Hi there
I really need someones help I have been getting these popups from loadingwebsite and urllogic and they are driving me nuts ....this is as far as my brains can take me any help much appriciated
best wishes Steve :mad:
L2MFIX find log 1.02a
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Setup]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\g622lgfo162c.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
**********************************************************************************
useragent:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{72C92B96-6FAC-4F40-B713-B4060C74CD0A}"=""
**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}"="iTunes"
"{E0D79304-84BE-11CE-9641-444553540000}"="WinZip"
"{E0D79305-84BE-11CE-9641-444553540000}"="WinZip"
"{E0D79306-84BE-11CE-9641-444553540000}"="WinZip"
"{E0D79307-84BE-11CE-9641-444553540000}"="WinZip"
"{BF96875C-C94B-4FB2-9570-62092B6B84FF}"=""
"{AB77609F-2178-4E6F-9C4B-44AC179D937A}"="aż Context Menu Shell Extension"
**********************************************************************************
HKEY ROOT CLASSIDS:
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{BF96875C-C94B-4FB2-9570-62092B6B84FF}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{BF96875C-C94B-4FB2-9570-62092B6B84FF}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{BF96875C-C94B-4FB2-9570-62092B6B84FF}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{BF96875C-C94B-4FB2-9570-62092B6B84FF}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"
**********************************************************************************
Files Found are not all bad files:
C:\WINDOWS\SYSTEM32\
akcore.dll Fri 4 Feb 2005 10:01:02 A.... 188,416 184.00 K
akrules.dll Wed 9 Feb 2005 12:02:38 A.... 110,592 108.00 K
akupd.dll Fri 4 Feb 2005 10:00:46 A.... 155,648 152.00 K
browseui.dll Thu 27 Jan 2005 17:13:16 A.... 1,016,832 993.00 K
cdfview.dll Thu 27 Jan 2005 17:13:16 A.... 151,040 147.50 K
docore.dll Sun 6 Feb 2005 19:43:42 A.... 151,552 148.00 K
dolsp.dll Sun 6 Feb 2005 19:43:44 A.... 139,264 136.00 K
dosync.dll Sun 6 Feb 2005 19:43:40 A.... 114,688 112.00 K
enapi.dll Mon 7 Feb 2005 9:05:00 ..S.R 232,157 226.71 K
enbteg.dll Fri 4 Feb 2005 20:31:00 A.... 230,055 224.66 K
g622lg~1.dll Wed 9 Feb 2005 20:31:34 ..S.R 231,494 226.07 K
gccoll~1.dll Fri 31 Dec 2004 18:00:00 A.... 134,880 131.72 K
gcmd5q~1.dll Wed 9 Feb 2005 19:34:26 A.... 10,752 10.50 K
gcunco~1.dll Fri 31 Dec 2004 16:14:32 A.... 130,272 127.22 K
hashlib.dll Fri 31 Dec 2004 18:00:00 A.... 81,120 79.22 K
hlink.dll Tue 16 Nov 2004 21:17:00 A.... 68,096 66.50 K
iepeers.dll Thu 27 Jan 2005 17:13:16 A.... 249,856 244.00 K
iipzue.dll Sun 6 Feb 2005 19:01:38 A.... 24,576 24.00 K
inseng.dll Thu 27 Jan 2005 17:13:16 A.... 96,256 94.00 K
ir22l5~1.dll Sun 6 Feb 2005 9:21:14 A.... 228,812 223.45 K
j4p0le~1.dll Mon 7 Feb 2005 12:04:50 ..S.R 232,157 226.71 K
jkproxy.dll Fri 4 Feb 2005 20:16:28 A.... 229,736 224.35 K
lgngwrbk.dll Wed 9 Feb 2005 4:48:22 A.... 230,547 225.14 K
lmcmp12n.dll Tue 8 Feb 2005 13:06:56 A.... 230,547 225.14 K
lsawd10n.dll Wed 9 Feb 2005 20:40:32 A.... 228,816 223.45 K
lv0809~1.dll Wed 9 Feb 2005 20:45:36 ..S.R 228,816 223.45 K
lvjm09~1.dll Fri 4 Feb 2005 20:28:26 ..S.R 229,736 224.35 K
mmstkprp.dll Fri 4 Feb 2005 14:21:06 A.... 229,736 224.35 K
mshtml.dll Thu 27 Jan 2005 17:13:18 A.... 3,006,976 2.87 M
mxxml4a.dll Fri 4 Feb 2005 9:24:34 A.... 229,736 224.35 K
n68o0g~1.dll Fri 4 Feb 2005 20:16:26 ..S.R 230,122 224.73 K
ole32.dll Fri 14 Jan 2005 8:55:50 A.... 1,285,120 1.22 M
olecli32.dll Fri 14 Jan 2005 8:55:50 A.... 74,752 73.00 K
olecnv32.dll Fri 14 Jan 2005 8:55:50 A.... 37,888 37.00 K
rpcss.dll Fri 14 Jan 2005 8:55:50 A.... 395,776 386.50 K
shdocvw.dll Thu 27 Jan 2005 17:13:18 A.... 1,483,264 1.41 M
shell32.dll Tue 21 Dec 2004 20:49:36 A.... 8,450,048 8.06 M
shlwapi.dll Thu 27 Jan 2005 17:13:18 A.... 473,600 462.50 K
srvsvc.dll Tue 7 Dec 2004 19:32:34 A.... 96,768 94.50 K
urlmon.dll Thu 27 Jan 2005 17:13:18 A.... 607,744 593.50 K
wininet.dll Thu 27 Jan 2005 17:13:18 A.... 656,896 641.50 K
41 items found: 41 files (6 H/S), 0 directories.
Total of file sizes: 22,615,139 bytes 21.57 M
Locate .tmp files:
C:\WINDOWS\SYSTEM32\
guard.tmp Wed 9 Feb 2005 20:51:32 A.... 231,494 226.07 K
1 item found: 1 file, 0 directories.
Total of file sizes: 231,494 bytes 226.07 K
**********************************************************************************
Directory Listing of system files:
Volume in drive C has no label.
Volume Serial Number is C4DC-F8E5
Directory of C:\WINDOWS\System32
09/02/2005 20:45 228,816 lv0809due.dll
09/02/2005 20:31 231,494 g622lgfo162c.dll
07/02/2005 12:04 232,157 j4p0le7m1h.dll
07/02/2005 09:04 232,157 ENAPI.dll
04/02/2005 20:28 229,736 lvjm0911e.dll
04/02/2005 20:16 230,122 n68o0gl3e6q.dll
06/10/2004 14:19 <DIR> DLLCACHE
04/08/2004 06:55 10,022 KGyGaAvL.sys
11/10/2002 18:41 <DIR> Microsoft
20/09/2002 08:00 181,296 SCSIACC.EXE
8 File(s) 1,575,800 bytes
2 Dir(s) 49,916,305,408 bytes free
Hope this is going to the right post 1st timer sorry If i have screwed up where i post this
Steve