This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

IS there anybody who knows what is TkBellExe

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This program (TkBellExe) try to access to Internet very often even when I disabled it from Zone Alarm. I remember it started to appear when I went to a website:

http://www.wzor.net/

and then Real Player opened with a pop up message. I never use Real Player so I thought it's was quite strange… Any ideas what is going on? Thanks for your cooperation in advance!


Logfile of HijackThis v1.99.1
Scan saved at 8:56:12 AM, on 1/1/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dantz\Retrospect 7.0\retrorun.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\FileAnt\FileAnt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\AutoSizer\AutoSizer.exe
C:\Program Files\Ashampoo\Ashampoo UnInstaller Platinum Suite\UIWatcher.exe
C:\Documents and Settings\Y0G\My Documents\Perso Download\Security\antiCWS\HijackThis.exe
C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe
C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe
C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe
C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe
C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer (SpywareBlaster from L)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat

7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: pdfMachine - {0E1230F8-EA50-42A9-983C-E22ABC2EED3F} - C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\bgstb.dll
O3 - Toolbar: Folder Pilot - {5CE1F973-16E2-49A1-BF2A-F4172C65509B} - C:\PROGRA~1\FOLDER~1\FOLDER~1.DLL
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [FileAnt] C:\Program Files\FileAnt\FileAnt.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [AutoSizer] "C:\Program Files\AutoSizer\AutoSizer.exe"
O4 - HKCU\..\Run: [UIWatcher] C:\Program Files\Ashampoo\Ashampoo UnInstaller Platinum Suite\UIWatcher.exe
O4 - HKCU\..\Run: [HijackThis startup scan] C:\Documents and Settings\Y0G\My Documents\Perso

Download\Security\antiCWS\HijackThis.exe /startupscan
O4 - Startup: Konfabulator.lnk = C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Download all by Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download by Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Download selected by Free Download Manager - file://C:\Program Files\Free Download

Manager\dlselected.htm
O8 - Extra context menu item: Download web site by Free Download Manager - file://C:\Program Files\Free Download

Manager\dlpage.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft

ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program

Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} -

C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

http://v5.windowsupdate.microsoft.com/v5co…b?1107089097316
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: DAGTQMHH - Sysinternals - www.sysinternals.com - C:\DOCUME~1\Y0G\LOCALS~1\Temp\DAGTQMHH.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive

Software\DiskeeperLite\DKService.exe
O23 - Service: GMD - Sysinternals - www.sysinternals.com - C:\DOCUME~1\Y0G\LOCALS~1\Temp\GMD.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common

Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect

7.0\retrorun.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

http://www.mikescomputerinfo.com/TkBellExe.htm


Siggyx, thank you for having taken some time to send me that information! I just read it and understand now that this problem is not too bad. Nevertheless, since my computer is behaving abnormally (some programs don't work anymore, sluggishness, etc.), I wonder if, according to my log, everything is ok…? Do you have any knowledge in that field…?
Step # 1

Please download and run CWShredder. Make sure that all browser windows are closed with the exception of Cwshredder and choose FIX.

http://www.majorgeeks.com/downloadget.php?…7fd6b3ff02edc90

REBOOT

Step #2

Please download and run Spybot 1.4 & AdAware SE Then follow the instructions in the link below to run.

Spybot & Adaware Tutorial

REBOOT

Step # 3

Then do a virus scan here >>> Trend Micro

Step # 4

Please download the trial version of Ewido Security Suite here:
http://www.ewido.net/en/download/

Install it, and update the definitions to the newest files.

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

Then please run Ewido, and run a full scan. Save the logfile from the scan.

Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan.
Siggyx, I finally managed to do what you had suggested me after having had some computer problems…

I had for example to uninstall my antivirus (AVG) and install another one, for instance F-Secure. But found that it was making my computer system slower. So, I decided to give a go instead to Kaspersky, but found now that it's even more slower and takes lots of my computer ressources. I am not very happy with it also! (Any suggestions for a powerful Antivirus which is light and fast…?)

In the testing that you suggested me to do, one Trojan was found by TrendMicro and then after having installed F-Secure and Kaspersky, both of them found four more Trojans but none of them were active in the sense that they were in compressed files that I had previously saved in my computer but never opened. I was very surprised that AVG did not find those, (nor Ad-Aware and Spybot)!

I haven't been able to find out how to get or make a logfile with Ewido, but nothing important (I think!) was found under my username, because they were only spyware cookies in Firefox…


Otherwise the result for HijackThis is as follow:

Logfile of HijackThis v1.99.1
Scan saved at 12:18:32 PM, on 1/6/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dantz\Retrospect 7.0\retrorun.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\FileAnt\FileAnt.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\AutoSizer\AutoSizer.exe
C:\Program Files\Ashampoo\Ashampoo UnInstaller Platinum Suite\UIWatcher.exe
C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe
C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe
C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe
C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe
C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe
C:\Documents and Settings\Y0G\My Documents\Perso Download\Security\antiCWS\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer (SpywareBlaster from L)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: pdfMachine - {0E1230F8-EA50-42A9-983C-E22ABC2EED3F} - C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\bgstb.dll
O3 - Toolbar: Folder Pilot - {5CE1F973-16E2-49A1-BF2A-F4172C65509B} - C:\PROGRA~1\FOLDER~1\FOLDER~1.DLL
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [FileAnt] C:\Program Files\FileAnt\FileAnt.exe
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [AutoSizer] "C:\Program Files\AutoSizer\AutoSizer.exe"
O4 - HKCU\..\Run: [UIWatcher] C:\Program Files\Ashampoo\Ashampoo UnInstaller Platinum Suite\UIWatcher.exe
O4 - Startup: Konfabulator.lnk = C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Download all by Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download by Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Download selected by Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download web site by Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1107089097316
O17 - HKLM\System\CCS\Services\Tcpip\..\{6754F810-C2B7-4E00-8362-C8579F909D7D}: NameServer = 213.154.95.126 213.154.64.13
O23 - Service: DAGTQMHH - Unknown owner - C:\DOCUME~1\Y0G\LOCALS~1\Temp\DAGTQMHH.exe (file missing)
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: GMD - Unknown owner - C:\DOCUME~1\Y0G\LOCALS~1\Temp\GMD.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect 7.0\retrorun.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Please download Asquared from the link below.

http://www.emsisoft.com/en/software/download/

Safe it to your desktop. Next open and check for updates.

Boot to safe mode (tap f8 while bios loads)

Then scan your system (this will take some time) after the scan is complete allow it to fix what it has found. If there is something that it can not clean please let me know what it was.

Then reboot and post a new hijackthis log.
This is a zip download so may go faster for you.

Download MicroWorld virus scan here >>> Micro World http://www.mwti.net/antivirus/free_utilities.asp

To run the virus scan make sure you click the following

memory, registry, startup folders, system folders, services, drive (all drives will be added) then click on scan clean. When the scan is complete hilight all the files in the LOWER box. Then ctrl + c and paste them into the thread ctrl + v.

I warn you the scan will take a long time to run and will not fix anything just identifies bad files.
VERY INTERESTING! Although MWAV is powered by Kaspersky it has found malwares that even Kaspersky didn't find… I CAN'T BELIEVE IT! 15 malwares (and many errors) were found. I was aware of 1 trojan only (kept in the !!!VIRUS!!! folder). I haven't done the scan in safe mode but yet MWAV founds them and mainly in my Thunderbird folders (original and backups). I found information about the "Email-Worm.Win32.Sober.k" which is not a good news, but the "Net-Worm.Win32.Mytob.bi" seems to be a much bigger threat …! But those malwares have been found in my emails only, so they were not active on my machine, isn't it ? What do you think Siggyx ? File C:\Documents and Settings\Y0G\Desktop\Thunderbird\Profiles\e0p1fp2n.default\ImapMail\mail.cotse.net\Sent infected by "Email-Worm.Win32.Sober.k" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\Y0G\Desktop\Thunderbird\Profiles\e0p1fp2n.default\ImapMail\mail.cotse.net\Spams infected by "Net-Worm.Win32.Mytob.bi" Virus! Action Taken: No Action Taken. Object "searchexe Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "free scratch and win Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "vx2 Spyware/Adware" found in File System! Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\BK Anju\Local Settings\Application Data\Microsoft\OFFICE\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\Konfabulator\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\Retrospect\". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".bac_a03824". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".bak". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".CH_". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".DS_Store". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".FBCIndex". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".GalleryItems". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".ms". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".part". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".pf". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".rjs". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".rjt". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".rnx". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".rp". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".rt". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".sd". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".sdp". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".xpi". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".xpt". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object "OpenWithList". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Adobe Photoshop 7.0". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Browser Hijack Blaster_is1". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Deer Park Alpha 2 (1.0+)". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB823559". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB828741". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB833987". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB834707-IE6-20040929.115007". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB835732". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB840987". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB841356". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB841533". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB842773". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB873376". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB887822". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Mozilla Firefox (1.0)". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Mozilla Firefox (1.0.4)". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Mozilla Firefox (1.0.6)". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Mozilla Thunderbird (1.0.2)". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "NetscapeRoboformPlugin". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q329048". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q329115". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q329170". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q329390". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q329441". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q329834". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q810577". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q810833". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q817606". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "RealPlayer 6.0". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Shareaza_is1". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Yahoo! Customizations". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Yahoo! Messenger". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Your Uninstaller! 2003_is1". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "ZoneAlarm". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{0AD5AD99-6172-4385-8765-385FBE3A1013}". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{333BECA0-DED8-4139-A516-8D9E44E22669}". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{3F381CAE-EE1C-4C24-B891-9ED092EF1E6F}". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{466ED896-E3CF-4DF3-B47E-39F74B8FC3C6}". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{7BF7B688-4A95-4003-BA98-EA8A79DA0ABA}". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{8C92D38B-C1DE-490A-B6D1-AAAA8E17DCE2}". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{989273D7-54A6-4E33-84A8-9FCEC33169EA}". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{9C2EDC9C-EF3B-443A-BB2C-3488DAC7247E}". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{A990EAA7-8941-4621-BC27-4F16261D3180}". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{AC76BA86-0000-7EC8-7489-000000000702}". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{AC76BA86-0000-7EC8-7489-000000000703}". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{B6F867E8-F092-4C5E-7D72-AC7057DBEF45}". Action Taken: No Action Taken. Entry "HKCR\CLSID\{0C5B0CED-206B-4c39-B615-0EB23C824612}" refers to invalid object "C:\Program Files\Common Files\Adobe\Shell\AIIcon.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{35E7AF47-1611-4F7C-87C9-C7FFDFA81C64}" refers to invalid object "C:\Program Files\Adobe\Photoshop 7.0\Photoshop.exe /StiDevice:%1 /StiEvent:%2". Action Taken: No Action Taken. Entry "HKCR\CLSID\{4C171D40-8277-11D5-AD55-00010333D0AD}" refers to invalid object "C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{52F2F130-2BC5-11D2-8FB7-000000000000}" refers to invalid object "C:\PROGRA~1\Adobe\PHOTOS~1.0\IMAGER~1.EXE". Action Taken: No Action Taken. Entry "HKCR\CLSID\{63E6BE14-A742-4EEA-8AF3-0EC39F10F850}" refers to invalid object "C:\PROGRA~1\Google\GOOGLE~1\GOOGLE~1.EXE". Action Taken: No Action Taken. Entry "HKCR\CLSID\{6719B01F-E5BC-4792-90F0-055A7AECF42D}" refers to invalid object "C:\Program Files\Ulead Systems\Ulead Photo Explorer 6.0\PE6.exe /StiDevice:%1 /StiEvent:%2". Action Taken: No Action Taken. Entry "HKCR\CLSID\{A2D4475B-C9AA-48E2-A029-1DB829DACF7B}" refers to invalid object "C:\PROGRA~1\Google\GOOGLE~1\GOOGLE~1.EXE". Action Taken: No Action Taken. Entry "HKCR\CLSID\{AD410D49-E330-4A22-9F8F-5DEF65CCF62B}" refers to invalid object "C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Apps\PhotoshopAlbum.exe -deviceConnect". Action Taken: No Action Taken. Entry "HKCR\CLSID\{AFD07A5E-3E20-4D77-825C-2F6D1A50BE5B}" refers to invalid object "C:\PROGRA~1\Google\GOOGLE~1\GOOGLE~1.EXE". Action Taken: No Action Taken. Entry "HKCR\CLSID\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96}" refers to invalid object "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE". Action Taken: No Action Taken. Entry "HKCR\.psd" refers to invalid object "Photoshop.Image.7". Action Taken: No Action Taken. Entry "HKCR\.wbmp" refers to invalid object "Photoshop.WBMFile". Action Taken: No Action Taken. Entry "HKCR\Alg.AlgSetup" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken. Entry "HKCR\Alg.AlgSetup.1" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken. Entry "HKCR\ComPlusMetaData.MsCorHost" refers to invalid object "{727CDF4F-3BA0-11D3-8738-00C04F79ED0D}". Action Taken: No Action Taken. Entry "HKCR\ComPlusMetaData.MsCorHost.2" refers to invalid object "{727CDF4F-3BA0-11D3-8738-00C04F79ED0D}". Action Taken: No Action Taken. Entry "HKCR\Connection Manager Profile\shell\open\command" refers to invalid object "C:\WINDOWS\System32\CMMGR32.EXE "%1"". Action Taken: No Action Taken. Entry "HKCR\MailFileAtt" refers to invalid object "{00020D05-0000-0000-C000-000000000046}". Action Taken: No Action Taken. Entry "HKCR\mapifvbx.object" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken. Entry "HKCR\mapifvbx.object.1" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken. Entry "HKCR\PhEdit-tst\shell\open\command" refers to invalid object "C:\Program Files\VCW VicMan's Photo Editor\vcwphoto.exe %1". Action Taken: No Action Taken. Entry "HKCR\PhEdit.jpg\shell\open\command" refers to invalid object "C:\Program Files\VCW VicMan's Photo Editor\vcwphoto.exe %1". Action Taken: No Action Taken. Entry "HKCR\Plenoptic.Plenoptic" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken. Entry "HKCR\Plenoptic.Plenoptic.1" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken. Entry "HKCR\RealJukebox.CDA.1\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.AIFF.6\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.AU.6\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.AVI.6\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.M4A.6\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.MP1.6\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.MP2.6\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.MP3.6\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.MP3PL.6\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RealPlayer.WAV.6\shell\open\command" refers to invalid object ""C:\Program Files\Real\RealPlayer\RealPlay.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\RTCCore.RTCClient" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken. Entry "HKCR\RTCCore.RTCClient.1" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken. Entry "HKCR\SpyDoctor.EBankProblem" refers to invalid object "{AE612304-E8F9-45D9-A444-32409D33E954}". Action Taken: No Action Taken. Entry "HKCR\SpyDoctor.QuarantinedItemProxy" refers to invalid object "{C2CE6266-0404-4C54-96B4-8829852E3537}". Action Taken: No Action Taken. Entry "HKCR\SpyDoctor.ScripterProxy" refers to invalid object "{9FEF02F5-B3B8-4D7B-8939-72A1C989D1B9}". Action Taken: No Action Taken. Entry "HKCR\sunasDtServ.Agent" refers to invalid object "{ABA6B35D-3F5E-44E5-9FE2-F0E02720EC42}". Action Taken: No Action Taken. Entry "HKCR\sunasDtServ.AgentDataStore" refers to invalid object "{E09B7103-05F6-4FA0-A244-AFCCB0668E3E}". Action Taken: No Action Taken. Entry "HKCR\sunasDtServ.Agents" refers to invalid object "{6F888DC4-15EF-4E58-9A87-71713BB3A7AE}". Action Taken: No Action Taken. Entry "HKCR\sunasDtServ.Common" refers to invalid object "{0EBBE452-CBF3-41D9-9FBF-4B07B2943FBE}". Action Taken: No Action Taken. Entry "HKCR\sunasDtServ.DataStore" refers to invalid object "{F8564792-D478-4162-8F07-7B6F9A4D7D5F}". Action Taken: No Action Taken. Entry "HKCR\sunasDtServ.EventObject" refers to invalid object "{F3F07A51-A7CF-45DC-B8A2-9719758A7121}". Action Taken: No Action Taken. Entry "HKCR\sunasDtServ.Events" refers to invalid object "{3C28D6C7-297F-4687-814C-1C1BC47B289A}". Action Taken: No Action Taken. Entry "HKCR\sunasDtServ.Explorer" refers to invalid object "{444598CA-89F4-4CCB-98F7-8D412125CBEB}". Action Taken: No Action Taken. Entry "HKCR\sunasDtServ.Explorers" refers to invalid object "{DABC9585-5791-4C38-A33F-BB0C77A9A4B8}". Action Taken: No Action Taken. Entry "HKCR\sunasDtServ.Inoculation" refers to invalid object "{D1A69F54-E98A-4EAF-AD49-7DE6F9352D76}". Action Taken: No Action Taken. Entry "HKCR\sunasDtServ.Inoculations" refers to invalid object "{CA976C94-AFE1-4E59-AC3C-00DEF093687C}". Action Taken: No Action Taken. Entry "HKCR\sunasDtServ.ManagedApps" refers to invalid object "{58C12E25-66BE-4D84-868C-2008CC427497}". Action Taken: No Action Taken. Entry "HKCR\sunasDtServ.ManagedAppsExe" refers to invalid object "{2A58F9BD-518B-4080-B964-B849B58EC93D}". Action Taken: No Action Taken. Entry "HKCR\sunasDtServ.ManagedAppsExes" refers to invalid object "{15F7410F-4AE9-47FB-8A9B-D1447279128D}". Action Taken: No Action Taken. Entry "HKCR\sunasDtServ.ManagedAppsKey" refers to invalid object "{C3AA846C-5F18-47D2-940E-BFFA81A941AE}". Action Taken: No Action Taken. Entry "HKCR\sunasDtServ.ManagedAppsKeys" refers to invalid object "{05D4EC19-D02F-4CFD-A7DB-0D15F9A77AC5}". Action Taken: No Action Taken. Entry "HKCR\sunasDtServ.Manager" refers to invalid object "{C08637C7-7379-46BB-868E-63BBC830EEDC}". Action Taken: No Action Taken. Entry "HKCR\sunasDtServ.Quarantine" refers to invalid object "{E7963E69-0830-44A3-BDFA-7582869EB93A}". Action Taken: No Action Taken. Entry "HKCR\sunasDtServ.QuarantineContainer" refers to invalid object "{C8E26BB0-588A-4EC1-9342-8E756B147B46}". Action Taken: No Action Taken. Entry "HKCR\sunasDtServ.QuarantineItem" refers to invalid object "{50A4066C-971D-4F1E-84BC-90D43D723DDE}". Action Taken: No Action Taken. Entry "HKCR\sunasDtServ.ResourceStore" refers to invalid object "{5794C642-4E53-4C3E-84B3-02A615B6B137}". Action Taken: No Action Taken. Entry "HKCR\sunasDtServ.Schedule" refers to invalid object "{8B3BD3F5-2C0F-4B2B-9407-C726C7DFB5DC}". Action Taken: No Action Taken. Entry "HKCR\sunasDtServ.ScheduleScans" refers to invalid object "{66719EB5-1F77-429A-BFEE-23B3DF7793AE}". Action Taken: No Action Taken. Entry "HKCR\sunasDtServ.Session" refers to invalid object "{703F1CB1-5E95-41EB-B841-07348D780885}". Action Taken: No Action Taken. Entry "HKCR\sunasDtServ.ThreatData" refers to invalid object "{97641301-0964-42A0-A0A0-B725965CBD87}". Action Taken: No Action Taken. Entry "HKCR\sunasDtServ.UpdateSchedule" refers to invalid object "{6476E647-EBEB-4DBD-8339-5DCC0611593B}". Action Taken: No Action Taken. Entry "HKCR\SymWriter.pdb" refers to invalid object "{520DC67A-752E-11D3-8D56-00C04F680B2B}". Action Taken: No Action Taken. Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken. Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr.1" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken. Entry "HKCR\WMPShell.HWEventHandler" refers to invalid object "{9B186A8F-F520-4eeb-B553-118304AC46C5}". Action Taken: No Action Taken. Entry "HKCR\WMPShell.HWEventHandler.1" refers to invalid object "{9B186A8F-F520-4eeb-B553-118304AC46C5}". Action Taken: No Action Taken. Entry "HKCR\YAlertCenter.YAlert" refers to invalid object "{97D85205-80CF-4b71-90A5-D220DA4FEE58}". Action Taken: No Action Taken. Entry "HKCR\YAlertCenter.YAlert.1" refers to invalid object "{97D85205-80CF-4b71-90A5-D220DA4FEE58}". Action Taken: No Action Taken. Entry "HKCR\YbSkin.YbButtonX" refers to invalid object "{B448FAA5-DC36-4C3D-9436-67021CDECA82}". Action Taken: No Action Taken. Entry "HKCR\YbSkin.YbButtonX.1" refers to invalid object "{B448FAA5-DC36-4C3D-9436-67021CDECA82}". Action Taken: No Action Taken. Entry "HKCR\YbSkin.YbImage" refers to invalid object "{E4528244-55B0-4FBC-B27E-26851B634D02}". Action Taken: No Action Taken. Entry "HKCR\YbSkin.YbImage.1" refers to invalid object "{E4528244-55B0-4FBC-B27E-26851B634D02}". Action Taken: No Action Taken. Entry "HKCR\YbSkin.YbImgX" refers to invalid object "{E7EEC168-A4C4-42C6-8601-B02816959B24}". Action Taken: No Action Taken. Entry "HKCR\YbSkin.YbImgX.1" refers to invalid object "{E7EEC168-A4C4-42C6-8601-B02816959B24}". Action Taken: No Action Taken. Entry "HKCR\YbSkin.YbSkin" refers to invalid object "{3D5D83B0-47DC-4862-93D6-3E827A14AED1}". Action Taken: No Action Taken. Entry "HKCR\YbSkin.YbSkin.1" refers to invalid object "{3D5D83B0-47DC-4862-93D6-3E827A14AED1}". Action Taken: No Action Taken. Entry "HKCR\YbSkinSelect.SkinSelector" refers to invalid object "{2018C303-E3F2-4455-AA1A-773F84F10902}". Action Taken: No Action Taken. Entry "HKCR\YbSkinSelect.SkinSelector.1" refers to invalid object "{2018C303-E3F2-4455-AA1A-773F84F10902}". Action Taken: No Action Taken. Entry "HKCR\YInstHelper.YInstStarter" refers to invalid object "{30528230-99F7-4BB4-88D8-FA1D4F56A2AB}". Action Taken: No Action Taken. Entry "HKCR\YInstHelper.YInstStarter.1" refers to invalid object "{30528230-99F7-4BB4-88D8-FA1D4F56A2AB}". Action Taken: No Action Taken. Entry "HKCR\YInstHelper.YInstStarterUpgrade" refers to invalid object "{0291E591-EA41-4c82-8106-3DC6CE7F7664}". Action Taken: No Action Taken. Entry "HKCR\YInstHelper.YInstStarterUpgrade.1" refers to invalid object "{0291E591-EA41-4c82-8106-3DC6CE7F7664}". Action Taken: No Action Taken. Entry "HKCR\YInstHelper.YSearchSetting2" refers to invalid object "{347B0667-C7ED-429B-BDE3-CC8D3BACAA31}". Action Taken: No Action Taken. Entry "HKCR\YInstHelper.YSearchSetting2.1" refers to invalid object "{347B0667-C7ED-429B-BDE3-CC8D3BACAA31}". Action Taken: No Action Taken. Entry "HKCR\ymsgr\shell\open\command" refers to invalid object ""C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" %1". Action Taken: No Action Taken. File C:\Documents and Settings\Y0G\Application Data\Thunderbird\Profiles\e0p1fp2n.default\ImapMail\mail.cotse.net\INBOX infected by "Email-Worm.Win32.Sober.y" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\Y0G\Application Data\Thunderbird\Profiles\e0p1fp2n.default\ImapMail\mail.cotse.net\Sent infected by "Email-Worm.Win32.Sober.k" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\Y0G\Application Data\Thunderbird\Profiles\e0p1fp2n.default\ImapMail\mail.cotse.net\Spam infected by "Email-Worm.Win32.Sober.y" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\Y0G\Application Data\Thunderbird\Profiles\e0p1fp2n.default\ImapMail\mail.cotse.net\Temp infected by "Email-Worm.Win32.Sober.y" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\Y0G\Desktop\Thunderbird\Profiles\e0p1fp2n.default\ImapMail\mail.cotse.net\Sent infected by "Email-Worm.Win32.Sober.k" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\Y0G\Desktop\Thunderbird\Profiles\e0p1fp2n.default\ImapMail\mail.cotse.net\Spams infected by "Net-Worm.Win32.Mytob.bi" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\Y0G\My Documents\!!!VIRUS!!!\Direct Folders info.rar infected by "Trojan-Clicker.Win32.Delf.eg" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\Y0G\My Documents\LM\Settings (Backup)\BackupFox\Thunderbird\Y0G_2005-09-11.thunderbird infected by "Email-Worm.Win32.Sober.k" Virus! Action Taken: No Action Taken.
Please download and run Stinger >>>> http://vil.nai.com/vil/stinger/

Next

Download L2mfix from one of these two locations:

http://www.atribune.org/downloads/l2mfix.exe
http://www.downloads.subratam.org/l2mfix.exe

Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so! This Fix must NOT be run in safe mode for it to work.

if you receive, while running option #1, an error similar like: ''C:\windows\system32\cmd.exe
C:\windows\system32\autoexec.nt the system file is not suitable for running ms-dos and microsoft windows applications. choose close to terminate the application.."…then please use option 5 or the web page link in the l2mfix folder to solve this error condition. do not run the fix portion without fixing this first.
Done! Stinger has found 6 infected files: C:/Documents and Settings:/…/Thunderbird/…/Spam/reg_pass-data.zip/FILE PACKED_DATAINFO.EXE Found W32/SOBER@MM:M681 virus !!! C:/Documents and Settings:/…/Thunderbird/…/Spam/reg_pass-data.zip/FILE PACKED_DATAINFO.EXE Found W32/SOBER@MM:M681 virus !!! C:/Documents and Settings:/…/Thunderbird/…/Spam/reg_pass-data.zip/FILE PACKED_DATAINFO.EXE Found W32/SOBER@MM:M681 virus !!! C:/Documents and Settings:/…/Thunderbird/…/Spam could not be repaired C:/Documents and Settings:/…/Thunderbird/…/Temp/reg_pass-data.zip/FILE PACKED_DATAINFO.EXE Found W32/SOBER@MM:M681 virus !!! C:/Documents and Settings:/…/Thunderbird/…/Temp/mail_body.zip/FILE PACKED_DATAINFO.EXE Found W32/SOBER@MM:M681 virus !!! C:/Documents and Settings:/…/Thunderbird/…/Temp/mail_body.zip/FILE PACKED_DATAINFO.EXE Found W32/SOBER@MM:M681 virus !!! C:/Documents and Settings:/…/Thunderbird/…/Temp could not be repaired Since I couldn't copy or find the log for the Stinger scan, I manually wrote it (hope I haven't made mistakes). If needed, I captured an image from it. I have read (after doing the scan) that I should have had disabled the System Restore Utility to remove the infected files, but I haven't done so… Is it ok Siggyx or should I do it again? Here below is the l2mfix log: L2MFIX find log 010406 These are the registry keys present ********************************************************************************** Winlogon/notify: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "Logoff"="ChainWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Logoff"="CryptnetWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] "DLLName"="cscdll.dll" "Logon"="WinlogonLogonEvent" "Logoff"="WinlogonLogoffEvent" "ScreenSaver"="WinlogonScreenSaverEvent" "Startup"="WinlogonStartupEvent" "Shutdown"="WinlogonShutdownEvent" "StartShell"="WinlogonStartShellEvent" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] "DLLName"="wlnotify.dll" "Logon"="SCardStartCertProp" "Logoff"="SCardStopCertProp" "Lock"="SCardSuspendCertProp" "Unlock"="SCardResumeCertProp" "Enabled"=dword:00000001 "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Impersonate"=dword:00000000 "StartShell"="SchedStartShell" "Logoff"="SchedEventLogOff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] "Logoff"="WLEventLogoff" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] "DLLName"="WlNotify.dll" "Lock"="SensLockEvent" "Logon"="SensLogonEvent" "Logoff"="SensLogoffEvent" "Safe"=dword:00000001 "MaxWait"=dword:00000258 "StartScreenSaver"="SensStartScreenSaverEvent" "StopScreenSaver"="SensStopScreenSaverEvent" "Startup"="SensStartupEvent" "Shutdown"="SensShutdownEvent" "StartShell"="SensStartShellEvent" "PostShell"="SensPostShellEvent" "Disconnect"="SensDisconnectEvent" "Reconnect"="SensReconnectEvent" "Unlock"="SensUnlockEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Impersonate"=dword:00000000 "Logoff"="TSEventLogoff" "Logon"="TSEventLogon" "PostShell"="TSEventPostShell" "Shutdown"="TSEventShutdown" "StartShell"="TSEventStartShell" "Startup"="TSEventStartup" "MaxWait"=dword:00000258 "Reconnect"="TSEventReconnect" "Disconnect"="TSEventDisconnect" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] "DLLName"="wlnotify.dll" "Logon"="RegisterTicketExpiredNotificationEvent" "Logoff"="UnregisterTicketExpiredNotificationEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 ********************************************************************************** useragent: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] "SV1"="" ********************************************************************************** Shell Extension key: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved] "{21569614-B795-46b1-85F4-E737A8DC09AD}"="Shell Search Band" "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension" "{1C071B19-C260-41C8-BFC1-4B1353203678}"="bxFP" ********************************************************************************** HKEY ROOT CLASSIDS: ********************************************************************************** Files Found are not all bad files: C:\WINDOWS\SYSTEM32\ browseui.dll Thu Nov 24 2005 1:06:34a A…. 1,022,464 998.50 K cdfview.dll Fri Oct 21 2005 3:39:26a A…. 151,040 147.50 K danim.dll Sat Nov 5 2005 3:16:24a A…. 1,054,208 1.00 M dxtrans.dll Fri Oct 21 2005 3:39:28a A…. 205,312 200.50 K esent.dll Thu Oct 20 2005 10:20:04p A…. 1,082,368 1.03 M extmgr.dll Fri Oct 21 2005 3:39:28a ….. 55,808 54.50 K gdi32.dll Thu Dec 29 2005 2:54:36a A…. 280,064 273.50 K iepeers.dll Fri Oct 21 2005 3:39:28a A…. 251,392 245.50 K inseng.dll Fri Oct 21 2005 3:39:28a A…. 96,256 94.00 K mshtml.dll Thu Nov 24 2005 1:06:34a A…. 3,015,680 2.88 M mshtmled.dll Fri Oct 21 2005 3:39:30a A…. 448,512 438.00 K msrating.dll Fri Oct 21 2005 3:39:30a A…. 146,432 143.00 K mstime.dll Fri Oct 21 2005 3:39:30a A…. 530,944 518.50 K openpo~1.dll Thu Oct 20 2005 3:37:00p A…. 24,924 24.34 K pngfilt.dll Fri Oct 21 2005 3:39:30a A…. 39,424 38.50 K px.dll Mon Dec 5 2005 5:12:26a ….. 339,968 332.00 K pxdrv.dll Mon Dec 5 2005 5:12:26a ….. 405,504 396.00 K pxmas.dll Mon Dec 5 2005 5:12:26a ….. 172,032 168.00 K pxwave.dll Mon Dec 5 2005 5:12:26a ….. 339,968 332.00 K sdelete.dll Thu Oct 20 2005 3:37:00p A…. 40,960 40.00 K shdocvw.dll Thu Dec 1 2005 3:59:30a A…. 1,492,480 1.42 M shlwapi.dll Fri Oct 21 2005 3:39:30a A…. 473,600 462.50 K spmsg.dll Wed Oct 12 2005 11:12:26p ….. 14,048 13.72 K urlmon.dll Sat Nov 5 2005 3:16:28a A…. 609,280 595.00 K vsdata.dll Tue Nov 15 2005 12:50:30a A…. 83,720 81.76 K vsinit.dll Tue Nov 15 2005 12:50:42a A…. 141,064 137.76 K vsmonapi.dll Tue Nov 15 2005 12:50:52a A…. 104,208 101.77 K vspubapi.dll Tue Nov 15 2005 12:50:56a A…. 227,088 221.77 K vsregexp.dll Tue Nov 15 2005 12:51:00a A…. 71,440 69.77 K vsutil.dll Tue Nov 15 2005 12:51:12a A…. 382,728 373.76 K vsxml.dll Tue Nov 15 2005 12:51:20a A…. 100,104 97.76 K vxblock.dll Mon Dec 5 2005 5:12:26a ….. 28,672 28.00 K wininet.dll Fri Oct 21 2005 3:39:30a A…. 658,432 643.00 K zlcomm.dll Tue Nov 15 2005 12:51:40a A…. 79,624 77.76 K zlcommdb.dll Tue Nov 15 2005 12:51:44a A…. 71,440 69.77 K 35 items found: 35 files, 0 directories. Total of file sizes: 14,241,188 bytes 13.58 M Locate .tmp files: No matches found. ********************************************************************************** Directory Listing of system files: Volume in drive C has no label. Volume Serial Number is 98BF-44A0 Directory of C:\WINDOWS\System32 10/22/2005 05:17 AM dllcache 01/30/2005 01:20 PM Microsoft 0 File(s) 0 bytes 2 Dir(s) 6,169,591,808 bytes free
Close any programs you have open since this step requires a reboot.

From the l2mfix folder on your desktop, double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing enter. It will process then start. Your desktop and icons will disappear (this is normal). L2mfix will continue to scan your computer and when it's finished, it will be ready for a reboot. Press any key to reboot. After the reboot notepad will open with a log. Copy the contents of that log and paste it back into this thread, along with a new hijackthis log.

IMPORTANT: Do NOT run any other files in the l2mfix folder unless you are asked to do so! Do Not run in safe mode!!
If after the reboot the log does not open double click on it in the l2mfix folder.
DONE!



L2mfix 010406
Creating Account.
The command completed successfully.

Adding Administrative privleges.
The command completed successfully.
Checking for L2MFix account(0=no 1=yes):
1
Granting SeDebugPrivilege to L2MFIX … successful

Running From:
C:\WINDOWS\system32

Killing Processes!

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Killing PID 624 'smss.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Killing PID 716 'winlogon.exe'
Killing PID 716 'winlogon.exe'
Killing PID 716 'winlogon.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Killing PID 232 'explorer.exe'
Killing PID 232 'explorer.exe'
Killing PID 232 'explorer.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Error, Cannot find a process with an image name of rundll32.exe
Restoring Sedebugprivilege:
Granting SeDebugPrivilege to Administrators … successful

Scanning First Pass. Please Wait!

First Pass Completed

Second Pass Scanning

Second pass Completed!



Restoring Windows Update Certificates.:

The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


The following are the files found:
****************************************************************************

Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"SV1"=""
****************************************************************************
Desktop.ini Contents:
****************************************************************************

****************************************************************************
Checking for L2MFix account(0=no 1=yes):
0
Zipping up files for submission:
zip warning: name not matched: dlls\*.*

zip error: Nothing to do! (backup.zip)
adding: backregs/notibac.reg (140 bytes security) (deflated 87%)





AND THE HIJACKTHIS:





Logfile of HijackThis v1.99.1
Scan saved at 7:22:25 AM, on 1/13/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dantz\Retrospect 7.0\retrorun.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AutoSizer\AutoSizer.exe
C:\Program Files\Ashampoo\Ashampoo UnInstaller Platinum Suite\UIWatcher.exe
C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe
C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe
C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe
C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe
C:\Documents and Settings\Y0G\My Documents\Perso Download\Security\antiCWS\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer (SpywareBlaster from L)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: pdfMachine - {0E1230F8-EA50-42A9-983C-E22ABC2EED3F} - C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\bgstb.dll
O3 - Toolbar: Folder Pilot - {5CE1F973-16E2-49A1-BF2A-F4172C65509B} - C:\PROGRA~1\FOLDER~1\FOLDER~1.DLL
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AutoSizer] "C:\Program Files\AutoSizer\AutoSizer.exe"
O4 - HKCU\..\Run: [UIWatcher] C:\Program Files\Ashampoo\Ashampoo UnInstaller Platinum Suite\UIWatcher.exe
O4 - Startup: Konfabulator.lnk = C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1107089097316
O23 - Service: DAGTQMHH - Unknown owner - C:\DOCUME~1\Y0G\LOCALS~1\Temp\DAGTQMHH.exe (file missing)
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: GMD - Unknown owner - C:\DOCUME~1\Y0G\LOCALS~1\Temp\GMD.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect 7.0\retrorun.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI