Logfile of HijackThis v1.99.1Scan saved at 10:48:38 AM, on 8/11/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\RTVSCN95.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\VPTRAY.EXE
C:\WINDOWS\RAMHLL.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\CMD\COMMAND.EXE
C:\PROGRAM FILES\EZULA\MMOD.EXE
C:\PROGRAM FILES\WEB OFFER\WO.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
C:\HJT\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://google.com/R3 - Default URLSearchHook is missing
O2 - BHO: SDWin32 Class - {8A36E75F-112B-4FBF-A497-73CEEF29380A} - C:\WINDOWS\SYSTEM\BPQKS.DLL
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [FlashClean] C:\PROGRAM FILES\FLASHCLEAN\FlashClean.exe %1
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\ramhll.exe reg_run
O4 - HKLM\..\Run: [autoupdate] rundll32 C:\WINDOWS\SYSTEM\DATADX.DLL,SHStart
O4 - HKLM\..\Run: [Command] C:\WINDOWS\cmd\command.exe
O4 - HKLM\..\Run: [bpqksc] C:\WINDOWS\SYSTEM\bpqksc.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [rtvscn95] C:\PROGRA~1\SYMANT~1\SYMANT~1\rtvscn95.exe
O4 - HKCU\..\Run: [ccleaner] "C:\PROGRAM FILES\CCLEANER\CCLEANER.exe" /AUTO
O4 - HKCU\..\Run: [eZmmod] C:\PROGRA~1\ezula\mmod.exe
O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe
O4 - Startup: natr.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) -
http://games-dl.real...ArcadeRdxIE.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cabO16 - DPF: Yahoo! Pool 2 -
http://download.game...ts/y/pote_x.cabO16 - DPF: {90918C20-FB99-495A-BD79-CB91ACF44887} -
http://www.typingmas...ick/TMSetup.cabO16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) -
http://rd1.surfernet...urferplugin.ocxO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://www.popcap.co...aploader_v6.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://zone.msn.com/...ro.cab34246.cabO16 - DPF: {8DA664DC-123E-4836-B7B3-6653A8B082AB} (ChatOCX Control) -
http://www.igl.net/c...ChatOCXProj.cabO16 - DPF: {64D01C7F-810D-446E-A07E-16C764235644} (AtlAtomadersCtlAttrib Class) -
http://zone.msn.com/...t/atomaders.cabO16 - DPF: {DAF5D9A2-D982-4671-83E4-0398706A5F6A} (SCEWebLauncherCtl Object) -
http://zone.msn.com/...WebLauncher.cabO16 - DPF: {3DA5D23B-EFE1-4181-ADB7-7D457567AACA} (TGOnlineCtrl Class) -
http://zone.msn.com/...pandaonline.cabO16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) -
http://dlmanager.aka...vex-2.0.2.7.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft.../as5/asinst.cabO16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://www.bitdefend...can8/oscan8.cabO16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) -
http://pdl.stream.ao.../ampx_en_dl.cabO16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...ebscan_ansi.cabO16 - DPF: {4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} (ActiveX Control) -
http://www.icannnews.../ST/ActiveX.ocxO16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) -
http://download.zone...ctor/WebAAS.cabLog of L2M9XFix v1 ************
Running from directory:
C:\WINDOWS\Desktop\l2m9xfix
************
Files found:
C:\WINDOWS\system\AATXPRXY.DLL
C:\WINDOWS\system\AATXPRXY.DLL
C:\WINDOWS\system\AATXPRXY.DLL
C:\WINDOWS\system\AATXPRXY.DLL
C:\WINDOWS\system\ABRACE.DLL
C:\WINDOWS\system\ABRACE.DLL
C:\WINDOWS\system\ABRACE.DLL
C:\WINDOWS\system\ABRACE.DLL
C:\WINDOWS\system\AFKRNL32.DLL
C:\WINDOWS\system\AFKRNL32.DLL
C:\WINDOWS\system\AFKRNL32.DLL
C:\WINDOWS\system\AFKRNL32.DLL
C:\WINDOWS\system\ALSTREAM.DLL
C:\WINDOWS\system\ALSTREAM.DLL
C:\WINDOWS\system\ALSTREAM.DLL
C:\WINDOWS\system\ALSTREAM.DLL
C:\WINDOWS\system\AMMUI.DLL
C:\WINDOWS\system\AMMUI.DLL
C:\WINDOWS\system\APMUI.DLL
C:\WINDOWS\system\APMUI.DLL
C:\WINDOWS\system\axl71.DLL
C:\WINDOWS\system\axl71.DLL
C:\WINDOWS\system\axl71.DLL
C:\WINDOWS\system\axl71.DLL
C:\WINDOWS\system\AYMUI.DLL
C:\WINDOWS\system\AYMUI.DLL
C:\WINDOWS\system\AYMUI.DLL
C:\WINDOWS\system\AYMUI.DLL
C:\WINDOWS\system\AYSTREAM.DLL
C:\WINDOWS\system\AYSTREAM.DLL
C:\WINDOWS\system\AYSTREAM.DLL
C:\WINDOWS\system\AYSTREAM.DLL
C:\WINDOWS\system\CCMMDLG.DLL
C:\WINDOWS\system\CCMMDLG.DLL
C:\WINDOWS\system\CCMMDLG.DLL
C:\WINDOWS\system\CCMMDLG.DLL
C:\WINDOWS\system\CJA.DLL
C:\WINDOWS\system\CJA.DLL
C:\WINDOWS\system\CJA.DLL
C:\WINDOWS\system\CJA.DLL
C:\WINDOWS\system\CMRPOL.DLL
C:\WINDOWS\system\CMRPOL.DLL
C:\WINDOWS\system\CMRPOL.DLL
C:\WINDOWS\system\CMRPOL.DLL
C:\WINDOWS\system\CNOOSUSR.DLL
C:\WINDOWS\system\CNOOSUSR.DLL
C:\WINDOWS\system\CNOOSUSR.DLL
C:\WINDOWS\system\CNOOSUSR.DLL
C:\WINDOWS\system\CUYPTNET.DLL
C:\WINDOWS\system\CUYPTNET.DLL
C:\WINDOWS\system\CUYPTNET.DLL
C:\WINDOWS\system\CUYPTNET.DLL
C:\WINDOWS\system\cyral.dll
C:\WINDOWS\system\cyral.dll
C:\WINDOWS\system\cyral.dll
C:\WINDOWS\system\cyral.dll
C:\WINDOWS\system\DADRM16F.DLL
C:\WINDOWS\system\DADRM16F.DLL
C:\WINDOWS\system\DADRM16F.DLL
C:\WINDOWS\system\DADRM16F.DLL
C:\WINDOWS\system\DAGHELP.DLL
C:\WINDOWS\system\DAGHELP.DLL
C:\WINDOWS\system\DAGHELP.DLL
C:\WINDOWS\system\DAGHELP.DLL
C:\WINDOWS\system\DAUSIC.DLL
C:\WINDOWS\system\DAUSIC.DLL
C:\WINDOWS\system\DAUSIC.DLL
C:\WINDOWS\system\DAUSIC.DLL
C:\WINDOWS\system\dbdmo.dll
C:\WINDOWS\system\DBDRAMPF.DLL
C:\WINDOWS\system\DBDRAMPF.DLL
C:\WINDOWS\system\DBDRAMPF.DLL
C:\WINDOWS\system\DBDRAMPF.DLL
C:\WINDOWS\system\dbwave.dll
C:\WINDOWS\system\dbwave.dll
C:\WINDOWS\system\dbwave.dll
C:\WINDOWS\system\dbwave.dll
C:\WINDOWS\system\DCSKCOPY.DLL
C:\WINDOWS\system\DCSKCOPY.DLL
C:\WINDOWS\system\DCSKCOPY.DLL
C:\WINDOWS\system\DCSKCOPY.DLL
C:\WINDOWS\system\DESPEX.DLL
C:\WINDOWS\system\DESPEX.DLL
C:\WINDOWS\system\DESPEX.DLL
C:\WINDOWS\system\DESPEX.DLL
C:\WINDOWS\system\DFCVW_32.DLL
C:\WINDOWS\system\DFCVW_32.DLL
C:\WINDOWS\system\dgnaddr.dll
C:\WINDOWS\system\dgnaddr.dll
C:\WINDOWS\system\dgnaddr.dll
C:\WINDOWS\system\dgnaddr.dll
C:\WINDOWS\system\DHMODEMX.DLL
C:\WINDOWS\system\DHMODEMX.DLL
C:\WINDOWS\system\DHMODEMX.DLL
C:\WINDOWS\system\DHMODEMX.DLL
C:\WINDOWS\system\DJDIM.DLL
C:\WINDOWS\system\DJDIM.DLL
C:\WINDOWS\system\DJDIM.DLL
C:\WINDOWS\system\DJDIM.DLL
C:\WINDOWS\system\DKDHALF.DLL
C:\WINDOWS\system\DKDHALF.DLL
C:\WINDOWS\system\DKDHALF.DLL
C:\WINDOWS\system\DKDHALF.DLL
C:\WINDOWS\system\DKLAY.DLL
C:\WINDOWS\system\DKLAY.DLL
C:\WINDOWS\system\DKLAY.DLL
C:\WINDOWS\system\DKLAY.DLL
C:\WINDOWS\system\DLDREF.DLL
C:\WINDOWS\system\DLDREF.DLL
C:\WINDOWS\system\DLDREF.DLL
C:\WINDOWS\system\DLDREF.DLL
C:\WINDOWS\system\DQDRG8X.DLL
C:\WINDOWS\system\DQDRG8X.DLL
C:\WINDOWS\system\DQDRG8X.DLL
C:\WINDOWS\system\DQDRG8X.DLL
C:\WINDOWS\system\DTEML.DLL
C:\WINDOWS\system\DTEML.DLL
C:\WINDOWS\system\DTEML.DLL
C:\WINDOWS\system\DTEML.DLL
C:\WINDOWS\system\DVDIM.DLL
C:\WINDOWS\system\DVDIM.DLL
C:\WINDOWS\system\DVDIM.DLL
C:\WINDOWS\system\DVDIM.DLL
C:\WINDOWS\system\DWSENH.DLL
C:\WINDOWS\system\DWSENH.DLL
C:\WINDOWS\system\DY3J.DLL
C:\WINDOWS\system\DY3J.DLL
C:\WINDOWS\system\DY3J.DLL
C:\WINDOWS\system\DY3J.DLL
C:\WINDOWS\system\DYDRG24X.DLL
C:\WINDOWS\system\DYDRG24X.DLL
C:\WINDOWS\system\DYDRG24X.DLL
C:\WINDOWS\system\DYDRG24X.DLL
C:\WINDOWS\system\efenu.dll
C:\WINDOWS\system\efenu.dll
C:\WINDOWS\system\efenu.dll
C:\WINDOWS\system\efenu.dll
C:\WINDOWS\system\eienu.dll
C:\WINDOWS\system\eienu.dll
C:\WINDOWS\system\eienu.dll
C:\WINDOWS\system\eienu.dll
C:\WINDOWS\system\ET.DLL
C:\WINDOWS\system\ET.DLL
C:\WINDOWS\system\ET.DLL
C:\WINDOWS\system\ET.DLL
C:\WINDOWS\system\GBF.DLL
C:\WINDOWS\system\GBF.DLL
C:\WINDOWS\system\GBF.DLL
C:\WINDOWS\system\GBF.DLL
C:\WINDOWS\system\GIU32.DLL
C:\WINDOWS\system\GIU32.DLL
C:\WINDOWS\system\HFTPLUG.DLL
C:\WINDOWS\system\HFTPLUG.DLL
C:\WINDOWS\system\HFTPLUG.DLL
C:\WINDOWS\system\HFTPLUG.DLL
C:\WINDOWS\system\HXINK.DLL
C:\WINDOWS\system\HXINK.DLL
C:\WINDOWS\system\HXINK.DLL
C:\WINDOWS\system\HXINK.DLL
C:\WINDOWS\system\IDROP.DLL
C:\WINDOWS\system\IDROP.DLL
C:\WINDOWS\system\IISENG.DLL
C:\WINDOWS\system\IISENG.DLL
C:\WINDOWS\system\IISENG.DLL
C:\WINDOWS\system\IISENG.DLL
C:\WINDOWS\system\ILM32.DLL
C:\WINDOWS\system\ILM32.DLL
C:\WINDOWS\system\ILM32.DLL
C:\WINDOWS\system\ILM32.DLL
C:\WINDOWS\system\IMMFILTER.DLL
C:\WINDOWS\system\IMMFILTER.DLL
C:\WINDOWS\system\IMMFILTER.DLL
C:\WINDOWS\system\IMMFILTER.DLL
C:\WINDOWS\system\IQMUI.DLL
C:\WINDOWS\system\IQMUI.DLL
C:\WINDOWS\system\IQMUI.DLL
C:\WINDOWS\system\IQMUI.DLL
C:\WINDOWS\system\ISM32.DLL
C:\WINDOWS\system\ISM32.DLL
C:\WINDOWS\system\ISM32.DLL
C:\WINDOWS\system\ISM32.DLL
C:\WINDOWS\system\IW3Svc.dll
C:\WINDOWS\system\IWROP.DLL
C:\WINDOWS\system\IWROP.DLL
C:\WINDOWS\system\IWROP.DLL
C:\WINDOWS\system\IWROP.DLL
C:\WINDOWS\system\IYGCMN.DLL
C:\WINDOWS\system\IYGCMN.DLL
C:\WINDOWS\system\IYGCMN.DLL
C:\WINDOWS\system\IYGCMN.DLL
C:\WINDOWS\system\IZ50_QCX.DLL
C:\WINDOWS\system\IZ50_QCX.DLL
C:\WINDOWS\system\IZ50_QCX.DLL
C:\WINDOWS\system\IZ50_QCX.DLL
C:\WINDOWS\system\IZWDIAL.DLL
C:\WINDOWS\system\IZWDIAL.DLL
C:\WINDOWS\system\jgd.dll
C:\WINDOWS\system\jgd.dll
C:\WINDOWS\system\jgd.dll
C:\WINDOWS\system\jgd.dll
C:\WINDOWS\system\JJEG2X32.DLL
C:\WINDOWS\system\JJEG2X32.DLL
C:\WINDOWS\system\JJEG2X32.DLL
C:\WINDOWS\system\JJEG2X32.DLL
C:\WINDOWS\system\KCRNEL32.DLL
C:\WINDOWS\system\KCRNEL32.DLL
C:\WINDOWS\system\KCRNEL32.DLL
C:\WINDOWS\system\KCRNEL32.DLL
C:\WINDOWS\system\lvqp7c25q.dll
C:\WINDOWS\system\lvqp7c25q.dll
C:\WINDOWS\system\mbcpxl32.dll
C:\WINDOWS\system\mbcpxl32.dll
C:\WINDOWS\system\mbcpxl32.dll
C:\WINDOWS\system\mbcpxl32.dll
C:\WINDOWS\system\MCC30.DLL
C:\WINDOWS\system\MCC30.DLL
C:\WINDOWS\system\MCC30.DLL
C:\WINDOWS\system\MCC30.DLL
C:\WINDOWS\system\mecpxl32.dll
C:\WINDOWS\system\mecpxl32.dll
C:\WINDOWS\system\mecpxl32.dll
C:\WINDOWS\system\mecpxl32.dll
C:\WINDOWS\system\MEPWL32.DLL
C:\WINDOWS\system\MEPWL32.DLL
C:\WINDOWS\system\mfvcr70.dll
C:\WINDOWS\system\mfvcr70.dll
C:\WINDOWS\system\mfvcr70.dll
C:\WINDOWS\system\mfvcr70.dll
C:\WINDOWS\system\MHC40.DLL
C:\WINDOWS\system\MHC40.DLL
C:\WINDOWS\system\MHC40.DLL
C:\WINDOWS\system\MHC40.DLL
C:\WINDOWS\system\MIPMSP.DLL
C:\WINDOWS\system\MIPMSP.DLL
C:\WINDOWS\system\MIPMSP.DLL
C:\WINDOWS\system\MIPMSP.DLL
C:\WINDOWS\system\MKREPL40.DLL
C:\WINDOWS\system\MKREPL40.DLL
C:\WINDOWS\system\MKREPL40.DLL
C:\WINDOWS\system\MKREPL40.DLL
C:\WINDOWS\system\MLRD2X40.DLL
C:\WINDOWS\system\MLRD2X40.DLL
C:\WINDOWS\system\MLRD2X40.DLL
C:\WINDOWS\system\MLRD2X40.DLL
C:\WINDOWS\system\MMLTUS40.DLL
C:\WINDOWS\system\MMLTUS40.DLL
C:\WINDOWS\system\MMLTUS40.DLL
C:\WINDOWS\system\MMLTUS40.DLL
C:\WINDOWS\system\MOC30.DLL
C:\WINDOWS\system\MOC30.DLL
C:\WINDOWS\system\MOC30.DLL
C:\WINDOWS\system\MOC30.DLL
C:\WINDOWS\system\mqpatcha.dll
C:\WINDOWS\system\mqpatcha.dll
C:\WINDOWS\system\mqpatcha.dll
C:\WINDOWS\system\mqpatcha.dll
C:\WINDOWS\system\mrjetoledb40.dll
C:\WINDOWS\system\mrjetoledb40.dll
C:\WINDOWS\system\mrjetoledb40.dll
C:\WINDOWS\system\mrjetoledb40.dll
C:\WINDOWS\system\MTAWT.DLL
C:\WINDOWS\system\MTAWT.DLL
C:\WINDOWS\system\MTAWT.DLL
C:\WINDOWS\system\MTAWT.DLL
C:\WINDOWS\system\MTJINT40.DLL
C:\WINDOWS\system\MTJINT40.DLL
C:\WINDOWS\system\MTJINT40.DLL
C:\WINDOWS\system\MTJINT40.DLL
C:\WINDOWS\system\MUEXCL40.DLL
C:\WINDOWS\system\MUEXCL40.DLL
C:\WINDOWS\system\MUEXCL40.DLL
C:\WINDOWS\system\MUEXCL40.DLL
C:\WINDOWS\system\MUMIXMGR.DLL
C:\WINDOWS\system\MUMIXMGR.DLL
C:\WINDOWS\system\MUMIXMGR.DLL
C:\WINDOWS\system\MUMIXMGR.DLL
C:\WINDOWS\system\mWpi32x.dll
C:\WINDOWS\system\mWpi32x.dll
C:\WINDOWS\system\mWpi32x.dll
C:\WINDOWS\system\mWpi32x.dll
C:\WINDOWS\system\mypatcha.dll
C:\WINDOWS\system\mypatcha.dll
C:\WINDOWS\system\mypatcha.dll
C:\WINDOWS\system\mypatcha.dll
C:\WINDOWS\system\NHONN32.DLL
C:\WINDOWS\system\NHONN32.DLL
C:\WINDOWS\system\NHONN32.DLL
C:\WINDOWS\system\NHONN32.DLL
C:\WINDOWS\system\NRTOS.DLL
C:\WINDOWS\system\NRTOS.DLL
C:\WINDOWS\system\OFFIL400.DLL
C:\WINDOWS\system\OFFIL400.DLL
C:\WINDOWS\system\OFFIL400.DLL
C:\WINDOWS\system\OFFIL400.DLL
C:\WINDOWS\system\ONSLB400.DLL
C:\WINDOWS\system\ONSLB400.DLL
C:\WINDOWS\system\ONSLB400.DLL
C:\WINDOWS\system\ONSLB400.DLL
C:\WINDOWS\system\OOESVR.DLL
C:\WINDOWS\system\OOESVR.DLL
C:\WINDOWS\system\OOESVR.DLL
C:\WINDOWS\system\OOESVR.DLL
C:\WINDOWS\system\OPEXL32.DLL
C:\WINDOWS\system\OPEXL32.DLL
C:\WINDOWS\system\OPEXL32.DLL
C:\WINDOWS\system\OPEXL32.DLL
C:\WINDOWS\system\OSETHK32.DLL
C:\WINDOWS\system\OSETHK32.DLL
C:\WINDOWS\system\OSETHK32.DLL
C:\WINDOWS\system\OSETHK32.DLL
C:\WINDOWS\system\OWENGL32.DLL
C:\WINDOWS\system\OWENGL32.DLL
C:\WINDOWS\system\OWENGL32.DLL
C:\WINDOWS\system\OWENGL32.DLL
C:\WINDOWS\system\oybccu32.dll
C:\WINDOWS\system\oybccu32.dll
C:\WINDOWS\system\oybccu32.dll
C:\WINDOWS\system\oybccu32.dll
C:\WINDOWS\system\PDPD.DLL
C:\WINDOWS\system\PDPD.DLL
C:\WINDOWS\system\PDPD.DLL
C:\WINDOWS\system\PDPD.DLL
C:\WINDOWS\system\PEWRPROF.DLL
C:\WINDOWS\system\PEWRPROF.DLL
C:\WINDOWS\system\PEWRPROF.DLL
C:\WINDOWS\system\PEWRPROF.DLL
C:\WINDOWS\system\PUSPL.DLL
C:\WINDOWS\system\PUSPL.DLL
C:\WINDOWS\system\PUSPL.DLL
C:\WINDOWS\system\PUSPL.DLL
C:\WINDOWS\system\QCV.DLL
C:\WINDOWS\system\QCV.DLL
C:\WINDOWS\system\QCV.DLL
C:\WINDOWS\system\QCV.DLL
C:\WINDOWS\system\QGVD.DLL
C:\WINDOWS\system\QGVD.DLL
C:\WINDOWS\system\QGVD.DLL
C:\WINDOWS\system\QGVD.DLL
C:\WINDOWS\system\QLV.DLL
C:\WINDOWS\system\QLV.DLL
C:\WINDOWS\system\QLV.DLL
C:\WINDOWS\system\QLV.DLL
C:\WINDOWS\system\QOV.DLL
C:\WINDOWS\system\QOV.DLL
C:\WINDOWS\system\QOV.DLL
C:\WINDOWS\system\QOV.DLL
C:\WINDOWS\system\QXDIT.DLL
C:\WINDOWS\system\QXDIT.DLL
C:\WINDOWS\system\QXDIT.DLL
C:\WINDOWS\system\QXDIT.DLL
C:\WINDOWS\system\RECMQSVR.DLL
C:\WINDOWS\system\RECMQSVR.DLL
C:\WINDOWS\system\RECMQSVR.DLL
C:\WINDOWS\system\RECMQSVR.DLL
C:\WINDOWS\system\RECRES.dll
C:\WINDOWS\system\RECRES.dll
C:\WINDOWS\system\RECRES.dll
C:\WINDOWS\system\RECRES.dll
C:\WINDOWS\system\RLSTORRC.DLL
C:\WINDOWS\system\RLSTORRC.DLL
C:\WINDOWS\system\RLSTORRC.DLL
C:\WINDOWS\system\RLSTORRC.DLL
C:\WINDOWS\system\RMAPH.DLL
C:\WINDOWS\system\RMAPH.DLL
C:\WINDOWS\system\RMAPH.DLL
C:\WINDOWS\system\RMAPH.DLL
C:\WINDOWS\system\RPAPH.DLL
C:\WINDOWS\system\RPAPH.DLL
C:\WINDOWS\system\RPAPH.DLL
C:\WINDOWS\system\RPAPH.DLL
C:\WINDOWS\system\RYABASE.DLL
C:\WINDOWS\system\RYABASE.DLL
C:\WINDOWS\system\RYABASE.DLL
C:\WINDOWS\system\RYABASE.DLL
C:\WINDOWS\system\SASCLASS.DLL
C:\WINDOWS\system\SASCLASS.DLL
C:\WINDOWS\system\SASCLASS.DLL
C:\WINDOWS\system\SASCLASS.DLL
C:\WINDOWS\system\SBDOCLC.DLL
C:\WINDOWS\system\SBDOCLC.DLL
C:\WINDOWS\system\SCRIALUI.DLL
C:\WINDOWS\system\SCRIALUI.DLL
C:\WINDOWS\system\SCRIALUI.DLL
C:\WINDOWS\system\SCRIALUI.DLL
C:\WINDOWS\system\SE_8M.DLL
C:\WINDOWS\system\SE_8M.DLL
C:\WINDOWS\system\SFI.DLL
C:\WINDOWS\system\SFI.DLL
C:\WINDOWS\system\SFI.DLL
C:\WINDOWS\system\SFI.DLL
C:\WINDOWS\system\SIHAV.DLL
C:\WINDOWS\system\SII.DLL
C:\WINDOWS\system\SII.DLL
C:\WINDOWS\system\SPDOCVW.DLL
C:\WINDOWS\system\SPDOCVW.DLL
C:\WINDOWS\system\SPDOCVW.DLL
C:\WINDOWS\system\SPDOCVW.DLL
C:\WINDOWS\system\SSHAV.DLL
C:\WINDOWS\system\SSHAV.DLL
C:\WINDOWS\system\SSHAV.DLL
C:\WINDOWS\system\SSHAV.DLL
C:\WINDOWS\system\SSRIALUI.DLL
C:\WINDOWS\system\SSRIALUI.DLL
C:\WINDOWS\system\SSRIALUI.DLL
C:\WINDOWS\system\SSRIALUI.DLL
C:\WINDOWS\system\SXRIALUI.DLL
C:\WINDOWS\system\SXRIALUI.DLL
C:\WINDOWS\system\TCPI.DLL
C:\WINDOWS\system\TCPI.DLL
C:\WINDOWS\system\TCPI.DLL
C:\WINDOWS\system\TCPI.DLL
C:\WINDOWS\system\THOLHELP.DLL
C:\WINDOWS\system\THOLHELP.DLL
C:\WINDOWS\system\THOLHELP.DLL
C:\WINDOWS\system\THOLHELP.DLL
C:\WINDOWS\system\tQembed.dll
C:\WINDOWS\system\tQembed.dll
C:\WINDOWS\system\tQembed.dll
C:\WINDOWS\system\tQembed.dll
C:\WINDOWS\system\UAP10.DLL
C:\WINDOWS\system\UAP10.DLL
C:\WINDOWS\system\UAP10.DLL
C:\WINDOWS\system\UAP10.DLL
C:\WINDOWS\system\UBBUI.DLL
C:\WINDOWS\system\UBBUI.DLL
C:\WINDOWS\system\UBBUI.DLL
C:\WINDOWS\system\UBBUI.DLL
C:\WINDOWS\system\UBL.DLL
C:\WINDOWS\system\VHWWDM32.DLL
C:\WINDOWS\system\VHWWDM32.DLL
C:\WINDOWS\system\VHWWDM32.DLL
C:\WINDOWS\system\VHWWDM32.DLL
C:\WINDOWS\system\VIODCTL.DLL
C:\WINDOWS\system\VIODCTL.DLL
C:\WINDOWS\system\VIODCTL.DLL
C:\WINDOWS\system\VIODCTL.DLL
C:\WINDOWS\system\VKWWDM32.DLL
C:\WINDOWS\system\VKWWDM32.DLL
C:\WINDOWS\system\VKWWDM32.DLL
C:\WINDOWS\system\VKWWDM32.DLL
C:\WINDOWS\system\VVRSION.DLL
C:\WINDOWS\system\VVRSION.DLL
C:\WINDOWS\system\VVRSION.DLL
C:\WINDOWS\system\VVRSION.DLL
C:\WINDOWS\system\WDCTHUNK.DLL
C:\WINDOWS\system\WDCTHUNK.DLL
C:\WINDOWS\system\WDCTHUNK.DLL
C:\WINDOWS\system\WDCTHUNK.DLL
C:\WINDOWS\system\wgpcore.dll
C:\WINDOWS\system\wgpcore.dll
C:\WINDOWS\system\wgpcore.dll
C:\WINDOWS\system\wgpcore.dll
C:\WINDOWS\system\WJADMOD.DLL
C:\WINDOWS\system\WJADMOD.DLL
C:\WINDOWS\system\WJADMOD.DLL
C:\WINDOWS\system\WJADMOD.DLL
C:\WINDOWS\system\WJW32.DLL
C:\WINDOWS\system\WJW32.DLL
C:\WINDOWS\system\WJW32.DLL
C:\WINDOWS\system\WJW32.DLL
C:\WINDOWS\system\wkp.dll
C:\WINDOWS\system\wkp.dll
C:\WINDOWS\system\wkp.dll
C:\WINDOWS\system\wkp.dll
C:\WINDOWS\system\WKW32.DLL
C:\WINDOWS\system\WKW32.DLL
C:\WINDOWS\system\WKW32.DLL
C:\WINDOWS\system\WKW32.DLL
C:\WINDOWS\system\WPASCR.DLL
C:\WINDOWS\system\WPASCR.DLL
C:\WINDOWS\system\WPASCR.DLL
C:\WINDOWS\system\WPASCR.DLL
C:\WINDOWS\system\WPICORE.DLL
C:\WINDOWS\system\WPICORE.DLL
C:\WINDOWS\system\WPICORE.DLL
C:\WINDOWS\system\WPICORE.DLL
C:\WINDOWS\system\WTADMOD.DLL
C:\WINDOWS\system\WTADMOD.DLL
C:\WINDOWS\system\WX5INF32.DLL
C:\WINDOWS\system\WX5INF32.DLL
C:\WINDOWS\system\WX5INF32.DLL
C:\WINDOWS\system\WX5INF32.DLL
C:\WINDOWS\system\WY2THK.DLL
C:\WINDOWS\system\WY2THK.DLL
C:\WINDOWS\system\WY2THK.DLL
C:\WINDOWS\system\WY2THK.DLL
C:\WINDOWS\system\WYASCR.DLL
C:\WINDOWS\system\xjoice.dll
C:\WINDOWS\system\xjoice.dll
C:\WINDOWS\system\xjoice.dll
C:\WINDOWS\system\xjoice.dll
C:\WINDOWS\system\zmib.dll
C:\WINDOWS\system\zmib.dll
C:\WINDOWS\system\ZQORT4AS.dll
C:\WINDOWS\system\ZQORT4AS.dll
C:\WINDOWS\system\ZQORT4AS.dll
C:\WINDOWS\system\ZQORT4AS.dll
************
Registry entries found:
[HKEY_CLASSES_ROOT\CLSID\{8DABE793-23D9-45DF-A3DB-F442883BB479}\InprocServer32]
@="C:\\WINDOWS\\SYSTEM\\WBEM\\NET.DLL"
--
[HKEY_CLASSES_ROOT\CLSID\{4CB3ACD0-B2D8-11D3-8791-005004A8FC4D}\InprocServer32]
@="C:\\PROGRAM FILES\\COMMON FILES\\ADAPTEC SHARED\\CREATORAPI\\JOLIET.DLL"
--
[HKEY_CLASSES_ROOT\CLSID\{743F1DC6-5ABA-429F-8BDF-C54D03253DC2}\InProcServer32]
@="dpnet.dll"
--
[HKEY_CLASSES_ROOT\CLSID\{DA825E1B-6830-43D7-835D-0B5AD82956A2}\InProcServer32]
@="dpnet.dll"
--
[HKEY_CLASSES_ROOT\CLSID\{286F484D-375E-4458-A272-B138E2F80A6A}\InProcServer32]
@="dpnet.dll"
[HKEY_CLASSES_ROOT\CLSID\{8DABE793-23D9-45DF-A3DB-F442883BB479}\InprocServer32]
@="C:\\WINDOWS\\SYSTEM\\WBEM\\NET.DLL"
--
[HKEY_CLASSES_ROOT\CLSID\{4CB3ACD0-B2D8-11D3-8791-005004A8FC4D}\InprocServer32]
@="C:\\PROGRAM FILES\\COMMON FILES\\ADAPTEC SHARED\\CREATORAPI\\JOLIET.DLL"
--
[HKEY_CLASSES_ROOT\CLSID\{743F1DC6-5ABA-429F-8BDF-C54D03253DC2}\InProcServer32]
@="dpnet.dll"
--
[HKEY_CLASSES_ROOT\CLSID\{DA825E1B-6830-43D7-835D-0B5AD82956A2}\InProcServer32]
@="dpnet.dll"
--
[HKEY_CLASSES_ROOT\CLSID\{286F484D-375E-4458-A272-B138E2F80A6A}\InProcServer32]
@="dpnet.dll"
[HKEY_CLASSES_ROOT\CLSID\{8DABE793-23D9-45DF-A3DB-F442883BB479}\InprocServer32]
@="C:\\WINDOWS\\SYSTEM\\WBEM\\NET.DLL"
--
[HKEY_CLASSES_ROOT\CLSID\{4CB3ACD0-B2D8-11D3-8791-005004A8FC4D}\InprocServer32]
@="C:\\PROGRAM FILES\\COMMON FILES\\ADAPTEC SHARED\\CREATORAPI\\JOLIET.DLL"
--
[HKEY_CLASSES_ROOT\CLSID\{743F1DC6-5ABA-429F-8BDF-C54D03253DC2}\InProcServer32]
@="dpnet.dll"
--
[HKEY_CLASSES_ROOT\CLSID\{DA825E1B-6830-43D7-835D-0B5AD82956A2}\InProcServer32]
@="dpnet.dll"
--
[HKEY_CLASSES_ROOT\CLSID\{286F484D-375E-4458-A272-B138E2F80A6A}\InProcServer32]
@="dpnet.dll"
[HKEY_CLASSES_ROOT\CLSID\{8DABE793-23D9-45DF-A3DB-F442883BB479}\InprocServer32]
@="C:\\WINDOWS\\SYSTEM\\WBEM\\NET.DLL"
--
[HKEY_CLASSES_ROOT\CLSID\{4CB3ACD0-B2D8-11D3-8791-005004A8FC4D}\InprocServer32]
@="C:\\PROGRAM FILES\\COMMON FILES\\ADAPTEC SHARED\\CREATORAPI\\JOLIET.DLL"
--
[HKEY_CLASSES_ROOT\CLSID\{743F1DC6-5ABA-429F-8BDF-C54D03253DC2}\InProcServer32]
@="dpnet.dll"
--
[HKEY_CLASSES_ROOT\CLSID\{DA825E1B-6830-43D7-835D-0B5AD82956A2}\InProcServer32]
@="dpnet.dll"
--
[HKEY_CLASSES_ROOT\CLSID\{286F484D-375E-4458-A272-B138E2F80A6A}\InProcServer32]
@="dpnet.dll"
[HKEY_CLASSES_ROOT\CLSID\{51A0A4C2-7361-4B80-85EB-96B8718AFBCE}\InprocServer32]
@="C:\\WINDOWS\\SYSTEM\\MBCPXL32.DLL"
[HKEY_CLASSES_ROOT\CLSID\{51A0A4C2-7361-4B80-85EB-96B8718AFBCE}\InprocServer32]
@="C:\\WINDOWS\\SYSTEM\\MBCPXL32.DLL"
[HKEY_CLASSES_ROOT\CLSID\{51A0A4C2-7361-4B80-85EB-96B8718AFBCE}\InprocServer32]
@="C:\\WINDOWS\\SYSTEM\\MBCPXL32.DLL"
[HKEY_CLASSES_ROOT\CLSID\{51A0A4C2-7361-4B80-85EB-96B8718AFBCE}\InprocServer32]
@="C:\\WINDOWS\\SYSTEM\\MBCPXL32.DLL"
************
Killing Explorer
Done!
Killing Rundll32
Done!
Removing malicious CLSID(s)
Done!
Restarting Explorer
Done!
Deleting malicious files
Done!
Finished!
WinPFindWARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.
If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.
»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Windows Millennium Edition Version: 4.90.3000
Internet Explorer Version: 6.0.2800.1106
»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»
Checking %SystemDrive% folder...
UPX! 8/10/2005 8:29:08 PM 25105 C:\MTE2NzY6ODoxNg.exe
Checking %ProgramFilesDir% folder...
Checking %WinDir% folder...
qoologic 8/11/2005 10:34:48 AM 1421344 C:\WINDOWS\USER.DAT
KavSvc 8/11/2005 10:34:48 AM 2129952 C:\WINDOWS\SYSTEM.DAT
winsync 8/11/2005 10:34:48 AM 2129952 C:\WINDOWS\SYSTEM.DAT
PECompact2 6/14/2005 10:06:00 AM 15162837 C:\WINDOWS\VPTNFILE.685
qoologic 6/14/2005 10:06:00 AM 15162837 C:\WINDOWS\VPTNFILE.685
SAHAgent 6/14/2005 10:06:00 AM 15162837 C:\WINDOWS\VPTNFILE.685
UPX! 8/10/2005 3:43:24 PM 82432 C:\WINDOWS\ru.exe
Items found in C:\WINDOWS\hosts
KavSvc 8/3/2005 4:27:30 AM 34816 C:\WINDOWS\rkunyyn.dll
69.59.186.63 8/3/2005 4:27:30 AM 34816 C:\WINDOWS\rkunyyn.dll
209.66.67.134 8/3/2005 4:27:30 AM 34816 C:\WINDOWS\rkunyyn.dll
testpopup 8/3/2005 4:27:30 AM 34816 C:\WINDOWS\rkunyyn.dll
web-nex 8/3/2005 4:27:30 AM 34816 C:\WINDOWS\rkunyyn.dll
yourkey 8/3/2005 4:27:30 AM 34816 C:\WINDOWS\rkunyyn.dll
aspack 7/4/2005 12:29:26 PM 535040 C:\WINDOWS\flashax.exe
web-nex 8/11/2005 10:30:16 AM 38003 C:\WINDOWS\jnkmr.dll
qoologic 7/31/2005 10:39:32 PM 2627 C:\WINDOWS\hostsagb
urllogic 7/31/2005 10:39:32 PM 2627 C:\WINDOWS\hostsagb
urllogic 7/31/2005 10:39:32 PM 2627 C:\WINDOWS\hostsagb
UPX! 6/14/2005 10:06:02 AM 1044560 C:\WINDOWS\vsapi32.dll
aspack 6/14/2005 10:06:02 AM 1044560 C:\WINDOWS\vsapi32.dll
UPX! 6/14/2005 10:06:04 AM 170053 C:\WINDOWS\tsc.exe
KavSvc 8/3/2005 4:27:30 AM 16384 C:\WINDOWS\uknig.dll
69.59.186.63 8/3/2005 4:27:30 AM 16384 C:\WINDOWS\uknig.dll
209.66.67.134 8/3/2005 4:27:30 AM 16384 C:\WINDOWS\uknig.dll
web-nex 8/3/2005 4:27:30 AM 16384 C:\WINDOWS\uknig.dll
yourkey 8/3/2005 4:27:30 AM 16384 C:\WINDOWS\uknig.dll
Checking %System% folder...
aspack 8/10/2005 4:20:02 PM 29184 C:\WINDOWS\SYSTEM\supdate.dll
KavSvc 8/10/2005 4:20:02 PM 29184 C:\WINDOWS\SYSTEM\supdate.dll
69.59.186.63 8/10/2005 4:20:02 PM 29184 C:\WINDOWS\SYSTEM\supdate.dll
209.66.67.134 8/10/2005 4:20:02 PM 29184 C:\WINDOWS\SYSTEM\supdate.dll
66.63.167.97 8/10/2005 4:20:02 PM 29184 C:\WINDOWS\SYSTEM\supdate.dll
66.63.167.77 8/10/2005 4:20:02 PM 29184 C:\WINDOWS\SYSTEM\supdate.dll
web-nex 8/10/2005 4:20:02 PM 29184 C:\WINDOWS\SYSTEM\supdate.dll
yourkey 8/10/2005 4:20:02 PM 29184 C:\WINDOWS\SYSTEM\supdate.dll
rec2_run 8/10/2005 4:20:02 PM 29184 C:\WINDOWS\SYSTEM\supdate.dll
FSG! 8/19/2001 6:30:46 AM 11593 C:\WINDOWS\SYSTEM\temperror32.dat
SAHAgent 6/16/2005 2:28:14 PM 3523 C:\WINDOWS\SYSTEM\4d7cfuso.ini
69.59.186.63 8/11/2005 10:11:30 AM 29184 C:\WINDOWS\SYSTEM\datadx.dll
209.66.67.134 8/11/2005 10:11:30 AM 29184 C:\WINDOWS\SYSTEM\datadx.dll
66.63.167.97 8/11/2005 10:11:30 AM 29184 C:\WINDOWS\SYSTEM\datadx.dll
66.63.167.77 8/11/2005 10:11:30 AM 29184 C:\WINDOWS\SYSTEM\datadx.dll
web-nex 8/11/2005 10:11:30 AM 29184 C:\WINDOWS\SYSTEM\datadx.dll
winsync 8/11/2005 10:11:30 AM 29184 C:\WINDOWS\SYSTEM\datadx.dll
rec2_run 8/11/2005 10:11:30 AM 29184 C:\WINDOWS\SYSTEM\datadx.dll
SAHAgent 6/14/2005 3:34:14 PM 203264 C:\WINDOWS\SYSTEM\4d7cfuso.exe
SAHAgent 6/16/2005 2:16:46 PM 35 C:\WINDOWS\SYSTEM\1pr8lv29.ini
Checking %System%\Drivers folder and sub-folders...
Checking the Windows folder for system and hidden files within the last 60 days...
8/11/2005 10:36:08 AM 1421344 C:\WINDOWS\USER.DAT
8/11/2005 10:34:28 AM 3784736 C:\WINDOWS\CLASSES.DAT
8/11/2005 10:34:48 AM 2129952 C:\WINDOWS\SYSTEM.DAT
8/10/2005 3:43:24 PM 82432 C:\WINDOWS\ru.exe
8/11/2005 10:05:02 AM 3864 C:\WINDOWS\ttfCache
8/11/2005 10:28:44 AM 376764 C:\WINDOWS\ShellIconCache
7/4/2005 12:12:18 AM 4212 C:\WINDOWS\SYSTEM\zllictbl.dat
7/25/2005 12:34:30 PM 5852 C:\WINDOWS\SYSTEM\KGyGaAvL.sys
7/25/2005 12:34:18 PM 104 C:\WINDOWS\SYSTEM\04E9A3F359.sys
8/11/2005 10:35:48 AM 2840 C:\WINDOWS\PCHEALTH\HELPCTR\Database\HelpSessionHistory.stream
8/10/2005 3:43:24 PM 6 C:\WINDOWS\TASKS\SA.DAT
8/11/2005 10:35:26 AM 2702 C:\WINDOWS\Application Data\Microsoft\Internet Explorer\Desktop.htt
8/11/2005 10:31:34 AM 67 C:\WINDOWS\Temporary Internet Files\desktop.ini
8/11/2005 10:31:34 AM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\desktop.ini
8/11/2005 10:35:28 AM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\01234567\desktop.ini
8/11/2005 10:35:28 AM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\8LANIP8R\desktop.ini
8/11/2005 10:35:28 AM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\V11YF6KU\desktop.ini
8/11/2005 10:35:28 AM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\F7HIJTLD\desktop.ini
»»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»
Checking files in %ALLUSERSPROFILE%\Startup folder...
Checking files in %ALLUSERSPROFILE%\Application Data folder...
Checking files in %USERPROFILE%\Startup folder...
8/3/2005 4:27:30 AM 81920 C:\WINDOWS\Start Menu\Programs\StartUp\natr.exe
Checking files in %USERPROFILE%\Application Data folder...
7/27/2005 10:20:52 PM 15036 C:\WINDOWS\Application Data\dw.log
5/26/2005 2:56:40 PM 8568 C:\WINDOWS\Application Data\GDIPFONTCACHEV1.DAT
»»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»»
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
{FEF10FA2-355E-4e06-9381-9B24D7F7CC88} = C:\WINDOWS\SYSTEM\SHELL32.DLL
{53C74826-AB99-4d33-ACA4-3117F51D3788} = C:\WINDOWS\SYSTEM\SHELL32.DLL
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
[HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
{09799AFB-AD67-11d1-ABCD-00C04FC30936} = C:\WINDOWS\SYSTEM\SHELL32.DLL
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Yahoo! Mail
{5464D816-CF16-4784-B9F3-75C0DB52B499} = C:\PROGRAM FILES\YAHOO!\COMMON\YMMAPI.DLL
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\LDVPMenu
{BDA77241-42F6-11d0-85E2-00AA001FE28C} = C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SSC\VPSHELL2.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\LDVPMenu
{BDA77241-42F6-11d0-85E2-00AA001FE28C} = C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SSC\VPSHELL2.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
<<< WARNING! - NOT A VALID WIN98 KEY! (ME is Ok) >>>
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
= C:\WINDOWS\SYSTEM\SHELL32.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
= C:\WINDOWS\SYSTEM\SHELL32.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
= C:\WINDOWS\SYSTEM\SHELL32.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{7ab770c7-0e23-4d7a-8aa2-19bfad479829}
= C:\WINDOWS\SYSTEM\SHELL32.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{884EA37B-37C0-11d2-BE3F-00A0C9A83DA1}
= C:\WINDOWS\SYSTEM\DOCPROP2.DLL
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A36E75F-112B-4FBF-A497-73CEEF29380A}
SDWin32 Class = C:\WINDOWS\SYSTEM\BPQKS.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
&Tip of the Day = C:\WINDOWS\SYSTEM\SHDOCVW.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4528BBE0-4E08-11D5-AD55-00010333D0AD}
=
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{50B4D2B3-723F-41B3-AEC4-0BD66F0F45FF}
Web Offer Bar = C:\WINDOWS\SYSTEM\shdocvw.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{A166C1B0-5CDB-447A-894A-4B9FD7149D51}
Web Offer Bar = C:\WINDOWS\SYSTEM\shdocvw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45}
ButtonText = AIM : C:\PROGRAM FILES\AIM\AIM.EXE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping
MenuText = :
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478}
Media Band = C:\WINDOWS\SYSTEM\BROWSEUI.DLL
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{4528BBE0-4E08-11D5-AD55-00010333D0AD}
=
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}
File and Folders Search ActiveX Control = C:\WINDOWS\SYSTEM\SHELL32.DLL
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E61-B078-11D0-89E4-00C04FC9E26E}
Favorites Band = C:\WINDOWS\SYSTEM\SHDOCVW.DLL
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{7BED0340-176B-44BC-915E-C21C1DD6F617}
=
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E62-B078-11D0-89E4-00C04FC9E26E}
History Band = C:\WINDOWS\SYSTEM\SHDOCVW.DLL
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : C:\WINDOWS\SYSTEM\BROWSEUI.DLL
{2D51D869-C36B-42BD-AE68-0A81BC771FA5} = :
{7BED0340-176B-44BC-915E-C21C1DD6F617} = :
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : C:\WINDOWS\SYSTEM\BROWSEUI.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
vptray C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
ScanRegistry C:\WINDOWS\scanregw.exe /autorun
FlashClean C:\PROGRAM FILES\FLASHCLEAN\FlashClean.exe %1
KavSvc C:\WINDOWS\ramhll.exe reg_run
autoupdate rundll32 C:\WINDOWS\SYSTEM\DATADX.DLL,SHStart
Command C:\WINDOWS\cmd\command.exe
bpqksc C:\WINDOWS\SYSTEM\bpqksc.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
*StateMgr C:\WINDOWS\System\Restore\StateMgr.exe
rtvscn95 C:\PROGRA~1\SYMANT~1\SYMANT~1\rtvscn95.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
ccleaner "C:\PROGRAM FILES\CCLEANER\CCLEANER.exe" /AUTO
eZmmod C:\PROGRA~1\ezula\mmod.exe
eZWO C:\PROGRA~1\Web Offer\wo.exe
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WinOldApp
NoRealMode 1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Network
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} = C:\PROGRA~1\COMMON~1\MICROS~1\Web Folders\MSONSEXT.DLL
{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} =
{0DF44EAA-FF21-4412-828E-260A8728E7F1} =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
DisableLocalMachineRun 0
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoDriveTypeAutoRun •
CDRAutoRun
DisableLocalUserRun 0
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
MSERAT C:\WINDOWS\SYSTEM\MSERAT.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = C:\WINDOWS\SYSTEM\WEBCHECK.DLL
AUHook {BCBCD383-3E06-11D3-91A9-00C04F68105C} = C:\WINDOWS\SYSTEM\AUHOOK.DLL
<<< WARNING! - NOT A VALID WIN98
*admin KEY! >>>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit =
Shell = Explorer.exe
System =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
<<< WARNING! - NOT A VALID WIN98
*admin KEY! >>>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
AppInit_DLLs
»»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
WinPFind v1.2.9 - Log file written to "WinPFind.Txt" in the WinPFind folder.
Scan completed on 8/11/2005 10:39:02 AM
Track qoo.vbsREGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vptray"="C:\\PROGRA~1\\SYMANT~1\\SYMANT~1\\vptray.exe"
"ScanRegistry"="C:\\WINDOWS\\scanregw.exe /autorun"
"FlashClean"="C:\\PROGRAM FILES\\FLASHCLEAN\\FlashClean.exe %1"
"KavSvc"="C:\\WINDOWS\\ramhll.exe reg_run"
"autoupdate"="rundll32 C:\\WINDOWS\\SYSTEM\\DATADX.DLL,SHStart"
"Command"="C:\\WINDOWS\\cmd\\command.exe"
"bpqksc"="C:\\WINDOWS\\SYSTEM\\bpqksc.exe"
-----------------
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers
Subkey --- Open With
{09799AFB-AD67-11d1-ABCD-00C04FC30936}
C:\WINDOWS\SYSTEM\SHELL32.DLL
Subkey --- Yahoo! Mail
{5464D816-CF16-4784-B9F3-75C0DB52B499}
C:\PROGRAM FILES\YAHOO!\COMMON\YMMAPI.DLL
Subkey --- WinZip
{E0D79304-84BE-11CE-9641-444553540000}
C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
Subkey --- LDVPMenu
{BDA77241-42F6-11d0-85E2-00AA001FE28C}
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SSC\VPSHELL2.DLL
=====================
HKEY_CLASSES_ROOT\Folder\shellex\ColumnHandlers
Subkey --- {24F14F01-7B1C-11d1-838f-0000F80461CF}
C:\WINDOWS\SYSTEM\SHELL32.DLL
Subkey --- {24F14F02-7B1C-11d1-838f-0000F80461CF}
C:\WINDOWS\SYSTEM\SHELL32.DLL
Subkey --- {0D2E74C4-3C34-11d2-A27E-00C04FC30871}
C:\WINDOWS\SYSTEM\SHELL32.DLL
Subkey --- {7ab770c7-0e23-4d7a-8aa2-19bfad479829}
C:\WINDOWS\SYSTEM\SHELL32.DLL
Subkey --- {884EA37B-37C0-11d2-BE3F-00A0C9A83DA1}
C:\WINDOWS\SYSTEM\DOCPROP2.DLL
==============================
C:\WINDOWS\All Users\Start Menu\Programs\StartUp
==============================
C:\WINDOWS\Start Menu\Programs\StartUp
natr.exe
==============================
C:\WINDOWS\SYSTEM cpl files
INETCPL.CPL Microsoft Corporation
INTL.CPL Microsoft Corporation
MODEM.CPL Microsoft Corporation
POWERCFG.CPL Microsoft Corporation
APPWIZ.CPL Microsoft Corporation
DESK.CPL Microsoft Corporation
MAIN.CPL Microsoft Corporation
MMSYS.CPL Microsoft Corporation
NETCPL.CPL Microsoft Corporation
PASSWORD.CPL Microsoft Corporation
SYSDM.CPL Microsoft Corporation
TELEPHON.CPL Microsoft Corporation
TIMEDATE.CPL Microsoft Corporation
WUAUCPL.CPL Microsoft Corporation
ACCESS.CPL Microsoft Corporation
CMICNFG.CPL C-Media Corporation
JOY.CPL Microsoft Corporation
jpicpl32.cpl Sun Microsystems, Inc.
odbccp32.cpl Microsoft Corporation
conres.cpl