Tech Support banner

Status
Not open for further replies.
1 - 20 of 50 Posts

·
Registered
Joined
·
28 Posts
Discussion Starter #1 (Edited)
I've searched and downloaded for days trying to rid myself of countless problems my computer seems to be encountering, but with little success.
I've run or installed Ad-aware, SpyBot, SpywareBlaster, the BitDefender online virus scan, McAfee Stinger antivirus, Microsoft's Antispyware tool (which no longer works, for some reason), CCleaner, aboutbuster5, kill2me, cwshredder, the Zone Alarm Firewall, and several other programs which ultimately either failed to work, screwed up my computer further, or would not install in the first place.

I have recently been getting the infamous blue screen of death after logging on for a few seconds, though only sometimes.
Random freezing has been a problem for as long as I can remember. Normally when using explorer or switching between programs.
Explorer also closes down randomly when I try to access Control Panel.
Windows Update will not work, and the XP Service Pack 2 will not install. I have also had difficulties installing the latest version of DirectX 9.
I'm almost postive a number of malware programs still exist despite my best efforts.
There are four accounts on this computer, one for each member of our family. Some seem more stable than others. I've fiddled around in all of them.

Now, I am tired and defeated.
I downloaded HJT, closing the browsers and programs that I could, saved the log, then used the KRC log analyzer as recommended. I am a high school student who desperately needs a functioning computer for schoolwork, so I would be eternally grateful if aid came quickly.
So here's the log.

==========================================================

==========
Log was analyzed using KRC HijackThis Analyzer - Updated

on 8/4/05
Get updates at http://www.greyknight17.com/download.

htm#programs

***Security Programs Detected***


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

~~~~~~~~~~

Logfile of HijackThis v1.99.1
Scan saved at 3:24:07 PM, on 09/24/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\javascript.exe
C:\WINDOWS\surfmonkey\SMProxy.exe

R1 - HKCU\Software\Microsoft\Internet

Explorer\Main,Default_Page_URL = http://start.earthlink.

net
R1 - HKCU\Software\Microsoft\Internet

Explorer\Main,Default_Search_URL = http://www.earthlink.

net/partner/more/msie/button/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search

Bar = http://start.earthlink.net/AL/Search
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search

Page = http://www.earthlink.net/partner/more/msie/button/

search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start

Page = http://start.earthlink.net/
R1 -

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet

Settings,ProxyServer = http=127.0.0.1:9022
R0 - HKCU\Software\Microsoft\Internet

Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {44F9B173-041C-4825-A9B9-

D914BD9DCBB3} - (no file)
R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-

00C04FD64497} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0

B3} - (no file)
O2 - BHO: EarthLink ScamBlocker V2 - {15F4D456-5BAA-4076-

8486-EECB38CD3E57} - C:\Program Files\EarthLink

TotalAccess\Toolbar\EScamBlk.dll
O2 - BHO: (no name) - {325743F1-AC42-8FC2-61BF-800DF38DA

59A} - (no file)
O2 - BHO: (no name) - {49D9335A-9217-21C7-D159-61550CAD2E

19} - (no file)
O2 - BHO: EarthLink PopUp Blocker V2 - {512ACF1B-64D9-

4928-B382-A80556F28DB4} - C:\Program Files\EarthLink

TotalAccess\Toolbar\ElnkPuB.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D

7942484F} - (no file)
O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-

001234567890} - (no file)
O2 - BHO: (no name) - {64ED9819-78A5-0F24-8681-564047ECFA

9E} - (no file)
O2 - BHO: (no name) - {656EC4B7-072B-4698-B504-2A414C1F

0037} - (no file)
O2 - BHO: Earthlink Protection BHO - {9579D574-D4D8-4335-

9560-FE8641A013BD} - C:\Program Files\EarthLink

TotalAccess\Toolbar\ProtctIE.dll
O2 - BHO: Uninstall Legacy Earthlink Toolbar - {E713904C-

DF05-4C79-BBAD-02DB923253BE} - C:\Program Files\EarthLink

TotalAccess\Toolbar\uninsttb.dll
O2 - BHO: (no name) - {FFF4E223-7019-4ce7-BE03-D7D3C8CCE

884} - (no file)
O4 - HKLM\..\Run: [EPSON Stylus C82 Series (Copy 1)] C:

\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE /P32

"EPSON Stylus C82 Series (Copy 1)" /O6 "USB001" /M "Stylus

C82"
O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System

32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus

CX5400" /O6 "USB003" /M "Stylus CX5400"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program

Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1

\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common

Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [time] time.exe
O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live

Update 3\LMonitor.exe
O4 - HKLM\..\Run: [lux] C:\WINDOWS\System32\jjxgz.exe
O4 - HKLM\..\Run: [Media-XP-Service-Pack3] msnzx.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system

32\dumprep 0 -k
O4 - HKLM\..\Run: [ELNKProxy] C:

\WINDOWS\surfmonkey\smproxy.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone

Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\RunServices: [time] time.exe
O4 - HKLM\..\RunServices: [Media-XP-Service-Pack3] msnzx.

exe
O4 - HKCU\..\Run: [SOProc_RegWxSzNn] rundll32 shell32.

dll,ShellExec_RunDLL C:\PROGRA~1\SOFTWA~1\soproc.exe -pack

RegWxSzNn
O4 - HKCU\..\Run: [time] time.exe
O4 - HKCU\..\Run: [Media-XP-Service-Pack3] msnzx.exe
O4 - HKCU\..\Run: [DNS] C:\Program Files\Common Files\mc-

58-12-0000133.exe
O4 - HKCU\..\RunServices: [Media-XP-Service-Pack3] msnzx.

exe
O7 -

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Sy

stem, DisableRegedit=1
O8 - Extra context menu item: &Viewpoint Search - res://C

:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/

CXTSEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-

00401C608501} - C:\Program Files\Java\jre1.5.0_04

\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0

-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre

1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-

0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online

Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %

windir%\bdoscandel.exe (file missing)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows

Genuine Advantage Validation Tool) - http://go.microsoft.

com/fwlink/?linkid=39204
O16 - DPF: {4E330863-6A11-11D0-BFD8-006097237877} - http

://tw.msi.com.tw/autobios/client/iftwclix.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (

BDSCANONLINE Control) - http://www.bitdefender.com/scan8/

oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (

WUWebControl Class) - http://update.microsoft.com/

windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?

1126740081864
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (

MUWebControl Class) - http://update.microsoft.com/

microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.

cab?1126740173915
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (

ICSScanner Class) - http://download.zonelabs.com/bin/

promotions/spywaredetector/ICSScanner37320.cab
O23 - Service: EarthLink Monitor Service (

EarthLinkMonitor) - Boingo Wireless, Inc. - C:\Program

Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
O23 - Service: Hardware Clock Driver (hwclock) - Unknown

owner - C:\WINDOWS\System32\hwclock.exe
O23 - Service: Enables Javascript Support (Javascript) -

Unknown owner - C:\WINDOWS\System32\javascript.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone

Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe


End of KRC HijackThis Analyzer Log.
==========================================================

==========
 

·
Registered
Joined
·
28 Posts
Discussion Starter #2
It occured to me that the above log was taken while I was running in Safe Mode.
I do not know if that would cause anything to act differently, but to be safe, I restarted in normal mode and took another log.
I will post it here.

====================================================================
Log was analyzed using KRC HijackThis Analyzer - Updated on 8/4/05
Get updates at http://www.greyknight17.com/download.htm#programs

***Security Programs Detected***

C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Logfile of HijackThis v1.99.1
Scan saved at 4:23:51 PM, on 09/24/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM32\ati2sgag.exe
C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
C:\WINDOWS\System32\javascript.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\MSI\Live Update 3\LMonitor.exe
C:\WINDOWS\System32\jjxgz.exe
C:\WINDOWS\System32\msnzx.exe
C:\WINDOWS\surfmonkey\smproxy.exe
C:\Program Files\Common Files\services.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.earthlink.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink.net/partner/more/msie/button/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://start.earthlink.net/AL/Search
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.earthlink.net/partner/more/msie/button/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.earthlink.net/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9022
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {44F9B173-041C-4825-A9B9-D914BD9DCBB3} - (no file)
R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: EarthLink ScamBlocker V2 - {15F4D456-5BAA-4076-8486-EECB38CD3E57} - C:\Program Files\EarthLink TotalAccess\Toolbar\EScamBlk.dll
O2 - BHO: (no name) - {325743F1-AC42-8FC2-61BF-800DF38DA59A} - (no file)
O2 - BHO: (no name) - {49D9335A-9217-21C7-D159-61550CAD2E19} - (no file)
O2 - BHO: EarthLink PopUp Blocker V2 - {512ACF1B-64D9-4928-B382-A80556F28DB4} - C:\Program Files\EarthLink TotalAccess\Toolbar\ElnkPuB.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-001234567890} - (no file)
O2 - BHO: (no name) - {64ED9819-78A5-0F24-8681-564047ECFA9E} - (no file)
O2 - BHO: (no name) - {656EC4B7-072B-4698-B504-2A414C1F0037} - (no file)
O2 - BHO: Earthlink Protection BHO - {9579D574-D4D8-4335-9560-FE8641A013BD} - C:\Program Files\EarthLink TotalAccess\Toolbar\ProtctIE.dll
O2 - BHO: Uninstall Legacy Earthlink Toolbar - {E713904C-DF05-4C79-BBAD-02DB923253BE} - C:\Program Files\EarthLink TotalAccess\Toolbar\uninsttb.dll
O2 - BHO: (no name) - {FFF4E223-7019-4ce7-BE03-D7D3C8CCE884} - (no file)
O4 - HKLM\..\Run: [EPSON Stylus C82 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE /P32 "EPSON Stylus C82 Series (Copy 1)" /O6 "USB001" /M "Stylus C82"
O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB003" /M "Stylus CX5400"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [time] time.exe
O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe
O4 - HKLM\..\Run: [lux] C:\WINDOWS\System32\jjxgz.exe
O4 - HKLM\..\Run: [Media-XP-Service-Pack3] msnzx.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ELNKProxy] C:\WINDOWS\surfmonkey\smproxy.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\RunServices: [time] time.exe
O4 - HKLM\..\RunServices: [Media-XP-Service-Pack3] msnzx.exe
O4 - HKCU\..\Run: [SOProc_RegWxSzNn] rundll32 shell32.dll,ShellExec_RunDLL C:\PROGRA~1\SOFTWA~1\soproc.exe -pack RegWxSzNn
O4 - HKCU\..\Run: [time] time.exe
O4 - HKCU\..\Run: [DNS] C:\Program Files\Common Files\mc-58-12-0000133.exe
O4 - HKCU\..\Run: [Media-XP-Service-Pack3] msnzx.exe
O4 - HKCU\..\RunServices: [Media-XP-Service-Pack3] msnzx.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4E330863-6A11-11D0-BFD8-006097237877} - http://tw.msi.com.tw/autobios/client/iftwclix.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1126740081864
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1126740173915
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner37320.cab
O23 - Service: EarthLink Monitor Service (EarthLinkMonitor) - Boingo Wireless, Inc. - C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
O23 - Service: Hardware Clock Driver (hwclock) - Unknown owner - C:\WINDOWS\System32\hwclock.exe
O23 - Service: Enables Javascript Support (Javascript) - Unknown owner - C:\WINDOWS\System32\javascript.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe


End of KRC HijackThis Analyzer Log.
====================================================================
 

·
TSF Security Manager, Emeritus
Joined
·
42,837 Posts
Hello Heroic and welcome to TSF,

Please print out or copy this page to Notepad since you will not have any of browsers open while you are fixing this. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. Again, you should not have any open browsers when you are following the procedures below.

Please make sure system restore is enabled by right clicking on My Computer and go to Properties->System Restore and check the box for Turn OFF System Restore and make sure it’s NOT checked. We want system restore ON and monitoring your current hard drive. Once your clean we will turn this off and then back on to remove the infection from the restore folder and create a clean restore point.

Please download Ewido Security Suite at http://www.ewido.net/en/download/.

1. Install Ewido Security Suite.
2. When installing, under 'Additional Options' uncheck:
* Install background guard
* Install scan via context menu
3. Launch Ewido, there should be an icon on your desktop, double click it.
4. The program will now open to the main screen.
5. When you run Ewido for the first time, you will get a warning 'Database could not be found!'. Click OK. We will fix this in a moment.
6. You will need to update Ewido to the latest definition files.
* On the left hand side of the main screen click update.
* Then click on Start Update.
7. The update will start and a progress bar will show the updates being installed. The status bar at the bottom will display 'Update successful'.
8. Exit Ewido. DO NOT scan yet.

If you are having problems with the updater, you can go to http://www.ewido.net/en/download/updates/ to update manually.

Download CleanUp! (Alternate Link if main link doesn't work) and install it. Do not run it yet.

Go to My Computer->Tools->Folder Options->View tab:
* Under the Hidden files and folders heading, select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm and then click OK.

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

Go into Hijack This->Config->Misc. Tools->Open process manager. Select the following and click “Kill process” for each one if they are still listed (they shouldn't be - but double check it):(You must kill them one at a time).

C:\WINDOWS\System32\jjxgz.exe
C:\WINDOWS\System32\msnzx.exe
C:\WINDOWS\surfmonkey\smproxy.exe
C:\Program Files\Common Files\services.exe


Uninstall the following via the Add/Remove Panel (Start->(Settings)->Control Panel->Add/Remove Programs) if they exist:

Viewpoint

1. Go to Start > Run and type in Services.msc then click OK
2. Click the Extended tab.
3. Scroll down until you find the service.
===> Hardware Clock Driver (hwclock)
4. Click once on the service to highlight it.
5. Click Stop
6. Right-Click on the service.
7. Click on 'Properties'
8. Select the 'General' tab
9. Click the Arrow-down tab on the right-hand side on the 'Start-up Type' box
10. From the drop-down menu, click on 'Disabled'
11. Click the 'Apply' tab, then click 'OK'

Now, while still in Services.msc, look for the following entry:

Service: Enables Javascript Support (Javascript)
Repeat the above steps for this entry as well.

Open HijackThis>Config>Misc Tools>Delete an NT Service. Copy/paste the following entries into the box, (one at a time) and click Ok:

hwclock
Javascript


Run a scan in HijackThis. Check each of the following and hit 'Fix checked' (after checking them) if they still exist (make sure not to miss any):

R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: (no name) - {325743F1-AC42-8FC2-61BF-800DF38DA59A} - (no file)
O2 - BHO: (no name) - {49D9335A-9217-21C7-D159-61550CAD2E19} - (no file)
O2 - BHO: (no name) - {64ED9819-78A5-0F24-8681-564047ECFA9E} - (no file)
O2 - BHO: (no name) - {FFF4E223-7019-4ce7-BE03-D7D3C8CCE884} - (no file)
O4 - HKLM\..\Run: [time] time.exe
O4 - HKLM\..\Run: [lux] C:\WINDOWS\System32\jjxgz.exe
O4 - HKLM\..\Run: [Media-XP-Service-Pack3] msnzx.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ELNKProxy] C:\WINDOWS\surfmonkey\smproxy.exe
O4 - HKLM\..\RunServices: [Media-XP-Service-Pack3] msnzx.exe
O4 - HKCU\..\Run: [SOProc_RegWxSzNn] rundll32 shell32.dll,ShellExec_RunDLL C:\PROGRA~1\SOFTWA~1\soproc.exe -pack RegWxSzNn
O4 - HKCU\..\Run: [time] time.exe
O4 - HKCU\..\Run: [DNS] C:\Program Files\Common Files\mc-58-12-0000133.exe
O4 - HKCU\..\Run: [Media-XP-Service-Pack3] msnzx.exe
O4 - HKCU\..\RunServices: [Media-XP-Service-Pack3] msnzx.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Pol icies\System, DisableRegedit=1
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O23 - Service: Hardware Clock Driver (hwclock) - Unknown owner - C:\WINDOWS\System32\hwclock.exe
O23 - Service: Enables Javascript Support (Javascript) - Unknown owner - C:\WINDOWS\System32\javascript.exe


Delete the following Files and Folders if they still exist.

C:\WINDOWS\System32\jjxgz.exe
C:\WINDOWS\System32\msnzx.exe
C:\PROGRA~1\SOFTWA~1
C:\WINDOWS\surfmonkey
C:\Program Files\Common Files\services.exe
C:\Program Files\Common Files\mc-58-12-0000133.exe
C:\Program Files\Viewpoint
C:\WINDOWS\System32\hwclock.exe
C:\WINDOWS\System32\javascript.exe
Search for the following file via Start>Search and delete:
time.exe

CleanUp! deletes EVERYTHING out of your temp/temporary folders, it does not make backups. If you have any documents or programs that are saved in any Temporary Folders, please make a backup of these before running CleanUp!.

Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows:
*Click "Options..."
*Move the arrow down to "Custom CleanUp!"
*Put a check next to the following:
-Empty Recycle Bins
-Temporary Internet Files
-Delete Cookies
-Delete Prefetch files
-[X]Scan local drives for temporary files (Please uncheck this option)
-Cleanup! All Users
Click OK
Press the CleanUp! button to start the program. Reboot/logoff when prompted.

Reboot back into Safe Mode.

Run Ewido:
*Click [Scanner]
*Click [Complete System Scan] to begin scanning.
*Click [OK] when prompted to clean files

With the first file it prompts to clean, select the option - "Perform action on all infections" - & choose clean and click [OK].

Once finished, click the [Save report] button
Save the report to your desktop
Close Ewido

Reboot into Normal Mode. Run another scan with HijackThis and post the log here along with the results of the Ewido Scan.
 

·
Registered
Joined
·
28 Posts
Discussion Starter #4 (Edited)
Followed directions as closely as I could.
When I ran services.msc I could not find the Hardware Clock Driver.
Proceeded beyond that point as per normal until I used HJT to "Fix checked". hwclock.exe and javascript.exe were not present in the list, so I assumed them already dealt with and continued.
Everything past that point went smoothly.

Here is the HJT log and Ewido log you asked for.

==========================================================

==========
Log was analyzed using KRC HijackThis Analyzer - Updated

on 8/4/05
Get updates at http://www.greyknight17.com/download.

htm#programs

***Security Programs Detected***

C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

~~~~~~~~~~

Logfile of HijackThis v1.99.1
Scan saved at 1:40:30 PM, on 09/25/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM32\ati2sgag.exe
C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.

exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\MSI\Live Update 3\LMonitor.exe

R1 - HKCU\Software\Microsoft\Internet

Explorer\Main,Default_Page_URL = http://start.earthlink.

net
R1 - HKCU\Software\Microsoft\Internet

Explorer\Main,Default_Search_URL = http://www.earthlink.

net/partner/more/msie/button/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search

Bar = http://start.earthlink.net/AL/Search
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search

Page = http://www.earthlink.net/partner/more/msie/button/

search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start

Page = http://start.earthlink.net/
R1 -

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet

Settings,ProxyServer = http=127.0.0.1:9022
R0 - HKCU\Software\Microsoft\Internet

Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {44F9B173-041C-4825-A9B9-

D914BD9DCBB3} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0

B3} - (no file)
O2 - BHO: EarthLink ScamBlocker V2 - {15F4D456-5BAA-4076-

8486-EECB38CD3E57} - C:\Program Files\EarthLink

TotalAccess\Toolbar\EScamBlk.dll
O2 - BHO: EarthLink PopUp Blocker V2 - {512ACF1B-64D9-

4928-B382-A80556F28DB4} - C:\Program Files\EarthLink

TotalAccess\Toolbar\ElnkPuB.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D

7942484F} - (no file)
O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-

001234567890} - (no file)
O2 - BHO: (no name) - {656EC4B7-072B-4698-B504-2A414C1F

0037} - (no file)
O2 - BHO: Earthlink Protection BHO - {9579D574-D4D8-4335-

9560-FE8641A013BD} - C:\Program Files\EarthLink

TotalAccess\Toolbar\ProtctIE.dll
O2 - BHO: Uninstall Legacy Earthlink Toolbar - {E713904C-

DF05-4C79-BBAD-02DB923253BE} - C:\Program Files\EarthLink

TotalAccess\Toolbar\uninsttb.dll
O4 - HKLM\..\Run: [EPSON Stylus C82 Series (Copy 1)] C:

\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE /P32

"EPSON Stylus C82 Series (Copy 1)" /O6 "USB001" /M "Stylus

C82"
O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System

32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus

CX5400" /O6 "USB003" /M "Stylus CX5400"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program

Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1

\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common

Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live

Update 3\LMonitor.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone

Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\RunServices: [time] time.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-

00401C608501} - C:\Program Files\Java\jre1.5.0_04

\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0

-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre

1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-

0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online

Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %

windir%\bdoscandel.exe (file missing)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows

Genuine Advantage Validation Tool) - http://go.microsoft.

com/fwlink/?linkid=39204
O16 - DPF: {4E330863-6A11-11D0-BFD8-006097237877} - http

://tw.msi.com.tw/autobios/client/iftwclix.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (

BDSCANONLINE Control) - http://www.bitdefender.com/scan8/

oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (

WUWebControl Class) - http://update.microsoft.com/

windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?

1126740081864
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (

MUWebControl Class) - http://update.microsoft.com/

microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.

cab?1126740173915
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (

ICSScanner Class) - http://download.zonelabs.com/bin/

promotions/spywaredetector/ICSScanner37320.cab
O23 - Service: EarthLink Monitor Service (

EarthLinkMonitor) - Boingo Wireless, Inc. - C:\Program

Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
O23 - Service: ewido security suite control - ewido

networks - C:\Program Files\ewido\security

suite\ewidoctrl.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone

Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe


End of KRC HijackThis Analyzer Log.
==========================================================

==========







---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 1:33:06 PM, 09/25/2005
+ Report-Checksum: EF5B2942

+ Scan result:

HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Spyware.WebRebates : Cleaned with backup
HKU\S-1-5-21-796845957-2049760794-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-59D4-4008-9058-080011001200} -> Spyware.VX2 : Cleaned with backup
HKU\S-1-5-21-796845957-2049760794-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-DD60-0064-6EC2-6E0100000000} -> Spyware.MediaMotor : Cleaned with backup
HKU\S-1-5-21-796845957-2049760794-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000010-6F7D-442C-93E3-4A4827C2E4C8} -> Spyware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-21-796845957-2049760794-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000EF1-0786-4633-87C6-1AA7A44296DA} -> Spyware.FavoriteMan : Cleaned with backup
HKU\S-1-5-21-796845957-2049760794-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00320615-B6C2-40A6-8F99-F1C52D674FAD} -> Spyware.Transponder : Cleaned with backup
HKU\S-1-5-21-796845957-2049760794-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01F44A8A-8C97-4325-A378-76E68DC4AB2E} -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-796845957-2049760794-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{120E090D-9136-4B78-8258-F0B44B4BD2AC} -> Spyware.Maxspeed : Cleaned with backup
HKU\S-1-5-21-796845957-2049760794-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{205FF73B-CA67-11D5-99DD-444553540006} -> Spyware.CnsMin : Cleaned with backup
HKU\S-1-5-21-796845957-2049760794-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{339BB23F-A864-48C0-A59F-29EA915965EC} -> Spyware.HuntBar : Cleaned with backup
HKU\S-1-5-21-796845957-2049760794-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{386A771C-E96A-421F-8BA7-32F1B706892F} -> Spyware.ISTBar : Cleaned with backup
HKU\S-1-5-21-796845957-2049760794-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Spyware.NewDotNet : Cleaned with backup
HKU\S-1-5-21-796845957-2049760794-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6685509E-B47B-4F47-8E16-9A5F3A62F683} -> Spyware.MoneyMaker : Cleaned with backup
HKU\S-1-5-21-796845957-2049760794-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{669695BC-A811-4A9D-8CDF-BA8C795F261C} -> Spyware.PowerStrip : Cleaned with backup
HKU\S-1-5-21-796845957-2049760794-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6A6E50DC-BFA8-4B40-AB1B-159E03E829FD} -> Spyware.LinkReplacer : Cleaned with backup
HKU\S-1-5-21-796845957-2049760794-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7C559105-9ECF-42B8-B3F7-832E75EDD959} -> Spyware.ISTBar : Cleaned with backup
HKU\S-1-5-21-796845957-2049760794-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{87766247-311C-43B4-8499-3D5FEC94A183} -> Spyware.HuntBar : Cleaned with backup
HKU\S-1-5-21-796845957-2049760794-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8952A998-1E7E-4716-B23D-3DBE03910972} -> Spyware.HuntBar : Cleaned with backup
HKU\S-1-5-21-796845957-2049760794-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC378B83-9577-44D0-B4F8-0DD965E176FC} -> Spyware.Esyndicate : Cleaned with backup
C:\Documents and Settings\Chuck Owens\Application Data\Earthlink\6.0\[email protected]\Cookies\chuck [email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Chuck Owens\Application Data\Earthlink\6.0\[email protected]\Cookies\chuck [email protected][2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Chuck Owens\Application Data\Earthlink\6.0\[email protected]\Cookies\chuck [email protected][1].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Documents and Settings\Chuck Owens\Application Data\Earthlink\6.0\[email protected]\Cookies\chuck [email protected][2].txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\Chuck Owens\Application Data\Earthlink\6.0\[email protected]\Cookies\chuck [email protected][2].txt -> Spyware.Cookie.Popuptraffic : Cleaned with backup
C:\Documents and Settings\Chuck Owens\Application Data\Earthlink\6.0\[email protected]\Cookies\chuck [email protected][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Chuck Owens\Application Data\Earthlink\6.0\[email protected]\Cookies\chuck [email protected][1].txt -> Spyware.Cookie.Clickhype : Cleaned with backup
C:\Documents and Settings\Chuck Owens\Application Data\Earthlink\6.0\[email protected]\Cookies\chuck [email protected][2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Chuck Owens\Application Data\Earthlink\6.0\[email protected]\Cookies\chuck [email protected][1].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Documents and Settings\Chuck Owens\Application Data\Earthlink\6.0\[email protected]\Cookies\chuck [email protected][2].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\Chuck Owens\Application Data\Earthlink\6.0\[email protected]\Cookies\chuck [email protected][1].txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\Chuck Owens\msdirectx.sys -> Trojan.Rootkit.h : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\gka8h9m9.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\gka8h9m9.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Mary\msdirectx.sys -> Trojan.Rootkit.h : Cleaned with backup
C:\Documents and Settings\Matthrew\Application Data\Earthlink\6.0\[email protected]\Cookies\[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Matthrew\Application Data\Earthlink\6.0\[email protected]\Cookies\[email protected][2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Matthrew\Application Data\Earthlink\6.0\[email protected]\Cookies\[email protected][1].txt -> Spyware.Cookie.Masterstats : Cleaned with backup
C:\Documents and Settings\Matthrew\Application Data\Earthlink\6.0\[email protected]\Cookies\[email protected][2].txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\Matthrew\Application Data\Earthlink\6.0\[email protected]\Cookies\[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Matthrew\Application Data\Earthlink\6.0\[email protected]\Cookies\[email protected][2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Matthrew\Application Data\Earthlink\6.0\[email protected]\Cookies\[email protected][1].txt -> Spyware.Cookie.Masterstats : Cleaned with backup
C:\Documents and Settings\Matthrew\Application Data\Earthlink\6.0\[email protected]\Cookies\[email protected][1].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Documents and Settings\Matthrew\Application Data\Earthlink\6.0\[email protected]\Cookies\[email protected][1].txt -> Spyware.Cookie.Popularix : Cleaned with backup
C:\Documents and Settings\Matthrew\Application Data\Earthlink\6.0\[email protected]\Cookies\[email protected][2].txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.100:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.104:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.105:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.122:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.137:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.138:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.150:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.151:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.152:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.153:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.154:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.155:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.156:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.157:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.161:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.162:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.164:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.165:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.172:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.173:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.193:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.194:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.195:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.196:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.197:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.200:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Estat : Cleaned with backup
:mozilla.257:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Ivwbox : Cleaned with backup
:mozilla.306:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.307:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.312:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.313:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Popularix : Cleaned with backup
:mozilla.314:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
:mozilla.315:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
:mozilla.316:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
:mozilla.317:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
:mozilla.333:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.337:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.338:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.339:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.340:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.353:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.354:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.355:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.369:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.403:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.404:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.405:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.406:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.407:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.408:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.436:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.7search : Cleaned with backup
:mozilla.437:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.7search : Cleaned with backup
:mozilla.438:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.7search : Cleaned with backup
:mozilla.439:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.7search : Cleaned with backup
:mozilla.443:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.444:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.445:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.446:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.447:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.448:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.463:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.471:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.472:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.491:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.492:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.493:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.494:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.495:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.505:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.506:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.507:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.508:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.509:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.510:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.533:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
:mozilla.534:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.549:C:\Documents and Settings\Matthrew\Application Data\Mozilla\Firefox\Profiles\2j8ea6de.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
C:\Documents and Settings\Matthrew\msdirectx.sys -> Trojan.Rootkit.h : Cleaned with backup
C:\Program Files\Common Files\services.exe -> Spyware.Maxifiles : Cleaned with backup
C:\Program Files\Common Files\Windows\services32.exe -> Spyware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001032.exe -> TrojanProxy.Agent.gr : Cleaned with backup
C:\WINDOWS\SYSTEM32\.exe -> Backdoor.Small.eo : Cleaned with backup
C:\WINDOWS\SYSTEM32\3DFX32VS.exe -> Spyware.AdSrve : Cleaned with backup
C:\WINDOWS\SYSTEM32\asferror.exe -> Spyware.AdSrve : Cleaned with backup
C:\WINDOWS\SYSTEM32\ati2dvag.exe -> Spyware.VB : Cleaned with backup
C:\WINDOWS\SYSTEM32\avtapi26.exe -> Spyware.UrlSpy : Cleaned with backup
C:\WINDOWS\SYSTEM32\ctfqe.exe -> TrojanProxy.Agent.gr : Cleaned with backup
C:\WINDOWS\SYSTEM32\dbjxn.exe -> TrojanProxy.Agent.gr : Cleaned with backup
C:\WINDOWS\SYSTEM32\dzzlqby.exe -> TrojanProxy.Agent.gr : Cleaned with backup
C:\WINDOWS\SYSTEM32\eacqahz.exe -> TrojanProxy.Agent.gr : Cleaned with backup
C:\WINDOWS\SYSTEM32\eljinmlx.exe -> TrojanProxy.Agent.gr : Cleaned with backup
C:\WINDOWS\SYSTEM32\gxlbuli.exe -> TrojanProxy.Agent.gr : Cleaned with backup
C:\WINDOWS\SYSTEM32\in10b6.dll -> Adware.eZula : Cleaned with backup
C:\WINDOWS\SYSTEM32\jbtbvjiy.exe -> TrojanProxy.Agent.gr : Cleaned with backup
C:\WINDOWS\SYSTEM32\jtkcfmcg.exe -> TrojanProxy.Agent.gr : Cleaned with backup
C:\WINDOWS\SYSTEM32\jtzeggr.exe -> TrojanProxy.Agent.gr : Cleaned with backup
C:\WINDOWS\SYSTEM32\kvgev.exe -> TrojanProxy.Agent.gr : Cleaned with backup
C:\WINDOWS\SYSTEM32\lhqfncw.exe -> TrojanProxy.Agent.gr : Cleaned with backup
C:\WINDOWS\SYSTEM32\qmqqtb.exe -> TrojanProxy.Agent.gr : Cleaned with backup
C:\WINDOWS\SYSTEM32\qtzlqjp.exe -> TrojanProxy.Agent.gr : Cleaned with backup
C:\WINDOWS\SYSTEM32\rfbwgdo.exe -> TrojanProxy.Agent.gr : Cleaned with backup
C:\WINDOWS\SYSTEM32\soqh.exe -> TrojanProxy.Agent.gr : Cleaned with backup
C:\WINDOWS\SYSTEM32\sxzr.exe -> TrojanProxy.Agent.gr : Cleaned with backup
C:\WINDOWS\SYSTEM32\terpy.exe -> TrojanProxy.Agent.gr : Cleaned with backup
C:\WINDOWS\SYSTEM32\ttci.exe -> TrojanProxy.Agent.gr : Cleaned with backup
C:\WINDOWS\SYSTEM32\tvmk1.dll -> TrojanDropper.Small.ly : Cleaned with backup
C:\WINDOWS\SYSTEM32\umqltg4cl.ini -> Adware.SAHA : Cleaned with backup
C:\WINDOWS\SYSTEM32\vjzt.exe -> TrojanProxy.Agent.gr : Cleaned with backup
C:\WINDOWS\SYSTEM32\znpokmqj.exe -> TrojanProxy.Agent.gr : Cleaned with backup
D:\Recycled\Dd101.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
D:\Recycled\Dd102.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
D:\Recycled\Dd106.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
D:\Recycled\Dd107.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
D:\Recycled\Dd118.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
D:\Recycled\Dd128.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
D:\Recycled\Dd132.txt -> Spyware.Cookie.Advertising : Cleaned with backup
D:\Recycled\Dd133.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
D:\Recycled\Dd134.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
D:\Recycled\Dd138.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
D:\Recycled\Dd144.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
D:\Recycled\Dd89.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
D:\Recycled\Dd90.txt -> Spyware.Cookie.Advertising : Cleaned with backup
D:\Recycled\Dd94.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
D:\Recycled\Dd95.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
D:\Recycled\Dd96.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
D:\Recycled\Dd99.txt -> Spyware.Cookie.Com : Cleaned with backup
D:\WINDOWS\PCTPTT.EXE -> Dialer.Generic : Cleaned with backup


::Report End






Edit: It seems ZoneAlarm has mysteriously ceased to function. This is causing me a due amount of distress, seeing as that means I have no firewall up now. Whenever I try to run it, it simply states "ZoneAlarm is initializing" in a small message screen, then causes my computer to slow down noticably, then quits.
 

·
TSF Security Manager, Emeritus
Joined
·
42,837 Posts
Hi Heroic,

Let's try this entry again:

Reboot into Safe Mode.

Run a scan in HijackThis. Check each of the following and hit 'Fix checked' (after checking them) if they still exist (make sure not to miss any):

O4 - HKLM\..\RunServices: [time] time.exe

Now search for and delete this file: time.exe

Reboot into Normal Mode.

Perform an online scan using Internet Explorer with Panda ActiveScan - requires Internet Explorer

  1. Click on the Scan your PC button & a 'pop up' window shall appear. * ensure that your pop up blocker doesn't block it
  2. Click On 'Scan Now'
  3. Enter your e-mail address & click 'Scan Now' ...begins downloading Panda's ActiveX controls.- 8MB
  4. Begin the scan by selecting My Computer
    * You needn't remain online while it's doing the scan but you have to re-connect after it has finished to see the report.
  5. If it finds any malware, it will offer you a report. Click on see report
  6. Then click Save report
  7. Post the contents of the report in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan

Run another scan with HijackThis and post the log here. (Please turn WordWrap Off in Notepad, it's very difficult to read your log in that format. :smile: )
 

·
Registered
Joined
·
28 Posts
Discussion Starter #6
Delay

Tried to do the Panda ActiveScan last night, but it crashed about 60% of the way through.
Just got home from school, so I'm going to run it again. I'll post again in a couple hours when or if it finishes.
 

·
TSF Security Manager, Emeritus
Joined
·
42,837 Posts
If Panda fails again, please do the following:

Please empty any Quarantine folder in your antivirus program and purge all recovery items in the Spybot program (if you use it) before running this tool.

Download the Mwav virus checker at http://www.mwti.net/products/mwav/mwav.asp (Use Link 3)

1. Save it to a folder.
2. Reboot into Safe Mode.
3. Double click the Mwav.exe file. This is a stand alone tool and NOT just a virus checker......so it won't install anything.
4. Select all local drives, scan all files, and press SCAN. When it is completed, anything found will be displayed in the lower pane.
5. In the Virus Log Information Pane......
Left click and highlight all the information in the Lower pane --- Use CTRL C on your keyboard to copy everything found in the lower pane and save it to a notepad file
*Note* If prompted that a virus was found and you need to purchase the product to remove the malware, just close out the prompt and let it continue scanning. We are not going to use this to remove anything...but to ID the bad files.

Once you copy that to a Notepad file...highlight the text and copy it here.
 

·
Registered
Joined
·
28 Posts
Discussion Starter #8
Panda's scan managed to make it through. Thank you for being patient.
Here is the ActiveScan log along with a fresh HJT log.


Incident Status Location

Adware:adware/maxifiles No disinfected C:\PROGRAM FILES\COMMON FILES\system32.dll
Adware:adware/savenow No disinfected Windows Registry
Adware:Adware/IST.ISTBar No disinfected C:\Documents and Settings\Matthrew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-3c936701-7e596b08.zip[InstallerApplet.class]
Possible Virus. No disinfected C:\Matthew\Zips and Setups\awsetup.exe
Possible Virus. No disinfected C:\Program Files\AWClient\awclient.exe
Adware:Adware/Maxifiles No disinfected C:\Program Files\Common Files\InetGet2\mc-58-12-0000133.exe
Adware:Adware/Maxifiles No disinfected C:\Program Files\Common Files\mc-58-12-0000133.exe
Hacktool:HackTool/Rootkit.C No disinfected C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001237.sys
Hacktool:HackTool/Rootkit.C No disinfected C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001238.sys
Hacktool:HackTool/Rootkit.C No disinfected C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001239.sys
Adware:Adware/Maxifiles No disinfected C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001240.exe
Adware:Adware/IEDriver No disinfected C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001243.exe
Adware:Adware/IEDriver No disinfected C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001244.exe
Adware:Adware/IEDriver No disinfected C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001245.exe
Spyware:Spyware/UrlSpy No disinfected C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001246.exe
Adware:Adware/Maxifiles No disinfected C:\WINDOWS\SYSTEM32\mc-58-12-0000133.exe


===================================================================
Log was analyzed using KRC HijackThis Analyzer - Updated on 8/4/05
Get updates at http://www.greyknight17.com/download.htm#programs

***Security Programs Detected***


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Logfile of HijackThis v1.99.1
Scan saved at 5:38:30 PM, on 09/26/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\MSI\Live Update 3\LMonitor.exe
C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
C:\Program Files\VideoLAN\VLC\vlc.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.earthlink.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink.net/partner/more/msie/button/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://start.earthlink.net/AL/Search
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.earthlink.net/partner/more/msie/button/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.earthlink.net/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9022
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {44F9B173-041C-4825-A9B9-D914BD9DCBB3} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: EarthLink ScamBlocker V2 - {15F4D456-5BAA-4076-8486-EECB38CD3E57} - C:\Program Files\EarthLink TotalAccess\Toolbar\EScamBlk.dll
O2 - BHO: EarthLink PopUp Blocker V2 - {512ACF1B-64D9-4928-B382-A80556F28DB4} - C:\Program Files\EarthLink TotalAccess\Toolbar\ElnkPuB.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-001234567890} - (no file)
O2 - BHO: (no name) - {656EC4B7-072B-4698-B504-2A414C1F0037} - (no file)
O2 - BHO: Earthlink Protection BHO - {9579D574-D4D8-4335-9560-FE8641A013BD} - C:\Program Files\EarthLink TotalAccess\Toolbar\ProtctIE.dll
O2 - BHO: Uninstall Legacy Earthlink Toolbar - {E713904C-DF05-4C79-BBAD-02DB923253BE} - C:\Program Files\EarthLink TotalAccess\Toolbar\uninsttb.dll
O4 - HKLM\..\Run: [EPSON Stylus C82 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE /P32 "EPSON Stylus C82 Series (Copy 1)" /O6 "USB001" /M "Stylus C82"
O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB003" /M "Stylus CX5400"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4E330863-6A11-11D0-BFD8-006097237877} - http://tw.msi.com.tw/autobios/client/iftwclix.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1126740081864
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1126740173915
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner37320.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: EarthLink Monitor Service (EarthLinkMonitor) - Boingo Wireless, Inc. - C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe


End of KRC HijackThis Analyzer Log.
====================================================================


Also, I was watching videos on VLC media player to pass the time during scanning. That's okay to do, right? Just want to be sure.
 

·
Registered
Joined
·
28 Posts
Discussion Starter #10
New problem

New problem seems to have cropped up.
If my computer runs for an extended amount of time, it will no longer run programs.
Any programs already open will function fine, but no new programs will work no matter how long I wait or how many times I click.
If I click the "start" button, the whole bar freezes.
This has happened twice now today.
 

·
TSF Security Manager, Emeritus
Joined
·
42,837 Posts
Thank you for your patience. :smile:

Download KillBox http://www.greyknight17.com/spy/KillBox.exe.

Reboot into Safe Mode.(tapping F8 or F5)

Copy the file names below to the clipboard by highlighting them and pressing Ctrl-C:

C:\PROGRAM FILES\COMMON FILES\system32.dll
C:\Program Files\Common Files\InetGet2\mc-58-12-0000133.exe
C:\Program Files\Common Files\mc-58-12-0000133.exe


Start KillBox.
Go to the File menu, and choose Paste from Clipboard.
Verify that you've done this properly by clicking the dropdown-arrow next to the Full Path of File to Delete field. The filenames you pasted will be found in there.
Select/tick the following:
* Delete on Reboot
* End Explorer Shell While Killing File
* Unregister.dll Before Deleting" if it's not grayed out.
Click the RED X button.

Click [Yes] at the 'Delete on Reboot' prompt. Click [No] at the Pending Operations prompt.

Click on Start->Settings->Control Panel->Java Plug-in and click on the Cache tab. Then click on the Clear button and hit OK.

Did you install this program? AWClient

Reboot into Normal Mode. How are things running now? If you're still experiencing problems please look for the instructions I gave earlier (about 4 posts up). Download and run the Mwav scan and post the results here along with another HijackThis log.
 

·
Registered
Joined
·
28 Posts
Discussion Starter #12
... No. Computer still crashing.
Tried to install Spyguard. Installed and ran for about a minute.
Then some ActiveX can't create object error popped up and the thing crashed.
Then programs wouldn't run.
Then the computer crashed.

I'll run the scan like you said.
 

·
Registered
Joined
·
28 Posts
Discussion Starter #13 (Edited)
Here is my MWAV scan virus reading and HJT log as requested.



Object "bearshare Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "powerstrip Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "powerstrip Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "bearshare Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "kazaa Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "win32.passma Virus" found in File System! Action Taken: No Action Taken.
Object "bearshare Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "bearshare Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "midaddle Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "midaddle Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "conducent flexpak Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "180solutions Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "midaddle Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "sahagent Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "maxspeed Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "atgames Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "midaddle Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "midaddle Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "midaddle Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "unknown toolbar Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "atgames Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "midaddle Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "coolwebsearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "coolwebsearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "statblaster Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "maxspeed Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "atgames Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "midaddle Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "midaddle Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "midaddle Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "unknown toolbar Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "kazaa Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "coolwebsearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "coolwebsearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "sahagent Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "midaddle Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "cws.smartsearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "Software\Microsoft\Windows\CurrentVersion\ModuleUsage\C:\WINDOWS\SYSTEM\ddrawex.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "Software\Microsoft\Windows\CurrentVersion\ModuleUsage\C:\WINDOWS\SYSTEM\quartz.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\surfmonkey\RedLight.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\surfmonkey\EStream.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\surfmonkey\IMClient.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\surfmonkey\epevents.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\surfmonkey\SMProxy.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\gcUnCompress.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\GCCollection.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\WINDOWS\surfmonkey\". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".exe_tobedeleted". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".tmp". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{94D5AF0F-E6EE-4A75-BE31-9C9C9A87AD45}". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{09AB82D8-AAF7-488C-BD4A-72C4307FC197}" refers to invalid object "C:\Program Files\Microsoft AntiSpyware\gcAntiSpywareLibrary.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{3A5AC3A7-CC29-47F8-A0FF-AB82F3D2D9F5}" refers to invalid object "C:\program files\microsoft antispyware\gcasdtserv.exe". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{422AB1FE-7DD7-4F13-A641-C488C1AC3B25}" refers to invalid object "C:\Program Files\Microsoft AntiSpyware\gcASPrivacyLib.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{5313EE22-5DAB-4A9B-80BB-FA8E46A6CDCB}" refers to invalid object "C:\Program Files\Microsoft AntiSpyware\gcASThreatAudit.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{543FE036-EB0F-49e1-B62C-EDB61400B28C}" refers to invalid object "C:\WINDOWS\System32\GCCollection.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{620B2E41-9B8C-11D3-B0B7-0050DA0F20FC}" refers to invalid object "C:\WINDOWS\surfmonkey\IMClient.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{88E963F5-0B9F-4aab-9CF2-403369C98FE8}" refers to invalid object "C:\WINDOWS\System32\GCCollection.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{A1661681-A796-44FA-9ABA-EE25312F70A5}" refers to invalid object "C:\Program Files\Microsoft AntiSpyware\gcASSoapLib.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{DA95A4F4-AD73-4FD4-A478-3D1EE205CFDA}" refers to invalid object "C:\Program Files\Microsoft AntiSpyware\gcSoftwareUpdateLib.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{E18E6122-8EA2-4B9B-930B-61BE40FEF841}" refers to invalid object "C:\Program Files\Microsoft AntiSpyware\gcTCPObjLib.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3007E4D-A34C-4223-8091-744FC60FCDB5}" refers to invalid object "C:\WINDOWS\System32\GCCollection.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F882289E-E2C5-11D5-B1BC-0050DA0F20FC}" refers to invalid object "C:\WINDOWS\surfmonkey\epevents.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{120A76F4-55FE-41FA-9EB1-9C35B8D25E11}" refers to invalid object "C:\WINDOWS\System32\GCCollection.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{140CF3D1-451B-4C9C-AB04-02C72D06A88D}" refers to invalid object "C:\Program Files\Microsoft AntiSpyware\gcAntiSpywareLibrary.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{1C4D3904-8E59-437B-A010-B3CE69588807}" refers to invalid object "C:\Tools\eAntiSpyTrial\Controls\vbalColumnTreeView6.ocx". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{1D29F3E7-72A2-490E-926B-22E32F34A8DE}" refers to invalid object "G:\install4\VBWINSYS.EXE". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{1D8A3351-C678-11D1-AA6F-000000000000}" refers to invalid object "C:\WINDOWS\system32\DartSock.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{233A9691-667E-11D1-9DFB-006097D50408}" refers to invalid object "C:\Program Files\MSN\MSNCoreFiles\mailui.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{259B72ED-9E4A-11D4-9546-00A0CC532DDD}" refers to invalid object "C:\Program Files\Visioneer OneTouch\OneTouchImgConv.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{29DBA9AA-9E3B-45DC-BE20-CB0B3311D5C5}" refers to invalid object "C:\DOCUME~1\Matthrew\LOCALS~1\Temp\Word8.0\MSForms.exd". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{311EDE7B-141B-4A7F-BC31-A1C0D946F514}" refers to invalid object "C:\Program Files\MSN\MSNIA\CC\MSNCC\msncc.exe". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{31DDE823-839A-4DD2-8D96-DF766052E142}" refers to invalid object "C:\Program Files\Microsoft AntiSpyware\gcTCPObjLib.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{3C2D2A1E-031F-4397-9614-87C932A848E0}" refers to invalid object "C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{401190A3-CDEA-11D2-953E-0040052FC4F9}" refers to invalid object "C:\Program Files\Visioneer OneTouch\OneTouchTargets.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{4CFCC039-CD0C-11D2-953E-0040052FC4F9}" refers to invalid object "C:\Program Files\Visioneer OneTouch\OneTouchDevices.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{527A4DA4-7F2C-11D2-B12D-0000F81F5995}" refers to invalid object "C:\WINDOWS\SYSTEM\DXTRANS.DLL". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{52D761FC-F7A2-4CF1-AEA9-B1746E2A2B5C}" refers to invalid object "C:\Program Files\Microsoft AntiSpyware\gcASSoapLib.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{5A06DF87-4C43-47B5-9654-B9457B61C774}" refers to invalid object "C:\DOCUME~1\CHUCKO~1\LOCALS~1\Temp\Word8.0\MSForms.exd". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{5C39C5CE-809D-11D5-B195-0050DA0F20FC}" refers to invalid object "C:\WINDOWS\surfmonkey\SMProxy.exe". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{620B2E33-9B8C-11D3-B0B7-0050DA0F20FC}" refers to invalid object "C:\WINDOWS\surfmonkey\IMClient.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{71A2702D-C7D8-11D2-BEF8-525400DFB47A}" refers to invalid object "C:\Tools\eAntiSpyTrial\Controls\SSubTmr6.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{7479B280-A309-415C-A351-05483C51F75F}" refers to invalid object "C:\Program Files\Microsoft AntiSpyware\gcSoftwareUpdateLib.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{77ECEA78-E034-4DE3-8ED7-545449FA2339}" refers to invalid object "C:\PROGRAM FILES\MSN\MSNCOREFILES\SEAL.DLL". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}" refers to invalid object "C:\WINDOWS\SYSTEM32\AniGIF.ocx". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{86073239-029C-458B-8546-383694B94B7D}" refers to invalid object "C:\Program Files\Microsoft AntiSpyware\gcASPrivacyLib.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{87BCF2DB-8E1F-4F90-B16D-C088A5BF53D4}" refers to invalid object "C:\DOCUME~1\CHUCKO~1\LOCALS~1\Temp\Word8.0\MSForms.exd". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{94EF7DB4-DFBA-11D2-953E-0040052FC4F9}" refers to invalid object "C:\Program Files\Visioneer OneTouch\OneTouchTransfer.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{9869EFA6-18E9-11D3-A837-00104B9E30B5}" refers to invalid object "C:\DOCUME~1\Matthrew\LOCALS~1\Temp\CmdLineExt03.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{ABBA0019-3075-11D6-88A4-00B0D0200F88}" refers to invalid object "C:\WINDOWS\SYSTEM32\psisdecd.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{ACAC3D3B-FA11-48ED-B087-CA33448F8B64}" refers to invalid object "C:\Tools\Microsoft AntiSpyware\shellextension.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{B162D478-EF46-4475-B1FE-216BDEDB7FAD}" refers to invalid object "C:\WINDOWS\WT\WEBDRIVER\WTMULTI.DLL". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{B6F2E083-CC31-11D2-953E-0040052FC4F9}" refers to invalid object "C:\Program Files\Visioneer OneTouch\OneTouchSettings.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{B7E20302-C22C-4AF2-9D75-C3EB6EEE9DD8}" refers to invalid object "C:\WINDOWS\WT\WEBDRIVER\WTHOSTCTL.DLL". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{C39962BA-5DDC-408D-9367-FEE637EE54D6}" refers to invalid object "C:\Program Files\Microsoft AntiSpyware\gcASThreatAudit.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{CEACE91F-3F71-4A8C-B952-63716B2BC026}" refers to invalid object "C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{DCB43485-19FB-4D6D-BB3D-73C7F48D5F00}" refers to invalid object "C:\Program Files\Messenger\rtcimsp.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{E3DEE443-DCC1-11D2-953E-0040052FC4F9}" refers to invalid object "C:\Program Files\Visioneer OneTouch\OneTouchHardware.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{F62EC210-3A46-4AE0-AFC4-22A796213285}" refers to invalid object "C:\Program Files\MSN\MSNIA\CC\MSNCC\logonmgr.exe". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{F8822891-E2C5-11D5-B1BC-0050DA0F20FC}" refers to invalid object "C:\WINDOWS\surfmonkey\epevents.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{FA13AA2E-CA9B-11D2-9780-00104B242EA3}" refers to invalid object "C:\WINDOWS\WT\WEBDRIVER\WEBDRIVER.DLL". Action Taken: No Action Taken.
Entry "HKCR\.crl" refers to invalid object "CRLFile". Action Taken: No Action Taken.
Entry "HKCR\.p10" refers to invalid object "P10File". Action Taken: No Action Taken.
Entry "HKCR\.p12" refers to invalid object "PFXFile". Action Taken: No Action Taken.
Entry "HKCR\.p7b" refers to invalid object "SPCFile". Action Taken: No Action Taken.
Entry "HKCR\.p7m" refers to invalid object "P7MFile". Action Taken: No Action Taken.
Entry "HKCR\.p7r" refers to invalid object "SPCFile". Action Taken: No Action Taken.
Entry "HKCR\.p7s" refers to invalid object "P7SFile". Action Taken: No Action Taken.
Entry "HKCR\.pfx" refers to invalid object "PFXFile". Action Taken: No Action Taken.
Entry "HKCR\.pko" refers to invalid object "PKOFile". Action Taken: No Action Taken.
Entry "HKCR\.spc" refers to invalid object "SPCFile". Action Taken: No Action Taken.
Entry "HKCR\.stl" refers to invalid object "STLFile". Action Taken: No Action Taken.
Entry "HKCR\BlnMgr.BlnMgr.11" refers to invalid object "{2B992972-69FB-470B-B823-3AA54ADB0D5E}". Action Taken: No Action Taken.
Entry "HKCR\BlnMgrPs.BlnMgrPs.11" refers to invalid object "{A0577268-C54E-4CF4-BBD1-DFEB3DC680F7}". Action Taken: No Action Taken.
Entry "HKCR\BlnMgrPs.BlnPs.11" refers to invalid object "{8CEF9607-D94D-4DB5-B264-95A3120D5BAC}". Action Taken: No Action Taken.
Entry "HKCR\BlnMgrPs.BlnSetPs.11" refers to invalid object "{00D6C06D-E5F9-495B-9C0A-CC35E74891B4}". Action Taken: No Action Taken.
Entry "HKCR\BlnMgrPs.BlnSetUserPs.11" refers to invalid object "{261F6572-578B-40A7-B72E-61B7261D9F0C}". Action Taken: No Action Taken.
Entry "HKCR\DataCtl.DataCtl" refers to invalid object "{0468C085-CA5B-11D0-AF08-00609797F0E0}". Action Taken: No Action Taken.
Entry "HKCR\DataCtl.DataCtl.1" refers to invalid object "{0468C085-CA5B-11D0-AF08-00609797F0E0}". Action Taken: No Action Taken.
Entry "HKCR\DMM.CEALG" refers to invalid object "{89555CC1-4928-11D3-8D4C-00E029154FDE}". Action Taken: No Action Taken.
Entry "HKCR\DMM.CEALG.1" refers to invalid object "{89555CC1-4928-11D3-8D4C-00E029154FDE}". Action Taken: No Action Taken.
Entry "HKCR\DMM.ClassificationModel" refers to invalid object "{830437A6-2F36-11D3-8C76-00600832DCED}". Action Taken: No Action Taken.
Entry "HKCR\DMM.ClassificationModel.1" refers to invalid object "{830437A6-2F36-11D3-8C76-00600832DCED}". Action Taken: No Action Taken.
Entry "HKCR\DMM.Classifier" refers to invalid object "{08EAF772-59A5-11D3-B3A7-00C04F687719}". Action Taken: No Action Taken.
Entry "HKCR\DMM.Classifier.1" refers to invalid object "{08EAF772-59A5-11D3-B3A7-00C04F687719}". Action Taken: No Action Taken.
Entry "HKCR\DMM.DMMCorrCount" refers to invalid object "{65813659-4461-11D3-8C7B-00600832DCED}". Action Taken: No Action Taken.
Entry "HKCR\DMM.DMMCorrCount.1" refers to invalid object "{65813659-4461-11D3-8C7B-00600832DCED}". Action Taken: No Action Taken.
Entry "HKCR\DMM.DMMCorrCountSource" refers to invalid object "{65813656-4461-11D3-8C7B-00600832DCED}". Action Taken: No Action Taken.
Entry "HKCR\DMM.DMMCorrCountSource.1" refers to invalid object "{65813656-4461-11D3-8C7B-00600832DCED}". Action Taken: No Action Taken.
Entry "HKCR\DXSurface.OAVEmpty" refers to invalid object "{98E2F337-EE36-11D3-BA3C-00C04F6843FA}". Action Taken: No Action Taken.
Entry "HKCR\DXSurface.OAVEmpty.1" refers to invalid object "{98E2F337-EE36-11D3-BA3C-00C04F6843FA}". Action Taken: No Action Taken.
Entry "HKCR\Equation.3" refers to invalid object "{0002CE02-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\Equations" refers to invalid object "{0002CE02-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\Excel.Application" refers to invalid object "{00024500-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\Excel.Application.11" refers to invalid object "{00024500-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\ExcelChart" refers to invalid object "{00030001-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\ExcelMacrosheet" refers to invalid object "{00030002-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\ExcelWorksheet" refers to invalid object "{00030000-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\FName.Factoid" refers to invalid object "{87EF1CFE-51CA-4E6B-8C76-E576AA926888}". Action Taken: No Action Taken.
Entry "HKCR\FName.Factoid.2" refers to invalid object "{87EF1CFE-51CA-4E6B-8C76-E576AA926888}". Action Taken: No Action Taken.
Entry "HKCR\FPDTC.LISTVIEWCTL" refers to invalid object "{4421FEE2-A45D-11D3-9F7C-005004AE6818}". Action Taken: No Action Taken.
Entry "HKCR\FPDTC.LISTVIEWCTL.1" refers to invalid object "{4421FEE2-A45D-11D3-9F7C-005004AE6818}". Action Taken: No Action Taken.
Entry "HKCR\FPDTC.LISTVIEWPPG" refers to invalid object "{4421FEE4-A45D-11D3-9F7C-005004AE6818}". Action Taken: No Action Taken.
Entry "HKCR\FPDTC.LISTVIEWPPG.1" refers to invalid object "{4421FEE4-A45D-11D3-9F7C-005004AE6818}". Action Taken: No Action Taken.
Entry "HKCR\FPDTC.NAVBARCTL" refers to invalid object "{4421FEDE-A45D-11D3-9F7C-005004AE6818}". Action Taken: No Action Taken.
Entry "HKCR\FPDTC.NAVBARCTL.1" refers to invalid object "{4421FEDE-A45D-11D3-9F7C-005004AE6818}". Action Taken: No Action Taken.
Entry "HKCR\FPDTC.NAVBARPPG" refers to invalid object "{4421FEE3-A45D-11D3-9F7C-005004AE6818}". Action Taken: No Action Taken.
Entry "HKCR\FPDTC.NAVBARPPG.1" refers to invalid object "{4421FEE3-A45D-11D3-9F7C-005004AE6818}". Action Taken: No Action Taken.
Entry "HKCR\FPDTC.NAVBARSTYLEPPG" refers to invalid object "{59049080-EEE1-11D3-9F8B-005004AE6818}". Action Taken: No Action Taken.
Entry "HKCR\FPDTC.NAVBARSTYLEPPG.1" refers to invalid object "{59049080-EEE1-11D3-9F8B-005004AE6818}". Action Taken: No Action Taken.
Entry "HKCR\FPerson.Factoid" refers to invalid object "{339361CD-6723-455D-A40B-C95F1F91FF8A}". Action Taken: No Action Taken.
Entry "HKCR\FPerson.Factoid.2" refers to invalid object "{339361CD-6723-455D-A40B-C95F1F91FF8A}". Action Taken: No Action Taken.
Entry "HKCR\FStock.Factoid" refers to invalid object "{49DF3409-46B3-4B0C-B7BF-FEC0F9401EDD}". Action Taken: No Action Taken.
Entry "HKCR\FStock.Factoid.2" refers to invalid object "{49DF3409-46B3-4B0C-B7BF-FEC0F9401EDD}". Action Taken: No Action Taken.
Entry "HKCR\HTMLInlineSoundCtl.1" refers to invalid object "{8422DAE3-9929-11CF-B8D3-004033373DA8}". Action Taken: No Action Taken.
Entry "HKCR\HTMLInlineVideoCtl.1" refers to invalid object "{8422DAE7-9929-11CF-B8D3-004033373DA8}". Action Taken: No Action Taken.
Entry "HKCR\Ietag.EvtSink" refers to invalid object "{08F5D2F6-4AE5-486B-98E0-3E85BA6B4D11}". Action Taken: No Action Taken.
Entry "HKCR\Ietag.EvtSink.1" refers to invalid object "{08F5D2F6-4AE5-486B-98E0-3E85BA6B4D11}". Action Taken: No Action Taken.
Entry "HKCR\Ietag.Factory" refers to invalid object "{38481807-CA0E-42D2-BF39-B33AF135CC4D}". Action Taken: No Action Taken.
Entry "HKCR\Ietag.Factory.1" refers to invalid object "{38481807-CA0E-42D2-BF39-B33AF135CC4D}". Action Taken: No Action Taken.
Entry "HKCR\Ietag.OOC" refers to invalid object "{03B54468-0899-4233-8689-623FFFC295EE}". Action Taken: No Action Taken.
Entry "HKCR\Ietag.OOC.1" refers to invalid object "{03B54468-0899-4233-8689-623FFFC295EE}". Action Taken: No Action Taken.
Entry "HKCR\LISTNET.Listnet" refers to invalid object "{65BCBEE4-7728-41A0-97BE-14E1CAE36AAE}". Action Taken: No Action Taken.
Entry "HKCR\LISTNET.Listnet.11" refers to invalid object "{65BCBEE4-7728-41A0-97BE-14E1CAE36AAE}". Action Taken: No Action Taken.
Entry "HKCR\LR.LexRefStEsObject.1.0" refers to invalid object "{4CFB5280-800B-4367-848F-5A13EBF27F1D}". Action Taken: No Action Taken.
Entry "HKCR\LR.LexRefStEsObject.1.0.1" refers to invalid object "{4CFB5280-800B-4367-848F-5A13EBF27F1D}". Action Taken: No Action Taken.
Entry "HKCR\LR.LexRefStFrObject.1.0" refers to invalid object "{B3E0E785-BD78-4366-9560-B7DABE2723BE}". Action Taken: No Action Taken.
Entry "HKCR\LR.LexRefStFrObject.1.0.1" refers to invalid object "{B3E0E785-BD78-4366-9560-B7DABE2723BE}". Action Taken: No Action Taken.
Entry "HKCR\MailFileAtt" refers to invalid object "{00020D05-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\MailMsgAtt" refers to invalid object "{00020D09-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\MapiCvt.MapiCvt" refers to invalid object "{0006F085-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\MapiCvt.MapiCvt.1" refers to invalid object "{0006F085-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\mapifvbx.object" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.
Entry "HKCR\mapifvbx.object.1" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.
Entry "HKCR\MARQUEE.MarqueeCtrl.1" refers to invalid object "{250770F3-6AF2-11CF-A915-008029E31FCD}". Action Taken: No Action Taken.
Entry "HKCR\mce.CCSProperties" refers to invalid object "{4E7F49AF-E4B5-11D1-8D9D-006097DBEFEF}". Action Taken: No Action Taken.
Entry "HKCR\mce.CCSproperty" refers to invalid object "{4E7F49AD-E4B5-11D1-8D9D-006097DBEFEF}". Action Taken: No Action Taken.
Entry "HKCR\mce.chartwizard" refers to invalid object "{4E7F49D5-E4B5-11D1-8D9D-006097DBEFEF}". Action Taken: No Action Taken.
Entry "HKCR\mce.IMCEResource" refers to invalid object "{4E7F49B6-E4B5-11D1-8D9D-006097DBEFEF}". Action Taken: No Action Taken.
Entry "HKCR\mce.IMCEResources" refers to invalid object "{5D62A639-0FB0-11D2-8DB2-006097DBEFEF}". Action Taken: No Action Taken.
Entry "HKCR\mce.MiniCubeEditor" refers to invalid object "{4E7F49B8-E4B5-11D1-8D9D-006097DBEFEF}". Action Taken: No Action Taken.
Entry "HKCR\mce.RW" refers to invalid object "{4E7F49CF-E4B5-11D1-8D9D-006097DBEFEF}". Action Taken: No Action Taken.
Entry "HKCR\MediaCatalogDB" refers to invalid object "{09E767A6-4481-4791-86A5-A739E5290E4C}". Action Taken: No Action Taken.
Entry "HKCR\MediaCatalogDB.11" refers to invalid object "{09E767A6-4481-4791-86A5-A739E5290E4C}". Action Taken: No Action Taken.
Entry "HKCR\MediaCatalogMergedDB" refers to invalid object "{1B118620-8818-4E01-A5DB-E56764F709DB}". Action Taken: No Action Taken.
Entry "HKCR\MediaCatalogMergedDB.11" refers to invalid object "{1B118620-8818-4E01-A5DB-E56764F709DB}". Action Taken: No Action Taken.
Entry "HKCR\MediaCatalogWebDB" refers to invalid object "{75F1D42A-FD3E-478C-A36C-433B847441BD}". Action Taken: No Action Taken.
Entry "HKCR\MediaCatalogWebDB.11" refers to invalid object "{75F1D42A-FD3E-478C-A36C-433B847441BD}". Action Taken: No Action Taken.
Entry "HKCR\Microsoft.Access.OLEDB.10.0" refers to invalid object "{25377C20-D19C-11D2-B483-00600832C573}". Action Taken: No Action Taken.
Entry "HKCR\Microsoft.Office.List.OLEDB.1.0" refers to invalid object "{252BFDA2-4B21-4872-ABA3-043945949BF8}". Action Taken: No Action Taken.
Entry "HKCR\Microsoft.VbaAddinForOutlook" refers to invalid object "{799ED9EA-FB5E-11D1-B7D6-00C04FC2AAE2}". Action Taken: No Action Taken.
Entry "HKCR\Microsoft.VbaAddinForOutlook.1" refers to invalid object "{799ED9EA-FB5E-11D1-B7D6-00C04FC2AAE2}". Action Taken: No Action Taken.
Entry "HKCR\Microsoft.WebCapture" refers to invalid object "{742D385A-D5BF-427D-9AF2-88258FB73EAF}". Action Taken: No Action Taken.
Entry "HKCR\Microsoft.WebCapture.1" refers to invalid object "{742D385A-D5BF-427D-9AF2-88258FB73EAF}". Action Taken: No Action Taken.
Entry "HKCR\MicrosoftRDO.rdoEngine" refers to invalid object "{5E71F04C-551F-11CF-8152-00AA00A40C25}". Action Taken: No Action Taken.
Entry "HKCR\MicrosoftRDO.RdoQuery" refers to invalid object "{5EBB68F5-3BF1-11CF-814C-00AA00A40C25}". Action Taken: No Action Taken.
Entry "HKCR\Midoc.MiDocument" refers to invalid object "{863305F6-E822-4C08-9BE1-F1C7CFC919AF}". Action Taken: No Action Taken.
Entry "HKCR\Midoc.MiDocument.1" refers to invalid object "{863305F6-E822-4C08-9BE1-F1C7CFC919AF}". Action Taken: No Action Taken.
Entry "HKCR\MiDocViewer.MiRioEventSink" refers to invalid object "{5CBAD860-46EE-4193-8FDF-5EF8625E0CA1}". Action Taken: No Action Taken.
Entry "HKCR\MiDocViewer.MiRioEventSink.1" refers to invalid object "{5CBAD860-46EE-4193-8FDF-5EF8625E0CA1}". Action Taken: No Action Taken.
Entry "HKCR\MiEng.MiEngine" refers to invalid object "{9D13E607-106F-4892-8A83-FF9827C0A3D5}". Action Taken: No Action Taken.
Entry "HKCR\MiEng.MiEngine.1" refers to invalid object "{9D13E607-106F-4892-8A83-FF9827C0A3D5}". Action Taken: No Action Taken.
Entry "HKCR\MiImage.NbImageLayer" refers to invalid object "{8EE4C235-F2CE-4C3B-9ADE-DD68718AE32A}". Action Taken: No Action Taken.
Entry "HKCR\MiImage.NbImageLayer.1" refers to invalid object "{8EE4C235-F2CE-4C3B-9ADE-DD68718AE32A}". Action Taken: No Action Taken.
Entry "HKCR\MiInkSeg.MiRichInkSegment" refers to invalid object "{7EDA10AF-96CA-49AD-8BE0-FFE624FB5D5E}". Action Taken: No Action Taken.
Entry "HKCR\MiInkSeg.MiRichInkSegment.1" refers to invalid object "{7EDA10AF-96CA-49AD-8BE0-FFE624FB5D5E}". Action Taken: No Action Taken.
Entry "HKCR\MiInkSeg.MiRioEventSender" refers to invalid object "{AD3704F3-6BE8-4ADE-9737-BF0DB60060B8}". Action Taken: No Action Taken.
Entry "HKCR\MiInkSeg.MiRioEventSender.1" refers to invalid object "{AD3704F3-6BE8-4ADE-9737-BF0DB60060B8}". Action Taken: No Action Taken.
Entry "HKCR\MimeDir.MimeDirItem" refers to invalid object "{0006F081-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\MimeDir.MimeDirItem.1" refers to invalid object "{0006F081-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\MimeDir.MimeDirParser" refers to invalid object "{0006F082-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\MimeDir.MimeDirParser.1" refers to invalid object "{0006F082-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\MimeDir.MimeDirProfile" refers to invalid object "{0006F084-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\MimeDir.MimeDirProfile.1" refers to invalid object "{0006F084-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\MODI.Document" refers to invalid object "{40942A6C-1520-4132-BDF8-BDC1F71F547B}". Action Taken: No Action Taken.
Entry "HKCR\MODI.Document.1" refers to invalid object "{40942A6C-1520-4132-BDF8-BDC1F71F547B}". Action Taken: No Action Taken.
Entry "HKCR\MOFL.Factoid" refers to invalid object "{64AB6C69-B40E-40AF-9B7F-F5687B48E2B6}". Action Taken: No Action Taken.
Entry "HKCR\MOFL.Factoid.2" refers to invalid object "{64AB6C69-B40E-40AF-9B7F-F5687B48E2B6}". Action Taken: No Action Taken.
Entry "HKCR\MSAddnDr.AddInDesigner" refers to invalid object "{AC0714F6-3D04-11D1-AE7D-00A0C90F26F4}". Action Taken: No Action Taken.
Entry "HKCR\MSAddnDr.AddInDesigner.1" refers to invalid object "{AC0714F6-3D04-11D1-AE7D-00A0C90F26F4}". Action Taken: No Action Taken.
Entry "HKCR\MSAddnDr.AddInInstance" refers to invalid object "{AC0714F7-3D04-11D1-AE7D-00A0C90F26F4}". Action Taken: No Action Taken.
Entry "HKCR\MSAddnDr.AddInInstance.1" refers to invalid object "{AC0714F7-3D04-11D1-AE7D-00A0C90F26F4}". Action Taken: No Action Taken.
Entry "HKCR\MSASR.LocaleHandler" refers to invalid object "{3246A6CF-2898-4541-AA7E-3F847903D29B}". Action Taken: No Action Taken.
Entry "HKCR\MSASR.LocaleHandler.2" refers to invalid object "{3246A6CF-2898-4541-AA7E-3F847903D29B}". Action Taken: No Action Taken.
Entry "HKCR\MSASR.LocaleHandler1041" refers to invalid object "{8619FFAE-8AE1-481F-84B2-41A3C9669C0A}". Action Taken: No Action Taken.
Entry "HKCR\MSASR.LocaleHandler1041.2" refers to invalid object "{8619FFAE-8AE1-481F-84B2-41A3C9669C0A}". Action Taken: No Action Taken.
Entry "HKCR\MSASR.LocaleHandler2052" refers to invalid object "{35AAEA84-40DC-4397-9A80-613FD196FBAD}". Action Taken: No Action Taken.
Entry "HKCR\MSASR.LocaleHandler2052.2" refers to invalid object "{35AAEA84-40DC-4397-9A80-613FD196FBAD}". Action Taken: No Action Taken.
Entry "HKCR\MSASR60.ITN1033" refers to invalid object "{8A17CA50-7EDE-46DA-BBC7-87408B393CFB}". Action Taken: No Action Taken.
Entry "HKCR\MSASR60.ITN1033.2" refers to invalid object "{8A17CA50-7EDE-46DA-BBC7-87408B393CFB}". Action Taken: No Action Taken.
Entry "HKCR\Msasrx.MsasrUI" refers to invalid object "{4C7A1FE9-5047-4E61-90A0-872436277809}". Action Taken: No Action Taken.
Entry "HKCR\Msasrx.MsasrUI.3" refers to invalid object "{4C7A1FE9-5047-4E61-90A0-872436277809}". Action Taken: No Action Taken.
Entry "HKCR\Msasrx.RecoExt" refers to invalid object "{6BEF5B00-D46E-49B0-BFD2-49847061ED73}". Action Taken: No Action Taken.
Entry "HKCR\Msasrx.RecoExt.3" refers to invalid object "{6BEF5B00-D46E-49B0-BFD2-49847061ED73}". Action Taken: No Action Taken.
Entry "HKCR\MSDAIPP.WEBFOLDERFORMS" refers to invalid object "{11480D94-C3A5-11D3-BA7C-00C04F7948B3}". Action Taken: No Action Taken.
Entry "HKCR\MSDAIPP.WEBFOLDERFORMS.1" refers to invalid object "{11480D94-C3A5-11D3-BA7C-00C04F7948B3}". Action Taken: No Action Taken.
Entry "HKCR\MSDMine" refers to invalid object "{2CB6C2D3-DD7C-11D2-AFE4-00105A994724}". Action Taken: No Action Taken.
Entry "HKCR\MSDMine.1" refers to invalid object "{2CB6C2D3-DD7C-11D2-AFE4-00105A994724}". Action Taken: No Action Taken.
Entry "HKCR\MSDMine.MSDMineEnum" refers to invalid object "{8853D6B2-E8AE-11D2-AFE8-00105A994724}". Action Taken: No Action Taken.
Entry "HKCR\MSDMine.MSDMineEnum.1" refers to invalid object "{8853D6B2-E8AE-11D2-AFE8-00105A994724}". Action Taken: No Action Taken.
Entry "HKCR\MSDMineErrorLookup" refers to invalid object "{72B082C6-97D5-11D3-8BEC-00C04F68DDC2}". Action Taken: No Action Taken.
Entry "HKCR\MSDMineErrorLookup.1" refers to invalid object "{72B082C6-97D5-11D3-8BEC-00C04F68DDC2}". Action Taken: No Action Taken.
Entry "HKCR\MSExchange.Events" refers to invalid object "{2F42C693-C6A4-11D0-93E9-00AA0064D470}". Action Taken: No Action Taken.
Entry "HKCR\MSExchange.Events.1" refers to invalid object "{2F42C693-C6A4-11D0-93E9-00AA0064D470}". Action Taken: No Action Taken.
Entry "HKCR\MSGraph.Application" refers to invalid object "{00024502-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\MSGraph.Application.8" refers to invalid object "{00024502-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\MSGraph.Chart" refers to invalid object "{00020803-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\MSGraph.Chart.5" refers to invalid object "{00020801-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\MSGraph.Chart.8" refers to invalid object "{00020803-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\MSMDSRV.PNDComManager" refers to invalid object "{3A5E75F5-DE4B-11D2-AB46-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOAUTH.Binder" refers to invalid object "{46816230-46E3-11D3-8D01-005004838617}". Action Taken: No Action Taken.
Entry "HKCR\MSOAUTH.Binder.1" refers to invalid object "{46816230-46E3-11D3-8D01-005004838617}". Action Taken: No Action Taken.
Entry "HKCR\MsoEuro.Converter" refers to invalid object "{30A095E2-9A0C-11D2-93BB-00105A994D2C}". Action Taken: No Action Taken.
Entry "HKCR\MsoEuro.Converter.1" refers to invalid object "{30A095E2-9A0C-11D2-93BB-00105A994D2C}". Action Taken: No Action Taken.
Entry "HKCR\MSOLAP.2" refers to invalid object "{A07CCD0C-8148-11D0-87BB-00C04FC33942}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPAggregation" refers to invalid object "{1E083973-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPAggregation.1" refers to invalid object "{1E083973-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPAggregations" refers to invalid object "{1E083972-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPAggregations.1" refers to invalid object "{1E083972-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPAuxiliarie" refers to invalid object "{1E083979-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPAuxiliarie.1" refers to invalid object "{1E083979-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPAuxiliaries" refers to invalid object "{1E083978-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPAuxiliaries.1" refers to invalid object "{1E083978-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPClient" refers to invalid object "{1E083962-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPClient.1" refers to invalid object "{1E083962-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPCubeSecurities" refers to invalid object "{1E08397D-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPCubeSecurities.1" refers to invalid object "{1E08397D-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPCubeSecurity" refers to invalid object "{1E08397C-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPCubeSecurity.1" refers to invalid object "{1E08397C-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPDatabase" refers to invalid object "{1E083964-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPDatabase.1" refers to invalid object "{1E083964-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPDatabases" refers to invalid object "{1E083963-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPDatabases.1" refers to invalid object "{1E083963-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPDetail" refers to invalid object "{1E08396B-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPDetail.1" refers to invalid object "{1E08396B-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPDetails" refers to invalid object "{1E08396A-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPDetails.1" refers to invalid object "{1E08396A-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPDimension" refers to invalid object "{1E083969-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPDimension.1" refers to invalid object "{1E083969-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPDimensions" refers to invalid object "{1E083980-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPDimensions.1" refers to invalid object "{1E083980-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPExtLevel" refers to invalid object "{1E083975-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPExtLevel.1" refers to invalid object "{1E083975-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPExtLevels" refers to invalid object "{1E083974-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPExtLevels.1" refers to invalid object "{1E083974-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPExtMeasure" refers to invalid object "{1E083977-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPExtMeasure.1" refers to invalid object "{1E083977-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPExtMeasures" refers to invalid object "{1E083976-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPExtMeasures.1" refers to invalid object "{1E083976-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPLastError" refers to invalid object "{1E08397F-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPLastError.1" refers to invalid object "{1E08397F-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPLevel" refers to invalid object "{1E08396D-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPLevel.1" refers to invalid object "{1E08396D-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPLevels" refers to invalid object "{1E08396C-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPLevels.1" refers to invalid object "{1E08396C-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPLockManager" refers to invalid object "{1E08397E-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPLockManager.1" refers to invalid object "{1E08397E-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPMeasure" refers to invalid object "{1E08396F-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPMeasure.1" refers to invalid object "{1E08396F-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPMeasures" refers to invalid object "{1E08396E-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPMeasures.1" refers to invalid object "{1E08396E-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPModel" refers to invalid object "{1E083968-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPModel.1" refers to invalid object "{1E083968-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPModels" refers to invalid object "{1E083967-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPModels.1" refers to invalid object "{1E083967-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPPartition" refers to invalid object "{1E083971-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPPartition.1" refers to invalid object "{1E083971-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPPartitions" refers to invalid object "{1E083970-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPPartitions.1" refers to invalid object "{1E083970-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPRole" refers to invalid object "{1E08397A-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPRole.1" refers to invalid object "{1E08397A-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPRoles" refers to invalid object "{1E08397B-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPRoles.1" refers to invalid object "{1E08397B-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPSource" refers to invalid object "{1E083966-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPSource.1" refers to invalid object "{1E083966-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPSources" refers to invalid object "{1E083965-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPSources.1" refers to invalid object "{1E083965-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOLAPErrorLookup.2" refers to invalid object "{A07CCD0D-8148-11D0-87BB-00C04FC33942}". Action Taken: No Action Taken.
Entry "HKCR\MSOLAPUI80.ConnectDialog" refers to invalid object "{5C63C824-4122-4A70-A03E-482B2B9A8269}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimateDHTMLBehavior" refers to invalid object "{816CA828-8BE4-11D3-A498-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimateDHTMLBehavior.1" refers to invalid object "{816CA828-8BE4-11D3-A498-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimColorDHTMLBehavior" refers to invalid object "{816CA825-8BE4-11D3-A498-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimColorDHTMLBehavior.1" refers to invalid object "{816CA825-8BE4-11D3-A498-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimExecutiveBehavior" refers to invalid object "{A4639D3F-774E-11D3-A490-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimExecutiveBehavior.1" refers to invalid object "{A4639D3F-774E-11D3-A490-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimFilterDHTMLBehavior" refers to invalid object "{816CA82A-8BE4-11D3-A498-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimFilterDHTMLBehavior.1" refers to invalid object "{816CA82A-8BE4-11D3-A498-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimMotionDHTMLBehavior" refers to invalid object "{816CA82C-8BE4-11D3-A498-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimMotionDHTMLBehavior.1" refers to invalid object "{816CA82C-8BE4-11D3-A498-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimRotationDHTMLBehavior" refers to invalid object "{816CA82E-8BE4-11D3-A498-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimRotationDHTMLBehavior.1" refers to invalid object "{816CA82E-8BE4-11D3-A498-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimScaleDHTMLBehavior" refers to invalid object "{816CA830-8BE4-11D3-A498-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimScaleDHTMLBehavior.1" refers to invalid object "{816CA830-8BE4-11D3-A498-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimSetDHTMLBehavior" refers to invalid object "{816CA832-8BE4-11D3-A498-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimSetDHTMLBehavior.1" refers to invalid object "{816CA832-8BE4-11D3-A498-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.CommandDHTMLBehavior" refers to invalid object "{5DC20347-0A84-11D4-A4EE-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.CommandDHTMLBehavior.1" refers to invalid object "{5DC20347-0A84-11D4-A4EE-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.IEAnimBehaviorFactory" refers to invalid object "{A4639D2F-774E-11D3-A490-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.IEAnimBehaviorFactory.1" refers to invalid object "{A4639D2F-774E-11D3-A490-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.IEEventListenerProxy" refers to invalid object "{1A556DAA-781C-11D3-A490-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.IEEventListenerProxy.1" refers to invalid object "{1A556DAA-781C-11D3-A490-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.IEPropertyListenerProxy" refers to invalid object "{1A556DAC-781C-11D3-A490-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.IEPropertyListenerProxy.1" refers to invalid object "{1A556DAC-781C-11D3-A490-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.IETimeBehaviorFactory" refers to invalid object "{A4639D29-774E-11D3-A490-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.IETimeBehaviorFactory.1" refers to invalid object "{A4639D29-774E-11D3-A490-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.IterateDHTMLBehavior" refers to invalid object "{B96F84F7-D5AB-11D3-A4CA-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.IterateDHTMLBehavior.1" refers to invalid object "{B96F84F7-D5AB-11D3-A4CA-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.OAVDShowPlayer" refers to invalid object "{3FDA5DC2-ECE0-11D3-9C20-00C04F72DD5F}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.OAVDShowPlayer.1" refers to invalid object "{3FDA5DC2-ECE0-11D3-9C20-00C04F72DD5F}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.OAVIEClock" refers to invalid object "{B1A3692E-EAFB-11D3-A4DC-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.OAVIEClock.1" refers to invalid object "{B1A3692E-EAFB-11D3-A4DC-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.OAVMediaDHTMLBehavior" refers to invalid object "{3408C281-EAEA-11D3-A4DC-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.OAVMediaDHTMLBehavior.1" refers to invalid object "{3408C281-EAEA-11D3-A4DC-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.OAVRedirectFallback" refers to invalid object "{999937BC-30FE-11D4-BA52-00C04F6843FA}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.OAVRedirectFallback.1" refers to invalid object "{999937BC-30FE-11D4-BA52-00C04F6843FA}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.TimeDHTMLBehavior" refers to invalid object "{A4639D41-774E-11D3-A490-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.TimeDHTMLBehavior.1" refers to invalid object "{A4639D41-774E-11D3-A490-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.TimeExecutiveBehavior" refers to invalid object "{A4639D33-774E-11D3-A490-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.TimeExecutiveBehavior.1" refers to invalid object "{A4639D33-774E-11D3-A490-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.ByteArrayAttachment30" refers to invalid object "{86EB31E4-A46F-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.DataEncoderFactory30" refers to invalid object "{86EB31E8-A46F-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.DimeComposer30" refers to invalid object "{86EB31DF-A46F-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.DimeParser30" refers to invalid object "{86EB31E2-A46F-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.FileAttachment30" refers to invalid object "{86EB31E3-A46F-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.GenericCustomTypeMapper30" refers to invalid object "{9A36D31A-A470-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.ReceivedAttachment30" refers to invalid object "{86EB31E7-A46F-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.ReceivedAttachments30" refers to invalid object "{86EB31EE-A46F-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.SentAttachments30" refers to invalid object "{86EB31ED-A46F-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.SimpleComposer30" refers to invalid object "{86EB31EB-A46F-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.SimpleParser30" refers to invalid object "{86EB31EC-A46F-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.SoapClient30" refers to invalid object "{34E0D4B8-A470-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.SoapReader30" refers to invalid object "{52ABBE5B-A470-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.SoapSerializer30" refers to invalid object "{764FE7E3-A470-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.SoapTypeMapperFactory30" refers to invalid object "{9A36D319-A470-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.StreamAttachment30" refers to invalid object "{86EB31E6-A46F-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.StringAttachment30" refers to invalid object "{86EB31E5-A46F-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.UDTMapper30" refers to invalid object "{9A36D31B-A470-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.WSDLReader30" refers to invalid object "{9A36D318-A470-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\Msshed.ShedDSO" refers to invalid object "{5F6C4076-12F5-11D3-8CEE-005004838434}". Action Taken: No Action Taken.
Entry "HKCR\Msshed.ShedDSO.1" refers to invalid object "{5F6C4076-12F5-11D3-8CEE-005004838434}". Action Taken: No Action Taken.
Entry "HKCR\Msshed.ShedListDSO" refers to invalid object "{B8E622FC-D912-4C4D-B0F9-616AA3B44EED}". Action Taken: No Action Taken.
Entry "HKCR\Msshed.ShedListDSO.1" refers to invalid object "{B8E622FC-D912-4C4D-B0F9-616AA3B44EED}". Action Taken: No Action Taken.
Entry "HKCR\MSUSP.OCD" refers to invalid object "{433CBF68-A873-4C6D-A211-623281ED930E}". Action Taken: No Action Taken.
Entry "HKCR\MSUSP.OCD.1" refers to invalid object "{433CBF68-A873-4C6D-A211-623281ED930E}". Action Taken: No Action Taken.
Entry "HKCR\Msxml2.DOMDocument.5.0" refers to invalid object "{88D969E5-F192-11D4-A65F-0040963251E5}". Action Taken: No Action Taken.
Entry "HKCR\Msxml2.DSOControl.5.0" refers to invalid object "{88D969E9-F192-11D4-A65F-0040963251E5}". Action Taken: No Action Taken.
Entry "HKCR\Msxml2.FreeThreadedDOMDocument.5.0" refers to invalid object "{88D969E6-F192-11D4-A65F-0040963251E5}". Action Taken: No Action Taken.
Entry "HKCR\Msxml2.MXDigitalSignature.5.0" refers to invalid object "{88D969F5-F192-11D4-A65F-0040963251E5}". Action Taken: No Action Taken.
Entry "HKCR\Msxml2.MXHTMLWriter.5.0" refers to invalid object "{88D969F0-F192-11D4-A65F-0040963251E5}". Action Taken: No Action Taken.
Entry "HKCR\Msxml2.MXNamespaceManager.5.0" refers to invalid object "{88D969F1-F192-11D4-A65F-0040963251E5}". Action Taken: No Action Taken.
Entry "HKCR\Msxml2.MXXMLWriter.5.0" refers to invalid object "{88D969EF-F192-11D4-A65F-0040963251E5}". Action Taken: No Action Taken.
Entry "HKCR\Msxml2.SAXAttributes.5.0" refers to invalid object "{88D969EE-F192-11D4-A65F-0040963251E5}". Action Taken: No Action Taken.
Entry "HKCR\Msxml2.SAXXMLReader.5.0" refers to invalid object "{88D969EC-8B8B-4C3D-859E-AF6CD158BE0F}". Action Taken: No Action Taken.
Entry "HKCR\Msxml2.ServerXMLHTTP.5.0" refers to invalid object "{88D969EB-F192-11D4-A65F-0040963251E5}". Action Taken: No Action Taken.
Entry "HKCR\Msxml2.XMLHTTP.5.0" refers to invalid object "{88D969EA-F192-11D4-A65F-0040963251E5}". Action Taken: No Action Taken.
Entry "HKCR\Msxml2.XMLSchemaCache.5.0" refers to invalid object "{88D969E7-F192-11D4-A65F-0040963251E5}". Action Taken: No Action Taken.
Entry "HKCR\Msxml2.XSLTemplate.5.0" refers to invalid object "{88D969E8-F192-11D4-A65F-0040963251E5}". Action Taken: No Action Taken.
Entry "HKCR\MultiMgrAddIn.AddInDesigner1" refers to invalid object "{3EDC309B-6AF0-11D4-963C-000039B6C417}". Action Taken: No Action Taken.
Entry "HKCR\Office.Authz" refers to invalid object "{4453D895-F2A1-4A38-A285-1EF9BD3F6D5D}". Action Taken: No Action Taken.
Entry "HKCR\Office.Authz.1" refers to invalid object "{4453D895-F2A1-4A38-A285-1EF9BD3F6D5D}". Action Taken: No Action Taken.
Entry "HKCR\OfficeCompatible.Application" refers to invalid object "{812034D2-760F-11CF-9370-00AA00B8BF00}". Action Taken: No Action Taken.
Entry "HKCR\OfficeCompatible.Application.1" refers to invalid object "{812034D2-760F-11CF-9370-00AA00B8BF00}". Action Taken: No Action Taken.
Entry "HKCR\ORG10SVR.Application" refers to invalid object "{787A1520-75B9-11CF-980D-444553540000}". Action Taken: No Action Taken.
Entry "HKCR\ORG10SVR.Application.1" refers to invalid object "{787A1520-75B9-11CF-980D-444553540000}". Action Taken: No Action Taken.
Entry "HKCR\OSE.Discussion" refers to invalid object "{BDEADEDA-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OSE.Discussion.2" refers to invalid object "{BDEADEDA-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OSE.Discussions" refers to invalid object "{BDEADEDB-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OSE.Discussions.2" refers to invalid object "{BDEADEDB-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OSE.DiscussionServer" refers to invalid object "{BDEADEDC-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OSE.DiscussionServer.2" refers to invalid object "{BDEADEDC-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OSE.DiscussionServers" refers to invalid object "{BDEADEDD-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OSE.DiscussionServers.2" refers to invalid object "{BDEADEDD-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OSE.Global" refers to invalid object "{BDEADEDE-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OSE.Global.2" refers to invalid object "{BDEADEDE-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\otkloadr.WRAssembly" refers to invalid object "{A08A033D-1A75-4AB6-A166-EAD02F547959}". Action Taken: No Action Taken.
Entry "HKCR\otkloadr.WRAssembly.1" refers to invalid object "{A08A033D-1A75-4AB6-A166-EAD02F547959}". Action Taken: No Action Taken.
Entry "HKCR\otkloadr.WRLoader" refers to invalid object "{05741520-C4EB-440A-AC3F-9643BBC9F847}". Action Taken: No Action Taken.
Entry "HKCR\otkloadr.WRLoader.1" refers to invalid object "{05741520-C4EB-440A-AC3F-9643BBC9F847}". Action Taken: No Action Taken.
Entry "HKCR\OutlAddrParser" refers to invalid object "{00EAC191-C3E0-48DF-A055-7FB15720BE8E}". Action Taken: No Action Taken.
Entry "HKCR\OutlAddrParser.1" refers to invalid object "{00EAC191-C3E0-48DF-A055-7FB15720BE8E}". Action Taken: No Action Taken.
Entry "HKCR\OutlMapiPH" refers to invalid object "{8D2595E1-07C3-11D3-B8AF-00105A19CDC6}". Action Taken: No Action Taken.
Entry "HKCR\OutlMapiPH.1" refers to invalid object "{8D2595E1-07C3-11D3-B8AF-00105A19CDC6}". Action Taken: No Action Taken.
Entry "HKCR\Outlook.Application" refers to invalid object "{0006F03A-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\Outlook.Application.11" refers to invalid object "{0006F03A-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\Outlook.Envelope" refers to invalid object "{0006F01A-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\Outlook.Envelope.11" refers to invalid object "{0006F01A-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\Outlook.FileAttach" refers to invalid object "{0006F031-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\Outlook.MsgAttach" refers to invalid object "{0006F032-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OutlPOPPH" refers to invalid object "{848F8363-04C9-11D3-B8AF-00105A19CDC6}". Action Taken: No Action Taken.
Entry "HKCR\OutlPOPPH.1" refers to invalid object "{848F8363-04C9-11D3-B8AF-00105A19CDC6}". Action Taken: No Action Taken.
Entry "HKCR\OutlSMTPPH" refers to invalid object "{8D2595E0-07C3-11D3-B8AF-00105A19CDC6}". Action Taken: No Action Taken.
Entry "HKCR\OutlSMTPPH.1" refers to invalid object "{8D2595E0-07C3-11D3-B8AF-00105A19CDC6}". Action Taken: No Action Taken.
Entry "HKCR\outlspam.SpamFilterCreator" refers to invalid object "{18D0D532-0E23-487C-A229-88FFBD9B9799}". Action Taken: No Action Taken.
Entry "HKCR\outlspam.SpamFilterCreator.1" refers to invalid object "{18D0D532-0E23-487C-A229-88FFBD9B9799}". Action Taken: No Action Taken.
Entry "HKCR\OVCtl.OVCtl" refers to invalid object "{0006F063-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OVCtl.OVCtl.1" refers to invalid object "{0006F063-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.AccSync.AccSubNotHandler" refers to invalid object "{A2DDA1DC-D557-486A-AFCF-E655B5656156}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.AccSync.AccSubNotHandler.1" refers to invalid object "{A2DDA1DC-D557-486A-AFCF-E655B5656156}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.AccSync.SyncMgrHandler" refers to invalid object "{180464BF-79D4-489B-BB3F-950B8C527DD4}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.AccSync.SyncMgrHandler.1" refers to invalid object "{180464BF-79D4-489B-BB3F-950B8C527DD4}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.ChartSpace" refers to invalid object "{0002E55D-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.ChartSpace.11" refers to invalid object "{0002E55D-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.DataSourceControl" refers to invalid object "{0002E55B-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.DataSourceControl.11" refers to invalid object "{0002E55B-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.FieldList" refers to invalid object "{0002E55E-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.FieldList.11" refers to invalid object "{0002E55E-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.NumberFormat" refers to invalid object "{2C5A4157-324C-4B29-BC36-63ECC6B77CC5}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.NumberFormat.1" refers to invalid object "{2C5A4157-324C-4B29-BC36-63ECC6B77CC5}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.OfflineInfo_OfflineInfo" refers to invalid object "{867ECD39-FD5D-427B-AC28-AF236565BECA}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.OfflineInfo_OfflineInfo.1" refers to invalid object "{867ECD39-FD5D-427B-AC28-AF236565BECA}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.PivotTable" refers to invalid object "{0002E55A-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.PivotTable.11" refers to invalid object "{0002E55A-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.RecordNavigationControl" refers to invalid object "{0002E55C-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.RecordNavigationControl.11" refers to invalid object "{0002E55C-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.Spreadsheet" refers to invalid object "{0002E559-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.Spreadsheet.11" refers to invalid object "{0002E559-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OWCATP.OWCATP" refers to invalid object "{3F98D457-551B-48C5-BDE8-7FDECCD5AFA5}". Action Taken: No Action Taken.
Entry "HKCR\OWCATP.OWCATP.2" refers to invalid object "{3F98D457-551B-48C5-BDE8-7FDECCD5AFA5}". Action Taken: No Action Taken.
Entry "HKCR\OWS.BrowserUI" refers to invalid object "{BDEADE43-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.BrowserUI.2" refers to invalid object "{BDEADE43-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.ClientCollaboration" refers to invalid object "{BDEADEB8-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.ClientCollaboration.2" refers to invalid object "{BDEADEB8-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.ClientComment" refers to invalid object "{BDEADE42-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.ClientComment.2" refers to invalid object "{BDEADE42-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.ClientCommentThread" refers to invalid object "{BDEADE40-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.ClientCommentThread.2" refers to invalid object "{BDEADE40-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.ClientEventSubscription" refers to invalid object "{BDEADE3E-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.ClientEventSubscription.2" refers to invalid object "{BDEADE3E-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.ClientMiscApis" refers to invalid object "{BDEADE3F-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.ClientMiscApis.2" refers to invalid object "{BDEADE3F-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.DiscussionBar.1" refers to invalid object "{BDEADEE0-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.DiscussionServers" refers to invalid object "{BDEADEB7-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.DiscussionServers.2" refers to invalid object "{BDEADEB7-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.ExcelUI" refers to invalid object "{BDEADEB3-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.ExcelUI.2" refers to invalid object "{BDEADEB3-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.PostData" refers to invalid object "{BDEADE98-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.PostData.1" refers to invalid object "{BDEADE98-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.PptUI" refers to invalid object "{BDEADEB5-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.PptUI.2" refers to invalid object "{BDEADEB5-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.WordUI" refers to invalid object "{BDEADEB4-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.WordUI.2" refers to invalid object "{BDEADEB4-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\Paper.Document" refers to invalid object "{AAEC6A40-8FE6-106A-BCF0-0020AF25B98A}". Action Taken: No Action Taken.
Entry "HKCR\PDCube2.PDCubeCreate.1" refers to invalid object "{8A285C52-8687-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\PowerPoint.Application" refers to invalid object "{91493441-5A91-11CF-8700-00AA0060263B}". Action Taken: No Action Taken.
Entry "HKCR\PowerPoint.Application.11" refers to invalid object "{91493441-5A91-11CF-8700-00AA0060263B}". Action Taken: No Action Taken.
Entry "HKCR\RECIP.RecipCtl.1" refers to invalid object "{0006F023-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\RefEdit.Ctrl" refers to invalid object "{00024512-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\RNL.RNLEngine" refers to invalid object "{24A1D7C2-47FD-4F31-B5DB-9FBC1910A2D4}". Action Taken: No Action Taken.
Entry "HKCR\RNL.RNLEngine.1" refers to invalid object "{24A1D7C2-47FD-4F31-B5DB-9FBC1910A2D4}". Action Taken: No Action Taken.
Entry "HKCR\SchedulePlus.Application" refers to invalid object "{0482E074-C5B7-101A-82E0-08002B36A333}". Action Taken: No Action Taken.
Entry "HKCR\SchedulePlus.Application.7" refers to invalid object "{0482E074-C5B7-101A-82E0-08002B36A333}". Action Taken: No Action Taken.
Entry "HKCR\SchedulePlus.Library" refers to invalid object "{800DD100-DB43-11CE-914E-00A004000162}". Action Taken: No Action Taken.
Entry "HKCR\SchedulePlus.Library.7" refers to invalid object "{800DD100-DB43-11CE-914E-00A004000162}". Action Taken: No Action Taken.
Entry "HKCR\SharePoint.OpenDocuments.1" refers to invalid object "{BDEADEF2-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\SharePoint.OpenDocuments.2" refers to invalid object "{9F9C4924-C3F3-4459-A396-9E9E0D8B83D1}". Action Taken: No Action Taken.
Entry "HKCR\SharePoint.SpreadsheetLauncher" refers to invalid object "{3FD37ABB-F90A-4DE5-AA38-179629E64C2F}". Action Taken: No Action Taken.
Entry "HKCR\SharePoint.SpreadsheetLauncher.1" refers to invalid object "{BDEADE9E-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\SharePoint.SpreadsheetLauncher.2" refers to invalid object "{3FD37ABB-F90A-4DE5-AA38-179629E64C2F}". Action Taken: No Action Taken.
Entry "HKCR\SharePoint.StssyncHandler" refers to invalid object "{BDEADEF4-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\SharePoint.StssyncHandler.2" refers to invalid object "{BDEADEF4-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\Srdrv1.Alternates" refers to invalid object "{5487C2E7-3897-4FF7-9F18-BBA544EC0FCF}". Action Taken: No Action Taken.
Entry "HKCR\Srdrv1.Alternates.3" refers to invalid object "{5487C2E7-3897-4FF7-9F18-BBA544EC0FCF}". Action Taken: No Action Taken.
Entry "HKCR\STSUpld.UploadCtl" refers to invalid object "{07B06095-5687-4D13-9E32-12B4259C9813}". Action Taken: No Action Taken.
Entry "HKCR\STSUpld.UploadCtl.1" refers to invalid object "{07B06095-5687-4D13-9E32-12B4259C9813}". Action Taken: No Action Taken.
Entry "HKCR\USPInt.USPIntFactory" refers to invalid object "{39E4ABC0-0641-4230-9962-CDA8CFF95F22}". Action Taken: No Action Taken.
Entry "HKCR\USPInt.USPIntFactory.1" refers to invalid object "{39E4ABC0-0641-4230-9962-CDA8CFF95F22}". Action Taken: No Action Taken.
Entry "HKCR\VsaVbRT" refers to invalid object "{24800CD0-0F4E-4df7-9F69-3C6903C89224}". Action Taken: No Action Taken.
Entry "HKCR\VSFLEX.vsFlexArrayCtrl.1" refers to invalid object "{8AE029D3-08E3-11D1-BAA2-444553540000}". Action Taken: No Action Taken.
Entry "HKCR\VSFLEX.vsFlexStringCtrl.1" refers to invalid object "{8AE029D6-08E3-11D1-BAA2-444553540000}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpFile" refers to invalid object "{60704304-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpFile.2" refers to invalid object "{60704304-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpFolder" refers to invalid object "{60704305-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpFolder.2" refers to invalid object "{60704305-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpMetaInfo" refers to invalid object "{60704307-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpMetaInfo.2" refers to invalid object "{60704307-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpStats" refers to invalid object "{6070430A-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpStats.2" refers to invalid object "{6070430A-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpStructureElement" refers to invalid object "{60704309-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpStructureElement.2" refers to invalid object "{60704309-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpStructureModification" refers to invalid object "{60704308-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpStructureModification.2" refers to invalid object "{60704308-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpwAccessSetup2" refers to invalid object "{6070430B-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpwGroup2" refers to invalid object "{6070430D-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpwUser2" refers to invalid object "{6070430C-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.WebExtenderClient" refers to invalid object "{60704306-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.WebExtenderClient.2" refers to invalid object "{60704306-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.
Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr.1" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.
Entry "HKCR\ZAMailSafe\shell\open\command" refers to invalid object ""C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" -warning "%1"". Action Taken: No Action Taken.
File C:\WINDOWS\System32\mc-58-12-0000133.exe tagged as "not-a-virus:AdWare.Win32.Maxifiles.f". Action Taken: No Action Taken.
File C:\Documents and Settings\Matthrew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-3c936701-7e596b08.zip infected by "Trojan-Downloader.Java.OpenStream.w" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Matthrew\Desktop\BSINSTALL.exe tagged as "not-a-virus:AdWare.SaveNow.z". Action Taken: No Action Taken.
File C:\Matthew\OiUninstaller.exe tagged as "not-a-virus:AdWare.Win32.MediaTickets.n". Action Taken: No Action Taken.
File C:\Program Files\DNS\Catcher.dll tagged as "not-a-virus:AdWare.Win32.Maxifiles.a". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001237.sys infected by "Rootkit.Win32.Agent.l" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001238.sys infected by "Rootkit.Win32.Agent.l" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001239.sys infected by "Rootkit.Win32.Agent.l" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001240.exe tagged as "not-a-virus:AdWare.Maxifiles.j". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001241.exe tagged as "not-a-virus:AdWare.Win32.Maxifiles.h". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001243.exe tagged as "not-a-virus:AdWare.Win32.AdSrve.c". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001244.exe tagged as "not-a-virus:AdWare.AdSrve.b". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001245.exe tagged as "not-a-virus:AdWare.Win32.VB.a". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001246.exe tagged as "not-a-virus:AdWare.Win32.UrlSpy.a". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001253.dll infected by "Trojan-Dropper.Win32.Small.xm" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001267.ini tagged as "not-a-virus:AdWare.Win32.Sahat.ao". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0006403.dll tagged as "not-a-virus:AdWare.Win32.Maxifiles.a". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0006404.exe tagged as "not-a-virus:AdWare.Maxifiles.j". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0006405.exe tagged as "not-a-virus:AdWare.Maxifiles.j". Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\mc-58-12-0000133.exe tagged as "not-a-virus:AdWare.Win32.Maxifiles.f". Action Taken: No Action Taken.








Logfile of HijackThis v1.99.1
Scan saved at 4:38:48 PM, on 09/29/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSI\Live Update 3\LMonitor.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\ScanSoft\PAPERP~1\PPWebCap.exe
C:\Program Files\AIM\aim.exe
C:\Tools\SpywareGuard\sgbhp.exe
C:\WINDOWS\explorer.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.earthlink.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink.net/partner/more/msie/button/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://start.earthlink.net/AL/Search
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.earthlink.net/partner/more/msie/button/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.earthlink.net/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9022
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {44F9B173-041C-4825-A9B9-D914BD9DCBB3} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: EarthLink ScamBlocker V2 - {15F4D456-5BAA-4076-8486-EECB38CD3E57} - C:\Program Files\EarthLink TotalAccess\Toolbar\EScamBlk.dll
O2 - BHO: EarthLink PopUp Blocker V2 - {512ACF1B-64D9-4928-B382-A80556F28DB4} - C:\Program Files\EarthLink TotalAccess\Toolbar\ElnkPuB.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-001234567890} - (no file)
O2 - BHO: (no name) - {656EC4B7-072B-4698-B504-2A414C1F0037} - (no file)
O2 - BHO: Earthlink Protection BHO - {9579D574-D4D8-4335-9560-FE8641A013BD} - C:\Program Files\EarthLink TotalAccess\Toolbar\ProtctIE.dll
O2 - BHO: Uninstall Legacy Earthlink Toolbar - {E713904C-DF05-4C79-BBAD-02DB923253BE} - C:\Program Files\EarthLink TotalAccess\Toolbar\uninsttb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EPSON Stylus C82 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE /P32 "EPSON Stylus C82 Series (Copy 1)" /O6 "USB001" /M "Stylus C82"
O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB003" /M "Stylus CX5400"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [PPWebCap] C:\PROGRA~1\ScanSoft\PAPERP~1\PPWebCap.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4E330863-6A11-11D0-BFD8-006097237877} - http://tw.msi.com.tw/autobios/client/iftwclix.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1126740081864
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1126740173915
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner37320.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: EarthLink Monitor Service (EarthLinkMonitor) - Boingo Wireless, Inc. - C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe





Edit: I didn't realize HJT kept backups of the items I deleted with it. I did not delete them before running MWAV, so they may have been detected by the scan. I have removed them now. My apologies.
 

·
TSF Security Manager, Emeritus
Joined
·
42,837 Posts
Hi,

You didn’t need to delete the HJT backups just yet, but thanks for letting me know.

To clean out those orphaned registry entries showing in Mwav, please download Ccleaner www.ccleaner.com Do not run it yet.

Reboot into Safe Mode.(tapping F8 or F5)

Copy the file names below to the clipboard by highlighting them and pressing Ctrl-C:

C:\WINDOWS\System32\mc-58-12-0000133.exe
C:\Documents and Settings\Matthrew\Desktop\BSINSTALL.exe
C:\Matthew\OiUninstaller.exe
C:\Program Files\DNS\Catcher.dll


Start KillBox.
Go to the File menu, and choose Paste from Clipboard.
Verify that you've done this properly by clicking the dropdown-arrow next to the Full Path of File to Delete field. The filenames you pasted will be found in there.
Select/tick the following:
* Delete on Reboot
* End Explorer Shell While Killing File
* Unregister.dll Before Deleting" if it's not grayed out.
Click the RED X button.

Click [Yes] at the 'Delete on Reboot' prompt. Click [No] at the Pending Operations prompt.

Uninstall the following via the Add/Remove Panel (Start->(Settings)->Control Panel->Add/Remove Programs) if they exist:

DNS

Delete the following folder:

C:\Program Files\DNS

Clear your Java Cache:
Click on Start->Settings->Control Panel->Java Plug-in and click on the Cache tab. Then click on the Clear button and hit OK.

Run Ccleaner.
Click on the 'Issues' tab to clean registry. Be sure that box is checked to 'prompt to backup registry' in the Options>Advanced section.

Click 'Analyze', then 'Fix Issues'

Reboot into Normal Mode.

Run another scan with Mwav and post the results here along with a new HijackThis log and an update on how your system is running.

If you are still experiencing problems with programs not starting , etc., please do the following as well:

Click Start>Run> and type in sfc /scannow (there is a space between sfc and /) and let it scan for missing/corrupt files. You may need your Windows XP install disc so have it handy.
 

·
Registered
Joined
·
28 Posts
Discussion Starter #15
Followed the directions, just about to run the scans.
However, in my control panel there was no item labeled as "Java Plug-in".
There was one simply named "Java" which I opened but could find nothing about clearing caches.
What should I do about that...?
 

·
Registered
Joined
·
28 Posts
Discussion Starter #17 (Edited)
Ran a scan in MWAV, but the powers that be made my computer crash yet again before I could copy and paste the results.
I've rebooted in safe mode and am going to try and run it again, seeing as the computer seems much less crash-susceptable there. It should take somewhere around four hours.
I also have the Windows XP install disc sitting right next to me as you asked.

Edit: And I deleted the Java cache files via the direction in the link you gave me. I had actually done that previously without realizing it, I guess. But I did it again to make sure.

Edit2: Uh... My D drive disappeared. It's just... Not in My Computer anymore. This has happened once before, come to think about it, but it eventually reappeared on its own.
Really kind of creepy when you think about it. Phantom D drive.
I don't have anything important on there but... I figured it was worth mentioning.
 

·
TSF Security Manager, Emeritus
Joined
·
42,837 Posts
Ok, do this first then:

Click Start>Run> and type in sfc /scannow (there is a space between sfc and /) and let it scan for missing/corrupt files. You may need your Windows XP install disc so have it handy.

Mwav should be run from Safe Mode. :wink:

Let me know...
 

·
Registered
Joined
·
28 Posts
Discussion Starter #19 (Edited)
Well, the sfc /scannow didn't turn up anything... I think.
I started it up, put in the disc, and let it run.
The bar filled up and then the little window closed with no other messages.
That how it's supposed to work?

Regardless, I have the HJT and MWAV logs you asked for.

====================================================================
Log was analyzed using KRC HijackThis Analyzer - Updated on 8/4/05
Get updates at http://www.greyknight17.com/download.htm#programs

***Security Programs Detected***


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Logfile of HijackThis v1.99.1
Scan saved at 7:57:01 PM, on 09/30/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\javascript.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\MSI\Live Update 3\LMonitor.exe
C:\WINDOWS\System32\tesakrmger.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.earthlink.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink.net/partner/more/msie/button/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://start.earthlink.net/AL/Search
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.earthlink.net/partner/more/msie/button/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.earthlink.net/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9022
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {44F9B173-041C-4825-A9B9-D914BD9DCBB3} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: EarthLink ScamBlocker V2 - {15F4D456-5BAA-4076-8486-EECB38CD3E57} - C:\Program Files\EarthLink TotalAccess\Toolbar\EScamBlk.dll
O2 - BHO: EarthLink PopUp Blocker V2 - {512ACF1B-64D9-4928-B382-A80556F28DB4} - C:\Program Files\EarthLink TotalAccess\Toolbar\ElnkPuB.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-001234567890} - (no file)
O2 - BHO: (no name) - {656EC4B7-072B-4698-B504-2A414C1F0037} - (no file)
O2 - BHO: Earthlink Protection BHO - {9579D574-D4D8-4335-9560-FE8641A013BD} - C:\Program Files\EarthLink TotalAccess\Toolbar\ProtctIE.dll
O2 - BHO: Uninstall Legacy Earthlink Toolbar - {E713904C-DF05-4C79-BBAD-02DB923253BE} - C:\Program Files\EarthLink TotalAccess\Toolbar\uninsttb.dll
O4 - HKLM\..\Run: [EPSON Stylus C82 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE /P32 "EPSON Stylus C82 Series (Copy 1)" /O6 "USB001" /M "Stylus C82"
O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB003" /M "Stylus CX5400"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe
O4 - HKLM\..\Run: [Windeows NetStart Service2] tesakrmger.exe
O4 - HKLM\..\RunServices: [Windeows NetStart Service2] tesakrmger.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4E330863-6A11-11D0-BFD8-006097237877} - http://tw.msi.com.tw/autobios/client/iftwclix.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1126740081864
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1126740173915
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner37320.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: EarthLink Monitor Service (EarthLinkMonitor) - Boingo Wireless, Inc. - C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Enables Javascript Support (Javascript) - Unknown owner - C:\WINDOWS\System32\javascript.exe


End of KRC HijackThis Analyzer Log.
====================================================================





File C:\WINDOWS\System32\javascript.exe infected by "Backdoor.Win32.Codbot.al" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\System32\javascript.exe infected by "Backdoor.Win32.Codbot.al" Virus! Action Taken: No Action Taken.
Object "bearshare Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "powerstrip Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "powerstrip Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "bearshare Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "kazaa Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "win32.passma Virus" found in File System! Action Taken: No Action Taken.
Object "bearshare Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "bearshare Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "midaddle Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "midaddle Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "conducent flexpak Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "180solutions Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "midaddle Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "sahagent Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "maxspeed Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "atgames Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "midaddle Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "midaddle Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "midaddle Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "unknown toolbar Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "atgames Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "midaddle Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "coolwebsearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "coolwebsearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "statblaster Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "maxspeed Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "atgames Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "midaddle Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "midaddle Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "midaddle Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "unknown toolbar Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "kazaa Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "coolwebsearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "coolwebsearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "sahagent Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "midaddle Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "cws.smartsearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "Software\Microsoft\Windows\CurrentVersion\ModuleUsage\C:\WINDOWS\SYSTEM\ddrawex.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "Software\Microsoft\Windows\CurrentVersion\ModuleUsage\C:\WINDOWS\SYSTEM\quartz.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "8dc45701cfeb". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{94D5AF0F-E6EE-4A75-BE31-9C9C9A87AD45}". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{120A76F4-55FE-41FA-9EB1-9C35B8D25E11}" refers to invalid object "C:\WINDOWS\System32\GCCollection.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{140CF3D1-451B-4C9C-AB04-02C72D06A88D}" refers to invalid object "C:\Program Files\Microsoft AntiSpyware\gcAntiSpywareLibrary.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{1C4D3904-8E59-437B-A010-B3CE69588807}" refers to invalid object "C:\Tools\eAntiSpyTrial\Controls\vbalColumnTreeView6.ocx". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{1D29F3E7-72A2-490E-926B-22E32F34A8DE}" refers to invalid object "G:\install4\VBWINSYS.EXE". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{1D8A3351-C678-11D1-AA6F-000000000000}" refers to invalid object "C:\WINDOWS\system32\DartSock.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{233A9691-667E-11D1-9DFB-006097D50408}" refers to invalid object "C:\Program Files\MSN\MSNCoreFiles\mailui.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{259B72ED-9E4A-11D4-9546-00A0CC532DDD}" refers to invalid object "C:\Program Files\Visioneer OneTouch\OneTouchImgConv.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{29DBA9AA-9E3B-45DC-BE20-CB0B3311D5C5}" refers to invalid object "C:\DOCUME~1\Matthrew\LOCALS~1\Temp\Word8.0\MSForms.exd". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{311EDE7B-141B-4A7F-BC31-A1C0D946F514}" refers to invalid object "C:\Program Files\MSN\MSNIA\CC\MSNCC\msncc.exe". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{31DDE823-839A-4DD2-8D96-DF766052E142}" refers to invalid object "C:\Program Files\Microsoft AntiSpyware\gcTCPObjLib.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{3C2D2A1E-031F-4397-9614-87C932A848E0}" refers to invalid object "C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{401190A3-CDEA-11D2-953E-0040052FC4F9}" refers to invalid object "C:\Program Files\Visioneer OneTouch\OneTouchTargets.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{4CFCC039-CD0C-11D2-953E-0040052FC4F9}" refers to invalid object "C:\Program Files\Visioneer OneTouch\OneTouchDevices.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{527A4DA4-7F2C-11D2-B12D-0000F81F5995}" refers to invalid object "C:\WINDOWS\SYSTEM\DXTRANS.DLL". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{52D761FC-F7A2-4CF1-AEA9-B1746E2A2B5C}" refers to invalid object "C:\Program Files\Microsoft AntiSpyware\gcASSoapLib.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{5A06DF87-4C43-47B5-9654-B9457B61C774}" refers to invalid object "C:\DOCUME~1\CHUCKO~1\LOCALS~1\Temp\Word8.0\MSForms.exd". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{5C39C5CE-809D-11D5-B195-0050DA0F20FC}" refers to invalid object "C:\WINDOWS\surfmonkey\SMProxy.exe". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{620B2E33-9B8C-11D3-B0B7-0050DA0F20FC}" refers to invalid object "C:\WINDOWS\surfmonkey\IMClient.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{71A2702D-C7D8-11D2-BEF8-525400DFB47A}" refers to invalid object "C:\Tools\eAntiSpyTrial\Controls\SSubTmr6.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{7479B280-A309-415C-A351-05483C51F75F}" refers to invalid object "C:\Program Files\Microsoft AntiSpyware\gcSoftwareUpdateLib.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{77ECEA78-E034-4DE3-8ED7-545449FA2339}" refers to invalid object "C:\PROGRAM FILES\MSN\MSNCOREFILES\SEAL.DLL". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}" refers to invalid object "C:\WINDOWS\SYSTEM32\AniGIF.ocx". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{86073239-029C-458B-8546-383694B94B7D}" refers to invalid object "C:\Program Files\Microsoft AntiSpyware\gcASPrivacyLib.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{87BCF2DB-8E1F-4F90-B16D-C088A5BF53D4}" refers to invalid object "C:\DOCUME~1\CHUCKO~1\LOCALS~1\Temp\Word8.0\MSForms.exd". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{94EF7DB4-DFBA-11D2-953E-0040052FC4F9}" refers to invalid object "C:\Program Files\Visioneer OneTouch\OneTouchTransfer.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{9869EFA6-18E9-11D3-A837-00104B9E30B5}" refers to invalid object "C:\DOCUME~1\Matthrew\LOCALS~1\Temp\CmdLineExt03.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{ABBA0019-3075-11D6-88A4-00B0D0200F88}" refers to invalid object "C:\WINDOWS\SYSTEM32\psisdecd.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{ACAC3D3B-FA11-48ED-B087-CA33448F8B64}" refers to invalid object "C:\Tools\Microsoft AntiSpyware\shellextension.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{B162D478-EF46-4475-B1FE-216BDEDB7FAD}" refers to invalid object "C:\WINDOWS\WT\WEBDRIVER\WTMULTI.DLL". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{B6F2E083-CC31-11D2-953E-0040052FC4F9}" refers to invalid object "C:\Program Files\Visioneer OneTouch\OneTouchSettings.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{B7E20302-C22C-4AF2-9D75-C3EB6EEE9DD8}" refers to invalid object "C:\WINDOWS\WT\WEBDRIVER\WTHOSTCTL.DLL". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{C39962BA-5DDC-408D-9367-FEE637EE54D6}" refers to invalid object "C:\Program Files\Microsoft AntiSpyware\gcASThreatAudit.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{CEACE91F-3F71-4A8C-B952-63716B2BC026}" refers to invalid object "C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{DCB43485-19FB-4D6D-BB3D-73C7F48D5F00}" refers to invalid object "C:\Program Files\Messenger\rtcimsp.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{E3DEE443-DCC1-11D2-953E-0040052FC4F9}" refers to invalid object "C:\Program Files\Visioneer OneTouch\OneTouchHardware.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{F62EC210-3A46-4AE0-AFC4-22A796213285}" refers to invalid object "C:\Program Files\MSN\MSNIA\CC\MSNCC\logonmgr.exe". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{F8822891-E2C5-11D5-B1BC-0050DA0F20FC}" refers to invalid object "C:\WINDOWS\surfmonkey\epevents.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{FA13AA2E-CA9B-11D2-9780-00104B242EA3}" refers to invalid object "C:\WINDOWS\WT\WEBDRIVER\WEBDRIVER.DLL". Action Taken: No Action Taken.
Entry "HKCR\.crl" refers to invalid object "CRLFile". Action Taken: No Action Taken.
Entry "HKCR\.p10" refers to invalid object "P10File". Action Taken: No Action Taken.
Entry "HKCR\.p12" refers to invalid object "PFXFile". Action Taken: No Action Taken.
Entry "HKCR\.p7b" refers to invalid object "SPCFile". Action Taken: No Action Taken.
Entry "HKCR\.p7m" refers to invalid object "P7MFile". Action Taken: No Action Taken.
Entry "HKCR\.p7r" refers to invalid object "SPCFile". Action Taken: No Action Taken.
Entry "HKCR\.p7s" refers to invalid object "P7SFile". Action Taken: No Action Taken.
Entry "HKCR\.pfx" refers to invalid object "PFXFile". Action Taken: No Action Taken.
Entry "HKCR\.pko" refers to invalid object "PKOFile". Action Taken: No Action Taken.
Entry "HKCR\.spc" refers to invalid object "SPCFile". Action Taken: No Action Taken.
Entry "HKCR\.stl" refers to invalid object "STLFile". Action Taken: No Action Taken.
Entry "HKCR\BlnMgr.BlnMgr.11" refers to invalid object "{2B992972-69FB-470B-B823-3AA54ADB0D5E}". Action Taken: No Action Taken.
Entry "HKCR\BlnMgrPs.BlnMgrPs.11" refers to invalid object "{A0577268-C54E-4CF4-BBD1-DFEB3DC680F7}". Action Taken: No Action Taken.
Entry "HKCR\BlnMgrPs.BlnPs.11" refers to invalid object "{8CEF9607-D94D-4DB5-B264-95A3120D5BAC}". Action Taken: No Action Taken.
Entry "HKCR\BlnMgrPs.BlnSetPs.11" refers to invalid object "{00D6C06D-E5F9-495B-9C0A-CC35E74891B4}". Action Taken: No Action Taken.
Entry "HKCR\BlnMgrPs.BlnSetUserPs.11" refers to invalid object "{261F6572-578B-40A7-B72E-61B7261D9F0C}". Action Taken: No Action Taken.
Entry "HKCR\DataCtl.DataCtl" refers to invalid object "{0468C085-CA5B-11D0-AF08-00609797F0E0}". Action Taken: No Action Taken.
Entry "HKCR\DataCtl.DataCtl.1" refers to invalid object "{0468C085-CA5B-11D0-AF08-00609797F0E0}". Action Taken: No Action Taken.
Entry "HKCR\DMM.CEALG" refers to invalid object "{89555CC1-4928-11D3-8D4C-00E029154FDE}". Action Taken: No Action Taken.
Entry "HKCR\DMM.CEALG.1" refers to invalid object "{89555CC1-4928-11D3-8D4C-00E029154FDE}". Action Taken: No Action Taken.
Entry "HKCR\DMM.ClassificationModel" refers to invalid object "{830437A6-2F36-11D3-8C76-00600832DCED}". Action Taken: No Action Taken.
Entry "HKCR\DMM.ClassificationModel.1" refers to invalid object "{830437A6-2F36-11D3-8C76-00600832DCED}". Action Taken: No Action Taken.
Entry "HKCR\DMM.Classifier" refers to invalid object "{08EAF772-59A5-11D3-B3A7-00C04F687719}". Action Taken: No Action Taken.
Entry "HKCR\DMM.Classifier.1" refers to invalid object "{08EAF772-59A5-11D3-B3A7-00C04F687719}". Action Taken: No Action Taken.
Entry "HKCR\DMM.DMMCorrCount" refers to invalid object "{65813659-4461-11D3-8C7B-00600832DCED}". Action Taken: No Action Taken.
Entry "HKCR\DMM.DMMCorrCount.1" refers to invalid object "{65813659-4461-11D3-8C7B-00600832DCED}". Action Taken: No Action Taken.
Entry "HKCR\DMM.DMMCorrCountSource" refers to invalid object "{65813656-4461-11D3-8C7B-00600832DCED}". Action Taken: No Action Taken.
Entry "HKCR\DMM.DMMCorrCountSource.1" refers to invalid object "{65813656-4461-11D3-8C7B-00600832DCED}". Action Taken: No Action Taken.
Entry "HKCR\DXSurface.OAVEmpty" refers to invalid object "{98E2F337-EE36-11D3-BA3C-00C04F6843FA}". Action Taken: No Action Taken.
Entry "HKCR\DXSurface.OAVEmpty.1" refers to invalid object "{98E2F337-EE36-11D3-BA3C-00C04F6843FA}". Action Taken: No Action Taken.
Entry "HKCR\Equation.3" refers to invalid object "{0002CE02-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\Equations" refers to invalid object "{0002CE02-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\Excel.Application" refers to invalid object "{00024500-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\Excel.Application.11" refers to invalid object "{00024500-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\ExcelChart" refers to invalid object "{00030001-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\ExcelMacrosheet" refers to invalid object "{00030002-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\ExcelWorksheet" refers to invalid object "{00030000-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\FName.Factoid" refers to invalid object "{87EF1CFE-51CA-4E6B-8C76-E576AA926888}". Action Taken: No Action Taken.
Entry "HKCR\FName.Factoid.2" refers to invalid object "{87EF1CFE-51CA-4E6B-8C76-E576AA926888}". Action Taken: No Action Taken.
Entry "HKCR\FPDTC.LISTVIEWCTL" refers to invalid object "{4421FEE2-A45D-11D3-9F7C-005004AE6818}". Action Taken: No Action Taken.
Entry "HKCR\FPDTC.LISTVIEWCTL.1" refers to invalid object "{4421FEE2-A45D-11D3-9F7C-005004AE6818}". Action Taken: No Action Taken.
Entry "HKCR\FPDTC.LISTVIEWPPG" refers to invalid object "{4421FEE4-A45D-11D3-9F7C-005004AE6818}". Action Taken: No Action Taken.
Entry "HKCR\FPDTC.LISTVIEWPPG.1" refers to invalid object "{4421FEE4-A45D-11D3-9F7C-005004AE6818}". Action Taken: No Action Taken.
Entry "HKCR\FPDTC.NAVBARCTL" refers to invalid object "{4421FEDE-A45D-11D3-9F7C-005004AE6818}". Action Taken: No Action Taken.
Entry "HKCR\FPDTC.NAVBARCTL.1" refers to invalid object "{4421FEDE-A45D-11D3-9F7C-005004AE6818}". Action Taken: No Action Taken.
Entry "HKCR\FPDTC.NAVBARPPG" refers to invalid object "{4421FEE3-A45D-11D3-9F7C-005004AE6818}". Action Taken: No Action Taken.
Entry "HKCR\FPDTC.NAVBARPPG.1" refers to invalid object "{4421FEE3-A45D-11D3-9F7C-005004AE6818}". Action Taken: No Action Taken.
Entry "HKCR\FPDTC.NAVBARSTYLEPPG" refers to invalid object "{59049080-EEE1-11D3-9F8B-005004AE6818}". Action Taken: No Action Taken.
Entry "HKCR\FPDTC.NAVBARSTYLEPPG.1" refers to invalid object "{59049080-EEE1-11D3-9F8B-005004AE6818}". Action Taken: No Action Taken.
Entry "HKCR\FPerson.Factoid" refers to invalid object "{339361CD-6723-455D-A40B-C95F1F91FF8A}". Action Taken: No Action Taken.
Entry "HKCR\FPerson.Factoid.2" refers to invalid object "{339361CD-6723-455D-A40B-C95F1F91FF8A}". Action Taken: No Action Taken.
Entry "HKCR\FStock.Factoid" refers to invalid object "{49DF3409-46B3-4B0C-B7BF-FEC0F9401EDD}". Action Taken: No Action Taken.
Entry "HKCR\FStock.Factoid.2" refers to invalid object "{49DF3409-46B3-4B0C-B7BF-FEC0F9401EDD}". Action Taken: No Action Taken.
Entry "HKCR\HTMLInlineSoundCtl.1" refers to invalid object "{8422DAE3-9929-11CF-B8D3-004033373DA8}". Action Taken: No Action Taken.
Entry "HKCR\HTMLInlineVideoCtl.1" refers to invalid object "{8422DAE7-9929-11CF-B8D3-004033373DA8}". Action Taken: No Action Taken.
Entry "HKCR\Ietag.EvtSink" refers to invalid object "{08F5D2F6-4AE5-486B-98E0-3E85BA6B4D11}". Action Taken: No Action Taken.
Entry "HKCR\Ietag.EvtSink.1" refers to invalid object "{08F5D2F6-4AE5-486B-98E0-3E85BA6B4D11}". Action Taken: No Action Taken.
Entry "HKCR\Ietag.Factory" refers to invalid object "{38481807-CA0E-42D2-BF39-B33AF135CC4D}". Action Taken: No Action Taken.
Entry "HKCR\Ietag.Factory.1" refers to invalid object "{38481807-CA0E-42D2-BF39-B33AF135CC4D}". Action Taken: No Action Taken.
Entry "HKCR\Ietag.OOC" refers to invalid object "{03B54468-0899-4233-8689-623FFFC295EE}". Action Taken: No Action Taken.
Entry "HKCR\Ietag.OOC.1" refers to invalid object "{03B54468-0899-4233-8689-623FFFC295EE}". Action Taken: No Action Taken.
Entry "HKCR\IMClient.SMIMClient" refers to invalid object "{620B2E41-9B8C-11D3-B0B7-0050DA0F20FC}". Action Taken: No Action Taken.
Entry "HKCR\IMClient.SMIMClient.1" refers to invalid object "{620B2E41-9B8C-11D3-B0B7-0050DA0F20FC}". Action Taken: No Action Taken.
Entry "HKCR\LISTNET.Listnet" refers to invalid object "{65BCBEE4-7728-41A0-97BE-14E1CAE36AAE}". Action Taken: No Action Taken.
Entry "HKCR\LISTNET.Listnet.11" refers to invalid object "{65BCBEE4-7728-41A0-97BE-14E1CAE36AAE}". Action Taken: No Action Taken.
Entry "HKCR\LR.LexRefStEsObject.1.0" refers to invalid object "{4CFB5280-800B-4367-848F-5A13EBF27F1D}". Action Taken: No Action Taken.
Entry "HKCR\LR.LexRefStEsObject.1.0.1" refers to invalid object "{4CFB5280-800B-4367-848F-5A13EBF27F1D}". Action Taken: No Action Taken.
Entry "HKCR\LR.LexRefStFrObject.1.0" refers to invalid object "{B3E0E785-BD78-4366-9560-B7DABE2723BE}". Action Taken: No Action Taken.
Entry "HKCR\LR.LexRefStFrObject.1.0.1" refers to invalid object "{B3E0E785-BD78-4366-9560-B7DABE2723BE}". Action Taken: No Action Taken.
Entry "HKCR\MailFileAtt" refers to invalid object "{00020D05-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\MailMsgAtt" refers to invalid object "{00020D09-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\MapiCvt.MapiCvt" refers to invalid object "{0006F085-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\MapiCvt.MapiCvt.1" refers to invalid object "{0006F085-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\mapifvbx.object" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.
Entry "HKCR\mapifvbx.object.1" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.
Entry "HKCR\MARQUEE.MarqueeCtrl.1" refers to invalid object "{250770F3-6AF2-11CF-A915-008029E31FCD}". Action Taken: No Action Taken.
Entry "HKCR\mce.CCSProperties" refers to invalid object "{4E7F49AF-E4B5-11D1-8D9D-006097DBEFEF}". Action Taken: No Action Taken.
Entry "HKCR\mce.CCSproperty" refers to invalid object "{4E7F49AD-E4B5-11D1-8D9D-006097DBEFEF}". Action Taken: No Action Taken.
Entry "HKCR\mce.chartwizard" refers to invalid object "{4E7F49D5-E4B5-11D1-8D9D-006097DBEFEF}". Action Taken: No Action Taken.
Entry "HKCR\mce.IMCEResource" refers to invalid object "{4E7F49B6-E4B5-11D1-8D9D-006097DBEFEF}". Action Taken: No Action Taken.
Entry "HKCR\mce.IMCEResources" refers to invalid object "{5D62A639-0FB0-11D2-8DB2-006097DBEFEF}". Action Taken: No Action Taken.
Entry "HKCR\mce.MiniCubeEditor" refers to invalid object "{4E7F49B8-E4B5-11D1-8D9D-006097DBEFEF}". Action Taken: No Action Taken.
Entry "HKCR\mce.RW" refers to invalid object "{4E7F49CF-E4B5-11D1-8D9D-006097DBEFEF}". Action Taken: No Action Taken.
Entry "HKCR\MediaCatalogDB" refers to invalid object "{09E767A6-4481-4791-86A5-A739E5290E4C}". Action Taken: No Action Taken.
Entry "HKCR\MediaCatalogDB.11" refers to invalid object "{09E767A6-4481-4791-86A5-A739E5290E4C}". Action Taken: No Action Taken.
Entry "HKCR\MediaCatalogMergedDB" refers to invalid object "{1B118620-8818-4E01-A5DB-E56764F709DB}". Action Taken: No Action Taken.
Entry "HKCR\MediaCatalogMergedDB.11" refers to invalid object "{1B118620-8818-4E01-A5DB-E56764F709DB}". Action Taken: No Action Taken.
Entry "HKCR\MediaCatalogWebDB" refers to invalid object "{75F1D42A-FD3E-478C-A36C-433B847441BD}". Action Taken: No Action Taken.
Entry "HKCR\MediaCatalogWebDB.11" refers to invalid object "{75F1D42A-FD3E-478C-A36C-433B847441BD}". Action Taken: No Action Taken.
Entry "HKCR\Microsoft.Access.OLEDB.10.0" refers to invalid object "{25377C20-D19C-11D2-B483-00600832C573}". Action Taken: No Action Taken.
Entry "HKCR\Microsoft.Office.List.OLEDB.1.0" refers to invalid object "{252BFDA2-4B21-4872-ABA3-043945949BF8}". Action Taken: No Action Taken.
Entry "HKCR\Microsoft.VbaAddinForOutlook" refers to invalid object "{799ED9EA-FB5E-11D1-B7D6-00C04FC2AAE2}". Action Taken: No Action Taken.
Entry "HKCR\Microsoft.VbaAddinForOutlook.1" refers to invalid object "{799ED9EA-FB5E-11D1-B7D6-00C04FC2AAE2}". Action Taken: No Action Taken.
Entry "HKCR\Microsoft.WebCapture" refers to invalid object "{742D385A-D5BF-427D-9AF2-88258FB73EAF}". Action Taken: No Action Taken.
Entry "HKCR\Microsoft.WebCapture.1" refers to invalid object "{742D385A-D5BF-427D-9AF2-88258FB73EAF}". Action Taken: No Action Taken.
Entry "HKCR\MicrosoftRDO.rdoEngine" refers to invalid object "{5E71F04C-551F-11CF-8152-00AA00A40C25}". Action Taken: No Action Taken.
Entry "HKCR\MicrosoftRDO.RdoQuery" refers to invalid object "{5EBB68F5-3BF1-11CF-814C-00AA00A40C25}". Action Taken: No Action Taken.
Entry "HKCR\Midoc.MiDocument" refers to invalid object "{863305F6-E822-4C08-9BE1-F1C7CFC919AF}". Action Taken: No Action Taken.
Entry "HKCR\Midoc.MiDocument.1" refers to invalid object "{863305F6-E822-4C08-9BE1-F1C7CFC919AF}". Action Taken: No Action Taken.
Entry "HKCR\MiDocViewer.MiRioEventSink" refers to invalid object "{5CBAD860-46EE-4193-8FDF-5EF8625E0CA1}". Action Taken: No Action Taken.
Entry "HKCR\MiDocViewer.MiRioEventSink.1" refers to invalid object "{5CBAD860-46EE-4193-8FDF-5EF8625E0CA1}". Action Taken: No Action Taken.
Entry "HKCR\MiEng.MiEngine" refers to invalid object "{9D13E607-106F-4892-8A83-FF9827C0A3D5}". Action Taken: No Action Taken.
Entry "HKCR\MiEng.MiEngine.1" refers to invalid object "{9D13E607-106F-4892-8A83-FF9827C0A3D5}". Action Taken: No Action Taken.
Entry "HKCR\MiImage.NbImageLayer" refers to invalid object "{8EE4C235-F2CE-4C3B-9ADE-DD68718AE32A}". Action Taken: No Action Taken.
Entry "HKCR\MiImage.NbImageLayer.1" refers to invalid object "{8EE4C235-F2CE-4C3B-9ADE-DD68718AE32A}". Action Taken: No Action Taken.
Entry "HKCR\MiInkSeg.MiRichInkSegment" refers to invalid object "{7EDA10AF-96CA-49AD-8BE0-FFE624FB5D5E}". Action Taken: No Action Taken.
Entry "HKCR\MiInkSeg.MiRichInkSegment.1" refers to invalid object "{7EDA10AF-96CA-49AD-8BE0-FFE624FB5D5E}". Action Taken: No Action Taken.
Entry "HKCR\MiInkSeg.MiRioEventSender" refers to invalid object "{AD3704F3-6BE8-4ADE-9737-BF0DB60060B8}". Action Taken: No Action Taken.
Entry "HKCR\MiInkSeg.MiRioEventSender.1" refers to invalid object "{AD3704F3-6BE8-4ADE-9737-BF0DB60060B8}". Action Taken: No Action Taken.
Entry "HKCR\MimeDir.MimeDirItem" refers to invalid object "{0006F081-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\MimeDir.MimeDirItem.1" refers to invalid object "{0006F081-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\MimeDir.MimeDirParser" refers to invalid object "{0006F082-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\MimeDir.MimeDirParser.1" refers to invalid object "{0006F082-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\MimeDir.MimeDirProfile" refers to invalid object "{0006F084-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\MimeDir.MimeDirProfile.1" refers to invalid object "{0006F084-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\MODI.Document" refers to invalid object "{40942A6C-1520-4132-BDF8-BDC1F71F547B}". Action Taken: No Action Taken.
Entry "HKCR\MODI.Document.1" refers to invalid object "{40942A6C-1520-4132-BDF8-BDC1F71F547B}". Action Taken: No Action Taken.
Entry "HKCR\MOFL.Factoid" refers to invalid object "{64AB6C69-B40E-40AF-9B7F-F5687B48E2B6}". Action Taken: No Action Taken.
Entry "HKCR\MOFL.Factoid.2" refers to invalid object "{64AB6C69-B40E-40AF-9B7F-F5687B48E2B6}". Action Taken: No Action Taken.
Entry "HKCR\MSAddnDr.AddInDesigner" refers to invalid object "{AC0714F6-3D04-11D1-AE7D-00A0C90F26F4}". Action Taken: No Action Taken.
Entry "HKCR\MSAddnDr.AddInDesigner.1" refers to invalid object "{AC0714F6-3D04-11D1-AE7D-00A0C90F26F4}". Action Taken: No Action Taken.
Entry "HKCR\MSAddnDr.AddInInstance" refers to invalid object "{AC0714F7-3D04-11D1-AE7D-00A0C90F26F4}". Action Taken: No Action Taken.
Entry "HKCR\MSAddnDr.AddInInstance.1" refers to invalid object "{AC0714F7-3D04-11D1-AE7D-00A0C90F26F4}". Action Taken: No Action Taken.
Entry "HKCR\MSASR.LocaleHandler" refers to invalid object "{3246A6CF-2898-4541-AA7E-3F847903D29B}". Action Taken: No Action Taken.
Entry "HKCR\MSASR.LocaleHandler.2" refers to invalid object "{3246A6CF-2898-4541-AA7E-3F847903D29B}". Action Taken: No Action Taken.
Entry "HKCR\MSASR.LocaleHandler1041" refers to invalid object "{8619FFAE-8AE1-481F-84B2-41A3C9669C0A}". Action Taken: No Action Taken.
Entry "HKCR\MSASR.LocaleHandler1041.2" refers to invalid object "{8619FFAE-8AE1-481F-84B2-41A3C9669C0A}". Action Taken: No Action Taken.
Entry "HKCR\MSASR.LocaleHandler2052" refers to invalid object "{35AAEA84-40DC-4397-9A80-613FD196FBAD}". Action Taken: No Action Taken.
Entry "HKCR\MSASR.LocaleHandler2052.2" refers to invalid object "{35AAEA84-40DC-4397-9A80-613FD196FBAD}". Action Taken: No Action Taken.
Entry "HKCR\MSASR60.ITN1033" refers to invalid object "{8A17CA50-7EDE-46DA-BBC7-87408B393CFB}". Action Taken: No Action Taken.
Entry "HKCR\MSASR60.ITN1033.2" refers to invalid object "{8A17CA50-7EDE-46DA-BBC7-87408B393CFB}". Action Taken: No Action Taken.
Entry "HKCR\Msasrx.MsasrUI" refers to invalid object "{4C7A1FE9-5047-4E61-90A0-872436277809}". Action Taken: No Action Taken.
Entry "HKCR\Msasrx.MsasrUI.3" refers to invalid object "{4C7A1FE9-5047-4E61-90A0-872436277809}". Action Taken: No Action Taken.
Entry "HKCR\Msasrx.RecoExt" refers to invalid object "{6BEF5B00-D46E-49B0-BFD2-49847061ED73}". Action Taken: No Action Taken.
Entry "HKCR\Msasrx.RecoExt.3" refers to invalid object "{6BEF5B00-D46E-49B0-BFD2-49847061ED73}". Action Taken: No Action Taken.
Entry "HKCR\MSDAIPP.WEBFOLDERFORMS" refers to invalid object "{11480D94-C3A5-11D3-BA7C-00C04F7948B3}". Action Taken: No Action Taken.
Entry "HKCR\MSDAIPP.WEBFOLDERFORMS.1" refers to invalid object "{11480D94-C3A5-11D3-BA7C-00C04F7948B3}". Action Taken: No Action Taken.
Entry "HKCR\MSDMine" refers to invalid object "{2CB6C2D3-DD7C-11D2-AFE4-00105A994724}". Action Taken: No Action Taken.
Entry "HKCR\MSDMine.1" refers to invalid object "{2CB6C2D3-DD7C-11D2-AFE4-00105A994724}". Action Taken: No Action Taken.
Entry "HKCR\MSDMine.MSDMineEnum" refers to invalid object "{8853D6B2-E8AE-11D2-AFE8-00105A994724}". Action Taken: No Action Taken.
Entry "HKCR\MSDMine.MSDMineEnum.1" refers to invalid object "{8853D6B2-E8AE-11D2-AFE8-00105A994724}". Action Taken: No Action Taken.
Entry "HKCR\MSDMineErrorLookup" refers to invalid object "{72B082C6-97D5-11D3-8BEC-00C04F68DDC2}". Action Taken: No Action Taken.
Entry "HKCR\MSDMineErrorLookup.1" refers to invalid object "{72B082C6-97D5-11D3-8BEC-00C04F68DDC2}". Action Taken: No Action Taken.
Entry "HKCR\MSExchange.Events" refers to invalid object "{2F42C693-C6A4-11D0-93E9-00AA0064D470}". Action Taken: No Action Taken.
Entry "HKCR\MSExchange.Events.1" refers to invalid object "{2F42C693-C6A4-11D0-93E9-00AA0064D470}". Action Taken: No Action Taken.
Entry "HKCR\MSGraph.Application" refers to invalid object "{00024502-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\MSGraph.Application.8" refers to invalid object "{00024502-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\MSGraph.Chart" refers to invalid object "{00020803-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\MSGraph.Chart.5" refers to invalid object "{00020801-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\MSGraph.Chart.8" refers to invalid object "{00020803-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\MSMDSRV.PNDComManager" refers to invalid object "{3A5E75F5-DE4B-11D2-AB46-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOAUTH.Binder" refers to invalid object "{46816230-46E3-11D3-8D01-005004838617}". Action Taken: No Action Taken.
Entry "HKCR\MSOAUTH.Binder.1" refers to invalid object "{46816230-46E3-11D3-8D01-005004838617}". Action Taken: No Action Taken.
Entry "HKCR\MsoEuro.Converter" refers to invalid object "{30A095E2-9A0C-11D2-93BB-00105A994D2C}". Action Taken: No Action Taken.
Entry "HKCR\MsoEuro.Converter.1" refers to invalid object "{30A095E2-9A0C-11D2-93BB-00105A994D2C}". Action Taken: No Action Taken.
Entry "HKCR\MSOLAP.2" refers to invalid object "{A07CCD0C-8148-11D0-87BB-00C04FC33942}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPAggregation" refers to invalid object "{1E083973-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPAggregation.1" refers to invalid object "{1E083973-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPAggregations" refers to invalid object "{1E083972-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPAggregations.1" refers to invalid object "{1E083972-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPAuxiliarie" refers to invalid object "{1E083979-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPAuxiliarie.1" refers to invalid object "{1E083979-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPAuxiliaries" refers to invalid object "{1E083978-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPAuxiliaries.1" refers to invalid object "{1E083978-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPClient" refers to invalid object "{1E083962-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPClient.1" refers to invalid object "{1E083962-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPCubeSecurities" refers to invalid object "{1E08397D-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPCubeSecurities.1" refers to invalid object "{1E08397D-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPCubeSecurity" refers to invalid object "{1E08397C-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPCubeSecurity.1" refers to invalid object "{1E08397C-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPDatabase" refers to invalid object "{1E083964-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPDatabase.1" refers to invalid object "{1E083964-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPDatabases" refers to invalid object "{1E083963-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPDatabases.1" refers to invalid object "{1E083963-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPDetail" refers to invalid object "{1E08396B-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPDetail.1" refers to invalid object "{1E08396B-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPDetails" refers to invalid object "{1E08396A-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPDetails.1" refers to invalid object "{1E08396A-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPDimension" refers to invalid object "{1E083969-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPDimension.1" refers to invalid object "{1E083969-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPDimensions" refers to invalid object "{1E083980-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPDimensions.1" refers to invalid object "{1E083980-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPExtLevel" refers to invalid object "{1E083975-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPExtLevel.1" refers to invalid object "{1E083975-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPExtLevels" refers to invalid object "{1E083974-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPExtLevels.1" refers to invalid object "{1E083974-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPExtMeasure" refers to invalid object "{1E083977-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPExtMeasure.1" refers to invalid object "{1E083977-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPExtMeasures" refers to invalid object "{1E083976-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPExtMeasures.1" refers to invalid object "{1E083976-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPLastError" refers to invalid object "{1E08397F-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPLastError.1" refers to invalid object "{1E08397F-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPLevel" refers to invalid object "{1E08396D-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPLevel.1" refers to invalid object "{1E08396D-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPLevels" refers to invalid object "{1E08396C-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPLevels.1" refers to invalid object "{1E08396C-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPLockManager" refers to invalid object "{1E08397E-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPLockManager.1" refers to invalid object "{1E08397E-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPMeasure" refers to invalid object "{1E08396F-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPMeasure.1" refers to invalid object "{1E08396F-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPMeasures" refers to invalid object "{1E08396E-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPMeasures.1" refers to invalid object "{1E08396E-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPModel" refers to invalid object "{1E083968-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPModel.1" refers to invalid object "{1E083968-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPModels" refers to invalid object "{1E083967-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPModels.1" refers to invalid object "{1E083967-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPPartition" refers to invalid object "{1E083971-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPPartition.1" refers to invalid object "{1E083971-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPPartitions" refers to invalid object "{1E083970-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPPartitions.1" refers to invalid object "{1E083970-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPRole" refers to invalid object "{1E08397A-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPRole.1" refers to invalid object "{1E08397A-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPRoles" refers to invalid object "{1E08397B-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPRoles.1" refers to invalid object "{1E08397B-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPSource" refers to invalid object "{1E083966-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPSource.1" refers to invalid object "{1E083966-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPSources" refers to invalid object "{1E083965-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOlapAdmin2.MSOLAPSources.1" refers to invalid object "{1E083965-829F-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\MSOLAPErrorLookup.2" refers to invalid object "{A07CCD0D-8148-11D0-87BB-00C04FC33942}". Action Taken: No Action Taken.
Entry "HKCR\MSOLAPUI80.ConnectDialog" refers to invalid object "{5C63C824-4122-4A70-A03E-482B2B9A8269}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimateDHTMLBehavior" refers to invalid object "{816CA828-8BE4-11D3-A498-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimateDHTMLBehavior.1" refers to invalid object "{816CA828-8BE4-11D3-A498-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimColorDHTMLBehavior" refers to invalid object "{816CA825-8BE4-11D3-A498-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimColorDHTMLBehavior.1" refers to invalid object "{816CA825-8BE4-11D3-A498-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimExecutiveBehavior" refers to invalid object "{A4639D3F-774E-11D3-A490-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimExecutiveBehavior.1" refers to invalid object "{A4639D3F-774E-11D3-A490-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimFilterDHTMLBehavior" refers to invalid object "{816CA82A-8BE4-11D3-A498-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimFilterDHTMLBehavior.1" refers to invalid object "{816CA82A-8BE4-11D3-A498-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimMotionDHTMLBehavior" refers to invalid object "{816CA82C-8BE4-11D3-A498-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimMotionDHTMLBehavior.1" refers to invalid object "{816CA82C-8BE4-11D3-A498-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimRotationDHTMLBehavior" refers to invalid object "{816CA82E-8BE4-11D3-A498-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimRotationDHTMLBehavior.1" refers to invalid object "{816CA82E-8BE4-11D3-A498-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimScaleDHTMLBehavior" refers to invalid object "{816CA830-8BE4-11D3-A498-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimScaleDHTMLBehavior.1" refers to invalid object "{816CA830-8BE4-11D3-A498-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimSetDHTMLBehavior" refers to invalid object "{816CA832-8BE4-11D3-A498-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.AnimSetDHTMLBehavior.1" refers to invalid object "{816CA832-8BE4-11D3-A498-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.CommandDHTMLBehavior" refers to invalid object "{5DC20347-0A84-11D4-A4EE-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.CommandDHTMLBehavior.1" refers to invalid object "{5DC20347-0A84-11D4-A4EE-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.IEAnimBehaviorFactory" refers to invalid object "{A4639D2F-774E-11D3-A490-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.IEAnimBehaviorFactory.1" refers to invalid object "{A4639D2F-774E-11D3-A490-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.IEEventListenerProxy" refers to invalid object "{1A556DAA-781C-11D3-A490-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.IEEventListenerProxy.1" refers to invalid object "{1A556DAA-781C-11D3-A490-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.IEPropertyListenerProxy" refers to invalid object "{1A556DAC-781C-11D3-A490-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.IEPropertyListenerProxy.1" refers to invalid object "{1A556DAC-781C-11D3-A490-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.IETimeBehaviorFactory" refers to invalid object "{A4639D29-774E-11D3-A490-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.IETimeBehaviorFactory.1" refers to invalid object "{A4639D29-774E-11D3-A490-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.IterateDHTMLBehavior" refers to invalid object "{B96F84F7-D5AB-11D3-A4CA-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.IterateDHTMLBehavior.1" refers to invalid object "{B96F84F7-D5AB-11D3-A4CA-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.OAVDShowPlayer" refers to invalid object "{3FDA5DC2-ECE0-11D3-9C20-00C04F72DD5F}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.OAVDShowPlayer.1" refers to invalid object "{3FDA5DC2-ECE0-11D3-9C20-00C04F72DD5F}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.OAVIEClock" refers to invalid object "{B1A3692E-EAFB-11D3-A4DC-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.OAVIEClock.1" refers to invalid object "{B1A3692E-EAFB-11D3-A4DC-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.OAVMediaDHTMLBehavior" refers to invalid object "{3408C281-EAEA-11D3-A4DC-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.OAVMediaDHTMLBehavior.1" refers to invalid object "{3408C281-EAEA-11D3-A4DC-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.OAVRedirectFallback" refers to invalid object "{999937BC-30FE-11D4-BA52-00C04F6843FA}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.OAVRedirectFallback.1" refers to invalid object "{999937BC-30FE-11D4-BA52-00C04F6843FA}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.TimeDHTMLBehavior" refers to invalid object "{A4639D41-774E-11D3-A490-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.TimeDHTMLBehavior.1" refers to invalid object "{A4639D41-774E-11D3-A490-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.TimeExecutiveBehavior" refers to invalid object "{A4639D33-774E-11D3-A490-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MsoRun.TimeExecutiveBehavior.1" refers to invalid object "{A4639D33-774E-11D3-A490-00C04F6843FB}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.ByteArrayAttachment30" refers to invalid object "{86EB31E4-A46F-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.DataEncoderFactory30" refers to invalid object "{86EB31E8-A46F-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.DimeComposer30" refers to invalid object "{86EB31DF-A46F-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.DimeParser30" refers to invalid object "{86EB31E2-A46F-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.FileAttachment30" refers to invalid object "{86EB31E3-A46F-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.GenericCustomTypeMapper30" refers to invalid object "{9A36D31A-A470-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.ReceivedAttachment30" refers to invalid object "{86EB31E7-A46F-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.ReceivedAttachments30" refers to invalid object "{86EB31EE-A46F-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.SentAttachments30" refers to invalid object "{86EB31ED-A46F-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.SimpleComposer30" refers to invalid object "{86EB31EB-A46F-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.SimpleParser30" refers to invalid object "{86EB31EC-A46F-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.SoapClient30" refers to invalid object "{34E0D4B8-A470-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.SoapReader30" refers to invalid object "{52ABBE5B-A470-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.SoapSerializer30" refers to invalid object "{764FE7E3-A470-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.SoapTypeMapperFactory30" refers to invalid object "{9A36D319-A470-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.StreamAttachment30" refers to invalid object "{86EB31E6-A46F-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.StringAttachment30" refers to invalid object "{86EB31E5-A46F-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.UDTMapper30" refers to invalid object "{9A36D31B-A470-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\MSOSOAP.WSDLReader30" refers to invalid object "{9A36D318-A470-11D6-9500-00065B874123}". Action Taken: No Action Taken.
Entry "HKCR\Msshed.ShedDSO" refers to invalid object "{5F6C4076-12F5-11D3-8CEE-005004838434}". Action Taken: No Action Taken.
Entry "HKCR\Msshed.ShedDSO.1" refers to invalid object "{5F6C4076-12F5-11D3-8CEE-005004838434}". Action Taken: No Action Taken.
Entry "HKCR\Msshed.ShedListDSO" refers to invalid object "{B8E622FC-D912-4C4D-B0F9-616AA3B44EED}". Action Taken: No Action Taken.
Entry "HKCR\Msshed.ShedListDSO.1" refers to invalid object "{B8E622FC-D912-4C4D-B0F9-616AA3B44EED}". Action Taken: No Action Taken.
Entry "HKCR\MSUSP.OCD" refers to invalid object "{433CBF68-A873-4C6D-A211-623281ED930E}". Action Taken: No Action Taken.
Entry "HKCR\MSUSP.OCD.1" refers to invalid object "{433CBF68-A873-4C6D-A211-623281ED930E}". Action Taken: No Action Taken.
Entry "HKCR\Msxml2.DOMDocument.5.0" refers to invalid object "{88D969E5-F192-11D4-A65F-0040963251E5}". Action Taken: No Action Taken.
Entry "HKCR\Msxml2.DSOControl.5.0" refers to invalid object "{88D969E9-F192-11D4-A65F-0040963251E5}". Action Taken: No Action Taken.
Entry "HKCR\Msxml2.FreeThreadedDOMDocument.5.0" refers to invalid object "{88D969E6-F192-11D4-A65F-0040963251E5}". Action Taken: No Action Taken.
Entry "HKCR\Msxml2.MXDigitalSignature.5.0" refers to invalid object "{88D969F5-F192-11D4-A65F-0040963251E5}". Action Taken: No Action Taken.
Entry "HKCR\Msxml2.MXHTMLWriter.5.0" refers to invalid object "{88D969F0-F192-11D4-A65F-0040963251E5}". Action Taken: No Action Taken.
Entry "HKCR\Msxml2.MXNamespaceManager.5.0" refers to invalid object "{88D969F1-F192-11D4-A65F-0040963251E5}". Action Taken: No Action Taken.
Entry "HKCR\Msxml2.MXXMLWriter.5.0" refers to invalid object "{88D969EF-F192-11D4-A65F-0040963251E5}". Action Taken: No Action Taken.
Entry "HKCR\Msxml2.SAXAttributes.5.0" refers to invalid object "{88D969EE-F192-11D4-A65F-0040963251E5}". Action Taken: No Action Taken.
Entry "HKCR\Msxml2.SAXXMLReader.5.0" refers to invalid object "{88D969EC-8B8B-4C3D-859E-AF6CD158BE0F}". Action Taken: No Action Taken.
Entry "HKCR\Msxml2.ServerXMLHTTP.5.0" refers to invalid object "{88D969EB-F192-11D4-A65F-0040963251E5}". Action Taken: No Action Taken.
Entry "HKCR\Msxml2.XMLHTTP.5.0" refers to invalid object "{88D969EA-F192-11D4-A65F-0040963251E5}". Action Taken: No Action Taken.
Entry "HKCR\Msxml2.XMLSchemaCache.5.0" refers to invalid object "{88D969E7-F192-11D4-A65F-0040963251E5}". Action Taken: No Action Taken.
Entry "HKCR\Msxml2.XSLTemplate.5.0" refers to invalid object "{88D969E8-F192-11D4-A65F-0040963251E5}". Action Taken: No Action Taken.
Entry "HKCR\MultiMgrAddIn.AddInDesigner1" refers to invalid object "{3EDC309B-6AF0-11D4-963C-000039B6C417}". Action Taken: No Action Taken.
Entry "HKCR\Office.Authz" refers to invalid object "{4453D895-F2A1-4A38-A285-1EF9BD3F6D5D}". Action Taken: No Action Taken.
Entry "HKCR\Office.Authz.1" refers to invalid object "{4453D895-F2A1-4A38-A285-1EF9BD3F6D5D}". Action Taken: No Action Taken.
Entry "HKCR\OfficeCompatible.Application" refers to invalid object "{812034D2-760F-11CF-9370-00AA00B8BF00}". Action Taken: No Action Taken.
Entry "HKCR\OfficeCompatible.Application.1" refers to invalid object "{812034D2-760F-11CF-9370-00AA00B8BF00}". Action Taken: No Action Taken.
Entry "HKCR\ORG10SVR.Application" refers to invalid object "{787A1520-75B9-11CF-980D-444553540000}". Action Taken: No Action Taken.
Entry "HKCR\ORG10SVR.Application.1" refers to invalid object "{787A1520-75B9-11CF-980D-444553540000}". Action Taken: No Action Taken.
Entry "HKCR\OSE.Discussion" refers to invalid object "{BDEADEDA-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OSE.Discussion.2" refers to invalid object "{BDEADEDA-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OSE.Discussions" refers to invalid object "{BDEADEDB-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OSE.Discussions.2" refers to invalid object "{BDEADEDB-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OSE.DiscussionServer" refers to invalid object "{BDEADEDC-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OSE.DiscussionServer.2" refers to invalid object "{BDEADEDC-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OSE.DiscussionServers" refers to invalid object "{BDEADEDD-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OSE.DiscussionServers.2" refers to invalid object "{BDEADEDD-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OSE.Global" refers to invalid object "{BDEADEDE-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OSE.Global.2" refers to invalid object "{BDEADEDE-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\otkloadr.WRAssembly" refers to invalid object "{A08A033D-1A75-4AB6-A166-EAD02F547959}". Action Taken: No Action Taken.
Entry "HKCR\otkloadr.WRAssembly.1" refers to invalid object "{A08A033D-1A75-4AB6-A166-EAD02F547959}". Action Taken: No Action Taken.
Entry "HKCR\otkloadr.WRLoader" refers to invalid object "{05741520-C4EB-440A-AC3F-9643BBC9F847}". Action Taken: No Action Taken.
Entry "HKCR\otkloadr.WRLoader.1" refers to invalid object "{05741520-C4EB-440A-AC3F-9643BBC9F847}". Action Taken: No Action Taken.
Entry "HKCR\OutlAddrParser" refers to invalid object "{00EAC191-C3E0-48DF-A055-7FB15720BE8E}". Action Taken: No Action Taken.
Entry "HKCR\OutlAddrParser.1" refers to invalid object "{00EAC191-C3E0-48DF-A055-7FB15720BE8E}". Action Taken: No Action Taken.
Entry "HKCR\OutlMapiPH" refers to invalid object "{8D2595E1-07C3-11D3-B8AF-00105A19CDC6}". Action Taken: No Action Taken.
Entry "HKCR\OutlMapiPH.1" refers to invalid object "{8D2595E1-07C3-11D3-B8AF-00105A19CDC6}". Action Taken: No Action Taken.
Entry "HKCR\Outlook.Application" refers to invalid object "{0006F03A-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\Outlook.Application.11" refers to invalid object "{0006F03A-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\Outlook.Envelope" refers to invalid object "{0006F01A-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\Outlook.Envelope.11" refers to invalid object "{0006F01A-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\Outlook.FileAttach" refers to invalid object "{0006F031-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\Outlook.MsgAttach" refers to invalid object "{0006F032-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OutlPOPPH" refers to invalid object "{848F8363-04C9-11D3-B8AF-00105A19CDC6}". Action Taken: No Action Taken.
Entry "HKCR\OutlPOPPH.1" refers to invalid object "{848F8363-04C9-11D3-B8AF-00105A19CDC6}". Action Taken: No Action Taken.
Entry "HKCR\OutlSMTPPH" refers to invalid object "{8D2595E0-07C3-11D3-B8AF-00105A19CDC6}". Action Taken: No Action Taken.
Entry "HKCR\OutlSMTPPH.1" refers to invalid object "{8D2595E0-07C3-11D3-B8AF-00105A19CDC6}". Action Taken: No Action Taken.
Entry "HKCR\outlspam.SpamFilterCreator" refers to invalid object "{18D0D532-0E23-487C-A229-88FFBD9B9799}". Action Taken: No Action Taken.
Entry "HKCR\outlspam.SpamFilterCreator.1" refers to invalid object "{18D0D532-0E23-487C-A229-88FFBD9B9799}". Action Taken: No Action Taken.
Entry "HKCR\OVCtl.OVCtl" refers to invalid object "{0006F063-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OVCtl.OVCtl.1" refers to invalid object "{0006F063-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.AccSync.AccSubNotHandler" refers to invalid object "{A2DDA1DC-D557-486A-AFCF-E655B5656156}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.AccSync.AccSubNotHandler.1" refers to invalid object "{A2DDA1DC-D557-486A-AFCF-E655B5656156}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.AccSync.SyncMgrHandler" refers to invalid object "{180464BF-79D4-489B-BB3F-950B8C527DD4}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.AccSync.SyncMgrHandler.1" refers to invalid object "{180464BF-79D4-489B-BB3F-950B8C527DD4}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.ChartSpace" refers to invalid object "{0002E55D-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.ChartSpace.11" refers to invalid object "{0002E55D-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.DataSourceControl" refers to invalid object "{0002E55B-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.DataSourceControl.11" refers to invalid object "{0002E55B-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.FieldList" refers to invalid object "{0002E55E-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.FieldList.11" refers to invalid object "{0002E55E-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.NumberFormat" refers to invalid object "{2C5A4157-324C-4B29-BC36-63ECC6B77CC5}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.NumberFormat.1" refers to invalid object "{2C5A4157-324C-4B29-BC36-63ECC6B77CC5}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.OfflineInfo_OfflineInfo" refers to invalid object "{867ECD39-FD5D-427B-AC28-AF236565BECA}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.OfflineInfo_OfflineInfo.1" refers to invalid object "{867ECD39-FD5D-427B-AC28-AF236565BECA}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.PivotTable" refers to invalid object "{0002E55A-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.PivotTable.11" refers to invalid object "{0002E55A-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.RecordNavigationControl" refers to invalid object "{0002E55C-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.RecordNavigationControl.11" refers to invalid object "{0002E55C-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.Spreadsheet" refers to invalid object "{0002E559-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OWC11.Spreadsheet.11" refers to invalid object "{0002E559-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\OWCATP.OWCATP" refers to invalid object "{3F98D457-551B-48C5-BDE8-7FDECCD5AFA5}". Action Taken: No Action Taken.
Entry "HKCR\OWCATP.OWCATP.2" refers to invalid object "{3F98D457-551B-48C5-BDE8-7FDECCD5AFA5}". Action Taken: No Action Taken.
Entry "HKCR\OWS.BrowserUI" refers to invalid object "{BDEADE43-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.BrowserUI.2" refers to invalid object "{BDEADE43-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.ClientCollaboration" refers to invalid object "{BDEADEB8-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.ClientCollaboration.2" refers to invalid object "{BDEADEB8-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.ClientComment" refers to invalid object "{BDEADE42-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.ClientComment.2" refers to invalid object "{BDEADE42-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.ClientCommentThread" refers to invalid object "{BDEADE40-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.ClientCommentThread.2" refers to invalid object "{BDEADE40-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.ClientEventSubscription" refers to invalid object "{BDEADE3E-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.ClientEventSubscription.2" refers to invalid object "{BDEADE3E-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.ClientMiscApis" refers to invalid object "{BDEADE3F-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.ClientMiscApis.2" refers to invalid object "{BDEADE3F-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.DiscussionBar.1" refers to invalid object "{BDEADEE0-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.DiscussionServers" refers to invalid object "{BDEADEB7-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.DiscussionServers.2" refers to invalid object "{BDEADEB7-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.ExcelUI" refers to invalid object "{BDEADEB3-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.ExcelUI.2" refers to invalid object "{BDEADEB3-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.PostData" refers to invalid object "{BDEADE98-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.PostData.1" refers to invalid object "{BDEADE98-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.PptUI" refers to invalid object "{BDEADEB5-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.PptUI.2" refers to invalid object "{BDEADEB5-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.WordUI" refers to invalid object "{BDEADEB4-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\OWS.WordUI.2" refers to invalid object "{BDEADEB4-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\Paper.Document" refers to invalid object "{AAEC6A40-8FE6-106A-BCF0-0020AF25B98A}". Action Taken: No Action Taken.
Entry "HKCR\PDCube2.PDCubeCreate.1" refers to invalid object "{8A285C52-8687-11D3-AB5D-00C04F9407B9}". Action Taken: No Action Taken.
Entry "HKCR\PowerPoint.Application" refers to invalid object "{91493441-5A91-11CF-8700-00AA0060263B}". Action Taken: No Action Taken.
Entry "HKCR\PowerPoint.Application.11" refers to invalid object "{91493441-5A91-11CF-8700-00AA0060263B}". Action Taken: No Action Taken.
Entry "HKCR\Proxyevents.RecvSMPEvents" refers to invalid object "{F882289E-E2C5-11D5-B1BC-0050DA0F20FC}". Action Taken: No Action Taken.
Entry "HKCR\Proxyevents.RecvSMPEvents.1" refers to invalid object "{F882289E-E2C5-11D5-B1BC-0050DA0F20FC}". Action Taken: No Action Taken.
Entry "HKCR\RECIP.RecipCtl.1" refers to invalid object "{0006F023-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\RefEdit.Ctrl" refers to invalid object "{00024512-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\RNL.RNLEngine" refers to invalid object "{24A1D7C2-47FD-4F31-B5DB-9FBC1910A2D4}". Action Taken: No Action Taken.
Entry "HKCR\RNL.RNLEngine.1" refers to invalid object "{24A1D7C2-47FD-4F31-B5DB-9FBC1910A2D4}". Action Taken: No Action Taken.
Entry "HKCR\SchedulePlus.Application" refers to invalid object "{0482E074-C5B7-101A-82E0-08002B36A333}". Action Taken: No Action Taken.
Entry "HKCR\SchedulePlus.Application.7" refers to invalid object "{0482E074-C5B7-101A-82E0-08002B36A333}". Action Taken: No Action Taken.
Entry "HKCR\SchedulePlus.Library" refers to invalid object "{800DD100-DB43-11CE-914E-00A004000162}". Action Taken: No Action Taken.
Entry "HKCR\SchedulePlus.Library.7" refers to invalid object "{800DD100-DB43-11CE-914E-00A004000162}". Action Taken: No Action Taken.
Entry "HKCR\SharePoint.OpenDocuments.1" refers to invalid object "{BDEADEF2-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\SharePoint.OpenDocuments.2" refers to invalid object "{9F9C4924-C3F3-4459-A396-9E9E0D8B83D1}". Action Taken: No Action Taken.
Entry "HKCR\SharePoint.SpreadsheetLauncher" refers to invalid object "{3FD37ABB-F90A-4DE5-AA38-179629E64C2F}". Action Taken: No Action Taken.
Entry "HKCR\SharePoint.SpreadsheetLauncher.1" refers to invalid object "{BDEADE9E-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\SharePoint.SpreadsheetLauncher.2" refers to invalid object "{3FD37ABB-F90A-4DE5-AA38-179629E64C2F}". Action Taken: No Action Taken.
Entry "HKCR\SharePoint.StssyncHandler" refers to invalid object "{BDEADEF4-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\SharePoint.StssyncHandler.2" refers to invalid object "{BDEADEF4-C265-11D0-BCED-00A0C90AB50F}". Action Taken: No Action Taken.
Entry "HKCR\Srdrv1.Alternates" refers to invalid object "{5487C2E7-3897-4FF7-9F18-BBA544EC0FCF}". Action Taken: No Action Taken.
Entry "HKCR\Srdrv1.Alternates.3" refers to invalid object "{5487C2E7-3897-4FF7-9F18-BBA544EC0FCF}". Action Taken: No Action Taken.
Entry "HKCR\STSUpld.UploadCtl" refers to invalid object "{07B06095-5687-4D13-9E32-12B4259C9813}". Action Taken: No Action Taken.
Entry "HKCR\STSUpld.UploadCtl.1" refers to invalid object "{07B06095-5687-4D13-9E32-12B4259C9813}". Action Taken: No Action Taken.
Entry "HKCR\USPInt.USPIntFactory" refers to invalid object "{39E4ABC0-0641-4230-9962-CDA8CFF95F22}". Action Taken: No Action Taken.
Entry "HKCR\USPInt.USPIntFactory.1" refers to invalid object "{39E4ABC0-0641-4230-9962-CDA8CFF95F22}". Action Taken: No Action Taken.
Entry "HKCR\VsaVbRT" refers to invalid object "{24800CD0-0F4E-4df7-9F69-3C6903C89224}". Action Taken: No Action Taken.
Entry "HKCR\VSFLEX.vsFlexArrayCtrl.1" refers to invalid object "{8AE029D3-08E3-11D1-BAA2-444553540000}". Action Taken: No Action Taken.
Entry "HKCR\VSFLEX.vsFlexStringCtrl.1" refers to invalid object "{8AE029D6-08E3-11D1-BAA2-444553540000}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpFile" refers to invalid object "{60704304-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpFile.2" refers to invalid object "{60704304-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpFolder" refers to invalid object "{60704305-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpFolder.2" refers to invalid object "{60704305-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpMetaInfo" refers to invalid object "{60704307-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpMetaInfo.2" refers to invalid object "{60704307-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpStats" refers to invalid object "{6070430A-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpStats.2" refers to invalid object "{6070430A-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpStructureElement" refers to invalid object "{60704309-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpStructureElement.2" refers to invalid object "{60704309-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpStructureModification" refers to invalid object "{60704308-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpStructureModification.2" refers to invalid object "{60704308-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpwAccessSetup2" refers to invalid object "{6070430B-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpwGroup2" refers to invalid object "{6070430D-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.FpwUser2" refers to invalid object "{6070430C-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.WebExtenderClient" refers to invalid object "{60704306-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WECAPI5.WebExtenderClient.2" refers to invalid object "{60704306-094E-4A1E-B7B4-756F3537EC3B}". Action Taken: No Action Taken.
Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.
Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr.1" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.
File C:\WINDOWS\System32\tesakrmger.exe infected by "Backdoor.Win32.IRCBot.az" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Matthrew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-3c936701-7e596b08.zip infected by "Trojan-Downloader.Java.OpenStream.w" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001237.sys infected by "Rootkit.Win32.Agent.l" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001238.sys infected by "Rootkit.Win32.Agent.l" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001239.sys infected by "Rootkit.Win32.Agent.l" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001240.exe tagged as "not-a-virus:AdWare.Maxifiles.j". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001241.exe tagged as "not-a-virus:AdWare.Win32.Maxifiles.h". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001243.exe tagged as "not-a-virus:AdWare.Win32.AdSrve.c". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001244.exe tagged as "not-a-virus:AdWare.AdSrve.b". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001245.exe tagged as "not-a-virus:AdWare.Win32.VB.a". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001246.exe tagged as "not-a-virus:AdWare.Win32.UrlSpy.a". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001253.dll infected by "Trojan-Dropper.Win32.Small.xm" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0001267.ini tagged as "not-a-virus:AdWare.Win32.Sahat.ao". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0006403.dll tagged as "not-a-virus:AdWare.Win32.Maxifiles.a". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0006404.exe tagged as "not-a-virus:AdWare.Maxifiles.j". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP1\A0006405.exe tagged as "not-a-virus:AdWare.Maxifiles.j". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP4\A0016990.dll tagged as "not-a-virus:AdWare.Win32.Maxifiles.a". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP4\A0016992.exe tagged as "not-a-virus:AdWare.Win32.Maxifiles.f". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP4\A0016993.exe tagged as "not-a-virus:AdWare.SaveNow.z". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{D2F453C3-887F-4840-ABA3-5CEE46626134}\RP4\A0016994.exe tagged as "not-a-virus:AdWare.Win32.MediaTickets.n". Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\tesakrmger.exe infected by "Backdoor.Win32.IRCBot.az" Virus! Action Taken: No Action Taken.







Issues are still persisting. I should also be able to run scans and reply more quickly with the weekend coming up, so I'll be awaiting your aid.

Edit: Something more I noticed... Seemingly at random the "has encountered a problem and needs to close" message pops up for the Generic Host Process for Win32. I don't know what it means, but I'm sure it can't be good. The computer does seem to continue functioning with relative normallity afterwards, however.
 

·
TSF Security Manager, Emeritus
Joined
·
42,837 Posts
The infection has finally reared it's ugly head Heroic. :grin:

Reboot into Safe Mode.

Copy the file names below to the clipboard by highlighting them and pressing Ctrl-C:

C:\WINDOWS\System32\javascript.exe
C:\WINDOWS\System32\tesakrmger.exe


Start KillBox.
Go to the File menu, and choose Paste from Clipboard.
Verify that you've done this properly by clicking the dropdown-arrow next to the Full Path of File to Delete field. The filenames you pasted will be found in there.
Select/tick the following:
* Delete on Reboot
* End Explorer Shell While Killing File
* Unregister.dll Before Deleting" if it's not grayed out.
Click the RED X button.

Click [Yes] at the 'Delete on Reboot' prompt. Click [No] at the Pending Operations prompt.

Run a scan in HijackThis. Check each of the following and hit 'Fix checked' (after checking them) if they still exist (make sure not to miss any):

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [Windeows NetStart Service2] tesakrmger.exe
O4 - HKLM\..\RunServices: [Windeows NetStart Service2] tesakrmger.exe


Delete the following file:

C:\Documents and Settings\Matthrew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jav ainstaller.jar-3c936701-7e596b08.zip

Please--let's clean that registry :wink:

Run the Ccleaner I had you download earlier:
Click on the 'Issues' tab to clean registry. Be sure that box is checked to 'prompt to backup registry' in the Options>Advanced section.

Click 'Analyze', then 'Fix Issues'

Reboot into Normal Mode and see if you can run that online scan at Panda now. If not, run the Mwav again, from Safe Mode.
 
1 - 20 of 50 Posts
Status
Not open for further replies.
Top