This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Well, I Tried! But I Still Need Help.

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello again, it's been awhile since I've had to post here. But this computer I'm working on has got me stumped. I've run adaware (found 1873 critical objects!), spybot s&d (found 419 more!), also ran housecall and that found 43 trojans!
Needless to say this computer was pretty messed up. I got rid of most of it but I'm still getting a lot of popups and some random freezes (mostly when I click a link). A popup I get a lot is one wanting me to install MMViewer, hope that helps.
Anyway I was hoping the wonderful folks at Tom Coyote could take a look at my log and tell me what I've missed. Also, I know I'm not running the latest version of HJT, but everytime I've tried to download it, IE stops responding. I hope this is'nt a big deal. Thanks in advance!



Logfile of HijackThis v1.99.0
Scan saved at 7:19:55 PM, on 3/19/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
c:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\TrojanHunter 4.0\THGuard.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Bonnie\Desktop\hijack this\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O2 - BHO: (no name) - {1C044AAD-7955-4cbd-8175-501A165C4E5D} - C:\WINDOWS\System32\req.dat
O4 - HKLM\..\Run: [DwlClient] c:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\PDF15c8.dll"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.0\THGuard.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\PDF15c8.dll"
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid;=0x409
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by10fd.bay10.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www5.incredimail.com/contents/setup…p1/imloader.cab
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
bump Also, adaware keeps finding these entries: altnetbde, windupdates, 69.20.16.183:search.netscape.com, 69.20.16.183:ieautosearch and 69.20.16.183:auto.search.msn.com. Adaware gets rid of these everytime, but when I restart the computer and run adaware again, they come back everytime. Hope that helps. Thanks again.
Hello jjzero, Welcome to the TC.

Download L2mfix from one of these two locations:

http://www.atribune.org/downloads/l2mfix.exe
http://www.downloads.subratam.org/l2mfix.exe

Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!
Hello LDTate, thank you very much for responding. Your help is greatly appreciated. I did what you said and here is the log. L2MFIX find log 1.03 These are the registry keys present ********************************************************************************** Winlogon/notify: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "Logoff"="ChainWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Logoff"="CryptnetWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] "DLLName"="cscdll.dll" "Logon"="WinlogonLogonEvent" "Logoff"="WinlogonLogoffEvent" "ScreenSaver"="WinlogonScreenSaverEvent" "Startup"="WinlogonStartupEvent" "Shutdown"="WinlogonShutdownEvent" "StartShell"="WinlogonStartShellEvent" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\req] "Asynchronous"=dword:00000001 "DllName"="C:\\WINDOWS\\System32\\req.dat" "Impersonate"=dword:00000000 "Logon"="MachineLogon" "Logoff"="MachineLogoff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] "DLLName"="wlnotify.dll" "Logon"="SCardStartCertProp" "Logoff"="SCardStopCertProp" "Lock"="SCardSuspendCertProp" "Unlock"="SCardResumeCertProp" "Enabled"=dword:00000001 "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Impersonate"=dword:00000000 "StartShell"="SchedStartShell" "Logoff"="SchedEventLogOff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] "Logoff"="WLEventLogoff" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] "DLLName"="WlNotify.dll" "Lock"="SensLockEvent" "Logon"="SensLogonEvent" "Logoff"="SensLogoffEvent" "Safe"=dword:00000001 "MaxWait"=dword:00000258 "StartScreenSaver"="SensStartScreenSaverEvent" "StopScreenSaver"="SensStopScreenSaverEvent" "Startup"="SensStartupEvent" "Shutdown"="SensShutdownEvent" "StartShell"="SensStartShellEvent" "PostShell"="SensPostShellEvent" "Disconnect"="SensDisconnectEvent" "Reconnect"="SensReconnectEvent" "Unlock"="SensUnlockEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Impersonate"=dword:00000000 "Logoff"="TSEventLogoff" "Logon"="TSEventLogon" "PostShell"="TSEventPostShell" "Shutdown"="TSEventShutdown" "StartShell"="TSEventStartShell" "Startup"="TSEventStartup" "MaxWait"=dword:00000258 "Reconnect"="TSEventReconnect" "Disconnect"="TSEventDisconnect" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] "DLLName"="wlnotify.dll" "Logon"="RegisterTicketExpiredNotificationEvent" "Logoff"="UnregisterTicketExpiredNotificationEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 ********************************************************************************** useragent: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] "{D7FD170C-D3E1-E7CE-9524-4F6E28FADF86}"="" ********************************************************************************** Shell Extension key: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved] "{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet" "{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management" "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page" "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page" "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing" "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension" "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension" "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension" "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension" "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page" "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page" "{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler" "{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension" "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects" "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management" "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management" "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression" "{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension" "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI" "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu" "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase" "{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext" "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts" "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile" "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page" "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing" "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension" "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension" "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension" "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections" "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections" "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras" "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras" "{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras" "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras" "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras" "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension" "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension" "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host" "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link" "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler" "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension" "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks" "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu" "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search" "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support" "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support" "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run…" "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet" "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail" "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts" "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools" "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler" "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler" "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler" "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler" "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler" "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor" "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar" "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status" "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder" "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2" "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy" "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand" "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band" "{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band" "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search" "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search" "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility" "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address" "{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox" "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete" "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor" "{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List" "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List" "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible" "{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar" "{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser" "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List" "{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List" "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container" "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu" "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp" "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar" "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite" "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist" "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings" "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band" "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service" "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer" "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture" "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut" "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service" "{FF393560-C2A7-11CF-BFF4-444553540000}"="History" "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files" "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files" "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook" "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen" "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook" "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC" "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC" "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet" "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space" "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band" "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service" "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service" "{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder" "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck" "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr" "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder" "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler" "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent" "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent" "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent" "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent" "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent" "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler" "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager" "{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator" "{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher" "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs" "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory" "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor" "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)" "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor" "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler" "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard" "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web" "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object" "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard" "{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts" "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler" "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target" "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File" "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut" "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object" "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu" "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties" "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview" "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext" "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control" "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control" "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control" "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control" "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control" "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI" "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object" "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find" "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find" "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI" "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs" "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook" "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target" "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties" "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu" "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options" "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder" "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler" "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell" "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%" "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler" "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer" "{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People…" "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler" "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler" "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler" "{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache" "{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Web Folders" "{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler" "{567C71FC-4462-451E-A694-575E204A0AE2}"="" "{BBAA76F5-F8A7-4E4D-8BDD-F473D0EA463C}"="" "{61ECF7B4-9FE7-42F0-866A-F47AA0C5807E}"="" "{38291AAC-3659-4963-B282-FFE45D9D6537}"="" "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player" "{5AA9F982-2C27-465E-B174-0D530B0FB6C7}"="" "{530B2C05-7D0C-4D22-86D5-2BD19F53F148}"="" "{B7B14F2F-B997-41A9-9145-ED3DBA649B07}"="" "{9F5C9B0E-03A5-47E5-BA64-54D2FE085C2D}"="" "{F14E7CB9-818B-43B4-B569-968D443D2863}"="" "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"="AVG7 Shell Extension" "{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}"="AVG7 Find Extension" "{EBDF1F20-C829-11D1-8233-FF20AF3E97A9}"="TrojanHunter Menu Shell Extension" ********************************************************************************** HKEY ROOT CLASSIDS: Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{567C71FC-4462-451E-A694-575E204A0AE2}] @="" [HKEY_CLASSES_ROOT\CLSID\{567C71FC-4462-451E-A694-575E204A0AE2}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{567C71FC-4462-451E-A694-575E204A0AE2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{BBAA76F5-F8A7-4E4D-8BDD-F473D0EA463C}] @="" [HKEY_CLASSES_ROOT\CLSID\{BBAA76F5-F8A7-4E4D-8BDD-F473D0EA463C}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{BBAA76F5-F8A7-4E4D-8BDD-F473D0EA463C}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{61ECF7B4-9FE7-42F0-866A-F47AA0C5807E}] @="" [HKEY_CLASSES_ROOT\CLSID\{61ECF7B4-9FE7-42F0-866A-F47AA0C5807E}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{61ECF7B4-9FE7-42F0-866A-F47AA0C5807E}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{38291AAC-3659-4963-B282-FFE45D9D6537}] @="" [HKEY_CLASSES_ROOT\CLSID\{38291AAC-3659-4963-B282-FFE45D9D6537}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{38291AAC-3659-4963-B282-FFE45D9D6537}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{5AA9F982-2C27-465E-B174-0D530B0FB6C7}] @="" [HKEY_CLASSES_ROOT\CLSID\{5AA9F982-2C27-465E-B174-0D530B0FB6C7}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{5AA9F982-2C27-465E-B174-0D530B0FB6C7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{530B2C05-7D0C-4D22-86D5-2BD19F53F148}] @="" [HKEY_CLASSES_ROOT\CLSID\{530B2C05-7D0C-4D22-86D5-2BD19F53F148}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{530B2C05-7D0C-4D22-86D5-2BD19F53F148}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{B7B14F2F-B997-41A9-9145-ED3DBA649B07}] @="" [HKEY_CLASSES_ROOT\CLSID\{B7B14F2F-B997-41A9-9145-ED3DBA649B07}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{B7B14F2F-B997-41A9-9145-ED3DBA649B07}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{9F5C9B0E-03A5-47E5-BA64-54D2FE085C2D}] @="" [HKEY_CLASSES_ROOT\CLSID\{9F5C9B0E-03A5-47E5-BA64-54D2FE085C2D}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{9F5C9B0E-03A5-47E5-BA64-54D2FE085C2D}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{F14E7CB9-818B-43B4-B569-968D443D2863}] @="" [HKEY_CLASSES_ROOT\CLSID\{F14E7CB9-818B-43B4-B569-968D443D2863}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{F14E7CB9-818B-43B4-B569-968D443D2863}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" ********************************************************************************** Files Found are not all bad files: Locate .tmp files: ********************************************************************************** Directory Listing of system files: Volume in drive C has no label. Volume Serial Number is B0C7-C759 Directory of C:\WINDOWS\System32 03/20/2005 01:53 PM 234,019 mvpol9731.dll 03/20/2005 01:35 PM 232,640 n2l80c3uef.dll 03/20/2005 12:58 PM DLLCACHE 03/19/2005 01:04 AM 234,153 k0800almedqa0.dll 03/18/2005 09:18 PM 234,466 WENMM.DLL 03/18/2005 09:01 PM 234,419 MNISAM11.DLL 03/18/2005 08:48 PM 234,419 NOTID.DLL 03/18/2005 08:47 PM 235,891 h4n00e5meh.dll 03/18/2005 08:34 AM 234,419 i6jq0g15e6.dll 03/18/2005 08:07 AM 234,419 nlcpl.dll 03/18/2005 08:07 AM 235,766 kt4ol7h31.dll 03/18/2005 07:54 AM 235,608 mv8ml9l11.dll 03/18/2005 07:43 AM 235,231 l2j80c1uef.dll 03/18/2005 06:25 AM 235,276 jtn8075ue.dll 03/17/2005 07:50 PM 234,930 dnjq0115e.dll 03/17/2005 06:27 PM 236,201 r28slcl71fq.dll 03/17/2005 05:54 PM 236,056 ktl6l73s1.dll 03/17/2005 09:35 AM 234,649 h0l20a3oed.dll 03/17/2005 09:00 AM 417,792 w?nspool.exe 03/16/2005 09:24 AM 233,248 lv6809jue.dll 03/16/2005 08:37 AM 233,887 lvl6093se.dll 03/15/2005 09:15 PM 234,649 en04l1dq1.dll 03/15/2005 08:38 PM 235,199 ennul1591.dll 03/15/2005 03:45 PM 233,248 MVC71ESP.DLL 03/15/2005 02:45 PM 233,248 MNDART.DLL 03/15/2005 02:45 PM 233,248 MNCONF.DLL 03/15/2005 01:45 PM 233,248 MZXOCI.DLL 03/15/2005 01:45 PM 233,248 MPDOCS.DLL 03/15/2005 07:57 AM 236,276 o866lijs18o6.dll 03/15/2005 07:45 AM 236,276 RAPDD.DLL 03/15/2005 07:45 AM 232,775 d20mlcd11f0.dll 03/15/2005 07:37 AM 232,802 i6nmlg5116.dll 03/14/2005 08:47 PM 233,018 mv8ql9l51.dll 03/14/2005 06:28 PM 232,621 hrrs0597e.dll 03/14/2005 04:05 PM 234,886 i0lo0a33ed.dll 03/14/2005 03:52 PM 236,276 o0rola931d.dll 03/14/2005 03:48 PM 236,211 ir2ol5f31.dll 03/13/2005 06:58 PM 233,112 ktpsl7771.dll 03/13/2005 05:29 PM 236,214 h82olif3182.dll 03/13/2005 04:51 PM 234,886 jtl4073qe.dll 03/13/2005 04:35 PM 233,233 l6n40g5qe6.dll 03/13/2005 04:25 PM 236,295 aza0l39m1.dll 03/13/2005 01:39 PM 235,528 m2460chsef460.dll 03/13/2005 01:26 PM 235,979 gpr0l39m1.dll 03/13/2005 11:43 AM 234,926 r6p8lg7u16.dll 03/13/2005 11:30 AM 233,362 g2jo0c13ef.dll 03/13/2005 11:24 AM 233,453 fp0403dqe.dll 03/12/2005 03:06 PM 234,285 irl2l53o1.dll 03/12/2005 03:00 PM 233,924 r4p80e7ueh.dll 03/12/2005 02:54 PM 234,737 kt86l7ls1.dll 03/12/2005 02:48 PM 236,253 hrl2053oe.dll 03/12/2005 02:42 PM 232,917 KIDSW.DLL 03/12/2005 02:40 PM 236,253 CXPBK32.DLL 03/12/2005 02:37 PM 236,253 OBECLI32.DLL 03/12/2005 01:13 PM 232,609 dnps0177e.dll 03/12/2005 01:08 PM 233,105 dnn8015ue.dll 03/12/2005 11:33 AM 232,941 j4l4le3q1h.dll 03/12/2005 10:37 AM 234,208 o6lu0g39e6.dll 03/12/2005 10:26 AM 234,894 q6860glse6q60.dll 03/11/2005 05:23 PM 234,208 d2j0lc1m1f.dll 03/11/2005 04:47 PM 234,874 o6660gjse6o60.dll 03/11/2005 03:05 PM 234,988 r08s0al7edq.dll 03/11/2005 02:59 PM 235,109 dn0u01d9e.dll 03/10/2005 03:11 PM 18,432 req.dat 03/10/2005 08:47 AM 234,208 hr4005hme.dll 03/10/2005 08:25 AM 234,208 mv8ul9l91.dll 01/08/2005 07:25 PM 223,790 lv8609lse.dll 07/29/2004 06:27 PM Microsoft 66 File(s) 15,433,902 bytes 2 Dir(s) 66,021,908,480 bytes free
Close any programs you have open since this step requires a reboot.

From the l2mfix folder on your desktop, double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing enter, then press any key to reboot your computer. After a reboot, your desktop and icons will appear, then disappear (this is normal). L2mfix will continue to scan your computer and when it's finished, notepad will open with a log. Copy the contents of that log and paste it back into this thread, along with a new hijackthis log.

IMPORTANT: Do NOT run any other files in the l2mfix folder unless you are asked to do so!
Finally I was able to get the newest version of HJT, so I hope that helps too.
Here are the logs you requested.

L2Mfix 1.03

Running From:
C:\Documents and Settings\Bonnie\Desktop\l2mfix



RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER



Setting registry permissions:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!


Denying C(CI) access for predefined group "Administrators"
- adding new ACCESS DENY entry


Registry Permissions set too:

RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(CI) DENY –C——- BUILTIN\Administrators
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER



Setting up for Reboot


Starting Reboot!

C:\Documents and Settings\Bonnie\Desktop\l2mfix
System Rebooted!

Running From:
C:\Documents and Settings\Bonnie\Desktop\l2mfix

killing explorer and rundll32.exe

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Killing PID 1952 'explorer.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Error, Cannot find a process with an image name of rundll32.exe

Scanning First Pass. Please Wait!

First Pass Completed

Second Pass Scanning

Second pass Completed!
Backing Up: C:\WINDOWS\system32\ABI3D2AG.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\aza0l39m1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\CFFVIEW.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\CVNFMSP.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\CXPBK32.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\CYBVIEW.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\d20mlcd11f0.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\d2j0lc1m1f.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\djcompos.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dn0u01d9e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dnjq0115e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dnn8015ue.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dnps0177e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\DORGSNAP.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\en04l1dq1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\EnnClass.Dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ennul1591.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\fp0403dqe.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\fqsui.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\g2jo0c13ef.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\gpr0l39m1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\h0l20a3oed.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\h4n00e5meh.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\h82olif3182.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\hr4005hme.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\hrl2053oe.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\hrrs0597e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\i0lo0a33ed.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\i6600gjme6oa0.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\i6jq0g15e6.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\i6nmlg5116.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\IGPEERS.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\IOSRAD.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ir2ol5f31.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\irl2l53o1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ITMP.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\j4l4le3q1h.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\jtl4073qe.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\jtn8075ue.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\k0800almedqa0.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\KIDSW.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\KODRO.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\KRDHELA3.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\kt4ol7h31.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\kt86l7ls1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ktl6l73s1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ktpsl7771.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\l2j80c1uef.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\l6n40g5qe6.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\lv6809jue.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\lvl6093se.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\m2460chsef460.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\MEOBJS.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\MLAFD.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\MNCONF.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\MNDART.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\MNISAM11.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\MOHCP.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\MPDOCS.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\MRSYSTEM.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mtcans32.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mtjml9111.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mv8ml9l11.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mv8ql9l51.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mv8ul9l91.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\MVC71ESP.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mvpol9731.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\MZWSOCK.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\MZXOCI.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\n2l80c3uef.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\nbrsno.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\nkrsfr.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\nlcpl.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\NOTID.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\nwwrsnl.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\o0rola931d.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\o6660gjse6o60.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\o6lu0g39e6.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\o866lijs18o6.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\OBECLI32.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\OWEACCRC.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\PIRFNET.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\PVRFDISK.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\q6860glse6q60.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\r08s0al7edq.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\r28slcl71fq.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\r4p80e7ueh.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\r6p8lg7u16.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\RAPDD.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\SGMPSNAP.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\SIS.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\TGEMBED.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\TMAFFIC.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\TMPI.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\UDNPHOST.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\wdvcore.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\WENMM.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\XheedFtp.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\XveedFtp.dll
1 file(s) copied.
deleting: C:\WINDOWS\system32\ABI3D2AG.DLL
Successfully Deleted: C:\WINDOWS\system32\ABI3D2AG.DLL
deleting: C:\WINDOWS\system32\aza0l39m1.dll
Successfully Deleted: C:\WINDOWS\system32\aza0l39m1.dll
deleting: C:\WINDOWS\system32\CFFVIEW.DLL
Successfully Deleted: C:\WINDOWS\system32\CFFVIEW.DLL
deleting: C:\WINDOWS\system32\CVNFMSP.DLL
Successfully Deleted: C:\WINDOWS\system32\CVNFMSP.DLL
deleting: C:\WINDOWS\system32\CXPBK32.DLL
Successfully Deleted: C:\WINDOWS\system32\CXPBK32.DLL
deleting: C:\WINDOWS\system32\CYBVIEW.DLL
Successfully Deleted: C:\WINDOWS\system32\CYBVIEW.DLL
deleting: C:\WINDOWS\system32\d20mlcd11f0.dll
Successfully Deleted: C:\WINDOWS\system32\d20mlcd11f0.dll
deleting: C:\WINDOWS\system32\d2j0lc1m1f.dll
Successfully Deleted: C:\WINDOWS\system32\d2j0lc1m1f.dll
deleting: C:\WINDOWS\system32\djcompos.dll
Successfully Deleted: C:\WINDOWS\system32\djcompos.dll
deleting: C:\WINDOWS\system32\dn0u01d9e.dll
Successfully Deleted: C:\WINDOWS\system32\dn0u01d9e.dll
deleting: C:\WINDOWS\system32\dnjq0115e.dll
Successfully Deleted: C:\WINDOWS\system32\dnjq0115e.dll
deleting: C:\WINDOWS\system32\dnn8015ue.dll
Successfully Deleted: C:\WINDOWS\system32\dnn8015ue.dll
deleting: C:\WINDOWS\system32\dnps0177e.dll
Successfully Deleted: C:\WINDOWS\system32\dnps0177e.dll
deleting: C:\WINDOWS\system32\DORGSNAP.DLL
Successfully Deleted: C:\WINDOWS\system32\DORGSNAP.DLL
deleting: C:\WINDOWS\system32\en04l1dq1.dll
Successfully Deleted: C:\WINDOWS\system32\en04l1dq1.dll
deleting: C:\WINDOWS\system32\EnnClass.Dll
Successfully Deleted: C:\WINDOWS\system32\EnnClass.Dll
deleting: C:\WINDOWS\system32\ennul1591.dll
Successfully Deleted: C:\WINDOWS\system32\ennul1591.dll
deleting: C:\WINDOWS\system32\fp0403dqe.dll
Successfully Deleted: C:\WINDOWS\system32\fp0403dqe.dll
deleting: C:\WINDOWS\system32\fqsui.dll
Successfully Deleted: C:\WINDOWS\system32\fqsui.dll
deleting: C:\WINDOWS\system32\g2jo0c13ef.dll
Successfully Deleted: C:\WINDOWS\system32\g2jo0c13ef.dll
deleting: C:\WINDOWS\system32\gpr0l39m1.dll
Successfully Deleted: C:\WINDOWS\system32\gpr0l39m1.dll
deleting: C:\WINDOWS\system32\h0l20a3oed.dll
Successfully Deleted: C:\WINDOWS\system32\h0l20a3oed.dll
deleting: C:\WINDOWS\system32\h4n00e5meh.dll
Successfully Deleted: C:\WINDOWS\system32\h4n00e5meh.dll
deleting: C:\WINDOWS\system32\h82olif3182.dll
Successfully Deleted: C:\WINDOWS\system32\h82olif3182.dll
deleting: C:\WINDOWS\system32\hr4005hme.dll
Successfully Deleted: C:\WINDOWS\system32\hr4005hme.dll
deleting: C:\WINDOWS\system32\hrl2053oe.dll
Successfully Deleted: C:\WINDOWS\system32\hrl2053oe.dll
deleting: C:\WINDOWS\system32\hrrs0597e.dll
Successfully Deleted: C:\WINDOWS\system32\hrrs0597e.dll
deleting: C:\WINDOWS\system32\i0lo0a33ed.dll
Successfully Deleted: C:\WINDOWS\system32\i0lo0a33ed.dll
deleting: C:\WINDOWS\system32\i6600gjme6oa0.dll
Successfully Deleted: C:\WINDOWS\system32\i6600gjme6oa0.dll
deleting: C:\WINDOWS\system32\i6jq0g15e6.dll
Successfully Deleted: C:\WINDOWS\system32\i6jq0g15e6.dll
deleting: C:\WINDOWS\system32\i6nmlg5116.dll
Successfully Deleted: C:\WINDOWS\system32\i6nmlg5116.dll
deleting: C:\WINDOWS\system32\IGPEERS.DLL
Successfully Deleted: C:\WINDOWS\system32\IGPEERS.DLL
deleting: C:\WINDOWS\system32\IOSRAD.DLL
Successfully Deleted: C:\WINDOWS\system32\IOSRAD.DLL
deleting: C:\WINDOWS\system32\ir2ol5f31.dll
Successfully Deleted: C:\WINDOWS\system32\ir2ol5f31.dll
deleting: C:\WINDOWS\system32\irl2l53o1.dll
Successfully Deleted: C:\WINDOWS\system32\irl2l53o1.dll
deleting: C:\WINDOWS\system32\ITMP.DLL
Successfully Deleted: C:\WINDOWS\system32\ITMP.DLL
deleting: C:\WINDOWS\system32\j4l4le3q1h.dll
Successfully Deleted: C:\WINDOWS\system32\j4l4le3q1h.dll
deleting: C:\WINDOWS\system32\jtl4073qe.dll
Successfully Deleted: C:\WINDOWS\system32\jtl4073qe.dll
deleting: C:\WINDOWS\system32\jtn8075ue.dll
Successfully Deleted: C:\WINDOWS\system32\jtn8075ue.dll
deleting: C:\WINDOWS\system32\k0800almedqa0.dll
Successfully Deleted: C:\WINDOWS\system32\k0800almedqa0.dll
deleting: C:\WINDOWS\system32\KIDSW.DLL
Successfully Deleted: C:\WINDOWS\system32\KIDSW.DLL
deleting: C:\WINDOWS\system32\KODRO.DLL
Successfully Deleted: C:\WINDOWS\system32\KODRO.DLL
deleting: C:\WINDOWS\system32\KRDHELA3.DLL
Successfully Deleted: C:\WINDOWS\system32\KRDHELA3.DLL
deleting: C:\WINDOWS\system32\kt4ol7h31.dll
Successfully Deleted: C:\WINDOWS\system32\kt4ol7h31.dll
deleting: C:\WINDOWS\system32\kt86l7ls1.dll
Successfully Deleted: C:\WINDOWS\system32\kt86l7ls1.dll
deleting: C:\WINDOWS\system32\ktl6l73s1.dll
Successfully Deleted: C:\WINDOWS\system32\ktl6l73s1.dll
deleting: C:\WINDOWS\system32\ktpsl7771.dll
Successfully Deleted: C:\WINDOWS\system32\ktpsl7771.dll
deleting: C:\WINDOWS\system32\l2j80c1uef.dll
Successfully Deleted: C:\WINDOWS\system32\l2j80c1uef.dll
deleting: C:\WINDOWS\system32\l6n40g5qe6.dll
Successfully Deleted: C:\WINDOWS\system32\l6n40g5qe6.dll
deleting: C:\WINDOWS\system32\lv6809jue.dll
Successfully Deleted: C:\WINDOWS\system32\lv6809jue.dll
deleting: C:\WINDOWS\system32\lvl6093se.dll
Successfully Deleted: C:\WINDOWS\system32\lvl6093se.dll
deleting: C:\WINDOWS\system32\m2460chsef460.dll
Successfully Deleted: C:\WINDOWS\system32\m2460chsef460.dll
deleting: C:\WINDOWS\system32\MEOBJS.DLL
Successfully Deleted: C:\WINDOWS\system32\MEOBJS.DLL
deleting: C:\WINDOWS\system32\MLAFD.DLL
Successfully Deleted: C:\WINDOWS\system32\MLAFD.DLL
deleting: C:\WINDOWS\system32\MNCONF.DLL
Successfully Deleted: C:\WINDOWS\system32\MNCONF.DLL
deleting: C:\WINDOWS\system32\MNDART.DLL
Successfully Deleted: C:\WINDOWS\system32\MNDART.DLL
deleting: C:\WINDOWS\system32\MNISAM11.DLL
Successfully Deleted: C:\WINDOWS\system32\MNISAM11.DLL
deleting: C:\WINDOWS\system32\MOHCP.DLL
Successfully Deleted: C:\WINDOWS\system32\MOHCP.DLL
deleting: C:\WINDOWS\system32\MPDOCS.DLL
Successfully Deleted: C:\WINDOWS\system32\MPDOCS.DLL
deleting: C:\WINDOWS\system32\MRSYSTEM.DLL
Successfully Deleted: C:\WINDOWS\system32\MRSYSTEM.DLL
deleting: C:\WINDOWS\system32\mtcans32.dll
Successfully Deleted: C:\WINDOWS\system32\mtcans32.dll
deleting: C:\WINDOWS\system32\mtjml9111.dll
Successfully Deleted: C:\WINDOWS\system32\mtjml9111.dll
deleting: C:\WINDOWS\system32\mv8ml9l11.dll
Successfully Deleted: C:\WINDOWS\system32\mv8ml9l11.dll
deleting: C:\WINDOWS\system32\mv8ql9l51.dll
Successfully Deleted: C:\WINDOWS\system32\mv8ql9l51.dll
deleting: C:\WINDOWS\system32\mv8ul9l91.dll
Successfully Deleted: C:\WINDOWS\system32\mv8ul9l91.dll
deleting: C:\WINDOWS\system32\MVC71ESP.DLL
Successfully Deleted: C:\WINDOWS\system32\MVC71ESP.DLL
deleting: C:\WINDOWS\system32\mvpol9731.dll
Successfully Deleted: C:\WINDOWS\system32\mvpol9731.dll
deleting: C:\WINDOWS\system32\MZWSOCK.DLL
Successfully Deleted: C:\WINDOWS\system32\MZWSOCK.DLL
deleting: C:\WINDOWS\system32\MZXOCI.DLL
Successfully Deleted: C:\WINDOWS\system32\MZXOCI.DLL
deleting: C:\WINDOWS\system32\n2l80c3uef.dll
Successfully Deleted: C:\WINDOWS\system32\n2l80c3uef.dll
deleting: C:\WINDOWS\system32\nbrsno.dll
Successfully Deleted: C:\WINDOWS\system32\nbrsno.dll
deleting: C:\WINDOWS\system32\nkrsfr.dll
Successfully Deleted: C:\WINDOWS\system32\nkrsfr.dll
deleting: C:\WINDOWS\system32\nlcpl.dll
Successfully Deleted: C:\WINDOWS\system32\nlcpl.dll
deleting: C:\WINDOWS\system32\NOTID.DLL
Successfully Deleted: C:\WINDOWS\system32\NOTID.DLL
deleting: C:\WINDOWS\system32\nwwrsnl.dll
Successfully Deleted: C:\WINDOWS\system32\nwwrsnl.dll
deleting: C:\WINDOWS\system32\o0rola931d.dll
Successfully Deleted: C:\WINDOWS\system32\o0rola931d.dll
deleting: C:\WINDOWS\system32\o6660gjse6o60.dll
Successfully Deleted: C:\WINDOWS\system32\o6660gjse6o60.dll
deleting: C:\WINDOWS\system32\o6lu0g39e6.dll
Successfully Deleted: C:\WINDOWS\system32\o6lu0g39e6.dll
deleting: C:\WINDOWS\system32\o866lijs18o6.dll
Successfully Deleted: C:\WINDOWS\system32\o866lijs18o6.dll
deleting: C:\WINDOWS\system32\OBECLI32.DLL
Successfully Deleted: C:\WINDOWS\system32\OBECLI32.DLL
deleting: C:\WINDOWS\system32\OWEACCRC.DLL
Successfully Deleted: C:\WINDOWS\system32\OWEACCRC.DLL
deleting: C:\WINDOWS\system32\PIRFNET.DLL
Successfully Deleted: C:\WINDOWS\system32\PIRFNET.DLL
deleting: C:\WINDOWS\system32\PVRFDISK.DLL
Successfully Deleted: C:\WINDOWS\system32\PVRFDISK.DLL
deleting: C:\WINDOWS\system32\q6860glse6q60.dll
Successfully Deleted: C:\WINDOWS\system32\q6860glse6q60.dll
deleting: C:\WINDOWS\system32\r08s0al7edq.dll
Successfully Deleted: C:\WINDOWS\system32\r08s0al7edq.dll
deleting: C:\WINDOWS\system32\r28slcl71fq.dll
Successfully Deleted: C:\WINDOWS\system32\r28slcl71fq.dll
deleting: C:\WINDOWS\system32\r4p80e7ueh.dll
Successfully Deleted: C:\WINDOWS\system32\r4p80e7ueh.dll
deleting: C:\WINDOWS\system32\r6p8lg7u16.dll
Successfully Deleted: C:\WINDOWS\system32\r6p8lg7u16.dll
deleting: C:\WINDOWS\system32\RAPDD.DLL
Successfully Deleted: C:\WINDOWS\system32\RAPDD.DLL
deleting: C:\WINDOWS\system32\SGMPSNAP.DLL
Successfully Deleted: C:\WINDOWS\system32\SGMPSNAP.DLL
deleting: C:\WINDOWS\system32\SIS.DLL
Successfully Deleted: C:\WINDOWS\system32\SIS.DLL
deleting: C:\WINDOWS\system32\TGEMBED.DLL
Successfully Deleted: C:\WINDOWS\system32\TGEMBED.DLL
deleting: C:\WINDOWS\system32\TMAFFIC.DLL
Successfully Deleted: C:\WINDOWS\system32\TMAFFIC.DLL
deleting: C:\WINDOWS\system32\TMPI.DLL
Successfully Deleted: C:\WINDOWS\system32\TMPI.DLL
deleting: C:\WINDOWS\system32\UDNPHOST.DLL
Successfully Deleted: C:\WINDOWS\system32\UDNPHOST.DLL
deleting: C:\WINDOWS\system32\wdvcore.dll
Successfully Deleted: C:\WINDOWS\system32\wdvcore.dll
deleting: C:\WINDOWS\system32\WENMM.DLL
Successfully Deleted: C:\WINDOWS\system32\WENMM.DLL
deleting: C:\WINDOWS\system32\XheedFtp.dll
Successfully Deleted: C:\WINDOWS\system32\XheedFtp.dll
deleting: C:\WINDOWS\system32\XveedFtp.dll
Successfully Deleted: C:\WINDOWS\system32\XveedFtp.dll

Desktop.ini sucessfully removed

Zipping up files for submission:
adding: ABI3D2AG.DLL (164 bytes security) (deflated 4%)
adding: aza0l39m1.dll (164 bytes security) (deflated 6%)
adding: CFFVIEW.DLL (164 bytes security) (deflated 4%)
adding: CVNFMSP.DLL (164 bytes security) (deflated 4%)
adding: CXPBK32.DLL (164 bytes security) (deflated 6%)
adding: CYBVIEW.DLL (164 bytes security) (deflated 4%)
adding: d20mlcd11f0.dll (164 bytes security) (deflated 4%)
adding: d2j0lc1m1f.dll (164 bytes security) (deflated 5%)
adding: djcompos.dll (164 bytes security) (deflated 4%)
adding: dn0u01d9e.dll (164 bytes security) (deflated 5%)
adding: dnjq0115e.dll (164 bytes security) (deflated 5%)
adding: dnn8015ue.dll (164 bytes security) (deflated 4%)
adding: dnps0177e.dll (164 bytes security) (deflated 4%)
adding: DORGSNAP.DLL (164 bytes security) (deflated 4%)
adding: en04l1dq1.dll (164 bytes security) (deflated 5%)
adding: EnnClass.Dll (164 bytes security) (deflated 4%)
adding: ennul1591.dll (164 bytes security) (deflated 5%)
adding: fp0403dqe.dll (164 bytes security) (deflated 4%)
adding: fqsui.dll (164 bytes security) (deflated 4%)
adding: g2jo0c13ef.dll (164 bytes security) (deflated 4%)
adding: gpr0l39m1.dll (164 bytes security) (deflated 6%)
adding: h0l20a3oed.dll (164 bytes security) (deflated 5%)
adding: h4n00e5meh.dll (164 bytes security) (deflated 5%)
adding: h82olif3182.dll (164 bytes security) (deflated 6%)
adding: hr4005hme.dll (164 bytes security) (deflated 5%)
adding: hrl2053oe.dll (164 bytes security) (deflated 6%)
adding: hrrs0597e.dll (164 bytes security) (deflated 4%)
adding: i0lo0a33ed.dll (164 bytes security) (deflated 5%)
adding: i6600gjme6oa0.dll (164 bytes security) (deflated 4%)
adding: i6jq0g15e6.dll (164 bytes security) (deflated 5%)
adding: i6nmlg5116.dll (164 bytes security) (deflated 4%)
adding: IGPEERS.DLL (164 bytes security) (deflated 4%)
adding: IOSRAD.DLL (164 bytes security) (deflated 4%)
adding: ir2ol5f31.dll (164 bytes security) (deflated 6%)
adding: irl2l53o1.dll (164 bytes security) (deflated 5%)
adding: ITMP.DLL (164 bytes security) (deflated 4%)
adding: j4l4le3q1h.dll (164 bytes security) (deflated 4%)
adding: jtl4073qe.dll (164 bytes security) (deflated 5%)
adding: jtn8075ue.dll (164 bytes security) (deflated 5%)
adding: k0800almedqa0.dll (164 bytes security) (deflated 5%)
adding: KIDSW.DLL (164 bytes security) (deflated 4%)
adding: KODRO.DLL (164 bytes security) (deflated 4%)
adding: KRDHELA3.DLL (164 bytes security) (deflated 4%)
adding: kt4ol7h31.dll (164 bytes security) (deflated 5%)
adding: kt86l7ls1.dll (164 bytes security) (deflated 5%)
adding: ktl6l73s1.dll (164 bytes security) (deflated 5%)
adding: ktpsl7771.dll (164 bytes security) (deflated 4%)
adding: l2j80c1uef.dll (164 bytes security) (deflated 5%)
adding: l6n40g5qe6.dll (164 bytes security) (deflated 4%)
adding: lv6809jue.dll (164 bytes security) (deflated 4%)
adding: lvl6093se.dll (164 bytes security) (deflated 5%)
adding: m2460chsef460.dll (164 bytes security) (deflated 5%)
adding: MEOBJS.DLL (164 bytes security) (deflated 4%)
adding: MLAFD.DLL (164 bytes security) (deflated 4%)
adding: MNCONF.DLL (164 bytes security) (deflated 4%)
adding: MNDART.DLL (164 bytes security) (deflated 4%)
adding: MNISAM11.DLL (164 bytes security) (deflated 5%)
adding: MOHCP.DLL (164 bytes security) (deflated 4%)
adding: MPDOCS.DLL (164 bytes security) (deflated 4%)
adding: MRSYSTEM.DLL (164 bytes security) (deflated 4%)
adding: mtcans32.dll (164 bytes security) (deflated 4%)
adding: mtjml9111.dll (164 bytes security) (deflated 4%)
adding: mv8ml9l11.dll (164 bytes security) (deflated 5%)
adding: mv8ql9l51.dll (164 bytes security) (deflated 4%)
adding: mv8ul9l91.dll (164 bytes security) (deflated 5%)
adding: MVC71ESP.DLL (164 bytes security) (deflated 4%)
adding: mvpol9731.dll (164 bytes security) (deflated 5%)
adding: MZWSOCK.DLL (164 bytes security) (deflated 4%)
adding: MZXOCI.DLL (164 bytes security) (deflated 4%)
adding: n2l80c3uef.dll (164 bytes security) (deflated 4%)
adding: nbrsno.dll (164 bytes security) (deflated 4%)
adding: nkrsfr.dll (164 bytes security) (deflated 4%)
adding: nlcpl.dll (164 bytes security) (deflated 5%)
adding: NOTID.DLL (164 bytes security) (deflated 5%)
adding: nwwrsnl.dll (164 bytes security) (deflated 4%)
adding: o0rola931d.dll (164 bytes security) (deflated 6%)
adding: o6660gjse6o60.dll (164 bytes security) (deflated 5%)
adding: o6lu0g39e6.dll (164 bytes security) (deflated 5%)
adding: o866lijs18o6.dll (164 bytes security) (deflated 6%)
adding: OBECLI32.DLL (164 bytes security) (deflated 6%)
adding: OWEACCRC.DLL (164 bytes security) (deflated 4%)
adding: PIRFNET.DLL (164 bytes security) (deflated 4%)
adding: PVRFDISK.DLL (164 bytes security) (deflated 4%)
adding: q6860glse6q60.dll (164 bytes security) (deflated 5%)
adding: r08s0al7edq.dll (164 bytes security) (deflated 5%)
adding: r28slcl71fq.dll (164 bytes security) (deflated 5%)
adding: r4p80e7ueh.dll (164 bytes security) (deflated 5%)
adding: r6p8lg7u16.dll (164 bytes security) (deflated 5%)
adding: RAPDD.DLL (164 bytes security) (deflated 6%)
adding: SGMPSNAP.DLL (164 bytes security) (deflated 4%)
adding: SIS.DLL (164 bytes security) (deflated 4%)
adding: TGEMBED.DLL (164 bytes security) (deflated 4%)
adding: TMAFFIC.DLL (164 bytes security) (deflated 4%)
adding: TMPI.DLL (164 bytes security) (deflated 4%)
adding: UDNPHOST.DLL (164 bytes security) (deflated 4%)
adding: wdvcore.dll (164 bytes security) (deflated 4%)
adding: WENMM.DLL (164 bytes security) (deflated 5%)
adding: XheedFtp.dll (164 bytes security) (deflated 4%)
adding: XveedFtp.dll (164 bytes security) (deflated 4%)
adding: clear.reg (164 bytes security) (deflated 63%)
adding: echo.reg (164 bytes security) (deflated 9%)
adding: desktop.ini (164 bytes security) (deflated 15%)
adding: direct.txt (164 bytes security) (stored 0%)
adding: lo2.txt (164 bytes security) (deflated 88%)
adding: readme.txt (164 bytes security) (deflated 49%)
adding: report.txt (164 bytes security) (deflated 68%)
adding: test.txt (164 bytes security) (deflated 83%)
adding: test2.txt (164 bytes security) (deflated 44%)
adding: test3.txt (164 bytes security) (deflated 44%)
adding: test5.txt (164 bytes security) (deflated 44%)
adding: xfind.txt (164 bytes security) (deflated 78%)
adding: backregs/38291AAC-3659-4963-B282-FFE45D9D6537.reg (164 bytes security) (deflated 69%)
adding: backregs/530B2C05-7D0C-4D22-86D5-2BD19F53F148.reg (164 bytes security) (deflated 69%)
adding: backregs/567C71FC-4462-451E-A694-575E204A0AE2.reg (164 bytes security) (deflated 69%)
adding: backregs/5AA9F982-2C27-465E-B174-0D530B0FB6C7.reg (164 bytes security) (deflated 69%)
adding: backregs/61ECF7B4-9FE7-42F0-866A-F47AA0C5807E.reg (164 bytes security) (deflated 69%)
adding: backregs/9F5C9B0E-03A5-47E5-BA64-54D2FE085C2D.reg (164 bytes security) (deflated 69%)
adding: backregs/B7B14F2F-B997-41A9-9145-ED3DBA649B07.reg (164 bytes security) (deflated 69%)
adding: backregs/BBAA76F5-F8A7-4E4D-8BDD-F473D0EA463C.reg (164 bytes security) (deflated 69%)
adding: backregs/F14E7CB9-818B-43B4-B569-968D443D2863.reg (164 bytes security) (deflated 69%)
adding: backregs/shell.reg (164 bytes security) (deflated 73%)

Restoring Registry Permissions:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!


Revoking access for predefined group "Administrators"
Inherited ACE can not be revoked here!
Inherited ACE can not be revoked here!


Registry permissions set too:

RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER


Restoring Sedebugprivilege:

Granting SeDebugPrivilege to Administrators … successful

deleting local copy: ABI3D2AG.DLL
deleting local copy: aza0l39m1.dll
deleting local copy: CFFVIEW.DLL
deleting local copy: CVNFMSP.DLL
deleting local copy: CXPBK32.DLL
deleting local copy: CYBVIEW.DLL
deleting local copy: d20mlcd11f0.dll
deleting local copy: d2j0lc1m1f.dll
deleting local copy: djcompos.dll
deleting local copy: dn0u01d9e.dll
deleting local copy: dnjq0115e.dll
deleting local copy: dnn8015ue.dll
deleting local copy: dnps0177e.dll
deleting local copy: DORGSNAP.DLL
deleting local copy: en04l1dq1.dll
deleting local copy: EnnClass.Dll
deleting local copy: ennul1591.dll
deleting local copy: fp0403dqe.dll
deleting local copy: fqsui.dll
deleting local copy: g2jo0c13ef.dll
deleting local copy: gpr0l39m1.dll
deleting local copy: h0l20a3oed.dll
deleting local copy: h4n00e5meh.dll
deleting local copy: h82olif3182.dll
deleting local copy: hr4005hme.dll
deleting local copy: hrl2053oe.dll
deleting local copy: hrrs0597e.dll
deleting local copy: i0lo0a33ed.dll
deleting local copy: i6600gjme6oa0.dll
deleting local copy: i6jq0g15e6.dll
deleting local copy: i6nmlg5116.dll
deleting local copy: IGPEERS.DLL
deleting local copy: IOSRAD.DLL
deleting local copy: ir2ol5f31.dll
deleting local copy: irl2l53o1.dll
deleting local copy: ITMP.DLL
deleting local copy: j4l4le3q1h.dll
deleting local copy: jtl4073qe.dll
deleting local copy: jtn8075ue.dll
deleting local copy: k0800almedqa0.dll
deleting local copy: KIDSW.DLL
deleting local copy: KODRO.DLL
deleting local copy: KRDHELA3.DLL
deleting local copy: kt4ol7h31.dll
deleting local copy: kt86l7ls1.dll
deleting local copy: ktl6l73s1.dll
deleting local copy: ktpsl7771.dll
deleting local copy: l2j80c1uef.dll
deleting local copy: l6n40g5qe6.dll
deleting local copy: lv6809jue.dll
deleting local copy: lvl6093se.dll
deleting local copy: m2460chsef460.dll
deleting local copy: MEOBJS.DLL
deleting local copy: MLAFD.DLL
deleting local copy: MNCONF.DLL
deleting local copy: MNDART.DLL
deleting local copy: MNISAM11.DLL
deleting local copy: MOHCP.DLL
deleting local copy: MPDOCS.DLL
deleting local copy: MRSYSTEM.DLL
deleting local copy: mtcans32.dll
deleting local copy: mtjml9111.dll
deleting local copy: mv8ml9l11.dll
deleting local copy: mv8ql9l51.dll
deleting local copy: mv8ul9l91.dll
deleting local copy: MVC71ESP.DLL
deleting local copy: mvpol9731.dll
deleting local copy: MZWSOCK.DLL
deleting local copy: MZXOCI.DLL
deleting local copy: n2l80c3uef.dll
deleting local copy: nbrsno.dll
deleting local copy: nkrsfr.dll
deleting local copy: nlcpl.dll
deleting local copy: NOTID.DLL
deleting local copy: nwwrsnl.dll
deleting local copy: o0rola931d.dll
deleting local copy: o6660gjse6o60.dll
deleting local copy: o6lu0g39e6.dll
deleting local copy: o866lijs18o6.dll
deleting local copy: OBECLI32.DLL
deleting local copy: OWEACCRC.DLL
deleting local copy: PIRFNET.DLL
deleting local copy: PVRFDISK.DLL
deleting local copy: q6860glse6q60.dll
deleting local copy: r08s0al7edq.dll
deleting local copy: r28slcl71fq.dll
deleting local copy: r4p80e7ueh.dll
deleting local copy: r6p8lg7u16.dll
deleting local copy: RAPDD.DLL
deleting local copy: SGMPSNAP.DLL
deleting local copy: SIS.DLL
deleting local copy: TGEMBED.DLL
deleting local copy: TMAFFIC.DLL
deleting local copy: TMPI.DLL
deleting local copy: UDNPHOST.DLL
deleting local copy: wdvcore.dll
deleting local copy: WENMM.DLL
deleting local copy: XheedFtp.dll
deleting local copy: XveedFtp.dll

The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\req]
"Asynchronous"=dword:00000001
"DllName"="C:\\WINDOWS\\System32\\req.dat"
"Impersonate"=dword:00000000
"Logon"="MachineLogon"
"Logoff"="MachineLogoff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


The following are the files found:
****************************************************************************
C:\WINDOWS\system32\ABI3D2AG.DLL
C:\WINDOWS\system32\aza0l39m1.dll
C:\WINDOWS\system32\CFFVIEW.DLL
C:\WINDOWS\system32\CVNFMSP.DLL
C:\WINDOWS\system32\CXPBK32.DLL
C:\WINDOWS\system32\CYBVIEW.DLL
C:\WINDOWS\system32\d20mlcd11f0.dll
C:\WINDOWS\system32\d2j0lc1m1f.dll
C:\WINDOWS\system32\djcompos.dll
C:\WINDOWS\system32\dn0u01d9e.dll
C:\WINDOWS\system32\dnjq0115e.dll
C:\WINDOWS\system32\dnn8015ue.dll
C:\WINDOWS\system32\dnps0177e.dll
C:\WINDOWS\system32\DORGSNAP.DLL
C:\WINDOWS\system32\en04l1dq1.dll
C:\WINDOWS\system32\EnnClass.Dll
C:\WINDOWS\system32\ennul1591.dll
C:\WINDOWS\system32\fp0403dqe.dll
C:\WINDOWS\system32\fqsui.dll
C:\WINDOWS\system32\g2jo0c13ef.dll
C:\WINDOWS\system32\gpr0l39m1.dll
C:\WINDOWS\system32\h0l20a3oed.dll
C:\WINDOWS\system32\h4n00e5meh.dll
C:\WINDOWS\system32\h82olif3182.dll
C:\WINDOWS\system32\hr4005hme.dll
C:\WINDOWS\system32\hrl2053oe.dll
C:\WINDOWS\system32\hrrs0597e.dll
C:\WINDOWS\system32\i0lo0a33ed.dll
C:\WINDOWS\system32\i6600gjme6oa0.dll
C:\WINDOWS\system32\i6jq0g15e6.dll
C:\WINDOWS\system32\i6nmlg5116.dll
C:\WINDOWS\system32\IGPEERS.DLL
C:\WINDOWS\system32\IOSRAD.DLL
C:\WINDOWS\system32\ir2ol5f31.dll
C:\WINDOWS\system32\irl2l53o1.dll
C:\WINDOWS\system32\ITMP.DLL
C:\WINDOWS\system32\j4l4le3q1h.dll
C:\WINDOWS\system32\jtl4073qe.dll
C:\WINDOWS\system32\jtn8075ue.dll
C:\WINDOWS\system32\k0800almedqa0.dll
C:\WINDOWS\system32\KIDSW.DLL
C:\WINDOWS\system32\KODRO.DLL
C:\WINDOWS\system32\KRDHELA3.DLL
C:\WINDOWS\system32\kt4ol7h31.dll
C:\WINDOWS\system32\kt86l7ls1.dll
C:\WINDOWS\system32\ktl6l73s1.dll
C:\WINDOWS\system32\ktpsl7771.dll
C:\WINDOWS\system32\l2j80c1uef.dll
C:\WINDOWS\system32\l6n40g5qe6.dll
C:\WINDOWS\system32\lv6809jue.dll
C:\WINDOWS\system32\lvl6093se.dll
C:\WINDOWS\system32\m2460chsef460.dll
C:\WINDOWS\system32\MEOBJS.DLL
C:\WINDOWS\system32\MLAFD.DLL
C:\WINDOWS\system32\MNCONF.DLL
C:\WINDOWS\system32\MNDART.DLL
C:\WINDOWS\system32\MNISAM11.DLL
C:\WINDOWS\system32\MOHCP.DLL
C:\WINDOWS\system32\MPDOCS.DLL
C:\WINDOWS\system32\MRSYSTEM.DLL
C:\WINDOWS\system32\mtcans32.dll
C:\WINDOWS\system32\mtjml9111.dll
C:\WINDOWS\system32\mv8ml9l11.dll
C:\WINDOWS\system32\mv8ql9l51.dll
C:\WINDOWS\system32\mv8ul9l91.dll
C:\WINDOWS\system32\MVC71ESP.DLL
C:\WINDOWS\system32\mvpol9731.dll
C:\WINDOWS\system32\MZWSOCK.DLL
C:\WINDOWS\system32\MZXOCI.DLL
C:\WINDOWS\system32\n2l80c3uef.dll
C:\WINDOWS\system32\nbrsno.dll
C:\WINDOWS\system32\nkrsfr.dll
C:\WINDOWS\system32\nlcpl.dll
C:\WINDOWS\system32\NOTID.DLL
C:\WINDOWS\system32\nwwrsnl.dll
C:\WINDOWS\system32\o0rola931d.dll
C:\WINDOWS\system32\o6660gjse6o60.dll
C:\WINDOWS\system32\o6lu0g39e6.dll
C:\WINDOWS\system32\o866lijs18o6.dll
C:\WINDOWS\system32\OBECLI32.DLL
C:\WINDOWS\system32\OWEACCRC.DLL
C:\WINDOWS\system32\PIRFNET.DLL
C:\WINDOWS\system32\PVRFDISK.DLL
C:\WINDOWS\system32\q6860glse6q60.dll
C:\WINDOWS\system32\r08s0al7edq.dll
C:\WINDOWS\system32\r28slcl71fq.dll
C:\WINDOWS\system32\r4p80e7ueh.dll
C:\WINDOWS\system32\r6p8lg7u16.dll
C:\WINDOWS\system32\RAPDD.DLL
C:\WINDOWS\system32\SGMPSNAP.DLL
C:\WINDOWS\system32\SIS.DLL
C:\WINDOWS\system32\TGEMBED.DLL
C:\WINDOWS\system32\TMAFFIC.DLL
C:\WINDOWS\system32\TMPI.DLL
C:\WINDOWS\system32\UDNPHOST.DLL
C:\WINDOWS\system32\wdvcore.dll
C:\WINDOWS\system32\WENMM.DLL
C:\WINDOWS\system32\XheedFtp.dll
C:\WINDOWS\system32\XveedFtp.dll

Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{567C71FC-4462-451E-A694-575E204A0AE2}"=-
"{BBAA76F5-F8A7-4E4D-8BDD-F473D0EA463C}"=-
"{61ECF7B4-9FE7-42F0-866A-F47AA0C5807E}"=-
"{38291AAC-3659-4963-B282-FFE45D9D6537}"=-
"{5AA9F982-2C27-465E-B174-0D530B0FB6C7}"=-
"{530B2C05-7D0C-4D22-86D5-2BD19F53F148}"=-
"{B7B14F2F-B997-41A9-9145-ED3DBA649B07}"=-
"{9F5C9B0E-03A5-47E5-BA64-54D2FE085C2D}"=-
"{F14E7CB9-818B-43B4-B569-968D443D2863}"=-
[-HKEY_CLASSES_ROOT\CLSID\{567C71FC-4462-451E-A694-575E204A0AE2}]
[-HKEY_CLASSES_ROOT\CLSID\{BBAA76F5-F8A7-4E4D-8BDD-F473D0EA463C}]
[-HKEY_CLASSES_ROOT\CLSID\{61ECF7B4-9FE7-42F0-866A-F47AA0C5807E}]
[-HKEY_CLASSES_ROOT\CLSID\{38291AAC-3659-4963-B282-FFE45D9D6537}]
[-HKEY_CLASSES_ROOT\CLSID\{5AA9F982-2C27-465E-B174-0D530B0FB6C7}]
[-HKEY_CLASSES_ROOT\CLSID\{530B2C05-7D0C-4D22-86D5-2BD19F53F148}]
[-HKEY_CLASSES_ROOT\CLSID\{B7B14F2F-B997-41A9-9145-ED3DBA649B07}]
[-HKEY_CLASSES_ROOT\CLSID\{9F5C9B0E-03A5-47E5-BA64-54D2FE085C2D}]
[-HKEY_CLASSES_ROOT\CLSID\{F14E7CB9-818B-43B4-B569-968D443D2863}]
REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"SV1"=""
****************************************************************************
Desktop.ini Contents:
****************************************************************************
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
{CFCDB0B3-297A-41BE-8D41-203A926103E7}
VT00
200
****************************************************************************


Logfile of HijackThis v1.99.1
Scan saved at 2:24:06 PM, on 3/20/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\TrojanHunter 4.0\THGuard.exe
c:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Bonnie\Local Settings\Temp\Temporary Directory 1 for hijackthis1991.zip\HijackThis.exe
C:\Documents and Settings\Bonnie\Local Settings\Temp\Temporary Directory 2 for hijackthis1991.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = www.google.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {1C044AAD-7955-4cbd-8175-501A165C4E5D} - C:\WINDOWS\System32\req.dat
O4 - HKLM\..\Run: [DwlClient] c:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.0\THGuard.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by10fd.bay10.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1111340562828
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O20 - Winlogon Notify: req - C:\WINDOWS\System32\req.dat
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Thanks again LDTate!
Important: Do this before any fix.

Please put your HijackThis in it's own folder, (I create a new folder in C:\ named HJT).
You can do a Right Click on any open area on the desktop, New> Folder, then rename the folder HJT.

Go to where your HijackThis is and Right Click on HijackThis.exe, select Cut, then open the new folder you just created (HJT) Right Click in the folder and select paste.

The reason we do this is Hijackthis creates backup files just in case you'd need to restore one and we'll be cleaning out the temp files.



After the above:


I suggest you do this:

Run Hijack This again and put a check by these.

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: (no name) - {1C044AAD-7955-4cbd-8175-501A165C4E5D} - C:\WINDOWS\System32\req.dat

O20 - Winlogon Notify: req - C:\WINDOWS\System32\req.dat


Close ALL windows and browsers except HijackThis and click "Fix checked"


1. Open My Computer
2. Right click on your hard drive that you wish to clean (C drive, for example)
3. In the context menu that opens, select properties
4. Under the general tab you should select Disk Cleanup
5. Windows will scan your drive which will take a few seconds/minutes
6. A box will display the various files you can remove.
Check all boxes except compress old files (If listed)
7. Click OK and windows will comply.

Restart your computer.

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
HJT does'nt seem to want to get rid of the req.dat entries, I even tried to use HJT in safe mode and that still did'nt work. They keep coming back when I re-scan. As far as how this computer acting, it's a lot better. I have'nt had a popup in awhile. The only weird thing it's donig now is IE will not open in a full browser, I can see about an inch of the desktop on top and the bottom inch of IE is not viewable. I find this very strange, it just started doing this about a half-hour ago. Anyway here is my new HJT log and thanks again.

Logfile of HijackThis v1.99.1
Scan saved at 2:59:05 PM, on 3/20/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
c:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Bonnie\Desktop\hjt1991\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = www.google.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {1C044AAD-7955-4cbd-8175-501A165C4E5D} - C:\WINDOWS\System32\req.dat
O4 - HKLM\..\Run: [DwlClient] c:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.0\THGuard.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by10fd.bay10.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1111340562828
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O20 - Winlogon Notify: req - C:\WINDOWS\System32\req.dat
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Download KillBox.zip from here:
http://www.downloads.subratam.org/KillBox.zip
Place it in a folder on your Desktop.

Extract KillBox from the zip file and double-click on KillBox.exe to run it.

In the main screen of Pocket KillBox, go to Tools in the top menu bar, and select: Delete Temp Files.

Back at the main screen of KillBox, select the option: Delete on Reboot

In the Full Path of File to Delete box, copy and paste this entry:
C:\WINDOWS\System32\req.dat
Press the button with a red circle and a white X.
When asked if you would like to Reboot, select Yes



Run Hijack This again and put a check by these.

O2 - BHO: (no name) - {1C044AAD-7955-4cbd-8175-501A165C4E5D} - C:\WINDOWS\System32\req.dat

O20 - Winlogon Notify: req - C:\WINDOWS\System32\req.dat


Close ALL windows and browsers except HijackThis and click "Fix checked"


Empty Recycle Bin

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
That did it! Thank you so much. This computer is acting a lot better. Before, everytime I clicked on one of the links included in your messages, IE froze. But that is no longer the case. The full browser problem still exists though.
I'm not really concerned with that because I've got Firefox downloaded, I just did'nt want to install it until some of these problems were cleared up. I'm assuming Firefox will not have this same problem. But if you have any idea what might be causing that it would be nice to fix. Once again, thank you LDTate.
Here is my new HJT log.


Logfile of HijackThis v1.99.1
Scan saved at 3:30:11 PM, on 3/20/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
c:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Bonnie\Desktop\hjt1991\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = www.google.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O4 - HKLM\..\Run: [DwlClient] c:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.0\THGuard.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by10fd.bay10.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1111340562828
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Can you adjust it? Click and hold the mouse button on bottom corner and drag it open or click and hold on the top bar and adjust it?
Yep, that worked, boy do I feel silly. :lol: Everything seems to be working ok now. Thank you very much LDTate. I have made a small donation to Tom Coyote, I wish I could do more because you guys are the best! Have a wonderful day!
Good Job :thumbup:


Log looks good :D :thumbup:

Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.

Click Start> My Computer, select the Tools menu and then Folder Options, after the new window appears select the View tab…]
This time select the: Restore Defaults
Select: Apply, and click OK




If you dont have these three programs I would recommend that you get them. Spywareblaster, Spywareguard and IESPY AD. They will add 1000's of sites to your resticted zone and block some hijacks from happening. I also have a FREE FIREWALL and FREE ANTI VIRUS if you need one.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Safe Surfing. :D
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI