Thanks so much for doing all this, i realy appreciate it.
L2MFIX find log 051206
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
"Logon"="WLEventLogon"
"Logoff"="WLEventLogoff"
"Startup"="WLEventStartup"
"Shutdown"="WLEventShutdown"
"StartScreenSaver"="WLEventStartScreenSaver"
"StopScreenSaver"="WLEventStopScreenSaver"
"Lock"="WLEventLock"
"Unlock"="WLEventUnlock"
"StartShell"="WLEventStartShell"
"PostShell"="WLEventPostShell"
"Disconnect"="WLEventDisconnect"
"Reconnect"="WLEventReconnect"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000000
"SafeMode"=dword:00000001
"MaxWait"=dword:ffffffff
"DllName"=hex(2):57,00,67,00,61,00,4c,00,6f,00,67,00,6f,00,6e,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Event"=dword:0000001f
"InstallNotifyShown"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon\Settings]
"Data"=hex:01,00,00,00,d0,8c,9d,df,01,15,d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,\
00,00,57,13,53,ad,d1,f7,23,42,a8,4d,b6,2c,ae,d5,94,26,04,00,00,00,04,00,00,\
00,53,00,00,00,03,66,00,00,a8,00,00,00,10,00,00,00,72,8d,da,83,34,9e,a4,79,\
f0,03,90,36,8a,4c,a9,2b,00,00,00,00,04,80,00,00,a0,00,00,00,10,00,00,00,46,\
17,f9,05,67,8f,da,c0,8b,4d,9c,ee,3a,cd,13,ff,f8,04,00,00,da,55,4e,32,90,2a,\
54,c2,b7,48,4e,ca,f1,d8,b3,5d,b7,b0,30,92,b0,05,75,1e,9e,4b,37,13,29,2a,3b,\
36,aa,31,d6,57,72,90,a0,79,23,78,a8,3b,82,e4,2f,70,91,5a,fe,1c,f6,8f,97,5d,\
10,a4,c1,5b,16,15,ad,f9,27,7b,d7,36,c9,f6,18,2b,33,a2,9f,76,0f,3e,24,49,44,\
0a,c0,db,0e,6c,19,56,59,bf,07,c5,fb,1c,ec,fd,20,c4,0b,7a,48,36,af,8d,ba,b4,\
2f,e2,27,84,33,ab,73,a4,06,c8,79,c1,91,67,4b,df,79,12,26,ac,d4,01,8d,e5,8f,\
ef,de,3c,77,14,d2,9f,13,6c,94,e7,3b,42,30,71,3a,e2,24,20,5b,d4,bc,7d,9e,f8,\
26,20,07,69,0e,41,97,df,10,44,89,42,d9,12,f0,79,a3,a5,bb,c9,48,b8,de,2b,71,\
c8,29,0b,79,cb,a2,25,24,ac,59,41,1c,1b,28,3b,66,89,41,43,5f,ee,e0,47,7f,ae,\
50,14,7f,9e,86,71,20,57,6a,f7,5e,da,e6,7d,60,87,a1,04,84,b3,0b,49,67,0e,f5,\
4c,e6,b0,67,35,6b,e7,67,80,cb,13,74,92,f6,81,5b,f0,72,14,6f,7d,99,8e,74,ba,\
53,a0,d5,ba,48,ec,65,75,d6,01,41,27,ae,68,d0,2f,9d,af,f9,e0,03,02,4e,ce,ef,\
37,84,23,95,0f,bd,d5,7c,c3,12,19,0a,61,68,7d,d2,4e,16,f6,c9,cd,7f,b4,1b,6f,\
9d,c1,31,10,5d,42,dc,51,1b,4c,5c,3f,a5,7a,cf,99,94,8e,a4,59,be,02,72,4d,1d,\
43,d9,ce,e6,3a,27,b8,57,16,d5,5a,83,bc,48,f8,9d,ff,3a,3a,a4,22,2f,57,0c,2e,\
8c,3d,b7,74,1d,21,16,35,6a,d0,97,87,bb,54,51,e3,31,a0,00,55,19,a2,41,5e,c4,\
23,e6,d4,82,a8,37,e5,db,a3,b5,c8,50,33,9e,71,2d,f1,92,bf,cd,bd,b4,ab,a2,17,\
b9,31,76,e8,cf,77,ce,9c,4f,c3,31,fa,71,cf,d7,56,6f,dd,7c,ab,c5,5c,21,e9,17,\
f7,3f,6c,ea,51,3f,d6,03,a1,b8,49,93,d4,2f,55,56,5f,f8,bd,e2,34,b8,0d,cd,89,\
99,72,40,59,5e,e3,b2,3c,91,1d,86,dc,54,d2,d4,76,c5,73,f4,c5,c4,d4,87,ce,97,\
77,4a,05,9f,88,c6,aa,57,ee,3a,a8,fc,2b,39,81,62,1d,13,91,1d,b5,3b,7a,d4,61,\
53,19,e9,71,03,2d,4e,61,7e,02,0d,16,1e,3d,83,27,e3,41,f5,75,ab,83,e4,7d,68,\
fe,f0,ff,01,b9,8a,18,fd,4b,f3,af,f8,1f,d4,9d,0f,00,83,14,e9,ff,81,d4,da,f7,\
03,41,4a,c9,57,92,99,db,15,b6,48,79,81,16,88,2c,95,98,1b,4e,6d,7b,83,32,75,\
eb,44,75,98,bf,40,80,1b,28,fb,57,59,60,3e,41,8b,16,2a,f4,47,f4,d6,32,69,c0,\
ab,71,12,db,48,fc,90,1b,5e,35,4c,ca,a2,d5,0d,0d,66,84,b6,b7,9c,58,32,62,0b,\
ca,f4,a8,00,91,a0,94,66,8f,13,53,7f,cb,47,e3,1f,77,03,2e,0c,a2,80,f7,37,8f,\
aa,51,bf,da,60,3d,bc,f1,95,f4,c3,7f,de,37,69,25,54,4c,f9,50,eb,6d,89,67,80,\
e9,8c,ba,30,44,4b,f8,fd,ad,df,9a,f4,17,6f,89,0d,de,6c,6b,25,23,15,c8,14,87,\
04,73,64,e9,5c,c2,ba,84,ce,84,3a,5b,4c,dd,37,77,2b,05,ae,e4,c7,f1,8b,3a,13,\
02,03,f3,57,ef,2d,14,9e,f9,6f,36,83,e9,55,79,97,20,3e,50,56,db,e9,b4,a7,c4,\
d7,20,cf,d6,7b,55,72,51,93,35,48,79,9d,20,06,93,e0,dc,a3,c4,b2,0c,27,4a,fc,\
6b,e3,e3,9b,15,76,36,2f,52,0f,a7,aa,0d,a0,4c,06,85,ca,0a,f2,18,94,21,54,3c,\
99,ec,d4,11,84,4b,8a,97,45,f7,1d,3e,f3,1f,34,99,99,fc,12,9b,8c,a2,39,99,20,\
f9,db,1d,57,3f,ba,c0,f9,95,e1,9b,76,22,09,a1,ea,38,40,e4,29,2b,21,1a,5f,aa,\
71,12,9b,ab,bc,9f,97,c8,78,fa,3b,46,f5,de,b2,71,39,6d,d6,1e,42,8d,86,f5,f8,\
5a,f5,d2,da,9d,dd,83,18,80,57,d4,68,02,ca,32,4a,40,4e,1d,da,08,ba,0b,dd,cb,\
3b,8f,d3,5d,a5,6b,b7,23,14,b7,22,28,66,d7,60,29,d1,cb,15,f5,f7,aa,5a,c0,3d,\
4a,c4,a9,8b,74,41,c9,46,88,da,8a,d8,33,cc,2b,a6,98,14,f7,12,b5,0f,a1,13,cc,\
ed,1e,8c,07,8e,4f,81,e5,73,9c,ae,24,83,a2,d2,f4,80,ab,58,d8,12,65,be,2d,1a,\
fe,62,84,c1,01,1a,9e,09,3c,9c,40,b9,13,2f,54,d7,90,23,dc,74,19,e8,81,ef,05,\
10,b8,58,5b,05,ef,e7,a6,f5,bd,54,78,8b,e5,0e,9f,3b,eb,f7,d2,4e,eb,59,37,f3,\
f5,78,92,59,a2,d5,a8,37,3f,84,fc,ea,21,8d,f1,99,df,73,07,21,69,59,fc,fb,62,\
0b,7c,21,06,9e,09,a2,1f,1f,8c,d3,ad,f6,0b,cd,c1,55,b1,a5,b3,4a,5a,fa,f0,8a,\
40,12,57,1f,a0,5c,51,41,42,03,db,7d,6d,b2,69,6e,50,67,b2,67,60,97,f8,8e,17,\
5d,42,9f,70,d7,27,c8,57,ee,4f,30,2b,8a,56,d7,f1,2c,c0,3e,23,82,bb,01,88,16,\
28,0e,a8,c2,34,d2,a5,92,94,fe,b5,25,18,75,05,90,09,de,b4,f8,d7,89,33,65,74,\
33,d6,3a,14,7f,23,2c,4a,94,55,c0,be,9d,fe,a2,cf,f9,b0,4f,d1,c6,c6,61,d1,f8,\
4d,a6,64,9d,6e,8c,b9,b3,65,30,0a,7b,05,78,cc,5e,4b,9e,1b,4c,de,c6,25,df,c0,\
ed,24,df,12,c8,78,cc,99,1a,06,bb,58,0d,d7,f8,18,8f,73,02,b1,98,c7,4f,96,16,\
16,00,e1,f3,3f,bf,10,b4,39,c8,9b,10,ea,60,25,c5,2c,13,48,ae,d8,06,10,70,ad,\
4c,09,aa,48,5f,a0,6a,8b,42,3b,8d,88,ed,4e,27,d0,14,00,00,00,1f,87,09,78,0c,\
34,f9,d4,b4,26,56,b0,7d,11,57,95,fe,9b,dc,51
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WRNotifier]
"Asynchronous"=dword:00000000
"DllName"="WRLogonNTF.dll"
"Impersonate"=dword:00000001
"Lock"="WRLock"
"StartScreenSaver"="WRStartScreenSaver"
"StartShell"="WRStartShell"
"Startup"="WRStartup"
"StopScreenSaver"="WRStopScreenSaver"
"Unlock"="WRUnlock"
"Shutdown"="WRShutdown"
"Logoff"="WRLogoff"
"Logon"="WRLogon"
**********************************************************************************
useragent:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"sv1"=""
**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{A70C977A-BF00-412C-90B7-034C51DA2439}"="NvCpl DesktopContext Class"
"{FFB699E0-306A-11d3-8BD1-00104B6F7516}"="Play on my TV helper"
"{1CDB2949-8F65-4355-8456-263E7C208A5D}"="Desktop Explorer"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}"="Desktop Explorer Menu"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A48}"="nView Desktop Context Menu"
"{21569614-B795-46b1-85F4-E737A8DC09AD}"="Shell Search Band"
"{CA5FEE26-14C1-4B5A-86E9-233FC0EE2682}"="IZArc DragDrop Menu"
"{8D9D4D0D-FDDD-44CB-AAB2-6161FA0757C5}"="IZArc Shell Context Menu"
"{32020A01-506E-484D-A2A8-BE3CF17601C3}"="AlcoholShellEx"
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
"{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}"="PowerISO"
"{e82a2d71-5b2f-43a0-97b8-81be15854de8}"="ShellLink for Application References"
"{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75}"="Shell Icon Handler for Application References"
"{36A21736-36C2-4C11-8ACB-D4136F2B57BD}"="AutoCAD Digital Signatures Icon Overlay Handler"
"{AC1DB655-4F9A-4c39-8AD2-A65324A4C446}"="Autodesk Drawing Preview"
"{7C9D5882-CB4A-4090-96C8-430BFE8B795B}"="Webroot Spy Sweeper Context Menu Integration"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
**********************************************************************************
HKEY ROOT CLASSIDS:
**********************************************************************************
Files Found are not all bad files:
C:\WINDOWS\SYSTEM32\
atmtd.dll Mon 3 Jul 2006 17:46:42 A.... 687,592 671.48 K
bassmod.dll Sun 11 Jun 2006 18:05:44 A.... 14,848 14.50 K
hp0023~1.dll Wed 12 Jul 2006 10:00:56 ..S.R 236,487 230.94 K
pkdrv.dll Tue 11 Jul 2006 17:10:56 ..... 236,487 230.94 K
ravpperf.dll Wed 12 Jul 2006 17:05:06 ..S.R 236,487 230.94 K
5 items found: 5 files (2 H/S), 0 directories.
Total of file sizes: 1,411,901 bytes 1.34 M
Locate .tmp files:
No matches found.
**********************************************************************************
Directory Listing of system files:
Volume in drive C has no label.
Volume Serial Number is 1859-0C70
Directory of C:\WINDOWS\System32
13/07/2006 06:52 PM <DIR> ..
13/07/2006 06:52 PM <DIR> .
13/07/2006 09:33 AM <DIR> dllcache
12/07/2006 05:05 PM 236,487 ravpperf.dll
12/07/2006 10:00 AM 236,487 hp0023dmg.dll
19/03/2006 08:45 AM 32 {7D7B0656-012A-4FFD-88CF-703A6BE4E46C}.dat
12/03/2006 04:33 PM 1,004 KGyGaAvL.sys
09/01/2006 11:58 PM 56 33DAC8FEE2.sys
13/07/2005 04:03 PM <DIR> Microsoft
5 File(s) 474,066 bytes
4 Dir(s) 2,950,344,704 bytes free
|