Edited by bananafanafo, 22 May 2005 - 10:59 PM.
TROJAN.VUNDO.B (C:\windows\repair\catip.dll)
#46
Posted 22 May 2005 - 10:56 PM
#47
Posted 22 May 2005 - 11:08 PM
Edited by bananafanafo, 22 May 2005 - 11:08 PM.
#48
Posted 23 May 2005 - 01:16 AM
Open Notepad. Please copy EVERYTHING in the code box below and paste it into a new Notepad file. Change the "Save As Type" to "All Files" and save it as vundo.reg on your desktop. Make sure there is NO blank line above REGEDIT4:
REGEDIT4 [-HKEY_CLASSES_ROOT\CLSID\{44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSEvents.MSEvents] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSEvents.MSEvents.1]
Don't run it yet, though.
Edited by bananafanafo, 23 May 2005 - 01:18 AM.
#49
Posted 23 May 2005 - 04:15 AM
#50
Posted 23 May 2005 - 10:09 AM
#51
Posted 23 May 2005 - 04:55 PM
#52
Posted 23 May 2005 - 06:02 PM
Ok, here we go:
Disconnect from the Internet.
Disable Norton Auto-Protect.
Disable Ewido.
Disable AOL Anti-Spyware.
Install APM if you haven't yet.
Start APM.
Locate C:\Windows\System32\winlogon.exe in the upper panel and click on it once to highlight it.
In the lower panel, locate all instances of C:\WINDOWS\repair\catip.dll
Right-click on each one and select "unload DLL".
After that's done, locate C:\Windows\explorer.exe in the top panel and do the same thing.
You may have to experiment a little with this on which DLLs to unload from which process first (ie unload DLLs under explorer before winlogon).
We have to make sure ALL the DLLs are unloaded from both of these processes even one DLL running will cause this not to work!
So do this:
*Open HiJackThis
*Click on "Open the Misc Tools Section"
*Click on "Open Process Manager"
*In the top right-hand corner it will say "Show DLLs" - please put a checkmark in this box.
*Another panel will open on the bottom.
*In the TOP panel, I need you to click on C:\Windows\System\Winlogon.exe to highlight it.
*When it's highlighted all the DLLs will load in the BOTTOM panel.
*In this BOTTOM panel I need you to make sure ALL instances of C:\WINDOWS\repair\catip.dll are GONE!
*Do the same thing for C:\Windows\explorer.exe
In HiJackThis, if this DLL: catip.dll is still loading anywhere under winlogon or explorer, then I need you to go back to APM and unload the DLLs that are still running.
After ALL dlls have been unloaded from both of these processes follow the instructions below.
Run HijackThis and place a check beside the following items and click FIX CHECKED:
O2 - BHO: MSEvents Object - {44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44} - C:\WINDOWS\repair\catip.dll
O20 - Winlogon Notify: catip - C:\WINDOWS\repair\catip.dll
Close HijackThis.
**This is the NEW vundo.reg! Make sure you use this one and not the old one otherwise this fix will not work!
Open Notepad. Please copy EVERYTHING in the code box below and paste it into a new Notepad file. Change the "Save As Type" to "All Files" and save it as vundo.reg on your desktop. Make sure there is NO blank line above REGEDIT4:
REGEDIT4 [-HKEY_CLASSES_ROOT\CLSID\{44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSEvents.MSEvents] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSEvents.MSEvents.1]
Double-click vundo.reg and allow to merge with the registry. After "merged successfully" prompt, follow the below instructions.
Double click on Killbox.exe and then click the "REPLACE on Reboot", then put a checkmark next to "Use Dummy"
Enter the following filepath and filename into the Full path of file to delete box (in the upper box, please leave the 2nd box exactly as it is!):
C:\WINDOWS\repair\catip.dll
Click the red circle with the white x and allow your computer to reboot.
After your computer has rebooted please run Hijackthis again and post a new HijackThis log.
#53
Posted 23 May 2005 - 08:55 PM
Harold
#54
Posted 23 May 2005 - 08:58 PM
I'll post as soon as I find out something!
#55
Posted 23 May 2005 - 11:15 PM
Ok, we need to try and see if there is a file guarding the dll. Please do this for me (it will take a WHILE to do):
I need you to download MWav to a convenient location.
This scan might take around 3+ hours to finish when set to scan everything.
I need you to run MWav by double-clicking on mwav.exe.
Put a check next to the below items before scanning:
- Memory
- Startup Folders
- Drive - All Local Drives
- Folder - then click "browse" to change the directory to C: (default is C:\Windows)
- Registry
- System Folders
- Services
- Include Sub-Directory
- Scan All Files
**NOTE*** Sometimes MWav will pause and it appears to be finished, but it isn't done. Just let it run until it says it's complete.
On the bottom portion of the window, you will see the lower panel where MWav is listing "infected items", please highlight everything in that lower panel and copy them by holding CTRL + C then paste it here. The whole log will be extremely BIG so there is no way to post the log. I just need the infected items list.
Edited by bananafanafo, 24 May 2005 - 01:37 AM.
#56
Posted 24 May 2005 - 07:30 PM
#57
Posted 25 May 2005 - 06:34 PM
#58
Posted 25 May 2005 - 10:40 PM
Object "HuntBar Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "AltNet Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "cws.therealsearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
File C:\Program Files\ewido\security suite\Quarantine\quaraFile56.ess infected by "Trojan.Win32.Qhost.r" Virus! Action Taken: No Action Taken.
File C:\Program Files\ewido\security suite\Quarantine\quaraFile57.ess infected by "Trojan.Win32.Qhost.r" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\27D941B2.exe infected by "Trojan-Downloader.Win32.Dyfuca.dx" Virus! Action Taken: No Action Taken.
File C:\Program Files\WhistleSoftware\WselServices\setupSilent610.exe tagged as "not-a-virus:AdWare.Whistle.a". Action Taken: No Action Taken.
File C:\Documents and Settings\Harold\Application Data\setup keep third\SECT TEAM.exe infected by "Trojan-Downloader.Win32.Swizzor.bo" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Joyce\Application Data\Wave Up Wait\TICKAIMBIBBOLD.exe infected by "Trojan-Downloader.Win32.Swizzor.cm" Virus! Action Taken: No Action Taken.
File C:\Program Files\America Online 9.0\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File C:\Program Files\ewido\security suite\Quarantine\quaraFile56.ess infected by "Trojan.Win32.Qhost.r" Virus! Action Taken: No Action Taken.
File C:\Program Files\ewido\security suite\Quarantine\quaraFile57.ess infected by "Trojan.Win32.Qhost.r" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\27D941B2.exe infected by "Trojan-Downloader.Win32.Dyfuca.dx" Virus! Action Taken: No Action Taken.
File C:\Program Files\WhistleSoftware\WselServices\setupSilent610.exe tagged as "not-a-virus:AdWare.Whistle.a". Action Taken: No Action Taken.
File C:\Documents and Settings\Harold\Application Data\setup keep third\SECT TEAM.exe infected by "Trojan-Downloader.Win32.Swizzor.bo" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Joyce\Application Data\Wave Up Wait\TICKAIMBIBBOLD.exe infected by "Trojan-Downloader.Win32.Swizzor.cm" Virus! Action Taken: No Action Taken.
File C:\Program Files\America Online 9.0\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
Is some of that files that are in quarantine (I would think that they should be deleted by the program that found them?
Can I delete stuff like this?
Entry "HKCR\CLSID\{F3CA5737-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
I think there is about 100 entries that refer to invalid objects.
Wed May 25 23:51:24 2005 => Total Objects Scanned: 194296
Wed May 25 23:51:24 2005 => Total Virus(es) Found: 17
Wed May 25 23:51:24 2005 => Total Disinfected Files: 0
Wed May 25 23:51:24 2005 => Total Files Renamed: 0
Wed May 25 23:51:24 2005 => Total Deleted Objects: 0
Wed May 25 23:51:24 2005 => Total Errors: 402
Wed May 25 23:51:24 2005 => Time Elapsed: 03:57:10
Wed May 25 23:51:24 2005 => Virus Database Date: 2005/05/23
Wed May 25 23:51:24 2005 => Virus Database Count: 131417
Wed May 25 23:51:24 2005 => Scan Completed.
Thats about it for now. I'm going to start Norton's and go to bed. Thanks again.
#59
Posted 26 May 2005 - 12:35 AM
Open Norton and go into the quarantine folder (I believe it's under "View reports") and delete items quarantined. Delete the items quarantined by Ewido as well.
You said there are about 100 of these? Do they all have a different "invalid file"?? Is the number different on each one? If it is I need to see the list so we can get rid of them.HKCR\CLSID\{F3CA5737-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Delete these folders:
C:\Documents and Settings\Harold\Application Data\setup keep third
C:\Documents and Settings\Joyce\Application Data\Wave Up Wait
C:\Program Files\WhistleSoftware
#60
Posted 26 May 2005 - 05:24 PM
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\dll2phase.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\HDPlugin1018.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\rfx2pdef.txt". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\tgctlcm.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\msxml3a.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\KPCMS\CMSCP\cp01". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\rfx2pdef.txt". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\dll2phase.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\HDPlugin1018.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\tgctlcm.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{01111F00-3E00-11D2-8470-0060089874ED}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\CONFLICT.1\tgctlins.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{01117F00-3E00-11D2-8470-0060089874ED}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\CONFLICT.1\tgctlins.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0514B040-84EA-11D0-A8BF-00A0C9008A48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" refers to invalid object "C:\WINDOWS\System32\msjava.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7}" refers to invalid object "C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0f3aede0-3f66-11d2-b1a1-00c04fcb5466}" refers to invalid object "C:\WINDOWS\System32\FB62Uusd.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{248DD896-BB45-11CF-9ABC-0080C7E7B78D}" refers to invalid object "C:\WINDOWS\system32\MSWINSCK.OCX". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{248DD897-BB45-11CF-9ABC-0080C7E7B78D}" refers to invalid object "C:\WINDOWS\system32\MSWINSCK.OCX". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{5B7524C8-2446-40E9-9474-94A779DBA224}" refers to invalid object "c:\WINDOWS\Downloaded Program Files\isusweb.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{7F23E6E5-0E79-4aee-B723-B1463805D5A9}" refers to invalid object "C:\WINDOWS\wt\webdriver\4.1.1\sound.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{83D4679F-B6D7-11D2-BF36-00C04FB90A03}" refers to invalid object "C:\PROGRA~1\MESSEN~1\rtcimsp.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{885BB46A-3F1E-44C3-A01B-A7D9260CC98B}" refers to invalid object "c:\WINDOWS\Downloaded Program Files\dwusplay.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{88E729D6-BDC1-11D1-BD2A-00C04FB9603F}" refers to invalid object "fde.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{8E13DDE1-E013-47ec-9C4C-27C2F78BDD26}" refers to invalid object "C:\WINDOWS\system32\req.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{8ECF83A0-1AC9-11D4-8501-00A0CC5D1F63}" refers to invalid object "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{93DF49AE-0E92-4ebf-80E9-ED36498072AB}" refers to invalid object "C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{94BF6C82-F075-11D4-AB95-000102B2D025}" refers to invalid object "D:\MDMDptch.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{99180163-DA16-101A-935C-444553540000}" refers to invalid object "recncl.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{B9BA256A-075B-49ea-B9E2-7DBC2EF021D5}" refers to invalid object "C:\WINDOWS\wt\webdriver\4.1.1\sound.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{BFFFD262-7705-11D0-B5DC-444553540000}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{C55A1680-CD5A-11CF-8D29-444553540000}" refers to invalid object "C:\DOCUME~1\Harold\LOCALS~1\Temp\twc\installer\bin\regobj.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{E7BC34A3-BA86-11CF-84B1-CBC2DA68BF6C}" refers to invalid object "C:\WINDOWS\system32\ntsvc.ocx". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{ECFBE6E0-1AC8-11D4-8501-00A0CC5D1F63}" refers to invalid object "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA5665-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA566B-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA5671-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA5677-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA567D-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA5683-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA5689-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA568F-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA5695-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA569B-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA56A1-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA56A7-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA56AD-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA56B3-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA56B9-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA56BF-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA56C5-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA56CB-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA56D1-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA56D7-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA56DD-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA56E3-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA56E9-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA56EF-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA56F5-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA56FB-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA5701-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA5707-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA570D-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA5713-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA571F-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA572B-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA5731-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA5737-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA573D-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA5749-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA574F-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA5755-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA575B-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA5767-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA5791-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA57DF-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA57E5-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F3CA57EB-C5DA-11CF-8F28-00AA0060FD48}" refers to invalid object "C:\WINDOWS\System32\dx3j.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FA13A9FA-CA9B-11D2-9780-00104B242EA3}" refers to invalid object "C:\WINDOWS\wt\webdriver\4.1.1\webdriver.dll". Action Taken: No Action Taken.
Entry "HKCR\ActMsg.Session" refers to invalid object "{3FA7DEB3-6438-101B-ACC1-00AA00423326}". Action Taken: No Action Taken.
Entry "HKCR\Alg.AlgSetup" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken.
Entry "HKCR\Alg.AlgSetup.1" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken.
Entry "HKCR\ComPlusMetaData.MsCorHost" refers to invalid object "{727CDF4F-3BA0-11D3-8738-00C04F79ED0D}". Action Taken: No Action Taken.
Entry "HKCR\ComPlusMetaData.MsCorHost.2" refers to invalid object "{727CDF4F-3BA0-11D3-8738-00C04F79ED0D}". Action Taken: No Action Taken.
Entry "HKCR\JavaPlugin.142" refers to invalid object "{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}". Action Taken: No Action Taken.
Entry "HKCR\MailFileAtt" refers to invalid object "{00020D05-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\mapifvbx.object" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.
Entry "HKCR\mapifvbx.object.1" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.
Entry "HKCR\Nisbho.CNisExtBho" refers to invalid object "{9ECB9560-04F9-4bbc-943D-298DDF1699E1}". Action Taken: No Action Taken.
Entry "HKCR\Nisbho.CNisExtBho.1" refers to invalid object "{9ECB9560-04F9-4bbc-943D-298DDF1699E1}". Action Taken: No Action Taken.
Entry "HKCR\OPUCatalog.OPUCatalog11.1" refers to invalid object "{3E68E405-C6DE-49ff-83AE-41EE9F4C36CE}". Action Taken: No Action Taken.
Entry "HKCR\Plenoptic.Plenoptic" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken.
Entry "HKCR\Plenoptic.Plenoptic.1" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken.
Entry "HKCR\QDiagAOLCCUpdateObj.QDiagAOLCCUpdateObj.1" refers to invalid object "{4A3CF76B-EC7A-405d-A67D-8DC6B52AB35B}". Action Taken: No Action Taken.
Entry "HKCR\RFXPlayer.RFXPlayer.5" refers to invalid object "{47f591a2-8783-11d2-8343-00a0c945a819}". Action Taken: No Action Taken.
Entry "HKCR\RTCCore.RTCClient" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken.
Entry "HKCR\RTCCore.RTCClient.1" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken.
Entry "HKCR\SdcUser.TgConfCtl" refers to invalid object "{01113300-3e00-11d2-8470-0060089874ed}". Action Taken: No Action Taken.
Entry "HKCR\SdcUser.TgConfCtl.1" refers to invalid object "{01113300-3e00-11d2-8470-0060089874ed}". Action Taken: No Action Taken.
Entry "HKCR\SymWriter.pdb" refers to invalid object "{520DC67A-752E-11D3-8D56-00C04F680B2B}". Action Taken: No Action Taken.
Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.
Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr.1" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.
I guess they need to be deleted. Hopefully it is an easy process. Thanks
Harold
Similar Topics
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users