Blacklight ne détecte rien
Je vais te montrer le résulta de RootkitRevealer et de Rootkit Detective(de McAfee), sa pourrai peu étre t'aider à trouver mon probléme.
RootkitRevealer
HKU\S-1-5-21-2102044601-677604078-2371354468-1009 0 bytes Error dumping hive: Le fichier spécifié est introuvable.
HKLM\SECURITY\Policy\Secrets\SAC* 2004-10-27 11:37 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 2004-10-27 11:37 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\McAfee\VSCore\On Access Scanner\McShield\dwFilesScanned 2008-03-22 09:28 4 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\McAfee\VSCore\On Access Scanner\McShield\szLastScanned 2008-03-22 09:28 50 bytes Windows API length not consistent with raw hive data.
C:\Documents and Settings\Marc\Local Settings\Apps 2008-03-22 09:33 0 bytes Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Marc\Local Settings\Apps\2.0 2008-03-22 09:33 0 bytes Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Marc\Local Settings\Apps\2.0\KT9BE2ZD.N8R 2008-03-22 09:33 0 bytes Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Marc\Local Settings\Apps\2.0\KT9BE2ZD.N8R\GTVH3VLM.OP0 2008-03-22 09:33 0 bytes Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\Marc\Local Settings\Apps\2.0\KT9BE2ZD.N8R\GTVH3VLM.OP0\manifests 2008-03-22 09:33 0 bytes Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll 2008-03-15 20:25 252.00 KB Visible in Windows API, but not in MFT or directory index.
C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll 2008-03-15 20:25 111.50 KB Visible in Windows API, but not in MFT or directory index.
C:\WINDOWS\Prefetch\ROOTKIT_DETECTIVE.EXE-1E3401EE.pf 2008-03-22 09:34 21.52 KB Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\2782.mht 2008-03-22 09:34 2.23 MB Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\2ed3.sys 2008-03-22 09:34 53.34 KB Visible in directory index, but not Windows API or MFT.
C:\WINDOWS\system32\f884.tmp 2004-08-05 08:00 716.00 KB Visible in directory index, but not Windows API or MFT.
Rootkit Detective
Object-Type: Registry-value
Object-Name: (Default)
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A04E0F8-DC88-B943-2C7B-226A2C7B226A}\InprocServer32
Status: Unable to access registry key
Object-Type: Registry-value
Object-Name: (Default)
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\InprocServer32
Status: Unable to access registry key
Object-Type: Registry-value
Object-Name: (Default)
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6802E635-CB18-F544-790D-700BAC51E508}\InprocServer32
Status: Unable to access registry key
Object-Type: Registry-key
Object-Name: Data 2.REN.REN.REN.REN.REN.REN.REN.REN.REN.REND-700BAC51E508}\InprocServer32
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data 2.REN.REN.REN.REN.REN.REN.REN.REN.REN.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: WindowsE\Microsoft\Protected Storage System Provider\*Local Machine*\Data 2.REN.REN.REN.REN.REN.REN.REN.REN.REN.REN
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data 2.REN.REN.REN.REN.REN.REN.REN.REN.REN.REN\Windows
Status: Hidden
Object-Type: Registry-key
Object-Name: Windows.RENcrosoft\Protected Storage System Provider\*Local Machine*\Data 2.REN.REN.REN.REN.REN.REN.REN.REN.REN.REN\Windows
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data 2.REN.REN.REN.REN.REN.REN.REN.REN.REN.REN\Windows.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: Windows.REN.RENoft\Protected Storage System Provider\*Local Machine*\Data 2.REN.REN.REN.REN.REN.REN.REN.REN.REN.REN\Windows.REN
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data 2.REN.REN.REN.REN.REN.REN.REN.REN.REN.REN\Windows.REN.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: Windows.REN.REN.RENProtected Storage System Provider\*Local Machine*\Data 2.REN.REN.REN.REN.REN.REN.REN.REN.REN.REN\Windows.REN.REN
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data 2.REN.REN.REN.REN.REN.REN.REN.REN.REN.REN\Windows.REN.REN.REN
Status: Hidden
Object-Type: Registry-value
Object-Name: Value
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data 2.REN.REN.REN.REN.REN.REN.REN.REN.REN.REN\Windows.REN.REN.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: Data.REN.REN.REN.REN.REN.REN.REN.REN.RENtem Provider\*Local Machine*\Data 2.REN.REN.REN.REN.REN.REN.REN.REN.REN.REN\Windows.REN.REN.REN
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.RENtem Provider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: 00000000-0000-0000-0000-000000000000.RENtem Provider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN000000-0000-0000-0000-000000000000.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: {6340E680-FF06-435f-8767-B79D88AEBD4D}.RENm Provider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN000000-0000-0000-0000-000000000000.REN
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN000000-0000-0000-0000-000000000000.REN\{6340E680-FF06-435f-8767-B79D88AEBD4D}.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: {6340E680-FF06-435f-8767-B79D88AEBD4D}.REN.RENovider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN000000-0000-0000-0000-000000000000.REN\{6340E680-FF06-435f-8767-B79D88AEBD4D}.REN
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN000000-0000-0000-0000-000000000000.REN\{6340E680-FF06-435f-8767-B79D88AEBD4D}.REN.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: {6340E680-FF06-435f-8767-B79D88AEBD4D}.REN.REN.RENer\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN000000-0000-0000-0000-000000000000.REN\{6340E680-FF06-435f-8767-B79D88AEBD4D}.REN.REN
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN000000-0000-0000-0000-000000000000.REN\{6340E680-FF06-435f-8767-B79D88AEBD4D}.REN.REN.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: {6340E680-FF06-435f-8767-B79D88AEBD4D}.REN.REN.REN.RENLocal Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN000000-0000-0000-0000-000000000000.REN\{6340E680-FF06-435f-8767-B79D88AEBD4D}.REN.REN.REN
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN000000-0000-0000-0000-000000000000.REN\{6340E680-FF06-435f-8767-B79D88AEBD4D}.REN.REN.REN.REN
Status: Hidden
Object-Type: Registry-value
Object-Name: Item Data
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN000000-0000-0000-0000-000000000000.REN\{6340E680-FF06-435f-8767-B79D88AEBD4D}.REN.REN.REN.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: 00000000-0000-0000-0000-000000000000.REN.RENProvider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN000000-0000-0000-0000-000000000000.REN\{6340E680-FF06-435f-8767-B79D88AEBD4D}.REN.REN.REN.REN
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN000000-0000-0000-0000-000000000000.REN.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: 00000000-0000-0000-0000-000000000000.REN.REN.RENider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN000000-0000-0000-0000-000000000000.REN.REN
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN000000-0000-0000-0000-000000000000.REN.REN.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: 00000000-0000-0000-0000-000000000000.REN.REN.REN.REN\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN000000-0000-0000-0000-000000000000.REN.REN.REN
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN000000-0000-0000-0000-000000000000.REN.REN.REN.REN
Status: Hidden
Object-Type: Registry-value
Object-Name: Display String
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN000000-0000-0000-0000-000000000000.REN.REN.REN.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN.RENProvider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN000000-0000-0000-0000-000000000000.REN.REN.REN.REN
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN.REN.REN.REN\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN.REN
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN.REN.REN.REN
Status: Hidden
Object-Type: Registry-value
Object-Name: Display String
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN.REN.REN.REN
Status: Hidden
Object-Type: IAT/EAT-hook
PID: 260
Details: Export : Function : USER32.dll!SetWindowsHookExW =>
Object-Path:
Status: Hooked
Object-Type: IAT/EAT-hook
PID: 260
Details: Export : Function : USER32.dll!SetWindowsHookExA =>
Object-Path:
Status: Hooked
Object-Type: Process
Object-Name: M3SRCHMN.EXE
Pid: 2076
Object-Path: C:\PROGRA~1\MYWEBS~1\bar\4.bin\m3SrchMn.exe
Status: Visible
Object-Type: Process
Object-Name: svchost.exe
Pid: 836
Object-Path: C:\WINDOWS\system32\svchost.exe
Status: Visible
Object-Type: Process
Object-Name: nTuneService.ex
Pid: 1704
Object-Path: C:\NVIDIA\Win2KXP\162.18\nTune\nTuneService.exe
Status: Visible
Object-Type: Process
Object-Name: PnkBstrB.exe
Pid: 1828
Object-Path: C:\WINDOWS\system32\PnkBstrB.exe
Status: Visible
Object-Type: Process
Object-Name: System Idle Process
Pid: 0
Object-Path:
Status: Visible
Object-Type: Process
Object-Name: spoolsv.exe
Pid: 1364
Object-Path: C:\WINDOWS\system32\spoolsv.exe
Status: Visible
Object-Type: Process
Object-Name: csrss.exe
Pid: 528
Object-Path: C:\WINDOWS\system32\csrss.exe
Status: Visible
Object-Type: Process
Object-Name: System
Pid: 4
Object-Path:
Status: Visible
Object-Type: Process
Object-Name: alg.exe
Pid: 904
Object-Path: C:\WINDOWS\System32\alg.exe
Status: Visible
Object-Type: Process
Object-Name: wuauclt.exe
Pid: 4036
Object-Path: C:\WINDOWS\system32\wuauclt.exe
Status: Visible
Object-Type: Process
Object-Name: VsTskMgr.exe
Pid: 1588
Object-Path: C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
Status: Visible
Object-Type: Process
Object-Name: GoogleToolbarNo
Pid: 2148
Object-Path: C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
Status: Visible
Object-Type: Process
Object-Name: ctfmon.exe
Pid: 2180
Object-Path: C:\WINDOWS\system32\ctfmon.exe
Status: Visible
Object-Type: Process
Object-Name: WinStylerThemeS
Pid: 848
Object-Path: C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe
Status: Visible
Object-Type: Process
Object-Name: explorer.exe
Pid: 260
Object-Path: C:\WINDOWS\Explorer.EXE
Status: Visible
Object-Type: Process
Object-Name: shstat.exe
Pid: 1904
Object-Path: C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
Status: Visible
Object-Type: Process
Object-Name: RootkitRevealer
Pid: 1036
Object-Path: C:\anti rootkit\RootkitRevealer\RootkitRevealer.exe
Status: Visible
Object-Type: Process
Object-Name: smss.exe
Pid: 448
Object-Path: C:\WINDOWS\System32\smss.exe
Status: Visible
Object-Type: Process
Object-Name: services.exe
Pid: 604
Object-Path: C:\WINDOWS\system32\services.exe
Status: Visible
Object-Type: Process
Object-Name: SOUNDMAN.EXE
Pid: 1628
Object-Path: C:\WINDOWS\SOUNDMAN.EXE
Status: Visible
Object-Type: Process
Object-Name: SMSTray.exe
Pid: 1876
Object-Path: C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
Status: Visible
Object-Type: Process
Object-Name: FrameworkServic
Pid: 1504
Object-Path: C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
Status: Visible
Object-Type: Process
Object-Name: PnkBstrA.exe
Pid: 1784
Object-Path: C:\WINDOWS\system32\PnkBstrA.exe
Status: Visible
Object-Type: Process
Object-Name: svchost.exe
Pid: 1908
Object-Path: C:\WINDOWS\system32\svchost.exe
Status: Visible
Object-Type: Process
Object-Name: qttask.exe
Pid: 1072
Object-Path: C:\Program Files\QuickTime\qttask.exe
Status: Visible
Object-Type: Process
Object-Name: Mctray.exe
Pid: 2312
Object-Path: C:\Program Files\Network Associates\Common Framework\McTray.exe
Status: Visible
Object-Type: Process
Object-Name: Rootkit_Detecti
Pid: 204
Object-Path: C:\bnbn\Rootkit_Detective.exe
Status: Visible
Object-Type: Process
Object-Name: svchost.exe
Pid: 1228
Object-Path: C:\WINDOWS\system32\svchost.exe
Status: Visible
Object-Type: Process
Object-Name: CursorXP.exe
Pid: 2128
Object-Path: C:\Program Files\Curseur\CursorXP.exe
Status: Visible
Object-Type: Process
Object-Name: svchost.exe
Pid: 1136
Object-Path: C:\WINDOWS\system32\svchost.exe
Status: Visible
Object-Type: Process
Object-Name: OLPPOTHLLOTZUAB
Pid: 1168
Object-Path: C:\DOCUME~1\Marc\LOCALS~1\Temp\OLPPOTHLLOTZUABMKX.exe
Status: Visible
Object-Type: Process
Object-Name: WLLoginProxy.ex
Pid: 3372
Object-Path: C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
Status: Visible
Object-Type: Process
Object-Name: naPrdMgr.exe
Pid: 1636
Object-Path: C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe
Status: Visible
Object-Type: Process
Object-Name: rundll32.exe
Pid: 1792
Object-Path: C:\WINDOWS\system32\RUNDLL32.EXE
Status: Visible
Object-Type: Process
Object-Name: UdaterUI.exe
Pid: 1916
Object-Path: C:\Program Files\Network Associates\Common Framework\UdaterUI.exe
Status: Visible
Object-Type: Process
Object-Name: PrevxCSI.exe
Pid: 2288
Object-Path: C:\Program Files\PrevxCSI\prevxcsi.exe
Status: Visible
Object-Type: Process
Object-Name: iexplore.exe
Pid: 3032
Object-Path: C:\Program Files\Internet Explorer\iexplore.exe
Status: Visible
Object-Type: Process
Object-Name: winlogon.exe
Pid: 552
Object-Path: C:\WINDOWS\system32\winlogon.exe
Status: Visible
Object-Type: Process
Object-Name: Mcshield.exe
Pid: 1544
Object-Path: C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
Status: Visible
Object-Type: Process
Object-Name: svchost.exe
Pid: 956
Object-Path: C:\WINDOWS\System32\svchost.exe
Status: Visible
Object-Type: Process
Object-Name: lsass.exe
Pid: 616
Object-Path: C:\WINDOWS\system32\lsass.exe
Status: Visible
Object-Type: Process
Object-Name: svchost.exe
Pid: 988
Object-Path: C:\WINDOWS\system32\svchost.exe
Status: Visible
Object-Type: Process
Object-Name: swdoctor.exe
Pid: 2136
Object-Path: C:\Program Files\Spyware Doctor\swdoctor.exe
Status: Visible
Object-Type: Process
Object-Name: svchost.exe
Pid: 772
Object-Path: C:\WINDOWS\system32\svchost.exe
Status: Visible
Object-Type: Process
Object-Name: nvsvc32.exe
Pid: 1764
Object-Path: C:\WINDOWS\system32\nvsvc32.exe
Status: Visible
Scan complete. Hidden registry keys/values: 21
McAfee® Rootkit Detective 1.1 scan report
On 22-03-2008 at 09:46:13
OS-Version 5.1.2600
Service Pack 2.0
====================================
Object-Type: Registry-value
Object-Name: (Default)
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A04E0F8-DC88-B943-2C7B-226A2C7B226A}\InprocServer32
Status: Unable to access registry key
Object-Type: Registry-value
Object-Name: (Default)
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}\InprocServer32
Status: Unable to access registry key
Object-Type: Registry-value
Object-Name: (Default)
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6802E635-CB18-F544-790D-700BAC51E508}\InprocServer32
Status: Unable to access registry key
Object-Type: Registry-key
Object-Name: Data 2.REN.REN.REN.REN.REN.REN.REN.REN.REN.REND-700BAC51E508}\InprocServer32
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data 2.REN.REN.REN.REN.REN.REN.REN.REN.REN.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: WindowsE\Microsoft\Protected Storage System Provider\*Local Machine*\Data 2.REN.REN.REN.REN.REN.REN.REN.REN.REN.REN
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data 2.REN.REN.REN.REN.REN.REN.REN.REN.REN.REN\Windows
Status: Hidden
Object-Type: Registry-key
Object-Name: Windows.RENcrosoft\Protected Storage System Provider\*Local Machine*\Data 2.REN.REN.REN.REN.REN.REN.REN.REN.REN.REN\Windows
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data 2.REN.REN.REN.REN.REN.REN.REN.REN.REN.REN\Windows.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: Windows.REN.RENoft\Protected Storage System Provider\*Local Machine*\Data 2.REN.REN.REN.REN.REN.REN.REN.REN.REN.REN\Windows.REN
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data 2.REN.REN.REN.REN.REN.REN.REN.REN.REN.REN\Windows.REN.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: Windows.REN.REN.RENProtected Storage System Provider\*Local Machine*\Data 2.REN.REN.REN.REN.REN.REN.REN.REN.REN.REN\Windows.REN.REN
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data 2.REN.REN.REN.REN.REN.REN.REN.REN.REN.REN\Windows.REN.REN.REN
Status: Hidden
Object-Type: Registry-value
Object-Name: Value
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data 2.REN.REN.REN.REN.REN.REN.REN.REN.REN.REN\Windows.REN.REN.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: Data.REN.REN.REN.REN.REN.REN.REN.REN.RENtem Provider\*Local Machine*\Data 2.REN.REN.REN.REN.REN.REN.REN.REN.REN.REN\Windows.REN.REN.REN
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.RENtem Provider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: 00000000-0000-0000-0000-000000000000.RENtem Provider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN000000-0000-0000-0000-000000000000.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: {6340E680-FF06-435f-8767-B79D88AEBD4D}.RENm Provider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN000000-0000-0000-0000-000000000000.REN
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN000000-0000-0000-0000-000000000000.REN\{6340E680-FF06-435f-8767-B79D88AEBD4D}.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: {6340E680-FF06-435f-8767-B79D88AEBD4D}.REN.RENovider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN000000-0000-0000-0000-000000000000.REN\{6340E680-FF06-435f-8767-B79D88AEBD4D}.REN
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN000000-0000-0000-0000-000000000000.REN\{6340E680-FF06-435f-8767-B79D88AEBD4D}.REN.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: {6340E680-FF06-435f-8767-B79D88AEBD4D}.REN.REN.RENer\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN000000-0000-0000-0000-000000000000.REN\{6340E680-FF06-435f-8767-B79D88AEBD4D}.REN.REN
Object-Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider\*Local Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN000000-0000-0000-0000-000000000000.REN\{6340E680-FF06-435f-8767-B79D88AEBD4D}.REN.REN.REN
Status: Hidden
Object-Type: Registry-key
Object-Name: {6340E680-FF06-435f-8767-B79D88AEBD4D}.REN.REN.REN.RENLocal Machine*\Data.REN.REN.REN.REN.REN.REN.REN.REN.REN\a5c5c2e4-6bee-4ef9-a0f5-f76a07cce771.REN000000-0000-0000-0000-000000000000.REN\{6340E680-FF06-435f-8767-B79D88AEB