Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Popups Like Crazy


  • Please log in to reply
11 replies to this topic

#1 g3o

g3o

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:10:17 PM

Posted 11 January 2006 - 08:12 PM

Random explorer ads keep popping up when im doing nothing...
I have updated versions of the following and cannot get rid of it:

Adaware, Spybot, AVG Antivirus, Microsoft Antispyware, Spysweeper, Adsspy

This is gonna drive me crazy, any help would be greatly appreciated.

Heres my Hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 8:07:48 PM, on 1/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Webroot\Enterprise\Spy Sweeper\SpySweeperTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe
C:\Program Files\Sophos SWEEP for NT\ICMON.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Sophos\Remote Update\cachemgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sophos SWEEP for NT\SWNETSUP.EXE
C:\Program Files\Sophos SWEEP for NT\SWEEPSRV.SYS
C:\Program Files\Webroot\Enterprise\CommAgent\CommAgent.exe
C:\Program Files\Webroot\Enterprise\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\My Documents\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.bridgew.edu/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: 0 UseCustom # Webroot SpySweeper entry
O1 - Hosts: 0 UseDefs # Webroot SpySweeper entry
O1 - Hosts: iefeadsl.com # Webroot SpySweeper entry
O1 - Hosts: 008k.com # Webroot SpySweeper entry
O1 - Hosts: 356563.net # Webroot SpySweeper entry
O1 - Hosts: 75tz.com # Webroot SpySweeper entry
O1 - Hosts: kitasearch.com # Webroot SpySweeper entry
O1 - Hosts: lookfor.com # Webroot SpySweeper entry
O1 - Hosts: look-today.com # Webroot SpySweeper entry
O1 - Hosts: new.8ad.com # Webroot SpySweeper entry
O1 - Hosts: rf104.com # Webroot SpySweeper entry
O1 - Hosts: search-to-find.com # Webroot SpySweeper entry
O1 - Hosts: www.05p.com # Webroot SpySweeper entry
O1 - Hosts: www.6o9.com # Webroot SpySweeper entry
O1 - Hosts: www.ga31.com # Webroot SpySweeper entry
O1 - Hosts: www.v61.com # Webroot SpySweeper entry
O4 - HKLM\..\Run: [Webroot Spy Sweeper, Enterprise Edition] c:\Program Files\Webroot\Enterprise\Spy Sweeper\SpySweeperTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Clean Access Agent.lnk = C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe
O4 - Global Startup: InterCheck Monitor.LNK = C:\Program Files\Sophos SWEEP for NT\ICMON.EXE
O4 - Global Startup: Remote Update Monitor.lnk = C:\Program Files\Sophos\Remote Update\imonitor.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1136416264421
O20 - Winlogon Notify: SideBySide - C:\WINDOWS\system32\i4420ehoeh4c0.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Sophos Cache Manager (CacheMgr) - SOPHOS Plc - C:\Program Files\Sophos\Remote Update\cachemgr.exe
O23 - Service: Sophos Anti-Virus Network (SweepNet) - Sophos Plc - C:\Program Files\Sophos SWEEP for NT\SWNETSUP.EXE
O23 - Service: Sophos Anti-Virus (SWEEPSRV.SYS) - Sophos Plc - C:\Program Files\Sophos SWEEP for NT\SWEEPSRV.SYS
O23 - Service: Webroot CommAgent Service (WebrootCommAgentService) - Webroot Software, Inc. - C:\Program Files\Webroot\Enterprise\CommAgent\CommAgent.exe
O23 - Service: Webroot SpySweeper Service (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Enterprise\Spy Sweeper\SpySweeper.exe

BC AdBot (Login to Remove)

 


#2 Guest_Cretemonster_*

Guest_Cretemonster_*

  • Guests
  • OFFLINE
  •  

Posted 14 January 2006 - 07:54 AM

Hi g3o and Welcome to the Bleeping Computer!

Please Download the l2mfix from
http://www.atribune.org/downloads/l2mfix.exe
or
http://www.downloads.subratam.org/l2mfix.exe

Save the file to your desktop and double click l2mfix.exe.

Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop.

Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter.

This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log.

Copy the contents of that log and paste it into this thread.

IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!


If you recieve any errors while attempting to run Option 1 of the l2mfix similar to these


C:\windows\system32\cmd.exe or C:\windows\system32\autoexec.nt

"The system file is not suitable for running ms-dos and microsoft windows applications"

Choose "Close to terminate the application"

Then please use option 5 of the l2mfix or the web page link in the l2mfix folder to solve this error condition.

DO NOT run the fix portion without repairing this first.


#3 g3o

g3o
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  

Posted 30 January 2006 - 01:04 PM

heres the log, thanks in advance.

L2MFIX find log 010406
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Explorer]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\q4860elsehq60.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

**********************************************************************************
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{AEB7C5D2-5AB8-7881-C24A-6050C8EF443F}"=""

**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run..."
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People..."
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{5E44E225-A408-11CF-B581-008029601108}"="Adaptec DirectCD Shell Extension"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Web Folders"
"{00020D75-0000-0000-C000-000000000046}"="Microsoft Office Outlook Desktop Icon Handler"
"{0006F045-0000-0000-C000-000000000046}"="Microsoft Office Outlook Custom Icon Handler"
"{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
"{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
"{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
"{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
"{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
"{29e3fb5b-cf62-45b5-b8bf-1ad500385fc7}"="Shell Context Menu Handler for Application References"
"{29e3fb5b-cf62-45b5-b8bf-1ad500385fc6}"="Shell Context Menu Handler for Application Manifests"
"{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75}"="Shell Icon Handler for Application References"
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
"{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
"{1B804342-7C5C-426E-BC3D-B1AA44DEE3B9}"=""
"{21569614-B795-46b1-85F4-E737A8DC09AD}"="Shell Search Band"
"{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"="AVG7 Shell Extension"
"{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}"="AVG7 Find Extension"

**********************************************************************************
HKEY ROOT CLASSIDS:
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{1B804342-7C5C-426E-BC3D-B1AA44DEE3B9}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{1B804342-7C5C-426E-BC3D-B1AA44DEE3B9}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{1B804342-7C5C-426E-BC3D-B1AA44DEE3B9}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{1B804342-7C5C-426E-BC3D-B1AA44DEE3B9}\InprocServer32]
@="C:\\WINDOWS\\system32\\MQRDO20.DLL"
"ThreadingModel"="Apartment"

**********************************************************************************
Files Found are not all bad files:

C:\WINDOWS\SYSTEM32\
04cgqrom.dll Mon Dec 12 2005 8:28:34p A.... 41,472 40.50 K
armlib.dll Fri Dec 16 2005 5:59:14p ..S.R 235,339 229.82 K
browseui.dll Wed Nov 23 2005 8:06:34p A.... 1,022,464 998.50 K
danim.dll Fri Nov 4 2005 10:16:24p A.... 1,054,208 1.00 M
en68l1~1.dll Mon Jan 23 2006 12:10:36p ..S.R 237,200 231.64 K
gccoll~1.dll Tue Nov 15 2005 12:12:08p A.... 126,680 123.71 K
gcunco~1.dll Tue Nov 15 2005 12:12:06p A.... 95,448 93.21 K
gdi32.dll Wed Dec 28 2005 9:54:36p A.... 280,064 273.50 K
gwfspi~1.dll Fri Nov 4 2005 4:27:18p A.... 23,304 22.76 K
hashlib.dll Tue Nov 15 2005 12:12:08p A.... 117,976 115.21 K
j40sle~1.dll Wed Jan 11 2006 8:59:06p ..S.R 235,339 229.82 K
kxdsmsfi.dll Fri Dec 16 2005 5:53:40p ..S.R 235,339 229.82 K
legitc~1.dll Fri Nov 4 2005 4:27:24p A.... 534,280 521.76 K
lv0609~1.dll Mon Jan 30 2006 12:07:06p ..S.R 235,948 230.42 K
mfvbvm50.dll Mon Dec 12 2005 8:26:06p ..S.R 234,885 229.38 K
mqrdo20.dll Mon Jan 30 2006 12:07:06p ..S.R 235,339 229.82 K
mshtml.dll Wed Nov 23 2005 8:06:34p A.... 3,015,680 2.88 M
msvcp71.dll Tue Dec 20 2005 7:08:20p A.... 499,712 488.00 K
ojbcji32.dll Fri Dec 16 2005 6:53:54p ..S.R 235,339 229.82 K
owjsel.dll Mon Dec 12 2005 9:05:08p ..S.R 234,885 229.38 K
oze32.dll Fri Dec 16 2005 5:55:28p ..S.R 235,339 229.82 K
paapi.dll Fri Dec 16 2005 5:55:54p ..S.R 235,339 229.82 K
plrfnw.dll Fri Dec 16 2005 5:55:42p ..S.R 235,339 229.82 K
q4860e~1.dll Wed Jan 11 2006 5:46:14p ..S.R 235,339 229.82 K
rssapi32.dll Fri Dec 16 2005 9:11:14p ..S.R 235,339 229.82 K
searddlg.dll Fri Dec 16 2005 5:56:58p ..S.R 235,339 229.82 K
shdocvw.dll Wed Nov 30 2005 10:59:30p A.... 1,492,480 1.42 M
siarddlg.dll Fri Dec 16 2005 5:56:26p ..S.R 235,339 229.82 K
skdocvw.dll Fri Dec 16 2005 5:56:48p ..S.R 235,339 229.82 K
skriptpw.dll Fri Dec 16 2005 5:56:36p ..S.R 235,339 229.82 K
snsbkup.dll Fri Dec 16 2005 1:52:02p ..S.R 234,885 229.38 K
sqmpapi.dll Fri Dec 16 2005 5:57:10p ..S.R 235,339 229.82 K
svclient.dll Fri Dec 16 2005 5:57:20p ..S.R 235,339 229.82 K
sxreamci.dll Fri Dec 16 2005 5:57:30p ..S.R 235,339 229.82 K
tjappcmp.dll Fri Dec 16 2005 5:57:46p ..S.R 235,339 229.82 K
urlmon.dll Fri Nov 4 2005 10:16:28p A.... 609,280 595.00 K
uynp.dll Fri Dec 16 2005 5:57:58p ..S.R 235,339 229.82 K
wccsvc.dll Mon Dec 12 2005 10:11:34p ..S.R 234,885 229.38 K
wodap32.dll Fri Dec 16 2005 3:29:06p ..S.R 234,885 229.38 K

39 items found: 39 files (26 H/S), 0 directories.
Total of file sizes: 15,032,062 bytes 14.33 M
Locate .tmp files:

No matches found.
**********************************************************************************
Directory Listing of system files:
Volume in drive C has no label.
Volume Serial Number is E8C7-934B

Directory of C:\WINDOWS\System32

01/30/2006 12:07 PM 235,339 MQRDO20.DLL
01/30/2006 12:07 PM 235,948 lv0609dse.dll
01/23/2006 12:10 PM 237,200 en68l1ju1.dll
01/11/2006 08:59 PM 235,339 j40sled71h0.dll
01/11/2006 05:46 PM 235,339 q4860elsehq60.dll
01/11/2006 05:34 PM <DIR> dllcache
12/16/2005 09:11 PM 235,339 rSsapi32.dll
12/16/2005 06:53 PM 235,339 ojbcji32.dll
12/16/2005 05:59 PM 235,339 armlib.dll
12/16/2005 05:57 PM 235,339 uynp.dll
12/16/2005 05:57 PM 235,339 tjappcmp.dll
12/16/2005 05:57 PM 235,339 sxreamci.dll
12/16/2005 05:57 PM 235,339 svclient.dll
12/16/2005 05:57 PM 235,339 sqmpapi.dll
12/16/2005 05:56 PM 235,339 searddlg.dll
12/16/2005 05:56 PM 235,339 skdocvw.dll
12/16/2005 05:56 PM 235,339 skriptpw.dll
12/16/2005 05:56 PM 235,339 siarddlg.dll
12/16/2005 05:55 PM 235,339 paapi.dll
12/16/2005 05:55 PM 235,339 plrfnw.dll
12/16/2005 05:55 PM 235,339 oze32.dll
12/16/2005 05:53 PM 235,339 kxdsmsfi.dll
12/16/2005 03:29 PM 234,885 wodap32.dll
12/16/2005 01:52 PM 234,885 snsbkup.dll
12/12/2005 10:11 PM 234,885 wccsvc.dll
12/12/2005 09:05 PM 234,885 owjsel.dll
12/12/2005 08:26 PM 234,885 mfvbvm50.dll
05/07/2004 10:00 AM <DIR> Microsoft
26 File(s) 6,119,014 bytes
2 Dir(s) 15,936,622,592 bytes free

#4 Guest_Cretemonster_*

Guest_Cretemonster_*

  • Guests
  • OFFLINE
  •  

Posted 04 February 2006 - 07:36 AM

My Apologies,I was called out of town on emergency buisness.


Close any programs you have open since this step requires a reboot.

From the l2mfix folder on your desktop, double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing enter, then it will ask for a password enter bye (lowercase) then hit enter.

Your desktop and icons will disappear (this is normal).

L2mfix will continue to scan your computer and when it's finished, it will be ready for a reboot.

Press any key to reboot.

After the reboot notepad will open with a log.

Copy the contents of that log and paste it back into this thread, along with a new hijackthis log.

IMPORTANT: Do NOT run any other files in the l2mfix folder unless you are asked to do so!
If after the reboot the log does not open double click on it in the l2mfix folder.

#5 g3o

g3o
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:10:17 PM

Posted 05 February 2006 - 04:53 PM

L2mfix 010406
Creating Account.
The command completed successfully.

Adding Administrative privleges.
The command completed successfully.
Checking for L2MFix account(0=no 1=yes):
1
Granting SeDebugPrivilege to L2MFIX ... successful

Running From:
C:\WINDOWS\system32

Killing Processes!

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 776 'smss.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 872 'winlogon.exe'
Killing PID 872 'winlogon.exe'
Killing PID 872 'winlogon.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 448 'explorer.exe'
Killing PID 448 'explorer.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 1952 'rundll32.exe'
Restoring Sedebugprivilege:
Granting SeDebugPrivilege to Administrators ... successful

Scanning First Pass. Please Wait!

First Pass Completed

Second Pass Scanning

Second pass Completed!
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
Deleting: C:\WINDOWS\system32\armlib.dll
Successfully Deleted: C:\WINDOWS\system32\armlib.dll
Deleting: C:\WINDOWS\system32\en68l1ju1.dll
Successfully Deleted: C:\WINDOWS\system32\en68l1ju1.dll
Deleting: C:\WINDOWS\system32\j40sled71h0.dll
Successfully Deleted: C:\WINDOWS\system32\j40sled71h0.dll
Deleting: C:\WINDOWS\system32\kxdsmsfi.dll
Successfully Deleted: C:\WINDOWS\system32\kxdsmsfi.dll
Deleting: C:\WINDOWS\system32\lv0609dse.dll
Successfully Deleted: C:\WINDOWS\system32\lv0609dse.dll
Deleting: C:\WINDOWS\system32\mfvbvm50.dll
Successfully Deleted: C:\WINDOWS\system32\mfvbvm50.dll
Deleting: C:\WINDOWS\system32\MQRDO20.DLL
Successfully Deleted: C:\WINDOWS\system32\MQRDO20.DLL
Deleting: C:\WINDOWS\system32\ojbcji32.dll
Successfully Deleted: C:\WINDOWS\system32\ojbcji32.dll
Deleting: C:\WINDOWS\system32\owjsel.dll
Successfully Deleted: C:\WINDOWS\system32\owjsel.dll
Deleting: C:\WINDOWS\system32\oze32.dll
Successfully Deleted: C:\WINDOWS\system32\oze32.dll
Deleting: C:\WINDOWS\system32\paapi.dll
Successfully Deleted: C:\WINDOWS\system32\paapi.dll
Deleting: C:\WINDOWS\system32\plrfnw.dll
Successfully Deleted: C:\WINDOWS\system32\plrfnw.dll
Deleting: C:\WINDOWS\system32\q4860elsehq60.dll
Successfully Deleted: C:\WINDOWS\system32\q4860elsehq60.dll
Deleting: C:\WINDOWS\system32\rSsapi32.dll
Successfully Deleted: C:\WINDOWS\system32\rSsapi32.dll
Deleting: C:\WINDOWS\system32\searddlg.dll
Successfully Deleted: C:\WINDOWS\system32\searddlg.dll
Deleting: C:\WINDOWS\system32\siarddlg.dll
Successfully Deleted: C:\WINDOWS\system32\siarddlg.dll
Deleting: C:\WINDOWS\system32\skdocvw.dll
Successfully Deleted: C:\WINDOWS\system32\skdocvw.dll
Deleting: C:\WINDOWS\system32\skriptpw.dll
Successfully Deleted: C:\WINDOWS\system32\skriptpw.dll
Deleting: C:\WINDOWS\system32\snsbkup.dll
Successfully Deleted: C:\WINDOWS\system32\snsbkup.dll
Deleting: C:\WINDOWS\system32\sqmpapi.dll
Successfully Deleted: C:\WINDOWS\system32\sqmpapi.dll
Deleting: C:\WINDOWS\system32\svclient.dll
Successfully Deleted: C:\WINDOWS\system32\svclient.dll
Deleting: C:\WINDOWS\system32\sxreamci.dll
Successfully Deleted: C:\WINDOWS\system32\sxreamci.dll
Deleting: C:\WINDOWS\system32\tjappcmp.dll
Successfully Deleted: C:\WINDOWS\system32\tjappcmp.dll
Deleting: C:\WINDOWS\system32\uynp.dll
Successfully Deleted: C:\WINDOWS\system32\uynp.dll
Deleting: C:\WINDOWS\system32\wccsvc.dll
Successfully Deleted: C:\WINDOWS\system32\wccsvc.dll
Deleting: C:\WINDOWS\system32\wodap32.dll
Successfully Deleted: C:\WINDOWS\system32\wodap32.dll

msg11?.dll
0 file(s) copied.



Restoring Windows Update Certificates.:

The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Explorer]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\q4860elsehq60.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


The following are the files found:
****************************************************************************
C:\WINDOWS\system32\armlib.dll
C:\WINDOWS\system32\en68l1ju1.dll
C:\WINDOWS\system32\j40sled71h0.dll
C:\WINDOWS\system32\kxdsmsfi.dll
C:\WINDOWS\system32\lv0609dse.dll
C:\WINDOWS\system32\mfvbvm50.dll
C:\WINDOWS\system32\MQRDO20.DLL
C:\WINDOWS\system32\ojbcji32.dll
C:\WINDOWS\system32\owjsel.dll
C:\WINDOWS\system32\oze32.dll
C:\WINDOWS\system32\paapi.dll
C:\WINDOWS\system32\plrfnw.dll
C:\WINDOWS\system32\q4860elsehq60.dll
C:\WINDOWS\system32\rSsapi32.dll
C:\WINDOWS\system32\searddlg.dll
C:\WINDOWS\system32\siarddlg.dll
C:\WINDOWS\system32\skdocvw.dll
C:\WINDOWS\system32\skriptpw.dll
C:\WINDOWS\system32\snsbkup.dll
C:\WINDOWS\system32\sqmpapi.dll
C:\WINDOWS\system32\svclient.dll
C:\WINDOWS\system32\sxreamci.dll
C:\WINDOWS\system32\tjappcmp.dll
C:\WINDOWS\system32\uynp.dll
C:\WINDOWS\system32\wccsvc.dll
C:\WINDOWS\system32\wodap32.dll

Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{1B804342-7C5C-426E-BC3D-B1AA44DEE3B9}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{1B804342-7C5C-426E-BC3D-B1AA44DEE3B9}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{1B804342-7C5C-426E-BC3D-B1AA44DEE3B9}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{1B804342-7C5C-426E-BC3D-B1AA44DEE3B9}\InprocServer32]
@="C:\\WINDOWS\\system32\\MQRDO20.DLL"
"ThreadingModel"="Apartment"

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{1B804342-7C5C-426E-BC3D-B1AA44DEE3B9}"=-
[-HKEY_CLASSES_ROOT\CLSID\{1B804342-7C5C-426E-BC3D-B1AA44DEE3B9}]
REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"SV1"=""
****************************************************************************
Desktop.ini Contents:
****************************************************************************

****************************************************************************
Checking for L2MFix account(0=no 1=yes):
0
Zipping up files for submission:
adding: dlls/armlib.dll (164 bytes security) (deflated 5%)
adding: dlls/en68l1ju1.dll (164 bytes security) (deflated 5%)
adding: dlls/j40sled71h0.dll (164 bytes security) (deflated 5%)
adding: dlls/kxdsmsfi.dll (164 bytes security) (deflated 5%)
adding: dlls/lv0609dse.dll (164 bytes security) (deflated 5%)
adding: dlls/mfvbvm50.dll (164 bytes security) (deflated 5%)
adding: dlls/MQRDO20.DLL (164 bytes security) (deflated 5%)
adding: dlls/ojbcji32.dll (164 bytes security) (deflated 5%)
adding: dlls/owjsel.dll (164 bytes security) (deflated 5%)
adding: dlls/oze32.dll (164 bytes security) (deflated 5%)
adding: dlls/paapi.dll (164 bytes security) (deflated 5%)
adding: dlls/plrfnw.dll (164 bytes security) (deflated 5%)
adding: dlls/q4860elsehq60.dll (164 bytes security) (deflated 5%)
adding: dlls/rSsapi32.dll (164 bytes security) (deflated 5%)
adding: dlls/searddlg.dll (164 bytes security) (deflated 5%)
adding: dlls/siarddlg.dll (164 bytes security) (deflated 5%)
adding: dlls/skdocvw.dll (164 bytes security) (deflated 5%)
adding: dlls/skriptpw.dll (164 bytes security) (deflated 5%)
adding: dlls/snsbkup.dll (164 bytes security) (deflated 5%)
adding: dlls/sqmpapi.dll (164 bytes security) (deflated 5%)
adding: dlls/svclient.dll (164 bytes security) (deflated 5%)
adding: dlls/sxreamci.dll (164 bytes security) (deflated 5%)
adding: dlls/tjappcmp.dll (164 bytes security) (deflated 5%)
adding: dlls/uynp.dll (164 bytes security) (deflated 5%)
adding: dlls/wccsvc.dll (164 bytes security) (deflated 5%)
adding: dlls/wodap32.dll (164 bytes security) (deflated 5%)
adding: backregs/1B804342-7C5C-426E-BC3D-B1AA44DEE3B9.reg (212 bytes security) (deflated 70%)
adding: backregs/notibac.reg (164 bytes security) (deflated 63%)
adding: backregs/shell.reg (164 bytes security) (deflated 74%)

#6 g3o

g3o
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  

Posted 05 February 2006 - 04:54 PM

Logfile of HijackThis v1.99.1
Scan saved at 4:51:55 PM, on 2/5/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Webroot\Enterprise\Spy Sweeper\SpySweeperTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe
C:\Program Files\Sophos SWEEP for NT\ICMON.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Administrator\My Documents\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.bridgew.edu/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: 0 UseCustom # Webroot SpySweeper entry
O1 - Hosts: 0 UseDefs # Webroot SpySweeper entry
O1 - Hosts: iefeadsl.com # Webroot SpySweeper entry
O1 - Hosts: 008k.com # Webroot SpySweeper entry
O1 - Hosts: 356563.net # Webroot SpySweeper entry
O1 - Hosts: 75tz.com # Webroot SpySweeper entry
O1 - Hosts: kitasearch.com # Webroot SpySweeper entry
O1 - Hosts: lookfor.com # Webroot SpySweeper entry
O1 - Hosts: look-today.com # Webroot SpySweeper entry
O1 - Hosts: new.8ad.com # Webroot SpySweeper entry
O1 - Hosts: rf104.com # Webroot SpySweeper entry
O1 - Hosts: search-to-find.com # Webroot SpySweeper entry
O1 - Hosts: www.05p.com # Webroot SpySweeper entry
O1 - Hosts: www.6o9.com # Webroot SpySweeper entry
O1 - Hosts: www.ga31.com # Webroot SpySweeper entry
O1 - Hosts: www.v61.com # Webroot SpySweeper entry
O4 - HKLM\..\Run: [Webroot Spy Sweeper, Enterprise Edition] c:\Program Files\Webroot\Enterprise\Spy Sweeper\SpySweeperTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Clean Access Agent.lnk = C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe
O4 - Global Startup: InterCheck Monitor.LNK = C:\Program Files\Sophos SWEEP for NT\ICMON.EXE
O4 - Global Startup: Remote Update Monitor.lnk = C:\Program Files\Sophos\Remote Update\imonitor.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1136416264421
O20 - Winlogon Notify: Explorer - C:\WINDOWS\system32\q4860elsehq60.dll (file missing)

#7 g3o

g3o
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:10:17 PM

Posted 05 February 2006 - 04:57 PM

It appears to be fixed, I haven't had anything in about 15 mins since the reboot after I ran the fix.

Just a note for future reference on whatever I had, the popups didnt seem to come when I had my internet unplugged.

Anyway, thanks a bunch, you are great. :thumbsup:

#8 Guest_Cretemonster_*

Guest_Cretemonster_*

  • Guests
  • OFFLINE
  •  

Posted 05 February 2006 - 04:58 PM

Download WinPFind to your C Drive.
http://www.bleepingcomputer.com/files/winpfind.php

Right Click the Zip Folder and Select "Extract All"

Don't use it yet

Reboot into SAFE MODE(Tap F8 when restarting)
Here is a link on how to boot into Safe Mode:
http://service1.symantec.com/SUPPORT/tsgen...src=sec_doc_nam

From the WinPFind folder-> Doubleclick WinPFind.exe and Click "Start Scan"

It will scan the entire System, so please be patient

Once you see "Scan Complete"-> a log (WinPFind.txt) will be automatically generated in the WinPFind folder


Run MSCONFIG and enable everything in the startup area. To get to MSCONFIG, click on Start -> Run -> type in MSCONFIG -> click OK!

Under the "General" Tab

Make Sure "Normal Startup-load all device drivers and services" has a green tick by it

Click Apply->Close->Follow the Prompts to Restart

Restart Normal and have the PC Scanned here:
Panda Active Scan

You will need to be using Internet Explorer for the Scan to work

Save the Report it generates

Post back with a fresh HijackThis log and the reports from WinPFind and Panda

#9 g3o

g3o
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:10:17 PM

Posted 05 February 2006 - 07:37 PM

Panda, said to pay 50$ to disenfect =/


Incident Status Location

Adware:adware/dollarrevenue Not disinfected C:\WINDOWS\timessquare1.dat
Adware:adware/cws.searchmeup Not disinfected C:\WINDOWS\uniq
Adware:adware/sqwire Not disinfected Windows Registry
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\backup.zip[armlib.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\backup.zip[en68l1ju1.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\backup.zip[j40sled71h0.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\backup.zip[kxdsmsfi.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\backup.zip[lv0609dse.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\backup.zip[mfvbvm50.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\backup.zip[MQRDO20.DLL]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\backup.zip[ojbcji32.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\backup.zip[owjsel.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\backup.zip[oze32.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\backup.zip[paapi.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\backup.zip[plrfnw.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\backup.zip[q4860elsehq60.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\backup.zip[rSsapi32.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\backup.zip[searddlg.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\backup.zip[siarddlg.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\backup.zip[skdocvw.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\backup.zip[skriptpw.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\backup.zip[snsbkup.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\backup.zip[sqmpapi.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\backup.zip[svclient.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\backup.zip[sxreamci.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\backup.zip[tjappcmp.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\backup.zip[uynp.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\backup.zip[wccsvc.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\backup.zip[wodap32.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\dlls\armlib.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\dlls\en68l1ju1.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\dlls\j40sled71h0.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\dlls\kxdsmsfi.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\dlls\lv0609dse.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\dlls\mfvbvm50.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\dlls\MQRDO20.DLL
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\dlls\ojbcji32.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\dlls\owjsel.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\dlls\oze32.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\dlls\paapi.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\dlls\plrfnw.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\dlls\q4860elsehq60.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\dlls\rSsapi32.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\dlls\searddlg.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\dlls\siarddlg.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\dlls\skdocvw.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\dlls\skriptpw.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\dlls\snsbkup.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\dlls\sqmpapi.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\dlls\svclient.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\dlls\sxreamci.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\dlls\tjappcmp.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\dlls\uynp.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\dlls\wccsvc.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\dlls\wodap32.dll
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Administrator\Desktop\l2mfix\Process.exe
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@ad.yieldmanager[2].txt
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@azjmp[2].txt
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@maxserving[1].txt
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@questionmarket[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@realmedia[2].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@stats1.reliablestats[2].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@trafficmp[2].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@tribalfusion[1].txt
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\Temporary Internet Files\Content.IE5\4DQR4HQR\l2mfix[1].exe[Process.exe]
Virus:Crew A.2480 Renamed C:\Documents and Settings\Administrator\My Documents\!midnight\public_html\dkp\includes\lib\class.soapclient.php
Hacktool:HackTool/ExitWin.C Not disinfected C:\masm32\examples\EXAMPLE1\QEXIT\QEXIT.EXE
Virus:Trj/Torpig.U Disinfected C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.dll
Spyware:Cookie/Atlas DMT Not disinfected C:\RECYCLER\S-1-5-21-861567501-436374069-1343024091-1003\Dc1.txt
Spyware:Cookie/Doubleclick Not disinfected C:\RECYCLER\S-1-5-21-861567501-436374069-1343024091-1003\Dc2.txt
Virus:Trj/Qhost.AX Disinfected C:\WINDOWS\system32\drivers\etc\hosts.20051212-200402.backup
Virus:Trj/Qhost.AX Disinfected C:\WINDOWS\system32\drivers\etc\hosts.20051212-200518.backup
Virus:Trj/Qhost.AX Disinfected C:\WINDOWS\system32\drivers\etc\hosts.20051212-200519.backup
Virus:Trj/Qhost.AX Disinfected C:\WINDOWS\system32\drivers\etc\hosts.20051212-202347.backup
Virus:Trj/Qhost.AX Disinfected C:\WINDOWS\system32\drivers\etc\hosts.20051212-202348.backup
Virus:Trj/Qhost.AX Disinfected C:\WINDOWS\system32\drivers\etc\hosts.20051212-203718.backup
Virus:Trj/Qhost.AX Disinfected C:\WINDOWS\system32\drivers\etc\hosts.20051212-212041.backup
Virus:Trj/Qhost.gen Disinfected C:\WINDOWS\system32\drivers\etc\hosts.20051212-213454.backup
Spyware:Cookie/YieldManager Not disinfected C:\WINDOWS\Temp\Cookies\administrator@ad.yieldmanager[1].txt
Spyware:Cookie/YieldManager Not disinfected C:\WINDOWS\Temp\Cookies\administrator@ad.yieldmanager[3].txt
Spyware:Cookie/YieldManager Not disinfected C:\WINDOWS\Temp\Cookies\administrator@ad.yieldmanager[4].txt
Spyware:Cookie/YieldManager Not disinfected C:\WINDOWS\Temp\Cookies\administrator@ad.yieldmanager[5].txt
Spyware:Cookie/Hbmediapro Not disinfected C:\WINDOWS\Temp\Cookies\administrator@adopt.hbmediapro[2].txt
Spyware:Cookie/Adrevolver Not disinfected C:\WINDOWS\Temp\Cookies\administrator@adrevolver[1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\WINDOWS\Temp\Cookies\administrator@adrevolver[3].txt
Spyware:Cookie/Apmebf Not disinfected C:\WINDOWS\Temp\Cookies\administrator@apmebf[2].txt
Spyware:Cookie/Falkag Not disinfected C:\WINDOWS\Temp\Cookies\administrator@as-eu.falkag[1].txt
Spyware:Cookie/Falkag Not disinfected C:\WINDOWS\Temp\Cookies\administrator@as1.falkag[2].txt
Spyware:Cookie/Ask Not disinfected C:\WINDOWS\Temp\Cookies\administrator@ask[1].txt
Spyware:Cookie/Azjmp Not disinfected C:\WINDOWS\Temp\Cookies\administrator@azjmp[1].txt
Spyware:Cookie/Belnk Not disinfected C:\WINDOWS\Temp\Cookies\administrator@belnk[1].txt
Spyware:Cookie/BurstNet Not disinfected C:\WINDOWS\Temp\Cookies\administrator@burstnet[2].txt
Spyware:Cookie/Zedo Not disinfected C:\WINDOWS\Temp\Cookies\administrator@c5.zedo[2].txt
Spyware:Cookie/Casalemedia Not disinfected C:\WINDOWS\Temp\Cookies\administrator@casalemedia[1].txt
Spyware:Cookie/Belnk Not disinfected C:\WINDOWS\Temp\Cookies\administrator@dist.belnk[2].txt
Spyware:Cookie/Screensavers Not disinfected C:\WINDOWS\Temp\Cookies\administrator@i.screensavers[1].txt
Spyware:Cookie/Maxserving Not disinfected C:\WINDOWS\Temp\Cookies\administrator@maxserving[2].txt
Spyware:Cookie/Overture Not disinfected C:\WINDOWS\Temp\Cookies\administrator@overture[1].txt
Spyware:Cookie/Paypopup Not disinfected C:\WINDOWS\Temp\Cookies\administrator@paypopup[1].txt
Spyware:Cookie/Overture Not disinfected C:\WINDOWS\Temp\Cookies\administrator@perf.overture[1].txt
Spyware:Cookie/QkSrv Not disinfected C:\WINDOWS\Temp\Cookies\administrator@qksrv[1].txt
Spyware:Cookie/QuestionMarket Not disinfected C:\WINDOWS\Temp\Cookies\administrator@questionmarket[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\WINDOWS\Temp\Cookies\administrator@realmedia[2].txt
Spyware:Cookie/WUpd Not disinfected C:\WINDOWS\Temp\Cookies\administrator@revenue[1].txt
Spyware:Cookie/Rn11 Not disinfected C:\WINDOWS\Temp\Cookies\administrator@rn11[1].txt
Spyware:Cookie/Reliablestats Not disinfected C:\WINDOWS\Temp\Cookies\administrator@stats1.reliablestats[1].txt
Spyware:Cookie/Tradedoubler Not disinfected C:\WINDOWS\Temp\Cookies\administrator@tradedoubler[2].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\WINDOWS\Temp\Cookies\administrator@trafficmp[1].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\WINDOWS\Temp\Cookies\administrator@tribalfusion[1].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\WINDOWS\Temp\Cookies\administrator@www.burstbeacon[1].txt
Spyware:Cookie/Adserver Not disinfected C:\WINDOWS\Temp\Cookies\administrator@z1.adserver[1].txt
Spyware:Cookie/Zedo Not disinfected C:\WINDOWS\Temp\Cookies\administrator@zedo[1].txt
Potentially unwanted tool:Application/Winfixer2005 Not disinfected C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\0PE678RY\WinAntiVirusPro2006ScannerInstall[1].exe

Edited by g3o, 05 February 2006 - 07:43 PM.


#10 g3o

g3o
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:10:17 PM

Posted 05 February 2006 - 07:43 PM

WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.

If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.

Windows OS and Versions
Product Name: Microsoft Windows XP Current Build: Service Pack 2 Current Build Number: 2600
Internet Explorer Version: 6.0.2900.2180

Checking Selected Standard Folders

Checking %SystemDrive% folder...
qoologic 1/1/2006 11:57:06 AM 12286525 C:\AVG7QT.DAT
urllogic 1/1/2006 11:57:06 AM 12286525 C:\AVG7QT.DAT
qoologic 2/5/2006 5:00:00 PM 204131 C:\WinPFind.zip

Checking %ProgramFilesDir% folder...

Checking %WinDir% folder...
ad-w-a-r-e.com 12/12/2005 8:50:58 PM 1468 C:\WINDOWS\IE4 Error Log.txt
PTech 9/23/2004 11:12:58 AM 1360638 C:\WINDOWS\setupapi.log.0.old

Checking %System% folder...
UPX! 12/12/2005 8:28:34 PM 41472 C:\WINDOWS\SYSTEM32\04cgqrom.dll
PEC2 8/23/2001 7:00:00 AM 41397 C:\WINDOWS\SYSTEM32\dfrg.msc
PTech 11/4/2005 4:27:24 PM 534280 C:\WINDOWS\SYSTEM32\LegitCheckControl.DLL
PECompact2 1/4/2006 10:41:02 PM 2827616 C:\WINDOWS\SYSTEM32\MRT.exe
aspack 1/4/2006 10:41:02 PM 2827616 C:\WINDOWS\SYSTEM32\MRT.exe
aspack 8/4/2004 2:56:36 AM 708096 C:\WINDOWS\SYSTEM32\ntdll.dll
qoologic 3/7/2005 6:13:24 PM 8806998 C:\WINDOWS\SYSTEM32\pav.sig
aspack 3/7/2005 6:13:24 PM 8806998 C:\WINDOWS\SYSTEM32\pav.sig
SAHAgent 3/7/2005 6:13:24 PM 8806998 C:\WINDOWS\SYSTEM32\pav.sig
winsync 3/7/2005 6:13:24 PM 8806998 C:\WINDOWS\SYSTEM32\pav.sig
Umonitor 8/4/2004 2:56:44 AM 657920 C:\WINDOWS\SYSTEM32\rasdlg.dll
UPX! 7/11/2005 3:29:36 PM R 118888 C:\WINDOWS\SYSTEM32\resetWireless.exe
winsync 8/23/2001 7:00:00 AM 1309184 C:\WINDOWS\SYSTEM32\wbdbase.deu

Checking %System%\Drivers folder and sub-folders...
UPX! 1/24/2006 7:12:26 PM 752608 C:\WINDOWS\SYSTEM32\drivers\avg7core.sys
FSG! 1/24/2006 7:12:26 PM 752608 C:\WINDOWS\SYSTEM32\drivers\avg7core.sys
PEC2 1/24/2006 7:12:26 PM 752608 C:\WINDOWS\SYSTEM32\drivers\avg7core.sys
aspack 1/24/2006 7:12:26 PM 752608 C:\WINDOWS\SYSTEM32\drivers\avg7core.sys
PTech 8/4/2004 12:41:38 AM 1309184 C:\WINDOWS\SYSTEM32\drivers\mtlstrm.sys

Items found in C:\WINDOWS\SYSTEM32\drivers\etc\hosts
127.0.0.1 www.qoologic.com
127.0.0.1 www.urllogic.com

qoologic 12/12/2005 8:04:04 PM R 3775 C:\WINDOWS\SYSTEM32\drivers\etc\hosts.20051212-200402.backup
urllogic 12/12/2005 8:04:04 PM R 3775 C:\WINDOWS\SYSTEM32\drivers\etc\hosts.20051212-200402.backup
qoologic 12/12/2005 8:05:20 PM R 3672 C:\WINDOWS\SYSTEM32\drivers\etc\hosts.20051212-200518.backup
urllogic 12/12/2005 8:05:20 PM R 3672 C:\WINDOWS\SYSTEM32\drivers\etc\hosts.20051212-200518.backup
qoologic 12/12/2005 8:05:20 PM R 3470 C:\WINDOWS\SYSTEM32\drivers\etc\hosts.20051212-200519.backup
urllogic 12/12/2005 8:05:20 PM R 3470 C:\WINDOWS\SYSTEM32\drivers\etc\hosts.20051212-200519.backup
qoologic 12/12/2005 8:23:48 PM R 3445 C:\WINDOWS\SYSTEM32\drivers\etc\hosts.20051212-202347.backup
urllogic 12/12/2005 8:23:48 PM R 3445 C:\WINDOWS\SYSTEM32\drivers\etc\hosts.20051212-202347.backup
qoologic 12/12/2005 8:23:48 PM R 3374 C:\WINDOWS\SYSTEM32\drivers\etc\hosts.20051212-202348.backup
urllogic 12/12/2005 8:23:48 PM R 3374 C:\WINDOWS\SYSTEM32\drivers\etc\hosts.20051212-202348.backup
qoologic 12/12/2005 8:37:20 PM R 3140 C:\WINDOWS\SYSTEM32\drivers\etc\hosts.20051212-203718.backup
urllogic 12/12/2005 8:37:20 PM R 3140 C:\WINDOWS\SYSTEM32\drivers\etc\hosts.20051212-203718.backup
qoologic 12/12/2005 9:20:42 PM R 3061 C:\WINDOWS\SYSTEM32\drivers\etc\hosts.20051212-212041.backup
urllogic 12/12/2005 9:20:42 PM R 3061 C:\WINDOWS\SYSTEM32\drivers\etc\hosts.20051212-212041.backup
qoologic 12/12/2005 9:34:56 PM R 2326 C:\WINDOWS\SYSTEM32\drivers\etc\hosts.20051212-213454.backup
urllogic 12/12/2005 9:34:56 PM R 2326 C:\WINDOWS\SYSTEM32\drivers\etc\hosts.20051212-213454.backup
qoologic 1/11/2006 7:13:12 PM 2302 C:\WINDOWS\SYSTEM32\drivers\etc\hosts.new
urllogic 1/11/2006 7:13:12 PM 2302 C:\WINDOWS\SYSTEM32\drivers\etc\hosts.new

Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
2/5/2006 5:03:44 PM S 2048 C:\WINDOWS\bootstat.dat
2/5/2006 5:02:14 PM S 64 C:\WINDOWS\CSC\00000001
12/15/2005 10:09:10 PM S 64 C:\WINDOWS\CSC\00000002
1/11/2006 5:25:34 PM H 0 C:\WINDOWS\inf\oem17.inf
1/2/2006 6:09:36 PM S 11223 C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB912919.cat
2/5/2006 5:03:32 PM H 8192 C:\WINDOWS\system32\config\default.LOG
2/5/2006 5:04:04 PM H 1024 C:\WINDOWS\system32\config\SAM.LOG
2/5/2006 5:03:46 PM H 16384 C:\WINDOWS\system32\config\SECURITY.LOG
2/5/2006 5:04:06 PM H 81920 C:\WINDOWS\system32\config\software.LOG
2/5/2006 5:03:50 PM H 962560 C:\WINDOWS\system32\config\system.LOG
1/4/2006 6:06:40 PM H 1024 C:\WINDOWS\system32\config\systemprofile\NTUSER.DAT.LOG
12/25/2005 12:38:36 PM S 1047 C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Content\7C8A03C4580C6B04FDF34357F3474EDC
12/25/2005 12:38:36 PM S 1370 C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Content\B82262A5D5DA4DDACE9EDA7F787D0DEB
12/25/2005 12:38:38 PM S 126 C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaData\7C8A03C4580C6B04FDF34357F3474EDC
12/25/2005 12:38:36 PM S 194 C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaData\B82262A5D5DA4DDACE9EDA7F787D0DEB
1/18/2006 9:39:46 AM HS 388 C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\90c04d1d-39fc-4465-9577-c96063f6f8f7
1/18/2006 9:39:46 AM HS 24 C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\Preferred
2/5/2006 5:02:14 PM H 6 C:\WINDOWS\Tasks\SA.DAT
12/12/2005 5:30:56 PM HS 113 C:\WINDOWS\Temp\History\History.IE5\desktop.ini
12/12/2005 5:30:54 PM HS 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\desktop.ini
12/12/2005 5:30:56 PM HS 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\0PE678RY\desktop.ini
1/18/2006 12:19:30 PM HS 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\4HUNSX2V\desktop.ini
1/18/2006 12:19:30 PM HS 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\4LYFGXMB\desktop.ini
1/18/2006 12:19:30 PM HS 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\89QNWL23\desktop.ini
12/22/2005 7:25:52 PM HS 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\A2SDAU7R\desktop.ini
1/18/2006 12:19:30 PM HS 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\CLQ34TYJ\desktop.ini
12/22/2005 7:25:52 PM HS 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\FYR9O4CH\desktop.ini
12/22/2005 7:25:52 PM HS 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\GB6T8X4O\desktop.ini
12/12/2005 5:30:54 PM HS 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\KTIB456V\desktop.ini
12/22/2005 7:25:52 PM HS 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\RTN7US1K\desktop.ini
12/12/2005 5:30:54 PM HS 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\STQFG5AR\desktop.ini
12/12/2005 5:30:54 PM HS 67 C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\YZ0J2345\desktop.ini

Checking for CPL files...
Microsoft Corporation 8/4/2004 2:56:58 AM 68608 C:\WINDOWS\SYSTEM32\access.cpl
Microsoft Corporation 8/4/2004 2:56:58 AM 549888 C:\WINDOWS\SYSTEM32\appwiz.cpl
Dell Computer Corporation 2/20/2004 3:13:56 PM 958464 C:\WINDOWS\SYSTEM32\BCMWLCPL.CPL
Microsoft Corporation 8/4/2004 2:56:58 AM 110592 C:\WINDOWS\SYSTEM32\bthprops.cpl
Microsoft Corporation 8/4/2004 2:56:58 AM 135168 C:\WINDOWS\SYSTEM32\desk.cpl
Microsoft Corporation 8/4/2004 2:56:58 AM 80384 C:\WINDOWS\SYSTEM32\firewall.cpl
Microsoft Corporation 8/4/2004 2:56:58 AM 155136 C:\WINDOWS\SYSTEM32\hdwwiz.cpl
Microsoft Corporation 8/4/2004 2:56:58 AM 358400 C:\WINDOWS\SYSTEM32\inetcpl.cpl
Microsoft Corporation 8/4/2004 2:56:58 AM 129536 C:\WINDOWS\SYSTEM32\intl.cpl
Microsoft Corporation 8/4/2004 2:56:58 AM 380416 C:\WINDOWS\SYSTEM32\irprops.cpl
Microsoft Corporation 8/4/2004 2:56:58 AM 68608 C:\WINDOWS\SYSTEM32\joy.cpl
Sun Microsystems 6/28/2003 7:56:38 AM 229487 C:\WINDOWS\SYSTEM32\jpicpl32.cpl
Microsoft Corporation 8/23/2001 7:00:00 AM 187904 C:\WINDOWS\SYSTEM32\main.cpl
Microsoft Corporation 8/4/2004 2:56:58 AM 618496 C:\WINDOWS\SYSTEM32\mmsys.cpl
Microsoft Corporation 8/23/2001 7:00:00 AM 35840 C:\WINDOWS\SYSTEM32\ncpa.cpl
Microsoft Corporation 8/4/2004 2:56:58 AM 25600 C:\WINDOWS\SYSTEM32\netsetup.cpl
Microsoft Corporation 8/4/2004 2:56:58 AM 257024 C:\WINDOWS\SYSTEM32\nusrmgr.cpl
Microsoft Corporation 8/23/2001 7:00:00 AM 36864 C:\WINDOWS\SYSTEM32\nwc.cpl
Microsoft Corporation 8/4/2004 2:56:58 AM 32768 C:\WINDOWS\SYSTEM32\odbccp32.cpl
Microsoft Corporation 8/4/2004 2:56:58 AM 114688 C:\WINDOWS\SYSTEM32\powercfg.cpl
SigmaTel Inc. 4/9/2003 9:13:02 PM 81920 C:\WINDOWS\SYSTEM32\STAC97.cpl
Microsoft Corporation 8/4/2004 2:56:58 AM 298496 C:\WINDOWS\SYSTEM32\sysdm.cpl
Microsoft Corporation 8/23/2001 7:00:00 AM 28160 C:\WINDOWS\SYSTEM32\telephon.cpl
Microsoft Corporation 8/4/2004 2:56:58 AM 94208 C:\WINDOWS\SYSTEM32\timedate.cpl
Microsoft Corporation 8/4/2004 2:56:58 AM 148480 C:\WINDOWS\SYSTEM32\wscui.cpl
Microsoft Corporation 5/26/2005 3:16:30 AM 174360 C:\WINDOWS\SYSTEM32\wuaucpl.cpl
Microsoft Corporation 8/23/2001 7:00:00 AM 187904 C:\WINDOWS\SYSTEM32\dllcache\main.cpl
Microsoft Corporation 8/23/2001 7:00:00 AM 35840 C:\WINDOWS\SYSTEM32\dllcache\ncpa.cpl
Microsoft Corporation 8/23/2001 7:00:00 AM 36864 C:\WINDOWS\SYSTEM32\dllcache\nwc.cpl
Microsoft Corporation 8/23/2001 7:00:00 AM 28160 C:\WINDOWS\SYSTEM32\dllcache\telephon.cpl
Microsoft Corporation 5/26/2005 3:16:30 AM 174360 C:\WINDOWS\SYSTEM32\dllcache\wuaucpl.cpl

Checking Selected Startup Folders

Checking files in %ALLUSERSPROFILE%\Startup folder...
10/3/2005 10:01:02 AM 1816 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Clean Access Agent.lnk
5/7/2004 9:34:26 AM HS 84 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini
11/10/2004 9:25:02 AM 1672 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterCheck Monitor.LNK
5/12/2004 2:34:48 PM 822 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Remote Update Monitor.lnk

Checking files in %ALLUSERSPROFILE%\Application Data folder...
5/7/2004 5:17:20 AM HS 62 C:\Documents and Settings\All Users\Application Data\desktop.ini

Checking files in %USERPROFILE%\Startup folder...
5/7/2004 9:34:26 AM HS 84 C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\desktop.ini

Checking files in %USERPROFILE%\Application Data folder...
5/7/2004 5:17:20 AM HS 62 C:\Documents and Settings\Administrator\Application Data\desktop.ini
12/12/2005 5:31:28 PM 2235201 C:\Documents and Settings\Administrator\Application Data\Install.dat

Checking Selected Registry Keys

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
SV1 =

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\AVG7 Shell Extension
{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG Free\avgse.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
{09799AFB-AD67-11d1-ABCD-00C04FC30936} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinRAR
{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
Start Menu Pin = %SystemRoot%\system32\SHELL32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\AVG7 Shell Extension
{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG Free\avgse.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\WinRAR
{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Sharing
{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = ntshrui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\WinRAR
{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE}
= %SystemRoot%\system32\SHELL32.dll

[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
&Tip of the Day = %SystemRoot%\System32\shdocvw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
MenuText = Sun Java Console : C:\WINDOWS\system32\msjava.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45}
ButtonText = AIM : C:\Program Files\AIM\aim.exe

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478}
=
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E64-B078-11D0-89E4-00C04FC9E26E}
Explorer Band = %SystemRoot%\System32\shdocvw.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\System32\browseui.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\System32\browseui.dll
{0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links : %SystemRoot%\system32\SHELL32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Webroot Spy Sweeper, Enterprise Edition c:\Program Files\Webroot\Enterprise\Spy Sweeper\SpySweeperTray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
IMAIL Installed = 1
MAPI Installed = 1
MSFS Installed = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
ctfmon.exe C:\WINDOWS\system32\ctfmon.exe

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services
wscsvc 2
MDM 2
Ati HotKey Poller 2
WebrootSpySweeperService 2
WebrootCommAgentService 2
SWEEPSRV.SYS 2
SweepNet 2
CacheMgr 2
AVGEMS 2
Avg7UpdSvc 2
Avg7Alrt 2


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^Microsoft Office OneNote 2003 Quick Launch.lnk
path C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk
backup C:\WINDOWS\pss\Microsoft Office OneNote 2003 Quick Launch.lnkStartup
location Startup
command C:\PROGRA~1\MICROS~2\OFFICE11\ONENOTEM.EXE /tsr
item Microsoft Office OneNote 2003 Quick Launch
path C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk
backup C:\WINDOWS\pss\Microsoft Office OneNote 2003 Quick Launch.lnkStartup
location Startup
command C:\PROGRA~1\MICROS~2\OFFICE11\ONENOTEM.EXE /tsr
item Microsoft Office OneNote 2003 Quick Launch

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office OneNote 2003 Quick Launch.lnk
path C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk
backup C:\WINDOWS\pss\Microsoft Office OneNote 2003 Quick Launch.lnkCommon Startup
location Common Startup
command C:\PROGRA~1\MICROS~2\OFFICE11\ONENOTEM.EXE /tsr
item Microsoft Office OneNote 2003 Quick Launch
path C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk
backup C:\WINDOWS\pss\Microsoft Office OneNote 2003 Quick Launch.lnkCommon Startup
location Common Startup
command C:\PROGRA~1\MICROS~2\OFFICE11\ONENOTEM.EXE /tsr
item Microsoft Office OneNote 2003 Quick Launch

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\04cg09gk.dll
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item RUNDLL32
hkey HKLM
command RUNDLL32.EXE 04cg09gk.dll,b 462012919
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item RUNDLL32
hkey HKLM
command RUNDLL32.EXE 04cg09gk.dll,b 462012919
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AdaptecDirectCD
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item DirectCD
hkey HKLM
command "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item DirectCD
hkey HKLM
command "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\adtech2006
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item adtech2006a
hkey HKLM
command C:\windows\adtech2006a.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item adtech2006a
hkey HKLM
command C:\windows\adtech2006a.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AIM
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item aim
hkey HKCU
command C:\Program Files\AIM\aim.exe -cnetwait.odl
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item aim
hkey HKCU
command C:\Program Files\AIM\aim.exe -cnetwait.odl
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Apoint
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item Apoint
hkey HKLM
command C:\Program Files\Apoint\Apoint.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item Apoint
hkey HKLM
command C:\Program Files\Apoint\Apoint.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ares
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item Ares
hkey HKCU
command "C:\Program Files\Ares Lite Edition\Ares.exe" -h
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item Ares
hkey HKCU
command "C:\Program Files\Ares Lite Edition\Ares.exe" -h
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ATIModeChange
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item Ati2mdxx
hkey HKLM
command Ati2mdxx.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item Ati2mdxx
hkey HKLM
command Ati2mdxx.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ATIPTA
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item atiptaxx
hkey HKLM
command C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item atiptaxx
hkey HKLM
command C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ctfmon.exe
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ctfmon
hkey HKCU
command C:\WINDOWS\system32\ctfmon.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ctfmon
hkey HKCU
command C:\WINDOWS\system32\ctfmon.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Dell AIO Printer A920
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item dlbkbmgr
hkey HKLM
command "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item dlbkbmgr
hkey HKLM
command "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\eDonkey2000
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item eDonkey2000
hkey HKLM
command "C:\Program Files\eDonkey2000\eDonkey2000.exe" -t
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item eDonkey2000
hkey HKLM
command "C:\Program Files\eDonkey2000\eDonkey2000.exe" -t
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\lspins
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item igps
hkey HKLM
command "C:\WINDOWS\system32\igps.exe"
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item igps
hkey HKLM
command "C:\WINDOWS\system32\igps.exe"
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Microsoft tool
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item mstool
hkey HKLM
command C:\WINDOWS\system32\mstool.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item mstool
hkey HKLM
command C:\WINDOWS\system32\mstool.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MSMSGS
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item msmsgs
hkey HKCU
command "C:\Program Files\Messenger\msmsgs.exe" /background
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item msmsgs
hkey HKCU
command "C:\Program Files\Messenger\msmsgs.exe" /background
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\New.net Startup
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item NEWDOT~2
hkey HKLM
command rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item NEWDOT~2
hkey HKLM
command rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\oqzo
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item oqzom
hkey HKCU
command C:\PROGRA~1\COMMON~1\oqzo\oqzom.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item oqzom
hkey HKCU
command C:\PROGRA~1\COMMON~1\oqzo\oqzom.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PayTime
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item paytime
hkey HKLM
command C:\WINDOWS\system32\paytime.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item paytime
hkey HKLM
command C:\WINDOWS\system32\paytime.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Run
key SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
item services
hkey HKCU
command C:\WINDOWS\inet20009\services.exe
inimapping 1
key SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
item services
hkey HKCU
command C:\WINDOWS\inet20009\services.exe
inimapping 1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Shell
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ibm00001
hkey HKCU
command "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ibm00001
hkey HKCU
command "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TBPS
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item TBPS
hkey HKLM
command C:\PROGRA~1\Toolbar\TBPS.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item TBPS
hkey HKLM
command C:\PROGRA~1\Toolbar\TBPS.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\timessquare
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item timessquare
hkey HKLM
command C:\windows\timessquare.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item timessquare
hkey HKLM
command C:\windows\timessquare.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ViewMgr
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ViewMgr
hkey HKLM
command C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ViewMgr
hkey HKLM
command C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\webHancer Agent
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item whAgent
hkey HKLM
command "C:\Program Files\webHancer\Programs\whAgent.exe"
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item whAgent
hkey HKLM
command "C:\Program Files\webHancer\Programs\whAgent.exe"
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\webHancer Survey Companion
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item whSurvey
hkey HKLM
command "C:\Program Files\webHancer\Programs\whSurvey.exe"
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item whSurvey
hkey HKLM
command "C:\Program Files\webHancer\Programs\whSurvey.exe"
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WinampAgent
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item winampa
hkey HKLM
command C:\Program Files\Winamp\winampa.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item winampa
hkey HKLM
command C:\Program Files\Winamp\winampa.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\xp_system
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item services
hkey HKLM
command C:\WINDOWS\inet20009\services.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item services
hkey HKLM
command C:\WINDOWS\inet20009\services.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state
system.ini 0
win.ini 0
bootini 0
services 2
startup 2


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} =
{0DF44EAA-FF21-4412-828E-260A8728E7F1} =


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
dontdisplaylastusername 0
legalnoticecaption
legalnoticetext
shutdownwithoutlogon 1
undockwithoutlogon 1
LogonType 0


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop
NoChangingWallpaper 0
NoComponents 0
NoAddingComponents 0
NoDeletingComponents 0
NoEditingComponents 0
NoHTMLWallPaper 1

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoDriveTypeAutoRun 145
ForceStartMenuLogOff 1
NoActiveDesktop 0
ClassicShell 0
ForceActiveDesktopOn 0

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
PostBootReminder {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll
CDBurn {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll
WebCheck {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\System32\webcheck.dll
SysTray {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\System32\stobject.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
Shell = explorer.exe
System =

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
= crypt32.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
= cryptnet.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
= cscdll.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Explorer
= C:\WINDOWS\system32\q4860elsehq60.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
= wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
= wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
= sclgntfy.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
= WlNotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
= wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
= wlnotify.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
Debugger = ntsd -d

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
AppInit_DLLs


Scan Complete
WinPFind v1.4.1 - Log file written to "WinPFind.Txt" in the WinPFind folder.
Scan completed on 2/5/2006 5:18:04 PM

#11 g3o

g3o
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  

Posted 05 February 2006 - 07:44 PM

Logfile of HijackThis v1.99.1
Scan saved at 7:36:04 PM, on 2/5/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Webroot\Enterprise\Spy Sweeper\SpySweeperTray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Sophos\Remote Update\cachemgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sophos SWEEP for NT\SWNETSUP.EXE
C:\Program Files\Sophos SWEEP for NT\SWEEPSRV.SYS
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Webroot\Enterprise\CommAgent\CommAgent.exe
C:\Program Files\Webroot\Enterprise\Spy Sweeper\SpySweeper.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Administrator\My Documents\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.bridgew.edu/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: 0 UseCustom # Webroot SpySweeper entry
O1 - Hosts: 0 UseDefs # Webroot SpySweeper entry
O1 - Hosts: iefeadsl.com # Webroot SpySweeper entry
O1 - Hosts: 008k.com # Webroot SpySweeper entry
O1 - Hosts: 356563.net # Webroot SpySweeper entry
O1 - Hosts: 75tz.com # Webroot SpySweeper entry
O1 - Hosts: kitasearch.com # Webroot SpySweeper entry
O1 - Hosts: lookfor.com # Webroot SpySweeper entry
O1 - Hosts: look-today.com # Webroot SpySweeper entry
O1 - Hosts: new.8ad.com # Webroot SpySweeper entry
O1 - Hosts: rf104.com # Webroot SpySweeper entry
O1 - Hosts: search-to-find.com # Webroot SpySweeper entry
O1 - Hosts: www.05p.com # Webroot SpySweeper entry
O1 - Hosts: www.6o9.com # Webroot SpySweeper entry
O1 - Hosts: www.ga31.com # Webroot SpySweeper entry
O1 - Hosts: www.v61.com # Webroot SpySweeper entry
O4 - HKLM\..\Run: [Webroot Spy Sweeper, Enterprise Edition] c:\Program Files\Webroot\Enterprise\Spy Sweeper\SpySweeperTray.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [04cg09gk.dll] RUNDLL32.EXE 04cg09gk.dll,b 462012919
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
O4 - HKLM\..\Run: [Microsoft tool] C:\WINDOWS\system32\mstool.exe
O4 - HKLM\..\Run: [eDonkey2000] "C:\Program Files\eDonkey2000\eDonkey2000.exe" -t
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [oqzo] C:\PROGRA~1\COMMON~1\oqzo\oqzom.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares Lite Edition\Ares.exe" -h
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: Clean Access Agent.lnk = C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1136416264421
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Sophos Cache Manager (CacheMgr) - SOPHOS Plc - C:\Program Files\Sophos\Remote Update\cachemgr.exe
O23 - Service: Sophos Anti-Virus Network (SweepNet) - Sophos Plc - C:\Program Files\Sophos SWEEP for NT\SWNETSUP.EXE
O23 - Service: Sophos Anti-Virus (SWEEPSRV.SYS) - Sophos Plc - C:\Program Files\Sophos SWEEP for NT\SWEEPSRV.SYS
O23 - Service: Webroot CommAgent Service (WebrootCommAgentService) - Webroot Software, Inc. - C:\Program Files\Webroot\Enterprise\CommAgent\CommAgent.exe
O23 - Service: Webroot SpySweeper Service (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Enterprise\Spy Sweeper\SpySweeper.exe

#12 Guest_Cretemonster_*

Guest_Cretemonster_*

  • Guests
  • OFFLINE
  •  

Posted 06 February 2006 - 12:50 PM

Please download the Killbox by Option^Explicit.


Restart in Safe Mode-> Open Pocket Killbox-> Copy&Paste each below,one at a time,into Killbox

C:\windows\timessquare.exe
C:\WINDOWS\inet20009
C:\windows\adtech2006a.exe
C:\WINDOWS\IE4 Error Log.txt
C:\WINDOWS\setupapi.log.0.old
C:\WINDOWS\timessquare1.dat
C:\WINDOWS\uniq
C:\WINDOWS\system32\igps.exe
C:\WINDOWS\system32\paytime.exe
C:\WINDOWS\system32\mstool.exe
C:\WINDOWS\system32\04cg09gk.dll
C:\WINDOWS\SYSTEM32\drivers\etc\hosts.new
C:\WINDOWS\SYSTEM32\drivers\etc\hosts.20051212-213454.backup
C:\Documents and Settings\Administrator\Application Data\Install.dat
C:\Program Files\eDonkey2000
C:\Program Files\webHancer
C:\Program Files\Toolbar
C:\Program Files\NewDotNet
C:\Program Files\Common Files\oqzo
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\0PE678RY
C:\Documents and Settings\Administrator\My Documents\!midnight


As you paste each entry in,please place a tick by any of these selections available

"Standard File Kill"
"End Explorer Shell while Killing File"
"Unregister .dll before Deleting"
"Deltree(Include Subdirectories)"


Click the Red Circle with the White X in the Middle to Delete


Open HijackThis-> Click "Do a System Scan Only" and put a check by these but DO NOT hit the Fix Checked button yet

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O4 - HKLM\..\Run: [04cg09gk.dll] RUNDLL32.EXE 04cg09gk.dll,b 462012919

O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s

O4 - HKLM\..\Run: [Microsoft tool] C:\WINDOWS\system32\mstool.exe

O4 - HKLM\..\Run: [eDonkey2000] "C:\Program Files\eDonkey2000\eDonkey2000.exe" -t

O4 - HKCU\..\Run: [oqzo] C:\PROGRA~1\COMMON~1\oqzo\oqzom.exe

Now Make sure ALL WINDOWS and BROWSERS are CLOSED and hit the Fix Checked Button


Restart Normal and Download The Hoster from here:
http://www.funkytoad.com/download/hoster.zip

Right Click the Zip Folder and Select "Extract All"

Open Hoster and Make sure that the "Make Hosts Writable?" button in the upper right corner is Enabled

Click "Back up Host files"

Press "Restore Original Hosts" and press "OK"

Exit the Program.

Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post along with a fresh HijackThis log.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users