Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

HELP ME! Infected with Look2me? HELP!


  • Please log in to reply

#1
SlappyMuttMutt

SlappyMuttMutt

    Member

  • Member
  • PipPip
  • 22 posts
I am getting annoying popups :tazz: Often including yyy in URL. I think the problem is O20 - Winlogon Notify: URL - C:\windows\system32\enrol1931.dll

The DLL file changes everytime I startup my PC :) I tried the l2mfix second option, to fix, and when it boots up I dont get any log. Don't know if that is good or not...HELP!!!


Logfile of HijackThis v1.99.1
Scan saved at 12:04:49 AM, on 10/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\windows\System32\smss.exe
C:\windows\SYSTEM32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\windows\SYSTEM32\rundll32.exe
C:\Custom\WindowBlinds\wbload.exe
C:\windows\Explorer.EXE
C:\windows\system32\nvsvc32.exe
C:\windows\System32\svchost.exe
C:\Program Files\ASUS\Probe\AsusProb.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\windows\system32\ctfmon.exe
C:\PROGRAM FILES\OPERA\OPERA.EXE
C:\Program Files\ShareScan\ShareScan 2.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\windows\System32\rsvp.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Hijack\HijackThis.exe

O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O17 - HKLM\System\CCS\Services\Tcpip\..\{184FAE42-36B8-49D1-B442-E3DA4EAE6847}: NameServer = 131.202.1.3,131.202.3.4
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: URL - C:\windows\system32\enrol1931.dll
O20 - Winlogon Notify: WB - C:\Custom\WINDOW~1\fastload.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe





L2MFIX find log 1.04a
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\URL]
"Asynchronous"=dword:00000000
"DllName"="C:\\windows\\system32\\enrol1931.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WB]
"Asynchronous"=dword:00000000
"DllName"="C:\\Custom\\WINDOW~1\\fastload.dll"
"Startup"="StartSys"
"Logon"="StartWB"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
"DLLName"="wzcdlg.dll"
"Logon"="WZCEventLogon"
"Logoff"="WZCEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000000


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER


**********************************************************************************
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{CD1508FE-CFE5-7B34-E05C-8458C06FE03C}"=""

**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run..."
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People..."
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Web Folders"
"{0006F045-0000-0000-C000-000000000046}"="Microsoft Outlook Custom Icon Handler"
"{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
"{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
"{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
"{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
"{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
"{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
"{B446400D-0030-457b-8F64-422A19605186}"="Logitech Gallery"
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
"{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache"
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
"{32020A01-506E-484D-A2A8-BE3CF17601C3}"="AlcoholShellEx"
"{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802}"="Adobe.Acrobat.ContextMenu"
"{79BC0345-1015-11D2-A299-006008312725}"="blue.shell"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{e57ce731-33e8-4c51-8354-bb4de9d215d1}"="Universal Plug and Play Devices"
"{2F5AC606-70CF-461C-BFE1-734234536262}"="WindowBlinds CPL Extension"
"{A70C977A-BF00-412C-90B7-034C51DA2439}"="NvCpl DesktopContext Class"
"{FFB699E0-306A-11d3-8BD1-00104B6F7516}"="Play on my TV helper"
"{1CDB2949-8F65-4355-8456-263E7C208A5D}"="Desktop Explorer"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}"="Desktop Explorer Menu"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A48}"="nView Desktop Context Menu"
"{EBDF1F20-C829-11D1-8233-FF20AF3E97A9}"="TrojanHunter Menu Shell Extension"
"{7C9D5882-CB4A-4090-96C8-430BFE8B795B}"="Webroot Spy Sweeper Context Menu Integration"
"{A5F1F635-6356-41D8-9B49-4B99C68DF3A6}"=""
"{8964C781-2AF3-470D-96D5-BE38C56AEDCA}"=""
"{0996FF25-04D3-4F8C-93F8-09B3AEDA5521}"=""
"{20AD043F-D0A6-45DE-8B33-2AC32B8DD2AD}"=""

**********************************************************************************
HKEY ROOT CLASSIDS:
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{A5F1F635-6356-41D8-9B49-4B99C68DF3A6}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A5F1F635-6356-41D8-9B49-4B99C68DF3A6}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A5F1F635-6356-41D8-9B49-4B99C68DF3A6}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A5F1F635-6356-41D8-9B49-4B99C68DF3A6}\InprocServer32]
@="C:\\windows\\system32\\rgmotepg.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{8964C781-2AF3-470D-96D5-BE38C56AEDCA}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8964C781-2AF3-470D-96D5-BE38C56AEDCA}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8964C781-2AF3-470D-96D5-BE38C56AEDCA}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8964C781-2AF3-470D-96D5-BE38C56AEDCA}\InprocServer32]
@="C:\\windows\\system32\\qmsname.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{0996FF25-04D3-4F8C-93F8-09B3AEDA5521}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0996FF25-04D3-4F8C-93F8-09B3AEDA5521}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0996FF25-04D3-4F8C-93F8-09B3AEDA5521}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0996FF25-04D3-4F8C-93F8-09B3AEDA5521}\InprocServer32]
@="C:\\windows\\system32\\cEtsrv(2).dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{20AD043F-D0A6-45DE-8B33-2AC32B8DD2AD}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{20AD043F-D0A6-45DE-8B33-2AC32B8DD2AD}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{20AD043F-D0A6-45DE-8B33-2AC32B8DD2AD}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{20AD043F-D0A6-45DE-8B33-2AC32B8DD2AD}\InprocServer32]
@="C:\\windows\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

**********************************************************************************
Files Found are not all bad files:

C:\WINDOWS\SYSTEM32\
atmtd.dll Fri Oct 21 2005 10:57:58p A.... 687,592 671.48 K
bassmod.dll Fri Oct 14 2005 12:25:18p A.... 34,308 33.50 K
cetsrv~1.dll Mon Oct 24 2005 10:13:34p ..S.R 236,869 231.32 K
cmdlin~1.dll Wed Sep 7 2005 6:26:22p A.... 98,304 96.00 K
cmdlin~2.dll Fri Oct 21 2005 9:11:24p A.... 43,520 42.50 K
divx.dll Tue Aug 9 2005 7:14:00p A.... 692,736 676.50 K
divx_x~1.dll Tue Aug 9 2005 7:13:52p A.... 688,128 672.00 K
divx_x~2.dll Tue Aug 9 2005 7:13:54p A.... 688,128 672.00 K
divx_x~3.dll Tue Aug 9 2005 7:13:52p A.... 671,744 656.00 K
dpl100.dll Tue Aug 9 2005 7:12:30p A.... 86,016 84.00 K
dpu11.dll Tue Aug 9 2005 7:12:28p A.... 245,760 240.00 K
dpugui11.dll Tue Aug 9 2005 7:12:30p A.... 581,632 568.00 K
dpus11.dll Tue Aug 9 2005 7:12:28p A.... 303,104 296.00 K
dpv11.dll Tue Aug 9 2005 7:12:28p A.... 57,344 56.00 K
dtu100.dll Tue Aug 9 2005 7:12:30p A.... 200,704 196.00 K
enrol1~1.dll Mon Oct 24 2005 12:57:56p ..S.R 236,869 231.32 K
gp80l3~1.dll Mon Oct 24 2005 6:16:18p ..S.R 236,869 231.32 K
islzma.dll Wed Jul 27 2005 4:12:28p A.... 102,912 100.50 K
legitc~1.dll Mon Aug 29 2005 1:27:12p A.... 520,968 508.76 K
libeay32.dll Tue Aug 9 2005 7:13:32p A.... 831,488 812.00 K
lv0609~1.dll Mon Oct 24 2005 11:24:56a ..S.R 233,552 228.08 K
mcdmsg4.dll Tue Sep 20 2005 7:50:14p A.... 7,840 7.66 K
mrpriv~1.dll Sun Oct 23 2005 11:53:36a ..... 234,279 228.79 K
n2l8lc~1.dll Sat Oct 22 2005 11:41:54a ..S.R 236,104 230.57 K
nv4_disp.dll Mon Oct 10 2005 9:49:00p A.... 3,921,024 3.74 M
nv4_di~1.dll Mon Oct 10 2005 9:49:00p A.... 3,921,024 3.74 M
nvapi.dll Mon Oct 10 2005 9:49:00p A.... 45,056 44.00 K
nvcod.dll Mon Oct 10 2005 9:49:00p A.... 34,304 33.50 K
nvcodins.dll Mon Oct 10 2005 9:49:00p A.... 34,304 33.50 K
nvcpl.dll Mon Oct 10 2005 9:49:00p A.... 7,286,784 6.95 M
nvhwvid.dll Mon Oct 10 2005 9:49:00p A.... 573,440 560.00 K
nview.dll Mon Oct 10 2005 9:49:00p A.... 1,466,368 1.40 M
nvmccs.dll Mon Oct 10 2005 9:49:00p A.... 229,376 224.00 K
nvmccsrs.dll Mon Oct 10 2005 9:49:00p A.... 45,056 44.00 K
nvmctray.dll Mon Oct 10 2005 9:49:00p A.... 86,016 84.00 K
nvnt4cpl.dll Mon Oct 10 2005 9:49:00p A.... 286,720 280.00 K
nvoglnt.dll Mon Oct 10 2005 9:49:00p A.... 5,378,048 5.13 M
nvrsar.dll Mon Oct 10 2005 9:49:00p A.... 319,488 312.00 K
nvrscs.dll Mon Oct 10 2005 9:49:00p A.... 241,664 236.00 K
nvrsda.dll Mon Oct 10 2005 9:49:00p A.... 245,760 240.00 K
nvrsde.dll Mon Oct 10 2005 9:49:00p A.... 270,336 264.00 K
nvrsel.dll Mon Oct 10 2005 9:49:00p A.... 274,432 268.00 K
nvrseng.dll Mon Oct 10 2005 9:49:00p A.... 241,664 236.00 K
nvrses.dll Mon Oct 10 2005 9:49:00p A.... 274,432 268.00 K
nvrsesm.dll Mon Oct 10 2005 9:49:00p A.... 266,240 260.00 K
nvrsfi.dll Mon Oct 10 2005 9:49:00p A.... 241,664 236.00 K
nvrsfr.dll Mon Oct 10 2005 9:49:00p A.... 278,528 272.00 K
nvrshe.dll Mon Oct 10 2005 9:49:00p A.... 319,488 312.00 K
nvrshu.dll Mon Oct 10 2005 9:49:00p A.... 253,952 248.00 K
nvrsit.dll Mon Oct 10 2005 9:49:00p A.... 274,432 268.00 K
nvrsja.dll Mon Oct 10 2005 9:49:00p A.... 258,048 252.00 K
nvrsko.dll Mon Oct 10 2005 9:49:00p A.... 253,952 248.00 K
nvrsnl.dll Mon Oct 10 2005 9:49:00p A.... 266,240 260.00 K
nvrsno.dll Mon Oct 10 2005 9:49:00p A.... 249,856 244.00 K
nvrspl.dll Mon Oct 10 2005 9:49:00p A.... 249,856 244.00 K
nvrspt.dll Mon Oct 10 2005 9:49:00p A.... 266,240 260.00 K
nvrsptb.dll Mon Oct 10 2005 9:49:00p A.... 262,144 256.00 K
nvrsru.dll Mon Oct 10 2005 9:49:00p A.... 262,144 256.00 K
nvrssk.dll Mon Oct 10 2005 9:49:00p A.... 249,856 244.00 K
nvrssl.dll Mon Oct 10 2005 9:49:00p A.... 249,856 244.00 K
nvrssv.dll Mon Oct 10 2005 9:49:00p A.... 245,760 240.00 K
nvrstr.dll Mon Oct 10 2005 9:49:00p A.... 249,856 244.00 K
nvrszhc.dll Mon Oct 10 2005 9:49:00p A.... 217,088 212.00 K
nvrszht.dll Mon Oct 10 2005 9:49:00p A.... 118,784 116.00 K
nvshell.dll Mon Oct 10 2005 9:49:00p A.... 466,944 456.00 K
nvwddi.dll Mon Oct 10 2005 9:49:00p A.... 81,920 80.00 K
nvwdmcpl.dll Mon Oct 10 2005 9:49:00p A.... 1,662,976 1.59 M
nvwimg.dll Mon Oct 10 2005 9:49:00p A.... 1,019,904 996.00 K
nvwrsar.dll Mon Oct 10 2005 9:49:00p A.... 282,624 276.00 K
nvwrscs.dll Mon Oct 10 2005 9:49:00p A.... 286,720 280.00 K
nvwrsda.dll Mon Oct 10 2005 9:49:00p A.... 294,912 288.00 K
nvwrsde.dll Mon Oct 10 2005 9:49:00p A.... 311,296 304.00 K
nvwrsel.dll Mon Oct 10 2005 9:49:00p A.... 335,872 328.00 K
nvwrseng.dll Mon Oct 10 2005 9:49:00p A.... 286,720 280.00 K
nvwrses.dll Mon Oct 10 2005 9:49:00p A.... 335,872 328.00 K
nvwrsesm.dll Mon Oct 10 2005 9:49:00p A.... 327,680 320.00 K
nvwrsfi.dll Mon Oct 10 2005 9:49:00p A.... 303,104 296.00 K
nvwrsfr.dll Mon Oct 10 2005 9:49:00p A.... 327,680 320.00 K
nvwrshe.dll Mon Oct 10 2005 9:49:00p A.... 278,528 272.00 K
nvwrshu.dll Mon Oct 10 2005 9:49:00p A.... 315,392 308.00 K
nvwrsit.dll Mon Oct 10 2005 9:49:00p A.... 323,584 316.00 K
nvwrsja.dll Mon Oct 10 2005 9:49:00p A.... 212,992 208.00 K
nvwrsko.dll Mon Oct 10 2005 9:49:00p A.... 196,608 192.00 K
nvwrsnl.dll Mon Oct 10 2005 9:49:00p A.... 319,488 312.00 K
nvwrsno.dll Mon Oct 10 2005 9:49:00p A.... 299,008 292.00 K
nvwrspl.dll Mon Oct 10 2005 9:49:00p A.... 294,912 288.00 K
nvwrspt.dll Mon Oct 10 2005 9:49:00p A.... 323,584 316.00 K
nvwrsptb.dll Mon Oct 10 2005 9:49:00p A.... 319,488 312.00 K
nvwrsru.dll Mon Oct 10 2005 9:49:00p A.... 315,392 308.00 K
nvwrssk.dll Mon Oct 10 2005 9:49:00p A.... 299,008 292.00 K
nvwrssl.dll Mon Oct 10 2005 9:49:00p A.... 303,104 296.00 K
nvwrssv.dll Mon Oct 10 2005 9:49:00p A.... 294,912 288.00 K
nvwrstr.dll Mon Oct 10 2005 9:49:00p A.... 303,104 296.00 K
nvwrszhc.dll Mon Oct 10 2005 9:49:00p A.... 163,840 160.00 K
nvwrszht.dll Mon Oct 10 2005 9:49:00p A.... 167,936 164.00 K
qmsname.dll Sun Oct 23 2005 12:53:22p ..S.R 236,869 231.32 K
qt-dx331.dll Tue Aug 9 2005 7:12:30p A.... 3,596,288 3.43 M
rgmotepg.dll Sun Oct 23 2005 11:44:56a ..S.R 236,187 230.65 K
sirenacm.dll Sat Aug 13 2005 2:41:12p A.... 118,784 116.00 K
ssleay32.dll Tue Aug 9 2005 7:13:32p A.... 159,744 156.00 K
unicows.dll Tue Aug 9 2005 7:13:32p A.... 245,408 239.66 K
uxd99b~1.dll Tue Sep 20 2005 8:24:46p A.... 218,624 213.50 K
uxtheme.dll Tue Sep 20 2005 8:24:46p A.... 218,624 213.50 K

103 items found: 103 files (7 H/S), 0 directories.
Total of file sizes: 54,251,682 bytes 51.74 M
Locate .tmp files:

No matches found.
**********************************************************************************
Directory Listing of system files:
Volume in drive C is Programs and files
Volume Serial Number is DC1C-18F4

Directory of C:\windows\System32

10/24/2005 10:13 PM 236,869 cEtsrv(2).dll
10/24/2005 06:16 PM 236,869 gp80l3lm1.dll
10/24/2005 12:57 PM 236,869 enrol1931.dll
10/24/2005 11:24 AM 233,552 lv0609dse.dll
10/23/2005 01:20 PM <DIR> dllcache
10/23/2005 12:53 PM 236,869 qmsname.dll
10/23/2005 11:44 AM 236,187 rgmotepg.dll
10/22/2005 11:41 AM 236,104 n2l8lc3u1f.dll
04/27/2005 08:53 PM <DIR> Microsoft
7 File(s) 1,653,319 bytes
2 Dir(s) 39,258,013,696 bytes free
  • 0

Advertisements


#2
austin_o

austin_o

    Retired Staff

  • Retired Staff
  • 2,089 posts
Hi. There is help available here. First, you need to work through the malware removal guide, see the link at the top of the forum where it says "Do you suspect a malware (Spyware, Virus, Trojan) infection? Please Start Here. " This link will take you right to it. http://www.geekstogo...?showtopic=2852
This enables folks to solve most problems on their own. If you still have trouble after that, post a new hijack this log in the malware forum at http://www.geekstogo...hp?showforum=37
:tazz:
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP