Lots O' Pop Ups
-
Lots O' Pop Ups
Have a user complaining of pop ups. Here's the log:
Logfile of HijackThis v1.99.1
Scan saved at 2:03:02 PM, on 6/30/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\carpserv.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\system32\cisvc.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\WINDOWS\wanmpsvc.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\HiJackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.comcast.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitexut32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Ncao] C:\Documents and Settings\David\Application Data\osoa.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O16 - DPF: {A97608DD-6999-11D5-9C8C-0010A4F2D6BF} (QCOMCont Class) - http://www.quicken.com/qw2001/qcominst.cab
O20 - Winlogon Notify: Hints - C:\WINDOWS\system32\enp2l17o1.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
-
Hi,JenniferH
Download L2mfix from one of these two locations:
http://www.atribune.org/downloads/l2mfix.exe
http://www.downloads.subratam.org/l2mfix.exe
Save the file to your Desktop but do not run it yet
Please download miekiemoes' LQfix batch here:
http://www.downloads.subratam.org/LQfix.zip
Unzip it to the desktop but do NOT run it yet.
Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.
For additional help in booting into Safe Mode, see the following site:
http://www.pchell.com/support/safemode.shtml
Once in Safe Mode, please run LQfix.bat. When finished, restart your computer in normal mode and please do this here.
double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.
IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!
then show me a HijackThis logfile & the logfile of l2mfix
HGD
Last edited by HJThis; 30-06-2005 at 07:37 PM.
-
The l2mfix log was too long to fit into one post, so I'm breaking it into sections:
Section 1:
L2MFIX find log 1.03
These are the registry keys present
************************************************** ********************************
Winlogon/notify:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Nls]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\irlol5331.dl l"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
************************************************** ********************************
useragent:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Internet Settings\User Agent\Post Platform]
"{51323D5C-A2DC-A3CE-4E0E-4737B31BDB97}"=""
************************************************** ********************************
Shell Extension key:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run..."
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People..."
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache"
"{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Web Folders"
"{0006F045-0000-0000-C000-000000000046}"="Microsoft Outlook Custom Icon Handler"
"{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
"{5E44E225-A408-11CF-B581-008029601108}"="Adaptec DirectCD Shell Extension"
"{F21C9935-8103-413a-8CDA-B95B539ADDC3}"="Broadband FREE Trial"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{0E313386-758B-4B23-B8C8-CED0FB3D8160}"=""
"{898683AA-F365-49B2-BB40-E9F8D5A5077E}"=""
"{FB3B75A8-A2FD-42E8-8AE3-17696F2F076A}"=""
"{2740C4D0-AE78-4918-B5CB-2BE0660168C4}"=""
"{7186172B-A1F1-40CD-9EA2-CF68279EBC8B}"=""
-
Section 2:
HKEY ROOT CLASSIDS:
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{0E313386-758B-4B23-B8C8-CED0FB3D8160}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{0E313386-758B-4B23-B8C8-CED0FB3D8160}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{0E313386-758B-4B23-B8C8-CED0FB3D8160}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{0E313386-758B-4B23-B8C8-CED0FB3D8160}\InprocServer32]
@="C:\\WINDOWS\\system32\\KMDSL.DLL"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{898683AA-F365-49B2-BB40-E9F8D5A5077E}]
@=""
"IDEx"="AD"
[HKEY_CLASSES_ROOT\CLSID\{898683AA-F365-49B2-BB40-E9F8D5A5077E}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{898683AA-F365-49B2-BB40-E9F8D5A5077E}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{898683AA-F365-49B2-BB40-E9F8D5A5077E}\InprocServer32]
@="C:\\WINDOWS\\system32\\mfrepl35.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{FB3B75A8-A2FD-42E8-8AE3-17696F2F076A}]
@=""
"IDEx"="AD"
[HKEY_CLASSES_ROOT\CLSID\{FB3B75A8-A2FD-42E8-8AE3-17696F2F076A}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{FB3B75A8-A2FD-42E8-8AE3-17696F2F076A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{FB3B75A8-A2FD-42E8-8AE3-17696F2F076A}\InprocServer32]
@="C:\\WINDOWS\\system32\\PGH.DLL"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{2740C4D0-AE78-4918-B5CB-2BE0660168C4}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{2740C4D0-AE78-4918-B5CB-2BE0660168C4}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{2740C4D0-AE78-4918-B5CB-2BE0660168C4}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{2740C4D0-AE78-4918-B5CB-2BE0660168C4}\InprocServer32]
@="C:\\WINDOWS\\system32\\SUNCENG.DLL"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{7186172B-A1F1-40CD-9EA2-CF68279EBC8B}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{7186172B-A1F1-40CD-9EA2-CF68279EBC8B}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{7186172B-A1F1-40CD-9EA2-CF68279EBC8B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{7186172B-A1F1-40CD-9EA2-CF68279EBC8B}\InprocServer32]
@="C:\\WINDOWS\\system32\\DFMRTP.DLL"
"ThreadingModel"="Apartment"
************************************************** ********************************
Files Found are not all bad files:
C:\WINDOWS\SYSTEM32\
afl.dll Sat May 14 2005 10:10:52a ..S.R 234,847 229.34 K
aosnds.dll Tue Apr 26 2005 8:52:24a ..S.R 234,047 228.56 K
apvapi32.dll Tue May 17 2005 2:06:22p ..S.R 235,107 229.59 K
awfsipc.dll Mon May 16 2005 10:29:04a ..S.R 235,276 229.76 K
bstsprx2.dll Thu May 19 2005 11:50:26a ..S.R 233,211 227.74 K
cautil.dll Tue May 24 2005 9:55:38a ..S.R 233,211 227.74 K
cdm.dll Thu May 26 2005 4:16:24a A.... 75,544 73.77 K
cemodem.dll Thu Apr 28 2005 10:41:26a ..S.R 235,207 229.69 K
clmctl32.dll Thu Apr 7 2005 6:10:36p ..S.R 234,238 228.75 K
cumvs4o.dll Tue May 3 2005 9:51:00a ..S.R 233,805 228.32 K
cxodm.dll Wed Jun 1 2005 8:29:10a ..S.R 233,211 227.74 K
czyptui.dll Mon Jun 27 2005 12:33:22p ..S.R 234,272 228.78 K
dcnet.dll Fri May 6 2005 6:19:50p ..S.R 235,164 229.65 K
ddtaclen.dll Sat May 7 2005 5:04:20p ..S.R 235,164 229.65 K
dfmrtp.dll Fri Jul 1 2005 3:10:26p ..S.R 235,317 229.80 K
divvox.dll Fri Apr 29 2005 9:22:16a ..S.R 235,207 229.69 K
dncpsapi.dll Thu Jun 2 2005 4:02:52p ..S.R 234,577 229.08 K
dnsec.dll Wed Apr 20 2005 10:29:42a ..S.R 235,450 229.93 K
drutil.dll Wed May 4 2005 4:16:54p ..S.R 233,805 228.32 K
dsdskres.dll Tue Apr 26 2005 1:59:06p ..S.R 234,047 228.56 K
dtusic.dll Mon Apr 18 2005 3:20:18p ..S.R 234,139 228.65 K
dullsys.dll Thu May 12 2005 4:44:58p ..S.R 234,272 228.78 K
dusrslvr.dll Mon Apr 11 2005 12:05:40p ..S.R 232,907 227.45 K
dvghelp.dll Fri May 20 2005 11:48:16a ..S.R 233,211 227.74 K
dwscript.dll Wed Apr 13 2005 3:20:54p ..S.R 233,169 227.70 K
dzwsockx.dll Thu May 12 2005 4
04p ..S.R 234,272 228.78 K
enp6l1~1.dll Thu Apr 14 2005 1:38:28p ..S.R 233,169 227.70 K
enpol1~1.dll Thu Apr 7 2005 4:04:56p ..S.R 233,787 228.30 K
fbifs.dll Fri Jun 24 2005 3:00:54p ..S.R 235,221 229.71 K
ff20enu.dll Wed Jun 29 2005 8:54:46a ..S.R 235,317 229.80 K
fmultrep.dll Tue Apr 12 2005 6:52:58p ..S.R 236,135 230.60 K
ft20.dll Mon May 2 2005 3:54:54p ..S.R 234,049 228.56 K
gzdef.dll Wed Jun 15 2005 10:32:48a ..S.R 235,507 229.98 K
h0l2la~1.dll Wed Jun 1 2005 4:44:20p ..S.R 236,528 230.98 K
hasetup.dll Sun Apr 3 2005 3:44:36p ..S.R 235,076 229.57 K
hgetcfg.dll Mon Apr 18 2005 1:54:02p ..S.R 234,139 228.65 K
hjcutils.dll Wed Jun 15 2005 3:52:02p ..S.R 235,507 229.98 K
hkui.dll Wed Apr 13 2005 11:29:34a ..S.R 233,169 227.70 K
hr2s05~1.dll Thu May 5 2005 1:16:10p ..S.R 234,049 228.56 K
hr4805~1.dll Thu May 12 2005 11:13:20a ..S.R 235,563 230.04 K
hr4s05~1.dll Wed Jun 15 2005 4:35:02p ..S.R 235,507 229.98 K
hr6805~1.dll Thu Jun 16 2005 4:17:20p ..S.R 235,831 230.30 K
hrls05~1.dll Tue May 10 2005 3:42:58p ..S.R 235,164 229.65 K
hrn605~1.dll Thu May 12 2005 4:41:56p ..S.R 236,218 230.68 K
i6jqlg~1.dll Fri Jun 24 2005 4:04:58p ..S.R 235,221 229.71 K
id50_qcx.dll Tue May 17 2005 2:16:18p ..S.R 233,596 228.12 K
igircl.dll Thu May 19 2005 9:35:30a ..S.R 236,612 231.07 K
ihspolcy.dll Wed Jun 8 2005 10:32:30a ..S.R 234,577 229.08 K
ijssdo.dll Wed Jun 1 2005 8:53:32a ..S.R 234,577 229.08 K
iketres.dll Tue May 10 2005 4:23:18p ..S.R 235,563 230.04 K
imfxdo.dll Thu Apr 7 2005 4:07:30p ..S.R 232,416 226.97 K
irlol5~1.dll Fri Jul 1 2005 3:06:38p ..S.R 235,317 229.80 K
itsetup.dll Sat May 21 2005 10:22:34a ..S.R 233,211 227.74 K
iuengine.dll Thu May 26 2005 4:16:24a A.... 198,424 193.77 K
ivetres.dll Wed May 18 2005 1:04:08p ..S.R 233,662 228.18 K
iwsetup.dll Mon May 23 2005 12:02:22p ..S.R 234,577 229.08 K
ixfxsrvc.dll Tue May 31 2005 8:19:16a ..S.R 234,577 229.08 K
ixlmgicd.dll Tue May 3 2005 4:53:08p ..S.R 233,805 228.32 K
iyfxsrvc.dll Wed Apr 27 2005 4:40:12p ..S.R 234,047 228.56 K
jlaw400.dll Tue Jun 21 2005 12:16:36p ..S.R 234,784 229.28 K
k4800e~1.dll Fri Jun 3 2005 10:02:42a ..S.R 235,156 229.64 K
kadhe.dll Tue Jun 7 2005 2:18:08p ..S.R 235,322 229.80 K
kgdhe.dll Wed Apr 20 2005 2:09:04p ..S.R 235,739 230.21 K
kidgkl.dll Wed May 4 2005 12:17:16p ..S.R 234,049 228.56 K
kidno.dll Tue Jun 7 2005 10:37:04a ..S.R 234,577 229.08 K
kkdsl.dll Mon May 30 2005 2:58:10p ..S.R 234,577 229.08 K
kndsl.dll Tue May 17 2005 9:57:22a ..S.R 233,596 228.12 K
kndtat.dll Wed Jun 22 2005 8:54:58a ..S.R 233,459 227.98 K
kodtat.dll Sun May 1 2005 11:12:12a ..S.R 233,805 228.32 K
ktnul7~1.dll Sun Jun 26 2005 11:59:24a ..S.R 236,171 230.63 K
kwdpl1.dll Fri Apr 15 2005 6:46:52p ..S.R 234,139 228.65 K
kydfr.dll Sun May 8 2005 11:18:28a ..S.R 235,578 230.05 K
kzdgr1.dll Thu Apr 28 2005 10:36:18a ..S.R 233,200 227.73 K
leexpand.dll Mon Apr 25 2005 2:37:24p ..S.R 234,047 228.56 K
ltexpand.dll Mon Apr 25 2005 3:42:44p ..S.R 234,047 228.56 K
lvj209~1.dll Wed Apr 20 2005 3:47:04p ..S.R 235,739 230.21 K
lvlo09~1.dll Fri Jul 1 2005 3:10:26p ..S.R 235,656 230.13 K
lvn009~1.dll Wed Apr 13 2005 1:18:56p ..S.R 233,169 227.70 K
lvprxy.dll Sun Apr 24 2005 12:55:44p ..S.R 232,902 227.44 K
mclbui.dll Wed Jun 1 2005 2:06:32p ..S.R 233,211 227.74 K
mdxml3r.dll Wed Jun 29 2005 9:28:54a ..S.R 234,272 228.78 K
mecertui.dll Mon May 16 2005 10:32:36a ..S.R 234,847 229.34 K
mgminst.dll Wed Apr 6 2005 9:07:32a ..S.R 235,365 229.85 K
mgvcrt40.dll Thu Apr 14 2005 9:28:26a ..S.R 233,169 227.70 K
miswch.dll Tue May 10 2005 10:20:56a ..S.R 235,578 230.05 K
mjjet40.dll Tue Apr 19 2005 2:02:56p ..S.R 235,739 230.21 K
mnxbse35.dll Thu Jun 30 2005 3
46p ..S.R 235,317 229.80 K
moaatext.dll Fri Apr 15 2005 9:05:04a ..S.R 234,139 228.65 K
mpvidc32.dll Thu May 12 2005 9:44:18a ..S.R 235,563 230.04 K
mqpi.dll Tue Jun 21 2005 6:07:48p ..S.R 234,784 229.28 K
msi.dll Wed May 4 2005 2:45:32p A.... 2,890,240 2.75 M
msihnd.dll Wed May 4 2005 2:45:36p A.... 271,360 265.00 K
msimsg.dll Wed May 4 2005 2:45:36p A.... 884,736 864.00 K
msisip.dll Wed May 4 2005 2:45:36p A.... 15,360 15.00 K
mtidntld.dll Wed Apr 27 2005 12
04p ..S.R 235,207 229.69 K
mtrating.dll Mon Jun 27 2005 11:26:56a ..S.R 235,221 229.71 K
mvacm32.dll Fri May 13 2005 3:53:50p ..S.R 234,272 228.78 K
mvgina.dll Thu May 19 2005 11:54:44a ..S.R 236,612 231.07 K
mvvbvm60.dll Fri Jun 24 2005 6:03:06a ..S.R 235,221 229.71 K
mvwdat10.dll Mon Apr 11 2005 11:47:14a ..S.R 236,135 230.60 K
mygina.dll Tue May 3 2005 2:59:20p ..S.R 234,049 228.56 K
mzr2c.dll Sun May 15 2005 10:35:16a ..S.R 234,847 229.34 K
ndtevent.dll Tue Jun 21 2005 8:29:44a ..S.R 235,507 229.98 K
nftrap.dll Thu Jun 30 2005 12:50:22p ..... 234,272 228.78 K
nrtui0.dll Thu May 19 2005 9:30:04a ..S.R 235,181 229.67 K
nxdsbcli.dll Thu Apr 28 2005 3:15:36p ..S.R 233,200 227.73 K
nyapi16.dll Thu May 26 2005 10:39:24a ..S.R 234,577 229.08 K
oiengl32.dll Fri May 13 2005 8:40:32a ..S.R 234,847 229.34 K
orepro32.dll Fri May 20 2005 3:55:20p ..S.R 234,577 229.08 K
oylomo.dll Wed Apr 6 2005 8:29:48a A.... 163,840 160.00 K
p6n8lg~1.dll Wed Apr 13 2005 1:06:48p ..S.R 236,135 230.60 K
petorsvc.dll Sun Jun 12 2005 5:06:56p ..S.R 235,507 229.98 K
pvrfos.dll Tue Apr 26 2005 1:55:22p ..S.R 235,207 229.69 K
pxrfctrs.dll Wed May 18 2005 3:39:16p ..S.R 235,107 229.59 K
rbsppp.dll Fri Jun 24 2005 12:09:42p ..S.R 233,459 227.98 K
rdgsvc.dll Thu May 12 2005 4:41:56p ..S.R 235,563 230.04 K
rhbdyctl.dll Mon May 9 2005 4:20:28p ..S.R 235,164 229.65 K
rosppp.dll Wed May 18 2005 9:42:30a ..S.R 235,107 229.59 K
rrmotepg.dll Fri Apr 15 2005 6:20:34p ..S.R 234,139 228.65 K
rssman.dll Tue Jun 21 2005 3:38:00p ..S.R 234,784 229.28 K
rvm.dll Mon Apr 18 2005 1:57:48p ..S.R 234,139 228.65 K
rwboex32.dll Fri Jun 10 2005 8:05:46a ..S.R 234,577 229.08 K
sbntpfcs.dll Fri Apr 15 2005 8:31:24a ..S.R 234,139 228.65 K
sic_os.dll Tue Apr 12 2005 4:31:12p ..S.R 232,907 227.45 K
sincui.dll Tue Jun 21 2005 5:32:06p ..S.R 236,470 230.93 K
sinike.dll Tue Apr 19 2005 10:12:36a ..S.R 235,450 229.93 K
sksinv.dll Wed Jun 15 2005 12:23:14p ..S.R 235,831 230.30 K
slfrslv.dll Thu Apr 7 2005 10:50:56a ..S.R 236,255 230.71 K
spi.dll Mon Jun 27 2005 2:39:42p ..S.R 234,272 228.78 K
spmsg.dll Wed May 4 2005 2:45:26p ..... 13,536 13.22 K
stntpfcs.dll Tue Jun 21 2005 3:30:30p ..S.R 235,464 229.95 K
sunceng.dll Thu Jun 30 2005 12:52:06p ..S.R 235,317 229.80 K
suobject.dll Tue Jun 28 2005 8:48:54a ..S.R 234,272 228.78 K
sycsccp.dll Wed May 11 2005 10:58:28a ..S.R 233,184 227.72 K
thpmib.dll Fri Jul 1 2005 3:07:40p ..S.R 236,573 231.03 K
tmrmsrv.dll Tue Apr 19 2005 9:58:10a ..S.R 234,139 228.65 K
topiui.dll Thu Apr 28 2005 9:20:28a ..S.R 235,207 229.69 K
tpd32.dll Fri Jun 3 2005 3:57:14p ..S.R 234,577 229.08 K
ts8ulc~1.dll Mon Apr 25 2005 4:07:44p ..S.R 235,207 229.69 K
ttd32.dll Sat May 14 2005 3:44:14p ..S.R 234,272 228.78 K
uber32.dll Mon Apr 25 2005 3:31:30p ..S.R 235,458 229.94 K
uzat.dll Mon Jun 6 2005 10:36:40a ..S.R 235,322 229.80 K
vihelper.dll Wed Apr 13 2005 1:24:10p ..S.R 233,169 227.70 K
vxsapi.dll Sat Apr 30 2005 3:59:58p ..S.R 233,200 227.73 K
wbbvw.dll Tue Jun 21 2005 2:29:42p ..S.R 234,784 229.28 K
wj2_32.dll Tue Jun 14 2005 8:39:30a ..S.R 235,507 229.98 K
wjnscard.dll Wed Apr 27 2005 12:37:06p ..S.R 234,047 228.56 K
wnhisn.dll Tue Apr 5 2005 10:24:58a ..S.R 235,076 229.57 K
wnnotify.dll Mon Apr 11 2005 8:18:40p ..S.R 236,135 230.60 K
wnntrust.dll Thu Apr 7 2005 4:04:56p ..S.R 232,416 226.97 K
wtascr.dll Fri Apr 15 2005 6:50:44p ..S.R 234,139 228.65 K
wuapi.dll Thu May 26 2005 4:16:30a A.... 465,176 454.27 K
wuaueng.dll Thu May 26 2005 4:16:30a A.... 1,343,768 1.28 M
wuaueng1.dll Thu May 26 2005 4:16:30a A.... 194,328 189.77 K
wucltui.dll Thu May 26 2005 4:16:30a A.... 127,256 124.27 K
wunrnr.dll Thu Jun 2 2005 2:22:42p ..S.R 235,156 229.64 K
wups.dll Thu May 26 2005 4:16:30a A.... 41,240 40.27 K
wups2.dll Thu May 26 2005 4:16:30a A.... 18,200 17.77 K
wuweb.dll Thu May 26 2005 4:16:30a A.... 173,536 169.47 K
wwcsvc.dll Fri May 27 2005 10:00:40a ..S.R 233,211 227.74 K
wyascr.dll Mon May 16 2005 1:00:34p ..S.R 235,276 229.76 K
161 items found: 161 files (145 H/S), 0 directories.
Total of file sizes: 41,136,112 bytes 39.23 M
Locate .tmp files:
-
Section 3:
Directory Listing of system files:
Volume in drive C has no label.
Volume Serial Number is A0FF-2CD3
Directory of C:\WINDOWS\System32
07/01/2005 03:10 PM 235,317 DFMRTP.DLL
07/01/2005 03:10 PM 235,656 lvlo0933e.dll
07/01/2005 03:07 PM 236,573 THPMIB.DLL
07/01/2005 03:06 PM 235,317 irlol5331.dll
06/30/2005 03:21 PM 235,317 mnxbse35.dll
06/30/2005 01:40 PM 512 NuaK63G.i9q
06/30/2005 12:52 PM 235,317 SUNCENG.DLL
06/30/2005 12:50 PM 253,962 Ffha.exe
06/30/2005 12:50 PM 253,962 MmriZTL2.exe
06/30/2005 12:50 PM 253,962 Use13R.exe
06/30/2005 12:50 PM 253,962 Fym442mI.exe
06/30/2005 12:50 PM 253,962 Tpws.exe
06/29/2005 04:44 PM <DIR> DLLCACHE
06/29/2005 09:28 AM 234,272 MDXML3R.DLL
06/29/2005 08:54 AM 235,317 FF20ENU.DLL
06/28/2005 08:48 AM 234,272 SUOBJECT.DLL
06/27/2005 02:39 PM 234,272 SPI.DLL
06/27/2005 12:33 PM 234,272 czyptui.dll
06/27/2005 11:26 AM 235,221 MTRATING.DLL
06/26/2005 11:59 AM 236,171 ktnul7591.dll
06/24/2005 04:04 PM 235,221 i6jqlg1516.dll
06/24/2005 03:00 PM 235,221 FBIFS.DLL
06/24/2005 12:09 PM 233,459 RBSPPP.DLL
06/24/2005 06:03 AM 235,221 MVVBVM60.DLL
06/22/2005 08:54 AM 233,459 KNDTAT.DLL
06/21/2005 06:07 PM 234,784 MQPI.DLL
06/21/2005 05:32 PM 236,470 SINCUI.DLL
06/21/2005 03:37 PM 234,784 RSSMAN.DLL
06/21/2005 03:30 PM 235,464 StnTPFcs.dll
06/21/2005 02:29 PM 234,784 WBBVW.DLL
06/21/2005 12:31 PM 512 Qvm9Y4.42n
06/21/2005 12:16 PM 234,784 JLAW400.DLL
06/21/2005 08:29 AM 235,507 NDTEVENT.DLL
06/16/2005 04:17 PM 235,831 hr6805jue.dll
06/15/2005 04:35 PM 235,507 hr4s05h7e.dll
06/15/2005 03:52 PM 235,507 hjcutils.dll
06/15/2005 12:23 PM 235,831 SKSINV.DLL
06/15/2005 10:32 AM 235,507 GZDEF.DLL
06/14/2005 08:39 AM 235,507 WJ2_32.DLL
06/12/2005 05:06 PM 235,507 PETORSVC.DLL
06/10/2005 08:05 AM 234,577 Rwboex32.dll
06/08/2005 10:32 AM 234,577 IHSPOLCY.DLL
06/07/2005 02:18 PM 235,322 KADHE.DLL
06/07/2005 10:37 AM 234,577 KIDNO.DLL
06/06/2005 10:36 AM 235,322 UZAT.DLL
06/03/2005 03:57 PM 234,577 TPD32.DLL
06/03/2005 10:02 AM 235,156 k4800elmehqa0.dll
06/02/2005 04:02 PM 234,577 DNCPSAPI.DLL
06/02/2005 02:22 PM 235,156 WUNRNR.DLL
06/01/2005 04:44 PM 236,528 h0l2la3o1d.dll
06/01/2005 02:06 PM 233,211 MCLBUI.DLL
06/01/2005 08:53 AM 234,577 IJSSDO.DLL
06/01/2005 08:29 AM 233,211 CXODM.DLL
05/31/2005 11:21 AM 512 Anh4W.7u0
05/31/2005 08:19 AM 234,577 ixfxsrvc.dll
05/30/2005 02:58 PM 234,577 KKDSL.DLL
05/27/2005 10:00 AM 233,211 WWCSVC.DLL
05/26/2005 10:39 AM 234,577 NYAPI16.DLL
05/24/2005 09:55 AM 233,211 cautil.dll
05/23/2005 12:02 PM 234,577 IWSETUP.DLL
05/21/2005 10:22 AM 233,211 ITSETUP.DLL
05/20/2005 03:55 PM 234,577 OREPRO32.DLL
05/20/2005 11:48 AM 233,211 DVGHELP.DLL
05/19/2005 11:54 AM 236,612 mvgina.dll
05/19/2005 11:50 AM 233,211 bstsprx2.dll
05/19/2005 09:35 AM 236,612 igircl.dll
05/19/2005 09:30 AM 235,181 NRTUI0.DLL
05/18/2005 03:39 PM 235,107 PXRFCTRS.DLL
05/18/2005 01:04 PM 233,662 IVETRES.DLL
05/18/2005 09:42 AM 235,107 ROSPPP.DLL
05/17/2005 02:16 PM 233,596 id50_qcx.dll
05/17/2005 02:06 PM 235,107 APVAPI32.DLL
05/17/2005 09:57 AM 233,596 KNDSL.DLL
05/16/2005 01:00 PM 235,276 WYASCR.DLL
05/16/2005 10:32 AM 234,847 MECERTUI.DLL
05/16/2005 10:29 AM 235,276 AWFSIPC.DLL
05/15/2005 10:35 AM 234,847 MZR2C.DLL
05/14/2005 03:44 PM 234,272 TTD32.DLL
05/14/2005 10:10 AM 234,847 AFL.DLL
05/13/2005 03:53 PM 234,272 MVACM32.DLL
05/13/2005 08:40 AM 234,847 OIENGL32.DLL
05/12/2005 04:56 PM 234,272 dzwsockx.dll
05/12/2005 04:44 PM 234,272 DullSys.dll
05/12/2005 04:41 PM 235,563 RDGSVC.DLL
05/12/2005 04:41 PM 236,218 hrn6055se.dll
05/12/2005 11:13 AM 235,563 hr4805hue.dll
05/12/2005 09:44 AM 235,563 MPVIDC32.DLL
05/11/2005 10:58 AM 233,184 SYCSCCP.DLL
05/10/2005 04:23 PM 235,563 IKETRES.DLL
05/10/2005 03:42 PM 235,164 hrls0537e.dll
05/10/2005 10:20 AM 235,578 MISWCH.DLL
05/09/2005 04:20 PM 235,164 RHBDYCTL.DLL
05/08/2005 11:18 AM 235,578 KYDFR.DLL
05/07/2005 05:04 PM 235,164 DDTACLEN.DLL
05/06/2005 06:19 PM 235,164 DCNET.DLL
05/05/2005 01:16 PM 234,049 hr2s05f7e.dll
05/04/2005 04:16 PM 233,805 DRUTIL.DLL
05/04/2005 12:17 PM 234,049 KIDGKL.DLL
05/03/2005 04:53 PM 233,805 iXlmgicd.dll
05/03/2005 02:59 PM 234,049 mygina.dll
05/03/2005 09:50 AM 233,805 CUMVS4o.DLL
05/02/2005 03:54 PM 234,049 FT20.DLL
05/01/2005 11:12 AM 233,805 KODTAT.DLL
04/30/2005 03:59 PM 233,200 VXSAPI.DLL
04/29/2005 09:22 AM 235,207 DIVVOX.DLL
04/28/2005 03:15 PM 233,200 NXDSBCLI.DLL
04/28/2005 10:41 AM 235,207 CEMODEM.DLL
04/28/2005 10:36 AM 233,200 KZDGR1.DLL
04/28/2005 09:20 AM 235,207 TOPIUI.DLL
04/27/2005 04:40 PM 234,047 iyfxsrvc.dll
04/27/2005 12:56 PM 235,207 MTIDNTLD.DLL
04/27/2005 12:37 PM 234,047 WJNSCARD.DLL
04/26/2005 01:59 PM 234,047 DSDSKRES.DLL
04/26/2005 01:55 PM 235,207 PVRFOS.DLL
04/26/2005 08:52 AM 234,047 AOSNDS.DLL
04/25/2005 04:07 PM 235,207 tS8ulcl91fq.dll
04/25/2005 03:42 PM 234,047 LTEXPAND.DLL
04/25/2005 03:31 PM 235,458 uber32.dll
04/25/2005 02:37 PM 234,047 LEEXPAND.DLL
04/24/2005 12:55 PM 232,902 lVprxy.dll
04/20/2005 03:47 PM 235,739 lvj2091oe.dll
04/20/2005 02:09 PM 235,739 KGDHE.DLL
04/20/2005 10:29 AM 235,450 DNSEC.DLL
04/19/2005 02:02 PM 235,739 mjjet40.dll
04/19/2005 10:12 AM 235,450 SINIKE.DLL
04/19/2005 09:58 AM 234,139 TMRMSRV.DLL
04/18/2005 03:20 PM 234,139 DTUSIC.DLL
04/18/2005 01:57 PM 234,139 RVM.DLL
04/18/2005 01:54 PM 234,139 HGETCFG.DLL
04/15/2005 06:50 PM 234,139 WTASCR.DLL
04/15/2005 06:46 PM 234,139 KWDPL1.DLL
04/15/2005 06:20 PM 234,139 RRMOTEPG.DLL
04/15/2005 09:05 AM 234,139 MOAATEXT.DLL
04/15/2005 08:31 AM 234,139 SbnTPFcs.dll
04/14/2005 01:38 PM 233,169 enp6l17s1.dll
04/14/2005 09:28 AM 233,169 MGVCRT40.DLL
04/13/2005 03:20 PM 233,169 DWSCRIPT.DLL
04/13/2005 01:24 PM 233,169 vihelper.dll
04/13/2005 01:18 PM 233,169 lvn0095me.dll
04/13/2005 01:06 PM 236,135 p6n8lg5u16.dll
04/13/2005 11:29 AM 233,169 HKUI.DLL
04/12/2005 06:52 PM 236,135 FMULTREP.DLL
04/12/2005 04:31 PM 232,907 SIC_OS.DLL
04/11/2005 08:18 PM 236,135 WNNOTIFY.DLL
04/11/2005 12:05 PM 232,907 DUSRSLVR.DLL
04/11/2005 11:47 AM 236,135 mvwdat10.dll
04/07/2005 06:10 PM 234,238 CLMCTL32.DLL
04/07/2005 04:07 PM 232,416 imfxdo.dll
04/07/2005 04:04 PM 232,416 WNNTRUST.DLL
04/07/2005 04:04 PM 233,787 enpol1731.dll
04/07/2005 10:50 AM 236,255 SLFRSLV.DLL
04/06/2005 09:07 AM 235,365 MGMINST.DLL
04/05/2005 10:24 AM 235,076 WNHISN.DLL
04/03/2005 03:44 PM 235,076 hasetup.dll
03/31/2005 04:38 PM 235,076 hfcoin.dll
03/30/2005 03:35 PM 233,174 NQTID.DLL
03/30/2005 10:34 AM 232,574 HBETCFG.DLL
03/30/2005 08:28 AM 235,634 DAEML.DLL
03/29/2005 04:14 PM 235,225 INXSAP.DLL
03/29/2005 02:13 PM 235,634 ETSADU.DLL
03/29/2005 01:48 PM 235,225 PENMAP.DLL
03/29/2005 10:20 AM 234,826 MIVCP60.DLL
03/28/2005 05:31 PM 234,236 SUI.DLL
03/28/2005 01:54 PM 234,996 qegrprxy.dll
03/27/2005 06:33 PM 234,236 DWOCX.DLL
03/23/2005 11:27 AM 233,957 MUL_MTF.DLL
03/23/2005 10:02 AM 233,957 KPDLV.DLL
03/22/2005 06:38 PM 233,837 PGFMGR.DLL
03/22/2005 04:20 PM 233,957 SKRRUN.DLL
03/21/2005 04:17 PM 233,837 sumedia.dll
03/20/2005 07:41 PM 233,957 LPCMGR10.DLL
03/18/2005 10:15 AM 233,957 UARV80A.DLL
03/17/2005 05:26 PM 233,837 CORSRV.DLL
03/17/2005 09:00 AM 233,957 mP28lgfu1628.dll
03/16/2005 05:31 PM 232,862 dnmv2clt.dll
03/16/2005 05:31 PM 233,837 DQOUND3D.DLL
03/16/2005 05:00 PM 235,803 lv4m09h1e.dll
03/16/2005 03:15 PM 235,803 NVTUI1.DLL
03/16/2005 09:27 AM 233,248 SVMPSNAP.DLL
03/15/2005 06:09 PM 233,248 WRSAPI32.DLL
03/15/2005 06:07 PM 235,057 p24ulch91f4.dll
03/15/2005 06:01 PM 236,018 j0p0la7m1d.dll
03/15/2005 06:01 PM 236,018 WMHTCPIP.DLL
03/15/2005 06:01 PM 232,654 q0680ajuedo80.dll
03/15/2005 06:01 PM 233,248 APSMSEXT.DLL
03/15/2005 05:59 PM 233,399 d40m0ed1eh0.dll
03/15/2005 05:57 PM 232,859 azau0559e.dll
03/15/2005 05:57 PM 233,248 mfrepl35.dll
03/15/2005 05:57 PM 233,357 lv0m09d1e.dll
03/15/2005 05:53 PM 232,426 g4040edqeh0e0.dll
03/15/2005 12:25 PM 236,018 n62ulgf9162.dll
03/14/2005 04:50 PM 234,947 IJUV_32.DLL
03/14/2005 12:06 PM 234,092 JUPROXY.DLL
03/11/2005 11:19 PM 232,736 aulddial.dll
03/10/2005 05:14 PM 225,396 CLETCFG.DLL
03/10/2005 05:11 PM 225,396 j46m0ej1eho.dll
03/09/2005 01:23 PM 225,396 p64ulgh9164.dll
03/09/2005 12:45 PM 225,396 TIPMIB.DLL
03/08/2005 02:09 PM 225,396 FCAMEBUF.DLL
03/08/2005 11:07 AM 225,396 baackbox.dll
03/07/2005 02:25 PM 226,296 l00u0ad9ed0.dll
03/07/2005 09:23 AM 223,141 KFDCZ.DLL
03/04/2005 12:45 PM 225,396 MEORC32R.DLL
03/03/2005 03:34 PM 224,873 KIDHU1.DLL
03/03/2005 12:45 PM 225,037 DSDXOF.DLL
03/03/2005 12:34 PM 223,121 m628lgfu1628.dll
03/03/2005 09:20 AM 223,267 mrxoci.dll
03/02/2005 05:58 PM 224,873 czlbact.dll
03/02/2005 01:24 PM 512 Elq0h.z89
03/02/2005 09:23 AM 224,873 NJWKS.DLL
03/01/2005 01:04 PM 223,267 ltj0271mg.dll
03/01/2005 10:18 AM 223,267 SNI_CI.DLL
02/28/2005 10:22 AM 224,753 KLDHE319.DLL
02/27/2005 02:05 PM 223,267 DICONFIG.DLL
02/25/2005 11:18 AM 224,753 QIAP.DLL
02/25/2005 11:10 AM 223,267 NLTEVENT.DLL
02/24/2005 03:25 PM 222,728 MGORCL32.DLL
02/23/2005 11:28 AM 223,267 UXNPHOST.DLL
02/22/2005 03:31 PM 222,728 WHV8DMOD.DLL
02/19/2005 06:22 PM 222,543 RYUTETAB.DLL
02/18/2005 10:44 AM 226,144 BSAPI.dll
02/17/2005 03:05 PM 222,543 SZNSCFG.DLL
02/17/2005 09:37 AM 222,543 RNVPSP.DLL
02/16/2005 07:40 PM 226,144 MFW3PRT.DLL
02/15/2005 05:53 PM 226,010 DGEML.DLL
02/15/2005 05:35 PM 226,010 OVTEXT32.DLL
02/15/2005 05:35 PM 222,803 enrml1911.dll
02/14/2005 04:11 PM 225,976 UHBUI.DLL
02/14/2005 10:36 AM 222,703 SPARDDLG.DLL
02/13/2005 03:00 PM 225,976 AWRSVC.DLL
02/12/2005 11:12 AM 222,703 ONBC32GT.DLL
02/10/2005 03:13 PM 225,407 DXMSRPCN.DLL
02/10/2005 03:04 PM 225,766 VDDEX.DLL
02/09/2005 03:03 PM 225,407 IBETCOMM.DLL
02/09/2005 03:01 PM 225,407 DJDPMESH.DLL
02/09/2005 03:01 PM 225,926 lvjq0915e.dll
02/09/2005 02:58 PM 225,407 SSFRSLV.DLL
02/09/2005 12:57 PM 224,422 l6j8lg1u16.dll
02/09/2005 09:12 AM 224,422 AMKCTRS.DLL
02/08/2005 05:34 PM 225,407 SWCSCCP.DLL
02/08/2005 03:27 PM 224,422 vudata.dll
02/08/2005 03:23 PM 222,410 KJDHE220.DLL
02/08/2005 10:31 AM 417,792 ??rvices.exe
02/07/2005 10:54 AM 222,410 SQSVCS.DLL
02/04/2005 10:18 AM 225,992 MVRATELC.DLL
02/04/2005 09:41 AM 225,992 cTtsrv.dll
02/03/2005 05:49 PM 222,410 UVRVPA.DLL
02/03/2005 05:45 PM 225,992 ITMON.DLL
02/03/2005 11:08 AM 225,177 SBRIALUI.DLL
02/03/2005 11:03 AM 225,992 CFMOCX.DLL
02/03/2005 10:52 AM 225,177 JYPROXY.DLL
02/02/2005 11:40 AM 225,093 MYRATING.DLL
02/01/2005 05:50 PM 224,749 KIDSG.DLL
02/01/2005 05:41 PM 224,114 cbl3d32.dll
02/01/2005 01:24 PM 224,749 TIRMSRV.DLL
02/01/2005 11:01 AM 224,114 MCORCL32.DLL
02/01/2005 10:57 AM 224,749 WZBCLNT.DLL
01/31/2005 10:49 AM 224,114 DTDSKRES.DLL
01/31/2005 09:32 AM 225,820 VWS_PS.DLL
01/28/2005 05:35 PM 224,114 MECTF.DLL
01/27/2005 10:01 AM 223,083 DFDMOPRP.DLL
01/27/2005 09:33 AM 223,202 sqrstr.dll
01/25/2005 07:11 PM 223,083 WL2TOPL.DLL
01/25/2005 07:07 PM 222,599 e0jmla111d.dll
01/25/2005 06:59 PM 222,599 CCMCAT.DLL
01/25/2005 06:55 PM 222,570 hrjs0517e.dll
01/25/2005 06:40 PM 222,570 DCNHPAST.DLL
01/25/2005 12:05 PM 226,235 MALBUI.DLL
01/24/2005 10:09 AM 224,820 SILGNTFY.DLL
01/20/2005 04:20 PM 226,235 wwps.dll
01/19/2005 04:36 PM 224,820 mgdtcuiu.dll
01/19/2005 12:17 PM 226,235 MRGENTR.DLL
01/18/2005 12:46 PM 224,820 vrmdbg.dll
01/18/2005 08:32 AM 226,235 OWJSEL.DLL
01/17/2005 10:48 PM 224,820 QWDWIPES.DLL
01/17/2005 08:18 PM 224,899 MIPORTS.DLL
01/17/2005 01:16 PM 224,899 WUBHITS.DLL
01/14/2005 11:19 AM 224,820 CTTSRVPS.DLL
01/13/2005 02:49 PM 222,773 UITFS.DLL
01/13/2005 02:37 PM 224,084 WPCSAPI.DLL
01/13/2005 10:36 AM 222,773 NIAPI16.DLL
01/12/2005 10:49 AM 225,297 RCSCHAP.DLL
01/11/2005 01:54 PM 223,581 MWRATELC.DLL
01/11/2005 09:59 AM 222,992 cBtsrv.dll
01/10/2005 10:55 AM 223,581 wqpcore.dll
01/10/2005 10:10 AM 222,992 vxxml.dll
01/07/2005 05:09 PM 222,868 MESTDFMT.DLL
01/07/2005 05:08 PM 222,868 KQDHE319.DLL
01/06/2005 06:56 PM 225,760 hrrq0595e.dll
01/06/2005 06:23 PM 225,760 AMFSIPC.DLL
01/05/2005 01:12 PM 222,868 WPBHITS.DLL
01/05/2005 11:31 AM 225,760 HLD.DLL
01/04/2005 10:26 AM 224,414 KQDIT.DLL
12/31/2004 09:55 AM 225,760 BWDISPL.DLL
12/30/2004 03:14 PM 224,414 RTSCHAP.DLL
12/30/2004 03:14 PM 225,659 ir42l5ho1.dll
12/29/2004 04:12 PM 224,414 COUTIL.DLL
12/29/2004 04:10 PM 224,414 hr2u05f9e.dll
12/29/2004 04:01 PM 222,918 ennsl1571.dll
12/28/2004 05:16 PM 224,414 COICONFG.DLL
12/28/2004 10:17 AM 222,918 SWNIKE.DLL
12/28/2004 09:50 AM 222,918 MZDRV.DLL
12/27/2004 06:14 PM 225,087 ir80l5lm1.dll
12/27/2004 05:42 PM 225,087 ALIFIL32.DLL
12/27/2004 05:26 PM 222,938 en64l1jq1.dll
12/27/2004 05:21 PM 225,087 SKEIO.DLL
12/27/2004 05:21 PM 226,042 hrnu0559e.dll
12/27/2004 09:19 AM 225,087 WFI.DLL
12/27/2004 09:19 AM 226,047 r06u0aj9edo.dll
12/26/2004 08:19 PM 225,087 SWAYERXP.DLL
12/26/2004 08:19 PM 226,192 ir0ml5d11.dll
12/19/2004 03:57 PM 224,558 l04q0ah5ed4.dll
12/19/2004 03:53 PM 224,558 mtjet40.dll
12/19/2004 03:50 PM 224,558 DMSSHLEX.DLL
12/17/2004 04:43 PM 225,214 t28ulcl91fq.dll
12/17/2004 04:39 PM 224,738 h60qlgd5160.dll
12/17/2004 03:04 PM 225,098 q668lgju16o8.dll
10/07/2004 10:02 AM 499,722 FmtlA.exe
10/07/2004 10:02 AM 499,722 QmtPCB55.exe
10/07/2004 10:02 AM 499,722 Srohe2Nf.exe
10/07/2004 09:25 AM 1,104 Xej7.b76
06/25/2004 01:29 PM 458,762 Elq0i.exe
06/27/2003 08:43 PM <DIR> Microsoft
321 File(s) 74,202,876 bytes
2 Dir(s) 22,129,098,752 bytes free
-
Here's the HiJack This Log:
Logfile of HijackThis v1.99.1
Scan saved at 3:13:04 PM, on 7/1/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\system32\cisvc.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\carpserv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\wuauclt.exe
C:\HiJackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.comcast.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Ncao] C:\Documents and Settings\David\Application Data\osoa.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O16 - DPF: {A97608DD-6999-11D5-9C8C-0010A4F2D6BF} (QCOMCont Class) - http://www.quicken.com/qw2001/qcominst.cab
O20 - Winlogon Notify: Nls - C:\WINDOWS\system32\irlol5331.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
-
Hi,JenniferH
Close any programs you have open since this step requires a reboot. Disconnect from the internet.
From the l2mfix folder on your desktop, double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing enter, then press any key to reboot your computer. After a reboot, your desktop and icons will appear, then disappear (this is normal). L2mfix will continue to scan your computer and when it's finished, notepad will open with a log. Copy the contents of that log and paste it back into this thread, along with a new Hijack This log.
HGD
-
Here's the latest HiJack log:
Logfile of HijackThis v1.99.1
Scan saved at 4:36:49 PM, on 7/1/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\system32\cisvc.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\carpserv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\EXPLORER.EXE
C:\HiJackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.comcast.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Ncao] C:\Documents and Settings\David\Application Data\osoa.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O16 - DPF: {A97608DD-6999-11D5-9C8C-0010A4F2D6BF} (QCOMCont Class) - http://www.quicken.com/qw2001/qcominst.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
-
Here's the l2mfix log in sections:
L2Mfix 1.03
Running From:
C:\Documents and Settings\David\Desktop\l2mfix
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Read BUILTIN\Power Users
(ID-IO) ALLOW Read BUILTIN\Power Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER
Setting registry permissions:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Denying C(CI) access for predefined group "Administrators"
- adding new ACCESS DENY entry
Registry Permissions set too:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(CI) DENY --C------- BUILTIN\Administrators
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Read BUILTIN\Power Users
(ID-IO) ALLOW Read BUILTIN\Power Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER
Setting up for Reboot
Starting Reboot!
C:\Documents and Settings\David\Desktop\l2mfix
System Rebooted!
Running From:
C:\Documents and Settings\David\Desktop\l2mfix
killing explorer and rundll32.exe
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Pea****@beyondlogic.org
Killing PID 1196 'explorer.exe'
Killing PID 1196 'explorer.exe'
Killing PID 1196 'explorer.exe'
Killing PID 1196 'explorer.exe'
Killing PID 1196 'explorer.exe'
Killing PID 1196 'explorer.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Pea****@beyondlogic.org
Killing PID 1528 'rundll32.exe'
Scanning First Pass. Please Wait!
First Pass Completed
Second Pass Scanning
Second pass Completed!
Backing Up: C:\WINDOWS\system32\AFL.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ALIFIL32.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\AMFSIPC.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\AMKCTRS.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\AOSNDS.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\APSMSEXT.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\APVAPI32.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\aulddial.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\AWFSIPC.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\AWRSVC.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\azau0559e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\baackbox.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\BSAPI.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\bstsprx2.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\BWDISPL.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\cautil.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\cbl3d32.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\cBtsrv.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\CCMCAT.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\CEMODEM.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\CFMOCX.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\CLETCFG.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\CLMCTL32.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\COICONFG.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\CORSRV.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\COUTIL.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\cTtsrv.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\CTTSRVPS.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\CUMVS4o.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\CXODM.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\czlbact.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\czyptui.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\d40m0ed1eh0.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\DAEML.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\DCNET.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\DCNHPAST.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\DDTACLEN.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\DFDMOPRP.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\DFMRTP.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\DGEML.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\DICONFIG.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\DIVVOX.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\DJDPMESH.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\DMSSHLEX.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\DNCPSAPI.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dnmv2clt.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\DNSEC.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\DQOUND3D.DLL
1 file(s) copied.
-

Backing Up: C:\WINDOWS\system32\DRUTIL.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\DSDSKRES.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\DSDXOF.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\DTDSKRES.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\DTUSIC.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\DullSys.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\DUSRSLVR.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\DVGHELP.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\DWOCX.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\DWSCRIPT.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\DXMSRPCN.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dzwsockx.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\e0jmla111d.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\en64l1jq1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ennql1551.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ennsl1571.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\enp6l17s1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\enpol1731.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\enrml1911.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ETSADU.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\FBIFS.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\FCAMEBUF.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\FF20ENU.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\FMULTREP.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\FT20.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\g4040edqeh0e0.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\GZDEF.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\h0l2la3o1d.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\h60qlgd5160.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\hasetup.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\HBETCFG.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\hfcoin.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\HGETCFG.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\hjcutils.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\HKUI.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\HLD.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\hr2s05f7e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\hr2u05f9e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\hr4805hue.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\hr4s05h7e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\hr6805jue.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\hrjs0517e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\hrls0537e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\hrn6055se.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\hrnu0559e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\hrrq0595e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\i4jqle151h.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\i6jqlg1516.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\IBETCOMM.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ICSACCT.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\id50_qcx.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\igircl.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\IHSPOLCY.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\IJSSDO.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\IJUV_32.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\IKETRES.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\imfxdo.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\INXSAP.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ir0ml5d11.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ir42l5ho1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ir80l5lm1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ITMON.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ITSETUP.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\IVETRES.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\IWSETUP.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ixfxsrvc.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\iXlmgicd.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\iyfxsrvc.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\j0p0la7m1d.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\j46m0ej1eho.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\JLAW400.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\JUPROXY.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\JYPROXY.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\k4800elmehqa0.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\KADHE.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\KFDCZ.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\KGDHE.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\KGDSL.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\KIDGKL.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\KIDHU1.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\KIDNO.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\KIDSG.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\KJDHE220.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\KKDSL.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\KLDHE319.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\KNDSL.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\KNDTAT.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\KODTAT.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\KPDLV.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\KQDHE319.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\KQDIT.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ktnul7591.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\KWDPL1.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\KYDFR.DLL
1 file(s) copied.