C:\Windows\System32\SyncCenter.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {B32D3949-ED98-4DBB-B347-17A144969BBA} | Delete C:\Windows\System32\SyncCenter.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {2E9E59C0-B437-4981-A647-9C34B9B90891} | Delete C:\Windows\System32\SyncCenter.dll | Active | Registry key | HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved, {9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF} | Delete |