Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Hijackthis log [RESOLVED]


  • This topic is locked This topic is locked

#46
Excal

Excal

    Malware Slayer Extraordinaire!

  • Retired Staff
  • 12,739 posts
Ok, might take a few posts.

but sounds good.


Thanks,

:tazz:

Excal
  • 0

Advertisements


#47
Sk0rch

Sk0rch

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 335 posts
Fri Aug 12 18:38:24 2005 => Entry "HKCR\CLSID\{92BA82F7-ED28-4212-9D86-8072E2F6F07F}" refers to invalid object "C:\WINDOWS\System32\ieaeb.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:25 2005 => Entry "HKCR\CLSID\{92FD235A-DD0B-4624-AE11-509D1E7B4A86}" refers to invalid object "C:\WINDOWS\System32\defpca.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:25 2005 => Entry "HKCR\CLSID\{93C083C7-DCDF-4EB0-8AE4-5091D0F67F08}" refers to invalid object "C:\WINDOWS\System32\dmd.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:25 2005 => Entry "HKCR\CLSID\{97075DE7-4CA5-4D1A-A162-E1179CEF19CC}" refers to invalid object "C:\WINDOWS\System32\dmje.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:25 2005 => Entry "HKCR\CLSID\{9869EFB4-18E9-11D3-A837-00104B9E30B5}" refers to invalid object "C:\DOCUME~1\Owner\LOCALS~1\Temp\CMDLIN~1.DLL". Action Taken: No Action Taken.

Fri Aug 12 18:38:25 2005 => Entry "HKCR\CLSID\{98975DA4-05E4-45CC-B906-2279D05FEBC5}" refers to invalid object "C:\WINDOWS\System32\defpca.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:25 2005 => Entry "HKCR\CLSID\{99D5C558-CF34-4A82-8F6A-C84D741F56A2}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:25 2005 => Entry "HKCR\CLSID\{9A2840C9-F42D-01BA-D858-94884A950CC9}" refers to invalid object "C:\Program Files\MSN\MSNCoreFiles\msnmetal.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:25 2005 => Entry "HKCR\CLSID\{9B605939-DD42-47E9-959D-403C87865795}" refers to invalid object "C:\Program Files\Tech\MagicBall\1.2\SCRBALUI.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:25 2005 => Entry "HKCR\CLSID\{9BEC70AD-A836-4C2E-8B17-86E24034C6FC}" refers to invalid object "C:\WINDOWS\System32\ieaeb.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:25 2005 => Entry "HKCR\CLSID\{9D3E4364-19FD-6182-4D69-F9AFEDEE744B}" refers to invalid object "C:\Program Files\MSN\MSNCoreFiles\msnmetal.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:25 2005 => Entry "HKCR\CLSID\{9D3F09BD-AFAC-4B2C-88F2-C0FB40EE5649}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:25 2005 => Entry "HKCR\CLSID\{9D92A143-E936-4279-8B60-AA12E800DC91}" refers to invalid object "C:\WINDOWS\System32\icfeeb.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:25 2005 => Entry "HKCR\CLSID\{9E3D6AF0-4CFC-4968-867E-0560E9ECF440}" refers to invalid object "C:\Program Files\Sonic\MyDVD\Offset.ax". Action Taken: No Action Taken.

Fri Aug 12 18:38:25 2005 => Entry "HKCR\CLSID\{9EB579F9-AD42-4D15-BA2B-FC3EDB61CCA1}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:25 2005 => Entry "HKCR\CLSID\{9FC9FAD9-CC48-4E7E-BFB2-748C96F54B26}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:25 2005 => Entry "HKCR\CLSID\{A060134A-C98B-42C4-AFCC-75505A190F85}" refers to invalid object "C:\WINDOWS\System32\defpca.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:25 2005 => Entry "HKCR\CLSID\{A103BF4E-5493-44F7-9683-01BE00122E86}" refers to invalid object "C:\WINDOWS\System32\ieaeb.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:25 2005 => Entry "HKCR\CLSID\{A17E30C4-A9BA-11D4-8673-60DB54C10000}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\ymmapi.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:25 2005 => Entry "HKCR\CLSID\{A21B7E84-A200-4383-AD08-00E05DC5DE8A}" refers to invalid object "C:\WINDOWS\System32\ieaeb.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{A28541E5-DB74-4336-AA0C-C7CECDB68784}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{A435E773-FA9A-46F5-84FA-EA68C57E76AD}" refers to invalid object "C:\WINDOWS\System32\acjch.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{A4E21F1A-6B91-4B9B-B708-4AE3B0E748C8}" refers to invalid object "C:\WINDOWS\system32\fbajb.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{A559F1DB-FA57-4245-947B-CC453C5C6971}" refers to invalid object "C:\WINDOWS\System32\ieaeb.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{A62FA99E-922E-4ECA-A1D9-B54EF294A3CC}" refers to invalid object "C:\Program Files\WildTangent\Apps\CDA\CDALogger0401.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{A689A631-11D0-4B0C-B339-63DF5DF0E005}" refers to invalid object "C:\Program Files\Sonic\MyDVD\GoMotionDVtoMPEG.ax". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{A6CD6E57-72E3-46D3-A9EF-C341C59E9033}" refers to invalid object "C:\Program Files\Sonic\MyDVD\lmpgad.ax". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{A7F78220-7648-4826-837B-6001E2AD7824}" refers to invalid object "C:\PROGRA~1\Ahead\NEROWA~1\AUDIOC~1.OCX". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{A8DC3A14-CBFC-4BE8-995D-2FDB6C7AA9F2}" refers to invalid object "C:\PROGRA~1\Ahead\NEROWA~1\AUDIOC~1.OCX". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{A99A3354-63FB-474D-9953-5C6871AAE8BC}" refers to invalid object "C:\WINDOWS\system32\cbec.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{AA218328-0EA8-4D70-8972-E987A9190FF4}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\ymmapi.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{AB9FA086-83C4-4F56-B614-77CA8C349270}" refers to invalid object "C:\Program Files\Stardock\Object Desktop\DesktopX\SDPlugins\DXAxHost.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{ABC0D24C-A963-48D6-A002-A988EF69E298}" refers to invalid object "C:\WINDOWS\system32\odpic.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{ACEDA7F8-7748-414B-89C8-385E004E5D0B}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{ADE04BE1-90CF-4133-972D-76F718E43390}" refers to invalid object "C:\Program Files\Nexon\Shattered Galaxy\thidchk.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{AEF7E2FF-ECA5-43E8-8FD2-5BE8745EFA8E}" refers to invalid object "C:\WINDOWS\System32\ieaeb.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{AF7B940E-9110-46EB-83F0-66C6C265FB36}" refers to invalid object "C:\WINDOWS\System32\defpca.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{AFBF185C-EE24-4BD3-ABA9-EBD1C9E51FEA}" refers to invalid object "C:\WINDOWS\System32\ibd.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{B0693766-5278-4ec6-B9E1-3CE40560EF5A}" refers to invalid object "CaPlgin.ax". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{B0CB5CC5-20E9-4E10-85AE-29DF83851EED}" refers to invalid object "C:\Program Files\Sonic\MyDVD\SonicRainbowFix.ax". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{B29FE516-50AF-4392-AD5A-D5A03EC18F1E}" refers to invalid object "C:\WINDOWS\System32\ieaeb.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{B318A498-B360-4C6C-88EE-F9AC389527CA}" refers to invalid object "C:\WINDOWS\System32\dmd.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{B36031AF-F191-4331-81A3-15EF66D3092D}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{B40EE9F3-1CAF-4FA1-A87C-AB00A3071131}" refers to invalid object "C:\WINDOWS\System32\aljjl.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{B48140F4-7072-48B5-A290-7529F15892B1}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{B5D1523F-A756-4EF5-A738-0BDC44CBCFC7}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{B6B5C9ED-B6FA-4B69-B3AE-FE9B58776655}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{B7156514-A76C-4545-9D5B-A4E1D02C7AEC}" refers to invalid object "C:\Program Files\Kazaa\Topsearch.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{B7657DCA-B0F4-4670-8E18-539210BB0395}" refers to invalid object "C:\WINDOWS\System32\ieaeb.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{B8809DC2-7531-470A-A2BE-166945388211}" refers to invalid object "C:\WINDOWS\System32\ieaeb.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:26 2005 => Entry "HKCR\CLSID\{B98F8EC0-8EA6-49C9-9CD3-1533EE96608F}" refers to invalid object "C:\Program Files\Sonic\MyDVD\SonicFileWriter.ax". Action Taken: No Action Taken.

Fri Aug 12 18:38:27 2005 => Entry "HKCR\CLSID\{BA966447-CE4D-493B-9606-28682CBE7334}" refers to invalid object "C:\WINDOWS\system32\fbpo.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:27 2005 => Entry "HKCR\CLSID\{BAE67246-0329-4EB0-84EC-7A52AFB5A901}" refers to invalid object "C:\PROGRA~1\Ahead\NEROWA~1\LEDMeter.ocx". Action Taken: No Action Taken.

Fri Aug 12 18:38:27 2005 => Entry "HKCR\CLSID\{BB2977D6-2FD8-4844-B436-B99C8B98E265}" refers to invalid object "C:\WINDOWS\System32\ibd.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:27 2005 => Entry "HKCR\CLSID\{BB88CA44-3654-4537-8A64-A50A553AA034}" refers to invalid object "C:\WINDOWS\System32\defpca.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:27 2005 => Entry "HKCR\CLSID\{BC77D989-404E-4DE5-BC32-EF44CCFB5F63}" refers to invalid object "C:\WINDOWS\System32\ibd.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:27 2005 => Entry "HKCR\CLSID\{BCB84956-DED5-4478-9E29-E07A431D9020}" refers to invalid object "C:\WINDOWS\system32\den.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:27 2005 => Entry "HKCR\CLSID\{BCD7AC23-9FB7-4E16-9C97-D5225D2567B5}" refers to invalid object "C:\PROGRA~1\Ahead\NEROWA~1\Axis.ocx". Action Taken: No Action Taken.

Fri Aug 12 18:38:27 2005 => Entry "HKCR\CLSID\{BE01BF0A-F07D-4455-A6DD-2CC599BA59C2}" refers to invalid object "C:\WINDOWS\System32\dcjjief.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:27 2005 => Entry "HKCR\CLSID\{BEC456DA-A40B-4150-9B0E-569B58DA0EAD}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:27 2005 => Entry "HKCR\CLSID\{BF39B296-B66A-463D-B5DA-65985B7F07B0}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:27 2005 => Entry "HKCR\CLSID\{C05F6F2B-E949-4BF3-A1D2-A28F7EE878CA}" refers to invalid object "C:\WINDOWS\System32\kamnah.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:27 2005 => Entry "HKCR\CLSID\{C07029C7-9DA6-49F3-BEDD-DF6971FD85EF}" refers to invalid object "C:\WINDOWS\System32\ibd.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:27 2005 => Entry "HKCR\CLSID\{C0CA1ED7-9962-4309-8C31-4590242B173A}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:27 2005 => Entry "HKCR\CLSID\{C0F2807E-7D93-4148-8B2A-D18F89976640}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:27 2005 => Entry "HKCR\CLSID\{C16BF7D3-9130-4CAF-BC48-93D05CAFC457}" refers to invalid object "C:\WINDOWS\System32\ieaeb.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:27 2005 => Entry "HKCR\CLSID\{C398B5BE-6FC7-4204-B9A6-C49332A81939}" refers to invalid object "C:\WINDOWS\system32\nnhdg.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:27 2005 => Entry "HKCR\CLSID\{C5AC3E71-AFAD-4F2F-973A-21A4F693D524}" refers to invalid object "C:\PROGRA~1\Ahead\NEROWA~1\AUDIOC~1.OCX". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{C8EE7937-9A3C-43BF-8119-9E0F40FC9C8D}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{C908FE29-D292-4923-930D-694C1A78C8A6}" refers to invalid object "C:\WINDOWS\system32\ecaae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{C9249FD5-03BC-4A34-9174-FE22998A6CFE}" refers to invalid object "C:\WINDOWS\System32\kamnah.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{C9A2784F-B4D2-4C7E-8AA2-56D0460CD0A7}" refers to invalid object "C:\WINDOWS\system32\begidpd.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{CA034DCC-A580-4333-B52F-15F98C42E04C}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\dwnldr.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{CA11C94C-15DB-4311-9EDE-22EE006AC49F}" refers to invalid object "C:\WINDOWS\system32\odpic.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{CA2AF03F-7743-43CB-BC10-2EF9A7EEA1E2}" refers to invalid object "C:\WINDOWS\system32\dci.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{CAC2415D-0A8F-4243-803A-59A1B81E2479}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{CB51EFC1-40D6-11D3-B265-00A0C9A3A56F}" refers to invalid object "C:\Program Files\Sonic\MyDVD\lmpgspl.ax". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{CB51EFC2-40D6-11D3-B265-00A0C9A3A56F}" refers to invalid object "C:\Program Files\Sonic\MyDVD\lmpgvd.ax". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{CB51EFC3-40D6-11D3-B265-00A0C9A3A56F}" refers to invalid object "C:\Program Files\Sonic\MyDVD\lmpgspl.ax". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{CB51EFC4-40D6-11D3-B265-00A0C9A3A56F}" refers to invalid object "C:\Program Files\Sonic\MyDVD\lmpgvd.ax". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{CBDA80AE-5EF2-4755-AF8E-840C0976DE57}" refers to invalid object "C:\Program Files\Deskshare\Video Edit Magic 4.0\PosterizeEffect.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{CD23AF5A-9D31-4AFB-93C7-E51D0F24539E}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{CE27D4DF-714B-4427-95EB-923FE53ADF8E}" refers to invalid object "C:\WINDOWS\dsr.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{CFDA1DB7-91C4-4E70-AB73-B374B3F9BA53}" refers to invalid object "C:\WINDOWS\System32\defpca.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{D16F98AF-2D28-40EE-8C84-79AE86084E22}" refers to invalid object "C:\WINDOWS\System32\ieaeb.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{D288DD22-DB1C-4782-B9F0-3329AEC1F2B1}" refers to invalid object "C:\WINDOWS\System32\defpca.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{D2E8800B-C57C-4713-BD0D-03FE0A301892}" refers to invalid object "C:\WINDOWS\System32\defpca.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{D36F70B1-7DF5-4FD4-A765-70CCC8F72CD7}" refers to invalid object "C:\WINDOWS\systb.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{D46FB921-8392-465F-B94B-7E6E957B6A21}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{D47E8E4B-3C59-4D5D-AF94-F9E9C6DD6215}" refers to invalid object "C:\WINDOWS\system32\fifm.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{D4AD8206-C45B-4240-A090-E063A222B66C}" refers to invalid object "C:\Program Files\Ahead\Nero\NeroCom.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{D59CF868-3464-49D3-9A96-3E6890EDC7E8}" refers to invalid object "C:\Program Files\Stardock\Object Desktop\DesktopX\SDPlugins\DXAxHost.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{D649417D-27B6-42D9-9341-D1A94D46985A}" refers to invalid object "C:\WINDOWS\System32\dmd.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{D69F3948-4C72-47E6-BCBD-8492D25525B8}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{D775557E-EFCD-47C1-A3E0-2E5F00635B90}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{D795A49F-A0E8-4E3C-941B-C3E14DD76988}" refers to invalid object "C:\WINDOWS\System32\defpca.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{D79A024D-2223-476C-A142-A14DCE66C5C5}" refers to invalid object "C:\WINDOWS\System32\defpca.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{D7FAD411-41DA-4BE2-93BE-BC0970C5A819}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{D828A7E9-BF37-4670-9882-E7911CFFF561}" refers to invalid object "C:\WINDOWS\system32\gbc.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:28 2005 => Entry "HKCR\CLSID\{D88D2C6E-4D89-47F0-BE45-089697D26D2B}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{DA53674E-7AB8-43D7-8139-A2F58B466117}" refers to invalid object "C:\WINDOWS\System32\ieaeb.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{DB85D3FF-53A6-450F-A528-5598491A7F4A}" refers to invalid object "C:\WINDOWS\System32\diih.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{DB984F74-528B-4093-907B-2D74C05862DB}" refers to invalid object "C:\WINDOWS\System32\ibd.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{DD97AC7E-15E9-4CA8-8C70-392D9D983F9F}" refers to invalid object "C:\WINDOWS\System32\ieaeb.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{DDC4113C-C094-497F-A92A-6B0EB70E0350}" refers to invalid object "C:\WINDOWS\System32\kfhpk.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{DDC79D05-2A7C-45B0-B0E6-AE082DCF7F3C}" refers to invalid object "C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{DE05ACD8-E76E-4BE2-A522-7D734FAFD072}" refers to invalid object "C:\Program Files\Ahead\Nero\NeroCom.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{DE9C389F-3316-41A7-809B-AA305ED9D922}" refers to invalid object "C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{DEE471AA-AD6C-4B87-A0AC-0D3361185523}" refers to invalid object "C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{DF1977E3-1EA8-4135-9428-2A49AAD661F5}" refers to invalid object "C:\WINDOWS\System32\defpca.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{E1685C30-131B-45CA-9BF9-6AA760BE8FCF}" refers to invalid object "C:\WINDOWS\System32\ieaeb.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{E1A46626-9FD3-11D4-824D-B0D52C000000}" refers to invalid object "C:\Program Files\Ahead\Nero\NeroCom.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{E2A34665-0800-4C0F-9F1B-CEFB3439531B}" refers to invalid object "C:\WINDOWS\System32\defpca.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{E2D2FE40-5674-4b77-802B-EC86B6C2C41D}" refers to invalid object "C:\WINDOWS\dsr.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{E30B2512-1D46-4055-9A0B-F73FD299C724}" refers to invalid object "C:\WINDOWS\System32\dmje.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{E311D3A5-4A3B-4e49-9E0A-B40FAE1F0B28}" refers to invalid object "C:\WINDOWS\dsr.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{E6674EE4-57B1-42F2-A953-43705B992AD5}" refers to invalid object "C:\PROGRA~1\Ahead\NEROSO~1\EFFECT~1.OCX". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{E70E98A7-4FB1-440C-8E06-105D1C32951D}" refers to invalid object "C:\WINDOWS\System32\kamnah.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{E745B262-93B6-4630-B26E-4E0CD4C435EC}" refers to invalid object "C:\Program Files\Stardock\Object Desktop\DesktopX\SDPlugins\DXAxHost.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{E7A3DAB4-5270-4352-8706-E05746645109}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{E7D0461B-ECCD-4DD7-847A-1224C5436CA1}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{E7F55848-5AC4-42A3-AFBC-D411F12376D8}" refers to invalid object "C:\WINDOWS\System32\ibd.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{E80A2814-3A36-4897-8BFF-924D39C26FF8}" refers to invalid object "C:\Program Files\Ahead\Nero\NeroCom.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{E9023BB2-3F47-47C2-8A56-637CDB04C421}" refers to invalid object "C:\WINDOWS\system32\jmdcagd.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{E9A18A7F-6119-4FCE-A351-5362B1C86DBA}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{E9C1D3D7-3AD8-41B7-9564-3AA3C457FCBD}" refers to invalid object "C:\WINDOWS\System32\defpca.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{EA09F0D8-B88C-4472-8E4B-57F12CDB388B}" refers to invalid object "C:\PROGRA~1\Ahead\NEROSO~1\EFFECT~1.OCX". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{EA1C6100-FF76-4C64-96F2-8C461EEF51C5}" refers to invalid object "C:\WINDOWS\system32\fifm.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{EA756889-2338-43DB-8F07-D1CA6FB9C90D}" refers to invalid object "C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{EAD6F1D6-B925-4B92-BE51-C1496DCA1326}" refers to invalid object "C:\WINDOWS\System32\ibd.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{ECF4E07C-CE18-4DB6-A7B7-C8482902D9E1}" refers to invalid object "C:\WINDOWS\System32\defpca.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{ED053B94-C351-46B5-A837-A2D9B43BC66C}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{ed28050f-d713-43ba-a376-dcc5c35407d5}" refers to invalid object "C:\Progra~1\MsnMusic\4021130\msnmusax.ocx". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{ED36B108-5D89-4689-BA9F-1DFCEBF20C0F}" refers to invalid object "C:\WINDOWS\System32\defpca.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:29 2005 => Entry "HKCR\CLSID\{EE16E722-DCFF-490d-AC63-2A14275FE651}" refers to invalid object "C:\Program Files\Deskshare\Video Edit Magic 4.0\ColorChannelEffect.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:30 2005 => Entry "HKCR\CLSID\{EE7CB360-F635-449D-BBB1-0D844F2A269D}" refers to invalid object "C:\Program Files\Common Files\AOL\AOL Toolbar\AOLHelper.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:30 2005 => Entry "HKCR\CLSID\{EEEDE8FC-EF67-4C19-803B-53A7ECECCA70}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:30 2005 => Entry "HKCR\CLSID\{EFEDF1EE-AD78-4DE4-9878-8E110683E49F}" refers to invalid object "C:\Program Files\Ahead\Nero\NeroCom.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:30 2005 => Entry "HKCR\CLSID\{F073CACD-3CEC-470B-8672-5898988ED038}" refers to invalid object "C:\WINDOWS\System32\ieaeb.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:30 2005 => Entry "HKCR\CLSID\{F091FED8-F0EB-44A4-841A-648B35397565}" refers to invalid object "C:\Program Files\Ahead\Nero\NeroCom.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:30 2005 => Entry "HKCR\CLSID\{F174EF8F-F2FB-4B58-89A0-D61381DE564A}" refers to invalid object "C:\WINDOWS\System32\defpca.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:30 2005 => Entry "HKCR\CLSID\{F1BA54A9-5CC4-48F4-9F28-41FE88E56EBF}" refers to invalid object "C:\WINDOWS\System32\kamnah.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:30 2005 => Entry "HKCR\CLSID\{F1C0FAF2-E52F-4370-BC75-2C828C027B9E}" refers to invalid object "C:\WINDOWS\System32\popkill.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:30 2005 => Entry "HKCR\CLSID\{F3B9ED5F-53E2-4DCC-AA53-55DAE6337151}" refers to invalid object "C:\Program Files\Sonic\MyDVD\snicspvr.ax". Action Taken: No Action Taken.

Fri Aug 12 18:38:30 2005 => Entry "HKCR\CLSID\{F3FBC8E5-93A3-11D4-8217-A85459000000}" refers to invalid object "C:\Program Files\Ahead\Nero\NeroCom.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:30 2005 => Entry "HKCR\CLSID\{F4650302-8D48-4F85-87E4-150D001D078F}" refers to invalid object "C:\WINDOWS\system32\bmjpida.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:30 2005 => Entry "HKCR\CLSID\{F4911B55-626B-4BBD-821E-F427EA3A9D46}" refers to invalid object "C:\WINDOWS\System32\aja.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:30 2005 => Entry "HKCR\CLSID\{F68051F1-F2D7-4B2F-A695-953C286B9CE5}" refers to invalid object "C:\WINDOWS\System32\ieaeb.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:30 2005 => Entry "HKCR\CLSID\{F6BBCAE2-7E03-4399-A2D8-13323C837CB8}" refers to invalid object "C:\WINDOWS\System32\aja.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:30 2005 => Entry "HKCR\CLSID\{F7003DF6-75B6-491A-8D19-166D0C4AEDD6}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:30 2005 => Entry "HKCR\CLSID\{F8CE4011-5762-4553-A399-F9A410FECDCB}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:30 2005 => Entry "HKCR\CLSID\{F9981FB2-6925-44E7-BC5B-65084C116873}" refers to invalid object "C:\WINDOWS\System32\defpca.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:30 2005 => Entry "HKCR\CLSID\{F999E58B-C7CD-4A75-BB96-96F798B64AC0}" refers to invalid object "C:\WINDOWS\System32\kamnah.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:30 2005 => Entry "HKCR\CLSID\{F9FABC72-9797-446B-82C1-02B2E390D9B6}" refers to invalid object "C:\WINDOWS\System32\defpca.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:30 2005 => Entry "HKCR\CLSID\{FD01DB69-9F0D-429F-BFE5-EF938667AC11}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:30 2005 => Entry "HKCR\CLSID\{FDB283BF-763E-42C2-92A9-5875D72BCEE1}" refers to invalid object "C:\WINDOWS\System32\aja.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:30 2005 => Entry "HKCR\CLSID\{FE1CB638-493D-41AE-8C0D-B7978F92D733}" refers to invalid object "C:\WINDOWS\System32\ibd.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:30 2005 => Entry "HKCR\CLSID\{FE2A0CB9-0BEE-463D-87D7-DB3397BC442D}" refers to invalid object "C:\WINDOWS\System32\aae.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:30 2005 => Entry "HKCR\CLSID\{FEC5F6B2-A15A-11D4-8250-9C9E8B000000}" refers to invalid object "C:\Program Files\Ahead\Nero\NeroCom.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:30 2005 => Entry "HKCR\CLSID\{FF5711B9-1D62-45FD-BC5D-83FD2F57C858}" refers to invalid object "C:\Program Files\Sonic\MyDVD\DVIntcpt.ax". Action Taken: No Action Taken.

Fri Aug 12 18:38:30 2005 => Entry "HKCR\CLSID\{FF583EFB-D909-45BF-9BB8-581DA9757050}" refers to invalid object "C:\WINDOWS\System32\defpca.dll". Action Taken: No Action Taken.

Fri Aug 12 18:38:31 2005 => Entry "HKCR\AcroIEHelper.AcroIEHlprObj" refers to invalid object "{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}". Action Taken: No Action Taken.

Fri Aug 12 18:38:31 2005 => Entry "HKCR\AcroIEHelper.AcroIEHlprObj.1" refers to invalid object "{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}". Action Taken: No Action Taken.

Fri Aug 12 18:38:31 2005 => Entry "HKCR\ADP.UrlCatcher.1" refers to invalid object "{F4E04583-354E-4076-BE7D-ED6A80FD66DA}". Action Taken: No Action Taken.

Fri Aug 12 18:38:31 2005 => Entry "HKCR\Alg.AlgSetup" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken.

Fri Aug 12 18:38:31 2005 => Entry "HKCR\Alg.AlgSetup.1" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken.

Fri Aug 12 18:38:32 2005 => Entry "HKCR\BrowserHelperObject.BAHelper.1" refers to invalid object "{A3FDD654-A057-4971-9844-4ED8E67DBBB8}". Action Taken: No Action Taken.

Fri Aug 12 18:38:32 2005 => Entry "HKCR\CDDBControlApple.CddbFullName.1" refers to invalid object "{63338267-37c4-44cf-8e46-756fbe9c8fdc}". Action Taken: No Action Taken.

Fri Aug 12 18:38:32 2005 => Entry "HKCR\CDDBControlApple.FullName" refers to invalid object "{63338267-37c4-44cf-8e46-756fbe9c8fdc}". Action Taken: No Action Taken.

Fri Aug 12 18:38:32 2005 => Entry "HKCR\ClientAX.ClientInstaller.1" refers to invalid object "{99410CDE-6F16-42ce-9D49-3807F78F0287}". Action Taken: No Action Taken.

Fri Aug 12 18:38:33 2005 => Entry "HKCR\DSP.DSP" refers to invalid object "{9C123EA9-AEC9-4f75-BBC0-7565FA1398966}". Action Taken: No Action Taken.

Fri Aug 12 18:38:33 2005 => Entry "HKCR\DSP.DSPDMOProp_Chorus.1" refers to invalid object "{6F63B172-5543-4593-91CE-EDBA65B9FACDB}". Action Taken: No Action Taken.

Fri Aug 12 18:38:33 2005 => Entry "HKCR\DSrch.Band" refers to invalid object "{00F1D395-4744-40f0-A611-980F61AE2C59}". Action Taken: No Action Taken.

Fri Aug 12 18:38:33 2005 => Entry "HKCR\DSrch.Band.1" refers to invalid object "{00F1D395-4744-40f0-A611-980F61AE2C59}". Action Taken: No Action Taken.

Fri Aug 12 18:38:33 2005 => Entry "HKCR\DyFuCA_BH.SinkObj.1" refers to invalid object "{CEA206E8-8057-4A04-ACE9-FF0D69A92297}". Action Taken: No Action Taken.

Fri Aug 12 18:38:34 2005 => Entry "HKCR\Messenger.MessengerApp" refers to invalid object "{FB7199AB-79BF-11d2-8D94-0000F875C541}". Action Taken: No Action Taken.

Fri Aug 12 18:38:34 2005 => Entry "HKCR\Messenger.MessengerApp.1" refers to invalid object "{FB7199AB-79BF-11d2-8D94-0000F875C541}". Action Taken: No Action Taken.

Fri Aug 12 18:38:34 2005 => Entry "HKCR\MiniBugTransporter.MiniBugTransporterX" refers to invalid object "{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C}". Action Taken: No Action Taken.

Fri Aug 12 18:38:34 2005 => Entry "HKCR\MiniBugTransporter.MiniBugTransporterX.1" refers to invalid object "{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C}". Action Taken: No Action Taken.

Fri Aug 12 18:38:34 2005 => Entry "HKCR\ncmyb.SABHO" refers to invalid object "{21B4ACC4-8874-4AEC-AEAC-F567A249B4D4}". Action Taken: No Action Taken.

Fri Aug 12 18:38:34 2005 => Entry "HKCR\ncmyb.SABHO.1" refers to invalid object "{21B4ACC4-8874-4AEC-AEAC-F567A249B4D4}". Action Taken: No Action Taken.

Fri Aug 12 18:38:35 2005 => Entry "HKCR\Plenoptic.Plenoptic" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken.

Fri Aug 12 18:38:35 2005 => Entry "HKCR\Plenoptic.Plenoptic.1" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken.

Fri Aug 12 18:38:35 2005 => Entry "HKCR\PynixDll.PynixDllObj.1" refers to invalid object "{00000000-DD60-0064-6EC2-6E0100000000}". Action Taken: No Action Taken.

Fri Aug 12 18:38:35 2005 => Entry "HKCR\RTCCore.RTCClient" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken.

Fri Aug 12 18:38:35 2005 => Entry "HKCR\RTCCore.RTCClient.1" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken.

Fri Aug 12 18:38:36 2005 => Entry "HKCR\SideFind.Finder.1" refers to invalid object "{8CBA1B49-8144-4721-A7B1-64C578C9EED7}". Action Taken: No Action Taken.

Fri Aug 12 18:38:36 2005 => Entry "HKCR\Wbho.Band.1" refers to invalid object "{0007522A-2297-43C1-8EB1-C90B0FF20DA5}". Action Taken: No Action Taken.

Fri Aug 12 18:38:36 2005 => Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.

Fri Aug 12 18:38:36 2005 => Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr.1" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.

Fri Aug 12 18:38:36 2005 => Entry "HKCR\Ysb.YsbObj.1" refers to invalid object "{86227D9C-0EFE-4f8a-AA55-30386A3F5686}". Action Taken: No Action Taken.
  • 0

#48
Excal

Excal

    Malware Slayer Extraordinaire!

  • Retired Staff
  • 12,739 posts
All of thoses were in valid objects, most likely from old uninstalls. this should take care of those.

I think it would serve you well to clean your registry!
  • Please dowload: RegSeeker.
  • Click on "Clean The Registry" in the left panel.
  • Check all boxes (make sure the backup box in the lower left corner is selected!).
  • After it runs, click "Select All" on the bottom, then right-click on any selected item in the window and select "Delete Selected Items".
  • Click "Quit RegSeeker".
Now, open any of your installed programs, and make sure that everything opens ok. If so, reboot, then go back and run the RegSeeker again, do the same thing again if anything is found. When RegSeeker finds nothing else, then it's clean!
  • 0

#49
Sk0rch

Sk0rch

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 335 posts
Fri Aug 12 18:38:38 2005 => File C:\WINDOWS\cnbabeie.exe tagged as "not-a-virus:AdWare.CommonName.b". Action Taken: No Action Taken.

Fri Aug 12 18:38:42 2005 => File C:\WINDOWS\NDNuninstall5_40.exe tagged as "not-a-virus:AdWare.NewDotNet". Action Taken: No Action Taken.

Fri Aug 12 18:38:42 2005 => Scanning File C:\WINDOWS\NDNuninstall5_48.exe
Fri Aug 12 18:38:42 2005 => File C:\WINDOWS\NDNuninstall5_48.exe tagged as "not-a-virus:AdWare.NewDotNet". Action Taken: No Action Taken.

Fri Aug 12 18:38:47 2005 => File C:\WINDOWS\xuykvgnuymg.exe tagged as "not-a-virus:AdWare.BetterInternet". Action Taken: No Action Taken.

Fri Aug 12 18:38:47 2005 => Scanning File C:\WINDOWS\yacs.log
Fri Aug 12 18:38:47 2005 => Scanning File C:\WINDOWS\yebit.exe
Fri Aug 12 18:38:47 2005 => File C:\WINDOWS\yebit.exe infected by "Trojan-Clicker.Win32.VB.ca" Virus! Action Taken: No Action Taken.

Aug 12 18:40:01 2005 => Scanning File C:\WINDOWS\system32\n?tdde.exe
Fri Aug 12 18:40:01 2005 => Result: ERROR!!! File C:\WINDOWS\system32\n?tdde.exe: Scanning Failure!!!
Fri Aug 12 18:40:01 2005 => ERROR!!! ScanFile fails for C:\WINDOWS\system32\n?tdde.exe
Fri Aug 12 18:40:24 2005 => File C:\WINDOWS\system32\ucrppcmb.dll infected by "Trojan-Downloader.Win32.Agent.b" Virus! Action Taken: No Action Taken.

Fri Aug 12 18:40:39 2005 => File C:\WINDOWS\system32\xxinnfnw.dll infected by "Trojan.Win32.Golid" Virus! Action Taken: No Action Taken.

Fri Aug 12 18:40:40 2005 => Scanning File C:\WINDOWS\system32\ZWebAuth.dll
Fri Aug 12 18:40:40 2005 => Scanning File C:\WINDOWS\system32\__delete_on_reboot__nnhdg.dll
Fri Aug 12 18:40:40 2005 => File C:\WINDOWS\system32\__delete_on_reboot__nnhdg.dll infected by "Trojan.Win32.StartPage.vr" Virus! Action Taken: No Action Taken.


Fri Aug 12 18:40:47 2005 => File C:\DOCUME~1Fri Aug 12 18:44:38 2005 => File C:\Documents and Settings\All Users\Desktop\nailfix\Process.exe tagged as not-a-virus:RiskTool.Win32.Processor.20. No Action Taken.
\Owner\LOCALS~1\Temp\se.dll infected by "Trojan.Win32.StartPage.uz" Virus! Action Taken: No Action Taken.Fri Aug 12 18:44:38 2005 => File C:\Documents and Settings\All Users\Desktop\nailfix\Process.exe tagged as not-a-virus:RiskTool.Win32.Processor.20. No Action Taken.


Fri Aug 12 18:43:26 2005 => Scanning File C:\Documents and Settings\Administrator.HOME\My Documents\mirc612.exe
Fri Aug 12 18:43:27 2005 => File C:\Documents and Settings\Administrator.HOME\My Documents\mirc612.exe tagged as not-a-virus:Client-IRC.Win32.mIRC.612. No Action Taken.

Fri Aug 12 18:47:15 2005 => File C:\Documents and Settings\Default User\My Documents\mirc612.exe tagged as not-a-virus:Client-IRC.Win32.mIRC.612. No Action Taken.

Fri Aug 12 18:50:01 2005 => File C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-3cc46f89-576c2242.zip infected by "Trojan-Downloader.Java.OpenStream.w" Virus! Action Taken: No Action Taken.
Fri Aug 12 18:55:08 2005 => File C:\Documents and Settings\Owner\Local Settings\Temp\se.dll infected by "Trojan.Win32.StartPage.uz" Virus! Action Taken: No Action Taken.
Fri Aug 12 18:57:26 2005 => File C:\Documents and Settings\Owner\My Documents\mirc612.exe tagged as not-a-virus:Client-IRC.Win32.mIRC.612. No Action Taken.
Fri Aug 12 19:39:53 2005 => File C:\Program Files\mIRC\backup\mirc.exe tagged as not-a-virus:Client-IRC.Win32.mIRC.612. No Action Taken.

Fri Aug 12 19:39:58 2005 => File C:\Program Files\mIRC\mirc.exe tagged as not-a-virus:Client-IRC.Win32.mIRC.616. No Action Taken.

Fri Aug 12 19:58:27 2005 => File C:\RECYCLER\S-1-5-21-4241364164-3383969137-4226995620-1003\Dc143.exe tagged as "not-a-virus:AdWare.ToolBar.IeSearchBar". Action Taken: No Action Taken.
Fri Aug 12 19:58:30 2005 => File C:\RECYCLER\S-1-5-21-4241364164-3383969137-4226995620-1003\Dc184.exe infected by "Trojan-Downloader.Win32.VB.fz" Virus! Action Taken: No Action Taken.

Fri Aug 12 19:59:00 2005 => File C:\RECYCLER\S-1-5-21-4241364164-3383969137-4226995620-1003\Dc68.exe tagged as "not-a-virus:AdWare.ToolBar.Cash". Action Taken: No Action Taken.
Fri Aug 12 19:59:03 2005 => File C:\Rest of Desktop\cs1005.exe tagged as not-a-virus:Server-Proxy.Win32.Hltv. No Action Taken.

Fri Aug 12 19:59:03 2005 => Scanning File C:\Rest of Desktop\cs1point5.exe
Fri Aug 12 19:59:05 2005 => File C:\Rest of Desktop\cs1point5.exe tagged as not-a-virus:Server-Proxy.Win32.Hltv. No Action Taken.
Fri Aug 12 20:06:01 2005 => File C:\unzipped\hijackthis\backups\backup-20050807-144556-491.dll infected by "Trojan.Win32.StartPage.qr" Virus! Action Taken: a.

Fri Aug 12 20:06:01 2005 => File C:\unzipped\hijackthis\backups\backup-20050807-144556-906.dll tagged as "not-a-virus:AdWare.PurityScan.ak". Action Taken: No Action Taken.

Fri Aug 12 20:10:21 2005 => File C:\WINDOWS\browserxtras\pn\remove.exe infected by "Trojan-Downloader.Win32.Keenval.f" Virus! Action Taken: No Action Taken.

Fri Aug 12 20:10:21 2005 => File C:\WINDOWS\cnbabeie.exe tagged as "not-a-virus:AdWare.CommonName.b". Action Taken: No Action Taken.

Fri Aug 12 20:28:04 2005 => File C:\WINDOWS\NDNuninstall5_40.exe tagged as "not-a-virus:AdWare.NewDotNet". Action Taken: No Action Taken.

Fri Aug 12 20:28:04 2005 => Scanning File C:\WINDOWS\NDNuninstall5_48.exe
Fri Aug 12 20:28:04 2005 => File C:\WINDOWS\NDNuninstall5_48.exe tagged as "not-a-virus:AdWare.NewDotNet". Action Taken: No Action Taken.

Fri Aug 12 20:36:14 2005 => File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\all_files9.exe tagged as "not-a-virus:AdWare.PurityScan.h". Action Taken: No Action Taken.

Fri Aug 12 20:39:00 2005 => File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\Patch211.exe infected by "Trojan-Dropper.Win32.Agent.r" Virus! Action Taken: No Action Taken.

Fri Aug 12 20:40:54 2005 => File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\tracker9.exe tagged as "not-a-virus:AdWare.WinFetcher.d". Action Taken: No Action Taken.

Fri Aug 12 20:40:54 2005 => File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\UpdatedUpdaterInstall.exe infected by "Trojan-Downloader.Win32.Small.alx" Virus! Action Taken: No Action Taken.

Fri Aug 12 20:41:05 2005 => File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\U8MZEX3T\bot[1].exe infected by "Backdoor.Win32.Agobot.gen" Virus! Action Taken: No Action Taken.

Fri Aug 12 20:41:39 2005 => File C:\WINDOWS\system32\config\systemprofile\My Documents\mirc612.exe tagged as not-a-virus:Client-IRC.Win32.mIRC.612. No Action Taken.

Fri Aug 12 20:47:13 2005 => File C:\WINDOWS\system32\ucrppcmb.dll infected by "Trojan-Downloader.Win32.Agent.b" Virus! Action Taken: No Action Taken.
Fri Aug 12 20:47:45 2005 => File C:\WINDOWS\system32\xxinnfnw.dll infected by "Trojan.Win32.Golid" Virus! Action Taken: No Action Taken.


Fri Aug 12 20:47:45 2005 => File C:\WINDOWS\system32\__delete_on_reboot__nnhdg.dll infected by "Trojan.Win32.StartPage.vr" Virus! Action Taken: No Action Taken.

Fri Aug 12 20:48:06 2005 => File C:\WINDOWS\xuykvgnuymg.exe tagged as "not-a-virus:AdWare.BetterInternet". Action Taken: No Action Taken.

Fri Aug 12 20:48:06 2005 => Scanning File C:\WINDOWS\yacs.log
Fri Aug 12 20:48:07 2005 => Scanning File C:\WINDOWS\yebit.exe
Fri Aug 12 20:48:07 2005 => File C:\WINDOWS\yebit.exe infected by "Trojan-Clicker.Win32.VB.ca" Virus! Action Taken: No Action Taken.

Fri Aug 12 21:03:31 2005 => File C:\WINDOWS\browserxtras\pn\remove.exe infected by "Trojan-Downloader.Win32.Keenval.f" Virus! Action Taken: No Action Taken.

Fri Aug 12 21:03:32 2005 => File C:\WINDOWS\cnbabeie.exe tagged as "not-a-virus:AdWare.CommonName.b". Action Taken: No Action Taken.


Fri Aug 12 21:21:48 2005 => File C:\WINDOWS\NDNuninstall5_40.exe tagged as "not-a-virus:AdWare.NewDotNet". Action Taken: No Action Taken.

Fri Aug 12 21:21:48 2005 => Scanning File C:\WINDOWS\NDNuninstall5_48.exe
Fri Aug 12 21:21:48 2005 => File C:\WINDOWS\NDNuninstall5_48.exe tagged as "not-a-virus:AdWare.NewDotNet". Action Taken: No Action Taken.

Fri Aug 12 21:31:47 2005 => File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\all_files9.exe tagged as "not-a-virus:AdWare.PurityScan.h". Action Taken: No Action Taken.

Fri Aug 12 21:33:33 2005 => File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\Patch211.exe infected by "Trojan-Dropper.Win32.Agent.r" Virus! Action Taken: No Action Taken.
Fri Aug 12 21:34:29 2005 => File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\tracker9.exe tagged as "not-a-virus:AdWare.WinFetcher.d". Action Taken: No Action Taken

Fri Aug 12 21:34:29 2005 => File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\UpdatedUpdaterInstall.exe infected by "Trojan-Downloader.Win32.Small.alx" Virus! Action Taken: No Action Taken

Fri Aug 12 21:34:38 2005 => File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\U8MZEX3T\bot[1].exe infected by "Backdoor.Win32.Agobot.gen" Virus! Action Taken: No Action Taken.

Fri Aug 12 21:34:58 2005 => File C:\WINDOWS\system32\config\systemprofile\My Documents\mirc612.exe tagged as not-a-virus:Client-IRC.Win32.mIRC.612. No Action Taken.


Fri Aug 12 21:38:24 2005 => File C:\WINDOWS\system32\ucrppcmb.dll infected by "Trojan-Downloader.Win32.Agent.b" Virus! Action Taken: No Action Taken.

Fri Aug 12 21:38:46 2005 => File C:\WINDOWS\system32\xxinnfnw.dll infected by "Trojan.Win32.Golid" Virus! Action Taken: No Action Taken.


Fri Aug 12 21:38:46 2005 => File C:\WINDOWS\system32\__delete_on_reboot__nnhdg.dll infected by "Trojan.Win32.StartPage.vr" Virus! Action Taken: No Action Taken.

Fri Aug 12 21:39:02 2005 => File C:\WINDOWS\xuykvgnuymg.exe tagged as "not-a-virus:AdWare.BetterInternet". Action Taken: No Action Taken.

Fri Aug 12 21:39:02 2005 => Scanning File C:\WINDOWS\yacs.log
Fri Aug 12 21:39:02 2005 => Scanning File C:\WINDOWS\yebit.exe
Fri Aug 12 21:39:02 2005 => File C:\WINDOWS\yebit.exe infected by "Trojan-Clicker.Win32.VB.ca" Virus! Action Taken: No Action Taken.
  • 0

#50
Sk0rch

Sk0rch

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 335 posts
Ok I think that is all of them, besides the ones that were in System Volume Information, there were a lot of those, can I ask why you don't want those?

I am running Regseeker right now, about how long do you think it will take, it has found about 600 things so far.

Edited by Sk0rch, 13 August 2005 - 04:44 PM.

  • 0

#51
Excal

Excal

    Malware Slayer Extraordinaire!

  • Retired Staff
  • 12,739 posts

besides the ones that were in System Volume Information, there were a lot of those, can I ask why you don't want those?

View Post



Sure you can :tazz: Those will be deleted once we reset your restore points ;)


Please download the Killbox.


Please run Killbox.
  • Select "Delete on Reboot".
  • Copy the file names below to the clipboard by highlighting them and pressing Control-C:


    C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-3cc46f89-576c2242.zip
    C:\Documents and Settings\Owner\Local Settings\Temp\se.dll
    C:\RECYCLER\S-1-5-21-4241364164-3383969137-4226995620-1003\Dc143.exe
    C:\RECYCLER\S-1-5-21-4241364164-3383969137-4226995620-1003\Dc184.exe
    C:\RECYCLER\S-1-5-21-4241364164-3383969137-4226995620-1003\Dc68.exe
    C:\Rest of Desktop\cs1005.exe
    C:\Rest of Desktop\cs1point5.exe .
    C:\WINDOWS\system32\ucrppcmb.dll
    C:\WINDOWS\system32\xxinnfnw.dll
    C:\WINDOWS\browserxtras\pn\remove.exe
    C:\WINDOWS\cnbabeie.exe
    C:\WINDOWS\NDNuninstall5_40.exe
    C:\WINDOWS\NDNuninstall5_48.exe
    C:\WINDOWS\NDNuninstall5_48.exe
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\all_files9.exe
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\Patch211.exe
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\tracker9.exe
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\UpdatedUpdaterInstall.exe
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\U8MZEX3T\bot[1].exe
    C:\WINDOWS\system32\ucrppcmb.dll
    C:\WINDOWS\system32\xxinnfnw.dll
    C:\WINDOWS\system32\__delete_on_reboot__nnhdg.dll
    C:\WINDOWS\xuykvgnuymg.exe
    C:\WINDOWS\yacs.log
    C:\WINDOWS\yebit.exe



  • Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
  • Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

    If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click here to download and run missingfilesetup.exe. Then try TheKillbox again..

  • Let the system reboot.

Please run cleanup! again.

Copy everything inside the quote box below (starting with dir) and paste it into notepad. Go up to "File > Save As" and click the drop-down box to change the "Save As Type" to "All Files". Save it as findfile.bat on your Desktop.

dir C:\WINDOWS\system32\n?tdde.exe /a h > files.txt
notepad files.txt


Locate findfile.bat on your Desktop and double-click on it. It will open Notepad with some text in it. Please post the contents of that Notepad here along with a new HiJackThis log.
  • 0

#52
Sk0rch

Sk0rch

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 335 posts
Regseeker is done, what do you want me to do with that?

[*] Copy the file names below to the clipboard by highlighting them and pressing Control-C:
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-3cc46f89-576c2242.zip
C:\Documents and Settings\Owner\Local Settings\Temp\se.dll
C:\RECYCLER\S-1-5-21-4241364164-3383969137-4226995620-1003\Dc143.exe
C:\RECYCLER\S-1-5-21-4241364164-3383969137-4226995620-1003\Dc184.exe
C:\RECYCLER\S-1-5-21-4241364164-3383969137-4226995620-1003\Dc68.exe
C:\Rest of Desktop\cs1005.exe
C:\Rest of Desktop\cs1point5.exe .
C:\WINDOWS\system32\ucrppcmb.dll
C:\WINDOWS\system32\xxinnfnw.dll
C:\WINDOWS\browserxtras\pn\remove.exe
C:\WINDOWS\cnbabeie.exe
C:\WINDOWS\NDNuninstall5_40.exe
C:\WINDOWS\NDNuninstall5_48.exe
C:\WINDOWS\NDNuninstall5_48.exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\all_files9.exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\Patch211.exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\tracker9.exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\UpdatedUpdaterInstall.exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\U8MZEX3T\bot[1].exe
C:\WINDOWS\system32\ucrppcmb.dll
C:\WINDOWS\system32\xxinnfnw.dll
C:\WINDOWS\system32\__delete_on_reboot__nnhdg.dll
C:\WINDOWS\xuykvgnuymg.exe
C:\WINDOWS\yacs.log
C:\WINDOWS\yebit.exe

[*] Return to Killbox, go to the File menu, and choose "Paste from Clipboard".

I highlighted those directories and pressed control C, you said you wanted to paste them in the clipboard... what clipboard? I have killbox open, I do not see anything called a clipboard, the closest thing I see is where it says paste from clipboard under file.
  • 0

#53
Sk0rch

Sk0rch

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 335 posts
Oh I see you want me to copy them one at a time, then go to file and click paste from clipboard, then deleting it correct?
  • 0

#54
Sk0rch

Sk0rch

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 335 posts
Ok I deleted all that stuff with killbox, and I restarted and I am about to run Cleanup! But you know how you made me find that stuff in registry with Regseeker, well it found about 2500 items and you didn't tell me what to do with that program after that, and now I restarted, will I have to do the scan for Regseeker all over again?
  • 0

#55
Sk0rch

Sk0rch

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 335 posts
Here are the contents of the of the findfile.bat and the Hijackthis log.

Volume in drive C is HP_PAVILION
Volume Serial Number is A8E1-CAEB

Directory of C:\WINDOWS\system32

08/04/2004 02:56 AM 111,104 netdde.exe
07/21/2005 08:55 AM 401,408 n?tdde.exe
2 File(s) 512,512 bytes

Directory of C:\Documents and Settings\Owner\Desktop

-----------------

Logfile of HijackThis v1.99.1
Scan saved at 7:42:13 PM, on 8/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Browser MOUSE\mouse32a.exe
C:\WINDOWS\system32\rundll32.exe
C:\program files\steam\steam.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\unzipped\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Owner\LOCALS~1\Temp\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Owner\LOCALS~1\Temp\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe
O2 - BHO: (no name) - {75EADD2C-263D-432F-B554-4C4421866062} - C:\WINDOWS\system32\jooa.dll (file missing)
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Browser MOUSE\mouse32a.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\Owner\LOCALS~1\Temp\se.dll,DllInstall
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O9 - Extra button: Wild Jack Poker - {17709D14-4A02-42c6-B9FA-18C90A851F51} - C:\Program Files\wildjackMPP\MPPoker.exe
O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Program Files\Poker.com\poker.exe
O9 - Extra button: CDpoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - C:\Program Files\CDpoker\casino.exe
O9 - Extra 'Tools' menuitem: CDpoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - C:\Program Files\CDpoker\casino.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\earthlinkim\aim.exe
O9 - Extra button: bet365 Poker - {B1BA4A3F-1C95-497b-9F82-F8DA4A5C89DD} - C:\Program Files\bet365MPP\MPPoker.exe
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\GameClient.exe
O9 - Extra button: Royal Vegas Poker - {FA4904B4-1FAF-4afd-886C-C19D2297BA62} - C:\Program Files\royalvegasMPP\MPPoker.exe
O9 - Extra button: POKER - {FB389F33-303A-4490-9E18-B301A493FBF2} - C:\Program Files\PokermMPP\MPPoker.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplane...DC_1_0_0_44.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.r...ip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1096169702640
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.c.../ymmapi_416.dll
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla...ller/dwnldr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4DF65C0F-7292-4D21-8937-D46BD8F1A1E7}: NameServer = 206.141.192.60 206.141.193.55
O18 - Filter: text/html - {89DE7EE8-8EC8-4434-A7BD-7BFA204884B0} - C:\WINDOWS\system32\jooa.dll
O18 - Filter: text/plain - {89DE7EE8-8EC8-4434-A7BD-7BFA204884B0} - C:\WINDOWS\system32\jooa.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
  • 0

Advertisements


#56
Excal

Excal

    Malware Slayer Extraordinaire!

  • Retired Staff
  • 12,739 posts

Oh I see you want me to copy them one at a time, then go to file and click paste from clipboard, then deleting it correct?


No copy the whole list. Then paste from clip board. It will look like there is only one in there.

#  After it runs, click "Select All" on the bottom, then right-click on any selected item in the window and select "Delete Selected Items".
# Click "Quit RegSeeker".


So you want to delete all of them, then reboot, then run again.

If you already have these, you don't need to download them again ;)

Download about:buster by RubbeRDuckY Here.
Download CWShredder Here.
Download SpSeHjfix Here.


reboot into safe mode


Now run CWShredder. Click I Agree, then Fix and then Next, let it fix everything it asks about

Open HiJackthis and check the following off:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Owner\LOCALS~1\Temp\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Owner\LOCALS~1\Temp\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\Owner\LOCALS~1\Temp\se.dll,DllInstall


Click FIX CHECKED, then close HJT

Please run about:buster by RubbeRDuckY:
  • Click Begin Removal.
  • It will begin to check your computer for malicious files.
  • AboutBuster will finish and open a new page. Follow the instructions for protection on that page.
  • Shut down AboutBuster. A log should have been created.Please Save this log and copy it in your next post.
Now run SpSeHjfix. A log will be saved in the same folder that you put the exe into. Please post the results of that log in your next reply.

Run the program CleanUp!

Reboot and please post a fresh HJT log along with the spsehjfix log and the about buster log


Thanks,

:tazz:

Excal

Edited by Excal, 13 August 2005 - 06:53 PM.

  • 0

#57
Sk0rch

Sk0rch

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 335 posts
Well I copy pasted them one at a time and deleted them, and then I restarted and ran clean up, is that all right? As for regseeker, after it scanned, I forgot to click select all and delete the selected items, do you want me to click clean the registry and scan again?
  • 0

#58
Excal

Excal

    Malware Slayer Extraordinaire!

  • Retired Staff
  • 12,739 posts
Yes. Your suppose to run it, delete, reboot, and do it again. Keep doing it until it can't fix anymore.


Thanks,

:tazz:

Excal
  • 0

#59
Sk0rch

Sk0rch

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 335 posts
Ok, well I kept deleting and restarted about 4 times, the last two times I scanned, when I opeend Regseeker it showed some red X errors in german, but it still works so oh well. I am done with Regseeker, about to do that safe mode stuff.
  • 0

#60
Excal

Excal

    Malware Slayer Extraordinaire!

  • Retired Staff
  • 12,739 posts
I think I can see the light at the end of the tunnel my friend!!

:tazz:

Excal
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP