i have done hijack this and the report follows
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:00:40, on 18/09/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\WINDOWS\system32\svchost.exe
c:\windows\system32\HealthNotifier.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\system32\lxdxcoms.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
C:\Program Files\Motorola\MotoConnectService\MotoConnect.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe
C:\Program Files\BT Broadband Desktop Help\btbb_wcm\McciTrayApp.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\Yahoo!\Search Protection\YspService.exe
C:\Program Files\Lexmark 3600-4600 Series\lxdxMsdMon.exe
C:\DOCUME~1\phil\LOCALS~1\Temp\Tj1.exe
c:\Program Files\STOPzilla!\STOPzilla.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\AVG\AVG9\avgui.exe
C:\Program Files\AVG\AVG9\avgcmgr.exe
C:\Program Files\Netscape\Navigator 9\navigator.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sp/*http://uk.search.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.mywebsearch.com/mywebsearch/default.jhtml?ptnrS=ZLfox000&ptb=5l0s4jVA313BWBGBrwwXkw
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sp/*http://uk.search.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - *00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
R3 - URLSearchHook: (no name) - *CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - *E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
R3 - URLSearchHook: (no name) - *{E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
R3 - URLSearchHook: (no name) - *{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
R3 - URLSearchHook: (no name) - *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: (no name) - rsion - (no file)
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\Stopzilla!\Toolbar\SZSG.dll
O2 - BHO: YSPManager - {25BC7718-0BFA-40EA-B381-4B2D9732D686} - C:\Program Files\Yahoo!\Search Protection\ysp.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Beta - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - c:\Program Files\STOPzilla!\SZIEBHO.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: &Windows Live Toolbar Beta - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\Stopzilla!\Toolbar\SZSG.dll
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\WordPerfect Office 11\Programs\QFSCHD110.EXE"
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [lxdxmon.exe] "C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe"
O4 - HKLM\..\Run: [lxdxamon] "C:\Program Files\Lexmark 3600-4600 Series\lxdxamon.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [btbb_McciTrayApp] "C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe"
O4 - HKLM\..\Run: [btbb_wcm_McciTrayApp] "C:\Program Files\BT Broadband Desktop Help\btbb_wcm\McciTrayApp.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Power2GoExpress] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\YspService.exe
O4 - HKCU\..\Run: [TrayOKO] C:\Documents and Settings\phil\Application Data\Microsoft\ld30.exe
O4 - HKCU\..\Run: [YXE7DXCQ37] C:\DOCUME~1\phil\LOCALS~1\Temp\Tj1.exe
O4 - HKLM\..\Policies\Explorer\Run: [nvstfatxo] rundll32 "C:\WINDOWS\system32\msvideoz.dll",ritmilg
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Search with Wanadoo - res://C:\WINDOWS\system32\WSBar.dll/VSearch.htm
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BBF74FB9-ABCD-4678-880A-2511DAABB5E1} - C:\Program Files\Yahoo!\Search Protection\ysp.dll
O9 - Extra 'Tools' menuitem: Yahoo! Search Protection - {BBF74FB9-ABCD-4678-880A-2511DAABB5E1} - C:\Program Files\Yahoo!\Search Protection\ysp.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://uk.msn.com/
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file://C:\Program Files\SCRABBLE\Images\stg_drm.ocx
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file://C:\Program Files\SCRABBLE\Images\armhelper.ocx
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\570\G2AWinLogon.dll
O22 - SharedTaskScheduler: homeridae - {95dde900-8bf3-428c-b9be-8345c9d194f7} - (no file)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\570\g2aservice.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HealthNotifier - Unknown owner - c:\windows\system32\HealthNotifier.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: lxdxCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdxserv.exe
O23 - Service: lxdx_device - - C:\WINDOWS\system32\lxdxcoms.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - Unknown owner - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (file missing)
O23 - Service: MotoConnect Service - Unknown owner - C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe
O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - c:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 16090 bytes
so any ideas would be great

Recommended Answers

All 28 Replies

I believe I have a virus but I don't know what to do about it. Any time I try to download a program to fix my computer, it won't let me. Also, if I try to go to a website for an anti virus program, I get an error page. Occasionally when I am on the internet tons of internet explorers will open on their own, over and over again, crashing my computer.
Please help.

You have some malware loading:

C:\DOCUME~1\phil\LOCALS~1\Temp\Tj1.exe

You have some malware loading:

C:\DOCUME~1\phil\LOCALS~1\Temp\Tj1.exe

You are correct OldTime. We saw that, this is why the poster must follow all the steps in the Read Me Sticky. The longer he waits the more infected the computer will become.

that file i cant get rid of

that file i cant get rid of

One thing you can do is go to the properties of the file, go to the Security tab, go to Advanced and then the Owner tab. From there, take ownership of the file. After taking ownership, remove read & execute permissions from the user "SYSTEM" and then restart your computer. After rebooting, the file will not be able to run and therefore you should then be able to delete the file.

that file i cant get rid of

Follow the link I provided and do the steps there if you want our assistance.
Everybody who comes for help follows those steps.

One thing you can do is go to the properties of the file, go to the Security tab, go to Advanced and then the Owner tab. From there, take ownership of the file. After taking ownership, remove read & execute permissions from the user "SYSTEM" and then restart your computer. After rebooting, the file will not be able to run and therefore you should then be able to delete the file.

I appreciate that you are trying to help, but as jholland1964 already told you, there are steps to be taken to ensure a clean pc. Giving a quick fix is not the answer.

still cant get to that page to change or delete it n just to let everyone know i'm using my laptop which is fine its the pc that is infected

So download those tools in the sticky on to your laptop and use a flash drive or something to transfer them to the affected PC.

I appreciate that you are trying to help, but as jholland1964 already told you, there are steps to be taken to ensure a clean pc. Giving a quick fix is not the answer.

I assumed he had already done so after jholland1964's post and still couldn't get rid of the file and therefore I offered an idea to help.

DS (Ver_10-03-17.01) - NTFSx86
Run by phil at 21:59:06.48 on 20/09/2010
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_19
Microsoft Windows XP Home Edition 5.1.2600.2.1252.44.1033.18.1022.474 [GMT 1:00]


============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k svcnet
c:\windows\system32\HealthNotifier.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\lxdxcoms.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Motorola\MotoConnectService\MotoConnect.exe
C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\BT Broadband Desktop Help\btbb_wcm\McciTrayApp.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Lexmark 3600-4600 Series\lxdxMsdMon.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\DOCUME~1\phil\LOCALS~1\Temp\Tj1.exe
E:\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://search.mywebsearch.com/mywebsearch/default.jhtml?ptnrS=ZLfox000&ptb=5l0s4jVA313BWBGBrwwXkw
uSearch Page = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sp/*http://uk.search.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex}&startPage={startPage}
mDefault_Page_URL = hxxp://www.yahoo.com
mDefault_Search_URL = hxxp://www.google.com/ie
mSearch Page = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sp/*http://uk.search.yahoo.com/
mStart Page = hxxp://www.yahoo.com
mSearch Bar = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn2\yt.dll
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
mURLSearchHooks: SrchHook Class: {d3f669eb-57ce-4f45-8fbd-e245cbb46366} - c:\program files\stopzilla!\toolbar\SZIESearchHook.dll
mURLSearchHooks: H - No File
BHO: rsion - No File
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn2\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - c:\program files\lexmark toolbar\toolband.dll
BHO: ZILLAbar Browser Helper Object: {1827766b-9f49-4854-8034-f6ee26fcb1ec} - c:\program files\stopzilla!\toolbar\SZSG.dll
BHO: Yahooo Search Protection: {25bc7718-0bfa-40ea-b381-4b2d9732d686} - c:\program files\yahoo!\search protection\ysp.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\progra~1\yahoo!\common\yiesrvc.dll
BHO: Click-to-Call BHO: {5c255c8a-e604-49b4-9d64-90988571cecb} - c:\program files\windows live\messenger\wlchtc.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Beta: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: STOPzilla Browser Helper Object: {e3215f20-3212-11d6-9f8b-00d0b743919d} - c:\program files\stopzilla!\SZIEBHO.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn2\YTSingleInstance.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn2\yt.dll
TB: &Windows Live Toolbar Beta: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - c:\program files\lexmark toolbar\toolband.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll
TB: STOPzilla: {98828ded-a591-462f-83ba-d2f62a68b8b8} - c:\program files\stopzilla!\toolbar\SZSG.dll
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
EB: &Research: {ff059e31-cc5a-4e2e-bf3b-96e929d65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
uRun: [Power2GoExpress] %systemroot%\system32\dumprep 0 -k
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\Wcescomm.exe"
uRun: [YSearchProtection] c:\program files\yahoo!\search protection\YspService.exe
uRun: [TrayOKO] c:\documents and settings\phil\application data\microsoft\ld30.exe
uRun: [YXE7DXCQ37] c:\docume~1\phil\locals~1\temp\Tj1.exe
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [QuickFinder Scheduler] "c:\program files\wordperfect office 11\programs\QFSCHD110.EXE"
mRun: [Lexmark X1100 Series] "c:\program files\lexmark x1100 series\lxbkbmgr.exe"
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [lxdxmon.exe] "c:\program files\lexmark 3600-4600 series\lxdxmon.exe"
mRun: [lxdxamon] "c:\program files\lexmark 3600-4600 series\lxdxamon.exe"
mRun: [FaxCenterServer] "c:\program files\lexmark fax solutions\fm3032.exe" /s
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [btbb_McciTrayApp] "c:\program files\bt broadband desktop help\btbb\BTHelpNotifier.exe"
mRun: [btbb_wcm_McciTrayApp] "c:\program files\bt broadband desktop help\btbb_wcm\McciTrayApp.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
mExplorerRun: [nvstfatxo] rundll32 "c:\windows\system32\msvideoz.dll",ritmilg
IE: &Search
IE: &Windows Live Search - c:\program files\windows live toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Search with Wanadoo - c:\windows\system32\WSBar.dll/VSearch.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\progra~1\yahoo!\common\yiesrvc.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {BBF74FB9-ABCD-4678-880A-2511DAABB5E1} - {25BC7718-0BFA-40EA-B381-4B2D9732D686} - c:\program files\yahoo!\search protection\ysp.dll
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file://c:\program files\scrabble\images\stg_drm.ocx
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?40394.3027893519
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file://c:\program files\scrabble\images\armhelper.ocx
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: GoToAssist - c:\program files\citrix\gotoassist\570\G2AWinLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
STS: {95dde900-8bf3-428c-b9be-8345c9d194f7}: homeridae
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL

============= SERVICES / DRIVERS ===============

R0 RapportKELL;RapportKELL;c:\windows\system32\drivers\RapportKELL.sys [2010-8-5 58984]
R0 szkg5;szkg5;c:\windows\system32\drivers\SZKG.sys [2009-12-7 61328]
R0 szkgfs;szkgfs;c:\windows\system32\drivers\SZKGFS.sys [2010-5-12 59280]
R1 ClausDisk;HID Band Driver Microsoft Adapter Internet Mouse File handler DataHandler;c:\windows\system32\drivers\clauspnp.sys [2004-12-19 56320]
R1 RapportCerberus_18130;RapportCerberus_18130;c:\documents and settings\all users\application data\trusteer\rapport\store\exts\rapportcerberus\18130\RapportCerberus_18130.sys [2010-8-5 34536]
R1 RapportPG;RapportPG;c:\program files\trusteer\rapport\bin\RapportPG.sys [2010-8-5 168936]
R2 ATTSCAP;AVerMedia, WDM MPEG-2 TS Capture (DVBT);c:\windows\system32\drivers\attscap.sys [2005-1-21 18048]
R2 ATVCAP;AVerMedia, DVB-T WDM Video Capture;c:\windows\system32\drivers\atvcap.sys [2005-1-21 56320]
R2 ATXBAR;AVerMedia, DVB-T WDM Crossbar;c:\windows\system32\drivers\atxbar.sys [2005-1-21 8576]
R2 ClopSrv;Controller. USB Search Handler Profile Management;c:\windows\system32\svchost.exe -k svcnet [2004-10-27 14336]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2008-11-15 56344]
R2 HealthNotifier;HealthNotifier;c:\windows\system32\HealthNotifier.exe [2005-4-8 775680]
R2 lxdx_device;lxdx_device;c:\windows\system32\lxdxcoms.exe -service --> c:\windows\system32\lxdxcoms.exe -service [?]
R2 MotoConnect Service;MotoConnect Service;c:\program files\motorola\motoconnectservice\MotoConnectService.exe [2010-5-10 91392]
R2 RapportMgmtService;Rapport Management Service;c:\program files\trusteer\rapport\bin\RapportMgmtService.exe [2010-8-5 763112]
S0 is3srv;is3srv;c:\windows\system32\drivers\is3srv.sys [2009-12-7 61328]
S2 lxdxCATSCustConnectService;lxdxCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdxserv.exe [2008-12-7 98984]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\c:\program files\common files\symantec shared\eengine\eraserutilrebootdrv.sys --> c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [?]
S3 fsssvc;Windows Live Family Safety;c:\program files\windows live\family safety\fsssvc.exe [2008-9-4 512536]
S3 McComponentHostService;McAfee Security Scan Component Host Service;"c:\program files\mcafee security scan\2.0.181\mcchsvc.exe" --> c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [?]
S3 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2007-9-27 1174664]
S4 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-5-7 38224]

=============== Created Last 30 ================

2010-09-20 17:09:58 1424 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2010-09-20 16:52:39 0 d-----w- c:\program files\AVG2
2010-09-18 20:59:46 0 d-----w- c:\program files\Trend Micro
2010-09-17 17:53:48 22992 ----a-r- c:\windows\system32\SZIO5.dll
2010-09-17 17:53:48 132560 ----a-r- c:\windows\system32\IS3HTUI5.dll
2010-09-17 17:53:46 99792 ----a-r- c:\windows\system32\IS3Svc5.dll
2010-09-17 17:53:46 67024 ----a-r- c:\windows\system32\IS3Hks5.dll
2010-09-17 17:53:46 546256 ----a-r- c:\windows\system32\SZComp5.dll
2010-09-17 17:53:46 452048 ----a-r- c:\windows\system32\SZBase5.dll
2010-09-17 17:53:46 398800 ----a-r- c:\windows\system32\IS3DBA5.dll
2010-09-17 17:53:46 28624 ----a-r- c:\windows\system32\IS3XDat5.dll
2010-09-17 17:53:44 99792 ----a-r- c:\windows\system32\IS3Inet5.dll
2010-09-17 17:53:44 738768 ----a-r- c:\windows\system32\IS3Base5.dll
2010-09-17 17:53:44 390608 ----a-r- c:\windows\system32\IS3UI5.dll
2010-09-17 17:53:44 230864 ----a-r- c:\windows\system32\IS3Win325.dll
2010-09-08 11:04:35 155648 --sha-r- c:\windows\system32\msvideoz.dll
2010-09-08 11:04:20 211968 ----a-w- c:\windows\Tboxya.exe
2010-08-30 11:42:05 0 d-----w- c:\docume~1\phil\applic~1\Trusteer
2010-08-30 11:41:27 0 d-----w- c:\program files\Trusteer
2010-08-30 11:40:12 0 d-----w- c:\docume~1\alluse~1\applic~1\Trusteer

==================== Find3M ====================

2010-08-21 17:25:01 17934 ----a-w- c:\docume~1\phil\applic~1\wklnhst.dat
2010-08-05 18:19:28 58984 ----a-w- c:\windows\system32\drivers\RapportKELL.sys
2009-05-19 16:26:38 469 ----a-w- c:\program files\Shortcut to Yahoo!.lnk
2008-02-15 09:07:12 5917620 ----a-w- c:\program files\kristi_trailer.wmv
2007-02-01 19:32:35 5632 -csha-w- c:\program files\Thumbs.db
2006-12-03 19:08:21 25755448 ----a-w- c:\program files\wmp11-windowsxp-x86-enu.exe
2006-11-08 17:17:44 4800516 ----a-w- c:\program files\victoria_rose.mpeg
2006-11-02 18:20:34 7866 ----a-w- c:\program files\VirginNetSettings.ins
2006-10-17 10:48:55 15302448 ----a-w- c:\program files\IE7RC1-WindowsXP-x86-enu.exe
2006-10-16 23:09:48 3889355 ----a-w- c:\program files\SexyBack.mp3
2006-10-16 22:39:50 858 ----a-w- c:\program files\MyChemicalRomanceWel.gvp
2006-10-03 17:37:10 83264238 ----a-w- c:\program files\fm2007_demo_vanilla.zip
2006-09-23 14:30:12 736650 ----a-w- c:\program files\subcat1MB.rm
2006-07-03 13:29:32 36499856 ----a-w- c:\program files\6-6_xp-2k_dd_ccc_wdm_enu_33678.exe
2006-07-03 13:22:45 23510720 ----a-w- c:\program files\dotnetfx.exe
2006-07-03 13:01:58 10672504 ----a-w- c:\program files\hydravision-3-25-0006.exe
2006-04-23 17:56:25 11817800 ----a-w- c:\program files\GoogleEarth.exe

re doing wat was here

NLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-03-17.01)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 08/04/2005 13:05:52
System Uptime: 20/09/2010 18:05:47 (4 hours ago)

Motherboard: | | MS-7093
Processor: AMD Athlon(tm) 64 Processor 3800+ | Socket 939 | 2400/200mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 182 GiB total, 91.33 GiB free.
D: is FIXED (NTFS) - 186 GiB total, 186.227 GiB free.
E: is CDROM (UDF)
F: is CDROM ()
H: is Removable
I: is Removable
J: is Removable
K: is Removable

==== Disabled Device Manager Items =============

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: 802.11g PCI Wireless Network Adapter
Device ID: PCI\VEN_1814&DEV_0201&SUBSYS_68341462&REV_01\4&1C88B56&0&10A4
Manufacturer: 802.11 Wireless
Name: 802.11g PCI Wireless Network Adapter
PNP Device ID: PCI\VEN_1814&DEV_0201&SUBSYS_68341462&REV_01\4&1C88B56&0&10A4
Service: M2500

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: 1394 Net Adapter
Device ID: V1394\NIC1394\9355CB10DC00
Manufacturer: Microsoft
Name: 1394 Net Adapter #2
PNP Device ID: V1394\NIC1394\9355CB10DC00
Service: NIC1394

==== System Restore Points ===================

RP1: 09/09/2010 08:44:38 - System Checkpoint
RP2: 20/09/2010 17:14:02 - Removed AVG Free 9.0
RP3: 20/09/2010 17:18:05 - Installed AVG Free 9.0
RP4: 20/09/2010 21:05:11 - Removed STOPzilla. Available with Windows Installer version 1.2 and later.
RP5: 20/09/2010 21:05:33 - Installed STOPzilla. Available with Windows Installer version 1.2 and later.

==== Installed Programs ======================


ABBYY FineReader 5.0 Sprint
ABBYY FineReader 6.0 Sprint
Adobe Acrobat 5.0
Adobe Flash Player 10 Plugin
Adobe Reader 8.2.4
Age of Empires III
Apple Software Update
Application Suite
ATI - Software Uninstall Utility
ATI Catalyst Control Center
ATI Control Panel
ATI Display Driver
ATI HYDRAVISION
Avanquest update
AVerTV DVB-T
BT Broadband Desktop Help
BT Broadband Support Tools
BT Wireless Connection Manager
BT Yahoo! Applications
BTHomeHub
CardRd81
CCHelp
CCleaner (remove only)
CCScore
Choice Guard
Command & Conquer 3
Command & Conquer Red Alert 2
Compatibility Pack for the 2007 Office system
Contacts
CoPilot - Pocket PC 6
CoPilot PocketPC
CR2
DivX Codec
DNA
Dorling Kindersley Application Database v1.4
Empire Earth III
ESSAdpt
ESSANUP
ESSBrwr
ESSCAM
ESSCDBK
ESScore
ESSCT
ESSEMAIL
ESSgui
ESShelp
ESSini
ESSPCD
ESSPDock
ESSSONIC
ESSTUTOR
ESSvpaht
ESSvpot
FaxTools
Free Mp3 Wma Converter V 1.7.2
FreeZip
GameShadow
GearDrvs
Google Earth
Google Updater
GoToAssist Corporate
greenstreet Publisher 3.13
greenstreet Utilities
HijackThis 2.0.2
HLPCCTR
HLPIndex
HLPPDOCK
HLPSFO
HMRC Employer CD-ROM 2009
HMRC Employer CD-ROM 2010
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB909394)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB918997)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB954708)
iMesh
J2SE Runtime Environment 5.0 Update 4
J2SE Runtime Environment 5.0 Update 6
Jasc Paint Shop Pro 8
Java Auto Updater
Java(TM) 6 Update 19
Java(TM) 6 Update 2
Kodak EasyShare software
KSU
LDC Driving Test 3-in-1
Lexmark 3600-4600 Series
Lexmark Fax Solutions
Lexmark Toolbar
Lexmark Tools for Office
Lexmark X1100 Series
LucasArts' Star Wars Supremacy
Malwarebytes' Anti-Malware
Medieval II Total War
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft .NET Framework 3.0
Microsoft ActiveSync
Microsoft Application Error Reporting
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft Managed DirectX (1126)
Microsoft National Language Support Downlevel APIs
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook Connector
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 12
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
MioMore Desktop 2008
Miro
mobile PhoneTools
Motorola Driver Installation 4.2.0
Motorola Phone Tools
MP3 music player
MP3 Player
MP3 Player Utilities 4.09
MS Access 97 SP2
MSN
MSN Toolbar
MSVCRT
MSXML 4.0 SP2 (KB925672)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 6.0 Parser
Music Coach Player
Music Manager
Musicmatch® Jukebox
NavDesk 2008
Netscape Navigator (9.0.0.6)
Nokia Connectivity Cable Driver
Nokia Lifeblog 2.0
Nokia PC Connectivity Solution
Nokia PC Suite
Notifier
Oblivion
OfotoXMI
Ontrack(R) PowerControls(TM) 3.10 Free
OpenTTD 0.5.3
OTtBP
OTtBPSDK
PCDLNCH
POI-Warner Speed Camera Updater
Power2Go 3.0
PowerDVD
PowerProducer
PrintMaster Gold 3.00
QuickTime
Rapport
Realtek AC'97 Audio
REALTEK Gigabit and Fast Ethernet NIC Driver
RegCure 1.5.0.1
Rome - Total War(TM)
SAGEM F@st 800-840
Scrabble Solution
Screensaver06 1.0
Search Settings 1.1
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944533)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB958644)
Segoe UI
SFR
SFR2
Shockwave
Sid Meier's Civilization 4
SONIC HEROES
Spooner 1.1
SPORE™
Spotify
StarOffice 7
Steam
STOPzilla
STOPzilla Toolbar
SupaDial
Symantec Technical Support Web Controls
The Battle for Middle-earth (tm) II
Transport Tycoon Deluxe
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
USB Wireless Keyboard Driver Ver1.1
V92 PCI Voice Faxmodem
VCAMCEN
Viewpoint Media Player
VPRINTOL
WebFldrs XP
Westwood Shared Internet Components
Windows Communication Foundation
Windows Driver Package - Nokia Modem (06/12/2006 6.81.0.21)
Windows Genuine Advantage Notifications (KB905474)
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Live Beta (all programs)
Windows Live Call
Windows Live Family Safety
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery Beta
Windows Live Sign-in Assistant
Windows Live Toolbar Beta
Windows Live Writer
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player Firefox Plugin
Windows Mobile® Device Handbook
Windows Presentation Foundation
Windows Workflow Foundation
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
WinZip
WordPerfect Office 11
XML Paper Specification Shared Components Pack 1.0
Yahoo! Search Protection
Yahoo! Software Update

==== End Of File ===========================

Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_19

You should really consider updating Internet Explorer. Version 6 is pretty outdated and insecure and is probably one of the main reasons for your malware issues.

You should really consider updating Internet Explorer. Version 6 is pretty outdated and insecure and is probably one of the main reasons for your malware issues.

OldTime, you have been warned once by Crunchie. I realize that you want to help but at this time attempting to install updates on an infected computer is a bad idea. The #1 rule for updating any part of the operating system, and IE IS part of the operating system, is that the system be clean and free of infection.
When the computer is clean THEN I will advise the poster what updates need to be done, and there are many more in addition to Internet Explorer.
PLUS the poster had not yet posted all the requested logs. We cannot advise anything else until all of those programs have been run and the logs posted. THEN we will advise on other clean up steps to complete BEFORE any updates recommending will be done.

OldTime, you have been warned once by Crunchie. I realize that you want to help but at this time attempting to install updates on an infected computer is a bad idea. The #1 rule for updating any part of the operating system, and IE IS part of the operating system, is that the system be clean and free of infection.
When the computer is clean THEN I will advise the poster what updates need to be done, and there are many more in addition to Internet Explorer.
PLUS the poster had not yet posted all the requested logs. We cannot advise anything else until all of those programs have been run and the logs posted. THEN we will advise on other clean up steps to complete BEFORE any updates recommending will be done.

Wait, did I say "Stop what you are doing and install the newest version of IE now!"? Or "Before you do anything else, upgrade IE!!!"? No, I didn't. I was just pointing out the fact that he has a really outdated and insecure version of IE and his malware issues could have stemmed from having such and it should be updated.

Wait, did I say "Stop what you are doing and install the newest version of IE now!"? Or "Before you do anything else, upgrade IE!!!"? No, I didn't. I was just pointing out the fact that he has a really outdated and insecure version of IE and his malware issues could have stemmed from having such and it should be updated.

And too many cooks spoil the broth, so I will kindly ask you to refrain from 'helping' please.

@ jmainzer, you are missing a couple of logs. You need to post them before I go further with this.

And too many cooks spoil the broth, so I will kindly ask you to refrain from 'helping' please.

@ jmainzer, you are missing a couple of logs. You need to post them before I go further with this.

Sorry, I'm not trying to confuse things. I'll zip my lips.

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-09-20 23:30:35
Windows 5.1.2600 Service Pack 2
Running: svhx23cy.exe; Driver: C:\DOCUME~1\phil\LOCALS~1\Temp\pxtdrpog.sys


---- Registry - GMER 1.0.15 ----

Reg HKLM\SOFTWARE\Classes\.EE3sav@ EE3savType
Reg HKLM\SOFTWARE\Classes\.EE3sav\ShellEx
Reg HKLM\SOFTWARE\Classes\.EE3sav\ShellEx\{BB2E617C-0920-11d1-9A0B-00C04FC2D6C1}
Reg HKLM\SOFTWARE\Classes\.EE3sav\ShellEx\{BB2E617C-0920-11d1-9A0B-00C04FC2D6C1}@ {4E5BFBF8-F59A-4e87-9805-1F9B42CC254A}
Reg HKLM\SOFTWARE\Classes\.EE3wsv@ EE3wsvType
Reg HKLM\SOFTWARE\Classes\.EE3wsv\ShellEx
Reg HKLM\SOFTWARE\Classes\.EE3wsv\ShellEx\{BB2E617C-0920-11d1-9A0B-00C04FC2D6C1}
Reg HKLM\SOFTWARE\Classes\.EE3wsv\ShellEx\{BB2E617C-0920-11d1-9A0B-00C04FC2D6C1}@ {4E5BFBF8-F59A-4e87-9805-1F9B42CC254A}
Reg HKLM\SOFTWARE\Classes\.flv@ RealPlayer.FLV.6
Reg HKLM\SOFTWARE\Classes\.flv@PerceivedType video
Reg HKLM\SOFTWARE\Classes\.flv@Content Type video/x-flv
Reg HKLM\SOFTWARE\Classes\.ivr@ RealPlayer.IVR.6
Reg HKLM\SOFTWARE\Classes\.ivr@PerceivedType video
Reg HKLM\SOFTWARE\Classes\.liveupdate@ LiveupdateFile?
Reg HKLM\SOFTWARE\Classes\.mfp@ MacromediaFlashPaper.MacromediaFlashPaper
Reg HKLM\SOFTWARE\Classes\.mfp@Content Type application/x-shockwave-flash
Reg HKLM\SOFTWARE\Classes\.myx@ MySpaceIM
Reg HKLM\SOFTWARE\Classes\.part@ part_auto_file
Reg HKLM\SOFTWARE\Classes\.rpm@Content Type audio/x-pn-realaudio-plugin
Reg HKLM\SOFTWARE\Classes\.rpm@CLSID {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA}
Reg HKLM\SOFTWARE\Classes\.WICSaveGame@ WICSaveGameType
Reg HKLM\SOFTWARE\Classes\.WICSaveGame\ShellEx
Reg HKLM\SOFTWARE\Classes\.WICSaveGame\ShellEx\{BB2E617C-0920-11d1-9A0B-00C04FC2D6C1}
Reg HKLM\SOFTWARE\Classes\.WICSaveGame\ShellEx\{BB2E617C-0920-11d1-9A0B-00C04FC2D6C1}@ {4E5BFBF8-F59A-4e87-9805-1F9B42CC254A}
Reg HKLM\SOFTWARE\Classes\.xaml@ Windows.XamlDocument
Reg HKLM\SOFTWARE\Classes\.xaml@Content Type application/xaml+xml
Reg HKLM\SOFTWARE\Classes\.xaml\bootstrap
Reg HKLM\SOFTWARE\Classes\.xaml\bootstrap@ bootstrap.xaml.1
Reg HKLM\SOFTWARE\Classes\.xbap@ Windows.Xbap
Reg HKLM\SOFTWARE\Classes\.xbap@Content Type application/x-ms-xbap
Reg HKLM\SOFTWARE\Classes\.xbap\bootstrap
Reg HKLM\SOFTWARE\Classes\.xbap\bootstrap@ bootstrap.xbap.1
Reg HKLM\SOFTWARE\Classes\.xml@ xmlfile
Reg HKLM\SOFTWARE\Classes\.xml@Content Type text/xml
Reg HKLM\SOFTWARE\Classes\.xml\OpenWithList
Reg HKLM\SOFTWARE\Classes\.xml\OpenWithList\vsta.exe
Reg HKLM\SOFTWARE\Classes\.xml\OpenWithList\vsta.exe@
Reg HKLM\SOFTWARE\Classes\.xml\OpenWithList\winword.exe
Reg HKLM\SOFTWARE\Classes\.xml\OpenWithList\winword.exe@
Reg HKLM\SOFTWARE\Classes\.xml\OpenWithProgids
Reg HKLM\SOFTWARE\Classes\.xml\OpenWithProgids@VSTA_IP.xml.8.0
Reg HKLM\SOFTWARE\Classes\.xml\OpenWithProgids@InfoPath.Document.2
Reg HKLM\SOFTWARE\Classes\.xml\OpenWithProgids@VSTA.xml.8.0
Reg HKLM\SOFTWARE\Classes\.xml\PersistentHandler
Reg HKLM\SOFTWARE\Classes\.xml\PersistentHandler@ {5e941d80-bf96-11cd-b579-08002b30bfeb}
Reg HKLM\SOFTWARE\Classes\.xps@ XPSViewer.Document
Reg HKLM\SOFTWARE\Classes\.xps@Content Type application/vnd.ms-xpsdocument
Reg HKLM\SOFTWARE\Classes\.xps\bootstrap
Reg HKLM\SOFTWARE\Classes\.xps\bootstrap@ bootstrap.xps.1
Reg HKLM\SOFTWARE\Classes\.xps\OpensWithProgIds
Reg HKLM\SOFTWARE\Classes\.xps\OpensWithProgIds@XPSViewer.Document 0
Reg HKLM\SOFTWARE\Classes\.xps\PersistentHandler
Reg HKLM\SOFTWARE\Classes\.xps\PersistentHandler@ {A9A9AA2F-CAA7-4A6F-95D2-769C556E325B}
Reg HKLM\SOFTWARE\Classes\.xsl@ xslfile
Reg HKLM\SOFTWARE\Classes\.xsl@Content Type text/xml
Reg HKLM\SOFTWARE\Classes\.xsl\OpenWithList
Reg HKLM\SOFTWARE\Classes\.xsl\OpenWithList\vsta.exe
Reg HKLM\SOFTWARE\Classes\.xsl\OpenWithList\vsta.exe@
Reg HKLM\SOFTWARE\Classes\.xsl\OpenWithProgids
Reg HKLM\SOFTWARE\Classes\.xsl\OpenWithProgids@VSTA_IP.xsl.8.0
Reg HKLM\SOFTWARE\Classes\.xsl\OpenWithProgids@VSTA.xsl.8.0
Reg HKLM\SOFTWARE\Classes\.xsl\PersistentHandler
Reg HKLM\SOFTWARE\Classes\.xsl\PersistentHandler@ {5e941d80-bf96-11cd-b579-08002b30bfeb}
Reg HKLM\SOFTWARE\Classes\AACCONVERTERACTIVEX.AacconverteractiveXCtrl.1@ AacconverteractiveX Control
Reg HKLM\SOFTWARE\Classes\AACCONVERTERACTIVEX.AacconverteractiveXCtrl.1\CLSID
Reg HKLM\SOFTWARE\Classes\AACCONVERTERACTIVEX.AacconverteractiveXCtrl.1\CLSID@ {6EBB63B9-8A65-4A52-9663-959E7D9AA449}
Reg HKLM\SOFTWARE\Classes\AACDECODER.AACdecoderCtrl.1@ AACdecoder Control
Reg HKLM\SOFTWARE\Classes\AACDECODER.AACdecoderCtrl.1\CLSID
Reg HKLM\SOFTWARE\Classes\AACDECODER.AACdecoderCtrl.1\CLSID@ {1E2B431B-BCF9-4851-9A10-95EE2A87C3AC}
Reg HKLM\SOFTWARE\Classes\AACDECODER2.AACDecoder2Ctrl.1@ AACDecoder2 Control
Reg HKLM\SOFTWARE\Classes\AACDECODER2.AACDecoder2Ctrl.1\CLSID
Reg HKLM\SOFTWARE\Classes\AACDECODER2.AACDecoder2Ctrl.1\CLSID@ {903EB46D-16B3-4073-AC2A-157C0B3F8D5E}
Reg HKLM\SOFTWARE\Classes\aAvgAPI.AvgBro@ AvgBro Object
Reg HKLM\SOFTWARE\Classes\aAvgAPI.AvgBro\Clsid
Reg HKLM\SOFTWARE\Classes\aAvgAPI.AvgBro\Clsid@ {18B30EBF-6B58-425E-AC54-831C05D91B5A}
Reg HKLM\SOFTWARE\Classes\AC3DEC.Ac3decCtrl.1@ Ac3dec Control
Reg HKLM\SOFTWARE\Classes\AC3DEC.Ac3decCtrl.1\CLSID
Reg HKLM\SOFTWARE\Classes\AC3DEC.Ac3decCtrl.1\CLSID@ {5F350198-232D-44F1-AE79-5C15C32A4BE2}
Reg HKLM\SOFTWARE\Classes\ArmHelper.ArmClass@ ArmHelper Control
Reg HKLM\SOFTWARE\Classes\ArmHelper.ArmClass\CLSID
Reg HKLM\SOFTWARE\Classes\ArmHelper.ArmClass\CLSID@ {CC450D71-CC90-424C-8638-1F2DBAC87A54}
Reg HKLM\SOFTWARE\Classes\ArmHelper.ArmClass\CurVer
Reg HKLM\SOFTWARE\Classes\ArmHelper.ArmClass\CurVer@ ArmHelper.ArmClass.1
Reg HKLM\SOFTWARE\Classes\ArmHelper.ArmClass.1@ ArmHelper Control
Reg HKLM\SOFTWARE\Classes\ArmHelper.ArmClass.1\CLSID
Reg HKLM\SOFTWARE\Classes\ArmHelper.ArmClass.1\CLSID@ {CC450D71-CC90-424C-8638-1F2DBAC87A54}
Reg HKLM\SOFTWARE\Classes\AutoProto.AutoProto@ AutoProto Class
Reg HKLM\SOFTWARE\Classes\AutoProto.AutoProto\CurVer
Reg HKLM\SOFTWARE\Classes\AutoProto.AutoProto\CurVer@ AutoProto.AutoProto.1
Reg HKLM\SOFTWARE\Classes\AutoProto.AutoProto.1@ AutoProto Class
Reg HKLM\SOFTWARE\Classes\AutoProto.AutoProto.1\CLSID
Reg HKLM\SOFTWARE\Classes\AutoProto.AutoProto.1\CLSID@ {D24C7F41-2F44-11D3-92EF-00C0F01F77C1}
Reg HKLM\SOFTWARE\Classes\AutoStream.AutoStream@ AutoStream Class
Reg HKLM\SOFTWARE\Classes\AutoStream.AutoStream\CurVer
Reg HKLM\SOFTWARE\Classes\AutoStream.AutoStream\CurVer@ AutoStream.AutoStream.1
Reg HKLM\SOFTWARE\Classes\AutoStream.AutoStream.1@ AutoStream Class
Reg HKLM\SOFTWARE\Classes\AutoStream.AutoStream.1\CLSID
Reg HKLM\SOFTWARE\Classes\AutoStream.AutoStream.1\CLSID@ {405DE7C0-E7DD-11D2-92C5-00C0F01F77C1}
Reg HKLM\SOFTWARE\Classes\AVG.Office@ AVG plugin for the Microsoft Office
Reg HKLM\SOFTWARE\Classes\AVG.Office\CLSID
Reg HKLM\SOFTWARE\Classes\AVG.Office\CLSID@ {04373D9C-5ED8-44f2-BA00-7895D6A5A2DA}
Reg HKLM\SOFTWARE\Classes\AVG.Office\CurVer
Reg HKLM\SOFTWARE\Classes\AVG.Office\CurVer@ AVG.Office.8
Reg HKLM\SOFTWARE\Classes\AVG.Office.8@ AVG plugin for the Microsoft Office
Reg HKLM\SOFTWARE\Classes\AVG.Office.8\CLSID
Reg HKLM\SOFTWARE\Classes\AVG.Office.8\CLSID@ {04373D9C-5ED8-44f2-BA00-7895D6A5A2DA}
Reg HKLM\SOFTWARE\Classes\avgtoolbar.AVGTOOLBARMenu Button@ AVGTOOLBARMenu Button
Reg HKLM\SOFTWARE\Classes\avgtoolbar.AVGTOOLBARMenu Button\Clsid
Reg HKLM\SOFTWARE\Classes\avgtoolbar.AVGTOOLBARMenu Button\Clsid@ {A057A204-BACC-4D26-9990-79A187E26990}
Reg HKLM\SOFTWARE\Classes\avgtoolbar.AVGTOOLBARToggle Button@ AVGTOOLBARToggle Button
Reg HKLM\SOFTWARE\Classes\avgtoolbar.AVGTOOLBARToggle Button\Clsid
Reg HKLM\SOFTWARE\Classes\avgtoolbar.AVGTOOLBARToggle Button\Clsid@ {A057A204-BACC-4D26-9990-79A187E2698F}
Reg HKLM\SOFTWARE\Classes\BarControl.GDSControl@ GDSControl Class
Reg HKLM\SOFTWARE\Classes\BarControl.GDSControl\CLSID
Reg HKLM\SOFTWARE\Classes\BarControl.GDSControl\CLSID@ {E876339C-2984-41F8-A49A-F908555CE4C9}
Reg HKLM\SOFTWARE\Classes\BarControl.GDSControl\CurVer
Reg HKLM\SOFTWARE\Classes\BarControl.GDSControl\CurVer@ BarControl.GDSControl.1
Reg HKLM\SOFTWARE\Classes\BarControl.GDSControl.1@ GDSControl Class
Reg HKLM\SOFTWARE\Classes\BarControl.GDSControl.1\CLSID
Reg HKLM\SOFTWARE\Classes\BarControl.GDSControl.1\CLSID@ {E876339C-2984-41F8-A49A-F908555CE4C9}
Reg HKLM\SOFTWARE\Classes\BarControl.GoogleBarControl@ GoogleBarControl Class
Reg HKLM\SOFTWARE\Classes\BarControl.GoogleBarControl\CLSID
Reg HKLM\SOFTWARE\Classes\BarControl.GoogleBarControl\CLSID@ {5349B405-C992-4A4D-8EB8-5D237C5A0623}
Reg HKLM\SOFTWARE\Classes\BarControl.GoogleBarControl\CurVer
Reg HKLM\SOFTWARE\Classes\BarControl.GoogleBarControl\CurVer@ BarControl.GoogleBarControl.1
Reg HKLM\SOFTWARE\Classes\BarControl.GoogleBarControl.1@ GoogleBarControl Class
Reg HKLM\SOFTWARE\Classes\BarControl.GoogleBarControl.1\CLSID
Reg HKLM\SOFTWARE\Classes\BarControl.GoogleBarControl.1\CLSID@ {5349B405-C992-4A4D-8EB8-5D237C5A0623}
Reg HKLM\SOFTWARE\Classes\BarControl.GoogleBarControl2@ GoogleBarControl2 Class
Reg HKLM\SOFTWARE\Classes\BarControl.GoogleBarControl2\CLSID
Reg HKLM\SOFTWARE\Classes\BarControl.GoogleBarControl2\CLSID@ {3338A2DD-8C8E-4AC8-94E8-FD248849D77F}
Reg HKLM\SOFTWARE\Classes\BarControl.GoogleBarControl2\CurVer
Reg HKLM\SOFTWARE\Classes\BarControl.GoogleBarControl2\CurVer@ BarControl.GoogleBarControl2.1
Reg HKLM\SOFTWARE\Classes\BarControl.GoogleBarControl2.1@ GoogleBarControl2 Class
Reg HKLM\SOFTWARE\Classes\BarControl.GoogleBarControl2.1\CLSID
Reg HKLM\SOFTWARE\Classes\BarControl.GoogleBarControl2.1\CLSID@ {3338A2DD-8C8E-4AC8-94E8-FD248849D77F}
Reg HKLM\SOFTWARE\Classes\bittorrent@ TORRENT File
Reg HKLM\SOFTWARE\Classes\bittorrent\Content Type
Reg HKLM\SOFTWARE\Classes\bittorrent\Content Type@ application/x-bittorrent
Reg HKLM\SOFTWARE\Classes\bittorrent\DefaultIcon
Reg HKLM\SOFTWARE\Classes\bittorrent\DefaultIcon@ C:\Program Files\BitTorrent\bittorrent.exe,0
Reg HKLM\SOFTWARE\Classes\bittorrent\shell
Reg HKLM\SOFTWARE\Classes\bittorrent\shell@ open
Reg HKLM\SOFTWARE\Classes\bittorrent\shell\open
Reg HKLM\SOFTWARE\Classes\bittorrent\shell\open\command
Reg HKLM\SOFTWARE\Classes\bittorrent\shell\open\command@ "C:\Program Files\BitTorrent\bittorrent.exe" "%1"
Reg HKLM\SOFTWARE\Classes\BitTorrent.BitTorrentCtrl.1@ BitTorrent Control
Reg HKLM\SOFTWARE\Classes\BitTorrent.BitTorrentCtrl.1\CLSID
Reg HKLM\SOFTWARE\Classes\BitTorrent.BitTorrentCtrl.1\CLSID@ {21C4E4B2-40F7-4E77-BF19-8BED7187BB55}
Reg HKLM\SOFTWARE\Classes\BrainGymMaths.GameArea@ BrainGymMaths.GameArea
Reg HKLM\SOFTWARE\Classes\BrainGymMaths.GameArea\Clsid
Reg HKLM\SOFTWARE\Classes\BrainGymMaths.GameArea\Clsid@ {31CBF0FF-DACB-4DF5-B515-4471295CECEA}
Reg HKLM\SOFTWARE\Classes\BT2EN.Dummy@ BT2EN.Dummy
Reg HKLM\SOFTWARE\Classes\BT2EN.Dummy\Clsid
Reg HKLM\SOFTWARE\Classes\BT2EN.Dummy\Clsid@ {9822BE17-36CA-4F50-8E97-1E88A6944486}
Reg HKLM\SOFTWARE\Classes\CLSID\{E51F9669-AE1E-2439-F50A-F8A302B61B33}\InprocServer32@ C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\ITIRCL52.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E51F9669-AE1E-2439-F50A-F8A302B61B33}\InprocServer32@InprocServer32 )l1^Vn-}f(ZXfeAR6.jiTranslationHidden>BbxH8x=!g(3?!!!_GX=b?
Reg HKLM\SOFTWARE\Classes\CLSID\{E51F9669-AE1E-2439-F50A-F8A302B61B33}\InprocServer32@ThreadingModel both
Reg HKLM\SOFTWARE\Classes\CLSID\{E51F9669-AE1E-2439-F50A-F8A302B61B33}\ProgID@ ITIR.DefaultCharMap.5.2
Reg HKLM\SOFTWARE\Classes\CmdLineExt.CmdLineContextMenu@ CmdLineContextMenu Class
Reg HKLM\SOFTWARE\Classes\CmdLineExt.CmdLineContextMenu\CLSID
Reg HKLM\SOFTWARE\Classes\CmdLineExt.CmdLineContextMenu\CLSID@ {F0407C3D-349C-42b9-B83E-821E31623DF9}
Reg HKLM\SOFTWARE\Classes\CmdLineExt.CmdLineContextMenu\CurVer
Reg HKLM\SOFTWARE\Classes\CmdLineExt.CmdLineContextMenu\CurVer@ CmdLineExt.CmdLineContextMenu.1
Reg HKLM\SOFTWARE\Classes\CmdLineExt.CmdLineContextMenu.1@ CmdLineContextMenu Class
Reg HKLM\SOFTWARE\Classes\CmdLineExt.CmdLineContextMenu.1\CLSID
Reg HKLM\SOFTWARE\Classes\CmdLineExt.CmdLineContextMenu.1\CLSID@ {F0407C3D-349C-42b9-B83E-821E31623DF9}
Reg HKLM\SOFTWARE\Classes\ColourMatching.GameArea@ ColourMatching.GameArea
Reg HKLM\SOFTWARE\Classes\ColourMatching.GameArea\Clsid
Reg HKLM\SOFTWARE\Classes\ColourMatching.GameArea\Clsid@ {3A83BE98-BB6C-4419-9D90-3367A0B12378}
Reg HKLM\SOFTWARE\Classes\ColourMatching.Squircle@ ColourMatching.Squircle
Reg HKLM\SOFTWARE\Classes\ColourMatching.Squircle\Clsid
Reg HKLM\SOFTWARE\Classes\ColourMatching.Squircle\Clsid@ {C9BF956E-092E-4242-83C4-F0C65279E0EB}
Reg HKLM\SOFTWARE\Classes\ColourTiles.GameArea@ ColourTiles.GameArea
Reg HKLM\SOFTWARE\Classes\ColourTiles.GameArea\Clsid
Reg HKLM\SOFTWARE\Classes\ColourTiles.GameArea\Clsid@ {A314CC7E-B8AF-4B0C-A405-7959D6D39DBB}
Reg HKLM\SOFTWARE\Classes\COMCTL.ImageListCtrl@ Microsoft ImageList Control, version 5.0 (SP2)
Reg HKLM\SOFTWARE\Classes\COMCTL.ImageListCtrl\CLSID
Reg HKLM\SOFTWARE\Classes\COMCTL.ImageListCtrl\CLSID@ {58DA8D8F-9D6A-101B-AFC0-4210102A8DA7}
Reg HKLM\SOFTWARE\Classes\COMCTL.ImageListCtrl\CurVer
Reg HKLM\SOFTWARE\Classes\COMCTL.ImageListCtrl\CurVer@ COMCTL.ImageListCtrl.1
Reg HKLM\SOFTWARE\Classes\COMCTL.ImageListCtrl.1@ Microsoft ImageList Control, version 5.0 (SP2)
Reg HKLM\SOFTWARE\Classes\COMCTL.ImageListCtrl.1\CLSID
Reg HKLM\SOFTWARE\Classes\COMCTL.ImageListCtrl.1\CLSID@ {58DA8D8F-9D6A-101B-AFC0-4210102A8DA7}
Reg HKLM\SOFTWARE\Classes\COMCTL.ListViewCtrl@ Microsoft ListView Control, version 5.0 (SP2)
Reg HKLM\SOFTWARE\Classes\COMCTL.ListViewCtrl\CLSID
Reg HKLM\SOFTWARE\Classes\COMCTL.ListViewCtrl\CLSID@ {58DA8D8A-9D6A-101B-AFC0-4210102A8DA7}
Reg HKLM\SOFTWARE\Classes\COMCTL.ListViewCtrl\CurVer
Reg HKLM\SOFTWARE\Classes\COMCTL.ListViewCtrl\CurVer@ COMCTL.ListViewCtrl.1
Reg HKLM\SOFTWARE\Classes\COMCTL.ListViewCtrl.1@ Microsoft ListView Control, version 5.0 (SP2)
Reg HKLM\SOFTWARE\Classes\COMCTL.ListViewCtrl.1\CLSID
Reg HKLM\SOFTWARE\Classes\COMCTL.ListViewCtrl.1\CLSID@ {58DA8D8A-9D6A-101B-AFC0-4210102A8DA7}
Reg HKLM\SOFTWARE\Classes\COMCTL.ProgCtrl@ Microsoft ProgressBar Control, version 5.0 (SP2)
Reg HKLM\SOFTWARE\Classes\COMCTL.ProgCtrl\CLSID
Reg HKLM\SOFTWARE\Classes\COMCTL.ProgCtrl\CLSID@ {0713E8D2-850A-101B-AFC0-4210102A8DA7}
Reg HKLM\SOFTWARE\Classes\COMCTL.ProgCtrl\CurVer
Reg HKLM\SOFTWARE\Classes\COMCTL.ProgCtrl\CurVer@ COMCTL.ProgCtrl.1
Reg HKLM\SOFTWARE\Classes\COMCTL.ProgCtrl.1@ Microsoft ProgressBar Control, version 5.0 (SP2)
Reg HKLM\SOFTWARE\Classes\COMCTL.ProgCtrl.1\CLSID
Reg HKLM\SOFTWARE\Classes\COMCTL.ProgCtrl.1\CLSID@ {0713E8D2-850A-101B-AFC0-4210102A8DA7}
Reg HKLM\SOFTWARE\Classes\COMCTL.SBarCtrl@ Microsoft StatusBar Control, version 5.0 (SP2)
Reg HKLM\SOFTWARE\Classes\COMCTL.SBarCtrl\CLSID
Reg HKLM\SOFTWARE\Classes\COMCTL.SBarCtrl\CLSID@ {6B7E638F-850A-101B-AFC0-4210102A8DA7}
Reg HKLM\SOFTWARE\Classes\COMCTL.SBarCtrl\CurVer
Reg HKLM\SOFTWARE\Classes\COMCTL.SBarCtrl\CurVer@ COMCTL.SBarCtrl.1
Reg HKLM\SOFTWARE\Classes\COMCTL.SBarCtrl.1@ Microsoft StatusBar Control, version 5.0 (SP2)
Reg HKLM\SOFTWARE\Classes\COMCTL.SBarCtrl.1\CLSID
Reg HKLM\SOFTWARE\Classes\COMCTL.SBarCtrl.1\CLSID@ {6B7E638F-850A-101B-AFC0-4210102A8DA7}
Reg HKLM\SOFTWARE\Classes\COMCTL.Slider@ Microsoft Slider Control, version 5.0 (SP2)
Reg HKLM\SOFTWARE\Classes\COMCTL.Slider\CLSID
Reg HKLM\SOFTWARE\Classes\COMCTL.Slider\CLSID@ {373FF7F0-EB8B-11CD-8820-08002B2F4F5A}
Reg HKLM\SOFTWARE\Classes\COMCTL.Slider\CurVer
Reg HKLM\SOFTWARE\Classes\COMCTL.Slider\CurVer@ COMCTL.Slider.1
Reg HKLM\SOFTWARE\Classes\COMCTL.Slider.1@ Microsoft Slider Control, version 5.0 (SP2)
Reg HKLM\SOFTWARE\Classes\COMCTL.Slider.1\CLSID
Reg HKLM\SOFTWARE\Classes\COMCTL.Slider.1\CLSID@ {373FF7F0-EB8B-11CD-8820-08002B2F4F5A}
Reg HKLM\SOFTWARE\Classes\COMCTL.TabStrip@ Microsoft TabStrip Control, version 5.0 (SP2)
Reg HKLM\SOFTWARE\Classes\COMCTL.TabStrip\CLSID
Reg HKLM\SOFTWARE\Classes\COMCTL.TabStrip\CLSID@ {9ED94440-E5E8-101B-B9B5-444553540000}
Reg HKLM\SOFTWARE\Classes\COMCTL.TabStrip\CurVer
Reg HKLM\SOFTWARE\Classes\COMCTL.TabStrip\CurVer@ COMCTL.TabStrip.1
Reg HKLM\SOFTWARE\Classes\COMCTL.TabStrip.1@ Microsoft TabStrip Control, version 5.0 (SP2)
Reg HKLM\SOFTWARE\Classes\COMCTL.TabStrip.1\CLSID
Reg HKLM\SOFTWARE\Classes\COMCTL.TabStrip.1\CLSID@ {9ED94440-E5E8-101B-B9B5-444553540000}
Reg HKLM\SOFTWARE\Classes\COMCTL.Toolbar@ Microsoft Toolbar Control, version 5.0 (SP2)
Reg HKLM\SOFTWARE\Classes\COMCTL.Toolbar\CLSID
Reg HKLM\SOFTWARE\Classes\COMCTL.Toolbar\CLSID@ {612A8624-0FB3-11CE-8747-524153480004}
Reg HKLM\SOFTWARE\Classes\COMCTL.Toolbar\CurVer
Reg HKLM\SOFTWARE\Classes\COMCTL.Toolbar\CurVer@ COMCTL.Toolbar.1
Reg HKLM\SOFTWARE\Classes\COMCTL.Toolbar.1@ Microsoft Toolbar Control, version 5.0 (SP2)
Reg HKLM\SOFTWARE\Classes\COMCTL.Toolbar.1\CLSID
Reg HKLM\SOFTWARE\Classes\COMCTL.Toolbar.1\CLSID@ {612A8624-0FB3-11CE-8747-524153480004}
Reg HKLM\SOFTWARE\Classes\COMCTL.TreeCtrl@ Microsoft TreeView Control, version 5.0 (SP2)
Reg HKLM\SOFTWARE\Classes\COMCTL.TreeCtrl\CLSID
Reg HKLM\SOFTWARE\Classes\COMCTL.TreeCtrl\CLSID@ {0713E8A2-850A-101B-AFC0-4210102A8DA7}
Reg HKLM\SOFTWARE\Classes\COMCTL.TreeCtrl\CurVer
Reg HKLM\SOFTWARE\Classes\COMCTL.TreeCtrl\CurVer@ COMCTL.TreeCtrl.1
Reg HKLM\SOFTWARE\Classes\COMCTL.TreeCtrl.1@ Microsoft TreeView Control, version 5.0 (SP2)
Reg HKLM\SOFTWARE\Classes\COMCTL.TreeCtrl.1\CLSID
Reg HKLM\SOFTWARE\Classes\COMCTL.TreeCtrl.1\CLSID@ {0713E8A2-850A-101B-AFC0-4210102A8DA7}
Reg HKLM\SOFTWARE\Classes\ControlActiveX.Subclass@ SoftCircuits Subclass Control
Reg HKLM\SOFTWARE\Classes\ControlActiveX.Subclass\Clsid
Reg HKLM\SOFTWARE\Classes\ControlActiveX.Subclass\Clsid@ {DC92A719-141B-4824-BC00-430C23F7C1F2}
Reg HKLM\SOFTWARE\Classes\CubePicker.GameArea@ CubePicker.GameArea
Reg HKLM\SOFTWARE\Classes\CubePicker.GameArea\Clsid
Reg HKLM\SOFTWARE\Classes\CubePicker.GameArea\Clsid@ {708FB2EA-B85C-40A6-AF02-D516A1E05E61}
Reg HKLM\SOFTWARE\Classes\DMO.HXAudioDeviceHook@ CHXAudioDeviceHook Class
Reg HKLM\SOFTWARE\Classes\DMO.HXAudioDeviceHook\CLSID
Reg HKLM\SOFTWARE\Classes\DMO.HXAudioDeviceHook\CLSID@ {2cfa30da-118b-4ca3-aaf3-f474162302e5}
Reg HKLM\SOFTWARE\Classes\DMO.HXAudioDeviceHook\CurVer
Reg HKLM\SOFTWARE\Classes\DMO.HXAudioDeviceHook\CurVer@ DMO.HXAudioDeviceHook.1
Reg HKLM\SOFTWARE\Classes\DMO.HXAudioDeviceHook.1@ CHXAudioDeviceHook Class
Reg HKLM\SOFTWARE\Classes\DMO.HXAudioDeviceHook.1\CLSID
Reg HKLM\SOFTWARE\Classes\DMO.HXAudioDeviceHook.1\CLSID@ {2cfa30da-118b-4ca3-aaf3-f474162302e5}
Reg HKLM\SOFTWARE\Classes\EE3savType@PreviewTitle prop:System.Game.RichSaveName;System.Game.RichApplicationName
Reg HKLM\SOFTWARE\Classes\EE3savType@PreviewDetails prop:System.Game.RichLevel;System.DateChanged;System.Game.RichComment;System.DisplayName;System.DisplayType
Reg HKLM\SOFTWARE\Classes\EE3savType\Shell
Reg HKLM\SOFTWARE\Classes\EE3savType\Shell\Open
Reg HKLM\SOFTWARE\Classes\EE3savType\Shell\Open\Command
Reg HKLM\SOFTWARE\Classes\EE3savType\Shell\Open\Command@ C:\Program Files\Sierra Entertainment\Empire Earth III\EE3.exe run=%1
Reg HKLM\SOFTWARE\Classes\EE3wsvType@PreviewTitle prop:System.Game.RichSaveName;System.Game.RichApplicationName
Reg HKLM\SOFTWARE\Classes\EE3wsvType@PreviewDetails prop:System.Game.RichLevel;System.DateChanged;System.Game.RichComment;System.DisplayName;System.DisplayType
Reg HKLM\SOFTWARE\Classes\EE3wsvType\Shell
Reg HKLM\SOFTWARE\Classes\EE3wsvType\Shell\Open
Reg HKLM\SOFTWARE\Classes\EE3wsvType\Shell\Open\Command
Reg HKLM\SOFTWARE\Classes\EE3wsvType\Shell\Open\Command@ C:\Program Files\Sierra Entertainment\Empire Earth III\EE3.exe runWD=%1
Reg HKLM\SOFTWARE\Classes\FlacCodec.FlacCodecCtrl.1@ Flac_Codec Control
Reg HKLM\SOFTWARE\Classes\FlacCodec.FlacCodecCtrl.1\CLSID
Reg HKLM\SOFTWARE\Classes\FlacCodec.FlacCodecCtrl.1\CLSID@ {DA16078B-5007-4272-A508-C822EE9716AF}
Reg HKLM\SOFTWARE\Classes\FollowLeader.GameArea@ FollowLeader.GameArea
Reg HKLM\SOFTWARE\Classes\FollowLeader.GameArea\Clsid
Reg HKLM\SOFTWARE\Classes\FollowLeader.GameArea\Clsid@ {C0F0862B-0D10-4214-B100-7B30B3DA728D}
Reg HKLM\SOFTWARE\Classes\FollowLeader.Light@ FollowLeader.Light
Reg HKLM\SOFTWARE\Classes\FollowLeader.Light\Clsid
Reg HKLM\SOFTWARE\Classes\FollowLeader.Light\Clsid@ {447631FD-0943-42E4-BD2E-B475E5C71F08}
Reg HKLM\SOFTWARE\Classes\FourColour.GameArea@ FourColour.GameArea
Reg HKLM\SOFTWARE\Classes\FourColour.GameArea\Clsid
Reg HKLM\SOFTWARE\Classes\FourColour.GameArea\Clsid@ {E1DD7253-8C0E-4628-9C87-4557942CBF0F}
Reg HKLM\SOFTWARE\Classes\freezip@ ZIP File
Reg HKLM\SOFTWARE\Classes\freezip\DefaultIcon
Reg HKLM\SOFTWARE\Classes\freezip\DefaultIcon@ C:\WINDOWS\system32\unknown\freezip.ico
Reg HKLM\SOFTWARE\Classes\freezip\Shell
Reg HKLM\SOFTWARE\Classes\freezip\Shell@ UnZip
Reg HKLM\SOFTWARE\Classes\freezip\Shell\About FreeZip
Reg HKLM\SOFTWARE\Classes\freezip\Shell\About FreeZip\command
Reg HKLM\SOFTWARE\Classes\freezip\Shell\About FreeZip\command@ rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\freezip.inf,AboutNT
Reg HKLM\SOFTWARE\Classes\freezip\Shell\FreeZip Help
Reg HKLM\SOFTWARE\Classes\freezip\Shell\FreeZip Help\command
Reg HKLM\SOFTWARE\Classes\freezip\Shell\FreeZip Help\command@ hh.exe C:\WINDOWS\help\freezip.chm
Reg HKLM\SOFTWARE\Classes\freezip\Shell\ListZip
Reg HKLM\SOFTWARE\Classes\freezip\Shell\ListZip\command
Reg HKLM\SOFTWARE\Classes\freezip\Shell\ListZip\command@ C:\WINDOWS\system32\cmd.exe /k C:\WINDOWS\system32\unknown\unzip.exe -lM "%1"
Reg HKLM\SOFTWARE\Classes\freezip\Shell\Pick UnZip folder
Reg HKLM\SOFTWARE\Classes\freezip\Shell\Pick UnZip folder\command
Reg HKLM\SOFTWARE\Classes\freezip\Shell\Pick UnZip folder\command@ rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\freezip.inf,Pickfolder
Reg HKLM\SOFTWARE\Classes\freezip\Shell\Reset UnZip folder
Reg HKLM\SOFTWARE\Classes\freezip\Shell\Reset UnZip folder\command
Reg HKLM\SOFTWARE\Classes\freezip\Shell\Reset UnZip folder\command@ rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\freezip.inf,Resetfolder
Reg HKLM\SOFTWARE\Classes\freezip\Shell\TestZip
Reg HKLM\SOFTWARE\Classes\freezip\Shell\TestZip\command
Reg HKLM\SOFTWARE\Classes\freezip\Shell\TestZip\command@ C:\WINDOWS\system32\cmd.exe /k C:\WINDOWS\system32\unknown\unzip.exe -tM "%1"
Reg HKLM\SOFTWARE\Classes\freezip\Shell\UnZip
Reg HKLM\SOFTWARE\Classes\freezip\Shell\UnZip\command
Reg HKLM\SOFTWARE\Classes\freezip\Shell\UnZip\command@ C:\WINDOWS\system32\unknown\unzip.exe "%1"
Reg HKLM\SOFTWARE\Classes\freezip\Shell\UnZip &here
Reg HKLM\SOFTWARE\Classes\freezip\Shell\UnZip &here\command
Reg HKLM\SOFTWARE\Classes\freezip\Shell\UnZip &here\command@ C:\WINDOWS\system32\unknown\unzip.exe "%1"
Reg HKLM\SOFTWARE\Classes\freezip\Version
Reg HKLM\SOFTWARE\Classes\freezip\Version@used 1.4.9
Reg HKLM\SOFTWARE\Classes\freezip\Version@1.4.9
Reg HKLM\SOFTWARE\Classes\HexagonSpin.GameArea@ HexagonSpin.GameArea
Reg HKLM\SOFTWARE\Classes\HexagonSpin.GameArea\Clsid
Reg HKLM\SOFTWARE\Classes\HexagonSpin.GameArea\Clsid@ {AAD19BCD-4A76-4962-81CC-2F515ACE4D73}
Reg HKLM\SOFTWARE\Classes\HookMenu.ctxHookMenu@ HookMenu.ctxHookMenu
Reg HKLM\SOFTWARE\Classes\HookMenu.ctxHookMenu\Clsid
Reg HKLM\SOFTWARE\Classes\HookMenu.ctxHookMenu\Clsid@ {066F86D8-D35A-48FB-85D6-1A203DAE80F2}
Reg HKLM\SOFTWARE\Classes\IERJCtl.IERJCtl@ IERJCtl Class
Reg HKLM\SOFTWARE\Classes\IERJCtl.IERJCtl\CurVer
Reg HKLM\SOFTWARE\Classes\IERJCtl.IERJCtl\CurVer@ IERJCtl.IERJCtl.1
Reg HKLM\SOFTWARE\Classes\IERJCtl.IERJCtl.1@ IERJCtl Class
Reg HKLM\SOFTWARE\Classes\IERJCtl.IERJCtl.1\CLSID
Reg HKLM\SOFTWARE\Classes\IERJCtl.IERJCtl.1\CLSID@ {00CEDC01-864D-11D3-908D-00C0F03B3EDC}
Reg HKLM\SOFTWARE\Classes\jpegfile@FriendlyTypeName @%SystemRoot%\system32\shimgvw.dll,-303
Reg HKLM\SOFTWARE\Classes\jpegfile@ImageOptionFlags 3
Reg HKLM\SOFTWARE\Classes\LinkScannerIE.NavFilter@ AVG Safe Search
Reg HKLM\SOFTWARE\Classes\LinkScannerIE.NavFilter\CLSID
Reg HKLM\SOFTWARE\Classes\LinkScannerIE.NavFilter\CLSID@ {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Reg HKLM\SOFTWARE\Classes\LinkScannerIE.NavFilter\CurVer
Reg HKLM\SOFTWARE\Classes\LinkScannerIE.NavFilter\CurVer@ LinkScannerIE.NavFilter.1
Reg HKLM\SOFTWARE\Classes\LinkScannerIE.NavFilter.1@ AVG Safe Search
Reg HKLM\SOFTWARE\Classes\LinkScannerIE.NavFilter.1\CLSID
Reg HKLM\SOFTWARE\Classes\LinkScannerIE.NavFilter.1\CLSID@ {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Reg HKLM\SOFTWARE\Classes\LiveupdateFile@ LiveUpdate Settings File
Reg HKLM\SOFTWARE\Classes\LiveupdateFile@NoOpen
Reg HKLM\SOFTWARE\Classes\LiveupdateFile\DefaultIcon
Reg HKLM\SOFTWARE\Classes\LiveupdateFile\DefaultIcon@ C:\Program Files\Symantec\LiveUpdate\LUALL.EXE,0
Reg HKLM\SOFTWARE\Classes\mailto@URL Protocol
Reg HKLM\SOFTWARE\Classes\mailto@ URL:MailTo Protocol
Reg HKLM\SOFTWARE\Classes\mailto\DefaultIcon
Reg HKLM\SOFTWARE\Classes\mailto\DefaultIcon@ "C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE",7
Reg HKLM\SOFTWARE\Classes\mailto\shell
Reg HKLM\SOFTWARE\Classes\mailto\shell\open
Reg HKLM\SOFTWARE\Classes\mailto\shell\open\command
Reg HKLM\SOFTWARE\Classes\mailto\shell\open\command@ "C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE" -c IPM.Note /m "%1"
Reg HKLM\SOFTWARE\Classes\MatchPairs.Card@ MatchPairs.Card
Reg HKLM\SOFTWARE\Classes\MatchPairs.Card\Clsid
Reg HKLM\SOFTWARE\Classes\MatchPairs.Card\Clsid@ {0FB13A6F-6BBD-43C7-970C-B6914F21749E}
Reg HKLM\SOFTWARE\Classes\MatchPairs.GameArea@ MatchPairs.GameArea
Reg HKLM\SOFTWARE\Classes\MatchPairs.GameArea\Clsid
Reg HKLM\SOFTWARE\Classes\MatchPairs.GameArea\Clsid@ {C6EA1C82-2482-41AF-AD75-F2B072211CBC}
Reg HKLM\SOFTWARE\Classes\MemoryGrid.GameArea@ MemoryGrid.GameArea
Reg HKLM\SOFTWARE\Classes\MemoryGrid.GameArea\Clsid
Reg HKLM\SOFTWARE\Classes\MemoryGrid.GameArea\Clsid@ {C86B609D-1C05-48A9-8960-A730B5C1DD53}
Reg HKLM\SOFTWARE\Classes\Microsoft.FreeThreadedXMLDOM@ Free Threaded XML DOM Document
Reg HKLM\SOFTWARE\Classes\Microsoft.FreeThreadedXMLDOM\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.FreeThreadedXMLDOM\CLSID@ {2933BF91-7B36-11D2-B20E-00C04F983E60}
Reg HKLM\SOFTWARE\Classes\Microsoft.FreeThreadedXMLDOM\CurVer
Reg HKLM\SOFTWARE\Classes\Microsoft.FreeThreadedXMLDOM\CurVer@ Microsoft.FreeThreadedXMLDOM.1.0
Reg HKLM\SOFTWARE\Classes\Microsoft.FreeThreadedXMLDOM.1.0@ Free Threaded XML DOM Document
Reg HKLM\SOFTWARE\Classes\Microsoft.FreeThreadedXMLDOM.1.0\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.FreeThreadedXMLDOM.1.0\CLSID@ {2933BF91-7B36-11D2-B20E-00C04F983E60}
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDOM@ XML DOM Document
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDOM\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDOM\CLSID@ {2933BF90-7B36-11D2-B20E-00C04F983E60}
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDOM\CurVer
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDOM\CurVer@ Microsoft.XMLDOM.1.0
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDOM.1.0@ XML DOM Document
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDOM.1.0\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDOM.1.0\CLSID@ {2933BF90-7B36-11D2-B20E-00C04F983E60}
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDSO@ XML Data Source Object
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDSO\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDSO\CLSID@ {550DDA30-0541-11D2-9CA9-0060B0EC3D39}
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDSO\CurVer
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDSO\CurVer@ Microsoft.XMLDSO.1.0
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDSO.1.0@ XML Data Source Object
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDSO.1.0\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLDSO.1.0\CLSID@ {550DDA30-0541-11D2-9CA9-0060B0EC3D39}
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLHTTP@ XML HTTP Request
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLHTTP\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLHTTP\CLSID@ {ED8C108E-4349-11D2-91A4-00C04F7969E8}
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLHTTP\CurVer
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLHTTP\CurVer@ Microsoft.XMLHTTP.1.0
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLHTTP.1.0@ XML HTTP Request
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLHTTP.1.0\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLHTTP.1.0\CLSID@ {ED8C108E-4349-11D2-91A4-00C04F7969E8}
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLParser@ XML Parser
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLParser\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLParser\CLSID@ {D2423620-51A0-11D2-9CAF-0060B0EC3D39}
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLParser\CurVer
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLParser\CurVer@ Microsoft.XMLParser.1.0
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLParser.1.0@ XML Parser
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLParser.1.0\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.XMLParser.1.0\CLSID@ {D2423620-51A0-11D2-9CAF-0060B0EC3D39}
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ImageComboCtl@ Microsoft ImageComboBox Control 6.0 (SP6)
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ImageComboCtl\CLSID
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ImageComboCtl\CLSID@ {DD9DA666-8594-11D1-B16A-00C0F0283628}
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ImageComboCtl\CurVer
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ImageComboCtl\CurVer@ MSComctlLib.ImageComboCtl.2
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ImageComboCtl.2@ Microsoft ImageComboBox Control 6.0 (SP6)
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ImageComboCtl.2\CLSID
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ImageComboCtl.2\CLSID@ {DD9DA666-8594-11D1-B16A-00C0F0283628}
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ImageListCtrl@ Microsoft ImageList Control 6.0 (SP6)
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ImageListCtrl\CLSID
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ImageListCtrl\CLSID@ {2C247F23-8591-11D1-B16A-00C0F0283628}
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ImageListCtrl\CurVer
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ImageListCtrl\CurVer@ MSComctlLib.ImageListCtrl.2
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ImageListCtrl.2@ Microsoft ImageList Control 6.0 (SP6)
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ImageListCtrl.2\CLSID
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ImageListCtrl.2\CLSID@ {2C247F23-8591-11D1-B16A-00C0F0283628}
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ListViewCtrl@ Microsoft ListView Control 6.0 (SP6)
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ListViewCtrl\CLSID
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ListViewCtrl\CLSID@ {BDD1F04B-858B-11D1-B16A-00C0F0283628}
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ListViewCtrl\CurVer
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ListViewCtrl\CurVer@ MSComctlLib.ListViewCtrl.2
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ListViewCtrl.2@ Microsoft ListView Control 6.0 (SP6)
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ListViewCtrl.2\CLSID
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ListViewCtrl.2\CLSID@ {BDD1F04B-858B-11D1-B16A-00C0F0283628}
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ProgCtrl@ Microsoft ProgressBar Control 6.0 (SP6)
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ProgCtrl\CLSID
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ProgCtrl\CLSID@ {35053A22-8589-11D1-B16A-00C0F0283628}
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ProgCtrl\CurVer
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ProgCtrl\CurVer@ MSComctlLib.ProgCtrl.2
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ProgCtrl.2@ Microsoft ProgressBar Control 6.0 (SP6)
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ProgCtrl.2\CLSID
Reg HKLM\SOFTWARE\Classes\MSComctlLib.ProgCtrl.2\CLSID@ {35053A22-8589-11D1-B16A-00C0F0283628}
Reg HKLM\SOFTWARE\Classes\MSComctlLib.SBarCtrl@ Microsoft StatusBar Control 6.0 (SP6)
Reg HKLM\SOFTWARE\Classes\MSComctlLib.SBarCtrl\CLSID
Reg HKLM\SOFTWARE\Classes\MSComctlLib.SBarCtrl\CLSID@ {8E3867A3-8586-11D1-B16A-00C0F0283628}
Reg HKLM\SOFTWARE\Classes\MSComctlLib.SBarCtrl\CurVer
Reg HKLM\SOFTWARE\Classes\MSComctlLib.SBarCtrl\CurVer@ MSComctlLib.SBarCtrl.2
Reg HKLM\SOFTWARE\Classes\MSComctlLib.SBarCtrl.2@ Microsoft StatusBar Control 6.0 (SP6)
Reg HKLM\SOFTWARE\Classes\MSComctlLib.SBarCtrl.2\CLSID
Reg HKLM\SOFTWARE\Classes\MSComctlLib.SBarCtrl.2\CLSID@ {8E3867A3-8586-11D1-B16A-00C0F0283628}
Reg HKLM\SOFTWARE\Classes\MSComctlLib.Slider@ Microsoft Slider Control 6.0 (SP6)
Reg HKLM\SOFTWARE\Classes\MSComctlLib.Slider\CLSID
Reg HKLM\SOFTWARE\Classes\MSComctlLib.Slider\CLSID@ {F08DF954-8592-11D1-B16A-00C0F0283628}
Reg HKLM\SOFTWARE\Classes\MSComctlLib.Slider\CurVer
Reg HKLM\SOFTWARE\Classes\MSComctlLib.Slider\CurVer@ MSComctlLib.Slider.2
Reg HKLM\SOFTWARE\Classes\MSComctlLib.Slider.2@ Microsoft Slider Control 6.0 (SP6)
Reg HKLM\SOFTWARE\Classes\MSComctlLib.Slider.2\CLSID
Reg HKLM\SOFTWARE\Classes\MSComctlLib.Slider.2\CLSID@ {F08DF954-8592-11D1-B16A-00C0F0283628}
Reg HKLM\SOFTWARE\Classes\MSComctlLib.TabStrip@ Microsoft TabStrip Control 6.0 (SP6)
Reg HKLM\SOFTWARE\Classes\MSComctlLib.TabStrip\CLSID
Reg HKLM\SOFTWARE\Classes\MSComctlLib.TabStrip\CLSID@ {1EFB6596-857C-11D1-B16A-00C0F0283628}
Reg HKLM\SOFTWARE\Classes\MSComctlLib.TabStrip\CurVer
Reg HKLM\SOFTWARE\Classes\MSComctlLib.TabStrip\CurVer@ MSComctlLib.TabStrip.2
Reg HKLM\SOFTWARE\Classes\MSComctlLib.TabStrip.2@ Microsoft TabStrip Control 6.0 (SP6)
Reg HKLM\SOFTWARE\Classes\MSComctlLib.TabStrip.2\CLSID
Reg HKLM\SOFTWARE\Classes\MSComctlLib.TabStrip.2\CLSID@ {1EFB6596-857C-11D1-B16A-00C0F0283628}
Reg HKLM\SOFTWARE\Classes\MSComctlLib.Toolbar@ Microsoft Toolbar Control 6.0 (SP6)
Reg HKLM\SOFTWARE\Classes\MSComctlLib.Toolbar\CLSID
Reg HKLM\SOFTWARE\Classes\MSComctlLib.Toolbar\CLSID@ {66833FE6-8583-11D1-B16A-00C0F0283628}
Reg HKLM\SOFTWARE\Classes\MSComctlLib.Toolbar\CurVer
Reg HKLM\SOFTWARE\Classes\MSComctlLib.Toolbar\CurVer@ MSComctlLib.Toolbar.2
Reg HKLM\SOFTWARE\Classes\MSComctlLib.Toolbar.2@ Microsoft Toolbar Control 6.0 (SP6)
Reg HKLM\SOFTWARE\Classes\MSComctlLib.Toolbar.2\CLSID
Reg HKLM\SOFTWARE\Classes\MSComctlLib.Toolbar.2\CLSID@ {66833FE6-8583-11D1-B16A-00C0F0283628}
Reg HKLM\SOFTWARE\Classes\MSComctlLib.TreeCtrl@ Microsoft TreeView Control 6.0 (SP6)
Reg HKLM\SOFTWARE\Classes\MSComctlLib.TreeCtrl\CLSID
Reg HKLM\SOFTWARE\Classes\MSComctlLib.TreeCtrl\CLSID@ {C74190B6-8589-11D1-B16A-00C0F0283628}
Reg HKLM\SOFTWARE\Classes\MSComctlLib.TreeCtrl\CurVer
Reg HKLM\SOFTWARE\Classes\MSComctlLib.TreeCtrl\CurVer@ MSComctlLib.TreeCtrl.2
Reg HKLM\SOFTWARE\Classes\MSComctlLib.TreeCtrl.2@ Microsoft TreeView Control 6.0 (SP6)
Reg HKLM\SOFTWARE\Classes\MSComctlLib.TreeCtrl.2\CLSID
Reg HKLM\SOFTWARE\Classes\MSComctlLib.TreeCtrl.2\CLSID@ {C74190B6-8589-11D1-B16A-00C0F0283628}
Reg HKLM\SOFTWARE\Classes\Msxml@ Msxml
Reg HKLM\SOFTWARE\Classes\Msxml\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml\CLSID@ {CFC399AF-D876-11D0-9C10-00C04FC99C8E}
Reg HKLM\SOFTWARE\Classes\MSXML.DOMDocument@ XML DOM Document
Reg HKLM\SOFTWARE\Classes\MSXML.DOMDocument\CLSID
Reg HKLM\SOFTWARE\Classes\MSXML.DOMDocument\CLSID@ {2933BF90-7B36-11D2-B20E-00C04F983E60}
Reg HKLM\SOFTWARE\Classes\MSXML.DOMDocument\CurVer
Reg HKLM\SOFTWARE\Classes\MSXML.DOMDocument\CurVer@ Microsoft.XMLDOM.1.0
Reg HKLM\SOFTWARE\Classes\MSXML.FreeThreadedDOMDocument@ Free Threaded XML DOM Document
Reg HKLM\SOFTWARE\Classes\MSXML.FreeThreadedDOMDocument\CLSID
Reg HKLM\SOFTWARE\Classes\MSXML.FreeThreadedDOMDocument\CLSID@ {2933BF91-7B36-11D2-B20E-00C04F983E60}
Reg HKLM\SOFTWARE\Classes\MSXML.FreeThreadedDOMDocument\CurVer
Reg HKLM\SOFTWARE\Classes\MSXML.FreeThreadedDOMDocument\CurVer@ Microsoft.FreeThreadedXMLDOM.1.0
Reg HKLM\SOFTWARE\Classes\Msxml2.DOMDocument@ XML DOM Document
Reg HKLM\SOFTWARE\Classes\Msxml2.DOMDocument\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.DOMDocument\CLSID@ {F6D90F11-9C73-11D3-B32E-00C04F990BB4}
Reg HKLM\SOFTWARE\Classes\Msxml2.DOMDocument\CurVer
Reg HKLM\SOFTWARE\Classes\Msxml2.DOMDocument\CurVer@ Msxml2.DOMDocument.3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.DOMDocument.3.0@ XML DOM Document 3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.DOMDocument.3.0\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.DOMDocument.3.0\CLSID@ {F5078F32-C551-11D3-89B9-0000F81FE221}
Reg HKLM\SOFTWARE\Classes\Msxml2.DSOControl@ XML Data Source Object
Reg HKLM\SOFTWARE\Classes\Msxml2.DSOControl\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.DSOControl\CLSID@ {F6D90F14-9C73-11D3-B32E-00C04F990BB4}
Reg HKLM\SOFTWARE\Classes\Msxml2.DSOControl\CurVer
Reg HKLM\SOFTWARE\Classes\Msxml2.DSOControl\CurVer@ Msxml2.DSOControl.3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.DSOControl.3.0@ XML Data Source Object 3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.DSOControl.3.0\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.DSOControl.3.0\CLSID@ {F5078F39-C551-11D3-89B9-0000F81FE221}
Reg HKLM\SOFTWARE\Classes\Msxml2.FreeThreadedDOMDocument@ Free Threaded XML DOM Document
Reg HKLM\SOFTWARE\Classes\Msxml2.FreeThreadedDOMDocument\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.FreeThreadedDOMDocument\CLSID@ {F6D90F12-9C73-11D3-B32E-00C04F990BB4}
Reg HKLM\SOFTWARE\Classes\Msxml2.FreeThreadedDOMDocument\CurVer
Reg HKLM\SOFTWARE\Classes\Msxml2.FreeThreadedDOMDocument\CurVer@ Msxml2.FreeThreadedDOMDocument.3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.FreeThreadedDOMDocument.3.0@ Free Threaded XML DOM Document 3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.FreeThreadedDOMDocument.3.0\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.FreeThreadedDOMDocument.3.0\CLSID@ {F5078F33-C551-11D3-89B9-0000F81FE221}
Reg HKLM\SOFTWARE\Classes\Msxml2.MXXMLWriter@ MXXMLWriter
Reg HKLM\SOFTWARE\Classes\Msxml2.MXXMLWriter\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.MXXMLWriter\CLSID@ {FC220AD8-A72A-4EE8-926E-0B7AD152A020}
Reg HKLM\SOFTWARE\Classes\Msxml2.MXXMLWriter\CurVer
Reg HKLM\SOFTWARE\Classes\Msxml2.MXXMLWriter\CurVer@ Msxml2.MXXMLWriter.3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.MXXMLWriter.3.0@ MXXMLWriter 3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.MXXMLWriter.3.0\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.MXXMLWriter.3.0\CLSID@ {3D813DFE-6C91-4A4E-8F41-04346A841D9C}
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXAttributes@ SAXAttributes
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXAttributes\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXAttributes\CLSID@ {4DD441AD-526D-4A77-9F1B-9841ED802FB0}
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXAttributes\CurVer
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXAttributes\CurVer@ Msxml2.SAXAttributes.3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXAttributes.3.0@ SAXAttributes 3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXAttributes.3.0\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXAttributes.3.0\CLSID@ {3E784A01-F3AE-4DC0-9354-9526B9370EBA}
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXXMLReader@ SAX XML Reader
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXXMLReader\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXXMLReader\CLSID@ {079AA557-4A18-424A-8EEE-E39F0A8D41B9}
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXXMLReader\CurVer
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXXMLReader\CurVer@ Msxml2.SAXXMLReader.3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXXMLReader.3.0@ SAX XML Reader 3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXXMLReader.3.0\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.SAXXMLReader.3.0\CLSID@ {3124C396-FB13-4836-A6AD-1317F1713688}
Reg HKLM\SOFTWARE\Classes\Msxml2.ServerXMLHTTP@ Server XML HTTP
Reg HKLM\SOFTWARE\Classes\Msxml2.ServerXMLHTTP\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.ServerXMLHTTP\CLSID@ {AFBA6B42-5692-48EA-8141-DC517DCF0EF1}
Reg HKLM\SOFTWARE\Classes\Msxml2.ServerXMLHTTP\CurVer
Reg HKLM\SOFTWARE\Classes\Msxml2.ServerXMLHTTP\CurVer@ Msxml2.ServerXMLHTTP.3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.ServerXMLHTTP.3.0@ Server XML HTTP 3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.ServerXMLHTTP.3.0\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.ServerXMLHTTP.3.0\CLSID@ {AFB40FFD-B609-40A3-9828-F88BBE11E4E3}
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLHTTP@ XML HTTP
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLHTTP\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLHTTP\CLSID@ {F6D90F16-9C73-11D3-B32E-00C04F990BB4}
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLHTTP\CurVer
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLHTTP\CurVer@ Msxml2.XMLHTTP.3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLHTTP.3.0@ XML HTTP 3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLHTTP.3.0\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLHTTP.3.0\CLSID@ {F5078F35-C551-11D3-89B9-0000F81FE221}
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLParser@ XML Parser
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLParser\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLParser\CLSID@ {F5078F19-C551-11D3-89B9-0000F81FE221}
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLParser\CurVer
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLParser\CurVer@ Msxml2.XMLParser.3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLParser.3.0@ XML Parser 3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLParser.3.0\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLParser.3.0\CLSID@ {F5078F31-C551-11D3-89B9-0000F81FE221}
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLSchemaCache@ XML Schema Cache
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLSchemaCache\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLSchemaCache\CLSID@ {373984C9-B845-449B-91E7-45AC83036ADE}
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLSchemaCache\CurVer
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLSchemaCache\CurVer@ Msxml2.XMLSchemaCache.3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLSchemaCache.3.0@ XML Schema Cache 3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLSchemaCache.3.0\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.XMLSchemaCache.3.0\CLSID@ {F5078F34-C551-11D3-89B9-0000F81FE221}
Reg HKLM\SOFTWARE\Classes\Msxml2.XSLTemplate@ XSL Template
Reg HKLM\SOFTWARE\Classes\Msxml2.XSLTemplate\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.XSLTemplate\CLSID@ {2933BF94-7B36-11D2-B20E-00C04F983E60}
Reg HKLM\SOFTWARE\Classes\Msxml2.XSLTemplate\CurVer
Reg HKLM\SOFTWARE\Classes\Msxml2.XSLTemplate\CurVer@ Msxml2.XSLTemplate.3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.XSLTemplate.3.0@ XSL Template 3.0
Reg HKLM\SOFTWARE\Classes\Msxml2.XSLTemplate.3.0\CLSID
Reg HKLM\SOFTWARE\Classes\Msxml2.XSLTemplate.3.0\CLSID@ {F5078F36-C551-11D3-89B9-0000F81FE221}
Reg HKLM\SOFTWARE\Classes\MusicExplorer.cTVItem@ MusicExplorer.cTVItem
Reg HKLM\SOFTWARE\Classes\MusicExplorer.cTVItem\Clsid
Reg HKLM\SOFTWARE\Classes\MusicExplorer.cTVItem\Clsid@ {0F8B624E-49E8-4597-A4A7-5348DCAADD32}
Reg HKLM\SOFTWARE\Classes\MusicExplorer.Explorer@ MusicExplorer.Explorer
Reg HKLM\SOFTWARE\Classes\MusicExplorer.Explorer\Clsid
Reg HKLM\SOFTWARE\Classes\MusicExplorer.Explorer\Clsid@ {108BD590-972F-4522-B436-01F29D3FF0BF}
Reg HKLM\SOFTWARE\Classes\myim@URL Protocol
Reg HKLM\SOFTWARE\Classes\myim\shell
Reg HKLM\SOFTWARE\Classes\myim\shell\open
Reg HKLM\SOFTWARE\Classes\myim\shell\open\command
Reg HKLM\SOFTWARE\Classes\myim\shell\open\command@ C:\Program Files\MySpace\IM\MySpaceIM.exe %1
Reg HKLM\SOFTWARE\Classes\NCTAudioDesign2.NCTAmpBar2@ NCTAmpBar2 Class
Reg HKLM\SOFTWARE\Classes\NCTAudioDesign2.NCTAmpBar2\CLSID
Reg HKLM\SOFTWARE\Classes\NCTAudioDesign2.NCTAmpBar2\CLSID@ {2B59C634-1711-4C5D-ABB3-79610E43EA72}
Reg HKLM\SOFTWARE\Classes\NCTAudioDesign2.NCTAmpBar2\CurVer
Reg HKLM\SOFTWARE\Classes\NCTAudioDesign2.NCTAmpBar2\CurVer@ NCTAudioDesign2.NCTAmpBar2.2
Reg HKLM\SOFTWARE\Classes\NCTAudioDesign2.NCTAmpBar2.2@ NCTAmpBar2 Class
Reg HKLM\SOFTWARE\Classes\NCTAudioDesign2.NCTAmpBar2.2\CLSID
Reg HKLM\SOFTWARE\Classes\NCTAudioDesign2.NCTAmpBar2.2\CLSID@ {2B59C634-1711-4C5D-ABB3-79610E43EA72}
Reg HKLM\SOFTWARE\Classes\NCTAudioDesign2.NCTCMU2@ NCTCMU2 Class
Reg HKLM\SOFTWARE\Classes\NCTAudioDesign2.NCTCMU2\CLSID
Reg HKLM\SOFTWARE\Classes\NCTAudioDesign2.NCTCMU2\CLSID@ {48E4246C-0DB9-437F-83CF-A53C230C3022}
Reg HKLM\SOFTWARE\Classes\NCTAudioDesign2.NCTCMU2\CurVer
Reg HKLM\SOFTWARE\Classes\NCTAudioDesign2.NCTCMU2\CurVer@ NCTAudioDesign2.NCTCMU2.2
Reg HKLM\SOFTWARE\Classes\NCTAudioDesign2.NCTCMU2.2@ NCTCMU2 Class
Reg HKLM\SOFTWARE\Classes\NCTAudioDesign2.NCTCMU2.2\CLSID
Reg HKLM\SOFTWARE\Classes\NCTAudioDesign2.NCTCMU2.2\CLSID@ {48E4246C-0DB9-437F-83CF-A53C230C3022}
Reg HKLM\SOFTWARE\Classes\NCTAudioDesign2.NCTEqualizer2@ NCTEqualizer2 Class
Reg HKLM\SOFTWARE\Classes\NCTAudioDesign2.NCTEqualizer2\CLSID
Reg HKLM\SOFTWARE\Classes\NCTAudioDesign2.NCTEqualizer2\CLSID@ {69A825BF-36AD-4A29-85D6-B18EED0E5BC5}
Reg HKLM\SOFTWARE\Classes\NCTAudioDesign2.NCTEqualizer2\CurVer
Reg HKLM\SOFTWARE\Classes\NCTAudioDesign2.NCTEqualizer2\CurVer@ NCTAudioDesign2.NCTEqualizer2.2
Reg HKLM\SOFTWARE\Classes\NCTAudioDesign2.NCTEqualizer2.2@ NCTEqualizer2 Class

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4075

Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

20/09/2010 20:17:27
mbam-log-2010-09-20 (20-17-27).txt

Scan type: Quick scan
Objects scanned: 1
Time elapsed: 5 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

hope thats all the reports u need

Thats great :).

Were you unable to update MBAM?

==

Please download ComboFix by sUBs from HERE or HERE

  • You must download it to and run it from your Desktop
  • Physically disconnect from the internet.
  • Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply.
  • Re-enable all the programs that were disabled during the running of ComboFix..

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Run Combofix ONCE only!!

will not let me load combo fix

just updated mbam running scan on it then ill post it

What happened with combofix? The more info you give, the better I am able to assist.

Can you try running it in safe mode. Tap F8 button whilst booting.

internet explore says page not found on any antivirus programes in normal or safe mode

Are you able to download it from a different location?

If not try this;

Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

There are 4 different versions. If one of them won't run then download and try to run the other one.

Vista and Win7 users need to right click Rkill and choose Run as Administrator

You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

* Rkill.com
* Rkill.scr
* Rkill.pif
* Rkill.exe

  • * Double-click on the Rkill desktop icon to run the tool.

  • *

If using Vista or Windows 7 right-click on it and choose Run As Administrator.
* A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
* If not, delete the file, then download and use the one provided in Link 2.
* If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
* Do not reboot until instructed.
* If the tool does not run from any of the links provided, please let me know.


Once you've gotten one of them to run then try to immediately run the following.

Now download and run exeHelper.

  • * Please download

exeHelper from Raktor to your desktop.
* Double-click on exeHelper.com to run the fix.
* A black window should pop up, press any key to close once the fix is completed.
* A log file named log.txt will be created in the directory where you ran exeHelper.com
* Attach the log.txt file to your next message.

Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

=================================================================

Now try and download and run combofix again.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.