Buffer overflow virus
Solved/Closed
gdf
Posted messages
22
Status
Membre
-
abdou -
abdou -
Hello, I need help solving a blockage issue due to a buffer overflow detected by Virus Scan Enterprise 8.0
Message type: c\:windows\system32\svchost.exe:: loadlibrarya
Thank you in advance
gdf
Message type: c\:windows\system32\svchost.exe:: loadlibrarya
Thank you in advance
gdf
34 réponses
- 1
- 2
Suivant
Hello
download HijackThis here:
http://telechargement.zebulon.fr/138-hijackthis-1991.html
Unzip it into a designated folder.
For example C:\hijackthis < Make sure to save it in c: !
Demo: (Thanks to Balltrap34 for this production)
http://pageperso.aol.fr/balltrap34/Hijenr.gif
Launch it then:
click on "do a system scan and save logfile" (see demo)
copy and paste the entire log on the forum
Demo: (Thanks to Balltrap34 for this production)
http://pageperso.aol.fr/balltrap34/demohijack.htm
Good luck
See you later
download HijackThis here:
http://telechargement.zebulon.fr/138-hijackthis-1991.html
Unzip it into a designated folder.
For example C:\hijackthis < Make sure to save it in c: !
Demo: (Thanks to Balltrap34 for this production)
http://pageperso.aol.fr/balltrap34/Hijenr.gif
Launch it then:
click on "do a system scan and save logfile" (see demo)
copy and paste the entire log on the forum
Demo: (Thanks to Balltrap34 for this production)
http://pageperso.aol.fr/balltrap34/demohijack.htm
Good luck
See you later
Hi
I don't have surfairy in add/remove programs
However, I'm sending you a new log copy because during the first send, my antivirus (VirusScan Enterprise 8.0), my internet browser (Mozilla), and my Ethernet connection were not working
Now I'm back to normal config... if we can say so...
new log
Logfile of HijackThis v1.99.1
Scan saved at 21:42:12, on 10/10/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\WINDOWS\System32\winIogon.exe
C:\WINDOWS\System32\iexplore.exe
C:\WINDOWS\System32\algs.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\system32\lscas.exe
c:\windows\pwr.exe
c:\nwnmff_e26.exe
c:\dfndrff_e26.exe
C:\WINDOWS\explorer.exe
\?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE
C:\Documents and Settings\grand\Local Settings\Temp\Temporary Directory 3 for hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Planetis
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\apps\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SurfairyHlp Class - {E0B9B5FE-B66E-4FB0-A1D9-726F0E743CFD} - C:\Program Files\Surfairy\SurfairyPP.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: UCmore XP - The Search Accelerator - {44BE0690-5429-47f0-85BB-3FFD8020233E} - C:\Program Files\TheSearchAccelerator\UCMTSAIE.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [Windows Logon Application] C:\WINDOWS\System32\winIogon.exe
O4 - HKLM\..\Run: [Microsoft Internet Explorer] C:\WINDOWS\System32\iexplore.exe
O4 - HKLM\..\Run: [Application Layer Gateway Service] C:\WINDOWS\System32\algs.exe
O4 - HKLM\..\Run: [newname] c:\\nwnmff_e26.exe
O4 - HKLM\..\Run: [defender] c:\\dfndrff_e26.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O9 - Extra button: Suggestions - {2223664C-1942-4276-9A2D-E8D8F547C5D2} - res://EffiPeled (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O14 - IERESET.INF: START_PAGE_URL=www.packardbell.fr/center
O20 - Winlogon Notify: Telephony - C:\WINDOWS\system32\tqemeui.dll
O23 - Service: Service Framework McAfee (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Remote Administrator Services - Unknown owner - C:\WINDOWS\system32\lscas.exe
a+
thank you
I don't have surfairy in add/remove programs
However, I'm sending you a new log copy because during the first send, my antivirus (VirusScan Enterprise 8.0), my internet browser (Mozilla), and my Ethernet connection were not working
Now I'm back to normal config... if we can say so...
new log
Logfile of HijackThis v1.99.1
Scan saved at 21:42:12, on 10/10/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\WINDOWS\System32\winIogon.exe
C:\WINDOWS\System32\iexplore.exe
C:\WINDOWS\System32\algs.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\system32\lscas.exe
c:\windows\pwr.exe
c:\nwnmff_e26.exe
c:\dfndrff_e26.exe
C:\WINDOWS\explorer.exe
\?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE
C:\Documents and Settings\grand\Local Settings\Temp\Temporary Directory 3 for hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Planetis
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\apps\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SurfairyHlp Class - {E0B9B5FE-B66E-4FB0-A1D9-726F0E743CFD} - C:\Program Files\Surfairy\SurfairyPP.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: UCmore XP - The Search Accelerator - {44BE0690-5429-47f0-85BB-3FFD8020233E} - C:\Program Files\TheSearchAccelerator\UCMTSAIE.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [Windows Logon Application] C:\WINDOWS\System32\winIogon.exe
O4 - HKLM\..\Run: [Microsoft Internet Explorer] C:\WINDOWS\System32\iexplore.exe
O4 - HKLM\..\Run: [Application Layer Gateway Service] C:\WINDOWS\System32\algs.exe
O4 - HKLM\..\Run: [newname] c:\\nwnmff_e26.exe
O4 - HKLM\..\Run: [defender] c:\\dfndrff_e26.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O9 - Extra button: Suggestions - {2223664C-1942-4276-9A2D-E8D8F547C5D2} - res://EffiPeled (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O14 - IERESET.INF: START_PAGE_URL=www.packardbell.fr/center
O20 - Winlogon Notify: Telephony - C:\WINDOWS\system32\tqemeui.dll
O23 - Service: Service Framework McAfee (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Remote Administrator Services - Unknown owner - C:\WINDOWS\system32\lscas.exe
a+
thank you
Hello;
Download this: (thanks to S!RI for this program).
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
Run it, double-click on Smitfraudfix.cmd, choose option 1, it will generate a report
Copy/paste it on the post please.
See you later!
Download this: (thanks to S!RI for this program).
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
Run it, double-click on Smitfraudfix.cmd, choose option 1, it will generate a report
Copy/paste it on the post please.
See you later!
hello, here is what you requested after running the program
report
SmitFraudFix v2.109
Report made at 19:41:34.48, 11/10/2006
Executed from C:\Documents and Settings\grand\My documents\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Fix executed in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» C:\
C:\drsmartload?.exe PRESENT !
C:\drsmartload??.exe PRESENT !
C:\drsmartload???.exe PRESENT !
C:\drsmartload????.exe PRESENT !
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
C:\WINDOWS\drsmartload2.dat PRESENT !
C:\WINDOWS\newname.dat PRESENT !
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\grand
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\grand\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\grand\Favorites
»»»»»»»»»»»»»»»»»»»»»»»» Desktop
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop items
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Warning, the following keys are not necessarily infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Warning, the following keys are not necessarily infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32
»»»»»»»»»»»»»»»»»»»»»»»» Searching for wininet.dll infection
»»»»»»»»»»»»»»»»»»»»»»»» End
a+
gdf
report
SmitFraudFix v2.109
Report made at 19:41:34.48, 11/10/2006
Executed from C:\Documents and Settings\grand\My documents\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Fix executed in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» C:\
C:\drsmartload?.exe PRESENT !
C:\drsmartload??.exe PRESENT !
C:\drsmartload???.exe PRESENT !
C:\drsmartload????.exe PRESENT !
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
C:\WINDOWS\drsmartload2.dat PRESENT !
C:\WINDOWS\newname.dat PRESENT !
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\grand
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\grand\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\grand\Favorites
»»»»»»»»»»»»»»»»»»»»»»»» Desktop
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop items
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Warning, the following keys are not necessarily infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Warning, the following keys are not necessarily infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32
»»»»»»»»»»»»»»»»»»»»»»»» Searching for wininet.dll infection
»»»»»»»»»»»»»»»»»»»»»»»» End
a+
gdf
Hi
Start in safe mode, run smitfraudfix, choose option 2 and then save the report.
Restart the PC and copy-paste the report here.
See you!
Start in safe mode, run smitfraudfix, choose option 2 and then save the report.
Restart the PC and copy-paste the report here.
See you!
hello
I did the manipulations you asked for, here is the report
SmitFraudFix v2.109
Report created at 14:37:05.73, 12/10/2006
Executed from C:\Documents and Settings\grand\My Documents\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Fix executed in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Warning, the keys that follow are not necessarily infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Stopping processes
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
C:\drsmartload?.exe deleted
C:\WINDOWS\drsmartload2.dat deleted
C:\WINDOWS\newname.dat deleted
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temporary Files
»»»»»»»»»»»»»»»»»»»»»»»» Cleaning the registry
Cleaning completed.
»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Warning, the keys that follow are not necessarily infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
see you+
gdf
I did the manipulations you asked for, here is the report
SmitFraudFix v2.109
Report created at 14:37:05.73, 12/10/2006
Executed from C:\Documents and Settings\grand\My Documents\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Fix executed in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Warning, the keys that follow are not necessarily infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Stopping processes
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
C:\drsmartload?.exe deleted
C:\WINDOWS\drsmartload2.dat deleted
C:\WINDOWS\newname.dat deleted
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temporary Files
»»»»»»»»»»»»»»»»»»»»»»»» Cleaning the registry
Cleaning completed.
»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Warning, the keys that follow are not necessarily infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
see you+
gdf
salut voici le log
Logfile of HijackThis v1.99.1
Scan saved at 22:23:49, on 12/10/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\system32\lscas.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe
C:\WINDOWS\System32\winIogon.exe
C:\WINDOWS\System32\iexplore.exe
C:\WINDOWS\System32\algs.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\grand\Local Settings\Temp\Répertoire temporaire 5 pour hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer fourni par Planetis
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\apps\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SurfairyHlp Class - {E0B9B5FE-B66E-4FB0-A1D9-726F0E743CFD} - C:\Program Files\Surfairy\SurfairyPP.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: UCmore XP - The Search Accelerator - {44BE0690-5429-47f0-85BB-3FFD8020233E} - C:\Program Files\TheSearchAccelerator\UCMTSAIE.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [Windows Logon Application] C:\WINDOWS\System32\winIogon.exe
O4 - HKLM\..\Run: [Microsoft Internet Explorer] C:\WINDOWS\System32\iexplore.exe
O4 - HKLM\..\Run: [Application Layer Gateway Service] C:\WINDOWS\System32\algs.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O9 - Extra button: Suggestions - {2223664C-1942-4276-9A2D-E8D8F547C5D2} - res://EffiPeled (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O14 - IERESET.INF: START_PAGE_URL=www.packardbell.fr/center
O20 - Winlogon Notify: RunServices - C:\WINDOWS\system32\fp4403hqe.dll
O23 - Service: Service Framework McAfee (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Remote Administrator Services - Unknown owner - C:\WINDOWS\system32\lscas.exe
a+
gdf
Logfile of HijackThis v1.99.1
Scan saved at 22:23:49, on 12/10/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\system32\lscas.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe
C:\WINDOWS\System32\winIogon.exe
C:\WINDOWS\System32\iexplore.exe
C:\WINDOWS\System32\algs.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\grand\Local Settings\Temp\Répertoire temporaire 5 pour hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer fourni par Planetis
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\apps\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SurfairyHlp Class - {E0B9B5FE-B66E-4FB0-A1D9-726F0E743CFD} - C:\Program Files\Surfairy\SurfairyPP.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: UCmore XP - The Search Accelerator - {44BE0690-5429-47f0-85BB-3FFD8020233E} - C:\Program Files\TheSearchAccelerator\UCMTSAIE.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [Windows Logon Application] C:\WINDOWS\System32\winIogon.exe
O4 - HKLM\..\Run: [Microsoft Internet Explorer] C:\WINDOWS\System32\iexplore.exe
O4 - HKLM\..\Run: [Application Layer Gateway Service] C:\WINDOWS\System32\algs.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O9 - Extra button: Suggestions - {2223664C-1942-4276-9A2D-E8D8F547C5D2} - res://EffiPeled (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O14 - IERESET.INF: START_PAGE_URL=www.packardbell.fr/center
O20 - Winlogon Notify: RunServices - C:\WINDOWS\system32\fp4403hqe.dll
O23 - Service: Service Framework McAfee (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Remote Administrator Services - Unknown owner - C:\WINDOWS\system32\lscas.exe
a+
gdf
Hello,
Follow the method in order...
Windows is not up to date, your system is therefore open to all infections and hackers.
----------------------------------------------------------------------------
¤Download these programs but do not use them right away:
1/
Spybot S&D 1.4
https://www.safer-networking.org/
Usage demo (thanks to Balltrap34 for this implementation).
http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm
2/
Ad-Aware SE 1.06
https://www.adaware.com/
-A help guide:
http://usa.lucretius-ada.com/zcvisitor/8782d344-4821-11ea-83ce-0a2cdf2c6be7?campaignid=0d1dff40-82d7-11e9-9533-0a157bfa6bfc
- Install the French patch, you can find it here:
http://download.lavasoft.de.edgesuite.net/public/pllangs.exe
and a short usage video here: (thanks to Moe31 for this implementation).
http://pageperso.aol.fr/balltrap34/adawrevid.asf
3/ Ewido:
http://download.ewido.net/ewido-setup.exe
4/ Ccleaner:
https://www.pcastuces.com/logitheque/ccleaner.htm
----------------------------------------------------------------------------
¤Show all files and folders:
Click on start/control panel/tool/folder options/view
Check "show hidden files and folders"
Uncheck the box "Hide protected operating system files (recommended)"
Uncheck "hide extensions for known file types"
Then click "Ok" to validate the changes.
And apply!
----------------------------------------------------------------------------
¤Restart HijackThis, check the boxes next to these lines and then click on fix checked:
O2 - BHO: SurfairyHlp Class - {E0B9B5FE-B66E-4FB0-A1D9-726F0E743CFD} - C:\Program Files\Surfairy\SurfairyPP.dll
O3 - Toolbar: UCmore XP - The Search Accelerator - {44BE0690-5429-47f0-85BB-3FFD8020233E} - C:\Program Files\TheSearchAccelerator\UCMTSAIE.dll
O4 - HKLM\..\Run: [Windows Logon Application] C:\WINDOWS\System32\winIogon.exe
O4 - HKLM\..\Run: [Microsoft Internet Explorer] C:\WINDOWS\System32\iexplore.exe
O4 - HKLM\..\Run: [Application Layer Gateway Service] C:\WINDOWS\System32\algs.exe
O9 - Extra button: Suggestions - {2223664C-1942-4276-9A2D-E8D8F547C5D2} - res://EffiPeled (file missing)
O20 - Winlogon Notify: RunServices - C:\WINDOWS\system32\fp4403hqe.dll
O23 - Service: Remote Administrator Services - Unknown owner - C:\WINDOWS\system32\lscas.exe
----------------------------------------------------------------------------
¤Start in safe mode:
To do this, tap the F8 key as soon as you turn on the pc without stopping
A window will open, navigate with the arrow keys to start in safe mode and then hit enter.
Once on the desktop if there are not all the colors and others it’s normal!
(If F8 doesn’t work use the F5 key).
----------------------------------------------------------------------------
¤Search and delete this:
attention only the files (if present).
C:\Program Files\Surfairy
C:\Program Files\TheSearchAccelerator
C:\WINDOWS\System32\winIogon.exe << with a I
C:\WINDOWS\System32\algs.exe
C:\WINDOWS\system32\lscas.exe
----------------------------------------------------------------------------
¤Stop these services:
Click on Start->run->type: services.msc
Double-click: Service: Remote Administrator Services
Set it to "Stopped" and "Disabled".
----------------------------------------------------------------------------
¤ Launch and run Ewido for a full scan and copy/paste the report on the forum.
----------------------------------------------------------------------------
¤ Run Ad-Aware and delete everything it finds + delete quarantines...
----------------------------------------------------------------------------
¤ Run Spybot and fix everything it finds + vaccinate + delete quarantines...
-------------------------------------------------------------------------------------------
¤ Run CCleaner.
Deleting temporary files
Go to the "Options" section located in the left margin. Go to "Advanced" and uncheck "Delete only files in the Windows Temp folder older than 48 hours". Then go back to the "Cleaner" section
Be sure to check all boxes in the left margin (Internet Explorer/Windows Explorer/System/Advanced)
• Click on Analyze
• Wait for the scan, which may take a little time if it's the first time.
• Once the scan is completed, click on Run the Cleaning
Fixing registry inconsistencies
• Click on the Errors icon located in the left margin.
• Then click on Analyze errors
• Wait while CCleaner scans your registry.
• Once the scan is finished, check all the entries it found.
• You can then click on Fix errors.
If you are unsure of what you are doing, you can choose to back up the checked entries for later restoration.
----------------------------------------------------------------------------
¤ Empty your Recycle Bin.
----------------------------------------------------------------------------
¤ Restart in normal mode, relaunch Hijackthis and copy/paste a new report on the forum.
Specify your issues if any remain....
Keep me updated
See you soon
Follow the method in order...
Windows is not up to date, your system is therefore open to all infections and hackers.
----------------------------------------------------------------------------
¤Download these programs but do not use them right away:
1/
Spybot S&D 1.4
https://www.safer-networking.org/
Usage demo (thanks to Balltrap34 for this implementation).
http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm
2/
Ad-Aware SE 1.06
https://www.adaware.com/
-A help guide:
http://usa.lucretius-ada.com/zcvisitor/8782d344-4821-11ea-83ce-0a2cdf2c6be7?campaignid=0d1dff40-82d7-11e9-9533-0a157bfa6bfc
- Install the French patch, you can find it here:
http://download.lavasoft.de.edgesuite.net/public/pllangs.exe
and a short usage video here: (thanks to Moe31 for this implementation).
http://pageperso.aol.fr/balltrap34/adawrevid.asf
3/ Ewido:
http://download.ewido.net/ewido-setup.exe
4/ Ccleaner:
https://www.pcastuces.com/logitheque/ccleaner.htm
----------------------------------------------------------------------------
¤Show all files and folders:
Click on start/control panel/tool/folder options/view
Check "show hidden files and folders"
Uncheck the box "Hide protected operating system files (recommended)"
Uncheck "hide extensions for known file types"
Then click "Ok" to validate the changes.
And apply!
----------------------------------------------------------------------------
¤Restart HijackThis, check the boxes next to these lines and then click on fix checked:
O2 - BHO: SurfairyHlp Class - {E0B9B5FE-B66E-4FB0-A1D9-726F0E743CFD} - C:\Program Files\Surfairy\SurfairyPP.dll
O3 - Toolbar: UCmore XP - The Search Accelerator - {44BE0690-5429-47f0-85BB-3FFD8020233E} - C:\Program Files\TheSearchAccelerator\UCMTSAIE.dll
O4 - HKLM\..\Run: [Windows Logon Application] C:\WINDOWS\System32\winIogon.exe
O4 - HKLM\..\Run: [Microsoft Internet Explorer] C:\WINDOWS\System32\iexplore.exe
O4 - HKLM\..\Run: [Application Layer Gateway Service] C:\WINDOWS\System32\algs.exe
O9 - Extra button: Suggestions - {2223664C-1942-4276-9A2D-E8D8F547C5D2} - res://EffiPeled (file missing)
O20 - Winlogon Notify: RunServices - C:\WINDOWS\system32\fp4403hqe.dll
O23 - Service: Remote Administrator Services - Unknown owner - C:\WINDOWS\system32\lscas.exe
----------------------------------------------------------------------------
¤Start in safe mode:
To do this, tap the F8 key as soon as you turn on the pc without stopping
A window will open, navigate with the arrow keys to start in safe mode and then hit enter.
Once on the desktop if there are not all the colors and others it’s normal!
(If F8 doesn’t work use the F5 key).
----------------------------------------------------------------------------
¤Search and delete this:
attention only the files (if present).
C:\Program Files\Surfairy
C:\Program Files\TheSearchAccelerator
C:\WINDOWS\System32\winIogon.exe << with a I
C:\WINDOWS\System32\algs.exe
C:\WINDOWS\system32\lscas.exe
----------------------------------------------------------------------------
¤Stop these services:
Click on Start->run->type: services.msc
Double-click: Service: Remote Administrator Services
Set it to "Stopped" and "Disabled".
----------------------------------------------------------------------------
¤ Launch and run Ewido for a full scan and copy/paste the report on the forum.
----------------------------------------------------------------------------
¤ Run Ad-Aware and delete everything it finds + delete quarantines...
----------------------------------------------------------------------------
¤ Run Spybot and fix everything it finds + vaccinate + delete quarantines...
-------------------------------------------------------------------------------------------
¤ Run CCleaner.
Deleting temporary files
Go to the "Options" section located in the left margin. Go to "Advanced" and uncheck "Delete only files in the Windows Temp folder older than 48 hours". Then go back to the "Cleaner" section
Be sure to check all boxes in the left margin (Internet Explorer/Windows Explorer/System/Advanced)
• Click on Analyze
• Wait for the scan, which may take a little time if it's the first time.
• Once the scan is completed, click on Run the Cleaning
Fixing registry inconsistencies
• Click on the Errors icon located in the left margin.
• Then click on Analyze errors
• Wait while CCleaner scans your registry.
• Once the scan is finished, check all the entries it found.
• You can then click on Fix errors.
If you are unsure of what you are doing, you can choose to back up the checked entries for later restoration.
----------------------------------------------------------------------------
¤ Empty your Recycle Bin.
----------------------------------------------------------------------------
¤ Restart in normal mode, relaunch Hijackthis and copy/paste a new report on the forum.
Specify your issues if any remain....
Keep me updated
See you soon
Hi
Note: I’m connecting from a mobile device to communicate with you
I’ve performed the actions you requested and encountered several issues:
No Iscas.exe file to delete
Unable to launch Spybot in safe mode as I couldn’t update it, so I updated it in normal mode...
after that Spybot worked
Ewido scan then report
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 18:20:05 14/10/2006
+ Scan result:
C:\Documents and Settings\grand\Local Settings\Temporary Internet Files\Content.IE5\RYW7POQG\AppWrap[1].exe -> Adware.AdURL: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001505.exe -> Adware.AdURL: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000297.dll -> Adware.Look2Me: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000302.dll -> Adware.Look2Me: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000312.dll -> Adware.Look2Me: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000324.dll -> Adware.Look2Me: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000334.dll -> Adware.Look2Me: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000345.dll -> Adware.Look2Me: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000355.dll -> Adware.Look2Me: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000360.dll -> Adware.Look2Me: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000396.dll -> Adware.Look2Me: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001414.dll -> Adware.Look2Me: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001416.dll -> Adware.Look2Me: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001467.dll -> Adware.Look2Me: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001495.dll -> Adware.Look2Me: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001511.dll -> Adware.Look2Me: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001522.dll -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\__delete_on_reboot__c_z_y_p_t_d_l_l_._d_l_l_ -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\__delete_on_reboot__g_u_a_r_d_._t_m_p_ -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\aysnt.dll -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\cucfg32.dll -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\dwdlgs.dll -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\e6020gdoe60c0.dll -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\guard.tmp_tobedeleted -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\h0n0la5m1d.dll -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\iwv6mon.dll -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\ixseng.dll -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\mpwmdm.dll -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\nkevtmsg.dll -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\pKqsp.dll -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\pfchdprf.dll -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\ubrvpa.dll -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\uhtheme.dll -> Adware.Look2Me: Ignored.
[584] C:\WINDOWS\system32\uqandlg.dll -> Adware.Look2Me: Ignored.
[716] C:\WINDOWS\system32\uqandlg.dll -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\iexplore.exe -> Backdoor.Agobot.aix: Ignored.
C:\WINDOWS\system32\hlzx.exe -> Backdoor.PoeBot.j: Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\8L2ZGPIZ\drsmartload1022a[1].exe -> Downloader.Adload.fu: Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\D5NRWLNA\drsmartload45a[1].exe -> Downloader.Adload.fu: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000263.exe -> Downloader.Adload.fu: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000266.exe -> Downloader.Adload.fu: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001490.exe -> Downloader.Adload.fu: Ignored.
C:\WINDOWS\dov9.exe -> Downloader.Adload.fu: Ignored.
C:\doc.exe -> Downloader.Adload.fu: Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\8L2ZGPIZ\MTE3NDI6ODoxNgV2[1].exe -> Downloader.Agent.azc: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001492.exe -> Downloader.Agent.azc: Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\D5NRWLNA\ac3_0010[1].exe -> Downloader.Small: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001489.exe -> Downloader.Small: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001428.exe -> Dropper.Paradrop.a: Ignored.
:mozilla.15:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Cpvfeed: Ignored.
:mozilla.16:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Cpvfeed: Ignored.
:mozilla.17:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Cpvfeed: Ignored.
:mozilla.18:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Cpvfeed: Ignored.
:mozilla.52:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Reliablestats: Ignored.
:mozilla.53:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Reliablestats: Ignored.
:mozilla.54:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Reliablestats: Ignored.
:mozilla.55:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Reliablestats: Ignored.
:mozilla.56:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Reliablestats: Ignored.
:mozilla.10:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Yieldmanager: Ignored.
:mozilla.11:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Yieldmanager: Ignored.
:mozilla.12:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Yieldmanager: Ignored.
:mozilla.13:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Yieldmanager: Ignored.
:mozilla.6:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Yieldmanager: Ignored.
:mozilla.7:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Yieldmanager: Ignored.
:mozilla.8:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Yieldmanager: Ignored.
:mozilla.9:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Yieldmanager: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000247.exe -> Trojan.Dialer.u: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000262.exe -> Trojan.Dialer.u: Ignored.
C:\mv.exe -> Trojan.Dialer.u: Ignored.
End of report
Ad Adware process:
detection of Adware.Look2Me files (C\WINDOW\System32\irp2157o1.dll) and Adware.Look2Me (C\WINDOW\System32\rFsctrs.dll) unable to delete. The program indicates they will be deleted on the next restart???
Spybot process
detection of the Look2Me.Topcobversing file, unable to delete, file still active, will be deleted on the next restart???
CCleaner run: no problems apparently
Final Hijackthis report:
Logfile of HijackThis v1.99.1
Scan saved at 19:34:49, on 14/10/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\grand\Local Settings\Temp\Temporary directory 1 for hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Planetis
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O14 - IERESET.INF: START_PAGE_URL=www.packardbell.fr/center
O20 - Winlogon Notify: OptimalLayout - C:\WINDOWS\system32\o4480ehueh480.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Service Framework McAfee (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
Remaining problems:
Unwanted launching of Mozilla on gambling sites or antivirus sales sites...
This morning, system shutdown due to the following problem message:
Problem with file C\WINDOW\System 32\Iass.exe error type 107 37 418 19
That's all I can tell you, good luck
See you
GDF
Note: I’m connecting from a mobile device to communicate with you
I’ve performed the actions you requested and encountered several issues:
No Iscas.exe file to delete
Unable to launch Spybot in safe mode as I couldn’t update it, so I updated it in normal mode...
after that Spybot worked
Ewido scan then report
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 18:20:05 14/10/2006
+ Scan result:
C:\Documents and Settings\grand\Local Settings\Temporary Internet Files\Content.IE5\RYW7POQG\AppWrap[1].exe -> Adware.AdURL: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001505.exe -> Adware.AdURL: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000297.dll -> Adware.Look2Me: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000302.dll -> Adware.Look2Me: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000312.dll -> Adware.Look2Me: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000324.dll -> Adware.Look2Me: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000334.dll -> Adware.Look2Me: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000345.dll -> Adware.Look2Me: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000355.dll -> Adware.Look2Me: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000360.dll -> Adware.Look2Me: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000396.dll -> Adware.Look2Me: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001414.dll -> Adware.Look2Me: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001416.dll -> Adware.Look2Me: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001467.dll -> Adware.Look2Me: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001495.dll -> Adware.Look2Me: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001511.dll -> Adware.Look2Me: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001522.dll -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\__delete_on_reboot__c_z_y_p_t_d_l_l_._d_l_l_ -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\__delete_on_reboot__g_u_a_r_d_._t_m_p_ -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\aysnt.dll -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\cucfg32.dll -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\dwdlgs.dll -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\e6020gdoe60c0.dll -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\guard.tmp_tobedeleted -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\h0n0la5m1d.dll -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\iwv6mon.dll -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\ixseng.dll -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\mpwmdm.dll -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\nkevtmsg.dll -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\pKqsp.dll -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\pfchdprf.dll -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\ubrvpa.dll -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\uhtheme.dll -> Adware.Look2Me: Ignored.
[584] C:\WINDOWS\system32\uqandlg.dll -> Adware.Look2Me: Ignored.
[716] C:\WINDOWS\system32\uqandlg.dll -> Adware.Look2Me: Ignored.
C:\WINDOWS\system32\iexplore.exe -> Backdoor.Agobot.aix: Ignored.
C:\WINDOWS\system32\hlzx.exe -> Backdoor.PoeBot.j: Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\8L2ZGPIZ\drsmartload1022a[1].exe -> Downloader.Adload.fu: Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\D5NRWLNA\drsmartload45a[1].exe -> Downloader.Adload.fu: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000263.exe -> Downloader.Adload.fu: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000266.exe -> Downloader.Adload.fu: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001490.exe -> Downloader.Adload.fu: Ignored.
C:\WINDOWS\dov9.exe -> Downloader.Adload.fu: Ignored.
C:\doc.exe -> Downloader.Adload.fu: Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\8L2ZGPIZ\MTE3NDI6ODoxNgV2[1].exe -> Downloader.Agent.azc: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001492.exe -> Downloader.Agent.azc: Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\D5NRWLNA\ac3_0010[1].exe -> Downloader.Small: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001489.exe -> Downloader.Small: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001428.exe -> Dropper.Paradrop.a: Ignored.
:mozilla.15:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Cpvfeed: Ignored.
:mozilla.16:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Cpvfeed: Ignored.
:mozilla.17:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Cpvfeed: Ignored.
:mozilla.18:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Cpvfeed: Ignored.
:mozilla.52:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Reliablestats: Ignored.
:mozilla.53:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Reliablestats: Ignored.
:mozilla.54:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Reliablestats: Ignored.
:mozilla.55:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Reliablestats: Ignored.
:mozilla.56:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Reliablestats: Ignored.
:mozilla.10:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Yieldmanager: Ignored.
:mozilla.11:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Yieldmanager: Ignored.
:mozilla.12:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Yieldmanager: Ignored.
:mozilla.13:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Yieldmanager: Ignored.
:mozilla.6:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Yieldmanager: Ignored.
:mozilla.7:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Yieldmanager: Ignored.
:mozilla.8:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Yieldmanager: Ignored.
:mozilla.9:C:\Documents and Settings\grand\Application Data\Mozilla\Profiles\default\7ajw1r8i.slt\cookies.txt -> TrackingCookie.Yieldmanager: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000247.exe -> Trojan.Dialer.u: Ignored.
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000262.exe -> Trojan.Dialer.u: Ignored.
C:\mv.exe -> Trojan.Dialer.u: Ignored.
End of report
Ad Adware process:
detection of Adware.Look2Me files (C\WINDOW\System32\irp2157o1.dll) and Adware.Look2Me (C\WINDOW\System32\rFsctrs.dll) unable to delete. The program indicates they will be deleted on the next restart???
Spybot process
detection of the Look2Me.Topcobversing file, unable to delete, file still active, will be deleted on the next restart???
CCleaner run: no problems apparently
Final Hijackthis report:
Logfile of HijackThis v1.99.1
Scan saved at 19:34:49, on 14/10/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\grand\Local Settings\Temp\Temporary directory 1 for hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Planetis
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O14 - IERESET.INF: START_PAGE_URL=www.packardbell.fr/center
O20 - Winlogon Notify: OptimalLayout - C:\WINDOWS\system32\o4480ehueh480.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Service Framework McAfee (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
Remaining problems:
Unwanted launching of Mozilla on gambling sites or antivirus sales sites...
This morning, system shutdown due to the following problem message:
Problem with file C\WINDOW\System 32\Iass.exe error type 107 37 418 19
That's all I can tell you, good luck
See you
GDF
Hello, here is the ewido report in question
---------------------------------------------------------
AVG Anti-Spyware - Scan report
---------------------------------------------------------
+ Created at: 20:44:00 17/10/2006
+ Scan result:
C:\WINDOWS\system32\__delete_on_reboot__c_z_y_p_t_d_l_l_._d_l_l_ -> Adware.Look2Me : No action taken.
C:\WINDOWS\system32\__delete_on_reboot__g_u_a_r_d_._t_m_p_ -> Adware.Look2Me : No action taken.
C:\WINDOWS\system32\n62ulgf9162.dll -> Adware.Look2Me : No action taken.
C:\WINDOWS\system32\nkevtmsg.dll -> Adware.Look2Me : No action taken.
C:\WINDOWS\system32\pKqsp.dll -> Adware.Look2Me : No action taken.
C:\WINDOWS\system32\pfchdprf.dll -> Adware.Look2Me : No action taken.
C:\WINDOWS\system32\ubrvpa.dll -> Adware.Look2Me : No action taken.
C:\WINDOWS\system32\uhtheme.dll -> Adware.Look2Me : No action taken.
End of report
Note: when I turned on my computer, I had an error of the same type as the previous time which caused a system shutdown.
During the ewido scan, I had several unexpected restarts of Mozilla with connections to gaming, dating, and real estate websites.
I had the appearance on my desktop of 3 shortcuts probably to internet sites, here are their names:
Online Dating
Cheap Holiday Travel
Free Online Music
Thank you
Cheers
gdf
---------------------------------------------------------
AVG Anti-Spyware - Scan report
---------------------------------------------------------
+ Created at: 20:44:00 17/10/2006
+ Scan result:
C:\WINDOWS\system32\__delete_on_reboot__c_z_y_p_t_d_l_l_._d_l_l_ -> Adware.Look2Me : No action taken.
C:\WINDOWS\system32\__delete_on_reboot__g_u_a_r_d_._t_m_p_ -> Adware.Look2Me : No action taken.
C:\WINDOWS\system32\n62ulgf9162.dll -> Adware.Look2Me : No action taken.
C:\WINDOWS\system32\nkevtmsg.dll -> Adware.Look2Me : No action taken.
C:\WINDOWS\system32\pKqsp.dll -> Adware.Look2Me : No action taken.
C:\WINDOWS\system32\pfchdprf.dll -> Adware.Look2Me : No action taken.
C:\WINDOWS\system32\ubrvpa.dll -> Adware.Look2Me : No action taken.
C:\WINDOWS\system32\uhtheme.dll -> Adware.Look2Me : No action taken.
End of report
Note: when I turned on my computer, I had an error of the same type as the previous time which caused a system shutdown.
During the ewido scan, I had several unexpected restarts of Mozilla with connections to gaming, dating, and real estate websites.
I had the appearance on my desktop of 3 shortcuts probably to internet sites, here are their names:
Online Dating
Cheap Holiday Travel
Free Online Music
Thank you
Cheers
gdf
Hi;
Download l2mfix.exe from http://www.downloads.subratam.org/l2mfix.exe
- Disconnect from the internet, close the browser, and any other application windows;
- Unzip l2mfix.exe to the desktop;
- In the program folder, double-click on l2mfix.bat;
- Choose OPTION 1 (Run find log) and confirm by pressing the [Enter] key
See you!
Download l2mfix.exe from http://www.downloads.subratam.org/l2mfix.exe
- Disconnect from the internet, close the browser, and any other application windows;
- Unzip l2mfix.exe to the desktop;
- In the program folder, double-click on l2mfix.bat;
- Choose OPTION 1 (Run find log) and confirm by pressing the [Enter] key
See you!
Hello, I used the program in question, I'm sending you the report just in case
L2MFIX find log 051206
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ShellScrap]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\azas0c77ef.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
**********************************************************************************
useragent:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{6EF6876E-8CCB-3784-1CE9-221E167E383C}"=""
**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia file property sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE DocFile Properties Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Sharing Environment Extensions"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Control Panel Display Card Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Control Panel Screen Display Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Control Panel Panorama Display Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Damaged Environment Data Manager"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Floppy Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Environment Extensions for Microsoft Windows Network Objects"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Screen Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="File Compression Environment Extensions"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Environment Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption context menu"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Clipboard"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Extension"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printer Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Sharing Environment Extensions"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="PKO Cryptography Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Sign Cryptography Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners and Cameras"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners and Cameras"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners and Cameras"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners and Cameras"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners and Cameras"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Automatic Update Property Page Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Windows Script Host Environment Command Interpreter Extensions"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Binding"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run..."
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="Email"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Expanded Desktop Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft Browser Band"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="Integrated Search Pane"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="Address"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address Entry Input Box"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoComplete List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Auto-opening Progress Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Analyzer"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Desktop Bar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assistance"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Parameters"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Startup Image"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Registration Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11D0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Environment Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Applications Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin Application Publishing"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="File + GDI Thumbnail Extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Thumbnail Manager - Summary Info (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Site Publishing Assistant"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Web Print Command"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Assistant Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport identity Assistant"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Chain File"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Chain Shortcut"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="From &people..."
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{59850401-6664-101B-B21C-00AA004BA90B}"="Microsoft Office Binder Unbind"
"{A0752120-6D75-D111-B5B1-0800095A2318}"="HandyBits EasyCrypto Shell Extensions"
"{BE7FC451-2B79-42E6-8408-3F28D7447790}"=""
"{3334FE85-C609-4B41-B1C1-1E52CD79F1FC}"=""
"{96E0C116-31FD-4DB6-9228-6F91ABF97CBA}"=""
"{29068B4E-5D2F-4B88-B946-A272CA4A3E0E}"=""
"{7A1445DC-30A9-4F8D-9B4F-E039EE2B14EC}"=""
"{0F97195D-DFB2-44BB-9478-7AF687B7A2A3}"=""
"{59EE1164-21F9-4916-BF4B-4BF5E20379C0}"=""
"{F01C7487-C6F7-4B3B-86E0-5CFB15A600FA}"=""
"{A152C159-37D3-4080-94FE-9D697715D876}"=""
**********************************************************************************
Files Found are not all bad files:
C:\WINDOWS\SYSTEM32\
aysnt.dll Sat 14 Oct 2006 11:50:26 ..S.R 236 646 231.10 K
azas0c~1.dll Wed 18 Oct 2006 13:53:06 ..S.R 236 934 231.38 K
cucfg32.dll Fri 13 Oct 2006 17:58:56 ..S.R 234 167 228.68 K
dnr401~1.dll Wed 18 Oct 2006 14:00:06 ..S.R 233 493 228.02 K
dwdlgs.dll Thu 12 Oct 2006 22:23:02 ..S.R 236 191 230.65 K
e6020g~1.dll Sat 14 Oct 2006 11:22:52 ..S.R 235 721 230.20 K
fpro03~1.dll Sun 15 Oct 2006 11:07:12 ..S.R 235 467 229.95 K
h0n0la~1.dll Sat 14 Oct 2006 13:52:28 ..S.R 234 037 228.55 K
iwv6mon.dll Thu 12 Oct 2006 14:36:06 ..S.R 234 251 228.76 K
ixseng.dll Sat 14 Oct 2006 11:46:22 ..S.R 235 721 230.20 K
jivart.dll Wed 18 Oct 2006 14:00:06 ..S.R 236 934 231.38 K
jt8s07~1.dll Wed 18 Oct 2006 13:56:06 ..S.R 235 846 230.32 K
k4440e~1.dll Sun 15 Oct 2006 12:00:04 ..S.R 235 518 229.99 K
k8pmli~1.dll Tue 17 Oct 2006 20:12:52 ..S.R 236 252 230.71 K
l26o0c~1.dll Sun 15 Oct 2006 11:00:30 ..S.R 235 436 229.92 K
mlrating.dll Tue 17 Oct 2006 20:15:18 ..S.R 235 074 229.56 K
mpwmdm.dll Wed 11 Oct 2006 19:18:16 ..S.R 235 747 230.22 K
17 items found: 17 files (17 H/S), 0 directories.
Total of file sizes: 4 003 435 bytes 3.82 M
Locate .tmp files:
C:\WINDOWS\SYSTEM32\
guard~1.tmp Sat 14 Oct 2006 19:14:36 ..... 235 752 230.23 K
1 item found: 1 file, 0 directories.
Total of file sizes: 235 752 bytes 230.23 K
**********************************************************************************
Directory Listing of system files:
The volume in drive C is called HDD
The serial number of the volume is 18CF-1E3A
Directory of C:\WINDOWS\System32
18/10/2006 14:00 236ÿ934 jIvart.dll
18/10/2006 14:00 233ÿ493 dnr4019qe.dll
18/10/2006 13:56 235ÿ846 jt8s07l7e.dll
18/10/2006 13:53 236ÿ934 azas0c77ef.dll
17/10/2006 20:15 235ÿ074 mlrating.dll
17/10/2006 20:12 236ÿ252 k8pmli7118.dll
15/10/2006 12:00 235ÿ518 k4440ehqeh4e0.dll
15/10/2006 11:07 235ÿ467 fpro0393e.dll
15/10/2006 11:00 235ÿ436 l26o0cj3efo.dll
14/10/2006 13:52 234ÿ037 h0n0la5m1d.dll
14/10/2006 11:50 236ÿ646 aysnt.dll
14/10/2006 11:46 235ÿ721 ixseng.dll
14/10/2006 11:22 235ÿ721 e6020gdoe60c0.dll
13/10/2006 17:58 234ÿ167 cucfg32.dll
12/10/2006 22:23 236ÿ191 dwdlgs.dll
12/10/2006 14:36 234ÿ251 iwv6mon.dll
11/10/2006 19:35 <REP> dllcache
11/10/2006 19:18 235ÿ747 mpwmdm.dll
10/10/2006 21:38 75ÿ264 lscas.exe
10/10/2006 20:00 <REP> Microsoft
18 files 4ÿ078ÿ699 bytes
2 Reps 34ÿ329ÿ030ÿ656 bytes free
a+
gdf
L2MFIX find log 051206
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ShellScrap]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\azas0c77ef.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
**********************************************************************************
useragent:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{6EF6876E-8CCB-3784-1CE9-221E167E383C}"=""
**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia file property sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE DocFile Properties Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Sharing Environment Extensions"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Control Panel Display Card Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Control Panel Screen Display Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Control Panel Panorama Display Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Damaged Environment Data Manager"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Floppy Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Environment Extensions for Microsoft Windows Network Objects"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Screen Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="File Compression Environment Extensions"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Environment Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption context menu"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Clipboard"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Extension"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printer Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Sharing Environment Extensions"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="PKO Cryptography Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Sign Cryptography Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners and Cameras"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners and Cameras"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners and Cameras"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners and Cameras"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners and Cameras"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Automatic Update Property Page Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Windows Script Host Environment Command Interpreter Extensions"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Binding"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run..."
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="Email"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Expanded Desktop Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft Browser Band"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="Integrated Search Pane"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="Address"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address Entry Input Box"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoComplete List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Auto-opening Progress Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Analyzer"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Desktop Bar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assistance"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Parameters"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Startup Image"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Registration Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11D0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Environment Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Applications Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin Application Publishing"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="File + GDI Thumbnail Extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Thumbnail Manager - Summary Info (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Site Publishing Assistant"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Web Print Command"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Assistant Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport identity Assistant"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Chain File"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Chain Shortcut"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="From &people..."
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{59850401-6664-101B-B21C-00AA004BA90B}"="Microsoft Office Binder Unbind"
"{A0752120-6D75-D111-B5B1-0800095A2318}"="HandyBits EasyCrypto Shell Extensions"
"{BE7FC451-2B79-42E6-8408-3F28D7447790}"=""
"{3334FE85-C609-4B41-B1C1-1E52CD79F1FC}"=""
"{96E0C116-31FD-4DB6-9228-6F91ABF97CBA}"=""
"{29068B4E-5D2F-4B88-B946-A272CA4A3E0E}"=""
"{7A1445DC-30A9-4F8D-9B4F-E039EE2B14EC}"=""
"{0F97195D-DFB2-44BB-9478-7AF687B7A2A3}"=""
"{59EE1164-21F9-4916-BF4B-4BF5E20379C0}"=""
"{F01C7487-C6F7-4B3B-86E0-5CFB15A600FA}"=""
"{A152C159-37D3-4080-94FE-9D697715D876}"=""
**********************************************************************************
Files Found are not all bad files:
C:\WINDOWS\SYSTEM32\
aysnt.dll Sat 14 Oct 2006 11:50:26 ..S.R 236 646 231.10 K
azas0c~1.dll Wed 18 Oct 2006 13:53:06 ..S.R 236 934 231.38 K
cucfg32.dll Fri 13 Oct 2006 17:58:56 ..S.R 234 167 228.68 K
dnr401~1.dll Wed 18 Oct 2006 14:00:06 ..S.R 233 493 228.02 K
dwdlgs.dll Thu 12 Oct 2006 22:23:02 ..S.R 236 191 230.65 K
e6020g~1.dll Sat 14 Oct 2006 11:22:52 ..S.R 235 721 230.20 K
fpro03~1.dll Sun 15 Oct 2006 11:07:12 ..S.R 235 467 229.95 K
h0n0la~1.dll Sat 14 Oct 2006 13:52:28 ..S.R 234 037 228.55 K
iwv6mon.dll Thu 12 Oct 2006 14:36:06 ..S.R 234 251 228.76 K
ixseng.dll Sat 14 Oct 2006 11:46:22 ..S.R 235 721 230.20 K
jivart.dll Wed 18 Oct 2006 14:00:06 ..S.R 236 934 231.38 K
jt8s07~1.dll Wed 18 Oct 2006 13:56:06 ..S.R 235 846 230.32 K
k4440e~1.dll Sun 15 Oct 2006 12:00:04 ..S.R 235 518 229.99 K
k8pmli~1.dll Tue 17 Oct 2006 20:12:52 ..S.R 236 252 230.71 K
l26o0c~1.dll Sun 15 Oct 2006 11:00:30 ..S.R 235 436 229.92 K
mlrating.dll Tue 17 Oct 2006 20:15:18 ..S.R 235 074 229.56 K
mpwmdm.dll Wed 11 Oct 2006 19:18:16 ..S.R 235 747 230.22 K
17 items found: 17 files (17 H/S), 0 directories.
Total of file sizes: 4 003 435 bytes 3.82 M
Locate .tmp files:
C:\WINDOWS\SYSTEM32\
guard~1.tmp Sat 14 Oct 2006 19:14:36 ..... 235 752 230.23 K
1 item found: 1 file, 0 directories.
Total of file sizes: 235 752 bytes 230.23 K
**********************************************************************************
Directory Listing of system files:
The volume in drive C is called HDD
The serial number of the volume is 18CF-1E3A
Directory of C:\WINDOWS\System32
18/10/2006 14:00 236ÿ934 jIvart.dll
18/10/2006 14:00 233ÿ493 dnr4019qe.dll
18/10/2006 13:56 235ÿ846 jt8s07l7e.dll
18/10/2006 13:53 236ÿ934 azas0c77ef.dll
17/10/2006 20:15 235ÿ074 mlrating.dll
17/10/2006 20:12 236ÿ252 k8pmli7118.dll
15/10/2006 12:00 235ÿ518 k4440ehqeh4e0.dll
15/10/2006 11:07 235ÿ467 fpro0393e.dll
15/10/2006 11:00 235ÿ436 l26o0cj3efo.dll
14/10/2006 13:52 234ÿ037 h0n0la5m1d.dll
14/10/2006 11:50 236ÿ646 aysnt.dll
14/10/2006 11:46 235ÿ721 ixseng.dll
14/10/2006 11:22 235ÿ721 e6020gdoe60c0.dll
13/10/2006 17:58 234ÿ167 cucfg32.dll
12/10/2006 22:23 236ÿ191 dwdlgs.dll
12/10/2006 14:36 234ÿ251 iwv6mon.dll
11/10/2006 19:35 <REP> dllcache
11/10/2006 19:18 235ÿ747 mpwmdm.dll
10/10/2006 21:38 75ÿ264 lscas.exe
10/10/2006 20:00 <REP> Microsoft
18 files 4ÿ078ÿ699 bytes
2 Reps 34ÿ329ÿ030ÿ656 bytes free
a+
gdf
Re,
Now restart l2mfix.bat
and choose option 2
It will ask you to press a key to restart
press any key and let the PC restart
the notepad will open, copy and paste the content here
See you+
Now restart l2mfix.bat
and choose option 2
It will ask you to press a key to restart
press any key and let the PC restart
the notepad will open, copy and paste the content here
See you+
Hello,
the notepad did not open automatically, but there was a log.txt file on the desktop
L2mfix 051206
Creating Account.
The command completed successfully.
Adding Administrative privileges.
Checking for L2MFix account(0=no 1=yes):
1
Granting SeDebugPrivilege to L2MFIX ... successful
Checking for L2MFix account(0=no 1=yes):
0
Zipping up files for submission:
zip warning: name not matched: dlls\*.*
zip error: Nothing to do! (backup.zip)
updating: backregs/notibac.reg (164 bytes security) (deflated 87%)
Rq: the files
echo.reg
cleanup.bat
and the folder backup.zip appeared on the desktop
see you
gdf
the notepad did not open automatically, but there was a log.txt file on the desktop
L2mfix 051206
Creating Account.
The command completed successfully.
Adding Administrative privileges.
Checking for L2MFix account(0=no 1=yes):
1
Granting SeDebugPrivilege to L2MFIX ... successful
Checking for L2MFix account(0=no 1=yes):
0
Zipping up files for submission:
zip warning: name not matched: dlls\*.*
zip error: Nothing to do! (backup.zip)
updating: backregs/notibac.reg (164 bytes security) (deflated 87%)
Rq: the files
echo.reg
cleanup.bat
and the folder backup.zip appeared on the desktop
see you
gdf
Hi
Download: Pocket Killbox here
http://www.downloads.subratam.org/KillBox.exe
:: Usage demo (thanks to Balltrap34 for this creation) ::
http://pageperso.aol.fr/balltrap34/killbox.htm
Use the Notepad method (see video)
Here is the list:
C:\WINDOWS\System32\uabmon.dll
C:\WINDOWS\System32\mv60l9jm1.dll
C:\WINDOWS\System32\pBnmap.dll
C:\WINDOWS\System32\c600lgdm160a.dll
C:\WINDOWS\System32\iogutil.dll
C:\WINDOWS\System32\lvnu0959e.dll
C:\WINDOWS\System32\solwid.dll
C:\WINDOWS\System32\aza40ehqeh4e0.dll
C:\WINDOWS\System32\maastmib.dll
C:\WINDOWS\System32\jt8s07l7e.dll
C:\WINDOWS\System32\mlrating.dll
C:\WINDOWS\System32\k8pmli7118.dll
C:\WINDOWS\System32\k4440ehqeh4e0.dll
C:\WINDOWS\System32\fpro0393e.dll
C:\WINDOWS\System32\l26o0cj3efo.dll
C:\WINDOWS\System32\h0n0la5m1d.dll
C:\WINDOWS\System32\aysnt.dll
C:\WINDOWS\System32\ixseng.dll
C:\WINDOWS\System32\e6020gdoe60c0.dll
C:\WINDOWS\System32\cucfg32.dll
C:\WINDOWS\System32\dwdlgs.dll
C:\WINDOWS\System32\iwv6mon.dll
C:\WINDOWS\System32\mpwmdm.dll
C:\WINDOWS\System32\lscas.exe
Restart and run an lm2fix option 1.
See you+
Download: Pocket Killbox here
http://www.downloads.subratam.org/KillBox.exe
:: Usage demo (thanks to Balltrap34 for this creation) ::
http://pageperso.aol.fr/balltrap34/killbox.htm
Use the Notepad method (see video)
Here is the list:
C:\WINDOWS\System32\uabmon.dll
C:\WINDOWS\System32\mv60l9jm1.dll
C:\WINDOWS\System32\pBnmap.dll
C:\WINDOWS\System32\c600lgdm160a.dll
C:\WINDOWS\System32\iogutil.dll
C:\WINDOWS\System32\lvnu0959e.dll
C:\WINDOWS\System32\solwid.dll
C:\WINDOWS\System32\aza40ehqeh4e0.dll
C:\WINDOWS\System32\maastmib.dll
C:\WINDOWS\System32\jt8s07l7e.dll
C:\WINDOWS\System32\mlrating.dll
C:\WINDOWS\System32\k8pmli7118.dll
C:\WINDOWS\System32\k4440ehqeh4e0.dll
C:\WINDOWS\System32\fpro0393e.dll
C:\WINDOWS\System32\l26o0cj3efo.dll
C:\WINDOWS\System32\h0n0la5m1d.dll
C:\WINDOWS\System32\aysnt.dll
C:\WINDOWS\System32\ixseng.dll
C:\WINDOWS\System32\e6020gdoe60c0.dll
C:\WINDOWS\System32\cucfg32.dll
C:\WINDOWS\System32\dwdlgs.dll
C:\WINDOWS\System32\iwv6mon.dll
C:\WINDOWS\System32\mpwmdm.dll
C:\WINDOWS\System32\lscas.exe
Restart and run an lm2fix option 1.
See you+
hello
here is what you asked for
L2MFIX find log 051206
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\URL]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\jtr8079ue.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
**********************************************************************************
useragent:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{6EF6876E-8CCB-3784-1CE9-221E167E383C}"=""
**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia file properties sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE DocFile Properties Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Sharing environment extensions"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Control Panel Display Card Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Control Panel Display Screen Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Control Panel Display Panorama Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Corrupted environment data manager"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Floppy Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Windows Network Object Environment Extensions"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Screen Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="File Compression Environment Extensions"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Environment Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu Extension"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Clipboard"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Extension"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printer Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Sharing environment extensions"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display Troubleshoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="PKO Cryptography Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Sign Cryptography Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners and Cameras"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners and Cameras"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners and Cameras"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners and Cameras"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners and Cameras"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Automatic Update Properties Page Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Windows Script Host Extensions for Windows Script Execution Environment"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Binding"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run..."
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="Email"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Expanded Desktops Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Expanded Shell Folder"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft Browser Band"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="Integrated Search Pane"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="Address"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address Bar Edit Box"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoComplete List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Auto-Opening Progress Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell AutoComplete List Folder"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multi-AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Bands Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Desktop Bar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assistance"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Parameters"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Startup Image"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Registration Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Environment Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Applications Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin Application Publishing"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="File + GDI Thumbnail Extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Thumbnail Manager - Summary Info (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Site Publishing Assistant"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Web Printing Command"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Assistant Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get Passport Identity Assistant"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Chain File"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Chain Shortcut"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="People..."
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{59850401-6664-101B-B21C-00AA004BA90B}"="Microsoft Office Binder Unbind"
"{A0752120-6D75-D111-B5B1-0800095A2318}"="HandyBits EasyCrypto Shell Extensions"
"{BE7FC451-2B79-42E6-8408-3F28D7447790}"=""
"{3334FE85-C609-4B41-B1C1-1E52CD79F1FC}"=""
"{96E0C116-31FD-4DB6-9228-6F91ABF97CBA}"=""
"{29068B4E-5D2F-4B88-B946-A272CA4A3E0E}"=""
"{7A1445DC-30A9-4F8D-9B4F-E039EE2B14EC}"=""
"{0F97195D-DFB2-44BB-9478-7AF687B7A2A3}"=""
"{59EE1164-21F9-4916-BF4B-4BF5E20379C0}"=""
"{F01C7487-C6F7-4B3B-86E0-5CFB15A600FA}"=""
"{A152C159-37D3-4080-94FE-9D697715D876}"=""
**********************************************************************************
Files Found are not all bad files:
C:\WINDOWS\SYSTEM32\
aza0l9~1.dll Thu 19 Oct 2006 19:06:12 ..S.R 235 240 229.73 K
cbmres.dll Fri 20 Oct 2006 12:59:28 ..S.R 235 396 229.88 K
drmrtp.dll Fri 20 Oct 2006 13:04:24 ..S.R 236 293 230.75 K
e6jmlg~1.dll Fri 20 Oct 2006 12:53:54 ..S.R 234 234 228.74 K
fplo03~1.dll Fri 20 Oct 2006 13:04:24 ..S.R 236 626 231.08 K
jtr807~1.dll Fri 20 Oct 2006 12:59:28 ..S.R 236 293 230.75 K
t2r8lc~1.dll Fri 20 Oct 2006 12:49:52 A.... 236 126 230.59 K
7 items found: 7 files (6 H/S), 0 directories.
Total of file sizes: 1,650,208 bytes 1.57 MB
Locate .tmp files:
C:\WINDOWS\SYSTEM32\
guard~1.tmp Sat 14 Oct 2006 19:14:36 ..... 235,752 230.23 K
1 item found: 1 file, 0 directories.
Total of file sizes: 235,752 bytes 230.23 K
**********************************************************************************
Directory Listing of system files:
The volume in drive C is called HDD
The serial number of the volume is 18CF-1E3A
Directory of C:\WINDOWS\System32
20/10/2006 13:04 236,293 drmrtp.dll
20/10/2006 13:04 236,626 fplo0333e.dll
20/10/2006 12:59 235,396 cbmres.dll
20/10/2006 12:59 236,293 jtr8079ue.dll
20/10/2006 12:53 234,234 e6jmlg1116.dll
19/10/2006 19:06 235,240 aza0l9jm1.dll
11/10/2006 19:35 <REP> dllcache
10/10/2006 20:00 <REP> Microsoft
6 file(s) 1,414,082 bytes
2 Reps 34,314,784,768 bytes free
Note:
mozilla unexpectedly launched a download site called Anwinantyspyware and a casino site
best regards
gdf
here is what you asked for
L2MFIX find log 051206
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\URL]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\jtr8079ue.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
**********************************************************************************
useragent:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{6EF6876E-8CCB-3784-1CE9-221E167E383C}"=""
**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia file properties sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE DocFile Properties Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Sharing environment extensions"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Control Panel Display Card Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Control Panel Display Screen Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Control Panel Display Panorama Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Corrupted environment data manager"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Floppy Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Windows Network Object Environment Extensions"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Screen Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="File Compression Environment Extensions"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Environment Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu Extension"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Clipboard"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Extension"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printer Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Sharing environment extensions"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display Troubleshoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="PKO Cryptography Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Sign Cryptography Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners and Cameras"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners and Cameras"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners and Cameras"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners and Cameras"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners and Cameras"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Automatic Update Properties Page Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Windows Script Host Extensions for Windows Script Execution Environment"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Binding"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run..."
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="Email"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Expanded Desktops Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Expanded Shell Folder"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft Browser Band"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="Integrated Search Pane"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="Address"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address Bar Edit Box"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoComplete List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Auto-Opening Progress Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell AutoComplete List Folder"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multi-AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Bands Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Desktop Bar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assistance"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Parameters"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Startup Image"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Registration Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Environment Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Applications Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin Application Publishing"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="File + GDI Thumbnail Extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Thumbnail Manager - Summary Info (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Site Publishing Assistant"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Web Printing Command"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Assistant Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get Passport Identity Assistant"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Chain File"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Chain Shortcut"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="People..."
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{59850401-6664-101B-B21C-00AA004BA90B}"="Microsoft Office Binder Unbind"
"{A0752120-6D75-D111-B5B1-0800095A2318}"="HandyBits EasyCrypto Shell Extensions"
"{BE7FC451-2B79-42E6-8408-3F28D7447790}"=""
"{3334FE85-C609-4B41-B1C1-1E52CD79F1FC}"=""
"{96E0C116-31FD-4DB6-9228-6F91ABF97CBA}"=""
"{29068B4E-5D2F-4B88-B946-A272CA4A3E0E}"=""
"{7A1445DC-30A9-4F8D-9B4F-E039EE2B14EC}"=""
"{0F97195D-DFB2-44BB-9478-7AF687B7A2A3}"=""
"{59EE1164-21F9-4916-BF4B-4BF5E20379C0}"=""
"{F01C7487-C6F7-4B3B-86E0-5CFB15A600FA}"=""
"{A152C159-37D3-4080-94FE-9D697715D876}"=""
**********************************************************************************
Files Found are not all bad files:
C:\WINDOWS\SYSTEM32\
aza0l9~1.dll Thu 19 Oct 2006 19:06:12 ..S.R 235 240 229.73 K
cbmres.dll Fri 20 Oct 2006 12:59:28 ..S.R 235 396 229.88 K
drmrtp.dll Fri 20 Oct 2006 13:04:24 ..S.R 236 293 230.75 K
e6jmlg~1.dll Fri 20 Oct 2006 12:53:54 ..S.R 234 234 228.74 K
fplo03~1.dll Fri 20 Oct 2006 13:04:24 ..S.R 236 626 231.08 K
jtr807~1.dll Fri 20 Oct 2006 12:59:28 ..S.R 236 293 230.75 K
t2r8lc~1.dll Fri 20 Oct 2006 12:49:52 A.... 236 126 230.59 K
7 items found: 7 files (6 H/S), 0 directories.
Total of file sizes: 1,650,208 bytes 1.57 MB
Locate .tmp files:
C:\WINDOWS\SYSTEM32\
guard~1.tmp Sat 14 Oct 2006 19:14:36 ..... 235,752 230.23 K
1 item found: 1 file, 0 directories.
Total of file sizes: 235,752 bytes 230.23 K
**********************************************************************************
Directory Listing of system files:
The volume in drive C is called HDD
The serial number of the volume is 18CF-1E3A
Directory of C:\WINDOWS\System32
20/10/2006 13:04 236,293 drmrtp.dll
20/10/2006 13:04 236,626 fplo0333e.dll
20/10/2006 12:59 235,396 cbmres.dll
20/10/2006 12:59 236,293 jtr8079ue.dll
20/10/2006 12:53 234,234 e6jmlg1116.dll
19/10/2006 19:06 235,240 aza0l9jm1.dll
11/10/2006 19:35 <REP> dllcache
10/10/2006 20:00 <REP> Microsoft
6 file(s) 1,414,082 bytes
2 Reps 34,314,784,768 bytes free
Note:
mozilla unexpectedly launched a download site called Anwinantyspyware and a casino site
best regards
gdf
Hi
Please print these instructions or paste them into a text file for reading during this fix. Make sure to check the three little notes at the bottom before starting.
Download Look2Me-Destroyer.exe (by Atribune) to your Desktop.
http://www.atribune.org/ccount/click.php?id=7
Close all active windows before moving to the next step.
• Double-click Look2Me-Destroyer.exe to launch the tool.
• Check Run this program as a task
• A message will appear saying: "Look2Me-Destroyer will close and re-open in approximately 10 seconds." Click OK
• It will restart after 10 seconds, then click the Scan for L2M button; the icons on your Desktop will disappear: this is normal.
• When the scan is complete, click the Remove L2M button
• A Done Scanning message will appear, click OK.
• A new message will appear: Done removing infected files! Look2Me-Destroyer will now shutdown your computer; click OK.
• Your PC will now shut down.
• Start your PC normally.
• Paste the generated report, located here: C:\Look2Me-Destroyer.txt, along with a new HijackThis! report in your next response.
*If Look2Me-Destroyer does not restart automatically after 10 seconds, restart and try again.
**If you receive a message from your firewall that the tool is trying to access the internet: accept it.
***If a runtime error '339' message appears: download MSWINSCK.OCX from the link below, and place it in the C:\Windows\System32 folder.
http://www.ascentive.com/support/new/images/lib/MSWINSCK.OCX
Then resend a HijackThis + a LM2FIX option 1.
See you+
Please print these instructions or paste them into a text file for reading during this fix. Make sure to check the three little notes at the bottom before starting.
Download Look2Me-Destroyer.exe (by Atribune) to your Desktop.
http://www.atribune.org/ccount/click.php?id=7
Close all active windows before moving to the next step.
• Double-click Look2Me-Destroyer.exe to launch the tool.
• Check Run this program as a task
• A message will appear saying: "Look2Me-Destroyer will close and re-open in approximately 10 seconds." Click OK
• It will restart after 10 seconds, then click the Scan for L2M button; the icons on your Desktop will disappear: this is normal.
• When the scan is complete, click the Remove L2M button
• A Done Scanning message will appear, click OK.
• A new message will appear: Done removing infected files! Look2Me-Destroyer will now shutdown your computer; click OK.
• Your PC will now shut down.
• Start your PC normally.
• Paste the generated report, located here: C:\Look2Me-Destroyer.txt, along with a new HijackThis! report in your next response.
*If Look2Me-Destroyer does not restart automatically after 10 seconds, restart and try again.
**If you receive a message from your firewall that the tool is trying to access the internet: accept it.
***If a runtime error '339' message appears: download MSWINSCK.OCX from the link below, and place it in the C:\Windows\System32 folder.
http://www.ascentive.com/support/new/images/lib/MSWINSCK.OCX
Then resend a HijackThis + a LM2FIX option 1.
See you+
Hello
I was able to use the Look2Me Destroyer program without too many issues, I just restarted once because the computer was frozen.
Here are the reports:
The report Look2Me-Destroyer.txt was on the desktop ??
Look2Me-Destroyer V1.0.12
Scanning for infected files.....
Scan started at 24/10/2006 19:41:11
Infected! C:\WINDOWS\system32\c600lgdm160a.dll
Infected! C:\!KillBox\aysnt.dll
Infected! C:\!KillBox\aza0l9jm1.dll
Infected! C:\!KillBox\aza40ehqeh4e0.dll
Infected! C:\!KillBox\cucfg32.dll
Infected! C:\!KillBox\dwdlgs.dll
Infected! C:\!KillBox\e6020gdoe60c0.dll
Infected! C:\!KillBox\e6jmlg1116.dll
Infected! C:\!KillBox\fpro0393e.dll
Infected! C:\!KillBox\h0n0la5m1d.dll
Infected! C:\!KillBox\iogutil.dll
Infected! C:\!KillBox\iwv6mon.dll
Infected! C:\!KillBox\ixseng.dll
Infected! C:\!KillBox\jt8s07l7e.dll
Infected! C:\!KillBox\k4440ehqeh4e0.dll
Infected! C:\!KillBox\k8pmli7118.dll
Infected! C:\!KillBox\l26o0cj3efo.dll
Infected! C:\!KillBox\lvnu0959e.dll
Infected! C:\!KillBox\maastmib.dll
Infected! C:\!KillBox\mlrating.dll
Infected! C:\!KillBox\mpwmdm.dll
Infected! C:\!KillBox\solwid.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000297.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000302.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000312.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000324.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000334.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000345.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000355.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000360.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000396.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001414.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001416.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001467.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001495.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001511.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001522.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002541.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002547.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002565.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002581.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002589.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0003589.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004589.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004597.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004603.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004604.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004605.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004606.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004607.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004608.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004611.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004620.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004628.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005628.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005631.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005639.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005641.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005674.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005684.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005686.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005695.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0006693.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0006695.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0006703.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007695.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007703.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007706.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007707.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007708.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007709.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007710.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007711.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007712.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007713.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007714.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007715.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007716.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007717.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007718.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007719.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007720.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007721.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007722.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007723.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007725.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007733.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007735.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007743.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0008742.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0009742.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011742.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011745.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011746.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011747.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011755.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0012752.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0012756.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0012764.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0013763.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0014763.dll
Infected! C:\WINDOWS\system32\c600lgdm160a.dll
Infected! C:\WINDOWS\system32\cCpesnpn.dll
Infected! C:\WINDOWS\system32\dnru0199e.dll
Infected! C:\WINDOWS\system32\h60qlgd5160.dll
Infected! C:\WINDOWS\system32\ktr8l79u1.dll
Infected! C:\WINDOWS\system32\m2ju0c19ef.dll
Infected! C:\WINDOWS\system32\mv8sl9l71.dll
Infected! C:\WINDOWS\system32\n24slch71f4.dll
Infected! C:\WINDOWS\system32\q668lgju16o8.dll
Infected! C:\WINDOWS\system32\r4r6le9s1h.dll
Infected! C:\WINDOWS\system32\t2r8lc9u1f.dll
Attempting to delete infected files...
Attempting to delete: C:\WINDOWS\system32\c600lgdm160a.dll
C:\WINDOWS\system32\c600lgdm160a.dll Deleted successfully!
Attempting to delete: C:\!KillBox\aysnt.dll
C:\!KillBox\aysnt.dll Deleted successfully!
Attempting to delete: C:\!KillBox\aza0l9jm1.dll
C:\!KillBox\aza0l9jm1.dll Deleted successfully!
Attempting to delete: C:\!KillBox\aza40ehqeh4e0.dll
C:\!KillBox\aza40ehqeh4e0.dll Deleted successfully!
Attempting to delete: C:\!KillBox\cucfg32.dll
C:\!KillBox\cucfg32.dll Deleted successfully!
Attempting to delete: C:\!KillBox\dwdlgs.dll
C:\!KillBox\dwdlgs.dll Deleted successfully!
Attempting to delete: C:\!KillBox\e6020gdoe60c0.dll
C:\!KillBox\e6020gdoe60c0.dll Deleted successfully!
Attempting to delete: C:\!KillBox\e6jmlg1116.dll
C:\!KillBox\e6jmlg1116.dll Deleted successfully!
Attempting to delete: C:\!KillBox\fpro0393e.dll
C:\!KillBox\fpro0393e.dll Deleted successfully!
Attempting to delete: C:\!KillBox\h0n0la5m1d.dll
C:\!KillBox\h0n0la5m1d.dll Deleted successfully!
Attempting to delete: C:\!KillBox\iogutil.dll
C:\!KillBox\iogutil.dll Deleted successfully!
Attempting to delete: C:\!KillBox\iwv6mon.dll
C:\!KillBox\iwv6mon.dll Deleted successfully!
Attempting to delete: C:\!KillBox\ixseng.dll
C:\!KillBox\ixseng.dll Deleted successfully!
Attempting to delete: C:\!KillBox\jt8s07l7e.dll
C:\!KillBox\jt8s07l7e.dll Deleted successfully!
Attempting to delete: C:\!KillBox\k4440ehqeh4e0.dll
C:\!KillBox\k4440ehqeh4e0.dll Deleted successfully!
Attempting to delete: C:\!KillBox\k8pmli7118.dll
C:\!KillBox\k8pmli7118.dll Deleted successfully!
Attempting to delete: C:\!KillBox\l26o0cj3efo.dll
C:\!KillBox\l26o0cj3efo.dll Deleted successfully!
Attempting to delete: C:\!KillBox\lvnu0959e.dll
C:\!KillBox\lvnu0959e.dll Deleted successfully!
Attempting to delete: C:\!KillBox\maastmib.dll
C:\!KillBox\maastmib.dll Deleted successfully!
Attempting to delete: C:\!KillBox\mlrating.dll
C:\!KillBox\mlrating.dll Deleted successfully!
Attempting to delete: C:\!KillBox\mpwmdm.dll
C:\!KillBox\mpwmdm.dll Deleted successfully!
Attempting to delete: C:\!KillBox\solwid.dll
C:\!KillBox\solwid.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000297.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000297.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000302.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000302.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000312.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000312.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000324.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000324.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000334.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000334.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000345.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000345.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000355.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000355.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000360.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000360.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000396.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000396.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001414.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001414.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001416.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001416.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001467.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001467.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001495.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001495.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001511.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001511.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001522.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001522.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002541.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002541.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002547.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002547.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002565.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002565.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002581.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002581.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002589.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002589.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0003589.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0003589.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004589.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004589.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004597.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004597.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004603.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004603.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004604.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004604.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004605.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004605.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004606.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004606.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004607.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004607.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004608.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004608.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004611.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004611.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004620.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004620.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004628.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004628.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005628.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005628.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005631.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005631.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005639.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005639.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005641.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005641.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005674.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005674.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005684.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005684.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005686.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005686.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005695.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005695.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0006693.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0006693.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0006695.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0006695.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0006703.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0006703.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007695.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007695.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007703.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007703.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007706.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007706.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007707.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007707.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007708.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007708.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007709.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007709.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007710.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007710.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007711.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007711.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007712.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007712.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007713.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007713.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007714.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007714.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007715.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007715.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007716.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007716.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007717.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007717.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007718.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007718.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007719.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007719.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007720.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007720.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007721.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007721.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007722.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007722.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007723.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007723.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007725.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007725.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C-1C120AAC30F2}\RP3\A0007733.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007733.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007735.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007735.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007743.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007743.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0008742.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0008742.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0009742.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0009742.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011742.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011742.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011745.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011745.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011746.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011746.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011747.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011747.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011755.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011755.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0012752.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0012752.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0012756.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0012756.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C-1C120AAC30F2}\RP3\A0012764.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C-1C120AAC30F2}\RP3\A0012764.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C-1C120AAC30F2}\RP3\A0013763.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C-1C120AAC30F2}\RP3\A0013763.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\c600lgdm160a.dll
C:\WINDOWS\system32\c600lgdm160a.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\cCpesnpn.dll
C:\WINDOWS\system32\cCpesnpn.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\dnru0199e.dll
C:\WINDOWS\system32\dnru0199e.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\h60qlgd5160.dll
C:\WINDOWS\system32\h60qlgd5160.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\ktr8l79u1.dll
C:\WINDOWS\system32\ktr8l79u1.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\m2ju0c19ef.dll
C:\WINDOWS\system32\m2ju0c19ef.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\mv8sl9l71.dll
C:\WINDOWS\system32\mv8sl9l71.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\n24slch71f4.dll
C:\WINDOWS\system32\n24slch71f4.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\q668lgju16o8.dll
C:\WINDOWS\system32\q668lgju16o8.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\r4r6le9s1h.dll
C:\WINDOWS\system32\r4r6le9s1h.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\t2r8lc9u1f.dll
C:\WINDOWS\system32\t2r8lc9u1f.dll Deleted successfully!
Making registry repairs.
Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\policies
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{BE7FC451-2B79-42E6-8408-3F28D7447790}"
HKCR\Clsid\{BE7FC451-2B79-42E6-8408-3F28D7447790}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{3334FE85-C609-4B41-B1C1-1E52CD79F1FC}"
HKCR\Clsid\{3334FE85-C609-4B41-B1C1-1E52CD79F1FC}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{96E0C116-31FD-4DB6-9228-6F91ABF97CBA}"
HKCR\Clsid\{96E0C116-31FD-4DB6-9228-6F91ABF97CBA}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{29068B4E-5D2F-4B88-B946-A272CA4A3E0E}"
HKCR\Clsid\{29068B4E-5D2F-4B88-B946-A272CA4A3E0E}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{7A1445DC-30A9-4F8D-9B4F-E039EE2B14EC}"
HKCR\Clsid\{7A1445DC-30A9-4F8D-9B4F-E039EE2B14EC}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{0F97195D-DFB2-44BB-9478-7AF687B7A2A3}"
HKCR\Clsid\{0F97195D-DFB2-44BB-9478-7AF687B7A2A3}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{59EE1164-21F9-4916-BF4B-4BF5E20379C0}"
HKCR\Clsid\{59EE1164-21F9-4916-BF4B-4BF5E20379C0}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{F01C7487-C6F7-4B3B-86E0-5CFB15A600FA}"
HKCR\Clsid\{F01C7487-C6F7-4B3B-86E0-5CFB15A600FA}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{A152C159-37D3-4080-94FE-9D697715D876}"
HKCR\Clsid\{A152C159-37D3-4080-94FE-9D697715D876}
Restoring Windows certificates.
Replaced hosts file with default windows hosts file
Restoring SeDebugPrivilege for Administrators - Succeeded
Hijack This Report
Logfile of HijackThis v1.99.1
Scan saved at 19:48:53, on 24/10/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\grand\Local Settings\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Planetis
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network
I was able to use the Look2Me Destroyer program without too many issues, I just restarted once because the computer was frozen.
Here are the reports:
The report Look2Me-Destroyer.txt was on the desktop ??
Look2Me-Destroyer V1.0.12
Scanning for infected files.....
Scan started at 24/10/2006 19:41:11
Infected! C:\WINDOWS\system32\c600lgdm160a.dll
Infected! C:\!KillBox\aysnt.dll
Infected! C:\!KillBox\aza0l9jm1.dll
Infected! C:\!KillBox\aza40ehqeh4e0.dll
Infected! C:\!KillBox\cucfg32.dll
Infected! C:\!KillBox\dwdlgs.dll
Infected! C:\!KillBox\e6020gdoe60c0.dll
Infected! C:\!KillBox\e6jmlg1116.dll
Infected! C:\!KillBox\fpro0393e.dll
Infected! C:\!KillBox\h0n0la5m1d.dll
Infected! C:\!KillBox\iogutil.dll
Infected! C:\!KillBox\iwv6mon.dll
Infected! C:\!KillBox\ixseng.dll
Infected! C:\!KillBox\jt8s07l7e.dll
Infected! C:\!KillBox\k4440ehqeh4e0.dll
Infected! C:\!KillBox\k8pmli7118.dll
Infected! C:\!KillBox\l26o0cj3efo.dll
Infected! C:\!KillBox\lvnu0959e.dll
Infected! C:\!KillBox\maastmib.dll
Infected! C:\!KillBox\mlrating.dll
Infected! C:\!KillBox\mpwmdm.dll
Infected! C:\!KillBox\solwid.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000297.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000302.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000312.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000324.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000334.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000345.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000355.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000360.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000396.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001414.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001416.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001467.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001495.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001511.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001522.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002541.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002547.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002565.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002581.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002589.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0003589.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004589.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004597.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004603.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004604.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004605.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004606.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004607.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004608.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004611.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004620.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004628.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005628.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005631.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005639.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005641.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005674.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005684.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005686.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005695.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0006693.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0006695.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0006703.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007695.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007703.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007706.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007707.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007708.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007709.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007710.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007711.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007712.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007713.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007714.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007715.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007716.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007717.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007718.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007719.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007720.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007721.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007722.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007723.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007725.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007733.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007735.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007743.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0008742.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0009742.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011742.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011745.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011746.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011747.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011755.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0012752.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0012756.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0012764.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0013763.dll
Infected! C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0014763.dll
Infected! C:\WINDOWS\system32\c600lgdm160a.dll
Infected! C:\WINDOWS\system32\cCpesnpn.dll
Infected! C:\WINDOWS\system32\dnru0199e.dll
Infected! C:\WINDOWS\system32\h60qlgd5160.dll
Infected! C:\WINDOWS\system32\ktr8l79u1.dll
Infected! C:\WINDOWS\system32\m2ju0c19ef.dll
Infected! C:\WINDOWS\system32\mv8sl9l71.dll
Infected! C:\WINDOWS\system32\n24slch71f4.dll
Infected! C:\WINDOWS\system32\q668lgju16o8.dll
Infected! C:\WINDOWS\system32\r4r6le9s1h.dll
Infected! C:\WINDOWS\system32\t2r8lc9u1f.dll
Attempting to delete infected files...
Attempting to delete: C:\WINDOWS\system32\c600lgdm160a.dll
C:\WINDOWS\system32\c600lgdm160a.dll Deleted successfully!
Attempting to delete: C:\!KillBox\aysnt.dll
C:\!KillBox\aysnt.dll Deleted successfully!
Attempting to delete: C:\!KillBox\aza0l9jm1.dll
C:\!KillBox\aza0l9jm1.dll Deleted successfully!
Attempting to delete: C:\!KillBox\aza40ehqeh4e0.dll
C:\!KillBox\aza40ehqeh4e0.dll Deleted successfully!
Attempting to delete: C:\!KillBox\cucfg32.dll
C:\!KillBox\cucfg32.dll Deleted successfully!
Attempting to delete: C:\!KillBox\dwdlgs.dll
C:\!KillBox\dwdlgs.dll Deleted successfully!
Attempting to delete: C:\!KillBox\e6020gdoe60c0.dll
C:\!KillBox\e6020gdoe60c0.dll Deleted successfully!
Attempting to delete: C:\!KillBox\e6jmlg1116.dll
C:\!KillBox\e6jmlg1116.dll Deleted successfully!
Attempting to delete: C:\!KillBox\fpro0393e.dll
C:\!KillBox\fpro0393e.dll Deleted successfully!
Attempting to delete: C:\!KillBox\h0n0la5m1d.dll
C:\!KillBox\h0n0la5m1d.dll Deleted successfully!
Attempting to delete: C:\!KillBox\iogutil.dll
C:\!KillBox\iogutil.dll Deleted successfully!
Attempting to delete: C:\!KillBox\iwv6mon.dll
C:\!KillBox\iwv6mon.dll Deleted successfully!
Attempting to delete: C:\!KillBox\ixseng.dll
C:\!KillBox\ixseng.dll Deleted successfully!
Attempting to delete: C:\!KillBox\jt8s07l7e.dll
C:\!KillBox\jt8s07l7e.dll Deleted successfully!
Attempting to delete: C:\!KillBox\k4440ehqeh4e0.dll
C:\!KillBox\k4440ehqeh4e0.dll Deleted successfully!
Attempting to delete: C:\!KillBox\k8pmli7118.dll
C:\!KillBox\k8pmli7118.dll Deleted successfully!
Attempting to delete: C:\!KillBox\l26o0cj3efo.dll
C:\!KillBox\l26o0cj3efo.dll Deleted successfully!
Attempting to delete: C:\!KillBox\lvnu0959e.dll
C:\!KillBox\lvnu0959e.dll Deleted successfully!
Attempting to delete: C:\!KillBox\maastmib.dll
C:\!KillBox\maastmib.dll Deleted successfully!
Attempting to delete: C:\!KillBox\mlrating.dll
C:\!KillBox\mlrating.dll Deleted successfully!
Attempting to delete: C:\!KillBox\mpwmdm.dll
C:\!KillBox\mpwmdm.dll Deleted successfully!
Attempting to delete: C:\!KillBox\solwid.dll
C:\!KillBox\solwid.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000297.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000297.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000302.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000302.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000312.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000312.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000324.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000324.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000334.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000334.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000345.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000345.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000355.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000355.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000360.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000360.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000396.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0000396.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001414.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001414.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001416.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001416.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001467.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001467.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001495.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001495.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001511.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001511.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001522.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0001522.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002541.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002541.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002547.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002547.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002565.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002565.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002581.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002581.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002589.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP2\A0002589.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0003589.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0003589.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004589.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004589.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004597.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004597.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004603.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004603.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004604.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004604.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004605.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004605.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004606.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004606.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004607.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004607.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004608.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004608.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004611.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004611.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004620.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004620.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004628.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0004628.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005628.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005628.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005631.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005631.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005639.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005639.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005641.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005641.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005674.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005674.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005684.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005684.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005686.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005686.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005695.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0005695.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0006693.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0006693.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0006695.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0006695.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0006703.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0006703.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007695.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007695.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007703.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007703.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007706.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007706.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007707.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007707.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007708.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007708.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007709.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007709.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007710.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007710.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007711.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007711.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007712.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007712.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007713.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007713.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007714.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007714.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007715.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007715.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007716.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007716.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007717.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007717.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007718.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007718.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007719.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007719.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007720.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007720.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007721.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007721.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007722.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007722.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007723.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007723.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007725.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007725.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C-1C120AAC30F2}\RP3\A0007733.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007733.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007735.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007735.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007743.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0007743.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0008742.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0008742.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0009742.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0009742.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011742.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011742.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011745.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011745.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011746.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011746.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011747.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011747.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011755.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0011755.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0012752.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0012752.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0012756.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3\A0012756.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C-1C120AAC30F2}\RP3\A0012764.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C-1C120AAC30F2}\RP3\A0012764.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C-1C120AAC30F2}\RP3\A0013763.dll
C:\System Volume Information\_restore{B2E81E50-A630-4002-822C-1C-1C120AAC30F2}\RP3\A0013763.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\c600lgdm160a.dll
C:\WINDOWS\system32\c600lgdm160a.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\cCpesnpn.dll
C:\WINDOWS\system32\cCpesnpn.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\dnru0199e.dll
C:\WINDOWS\system32\dnru0199e.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\h60qlgd5160.dll
C:\WINDOWS\system32\h60qlgd5160.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\ktr8l79u1.dll
C:\WINDOWS\system32\ktr8l79u1.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\m2ju0c19ef.dll
C:\WINDOWS\system32\m2ju0c19ef.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\mv8sl9l71.dll
C:\WINDOWS\system32\mv8sl9l71.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\n24slch71f4.dll
C:\WINDOWS\system32\n24slch71f4.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\q668lgju16o8.dll
C:\WINDOWS\system32\q668lgju16o8.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\r4r6le9s1h.dll
C:\WINDOWS\system32\r4r6le9s1h.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\t2r8lc9u1f.dll
C:\WINDOWS\system32\t2r8lc9u1f.dll Deleted successfully!
Making registry repairs.
Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\policies
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{BE7FC451-2B79-42E6-8408-3F28D7447790}"
HKCR\Clsid\{BE7FC451-2B79-42E6-8408-3F28D7447790}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{3334FE85-C609-4B41-B1C1-1E52CD79F1FC}"
HKCR\Clsid\{3334FE85-C609-4B41-B1C1-1E52CD79F1FC}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{96E0C116-31FD-4DB6-9228-6F91ABF97CBA}"
HKCR\Clsid\{96E0C116-31FD-4DB6-9228-6F91ABF97CBA}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{29068B4E-5D2F-4B88-B946-A272CA4A3E0E}"
HKCR\Clsid\{29068B4E-5D2F-4B88-B946-A272CA4A3E0E}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{7A1445DC-30A9-4F8D-9B4F-E039EE2B14EC}"
HKCR\Clsid\{7A1445DC-30A9-4F8D-9B4F-E039EE2B14EC}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{0F97195D-DFB2-44BB-9478-7AF687B7A2A3}"
HKCR\Clsid\{0F97195D-DFB2-44BB-9478-7AF687B7A2A3}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{59EE1164-21F9-4916-BF4B-4BF5E20379C0}"
HKCR\Clsid\{59EE1164-21F9-4916-BF4B-4BF5E20379C0}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{F01C7487-C6F7-4B3B-86E0-5CFB15A600FA}"
HKCR\Clsid\{F01C7487-C6F7-4B3B-86E0-5CFB15A600FA}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{A152C159-37D3-4080-94FE-9D697715D876}"
HKCR\Clsid\{A152C159-37D3-4080-94FE-9D697715D876}
Restoring Windows certificates.
Replaced hosts file with default windows hosts file
Restoring SeDebugPrivilege for Administrators - Succeeded
Hijack This Report
Logfile of HijackThis v1.99.1
Scan saved at 19:48:53, on 24/10/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\grand\Local Settings\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Planetis
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network
Hello
here is the requested Hijack This log
Logfile of HijackThis v1.99.1
Scan saved at 19:38:30, on 26/10/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Documents and Settings\grand\Local Settings\Temp\Temporary Directory 3 for hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Planetis
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O14 - IERESET.INF: START_PAGE_URL=www.packardbell.fr/center
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: McAfee Service Framework (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
PS:
If you want to reply to me, I am reachable until 10:30 PM tonight
after that, I am on vacation and unreachable until 11/5 included
Thank you
See you
gdf
here is the requested Hijack This log
Logfile of HijackThis v1.99.1
Scan saved at 19:38:30, on 26/10/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Documents and Settings\grand\Local Settings\Temp\Temporary Directory 3 for hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Planetis
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O14 - IERESET.INF: START_PAGE_URL=www.packardbell.fr/center
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: McAfee Service Framework (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
PS:
If you want to reply to me, I am reachable until 10:30 PM tonight
after that, I am on vacation and unreachable until 11/5 included
Thank you
See you
gdf
Hello,
here's what I get when I go to the link you gave me
Thank you for your interest in obtaining updates from our site.
To use this site, you must be running Microsoft Internet Explorer 5 or later.
To upgrade to the latest version of the browser, go to the Internet Explorer Downloads website.
If you prefer to use a different web browser, you can obtain updates from the Microsoft Download Center or you can stay up to date with the latest critical and security updates by using Automatic Updates. To turn on Automatic Updates:
1. Click Start, and then click Control Panel.
2. Depending on which Control Panel view you use, Classic or Category, do one of the following:
* Click System, and then click the Automatic Updates tab.
* Click Performance and Maintenance, click System, and then click the Automatic Updates tab.
3. Click the option that you want. Make sure Automatic Updates is not turned off.
It seems that you need to configure the updates through the control panel, I have done it and several updates have been performed, how can I know if everything is OK and if the SP2 pack is installed.
On the desktop, I still have the shortcuts
Online Dating
Free Online Music
Cheap Holiday Travel
plus the following icons
folder backregs and dlls
file echo.reg
can you confirm that I can delete all of this
Otherwise, it seems that there are no more unwanted connections on the various sites already mentioned.
VIRUS SCAN detected 4 viruses during an on-demand scan
a trojan A0004599.exe type DollarRevenue.gen which has been deleted
3 viruses A0004600.exe and A004601.exe detected as W32/Poebot.gen and A004602.exe detected as W32/Sdbot.worm.gen.z
they are all located in the following folder
c:\ System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3
what should I do to delete them
see you later
gdf
here's what I get when I go to the link you gave me
Thank you for your interest in obtaining updates from our site.
To use this site, you must be running Microsoft Internet Explorer 5 or later.
To upgrade to the latest version of the browser, go to the Internet Explorer Downloads website.
If you prefer to use a different web browser, you can obtain updates from the Microsoft Download Center or you can stay up to date with the latest critical and security updates by using Automatic Updates. To turn on Automatic Updates:
1. Click Start, and then click Control Panel.
2. Depending on which Control Panel view you use, Classic or Category, do one of the following:
* Click System, and then click the Automatic Updates tab.
* Click Performance and Maintenance, click System, and then click the Automatic Updates tab.
3. Click the option that you want. Make sure Automatic Updates is not turned off.
It seems that you need to configure the updates through the control panel, I have done it and several updates have been performed, how can I know if everything is OK and if the SP2 pack is installed.
On the desktop, I still have the shortcuts
Online Dating
Free Online Music
Cheap Holiday Travel
plus the following icons
folder backregs and dlls
file echo.reg
can you confirm that I can delete all of this
Otherwise, it seems that there are no more unwanted connections on the various sites already mentioned.
VIRUS SCAN detected 4 viruses during an on-demand scan
a trojan A0004599.exe type DollarRevenue.gen which has been deleted
3 viruses A0004600.exe and A004601.exe detected as W32/Poebot.gen and A004602.exe detected as W32/Sdbot.worm.gen.z
they are all located in the following folder
c:\ System Volume Information\_restore{B2E81E50-A630-4002-822C-1C120AAC30F2}\RP3
what should I do to delete them
see you later
gdf
Hi
Please give me a Hijack This, I'll check if SP2 is installed.
Yes, you can delete what's on the desktop
The infections are inactive...
¤Disable your system restore (only if you're on XP):
Right-click on My Computer, then
properties, click on the System Restore tab
check the box "Disable System Restore" and apply.
Then,
¤Reactivate your system restore (only if you're on XP):
Right-click on My Computer, then
properties, click on the System Restore tab
uncheck the box "Disable System Restore" and apply.
See you later
Please give me a Hijack This, I'll check if SP2 is installed.
Yes, you can delete what's on the desktop
The infections are inactive...
¤Disable your system restore (only if you're on XP):
Right-click on My Computer, then
properties, click on the System Restore tab
check the box "Disable System Restore" and apply.
Then,
¤Reactivate your system restore (only if you're on XP):
Right-click on My Computer, then
properties, click on the System Restore tab
uncheck the box "Disable System Restore" and apply.
See you later
Hi,
I have completed the requested manipulations
Here is the HijackThis report
Logfile of HijackThis v1.99.1
Scan saved at 20:58:46, on 07/11/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\mozilla.org\Mozilla\mozilla.exe
C:\Documents and Settings\grand\Local Settings\Temp\Temporary Directory 4 for hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Planetis
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O14 - IERESET.INF: START_PAGE_URL=www.packardbell.fr/center
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
a+
gdf
I have completed the requested manipulations
Here is the HijackThis report
Logfile of HijackThis v1.99.1
Scan saved at 20:58:46, on 07/11/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\mozilla.org\Mozilla\mozilla.exe
C:\Documents and Settings\grand\Local Settings\Temp\Temporary Directory 4 for hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Planetis
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O14 - IERESET.INF: START_PAGE_URL=www.packardbell.fr/center
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
a+
gdf
Hi,
apparently SP2 has been downloaded successfully
hijack log
Logfile of HijackThis v1.99.1
Scan saved at 22:56:16, on 08/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\msiexec.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
\?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE
C:\Program Files\mozilla.org\Mozilla\mozilla.exe
\?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE
C:\DOCUME~1\grand\LOCALS~1\Temp\Temporary directory 5 for hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Planetis
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=www.packardbell.fr/center
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Microsoft McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
I think everything is OK
see you
gdf
apparently SP2 has been downloaded successfully
hijack log
Logfile of HijackThis v1.99.1
Scan saved at 22:56:16, on 08/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\msiexec.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
\?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE
C:\Program Files\mozilla.org\Mozilla\mozilla.exe
\?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE
C:\DOCUME~1\grand\LOCALS~1\Temp\Temporary directory 5 for hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Planetis
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=www.packardbell.fr/center
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Microsoft McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
I think everything is OK
see you
gdf
- 1
- 2
Suivant
Logfile of HijackThis v1.99.1
Scan saved at 20:05:48, on 10/10/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\System32\msdtc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\grand\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.packardbell.fr/center
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.packardbell.fr/center
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Planetis
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\apps\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SurfairyHlp Class - {E0B9B5FE-B66E-4FB0-A1D9-726F0E743CFD} - C:\Program Files\Surfairy\SurfairyPP.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O9 - Extra button: Suggestions - {2223664C-1942-4276-9A2D-E8D8F547C5D2} - res://EffiPeled (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O14 - IERESET.INF: START_PAGE_URL=www.packardbell.fr/center
O20 - Winlogon Notify: EFS - C:\WINDOWS\SYSTEM32\sclgntfy.dll
hoping you can see something
thank you in advance
see you
gdf
Here are my data:
Logfile of HijackThis v1.99.1
Scan saved at 5:59:31 PM, on 11/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\TOSHIBA\Power Management\CeEPwrSvc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\PROGRA~1\EzButton\CPLDFL10.EXE
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DragDrop.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\DOCUME~1\admin\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [CPLDFL10] C:\PROGRA~1\EzButton\CPLDFL10.EXE
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Drag'n Drop CD+DVD] C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DragDrop.exe /StartUp
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O17 - HKLM\System\CCS\Services\Tcpip\..\{78A04BF5-EF63-43B7-B047-FFE85A3DC7A6}: NameServer = 85.255.115.77,85.255.112.159
O17 - HKLM\System\CCS\Services\Tcpip\..\{9F22C040-C162-4A4A-9BD5-379843DC9874}: NameServer = 85.255.115.77,85.255.112.159
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.77 85.255.112.159
O17 - HKLM\System\CS1\Services\Tcpip\..\{78A04BF5-EF63-43B7-B047-FFE85A3DC7A6}: NameServer = 85.255.115.77,85.255.112.159
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.115.77 85.255.112.159
O17 - HKLM\System\CS2\Services\Tcpip\..\{78A04BF5-EF63-43B7-B047-FFE85A3DC7A6}: NameServer = 85.255.115.77,85.255.112.159
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.77 85.255.112.159
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: CeEPwrSvc - COMPAL ELECTRONIC INC. - C:\Program Files\TOSHIBA\Power Management\CeEPwrSvc.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Service Framework McAfee (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Scan saved at 21:49:22, on 15/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\windows\system32\azvfjr.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\myagttry.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\linkprd.exe
C:\DOCUME~1\abdou\LOCALS~1\Temp\winlogon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\PROGRA~1\McAfee\MANAGE~1\VScan\McShield.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\HtmlDlg.Exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\abdou\LOCALS~1\Temp\Rar$EX16.221\HijackThis.exe
C:\WINDOWS\SoftwareDistribution\Download\8d31f6e93a03bc7a736602ed1adb9986\update\update.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SWEETIE Class - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CanalPlayer] C:\Program Files\CANALPLAY Player\CanalPlayer.exe /iconic
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [jtdyef] c:\windows\system32\jtdyef.exe jtdyef
O4 - HKLM\..\Run: [ugdccw] "C:\PROGRA~1\PCDRIV~1\UGDCcw.exe" -start
O4 - HKLM\..\Run: [ddasmjhdz] c:\windows\system32\ddasmjhdz.exe ddasmjhdz
O4 - HKLM\..\Run: [etircczx] c:\windows\system32\etircczx.exe etircczx
O4 - HKLM\..\Run: [etlzggn] c:\windows\system32\etlzggn.exe etlzggn
O4 - HKLM\..\Run: [azvfjr] c:\windows\system32\azvfjr.exe azvfjr
O4 - HKLM\..\Run: [MVS Splash] C:\Program Files\McAfee\Managed VirusScan\Agent\Splash.exe
O4 - HKLM\..\Run: [McAfee Managed Services Tray] "C:\Program Files\McAfee\Managed VirusScan\Agent\myagttry.exe"
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Instant Access] C:\WINDOWS\system32\linkprd.exe /res
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ssgrate.exe] C:\WINDOWS\system32\system.exe
O4 - HKCU\..\Run: [Firewall auto setup] C:\DOCUME~1\abdou\LOCALS~1\Temp\winlogon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Quick Launch of Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {201B9B37-848F-40BD-90EA-7B8F0AA89D6A} - http://us2-scripts.dlv4.com/binaries/egaccess4/egaccess4_1071_em_XP.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A8B8837E-EB2E-478C-B3BE-DC2FCBA3D219}: NameServer = 212.217.1.4 212.217.0.14
O20 - Winlogon Notify: rpcc - C:\WINDOWS\system32\rpcc.dll
O21 - SSODL: system32 - {0262E82C-2A91-47BB-8F5C-F5578F18933A} - sysprinters.dll (file missing)
O23 - Service: Boonty Games - Unknown owner - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe (file missing)
O23 - Service: McShield - McAfee, Inc. - C:\PROGRA~1\McAfee\MANAGE~1\VScan\McShield.exe
O23 - Service: McAfee Virus and Spyware Protection Service (myAgtSvc) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
O23 - Service: Card Adapter (NETDown) - Unknown owner - C:\WINDOWS\smss.exe (file missing)
--
End of file - 6876 bytes