Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Flash Ads


  • Please log in to reply

#1
hunner107

hunner107

    Member

  • Member
  • PipPip
  • 11 posts
I need a program to stop all these ads made in flashplayer to bypass my firewall. Normally they're easy to close but in online games I have to get out of the game then close them, usually resulting in me losing/dying. I've tried Spybot, Adaware, ZoneAlarm, and even reconfigured firefox to stop these annoying ads.
Also, sometimes when i go to a webpage it will redirect me to an ad page.
Any help would be greatly appreciated.

Logfile of HijackThis v1.99.1
Scan saved at 8:32:45 PM, on 9/14/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUMENTS AND SETTINGS\EMILY HALLMARK\DESKTOP\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us.f808.mail....d=8pcik2b67pvie
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - http://files.member....s/sbc/yinst.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1101957437843
O16 - DPF: {C4DD6732-1E82-4AE7-BD94-180331B84082} (DeltaCVX Control) - http://www.mathxl.co...ts/deltacvx.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo....plorer1_9us.cab
O20 - Winlogon Notify: Run - C:\WINDOWS\system32\lvp2097oe.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE

Edited by hunner107, 14 September 2005 - 07:35 PM.

  • 0

Advertisements


#2
tampabelle

tampabelle

    Member 5k

  • Retired Staff
  • 6,363 posts
We'll need you to use a free diagnostic tool, Hijack This. Follow the instructions in step five of this guide, and reply here with your log.

Most of what Hijack This lists lists will be harmless or even essential, DO NOT delete or modify anything yet! Someone will be along to tell you what steps to take after you post the contents of the scan results.

Edited by tampabelle, 14 September 2005 - 06:21 PM.

  • 0

#3
tampabelle

tampabelle

    Member 5k

  • Retired Staff
  • 6,363 posts
Hi,

I saw your post in the 3 Days no reply topic.

You posted your log by editing the previous post.

If you edit your posts, then I get no notification of it. I cant know that you have posted something new in the topic.

Always post new stuff - comments, info, questions or logs - as new reply but in the same topic.

Since it has been quite some time wince you last posted your log, please post a fresh Hijack This log in this topic only by using the "Add Reply". I will take it up immediately.
  • 0

#4
hunner107

hunner107

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Thank you for helping me. Here is the fresh log.

Logfile of HijackThis v1.99.1
Scan saved at 10:26:26 AM, on 9/23/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\PrvDef3.0\PrvDef3.0.exe
C:\Program Files\AIM95\aim.exe
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SAdBlock.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Hijack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us.f808.mail....d=8pcik2b67pvie
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [PrvDef3.0] C:\Program Files\PrvDef3.0\PrvDef3.0.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell....iler/SysPro.CAB
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - http://files.member....s/sbc/yinst.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1101957437843
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1126905242937
O16 - DPF: {C4DD6732-1E82-4AE7-BD94-180331B84082} (DeltaCVX Control) - http://www.mathxl.co...ts/deltacvx.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo....plorer1_9us.cab
O20 - Winlogon Notify: SMDEn - C:\WINDOWS\system32\dbquery.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: CWShredder Service - Trend Micro Incorporated - C:\DOCUMENTS AND SETTINGS\EMILY HALLMARK\DESKTOP\CWShredder.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE
  • 0

#5
tampabelle

tampabelle

    Member 5k

  • Retired Staff
  • 6,363 posts
Download L2mfix from one of these two locations:

http://www.atribune....oads/l2mfix.exe
http://www.downloads....org/l2mfix.exe

Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!
  • 0

#6
hunner107

hunner107

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Here's the l2mfix log.

L2MFIX find log 1.04a
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
"Asynchronous"=dword:00000000
"DllName"=""
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SMDEn]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\dbquery.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER


**********************************************************************************
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{78F45A78-1F42-E7E3-5CA1-6D2E8CDBC9A4}"=""

**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run..."
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People..."
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache"
"{955B7B84-5308-419c-8ED8-0B9CA3C56985}"="America Online"
"{5E44E225-A408-11CF-B581-008029601108}"="Adaptec DirectCD Shell Extension"
"{E0D79304-84BE-11CE-9641-444553540000}"="WinZip"
"{E0D79305-84BE-11CE-9641-444553540000}"="WinZip"
"{E0D79306-84BE-11CE-9641-444553540000}"="WinZip"
"{E0D79307-84BE-11CE-9641-444553540000}"="WinZip"
"{6E3C607A-B99C-4FA8-98F5-1AC1ADF7F5B9}"="MediaFace extension"
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{8FF88D21-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6b1 (beta test) Context Menu Shell Extension"
"{8FF88D25-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6b1 (beta test) DragDrop Shell Extension"
"{8FF88D27-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6b1 (beta test) Context Menu Shell Extension"
"{8FF88D23-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6b1 (beta test) Property Sheet Shell Extension"
"{2F860D81-AF3C-11D4-BDB3-00E0987D8540}"="UltimateZip Shell Extension"
"{2F860D82-AF3C-11D4-BDB3-00E0987D8540}"="UltimateZip Drag Drop Handler"
"{DF3A7FAD-F24C-46EE-B5A8-CD031FE738C6}"=""
"{7D4037F4-AAB3-4621-82B6-986E61218E87}"=""
"{B5CC3548-5DD1-4129-9A24-0C1E28B74B14}"=""
"{9A08FE74-D7B9-4F3E-94D6-08D0A87FDE92}"=""
"{F5EE2610-4141-43DE-84EF-555637F09D0A}"=""
"{B5CD3B45-3639-4CDD-8631-34AA5D087354}"=""
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
"{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
"{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
"{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
"{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
"{05AEF43B-1C2C-4469-9A44-6AFA3B5F2C94}"=""
"{4BE4F383-14B8-446E-822F-AA7B1A8CAB1F}"=""
"{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
"{DB43753E-D1F3-4F19-906F-FCE2F070C4EC}"=""
"{677B9E07-3CAC-4E4C-B16B-606CF897A654}"=""
"{85680D57-B66A-4041-B87E-771A55EBA089}"=""
"{8F1E39B0-6362-4C71-ADFB-FEDC1B9DDB3E}"=""
"{32A21CE4-BA69-42BF-BB84-AC7AF18CEB3A}"=""
"{57E5CB65-4D2A-4232-A360-D258F3A0CEED}"=""
"{02E980AC-830D-415A-8B14-D642D906DA0F}"=""
"{97050CDB-897D-4602-95A8-9085C42A92C7}"=""
"{1346A194-1096-44E7-BE93-56C8FA960183}"=""
"{6D7024ED-E85F-4354-80C5-9C060897B36D}"=""
"{5464D816-CF16-4784-B9F3-75C0DB52B499}"="Yahoo! Mail"
"{84216937-B698-4274-ACFC-4EED8B95DFBC}"=""
"{6914557E-71B6-4A55-BBDE-F4432F84626D}"=""
"{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"="AVG7 Shell Extension"
"{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}"="AVG7 Find Extension"
"{7B88F8B0-7260-4C58-8DD3-E0515DFE9E82}"=""
"{B4B3001E-0F56-4E51-8250-BDE11547EC55}"="Super Ad Blocker Toolbar"
"{9B975BB6-9C7A-4596-955F-BBAE3D784B40}"=""

**********************************************************************************
HKEY ROOT CLASSIDS:
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{DF3A7FAD-F24C-46EE-B5A8-CD031FE738C6}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{DF3A7FAD-F24C-46EE-B5A8-CD031FE738C6}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{DF3A7FAD-F24C-46EE-B5A8-CD031FE738C6}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{DF3A7FAD-F24C-46EE-B5A8-CD031FE738C6}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{7D4037F4-AAB3-4621-82B6-986E61218E87}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7D4037F4-AAB3-4621-82B6-986E61218E87}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7D4037F4-AAB3-4621-82B6-986E61218E87}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7D4037F4-AAB3-4621-82B6-986E61218E87}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{B5CC3548-5DD1-4129-9A24-0C1E28B74B14}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B5CC3548-5DD1-4129-9A24-0C1E28B74B14}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B5CC3548-5DD1-4129-9A24-0C1E28B74B14}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B5CC3548-5DD1-4129-9A24-0C1E28B74B14}\InprocServer32]
@="C:\\WINDOWS\\system32\\EQIUIE5A.DLL"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{9A08FE74-D7B9-4F3E-94D6-08D0A87FDE92}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9A08FE74-D7B9-4F3E-94D6-08D0A87FDE92}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9A08FE74-D7B9-4F3E-94D6-08D0A87FDE92}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9A08FE74-D7B9-4F3E-94D6-08D0A87FDE92}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{F5EE2610-4141-43DE-84EF-555637F09D0A}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{F5EE2610-4141-43DE-84EF-555637F09D0A}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{F5EE2610-4141-43DE-84EF-555637F09D0A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{F5EE2610-4141-43DE-84EF-555637F09D0A}\InprocServer32]
@="C:\\WINDOWS\\system32\\DNSKCOPY.DLL"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{B5CD3B45-3639-4CDD-8631-34AA5D087354}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B5CD3B45-3639-4CDD-8631-34AA5D087354}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B5CD3B45-3639-4CDD-8631-34AA5D087354}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B5CD3B45-3639-4CDD-8631-34AA5D087354}\InprocServer32]
@="C:\\WINDOWS\\system32\\AXKCTRS.DLL"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{05AEF43B-1C2C-4469-9A44-6AFA3B5F2C94}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{05AEF43B-1C2C-4469-9A44-6AFA3B5F2C94}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{05AEF43B-1C2C-4469-9A44-6AFA3B5F2C94}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{05AEF43B-1C2C-4469-9A44-6AFA3B5F2C94}\InprocServer32]
@="C:\\WINDOWS\\system32\\cwbcatex.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{4BE4F383-14B8-446E-822F-AA7B1A8CAB1F}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{4BE4F383-14B8-446E-822F-AA7B1A8CAB1F}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{4BE4F383-14B8-446E-822F-AA7B1A8CAB1F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{4BE4F383-14B8-446E-822F-AA7B1A8CAB1F}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{DB43753E-D1F3-4F19-906F-FCE2F070C4EC}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{DB43753E-D1F3-4F19-906F-FCE2F070C4EC}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{DB43753E-D1F3-4F19-906F-FCE2F070C4EC}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{DB43753E-D1F3-4F19-906F-FCE2F070C4EC}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{677B9E07-3CAC-4E4C-B16B-606CF897A654}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{677B9E07-3CAC-4E4C-B16B-606CF897A654}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{677B9E07-3CAC-4E4C-B16B-606CF897A654}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{677B9E07-3CAC-4E4C-B16B-606CF897A654}\InprocServer32]
@="C:\\WINDOWS\\system32\\nctapi32.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{85680D57-B66A-4041-B87E-771A55EBA089}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{85680D57-B66A-4041-B87E-771A55EBA089}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{85680D57-B66A-4041-B87E-771A55EBA089}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{85680D57-B66A-4041-B87E-771A55EBA089}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{8F1E39B0-6362-4C71-ADFB-FEDC1B9DDB3E}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8F1E39B0-6362-4C71-ADFB-FEDC1B9DDB3E}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8F1E39B0-6362-4C71-ADFB-FEDC1B9DDB3E}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8F1E39B0-6362-4C71-ADFB-FEDC1B9DDB3E}\InprocServer32]
@="C:\\WINDOWS\\system32\\COVFAT.DLL"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{32A21CE4-BA69-42BF-BB84-AC7AF18CEB3A}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{32A21CE4-BA69-42BF-BB84-AC7AF18CEB3A}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{32A21CE4-BA69-42BF-BB84-AC7AF18CEB3A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{32A21CE4-BA69-42BF-BB84-AC7AF18CEB3A}\InprocServer32]
@="C:\\WINDOWS\\system32\\UHRRTOSA.DLL"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{57E5CB65-4D2A-4232-A360-D258F3A0CEED}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{57E5CB65-4D2A-4232-A360-D258F3A0CEED}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{57E5CB65-4D2A-4232-A360-D258F3A0CEED}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{57E5CB65-4D2A-4232-A360-D258F3A0CEED}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{02E980AC-830D-415A-8B14-D642D906DA0F}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{02E980AC-830D-415A-8B14-D642D906DA0F}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{02E980AC-830D-415A-8B14-D642D906DA0F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{02E980AC-830D-415A-8B14-D642D906DA0F}\InprocServer32]
@="C:\\WINDOWS\\system32\\tyemeui.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{97050CDB-897D-4602-95A8-9085C42A92C7}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{97050CDB-897D-4602-95A8-9085C42A92C7}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{97050CDB-897D-4602-95A8-9085C42A92C7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{97050CDB-897D-4602-95A8-9085C42A92C7}\InprocServer32]
@="C:\\WINDOWS\\system32\\lzflc13n.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{1346A194-1096-44E7-BE93-56C8FA960183}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{1346A194-1096-44E7-BE93-56C8FA960183}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{1346A194-1096-44E7-BE93-56C8FA960183}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{1346A194-1096-44E7-BE93-56C8FA960183}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{6D7024ED-E85F-4354-80C5-9C060897B36D}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{6D7024ED-E85F-4354-80C5-9C060897B36D}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{6D7024ED-E85F-4354-80C5-9C060897B36D}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{6D7024ED-E85F-4354-80C5-9C060897B36D}\InprocServer32]
@="C:\\WINDOWS\\system32\\KADSL.DLL"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{84216937-B698-4274-ACFC-4EED8B95DFBC}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{84216937-B698-4274-ACFC-4EED8B95DFBC}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{84216937-B698-4274-ACFC-4EED8B95DFBC}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{84216937-B698-4274-ACFC-4EED8B95DFBC}\InprocServer32]
@="C:\\WINDOWS\\system32\\kld101a.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{6914557E-71B6-4A55-BBDE-F4432F84626D}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{6914557E-71B6-4A55-BBDE-F4432F84626D}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{6914557E-71B6-4A55-BBDE-F4432F84626D}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{6914557E-71B6-4A55-BBDE-F4432F84626D}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{7B88F8B0-7260-4C58-8DD3-E0515DFE9E82}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7B88F8B0-7260-4C58-8DD3-E0515DFE9E82}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7B88F8B0-7260-4C58-8DD3-E0515DFE9E82}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7B88F8B0-7260-4C58-8DD3-E0515DFE9E82}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{9B975BB6-9C7A-4596-955F-BBAE3D784B40}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9B975BB6-9C7A-4596-955F-BBAE3D784B40}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9B975BB6-9C7A-4596-955F-BBAE3D784B40}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9B975BB6-9C7A-4596-955F-BBAE3D784B40}\InprocServer32]
@="C:\\WINDOWS\\system32\\dbquery.dll"
"ThreadingModel"="Apartment"

**********************************************************************************
Files Found are not all bad files:

C:\WINDOWS\SYSTEM32\
atl71.dll Wed Jul 6 2005 5:17:28p A.... 89,088 87.00 K
browseui.dll Sat Jul 2 2005 9:11:28p A.... 1,019,904 996.00 K
cdfview.dll Sat Jul 2 2005 9:11:28p A.... 151,040 147.50 K
cjm.dll Wed Sep 21 2005 5:21:36p ..S.R 237,206 231.64 K
dbquery.dll Thu Sep 22 2005 11:30:20a ..S.R 237,206 231.64 K
divx.dll Tue Aug 9 2005 5:14:00p A.... 692,736 676.50 K
divx_x~1.dll Tue Aug 9 2005 5:13:52p A.... 688,128 672.00 K
divx_x~2.dll Tue Aug 9 2005 5:13:54p A.... 688,128 672.00 K
divx_x~3.dll Tue Aug 9 2005 5:13:52p A.... 671,744 656.00 K
dpl100.dll Tue Aug 9 2005 5:12:30p A.... 86,016 84.00 K
dpu11.dll Tue Aug 9 2005 5:12:28p A.... 245,760 240.00 K
dpugui11.dll Tue Aug 9 2005 5:12:30p A.... 581,632 568.00 K
dpus11.dll Tue Aug 9 2005 5:12:28p A.... 303,104 296.00 K
dpv11.dll Tue Aug 9 2005 5:12:28p A.... 57,344 56.00 K
dtu100.dll Tue Aug 9 2005 5:12:30p A.... 200,704 196.00 K
gccoll~1.dll Tue Jul 12 2005 3:35:14p A.... 126,680 123.71 K
gcunco~1.dll Tue Jul 12 2005 3:35:10p A.... 95,448 93.21 K
hashlib.dll Tue Jul 12 2005 3:35:14p A.... 117,976 115.21 K
icm32.dll Tue Jun 28 2005 8:46:00p A.... 254,976 249.00 K
iepeers.dll Sat Jul 2 2005 9:11:28p A.... 251,392 245.50 K
inseng.dll Sat Jul 2 2005 9:11:28p A.... 96,256 94.00 K
irr6l5~1.dll Thu Sep 22 2005 11:30:16a ..S.R 234,095 228.61 K
jtpq07~1.dll Mon Sep 19 2005 7:56:44p ..S.R 0 0.00 K
kt24l7~1.dll Thu Sep 22 2005 11:30:20a ..S.R 233,961 228.48 K
ktn4l7~1.dll Wed Sep 21 2005 6:45:36a ..S.R 235,729 230.20 K
legitc~1.dll Mon Aug 29 2005 1:27:12p A.... 520,968 508.76 K
libeay32.dll Tue Aug 9 2005 5:13:32p A.... 831,488 812.00 K
lvl409~1.dll Wed Sep 21 2005 4:02:26p ..S.R 233,467 227.99 K
mkexch40.dll Tue Sep 20 2005 10:10:02p ..S.R 234,272 228.78 K
mscms.dll Tue Jun 28 2005 8:46:00p A.... 74,240 72.50 K
mshtml.dll Tue Jul 19 2005 9:00:30p A.... 3,014,144 2.87 M
mshtmled.dll Sat Jul 2 2005 9:11:30p A.... 448,512 438.00 K
msrating.dll Sat Jul 2 2005 9:11:30p A.... 146,432 143.00 K
pngfilt.dll Sat Jul 2 2005 9:11:30p A.... 39,424 38.50 K
qt-dx331.dll Tue Aug 9 2005 5:12:30p A.... 3,596,288 3.43 M
shdocvw.dll Sat Jul 2 2005 9:11:30p A.... 1,483,776 1.41 M
shlwapi.dll Sat Jul 2 2005 9:11:30p A.... 473,600 462.50 K
ssleay32.dll Tue Aug 9 2005 5:13:32p A.... 159,744 156.00 K
tapisrv.dll Fri Jul 8 2005 11:27:56a A.... 249,344 243.50 K
umpnpmgr.dll Wed Jun 29 2005 9:02:40p A.... 118,272 115.50 K
unicows.dll Tue Aug 9 2005 5:13:32p A.... 245,408 239.66 K
urlmon.dll Sat Jul 2 2005 9:11:30p A.... 607,744 593.50 K
wininet.dll Sat Jul 2 2005 9:11:30p A.... 658,432 643.00 K
__dele~1.dll Thu Sep 22 2005 8:34:30p A.... 237,206 231.64 K

44 items found: 44 files (8 H/S), 0 directories.
Total of file sizes: 20,969,014 bytes 19.99 M
Locate .tmp files:

C:\WINDOWS\SYSTEM32\
guard.tmp Thu Sep 22 2005 8:32:20p ..S.R 237,206 231.64 K

1 item found: 1 file (1 H/S), 0 directories.
Total of file sizes: 237,206 bytes 231.64 K
**********************************************************************************
Directory Listing of system files:
Volume in drive C has no label.
Volume Serial Number is 34CF-F6C7

Directory of C:\WINDOWS\System32

09/22/2005 08:32 PM 237,206 guard.tmp
09/22/2005 11:30 AM 237,206 dbquery.dll
09/22/2005 11:30 AM 233,961 kt24l7fq1.dll
09/22/2005 11:30 AM 234,095 irr6l59s1.dll
09/21/2005 05:21 PM 237,206 cjm.dll
09/21/2005 04:02 PM 233,467 lvl4093qe.dll
09/21/2005 06:45 AM 235,729 ktn4l75q1.dll
09/20/2005 10:10 PM 234,272 mkexch40.dll
09/20/2005 09:04 PM <DIR> DLLCACHE
09/19/2005 07:56 PM 0 jtpq0775e.dll
03/20/2005 10:02 AM 56 5E0D9528C2.sys
01/21/2005 06:47 PM 222,625 ir4ul5h91.dll
01/19/2005 11:35 PM 222,572 enp0l17m1.dll
01/18/2005 11:31 PM 222,572 ir0ol5d31.dll
01/18/2005 11:18 PM 222,572 s8puli7918.dll
01/18/2005 11:06 PM 222,572 h80q0id5e80.dll
01/18/2005 07:02 PM 222,572 p68q0gl5e6q.dll
01/18/2005 05:39 PM 222,572 p0n80a5ued.dll
01/18/2005 04:10 PM 223,512 p04u0ah9ed4.dll
01/18/2005 03:57 PM 223,242 azao0e53eh.dll
01/16/2005 10:27 PM 225,952 k8pmli7118.dll
01/16/2005 04:00 PM 225,794 COVFAT.DLL
01/16/2005 03:53 PM 223,221 lt2027fmg.dll
01/09/2005 02:38 PM 225,797 fp0003dme.dll
01/09/2005 02:35 PM 225,794 aflsp.dll
01/09/2005 02:35 PM 222,630 hr4805hue.dll
01/09/2005 02:08 PM 225,794 irss.dll
01/09/2005 02:08 PM 222,531 m6460ghse6460.dll
01/09/2005 02:00 PM 225,794 hZ0qlgd5160.dll
01/09/2005 02:00 PM 222,937 l8n4li5q18.dll
01/09/2005 01:55 PM 225,878 k4800elmehqa0.dll
01/09/2005 01:41 PM 222,968 en2ql1f51.dll
01/09/2005 01:35 PM 223,032 m846lihs1846.dll
01/09/2005 12:42 AM 225,794 t4r80e9ueh.dll
01/09/2005 12:41 AM 225,794 KHDLA.DLL
01/09/2005 12:41 AM 223,231 lt4027hmg.dll
01/09/2005 12:35 AM 222,715 d4j0le1m1h.dll
01/08/2005 06:53 PM 225,794 k6080gdue6080.dll
01/06/2005 05:01 PM 225,794 djmodemx.dll
01/05/2005 10:48 PM 225,794 azaml9911.dll
01/03/2005 11:27 PM 224,945 k2260cfsef260.dll
01/03/2005 10:21 PM 224,945 axi2cqag.dll
01/03/2005 11:56 AM 224,945 ktj2l71o1.dll
01/02/2005 03:08 PM 224,945 LYAUT13n.dll
01/01/2005 09:32 PM 224,945 iKlmgicd.dll
01/01/2005 08:40 PM 224,945 en2ml1f11.dll
01/01/2005 08:04 PM 224,945 CRC.DLL
01/01/2005 04:50 PM 224,945 m2820cloefqc0.dll
12/31/2004 12:48 PM 224,945 gp6ul3j91.dll
12/30/2004 11:38 PM 224,945 lEn4lg5q16.dll
12/30/2004 05:50 PM 226,284 mvlol9331.dll
12/29/2004 07:19 PM 224,945 h60qlgd5160.dll
12/29/2004 12:44 PM 224,945 f22mlcf11f2.dll
12/29/2004 01:46 AM 224,945 j04olah31d4.dll
12/28/2004 01:16 AM 223,245 dn0401dqe.dll
12/26/2004 04:46 PM 223,368 fp2m03f1e.dll
12/26/2004 04:04 PM 223,245 l20ulcd91f0.dll
12/22/2004 02:18 AM 223,144 k8800ilme8qa0.dll
12/22/2004 12:31 AM 223,144 mlricons.dll
12/22/2004 12:23 AM 223,527 fp8o03l3e.dll
12/20/2004 10:17 PM 224,865 gp80l3lm1.dll
12/19/2004 06:53 PM 222,847 lvn8095ue.dll
12/19/2004 02:35 AM 225,546 mvn4l95q1.dll
12/19/2004 12:41 AM 222,863 enjol1131.dll
12/18/2004 07:49 PM 224,811 k0260afsed260.dll
12/17/2004 11:59 PM 225,376 hr2405fqe.dll
12/17/2004 04:17 PM 225,376 KCDLV.DLL
12/15/2004 07:15 PM 225,390 mvrml9911.dll
12/15/2004 06:22 PM 223,226 enn6l15s1.dll
12/13/2004 07:27 PM 223,360 g4lm0e31eh.dll
12/12/2004 05:06 PM 224,613 kt8ol7l31.dll
12/12/2004 04:43 PM 225,208 t28ulcl91fq.dll
12/12/2004 11:25 AM 223,226 INV6MON.DLL
12/12/2004 11:25 AM 225,220 u4rule991h.dll
12/12/2004 10:28 AM 225,237 fnj0211mg.dll
12/12/2004 09:55 AM 223,226 OZBCJI32.DLL
12/12/2004 09:53 AM 223,226 o0480ahued480.dll
12/11/2004 06:38 PM 224,682 l6n4lg5q16.dll
12/11/2004 05:14 PM 224,889 gp66l3js1.dll
12/11/2004 04:55 PM 225,121 k4no0e53eh.dll
12/09/2004 11:04 PM 222,946 gpp2l37o1.dll
12/08/2004 05:38 PM 223,587 fp8s03l7e.dll
12/06/2004 06:30 PM 223,587 krd101c.dll
12/01/2004 10:50 PM 224,930 i4060edseh060.dll
12/01/2004 09:55 PM 224,464 h2l2lc3o1f.dll
12/01/2004 05:10 PM 225,068 n6l8lg3u16.dll
12/16/2002 01:25 PM <DIR> Microsoft
85 File(s) 18,704,179 bytes
2 Dir(s) 8,468,516,864 bytes free
  • 0

#7
tampabelle

tampabelle

    Member 5k

  • Retired Staff
  • 6,363 posts
Close any programs you have open since this step requires a reboot.

From the l2mfix folder on your desktop, double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing enter, then press any key to reboot your computer. After a reboot, your desktop and icons will appear, then disappear (this is normal). L2mfix will continue to scan your computer and when it's finished, notepad will open with a log. Copy the contents of that log and paste it back into this thread, along with a new hijackthis log, and we'll clean up what's left. :tazz:

IMPORTANT: Do NOT run any other files in the l2mfix folder unless you are asked to do so!
  • 0

#8
hunner107

hunner107

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
When I reboot after running l2mfix.bat, my icons don't disappear and the scan doesn't start. After the reboot the AIM window pops up and then privacy defender starts to scan.
  • 0

#9
tampabelle

tampabelle

    Member 5k

  • Retired Staff
  • 6,363 posts
Can you run l2mfix.bat and choose option 1 and post the fresh log please??

I will prepare a manual fix for it.
  • 0

#10
hunner107

hunner107

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Fresh log:

L2MFIX find log 1.04a
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Installer]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\n44sleh71h4.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
"DLLName"="wzcdlg.dll"
"Logon"="WZCEventLogon"
"Logoff"="WZCEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000000


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER


**********************************************************************************
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{78F45A78-1F42-E7E3-5CA1-6D2E8CDBC9A4}"=""

**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run..."
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People..."
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache"
"{955B7B84-5308-419c-8ED8-0B9CA3C56985}"="America Online"
"{5E44E225-A408-11CF-B581-008029601108}"="Adaptec DirectCD Shell Extension"
"{E0D79304-84BE-11CE-9641-444553540000}"="WinZip"
"{E0D79305-84BE-11CE-9641-444553540000}"="WinZip"
"{E0D79306-84BE-11CE-9641-444553540000}"="WinZip"
"{E0D79307-84BE-11CE-9641-444553540000}"="WinZip"
"{6E3C607A-B99C-4FA8-98F5-1AC1ADF7F5B9}"="MediaFace extension"
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{8FF88D21-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6b1 (beta test) Context Menu Shell Extension"
"{8FF88D25-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6b1 (beta test) DragDrop Shell Extension"
"{8FF88D27-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6b1 (beta test) Context Menu Shell Extension"
"{8FF88D23-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6b1 (beta test) Property Sheet Shell Extension"
"{2F860D81-AF3C-11D4-BDB3-00E0987D8540}"="UltimateZip Shell Extension"
"{2F860D82-AF3C-11D4-BDB3-00E0987D8540}"="UltimateZip Drag Drop Handler"
"{7D4037F4-AAB3-4621-82B6-986E61218E87}"=""
"{9A08FE74-D7B9-4F3E-94D6-08D0A87FDE92}"=""
"{B5CD3B45-3639-4CDD-8631-34AA5D087354}"=""
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
"{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
"{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
"{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
"{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
"{4BE4F383-14B8-446E-822F-AA7B1A8CAB1F}"=""
"{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
"{677B9E07-3CAC-4E4C-B16B-606CF897A654}"=""
"{8F1E39B0-6362-4C71-ADFB-FEDC1B9DDB3E}"=""
"{57E5CB65-4D2A-4232-A360-D258F3A0CEED}"=""
"{97050CDB-897D-4602-95A8-9085C42A92C7}"=""
"{6D7024ED-E85F-4354-80C5-9C060897B36D}"=""
"{5464D816-CF16-4784-B9F3-75C0DB52B499}"="Yahoo! Mail"
"{6914557E-71B6-4A55-BBDE-F4432F84626D}"=""
"{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"="AVG7 Shell Extension"
"{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}"="AVG7 Find Extension"
"{B4B3001E-0F56-4E51-8250-BDE11547EC55}"="Super Ad Blocker Toolbar"
"{781EB7B6-3351-44B0-BE43-0AA463D8B62B}"=""
"{126C5B12-6DC9-4BB6-BB47-F31982018E60}"=""

**********************************************************************************
HKEY ROOT CLASSIDS:
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{7D4037F4-AAB3-4621-82B6-986E61218E87}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7D4037F4-AAB3-4621-82B6-986E61218E87}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7D4037F4-AAB3-4621-82B6-986E61218E87}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7D4037F4-AAB3-4621-82B6-986E61218E87}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{9A08FE74-D7B9-4F3E-94D6-08D0A87FDE92}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9A08FE74-D7B9-4F3E-94D6-08D0A87FDE92}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9A08FE74-D7B9-4F3E-94D6-08D0A87FDE92}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9A08FE74-D7B9-4F3E-94D6-08D0A87FDE92}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{B5CD3B45-3639-4CDD-8631-34AA5D087354}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B5CD3B45-3639-4CDD-8631-34AA5D087354}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B5CD3B45-3639-4CDD-8631-34AA5D087354}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B5CD3B45-3639-4CDD-8631-34AA5D087354}\InprocServer32]
@="C:\\WINDOWS\\system32\\AXKCTRS.DLL"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{4BE4F383-14B8-446E-822F-AA7B1A8CAB1F}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{4BE4F383-14B8-446E-822F-AA7B1A8CAB1F}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{4BE4F383-14B8-446E-822F-AA7B1A8CAB1F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{4BE4F383-14B8-446E-822F-AA7B1A8CAB1F}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{677B9E07-3CAC-4E4C-B16B-606CF897A654}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{677B9E07-3CAC-4E4C-B16B-606CF897A654}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{677B9E07-3CAC-4E4C-B16B-606CF897A654}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{677B9E07-3CAC-4E4C-B16B-606CF897A654}\InprocServer32]
@="C:\\WINDOWS\\system32\\nctapi32.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{8F1E39B0-6362-4C71-ADFB-FEDC1B9DDB3E}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8F1E39B0-6362-4C71-ADFB-FEDC1B9DDB3E}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8F1E39B0-6362-4C71-ADFB-FEDC1B9DDB3E}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8F1E39B0-6362-4C71-ADFB-FEDC1B9DDB3E}\InprocServer32]
@="C:\\WINDOWS\\system32\\COVFAT.DLL"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{57E5CB65-4D2A-4232-A360-D258F3A0CEED}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{57E5CB65-4D2A-4232-A360-D258F3A0CEED}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{57E5CB65-4D2A-4232-A360-D258F3A0CEED}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{57E5CB65-4D2A-4232-A360-D258F3A0CEED}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{97050CDB-897D-4602-95A8-9085C42A92C7}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{97050CDB-897D-4602-95A8-9085C42A92C7}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{97050CDB-897D-4602-95A8-9085C42A92C7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{97050CDB-897D-4602-95A8-9085C42A92C7}\InprocServer32]
@="C:\\WINDOWS\\system32\\lzflc13n.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{6D7024ED-E85F-4354-80C5-9C060897B36D}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{6D7024ED-E85F-4354-80C5-9C060897B36D}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{6D7024ED-E85F-4354-80C5-9C060897B36D}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{6D7024ED-E85F-4354-80C5-9C060897B36D}\InprocServer32]
@="C:\\WINDOWS\\system32\\KADSL.DLL"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{6914557E-71B6-4A55-BBDE-F4432F84626D}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{6914557E-71B6-4A55-BBDE-F4432F84626D}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{6914557E-71B6-4A55-BBDE-F4432F84626D}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{6914557E-71B6-4A55-BBDE-F4432F84626D}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{781EB7B6-3351-44B0-BE43-0AA463D8B62B}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{781EB7B6-3351-44B0-BE43-0AA463D8B62B}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{781EB7B6-3351-44B0-BE43-0AA463D8B62B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{781EB7B6-3351-44B0-BE43-0AA463D8B62B}\InprocServer32]
@="C:\\WINDOWS\\system32\\bNsesrv.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{126C5B12-6DC9-4BB6-BB47-F31982018E60}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{126C5B12-6DC9-4BB6-BB47-F31982018E60}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{126C5B12-6DC9-4BB6-BB47-F31982018E60}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{126C5B12-6DC9-4BB6-BB47-F31982018E60}\InprocServer32]
@="C:\\WINDOWS\\system32\\myvcirt.dll"
"ThreadingModel"="Apartment"

**********************************************************************************
Files Found are not all bad files:

C:\WINDOWS\SYSTEM32\
atl71.dll Wed Jul 6 2005 5:17:28p A.... 89,088 87.00 K
bnsesrv.dll Sat Sep 24 2005 12:38:24p ..S.R 237,206 231.64 K
browseui.dll Sat Jul 2 2005 9:11:28p A.... 1,019,904 996.00 K
cdfview.dll Sat Jul 2 2005 9:11:28p A.... 151,040 147.50 K
cjm.dll Wed Sep 21 2005 5:21:36p ..S.R 237,206 231.64 K
divx.dll Tue Aug 9 2005 5:14:00p A.... 692,736 676.50 K
divx_x~1.dll Tue Aug 9 2005 5:13:52p A.... 688,128 672.00 K
divx_x~2.dll Tue Aug 9 2005 5:13:54p A.... 688,128 672.00 K
divx_x~3.dll Tue Aug 9 2005 5:13:52p A.... 671,744 656.00 K
dpl100.dll Tue Aug 9 2005 5:12:30p A.... 86,016 84.00 K
dpu11.dll Tue Aug 9 2005 5:12:28p A.... 245,760 240.00 K
dpugui11.dll Tue Aug 9 2005 5:12:30p A.... 581,632 568.00 K
dpus11.dll Tue Aug 9 2005 5:12:28p A.... 303,104 296.00 K
dpv11.dll Tue Aug 9 2005 5:12:28p A.... 57,344 56.00 K
dtu100.dll Tue Aug 9 2005 5:12:30p A.... 200,704 196.00 K
gccoll~1.dll Tue Jul 12 2005 3:35:14p A.... 126,680 123.71 K
gcunco~1.dll Tue Jul 12 2005 3:35:10p A.... 95,448 93.21 K
hashlib.dll Tue Jul 12 2005 3:35:14p A.... 117,976 115.21 K
icm32.dll Tue Jun 28 2005 8:46:00p A.... 254,976 249.00 K
iepeers.dll Sat Jul 2 2005 9:11:28p A.... 251,392 245.50 K
inseng.dll Sat Jul 2 2005 9:11:28p A.... 96,256 94.00 K
irr6l5~1.dll Thu Sep 22 2005 11:30:16a ..S.R 234,095 228.61 K
jtpq07~1.dll Mon Sep 19 2005 7:56:44p ..S.R 0 0.00 K
kt24l7~1.dll Thu Sep 22 2005 11:30:20a ..S.R 233,961 228.48 K
ktn4l7~1.dll Wed Sep 21 2005 6:45:36a ..S.R 235,729 230.20 K
legitc~1.dll Mon Aug 29 2005 1:27:12p A.... 520,968 508.76 K
libeay32.dll Tue Aug 9 2005 5:13:32p A.... 831,488 812.00 K
lvl409~1.dll Wed Sep 21 2005 4:02:26p ..S.R 233,467 227.99 K
mkexch40.dll Tue Sep 20 2005 10:10:02p ..S.R 234,272 228.78 K
mscms.dll Tue Jun 28 2005 8:46:00p A.... 74,240 72.50 K
mshtml.dll Tue Jul 19 2005 9:00:30p A.... 3,014,144 2.87 M
mshtmled.dll Sat Jul 2 2005 9:11:30p A.... 448,512 438.00 K
msrating.dll Sat Jul 2 2005 9:11:30p A.... 146,432 143.00 K
myvcirt.dll Sat Sep 24 2005 11:28:44p ..S.R 233,386 227.91 K
n44sle~1.dll Sat Sep 24 2005 1:04:48p ..S.R 233,386 227.91 K
p28qlc~1.dll Sat Sep 24 2005 11:27:42p ..S.R 237,206 231.64 K
pngfilt.dll Sat Jul 2 2005 9:11:30p A.... 39,424 38.50 K
qt-dx331.dll Tue Aug 9 2005 5:12:30p A.... 3,596,288 3.43 M
shdocvw.dll Sat Jul 2 2005 9:11:30p A.... 1,483,776 1.41 M
shlwapi.dll Sat Jul 2 2005 9:11:30p A.... 473,600 462.50 K
ssleay32.dll Tue Aug 9 2005 5:13:32p A.... 159,744 156.00 K
tapisrv.dll Fri Jul 8 2005 11:27:56a A.... 249,344 243.50 K
umpnpmgr.dll Wed Jun 29 2005 9:02:40p A.... 118,272 115.50 K
unicows.dll Tue Aug 9 2005 5:13:32p A.... 245,408 239.66 K
urlmon.dll Sat Jul 2 2005 9:11:30p A.... 607,744 593.50 K
wininet.dll Sat Jul 2 2005 9:11:30p A.... 658,432 643.00 K

46 items found: 46 files (11 H/S), 0 directories.
Total of file sizes: 21,435,786 bytes 20.44 M
Locate .tmp files:

No matches found.
**********************************************************************************
Directory Listing of system files:
Volume in drive C has no label.
Volume Serial Number is 34CF-F6C7

Directory of C:\WINDOWS\System32

09/24/2005 11:28 PM 233,386 myvcirt.dll
09/24/2005 11:27 PM 237,206 p28qlcl51fq.dll
09/24/2005 01:04 PM 233,386 n44sleh71h4.dll
09/24/2005 12:38 PM 237,206 bNsesrv.dll
09/22/2005 11:30 AM 233,961 kt24l7fq1.dll
09/22/2005 11:30 AM 234,095 irr6l59s1.dll
09/21/2005 05:21 PM 237,206 cjm.dll
09/21/2005 04:02 PM 233,467 lvl4093qe.dll
09/21/2005 06:45 AM 235,729 ktn4l75q1.dll
09/20/2005 10:10 PM 234,272 mkexch40.dll
09/20/2005 09:04 PM <DIR> DLLCACHE
09/19/2005 07:56 PM 0 jtpq0775e.dll
03/20/2005 10:02 AM 56 5E0D9528C2.sys
01/21/2005 06:47 PM 222,625 ir4ul5h91.dll
01/19/2005 11:35 PM 222,572 enp0l17m1.dll
01/18/2005 11:31 PM 222,572 ir0ol5d31.dll
01/18/2005 11:18 PM 222,572 s8puli7918.dll
01/18/2005 11:06 PM 222,572 h80q0id5e80.dll
01/18/2005 07:02 PM 222,572 p68q0gl5e6q.dll
01/18/2005 05:39 PM 222,572 p0n80a5ued.dll
01/18/2005 04:10 PM 223,512 p04u0ah9ed4.dll
01/18/2005 03:57 PM 223,242 azao0e53eh.dll
01/16/2005 10:27 PM 225,952 k8pmli7118.dll
01/16/2005 04:00 PM 225,794 COVFAT.DLL
01/16/2005 03:53 PM 223,221 lt2027fmg.dll
01/09/2005 02:38 PM 225,797 fp0003dme.dll
01/09/2005 02:35 PM 225,794 aflsp.dll
01/09/2005 02:35 PM 222,630 hr4805hue.dll
01/09/2005 02:08 PM 225,794 irss.dll
01/09/2005 02:08 PM 222,531 m6460ghse6460.dll
01/09/2005 02:00 PM 225,794 hZ0qlgd5160.dll
01/09/2005 02:00 PM 222,937 l8n4li5q18.dll
01/09/2005 01:55 PM 225,878 k4800elmehqa0.dll
01/09/2005 01:41 PM 222,968 en2ql1f51.dll
01/09/2005 01:35 PM 223,032 m846lihs1846.dll
01/09/2005 12:42 AM 225,794 t4r80e9ueh.dll
01/09/2005 12:41 AM 225,794 KHDLA.DLL
01/09/2005 12:41 AM 223,231 lt4027hmg.dll
01/09/2005 12:35 AM 222,715 d4j0le1m1h.dll
01/08/2005 06:53 PM 225,794 k6080gdue6080.dll
01/06/2005 05:01 PM 225,794 djmodemx.dll
01/05/2005 10:48 PM 225,794 azaml9911.dll
01/03/2005 11:27 PM 224,945 k2260cfsef260.dll
01/03/2005 10:21 PM 224,945 axi2cqag.dll
01/03/2005 11:56 AM 224,945 ktj2l71o1.dll
01/02/2005 03:08 PM 224,945 LYAUT13n.dll
01/01/2005 09:32 PM 224,945 iKlmgicd.dll
01/01/2005 08:40 PM 224,945 en2ml1f11.dll
01/01/2005 08:04 PM 224,945 CRC.DLL
01/01/2005 04:50 PM 224,945 m2820cloefqc0.dll
12/31/2004 12:48 PM 224,945 gp6ul3j91.dll
12/30/2004 11:38 PM 224,945 lEn4lg5q16.dll
12/30/2004 05:50 PM 226,284 mvlol9331.dll
12/29/2004 07:19 PM 224,945 h60qlgd5160.dll
12/29/2004 12:44 PM 224,945 f22mlcf11f2.dll
12/29/2004 01:46 AM 224,945 j04olah31d4.dll
12/28/2004 01:16 AM 223,245 dn0401dqe.dll
12/26/2004 04:46 PM 223,368 fp2m03f1e.dll
12/26/2004 04:04 PM 223,245 l20ulcd91f0.dll
12/22/2004 02:18 AM 223,144 k8800ilme8qa0.dll
12/22/2004 12:31 AM 223,144 mlricons.dll
12/22/2004 12:23 AM 223,527 fp8o03l3e.dll
12/20/2004 10:17 PM 224,865 gp80l3lm1.dll
12/19/2004 06:53 PM 222,847 lvn8095ue.dll
12/19/2004 02:35 AM 225,546 mvn4l95q1.dll
12/19/2004 12:41 AM 222,863 enjol1131.dll
12/18/2004 07:49 PM 224,811 k0260afsed260.dll
12/17/2004 11:59 PM 225,376 hr2405fqe.dll
12/17/2004 04:17 PM 225,376 KCDLV.DLL
12/15/2004 07:15 PM 225,390 mvrml9911.dll
12/15/2004 06:22 PM 223,226 enn6l15s1.dll
12/13/2004 07:27 PM 223,360 g4lm0e31eh.dll
12/12/2004 05:06 PM 224,613 kt8ol7l31.dll
12/12/2004 04:43 PM 225,208 t28ulcl91fq.dll
12/12/2004 11:25 AM 223,226 INV6MON.DLL
12/12/2004 11:25 AM 225,220 u4rule991h.dll
12/12/2004 10:28 AM 225,237 fnj0211mg.dll
12/12/2004 09:55 AM 223,226 OZBCJI32.DLL
12/12/2004 09:53 AM 223,226 o0480ahued480.dll
12/11/2004 06:38 PM 224,682 l6n4lg5q16.dll
12/11/2004 05:14 PM 224,889 gp66l3js1.dll
12/11/2004 04:55 PM 225,121 k4no0e53eh.dll
12/09/2004 11:04 PM 222,946 gpp2l37o1.dll
12/08/2004 05:38 PM 223,587 fp8s03l7e.dll
12/06/2004 06:30 PM 223,587 krd101c.dll
12/01/2004 10:50 PM 224,930 i4060edseh060.dll
12/01/2004 09:55 PM 224,464 h2l2lc3o1f.dll
12/01/2004 05:10 PM 225,068 n6l8lg3u16.dll
12/16/2002 01:25 PM <DIR> Microsoft
87 File(s) 19,170,951 bytes
2 Dir(s) 10,330,390,528 bytes free
  • 0

#11
tampabelle

tampabelle

    Member 5k

  • Retired Staff
  • 6,363 posts
Download Pocket KillBox from here. There is a Direct Download and a description of what the Program does inside this link.

Please open Notepad, and copy/paste the code in the box below into a new text file. Save it as fixl2m.reg (set Filetype to "All Files") and save it on your Desktop.

REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"SV1"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{7D4037F4-AAB3-4621-82B6-986E61218E87}"=-
"{9A08FE74-D7B9-4F3E-94D6-08D0A87FDE92}"=-
"{B5CD3B45-3639-4CDD-8631-34AA5D087354}"=-
"{4BE4F383-14B8-446E-822F-AA7B1A8CAB1F}"=-
"{677B9E07-3CAC-4E4C-B16B-606CF897A654}"=-
"{8F1E39B0-6362-4C71-ADFB-FEDC1B9DDB3E}"=-
"{57E5CB65-4D2A-4232-A360-D258F3A0CEED}"=-
"{97050CDB-897D-4602-95A8-9085C42A92C7}"=-
"{6D7024ED-E85F-4354-80C5-9C060897B36D}"=-
"{6914557E-71B6-4A55-BBDE-F4432F84626D}"=-
"{781EB7B6-3351-44B0-BE43-0AA463D8B62B}"=-
"{126C5B12-6DC9-4BB6-BB47-F31982018E60}"=-


[-HKEY_CLASSES_ROOT\CLSID\{7D4037F4-AAB3-4621-82B6-986E61218E87}]

[-HKEY_CLASSES_ROOT\CLSID\{9A08FE74-D7B9-4F3E-94D6-08D0A87FDE92}]

[-HKEY_CLASSES_ROOT\CLSID\{B5CD3B45-3639-4CDD-8631-34AA5D087354}]

[-HKEY_CLASSES_ROOT\CLSID\{4BE4F383-14B8-446E-822F-AA7B1A8CAB1F}]

[-HKEY_CLASSES_ROOT\CLSID\{677B9E07-3CAC-4E4C-B16B-606CF897A654}]

[-HKEY_CLASSES_ROOT\CLSID\{8F1E39B0-6362-4C71-ADFB-FEDC1B9DDB3E}]

[-HKEY_CLASSES_ROOT\CLSID\{57E5CB65-4D2A-4232-A360-D258F3A0CEED}]

[-HKEY_CLASSES_ROOT\CLSID\{97050CDB-897D-4602-95A8-9085C42A92C7}]

[-HKEY_CLASSES_ROOT\CLSID\{6D7024ED-E85F-4354-80C5-9C060897B36D}]

[-HKEY_CLASSES_ROOT\CLSID\{6914557E-71B6-4A55-BBDE-F4432F84626D}]

[-HKEY_CLASSES_ROOT\CLSID\{781EB7B6-3351-44B0-BE43-0AA463D8B62B}]

[-HKEY_CLASSES_ROOT\CLSID\{126C5B12-6DC9-4BB6-BB47-F31982018E60}]


Open Pocket Killbox and Copy & Paste the entries below into the "Full Path of File to Delete"

C:\WINDOWS\system32\n44sleh71h4.dll
C:\WINDOWS\system32\guard.tmp
C:\WINDOWS\system32\AXKCTRS.DLL
C:\WINDOWS\system32\nctapi32.dll
C:\WINDOWS\system32\COVFAT.DLL
C:\WINDOWS\system32\lzflc13n.dll
C:\WINDOWS\system32\KADSL.DLL
C:\WINDOWS\system32\bNsesrv.dll
C:\WINDOWS\system32\myvcirt.dll
c:\windows\system32\myvcirt.dll
c:\windows\system32\p28qlcl51fq.dll
c:\windows\system32\n44sleh71h4.dll
c:\windows\system32\bNsesrv.dll
c:\windows\system32\kt24l7fq1.dll
c:\windows\system32\irr6l59s1.dll
c:\windows\system32\cjm.dll
c:\windows\system32\lvl4093qe.dll
c:\windows\system32\ktn4l75q1.dll
c:\windows\system32\mkexch40.dll
c:\windows\system32\jtpq0775e.dll
c:\windows\system32\5E0D9528C2.sys
c:\windows\system32\ir4ul5h91.dll
c:\windows\system32\enp0l17m1.dll
c:\windows\system32\ir0ol5d31.dll
c:\windows\system32\s8puli7918.dll
c:\windows\system32\h80q0id5e80.dll
c:\windows\system32\p68q0gl5e6q.dll
c:\windows\system32\p0n80a5ued.dll
c:\windows\system32\p04u0ah9ed4.dll
c:\windows\system32\azao0e53eh.dll
c:\windows\system32\k8pmli7118.dll
c:\windows\system32\COVFAT.DLL
c:\windows\system32\lt2027fmg.dll
c:\windows\system32\fp0003dme.dll
c:\windows\system32\aflsp.dll
c:\windows\system32\hr4805hue.dll
c:\windows\system32\irss.dll
c:\windows\system32\m6460ghse6460.dll
c:\windows\system32\hZ0qlgd5160.dll
c:\windows\system32\l8n4li5q18.dll
c:\windows\system32\k4800elmehqa0.dll
c:\windows\system32\en2ql1f51.dll
c:\windows\system32\m846lihs1846.dll
c:\windows\system32\t4r80e9ueh.dll
c:\windows\system32\KHDLA.DLL
c:\windows\system32\lt4027hmg.dll
c:\windows\system32\d4j0le1m1h.dll
c:\windows\system32\k6080gdue6080.dll
c:\windows\system32\djmodemx.dll
c:\windows\system32\azaml9911.dll
c:\windows\system32\k2260cfsef260.dll
c:\windows\system32\axi2cqag.dll
c:\windows\system32\ktj2l71o1.dll
c:\windows\system32\LYAUT13n.dll
c:\windows\system32\iKlmgicd.dll
c:\windows\system32\en2ml1f11.dll
c:\windows\system32\CRC.DLL
c:\windows\system32\m2820cloefqc0.dll
c:\windows\system32\gp6ul3j91.dll
c:\windows\system32\lEn4lg5q16.dll
c:\windows\system32\mvlol9331.dll
c:\windows\system32\h60qlgd5160.dll
c:\windows\system32\f22mlcf11f2.dll
c:\windows\system32\j04olah31d4.dll
c:\windows\system32\dn0401dqe.dll
c:\windows\system32\fp2m03f1e.dll
c:\windows\system32\l20ulcd91f0.dll
c:\windows\system32\k8800ilme8qa0.dll
c:\windows\system32\mlricons.dll
c:\windows\system32\fp8o03l3e.dll
c:\windows\system32\gp80l3lm1.dll
c:\windows\system32\lvn8095ue.dll
c:\windows\system32\mvn4l95q1.dll
c:\windows\system32\enjol1131.dll
c:\windows\system32\k0260afsed260.dll
c:\windows\system32\hr2405fqe.dll
c:\windows\system32\KCDLV.DLL
c:\windows\system32\mvrml9911.dll
c:\windows\system32\enn6l15s1.dll
c:\windows\system32\g4lm0e31eh.dll
c:\windows\system32\kt8ol7l31.dll
c:\windows\system32\t28ulcl91fq.dll
c:\windows\system32\INV6MON.DLL
c:\windows\system32\u4rule991h.dll
c:\windows\system32\fnj0211mg.dll
c:\windows\system32\OZBCJI32.DLL
c:\windows\system32\o0480ahued480.dll
c:\windows\system32\l6n4lg5q16.dll
c:\windows\system32\gp66l3js1.dll
c:\windows\system32\k4no0e53eh.dll
c:\windows\system32\gpp2l37o1.dll
c:\windows\system32\fp8s03l7e.dll
c:\windows\system32\krd101c.dll
c:\windows\system32\i4060edseh060.dll
c:\windows\system32\h2l2lc3o1f.dll
c:\windows\system32\n6l8lg3u16.dll


As you Paste each entry into Killbox,place a tick by any of these Selections available

"Delete on Reboot"
"Unregister .dll before Deleting"


Click the Red Circle with the White X in the Middle to Delete!

Restart in Safe Mode and Run those files through Killbox once more to be sure nothing survived.

This time place a tick by any of these selections available

"Standard File Kill"
"End Explorer Shell while Killing File"
"Unregister .dll before Deleting"


Now Locate and DoubleClick fixl2m.reg-> Allow it to merge into the Registry!

Run l2mfix.bat and choose the Option #4.

Restart back in Normal Mode and Post a fresh l2mfix Option #1 log please!
  • 0

#12
hunner107

hunner107

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Fresher log:

L2MFIX find log 1.04a
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\OptimalLayout]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\k6no0g53e6.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
"DLLName"="wzcdlg.dll"
"Logon"="WZCEventLogon"
"Logoff"="WZCEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000000


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER


**********************************************************************************
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{78F45A78-1F42-E7E3-5CA1-6D2E8CDBC9A4}"=""

**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run..."
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People..."
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache"
"{955B7B84-5308-419c-8ED8-0B9CA3C56985}"="America Online"
"{5E44E225-A408-11CF-B581-008029601108}"="Adaptec DirectCD Shell Extension"
"{E0D79304-84BE-11CE-9641-444553540000}"="WinZip"
"{E0D79305-84BE-11CE-9641-444553540000}"="WinZip"
"{E0D79306-84BE-11CE-9641-444553540000}"="WinZip"
"{E0D79307-84BE-11CE-9641-444553540000}"="WinZip"
"{6E3C607A-B99C-4FA8-98F5-1AC1ADF7F5B9}"="MediaFace extension"
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{8FF88D21-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6b1 (beta test) Context Menu Shell Extension"
"{8FF88D25-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6b1 (beta test) DragDrop Shell Extension"
"{8FF88D27-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6b1 (beta test) Context Menu Shell Extension"
"{8FF88D23-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6b1 (beta test) Property Sheet Shell Extension"
"{2F860D81-AF3C-11D4-BDB3-00E0987D8540}"="UltimateZip Shell Extension"
"{2F860D82-AF3C-11D4-BDB3-00E0987D8540}"="UltimateZip Drag Drop Handler"
"{7D4037F4-AAB3-4621-82B6-986E61218E87}"=""
"{9A08FE74-D7B9-4F3E-94D6-08D0A87FDE92}"=""
"{B5CD3B45-3639-4CDD-8631-34AA5D087354}"=""
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
"{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
"{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
"{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
"{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
"{4BE4F383-14B8-446E-822F-AA7B1A8CAB1F}"=""
"{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
"{677B9E07-3CAC-4E4C-B16B-606CF897A654}"=""
"{8F1E39B0-6362-4C71-ADFB-FEDC1B9DDB3E}"=""
"{57E5CB65-4D2A-4232-A360-D258F3A0CEED}"=""
"{97050CDB-897D-4602-95A8-9085C42A92C7}"=""
"{6D7024ED-E85F-4354-80C5-9C060897B36D}"=""
"{5464D816-CF16-4784-B9F3-75C0DB52B499}"="Yahoo! Mail"
"{6914557E-71B6-4A55-BBDE-F4432F84626D}"=""
"{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"="AVG7 Shell Extension"
"{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}"="AVG7 Find Extension"
"{B4B3001E-0F56-4E51-8250-BDE11547EC55}"="Super Ad Blocker Toolbar"
"{781EB7B6-3351-44B0-BE43-0AA463D8B62B}"=""
"{126C5B12-6DC9-4BB6-BB47-F31982018E60}"=""

**********************************************************************************
HKEY ROOT CLASSIDS:
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{7D4037F4-AAB3-4621-82B6-986E61218E87}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7D4037F4-AAB3-4621-82B6-986E61218E87}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7D4037F4-AAB3-4621-82B6-986E61218E87}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7D4037F4-AAB3-4621-82B6-986E61218E87}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{9A08FE74-D7B9-4F3E-94D6-08D0A87FDE92}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9A08FE74-D7B9-4F3E-94D6-08D0A87FDE92}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9A08FE74-D7B9-4F3E-94D6-08D0A87FDE92}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9A08FE74-D7B9-4F3E-94D6-08D0A87FDE92}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{B5CD3B45-3639-4CDD-8631-34AA5D087354}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B5CD3B45-3639-4CDD-8631-34AA5D087354}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B5CD3B45-3639-4CDD-8631-34AA5D087354}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B5CD3B45-3639-4CDD-8631-34AA5D087354}\InprocServer32]
@="C:\\WINDOWS\\system32\\AXKCTRS.DLL"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{4BE4F383-14B8-446E-822F-AA7B1A8CAB1F}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{4BE4F383-14B8-446E-822F-AA7B1A8CAB1F}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{4BE4F383-14B8-446E-822F-AA7B1A8CAB1F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{4BE4F383-14B8-446E-822F-AA7B1A8CAB1F}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{677B9E07-3CAC-4E4C-B16B-606CF897A654}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{677B9E07-3CAC-4E4C-B16B-606CF897A654}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{677B9E07-3CAC-4E4C-B16B-606CF897A654}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{677B9E07-3CAC-4E4C-B16B-606CF897A654}\InprocServer32]
@="C:\\WINDOWS\\system32\\nctapi32.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{8F1E39B0-6362-4C71-ADFB-FEDC1B9DDB3E}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8F1E39B0-6362-4C71-ADFB-FEDC1B9DDB3E}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8F1E39B0-6362-4C71-ADFB-FEDC1B9DDB3E}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8F1E39B0-6362-4C71-ADFB-FEDC1B9DDB3E}\InprocServer32]
@="C:\\WINDOWS\\system32\\COVFAT.DLL"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{57E5CB65-4D2A-4232-A360-D258F3A0CEED}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{57E5CB65-4D2A-4232-A360-D258F3A0CEED}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{57E5CB65-4D2A-4232-A360-D258F3A0CEED}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{57E5CB65-4D2A-4232-A360-D258F3A0CEED}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{97050CDB-897D-4602-95A8-9085C42A92C7}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{97050CDB-897D-4602-95A8-9085C42A92C7}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{97050CDB-897D-4602-95A8-9085C42A92C7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{97050CDB-897D-4602-95A8-9085C42A92C7}\InprocServer32]
@="C:\\WINDOWS\\system32\\lzflc13n.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{6D7024ED-E85F-4354-80C5-9C060897B36D}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{6D7024ED-E85F-4354-80C5-9C060897B36D}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{6D7024ED-E85F-4354-80C5-9C060897B36D}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{6D7024ED-E85F-4354-80C5-9C060897B36D}\InprocServer32]
@="C:\\WINDOWS\\system32\\KADSL.DLL"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{6914557E-71B6-4A55-BBDE-F4432F84626D}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{6914557E-71B6-4A55-BBDE-F4432F84626D}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{6914557E-71B6-4A55-BBDE-F4432F84626D}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{6914557E-71B6-4A55-BBDE-F4432F84626D}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{781EB7B6-3351-44B0-BE43-0AA463D8B62B}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{781EB7B6-3351-44B0-BE43-0AA463D8B62B}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{781EB7B6-3351-44B0-BE43-0AA463D8B62B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{781EB7B6-3351-44B0-BE43-0AA463D8B62B}\InprocServer32]
@="C:\\WINDOWS\\system32\\bNsesrv.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{126C5B12-6DC9-4BB6-BB47-F31982018E60}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{126C5B12-6DC9-4BB6-BB47-F31982018E60}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{126C5B12-6DC9-4BB6-BB47-F31982018E60}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{126C5B12-6DC9-4BB6-BB47-F31982018E60}\InprocServer32]
@="C:\\WINDOWS\\system32\\sxnceng.dll"
"ThreadingModel"="Apartment"

**********************************************************************************
Files Found are not all bad files:

C:\WINDOWS\SYSTEM32\
atl71.dll Wed Jul 6 2005 5:17:28p A.... 89,088 87.00 K
bnsesrv.dll Sat Sep 24 2005 12:38:24p ..S.R 237,206 231.64 K
browseui.dll Sat Jul 2 2005 9:11:28p A.... 1,019,904 996.00 K
cdfview.dll Sat Jul 2 2005 9:11:28p A.... 151,040 147.50 K
cjm.dll Wed Sep 21 2005 5:21:36p ..S.R 237,206 231.64 K
divx.dll Tue Aug 9 2005 5:14:00p A.... 692,736 676.50 K
divx_x~1.dll Tue Aug 9 2005 5:13:52p A.... 688,128 672.00 K
divx_x~2.dll Tue Aug 9 2005 5:13:54p A.... 688,128 672.00 K
divx_x~3.dll Tue Aug 9 2005 5:13:52p A.... 671,744 656.00 K
dpl100.dll Tue Aug 9 2005 5:12:30p A.... 86,016 84.00 K
dpu11.dll Tue Aug 9 2005 5:12:28p A.... 245,760 240.00 K
dpugui11.dll Tue Aug 9 2005 5:12:30p A.... 581,632 568.00 K
dpus11.dll Tue Aug 9 2005 5:12:28p A.... 303,104 296.00 K
dpv11.dll Tue Aug 9 2005 5:12:28p A.... 57,344 56.00 K
dtu100.dll Tue Aug 9 2005 5:12:30p A.... 200,704 196.00 K
en0ul1~1.dll Sun Sep 25 2005 4:15:02p ..S.R 236,731 231.18 K
gccoll~1.dll Tue Jul 12 2005 3:35:14p A.... 126,680 123.71 K
gcunco~1.dll Tue Jul 12 2005 3:35:10p A.... 95,448 93.21 K
hashlib.dll Tue Jul 12 2005 3:35:14p A.... 117,976 115.21 K
icm32.dll Tue Jun 28 2005 8:46:00p A.... 254,976 249.00 K
iepeers.dll Sat Jul 2 2005 9:11:28p A.... 251,392 245.50 K
inseng.dll Sat Jul 2 2005 9:11:28p A.... 96,256 94.00 K
irr6l5~1.dll Thu Sep 22 2005 11:30:16a ..S.R 234,095 228.61 K
jtpq07~1.dll Mon Sep 19 2005 7:56:44p ..S.R 0 0.00 K
k6no0g~1.dll Sat Sep 24 2005 12:46:54p ..S.R 237,206 231.64 K
kt24l7~1.dll Thu Sep 22 2005 11:30:20a ..S.R 233,961 228.48 K
ktn4l7~1.dll Wed Sep 21 2005 6:45:36a ..S.R 235,729 230.20 K
legitc~1.dll Mon Aug 29 2005 1:27:12p A.... 520,968 508.76 K
libeay32.dll Tue Aug 9 2005 5:13:32p A.... 831,488 812.00 K
lvl409~1.dll Wed Sep 21 2005 4:02:26p ..S.R 233,467 227.99 K
mkexch40.dll Tue Sep 20 2005 10:10:02p ..S.R 234,272 228.78 K
mscms.dll Tue Jun 28 2005 8:46:00p A.... 74,240 72.50 K
mshtml.dll Tue Jul 19 2005 9:00:30p A.... 3,014,144 2.87 M
mshtmled.dll Sat Jul 2 2005 9:11:30p A.... 448,512 438.00 K
msrating.dll Sat Jul 2 2005 9:11:30p A.... 146,432 143.00 K
n44sle~1.dll Sat Sep 24 2005 1:04:48p ..S.R 233,386 227.91 K
pngfilt.dll Sat Jul 2 2005 9:11:30p A.... 39,424 38.50 K
qt-dx331.dll Tue Aug 9 2005 5:12:30p A.... 3,596,288 3.43 M
shdocvw.dll Sat Jul 2 2005 9:11:30p A.... 1,483,776 1.41 M
shlwapi.dll Sat Jul 2 2005 9:11:30p A.... 473,600 462.50 K
ssleay32.dll Tue Aug 9 2005 5:13:32p A.... 159,744 156.00 K
sxnceng.dll Sun Sep 25 2005 4:21:46p ..S.R 237,206 231.64 K
tapisrv.dll Fri Jul 8 2005 11:27:56a A.... 249,344 243.50 K
umpnpmgr.dll Wed Jun 29 2005 9:02:40p A.... 118,272 115.50 K
unicows.dll Tue Aug 9 2005 5:13:32p A.... 245,408 239.66 K
urlmon.dll Sat Jul 2 2005 9:11:30p A.... 607,744 593.50 K
wininet.dll Sat Jul 2 2005 9:11:30p A.... 658,432 643.00 K

47 items found: 47 files (12 H/S), 0 directories.
Total of file sizes: 21,676,337 bytes 20.67 M
Locate .tmp files:

No matches found.
**********************************************************************************
Directory Listing of system files:
Volume in drive C has no label.
Volume Serial Number is 34CF-F6C7

Directory of C:\WINDOWS\System32

09/25/2005 04:21 PM 237,206 sxnceng.dll
09/25/2005 04:15 PM 236,731 en0ul1d91.dll
09/24/2005 01:04 PM 233,386 n44sleh71h4.dll
09/24/2005 12:46 PM 237,206 k6no0g53e6.dll
09/24/2005 12:38 PM 237,206 bNsesrv.dll
09/22/2005 11:30 AM 233,961 kt24l7fq1.dll
09/22/2005 11:30 AM 234,095 irr6l59s1.dll
09/21/2005 05:21 PM 237,206 cjm.dll
09/21/2005 04:02 PM 233,467 lvl4093qe.dll
09/21/2005 06:45 AM 235,729 ktn4l75q1.dll
09/20/2005 10:10 PM 234,272 mkexch40.dll
09/20/2005 09:04 PM <DIR> DLLCACHE
09/19/2005 07:56 PM 0 jtpq0775e.dll
03/20/2005 10:02 AM 56 5E0D9528C2.sys
01/21/2005 06:47 PM 222,625 ir4ul5h91.dll
01/19/2005 11:35 PM 222,572 enp0l17m1.dll
01/18/2005 11:31 PM 222,572 ir0ol5d31.dll
01/18/2005 11:18 PM 222,572 s8puli7918.dll
01/18/2005 11:06 PM 222,572 h80q0id5e80.dll
01/18/2005 07:02 PM 222,572 p68q0gl5e6q.dll
01/18/2005 05:39 PM 222,572 p0n80a5ued.dll
01/18/2005 04:10 PM 223,512 p04u0ah9ed4.dll
01/18/2005 03:57 PM 223,242 azao0e53eh.dll
01/16/2005 10:27 PM 225,952 k8pmli7118.dll
01/16/2005 04:00 PM 225,794 COVFAT.DLL
01/16/2005 03:53 PM 223,221 lt2027fmg.dll
01/09/2005 02:38 PM 225,797 fp0003dme.dll
01/09/2005 02:35 PM 225,794 aflsp.dll
01/09/2005 02:35 PM 222,630 hr4805hue.dll
01/09/2005 02:08 PM 225,794 irss.dll
01/09/2005 02:08 PM 222,531 m6460ghse6460.dll
01/09/2005 02:00 PM 225,794 hZ0qlgd5160.dll
01/09/2005 02:00 PM 222,937 l8n4li5q18.dll
01/09/2005 01:55 PM 225,878 k4800elmehqa0.dll
01/09/2005 01:41 PM 222,968 en2ql1f51.dll
01/09/2005 01:35 PM 223,032 m846lihs1846.dll
01/09/2005 12:42 AM 225,794 t4r80e9ueh.dll
01/09/2005 12:41 AM 225,794 KHDLA.DLL
01/09/2005 12:41 AM 223,231 lt4027hmg.dll
01/09/2005 12:35 AM 222,715 d4j0le1m1h.dll
01/08/2005 06:53 PM 225,794 k6080gdue6080.dll
01/06/2005 05:01 PM 225,794 djmodemx.dll
01/05/2005 10:48 PM 225,794 azaml9911.dll
01/03/2005 11:27 PM 224,945 k2260cfsef260.dll
01/03/2005 10:21 PM 224,945 axi2cqag.dll
01/03/2005 11:56 AM 224,945 ktj2l71o1.dll
01/02/2005 03:08 PM 224,945 LYAUT13n.dll
01/01/2005 09:32 PM 224,945 iKlmgicd.dll
01/01/2005 08:40 PM 224,945 en2ml1f11.dll
01/01/2005 08:04 PM 224,945 CRC.DLL
01/01/2005 04:50 PM 224,945 m2820cloefqc0.dll
12/31/2004 12:48 PM 224,945 gp6ul3j91.dll
12/30/2004 11:38 PM 224,945 lEn4lg5q16.dll
12/30/2004 05:50 PM 226,284 mvlol9331.dll
12/29/2004 07:19 PM 224,945 h60qlgd5160.dll
12/29/2004 12:44 PM 224,945 f22mlcf11f2.dll
12/29/2004 01:46 AM 224,945 j04olah31d4.dll
12/28/2004 01:16 AM 223,245 dn0401dqe.dll
12/26/2004 04:46 PM 223,368 fp2m03f1e.dll
12/26/2004 04:04 PM 223,245 l20ulcd91f0.dll
12/22/2004 02:18 AM 223,144 k8800ilme8qa0.dll
12/22/2004 12:31 AM 223,144 mlricons.dll
12/22/2004 12:23 AM 223,527 fp8o03l3e.dll
12/20/2004 10:17 PM 224,865 gp80l3lm1.dll
12/19/2004 06:53 PM 222,847 lvn8095ue.dll
12/19/2004 02:35 AM 225,546 mvn4l95q1.dll
12/19/2004 12:41 AM 222,863 enjol1131.dll
12/18/2004 07:49 PM 224,811 k0260afsed260.dll
12/17/2004 11:59 PM 225,376 hr2405fqe.dll
12/17/2004 04:17 PM 225,376 KCDLV.DLL
12/15/2004 07:15 PM 225,390 mvrml9911.dll
12/15/2004 06:22 PM 223,226 enn6l15s1.dll
12/13/2004 07:27 PM 223,360 g4lm0e31eh.dll
12/12/2004 05:06 PM 224,613 kt8ol7l31.dll
12/12/2004 04:43 PM 225,208 t28ulcl91fq.dll
12/12/2004 11:25 AM 223,226 INV6MON.DLL
12/12/2004 11:25 AM 225,220 u4rule991h.dll
12/12/2004 10:28 AM 225,237 fnj0211mg.dll
12/12/2004 09:55 AM 223,226 OZBCJI32.DLL
12/12/2004 09:53 AM 223,226 o0480ahued480.dll
12/11/2004 06:38 PM 224,682 l6n4lg5q16.dll
12/11/2004 05:14 PM 224,889 gp66l3js1.dll
12/11/2004 04:55 PM 225,121 k4no0e53eh.dll
12/09/2004 11:04 PM 222,946 gpp2l37o1.dll
12/08/2004 05:38 PM 223,587 fp8s03l7e.dll
12/06/2004 06:30 PM 223,587 krd101c.dll
12/01/2004 10:50 PM 224,930 i4060edseh060.dll
12/01/2004 09:55 PM 224,464 h2l2lc3o1f.dll
12/01/2004 05:10 PM 225,068 n6l8lg3u16.dll
12/16/2002 01:25 PM <DIR> Microsoft
88 File(s) 19,411,502 bytes
2 Dir(s) 9,953,701,888 bytes free
  • 0

#13
tampabelle

tampabelle

    Member 5k

  • Retired Staff
  • 6,363 posts
Did you have issues when

1) you ran l2mfix Option #1

2) l2mfix option #2

3) Running Killbox and deleting the files

4) merging the file fixl2m.reg with the registry

Almost all the original entries are still there :tazz:
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP