Сделал портэбл Trojan Remover. Изоляция задана Full - для всего, что связано с прогой. Для всех остальных: папки - Merged, реестр - WriteCopy (поскольку все равно привык сначала проверять, что думает общественность по поводу той или иной записи в реестре, а потом удалять руками, если надо). Проверил на двух компах (ХР SP3), работает, как задумано. Но вот какая проблема. При запуске на компе, где установлен PDF-XChange 4, при сканировании Browser Helper Objects выскакивает ошибка:
Та же версия Trojan Remover, инсталлированная на этом компе, отрабатывает нормально. Process Monitor-ом отследил процесс для обеих прог,
[more=здесь логи]
real
----
1. RegEnumKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects SUCCESS Index: 0, Name: {42DFA04F-0F16-418e-B80C-AB97A5AFAD39}
2. RegEnumKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects SUCCESS Index: 1, Name: {9961627E-4059-41B4-8E0E-A7D6B3854ADF}
3. RegCloseKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects SUCCESS
4. RegOpenKey HKCU\Software\Simply Super Software\Trojan Remover\Scan Preferences SUCCESS Desired Access: Read
5. RegQueryValue HKCU\Software\Simply Super Software\Trojan Remover\Scan Preferences\UseVerifiedFilesList NAME NOT FOUND Length: 144
6. RegCloseKey HKCU\Software\Simply Super Software\Trojan Remover\Scan Preferences SUCCESS
7. FASTIO_NETWORK_QUERY_OPEN C:\Documents and Settings\All Users\Application Data\Simply Super Software\Trojan Remover\Data\trjlist26.dta SUCCESS CreationTime: 22.01.2011 0:03:07, LastAccessTime: 28.03.2011 19:09:18, LastWriteTime: 05.06.2009 13:52:10, ChangeTime: 28.03.2011 19:09:18, AllocationSize: 4 096, EndOfFile: 3 485, FileAttributes: A
8. IRP_MJ_READ C:\$Mft SUCCESS Offset: 18 964 480, Length: 4 096, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O
9. IRP_MJ_CREATE C:\Documents and Settings\All Users\Application Data\Simply Super Software\Trojan Remover\Data\trjlist26.dta SUCCESS Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
10. FASTIO_QUERY_INFORMATION C:\Documents and Settings\All Users\Application Data\Simply Super Software\Trojan Remover\Data\trjlist26.dta SUCCESS Type: QueryStandardInformationFile, AllocationSize: 4 096, EndOfFile: 3 485, NumberOfLinks: 1, DeletePending: False, Directory: False
11. IRP_MJ_READ C:\Documents and Settings\All Users\Application Data\Simply Super Software\Trojan Remover\Data\trjlist26.dta SUCCESS Offset: 0, Length: 3 485
12. IRP_MJ_READ C:\Documents and Settings\All Users\Application Data\Simply Super Software\Trojan Remover\Data\trjlist26.dta SUCCESS Offset: 0, Length: 3 485, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O
13. IRP_MJ_CLEANUP C:\Documents and Settings\All Users\Application Data\Simply Super Software\Trojan Remover\Data\trjlist26.dta SUCCESS
14. RegQueryKey HKCU\Software\Classes SUCCESS Query: Name
15. RegOpenKey HKCU\Software\Classes\CLSID\{42DFA04F-0F16-418e-B80C-AB97A5AFAD39}\InProcServer32 NAME NOT FOUND Desired Access: Read
16. RegOpenKey HKCR\CLSID\{42DFA04F-0F16-418e-B80C-AB97A5AFAD39}\InProcServer32 SUCCESS Desired Access: Read
17. RegQueryKey HKCR\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32 SUCCESS Query: Name
18. RegOpenKey HKCU\Software\Classes\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32 NAME NOT FOUND Desired Access: Maximum Allowed
19. RegQueryValue HKCR\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32\(Default) SUCCESS Type: REG_SZ, Length: 128, Data: C:\Program Files\Tracker Software\PDF-XChange 4\PXCIEAddin4.dll
20. RegQueryKey HKCR\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32 SUCCESS Query: Name
21. RegOpenKey HKCU\Software\Classes\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32 NAME NOT FOUND Desired Access: Maximum Allowed
22. RegQueryValue HKCR\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32\(Default) SUCCESS Type: REG_SZ, Length: 128, Data: C:\Program Files\Tracker Software\PDF-XChange 4\PXCIEAddin4.dll
23. RegQueryKey HKCR\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32 SUCCESS Query: Name
24. RegOpenKey HKCU\Software\Classes\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32 NAME NOT FOUND Desired Access: Maximum Allowed
25. RegQueryValue HKCR\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32\(Default) SUCCESS Type: REG_SZ, Length: 128, Data: C:\Program Files\Tracker Software\PDF-XChange 4\PXCIEAddin4.dll
26. RegQueryKey HKCR\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32 SUCCESS Query: Name
27. RegOpenKey HKCU\Software\Classes\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32 NAME NOT FOUND Desired Access: Maximum Allowed
28. RegQueryValue HKCR\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32\(Default) SUCCESS Type: REG_SZ, Length: 128, Data: C:\Program Files\Tracker Software\PDF-XChange 4\PXCIEAddin4.dll
29. RegQueryKey HKCR\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32 SUCCESS Query: Name
30. RegOpenKey HKCU\Software\Classes\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32 NAME NOT FOUND Desired Access: Maximum Allowed
31. RegQueryValue HKCR\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32\(Default) SUCCESS Type: REG_SZ, Length: 128, Data: C:\Program Files\Tracker Software\PDF-XChange 4\PXCIEAddin4.dll
32. RegQueryKey HKCR\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32 SUCCESS Query: Name
33. RegOpenKey HKCU\Software\Classes\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32 NAME NOT FOUND Desired Access: Maximum Allowed
34. RegQueryValue HKCR\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32\(Default) SUCCESS Type: REG_SZ, Length: 128, Data: C:\Program Files\Tracker Software\PDF-XChange 4\PXCIEAddin4.dll
35. RegCloseKey HKCR\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32 SUCCESS
36. FASTIO_NETWORK_QUERY_OPEN C:\Program Files\Tracker Software\PDF-XChange 4\PXCIEAddin4.dll SUCCESS CreationTime: 15.02.2011 12:49:44, LastAccessTime: 07.03.2011 20:19:17, LastWriteTime: 15.02.2011 12:49:44, ChangeTime: 07.03.2011 20:19:17, AllocationSize: 417 792, EndOfFile: 414 488, FileAttributes: A
virtual
-------
1. RegEnumKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects SUCCESS Index: 0, Name: {42DFA04F-0F16-418e-B80C-AB97A5AFAD39}
2. RegEnumKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects SUCCESS Index: 1, Name: {9961627E-4059-41B4-8E0E-A7D6B3854ADF}
3. RegEnumKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects NO MORE ENTRIES Index: 2, Length: 288
4. RegQueryKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects SUCCESS Query: Cached, SubKeys: 2, Values: 0
5. RegEnumValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects NO MORE ENTRIES Index: 0, Length: 220
6. RegQueryKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects SUCCESS Query: Full, SubKeys: 2, Values: 0
7. RegEnumKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects SUCCESS Index: 0, Name: {42DFA04F-0F16-418e-B80C-AB97A5AFAD39}
8. RegEnumKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects SUCCESS Index: 1, Name: {9961627E-4059-41B4-8E0E-A7D6B3854ADF}
9. RegEnumKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects NO MORE ENTRIES Index: 2, Length: 288
10. RegCloseKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects SUCCESS
11. RegOpenKey HKCU\Software\Simply Super Software\Trojan Remover\Scan Preferences SUCCESS Desired Access: Read
12. RegQueryValue HKCU\Software\Simply Super Software\Trojan Remover\Scan Preferences\UseVerifiedFilesList NAME NOT FOUND Length: 144
13. RegCloseKey HKCU\Software\Simply Super Software\Trojan Remover\Scan Preferences SUCCESS
14. FASTIO_NETWORK_QUERY_OPEN D:\PortableApps\AntivirScan\Trojan Remover 6.8.2\Trojan Remover 6.8.2\%Common AppData%\Simply Super Software\Trojan Remover\Data\trjlist26.dta SUCCESS CreationTime: 28.03.2011 20:49:20, LastAccessTime: 28.03.2011 20:49:20, LastWriteTime: 05.06.2009 13:52:10, ChangeTime: 28.03.2011 20:49:20, AllocationSize: 4 096, EndOfFile: 3 485, FileAttributes: A
15. IRP_MJ_CREATE C:\ SUCCESS Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
16. IRP_MJ_DIRECTORY_CONTROL C:\Documents and Settings SUCCESS Type: QueryDirectory, Filter: Documents and Settings, 2: Documents and Settings
17. IRP_MJ_CLEANUP C:\ SUCCESS
18. IRP_MJ_CLOSE C:\ SUCCESS
19. IRP_MJ_CREATE C:\Documents and Settings SUCCESS Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
20. IRP_MJ_DIRECTORY_CONTROL C:\Documents and Settings\All Users SUCCESS Type: QueryDirectory, Filter: All Users, 2: All Users
21. IRP_MJ_CLEANUP C:\Documents and Settings SUCCESS
22. IRP_MJ_CLOSE C:\Documents and Settings SUCCESS
23. IRP_MJ_CREATE C:\Documents and Settings\All Users SUCCESS Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
24. IRP_MJ_DIRECTORY_CONTROL C:\Documents and Settings\All Users\Application Data SUCCESS Type: QueryDirectory, Filter: Application Data, 2: Application Data
IRP_MJ_CLEANUP C:\Documents and Settings\All Users SUCCESS
25. IRP_MJ_CLOSE C:\Documents and Settings\All Users SUCCESS
26. FASTIO_NETWORK_QUERY_OPEN D:\PortableApps\AntivirScan\Trojan Remover 6.8.2\Trojan Remover 6.8.2\%Common AppData%\Simply Super Software\Trojan Remover\Data\trjlist26.dta SUCCESS CreationTime: 28.03.2011 20:49:20, LastAccessTime: 28.03.2011 20:49:20, LastWriteTime: 05.06.2009 13:52:10, ChangeTime: 28.03.2011 20:49:20, AllocationSize: 4 096, EndOfFile: 3 485, FileAttributes: A
27. IRP_MJ_CREATE D:\PortableApps\AntivirScan\Trojan Remover 6.8.2\Trojan Remover 6.8.2\%Common AppData%\Simply Super Software\Trojan Remover\Data\trjlist26.dta SUCCESS Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
28. FASTIO_QUERY_INFORMATION D:\PortableApps\AntivirScan\Trojan Remover 6.8.2\Trojan Remover 6.8.2\%Common AppData%\Simply Super Software\Trojan Remover\Data\trjlist26.dta SUCCESS Type: QueryStandardInformationFile, AllocationSize: 4 096, EndOfFile: 3 485, NumberOfLinks: 1, DeletePending: False, Directory: False
29. IRP_MJ_READ D:\PortableApps\AntivirScan\Trojan Remover 6.8.2\Trojan Remover 6.8.2\%Common AppData%\Simply Super Software\Trojan Remover\Data\trjlist26.dta SUCCESS Offset: 0, Length: 3 485
30. IRP_MJ_CLEANUP D:\PortableApps\AntivirScan\Trojan Remover 6.8.2\Trojan Remover 6.8.2\%Common AppData%\Simply Super Software\Trojan Remover\Data\trjlist26.dta SUCCESS
31. RegOpenKey HKCU\Software\Classes\CLSID\{42DFA04F-0F16-418e-B80C-AB97A5AFAD39}\InProcServer32 NAME NOT FOUND Desired Access: Maximum Allowed
32. RegQueryKey HKCU\Software\Classes SUCCESS Query: Name
33. RegOpenKey HKCU\Software\Classes\CLSID\{42DFA04F-0F16-418e-B80C-AB97A5AFAD39}\InProcServer32 NAME NOT FOUND Desired Access: Read
34. RegOpenKey HKCR\CLSID\{42DFA04F-0F16-418e-B80C-AB97A5AFAD39}\InProcServer32 SUCCESS Desired Access: Read
35. RegOpenKey HKCU\Software\Classes\CLSID\{42DFA04F-0F16-418e-B80C-AB97A5AFAD39}\InProcServer32 NAME NOT FOUND Desired Access: Query Value
36. RegOpenKey HKCR\CLSID\{42DFA04F-0F16-418e-B80C-AB97A5AFAD39}\InProcServer32 SUCCESS Desired Access: Query Value
37. RegQueryValue HKCR\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32\(Default) SUCCESS Type: REG_SZ, Length: 128, Data: C:\Program Files\Tracker Software\PDF-XChange 4\PXCIEAddin4.dll
38. RegCloseKey HKCR\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32 SUCCESS
39. RegOpenKey HKCU\Software\Classes\CLSID\{42DFA04F-0F16-418e-B80C-AB97A5AFAD39}\InProcServer32 NAME NOT FOUND Desired Access: Query Value
40. RegOpenKey HKCR\CLSID\{42DFA04F-0F16-418e-B80C-AB97A5AFAD39}\InProcServer32 SUCCESS Desired Access: Query Value
41. RegQueryValue HKCR\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32\(Default) SUCCESS Type: REG_SZ, Length: 128, Data: C:\Program Files\Tracker Software\PDF-XChange 4\PXCIEAddin4.dll
42. RegCloseKey HKCR\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32 SUCCESS
43. RegOpenKey HKCU\Software\Classes\CLSID\{42DFA04F-0F16-418e-B80C-AB97A5AFAD39}\InProcServer32 NAME NOT FOUND Desired Access: Query Value
44. RegOpenKey HKCR\CLSID\{42DFA04F-0F16-418e-B80C-AB97A5AFAD39}\InProcServer32 SUCCESS Desired Access: Query Value
45. RegQueryValue HKCR\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32\(Default) SUCCESS Type: REG_SZ, Length: 128, Data: C:\Program Files\Tracker Software\PDF-XChange 4\PXCIEAddin4.dll
46. RegCloseKey HKCR\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32 SUCCESS
47. RegOpenKey HKCU\Software\Classes\CLSID\{42DFA04F-0F16-418e-B80C-AB97A5AFAD39}\InProcServer32 NAME NOT FOUND Desired Access: Query Value
48. RegOpenKey HKCR\CLSID\{42DFA04F-0F16-418e-B80C-AB97A5AFAD39}\InProcServer32 SUCCESS Desired Access: Query Value
49. RegQueryValue HKCR\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32\(Default) SUCCESS Type: REG_SZ, Length: 128, Data: C:\Program Files\Tracker Software\PDF-XChange 4\PXCIEAddin4.dll
50. RegCloseKey HKCR\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32 SUCCESS
51. RegOpenKey HKCU\Software\Classes\CLSID\{42DFA04F-0F16-418e-B80C-AB97A5AFAD39}\InProcServer32 NAME NOT FOUND Desired Access: Query Value
52. RegOpenKey HKCR\CLSID\{42DFA04F-0F16-418e-B80C-AB97A5AFAD39}\InProcServer32 SUCCESS Desired Access: Query Value
53. RegQueryValue HKCR\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32\(Default) SUCCESS Type: REG_SZ, Length: 128, Data: C:\Program Files\Tracker Software\PDF-XChange 4\PXCIEAddin4.dll
54. RegCloseKey HKCR\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32 SUCCESS
55. RegCloseKey HKCR\CLSID\{42DFA04F-0F16-418E-B80C-AB97A5AFAD39}\InprocServer32 SUCCESS
56. FASTIO_NETWORK_QUERY_OPEN D:\PortableApps\AntivirScan\Trojan Remover 6.8.2\Coftware\Classes\CLSID\{42DFA04F-0F16-418e-B80C-AB97A5AFAD39}\In PATH NOT FOUND
одинаковые для всех строк колонки убрал
[/more].
Видно, что инсталлированный Trojan Remover, как и положено, обращается к файлу PXCIEAddin4.dll, в то время как портэбл к несуществующему и непонятно откуда взявшемуся ...\Coftware\Classes\CLSID\{42DFA04F-0F16-418e-B80C-AB97A5AFAD39}\In!
Хотелось бы очень понять в чем проблема? Я неправильно что-то сделал или это, может быть, какой-то принципиальный глюк?