Tech Support banner

Status
Not open for further replies.
1 - 9 of 9 Posts

·
Registered
Joined
·
5 Posts
please help. my pc has a virus. i cannot open web browsers or even spybot because wininet.dll was not found. i am using a PSP's internet browser so thats why i attached the hijackthis log and renamed it as a .txt file. please help me!


Logfile of HijackThis v1.99.0
Scan saved at 11:52:24 PM, on 9/28/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://C:\WINDOWS\system32\shdocnvt.dll/warningAPI.htm#IDxMS;230905;
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/search?x=...raUY65PnmkA6Mo6kbtxvq8YqjN4qwn5uGwegU91ZQ8Tw=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Add to AD Black List - C:\Program Files\Avant Browser\AddToADBlackList.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Highlight - C:\Program Files\Avant Browser\Highlight.htm
O8 - Extra context menu item: Open All Links in This Page... - C:\Program Files\Avant Browser\OpenAllLinks.htm
O8 - Extra context menu item: Search - C:\Program Files\Avant Browser\Search.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {4989312D-58CF-11D5-A7D7-00E02911103E} (Interealty MultiSelect) - http://sef.mlxchange.com/Control/MultiSelectComboBox.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay102.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1113668481331
O16 - DPF: {6FD482A3-7B57-438B-B040-52CAA30147EE} (MLXchange Client Utils) - http://sef.mlxchange.com/Control/MLXClientUtils.cab
O16 - DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} (GeacRevw Control) - http://sef.mlxchange.com/Control/IRCSharc.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/1,5,0,4351/mcfscan.cab
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.60/code/iPIX-ImageWell-ipix.cab
O23 - Service: AOL Connectivity Service - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Crypkey License - Unknown - crypserv.exe (file missing)
O23 - Service: LexBce Server - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Sony SPTI Service - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: WAN Miniport (ATW) Service - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
 

Attachments

·
Registered
Joined
·
5 Posts
Discussion Starter #2
This is the HJT log.. Thought I should post it not as an attachment.

------------------

Logfile of HijackThis v1.99.0
Scan saved at 11:52:24 PM, on 9/28/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://C:\WINDOWS\system32\shdocnvt.dll/warningAPI.htm#IDxMS;230905;
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/search?x=...raUY65PnmkA6Mo6kbtxvq8YqjN4qwn5uGwegU91ZQ8Tw=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Add to AD Black List - C:\Program Files\Avant Browser\AddToADBlackList.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Highlight - C:\Program Files\Avant Browser\Highlight.htm
O8 - Extra context menu item: Open All Links in This Page... - C:\Program Files\Avant Browser\OpenAllLinks.htm
O8 - Extra context menu item: Search - C:\Program Files\Avant Browser\Search.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {4989312D-58CF-11D5-A7D7-00E02911103E} (Interealty MultiSelect) - http://sef.mlxchange.com/Control/MultiSelectComboBox.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay102.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1113668481331
O16 - DPF: {6FD482A3-7B57-438B-B040-52CAA30147EE} (MLXchange Client Utils) - http://sef.mlxchange.com/Control/MLXClientUtils.cab
O16 - DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} (GeacRevw Control) - http://sef.mlxchange.com/Control/IRCSharc.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/1,5,0,4351/mcfscan.cab
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.60/code/iPIX-ImageWell-ipix.cab
O23 - Service: AOL Connectivity Service - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Crypkey License - Unknown - crypserv.exe (file missing)
O23 - Service: LexBce Server - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Sony SPTI Service - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: WAN Miniport (ATW) Service - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe



----

if anyone could please help, it would be greatly appreciated
 

·
Registered
Joined
·
6,574 Posts
Download Ewido Security Suite - Install & Update it's database but do not run it yet.

= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

REBOOT TO SAFE MODE
  1. Restart the computer. The computer begins processing a set of instructions known as BIOS.
  2. As soon as the BIOS has finished loading, begin tapping the F8 key on your keyboard.
  3. Continue to do so until the 'Windows Advanced Options' menu appears.
  4. Using the arrow keys on the keyboard, scroll to and select the menu item - Safe Mode.

= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

** Please disable all other antivirus programs before proceeding.**

Run Ewido:
  • Click Scanner
  • Click Complete System Scan to begin scanning.
  • Click OK when prompted to clean files
  • With the first file it prompts to clean, select the option - "Perform action on all infections" - & choose clean and click OK
  • Once finished, click the Save report button
  • Save the report to your desktop
Close Ewido
* Ewido scan would require at least an hour. I suggest that you go grab a cup of coffee & do something else while you wait for it to complete.

Reboot to safe mode and provide the results of:
1. a NEW HJT log
2. the Ewido Results.
 

·
Registered
Joined
·
5 Posts
did everthing told to do, but theres still a problem

i still have a problem opening any web browser. the message

"the procedure entry point SHRegGetValueW could not be located in the dynamic link library SHLWAPI.dll"

I did everything mentioned but I still get an error saying

"The procedure entry point SHRegGetValueW
could not be located in the dynamic link library SHLWAPI.dll"

when I try to open a Web Browser, or even Windows Help and Support

---------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 5:33:54 PM, on 9/29/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://C:\WINDOWS\system32\shdocnvt.dll/warningAPI.htm#IDxMS;230905;
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/search?x=...raUY65PnmkA6Mo6kbtxvq8YqjN4qwn5uGwegU91ZQ8Tw=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Add to AD Black List - C:\Program Files\Avant Browser\AddToADBlackList.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Highlight - C:\Program Files\Avant Browser\Highlight.htm
O8 - Extra context menu item: Open All Links in This Page... - C:\Program Files\Avant Browser\OpenAllLinks.htm
O8 - Extra context menu item: Search - C:\Program Files\Avant Browser\Search.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {4989312D-58CF-11D5-A7D7-00E02911103E} (Interealty MultiSelect) - http://sef.mlxchange.com/Control/MultiSelectComboBox.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay102.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1113668481331
O16 - DPF: {6FD482A3-7B57-438B-B040-52CAA30147EE} (MLXchange Client Utils) - http://sef.mlxchange.com/Control/MLXClientUtils.cab
O16 - DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} (GeacRevw Control) - http://sef.mlxchange.com/Control/IRCSharc.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/1,5,0,4351/mcfscan.cab
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.60/code/iPIX-ImageWell-ipix.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 5:21:15 PM, 9/29/2005
+ Report-Checksum: 8E16125C

+ Scan result:

HKLM\SOFTWARE\180solutions -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\2020Search -> Spyware.2020Search : Cleaned with backup
HKLM\SOFTWARE\Classes\AppID\adm.EXE -> Spyware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\AppID\adm.EXE\\AppID -> Spyware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\AppID\Altnet Signing Module.EXE -> Spyware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\AppID\Altnet Signing Module.EXE\\AppID -> Spyware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\AppID\AtlBrowser.EXE -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\AppID\AtlBrowser.EXE\\AppID -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\AppID\{0818D423-6247-11D1-ABEE-00D049C10000} -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{016235BE-59D4-4CEB-ADD5-E2378282A1D9} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{043B5D00-92A9-4cae-A3D8-A4B4B8D52BB1} -> Spyware.Winspoe : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{25630B47-53C6-4E66-A945-9D7B6B2171FF} -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{357A87ED-3E5D-437d-B334-DEB7EB4982A3} -> Trojan.Agent.eo : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{370F6354-41C4-4FA6-A2DF-1BA57EE0FBB9} -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8940E505-72C6-44DE-BE85-1D746780EFBF} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8940E505-72C6-44DE-BE85-1D746780EFBF}\TypeLib\\ -> Spyware.VirtualBouncer : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B5AB638F-D76C-415B-A8F2-F3CEAC502212} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B843DA96-2B2D-447E-90AB-B92929AA11AF} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B843DA96-2B2D-447E-90AB-B92929AA11AF}\TypeLib\\ -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\CSBB.CSBBCore -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CSBB.CSBBCore\CLSID -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CSBB.CSBBCore\CLSID\\ -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CSBB.CSBBCore\CurVer -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CSBB.CSBBCore.1 -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CSBB.CSBBCore.1\CLSID\\ -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\EGHTMLDialer.HTMLDialer -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\EGHTMLDialer.HTMLDialer\CLSID -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\EGHTMLDialer.HTMLDialer\CLSID\\ -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\EGHTMLDialer.HTMLDialer\CurVer -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\EGHTMLDialer.HTMLDialer.1 -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\EGHTMLDialer.HTMLDialer.1\CLSID\\ -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{15BF1D7C-9E2C-489C-ACA0-EDE133A06DF5} -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{15BF1D7C-9E2C-489C-ACA0-EDE133A06DF5}\TypeLib\\ -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{17973BD7-959C-4D8A-8B2F-AB200E20A75E} -> Spyware.Begin2Search : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{17973BD7-959C-4D8A-8B2F-AB200E20A75E}\TypeLib\\ -> Spyware.Begin2Search : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{26C23254-9C6C-48D8-8BF4-E629104E8B36}\TypeLib\\ -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{370F6327-41C4-4FA6-A2DF-1BA57EE0FBB9} -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{370F6327-41C4-4FA6-A2DF-1BA57EE0FBB9}\TypeLib\\ -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{49DB48FF-02B5-4645-B676-94A4DF1AA026} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{49DB48FF-02B5-4645-B676-94A4DF1AA026}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{62BFAEC2-82A5-4117-A98B-FEA89413D924} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{62BFAEC2-82A5-4117-A98B-FEA89413D924}\TypeLib\\ -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{6E0ED53C-9908-49ED-B055-7CB31B162577} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{6E0ED53C-9908-49ED-B055-7CB31B162577}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{6FE4AADF-EDAC-4037-9164-0B60179A4F12} -> Spyware.Begin2Search : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{6FE4AADF-EDAC-4037-9164-0B60179A4F12}\TypeLib\\ -> Spyware.Begin2Search : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{81C2F7F3-F930-455E-9AA5-0876D387C787} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{81C2F7F3-F930-455E-9AA5-0876D387C787}\TypeLib\\ -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{830D3AED-2FA9-454F-B266-D931862BBF34} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{830D3AED-2FA9-454F-B266-D931862BBF34}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8C505A6B-124B-4768-8FD3-1A066C839848} -> Spyware.BlazeFind : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8C505A6B-124B-4768-8FD3-1A066C839848}\TypeLib\\ -> Spyware.BlazeFind : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8C53BD8E-B12D-4C8F-AD0E-C9DDC39D1273} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8C53BD8E-B12D-4C8F-AD0E-C9DDC39D1273}\TypeLib\\ -> Spyware.VirtualBouncer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8EEE58D5-130E-4CBD-9C83-35A0564E1357} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8EEE58D5-130E-4CBD-9C83-35A0564E1357}\TypeLib\\ -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8EEE58D5-130E-4CBD-9C83-35A0564E2468} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8EEE58D5-130E-4CBD-9C83-35A0564E2468}\TypeLib\\ -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{9BCDD51B-4A7B-446C-8452-D32D38004582} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{9BCDD51B-4A7B-446C-8452-D32D38004582}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{A797A41D-F9F0-4A32-B9B5-AF927CB5AE54} -> Spyware.Begin2Search : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{A797A41D-F9F0-4A32-B9B5-AF927CB5AE54}\TypeLib\\ -> Spyware.Begin2Search : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{A986F4DB-792E-4571-8974-0BB6E024766F} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{A986F4DB-792E-4571-8974-0BB6E024766F}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{B12508AD-CA55-4238-8DB3-55808BA6915A} -> Spyware.Begin2Search : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{B12508AD-CA55-4238-8DB3-55808BA6915A}\TypeLib\\ -> Spyware.Begin2Search : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{B548B7D8-3D03-4AED-A6A1-4251FAD00C10} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{B548B7D8-3D03-4AED-A6A1-4251FAD00C10}\ProxyStubClsid32\\ -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{B99A727F-0782-4A71-BCC2-6E1E66414904} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{B99A727F-0782-4A71-BCC2-6E1E66414904}\ProxyStubClsid32\\ -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{BB0D5ADC-028D-4185-9288-722DDCE2C757} -> Spyware.BetterInternet : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{BB0D5ADC-028D-4185-9288-722DDCE2C757}\TypeLib\\ -> Spyware.BetterInternet : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA}\ProxyStubClsid32\\ -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{BCCAB53D-0895-40C3-A942-A03538CE227A} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{BCCAB53D-0895-40C3-A942-A03538CE227A}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{BF7CB2C3-55B6-44C1-9615-920D004C27F7} -> Spyware.Begin2Search : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{BF7CB2C3-55B6-44C1-9615-920D004C27F7}\TypeLib\\ -> Spyware.Begin2Search : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C0F88E9E-DCEB-4655-968A-AE508A677C39} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C0F88E9E-DCEB-4655-968A-AE508A677C39}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C6906A23-4717-4E1F-B6FD-F06EBED11357} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C6906A23-4717-4E1F-B6FD-F06EBED11357}\TypeLib\\ -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C6906A23-4717-4E1F-B6FD-F06EBED12468} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C6906A23-4717-4E1F-B6FD-F06EBED12468}\TypeLib\\ -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{CABBB49A-4D7B-415B-8250-15C3B854E9FF} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{D7EAC2D8-2D52-4010-A4AD-DFDF60C1706C} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{D7EAC2D8-2D52-4010-A4AD-DFDF60C1706C}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{EFA52460-8822-4191-BA38-FACDD2007910} -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{EFA52460-8822-4191-BA38-FACDD2007910}\TypeLib\\ -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{F912C325-5B26-4AD6-BF39-84370833E972} -> Spyware.Begin2Search : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{F912C325-5B26-4AD6-BF39-84370833E972}\TypeLib\\ -> Spyware.Begin2Search : Cleaned with backup
HKLM\SOFTWARE\Classes\MiniBugTransporter.MiniBugTransporterX\CLSID\\ -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\MiniBugTransporter.MiniBugTransporterX.1\CLSID\\ -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\Softomate.IEToolbar -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Softomate.IEToolbar\CLSID -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Softomate.IEToolbar\CurVer -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Softomate.IEToolbar.1 -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\SWRT01.RT -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\SWRT01.RT\Clsid -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\SWRT01.RT\Clsid\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{4EB7BBE8-2E15-424B-9DDB-2CDB9516E2A3} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{5E594162-60A9-487D-84B8-DBDD716CB862} -> Spyware.VirtualBouncer : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{7699AEF9-F83A-44FA-B374-AA02CEDF247D} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{92DAF5C1-2135-4E0C-B7A0-259ABFCD3904} -> Spyware.BetterInternet : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{ABBF650C-E69A-4C95-BA45-0F2C7C2A13A4} -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\CSBB -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\CSBB\contextsidebar -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\CSBB\Loader -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\CSBB\mirrorunder -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\CSBB\resolvers -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\CSBB\ronsidebar -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\CSBB\sidebar -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\CSBB\spidersidebar -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\CSBB\urlsidebar -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\UrlSearchHooks\\{20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} -> Spyware.TVMedia : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ISTbarISTbar -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/bridge.dll\\.Owner -> Spyware.WinFavorites : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/bridge.dll\\{9C691A33-7DDA-4C2F-BE4C-C176083F35CF} -> Spyware.WinFavorites : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.1/QDow.dll\\.Owner -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.1/QDow.dll\\{26E8361F-BCE7-4F75-A347-98C88B418322} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/HDPlugin1101.dll\\.Owner -> Spyware.Gator : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/HDPlugin1101.dll\\{DBAE7000-01EC-4162-8FEB-8A27AC937CA0} -> Spyware.Gator : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/jao.dll\\.Owner -> Spyware.WinFavorites : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/jao.dll\\{9C691A33-7DDA-4C2F-BE4C-C176083F35CF} -> Spyware.WinFavorites : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/nCaseInstaller.dll\\.Owner -> Spyware.NCase : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/nCaseInstaller.dll\\{6EB5B540-1E74-4D91-A7F0-5B758D333702} -> Spyware.NCase : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/PdpPlugin5094.dll\\.Owner -> Spyware.Gator : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/PdpPlugin5094.dll\\{C7B05B62-C8D7-438C-840B-4994DAAA8EEE} -> Spyware.Gator : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/QDow.dll\\.Owner -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/QDow.dll\\{26E8361F-BCE7-4F75-A347-98C88B418322} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/SbCIe028.dll\\.Owner -> Spyware.SideStep : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/SbCIe028.dll\\{640B39C1-D713-464F-92C3-75BD972B95EE} -> Spyware.SideStep : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/SBFull.ocx\\.Owner -> Spyware.SpyBlast : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/SBFull.ocx\\{E6D5237D-A6C7-4C83-A67F-F9F15586FA62} -> Spyware.SpyBlast : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/videox.dll\\.Owner -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/videox.dll\\{1C955F3B-5B32-4393-A05D-24B4970CD2A1} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\msbb -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\ohbbackup -> Spyware.EliteBar : Cleaned with backup
HKLM\SOFTWARE\PerfectNav -> Spyware.KeenValue : Cleaned with backup
HKLM\SOFTWARE\saie -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\SurfSideKick2 -> Spyware.SurfSide : Cleaned with backup
HKLM\SOFTWARE\SurfSideKick2\Internet Explorer -> Spyware.SurfSide : Cleaned with backup
HKLM\SOFTWARE\WildMedia -> Spyware.MidAddle : Cleaned with backup
HKLM\SOFTWARE\WildMedia\LicenseStores -> Spyware.MidAddle : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Spyware.Alexa : Cleaned with backup
HKU\S-1-5-21-2035789119-4179051517-1260927497-1005\Software\aaa_soft -> Spyware.Begin2Search : Cleaned with backup
HKU\S-1-5-21-2035789119-4179051517-1260927497-1005\Software\aaa_soft\kkkk -> Spyware.Begin2Search : Cleaned with backup
HKU\S-1-5-21-2035789119-4179051517-1260927497-1005\Software\aaa_soft\pppp -> Spyware.Begin2Search : Cleaned with backup
HKU\S-1-5-21-2035789119-4179051517-1260927497-1005\Software\aaa_soft\ssss -> Spyware.Begin2Search : Cleaned with backup
HKU\S-1-5-21-2035789119-4179051517-1260927497-1005\Software\Bundles -> Spyware.SecondThought : Cleaned with backup
HKU\S-1-5-21-2035789119-4179051517-1260927497-1005\Software\Ceres -> Spyware.BetterInternet : Cleaned with backup
HKU\S-1-5-21-2035789119-4179051517-1260927497-1005\Software\dsktb -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-2035789119-4179051517-1260927497-1005\Software\dsktb\DesktopToolbar -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-2035789119-4179051517-1260927497-1005\Software\intexp -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-2035789119-4179051517-1260927497-1005\Software\intexp\Config -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-2035789119-4179051517-1260927497-1005\Software\intexp\Config\button0 -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-2035789119-4179051517-1260927497-1005\Software\intexp\Config\button1 -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-2035789119-4179051517-1260927497-1005\Software\intexp\Config\button2 -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-2035789119-4179051517-1260927497-1005\Software\intexp\Config\button3 -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-2035789119-4179051517-1260927497-1005\Software\intexp\Config\KeyWordFreqCap -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-2035789119-4179051517-1260927497-1005\Software\intexp\MyFileSystem2 -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-2035789119-4179051517-1260927497-1005\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Spyware.Alexa : Cleaned with backup
HKU\S-1-5-21-2035789119-4179051517-1260927497-1005\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{10E42047-DEB9-4535-A118-B3F6EC39B807} -> Spyware.SideFind : Cleaned with backup
HKU\S-1-5-21-2035789119-4179051517-1260927497-1005\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{6685509E-B47B-4f47-8E16-9A5F3A62F683} -> Spyware.MoneyMaker : Cleaned with backup
HKU\S-1-5-21-2035789119-4179051517-1260927497-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{825CF5BD-8862-4430-B771-0C15C5CA8DEF} -> Spyware.EliteBar : Cleaned with backup
HKU\S-1-5-21-2035789119-4179051517-1260927497-1005\Software\msbb -> Spyware.180Solutions : Cleaned with backup
HKU\S-1-5-21-2035789119-4179051517-1260927497-1005\Software\saie -> Spyware.180Solutions : Cleaned with backup
HKU\S-1-5-21-2035789119-4179051517-1260927497-1005\Software\SurfSideKick2 -> Spyware.SurfSide : Cleaned with backup
HKU\S-1-5-21-2035789119-4179051517-1260927497-1005\Software\SurfSideKick2\Internet Explorer -> Spyware.SurfSide : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Spyware.Alexa : Error during cleaning
:mozilla.6:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.7:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.9:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Hotlog : Cleaned with backup
:mozilla.115:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Internetfuel : Cleaned with backup
:mozilla.116:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Internetfuel : Cleaned with backup
:mozilla.117:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Internetfuel : Cleaned with backup
:mozilla.118:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Internetfuel : Cleaned with backup
:mozilla.119:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Internetfuel : Cleaned with backup
:mozilla.150:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.161:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.162:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Spylog : Cleaned with backup
:mozilla.175:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.176:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.177:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.178:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.179:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.180:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.188:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.189:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.190:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.191:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.192:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.193:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.194:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.195:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.196:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.197:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.198:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.199:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.200:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.201:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.203:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.214:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.215:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.217:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.228:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
:mozilla.235:C:\Documents and Settings\Franco.FRANCOCOMPUTER\Application Data\Mozilla\Profiles\default\oezbhdq0.slt\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Cookies\[email protected][2].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Desktop\backups\backup-20050102-234350-393.dll -> Spyware.ClearSearch : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Desktop\backups\backup-20050102-234351-341.dll -> Spyware.MyWay : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Desktop\backups\backup-20050102-234351-350.dll -> Spyware.MegaSearch : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Desktop\JeC's foLder\backups\backup-20041006-155133-111.dll -> Spyware.VB : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Desktop\JeC's foLder\backups\backup-20041006-155133-186.dll -> Spyware.BiSpy : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Desktop\JeC's foLder\backups\backup-20041006-155133-251.dll -> Spyware.SearchBand : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Desktop\JeC's foLder\backups\backup-20041006-155133-347.dll -> Spyware.SmartPops : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Desktop\JeC's foLder\backups\backup-20041006-155133-365.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Desktop\JeC's foLder\backups\backup-20041006-155133-475.dll -> Spyware.ClearSearch : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Desktop\JeC's foLder\backups\backup-20041006-155133-673.dll -> Spyware.Beginto : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Desktop\JeC's foLder\backups\backup-20041006-155133-716.dll -> TrojanDownloader.Dyfuca.dc : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Desktop\JeC's foLder\backups\backup-20041006-155133-718.dll -> Spyware.SideFind : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Desktop\JeC's foLder\backups\backup-20041006-155133-954.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Desktop\JeC's foLder\backups\backup-20041006-155133-958.dll -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Desktop\JeC's foLder\backups\backup-20041006-155134-828.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Application Data\Wildtangent\Cdacache\00\00\0D.dat/files\wtvh.dll -> Spyware.WildTangent : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Temp\Cookies\[email protected][2].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Temp\Cookies\[email protected][2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Temp\Cookies\[email protected][2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Temp\Cookies\[email protected][2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Temp\Cookies\[email protected][2].txt -> Spyware.Cookie.Mysearch : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Temp\Cookies\[email protected][2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Temp\msbbhook.dll -> Spyware.180Solutions : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Temp\ncmyb.dll -> Spyware.180Solutions : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Temp\Temporary Internet Files\Content.IE5\QBRZBQA5\install_1000[1].exe -> Trojan.SecondThought.bd : Cleaned with backup
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Temp\thnall1b.exe -> Adware.BetterInternet : Cleaned with backup
C:\found.000\dir0000.chk\auto_update_uninstall.exe -> Spyware.AproposMedia : Cleaned with backup
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Spyware.Wheaterbug : Cleaned with backup
C:\Program Files\CxtPls\ace.dll -> Spyware.AproposMedia : Cleaned with backup
C:\Program Files\CxtPls\CxtPls.dll -> Spyware.AproposMedia : Cleaned with backup
C:\Program Files\CxtPls\uninstaller.exe -> Spyware.Apropos : Cleaned with backup
C:\Program Files\CxtPls\WinGenerics.dll -> Spyware.AproposMedia : Cleaned with backup
C:\RECYCLER\S-1-5-21-2035789119-4179051517-1260927497-1005\Dc118\bar\1.bin\NPMYSRCH.DLL -> Spyware.MyWay : Cleaned with backup
C:\RECYCLER\S-1-5-21-2035789119-4179051517-1260927497-1005\Dc118\bar\1.bin\S42NS.EXE -> Spyware.MyWay : Cleaned with backup
C:\sidebDD.exe -> Spyware.EliteBar : Cleaned with backup
C:\stcupdt.exe -> Trojan.SecondThought.bd : Cleaned with backup
C:\WINDOWS\bsx32 -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ADBN2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ADBN3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ADTMI1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ADVC5.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ADVCTX2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ADVCUK1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIB9894.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIC29667.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASID12180.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIE17070.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIF29819.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIF4502.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIFA15376.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIFWH29233.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIG21943.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIGT10102.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIH21180.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIH7853.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASII21469.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIL18549.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASILS29399.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIM4381.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIM9740.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIOG19375.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIOT25456.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIPF1965.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIR21184.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIRE20082.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIS24110.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIS31590.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIT17011.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIT26116.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIW11211.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIWS3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\AUTOS2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\BID1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\BingoRoom1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\CARD2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\CARS3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\CASH2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\DATE4.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\DEBT1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\DENT1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\EECH1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\EML1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\FAST1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\FINC3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\FINC5.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\FLWR1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\FMND1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\HEAL5.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\HEBE2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\HEBE3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\HERBS1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\HOGAR2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\HOGAR3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\INK1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\INSUR4.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\JOBS4.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\MORT4.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\MORT5.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\MOVS2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\NEWS2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\OPPR3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\SHOP2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\SPEC1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\SPZ3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TECH2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMP3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TRVL5.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TRVL6.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TVEN2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TVMX.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\UTONE2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\VENUE1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\WOMEN2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\WWW3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\XTFL2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\BTGrab.dll -> Spyware.BiSpy : Cleaned with backup
C:\WINDOWS\bundles\ezStubseedcorn.exe -> Adware.eZula : Cleaned with backup
C:\WINDOWS\bxxs5.dll -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\dealhlpr.dll -> Spyware.DealHelper : Cleaned with backup
C:\WINDOWS\dhbrwsr.exe -> Spyware.DealHelper : Cleaned with backup
C:\WINDOWS\DHP.dll -> Spyware.DealHelper : Cleaned with backup
C:\WINDOWS\DHP2.dll -> Spyware.DealHelper : Cleaned with backup
C:\WINDOWS\DHUpdt.exe -> Spyware.DealHelper : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\install007.exe -> Trojan.SecondThought.ao : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\install007.exe -> Trojan.SecondThought.ao : Cleaned with backup
C:\WINDOWS\EliteToolBar\EliteToolBar version 59.dll -> Spyware.EliteBar : Cleaned with backup
C:\WINDOWS\extract.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\WINDOWS\mmgsvc.ocx -> Spyware.Suggestor : Cleaned with backup
C:\WINDOWS\msbbi.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\WINDOWS\preInsln.exe -> Spyware.BiSpy : Cleaned with backup
C:\WINDOWS\save.exe -> Adware.SaveNow : Cleaned with backup
C:\WINDOWS\system32\449166.exe -> Spyware.Beginto.a : Cleaned with backup
C:\WINDOWS\system32\axuninstall.exe -> Spyware.BlazeFind : Cleaned with backup
C:\WINDOWS\system32\BO2802040113.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\BO2804040113.exe -> Spyware.VirtualBouncer : Cleaned with backup
C:\WINDOWS\system32\bs5-nt15v.exe -> Spyware.BookedSpace.b : Cleaned with backup
C:\WINDOWS\system32\Cache\cxtpls_loader.exe -> Spyware.AproposMedia : Cleaned with backup
C:\WINDOWS\system32\cmhkh.dll -> Spyware.Adstart : Cleaned with backup
C:\WINDOWS\system32\cmhkhd.exe -> Spyware.Adstart : Cleaned with backup
C:\WINDOWS\system32\cmhkhf.exe -> Spyware.Adstart : Cleaned with backup
C:\WINDOWS\system32\doolsav.dat -> Spyware.EliteBar : Cleaned with backup
C:\WINDOWS\system32\ezWbr.dll -> Adware.eZula : Cleaned with backup
C:\WINDOWS\system32\in10b6s.dll -> TrojanDropper.Mudrop.m : Cleaned with backup
C:\WINDOWS\system32\julie.exe -> Spyware.VB.c : Cleaned with backup
C:\WINDOWS\system32\k404SearchSetup_MS14.exe -> Spyware.404Search : Cleaned with backup
C:\WINDOWS\system32\msfaol.dll -> Spyware.ClientMan : Cleaned with backup
C:\WINDOWS\system32\msiaih.dll -> Spyware.Ipend : Cleaned with backup
C:\WINDOWS\system32\msnimk.gif -> Spyware.Ipend : Cleaned with backup
C:\WINDOWS\system32\newdevin.exe -> Spyware.BookedSpace.c : Cleaned with backup
C:\WINDOWS\system32\rbdzyc.exe -> Spyware.Adstart : Cleaned with backup
C:\WINDOWS\system32\rbdzyf.exe -> Spyware.Adstart : Cleaned with backup
C:\WINDOWS\system32\reg6523.exe -> Spyware.Beginto : Cleaned with backup
C:\WINDOWS\system32\SHAgentNew.dll -> Adware.SAHA : Cleaned with backup
C:\WINDOWS\system32\silent.exe -> Spyware.WinFetcher.b : Cleaned with backup
C:\WINDOWS\system32\SWRT01.dll -> Spyware.VirtualBouncer : Cleaned with backup
C:\WINDOWS\system32\TFTP2632 -> Worm.Lovesan.a : Cleaned with backup
C:\WINDOWS\system32\thinInstall12.dll -> Adware.eZula : Cleaned with backup
C:\WINDOWS\system32\thinInstOIT61MegaV2s.dll -> Adware.eZula : Cleaned with backup
C:\WINDOWS\system32\trncee.dll/bi.dll -> Spyware.BiSpy : Cleaned with backup
C:\WINDOWS\system32\trncee.dll/biprep.exe -> Trojan.Bispy.B : Cleaned with backup
C:\WINDOWS\system32\trncee.dll/bi.dll -> Spyware.BiSpy : Cleaned with backup
C:\WINDOWS\system32\trncee.dll/biprep.exe -> Trojan.Bispy.B : Cleaned with backup
C:\WINDOWS\system32\W2020Setup.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\W2020Setup.dlltmp -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\winupdtl.exe -> Trojan.SecondThought.bd : Cleaned with backup
C:\WINDOWS\wt\wtvh.dll -> Spyware.WildTangent : Cleaned with backup


::Report End
 

Attachments

·
Registered
Joined
·
6,574 Posts
Ewido clearly shows you're deeply infected.. it's deleted a lot of junk.

Fix these in HJT:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://C:\WINDOWS\system32\shdocnvt.dll/warningAPI.htm#IDxMS;230905;
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/search?x=...raUY65PnmkA6Mo6kbtxvq8YqjN4qwn5uGwegU91ZQ8Tw=
R3 - Default URLSearchHook is missing


Please download Trend Micro™ Anti-Spyware for the Web Utility (by clicking the "Scan and Clean your PC" button).
  • Save it to your desktop.
  • Double-click the new icon on your desktop (tmas-web-scan.exe)
  • It will say "Loading TrendMicro definitions".
  • Once the definitions are loaded, the program will appear to close then re-open.
  • Click "Start Scan"
  • After it's done scanning, click "Scan Results"
  • Make sure all items found have a check next to them, then click "Clean Threats Now".
  • Click Exit.
Reboot your computer. In place of the TrendMicro icon will be a text file called "Antispyware.log", please double-click that log and copy the entire contents and paste them in your next post.

Take a read here for you're problem/error.

I'll try and fix this issue when I return home tonight. Meanwhile run the TMAS to get any remaining junk.

http://www.experts-exchange.com/Operating_Systems/WinXP/Q_21182430.html
 

·
TSF Security Manager, Emeritus
Joined
·
42,837 Posts
Hello odbx,

Going way back to your first post, let's try replacing the wininet.dll http://www.dll-files.com/dllindex/dll-files.shtml?wininet

Did you at any point attempt to download XP SP2 and it failed?

If you still can't use a web browser for scans, please do the following:

Please empty any Quarantine folder in your antivirus program and purge all recovery items in the Spybot program (if you use it) before running this tool.

Download the Mwav virus checker at http://www.mwti.net/products/mwav/mwav.asp (Use Link 3)

1. Save it to a folder.
2. Reboot into Safe Mode.
3. Double click the Mwav.exe file. This is a stand alone tool and NOT just a virus checker......so it won't install anything.
4. Select all local drives, scan all files, and press SCAN. When it is completed, anything found will be displayed in the lower pane.
5. In the Virus Log Information Pane......
Left click and highlight all the information in the Lower pane --- Use CTRL C on your keyboard to copy everything found in the lower pane and save it to a notepad file
*Note* If prompted that a virus was found and you need to purchase the product to remove the malware, just close out the prompt and let it continue scanning. We are not going to use this to remove anything...but to ID the bad files.

Once you copy that to a Notepad file...highlight the text and copy it here along with a new HijackThis log.
 

·
Registered
Joined
·
5 Posts
Discussion Starter #8 (Edited by Moderator)
did everything asked

i dont think i tried to download SP2.

i attached the virus log and a new HJT log

Logfile of HijackThis v1.99.1
Scan saved at 8:08:08 AM, on 10/1/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\notepad.exe
C:\Documents and Settings\Franco.FRANCOCOMPUTER\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Add to AD Black List - C:\Program Files\Avant Browser\AddToADBlackList.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Highlight - C:\Program Files\Avant Browser\Highlight.htm
O8 - Extra context menu item: Open All Links in This Page... - C:\Program Files\Avant Browser\OpenAllLinks.htm
O8 - Extra context menu item: Search - C:\Program Files\Avant Browser\Search.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {4989312D-58CF-11D5-A7D7-00E02911103E} (Interealty MultiSelect) - http://sef.mlxchange.com/Control/MultiSelectComboBox.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay102.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1113668481331
O16 - DPF: {6FD482A3-7B57-438B-B040-52CAA30147EE} (MLXchange Client Utils) - http://sef.mlxchange.com/Control/MLXClientUtils.cab
O16 - DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} (GeacRevw Control) - http://sef.mlxchange.com/Control/IRCSharc.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/1,5,0,4351/mcfscan.cab
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.60/code/iPIX-ImageWell-ipix.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


Object "stoppop Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "search assistant Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "mysearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "ares Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "downloadware Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "spyblast Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "search assistant Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "ares Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "kazaa Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "sahagent Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "trojan.win32.secondthought.l Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "whenu.weathercast Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "search assistant Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "abetterinternet Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "toprebates Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "bookedspace Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "adroar Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "dealhelper Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "egroup Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "searchmiracle.elitebar Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "elitebar Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "conducent flexpak Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "aurora Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "stop-popup-ads-now Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "adrotator Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "dealhelper.com Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "twain-tech Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "ezula Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "180solutions Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "begin2search Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "egroup Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "ezula Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "adrotator Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "begin2search Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "spediabar Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "unknown pest Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "netpal Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "mydailyhoroscope Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "windupdates Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "songspy Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "abetterinternet Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "gator-gain-claria Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "bargainbuddy Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "tooncomics Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "surfsidekick Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "surfsidekick Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "surfsidekick Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "tvmedia Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "easysearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "easysearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "abetterinternet Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "gator-gain-claria Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "bargainbuddy Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "tooncomics Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "surfsidekick Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "gonnasearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "gonnasearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "gonnasearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "kazaa Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "claria Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "claria Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "cydoor Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "cws.therealsearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "cydoor Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "cws.therealsearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "egroup Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "mydailyhoroscope Spyware/Adware" found in File System! Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\ActiveSecurity.ocx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\bridge.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\CONFLICT.1\QDow.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\GeacRevw.ocx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\HDPlugin1101.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\hrtbeat.ocx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\Install.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\iPIX-ImageWell-ipix.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\jao.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\MLXClientUtils.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\MultiSelectComboBox.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\nCaseInstaller.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\PdpPlugin5094.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\QDow.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\RdxIE.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\SbCIe028.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\SBFull.ocx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\videox.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\yinsthelper.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\zsetup.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "c:\Program Files\Common Files\Microsoft Shared\Proof\msgren32.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "c:\Program Files\Common Files\Microsoft Shared\Proof\msgr_en.lex". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\zsetup.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\hrtbeat.ocx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\yinsthelper.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\DOCUME~1\FRANCO~1.FRA\LOCALS~1\Temp\_ISTMP2.DIR\_ISTMP0.DIR\FileGrp\Msvcrt10.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\PdpPlugin5094.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\nCaseInstaller.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\videox.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\QDow.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\RdxIE.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\CONFLICT.1\QDow.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\SBFull.ocx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\ActiveSecurity.ocx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\DIMM.DLL". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Sony Shared\OpenMG\ekb\newekb021224.txt". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\MLXClientUtils.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\MultiSelectComboBox.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\GeacRevw.ocx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\2020search2.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\jao.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\bridge.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\SbCIe028.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\iPIX-ImageWell-ipix.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\DOCUME~1\FRANCO~1.FRA\LOCALS~1\Temp\_ISTMP1.DIR\_ISTMP0.DIR\FileGrp\Msvcrt10.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\AppsInstalled.htm". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\dealhlpr.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\dhbrwsr.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\DHP.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\DHP2.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\DHUpdt.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\AANTX.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\Install.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\HDPlugin1101.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\cmmgr32.exe" refers to invalid object "C:\WINDOWS\System32\cmmgr32.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\idctrrun" refers to invalid object "C:\WINDOWS\System32\idctup20.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\idctrsys" refers to invalid object "C:\WINDOWS\System32\inetdctr.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\ORUN32.EXE" refers to invalid object "C:\WINDOWS\ORUN32.EXE". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\SoundMAX" refers to invalid object "C:\Program Files\Analog Devices\SoundMAX\SoundMAX". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\SoundMAX WDM Driver" refers to invalid object "C:\Program Files\Analog Devices\SoundMAX WDM Driver\SoundMAX WDM Driver". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Favorites\Financial Links\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Program Files\Common Files\Symantec Shared\Script Blocking\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\PrintMe Internet Printing\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Program Files\SONICblue\Rio Internet Update\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Program Files\LimeWire\LimeWire 4.2.6\". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".APP". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".auf". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".aup". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".crd". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".fcn". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".GBA". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".GHO". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".HT_". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".idolonline[1]". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".jsf". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".kpl". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".LST". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".m4a". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".n64". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".odl". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".P". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".part". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".pf". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".php". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".php?startMessage=1&passed_id=30&mailbox=INBOX&ent_id=1". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".qcp". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".r3t". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".rar". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".rev". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".rf". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".rjs". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".rjt". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".rnx". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".rp". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".rt". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".sdp". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".THM". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".uce". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".V64". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".VCD". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".wmru". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".z80". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object "OpenWithList". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "AltnetDM". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Audacity_is1". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "BargainBuddy". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "BellSouth". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "ContextSidebar". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Dbi". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "DownloadWare". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "e2g Plugin". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "eZula". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Internet Optimizer". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Internet Optimizer Software Installer". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "ISTsvc". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "kazaalite202_is1". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB821557". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB823559". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB823980". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "MirrorUnder". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "msbb". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "P2P Networking". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q309521". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q311889". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q311967". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q313450". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q314862". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q315000". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q315403". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q317277". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q318138". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q319580". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q323172". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q324096". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q324380". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q326830". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q328310". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q329048". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q329115". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q329170". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q329390". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q329441". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q331953". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q810577". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q811493". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q815021". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q817606". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Recommended Hotfix - 421701D". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "RonSidebar". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "saie". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "ShopAtHomeSelect Agent". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "SideFind". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "SideStep". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "SpiderSidebar". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Spyware Stormer". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "TV Media". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "untopr1150". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "UrlSidebar". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Viewpoint Manager". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Virtual Bouncer". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "wcmdmgr.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "WSEM Update". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "wtdmmp". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "wtwebdriver". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{00120409-78E1-11D2-B60F-006097C998E7}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{ABEB838C-A1A7-4C5D-B7E1-8B4314600133}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{F4C9398F-B6C6-4A4B-8B6D-795CD86F915D}". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{01011300-5e80-11d8-9e86-0007e96c65ae}" refers to invalid object "C:\Program Files\Support.com\bin\sprtnetcheck.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{01118c00-3e00-11d2-8470-0060089874ed}" refers to invalid object "D:\install.exe". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{16D44660-099F-11D3-B6AC-00105A69E391}" refers to invalid object "C:\PROGRA~1\Canon\ZOOMBR~1\Program\ZOOMBR~2.EXE". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{1EFD6A40-3999-11CF-9150-00AA0059F70D}" refers to invalid object "D:\PROGRAM\32\mci32.ocx". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{3524DDE3-0779-11D3-BD90-00105A5FD92B}" refers to invalid object "C:\PROGRA~1\Canon\ZOOMBR~1\Program\ZOOMBR~1.EXE". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{3775D2E0-7C5D-11CF-899E-00AA00688B10}" refers to invalid object "D:\PROGRAM\32\mci32.ocx". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{3D48B387-E74A-4651-A2ED-7FC490964319}" refers to invalid object "C:\Program Files\America Online 9.0\MyCalendar.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{3DCC93C5-4C0D-B872-32BB-9B957DE34DDE}" refers to invalid object "C:\WINDOWS\Xhwwfeer.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{40D41A8B-D79B-43d7-99A7-9EE0F344C385}" refers to invalid object "C:\Program Files\AIM Toolbar\AIMBar.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{43918f8f-f3be-4760-b4bb-6c89d9d91487}" refers to invalid object "C:\Program Files\Winamp\Plugins\cddbcontrolwinamp.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{44b09a5f-5dee-4539-8001-d4b2d45c2876}" refers to invalid object "C:\Program Files\Winamp\Plugins\cddbcontrolwinamp.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{4634A8A8-E78E-4fed-9751-52307590D7F1}" refers to invalid object "C:\Program Files\America Online 9.0\MyCalendar.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{46986115-84D6-459c-8F95-52DD653E532E}" refers to invalid object ""C:\Program Files\Winamp\Winamp.exe"". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{4989312D-58CF-11D5-A7D7-00E02911103E}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\MultiSelectComboBox.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{4C171D40-8277-11D5-AD55-00010333D0AD}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{4E7BD74F-2B8D-469E-A1F6-FC7EB590A97E}" refers to invalid object "C:\WINDOWS\DOWNLO~1\search3.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{4E7BD74F-2B8D-469E-A1F6-FC7EB590A97F}" refers to invalid object "C:\WINDOWS\DOWNLO~1\search3.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{51B21D54-F57F-4ca1-93FF-D986E9F0A388}" refers to invalid object "C:\Program Files\America Online 9.0\MyCalendar.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{56336BCA-3D8A-11d6-A00B-0050DA18DE71}" refers to invalid object "C:\DOCUME~1\FRANCO~1.FRA\LOCALS~1\Temp\InfoWindow.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{5696744A-F3BD-11D4-8A1D-001083023C0D}" refers to invalid object "C:\PROGRA~1\AMERIC~1.0\IE_NDS.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{584B6591-8E5F-11CE-8F97-00AA0036005A}" refers to invalid object "C:\WINDOWS\System32\Dwshk32.ocx". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{597CAA70-72AA-11CF-831E-524153480000}" refers to invalid object "C:\PROGRA~1\MACROM~1\FLASHM~1\Flash.exe". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{60A07B6D-B66C-4339-BD52-EC9520FDCE6A}" refers to invalid object "C:\Program Files\America Online 9.0\MyCalendar.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{629CACAE-B028-11D2-BA9E-00A024BF101B}" refers to invalid object "C:\PROGRA~1\Canon\PHOTOR~1\OPPRIN~1\OPPRIN~1.EXE". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{63603526-954A-42eb-8BEB-8E4BF2F636CB}" refers to invalid object "C:\Program Files\America Online 9.0\MyCalendar.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{63CCB35F-4B6C-11D2-BA18-00A024BF101B}" refers to invalid object "C:\Program Files\Canon\PhotoRecord\OpPrintCom\OpPrintCom.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{6833E5F0-F6D8-11D4-8A1F-001083023C0D}" refers to invalid object "C:\PROGRA~1\AMERIC~1.0\IE_NDS.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{6FD482A3-7B57-438B-B040-52CAA30147EE}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\MLXClientUtils.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{741506D7-C215-48A1-8211-4CEFF2E8FE2C}" refers to invalid object "C:\Program Files\America Online 9.0\MyCalendar.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{77A366BA-2BE4-4a1e-9263-7734AA3E99A2}" refers to invalid object ""C:\Program Files\Winamp\Winamp.exe"". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{7F23E6E5-0E79-4aee-B723-B1463805D5A9}" refers to invalid object "C:\WINDOWS\wt\webdriver\4.1.1\sound.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E}" refers to invalid object "C:\WINDOWS\DOWNLO~1\GeacRevw.ocx". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{83AB6E4E-CDD7-11D3-B5E7-00104B9AFF6E}" refers to invalid object "C:\WINDOWS\DOWNLO~1\GeacRevw.ocx". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{83B28A74-640D-48F4-9F51-E80EED7CC7E0}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\SbCIe028.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{8CEEEF03-A28B-4B4C-8693-B38ECFA9D91A}" refers to invalid object "C:\Program Files\Canon\ZoomBrowser EX\Program\ZOOMBROWSER.EXE /StiDevice:%1 /StiEvent:%2". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{8DD06381-FB75-11CE-906E-00AA0036005A}" refers to invalid object "C:\WINDOWS\System32\DWEASY32.OCX". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{8DD06383-FB75-11CE-906E-00AA0036005A}" refers to invalid object "C:\WINDOWS\System32\DWEASY32.OCX". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{8ECF83A0-1AC9-11D4-8501-00A0CC5D1F63}" refers to invalid object "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{94E03510-31B9-47a0-A44E-E932AC86BB17}" refers to invalid object ""C:\Program Files\Windows Media Player\wmlaunch.exe"". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{96632d1e-f3eb-4f54-ba79-9969692db659}" refers to invalid object "C:\Program Files\Winamp\Plugins\cddbuiwinamp.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{99720901-B635-43bd-83E6-D084A990F15A}" refers to invalid object "C:\Program Files\America Online 9.0\MyCalendar.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{9DC1221E-0B36-445a-A2D1-FCA92E502834}" refers to invalid object "C:\Program Files\America Online 9.0\MyCalendar.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{A1B09066-C95C-4EF6-8DFD-3DD0AFE610B6}" refers to invalid object "C:\PROGRA~1\COMMON~1\AOL\SCREEN~1\YGPSCR~1.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{B20B4521-CCF8-11D6-B8A5-000064657374}" refers to invalid object "C:\Program Files\Netscape\Netscape\Netscp.exe -PalmSyncStartup". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{B4087707-EFB7-46C0-830E-714899CCE724}" refers to invalid object "C:\Program Files\America Online 9.0\MyCalendar.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{B9BA256A-075B-49ea-B9E2-7DBC2EF021D5}" refers to invalid object "C:\WINDOWS\wt\webdriver\4.1.1\sound.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{BAF457A6-A404-D904-8DF8-51A7B57FBB71}" refers to invalid object "C:\WINDOWS\Xhwwfeer.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{bc8a96c0-3909-11d5-9001-00c04f4c3b9f}" refers to invalid object "C:\PROGRA~1\AMERIC~1.0\Media\CDDBControl.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{bc8a96c1-3909-11d5-9001-00c04f4c3b9f}" refers to invalid object "C:\PROGRA~1\AMERIC~1.0\Media\CDDBControl.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{bc8a96c2-3909-11d5-9001-00c04f4c3b9f}" refers to invalid object "C:\PROGRA~1\AMERIC~1.0\Media\CDDBControl.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{bc8a96c3-3909-11d5-9001-00c04f4c3b9f}" refers to invalid object "C:\PROGRA~1\AMERIC~1.0\Media\CDDBControl.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{BD0A8DE1-CC9A-11CE-8FDA-00AA0036005A}" refers to invalid object "C:\WINDOWS\System32\Dwshk32.ocx". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{C0E7AB80-AE60-101C-B41C-6E74AC177608}" refers to invalid object "C:\WINDOWS\System32\DWEASY32.OCX". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{C0E7AB84-AE60-101C-B41C-6E74AC177608}" refers to invalid object "C:\WINDOWS\System32\DWEASY32.OCX". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{C1A8AF25-1257-101B-8FB0-0020AF039CA3}" refers to invalid object "D:\PROGRAM\32\mci32.ocx". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{C31746DC-4BF9-4DC8-A299-B0F09AFACFB4}" refers to invalid object "C:\PROGRA~1\AMERIC~1.0\AMH.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{C3C6A060-C344-11D0-A20B-0800361A1803}" refers to invalid object "C:\Program Files\HTML Help Workshop\cnvtoc.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{C4105451-D5F7-11CE-8FF4-00AA0036005A}" refers to invalid object "C:\WINDOWS\System32\Dwshk32.ocx". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{C4105453-D5F7-11CE-8FF4-00AA0036005A}" refers to invalid object "C:\WINDOWS\System32\Dwshk32.ocx". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{C55A1680-CD5A-11CF-8D29-444553540000}" refers to invalid object "C:\Program Files\Support.com\BellSouth\utilities\regobj.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{C627B4C0-01AF-41BB-A4CF-EC0DEF91ADAF}" refers to invalid object "C:\PROGRA~1\AMERIC~1.0\AMH.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{C8B29238-05AD-421E-8B44-1C11C43FAE1C}" refers to invalid object "C:\Program Files\America Online 9.0\MyCalendar.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{C8CE6FC1-CCF1-11D6-B8A5-000064657374}" refers to invalid object "C:\Program Files\Netscape\Netscape\PalmSyncProxy.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{CD34B69E-6117-4eaf-B5B4-F9FD659BF00D}" refers to invalid object "C:\Program Files\America Online 9.0\MyCalendar.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{d4387178-98ca-4929-b8e3-a11cd2f333a6}" refers to invalid object "C:\Program Files\Winamp\Plugins\cddbcontrolwinamp.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{E3A43ED1-D47A-11CE-8FF0-00AA0036005A}" refers to invalid object "C:\WINDOWS\System32\Dwshk32.ocx". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96}" refers to invalid object "C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{EB6BEA6B-F489-4846-902B-4CA285EA2311}" refers to invalid object "C:\PROGRA~1\AMERIC~1.0\AMH.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{ECFBE6E0-1AC8-11D4-8501-00A0CC5D1F63}" refers to invalid object "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{ef8d9f2a-f641-4ef0-b2ec-3ba2be7c2960}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\iPIX-ImageWell-ipix.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F091791F-D50D-4ace-9D82-05C42DBB9897}" refers to invalid object "C:\Program Files\America Online 9.0\MyCalendar.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{f7a05bac-9778-410a-9cde-bfbd4d5d2b7f}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\iPIX-ImageWell-ipix.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FA13A9FA-CA9B-11D2-9780-00104B242EA3}" refers to invalid object "C:\WINDOWS\wt\webdriver\4.1.1\webdriver.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{fba38bcf-e23d-4979-811e-1326bbadb8c8}" refers to invalid object "C:\Program Files\Winamp\Plugins\cddbcontrolwinamp.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{00CEDBF1-864D-11D3-908D-00C0F03B3EDC}" refers to invalid object "C:\Program Files\Real\RealPlayer\ierjplug.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{01011301-5E80-11D8-9E86-0007E96C65AE}" refers to invalid object "C:\Program Files\Support.com\bin\sprtnetcheck.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{01118C01-3E00-11D2-8470-0060089874ED}" refers to invalid object "D:\install.exe". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{12D56325-94E3-4E74-A91B-586982151C2F}" refers to invalid object "C:\Program Files\Common Files\aolshare\Coach\Player\coachdm2.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{17016CEB-E118-11D0-94B8-00A0C91110ED}" refers to invalid object "C:\Program Files\Common Files\designer\WBCLSDSR.OCX". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{1D37DE23-9C6C-101C-B41C-6E74AC177608}" refers to invalid object "C:\WINDOWS\System32\Dwshk32.ocx". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{1F22CD1C-E3DB-11D3-BC4E-0010833594F0}" refers to invalid object "C:\PROGRA~1\AMERIC~1.0\ebrowser.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{205FF72E-CA67-11D5-99DD-444553540000}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\Install.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{324C8F3B-14E7-41E1-A2A3-10CE6F86A6B3}" refers to invalid object "C:\WINDOWS\System32\MSCOMCTL.oca". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{3274DEAA-A88B-4F8B-ABF8-659F93AF66EA}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\MultiSelectComboBox.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{33E3924C-674A-11D6-97B5-0010DC2A6243}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\ActiveSecurity.ocx". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{390CE9E4-C4A0-11D4-8A92-0090271D4F88}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\ycrwin32.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{3A051814-4E16-49D3-ACCF-76484CF6BC80}" refers to invalid object "C:\WINDOWS\System32\AANTX.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{3C2D2A1E-031F-4397-9614-87C932A848E0}" refers to invalid object "C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{405DE7B2-E7DD-11D2-92C5-00C0F01F77C1}" refers to invalid object "C:\Program Files\Real\RealPlayer\rpau3260.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{47F59201-8783-11D2-8343-00A0C945A819}" refers to invalid object "C:\Program Files\Internet Explorer\PLUGINS\RichFX\Player\nprfxins.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{4E038CD0-0D82-4AA7-A09D-4E5F48B12A9E}" refers to invalid object "C:\PROGRA~1\AMERIC~1.0\AMH.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{4F7D1B07-6203-41F0-947B-A29CC9ECD9B0}" refers to invalid object "C:\Program Files\Viewpoint\Viewpoint Media Player\AxMetaStream.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{58E0CBEA-38D1-4A35-805B-1D4922C19EBB}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\MLXClientUtils.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{7AF322C5-AB43-11D4-A00B-0050DA18DE71}" refers to invalid object "C:\DOCUME~1\FRANCO~1.FRA\LOCALS~1\Temp\InfoWindow.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{8008F09D-5B18-41F3-BC53-1A3049D4F100}" refers to invalid object "C:\PROGRA~1\AMERIC~1.0\waol.exe". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{83AB6E4A-CDD7-11D3-B5E7-00104B9AFF6E}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\GeacRevw.ocx". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{8E926E2D-BF6C-11D2-A33D-00A0C94B8D0E}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\stock.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{9FFB4822-0EE5-11D1-A787-0000F80272EA}" refers to invalid object "C:\WINDOWS\System32\HTMUTIL.DLL". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{A67004E0-8362-42F9-B186-88706C346DD9}" refers to invalid object "C:\Program Files\Real\RealPlayer\rpplugins\ierpplug.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{ABD7EB19-2273-4644-87AA-81803EA66D38}" refers to invalid object "C:\DOCUME~1\FRANCO~1.FRA\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{BA3C9072-E7D6-11D0-8C2E-00A024729DDE}" refers to invalid object "C:\Program Files\Xara\Xara X\templman.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{BB9EF4CE-09E6-44C5-A6E9-AD9A471B4025}" refers to invalid object "C:\Program Files\America Online 9.0\MyCalendar.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{C0E7AB83-AE60-101C-B41C-6E74AC177608}" refers to invalid object "C:\WINDOWS\System32\DWEASY32.OCX". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{C1A8AF28-1257-101B-8FB0-0020AF039CA3}" refers to invalid object "D:\PROGRAM\32\mci32.ocx". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{CC09D895-51EF-11D2-BA2A-00A024BF101B}" refers to invalid object "C:\Program Files\Canon\PhotoRecord\OpPrintCom\OpPrintCom.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{D04A7099-0C25-4FC7-970F-6EC7D77886F3}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\iPIX-ImageWell-ipix.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{DD3FCE4D-8442-4EFA-A71E-1C131F502F4A}" refers to invalid object "C:\PROGRA~1\COMMON~1\AOL\SCREEN~1\YGPSCR~1.DLL". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{DE10C540-810E-11CF-BBE7-444553540000}" refers to invalid object "C:\Program Files\Support.com\BellSouth\utilities\regobj.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{E5D12C41-7B4F-11D3-B5C9-0050045C3C96}" refers to invalid object "C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{F0012D80-989C-11D3-B7C5-0090271D5CA7}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\MyYahoo.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{FA13AA2E-CA9B-11D2-9780-00104B242EA3}" refers to invalid object "C:\WINDOWS\wt\webdriver\4.1.1\webdriver.dll". Action Taken: No Action Taken.
Entry "HKCR\.sll" refers to invalid object "SSLFile". Action Taken: No Action Taken.
Entry "HKCR\.stl" refers to invalid object "FireworksStyleLibrary". Action Taken: No Action Taken.
Entry "HKCR\Ares.CollectionList\shell\open\command" refers to invalid object ""C:\Program Files\Ares Lite Edition\AresLite.exe" "%1"". Action Taken: No Action Taken.
Entry "HKCR\arlnk\shell\open\command" refers to invalid object ""C:\Program Files\Ares Lite Edition\AresLite.exe" "%L"". Action Taken: No Action Taken.
Entry "HKCR\dvf_auto_file\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\realplay.exe" "%1"". Action Taken: No Action Taken.
Entry "HKCR\RealPlayer.3GPP2.10\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken.
Entry "HKCR\RealPlayer.3GPP_AMR.10\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken.
Entry "HKCR\SdcUser.UnkItem" refers to invalid object "{01115500-3e00-11d2-8470-0060089874ed}". Action Taken: No Action Taken.
Entry "HKCR\SdcUser.UnkItem.1" refers to invalid object "{01115500-3e00-11d2-8470-0060089874ed}". Action Taken: No Action Taken.
File C:\WINDOWS\cpruninst.exe infected by "Trojan-Downloader.Win32.Adroar" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\desktop.html infected by "not-virus:Hoax.Win32.Aflac.a" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\dhsvr.exe tagged as "not-a-virus:AdWare.DealHelper.g". Action Taken: No Action Taken.
File C:\WINDOWS\id120.exe infected by "Trojan.Win32.SecondThought.ae" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\lycos.exe tagged as "not-a-virus:AdWare.Sidesearch.b". Action Taken: No Action Taken.
File C:\WINDOWS\rgrt.exe tagged as "not-a-virus:AdWare.ShopNav.g". Action Taken: No Action Taken.
File C:\WINDOWS\wast2.exe tagged as "not-a-virus:AdWare.Win32.AdWast.a". Action Taken: No Action Taken.
File C:\WINDOWS\woinstall.exe tagged as "not-a-virus:AdWare.Win32.EZula.ak". Action Taken: No Action Taken.
File C:\WINDOWS\System32\commcoss.dll tagged as "not-a-virus:AdWare.SafeSurfing.c". Action Taken: No Action Taken.
File C:\WINDOWS\System32\ezStub3.dll tagged as "not-a-virus:AdWare.EZula.a". Action Taken: No Action Taken.
File C:\WINDOWS\System32\host.exe infected by "Trojan.Win32.Qhost.x" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\System32\KVIF_7.dll infected by "Trojan-Downloader.Win32.Keenval" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\System32\MegasearchBarSetup.dll tagged as "not-a-virus:AdWare.F1Organizer.n". Action Taken: No Action Taken.
File C:\WINDOWS\System32\msdipo.dll tagged as "not-a-virus:AdWare.ClientMan". Action Taken: No Action Taken.
File C:\WINDOWS\System32\msfdje.gif tagged as "not-a-virus:AdWare.ClientMan". Action Taken: No Action Taken.
File C:\WINDOWS\System32\msglji.gif tagged as "not-a-virus:AdWare.Win32.SearchAssistant.d". Action Taken: No Action Taken.
File C:\WINDOWS\System32\mshpeb.dll tagged as "not-a-virus:AdWare.WebSearch.c". Action Taken: No Action Taken.
File C:\WINDOWS\System32\O infected by "Trojan-Downloader.BAT.Ftp.af" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\System32\oleext.dll infected by "Virus.Win32.Nsag.b" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\System32\rbdzy.dll tagged as "not-a-virus:AdWare.Win32.Adstart.i". Action Taken: No Action Taken.
File C:\WINDOWS\System32\rbdzyd.exe tagged as "not-a-virus:AdWare.Win32.Adstart.i". Action Taken: No Action Taken.
File C:\WINDOWS\System32\setup_incred_7.exe infected by "Trojan-Downloader.Win32.Keenval" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\System32\setup_incred_8.exe infected by "Trojan-Downloader.Win32.Keenval" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\System32\setup_silent_25207.exe tagged as "not-a-virus:AdWare.MDH.a". Action Taken: No Action Taken.
File C:\WINDOWS\System32\setup_silent_26222.exe tagged as "not-a-virus:AdWare.MDH.a". Action Taken: No Action Taken.
File C:\WINDOWS\System32\winb2s33.dll tagged as "not-a-virus:AdWare.ToolBar.Ilookup.b". Action Taken: No Action Taken.
File C:\WINDOWS\System32\winspoe.dll tagged as "not-a-virus:AdWare.Win32.SrchResults.a". Action Taken: No Action Taken.
File C:\WINDOWS\System32\Xcite2.exe tagged as "not-a-virus:AdWare.ToolBar.MyWay.i". Action Taken: No Action Taken.
File C:\DOCUME~1\FRANCO~1.FRA\LOCALS~1\Temp\banner.exe tagged as "not-a-virus:AdWare.BetterInternet". Action Taken: No Action Taken.
File C:\DOCUME~1\FRANCO~1.FRA\LOCALS~1\Temp\cpr_adsav.exe infected by "Trojan-Downloader.Win32.Adroar" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\FRANCO~1.FRA\LOCALS~1\Temp\ICD1.tmp\siinstaller.exe tagged as "not-a-virus:AdWare.Win32.Comet.c". Action Taken: No Action Taken.
File C:\DOCUME~1\FRANCO~1.FRA\LOCALS~1\Temp\SskUpdater.exe tagged as "not-a-virus:AdWare.SurfSide.c". Action Taken: No Action Taken.
File C:\DOCUME~1\FRANCO~1.FRA\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\GJMJEJIJ\installer_ICMEDIAX[1].cab infected by "Trojan-Downloader.Win32.Adload.e" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\FRANCO~1.FRA\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ML25K9KR\TRACK[1].CHM infected by "Trojan-Downloader.JS.Psyme.n" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\FRANCO~1.FRA\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\QBRZBQA5\track[1].htm infected by "Exploit.HTML.Mht" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\FRANCO~1.FRA\LOCALS~1\Temp\UF38.tmp tagged as "not-a-virus:AdWare.Win32.TotalVelocity.aa". Action Taken: No Action Taken.
File C:\DOCUME~1\FRANCO~1.FRA\LOCALS~1\TEMPOR~1\Content.IE5\QLXYJEDS\html[1].chm infected by "Trojan-Downloader.Win32.Delf.ks" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\FRANCO~1.FRA\LOCALS~1\TEMPOR~1\Content.IE5\WD6RWLUB\html[1].chm infected by "Trojan-Downloader.Win32.Delf.ks" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer.zip infected by "Password-protected-EXE" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Megasearch.zip infected by "Password-protected-EXE" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader.zip infected by "Password-protected-EXE" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader3.zip infected by "Password-protected-EXE" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader5.zip infected by "Password-protected-EXE" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Franco.FRANCOCOMPUTER\.jpi_cache\jar\1.0\classload.jar-595832fe-5d4badca.zip infected by "Trojan.Java.ClassLoader.v" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Temp\banner.exe tagged as "not-a-virus:AdWare.BetterInternet". Action Taken: No Action Taken.
File C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Temp\cpr_adsav.exe infected by "Trojan-Downloader.Win32.Adroar" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Temp\ICD1.tmp\siinstaller.exe tagged as "not-a-virus:AdWare.Win32.Comet.c". Action Taken: No Action Taken.
File C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Temp\SskUpdater.exe tagged as "not-a-virus:AdWare.SurfSide.c". Action Taken: No Action Taken.
File C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Temp\Temporary Internet Files\Content.IE5\GJMJEJIJ\installer_ICMEDIAX[1].cab infected by "Trojan-Downloader.Win32.Adload.e" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Temp\Temporary Internet Files\Content.IE5\ML25K9KR\TRACK[1].CHM infected by "Trojan-Downloader.JS.Psyme.n" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Temp\Temporary Internet Files\Content.IE5\QBRZBQA5\track[1].htm infected by "Exploit.HTML.Mht" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Temp\UF38.tmp tagged as "not-a-virus:AdWare.Win32.TotalVelocity.aa". Action Taken: No Action Taken.
File C:\Documents and Settings\Franco.FRANCOCOMPUER\Local Settings\Temporary Internet Files\Content.IE5\QLXYJEDS\html[1].chm infected by "Trojan-Downloader.Win32.Delf.ks" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Franco.FRANCOCOMPUTER\Local Settings\Temporary Internet Files\Content.IE5\WD6RWLUB\html[1].chm infected by "Trojan-Downloader.Win32.Delf.ks" Virus! Action Taken: No Action Taken.
File C:\Program Files\CxtPls\CxtPls.exe infected by "Trojan-Downloader.Win32.Apropo.x" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\cpruninst.exe infected by "Trojan-Downloader.Win32.Adroar" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\desktop.html infected by "not-virus:Hoax.Win32.Aflac.a" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\dhsvr.exe tagged as "not-a-virus:AdWare.DealHelper.g". Action Taken: No Action Taken.
File C:\WINDOWS\id120.exe infected by "Trojan.Win32.SecondThought.ae" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\lycos.exe tagged as "not-a-virus:AdWare.Sidesearch.b". Action Taken: No Action Taken.
File C:\WINDOWS\rgrt.exe tagged as "not-a-virus:AdWare.ShopNav.g". Action Taken: No Action Taken.
File C:\WINDOWS\system32\commcoss.dll tagged as "not-a-virus:AdWare.SafeSurfing.c". Action Taken: No Action Taken.
File C:\WINDOWS\system32\ezStub3.dll tagged as "not-a-virus:AdWare.EZula.a". Action Taken: No Action Taken.
File C:\WINDOWS\system32\host.exe infected by "Trojan.Win32.Qhost.x" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\KVIF_7.dll infected by "Trojan-Downloader.Win32.Keenval" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\MegasearchBarSetup.dll tagged as "not-a-virus:AdWare.F1Organizer.n". Action Taken: No Action Taken.
File C:\WINDOWS\system32\msdipo.dll tagged as "not-a-virus:AdWare.ClientMan". Action Taken: No Action Taken.
File C:\WINDOWS\system32\msfdje.gif tagged as "not-a-virus:AdWare.ClientMan". Action Taken: No Action Taken.
File C:\WINDOWS\system32\msglji.gif tagged as "not-a-virus:AdWare.Win32.SearchAssistant.d". Action Taken: No Action Taken.
File C:\WINDOWS\system32\mshpeb.dll tagged as "not-a-virus:AdWare.WebSearch.c". Action Taken: No Action Taken.
File C:\WINDOWS\system32\O infected by "Trojan-Downloader.BAT.Ftp.af" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\oleext.dll infected by "Virus.Win32.Nsag.b" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\rbdzy.dll tagged as "not-a-virus:AdWare.Win32.Adstart.i". Action Taken: No Action Taken.
File C:\WINDOWS\system32\rbdzyd.exe tagged as "not-a-virus:AdWare.Win32.Adstart.i". Action Taken: No Action Taken.
File C:\WINDOWS\system32\setup_incred_7.exe infected by "Trojan-Downloader.Win32.Keenval" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\setup_incred_8.exe infected by "Trojan-Downloader.Win32.Keenval" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\setup_silent_25207.exe tagged as "not-a-virus:AdWare.MDH.a". Action Taken: No Action Taken.
File C:\WINDOWS\system32\setup_silent_26222.exe tagged as "not-a-virus:AdWare.MDH.a". Action Taken: No Action Taken.
File C:\WINDOWS\system32\winb2s33.dll tagged as "not-a-virus:AdWare.ToolBar.Ilookup.b". Action Taken: No Action Taken.
File C:\WINDOWS\system32\winspoe.dll tagged as "not-a-virus:AdWare.Win32.SrchResults.a". Action Taken: No Action Taken.
File C:\WINDOWS\system32\Xcite2.exe tagged as "not-a-virus:AdWare.ToolBar.MyWay.i". Action Taken: No Action Taken.
File C:\WINDOWS\wast2.exe tagged as "not-a-virus:AdWare.Win32.AdWast.a". Action Taken: No Action Taken.
File C:\WINDOWS\woinstall.exe tagged as "not-a-virus:AdWare.Win32.EZula.ak". Action Taken: No Action Taken.
 

Attachments

·
TSF Security Manager, Emeritus
Joined
·
42,837 Posts
Hi,

You've got a bit of work ahead of you, so please take your time. :smile:

Please print out or copy this page to Notepad since you will not have any of browsers open while you are fixing this. Make sure to work through the fixes in the exact order it is mentioned below.

The Temp folders should be cleaned out periodically as installation programs and hijack programs leave a lot of junk there. Download CleanUp! (Alternate Link if main link doesn't work) and install it. Do not run it yet.

Download smitRem at http://noahdfear.geekstogo.com/click counter/click.php?id=1 and save the file to your desktop. Do not run it yet.

Download KillBox http://www.greyknight17.com/spy/KillBox.exe. Do not run it yet.

If you have not already installed Ad-Aware SE 1.06, follow the download and setup instructions at http://rstones12.geekstogo.com/adawareSE_setup.htm. Otherwise, check for updates. Don't run it yet.

Check for updates once again for Ewido.

Reboot into Safe Mode.(tapping F8 or F5)

Copy the file names below to the clipboard by highlighting them and pressing Ctrl-C:

C:\WINDOWS\System32\commcoss.dll
C:\WINDOWS\cpruninst.exe
C:\WINDOWS\dhsvr.exe
C:\WINDOWS\id120.exe
C:\WINDOWS\lycos.exe
C:\WINDOWS\rgrt.exe
C:\WINDOWS\wast2.exe
C:\WINDOWS\woinstall.exe
C:\WINDOWS\System32\ezStub3.dll
C:\WINDOWS\System32\host.exe
C:\WINDOWS\System32\KVIF_7.dll
C:\WINDOWS\System32\MegasearchBarSetup.dll
C:\WINDOWS\System32\msdipo.dll
C:\WINDOWS\System32\msfdje.gif
C:\WINDOWS\System32\msglji.gif
C:\WINDOWS\System32\mshpeb.dll
C:\WINDOWS\System32\oleext.dll
C:\WINDOWS\System32\rbdzy.dll
C:\WINDOWS\System32\rbdzyd.exe
C:\WINDOWS\System32\setup_incred_7.exe
C:\WINDOWS\System32\setup_incred_8.exe
C:\WINDOWS\System32\setup_silent_25207.exe
C:\WINDOWS\System32\setup_silent_26222.exe
C:\WINDOWS\System32\winb2s33.dll
C:\WINDOWS\System32\winspoe.dll
C:\WINDOWS\System32\Xcite2.exe
C:\Program Files\CxtPls\CxtPls.exe


Start KillBox.
Go to the File menu, and choose Paste from Clipboard.
Verify that you've done this properly by clicking the dropdown-arrow next to the Full Path of File to Delete field. The filenames you pasted will be found in there.
Select/tick the following:
* Delete on Reboot
* End Explorer Shell While Killing File
* Unregister.dll Before Deleting" if it's not grayed out.
Click the RED X button.

Click [Yes] at the 'Delete on Reboot' prompt. Click [No] at the Pending Operations prompt.

Run the smitRem.exe tool you downloaded earlier. Follow the prompts on the screen. Wait for the tool to complete and disk cleanup to finish.

The tool will create a log named smitfiles.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.

Open Ad-aware and do a full scan. Remove all it finds.

Run Ewido:

* Click on scanner.
* Click on Complete System Scan and the scan will begin.
* NOTE: During some scans with ewido it is finding cases of false positives.
* You will need to step through the process of cleaning files one-by-one.
* If Ewido detects a file you KNOW to be legitimate, select none as the action.
* Do NOT select 'Perform action on all infections'.
* If you are unsure of any entry found, select none for now.
* When the scan is finished, click the Save report button at the bottom of the screen.
* Save the report to your desktop.

Close Ewido.

Next go to Control Panel->Display->Desktop->Customize Desktop->Web-> Uncheck 'Security Info' if present.

Uninstall the following via the Add/Remove Panel (Start->(Settings)->Control Panel->Add/Remove Programs) if they exist:

CxtPls

Delete the following Folders:

C:\WINDOWS\System32\O
C:\Program Files\CxtPls

Follow the instructions here to clean out your Java cache...
http://www.java.com/en/download/help/cache_virus.xml

CleanUp! deletes EVERYTHING out of your temp/temporary folders, it does not make backups. If you have any documents or programs that are saved in any Temporary Folders, please make a backup of these before running CleanUp!.

Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows:
*Click "Options..."
*Move the arrow down to "Custom CleanUp!"
*Put a check next to the following:
-Empty Recycle Bins
-Temporary Internet Files
-Delete Cookies
-Delete Prefetch files
-[X]Scan local drives for temporary files (Please uncheck this option)
-Cleanup! All Users
Click OK
Press the CleanUp! button to start the program. Reboot/logoff when prompted.

Reboot back into Normal Mode. See if you can run that online scan at Panda now:

Perform an online scan using Internet Explorer with Panda ActiveScan - requires Internet Explorer

  1. Click on the Scan your PC button & a 'pop up' window shall appear. * ensure that your pop up blocker doesn't block it
  2. Click On 'Scan Now'
  3. Enter your e-mail address & click 'Scan Now' ...begins downloading Panda's ActiveX controls.- 8MB
  4. Begin the scan by selecting My Computer
    * You needn't remain online while it's doing the scan but you have to re-connect after it has finished to see the report.
  5. If it finds any malware, it will offer you a report. Click on see report
  6. Then click Save report
  7. Post the contents of the report in your next reply along with a new HijackThis log.
* Turn off the real time scanner of any existing antivirus program while performing the online scan
 
1 - 9 of 9 Posts
Status
Not open for further replies.
Top