EXTRA.CAV

EXTRA.CAV

The file extra.cav description is: COMODO Internet Security. The file extra.cav is related to the COMODO. The version of the file extra.cav: 5, 9, 219747, 2195. The extra.cav is a part of software product: COMODO Internet Security LegalCopyright: 2005-2009 COMODO. All rights reserved..
The file extra.cav size is: 192 840 bytes.
Default location: %Program Files%\COMODO\COMODO Internet Security\scanners\extra.cav
extra.cav MD5: AF26443F84C03A23A3F0E66ECE106F54
extra.cav SHA1: 361E9C03 537D1963 F138EFA0 ED4B5A70 F138B0F8

Registry strings in the extra.cav:

MACHINE\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup
MACHINE\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
MACHINE\SOFTWARE\AppDataLow\Software
MACHINE\SOFTWARE\CLSID
MACHINE\SOFTWARE\Licenses
MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components
MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units
MACHINE\SOFTWARE\Microsoft\Command Processor\Autorun
MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars
MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions
MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy
MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar
MACHINE\SOFTWARE\Microsoft\Internet Explorer\UrlSearchHooks
MACHINE\Software\Microsoft\ole
MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\TerminalServer\Install\Software\Microsoft\Windows\CurrentVersion\Run
MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\TerminalServer\Install\Software\Microsoft\Windows\CurrentVersion\Runonce
MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\TerminalServer\Install\Software\Microsoft\Windows\CurrentVersion\RunonceEx
MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInitDLLs
MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Load
MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Run
MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\system
MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UIHost
MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
MACHINE\SOFTWARE\Microsoft\Windows\AppInit
MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths
MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ExplNetProjowser Helper Objects
MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL
MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace
MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace
MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace
MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\NetworkNeighborhood\NameSpace
MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers
MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved
MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes
MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components
MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products
MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Shell
MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
MACHINE\SOFTWARE\Mozilla\Firefox\Extensions
MACHINE\System\CurrentControlSet\Control\BootVerificationProgram\ImageName
MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\AlternateShell
MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment
MACHINE\SYSTEM\CurrentControlSet\Services
MACHINE\System\CurrentControlSet\Services\Control\Session Manager\BootExecute
MACHINE\System\CurrentControlSet\Services\Control\Session Manager\KnownDlls
s\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
s\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
USER\SOFTWARE\AppDataLow\Software
USER\SOFTWARE\Microsoft\Command Processor\Autorun
USER\SOFTWARE\Microsoft\Explorer\Bars
USER\SOFTWARE\Microsoft\Installer\Features
USER\SOFTWARE\Microsoft\Installer\Products
USER\SOFTWARE\Microsoft\Installer\UpgradeCodes
USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars
USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping
USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar
USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ShellBrowser
USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser
USER\SOFTWARE\Microsoft\Internet Explorer\UrlSearchHooks
USER\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates
USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\TerminalServer\Install\Software\Microsoft\Windows\CurrentVersion\Run
USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\TerminalServer\Install\Software\Microsoft\Windows\CurrentVersion\Runonce
USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\TerminalServer\Install\Software\Microsoft\Windows\CurrentVersion\RunonceEx
USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Load
USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Run
USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CLSID
USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats
USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Shell
USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
USER\SOFTWARE\Mozilla\Firefox\Extensions
USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer

The EXTRA.CAV related files:
ADVAPI32.dll KERNEL32.dll ntdll.dll SHLWAPI.dll USER32.DLL

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit is required. Reviews. EULA. Privacy Policy.

Leave a Reply