Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Bloodhound "virus" alert; CD music problems [RESOLVED]


  • This topic is locked This topic is locked

#1
trapsmv15

trapsmv15

    Member

  • Member
  • PipPip
  • 20 posts
Hello, thank you all for contributing to, and providing this great forum.

I ran a CD with MediaMax (wasn't aware until after symptoms) two days ago, and have experienced problems playing any CD on my computer. They all play with distortion. I tried the "fixes" by Sony/BMG and Sunncomm, but they don't help. It's not a huge problem, and if I had to live with it, it'd be fine. But, today, I experienced a weird "loading" box(?) I guess you could call it... I didn't know what to do, so I hit cancel before it loaded all the way. Then a Norton pop-up said I have a Bloodhound "virus" (which I understand is only a vague term for "something's wrong", correct?), but I can't recall what the full name was. Anyway, there is no serious problem with the computer right now, excluding the playing of CD's. I'm just frightened by the fact that the Bloodhound message showed up. Any help is greatly appreciated. Thank you.

Ryan
(below is my log file)



Logfile of HijackThis v1.99.1
Scan saved at 10:53:33 AM, on 9/2/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CallWave\IAM.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\YSIGet\YSIGet.exe
C:\Program Files\YSIGet\WGET.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Documents and Settings\Compaq_Owner\Desktop\YouSendIt Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...arm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.h...arm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...arm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.h...arm1=seconduser
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...arm1=seconduser
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] c:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: CallWave.lnk = C:\Program Files\CallWave\IAM.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{4AFBBF97-4356-4366-ADA6-C7D5980AB2CC}: NameServer = 204.97.128.2
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
  • 0

Advertisements


#2
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 32,943 posts
Updating Java and Clearing Cache
  • Go to Start > Control Panel double-click on the Java Icon (coffee cup) in the Control Panel.
  • It will say "Java Plug-in" under the icon.
    Please find the update button or tab in the Java Control Panel. Update your Java then reboot.
  • If you are unable to update you can manually update by going here:
  • After the reboot, go back into the Control Panel and double-click the Java Icon.
  • Under Temporary Internet Files, click the Delete Files button.
  • There are three options in the window to clear the cache - Leave ALL 3 CheckedDownloaded Applets
    Downloaded Applications
    Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Java Control Panel.
Also, run HJT:
  • Click Open the Misc Tools section.
  • Click Open Uninstall Manager...
  • Click Save list... and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.
Regards,
  • 0

#3
trapsmv15

trapsmv15

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
Below, as requested. Thanks.


Ad-Aware SE Personal
Adobe Reader 7.0
AOL Instant Messenger
AOL Uninstaller (Choose which Products to Remove)
ATI Control Panel
ATI Display Driver
Audacity 1.3.0
AVG Free Edition
Band-in-a-Box 12
Barnyard Invasion from Compaq (remove only)
Bejeweled 2 Deluxe from Compaq (remove only)
Big Kahuna Reef from Compaq (remove only)
Blackhawk Striker 2 from Compaq (remove only)
Blasterball 2 from Compaq (remove only)
Blasterball 2 Holidays from Compaq (remove only)
Boggle Supreme from Compaq (remove only)
Bookworm Deluxe from Compaq (remove only)
Bounce Symphony from Compaq (remove only)
CallWave
CardRd81
CC_ccProxyExt
ccCommon
CCHelp
ccPxyCore
CCScore
Compaq Connections (remove only)
Compaq Game Console and games
Compaq Organize
CR2
Crystal Maze from Compaq (remove only)
Data Fax SoftModem with SmartCP
Digby's Donuts from Compaq (remove only)
DivX
Easy Internet Sign-up
ESSAdpt
ESSANUP
ESSBrwr
ESSCAM
ESSCDBK
ESScore
ESSCT
ESSgui
ESShelp
ESSini
ESSPCD
ESSSONIC
ESSTUTOR
ESSvpaht
ESSvpot
ewido anti-spyware 4.0
FastStone Image Viewer 2.29
FATE Demo from Compaq (remove only)
Flip Words from Compaq (remove only)
Free Mp3 Wma Converter V 1.4.0
High Definition Audio Driver Package - KB888111
HijackThis 1.99.1
HLPCCTR
HLPIndex
HLPRFO
HP Boot Optimizer
HP Image Zone Express
HP Imaging Device Functions 5.3
HP PSC & OfficeJet 5.3.B
HP Software Update
HP Software Update
HP Solution Center & Imaging Support Tools 5.3
Insaniquarium Deluxe from Compaq (remove only)
InterActual Player
InterVideo WinDVD Player
iTunes
J2SE Runtime Environment 5.0
J2SE Runtime Environment 5.0 Update 6
Jewel Quest from Compaq (remove only)
Kodak EasyShare software
LimeWire 4.10.9
LiveReg (Symantec Corporation)
LiveUpdate 2.6 (Symantec Corporation)
Macromedia Flash Player 8
Mah Jong Quest from Compaq (remove only)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft Money 2005
Microsoft Plus! Dancer LE
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Works
MSN Messenger 7.5
MSRedist
Norton AntiSpam
Norton AntiVirus 2005
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security 2005 (Symantec Corporation)
Norton Security Center
Norton WMI Update
Norton WMI Update
Notifier
Office 2003 Tour
OTtBP
OTtBPSDK
PCDLNCH
PC-Doctor 5 for Windows
Polar Bowler from Compaq (remove only)
Polar Golfer from Compaq (remove only)
Puzzle Express from Compaq (remove only)
Python 2.2 pywin32 extensions (build 203)
Python 2.2.3
Quicken 2005
QuickTime
RealPlayer
Ricochet Lost Worlds from Compaq (remove only)
SCRABBLE Blast from Compaq (remove only)
SCRABBLE from Compaq (remove only)
SCRABBLE Rack Attack from Compaq (remove only)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
SFR
SFR2
Shrek 2 Ogre Bowler from Compaq (remove only)
Slingo Deluxe from Compaq (remove only)
Slyder from Compaq (remove only)
Sonic Express Labeler
Sonic MyDVD Plus
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
SPBBC
Super Granny from Compaq (remove only)
Swarm from Compaq (remove only)
SymNet
Tradewinds from Compaq (remove only)
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
VCAMCEN
Viewpoint Manager (Remove Only)
Viewpoint Media Player
VPRINTOL
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB883667
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888239
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
YSIGet
  • 0

#4
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 32,943 posts
Use Add/remove Software to uninstall these two:

Viewpoint Manager (Remove Only)
Viewpoint Media Player

Let me know if that solves your problem.

Regards,
  • 0

#5
trapsmv15

trapsmv15

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
No, distortion remains on all CD's played (MediaMax or not). Computer speed does seem a bit better. I had followed instructions to disable and delete the sbcphid driver that MediaMax is, but I was not about to fiddle on my own with the registry to delete the broken links, or pay a lot for a program to do it for me. I'm hoping that's all the problem is. But my knowledge of computers isn't astounding. :whistling: :blink:

Thanks for your help.
  • 0

#6
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 32,943 posts
1. Launch Notepad, and copy/paste the contents of the quote box below into a new Notepad file. Save it with file name options.txt and save as file type: all files to your desktop.

RegSearch Options File

[Search]
$sys$
ecddiskproducer
sonybmg
crater
aries
qwap


[Exclude]

[Options]
Filter=KVDLUI



2. Download Registry Search to your desktop.
  • Right click on the compressed RegSearch folder, and choose "Extract All". In the box that pops open, click "Next", then "Next" again, and then "Finish". You now have another RegSearch folder on your desktop.
  • Open the new folder, and double click on regsearch.exe
  • Click "Import" in the lower left corner and browse to the options.txt file that you just saved on your desktop. Do not choose the one in the RegSearch folder itself.
  • Click OK and Registry Search will scan your registry for the file(s), and a Notepad box will open with a report.
  • Please reply here with the entire contents of the Notepad file from RegSearch.
Regards,
  • 0

#7
trapsmv15

trapsmv15

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
REGEDIT4

; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.1.0

; Results at 9/9/2006 10:13:52 AM for strings:
; '$sys$'
; 'ecddiskproducer'
; 'sonybmg'
; 'crater'
; 'aries'
; 'qwap'
; Strings excluded from search:
; (None)
; Search in:
; Registry Keys Registry Values Registry Data
; HKEY_LOCAL_MACHINE HKEY_USERS


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{05AE7FB3-C4E9-4F79-A5C3-DAB525E31F2C}\InprocServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\MSSOAP30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{06290BD5-48AA-11D2-8432-006008C3FBFC}]
@="Object for constructing type libraries for scriptlets"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0AF40C53-9257-11D5-87EA-00B0D0BE6479}\InprocServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\MSSOAP30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0AF40C54-9257-11D5-87EA-00B0D0BE6479}\InprocServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\WISC30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0AF40C55-9257-11D5-87EA-00B0D0BE6479}\InprocServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\WHSC30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0AF40C58-9257-11D5-87EA-00B0D0BE6479}\InprocServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\MSSOAP30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1E083978-829F-11D3-AB5D-00C04F9407B9}]
@="MSOLAPAuxiliaries Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1E083978-829F-11D3-AB5D-00C04F9407B9}\ProgID]
@="MSOlapAdmin2.MSOLAPAuxiliaries.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1E083978-829F-11D3-AB5D-00C04F9407B9}\VersionIndependentProgID]
@="MSOlapAdmin2.MSOLAPAuxiliaries"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{273380E8-1438-4B2C-95B0-713284FBC302}\InprocServer32]
@="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\msinfo.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{273380E8-1438-4B2C-95B0-713284FBC302}\ToolboxBitmap32]
@="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\msinfo.dll, 102"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2F943EAE-47B9-4F32-8CB8-A1617778C004}\InprocServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\MSSOAP30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4CE546FF-9128-465E-B5C5-5A36CFC2C285}\InprocServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\mssoap1.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4D602A27-DC39-45D6-A6B1-7003DE2E173C}\InprocServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\MSSOAP30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4ECB650F-4630-41D3-AC9A-C8F926FC5907}\InprocServer32]
@="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\msinfo.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{565FBBE9-8563-4302-BE8A-7C6A64FB0A85}\InprocServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\MSSOAP30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6205B8C9-75FF-4623-A50A-88E1F14EAFF2}\InprocServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\mssoap1.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{722C5A81-4FEC-43F7-8656-E16EC6853073}\InprocServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\MSSOAP30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7A51A663-4790-4885-B0E4-124D4BDADB3E}\InprocServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\MSSOAP30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7F017F96-9257-11D5-87EA-00B0D0BE6479}\InProcServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\MSSOAP30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7F017F97-9257-11D5-87EA-00B0D0BE6479}\InProcServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\MSSOAP30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{86D54F3D-652D-4ab3-A1A6-14D403F6C813}\InProcServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\mssoap1.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8BCD9554-86C7-435d-A8C8-BCB3C72FBEE9}\InProcServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\MSSOAP30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90A299F3-26C6-457D-A514-404335109EDD}\InprocServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\MSSOAP30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9C5754F7-ADF5-4D82-B181-0F8FC5EA882B}\InProcServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\mssoap1.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A0F93E27-F05D-4153-A151-F3720369A4C7}\InprocServer32]
@="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\msinfo.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8D986B6-9257-11D5-87EA-00B0D0BE6479}\InProcServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\MSSOAP30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA535F30-D78F-4985-ACDE-21E523848432}\InprocServer32]
@="c:\\PROGRA~1\\Quicken\\QWAPP.DLL"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA535F30-D78F-4985-ACDE-21E523848432}\ToolboxBitmap32]
@="c:\\PROGRA~1\\Quicken\\QWAPP.DLL, 101"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ADE424F3-AA10-471D-8A0A-687534555900}\InProcServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\mssoap1.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AF9B6377-6505-4934-AD85-BAB87E15EF65}\InprocServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\MSSOAP30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B76585B0-9257-11D5-87EA-00B0D0BE6479}\InProcServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\MSSOAP30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B85E6E71-1493-442F-BC97-B511BE0D5D96}\InprocServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\MSSOAP30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BB023FC5-AA10-47CE-8A0A-6875C17B5914}\InProcServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\mssoap1.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C79C91A1-DB06-11D2-9E0C-00105A26F05D}\InprocServer32]
@="c:\\PROGRA~1\\Quicken\\QWAPP.DLL"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C79C91A1-DB06-11D2-9E0C-00105A26F05D}\ToolboxBitmap32]
@="c:\\PROGRA~1\\Quicken\\QWAPP.DLL, 101"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CE071800-E681-4ADF-9422-A3D0BD0D51CB}\InprocServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\MSSOAP30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFC2FA0B-CC72-4486-B9F4-06FE8A75D58F}\InprocServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\MSSOAP30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E16C0594-128F-11D1-97E4-00C04FB9618A}]
@="ARIES Log Recovery Engine"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EBB2FF12-861A-42b6-B815-B1AF4D944916}\InProcServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\mssoap1.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF90A70C-925B-11D5-87EA-00B0D0BE6479}\InProcServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\MSSOAP30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF90A715-925B-11D5-87EA-00B0D0BE6479}\InProcServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\MSSOAP30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF90A716-925B-11D5-87EA-00B0D0BE6479}\InProcServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\MSSOAP30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F25BC7B7-C60D-4FB9-AAE4-3CA0F6C7038A}\InprocServer32]
@="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\brpinfo.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F7E00C3F-D6C7-4E53-9887-61A2D4EBF0E8}\InprocServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\MSSOAP30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FC7D9E02-3F9E-11d3-93C0-00C04F72DAF7}\InprocServer32]
@="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\HelpCtr.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FC7D9E02-3F9E-11d3-93C0-00C04F72DAF7}\InstalledVersion]
"C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\HelpCtr.exe"="5,1,2600,1106"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FC7D9E06-3F9E-11d3-93C0-00C04F72DAF7}\InprocServer32]
@="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\HelpCtr.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FC7D9E08-3F9E-11d3-93C0-00C04F72DAF7}\InprocServer32]
@="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\HelpCtr.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FC7D9E09-3F9E-11d3-93C0-00C04F72DAF7}\InprocServer32]
@="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\HelpCtr.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FDE424F3-AA10-471D-8A0A-6875C17B5914}\InProcServer32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\mssoap1.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\HCP]
"FriendlyTypeName"="@C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\HCAppRes.dll,-2100"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\HCP\shell\open\command]
@="\"C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\HelpCtr.exe\" -FromHCP -url \"%1\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{349C6ABD-A30C-11D1-ABE5-00C04FC30999}]
@="IMSOLAPAuxiliaries"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSInfo.Document]
"FriendlyTypeName"="@C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\msinfo.dll,-391"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSOlapAdmin2.MSOLAPAuxiliaries]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSOlapAdmin2.MSOLAPAuxiliaries]
@="MSOLAPAuxiliaries Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSOlapAdmin2.MSOLAPAuxiliaries\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSOlapAdmin2.MSOLAPAuxiliaries.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSOlapAdmin2.MSOLAPAuxiliaries.1]
@="MSOLAPAuxiliaries Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSOlapAdmin2.MSOLAPAuxiliaries.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MsRcIncident\DefaultIcon]
; Contents of value:
; %systemroot%\pchealth\helpctr\binaries\helpctr.exe
@=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,50,43,48,65,61,6c,74,68,5c,48,\
65,6c,70,43,74,72,5c,42,69,6e,61,72,69,65,73,5c,48,65,6c,70,43,74,72,2e,65,\
78,65,00

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MsRcIncident\shell\open\command]
; Contents of value:
; %systemroot%\pchealth\helpctr\binaries\helpctr.exe -mode "hcp://system/remote%%20assistance/raclientlayout.xml" -url "hcp://system/remote%%20assistance/interaction/client/rctoolscreen1.htm" -extraargument "incidentfile=%1"
@=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,50,43,48,65,61,6c,74,68,5c,48,\
65,6c,70,43,74,72,5c,42,69,6e,61,72,69,65,73,5c,48,65,6c,70,43,74,72,2e,65,\
78,65,20,2d,4d,6f,64,65,20,22,68,63,70,3a,2f,2f,73,79,73,74,65,6d,2f,52,65,\
6d,6f,74,65,25,25,32,30,41,73,73,69,73,74,61,6e,63,65,2f,52,41,43,6c,69,65,\
6e,74,4c,61,79,6f,75,74,2e,78,6d,6c,22,20,2d,75,72,6c,20,22,68,63,70,3a,2f,\
2f,73,79,73,74,65,6d,2f,52,65,6d,6f,74,65,25,25,32,30,41,73,73,69,73,74,61,\
6e,63,65,2f,49,6e,74,65,72,61,63,74,69,6f,6e,2f,43,6c,69,65,6e,74,2f,72,63,\
74,6f,6f,6c,53,63,72,65,65,6e,31,2e,68,74,6d,22,20,2d,45,78,74,72,61,41,72,\
67,75,6d,65,6e,74,20,22,49,6e,63,69,64,65,6e,74,46,69,6c,65,3d,25,31,22,00

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Scriptlet.TypeLib]
@="Object for constructing type libraries for scriptlets"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{46BF17C1-9257-11D5-87EA-00B0D0BE6479}\3.0\0\win32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\WISC30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{46BF17C2-9257-11D5-87EA-00B0D0BE6479}\3.0\0\win32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\WHSC30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4E2B30D0-E0A2-11D2-9E11-00105A26F05D}\1.0\0\win32]
@="c:\\PROGRA~1\\Quicken\\QWAPP.DLL"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{7AC18319-0739-4377-8984-848573D519A5}\1.0\0\win32]
@="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\msinfo.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{7AC18319-0739-4377-8984-848573D519A5}\1.0\HELPDIR]
@="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{833E4000-AFF7-4AC3-AAC2-9F24C1457BCE}\1.0\0\win32]
@="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\HelpSvc.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{833E4000-AFF7-4AC3-AAC2-9F24C1457BCE}\1.0\HELPDIR]
@="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{91147A58-DFE4-47C0-8E76-987FC1A6001B}\3.0\0\win32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\MSSOAP30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{91147A58-DFE4-47C0-8E76-987FC1A6001B}\3.0\HELPDIR]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C65657D9-5C4B-421E-8DA6-AD4D590FE854}\1.0\0\win32]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\mssoap1.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C65657D9-5C4B-421E-8DA6-AD4D590FE854}\1.0\HELPDIR]
@="C:\\Program Files\\Common Files\\MSSoap\\Binaries"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CA9F6CB1-47F1-4874-90CB-C674E9A86495}\1.0\0\win32]
@="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\brpinfo.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CA9F6CB1-47F1-4874-90CB-C674E9A86495}\1.0\HELPDIR]
@="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FC7D9000-3F9E-11D3-93C0-00C04F72DAF7}\1.0\0\win32]
@="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\HelpCtr.exe\\2"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FC7D9000-3F9E-11D3-93C0-00C04F72DAF7}\1.0\HELPDIR]
@="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\HelpCtr.exe\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FC7D9E00-3F9E-11D3-93C0-00C04F72DAF7}\1.0\0\win32]
@="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\HelpCtr.exe\\1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FC7D9E00-3F9E-11D3-93C0-00C04F72DAF7}\1.0\HELPDIR]
@="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\HelpCtr.exe\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\HELPCTR.EXE]
@="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\HelpCtr.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MSCONFIG.EXE]
@="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0005576A4763A4C46933697E6B7A808C]
"6B9C453C0E4A0BB43A86D66CCB0A3E41"="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\Resources\\1033\\MSSOAPR3.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B67353C23B9C6345AA46FDFADD82F69]
"00000000000000000000000000000000"="01:\\Software\\Microsoft\\Shared Tools\\Proofing Tools\\Custom Dictionaries\\1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\30058796CBE9DA54D990A21DA8BA82C7]
"6B9C453C0E4A0BB43A86D66CCB0A3E41"="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\WHSC30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3F298CDED1EB7C14A905047755CAECC1]
"6B9C453C0E4A0BB43A86D66CCB0A3E41"="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\WISC30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF7D04D7D6686694E95295E98D20F43B]
"DD14EBD2921256C43A3D657432A6063F"="c?\\Program Files\\Quicken\\qwapp.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B605419A1EFE72D438E0AFD5AD47173A]
"6B9C453C0E4A0BB43A86D66CCB0A3E41"="C:\\Program Files\\Common Files\\MSSoap\\Binaries\\MSSOAP30.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"c:\\Program Files\\Quicken\\qwapp.dll"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7]
"Identity"="Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries,processorArchitecture=\"x86\",publicKeyToken=\"6595b64144ccf1df\",type=\"win32\",version=\"6.0.0.0\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7\Codebases]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7\Codebases\OS]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7\Files]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7\Files\0]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7\Files\1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7\Files\2]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7\Files\3]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7\References]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers]
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"="DisableNXShowUI"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Event Viewer]
; Contents of value:
; %systemroot%\pchealth\helpctr\binaries\helpctr.exe
"MicrosoftRedirectionProgram"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,50,\
43,48,65,61,6c,74,68,5c,48,65,6c,70,43,74,72,5c,42,69,6e,61,72,69,65,73,5c,\
48,65,6c,70,43,74,72,2e,65,78,65,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}\{8513A523-F416-4945-A663-7C0485BD6DF0}\Ndi]
"HelpText"="A protocol layered on TCP/IP which preserves message boundaries. This instance of the protocol is for use by the file sharing protocol."

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\HelpSvc]
"EventMessageFile"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\HCAppRes.dll"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\helpsvc\Parameters]
; Contents of value:
; %windir%\pchealth\helpctr\binaries\pchsvc.dll
"ServiceDll"=hex(2):25,57,49,4e,44,49,52,25,5c,50,43,48,65,61,6c,74,68,5c,48,\
65,6c,70,43,74,72,5c,42,69,6e,61,72,69,65,73,5c,70,63,68,73,76,63,2e,64,6c,\
6c,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}\{8513A523-F416-4945-A663-7C0485BD6DF0}\Ndi]
"HelpText"="A protocol layered on TCP/IP which preserves message boundaries. This instance of the protocol is for use by the file sharing protocol."

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\Application\HelpSvc]
"EventMessageFile"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\HCAppRes.dll"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\helpsvc\Parameters]
; Contents of value:
; %windir%\pchealth\helpctr\binaries\pchsvc.dll
"ServiceDll"=hex(2):25,57,49,4e,44,49,52,25,5c,50,43,48,65,61,6c,74,68,5c,48,\
65,6c,70,43,74,72,5c,42,69,6e,61,72,69,65,73,5c,70,63,68,73,76,63,2e,64,6c,\
6c,00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}\{8513A523-F416-4945-A663-7C0485BD6DF0}\Ndi]
"HelpText"="A protocol layered on TCP/IP which preserves message boundaries. This instance of the protocol is for use by the file sharing protocol."

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\HelpSvc]
"EventMessageFile"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\HCAppRes.dll"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\helpsvc\Parameters]
; Contents of value:
; %windir%\pchealth\helpctr\binaries\pchsvc.dll
"ServiceDll"=hex(2):25,57,49,4e,44,49,52,25,5c,50,43,48,65,61,6c,74,68,5c,48,\
65,6c,70,43,74,72,5c,42,69,6e,61,72,69,65,73,5c,70,63,68,73,76,63,2e,64,6c,\
6c,00

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\WINDOWS\\pchealth\\uploadlb\\binaries\\uploadm.exe"="PC Health Upload Manager"

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\WINDOWS\\pchealth\\uploadlb\\binaries\\uploadm.exe"="PC Health Upload Manager"

[HKEY_USERS\S-1-5-21-3317059243-2039455778-3489587019-1009\Software\Microsoft\Search Assistant\ACMru\5603]
"001"="$sys$caj.dll"

[HKEY_USERS\S-1-5-21-3317059243-2039455778-3489587019-1009\Software\Microsoft\Shared Tools\Proofing Tools\Custom Dictionaries]

[HKEY_USERS\S-1-5-21-3317059243-2039455778-3489587019-1009\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\HelpCtr.exe"="Microsoft Help and Support Center"
"@C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\msinfo.dll,-391"="MSInfo Document"

; End Of The Log...
  • 0

#8
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 32,943 posts
Looks like you did a thorough job removing the Sony software.

I would try re-installing the drive's driver next.
If you need any help with that please strat a thread here:
http://www.geekstogo...pherals-f9.html

Describe your problem and post a link to this thread, so they can see what we already tried.
A link to this thread is:
http://www.geekstogo...howtopic=128924

Regards,
  • 0

#9
trapsmv15

trapsmv15

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
OK - I've just done that. Thank you very much for your help.


ETA: This is the key I believe I was told to search for. Should this be deleted???

[HKEY_USERS\S-1-5-21-3317059243-2039455778-3489587019-1009\Software\Microsoft\Search Assistant\ACMru\5603]
"001"="$sys$caj.dll"

By the way, this is the post I worked from - referred to by a friend. ---> http://club.cdfreaks...ad.php?t=154811

Edited by trapsmv15, 09 September 2006 - 08:47 AM.

  • 0

#10
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 32,943 posts
The ACMru keys are usage tracks.

All it means is that you did a FindFiles for that filename.
Nothing to worry about.
  • 0

Advertisements


#11
trapsmv15

trapsmv15

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
OK, great. Thank you so much for your help. We're in the process of re-installing.
  • 0

#12
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 32,943 posts
My pleasure. :whistling:

Take care and good luck,
  • 0

#13
trapsmv15

trapsmv15

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
Well, the re-installation didn't work. Same problems as before, though, the computer seems to be running a little faster (maybe b/c of the Viewpoint Player). Burned CD's, normal CD's with no software... Same problem. :whistling:

ETA: It's still behaving just like the symptoms of MediaMax in that, I can hold Shift down, insert the CD, and burn it through WMP straight to my computer. Those mp3's have no problems at all. To me, it seems it has to be some sort of software problem. *shrugs*

Edited by trapsmv15, 09 September 2006 - 10:17 AM.

  • 0

#14
trapsmv15

trapsmv15

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
Here is what we did to the driver:
http://www.geekstogo...s...pid=781180

And here is a fresh HJT:

Logfile of HijackThis v1.99.1
Scan saved at 12:20:02 PM, on 9/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\CallWave\IAM.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Compaq_Owner\Desktop\YouSendIt Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...arm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.h...arm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...arm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.h...arm1=seconduser
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...arm1=seconduser
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] c:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: CallWave.lnk = C:\Program Files\CallWave\IAM.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{4AFBBF97-4356-4366-ADA6-C7D5980AB2CC}: NameServer = 204.97.128.2
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
  • 0

#15
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 32,943 posts
Which software did you install to remove Mediamax?

We can disable some stuff that isn't really necessary, but a lot will have been on your computer before this started.

Regards,
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP