L2Mfix 1.02b
Running From:
C:\DOCUME~1\Linda\Desktop\l2mfix
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (
http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify:
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER
Setting registry permissions:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (
http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Denying C access for really "Everyone"
- adding new ACCESS DENY entry
Registry Permissions set too:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (
http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify:
(CI) DENY --C------- Everyone
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER
Setting up for Reboot
Starting Reboot!
C:\Documents and Settings\Linda\Desktop\l2mfix
System Rebooted!
Running From:
C:\Documents and Settings\Linda\Desktop\l2mfix
killing explorer and rundll32.exe
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003
[email protected]
Killing PID 1508 'explorer.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003
[email protected]
Error, Cannot find a process with an image name of rundll32.exe
Scanning First Pass. Please Wait!
First Pass Completed
Second Pass Scanning
Second pass Completed!
Backing Up: C:\WINDOWS\system32\aztxprxy.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\cdmres.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dn4s01h7e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dnr4019qe.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\e6jmlg1116.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\en68l1ju1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\enr4l19q1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\f2l0lc3m1f.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\f6l00g3me6.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\g0lm0a31ed.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\g4jo0e13eh.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\gpj6l31s1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\h20q0cd5ef0.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\hH23msp.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\hrro0593e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\idengine.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ir60l5jm1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ir8ul5l91.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\jt2m07f1e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\jt4m07h1e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\k408ledu1h08.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\k4lqle351h.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\kddest.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\kfdur.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\kidblr.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ktl0l73m1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ktlsl7371.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ktpml7711.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\l2l60c3sef.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\l46o0ej3eho.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\LPDIS11n.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\lv0209doe.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\lv8m09l1e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\lvghours.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\lvlu0939e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\lvp8097ue.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\m4rmle911h.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\m646lghs1646.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mbpbde40.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mcjint40.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\moxlegih.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mpmtapi.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mrwmdm.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\msminst.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mv40l9hm1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mvl_hp.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mwexcl40.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\MYRio300.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mz40l9hm1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\nttevent.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ofbccu32.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\p04ulah91d4.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\p8p6li7s18.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\pqrpnsp.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\q6nulg5916.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\rwutils.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\s0pu0a79ed.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\SLP32.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\tnddd.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\tzpmib.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\vxdex.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\wgnmm.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\wtauserv.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\guard.tmp
1 file(s) copied.
deleting: C:\WINDOWS\system32\aztxprxy.dll
Successfully Deleted: C:\WINDOWS\system32\aztxprxy.dll
deleting: C:\WINDOWS\system32\cdmres.dll
Successfully Deleted: C:\WINDOWS\system32\cdmres.dll
deleting: C:\WINDOWS\system32\dn4s01h7e.dll
Successfully Deleted: C:\WINDOWS\system32\dn4s01h7e.dll
deleting: C:\WINDOWS\system32\dnr4019qe.dll
Successfully Deleted: C:\WINDOWS\system32\dnr4019qe.dll
deleting: C:\WINDOWS\system32\e6jmlg1116.dll
Successfully Deleted: C:\WINDOWS\system32\e6jmlg1116.dll
deleting: C:\WINDOWS\system32\en68l1ju1.dll
Successfully Deleted: C:\WINDOWS\system32\en68l1ju1.dll
deleting: C:\WINDOWS\system32\enr4l19q1.dll
Successfully Deleted: C:\WINDOWS\system32\enr4l19q1.dll
deleting: C:\WINDOWS\system32\f2l0lc3m1f.dll
Successfully Deleted: C:\WINDOWS\system32\f2l0lc3m1f.dll
deleting: C:\WINDOWS\system32\f6l00g3me6.dll
Successfully Deleted: C:\WINDOWS\system32\f6l00g3me6.dll
deleting: C:\WINDOWS\system32\g0lm0a31ed.dll
Successfully Deleted: C:\WINDOWS\system32\g0lm0a31ed.dll
deleting: C:\WINDOWS\system32\g4jo0e13eh.dll
Successfully Deleted: C:\WINDOWS\system32\g4jo0e13eh.dll
deleting: C:\WINDOWS\system32\gpj6l31s1.dll
Successfully Deleted: C:\WINDOWS\system32\gpj6l31s1.dll
deleting: C:\WINDOWS\system32\h20q0cd5ef0.dll
Successfully Deleted: C:\WINDOWS\system32\h20q0cd5ef0.dll
deleting: C:\WINDOWS\system32\hH23msp.dll
Successfully Deleted: C:\WINDOWS\system32\hH23msp.dll
deleting: C:\WINDOWS\system32\hrro0593e.dll
Successfully Deleted: C:\WINDOWS\system32\hrro0593e.dll
deleting: C:\WINDOWS\system32\idengine.dll
Successfully Deleted: C:\WINDOWS\system32\idengine.dll
deleting: C:\WINDOWS\system32\ir60l5jm1.dll
Successfully Deleted: C:\WINDOWS\system32\ir60l5jm1.dll
deleting: C:\WINDOWS\system32\ir8ul5l91.dll
Successfully Deleted: C:\WINDOWS\system32\ir8ul5l91.dll
deleting: C:\WINDOWS\system32\jt2m07f1e.dll
Successfully Deleted: C:\WINDOWS\system32\jt2m07f1e.dll
deleting: C:\WINDOWS\system32\jt4m07h1e.dll
Successfully Deleted: C:\WINDOWS\system32\jt4m07h1e.dll
deleting: C:\WINDOWS\system32\k408ledu1h08.dll
Successfully Deleted: C:\WINDOWS\system32\k408ledu1h08.dll
deleting: C:\WINDOWS\system32\k4lqle351h.dll
Successfully Deleted: C:\WINDOWS\system32\k4lqle351h.dll
deleting: C:\WINDOWS\system32\kddest.dll
Successfully Deleted: C:\WINDOWS\system32\kddest.dll
deleting: C:\WINDOWS\system32\kfdur.dll
Successfully Deleted: C:\WINDOWS\system32\kfdur.dll
deleting: C:\WINDOWS\system32\kidblr.dll
Successfully Deleted: C:\WINDOWS\system32\kidblr.dll
deleting: C:\WINDOWS\system32\ktl0l73m1.dll
Successfully Deleted: C:\WINDOWS\system32\ktl0l73m1.dll
deleting: C:\WINDOWS\system32\ktlsl7371.dll
Successfully Deleted: C:\WINDOWS\system32\ktlsl7371.dll
deleting: C:\WINDOWS\system32\ktpml7711.dll
Successfully Deleted: C:\WINDOWS\system32\ktpml7711.dll
deleting: C:\WINDOWS\system32\l2l60c3sef.dll
Successfully Deleted: C:\WINDOWS\system32\l2l60c3sef.dll
deleting: C:\WINDOWS\system32\l46o0ej3eho.dll
Successfully Deleted: C:\WINDOWS\system32\l46o0ej3eho.dll
deleting: C:\WINDOWS\system32\LPDIS11n.dll
Successfully Deleted: C:\WINDOWS\system32\LPDIS11n.dll
deleting: C:\WINDOWS\system32\lv0209doe.dll
Successfully Deleted: C:\WINDOWS\system32\lv0209doe.dll
deleting: C:\WINDOWS\system32\lv8m09l1e.dll
Successfully Deleted: C:\WINDOWS\system32\lv8m09l1e.dll
deleting: C:\WINDOWS\system32\lvghours.dll
Successfully Deleted: C:\WINDOWS\system32\lvghours.dll
deleting: C:\WINDOWS\system32\lvlu0939e.dll
Successfully Deleted: C:\WINDOWS\system32\lvlu0939e.dll
deleting: C:\WINDOWS\system32\lvp8097ue.dll
Successfully Deleted: C:\WINDOWS\system32\lvp8097ue.dll
deleting: C:\WINDOWS\system32\m4rmle911h.dll
Successfully Deleted: C:\WINDOWS\system32\m4rmle911h.dll
deleting: C:\WINDOWS\system32\m646lghs1646.dll
Successfully Deleted: C:\WINDOWS\system32\m646lghs1646.dll
deleting: C:\WINDOWS\system32\mbpbde40.dll
Successfully Deleted: C:\WINDOWS\system32\mbpbde40.dll
deleting: C:\WINDOWS\system32\mcjint40.dll
Successfully Deleted: C:\WINDOWS\system32\mcjint40.dll
deleting: C:\WINDOWS\system32\moxlegih.dll
Successfully Deleted: C:\WINDOWS\system32\moxlegih.dll
deleting: C:\WINDOWS\system32\mpmtapi.dll
Successfully Deleted: C:\WINDOWS\system32\mpmtapi.dll
deleting: C:\WINDOWS\system32\mrwmdm.dll
Successfully Deleted: C:\WINDOWS\system32\mrwmdm.dll
deleting: C:\WINDOWS\system32\msminst.dll
Successfully Deleted: C:\WINDOWS\system32\msminst.dll
deleting: C:\WINDOWS\system32\mv40l9hm1.dll
Successfully Deleted: C:\WINDOWS\system32\mv40l9hm1.dll
deleting: C:\WINDOWS\system32\mvl_hp.dll
Successfully Deleted: C:\WINDOWS\system32\mvl_hp.dll
deleting: C:\WINDOWS\system32\mwexcl40.dll
Successfully Deleted: C:\WINDOWS\system32\mwexcl40.dll
deleting: C:\WINDOWS\system32\MYRio300.dll
Successfully Deleted: C:\WINDOWS\system32\MYRio300.dll
deleting: C:\WINDOWS\system32\mz40l9hm1.dll
Successfully Deleted: C:\WINDOWS\system32\mz40l9hm1.dll
deleting: C:\WINDOWS\system32\nttevent.dll
Successfully Deleted: C:\WINDOWS\system32\nttevent.dll
deleting: C:\WINDOWS\system32\ofbccu32.dll
Successfully Deleted: C:\WINDOWS\system32\ofbccu32.dll
deleting: C:\WINDOWS\system32\p04ulah91d4.dll
Successfully Deleted: C:\WINDOWS\system32\p04ulah91d4.dll
deleting: C:\WINDOWS\system32\p8p6li7s18.dll
Successfully Deleted: C:\WINDOWS\system32\p8p6li7s18.dll
deleting: C:\WINDOWS\system32\pqrpnsp.dll
Successfully Deleted: C:\WINDOWS\system32\pqrpnsp.dll
deleting: C:\WINDOWS\system32\q6nulg5916.dll
Successfully Deleted: C:\WINDOWS\system32\q6nulg5916.dll
deleting: C:\WINDOWS\system32\rwutils.dll
Successfully Deleted: C:\WINDOWS\system32\rwutils.dll
deleting: C:\WINDOWS\system32\s0pu0a79ed.dll
Successfully Deleted: C:\WINDOWS\system32\s0pu0a79ed.dll
deleting: C:\WINDOWS\system32\SLP32.DLL
Successfully Deleted: C:\WINDOWS\system32\SLP32.DLL
deleting: C:\WINDOWS\system32\tnddd.dll
Successfully Deleted: C:\WINDOWS\system32\tnddd.dll
deleting: C:\WINDOWS\system32\tzpmib.dll
Successfully Deleted: C:\WINDOWS\system32\tzpmib.dll
deleting: C:\WINDOWS\system32\vxdex.dll
Successfully Deleted: C:\WINDOWS\system32\vxdex.dll
deleting: C:\WINDOWS\system32\wgnmm.dll
Successfully Deleted: C:\WINDOWS\system32\wgnmm.dll
deleting: C:\WINDOWS\system32\wtauserv.dll
Successfully Deleted: C:\WINDOWS\system32\wtauserv.dll
deleting: C:\WINDOWS\system32\guard.tmp
Successfully Deleted: C:\WINDOWS\system32\guard.tmp
Desktop.ini sucessfully removed
Zipping up files for submission:
adding: aztxprxy.dll (164 bytes security) (deflated 4%)
adding: cdmres.dll (164 bytes security) (deflated 4%)
adding: dn4s01h7e.dll (164 bytes security) (deflated 4%)
adding: dnr4019qe.dll (164 bytes security) (deflated 4%)
adding: e6jmlg1116.dll (164 bytes security) (deflated 5%)
adding: en68l1ju1.dll (164 bytes security) (deflated 4%)
adding: enr4l19q1.dll (164 bytes security) (deflated 4%)
adding: f2l0lc3m1f.dll (164 bytes security) (deflated 3%)
adding: f6l00g3me6.dll (164 bytes security) (deflated 4%)
adding: g0lm0a31ed.dll (164 bytes security) (deflated 4%)
adding: g4jo0e13eh.dll (164 bytes security) (deflated 4%)
adding: gpj6l31s1.dll (164 bytes security) (deflated 4%)
adding: h20q0cd5ef0.dll (164 bytes security) (deflated 4%)
adding: hH23msp.dll (164 bytes security) (deflated 4%)
adding: hrro0593e.dll (164 bytes security) (deflated 4%)
adding: idengine.dll (164 bytes security) (deflated 4%)
adding: ir60l5jm1.dll (164 bytes security) (deflated 5%)
adding: ir8ul5l91.dll (164 bytes security) (deflated 4%)
adding: jt2m07f1e.dll (164 bytes security) (deflated 4%)
adding: jt4m07h1e.dll (164 bytes security) (deflated 5%)
adding: k408ledu1h08.dll (164 bytes security) (deflated 4%)
adding: k4lqle351h.dll (164 bytes security) (deflated 5%)
adding: kddest.dll (164 bytes security) (deflated 5%)
adding: kfdur.dll (164 bytes security) (deflated 4%)
adding: kidblr.dll (164 bytes security) (deflated 4%)
adding: ktl0l73m1.dll (164 bytes security) (deflated 4%)
adding: ktlsl7371.dll (164 bytes security) (deflated 4%)
adding: ktpml7711.dll (164 bytes security) (deflated 5%)
adding: l2l60c3sef.dll (164 bytes security) (deflated 4%)
adding: l46o0ej3eho.dll (164 bytes security) (deflated 4%)
adding: LPDIS11n.dll (164 bytes security) (deflated 4%)
adding: lv0209doe.dll (164 bytes security) (deflated 4%)
adding: lv8m09l1e.dll (164 bytes security) (deflated 4%)
adding: lvghours.dll (164 bytes security) (deflated 5%)
adding: lvlu0939e.dll (164 bytes security) (deflated 4%)
adding: lvp8097ue.dll (164 bytes security) (deflated 4%)
adding: m4rmle911h.dll (164 bytes security) (deflated 4%)
adding: m646lghs1646.dll (164 bytes security) (deflated 4%)
adding: mbpbde40.dll (164 bytes security) (deflated 4%)
adding: mcjint40.dll (164 bytes security) (deflated 4%)
adding: moxlegih.dll (164 bytes security) (deflated 4%)
adding: mpmtapi.dll (164 bytes security) (deflated 5%)
adding: mrwmdm.dll (164 bytes security) (deflated 3%)
adding: msminst.dll (164 bytes security) (deflated 4%)
adding: mv40l9hm1.dll (164 bytes security) (deflated 4%)
adding: mvl_hp.dll (164 bytes security) (deflated 4%)
adding: mwexcl40.dll (164 bytes security) (deflated 5%)
adding: MYRio300.dll (164 bytes security) (deflated 4%)
adding: mz40l9hm1.dll (164 bytes security) (deflated 4%)
adding: nttevent.dll (164 bytes security) (deflated 5%)
adding: ofbccu32.dll (164 bytes security) (deflated 3%)
adding: p04ulah91d4.dll (164 bytes security) (deflated 4%)
adding: p8p6li7s18.dll (164 bytes security) (deflated 3%)
adding: pqrpnsp.dll (164 bytes security) (deflated 5%)
adding: q6nulg5916.dll (164 bytes security) (deflated 4%)
adding: rwutils.dll (164 bytes security) (deflated 4%)
adding: s0pu0a79ed.dll (164 bytes security) (deflated 4%)
adding: SLP32.DLL (164 bytes security) (deflated 4%)
adding: tnddd.dll (164 bytes security) (deflated 4%)
adding: tzpmib.dll (164 bytes security) (deflated 4%)
adding: vxdex.dll (164 bytes security) (deflated 4%)
adding: wgnmm.dll (164 bytes security) (deflated 5%)
adding: wtauserv.dll (164 bytes security) (deflated 5%)
adding: guard.tmp (164 bytes security) (deflated 4%)
adding: clear.reg (164 bytes security) (deflated 55%)
adding: echo.reg (164 bytes security) (deflated 9%)
adding: desktop.ini (164 bytes security) (deflated 13%)
adding: direct.txt (164 bytes security) (stored 0%)
adding: lo2.txt (164 bytes security) (deflated 87%)
adding: readme.txt (164 bytes security) (deflated 49%)
adding: report.txt (164 bytes security) (deflated 69%)
adding: test.txt (164 bytes security) (deflated 83%)
adding: test2.txt (164 bytes security) (deflated 36%)
adding: test3.txt (164 bytes security) (deflated 36%)
adding: test5.txt (164 bytes security) (deflated 36%)
adding: xfind.txt (164 bytes security) (deflated 78%)
adding: backregs/24A942D3-E6A3-498F-AC80-594AEFC962E4.reg (164 bytes security)
(deflated 70%)
adding: backregs/6D26AA7A-4722-46E1-9B11-07ABDFFFBFDE.reg (164 bytes security)
(deflated 70%)
adding: backregs/7FDE72E5-B4B0-4A6D-8452-D3441580D712.reg (164 bytes security)
(deflated 70%)
adding: backregs/92E5FBC7-4296-4FC0-B287-D45D0D43ABD2.reg (164 bytes security)
(deflated 70%)
adding: backregs/C8D06C4A-0E5B-4A5B-A1F6-03A7B60CF9D4.reg (164 bytes security)
(deflated 70%)
adding: backregs/shell.reg (164 bytes security) (deflated 73%)
Restoring Registry Permissions:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (
http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Revoking access for really "Everyone"
Registry permissions set too:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (
http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify:
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER
Restoring Sedebugprivilege:
Granting SeDebugPrivilege to Administrators ... successful
deleting local copy: aztxprxy.dll
deleting local copy: cdmres.dll
deleting local copy: dn4s01h7e.dll
deleting local copy: dnr4019qe.dll
deleting local copy: e6jmlg1116.dll
deleting local copy: en68l1ju1.dll
deleting local copy: enr4l19q1.dll
deleting local copy: f2l0lc3m1f.dll
deleting local copy: f6l00g3me6.dll
deleting local copy: g0lm0a31ed.dll
deleting local copy: g4jo0e13eh.dll
deleting local copy: gpj6l31s1.dll
deleting local copy: h20q0cd5ef0.dll
deleting local copy: hH23msp.dll
deleting local copy: hrro0593e.dll
deleting local copy: idengine.dll
deleting local copy: ir60l5jm1.dll
deleting local copy: ir8ul5l91.dll
deleting local copy: jt2m07f1e.dll
deleting local copy: jt4m07h1e.dll
deleting local copy: k408ledu1h08.dll
deleting local copy: k4lqle351h.dll
deleting local copy: kddest.dll
deleting local copy: kfdur.dll
deleting local copy: kidblr.dll
deleting local copy: ktl0l73m1.dll
deleting local copy: ktlsl7371.dll
deleting local copy: ktpml7711.dll
deleting local copy: l2l60c3sef.dll
deleting local copy: l46o0ej3eho.dll
deleting local copy: LPDIS11n.dll
deleting local copy: lv0209doe.dll
deleting local copy: lv8m09l1e.dll
deleting local copy: lvghours.dll
deleting local copy: lvlu0939e.dll
deleting local copy: lvp8097ue.dll
deleting local copy: m4rmle911h.dll
deleting local copy: m646lghs1646.dll
deleting local copy: mbpbde40.dll
deleting local copy: mcjint40.dll
deleting local copy: moxlegih.dll
deleting local copy: mpmtapi.dll
deleting local copy: mrwmdm.dll
deleting local copy: msminst.dll
deleting local copy: mv40l9hm1.dll
deleting local copy: mvl_hp.dll
deleting local copy: mwexcl40.dll
deleting local copy: MYRio300.dll
deleting local copy: mz40l9hm1.dll
deleting local copy: nttevent.dll
deleting local copy: ofbccu32.dll
deleting local copy: p04ulah91d4.dll
deleting local copy: p8p6li7s18.dll
deleting local copy: pqrpnsp.dll
deleting local copy: q6nulg5916.dll
deleting local copy: rwutils.dll
deleting local copy: s0pu0a79ed.dll
deleting local copy: SLP32.DLL
deleting local copy: tnddd.dll
deleting local copy: tzpmib.dll
deleting local copy: vxdex.dll
deleting local copy: wgnmm.dll
deleting local copy: wtauserv.dll
deleting local copy: guard.tmp
The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
The following are the files found:
****************************************************************************
C:\WINDOWS\system32\aztxprxy.dll
C:\WINDOWS\system32\cdmres.dll
C:\WINDOWS\system32\dn4s01h7e.dll
C:\WINDOWS\system32\dnr4019qe.dll
C:\WINDOWS\system32\e6jmlg1116.dll
C:\WINDOWS\system32\en68l1ju1.dll
C:\WINDOWS\system32\enr4l19q1.dll
C:\WINDOWS\system32\f2l0lc3m1f.dll
C:\WINDOWS\system32\f6l00g3me6.dll
C:\WINDOWS\system32\g0lm0a31ed.dll
C:\WINDOWS\system32\g4jo0e13eh.dll
C:\WINDOWS\system32\gpj6l31s1.dll
C:\WINDOWS\system32\h20q0cd5ef0.dll
C:\WINDOWS\system32\hH23msp.dll
C:\WINDOWS\system32\hrro0593e.dll
C:\WINDOWS\system32\idengine.dll
C:\WINDOWS\system32\ir60l5jm1.dll
C:\WINDOWS\system32\ir8ul5l91.dll
C:\WINDOWS\system32\jt2m07f1e.dll
C:\WINDOWS\system32\jt4m07h1e.dll
C:\WINDOWS\system32\k408ledu1h08.dll
C:\WINDOWS\system32\k4lqle351h.dll
C:\WINDOWS\system32\kddest.dll
C:\WINDOWS\system32\kfdur.dll
C:\WINDOWS\system32\kidblr.dll
C:\WINDOWS\system32\ktl0l73m1.dll
C:\WINDOWS\system32\ktlsl7371.dll
C:\WINDOWS\system32\ktpml7711.dll
C:\WINDOWS\system32\l2l60c3sef.dll
C:\WINDOWS\system32\l46o0ej3eho.dll
C:\WINDOWS\system32\LPDIS11n.dll
C:\WINDOWS\system32\lv0209doe.dll
C:\WINDOWS\system32\lv8m09l1e.dll
C:\WINDOWS\system32\lvghours.dll
C:\WINDOWS\system32\lvlu0939e.dll
C:\WINDOWS\system32\lvp8097ue.dll
C:\WINDOWS\system32\m4rmle911h.dll
C:\WINDOWS\system32\m646lghs1646.dll
C:\WINDOWS\system32\mbpbde40.dll
C:\WINDOWS\system32\mcjint40.dll
C:\WINDOWS\system32\moxlegih.dll
C:\WINDOWS\system32\mpmtapi.dll
C:\WINDOWS\system32\mrwmdm.dll
C:\WINDOWS\system32\msminst.dll
C:\WINDOWS\system32\mv40l9hm1.dll
C:\WINDOWS\system32\mvl_hp.dll
C:\WINDOWS\system32\mwexcl40.dll
C:\WINDOWS\system32\MYRio300.dll
C:\WINDOWS\system32\mz40l9hm1.dll
C:\WINDOWS\system32\nttevent.dll
C:\WINDOWS\system32\ofbccu32.dll
C:\WINDOWS\system32\p04ulah91d4.dll
C:\WINDOWS\system32\p8p6li7s18.dll
C:\WINDOWS\system32\pqrpnsp.dll
C:\WINDOWS\system32\q6nulg5916.dll
C:\WINDOWS\system32\rwutils.dll
C:\WINDOWS\system32\s0pu0a79ed.dll
C:\WINDOWS\system32\SLP32.DLL
C:\WINDOWS\system32\tnddd.dll
C:\WINDOWS\system32\tzpmib.dll
C:\WINDOWS\system32\vxdex.dll
C:\WINDOWS\system32\wgnmm.dll
C:\WINDOWS\system32\wtauserv.dll
C:\WINDOWS\system32\guard.tmp
Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell
Extensions\Approved]
"{24A942D3-E6A3-498F-AC80-594AEFC962E4}"=-
"{92E5FBC7-4296-4FC0-B287-D45D0D43ABD2}"=-
"{C8D06C4A-0E5B-4A5B-A1F6-03A7B60CF9D4}"=-
"{6D26AA7A-4722-46E1-9B11-07ABDFFFBFDE}"=-
"{7FDE72E5-B4B0-4A6D-8452-D3441580D712}"=-
[-HKEY_CLASSES_ROOT\CLSID\{24A942D3-E6A3-498F-AC80-594AEFC962E4}]
[-HKEY_CLASSES_ROOT\CLSID\{92E5FBC7-4296-4FC0-B287-D45D0D43ABD2}]
[-HKEY_CLASSES_ROOT\CLSID\{C8D06C4A-0E5B-4A5B-A1F6-03A7B60CF9D4}]
[-HKEY_CLASSES_ROOT\CLSID\{6D26AA7A-4722-46E1-9B11-07ABDFFFBFDE}]
[-HKEY_CLASSES_ROOT\CLSID\{7FDE72E5-B4B0-4A6D-8452-D3441580D712}]
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet
Settings\User Agent\Post Platform]
"{52B9BBD7-12BF-4266-88AC-6FFA69968EAF}"=-
"SV1"=""
****************************************************************************
Desktop.ini Contents:
****************************************************************************
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
<IDone>{52B9BBD7-12BF-4266-88AC-6FFA69968EAF}</IDone>
<IDtwo>VT03</IDtwo>
<VERSION>200</VERSION>
****************************************************************************