Ok i did exactly what you told me to do.
This is the new Hjt log.
Logfile of HijackThis v1.99.1
Scan saved at 2:46:42 PM, on 5/17/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\gggg\Desktop\hijackthis\HijackThis.exe
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/Ms...Downloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://messenger.zone.msn.com/binary...o.cab32846.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) -
http://chat.msn.com/controls/msnchat45.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
and this is the other file that you told me to send.
L2mfix 051206
Creating Account.
The command completed successfully.
Adding Administrative privleges.
The command completed successfully.
Checking for L2MFix account(0=no 1=yes):
1
Granting SeDebugPrivilege to L2MFIX ... successful
Running From:
C:\WINDOWS\system32
Killing Processes!
Killing 'smss.exe'
\SystemRoot\System32\smss.exe (584)
Killing 'winlogon.exe'
winlogon.exe (676)
Killing 'explorer.exe'
C:\WINDOWS\Explorer.EXE (2328)
Killing 'rundll32.exe'
rundll32.exe "C:\WINDOWS\system32\mctlsapi.dll",DllGetVersion (1520)
Restoring Sedebugprivilege:
Granting SeDebugPrivilege to Administrators ... successful
Scanning First Pass. Please Wait!
First Pass Completed
Second Pass Scanning
Second pass Completed!
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
Deleting: C:\WINDOWS\system32\aza801hue.dll
Successfully Deleted: C:\WINDOWS\system32\aza801hue.dll
Deleting: C:\WINDOWS\system32\didmo.dll
Successfully Deleted: C:\WINDOWS\system32\didmo.dll
Deleting: C:\WINDOWS\system32\dn0401dqe.dll
Successfully Deleted: C:\WINDOWS\system32\dn0401dqe.dll
Deleting: C:\WINDOWS\system32\dn4801hue.dll
Successfully Deleted: C:\WINDOWS\system32\dn4801hue.dll
Deleting: C:\WINDOWS\system32\dn4o01h3e.dll
Successfully Deleted: C:\WINDOWS\system32\dn4o01h3e.dll
Deleting: C:\WINDOWS\system32\dnj8011ue.dll
Successfully Deleted: C:\WINDOWS\system32\dnj8011ue.dll
Deleting: C:\WINDOWS\system32\dnvvox.dll
Successfully Deleted: C:\WINDOWS\system32\dnvvox.dll
Deleting: C:\WINDOWS\system32\dtprpres.dll
Successfully Deleted: C:\WINDOWS\system32\dtprpres.dll
Deleting: C:\WINDOWS\system32\en4ol1h31.dll
Successfully Deleted: C:\WINDOWS\system32\en4ol1h31.dll
Deleting: C:\WINDOWS\system32\en68l1ju1.dll
Successfully Deleted: C:\WINDOWS\system32\en68l1ju1.dll
Deleting: C:\WINDOWS\system32\f02mlaf11d2.dll
Successfully Deleted: C:\WINDOWS\system32\f02mlaf11d2.dll
Deleting: C:\WINDOWS\system32\f0j20a1oed.dll
Successfully Deleted: C:\WINDOWS\system32\f0j20a1oed.dll
Deleting: C:\WINDOWS\system32\f2l0lc3m1f.dll
Successfully Deleted: C:\WINDOWS\system32\f2l0lc3m1f.dll
Deleting: C:\WINDOWS\system32\fp4803hue.dll
Successfully Deleted: C:\WINDOWS\system32\fp4803hue.dll
Deleting: C:\WINDOWS\system32\fppq0375e.dll
Successfully Deleted: C:\WINDOWS\system32\fppq0375e.dll
Deleting: C:\WINDOWS\system32\h04mlah11d4.dll
Successfully Deleted: C:\WINDOWS\system32\h04mlah11d4.dll
Deleting: C:\WINDOWS\system32\hr6m05j1e.dll
Successfully Deleted: C:\WINDOWS\system32\hr6m05j1e.dll
Deleting: C:\WINDOWS\system32\hrrq0595e.dll
Successfully Deleted: C:\WINDOWS\system32\hrrq0595e.dll
Deleting: C:\WINDOWS\system32\hTl.dll
Successfully Deleted: C:\WINDOWS\system32\hTl.dll
Deleting: C:\WINDOWS\system32\iksso.dll
Successfully Deleted: C:\WINDOWS\system32\iksso.dll
Deleting: C:\WINDOWS\system32\j60slgd7160.dll
Successfully Deleted: C:\WINDOWS\system32\j60slgd7160.dll
Deleting: C:\WINDOWS\system32\jnt500.dll
Successfully Deleted: C:\WINDOWS\system32\jnt500.dll
Deleting: C:\WINDOWS\system32\jr2025fmg.dll
Successfully Deleted: C:\WINDOWS\system32\jr2025fmg.dll
Deleting: C:\WINDOWS\system32\jt0m07d1e.dll
Successfully Deleted: C:\WINDOWS\system32\jt0m07d1e.dll
Deleting: C:\WINDOWS\system32\jtju0719e.dll
Successfully Deleted: C:\WINDOWS\system32\jtju0719e.dll
Deleting: C:\WINDOWS\system32\jtro0793e.dll
Successfully Deleted: C:\WINDOWS\system32\jtro0793e.dll
Deleting: C:\WINDOWS\system32\k426lefs1h26.dll
Successfully Deleted: C:\WINDOWS\system32\k426lefs1h26.dll
Deleting: C:\WINDOWS\system32\k8260ifse8260.dll
Successfully Deleted: C:\WINDOWS\system32\k8260ifse8260.dll
Deleting: C:\WINDOWS\system32\kkdbu.dll
Successfully Deleted: C:\WINDOWS\system32\kkdbu.dll
Deleting: C:\WINDOWS\system32\kt42l7ho1.dll
Successfully Deleted: C:\WINDOWS\system32\kt42l7ho1.dll
Deleting: C:\WINDOWS\system32\kt88l7lu1.dll
Successfully Deleted: C:\WINDOWS\system32\kt88l7lu1.dll
Deleting: C:\WINDOWS\system32\l68mlgl116q.dll
Successfully Deleted: C:\WINDOWS\system32\l68mlgl116q.dll
Deleting: C:\WINDOWS\system32\lDngwrbk.dll
Successfully Deleted: C:\WINDOWS\system32\lDngwrbk.dll
Deleting: C:\WINDOWS\system32\lvj6091se.dll
Successfully Deleted: C:\WINDOWS\system32\lvj6091se.dll
Deleting: C:\WINDOWS\system32\lvpq0975e.dll
Successfully Deleted: C:\WINDOWS\system32\lvpq0975e.dll
Deleting: C:\WINDOWS\system32\m0pola731d.dll
Successfully Deleted: C:\WINDOWS\system32\m0pola731d.dll
Deleting: C:\WINDOWS\system32\m628lgfu1628.dll
Successfully Deleted: C:\WINDOWS\system32\m628lgfu1628.dll
Deleting: C:\WINDOWS\system32\mctlsapi.dll
Successfully Deleted: C:\WINDOWS\system32\mctlsapi.dll
Deleting: C:\WINDOWS\system32\mkc42u.dll
Successfully Deleted: C:\WINDOWS\system32\mkc42u.dll
Deleting: C:\WINDOWS\system32\mv0ul9d91.dll
Successfully Deleted: C:\WINDOWS\system32\mv0ul9d91.dll
Deleting: C:\WINDOWS\system32\mv66l9js1.dll
Successfully Deleted: C:\WINDOWS\system32\mv66l9js1.dll
Deleting: C:\WINDOWS\system32\n48olel31hq.dll
Successfully Deleted: C:\WINDOWS\system32\n48olel31hq.dll
Deleting: C:\WINDOWS\system32\n4n60e5seh.dll
Successfully Deleted: C:\WINDOWS\system32\n4n60e5seh.dll
Deleting: C:\WINDOWS\system32\n6r2lg9o16.dll
Successfully Deleted: C:\WINDOWS\system32\n6r2lg9o16.dll
Deleting: C:\WINDOWS\system32\o084lalq1dqe.dll
Successfully Deleted: C:\WINDOWS\system32\o084lalq1dqe.dll
Deleting: C:\WINDOWS\system32\o8480ihue8480.dll
Successfully Deleted: C:\WINDOWS\system32\o8480ihue8480.dll
Deleting: C:\WINDOWS\system32\o8roli9318.dll
Successfully Deleted: C:\WINDOWS\system32\o8roli9318.dll
Deleting: C:\WINDOWS\system32\ofbc32.dll
Successfully Deleted: C:\WINDOWS\system32\ofbc32.dll
Deleting: C:\WINDOWS\system32\p6n80g5ue6.dll
Successfully Deleted: C:\WINDOWS\system32\p6n80g5ue6.dll
Deleting: C:\WINDOWS\system32\q868liju18o8.dll
Successfully Deleted: C:\WINDOWS\system32\q868liju18o8.dll
Deleting: C:\WINDOWS\system32\r8r60i9se8.dll
Successfully Deleted: C:\WINDOWS\system32\r8r60i9se8.dll
Deleting: C:\WINDOWS\system32\rpaenh.dll
Successfully Deleted: C:\WINDOWS\system32\rpaenh.dll
Deleting: C:\WINDOWS\system32\shmsg.dll
Successfully Deleted: C:\WINDOWS\system32\shmsg.dll
Deleting: C:\WINDOWS\system32\snsvc.dll
Successfully Deleted: C:\WINDOWS\system32\snsvc.dll
Deleting: C:\WINDOWS\system32\srsvcs.dll
Successfully Deleted: C:\WINDOWS\system32\srsvcs.dll
Deleting: C:\WINDOWS\system32\syclient.dll
Successfully Deleted: C:\WINDOWS\system32\syclient.dll
Deleting: C:\WINDOWS\system32\t0r80a9ued.dll
Successfully Deleted: C:\WINDOWS\system32\t0r80a9ued.dll
Deleting: C:\WINDOWS\system32\tvcfgwmi.dll
Successfully Deleted: C:\WINDOWS\system32\tvcfgwmi.dll
Deleting: C:\WINDOWS\system32\vvipxspx.dll
Successfully Deleted: C:\WINDOWS\system32\vvipxspx.dll
Deleting: C:\WINDOWS\system32\wwcltui.dll
Successfully Deleted: C:\WINDOWS\system32\wwcltui.dll
msg11?.dll
0 file(s) copied.
Restoring Windows Update Certificates.:
The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\RunOnce]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\h04mlah11d4.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
The following are the files found:
****************************************************************************
C:\WINDOWS\system32\aza801hue.dll
C:\WINDOWS\system32\didmo.dll
C:\WINDOWS\system32\dn0401dqe.dll
C:\WINDOWS\system32\dn4801hue.dll
C:\WINDOWS\system32\dn4o01h3e.dll
C:\WINDOWS\system32\dnj8011ue.dll
C:\WINDOWS\system32\dnvvox.dll
C:\WINDOWS\system32\dtprpres.dll
C:\WINDOWS\system32\en4ol1h31.dll
C:\WINDOWS\system32\en68l1ju1.dll
C:\WINDOWS\system32\f02mlaf11d2.dll
C:\WINDOWS\system32\f0j20a1oed.dll
C:\WINDOWS\system32\f2l0lc3m1f.dll
C:\WINDOWS\system32\fp4803hue.dll
C:\WINDOWS\system32\fppq0375e.dll
C:\WINDOWS\system32\h04mlah11d4.dll
C:\WINDOWS\system32\hr6m05j1e.dll
C:\WINDOWS\system32\hrrq0595e.dll
C:\WINDOWS\system32\hTl.dll
C:\WINDOWS\system32\iksso.dll
C:\WINDOWS\system32\j60slgd7160.dll
C:\WINDOWS\system32\jnt500.dll
C:\WINDOWS\system32\jr2025fmg.dll
C:\WINDOWS\system32\jt0m07d1e.dll
C:\WINDOWS\system32\jtju0719e.dll
C:\WINDOWS\system32\jtro0793e.dll
C:\WINDOWS\system32\k426lefs1h26.dll
C:\WINDOWS\system32\k8260ifse8260.dll
C:\WINDOWS\system32\kkdbu.dll
C:\WINDOWS\system32\kt42l7ho1.dll
C:\WINDOWS\system32\kt88l7lu1.dll
C:\WINDOWS\system32\l68mlgl116q.dll
C:\WINDOWS\system32\lDngwrbk.dll
C:\WINDOWS\system32\lvj6091se.dll
C:\WINDOWS\system32\lvpq0975e.dll
C:\WINDOWS\system32\m0pola731d.dll
C:\WINDOWS\system32\m628lgfu1628.dll
C:\WINDOWS\system32\mctlsapi.dll
C:\WINDOWS\system32\mkc42u.dll
C:\WINDOWS\system32\mv0ul9d91.dll
C:\WINDOWS\system32\mv66l9js1.dll
C:\WINDOWS\system32\n48olel31hq.dll
C:\WINDOWS\system32\n4n60e5seh.dll
C:\WINDOWS\system32\n6r2lg9o16.dll
C:\WINDOWS\system32\o084lalq1dqe.dll
C:\WINDOWS\system32\o8480ihue8480.dll
C:\WINDOWS\system32\o8roli9318.dll
C:\WINDOWS\system32\ofbc32.dll
C:\WINDOWS\system32\p6n80g5ue6.dll
C:\WINDOWS\system32\q868liju18o8.dll
C:\WINDOWS\system32\r8r60i9se8.dll
C:\WINDOWS\system32\rpaenh.dll
C:\WINDOWS\system32\shmsg.dll
C:\WINDOWS\system32\snsvc.dll
C:\WINDOWS\system32\srsvcs.dll
C:\WINDOWS\system32\syclient.dll
C:\WINDOWS\system32\t0r80a9ued.dll
C:\WINDOWS\system32\tvcfgwmi.dll
C:\WINDOWS\system32\vvipxspx.dll
C:\WINDOWS\system32\wwcltui.dll
Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{8019392E-DC2A-4BED-9F43-F6243967838F}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{8019392E-DC2A-4BED-9F43-F6243967838F}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{8019392E-DC2A-4BED-9F43-F6243967838F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{8019392E-DC2A-4BED-9F43-F6243967838F}\InprocServer32]
@="C:\\WINDOWS\\system32\\dSdim.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{FC7F5CEA-05CB-465C-ABA1-D7B1C0EE4B2E}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{FC7F5CEA-05CB-465C-ABA1-D7B1C0EE4B2E}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{FC7F5CEA-05CB-465C-ABA1-D7B1C0EE4B2E}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{FC7F5CEA-05CB-465C-ABA1-D7B1C0EE4B2E}\InprocServer32]
@="C:\\WINDOWS\\system32\\ofbc32.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{1C6CE0CE-2002-4B89-8DAC-0CDE79913848}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{1C6CE0CE-2002-4B89-8DAC-0CDE79913848}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{1C6CE0CE-2002-4B89-8DAC-0CDE79913848}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{1C6CE0CE-2002-4B89-8DAC-0CDE79913848}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{EA8EE447-1CC1-41BF-B312-BBE3CB0A208B}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{EA8EE447-1CC1-41BF-B312-BBE3CB0A208B}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{EA8EE447-1CC1-41BF-B312-BBE3CB0A208B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{EA8EE447-1CC1-41BF-B312-BBE3CB0A208B}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{7CB9B28D-9E01-47B7-9004-935D3045BBD9}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{7CB9B28D-9E01-47B7-9004-935D3045BBD9}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{7CB9B28D-9E01-47B7-9004-935D3045BBD9}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{7CB9B28D-9E01-47B7-9004-935D3045BBD9}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{7F4B12CD-251C-42E4-B559-1C2BAEF02F35}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{7F4B12CD-251C-42E4-B559-1C2BAEF02F35}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{7F4B12CD-251C-42E4-B559-1C2BAEF02F35}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{7F4B12CD-251C-42E4-B559-1C2BAEF02F35}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{09A084A8-4AE6-4450-9412-E8DFB63638CD}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{09A084A8-4AE6-4450-9412-E8DFB63638CD}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{09A084A8-4AE6-4450-9412-E8DFB63638CD}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{09A084A8-4AE6-4450-9412-E8DFB63638CD}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{60255E2B-E31B-4EAE-95DE-FA3881E35AA8}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{60255E2B-E31B-4EAE-95DE-FA3881E35AA8}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{60255E2B-E31B-4EAE-95DE-FA3881E35AA8}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{60255E2B-E31B-4EAE-95DE-FA3881E35AA8}\InprocServer32]
@="C:\\WINDOWS\\system32\\ogethk32.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{38B5FC10-606A-4145-A293-8C6CC4B29ABD}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{38B5FC10-606A-4145-A293-8C6CC4B29ABD}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{38B5FC10-606A-4145-A293-8C6CC4B29ABD}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{38B5FC10-606A-4145-A293-8C6CC4B29ABD}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{1B10A595-7C40-4099-A683-46E7E8536971}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{1B10A595-7C40-4099-A683-46E7E8536971}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{1B10A595-7C40-4099-A683-46E7E8536971}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{1B10A595-7C40-4099-A683-46E7E8536971}\InprocServer32]
@="C:\\WINDOWS\\system32\\mhang.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{D61C4824-C27C-47CB-BD69-04413524A275}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{D61C4824-C27C-47CB-BD69-04413524A275}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{D61C4824-C27C-47CB-BD69-04413524A275}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{D61C4824-C27C-47CB-BD69-04413524A275}\InprocServer32]
@="C:\\WINDOWS\\system32\\mctlsapi.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{68FB979E-6FD6-4E93-B485-3518D58EE8E0}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{68FB979E-6FD6-4E93-B485-3518D58EE8E0}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{68FB979E-6FD6-4E93-B485-3518D58EE8E0}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{68FB979E-6FD6-4E93-B485-3518D58EE8E0}\InprocServer32]
@="C:\\WINDOWS\\system32\\kydcz1.dll"
"ThreadingModel"="Apartment"
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{8019392E-DC2A-4BED-9F43-F6243967838F}"=-
"{177F85EF-CA11-476F-B74A-651A9ECF8AEB}"=-
"{FC7F5CEA-05CB-465C-ABA1-D7B1C0EE4B2E}"=-
"{1C6CE0CE-2002-4B89-8DAC-0CDE79913848}"=-
"{EA8EE447-1CC1-41BF-B312-BBE3CB0A208B}"=-
"{7CB9B28D-9E01-47B7-9004-935D3045BBD9}"=-
"{7F4B12CD-251C-42E4-B559-1C2BAEF02F35}"=-
"{09A084A8-4AE6-4450-9412-E8DFB63638CD}"=-
"{60255E2B-E31B-4EAE-95DE-FA3881E35AA8}"=-
"{38B5FC10-606A-4145-A293-8C6CC4B29ABD}"=-
"{1B10A595-7C40-4099-A683-46E7E8536971}"=-
"{D61C4824-C27C-47CB-BD69-04413524A275}"=-
"{68FB979E-6FD6-4E93-B485-3518D58EE8E0}"=-
[-HKEY_CLASSES_ROOT\CLSID\{8019392E-DC2A-4BED-9F43-F6243967838F}]
[-HKEY_CLASSES_ROOT\CLSID\{177F85EF-CA11-476F-B74A-651A9ECF8AEB}]
[-HKEY_CLASSES_ROOT\CLSID\{FC7F5CEA-05CB-465C-ABA1-D7B1C0EE4B2E}]
[-HKEY_CLASSES_ROOT\CLSID\{1C6CE0CE-2002-4B89-8DAC-0CDE79913848}]
[-HKEY_CLASSES_ROOT\CLSID\{EA8EE447-1CC1-41BF-B312-BBE3CB0A208B}]
[-HKEY_CLASSES_ROOT\CLSID\{7CB9B28D-9E01-47B7-9004-935D3045BBD9}]
[-HKEY_CLASSES_ROOT\CLSID\{7F4B12CD-251C-42E4-B559-1C2BAEF02F35}]
[-HKEY_CLASSES_ROOT\CLSID\{09A084A8-4AE6-4450-9412-E8DFB63638CD}]
[-HKEY_CLASSES_ROOT\CLSID\{60255E2B-E31B-4EAE-95DE-FA3881E35AA8}]
[-HKEY_CLASSES_ROOT\CLSID\{38B5FC10-606A-4145-A293-8C6CC4B29ABD}]
[-HKEY_CLASSES_ROOT\CLSID\{1B10A595-7C40-4099-A683-46E7E8536971}]
[-HKEY_CLASSES_ROOT\CLSID\{D61C4824-C27C-47CB-BD69-04413524A275}]
[-HKEY_CLASSES_ROOT\CLSID\{68FB979E-6FD6-4E93-B485-3518D58EE8E0}]
REGEDIT4
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"SV1"=""
****************************************************************************
Desktop.ini Contents:
****************************************************************************
****************************************************************************
Checking for L2MFix account(0=no 1=yes):
0
Zipping up files for submission:
adding: dlls/aza801hue.dll (164 bytes security) (deflated 4%)
adding: dlls/didmo.dll (164 bytes security) (deflated 5%)
adding: dlls/dn0401dqe.dll (164 bytes security) (deflated 4%)
adding: dlls/dn4801hue.dll (164 bytes security) (deflated 5%)
adding: dlls/dn4o01h3e.dll (164 bytes security) (deflated 5%)
adding: dlls/dnj8011ue.dll (164 bytes security) (deflated 4%)
adding: dlls/dnvvox.dll (164 bytes security) (deflated 6%)
adding: dlls/dtprpres.dll (164 bytes security) (deflated 4%)
adding: dlls/en4ol1h31.dll (164 bytes security) (deflated 6%)
adding: dlls/en68l1ju1.dll (164 bytes security) (deflated 5%)
adding: dlls/f02mlaf11d2.dll (164 bytes security) (deflated 5%)
adding: dlls/f0j20a1oed.dll (164 bytes security) (deflated 5%)
adding: dlls/f2l0lc3m1f.dll (164 bytes security) (deflated 5%)
adding: dlls/fp4803hue.dll (164 bytes security) (deflated 5%)
adding: dlls/fppq0375e.dll (164 bytes security) (deflated 4%)
adding: dlls/h04mlah11d4.dll (164 bytes security) (deflated 6%)
adding: dlls/hr6m05j1e.dll (164 bytes security) (deflated 4%)
adding: dlls/hrrq0595e.dll (164 bytes security) (deflated 6%)
adding: dlls/hTl.dll (164 bytes security) (deflated 5%)
adding: dlls/iksso.dll (164 bytes security) (deflated 6%)
adding: dlls/j60slgd7160.dll (164 bytes security) (deflated 5%)
adding: dlls/jnt500.dll (164 bytes security) (deflated 4%)
adding: dlls/jr2025fmg.dll (164 bytes security) (deflated 5%)
adding: dlls/jt0m07d1e.dll (164 bytes security) (deflated 4%)
adding: dlls/jtju0719e.dll (164 bytes security) (deflated 5%)
adding: dlls/jtro0793e.dll (164 bytes security) (deflated 4%)
adding: dlls/k426lefs1h26.dll (164 bytes security) (deflated 4%)
adding: dlls/k8260ifse8260.dll (164 bytes security) (deflated 5%)
adding: dlls/kkdbu.dll (164 bytes security) (deflated 6%)
adding: dlls/kt42l7ho1.dll (164 bytes security) (deflated 5%)
adding: dlls/kt88l7lu1.dll (164 bytes security) (deflated 4%)
adding: dlls/l68mlgl116q.dll (164 bytes security) (deflated 4%)
adding: dlls/lDngwrbk.dll (164 bytes security) (deflated 6%)
adding: dlls/lvj6091se.dll (164 bytes security) (deflated 6%)
adding: dlls/lvpq0975e.dll (164 bytes security) (deflated 5%)
adding: dlls/m0pola731d.dll (164 bytes security) (deflated 4%)
adding: dlls/m628lgfu1628.dll (164 bytes security) (deflated 5%)
adding: dlls/mctlsapi.dll (164 bytes security) (deflated 6%)
adding: dlls/mkc42u.dll (164 bytes security) (deflated 4%)
adding: dlls/mv0ul9d91.dll (164 bytes security) (deflated 5%)
adding: dlls/mv66l9js1.dll (164 bytes security) (deflated 5%)
adding: dlls/n48olel31hq.dll (164 bytes security) (deflated 4%)
adding: dlls/n4n60e5seh.dll (164 bytes security) (deflated 6%)
adding: dlls/n6r2lg9o16.dll (164 bytes security) (deflated 5%)
adding: dlls/o084lalq1dqe.dll (164 bytes security) (deflated 6%)
adding: dlls/o8480ihue8480.dll (164 bytes security) (deflated 6%)
adding: dlls/o8roli9318.dll (164 bytes security) (deflated 5%)
adding: dlls/ofbc32.dll (164 bytes security) (deflated 4%)
adding: dlls/p6n80g5ue6.dll (164 bytes security) (deflated 6%)
adding: dlls/q868liju18o8.dll (164 bytes security) (deflated 5%)
adding: dlls/r8r60i9se8.dll (164 bytes security) (deflated 5%)
adding: dlls/rpaenh.dll (164 bytes security) (deflated 5%)
adding: dlls/shmsg.dll (164 bytes security) (deflated 4%)
adding: dlls/snsvc.dll (164 bytes security) (deflated 6%)
adding: dlls/srsvcs.dll (164 bytes security) (deflated 5%)
adding: dlls/syclient.dll (164 bytes security) (deflated 5%)
adding: dlls/t0r80a9ued.dll (164 bytes security) (deflated 5%)
adding: dlls/tvcfgwmi.dll (164 bytes security) (deflated 6%)
adding: dlls/vvipxspx.dll (164 bytes security) (deflated 5%)
adding: dlls/wwcltui.dll (164 bytes security) (deflated 5%)
adding: backregs/09A084A8-4AE6-4450-9412-E8DFB63638CD.reg (212 bytes security) (deflated 70%)
adding: backregs/1B10A595-7C40-4099-A683-46E7E8536971.reg (212 bytes security) (deflated 70%)
adding: backregs/1C6CE0CE-2002-4B89-8DAC-0CDE79913848.reg (212 bytes security) (deflated 70%)
adding: backregs/38B5FC10-606A-4145-A293-8C6CC4B29ABD.reg (212 bytes security) (deflated 70%)
adding: backregs/60255E2B-E31B-4EAE-95DE-FA3881E35AA8.reg (212 bytes security) (deflated 70%)
adding: backregs/68FB979E-6FD6-4E93-B485-3518D58EE8E0.reg (212 bytes security) (deflated 70%)
adding: backregs/7CB9B28D-9E01-47B7-9004-935D3045BBD9.reg (212 bytes security) (deflated 70%)
adding: backregs/7F4B12CD-251C-42E4-B559-1C2BAEF02F35.reg (212 bytes security) (deflated 70%)
adding: backregs/8019392E-DC2A-4BED-9F43-F6243967838F.reg (212 bytes security) (deflated 70%)
adding: backregs/D61C4824-C27C-47CB-BD69-04413524A275.reg (212 bytes security) (deflated 70%)
adding: backregs/EA8EE447-1CC1-41BF-B312-BBE3CB0A208B.reg (212 bytes security) (deflated 70%)
adding: backregs/FC7F5CEA-05CB-465C-ABA1-D7B1C0EE4B2E.reg (212 bytes security) (deflated 70%)
adding: backregs/notibac.reg (164 bytes security) (deflated 87%)
adding: backregs/shell.reg (164 bytes security) (deflated 73%)