Here are the new results
L2Mfix 1.02
Running From:
C:\Documents and Settings\Frederick Bielo\Desktop\l2mfix
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (
http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER
Setting registry permissions:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (
http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Denying C access for really "Everyone"
- adding new ACCESS DENY entry
Registry Permissions set too:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (
http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(CI) DENY --C------- Everyone
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER
Setting up for Reboot
Starting Reboot!
C:\Documents and Settings\Frederick Bielo\Desktop\l2mfix
System Rebooted!
Running From:
C:\Documents and Settings\Frederick Bielo\Desktop\l2mfix
killing explorer and rundll32.exe
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003
[email protected]
Killing PID 1516 'explorer.exe'
Killing PID 1516 'explorer.exe'
Killing PID 1516 'explorer.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003
[email protected]
Error, Cannot find a process with an image name of rundll32.exe
Scanning First Pass. Please Wait!
First Pass Completed
Second Pass Scanning
Second pass Completed!
Backing Up: C:\WINDOWS\system32\acifil32.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\amlsp(2).dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\bFsesrv.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\c2000cdmef0a0.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\cmb.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\cmrsrv.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dn0201doe.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dn0601dse.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dn4601hse.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\eeentlog.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\enr8l19u1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\fp0q03d5e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\g0jola131d.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\g804lidq180e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\h24mlch11f4.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\h64m0gh1e64.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\hp0023dmg.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\hr2u05f9e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\i0420ahoed4c0.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\i8jqli1518.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ir0sl5d71.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\irpsl5771.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\itign32.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\iTsrecst.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\j82q0if5e82.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\jtl2073oe.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\k2pm0c71ef.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\k608lgdu1608.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\khdur.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\kjdes.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\kt04l7dq1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\l00u0ad9ed0.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\l0j8la1u1d.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\l0r0la9m1d.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\l26olcj31fo.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\lgimg12n.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ljpsd11n.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\loxwd12n.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\lpbmp12n.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\lv0209doe.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\lv0m09d1e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\lv8809lue.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\lvlu0939e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mbtask.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mgjet35.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\myihnd.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\n0r2la9o1d.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\njrsru.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\nqhtml.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\o6840glqe6qe0.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\p28qlcl51fq.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\p6r4lg9q16.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\p8r40i9qe8.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\q4860elsehq60.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\q668lgju16o8.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\t0r80a9ued.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\tccfgwmi.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\tupmon.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\txappcmp.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ujlmon.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\umrcntra.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\wycsvc.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\guard.tmp
1 file(s) copied.
deleting: C:\WINDOWS\system32\acifil32.dll
Successfully Deleted: C:\WINDOWS\system32\acifil32.dll
deleting: C:\WINDOWS\system32\amlsp(2).dll
Successfully Deleted: C:\WINDOWS\system32\amlsp(2).dll
deleting: C:\WINDOWS\system32\bFsesrv.dll
Successfully Deleted: C:\WINDOWS\system32\bFsesrv.dll
deleting: C:\WINDOWS\system32\c2000cdmef0a0.dll
Successfully Deleted: C:\WINDOWS\system32\c2000cdmef0a0.dll
deleting: C:\WINDOWS\system32\cmb.dll
Successfully Deleted: C:\WINDOWS\system32\cmb.dll
deleting: C:\WINDOWS\system32\cmrsrv.dll
Successfully Deleted: C:\WINDOWS\system32\cmrsrv.dll
deleting: C:\WINDOWS\system32\dn0201doe.dll
Successfully Deleted: C:\WINDOWS\system32\dn0201doe.dll
deleting: C:\WINDOWS\system32\dn0601dse.dll
Successfully Deleted: C:\WINDOWS\system32\dn0601dse.dll
deleting: C:\WINDOWS\system32\dn4601hse.dll
Successfully Deleted: C:\WINDOWS\system32\dn4601hse.dll
deleting: C:\WINDOWS\system32\eeentlog.dll
Successfully Deleted: C:\WINDOWS\system32\eeentlog.dll
deleting: C:\WINDOWS\system32\enr8l19u1.dll
Successfully Deleted: C:\WINDOWS\system32\enr8l19u1.dll
deleting: C:\WINDOWS\system32\fp0q03d5e.dll
Successfully Deleted: C:\WINDOWS\system32\fp0q03d5e.dll
deleting: C:\WINDOWS\system32\g0jola131d.dll
Successfully Deleted: C:\WINDOWS\system32\g0jola131d.dll
deleting: C:\WINDOWS\system32\g804lidq180e.dll
Successfully Deleted: C:\WINDOWS\system32\g804lidq180e.dll
deleting: C:\WINDOWS\system32\h24mlch11f4.dll
Successfully Deleted: C:\WINDOWS\system32\h24mlch11f4.dll
deleting: C:\WINDOWS\system32\h64m0gh1e64.dll
Successfully Deleted: C:\WINDOWS\system32\h64m0gh1e64.dll
deleting: C:\WINDOWS\system32\hp0023dmg.dll
Successfully Deleted: C:\WINDOWS\system32\hp0023dmg.dll
deleting: C:\WINDOWS\system32\hr2u05f9e.dll
Successfully Deleted: C:\WINDOWS\system32\hr2u05f9e.dll
deleting: C:\WINDOWS\system32\i0420ahoed4c0.dll
Successfully Deleted: C:\WINDOWS\system32\i0420ahoed4c0.dll
deleting: C:\WINDOWS\system32\i8jqli1518.dll
Successfully Deleted: C:\WINDOWS\system32\i8jqli1518.dll
deleting: C:\WINDOWS\system32\ir0sl5d71.dll
Successfully Deleted: C:\WINDOWS\system32\ir0sl5d71.dll
deleting: C:\WINDOWS\system32\irpsl5771.dll
Successfully Deleted: C:\WINDOWS\system32\irpsl5771.dll
deleting: C:\WINDOWS\system32\itign32.dll
Successfully Deleted: C:\WINDOWS\system32\itign32.dll
deleting: C:\WINDOWS\system32\iTsrecst.dll
Successfully Deleted: C:\WINDOWS\system32\iTsrecst.dll
deleting: C:\WINDOWS\system32\j82q0if5e82.dll
Successfully Deleted: C:\WINDOWS\system32\j82q0if5e82.dll
deleting: C:\WINDOWS\system32\jtl2073oe.dll
Successfully Deleted: C:\WINDOWS\system32\jtl2073oe.dll
deleting: C:\WINDOWS\system32\k2pm0c71ef.dll
Successfully Deleted: C:\WINDOWS\system32\k2pm0c71ef.dll
deleting: C:\WINDOWS\system32\k608lgdu1608.dll
Successfully Deleted: C:\WINDOWS\system32\k608lgdu1608.dll
deleting: C:\WINDOWS\system32\khdur.dll
Successfully Deleted: C:\WINDOWS\system32\khdur.dll
deleting: C:\WINDOWS\system32\kjdes.dll
Successfully Deleted: C:\WINDOWS\system32\kjdes.dll
deleting: C:\WINDOWS\system32\kt04l7dq1.dll
Successfully Deleted: C:\WINDOWS\system32\kt04l7dq1.dll
deleting: C:\WINDOWS\system32\l00u0ad9ed0.dll
Successfully Deleted: C:\WINDOWS\system32\l00u0ad9ed0.dll
deleting: C:\WINDOWS\system32\l0j8la1u1d.dll
Successfully Deleted: C:\WINDOWS\system32\l0j8la1u1d.dll
deleting: C:\WINDOWS\system32\l0r0la9m1d.dll
Successfully Deleted: C:\WINDOWS\system32\l0r0la9m1d.dll
deleting: C:\WINDOWS\system32\l26olcj31fo.dll
Successfully Deleted: C:\WINDOWS\system32\l26olcj31fo.dll
deleting: C:\WINDOWS\system32\lgimg12n.dll
Successfully Deleted: C:\WINDOWS\system32\lgimg12n.dll
deleting: C:\WINDOWS\system32\ljpsd11n.dll
Successfully Deleted: C:\WINDOWS\system32\ljpsd11n.dll
deleting: C:\WINDOWS\system32\loxwd12n.dll
Successfully Deleted: C:\WINDOWS\system32\loxwd12n.dll
deleting: C:\WINDOWS\system32\lpbmp12n.dll
Successfully Deleted: C:\WINDOWS\system32\lpbmp12n.dll
deleting: C:\WINDOWS\system32\lv0209doe.dll
Successfully Deleted: C:\WINDOWS\system32\lv0209doe.dll
deleting: C:\WINDOWS\system32\lv0m09d1e.dll
Successfully Deleted: C:\WINDOWS\system32\lv0m09d1e.dll
deleting: C:\WINDOWS\system32\lv8809lue.dll
Successfully Deleted: C:\WINDOWS\system32\lv8809lue.dll
deleting: C:\WINDOWS\system32\lvlu0939e.dll
Successfully Deleted: C:\WINDOWS\system32\lvlu0939e.dll
deleting: C:\WINDOWS\system32\mbtask.dll
Successfully Deleted: C:\WINDOWS\system32\mbtask.dll
deleting: C:\WINDOWS\system32\mgjet35.dll
Successfully Deleted: C:\WINDOWS\system32\mgjet35.dll
deleting: C:\WINDOWS\system32\myihnd.dll
Successfully Deleted: C:\WINDOWS\system32\myihnd.dll
deleting: C:\WINDOWS\system32\n0r2la9o1d.dll
Successfully Deleted: C:\WINDOWS\system32\n0r2la9o1d.dll
deleting: C:\WINDOWS\system32\njrsru.dll
Successfully Deleted: C:\WINDOWS\system32\njrsru.dll
deleting: C:\WINDOWS\system32\nqhtml.dll
Successfully Deleted: C:\WINDOWS\system32\nqhtml.dll
deleting: C:\WINDOWS\system32\o6840glqe6qe0.dll
Successfully Deleted: C:\WINDOWS\system32\o6840glqe6qe0.dll
deleting: C:\WINDOWS\system32\p28qlcl51fq.dll
Successfully Deleted: C:\WINDOWS\system32\p28qlcl51fq.dll
deleting: C:\WINDOWS\system32\p6r4lg9q16.dll
Successfully Deleted: C:\WINDOWS\system32\p6r4lg9q16.dll
deleting: C:\WINDOWS\system32\p8r40i9qe8.dll
Successfully Deleted: C:\WINDOWS\system32\p8r40i9qe8.dll
deleting: C:\WINDOWS\system32\q4860elsehq60.dll
Successfully Deleted: C:\WINDOWS\system32\q4860elsehq60.dll
deleting: C:\WINDOWS\system32\q668lgju16o8.dll
Successfully Deleted: C:\WINDOWS\system32\q668lgju16o8.dll
deleting: C:\WINDOWS\system32\t0r80a9ued.dll
Successfully Deleted: C:\WINDOWS\system32\t0r80a9ued.dll
deleting: C:\WINDOWS\system32\tccfgwmi.dll
Successfully Deleted: C:\WINDOWS\system32\tccfgwmi.dll
deleting: C:\WINDOWS\system32\tupmon.dll
Successfully Deleted: C:\WINDOWS\system32\tupmon.dll
deleting: C:\WINDOWS\system32\txappcmp.dll
Successfully Deleted: C:\WINDOWS\system32\txappcmp.dll
deleting: C:\WINDOWS\system32\ujlmon.dll
Successfully Deleted: C:\WINDOWS\system32\ujlmon.dll
deleting: C:\WINDOWS\system32\umrcntra.dll
Successfully Deleted: C:\WINDOWS\system32\umrcntra.dll
deleting: C:\WINDOWS\system32\wycsvc.dll
Successfully Deleted: C:\WINDOWS\system32\wycsvc.dll
deleting: C:\WINDOWS\system32\guard.tmp
Successfully Deleted: C:\WINDOWS\system32\guard.tmp
Desktop.ini sucessfully removed
Zipping up files for submission:
adding: acifil32.dll (164 bytes security) (deflated 3%)
adding: amlsp(2).dll (164 bytes security) (deflated 4%)
adding: bFsesrv.dll (164 bytes security) (deflated 4%)
adding: c2000cdmef0a0.dll (164 bytes security) (deflated 3%)
adding: cmb.dll (164 bytes security) (deflated 4%)
adding: cmrsrv.dll (164 bytes security) (deflated 4%)
adding: dn0201doe.dll (164 bytes security) (deflated 4%)
adding: dn0601dse.dll (164 bytes security) (deflated 4%)
adding: dn4601hse.dll (164 bytes security) (deflated 4%)
adding: eeentlog.dll (164 bytes security) (deflated 3%)
adding: enr8l19u1.dll (164 bytes security) (deflated 4%)
adding: fp0q03d5e.dll (164 bytes security) (deflated 4%)
adding: g0jola131d.dll (164 bytes security) (deflated 4%)
adding: g804lidq180e.dll (164 bytes security) (deflated 4%)
adding: h24mlch11f4.dll (164 bytes security) (deflated 5%)
adding: h64m0gh1e64.dll (164 bytes security) (deflated 4%)
adding: hp0023dmg.dll (164 bytes security) (deflated 3%)
adding: hr2u05f9e.dll (164 bytes security) (deflated 4%)
adding: i0420ahoed4c0.dll (164 bytes security) (deflated 4%)
adding: i8jqli1518.dll (164 bytes security) (deflated 3%)
adding: ir0sl5d71.dll (164 bytes security) (deflated 3%)
adding: irpsl5771.dll (164 bytes security) (deflated 4%)
adding: itign32.dll (164 bytes security) (deflated 3%)
adding: iTsrecst.dll (164 bytes security) (deflated 3%)
adding: j82q0if5e82.dll (164 bytes security) (deflated 4%)
adding: jtl2073oe.dll (164 bytes security) (deflated 4%)
adding: k2pm0c71ef.dll (164 bytes security) (deflated 4%)
adding: k608lgdu1608.dll (164 bytes security) (deflated 4%)
adding: khdur.dll (164 bytes security) (deflated 5%)
adding: kjdes.dll (164 bytes security) (deflated 4%)
adding: kt04l7dq1.dll (164 bytes security) (deflated 4%)
adding: l00u0ad9ed0.dll (164 bytes security) (deflated 3%)
adding: l0j8la1u1d.dll (164 bytes security) (deflated 4%)
adding: l0r0la9m1d.dll (164 bytes security) (deflated 4%)
adding: l26olcj31fo.dll (164 bytes security) (deflated 3%)
adding: lgimg12n.dll (164 bytes security) (deflated 4%)
adding: ljpsd11n.dll (164 bytes security) (deflated 4%)
adding: loxwd12n.dll (164 bytes security) (deflated 4%)
adding: lpbmp12n.dll (164 bytes security) (deflated 4%)
adding: lv0209doe.dll (164 bytes security) (deflated 4%)
adding: lv0m09d1e.dll (164 bytes security) (deflated 3%)
adding: lv8809lue.dll (164 bytes security) (deflated 4%)
adding: lvlu0939e.dll (164 bytes security) (deflated 4%)
adding: mbtask.dll (164 bytes security) (deflated 4%)
adding: mgjet35.dll (164 bytes security) (deflated 4%)
adding: myihnd.dll (164 bytes security) (deflated 4%)
adding: n0r2la9o1d.dll (164 bytes security) (deflated 4%)
adding: njrsru.dll (164 bytes security) (deflated 4%)
adding: nqhtml.dll (164 bytes security) (deflated 3%)
adding: o6840glqe6qe0.dll (164 bytes security) (deflated 4%)
adding: p28qlcl51fq.dll (164 bytes security) (deflated 4%)
adding: p6r4lg9q16.dll (164 bytes security) (deflated 3%)
adding: p8r40i9qe8.dll (164 bytes security) (deflated 4%)
adding: q4860elsehq60.dll (164 bytes security) (deflated 5%)
adding: q668lgju16o8.dll (164 bytes security) (deflated 3%)
adding: t0r80a9ued.dll (164 bytes security) (deflated 4%)
adding: tccfgwmi.dll (164 bytes security) (deflated 4%)
adding: tupmon.dll (164 bytes security) (deflated 5%)
adding: txappcmp.dll (164 bytes security) (deflated 4%)
adding: ujlmon.dll (164 bytes security) (deflated 4%)
adding: umrcntra.dll (164 bytes security) (deflated 4%)
adding: wycsvc.dll (164 bytes security) (deflated 4%)
adding: guard.tmp (164 bytes security) (deflated 4%)
adding: cecho.reg (164 bytes security) (deflated 2%)
adding: clear.reg (164 bytes security) (deflated 70%)
adding: echo.reg (164 bytes security) (deflated 10%)
adding: desktop.ini (164 bytes security) (deflated 15%)
adding: direct.txt (164 bytes security) (stored 0%)
adding: lo2.txt (164 bytes security) (deflated 87%)
adding: readme.txt (164 bytes security) (deflated 49%)
adding: test.txt (164 bytes security) (deflated 83%)
adding: test2.txt (164 bytes security) (deflated 49%)
adding: xfind.txt (164 bytes security) (deflated 78%)
adding: backregs/05272204-965B-4758-B8B1-E630EA91D1C3.reg (164 bytes security) (deflated 70%)
adding: backregs/1974C3D9-CB55-46DD-AA93-FC838A3CA088.reg (164 bytes security) (deflated 70%)
adding: backregs/1E02EC30-1E8B-4281-967A-2602B7E0621E.reg (164 bytes security) (deflated 70%)
adding: backregs/27D4821B-D8F0-48B2-89BD-B96161D068D5.reg (164 bytes security) (deflated 70%)
adding: backregs/2C7CDAC2-0833-413E-AC2B-63A2F115B410.reg (164 bytes security) (deflated 70%)
adding: backregs/2CD5DBA9-54D4-490E-8AE8-3490C0CA91B9.reg (164 bytes security) (deflated 70%)
adding: backregs/312B36C6-F4AE-4794-8A45-61E69715A8CA.reg (164 bytes security) (deflated 70%)
adding: backregs/3B6AC894-EE5B-47E7-9D76-BC153B38C88F.reg (164 bytes security) (deflated 70%)
adding: backregs/50D8AF94-93F8-4D07-AEF7-E7E9C2093A7F.reg (164 bytes security) (deflated 70%)
adding: backregs/703D167D-1E0D-4762-9799-80FF17F99065.reg (164 bytes security) (deflated 70%)
adding: backregs/747ED573-5438-428B-84A5-5EDBBB054910.reg (164 bytes security) (deflated 70%)
adding: backregs/856B51C4-F1A4-4DA7-BFB1-F7BAD1B66496.reg (164 bytes security) (deflated 70%)
adding: backregs/9624D36B-4DBF-4988-9A2A-81691CCB34D1.reg (164 bytes security) (deflated 70%)
adding: backregs/9C163635-F210-4A9F-BE29-4073CBC9DB35.reg (164 bytes security) (deflated 70%)
adding: backregs/9DAFBFE9-8667-47C3-8313-E6E033013F93.reg (164 bytes security) (deflated 70%)
adding: backregs/B4E4DF1F-4EE4-4BA2-868C-1CEE5FCDB6FA.reg (164 bytes security) (deflated 70%)
adding: backregs/B63FCEF6-B0CC-4D0E-AB62-B0562C2F22EB.reg (164 bytes security) (deflated 70%)
adding: backregs/CF530C0F-EF89-4694-BC89-AAD3A48D8770.reg (164 bytes security) (deflated 70%)
adding: backregs/DE967909-503D-428A-90A4-ED226FD894FA.reg (164 bytes security) (deflated 70%)
adding: backregs/E0D0CE8B-0067-4F87-8726-F14273F6E63E.reg (164 bytes security) (deflated 70%)
adding: backregs/E2A60F62-BE7D-4D08-ABA1-A2F0A09B5050.reg (164 bytes security) (deflated 70%)
adding: backregs/E3FAC432-C82D-4B8F-8725-AB4040CF177A.reg (164 bytes security) (deflated 70%)
adding: backregs/F0CF68B1-D7E5-473D-9008-0B80E5DF088B.reg (164 bytes security) (deflated 70%)
adding: backregs/F8025330-DC11-4425-8DE2-4A04145D1207.reg (164 bytes security) (deflated 70%)
adding: backregs/shell.reg (164 bytes security) (deflated 73%)
Restoring Registry Permissions:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (
http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Revoking access for really "Everyone"
Registry permissions set too:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (
http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER
Restoring Sedebugprivilege:
Granting SeDebugPrivilege to Administrators ... successful
deleting local copy: acifil32.dll
deleting local copy: amlsp(2).dll
deleting local copy: bFsesrv.dll
deleting local copy: c2000cdmef0a0.dll
deleting local copy: cmb.dll
deleting local copy: cmrsrv.dll
deleting local copy: dn0201doe.dll
deleting local copy: dn0601dse.dll
deleting local copy: dn4601hse.dll
deleting local copy: eeentlog.dll
deleting local copy: enr8l19u1.dll
deleting local copy: fp0q03d5e.dll
deleting local copy: g0jola131d.dll
deleting local copy: g804lidq180e.dll
deleting local copy: h24mlch11f4.dll
deleting local copy: h64m0gh1e64.dll
deleting local copy: hp0023dmg.dll
deleting local copy: hr2u05f9e.dll
deleting local copy: i0420ahoed4c0.dll
deleting local copy: i8jqli1518.dll
deleting local copy: ir0sl5d71.dll
deleting local copy: irpsl5771.dll
deleting local copy: itign32.dll
deleting local copy: iTsrecst.dll
deleting local copy: j82q0if5e82.dll
deleting local copy: jtl2073oe.dll
deleting local copy: k2pm0c71ef.dll
deleting local copy: k608lgdu1608.dll
deleting local copy: khdur.dll
deleting local copy: kjdes.dll
deleting local copy: kt04l7dq1.dll
deleting local copy: l00u0ad9ed0.dll
deleting local copy: l0j8la1u1d.dll
deleting local copy: l0r0la9m1d.dll
deleting local copy: l26olcj31fo.dll
deleting local copy: lgimg12n.dll
deleting local copy: ljpsd11n.dll
deleting local copy: loxwd12n.dll
deleting local copy: lpbmp12n.dll
deleting local copy: lv0209doe.dll
deleting local copy: lv0m09d1e.dll
deleting local copy: lv8809lue.dll
deleting local copy: lvlu0939e.dll
deleting local copy: mbtask.dll
deleting local copy: mgjet35.dll
deleting local copy: myihnd.dll
deleting local copy: n0r2la9o1d.dll
deleting local copy: njrsru.dll
deleting local copy: nqhtml.dll
deleting local copy: o6840glqe6qe0.dll
deleting local copy: p28qlcl51fq.dll
deleting local copy: p6r4lg9q16.dll
deleting local copy: p8r40i9qe8.dll
deleting local copy: q4860elsehq60.dll
deleting local copy: q668lgju16o8.dll
deleting local copy: t0r80a9ued.dll
deleting local copy: tccfgwmi.dll
deleting local copy: tupmon.dll
deleting local copy: txappcmp.dll
deleting local copy: ujlmon.dll
deleting local copy: umrcntra.dll
deleting local copy: wycsvc.dll
deleting local copy: guard.tmp
The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
"Asynchronous"=dword:00000000
"DllName"=""
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
The following are the files found:
****************************************************************************
C:\WINDOWS\system32\acifil32.dll
C:\WINDOWS\system32\amlsp(2).dll
C:\WINDOWS\system32\bFsesrv.dll
C:\WINDOWS\system32\c2000cdmef0a0.dll
C:\WINDOWS\system32\cmb.dll
C:\WINDOWS\system32\cmrsrv.dll
C:\WINDOWS\system32\dn0201doe.dll
C:\WINDOWS\system32\dn0601dse.dll
C:\WINDOWS\system32\dn4601hse.dll
C:\WINDOWS\system32\eeentlog.dll
C:\WINDOWS\system32\enr8l19u1.dll
C:\WINDOWS\system32\fp0q03d5e.dll
C:\WINDOWS\system32\g0jola131d.dll
C:\WINDOWS\system32\g804lidq180e.dll
C:\WINDOWS\system32\h24mlch11f4.dll
C:\WINDOWS\system32\h64m0gh1e64.dll
C:\WINDOWS\system32\hp0023dmg.dll
C:\WINDOWS\system32\hr2u05f9e.dll
C:\WINDOWS\system32\i0420ahoed4c0.dll
C:\WINDOWS\system32\i8jqli1518.dll
C:\WINDOWS\system32\ir0sl5d71.dll
C:\WINDOWS\system32\irpsl5771.dll
C:\WINDOWS\system32\itign32.dll
C:\WINDOWS\system32\iTsrecst.dll
C:\WINDOWS\system32\j82q0if5e82.dll
C:\WINDOWS\system32\jtl2073oe.dll
C:\WINDOWS\system32\k2pm0c71ef.dll
C:\WINDOWS\system32\k608lgdu1608.dll
C:\WINDOWS\system32\khdur.dll
C:\WINDOWS\system32\kjdes.dll
C:\WINDOWS\system32\kt04l7dq1.dll
C:\WINDOWS\system32\l00u0ad9ed0.dll
C:\WINDOWS\system32\l0j8la1u1d.dll
C:\WINDOWS\system32\l0r0la9m1d.dll
C:\WINDOWS\system32\l26olcj31fo.dll
C:\WINDOWS\system32\lgimg12n.dll
C:\WINDOWS\system32\ljpsd11n.dll
C:\WINDOWS\system32\loxwd12n.dll
C:\WINDOWS\system32\lpbmp12n.dll
C:\WINDOWS\system32\lv0209doe.dll
C:\WINDOWS\system32\lv0m09d1e.dll
C:\WINDOWS\system32\lv8809lue.dll
C:\WINDOWS\system32\lvlu0939e.dll
C:\WINDOWS\system32\mbtask.dll
C:\WINDOWS\system32\mgjet35.dll
C:\WINDOWS\system32\myihnd.dll
C:\WINDOWS\system32\n0r2la9o1d.dll
C:\WINDOWS\system32\njrsru.dll
C:\WINDOWS\system32\nqhtml.dll
C:\WINDOWS\system32\o6840glqe6qe0.dll
C:\WINDOWS\system32\p28qlcl51fq.dll
C:\WINDOWS\system32\p6r4lg9q16.dll
C:\WINDOWS\system32\p8r40i9qe8.dll
C:\WINDOWS\system32\q4860elsehq60.dll
C:\WINDOWS\system32\q668lgju16o8.dll
C:\WINDOWS\system32\t0r80a9ued.dll
C:\WINDOWS\system32\tccfgwmi.dll
C:\WINDOWS\system32\tupmon.dll
C:\WINDOWS\system32\txappcmp.dll
C:\WINDOWS\system32\ujlmon.dll
C:\WINDOWS\system32\umrcntra.dll
C:\WINDOWS\system32\wycsvc.dll
C:\WINDOWS\system32\guard.tmp
Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{9720871C-1C91-4D19-9530-3EBF8685423E}"=-
"{CF1D5924-40F1-4241-BBCF-B2C82682B25A}"=-
"{F0CF68B1-D7E5-473D-9008-0B80E5DF088B}"=-
"{27D4821B-D8F0-48B2-89BD-B96161D068D5}"=-
"{9624D36B-4DBF-4988-9A2A-81691CCB34D1}"=-
"{E0D0CE8B-0067-4F87-8726-F14273F6E63E}"=-
"{2CD5DBA9-54D4-490E-8AE8-3490C0CA91B9}"=-
"{50D8AF94-93F8-4D07-AEF7-E7E9C2093A7F}"=-
"{1974C3D9-CB55-46DD-AA93-FC838A3CA088}"=-
"{312B36C6-F4AE-4794-8A45-61E69715A8CA}"=-
"{05272204-965B-4758-B8B1-E630EA91D1C3}"=-
"{CF530C0F-EF89-4694-BC89-AAD3A48D8770}"=-
"{9C163635-F210-4A9F-BE29-4073CBC9DB35}"=-
"{E3FAC432-C82D-4B8F-8725-AB4040CF177A}"=-
"{F8025330-DC11-4425-8DE2-4A04145D1207}"=-
"{703D167D-1E0D-4762-9799-80FF17F99065}"=-
"{856B51C4-F1A4-4DA7-BFB1-F7BAD1B66496}"=-
"{1E02EC30-1E8B-4281-967A-2602B7E0621E}"=-
"{747ED573-5438-428B-84A5-5EDBBB054910}"=-
"{DE967909-503D-428A-90A4-ED226FD894FA}"=-
"{B63FCEF6-B0CC-4D0E-AB62-B0562C2F22EB}"=-
"{9DAFBFE9-8667-47C3-8313-E6E033013F93}"=-
"{B4E4DF1F-4EE4-4BA2-868C-1CEE5FCDB6FA}"=-
"{E2A60F62-BE7D-4D08-ABA1-A2F0A09B5050}"=-
"{2C7CDAC2-0833-413E-AC2B-63A2F115B410}"=-
"{3B6AC894-EE5B-47E7-9D76-BC153B38C88F}"=-
[-HKEY_CLASSES_ROOT\CLSID\{9720871C-1C91-4D19-9530-3EBF8685423E}]
[-HKEY_CLASSES_ROOT\CLSID\{CF1D5924-40F1-4241-BBCF-B2C82682B25A}]
[-HKEY_CLASSES_ROOT\CLSID\{F0CF68B1-D7E5-473D-9008-0B80E5DF088B}]
[-HKEY_CLASSES_ROOT\CLSID\{27D4821B-D8F0-48B2-89BD-B96161D068D5}]
[-HKEY_CLASSES_ROOT\CLSID\{9624D36B-4DBF-4988-9A2A-81691CCB34D1}]
[-HKEY_CLASSES_ROOT\CLSID\{E0D0CE8B-0067-4F87-8726-F14273F6E63E}]
[-HKEY_CLASSES_ROOT\CLSID\{2CD5DBA9-54D4-490E-8AE8-3490C0CA91B9}]
[-HKEY_CLASSES_ROOT\CLSID\{50D8AF94-93F8-4D07-AEF7-E7E9C2093A7F}]
[-HKEY_CLASSES_ROOT\CLSID\{1974C3D9-CB55-46DD-AA93-FC838A3CA088}]
[-HKEY_CLASSES_ROOT\CLSID\{312B36C6-F4AE-4794-8A45-61E69715A8CA}]
[-HKEY_CLASSES_ROOT\CLSID\{05272204-965B-4758-B8B1-E630EA91D1C3}]
[-HKEY_CLASSES_ROOT\CLSID\{CF530C0F-EF89-4694-BC89-AAD3A48D8770}]
[-HKEY_CLASSES_ROOT\CLSID\{9C163635-F210-4A9F-BE29-4073CBC9DB35}]
[-HKEY_CLASSES_ROOT\CLSID\{E3FAC432-C82D-4B8F-8725-AB4040CF177A}]
[-HKEY_CLASSES_ROOT\CLSID\{F8025330-DC11-4425-8DE2-4A04145D1207}]
[-HKEY_CLASSES_ROOT\CLSID\{703D167D-1E0D-4762-9799-80FF17F99065}]
[-HKEY_CLASSES_ROOT\CLSID\{856B51C4-F1A4-4DA7-BFB1-F7BAD1B66496}]
[-HKEY_CLASSES_ROOT\CLSID\{1E02EC30-1E8B-4281-967A-2602B7E0621E}]
[-HKEY_CLASSES_ROOT\CLSID\{747ED573-5438-428B-84A5-5EDBBB054910}]
[-HKEY_CLASSES_ROOT\CLSID\{DE967909-503D-428A-90A4-ED226FD894FA}]
[-HKEY_CLASSES_ROOT\CLSID\{B63FCEF6-B0CC-4D0E-AB62-B0562C2F22EB}]
[-HKEY_CLASSES_ROOT\CLSID\{9DAFBFE9-8667-47C3-8313-E6E033013F93}]
[-HKEY_CLASSES_ROOT\CLSID\{B4E4DF1F-4EE4-4BA2-868C-1CEE5FCDB6FA}]
[-HKEY_CLASSES_ROOT\CLSID\{E2A60F62-BE7D-4D08-ABA1-A2F0A09B5050}]
[-HKEY_CLASSES_ROOT\CLSID\{2C7CDAC2-0833-413E-AC2B-63A2F115B410}]
[-HKEY_CLASSES_ROOT\CLSID\{3B6AC894-EE5B-47E7-9D76-BC153B38C88F}]
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{BA6A3837-B854-4B8C-92B0-9BFCC80EBBC8}"=-
****************************************************************************
Desktop.ini Contents:
****************************************************************************
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
<IDone>{BA6A3837-B854-4B8C-92B0-9BFCC80EBBC8}</IDone>
<IDtwo>VT00</IDtwo>
<VERSION>200</VERSION>
****************************************************************************
Classid's found from regsearch:
****************************************************************************