good almost done...thanks again...ive been over at my mothers house for the past few days trying to fix her pc. my own pc is fine...mainly because I know what to open and what not to open...and I have anti-spyware running...but i swear i cant get it through my mothers head that everything on the internet is NOT safe...shes from the old school "trust everything" way of thinking...but anywho thanks again
p.s. yes i have beat her with a large trout...and she still hasnt listened
drew
Logfile of HijackThis v1.99.1
Scan saved at 1:27:48 PM, on 06/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\hpdll\tempdl\RAS012505.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\LTMSG.exe
C:\WINDOWS\system32\lhfkcps\rbaluma.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Mary\Desktop\Drews Pics\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://webmail.central.cox.net/R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://webmail.central.cox.net/O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [zKw] C:\documents and settings\mary\local settings\temp\zKw.exe
O4 - HKLM\..\Run: [Zbraa] C:\WINDOWS\uxfna.exe
O4 - HKLM\..\Run: [yjenvowauutxastptrul] C:\WINDOWS\grvyqbvx.exe
O4 - HKLM\..\Run: [xhxhmc] C:\WINDOWS\system32\xhxhmc.exe
O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\system32\winupdt.exe
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\system32\wintask.exe
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O4 - HKLM\..\Run: [WeirdOnTheWeb] "C:\Program Files\WeirdOnTheWeb\WeirdOnTheWeb.exe"
O4 - HKLM\..\Run: [wdskctl] C:\WINDOWS\wdskctl.exe
O4 - HKLM\..\Run: [Wast] C:\WINDOWS\wast2.exe 2
O4 - HKLM\..\Run: [vmss] C:\WINDOWS\system32\vmss\vmss.exe
O4 - HKLM\..\Run: [Visual Element Fx] C:\Program Files\hpdll\tempdl\RAS012505.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [version] C:\WINDOWS\system32\Oumodt.exe
O4 - HKLM\..\Run: [VBundleOuterDL] C:\Program Files\VBouncer\BundleOuter.EXE
O4 - HKLM\..\Run: [TinkoPal] C:\Program Files\TinkoPal\AppStart.exe
O4 - HKLM\..\Run: [TB_setup] C:\DOCUME~1\Mary\LOCALS~1\Temp\tb_setup.exe /dcheck
O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe
O4 - HKLM\..\Run: [tapisys] C:\WINDOWS\System32\tss.exe
O4 - HKLM\..\Run: [SystemCheck] C:\WINDOWS\SysCheckBop32
O4 - HKLM\..\Run: [SurfSideKick 2] C:\Program Files\SurfSideKick 2\Ssk.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [SpySpotter] C:\PROGRA~1\SPYSPO~1\SpySpotter.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
O4 - HKLM\..\Run: [seeve] C:\WINDOWS\seeve.exe
O4 - HKLM\..\Run: [salm] c:\windows\salm.exe
O4 - HKLM\..\Run: [sac] c:\program files\180searchassistant\sac.exe
O4 - HKLM\..\Run: [rylyvct] c:\windows\system32\rylyvct.exe
O4 - HKLM\..\Run: [rydgfek] C:\WINDOWS\System32\rylyvct.exe
O4 - HKLM\..\Run: [Rxagik] C:\WINDOWS\Meruoq.exe
O4 - HKLM\..\Run: [RSync] C:\WINDOWS\system32\netsync.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [pgtaff] C:\WINDOWS\pgtaff.exe
O4 - HKLM\..\Run: [otfulsbgxo] C:\WINDOWS\system32\rylyvct.exe
O4 - HKLM\..\Run: [odochws] C:\WINDOWS\system32\odochws.exe
O4 - HKLM\..\Run: [ntechin] C:\WINDOWS\system32\n20050308.exe
O4 - HKLM\..\Run: [nsj] C:\WINDOWS\nsj.exe
O4 - HKLM\..\Run: [ngftnc] C:\WINDOWS\system32\ngftnc.exe
O4 - HKLM\..\Run: [Narrator] C:\WINDOWS\system32\vgikgk.exe
O4 - HKLM\..\Run: [mR] C:\windows\temp\mR.exe
O4 - HKLM\..\Run: [MPFTray] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [Makarzy] C:\WINDOWS\nyei.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [lloirc] C:\WINDOWS\system32\lloirc.exe
O4 - HKLM\..\Run: [kqltrufn] C:\WINDOWS\system32\kgrsu\kqltrufn.exe
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\ikpnkn.exe
O4 - HKLM\..\Run: [kalvsys] C:\windows\system32\kalvwvx32.exe
O4 - HKLM\..\Run: [JG0oc3iEv] C:\documents and settings\mary\local settings\temp\JG0oc3iEv.exe
O4 - HKLM\..\Run: [JDhG] C:\documents and settings\mary\local settings\temp\JDhG.exe
O4 - HKLM\..\Run: [JD] C:\documents and settings\mary\local settings\temp\JD.exe
O4 - HKLM\..\Run: [javauu.exe] C:\WINDOWS\system32\javauu.exe
O4 - HKLM\..\Run: [j599pd3s] C:\Program Files\j599pd3s\j599pd3s.exe
O4 - HKLM\..\Run: [ivex] C:\WINDOWS\ivex.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [HUGA] C:\documents and settings\mary\local settings\temp\HUGA.exe
O4 - HKLM\..\Run: [HPNT] C:\Program Files\hpdll\hpdll.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [fwvcj] C:\WINDOWS\fwvcj.exe
O4 - HKLM\..\Run: [farmmext] C:\WINDOWS\farmmext.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\system32\exp.exe
O4 - HKLM\..\Run: [ErrorGuard] C:\Program Files\ErrorGuard\ErrorGuard.Exe
O4 - HKLM\..\Run: [EbatesMoeMoneyMaker0] "C:\Program Files\Ebates_MoeMoneyMaker\EbatesMoeMoneyMaker0.exe"
O4 - HKLM\..\Run: [Dvx] C:\WINDOWS\system32\wsxsvc\wsxsvc.exe
O4 - HKLM\..\Run: [DownloadWare] "C:\Program Files\DownloadWare\dw.exe" /H
O4 - HKLM\..\Run: [CSV7P70] C:\Program Files\CSBB\CSV7P070.exe
O4 - HKLM\..\Run: [CSV10P70] C:\Program Files\CSBB\CSv10P070.exe
O4 - HKLM\..\Run: [CashBack] C:\Program Files\CashBack\bin\cashback.exe
O4 - HKLM\..\Run: [BullsEye Network] C:\Program Files\BullsEye Network\bin\bargains.exe
O4 - HKLM\..\Run: [Breg] "C:\Program Files\Common Files\Java\bptre.exe"
O4 - HKLM\..\Run: [BPT] "C:\Program Files\Bpt\bpt.exe"
O4 - HKLM\..\Run: [App32dll] C:\windows\system32\msnavc32.exe lee0105
O4 - HKLM\..\Run: [antiware] C:\windows\system32\elitevbx32.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [AdRoarUpdate] C:\WINDOWS\ARUpdate.exe
O4 - HKLM\..\Run: [Admanager Controller] C:\Program Files\Admanager Controller\AdManCtl.exe
O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
O4 - HKLM\..\Run: [474S34l] hnewvdrv.exe
O4 - HKLM\..\Run: [39w] c:\windows\system32\39w.exe
O4 - HKLM\..\Run: [180ax] c:\windows\180ax.exe
O4 - HKLM\..\Run: [rbaluma] C:\WINDOWS\system32\lhfkcps\rbaluma.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Tsa] C:\PROGRA~1\COMMON~1\tsa\tsm.exe
O4 - HKCU\..\Run: [sysmonnt] C:\WINDOWS\system32\sysmonnt
O4 - HKCU\..\Run: [SpyWareWall] C:\PROGRA~1\SPYWAR~2\SpyWareWall.exe
O4 - HKCU\..\Run: [prutqct] C:\WINDOWS\system32\prutqct.exe
O4 - HKCU\..\Run: [Prgg] C:\WINDOWS\system32\??oolsv.exe
O4 - HKCU\..\Run: [Okqmv] C:\WINDOWS\System32\r?ndll32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /startmonitor
O4 - HKCU\..\Run: [Lwv2RQJqW] fwcprovi.exe
O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe
O4 - HKCU\..\Run: [eZmmod] C:\PROGRA~1\ezula\mmod.exe
O4 - HKCU\..\Run: [Eeor] C:\Documents and Settings\Mary\Application Data\suos.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Startup: popupwall.lnk = C:\Program Files\PopUpWall\PopUpWall.exe
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Wireless Configuration Utility.lnk = C:\Program Files\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.21 V1.10\WlanCU.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....738&clcid=0x409O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cabO16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) -
http://67.89.107.171...sCamControl.ocxO18 - Filter: text/html - (no CLSID) - (no file)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
L2Mfix 1.03
Running From:
C:\Documents and Settings\Mary\Desktop\l2mfix
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (
http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER
Setting registry permissions:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (
http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Denying C(CI) access for predefined group "Administrators"
- adding new ACCESS DENY entry
Registry Permissions set too:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (
http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(CI) DENY --C------- BUILTIN\Administrators
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER
Setting up for Reboot
Starting Reboot!
C:\Documents and Settings\Mary\Desktop\l2mfix
System Rebooted!
Running From:
C:\Documents and Settings\Mary\Desktop\l2mfix
killing explorer and rundll32.exe
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003
[email protected]Killing PID 964 'explorer.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003
[email protected]Killing PID 1384 'rundll32.exe'
Scanning First Pass. Please Wait!
First Pass Completed
Second Pass Scanning
Second pass Completed!
Backing Up: C:\WINDOWS\system32\aza02g3mg6.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\aza0lclm1fqa.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\aza2l55o1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\azam01j1e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\azao0133e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\azaolc331f.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\c6002gdmg60a2.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\cnrsrv.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\d8j00i1me8.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dbauth.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dn6m01j1e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dnlo0133e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dnp2017oe.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dnr6019se.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dnrm0191e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\en4ul1h91.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\enp2l17o1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\f00olad31d0.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\fn2021fmg.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\fp2203foe.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\fp8q03l5e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\fpj6031se.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\fplo0333e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\g2220cfoef2c0.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\g6jo0g13e6.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\GBCollection.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\gp8ql3l51.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\gppul3791.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\gpr6l39s1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\gprml3911.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\h0j40a1qed.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\h40q0ed5eh0.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\h8l20i3oe8.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\hrl0053me.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\hrlq0535e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\hrro0593e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\hrrq0595e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\i2lo0c33ef.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\i2lolc331f.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\i6600gjme6oa0.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\i8jq0i15e8.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ir24l5fq1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\irn2l55o1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\irp6l57s1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\irrql5951.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\jr0025dmg.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\jt4807hue.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\jt8407lqe.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\jtj0071me.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\k280lclm1fqa.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\k6pmlg7116.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\kodsp.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ktp6l77s1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\l0l6la3s1d.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\l22s0cf7ef2.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\l22slcf71f2.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\l46o0ej3eho.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\l4r0le9m1h.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\l6j8lg1u16.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\l80u0id9e80.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\l8n40i5qe8.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\lv0409dqe.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\m8po0i73e8.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mv8ul9l91.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mvp8l97u1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mvrql9951.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\n66qlgj516o.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\o0660ajsedo60.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\o066lajs1do6.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\o4nsle571h.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\p04u0ah9ed4.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\q268lcju1fo8.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\q468leju1ho8.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\SbyLt3Pr.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\t6r8lg9u16.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\t88u0il9e8q.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\uqrfaxa.dll
1 file(s) copied.
deleting: C:\WINDOWS\system32\aza02g3mg6.dll
Successfully Deleted: C:\WINDOWS\system32\aza02g3mg6.dll
deleting: C:\WINDOWS\system32\aza0lclm1fqa.dll
Successfully Deleted: C:\WINDOWS\system32\aza0lclm1fqa.dll
deleting: C:\WINDOWS\system32\aza2l55o1.dll
Successfully Deleted: C:\WINDOWS\system32\aza2l55o1.dll
deleting: C:\WINDOWS\system32\azam01j1e.dll
Successfully Deleted: C:\WINDOWS\system32\azam01j1e.dll
deleting: C:\WINDOWS\system32\azao0133e.dll
Successfully Deleted: C:\WINDOWS\system32\azao0133e.dll
deleting: C:\WINDOWS\system32\azaolc331f.dll
Successfully Deleted: C:\WINDOWS\system32\azaolc331f.dll
deleting: C:\WINDOWS\system32\c6002gdmg60a2.dll
Successfully Deleted: C:\WINDOWS\system32\c6002gdmg60a2.dll
deleting: C:\WINDOWS\system32\cnrsrv.dll
Successfully Deleted: C:\WINDOWS\system32\cnrsrv.dll
deleting: C:\WINDOWS\system32\d8j00i1me8.dll
Successfully Deleted: C:\WINDOWS\system32\d8j00i1me8.dll
deleting: C:\WINDOWS\system32\dbauth.dll
Successfully Deleted: C:\WINDOWS\system32\dbauth.dll
deleting: C:\WINDOWS\system32\dn6m01j1e.dll
Successfully Deleted: C:\WINDOWS\system32\dn6m01j1e.dll
deleting: C:\WINDOWS\system32\dnlo0133e.dll
Successfully Deleted: C:\WINDOWS\system32\dnlo0133e.dll
deleting: C:\WINDOWS\system32\dnp2017oe.dll
Successfully Deleted: C:\WINDOWS\system32\dnp2017oe.dll
deleting: C:\WINDOWS\system32\dnr6019se.dll
Successfully Deleted: C:\WINDOWS\system32\dnr6019se.dll
deleting: C:\WINDOWS\system32\dnrm0191e.dll
Successfully Deleted: C:\WINDOWS\system32\dnrm0191e.dll
deleting: C:\WINDOWS\system32\en4ul1h91.dll
Successfully Deleted: C:\WINDOWS\system32\en4ul1h91.dll
deleting: C:\WINDOWS\system32\enp2l17o1.dll
Successfully Deleted: C:\WINDOWS\system32\enp2l17o1.dll
deleting: C:\WINDOWS\system32\f00olad31d0.dll
Successfully Deleted: C:\WINDOWS\system32\f00olad31d0.dll
deleting: C:\WINDOWS\system32\fn2021fmg.dll
Successfully Deleted: C:\WINDOWS\system32\fn2021fmg.dll
deleting: C:\WINDOWS\system32\fp2203foe.dll
Successfully Deleted: C:\WINDOWS\system32\fp2203foe.dll
deleting: C:\WINDOWS\system32\fp8q03l5e.dll
Successfully Deleted: C:\WINDOWS\system32\fp8q03l5e.dll
deleting: C:\WINDOWS\system32\fpj6031se.dll
Successfully Deleted: C:\WINDOWS\system32\fpj6031se.dll
deleting: C:\WINDOWS\system32\fplo0333e.dll
Successfully Deleted: C:\WINDOWS\system32\fplo0333e.dll
deleting: C:\WINDOWS\system32\g2220cfoef2c0.dll
Successfully Deleted: C:\WINDOWS\system32\g2220cfoef2c0.dll
deleting: C:\WINDOWS\system32\g6jo0g13e6.dll
Successfully Deleted: C:\WINDOWS\system32\g6jo0g13e6.dll
deleting: C:\WINDOWS\system32\GBCollection.dll
Successfully Deleted: C:\WINDOWS\system32\GBCollection.dll
deleting: C:\WINDOWS\system32\gp8ql3l51.dll
Successfully Deleted: C:\WINDOWS\system32\gp8ql3l51.dll
deleting: C:\WINDOWS\system32\gppul3791.dll
Successfully Deleted: C:\WINDOWS\system32\gppul3791.dll
deleting: C:\WINDOWS\system32\gpr6l39s1.dll
Successfully Deleted: C:\WINDOWS\system32\gpr6l39s1.dll
deleting: C:\WINDOWS\system32\gprml3911.dll
Successfully Deleted: C:\WINDOWS\system32\gprml3911.dll
deleting: C:\WINDOWS\system32\h0j40a1qed.dll
Successfully Deleted: C:\WINDOWS\system32\h0j40a1qed.dll
deleting: C:\WINDOWS\system32\h40q0ed5eh0.dll
Successfully Deleted: C:\WINDOWS\system32\h40q0ed5eh0.dll
deleting: C:\WINDOWS\system32\h8l20i3oe8.dll
Successfully Deleted: C:\WINDOWS\system32\h8l20i3oe8.dll
deleting: C:\WINDOWS\system32\hrl0053me.dll
Successfully Deleted: C:\WINDOWS\system32\hrl0053me.dll
deleting: C:\WINDOWS\system32\hrlq0535e.dll
Successfully Deleted: C:\WINDOWS\system32\hrlq0535e.dll
deleting: C:\WINDOWS\system32\hrro0593e.dll
Successfully Deleted: C:\WINDOWS\system32\hrro0593e.dll
deleting: C:\WINDOWS\system32\hrrq0595e.dll
Successfully Deleted: C:\WINDOWS\system32\hrrq0595e.dll
deleting: C:\WINDOWS\system32\i2lo0c33ef.dll
Successfully Deleted: C:\WINDOWS\system32\i2lo0c33ef.dll
deleting: C:\WINDOWS\system32\i2lolc331f.dll
Successfully Deleted: C:\WINDOWS\system32\i2lolc331f.dll
deleting: C:\WINDOWS\system32\i6600gjme6oa0.dll
Successfully Deleted: C:\WINDOWS\system32\i6600gjme6oa0.dll
deleting: C:\WINDOWS\system32\i8jq0i15e8.dll
Successfully Deleted: C:\WINDOWS\system32\i8jq0i15e8.dll
deleting: C:\WINDOWS\system32\ir24l5fq1.dll
Successfully Deleted: C:\WINDOWS\system32\ir24l5fq1.dll
deleting: C:\WINDOWS\system32\irn2l55o1.dll
Successfully Deleted: C:\WINDOWS\system32\irn2l55o1.dll
deleting: C:\WINDOWS\system32\irp6l57s1.dll
Successfully Deleted: C:\WINDOWS\system32\irp6l57s1.dll
deleting: C:\WINDOWS\system32\irrql5951.dll
Successfully Deleted: C:\WINDOWS\system32\irrql5951.dll
deleting: C:\WINDOWS\system32\jr0025dmg.dll
Successfully Deleted: C:\WINDOWS\system32\jr0025dmg.dll
deleting: C:\WINDOWS\system32\jt4807hue.dll
Successfully Deleted: C:\WINDOWS\system32\jt4807hue.dll
deleting: C:\WINDOWS\system32\jt8407lqe.dll
Successfully Deleted: C:\WINDOWS\system32\jt8407lqe.dll
deleting: C:\WINDOWS\system32\jtj0071me.dll
Successfully Deleted: C:\WINDOWS\system32\jtj0071me.dll
deleting: C:\WINDOWS\system32\k280lclm1fqa.dll
Successfully Deleted: C:\WINDOWS\system32\k280lclm1fqa.dll
deleting: C:\WINDOWS\system32\k6pmlg7116.dll
Successfully Deleted: C:\WINDOWS\system32\k6pmlg7116.dll
deleting: C:\WINDOWS\system32\kodsp.dll
Successfully Deleted: C:\WINDOWS\system32\kodsp.dll
deleting: C:\WINDOWS\system32\ktp6l77s1.dll
Successfully Deleted: C:\WINDOWS\system32\ktp6l77s1.dll
deleting: C:\WINDOWS\system32\l0l6la3s1d.dll
Successfully Deleted: C:\WINDOWS\system32\l0l6la3s1d.dll
deleting: C:\WINDOWS\system32\l22s0cf7ef2.dll
Successfully Deleted: C:\WINDOWS\system32\l22s0cf7ef2.dll
deleting: C:\WINDOWS\system32\l22slcf71f2.dll
Successfully Deleted: C:\WINDOWS\system32\l22slcf71f2.dll
deleting: C:\WINDOWS\system32\l46o0ej3eho.dll
Successfully Deleted: C:\WINDOWS\system32\l46o0ej3eho.dll
deleting: C:\WINDOWS\system32\l4r0le9m1h.dll
Successfully Deleted: C:\WINDOWS\system32\l4r0le9m1h.dll
deleting: C:\WINDOWS\system32\l6j8lg1u16.dll
Successfully Deleted: C:\WINDOWS\system32\l6j8lg1u16.dll
deleting: C:\WINDOWS\system32\l80u0id9e80.dll
Successfully Deleted: C:\WINDOWS\system32\l80u0id9e80.dll
deleting: C:\WINDOWS\system32\l8n40i5qe8.dll
Successfully Deleted: C:\WINDOWS\system32\l8n40i5qe8.dll
deleting: C:\WINDOWS\system32\lv0409dqe.dll
Successfully Deleted: C:\WINDOWS\system32\lv0409dqe.dll
deleting: C:\WINDOWS\system32\m8po0i73e8.dll
Successfully Deleted: C:\WINDOWS\system32\m8po0i73e8.dll
deleting: C:\WINDOWS\system32\mv8ul9l91.dll
Successfully Deleted: C:\WINDOWS\system32\mv8ul9l91.dll
deleting: C:\WINDOWS\system32\mvp8l97u1.dll
Successfully Deleted: C:\WINDOWS\system32\mvp8l97u1.dll
deleting: C:\WINDOWS\system32\mvrql9951.dll
Successfully Deleted: C:\WINDOWS\system32\mvrql9951.dll
deleting: C:\WINDOWS\system32\n66qlgj516o.dll
Successfully Deleted: C:\WINDOWS\system32\n66qlgj516o.dll
deleting: C:\WINDOWS\system32\o0660ajsedo60.dll
Successfully Deleted: C:\WINDOWS\system32\o0660ajsedo60.dll
deleting: C:\WINDOWS\system32\o066lajs1do6.dll
Successfully Deleted: C:\WINDOWS\system32\o066lajs1do6.dll
deleting: C:\WINDOWS\system32\o4nsle571h.dll
Successfully Deleted: C:\WINDOWS\system32\o4nsle571h.dll
deleting: C:\WINDOWS\system32\p04u0ah9ed4.dll
Successfully Deleted: C:\WINDOWS\system32\p04u0ah9ed4.dll
deleting: C:\WINDOWS\system32\q268lcju1fo8.dll
Successfully Deleted: C:\WINDOWS\system32\q268lcju1fo8.dll
deleting: C:\WINDOWS\system32\q468leju1ho8.dll
Successfully Deleted: C:\WINDOWS\system32\q468leju1ho8.dll
deleting: C:\WINDOWS\system32\SbyLt3Pr.dll
Successfully Deleted: C:\WINDOWS\system32\SbyLt3Pr.dll
deleting: C:\WINDOWS\system32\t6r8lg9u16.dll
Successfully Deleted: C:\WINDOWS\system32\t6r8lg9u16.dll
deleting: C:\WINDOWS\system32\t88u0il9e8q.dll
Successfully Deleted: C:\WINDOWS\system32\t88u0il9e8q.dll
deleting: C:\WINDOWS\system32\uqrfaxa.dll
Successfully Deleted: C:\WINDOWS\system32\uqrfaxa.dll
Desktop.ini sucessfully removed
Zipping up files for submission:
adding: aza02g3mg6.dll (164 bytes security) (deflated 4%)
adding: aza0lclm1fqa.dll (164 bytes security) (deflated 3%)
adding: aza2l55o1.dll (164 bytes security) (deflated 4%)
adding: azam01j1e.dll (164 bytes security) (deflated 4%)
adding: azao0133e.dll (164 bytes security) (deflated 3%)
adding: azaolc331f.dll (164 bytes security) (deflated 4%)
adding: c6002gdmg60a2.dll (164 bytes security) (deflated 4%)
adding: cnrsrv.dll (164 bytes security) (deflated 4%)
adding: d8j00i1me8.dll (164 bytes security) (deflated 4%)
adding: dbauth.dll (164 bytes security) (deflated 4%)
adding: dn6m01j1e.dll (164 bytes security) (deflated 4%)
adding: dnlo0133e.dll (164 bytes security) (deflated 4%)
adding: dnp2017oe.dll (164 bytes security) (deflated 4%)
adding: dnr6019se.dll (164 bytes security) (deflated 4%)
adding: dnrm0191e.dll (164 bytes security) (deflated 4%)
adding: en4ul1h91.dll (164 bytes security) (deflated 4%)
adding: enp2l17o1.dll (164 bytes security) (deflated 4%)
adding: f00olad31d0.dll (164 bytes security) (deflated 4%)
adding: fn2021fmg.dll (164 bytes security) (deflated 5%)
adding: fp2203foe.dll (164 bytes security) (deflated 4%)
adding: fp8q03l5e.dll (164 bytes security) (deflated 4%)
adding: fpj6031se.dll (164 bytes security) (deflated 4%)
adding: fplo0333e.dll (164 bytes security) (deflated 3%)
adding: g2220cfoef2c0.dll (164 bytes security) (deflated 4%)
adding: g6jo0g13e6.dll (164 bytes security) (deflated 4%)
adding: GBCollection.dll (164 bytes security) (deflated 4%)
adding: gp8ql3l51.dll (164 bytes security) (deflated 4%)
adding: gppul3791.dll (164 bytes security) (deflated 5%)
adding: gpr6l39s1.dll (164 bytes security) (deflated 4%)
adding: gprml3911.dll (164 bytes security) (deflated 4%)
adding: h0j40a1qed.dll (164 bytes security) (deflated 4%)
adding: h40q0ed5eh0.dll (164 bytes security) (deflated 4%)
adding: h8l20i3oe8.dll (164 bytes security) (deflated 5%)
adding: hrl0053me.dll (164 bytes security) (deflated 4%)
adding: hrlq0535e.dll (164 bytes security) (deflated 4%)
adding: hrro0593e.dll (164 bytes security) (deflated 5%)
adding: hrrq0595e.dll (164 bytes security) (deflated 4%)
adding: i2lo0c33ef.dll (164 bytes security) (deflated 4%)
adding: i2lolc331f.dll (164 bytes security) (deflated 5%)
adding: i6600gjme6oa0.dll (164 bytes security) (deflated 4%)
adding: i8jq0i15e8.dll (164 bytes security) (deflated 4%)
adding: ir24l5fq1.dll (164 bytes security) (deflated 3%)
adding: irn2l55o1.dll (164 bytes security) (deflated 4%)
adding: irp6l57s1.dll (164 bytes security) (deflated 4%)
adding: irrql5951.dll (164 bytes security) (deflated 4%)
adding: jr0025dmg.dll (164 bytes security) (deflated 5%)
adding: jt4807hue.dll (164 bytes security) (deflated 4%)
adding: jt8407lqe.dll (164 bytes security) (deflated 4%)
adding: jtj0071me.dll (164 bytes security) (deflated 4%)
adding: k280lclm1fqa.dll (164 bytes security) (deflated 4%)
adding: k6pmlg7116.dll (164 bytes security) (deflated 4%)
adding: kodsp.dll (164 bytes security) (deflated 3%)
adding: ktp6l77s1.dll (164 bytes security) (deflated 4%)
adding: l0l6la3s1d.dll (164 bytes security) (deflated 4%)
adding: l22s0cf7ef2.dll (164 bytes security) (deflated 5%)
adding: l22slcf71f2.dll (164 bytes security) (deflated 4%)
adding: l46o0ej3eho.dll (164 bytes security) (deflated 5%)
adding: l4r0le9m1h.dll (164 bytes security) (deflated 5%)
adding: l6j8lg1u16.dll (164 bytes security) (deflated 4%)
adding: l80u0id9e80.dll (164 bytes security) (deflated 4%)
adding: l8n40i5qe8.dll (164 bytes security) (deflated 4%)
adding: lv0409dqe.dll (164 bytes security) (deflated 4%)
adding: m8po0i73e8.dll (164 bytes security) (deflated 4%)
adding: mv8ul9l91.dll (164 bytes security) (deflated 4%)
adding: mvp8l97u1.dll (164 bytes security) (deflated 4%)
adding: mvrql9951.dll (164 bytes security) (deflated 4%)
adding: n66qlgj516o.dll (164 bytes security) (deflated 5%)
adding: o0660ajsedo60.dll (164 bytes security) (deflated 4%)
adding: o066lajs1do6.dll (164 bytes security) (deflated 5%)
adding: o4nsle571h.dll (164 bytes security) (deflated 5%)
adding: p04u0ah9ed4.dll (164 bytes security) (deflated 4%)
adding: q268lcju1fo8.dll (164 bytes security) (deflated 4%)
adding: q468leju1ho8.dll (164 bytes security) (deflated 3%)
adding: SbyLt3Pr.dll (164 bytes security) (deflated 4%)
adding: t6r8lg9u16.dll (164 bytes security) (deflated 4%)
adding: t88u0il9e8q.dll (164 bytes security) (deflated 4%)
adding: uqrfaxa.dll (164 bytes security) (deflated 5%)
adding: clear.reg (164 bytes security) (deflated 69%)
adding: echo.reg (164 bytes security) (deflated 8%)
adding: desktop.ini (164 bytes security) (deflated 15%)
adding: direct.txt (164 bytes security) (stored 0%)
adding: lo2.txt (164 bytes security) (deflated 88%)
adding: readme.txt (164 bytes security) (deflated 49%)
adding: test.txt (164 bytes security) (deflated 83%)
adding: test2.txt (164 bytes security) (deflated 48%)
adding: test3.txt (164 bytes security) (deflated 48%)
adding: test5.txt (164 bytes security) (deflated 48%)
adding: xfind.txt (164 bytes security) (deflated 79%)
adding: backregs/105376F3-0A9C-450F-925E-E39C577DCD34.reg (164 bytes security) (deflated 71%)
adding: backregs/37C94FEB-49F3-46E3-A8A3-D6A66959CFC3.reg (164 bytes security) (deflated 70%)
adding: backregs/3838F7A4-A38E-4D3C-B668-83F6D2E8BE62.reg (164 bytes security) (deflated 71%)
adding: backregs/4056A87A-9055-4911-8513-2F4369DA4283.reg (164 bytes security) (deflated 71%)
adding: backregs/4A4B92DE-3258-4C24-AAA1-D9966C6105B9.reg (164 bytes security) (deflated 70%)
adding: backregs/536CC415-6460-4768-BB0A-B40C4439F179.reg (164 bytes security) (deflated 71%)
adding: backregs/5701C41D-5885-4E35-B013-100BF38BE2E2.reg (164 bytes security) (deflated 71%)
adding: backregs/58E0CAE6-4166-460D-86A5-D987AE121C97.reg (164 bytes security) (deflated 70%)
adding: backregs/6421CEBC-D361-46C2-9A76-A329ABAFEC04.reg (164 bytes security) (deflated 71%)
adding: backregs/6BE8887D-09AD-4449-97AF-E391F1421E18.reg (164 bytes security) (deflated 71%)
adding: backregs/8AC0BAA5-F4D7-40D5-A95E-8A3931151402.reg (164 bytes security) (deflated 71%)
adding: backregs/A494F5B0-4B93-46D3-8E2F-F5E0D9AAA98D.reg (164 bytes security) (deflated 71%)
adding: backregs/ADD21D69-F58C-4FE7-80EF-6A26B6182C3C.reg (164 bytes security) (deflated 70%)
adding: backregs/B2C12BBF-26A0-4C4C-9E45-9BBDCC97C77B.reg (164 bytes security) (deflated 71%)
adding: backregs/BF9FE0A0-F75F-4E40-BF97-36229700C30D.reg (164 bytes security) (deflated 71%)
adding: backregs/C45D161B-1A54-483B-955A-B7591DEFA02B.reg (164 bytes security) (deflated 71%)
adding: backregs/CE15ACB4-F7D9-4A0C-98E6-5E63FDEF66BE.reg (164 bytes security) (deflated 71%)
adding: backregs/E417E5B1-53A8-43D7-A074-41B277189561.reg (164 bytes security) (deflated 71%)
adding: backregs/E7C8F3B9-1336-47B0-A616-231EB01C1503.reg (164 bytes security) (deflated 71%)
adding: backregs/shell.reg (164 bytes security) (deflated 73%)
Restoring Registry Permissions:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (
http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Revoking access for predefined group "Administrators"
Inherited ACE can not be revoked here!
Inherited ACE can not be revoked here!
Registry permissions set too:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (
http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER
Restoring Sedebugprivilege:
Granting SeDebugPrivilege to Administrators ... successful
deleting local copy: aza02g3mg6.dll
deleting local copy: aza0lclm1fqa.dll
deleting local copy: aza2l55o1.dll
deleting local copy: azam01j1e.dll
deleting local copy: azao0133e.dll
deleting local copy: azaolc331f.dll
deleting local copy: c6002gdmg60a2.dll
deleting local copy: cnrsrv.dll
deleting local copy: d8j00i1me8.dll
deleting local copy: dbauth.dll
deleting local copy: dn6m01j1e.dll
deleting local copy: dnlo0133e.dll
deleting local copy: dnp2017oe.dll
deleting local copy: dnr6019se.dll
deleting local copy: dnrm0191e.dll
deleting local copy: en4ul1h91.dll
deleting local copy: enp2l17o1.dll
deleting local copy: f00olad31d0.dll
deleting local copy: fn2021fmg.dll
deleting local copy: fp2203foe.dll
deleting local copy: fp8q03l5e.dll
deleting local copy: fpj6031se.dll
deleting local copy: fplo0333e.dll
deleting local copy: g2220cfoef2c0.dll
deleting local copy: g6jo0g13e6.dll
deleting local copy: GBCollection.dll
deleting local copy: gp8ql3l51.dll
deleting local copy: gppul3791.dll
deleting local copy: gpr6l39s1.dll
deleting local copy: gprml3911.dll
deleting local copy: h0j40a1qed.dll
deleting local copy: h40q0ed5eh0.dll
deleting local copy: h8l20i3oe8.dll
deleting local copy: hrl0053me.dll
deleting local copy: hrlq0535e.dll
deleting local copy: hrro0593e.dll
deleting local copy: hrrq0595e.dll
deleting local copy: i2lo0c33ef.dll
deleting local copy: i2lolc331f.dll
deleting local copy: i6600gjme6oa0.dll
deleting local copy: i8jq0i15e8.dll
deleting local copy: ir24l5fq1.dll
deleting local copy: irn2l55o1.dll
deleting local copy: irp6l57s1.dll
deleting local copy: irrql5951.dll
deleting local copy: jr0025dmg.dll
deleting local copy: jt4807hue.dll
deleting local copy: jt8407lqe.dll
deleting local copy: jtj0071me.dll
deleting local copy: k280lclm1fqa.dll
deleting local copy: k6pmlg7116.dll
deleting local copy: kodsp.dll
deleting local copy: ktp6l77s1.dll
deleting local copy: l0l6la3s1d.dll
deleting local copy: l22s0cf7ef2.dll
deleting local copy: l22slcf71f2.dll
deleting local copy: l46o0ej3eho.dll
deleting local copy: l4r0le9m1h.dll
deleting local copy: l6j8lg1u16.dll
deleting local copy: l80u0id9e80.dll
deleting local copy: l8n40i5qe8.dll
deleting local copy: lv0409dqe.dll
deleting local copy: m8po0i73e8.dll
deleting local copy: mv8ul9l91.dll
deleting local copy: mvp8l97u1.dll
deleting local copy: mvrql9951.dll
deleting local copy: n66qlgj516o.dll
deleting local copy: o0660ajsedo60.dll
deleting local copy: o066lajs1do6.dll
deleting local copy: o4nsle571h.dll
deleting local copy: p04u0ah9ed4.dll
deleting local copy: q268lcju1fo8.dll
deleting local copy: q468leju1ho8.dll
deleting local copy: SbyLt3Pr.dll
deleting local copy: t6r8lg9u16.dll
deleting local copy: t88u0il9e8q.dll
deleting local copy: uqrfaxa.dll
The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
@=""
"DLLName"="igfxsrvc.dll"
"Asynchronous"=dword:00000001
"Impersonate"=dword:00000001
"Unlock"="WinlogonUnlockEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
The following are the files found:
****************************************************************************
C:\WINDOWS\system32\aza02g3mg6.dll
C:\WINDOWS\system32\aza0lclm1fqa.dll
C:\WINDOWS\system32\aza2l55o1.dll
C:\WINDOWS\system32\azam01j1e.dll
C:\WINDOWS\system32\azao0133e.dll
C:\WINDOWS\system32\azaolc331f.dll
C:\WINDOWS\system32\c6002gdmg60a2.dll
C:\WINDOWS\system32\cnrsrv.dll
C:\WINDOWS\system32\d8j00i1me8.dll
C:\WINDOWS\system32\dbauth.dll
C:\WINDOWS\system32\dn6m01j1e.dll
C:\WINDOWS\system32\dnlo0133e.dll
C:\WINDOWS\system32\dnp2017oe.dll
C:\WINDOWS\system32\dnr6019se.dll
C:\WINDOWS\system32\dnrm0191e.dll
C:\WINDOWS\system32\en4ul1h91.dll
C:\WINDOWS\system32\enp2l17o1.dll
C:\WINDOWS\system32\f00olad31d0.dll
C:\WINDOWS\system32\fn2021fmg.dll
C:\WINDOWS\system32\fp2203foe.dll
C:\WINDOWS\system32\fp8q03l5e.dll
C:\WINDOWS\system32\fpj6031se.dll
C:\WINDOWS\system32\fplo0333e.dll
C:\WINDOWS\system32\g2220cfoef2c0.dll
C:\WINDOWS\system32\g6jo0g13e6.dll
C:\WINDOWS\system32\GBCollection.dll
C:\WINDOWS\system32\gp8ql3l51.dll
C:\WINDOWS\system32\gppul3791.dll
C:\WINDOWS\system32\gpr6l39s1.dll
C:\WINDOWS\system32\gprml3911.dll
C:\WINDOWS\system32\h0j40a1qed.dll
C:\WINDOWS\system32\h40q0ed5eh0.dll
C:\WINDOWS\system32\h8l20i3oe8.dll
C:\WINDOWS\system32\hrl0053me.dll
C:\WINDOWS\system32\hrlq0535e.dll
C:\WINDOWS\system32\hrro0593e.dll
C:\WINDOWS\system32\hrrq0595e.dll
C:\WINDOWS\system32\i2lo0c33ef.dll
C:\WINDOWS\system32\i2lolc331f.dll
C:\WINDOWS\system32\i6600gjme6oa0.dll
C:\WINDOWS\system32\i8jq0i15e8.dll
C:\WINDOWS\system32\ir24l5fq1.dll
C:\WINDOWS\system32\irn2l55o1.dll
C:\WINDOWS\system32\irp6l57s1.dll
C:\WINDOWS\system32\irrql5951.dll
C:\WINDOWS\system32\jr0025dmg.dll
C:\WINDOWS\system32\jt4807hue.dll
C:\WINDOWS\system32\jt8407lqe.dll
C:\WINDOWS\system32\jtj0071me.dll
C:\WINDOWS\system32\k280lclm1fqa.dll
C:\WINDOWS\system32\k6pmlg7116.dll
C:\WINDOWS\system32\kodsp.dll
C:\WINDOWS\system32\ktp6l77s1.dll
C:\WINDOWS\system32\l0l6la3s1d.dll
C:\WINDOWS\system32\l22s0cf7ef2.dll
C:\WINDOWS\system32\l22slcf71f2.dll
C:\WINDOWS\system32\l46o0ej3eho.dll
C:\WINDOWS\system32\l4r0le9m1h.dll
C:\WINDOWS\system32\l6j8lg1u16.dll
C:\WINDOWS\system32\l80u0id9e80.dll
C:\WINDOWS\system32\l8n40i5qe8.dll
C:\WINDOWS\system32\lv0409dqe.dll
C:\WINDOWS\system32\m8po0i73e8.dll
C:\WINDOWS\system32\mv8ul9l91.dll
C:\WINDOWS\system32\mvp8l97u1.dll
C:\WINDOWS\system32\mvrql9951.dll
C:\WINDOWS\system32\n66qlgj516o.dll
C:\WINDOWS\system32\o0660ajsedo60.dll
C:\WINDOWS\system32\o066lajs1do6.dll
C:\WINDOWS\system32\o4nsle571h.dll
C:\WINDOWS\system32\p04u0ah9ed4.dll
C:\WINDOWS\system32\q268lcju1fo8.dll
C:\WINDOWS\system32\q468leju1ho8.dll
C:\WINDOWS\system32\SbyLt3Pr.dll
C:\WINDOWS\system32\t6r8lg9u16.dll
C:\WINDOWS\system32\t88u0il9e8q.dll
C:\WINDOWS\system32\uqrfaxa.dll
Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{5701C41D-5885-4E35-B013-100BF38BE2E2}"=-
"{37C94FEB-49F3-46E3-A8A3-D6A66959CFC3}"=-
"{A494F5B0-4B93-46D3-8E2F-F5E0D9AAA98D}"=-
"{4A4B92DE-3258-4C24-AAA1-D9966C6105B9}"=-
"{58E0CAE6-4166-460D-86A5-D987AE121C97}"=-
"{ADD21D69-F58C-4FE7-80EF-6A26B6182C3C}"=-
"{CE15ACB4-F7D9-4A0C-98E6-5E63FDEF66BE}"=-
"{105376F3-0A9C-450F-925E-E39C577DCD34}"=-
"{6421CEBC-D361-46C2-9A76-A329ABAFEC04}"=-
"{E417E5B1-53A8-43D7-A074-41B277189561}"=-
"{C45D161B-1A54-483B-955A-B7591DEFA02B}"=-
"{E7C8F3B9-1336-47B0-A616-231EB01C1503}"=-
"{6BE8887D-09AD-4449-97AF-E391F1421E18}"=-
"{BF9FE0A0-F75F-4E40-BF97-36229700C30D}"=-
"{8AC0BAA5-F4D7-40D5-A95E-8A3931151402}"=-
"{3838F7A4-A38E-4D3C-B668-83F6D2E8BE62}"=-
"{B2C12BBF-26A0-4C4C-9E45-9BBDCC97C77B}"=-
"{536CC415-6460-4768-BB0A-B40C4439F179}"=-
"{4056A87A-9055-4911-8513-2F4369DA4283}"=-
[-HKEY_CLASSES_ROOT\CLSID\{5701C41D-5885-4E35-B013-100BF38BE2E2}]
[-HKEY_CLASSES_ROOT\CLSID\{37C94FEB-49F3-46E3-A8A3-D6A66959CFC3}]
[-HKEY_CLASSES_ROOT\CLSID\{A494F5B0-4B93-46D3-8E2F-F5E0D9AAA98D}]
[-HKEY_CLASSES_ROOT\CLSID\{4A4B92DE-3258-4C24-AAA1-D9966C6105B9}]
[-HKEY_CLASSES_ROOT\CLSID\{58E0CAE6-4166-460D-86A5-D987AE121C97}]
[-HKEY_CLASSES_ROOT\CLSID\{ADD21D69-F58C-4FE7-80EF-6A26B6182C3C}]
[-HKEY_CLASSES_ROOT\CLSID\{CE15ACB4-F7D9-4A0C-98E6-5E63FDEF66BE}]
[-HKEY_CLASSES_ROOT\CLSID\{105376F3-0A9C-450F-925E-E39C577DCD34}]
[-HKEY_CLASSES_ROOT\CLSID\{6421CEBC-D361-46C2-9A76-A329ABAFEC04}]
[-HKEY_CLASSES_ROOT\CLSID\{E417E5B1-53A8-43D7-A074-41B277189561}]
[-HKEY_CLASSES_ROOT\CLSID\{C45D161B-1A54-483B-955A-B7591DEFA02B}]
[-HKEY_CLASSES_ROOT\CLSID\{E7C8F3B9-1336-47B0-A616-231EB01C1503}]
[-HKEY_CLASSES_ROOT\CLSID\{6BE8887D-09AD-4449-97AF-E391F1421E18}]
[-HKEY_CLASSES_ROOT\CLSID\{BF9FE0A0-F75F-4E40-BF97-36229700C30D}]
[-HKEY_CLASSES_ROOT\CLSID\{8AC0BAA5-F4D7-40D5-A95E-8A3931151402}]
[-HKEY_CLASSES_ROOT\CLSID\{3838F7A4-A38E-4D3C-B668-83F6D2E8BE62}]
[-HKEY_CLASSES_ROOT\CLSID\{B2C12BBF-26A0-4C4C-9E45-9BBDCC97C77B}]
[-HKEY_CLASSES_ROOT\CLSID\{536CC415-6460-4768-BB0A-B40C4439F179}]
[-HKEY_CLASSES_ROOT\CLSID