Thank you. When multiple instructions are posted then you need to follow them in the order given and then post exactly what was done. If recommendation includes updating programs then that must be done and new scans run with those programs and the logs posted. Continually posting logs from out of date programs show nothing really.
jholland1964 650 Posting Expert Team Colleague Featured Poster
sdsurfer 0 Newbie Poster
Here is the DDS log. I was not able to run the ESET. and no Web search files were found.
DDS (Ver_10-03-17.01) - NTFSx86
Run by Alyson at 11:32:48.87 on Sat 05/08/2010
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.502.155 [GMT -7:00]
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRAM FILES\QUICKTIME\QTTASK.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Documents and Settings\Alyson\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.cbssports.com/collegebasketball/teams/page/SYR
uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
uDefault_Page_URL = hxxp://www.dell4me.com/myway
uSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
mDefault_Page_URL = hxxp://www.yahoo.com/
mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll
BHO: Yahooo Search Protection: {25bc7718-0bfa-40ea-b381-4b2d9732d686} - c:\program files\yahoo!\search protection\ysp.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn1\YTSingleInstance.dll
BHO: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No File
TB: {BA52B914-B692-46c4-B683-905236F6F655} - No File
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
EB: &Yahoo! Messenger: {4528bbe0-4e08-11d5-ad55-00010333d0ad} - c:\progra~1\yahoo!\common\yhexbmesus.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [Search Protection] c:\program files\yahoo!\search protection\SearchProtection.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [PCMService] "c:\program files\dell\media experience\PCMService.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [IntelMeM] c:\program files\intel\modem event monitor\IntelMEM.exe
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [Dell AIO Printer A920] "c:\program files\dell aio printer a920\dlbkbmgr.exe"
mRun: [Microsoft Works Update Detection] c:\program files\common files\microsoft shared\works shared\WkUFind.exe
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTASK.EXE" -atboottime
dRunOnce: [RunNarrator] Narrator.exe
StartupFolder: c:\docume~1\alyson\startm~1\programs\startup\limewi~1.lnk - c:\program files\limewire\LimeWire.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\1.0.150\SSScheduler.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {BBF74FB9-ABCD-4678-880A-2511DAABB5E1} - {25BC7718-0BFA-40EA-B381-4B2D9732D686} - c:\program files\yahoo!\search protection\ysp.dll
Trusted Zone: musicmatch.com\online
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1005.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} - hxxp://web1.shutterfly.com/downloads/Uploader.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-8-1 11608]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-6 68168]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-8-1 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-8-1 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-8-1 56816]
S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\tffsmon.sys --> c:\windows\system32\drivers\TfFsMon.sys [?]
S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\tfsysmon.sys --> c:\windows\system32\drivers\TfSysMon.sys [?]
S3 DCamUSBVeo532;Veo Stingray/Connect Web Camera;c:\windows\system32\drivers\ubVeo532.sys [2002-7-1 95232]
S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\tfnetmon.sys --> c:\windows\system32\drivers\TfNetMon.sys [?]
=============== Created Last 30 ================
2010-05-08 05:54:02 0 d-----w- c:\program files\common files\Wise Installation Wizard
2010-04-25 18:45:27 0 d-----w- c:\docume~1\alluse~1\applic~1\avG
2010-04-25 05:16:54 1103 --sha-w- c:\windows\system32\883584322
2010-04-25 05:16:53 817 ----a-w- c:\windows\system32\1694121234
2010-04-25 05:16:14 113 ----a-w- c:\windows\system32\sl1431044048
2010-04-25 05:15:59 203776 --sh--w- c:\windows\system32\unrar.exe
2010-04-25 05:15:59 0 d-----w- c:\windows\system32\1455970933
2010-04-25 05:12:53 0 d-sh--w- C:\found.001
2010-04-17 05:39:52 0 d-----w- c:\program files\Merge
==================== Find3M ====================
2010-05-06 01:14:09 10196 ----a-w- c:\docume~1\alyson\applic~1\wklnhst.dat
2010-04-29 22:39:38 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 22:39:26 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-10 13:18:21 13824 ------w- c:\windows\system32\dllcache\ieudinit.exe
2010-03-10 13:18:20 70656 ------w- c:\windows\system32\dllcache\ie4uinit.exe
2010-03-09 11:09:18 430080 ----a-w- c:\windows\system32\vbscript.dll
2010-03-09 11:09:18 430080 ------w- c:\windows\system32\dllcache\vbscript.dll
2010-02-24 13:11:07 455680 ------w- c:\windows\system32\dllcache\mrxsmb.sys
2010-02-23 05:20:02 634648 ----a-w- c:\windows\system32\dllcache\iexplore.exe
2010-02-23 05:18:28 161792 ------w- c:\windows\system32\dllcache\ieakui.dll
2010-02-17 16:10:28 2189952 ------w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-02-16 14:08:49 2146304 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 14:08:49 2146304 ------w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-02-16 13:25:04 2066816 ------w- c:\windows\system32\dllcache\ntkrnlpa.exe
2010-02-16 13:25:04 2024448 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-16 13:25:04 2024448 ------w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-02-12 04:33:11 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-12 04:33:11 100864 ------w- c:\windows\system32\dllcache\6to4svc.dll
2010-02-11 12:02:15 226880 ------w- c:\windows\system32\dllcache\tcpip6.sys
2006-10-12 07:00:59 475 --sh--w- c:\windows\system32\xptm.dll
2008-10-12 18:03:15 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008101220081013\index.dat
2008-12-24 04:35:48 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008122320081224\index.dat
2009-02-27 05:02:40 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009022620090227\index.dat
2009-04-03 05:20:58 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009040220090403\index.dat
============= FINISH: 11:33:33.65 ===============
sdsurfer 0 Newbie Poster
Attach file
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-03-17.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 3/15/2005 7:29:43 PM
System Uptime: 5/8/2010 10:20:48 AM (1 hours ago)
Motherboard: Dell Inc. | | 0DH682
Processor: Intel(R) Pentium(R) 4 CPU 2.80GHz | Microprocessor | 2793/800mhz
==== Disk Partitions =========================
A: is Removable
C: is FIXED (NTFS) - 34 GiB total, 8.633 GiB free.
D: is CDROM ()
E: is CDROM ()
==== Disabled Device Manager Items =============
Class GUID: {4D36E96C-E325-11CE-BFC1-08002BE10318}
Description: Microsoft Kernel Wave Audio Mixer
Device ID: SW\{B7EAFDC0-A680-11D0-96D8-00AA0051E51D}\{9B365890-165F-11D0-A195-0020AFD156E4}
Manufacturer: Microsoft
Name: Microsoft Kernel Wave Audio Mixer
PNP Device ID: SW\{B7EAFDC0-A680-11D0-96D8-00AA0051E51D}\{9B365890-165F-11D0-A195-0020AFD156E4}
Service: kmixer
==== System Restore Points ===================
RP345: 2/9/2010 2:42:22 PM - Software Distribution Service 3.0
RP346: 2/20/2010 11:58:59 AM - System Checkpoint
RP347: 2/23/2010 3:52:32 PM - Software Distribution Service 3.0
RP348: 2/26/2010 8:06:22 PM - System Checkpoint
RP349: 2/27/2010 7:36:49 AM - Removed Skype™ 4.2
RP350: 2/27/2010 7:39:50 AM - Removed Skype Toolbars
RP351: 3/27/2010 11:18:03 AM - System Checkpoint
RP352: 4/2/2010 11:51:10 AM - System Checkpoint
RP353: 4/6/2010 4:55:56 PM - Software Distribution Service 3.0
RP354: 3/13/2010 10:47:19 AM - System Checkpoint
RP355: 3/15/2010 7:30:44 PM - System Checkpoint
RP356: 3/22/2010 6:48:12 PM - System Checkpoint
RP357: 3/26/2010 1:36:26 PM - System Checkpoint
RP358: 3/31/2010 9:00:20 AM - Software Distribution Service 3.0
RP359: 4/13/2010 2:11:56 PM - Software Distribution Service 3.0
RP360: 4/14/2010 3:31:10 PM - Software Distribution Service 3.0
RP361: 4/16/2010 10:47:32 AM - System Checkpoint
RP362: 4/22/2010 6:17:26 PM - System Checkpoint
RP363: 4/28/2010 6:39:47 PM - System Checkpoint
RP364: 4/30/2010 9:56:11 PM - Software Distribution Service 3.0
RP365: 5/2/2010 10:38:17 AM - System Checkpoint
RP366: 5/5/2010 11:09:26 PM - System Checkpoint
RP367: 5/7/2010 10:52:43 PM - Removed SUPERAntiSpyware Free Edition
RP368: 5/7/2010 10:54:44 PM - Installed SUPERAntiSpyware Free Edition
==== Installed Programs ======================
ABBYY FineReader 5.0 Sprint
Adobe Acrobat - Reader 6.0.2 Update
Adobe Acrobat and Reader 6.0.3 Update
Adobe Download Manager
Adobe Reader 6.0.1
Apple Application Support
Apple Software Update
Ariel's Story Studio
Avira AntiVir Personal - Free Antivirus
DA920EN
Dell AIO Printer A920
Dell Digital Jukebox Driver
Dell Driver Reset Tool
Dell Media Experience
Dell Support Center
Dell System Restore
DellSupport
Disneys Digital Coloring Book Featuring Little Mermaid
Google Earth
Google Toolbar for Internet Explorer
GoToAssist 8.0.0.514
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Intel(R) 537EP V9x DF PCI Modem
Intel(R) Graphics Media Accelerator Driver
Intel(R) PRO Network Adapters and Drivers
Intel(R) PROSet for Wired Connections
Internet Explorer Default Page
iTunes
Jasc Paint Shop Photo Album
Jasc Paint Shop Pro 8 Dell Edition
Java(TM) 6 Update 17
LimeWire 4.18.8
Make A Masterpiece(TM)
Malwarebytes' Anti-Malware
McAfee Security Scan
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Encarta Encyclopedia Standard 2004
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Money 2004
Microsoft Money 2004 System Pack
Microsoft National Language Support Downlevel APIs
Microsoft Picture It! Photo Premium 9
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Silverlight
Microsoft Streets and Trips 2004
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C Runtime
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Word 2002
Microsoft Works
Microsoft Works 2004 Setup Launcher
Microsoft Works Suite Add-in for Microsoft Word
Modem Event Monitor
Modem Helper
Modem On Hold
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Musicmatch® Jukebox
NetZeroInstallers
PowerDVD 5.3
Qualxserve Service Agreement
QuickTime
RealArcade
Samsung USB Driver (MCCI 4.34) WHQL v3.4
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Internet Explorer 7 (KB978207)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB981349)
Sportsbook.com
Sprint music manager
SUPERAntiSpyware Free Edition
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows Internet Explorer 7 (KB980182)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
WebFldrs XP
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Live Sign-in Assistant
Windows Live Upload Tool
Windows Media Format 11 runtime
Windows Media Player 10
Windows Media Player 11
Windows XP Service Pack 3
Yahoo! extras
Yahoo! Internet Mail
Yahoo! Messenger
Yahoo! Search Protection
Yahoo! Software Update
Yahoo! Toolbar
==== Event Viewer Messages From Past Week ========
5/7/2010 10:55:10 PM, error: Service Control Manager [7000] - The SASDIFSV service failed to start due to the following error: The system cannot find the file specified.
5/7/2010 10:52:57 PM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found.
5/7/2010 10:52:51 PM, error: Service Control Manager [7000] - The SASDIFSV service failed to start due to the following error: Cannot create a file when that file already exists.
5/5/2010 8:59:02 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: abp480n5 adpu160m agp440 agpCPQ Aha154x aic78u2 aic78xx AliIde alim1541 amdagp amsint asc asc3350p asc3550 cbidf cd20xrnt CmdIde Cpqarray dac2w2k dac960nt dpti2o hpn i2omp ini910u IntelIde mraid35x perc2 perc2hib ql1080 Ql10wnt ql12160 ql1240 ql1280 sisagp Sparrow symc810 symc8xx sym_hi sym_u3 TfFsMon TfSysMon TosIde ultra viaagp ViaIde
5/5/2010 8:58:46 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume.
5/4/2010 8:48:35 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: TfFsMon TfSysMon
==== End Of File ===========================
sdsurfer 0 Newbie Poster
I hope this helps. Let me know what needs to be done next. Thank you
jholland1964 650 Posting Expert Team Colleague Featured Poster
I hope this helps. Let me know what needs to be done next. Thank you
Well for one thing you need to read and follow what is stated in section
1a in this link http://www.daniweb.com/forums/thread134865.html
I clearly see Limewire running on the system when you did the DDS scan. Obviously leaving your system open to attack. If you don't totally UNINSTALL this program immediately then you can expect no more help or advice from me. It would be pointless.
There is no reason all of this should have gone on for 8 days. If all instructions had been followed there is a good chance it would have been wrapped up in much less time. There is no reason instructions to update programs should have to be repeated, they should be followed immediately.
But now I understand why, P2P is more important to you than cleaning the computer.
sdsurfer 0 Newbie Poster
I have now deleted Limewire. Sorry but I dont know what a P2P is.
jholland1964 650 Posting Expert Team Colleague Featured Poster
I have now deleted Limewire. Sorry but I dont know what a P2P is.
I truly find that extremely hard to believe. If you don't know what it is then why in the world would you have installed the program in the first place...and be running it during the scans?
Limewire didn't install itself, it had to be installed. P2P is short for Peer-to-Peer file sharing. Meaning you are sharing files...usually music, videos, games, etc. with other persons around the world. Generally you don't personally know the other person or where he or she got whatever it is that you are sharing. 9 out of 10 times it refers to sharing files which are paid files with another for free. A violation of copyright laws in many countries and the easiest way to transfer infection from one computer to another.
sdsurfer 0 Newbie Poster
I knew Limewire was on my computer. I use it to download music. I did not know what a P2P was. Sorry for the confusion.
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-08 20:02:07
Windows 5.1.2600 Service Pack 3
Running: vfw28i3g.exe; Driver: C:\DOCUME~1\Alyson\LOCALS~1\Temp\ugtdikoc.sys
---- System - GMER 1.0.15 ----
SSDT F8B7E24E ZwCreateKey
SSDT F8B7E244 ZwCreateThread
SSDT F8B7E253 ZwDeleteKey
SSDT F8B7E25D ZwDeleteValueKey
SSDT F8B7E262 ZwLoadKey
SSDT F8B7E230 ZwOpenProcess
SSDT F8B7E235 ZwOpenThread
SSDT F8B7E26C ZwReplaceKey
SSDT F8B7E267 ZwRestoreKey
SSDT F8B7E258 ZwSetValueKey
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xAA5E4950]
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Fastfat \Fat A933BD20
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Classes\.AKN@ AKN_AUTO
Reg HKLM\SOFTWARE\Classes\.application\bootstrap
Reg HKLM\SOFTWARE\Classes\.application\bootstrap@ bootstrap.application.1
Reg HKLM\SOFTWARE\Classes\.emp@ eMusicPackage
Reg HKLM\SOFTWARE\Classes\.emp@Content Type application/vnd.emusic-emusic_package
Reg HKLM\SOFTWARE\Classes\.eta@ Google Earth.etafile
Reg HKLM\SOFTWARE\Classes\.eta@Content Type application/earthviewer
Reg HKLM\SOFTWARE\Classes\.kml@ Google Earth.kmlfile
Reg HKLM\SOFTWARE\Classes\.kml@Content Type application/vnd.google-earth.kml+xml
Reg HKLM\SOFTWARE\Classes\.kmz@ Google Earth.kmzfile
Reg HKLM\SOFTWARE\Classes\.kmz@Content Type application/vnd.google-earth.kmz
Reg HKLM\SOFTWARE\Classes\.mfp@ MacromediaFlashPaper.MacromediaFlashPaper
Reg HKLM\SOFTWARE\Classes\.mfp@Content Type application/x-shockwave-flash
Reg HKLM\SOFTWARE\Classes\.pps\PersistentHandler
Reg HKLM\SOFTWARE\Classes\.pps\PersistentHandler@ {98de59a0-d175-11cd-a7bd-00006b827d94}
Reg HKLM\SOFTWARE\Classes\.sol@Content Type text/plain
Reg HKLM\SOFTWARE\Classes\.sor@Content Type text/plain
Reg HKLM\SOFTWARE\Classes\.xaml\bootstrap
Reg HKLM\SOFTWARE\Classes\.xaml\bootstrap@ bootstrap.xaml.1
Reg HKLM\SOFTWARE\Classes\.xbap\bootstrap
Reg HKLM\SOFTWARE\Classes\.xbap\bootstrap@ bootstrap.xbap.1
Reg HKLM\SOFTWARE\Classes\.xps\bootstrap
Reg HKLM\SOFTWARE\Classes\.xps\bootstrap@ bootstrap.xps.1
Reg HKLM\SOFTWARE\Classes\.ybm@ ybmfile
Reg HKLM\SOFTWARE\Classes\.ybm@ContentType text/ybm
Reg HKLM\SOFTWARE\Classes\AKN_AUTO\shell
Reg HKLM\SOFTWARE\Classes\AKN_AUTO\shell\open
Reg HKLM\SOFTWARE\Classes\AKN_AUTO\shell\open\command
Reg HKLM\SOFTWARE\Classes\AKN_AUTO\shell\open\command@ "C:\Program Files\Absolute Poker\SkinUpdate.exe" "%1"
Reg HKLM\SOFTWARE\Classes\bootstrap.application@ WinFX Bootstrapper for .application
Reg HKLM\SOFTWARE\Classes\bootstrap.application\CLSID
Reg HKLM\SOFTWARE\Classes\bootstrap.application\CLSID@ {0a402d70-1f10-4ae7-bec9-286a98240695}
Reg HKLM\SOFTWARE\Classes\bootstrap.application\CurVer
Reg HKLM\SOFTWARE\Classes\bootstrap.application\CurVer@ bootstrap.application.1
Reg HKLM\SOFTWARE\Classes\bootstrap.application.1@ WinFX Bootstrapper for .application
Reg HKLM\SOFTWARE\Classes\bootstrap.application.1@DocObject 0
Reg HKLM\SOFTWARE\Classes\bootstrap.application.1\CLSID
Reg HKLM\SOFTWARE\Classes\bootstrap.application.1\CLSID@ {0a402d70-1f10-4ae7-bec9-286a98240695}
Reg HKLM\SOFTWARE\Classes\bootstrap.application.1\DocObject
Reg HKLM\SOFTWARE\Classes\bootstrap.application.1\DocObject@ 0
Reg HKLM\SOFTWARE\Classes\bootstrap.xaml@ WinFX Bootstrapper for .xaml
Reg HKLM\SOFTWARE\Classes\bootstrap.xaml\CLSID
Reg HKLM\SOFTWARE\Classes\bootstrap.xaml\CLSID@ {7210ff00-0bcf-4dba-992a-80f60882922b}
Reg HKLM\SOFTWARE\Classes\bootstrap.xaml\CurVer
Reg HKLM\SOFTWARE\Classes\bootstrap.xaml\CurVer@ bootstrap.xaml.1
Reg HKLM\SOFTWARE\Classes\bootstrap.xaml.1@ WinFX Bootstrapper for .xaml
Reg HKLM\SOFTWARE\Classes\bootstrap.xaml.1@DocObject 0
Reg HKLM\SOFTWARE\Classes\bootstrap.xaml.1\CLSID
Reg HKLM\SOFTWARE\Classes\bootstrap.xaml.1\CLSID@ {7210ff00-0bcf-4dba-992a-80f60882922b}
Reg HKLM\SOFTWARE\Classes\bootstrap.xaml.1\DocObject
Reg HKLM\SOFTWARE\Classes\bootstrap.xaml.1\DocObject@ 0
Reg HKLM\SOFTWARE\Classes\bootstrap.xbap@ WinFX Bootstrapper for .xbap
Reg HKLM\SOFTWARE\Classes\bootstrap.xbap\CLSID
Reg HKLM\SOFTWARE\Classes\bootstrap.xbap\CLSID@ {89f11169-844a-4725-b7a5-c342c50431a7}
Reg HKLM\SOFTWARE\Classes\bootstrap.xbap\CurVer
Reg HKLM\SOFTWARE\Classes\bootstrap.xbap\CurVer@ bootstrap.xbap.1
Reg HKLM\SOFTWARE\Classes\bootstrap.xbap.1@ WinFX Bootstrapper for .xbap
Reg HKLM\SOFTWARE\Classes\bootstrap.xbap.1@DocObject 0
Reg HKLM\SOFTWARE\Classes\bootstrap.xbap.1\CLSID
Reg HKLM\SOFTWARE\Classes\bootstrap.xbap.1\CLSID@ {89f11169-844a-4725-b7a5-c342c50431a7}
Reg HKLM\SOFTWARE\Classes\bootstrap.xbap.1\DocObject
Reg HKLM\SOFTWARE\Classes\bootstrap.xbap.1\DocObject@ 0
Reg HKLM\SOFTWARE\Classes\bootstrap.xps@ WinFX Bootstrapper for .xps
Reg HKLM\SOFTWARE\Classes\bootstrap.xps\CLSID
Reg HKLM\SOFTWARE\Classes\bootstrap.xps\CLSID@ {c18d5e87-12b4-46a3-ae40-67cf39bc6758}
Reg HKLM\SOFTWARE\Classes\bootstrap.xps\CurVer
Reg HKLM\SOFTWARE\Classes\bootstrap.xps\CurVer@ bootstrap.xps.1
Reg HKLM\SOFTWARE\Classes\bootstrap.xps.1@ WinFX Bootstrapper for .xps
Reg HKLM\SOFTWARE\Classes\bootstrap.xps.1@DocObject 0
Reg HKLM\SOFTWARE\Classes\bootstrap.xps.1\CLSID
Reg HKLM\SOFTWARE\Classes\bootstrap.xps.1\CLSID@ {c18d5e87-12b4-46a3-ae40-67cf39bc6758}
Reg HKLM\SOFTWARE\Classes\bootstrap.xps.1\DocObject
Reg HKLM\SOFTWARE\Classes\bootstrap.xps.1\DocObject@ 0
Reg HKLM\SOFTWARE\Classes\callto@ URL: CallTo Protocol
Reg HKLM\SOFTWARE\Classes\callto@URL Protocol
Reg HKLM\SOFTWARE\Classes\callto\DefaultIcon
Reg HKLM\SOFTWARE\Classes\callto\DefaultIcon@ C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
Reg HKLM\SOFTWARE\Classes\callto\shell
Reg HKLM\SOFTWARE\Classes\callto\shell\open
Reg HKLM\SOFTWARE\Classes\callto\shell\open\command
Reg HKLM\SOFTWARE\Classes\callto\shell\open\command@ C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe ymsgr:callto? %1
Reg HKLM\SOFTWARE\Classes\CLSID\{01C82775-0AFA-463E-9870-45E917E2F383}\InprocServer32@ C:\WINDOWS\system32\certmgr32.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{01C82775-0AFA-463E-9870-45E917E2F383}\InprocServer32@ThreadingModel Both
Reg HKLM\SOFTWARE\Classes\CLSID\{36018685-C5B5-9B32-AB55-39A30EA1A452}\InprocServer32@ C:\WINDOWS\system32\wbem\fastprox.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{36018685-C5B5-9B32-AB55-39A30EA1A452}\InprocServer32@ThreadingModel Both
Reg HKLM\SOFTWARE\Classes\CLSID\{EB9A3602-1A27-35A0-22AE-35C6E60CA4B0}\InprocServer32@ThreadingModel Both
Reg HKLM\SOFTWARE\Classes\CLSID\{EB9A3602-1A27-35A0-22AE-35C6E60CA4B0}\InprocServer32@ C:\Program Files\Common Files\Microsoft Shared\Web Folders\VAIDDMGR.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EB9A3602-1A27-35A0-22AE-35C6E60CA4B0}\ProgID@ VAIDDManager.CacheSink.1
Reg HKLM\SOFTWARE\Classes\CLSID\{EB9A3602-1A27-35A0-22AE-35C6E60CA4B0}\Programmable@
Reg HKLM\SOFTWARE\Classes\CLSID\{EB9A3602-1A27-35A0-22AE-35C6E60CA4B0}\TypeLib@ {1C77DBD2-12C2-4086-91C0-A8CF727F7C1C}
Reg HKLM\SOFTWARE\Classes\CLSID\{EB9A3602-1A27-35A0-22AE-35C6E60CA4B0}\VersionIndependentProgID@ VAIDDManager.CacheSink
Reg HKLM\SOFTWARE\Classes\eMusicPackage@ eMusicPackage
Reg HKLM\SOFTWARE\Classes\eMusicPackage\shell
Reg HKLM\SOFTWARE\Classes\eMusicPackage\shell\open
Reg HKLM\SOFTWARE\Classes\eMusicPackage\shell\open\command
Reg HKLM\SOFTWARE\Classes\eMusicPackage\shell\open\command@ "C:\Program Files\eMusic Download Manager\emusic.exe" "%1"
Reg HKLM\SOFTWARE\Classes\Google Earth.etafile@ Google Earth ETA
Reg HKLM\SOFTWARE\Classes\Google Earth.etafile\shell
Reg HKLM\SOFTWARE\Classes\Google Earth.etafile\shell\open
Reg HKLM\SOFTWARE\Classes\Google Earth.etafile\shell\open\command
Reg HKLM\SOFTWARE\Classes\Google Earth.etafile\shell\open\command@ C:\Program Files\Google\Google Earth\googleearth.exe "%1"
Reg HKLM\SOFTWARE\Classes\Google Earth.kmlfile@ Google Earth KML
Reg HKLM\SOFTWARE\Classes\Google Earth.kmlfile@EditFlags 65536
Reg HKLM\SOFTWARE\Classes\Google Earth.kmlfile\DefaultIcon
Reg HKLM\SOFTWARE\Classes\Google Earth.kmlfile\DefaultIcon@ C:\Program Files\Google\Google Earth\kml_file.ico
Reg HKLM\SOFTWARE\Classes\Google Earth.kmlfile\shell
Reg HKLM\SOFTWARE\Classes\Google Earth.kmlfile\shell\open
Reg HKLM\SOFTWARE\Classes\Google Earth.kmlfile\shell\open\command
Reg HKLM\SOFTWARE\Classes\Google Earth.kmlfile\shell\open\command@ C:\Program Files\Google\Google Earth\googleearth.exe "%1"
Reg HKLM\SOFTWARE\Classes\Google Earth.kmlfile\shell\open\command@OldValue
Reg HKLM\SOFTWARE\Classes\Google Earth.kmzfile@ Google Earth KMZ
Reg HKLM\SOFTWARE\Classes\Google Earth.kmzfile@EditFlags 65536
Reg HKLM\SOFTWARE\Classes\Google Earth.kmzfile\DefaultIcon
Reg HKLM\SOFTWARE\Classes\Google Earth.kmzfile\DefaultIcon@ C:\Program Files\Google\Google Earth\kmz_file.ico
Reg HKLM\SOFTWARE\Classes\Google Earth.kmzfile\shell
Reg HKLM\SOFTWARE\Classes\Google Earth.kmzfile\shell\open
Reg HKLM\SOFTWARE\Classes\Google Earth.kmzfile\shell\open\command
Reg HKLM\SOFTWARE\Classes\Google Earth.kmzfile\shell\open\command@ C:\Program Files\Google\Google Earth\googleearth.exe "%1"
Reg HKLM\SOFTWARE\Classes\Google Earth.kmzfile\shell\open\command@OldValue
Reg HKLM\SOFTWARE\Classes\GoogleEarth.AnimationControllerGE@ AnimationControllerGE Class
Reg HKLM\SOFTWARE\Classes\GoogleEarth.AnimationControllerGE\CLSID
Reg HKLM\SOFTWARE\Classes\GoogleEarth.AnimationControllerGE\CLSID@ {1A239250-B650-4B63-B4CF-7FCC4DC07DC6}
Reg HKLM\SOFTWARE\Classes\GoogleEarth.AnimationControllerGE\CurVer
Reg HKLM\SOFTWARE\Classes\GoogleEarth.AnimationControllerGE\CurVer@ GoogleEarth.AnimationControllerGE.1
Reg HKLM\SOFTWARE\Classes\GoogleEarth.AnimationControllerGE.1@ AnimationControllerGE Class
Reg HKLM\SOFTWARE\Classes\GoogleEarth.AnimationControllerGE.1\CLSID
Reg HKLM\SOFTWARE\Classes\GoogleEarth.AnimationControllerGE.1\CLSID@ {1A239250-B650-4B63-B4CF-7FCC4DC07DC6}
Reg HKLM\SOFTWARE\Classes\GoogleEarth.ApplicationGE@ ApplicationGE Class
Reg HKLM\SOFTWARE\Classes\GoogleEarth.ApplicationGE\CLSID
Reg HKLM\SOFTWARE\Classes\GoogleEarth.ApplicationGE\CLSID@ {8097D7E9-DB9E-4AEF-9B28-61D82A1DF784}
Reg HKLM\SOFTWARE\Classes\GoogleEarth.ApplicationGE\CurVer
Reg HKLM\SOFTWARE\Classes\GoogleEarth.ApplicationGE\CurVer@ GoogleEarth.ApplicationGE.1
Reg HKLM\SOFTWARE\Classes\GoogleEarth.ApplicationGE.1@ ApplicationGE Class
Reg HKLM\SOFTWARE\Classes\GoogleEarth.ApplicationGE.1\CLSID
Reg HKLM\SOFTWARE\Classes\GoogleEarth.ApplicationGE.1\CLSID@ {8097D7E9-DB9E-4AEF-9B28-61D82A1DF784}
Reg HKLM\SOFTWARE\Classes\GoogleEarth.CameraInfoGE@ CameraInfoGE Class
Reg HKLM\SOFTWARE\Classes\GoogleEarth.CameraInfoGE\CLSID
Reg HKLM\SOFTWARE\Classes\GoogleEarth.CameraInfoGE\CLSID@ {645EEE5A-BD51-4C05-A6AF-6F2CF8950AAB}
Reg HKLM\SOFTWARE\Classes\GoogleEarth.CameraInfoGE\CurVer
Reg HKLM\SOFTWARE\Classes\GoogleEarth.CameraInfoGE\CurVer@ GoogleEarth.CameraInfoGE.1
Reg HKLM\SOFTWARE\Classes\GoogleEarth.CameraInfoGE.1@ CameraInfoGE Class
Reg HKLM\SOFTWARE\Classes\GoogleEarth.CameraInfoGE.1\CLSID
Reg HKLM\SOFTWARE\Classes\GoogleEarth.CameraInfoGE.1\CLSID@ {645EEE5A-BD51-4C05-A6AF-6F2CF8950AAB}
Reg HKLM\SOFTWARE\Classes\GoogleEarth.FeatureCollectionGE@ FeatureCollectionGE Class
Reg HKLM\SOFTWARE\Classes\GoogleEarth.FeatureCollectionGE\CLSID
Reg HKLM\SOFTWARE\Classes\GoogleEarth.FeatureCollectionGE\CLSID@ {9059C329-4661-49B2-9984-8753C45DB7B9}
Reg HKLM\SOFTWARE\Classes\GoogleEarth.FeatureCollectionGE\CurVer
Reg HKLM\SOFTWARE\Classes\GoogleEarth.FeatureCollectionGE\CurVer@ GoogleEarth.FeatureCollectionGE.1
Reg HKLM\SOFTWARE\Classes\GoogleEarth.FeatureCollectionGE.1@ FeatureCollection Class
Reg HKLM\SOFTWARE\Classes\GoogleEarth.FeatureCollectionGE.1\CLSID
Reg HKLM\SOFTWARE\Classes\GoogleEarth.FeatureCollectionGE.1\CLSID@ {9059C329-4661-49B2-9984-8753C45DB7B9}
Reg HKLM\SOFTWARE\Classes\GoogleEarth.FeatureGE@ FeatureGE Class
Reg HKLM\SOFTWARE\Classes\GoogleEarth.FeatureGE\CLSID
Reg HKLM\SOFTWARE\Classes\GoogleEarth.FeatureGE\CLSID@ {CBD4FB70-F00B-4963-B249-4B056E6A981A}
Reg HKLM\SOFTWARE\Classes\GoogleEarth.FeatureGE\CurVer
Reg HKLM\SOFTWARE\Classes\GoogleEarth.FeatureGE\CurVer@ GoogleEarth.FeatureGE.1
Reg HKLM\SOFTWARE\Classes\GoogleEarth.FeatureGE.1@ FeatureGE Class
Reg HKLM\SOFTWARE\Classes\GoogleEarth.FeatureGE.1\CLSID
Reg HKLM\SOFTWARE\Classes\GoogleEarth.FeatureGE.1\CLSID@ {CBD4FB70-F00B-4963-B249-4B056E6A981A}
Reg HKLM\SOFTWARE\Classes\GoogleEarth.PointOnTerrainGE@ PointOnTerrainGE Class
Reg HKLM\SOFTWARE\Classes\GoogleEarth.PointOnTerrainGE\CLSID
Reg HKLM\SOFTWARE\Classes\GoogleEarth.PointOnTerrainGE\CLSID@ {1796A329-04C1-4C07-B28E-E4A807935C06}
Reg HKLM\SOFTWARE\Classes\GoogleEarth.PointOnTerrainGE\CurVer
Reg HKLM\SOFTWARE\Classes\GoogleEarth.PointOnTerrainGE\CurVer@ GoogleEarth.PointOnTerrainGE.1
Reg HKLM\SOFTWARE\Classes\GoogleEarth.PointOnTerrainGE.1@ PointOnTerrainGE Class
Reg HKLM\SOFTWARE\Classes\GoogleEarth.PointOnTerrainGE.1\CLSID
Reg HKLM\SOFTWARE\Classes\GoogleEarth.PointOnTerrainGE.1\CLSID@ {1796A329-04C1-4C07-B28E-E4A807935C06}
Reg HKLM\SOFTWARE\Classes\GoogleEarth.SearchControllerGE@ SearchControllerGE Class
Reg HKLM\SOFTWARE\Classes\GoogleEarth.SearchControllerGE\CLSID
Reg HKLM\SOFTWARE\Classes\GoogleEarth.SearchControllerGE\CLSID@ {A4F65992-5738-475B-9C16-CF102BCDE153}
Reg HKLM\SOFTWARE\Classes\GoogleEarth.SearchControllerGE\CurVer
Reg HKLM\SOFTWARE\Classes\GoogleEarth.SearchControllerGE\CurVer@ GoogleEarth.SearchControllerGE.1
Reg HKLM\SOFTWARE\Classes\GoogleEarth.SearchControllerGE.1@ SearchControllerGE Class
Reg HKLM\SOFTWARE\Classes\GoogleEarth.SearchControllerGE.1\CLSID
Reg HKLM\SOFTWARE\Classes\GoogleEarth.SearchControllerGE.1\CLSID@ {A4F65992-5738-475B-9C16-CF102BCDE153}
Reg HKLM\SOFTWARE\Classes\GoogleEarth.TimeGE@ TimeGE Class
Reg HKLM\SOFTWARE\Classes\GoogleEarth.TimeGE\CLSID
Reg HKLM\SOFTWARE\Classes\GoogleEarth.TimeGE\CLSID@ {1AEDB68D-18A7-4CA9-B41B-3CE7E59FAB24}
Reg HKLM\SOFTWARE\Classes\GoogleEarth.TimeGE\CurVer
Reg HKLM\SOFTWARE\Classes\GoogleEarth.TimeGE\CurVer@ GoogleEarth.TimeGE.1
Reg HKLM\SOFTWARE\Classes\GoogleEarth.TimeGE.1@ TimeGE Class
Reg HKLM\SOFTWARE\Classes\GoogleEarth.TimeGE.1\CLSID
Reg HKLM\SOFTWARE\Classes\GoogleEarth.TimeGE.1\CLSID@ {1AEDB68D-18A7-4CA9-B41B-3CE7E59FAB24}
Reg HKLM\SOFTWARE\Classes\GoogleEarth.TimeIntervalGE@ TimeIntervalGE Class
Reg HKLM\SOFTWARE\Classes\GoogleEarth.TimeIntervalGE\CLSID
Reg HKLM\SOFTWARE\Classes\GoogleEarth.TimeIntervalGE\CLSID@ {1AEDB68D-18A7-4CA9-B41B-3CE7E59FAB24}
Reg HKLM\SOFTWARE\Classes\GoogleEarth.TimeIntervalGE\CurVer
Reg HKLM\SOFTWARE\Classes\GoogleEarth.TimeIntervalGE\CurVer@ GoogleEarth.TimeIntervalGE.1
Reg HKLM\SOFTWARE\Classes\GoogleEarth.TimeIntervalGE.1@ TimeIntervalGE Class
Reg HKLM\SOFTWARE\Classes\GoogleEarth.TimeIntervalGE.1\CLSID
Reg HKLM\SOFTWARE\Classes\GoogleEarth.TimeIntervalGE.1\CLSID@ {1AEDB68D-18A7-4CA9-B41B-3CE7E59FAB24}
Reg HKLM\SOFTWARE\Classes\GoogleEarth.TourControllerGE@ TourControllerGE Class
Reg HKLM\SOFTWARE\Classes\GoogleEarth.TourControllerGE\CLSID
Reg HKLM\SOFTWARE\Classes\GoogleEarth.TourControllerGE\CLSID@ {77C4C807-E257-43AD-BB3F-7CA88760BD29}
Reg HKLM\SOFTWARE\Classes\GoogleEarth.TourControllerGE\CurVer
Reg HKLM\SOFTWARE\Classes\GoogleEarth.TourControllerGE\CurVer@ GoogleEarth.TourControllerGE.1
Reg HKLM\SOFTWARE\Classes\GoogleEarth.TourControllerGE.1@ TourControllerGE Class
Reg HKLM\SOFTWARE\Classes\GoogleEarth.TourControllerGE.1\CLSID
Reg HKLM\SOFTWARE\Classes\GoogleEarth.TourControllerGE.1\CLSID@ {77C4C807-E257-43AD-BB3F-7CA88760BD29}
Reg HKLM\SOFTWARE\Classes\GoogleEarth.ViewExtentsGE@ ViewExtentsGE Class
Reg HKLM\SOFTWARE\Classes\GoogleEarth.ViewExtentsGE\CLSID
Reg HKLM\SOFTWARE\Classes\GoogleEarth.ViewExtentsGE\CLSID@ {D93BF052-FC68-4DB6-A4F8-A4DC9BEEB1C0}
Reg HKLM\SOFTWARE\Classes\GoogleEarth.ViewExtentsGE\CurVer
Reg HKLM\SOFTWARE\Classes\GoogleEarth.ViewExtentsGE\CurVer@ GoogleEarth.ViewExtentsGE.1
Reg HKLM\SOFTWARE\Classes\GoogleEarth.ViewExtentsGE.1@ ViewExtentsGE Class
Reg HKLM\SOFTWARE\Classes\GoogleEarth.ViewExtentsGE.1\CLSID
Reg HKLM\SOFTWARE\Classes\GoogleEarth.ViewExtentsGE.1\CLSID@ {D93BF052-FC68-4DB6-A4F8-A4DC9BEEB1C0}
Reg HKLM\SOFTWARE\Classes\GUSchedulerCtl.UpdaterScheduler@ Google Updater Scheduler class
Reg HKLM\SOFTWARE\Classes\GUSchedulerCtl.UpdaterScheduler\CLSID
Reg HKLM\SOFTWARE\Classes\GUSchedulerCtl.UpdaterScheduler\CLSID@ {B53B7061-6584-46AA-A033-D610EB10BD9B}
Reg HKLM\SOFTWARE\Classes\GUSchedulerCtl.UpdaterScheduler\CurVer
Reg HKLM\SOFTWARE\Classes\GUSchedulerCtl.UpdaterScheduler\CurVer@ GUSchedulerCtl.UpdaterScheduler.1
Reg HKLM\SOFTWARE\Classes\GUSchedulerCtl.UpdaterScheduler.1@ Google Updater Scheduler class
Reg HKLM\SOFTWARE\Classes\GUSchedulerCtl.UpdaterScheduler.1\CLSID
Reg HKLM\SOFTWARE\Classes\GUSchedulerCtl.UpdaterScheduler.1\CLSID@ {B53B7061-6584-46AA-A033-D610EB10BD9B}
Reg HKLM\SOFTWARE\Classes\GUServiceCtl.SilentUpdater@ Google Silent Updater class
Reg HKLM\SOFTWARE\Classes\GUServiceCtl.SilentUpdater\CLSID
Reg HKLM\SOFTWARE\Classes\GUServiceCtl.SilentUpdater\CLSID@ {89DAE4CD-9F17-4980-902A-99BA84A8F5C8}
Reg HKLM\SOFTWARE\Classes\GUServiceCtl.SilentUpdater\CurVer
Reg HKLM\SOFTWARE\Classes\GUServiceCtl.SilentUpdater\CurVer@ GUServiceCtl.SilentUpdater.1
Reg HKLM\SOFTWARE\Classes\GUServiceCtl.SilentUpdater.1@ Google Silent Updater class
Reg HKLM\SOFTWARE\Classes\GUServiceCtl.SilentUpdater.1\CLSID
Reg HKLM\SOFTWARE\Classes\GUServiceCtl.SilentUpdater.1\CLSID@ {89DAE4CD-9F17-4980-902A-99BA84A8F5C8}
Reg HKLM\SOFTWARE\Classes\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}\ProxyStubClsid@ {00020424-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}\ProxyStubClsid32@ {00020424-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}\TypeLib@ {E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}
Reg HKLM\SOFTWARE\Classes\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}\TypeLib@Version 1.0
Reg HKLM\SOFTWARE\Classes\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}\ProxyStubClsid@ {00020424-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}\ProxyStubClsid32@ {00020424-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}\TypeLib@ {C8CECDE3-1AE1-4C4A-AD82-6D5B00212144}
Reg HKLM\SOFTWARE\Classes\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}\TypeLib@Version 1.0
Reg HKLM\SOFTWARE\Classes\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}\ProxyStubClsid@ {00020424-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}\ProxyStubClsid32@ {00020424-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}\TypeLib@ {E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}
Reg HKLM\SOFTWARE\Classes\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}\TypeLib@Version 1.0
Reg HKLM\SOFTWARE\Classes\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}\ProxyStubClsid@ {00020420-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}\ProxyStubClsid32@ {00020420-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}\TypeLib@ {E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}
Reg HKLM\SOFTWARE\Classes\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}\TypeLib@Version 1.0
Reg HKLM\SOFTWARE\Classes\JavaPlugin.150_06\CLSID
Reg HKLM\SOFTWARE\Classes\JavaPlugin.150_06\CLSID@ {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
Reg HKLM\SOFTWARE\Classes\Keyhole.KHFeature@ KHFeature Class
Reg HKLM\SOFTWARE\Classes\Keyhole.KHFeature\CLSID
Reg HKLM\SOFTWARE\Classes\Keyhole.KHFeature\CLSID@ {B153D707-447A-4538-913E-6146B3FDEE02}
Reg HKLM\SOFTWARE\Classes\Keyhole.KHFeature.1@ KHFeature Class
Reg HKLM\SOFTWARE\Classes\Keyhole.KHFeature.1\CLSID
Reg HKLM\SOFTWARE\Classes\Keyhole.KHFeature.1\CLSID@ {B153D707-447A-4538-913E-6146B3FDEE02}
Reg HKLM\SOFTWARE\Classes\Keyhole.KHInterface@ KHInterface Class
Reg HKLM\SOFTWARE\Classes\Keyhole.KHInterface\CLSID
Reg HKLM\SOFTWARE\Classes\Keyhole.KHInterface\CLSID@ {AFD07A5E-3E20-4D77-825C-2F6D1A50BE5B}
Reg HKLM\SOFTWARE\Classes\Keyhole.KHInterface\CurVer
Reg HKLM\SOFTWARE\Classes\Keyhole.KHInterface\CurVer@ Keyhole.KHInterface.1
Reg HKLM\SOFTWARE\Classes\Keyhole.KHInterface.1@ KHInterface Class
Reg HKLM\SOFTWARE\Classes\Keyhole.KHInterface.1\CLSID
Reg HKLM\SOFTWARE\Classes\Keyhole.KHInterface.1\CLSID@ {AFD07A5E-3E20-4D77-825C-2F6D1A50BE5B}
Reg HKLM\SOFTWARE\Classes\Keyhole.KHViewExtents@ KHViewExtents Class
Reg HKLM\SOFTWARE\Classes\Keyhole.KHViewExtents\CLSID
Reg HKLM\SOFTWARE\Classes\Keyhole.KHViewExtents\CLSID@ {63E6BE14-A742-4EEA-8AF3-0EC39F10F850}
Reg HKLM\SOFTWARE\Classes\Keyhole.KHViewExtents.1@ KHViewExtents Class
Reg HKLM\SOFTWARE\Classes\Keyhole.KHViewExtents.1\CLSID
Reg HKLM\SOFTWARE\Classes\Keyhole.KHViewExtents.1\CLSID@ {63E6BE14-A742-4EEA-8AF3-0EC39F10F850}
Reg HKLM\SOFTWARE\Classes\Keyhole.KHViewInfo@ KHViewInfo Class
Reg HKLM\SOFTWARE\Classes\Keyhole.KHViewInfo\CLSID
Reg HKLM\SOFTWARE\Classes\Keyhole.KHViewInfo\CLSID@ {A2D4475B-C9AA-48E2-A029-1DB829DACF7B}
Reg HKLM\SOFTWARE\Classes\Keyhole.KHViewInfo\CurVer
Reg HKLM\SOFTWARE\Classes\Keyhole.KHViewInfo\CurVer@ Keyhole.KHViewInfo.1
Reg HKLM\SOFTWARE\Classes\Keyhole.KHViewInfo.1@ KHViewInfo Class
Reg HKLM\SOFTWARE\Classes\Keyhole.KHViewInfo.1\CLSID
Reg HKLM\SOFTWARE\Classes\Keyhole.KHViewInfo.1\CLSID@ {A2D4475B-C9AA-48E2-A029-1DB829DACF7B}
Reg HKLM\SOFTWARE\Classes\MacromediaFlashPaper.MacromediaFlashPaper@ Macromedia Flash Paper
Reg HKLM\SOFTWARE\Classes\MacromediaFlashPaper.MacromediaFlashPaper\DefaultIcon
Reg HKLM\SOFTWARE\Classes\MacromediaFlashPaper.MacromediaFlashPaper\DefaultIcon@ "%1"
Reg HKLM\SOFTWARE\Classes\MacromediaFlashPaper.MacromediaFlashPaper\shell
Reg HKLM\SOFTWARE\Classes\MacromediaFlashPaper.MacromediaFlashPaper\shell\open
Reg HKLM\SOFTWARE\Classes\MacromediaFlashPaper.MacromediaFlashPaper\shell\open\command
Reg HKLM\SOFTWARE\Classes\MacromediaFlashPaper.MacromediaFlashPaper\shell\open\command@ "C:\Program Files\Internet Explorer\iexplore.exe" -nohome "%1"
Reg HKLM\SOFTWARE\Classes\magnet@ URL:MagNet Protocol
Reg HKLM\SOFTWARE\Classes\magnet@URL Protocol
Reg HKLM\SOFTWARE\Classes\magnet\DefaultIcon
Reg HKLM\SOFTWARE\Classes\magnet\DefaultIcon@ "C:\Program Files\LimeWire\LimeWire.ico",-128
Reg HKLM\SOFTWARE\Classes\magnet\shell
Reg HKLM\SOFTWARE\Classes\magnet\shell@
Reg HKLM\SOFTWARE\Classes\magnet\shell\open
Reg HKLM\SOFTWARE\Classes\magnet\shell\open@
Reg HKLM\SOFTWARE\Classes\magnet\shell\open\command
Reg HKLM\SOFTWARE\Classes\magnet\shell\open\command@ "C:\Program Files\LimeWire\LimeWire.exe" "%L"
Reg HKLM\SOFTWARE\Classes\mailto@ URL:MailTo Protocol
Reg HKLM\SOFTWARE\Classes\mailto@URL Protocol
Reg HKLM\SOFTWARE\Classes\mailto\DefaultIcon
Reg HKLM\SOFTWARE\Classes\mailto\DefaultIcon@ C:\PROGRA~1\Yahoo!\Common\ymmapi.dll,0
Reg HKLM\SOFTWARE\Classes\mailto\shell
Reg HKLM\SOFTWARE\Classes\mailto\shell\open
Reg HKLM\SOFTWARE\Classes\mailto\shell\open\command
Reg HKLM\SOFTWARE\Classes\mailto\shell\open\command@ rundll32.exe C:\PROGRA~1\Yahoo!\Common\ymmapi.dll,MailToProtocolHandler %1
Reg HKLM\SOFTWARE\Classes\MEM.AutoplayApp@ MEM Autoplay app
Reg HKLM\SOFTWARE\Classes\MEM.AutoplayApp\CLSID
Reg HKLM\SOFTWARE\Classes\MEM.AutoplayApp\CLSID@ {F62AD501-DFDC-4f9e-80F3-A5640C0FAE72}
Reg HKLM\SOFTWARE\Classes\MEM.AutoplayApp\CurVer
Reg HKLM\SOFTWARE\Classes\MEM.AutoplayApp\CurVer@ MEM.AutoplayApp.1
Reg HKLM\SOFTWARE\Classes\MEM.AutoplayApp.1@ MEM Autoplay app
Reg HKLM\SOFTWARE\Classes\MEM.AutoplayApp.1\CLSID
Reg HKLM\SOFTWARE\Classes\MEM.AutoplayApp.1\CLSID@ {F62AD501-DFDC-4f9e-80F3-A5640C0FAE72}
Reg HKLM\SOFTWARE\Classes\Microsoft.FeedsManager@ Feed Subscriptions
Reg HKLM\SOFTWARE\Classes\Microsoft.FeedsManager\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.FeedsManager\CLSID@ {faeb54c4-f66f-4806-83a0-805299f5e3ad}
Reg HKLM\SOFTWARE\Classes\Microsoft.InformationCard.ElementBehaviorFactory.1\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.InformationCard.ElementBehaviorFactory.1\CLSID@ {c2c4f00a-720e-4389-aeb9-e9c4b0d93c6f}
Reg HKLM\SOFTWARE\Classes\Microsoft.Picture.It.9.AutoPlay\shell
Reg HKLM\SOFTWARE\Classes\Microsoft.Picture.It.9.AutoPlay\shell@ AutoPlay
Reg HKLM\SOFTWARE\Classes\Microsoft.Picture.It.9.AutoPlay\shell\AutoPlay
Reg HKLM\SOFTWARE\Classes\Microsoft.Picture.It.9.AutoPlay\shell\AutoPlay\Command
Reg HKLM\SOFTWARE\Classes\Microsoft.Picture.It.9.AutoPlay\shell\AutoPlay\Command@ C:\Program Files\Common Files\Microsoft Shared\Picture It!\imprtwiz.exe /invoke={D0551EC1-5A78-11cf-9DBE-00AA00A70BB5}
Reg HKLM\SOFTWARE\Classes\MSIDXS@ Microsoft OLE DB Provider for Indexing Service
Reg HKLM\SOFTWARE\Classes\MSIDXS\Clsid
Reg HKLM\SOFTWARE\Classes\MSIDXS\Clsid@ {F9AE8980-7E52-11d0-8964-00C04FD611D7}
Reg HKLM\SOFTWARE\Classes\MSIDXS ErrorLookup@ Microsoft OLE DB Error Lookup for Indexing Service
Reg HKLM\SOFTWARE\Classes\MSIDXS ErrorLookup\Clsid
Reg HKLM\SOFTWARE\Classes\MSIDXS ErrorLookup\Clsid@ {F9AE8981-7E52-11d0-8964-00C04FD611D7}
Reg HKLM\SOFTWARE\Classes\MySpace.PaneItems.4@ MySpace Uploader PaneItems Control
Reg HKLM\SOFTWARE\Classes\MySpace.PaneItems.4\CLSID
Reg HKLM\SOFTWARE\Classes\MySpace.PaneItems.4\CLSID@ {7746874F-26C2-4E52-A26A-F22A15DD42B3}
Reg HKLM\SOFTWARE\Classes\MySpace.PaneItems.4\CurVer
Reg HKLM\SOFTWARE\Classes\MySpace.PaneItems.4\CurVer@ MySpace.PaneItems.4.1
Reg HKLM\SOFTWARE\Classes\MySpace.PaneItems.4.1@ MySpace Uploader PaneItems Control
Reg HKLM\SOFTWARE\Classes\MySpace.PaneItems.4.1\CLSID
Reg HKLM\SOFTWARE\Classes\MySpace.PaneItems.4.1\CLSID@ {7746874F-26C2-4E52-A26A-F22A15DD42B3}
Reg HKLM\SOFTWARE\Classes\MySpace.ShellCombo.4@ MySpace Uploader Combo Control
Reg HKLM\SOFTWARE\Classes\MySpace.ShellCombo.4\CLSID
Reg HKLM\SOFTWARE\Classes\MySpace.ShellCombo.4\CLSID@ {69D797FE-62A0-4A86-9027-5C79634BA7F6}
Reg HKLM\SOFTWARE\Classes\MySpace.ShellCombo.4\CurVer
Reg HKLM\SOFTWARE\Classes\MySpace.ShellCombo.4\CurVer@ MySpace.ShellCombo.4.1
Reg HKLM\SOFTWARE\Classes\MySpace.ShellCombo.4.1@ MySpace Uploader Combo Control
Reg HKLM\SOFTWARE\Classes\MySpace.ShellCombo.4.1\CLSID
Reg HKLM\SOFTWARE\Classes\MySpace.ShellCombo.4.1\CLSID@ {69D797FE-62A0-4A86-9027-5C79634BA7F6}
Reg HKLM\SOFTWARE\Classes\MySpace.Thumbnail.4@ MySpace Uploader Thumbnail Control
Reg HKLM\SOFTWARE\Classes\MySpace.Thumbnail.4\CLSID
Reg HKLM\SOFTWARE\Classes\MySpace.Thumbnail.4\CLSID@ {CB5AB6FE-43E4-4C12-86F1-8F9444C6DA34}
Reg HKLM\SOFTWARE\Classes\MySpace.Thumbnail.4\CurVer
Reg HKLM\SOFTWARE\Classes\MySpace.Thumbnail.4\CurVer@ MySpace.Thumbnail.4.1
Reg HKLM\SOFTWARE\Classes\MySpace.Thumbnail.4.1@ MySpace Uploader Thumbnail Control
Reg HKLM\SOFTWARE\Classes\MySpace.Thumbnail.4.1\CLSID
Reg HKLM\SOFTWARE\Classes\MySpace.Thumbnail.4.1\CLSID@ {CB5AB6FE-43E4-4C12-86F1-8F9444C6DA34}
Reg HKLM\SOFTWARE\Classes\MySpace.Uploader.4@ MySpace Uploader Control
Reg HKLM\SOFTWARE\Classes\MySpace.Uploader.4\CLSID
Reg HKLM\SOFTWARE\Classes\MySpace.Uploader.4\CLSID@ {48DD0448-9209-4F81-9F6D-D83562940134}
Reg HKLM\SOFTWARE\Classes\MySpace.Uploader.4\CurVer
Reg HKLM\SOFTWARE\Classes\MySpace.Uploader.4\CurVer@ MySpace.Uploader.4.1
Reg HKLM\SOFTWARE\Classes\MySpace.Uploader.4.1@ MySpace Uploader Control
Reg HKLM\SOFTWARE\Classes\MySpace.Uploader.4.1\CLSID
Reg HKLM\SOFTWARE\Classes\MySpace.Uploader.4.1\CLSID@ {48DD0448-9209-4F81-9F6D-D83562940134}
Reg HKLM\SOFTWARE\Classes\MySpace.Uploader.4.1\Insertable
Reg HKLM\SOFTWARE\Classes\MySpace.UploadItems.4@ MySpace Uploader UploadItems Control
Reg HKLM\SOFTWARE\Classes\MySpace.UploadItems.4\CLSID
Reg HKLM\SOFTWARE\Classes\MySpace.UploadItems.4\CLSID@ {84BD32BE-61DC-45EF-997B-71127537D330}
Reg HKLM\SOFTWARE\Classes\MySpace.UploadItems.4\CurVer
Reg HKLM\SOFTWARE\Classes\MySpace.UploadItems.4\CurVer@ MySpace.UploadItems.4.1
Reg HKLM\SOFTWARE\Classes\MySpace.UploadItems.4.1@ MySpace Uploader UploadItems Control
Reg HKLM\SOFTWARE\Classes\MySpace.UploadItems.4.1\CLSID
Reg HKLM\SOFTWARE\Classes\MySpace.UploadItems.4.1\CLSID@ {84BD32BE-61DC-45EF-997B-71127537D330}
Reg HKLM\SOFTWARE\Classes\MySpace.UploadPane.4@ MySpace Uploader UploadPane Control
Reg HKLM\SOFTWARE\Classes\MySpace.UploadPane.4\CLSID
Reg HKLM\SOFTWARE\Classes\MySpace.UploadPane.4\CLSID@ {33F9C869-A43A-4138-B7A1-1E9598466EC5}
Reg HKLM\SOFTWARE\Classes\MySpace.UploadPane.4\CurVer
Reg HKLM\SOFTWARE\Classes\MySpace.UploadPane.4\CurVer@ MySpace.UploadPane.4.1
Reg HKLM\SOFTWARE\Classes\MySpace.UploadPane.4.1@ MySpace Uploader UploadPane Control
Reg HKLM\SOFTWARE\Classes\MySpace.UploadPane.4.1\CLSID
Reg HKLM\SOFTWARE\Classes\MySpace.UploadPane.4.1\CLSID@ {33F9C869-A43A-4138-B7A1-1E9598466EC5}
Reg HKLM\SOFTWARE\Classes\PhotoShare.PhotoPanel@ PhotoPanel Class
Reg HKLM\SOFTWARE\Classes\PhotoShare.PhotoPanel\CLSID
Reg HKLM\SOFTWARE\Classes\PhotoShare.PhotoPanel\CLSID@ {6FF98F64-474B-416F-A5B8-B593F8B44D24}
Reg HKLM\SOFTWARE\Classes\PhotoShare.PhotoPanel\CurVer
Reg HKLM\SOFTWARE\Classes\PhotoShare.PhotoPanel\CurVer@ PhotoShare.PhotoPanel.1
Reg HKLM\SOFTWARE\Classes\PhotoShare.PhotoPanel.1@ PhotoPanel Class
Reg HKLM\SOFTWARE\Classes\PhotoShare.PhotoPanel.1\CLSID
Reg HKLM\SOFTWARE\Classes\PhotoShare.PhotoPanel.1\CLSID@ {6FF98F64-474B-416F-A5B8-B593F8B44D24}
Reg HKLM\SOFTWARE\Classes\ProtectorExe.ProtectorHost@ ProtectorHost Class
Reg HKLM\SOFTWARE\Classes\ProtectorExe.ProtectorHost\CLSID
Reg HKLM\SOFTWARE\Classes\ProtectorExe.ProtectorHost\CLSID@ {FBA44040-BD27-4A09-ACC8-C08B7C723DCD}
Reg HKLM\SOFTWARE\Classes\ProtectorExe.ProtectorHost\CurVer
Reg HKLM\SOFTWARE\Classes\ProtectorExe.ProtectorHost\CurVer@ ProtectorExe.ProtectorHost.1
Reg HKLM\SOFTWARE\Classes\ProtectorExe.ProtectorHost.1@ ProtectorHost Class
Reg HKLM\SOFTWARE\Classes\ProtectorExe.ProtectorHost.1\CLSID
Reg HKLM\SOFTWARE\Classes\ProtectorExe.ProtectorHost.1\CLSID@ {FBA44040-BD27-4A09-ACC8-C08B7C723DCD}
Reg HKLM\SOFTWARE\Classes\protector_dll.Protector@ Protector Class
Reg HKLM\SOFTWARE\Classes\protector_dll.Protector\CLSID
Reg HKLM\SOFTWARE\Classes\protector_dll.Protector\CLSID@ {6134CEA9-DD6E-495C-A0D1-4F232027D7D7}
Reg HKLM\SOFTWARE\Classes\protector_dll.Protector\CurVer
Reg HKLM\SOFTWARE\Classes\protector_dll.Protector\CurVer@ protector_dll.Protector.1
Reg HKLM\SOFTWARE\Classes\protector_dll.Protector.1@ Protector Class
Reg HKLM\SOFTWARE\Classes\protector_dll.Protector.1\CLSID
Reg HKLM\SOFTWARE\Classes\protector_dll.Protector.1\CLSID@ {6134CEA9-DD6E-495C-A0D1-4F232027D7D7}
Reg HKLM\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.8@ Shockwave Flash Object
Reg HKLM\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.8\CLSID
Reg HKLM\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.8\CLSID@ {D27CDB6E-AE6D-11cf-96B8-444553540000}
Reg HKLM\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.9@ Shockwave Flash Object
Reg HKLM\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.9\CLSID
Reg HKLM\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.9\CLSID@ {D27CDB6E-AE6D-11cf-96B8-444553540000}
Reg HKLM\SOFTWARE\Classes\Yahoo.Messenger@ Messenger Class
Reg HKLM\SOFTWARE\Classes\Yahoo.Messenger\CLSID
Reg HKLM\SOFTWARE\Classes\Yahoo.Messenger\CLSID@ {96F8C0C7-F106-437D-90DC-6C92793246C4}
Reg HKLM\SOFTWARE\Classes\Yahoo.Messenger\CurVer
Reg HKLM\SOFTWARE\Classes\Yahoo.Messenger\CurVer@ Yahoo.Messenger.1
Reg HKLM\SOFTWARE\Classes\Yahoo.Messenger.1@ Messenger Class
Reg HKLM\SOFTWARE\Classes\Yahoo.Messenger.1\CLSID
Reg HKLM\SOFTWARE\Classes\Yahoo.Messenger.1\CLSID@ {96F8C0C7-F106-437D-90DC-6C92793246C4}
Reg HKLM\SOFTWARE\Classes\Ybmfile\shell
Reg HKLM\SOFTWARE\Classes\Ybmfile\shell\open
Reg HKLM\SOFTWARE\Classes\Ybmfile\shell\open\command
Reg HKLM\SOFTWARE\Classes\Ybmfile\shell\open\command@ C:\PROGRA~1\Yahoo!\Common\YSHORT~1.EXE %1
Reg HKLM\SOFTWARE\Classes\Ybmfile\shell\opennew
Reg HKLM\SOFTWARE\Classes\Ybmfile\shell\opennew\command
Reg HKLM\SOFTWARE\Classes\Ybmfile\shell\opennew\command@ C:\PROGRA~1\Yahoo!\Common\YSHORT~1.EXE %1
Reg HKLM\SOFTWARE\Classes\YIeTagBm.YahooTaggedBM@ YahooTaggedBM Class
Reg HKLM\SOFTWARE\Classes\YIeTagBm.YahooTaggedBM\CLSID
Reg HKLM\SOFTWARE\Classes\YIeTagBm.YahooTaggedBM\CLSID@ {65D886A2-7CA7-479B-BB95-14D1EFB7946A}
Reg HKLM\SOFTWARE\Classes\YIeTagBm.YahooTaggedBM\CurVer
Reg HKLM\SOFTWARE\Classes\YIeTagBm.YahooTaggedBM\CurVer@ YIeTagBm.YahooTaggedBM.1
Reg HKLM\SOFTWARE\Classes\YIeTagBm.YahooTaggedBM.1@ YahooTaggedBM Class
Reg HKLM\SOFTWARE\Classes\YIeTagBm.YahooTaggedBM.1\CLSID
Reg HKLM\SOFTWARE\Classes\YIeTagBm.YahooTaggedBM.1\CLSID@ {65D886A2-7CA7-479B-BB95-14D1EFB7946A}
Reg HKLM\SOFTWARE\Classes\YInstHelper.YInstStarter@ YInstStarter Class
Reg HKLM\SOFTWARE\Classes\YInstHelper.YInstStarter\CLSID
Reg HKLM\SOFTWARE\Classes\YInstHelper.YInstStarter\CLSID@ {30528230-99F7-4BB4-88D8-FA1D4F56A2AB}
Reg HKLM\SOFTWARE\Classes\YInstHelper.YInstStarter\CurVer
Reg HKLM\SOFTWARE\Classes\YInstHelper.YInstStarter\CurVer@ YInstHelper.YInstStarter.1
Reg HKLM\SOFTWARE\Classes\YInstHelper.YInstStarter.1@ YInstStarter Class
Reg HKLM\SOFTWARE\Classes\YInstHelper.YInstStarter.1\CLSID
Reg HKLM\SOFTWARE\Classes\YInstHelper.YInstStarter.1\CLSID@ {30528230-99F7-4BB4-88D8-FA1D4F56A2AB}
Reg HKLM\SOFTWARE\Classes\YInstHelper.YInstStarterUpgrade@ YInstStarterUpgrade Class
Reg HKLM\SOFTWARE\Classes\YInstHelper.YInstStarterUpgrade\CLSID
Reg HKLM\SOFTWARE\Classes\YInstHelper.YInstStarterUpgrade\CLSID@ {0291E591-EA41-4c82-8106-3DC6CE7F7664}
Reg HKLM\SOFTWARE\Classes\YInstHelper.YInstStarterUpgrade\CurVer
Reg HKLM\SOFTWARE\Classes\YInstHelper.YInstStarterUpgrade\CurVer@ YInstHelper.YInstStarterUpgrade.1
Reg HKLM\SOFTWARE\Classes\YInstHelper.YInstStarterUpgrade.1@ YInstStarterUpgrade Class
Reg HKLM\SOFTWARE\Classes\YInstHelper.YInstStarterUpgrade.1\CLSID
Reg HKLM\SOFTWARE\Classes\YInstHelper.YInstStarterUpgrade.1\CLSID@ {0291E591-EA41-4c82-8106-3DC6CE7F7664}
Reg HKLM\SOFTWARE\Classes\YInstHelper.YSearchSetting2@ YSearchSetting2 Class
Reg HKLM\SOFTWARE\Classes\YInstHelper.YSearchSetting2\CLSID
Reg HKLM\SOFTWARE\Classes\YInstHelper.YSearchSetting2\CLSID@ {347B0667-C7ED-429B-BDE3-CC8D3BACAA31}
Reg HKLM\SOFTWARE\Classes\YInstHelper.YSearchSetting2\CurVer
Reg HKLM\SOFTWARE\Classes\YInstHelper.YSearchSetting2\CurVer@ YInstHelper.YSearchSetting2.1
Reg HKLM\SOFTWARE\Classes\YInstHelper.YSearchSetting2.1@ YSearchSetting2 Class
Reg HKLM\SOFTWARE\Classes\YInstHelper.YSearchSetting2.1\CLSID
Reg HKLM\SOFTWARE\Classes\YInstHelper.YSearchSetting2.1\CLSID@ {347B0667-C7ED-429B-BDE3-CC8D3BACAA31}
Reg HKLM\SOFTWARE\Classes\YLoginIds.LoginMenuIds@ LoginMenuIds Class
Reg HKLM\SOFTWARE\Classes\YLoginIds.LoginMenuIds\CLSID
Reg HKLM\SOFTWARE\Classes\YLoginIds.LoginMenuIds\CLSID@ {2840354C-234F-4450-8F2D-12459E75AE71}
Reg HKLM\SOFTWARE\Classes\YLoginIds.LoginMenuIds\CurVer
Reg HKLM\SOFTWARE\Classes\YLoginIds.LoginMenuIds\CurVer@ YLoginIds.LoginMenuIds.1
Reg HKLM\SOFTWARE\Classes\YLoginIds.LoginMenuIds.1@ LoginMenuIds Class
Reg HKLM\SOFTWARE\Classes\YLoginIds.LoginMenuIds.1\CLSID
Reg HKLM\SOFTWARE\Classes\YLoginIds.LoginMenuIds.1\CLSID@ {2840354C-234F-4450-8F2D-12459E75AE71}
Reg HKLM\SOFTWARE\Classes\YPagerChecker.MessengerChecker@ MessengerChecker Class
Reg HKLM\SOFTWARE\Classes\YPagerChecker.MessengerChecker\CLSID
Reg HKLM\SOFTWARE\Classes\YPagerChecker.MessengerChecker\CLSID@ {DA4F543C-C8A9-4E88-9A79-548CBB46F18F}
Reg HKLM\SOFTWARE\Classes\YPagerChecker.MessengerChecker\CurVer
Reg HKLM\SOFTWARE\Classes\YPagerChecker.MessengerChecker\CurVer@ YPagerChecker.MessengerChecker.1
Reg HKLM\SOFTWARE\Classes\YPagerChecker.MessengerChecker.1@ MessengerChecker Class
Reg HKLM\SOFTWARE\Classes\YPagerChecker.MessengerChecker.1\CLSID
Reg HKLM\SOFTWARE\Classes\YPagerChecker.MessengerChecker.1\CLSID@ {DA4F543C-C8A9-4E88-9A79-548CBB46F18F}
Reg HKLM\SOFTWARE\Classes\YShortcut_DLL.Shortcut@ Shortcut Class
Reg HKLM\SOFTWARE\Classes\YShortcut_DLL.Shortcut\CLSID
Reg HKLM\SOFTWARE\Classes\YShortcut_DLL.Shortcut\CLSID@ {67CE97C5-ABE6-429A-B6BD-3BD1333A0825}
Reg HKLM\SOFTWARE\Classes\YShortcut_DLL.Shortcut\CurVer
Reg HKLM\SOFTWARE\Classes\YShortcut_DLL.Shortcut\CurVer@ YShortcut_DLL.Shortcut.1
Reg HKLM\SOFTWARE\Classes\YShortcut_DLL.Shortcut.1@ Shortcut Class
Reg HKLM\SOFTWARE\Classes\YShortcut_DLL.Shortcut.1\CLSID
Reg HKLM\SOFTWARE\Classes\YShortcut_DLL.Shortcut.1\CLSID@ {67CE97C5-ABE6-429A-B6BD-3BD1333A0825}
Reg HKLM\SOFTWARE\Classes\YShortcut_DLL.TabExtension@ TabExtension Class
Reg HKLM\SOFTWARE\Classes\YShortcut_DLL.TabExtension\CLSID
Reg HKLM\SOFTWARE\Classes\YShortcut_DLL.TabExtension\CLSID@ {0B9DB0A9-D390-431A-9F98-39AEE11F2022}
Reg HKLM\SOFTWARE\Classes\YShortcut_DLL.TabExtension\CurVer
Reg HKLM\SOFTWARE\Classes\YShortcut_DLL.TabExtension\CurVer@ YShortcut_DLL.TabExtension.1
Reg HKLM\SOFTWARE\Classes\YShortcut_DLL.TabExtension.1@ TabExtension Class
Reg HKLM\SOFTWARE\Classes\YShortcut_DLL.TabExtension.1\CLSID
Reg HKLM\SOFTWARE\Classes\YShortcut_DLL.TabExtension.1\CLSID@ {0B9DB0A9-D390-431A-9F98-39AEE11F2022}
Reg HKLM\SOFTWARE\Classes\YUber.UberButton@ Yahoo! IE Services Button Class
Reg HKLM\SOFTWARE\Classes\YUber.UberButton\CLSID
Reg HKLM\SOFTWARE\Classes\YUber.UberButton\CLSID@ {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}
Reg HKLM\SOFTWARE\Classes\YUber.UberButton\CurVer
Reg HKLM\SOFTWARE\Classes\YUber.UberButton\CurVer@ YUber.UberButton.1
Reg HKLM\SOFTWARE\Classes\YUber.UberButton.1@ Yahoo! IE Services Button Class
Reg HKLM\SOFTWARE\Classes\YUber.UberButton.1\CLSID
Reg HKLM\SOFTWARE\Classes\YUber.UberButton.1\CLSID@ {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}
Reg HKLM\SOFTWARE\Classes\YVerInfo.GetInfo@ GetInfo Class
Reg HKLM\SOFTWARE\Classes\YVerInfo.GetInfo\CLSID
Reg HKLM\SOFTWARE\Classes\YVerInfo.GetInfo\CLSID@ {D5184A39-CBDF-4A4F-AC1A-7A45A852C883}
Reg HKLM\SOFTWARE\Classes\YVerInfo.GetInfo\CurVer
Reg HKLM\SOFTWARE\Classes\YVerInfo.GetInfo\CurVer@ YVerInfo.GetInfo.1
Reg HKLM\SOFTWARE\Classes\YVerInfo.GetInfo.1@
sdsurfer 0 Newbie Poster
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4080
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
5/8/2010 10:45:52 PM
mbam-log-2010-05-08 (22-45-52).txt
Scan type: Quick scan
Objects scanned: 142995
Time elapsed: 7 minute(s), 12 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
jholland1964 650 Posting Expert Team Colleague Featured Poster
You only did the MBA-M quick scan. Instructions clearly say to do the Full Scan. Please update and do the Full Scan.
sdsurfer 0 Newbie Poster
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4083
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
5/9/2010 9:43:08 AM
mbam-log-2010-05-09 (09-43-08).txt
Scan type: Full scan (A:\|C:\|D:\|E:\|)
Objects scanned: 214734
Time elapsed: 53 minute(s), 24 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
sdsurfer 0 Newbie Poster
My next question is this. I have been unable to download the new version of the adobe flash player. I have tried to download it, but get same error message each time.
"Failed to install.
For troubleshooting tips, please see http://www.adobe.com/go/tn_19166"
But this reference has not been helpful to me...
Any advice? Or is there somewhere else I should ask this question?
Thank you for all your time and effort it is greatly appreciated.
danielperez -1 Newbie Poster
in my vast experience with malware and viruses, I download Malwarebytes from another computer to a flash drive. then I make sure the infected computer is off the network or internet and install Malware on it. then after it has installed on said computer run a complete scan and it should help you. you can also try AVG free download which is very good with viruses and malware. you can even try the AVG Pro for 30 days from the site which won't cost you a thing and it should not cost anything. the same thing is done download from a different computer to a flash drive. you can even you both if you want.
jholland1964 commented: MBA-M program has all ready been used. Anti-virus program is all ready on the computer. -1
Be a part of the DaniWeb community
We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.