Here you go, jonny... Man, I sooooo appreciate your help!
______________
L2Mfix 1.02a
Running From:
C:\Documents and Settings\onwer\Desktop\l2mfix
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (
http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify:
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER
Setting registry permissions:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (
http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Denying C access for really "Everyone"
- adding new ACCESS DENY entry
Registry Permissions set too:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (
http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify:
(CI) DENY --C------- Everyone
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER
Setting up for Reboot
Starting Reboot!
C:\Documents and Settings\onwer\Desktop\l2mfix
System Rebooted!
Running From:
C:\Documents and Settings\onwer\Desktop\l2mfix
killing explorer and rundll32.exe
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003
[email protected]Killing PID 1288 'explorer.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003
[email protected]Killing PID 1668 'rundll32.exe'
Killing PID 1676 'rundll32.exe'
Killing PID 1692 'rundll32.exe'
Scanning First Pass. Please Wait!
First Pass Completed
Second Pass Scanning
Second pass Completed!
Backing Up: C:\WINDOWS\system32\loasrv.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\imlogmsg.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ssnymaeb.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ir86l5ls1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dmlay.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\jt2007fme.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\wyadmoe.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\kp1394.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\l6p20g7oe6.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\kt66l7js1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\gp0ml3d11.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\e8jm0i11e8.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\lv0q09d5e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\PAVEXP.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\teolhelp.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\p4n80e5ueh.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dn0401dqe.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\skftpub.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\bfowselc.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\jcdw400.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\tjflog.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\sparddlg.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dnl4013qe.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\lv2209foe.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dnj0011me.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\fpl6033se.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\u4ru0e99eh.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\r2p8lc7u1f.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mvpul9791.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mvlol9331.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\h8j4li1q18.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\i406leds1h06.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mvl8l93u1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\fppq0375e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\rQsdlg.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ir06l5ds1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\enpol1731.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\lvns0957e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\e802lido180c.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\h6n00g5me6.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mv22l9fo1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\k4no0e53eh.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\i8loli3318.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\j86mlij118o.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\l28mlcl11fq.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\f4j20e1oeh.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\l00ulad91d0.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\g2400chmef4a0.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\k6080gdue6080.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\e002lado1d0c.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\guard.tmp
1 file(s) copied.
deleting: C:\WINDOWS\system32\loasrv.dll
Successfully Deleted: C:\WINDOWS\system32\loasrv.dll
deleting: C:\WINDOWS\system32\imlogmsg.dll
Successfully Deleted: C:\WINDOWS\system32\imlogmsg.dll
deleting: C:\WINDOWS\system32\ssnymaeb.dll
Successfully Deleted: C:\WINDOWS\system32\ssnymaeb.dll
deleting: C:\WINDOWS\system32\ir86l5ls1.dll
Successfully Deleted: C:\WINDOWS\system32\ir86l5ls1.dll
deleting: C:\WINDOWS\system32\dmlay.dll
Successfully Deleted: C:\WINDOWS\system32\dmlay.dll
deleting: C:\WINDOWS\system32\jt2007fme.dll
Successfully Deleted: C:\WINDOWS\system32\jt2007fme.dll
deleting: C:\WINDOWS\system32\wyadmoe.dll
Successfully Deleted: C:\WINDOWS\system32\wyadmoe.dll
deleting: C:\WINDOWS\system32\kp1394.dll
Successfully Deleted: C:\WINDOWS\system32\kp1394.dll
deleting: C:\WINDOWS\system32\l6p20g7oe6.dll
Successfully Deleted: C:\WINDOWS\system32\l6p20g7oe6.dll
deleting: C:\WINDOWS\system32\kt66l7js1.dll
Successfully Deleted: C:\WINDOWS\system32\kt66l7js1.dll
deleting: C:\WINDOWS\system32\gp0ml3d11.dll
Successfully Deleted: C:\WINDOWS\system32\gp0ml3d11.dll
deleting: C:\WINDOWS\system32\e8jm0i11e8.dll
Successfully Deleted: C:\WINDOWS\system32\e8jm0i11e8.dll
deleting: C:\WINDOWS\system32\lv0q09d5e.dll
Successfully Deleted: C:\WINDOWS\system32\lv0q09d5e.dll
deleting: C:\WINDOWS\system32\PAVEXP.DLL
Successfully Deleted: C:\WINDOWS\system32\PAVEXP.DLL
deleting: C:\WINDOWS\system32\teolhelp.dll
Successfully Deleted: C:\WINDOWS\system32\teolhelp.dll
deleting: C:\WINDOWS\system32\p4n80e5ueh.dll
Successfully Deleted: C:\WINDOWS\system32\p4n80e5ueh.dll
deleting: C:\WINDOWS\system32\dn0401dqe.dll
Successfully Deleted: C:\WINDOWS\system32\dn0401dqe.dll
deleting: C:\WINDOWS\system32\skftpub.dll
Successfully Deleted: C:\WINDOWS\system32\skftpub.dll
deleting: C:\WINDOWS\system32\bfowselc.dll
Successfully Deleted: C:\WINDOWS\system32\bfowselc.dll
deleting: C:\WINDOWS\system32\jcdw400.dll
Successfully Deleted: C:\WINDOWS\system32\jcdw400.dll
deleting: C:\WINDOWS\system32\tjflog.dll
Successfully Deleted: C:\WINDOWS\system32\tjflog.dll
deleting: C:\WINDOWS\system32\sparddlg.dll
Successfully Deleted: C:\WINDOWS\system32\sparddlg.dll
deleting: C:\WINDOWS\system32\dnl4013qe.dll
Successfully Deleted: C:\WINDOWS\system32\dnl4013qe.dll
deleting: C:\WINDOWS\system32\lv2209foe.dll
Successfully Deleted: C:\WINDOWS\system32\lv2209foe.dll
deleting: C:\WINDOWS\system32\dnj0011me.dll
Successfully Deleted: C:\WINDOWS\system32\dnj0011me.dll
deleting: C:\WINDOWS\system32\fpl6033se.dll
Successfully Deleted: C:\WINDOWS\system32\fpl6033se.dll
deleting: C:\WINDOWS\system32\u4ru0e99eh.dll
Successfully Deleted: C:\WINDOWS\system32\u4ru0e99eh.dll
deleting: C:\WINDOWS\system32\r2p8lc7u1f.dll
Successfully Deleted: C:\WINDOWS\system32\r2p8lc7u1f.dll
deleting: C:\WINDOWS\system32\mvpul9791.dll
Successfully Deleted: C:\WINDOWS\system32\mvpul9791.dll
deleting: C:\WINDOWS\system32\mvlol9331.dll
Successfully Deleted: C:\WINDOWS\system32\mvlol9331.dll
deleting: C:\WINDOWS\system32\h8j4li1q18.dll
Successfully Deleted: C:\WINDOWS\system32\h8j4li1q18.dll
deleting: C:\WINDOWS\system32\i406leds1h06.dll
Successfully Deleted: C:\WINDOWS\system32\i406leds1h06.dll
deleting: C:\WINDOWS\system32\mvl8l93u1.dll
Successfully Deleted: C:\WINDOWS\system32\mvl8l93u1.dll
deleting: C:\WINDOWS\system32\fppq0375e.dll
Successfully Deleted: C:\WINDOWS\system32\fppq0375e.dll
deleting: C:\WINDOWS\system32\rQsdlg.dll
Successfully Deleted: C:\WINDOWS\system32\rQsdlg.dll
deleting: C:\WINDOWS\system32\ir06l5ds1.dll
Successfully Deleted: C:\WINDOWS\system32\ir06l5ds1.dll
deleting: C:\WINDOWS\system32\enpol1731.dll
Successfully Deleted: C:\WINDOWS\system32\enpol1731.dll
deleting: C:\WINDOWS\system32\lvns0957e.dll
Successfully Deleted: C:\WINDOWS\system32\lvns0957e.dll
deleting: C:\WINDOWS\system32\e802lido180c.dll
Successfully Deleted: C:\WINDOWS\system32\e802lido180c.dll
deleting: C:\WINDOWS\system32\h6n00g5me6.dll
Successfully Deleted: C:\WINDOWS\system32\h6n00g5me6.dll
deleting: C:\WINDOWS\system32\mv22l9fo1.dll
Successfully Deleted: C:\WINDOWS\system32\mv22l9fo1.dll
deleting: C:\WINDOWS\system32\k4no0e53eh.dll
Successfully Deleted: C:\WINDOWS\system32\k4no0e53eh.dll
deleting: C:\WINDOWS\system32\i8loli3318.dll
Successfully Deleted: C:\WINDOWS\system32\i8loli3318.dll
deleting: C:\WINDOWS\system32\j86mlij118o.dll
Successfully Deleted: C:\WINDOWS\system32\j86mlij118o.dll
deleting: C:\WINDOWS\system32\l28mlcl11fq.dll
Successfully Deleted: C:\WINDOWS\system32\l28mlcl11fq.dll
deleting: C:\WINDOWS\system32\f4j20e1oeh.dll
Successfully Deleted: C:\WINDOWS\system32\f4j20e1oeh.dll
deleting: C:\WINDOWS\system32\l00ulad91d0.dll
Successfully Deleted: C:\WINDOWS\system32\l00ulad91d0.dll
deleting: C:\WINDOWS\system32\g2400chmef4a0.dll
Successfully Deleted: C:\WINDOWS\system32\g2400chmef4a0.dll
deleting: C:\WINDOWS\system32\k6080gdue6080.dll
Successfully Deleted: C:\WINDOWS\system32\k6080gdue6080.dll
deleting: C:\WINDOWS\system32\e002lado1d0c.dll
Successfully Deleted: C:\WINDOWS\system32\e002lado1d0c.dll
deleting: C:\WINDOWS\system32\guard.tmp
Successfully Deleted: C:\WINDOWS\system32\guard.tmp
Desktop.ini sucessfully removed
Zipping up files for submission:
adding: enpol1731.dll (deflated 4%)
adding: lvns0957e.dll (deflated 4%)
adding: e802lido180c.dll (deflated 4%)
adding: h6n00g5me6.dll (deflated 3%)
adding: mv22l9fo1.dll (deflated 4%)
adding: k4no0e53eh.dll (deflated 4%)
adding: i8loli3318.dll (deflated 5%)
adding: j86mlij118o.dll (deflated 4%)
adding: l28mlcl11fq.dll (deflated 5%)
adding: f4j20e1oeh.dll (deflated 4%)
adding: loasrv.dll (deflated 5%)
adding: imlogmsg.dll (deflated 4%)
adding: ssnymaeb.dll (deflated 3%)
adding: ir86l5ls1.dll (deflated 4%)
adding: dmlay.dll (deflated 5%)
adding: jt2007fme.dll (deflated 4%)
adding: wyadmoe.dll (deflated 4%)
adding: kp1394.dll (deflated 4%)
adding: l6p20g7oe6.dll (deflated 4%)
adding: kt66l7js1.dll (deflated 3%)
adding: gp0ml3d11.dll (deflated 4%)
adding: e8jm0i11e8.dll (deflated 5%)
adding: lv0q09d5e.dll (deflated 4%)
adding: PAVEXP.DLL (deflated 4%)
adding: teolhelp.dll (deflated 4%)
adding: p4n80e5ueh.dll (deflated 3%)
adding: dn0401dqe.dll (deflated 4%)
adding: skftpub.dll (deflated 4%)
adding: bfowselc.dll (deflated 4%)
adding: jcdw400.dll (deflated 3%)
adding: tjflog.dll (deflated 5%)
adding: sparddlg.dll (deflated 5%)
adding: dnl4013qe.dll (deflated 4%)
adding: lv2209foe.dll (deflated 4%)
adding: dnj0011me.dll (deflated 4%)
adding: fpl6033se.dll (deflated 4%)
adding: u4ru0e99eh.dll (deflated 4%)
adding: r2p8lc7u1f.dll (deflated 4%)
adding: mvpul9791.dll (deflated 4%)
adding: mvlol9331.dll (deflated 5%)
adding: h8j4li1q18.dll (deflated 4%)
adding: i406leds1h06.dll (deflated 4%)
adding: mvl8l93u1.dll (deflated 4%)
adding: fppq0375e.dll (deflated 3%)
adding: rQsdlg.dll (deflated 4%)
adding: ir06l5ds1.dll (deflated 3%)
adding: l00ulad91d0.dll (deflated 4%)
adding: g2400chmef4a0.dll (deflated 4%)
adding: k6080gdue6080.dll (deflated 4%)
adding: e002lado1d0c.dll (deflated 3%)
adding: guard.tmp (deflated 5%)
adding: echo.reg (deflated 9%)
adding: clear.reg (deflated 52%)
adding: desktop.ini (deflated 15%)
adding: readme.txt (deflated 49%)
adding: direct.txt (stored 0%)
adding: report.txt (deflated 66%)
adding: lo2.txt (deflated 85%)
adding: test2.txt (deflated 33%)
adding: test3.txt (deflated 33%)
adding: test5.txt (deflated 33%)
adding: test.txt (deflated 81%)
adding: xfind.txt (deflated 76%)
adding: backregs/shell.reg (deflated 74%)
adding: backregs/B38F00CF-2335-4437-B14F-5B451339E20C.reg (deflated 70%)
adding: backregs/12C1D96C-7B3A-474E-A81F-C920032214E6.reg (deflated 70%)
adding: backregs/443D0DE3-8D5A-41A4-9C92-850F7133710B.reg (deflated 70%)
adding: backregs/BFDD6019-C28C-4358-B822-58BA25496A81.reg (deflated 70%)
Restoring Registry Permissions:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (
http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Revoking access for really "Everyone"
Registry permissions set too:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (
http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify:
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER
Restoring Sedebugprivilege:
Granting SeDebugPrivilege to Administrators ... successful
deleting local copy: loasrv.dll
deleting local copy: imlogmsg.dll
deleting local copy: ssnymaeb.dll
deleting local copy: ir86l5ls1.dll
deleting local copy: dmlay.dll
deleting local copy: jt2007fme.dll
deleting local copy: wyadmoe.dll
deleting local copy: kp1394.dll
deleting local copy: l6p20g7oe6.dll
deleting local copy: kt66l7js1.dll
deleting local copy: gp0ml3d11.dll
deleting local copy: e8jm0i11e8.dll
deleting local copy: lv0q09d5e.dll
deleting local copy: PAVEXP.DLL
deleting local copy: teolhelp.dll
deleting local copy: p4n80e5ueh.dll
deleting local copy: dn0401dqe.dll
deleting local copy: skftpub.dll
deleting local copy: bfowselc.dll
deleting local copy: jcdw400.dll
deleting local copy: tjflog.dll
deleting local copy: sparddlg.dll
deleting local copy: dnl4013qe.dll
deleting local copy: lv2209foe.dll
deleting local copy: dnj0011me.dll
deleting local copy: fpl6033se.dll
deleting local copy: u4ru0e99eh.dll
deleting local copy: r2p8lc7u1f.dll
deleting local copy: mvpul9791.dll
deleting local copy: mvlol9331.dll
deleting local copy: h8j4li1q18.dll
deleting local copy: i406leds1h06.dll
deleting local copy: mvl8l93u1.dll
deleting local copy: fppq0375e.dll
deleting local copy: rQsdlg.dll
deleting local copy: ir06l5ds1.dll
deleting local copy: enpol1731.dll
deleting local copy: lvns0957e.dll
deleting local copy: e802lido180c.dll
deleting local copy: h6n00g5me6.dll
deleting local copy: mv22l9fo1.dll
deleting local copy: k4no0e53eh.dll
deleting local copy: i8loli3318.dll
deleting local copy: j86mlij118o.dll
deleting local copy: l28mlcl11fq.dll
deleting local copy: f4j20e1oeh.dll
deleting local copy: l00ulad91d0.dll
deleting local copy: g2400chmef4a0.dll
deleting local copy: k6080gdue6080.dll
deleting local copy: e002lado1d0c.dll
deleting local copy: guard.tmp
The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
The following are the files found:
****************************************************************************
C:\WINDOWS\system32\loasrv.dll
C:\WINDOWS\system32\imlogmsg.dll
C:\WINDOWS\system32\ssnymaeb.dll
C:\WINDOWS\system32\ir86l5ls1.dll
C:\WINDOWS\system32\dmlay.dll
C:\WINDOWS\system32\jt2007fme.dll
C:\WINDOWS\system32\wyadmoe.dll
C:\WINDOWS\system32\kp1394.dll
C:\WINDOWS\system32\l6p20g7oe6.dll
C:\WINDOWS\system32\kt66l7js1.dll
C:\WINDOWS\system32\gp0ml3d11.dll
C:\WINDOWS\system32\e8jm0i11e8.dll
C:\WINDOWS\system32\lv0q09d5e.dll
C:\WINDOWS\system32\PAVEXP.DLL
C:\WINDOWS\system32\teolhelp.dll
C:\WINDOWS\system32\p4n80e5ueh.dll
C:\WINDOWS\system32\dn0401dqe.dll
C:\WINDOWS\system32\skftpub.dll
C:\WINDOWS\system32\bfowselc.dll
C:\WINDOWS\system32\jcdw400.dll
C:\WINDOWS\system32\tjflog.dll
C:\WINDOWS\system32\sparddlg.dll
C:\WINDOWS\system32\dnl4013qe.dll
C:\WINDOWS\system32\lv2209foe.dll
C:\WINDOWS\system32\dnj0011me.dll
C:\WINDOWS\system32\fpl6033se.dll
C:\WINDOWS\system32\u4ru0e99eh.dll
C:\WINDOWS\system32\r2p8lc7u1f.dll
C:\WINDOWS\system32\mvpul9791.dll
C:\WINDOWS\system32\mvlol9331.dll
C:\WINDOWS\system32\h8j4li1q18.dll
C:\WINDOWS\system32\i406leds1h06.dll
C:\WINDOWS\system32\mvl8l93u1.dll
C:\WINDOWS\system32\fppq0375e.dll
C:\WINDOWS\system32\rQsdlg.dll
C:\WINDOWS\system32\ir06l5ds1.dll
C:\WINDOWS\system32\enpol1731.dll
C:\WINDOWS\system32\lvns0957e.dll
C:\WINDOWS\system32\e802lido180c.dll
C:\WINDOWS\system32\h6n00g5me6.dll
C:\WINDOWS\system32\mv22l9fo1.dll
C:\WINDOWS\system32\k4no0e53eh.dll
C:\WINDOWS\system32\i8loli3318.dll
C:\WINDOWS\system32\j86mlij118o.dll
C:\WINDOWS\system32\l28mlcl11fq.dll
C:\WINDOWS\system32\f4j20e1oeh.dll
C:\WINDOWS\system32\l00ulad91d0.dll
C:\WINDOWS\system32\g2400chmef4a0.dll
C:\WINDOWS\system32\k6080gdue6080.dll
C:\WINDOWS\system32\e002lado1d0c.dll
C:\WINDOWS\system32\guard.tmp
Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell
Extensions\Approved]
"{B38F00CF-2335-4437-B14F-5B451339E20C}"=-
"{12C1D96C-7B3A-474E-A81F-C920032214E6}"=-
"{443D0DE3-8D5A-41A4-9C92-850F7133710B}"=-
"{BFDD6019-C28C-4358-B822-58BA25496A81}"=-
[-HKEY_CLASSES_ROOT\CLSID\{B38F00CF-2335-4437-B14F-5B451339E20C}]
[-HKEY_CLASSES_ROOT\CLSID\{12C1D96C-7B3A-474E-A81F-C920032214E6}]
[-HKEY_CLASSES_ROOT\CLSID\{443D0DE3-8D5A-41A4-9C92-850F7133710B}]
[-HKEY_CLASSES_ROOT\CLSID\{BFDD6019-C28C-4358-B822-58BA25496A81}]
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet
Settings\User Agent\Post Platform]
"{0ED6EC5B-6689-4C9F-936B-B3B5ACE909A3}"=-
****************************************************************************
Desktop.ini Contents:
****************************************************************************
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
<IDone>{0ED6EC5B-6689-4C9F-936B-B3B5ACE909A3}</IDone>
<IDtwo>AD</IDtwo>
<VERSION>200</VERSION>
****************************************************************************
Logfile of HijackThis v1.99.0
Scan saved at 9:04:00 AM, on 1/30/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ygvork.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\QuickTime\qttask.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\SM1BG.EXE
C:\WINDOWS\system32\wsxsvc\wsxsvc.exe
C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\imapi.exe
C:\Program Files\McAfee.com\VSO\mcshield.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer
Provided by Cox High Speed Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =
127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: earch
O1 - Hosts: earch
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} -
c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: (no name) - {12EE7A5E-0674-42f9-A76B-000000004D00} - (no file)
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [WebTrapNT.exe] "C:\Program Files\Trend Micro\PC-cillin 2000
\WebTrapNT.exe"
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2000
\Pop3trap.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe"
/checktask
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [Dvx] C:\WINDOWS\system32\wsxsvc\wsxsvc.exe
O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe
E6F1873B.DLL,D9EBC318C
O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common
Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [{12EE7A5E-0674-42f9-A76B-000000004D00}] rundll32.exe
stlb2.dll,DllRunMain
O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBOUNCER\VirtualBouncer.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft
ActiveSync\WCESCOMM.EXE"
O4 - Startup: AdDestroyer.lnk = C:\Program Files\AdDestroyer\AdDestroyer.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program
Files\QUICKENW\bagent.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common
Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10
\OSA.EXE
O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\billmind.exe
O4 - Global Startup: VAIO Action Setup (Server).lnk = C:\Program Files\Sony\VAIO Action
Setup\VAServ.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1
\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!
\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!
\Common/ycsrch.htm
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} -
C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program
Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-
00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -
C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-
00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {0713E8D2-850A-101B-AFC0-4210102A8DA7} (Microsoft ProgressBar Control,
version 5.0 (SP2)) -
http://download.mcaf...22/ComCtl32.cabO16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) -
http://download.mcaf...ed/MGBrwFld.cabO16 - DPF: {0FC6BF2B-E16A-11CF-AB2E-0080AD08A326} -
http://activex.liveu...ntrols/cres.cabO16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://a1540.g.akama...s/us/win/QuickTimeInstaller.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating
System Class) -
http://bin.mcafee.co...72/mcinsctl.cabO16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) -
http://www.ofoto.com..._1/axofupld.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...housecall/xscan53.cab
O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) -
http://das.microsoft...tail/DASAct.cabO16 - DPF: {9184D21C-9835-42C5-A883-EA8BE7FC048D} (Downloader Class) -
http://www.shop.intu...bles/ie/IDA.cabO16 - DPF: {9771C160-AD19-11D5-91BE-0048546CB511} -
http://www.affiliate...wo/download.exeO16 - DPF: {A9DAD15A-365E-494D-9D41-8A0BB80007B0} (ArcticShell control) -
http://www.arcticpig...ivex/mayhem.cabO16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) -
http://bin.mcafee.co...,16/mcgdmgr.cabO16 - DPF: {FE67C682-F5EA-11CF-9C2F-0000C0C83ADC} (Jamba Class Library) -
http://www.kidscarni...om/Jambalib.cabO23 - Service: McAfee.com McShield - Unknown - C:\Program
Files\McAfee.com\VSO\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1
\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates
Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation -
C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sony SPTI Service - Sony Corporation - C:\Program Files\Common
Files\Sony Shared\AVLib\SPTISRV.exe