This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Registry issue

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I do clean up my pc on a fairly regular basis. Spybot is set to run each evening and recently has been kicking up this registry entry that is supposedly to do with Bear Share:


Bearshare: Class ID (Registry key, fixing failed)
HKEY_CLASSES_ROOT\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}



When checking out this key with regedit, this is in the drill down under the CLSID entry:

InprocServer32



Clicking on the InprocServer32 entry throws a warning box saying that

Cannot open InprocServer32: Error while opening key.



Clicking {558EC983-BEDB-9168-B2DE-31DBF0EE543E} and looking in the right hand pane, I see 2 entries:
(Default) REG_Z WMPlayer WMXEditor Class
htbjoaq REG_BINARY a3 3f 48 b3….. and on and on and on……


Should I just ignore this or should it be addressed? TIA for any input and I will include a Hijackthis log below fyi:

Logfile of HijackThis v1.99.1
Scan saved at 3:21:29 PM, on 12/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
e:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\crypserv.exe
E:\Program Files\security suite\ewidoctrl.exe
C:\Program Files\GM SPO\eSI\Apache Group\Tomcat 4.1\bin\tomcat.exe
C:\Program Files\GM SPO\eSI\Transbase\tbmux32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\GM SPO\eSI\Transbase\tbkern32.exe
C:\Program Files\GM SPO\eSI\Transbase\tbkern32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
E:\Program Files\apple\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
E:\Program Files\ClocX\ClocX.exe
E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\iPod\bin\iPodService.exe
E:\Program Files\Spyware\Spybot - Search & Destroy\TeaTimer.exe
E:\RocketDock\RocketDock.exe
E:\Program Files\Spamihilator\spamihilator.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Gigabyte\Gigabyte Windows Utility Manager\gwum.exe
C:\WINDOWS\system32\svchost.exe
E:\PROGRA~1\Office10\OUTLOOK.EXE
E:\Program Files\Office10\WINWORD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Jack\Desktop\Maintenance\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\Spyware\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] E:\Program Files\apple\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [ClocX] E:\Program Files\ClocX\ClocX.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [SpybotSD TeaTimer] E:\Program Files\Spyware\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [RocketDock] "E:\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [Spamihilator] "e:\Program Files\Spamihilator\spamihilator.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Shortcut to RKLauncher.exe.lnk.disabled
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: gwum.lnk = C:\Program Files\Gigabyte\Gigabyte Windows Utility Manager\gwum.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - E:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - E:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - E:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} (Dldrv2 Control) - http://210.80.76.119/object/Dldrv.ocx
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097537867716
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - e:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: ewido security suite control - ewido networks - E:\Program Files\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - E:\Program Files\SiSoftware Sandra Standard 2004.SP2 (Win32 x86)\SiSoftware Sandra Lite 2005.SR3\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - E:\Program Files\SiSoftware Sandra Standard 2004.SP2 (Win32 x86)\SiSoftware Sandra Lite 2005.SR3\RpcSandraSrv.exe
O23 - Service: SI Tomcat (SITomcat) - Alexandria Software Consulting - C:\Program Files\GM SPO\eSI\Apache Group\Tomcat 4.1\bin\tomcat.exe
O23 - Service: SI Transbase (SITransbase) - TransAction Software, D 81737 Munich - C:\Program Files\GM SPO\eSI\Transbase\tbmux32.exe
http://forums.spybot.info/archive/index.php/t-6222.html

I saw this post. LonnyRJones is very respected. I am not sure from looking whether it may be a glitch with SpyBot since the entry was not removed.

Evidently the entry is harmless. If it is a glitch, it may be difficult to fix.

If you want to try to remove it let's first check to locate the entry.

STEP 1.
======
Regscan

Please download RegScan.
Within RegScan.zip you will find the file regscan.vbs
You may have to allow this script to run or disable anti-spyware again in order for it to run.
A window will open titled RegFinder.vbs and you will see place to input search terms.
Please enter the search terms:
558EC983-BEDB-9168-B2DE-31DBF0EE543E
After the search has completed a window titled Results.txt will open.
Please copy the results and post(reply) back.
The key is not that hard to find with regedit…. I found out that there are no permissions allotted for this key either so its no wonder that I cannot access it. I've not had a lot to do with the registry, but I have done some so I know my way around a bit. I set up Spybot to ignore this entry during its scans so the message is no longer displayed in the morning, but of course the key is still there…… I would guess back up, change permissions, and then delete the key….. what do you think? Thanks for the help! Here is the result of the scan tool you requested: _________________________________________________ Windows Registry Editor Version 5.00 ; Regscan.vbs Version: 1.2 by rand1038 ; 1/3/2007 7:15:46 AM ; Search Term(s) Used: "558EC983-BEDB-9168-B2DE-31DBF0EE543E" ; 1 matches were found. ; The search took 58 seconds. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}] _________________________________________________ So, does this tell me that there are 2 instances of this? I find one at: HKEY_CLASSES_ROOT\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E} And one at: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}] In Regedit these 2 locations both have the same key and drill down
Backup the registry:

STEP 1.
======
Backup Your Registry with ERUNT
  • Please use the following link and scroll down to ERUNT and download it.
    http://aumha.org/freeware/freeware.php
  • For version with the Installer:
    Use the setup program to install ERUNT on your computer
  • For the zipped version:
    Unzip all the files into a folder of your choice.
Click Erunt.exe to backup your registry to the folder of your choice.

Note: to restore your registry, go to the folder and start ERDNT.exe

Then, go to start–>run

and type this in:
notepad

Paste this into the box:

REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E}]
Then click on the FILE menu and select save as
Save the file as regfix.reg. Save the file to the desktop.
IMPORTANT: make sure to save the file as "all types" and NOT as a text file
**

Now double click on regfix.reg and insert it into the registry.

Now let me know if SpyBot finds this entry again or you can try the previous step and let me know if 558EC983-BEDB-9168-B2DE-31DBF0EE543E was found.
I did just as you said…. created the reg file and executed it. I was asked if I wanted to enter this info to the registry and I said yes. Then I rebooted just in case. Spybot still finds the entry….. Looking through regedit and that entry is still there.

I would guess back up, change permissions, and then delete the key….. what do you think?


I am guessing that you need back up, to take ownership (permissions) and then delete it. I think the permissions is the problem.

Have you tried that already?
No I havent tried changing permissions yet. I will read up on how to restore the registry with this program and then give it a go tomorrow. Hopefully I can run that program and restore the registry from safe mode if needed, or from a boot disk or something….. Will post back with my results. Thanks for the help so far! Question though: Should I delete - HKEY_CLASSES_ROOT\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E} or just InprocServer32 Or both ?? (please see my first post) InprocServer32 is the one with missing permissions and is the drill down for HKEY_CLASSES_ROOT\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E} I can access HKEY_CLASSES_ROOT\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E} with no trouble and it has permissions set.
No Joy First, tried to delete HKEY_CLASSES_ROOT\CLSID\{558EC983-BEDB-9168-B2DE-31DBF0EE543E} but it gave me a no access violation. Next I tried to delete InprocServer32 Same thing Next I changed permissions for InprocServer32 to 'everyone' full control/read just as the others have. I was able to change the value but not save it. Same access violation…. or permission thing. Next I booted into safe mode and tried changing permissions and deletion there, same thing. I guess its not a big deal since I can tell Spybot to ignore it but I still know ithat its there ya know? Kinda like trying to leaving a hangnail alone….. LOL
Hello jrjr, Please try this. I would like you to uninstall SpyBot Search and Destroy. Then please repeat my instructions in Post #6. Let me know if this gets rid of the entry. If it does please let me know. Then reinstall SpyBot Search and Destroy.
Spybot uninstalled and then ran the reg file. Regedit still shows the entry. Reinstall and run Spybot and it still finds it. Aggravating eh?
Yes, it must be aggravating. I am curious as to what you have installed.

STEP 1.
======
Uninstall Manager

Let's see if we can find out what it got installed with.
  • Open HijackThis
  • Click on the configure button on the bottom right
  • Click on the tab "Misc Tools"
  • Click on the Box that says "Uninstall Manager"
  • Click on the button "Save list"
  • Copy and past the List from notepad into your post
I had installed a couple different versions of Bear Share and then removed them but that was over a year ago and this entry only surfaced in Spybot less than a month ago. Nothing noteworthy was installed in the same time frame but here is the log you asked for: @BIOS 3DMark03 Ad-Aware SE Personal Adobe Photoshop 7.0 Adobe Reader 7.0.8 AOL Instant Messenger Araneae 5.0.0 ATI Display Driver (Omega 3.8.221) AVG Anti-Spyware 7.5 AVG Free Edition Baxter Stationery Boomerang Stationery CCleaner (remove only) ClocX (1.4) Core FTP LE 1.3c CutePDF Writer 2.2 Dark River Stationery DivX DivX Player Doom 3 Driver Cleaner 3 EasyTune4 eMusic - 50 Free MP3 offer Enable S3 for USB Device EPSON Printer Software EPSON TWAIN 5 EVEREST Home Edition v1.10 ewido security suite FEARCombat FMS FrostWire [removed] BETA Gigabyte Face Wizard Gigabyte Windows Utility Manager Haunted Mansion HighMAT Extension to Microsoft Windows XP CD Writing Wizard HijackThis 1.99.1 Home Plan Pro for Windows 95/98/00/ME/NT/XP hp deskjet 930c series (Remove only) ICQ Image Resizer Powertoy for Windows XP Intel® 537EP Data Fax Modem iTunes J2SE Runtime Environment 5.0 Update 10 J2SE Runtime Environment 5.0 Update 2 J2SE Runtime Environment 5.0 Update 4 J2SE Runtime Environment 5.0 Update 6 JAlbum Java 2 Runtime Environment, SE v1.4.2_05 Java 2 Runtime Environment, SE v1.4.2_06 K9 Logitech Gaming Software Macromedia Dreamweaver MX Macromedia Extension Manager Macromedia Fireworks MX Macromedia Flash MX Macromedia Flash Player 8 Macromedia FreeHand 10 Macromedia Shockwave Player Marvell Miniport Driver Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB886903) Microsoft Forest Floor Stationery Microsoft Halo Microsoft Office Professional Edition 2003 Microsoft Office XP Professional with FrontPage Microsoft Text-to-Speech Engine 4.0 (English) Microsoft Visual Basic 6.0 Enterprise Edition Microsoft Web Publishing Wizard 1.53 Mozilla Firefox (2.0.0.1) MSN Music Assistant MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 Parser and SDK MultiRes (remove only) My Kitchen Stationery NTI CD-Maker Gold OneTouch Version 3.0 Opera 9.02 Paint Shop Pro 7 ESD PaperPort 7.02 QuickTime Radeon Omega Drivers v3.8.221 Setup Files and Tools RealPlayer Realtek AC'97 Audio RocketDock 1.2.5 Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB883939) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB896688) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899588) Security Update for Windows XP (KB899589) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB903235) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB905915) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB908531) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912812) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913446) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922760) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB925454) Security Update for Windows XP (KB925486) Security Update for Windows XP (KB926255) SI Data SIen v2004.19 SI Stand-alone application SI Tiff Viewer Plugin v4 SiSoftware Sandra Lite 2005.SR3 (Win64/32/CE) SiSoftware Sandra Standard 2004.SP2 (Win32 x86) SpamBayes 1.0.4 Spybot - Search & Destroy 1.4 SpywareBlaster v3.5.1 SWiSH v2.0 SWiSHmax Tweak UI Update for Windows XP (KB894391) Update for Windows XP (KB896727) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB916595) Update for Windows XP (KB917425) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Virtual RC Racing WeatherBug Winamp (remove only) Windows Genuine Advantage v1.3.0254.0 Windows Installer 3.1 (KB893803) Windows Installer 3.1 (KB893803) Windows Live Messenger Windows Media Format Runtime Windows Media Player 10 Windows XP Hotfix - KB834707 Windows XP Hotfix - KB867282 Windows XP Hotfix - KB873333 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB885884 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890047 Windows XP Hotfix - KB890175 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB890923 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB893066 Windows XP Hotfix - KB893086 Windows XP Service Pack 2 WinRAR archiver WinZip

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI