1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Resolved Uninstall Smart Update

Discussion in 'Windows XP' started by wmergen, 2010/03/13.

  1. 2010/03/13
    wmergen

    wmergen Inactive Thread Starter

    Joined:
    2003/07/11
    Messages:
    49
    Likes Received:
    0
    Each time I start my desktop lately, I get a window titled Smart Update; and it wants me to launch something called Project Update. I keep unchecking the checkbox and cancelling the dialogue box. I've been trying to find out what this Smart Update is, how might I have gotten it, do I need it, and why I can't find it in my Add/Remove Programs list, or anywhere else in my programs. Please explain what I have working here and what I should do about it!
     
  2. 2010/03/13
    Evan Omo

    Evan Omo Computer Support Technician Staff

    Joined:
    2006/09/10
    Messages:
    7,919
    Likes Received:
    511

  3. to hide this advert.

  4. 2010/03/13
    wildfire

    wildfire Getting Old

    Joined:
    2008/04/21
    Messages:
    4,649
    Likes Received:
    124
    Hard to say what it is at the moment,

    Could you please download Silent Runners to your desktop, execute it, skip the supplementary search by clicking OK then let it finish and post the contents of "Startup Programs ... txt" which should appear on your desktop.
     
  5. 2010/03/14
    wmergen

    wmergen Inactive Thread Starter

    Joined:
    2003/07/11
    Messages:
    49
    Likes Received:
    0
    Thanks Evan Omo...I've been to both those sites. "What is..." is trying to tell me how to configure it and about how it will alert me and so on. I don't have any Skyscrape products that I know about and I don't have any PDAs. "How to remove..." speaks to Control Panel, files, and icons on the tool tray and none of those are on my computer. There might be something in Startup on msconfig that relates, but I don't recognize anything. I appreciate your suggestions.

    Wildfire...I appreciate your willingness to look at the programs that Silent Runners will give us. I'll download Silent Runners and post the information that I get. Thanks very much.
     
  6. 2010/03/14
    scout321x Contributing Member

    scout321x Inactive

    Joined:
    2002/02/23
    Messages:
    237
    Likes Received:
    3
    Do you have Threatfire from PC Tools installed? "Smart Update" is it's term for it's updating process.
     
  7. 2010/03/14
    wmergen

    wmergen Inactive Thread Starter

    Joined:
    2003/07/11
    Messages:
    49
    Likes Received:
    0
    Wildfire: Here is the file you asked me to post:
    "Silent Runners.vbs ", revision 60, http://www.silentrunners.org/
    Operating System: Windows XP SP3
    Output limited to non-default values, except where indicated by "{++} "


    Startup items buried in registry:
    ---------------------------------

    HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
    "ctfmon.exe" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
    "swg" = "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ "Google Inc."]
    "MSMSGS" = " "C:\Program Files\Messenger\msmsgs.exe" /background" [MS]
    "RegistryMechanic" = "C:\Program Files\Registry Mechanic\RegMech.exe /H" [ "PC Tools"]
    "RecordNow!" = "(empty string)" [file not found]

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
    "ehTray" = "C:\WINDOWS\ehome\ehtray.exe" [MS]
    "ATIPTA" = " "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" " [ "ATI Technologies, Inc."]
    "DVDLauncher" = " "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" " [ "CyberLink Corp."]
    "DMXLauncher" = "C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [null data]
    "CTSysVol" = "C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r" [ "Creative Technology Ltd"]
    "CTDVDDET" = " "C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE" " [ "Creative Technology Ltd"]
    "CTHelper" = "CTHELPER.EXE" [ "Creative Technology Ltd"]
    "UpdReg" = "C:\WINDOWS\UpdReg.EXE" [ "Creative Technology Ltd."]
    "Adobe Photo Downloader" = " "C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe" " [ "Adobe Systems Incorporated"]
    "SetIcon" = "\Program Files\WDC\SetIcon.exe" [ "Standard Microsystems Corp."]
    "LifeCam" = " "C:\Program Files\Microsoft LifeCam\LifeExp.exe" " [MS]
    "VX3000" = "C:\WINDOWS\vVX3000.exe" [MS]
    "Kernel and Hardware Abstraction Layer" = "KHALMNPR.EXE" [ "Logitech, Inc."]
    "AVP" = " "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" " [ "Kaspersky Lab"]
    "KernelFaultCheck" = "C:\WINDOWS\system32\dumprep 0 -k "
    "UpdateManager" = " "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r" [ "Sonic Solutions"]
    "HP Software Update" = " "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" " [null data]
    "DVDTray" = " "C:\Program Files\HP DVD\Umbrella\DVDTray.exe" " [ "Hewlett-Packard Company"]
    "DVDBitSet" = " "C:\Program Files\HP DVD\Umbrella\DVDBitSet.exe" /NOUI" [ "Hewlett-Packard Company"]
    "SunJavaUpdateSched" = " "C:\Program Files\Common Files\Java\Java Update\jusched.exe" " [ "Sun Microsystems, Inc."]
    "Adobe Reader Speed Launcher" = " "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" " [ "Adobe Systems Incorporated"]
    "Adobe ARM" = " "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" " [ "Adobe Systems Incorporated"]

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\

    {18DF081C-E8AD-4283-A596-FA578C2EBDC3}\(Default) = "AcroIEHelperStub "
    -> {HKLM...CLSID} = "Adobe PDF Link Helper "
    \InProcServer32\(Default) = "C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll" [ "Adobe Systems Incorporated"]

    {22BF413B-C6D2-4d91-82A9-A0F997BA588C}\(Default) = "Skype add-on (mastermind) "
    -> {HKLM...CLSID} = "Skype add-on (mastermind) "
    \InProcServer32\(Default) = "C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll" [ "Skype Technologies S.A."]

    {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}\(Default) = "IEVkbdBHO "
    -> {HKLM...CLSID} = "IEVkbdBHO Class "
    \InProcServer32\(Default) = "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll" [ "Kaspersky Lab"]

    {9030D464-4C02-4ABF-8ECC-5164760863C6}\(Default) = (no title provided)
    -> {HKLM...CLSID} = "Windows Live Sign-in Helper "
    \InProcServer32\(Default) = "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll" [MS]

    {AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\(Default) = (no title provided)
    -> {HKLM...CLSID} = "Google Toolbar Notifier BHO "
    \InProcServer32\(Default) = "C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll" [ "Google Inc."]

    {DBC80044-A445-435b-BC74-9C25C1C588A9}\(Default) = (no title provided)
    -> {HKLM...CLSID} = "Java(tm) Plug-In 2 SSV Helper "
    \InProcServer32\(Default) = "C:\Program Files\Java\jre6\bin\jp2ssv.dll" [ "Sun Microsystems, Inc."]

    {E33CF602-D945-461A-83F0-819F76A199F8}\(Default) = "link filter bho "
    -> {HKLM...CLSID} = "FilterBHO Class "
    \InProcServer32\(Default) = "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll" [ "Kaspersky Lab"]

    {E7E6F031-17CE-4C07-BC86-EABFE594F69C}\(Default) = "JQSIEStartDetectorImpl "
    -> {HKLM...CLSID} = "JQSIEStartDetectorImpl Class "
    \InProcServer32\(Default) = "C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll" [ "Sun Microsystems, Inc."]

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\

    "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension "
    -> {HKLM...CLSID} = "Display Panning CPL Extension "
    \InProcServer32\(Default) = "deskpan.dll" [file not found]

    "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext "
    -> {HKLM...CLSID} = "HyperTerminal Icon Ext "
    \InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" [ "Hilgraeve, Inc."]

    "{EFA24E62-B078-11d0-89E4-00C04FC9E26E}" = "History Band "
    -> {HKLM...CLSID} = "History Band "
    \InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

    "{E0D79304-84BE-11CE-9641-444553540000}" = "WinZip "
    -> {HKLM...CLSID} = "WinZip "
    \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" [ "WinZip Computing, Inc."]

    "{E0D79305-84BE-11CE-9641-444553540000}" = "WinZip "
    -> {HKLM...CLSID} = "WinZip "
    \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" [ "WinZip Computing, Inc."]

    "{E0D79306-84BE-11CE-9641-444553540000}" = "WinZip "
    -> {HKLM...CLSID} = "WinZip "
    \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" [ "WinZip Computing, Inc."]

    "{E0D79307-84BE-11CE-9641-444553540000}" = "WinZip "
    -> {HKLM...CLSID} = "WinZip "
    \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" [ "WinZip Computing, Inc."]

    "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Custom Icon Handler "
    -> {HKLM...CLSID} = "Outlook File Icon Extension "
    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\OLKFSTUB.DLL" [MS]

    "{00020D75-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Desktop Icon Handler "
    -> {HKLM...CLSID} = "Microsoft Office Outlook "
    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\MLSHEXT.DLL" [MS]

    "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler "
    -> {HKLM...CLSID} = (no title provided)
    \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\msohevi.dll" [MS]

    "{993BE281-6695-4BA5-8A2A-7AACBFAAB69E}" = "Microsoft Office Metadata Handler "
    -> {HKLM...CLSID} = "Microsoft Office Metadata Handler "
    \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll" [MS]

    "{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97}" = "Microsoft Office Thumbnail Handler "
    -> {HKLM...CLSID} = "Microsoft Office Thumbnail Handler "
    \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll" [MS]

    "{DC70C4A5-2044-4c59-B806-DEFB9AE0DF7C}" = "Logitech Setpoint Extension "
    -> {HKLM...CLSID} = "KbLogiExt Class "
    \InProcServer32\(Default) = "C:\Program Files\Logitech\SetPoint\kbcplext.dll" [ "Logitech, Inc."]

    "{B9B9F083-2B04-452A-8691-83694AC1037B}" = "Logitech Setpoint Extension "
    -> {HKLM...CLSID} = "LogiExt Class "
    \InProcServer32\(Default) = "C:\Program Files\Logitech\SetPoint\mcplext.dll" [ "Logitech, Inc."]

    "{DEE12703-6333-4D4E-8F34-738C4DCC2E04}" = "RecordNow! SendToExt "
    -> {HKLM...CLSID} = "RecordNow! SendToExt "
    \InProcServer32\(Default) = "C:\Program Files\Sonic_RecordNow\shlext.dll" [ "Sonic Solutions"]

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\

    "WPDShServiceObj" = "{AAA288BA-9A4C-45B0-95D7-94D524869DB5} "
    -> {HKLM...CLSID} = "WPDShServiceObj Class "
    \InProcServer32\(Default) = "C:\WINDOWS\system32\WPDShServiceObj.dll" [MS]

    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\
    <<!>> "AppInit_DLLs" = "C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll" [file not found]

    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
    <<!>> klogon\DLLName = "C:\WINDOWS\system32\klogon.dll" [ "Kaspersky Lab"]
    <<!>> LBTWlgn\DLLName = "c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll" [ "Logitech, Inc."]

    HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\

    <<!>> text/xml\CLSID = "{807563E5-5146-11D5-A672-00B0D022E945} "
    -> {HKLM...CLSID} = "Microsoft Office InfoPath XML Mime Filter "
    \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL" [MS]

    HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\

    <<!>> ms-help\CLSID = "{314111c7-a502-11d2-bbca-00c04f8ec294} "
    -> {HKLM...CLSID} = "HxProtocol Class "
    \InProcServer32\(Default) = "C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll" [MS]

    HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\

    Kaspersky Anti-Virus\(Default) = "{dd230880-495a-11d1-b064-008048ec2fc5} "
    -> {HKLM...CLSID} = (no title provided)
    \InProcServer32\(Default) = "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\shellex.dll" [ "Kaspersky Lab"]

    WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000} "
    -> {HKLM...CLSID} = "WinZip "
    \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" [ "WinZip Computing, Inc."]

    HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\

    WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000} "
    -> {HKLM...CLSID} = "WinZip "
    \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" [ "WinZip Computing, Inc."]

    HKLM\SOFTWARE\Classes\Directory\shellex\CopyHookHandlers\

    PIDirectoryHook\(Default) = "{E8244BEF-0200-4A1A-BE4E-35A4A9F51C3F} "
    -> {HKLM...CLSID} = "PI5 Ŀ¼¹³ "
    \InProcServer32\(Default) = "C:\Program Files\ArcSoft\PhotoImpression 5\share\pihook.dll" [null data]

    HKLM\SOFTWARE\Classes\Directory\shellex\DragDropHandlers\

    WinZip\(Default) = "{E0D79305-84BE-11CE-9641-444553540000} "
    -> {HKLM...CLSID} = "WinZip "
    \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" [ "WinZip Computing, Inc."]

    HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\

    {F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info "
    -> {HKLM...CLSID} = "PDF Shell Extension "
    \InProcServer32\(Default) = "C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll" [ "Adobe Systems, Inc."]

    HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\

    Kaspersky Anti-Virus\(Default) = "{dd230880-495a-11d1-b064-008048ec2fc5} "
    -> {HKLM...CLSID} = (no title provided)
    \InProcServer32\(Default) = "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\shellex.dll" [ "Kaspersky Lab"]

    WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000} "
    -> {HKLM...CLSID} = "WinZip "
    \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" [ "WinZip Computing, Inc."]

    HKLM\SOFTWARE\Classes\Folder\shellex\DragDropHandlers\

    WinZip\(Default) = "{E0D79305-84BE-11CE-9641-444553540000} "
    -> {HKLM...CLSID} = "WinZip "
    \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" [ "WinZip Computing, Inc."]


    Group Policies {GPedit.msc branch and setting}:
    -----------------------------------------------

    Note: detected settings may not have any effect.

    HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\

    "NoChangingWallpaper" = (REG_DWORD) dword:0x00000000
    {User Configuration|Administrative Templates|Control Panel|Display|
    Prevent changing wallpaper}

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\

    "InstallVisualStyle" = (REG_EXPAND_SZ) C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
    {unrecognized setting}

    "InstallTheme" = (REG_EXPAND_SZ) C:\WINDOWS\Resources\Themes\Royale.theme
    {unrecognized setting}


    Active Desktop and Wallpaper:
    -----------------------------

    Active Desktop may be disabled at this entry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

    Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
    HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
    "Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Wallpaper1.bmp "

    Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
    HKCU\Control Panel\Desktop\
    "Wallpaper" = "C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp "


    Enabled Screen Saver:
    ---------------------

    HKCU\Control Panel\Desktop\
    "SCRNSAVE.EXE" = "C:\WINDOWS\system32\logon.scr" [MS]


    Windows Portable Device AutoPlay Handlers
    -----------------------------------------

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\

    AdobePhotoshopElements4ShowPicturesOnArrival\
    "Provider" = "Adobe Photoshop Elements "
    "InvokeProgID" = "PhotoshopElements.Application.4 "
    "InvokeVerb" = "launch "
    HKLM\SOFTWARE\Classes\PhotoshopElements.Application.4\shell\launch\command\(Default) = " "C:\Program Files\Adobe\Photoshop Elements 4.0\PseProxy.exe" -v "%1" " [ "Adobe Systems Incorporated"]

    AdobePremiereElementsCameraArrival\
    "Provider" = "Adobe Premiere Elements "
    "ProgID" = "Shell.HWEventHandlerShellExecute "
    "InitCmdLine" = " "C:\Program Files\Adobe\Adobe Premiere Elements 2.0\Adobe Premiere Elements.exe" "
    HKLM\SOFTWARE\Classes\Shell.HWEventHandlerShellExecute\CLSID\(Default) = "{FFB8655F-81B9-4fce-B89C-9A6BA76D13E7} "
    -> {HKLM...CLSID} = "ShellExecute HW Event Handler "
    \LocalServer32\(Default) = "rundll32.exe shell32.dll,SHCreateLocalServerRunDll {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}" [MS]

    ArcSoftVideoCameraArrival\
    "Provider" = "ArcSoft ShowBiz "
    "ProgID" = "Shell.HWEventHandlerShellExecute "
    "InitCmdLine" = "C:\PROGRA~1\ArcSoft\SHOWBI~1\showbiz.exe /capture "
    HKLM\SOFTWARE\Classes\Shell.HWEventHandlerShellExecute\CLSID\(Default) = "{FFB8655F-81B9-4fce-B89C-9A6BA76D13E7} "
    -> {HKLM...CLSID} = "ShellExecute HW Event Handler "
    \LocalServer32\(Default) = "rundll32.exe shell32.dll,SHCreateLocalServerRunDll {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}" [MS]

    DMXPlayCD\
    "Provider" = "Dell Media Experience "
    "InvokeProgID" = "DMX.PLAYCD "
    "InvokeVerb" = "Play "
    HKLM\SOFTWARE\Classes\DMX.PLAYCD\shell\Play\Command\(Default) = "C:\Program Files\Dell\Media Experience\DMX.exe Music "Play %1" " [null data]

    EHomeMusicDropTarget\
    "Provider" = "Media Center "
    "InvokeProgID" = "EHomeDropTarget.EHomeMusicDropTarget "
    "InvokeVerb" = "play "
    HKLM\SOFTWARE\Classes\EHomeDropTarget.EHomeMusicDropTarget\shell\play\DropTarget\CLSID = "{ED87EFF3-FF22-404E-B2BD-BC3841BDCB2C} "
    -> {HKLM...CLSID} = "EHomeMusicDropTarget Class "
    \InProcServer32\(Default) = "C:\WINDOWS\eHome\ehdrop.dll" [MS]

    EHomePhotosHandler\
    "Provider" = "Media Center "
    "InvokeProgID" = "EHomeDropTarget.EHomePhotosHandler "
    "InvokeVerb" = "play "
    HKLM\SOFTWARE\Classes\EHomeDropTarget.EHomePhotosHandler\shell\play\DropTarget\CLSID = "{4b7601c1-d292-4902-89f4-583a5ce0c535} "
    -> {HKLM...CLSID} = "EHomePhotosHandler Class "
    \InProcServer32\(Default) = "C:\WINDOWS\eHome\ehdrop.dll" [MS]

    EHomeVideoDropTarget\
    "Provider" = "Media Center "
    "InvokeProgID" = "EHomeDropTarget.EHomeVideoDropTarget "
    "InvokeVerb" = "play "
    HKLM\SOFTWARE\Classes\EHomeDropTarget.EHomeVideoDropTarget\shell\play\DropTarget\CLSID = "{A48E70A4-8E15-4465-9D85-CCE9E63F8AAB} "
    -> {HKLM...CLSID} = "EHomeVideoDropTarget Class "
    \InProcServer32\(Default) = "C:\WINDOWS\eHome\ehdrop.dll" [MS]

    EHomeVideosHandler\
    "Provider" = "Media Center "
    "InvokeProgID" = "EHomeDropTarget.EHomeVideosHandler "
    "InvokeVerb" = "play "
    HKLM\SOFTWARE\Classes\EHomeDropTarget.EHomeVideosHandler\shell\play\DropTarget\CLSID = "{4f61ec50-acef-4ae7-b4c6-b19bddc0f745} "
    -> {HKLM...CLSID} = "EHomeVideosHandler Class "
    \InProcServer32\(Default) = "C:\WINDOWS\eHome\ehdrop.dll" [MS]

    MSWPDShellNamespaceHandler\
    "Provider" = "@%SystemRoot%\System32\WPDShextRes.dll,-501 "
    "CLSID" = "{A55803CC-4D53-404c-8557-FD63DBA95D24} "
    "InitCmdLine" = " "
    -> {HKLM...CLSID} = "WPDShextAutoplay "
    \LocalServer32\(Default) = "C:\WINDOWS\system32\WPDShextAutoplay.exe" [MS]

    PDVDPlayDVDMovieOnArrival\
    "Provider" = "PowerDVD "
    "InvokeProgID" = "DVD "
    "InvokeVerb" = "PlayWithPowerDVD "
    HKLM\SOFTWARE\Classes\DVD\shell\PlayWithPowerDVD\Command\(Default) = " "C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe" MOVIE "%L" " [ "CyberLink Corp."]

    SonicRnCdOnArrival\
    "Provider" = "RecordNow! "
    "InvokeProgID" = "Sonic.RecordNow "
    "InvokeVerb" = "open "
    HKLM\SOFTWARE\Classes\Sonic.RecordNow\shell\open\Command\(Default) = "C:\Program Files\Sonic_RecordNow\RecordNow.exe" [null data]

    SonicVideoCameraArrival\
    "Provider" = "Sonic Solutions "
    "ProgID" = "MyDVD.MyDVDAPHandler "
    "InitCmdLine" = "new "
    HKLM\SOFTWARE\Classes\MyDVD.MyDVDAPHandler\CLSID\(Default) = "{3D5EF619-F606-4FAA-97C0-222B7DCA05EC} "
    -> {HKLM...CLSID} = "MyDVDAPHandler Class "
    \LocalServer32\(Default) = " "C:\Program Files\Roxio\Creator MyDVD LE Dell Edition\MyDVD LE\MyDVD.EXE" -autoplay" [ "Sonic Solutions"]

    SonicVideoCameraArrivalDirect\
    "Provider" = "Sonic Solutions "
    "ProgID" = "MyDVD.MyDVDAPHandler "
    "InitCmdLine" = "direct "
    HKLM\SOFTWARE\Classes\MyDVD.MyDVDAPHandler\CLSID\(Default) = "{3D5EF619-F606-4FAA-97C0-222B7DCA05EC} "
    -> {HKLM...CLSID} = "MyDVDAPHandler Class "
    \LocalServer32\(Default) = " "C:\Program Files\Roxio\Creator MyDVD LE Dell Edition\MyDVD LE\MyDVD.EXE" -autoplay" [ "Sonic Solutions"]


    Startup items in "Owner" & "All Users" startup folders:
    -------------------------------------------------------

    C:\Documents and Settings\Owner\Templates\Programs\Startup
    "Adobe Gamma" -> shortcut to: "C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe" [ "Adobe Systems, Inc."]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup
    "Logitech SetPoint" -> shortcut to: "C:\Program Files\Logitech\SetPoint\SetPoint.exe" [ "Logitech, Inc."]
    "Picture Package Menu" -> shortcut to: "C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe" [ "Sony Corporation"]
    "WinZip Quick Pick" -> shortcut to: "C:\Program Files\WinZip\WZQKPICK.EXE" [ "WinZip Computing, Inc."]
    "Wireless Network Monitor" -> shortcut to: "C:\Program Files\Linksys\WUSB100\WUSB100.exe" [ "Linksys"]


    Enabled Scheduled Tasks:
    ------------------------

    "Google Software Updater" -> launches: "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe scheduled_start" [ "Google"]
    "GoogleUpdateTaskMachineCore" -> launches: "C:\Program Files\Google\Update\GoogleUpdate.exe /c" [ "Google Inc."]
    "GoogleUpdateTaskMachineUA" -> launches: "C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler" [ "Google Inc."]
    "User_Feed_Synchronization-{C9D5B66E-A1C2-4B76-A855-41F8195F58D1}" -> launches: "C:\WINDOWS\system32\msfeedssync.exe sync" [MS]


    Winsock2 Service Provider DLLs:
    -------------------------------

    Namespace Service Providers

    HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
    000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
    000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
    000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

    Transport Service Providers

    HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
    0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
    %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 17
    %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


    Toolbars, Explorer Bars, Extensions:
    ------------------------------------

    Toolbars

    HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\

    "{F2CF5485-4E02-4F68-819C-B92DE9277049} "
    -> {HKLM...CLSID} = "&Links "
    \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

    HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\
    "{35CE0AE2-3411-4BB8-A16A-BEE30B282A26}" = (no title provided)
    -> {HKLM...CLSID} = "TurboTax ItsDeductible "
    \InProcServer32\(Default) = "C:\Program Files\Intuit\IDO\IDOToolbar.dll" [null data]

    Explorer Bars

    HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\

    HKLM\SOFTWARE\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = "&Research "
    Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
    InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL" [MS]

    Extensions (Tools menu items, main toolbar menu buttons)

    HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\
    {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E}\
    "ButtonText" = "Web Anti-Virus statistics "

    {4248FE82-7FCB-46AC-B270-339F08212110}\
    "ButtonText" = "&Virtual keyboard "
    "CLSIDExtension" = "{4248FE82-7FCB-46AC-B270-339F08212110} "
    -> {HKLM...CLSID} = "VirtualKeyboardButtonHandler Class "
    \InProcServer32\(Default) = "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll" [ "Kaspersky Lab"]

    {77BF5300-1474-4EC7-9980-D32B190E9B07}\
    "ButtonText" = "Skype "
    "CLSIDExtension" = "{77BF5300-1474-4EC7-9980-D32B190E9B07} "
    -> {HKLM...CLSID} = "Skype add-on (button) "
    \InProcServer32\(Default) = "C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll" [ "Skype Technologies S.A."]

    {92780B25-18CC-41C8-B9BE-3C9C571A8263}\
    "ButtonText" = "Research "

    {A26ABCF0-1C8F-46E7-A67C-0489DC21B9CC}\
    "ButtonText" = "TurboTax ItsDeductible "
    "MenuText" = "TurboTax ItsDeductible "

    {CCF151D8-D089-449F-A5A4-D9909053F20F}\
    "ButtonText" = "URLs c&heck "
    "CLSIDExtension" = "{CCF151D8-D089-449F-A5A4-D9909053F20F} "
    -> {HKLM...CLSID} = "FilterButtonHandler Class "
    \InProcServer32\(Default) = "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll" [ "Kaspersky Lab"]

    {E2E2DD38-D088-4134-82B7-F2BA38496583}\
    "MenuText" = "@xpsp3res.dll,-20001 "
    "Exec" = "%windir%\Network Diagnostic\xpnetdiag.exe" [MS]

    {FB5F1910-F110-11D2-BB9E-00C04F795683}\
    "ButtonText" = "Messenger "
    "MenuText" = "Windows Messenger "
    "Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]


    Running Services (Display Name, Service Name, Path {Service DLL}):
    ------------------------------------------------------------------

    Adobe Active File Monitor V4, AdobeActiveFileMonitor4.0, "C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe" [null data]
    Ati HotKey Poller, Ati HotKey Poller, "C:\WINDOWS\system32\Ati2evxx.exe" [ "ATI Technologies Inc."]
    Creative Service for CDROM Access, Creative Service for CDROM Access, "C:\WINDOWS\system32\CTsvcCDA.EXE" [ "Creative Technology Ltd"]
    Intuit Update Service, IntuitUpdateService, " "C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" " [null data]
    Java Quick Starter, JavaQuickStarterService, " "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf" " [ "Sun Microsystems, Inc."]
    Kaspersky Internet Security, AVP, "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe -r" [ "Kaspersky Lab"]
    McciCMService, McciCMService, " "C:\Program Files\Common Files\Motive\McciCMService.exe" " [ "Motive Communications, Inc."]
    Media Center Extender Service, McrdSvc, "C:\WINDOWS\ehome\mcrdsvc.exe" [MS]
    Media Center Receiver Service, ehRecvr, "C:\WINDOWS\eHome\ehRecvr.exe" [MS]
    Media Center Scheduler Service, ehSched, "C:\WINDOWS\eHome\ehSched.exe" [MS]
    MSCamSvc, MSCamSvc, " "C:\Program Files\Microsoft LifeCam\MSCamS32.exe" " [MS]
    PC Tools Startup and Shutdown Monitor service, PCToolsSSDMonitorSvc, "C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe" [ "PC Tools"]


    Print Monitors:
    ---------------

    HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\
    Canon BJ Language Monitor PIXMA iP4000\Driver = "CNMLM64.DLL" [ "CANON INC."]


    ---------- (launch time: 2010-03-14 11:52:27)
    <<!>>: Suspicious data at a malware launch point.

    + This report excludes default entries except where indicated.
    + To see *everywhere* the script checks and *everything* it finds,
    launch it from a command prompt or a shortcut with the -all parameter.
    + To search all directories of local fixed drives for DESKTOP.INI
    DLL launch points, use the -supp parameter or answer "No" at the
    first message box and "Yes" at the second message box.
    ---------- (total run time: 63 seconds, including 8 seconds for message boxes)
     
  8. 2010/03/14
    wildfire

    wildfire Getting Old

    Joined:
    2008/04/21
    Messages:
    4,649
    Likes Received:
    124
    Thanks wmergen,

    See scout321x's answer.

    Personally I wouldn't be happy with anyone using a registry cleaner on their system unless they were 100% clear about what they are doing.

    Uninstall Registry Mechanic and let us know how things go.
     
  9. 2010/03/16
    wmergen

    wmergen Inactive Thread Starter

    Joined:
    2003/07/11
    Messages:
    49
    Likes Received:
    0
    Wildfire...I think removing the Registry Mechanic program did it. I haven't seen any recurrence of the Smart Update window in two days and three reboots of the computer. Thanks for all the help and the effective advice.
     
  10. 2010/03/17
    wildfire

    wildfire Getting Old

    Joined:
    2008/04/21
    Messages:
    4,649
    Likes Received:
    124
    Good to know, sorry for the late reply but I've been Ill :( Feeling better now though :)

    If you're happy then please mark this thread as resolved.

     
  11. 2010/03/17
    Evan Omo

    Evan Omo Computer Support Technician Staff

    Joined:
    2006/09/10
    Messages:
    7,919
    Likes Received:
    511
    Thats great that you were able to resolve your problem. :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.