hello again this is what i got from the i2mfix
Starting Beta Fix 112305
Creating Account.
The command completed successfully.
Adding Administrative privleges.
The command completed successfully.
Checking for L2MFix account(0=no 1=yes):
1
Granting SeDebugPrivilege to L2MFIX ... successful
Setting Directory
C:\Documents and Settings\malcom\Desktop\l2mfix
C:\Documents and Settings\malcom\Desktop\l2mfix
Running From:
C:\Documents and Settings\malcom\Desktop\l2mfix
Killing Processes!
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003
[email protected]Killing PID 452 'smss.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003
[email protected]Killing PID 532 'winlogon.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003
[email protected]Killing PID 1676 'explorer.exe'
Killing PID 1676 'explorer.exe'
Killing PID 1676 'explorer.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003
[email protected]Killing PID 2808 'rundll32.exe'
Scanning First Pass. Please Wait!
First Pass Completed
Second Pass Scanning
Second pass Completed!
Backing Up: C:\WINDOWS\system32\akferror.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\aqwav.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\aui2dvaa.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\azsldp.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\CBOSUSER.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ciedui.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\crrpol.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\czvfat.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dnj6011se.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dnnq0155e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dxraw.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dzmasf.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dznwsock.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\enl8l13u1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ezsvc.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\FV20ENU.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\g6402ghmg64a2.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\gpr6l39s1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\gqmf32.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\iaxsap.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ir4ml5h11.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\iudkcs32.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\jkcript.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\k0pm0a71ed.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\k4lqle351h.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\klduzb.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\lvj2091oe.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\m2820cloefqc0.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mdiavi32.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mmcertui.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mrise.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mvl_mtf.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\newrsja.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\nprsfi.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\nprspt.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\nzwrstr.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\o2ro0c93ef.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\o8840ilqe8qe0.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ome2disp.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\qlsname.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\rcgwizc.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\rVsauto.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\sflunirl.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\sinscfg.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\sjrmfilt.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\smcsccp.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\smhannel.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\wdspdmod.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\wfn87em.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\wlbclnt.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\zjpfldr.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\guard.tmp
1 file(s) copied.
deleting: C:\WINDOWS\system32\akferror.dll
Successfully Deleted: C:\WINDOWS\system32\akferror.dll
deleting: C:\WINDOWS\system32\aqwav.dll
Successfully Deleted: C:\WINDOWS\system32\aqwav.dll
deleting: C:\WINDOWS\system32\aui2dvaa.dll
Successfully Deleted: C:\WINDOWS\system32\aui2dvaa.dll
deleting: C:\WINDOWS\system32\azsldp.dll
Successfully Deleted: C:\WINDOWS\system32\azsldp.dll
deleting: C:\WINDOWS\system32\CBOSUSER.DLL
Successfully Deleted: C:\WINDOWS\system32\CBOSUSER.DLL
deleting: C:\WINDOWS\system32\ciedui.dll
Successfully Deleted: C:\WINDOWS\system32\ciedui.dll
deleting: C:\WINDOWS\system32\crrpol.dll
Successfully Deleted: C:\WINDOWS\system32\crrpol.dll
deleting: C:\WINDOWS\system32\czvfat.dll
Successfully Deleted: C:\WINDOWS\system32\czvfat.dll
deleting: C:\WINDOWS\system32\dnj6011se.dll
Successfully Deleted: C:\WINDOWS\system32\dnj6011se.dll
deleting: C:\WINDOWS\system32\dnnq0155e.dll
Successfully Deleted: C:\WINDOWS\system32\dnnq0155e.dll
deleting: C:\WINDOWS\system32\dxraw.dll
Successfully Deleted: C:\WINDOWS\system32\dxraw.dll
deleting: C:\WINDOWS\system32\dzmasf.dll
Successfully Deleted: C:\WINDOWS\system32\dzmasf.dll
deleting: C:\WINDOWS\system32\dznwsock.dll
Successfully Deleted: C:\WINDOWS\system32\dznwsock.dll
deleting: C:\WINDOWS\system32\enl8l13u1.dll
Successfully Deleted: C:\WINDOWS\system32\enl8l13u1.dll
deleting: C:\WINDOWS\system32\ezsvc.dll
Successfully Deleted: C:\WINDOWS\system32\ezsvc.dll
deleting: C:\WINDOWS\system32\FV20ENU.DLL
Successfully Deleted: C:\WINDOWS\system32\FV20ENU.DLL
deleting: C:\WINDOWS\system32\g6402ghmg64a2.dll
Successfully Deleted: C:\WINDOWS\system32\g6402ghmg64a2.dll
deleting: C:\WINDOWS\system32\gpr6l39s1.dll
Successfully Deleted: C:\WINDOWS\system32\gpr6l39s1.dll
deleting: C:\WINDOWS\system32\gqmf32.dll
Successfully Deleted: C:\WINDOWS\system32\gqmf32.dll
deleting: C:\WINDOWS\system32\iaxsap.dll
Successfully Deleted: C:\WINDOWS\system32\iaxsap.dll
deleting: C:\WINDOWS\system32\ir4ml5h11.dll
Successfully Deleted: C:\WINDOWS\system32\ir4ml5h11.dll
deleting: C:\WINDOWS\system32\iudkcs32.dll
Successfully Deleted: C:\WINDOWS\system32\iudkcs32.dll
deleting: C:\WINDOWS\system32\jkcript.dll
Successfully Deleted: C:\WINDOWS\system32\jkcript.dll
deleting: C:\WINDOWS\system32\k0pm0a71ed.dll
Successfully Deleted: C:\WINDOWS\system32\k0pm0a71ed.dll
deleting: C:\WINDOWS\system32\k4lqle351h.dll
Successfully Deleted: C:\WINDOWS\system32\k4lqle351h.dll
deleting: C:\WINDOWS\system32\klduzb.dll
Successfully Deleted: C:\WINDOWS\system32\klduzb.dll
deleting: C:\WINDOWS\system32\lvj2091oe.dll
Successfully Deleted: C:\WINDOWS\system32\lvj2091oe.dll
deleting: C:\WINDOWS\system32\m2820cloefqc0.dll
Successfully Deleted: C:\WINDOWS\system32\m2820cloefqc0.dll
deleting: C:\WINDOWS\system32\mdiavi32.dll
Successfully Deleted: C:\WINDOWS\system32\mdiavi32.dll
deleting: C:\WINDOWS\system32\mmcertui.dll
Successfully Deleted: C:\WINDOWS\system32\mmcertui.dll
deleting: C:\WINDOWS\system32\mrise.dll
Successfully Deleted: C:\WINDOWS\system32\mrise.dll
deleting: C:\WINDOWS\system32\mvl_mtf.dll
Successfully Deleted: C:\WINDOWS\system32\mvl_mtf.dll
deleting: C:\WINDOWS\system32\newrsja.dll
Successfully Deleted: C:\WINDOWS\system32\newrsja.dll
deleting: C:\WINDOWS\system32\nprsfi.dll
Successfully Deleted: C:\WINDOWS\system32\nprsfi.dll
deleting: C:\WINDOWS\system32\nprspt.dll
Successfully Deleted: C:\WINDOWS\system32\nprspt.dll
deleting: C:\WINDOWS\system32\nzwrstr.dll
Successfully Deleted: C:\WINDOWS\system32\nzwrstr.dll
deleting: C:\WINDOWS\system32\o2ro0c93ef.dll
Successfully Deleted: C:\WINDOWS\system32\o2ro0c93ef.dll
deleting: C:\WINDOWS\system32\o8840ilqe8qe0.dll
Successfully Deleted: C:\WINDOWS\system32\o8840ilqe8qe0.dll
deleting: C:\WINDOWS\system32\ome2disp.dll
Successfully Deleted: C:\WINDOWS\system32\ome2disp.dll
deleting: C:\WINDOWS\system32\qlsname.dll
Successfully Deleted: C:\WINDOWS\system32\qlsname.dll
deleting: C:\WINDOWS\system32\rcgwizc.dll
Successfully Deleted: C:\WINDOWS\system32\rcgwizc.dll
deleting: C:\WINDOWS\system32\rVsauto.dll
Successfully Deleted: C:\WINDOWS\system32\rVsauto.dll
deleting: C:\WINDOWS\system32\sflunirl.dll
Successfully Deleted: C:\WINDOWS\system32\sflunirl.dll
deleting: C:\WINDOWS\system32\sinscfg.dll
Successfully Deleted: C:\WINDOWS\system32\sinscfg.dll
deleting: C:\WINDOWS\system32\sjrmfilt.dll
Successfully Deleted: C:\WINDOWS\system32\sjrmfilt.dll
deleting: C:\WINDOWS\system32\smcsccp.dll
Successfully Deleted: C:\WINDOWS\system32\smcsccp.dll
deleting: C:\WINDOWS\system32\smhannel.dll
Successfully Deleted: C:\WINDOWS\system32\smhannel.dll
deleting: C:\WINDOWS\system32\wdspdmod.dll
Successfully Deleted: C:\WINDOWS\system32\wdspdmod.dll
deleting: C:\WINDOWS\system32\wfn87em.dll
Successfully Deleted: C:\WINDOWS\system32\wfn87em.dll
deleting: C:\WINDOWS\system32\wlbclnt.dll
Successfully Deleted: C:\WINDOWS\system32\wlbclnt.dll
deleting: C:\WINDOWS\system32\zjpfldr.dll
Successfully Deleted: C:\WINDOWS\system32\zjpfldr.dll
deleting: C:\WINDOWS\system32\guard.tmp
Successfully Deleted: C:\WINDOWS\system32\guard.tmp
Zipping up files for submission:
adding: akferror.dll (164 bytes security) (deflated 4%)
adding: aqwav.dll (164 bytes security) (deflated 5%)
adding: aui2dvaa.dll (164 bytes security) (deflated 5%)
adding: azsldp.dll (164 bytes security) (deflated 4%)
adding: CBOSUSER.DLL (164 bytes security) (deflated 4%)
adding: ciedui.dll (164 bytes security) (deflated 5%)
adding: crrpol.dll (164 bytes security) (deflated 5%)
adding: czvfat.dll (164 bytes security) (deflated 5%)
adding: dnj6011se.dll (164 bytes security) (deflated 5%)
adding: dnnq0155e.dll (164 bytes security) (deflated 5%)
adding: dxraw.dll (164 bytes security) (deflated 5%)
adding: dzmasf.dll (164 bytes security) (deflated 5%)
adding: dznwsock.dll (164 bytes security) (deflated 5%)
adding: enl8l13u1.dll (164 bytes security) (deflated 5%)
adding: ezsvc.dll (164 bytes security) (deflated 5%)
adding: FV20ENU.DLL (164 bytes security) (deflated 5%)
adding: g6402ghmg64a2.dll (164 bytes security) (deflated 4%)
adding: gpr6l39s1.dll (164 bytes security) (deflated 5%)
adding: gqmf32.dll (164 bytes security) (deflated 5%)
adding: iaxsap.dll (164 bytes security) (deflated 5%)
adding: ir4ml5h11.dll (164 bytes security) (deflated 5%)
adding: iudkcs32.dll (164 bytes security) (deflated 5%)
adding: jkcript.dll (164 bytes security) (deflated 5%)
adding: k0pm0a71ed.dll (164 bytes security) (deflated 5%)
adding: k4lqle351h.dll (164 bytes security) (deflated 4%)
adding: klduzb.dll (164 bytes security) (deflated 5%)
adding: lvj2091oe.dll (164 bytes security) (deflated 5%)
adding: m2820cloefqc0.dll (164 bytes security) (deflated 5%)
adding: mdiavi32.dll (164 bytes security) (deflated 5%)
adding: mmcertui.dll (164 bytes security) (deflated 5%)
adding: mrise.dll (164 bytes security) (deflated 5%)
adding: mvl_mtf.dll (164 bytes security) (deflated 5%)
adding: newrsja.dll (164 bytes security) (deflated 5%)
adding: nprsfi.dll (164 bytes security) (deflated 5%)
adding: nprspt.dll (164 bytes security) (deflated 5%)
adding: nzwrstr.dll (164 bytes security) (deflated 5%)
adding: o2ro0c93ef.dll (164 bytes security) (deflated 5%)
adding: o8840ilqe8qe0.dll (164 bytes security) (deflated 5%)
adding: ome2disp.dll (164 bytes security) (deflated 5%)
adding: qlsname.dll (164 bytes security) (deflated 5%)
adding: rcgwizc.dll (164 bytes security) (deflated 5%)
adding: rVsauto.dll (164 bytes security) (deflated 5%)
adding: sflunirl.dll (164 bytes security) (deflated 5%)
adding: sinscfg.dll (164 bytes security) (deflated 5%)
adding: sjrmfilt.dll (164 bytes security) (deflated 5%)
adding: smcsccp.dll (164 bytes security) (deflated 5%)
adding: smhannel.dll (164 bytes security) (deflated 5%)
adding: wdspdmod.dll (164 bytes security) (deflated 5%)
adding: wfn87em.dll (164 bytes security) (deflated 5%)
adding: wlbclnt.dll (164 bytes security) (deflated 4%)
adding: zjpfldr.dll (164 bytes security) (deflated 5%)
adding: guard.tmp (164 bytes security) (deflated 5%)
adding: clear.reg (164 bytes security) (deflated 70%)
adding: echo.reg (164 bytes security) (deflated 11%)
zip warning: name not matched: *.ini
zip error: Nothing to do! (backup.zip)
adding: direct.txt (164 bytes security) (stored 0%)
adding: flag.txt (164 bytes security) (stored 0%)
adding: lo2.txt (164 bytes security) (deflated 87%)
adding: not.txt (164 bytes security) (stored 0%)
adding: readme.txt (164 bytes security) (deflated 52%)
adding: report.txt (164 bytes security) (deflated 71%)
adding: sec.txt (164 bytes security) (stored 0%)
adding: test.txt (164 bytes security) (deflated 82%)
adding: test2.txt (164 bytes security) (deflated 49%)
adding: test3.txt (164 bytes security) (deflated 49%)
adding: test5.txt (164 bytes security) (deflated 49%)
adding: xfind.txt (164 bytes security) (deflated 77%)
adding: backregs/18286857-C824-4B0C-B771-9A2D7D6D1000.reg (164 bytes security) (deflated 70%)
adding: backregs/1C366D49-F25A-4549-AAA2-AA6D2D137AEC.reg (164 bytes security) (deflated 70%)
adding: backregs/225741D7-1386-4B15-9051-58E473FDFB19.reg (164 bytes security) (deflated 70%)
adding: backregs/270D6813-1959-4B0D-9135-7209654A8939.reg (164 bytes security) (deflated 70%)
adding: backregs/37BC9363-A366-433B-8099-E85178CB5F91.reg (164 bytes security) (deflated 70%)
adding: backregs/459056BE-B699-47EF-A335-83F07D080FC0.reg (164 bytes security) (deflated 70%)
adding: backregs/472851EC-B648-4337-9D72-FDC7A896E050.reg (164 bytes security) (deflated 70%)
adding: backregs/4BD0BC84-2FDE-4BD4-ABA0-7AB5F43634AB.reg (164 bytes security) (deflated 70%)
adding: backregs/5E6BF15C-57FF-4B42-A672-8B9B13A773DD.reg (164 bytes security) (deflated 70%)
adding: backregs/684E37F4-BB5F-4933-A6E6-B9CB57AC770B.reg (164 bytes security) (deflated 70%)
adding: backregs/88ABB1AD-7D57-4950-877E-D9ECDA346D56.reg (164 bytes security) (deflated 70%)
adding: backregs/9DBC9B69-4F28-4CBB-9E6F-89E492268B3B.reg (164 bytes security) (deflated 70%)
adding: backregs/AC84673D-DC6E-46B5-B742-89FED617E14E.reg (164 bytes security) (deflated 70%)
adding: backregs/B2850790-E8BB-4DC3-845C-EB27FEC3B28A.reg (164 bytes security) (deflated 70%)
adding: backregs/B9B0B2A5-05CD-4A6A-BE4B-B1343FA1DE10.reg (164 bytes security) (deflated 70%)
adding: backregs/D072F687-CCDF-445D-A71F-4ED43F8516D0.reg (164 bytes security) (deflated 70%)
adding: backregs/D81EA6E8-643A-484C-8D7F-EE1586D73764.reg (164 bytes security) (deflated 70%)
adding: backregs/DDC91C81-2114-4C2E-85B7-67EB3906DB1E.reg (164 bytes security) (deflated 70%)
adding: backregs/DE723DA3-BF8A-4380-A162-6179A01197EF.reg (164 bytes security) (deflated 70%)
adding: backregs/F35EB24B-F9EE-43B1-B7F4-0B714CA3BB41.reg (164 bytes security) (deflated 70%)
adding: backregs/F542821F-FA07-4474-B0B3-7D7BF5C73687.reg (164 bytes security) (deflated 70%)
adding: backregs/F85D29BF-1DDD-4A46-BC5F-EEAD7DCD60EB.reg (164 bytes security) (deflated 70%)
adding: backregs/F8F173F2-714D-4533-BB22-717E67B48643.reg (164 bytes security) (deflated 70%)
adding: backregs/notibac.reg (164 bytes security) (deflated 87%)
adding: backregs/shell.reg (164 bytes security) (deflated 73%)
Restoring Sedebugprivilege:
Granting SeDebugPrivilege to Administrators ... successful
Restoring Windows Update Certificates.:
deleting local copy: akferror.dll
deleting local copy: aqwav.dll
deleting local copy: aui2dvaa.dll
deleting local copy: azsldp.dll
deleting local copy: CBOSUSER.DLL
deleting local copy: ciedui.dll
deleting local copy: crrpol.dll
deleting local copy: czvfat.dll
deleting local copy: dnj6011se.dll
deleting local copy: dnnq0155e.dll
deleting local copy: dxraw.dll
deleting local copy: dzmasf.dll
deleting local copy: dznwsock.dll
deleting local copy: enl8l13u1.dll
deleting local copy: ezsvc.dll
deleting local copy: FV20ENU.DLL
deleting local copy: g6402ghmg64a2.dll
deleting local copy: gpr6l39s1.dll
deleting local copy: gqmf32.dll
deleting local copy: iaxsap.dll
deleting local copy: ir4ml5h11.dll
deleting local copy: iudkcs32.dll
deleting local copy: jkcript.dll
deleting local copy: k0pm0a71ed.dll
deleting local copy: k4lqle351h.dll
deleting local copy: klduzb.dll
deleting local copy: lvj2091oe.dll
deleting local copy: m2820cloefqc0.dll
deleting local copy: mdiavi32.dll
deleting local copy: mmcertui.dll
deleting local copy: mrise.dll
deleting local copy: mvl_mtf.dll
deleting local copy: newrsja.dll
deleting local copy: nprsfi.dll
deleting local copy: nprspt.dll
deleting local copy: nzwrstr.dll
deleting local copy: o2ro0c93ef.dll
deleting local copy: o8840ilqe8qe0.dll
deleting local copy: ome2disp.dll
deleting local copy: qlsname.dll
deleting local copy: rcgwizc.dll
deleting local copy: rVsauto.dll
deleting local copy: sflunirl.dll
deleting local copy: sinscfg.dll
deleting local copy: sjrmfilt.dll
deleting local copy: smcsccp.dll
deleting local copy: smhannel.dll
deleting local copy: wdspdmod.dll
deleting local copy: wfn87em.dll
deleting local copy: wlbclnt.dll
deleting local copy: zjpfldr.dll
deleting local copy: guard.tmp
The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\BITS]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\dnj6011se.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
"DLLName"="wzcdlg.dll"
"Logon"="WZCEventLogon"
"Logoff"="WZCEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000000
The following are the files found:
****************************************************************************
C:\WINDOWS\system32\akferror.dll
C:\WINDOWS\system32\aqwav.dll
C:\WINDOWS\system32\aui2dvaa.dll
C:\WINDOWS\system32\azsldp.dll
C:\WINDOWS\system32\CBOSUSER.DLL
C:\WINDOWS\system32\ciedui.dll
C:\WINDOWS\system32\crrpol.dll
C:\WINDOWS\system32\czvfat.dll
C:\WINDOWS\system32\dnj6011se.dll
C:\WINDOWS\system32\dnnq0155e.dll
C:\WINDOWS\system32\dxraw.dll
C:\WINDOWS\system32\dzmasf.dll
C:\WINDOWS\system32\dznwsock.dll
C:\WINDOWS\system32\enl8l13u1.dll
C:\WINDOWS\system32\ezsvc.dll
C:\WINDOWS\system32\FV20ENU.DLL
C:\WINDOWS\system32\g6402ghmg64a2.dll
C:\WINDOWS\system32\gpr6l39s1.dll
C:\WINDOWS\system32\gqmf32.dll
C:\WINDOWS\system32\iaxsap.dll
C:\WINDOWS\system32\ir4ml5h11.dll
C:\WINDOWS\system32\iudkcs32.dll
C:\WINDOWS\system32\jkcript.dll
C:\WINDOWS\system32\k0pm0a71ed.dll
C:\WINDOWS\system32\k4lqle351h.dll
C:\WINDOWS\system32\klduzb.dll
C:\WINDOWS\system32\lvj2091oe.dll
C:\WINDOWS\system32\m2820cloefqc0.dll
C:\WINDOWS\system32\mdiavi32.dll
C:\WINDOWS\system32\mmcertui.dll
C:\WINDOWS\system32\mrise.dll
C:\WINDOWS\system32\mvl_mtf.dll
C:\WINDOWS\system32\newrsja.dll
C:\WINDOWS\system32\nprsfi.dll
C:\WINDOWS\system32\nprspt.dll
C:\WINDOWS\system32\nzwrstr.dll
C:\WINDOWS\system32\o2ro0c93ef.dll
C:\WINDOWS\system32\o8840ilqe8qe0.dll
C:\WINDOWS\system32\ome2disp.dll
C:\WINDOWS\system32\qlsname.dll
C:\WINDOWS\system32\rcgwizc.dll
C:\WINDOWS\system32\rVsauto.dll
C:\WINDOWS\system32\sflunirl.dll
C:\WINDOWS\system32\sinscfg.dll
C:\WINDOWS\system32\sjrmfilt.dll
C:\WINDOWS\system32\smcsccp.dll
C:\WINDOWS\system32\smhannel.dll
C:\WINDOWS\system32\wdspdmod.dll
C:\WINDOWS\system32\wfn87em.dll
C:\WINDOWS\system32\wlbclnt.dll
C:\WINDOWS\system32\zjpfldr.dll
C:\WINDOWS\system32\guard.tmp
Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{5E6BF15C-57FF-4B42-A672-8B9B13A773DD}"=-
"{459056BE-B699-47EF-A335-83F07D080FC0}"=-
"{D81EA6E8-643A-484C-8D7F-EE1586D73764}"=-
"{9DBC9B69-4F28-4CBB-9E6F-89E492268B3B}"=-
"{1C366D49-F25A-4549-AAA2-AA6D2D137AEC}"=-
"{37BC9363-A366-433B-8099-E85178CB5F91}"=-
"{472851EC-B648-4337-9D72-FDC7A896E050}"=-
"{18286857-C824-4B0C-B771-9A2D7D6D1000}"=-
"{270D6813-1959-4B0D-9135-7209654A8939}"=-
"{225741D7-1386-4B15-9051-58E473FDFB19}"=-
"{DDC91C81-2114-4C2E-85B7-67EB3906DB1E}"=-
"{D072F687-CCDF-445D-A71F-4ED43F8516D0}"=-
"{B9B0B2A5-05CD-4A6A-BE4B-B1343FA1DE10}"=-
"{B2850790-E8BB-4DC3-845C-EB27FEC3B28A}"=-
"{88ABB1AD-7D57-4950-877E-D9ECDA346D56}"=-
"{4BD0BC84-2FDE-4BD4-ABA0-7AB5F43634AB}"=-
"{F85D29BF-1DDD-4A46-BC5F-EEAD7DCD60EB}"=-
"{DE723DA3-BF8A-4380-A162-6179A01197EF}"=-
"{F542821F-FA07-4474-B0B3-7D7BF5C73687}"=-
"{AC84673D-DC6E-46B5-B742-89FED617E14E}"=-
"{684E37F4-BB5F-4933-A6E6-B9CB57AC770B}"=-
"{F35EB24B-F9EE-43B1-B7F4-0B714CA3BB41}"=-
"{F8F173F2-714D-4533-BB22-717E67B48643}"=-
[-HKEY_CLASSES_ROOT\CLSID\{5E6BF15C-57FF-4B42-A672-8B9B13A773DD}]
[-HKEY_CLASSES_ROOT\CLSID\{459056BE-B699-47EF-A335-83F07D080FC0}]
[-HKEY_CLASSES_ROOT\CLSID\{D81EA6E8-643A-484C-8D7F-EE1586D73764}]
[-HKEY_CLASSES_ROOT\CLSID\{9DBC9B69-4F28-4CBB-9E6F-89E492268B3B}]
[-HKEY_CLASSES_ROOT\CLSID\{1C366D49-F25A-4549-AAA2-AA6D2D137AEC}]
[-HKEY_CLASSES_ROOT\CLSID\{37BC9363-A366-433B-8099-E85178CB5F91}]
[-HKEY_CLASSES_ROOT\CLSID\{472851EC-B648-4337-9D72-FDC7A896E050}]
[-HKEY_CLASSES_ROOT\CLSID\{18286857-C824-4B0C-B771-9A2D7D6D1000}]
[-HKEY_CLASSES_ROOT\CLSID\{270D6813-1959-4B0D-9135-7209654A8939}]
[-HKEY_CLASSES_ROOT\CLSID\{225741D7-1386-4B15-9051-58E473FDFB19}]
[-HKEY_CLASSES_ROOT\CLSID\{DDC91C81-2114-4C2E-85B7-67EB3906DB1E}]
[-HKEY_CLASSES_ROOT\CLSID\{D072F687-CCDF-445D-A71F-4ED43F8516D0}]
[-HKEY_CLASSES_ROOT\CLSID\{B9B0B2A5-05CD-4A6A-BE4B-B1343FA1DE10}]
[-HKEY_CLASSES_ROOT\CLSID\{B2850790-E8BB-4DC3-845C-EB27FEC3B28A}]
[-HKEY_CLASSES_ROOT\CLSID\{88ABB1AD-7D57-4950-877E-D9ECDA346D56}]
[-HKEY_CLASSES_ROOT\CLSID\{4BD0BC84-2FDE-4BD4-ABA0-7AB5F43634AB}]
[-HKEY_CLASSES_ROOT\CLSID\{F85D29BF-1DDD-4A46-BC5F-EEAD7DCD60EB}]
[-HKEY_CLASSES_ROOT\CLSID\{DE723DA3-BF8A-4380-A162-6179A01197EF}]
[-HKEY_CLASSES_ROOT\CLSID\{F542821F-FA07-4474-B0B3-7D7BF5C73687}]
[-HKEY_CLASSES_ROOT\CLSID\{AC84673D-DC6E-46B5-B742-89FED617E14E}]
[-HKEY_CLASSES_ROOT\CLSID\{684E37F4-BB5F-4933-A6E6-B9CB57AC770B}]
[-HKEY_CLASSES_ROOT\CLSID\{F35EB24B-F9EE-43B1-B7F4-0B714CA3BB41}]
[-HKEY_CLASSES_ROOT\CLSID\{F8F173F2-714D-4533-BB22-717E67B48643}]
REGEDIT4
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"SV1"=""
****************************************************************************
Desktop.ini Contents:
****************************************************************************
****************************************************************************
AND THIS IS WHAT I GOT FROM MY HIJACKTHIS LOG FILE
Logfile of HijackThis v1.99.1
Scan saved at 18:47:27, on 26/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SGVsbG8\command.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trustix\Trustix AntiVirus\TAVMS.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Trustix\Trustix AntiVirus\Tav.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\WINDOWS\system32\paytime.exe
C:\windows\adtech2005.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\paytime.exe
C:\PROGRA~1\COMMON~1\immq\immqm.exe
C:\Program Files\Trustix\Trustix AntiVirus\Tavaud.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\malcom\Desktop\hjt\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00005.exe"
O1 - Hosts: .net
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Repair Registry Pro] C:\Program Files\Repair Registry Pro\RepairRegistryPro.exe -s
O4 - HKLM\..\Run: [cnfgTav] "C:\Program Files\Trustix\Trustix AntiVirus\Tav.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [PostCopy] C:\WINDOWS\system32\BELKIN\F5D5050\PostCopy.exe
O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\system32\paytime.exe
O4 - HKLM\..\Run: [adtech2005] C:\windows\adtech2005.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PayTime] C:\WINDOWS\system32\paytime.exe
O4 - HKCU\..\Run: [klop] C:\WINDOWS\E.tmp
O4 - HKCU\..\Run: [immq] C:\PROGRA~1\COMMON~1\immq\immqm.exe
O4 - HKCU\..\Run: [Shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00005.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Program Files\ladbrokesMPP\MPPoker.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) -
http://sib1.od2.com/...2/OCI/setup.exeO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupd...b?1118679888403O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn...pdownloader.cabO16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) -
http://cdn.digitalci...6.1.7_en_dl.cabO18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: BITS - C:\WINDOWS\system32\dnj6011se.dll (file missing)
O21 - SSODL: SysTray.Exys - {7368D5FC-6F5C-4f5b-B964-E67214F67852} - C:\WINDOWS\system32\mnknnabj.dll
O21 - SSODL: SysTray.Excn2 - {1722ECFF-4356-4f5b-B534-E67294FE75E9} - C:\WINDOWS\system32\feggbpho.dll (file missing)
O21 - SSODL: SysTray.Exsn - {2368D1FC-2F5C-4f1b-B124-E67214FC78E2} - C:\WINDOWS\system32\gpikkgmh.dll (file missing)
O21 - SSODL: SysTray.Exgl - {636821FC-6F5C-2f1b-B164-E67214F678E2} - C:\WINDOWS\system32\hceciqpk.dll
O21 - SSODL: mtkle - {0D941CB2-92ED-4397-8B90-6EA192C65589} - C:\WINDOWS\system32\dugx32.dll (file missing)
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\SGVsbG8\command.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Trustix AV Service (TAVM_Service) - Unknown owner - C:\Program Files\Trustix\Trustix AntiVirus\TAVMS.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe