Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: help virus  (Read 4120 times)

0 Members and 1 Guest are viewing this topic.

iamlost

    Topic Starter


    Starter

    • Experience: Beginner
    • OS: Unknown
    help virus
    « on: January 07, 2011, 09:47:41 PM »
    my computer is was saying hard drive in critical danger memory full all kinds of crazy stuff here are my posts i followed all the steps i hope i did it right i have no idea what i am doing please help.

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 12/28/2010 at 10:37 PM

    Application Version : 4.47.1000

    Core Rules Database Version : 6089
    Trace Rules Database Version: 3901

    Scan type       : Complete Scan
    Total Scan Time : 01:02:33

    Memory items scanned      : 773
    Memory threats detected   : 10
    Registry items scanned    : 7202
    Registry threats detected : 760
    File items scanned        : 130901
    File threats detected     : 140

    Disabled.TaskManager
       HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System#DisableTaskMgr
       HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM#DISABLETASKMGR
       HKU\S-1-5-21-2745362794-739201356-432249969-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM#DISABLETASKMGR

    Adware.MyWebSearch
       C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\F3HKSTUB.DLL
       C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\F3HKSTUB.DLL
       C:\PROGRA~1\MYWEBS~1\BAR\1.BIN\MWSSVC.EXE
       C:\PROGRA~1\MYWEBS~1\BAR\1.BIN\MWSSVC.EXE
       C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\M3SRCHMN.EXE
       C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\M3SRCHMN.EXE
       C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\MWSOEMON.EXE
       C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\MWSOEMON.EXE
       C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\MWSOESTB.DLL
       C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\MWSOESTB.DLL
       [My Web Search Bar Search Scope Monitor] C:\PROGRA~1\MYWEBS~1\BAR\1.BIN\M3SRCHMN.EXE
       C:\PROGRA~1\MYWEBS~1\BAR\1.BIN\M3SRCHMN.EXE
       [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\BAR\1.BIN\MWSOEMON.EXE
       C:\PROGRA~1\MYWEBS~1\BAR\1.BIN\MWSOEMON.EXE
       [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\BAR\1.BIN\MWSOEMON.EXE
       HKLM\Software\Classes\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D}
       HKCR\CLSID\{00A6FAF1-072E-44CF-8957-5838F569A31D}
       HKCR\CLSID\{00A6FAF1-072E-44CF-8957-5838F569A31D}
       HKCR\CLSID\{00A6FAF1-072E-44CF-8957-5838F569A31D}\InprocServer32
       HKCR\CLSID\{00A6FAF1-072E-44CF-8957-5838F569A31D}\InprocServer32#ThreadingModel
       HKCR\CLSID\{00A6FAF1-072E-44CF-8957-5838F569A31D}\Programmable
       C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\MWSSRCAS.DLL
       HKLM\Software\Classes\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}
       HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}
       HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}
       HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}\InprocServer32
       HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}\InprocServer32#ThreadingModel
       HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}\Programmable
       HKLM\Software\Classes\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
       HKCR\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
       HKCR\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
       HKCR\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\InprocServer32
       HKCR\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\InprocServer32#ThreadingModel
       C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\MWSBAR.DLL
       HKLM\Software\Classes\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
       HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
       HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
       HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\InprocServer32
       HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\InprocServer32#ThreadingModel
       HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A6FAF1-072E-44cf-8957-5838F569A31D}
       HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
       HKU\S-1-5-21-2745362794-739201356-432249969-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D}
       HKU\S-1-5-21-2745362794-739201356-432249969-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF6-072E-44CF-8957-5838F569A31D}
       HKU\S-1-5-21-2745362794-739201356-432249969-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
       HKU\S-1-5-21-2745362794-739201356-432249969-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
       HKU\S-1-5-21-2745362794-739201356-432249969-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
       HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
       HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
       HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\Control
       HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\InprocServer32
       HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\InprocServer32#ThreadingModel
       HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\MiscStatus
       HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\MiscStatus\1
       HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\ProgID
       HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\Programmable
       HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\TypeLib
       HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\Version
       HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\VersionIndependentProgID
       HKCR\MyWebSearchToolBar.SettingsPlugin.1
       HKCR\MyWebSearchToolBar.SettingsPlugin.1\CLSID
       HKCR\MyWebSearchToolBar.SettingsPlugin
       HKCR\MyWebSearchToolBar.SettingsPlugin\CLSID
       HKCR\MyWebSearchToolBar.SettingsPlugin\CurVer
       HKCR\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA}
       HKCR\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA}\1.0
       HKCR\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA}\1.0\0
       HKCR\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA}\1.0\0\win32
       HKCR\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA}\1.0\FLAGS
       HKCR\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA}\1.0\HELPDIR
       HKLM\Software\Microsoft\Internet Explorer\Toolbar#{07B18EA9-A523-4961-B6BB-170DE4475CCA}
       HKU\S-1-5-21-2745362794-739201356-432249969-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser#{07B18EA9-A523-4961-B6BB-170DE4475CCA}
       HKU\S-1-5-21-2745362794-739201356-432249969-1000\Software\Microsoft\Internet Explorer\URLSearchHooks#{00A6FAF6-072E-44cf-8957-5838F569A31D}
       HKLM\System\ControlSet001\Services\MyWebSearchService
       HKLM\System\ControlSet001\Enum\Root\LEGACY_MyWebSearchService
       HKLM\System\ControlSet003\Services\MyWebSearchService
       HKLM\System\ControlSet003\Enum\Root\LEGACY_MyWebSearchService
       HKLM\System\CurrentControlSet\Services\MyWebSearchService
       HKLM\System\CurrentControlSet\Enum\Root\LEGACY_MyWebSearchService

    Trojan.Agent/Gen-FakeSoft
       C:\USERS\CHRIS&~1\APPDATA\LOCAL\TEMP\VSGAVLKEHSNMOCX.DLL
       C:\USERS\CHRIS&~1\APPDATA\LOCAL\TEMP\VSGAVLKEHSNMOCX.DLL
       C:\USERS\CHRIS & MONET\APPDATA\LOCAL\TEMP\VSGAVLKEHSNMOCX.DLL

    Adware.ShopAtHome/SelectRebates
       C:\PROGRAM FILES\SELECTREBATES\SELECTREBATES.EXE
       C:\PROGRAM FILES\SELECTREBATES\SELECTREBATES.EXE
       [SelectRebates] C:\PROGRAM FILES\SELECTREBATES\SELECTREBATES.EXE

    Adware.MyWebSearch/FunWebProducts
       C:\PROGRAM FILES\WINDOWS LIVE\MESSENGER\MSIMG32.DLL
       C:\PROGRAM FILES\WINDOWS LIVE\MESSENGER\MSIMG32.DLL
       HKLM\Software\Classes\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}
       HKCR\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}
       HKCR\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}
       HKCR\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}\InprocServer32
       HKCR\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}\InprocServer32#ThreadingModel
       HKCR\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}\ProgID
       HKCR\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}\VersionIndependentProgID
       HKCR\FunWebProducts.HTMLMenu.2
       HKCR\FunWebProducts.HTMLMenu.2\CLSID
       HKCR\FunWebProducts.HTMLMenu
       HKCR\FunWebProducts.HTMLMenu\CLSID
       HKCR\FunWebProducts.HTMLMenu\CurVer
       C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\F3HTMLMU.DLL
       HKLM\Software\Classes\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB}
       HKCR\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB}
       HKCR\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB}
       HKCR\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB}\InprocServer32
       HKCR\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB}\InprocServer32#ThreadingModel
       HKCR\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB}\ProgID
       HKCR\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB}\VersionIndependentProgID
       HKCR\FunWebProducts.HTMLMenu.1
       HKCR\FunWebProducts.HTMLMenu.1\CLSID
       HKLM\SOFTWARE\Fun Web Products
       HKLM\SOFTWARE\Fun Web Products#JpegConversionLib
       HKLM\SOFTWARE\Fun Web Products\MSNMessenger
       HKLM\SOFTWARE\Fun Web Products\MSNMessenger#DLLFile
       HKLM\SOFTWARE\Fun Web Products\MSNMessenger#DLLDir
       HKLM\SOFTWARE\Fun Web Products\ScreenSaver
       HKLM\SOFTWARE\Fun Web Products\ScreenSaver#ImagesDir
       HKLM\SOFTWARE\Fun Web Products\Settings
       HKLM\SOFTWARE\Fun Web Products\Settings\Promos
       HKLM\SOFTWARE\Fun Web Products\Settings\Promos#BuddyTextNone.numActive
       HKLM\SOFTWARE\Fun Web Products\Settings\Promos#BuddyTextNone.0
       HKLM\SOFTWARE\Fun Web Products\Settings\Promos#BuddyFreqNone
       HKLM\SOFTWARE\Fun Web Products\Settings\Promos#BuddyTextUninstalled.numActive
       HKLM\SOFTWARE\Fun Web Products\Settings\Promos#BuddyTextUninstalled.0
       HKLM\SOFTWARE\Fun Web Products\Settings\Promos#BuddyFreqUninstalled
       HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.numActive
       HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.numActive2
       HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.1
       HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.2
       HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.3
       HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.4
       HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.5
       HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.6
       HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.7
       HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.8
       HKU\S-1-5-21-2745362794-739201356-432249969-1000\SOFTWARE\FunWebProducts
       HKLM\SOFTWARE\FunWebProducts
       HKLM\SOFTWARE\FunWebProducts\Installer
       HKLM\SOFTWARE\FunWebProducts\Installer#Dir
       HKLM\SOFTWARE\FunWebProducts\Installer#CurInstall
       HKLM\SOFTWARE\FunWebProducts\Installer#sr
       HKLM\SOFTWARE\FunWebProducts\Installer#pl
       HKU\S-1-5-21-2745362794-739201356-432249969-1000\SOFTWARE\MyWebSearch
       HKLM\SOFTWARE\MyWebSearch
       HKLM\SOFTWARE\MyWebSearch\bar
       HKLM\SOFTWARE\MyWebSearch\bar#Maximized
       HKLM\SOFTWARE\MyWebSearch\bar#Visible
       HKLM\SOFTWARE\MyWebSearch\bar#pid
       HKLM\SOFTWARE\MyWebSearch\bar#fwp
       HKLM\SOFTWARE\MyWebSearch\bar#mwsask
       HKLM\SOFTWARE\MyWebSearch\bar#un
       HKLM\SOFTWARE\MyWebSearch\bar#tiec
       HKLM\SOFTWARE\MyWebSearch\bar#Dir
       HKLM\SOFTWARE\MyWebSearch\bar#UninstallString
       HKLM\SOFTWARE\MyWebSearch\bar#PluginPath
       HKLM\SOFTWARE\MyWebSearch\bar#RegHookPath
       HKLM\SOFTWARE\MyWebSearch\bar#Id
       HKLM\SOFTWARE\MyWebSearch\bar#CurInstall
       HKLM\SOFTWARE\MyWebSearch\bar#SettingsDir
       HKLM\SOFTWARE\MyWebSearch\bar#sr
       HKLM\SOFTWARE\MyWebSearch\bar#pl
       HKLM\SOFTWARE\MyWebSearch\bar#HistoryDir
       HKLM\SOFTWARE\MyWebSearch\MWSOEMON
       HKLM\SOFTWARE\MyWebSearch\MWSOEMON#Version
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG#Version
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG#Path
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG#StandardSmileyDir.AIM
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#ICQT.numActive2
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#ICQT.0
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#ICQT.1
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#ICQT.2
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#ICQT.3
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#ICQT.4
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#ICQT.5
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#ICQT.6
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#ICQT.7
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#ICQT.8
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#ICQT.9
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.numActive
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.numActive2
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.0.old
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.1.old
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.2.old
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.3.old
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.4.old
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.5.old
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.6.old
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.7.old
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.8.old
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.9.old
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.10.old
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.11.old
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.12.old
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.13.old
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIM.numActive
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIM.numActive2
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIM.0.old
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIM.1.old
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIM.2.old
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIM.3.old
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIM.4.old
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIM.5.old
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIM.6.old
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIM.7.old
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIM.8
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIMT.numActive2
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIMT.0
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIMT.1
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIMT.2
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIMT.3
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIMT.4
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIMT.5
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIMT.6
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIMT.7
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIMT.8
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIMT.9
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#GoogleTalkHTML.numActive2
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#GoogleTalkHTML.0
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#GoogleTalkHTML.1
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#GoogleTalkHTML.2
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#GoogleTalkHTML.3
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#GoogleTalkHTML.4
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#GoogleTalkHTML.5
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#GoogleTalkHTML.6
       HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#GoogleTalkHTML.7
       HKLM\SOFTWARE\MyWebSearch\OEHosts
       HKLM\SOFTWARE\MyWebSearch\OEHosts#Windows10
       HKLM\SOFTWARE\MyWebSearch\OEHosts#Windows2
       HKLM\SOFTWARE\MyWebSearch\OEHosts#Windows3
       HKLM\SOFTWARE\MyWebSearch\OEHosts#Windows4
       HKLM\SOFTWARE\MyWebSearch\OEHosts#Windows5
       HKLM\SOFTWARE\MyWebSearch\OEHosts#Windows6
       HKLM\SOFTWARE\MyWebSearch\OEHosts#Windows7
       HKLM\SOFTWARE\MyWebSearch\OEHosts#Windows8
       HKLM\SOFTWARE\MyWebSearch\OEHosts#Windows9
       HKLM\SOFTWARE\MyWebSearch\SearchAssistant
       HKLM\SOFTWARE\MyWebSearch\SearchAssistant#pid
       HKLM\SOFTWARE\MyWebSearch\SearchAssistant#fwp
       HKLM\SOFTWARE\MyWebSearch\SearchAssistant#mwsask
       HKLM\SOFTWARE\MyWebSearch\SearchAssistant#esh
       HKLM\SOFTWARE\MyWebSearch\SearchAssistant#lsp
       HKLM\SOFTWARE\MyWebSearch\SearchAssistant#LastRequest
       HKLM\SOFTWARE\MyWebSearch\SearchAssistant#NextRequest
       HKLM\SOFTWARE\MyWebSearch\SkinTools
       HKLM\SOFTWARE\MyWebSearch\SkinTools#PlayerPath
       HKCR\FunWebProducts.DataControl
       HKCR\FunWebProducts.DataControl\CLSID
       HKCR\FunWebProducts.DataControl\CurVer
       HKCR\FunWebProducts.DataControl.1
       HKCR\FunWebProducts.DataControl.1\CLSID
       HKCR\FunWebProducts.HistoryKillerScheduler
       HKCR\FunWebProducts.HistoryKillerScheduler\CLSID
       HKCR\FunWebProducts.HistoryKillerScheduler\CurVer
       HKCR\FunWebProducts.HistoryKillerScheduler.1
       HKCR\FunWebProducts.HistoryKillerScheduler.1\CLSID
       HKCR\FunWebProducts.HistorySwatterControlBar
       HKCR\FunWebProducts.HistorySwatterControlBar\CLSID
       HKCR\FunWebProducts.HistorySwatterControlBar\CurVer
       HKCR\FunWebProducts.HistorySwatterControlBar.1
       HKCR\FunWebProducts.HistorySwatterControlBar.1\CLSID
       HKCR\FunWebProducts.IECookiesManager
       HKCR\FunWebProducts.IECookiesManager\CLSID
       HKCR\FunWebProducts.IECookiesManager\CurVer
       HKCR\FunWebProducts.IECookiesManager.1
       HKCR\FunWebProducts.IECookiesManager.1\CLSID
       HKCR\FunWebProducts.KillerObjManager
       HKCR\FunWebProducts.KillerObjManager\CLSID
       HKCR\FunWebProducts.KillerObjManager\CurVer
       HKCR\FunWebProducts.KillerObjManager.1
       HKCR\FunWebProducts.KillerObjManager.1\CLSID
       HKCR\FunWebProducts.PopSwatterBarButton
       HKCR\FunWebProducts.PopSwatterBarButton\CLSID
       HKCR\FunWebProducts.PopSwatterBarButton\CurVer
       HKCR\FunWebProducts.PopSwatterBarButton.1
       HKCR\FunWebProducts.PopSwatterBarButton.1\CLSID
       HKCR\FunWebProducts.PopSwatterSettingsControl
       HKCR\FunWebProducts.PopSwatterSettingsControl\CLSID
       HKCR\FunWebProducts.PopSwatterSettingsControl\CurVer
       HKCR\FunWebProducts.PopSwatterSettingsControl.1
       HKCR\FunWebProducts.PopSwatterSettingsControl.1\CLSID
       HKCR\MyWebSearch.ChatSessionPlugin
       HKCR\MyWebSearch.ChatSessionPlugin\CLSID
       HKCR\MyWebSearch.ChatSessionPlugin\CurVer
       HKCR\MyWebSearch.ChatSessionPlugin.1
       HKCR\MyWebSearch.ChatSessionPlugin.1\CLSID
       HKCR\MyWebSearch.HTMLPanel
       HKCR\MyWebSearch.HTMLPanel\CLSID
       HKCR\MyWebSearch.HTMLPanel\CurVer
       HKCR\MyWebSearch.HTMLPanel.1
       HKCR\MyWebSearch.HTMLPanel.1\CLSID
       HKCR\MyWebSearch.OutlookAddin
       HKCR\MyWebSearch.OutlookAddin\CLSID
       HKCR\MyWebSearch.OutlookAddin\CurVer
       HKCR\MyWebSearch.OutlookAddin.1
       HKCR\MyWebSearch.OutlookAddin.1\CLSID
       HKCR\MyWebSearch.PseudoTransparentPlugin
       HKCR\MyWebSearch.PseudoTransparentPlugin\CLSID
       HKCR\MyWebSearch.PseudoTransparentPlugin\CurVer
       HKCR\MyWebSearch.PseudoTransparentPlugin.1
       HKCR\MyWebSearch.PseudoTransparentPlugin.1\CLSID
       HKCR\MyWebSearchToolBar.ToolbarPlugin
       HKCR\MyWebSearchToolBar.ToolbarPlugin\CLSID
       HKCR\MyWebSearchToolBar.ToolbarPlugin\CurVer
       HKCR\MyWebSearchToolBar.ToolbarPlugin.1
       HKCR\MyWebSearchToolBar.ToolbarPlugin.1\CLSID
       HKCR\ScreenSaverControl.ScreenSaverInstaller
       HKCR\ScreenSaverControl.ScreenSaverInstaller\CLSID
       HKCR\ScreenSaverControl.ScreenSaverInstaller\CurVer
       HKCR\ScreenSaverControl.ScreenSaverInstaller.1
       HKCR\ScreenSaverControl.ScreenSaverInstaller.1\CLSID
       HKCR\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}
       HKCR\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}\InprocServer32
       HKCR\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}\InprocServer32#ThreadingModel
       HKCR\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}\ProgID
       HKCR\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}\Programmable
       HKCR\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}\TypeLib
       HKCR\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}\VersionIndependentProgID
       HKCR\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}
       HKCR\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}\TreatAs
       HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}
       HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\Implemented Categories
       HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\Implemented Categories\{00021493-0000-0000-C000-000000000046}
       HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\InprocServer32
       HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\InprocServer32#ThreadingModel
       HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\Instance
       HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\Instance#CLSID
       HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\Instance\InitPropertyBag
       HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\Instance\InitPropertyBag#Url
       HKCR\CLSID\{25560540-9571-4D7B-9389-0F166788785A}
       HKCR\CLSID\{25560540-9571-4D7B-9389-0F166788785A}\Control
       HKCR\CLSID\{25560540-9571-4D7B-9389-0F166788785A}\InprocServer32
       HKCR\CLSID\{25560540-9571-4D7B-9389-0F166788785A}\InprocServer32#ThreadingModel
       HKCR\CLSID\{25560540-9571-4D7B-9389-0F166788785A}\MiscStatus
       HKCR\CLSID\{25560540-9571-4D7B-9389-0F166788785A}\MiscStatus\1
       HKCR\CLSID\{25560540-9571-4D7B-9389-0F166788785A}\ProgID
       HKCR\CLSID\{25560540-9571-4D7B-9389-0F166788785A}\Programmable
       HKCR\CLSID\{25560540-9571-4D7B-9389-0F166788785A}\TypeLib
       HKCR\CLSID\{25560540-9571-4D7B-9389-0F166788785A}\Version
       HKCR\CLSID\{25560540-9571-4D7B-9389-0F166788785A}\VersionIndependentProgID
       HKCR\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}
       HKCR\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}\Control
       HKCR\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}\InprocServer32
       HKCR\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}\InprocServer32#ThreadingModel
       HKCR\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}\MiscStatus
       HKCR\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}\MiscStatus\1
       HKCR\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}\ProgID
       HKCR\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}\Programmable
       HKCR\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}\TypeLib
       HKCR\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}\Version
       HKCR\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}\VersionIndependentProgID
       HKCR\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}
       HKCR\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\InprocServer32
       HKCR\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\InprocServer32#ThreadingModel
       HKCR\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\ProgID
       HKCR\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\Programmable
       HKCR\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\TypeLib
       HKCR\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\VersionIndependentProgID
       HKCR\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}
       HKCR\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}\InprocServer32
       HKCR\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}\InprocServer32#ThreadingModel
       HKCR\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}\ProgID
       HKCR\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}\Programmable
       HKCR\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}\TypeLib
       HKCR\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}\VersionIndependentProgID
       HKCR\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}
       HKCR\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\Control
       HKCR\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\InprocServer32
       HKCR\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\InprocServer32#ThreadingModel
       HKCR\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\MiscStatus
       HKCR\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\MiscStatus\1
       HKCR\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\Programmable
       HKCR\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\TypeLib
       HKCR\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\Version
       HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}
       HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\Control
       HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\InprocServer32
       HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\InprocServer32#ThreadingModel
       HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\MiscStatus
       HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\MiscStatus\1
       HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\ProgID
       HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\Programmable
       HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\TypeLib
       HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\Version
       HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\VersionIndependentProgID
       HKCR\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}
       HKCR\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\Control
       HKCR\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\InprocServer32
       HKCR\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\InprocServer32#ThreadingModel
       HKCR\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\MiscStatus
       HKCR\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\MiscStatus\1
       HKCR\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\Programmable
       HKCR\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\TypeLib
       HKCR\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\Version
       HKCR\CLSID\{84DA4FDF-A1CF-4195-8688-3E961F505983}
       HKCR\CLSID\{84DA4FDF-A1CF-4195-8688-3E961F505983}\InprocServer32
       HKCR\CLSID\{84DA4FDF-A1CF-4195-8688-3E961F505983}\InprocServer32#ThreadingModel
       HKCR\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14}
       HKCR\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14}\InprocServer32
       HKCR\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14}\InprocServer32#ThreadingModel
       HKCR\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14}\ProgID
       HKCR\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14}\Programmable
       HKCR\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14}\TypeLib
       HKCR\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14}\VersionIndependentProgID
       HKCR\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA}
       HKCR\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA}\InprocServer32
       HKCR\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA}\InprocServer32#ThreadingModel
       HKCR\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}
       HKCR\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}\InprocServer32
       HKCR\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}\InprocServer32#ThreadingModel
       HKCR\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}\MiscStatus
       HKCR\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}\MiscStatus\1
       HKCR\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}\ProgID
       HKCR\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}\Programmable
       HKCR\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}\TypeLib
       HKCR\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}\Version
       HKCR\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}\VersionIndependentProgID
       HKCR\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3}
       HKCR\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3}\TreatAs
       HKCR\CLSID\{A9571378-68A1-443d-B082-284F960C6D17}
       HKCR\CLSID\{A9571378-68A1-443d-B082-284F960C6D17}\InprocServer32
       HKCR\CLSID\{A9571378-68A1-443d-B082-284F960C6D17}\InprocServer32#ThreadingModel
       HKCR\CLSID\{A9571378-68A1-443d-B082-284F960C6D17}\Programmable
       HKCR\CLSID\{A9571378-68A1-443d-B082-284F960C6D17}\TypeLib
       HKCR\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}
       HKCR\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}\InprocServer32
       HKCR\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}\InprocServer32#ThreadingModel
       HKCR\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}\ProgID
       HKCR\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}\Programmable
       HKCR\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}\VersionIndependentProgID
       HKCR\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}
       HKCR\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}\InprocServer32
       HKCR\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}\InprocServer32#ThreadingModel
       HKCR\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}\MiscStatus
       HKCR\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}\MiscStatus\1
       HKCR\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}\ProgID
       HKCR\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}\Programmable
       HKCR\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}\TypeLib
       HKCR\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}\Version
       HKCR\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}\VersionIndependentProgID
       HKCR\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}
       HKCR\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}\InprocServer32
       HKCR\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}\InprocServer32#ThreadingModel
       HKCR\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}\MiscStatus
       HKCR\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}\MiscStatus\1
       HKCR\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}\ProgID
       HKCR\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}\Programmable
       HKCR\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}\TypeLib
       HKCR\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}\Version
       HKCR\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}\VersionIndependentProgID
       HKCR\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}
       HKCR\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}\InprocServer32
       HKCR\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}\InprocServer32#ThreadingModel
       HKCR\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}\ProgID
       HKCR\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}\Programmable
       HKCR\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}\TypeLib
       HKCR\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}\VersionIndependentProgID
       HKCR\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805}
       HKCR\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805}\InprocServer32
       HKCR\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805}\InprocServer32#ThreadingModel
       HKCR\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805}\Programmable
       HKCR\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805}\TypeLib
       HKCR\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}
       HKCR\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}\Control
       HKCR\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}\InprocServer32
       HKCR\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}\InprocServer32#ThreadingModel
       HKCR\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}\MiscStatus
       HKCR\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}\MiscStatus\1
       HKCR\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}\ProgID
       HKCR\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}\Programmable
       HKCR\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}\TypeLib
       HKCR\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}\Version
       HKCR\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}\VersionIndependentProgID
       HKCR\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A}
       HKCR\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A}\1.0
       HKCR\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A}\1.0\0
       HKCR\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A}\1.0\0\win32
       HKCR\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A}\1.0\FLAGS
       HKCR\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A}\1.0\HELPDIR
       HKCR\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554}
       HKCR\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554}\1.0
       HKCR\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554}\1.0\0
       HKCR\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554}\1.0\0\win32
       HKCR\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554}\1.0\FLAGS
       HKCR\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554}\1.0\HELPDIR
       HKCR\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906}
       HKCR\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906}\1.0
       HKCR\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906}\1.0\0
       HKCR\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906}\1.0\0\win32
       HKCR\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906}\1.0\FLAGS
       HKCR\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906}\1.0\HELPDIR
       HKCR\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9}
       HKCR\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9}\1.0
       HKCR\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9}\1.0\0
       HKCR\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9}\1.0\0\win32
       HKCR\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9}\1.0\FLAGS
       HKCR\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9}\1.0\HELPDIR
       HKCR\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C}
       HKCR\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C}\1.0
       HKCR\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C}\1.0\0
       HKCR\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C}\1.0\0\win32
       HKCR\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C}\1.0\FLAGS
       HKCR\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C}\1.0\HELPDIR
       HKCR\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14}
       HKCR\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14}\1.0
       HKCR\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14}\1.0\0
       HKCR\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14}\1.0\0\win32
       HKCR\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14}\1.0\FLAGS
       HKCR\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14}\1.0\HELPDIR
       HKCR\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144}
       HKCR\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144}\1.0
       HKCR\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144}\1.0\0
       HKCR\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144}\1.0\0\win32
       HKCR\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144}\1.0\FLAGS
       HKCR\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144}\1.0\HELPDIR
       HKCR\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}
       HKCR\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0
       HKCR\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0\0
       HKCR\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0\0\win32
       HKCR\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0\FLAGS
       HKCR\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0\HELPDIR
       HKCR\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D}
       HKCR\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D}\1.0
       HKCR\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D}\1.0\0
       HKCR\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D}\1.0\0\win32
       HKCR\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D}\1.0\FLAGS
       HKCR\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D}\1.0\HELPDIR
       HKCR\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}
       HKCR\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}\1.0
       HKCR\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}\1.0\0
       HKCR\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}\1.0\0\win32
       HKCR\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}\1.0\FLAGS
       HKCR\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}\1.0\HELPDIR
       HKCR\TypeLib\{F42228FB-E84E-479E-B922-FBBD096E792C}
       HKCR\TypeLib\{F42228FB-E84E-479E-B922-FBBD096E792C}\1.0
       HKCR\TypeLib\{F42228FB-E84E-479E-B922-FBBD096E792C}\1.0\0
       HKCR\TypeLib\{F42228FB-E84E-479E-B922-FBBD096E792C}\1.0\0\win32
       HKCR\TypeLib\{F42228FB-E84E-479E-B922-FBBD096E792C}\1.0\FLAGS
       HKCR\TypeLib\{F42228FB-E84E-479E-B922-FBBD096E792C}\1.0\HELPDIR
       HKCR\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA}
       HKCR\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA}\ProxyStubClsid
       HKCR\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA}\ProxyStubClsid32
       HKCR\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA}\TypeLib
       HKCR\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA}\TypeLib#Version
       HKCR\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}
       HKCR\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}\ProxyStubClsid
       HKCR\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}\ProxyStubClsid32
       HKCR\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}\TypeLib
       HKCR\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}\TypeLib#Version
       HKCR\Interface\{1093995A-BA37-41D2-836E-091067C4AD17}
       HKCR\Interface\{1093995A-BA37-41D2-836E-091067C4AD17}\ProxyStubClsid
       HKCR\Interface\{1093995A-BA37-41D2-836E-091067C4AD17}\ProxyStubClsid32
       HKCR\Interface\{1093995A-BA37-41D2-836E-091067C4AD17}\TypeLib
       HKCR\Interface\{1093995A-BA37-41D2-836E-091067C4AD17}\TypeLib#Version
       HKCR\Interface\{120927BF-1700-43BC-810F-FAB92549B390}
       HKCR\Interface\{120927BF-1700-43BC-810F-FAB92549B390}\ProxyStubClsid
       HKCR\Interface\{120927BF-1700-43BC-810F-FAB92549B390}\ProxyStubClsid32
       HKCR\Interface\{120927BF-1700-43BC-810F-FAB92549B390}\TypeLib
       HKCR\Interface\{120927BF-1700-43BC-810F-FAB92549B390}\TypeLib#Version
       HKCR\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}
       HKCR\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}\ProxyStubClsid
       HKCR\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}\ProxyStubClsid32
       HKCR\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}\TypeLib
       HKCR\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}\TypeLib#Version
       HKCR\Interface\{1F52A5FA-A705-4415-B975-88503B291728}
       HKCR\Interface\{1F52A5FA-A705-4415-B975-88503B291728}\ProxyStubClsid
       HKCR\Interface\{1F52A5FA-A705-4415-B975-88503B291728}\ProxyStubClsid32
       HKCR\Interface\{1F52A5FA-A705-4415-B975-88503B291728}\TypeLib
       HKCR\Interface\{1F52A5FA-A705-4415-B975-88503B291728}\TypeLib#Version
       HKCR\Interface\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}
       HKCR\Interface\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}\ProxyStubClsid
       HKCR\Interface\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}\ProxyStubClsid32
       HKCR\Interface\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}\TypeLib
       HKCR\Interface\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}\TypeLib#Version
       HKCR\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}
       HKCR\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid
       HKCR\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid32
       HKCR\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib
       HKCR\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib#Version
       HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
       HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid
       HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid32
       HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib
       HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib#Version
       HKCR\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495}
       HKCR\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495}\ProxyStubClsid
       HKCR\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495}\ProxyStubClsid32
       HKCR\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495}\TypeLib
       HKCR\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495}\TypeLib#Version
       HKCR\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}
       HKCR\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}\ProxyStubClsid
       HKCR\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}\ProxyStubClsid32
       HKCR\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}\TypeLib
       HKCR\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}\TypeLib#Version
       HKCR\Interface\{3E720451-B472-4954-B7AA-33069EB53906}
       HKCR\Interface\{3E720451-B472-4954-B7AA-33069EB53906}\ProxyStubClsid
       HKCR\Interface\{3E720451-B472-4954-B7AA-33069EB53906}\ProxyStubClsid32
       HKCR\Interface\{3E720451-B472-4954-B7AA-33069EB53906}\TypeLib
       HKCR\Interface\{3E720451-B472-4954-B7AA-33069EB53906}\TypeLib#Version
       HKCR\Interface\{3E720453-B472-4954-B7AA-33069EB53906}
       HKCR\Interface\{3E720453-B472-4954-B7AA-33069EB53906}\ProxyStubClsid
       HKCR\Interface\{3E720453-B472-4954-B7AA-33069EB53906}\ProxyStubClsid32
       HKCR\Interface\{3E720453-B472-4954-B7AA-33069EB53906}\TypeLib
       HKCR\Interface\{3E720453-B472-4954-B7AA-33069EB53906}\TypeLib#Version
       HKCR\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C}
       HKCR\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C}\ProxyStubClsid
       HKCR\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C}\ProxyStubClsid32
       HKCR\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C}\TypeLib
       HKCR\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C}\TypeLib#Version
       HKCR\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}
       HKCR\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}\ProxyStubClsid
       HKCR\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}\ProxyStubClsid32
       HKCR\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}\TypeLib
       HKCR\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}\TypeLib#Version
       HKCR\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA}
       HKCR\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA}\ProxyStubClsid
       HKCR\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA}\ProxyStubClsid32
       HKCR\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA}\TypeLib
       HKCR\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA}\TypeLib#Version
       HKCR\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}
       HKCR\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}\ProxyStubClsid
       HKCR\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}\ProxyStubClsid32
       HKCR\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}\TypeLib
       HKCR\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}\TypeLib#Version
       HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}
       HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\ProxyStubClsid
       HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\ProxyStubClsid32
       HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\TypeLib
       HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\TypeLib#Version
       HKCR\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}
       HKCR\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid
       HKCR\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid32
       HKCR\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}\TypeLib
       HKCR\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}\TypeLib#Version
       HKCR\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}
       HKCR\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid
       HKCR\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid32
       HKCR\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}\TypeLib
       HKCR\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}\TypeLib#Version
       HKCR\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}
       HKCR\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid
       HKCR\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid32
       HKCR\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}\TypeLib
       HKCR\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}\TypeLib#Version
       HKCR\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}
       HKCR\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid
       HKCR\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid32
       HKCR\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}\TypeLib
       HKCR\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}\TypeLib#Version
       HKCR\Interface\{90449521-D834-4703-BB4E-D3AA44042FF8}
       HKCR\Interface\{90449521-D834-4703-BB4E-D3AA44042FF8}\ProxyStubClsid
       HKCR\Interface\{90449521-D834-4703-BB4E-D3AA44042FF8}\ProxyStubClsid32
       HKCR\Interface\{90449521-D834-4703-BB4E-D3AA44042FF8}\TypeLib
       HKCR\Interface\{90449521-D834-4703-BB4E-D3AA44042FF8}\TypeLib#Version
       HKCR\Interface\{991AAC62-B100-47CE-8B75-253965244F69}
       HKCR\Interface\{991AAC62-B100-47CE-8B75-253965244F69}\ProxyStubClsid
       HKCR\Interface\{991AAC62-B100-47CE-8B75-253965244F69}\ProxyStubClsid32
       HKCR\Interface\{991AAC62-B100-47CE-8B75-253965244F69}\TypeLib
       HKCR\Interface\{991AAC62-B100-47CE-8B75-253965244F69}\TypeLib#Version
       HKCR\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}
       HKCR\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}\ProxyStubClsid
       HKCR\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}\ProxyStubClsid32
       HKCR\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}\TypeLib
       HKCR\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}\TypeLib#Version
       HKCR\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}
       HKCR\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}\ProxyStubClsid
       HKCR\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}\ProxyStubClsid32
       HKCR\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}\TypeLib
       HKCR\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}\TypeLib#Version
       HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}
       HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\ProxyStubClsid
       HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\ProxyStubClsid32
       HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\TypeLib
       HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\TypeLib#Version
       HKCR\Interface\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1}
       HKCR\Interface\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1}\ProxyStubClsid
       HKCR\Interface\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1}\ProxyStubClsid32
       HKCR\Interface\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1}\TypeLib
       HKCR\Interface\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1}\TypeLib#Version
       HKCR\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}
       HKCR\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}\ProxyStubClsid
       HKCR\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}\ProxyStubClsid32
       HKCR\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}\TypeLib
       HKCR\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}\TypeLib#Version
       HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E}
       HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E}\ProxyStubClsid
       HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E}\ProxyStubClsid32
       HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E}\TypeLib
       HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E}\TypeLib#Version
       HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}
       HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}\ProxyStubClsid
       HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}\ProxyStubClsid32
       HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}\TypeLib
       HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}\TypeLib#Version
       HKCR\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}
       HKCR\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}\ProxyStubClsid
       HKCR\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}\ProxyStubClsid32
       HKCR\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}\TypeLib
       HKCR\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}\TypeLib#Version
       HKCR\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}
       HKCR\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}\ProxyStubClsid
       HKCR\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}\ProxyStubClsid32
       HKCR\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}\TypeLib
       HKCR\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}\TypeLib#Version
       HKCR\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}
       HKCR\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}\ProxyStubClsid
       HKCR\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}\ProxyStubClsid32
       HKCR\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}\TypeLib
       HKCR\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}\TypeLib#Version
       HKCR\Interface\{F87D7FB5-9DC5-4C8C-B998-D8DFE02E2978}
       HKCR\Interface\{F87D7FB5-9DC5-4C8C-B998-D8DFE02E2978}\ProxyStubClsid
       HKCR\Interface\{F87D7FB5-9DC5-4C8C-B998-D8DFE02E2978}\ProxyStubClsid32
       HKCR\Interface\{F87D7FB5-9DC5-4C8C-B998-D8DFE02E2978}\TypeLib
       HKCR\Interface\{F87D7FB5-9DC5-4C8C-B998-D8DFE02E2978}\TypeLib#Version
       HKLM\Software\FocusInteractive
       HKLM\Software\FocusInteractive\bar
       HKLM\Software\FocusInteractive\bar\Switches
       HKLM\Software\FocusInteractive\bar\Switches#incmail.exe
       HKLM\Software\FocusInteractive\bar\Switches#msimn.exe
       HKLM\Software\FocusInteractive\bar\Switches#msn.exe
       HKLM\Software\FocusInteractive\bar\Switches#outlook.exe
       HKLM\Software\FocusInteractive\bar\Switches#waol.exe
       HKLM\Software\FocusInteractive\bar\Switches#aim.exe
       HKLM\Software\FocusInteractive\bar\Switches#icq.exe
       HKLM\Software\FocusInteractive\bar\Switches#icqlite.exe
       HKLM\Software\FocusInteractive\bar\Switches#msmsgs.exe
       HKLM\Software\FocusInteractive\bar\Switches#msnmsgr.exe
       HKLM\Software\FocusInteractive\bar\Switches#ypager.exe
       HKLM\Software\FocusInteractive\bar\Switches#au
       HKLM\Software\FocusInteractive\bar\Switches#mwsSrcAs.dll
       HKLM\Software\FocusInteractive\bar\Switches#ua
       HKLM\Software\FocusInteractive\bar\Switches#ps
       HKLM\Software\FocusInteractive\bar\Switches#ok
       HKLM\Software\FocusInteractive\bar\Switches#od
       HKLM\Software\FocusInteractive\bar\Switches#nk
       HKLM\Software\FocusInteractive\bar\Switches#nd
       HKLM\Software\FocusInteractive\Email-IM
       HKLM\Software\FocusInteractive\Email-IM\0
       HKLM\Software\FocusInteractive\Email-IM\0#Toolbar
       HKLM\Software\FocusInteractive\Email-IM\0#AppName
       HKLM\Software\FocusInteractive\Email-IM\0#Path
       HKLM\Software\FocusInteractive\Outlook
       HKLM\Software\FocusInteractive\Outlook#MyWebSearch.OutlookAddin
       HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall
       HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall#DisplayName
       HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall#HelpLink
       HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall#Publisher
       HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall#UninstallString
       HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall#UrlInfoAbout
       HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService#Type
       HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService#Start
       HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService#ErrorControl
       HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService#ImagePath
       HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService#DisplayName
       HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService#ObjectName
       C:\Program Files\MyWebSearch\bar\1.bin\F3BKGERR.JPG
       C:\Program Files\MyWebSearch\bar\1.bin\F3CJPEG.DLL
       C:\Program Files\MyWebSearch\bar\1.bin\F3DTACTL.DLL
       C:\Program Files\MyWebSearch\bar\1.bin\F3HISTSW.DLL
       C:\Program Files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL
       C:\Program Files\MyWebSearch\bar\1.bin\F3POPSWT.DLL
       C:\Program Files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR
       C:\Program Files\MyWebSearch\bar\1.bin\F3REGHK.DLL
       C:\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL
       C:\Program Files\MyWebSearch\bar\1.bin\F3RESTUB.DLL
       C:\Program Files\MyWebSearch\bar\1.bin\F3SCHMON.EXE
       C:\Program Files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL
       C:\Program Files\MyWebSearch\bar\1.bin\F3SPACER.WMV
       C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT
       C:\Program Files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL
       C:\Program Files\MyWebSearch\bar\1.bin\FWPBUDDY.PNG
       C:\Program Files\MyWebSearch\bar\1.bin\M3AUXSTB.DLL
       C:\Program Files\MyWebSearch\bar\1.bin\M3DLGHK.DLL
       C:\Program Files\MyWebSearch\bar\1.bin\M3HIGHIN.EXE
       C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL
       C:\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL
       C:\Program Files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE
       C:\Program Files\MyWebSearch\bar\1.bin\M3MEDINT.EXE
       C:\Program Files\MyWebSearch\bar\1.bin\M3MSG.DLL
       C:\Program Files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL
       C:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL
       C:\Program Files\MyWebSearch\bar\1.bin\M3SKIN.DLL
       C:\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE
       C:\Program Files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE
       C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
       C:\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE
       C:\Program Files\MyWebSearch\bar\1.bin
       C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S
       C:\Program Files\MyWebSearch\bar\Avatar
       C:\Program Files\MyWebSearch\bar\firefox\chrome\M3FFXTBR.JAR
       C:\Program Files\MyWebSearch\bar\firefox\chrome
       C:\Program Files\MyWebSearch\bar\firefox\CHROME.MANIFEST
       C:\Program Files\MyWebSearch\bar\firefox\INSTALL.RDF
       C:\Program Files\MyWebSearch\bar\firefox\NPMYWEBS.DLL
       C:\Program Files\MyWebSearch\bar\firefox
       C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S
       C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S
       C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S
       C:\Program Files\MyWebSearch\bar\Game
       C:\Program Files\MyWebSearch\bar\History
       C:\Program Files\MyWebSearch\bar\icons\CM.ICO
       C:\Program Files\MyWebSearch\bar\icons\MFC.ICO
       C:\Program Files\MyWebSearch\bar\icons\PSS.ICO
       C:\Program Files\MyWebSearch\bar\icons\SMILEY.ICO
       C:\Program Files\MyWebSearch\bar\icons\WB.ICO
       C:\Program Files\MyWebSearch\bar\icons\ZWINKY.ICO
       C:\Program Files\MyWebSearch\bar\icons
       C:\Program Files\MyWebSearch\bar\Message\COMMON.F3S
       C:\Program Files\MyWebSearch\bar\Message
       C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S
       C:\Program Files\MyWebSearch\bar\Notifier\DOG.F3S
       C:\Program Files\MyWebSearch\bar\Notifier\FISH.F3S
       C:\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S
       C:\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
       C:\Program Files\MyWebSearch\bar\Notifier\MAID.F3S
       C:\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S
       C:\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S
       C:\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S
       C:\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S
       C:\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S
       C:\Program Files\MyWebSearch\bar\Notifier
       C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
       C:\Program Files\MyWebSearch\bar\Settings
       C:\Program Files\MyWebSearch\bar
       C:\Program Files\MyWebSearch
       C:\Program Files\FunWebProducts\ScreenSaver\Images
       C:\Program Files\FunWebProducts\ScreenSaver
       C:\Program Files\FunWebProducts
       C:\Windows\SYSTEM32\F3PSSAVR.SCR
       C:\PROGRAM FILES\WINDOWS LIVE\MESSENGER\RICHED20.DLL
       C:\Windows\Prefetch\M3SKPLAY.EXE-E106D3BA.pf

    Trojan.Agent/Gen-Kazy[IWin]
       C:\USERS\CHRIS & MONET\APPDATA\LOCAL\TEMP\ELKTBHTOIQUEWYN.EXE
       C:\USERS\CHRIS & MONET\APPDATA\LOCAL\TEMP\ELKTBHTOIQUEWYN.EXE
       [ElkTBhTOiqUEWYN.exe] C:\USERS\CHRIS&~1\APPDATA\LOCAL\TEMP\ELKTBHTOIQUEWYN.EXE
       C:\USERS\CHRIS&~1\APPDATA\LOCAL\TEMP\ELKTBHTOIQUEWYN.EXE

    Trojan.Agent/Gen-FraudWare
       C:\USERS\CHRIS&~1\APPDATA\LOCAL\TEMP\832936.EXE
       C:\USERS\CHRIS&~1\APPDATA\LOCAL\TEMP\832936.EXE
       [832936] C:\USERS\CHRIS&~1\APPDATA\LOCAL\TEMP\832936.EXE
       C:\USERS\CHRIS & MONET\APPDATA\LOCAL\TEMP\832936.EXE
       C:\Windows\Prefetch\832936.EXE-5E146713.pf

    Adware.ShopAtHomeSelect
       HKLM\Software\Classes\CLSID\{E8DAAA30-6CAA-4b58-9603-8E54238219E2}
       HKCR\CLSID\{E8DAAA30-6CAA-4B58-9603-8E54238219E2}
       HKCR\CLSID\{E8DAAA30-6CAA-4B58-9603-8E54238219E2}
       HKCR\CLSID\{E8DAAA30-6CAA-4B58-9603-8E54238219E2}\InprocServer32
       HKCR\CLSID\{E8DAAA30-6CAA-4B58-9603-8E54238219E2}\InprocServer32#ThreadingModel
       HKCR\CLSID\{E8DAAA30-6CAA-4B58-9603-8E54238219E2}\ProgID
       HKCR\CLSID\{E8DAAA30-6CAA-4B58-9603-8E54238219E2}\Programmable
       HKCR\CLSID\{E8DAAA30-6CAA-4B58-9603-8E54238219E2}\TypeLib
       HKCR\CLSID\{E8DAAA30-6CAA-4B58-9603-8E54238219E2}\VersionIndependentProgID
       HKCR\ToolBand.ShopAtHomeIEHelper.1
       HKCR\ToolBand.ShopAtHomeIEHelper.1\CLSID
       HKCR\ToolBand.ShopAtHomeIEHelper
       HKCR\ToolBand.ShopAtHomeIEHelper\CLSID
       HKCR\ToolBand.ShopAtHomeIEHelper\CurVer
       HKCR\TypeLib\{462E4AEC-DB3B-4e69-AF61-4F300D76255C}
       HKCR\TypeLib\{462E4AEC-DB3B-4e69-AF61-4F300D76255C}\1.0
       HKCR\TypeLib\{462E4AEC-DB3B-4e69-AF61-4F300D76255C}\1.0\0
       HKCR\TypeLib\{462E4AEC-DB3B-4e69-AF61-4F300D76255C}\1.0\0\win32
       HKCR\TypeLib\{462E4AEC-DB3B-4e69-AF61-4F300D76255C}\1.0\FLAGS
       HKCR\TypeLib\{462E4AEC-DB3B-4e69-AF61-4F300D76255C}\1.0\HELPDIR
       C:\PROGRAM FILES\SELECTREBATES\TOOLBAR\SHOPATHOMETOOLBAR.DLL
       HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E8DAAA30-6CAA-4b58-9603-8E54238219E2}
       HKU\S-1-5-21-2745362794-739201356-432249969-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E8DAAA30-6CAA-4B58-9603-8E54238219E2}

    Adware.SelectRebates
       C:\Program Files\SELECTREBATES\FFToolbar\chrome\sahtoolbar.jar
       C:\Program Files\SELECTREBATES\FFToolbar\chrome
       C:\Program Files\SELECTREBATES\FFToolbar\chrome.manifest
       C:\Program Files\SELECTREBATES\FFToolbar\defaults\preferences\sahtoolbar.js
       C:\Program Files\SELECTREBATES\FFToolbar\defaults\preferences
       C:\Program Files\SELECTREBATES\FFToolbar\defaults
       C:\Program Files\SELECTREBATES\FFToolbar\install.rdf
       C:\Program Files\SELECTREBATES\FFToolbar
       C:\Program Files\SELECTREBATES\SelectAlerts.dat
       C:\Program Files\SELECTREBATES\SelectRebates.ini
       C:\Program Files\SELECTREBATES\SelectRebatesA.dat
       C:\Program Files\SELECTREBATES\SelectRebatesApi.exe
       C:\Program Files\SELECTREBATES\SelectRebatesB.dat
       C:\Program Files\SELECTREBATES\SelectRebatesBT.dat
       C:\Program Files\SELECTREBATES\SelectRebatesDownload.exe
       C:\Program Files\SELECTREBATES\SelectRebatesUninstall.exe
       C:\Program Files\SELECTREBATES\SRebates.dll
       C:\Program Files\SELECTREBATES\SRFF3.dll
       C:\Program Files\SELECTREBATES\Toolbar\AddtoList.bmp
       C:\Program Files\SELECTREBATES\Toolbar\basis.xml
       C:\Program Files\SELECTREBATES\Toolbar\Basis.xml.dym
       C:\Program Files\SELECTREBATES\Toolbar\Blank.bmp
       C:\Program Files\SELECTREBATES\Toolbar\Cache
       C:\Program Files\SELECTREBATES\Toolbar\CashBack.bmp
       C:\Program Files\SELECTREBATES\Toolbar\Coupons.bmp
       C:\Program Files\SELECTREBATES\Toolbar\GroceryCoupon.bmp
       C:\Program Files\SELECTREBATES\Toolbar\icons.bmp
       C:\Program Files\SELECTREBATES\Toolbar\ImageCache
       C:\Program Files\SELECTREBATES\Toolbar\i_magnifying.bmp
       C:\Program Files\SELECTREBATES\Toolbar\logo.bmp
       C:\Program Files\SELECTREBATES\Toolbar\logo_24.bmp
       C:\Program Files\SELECTREBATES\Toolbar\logo_HotSpots.bmp
       C:\Program Files\SELECTREBATES\Toolbar\ReviewSite.bmp
       C:\Program Files\SELECTREBATES\Toolbar\RightControls.dym
       C:\Program Files\SELECTREBATES\Toolbar\Scissors.bmp
       C:\Program Files\SELECTREBATES\Toolbar
       C:\Program Files\SELECTREBATES

    Trojan.Agent/Gen
       HKU\S-1-5-21-2745362794-739201356-432249969-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN#103554165

    Adware.Tracking Cookie
       C:\Users\chris & monet\AppData\Roaming\Microsoft\Windows\Cookies\Low\chris_&_monet@adinterax[2].txt
       C:\Users\chris & monet\AppData\Roaming\Microsoft\Windows\Cookies\Low\chris_&_monet@advertising[2].txt
       C:\Users\chris & monet\AppData\Roaming\Microsoft\Windows\Cookies\Low\chris_&_monet@apmebf[1].txt
       C:\Users\chris & monet\AppData\Roaming\Microsoft\Windows\Cookies\Low\chris_&_monet@atdmt[1].txt
       C:\Users\chris & monet\AppData\Roaming\Microsoft\Windows\Cookies\Low\chris_&_monet@collective-media[2].txt
       C:\Users\chris & monet\AppData\Roaming\Microsoft\Windows\Cookies\Low\chris_&_monet@doubleclick[1].txt
       C:\Users\chris & monet\AppData\Roaming\Microsoft\Windows\Cookies\Low\chris_&_monet@mediaplex[2].txt
    Malwarebytes' Anti-Malware 1.50.1.1100
    www.malwarebytes.org

    Database version: 5414

    Windows 6.0.6002 Service Pack 2
    Internet Explorer 8.0.6001.18999

    12/28/2010 11:06:55 PM
    mbam-log-2010-12-28 (23-06-55).txt

    Scan type: Quick scan
    Objects scanned: 139029
    Time elapsed: 3 minute(s), 2 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 28
    Registry Values Infected: 3
    Registry Data Items Infected: 1
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4D7B-9389-0F166788785A} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3E720452-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98D9753D-D73B-42D5-8C85-4469CDA897AB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9FF05104-B030-46FC-94B8-81276E4E27DF} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSea

    SuperDave

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: help virus
    « Reply #1 on: January 08, 2011, 12:42:04 PM »
    Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

    1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
    2. The fixes are specific to your problem and should only be used for this issue on this machine.
    3. If you don't know or understand something, please don't hesitate to ask.
    4. Please DO NOT run any other tools or scans while I am helping you.
    5. It is important that you reply to this thread. Do not start a new topic.
    6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
    7. Absence of symptoms does not mean that everything is clear.

    If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.

    *************************************************
    Download Security Check by screen317 from one of the following links and save it to your desktop.

    Link 1
    Link 2

    * Unzip SecurityCheck.zip and a folder named Security Check should appear.
    * Open the Security Check folder and double-click Security Check.bat
    * Follow the on-screen instructions inside of the black box.
    * A Notepad document should open automatically called checkup.txt
    * Post the contents of that document in your next reply.

    Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.
    ***************************************************
    Download DDS from HERE or HERE and save it to your desktop.

    Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

    * XP users Double click on dds to run it.
    * If your antivirus or firewall try to block DDS then please allow it to run.
    * When finished DDS will open two (2) logs.

    1) DDS.txt
    2) Attach.txt

    * Save both logs to your desktop.
    * Please copy and paste the entire contents of both logs in your next reply.

    Note: DDS will instruct you to post the Attach.txt log as an attachment.
    Please just post it as you would any other log by copy and pasting it into the reply.
    Windows 8 and Windows 10 dual boot with two SSD's

    iamlost

      Topic Starter


      Starter

      • Experience: Beginner
      • OS: Unknown
      Re: help virus
      « Reply #2 on: January 08, 2011, 11:05:32 PM »

      NOTHING CAME UP IN THE FIRST NOTE PAD FROM SECURITY CHECK AND I THINK I DID IT RIGHT , ALSO I NOTICED IN MY FIRST POST ALL THREE LOGS I HAD COPY AND PASTED DID NOT SHOW UP DO YOU NEED ME TO RE POST FOR YOU. AND THANK YOU THANK YOU THANK YOU FOR YOUR HELP.

      DDS (Ver_10-12-12.02) - NTFSx86 
      Run by chris & monet at  0:00:29.30 on Sun 01/09/2011
      Internet Explorer: 8.0.6001.18999
      Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.3316.2308 [GMT -6:00]

      AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
      SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
      SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
      FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}

      ============== Running Processes ===============

      C:\Windows\system32\wininit.exe
      C:\Windows\system32\lsm.exe
      C:\Windows\system32\svchost.exe -k DcomLaunch
      C:\Windows\system32\svchost.exe -k rpcss
      C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
      C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
      C:\Windows\system32\svchost.exe -k netsvcs
      C:\Windows\system32\svchost.exe -k GPSvcGroup
      C:\Windows\system32\SLsvc.exe
      C:\Windows\system32\svchost.exe -k LocalService
      C:\Program Files\Dell\DellDock\DockLogin.exe
      C:\Windows\system32\svchost.exe -k NetworkService
      C:\Windows\System32\spoolsv.exe
      C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
      c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Windows\system32\taskeng.exe
      C:\Program Files\Common Files\Java\Java Update\jusched.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
      C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
      C:\Program Files\McAfee Online Backup\MOBKbackup.exe
      C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
      C:\Windows\system32\svchost.exe -k imgsvc
      C:\Windows\System32\svchost.exe -k WerSvcGroup
      C:\Windows\system32\SearchIndexer.exe
      C:\Windows\system32\DRIVERS\xaudio.exe
      C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
      C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
      C:\Windows\system32\WUDFHost.exe
      C:\Program Files\McAfee Online Backup\MOBKbackup.exe
      C:\Windows\system32\rundll32.exe
      C:\Windows\System32\mobsync.exe
      C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Program Files\Windows Media Player\wmpnetwk.exe
      C:\Windows\system32\Macromed\Flash\FlashUtil10l_ActiveX.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Dell Support Center\bin\sprtsvc.exe
      C:\Windows\system32\wuauclt.exe
      c:\PROGRA~1\mcafee.com\agent\mcagent.exe
      C:\Windows\system32\svchost.exe -k SDRSVC
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\system32\SearchProtocolHost.exe
      C:\Windows\system32\SearchFilterHost.exe
      C:\Users\chris & monet\Desktop\dds.scr
      C:\Windows\system32\wbem\wmiprvse.exe

      ============== Pseudo HJT Report ===============

      uStart Page = hxxp://www.ask.com?o=13735&l=dir
      uWindow Title = Internet Explorer provided by Dell
      uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
      uURLSearchHooks: UrlSearchHook Class: {00000000-6e41-4fd3-8538-502f5495e5fc} - c:\program files\ask.com\GenericAskToolbar.dll
      uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
      mURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
      BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
      BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
      BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
      BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
      BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
      BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20101104143454.dll
      BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
      BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
      BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll
      BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
      BHO: Dictionary.com Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
      BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
      BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
      BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll
      TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
      TB: The Weather Channel Toolbar: {2e5e800e-6ac0-411e-940a-369530a35e43} - c:\windows\system32\TwcToolbarIe7.dll
      TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
      TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
      TB: ShopAtHome Toolbar: {98279c38-de4b-4bcf-93c9-8ec26069d6f4} - c:\program files\selectrebates\toolbar\ShopAtHomeToolbar.dll
      TB: Dictionary.com Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
      TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
      uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
      mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
      mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
      mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter
      mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
      mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
      IE: &Search
      IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
      IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
      IE: {2E5E800E-6AC0-411E-940A-369530A35E43} - {A6790AA5-C6C7-4BCF-A46D-0FDAC4EA90EB}
      DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
      DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
      DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
      DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
      Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
      Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
      Notify: GoToAssist - c:\program files\citrix\gotoassist\480\G2AWinLogon.dll
      Notify: igfxcui - igfxdev.dll

      ============= SERVICES / DRIVERS ===============

      R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-1-9 386840]
      R1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\drivers\mfenlfk.sys [2010-3-4 64304]
      R1 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2010-3-5 164840]
      R1 MOBKFilter;MOBKFilter;c:\windows\system32\drivers\MOBK.sys [2010-3-4 54776]
      R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
      R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
      R2 DockLoginService;Dock Login Service;c:\program files\dell\delldock\DockLogin.exe [2008-9-23 155648]
      R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-3-4 271480]
      R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-3-4 271480]
      R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-3-4 271480]
      R2 McProxy;McAfee Proxy Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-3-4 271480]
      R2 McShield;McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2010-3-4 171168]
      R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2010-3-4 188136]
      R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\common files\mcafee\systemcore\mfevtps.exe [2010-3-4 141792]
      R2 MOBKbackup;McAfee Online Backup;c:\program files\mcafee online backup\MOBKbackup.exe [2010-2-5 229688]
      R2 RtNdPt60;Realtek NDIS Protocol Driver;c:\windows\system32\drivers\RtNdPt60.sys [2009-2-5 27648]
      R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-3-4 55840]
      R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-3-18 152960]
      R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-3-18 52104]
      R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-3-4 313288]
      S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
      S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-2 135664]
      S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
      S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-3-4 84264]
      S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-3-18 34248]
      S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-3-18 40552]
      S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]

      =============== Created Last 30 ================

      2010-12-29 05:38:21   388096   ----a-r-   c:\users\chris&~1\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
      2010-12-29 05:38:21   --------   d-----w-   c:\program files\Trend Micro
      2010-12-29 05:22:55   472808   ----a-w-   c:\windows\system32\deployJava1.dll
      2010-12-29 05:00:49   --------   d-----w-   c:\users\chris&~1\appdata\roaming\Malwarebytes
      2010-12-29 05:00:32   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
      2010-12-29 05:00:32   --------   d-----w-   c:\progra~2\Malwarebytes
      2010-12-29 05:00:29   20952   ----a-w-   c:\windows\system32\drivers\mbam.sys
      2010-12-29 05:00:29   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
      2010-12-29 04:50:47   172032   ----a-w-   c:\windows\system32\igfxres.dll
      2010-12-29 03:44:26   --------   d-----w-   c:\windows\pss
      2010-12-29 03:12:23   --------   d-----w-   c:\users\chris&~1\appdata\roaming\SUPERAntiSpyware.com
      2010-12-29 03:12:23   --------   d-----w-   c:\progra~2\SUPERAntiSpyware.com
      2010-12-29 03:12:10   --------   d-----w-   c:\program files\SUPERAntiSpyware
      2010-12-27 23:30:33   --------   d-----w-   c:\program files\CCleaner
      2010-12-15 20:02:55   601600   ----a-w-   c:\windows\system32\schedsvc.dll
      2010-12-15 20:02:55   352768   ----a-w-   c:\windows\system32\taskschd.dll
      2010-12-15 20:02:55   345600   ----a-w-   c:\windows\system32\wmicmiplugin.dll
      2010-12-15 20:02:55   270336   ----a-w-   c:\windows\system32\taskcomp.dll
      2010-12-15 20:02:55   171520   ----a-w-   c:\windows\system32\taskeng.exe
      2010-12-15 20:02:51   81920   ----a-w-   c:\windows\system32\consent.exe
      2010-12-15 20:02:49   34304   ----a-w-   c:\windows\system32\atmlib.dll
      2010-12-15 20:02:49   292352   ----a-w-   c:\windows\system32\atmfd.dll
      2010-12-15 20:02:48   72704   ----a-w-   c:\windows\system32\fontsub.dll
      2010-12-15 20:02:38   2048   ----a-w-   c:\windows\system32\tzres.dll
      2010-12-15 20:01:28   2409784   ----a-w-   c:\program files\windows mail\OESpamFilter.dat

      ==================== Find3M  ====================

      2010-11-02 06:01:54   916480   ----a-w-   c:\windows\system32\wininet.dll
      2010-11-02 05:57:41   43520   ----a-w-   c:\windows\system32\licmgr10.dll
      2010-11-02 05:57:27   1469440   ----a-w-   c:\windows\system32\inetcpl.cpl
      2010-11-02 05:57:11   71680   ----a-w-   c:\windows\system32\iesetup.dll
      2010-11-02 05:57:11   109056   ----a-w-   c:\windows\system32\iesysprep.dll
      2010-11-02 05:01:31   385024   ----a-w-   c:\windows\system32\html.iec
      2010-11-02 04:26:10   133632   ----a-w-   c:\windows\system32\ieUnatt.exe
      2010-11-02 04:24:44   1638912   ----a-w-   c:\windows\system32\mshtml.tlb
      2010-10-18 13:31:24   2038272   ----a-w-   c:\windows\system32\win32k.sys

      ============= FINISH:  0:01:14.10 ===============

      iamlost

        Topic Starter


        Starter

        • Experience: Beginner
        • OS: Unknown
        Re: help virus
        « Reply #3 on: January 08, 2011, 11:20:38 PM »
        one more thing should i be afraid to use my computer or should we just reboot everything and start from scratch i am so afraid of these machines.

        SuperDave

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Thanked: 1020
        • Certifications: List
        • Experience: Expert
        • OS: Windows 10
        Re: help virus
        « Reply #4 on: January 09, 2011, 01:32:52 PM »
        Quote
        NOTHING CAME UP IN THE FIRST NOTE PAD FROM SECURITY CHECK AND I THINK I DID IT RIGHT , ALSO I NOTICED IN MY FIRST POST ALL THREE LOGS I HAD COPY AND PASTED DID NOT SHOW UP DO YOU NEED ME TO RE POST FOR YOU. AND THANK YOU THANK YOU THANK YOU FOR YOUR HELP.
        Please turn off your capslock. It is considered shouting.

        Quote
        one more thing should i be afraid to use my computer or should we just reboot everything and start from scratch i am so afraid of these machines.
        If you mean to reformat you harddrive, no. There's nothing yet to indicate that we can't clean it.

        I strongly recommend that you remove Ask from your computer because it;

        •Promotes its toolbars on sites targeted to kids.

        •Promotes its toolbars through ads that appear to be part of other companies' sites.

        •Promotes its toolbars through other companies' spyware.

        •Installs without any disclosure whatsoever and without any consent whatsoever.

        •Solicits installations via "deceptive door openers" that do not accurately describe the offer; failing to affirmatively show a license agreement; linking to a EULA via an off-screen link.

        •Makes confusing changes to users' browsers -- increasing Ask's revenues while taking users to pages they didn't intend to visit.

        See Here for more info.

        If you choose to follow my recommendation then please go to Start > Control Panel > Add/Remove Programs and remove the following programs if present.

        AskBarDis or anything related to Ask

        Then please find and delete this folder in bold (if present):
        C:\Program Files\AskBarDis. or anything related to Ask.
        *****************************************************
        Download ComboFix by sUBs from one of the below links.  Be sure to save it to the Desktop.

        link # 1
        Link # 2

        Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix.

        Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

        Right-click combofix.exe and select Run as Administrator and follow the prompts.
        When finished, ComboFix will produce a log for you.
        Post the ComboFix log and a new HijackThis log in your next reply.

        NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

        Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.
        Windows 8 and Windows 10 dual boot with two SSD's

        iamlost

          Topic Starter


          Starter

          • Experience: Beginner
          • OS: Unknown
          Re: help virus
          « Reply #5 on: January 10, 2011, 12:27:18 AM »
          sorry about the caps I had no ideal.... looks like this is going to take a while I can not find any ask things to delete , though it is on my tool bar  and i know it is there
          i cant seem to find avast to disable anything maybe i need to pick this up i will reply with what you ask if you have a lamens way to go about all this it would be great remember when i said i have no ideal what i am doing i ment it like no ideal!!!!!!!!!!!!!!!!!!!! yhank you for your patience and time i will do my best and let you know.   thanks again

          SuperDave

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Thanked: 1020
          • Certifications: List
          • Experience: Expert
          • OS: Windows 10
          Re: help virus
          « Reply #6 on: January 10, 2011, 01:27:06 PM »
          You should be able to find Avast in the bottom right-hand corner of your desktop. If it's not there, go to Start, All Programs and look for the Avast program. You should be able to run it from there. Once you have it running, you should be able to disable it. I'm sorry if it's confusing for you but this is as simple as I can make it. Perhaps a computer-savvy friend can help you.
          Windows 8 and Windows 10 dual boot with two SSD's