Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Browser hijack problems

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Unread postby Susan528 » January 16th, 2006, 10:15 pm

Hello EileanBeag,

Let’s try this now.

STEP 1.
======
Cleaning Files

Navigate to C:\Windows\Prefetch
Click Edit, click Select All, press the DELETE key, and then click Yes to confirm that you want to send all the items to the Recycle Bin.

Navigate to C:\Windows\Temp
Click Edit, click Select All, press the DELETE key, and then click Yes to confirm that you want to send all the items to the Recycle Bin.

Example from your MWAV scan
C:\Documents and Settings\Margo\Local Settings\Temp\lf_C2C.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus!
This is very important because your MWAV scan show the Temp files in the Documents and Settings infected

Navigate to C:\Documents and Settings\(EVERY LISTED USER)\Local Settings\Temp
Click Edit, click Select All, press the DELETE key, and then click Yes to confirm that you want to send all the items to the Recycle Bin.

Clean out your Temporary Internet files. Proceed like this:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, click to select the Delete all offline content check box , and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
  • Click OK.


Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.

STEP 2.
======
Delete Files with Killbox

Download Pocket Killbox from http://www.downloads.subratam.org/KillBox.zip and unzip it; save it to your Desktop. DO NOT RUN IT YET.
==========
Double-click on KillBox.exe to launch the program. It is the red circle with a large white X in it
- Highlight the files in bold RED below and press the Ctrl key and the C key at the same time to copy them to the clipboard
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq25.tmp
C:\promax2.chm
C:\WINDOWS\Downloaded Program Files\btwebcontrol.dll
C:\WINDOWS\Downloaded Program Files\popcaploader.dll


In Killbox click on the File menu and then the Paste from Clipboard item
in the Full Path of File to Delete field drop down the arrow and make sure that all of the files are listed
(Please note that the tool checks your computer for the presence of the files pasted into the box so if files are not present, it is possible that you might not see all files you pasted into the box.)
Click the option to Delete on Reboot
- If not greyed out click the checkbox for Unregister .dll Before Deleting
- click End Explorer Shell while Killing File
- Now click on the red button with a white 'X' in the middle to delete the files
- Click Yes when it says all files will be deleted on the next reboot
- Click Yes when it asks if you want to reboot now
(Note: If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just reboot manually)

Note: Killbox will let you know if a file does not exist. If that happens, just continue on.

If you have any issues with this method you can copy and paste the lines one at a time into the killbox top box. Then click the "Single File" button. Then click the Red X ...and for the confirmation message that will appear, you will need to click Yes. A second message will ask to Reboot now? you will need to click No until the last one at which time you click yes to allow the reboot.

STEP 3.
======
Run the MWAV scan again. Please be sure that you copy the whole box. It looked like some of the bottom was missing from the last post of the MWAV scan.
MWAV Scan
Please download MWAV to a convenient location.
This scan only produces a report, it doesn't clean your system. I will analyze the report and recommend a course of action depending on the results.
This scan might take around 3+ hours to finish when set to scan everything.

Double-click on mwav.exe.
Put a check next to the below items before scanning:
  • Memory
  • Startup Folders
  • Drive - All Local Drives
  • Folder - then click "browse" to change the directory to C: (default is C:\Windows)
  • Registry
  • System Folders
  • Services
  • Include Sub-Directory
  • Scan All Files

Please make sure ALL of these are checked, then press the Scan button. This typically will take hours to complete.

**NOTE*** Sometimes MWav will pause and it appears to be finished, but it isn't done. Just let it run until it says it's complete.

On the bottom portion of the window, you will see the lower panel where MWav is listing "infected items", please highlight everything in that lower panel and copy them by holding CTRL + C then paste it here. The whole log will be extremely BIG so there is no way to post the log. I just need the infected items list.

Disable Microsoft AntiSpyware:
We need to disable your Microsoft AntiSpyware Real-time Protection as it may interfere with the fixes that we need to make.
  • Open Microsoft AntiSpyware
  • Click on Tools, Settings.
  • In the left pane, click on Real-time Protection
  • Under Startup Options uncheck Enable the Microsoft AntiSpyware Security Agents
  • Under Real-time spyware threat protection uncheck Enable real-time spyware threat protection (recommended).
  • After you uncheck these, click on the Save button and close Microsoft AntiSpyware.
  • Right click on the Microsoft AntiSpyware icon on the taskbar and select Shutdown Microsoft AntiSpyware.

After all of the fixes are complete it is very important that you enable Real-time Protection again.

Disable Ewido:
Please disable Ewido, as it may interfere with the fix. [br]To disable Ewido:
From the system tray:
  • Right-click the system tray icon and uncheck real time protection.
    or From within Ewido -
  • Under 'Your security status', if the real time protection is active, deactivate it by clicking 'real time protection' until the status says 'inactive'.

Once your log is clean you can re-enable Ewido.

Please set your system to show all files; please see here if you're unsure how to do this.

Close all programs leaving only HijackThis running. Place a check against each of the following, making sure you get them all and not any others by mistake:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
O4 - HKLM\..\Run: [ms1src] c:\program files\common files\system\ms1src.exe /install
O16 - DPF: {70B410C0-BADA-11D4-8308-0080C8D7ED4A} (GameDesire Bridge) - http://67.15.101.2/g_bin/eng/bridge_2_0_0_14.cab

Click on Fix Checked when finished and exit HijackThis.

Reboot into Safe Mode: please see here if you are not sure how to do this.

Using Windows Explorer, locate the following files/folders, and delete them:
c:\program files\common files\system\ms1src.exe<==file
Exit Explorer, and reboot as normal afterwards.

Post back a fresh HijackThis log and we will take another look.
User avatar
Susan528
MRU Master
MRU Master
 
Posts: 1594
Joined: April 4th, 2005, 9:20 am
Location: Alabama, USA
Advertisement
Register to Remove

Unread postby Eileanbeag » January 17th, 2006, 6:21 am

Got as far as C:\Documents and Settings but when trying to delete temporary files was told cannot delete~ DFB6B3 as it was being used by anothr programme
Eileanbeag
Active Member
 
Posts: 12
Joined: January 12th, 2006, 3:43 pm

Unread postby Susan528 » January 17th, 2006, 10:31 am

Hello Eileanbeag,

Let's try this:

STEP 2.
======
Delete Files with Killbox

Download Pocket Killbox from http://www.downloads.subratam.org/KillBox.zip and unzip it; save it to your Desktop. DO NOT RUN IT YET.
==========
Double-click on KillBox.exe to launch the program. It is the red circle with a large white X in it
- Highlight the files in bold RED below and press the Ctrl key and the C key at the same time to copy them to the clipboard
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_570.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_9E4.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_A18.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_A44.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_A54.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_A78.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_A84.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_AB4.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_B08.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_B10.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_B28.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_B2C.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_B38.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_B48.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_B68.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_B74.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_BA0.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_BA4.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_BC0.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_BDC.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_C20.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_C28.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_C2C.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_C30.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_C34.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_C50.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_C6C.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_C78.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_C8C.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_CB8.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\Temp\lf_E70.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_9E4.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_A18.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_A44.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_A54.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_A78.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_A84.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_AB4.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_B08.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_B10.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_B28.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_B2C.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_B38.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_B48.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_B68.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_B74.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_BA0.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_BA4.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_BC0.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_BDC.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_C20.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_C28.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_C2C.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_C30.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_C34.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_C50.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_C6C.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_C78.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_C8C.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_CB8.tmp
C:\Documents and Settings\Margo\Local Settings\Temp\lf_E70.tmp
C:\DOCUMENTS AND SETTINGS\Margo\LOCAL SETTINGS\TEMPORARY\Content.IE5\KHIZS5MV\fddli_1200_Mw_s_Inst-79[1].exe
C:\Documents and Settings\Margo\Local Settings\Temp\lf_570.tmp
C:\Documents and Settings\Margo\Local Settings\Temporary\Content.IE5\KHIZS5MV\fddli_1200_Mw_s_Inst-79[1].exe
C:\Program s\Yahoo!\YPSR\Quarantine\ppq25.tmp
C:\promax2.chm
C:\WINDOWS\Downloaded Programs\btwebcontrol.dll
C:\WINDOWS\Downloaded Programs\popcaploader.dll


In Killbox click on the File menu and then the Paste from Clipboard item
in the Full Path of File to Delete field drop down the arrow and make sure that all of the files are listed
(Please note that the tool checks your computer for the presence of the files pasted into the box so if files are not present, it is possible that you might not see all files you pasted into the box.)
Click the option to Delete on Reboot
- If not greyed out click the checkbox for Unregister .dll Before Deleting
- click End Explorer Shell while Killing File
- Now click on the red button with a white 'X' in the middle to delete the files
- Click Yes when it says all files will be deleted on the next reboot
- Click Yes when it asks if you want to reboot now
(Note: If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just reboot manually)

Note: Killbox will let you know if a file does not exist. If that happens, just continue on.

If you have any issues with this method you can copy and paste the lines one at a time into the killbox top box. Then click the "Single File" button. Then click the Red X ...and for the confirmation message that will appear, you will need to click Yes. A second message will ask to Reboot now? you will need to click No until the last one at which time you click yes to allow the reboot.

STEP 3.
======
Run the MWAV scan again. Please be sure that you copy the whole box. It looked like some of the bottom was missing from the last post of the MWAV scan.Here are the whole instructions again but you probably still have it so just do that part you need to do.
MWAV Scan
Please download MWAV to a convenient location.
This scan only produces a report, it doesn't clean your system. I will analyze the report and recommend a course of action depending on the results.
This scan might take around 3+ hours to finish when set to scan everything.

Double-click on mwav.exe.
Put a check next to the below items before scanning:
  • Memory
  • Startup Folders
  • Drive - All Local Drives
  • Folder - then click "browse" to change the directory to C: (default is C:\Windows)
  • Registry
  • System Folders
  • Services
  • Include Sub-Directory
  • Scan All Files

Please make sure ALL of these are checked, then press the Scan button. This typically will take hours to complete.

**NOTE*** Sometimes MWav will pause and it appears to be finished, but it isn't done. Just let it run until it says it's complete.

On the bottom portion of the window, you will see the lower panel where MWav is listing "infected items", please highlight everything in that lower panel and copy them by holding CTRL + C then paste it here. The whole log will be extremely BIG so there is no way to post the log. I just need the infected items list.
User avatar
Susan528
MRU Master
MRU Master
 
Posts: 1594
Joined: April 4th, 2005, 9:20 am
Location: Alabama, USA

Unread postby Eileanbeag » January 17th, 2006, 5:50 pm

Object "searchexe Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "bookmarkexpress Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "winpup32 Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "180solutions Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "downloader-ak Trojan-Downloader" found in File System! Action Taken: No Action Taken.
Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "startsurfing Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "startsurfing Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "cydoor.topicks.a Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "cydoor.topicks.a Spyware/Adware" found in File System! Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\CONFLICT.11\hrtbeat.ocx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\CONFLICT.2\hrtbeat.ocx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\CONFLICT.8\hrtbeat.ocx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\hrtbeat.ocx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\KPCMS\CMSCP\CP01". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\CoverDesigner\covered-deu.nls". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Intense Language Office\Demo Movies\DICT_E.SET". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Intense Language Office\Sound\ENGLISH.SND". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Intense Language Office\Help\AUDIO_E.gid". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Intense Language Office\Help\AUDIO_F.gid". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Intense Language Office\Help\AUDIO_G.gid". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Intense Language Office\Help\AUDIO_I.gid". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Intense Language Office\Help\AUDIO_P.gid". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Intense Language Office\Help\AUDIO_R.gid". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Intense Language Office\Help\AUDIO_S.gid". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Intense Language Office\Help\DICT_F.gid". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Intense Language Office\Help\DICT_G.gid". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Intense Language Office\Help\DICT_I.gid". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Intense Language Office\Help\DICT_P.gid". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Intense Language Office\Help\DICT_R.gid". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Intense Language Office\Help\DICT_S.gid". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Intense Language Office\Help\XSHOOT_E.gid". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Intense Language Office\Help\XSHOOT_F.gid". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Intense Language Office\Help\XSHOOT_G.gid". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Intense Language Office\Help\XSHOOT_I.gid". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Intense Language Office\Help\XSHOOT_P.gid". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Intense Language Office\Help\XSHOOT_R.gid". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Intense Language Office\Help\XSHOOT_S.gid". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Microsoft Office\Office\1033\MSOHELP.CHM". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Documents and Settings\All Users\Application Data\Ahead\NeroDigital\settings.xml". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero ShowTime\ShowTime-Deu.nls". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero Recode\Recode-Deu.nls". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\hrtbeat.ocx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\CONFLICT.2\hrtbeat.ocx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\CONFLICT.8\hrtbeat.ocx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\CONFLICT.11\hrtbeat.ocx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\system32\DIMM.DLL". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Serif\GraphicsPlus\AO2XCHG.DLL". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Serif\GraphicsPlus\GPLUSO.EXE". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Documents and Settings\All Users\Desktop\Training A Training.lnk". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero BackItUp\BackItUp-Deu.nls". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\system32\pxwma.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Symantec Shared\IDSDefs\IDSLU.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Symantec Shared\IDSDefs\IDSCoLU.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\August 2001 Adobe Product Update.exe" refers to invalid object "C:\Program Files\Common Files\Adobe\August 2001 Adobe Product Update.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\cmmgr32.exe" refers to invalid object "C:\WINDOWS\System32\cmmgr32.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\Createcd50.exe" refers to invalid object "C:\Program Files\Common Files\Adaptec Shared\CreateCD\createcd50.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\OnlinePrintApp.exe" refers to invalid object "C:\Program Files\Sony Corporation\Picture Package\OnlinePrint\OnlinePrintApp.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\QuickCam.exe" refers to invalid object "C:\Program Files\Logitech\Video\QuickCam.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\setup.exe" refers to invalid object "C:\Program Files\ATI Technologies\ATI Control Panel\setup.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\TSLite.exe" refers to invalid object "C:\Program Files\Bradbury\TopStyle3\TSLite3.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Program Files\PowerQuest\PartitionMagic 8.0\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Program Files\PowerQuest\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\WINDOWS\PCHEALTH\ERRORREP\QHEADLES\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\WINDOWS\PCHEALTH\ERRORREP\QSIGNOFF\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\DOCUME~1\Margo\LOCALS~1\Temp\SqlSetup\Temp\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\DOCUME~1\Margo\LOCALS~1\Temp\SqlSetup\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Shared Tools\msohelp.chm" refers to invalid object "C:\Program Files\Microsoft Office\Office\1033\MSOHELP.CHM". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".001". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".240505jpg". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".bak". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".bnw". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".BUP". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".cnt". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".colour". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".HMT". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".HOF". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".info". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".kodak[1]". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".map". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".mst". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".MSW". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".part". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".pf". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".PMD". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".PRT". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".r11". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".scn". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".sib". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".srs". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".tmp". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".tpl". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".via". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".zat". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".za_". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object "OpenWithList". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "AND Route 2003 Europe - OEM". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Bridge_Base_Online". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Don't Panic 2". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Easy BridgeDeinstall". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Genie Backup Manager V3.0_is1". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "ieupdate". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB810243". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB817778". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB820291". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB821253". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB822603". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB823182". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB824105". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB824141". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB825119". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB826939". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB826942". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB828028". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB828035". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB828741". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB832353". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB835732". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB837001". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB839643-DirectX9". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB839645". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB840315". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB840374". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB841873". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB842773". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "LiveReg". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Mah Jong Tiles Deluxe from GameHouse". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "MSNEXT". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "NoAdware_is1". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "NVIDIA Audio Driver". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "oeupdate". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q327979". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q814995". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q828026". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "RealDownload". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{032B93E8-D9A1-48D2-AA51-D057ABBA9E52}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{0496D9E8-224B-4AFA-8F37-23B98D52F1EB}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{15BB1726-1D8B-486A-866E-BAD34FFACF44}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{4F6BE6BA-AF27-4111-8243-FCADDA63970B}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{66563AD8-637B-407F-BCA7-0233A16891AB}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{7BF7B688-4A95-4003-BA98-EA8A79DA0ABA}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{82C36957-D2B8-4EF2-B88C-110000420}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{82C36957-D2B8-4EF2-B88C-110250590}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{90190409-6000-11D3-8CFE-0050048383C9}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{A8A7ACEF-A7AF-4129-9BC1-4F33A4C31EEC}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{ABEB838C-A1A7-4C5D-B7E1-8B4314600137}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{AC76BA86-0000-0000-0000-6028747ADE01}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{AC76BA86-0000-7EC8-7489-000000000702}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{AC76BA86-0000-7EC8-7489-000000000703}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{AC76BA86-0000-7EC8-7489-000000000704}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{AC76BA86-7AD7-1033-7B44-A00000000001}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{B6F867E8-F092-4C5E-7D72-AC7057DBEF45}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{CDB13FA6-C67F-11D6-9ECC-00024400E70B}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{DA256408-A2E7-41A5-8AD6-62ACB86A0FD7}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{E0F7DAE4-DFA0-46C6-AE55-0C95E4A68898}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{F891AAF3-DE9F-4445-85CF-6E41261A7F5A}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{FB015BB0-5518-4767-9DE4-F9A5C7C62E46}". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0365293D-00C7-4D0B-895D-D97B21EEFBFF}" refers to invalid object "C:\Program Files\Microsoft Office\Office10\WINWORD.EXE /IMG_WIA". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E}" refers to invalid object "C:\Program Files\Viewpoint\Viewpoint Media Player\AxMetaStream.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}" refers to invalid object "C:\Program Files\Viewpoint\Viewpoint Media Player\AxMetaStream.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{227036F9-4E59-4031-92BD-DD3E5184A788}" refers to invalid object "C:\Program Files\Microsoft Office\Office10\MSPUB.EXE /IMG_STI /StiDevice:%1 /StiEvent:%2". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{301A90C1-460F-413C-8AE3-44FA9A5905EB}" refers to invalid object "C:\Program Files\Adobe\Photoshop 5.0\Photoshp.exe /StiDevice:%1 /StiEvent:%2". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{499C2688-85A5-41B5-B8A7-DCC8DCF797B4}" refers to invalid object "C:\Program Files\MSN Apps\Updater\01.05.0000.1009\en-gb\msnappau.exe". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{5432567D-A901-4635-B450-8A6A15C311AA}" refers to invalid object "C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 4.0\DVDMF.exe". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{5C41BB19-ABA9-11D2-9ABC-0000212076C2}" refers to invalid object "C:\Program Files\Serif\wp60\program\3dplusserver.exe". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{70B410C0-BADA-11D4-8308-0080C8D7ED4A}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\Bridge.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{7FBDAB78-8361-11D0-A19B-00A0C9084C89}" refers to invalid object "C:\PROGRA~1\TEXTBR~1.0\Bin\WORDAC~1.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{83D4679F-B6D7-11D2-BF36-00C04FB90A03}" refers to invalid object "C:\PROGRA~1\MESSEN~1\rtcimsp.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{A950EBB5-BFEC-11D0-A1E7-00A0C9084C89}" refers to invalid object "C:\PROGRA~1\TEXTBR~1.0\Bin\EXCELA~1.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{B01F822E-5D6B-474A-8CA7-58FCC50BA035}" refers to invalid object "C:\Program Files\Microsoft Office\Office10\MSPUB.EXE /IMG_WIA". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{0970762F-3CD6-4B54-A5DD-61F06C3F07FB}" refers to invalid object "C:\DOCUME~1\Margo\LOCALS~1\Temp\VBE\MSForms.exd". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{1B7A32F2-3E64-11D1-B5FE-00A024080301}" refers to invalid object "C:\Program Files\ScanSoft\PaperPort\PPExpImp.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{364EA1A3-8100-11D0-A196-00A0C9084C89}" refers to invalid object "C:\WINDOWS\system32\WordAcc.tlb". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{5C21BCD5-F27A-11D2-BB98-00C04F72DA55}" refers to invalid object "C:\PROGRA~1\Bradbury\TOPSTY~1\TSLite3.exe". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{5CD45683-B281-11D1-8C73-00805F011DD6}" refers to invalid object "C:\Program Files\ScanSoft\PaperPort\PPPgCtl.ocx". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{5EA456CD-C03B-47F9-9D01-4B0239BC0E12}" refers to invalid object "C:\WINDOWS\TEMP\VBE\MSForms.exd". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{616664C4-38E7-11D1-839A-080009ACD8A8}" refers to invalid object "C:\Program Files\ScanSoft\PaperPort\PaprPort.exe". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{70B410B1-BADA-11D4-8308-0080C8D7ED4A}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\Bridge.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{7C311910-1435-11D1-8AB0-080009ACD8A8}" refers to invalid object "C:\Program Files\ScanSoft\PaperPort\PPFldrVw.ocx". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{910A56F6-0D16-11D1-8AAE-080009ACD8A8}" refers to invalid object "C:\Program Files\ScanSoft\PaperPort\PPFolder.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{916CD3A3-14CB-11D1-92B7-444553540000}" refers to invalid object "C:\Program Files\ScanSoft\PaperPort\PPLinkBr.ocx". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{93D50763-23F1-11D1-8397-080009ACD8A8}" refers to invalid object "C:\Program Files\ScanSoft\PaperPort\PPDeskVw.ocx". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{9DBB28C1-1925-11D3-A498-00104B6EB52E}" refers to invalid object "C:\Program Files\Viewpoint\Viewpoint Media Player\AxMetaStream.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{B8532AA0-4F93-11D1-98A4-00A0C925C2AC}" refers to invalid object "C:\Program Files\ScanSoft\PaperPort\PPOcrMg.exe". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{B9D87DF7-1A73-11D1-8AB1-080009ACD8A8}" refers to invalid object "C:\Program Files\ScanSoft\PaperPort\PPThumb.ocx". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{C09006C1-53DA-465F-9C5E-57C7AA832820}" refers to invalid object "C:\DOCUME~1\Margo\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{CAC9FCA3-6045-11D1-8355-080009ACD8A8}" refers to invalid object "C:\Program Files\ScanSoft\PaperPort\SmplSrch.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{D38659B2-BFD0-11D0-A1E6-00A0C9084C89}" refers to invalid object "C:\WINDOWS\System32\ExcelAcc.tlb". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{D5B7FCA0-3040-11D1-92BA-444553540000}" refers to invalid object "C:\Program Files\ScanSoft\PaperPort\PPScanMg.exe". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{DCB43485-19FB-4D6D-BB3D-73C7F48D5F00}" refers to invalid object "C:\Program Files\Messenger\rtcimsp.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{E261990A-29C8-11D1-B5FE-00A024080301}" refers to invalid object "C:\Program Files\ScanSoft\PaperPort\PPPrint.exe". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{E4BEC8F6-8EA6-4FB9-B31F-7F3ABED24AE3}" refers to invalid object "C:\DOCUME~1\Margo\LOCALS~1\Temp\Word8.0\MSForms.exd". Action Taken: No Action Taken.
Entry "HKCR\.acf" refers to invalid object "Photoshop.CustomFilterKernel". Action Taken: No Action Taken.
Entry "HKCR\.act" refers to invalid object "Photoshop.ColorTableFile". Action Taken: No Action Taken.
Entry "HKCR\.sll" refers to invalid object "SSLFile". Action Taken: No Action Taken.
Entry "HKCR\8BA_auto_file\shell\open\command" refers to invalid object ""C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe" "%1"". Action Taken: No Action Taken.
Entry "HKCR\ACDSee.PSD" refers to invalid object "{32DDCE4C-C4FB-11d1-AAB2-00C04FA3014E}". Action Taken: No Action Taken.
Entry "HKCR\Alg.AlgSetup" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken.
Entry "HKCR\Alg.AlgSetup.1" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken.
Entry "HKCR\BridgeVu\shell\open\command" refers to invalid object "c:\Bridge Base Online\NetBridgeVu.exe %1". Action Taken: No Action Taken.
Entry "HKCR\ComPlusMetaData.MsCorHost" refers to invalid object "{727CDF4F-3BA0-11D3-8738-00C04F79ED0D}". Action Taken: No Action Taken.
Entry "HKCR\ComPlusMetaData.MsCorHost.2" refers to invalid object "{727CDF4F-3BA0-11D3-8738-00C04F79ED0D}". Action Taken: No Action Taken.
Entry "HKCR\Connection Manager Profile\shell\open\command" refers to invalid object "C:\WINDOWS\System32\CMMGR32.EXE "%1"". Action Taken: No Action Taken.
Entry "HKCR\DSP.DSP" refers to invalid object "{9C123EA9-AEC9-4f75-BBC0-7565FA1398966}". Action Taken: No Action Taken.
Entry "HKCR\DSP.DSPDMOProp_Chorus.1" refers to invalid object "{6F63B172-5543-4593-91CE-EDBA65B9FACDB}". Action Taken: No Action Taken.
Entry "HKCR\EasyB.Document\shell\open\command" refers to invalid object "C:\Games\EASYBR~1\EASYBR~1.EXE "%1"". Action Taken: No Action Taken.
Entry "HKCR\FPXMIXFilter.DSPrintQueue" refers to invalid object "{12A9ACBF-F184-44BE-1F11-E6BA8193E12B}". Action Taken: No Action Taken.
Entry "HKCR\KoolMoves.Document\shell\open\command" refers to invalid object "C:\PROGRA~1\KOOLMO~1\KOOLMO~1.EXE "%1"". Action Taken: No Action Taken.
Entry "HKCR\MailFileAtt" refers to invalid object "{00020D05-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\mapifvbx.object" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.
Entry "HKCR\mapifvbx.object.1" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.
Entry "HKCR\MRK_auto_file\shell\open\command" refers to invalid object "C:\Program Files\Adobe\Photoshop 5.0\Photoshp.exe". Action Taken: No Action Taken.
Entry "HKCR\msbackupfile\shell\open\command" refers to invalid object "%SystemRoot%\system32\ntbackup.exe". Action Taken: No Action Taken.
Entry "HKCR\Plenoptic.Plenoptic" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken.
Entry "HKCR\Plenoptic.Plenoptic.1" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken.
Entry "HKCR\ppifile\shell\open\command" refers to invalid object "%SystemRoot%\System32\msppcnfg.exe /Config %1". Action Taken: No Action Taken.
Entry "HKCR\RTCCore.RTCClient" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken.
Entry "HKCR\RTCCore.RTCClient.1" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken.
Entry "HKCR\Serif3DPlusServer\shell\open\command" refers to invalid object "C:\Program Files\Serif\wp60\program\3dplusserver.exe "%1"". Action Taken: No Action Taken.
Entry "HKCR\SymWriter.pdb" refers to invalid object "{520DC67A-752E-11D3-8D56-00C04F680B2B}". Action Taken: No Action Taken.
Entry "HKCR\TIS_auto_file\shell\open\command" refers to invalid object "C:\Program Files\Adobe\Photoshop 5.0\Photoshp.exe". Action Taken: No Action Taken.
Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.
Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr.1" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.
Entry "HKCR\WMPShell.HWEventHandler" refers to invalid object "{9B186A8F-F520-4eeb-B553-118304AC46C5}". Action Taken: No Action Taken.
Entry "HKCR\WMPShell.HWEventHandler.1" refers to invalid object "{9B186A8F-F520-4eeb-B553-118304AC46C5}". Action Taken: No Action Taken.
Entry "HKCR\WMSServer.Server" refers to invalid object "{845FB959-4279-11D2-BF23-00805FBE84A6}". Action Taken: No Action Taken.
Entry "HKCR\WMSServer.Server.9" refers to invalid object "{845FB959-4279-11D2-BF23-00805FBE84A6}". Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_9E4.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_A18.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_A44.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_A54.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_A78.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_A84.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_AB4.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_B08.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_B10.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_B28.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_B2C.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_B38.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_B48.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_B68.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_B74.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_BA0.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_BA4.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_BC0.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_BDC.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_C20.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_C28.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_C2C.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_C30.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_C34.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_C50.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_C6C.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_C78.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_C8C.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_CB8.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Margo\LOCALS~1\Temp\lf_E70.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\!KillBox\lf_570.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\01B2484E.class infected by "Trojan.Java.ClassLoader.u" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\01B6724A.zip infected by "Trojan-Spy.Win32.Small.cg" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\03A75440 infected by "Trojan-Downloader.Win32.IstBar.gen" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\094B79B3.class infected by "Trojan.Java.Femad" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0E312825 tagged as "not-a-virus:AdWare.Win32.WinAD.bs". Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0E345221 tagged as "not-a-virus:AdWare.Win32.WinAD.bv". Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\116A1BAF.anr infected by "Trojan-Downloader.Win32.Ani.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\11716FA8.class infected by "Trojan.Java.Femad" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\11A8396B.anr infected by "Trojan-Downloader.Win32.Ani.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1A2254F3.class infected by "Trojan.Java.Femad" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1C554C0F.anr infected by "Trojan-Downloader.Win32.Ani.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1F7A5E0A.anr infected by "Trojan-Downloader.Win32.Ani.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\21D11B78.class infected by "Trojan.Java.Femad" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\247F0FD1.class infected by "Trojan.Java.ClassLoader.u" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2DDC24C6.anr infected by "Trojan-Downloader.Win32.Ani.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2DE622BB.anr infected by "Trojan-Downloader.Win32.Ani.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2E276A73.anr infected by "Trojan-Downloader.Win32.Ani.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2E5C0A3A.anr infected by "Trojan-Downloader.Win32.Ani.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3773240A.class infected by "Trojan.Java.Femad" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3C70560E.anr infected by "Trojan-Downloader.Win32.Ani.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3C70560E.class infected by "Trojan.Java.Femad" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3C772A07.class infected by "Trojan.Java.Femad" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3C7D7DFF.anr infected by "Trojan-Downloader.Win32.Ani.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3EE14431.htm infected by "Exploit.VBS.Phel.a" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\45AE3100.htm infected by "Exploit.VBS.Phel.a" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\46E61B92.jar infected by "Exploit.Java.ByteVerify" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4E620748.class infected by "Trojan.Java.Femad" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4EF3145C.anr infected by "Trojan-Downloader.Win32.Ani.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4EFA6855.anr infected by "Trojan-Downloader.Win32.Ani.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\59C9355D.class infected by "Trojan.Java.Femad" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5DFB76D3.exe infected by "Trojan-Downloader.Win32.Small.mg" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5E4D5304 infected by "Exploit.Win32.IMG-ANI.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5E5750BE.class infected by "Trojan.Java.ClassLoader.u" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5E9B0022.exe infected by "Trojan-Downloader.Win32.Small.mg" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\637B7DFB tagged as "not-a-virus:AdWare.Win32.WinAD.bv". Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\653D64FD.anr infected by "Trojan-Downloader.Win32.Ani.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\69EE3DE4.class infected by "Trojan.Java.Femad" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6AA462BF.anr infected by "Trojan-Downloader.Win32.Ani.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6B925BB8.anr infected by "Trojan-Downloader.Win32.Ani.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6BAC2B9B.anr infected by "Trojan-Downloader.Win32.Ani.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7150333A.class infected by "Trojan.Java.Femad" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\72756C24.anr infected by "Trojan-Downloader.Win32.Ani.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\75086F9C.anr infected by "Trojan-Downloader.Win32.Ani.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\76E8015B.class infected by "Trojan.Java.Femad" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7A0E0E14.anr infected by "Trojan-Downloader.Win32.Ani.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7F1770CA infected by "Trojan.Win32.Dialer.ce" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_9E4.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_A18.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_A44.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_A54.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_A78.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_A84.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_AB4.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_B08.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_B10.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_B28.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_B2C.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_B38.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_B48.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_B68.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_B74.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_BA0.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_BA4.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_BC0.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_BDC.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_C20.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_C28.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_C2C.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_C30.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_C34.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_C50.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_C6C.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_C78.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_C8C.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_CB8.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temp\lf_E70.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Margo\Local Settings\Temporary Internet Files\Content.IE5\KHIZS5MV\fddli_1200_Mw_s_Inst-79[1].exe tagged as "not-a-virus:AdWare.Win32.Gator.o". Action Taken: No Action Taken.
File C:\Program Files\Yahoo!\YPSR\Quarantine\ppq25.tmp tagged as "not-a-virus:AdWare.Win32.BMCentral.a". Action Taken: No Action Taken.
File C:\promax2.chm infected by "Trojan.Win32.Dialer.ce" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C3BE6AE0-5F33-47F4-90DC-FAC4475F44BA}\RP7\A0001202.exe tagged as "not-a-virus:Dialer.Win32.gen". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C3BE6AE0-5F33-47F4-90DC-FAC4475F44BA}\RP9\A0001288.exe infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\Downloaded Program Files\btwebcontrol.dll tagged as "not-a-virus:Dialer.Win32.BT.a". Action Taken: No Action Taken.
File C:\WINDOWS\Downloaded Program Files\popcaploader.dll tagged as not-a-virus:Downloader.Win32.PopCap.b. No Action Taken.
File C:\!KillBox\lf_570.tmp infected by "Trojan-Downloader.Win32.Dluca.ci" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\01B2484E.class infected by "Trojan.Java.ClassLoader.u" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\01B6724A.zip infected by "Trojan-Spy.Win32.Small.cg" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\03A75440 infected by "Trojan-Downloader.Win32.IstBar.gen" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\094B79B3.class infected by "Trojan.Java.Femad" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0E312825 tagged as "not-a-virus:AdWare.Win32.WinAD.bs". Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0E345221 tagged as "not-a-virus:AdWare.Win32.WinAD.bv". Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\116A1BAF.anr infected by "Trojan-Downloader.Win32.Ani.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\11716FA8.class infected by "Trojan.Java.Femad" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\11A8396B.anr infected by "Trojan-Downloader.Win32.Ani.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1A2254F3.class infected by "Trojan.Java.Femad" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1C554C0F.anr infected by "Trojan-Downloader.Win32.Ani.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1F7A5E0A.anr infected by "Trojan-Downloader.Win32.Ani.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\21D11B78.class infected by "Trojan.Java.Femad" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\247F0FD1.class infected by "Trojan.Java.ClassLoader.u" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2DDC24C6.anr infected by "Trojan-Downloader.Win32.Ani.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2DE622BB.anr infected by "Trojan-Downloader.Win32.Ani.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2E276A73.anr infected by "Trojan-Downloader.Win32.Ani.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2E5C0A3A.anr infected by "Trojan-Downloader.Win32.Ani.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3773240A.class infected by "Trojan.Java.Femad" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3C70560E.anr infected by "Trojan-Downloader.Win32.Ani.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3C70560E.class infected by "Trojan.Java.Femad" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3C772A07.class infected by "Trojan.Java.Femad" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3C7D7DFF.anr infected by "Trojan-Downloader.Win32.Ani.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3EE14431.htm infected by "Exploit.VBS.Phel.a" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\45AE3100.htm infected by "Exploit.VBS.Phel.a" Virus! Action Taken: No Action Taken.
File C:\Documents and
Eileanbeag
Active Member
 
Posts: 12
Joined: January 12th, 2006, 3:43 pm

Unread postby Susan528 » January 17th, 2006, 10:53 pm

STEP 1.
======
Online Virus Scans

Use IE to run at least two of these online virus scans (Or more if you wish.), Reboot after each scan:

If the above find things to clean, please re-run them to be sure the infections are gone. If not, please tell me what could not be cleared out.

STEP 2.
======
Trojan Hunter
[list]
[*] Download the free trial version of TrojanHunter
[*]Install (allow registry entry to be changed if necessary – THGuard) and update. You will get an evaluation notice – choose “Continue Evaluationâ€
User avatar
Susan528
MRU Master
MRU Master
 
Posts: 1594
Joined: April 4th, 2005, 9:20 am
Location: Alabama, USA

Unread postby Eileanbeag » January 19th, 2006, 3:54 pm

As My Computer is becoming more and more unstable I have decided to format - many thanks for all your help
Eileanbeag
Active Member
 
Posts: 12
Joined: January 12th, 2006, 3:43 pm

Unread postby Nick-YF19 » February 5th, 2006, 11:27 am

Glad we could be of assistance.

This topic is now closed. If you wish it
reopened, please send us an email to 'admin at malwareremoval.com' with a link to your thread.


You can help support this site from this link :
Donations For Malware Removal

Do not bother contacting us if you are not the topic starter. A valid,
working link to the closed topic is required along with the user name used.
If the user name does not match the one in the thread linked, the email will be deleted.
User avatar
Nick-YF19
Admin/Teacher Emeritus
 
Posts: 4036
Joined: May 17th, 2005, 12:42 am
Location: California
Advertisement
Register to Remove

Previous

  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 364 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware