Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Pop Ups/trojan Over-running Me


  • This topic is locked This topic is locked
11 replies to this topic

#1 PSUBaller

PSUBaller

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:01:08 AM

Posted 08 January 2006 - 12:55 PM

I've been getting constant advertising pop-ups and occaisional system crashes. IEXPLORER.EXE comes up in the proceesses repeatedly and if I don't end the processes the computer slows to a crawl. I've run Adaware, Spybot, and other recommended scans from this site. Here is my hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 12:50:42 PM, on 1/8/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\DIGStream\digstream.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\explorer.exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p...er=6&ar=msnhome
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.microsoft.com/search/search.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p...er=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.microsoft.com/search/search.asp
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://home.microsoft.com/access/autosearch.asp?p=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [DVDUpgrade] DVDUpgrd.exe /async9x
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: hp psc 1000 series.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O12 - Plugin for .avi: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .bmp: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O12 - Plugin for .wav: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npaudio.dll
O15 - Trusted Zone: http://free.aol.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kav...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - https://scan.safety.live.com/resource/downl...lscbase3401.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1136732402324
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://us-housecall.trendmicro-europe.com/...ivex/hcImpl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab
O20 - Winlogon Notify: TaskMon - C:\WINDOWS\system32\irjol5131.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

BC AdBot (Login to Remove)

 


m

#2 Cloutz

Cloutz

    The Malware Killa


  • Members
  • 150 posts
  • OFFLINE
  •  
  • Location:Montreal, Quebec
  • Local time:12:08 AM

Posted 12 January 2006 - 06:52 PM

Hi PSUBaller,
Welcome to BleepingComputer! My name is Nick and I will be helping you.

I apologize for the delay getting to your log, the helpers here are very busy.
If you still need help, please post a fresh Hijackthis log, in this thread, so I can help you with your Malware Problems.

If you have resolved this issue please let us know.

Edited by Cloutz, 12 January 2006 - 06:53 PM.

Posted Image Did I help? Please consider a small donation via paypal. Thank You.

Ad-Aware SE|CWShredder|Spybot S&D|Ewido Security Suite|HijackThis 1.99.1

Please don't PM me asking for help. The forums are there for a reason.

Cloutz 2006

#3 PSUBaller

PSUBaller
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:01:08 AM

Posted 18 January 2006 - 07:28 PM

Thanks for the reply, no fix for me yet, here is the updated log.

Logfile of HijackThis v1.99.1
Scan saved at 7:25:49 PM, on 1/18/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\DIGStream\digstream.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\DOCUME~1\Brandon\LOCALS~1\Temp\HijackThis.exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p...er=6&ar=msnhome
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.microsoft.com/search/search.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p...er=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.microsoft.com/search/search.asp
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://home.microsoft.com/access/autosearch.asp?p=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [DVDUpgrade] DVDUpgrd.exe /async9x
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: hp psc 1000 series.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O12 - Plugin for .avi: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .bmp: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O12 - Plugin for .wav: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npaudio.dll
O15 - Trusted Zone: http://free.aol.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kav...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - https://scan.safety.live.com/resource/downl...lscbase3401.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1136732402324
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://us-housecall.trendmicro-europe.com/...ivex/hcImpl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab
O20 - Winlogon Notify: Internet Settings - C:\WINDOWS\system32\ennul1591.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

#4 Cloutz

Cloutz

    The Malware Killa


  • Members
  • 150 posts
  • OFFLINE
  •  
  • Location:Montreal, Quebec
  • Local time:12:08 AM

Posted 18 January 2006 - 07:52 PM

Hi PSUBaller,

You have the latest version of VX2. Download L2mfix from one of these two locations:

http://www.downloads.subratam.org/l2mfix.exe
http://www.atribune.org/downloads/l2mfix.exe

Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!

if you receive, while running option #1, an error similar like: ''C:\windows\system32\cmd.exe,
C:\windows\system32\autoexec.nt the system file is not suitable for running ms-dos and microsoft windows applications. choose close to terminate the application.."...then please use option 5 or the web page link in the l2mfix folder to solve this error condition. do not run the fix portion without fixing this first.

Nick :thumbsup:
Posted Image Did I help? Please consider a small donation via paypal. Thank You.

Ad-Aware SE|CWShredder|Spybot S&D|Ewido Security Suite|HijackThis 1.99.1

Please don't PM me asking for help. The forums are there for a reason.

Cloutz 2006

#5 PSUBaller

PSUBaller
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:01:08 AM

Posted 18 January 2006 - 08:08 PM

L2MFIX find log 010406
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
"Asynchronous"=dword:00000000
"DllName"=""
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\BITS]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\i8nmli5118.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

**********************************************************************************
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{1DF63176-6B74-87E9-65E4-6CC42C678E2C}"=""

**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run..."
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People..."
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{568804CA-CBD7-11d0-9816-00C04FD91972}"="Menu Shell Folder"
"{5b4dae26-b807-11d0-9815-00c04fd91972}"="Menu Band"
"{8278F931-2A3E-11d2-838F-00C04FD918D0}"="Tracking Shell Menu"
"{E13EF4E4-D2F2-11d0-9816-00C04FD91972}"="Menu Site"
"{ECD4FC4F-521C-11D0-B792-00A0C90312E1}"="Menu Desk Bar"
"{D82BE2B0-5764-11D0-A96E-00C04FD705A2}"="IShellFolderBand"
"{0E5CBF21-D15F-11d0-8301-00AA005B4383}"="&Links"
"{7487cd30-f71a-11d0-9ea7-00805f714772}"="Thumbnail Image"
"{C2FBB630-2971-11d1-A18C-00C04FD75D13}"="Microsoft CopyTo Service"
"{C2FBB631-2971-11d1-A18C-00C04FD75D13}"="Microsoft MoveTo Service"
"{13709620-C279-11CE-A49E-444553540000}"="Shell Automation Service"
"{62112AA1-EBE4-11cf-A5FB-0020AFE7292D}"="Shell Automation Folder View"
"{4622AD11-FF23-11d0-8D34-00A0C90F2719}"="Start Menu"
"{7BA4C740-9E81-11CF-99D3-00AA004AE837}"="Microsoft SendTo Service"
"{D969A300-E7FF-11d0-A93B-00A0C90F2719}"="Microsoft New Object Service"
"{3FC0B520-68A9-11D0-8D77-00C04FD70822}"="Display Control Panel HTML Extensions"
"{75048700-EF1F-11D0-9888-006097DEACF9}"="ActiveDesktop"
"{6D5313C0-8C62-11D1-B2CD-006097DF8C11}"="Folder Options Property Page Extension"
"{57651662-CE3E-11D0-8D77-00C04FC99D61}"="CmdFileIcon"
"{B091E540-83E3-11CF-A713-0020AFD79762}"="File Types Page"
"{FBF23B41-E3F0-101B-8488-00AA003E56F8}"="MIME File Types Hook"
"{8BEBB290-52D0-11D0-B7F4-00C04FD706EC}"="Thumbnails"
"{7D688A77-C613-11D0-999B-00C04FD655E1}"="SlowFile Icon Overlay"
"{c2c1d8a0-016a-11d1-a7fa-444553540000}"="Shell Extension Sample"
"{B988C8B2-373B-11CF-B6E0-00AA00BBBA9E}"="ICCompPropPage"
"{8DE56A0D-E58B-41FE-9F80-3563CDCB2C22}"="Default Image Extrator for Properties"
"{BDA77241-42F6-11d0-85E2-00AA001FE28C}"="LDVP Shell Extensions"
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
"{336B02CE-F88A-4aea-8731-79EF94D3723A}"="Free AOL & Unlimited Internet.url"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
"{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
"{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
"{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
"{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
"{5464D816-CF16-4784-B9F3-75C0DB52B499}"="Yahoo! Mail"
"{1F4BF33F-3E8F-4607-9E96-F2A2B4CAE350}"=""
"{636B43EF-4158-492B-A8BA-D55749C0BF84}"=""
"{D9786B68-E07B-4F66-B982-6B7A9CCD7312}"=""
"{FCC1ECCE-D4D6-4104-839D-2B65E896C7D4}"=""
"{4E0E75E7-AE96-4FAB-9AAD-5E5BF1AE93B5}"=""
"{0CCC8F93-9814-41D6-B380-57A34F239F8B}"=""
"{52B87208-9CCF-42C9-B88E-069281105805}"="Trojan Remover Shell Extension"
"{21569614-B795-46b1-85F4-E737A8DC09AD}"="Shell Search Band"

**********************************************************************************
HKEY ROOT CLASSIDS:
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{1F4BF33F-3E8F-4607-9E96-F2A2B4CAE350}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{1F4BF33F-3E8F-4607-9E96-F2A2B4CAE350}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{1F4BF33F-3E8F-4607-9E96-F2A2B4CAE350}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{1F4BF33F-3E8F-4607-9E96-F2A2B4CAE350}\InprocServer32]
@="C:\\WINDOWS\\system32\\cviconfg.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{636B43EF-4158-492B-A8BA-D55749C0BF84}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{636B43EF-4158-492B-A8BA-D55749C0BF84}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{636B43EF-4158-492B-A8BA-D55749C0BF84}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{636B43EF-4158-492B-A8BA-D55749C0BF84}\InprocServer32]
@="C:\\WINDOWS\\system32\\MLSLGN32.DLL"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{D9786B68-E07B-4F66-B982-6B7A9CCD7312}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{D9786B68-E07B-4F66-B982-6B7A9CCD7312}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{D9786B68-E07B-4F66-B982-6B7A9CCD7312}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{D9786B68-E07B-4F66-B982-6B7A9CCD7312}\InprocServer32]
@="C:\\WINDOWS\\system32\\myxml2r.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{FCC1ECCE-D4D6-4104-839D-2B65E896C7D4}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{FCC1ECCE-D4D6-4104-839D-2B65E896C7D4}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{FCC1ECCE-D4D6-4104-839D-2B65E896C7D4}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{FCC1ECCE-D4D6-4104-839D-2B65E896C7D4}\InprocServer32]
@="C:\\WINDOWS\\system32\\aisldpc.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{4E0E75E7-AE96-4FAB-9AAD-5E5BF1AE93B5}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{4E0E75E7-AE96-4FAB-9AAD-5E5BF1AE93B5}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{4E0E75E7-AE96-4FAB-9AAD-5E5BF1AE93B5}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{4E0E75E7-AE96-4FAB-9AAD-5E5BF1AE93B5}\InprocServer32]
@="C:\\WINDOWS\\system32\\mwexch40.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{0CCC8F93-9814-41D6-B380-57A34F239F8B}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0CCC8F93-9814-41D6-B380-57A34F239F8B}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0CCC8F93-9814-41D6-B380-57A34F239F8B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0CCC8F93-9814-41D6-B380-57A34F239F8B}\InprocServer32]
@="C:\\WINDOWS\\system32\\gbkcsp.dll"
"ThreadingModel"="Apartment"

**********************************************************************************
Files Found are not all bad files:

C:\WINDOWS\SYSTEM32\
vcrifier.dll Wed Jan 4 2006 9:11:38p ..S.R 233,688 228.21 K
lv4209~1.dll Sun Dec 18 2005 3:12:20p ..S.R 233,688 228.21 K
cviconfg.dll Wed Jan 18 2006 7:37:40p ..S.R 233,688 228.21 K
oobctl32.dll Mon Dec 5 2005 4:08:34p ..S.R 233,784 228.30 K
gdi32.dll Wed Dec 28 2005 9:54:36p A.... 280,064 273.50 K
mshtml.dll Wed Nov 23 2005 8:06:34p A.... 3,015,680 2.88 M
mwexch40.dll Fri Dec 9 2005 4:34:00p ..S.R 235,581 230.06 K
browseui.dll Wed Nov 23 2005 8:06:34p A.... 1,022,464 998.50 K
danim.dll Fri Nov 4 2005 10:16:24p A.... 1,054,208 1.00 M
gbkcsp.dll Sat Dec 10 2005 10:14:22a ..S.R 236,836 231.29 K
myxml2r.dll Sun Dec 4 2005 7:00:16p ..S.R 235,509 229.99 K
mlslgn32.dll Sun Dec 4 2005 4:37:34p ..S.R 235,509 229.99 K
hashlib.dll Tue Nov 15 2005 12:12:08p A.... 117,976 115.21 K
msrating.dll Thu Oct 20 2005 10:39:30p A.... 146,432 143.00 K
dxtrans.dll Thu Oct 20 2005 10:39:28p A.... 205,312 200.50 K
extmgr.dll Thu Oct 20 2005 10:39:28p ..... 55,808 54.50 K
aisldpc.dll Sun Dec 4 2005 8:10:46p ..S.R 236,390 230.85 K
mstime.dll Thu Oct 20 2005 10:39:30p A.... 530,944 518.50 K
mshtmled.dll Thu Oct 20 2005 10:39:30p A.... 448,512 438.00 K
iepeers.dll Thu Oct 20 2005 10:39:28p A.... 251,392 245.50 K
cdfview.dll Thu Oct 20 2005 10:39:26p A.... 151,040 147.50 K
esent.dll Thu Oct 20 2005 5:20:04p A.... 1,082,368 1.03 M
wininet.dll Thu Oct 20 2005 10:39:30p A.... 658,432 643.00 K
urlmon.dll Fri Nov 4 2005 10:16:28p A.... 609,280 595.00 K
ktl2l7~1.dll Sun Dec 4 2005 10:09:06a ..S.R 235,509 229.99 K
kt88l7~1.dll Sat Dec 10 2005 8:25:32p ..S.R 236,836 231.29 K
shlwapi.dll Thu Oct 20 2005 10:39:30p A.... 473,600 462.50 K
shdocvw.dll Wed Nov 30 2005 10:59:30p A.... 1,492,480 1.42 M
lv0o09~1.dll Sun Dec 11 2005 12:27:18p ..S.R 233,997 228.51 K
pngfilt.dll Thu Oct 20 2005 10:39:30p A.... 39,424 38.50 K
lvn409~1.dll Sun Dec 4 2005 2:11:38p ..S.R 235,509 229.99 K
inseng.dll Thu Oct 20 2005 10:39:28p A.... 96,256 94.00 K
irnml5~1.dll Sun Dec 4 2005 5:39:20p ..S.R 236,664 231.12 K
k0jsla~1.dll Sun Dec 18 2005 2:28:46p ..S.R 235,344 229.83 K
cnsnpb22.dll Mon Dec 5 2005 3:54:18p ..S.R 236,692 231.14 K
hrlu05~1.dll Mon Dec 5 2005 5:11:16p ..S.R 236,516 230.97 K
lv8609~1.dll Mon Dec 5 2005 4:08:32p ..S.R 234,473 228.98 K
g4400e~1.dll Sun Dec 4 2005 12:06:14p ..S.R 235,509 229.99 K
h4n00e~1.dll Sun Dec 4 2005 11:35:20a ..S.R 236,484 230.94 K
ktrsl7~1.dll Mon Dec 5 2005 4:23:22p ..S.R 235,581 230.06 K
q068la~1.dll Sun Dec 4 2005 3:14:56p ..S.R 235,509 229.99 K
g8jo0i~1.dll Sun Dec 4 2005 7:18:24p ..S.R 236,708 231.16 K
gwfspi~1.dll Fri Nov 4 2005 4:27:18p A.... 23,304 22.76 K
jtjs07~1.dll Mon Dec 5 2005 7:56:20p ..S.R 236,298 230.76 K
enlql1~1.dll Sun Dec 11 2005 1:18:32p ..S.R 235,219 229.70 K
legitc~1.dll Fri Nov 4 2005 4:27:24p A.... 534,280 521.76 K
gcunco~1.dll Tue Nov 15 2005 12:12:06p A.... 95,448 93.21 K
gccoll~1.dll Tue Nov 15 2005 12:12:08p A.... 126,680 123.71 K
h00q0a~1.dll Sun Dec 4 2005 7:53:36p ..S.R 236,890 231.34 K
k0pmla~1.dll Sun Dec 4 2005 8:04:44p ..S.R 233,833 228.35 K
f20o0c~1.dll Sun Dec 4 2005 8:10:46p ..S.R 236,692 231.14 K
l04q0a~1.dll Sun Dec 4 2005 9:00:20p ..S.R 237,232 231.67 K
n22ulc~1.dll Mon Dec 5 2005 5:20:38p ..S.R 234,209 228.72 K
h64mlg~1.dll Mon Dec 5 2005 5:32:02p ..S.R 236,727 231.18 K
i0nmla~1.dll Fri Dec 9 2005 11:03:02p ..S.R 233,823 228.34 K
p04u0a~1.dll Sat Jan 7 2006 5:58:36p ..S.R 233,688 228.21 K
l62slg~1.dll Sat Jan 7 2006 10:06:24p ..S.R 233,688 228.21 K
i8nmli~1.dll Wed Jan 11 2006 5:46:44p ..S.R 233,688 228.21 K
k8js0i~1.dll Wed Jan 18 2006 7:28:20p ..S.R 233,688 228.21 K

59 items found: 59 files (36 H/S), 0 directories.
Total of file sizes: 20,983,063 bytes 20.01 M
Locate .tmp files:

C:\WINDOWS\SYSTEM32\
trj_nt~1.tmp Sat Jan 7 2006 3:50:00p A.... 2,122 2.07 K

1 item found: 1 file, 0 directories.
Total of file sizes: 2,122 bytes 2.07 K
**********************************************************************************
Directory Listing of system files:
Volume in drive C has no label.
Volume Serial Number is 3758-10D8

Directory of C:\WINDOWS\System32

01/18/2006 07:37 PM 233,688 cviconfg.dll
01/18/2006 07:28 PM 233,688 k8js0i17e8.dll
01/11/2006 05:46 PM 233,688 i8nmli5118.dll
01/07/2006 10:06 PM 233,688 l62slgf7162.dll
01/07/2006 05:58 PM 233,688 p04u0ah9ed4.dll
01/04/2006 09:11 PM 233,688 vcrifier.dll
12/18/2005 03:12 PM 233,688 lv4209hoe.dll
12/18/2005 02:28 PM 235,344 k0jsla171d.dll
12/11/2005 01:18 PM 235,219 enlql1351.dll
12/11/2005 12:27 PM 233,997 lv0o09d3e.dll
12/10/2005 08:25 PM 236,836 kt88l7lu1.dll
12/10/2005 10:14 AM 236,836 gbkcsp.dll
12/09/2005 11:03 PM 233,823 i0nmla511d.dll
12/09/2005 04:34 PM 235,581 mwexch40.dll
12/05/2005 07:56 PM 236,298 jtjs0717e.dll
12/05/2005 05:32 PM 236,727 h64mlgh1164.dll
12/05/2005 05:20 PM 234,209 n22ulcf91f2.dll
12/05/2005 05:11 PM 236,516 hrlu0539e.dll
12/05/2005 04:23 PM 235,581 ktrsl7971.dll
12/05/2005 04:08 PM 233,784 OOBCTL32.DLL
12/05/2005 04:08 PM 234,473 lv8609lse.dll
12/05/2005 03:54 PM 236,692 cnsNPB22.dll
12/04/2005 09:00 PM 237,232 l04q0ah5ed4.dll
12/04/2005 08:10 PM 236,692 f20o0cd3ef0.dll
12/04/2005 08:10 PM 236,390 aisldpc.dll
12/04/2005 08:04 PM 233,833 k0pmla711d.dll
12/04/2005 07:53 PM 236,890 h00q0ad5ed0.dll
12/04/2005 07:18 PM 236,708 g8jo0i13e8.dll
12/04/2005 07:00 PM 235,509 myxml2r.dll
12/04/2005 05:39 PM 236,664 irnml5511.dll
12/04/2005 04:37 PM 235,509 MLSLGN32.DLL
12/04/2005 03:14 PM 235,509 q068laju1do8.dll
12/04/2005 02:11 PM 235,509 lvn4095qe.dll
12/04/2005 12:06 PM 235,509 g4400ehmeh4a0.dll
12/04/2005 11:35 AM 236,484 h4n00e5meh.dll
12/04/2005 10:09 AM 235,509 ktl2l73o1.dll
07/30/2002 11:16 PM <DIR> Microsoft
07/30/2002 10:24 PM <DIR> dllcache
36 File(s) 8,471,679 bytes
2 Dir(s) 4,681,900,032 bytes free

Ok, there is the log, thank you again.
:thumbsup: :flowers: :huh:

#6 Cloutz

Cloutz

    The Malware Killa


  • Members
  • 150 posts
  • OFFLINE
  •  
  • Location:Montreal, Quebec
  • Local time:12:08 AM

Posted 18 January 2006 - 08:32 PM

Hi PSUBaller,

Close any programs you have open since this step requires a reboot.

From the l2mfix folder on your desktop, double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing enter. It will process then start. Your desktop and icons will disappear (this is normal). L2mfix will continue to scan your computer and when it's finished, it will be ready for a reboot. Press any key to reboot. After the reboot notepad will open with a log. Copy the contents of that log and paste it back into this thread, along with a new hijackthis log.

IMPORTANT: Do NOT run any other files in the l2mfix folder unless you are asked to do so!
If after the reboot the log does not open double click on it in the l2mfix folder.

Nick :thumbsup:
Posted Image Did I help? Please consider a small donation via paypal. Thank You.

Ad-Aware SE|CWShredder|Spybot S&D|Ewido Security Suite|HijackThis 1.99.1

Please don't PM me asking for help. The forums are there for a reason.

Cloutz 2006

#7 PSUBaller

PSUBaller
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:01:08 AM

Posted 18 January 2006 - 09:10 PM

Here is the log from the L2M fix:

L2mfix 010406
Creating Account.
The command completed successfully.

Adding Administrative privleges.
The command completed successfully.
Checking for L2MFix account(0=no 1=yes):
1
Granting SeDebugPrivilege to L2MFIX ... successful

Running From:
C:\WINDOWS\system32

Killing Processes!

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 276 'smss.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 368 'winlogon.exe'
Killing PID 368 'winlogon.exe'
Killing PID 368 'winlogon.exe'
Killing PID 368 'winlogon.exe'
Killing PID 368 'winlogon.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 3808 'explorer.exe'
Killing PID 3808 'explorer.exe'
Killing PID 3808 'explorer.exe'
Killing PID 3808 'explorer.exe'
Killing PID 3808 'explorer.exe'
Killing PID 3808 'explorer.exe'
Killing PID 3808 'explorer.exe'
Killing PID 3808 'explorer.exe'
Killing PID 3808 'explorer.exe'
Killing PID 3808 'explorer.exe'
Killing PID 3808 'explorer.exe'
Killing PID 3808 'explorer.exe'
Killing PID 3808 'explorer.exe'
Killing PID 3808 'explorer.exe'
Killing PID 3808 'explorer.exe'
Killing PID 3808 'explorer.exe'
Killing PID 3808 'explorer.exe'
Killing PID 3808 'explorer.exe'
Killing PID 3808 'explorer.exe'
Killing PID 3808 'explorer.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 1812 'rundll32.exe'
Killing PID 1812 'rundll32.exe'
Killing PID 1812 'rundll32.exe'
Killing PID 1812 'rundll32.exe'
Restoring Sedebugprivilege:
Granting SeDebugPrivilege to Administrators ... successful

Scanning First Pass. Please Wait!

First Pass Completed

Second Pass Scanning

Second pass Completed!
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
Deleting: C:\WINDOWS\system32\aisldpc.dll
Successfully Deleted: C:\WINDOWS\system32\aisldpc.dll
Deleting: C:\WINDOWS\system32\cnsNPB22.dll
Successfully Deleted: C:\WINDOWS\system32\cnsNPB22.dll
Deleting: C:\WINDOWS\system32\cviconfg.dll
Successfully Deleted: C:\WINDOWS\system32\cviconfg.dll
Deleting: C:\WINDOWS\system32\enlql1351.dll
Successfully Deleted: C:\WINDOWS\system32\enlql1351.dll
Deleting: C:\WINDOWS\system32\f20o0cd3ef0.dll
Successfully Deleted: C:\WINDOWS\system32\f20o0cd3ef0.dll
Deleting: C:\WINDOWS\system32\g4400ehmeh4a0.dll
Successfully Deleted: C:\WINDOWS\system32\g4400ehmeh4a0.dll
Deleting: C:\WINDOWS\system32\g8jo0i13e8.dll
Successfully Deleted: C:\WINDOWS\system32\g8jo0i13e8.dll
Deleting: C:\WINDOWS\system32\gbkcsp.dll
Successfully Deleted: C:\WINDOWS\system32\gbkcsp.dll
Deleting: C:\WINDOWS\system32\h00q0ad5ed0.dll
Successfully Deleted: C:\WINDOWS\system32\h00q0ad5ed0.dll
Deleting: C:\WINDOWS\system32\h4n00e5meh.dll
Successfully Deleted: C:\WINDOWS\system32\h4n00e5meh.dll
Deleting: C:\WINDOWS\system32\h64mlgh1164.dll
Successfully Deleted: C:\WINDOWS\system32\h64mlgh1164.dll
Deleting: C:\WINDOWS\system32\hrlu0539e.dll
Successfully Deleted: C:\WINDOWS\system32\hrlu0539e.dll
Deleting: C:\WINDOWS\system32\i0nmla511d.dll
Successfully Deleted: C:\WINDOWS\system32\i0nmla511d.dll
Deleting: C:\WINDOWS\system32\i8nmli5118.dll
Successfully Deleted: C:\WINDOWS\system32\i8nmli5118.dll
Deleting: C:\WINDOWS\system32\irnml5511.dll
Successfully Deleted: C:\WINDOWS\system32\irnml5511.dll
Deleting: C:\WINDOWS\system32\jtjs0717e.dll
Successfully Deleted: C:\WINDOWS\system32\jtjs0717e.dll
Deleting: C:\WINDOWS\system32\k0jsla171d.dll
Successfully Deleted: C:\WINDOWS\system32\k0jsla171d.dll
Deleting: C:\WINDOWS\system32\k0pmla711d.dll
Successfully Deleted: C:\WINDOWS\system32\k0pmla711d.dll
Deleting: C:\WINDOWS\system32\k8js0i17e8.dll
Successfully Deleted: C:\WINDOWS\system32\k8js0i17e8.dll
Deleting: C:\WINDOWS\system32\kt88l7lu1.dll
Successfully Deleted: C:\WINDOWS\system32\kt88l7lu1.dll
Deleting: C:\WINDOWS\system32\ktl2l73o1.dll
Successfully Deleted: C:\WINDOWS\system32\ktl2l73o1.dll
Deleting: C:\WINDOWS\system32\ktrsl7971.dll
Successfully Deleted: C:\WINDOWS\system32\ktrsl7971.dll
Deleting: C:\WINDOWS\system32\l04q0ah5ed4.dll
Successfully Deleted: C:\WINDOWS\system32\l04q0ah5ed4.dll
Deleting: C:\WINDOWS\system32\l62slgf7162.dll
Successfully Deleted: C:\WINDOWS\system32\l62slgf7162.dll
Deleting: C:\WINDOWS\system32\lv0o09d3e.dll
Successfully Deleted: C:\WINDOWS\system32\lv0o09d3e.dll
Deleting: C:\WINDOWS\system32\lv4209hoe.dll
Successfully Deleted: C:\WINDOWS\system32\lv4209hoe.dll
Deleting: C:\WINDOWS\system32\lv8609lse.dll
Successfully Deleted: C:\WINDOWS\system32\lv8609lse.dll
Deleting: C:\WINDOWS\system32\lvn4095qe.dll
Successfully Deleted: C:\WINDOWS\system32\lvn4095qe.dll
Deleting: C:\WINDOWS\system32\MLSLGN32.DLL
Successfully Deleted: C:\WINDOWS\system32\MLSLGN32.DLL
Deleting: C:\WINDOWS\system32\mwexch40.dll
Successfully Deleted: C:\WINDOWS\system32\mwexch40.dll
Deleting: C:\WINDOWS\system32\myxml2r.dll
Successfully Deleted: C:\WINDOWS\system32\myxml2r.dll
Deleting: C:\WINDOWS\system32\n22ulcf91f2.dll
Successfully Deleted: C:\WINDOWS\system32\n22ulcf91f2.dll
Deleting: C:\WINDOWS\system32\OOBCTL32.DLL
Successfully Deleted: C:\WINDOWS\system32\OOBCTL32.DLL
Deleting: C:\WINDOWS\system32\p04u0ah9ed4.dll
Successfully Deleted: C:\WINDOWS\system32\p04u0ah9ed4.dll
Deleting: C:\WINDOWS\system32\q068laju1do8.dll
Successfully Deleted: C:\WINDOWS\system32\q068laju1do8.dll
Deleting: C:\WINDOWS\system32\vcrifier.dll
Successfully Deleted: C:\WINDOWS\system32\vcrifier.dll

msg11?.dll
0 file(s) copied.
Desktop.ini sucessfully removed




Restoring Windows Update Certificates.:

The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\BITS]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\i8nmli5118.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


The following are the files found:
****************************************************************************
C:\WINDOWS\system32\aisldpc.dll
C:\WINDOWS\system32\cnsNPB22.dll
C:\WINDOWS\system32\cviconfg.dll
C:\WINDOWS\system32\enlql1351.dll
C:\WINDOWS\system32\f20o0cd3ef0.dll
C:\WINDOWS\system32\g4400ehmeh4a0.dll
C:\WINDOWS\system32\g8jo0i13e8.dll
C:\WINDOWS\system32\gbkcsp.dll
C:\WINDOWS\system32\h00q0ad5ed0.dll
C:\WINDOWS\system32\h4n00e5meh.dll
C:\WINDOWS\system32\h64mlgh1164.dll
C:\WINDOWS\system32\hrlu0539e.dll
C:\WINDOWS\system32\i0nmla511d.dll
C:\WINDOWS\system32\i8nmli5118.dll
C:\WINDOWS\system32\irnml5511.dll
C:\WINDOWS\system32\jtjs0717e.dll
C:\WINDOWS\system32\k0jsla171d.dll
C:\WINDOWS\system32\k0pmla711d.dll
C:\WINDOWS\system32\k8js0i17e8.dll
C:\WINDOWS\system32\kt88l7lu1.dll
C:\WINDOWS\system32\ktl2l73o1.dll
C:\WINDOWS\system32\ktrsl7971.dll
C:\WINDOWS\system32\l04q0ah5ed4.dll
C:\WINDOWS\system32\l62slgf7162.dll
C:\WINDOWS\system32\lv0o09d3e.dll
C:\WINDOWS\system32\lv4209hoe.dll
C:\WINDOWS\system32\lv8609lse.dll
C:\WINDOWS\system32\lvn4095qe.dll
C:\WINDOWS\system32\MLSLGN32.DLL
C:\WINDOWS\system32\mwexch40.dll
C:\WINDOWS\system32\myxml2r.dll
C:\WINDOWS\system32\n22ulcf91f2.dll
C:\WINDOWS\system32\OOBCTL32.DLL
C:\WINDOWS\system32\p04u0ah9ed4.dll
C:\WINDOWS\system32\q068laju1do8.dll
C:\WINDOWS\system32\vcrifier.dll

Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{1F4BF33F-3E8F-4607-9E96-F2A2B4CAE350}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{1F4BF33F-3E8F-4607-9E96-F2A2B4CAE350}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{1F4BF33F-3E8F-4607-9E96-F2A2B4CAE350}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{1F4BF33F-3E8F-4607-9E96-F2A2B4CAE350}\InprocServer32]
@="C:\\WINDOWS\\system32\\cviconfg.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{636B43EF-4158-492B-A8BA-D55749C0BF84}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{636B43EF-4158-492B-A8BA-D55749C0BF84}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{636B43EF-4158-492B-A8BA-D55749C0BF84}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{636B43EF-4158-492B-A8BA-D55749C0BF84}\InprocServer32]
@="C:\\WINDOWS\\system32\\MLSLGN32.DLL"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{D9786B68-E07B-4F66-B982-6B7A9CCD7312}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{D9786B68-E07B-4F66-B982-6B7A9CCD7312}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{D9786B68-E07B-4F66-B982-6B7A9CCD7312}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{D9786B68-E07B-4F66-B982-6B7A9CCD7312}\InprocServer32]
@="C:\\WINDOWS\\system32\\myxml2r.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{FCC1ECCE-D4D6-4104-839D-2B65E896C7D4}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{FCC1ECCE-D4D6-4104-839D-2B65E896C7D4}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{FCC1ECCE-D4D6-4104-839D-2B65E896C7D4}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{FCC1ECCE-D4D6-4104-839D-2B65E896C7D4}\InprocServer32]
@="C:\\WINDOWS\\system32\\aisldpc.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{4E0E75E7-AE96-4FAB-9AAD-5E5BF1AE93B5}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{4E0E75E7-AE96-4FAB-9AAD-5E5BF1AE93B5}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{4E0E75E7-AE96-4FAB-9AAD-5E5BF1AE93B5}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{4E0E75E7-AE96-4FAB-9AAD-5E5BF1AE93B5}\InprocServer32]
@="C:\\WINDOWS\\system32\\mwexch40.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{0CCC8F93-9814-41D6-B380-57A34F239F8B}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0CCC8F93-9814-41D6-B380-57A34F239F8B}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0CCC8F93-9814-41D6-B380-57A34F239F8B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0CCC8F93-9814-41D6-B380-57A34F239F8B}\InprocServer32]
@="C:\\WINDOWS\\system32\\gbkcsp.dll"
"ThreadingModel"="Apartment"

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{1F4BF33F-3E8F-4607-9E96-F2A2B4CAE350}"=-
"{636B43EF-4158-492B-A8BA-D55749C0BF84}"=-
"{D9786B68-E07B-4F66-B982-6B7A9CCD7312}"=-
"{FCC1ECCE-D4D6-4104-839D-2B65E896C7D4}"=-
"{4E0E75E7-AE96-4FAB-9AAD-5E5BF1AE93B5}"=-
"{0CCC8F93-9814-41D6-B380-57A34F239F8B}"=-
[-HKEY_CLASSES_ROOT\CLSID\{1F4BF33F-3E8F-4607-9E96-F2A2B4CAE350}]
[-HKEY_CLASSES_ROOT\CLSID\{636B43EF-4158-492B-A8BA-D55749C0BF84}]
[-HKEY_CLASSES_ROOT\CLSID\{D9786B68-E07B-4F66-B982-6B7A9CCD7312}]
[-HKEY_CLASSES_ROOT\CLSID\{FCC1ECCE-D4D6-4104-839D-2B65E896C7D4}]
[-HKEY_CLASSES_ROOT\CLSID\{4E0E75E7-AE96-4FAB-9AAD-5E5BF1AE93B5}]
[-HKEY_CLASSES_ROOT\CLSID\{0CCC8F93-9814-41D6-B380-57A34F239F8B}]
REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"SV1"=""
****************************************************************************
Desktop.ini Contents:
****************************************************************************
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
****************************************************************************
Checking for L2MFix account(0=no 1=yes):
0
Zipping up files for submission:
adding: dlls/aisldpc.dll (deflated 5%)
adding: dlls/cnsNPB22.dll (deflated 5%)
adding: dlls/cviconfg.dll (deflated 4%)
adding: dlls/enlql1351.dll (deflated 5%)
adding: dlls/f20o0cd3ef0.dll (deflated 5%)
adding: dlls/g4400ehmeh4a0.dll (deflated 5%)
adding: dlls/g8jo0i13e8.dll (deflated 5%)
adding: dlls/gbkcsp.dll (deflated 5%)
adding: dlls/h00q0ad5ed0.dll (deflated 5%)
adding: dlls/h4n00e5meh.dll (deflated 5%)
adding: dlls/h64mlgh1164.dll (deflated 5%)
adding: dlls/hrlu0539e.dll (deflated 5%)
adding: dlls/i0nmla511d.dll (deflated 4%)
adding: dlls/i8nmli5118.dll (deflated 4%)
adding: dlls/irnml5511.dll (deflated 5%)
adding: dlls/jtjs0717e.dll (deflated 5%)
adding: dlls/k0jsla171d.dll (deflated 5%)
adding: dlls/k0pmla711d.dll (deflated 4%)
adding: dlls/k8js0i17e8.dll (deflated 4%)
adding: dlls/kt88l7lu1.dll (deflated 5%)
adding: dlls/ktl2l73o1.dll (deflated 5%)
adding: dlls/ktrsl7971.dll (deflated 5%)
adding: dlls/l04q0ah5ed4.dll (deflated 5%)
adding: dlls/l62slgf7162.dll (deflated 4%)
adding: dlls/lv0o09d3e.dll (deflated 4%)
adding: dlls/lv4209hoe.dll (deflated 4%)
adding: dlls/lv8609lse.dll (deflated 5%)
adding: dlls/lvn4095qe.dll (deflated 5%)
adding: dlls/MLSLGN32.DLL (deflated 5%)
adding: dlls/mwexch40.dll (deflated 5%)
adding: dlls/myxml2r.dll (deflated 5%)
adding: dlls/n22ulcf91f2.dll (deflated 4%)
adding: dlls/OOBCTL32.DLL (deflated 4%)
adding: dlls/p04u0ah9ed4.dll (deflated 4%)
adding: dlls/q068laju1do8.dll (deflated 5%)
adding: dlls/vcrifier.dll (deflated 4%)
adding: backregs/notibac.reg (deflated 72%)
adding: backregs/shell.reg (deflated 74%)
adding: backregs/1F4BF33F-3E8F-4607-9E96-F2A2B4CAE350.reg (deflated 70%)
adding: backregs/636B43EF-4158-492B-A8BA-D55749C0BF84.reg (deflated 70%)
adding: backregs/D9786B68-E07B-4F66-B982-6B7A9CCD7312.reg (deflated 70%)
adding: backregs/FCC1ECCE-D4D6-4104-839D-2B65E896C7D4.reg (deflated 70%)
adding: backregs/4E0E75E7-AE96-4FAB-9AAD-5E5BF1AE93B5.reg (deflated 70%)
adding: backregs/0CCC8F93-9814-41D6-B380-57A34F239F8B.reg (deflated 70%)


Here is the new Hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 9:08:38 PM, on 1/18/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\DIGStream\digstream.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\DOCUME~1\Brandon\LOCALS~1\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p...er=6&ar=msnhome
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.microsoft.com/search/search.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p...er=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.microsoft.com/search/search.asp
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://home.microsoft.com/access/autosearch.asp?p=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [DVDUpgrade] DVDUpgrd.exe /async9x
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: hp psc 1000 series.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O12 - Plugin for .avi: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .bmp: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O12 - Plugin for .wav: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npaudio.dll
O15 - Trusted Zone: http://free.aol.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kav...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - https://scan.safety.live.com/resource/downl...lscbase3401.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1136732402324
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://us-housecall.trendmicro-europe.com/...ivex/hcImpl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab
O20 - Winlogon Notify: BITS - C:\WINDOWS\system32\i8nmli5118.dll (file missing)
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

And thank you again for your help!

#8 Cloutz

Cloutz

    The Malware Killa


  • Members
  • 150 posts
  • OFFLINE
  •  
  • Location:Montreal, Quebec
  • Local time:12:08 AM

Posted 19 January 2006 - 12:07 AM

Hi PSUBaller,

Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
O20 - Winlogon Notify: BITS - C:\WINDOWS\system32\i8nmli5118.dll (file missing)
Now close all windows other than HiJackThis, then click Fix Checked.

Then, please run this online virus scan: ActiveScan

Please give me a fresh HijackThis log along with the report from the ActiveScan.

Also, how's the pc going? Any pop-ups?

Thanks,
Nick
Posted Image Did I help? Please consider a small donation via paypal. Thank You.

Ad-Aware SE|CWShredder|Spybot S&D|Ewido Security Suite|HijackThis 1.99.1

Please don't PM me asking for help. The forums are there for a reason.

Cloutz 2006

#9 PSUBaller

PSUBaller
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:01:08 AM

Posted 19 January 2006 - 06:27 PM

The computer seems to be back to normal, no pop ups, no more iexplorer.exe processes showing up.

Here is the Hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 6:21:58 PM, on 1/19/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\DIGStream\digstream.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\DOCUME~1\Brandon\LOCALS~1\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p...er=6&ar=msnhome
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.microsoft.com/search/search.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p...er=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.microsoft.com/search/search.asp
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://home.microsoft.com/access/autosearch.asp?p=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [DVDUpgrade] DVDUpgrd.exe /async9x
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: hp psc 1000 series.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O12 - Plugin for .avi: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .bmp: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O12 - Plugin for .wav: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npaudio.dll
O15 - Trusted Zone: http://free.aol.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kav...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - https://scan.safety.live.com/resource/downl...lscbase3401.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1136732402324
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://us-housecall.trendmicro-europe.com/...ivex/hcImpl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

Here is the Active Scan log:



Incident Status Location

Adware:adware/toprebates Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Ebates.exe
Adware:adware/gator Not disinfected C:\WINDOWS\GatorSilentSetup.log
Potentially unwanted tool:application/myway Not disinfected HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{014DA6C9-189F-421A-88CD-07CFE51CFF10}
Spyware:Cookie/go Not disinfected C:\Documents and Settings\Brandon\Cookies\brandon@go[2].txt
Spyware:Cookie/go Not disinfected C:\Documents and Settings\Brandon\Application Data\Mozilla\Profiles\default\9rlsz1wg.slt\cookies.txt[.go.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Brandon\Application Data\Mozilla\Profiles\default\9rlsz1wg.slt\cookies.txt[servedby.advertising.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Brandon\Application Data\Mozilla\Profiles\default\9rlsz1wg.slt\cookies.txt[.advertising.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Brandon\Application Data\Mozilla\Profiles\default\9rlsz1wg.slt\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Brandon\Application Data\Mozilla\Profiles\default\9rlsz1wg.slt\cookies.txt[.bluestreak.com/]
Spyware:Cookie/Bfast Not disinfected C:\Documents and Settings\Brandon\Application Data\Mozilla\Profiles\default\9rlsz1wg.slt\cookies.txt[.bfast.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\WINDOWS\TEMP\Cookies\brandon@questionmarket[2].txt
Spyware:Cookie/Ask Not disinfected C:\WINDOWS\TEMP\Cookies\brandon@ask[1].txt
Spyware:Cookie/Hbmediapro Not disinfected C:\WINDOWS\TEMP\Cookies\brandon@adopt.hbmediapro[2].txt
Spyware:Cookie/Rn11 Not disinfected C:\WINDOWS\TEMP\Cookies\brandon@rn11[2].txt
Spyware:Cookie/Zedo Not disinfected C:\WINDOWS\TEMP\Cookies\brandon@c5.zedo[1].txt
Spyware:Cookie/Adserver Not disinfected C:\WINDOWS\TEMP\Cookies\brandon@z1.adserver[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\WINDOWS\TEMP\Cookies\brandon@realmedia[2].txt
Spyware:Cookie/Casalemedia Not disinfected C:\WINDOWS\TEMP\Cookies\brandon@casalemedia[2].txt
Spyware:Cookie/Maxserving Not disinfected C:\WINDOWS\TEMP\Cookies\brandon@maxserving[1].txt
Spyware:Cookie/YieldManager Not disinfected C:\WINDOWS\TEMP\Cookies\brandon@ad.yieldmanager[2].txt
Spyware:Cookie/Paypopup Not disinfected C:\WINDOWS\TEMP\Cookies\brandon@paypopup[1].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\WINDOWS\TEMP\Cookies\brandon@tribalfusion[2].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\WINDOWS\TEMP\Cookies\brandon@trafficmp[2].txt
Spyware:Cookie/Falkag Not disinfected C:\WINDOWS\TEMP\Cookies\brandon@as1.falkag[2].txt
Spyware:Cookie/WUpd Not disinfected C:\WINDOWS\TEMP\Cookies\brandon@revenue[1].txt
Spyware:Cookie/Falkag Not disinfected C:\WINDOWS\TEMP\Cookies\brandon@as-us.falkag[1].txt
Spyware:Cookie/Zedo Not disinfected C:\WINDOWS\TEMP\Cookies\brandon@zedo[2].txt
Adware:Adware/TopRebates Not disinfected C:\Program Files\Lime_Shop\Limeshop0.exe
Spyware:Spyware/Support Not disinfected C:\Program Files\Support.com\backup\tg\tgcmd.exe\1519616_5dbb20689_[tgcmd.exe]
Spyware:Spyware/Support Not disinfected C:\Program Files\Support.com\bin\tgcmd.exe
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@questionmarket[1].txt
Spyware:Cookie/Ask Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@ask[1].txt
Spyware:Cookie/Affiliate fuel Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@www.affiliatefuel[1].txt
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@burstnet[1].txt
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@888[2].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@casalemedia[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@belnk[1].txt
Spyware:Cookie/go Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@go[4].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@realmedia[1].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@perf.overture[1].txt
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@revenue[2].txt
Spyware:Cookie/go Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@go[2].txt
Spyware:Cookie/Microsofte Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@microsofteup.112.2o7[1].txt
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@z1.adserver[1].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@ad.yieldmanager[3].txt
Spyware:Cookie/go Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@go[3].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@ad.yieldmanager[1].txt
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@azjmp[2].txt
Spyware:Cookie/go Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@go[6].txt
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@as1.falkag[1].txt
Spyware:Cookie/Tickle Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@tickle[2].txt
Spyware:Cookie/Screensavers Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@i.screensavers[2].txt
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@adopt.hbmediapro[1].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@com[2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@dist.belnk[2].txt
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@yadro[2].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@adrevolver[1].txt
Spyware:Cookie/Rn11 Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@rn11[1].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@zedo[1].txt
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@apmebf[2].txt
Spyware:Cookie/QkSrv Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@qksrv[2].txt
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@as-us.falkag[2].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@trafficmp[1].txt
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@as-eu.falkag[1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@adrevolver[3].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@c5.zedo[1].txt
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@maxserving[2].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@ad.yieldmanager[5].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@stats1.reliablestats[1].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@www.burstbeacon[1].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Cookies\brandon@tribalfusion[1].txt
Spyware:Spyware/LinkReplacer Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\F0B85.tmp[Quicklinks.exe]
Spyware:Cookie/go Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\~DF4FF1.tmp
Spyware:Cookie/go Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temp\Perflib_Perfdata_1558.dat
Spyware:Spyware/LinkReplacer Not disinfected C:\Documents and Settings\Brandon\Local Settings\Temporary Internet Files\Content.IE5\IPDAZQD8\9400[1].cab[Quicklinks.exe]
Virus:Trj/Downloader.GPB Disinfected C:\Documents and Settings\Brandon\Local Settings\Temporary Internet Files\Content.IE5\J8TDF8K0\ltndmain[1].dll
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix.exe[Process.exe]
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\Process.exe
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\aisldpc.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\cnsNPB22.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\cviconfg.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\enlql1351.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\f20o0cd3ef0.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\g4400ehmeh4a0.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\g8jo0i13e8.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\gbkcsp.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\h00q0ad5ed0.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\h4n00e5meh.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\h64mlgh1164.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\hrlu0539e.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\i0nmla511d.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\i8nmli5118.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\irnml5511.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\jtjs0717e.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\k0jsla171d.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\k0pmla711d.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\k8js0i17e8.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\kt88l7lu1.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\ktl2l73o1.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\ktrsl7971.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\l04q0ah5ed4.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\l62slgf7162.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\lv0o09d3e.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\lv4209hoe.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\lv8609lse.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\lvn4095qe.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\MLSLGN32.DLL
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\mwexch40.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\myxml2r.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\n22ulcf91f2.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\OOBCTL32.DLL
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\p04u0ah9ed4.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\q068laju1do8.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\dlls\vcrifier.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\backup.zip[aisldpc.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\backup.zip[cnsNPB22.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\backup.zip[cviconfg.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\backup.zip[enlql1351.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\backup.zip[f20o0cd3ef0.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\backup.zip[g4400ehmeh4a0.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\backup.zip[g8jo0i13e8.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\backup.zip[gbkcsp.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\backup.zip[h00q0ad5ed0.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\backup.zip[h4n00e5meh.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\backup.zip[h64mlgh1164.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\backup.zip[hrlu0539e.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\backup.zip[i0nmla511d.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\backup.zip[i8nmli5118.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\backup.zip[irnml5511.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\backup.zip[jtjs0717e.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\backup.zip[k0jsla171d.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\backup.zip[k0pmla711d.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\backup.zip[k8js0i17e8.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\backup.zip[kt88l7lu1.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\backup.zip[ktl2l73o1.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\backup.zip[ktrsl7971.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Brandon\Desktop\l2mfix\backup.zip[l04q0ah5ed4.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Set

#10 Cloutz

Cloutz

    The Malware Killa


  • Members
  • 150 posts
  • OFFLINE
  •  
  • Location:Montreal, Quebec
  • Local time:12:08 AM

Posted 19 January 2006 - 07:27 PM

Hi PSUBaller,

Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

Everything looks great, your HijackThis log appears to be CLEAN!!!

Here is a list of tools I like to suggest to users to prevent future infections.
  • Spybot Search & Destroy - Uber powerful tool which can search and annhilate nasties that make it onto your system. Now with an Immunize section that will help prevent future infections.
  • AdAware -Another very powerful tool which searches and kills nasties that infect your system. AdAware and Spybot Search & Destroy compliment each other very well.
  • SpywareBlaster - Great prevention tool to keep nasties from installing on your system.
  • SpywareGuard - Works as a Spyware "Shield" to protect your computer from getting malware in the first place.
  • IE-SpyAd - Puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
  • CleanUP! -Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
  • Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.
  • Google Toolbar - Free google toolbar that allows you to use the powerful Google search engine from the bar, but also blocks pop up windows.
  • Trillian or Miranda-IM - These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN)
  • Firefox- Internet Explorer is NOT the most secure browser. I highly recommend Firefox as a safer alternative.
To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein

Nick :thumbsup:
Posted Image Did I help? Please consider a small donation via paypal. Thank You.

Ad-Aware SE|CWShredder|Spybot S&D|Ewido Security Suite|HijackThis 1.99.1

Please don't PM me asking for help. The forums are there for a reason.

Cloutz 2006

#11 PSUBaller

PSUBaller
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:01:08 AM

Posted 19 January 2006 - 07:39 PM

Nick,

Thank you for everything... I've already installed quite a few of the programs from your list and probably will look into a few more. I think the computer is actually running better than before I started with you, so thank you a few more times over!

Brandon

#12 Cloutz

Cloutz

    The Malware Killa


  • Members
  • 150 posts
  • OFFLINE
  •  
  • Location:Montreal, Quebec
  • Local time:12:08 AM

Posted 20 January 2006 - 05:23 PM

Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :thumbsup:

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
Posted Image Did I help? Please consider a small donation via paypal. Thank You.

Ad-Aware SE|CWShredder|Spybot S&D|Ewido Security Suite|HijackThis 1.99.1

Please don't PM me asking for help. The forums are there for a reason.

Cloutz 2006




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users