[HKLM\System\CurrentControlSet\Services\qq2]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360hotfix.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360rpt.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safe.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safebox.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360tray.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\apvxdwin.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ast.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avcenter.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avengine.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgnt.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avguard.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avltmain.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp32.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avtask.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdagent.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdwizreg.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\boxmod.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccapp.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccenter.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccevtmgr.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccregvfy.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccsetmgr.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\extdb.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\frameworkservice.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\frwstub.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\guardfield.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iparmor.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kaccore.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kasmain.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kav32.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavstart.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavsvc.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavsvcui.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kislnchr.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kissvc.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kmailmon.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\knownsvr.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kpfw32.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kpfwsvc.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kregex.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvfw.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvmonxp.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvmonxp.kxp]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvol.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvprescan.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvsrvxp.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvwsc.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvxp.kxp]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kwatch.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\livesrv.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\makereport.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcagent.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcdash.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcdetect.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcshield.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mctskshd.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcvsescn.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcvsshld.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mghtml.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Optionsaprdmgr.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Optionsavapsvc.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Optionsavapw32.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Optionsavw32.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Optionsmain.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Optionsod32.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Optionsod32krn.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Optionsod32kui.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Optionspfmntor.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\oasclnt.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavsrv51.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pfw.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\psctrls.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\psimreal.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\psimsvc.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qqdoctormain.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ras.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ravmon.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ravmond.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ravstub.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ravtask.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwcfg.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwmain.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwproxy.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwsrv.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rsagent.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rsmain.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rsnetsvr.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rssafety.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rstray.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safebank.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safeboxtray.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan32.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scanfrm.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sched.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\seccenter.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\secnotifier.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SetupLD.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\shstat.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartup.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sndsrvc.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spbbcsvc.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\symlcsvc.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tbmon.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\uihost.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ulibcfg.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\updaterui.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\uplive.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vcr32.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vcrmon.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vptray.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsserv.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vstskmgr.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vstskmgr.exe ]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\webproxy.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xcommsvr.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xnlscn.exe]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\РЮёґ№?ѕЯ.exe]
Удалить службу "ClipSrv", удалив ключ реестра:
[HKLM\System\CurrentControlSet\Services\ClipSrv]
Создать службу "ClipSrv", добавив в системный реестр следующую информацию:
[HKLM\System\CurrentControlSet\Services\ClipSrv]
"DependOnService"="NetDDE"
"Description"="Позволяет просматривать страницы папок обмена удаленных компьютеров. Если эта служба остановлена, программа просмотра страниц папок обмена не может обмениваться информацией с удаленными компьютерами. Если эта служба отключена, любые службы, которые явно зависят от нее, не могут быть запущены."
"DisplayName"="Сервер папки обмена"
"ErrorControl"=dword:00000001
"ImagePath"="%SystemRoot%\system32\clipsrv.exe"
"ObjectName"="LocalSystem"
"Start"=dword:00000004
"Type"=dword:00000010
[HKLM\System\CurrentControlSet\Services\ClipSrv\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,00,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,\
02,00,00,00,00,14,00,9d,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
Восстановить работу системных служб "Spooler" и "DMusic", в качестве исполняемых модулей указав следующие файлы:
Удалить файлы:
c:\Program Files\Internet Explorer\003.tmp
%System%\drivers\JM.sys
C:\Program Files\Internet Explorer\12~~.tmp
C:\Program Files\Internet Explorer\001.tmp
C:\Program Files\Internet Explorer\002.tmp
%WinDir%\java\classes\CLIPORV.DLL
%WinDir%\java\classes\CLIPORV.exe
Произвести полную проверку компьютера Антивирусом Касперского с обновленными антивирусными базами (скачать пробную версию).