Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

HJT Log - Jaems


  • Please log in to reply
9 replies to this topic

#1 Jaems

Jaems

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:08:04 PM

Posted 07 May 2005 - 11:04 AM

I've run both Adaware SE, and Spybot S-D, they found several things, which they 'fixed'. However, the problem, pop-ups nearly every 10-15 minutes no matter what is going on, persists.

Here is My Log:

Logfile of HijackThis v1.99.1
Scan saved at 10:56:59 AM, on 5/7/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
G:\Program Files\Norton Personal Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
G:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
G:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
G:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\tcpsvcs.exe
G:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\system32\vmvkrr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\nsvsvc\nsvsvc.exe
C:\WINDOWS\system32\picsvr\picsvr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
E:\Cody's Misc. Stuff\aim\aim.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/...://my.yahoo.com
O3 - Toolbar: Norton Personal Firewall - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - G:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\vmvkrr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [tsvcin] C:\WINDOWS\system32\n20050308.EXE
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\system32\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [picsvr] C:\WINDOWS\system32\picsvr\picsvr.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKCU\..\Run: [AIM] E:\Cody's Misc. Stuff\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Ersa] C:\Documents and Settings\Willie.MICRONPC\Application Data\ihss.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - E:\Cody's Misc. Stuff\aim\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/...tiveXPlugin.cab
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Service Client v.3.4) - http://ccon.futuremark.com/global/msc34.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{953309F4-A78E-4383-A175-0DEE9B501832}: Domain = mshome.net
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - (no file)
O20 - Winlogon Notify: IPConfTSP - C:\WINDOWS\system32\fp2603fse.dll
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - D:\Program Files\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - G:\Program Files\Norton Personal Firewall\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - G:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - G:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - G:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: SAVScan - Symantec Corporation - G:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - G:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Thanks.

BC AdBot (Login to Remove)

 


#2 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,542 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:09:04 PM

Posted 07 May 2005 - 04:16 PM

Print out these instructions and then close all windows including Internet Explorer.

Then I want you to fix some of those entries. Please do the following:

Please make sure that you can view all hidden files. Instructions on how to do this can be found here:

How to see hidden files in Windows

Run Hijackthis again, click scan, and Put a checkmark next to each of these. Then click the Fix button:


R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/...://my.yahoo.com
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\vmvkrr.exe
O4 - HKLM\..\Run: [tsvcin] C:\WINDOWS\system32\n20050308.EXE
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\system32\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [picsvr] C:\WINDOWS\system32\picsvr\picsvr.exe
O4 - HKCU\..\Run: [Ersa] C:\Documents and Settings\Willie.MICRONPC\Application Data\ihss.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - (no file)
O20 - Winlogon Notify: IPConfTSP - C:\WINDOWS\system32\fp2603fse.dll

Reboot your computer into Safe Mode

Then delete these files or directories (Do not be concerned if they do not exist)

C:\WINDOWS\system32\vmvkrr.exe
C:\WINDOWS\system32\n20050308.EXE
C:\WINDOWS\system32\nsvsvc\
C:\WINDOWS\system32\picsvr\picsvr.exe
C:\Documents and Settings\Willie.MICRONPC\Application Data\ihss.exe
C:\WINDOWS\system32\fp2603fse.dll

Reboot your computer to go back to normal mode and post a new log.

Download L2mfix from one of these two locations:

http://www.atribune.org/downloads/l2mfix.exe
http://www.downloads.subratam.org/l2mfix.exe

Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!

#3 Jaems

Jaems
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:08:04 PM

Posted 08 May 2005 - 12:34 PM

When deleting the files in safe mode, I found vmvkrr.exe, however it couldn't be deleted because it was being used.

Here is L2mfix's log:

L2MFIX find log 1.03
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Explorer]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\h64m0gh1e64.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

**********************************************************************************
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{B7AC15B3-E3CD-0C14-BB87-B4F182460F45}"=""

**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run..."
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People..."
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{5E44E225-A408-11CF-B581-008029601108}"="Adaptec DirectCD Shell Extension"
"{0006F045-0000-0000-C000-000000000046}"="Microsoft Outlook Custom Icon Handler"
"{1CDB2949-8F65-4355-8456-263E7C208A5D}"="Desktop Explorer"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}"="Desktop Explorer Menu"
"{e57ce731-33e8-4c51-8354-bb4de9d215d1}"="Universal Plug and Play Devices"
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
"{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
"{5464D816-CF16-4784-B9F3-75C0DB52B499}"="Yahoo! Mail"
"{A70C977A-BF00-412C-90B7-034C51DA2439}"="NvCpl DesktopContext Class"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A48}"="nView Desktop Context Menu"
"{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
"{FED7043D-346A-414D-ACD7-550D052499A7}"="dBpowerAMP Music Converter 1"
"{2C49B5D0-ACE7-4D17-9DF0-A254A6C5A0C5}"="dBpowerAMP Music Converter"
"{519CD672-8EF3-42F1-AAFA-89167C830588}"=""
"{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}"="iTunes"
"{A8D7E505-BF24-4698-B619-4BE58BADFF82}"=""
"{A5552847-4804-45E7-B0AE-B54F677F92D0}"=""
"{4243CA87-C045-4FD7-9940-2FF567F78CF0}"=""
"{F02E8617-B0FF-433C-9038-A3B5E33BC866}"=""
"{1F503F2D-D737-4B52-87AB-B1FD31C9E055}"=""
"{7D0FD3AA-219C-4E5F-AE73-6FF79AB04683}"=""
"{558C6E5D-4AAF-4BB0-BB3D-01F83AF5A50B}"=""
"{E9B355B2-F5CF-45CC-9D9A-CBBD84E11FD5}"=""
"{4252319C-5361-469A-86A2-C1AAB4828C43}"=""
"{C4F24F5A-E026-4A82-B177-C4DD8CF68458}"=""
"{950A9609-FB3E-452E-BF5A-7ABD793CFF90}"=""
"{BBE0559F-0667-4B7A-89EE-2A40AA7D1056}"=""
"{73E35E28-0E1D-44B2-BD4D-F2D8A8BFE494}"=""
"{565F8AB9-F3C1-40CC-9C90-F0608DFE2762}"=""
"{EE3A6AFC-CAD5-4718-99A2-CDEEB60F1200}"=""
"{33A404FE-82F9-446C-B18A-9D2FA22172F9}"=""
"{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
"{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
"{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
"{7D6DD24B-77C6-408F-ACA3-877F95647604}"=""
"{9DD3D014-2900-4326-9B94-DA546CC7B08B}"=""
"{02403FA0-EA02-4DCA-BF89-08559E2AB8C5}"=""
"{C66491F2-3ED0-4221-9734-9083DED88E92}"=""

**********************************************************************************
HKEY ROOT CLASSIDS:
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{558C6E5D-4AAF-4BB0-BB3D-01F83AF5A50B}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{558C6E5D-4AAF-4BB0-BB3D-01F83AF5A50B}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{558C6E5D-4AAF-4BB0-BB3D-01F83AF5A50B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{558C6E5D-4AAF-4BB0-BB3D-01F83AF5A50B}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{950A9609-FB3E-452E-BF5A-7ABD793CFF90}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{950A9609-FB3E-452E-BF5A-7ABD793CFF90}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{950A9609-FB3E-452E-BF5A-7ABD793CFF90}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{950A9609-FB3E-452E-BF5A-7ABD793CFF90}\InprocServer32]
@="C:\\WINDOWS\\system32\\MAWMDM.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{BBE0559F-0667-4B7A-89EE-2A40AA7D1056}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{BBE0559F-0667-4B7A-89EE-2A40AA7D1056}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{BBE0559F-0667-4B7A-89EE-2A40AA7D1056}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{BBE0559F-0667-4B7A-89EE-2A40AA7D1056}\InprocServer32]
@="C:\\WINDOWS\\system32\\ked106n.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{73E35E28-0E1D-44B2-BD4D-F2D8A8BFE494}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{73E35E28-0E1D-44B2-BD4D-F2D8A8BFE494}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{73E35E28-0E1D-44B2-BD4D-F2D8A8BFE494}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{73E35E28-0E1D-44B2-BD4D-F2D8A8BFE494}\InprocServer32]
@="C:\\WINDOWS\\system32\\crgbkend.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{565F8AB9-F3C1-40CC-9C90-F0608DFE2762}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{565F8AB9-F3C1-40CC-9C90-F0608DFE2762}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{565F8AB9-F3C1-40CC-9C90-F0608DFE2762}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{565F8AB9-F3C1-40CC-9C90-F0608DFE2762}\InprocServer32]
@="C:\\WINDOWS\\system32\\miencode.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{EE3A6AFC-CAD5-4718-99A2-CDEEB60F1200}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{EE3A6AFC-CAD5-4718-99A2-CDEEB60F1200}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{EE3A6AFC-CAD5-4718-99A2-CDEEB60F1200}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{EE3A6AFC-CAD5-4718-99A2-CDEEB60F1200}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{33A404FE-82F9-446C-B18A-9D2FA22172F9}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{33A404FE-82F9-446C-B18A-9D2FA22172F9}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{33A404FE-82F9-446C-B18A-9D2FA22172F9}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{33A404FE-82F9-446C-B18A-9D2FA22172F9}\InprocServer32]
@="C:\\WINDOWS\\system32\\latif12n.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{7D6DD24B-77C6-408F-ACA3-877F95647604}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7D6DD24B-77C6-408F-ACA3-877F95647604}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7D6DD24B-77C6-408F-ACA3-877F95647604}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7D6DD24B-77C6-408F-ACA3-877F95647604}\InprocServer32]
@="C:\\WINDOWS\\system32\\smmsg.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{9DD3D014-2900-4326-9B94-DA546CC7B08B}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9DD3D014-2900-4326-9B94-DA546CC7B08B}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9DD3D014-2900-4326-9B94-DA546CC7B08B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9DD3D014-2900-4326-9B94-DA546CC7B08B}\InprocServer32]
@="C:\\WINDOWS\\system32\\ndtmsg.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{02403FA0-EA02-4DCA-BF89-08559E2AB8C5}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{02403FA0-EA02-4DCA-BF89-08559E2AB8C5}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{02403FA0-EA02-4DCA-BF89-08559E2AB8C5}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{02403FA0-EA02-4DCA-BF89-08559E2AB8C5}\InprocServer32]
@="C:\\WINDOWS\\system32\\luasrv.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{C66491F2-3ED0-4221-9734-9083DED88E92}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{C66491F2-3ED0-4221-9734-9083DED88E92}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{C66491F2-3ED0-4221-9734-9083DED88E92}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{C66491F2-3ED0-4221-9734-9083DED88E92}\InprocServer32]
@="C:\\WINDOWS\\system32\\kaymgr.dll"
"ThreadingModel"="Apartment"

**********************************************************************************
Files Found are not all bad files:

C:\WINDOWS\SYSTEM32\
smmsg.dll Sun May 8 2005 12:26:52p ..S.R 234,830 229.32 K
apaun.dll Wed May 4 2005 8:17:42p A.... 4,096 4.00 K
ndtmsg.dll Sun May 8 2005 9:06:50a ..S.R 234,638 229.14 K
irr2l5~1.dll Wed May 4 2005 8:41:16p ..S.R 234,638 229.14 K
kaymgr.dll Sun May 8 2005 11:56:00a ..S.R 234,684 229.18 K
luasrv.dll Sun May 8 2005 11:41:30a ..S.R 234,638 229.14 K
l22slc~1.dll Wed May 4 2005 8:16:00p ..S.R 234,638 229.14 K
ir2ml5~1.dll Wed May 4 2005 8:44:46p ..S.R 234,638 229.14 K
h0l2la~1.dll Thu May 5 2005 3:33:50p ..S.R 234,638 229.14 K
lv6609~1.dll Wed May 4 2005 5:36:56p ..S.R 235,307 229.79 K
symredir.dll Tue Apr 5 2005 11:17:04a A.... 132,824 129.71 K
symneti.dll Tue Apr 5 2005 11:17:04a A.... 517,848 505.71 K
kt4ml7~1.dll Sun May 8 2005 9:15:50a ..S.R 234,638 229.14 K
dnp001~1.dll Thu May 5 2005 5:55:00p ..S.R 234,638 229.14 K
dnns01~1.dll Thu May 5 2005 8:05:50p ..S.R 234,638 229.14 K
fnl021~1.dll Thu May 5 2005 8:10:26p ..S.R 234,638 229.14 K
kt0ql7~1.dll Fri May 6 2005 12:44:58a ..S.R 234,638 229.14 K
enj2l1~1.dll Fri May 6 2005 7:08:36p ..S.R 234,638 229.14 K
fplq03~1.dll Fri May 6 2005 11:18:00p ..S.R 234,638 229.14 K
mv62l9~1.dll Sun May 8 2005 12:26:52p ..S.R 236,099 230.56 K
g2jolc~1.dll Thu May 5 2005 3:52:00p ..S.R 234,638 229.14 K
l44q0e~1.dll Thu May 5 2005 5:06:52p ..S.R 234,638 229.14 K
i624lg~1.dll Thu May 5 2005 11:07:20p ..S.R 234,638 229.14 K
f00ola~1.dll Fri May 6 2005 7:07:36p ..S.R 235,938 230.41 K
p6p6lg~1.dll Sat May 7 2005 10:06:36a ..S.R 234,638 229.14 K
aza2la~1.dll Sat May 7 2005 10:14:54a ..S.R 234,638 229.14 K
h64m0g~1.dll Sun May 8 2005 11:56:00a ..S.R 234,830 229.32 K
e2jmlc~1.dll Sun May 8 2005 11:24:54a ..S.R 234,638 229.14 K
g604lg~1.dll Sun May 8 2005 12:10:14p ..S.R 236,236 230.70 K
sporder.dll Fri Apr 22 2005 4:19:58p A.... 8,464 8.27 K
thtrppg.dll Fri Mar 25 2005 10:11:56p A.... 27,136 26.50 K
msi.dll Mon Mar 21 2005 3:00:20p A.... 2,890,240 2.75 M
msihnd.dll Mon Mar 21 2005 3:00:22p A.... 271,360 265.00 K
msimsg.dll Mon Mar 21 2005 3:00:22p A.... 884,736 864.00 K
msisip.dll Mon Mar 21 2005 3:00:22p A.... 15,360 15.00 K
shell32.dll Mon Feb 28 2005 6:11:18p A.... 8,450,048 8.06 M
winsrv.dll Wed Mar 2 2005 1:09:30p A.... 291,328 284.50 K
user32.dll Wed Mar 2 2005 1:09:30p A.... 577,024 563.50 K
authz.dll Wed Mar 2 2005 1:09:30p A.... 56,832 55.50 K
mscoree.dll Sat Apr 9 2005 12:40:10a A.... 253,952 248.00 K
mscorier.dll Sat Apr 9 2005 2:17:28a A.... 150,528 147.00 K
mscories.dll Fri Apr 8 2005 8:14:26p A.... 76,800 75.00 K
netfxp~1.dll Fri Apr 8 2005 6:35:16p A.... 32,768 32.00 K
msvcm80d.dll Fri Apr 8 2005 6:43:32p A.... 1,089,536 1.04 M
spmsg.dll Thu Feb 24 2005 7:35:06p ..... 14,048 13.72 K
wininet.dll Thu Mar 10 2005 3:02:36a A.... 656,896 641.50 K
urlmon.dll Thu Mar 10 2005 3:02:36a A.... 607,744 593.50 K
shlwapi.dll Thu Mar 10 2005 3:02:34a A.... 473,600 462.50 K
shdocvw.dll Thu Mar 10 2005 3:02:34a A.... 1,483,264 1.41 M
msrating.dll Thu Mar 10 2005 3:02:34a A.... 146,432 143.00 K
mshtml.dll Thu Mar 10 2005 3:02:34a A.... 3,010,560 2.87 M
inseng.dll Thu Mar 10 2005 3:02:34a A.... 96,256 94.00 K
iepeers.dll Thu Mar 10 2005 3:02:34a A.... 250,880 245.00 K
cdfview.dll Thu Mar 10 2005 3:02:34a A.... 151,040 147.50 K
browseui.dll Thu Mar 10 2005 3:02:34a A.... 1,016,832 993.00 K

55 items found: 55 files (26 H/S), 0 directories.
Total of file sizes: 29,744,478 bytes 28.36 M
Locate .tmp files:

No matches found.
**********************************************************************************
Directory Listing of system files:
Volume in drive C is DISK1PART01
Volume Serial Number is 5A6F-02EE

Directory of C:\WINDOWS\System32

05/08/2005 12:26 PM 234,830 smmsg.dll
05/08/2005 12:26 PM 236,099 mv62l9jo1.dll
05/08/2005 12:10 PM 236,236 g604lgdq160e.dll
05/08/2005 11:56 AM 234,684 kaymgr.dll
05/08/2005 11:56 AM 234,830 h64m0gh1e64.dll
05/08/2005 11:41 AM 234,638 luasrv.dll
05/08/2005 11:24 AM 234,638 e2jmlc111f.dll
05/08/2005 09:15 AM 234,638 kt4ml7h11.dll
05/08/2005 09:06 AM 234,638 ndtmsg.dll
05/07/2005 10:14 AM 234,638 aza2la3o1d.dll
05/07/2005 10:06 AM 234,638 p6p6lg7s16.dll
05/06/2005 11:18 PM 234,638 fplq0335e.dll
05/06/2005 07:08 PM 234,638 enj2l11o1.dll
05/06/2005 07:07 PM 235,938 f00olad31d0.dll
05/06/2005 12:44 AM 234,638 kt0ql7d51.dll
05/05/2005 11:07 PM 234,638 i624lgfq162e.dll
05/05/2005 08:10 PM 234,638 fnl0213mg.dll
05/05/2005 08:05 PM 234,638 dnns0157e.dll
05/05/2005 05:55 PM 234,638 dnp0017me.dll
05/05/2005 05:06 PM 234,638 l44q0eh5eh4.dll
05/05/2005 03:52 PM 234,638 g2jolc131f.dll
05/05/2005 03:33 PM 234,638 h0l2la3o1d.dll
05/04/2005 08:44 PM 234,638 ir2ml5f11.dll
05/04/2005 08:41 PM 234,638 irr2l59o1.dll
05/04/2005 08:16 PM 234,638 l22slcf71f2.dll
05/04/2005 05:36 PM 235,307 lv6609jse.dll
09/22/2003 07:36 PM <DIR> Microsoft
09/22/2003 06:20 PM 6,144 access.ctl
09/22/2003 06:20 PM <DIR> dllcache
09/09/1999 10:06 PM 168,720 msltus35.dll
06/07/1999 06:59 PM 250,128 mspdox35.dll
04/25/1999 05:00 PM 287,504 Msxbse35.dll
30 File(s) 6,818,542 bytes
2 Dir(s) 923,000,832 bytes free

-Thanks

#4 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,542 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:09:04 PM

Posted 08 May 2005 - 03:56 PM

Close any programs you have open since this step requires a reboot.

From the l2mfix folder on your desktop, double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing enter, then press any key to reboot your computer. After a reboot, your desktop and icons will appear, then disappear (this is normal). L2mfix will continue to scan your computer and when it's finished, notepad will open with a log. Copy the contents of that log and paste it back into this thread, along with a new hijackthis log.

IMPORTANT: Do NOT run any other files in the l2mfix folder until you are asked to do so!

#5 Jaems

Jaems
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:08:04 PM

Posted 08 May 2005 - 05:01 PM

New Log:

L2Mfix 1.03

Running From:
C:\Documents and Settings\Ben.MICRONPC\Desktop\l2mfix



RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Read BUILTIN\Power Users
(ID-IO) ALLOW Read BUILTIN\Power Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER



Setting registry permissions:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!


Denying C(CI) access for predefined group "Administrators"
- adding new ACCESS DENY entry


Registry Permissions set too:

RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(CI) DENY --C------- BUILTIN\Administrators
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Read BUILTIN\Power Users
(ID-IO) ALLOW Read BUILTIN\Power Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER



Setting up for Reboot


Starting Reboot!

C:\Documents and Settings\Ben.MICRONPC\Desktop\l2mfix
System Rebooted!

Running From:
C:\Documents and Settings\Ben.MICRONPC\Desktop\l2mfix

killing explorer and rundll32.exe

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 1792 'explorer.exe'
Killing PID 1792 'explorer.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 168 'rundll32.exe'

Scanning First Pass. Please Wait!

First Pass Completed

Second Pass Scanning

Second pass Completed!
Backing Up: C:\WINDOWS\system32\smmsg.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\wyhisn.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\irr2l59o1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\kaymgr.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\luasrv.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mlxlegih.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\l22slcf71f2.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ir2ml5f11.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\h0l2la3o1d.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\lv6609jse.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\kt4ml7h11.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dnp0017me.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dnns0157e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\fnl0213mg.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\kt0ql7d51.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\enj2l11o1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\fplq0335e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\g2jolc131f.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\l44q0eh5eh4.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\i624lgfq162e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\f00olad31d0.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\p6p6lg7s16.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\aza2la3o1d.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\s0pu0a79ed.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\e2jmlc111f.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\g604lgdq160e.dll
1 file(s) copied.
deleting: C:\WINDOWS\system32\smmsg.dll
Successfully Deleted: C:\WINDOWS\system32\smmsg.dll
deleting: C:\WINDOWS\system32\wyhisn.dll
Successfully Deleted: C:\WINDOWS\system32\wyhisn.dll
deleting: C:\WINDOWS\system32\irr2l59o1.dll
Successfully Deleted: C:\WINDOWS\system32\irr2l59o1.dll
deleting: C:\WINDOWS\system32\kaymgr.dll
Successfully Deleted: C:\WINDOWS\system32\kaymgr.dll
deleting: C:\WINDOWS\system32\luasrv.dll
Successfully Deleted: C:\WINDOWS\system32\luasrv.dll
deleting: C:\WINDOWS\system32\mlxlegih.dll
Successfully Deleted: C:\WINDOWS\system32\mlxlegih.dll
deleting: C:\WINDOWS\system32\l22slcf71f2.dll
Successfully Deleted: C:\WINDOWS\system32\l22slcf71f2.dll
deleting: C:\WINDOWS\system32\ir2ml5f11.dll
Successfully Deleted: C:\WINDOWS\system32\ir2ml5f11.dll
deleting: C:\WINDOWS\system32\h0l2la3o1d.dll
Successfully Deleted: C:\WINDOWS\system32\h0l2la3o1d.dll
deleting: C:\WINDOWS\system32\lv6609jse.dll
Successfully Deleted: C:\WINDOWS\system32\lv6609jse.dll
deleting: C:\WINDOWS\system32\kt4ml7h11.dll
Successfully Deleted: C:\WINDOWS\system32\kt4ml7h11.dll
deleting: C:\WINDOWS\system32\dnp0017me.dll
Successfully Deleted: C:\WINDOWS\system32\dnp0017me.dll
deleting: C:\WINDOWS\system32\dnns0157e.dll
Successfully Deleted: C:\WINDOWS\system32\dnns0157e.dll
deleting: C:\WINDOWS\system32\fnl0213mg.dll
Successfully Deleted: C:\WINDOWS\system32\fnl0213mg.dll
deleting: C:\WINDOWS\system32\kt0ql7d51.dll
Successfully Deleted: C:\WINDOWS\system32\kt0ql7d51.dll
deleting: C:\WINDOWS\system32\enj2l11o1.dll
Successfully Deleted: C:\WINDOWS\system32\enj2l11o1.dll
deleting: C:\WINDOWS\system32\fplq0335e.dll
Successfully Deleted: C:\WINDOWS\system32\fplq0335e.dll
deleting: C:\WINDOWS\system32\g2jolc131f.dll
Successfully Deleted: C:\WINDOWS\system32\g2jolc131f.dll
deleting: C:\WINDOWS\system32\l44q0eh5eh4.dll
Successfully Deleted: C:\WINDOWS\system32\l44q0eh5eh4.dll
deleting: C:\WINDOWS\system32\i624lgfq162e.dll
Successfully Deleted: C:\WINDOWS\system32\i624lgfq162e.dll
deleting: C:\WINDOWS\system32\f00olad31d0.dll
Successfully Deleted: C:\WINDOWS\system32\f00olad31d0.dll
deleting: C:\WINDOWS\system32\p6p6lg7s16.dll
Successfully Deleted: C:\WINDOWS\system32\p6p6lg7s16.dll
deleting: C:\WINDOWS\system32\aza2la3o1d.dll
Successfully Deleted: C:\WINDOWS\system32\aza2la3o1d.dll
deleting: C:\WINDOWS\system32\s0pu0a79ed.dll
Successfully Deleted: C:\WINDOWS\system32\s0pu0a79ed.dll
deleting: C:\WINDOWS\system32\e2jmlc111f.dll
Successfully Deleted: C:\WINDOWS\system32\e2jmlc111f.dll
deleting: C:\WINDOWS\system32\g604lgdq160e.dll
Successfully Deleted: C:\WINDOWS\system32\g604lgdq160e.dll

Desktop.ini sucessfully removed


Zipping up files for submission:
adding: smmsg.dll (deflated 5%)
adding: wyhisn.dll (deflated 6%)
adding: irr2l59o1.dll (deflated 5%)
adding: kaymgr.dll (deflated 5%)
adding: luasrv.dll (deflated 5%)
adding: mlxlegih.dll (deflated 6%)
adding: l22slcf71f2.dll (deflated 5%)
adding: ir2ml5f11.dll (deflated 5%)
adding: h0l2la3o1d.dll (deflated 5%)
adding: lv6609jse.dll (deflated 5%)
adding: kt4ml7h11.dll (deflated 5%)
adding: dnp0017me.dll (deflated 5%)
adding: dnns0157e.dll (deflated 5%)
adding: fnl0213mg.dll (deflated 5%)
adding: kt0ql7d51.dll (deflated 5%)
adding: enj2l11o1.dll (deflated 5%)
adding: fplq0335e.dll (deflated 5%)
adding: g2jolc131f.dll (deflated 5%)
adding: l44q0eh5eh4.dll (deflated 5%)
adding: i624lgfq162e.dll (deflated 5%)
adding: f00olad31d0.dll (deflated 6%)
adding: p6p6lg7s16.dll (deflated 5%)
adding: aza2la3o1d.dll (deflated 5%)
adding: s0pu0a79ed.dll (deflated 5%)
adding: e2jmlc111f.dll (deflated 5%)
adding: g604lgdq160e.dll (deflated 6%)
adding: echo.reg (deflated 9%)
adding: clear.reg (deflated 69%)
adding: desktop.ini (stored 0%)
adding: readme.txt (deflated 49%)
adding: direct.txt (stored 0%)
adding: report.txt (deflated 70%)
adding: lo2.txt (deflated 83%)
adding: test2.txt (deflated 49%)
adding: test3.txt (deflated 49%)
adding: test5.txt (deflated 49%)
adding: test.txt (deflated 79%)
adding: xfind.txt (deflated 74%)
adding: backregs/shell.reg (deflated 73%)
adding: backregs/558C6E5D-4AAF-4BB0-BB3D-01F83AF5A50B.reg (deflated 70%)
adding: backregs/950A9609-FB3E-452E-BF5A-7ABD793CFF90.reg (deflated 70%)
adding: backregs/BBE0559F-0667-4B7A-89EE-2A40AA7D1056.reg (deflated 70%)
adding: backregs/73E35E28-0E1D-44B2-BD4D-F2D8A8BFE494.reg (deflated 70%)
adding: backregs/565F8AB9-F3C1-40CC-9C90-F0608DFE2762.reg (deflated 70%)
adding: backregs/EE3A6AFC-CAD5-4718-99A2-CDEEB60F1200.reg (deflated 70%)
adding: backregs/33A404FE-82F9-446C-B18A-9D2FA22172F9.reg (deflated 70%)
adding: backregs/7D6DD24B-77C6-408F-ACA3-877F95647604.reg (deflated 70%)
adding: backregs/9DD3D014-2900-4326-9B94-DA546CC7B08B.reg (deflated 70%)
adding: backregs/02403FA0-EA02-4DCA-BF89-08559E2AB8C5.reg (deflated 70%)
adding: backregs/C66491F2-3ED0-4221-9734-9083DED88E92.reg (deflated 70%)

Restoring Registry Permissions:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!


Revoking access for predefined group "Administrators"
Inherited ACE can not be revoked here!
Inherited ACE can not be revoked here!


Registry permissions set too:

RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Read BUILTIN\Power Users
(ID-IO) ALLOW Read BUILTIN\Power Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER


Restoring Sedebugprivilege:

Granting SeDebugPrivilege to Administrators ... successful

deleting local copy: smmsg.dll
deleting local copy: wyhisn.dll
deleting local copy: irr2l59o1.dll
deleting local copy: kaymgr.dll
deleting local copy: luasrv.dll
deleting local copy: mlxlegih.dll
deleting local copy: l22slcf71f2.dll
deleting local copy: ir2ml5f11.dll
deleting local copy: h0l2la3o1d.dll
deleting local copy: lv6609jse.dll
deleting local copy: kt4ml7h11.dll
deleting local copy: dnp0017me.dll
deleting local copy: dnns0157e.dll
deleting local copy: fnl0213mg.dll
deleting local copy: kt0ql7d51.dll
deleting local copy: enj2l11o1.dll
deleting local copy: fplq0335e.dll
deleting local copy: g2jolc131f.dll
deleting local copy: l44q0eh5eh4.dll
deleting local copy: i624lgfq162e.dll
deleting local copy: f00olad31d0.dll
deleting local copy: p6p6lg7s16.dll
deleting local copy: aza2la3o1d.dll
deleting local copy: s0pu0a79ed.dll
deleting local copy: e2jmlc111f.dll
deleting local copy: g604lgdq160e.dll

The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


The following are the files found:
****************************************************************************
C:\WINDOWS\system32\smmsg.dll
C:\WINDOWS\system32\wyhisn.dll
C:\WINDOWS\system32\irr2l59o1.dll
C:\WINDOWS\system32\kaymgr.dll
C:\WINDOWS\system32\luasrv.dll
C:\WINDOWS\system32\mlxlegih.dll
C:\WINDOWS\system32\l22slcf71f2.dll
C:\WINDOWS\system32\ir2ml5f11.dll
C:\WINDOWS\system32\h0l2la3o1d.dll
C:\WINDOWS\system32\lv6609jse.dll
C:\WINDOWS\system32\kt4ml7h11.dll
C:\WINDOWS\system32\dnp0017me.dll
C:\WINDOWS\system32\dnns0157e.dll
C:\WINDOWS\system32\fnl0213mg.dll
C:\WINDOWS\system32\kt0ql7d51.dll
C:\WINDOWS\system32\enj2l11o1.dll
C:\WINDOWS\system32\fplq0335e.dll
C:\WINDOWS\system32\g2jolc131f.dll
C:\WINDOWS\system32\l44q0eh5eh4.dll
C:\WINDOWS\system32\i624lgfq162e.dll
C:\WINDOWS\system32\f00olad31d0.dll
C:\WINDOWS\system32\p6p6lg7s16.dll
C:\WINDOWS\system32\aza2la3o1d.dll
C:\WINDOWS\system32\s0pu0a79ed.dll
C:\WINDOWS\system32\e2jmlc111f.dll
C:\WINDOWS\system32\g604lgdq160e.dll

Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{519CD672-8EF3-42F1-AAFA-89167C830588}"=-
"{A8D7E505-BF24-4698-B619-4BE58BADFF82}"=-
"{A5552847-4804-45E7-B0AE-B54F677F92D0}"=-
"{4243CA87-C045-4FD7-9940-2FF567F78CF0}"=-
"{F02E8617-B0FF-433C-9038-A3B5E33BC866}"=-
"{1F503F2D-D737-4B52-87AB-B1FD31C9E055}"=-
"{7D0FD3AA-219C-4E5F-AE73-6FF79AB04683}"=-
"{558C6E5D-4AAF-4BB0-BB3D-01F83AF5A50B}"=-
"{E9B355B2-F5CF-45CC-9D9A-CBBD84E11FD5}"=-
"{4252319C-5361-469A-86A2-C1AAB4828C43}"=-
"{C4F24F5A-E026-4A82-B177-C4DD8CF68458}"=-
"{950A9609-FB3E-452E-BF5A-7ABD793CFF90}"=-
"{BBE0559F-0667-4B7A-89EE-2A40AA7D1056}"=-
"{73E35E28-0E1D-44B2-BD4D-F2D8A8BFE494}"=-
"{565F8AB9-F3C1-40CC-9C90-F0608DFE2762}"=-
"{EE3A6AFC-CAD5-4718-99A2-CDEEB60F1200}"=-
"{33A404FE-82F9-446C-B18A-9D2FA22172F9}"=-
"{7D6DD24B-77C6-408F-ACA3-877F95647604}"=-
"{9DD3D014-2900-4326-9B94-DA546CC7B08B}"=-
"{02403FA0-EA02-4DCA-BF89-08559E2AB8C5}"=-
"{C66491F2-3ED0-4221-9734-9083DED88E92}"=-
[-HKEY_CLASSES_ROOT\CLSID\{519CD672-8EF3-42F1-AAFA-89167C830588}]
[-HKEY_CLASSES_ROOT\CLSID\{A8D7E505-BF24-4698-B619-4BE58BADFF82}]
[-HKEY_CLASSES_ROOT\CLSID\{A5552847-4804-45E7-B0AE-B54F677F92D0}]
[-HKEY_CLASSES_ROOT\CLSID\{4243CA87-C045-4FD7-9940-2FF567F78CF0}]
[-HKEY_CLASSES_ROOT\CLSID\{F02E8617-B0FF-433C-9038-A3B5E33BC866}]
[-HKEY_CLASSES_ROOT\CLSID\{1F503F2D-D737-4B52-87AB-B1FD31C9E055}]
[-HKEY_CLASSES_ROOT\CLSID\{7D0FD3AA-219C-4E5F-AE73-6FF79AB04683}]
[-HKEY_CLASSES_ROOT\CLSID\{558C6E5D-4AAF-4BB0-BB3D-01F83AF5A50B}]
[-HKEY_CLASSES_ROOT\CLSID\{E9B355B2-F5CF-45CC-9D9A-CBBD84E11FD5}]
[-HKEY_CLASSES_ROOT\CLSID\{4252319C-5361-469A-86A2-C1AAB4828C43}]
[-HKEY_CLASSES_ROOT\CLSID\{C4F24F5A-E026-4A82-B177-C4DD8CF68458}]
[-HKEY_CLASSES_ROOT\CLSID\{950A9609-FB3E-452E-BF5A-7ABD793CFF90}]
[-HKEY_CLASSES_ROOT\CLSID\{BBE0559F-0667-4B7A-89EE-2A40AA7D1056}]
[-HKEY_CLASSES_ROOT\CLSID\{73E35E28-0E1D-44B2-BD4D-F2D8A8BFE494}]
[-HKEY_CLASSES_ROOT\CLSID\{565F8AB9-F3C1-40CC-9C90-F0608DFE2762}]
[-HKEY_CLASSES_ROOT\CLSID\{EE3A6AFC-CAD5-4718-99A2-CDEEB60F1200}]
[-HKEY_CLASSES_ROOT\CLSID\{33A404FE-82F9-446C-B18A-9D2FA22172F9}]
[-HKEY_CLASSES_ROOT\CLSID\{7D6DD24B-77C6-408F-ACA3-877F95647604}]
[-HKEY_CLASSES_ROOT\CLSID\{9DD3D014-2900-4326-9B94-DA546CC7B08B}]
[-HKEY_CLASSES_ROOT\CLSID\{02403FA0-EA02-4DCA-BF89-08559E2AB8C5}]
[-HKEY_CLASSES_ROOT\CLSID\{C66491F2-3ED0-4221-9734-9083DED88E92}]
REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"SV1"=""
****************************************************************************
Desktop.ini Contents:
****************************************************************************
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
****************************************************************************


-Thanks

#6 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,542 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:09:04 PM

Posted 08 May 2005 - 07:48 PM

Download http://www.bleepingcomputer.com/files/pfind.php

Extract pfind.zip to your c:\ folder.

Reboot your computer into Safe Mode

Then open c:\pfind and double-click on pfind.bat. When it is done, reboot and post the contents of c:\pfind.txt as a reply to this topic.

#7 Jaems

Jaems
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:08:04 PM

Posted 08 May 2005 - 10:49 PM

Pfind results:

Files found with this application may be legitimate.
Only remove files that you know are malware related.
Checking the C:\WINDOWS folder
C:\WINDOWS\MEMORY.DMP: UPX!
C:\WINDOWS\MEMORY.DMP: IAM s.urllogic.com
C:\WINDOWS\MEMORY.DMP: UPX!-
C:\WINDOWS\MEMORY.DMP: IAM"s.urllogic.com
C:\WINDOWS\MEMORY.DMP: FSG!-
C:\WINDOWS\MEMORY.DMP: UPX!-
C:\WINDOWS\MEMORY.DMP: u.ad-behavior.com
C:\WINDOWS\MEMORY.DMP: 127.0.0.1 www.qoologic.com
C:\WINDOWS\MEMORY.DMP: 127.0.0.1 www.urllogic.com
C:\WINDOWS\daemon.dll: UPX!
C:\WINDOWS\icont.exe: UPX!
C:\WINDOWS\jhjza.dll: defcfg_srv=u.urllogic.com
C:\WINDOWS\jhjza.dll: chpop_srv=s.urllogic.com
C:\WINDOWS\jhjza.dll: excl_urls=heavy.com,onemoresearch.net,update32.searchmiracle.com,atdmt.com,switch.atdmt.com,js1.yimg.com,us.js1.yimg.com,us.yimg.com,cdn.comcast.net,us.i1.yimg.com,goldenpalace.com,banner.goldenpalace.com,msads.net,global.msads.net,topmoxie.com,altfarm.mediaplex.com,mediaplex.com,maxserving.com,c4.maxserving.com,ar.atwola.com,alwaysupdatednews.com,fxfeeds.mozilla.org,cdn.aim.com,adv.eblocs.com,weatherbug.com,jicmedia.cjt1.net,ad.trafficmp.com,updates.qoologic.com,ads1.revenue.net,ar.atwola.com,ads.addynamix.com,v8.alwaysupdatednews.com,login.passport.net,pagead2.googlesyndication.com,ads.inet1.com,loginnet.passport.com,as-us.falkag.net,falkag.net,z1.adserver.com,a1.yimg.com,a.as-us.falkag.net,yimg.com,trafficmp.com,us.a1.yimg.com,ads.exitexchange.com,aaabesthomepage.com,pan-advert.com,clicktrk.com,t.trafficmp.com,loadingwebsite.com,ezula.com,server.iad.liveperson.net,u.clkoptimizer.com,adsv2.delfinproject.com,popup.msn.com,ads2.revenue.net,i.emarketresearchgroup.com,oz.valueclick.com,counters.honesty.com,ads.bidclix.com,radio.launch.yahoo.com,zone.msn.com,sr.adwave.com,xlime.offeroptimizer.com,clickspring.net,kill-pop-ups.com,us.update.companion.yahoo.com,qksrv.net,cdn-aimtoday.aol.com,search200.com,servedby.adscpm.com,count.exitexchange.com,xanga.com,jnictech.cjt1.net,xadsq.offeroptimizer.com,popuptraffic.com,paypopup.com,cdn-cf.aol.com,by.optimost.com,hotmail.msn.com,adfarm.mediaplex.com,amch.questionmarket.com,allaboutsearching.com,newupdates.lzio.com,akapp.whenu.com,cfg.mywebsearch.com,ads.delfinproject.com,searcheffect.com,hotmail.com,master.mx-targeting.com,ctl.twain-tech.com,jcontent.bns1.net,mail.yahoo.com,m2.doubleclick.net,insider.msg.yahoo.com,topicks.com,e.rn11.com,focusin.ads.targetnet.com,jmnad1.com,pgq.yahoo.com,stopzilla.com,ayb.lop.com,xadso.offeroptimizer.com,webpdp.gator.com,download.smileycentral.com,mm.delfinproject.com,view.atdmt.com,delfinproject.com,bannerfarm.ace.advertising.com,jbns2.cydoor.com,look2me.com,as.adwave.com,popuppers.com,wisapidata.weatherbug.com,games.yahoo.com,adsrv.qoologic.com,servedby.advertising.com,ww2.weatherbug.com,www4.yesadvertising.com,bannerserver.gator.com,rightmedia.net,websearch.com,hop.clickbank.net,media76.fastclick.net,mmm.media-motor.net,isapi60.weatherbug.com,web.tickle.com,wwp.icq.com,smileycentral.com,messenger.zango.com,adserv1.gruvmedia.com,cdn.icq.com,banners.pennyweb.com,s.clkoptimizer.com,tv.180solutions.com,pops.browseraid.com,adserv.internetfuel.com,download.abetterinternet.com,messenger.msn.com,sr.websearch.com,top-banners.com,advert.runescape.com,join1.winhundred.com,odysseusmarketing.com,v4.windowsupdate.microsoft.com,windowsupdate.microsoft.com,adverts.lzio.com,comcast.net,filter.belkin.com,clickit.go2net.com,sc.musicmatch.com,license.hotbar.com,web.icq.com,trk.pcsecurityshield.com,whenusearch.com,jbigpops.cjt1.net,isg05.casalemedia.com,anrdoezrs.net,aim-charts.pf.aol.com,microsoft.com,target.com,yahoo.com,aol.com,download.websearch.com,actualdeals.com,images.trafficmp.com,mydailyhoroscope.net,ekmas.com,affiliates.4lowrates.com,creativeby.viewpoint.com,couponage.com,c5.zedo.com,hits.clickandtrack.net,ads.mydailyhoroscope.net,clickserve.cc-dt.com,popups.ad-logics.com,host239.ipowerweb.com,adlog2.lzio.com,bv.channel.aol.com,img2.mailpostdirect.com,dw.dailywinner.net,m3.doubleclick.net,ad.doubleclick.net,as.casalemedia.com,toprebates.com,trk.bestmagsdirect.com,ads.clickagents.com,sandboxer.com,a.websponsors.com,click2.containsitall.com,media.fastclick.net,ads234.com,banners.searchingbooth.com,passportimages.com,stats.eblocs.com,media.deskwizz.com,c1.zedo.com,photobucket.com
C:\WINDOWS\setup_silent_26223.exe: UPX!


Checking the C:\WINDOWS\SYSTEM32 folder
C:\WINDOWS\SYSTEM32\pbpkq.dat: UPX!
C:\WINDOWS\SYSTEM32\pbpkq.dat: ?u.ad-behNior.com
C:\WINDOWS\SYSTEM32\brbmcco.exe: u.ad-behavior.com
C:\WINDOWS\SYSTEM32\apaun.dll: UPX!
C:\WINDOWS\SYSTEM32\apaun.dll: 7u.ad-behN
C:\WINDOWS\SYSTEM32\ntdll.dll: .aspack
C:\WINDOWS\SYSTEM32\Naruto SCR.scr: UPX!
C:\WINDOWS\SYSTEM32\UninstXviDDec.exe: UPX!
C:\WINDOWS\SYSTEM32\Incinerator.dll: .aspack
C:\WINDOWS\SYSTEM32\ntec32.exe: UPX!
C:\WINDOWS\SYSTEM32\vmvkrr.exe: UPX!
C:\WINDOWS\SYSTEM32\vmvkrr.exe: ?u.ad-behNior.com
C:\WINDOWS\SYSTEM32\thtrppg.dll: u.ad-behavior.com


Checking all directories under the C:\WINDOWS\SYSTEM32\drivers folder
C:\WINDOWS\SYSTEM32\Drivers\etc\hosts: 127.0.0.1 www.qoologic.com
C:\WINDOWS\SYSTEM32\Drivers\etc\hosts: 127.0.0.1 www.urllogic.com


Checking the C:\Documents and Settings\All Users.WINDOWS\Start Menu\programs\Startup\ folder

C:\Documents and Settings\All Users.WINDOWS\Start Menu\programs\Startup\npni.exe: UPX!
C:\Documents and Settings\All Users.WINDOWS\Start Menu\programs\Startup\npni.exe: ?u.ad-behNior.com


Checking the C:\Documents and Settings\All Users.WINDOWS\Application Data folder



Checking the C:\Documents and Settings\Administrator\Start Menu\programs\Startup\ folder



Checking the C:\Documents and Settings\Administrator\Application Data folder

#8 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,542 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:09:04 PM

Posted 09 May 2005 - 09:34 AM

Download FindQoologic.zip save it to your Desktop.
http://forums.net-integration.net/index.ph...=post&id=134981

Extract (unzip) the files inside into their own folder called FindQoologic.
Open the FindQoologic folder. Preferable to your desktop.
Locate and double-click the Find-Qoologic.bat file to run it.
Wait until a text opens.
Post this in your next repl together with a new hijackthislog.

#9 Jaems

Jaems
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:08:04 PM

Posted 09 May 2005 - 06:10 PM

Find FindQoologic:
PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
»»»»»»»»»»»»»»»»»»»»»»»» Files found »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

* urllogic C:\WINDOWS\JHJZA.DLL
* qoologic C:\WINDOWS\JHJZA.DLL

* ad-beh C:\WINDOWS\System32\APAUN.DLL
* ad-beh C:\WINDOWS\System32\THTRPPG.DLL
* ad-beh C:\WINDOWS\System32\BRBMCCO.EXE
* ad-beh C:\WINDOWS\System32\VMVKRR.EXE
* ad-beh C:\WINDOWS\System32\PBPKQ.DAT
»»»»»»»»»»»»»»»»»»»»»»»» startup files»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

* exe C:\docume~1\alluse~1\startm~1\programs\startup\POWERR~1.EXE
* exe C:\docume~1\alluse~1\startm~1\programs\startup\POWERR~2.EXE

»»»»»»»»»»»»»»»»»»»»»»»» Checking Global Startup »»»»»»»»»»»»»»»»»»»»»»

(fstarts by IMM - test ver. 0.001) NOT using address check -- 0x7c90df5e

Global Startup:
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup
.
..
desktop.ini
npni.exe

User Startup:
C:\Documents and Settings\Ben.MICRONPC\Start Menu\Programs\Startup
.
..
desktop.ini
PowerReg Scheduler V3.exe

»»»»»»»»»»»»»»»»»»»»»»»» Registry Entries Found »»»»»»»»»»»»»»»»»»»»»»»

! REG.EXE VERSION 3.0

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Audio Converter
<NO NAME> REG_SZ {8DA09D52-A809-430B-801C-BB91B50A2552}

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ftfxggqn
<NO NAME> REG_SZ {b5f6b16c-a4e4-4b7b-8cbc-1369e512f793}

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
<NO NAME> REG_SZ {750fdf0e-2a26-11d1-a3ea-080036587f03}

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
<NO NAME> REG_SZ {09799AFB-AD67-11d1-ABCD-00C04FC30936}

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
<NO NAME> REG_SZ {A470F8CF-A1E8-4f65-8335-227475AA5C46}

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinRAR
<NO NAME> REG_SZ {B41DB860-8EE4-11D2-9906-E49FADC173CA}

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Yahoo! Mail
<NO NAME> REG_SZ {5464D816-CF16-4784-B9F3-75C0DB52B499}

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
<NO NAME> REG_SZ Start Menu Pin

»»»»»»»»»»»»»»»»»»»»»»»»» Active setup »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

"Find activesetup", version1, launched at: 17:58
Operating System: Windows XP SP2


HKLM\Software\Microsoft\Active Setup\Installed Components\
">{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\(Default)" = "Windows Media Player"
\StubPath = "C:\WINDOWS\inf\unregmp2.exe /ShowWMP" [MS]
"bdd27ff0-d1ba-41a3-9f46-83482389c31c\(Default)" = ""
\StubPath = "C:\WINDOWS\system32\brbmcco.exe" [null data]

Hijack This:
Logfile of HijackThis v1.99.1
Scan saved at 6:09:32 PM, on 5/9/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\vmvkrr.exe
E:\Cody's Misc. Stuff\aim\aim.exe
G:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Internet Explorer\iexplore.exe
H:\Program Files\particleIllusion SE\particleIllusion_SE.exe
C:\WINDOWS\CDILLA64.EXE
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\HijackThis\HijackThis.exe

O3 - Toolbar: Norton Personal Firewall - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\vmvkrr.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [AIM] E:\Cody's Misc. Stuff\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SpybotSD TeaTimer] G:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: PowerReg Scheduler V3.exe
O8 - Extra context menu item: Download with GetRight - F:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - F:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - E:\Cody's Misc. Stuff\aim\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/...tiveXPlugin.cab
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Service Client v.3.4) - http://ccon.futuremark.com/global/msc34.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{953309F4-A78E-4383-A175-0DEE9B501832}: Domain = mshome.net
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - (no file)
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - D:\Program Files\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - G:\Program Files\Norton Personal Firewall\ISSVC.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (file missing)
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

#10 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,542 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:09:04 PM

Posted 09 May 2005 - 10:01 PM

Please read my next steps very carefully:

* Download Killbox.
Click killbox.exe.
Select the option "Delete on reboot".

Now copy the next bold:


C:\WINDOWS\JHJZA.DLL
C:\WINDOWS\System32\APAUN.DLL
C:\WINDOWS\System32\THTRPPG.DLL
C:\WINDOWS\System32\BRBMCCO.EXE
C:\WINDOWS\System32\VMVKRR.EXE
C:\WINDOWS\System32\PBPKQ.DAT
C:\Documents and Settings\All Users.WINDOWS\Start Menu\programs\Startup\npni.exe


Open 'file' in the killboxmenu on top and choose Paste from clipboard

Now you will see, this is pasted in the "Full Path of File to Delete"-field.
There's a little arrow (dropdown-arrow) next to that field.
If you expand it, these lines must be there together if the files are present!

Then press the button that looks like a red circle with a white X in it.
Killbox will tell you that all listed files will be deleted on next reboot.. Click YES
When it asks if you would like to Reboot now, click YES
If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just restart manually.

Your computer must reboot now.



Launch Notepad, and copy and paste the contents of the quote box below into a new text file.

Save it as file name: "fixme.reg" (not including the quotes). Save as file type: All files (*.*) and save it on your Desktop.

REGEDIT4

[-HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ftfxggqn]
[-HKLM\Software\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]


Then, locate fixme.reg on your Desktop and double-click on it.
You will receive a prompt similar to: "Do you wish to merge the information into the registry?".
Answer 'Yes' and wait for a message to appear similar to "Merged Successfully".


Reboot and post a new log




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users