This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Cleaning System... Down to some shell integration

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am having a hard time finishing the cleaning of a friends computer. I think it has to do with shell context menu integration.

WinPFind Text

WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.

If you see a message in the titlebar saying "Not responding…" you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.

»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Microsoft Windows XP    Current Build: Service Pack 2    Current Build Number: 2600
Internet Explorer Version: 6.0.2900.2180

»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»

Checking %SystemDrive% folder…

Checking %ProgramFilesDir% folder…

Checking %WinDir% folder…

Checking %System% folder…
UPX!                 7/9/2005 4:03:06 AM    433152     C:\WINDOWS\SYSTEM32\aswBoot.exe
Umonitor             8/15/2005 1:22:06 PM   417792     C:\WINDOWS\SYSTEM32\ausmsext.dll
WinShutDown          8/15/2005 1:22:06 PM   417792     C:\WINDOWS\SYSTEM32\ausmsext.dll
Umonitor             8/14/2005 1:14:40 AM   417792     C:\WINDOWS\SYSTEM32\cbintf.dll
WinShutDown          8/14/2005 1:14:40 AM   417792     C:\WINDOWS\SYSTEM32\cbintf.dll
69.59.186.63         8/13/2005 11:40:30 PM  30208      C:\WINDOWS\SYSTEM32\datadx.dll
209.66.67.134        8/13/2005 11:40:30 PM  30208      C:\WINDOWS\SYSTEM32\datadx.dll
66.63.167.97         8/13/2005 11:40:30 PM  30208      C:\WINDOWS\SYSTEM32\datadx.dll
66.63.167.77         8/13/2005 11:40:30 PM  30208      C:\WINDOWS\SYSTEM32\datadx.dll
web-nex              8/13/2005 11:40:30 PM  30208      C:\WINDOWS\SYSTEM32\datadx.dll
winsync              8/13/2005 11:40:30 PM  30208      C:\WINDOWS\SYSTEM32\datadx.dll
rec2_run             8/13/2005 11:40:30 PM  30208      C:\WINDOWS\SYSTEM32\datadx.dll
PEC2                 8/23/2001 7:00:00 AM   41397      C:\WINDOWS\SYSTEM32\dfrg.msc
Umonitor             8/13/2005 11:43:32 PM  417792     C:\WINDOWS\SYSTEM32\dvcdll.dll
WinShutDown          8/13/2005 11:43:32 PM  417792     C:\WINDOWS\SYSTEM32\dvcdll.dll
Umonitor             8/11/2005 8:38:24 AM   417792     C:\WINDOWS\SYSTEM32\guard.tmp
WinShutDown          8/11/2005 8:38:24 AM   417792     C:\WINDOWS\SYSTEM32\guard.tmp
Umonitor             8/14/2005 1:16:34 PM   417792     C:\WINDOWS\SYSTEM32\kpdmlt48.dll
WinShutDown          8/14/2005 1:16:34 PM   417792     C:\WINDOWS\SYSTEM32\kpdmlt48.dll
PTech                8/3/2005 10:33:42 AM   520456     C:\WINDOWS\SYSTEM32\LegitCheckControl.DLL
PECompact2           8/4/2005 8:31:38 PM    1449304    C:\WINDOWS\SYSTEM32\MRT.exe
aspack               8/4/2005 8:31:38 PM    1449304    C:\WINDOWS\SYSTEM32\MRT.exe
Umonitor             8/14/2005 12:23:04 AM  417792     C:\WINDOWS\SYSTEM32\mumtapi.dll
WinShutDown          8/14/2005 12:23:04 AM  417792     C:\WINDOWS\SYSTEM32\mumtapi.dll
aspack               8/4/2004 12:56:38 AM   708096     C:\WINDOWS\SYSTEM32\ntdll.dll
Umonitor             8/15/2005 7:00:56 PM   417792     C:\WINDOWS\SYSTEM32\peapi.dll
WinShutDown          8/15/2005 7:00:56 PM   417792     C:\WINDOWS\SYSTEM32\peapi.dll
Umonitor             8/14/2005 3:02:02 PM   417792     C:\WINDOWS\SYSTEM32\pprfnet.dll
WinShutDown          8/14/2005 3:02:02 PM   417792     C:\WINDOWS\SYSTEM32\pprfnet.dll
Umonitor             8/4/2004 12:56:46 AM   657920     C:\WINDOWS\SYSTEM32\rasdlg.dll
Umonitor             8/14/2005 12:32:02 AM  417792     C:\WINDOWS\SYSTEM32\spi_ci.dll
WinShutDown          8/14/2005 12:32:02 AM  417792     C:\WINDOWS\SYSTEM32\spi_ci.dll
Umonitor             8/14/2005 12:44:36 AM  417792     C:\WINDOWS\SYSTEM32\susvcs.dll
WinShutDown          8/14/2005 12:44:36 AM  417792     C:\WINDOWS\SYSTEM32\susvcs.dll
winsync              8/23/2001 7:00:00 AM   1309184    C:\WINDOWS\SYSTEM32\wbdbase.deu

Checking %System%\Drivers folder and sub-folders…
PTech                8/3/2004 10:41:38 PM   1309184    C:\WINDOWS\SYSTEM32\drivers\mtlstrm.sys

Items found in C:\WINDOWS\SYSTEM32\drivers\etc\hosts


Checking the Windows folder and sub-folders for system and hidden files within the last 60 days…
S                    8/15/2005 7:04:50 PM   2048       C:\WINDOWS\bootstat.dat
H                    7/1/2005 9:07:00 AM    0          C:\WINDOWS\inf\oem2.inf
S                    8/15/2005 1:22:06 PM   417792     C:\WINDOWS\system32\ausmsext.dll
S                    8/10/2005 12:58:58 PM  417792     C:\WINDOWS\system32\cagbkend.dll
S                    8/14/2005 1:14:40 AM   417792     C:\WINDOWS\system32\cbintf.dll
S                    8/13/2005 11:43:32 PM  417792     C:\WINDOWS\system32\dvcdll.dll
SH                   8/8/2005 8:22:10 AM    401408     C:\WINDOWS\system32\d?xplore.exe
S                    8/11/2005 8:38:24 AM   417792     C:\WINDOWS\system32\guard.tmp
S                    8/15/2005 7:11:18 PM   417792     C:\WINDOWS\system32\iwclass.dll
S                    8/14/2005 1:16:34 PM   417792     C:\WINDOWS\system32\kpdmlt48.dll
S                    8/14/2005 12:23:04 AM  417792     C:\WINDOWS\system32\mumtapi.dll
S                    8/15/2005 7:00:56 PM   417792     C:\WINDOWS\system32\peapi.dll
S                    8/14/2005 3:02:02 PM   417792     C:\WINDOWS\system32\pprfnet.dll
S                    8/14/2005 12:32:02 AM  417792     C:\WINDOWS\system32\spi_ci.dll
S                    8/14/2005 12:44:36 AM  417792     C:\WINDOWS\system32\susvcs.dll
H                    8/15/2005 7:01:22 PM   31767      C:\WINDOWS\system32\vsconfig.xml
H                    8/14/2005 1:08:24 AM   4212       C:\WINDOWS\system32\zllictbl.dat
S                    7/8/2005 4:23:18 PM    12143      C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB893756.cat
S                    6/30/2005 9:06:34 AM   11437      C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB896423.cat
S                    7/19/2005 7:18:10 PM   18913      C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB896727.cat
S                    6/30/2005 1:42:18 PM   11084      C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB899587.cat
S                    6/30/2005 2:21:10 PM   11084      C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB899588.cat
S                    6/30/2005 8:46:18 AM   11084      C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB899591.cat
S                    6/28/2005 7:12:56 PM   11845      C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB901214.cat
S                    7/2/2005 3:18:16 AM    9445       C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB903235.cat
H                    8/15/2005 7:11:20 PM   24576      C:\WINDOWS\system32\config\default.LOG
H                    8/15/2005 7:11:14 PM   1024       C:\WINDOWS\system32\config\SAM.LOG
H                    8/15/2005 7:04:52 PM   12288      C:\WINDOWS\system32\config\SECURITY.LOG
H                    8/15/2005 7:11:34 PM   188416     C:\WINDOWS\system32\config\software.LOG
H                    8/15/2005 7:04:58 PM   815104     C:\WINDOWS\system32\config\system.LOG
H                    8/10/2005 1:19:06 AM   1024       C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
SH                   8/13/2005 11:22:02 PM  388        C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\7fda2ba1-de5d-4651-9d12-ee7d39a426ac
SH                   8/13/2005 11:22:02 PM  24         C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\Preferred
SH                   6/24/2005 11:15:42 PM  388        C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\User\eb2fd650-bbd5-4c54-8013-96ab981bd214
SH                   6/24/2005 11:15:42 PM  24         C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\User\Preferred
SH                   8/15/2005 7:01:00 PM   192        C:\WINDOWS\Tasks\RUTASK.job
H                    8/15/2005 7:03:50 PM   6          C:\WINDOWS\Tasks\SA.DAT
SH                   8/10/2005 1:23:02 PM   113        C:\WINDOWS\Temp\History\History.IE5\desktop.ini
SH                   8/10/2005 1:23:00 PM   67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\desktop.ini

Checking for CPL files…
Microsoft Corporation          8/4/2004 12:56:58 AM   68608      C:\WINDOWS\SYSTEM32\access.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   549888     C:\WINDOWS\SYSTEM32\appwiz.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   110592     C:\WINDOWS\SYSTEM32\bthprops.cpl
                               8/12/2005 4:42:24 PM   31232      C:\WINDOWS\SYSTEM32\conres.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   135168     C:\WINDOWS\SYSTEM32\desk.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   80384      C:\WINDOWS\SYSTEM32\firewall.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   155136     C:\WINDOWS\SYSTEM32\hdwwiz.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   358400     C:\WINDOWS\SYSTEM32\inetcpl.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   129536     C:\WINDOWS\SYSTEM32\intl.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   380416     C:\WINDOWS\SYSTEM32\irprops.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   68608      C:\WINDOWS\SYSTEM32\joy.cpl
Sun Microsystems, Inc.         6/3/2005 3:52:54 AM    49265      C:\WINDOWS\SYSTEM32\jpicpl32.cpl
Microsoft Corporation          8/23/2001 7:00:00 AM   187904     C:\WINDOWS\SYSTEM32\main.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   618496     C:\WINDOWS\SYSTEM32\mmsys.cpl
Microsoft Corporation          8/23/2001 7:00:00 AM   35840      C:\WINDOWS\SYSTEM32\ncpa.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   25600      C:\WINDOWS\SYSTEM32\netsetup.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   257024     C:\WINDOWS\SYSTEM32\nusrmgr.cpl
Microsoft Corporation          8/23/2001 7:00:00 AM   36864      C:\WINDOWS\SYSTEM32\nwc.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   32768      C:\WINDOWS\SYSTEM32\odbccp32.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   114688     C:\WINDOWS\SYSTEM32\powercfg.cpl
Apple Computer, Inc.           8/26/1996 2:12:00 AM   341504     C:\WINDOWS\SYSTEM32\QTW32.CPL
Apple Computer, Inc.           9/23/2004 6:57:40 PM   323072     C:\WINDOWS\SYSTEM32\QuickTime.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   298496     C:\WINDOWS\SYSTEM32\sysdm.cpl
Microsoft Corporation          8/23/2001 7:00:00 AM   28160      C:\WINDOWS\SYSTEM32\telephon.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   94208      C:\WINDOWS\SYSTEM32\timedate.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   148480     C:\WINDOWS\SYSTEM32\wscui.cpl
Microsoft Corporation          5/26/2005 4:16:30 AM   174360     C:\WINDOWS\SYSTEM32\wuaucpl.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   68608      C:\WINDOWS\SYSTEM32\dllcache\access.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   549888     C:\WINDOWS\SYSTEM32\dllcache\appwiz.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   110592     C:\WINDOWS\SYSTEM32\dllcache\bthprops.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   135168     C:\WINDOWS\SYSTEM32\dllcache\desk.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   80384      C:\WINDOWS\SYSTEM32\dllcache\firewall.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   155136     C:\WINDOWS\SYSTEM32\dllcache\hdwwiz.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   358400     C:\WINDOWS\SYSTEM32\dllcache\inetcpl.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   129536     C:\WINDOWS\SYSTEM32\dllcache\intl.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   380416     C:\WINDOWS\SYSTEM32\dllcache\irprops.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   68608      C:\WINDOWS\SYSTEM32\dllcache\joy.cpl
Microsoft Corporation          8/23/2001 7:00:00 AM   187904     C:\WINDOWS\SYSTEM32\dllcache\main.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   618496     C:\WINDOWS\SYSTEM32\dllcache\mmsys.cpl
Microsoft Corporation          8/23/2001 7:00:00 AM   35840      C:\WINDOWS\SYSTEM32\dllcache\ncpa.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   25600      C:\WINDOWS\SYSTEM32\dllcache\netsetup.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   257024     C:\WINDOWS\SYSTEM32\dllcache\nusrmgr.cpl
Microsoft Corporation          8/23/2001 7:00:00 AM   36864      C:\WINDOWS\SYSTEM32\dllcache\nwc.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   32768      C:\WINDOWS\SYSTEM32\dllcache\odbccp32.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   114688     C:\WINDOWS\SYSTEM32\dllcache\powercfg.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   155648     C:\WINDOWS\SYSTEM32\dllcache\sapi.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   298496     C:\WINDOWS\SYSTEM32\dllcache\sysdm.cpl
Microsoft Corporation          8/23/2001 7:00:00 AM   28160      C:\WINDOWS\SYSTEM32\dllcache\telephon.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   94208      C:\WINDOWS\SYSTEM32\dllcache\timedate.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM   148480     C:\WINDOWS\SYSTEM32\dllcache\wscui.cpl
Microsoft Corporation          5/26/2005 4:16:30 AM   174360     C:\WINDOWS\SYSTEM32\dllcache\wuaucpl.cpl

»»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»

Checking files in %ALLUSERSPROFILE%\Startup folder…
                     12/25/2004 12:11:30 PM 986        C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
                     1/3/2005 9:17:18 PM    1757       C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
                     12/25/2004 11:31:48 AM 1730       C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk

Checking files in %ALLUSERSPROFILE%\Application Data folder…

Checking files in %USERPROFILE%\Startup folder…
                     5/14/2005 12:45:12 AM  676        C:\Documents and Settings\Family\Start Menu\Programs\Startup\Webshots.lnk

Checking files in %USERPROFILE%\Application Data folder…
                     1/3/2005 9:15:14 PM    871        C:\Documents and Settings\Family\Application Data\AdobeDLM.log
                     1/3/2005 9:15:14 PM    0          C:\Documents and Settings\Family\Application Data\dm.ini
                     2/10/2005 9:43:50 PM   20888      C:\Documents and Settings\Family\Application Data\GDIPFONTCACHEV1.DAT

»»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»»

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
   = 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
	{E1EFFF4C-D98A-45B7-95C3-70DC9E25893B}  = C:\WINDOWS\system32\iwclass.dll

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\avast
	{472083B0-C522-11CF-8763-00608CC02F24}  = C:\Program Files\Alwil Software\Avast4\ashShell.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\mtyffmms
	{2307e0d9-1073-4672-af0e-3e99c9d417cd}  = C:\WINDOWS\system32\eoajj.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
	{750fdf0e-2a26-11d1-a3ea-080036587f03}  = %SystemRoot%\System32\cscui.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
	{09799AFB-AD67-11d1-ABCD-00C04FC30936}  = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
	{A470F8CF-A1E8-4f65-8335-227475AA5C46}  = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
	Start Menu Pin  = %SystemRoot%\system32\SHELL32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\avast
	{472083B0-C522-11CF-8763-00608CC02F24}  = C:\Program Files\Alwil Software\Avast4\ashShell.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\EncryptionMenu
	{A470F8CF-A1E8-4f65-8335-227475AA5C46}  = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Offline Files
	{750fdf0e-2a26-11d1-a3ea-080036587f03}  = %SystemRoot%\System32\cscui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Sharing
	{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}  = ntshrui.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
  = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
  = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
  = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE}
  = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{F9DB5320-233E-11D1-9F84-707F02C10627}
  = C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll

[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
	AcroIEHlprObj Class = C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{49935711-CAF7-B302-D8FA-CC6945A2859B}
  = 
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}
  = C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB}
  = 
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}
	Google Toolbar Helper = c:\program files\google\googletoolbar1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
	&Tip of the Day = %SystemRoot%\System32\shdocvw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
	{2318C2B1-4965-11d4-9B18-009027A5CD4F}  = &Google	: c:\program files\google\googletoolbar1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
	MenuText  = Sun Java Console	: C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45}
	ButtonText  = AIM	: C:\Program Files\AIM\aim.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}
	ButtonText  = Messenger	: C:\Program Files\Messenger\msmsgs.exe

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478}
  = 
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}
	File Search Explorer Band = %SystemRoot%\system32\SHELL32.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E61-B078-11D0-89E4-00C04FC9E26E}
	Favorites Band = %SystemRoot%\System32\shdocvw.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E62-B078-11D0-89E4-00C04FC9E26E}
	History Band = %SystemRoot%\System32\shdocvw.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E64-B078-11D0-89E4-00C04FC9E26E}
	Explorer Band = %SystemRoot%\System32\shdocvw.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
	{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address	: %SystemRoot%\System32\browseui.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
	{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address	: %SystemRoot%\System32\browseui.dll
	{40D41A8B-D79B-43D7-99A7-9EE0F344C385} = AIM Search	: C:\Program Files\AIM Toolbar\AIMBar.dll
	{2318C2B1-4965-11D4-9B18-009027A5CD4F} = &Google	: c:\program files\google\googletoolbar1.dll
	{0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links	: %SystemRoot%\system32\SHELL32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
	Zone Labs Client	C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum
	{BDEADF00-C265-11D0-BCED-00A0C90AB50F} = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
	{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} = 
	{0DF44EAA-FF21-4412-828E-260A8728E7F1} = 


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
	dontdisplaylastusername	0
	legalnoticecaption	
	legalnoticetext	
	shutdownwithoutlogon	1
	undockwithoutlogon	1


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
	NoDriveTypeAutoRun	145


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
	PostBootReminder                {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll
	CDBurn                          {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll
	WebCheck                        {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\System32\webcheck.dll
	SysTray                        	{35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\System32\stobject.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
	UserInit	= C:\WINDOWS\system32\userinit.exe,
	Shell  = Explorer.exe
	System  = 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
  = crypt32.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
  = cryptnet.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
  = cscdll.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
  = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
  = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
  = sclgntfy.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
  = WlNotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
  = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Uninstall
  = C:\WINDOWS\system32\cagbkend.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
  = wlnotify.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
	Debugger = ntsd -d

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
	AppInit_DLLs	


»»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
WinPFind v1.3.0	- Log file written to "WinPFind.Txt" in the WinPFind folder.
Scan completed on 8/15/2005 7:18:28 PM


Trackqoo Report.txt

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Zone Labs Client"="C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe"
"winsync"="C:\\WINDOWS\\system32\\s4plls.exe reg_run"

—————–
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers


Subkey — avast
{472083B0-C522-11CF-8763-00608CC02F24}
C:\Program Files\Alwil Software\Avast4\ashShell.dll

Subkey — mtyffmms
{2307e0d9-1073-4672-af0e-3e99c9d417cd}
C:\WINDOWS\system32\eoajj.dll

Subkey — Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03}
C:\WINDOWS\System32\cscui.dll

Subkey — Open With
{09799AFB-AD67-11d1-ABCD-00C04FC30936}
C:\WINDOWS\system32\SHELL32.dll

Subkey — Open With EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46}
C:\WINDOWS\system32\SHELL32.dll

Subkey — {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
Start Menu Pin
C:\WINDOWS\system32\SHELL32.dll

=====================

HKEY_CLASSES_ROOT\Folder\shellex\ColumnHandlers


Subkey — {0D2E74C4-3C34-11d2-A27E-00C04FC30871}
C:\WINDOWS\system32\SHELL32.dll

Subkey — {24F14F01-7B1C-11d1-838f-0000F80461CF}
C:\WINDOWS\system32\SHELL32.dll

Subkey — {24F14F02-7B1C-11d1-838f-0000F80461CF}
C:\WINDOWS\system32\SHELL32.dll

Subkey — {66742402-F9B9-11D1-A202-0000F81FEDEE}
C:\WINDOWS\system32\SHELL32.dll

Subkey — {F9DB5320-233E-11D1-9F84-707F02C10627}
C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll

==============================
C:\Documents and Settings\All Users\Start Menu\Programs\Startup

Adobe Gamma Loader.lnk
Adobe Reader Speed Launch.lnk
desktop.ini
Microsoft Office.lnk
==============================
C:\Documents and Settings\Family\Start Menu\Programs\Startup

Adobe Gamma Loader.lnk
Adobe Reader Speed Launch.lnk
desktop.ini
Microsoft Office.lnk
desktop.ini
Webshots.lnk
==============================
C:\WINDOWS\system32 cpl files


access.cpl                    Microsoft Corporation
appwiz.cpl                    Microsoft Corporation
bthprops.cpl                  Microsoft Corporation
conres.cpl                    
desk.cpl                      Microsoft Corporation
firewall.cpl                  Microsoft Corporation
hdwwiz.cpl                    Microsoft Corporation
inetcpl.cpl                   Microsoft Corporation
intl.cpl                      Microsoft Corporation
irprops.cpl                   Microsoft Corporation
joy.cpl                       Microsoft Corporation
jpicpl32.cpl                  Sun Microsystems, Inc.
main.cpl                      Microsoft Corporation
mmsys.cpl                     Microsoft Corporation
ncpa.cpl                      Microsoft Corporation
netsetup.cpl                  Microsoft Corporation
nusrmgr.cpl                   Microsoft Corporation
nwc.cpl                       Microsoft Corporation
odbccp32.cpl                  Microsoft Corporation
powercfg.cpl                  Microsoft Corporation
QTW32.CPL                     Apple Computer, Inc.
QuickTime.cpl                 Apple Computer, Inc.
sysdm.cpl                     Microsoft Corporation
telephon.cpl                  Microsoft Corporation
timedate.cpl                  Microsoft Corporation
wscui.cpl                     Microsoft Corporation
wuaucpl.cpl                   Microsoft Corporation

Another place suggested (in a different thread, different person) created a "delete.reg" file and using it to delete the keys that should not be in the shellex registry location.

But I want to make sure I get all the extra gobbly gook removed from the system.

I think my delete reg should at least contain this…

REGEDIT4
[-HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\mtyffmms]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"winsync"=-

I am sure this has something to do with QOO

I dont know if the "winsync"=- is correct any possible additional help would be greatly appreciated. It looks like these programs have disabled my microsoft anti-spyware beta and also my avast at this time.
Hello and welcome to the forums!

Please download HijackThis from here.

Save it in a convenient permanent folder such as C:\HJT\, double click HijackThis.exe, and hit "Scan".

When the scan is finished, the "Scan" button will change into a "Save Log" button.
Save the log, and copy its contents here. Most of what it lists will be harmless or essential, don't fix anything yet.
Little late on the draw. We finally got it clean (after 6 hours of work) but we ended up having to reinstall it do to some registry issues with installing the cdrw drive. eh… thats life…. LOL :D
Sorry we couldn't help. Since this issue appears resolved … this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team
an email with the address of the thread. This applies only to the original topic starter. Any emails without the subject "Reopen" will be deleted without being looked at.

Everyone else please begin a New Topic.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI