Please help with WinPup

  1. #11
    Draco is offline Full Member

    Re: Please help with WinPup

    Hi Neal,

    I just want to start by saying thanks for everything so far. I first ran CCleaner.

    The 2 logs are long. I had to split them among 3 posts.

    SilentRunners:

    "Silent Runners.vbs", revision 41, http://www.silentrunners.org/
    Operating System: Windows Me (Millennium Edition)
    Output limited to non-default values, except where indicated by "{++}"


    Startup items buried in registry:
    ---------------------------------

    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \ {++}
    "a-squared" = ""C:\Program Files\a-squared\a2guard.exe"" [null data]

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \ {++}
    "PCHealth" = "C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s" [MS]
    "StatusClient" = "C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto" ["Hewlett-Packard"]
    "TomcatStartup" = "C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe" ["Hewlett-Packard"]
    "TkBellExe" = ""C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot" ["RealNetworks, Inc."]
    "devldr16.exe" = "C:\WINDOWS\SYSTEM\devldr16.exe" [file not found]

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Services\ {++}
    "SchedulingAgent" = "mstask.exe" [MS]
    "*StateMgr" = "C:\WINDOWS\System\Restore\StateMgr.exe" [MS]
    "HP Port Resolver" = "C:\WINDOWS\SYSTEM\hpbpro.exe" ["Hewlett-Packard Company"]
    "HP Status Server" = "C:\WINDOWS\SYSTEM\hpboid.exe" ["Hewlett-Packard Company"]
    "StillImageMonitor" = "C:\WINDOWS\SYSTEM\STIMON.EXE" [MS]
    "KB891711" = "C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE" [MS]

    HKLM\Software\Microsoft\Active Setup\Installed Components\
    PerUser_CVT_Inis\(Default) = "Windows Setup - FAT32 Converter"
    \StubPath = "rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_CVT_Inis 64 C:\WINDOWS\INF\applets1.inf" [MS]
    PerUser_Onlinelnks_Inis\(Default) = "Windows Setup - HyperTerminal"
    \StubPath = "rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_Onlinelnks_Inis_remove 64 C:\WINDOWS\INF\appletpp.inf" [MS]
    PerUser_Dialer_Inis\(Default) = "Windows Setup - Phone Dialer"
    \StubPath = "rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_Dialer_Inis_remove 64 C:\WINDOWS\INF\appletpp.inf" [MS]
    {44BBA842-CC51-11CF-AAFA-00AA00B6015C}\(Default) = "NetMeeting 3.01"
    \StubPath = "rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Remove.PerUser. W95" [MS]

    HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\
    {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = "AcroIEHlprObj Class" [from CLSID]
    -> {CLSID}\InProcServer32\(Default) = "C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL" ["Adobe Systems Incorporated"]

    HKLM\Software\Microsoft\Windows\CurrentVersion\She ll Extensions\Approved\
    "{e57ce731-33e8-4c51-8354-bb4de9d215d1}" = "Universal Plug and Play Devices"
    -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\SYSTEM\UPNPUI.DLL" [file not found]
    "{8f7261d0-d2b9-11d2-9909-00605205b24c}" = "CuteFTP Shell Extension"
    -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\GlobalSCAPE\CuteFTP\CuteShell.dll" [file not found]
    "{2F25CF20-C569-11D1-B94C-00608CB45480}" = "TextPad"
    -> {CLSID}\InProcServer32\(Default) = "C:\PROGRAM FILES\TEXTPAD 4\System\shellext.dll" [file not found]
    "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
    -> {CLSID}\InProcServer32\(Default) = "C:\PROGRAM FILES\REAL\REALPLAYER\RPSHELLEXT.DLL" ["RealNetworks"]

    HKLM\Software\Classes\*\shellex\ContextMenuHandler s\
    CuteFTP\(Default) = "{8f7261d0-d2b9-11d2-9909-00605205b24c}"
    -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\GlobalSCAPE\CuteFTP\CuteShell.dll" [file not found]
    WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
    -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
    TextPad\(Default) = "{2F25CF20-C569-11D1-B94C-00608CB45480}"
    -> {CLSID}\InProcServer32\(Default) = "C:\PROGRAM FILES\TEXTPAD 4\System\shellext.dll" [file not found]

    HKLM\Software\Classes\Directory\shellex\ContextMen uHandlers\
    CuteFTP\(Default) = "{8f7261d0-d2b9-11d2-9909-00605205b24c}"
    -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\GlobalSCAPE\CuteFTP\CuteShell.dll" [file not found]
    WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
    -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]

    HKLM\Software\Classes\Folder\shellex\ContextMenuHa ndlers\
    WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
    -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]


    Active Desktop and Wallpaper:
    -----------------------------

    Active Desktop is enabled at this entry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Exp lorer\ShellState

    HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
    "Wallpaper" = "C:\WINDOWS\Web\Wallpaper\Fall Memories.jpg"


    WIN.INI & SYSTEM.INI launch points:
    -----------------------------------

    SYSTEM.INI
    [boot]
    "SCRNSAVE.EXE=C:\WINDOWS\SYSTEM\UNDERW~1.SCR" (Underwater.scr) [MS]


    Enabled Scheduled Tasks:
    ------------------------

    "Tune-up Application Start" -> launches: "walign" [MS]
    "PCHealth Scheduler for Data Collection" -> launches: "C:\WINDOWS\PCHEALTH\SUPPORT\PCHSCHD.EXE -c" [MS]
    "Symantec NetDetect" -> launches: "C:\PROGRAM FILES\SYMANTEC\LIVEUPDATE\NDETECT.EXE" ["Symantec Corporation"]


    Winsock2 Service Provider DLLs:
    -------------------------------

    Namespace Service Providers

    HKLM\System\CurrentControlSet\Services\Winsock2\Pa rameters\NameSpace_Catalog5\Catalog_Entries\ {++}
    000000000001\LibraryPath = "C:\WINDOWS\SYSTEM\rnr20.dll" [MS]

    Transport Service Providers

    HKLM\System\CurrentControlSet\Services\Winsock2\Pa rameters\Protocol_Catalog9\Catalog_Entries\ {++}
    00000000000#\PackedCatalogItem (contains) DLL [Company Name], (at) # range:
    C:\WINDOWS\SYSTEM\msafd.dll [MS], 1 - 3
    C:\WINDOWS\SYSTEM\rsvpsp.dll [MS], 4 - 5


    Toolbars, Explorer Bars, Extensions:
    ------------------------------------

    Toolbars

    HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
    "{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" = "MSN" [from CLSID]
    -> {CLSID}\InProcServer32\(Default) = "C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.3000.1001\EN-US\MSNTB.DLL" [file not found]

    Explorer Bars

    HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\
    {FE54FA40-D68C-11D2-98FA-00C0F0318AFE}\ = "Real.com" [from CLSID]
    -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\SYSTEM\Shdocvw.dll" [MS]

    Extensions (Tools menu items, main toolbar menu buttons)

    HKCU\Software\Microsoft\Internet Explorer\Extensions\
    {EE117DAA-A30B-40FC-945C-38AE1B80C1FA}\
    "ButtonText" = "Dell Home"
    "Exec" = "http://www.dellnet.com/" [file not found]

    HKLM\Software\Microsoft\Internet Explorer\Extensions\
    {2FDEF853-0759-11D4-A92E-006097DBED37}\
    "ButtonText" = "Encarta Encyclopedia"
    "MenuText" = "Encarta Encyclopedia"
    "Script" = "C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM" [null data]

    {85D1F590-48F4-11D9-9669-0800200C9A66}\
    "MenuText" = "Uninstall BitDefender Online Scanner v8"
    "Exec" = "%windir%\bdoscandel.exe" [null data]


    Print Monitors:
    ---------------

    HKLM\System\CurrentControlSet\Control\Print\Monito rs\
    HCL LPR Monitor\Driver = "C:\WINDOWS\SYSTEM\Hummbird\HCLLPR.DLL" [file not found]
    Lexmark Network Printer Monitor\Driver = "LEXLMPM.DLL" ["Lexmark International, Inc."]
    USB Monitor\Driver = "usbmon.dll" [MS]
    USBPortMonitor\Driver = "usbmon.dll" [MS]
    HP Master Monitor\Driver = "HPBMMON.DLL" ["Hewlett-Packard"]


    ----------
    + This report excludes default entries except where indicated.
    + To see *everywhere* the script checks and *everything* it finds,
    launch it from a command prompt or a shortcut with the -all parameter.
    + To search all directories of local fixed drives for DESKTOP.INI
    DLL launch points and all Registry CLSIDs for dormant Explorer Bars,
    use the -supp parameter or answer "No" at the first message box.
    ---------- (total run time: 27 seconds, including 18 seconds for message boxes)
    Last edited by Draco; 15-11-2005 at 05:38 AM.


  2. #12
    Draco is offline Full Member
    More Splitting MWAV Part I:

    Object "istbar Spyware/Adware" found in File System! Action Taken: No Action Taken.
    Object "istbar Spyware/Adware" found in File System! Action Taken: No Action Taken.
    Object "bearshare Spyware/Adware" found in File System! Action Taken: No Action Taken.
    Object "bearshare Spyware/Adware" found in File System! Action Taken: No Action Taken.
    Object "matrix technology network 123mania Spyware/Adware" found in File System! Action Taken: No Action Taken.
    Object "win32.decisive.a Spyware/Adware" found in File System! Action Taken: No Action Taken.
    Object "whenu.sidefinder Spyware/Adware" found in File System! Action Taken: No Action Taken.
    Object "whenu.sidefinder Spyware/Adware" found in File System! Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Sh aredDlls" refers to invalid object "C:\WINDOWS\SYSTEM\CTSVCCDA.EXE". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Sh aredDlls" refers to invalid object "C:\WINDOWS\SYSTEM\CTSVCCTL.EXE". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Sh aredDlls" refers to invalid object "C:\WINDOWS\TEMP\_ISTMP0.DIR\Drivers\SONYCD~1.DLL" . Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Sh aredDlls" refers to invalid object "C:\WINDOWS\TEMP\_ISTMP0.DIR\Drivers\ERICDA~1.DLL" . Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Sh aredDlls" refers to invalid object "C:\WINDOWS\TEMP\_ISTMP0.DIR\Drivers\ERICFO~1.DLL" . Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Sh aredDlls" refers to invalid object "C:\WINDOWS\TEMP\_ISTMP0.DIR\Drivers\NOKIAG~1.DLL" . Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Sh aredDlls" refers to invalid object "C:\WINDOWS\TEMP\_ISTMP0.DIR\Drivers\NOKIAH~1.DLL" . Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Sh aredDlls" refers to invalid object "C:\WINDOWS\TEMP\_ISTMP0.DIR\Drivers\NOKIAT~1.DLL" . Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Sh aredDlls" refers to invalid object "C:\WINDOWS\TEMP\_ISTMP0.DIR\Drivers\NULLFO~1.DLL" . Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Sh aredDlls" refers to invalid object "C:\WINDOWS\TEMP\_ISTMP0.DIR\Drivers\SMARTL~1.DLL" . Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Sh aredDlls" refers to invalid object "C:\WINDOWS\TEMP\_ISTMP0.DIR\Drivers\07_07F~1.DLL" . Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Sh aredDlls" refers to invalid object "C:\WINDOWS\TEMP\_ISTMP0.DIR\Drivers\SAMCDM~1.DLL" . Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Sh aredDlls" refers to invalid object "C:\WINDOWS\TEMP\_ISTMP0.DIR\Drivers\CDMA1F~1.DLL" . Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Sh aredDlls" refers to invalid object "C:\WINDOWS\TEMP\_ISTMP0.DIR\Drivers\MITSUB~1.DLL" . Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Sh aredDlls" refers to invalid object "C:\WINDOWS\SYSTEM\SQLOLEDB.TXT". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Sh aredDlls" refers to invalid object "C:\WINDOWS\NEWSOFT\ACP.DLL". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Sh aredDlls" refers to invalid object "C:\Program Files\Microsoft Visual Studio\Common\Tools\SPYXX.CNT". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Sh aredDlls" refers to invalid object "C:\Program Files\Microsoft Visual Studio\Common\Tools\SPYXX.EXE". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Sh aredDlls" refers to invalid object "C:\WINDOWS\TEMP\_ISTMP13.DIR\_ISTMP0.DIR\DUMMY.TX T". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Sh aredDlls" refers to invalid object "C:\WINDOWS\TEMP\_ISTMP13.DIR\_ISTMP0.DIR\FTPINS~1 .DLL". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Sh aredDlls" refers to invalid object "C:\WINDOWS\TEMP\_ISTMP13.DIR\_ISTMP0.DIR\WHATSNEW .TXT". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Sh aredDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\RdxIE.dll". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Sh aredDlls" refers to invalid object "C:\Program Files\Common Files\Real\Update_OB\realevent.exe". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Sh aredDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\ISTactivex.dll". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Sh aredDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\WinServAdX.dll". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Ap p Paths\CMPAGENT.EXE" refers to invalid object "". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Ap p Paths\table30.exe" refers to invalid object "". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Ap p Paths\pbrush.exe" refers to invalid object "C:\WINDOWS\SYSTEM\mspaint.exe". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Ap p Paths\MRUN32.EXE" refers to invalid object "C:\WINDOWS\MRUN32.EXE". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Ap p Paths\minstall.exe" refers to invalid object "". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Ap p Paths\yourapp.Exe" refers to invalid object "C:\Program Files\Dell Computer Corporation\Dell Solution Center\yourapp.Exe". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Ap p Paths\iLearn6.exe" refers to invalid object "iLearn6.exe". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Ap p Paths\navlu32.exe" refers to invalid object "C:\Program Files\Norton AntiVirus\navlu32.exe". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Ap p Paths\MsoHtmEd.exe" refers to invalid object "". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Ap p Paths\Enc2001.exe" refers to invalid object "". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Ap p Paths\Aol.exe" refers to invalid object "C:\America Online 5.0aq\Aol.exe". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Ap p Paths\PCFriend.exe" refers to invalid object "C:\Program Files\PCFriendly". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Ap p Paths\cascade.exe" refers to invalid object "C:\Program Files\CASCADE\cascade.exe". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Ap p Paths\EViews3s.exe" refers to invalid object "C:\EViews3s\EViews3s.exe". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Ap p Paths\Netscp6.exe" refers to invalid object "". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Ap p Paths\EnterNet.exe" refers to invalid object "C:\Program Files\3Com\DLCC\app\EnterNet.exe". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Ap p Paths\InterActual Player" refers to invalid object "". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Ap p Paths\Createcd50.exe" refers to invalid object "C:\Program Files\Common Files\Adaptec Shared\CreateCD\createcd50.exe". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\In staller\Folders" refers to invalid object "C:\WINDOWS\Favorites\Financial Links\". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Shared Tools\spyxx.cnt" refers to invalid object "C:\Program Files\Microsoft Visual Studio\Common\Tools\SPYXX.CNT". Action Taken: No Action Taken.
    Entry "HKLM\Software\Microsoft\Shared Tools\spyxx.exe" refers to invalid object "C:\Program Files\Microsoft Visual Studio\Common\Tools\SPYXX.EXE". Action Taken: No Action Taken.
    Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Ex plorer\FileExts" refers to invalid object ".". Action Taken: No Action Taken.
    Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Ex plorer\FileExts" refers to invalid object ".CPP". Action Taken: No Action Taken.
    Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Ex plorer\FileExts" refers to invalid object ".RC". Action Taken: No Action Taken.
    Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Ex plorer\FileExts" refers to invalid object ".VOB". Action Taken: No Action Taken.
    Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Ex plorer\FileExts" refers to invalid object ".ZDB". Action Taken: No Action Taken.
    Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Ex plorer\FileExts" refers to invalid object ".doc?mailbox=INBOX&index=8894&bodypart=2&actionID =13". Action Taken: No Action Taken.
    Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Ex plorer\FileExts" refers to invalid object ".doc?mailbox=INBOX&index=10145&bodypart=2&actionI D=13". Action Taken: No Action Taken.
    Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Ex plorer\FileExts" refers to invalid object ".doc?mailbox=INBOX&index=10195&bodypart=2&actionI D=13". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{D3B1DE00-6B94-1069-8754-08002B2BD64F}" refers to invalid object "C:\WINDOWS\SYSTEM\disktool.dll". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{e57ce731-33e8-4c51-8354-bb4de9d215d1}" refers to invalid object "C:\WINDOWS\SYSTEM\UPNPUI.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{094814A2-7208-11d3-B30A-444553540001}" refers to invalid object "C:\WINDOWS\SYSTEM\WMPCORE.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{A175B891-3967-4554-8FBE-D2E1D9CD6E09}" refers to invalid object "C:\WINDOWS\SYSTEM\WMPCORE.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{6EB7F411-1AF7-11d3-BD41-00C04F67F69A}" refers to invalid object "C:\WINDOWS\SYSTEM\WMPUI.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{E8C2EE14-CAA0-11d2-B3FC-00C04F6EA46A}" refers to invalid object "C:\WINDOWS\SYSTEM\WMPUI.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{20291AC1-5931-11d2-A521-00A0D10129C0}" refers to invalid object "C:\WINDOWS\SYSTEM\WMPUI.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{76B53EF2-4ACC-404c-B869-3878120C3A68}" refers to invalid object "C:\WINDOWS\SYSTEM\WMPUI.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{1677bd28-d0d8-11d2-83b5-00c04f8edcc4}" refers to invalid object "C:\WINDOWS\SYSTEM\WMPUI.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{513148E2-7F51-4301-BF6B-1CAE2958BC54}" refers to invalid object "C:\WINDOWS\SYSTEM\WMPUI.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{D92319FA-0975-11D3-83D0-00C04F8EDCC4}" refers to invalid object "C:\WINDOWS\SYSTEM\WMPUI.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{CBA27036-DF06-44EA-BD80-AFE9F671CB76}" refers to invalid object "C:\WINDOWS\SYSTEM\WMPUI.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{E8C2EE18-CAA0-11D2-B3FC-00C04F6EA46A}" refers to invalid object "C:\WINDOWS\SYSTEM\WMPUI.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{20291AC2-5931-11D2-A521-00A0D10129C0}" refers to invalid object "C:\WINDOWS\SYSTEM\WMPUI.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{BB7DF450-F119-11CD-8465-00AA00425D90}" refers to invalid object "C:\Program Files\Microsoft Office\Office\". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{64BDA9B0-BE18-11CE-B46C-0020AF3F4639}" refers to invalid object "C:\PROGRAM FILES\HOSTEXPLORER.95\hTelnet.exe". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{DE39AEC4-3D73-11D0-8E0F-00A0240B2FE9}" refers to invalid object "C:\WINDOWS\SYSTEM\HUMMBIRD\RSHCTRL.OCX". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{DE39AEC7-3D73-11D0-8E0F-00A0240B2FE9}" refers to invalid object "C:\WINDOWS\SYSTEM\HUMMBIRD\RSHCTRL.OCX". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{DE39AED4-3D73-11D0-8E0F-00A0240B2FE9}" refers to invalid object "C:\WINDOWS\SYSTEM\HUMMBIRD\RSHCTRL.OCX". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{DE77BF00-66E4-11CF-AFC8-0020AFCEC901}" refers to invalid object "C:\PROGRAM FILES\HOSTEXPLORER.95\UUCOMP.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{D9A4C920-6AD4-11CF-AFC8-0020AFCEC901}" refers to invalid object "C:\PROGRAM FILES\HOSTEXPLORER.95\ZCOMP.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{82D47FC0-6776-11CF-AFC8-0020AFCEC901}" refers to invalid object "C:\PROGRAM FILES\HOSTEXPLORER.95\GZCOMP.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{D686594D-14EC-11cf-85D5-CA182533E812}" refers to invalid object "C:\PROGRAM FILES\HOSTEXPLORER.95\HOSTEX32.EXE /Automation". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{DB8DC413-C0AA-11D0-9545-080009B1C2F3}" refers to invalid object "C:\Program Files\HostExplorer.95\HESHELL.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{557A2053-A3C0-11D1-954B-0060089164DD}" refers to invalid object "C:\PROGRA~1\HOSTEX~1.95\HEFTPXFR.EXE". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{F23F7616-07BC-11D2-BEFD-004F490328D8}" refers to invalid object "C:\PROGRA~1\HOSTEX~1.95\HNSYNCH.EXE". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{B8E71371-F7F7-11D2-A2CE-0060B0FB9D0D}" refers to invalid object "C:\PROGRAM FILES\NETSCAPE\COMMUNICATOR\AOL\CDTOOL.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{8f7261d0-d2b9-11d2-9909-00605205b24c}" refers to invalid object "C:\Program Files\GlobalSCAPE\CuteFTP\CuteShell.dll". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{2F25CF20-C569-11D1-B94C-00608CB45480}" refers to invalid object "C:\PROGRAM FILES\TEXTPAD 4\System\shellext.dll". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{D3168A01-3A45-11d3-A043-00105ACD6E0E}" refers to invalid object "C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVRESC.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{D3168A02-3A45-11d3-A043-00105ACD6E0E}" refers to invalid object "C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVRESC.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{C1A8AF25-1257-101B-8FB0-0020AF039CA3}" refers to invalid object "E:\PROGRAM\32\MCI32.OCX". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{1EFD6A40-3999-11CF-9150-00AA0059F70D}" refers to invalid object "E:\PROGRAM\32\MCI32.OCX". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{3775D2E0-7C5D-11CF-899E-00AA00688B10}" refers to invalid object "E:\PROGRAM\32\MCI32.OCX". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{0D4C11A1-6BD0-11D3-B542-00902771A435}" refers to invalid object "C:\PROGRA~1\SYMANTEC\LIVEUP~1\LUCOMS~1.EXE". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{0D4C11A3-6BD0-11D3-B542-00902771A435}" refers to invalid object "C:\PROGRA~1\SYMANTEC\LIVEUP~1\LUCOMS~1.EXE". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{FE207EB8-122B-11D3-B527-00902771A435}" refers to invalid object "C:\PROGRA~1\SYMANTEC\LIVEUP~1\LUCOMS~1.EXE". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{2B83B324-49FD-11D3-B538-00902771A435}" refers to invalid object "C:\PROGRA~1\SYMANTEC\LIVEUP~1\LUCOMS~1.EXE". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{C10E2CC6-1525-11D3-B527-00902771A435}" refers to invalid object "C:\PROGRA~1\SYMANTEC\LIVEUP~1\LUCOMS~1.EXE". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{0A577C17-24F8-11D3-B530-00902771A435}" refers to invalid object "C:\PROGRA~1\SYMANTEC\LIVEUP~1\LUCOMS~1.EXE". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{0A577C19-24F8-11D3-B530-00902771A435}" refers to invalid object "C:\PROGRA~1\SYMANTEC\LIVEUP~1\LUCOMS~1.EXE". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{72C27151-4478-11D3-B537-00902771A435}" refers to invalid object "C:\PROGRA~1\SYMANTEC\LIVEUP~1\LUCOMS~1.EXE". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{F8E2BDBE-5723-11D3-B53D-00902771A435}" refers to invalid object "C:\PROGRA~1\SYMANTEC\LIVEUP~1\LUCOMS~1.EXE". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{2C5B6502-5731-11D3-B53D-00902771A435}" refers to invalid object "C:\PROGRA~1\SYMANTEC\LIVEUP~1\LUCOMS~1.EXE". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{03E0E6C2-363B-11D3-B536-00902771A435}" refers to invalid object "C:\PROGRA~1\SYMANTEC\LIVEUP~1\LUCOMS~1.EXE". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{87D37EC8-8342-11D3-B54C-00902771A435}" refers to invalid object "C:\PROGRA~1\SYMANTEC\LIVEUP~1\LUCOMS~1.EXE". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{0ED40801-D38D-11D3-B562-00902771A435}" refers to invalid object "C:\PROGRA~1\SYMANTEC\LIVEUP~1\LUCOMS~1.EXE". Action Taken: No Action Taken.

  3. #13
    Draco is offline Full Member
    MWAV Part 2:

    Entry "HKCR\CLSID\{72C2714F-4478-11D3-B537-00902771A435}" refers to invalid object "C:\PROGRA~1\SYMANTEC\LIVEUP~1\LUCOMS~1.EXE". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{1132C0A0-65F7-11CF-8627-00C06C256781}" refers to invalid object "C:\PROGRA~1\NEWSOFT\PRESTO~1.2\PEXPLORE.EXE". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{3A84503E-0A08-11D3-831F-00104B63E709}" refers to invalid object "C:\PROGRA~1\HOSTEX~1.95\HEMLIB.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{C7B3087F-E999-11D1-B0D1-006008914D5A}" refers to invalid object "C:\PROGRA~1\HOSTEX~1.95\HCLFTPOA.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{C7B30881-E999-11D1-B0D1-006008914D5A}" refers to invalid object "C:\PROGRA~1\HOSTEX~1.95\HCLFTPOA.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{C7B30883-E999-11D1-B0D1-006008914D5A}" refers to invalid object "C:\PROGRA~1\HOSTEX~1.95\HCLFTPOA.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{EB7558D2-F0B0-11D1-B0D1-006008914D5A}" refers to invalid object "C:\PROGRA~1\HOSTEX~1.95\HCLFTPOA.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{C7B75761-20D4-11D2-B0E6-006008914D5A}" refers to invalid object "C:\PROGRA~1\HOSTEX~1.95\HCLFTPOA.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{098119EF-E5DD-11D1-956D-0060089164DD}" refers to invalid object "C:\PROGRA~1\HOSTEX~1.95\HNCOMLIB.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{E8599914-2ACC-11D2-9582-0060089164DD}" refers to invalid object "C:\PROGRA~1\HOSTEX~1.95\FTPSEUI.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{C7F30E66-CEED-11D1-955B-F01FD3000000}" refers to invalid object "C:\PROGRA~1\HOSTEX~1.95\FTPSEUI.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{D78A7B12-A7AC-11D1-954C-0060089164DD}" refers to invalid object "C:\PROGRA~1\HOSTEX~1.95\FTPSEUI.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{2286B8D4-A6DF-11D1-954C-0060089164DD}" refers to invalid object "C:\PROGRA~1\HOSTEX~1.95\FTPSEUI.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{C9028DD4-9AC8-11D1-BEA9-004F490328D8}" refers to invalid object "C:\PROGRA~1\HOSTEX~1.95\FTPSEUI.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{280F9C31-9A54-11D1-BEA9-004F490328D8}" refers to invalid object "C:\PROGRA~1\HOSTEX~1.95\FTPSEUI.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{280F9C2E-9A54-11D1-BEA9-004F490328D8}" refers to invalid object "C:\PROGRA~1\HOSTEX~1.95\FTPSEUI.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{280F9C2B-9A54-11D1-BEA9-004F490328D8}" refers to invalid object "C:\PROGRA~1\HOSTEX~1.95\FTPSEUI.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{280F9C28-9A54-11D1-BEA9-004F490328D8}" refers to invalid object "C:\PROGRA~1\HOSTEX~1.95\FTPSEUI.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{56336BCA-3D8A-11d6-A00B-0050DA18DE71}" refers to invalid object "C:\WINDOWS\TEMP\INFOWINDOW.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{49707377-6974-6368-2E4A-756E6F644A02}" refers to invalid object "C:\PROGRAM FILES\WS_FTP PRO\NSFTPCH.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{C5271D66-CA03-4d51-B035-3E8AFA1EFB76}" refers to invalid object "C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVRESC.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" refers to invalid object "C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.3000.1001\EN-US\MSNTB.DLL". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{CE42CFF4-B402-757F-1745-318EC45C9853}" refers to invalid object "C:\WINDOWS\SYSTEM\SYSJJ32.EXE". Action Taken: No Action Taken.
    Entry "HKCR\CLSID\{5A301518-1F19-3BCA-7626-2B5A22CDEDD4}" refers to invalid object "C:\WINDOWS\SYSTEM\IEUF32.EXE". Action Taken: No Action Taken.
    Entry "HKCR\TypeLib\{60ED65E7-1B7F-11D3-B14E-00C04F79FAA6}" refers to invalid object "C:\WINDOWS\SYSTEM\WMPCORE.DLL". Action Taken: No Action Taken.
    Entry "HKCR\TypeLib\{FA50E692-0E38-11D3-A1D0-005004602752}" refers to invalid object "C:\WINDOWS\SYSTEM\WMPUI.DLL". Action Taken: No Action Taken.
    Entry "HKCR\TypeLib\{C1A8AF28-1257-101B-8FB0-0020AF039CA3}" refers to invalid object "E:\PROGRAM\32\MCI32.OCX". Action Taken: No Action Taken.
    Entry "HKCR\TypeLib\{51B9BCA6-4A06-11D3-B538-00902771A435}" refers to invalid object "C:\PROGRAM FILES\SYMANTEC\LIVEUPDATE\LUCOMSERVER.EXE". Action Taken: No Action Taken.
    Entry "HKCR\TypeLib\{3A845030-0A08-11D3-831F-00104B63E709}" refers to invalid object "C:\PROGRAM FILES\HOSTEXPLORER.95\HEMLIB.DLL". Action Taken: No Action Taken.
    Entry "HKCR\TypeLib\{098119E1-E5DD-11D1-956D-0060089164DD}" refers to invalid object "C:\PROGRAM FILES\HOSTEXPLORER.95\HNCOMLIB.DLL". Action Taken: No Action Taken.
    Entry "HKCR\TypeLib\{280F9C19-9A54-11D1-BEA9-004F490328D8}" refers to invalid object "C:\PROGRAM FILES\HOSTEXPLORER.95\FTPSEUI.DLL". Action Taken: No Action Taken.
    Entry "HKCR\TypeLib\{C7B30871-E999-11D1-B0D1-006008914D5A}" refers to invalid object "C:\PROGRAM FILES\HOSTEXPLORER.95\HCLFTPOA.DLL". Action Taken: No Action Taken.
    Entry "HKCR\TypeLib\{DE39AEC4-3D73-11D0-8E0F-00A0240B2FE9}" refers to invalid object "C:\WINDOWS\SYSTEM\HUMMBIRD\RSHCTRL.OCX". Action Taken: No Action Taken.
    Entry "HKCR\TypeLib\{3B029EA5-5642-11D3-88D2-00104B1F3A1E}" refers to invalid object "C:\WINDOWS\SYSTEM\C1U2.DLL". Action Taken: No Action Taken.
    Entry "HKCR\TypeLib\{C2F46CF0-50B9-11D3-88CB-00104B1F3A1E}" refers to invalid object "C:\WINDOWS\SYSTEM\GLIDLIST.DLL". Action Taken: No Action Taken.
    Entry "HKCR\TypeLib\{B8E71363-F7F7-11D2-A2CE-0060B0FB9D0D}" refers to invalid object "C:\PROGRAM FILES\NETSCAPE\COMMUNICATOR\AOL\CDTOOL.DLL". Action Taken: No Action Taken.
    Entry "HKCR\TypeLib\{5051C3C9-A921-4022-BEA6-E799E92B2816}" refers to invalid object "C:\WINDOWS\TEMP\Word8.0\MSForms.exd". Action Taken: No Action Taken.
    Entry "HKCR\TypeLib\{DC576793-75BE-423A-9220-3CEF4524528D}" refers to invalid object "C:\WINDOWS\TEMP\Word8.0\MARQUEELib.exd". Action Taken: No Action Taken.
    Entry "HKCR\TypeLib\{3EE88A1F-B8CC-45B9-B2AF-6CFB9D19218E}" refers to invalid object "C:\PROGRA~1\3721\CES\cesmain.dll". Action Taken: No Action Taken.
    Entry "HKCR\TypeLib\{7AF322C5-AB43-11D4-A00B-0050DA18DE71}" refers to invalid object "C:\WINDOWS\TEMP\INFOWINDOW.DLL". Action Taken: No Action Taken.
    Entry "HKCR\TypeLib\{502E11E3-F8D0-4C9A-925E-F9C4BFFF85F1}" refers to invalid object "C:\WINDOWS\TEMP\Excel8.0\MSForms.exd". Action Taken: No Action Taken.
    Entry "HKCR\TypeLib\{F99FACB3-1C20-47E7-8616-8EBE2D0BE95E}" refers to invalid object "C:\WINDOWS\TEMP\Word8.0\MSForms.exd". Action Taken: No Action Taken.
    Entry "HKCR\mailto\shell\open\command" refers to invalid object "C:\AMERIC~1.0AP\aol.exe -u"%1"". Action Taken: No Action Taken.
    Entry "HKCR\Plenoptic.Plenoptic.1" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken.
    Entry "HKCR\Plenoptic.Plenoptic" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken.
    Entry "HKCR\WMDMPDAExplorer.WMDMPDAExplorer.1" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.
    Entry "HKCR\WMDMPDAExplorer.WMDMPDAExplorer" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.
    Entry "HKCR\.vir" refers to invalid object "virfile". Action Taken: No Action Taken.
    Entry "HKCR\.nlu" refers to invalid object "NavLuFile". Action Taken: No Action Taken.
    Entry "HKCR\.aw" refers to invalid object "AWFile". Action Taken: No Action Taken.
    Entry "HKCR\.col" refers to invalid object "COLFile". Action Taken: No Action Taken.
    Entry "HKCR\.elm" refers to invalid object "ELMFile". Action Taken: No Action Taken.
    Entry "HKCR\.ffa" refers to invalid object "FFAFile". Action Taken: No Action Taken.
    Entry "HKCR\.ffl" refers to invalid object "FFLFile". Action Taken: No Action Taken.
    Entry "HKCR\.fft" refers to invalid object "FFTFile". Action Taken: No Action Taken.
    Entry "HKCR\.ffx" refers to invalid object "FFXFile". Action Taken: No Action Taken.
    Entry "HKCR\.lex" refers to invalid object "LEXFile". Action Taken: No Action Taken.
    Entry "HKCR\.opc" refers to invalid object "OPCFile". Action Taken: No Action Taken.
    Entry "HKCR\.stf" refers to invalid object "STFFile". Action Taken: No Action Taken.
    Entry "HKCR\.tuw" refers to invalid object "TUWFile". Action Taken: No Action Taken.
    Entry "HKCR\.wll" refers to invalid object "Word.Addin.8". Action Taken: No Action Taken.
    Entry "HKCR\Automap.Map.NA.8" refers to invalid object "{A49EEA00-9231-4C77-AA9E-2F89D72B4804}". Action Taken: No Action Taken.
    Entry "HKCR\Automap.Map.NA" refers to invalid object "{A49EEA00-9231-4C77-AA9E-2F89D72B4804}". Action Taken: No Action Taken.
    Entry "HKCR\Automap.Template.NA.8" refers to invalid object "{A49EEA00-9231-4C77-AA9E-2F89D72B4804}". Action Taken: No Action Taken.
    Entry "HKCR\aol\shell\open\command" refers to invalid object "C:\America Online 5.0aq\aol.exe -u"%1"". Action Taken: No Action Taken.
    Entry "HKCR\.det" refers to invalid object "DETFile". Action Taken: No Action Taken.
    Entry "HKCR\.frg" refers to invalid object "Access.Fragment". Action Taken: No Action Taken.
    Entry "HKCR\.gst" refers to invalid object "MSMap.Datainst.8". Action Taken: No Action Taken.
    Entry "HKCR\.ldb" refers to invalid object "Access.LockFile.9". Action Taken: No Action Taken.
    Entry "HKCR\.pcb" refers to invalid object "PCBFile". Action Taken: No Action Taken.
    Entry "HKCR\.SC2" refers to invalid object "SchedulePlus.Application.7". Action Taken: No Action Taken.
    Entry "HKCR\.SCD" refers to invalid object "SchedulePlus.Application.7". Action Taken: No Action Taken.
    Entry "HKCR\.SCH" refers to invalid object "SchedulePlus.Application.7". Action Taken: No Action Taken.
    Entry "HKCR\.sll" refers to invalid object "SSLFile". Action Taken: No Action Taken.
    Entry "HKCR\mapifvbx.object" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.
    Entry "HKCR\mapifvbx.object.1" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.
    Entry "HKCR\MailFileAtt" refers to invalid object "{00020D05-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
    Entry "HKCR\ActMsg.Session" refers to invalid object "{3FA7DEB3-6438-101B-ACC1-00AA00423326}". Action Taken: No Action Taken.
    Entry "HKCR\hclebasics\shell\open\command" refers to invalid object ""C:\Program Files\HostExplorer.95\ebasic.exe" "%1"". Action Taken: No Action Taken.
    Entry "HKCR\hclebasich\shell\open\command" refers to invalid object ""C:\Program Files\HostExplorer.95\ebasic.exe" "%1"". Action Taken: No Action Taken.
    Entry "HKCR\hclebrun\shell\open\command" refers to invalid object ""C:\Program Files\HostExplorer.95\ebrun.exe" "%1"". Action Taken: No Action Taken.
    Entry "HKCR\Hummingbird.WyseTerm\shell\open\command" refers to invalid object ""C:\PROGRAM FILES\HOSTEXPLORER.95\hTelnet.exe" @"%1"". Action Taken: No Action Taken.
    Entry "HKCR\HostExplorer.SessionProfile\shell\open\comma nd" refers to invalid object "C:\PROGRA~1\HOSTEX~1.95\HOSTEX32.EXE -p%1". Action Taken: No Action Taken.
    Entry "HKCR\PrintExplorer.SessionProfile\shell\open\comm and" refers to invalid object "C:\PROGRA~1\HOSTEX~1.95\HOSTPR32.EXE -p%1". Action Taken: No Action Taken.
    Entry "HKCR\Ipswitch.WSFTPStub" refers to invalid object "{49707377-6974-6368-2E4A-756E6F644A0A}". Action Taken: No Action Taken.
    Entry "HKCR\Ipswitch.WSFTPStub.981012" refers to invalid object "{49707377-6974-6368-2E4A-756E6F644A0A}". Action Taken: No Action Taken.
    Entry "HKCR\Ipswitch.NSFTP" refers to invalid object "{49707377-6974-6368-2E4A-756E6F644A01}". Action Taken: No Action Taken.
    Entry "HKCR\Ipswitch.NSFTP.20000920" refers to invalid object "{49707377-6974-6368-2E4A-756E6F644A01}". Action Taken: No Action Taken.
    Entry "HKCR\C1u2.Transfer.1" refers to invalid object "{11694C55-5706-11D3-88D3-00104B1F3A1E}". Action Taken: No Action Taken.
    Entry "HKCR\C1u2.Transfer" refers to invalid object "{11694C55-5706-11D3-88D3-00104B1F3A1E}". Action Taken: No Action Taken.
    Entry "HKCR\CoExist2.CoExist2.1" refers to invalid object "{28034321-6B7C-11D3-88E9-00104B1F3A1E}". Action Taken: No Action Taken.
    Entry "HKCR\CoExist2.CoExist2" refers to invalid object "{28034321-6B7C-11D3-88E9-00104B1F3A1E}". Action Taken: No Action Taken.
    Entry "HKCR\GLIDList.IDList.1" refers to invalid object "{C2F46CFE-50B9-11D3-88CB-00104B1F3A1E}". Action Taken: No Action Taken.
    Entry "HKCR\GLIDList.IDList" refers to invalid object "{C2F46CFE-50B9-11D3-88CB-00104B1F3A1E}". Action Taken: No Action Taken.
    Entry "HKCR\Iscon.iscon.1" refers to invalid object "{119CA12F-ED48-4B02-8C44-DC30FD808776}". Action Taken: No Action Taken.
    Entry "HKCR\Iscon.iscon" refers to invalid object "{119CA12F-ED48-4B02-8C44-DC30FD808776}". Action Taken: No Action Taken.
    Entry "HKCR\CuteFTP.Queue\shell\open\command" refers to invalid object "C:\PROGRAM FILES\GLOBALSCAPE\CUTEFTP\CUTFTP32.EXE QueueFile=%1". Action Taken: No Action Taken.
    Entry "HKCR\CuteFTP.Script\shell\open\command" refers to invalid object "C:\PROGRAM FILES\GLOBALSCAPE\CUTEFTP\CUTFTP32.EXE Macro=%1". Action Taken: No Action Taken.
    Entry "HKCR\SpruceDVDPlay.Document\shell\open\comman d" refers to invalid object "E:\IVI\WINDVD\SYZYGY.EXE "%1"". Action Taken: No Action Taken.
    Entry "HKCR\2_auto_file\shell\open\command" refers to invalid object "A:\MTW5.2 %1". Action Taken: No Action Taken.
    Entry "HKCR\.idc" refers to invalid object "idcfile". Action Taken: No Action Taken.
    Entry "HKCR\TextPad\shell\open\command" refers to invalid object "C:\PROGRA~1\TEXTPA~1\TEXTPAD.EXE -s". Action Taken: No Action Taken.
    Entry "HKCR\TextPad.tws\shell\open\command" refers to invalid object "C:\PROGRAM FILES\TEXTPAD 4\TEXTPAD.EXE -s". Action Taken: No Action Taken.
    Entry "HKCR\zTree.Treatment\shell\open\command" refers to invalid object "C:\TEMP\ZTREE.EXE "%1"". Action Taken: No Action Taken.
    Entry "HKCR\zTree.Questionnaire\shell\open\command" refers to invalid object "C:\TEMP\ZTREE.EXE "%1"". Action Taken: No Action Taken.
    Entry "HKCR\.fhf\shell\open\command" refers to invalid object "C:\PROGRAM FILES\WS_FTP PRO\wsftppro.exe -h "%1"". Action Taken: No Action Taken.

  4. #14
    Neal is offline Dedicated Member
    Nothing showing but a couple of activex that can be deleted if you want.


    C:\WINDOWS\Downloaded Program Files\ISTactivex.dll
    C:\WINDOWS\Downloaded Program Files\WinServAdX.dll

    Spybot may be picking up a harmless registry entry that is clutter or something in a temp folder

    Have you tried running spybot since CCleaner.

    As far as i am concerned you are clean.

    Let me know after new scan with spybot

  5. #15
    Draco is offline Full Member
    Thanks Neal.

    The funny thing is, I don't have either of those controls in that folder. In fact, the only non-antiMalware object I have in that folder is the "Shockwave Flash object". Does that make sense? Why would they show in my log?

    I've actually been running Spybot after every step you've told me and it always finds Winpup.

    Should we let this go? Thanks for everything.

  6. #16
    VopThis is offline Senior Member (Canada)
    Try dealing with the remaining items, as follows:


    * Please download the Killbox by Option^Explicit. *In the event you already have Killbox, make sure that you have this new version.

    * Save it to your desktop.

    * Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C

    C:\WINDOWS\Downloaded Program Files\ISTactivex.dll
    C:\WINDOWS\Downloaded Program Files\WinServAdX.dll

    * Please double-click Killbox.exe to run it.

    * Select "Delete on Reboot".

    * Go to the KillboxFile menu, and choose "Paste from Clipboard".

    * Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

    If your computer does not restart automatically, please restart it manually.

  7. #17
    Draco is offline Full Member
    Hi VopThis,

    I tried Killbox, but it doesn't respond well. For example, nothing happens when I choose paste from the clipboard from the file menu. So I tried 1 file, then I hit the red X and nothing happenned. It says below I would be prompted.

    Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

    Thanks.

  8. #18
    VopThis is offline Senior Member (Canada)
    nothing happens when I choose paste from the clipboard from the file menu
    That means that the copy sequence did not work - nothing was apparently copied to the 'clipboard'.


    Open up Notepad or other text editor.
    Highlight those two (2) files (that area should now be painted in blue).
    Right click on that highlighted area and select Copy option.
    Test what is in the 'Clipboard' by doing a paste operation (right click>paste) in Notepad (or other app).
    If that copy sequence works, then re-try the Killbox instructions.

  9. #19
    Draco is offline Full Member
    Hey VopThis,

    I was already trying the same drill with notepad that you are suggesting last night. It didn't work then and its not working now. I'm sure the data is on the clipboard.

    Also, shouldn't I be able to just paste one file into the box and delete it? That doesn't work either - nothing happens when I hit the red x.

    I really think its a sw issue (and not pilot error) - I've been able to follow all the instructions given to me so far including the safe mode stuff. Maybe nobody tested killbox with ME?

    Thanks.

  10. #20
    VopThis is offline Senior Member (Canada)
    Save 20% on AVG Internet Security 2012 Suite!
    I'm sure the data is on the clipboard.
    Please verify that your copied stuff is going to the Clipboard by clicking Start, Programs, Accessories, System Tools, and Clipboard Viewer. Potentially, the clipboard has been disabled by spyware.

    Otherwise, can you copy and paste to Notepad? Killbox should work in all flavors of Windows including ME.


    You could try manually typing the lines into Killbox.

    OR

    Use HijackThis (navigate, paste, or type in one line at a time - then reboot for each line entered):


    Run HJT.
    Click 'Open the Misc Tools section'.
    Click 'Delete a file on reboot'. Click the 'Open' button.

    You will now be asked if you would like to reboot your computer to delete the file. Click on the Yes button if you would like to reboot now, otherwise click on the No button to reboot later.

+ Reply to Thread
Page 2 of 3 FirstFirst 1 2 3 LastLast