1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

DMVlite and other nasties [HijackThis log included]

Discussion in 'Malware and Virus Removal Archive' started by ASkinner, 2005/01/17.

Thread Status:
Not open for further replies.
  1. 2005/01/17
    ASkinner

    ASkinner Inactive Thread Starter

    Joined:
    2005/01/17
    Messages:
    12
    Likes Received:
    0
    Under attack! DMVlite and other nasties

    Spyware and up to date antivirus still wasn't enough and I got a dose last week of enough junk to shut me down. Back up now, just barely, but still got some ugly stuff--something that keeps turning off my antivirus program, DMVlite, wwwcoolstuff, endless popups, etc. Below is a my Hijack this log--can someone decode? Thanks!

    Logfile of HijackThis v1.99.0
    Scan saved at 10:14:14 PM, on 1/17/2005
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\LEXBCES.EXE
    C:\WINNT\system32\spoolsv.exe
    C:\WINNT\system32\LEXPPS.EXE
    C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    C:\WINNT\System32\svchost.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINNT\system32\msupd4.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\wanmpsvc.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
    C:\Program Files\Microsoft IntelliPoint\point32.exe
    C:\WINNT\system32\spool\DRIVERS\W32X86\2\printray.exe
    C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
    C:\WINNT\mmups.exe
    C:\Program Files\SED\SED.exe
    C:\WINNT\system32\wsxsvc\wsxsvc.exe
    C:\WINNT\system32\ctfmon.exe
    C:\Program Files\Nikon\NkView6\NkvMon.exe
    C:\Program Files\BellSouth\FastAccessConnectionAgent\fastacc.exe
    C:\WINNT\system32\rundll32.exe
    C:\PROGRA~1\VBouncer\VIRTUA~1.EXE
    C:\WINNT\explorer.exe
    C:\Program Files\HijackThis\HijackThis.exe
    C:\Program Files\Internet Explorer\iexplore.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: 69.20.16.183 auto.search.msn.com
    O1 - Hosts: 69.20.16.183 search.netscape.com
    O1 - Hosts: 69.20.16.183 ieautosearch
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {93196BC7-0695-FDE6-44B6-8F462B2B019F} - C:\WINNT\system32\gvkrinzr.dll
    O2 - BHO: (no name) - {D7EF944F-21EA-AE92-641D-B50DA532A27C} - C:\WINNT\system32\impjxxzq.dll
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe "
    O4 - HKLM\..\Run: [PrinTray] C:\WINNT\system32\spool\DRIVERS\W32X86\2\printray.exe
    O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe "
    O4 - HKLM\..\Run: [mediamotor.exe] C:\WINNT\mmups.exe
    O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe "
    O4 - HKLM\..\Run: [Dvx] C:\WINNT\system32\wsxsvc\wsxsvc.exe
    O4 - HKLM\..\Run: [kalvsys] C:\winnt\system32\kalvfcv32.exe
    O4 - HKLM\..\Run: [Uninstall_TBPS] C:\WINNT\Temp\TBuninst.exe /remove
    O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
    O4 - Startup: PowerReg Scheduler V3.exe
    O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
    O4 - Global Startup: pphyiu.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
    O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{9849CA52-6FB3-45A3-B2BA-F43030E5C020}: NameServer = 205.152.37.23 205.152.144.23
    O23 - Service: AOL Spyware Protection Service - Unknown - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe
    O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: LexBce Server - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
    O23 - Service: Miscrosoft Updates Service 4 - Unknown - C:\WINNT\system32\msupd4.exe
    O23 - Service: Symantec AntiVirus Client - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
    O23 - Service: WAN Miniport (ATW) Service - America Online, Inc. - C:\WINNT\wanmpsvc.exe
     
  2. 2005/01/18
    Admin.

    Admin. Administrator Administrator Staff

    Joined:
    2001/12/30
    Messages:
    6,687
    Likes Received:
    107
    Please follow Posting Rules (#3 - Meaningful Subject) when posting.

    I have adjusted your subject.
     

  3. to hide this advert.

  4. 2005/01/18
    ASkinner

    ASkinner Inactive Thread Starter

    Joined:
    2005/01/17
    Messages:
    12
    Likes Received:
    0
    Thanks for moving!

    Realized the error right after posting but didn't want to repost--
     
  5. 2005/01/18
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    You got some stuff that for sure needs to go away. My brain is fried right now but if no one has posted with details by mid-morning tomorrow (EST), I'll take a shot at it.
     
    Newt,
    #4
  6. 2005/01/19
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    Hi

    The easyest way to start this is as fallows:
    Familiarize yourself with how to start in safe mode and how to show hidden files and folders, if you don't already know how to, links below.
    Set windows to show hidden extensions, file's, folder's.
    >click here for instructions<.

    Run Hiajckthis and fix JUST this for now
    O23 - Service: Miscrosoft Updates Service 4 - Unknown - C:\WINNT\system32\msupd4.exe


    Start into safe mode
    http://www.microsoft.com/windows2000/techinfo/administration/management/safemode.asp

    Find and delete (ONLY THESE EXACT) files and folder's (If present)
    C:\WINNT\mmups.exe
    C:\Program Files\SED
    C:\WINNT\system32\wsxsvc
    C:\PROGRAM FILES\VBouncer
    C:\WINNT\system32\msupd4.exe
    C:\WINNT\system32\gvkrinzr.dll
    C:\WINNT\system32\impjxxzq.dll
    C:\winnt\system32\kalvfcv32.exe < there will be a coupel other with same dates, names slightly differant, example: kalv***32.exe
    Delete the contents of all your temp folders, as in. Open C:\ then >
    C:\documents and settings\(all your pc users)\local settings\temp
    Note: Some systems have temporary internet files, Application Data and History in that temp, if so leave them and delete all other folders and files inside that temp..
    Delete the contents of the C:\windows\temp folder

    Clear Internet Explorers's cache
    1. In Control Panel, open Internet Options.
    2. Click the General tab, and then under Temporary Internet files, click Delete Files.
    3. In the Delete Files dialog box, click to select the Delete all offline content check box.
    4. wait for the hourglass to disapear
    5. Click OK.


    Restart the PC back to a normal windows session


    Start Hijackthis and place a check next to these items,
    Close all browser windows and shut down all other programs that show in the taskbar. (even Folders) Hit fix checked and close Hijackthis.
    O2 - BHO: (no name) - {93196BC7-0695-FDE6-44B6-8F462B2B019F} - C:\WINNT\system32\gvkrinzr.dll
    O2 - BHO: (no name) - {D7EF944F-21EA-AE92-641D-B50DA532A27C} - C:\WINNT\system32\impjxxzq.dll
    O4 - HKLM\..\Run: [mediamotor.exe] C:\WINNT\mmups.exe
    O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe "
    O4 - HKLM\..\Run: [Dvx] C:\WINNT\system32\wsxsvc\wsxsvc.exe
    O4 - HKLM\..\Run: [kalvsys] C:\winnt\system32\kalvfcv32.exe
    O4 - HKLM\..\Run: [Uninstall_TBPS] C:\WINNT\Temp\TBuninst.exe /remove
    O4 - Startup: PowerReg Scheduler V3.exe
    ===============================

    Restart your C for those changes to take effect
    Download Find-qoologic.zip from here
    http://forums.skads.org/index.php?showtopic=89

    Unzip the the files open the qoologic folder, Then run qoologic.bat from there wait for it to finish. do not run it from inside a zip.
    it will take awhile wait untill the dos box disapears and disk activity stops at text will open, post that back here please along with a new hijackthis log.
     
  7. 2005/01/19
    ASkinner

    ASkinner Inactive Thread Starter

    Joined:
    2005/01/17
    Messages:
    12
    Likes Received:
    0
    Thank you

    Thank you so much for taking the time to do this, Lonny. I'm never sure these days if the computer is even going to boot up, and no matter how many times I run Adaware and Spybot, the stuff just keeps multiplying.

    I've printed out all the instructions and will do this after work tonight. Thanks again.
     
  8. 2005/01/19
    ASkinner

    ASkinner Inactive Thread Starter

    Joined:
    2005/01/17
    Messages:
    12
    Likes Received:
    0
    Followed your instructions and found most of the files you noted. Below is the new qoologic log; after that is a new hijackthis log.

    C:\Documents and Settings\CBS4\My Documents\qoologic\qoologic

    PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
    Files Found in system Folder............
    ------------------------
    C:\WINNT\system32\mmhpaz.exe: updates.qoologic.com
    C:\WINNT\system32\uuezno.dll: updates.qoologic.com
    C:\WINNT\system32\zzcgqy.dll: updates.qoologic.com
    C:\WINNT\system32\installer.exe: .aspack
    C:\WINNT\system32\oowygi.doc.exe: .aspack
    C:\WINNT\system32\oowygi.exe: .aspack
    C:\WINNT\system32\yypqka.dat: .aspack

    Files Found in all users startup Folder............
    ------------------------
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\pphyiu.exe: .aspack
    Files Found in all users windows Folder............
    ------------------------
    Finished

    ====================================

    Logfile of HijackThis v1.99.0
    Scan saved at 8:28:05 PM, on 1/19/2005
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\LEXBCES.EXE
    C:\WINNT\system32\spoolsv.exe
    C:\WINNT\system32\LEXPPS.EXE
    C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    C:\WINNT\System32\svchost.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\wanmpsvc.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\rundll32.exe
    C:\WINNT\Explorer.EXE
    C:\WINNT\system32\oowygi.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
    C:\Program Files\Microsoft IntelliPoint\point32.exe
    C:\WINNT\system32\spool\DRIVERS\W32X86\2\printray.exe
    C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
    C:\WINNT\system32\ctfmon.exe
    C:\Program Files\Nikon\NkView6\NkvMon.exe
    C:\Program Files\BellSouth\FastAccessConnectionAgent\fastacc.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: 69.20.16.183 auto.search.msn.com
    O1 - Hosts: 69.20.16.183 search.netscape.com
    O1 - Hosts: 69.20.16.183 ieautosearch
    O2 - BHO: (no name) - {93196BC7-0695-FDE6-44B6-8F462B2B019F} - (no file)
    O2 - BHO: (no name) - {D7EF944F-21EA-AE92-641D-B50DA532A27C} - (no file)
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe "
    O4 - HKLM\..\Run: [PrinTray] C:\WINNT\system32\spool\DRIVERS\W32X86\2\printray.exe
    O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe "
    O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
    O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O17 - HKLM\System\CCS\Services\Tcpip\..\{9849CA52-6FB3-45A3-B2BA-F43030E5C020}: NameServer = 205.152.37.23 205.152.144.23
    O23 - Service: AOL Spyware Protection Service - Unknown - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe
    O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: LexBce Server - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
    O23 - Service: Symantec AntiVirus Client - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
    O23 - Service: WAN Miniport (ATW) Service - America Online, Inc. - C:\WINNT\wanmpsvc.exe

    ===================
    I've checked the following items every time I run Hijackthis, but they always reappear--
    O1 - Hosts: 69.20.16.183 auto.search.msn.com
    O1 - Hosts: 69.20.16.183 search.netscape.com
    O1 - Hosts: 69.20.16.183 ieautosearch
    O2 - BHO: (no name) - {93196BC7-0695-FDE6-44B6-8F462B2B019F} - (no file)
    O2 - BHO: (no name) - {D7EF944F-21EA-AE92-641D-B50DA532A27C} - (no file)

    Thank you for doing this!

    A
     
  9. 2005/01/20
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    Hi, Dont be fixing things on your own.

    Please copy this to a text for referance


    1. [1] Download Pocket Killbox.version 2.0.0.76
      If you already have Killbox ensure its this version
      [2] Unzip the contents of KillBox.zip to a convenient location.
      [3] Close all Browsers and programs that show in the windows taskbar
      [4] Double-click on KillBox.exe.
      [5] Click "Delete on Reboot "
      [6] Copy/Paste (not type or browse) this file into the top "Full Path of File to Delete" box.

      C:\Documents and Settings\All Users\Start Menu\Programs\Startup\pphyiu.exe

      [7] Click the "Delete File" button which looks like a stop sign.
      [8] Click "Yes" at the Replace on Reboot prompt.
      [9] Click "No" at the Pending Operations prompt.
      [10] Repeat steps 5-9 above for these files >.

      C:\WINNT\system32\mmhpaz.exe
      C:\WINNT\system32\uuezno.dll
      C:\WINNT\system32\zzcgqy.dll
      C:\WINNT\system32\installer.exe
      C:\WINNT\system32\oowygi.doc.exe
      C:\WINNT\system32\oowygi.exe
      C:\WINNT\system32\yypqka.dat

      [11] Exit Killbox, restart your PC


    You have probaly already downloaded L2mfix, If so i need you to delete it and re-download since its being improved all the time.
    we almosr need to be in the forums t the same time for this to work correctly
    If possible wait untill later at night or early morning to post these logs.
    PS: Im in the USA

    Note: Once these logs are posted do not restart your pc untill suggested
    =====================================
    Download L2mfix from one of these two locations:

    http://www.atribune.org/downloads/l2mfix.exe
    http://www.downloads.subratam.org/l2mfix.exe

    Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.
    Once posted do not restart your pc untill suggested
    IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!

    Note to others, do not use this tool without assistance, the infection is always slightly differant.
    =================
    In another post to this thread
    Download Silent runners.Vbs post the log it creates please
    http://www.silentrunners.org/
    Your antivirus script protection might interfear, please allow it to run after a bit box will say done.
    Wait untill there is a finished message !!, Then open and post the log next to it.
    ====================
    Note: Dont restart your PC, If your not going to be available dont make and post them yet, if the pc's been restarted we need all new log's before gettng started
     
  10. 2005/01/20
    ASkinner

    ASkinner Inactive Thread Starter

    Joined:
    2005/01/17
    Messages:
    12
    Likes Received:
    0
    Woohoo! Progress!

    Did the Killbox leg of your last post. Running faster, cleaner, fewer popups, hijacks, etc. in the last couple of days since starting the process, Adaware finding only 23 bits of junk today, Spybot nothing (down from 250+ files on Adaware and dozens on Spybot). Got Lm2fix downloaded, but will wait to run and post log until last thing tonight. I'm on east coast time, so likely won't overlap with you in the evenings.

    Your help is going to save me a fortune in service calls, if not the price of a new computer! :)
     
  11. 2005/01/20
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    Ok, yes post the log later tonight,Im off for now.
    But redownload it at that time, they might have changed it again :)
     
  12. 2005/01/20
    ASkinner

    ASkinner Inactive Thread Starter

    Joined:
    2005/01/17
    Messages:
    12
    Likes Received:
    0
    L2mfix log

    L2MFIX find log 1.01
    These are the registry keys present
    **********************************************************************************
    Winlogon/notify:
    Windows Registry Editor Version 5.00

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
    "Asynchronous "=dword:00000000
    "Impersonate "=dword:00000000
    "DllName "=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
    6c,00,00,00
    "Logoff "= "ChainWlxLogoffEvent "

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
    "Asynchronous "=dword:00000000
    "Impersonate "=dword:00000000
    "DllName "=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
    6c,00,6c,00,00,00
    "Logoff "= "CryptnetWlxLogoffEvent "

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
    "DLLName "= "cscdll.dll "
    "Logon "= "WinlogonLogonEvent "
    "Logoff "= "WinlogonLogoffEvent "
    "ScreenSaver "= "WinlogonScreenSaverEvent "
    "Startup "= "WinlogonStartupEvent "
    "Shutdown "= "WinlogonShutdownEvent "
    "StartShell "= "WinlogonStartShellEvent "
    "Impersonate "=dword:00000000
    "Asynchronous "=dword:00000001

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
    "DllName "= "C:\\WINNT\\system32\\NavLogon.dll "
    "StartShell "= "NavStartShellEvent "
    "Logoff "= "NavLogoffEvent "

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
    "Logoff "= "WLEventLogoff "
    "Impersonate "=dword:00000000
    "Asynchronous "=dword:00000001
    "DllName "=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
    6c,00,6c,00,00,00

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
    "DLLName "= "WlNotify.dll "
    "Lock "= "SensLockEvent "
    "Logon "= "SensLogonEvent "
    "Logoff "= "SensLogoffEvent "
    "Safe "=dword:00000001
    "MaxWait "=dword:00000258
    "StartScreenSaver "= "SensStartScreenSaverEvent "
    "StopScreenSaver "= "SensStopScreenSaverEvent "
    "Startup "= "SensStartupEvent "
    "Shutdown "= "SensShutdownEvent "
    "StartShell "= "SensStartShellEvent "
    "Unlock "= "SensUnlockEvent "
    "Impersonate "=dword:00000001
    "Asynchronous "=dword:00000001

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WebCheck]
    "Asynchronous "=dword:00000000
    "DllName "= "C:\\WINNT\\system32\\irnsl5571.dll "
    "Impersonate "=dword:00000000
    "Logon "= "WinLogon "
    "Logoff "= "WinLogoff "
    "Shutdown "= "WinShutdown "

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
    "DLLName "= "wzcdlg.dll "
    "Logon "= "WZCEventLogon "
    "Logoff "= "WZCEventLogoff "
    "Impersonate "=dword:00000000
    "Asynchronous "=dword:00000000

    **********************************************************************************
    useragent:
    Windows Registry Editor Version 5.00

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
    "{C6348400-254A-4A06-B48E-3BEDF30E19CD} "=" "

    **********************************************************************************
    Files Found are not all bad files:

    C:\WINNT\SYSTEM32\
    afpmgmts.dll Wed Jan 19 2005 7:27:44p ..S.R 225,652 220.36 K
    akcore.dll Tue Jan 11 2005 9:25:06p A.... 188,416 184.00 K
    aklsp.dll Tue Jan 11 2005 9:25:12p A.... 196,608 192.00 K
    akrules.dll Tue Jan 11 2005 9:25:08p A.... 110,592 108.00 K
    akupd.dll Tue Jan 11 2005 9:24:56p A.... 155,648 152.00 K
    aqfsipc.dll Sat Jan 15 2005 1:31:26p ..S.R 224,012 218.76 K
    ciodm.dll Thu Nov 4 2004 11:41:52p A.... 68,880 67.27 K
    dwdskres.dll Thu Jan 20 2005 2:15:10p A.... 225,652 220.36 K
    e6jmlg~1.dll Tue Jan 18 2005 7:36:20a ..S.R 223,125 217.89 K
    elent.dll Fri Jan 14 2005 10:13:42p ..S.R 224,012 218.76 K
    en8ul1~1.dll Wed Jan 19 2005 10:11:18p ..S.R 226,203 220.90 K
    hypertrm.dll Tue Nov 16 2004 5:47:02a A.... 576,784 563.27 K
    irnsl5~1.dll Thu Jan 20 2005 12:47:34p ..S.R 225,652 220.36 K
    jr4025~1.dll Mon Jan 17 2005 8:58:40a ..S.R 226,057 220.76 K
    jrj025~1.dll Thu Jan 20 2005 1:10:34p ..S.R 225,652 220.36 K
    jtru07~1.dll Sat Jan 15 2005 12:31:30p ..S.R 225,357 220.07 K
    mfoeacct.dll Wed Jan 12 2005 6:52:20a ..S.R 224,012 218.76 K
    mlrle32.dll Mon Jan 17 2005 8:58:42a ..S.R 224,012 218.76 K
    mshtml.dll Mon Oct 25 2004 10:39:16a A.... 2,693,120 2.57 M
    nttapi32.dll Wed Jan 12 2005 8:05:20p ..S.R 225,357 220.07 K
    rdsauth.dll Wed Jan 12 2005 6:35:26p ..S.R 224,012 218.76 K
    rhsauth.dll Wed Jan 19 2005 7:20:44p ..S.R 225,652 220.36 K
    shdocvw.dll Thu Nov 11 2004 11:20:56p A.... 1,332,224 1.27 M
    sp3res.dll Thu Dec 2 2004 9:27:18a ..... 6,272,512 5.98 M
    sporder.dll Tue Jan 11 2005 9:25:08p A.... 8,464 8.27 K
    svmapi.dll Fri Jan 14 2005 10:33:30p ..S.R 225,357 220.07 K
    urlmon.dll Mon Oct 25 2004 10:39:52a A.... 450,048 439.50 K
    user32.dll Wed Dec 29 2004 4:14:10a A.... 380,688 371.77 K
    uuezno.dll Thu Jan 20 2005 2:15:30p A.... 24,576 24.00 K
    zzcgqy.dll Thu Jan 20 2005 12:58:48p A.... 5,632 5.50 K

    30 items found: 30 files (15 H/S), 0 directories.
    Total of file sizes: 16,063,968 bytes 15.32 M
    Locate .tmp files:

    No matches found.
    **********************************************************************************
    Directory Listing of system files:
    Volume in drive C is CDC-139363
    Volume Serial Number is 3487-3804

    Directory of C:\WINNT\System32

    01/20/2005 01:10p 225,652 jrj0251mg.dll
    01/20/2005 12:47p 225,652 irnsl5571.dll
    01/19/2005 10:11p 226,203 en8ul1l91.dll
    01/19/2005 07:27p 225,652 afpmgmts.dll
    01/19/2005 07:20p 225,652 rHsauth.dll
    01/18/2005 10:07p <DIR> dllcache
    01/18/2005 07:36a 223,125 e6jmlg1116.dll
    01/17/2005 08:58a 224,012 mlrle32.dll
    01/17/2005 08:58a 226,057 jr4025hmg.dll
    01/15/2005 01:31p 224,012 aqfsipc.dll
    01/15/2005 12:31p 225,357 jtru0799e.dll
    01/14/2005 10:33p 225,357 svmapi.dll
    01/14/2005 10:13p 224,012 elent.dll
    01/12/2005 08:05p 225,357 NTTAPI32.DLL
    01/12/2005 06:35p 224,012 rDsauth.dll
    01/12/2005 06:52a 224,012 MFOEACCT.DLL
    15 File(s) 3,374,124 bytes
    1 Dir(s) 15,325,925,376 bytes free
     
  13. 2005/01/21
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    Hi

    Please delete l2mfix and zip, they have just improved it again, (sorry)
    Download L2mfix from one of these two locations:
    (version 1.02 as of1/21/2005)
    http://www.atribune.org/downloads/l2mfix.exe
    http://www.downloads.subratam.org/l2mfix.exe

    Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

    IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!

    Once posted do not restart your pc untill suggested

    Note to others, do not use this tool without assistance, the infection is always slightly differant.
     
  14. 2005/01/21
    BillyBob Lifetime Subscription

    BillyBob Inactive

    Joined:
    2002/01/07
    Messages:
    6,048
    Likes Received:
    0
    Wait for confirmation from Lonny Jones as he is handling things right now.

    But once you get the machine cleaned up [I think it is a good idea to DESTROYANY AND ALL types of backups.

    If using XP shut down and restart System Restore.

    Other wise you may well be WASTING your time.

    Again. Wait for Lonny.

    BillyBob
     
  15. 2005/01/24
    ASkinner

    ASkinner Inactive Thread Starter

    Joined:
    2005/01/17
    Messages:
    12
    Likes Received:
    0
    Got a REAL virus

    Sorry I didn't get the l2mfix done this weekend--got taken out by one of the kid's bugs. I'll get it done this evening if I get out of the office before midnight!

    Thanks guys. Ad-aware hits are starting to climb again in spite of spyware blaster and the clean up, --don't know if I'm picking up new stuff or the old stuff is just multiplying.
     
  16. 2005/01/24
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    Ok wait and make a new log when your ready. Limit internet time, that nastie Install's and attracts other ****
     
  17. 2005/01/25
    ASkinner

    ASkinner Inactive Thread Starter

    Joined:
    2005/01/17
    Messages:
    12
    Likes Received:
    0
    L2mfix Log

    THE LOG IS TOO LONG TO POST ALL HERE. THIS IS PART 1:

    L2MFIX find log 1.02
    These are the registry keys present
    Winlogon/notify:
    Windows Registry Editor Version 5.00
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
    "Asynchronous "=dword:00000000
    "Impersonate "=dword:00000000
    "DllName "=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
    6c,00,00,00
    "Logoff "= "ChainWlxLogoffEvent "

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
    "Asynchronous "=dword:00000000
    "Impersonate "=dword:00000000
    "DllName "=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
    6c,00,6c,00,00,00
    "Logoff "= "CryptnetWlxLogoffEvent "
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
    "DLLName "= "cscdll.dll "
    "Logon "= "WinlogonLogonEvent "
    "Logoff "= "WinlogonLogoffEvent "
    "ScreenSaver "= "WinlogonScreenSaverEvent "
    "Startup "= "WinlogonStartupEvent "
    "Shutdown "= "WinlogonShutdownEvent "
    "StartShell "= "WinlogonStartShellEvent "
    "Impersonate "=dword:00000000
    "Asynchronous "=dword:00000001
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
    "DllName "= "C:\\WINNT\\system32\\NavLogon.dll "
    "StartShell "= "NavStartShellEvent "
    "Logoff "= "NavLogoffEvent "
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
    "Logoff "= "WLEventLogoff "
    "Impersonate "=dword:00000000
    "Asynchronous "=dword:00000001
    "DllName "=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
    6c,00,6c,00,00,00
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
    "DLLName "= "WlNotify.dll "
    "Lock "= "SensLockEvent "
    "Logon "= "SensLogonEvent "
    "Logoff "= "SensLogoffEvent "
    "Safe "=dword:00000001
    "MaxWait "=dword:00000258
    "StartScreenSaver "= "SensStartScreenSaverEvent "
    "StopScreenSaver "= "SensStopScreenSaverEvent "
    "Startup "= "SensStartupEvent "
    "Shutdown "= "SensShutdownEvent "
    "StartShell "= "SensStartShellEvent "
    "Unlock "= "SensUnlockEvent "
    "Impersonate "=dword:00000001
    "Asynchronous "=dword:00000001
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ShellCompatibility]
    "Asynchronous "=dword:00000000
    "DllName "= "C:\\WINNT\\system32\\m046lahs1d46.dll "
    "Impersonate "=dword:00000000
    "Logon "= "WinLogon "
    "Logoff "= "WinLogoff "
    "Shutdown "= "WinShutdown "
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
    "DLLName "= "wzcdlg.dll "
    "Logon "= "WZCEventLogon "
    "Logoff "= "WZCEventLogoff "
    "Impersonate "=dword:00000000
    "Asynchronous "=dword:00000000

    useragent: Windows Registry Editor Version 5.00
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
    "{C6348400-254A-4A06-B48E-3BEDF30E19CD} "=" "


    Shell Extension key: Windows Registry Editor Version 5.00
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
    "{00022613-0000-0000-C000-000000000046} "= "Multimedia File Property Sheet "
    "{176d6597-26d3-11d1-b350-080036a75b03} "= "ICM Scanner Management "
    "{1F2E5C40-9550-11CE-99D2-00AA006E086C} "= "NTFS Security Page "
    "{3EA48300-8CF6-101B-84FB-666CCB9BCD32} "= "OLE Docfile Property Page "
    "{40dd6e20-7c17-11ce-a804-00aa003ca9f6} "= "Shell extensions for sharing "
    "{41E300E0-78B6-11ce-849B-444553540000} "= "PlusPack CPL Extension "
    "{42071712-76d4-11d1-8b24-00a0c9068ff3} "= "Display Adapter CPL Extension "
    "{42071713-76d4-11d1-8b24-00a0c9068ff3} "= "Display Monitor CPL Extension "
    "{42071714-76d4-11d1-8b24-00a0c9068ff3} "= "Display Panning CPL Extension "
    "{4E40F770-369C-11d0-8922-00A024AB2DBB} "= "DS Security Page "
    "{56117100-C0CD-101B-81E2-00AA004AE837} "= "Shell Scrap DataHandler "
    "{59099400-57FF-11CE-BD94-0020AF85B590} "= "Disk Copy Extension "
    "{59be4990-f85c-11ce-aff7-00aa003ca9f6} "= "Shell extensions for Microsoft Windows Network objects "
    "{5DB2625A-54DF-11D0-B6C4-0800091AA605} "= "ICM Monitor Management "
    "{675F097E-4C4D-11D0-B6C1-0800091AA605} "= "ICM Printer Management "
    "{764BF0E1-F219-11ce-972D-00AA00A14F56} "= "Shell extensions for file compression "
    "{77597368-7b15-11d0-a0c2-080036af3f03} "= "Web Printer Shell Extension "
    "{7988B573-EC89-11cf-9C00-00AA00A14F56} "= "Disk Quota UI "
    "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} "= "Encryption Context Menu "
    "{85BBD920-42A0-1069-A2E4-08002B30309D} "= "Briefcase "
    "{88895560-9AA2-1069-930E-00AA0030EBC8} "= "HyperTerminal Icon Ext "
    "{BD84B380-8CA2-1069-AB1D-08000948F534} "= "Fonts "
    "{DBCE2480-C732-101B-BE72-BA78E9AD5B27} "= "ICC Profile "
    "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723} "= "Printers Security Page "
    "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} "= "Shell extensions for sharing "
    "{f92e8c40-3d33-11d2-b1aa-080036a75b03} "= "Display TroubleShoot CPL Extension "
    "{60254CA5-953B-11CF-8C96-00AA00B8708C} "= "Shell extensions for Windows Script Host "
    "{7444C717-39BF-11D1-8CD9-00C04FC29D45} "= "Crypto PKO Extension "
    "{7444C719-39BF-11D1-8CD9-00C04FC29D45} "= "Crypto Sign Extension "
    "{7007ACC7-3202-11D1-AAD2-00805FC1270E} "= "Network and Dial-up Connections "
    "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF} "= "Tasks Folder Icon Handler "
    "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF} "= "Tasks Folder Shell Extension "
    "{D6277990-4C6A-11CF-8D87-00AA0060F5BF} "= "Scheduled Tasks "
    "{1A9BA3A0-143A-11CF-8350-444553540000} "= "Shell Favorite Folder "
    "{20D04FE0-3AEA-1069-A2D8-08002B30309D} "= "My Computer "
    "{86747AC0-42A0-1069-A2E6-08002B30309D} "= "Briefcase Folder "
    "{0AFACED1-E828-11D1-9187-B532F1E9575D} "= "Folder Shortcut "
    "{12518493-00B2-11d2-9FA5-9E3420524153} "= "Mounted Volume "
    "{21B22460-3AEA-1069-A2DC-08002B30309D} "= "File Property Page Extension "
    "{B091E540-83E3-11CF-A713-0020AFD79762} "= "File Types Page "
    "{FBF23B41-E3F0-101B-8488-00AA003E56F8} "= "MIME File Types Hook "
    "{C2FBB630-2971-11d1-A18C-00C04FD75D13} "= "Microsoft CopyTo Service "
    "{C2FBB631-2971-11d1-A18C-00C04FD75D13} "= "Microsoft MoveTo Service "
    "{13709620-C279-11CE-A49E-444553540000} "= "Shell Automation Service "
    "{62112AA1-EBE4-11cf-A5FB-0020AFE7292D} "= "Shell Automation Folder View "
    "{4622AD11-FF23-11d0-8D34-00A0C90F2719} "= "Start Menu "
    "{7BA4C740-9E81-11CF-99D3-00AA004AE837} "= "Microsoft SendTo Service "
    "{D969A300-E7FF-11d0-A93B-00A0C90F2719} "= "Microsoft New Object Service "
    "{09799AFB-AD67-11d1-ABCD-00C04FC30936} "= "Open With Context Menu Handler "
    "{3FC0B520-68A9-11D0-8D77-00C04FD70822} "= "Display Control Panel HTML Extensions "
    "{75048700-EF1F-11D0-9888-006097DEACF9} "= "ActiveDesktop "
    "{6D5313C0-8C62-11D1-B2CD-006097DF8C11} "= "Folder Options Property Page Extension "
    "{57651662-CE3E-11D0-8D77-00C04FC99D61} "= "CmdFileIcon "
    "{4657278A-411B-11d2-839A-00C04FD918D0} "= "Shell Drag and Drop helper "
    "{A470F8CF-A1E8-4f65-8335-227475AA5C46} "= "Add encryption item to context menus in explorer "
    "{5E6AB780-7743-11CF-A12B-00AA004AE837} "= "Microsoft Internet Toolbar "
    "{22BF0C20-6DA7-11D0-B373-00A0C9034938} "= "Download Status "
    "{568804CA-CBD7-11d0-9816-00C04FD91972} "= "Menu Shell Folder "
    "{5b4dae26-b807-11d0-9815-00c04fd91972} "= "Menu Band "
    "{8278F931-2A3E-11d2-838F-00C04FD918D0} "= "Tracking Shell Menu "
    "{E13EF4E4-D2F2-11d0-9816-00C04FD91972} "= "Menu Site "
    "{ECD4FC4F-521C-11D0-B792-00A0C90312E1} "= "Menu Desk Bar "
    "{91EA3F8B-C99B-11d0-9815-00C04FD91972} "= "Augmented Shell Folder "
    "{6413BA2C-B461-11d1-A18A-080036B11A03} "= "Augmented Shell Folder 2 "
    "{F61FFEC1-754F-11d0-80CA-00AA005B4383} "= "BandProxy "
    "{D82BE2B0-5764-11D0-A96E-00C04FD705A2} "= "IShellFolderBand "
    "{7BA4C742-9E81-11CF-99D3-00AA004AE837} "= "Microsoft BrowserBand "
    "{30D02401-6A81-11d0-8274-00C04FD5AE38} "= "Search Band "
    "{169A0691-8DF9-11d1-A1C4-00C04FD75D13} "= "In-pane search "
    "{07798131-AF23-11d1-9111-00A0C98BA67D} "= "Web Search "
    "{0E5CBF21-D15F-11d0-8301-00AA005B4383} "= "&Links "
    "{AF4F6510-F982-11d0-8595-00AA004CD6D8} "= "Registry Tree Options Utility "
    "{01E04581-4EEE-11d0-BFE9-00AA005B4383} "= "&Address "
    "{A08C11D2-A228-11d0-825B-00AA005B4383} "= "Address EditBox "
    "{00BB2763-6A77-11D0-A535-00C04FD7D062} "= "Microsoft AutoComplete "
    "{7487cd30-f71a-11d0-9ea7-00805f714772} "= "Thumbnail Image "
    "{7376D660-C583-11d0-A3A5-00C04FD706EC} "= "TridentImageExtractor "
    "{6756A641-DE71-11d0-831B-00AA005B4383} "= "MRU AutoComplete List "
    "{00BB2764-6A77-11D0-A535-00C04FD7D062} "= "Microsoft History AutoComplete List "
    "{03C036F1-A186-11D0-824A-00AA005B4383} "= "Microsoft Shell Folder AutoComplete List "
    "{00BB2765-6A77-11D0-A535-00C04FD7D062} "= "Microsoft Multiple AutoComplete List Container "
    "{ECD4FC4E-521C-11D0-B792-00A0C90312E1} "= "Shell Band Site Menu "
    "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF} "= "Shell DeskBarApp "
    "{ECD4FC4C-521C-11D0-B792-00A0C90312E1} "= "Shell DeskBar "
    "{ECD4FC4D-521C-11D0-B792-00A0C90312E1} "= "Shell Rebar BandSite "
    "{DD313E04-FEFF-11d1-8ECD-0000F87A470C} "= "User Assist "
    "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} "= "Global Folder Settings "
    "{EFA24E61-B078-11d0-89E4-00C04FC9E26E} "= "Favorites Band "
    "{0A89A860-D7B1-11CE-8350-444553540000} "= "Shell Automation Inproc Service "
    "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} "= "Shell DocObject Viewer "
    "{FBF23B40-E3F0-101B-8488-00AA003E56F8} "= "InternetShortcut "
    "{3C374A40-BAE4-11CF-BF7D-00AA006946EE} "= "Microsoft Url History Service "
    "{FF393560-C2A7-11CF-BFF4-444553540000} "= "History "
    "{7BD29E00-76C1-11CF-9DD0-00A0C9034933} "= "Temporary Internet Files "
    "{CFBFAE00-17A6-11D0-99CB-00C04FD64497} "= "Microsoft Url Search Hook "
    "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC} "= "IE4 Suite Splash Screen "
    "{67EA19A0-CCEF-11d0-8024-00C04FD75D13} "= "CDF Extension Copy Hook "
    "{131A6951-7F78-11D0-A979-00C04FD705A2} "= "ISFBand OC "
    "{9461b922-3c5a-11d2-bf8b-00c04fb93661} "= "Search Assistant OC "
    "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837} "= "The Internet "
    "{871C5380-42A0-1069-A2EA-08002B30309D} "= "Internet Name Space "
    "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE} "= "Sendmail service "
    "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE} "= "Sendmail service "
    "{88C6C381-2E85-11D0-94DE-444553540000} "= "ActiveX Cache Folder "
    "{E6FB5E20-DE35-11CF-9C87-00AA005127ED} "= "WebCheck "
    "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE} "= "Subscription Mgr "
    "{F5175861-2688-11d0-9C5E-00AA00A45957} "= "Subscription Folder "
    "{08165EA0-E946-11CF-9C87-00AA005127ED} "= "WebCheckWebCrawler "
    "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB} "= "WebCheckChannelAgent "
    "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7} "= "TrayAgent "
    "{7D559C10-9FE9-11d0-93F7-00AA0059CE02} "= "Code Download Agent "
    "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE} "= "ConnectionAgent "
    "{D8BD2030-6FC9-11D0-864F-00AA006809D9} "= "PostAgent "
    "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB} "= "WebCheck SyncMgr Handler "
    "{8BEBB290-52D0-11D0-B7F4-00C04FD706EC} "= "Thumbnails "
    "{EAB841A0-9550-11CF-8C16-00805F1408F3} "= "HTML Thumbnail Extractor "
    "{1AEB1360-5AFC-11D0-B806-00C04FD706EC} "= "Office Graphics Filters Thumbnail Extractor "
    "{9DBD2C50-62AD-11D0-B806-00C04FD706EC} "= "Summary Info Thumbnail handler (DOCFILES) "
    "{500202A0-731E-11D0-B829-00C04FD706EC} "= "LNK file thumbnail interface delegator "
    "{352EC2B7-8B9A-11D1-B8AE-006008059382} "= "Shell Application Manager "
    "{0B124F8C-91F0-11D1-B8B5-006008059382} "= "Installed Apps Enumerator "
    "{CFCCC7A0-A282-11D1-9082-006008059382} "= "Darwin App Publisher "
    "{fe1290f0-cfbd-11cf-a330-00aa00c16e65} "= "Directory Namespace "
    "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86} "= "Shell properties for a DS object "
    "{8A23E65E-31C2-11d0-891C-00A024AB2DBB} "= "Directory Query UI "
    "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB} "= "Directory Object Find "
    "{F020E586-5264-11d1-A532-0000F8757D7E} "= "Directory Start/Search Find "
    "{0D45D530-764B-11d0-A1CA-00AA00C16E65} "= "Directory Property UI "
    "{62AE1F9A-126A-11D0-A14B-0800361B1103} "= "Directory Context Menu Verbs "
    "{450D8FBA-AD25-11D0-98A8-0800361B1103} "= "MyDocs Folder "
    "{ECF03A33-103D-11d2-854D-006008059367} "= "MyDocs Copy Hook "
    "{ECF03A32-103D-11d2-854D-006008059367} "= "MyDocs Drop Target "
    "{4a7ded0a-ad25-11d0-98a8-0800361b1103} "= "MyDocs Properties "
    "{750fdf0e-2a26-11d1-a3ea-080036587f03} "= "Offline Files Menu "
    "{10CFC467-4392-11d2-8DB4-00C04FA31A66} "= "Offline Files Folder Options "
    "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E} "= "Offline Files Folder "
    "{7A80E4A8-8005-11D2-BCF8-00C04F72C717} "= "MMC Icon Handler "
    "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262} "= ".CAB file viewer "
    "{32683183-48a0-441b-a342-7c2a440a9478} "= "Media Band "
    "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A} "= "Custom MRU AutoCompleted List "
    "{7e653215-fa25-46bd-a339-34a2790f3cb7} "= "Accessible "
    "{acf35015-526e-4230-9596-becbe19f0ac9} "= "Track Popup Bar "
    "{E0E11A09-5CB8-4B6C-8332-E00720A168F2} "= "Address Bar Parser "
    "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61} "= "Microsoft Browser Architecture "
    "{7BD29E01-76C1-11CF-9DD0-00A0C9034933} "= "Temporary Internet Files "
    "{EFA24E64-B078-11d0-89E4-00C04FC9E26E} "= "Explorer Band "
    "{f39a0dc0-9cc8-11d0-a599-00c04fd64433} "= "Channel File "
    "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434} "= "Channel Shortcut "
    "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435} "= "Channel Handler Object "
    "{f3da0dc0-9cc8-11d0-a599-00c04fd64437} "= "Channel Menu "
    "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438} "= "Channel Properties "
    "{32714800-2E5F-11d0-8B85-00AA0044F941} "= "For &People... "
    "{1D2680C9-0E2A-469d-B787-065558BC7D43} "= "Fusion Cache "
    "{BDEADF00-C265-11D0-BCED-00A0C90AB50F} "= "Web Folders "
    "{42042206-2D85-11D3-8CFF-005004838597} "= "Microsoft Office HTML Icon Handler "
    "{E0D79304-84BE-11CE-9641-444553540000} "= "WinZip "
    "{E0D79305-84BE-11CE-9641-444553540000} "= "WinZip "
    "{E0D79306-84BE-11CE-9641-444553540000} "= "WinZip "
    "{E0D79307-84BE-11CE-9641-444553540000} "= "WinZip "
    "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} "= "Shell Extensions for RealOne Player "
    "{BDA77241-42F6-11d0-85E2-00AA001FE28C} "= "LDVP Shell Extensions "
    "{20082881-FC36-4E47-9A7A-644C95FF749F} "= "IntelliPoint Wireless Control Panel Property Page "
    "{AF90F543-6A3A-4C1B-8B16-ECEC073E69BE} "= "IntelliPoint Wheel Control Panel Property Page "
    "{653DCCC2-13DB-45B2-A389-427885776CFE} "= "IntelliPoint Activities Control Panel Property Page "
    "{124597D8-850A-41AE-849C-017A4FA99CA2} "= "IntelliPoint Buttons Control Panel Property Page "
    "{32A9D769-5B55-4a25-9A62-86B5683FE50A} "= "NikonView Drop Extension "
    "{26BEE9FC-ACE1-49FF-A903-3B49A6EBAAC4} "=" "
    "{028BC10E-E77C-4E7C-B88F-C417ADAFDDC0} "=" "
    "{D1133709-C408-4319-8F05-7161D69F7CEA} "=" "
    "{AD5052B6-EC7E-4325-A80B-0A8300EB59AC} "=" "
    "{BB869352-B5F3-407B-87E4-79B1F2CCEA95} "=" "
    "{1AFC34F1-B97C-4BA4-A6EC-8F8206A15E16} "=" "
    "{17F84AD5-22DF-4F23-A35F-C7CBA3BB2992} "=" "
    "{A10AF112-AE03-4437-9E37-05B2932F3017} "=" "
    "{3E0F630C-B28B-4E58-93DF-D6FA53DA49F3} "=" "
    "{1C6DBED5-A9D1-4131-BC50-291F9AAD46CB} "=" "
    "{8EBBB2A2-6BEA-4D3C-BA01-0503C3F473E8} "=" "
    "{E76FF1F7-F200-40EB-9B0F-402B27961593} "=" "
    "{0BA74B9A-6213-40F4-9A95-215ADE859CC0} "=" "
    "{8AA5C715-57FC-402D-AC11-8FF995C1C9FE} "=" "
    "{F8B2356E-7357-46FE-A8BF-BCE4B8A1AB50} "=" "
    "{25A456A5-8710-4D72-878B-B6E275B37E27} "=" "
    "{E23C6A3F-53EE-49E1-8DC1-734CADF7B2CB} "=" "
    "{61CB8F93-C1D1-49AE-8ABA-605893D16F2B} "=" "
    "{C140DBF2-56D3-4395-83E4-B12CF243D136} "=" "

    HKEY ROOT CLASSIDS:Windows Registry Editor Version 5.00
    [HKEY_CLASSES_ROOT\CLSID\{AD5052B6-EC7E-4325-A80B-0A8300EB59AC}]
    @=" "
    [HKEY_CLASSES_ROOT\CLSID\{AD5052B6-EC7E-4325-A80B-0A8300EB59AC}\Implemented Categories]
    @=" "
    [HKEY_CLASSES_ROOT\CLSID\{AD5052B6-EC7E-4325-A80B-0A8300EB59AC}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=" "
    [HKEY_CLASSES_ROOT\CLSID\{AD5052B6-EC7E-4325-A80B-0A8300EB59AC}\InprocServer32]
    @= "C:\\WINNT\\system32\\heui.dll "
    "ThreadingModel "= "Apartment "

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{1AFC34F1-B97C-4BA4-A6EC-8F8206A15E16}]
    @=" "
    [HKEY_CLASSES_ROOT\CLSID\{1AFC34F1-B97C-4BA4-A6EC-8F8206A15E16}\Implemented Categories]
    @=" "
    [HKEY_CLASSES_ROOT\CLSID\{1AFC34F1-B97C-4BA4-A6EC-8F8206A15E16}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=" "

    [HKEY_CLASSES_ROOT\CLSID\{1AFC34F1-B97C-4BA4-A6EC-8F8206A15E16}\InprocServer32]
    @= "C:\\WINNT\\system32\\RCSAPI32.DLL "
    "ThreadingModel "= "Apartment "

    Windows Registry Editor Version 5.00
    [HKEY_CLASSES_ROOT\CLSID\{A10AF112-AE03-4437-9E37-05B2932F3017}]
    @=" "
    [HKEY_CLASSES_ROOT\CLSID\{A10AF112-AE03-4437-9E37-05B2932F3017}\Implemented Categories]
    @=" "
    [HKEY_CLASSES_ROOT\CLSID\{A10AF112-AE03-4437-9E37-05B2932F3017}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=" "
    [HKEY_CLASSES_ROOT\CLSID\{A10AF112-AE03-4437-9E37-05B2932F3017}\InprocServer32]
    @= "C:\\WINNT\\system32\\moxmlr.dll "
    "ThreadingModel "= "Apartment "
    Windows Registry Editor Version 5.00
    [HKEY_CLASSES_ROOT\CLSID\{3E0F630C-B28B-4E58-93DF-D6FA53DA49F3}]
    @=" "
    [HKEY_CLASSES_ROOT\CLSID\{3E0F630C-B28B-4E58-93DF-D6FA53DA49F3}\Implemented Categories]
    @=" "
    [HKEY_CLASSES_ROOT\CLSID\{3E0F630C-B28B-4E58-93DF-D6FA53DA49F3}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=" "
    [HKEY_CLASSES_ROOT\CLSID\{3E0F630C-B28B-4E58-93DF-D6FA53DA49F3}\InprocServer32]
    @= "C:\\WINNT\\system32\\fdamebuf.dll "
    "ThreadingModel "= "Apartment "
    Windows Registry Editor Version 5.00
    [HKEY_CLASSES_ROOT\CLSID\{8EBBB2A2-6BEA-4D3C-BA01-0503C3F473E8}]
    @=" "
    [HKEY_CLASSES_ROOT\CLSID\{8EBBB2A2-6BEA-4D3C-BA01-0503C3F473E8}\Implemented Categories]
    @=" "
    [HKEY_CLASSES_ROOT\CLSID\{8EBBB2A2-6BEA-4D3C-BA01-0503C3F473E8}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=" "

    [HKEY_CLASSES_ROOT\CLSID\{8EBBB2A2-6BEA-4D3C-BA01-0503C3F473E8}\InprocServer32]
    @= "C:\\WINNT\\system32\\sqi_ci.dll "
    "ThreadingModel "= "Apartment "

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{E76FF1F7-F200-40EB-9B0F-402B27961593}]
    @=" "

    [HKEY_CLASSES_ROOT\CLSID\{E76FF1F7-F200-40EB-9B0F-402B27961593}\Implemented Categories]
    @=" "

    [HKEY_CLASSES_ROOT\CLSID\{E76FF1F7-F200-40EB-9B0F-402B27961593}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=" "

    [HKEY_CLASSES_ROOT\CLSID\{E76FF1F7-F200-40EB-9B0F-402B27961593}\InprocServer32]
    @= "C:\\WINNT\\system32\\nashrui.dll "
    "ThreadingModel "= "Apartment "

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{8AA5C715-57FC-402D-AC11-8FF995C1C9FE}]
    @=" "

    [HKEY_CLASSES_ROOT\CLSID\{8AA5C715-57FC-402D-AC11-8FF995C1C9FE}\Implemented Categories]
    @=" "

    [HKEY_CLASSES_ROOT\CLSID\{8AA5C715-57FC-402D-AC11-8FF995C1C9FE}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=" "

    [HKEY_CLASSES_ROOT\CLSID\{8AA5C715-57FC-402D-AC11-8FF995C1C9FE}\InprocServer32]
    @= "C:\\WINNT\\system32\\dwdskres.dll "
    "ThreadingModel "= "Apartment "

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{25A456A5-8710-4D72-878B-B6E275B37E27}]
    @=" "

    [HKEY_CLASSES_ROOT\CLSID\{25A456A5-8710-4D72-878B-B6E275B37E27}\Implemented Categories]
    @=" "

    [HKEY_CLASSES_ROOT\CLSID\{25A456A5-8710-4D72-878B-B6E275B37E27}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=" "

    [HKEY_CLASSES_ROOT\CLSID\{25A456A5-8710-4D72-878B-B6E275B37E27}\InprocServer32]
    @= "C:\\WINNT\\system32\\rvamsp.dll "
    "ThreadingModel "= "Apartment "

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{61CB8F93-C1D1-49AE-8ABA-605893D16F2B}]
    @=" "

    [HKEY_CLASSES_ROOT\CLSID\{61CB8F93-C1D1-49AE-8ABA-605893D16F2B}\Implemented Categories]
    @=" "

    [HKEY_CLASSES_ROOT\CLSID\{61CB8F93-C1D1-49AE-8ABA-605893D16F2B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=" "

    [HKEY_CLASSES_ROOT\CLSID\{61CB8F93-C1D1-49AE-8ABA-605893D16F2B}\InprocServer32]
    @= "C:\\WINNT\\system32\\phnppagn.dll "
    "ThreadingModel "= "Apartment "

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{C140DBF2-56D3-4395-83E4-B12CF243D136}]
    @=" "

    [HKEY_CLASSES_ROOT\CLSID\{C140DBF2-56D3-4395-83E4-B12CF243D136}\Implemented Categories]
    @=" "

    [HKEY_CLASSES_ROOT\CLSID\{C140DBF2-56D3-4395-83E4-B12CF243D136}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=" "

    [HKEY_CLASSES_ROOT\CLSID\{C140DBF2-56D3-4395-83E4-B12CF243D136}\InprocServer32]
    @= "C:\\WINNT\\system32\\dmmssocn.dll "
    "ThreadingModel "= "Apartment "
     
  18. 2005/01/25
    ASkinner

    ASkinner Inactive Thread Starter

    Joined:
    2005/01/17
    Messages:
    12
    Likes Received:
    0
    L2mfix Log Part 2

    Files Found are not all bad files:
    C:\WINNT\SYSTEM32\
    afpmgmts.dll Wed Jan 19 2005 7:27:44p ..S.R 225,652 220.36 K
    akcore.dll Tue Jan 11 2005 9:25:06p A.... 188,416 184.00 K
    aklsp.dll Tue Jan 11 2005 9:25:12p A.... 196,608 192.00 K
    akrules.dll Tue Jan 11 2005 9:25:08p A.... 110,592 108.00 K
    akupd.dll Tue Jan 11 2005 9:24:56p A.... 155,648 152.00 K
    aqfsipc.dll Sat Jan 15 2005 1:31:26p ..S.R 224,012 218.76 K
    ciodm.dll Thu Nov 4 2004 11:41:52p A.... 68,880 67.27 K
    d0ce0c~1.dll Sat Jan 22 2005 4:25:54p A.... 204,800 200.00 K
    docore.dll Mon Jan 24 2005 9:41:00p A.... 151,552 148.00 K
    dolsp.dll Sat Jan 22 2005 9:20:42a A.... 139,264 136.00 K
    dosync.dll Tue Jan 25 2005 5:19:48p A.... 114,688 112.00 K
    dwdskres.dll Thu Jan 20 2005 2:15:10p A.... 225,652 220.36 K
    e6f1873b.dll Sat Jan 22 2005 4:20:46p A.... 147,456 144.00 K
    e6jmlg~1.dll Tue Jan 18 2005 7:36:20a ..S.R 223,125 217.89 K
    elent.dll Fri Jan 14 2005 10:13:42p ..S.R 224,012 218.76 K
    en8ul1~1.dll Wed Jan 19 2005 10:11:18p ..S.R 226,203 220.90 K
    hr6405~1.dll Mon Jan 24 2005 10:45:34p ..S.R 225,652 220.36 K
    hypertrm.dll Tue Nov 16 2004 5:47:02a A.... 576,784 563.27 K
    jr4025~1.dll Mon Jan 17 2005 8:58:40a ..S.R 226,057 220.76 K
    jtru07~1.dll Sat Jan 15 2005 12:31:30p ..S.R 225,357 220.07 K
    m046la~1.dll Mon Jan 24 2005 10:32:32p A.... 223,028 217.80 K
    mfoeacct.dll Wed Jan 12 2005 6:52:20a ..S.R 224,012 218.76 K
    mlrle32.dll Mon Jan 17 2005 8:58:42a ..S.R 224,012 218.76 K
    nttapi32.dll Wed Jan 12 2005 8:05:20p ..S.R 225,357 220.07 K
    rdsauth.dll Wed Jan 12 2005 6:35:26p ..S.R 224,012 218.76 K
    rhsauth.dll Wed Jan 19 2005 7:20:44p ..S.R 225,652 220.36 K
    shdocvw.dll Thu Nov 11 2004 11:20:56p A.... 1,332,224 1.27 M
    sp3res.dll Thu Dec 2 2004 9:27:18a ..... 6,272,512 5.98 M
    sporder.dll Tue Jan 11 2005 9:25:08p A.... 8,464 8.27 K
    svmapi.dll Fri Jan 14 2005 10:33:30p ..S.R 225,357 220.07 K
    user32.dll Wed Dec 29 2004 4:14:10a A.... 380,688 371.77 K
    uuezno.dll Tue Jan 25 2005 4:26:04p A.... 24,576 24.00 K
    zzcgqy.dll Tue Jan 25 2005 4:26:04p A.... 5,632 5.50 K

    33 items found: 33 files (14 H/S), 0 directories.
    Total of file sizes: 13,675,936 bytes 13.04 M
    Locate .tmp files:

    C:\WINNT\SYSTEM32\
    guard.tmp Tue Jan 25 2005 2:02:26p A.... 223,028 217.80 K

    1 item found: 1 file, 0 directories.
    Total of file sizes: 223,028 bytes 217.80 K
    Directory Listing of system files:
    Volume in drive C is CDC-139363
    Volume Serial Number is 3487-3804
    Directory of C:\WINNT\System32
    01/24/2005 10:45p 225,652 hr6405jqe.dll
    01/19/2005 10:11p 226,203 en8ul1l91.dll
    01/19/2005 07:27p 225,652 afpmgmts.dll
    01/19/2005 07:20p 225,652 rHsauth.dll
    01/18/2005 10:07p <DIR> dllcache
    01/18/2005 07:36a 223,125 e6jmlg1116.dll
    01/17/2005 08:58a 224,012 mlrle32.dll
    01/17/2005 08:58a 226,057 jr4025hmg.dll
    01/15/2005 01:31p 224,012 aqfsipc.dll
    01/15/2005 12:31p 225,357 jtru0799e.dll
    01/14/2005 10:33p 225,357 svmapi.dll
    01/14/2005 10:13p 224,012 elent.dll
    01/12/2005 08:05p 225,357 NTTAPI32.DLL
    01/12/2005 06:35p 224,012 rDsauth.dll
    01/12/2005 06:52a 224,012 MFOEACCT.DLL
    14 File(s) 3,148,472 bytes
    1 Dir(s) 14,957,395,968 bytes free
     
  19. 2005/01/26
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    Hi

    Close any programs you have open since this step requires a reboot.

    From the l2mfix folder on your desktop, double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing enter, then press any key to reboot your computer. After a reboot, your desktop and icons will appear, then disappear (this is normal). L2mfix will continue to scan your computer and when it's finished, notepad will open with a log. Copy the contents of that log and paste it back into this thread, along with a new hijackthis log.

    IMPORTANT: Do NOT run any other files in the l2mfix folder unless you are asked to do so!
    Note to others, do not use this tool without assistance, the infection is always slightly differant.

    Also make and post a new Hijackthis log.
     
  20. 2005/01/26
    ASkinner

    ASkinner Inactive Thread Starter

    Joined:
    2005/01/17
    Messages:
    12
    Likes Received:
    0
    L2mfix Log 1/26/05

    L2Mfix 1.02

    Running From:
    C:\Documents and Settings\CBS4\Desktop\l2mfix



    RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
    Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
    This program is Freeware, use it on your own risk!

    Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
    (ID-NI) ALLOW Read BUILTIN\Users
    (ID-IO) ALLOW Read BUILTIN\Users
    (ID-NI) ALLOW Read BUILTIN\Power Users
    (ID-IO) ALLOW Read BUILTIN\Power Users
    (ID-NI) ALLOW Full access BUILTIN\Administrators
    (ID-IO) ALLOW Full access BUILTIN\Administrators
    (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
    (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
    (ID-IO) ALLOW Full access CREATOR OWNER



    Setting registry permissions:


    RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
    Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
    This program is Freeware, use it on your own risk!


    Denying C access for really "Everyone "
    - adding new ACCESS DENY entry


    Registry Permissions set too:

    RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
    Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
    This program is Freeware, use it on your own risk!

    Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
    (CI) DENY --C------- Everyone
    (ID-NI) ALLOW Read BUILTIN\Users
    (ID-IO) ALLOW Read BUILTIN\Users
    (ID-NI) ALLOW Read BUILTIN\Power Users
    (ID-IO) ALLOW Read BUILTIN\Power Users
    (ID-NI) ALLOW Full access BUILTIN\Administrators
    (ID-IO) ALLOW Full access BUILTIN\Administrators
    (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
    (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
    (ID-IO) ALLOW Full access CREATOR OWNER



    Setting up for Reboot


    Starting Reboot!

    C:\Documents and Settings\CBS4\Desktop\l2mfix
    System Rebooted!

    Running From:
    C:\Documents and Settings\CBS4\Desktop\l2mfix

    killing explorer and rundll32.exe

    Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
    Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
    Killing PID 1128 'explorer.exe'
    Killing PID 1128 'explorer.exe'
    Error 0x5 : Access is denied.


    Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
    Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
    Killing PID 1176 'rundll32.exe'
    Killing PID 1296 'rundll32.exe'
    Killing PID 1304 'rundll32.exe'

    Scanning First Pass. Please Wait!

    First Pass Completed

    Second Pass Scanning

    Second pass Completed!
    Backing Up: C:\WINNT\system32\afpmgmts.dll
    1 file(s) copied.
    Backing Up: C:\WINNT\system32\aqfsipc.dll
    1 file(s) copied.
    Backing Up: C:\WINNT\system32\dwdskres.dll
    1 file(s) copied.
    Backing Up: C:\WINNT\system32\e6jmlg1116.dll
    1 file(s) copied.
    Backing Up: C:\WINNT\system32\elent.dll
    1 file(s) copied.
    Backing Up: C:\WINNT\system32\en8ul1l91.dll
    1 file(s) copied.
    Backing Up: C:\WINNT\system32\jr4025hmg.dll
    1 file(s) copied.
    Backing Up: C:\WINNT\system32\jtru0799e.dll
    1 file(s) copied.
    Backing Up: C:\WINNT\system32\MFOEACCT.DLL
    1 file(s) copied.
    Backing Up: C:\WINNT\system32\mlrle32.dll
    1 file(s) copied.
    Backing Up: C:\WINNT\system32\NTTAPI32.DLL
    1 file(s) copied.
    Backing Up: C:\WINNT\system32\pzrfnet.dll
    1 file(s) copied.
    Backing Up: C:\WINNT\system32\q086lals1dq6.dll
    1 file(s) copied.
    Backing Up: C:\WINNT\system32\rDsauth.dll
    1 file(s) copied.
    Backing Up: C:\WINNT\system32\rHsauth.dll
    1 file(s) copied.
    Backing Up: C:\WINNT\system32\svmapi.dll
    1 file(s) copied.
    Backing Up: C:\WINNT\system32\guard.tmp
    1 file(s) copied.
    deleting: C:\WINNT\system32\afpmgmts.dll
    Successfully Deleted: C:\WINNT\system32\afpmgmts.dll
    deleting: C:\WINNT\system32\aqfsipc.dll
    Successfully Deleted: C:\WINNT\system32\aqfsipc.dll
    deleting: C:\WINNT\system32\dwdskres.dll
    Successfully Deleted: C:\WINNT\system32\dwdskres.dll
    deleting: C:\WINNT\system32\e6jmlg1116.dll
    Successfully Deleted: C:\WINNT\system32\e6jmlg1116.dll
    deleting: C:\WINNT\system32\elent.dll
    Successfully Deleted: C:\WINNT\system32\elent.dll
    deleting: C:\WINNT\system32\en8ul1l91.dll
    Successfully Deleted: C:\WINNT\system32\en8ul1l91.dll
    deleting: C:\WINNT\system32\jr4025hmg.dll
    Successfully Deleted: C:\WINNT\system32\jr4025hmg.dll
    deleting: C:\WINNT\system32\jtru0799e.dll
    Successfully Deleted: C:\WINNT\system32\jtru0799e.dll
    deleting: C:\WINNT\system32\MFOEACCT.DLL
    Successfully Deleted: C:\WINNT\system32\MFOEACCT.DLL
    deleting: C:\WINNT\system32\mlrle32.dll
    Successfully Deleted: C:\WINNT\system32\mlrle32.dll
    deleting: C:\WINNT\system32\NTTAPI32.DLL
    Successfully Deleted: C:\WINNT\system32\NTTAPI32.DLL
    deleting: C:\WINNT\system32\pzrfnet.dll
    Successfully Deleted: C:\WINNT\system32\pzrfnet.dll
    deleting: C:\WINNT\system32\q086lals1dq6.dll
    Successfully Deleted: C:\WINNT\system32\q086lals1dq6.dll
    deleting: C:\WINNT\system32\rDsauth.dll
    Successfully Deleted: C:\WINNT\system32\rDsauth.dll
    deleting: C:\WINNT\system32\rHsauth.dll
    Successfully Deleted: C:\WINNT\system32\rHsauth.dll
    deleting: C:\WINNT\system32\svmapi.dll
    Successfully Deleted: C:\WINNT\system32\svmapi.dll
    deleting: C:\WINNT\system32\guard.tmp
    Successfully Deleted: C:\WINNT\system32\guard.tmp

    Desktop.ini sucessfully removed

    Zipping up files for submission:
    adding: afpmgmts.dll (152 bytes security) (deflated 4%)
    adding: aqfsipc.dll (152 bytes security) (deflated 4%)
    adding: dwdskres.dll (152 bytes security) (deflated 4%)
    adding: e6jmlg1116.dll (152 bytes security) (deflated 3%)
    adding: elent.dll (152 bytes security) (deflated 4%)
    adding: en8ul1l91.dll (152 bytes security) (deflated 5%)
    adding: jr4025hmg.dll (152 bytes security) (deflated 5%)
    adding: jtru0799e.dll (152 bytes security) (deflated 4%)
    adding: MFOEACCT.DLL (152 bytes security) (deflated 4%)
    adding: mlrle32.dll (152 bytes security) (deflated 4%)
    adding: NTTAPI32.DLL (152 bytes security) (deflated 4%)
    adding: pzrfnet.dll (152 bytes security) (deflated 4%)
    adding: q086lals1dq6.dll (152 bytes security) (deflated 3%)
    adding: rDsauth.dll (152 bytes security) (deflated 4%)
    adding: rHsauth.dll (152 bytes security) (deflated 4%)
    adding: svmapi.dll (152 bytes security) (deflated 4%)
    adding: guard.tmp (152 bytes security) (deflated 4%)
    adding: cecho.reg (152 bytes security) (deflated 2%)
    adding: clear.reg (152 bytes security) (deflated 70%)
    adding: echo.reg (152 bytes security) (deflated 8%)
    adding: desktop.ini (152 bytes security) (deflated 15%)
    adding: direct.txt (152 bytes security) (stored 0%)
    adding: lo2.txt (152 bytes security) (deflated 81%)
    adding: readme.txt (152 bytes security) (deflated 49%)
    adding: report.txt (152 bytes security) (deflated 70%)
    adding: report012505.txt (152 bytes security) (deflated 70%)
    adding: test.txt (152 bytes security) (deflated 75%)
    adding: test2.txt (152 bytes security) (deflated 49%)
    adding: xfind.txt (152 bytes security) (deflated 68%)
    adding: backregs/0CE2B74E-D2A7-4106-94E5-39C2C50F6940.reg (152 bytes security) (deflated 70%)
    adding: backregs/1AFC34F1-B97C-4BA4-A6EC-8F8206A15E16.reg (152 bytes security) (deflated 70%)
    adding: backregs/25A456A5-8710-4D72-878B-B6E275B37E27.reg (152 bytes security) (deflated 70%)
    adding: backregs/3E0F630C-B28B-4E58-93DF-D6FA53DA49F3.reg (152 bytes security) (deflated 70%)
    adding: backregs/4B315C67-E860-4AC8-B253-6C9ACF3FDA94.reg (152 bytes security) (deflated 70%)
    adding: backregs/61CB8F93-C1D1-49AE-8ABA-605893D16F2B.reg (152 bytes security) (deflated 70%)
    adding: backregs/8AA5C715-57FC-402D-AC11-8FF995C1C9FE.reg (152 bytes security) (deflated 70%)
    adding: backregs/8EBBB2A2-6BEA-4D3C-BA01-0503C3F473E8.reg (152 bytes security) (deflated 70%)
    adding: backregs/A10AF112-AE03-4437-9E37-05B2932F3017.reg (152 bytes security) (deflated 70%)
    adding: backregs/AD5052B6-EC7E-4325-A80B-0A8300EB59AC.reg (152 bytes security) (deflated 70%)
    adding: backregs/B91E41CC-41D2-40A8-A49C-F4C2AA644306.reg (152 bytes security) (deflated 71%)
    adding: backregs/C140DBF2-56D3-4395-83E4-B12CF243D136.reg (152 bytes security) (deflated 70%)
    adding: backregs/E76FF1F7-F200-40EB-9B0F-402B27961593.reg (152 bytes security) (deflated 70%)
    adding: backregs/shell.reg (152 bytes security) (deflated 74%)

    Restoring Registry Permissions:


    RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
    Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
    This program is Freeware, use it on your own risk!


    Revoking access for really "Everyone "


    Registry permissions set too:

    RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
    Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
    This program is Freeware, use it on your own risk!

    Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
    (ID-NI) ALLOW Read BUILTIN\Users
    (ID-IO) ALLOW Read BUILTIN\Users
    (ID-NI) ALLOW Read BUILTIN\Power Users
    (ID-IO) ALLOW Read BUILTIN\Power Users
    (ID-NI) ALLOW Full access BUILTIN\Administrators
    (ID-IO) ALLOW Full access BUILTIN\Administrators
    (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
    (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
    (ID-IO) ALLOW Full access CREATOR OWNER


    Restoring Sedebugprivilege:

    Granting SeDebugPrivilege to Administrators ... successful

    deleting local copy: afpmgmts.dll
    deleting local copy: aqfsipc.dll
    deleting local copy: dwdskres.dll
    deleting local copy: e6jmlg1116.dll
    deleting local copy: elent.dll
    deleting local copy: en8ul1l91.dll
    deleting local copy: jr4025hmg.dll
    deleting local copy: jtru0799e.dll
    deleting local copy: MFOEACCT.DLL
    deleting local copy: mlrle32.dll
    deleting local copy: NTTAPI32.DLL
    deleting local copy: pzrfnet.dll
    deleting local copy: q086lals1dq6.dll
    deleting local copy: rDsauth.dll
    deleting local copy: rHsauth.dll
    deleting local copy: svmapi.dll
    deleting local copy: guard.tmp

    The following Is the Current Export of the Winlogon notify key:
    ****************************************************************************
    Windows Registry Editor Version 5.00

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
    "Asynchronous "=dword:00000000
    "Impersonate "=dword:00000000
    "DllName "=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
    6c,00,00,00
    "Logoff "= "ChainWlxLogoffEvent "

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
    "Asynchronous "=dword:00000000
    "Impersonate "=dword:00000000
    "DllName "=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
    6c,00,6c,00,00,00
    "Logoff "= "CryptnetWlxLogoffEvent "

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
    "DLLName "= "cscdll.dll "
    "Logon "= "WinlogonLogonEvent "
    "Logoff "= "WinlogonLogoffEvent "
    "ScreenSaver "= "WinlogonScreenSaverEvent "
    "Startup "= "WinlogonStartupEvent "
    "Shutdown "= "WinlogonShutdownEvent "
    "StartShell "= "WinlogonStartShellEvent "
    "Impersonate "=dword:00000000
    "Asynchronous "=dword:00000001

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
    "DllName "= "C:\\WINNT\\system32\\NavLogon.dll "
    "StartShell "= "NavStartShellEvent "
    "Logoff "= "NavLogoffEvent "

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
    "Logoff "= "WLEventLogoff "
    "Impersonate "=dword:00000000
    "Asynchronous "=dword:00000001
    "DllName "=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
    6c,00,6c,00,00,00

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
    "DLLName "= "WlNotify.dll "
    "Lock "= "SensLockEvent "
    "Logon "= "SensLogonEvent "
    "Logoff "= "SensLogoffEvent "
    "Safe "=dword:00000001
    "MaxWait "=dword:00000258
    "StartScreenSaver "= "SensStartScreenSaverEvent "
    "StopScreenSaver "= "SensStopScreenSaverEvent "
    "Startup "= "SensStartupEvent "
    "Shutdown "= "SensShutdownEvent "
    "StartShell "= "SensStartShellEvent "
    "Unlock "= "SensUnlockEvent "
    "Impersonate "=dword:00000001
    "Asynchronous "=dword:00000001

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
    "DLLName "= "wzcdlg.dll "
    "Logon "= "WZCEventLogon "
    "Logoff "= "WZCEventLogoff "
    "Impersonate "=dword:00000000
    "Asynchronous "=dword:00000000


    The following are the files found:
    ****************************************************************************
    C:\WINNT\system32\afpmgmts.dll
    C:\WINNT\system32\aqfsipc.dll
    C:\WINNT\system32\dwdskres.dll
    C:\WINNT\system32\e6jmlg1116.dll
    C:\WINNT\system32\elent.dll
    C:\WINNT\system32\en8ul1l91.dll
    C:\WINNT\system32\jr4025hmg.dll
    C:\WINNT\system32\jtru0799e.dll
    C:\WINNT\system32\MFOEACCT.DLL
    C:\WINNT\system32\mlrle32.dll
    C:\WINNT\system32\NTTAPI32.DLL
    C:\WINNT\system32\pzrfnet.dll
    C:\WINNT\system32\q086lals1dq6.dll
    C:\WINNT\system32\rDsauth.dll
    C:\WINNT\system32\rHsauth.dll
    C:\WINNT\system32\svmapi.dll
    C:\WINNT\system32\guard.tmp

    Registry Entries that were Deleted:
    Please verify that the listing looks ok.
    If there was something deleted wrongly there are backups in the backreg folder.
    ****************************************************************************
    REGEDIT4

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
    "{26BEE9FC-ACE1-49FF-A903-3B49A6EBAAC4} "=-
    "{028BC10E-E77C-4E7C-B88F-C417ADAFDDC0} "=-
    "{D1133709-C408-4319-8F05-7161D69F7CEA} "=-
    "{AD5052B6-EC7E-4325-A80B-0A8300EB59AC} "=-
    "{BB869352-B5F3-407B-87E4-79B1F2CCEA95} "=-
    "{1AFC34F1-B97C-4BA4-A6EC-8F8206A15E16} "=-
    "{17F84AD5-22DF-4F23-A35F-C7CBA3BB2992} "=-
    "{A10AF112-AE03-4437-9E37-05B2932F3017} "=-
    "{3E0F630C-B28B-4E58-93DF-D6FA53DA49F3} "=-
    "{1C6DBED5-A9D1-4131-BC50-291F9AAD46CB} "=-
    "{8EBBB2A2-6BEA-4D3C-BA01-0503C3F473E8} "=-
    "{E76FF1F7-F200-40EB-9B0F-402B27961593} "=-
    "{0BA74B9A-6213-40F4-9A95-215ADE859CC0} "=-
    "{8AA5C715-57FC-402D-AC11-8FF995C1C9FE} "=-
    "{F8B2356E-7357-46FE-A8BF-BCE4B8A1AB50} "=-
    "{25A456A5-8710-4D72-878B-B6E275B37E27} "=-
    "{E23C6A3F-53EE-49E1-8DC1-734CADF7B2CB} "=-
    "{61CB8F93-C1D1-49AE-8ABA-605893D16F2B} "=-
    "{C140DBF2-56D3-4395-83E4-B12CF243D136} "=-
    "{B91E41CC-41D2-40A8-A49C-F4C2AA644306} "=-
    "{4B315C67-E860-4AC8-B253-6C9ACF3FDA94} "=-
    "{0CE2B74E-D2A7-4106-94E5-39C2C50F6940} "=-
    [-HKEY_CLASSES_ROOT\CLSID\{26BEE9FC-ACE1-49FF-A903-3B49A6EBAAC4}]
    [-HKEY_CLASSES_ROOT\CLSID\{028BC10E-E77C-4E7C-B88F-C417ADAFDDC0}]
    [-HKEY_CLASSES_ROOT\CLSID\{D1133709-C408-4319-8F05-7161D69F7CEA}]
    [-HKEY_CLASSES_ROOT\CLSID\{AD5052B6-EC7E-4325-A80B-0A8300EB59AC}]
    [-HKEY_CLASSES_ROOT\CLSID\{BB869352-B5F3-407B-87E4-79B1F2CCEA95}]
    [-HKEY_CLASSES_ROOT\CLSID\{1AFC34F1-B97C-4BA4-A6EC-8F8206A15E16}]
    [-HKEY_CLASSES_ROOT\CLSID\{17F84AD5-22DF-4F23-A35F-C7CBA3BB2992}]
    [-HKEY_CLASSES_ROOT\CLSID\{A10AF112-AE03-4437-9E37-05B2932F3017}]
    [-HKEY_CLASSES_ROOT\CLSID\{3E0F630C-B28B-4E58-93DF-D6FA53DA49F3}]
    [-HKEY_CLASSES_ROOT\CLSID\{1C6DBED5-A9D1-4131-BC50-291F9AAD46CB}]
    [-HKEY_CLASSES_ROOT\CLSID\{8EBBB2A2-6BEA-4D3C-BA01-0503C3F473E8}]
    [-HKEY_CLASSES_ROOT\CLSID\{E76FF1F7-F200-40EB-9B0F-402B27961593}]
    [-HKEY_CLASSES_ROOT\CLSID\{0BA74B9A-6213-40F4-9A95-215ADE859CC0}]
    [-HKEY_CLASSES_ROOT\CLSID\{8AA5C715-57FC-402D-AC11-8FF995C1C9FE}]
    [-HKEY_CLASSES_ROOT\CLSID\{F8B2356E-7357-46FE-A8BF-BCE4B8A1AB50}]
    [-HKEY_CLASSES_ROOT\CLSID\{25A456A5-8710-4D72-878B-B6E275B37E27}]
    [-HKEY_CLASSES_ROOT\CLSID\{E23C6A3F-53EE-49E1-8DC1-734CADF7B2CB}]
    [-HKEY_CLASSES_ROOT\CLSID\{61CB8F93-C1D1-49AE-8ABA-605893D16F2B}]
    [-HKEY_CLASSES_ROOT\CLSID\{C140DBF2-56D3-4395-83E4-B12CF243D136}]
    [-HKEY_CLASSES_ROOT\CLSID\{B91E41CC-41D2-40A8-A49C-F4C2AA644306}]
    [-HKEY_CLASSES_ROOT\CLSID\{4B315C67-E860-4AC8-B253-6C9ACF3FDA94}]
    [-HKEY_CLASSES_ROOT\CLSID\{0CE2B74E-D2A7-4106-94E5-39C2C50F6940}]
    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
    "{C6348400-254A-4A06-B48E-3BEDF30E19CD} "=-
    ****************************************************************************
    Desktop.ini Contents:
    ****************************************************************************
    [.ShellClassInfo]
    CLSID={645FF040-5081-101B-9F08-00AA002F954E}
    <IDone>{C6348400-254A-4A06-B48E-3BEDF30E19CD}</IDone>
    <IDtwo>VT00</IDtwo>
    <VERSION>200</VERSION>
    ****************************************************************************
    Classid's found from regsearch:
    ****************************************************************************

    
     
  21. 2005/01/26
    ASkinner

    ASkinner Inactive Thread Starter

    Joined:
    2005/01/17
    Messages:
    12
    Likes Received:
    0
    Hijackthis Log 1/26/05

    Logfile of HijackThis v1.99.0
    Scan saved at 7:10:28 PM, on 1/26/2005
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\LEXBCES.EXE
    C:\WINNT\system32\spoolsv.exe
    C:\WINNT\system32\LEXPPS.EXE
    C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    C:\WINNT\System32\svchost.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\wanmpsvc.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\oowygi.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
    C:\Program Files\Microsoft IntelliPoint\point32.exe
    C:\WINNT\system32\spool\DRIVERS\W32X86\2\printray.exe
    C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
    C:\WINNT\system32\ctfmon.exe
    C:\Program Files\Nikon\NkView6\NkvMon.exe
    C:\WINNT\explorer.exe
    C:\Program Files\BellSouth\FastAccessConnectionAgent\fastacc.exe
    C:\WINNT\System32\svchost.exe
    C:\Program Files\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: 69.20.16.183 search.netscape.com
    O1 - Hosts: 69.20.16.183 ieautosearch
    O2 - BHO: (no name) - {93196BC7-0695-FDE6-44B6-8F462B2B019F} - (no file)
    O2 - BHO: (no name) - {D7EF944F-21EA-AE92-641D-B50DA532A27C} - (no file)
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe "
    O4 - HKLM\..\Run: [PrinTray] C:\WINNT\system32\spool\DRIVERS\W32X86\2\printray.exe
    O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe "
    O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
    O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
    O4 - HKLM\..\Run: [ntechin] C:\WINNT\system32\n20050308.exe
    O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
    O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O10 - Unknown file in Winsock LSP: c:\winnt\system32\dolsp.dll
    O10 - Unknown file in Winsock LSP: c:\winnt\system32\dolsp.dll
    O10 - Unknown file in Winsock LSP: c:\winnt\system32\dolsp.dll
    O10 - Unknown file in Winsock LSP: c:\winnt\system32\dolsp.dll
    O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O17 - HKLM\System\CCS\Services\Tcpip\..\{9849CA52-6FB3-45A3-B2BA-F43030E5C020}: NameServer = 205.152.37.23 205.152.144.23
    O23 - Service: AOL Spyware Protection Service - Unknown - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe
    O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: LexBce Server - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
    O23 - Service: Symantec AntiVirus Client - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
    O23 - Service: WAN Miniport (ATW) Service - America Online, Inc. - C:\WINNT\wanmpsvc.exe
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.