Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

My Hijack Log -- (eqadvice,ssk,csrssv & More..)


  • This topic is locked This topic is locked
12 replies to this topic

#1 Dragonchaser

Dragonchaser

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:13 PM

Posted 23 March 2006 - 06:39 PM

Hey BC,

I've tried a bunch of things, nothing's worked.
If anyone can help me, that'd be awesome. :thumbsup:
Thanks,
Mark

This logs pretty bad... lotsa fun stuff in there... :flowers:

Logfile of HijackThis v1.99.1
Scan saved at 4:23:57 PM, on 3/23/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINXP\System32\smss.exe
C:\WINXP\system32\winlogon.exe
C:\WINXP\system32\services.exe
C:\WINXP\system32\lsass.exe
C:\WINXP\system32\svchost.exe
C:\WINXP\System32\svchost.exe
C:\WINXP\system32\spoolsv.exe
C:\WINXP\System32\atievxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINXP\System32\svchost.exe
C:\WINXP\system32\ZONELABS\vsmon.exe
C:\WINXP\Explorer.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINXP\qnclbysA.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Buyertools Reminder\Reminder.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\EQAdvice\EQAdvice.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\My Documents\hijackthis\HijackThis.exe

R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINXP\System32\msdxm.ocx
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [qnclbysA] C:\WINXP\qnclbysA.exe
O4 - HKLM\..\Run: [Microsoft DLL Verifier] csrssv.exe
O4 - HKLM\..\RunServices: [Microsoft DLL Verifier] csrssv.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Simple Star PhotoShow Media Manager] C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Buyertools Reminder] "C:\Program Files\Buyertools Reminder\Reminder.exe" /autorun
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Buyertools Reminder - {27914077-B4D6-4A0E-9763-76B6E9DD9A81} - C:\Program Files\Buyertools Reminder\ReminderIE.exe
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Program Files\Titan Poker\casino.exe
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Program Files\Titan Poker\casino.exe
O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Program Files\Poker.com\poker.exe
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe
O9 - Extra button: River Belle Poker - {83F8B625-1B04-4c35-8BA1-6DB4D7EDBADF} - C:\Program Files\riverbelleMPP\MPPoker.exe
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Program Files\ladbrokesMPP\MPPoker.exe
O9 - Extra button: Fair Poker - {E49E0804-28BE-49ce-9E5F-AA6059B6DC7B} - C:\Program Files\Fair Poker\casino.exe
O9 - Extra 'Tools' menuitem: Fair Poker - {E49E0804-28BE-49ce-9E5F-AA6059B6DC7B} - C:\Program Files\Fair Poker\casino.exe
O9 - Extra button: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: Royal Vegas Poker - {FA4904B4-1FAF-4afd-886C-C19D2297BA62} - C:\Program Files\royalvegasMPP\MPPoker.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com/PhotoUpload/MsnPUpld.cab?10,0,911,0
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Filter: text/html - {994D478A-45D0-4DB4-AE77-288B1E346E99} - C:\Program Files\FCAdvice\FCAdvice.dll
O20 - AppInit_DLLs: Runner.dll
O20 - Winlogon Notify: Reliability - C:\WINXP\system32\n64slgh7164.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINXP\system32\ZONELABS\vsmon.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINXP\qnclbys.exe (file missing)

BC AdBot (Login to Remove)

 


#2 Dragonchaser

Dragonchaser
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:13 PM

Posted 24 March 2006 - 01:35 PM

K, did some work and got rid of what I thought was all the problems and I still get popups in firefox and IE.

So, I dont know what to do next...
Anything you guys can do would be great. :thumbsup:

Here's the new log:

Logfile of HijackThis v1.99.1
Scan saved at 11:31:34 AM, on 3/24/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINXP\System32\smss.exe
C:\WINXP\system32\winlogon.exe
C:\WINXP\system32\services.exe
C:\WINXP\system32\lsass.exe
C:\WINXP\system32\svchost.exe
C:\WINXP\System32\svchost.exe
C:\WINXP\system32\spoolsv.exe
C:\WINXP\system32\rundll32.exe
C:\WINXP\System32\atievxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINXP\System32\svchost.exe
C:\WINXP\Explorer.EXE
C:\WINXP\system32\ZONELABS\vsmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Buyertools Reminder\Reminder.exe
C:\PROGRA~1\BUYERT~1\REMIND~1.EXE
C:\PROGRA~1\BUYERT~1\REMIND~1.EXE
C:\PROGRA~1\BUYERT~1\REMIND~1.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\My Documents\hijackthis\HijackThis.exe

R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINXP\System32\msdxm.ocx
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Simple Star PhotoShow Media Manager] C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Buyertools Reminder] "C:\Program Files\Buyertools Reminder\Reminder.exe" /autorun
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Buyertools Reminder - {27914077-B4D6-4A0E-9763-76B6E9DD9A81} - C:\Program Files\Buyertools Reminder\ReminderIE.exe
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Program Files\Titan Poker\casino.exe
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Program Files\Titan Poker\casino.exe
O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Program Files\Poker.com\poker.exe
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe
O9 - Extra button: River Belle Poker - {83F8B625-1B04-4c35-8BA1-6DB4D7EDBADF} - C:\Program Files\riverbelleMPP\MPPoker.exe
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Program Files\ladbrokesMPP\MPPoker.exe
O9 - Extra button: Fair Poker - {E49E0804-28BE-49ce-9E5F-AA6059B6DC7B} - C:\Program Files\Fair Poker\casino.exe
O9 - Extra 'Tools' menuitem: Fair Poker - {E49E0804-28BE-49ce-9E5F-AA6059B6DC7B} - C:\Program Files\Fair Poker\casino.exe
O9 - Extra button: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: Royal Vegas Poker - {FA4904B4-1FAF-4afd-886C-C19D2297BA62} - C:\Program Files\royalvegasMPP\MPPoker.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com/PhotoUpload/MsnPUpld.cab?10,0,911,0
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: ShellCompatibility - C:\WINXP\system32\lvro0993e.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINXP\system32\ZONELABS\vsmon.exe

Cheers,
Mark

#3 Rawe

Rawe

  • Members
  • 2,363 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:09:13 PM

Posted 25 March 2006 - 09:10 AM

Hello and welcome.. Nice job with the cleaning, even though you have one infection left. :thumbsup:

==

Please download the L2MFix by Shadowwar:
  • Save it to your desktop.
  • Double-click l2mfix.exe
  • Click the Install - button to extract the files.
  • Follow the prompts, then please open the newly added l2mfix folder on your desktop.
  • Double-click the l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log.
Copy the contents of that log and paste it into your next reply. :flowers:

IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until I ask you to!

Note; if you recieve any error messages for CMD or Autoexec.bat>> select option 5 from the l2mfix and once at the site, click on the link that apply to your operating system.

Double-click the file it downloads and extract the files to its predetermined System32 folder.

Hi there, stranger!

#4 Dragonchaser

Dragonchaser
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:13 PM

Posted 25 March 2006 - 02:37 PM

L2MFIX find log 032106
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\App Management]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINXP\\system32\\s0rs0a97ed.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

**********************************************************************************
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{0812ACC9-83A1-1967-F6B0-9A43A13CB1C2}"=""

**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run..."
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People..."
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Web Folders"
"{0006F045-0000-0000-C000-000000000046}"="Microsoft Outlook Custom Icon Handler"
"{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
"{14E6F906-284F-433B-B352-97C7E6F78A45}"=""
"{5D2EB7AA-39ED-43B8-97BF-EF4C11DCDE21}"=""
"{194AE233-D9D7-4F55-9305-568CFD67589E}"=""
"{C4AE4F4E-9698-489F-A930-BB2AF85463B3}"=""
"{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"="AVG7 Shell Extension"
"{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}"="AVG7 Find Extension"
"{2AD354F8-3F3F-4528-8775-FAF592D9962E}"=""
"{2402FFEF-CF07-467F-BEA2-B865EC7BCFB9}"=""
"{7DD7871A-61B0-4E25-9A8E-F2189DEDFF25}"=""
"{CFF3FBE3-8722-484D-B550-910D53E4DDB8}"=""
"{081B5F6F-B1CF-4C4A-A1D9-382669FD681C}"=""
"{8AB5DA25-33D2-4769-96E7-6D94C520D837}"=""
"{A522A49C-935D-419B-A07E-C0562DAE5D85}"=""
"{A0957C1C-3A6F-4C0F-B26D-42C49C3C7499}"=""

**********************************************************************************
HKEY ROOT CLASSIDS:
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{14E6F906-284F-433B-B352-97C7E6F78A45}]
@=""
"IDEx"="ADDR"

[HKEY_CLASSES_ROOT\CLSID\{14E6F906-284F-433B-B352-97C7E6F78A45}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{14E6F906-284F-433B-B352-97C7E6F78A45}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{14E6F906-284F-433B-B352-97C7E6F78A45}\InprocServer32]
@="C:\\WINXP\\system32\\sgreamci.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{5D2EB7AA-39ED-43B8-97BF-EF4C11DCDE21}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{5D2EB7AA-39ED-43B8-97BF-EF4C11DCDE21}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{5D2EB7AA-39ED-43B8-97BF-EF4C11DCDE21}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{5D2EB7AA-39ED-43B8-97BF-EF4C11DCDE21}\InprocServer32]
@="C:\\WINXP\\system32\\mrasn1.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{194AE233-D9D7-4F55-9305-568CFD67589E}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{194AE233-D9D7-4F55-9305-568CFD67589E}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{194AE233-D9D7-4F55-9305-568CFD67589E}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{194AE233-D9D7-4F55-9305-568CFD67589E}\InprocServer32]
@="C:\\WINXP\\system32\\myc40u.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{C4AE4F4E-9698-489F-A930-BB2AF85463B3}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{C4AE4F4E-9698-489F-A930-BB2AF85463B3}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{C4AE4F4E-9698-489F-A930-BB2AF85463B3}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{C4AE4F4E-9698-489F-A930-BB2AF85463B3}\InprocServer32]
@="C:\\WINXP\\system32\\sarenacm.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{2AD354F8-3F3F-4528-8775-FAF592D9962E}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{2AD354F8-3F3F-4528-8775-FAF592D9962E}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{2AD354F8-3F3F-4528-8775-FAF592D9962E}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{2AD354F8-3F3F-4528-8775-FAF592D9962E}\InprocServer32]
@="C:\\WINXP\\system32\\sggina.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{2402FFEF-CF07-467F-BEA2-B865EC7BCFB9}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{2402FFEF-CF07-467F-BEA2-B865EC7BCFB9}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{2402FFEF-CF07-467F-BEA2-B865EC7BCFB9}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{2402FFEF-CF07-467F-BEA2-B865EC7BCFB9}\InprocServer32]
@="C:\\WINXP\\system32\\ohbcp32r.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{7DD7871A-61B0-4E25-9A8E-F2189DEDFF25}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7DD7871A-61B0-4E25-9A8E-F2189DEDFF25}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7DD7871A-61B0-4E25-9A8E-F2189DEDFF25}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7DD7871A-61B0-4E25-9A8E-F2189DEDFF25}\InprocServer32]
@="C:\\WINXP\\system32\\tkddd.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{CFF3FBE3-8722-484D-B550-910D53E4DDB8}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{CFF3FBE3-8722-484D-B550-910D53E4DDB8}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{CFF3FBE3-8722-484D-B550-910D53E4DDB8}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{CFF3FBE3-8722-484D-B550-910D53E4DDB8}\InprocServer32]
@="C:\\WINXP\\system32\\rzipxmib.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{081B5F6F-B1CF-4C4A-A1D9-382669FD681C}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{081B5F6F-B1CF-4C4A-A1D9-382669FD681C}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{081B5F6F-B1CF-4C4A-A1D9-382669FD681C}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{081B5F6F-B1CF-4C4A-A1D9-382669FD681C}\InprocServer32]
@="C:\\WINXP\\system32\\maimsg.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{8AB5DA25-33D2-4769-96E7-6D94C520D837}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8AB5DA25-33D2-4769-96E7-6D94C520D837}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8AB5DA25-33D2-4769-96E7-6D94C520D837}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8AB5DA25-33D2-4769-96E7-6D94C520D837}\InprocServer32]
@="C:\\WINXP\\system32\\ozengl32.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{A522A49C-935D-419B-A07E-C0562DAE5D85}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A522A49C-935D-419B-A07E-C0562DAE5D85}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A522A49C-935D-419B-A07E-C0562DAE5D85}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A522A49C-935D-419B-A07E-C0562DAE5D85}\InprocServer32]
@="C:\\WINXP\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{A0957C1C-3A6F-4C0F-B26D-42C49C3C7499}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A0957C1C-3A6F-4C0F-B26D-42C49C3C7499}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A0957C1C-3A6F-4C0F-B26D-42C49C3C7499}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A0957C1C-3A6F-4C0F-B26D-42C49C3C7499}\InprocServer32]
@="C:\\WINXP\\system32\\uiandlg.dll"
"ThreadingModel"="Apartment"

**********************************************************************************
Files Found are not all bad files:

C:\WINXP\SYSTEM32\
tkddd.dll Fri Mar 24 2006 1:14:22p ..S.R 236,161 230.63 K
sggina.dll Fri Mar 24 2006 10:27:00a ..S.R 234,541 229.04 K
ohbcp32r.dll Fri Mar 24 2006 1:10:48p ..S.R 236,161 230.63 K
rzipxmib.dll Fri Mar 24 2006 1:17:18p ..S.R 237,111 231.55 K
vsdata.dll Sun Feb 19 2006 6:26:20p A.... 83,720 81.76 K
hrnu05~1.dll Fri Mar 24 2006 12:29:06p ..S.R 237,116 231.56 K
vsutil.dll Sun Feb 19 2006 6:27:02p A.... 382,728 373.76 K
vsmonapi.dll Sun Feb 19 2006 6:26:42p A.... 104,208 101.77 K
vspubapi.dll Sun Feb 19 2006 6:26:46p A.... 227,088 221.77 K
vsinit.dll Sun Feb 19 2006 6:26:32p A.... 141,064 137.76 K
vsxml.dll Sun Feb 19 2006 6:27:10p A.... 100,104 97.76 K
vsregexp.dll Sun Feb 19 2006 6:26:50p A.... 71,440 69.77 K
zlcomm.dll Sun Feb 19 2006 6:27:32p A.... 79,624 77.76 K
zlcommdb.dll Sun Feb 19 2006 6:27:36p A.... 71,440 69.77 K
maimsg.dll Fri Mar 24 2006 1:20:42p ..S.R 237,250 231.69 K
q6rqlg~1.dll Fri Mar 24 2006 10:15:42a ..S.R 234,660 229.16 K
lvpo09~1.dll Fri Mar 24 2006 12:51:44p ..S.R 236,745 231.20 K
lvlm09~1.dll Fri Mar 24 2006 4:21:22p ..S.R 233,578 228.10 K
r06u0a~1.dll Fri Mar 24 2006 11:39:42a ..S.R 236,796 231.25 K
__dele~1.dll Fri Mar 24 2006 1:02:14p A.... 236,161 230.63 K
l0l60a~1.dll Fri Mar 24 2006 6:37:34p ..S.R 237,289 231.73 K
s0rs0a~1.dll Fri Mar 24 2006 4:00:10p ..S.R 237,289 231.73 K
__dele~2.dll Fri Mar 24 2006 6:40:26p A.... 237,289 231.73 K
runner.dll Wed Feb 15 2006 11:07:42a A.... 61,440 60.00 K

24 items found: 24 files (12 H/S), 0 directories.
Total of file sizes: 4,631,003 bytes 4.41 M
Locate .tmp files:

C:\WINXP\SYSTEM32\
mfc42d~1.tmp Thu Feb 2 2006 1:48:58p A.... 995,383 972.05 K

1 item found: 1 file, 0 directories.
Total of file sizes: 995,383 bytes 972.05 K
**********************************************************************************
Directory Listing of system files:
Volume in drive C is LAPTOP
Volume Serial Number is 0745-15F0

Directory of C:\WINXP\System32

03/24/2006 06:37 PM 237,289 l0l60a3sed.dll
03/24/2006 04:21 PM 233,578 lvlm0931e.dll
03/24/2006 04:00 PM 237,289 s0rs0a97ed.dll
03/24/2006 01:20 PM 237,250 maimsg.dll
03/24/2006 01:17 PM 237,111 rzipxmib.dll
03/24/2006 01:14 PM 236,161 tkddd.dll
03/24/2006 01:10 PM 236,161 ohbcp32r.dll
03/24/2006 12:51 PM 236,745 lvpo0973e.dll
03/24/2006 12:29 PM 237,116 hrnu0559e.dll
03/24/2006 11:39 AM 236,796 r06u0aj9edo.dll
03/24/2006 10:27 AM 234,541 sggina.dll
03/24/2006 10:15 AM 234,660 q6rqlg9516.dll
01/09/2006 09:28 PM <DIR> Microsoft
01/09/2006 06:00 PM <DIR> dllcache
12 File(s) 2,834,697 bytes
2 Dir(s) 9,505,062,912 bytes free
b

#5 Rawe

Rawe

  • Members
  • 2,363 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:09:13 PM

Posted 25 March 2006 - 02:55 PM

Before fixing there is something you must do:
  • Print this, or save as text into a convenient location.
  • Click Start -> Run and type in: services.msc
  • Check that the following services are running and that their startup is set to automatic:
  • Seclogon, or Secondary logon service
  • Next your machine needs to be offline, manually disconnect the network cable if necessary.
  • Your antivirus, and every other security software MUST be disabled.
==

Close any programs you have open since this step requires a reboot.

From the l2mfix folder on your desktop, double-click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing enter, then press any key to reboot your computer. After a reboot, your desktop and icons will appear, then disappear (this is normal). L2mfix will continue to scan your computer and when it's finished, notepad will open with a log. Reconnect back to the Internet. Copy the contents of that log and paste it back into this thread, along with a fresh HijackThis log, and we'll clean up what's left. :thumbsup:

IMPORTANT: Do NOT run any other files in the l2mfix folder unless you are asked to do so!
Hi there, stranger!

#6 Dragonchaser

Dragonchaser
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:13 PM

Posted 25 March 2006 - 03:21 PM

L2mfix 032106
Creating Account.
The command completed successfully.

Adding Administrative privleges.
The command completed successfully.
Checking for L2MFix account(0=no 1=yes):
1
Granting SeDebugPrivilege to L2MFIX ... successful

Running From:
C:\WINXP\system32

Killing Processes!

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 596 'smss.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 684 'winlogon.exe'
Killing PID 684 'winlogon.exe'
Killing PID 684 'winlogon.exe'
Killing PID 684 'winlogon.exe'
Killing PID 684 'winlogon.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 1884 'explorer.exe'
Killing PID 1884 'explorer.exe'
Killing PID 1884 'explorer.exe'
Killing PID 1884 'explorer.exe'
Killing PID 1884 'explorer.exe'
Killing PID 1884 'explorer.exe'
Killing PID 1884 'explorer.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 1388 'rundll32.exe'
Restoring Sedebugprivilege:
Granting SeDebugPrivilege to Administrators ... successful

Scanning First Pass. Please Wait!

First Pass Completed

Second Pass Scanning

Second pass Completed!
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
Deleting: C:\WINXP\system32\__delete_on_reboot__ioetpp.dll
Successfully Deleted: C:\WINXP\system32\__delete_on_reboot__ioetpp.dll
Deleting: C:\WINXP\system32\__delete_on_reboot__uiandlg.dll
Successfully Deleted: C:\WINXP\system32\__delete_on_reboot__uiandlg.dll
Deleting: C:\WINXP\system32\hrnu0559e.dll
Successfully Deleted: C:\WINXP\system32\hrnu0559e.dll
Deleting: C:\WINXP\system32\l0l60a3sed.dll
Successfully Deleted: C:\WINXP\system32\l0l60a3sed.dll
Deleting: C:\WINXP\system32\lvlm0931e.dll
Successfully Deleted: C:\WINXP\system32\lvlm0931e.dll
Deleting: C:\WINXP\system32\lvpo0973e.dll
Successfully Deleted: C:\WINXP\system32\lvpo0973e.dll
Deleting: C:\WINXP\system32\maimsg.dll
Successfully Deleted: C:\WINXP\system32\maimsg.dll
Deleting: C:\WINXP\system32\ohbcp32r.dll
Successfully Deleted: C:\WINXP\system32\ohbcp32r.dll
Deleting: C:\WINXP\system32\q6rqlg9516.dll
Successfully Deleted: C:\WINXP\system32\q6rqlg9516.dll
Deleting: C:\WINXP\system32\r06u0aj9edo.dll
Successfully Deleted: C:\WINXP\system32\r06u0aj9edo.dll
Deleting: C:\WINXP\system32\rzipxmib.dll
Successfully Deleted: C:\WINXP\system32\rzipxmib.dll
Deleting: C:\WINXP\system32\s0rs0a97ed.dll
Successfully Deleted: C:\WINXP\system32\s0rs0a97ed.dll
Deleting: C:\WINXP\system32\sggina.dll
Successfully Deleted: C:\WINXP\system32\sggina.dll
Deleting: C:\WINXP\system32\tkddd.dll
Successfully Deleted: C:\WINXP\system32\tkddd.dll

msg11?.dll
0 file(s) copied.
Desktop.ini sucessfully removed




Restoring Windows Update Certificates.:

The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\App Management]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINXP\\system32\\s0rs0a97ed.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


The following are the files found:
****************************************************************************
C:\WINXP\system32\__delete_on_reboot__ioetpp.dll
C:\WINXP\system32\__delete_on_reboot__uiandlg.dll
C:\WINXP\system32\hrnu0559e.dll
C:\WINXP\system32\l0l60a3sed.dll
C:\WINXP\system32\lvlm0931e.dll
C:\WINXP\system32\lvpo0973e.dll
C:\WINXP\system32\maimsg.dll
C:\WINXP\system32\ohbcp32r.dll
C:\WINXP\system32\q6rqlg9516.dll
C:\WINXP\system32\r06u0aj9edo.dll
C:\WINXP\system32\rzipxmib.dll
C:\WINXP\system32\s0rs0a97ed.dll
C:\WINXP\system32\sggina.dll
C:\WINXP\system32\tkddd.dll

Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{14E6F906-284F-433B-B352-97C7E6F78A45}]
@=""
"IDEx"="ADDR"

[HKEY_CLASSES_ROOT\CLSID\{14E6F906-284F-433B-B352-97C7E6F78A45}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{14E6F906-284F-433B-B352-97C7E6F78A45}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{14E6F906-284F-433B-B352-97C7E6F78A45}\InprocServer32]
@="C:\\WINXP\\system32\\sgreamci.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{5D2EB7AA-39ED-43B8-97BF-EF4C11DCDE21}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{5D2EB7AA-39ED-43B8-97BF-EF4C11DCDE21}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{5D2EB7AA-39ED-43B8-97BF-EF4C11DCDE21}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{5D2EB7AA-39ED-43B8-97BF-EF4C11DCDE21}\InprocServer32]
@="C:\\WINXP\\system32\\mrasn1.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{194AE233-D9D7-4F55-9305-568CFD67589E}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{194AE233-D9D7-4F55-9305-568CFD67589E}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{194AE233-D9D7-4F55-9305-568CFD67589E}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{194AE233-D9D7-4F55-9305-568CFD67589E}\InprocServer32]
@="C:\\WINXP\\system32\\myc40u.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{C4AE4F4E-9698-489F-A930-BB2AF85463B3}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{C4AE4F4E-9698-489F-A930-BB2AF85463B3}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{C4AE4F4E-9698-489F-A930-BB2AF85463B3}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{C4AE4F4E-9698-489F-A930-BB2AF85463B3}\InprocServer32]
@="C:\\WINXP\\system32\\sarenacm.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{2AD354F8-3F3F-4528-8775-FAF592D9962E}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{2AD354F8-3F3F-4528-8775-FAF592D9962E}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{2AD354F8-3F3F-4528-8775-FAF592D9962E}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{2AD354F8-3F3F-4528-8775-FAF592D9962E}\InprocServer32]
@="C:\\WINXP\\system32\\sggina.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{2402FFEF-CF07-467F-BEA2-B865EC7BCFB9}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{2402FFEF-CF07-467F-BEA2-B865EC7BCFB9}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{2402FFEF-CF07-467F-BEA2-B865EC7BCFB9}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{2402FFEF-CF07-467F-BEA2-B865EC7BCFB9}\InprocServer32]
@="C:\\WINXP\\system32\\ohbcp32r.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{7DD7871A-61B0-4E25-9A8E-F2189DEDFF25}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7DD7871A-61B0-4E25-9A8E-F2189DEDFF25}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7DD7871A-61B0-4E25-9A8E-F2189DEDFF25}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7DD7871A-61B0-4E25-9A8E-F2189DEDFF25}\InprocServer32]
@="C:\\WINXP\\system32\\tkddd.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{CFF3FBE3-8722-484D-B550-910D53E4DDB8}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{CFF3FBE3-8722-484D-B550-910D53E4DDB8}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{CFF3FBE3-8722-484D-B550-910D53E4DDB8}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{CFF3FBE3-8722-484D-B550-910D53E4DDB8}\InprocServer32]
@="C:\\WINXP\\system32\\rzipxmib.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{081B5F6F-B1CF-4C4A-A1D9-382669FD681C}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{081B5F6F-B1CF-4C4A-A1D9-382669FD681C}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{081B5F6F-B1CF-4C4A-A1D9-382669FD681C}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{081B5F6F-B1CF-4C4A-A1D9-382669FD681C}\InprocServer32]
@="C:\\WINXP\\system32\\maimsg.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{8AB5DA25-33D2-4769-96E7-6D94C520D837}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8AB5DA25-33D2-4769-96E7-6D94C520D837}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8AB5DA25-33D2-4769-96E7-6D94C520D837}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8AB5DA25-33D2-4769-96E7-6D94C520D837}\InprocServer32]
@="C:\\WINXP\\system32\\ozengl32.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{A522A49C-935D-419B-A07E-C0562DAE5D85}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A522A49C-935D-419B-A07E-C0562DAE5D85}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A522A49C-935D-419B-A07E-C0562DAE5D85}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A522A49C-935D-419B-A07E-C0562DAE5D85}\InprocServer32]
@="C:\\WINXP\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{A0957C1C-3A6F-4C0F-B26D-42C49C3C7499}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A0957C1C-3A6F-4C0F-B26D-42C49C3C7499}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A0957C1C-3A6F-4C0F-B26D-42C49C3C7499}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A0957C1C-3A6F-4C0F-B26D-42C49C3C7499}\InprocServer32]
@="C:\\WINXP\\system32\\uiandlg.dll"
"ThreadingModel"="Apartment"

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{14E6F906-284F-433B-B352-97C7E6F78A45}"=-
"{5D2EB7AA-39ED-43B8-97BF-EF4C11DCDE21}"=-
"{194AE233-D9D7-4F55-9305-568CFD67589E}"=-
"{C4AE4F4E-9698-489F-A930-BB2AF85463B3}"=-
"{2AD354F8-3F3F-4528-8775-FAF592D9962E}"=-
"{2402FFEF-CF07-467F-BEA2-B865EC7BCFB9}"=-
"{7DD7871A-61B0-4E25-9A8E-F2189DEDFF25}"=-
"{CFF3FBE3-8722-484D-B550-910D53E4DDB8}"=-
"{081B5F6F-B1CF-4C4A-A1D9-382669FD681C}"=-
"{8AB5DA25-33D2-4769-96E7-6D94C520D837}"=-
"{A522A49C-935D-419B-A07E-C0562DAE5D85}"=-
"{A0957C1C-3A6F-4C0F-B26D-42C49C3C7499}"=-
[-HKEY_CLASSES_ROOT\CLSID\{14E6F906-284F-433B-B352-97C7E6F78A45}]
[-HKEY_CLASSES_ROOT\CLSID\{5D2EB7AA-39ED-43B8-97BF-EF4C11DCDE21}]
[-HKEY_CLASSES_ROOT\CLSID\{194AE233-D9D7-4F55-9305-568CFD67589E}]
[-HKEY_CLASSES_ROOT\CLSID\{C4AE4F4E-9698-489F-A930-BB2AF85463B3}]
[-HKEY_CLASSES_ROOT\CLSID\{2AD354F8-3F3F-4528-8775-FAF592D9962E}]
[-HKEY_CLASSES_ROOT\CLSID\{2402FFEF-CF07-467F-BEA2-B865EC7BCFB9}]
[-HKEY_CLASSES_ROOT\CLSID\{7DD7871A-61B0-4E25-9A8E-F2189DEDFF25}]
[-HKEY_CLASSES_ROOT\CLSID\{CFF3FBE3-8722-484D-B550-910D53E4DDB8}]
[-HKEY_CLASSES_ROOT\CLSID\{081B5F6F-B1CF-4C4A-A1D9-382669FD681C}]
[-HKEY_CLASSES_ROOT\CLSID\{8AB5DA25-33D2-4769-96E7-6D94C520D837}]
[-HKEY_CLASSES_ROOT\CLSID\{A522A49C-935D-419B-A07E-C0562DAE5D85}]
[-HKEY_CLASSES_ROOT\CLSID\{A0957C1C-3A6F-4C0F-B26D-42C49C3C7499}]
REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
****************************************************************************
Desktop.ini Contents:
****************************************************************************
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
****************************************************************************
Checking for L2MFix account(0=no 1=yes):
0
Zipping up files for submission:
adding: dlls/__delete_on_reboot__ioetpp.dll (deflated 5%)
adding: dlls/__delete_on_reboot__uiandlg.dll (deflated 6%)
adding: dlls/hrnu0559e.dll (deflated 6%)
adding: dlls/l0l60a3sed.dll (deflated 6%)
adding: dlls/lvlm0931e.dll (deflated 4%)
adding: dlls/lvpo0973e.dll (deflated 6%)
adding: dlls/maimsg.dll (deflated 6%)
adding: dlls/ohbcp32r.dll (deflated 5%)
adding: dlls/q6rqlg9516.dll (deflated 4%)
adding: dlls/r06u0aj9edo.dll (deflated 5%)
adding: dlls/rzipxmib.dll (deflated 6%)
adding: dlls/s0rs0a97ed.dll (deflated 6%)
adding: dlls/sggina.dll (deflated 4%)
adding: dlls/tkddd.dll (deflated 5%)
adding: backregs/notibac.reg (deflated 87%)
adding: backregs/shell.reg (deflated 73%)
adding: backregs/14E6F906-284F-433B-B352-97C7E6F78A45.reg (deflated 69%)
adding: backregs/5D2EB7AA-39ED-43B8-97BF-EF4C11DCDE21.reg (deflated 70%)
adding: backregs/194AE233-D9D7-4F55-9305-568CFD67589E.reg (deflated 70%)
adding: backregs/C4AE4F4E-9698-489F-A930-BB2AF85463B3.reg (deflated 70%)
adding: backregs/2AD354F8-3F3F-4528-8775-FAF592D9962E.reg (deflated 70%)
adding: backregs/2402FFEF-CF07-467F-BEA2-B865EC7BCFB9.reg (deflated 70%)
adding: backregs/7DD7871A-61B0-4E25-9A8E-F2189DEDFF25.reg (deflated 70%)
adding: backregs/CFF3FBE3-8722-484D-B550-910D53E4DDB8.reg (deflated 70%)
adding: backregs/081B5F6F-B1CF-4C4A-A1D9-382669FD681C.reg (deflated 70%)
adding: backregs/8AB5DA25-33D2-4769-96E7-6D94C520D837.reg (deflated 70%)
adding: backregs/A522A49C-935D-419B-A07E-C0562DAE5D85.reg (deflated 70%)
adding: backregs/A0957C1C-3A6F-4C0F-B26D-42C49C3C7499.reg (deflated 70%)

HiJackThis Log:

Logfile of HijackThis v1.99.1
Scan saved at 1:20:44 PM, on 3/25/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINXP\System32\smss.exe
C:\WINXP\system32\winlogon.exe
C:\WINXP\system32\services.exe
C:\WINXP\system32\lsass.exe
C:\WINXP\system32\svchost.exe
C:\WINXP\System32\svchost.exe
C:\WINXP\Explorer.EXE
C:\WINXP\system32\spoolsv.exe
C:\WINXP\System32\atievxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINXP\System32\svchost.exe
C:\WINXP\system32\ZONELABS\vsmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\My Documents\hijackthis\HijackThis.exe

O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Simple Star PhotoShow Media Manager] C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Buyertools Reminder] "C:\Program Files\Buyertools Reminder\Reminder.exe" /autorun
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Buyertools Reminder - {27914077-B4D6-4A0E-9763-76B6E9DD9A81} - C:\Program Files\Buyertools Reminder\ReminderIE.exe
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Program Files\Titan Poker\casino.exe
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Program Files\Titan Poker\casino.exe
O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Program Files\Poker.com\poker.exe
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe
O9 - Extra button: River Belle Poker - {83F8B625-1B04-4c35-8BA1-6DB4D7EDBADF} - C:\Program Files\riverbelleMPP\MPPoker.exe
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Program Files\ladbrokesMPP\MPPoker.exe
O9 - Extra button: Fair Poker - {E49E0804-28BE-49ce-9E5F-AA6059B6DC7B} - C:\Program Files\Fair Poker\casino.exe
O9 - Extra 'Tools' menuitem: Fair Poker - {E49E0804-28BE-49ce-9E5F-AA6059B6DC7B} - C:\Program Files\Fair Poker\casino.exe
O9 - Extra button: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: Royal Vegas Poker - {FA4904B4-1FAF-4afd-886C-C19D2297BA62} - C:\Program Files\royalvegasMPP\MPPoker.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com/PhotoUpload/MsnPUpld.cab?10,0,911,0
O20 - Winlogon Notify: App Management - C:\WINXP\system32\s0rs0a97ed.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINXP\system32\ZONELABS\vsmon.exe

Voila!

#7 Rawe

Rawe

  • Members
  • 2,363 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:09:13 PM

Posted 25 March 2006 - 03:36 PM

Run a scan with HijackThis and check the following object for removal:

O20 - Winlogon Notify: App Management - C:\WINXP\system32\s0rs0a97ed.dll (file missing)

Now close ALL other open windows except for HijackThis and hit FIX CHECKED.

==

Do you play online Poker a lot? :thumbsup: There's quite a few installed games there..

==

Please go HERE to run Panda's ActiveScan
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open...click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report. :flowers:

Hi there, stranger!

#8 Dragonchaser

Dragonchaser
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:13 PM

Posted 25 March 2006 - 08:57 PM

I do play a lot of poker, usually 4-5 hrs a day.
It pays the bills right now.
I play on 12 different sites.

Here's the Panda log:


Incident Status Location

Spyware:spyware/surfsidekick Not disinfected C:\Documents and Settings\Marky\Local Settings\Temporary Internet Files\Ssk.log
Adware:adware/vaultsearch Not disinfected C:\PROGRAM FILES\COMMON FILES\VCClient
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Marky\Application Data\Mozilla\Firefox\Profiles\a219dpme.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Marky\Application Data\Mozilla\Firefox\Profiles\a219dpme.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Marky\Application Data\Mozilla\Firefox\Profiles\a219dpme.default\cookies.txt[.as-us.falkag.net/]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Marky\Application Data\Mozilla\Firefox\Profiles\a219dpme.default\cookies.txt[.adopt.hbmediapro.com/]
Spyware:Cookie/Advnt Not disinfected C:\Documents and Settings\Marky\Application Data\Mozilla\Firefox\Profiles\a219dpme.default\cookies.txt[www.advnt01.com/]
Spyware:Cookie/Rn11 Not disinfected C:\Documents and Settings\Marky\Application Data\Mozilla\Firefox\Profiles\a219dpme.default\cookies.txt[.rn11.com/]
Spyware:Cookie/Clickbank Not disinfected C:\Documents and Settings\Marky\Application Data\Mozilla\Firefox\Profiles\a219dpme.default\cookies.txt[.clickbank.net/]
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Marky\Application Data\Mozilla\Firefox\Profiles\a219dpme.default\cookies.txt[.888.com/]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Marky\Application Data\Mozilla\Firefox\Profiles\a219dpme.default\cookies.txt[.apmebf.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Marky\Application Data\Mozilla\Firefox\Profiles\a219dpme.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Marky\Application Data\Mozilla\Firefox\Profiles\a219dpme.default\cookies.txt[.belnk.com/]
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Marky\Application Data\Mozilla\Firefox\Profiles\a219dpme.default\cookies.txt[.bravenet.com/]
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Marky\Application Data\Mozilla\Firefox\Profiles\a219dpme.default\cookies.txt[.errorsafe.com/]
Spyware:Cookie/MediaTickets Not disinfected C:\Documents and Settings\Marky\Application Data\Mozilla\Firefox\Profiles\a219dpme.default\cookies.txt[.kinghost.com/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Marky\Application Data\Mozilla\Firefox\Profiles\a219dpme.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/MetriWeb Not disinfected C:\Documents and Settings\Marky\Application Data\Mozilla\Firefox\Profiles\a219dpme.default\cookies.txt[.metriweb.be/]
Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\Marky\Application Data\Mozilla\Firefox\Profiles\a219dpme.default\cookies.txt[.offeroptimizer.com/]
Spyware:Cookie/AspinallsOnlineCasino Not disinfected C:\Documents and Settings\Marky\Application Data\Mozilla\Firefox\Profiles\a219dpme.default\cookies.txt[.pacificpoker.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Marky\Application Data\Mozilla\Firefox\Profiles\a219dpme.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Marky\Application Data\Mozilla\Firefox\Profiles\a219dpme.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Marky\Application Data\Mozilla\Firefox\Profiles\a219dpme.default\cookies.txt[.zedo.com/]
Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Marky\Application Data\Mozilla\Firefox\Profiles\a219dpme.default\cookies.txt[landing.domainsponsor.com/]
Potentially unwanted tool:Application/Processor Not disinfected C:\Program Files\Mozilla Firefox\l2mfix\Process.exe
Adware:Adware/Deskwizz Not disinfected C:\WINXP\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\RT1WT3FY\DR140306[1].exe
Adware:Adware/CommAd Not disinfected C:\WINXP\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\RT1WT3FY\installer[1].exe
Adware:Adware/ConsumerAlertSystem Not disinfected C:\WINXP\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\E8REZGGY\WinFrgn[1].exe
Adware:Adware/ISearch Not disinfected C:\WINXP\TWFya3k\nqIVua4.vbs
Adware:Adware/ConsumerAlertSystem Not disinfected C:\WINXP\qnclbysA.exe
Adware:Adware/DigInk Not disinfected C:\WINXP\pf78bb.exe
Virus:Trj/sosmyn.A Disinfected C:\WINXP\errorhandler.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Marky\Local Settings\Application Data\Mozilla\Firefox\Profiles\a219dpme.default\Cache\C16DFCFBd01[Process.exe]
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix\Process.exe
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix\dlls\__delete_on_reboot__ioetpp.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix\dlls\__delete_on_reboot__uiandlg.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix\dlls\hrnu0559e.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix\dlls\l0l60a3sed.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix\dlls\lvlm0931e.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix\dlls\lvpo0973e.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix\dlls\maimsg.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix\dlls\ohbcp32r.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix\dlls\q6rqlg9516.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix\dlls\r06u0aj9edo.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix\dlls\rzipxmib.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix\dlls\s0rs0a97ed.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix\dlls\sggina.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix\dlls\tkddd.dll
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix\backup.zip[__delete_on_reboot__ioetpp.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix\backup.zip[__delete_on_reboot__uiandlg.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix\backup.zip[hrnu0559e.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix\backup.zip[l0l60a3sed.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix\backup.zip[lvlm0931e.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix\backup.zip[lvpo0973e.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix\backup.zip[maimsg.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix\backup.zip[ohbcp32r.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix\backup.zip[q6rqlg9516.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix\backup.zip[r06u0aj9edo.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix\backup.zip[rzipxmib.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix\backup.zip[s0rs0a97ed.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix\backup.zip[sggina.dll]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix\backup.zip[tkddd.dll]
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Marky\Desktop\l2mfix.exe[Process.exe]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Marky\Application Data\Mozilla\Firefox\Profiles\a219dpme.default\cookies.txt[]
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\5skd7mgk.default\cookies.txt[]

#9 Rawe

Rawe

  • Members
  • 2,363 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:09:13 PM

Posted 26 March 2006 - 06:25 AM

Nice job. :thumbsup:

Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 only.Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

==

How's the system running now?
Hi there, stranger!

#10 Dragonchaser

Dragonchaser
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:13 PM

Posted 26 March 2006 - 03:30 PM

:thumbsup: Works great! No More pop-ups!
Thanks a lot.

Just couple questions:
What protection is best to have running?
I have SpywareGuard, ZoneAlarm, SpyBot-SD, Ewido & AVG.
I guess I don't need all those running at once, right?
How do I know my system is completely cleaned?

#11 Rawe

Rawe

  • Members
  • 2,363 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:09:13 PM

Posted 27 March 2006 - 06:42 AM

I have SpywareGuard, ZoneAlarm, SpyBot-SD, Ewido & AVG.

Nope.. You definately don't need all of them. I suggest leaving SpyBot S&D's protection, but uninstall SpywareGuard -- it has REALLY old definitions, but SpyBot S&D is really up-to-date. As for Ewido, I'd suggest uninstalling that aswell, the Ewido guard won't work after 14 days is gone on the trial anyway. You could leave it as an on-demand scanner though. AVG & ZoneAlarm - definately.

Glad I was able to help. :thumbsup:

==


First priority: Install Service Pack 2 by visiting WindowsUpdates. After you have installed it, reboot, download & install ALL the available critical updates. Then some more preventive maintenance:

Please read here how to clear old restore points and create a new one.

Stand Up and Be Counted ---> Malware Complaints <--- where you can make difference!

The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.

Here's some tips for future to prevent spyware;

Detect and Remove Programs:
  • How to use Ad-Aware to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Ad-Aware.
  • How to use Spybot to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Spybot. Similar to Ad-Aware, I strongly recommend both to catch most spyware.
Prevention Programs:
  • Spywareblaster <= SpywareBlaster will prevent spyware from being installed. (My favourite)
  • Spywareguard <= SpywareGuard offers realtime protection from spyware installation attempts.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
Other necessary Programs:
  • AntiVirus Program <= An AntiVirus program is a must! Whether it is a free version like AVG or Anti-Vir, or a shareware version like Norton or Kaspersky, this is a must have.
  • Firewall <= A firewall is definatley a must have. Two good free versions are Sygate and ZoneLabs.
  • More Secure Browser <= Internet Explorer is not the most secure and best browser. There are safer and better alternatives available. I recommend Firefox.
And also see TonyKlein's good advice;
So how did I get infected in the first place? (My favourite)
Hi there, stranger!

#12 Dragonchaser

Dragonchaser
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:13 PM

Posted 27 March 2006 - 12:41 PM

Hey Rawe,
Thanks again,
She runs great.
Cheers,
Mark

#13 Rawe

Rawe

  • Members
  • 2,363 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:09:13 PM

Posted 28 March 2006 - 12:49 AM

You're welcome.

Since this issue appears to be resolved, this Topic has been closed. Should you need this Topic reopened, please PM a Staff member with the address of this thread. :thumbsup:
Hi there, stranger!




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users