Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Look2Me is on my computer, HELP!


  • Please log in to reply

#1
SlappyMuttMutt

SlappyMuttMutt

    Member

  • Member
  • PipPip
  • 22 posts
Help! Getting popups out of nowhere. The popups often include three y's in the URL. I've scanned with webroot, adaware, Spybot, microsoft, trojanhunter, pretty much everything. When scanning with CWShredder the VX2.Look2Me comes up and is "deleted", but everytime I run it its still there. Everytime I restart my PC the DLL file changes names!

Logfile of HijackThis v1.99.1
Scan saved at 1:00:13 AM, on 10/23/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\windows\System32\smss.exe
C:\windows\SYSTEM32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\windows\SYSTEM32\rundll32.exe
C:\Custom\WindowBlinds\wbload.exe
C:\windows\Explorer.EXE
C:\windows\system32\nvsvc32.exe
C:\windows\System32\svchost.exe
C:\Program Files\ASUS\Probe\AsusProb.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Hijack\HijackThis.exe
C:\Hijack\HijackThis.exe

O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O17 - HKLM\System\CCS\Services\Tcpip\..\{184FAE42-36B8-49D1-B442-E3DA4EAE6847}: NameServer = 131.202.1.3,131.202.3.4
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WB - C:\Custom\WINDOW~1\fastload.dll
O20 - Winlogon Notify: WindowsUpdate - C:\windows\system32\gp02l3do1.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe


The problem is: O20 - Winlogon Notify: WindowsUpdate - C:\windows\system32\gp02l3do1.dll
Everytime I boot up the DLL name changes also.

How to remove?



L2MFIX find log 1.04a
These are the registry keys present
********************************************************************************
**
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ShellServiceObjectDelayLoad]
"Asynchronous"=dword:00000000
"DllName"="C:\\windows\\system32\\q6860glse6q60.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WB]
"Asynchronous"=dword:00000000
"DllName"="C:\\Custom\\WINDOW~1\\fastload.dll"
"Startup"="StartSys"
"Logon"="StartWB"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WRNotifier]
"Asynchronous"=dword:00000000
"DllName"="WRLogonNTF.dll"
"Impersonate"=dword:00000001
"Lock"="WRLock"
"StartScreenSaver"="WRStartScreenSaver"
"StartShell"="WRStartShell"
"Startup"="WRStartup"
"StopScreenSaver"="WRStopScreenSaver"
"Unlock"="WRUnlock"
"Shutdown"="WRShutdown"
"Logoff"="WRLogoff"
"Logon"="WRLogon"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
"DLLName"="wzcdlg.dll"
"Logon"="WZCEventLogon"
"Logoff"="WZCEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000000


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER


********************************************************************************
**
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{CD1508FE-CFE5-7B34-E05C-8458C06FE03C}"=""

********************************************************************************
**
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run..."
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People..."
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Web Folders"
"{0006F045-0000-0000-C000-000000000046}"="Microsoft Outlook Custom Icon Handler"
"{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
"{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
"{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
"{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
"{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
"{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
"{B446400D-0030-457b-8F64-422A19605186}"="Logitech Gallery"
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
"{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache"
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
"{32020A01-506E-484D-A2A8-BE3CF17601C3}"="AlcoholShellEx"
"{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802}"="Adobe.Acrobat.ContextMenu"
"{79BC0345-1015-11D2-A299-006008312725}"="blue.shell"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{e57ce731-33e8-4c51-8354-bb4de9d215d1}"="Universal Plug and Play Devices"
"{2F5AC606-70CF-461C-BFE1-734234536262}"="WindowBlinds CPL Extension"
"{A70C977A-BF00-412C-90B7-034C51DA2439}"="NvCpl DesktopContext Class"
"{FFB699E0-306A-11d3-8BD1-00104B6F7516}"="Play on my TV helper"
"{1CDB2949-8F65-4355-8456-263E7C208A5D}"="Desktop Explorer"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}"="Desktop Explorer Menu"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A48}"="nView Desktop Context Menu"
"{EBDF1F20-C829-11D1-8233-FF20AF3E97A9}"="TrojanHunter Menu Shell Extension"
"{7C9D5882-CB4A-4090-96C8-430BFE8B795B}"="Webroot Spy Sweeper Context Menu Integration"
"{A5F1F635-6356-41D8-9B49-4B99C68DF3A6}"=""
"{8964C781-2AF3-470D-96D5-BE38C56AEDCA}"=""

********************************************************************************
**
HKEY ROOT CLASSIDS:
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{A5F1F635-6356-41D8-9B49-4B99C68DF3A6}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A5F1F635-6356-41D8-9B49-4B99C68DF3A6}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A5F1F635-6356-41D8-9B49-4B99C68DF3A6}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A5F1F635-6356-41D8-9B49-4B99C68DF3A6}\InprocServer32]
@="C:\\windows\\system32\\rgmotepg.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{8964C781-2AF3-470D-96D5-BE38C56AEDCA}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8964C781-2AF3-470D-96D5-BE38C56AEDCA}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8964C781-2AF3-470D-96D5-BE38C56AEDCA}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8964C781-2AF3-470D-96D5-BE38C56AEDCA}\InprocServer32]
@="C:\\windows\\system32\\sgcur32(3).dll"
"ThreadingModel"="Apartment"

********************************************************************************
**
Files Found are not all bad files:

C:\WINDOWS\SYSTEM32\
atmtd.dll Fri Oct 21 2005 10:57:58p A.... 687,592 671.48 K
bassmod.dll Fri Oct 14 2005 12:25:18p A.... 34,308 33.50 K
cmdlin~1.dll Wed Sep 7 2005 6:26:22p A.... 98,304 96.00 K
cmdlin~2.dll Fri Oct 21 2005 9:11:24p A.... 43,520 42.50 K
divx.dll Tue Aug 9 2005 7:14:00p A.... 692,736 676.50 K
divx_x~1.dll Tue Aug 9 2005 7:13:52p A.... 688,128 672.00 K
divx_x~2.dll Tue Aug 9 2005 7:13:54p A.... 688,128 672.00 K
divx_x~3.dll Tue Aug 9 2005 7:13:52p A.... 671,744 656.00 K
dpl100.dll Tue Aug 9 2005 7:12:30p A.... 86,016 84.00 K
dpu11.dll Tue Aug 9 2005 7:12:28p A.... 245,760 240.00 K
dpugui11.dll Tue Aug 9 2005 7:12:30p A.... 581,632 568.00 K
dpus11.dll Tue Aug 9 2005 7:12:28p A.... 303,104 296.00 K
dpv11.dll Tue Aug 9 2005 7:12:28p A.... 57,344 56.00 K
dtu100.dll Tue Aug 9 2005 7:12:30p A.... 200,704 196.00 K
islzma.dll Wed Jul 27 2005 4:12:28p A.... 102,912 100.50 K
legitc~1.dll Mon Aug 29 2005 1:27:12p A.... 520,968 508.76 K
libeay32.dll Tue Aug 9 2005 7:13:32p A.... 831,488 812.00 K
m4ls0e~1.dll Sun Oct 23 2005 12:10:22p ..S.R 235,791 230.26 K
mcdmsg4.dll Tue Sep 20 2005 7:50:14p A.... 7,840 7.66 K
mrpriv~1.dll Sun Oct 23 2005 11:53:36a ..... 234,279 228.79 K
n2l8lc~1.dll Sat Oct 22 2005 11:41:54a ..S.R 236,104 230.57 K
nv4_disp.dll Mon Oct 10 2005 9:49:00p A.... 3,921,024 3.74 M
nv4_di~1.dll Mon Oct 10 2005 9:49:00p A.... 3,921,024 3.74 M
nvapi.dll Mon Oct 10 2005 9:49:00p A.... 45,056 44.00 K
nvcod.dll Mon Oct 10 2005 9:49:00p A.... 34,304 33.50 K
nvcodins.dll Mon Oct 10 2005 9:49:00p A.... 34,304 33.50 K
nvcpl.dll Mon Oct 10 2005 9:49:00p A.... 7,286,784 6.95 M
nvhwvid.dll Mon Oct 10 2005 9:49:00p A.... 573,440 560.00 K
nview.dll Mon Oct 10 2005 9:49:00p A.... 1,466,368 1.40 M
nvmccs.dll Mon Oct 10 2005 9:49:00p A.... 229,376 224.00 K
nvmccsrs.dll Mon Oct 10 2005 9:49:00p A.... 45,056 44.00 K
nvmctray.dll Mon Oct 10 2005 9:49:00p A.... 86,016 84.00 K
nvnt4cpl.dll Mon Oct 10 2005 9:49:00p A.... 286,720 280.00 K
nvoglnt.dll Mon Oct 10 2005 9:49:00p A.... 5,378,048 5.13 M
nvrsar.dll Mon Oct 10 2005 9:49:00p A.... 319,488 312.00 K
nvrscs.dll Mon Oct 10 2005 9:49:00p A.... 241,664 236.00 K
nvrsda.dll Mon Oct 10 2005 9:49:00p A.... 245,760 240.00 K
nvrsde.dll Mon Oct 10 2005 9:49:00p A.... 270,336 264.00 K
nvrsel.dll Mon Oct 10 2005 9:49:00p A.... 274,432 268.00 K
nvrseng.dll Mon Oct 10 2005 9:49:00p A.... 241,664 236.00 K
nvrses.dll Mon Oct 10 2005 9:49:00p A.... 274,432 268.00 K
nvrsesm.dll Mon Oct 10 2005 9:49:00p A.... 266,240 260.00 K
nvrsfi.dll Mon Oct 10 2005 9:49:00p A.... 241,664 236.00 K
nvrsfr.dll Mon Oct 10 2005 9:49:00p A.... 278,528 272.00 K
nvrshe.dll Mon Oct 10 2005 9:49:00p A.... 319,488 312.00 K
nvrshu.dll Mon Oct 10 2005 9:49:00p A.... 253,952 248.00 K
nvrsit.dll Mon Oct 10 2005 9:49:00p A.... 274,432 268.00 K
nvrsja.dll Mon Oct 10 2005 9:49:00p A.... 258,048 252.00 K
nvrsko.dll Mon Oct 10 2005 9:49:00p A.... 253,952 248.00 K
nvrsnl.dll Mon Oct 10 2005 9:49:00p A.... 266,240 260.00 K
nvrsno.dll Mon Oct 10 2005 9:49:00p A.... 249,856 244.00 K
nvrspl.dll Mon Oct 10 2005 9:49:00p A.... 249,856 244.00 K
nvrspt.dll Mon Oct 10 2005 9:49:00p A.... 266,240 260.00 K
nvrsptb.dll Mon Oct 10 2005 9:49:00p A.... 262,144 256.00 K
nvrsru.dll Mon Oct 10 2005 9:49:00p A.... 262,144 256.00 K
nvrssk.dll Mon Oct 10 2005 9:49:00p A.... 249,856 244.00 K
nvrssl.dll Mon Oct 10 2005 9:49:00p A.... 249,856 244.00 K
nvrssv.dll Mon Oct 10 2005 9:49:00p A.... 245,760 240.00 K
nvrstr.dll Mon Oct 10 2005 9:49:00p A.... 249,856 244.00 K
nvrszhc.dll Mon Oct 10 2005 9:49:00p A.... 217,088 212.00 K
nvrszht.dll Mon Oct 10 2005 9:49:00p A.... 118,784 116.00 K
nvshell.dll Mon Oct 10 2005 9:49:00p A.... 466,944 456.00 K
nvwddi.dll Mon Oct 10 2005 9:49:00p A.... 81,920 80.00 K
nvwdmcpl.dll Mon Oct 10 2005 9:49:00p A.... 1,662,976 1.59 M
nvwimg.dll Mon Oct 10 2005 9:49:00p A.... 1,019,904 996.00 K
nvwrsar.dll Mon Oct 10 2005 9:49:00p A.... 282,624 276.00 K
nvwrscs.dll Mon Oct 10 2005 9:49:00p A.... 286,720 280.00 K
nvwrsda.dll Mon Oct 10 2005 9:49:00p A.... 294,912 288.00 K
nvwrsde.dll Mon Oct 10 2005 9:49:00p A.... 311,296 304.00 K
nvwrsel.dll Mon Oct 10 2005 9:49:00p A.... 335,872 328.00 K
nvwrseng.dll Mon Oct 10 2005 9:49:00p A.... 286,720 280.00 K
nvwrses.dll Mon Oct 10 2005 9:49:00p A.... 335,872 328.00 K
nvwrsesm.dll Mon Oct 10 2005 9:49:00p A.... 327,680 320.00 K
nvwrsfi.dll Mon Oct 10 2005 9:49:00p A.... 303,104 296.00 K
nvwrsfr.dll Mon Oct 10 2005 9:49:00p A.... 327,680 320.00 K
nvwrshe.dll Mon Oct 10 2005 9:49:00p A.... 278,528 272.00 K
nvwrshu.dll Mon Oct 10 2005 9:49:00p A.... 315,392 308.00 K
nvwrsit.dll Mon Oct 10 2005 9:49:00p A.... 323,584 316.00 K
nvwrsja.dll Mon Oct 10 2005 9:49:00p A.... 212,992 208.00 K
nvwrsko.dll Mon Oct 10 2005 9:49:00p A.... 196,608 192.00 K
nvwrsnl.dll Mon Oct 10 2005 9:49:00p A.... 319,488 312.00 K
nvwrsno.dll Mon Oct 10 2005 9:49:00p A.... 299,008 292.00 K
nvwrspl.dll Mon Oct 10 2005 9:49:00p A.... 294,912 288.00 K
nvwrspt.dll Mon Oct 10 2005 9:49:00p A.... 323,584 316.00 K
nvwrsptb.dll Mon Oct 10 2005 9:49:00p A.... 319,488 312.00 K
nvwrsru.dll Mon Oct 10 2005 9:49:00p A.... 315,392 308.00 K
nvwrssk.dll Mon Oct 10 2005 9:49:00p A.... 299,008 292.00 K
nvwrssl.dll Mon Oct 10 2005 9:49:00p A.... 303,104 296.00 K
nvwrssv.dll Mon Oct 10 2005 9:49:00p A.... 294,912 288.00 K
nvwrstr.dll Mon Oct 10 2005 9:49:00p A.... 303,104 296.00 K
nvwrszhc.dll Mon Oct 10 2005 9:49:00p A.... 163,840 160.00 K
nvwrszht.dll Mon Oct 10 2005 9:49:00p A.... 167,936 164.00 K
q6860g~1.dll Sun Oct 23 2005 11:55:22a ..S.R 235,057 229.55 K
qt-dx331.dll Tue Aug 9 2005 7:12:30p A.... 3,596,288 3.43 M
rgmotepg.dll Sun Oct 23 2005 11:44:56a ..S.R 236,187 230.65 K
sgcur3~1.dll Sun Oct 23 2005 12:10:24p ..S.R 235,057 229.55 K
sirenacm.dll Sat Aug 13 2005 2:41:12p A.... 118,784 116.00 K
ssleay32.dll Tue Aug 9 2005 7:13:32p A.... 159,744 156.00 K
unicows.dll Tue Aug 9 2005 7:13:32p A.... 245,408 239.66 K
uxd99b~1.dll Tue Sep 20 2005 8:24:46p A.... 218,624 213.50 K
uxtheme.dll Tue Sep 20 2005 8:24:46p A.... 218,624 213.50 K

101 items found: 101 files (5 H/S), 0 directories.
Total of file sizes: 53,776,559 bytes 51.29 M
Locate .tmp files:

No matches found.
********************************************************************************
**
Directory Listing of system files:
Volume in drive C is Programs and files
Volume Serial Number is DC1C-18F4

Directory of C:\windows\System32

10/23/2005 12:10 PM 235,057 sgcur32(3).dll
10/23/2005 12:10 PM 235,791 m4ls0e37eh.dll
10/23/2005 11:55 AM 235,057 q6860glse6q60.dll
10/23/2005 11:44 AM 236,187 rgmotepg.dll
10/22/2005 11:41 AM 236,104 n2l8lc3u1f.dll
10/20/2005 12:12 AM <DIR> dllcache
04/27/2005 08:53 PM <DIR> Microsoft
5 File(s) 1,178,196 bytes
2 Dir(s) 26,673,532,928 bytes free

This is my second topic, sorry, the other one wasnt good.

NOTE: The DLL names have changed due to system scan times, I rebooted a few times between the scans, current file is: j8p0li7m18.dll
  • 0

Advertisements


#2
SlappyMuttMutt

SlappyMuttMutt

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts
Bump!
  • 0

#3
infaddict

infaddict

    Visiting Staff

  • Member
  • PipPipPip
  • 734 posts
Hi SlappyMuttMutt,

Welcome to Geeks To Go, my name is infaddict and I will be helping you :tazz:. I am currently reviewing your log and will post back shortly with a fix. Thanks for your patience.
  • 0

#4
infaddict

infaddict

    Visiting Staff

  • Member
  • PipPipPip
  • 734 posts
Hi SlappyMuttMutt :tazz:

You have the latest version of VX2. Please delete any other/old L2mfix downloads from your hard disk and then re-download L2mfix from one of these two locations:

http://www.atribune....oads/l2mfix.exe
http://www.downloads....org/l2mfix.exe

Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!

if you receive, while running option #1, an error similar like: ''C:\windows\system32\cmd.exe
C:\windows\system32\autoexec.nt the system file is not suitable for running ms-dos and microsoft windows applications. choose close to terminate the application.."...then please use option 5 or the web page link in the l2mfix folder to solve this error condition. do not run the fix portion without fixing this first.

  • 0

#5
SlappyMuttMutt

SlappyMuttMutt

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts
Here you go sir.

L2MFIX find log 1.04a
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DateTime]
"Asynchronous"=dword:00000000
"DllName"="C:\\windows\\system32\\gp80l3lm1.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WB]
"Asynchronous"=dword:00000000
"DllName"="C:\\Custom\\WINDOW~1\\fastload.dll"
"Startup"="StartSys"
"Logon"="StartWB"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
"DLLName"="wzcdlg.dll"
"Logon"="WZCEventLogon"
"Logoff"="WZCEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000000


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER


**********************************************************************************
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{CD1508FE-CFE5-7B34-E05C-8458C06FE03C}"=""

**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run..."
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People..."
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Web Folders"
"{0006F045-0000-0000-C000-000000000046}"="Microsoft Outlook Custom Icon Handler"
"{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
"{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
"{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
"{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
"{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
"{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
"{B446400D-0030-457b-8F64-422A19605186}"="Logitech Gallery"
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
"{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache"
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
"{32020A01-506E-484D-A2A8-BE3CF17601C3}"="AlcoholShellEx"
"{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802}"="Adobe.Acrobat.ContextMenu"
"{79BC0345-1015-11D2-A299-006008312725}"="blue.shell"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{e57ce731-33e8-4c51-8354-bb4de9d215d1}"="Universal Plug and Play Devices"
"{2F5AC606-70CF-461C-BFE1-734234536262}"="WindowBlinds CPL Extension"
"{A70C977A-BF00-412C-90B7-034C51DA2439}"="NvCpl DesktopContext Class"
"{FFB699E0-306A-11d3-8BD1-00104B6F7516}"="Play on my TV helper"
"{1CDB2949-8F65-4355-8456-263E7C208A5D}"="Desktop Explorer"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}"="Desktop Explorer Menu"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A48}"="nView Desktop Context Menu"
"{EBDF1F20-C829-11D1-8233-FF20AF3E97A9}"="TrojanHunter Menu Shell Extension"
"{7C9D5882-CB4A-4090-96C8-430BFE8B795B}"="Webroot Spy Sweeper Context Menu Integration"
"{A5F1F635-6356-41D8-9B49-4B99C68DF3A6}"=""
"{8964C781-2AF3-470D-96D5-BE38C56AEDCA}"=""
"{0996FF25-04D3-4F8C-93F8-09B3AEDA5521}"=""
"{20AD043F-D0A6-45DE-8B33-2AC32B8DD2AD}"=""

**********************************************************************************
HKEY ROOT CLASSIDS:
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{A5F1F635-6356-41D8-9B49-4B99C68DF3A6}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A5F1F635-6356-41D8-9B49-4B99C68DF3A6}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A5F1F635-6356-41D8-9B49-4B99C68DF3A6}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A5F1F635-6356-41D8-9B49-4B99C68DF3A6}\InprocServer32]
@="C:\\windows\\system32\\rgmotepg.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{8964C781-2AF3-470D-96D5-BE38C56AEDCA}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8964C781-2AF3-470D-96D5-BE38C56AEDCA}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8964C781-2AF3-470D-96D5-BE38C56AEDCA}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8964C781-2AF3-470D-96D5-BE38C56AEDCA}\InprocServer32]
@="C:\\windows\\system32\\qmsname.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{0996FF25-04D3-4F8C-93F8-09B3AEDA5521}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0996FF25-04D3-4F8C-93F8-09B3AEDA5521}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0996FF25-04D3-4F8C-93F8-09B3AEDA5521}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0996FF25-04D3-4F8C-93F8-09B3AEDA5521}\InprocServer32]
@="C:\\windows\\system32\\wnnsta(6).dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{20AD043F-D0A6-45DE-8B33-2AC32B8DD2AD}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{20AD043F-D0A6-45DE-8B33-2AC32B8DD2AD}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{20AD043F-D0A6-45DE-8B33-2AC32B8DD2AD}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{20AD043F-D0A6-45DE-8B33-2AC32B8DD2AD}\InprocServer32]
@="C:\\windows\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

**********************************************************************************
Files Found are not all bad files:

C:\WINDOWS\SYSTEM32\
atmtd.dll Fri Oct 21 2005 10:57:58p A.... 687,592 671.48 K
bassmod.dll Fri Oct 14 2005 12:25:18p A.... 34,308 33.50 K
cmdlin~1.dll Wed Sep 7 2005 6:26:22p A.... 98,304 96.00 K
cmdlin~2.dll Fri Oct 21 2005 9:11:24p A.... 43,520 42.50 K
divx.dll Tue Aug 9 2005 7:14:00p A.... 692,736 676.50 K
divx_x~1.dll Tue Aug 9 2005 7:13:52p A.... 688,128 672.00 K
divx_x~2.dll Tue Aug 9 2005 7:13:54p A.... 688,128 672.00 K
divx_x~3.dll Tue Aug 9 2005 7:13:52p A.... 671,744 656.00 K
dpl100.dll Tue Aug 9 2005 7:12:30p A.... 86,016 84.00 K
dpu11.dll Tue Aug 9 2005 7:12:28p A.... 245,760 240.00 K
dpugui11.dll Tue Aug 9 2005 7:12:30p A.... 581,632 568.00 K
dpus11.dll Tue Aug 9 2005 7:12:28p A.... 303,104 296.00 K
dpv11.dll Tue Aug 9 2005 7:12:28p A.... 57,344 56.00 K
dtu100.dll Tue Aug 9 2005 7:12:30p A.... 200,704 196.00 K
gp80l3~1.dll Mon Oct 24 2005 6:16:18p ..S.R 236,869 231.32 K
islzma.dll Wed Jul 27 2005 4:12:28p A.... 102,912 100.50 K
legitc~1.dll Mon Aug 29 2005 1:27:12p A.... 520,968 508.76 K
libeay32.dll Tue Aug 9 2005 7:13:32p A.... 831,488 812.00 K
lv0609~1.dll Mon Oct 24 2005 11:24:56a ..S.R 233,552 228.08 K
lvl009~1.dll Tue Oct 25 2005 12:52:04p ..S.R 236,908 231.36 K
mcdmsg4.dll Tue Sep 20 2005 7:50:14p A.... 7,840 7.66 K
mrpriv~1.dll Sun Oct 23 2005 11:53:36a ..... 234,279 228.79 K
n2l8lc~1.dll Sat Oct 22 2005 11:41:54a ..S.R 236,104 230.57 K
nv4_disp.dll Mon Oct 10 2005 9:49:00p A.... 3,921,024 3.74 M
nv4_di~1.dll Mon Oct 10 2005 9:49:00p A.... 3,921,024 3.74 M
nvapi.dll Mon Oct 10 2005 9:49:00p A.... 45,056 44.00 K
nvcod.dll Mon Oct 10 2005 9:49:00p A.... 34,304 33.50 K
nvcodins.dll Mon Oct 10 2005 9:49:00p A.... 34,304 33.50 K
nvcpl.dll Mon Oct 10 2005 9:49:00p A.... 7,286,784 6.95 M
nvhwvid.dll Mon Oct 10 2005 9:49:00p A.... 573,440 560.00 K
nview.dll Mon Oct 10 2005 9:49:00p A.... 1,466,368 1.40 M
nvmccs.dll Mon Oct 10 2005 9:49:00p A.... 229,376 224.00 K
nvmccsrs.dll Mon Oct 10 2005 9:49:00p A.... 45,056 44.00 K
nvmctray.dll Mon Oct 10 2005 9:49:00p A.... 86,016 84.00 K
nvnt4cpl.dll Mon Oct 10 2005 9:49:00p A.... 286,720 280.00 K
nvoglnt.dll Mon Oct 10 2005 9:49:00p A.... 5,378,048 5.13 M
nvrsar.dll Mon Oct 10 2005 9:49:00p A.... 319,488 312.00 K
nvrscs.dll Mon Oct 10 2005 9:49:00p A.... 241,664 236.00 K
nvrsda.dll Mon Oct 10 2005 9:49:00p A.... 245,760 240.00 K
nvrsde.dll Mon Oct 10 2005 9:49:00p A.... 270,336 264.00 K
nvrsel.dll Mon Oct 10 2005 9:49:00p A.... 274,432 268.00 K
nvrseng.dll Mon Oct 10 2005 9:49:00p A.... 241,664 236.00 K
nvrses.dll Mon Oct 10 2005 9:49:00p A.... 274,432 268.00 K
nvrsesm.dll Mon Oct 10 2005 9:49:00p A.... 266,240 260.00 K
nvrsfi.dll Mon Oct 10 2005 9:49:00p A.... 241,664 236.00 K
nvrsfr.dll Mon Oct 10 2005 9:49:00p A.... 278,528 272.00 K
nvrshe.dll Mon Oct 10 2005 9:49:00p A.... 319,488 312.00 K
nvrshu.dll Mon Oct 10 2005 9:49:00p A.... 253,952 248.00 K
nvrsit.dll Mon Oct 10 2005 9:49:00p A.... 274,432 268.00 K
nvrsja.dll Mon Oct 10 2005 9:49:00p A.... 258,048 252.00 K
nvrsko.dll Mon Oct 10 2005 9:49:00p A.... 253,952 248.00 K
nvrsnl.dll Mon Oct 10 2005 9:49:00p A.... 266,240 260.00 K
nvrsno.dll Mon Oct 10 2005 9:49:00p A.... 249,856 244.00 K
nvrspl.dll Mon Oct 10 2005 9:49:00p A.... 249,856 244.00 K
nvrspt.dll Mon Oct 10 2005 9:49:00p A.... 266,240 260.00 K
nvrsptb.dll Mon Oct 10 2005 9:49:00p A.... 262,144 256.00 K
nvrsru.dll Mon Oct 10 2005 9:49:00p A.... 262,144 256.00 K
nvrssk.dll Mon Oct 10 2005 9:49:00p A.... 249,856 244.00 K
nvrssl.dll Mon Oct 10 2005 9:49:00p A.... 249,856 244.00 K
nvrssv.dll Mon Oct 10 2005 9:49:00p A.... 245,760 240.00 K
nvrstr.dll Mon Oct 10 2005 9:49:00p A.... 249,856 244.00 K
nvrszhc.dll Mon Oct 10 2005 9:49:00p A.... 217,088 212.00 K
nvrszht.dll Mon Oct 10 2005 9:49:00p A.... 118,784 116.00 K
nvshell.dll Mon Oct 10 2005 9:49:00p A.... 466,944 456.00 K
nvwddi.dll Mon Oct 10 2005 9:49:00p A.... 81,920 80.00 K
nvwdmcpl.dll Mon Oct 10 2005 9:49:00p A.... 1,662,976 1.59 M
nvwimg.dll Mon Oct 10 2005 9:49:00p A.... 1,019,904 996.00 K
nvwrsar.dll Mon Oct 10 2005 9:49:00p A.... 282,624 276.00 K
nvwrscs.dll Mon Oct 10 2005 9:49:00p A.... 286,720 280.00 K
nvwrsda.dll Mon Oct 10 2005 9:49:00p A.... 294,912 288.00 K
nvwrsde.dll Mon Oct 10 2005 9:49:00p A.... 311,296 304.00 K
nvwrsel.dll Mon Oct 10 2005 9:49:00p A.... 335,872 328.00 K
nvwrseng.dll Mon Oct 10 2005 9:49:00p A.... 286,720 280.00 K
nvwrses.dll Mon Oct 10 2005 9:49:00p A.... 335,872 328.00 K
nvwrsesm.dll Mon Oct 10 2005 9:49:00p A.... 327,680 320.00 K
nvwrsfi.dll Mon Oct 10 2005 9:49:00p A.... 303,104 296.00 K
nvwrsfr.dll Mon Oct 10 2005 9:49:00p A.... 327,680 320.00 K
nvwrshe.dll Mon Oct 10 2005 9:49:00p A.... 278,528 272.00 K
nvwrshu.dll Mon Oct 10 2005 9:49:00p A.... 315,392 308.00 K
nvwrsit.dll Mon Oct 10 2005 9:49:00p A.... 323,584 316.00 K
nvwrsja.dll Mon Oct 10 2005 9:49:00p A.... 212,992 208.00 K
nvwrsko.dll Mon Oct 10 2005 9:49:00p A.... 196,608 192.00 K
nvwrsnl.dll Mon Oct 10 2005 9:49:00p A.... 319,488 312.00 K
nvwrsno.dll Mon Oct 10 2005 9:49:00p A.... 299,008 292.00 K
nvwrspl.dll Mon Oct 10 2005 9:49:00p A.... 294,912 288.00 K
nvwrspt.dll Mon Oct 10 2005 9:49:00p A.... 323,584 316.00 K
nvwrsptb.dll Mon Oct 10 2005 9:49:00p A.... 319,488 312.00 K
nvwrsru.dll Mon Oct 10 2005 9:49:00p A.... 315,392 308.00 K
nvwrssk.dll Mon Oct 10 2005 9:49:00p A.... 299,008 292.00 K
nvwrssl.dll Mon Oct 10 2005 9:49:00p A.... 303,104 296.00 K
nvwrssv.dll Mon Oct 10 2005 9:49:00p A.... 294,912 288.00 K
nvwrstr.dll Mon Oct 10 2005 9:49:00p A.... 303,104 296.00 K
nvwrszhc.dll Mon Oct 10 2005 9:49:00p A.... 163,840 160.00 K
nvwrszht.dll Mon Oct 10 2005 9:49:00p A.... 167,936 164.00 K
qmsname.dll Sun Oct 23 2005 12:53:22p ..S.R 236,869 231.32 K
qt-dx331.dll Tue Aug 9 2005 7:12:30p A.... 3,596,288 3.43 M
rgmotepg.dll Sun Oct 23 2005 11:44:56a ..S.R 236,187 230.65 K
sirenacm.dll Sat Aug 13 2005 2:41:12p A.... 118,784 116.00 K
ssleay32.dll Tue Aug 9 2005 7:13:32p A.... 159,744 156.00 K
unicows.dll Tue Aug 9 2005 7:13:32p A.... 245,408 239.66 K
uxd99b~1.dll Tue Sep 20 2005 8:24:46p A.... 218,624 213.50 K
uxtheme.dll Tue Sep 20 2005 8:24:46p A.... 218,624 213.50 K
wnnsta~1.dll Tue Oct 25 2005 12:52:06p ..S.R 236,869 231.32 K

103 items found: 103 files (7 H/S), 0 directories.
Total of file sizes: 54,251,721 bytes 51.74 M
Locate .tmp files:

No matches found.
**********************************************************************************
Directory Listing of system files:
Volume in drive C is Programs and files
Volume Serial Number is DC1C-18F4

Directory of C:\windows\System32

10/25/2005 12:52 PM 236,869 wnnsta(6).dll
10/25/2005 12:52 PM 236,908 lvl0093me.dll
10/24/2005 06:16 PM 236,869 gp80l3lm1.dll
10/24/2005 11:24 AM 233,552 lv0609dse.dll
10/23/2005 01:20 PM <DIR> dllcache
10/23/2005 12:53 PM 236,869 qmsname.dll
10/23/2005 11:44 AM 236,187 rgmotepg.dll
10/22/2005 11:41 AM 236,104 n2l8lc3u1f.dll
04/27/2005 08:53 PM <DIR> Microsoft
7 File(s) 1,653,358 bytes
2 Dir(s) 39,153,029,120 bytes free
  • 0

#6
infaddict

infaddict

    Visiting Staff

  • Member
  • PipPipPip
  • 734 posts
Close any programs you have open since this step requires a reboot.

From the l2mfix folder on your desktop, double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing enter, then press any key to reboot your computer. After a reboot, your desktop and icons will appear, then disappear (this is normal). L2mfix will continue to scan your computer and when it's finished, notepad will open with a log. Copy the contents of that log and paste it back into this thread, along with a new hijackthis log.

IMPORTANT: Do NOT run any other files in the l2mfix folder unless you are asked to do so!

If after the reboot the desktop icons dont dissappear or the log does not pop up then in the l2mfix folder double click the second.bat file to continue with the fix.
  • 0

#7
SlappyMuttMutt

SlappyMuttMutt

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts
There you go, had to use Second bat file.

L2Mfix 1.04a

Running From:
C:\Documents and Settings\Michel\Desktop\l2mfix



RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER



Setting registry permissions:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!


Denying C(CI) access for predefined group "Administrators"
- adding new ACCESS DENY entry


Registry Permissions set too:

RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(CI) DENY --C------- BUILTIN\Administrators
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER



Setting up for Reboot


Starting Reboot!

Setting Directory
C:\Documents and Settings\Michel\Desktop\l2mfix
System Rebooted!

Running From:
C:\Documents and Settings\Michel\Desktop\l2mfix

killing explorer and rundll32.exe

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 536 'explorer.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 1920 'rundll32.exe'

Scanning First Pass. Please Wait!

First Pass Completed

Second Pass Scanning

Second pass Completed!
Backing Up: C:\windows\system32\cfcdll(2).dll
1 file(s) copied.
Backing Up: C:\windows\system32\lv0609dse.dll
1 file(s) copied.
Backing Up: C:\windows\system32\mrprivs(3).dll
1 file(s) copied.
Backing Up: C:\windows\system32\n2l8lc3u1f.dll
1 file(s) copied.
Backing Up: C:\windows\system32\qmsname.dll
1 file(s) copied.
Backing Up: C:\windows\system32\rgmotepg.dll
1 file(s) copied.
Backing Up: C:\windows\system32\guard.tmp
1 file(s) copied.
deleting: C:\windows\system32\cfcdll(2).dll
Successfully Deleted: C:\windows\system32\cfcdll(2).dll
deleting: C:\windows\system32\lv0609dse.dll
Successfully Deleted: C:\windows\system32\lv0609dse.dll
deleting: C:\windows\system32\mrprivs(3).dll
Successfully Deleted: C:\windows\system32\mrprivs(3).dll
deleting: C:\windows\system32\n2l8lc3u1f.dll
Successfully Deleted: C:\windows\system32\n2l8lc3u1f.dll
deleting: C:\windows\system32\qmsname.dll
Successfully Deleted: C:\windows\system32\qmsname.dll
deleting: C:\windows\system32\rgmotepg.dll
Successfully Deleted: C:\windows\system32\rgmotepg.dll
deleting: C:\windows\system32\guard.tmp


Zipping up files for submission:
adding: cfcdll(2).dll (164 bytes security) (deflated 6%)
adding: lv0609dse.dll (164 bytes security) (deflated 4%)
adding: mrprivs(3).dll (164 bytes security) (deflated 4%)
adding: n2l8lc3u1f.dll (164 bytes security) (deflated 5%)
adding: qmsname.dll (164 bytes security) (deflated 5%)
adding: rgmotepg.dll (164 bytes security) (deflated 5%)
adding: guard.tmp (164 bytes security) (deflated 6%)
adding: clear.reg (164 bytes security) (deflated 51%)
adding: echo.reg (164 bytes security) (deflated 11%)
adding: direct.txt (164 bytes security) (stored 0%)
adding: lo2.txt (164 bytes security) (deflated 77%)
adding: readme.txt (164 bytes security) (deflated 52%)
adding: report.txt (164 bytes security) (deflated 70%)
adding: test.txt (164 bytes security) (deflated 65%)
adding: test2.txt (164 bytes security) (deflated 32%)
adding: test3.txt (164 bytes security) (deflated 32%)
adding: test5.txt (164 bytes security) (deflated 32%)
adding: xfind.txt (164 bytes security) (deflated 58%)
adding: backregs/0996FF25-04D3-4F8C-93F8-09B3AEDA5521.reg (164 bytes security) (deflated 70%)
adding: backregs/20AD043F-D0A6-45DE-8B33-2AC32B8DD2AD.reg (164 bytes security) (deflated 70%)
adding: backregs/8964C781-2AF3-470D-96D5-BE38C56AEDCA.reg (164 bytes security) (deflated 70%)
adding: backregs/A5F1F635-6356-41D8-9B49-4B99C68DF3A6.reg (164 bytes security) (deflated 71%)
adding: backregs/notibac.reg (164 bytes security) (deflated 87%)
adding: backregs/shell.reg (164 bytes security) (deflated 73%)

Restoring Registry Permissions:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!


Revoking access for predefined group "Administrators"
Inherited ACE can not be revoked here!
Inherited ACE can not be revoked here!
Warning (option /rga:(ci)) - There is no ACE to remove!


Registry permissions set too:

RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER


Restoring Sedebugprivilege:

Granting SeDebugPrivilege to Administrators ... successful

Restoring Windows Update Certificates.:

deleting local copy: cfcdll(2).dll
deleting local copy: lv0609dse.dll
deleting local copy: mrprivs(3).dll
deleting local copy: n2l8lc3u1f.dll
deleting local copy: qmsname.dll
deleting local copy: rgmotepg.dll
deleting local copy: guard.tmp

The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Run]
"Asynchronous"=dword:00000000
"DllName"="C:\\windows\\system32\\lvl0093me.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WB]
"Asynchronous"=dword:00000000
"DllName"="C:\\Custom\\WINDOW~1\\fastload.dll"
"Startup"="StartSys"
"Logon"="StartWB"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
"DLLName"="wzcdlg.dll"
"Logon"="WZCEventLogon"
"Logoff"="WZCEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000000


The following are the files found:
****************************************************************************
C:\windows\system32\cfcdll(2).dll
C:\windows\system32\lv0609dse.dll
C:\windows\system32\mrprivs(3).dll
C:\windows\system32\n2l8lc3u1f.dll
C:\windows\system32\qmsname.dll
C:\windows\system32\rgmotepg.dll
C:\windows\system32\guard.tmp

Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{A5F1F635-6356-41D8-9B49-4B99C68DF3A6}"=-
"{8964C781-2AF3-470D-96D5-BE38C56AEDCA}"=-
"{0996FF25-04D3-4F8C-93F8-09B3AEDA5521}"=-
"{20AD043F-D0A6-45DE-8B33-2AC32B8DD2AD}"=-
[-HKEY_CLASSES_ROOT\CLSID\{A5F1F635-6356-41D8-9B49-4B99C68DF3A6}]
[-HKEY_CLASSES_ROOT\CLSID\{8964C781-2AF3-470D-96D5-BE38C56AEDCA}]
[-HKEY_CLASSES_ROOT\CLSID\{0996FF25-04D3-4F8C-93F8-09B3AEDA5521}]
[-HKEY_CLASSES_ROOT\CLSID\{20AD043F-D0A6-45DE-8B33-2AC32B8DD2AD}]
REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"SV1"=""
****************************************************************************
Desktop.ini Contents:
****************************************************************************
****************************************************************************


Logfile of HijackThis v1.99.1
Scan saved at 6:23:54 PM, on 10/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\windows\System32\smss.exe
C:\windows\SYSTEM32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\Custom\WindowBlinds\wbload.exe
C:\windows\system32\nvsvc32.exe
C:\windows\System32\svchost.exe
C:\Program Files\ASUS\Probe\AsusProb.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\windows\system32\ctfmon.exe
C:\windows\SYSTEM32\rundll32.exe
C:\PROGRAM FILES\OPERA\OPERA.EXE
C:\windows\explorer.exe
C:\windows\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Hijack\HijackThis.exe

O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O17 - HKLM\System\CCS\Services\Tcpip\..\{184FAE42-36B8-49D1-B442-E3DA4EAE6847}: NameServer = 131.202.1.3,131.202.3.4
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: Run - C:\windows\system32\lvl0093me.dll
O20 - Winlogon Notify: WB - C:\Custom\WINDOW~1\fastload.dll
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
  • 0

#8
infaddict

infaddict

    Visiting Staff

  • Member
  • PipPipPip
  • 734 posts
Hi SlappyMuttMutt :)

It appears that the infection is still present and has probably changed its name again. We need to redo the #1 part of the fix. Please do the following - do NOT reboot your computer in between steps or after posting your results (if at all possible). I will get back to you asap with the next part of the fix.

Run L2MFix #1

Please can you double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!

if you receive, while running option #1, an error similar like: ''C:\windows\system32\cmd.exe
C:\windows\system32\autoexec.nt the system file is not suitable for running ms-dos and microsoft windows applications. choose close to terminate the application.."...then please use option 5 or the web page link in the l2mfix folder to solve this error condition. do not run the fix portion without fixing this first.



Fresh HJT Log

Please run HijackThis, perform a scan and include the results in your next reply.


Thanks :tazz:
  • 0

#9
SlappyMuttMutt

SlappyMuttMutt

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts
here you go. If its possible, add me to MSN so we can do this faster. Email Address Removed

L2MFIX find log 1.04a
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Setup]
"Asynchronous"=dword:00000000
"DllName"="C:\\windows\\system32\\p64ulgh9164.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WB]
"Asynchronous"=dword:00000000
"DllName"="C:\\Custom\\WINDOW~1\\fastload.dll"
"Startup"="StartSys"
"Logon"="StartWB"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
"DLLName"="wzcdlg.dll"
"Logon"="WZCEventLogon"
"Logoff"="WZCEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000000


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER


**********************************************************************************
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{CD1508FE-CFE5-7B34-E05C-8458C06FE03C}"=""

**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run..."
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People..."
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Web Folders"
"{0006F045-0000-0000-C000-000000000046}"="Microsoft Outlook Custom Icon Handler"
"{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
"{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
"{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
"{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
"{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
"{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
"{B446400D-0030-457b-8F64-422A19605186}"="Logitech Gallery"
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
"{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache"
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
"{32020A01-506E-484D-A2A8-BE3CF17601C3}"="AlcoholShellEx"
"{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802}"="Adobe.Acrobat.ContextMenu"
"{79BC0345-1015-11D2-A299-006008312725}"="blue.shell"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{e57ce731-33e8-4c51-8354-bb4de9d215d1}"="Universal Plug and Play Devices"
"{2F5AC606-70CF-461C-BFE1-734234536262}"="WindowBlinds CPL Extension"
"{A70C977A-BF00-412C-90B7-034C51DA2439}"="NvCpl DesktopContext Class"
"{FFB699E0-306A-11d3-8BD1-00104B6F7516}"="Play on my TV helper"
"{1CDB2949-8F65-4355-8456-263E7C208A5D}"="Desktop Explorer"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}"="Desktop Explorer Menu"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A48}"="nView Desktop Context Menu"
"{EBDF1F20-C829-11D1-8233-FF20AF3E97A9}"="TrojanHunter Menu Shell Extension"
"{7C9D5882-CB4A-4090-96C8-430BFE8B795B}"="Webroot Spy Sweeper Context Menu Integration"
"{F8826F75-5CBA-4F33-994F-B6F3C89ABB04}"=""
"{99B143ED-0440-4986-923E-08E0409A442A}"=""

**********************************************************************************
HKEY ROOT CLASSIDS:
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{F8826F75-5CBA-4F33-994F-B6F3C89ABB04}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{F8826F75-5CBA-4F33-994F-B6F3C89ABB04}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{F8826F75-5CBA-4F33-994F-B6F3C89ABB04}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{F8826F75-5CBA-4F33-994F-B6F3C89ABB04}\InprocServer32]
@="blank"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{99B143ED-0440-4986-923E-08E0409A442A}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{99B143ED-0440-4986-923E-08E0409A442A}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{99B143ED-0440-4986-923E-08E0409A442A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{99B143ED-0440-4986-923E-08E0409A442A}\InprocServer32]
@="C:\\windows\\system32\\wgasf(2).dll"
"ThreadingModel"="Apartment"

**********************************************************************************
Files Found are not all bad files:

C:\WINDOWS\SYSTEM32\
atmtd.dll Fri Oct 21 2005 10:57:58p A.... 687,592 671.48 K
bassmod.dll Fri Oct 14 2005 12:25:18p A.... 34,308 33.50 K
cmdlin~1.dll Wed Sep 7 2005 6:26:22p A.... 98,304 96.00 K
cmdlin~2.dll Fri Oct 21 2005 9:11:24p A.... 43,520 42.50 K
divx.dll Tue Aug 9 2005 7:14:00p A.... 692,736 676.50 K
divx_x~1.dll Tue Aug 9 2005 7:13:52p A.... 688,128 672.00 K
divx_x~2.dll Tue Aug 9 2005 7:13:54p A.... 688,128 672.00 K
divx_x~3.dll Tue Aug 9 2005 7:13:52p A.... 671,744 656.00 K
dpl100.dll Tue Aug 9 2005 7:12:30p A.... 86,016 84.00 K
dpu11.dll Tue Aug 9 2005 7:12:28p A.... 245,760 240.00 K
dpugui11.dll Tue Aug 9 2005 7:12:30p A.... 581,632 568.00 K
dpus11.dll Tue Aug 9 2005 7:12:28p A.... 303,104 296.00 K
dpv11.dll Tue Aug 9 2005 7:12:28p A.... 57,344 56.00 K
dtu100.dll Tue Aug 9 2005 7:12:30p A.... 200,704 196.00 K
legitc~1.dll Mon Aug 29 2005 1:27:12p A.... 520,968 508.76 K
libeay32.dll Tue Aug 9 2005 7:13:32p A.... 831,488 812.00 K
mcdmsg4.dll Tue Sep 20 2005 7:50:14p A.... 7,840 7.66 K
n6p40g~1.dll Wed Oct 26 2005 9:02:18p ..S.R 234,697 229.20 K
nv4_disp.dll Mon Oct 10 2005 9:49:00p A.... 3,921,024 3.74 M
nv4_di~1.dll Mon Oct 10 2005 9:49:00p A.... 3,921,024 3.74 M
nvapi.dll Mon Oct 10 2005 9:49:00p A.... 45,056 44.00 K
nvcod.dll Mon Oct 10 2005 9:49:00p A.... 34,304 33.50 K
nvcodins.dll Mon Oct 10 2005 9:49:00p A.... 34,304 33.50 K
nvcpl.dll Mon Oct 10 2005 9:49:00p A.... 7,286,784 6.95 M
nvhwvid.dll Mon Oct 10 2005 9:49:00p A.... 573,440 560.00 K
nview.dll Mon Oct 10 2005 9:49:00p A.... 1,466,368 1.40 M
nvmccs.dll Mon Oct 10 2005 9:49:00p A.... 229,376 224.00 K
nvmccsrs.dll Mon Oct 10 2005 9:49:00p A.... 45,056 44.00 K
nvmctray.dll Mon Oct 10 2005 9:49:00p A.... 86,016 84.00 K
nvnt4cpl.dll Mon Oct 10 2005 9:49:00p A.... 286,720 280.00 K
nvoglnt.dll Mon Oct 10 2005 9:49:00p A.... 5,378,048 5.13 M
nvrsar.dll Mon Oct 10 2005 9:49:00p A.... 319,488 312.00 K
nvrscs.dll Mon Oct 10 2005 9:49:00p A.... 241,664 236.00 K
nvrsda.dll Mon Oct 10 2005 9:49:00p A.... 245,760 240.00 K
nvrsde.dll Mon Oct 10 2005 9:49:00p A.... 270,336 264.00 K
nvrsel.dll Mon Oct 10 2005 9:49:00p A.... 274,432 268.00 K
nvrseng.dll Mon Oct 10 2005 9:49:00p A.... 241,664 236.00 K
nvrses.dll Mon Oct 10 2005 9:49:00p A.... 274,432 268.00 K
nvrsesm.dll Mon Oct 10 2005 9:49:00p A.... 266,240 260.00 K
nvrsfi.dll Mon Oct 10 2005 9:49:00p A.... 241,664 236.00 K
nvrsfr.dll Mon Oct 10 2005 9:49:00p A.... 278,528 272.00 K
nvrshe.dll Mon Oct 10 2005 9:49:00p A.... 319,488 312.00 K
nvrshu.dll Mon Oct 10 2005 9:49:00p A.... 253,952 248.00 K
nvrsit.dll Mon Oct 10 2005 9:49:00p A.... 274,432 268.00 K
nvrsja.dll Mon Oct 10 2005 9:49:00p A.... 258,048 252.00 K
nvrsko.dll Mon Oct 10 2005 9:49:00p A.... 253,952 248.00 K
nvrsnl.dll Mon Oct 10 2005 9:49:00p A.... 266,240 260.00 K
nvrsno.dll Mon Oct 10 2005 9:49:00p A.... 249,856 244.00 K
nvrspl.dll Mon Oct 10 2005 9:49:00p A.... 249,856 244.00 K
nvrspt.dll Mon Oct 10 2005 9:49:00p A.... 266,240 260.00 K
nvrsptb.dll Mon Oct 10 2005 9:49:00p A.... 262,144 256.00 K
nvrsru.dll Mon Oct 10 2005 9:49:00p A.... 262,144 256.00 K
nvrssk.dll Mon Oct 10 2005 9:49:00p A.... 249,856 244.00 K
nvrssl.dll Mon Oct 10 2005 9:49:00p A.... 249,856 244.00 K
nvrssv.dll Mon Oct 10 2005 9:49:00p A.... 245,760 240.00 K
nvrstr.dll Mon Oct 10 2005 9:49:00p A.... 249,856 244.00 K
nvrszhc.dll Mon Oct 10 2005 9:49:00p A.... 217,088 212.00 K
nvrszht.dll Mon Oct 10 2005 9:49:00p A.... 118,784 116.00 K
nvshell.dll Mon Oct 10 2005 9:49:00p A.... 466,944 456.00 K
nvwddi.dll Mon Oct 10 2005 9:49:00p A.... 81,920 80.00 K
nvwdmcpl.dll Mon Oct 10 2005 9:49:00p A.... 1,662,976 1.59 M
nvwimg.dll Mon Oct 10 2005 9:49:00p A.... 1,019,904 996.00 K
nvwrsar.dll Mon Oct 10 2005 9:49:00p A.... 282,624 276.00 K
nvwrscs.dll Mon Oct 10 2005 9:49:00p A.... 286,720 280.00 K
nvwrsda.dll Mon Oct 10 2005 9:49:00p A.... 294,912 288.00 K
nvwrsde.dll Mon Oct 10 2005 9:49:00p A.... 311,296 304.00 K
nvwrsel.dll Mon Oct 10 2005 9:49:00p A.... 335,872 328.00 K
nvwrseng.dll Mon Oct 10 2005 9:49:00p A.... 286,720 280.00 K
nvwrses.dll Mon Oct 10 2005 9:49:00p A.... 335,872 328.00 K
nvwrsesm.dll Mon Oct 10 2005 9:49:00p A.... 327,680 320.00 K
nvwrsfi.dll Mon Oct 10 2005 9:49:00p A.... 303,104 296.00 K
nvwrsfr.dll Mon Oct 10 2005 9:49:00p A.... 327,680 320.00 K
nvwrshe.dll Mon Oct 10 2005 9:49:00p A.... 278,528 272.00 K
nvwrshu.dll Mon Oct 10 2005 9:49:00p A.... 315,392 308.00 K
nvwrsit.dll Mon Oct 10 2005 9:49:00p A.... 323,584 316.00 K
nvwrsja.dll Mon Oct 10 2005 9:49:00p A.... 212,992 208.00 K
nvwrsko.dll Mon Oct 10 2005 9:49:00p A.... 196,608 192.00 K
nvwrsnl.dll Mon Oct 10 2005 9:49:00p A.... 319,488 312.00 K
nvwrsno.dll Mon Oct 10 2005 9:49:00p A.... 299,008 292.00 K
nvwrspl.dll Mon Oct 10 2005 9:49:00p A.... 294,912 288.00 K
nvwrspt.dll Mon Oct 10 2005 9:49:00p A.... 323,584 316.00 K
nvwrsptb.dll Mon Oct 10 2005 9:49:00p A.... 319,488 312.00 K
nvwrsru.dll Mon Oct 10 2005 9:49:00p A.... 315,392 308.00 K
nvwrssk.dll Mon Oct 10 2005 9:49:00p A.... 299,008 292.00 K
nvwrssl.dll Mon Oct 10 2005 9:49:00p A.... 303,104 296.00 K
nvwrssv.dll Mon Oct 10 2005 9:49:00p A.... 294,912 288.00 K
nvwrstr.dll Mon Oct 10 2005 9:49:00p A.... 303,104 296.00 K
nvwrszhc.dll Mon Oct 10 2005 9:49:00p A.... 163,840 160.00 K
nvwrszht.dll Mon Oct 10 2005 9:49:00p A.... 167,936 164.00 K
p64ulg~1.dll Wed Oct 26 2005 3:07:08p ..S.R 234,221 228.73 K
qt-dx331.dll Tue Aug 9 2005 7:12:30p A.... 3,596,288 3.43 M
sirenacm.dll Sat Aug 13 2005 2:41:12p A.... 118,784 116.00 K
ssleay32.dll Tue Aug 9 2005 7:13:32p A.... 159,744 156.00 K
unicows.dll Tue Aug 9 2005 7:13:32p A.... 245,408 239.66 K
uxd99b~1.dll Tue Sep 20 2005 8:24:46p A.... 218,624 213.50 K
uxtheme.dll Tue Sep 20 2005 8:24:46p A.... 218,624 213.50 K
wgasf(2).dll Wed Oct 26 2005 9:02:18p ..S.R 234,221 228.73 K

97 items found: 97 files (3 H/S), 0 directories.
Total of file sizes: 52,964,311 bytes 50.51 M
Locate .tmp files:

No matches found.
**********************************************************************************
Directory Listing of system files:
Volume in drive C is Programs and files
Volume Serial Number is DC1C-18F4

Directory of C:\windows\System32

10/26/2005 09:02 PM 234,221 wgasf(2).dll
10/26/2005 09:02 PM 234,697 n6p40g7qe6.dll
10/26/2005 03:07 PM 234,221 p64ulgh9164.dll
10/23/2005 01:20 PM <DIR> dllcache
04/27/2005 08:53 PM <DIR> Microsoft
3 File(s) 703,139 bytes
2 Dir(s) 34,705,080,320 bytes free


Logfile of HijackThis v1.99.1
Scan saved at 9:07:22 PM, on 10/26/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\windows\System32\smss.exe
C:\windows\SYSTEM32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\windows\SYSTEM32\rundll32.exe
C:\Custom\WindowBlinds\wbload.exe
C:\windows\Explorer.EXE
C:\windows\system32\nvsvc32.exe
C:\windows\System32\svchost.exe
C:\Program Files\ASUS\Probe\AsusProb.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\windows\System32\rsvp.exe
C:\windows\system32\NOTEPAD.EXE
C:\Program Files\Skype\Phone\Skype.exe
C:\Hijack\HijackThis.exe

O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O17 - HKLM\System\CCS\Services\Tcpip\..\{184FAE42-36B8-49D1-B442-E3DA4EAE6847}: NameServer = 131.202.1.3,131.202.3.4
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: Setup - C:\windows\system32\p64ulgh9164.dll
O20 - Winlogon Notify: WB - C:\Custom\WINDOW~1\fastload.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe

Edited by ScHwErV, 27 October 2005 - 06:19 AM.

  • 0

#10
infaddict

infaddict

    Visiting Staff

  • Member
  • PipPipPip
  • 734 posts
Hi SlappyMuttMutt,

Okay, this one's being a little stubborn. Time to hit it with a hammer :) .

I notice you aren't running a firewall. This means you are wide open to reinfection at all times when you are connected to the internet.

Please download the free version of Zone Alarm and install it. Follow thru the whole installation including any restarts and then read the short tutorial. Zone Alarm will popup a warning box at the bottom right corner of the screen, everytime something tries to access your computer from the outside world, and also whenever your computer tries to reach outside. If you recognise the program requesting access, then you can allow it to do so. If you do not recognise the program, then you must click No.


Please download WebRoot SpySweeper from HERE (It's a 2 week trial):
  • Click the Free Trial link on the right - next to "SpySweeper for Home Computers" to download the program.
  • Double-click the file to install it as follows:
    • Click "Next", read the agreement, Click "Next"
    • Choose "Custom" click "Next".
    • Leave the default installation directory as it is, then click "Next".
    • UNcheck "Run SpySweeper at Windows Startup" and "Add Sweep for Spyware to Windows Explorer Context Menu". Click "Next".
    • On the following screen you can leave the e-mail address field blank, if you wish. Click "Next".
    • Finally, click "Install"
  • Once the program is installed, it will open.
  • It will prompt you to update to the latest definitions, click Yes.
  • Once the definitions are installed, click Sweep Now on the left side.
  • Click the Start button.
  • When it's done scanning, click the Next button.
  • Make sure everything has a check next to it, then click the Next button.
  • It will remove all of the items found.
  • Click Session Log in the upper right corner, copy everything in that window.
  • Click the Summary tab and click Finish.
  • Paste the contents of the session log you copied into your next reply.
Now double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!

if you receive, while running option #1, an error similar like: ''C:\windows\system32\cmd.exe
C:\windows\system32\autoexec.nt the system file is not suitable for running ms-dos and microsoft windows applications. choose close to terminate the application.."...then please use option 5 or the web page link in the l2mfix folder to solve this error condition. do not run the fix portion without fixing this first.



Please reply with :
  • SpySweeper Log
  • L2MFix Log
  • Fresh HijackThis Log
Thanks :tazz:
  • 0

Advertisements


#11
SlappyMuttMutt

SlappyMuttMutt

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts
Ahhh. I already had spysweeper, so I cant update it again. I scanned and nothing at all came up. How can I not have a firewall? My windows one is one, did I somehow disactivate it from hijack?
  • 0

#12
infaddict

infaddict

    Visiting Staff

  • Member
  • PipPipPip
  • 734 posts
Hi SlappyMuttMutt :)

The built in Windows firewall is primative and only blocks incoming traffic. It is important you have a good firewall installed that will stop outgoing traffic from your computer (including spyware). I highly recommend you install ZoneAlarm - it is a free product and I use it personally.

As you have used Spy Sweeper in the past, we will use a free trial of Ewido.

Please download ewido security suite it is a free version of the program.
  • Install ewido security suite
  • When installing, under "Additional Options" uncheck..
    • Install background guard
    • Install scan via context menu
  • Launch ewido, there should be an icon on your desktop, double-click it.
  • The program will now open to the main screen.
  • When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  • You will need to update ewido to the latest definition files.
    • On the left hand side of the main screen click update.
    • Then click on Start Update.
  • The update will start and a progress bar will show the updates being installed.
    (the status bar at the bottom will display ("Update successful")
If you are having problems with the updater, you can use this link to manually update ewido.
ewido manual updates

Now close Ewido and restart your computer, logging into Safe Mode (restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode).

Once in Safe Mode, run Ewido :
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • You will be prompted to clean the first infection.
  • Select "Perform action on all infections", then proceed.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop or a location where you can find it easily.
Close ewido security suite and reboot into Normal Mode.

Now double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!

if you receive, while running option #1, an error similar like: ''C:\windows\system32\cmd.exe
C:\windows\system32\autoexec.nt the system file is not suitable for running ms-dos and microsoft windows applications. choose close to terminate the application.."...then please use option 5 or the web page link in the l2mfix folder to solve this error condition. do not run the fix portion without fixing this first.


Please reply with :
  • Ewido Log
  • L2MFix Log
  • Fresh HijackThis Log
Thanks :tazz:
  • 0

#13
SlappyMuttMutt

SlappyMuttMutt

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts
I really appreciate what your doing...but I don't see the point. I've already scanned my PC with all these programs, ewido, spy sweeper, etc... It finds the dll file, it cannot delete it. When I restart in safemode again, it finds the virus again, under a different name. Can you direct me to the ultimate point of this, because, I do not see it. It clearly will not go away with a simple scan and an l2mfix, because I tried these things before I came here. If I am wrong, please, tell me. What is the end of all this? Direct me to the program and the series of actions please. Instead of asking for a log, just tell me what to do completly, after I scan and analyse the logs, I can perfectly analyse the logs myself. If you don't know what to do, tell me, if I am going offtrack here and we are very close to ending this, let me know, I can be very wrong on this.
  • 0

#14
infaddict

infaddict

    Visiting Staff

  • Member
  • PipPipPip
  • 734 posts
Hi SlappyMuttMutt :)

Can you direct me to the ultimate point of this, because, I do not see it. It clearly will not go away with a simple scan and an l2mfix, because I tried these things before I came here. If I am wrong, please, tell me

The ultimate point is to get you clean, by removing the infected files relating to Look2Me. As I have mentioned before, there's a lot of L2M about at the moment and its getting more resilient to normal scans and even to special fixes such as L2MFix. I am working on several L2M logs at the moment where L2MFix has not worked successfully and by using Spy Sweeper, these have now been cleaned. Of course, you cannot use/update Spy Sweeper as you've used it in the past. This is why I asked you to use Ewido in Safe Mode (Ewido is much more effective in Safe Mode). It should at least hit some of the L2M infection and we can manually remove the rest using other tools and registry fixes.

Instead of asking for a log, just tell me what to do completly, after I scan and analyse the logs, I can perfectly analyse the logs myself

Sadly, its not that easy. I cannot give a complete and full set of instructions because we are dealing with a new and resilient infection, so we have to take it one step at a time, analyse the logs and decide on the next course of action.


I urge you to stick with me and together we can fix this. Please follow my latest set of instructions and post back with the logs requested :tazz:
  • 0

#15
SlappyMuttMutt

SlappyMuttMutt

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts
Did Ewido scan, it says it cleaned it. Restarted, found an other one, of course.

Logfile of HijackThis v1.99.1
Scan saved at 9:17:35 PM, on 10/30/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\windows\System32\smss.exe
C:\windows\SYSTEM32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\Custom\WindowBlinds\wbload.exe
C:\windows\Explorer.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\windows\system32\nvsvc32.exe
C:\windows\System32\svchost.exe
C:\Program Files\ASUS\Probe\AsusProb.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\windows\system32\ctfmon.exe
C:\windows\SYSTEM32\rundll32.exe
\?\C:\windows\system32\WBEM\WMIADAP.EXE
C:\Hijack\HijackThis.exe

O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O17 - HKLM\System\CCS\Services\Tcpip\..\{184FAE42-36B8-49D1-B442-E3DA4EAE6847}: NameServer = 131.202.1.3,131.202.3.4
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WB - C:\Custom\WINDOW~1\fastload.dll
O20 - Winlogon Notify: WebCheck - C:\windows\system32\mv26l9fs1.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe



---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 9:14:13 PM, 10/30/2005
+ Report-Checksum: A44A0ED8

+ Scan result:

[744] C:\windows\system32\wbbcheck(2).dll -> Spyware.Look2Me : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.99:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.100:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.101:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.102:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.103:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.116:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.117:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.119:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.121:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.132:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.133:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.134:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.135:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.142:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.143:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.144:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.147:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.148:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.153:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.160:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.161:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.162:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.163:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.164:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.165:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.166:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.168:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.169:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.170:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.177:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.178:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.193:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.194:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.201:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Bfast : Cleaned with backup
:mozilla.209:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.210:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.253:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.268:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.272:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.273:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.276:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Shopathomeselect : Cleaned with backup
:mozilla.277:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Shopathomeselect : Cleaned with backup
:mozilla.278:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Shopathomeselect : Cleaned with backup
:mozilla.279:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.280:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.281:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Findwhat : Cleaned with backup
:mozilla.282:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.286:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.299:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.308:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.309:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.310:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.311:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.324:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.336:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.337:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.338:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.339:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.347:C:\Documents and Settings\Michel\Application Data\Mozilla\Firefox\Profiles\eut7z0pg.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\WINDOWS\system32\wbbcheck(2).dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\TWljaGVs\asappsrv.dll -> Spyware.CommAd : Cleaned with backup


::Report End

L2MFIX find log 1.04a
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WB]
"Asynchronous"=dword:00000000
"DllName"="C:\\Custom\\WINDOW~1\\fastload.dll"
"Startup"="StartSys"
"Logon"="StartWB"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WebCheck]
"Asynchronous"=dword:00000000
"DllName"="C:\\windows\\system32\\mv26l9fs1.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WRNotifier]
"Asynchronous"=dword:00000000
"DllName"="WRLogonNTF.dll"
"Impersonate"=dword:00000001
"Lock"="WRLock"
"StartScreenSaver"="WRStartScreenSaver"
"StartShell"="WRStartShell"
"Startup"="WRStartup"
"StopScreenSaver"="WRStopScreenSaver"
"Unlock"="WRUnlock"
"Shutdown"="WRShutdown"
"Logoff"="WRLogoff"
"Logon"="WRLogon"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
"DLLName"="wzcdlg.dll"
"Logon"="WZCEventLogon"
"Logoff"="WZCEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000000


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER


**********************************************************************************
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{CD1508FE-CFE5-7B34-E05C-8458C06FE03C}"=""

**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run..."
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People..."
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Web Folders"
"{0006F045-0000-0000-C000-000000000046}"="Microsoft Outlook Custom Icon Handler"
"{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
"{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
"{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
"{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
"{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
"{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
"{B446400D-0030-457b-8F64-422A19605186}"="Logitech Gallery"
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
"{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache"
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
"{32020A01-506E-484D-A2A8-BE3CF17601C3}"="AlcoholShellEx"
"{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802}"="Adobe.Acrobat.ContextMenu"
"{79BC0345-1015-11D2-A299-006008312725}"="blue.shell"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{e57ce731-33e8-4c51-8354-bb4de9d215d1}"="Universal Plug and Play Devices"
"{2F5AC606-70CF-461C-BFE1-734234536262}"="WindowBlinds CPL Extension"
"{A70C977A-BF00-412C-90B7-034C51DA2439}"="NvCpl DesktopContext Class"
"{FFB699E0-306A-11d3-8BD1-00104B6F7516}"="Play on my TV helper"
"{1CDB2949-8F65-4355-8456-263E7C208A5D}"="Desktop Explorer"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}"="Desktop Explorer Menu"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A48}"="nView Desktop Context Menu"
"{EBDF1F20-C829-11D1-8233-FF20AF3E97A9}"="TrojanHunter Menu Shell Extension"
"{F8826F75-5CBA-4F33-994F-B6F3C89ABB04}"=""
"{99B143ED-0440-4986-923E-08E0409A442A}"=""
"{F9FADD8C-8C69-4DD5-A582-94C290B97123}"=""
"{6C12A71C-2BE0-4CB2-BA0C-B158D2DF1FCE}"=""
"{5451B8B4-BCB0-4B9A-9F87-6A3014610C31}"=""

**********************************************************************************
HKEY ROOT CLASSIDS:
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{F8826F75-5CBA-4F33-994F-B6F3C89ABB04}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{F8826F75-5CBA-4F33-994F-B6F3C89ABB04}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{F8826F75-5CBA-4F33-994F-B6F3C89ABB04}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{F8826F75-5CBA-4F33-994F-B6F3C89ABB04}\InprocServer32]
@="blank"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{99B143ED-0440-4986-923E-08E0409A442A}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{99B143ED-0440-4986-923E-08E0409A442A}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{99B143ED-0440-4986-923E-08E0409A442A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{99B143ED-0440-4986-923E-08E0409A442A}\InprocServer32]
@="C:\\windows\\system32\\mggsvc.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{F9FADD8C-8C69-4DD5-A582-94C290B97123}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{F9FADD8C-8C69-4DD5-A582-94C290B97123}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{F9FADD8C-8C69-4DD5-A582-94C290B97123}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{F9FADD8C-8C69-4DD5-A582-94C290B97123}\InprocServer32]
@="C:\\windows\\system32\\cwmpobj.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{6C12A71C-2BE0-4CB2-BA0C-B158D2DF1FCE}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{6C12A71C-2BE0-4CB2-BA0C-B158D2DF1FCE}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{6C12A71C-2BE0-4CB2-BA0C-B158D2DF1FCE}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{6C12A71C-2BE0-4CB2-BA0C-B158D2DF1FCE}\InprocServer32]
@="C:\\windows\\system32\\cDbview.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{5451B8B4-BCB0-4B9A-9F87-6A3014610C31}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{5451B8B4-BCB0-4B9A-9F87-6A3014610C31}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{5451B8B4-BCB0-4B9A-9F87-6A3014610C31}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{5451B8B4-BCB0-4B9A-9F87-6A3014610C31}\InprocServer32]
@="C:\\windows\\system32\\wbbcheck(2).dll"
"ThreadingModel"="Apartment"

**********************************************************************************
Files Found are not all bad files:

C:\WINDOWS\SYSTEM32\
atmtd.dll Fri Oct 21 2005 9:57:58p A.... 687,592 671.48 K
bassmod.dll Fri Oct 14 2005 11:25:18a A.... 34,308 33.50 K
cmdlin~1.dll Wed Sep 7 2005 5:26:22p A.... 98,304 96.00 K
cmdlin~2.dll Fri Oct 21 2005 8:11:24p A.... 43,520 42.50 K
divx.dll Tue Aug 9 2005 6:14:00p A.... 692,736 676.50 K
divx_x~1.dll Tue Aug 9 2005 6:13:52p A.... 688,128 672.00 K
divx_x~2.dll Tue Aug 9 2005 6:13:54p A.... 688,128 672.00 K
divx_x~3.dll Tue Aug 9 2005 6:13:52p A.... 671,744 656.00 K
dpl100.dll Tue Aug 9 2005 6:12:30p A.... 86,016 84.00 K
dpu11.dll Tue Aug 9 2005 6:12:28p A.... 245,760 240.00 K
dpugui11.dll Tue Aug 9 2005 6:12:30p A.... 581,632 568.00 K
dpus11.dll Tue Aug 9 2005 6:12:28p A.... 303,104 296.00 K
dpv11.dll Tue Aug 9 2005 6:12:28p A.... 57,344 56.00 K
dtu100.dll Tue Aug 9 2005 6:12:30p A.... 200,704 196.00 K
legitc~1.dll Mon Aug 29 2005 12:27:12p A.... 520,968 508.76 K
libeay32.dll Tue Aug 9 2005 6:13:32p A.... 831,488 812.00 K
mcdmsg4.dll Tue Sep 20 2005 6:50:14p A.... 7,840 7.66 K
mggsvc.dll Sun Oct 30 2005 9:16:04p ..... 235,703 230.18 K
mv26l9~1.dll Sun Oct 30 2005 8:46:32p ..S.R 235,703 230.18 K
nv4_disp.dll Mon Oct 10 2005 8:49:00p A.... 3,921,024 3.74 M
nv4_di~1.dll Mon Oct 10 2005 8:49:00p A.... 3,921,024 3.74 M
nvapi.dll Mon Oct 10 2005 8:49:00p A.... 45,056 44.00 K
nvcod.dll Mon Oct 10 2005 8:49:00p A.... 34,304 33.50 K
nvcodins.dll Mon Oct 10 2005 8:49:00p A.... 34,304 33.50 K
nvcpl.dll Mon Oct 10 2005 8:49:00p A.... 7,286,784 6.95 M
nvhwvid.dll Mon Oct 10 2005 8:49:00p A.... 573,440 560.00 K
nview.dll Mon Oct 10 2005 8:49:00p A.... 1,466,368 1.40 M
nvmccs.dll Mon Oct 10 2005 8:49:00p A.... 229,376 224.00 K
nvmccsrs.dll Mon Oct 10 2005 8:49:00p A.... 45,056 44.00 K
nvmctray.dll Mon Oct 10 2005 8:49:00p A.... 86,016 84.00 K
nvnt4cpl.dll Mon Oct 10 2005 8:49:00p A.... 286,720 280.00 K
nvoglnt.dll Mon Oct 10 2005 8:49:00p A.... 5,378,048 5.13 M
nvrsar.dll Mon Oct 10 2005 8:49:00p A.... 319,488 312.00 K
nvrscs.dll Mon Oct 10 2005 8:49:00p A.... 241,664 236.00 K
nvrsda.dll Mon Oct 10 2005 8:49:00p A.... 245,760 240.00 K
nvrsde.dll Mon Oct 10 2005 8:49:00p A.... 270,336 264.00 K
nvrsel.dll Mon Oct 10 2005 8:49:00p A.... 274,432 268.00 K
nvrseng.dll Mon Oct 10 2005 8:49:00p A.... 241,664 236.00 K
nvrses.dll Mon Oct 10 2005 8:49:00p A.... 274,432 268.00 K
nvrsesm.dll Mon Oct 10 2005 8:49:00p A.... 266,240 260.00 K
nvrsfi.dll Mon Oct 10 2005 8:49:00p A.... 241,664 236.00 K
nvrsfr.dll Mon Oct 10 2005 8:49:00p A.... 278,528 272.00 K
nvrshe.dll Mon Oct 10 2005 8:49:00p A.... 319,488 312.00 K
nvrshu.dll Mon Oct 10 2005 8:49:00p A.... 253,952 248.00 K
nvrsit.dll Mon Oct 10 2005 8:49:00p A.... 274,432 268.00 K
nvrsja.dll Mon Oct 10 2005 8:49:00p A.... 258,048 252.00 K
nvrsko.dll Mon Oct 10 2005 8:49:00p A.... 253,952 248.00 K
nvrsnl.dll Mon Oct 10 2005 8:49:00p A.... 266,240 260.00 K
nvrsno.dll Mon Oct 10 2005 8:49:00p A.... 249,856 244.00 K
nvrspl.dll Mon Oct 10 2005 8:49:00p A.... 249,856 244.00 K
nvrspt.dll Mon Oct 10 2005 8:49:00p A.... 266,240 260.00 K
nvrsptb.dll Mon Oct 10 2005 8:49:00p A.... 262,144 256.00 K
nvrsru.dll Mon Oct 10 2005 8:49:00p A.... 262,144 256.00 K
nvrssk.dll Mon Oct 10 2005 8:49:00p A.... 249,856 244.00 K
nvrssl.dll Mon Oct 10 2005 8:49:00p A.... 249,856 244.00 K
nvrssv.dll Mon Oct 10 2005 8:49:00p A.... 245,760 240.00 K
nvrstr.dll Mon Oct 10 2005 8:49:00p A.... 249,856 244.00 K
nvrszhc.dll Mon Oct 10 2005 8:49:00p A.... 217,088 212.00 K
nvrszht.dll Mon Oct 10 2005 8:49:00p A.... 118,784 116.00 K
nvshell.dll Mon Oct 10 2005 8:49:00p A.... 466,944 456.00 K
nvwddi.dll Mon Oct 10 2005 8:49:00p A.... 81,920 80.00 K
nvwdmcpl.dll Mon Oct 10 2005 8:49:00p A.... 1,662,976 1.59 M
nvwimg.dll Mon Oct 10 2005 8:49:00p A.... 1,019,904 996.00 K
nvwrsar.dll Mon Oct 10 2005 8:49:00p A.... 282,624 276.00 K
nvwrscs.dll Mon Oct 10 2005 8:49:00p A.... 286,720 280.00 K
nvwrsda.dll Mon Oct 10 2005 8:49:00p A.... 294,912 288.00 K
nvwrsde.dll Mon Oct 10 2005 8:49:00p A.... 311,296 304.00 K
nvwrsel.dll Mon Oct 10 2005 8:49:00p A.... 335,872 328.00 K
nvwrseng.dll Mon Oct 10 2005 8:49:00p A.... 286,720 280.00 K
nvwrses.dll Mon Oct 10 2005 8:49:00p A.... 335,872 328.00 K
nvwrsesm.dll Mon Oct 10 2005 8:49:00p A.... 327,680 320.00 K
nvwrsfi.dll Mon Oct 10 2005 8:49:00p A.... 303,104 296.00 K
nvwrsfr.dll Mon Oct 10 2005 8:49:00p A.... 327,680 320.00 K
nvwrshe.dll Mon Oct 10 2005 8:49:00p A.... 278,528 272.00 K
nvwrshu.dll Mon Oct 10 2005 8:49:00p A.... 315,392 308.00 K
nvwrsit.dll Mon Oct 10 2005 8:49:00p A.... 323,584 316.00 K
nvwrsja.dll Mon Oct 10 2005 8:49:00p A.... 212,992 208.00 K
nvwrsko.dll Mon Oct 10 2005 8:49:00p A.... 196,608 192.00 K
nvwrsnl.dll Mon Oct 10 2005 8:49:00p A.... 319,488 312.00 K
nvwrsno.dll Mon Oct 10 2005 8:49:00p A.... 299,008 292.00 K
nvwrspl.dll Mon Oct 10 2005 8:49:00p A.... 294,912 288.00 K
nvwrspt.dll Mon Oct 10 2005 8:49:00p A.... 323,584 316.00 K
nvwrsptb.dll Mon Oct 10 2005 8:49:00p A.... 319,488 312.00 K
nvwrsru.dll Mon Oct 10 2005 8:49:00p A.... 315,392 308.00 K
nvwrssk.dll Mon Oct 10 2005 8:49:00p A.... 299,008 292.00 K
nvwrssl.dll Mon Oct 10 2005 8:49:00p A.... 303,104 296.00 K
nvwrssv.dll Mon Oct 10 2005 8:49:00p A.... 294,912 288.00 K
nvwrstr.dll Mon Oct 10 2005 8:49:00p A.... 303,104 296.00 K
nvwrszhc.dll Mon Oct 10 2005 8:49:00p A.... 163,840 160.00 K
nvwrszht.dll Mon Oct 10 2005 8:49:00p A.... 167,936 164.00 K
q2680c~1.dll Sun Oct 30 2005 9:16:04p ..S.R 236,565 231.02 K
qt-dx331.dll Tue Aug 9 2005 6:12:30p A.... 3,596,288 3.43 M
sirenacm.dll Sat Aug 13 2005 1:41:12p A.... 118,784 116.00 K
ssleay32.dll Tue Aug 9 2005 6:13:32p A.... 159,744 156.00 K
unicows.dll Tue Aug 9 2005 6:13:32p A.... 245,408 239.66 K
uxd99b~1.dll Tue Sep 20 2005 7:24:46p A.... 218,624 213.50 K
uxtheme.dll Tue Sep 20 2005 7:24:46p A.... 218,624 213.50 K

97 items found: 97 files (2 H/S), 0 directories.
Total of file sizes: 52,969,143 bytes 50.51 M
Locate .tmp files:

C:\WINDOWS\SYSTEM32\
__dele~1.tmp Sun Oct 30 2005 9:17:04p A.... 235,703 230.18 K

1 item found: 1 file, 0 directories.
Total of file sizes: 235,703 bytes 230.18 K
**********************************************************************************
Directory Listing of system files:
Volume in drive C is Programs and files
Volume Serial Number is DC1C-18F4

Directory of C:\windows\System32

10/30/2005 09:16 PM 236,565 q2680cjuefo80.dll
10/30/2005 08:46 PM 235,703 mv26l9fs1.dll
10/23/2005 12:20 PM <DIR> dllcache
04/27/2005 07:53 PM <DIR> Microsoft
2 File(s) 472,268 bytes
2 Dir(s) 32,861,806,592 bytes free


Enjoy!
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP