Author Topic: computer slow, desktop hijacker & daosearch  (Read 8160 times)

Offline rmccabe

  • Jr. Member
  • **
  • Posts: 59
  • Karma: +0/-0
    • View Profile
computer slow, desktop hijacker & daosearch
« on: June 12, 2005, 07:17:10 PM »
her is my hijack log.  it took forever to get this on my computer. I had clicksearchclick.  Don't think i do anymore.  Spysweeper got rid of it, I think.

Logfile of HijackThis v1.99.1
Scan saved at 3:57:39 PM, on 6/12/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SPOOLSRV32.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\CLGAMMA.EXE
C:\WINDOWS\SYSTEM\USBMONIT.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\HJT\HIJACKTHIS.EXE

F1 - win.ini: run=hpfsched
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ColorCorrection] C:\WINDOWS\CLGAMMA.EXE
O4 - HKLM\..\Run: [Gene USB Monitor] C:\WINDOWS\SYSTEM\USBMonit.exe
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NAVAPW32.EXE /LOADQUIET
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [Srv32 spool service] C:\WINDOWS\System\spoolsrv32.exe
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SPYSWEEPER.EXE" /0
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Microsoft AntiSpyware helper - {2EFB63E0-BCE5-11D9-8F50-444553540000} - C:\WINDOWS\SYSTEM\WLDR.DLL (file missing)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {2EFB63E0-BCE5-11D9-8F50-444553540000} - C:\WINDOWS\SYSTEM\WLDR.DLL (file missing)
O9 - Extra button: Microsoft AntiSpyware helper - {2EFB63E0-BCE5-11D9-8F50-444553540000} - C:\WINDOWS\SYSTEM\WLDR.DLL (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {2EFB63E0-BCE5-11D9-8F50-444553540000} - C:\WINDOWS\SYSTEM\WLDR.DLL (file missing) (HKCU)
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll

Thanks, hope you can help.

Offline rmccabe

  • Jr. Member
  • **
  • Posts: 59
  • Karma: +0/-0
    • View Profile
computer slow, desktop hijacker & daosearch
« Reply #1 on: June 14, 2005, 04:28:43 PM »
http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/sad.gif\' class=\'bbc_emoticon\' alt=\':(\' /> just checking to see i I got missed
still looking for some help.

Offline rmccabe

  • Jr. Member
  • **
  • Posts: 59
  • Karma: +0/-0
    • View Profile
computer slow, desktop hijacker & daosearch
« Reply #2 on: June 17, 2005, 05:08:21 AM »
Just doing the bump thing.  Still having a real problem.  Getting harder to get online.  needing some help soon!!!!!!
Rob

Offline rmccabe

  • Jr. Member
  • **
  • Posts: 59
  • Karma: +0/-0
    • View Profile
computer slow, desktop hijacker & daosearch
« Reply #3 on: June 20, 2005, 11:15:10 PM »
http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/dry.gif\' class=\'bbc_emoticon\' alt=\'<_<\' /> gonna try the bump thing for the third time maybe it's a charm!!!!! http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/sad.gif\' class=\'bbc_emoticon\' alt=\':(\' />

Zandro

  • Guest
computer slow, desktop hijacker & daosearch
« Reply #4 on: June 25, 2005, 06:15:54 PM »
Browsing through Google, I read your cry for help.  http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/wink.gif\' class=\'bbc_emoticon\' alt=\';)\' />

SPOOLSRV32.EXE

Adware.Topantispyware
http://securityresponse.symantec.com/avcen...ntispyware.html
Updated 21 June 2005

or...

W32.HLLW.Gaobot.AG
http://securityresponse.symantec.com/avcen....gaobot.ag.html
Updated 27 July 2004

Offline rmccabe

  • Jr. Member
  • **
  • Posts: 59
  • Karma: +0/-0
    • View Profile
computer slow, desktop hijacker & daosearch
« Reply #5 on: June 26, 2005, 12:48:25 PM »
thanks for the tips,  My computer is so messed up now nothing will run except hijack.  with no responce for this site i think i will try some one else.  I am using the folks computer to check if anyone has  replyed to this post. Thanks again for the tips.  I printed the removel instruction. Gonna see if I have these.  May try to put hijack on a disk and get a current post but i dont want to infect the folk's computed.  Don't know if It will????

Just a thought is it that I have windows 98 that no will help????? http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/dry.gif\' class=\'bbc_emoticon\' alt=\'<_<\' />

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
computer slow, desktop hijacker & daosearch
« Reply #6 on: June 26, 2005, 12:56:41 PM »
Sorry your post got overlooked
Why can't you use your computer to post the log?

Can you somehow post a fresh Hijackthis log to this thread please
You can run it on your computer and transfer to the other computer
Make sure you post the whole log too
From top to bottom

Is it just that you keep getting redirected with Internet Explorer that you can't post the log from the infected computer?
« Last Edit: June 26, 2005, 01:03:23 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline rmccabe

  • Jr. Member
  • **
  • Posts: 59
  • Karma: +0/-0
    • View Profile
computer slow, desktop hijacker & daosearch
« Reply #7 on: June 27, 2005, 10:32:24 PM »
hello here is a current hj log.  I have downloaded adaware and also windows cleanup and registry fix.  before my my computer started to really act upI was able to run them.  the computer is really slow to load any program, 53% of the resorces are used up nothing runs because it say's there are files missing "dll"  -- winwnet.dll, xms driver not installed.  I get this on a restart that the Himen.sys is missing but if I power down the computer it starts up slow but I get to the desktop.  On the desktop I now have a box that said's "Debug ---Display driver does not support Get Chip ID"

Logfile of HijackThis v1.99.1
Scan saved at 7:04:38 PM, on 6/27/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\COMMON FILES\EPSON\EBAPI\SAGENT2.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\CLGAMMA.EXE
C:\WINDOWS\SYSTEM\USBMONIT.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\AUCBPNP.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\ADAPTEC\USBCONTROL\AUSBCTRL.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\HJT\HIJACKTHIS.EXE

F1 - win.ini: run=hpfsched
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ColorCorrection] C:\WINDOWS\CLGAMMA.EXE
O4 - HKLM\..\Run: [Gene USB Monitor] C:\WINDOWS\SYSTEM\USBMonit.exe
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
O4 - HKLM\..\Run: [AUCBPNP] C:\WINDOWS\SYSTEM\aucbpnp.exe
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb07.exe
O4 - HKLM\..\Run: [Welcome] C:\WINDOWS\Welcome.exe /R
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NAVAPW32.EXE /LOADQUIET
O4 - HKLM\..\RunServices: [Srv32 spool service] C:\WINDOWS\System\spoolsrv32.exe
O4 - HKLM\..\RunServices: [SAgent2ExePath] C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\SYSTEM\mstask.exe
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SPYSWEEPER.EXE" /0
O4 - Startup: USBControl.lnk = C:\Program Files\Adaptec\USBControl\Ausbctrl.exe
O4 - Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\SYSTEM\E_SRCV02.EXE
O4 - Startup: EPSON CardMonitor.lnk = C:\Program Files\EPSON\EPSON CardMonitor\EPSON CardMonitor1.0.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Microsoft AntiSpyware helper - {2EFB63E0-BCE5-11D9-8F50-444553540000} - C:\WINDOWS\SYSTEM\WLDR.DLL (file missing)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {2EFB63E0-BCE5-11D9-8F50-444553540000} - C:\WINDOWS\SYSTEM\WLDR.DLL (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Microsoft AntiSpyware helper - {2EFB63E0-BCE5-11D9-8F50-444553540000} - C:\WINDOWS\SYSTEM\WLDR.DLL (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {2EFB63E0-BCE5-11D9-8F50-444553540000} - C:\WINDOWS\SYSTEM\WLDR.DLL (file missing) (HKCU)

is there any hope.  when I go to hook to the internet I have no internet connection options no option to type in my password or to change user option what i do have is  Dial - up and virtiual Private network settings and LAN setting  I just use the standard old dial up. http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/sad.gif\' class=\'bbc_emoticon\' alt=\':(\' />

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
computer slow, desktop hijacker & daosearch
« Reply #8 on: June 28, 2005, 12:39:43 AM »
This computer may have serious issues
I'm not saying we can't get it clean, but it may take a bit  http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />

I need you to repost a new hijackthis log
Please include the whole log
When you run another scan and save log with Hijackthis
at the top of the log
Click EDIT>>Select All
Right click and select Copy

Copy and paste back the whole contents

Quote
I have downloaded adaware and also windows cleanup and registry fix

What registry fix are you talking about???

Also
I need you to run a free online virus scan at Panda's
There is a link to it im my signature below
When the scan is complete please post back the Report from the scan

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline rmccabe

  • Jr. Member
  • **
  • Posts: 59
  • Karma: +0/-0
    • View Profile
computer slow, desktop hijacker & daosearch
« Reply #9 on: June 28, 2005, 01:11:15 AM »
I can not hook to the internet to run panda. is there any other way to run the scan?  I did not see a download to a disk or anything like that.
the registry fix is registryfix.com.  I have not purchased  the program just used the free scan/fix.  As far as the hj log I did edit selsct all, right click copy then insert disk and went to file, save as open up floppy and saved.  then put  disk into the other computer open up my computer open up floppy open file to note pad and select all copy and paste. what did I miss??? http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/dry.gif\' class=\'bbc_emoticon\' alt=\'<_<\' />
rob

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
computer slow, desktop hijacker & daosearch
« Reply #10 on: June 28, 2005, 09:07:27 AM »
I forgot you couldn't get on the Internet
Can you do me a favor please
This dll you said you were missing
You said it was winwnet.dll

Can I assume that you meant wininet.dll

That may be the reason you can't connect to the Net

Can you look in your C:\Windows\System folder please for this file
Wininet.dll
Right click on it and left click properties
Let me know creation and modification date

If possible
Can you zip up a copy of that file to a floppy
<Removed instructions>

Could you also check the following for me please
You should have a copy of Himem.sys in your
C:\Windows folder
Let me know if it's there
Also, look for Himem.sys in the following folder
C:\WINDOWS\COMMAND\EBD
Let me know if it's there


I'm at work right now so I'll look for your results when I get home
« Last Edit: July 01, 2005, 10:12:26 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline rmccabe

  • Jr. Member
  • **
  • Posts: 59
  • Karma: +0/-0
    • View Profile
computer slow, desktop hijacker & daosearch
« Reply #11 on: June 28, 2005, 09:45:38 PM »
yes you are correct - wininet.dll is missing is not in systems folder.I have winnet16.dll folder but mod date 4-23-99. Since I do not have this folder I did not do virus scan.I do have himen.sys folder in both windows folder & ebd folder both have modified date 4-23-99-created 6-22-05-accessed 6-2-05
ROB

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
computer slow, desktop hijacker & daosearch
« Reply #12 on: June 29, 2005, 12:27:02 AM »
We'll have to replace wininet.dll if it is missing
Double check and make sure it is not in the
System folder
Just make sure it is not present
I should be able to upload you a copy from my computer
from a 98SE machine I have

Also, can you do the following please
You will have to transfer this tool to the infected computer
It's too big to fit on a floppy

==Download this virus checker from eScan
Mwav.exe
There's nothing to install, Save it and transfer to the infected computers
desktop
Double click to run eScan's Mwav.exe scan
It will self extract

On the infected computer please create a new text file on the desktop
Go to START>>RUN
type in notepad
Hit OK
In Notepad click FILE>>SAVE AS
Name the file Log
and save it too desktop>>>This is where we will want to save the results of the scan when it's complete

You may want to disable Norton's auto protect at this point so it won't interfere
In Mwav
Select all local drives, scan all files, press 'SCAN' and when it is completed, anything found will be displayed in the lower pane.
This may take awhile, let it finish
In the Virus Log Information Pane
Left click and Highlight all the info in the Lower pane---  Use "CTRL +  C" keys  on your Keyboard to copy all found in the lower pane  and Paste too that  Notepad file you saved earlier

****If prompted that a Virus was found and you need to purchase the product  to remove the malware, just close out the prompt and let it continue scanning
We just want to see where the bad guys are

Post the log you saved from the Mwav scan back here in it's entirety

Since your transfering Mwav from one computer to the other, can I also have you do the following too
==Download the Killbox by Option^Explicit
* Save it to your desktop or a folder of the infected computer
« Last Edit: June 29, 2005, 12:47:32 AM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline rmccabe

  • Jr. Member
  • **
  • Posts: 59
  • Karma: +0/-0
    • View Profile
computer slow, desktop hijacker & daosearch
« Reply #13 on: June 29, 2005, 11:38:23 PM »
hello,
I rechecked my system folder no winenet.dll.  What I did find In my norton scan/virus log was "C:\Windows\system\wininet.dll was infected with bloodhound w32.ep virus on 6-22-05 an was deleted.  must have been on a restart because no scan was run.
heres the Mwav scan log

File C:\WINDOWS\System\spoolsrv32.exe tagged as "not-a-virus:AdWare.FindSpy.e". Action Taken: No Action Taken.
File C:\WINDOWS\Desktop\My Briefcase\aawsepersonal.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\WINDOWS\Desktop\ta03stdw.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\WINDOWS\Desktop\ta04stdw.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
Object "Alexa Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "CoolWebSearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "AltNet Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "iSearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\xscan53.ocx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\Color\SRGB.ICM". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Intuit\Shared\ICHELP32.CNT". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeStreaming.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeInternetExtras.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QTUninst.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeStreamingExtras.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeWebHelper.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeUpdateHelper.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeAuthoring.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeCapture.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeEffects.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeEssentials.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeImage.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeMusic.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeStreamingAuthoring.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeVRAuthoring.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeMPEG.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Intuit\Shared\ARHELP.CNT". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\archive.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\browser.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\chrome\all-locales.rdf". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\chrome\all-packages.rdf". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\chrome\all-skins.rdf". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\chrome\embed.jar". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\chrome\installed-chrome.txt". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\chrome\user-locales.rdf". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\chrome\user-skins.rdf". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\all.xpt". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\appshell.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\caps.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\chardet.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\chrome.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\docshell.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\dugprot.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\dugprot.xpt". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\editor.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\embedcomponents.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\gfx2.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\gkcontent.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\gkgfxwin.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\gklayout.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\gkparser.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\gkplugin.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\gkview.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\gkwidget.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\imggif.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\imgjpeg.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\imglib2.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\imgpng.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\imgppm.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\iubroker.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\iubroker.xpt". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\jar50.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\jsdom.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\jsurl.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\lwbrk.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\necko.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\nkcache.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\nphppui.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\nsgif.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\nsjpg.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\nslocale.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\nspng.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\profile.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\rdf.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\shistory.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\strres.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\ucharuti.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\uconv.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\ucvibm.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\ucvlatin.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\urildr.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\utilitybroker.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\utilitybroker.xpt". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\webbrwsr.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\xpc3250.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\xppref32.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\defaults\pref\all.js". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\defaults\pref\initpref.js". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\defaults\pref\winpref.js". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\dialup.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\gkgfx.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\hlw.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\hpfutility.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\hpvcirt.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\hpvcp60.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\hpvcrt.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\hpxmldispatch.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\img3250.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\internetupdate.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\jpeg3250.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\js3250.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\mozreg.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\nspr4.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\patchw32.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\plc4.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\plds4.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\printpcl.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\acceptlanguage.properties". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\buttonbindings.xml". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\buttons.css". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\checkbox.css". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\checkboxbindings.xml". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\fieldset.css". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\fieldsetbindings.xml". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\htmlbindings.xml". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\platformbuttonbindings.xml". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\platformcheckboxbindings.xml". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\platformfieldsetbindings.xml". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\platformhtmlbindings.xml". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\platformselectbindings.xml". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\select.css". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\selectbindings.xml". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\textfields.css". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\xbl-forms.css". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\charsetalias.properties". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\charsetdata.properties". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\fonts\fontencoding.properties". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\forms.css". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\html.css". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\langgroups.properties". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\language.properties". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\quirk.css". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\ua.css". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\viewsource.css". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\wincharset.properties". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\search.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\u32.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\xerces-c_1_3.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\xpcom.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\z32.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\zlib.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\3320\enu\.\data\3320enu.xml". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\3320\enu\.\data\3320enu.zip". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\3320\enu\.\data\html.cfg". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\3320\enu\.\data\lv3320enu.xml". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\3320\enu\.\data\search.idx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\components\vpminstallbroker.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\components\vpminstallbroker.xpt". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\Uninstall_Info\delay.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\Uninstall_Info\DirectoryRemovalUtility.exe ". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\hwinv.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\inv16.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\upapp\data\fruhtm\img\global\fillet-small-xlight-bl.bmp". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeQD3D.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeMPEG4.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeMPEG4Authoring.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\xscan53.ocx". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{D3B1DE00-6B94-1069-8754-08002B2BD64F}" refers to invalid object "C:\WINDOWS\SYSTEM\disktool.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{C56C4E21-706D-11d0-AFC5-444553540002}" refers to invalid object "C:\Program Files\PhotoDeluxe HE 3.0\FotoNation Explorer\camview.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{2BC66F51-93A8-11D3-BEB6-00105AA9B6AE}" refers to invalid object "C:\WINDOWS\DOWNLOADED PROGRAM FILES\AVSNIFF.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{2BC66F54-93A8-11D3-BEB6-00105AA9B6AE}" refers to invalid object "C:\WINDOWS\DOWNLOADED PROGRAM FILES\AVSNIFF.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{00061068-0000-0000-C000-000000000046}" refers to invalid object "D:\PFiles\MSOffice\Office\RECALL.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006729A-0000-0000-C000-000000000046}" refers to invalid object "D:\PFiles\MSOffice\Office\SENDTO9.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006F02A-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\OUTLLIB.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006F069-0000-0000-C000-000000000046}" refers to invalid object "D:\PFiles\MSOffice\Office\OUTLCTL.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006F071-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\OUTLLIB.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0468C085-CA5B-11D0-AF08-00609797F0E0}" refers to invalid object "D:\PFiles\MSOffice\Office\OUTLCTL.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{2F42C693-C6A4-11D0-93E9-00AA0064D470}" refers to invalid object "D:\PFiles\Common\System\Mapi\1033\ESCONF.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{799ED9EA-FB5E-11D1-B7D6-00C04FC2AAE2}" refers to invalid object "D:\PFiles\MSOffice\Office\Addins\OUTLVBA.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{800DD100-DB43-11CE-914E-00A004000162}" refers to invalid object "D:\PFiles\MSOffice\Office\1033\MSSPC32.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006F045-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\OLKFSTUB.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006F019-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\OLKFSTUB.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{00067009-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\OUTLRPC.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0002034E-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\OUTLRPC.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0002034C-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\OUTLRPC.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{99180163-DA16-101A-935C-444553540000}" refers to invalid object "recncl.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{00020D75-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\MLSHEXT.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{4E3A7680-B77A-11D0-9DA5-00C04FD65685}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\OUTLMIME.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006F084-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\MIMEDIR.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006F083-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\MIMEDIR.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006F082-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\MIMEDIR.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006F081-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\MIMEDIR.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006F085-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\MIMEDIR.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006F07C-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\OUTLAS9.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006F01A-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\ENVELOPE.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006F07B-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\OUTLAS9.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006F07A-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\OUTLAS9.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{20FF6B80-C312-11D0-B4E4-00A0C9261445}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\MDHELPER.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{9EEE8A7C-8472-11D0-8252-00AA00C01795}" refers to invalid object "D:\PFiles\MSOffice\Office\1033\FLDPUB.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{532FD821-83AB-11D0-8032-00A0C90A8FE0}" refers to invalid object "D:\PFiles\MSOffice\Office\1033\FPATL.OCX". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{CB0E73C7-706A-11CF-A056-00A02416065A}" refers to invalid object "D:\PFiles\MSOffice\Office\1033\FLDPUB.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{CB0E73C3-706A-11CF-A056-00A02416065A}" refers to invalid object "D:\PFiles\MSOffice\Office\1033\FLDPUB.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{CB0E73C2-706A-11CF-A056-00A02416065A}" refers to invalid object "D:\PFiles\MSOffice\Office\1033\FLDPUB.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{CB0E73C1-706A-11CF-A056-00A02416065A}" refers to invalid object "D:\PFiles\MSOffice\Office\1033\FLDPUB.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{210183C0-1E63-11d1-9693-00A0C90D04EF}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\OUTLACCT.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{837BBD11-2F82-11d1-969E-00A0C90D04EF}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\OUTLACCT.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CD9-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CDB-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CDC-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CDD-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CDE-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CDF-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CE0-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CE1-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CED-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CE2-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CE3-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{35461E30-C488-11d1-960E-00C04FBD7C09}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CE6-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CE7-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CE8-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CE9-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CEA-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CEB-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{5A580C11-E5EB-11d1-A86E-0000F8084F96}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{BB847B8A-054A-11d2-A894-0000F8084F96}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{EA678830-235D-11d2-A8B6-0000F8084F96}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{05300401-BCBC-11d0-85E3-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{64577982-86D7-11d1-BDFC-00C04FA31009}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{1C82EAD9-508E-11D1-8DCF-00C04FB951F9}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{B0D17FC2-7BC4-11d1-BDFA-00C04FA31009}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{40AF8200-4E6E-11D4-878D-00C0F6B0D1A7}" refers to invalid object "C:\PROGRAM FILES\ARCSOFT\FUNHOUSE\EZRGB24.AX". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{40AF8201-4E6E-11D4-878D-00C0F6B0D1A7}" refers to invalid object "C:\PROGRAM FILES\ARCSOFT\FUNHOUSE\EZRGB24.AX". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{56336BCA-3D8A-11d6-A00B-0050DA18DE71}" refers to invalid object "C:\WINDOWS\TEMP\INFOWINDOW.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{2EFB63E0-BCE5-11D9-8F50-444553540000}" refers to invalid object "C:\WINDOWS\SYSTEM\WLDR.DLL". Action Taken: No Action Taken.
Entry "HKCR\Overview.Document" refers to invalid object "{DA23B9C9-6893-11D0-8534-00C04FD7AD0C}". Action Taken: No Action Taken.
Entry "HKCR\FASTPIXEL.FASTPIXEL.1" refers to invalid object "{6F79DCE0-DCF5-11D0-800E-080009E9498B)". Action Taken: No Action Taken.
Entry "HKCR\BETTERPIXEL.BETTERPIXEL.1" refers to invalid object "{AD5EF240-9EBE-11D0-800E-080009E9498B)". Action Taken: No Action Taken.
Entry "HKCR\mapifvbx.object" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.
Entry "HKCR\mapifvbx.object.1" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.
Entry "HKCR\MailFileAtt" refers to invalid object "{00020D05-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\ActMsg.Session" refers to invalid object "{3FA7DEB3-6438-101B-ACC1-00AA00423326}". Action Taken: No Action Taken.
Entry "HKCR\SpyDoctor.EBankProblem" refers to invalid object "{AE612304-E8F9-45D9-A444-32409D33E954}". Action Taken: No Action Taken.
Entry "HKCR\SpyDoctor.ScripterProxy" refers to invalid object "{9FEF02F5-B3B8-4D7B-8939-72A1C989D1B9}". Action Taken: No Action Taken.
Entry "HKCR\SpyDoctor.QuarantinedItemProxy" refers to invalid object "{C2CE6266-0404-4C54-96B4-8829852E3537}". Action Taken: No Action Taken.
File C:\WINDOWS\internt.exe infected by "Trojan-Downloader.Win32.Small.agx" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM\oleadm.dll infected by "Trojan.Win32.Agent.eo" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\TEMPOR~1\CONTENT.IE5\TR3ZSGVR\file[1].exe infected by "Trojan.Win32.Agent.eo" Virus! Action Taken: No Action Taken.

Thanks, rob

Offline rmccabe

  • Jr. Member
  • **
  • Posts: 59
  • Karma: +0/-0
    • View Profile
computer slow, desktop hijacker & daosearch
« Reply #14 on: June 30, 2005, 02:01:30 AM »
I failed to check the all drive box and I did not check the folder box but I did check the Scan all files box
heres the new scan
File C:\WINDOWS\System\spoolsrv32.exe tagged as "not-a-virus:AdWare.FindSpy.e". Action Taken: No Action Taken.
File C:\WINDOWS\Desktop\My Briefcase\aawsepersonal.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\WINDOWS\Desktop\ta03stdw.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\WINDOWS\Desktop\ta04stdw.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
Object "Alexa Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "CoolWebSearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "AltNet Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "iSearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\xscan53.ocx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\Color\SRGB.ICM". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Intuit\Shared\ICHELP32.CNT". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeStreaming.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeInternetExtras.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QTUninst.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeStreamingExtras.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeWebHelper.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeUpdateHelper.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeAuthoring.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeCapture.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeEffects.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeEssentials.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeImage.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeMusic.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeStreamingAuthoring.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeVRAuthoring.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeMPEG.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Intuit\Shared\ARHELP.CNT". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\archive.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\browser.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\chrome\all-locales.rdf". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\chrome\all-packages.rdf". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\chrome\all-skins.rdf". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\chrome\embed.jar". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\chrome\installed-chrome.txt". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\chrome\user-locales.rdf". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\chrome\user-skins.rdf". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\all.xpt". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\appshell.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\caps.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\chardet.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\chrome.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\docshell.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\dugprot.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\dugprot.xpt". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\editor.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\embedcomponents.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\gfx2.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\gkcontent.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\gkgfxwin.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\gklayout.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\gkparser.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\gkplugin.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\gkview.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\gkwidget.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\imggif.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\imgjpeg.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\imglib2.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\imgpng.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\imgppm.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\iubroker.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\iubroker.xpt". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\jar50.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\jsdom.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\jsurl.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\lwbrk.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\necko.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\nkcache.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\nphppui.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\nsgif.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\nsjpg.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\nslocale.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\nspng.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\profile.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\rdf.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\shistory.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\strres.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\ucharuti.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\uconv.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\ucvibm.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\ucvlatin.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\urildr.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\utilitybroker.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\utilitybroker.xpt". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\webbrwsr.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\xpc3250.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\components\xppref32.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\defaults\pref\all.js". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\defaults\pref\initpref.js". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\defaults\pref\winpref.js". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\dialup.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\gkgfx.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\hlw.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\hpfutility.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\hpvcirt.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\hpvcp60.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\hpvcrt.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\hpxmldispatch.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\img3250.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\internetupdate.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\jpeg3250.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\js3250.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\mozreg.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\nspr4.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\patchw32.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\plc4.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\plds4.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\printpcl.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\acceptlanguage.properties". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\buttonbindings.xml". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\buttons.css". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\checkbox.css". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\checkboxbindings.xml". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\fieldset.css". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\fieldsetbindings.xml". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\htmlbindings.xml". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\platformbuttonbindings.xml". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\platformcheckboxbindings.xml". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\platformfieldsetbindings.xml". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\platformhtmlbindings.xml". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\platformselectbindings.xml". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\select.css". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\selectbindings.xml". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\textfields.css". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\builtin\xbl-forms.css". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\charsetalias.properties". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\charsetdata.properties". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\fonts\fontencoding.properties". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\forms.css". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\html.css". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\langgroups.properties". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\language.properties". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\quirk.css". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\ua.css". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\viewsource.css". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\.\res\wincharset.properties". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\search.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\u32.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\xerces-c_1_3.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\xpcom.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\z32.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\zlib.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\3320\enu\.\data\3320enu.xml". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\3320\enu\.\data\3320enu.zip". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\3320\enu\.\data\html.cfg". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\3320\enu\.\data\lv3320enu.xml". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\3320\enu\.\data\search.idx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\components\vpminstallbroker.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\hp deskjet assistant\bin\components\vpminstallbroker.xpt". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\Uninstall_Info\delay.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\Uninstall_Info\DirectoryRemovalUtility.exe ". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\hwinv.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\inv16.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Hewlett-Packard\upapp\data\fruhtm\img\global\fillet-small-xlight-bl.bmp". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeQD3D.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeMPEG4.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\QuickTime\QuickTimeMPEG4Authoring.qtx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\xscan53.ocx". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{D3B1DE00-6B94-1069-8754-08002B2BD64F}" refers to invalid object "C:\WINDOWS\SYSTEM\disktool.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{C56C4E21-706D-11d0-AFC5-444553540002}" refers to invalid object "C:\Program Files\PhotoDeluxe HE 3.0\FotoNation Explorer\camview.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{2BC66F51-93A8-11D3-BEB6-00105AA9B6AE}" refers to invalid object "C:\WINDOWS\DOWNLOADED PROGRAM FILES\AVSNIFF.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{2BC66F54-93A8-11D3-BEB6-00105AA9B6AE}" refers to invalid object "C:\WINDOWS\DOWNLOADED PROGRAM FILES\AVSNIFF.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{00061068-0000-0000-C000-000000000046}" refers to invalid object "D:\PFiles\MSOffice\Office\RECALL.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006729A-0000-0000-C000-000000000046}" refers to invalid object "D:\PFiles\MSOffice\Office\SENDTO9.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006F02A-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\OUTLLIB.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006F069-0000-0000-C000-000000000046}" refers to invalid object "D:\PFiles\MSOffice\Office\OUTLCTL.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006F071-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\OUTLLIB.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0468C085-CA5B-11D0-AF08-00609797F0E0}" refers to invalid object "D:\PFiles\MSOffice\Office\OUTLCTL.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{2F42C693-C6A4-11D0-93E9-00AA0064D470}" refers to invalid object "D:\PFiles\Common\System\Mapi\1033\ESCONF.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{799ED9EA-FB5E-11D1-B7D6-00C04FC2AAE2}" refers to invalid object "D:\PFiles\MSOffice\Office\Addins\OUTLVBA.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{800DD100-DB43-11CE-914E-00A004000162}" refers to invalid object "D:\PFiles\MSOffice\Office\1033\MSSPC32.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006F045-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\OLKFSTUB.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006F019-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\OLKFSTUB.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{00067009-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\OUTLRPC.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0002034E-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\OUTLRPC.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0002034C-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\OUTLRPC.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{99180163-DA16-101A-935C-444553540000}" refers to invalid object "recncl.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{00020D75-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\MLSHEXT.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{4E3A7680-B77A-11D0-9DA5-00C04FD65685}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\OUTLMIME.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006F084-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\MIMEDIR.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006F083-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\MIMEDIR.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006F082-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\MIMEDIR.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006F081-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\MIMEDIR.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006F085-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\MIMEDIR.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006F07C-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\OUTLAS9.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006F01A-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\ENVELOPE.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006F07B-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\OUTLAS9.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0006F07A-0000-0000-C000-000000000046}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\OUTLAS9.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{20FF6B80-C312-11D0-B4E4-00A0C9261445}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\MDHELPER.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{9EEE8A7C-8472-11D0-8252-00AA00C01795}" refers to invalid object "D:\PFiles\MSOffice\Office\1033\FLDPUB.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{532FD821-83AB-11D0-8032-00A0C90A8FE0}" refers to invalid object "D:\PFiles\MSOffice\Office\1033\FPATL.OCX". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{CB0E73C7-706A-11CF-A056-00A02416065A}" refers to invalid object "D:\PFiles\MSOffice\Office\1033\FLDPUB.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{CB0E73C3-706A-11CF-A056-00A02416065A}" refers to invalid object "D:\PFiles\MSOffice\Office\1033\FLDPUB.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{CB0E73C2-706A-11CF-A056-00A02416065A}" refers to invalid object "D:\PFiles\MSOffice\Office\1033\FLDPUB.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{CB0E73C1-706A-11CF-A056-00A02416065A}" refers to invalid object "D:\PFiles\MSOffice\Office\1033\FLDPUB.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{210183C0-1E63-11d1-9693-00A0C90D04EF}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\OUTLACCT.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{837BBD11-2F82-11d1-969E-00A0C90D04EF}" refers to invalid object "D:\PFILES\MSOFFICE\OFFICE\OUTLACCT.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CD9-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CDB-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CDC-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CDD-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CDE-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CDF-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CE0-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CE1-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CED-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CE2-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CE3-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{35461E30-C488-11d1-960E-00C04FBD7C09}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CE6-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CE7-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CE8-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CE9-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CEA-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CEB-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{5A580C11-E5EB-11d1-A86E-0000F8084F96}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{BB847B8A-054A-11d2-A894-0000F8084F96}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{EA678830-235D-11d2-A8B6-0000F8084F96}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{05300401-BCBC-11d0-85E3-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{64577982-86D7-11d1-BDFC-00C04FA31009}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{1C82EAD9-508E-11D1-8DCF-00C04FB951F9}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{B0D17FC2-7BC4-11d1-BDFA-00C04FA31009}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{40AF8200-4E6E-11D4-878D-00C0F6B0D1A7}" refers to invalid object "C:\PROGRAM FILES\ARCSOFT\FUNHOUSE\EZRGB24.AX". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{40AF8201-4E6E-11D4-878D-00C0F6B0D1A7}" refers to invalid object "C:\PROGRAM FILES\ARCSOFT\FUNHOUSE\EZRGB24.AX". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{56336BCA-3D8A-11d6-A00B-0050DA18DE71}" refers to invalid object "C:\WINDOWS\TEMP\INFOWINDOW.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{2EFB63E0-BCE5-11D9-8F50-444553540000}" refers to invalid object "C:\WINDOWS\SYSTEM\WLDR.DLL". Action Taken: No Action Taken.
Entry "HKCR\Overview.Document" refers to invalid object "{DA23B9C9-6893-11D0-8534-00C04FD7AD0C}". Action Taken: No Action Taken.
Entry "HKCR\FASTPIXEL.FASTPIXEL.1" refers to invalid object "{6F79DCE0-DCF5-11D0-800E-080009E9498B)". Action Taken: No Action Taken.
Entry "HKCR\BETTERPIXEL.BETTERPIXEL.1" refers to invalid object "{AD5EF240-9EBE-11D0-800E-080009E9498B)". Action Taken: No Action Taken.
Entry "HKCR\mapifvbx.object" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.
Entry "HKCR\mapifvbx.object.1" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.
Entry "HKCR\MailFileAtt" refers to invalid object "{00020D05-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\ActMsg.Session" refers to invalid object "{3FA7DEB3-6438-101B-ACC1-00AA00423326}". Action Taken: No Action Taken.
Entry "HKCR\SpyDoctor.EBankProblem" refers to invalid object "{AE612304-E8F9-45D9-A444-32409D33E954}". Action Taken: No Action Taken.
Entry "HKCR\SpyDoctor.ScripterProxy" refers to invalid object "{9FEF02F5-B3B8-4D7B-8939-72A1C989D1B9}". Action Taken: No Action Taken.
Entry "HKCR\SpyDoctor.QuarantinedItemProxy" refers to invalid object "{C2CE6266-0404-4C54-96B4-8829852E3537}". Action Taken: No Action Taken.
File C:\WINDOWS\internt.exe infected by "Trojan-Downloader.Win32.Small.agx" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM\oleadm.dll infected by "Trojan.Win32.Agent.eo" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\TEMPOR~1\CONTENT.IE5\TR3ZSGVR\file[1].exe infected by "Trojan.Win32.Agent.eo" Virus! Action Taken: No Action Taken.

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
computer slow, desktop hijacker & daosearch
« Reply #15 on: July 01, 2005, 09:35:25 PM »
Very sorry for the delay
With work and holiday weekend I'm having a heck of a time making it to the forum
 
Can you please do the following for me please
Transfer these to the infected computer
IF your version of Windows is the English version
Download and save to desktop Wininet.zip
Don't unzip this yet
We'll need it later
[attachment=281:attachment]
 
Then carry on with the rest of these instructions
 
Download SmitRem.zip
and UNZIP the folder within to your desktop
Don't run it yet
 
On the infected computer
Open Notepad (START>>>RUN>>>type in notepad)
Hit OK
Copy the contents of the CODE box to notepad, not including the word "code"
In Notepad click FILE>>SAVE AS
IMPORTANT>>>Change the Save as Type to All Files.
Name the file as fix.reg
 
Save this file on the desktop, well need this later, don't run it yet
 
 
Code: [Select]
REGEDIT4
 
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet update]

 
Can you do the following please
Print these instructions if you can to refer to them
 
Set the Infected computer to show hidden files
* Open My Computer.
    * Select the View menu and click Folder Options.
    * Select the View Tab.
    * In the Hidden files section select Show all files.
    * Uncheck Hide Extensions for known file types
    * Click OK.
 
Restart the computer into Safe mode
 
Find and delete these files if they exist
Exact spelling, don't delete something because it looks similiar
C:\WINDOWS\System\spoolsrv32.exe <-this file, exact spelling
C:\WINDOWS\SYSTEM\oleadm.dll
C:\WINDOWS\internt.exe
C:\WINDOWS\uninstIU.exe
 
Open the SmitRem folder you unzipped earlier and Double click on the RunThis.bat
Follow the prompts to run the tool
When it's done
 
Double click on fix.reg and allow to add or Merge to the registry

Do another scan with Hijackthis and put a check next to these entries:

O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)

O4 - HKLM\..\RunServices: [Srv32 spool service] C:\WINDOWS\System\spoolsrv32.exe

O9 - Extra button: Microsoft AntiSpyware helper - {2EFB63E0-BCE5-11D9-8F50-444553540000} - C:\WINDOWS\SYSTEM\WLDR.DLL (file missing)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {2EFB63E0-BCE5-11D9-8F50-444553540000} - C:\WINDOWS\SYSTEM\WLDR.DLL (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Microsoft AntiSpyware helper - {2EFB63E0-BCE5-11D9-8F50-444553540000} - C:\WINDOWS\SYSTEM\WLDR.DLL (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {2EFB63E0-BCE5-11D9-8F50-444553540000} - C:\WINDOWS\SYSTEM\WLDR.DLL (file missing) (HKCU)


After you have ticked the above entries, close All other open windows,
Leave Hijackthis open and click FIX CHECKED
OK the prompt and exit Hijackthis
 
Restart back to Normal mode
 
Unzip Wininet.zip to your C:\Windows\System folder
 
Try and connect online afterwards
You may have to restart the computer once you unzip the file
 
Post a fresh hijackthis log after you have completed the above steps
« Last Edit: July 02, 2005, 04:21:12 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline rmccabe

  • Jr. Member
  • **
  • Posts: 59
  • Karma: +0/-0
    • View Profile
computer slow, desktop hijacker & daosearch
« Reply #16 on: July 02, 2005, 02:22:23 AM »
http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' /> wow I can connect to the internet with my computer, pretty cool stuff.  Here's what I have:

 didn't have C:\WINDOWS\uninstIU.exe.

 I had all the others.

When smitrem ran It gave 2 errors
 cannot import C;\smitfrau.reg & sageset2005.reg,

Said there was and error opening.

The computer is still really slow with the mouse and loading any new window screens

Here's the current HJL.

Logfile of HijackThis v1.99.1
Scan saved at 10:53:52 PM, on 7/1/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\COMMON FILES\EPSON\EBAPI\SAGENT2.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\CLGAMMA.EXE
C:\WINDOWS\SYSTEM\USBMONIT.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\AUCBPNP.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\RunDLL.exe
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\ADAPTEC\USBCONTROL\AUSBCTRL.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\HJT\HIJACKTHIS.EXE

F1 - win.ini: run=C:\WINDOWS\hpfsched.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ColorCorrection] C:\WINDOWS\CLGAMMA.EXE
O4 - HKLM\..\Run: [Gene USB Monitor] C:\WINDOWS\SYSTEM\USBMonit.exe
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
O4 - HKLM\..\Run: [AUCBPNP] C:\WINDOWS\SYSTEM\aucbpnp.exe
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb07.exe
O4 - HKLM\..\Run: [Welcome] C:\WINDOWS\Welcome.exe /R
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NAVAPW32.EXE /LOADQUIET
O4 - HKLM\..\RunServices: [SAgent2ExePath] C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\SYSTEM\mstask.exe
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SPYSWEEPER.EXE" /0
O4 - Startup: USBControl.lnk = C:\Program Files\Adaptec\USBControl\Ausbctrl.exe
O4 - Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\SYSTEM\E_SRCV02.EXE
O4 - Startup: EPSON CardMonitor.lnk = C:\Program Files\EPSON\EPSON CardMonitor\EPSON CardMonitor1.0.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

when I start the computer up I get all kinds of windows, missing usb file,epson ink monitor missing file.I also noticed In theMWAV scan alot of stuff on HP: I dont run hp I have And EPSON printer.
Thanks for all your help so far , My girlfriend say's the computer is a gonner.  I don't think so. Thanks again for the help,
Rob
Happy 4th

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
computer slow, desktop hijacker & daosearch
« Reply #17 on: July 02, 2005, 11:14:44 AM »
I still think there's some things lurking on your computer
We'll have to try alternatives

Can you please do the following
==Download and Install this small program
to help clean your temp folders,cookies, etc...
Windows Cleanup
Give the link time to load or try it twice, it may be busy
Alternate Download link
Don't run it yet, we'll need it later

==Download and UNZIP to desktop or a folder
Smitfraud.zip, so you now have Smitfraud.reg extracted
We'll need this later
[attachment=282:attachment]

I'll assume you downloaded Killbox earlier, if not I'm including it again just in case
Please Open up a Notepad file
START>>RUN>>Type in notepad
Hit OK
Copy all of these instructions to that notepad file and save it on your computer
Close down all unneccessary windows running in the background
That includes this one

Can you please disable SpySweeper's realtime protection
We don't need it interfering in any fixes we are about to try

==Download the Killbox by Option^Explicit. [color=\"red\"]*In the event you already have Killbox, this is a new version that I need you to download[/color].
* Save it to your desktop or a folder

Please Save these instructions below to a Notepad file and save it to the infected computers desktop or a folder

Go to Start > Control Panel > Add or Remove Programs and remove the following programs, if found:

Security IGuard
Virtual Maid
Search Maid
PSGuard

Exit Add/Remove Programs.

* Please double-click Killbox.exe to run it.
* Select "Delete on Reboot".

* Open the Notepad file where you saved the instructions and copy the file paths below to the clipboard by highlighting ALL of them and pressing
 CTRL + C

[color=\"purple\"]Killbox file paths to copy to clipboard between dotted lines[/color]
===========================================
C:\wp.exe
C:\wp.bmp
C:\bsw.exe
C:\Windows\sites.ini
C:\Windows\popuper.exe
C:\Windows\zloader3.exe
C:\Windows\system\wp.bmp
C:\Windows\System\hhk.dll
C:\Windows\System\wldr.dll
C:\Windows\System\helper.exe
C:\Windows\System\intmon.exe
C:\Windows\System\shnlog.exe
C:\Windows\system\perfcii.ini
C:\Windows\System\intmonp.exe
C:\Windows\System\msmsgs.exe
C:\Windows\system\msole32.exe
C:\Windows\System\ole32vbs.exe
C:\WINDOWS\system\oleadm.dll
C:\WINDOWS\system\oleadm32.dll

===================================================
*  Return to Killbox, go to the File menu, and choose "Paste from Clipboard".

* Click the red-and-white "Delete File" button.  Click "Yes" at the Delete on Reboot prompt.  Click "No" at the Pending Operations prompt.
Don't worry about any file not found messages

If your computer does not restart automatically, please restart it manually.  

[color=\"red\"]While your computer is restarting, tap the F8 key continually until a menu appears.  Use your up arrow key to highlight Safe Mode, then hit enter.[/color]

In SAFE MODE

Using Windows Explorer, Manually navigate and delete these folders if found
Don't do a search for them, manually look for them

C:\Program Files\Search Maid
C:\Program Files\Security IGuard
C:\Program Files\Virtual Maid
C:\Program Files\PSGuard
C:\Windows\System\Log Files
Can you also look for Log Files in your System32 folder

==Double click on Smitfraud.reg and allow to add or Merge to the registry

==Open Windows CleanUp!>>START>>programs>>Cleanup!
Click on the CleanUp button, let it finish scanning for files, when it's done

Restart the computer back to Normal mode

Back in Windows
Can we run another scanner through your machine please
Download and Install Spybot 1.4 from
HERE
 or HERE
Don't activate the Tea Timer when installing, it's a great feature but can get in the way
of any fixes we may still have to do
After installation--Click the UPDATE button on the left
SEARCH FOR UPDATES on the right
Check, and download all updates
Click the Search & Destroy button on the left
Check for Problems---When the Scan is complete
FIX all selected promblems in RED

RESTART the computer to finish the cleaning process
Back in Windows

Run another scan with Hijackthis and post a fresh log
Could you also Open Hijackthis>>Open Misc tools section>>Open Uninstall Manager
Click the SAVE LIST button
Save the list to your desktop and then copy and paste back the contents here too along with the hijackthis log

I want to check a couple files
Although the may be legit, I want to make sure
Can you go to this link
Give this site time to load
Jotti's Online Malware scan

Use the browse button and navigate to this file on your hard drive
C:\WINDOWS\SYSTEM\aucbpnp.exe <-this file
Right click on it  and choose Select
Then use the Submit button
Let it finish scanning
Could you post back the results of the scan back here please, just the scanner results which includes name of file

Do the same for this file
C:\WINDOWS\CLGAMMA.EXE <-this may be legit, but won't hurt to check it

We'll worry about the cleaning of the registry and the error message from the USB file later
It looks like you have a USB port controller hooked to the machine
and some entries related on startup, this may be the reason for the error message on startup
« Last Edit: July 02, 2005, 11:15:22 AM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline rmccabe

  • Jr. Member
  • **
  • Posts: 59
  • Karma: +0/-0
    • View Profile
computer slow, desktop hijacker & daosearch
« Reply #18 on: July 03, 2005, 03:50:03 PM »
Hello it took awhile to get her computer is really slow and very hard to control the mouse.  I did not have any of the program that you wanted me to search for in my add/remove programs.
I ran killbox no problems there
I did not find any of the files, I double checked these.
I run smitfraud no problems.
I run spybot as instructed spybot found two problems.
alexa related & coolwwwsearch.yexe these were deleted.
It also found minibug but it was not in red.  so it was not deleted.
here is the current hjl and also the inistall manager log.
I still have problems with the display driver can only run 16 colors and 640 x 480 pixels i have tried to change it but keep getting error messages.  I have a window open on the desktop that say's DEBUG "display driver does not support Get Chip ID" with a  "OK" box to check.  I have not click the box!!

I would like to get rid of spy sweeper, unless you thing its and ok program. it is really slow to load.  Minimun system to run the program is 300mhz.  my little micron is a 166mhz. any thoughts??

Logfile of HijackThis v1.99.1
Scan saved at 11:44:03 AM, on 7/3/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\COMMON FILES\EPSON\EBAPI\SAGENT2.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\CLGAMMA.EXE
C:\WINDOWS\SYSTEM\USBMONIT.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\AUCBPNP.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE
C:\PROGRAM FILES\ADAPTEC\USBCONTROL\AUSBCTRL.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\HJT\HIJACKTHIS.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE

F1 - win.ini: run=C:\WINDOWS\hpfsched.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ColorCorrection] C:\WINDOWS\CLGAMMA.EXE
O4 - HKLM\..\Run: [Gene USB Monitor] C:\WINDOWS\SYSTEM\USBMonit.exe
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
O4 - HKLM\..\Run: [AUCBPNP] C:\WINDOWS\SYSTEM\aucbpnp.exe
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NAVAPW32.EXE /LOADQUIET
O4 - HKLM\..\RunServices: [SAgent2ExePath] C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\SYSTEM\mstask.exe
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SPYSWEEPER.EXE" /0
O4 - Startup: USBControl.lnk = C:\Program Files\Adaptec\USBControl\Ausbctrl.exe
O4 - Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\SYSTEM\E_SRCV02.EXE
O4 - Startup: EPSON CardMonitor.lnk = C:\Program Files\EPSON\EPSON CardMonitor\EPSON CardMonitor1.0.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE


Adaptec USB CardBus Manager
Ad-Aware SE Personal
Adobe Acrobat 5.0
CleanUp!
DAO 3.5
EPSON Printer Software
EPSON USB Printer Devices
Film Factory
HijackThis 1.99.1
Internet Explorer Q890923
LiveUpdate 2.6 (Symantec Corporation)
Microsoft Data Access Components KB870669
Microsoft Internet Explorer 6 SP1 and Internet Tools
Microsoft NetMeeting 2.11
Microsoft Office 2000 Small Business
Microsoft Picture It! 2000
Microsoft VGX Q833989
Microsoft Web Publishing Wizard 1.6
Norton AntiVirus 5.0 for Windows
QuickTime
RegistryFix v3.0
Spy Sweeper
Spybot - Search & Destroy 1.4
TaxACT 2002
TaxACT 2003
TaxACT 2004
upapp
USB Storage Driver
USBControl
Windows 98 KB891711 Update
Windows 98 Q823559 Update
Windows 98 Q840315 Update
Windows 98 Q888113 Update
Windows 98 Q890175 Update
WinZip Self-Extractor


Thanks for your help.
rob

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
computer slow, desktop hijacker & daosearch
« Reply #19 on: July 03, 2005, 10:07:54 PM »
Go ahead and remove SpySweeper from your system
Restart the computer afterwards

You probably have to install the correct Video drivers
Yours may be corrupt
Can you check your device manager for any yellow exclamation marks or red x's please
Right click "MyComputer"
Left click Properties

I would still like you to run those 2 files thru that online malware scan
One or both may be legit, I want a look see at them
Here's the instructions again

Quote
Can you go to this link
Give this site time to load
Jotti's Online Malware scan

Use the browse button and navigate to this file on your hard drive
C:\WINDOWS\SYSTEM\aucbpnp.exe <-this file
Right click on it  and choose Select
Then use the Submit button
Let it finish scanning
Could you post back the results of the scan back here please, just the scanner results which includes name of file

Do the same for this file
C:\WINDOWS\CLGAMMA.EXE <-this may be legit, but won't hurt to check it
« Last Edit: July 03, 2005, 11:07:33 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here