This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

What do I delete?

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 6:55:15 PM, on 8/11/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Verizon Online\bin\mpbtn.exe
C:\WINDOWS\T3duZXIA\command.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [57mV3FR] clel32.exe
O4 - HKLM\..\Run: [VBundleOuterDL] C:\Program Files\VBouncer\BundleOuter.EXE
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [exp] C:\WINDOWS\System32\exp
O4 - HKLM\..\Run: [ttupt] C:\WINDOWS\ttupt.exe
O4 - HKLM\..\Run: [System service62] C:\WINDOWS\etb\pokapoka62.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\bin\matcli.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} (Verizon Broadband Toolbar) - http://www2.verizon.net/micro/vol_toolbar/vzbb.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/22224bcabf9d5c…ip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1120219649179
O16 - DPF: {D06A22B4-6087-4D3D-B7AF-82B113E9ABD4} (CPostLaunch Object) - http://www2.verizon.net/update/msnwebinsta…es/vzWebIns.CAB
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spyspotter/…rCabInstall.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O20 - Winlogon Notify: MediaContentIndex - C:\WINDOWS\system32\MQSTKPRP.DLL
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\T3duZXIA\command.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
Greetings and welcome to TomCoyote.org!

We need to disable your Microsoft AntiSpyware Real-time Protection as it may interfere with the fixes that we need to make.
  • Open Microsoft AntiSpyware.
  • Click on Options, Settings.
  • In the left pane, click on Real-time Protection.
  • Under Startup Options uncheck Enable the Microsoft AntiSpyware Security Agents on startup (recommended).
  • Under Real-time spyware threat protection uncheck Enable real-time spyware threat protection (recommended).
  • After you uncheck these, click on the Save button and close Microsoft AntiSpyware.
  • Right click on the Microsoft AntiSpyware icon on the taskbar and select Shutdown Microsoft AntiSpyware.
After all of the fixes are complete it is very important that you enable Real-time Protection again.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

O4 - HKLM\..\Run: [57mV3FR] clel32.exe

O4 - HKLM\..\Run: [VBundleOuterDL] C:\Program Files\VBouncer\BundleOuter.EXE

O4 - HKLM\..\Run: [ttupt] C:\WINDOWS\ttupt.exe

O4 - HKLM\..\Run: [System service62] C:\WINDOWS\etb\pokapoka62.exe

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/22224bcabf9d5c…ip/RdxIE601.cab

O20 - Winlogon Notify: MediaContentIndex - C:\WINDOWS\system32\MQSTKPRP.DLL

O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\T3duZXIA\command.exe

Then click "Fix checked and close Hijack This!.

Now, please go to:

Start –> Run

In the box type in services.msc then hit < Enter > (or click OK)

In the Name column for:

Command Service (cmdService)

< Double-click > it.

In the dialogue box that pops up, check in the Path to executable box.

It should say: C:\WINDOWS\T3duZXIA\command.exe

That's how to be sure you have the right one.

Now, click Stop to stop that rogue process. If the Stop button is greyed out, just continue with the rest of the instructions.

In the Startup type box, change it to Disabled.

Click Apply then OK

Close the services.msc window.

Reboot in "safe" mode.

Delete all of these noted file(s)/FOLDER(s) you can find:

c:\program files\vbouncer <— FOLDER

c:\windows\etb <— FOLDER

c:\windows\system32\mqstkprp.dll <— file

c:\windows\t3duzxia <— FOLDER

c:\windows\ttupt.exe <— file

clel32.exe <— file

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new log file into this thread. :)
I hope I did everything right - Thanks!

Logfile of HijackThis v1.99.1
Scan saved at 5:28:23 PM, on 8/12/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Verizon Online\bin\mpbtn.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\HJT\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://69.28.210.175/media/1
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [exp] C:\WINDOWS\System32\exp
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\bin\matcli.exe
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} (Verizon Broadband Toolbar) - http://www2.verizon.net/micro/vol_toolbar/vzbb.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1120219649179
O16 - DPF: {D06A22B4-6087-4D3D-B7AF-82B113E9ABD4} (CPostLaunch Object) - http://www2.verizon.net/update/msnwebinsta…es/vzWebIns.CAB
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spyspotter/…rCabInstall.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O20 - Winlogon Notify: Uninstall - C:\WINDOWS\system32\MQSTKPRP.DLL
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
You did everything just PERFECT!!! :thumbup:

There is another bug still in there, but it takes a special tool/process to remove.

So, with that being said… Lets' get started!!!

Download L2mfix from one of these two locations:

http://www.atribune.org/downloads/l2mfix.exe

http://www.downloads.subratam.org/l2mfix.exe

Save the file to your desktop and l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop.

l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing .

This will scan your computer and it may appear nothing is happening, then, after a minute or 2, Notepad will open with a log. Copy/paste the contents of that log into this thread.


IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!
Yikes, I don't know how anyone can understand this stuff! L2MFIX find log 1.03 These are the registry keys present ********************************************************************************** Winlogon/notify: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Uninstall] "Asynchronous"=dword:00000000 "DllName"="C:\\WINDOWS\\system32\\MQSTKPRP.DLL" "Impersonate"=dword:00000000 "Logon"="WinLogon" "Logoff"="WinLogoff" "Shutdown"="WinShutdown" ********************************************************************************** useragent: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] "{087253D5-7495-66B9-5223-C1D68DF9D40F}"="" ********************************************************************************** Shell Extension key: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved] "{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet" "{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management" "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page" "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page" "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing" "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension" "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension" "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension" "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension" "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page" "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page" "{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler" "{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension" "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects" "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management" "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management" "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression" "{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension" "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI" "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu" "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase" "{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext" "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts" "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile" "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page" "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing" "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension" "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension" "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension" "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections" "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections" "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras" "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras" "{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras" "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras" "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras" "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension" "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension" "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host" "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link" "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler" "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension" "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks" "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu" "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search" "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support" "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support" "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run…" "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet" "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail" "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts" "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools" "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler" "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler" "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler" "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler" "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler" "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor" "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar" "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status" "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder" "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2" "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy" "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand" "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band" "{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band" "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search" "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search" "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility" "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address" "{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox" "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete" "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor" "{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List" "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List" "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible" "{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar" "{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser" "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List" "{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List" "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container" "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu" "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp" "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar" "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite" "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist" "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings" "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band" "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service" "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer" "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture" "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut" "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service" "{FF393560-C2A7-11CF-BFF4-444553540000}"="History" "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files" "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files" "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook" "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen" "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook" "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC" "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC" "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet" "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space" "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band" "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service" "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service" "{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder" "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck" "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr" "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder" "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler" "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent" "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent" "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent" "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent" "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent" "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler" "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager" "{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator" "{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher" "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs" "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory" "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor" "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)" "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor" "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler" "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard" "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web" "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object" "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard" "{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts" "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler" "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target" "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File" "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut" "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object" "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu" "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties" "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview" "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext" "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control" "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control" "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control" "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control" "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control" "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI" "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object" "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find" "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find" "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI" "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs" "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook" "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target" "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties" "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu" "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options" "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder" "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler" "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell" "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%" "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler" "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer" "{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People…" "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler" "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler" "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler" "{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}"="iTunes" "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player" "{5B776F24-3912-498B-90C5-2C9F84358265}"="" "{C328CC14-4361-4115-AD5E-3F6E19C2E000}"="" "{A48ED3CD-E8D5-441D-B185-B96B2C51C07B}"="" "{879DEA20-15B1-46FB-9853-8EA1ADE80431}"="" "{5E87E2B7-1E03-4F9C-A038-46F41666BADA}"="" "{A180E92E-9EB8-4A8C-B426-54E05AFF6ECC}"="" "{71BD64C7-AD73-4AE3-8764-26C4230ECE4C}"="" "{B86FA157-A6EC-41BB-82B4-CA2C36673CC6}"="" "{6C4E4E6F-52FD-4D18-A37D-C1CE72971B8B}"="" "{EFD66FA1-E49E-48A0-9759-B40961CC3C0B}"="" "{6544C9BA-A4AA-4E00-B7F5-F8EF8D0C3111}"="" "{4CDC0D82-00B8-464B-8027-68B1E5BC98E3}"="" "{0170732E-68EA-4C62-A624-4BF40200A682}"="" "{8BDB6836-424B-401A-BFC4-891A15D9FB2C}"="" "{664941B1-AC63-47AF-86DA-B5451BC76CF8}"="" "{123BDDC9-440E-4045-9DFA-05844210CD19}"="" "{77A1836C-52FC-4930-AF69-336D5D00ED38}"="" "{576BF191-9CD1-4645-814F-B28F31158A01}"="" "{EA4A88E0-7033-4FDD-AE7E-D8ECC3EAE70D}"="" "{D3E97FCC-4DA0-4165-BE6D-AE22E211F725}"="" "{68E2F03E-ED73-40E4-B262-F106A6D3E986}"="" "{8C9DA99B-20E7-4127-841D-70FB76412C07}"="" "{3F097533-8009-4081-99BD-DA4594CD5A55}"="" "{BBD43B64-2ED7-4D94-B9AB-BDA66F56CB2B}"="" "{2D0C1946-75CA-4398-A0F7-65017E68637C}"="" "{5086A582-7719-45C1-A020-0DF9ABBFF79A}"="" "{F5E1426A-D1E1-4A4A-A7D9-2A65E1DE8E67}"="" "{3EC983EE-F1EA-429D-B642-4BBE0FFAC838}"="" "{D93069D1-910F-4C82-9998-20ED52BB7E22}"="" "{94215412-6DCC-4459-9DF2-737D09509091}"="" "{C8225CDC-FB9E-4087-9C37-89DF27102DC8}"="" "{39BA1F1C-AF6D-4887-B93A-1C96EE287BA8}"="" "{65C32534-30DE-4B19-BE0E-519F99A47FDD}"="" "{1D5663B0-A5BC-4E69-8D42-7FB13E5F4518}"="" "{D3A69A1D-5714-4A00-BFC2-477C46D322A7}"="" ********************************************************************************** HKEY ROOT CLASSIDS: Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{5B776F24-3912-498B-90C5-2C9F84358265}] @="" [HKEY_CLASSES_ROOT\CLSID\{5B776F24-3912-498B-90C5-2C9F84358265}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{5B776F24-3912-498B-90C5-2C9F84358265}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{5B776F24-3912-498B-90C5-2C9F84358265}\InprocServer32] @="C:\\WINDOWS\\system32\\hvui.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{C328CC14-4361-4115-AD5E-3F6E19C2E000}] @="" [HKEY_CLASSES_ROOT\CLSID\{C328CC14-4361-4115-AD5E-3F6E19C2E000}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{C328CC14-4361-4115-AD5E-3F6E19C2E000}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{C328CC14-4361-4115-AD5E-3F6E19C2E000}\InprocServer32] @="C:\\WINDOWS\\system32\\dnghelp.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{A48ED3CD-E8D5-441D-B185-B96B2C51C07B}] @="" [HKEY_CLASSES_ROOT\CLSID\{A48ED3CD-E8D5-441D-B185-B96B2C51C07B}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{A48ED3CD-E8D5-441D-B185-B96B2C51C07B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{A48ED3CD-E8D5-441D-B185-B96B2C51C07B}\InprocServer32] @="C:\\WINDOWS\\system32\\rzpwsx.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{879DEA20-15B1-46FB-9853-8EA1ADE80431}] @="" [HKEY_CLASSES_ROOT\CLSID\{879DEA20-15B1-46FB-9853-8EA1ADE80431}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{879DEA20-15B1-46FB-9853-8EA1ADE80431}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{879DEA20-15B1-46FB-9853-8EA1ADE80431}\InprocServer32] @="C:\\WINDOWS\\system32\\iXlmdev5.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{5E87E2B7-1E03-4F9C-A038-46F41666BADA}] @="" [HKEY_CLASSES_ROOT\CLSID\{5E87E2B7-1E03-4F9C-A038-46F41666BADA}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{5E87E2B7-1E03-4F9C-A038-46F41666BADA}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{5E87E2B7-1E03-4F9C-A038-46F41666BADA}\InprocServer32] @="C:\\WINDOWS\\system32\\mmjet40.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{A180E92E-9EB8-4A8C-B426-54E05AFF6ECC}] @="" [HKEY_CLASSES_ROOT\CLSID\{A180E92E-9EB8-4A8C-B426-54E05AFF6ECC}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{A180E92E-9EB8-4A8C-B426-54E05AFF6ECC}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{A180E92E-9EB8-4A8C-B426-54E05AFF6ECC}\InprocServer32] @="C:\\WINDOWS\\system32\\dbmv2clt.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{71BD64C7-AD73-4AE3-8764-26C4230ECE4C}] @="" [HKEY_CLASSES_ROOT\CLSID\{71BD64C7-AD73-4AE3-8764-26C4230ECE4C}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{71BD64C7-AD73-4AE3-8764-26C4230ECE4C}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{71BD64C7-AD73-4AE3-8764-26C4230ECE4C}\InprocServer32] @="C:\\WINDOWS\\system32\\oye2nls.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{B86FA157-A6EC-41BB-82B4-CA2C36673CC6}] @="" [HKEY_CLASSES_ROOT\CLSID\{B86FA157-A6EC-41BB-82B4-CA2C36673CC6}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{B86FA157-A6EC-41BB-82B4-CA2C36673CC6}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{B86FA157-A6EC-41BB-82B4-CA2C36673CC6}\InprocServer32] @="C:\\WINDOWS\\system32\\kvd106.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{6C4E4E6F-52FD-4D18-A37D-C1CE72971B8B}] @="" [HKEY_CLASSES_ROOT\CLSID\{6C4E4E6F-52FD-4D18-A37D-C1CE72971B8B}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{6C4E4E6F-52FD-4D18-A37D-C1CE72971B8B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{6C4E4E6F-52FD-4D18-A37D-C1CE72971B8B}\InprocServer32] @="C:\\WINDOWS\\system32\\sjscrap.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{EFD66FA1-E49E-48A0-9759-B40961CC3C0B}] @="" [HKEY_CLASSES_ROOT\CLSID\{EFD66FA1-E49E-48A0-9759-B40961CC3C0B}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{EFD66FA1-E49E-48A0-9759-B40961CC3C0B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{EFD66FA1-E49E-48A0-9759-B40961CC3C0B}\InprocServer32] @="C:\\WINDOWS\\system32\\fmamebuf.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{6544C9BA-A4AA-4E00-B7F5-F8EF8D0C3111}] @="" [HKEY_CLASSES_ROOT\CLSID\{6544C9BA-A4AA-4E00-B7F5-F8EF8D0C3111}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{6544C9BA-A4AA-4E00-B7F5-F8EF8D0C3111}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{6544C9BA-A4AA-4E00-B7F5-F8EF8D0C3111}\InprocServer32] @="C:\\WINDOWS\\system32\\ajtodisc.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{4CDC0D82-00B8-464B-8027-68B1E5BC98E3}] @="" [HKEY_CLASSES_ROOT\CLSID\{4CDC0D82-00B8-464B-8027-68B1E5BC98E3}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{4CDC0D82-00B8-464B-8027-68B1E5BC98E3}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{4CDC0D82-00B8-464B-8027-68B1E5BC98E3}\InprocServer32] @="C:\\WINDOWS\\system32\\ig41_qc.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{0170732E-68EA-4C62-A624-4BF40200A682}] @="" [HKEY_CLASSES_ROOT\CLSID\{0170732E-68EA-4C62-A624-4BF40200A682}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{0170732E-68EA-4C62-A624-4BF40200A682}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{0170732E-68EA-4C62-A624-4BF40200A682}\InprocServer32] @="C:\\WINDOWS\\system32\\mhiqtz32.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{8BDB6836-424B-401A-BFC4-891A15D9FB2C}] @="" [HKEY_CLASSES_ROOT\CLSID\{8BDB6836-424B-401A-BFC4-891A15D9FB2C}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{8BDB6836-424B-401A-BFC4-891A15D9FB2C}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{8BDB6836-424B-401A-BFC4-891A15D9FB2C}\InprocServer32] @="C:\\WINDOWS\\system32\\onethk32.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{664941B1-AC63-47AF-86DA-B5451BC76CF8}] @="" [HKEY_CLASSES_ROOT\CLSID\{664941B1-AC63-47AF-86DA-B5451BC76CF8}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{664941B1-AC63-47AF-86DA-B5451BC76CF8}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{664941B1-AC63-47AF-86DA-B5451BC76CF8}\InprocServer32] @="C:\\WINDOWS\\system32\\stcurity.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{123BDDC9-440E-4045-9DFA-05844210CD19}] @="" [HKEY_CLASSES_ROOT\CLSID\{123BDDC9-440E-4045-9DFA-05844210CD19}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{123BDDC9-440E-4045-9DFA-05844210CD19}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{123BDDC9-440E-4045-9DFA-05844210CD19}\InprocServer32] @="C:\\WINDOWS\\system32\\dkvoice.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{77A1836C-52FC-4930-AF69-336D5D00ED38}] @="" [HKEY_CLASSES_ROOT\CLSID\{77A1836C-52FC-4930-AF69-336D5D00ED38}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{77A1836C-52FC-4930-AF69-336D5D00ED38}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{77A1836C-52FC-4930-AF69-336D5D00ED38}\InprocServer32] @="C:\\WINDOWS\\system32\\sfbrccsp.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{576BF191-9CD1-4645-814F-B28F31158A01}] @="" [HKEY_CLASSES_ROOT\CLSID\{576BF191-9CD1-4645-814F-B28F31158A01}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{576BF191-9CD1-4645-814F-B28F31158A01}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{576BF191-9CD1-4645-814F-B28F31158A01}\InprocServer32] @="C:\\WINDOWS\\system32\\mjwstr10.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{EA4A88E0-7033-4FDD-AE7E-D8ECC3EAE70D}] @="" [HKEY_CLASSES_ROOT\CLSID\{EA4A88E0-7033-4FDD-AE7E-D8ECC3EAE70D}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{EA4A88E0-7033-4FDD-AE7E-D8ECC3EAE70D}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{EA4A88E0-7033-4FDD-AE7E-D8ECC3EAE70D}\InprocServer32] @="C:\\WINDOWS\\system32\\rnoc3260.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{D3E97FCC-4DA0-4165-BE6D-AE22E211F725}] @="" [HKEY_CLASSES_ROOT\CLSID\{D3E97FCC-4DA0-4165-BE6D-AE22E211F725}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{D3E97FCC-4DA0-4165-BE6D-AE22E211F725}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{D3E97FCC-4DA0-4165-BE6D-AE22E211F725}\InprocServer32] @="C:\\WINDOWS\\system32\\ikm32.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{68E2F03E-ED73-40E4-B262-F106A6D3E986}] @="" [HKEY_CLASSES_ROOT\CLSID\{68E2F03E-ED73-40E4-B262-F106A6D3E986}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{68E2F03E-ED73-40E4-B262-F106A6D3E986}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{68E2F03E-ED73-40E4-B262-F106A6D3E986}\InprocServer32] @="C:\\WINDOWS\\system32\\ahl.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{8C9DA99B-20E7-4127-841D-70FB76412C07}] @="" [HKEY_CLASSES_ROOT\CLSID\{8C9DA99B-20E7-4127-841D-70FB76412C07}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{8C9DA99B-20E7-4127-841D-70FB76412C07}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{8C9DA99B-20E7-4127-841D-70FB76412C07}\InprocServer32] @="C:\\WINDOWS\\system32\\muwmdmsp.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{3F097533-8009-4081-99BD-DA4594CD5A55}] @="" [HKEY_CLASSES_ROOT\CLSID\{3F097533-8009-4081-99BD-DA4594CD5A55}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{3F097533-8009-4081-99BD-DA4594CD5A55}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{3F097533-8009-4081-99BD-DA4594CD5A55}\InprocServer32] @="C:\\WINDOWS\\system32\\TESServer.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{BBD43B64-2ED7-4D94-B9AB-BDA66F56CB2B}] @="" [HKEY_CLASSES_ROOT\CLSID\{BBD43B64-2ED7-4D94-B9AB-BDA66F56CB2B}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{BBD43B64-2ED7-4D94-B9AB-BDA66F56CB2B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{BBD43B64-2ED7-4D94-B9AB-BDA66F56CB2B}\InprocServer32] @="C:\\WINDOWS\\system32\\oatext32.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{2D0C1946-75CA-4398-A0F7-65017E68637C}] @="" [HKEY_CLASSES_ROOT\CLSID\{2D0C1946-75CA-4398-A0F7-65017E68637C}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{2D0C1946-75CA-4398-A0F7-65017E68637C}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{2D0C1946-75CA-4398-A0F7-65017E68637C}\InprocServer32] @="C:\\WINDOWS\\system32\\ooeprn.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{5086A582-7719-45C1-A020-0DF9ABBFF79A}] @="" [HKEY_CLASSES_ROOT\CLSID\{5086A582-7719-45C1-A020-0DF9ABBFF79A}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{5086A582-7719-45C1-A020-0DF9ABBFF79A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{5086A582-7719-45C1-A020-0DF9ABBFF79A}\InprocServer32] @="C:\\WINDOWS\\system32\\mcxml.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{F5E1426A-D1E1-4A4A-A7D9-2A65E1DE8E67}] @="" [HKEY_CLASSES_ROOT\CLSID\{F5E1426A-D1E1-4A4A-A7D9-2A65E1DE8E67}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{F5E1426A-D1E1-4A4A-A7D9-2A65E1DE8E67}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{F5E1426A-D1E1-4A4A-A7D9-2A65E1DE8E67}\InprocServer32] @="C:\\WINDOWS\\system32\\imetmib1.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{3EC983EE-F1EA-429D-B642-4BBE0FFAC838}] @="" [HKEY_CLASSES_ROOT\CLSID\{3EC983EE-F1EA-429D-B642-4BBE0FFAC838}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{3EC983EE-F1EA-429D-B642-4BBE0FFAC838}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{3EC983EE-F1EA-429D-B642-4BBE0FFAC838}\InprocServer32] @="C:\\WINDOWS\\system32\\cvusapi.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{D93069D1-910F-4C82-9998-20ED52BB7E22}] @="" [HKEY_CLASSES_ROOT\CLSID\{D93069D1-910F-4C82-9998-20ED52BB7E22}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{D93069D1-910F-4C82-9998-20ED52BB7E22}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{D93069D1-910F-4C82-9998-20ED52BB7E22}\InprocServer32] @="C:\\WINDOWS\\system32\\czfgnt.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{94215412-6DCC-4459-9DF2-737D09509091}] @="" [HKEY_CLASSES_ROOT\CLSID\{94215412-6DCC-4459-9DF2-737D09509091}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{94215412-6DCC-4459-9DF2-737D09509091}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{94215412-6DCC-4459-9DF2-737D09509091}\InprocServer32] @="C:\\WINDOWS\\system32\\btowser.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{C8225CDC-FB9E-4087-9C37-89DF27102DC8}] @="" [HKEY_CLASSES_ROOT\CLSID\{C8225CDC-FB9E-4087-9C37-89DF27102DC8}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{C8225CDC-FB9E-4087-9C37-89DF27102DC8}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{C8225CDC-FB9E-4087-9C37-89DF27102DC8}\InprocServer32] @="C:\\WINDOWS\\system32\\mmratelc.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{39BA1F1C-AF6D-4887-B93A-1C96EE287BA8}] @="" [HKEY_CLASSES_ROOT\CLSID\{39BA1F1C-AF6D-4887-B93A-1C96EE287BA8}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{39BA1F1C-AF6D-4887-B93A-1C96EE287BA8}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{39BA1F1C-AF6D-4887-B93A-1C96EE287BA8}\InprocServer32] @="C:\\WINDOWS\\system32\\mdnsspc.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{65C32534-30DE-4B19-BE0E-519F99A47FDD}] @="" [HKEY_CLASSES_ROOT\CLSID\{65C32534-30DE-4B19-BE0E-519F99A47FDD}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{65C32534-30DE-4B19-BE0E-519F99A47FDD}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{65C32534-30DE-4B19-BE0E-519F99A47FDD}\InprocServer32] @="C:\\WINDOWS\\system32\\cimuid.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{1D5663B0-A5BC-4E69-8D42-7FB13E5F4518}] @="" [HKEY_CLASSES_ROOT\CLSID\{1D5663B0-A5BC-4E69-8D42-7FB13E5F4518}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{1D5663B0-A5BC-4E69-8D42-7FB13E5F4518}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{1D5663B0-A5BC-4E69-8D42-7FB13E5F4518}\InprocServer32] @="C:\\WINDOWS\\system32\\aQlui.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{D3A69A1D-5714-4A00-BFC2-477C46D322A7}] @="" [HKEY_CLASSES_ROOT\CLSID\{D3A69A1D-5714-4A00-BFC2-477C46D322A7}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{D3A69A1D-5714-4A00-BFC2-477C46D322A7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{D3A69A1D-5714-4A00-BFC2-477C46D322A7}\InprocServer32] @="C:\\WINDOWS\\system32\\luexpand.dll" "ThreadingModel"="Apartment" ********************************************************************************** Files Found are not all bad files: Locate .tmp files: ********************************************************************************** Directory Listing of system files: Volume in drive C has no label. Volume Serial Number is D0D2-8781 Directory of C:\WINDOWS\System32 08/12/2005 05:27 PM 417,792 luexpand.dll 08/12/2005 05:10 PM 417,792 aNd.dll 08/12/2005 05:09 PM 417,792 tjolhelp.dll 08/12/2005 07:05 AM 417,792 fdntext.dll 08/11/2005 06:33 PM dllcache 08/11/2005 06:31 PM 417,792 aQlui.dll 08/11/2005 06:40 AM 417,792 cimuid.dll 08/09/2005 07:25 PM 417,792 mdnsspc.dll 08/09/2005 07:56 AM 417,792 mmratelc.dll 08/08/2005 05:56 PM 417,792 btowser.dll 08/08/2005 11:46 AM 417,792 czfgnt.dll 08/08/2005 11:39 AM 417,792 cvusapi.dll 08/07/2005 09:10 PM 417,792 imetmib1.dll 08/07/2005 04:26 PM 417,792 mcxml.dll 08/07/2005 10:24 AM 417,792 ooeprn.dll 08/07/2005 10:17 AM 417,792 oatext32.dll 08/07/2005 09:58 AM 417,792 TESServer.dll 08/07/2005 08:32 AM 417,792 muwmdmsp.dll 08/07/2005 08:22 AM 417,792 ahl.dll 08/07/2005 08:17 AM 417,792 ikm32.dll 08/06/2005 04:11 PM 417,792 rnoc3260.dll 08/06/2005 03:56 PM 417,792 mjwstr10.dll 08/06/2005 03:51 PM 417,792 sfbrccsp.dll 08/06/2005 03:30 PM 417,792 dkvoice.dll 08/06/2005 03:28 PM 417,792 stcurity.dll 08/06/2005 06:58 AM 417,792 onethk32.dll 08/05/2005 07:27 PM 417,792 mhiqtz32.dll 08/05/2005 07:12 PM 417,792 ig41_qc.dll 08/05/2005 06:36 PM 82,432 eetu.exe 08/05/2005 06:29 PM 417,792 ajtodisc.dll 08/01/2005 08:28 AM 417,792 fmamebuf.dll 08/01/2005 07:44 AM 417,792 sjscrap.dll 07/31/2005 09:31 AM 417,792 kvd106.dll 07/31/2005 09:19 AM 417,792 oye2nls.dll 07/30/2005 09:35 PM 417,792 dbmv2clt.dll 07/30/2005 08:47 AM 417,792 mmjet40.dll 07/28/2005 10:19 PM 417,792 iXlmdev5.dll 07/28/2005 10:09 PM 417,792 rzpwsx.dll 07/28/2005 10:05 PM 417,792 dnghelp.dll 07/28/2005 02:56 PM 417,792 hvui.dll 07/25/2005 06:41 AM 417,792 MQSTKPRP.DLL 07/25/2005 05:14 AM 417,792 jjpl400.dll 07/25/2005 05:14 AM 417,792 cbedui.dll 07/25/2005 04:07 AM 417,792 lhfil11n.DLL 07/25/2005 04:07 AM 417,792 lxrmonui.dll 07/25/2005 01:42 AM 417,792 pMqsp.dll 07/25/2005 01:41 AM 417,792 pCqsp.dll 07/24/2005 11:07 PM 417,792 mkxml3.dll 07/24/2005 11:07 PM 417,792 mcxex.dll 07/24/2005 09:47 PM 417,792 rLstapi.dll 07/24/2005 09:47 PM 417,792 rDsmontr.dll 07/24/2005 08:59 PM 417,792 nrtlogon.dll 07/24/2005 08:53 PM 417,792 ombc16gt.dll 07/24/2005 08:47 PM 417,792 rlmps.dll 07/24/2005 08:47 PM 417,792 SD2EVNT1.DLL 07/24/2005 07:54 PM 417,792 vqServices.dll 07/24/2005 07:43 PM 417,792 iHsrad.dll 07/24/2005 07:43 PM 417,792 iXsnap.dll 07/24/2005 06:31 PM 417,792 msglibnt.dll 07/24/2005 06:31 PM 417,792 mlc40u.dll 07/24/2005 05:22 PM 417,792 iLlmdev5.dll 07/24/2005 05:16 PM 417,792 kUuser.dll 07/24/2005 05:16 PM 417,792 kmd106.dll 07/24/2005 02:49 PM 417,792 kjymgr.dll 07/24/2005 02:49 PM 417,792 ibfxress.dll 07/24/2005 01:53 PM 417,792 ahstream.dll 07/24/2005 01:20 PM 417,792 bdowser.dll 07/24/2005 01:20 PM 417,792 bVtmeter.dll 07/24/2005 12:03 PM 417,792 ootext32.dll 07/24/2005 12:03 PM 417,792 owe2disp.dll 07/24/2005 10:40 AM 417,792 drmodemx.dll 07/24/2005 10:40 AM 417,792 dkcprop2.dll 07/24/2005 09:29 AM 417,792 rroc3260.dll 07/24/2005 09:29 AM 417,792 rzaenh.dll 07/24/2005 06:58 AM 417,792 iCsrecst.dll 07/24/2005 06:58 AM 417,792 ivq.dll 07/24/2005 05:06 AM 417,792 kodbr.dll 07/24/2005 05:06 AM 417,792 kgdaze.dll 07/24/2005 03:06 AM 417,792 kcdbe.dll 07/24/2005 03:05 AM 417,792 kkymgr.dll 07/24/2005 12:40 AM 417,792 oabctrac.dll 07/24/2005 12:40 AM 417,792 pSutoenr.dll 07/23/2005 10:24 PM 417,792 mxtext40.dll 07/23/2005 10:24 PM 417,792 mpvbvm60.dll 07/23/2005 09:09 PM 417,792 dbusic.dll 07/23/2005 09:09 PM 417,792 dtsynth.dll 07/23/2005 07:39 PM 417,792 ugnphost.dll 07/23/2005 07:39 PM 417,792 uzrcntra.dll 07/23/2005 05:04 PM 417,792 iketcplc.dll 07/23/2005 05:04 PM 417,792 ilfxres.dll 07/23/2005 02:50 PM 417,792 kmdbene.dll 07/23/2005 02:50 PM 417,792 kmd101b.dll 07/23/2005 01:34 PM 417,792 kvdkyr.dll 07/23/2005 01:21 PM 417,792 kgduzb.dll 07/23/2005 01:21 PM 417,792 kycom.dll 07/23/2005 12:21 PM 417,792 dtime.dll 07/23/2005 12:04 PM 417,792 meorcl32.dll 07/23/2005 12:04 PM 417,792 mwls31.dll 07/23/2005 10:59 AM 417,792 kldes.dll 07/23/2005 10:24 AM 417,792 vmscript.dll 07/23/2005 10:24 AM 417,792 vcajet32.dll 07/23/2005 07:44 AM 417,792 dedskres.dll 07/23/2005 07:44 AM 417,792 dxocx.dll 07/23/2005 06:40 AM 417,792 hyetmon.dll 07/23/2005 06:40 AM 417,792 hqactivex.dll 07/23/2005 05:19 AM 417,792 mroert2.dll 07/23/2005 05:19 AM 417,792 mrports.dll 07/23/2005 04:17 AM 417,792 wjnsock.dll 07/23/2005 04:17 AM 417,792 wbnrnr.dll 07/23/2005 03:09 AM 417,792 kgdbe.dll 07/23/2005 03:09 AM 417,792 jgcript.dll 07/23/2005 01:40 AM 417,792 mprd2x40.dll 07/23/2005 01:40 AM 417,792 mqrd2x40.dll 07/23/2005 12:26 AM 417,792 cbbcatex.dll 07/23/2005 12:26 AM 417,792 cum.dll 07/22/2005 10:57 PM 417,792 jvaw400.dll 07/22/2005 10:57 PM 417,792 joaw400.dll 07/22/2005 09:40 PM 417,792 iwmui.dll 07/22/2005 09:40 PM 417,792 iOsnap.dll 07/22/2005 08:37 PM 417,792 owbctrac.dll 07/22/2005 08:37 PM 417,792 owpdx32.dll 07/22/2005 07:16 PM 417,792 waninet.dll 07/22/2005 07:16 PM 417,792 wtashext.dll 07/22/2005 07:05 PM 417,792 dmcprop2.dll 07/22/2005 06:58 PM 417,792 dfquery.dll 07/22/2005 06:10 PM 417,792 wtnotify.dll 07/22/2005 06:10 PM 417,792 wlerror.dll 07/22/2005 05:08 PM 417,792 dinlobby.dll 07/22/2005 05:08 PM 417,792 danhupnp.dll 07/22/2005 03:43 PM 417,792 gvdef.dll 07/22/2005 03:43 PM 417,792 hOl.dll 07/22/2005 02:42 PM 417,792 merepl35.dll 07/22/2005 02:42 PM 417,792 merle32.dll 07/22/2005 02:16 PM 417,792 mmgsvc.dll 07/22/2005 01:38 PM 417,792 kauser.dll 07/22/2005 01:38 PM 417,792 ktrnel32.dll 07/22/2005 12:10 PM 417,792 aHd.dll 07/22/2005 12:10 PM 417,792 aalui.dll 07/22/2005 10:00 AM 417,792 wlwfaxui.dll 07/22/2005 10:00 AM 417,792 wehtcpip.dll 07/22/2005 08:37 AM 417,792 rCsapi32.dll 07/22/2005 08:36 AM 417,792 qvery.dll 07/22/2005 06:02 AM 417,792 skgina.dll 07/22/2005 06:02 AM 417,792 scfolder.dll 07/22/2005 04:39 AM 417,792 khdtat.dll 07/22/2005 04:39 AM 417,792 kacom.dll 07/22/2005 03:31 AM 417,792 mxl_hp.dll 07/22/2005 03:31 AM 417,792 mnndex.dll 07/22/2005 02:10 AM 417,792 mrdemui.dll 07/22/2005 02:10 AM 417,792 memxsdk.dll 07/22/2005 01:02 AM 417,792 kmdir.dll 07/22/2005 01:02 AM 417,792 kudit.dll 07/21/2005 11:40 PM 417,792 drmap.dll 07/21/2005 11:40 PM 417,792 dzrgres.dll 07/21/2005 09:08 PM 417,792 oeeprn.dll 07/21/2005 09:08 PM 417,792 oxeacc.dll 07/21/2005 07:39 PM 417,792 ih41_qcx.dll 07/21/2005 07:39 PM 417,792 iaircl.dll 07/21/2005 04:41 PM 417,792 pltorec.dll 07/21/2005 04:41 PM 417,792 qdap.dll 07/19/2005 05:05 PM 417,792 MGSTKPRP.DLL 07/15/2005 06:27 AM 417,792 kmdkyr.dll 07/15/2005 06:27 AM 417,792 kedmon.dll 07/15/2005 03:52 AM 417,792 kjdcz2.dll 07/15/2005 03:52 AM 417,792 krdbr.dll 07/15/2005 12:26 AM 417,792 dwband.dll 07/15/2005 12:26 AM 417,792 dwcpsapi.dll 07/14/2005 10:45 PM 417,792 SomStore.dll 07/14/2005 10:45 PM 417,792 soncui.dll 07/14/2005 09:07 PM 417,792 woploc.dll 07/14/2005 09:07 PM 417,792 wgvdmoe.dll 07/14/2005 03:58 PM 417,792 iodkcs32.dll 07/14/2005 03:58 PM 417,792 ieaapi.dll 07/14/2005 02:45 PM 417,792 kgdkyr.dll 07/14/2005 02:45 PM 417,792 lYprxy.dll 07/14/2005 01:30 PM 417,792 ksdkyr.dll 07/14/2005 01:30 PM 417,792 kxdhe220.dll 07/11/2005 12:22 PM 417,792 mjcomput.dll 07/11/2005 12:22 PM 417,792 mzrmsg.dll 07/09/2005 12:24 PM 417,792 ssredir.dll 07/01/2005 01:23 PM 417,792 cqyptsvc.dll 06/28/2005 07:41 AM 417,792 nftui0.dll 06/27/2005 02:47 PM 417,792 wcsdmoe2.dll 06/27/2005 11:29 AM 417,792 sqclient.dll 06/23/2005 02:35 PM 417,792 guard.tmp 06/17/2005 02:56 PM 417,792 mqricons.dll 06/17/2005 02:09 PM 417,792 mocomput.dll 06/17/2005 12:35 PM 417,792 uzbmon.dll 06/17/2005 11:55 AM 417,792 dluiext.dll 06/17/2005 11:20 AM 417,792 ktdtat.dll 06/17/2005 11:19 AM 417,792 hF23msp.dll 06/17/2005 11:08 AM 417,792 mlndex.dll 06/17/2005 11:08 AM 417,792 mwmefilt.dll 06/17/2005 10:36 AM 417,792 dmsapi.dll 06/17/2005 10:36 AM 417,792 dssapi.dll 05/13/2005 12:55 PM Microsoft 194 File(s) 80,716,288 bytes 2 Dir(s) 125,400,424,448 bytes free
Close any programs you have open since this step requires a reboot.

From the l2mfix folder on your desktop, l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing , then press any key to reboot your computer.

After the reboot, your desktop and icons will appear, then disappear (this is normal). L2mfix will continue to scan your computer and when it's finished, notepad will open with a log. Copy the contents of that log and paste it back into this thread, along with a new hijackthis log.

This will get rid of the "biggest baddie", but there are a few things left to take out using Hijack This!


IMPORTANT: Do NOT run any other files in the l2mfix folder unless you are asked to do so!
Logfile of HijackThis v1.99.1
Scan saved at 10:27:37 PM, on 8/12/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://69.28.210.175/media/1
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [exp] C:\WINDOWS\System32\exp
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\bin\matcli.exe
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} (Verizon Broadband Toolbar) - http://www2.verizon.net/micro/vol_toolbar/vzbb.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1120219649179
O16 - DPF: {D06A22B4-6087-4D3D-B7AF-82B113E9ABD4} (CPostLaunch Object) - http://www2.verizon.net/update/msnwebinsta…es/vzWebIns.CAB
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spyspotter/…rCabInstall.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
We need to disable your Microsoft AntiSpyware Real-time Protection as it may interfere with the fixes that we need to make.
  • Open Microsoft AntiSpyware.
  • Click on Options, Settings.
  • In the left pane, click on Real-time Protection.
  • Under Startup Options uncheck Enable the Microsoft AntiSpyware Security Agents on startup (recommended).
  • Under Real-time spyware threat protection uncheck Enable real-time spyware threat protection (recommended).
  • After you uncheck these, click on the Save button and close Microsoft AntiSpyware.
  • Right click on the Microsoft AntiSpyware icon on the taskbar and select Shutdown Microsoft AntiSpyware.
After all of the fixes are complete it is very important that you enable Real-time Protection again.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://69.28.210.175/media/1

O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)

O4 - HKLM\..\Run: [exp] C:\WINDOWS\System32\exp

Then click "Fix checked and close Hijack This!.

Reboot and "copy/paste" a new log file into this thread. :)
Logfile of HijackThis v1.99.1
Scan saved at 7:00:16 AM, on 8/13/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Verizon Online\bin\mpbtn.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\HJT\Hijackthis\HijackThis.exe

O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\bin\matcli.exe
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} (Verizon Broadband Toolbar) - http://www2.verizon.net/micro/vol_toolbar/vzbb.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1120219649179
O16 - DPF: {D06A22B4-6087-4D3D-B7AF-82B113E9ABD4} (CPostLaunch Object) - http://www2.verizon.net/update/msnwebinsta…es/vzWebIns.CAB
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spyspotter/…rCabInstall.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Great job!!!! :thumbup:

All the malware is gone!!!

GOD bless you, Ma'am!!!

M68 :)

Items you may wish to consider to harden your defenses against future infections:

Read "How did I get infected in the first place?"

Download/install IE-Spyad

IE-Spyad puts over 4000 known malicious web sites into IE's "restricted zone" to help prevent you from getting infected.

Check your browser settings at Qualsys.com

A series of "tests" (and suggested fixes) to help tweak IE's settings to help prevent infections when surfing the web.

Follow safe Internet practices:

1. Keep your virus definitions up to date, and scan your system regularly.

2. Don't open email, or download attachments from unrecognized email addresses.

3. Be careful when downloading email attachments, EVEN FROM PEOPLE YOU KNOW! Many virii, worms, and trojans infect a persons system then immeadiately spread themselves to the people in the infected persons addressbook via email attachments.

4. Be careful downloading files from the Internet. Scan all downloaded files with a reliable UP-TO-DATE antivirus program. Scan "zip" files BEFORE unzipping, and scan all unzipped files BEFORE USING THEM.

5. Keep your Windows and IE current with all the latest patches and updates.

Thank You! New question: I keep getting this message when trying to play a cd-rom. 16-bit MS-DOS Subsystem path to the program that you are trying to start or install C:\Windows\System32\Autoexec.nt The system file is not suitable for running MS-DOS and Microsoft Windows applications. Choose 'Close' to terminate the application. Help? Thanks!!!!
You guys have been so helpful! Thank you for everything. I wanted to post again, because I got a pop up when I went online today Does everything look OK?

Logfile of HijackThis v1.99.1
Scan saved at 7:48:03 PM, on 8/16/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Verizon Online\bin\mpbtn.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\PROGRA~1\NORTON~1\navw32.exe
C:\PROGRA~1\NORTON~1\QServer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\Hijackthis\HijackThis.exe

O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\s4psd4.exe reg_run
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\bin\matcli.exe
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} (Verizon Broadband Toolbar) - http://www2.verizon.net/micro/vol_toolbar/vzbb.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1120219649179
O16 - DPF: {D06A22B4-6087-4D3D-B7AF-82B113E9ABD4} (CPostLaunch Object) - http://www2.verizon.net/update/msnwebinsta…es/vzWebIns.CAB
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spyspotter/…rCabInstall.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI