UNSOLVED

blistex

updated

21 years ago

B

blistex

15 Posts

0

1079

February 7th, 2006 20:00

winfix trouble

Hello,
 
Can anyone help me with this winfix problem? I seem to have some sort of winfix popup virus that constantly causes my computer to freeze, crash, shut off, etc. This is my log:
 
Logfile of HijackThis v1.99.1
Scan saved at 4:57:05 PM, on 2/7/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Administrator\Desktop\hijackthis_sfx.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.search123forme.com/sp2.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.search123forme.com/sp2.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.search123forme.com/sp2.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = C:\WINDOWS\System32\msblank.html
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [McAfee Guardian] "C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VTPreset] VTPreset.exe
O4 - HKLM\..\Run: [MediaGateway] C:\Program Files\MediaGateway\MediaGateway.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo R220 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE /P30 "EPSON Stylus Photo R220 Series" /O6 "USB001" /M "Stylus Photo R220"
O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [WinProfile] sndcfg16.exe
O4 - HKLM\..\Run: [MNI.UWFX5_0001_MNI] "C:\Documents and Settings\Administrator\Desktop\WinFixer2005ScannerInstall.exe"
O4 - HKLM\..\RunServices: [WinProfile] sndcfg16.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-58-12-0000106.exe
O4 - HKCU\..\Run: [DNS] C:\Program Files\Common Files\mc-58-12-0000106.exe
O4 - HKCU\..\Run: [CMSystem] "C:\Program Files\CMSystem\CMSystem.exe"
O4 - HKCU\..\Run: [CAS Client] "C:\Program Files\Cas\Client\casclient.exe"
O4 - HKCU\..\Run: [PayTime] C:\WINDOWS\System32\paytime.exe
O4 - HKCU\..\Run: [Shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00005.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1129313162921
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1129260915562
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O18 - Protocol: aim - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: shell - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O20 - Winlogon Notify: Reinstall - C:\WINDOWS\system32\muftedit.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SmartLinkService (SLService) -   - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
 
Sorry if I need to be more specific, if you're willing to help but need more information just ask and I will do my best to provide.
 
Thanks,
Blistex
  • RKinner

    2 Intern

    5851 Posts

    448

    0

    Posted February 7th, 2006 21:00

    You have a lot more than winfixer.
     
    Get smitrem from:
     

    Download smitRem.exe, saving the file to your desktop. Double click it to extract the contents to a folder of its own.

     
    Shutdown and Restart and Boot into Safe Mode by tapping the F8 key when you see the PC
    maker's logo.
    Keep tapping until it tells you it is going to Safe Mode or you see the Safe
    Mode menu. Select the top option.  Log in with your usual login.
     
    Do a HijackThis Scan and check the following then Fix Checked.
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.search123forme.com/sp2.php
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.search123forme.com/sp2.php
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.search123forme.com/sp2.php
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = C:\WINDOWS\System32\msblank.html
    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\Run: [MediaGateway] C:\Program Files\MediaGateway\MediaGateway.exe
    O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
    O4 - HKLM\..\Run: [WinProfile] sndcfg16.exe
    O4 - HKLM\..\Run: [MNI.UWFX5_0001_MNI] "C:\Documents and Settings\Administrator\Desktop\WinFixer2005ScannerInstall.exe"
    O4 - HKLM\..\RunServices: [WinProfile] sndcfg16.exe
    O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-58-12-0000106.exe
    O4 - HKCU\..\Run: [DNS] C:\Program Files\Common Files\mc-58-12-0000106.exe
    O4 - HKCU\..\Run: [CMSystem] "C:\Program Files\CMSystem\CMSystem.exe"
    O4 - HKCU\..\Run: [CAS Client] "C:\Program Files\Cas\Client\casclient.exe"
    O4 - HKCU\..\Run: [PayTime] C:\WINDOWS\System32\paytime.exe
    O4 - HKCU\..\Run: [Shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00005.exe"
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
    O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
    O20 - Winlogon Notify: Reinstall - C:\WINDOWS\system32\muftedit.dll
     
    open the smitRem folder and double click the RunThis.bat file to start the tool. Follow the prompts on screen and allow disk cleanup to complete.
     
    Run a new hijackthis log and post it as a reply.  Let's see how we did.
     
    Ron

     
  • blistex

    15 Posts

    448

    0

    Posted February 8th, 2006 01:00

    Thanks a lot for your help. I followed your instructions (no more winzip popups!-although it looks like he's down but not out).
    Here is the new log:
     
    Logfile of HijackThis v1.99.1
    Scan saved at 10:54:47 PM, on 2/7/2006
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\ewido\security suite\ewidoctrl.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\MediaGateway\MediaGateway.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE
    C:\Program Files\winupdates\winupdates.exe
    C:\WINDOWS\System32\sndcfg16.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\aim\aim.exe
    C:\Program Files\AWS\WeatherBug\Weather.exe
    C:\Program Files\CASIO\Photo Loader\Plauto.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Documents and Settings\Gizzard\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [McAfee Guardian] "C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [VTPreset] VTPreset.exe
    O4 - HKLM\..\Run: [MediaGateway] C:\Program Files\MediaGateway\MediaGateway.exe
    O4 - HKLM\..\Run: [EPSON Stylus Photo R220 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE /P30 "EPSON Stylus Photo R220 Series" /O6 "USB001" /M "Stylus Photo R220"
    O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
    O4 - HKLM\..\Run: [WinProfile] sndcfg16.exe
    O4 - HKLM\..\Run: [MNI.UWFX5_0001_MNI] "C:\Documents and Settings\Administrator\Desktop\WinFixer2005ScannerInstall.exe"
    O4 - HKLM\..\RunServices: [WinProfile] sndcfg16.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
    O4 - HKCU\..\Run: [WinFixer  2005] C:\Program Files\WinFixer  2005\uwfx5.exe /scan
    O4 - HKCU\..\Run: [WinFixer2005] "C:\Program Files\WinFixer  2005\uwfx5.exe" /min
    O4 - Startup: Epson printer Registration.lnk = E:\Titles\Ereg\EPSONREG.EXE
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
    O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\WINDOWS\System32\shdocvw.dll
    O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
    O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
    O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
    O15 - Trusted Zone: *.bitdefender.com
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
    O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1129313162921
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1129260915562
    O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
    O18 - Protocol: aim - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
    O18 - Protocol: shell - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
    O20 - Winlogon Notify: Installer - C:\WINDOWS\system32\muftedit.dll
    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: SmartLinkService (SLService) -   - C:\WINDOWS\SYSTEM32\slserv.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
     

    Message Edited by blistex on 02-07-2006 09:58 PM

  • RKinner

    2 Intern

    5851 Posts

    448

    0

    Posted February 8th, 2006 15:00

    Strange that it made any difference.  Looks like winfixer has actually burrowed deeper into your system.
     
    Let's run the standard two programs for winfixer first just to see if they can get rid of the O20 entry.
     
    See Dell-ChrisM's post at:
     
     
    After you finish with them.

    Download and install ccleaner.exe from http://www.ccleaner.com. Don't let
    it clean anything yet. 
    Download the killbox:
    Unzip it to your desktop but don't run it.
     
    Click on the line that says:  DOWNLOAD RegSeeker 1.45 beta (21 languages included !)
     
    Install it but don't run it yet.

    Shutdown and Restart and Boot into Safe Mode by tapping the F8 key when you see the PC
    maker's logo.
    Keep tapping until it tells you it is going to Safe Mode or you see the Safe
    Mode menu. Select the top option. Log in as your usual login or you won't find the programs you put on the desktop
    and some of the entries may not appear we want to remove will not appear in HijackTHis.
    Run HijackThis and just do a Scan only. Check  then Fix Checked the following:
     
    O4 - HKLM\..\Run: [MediaGateway] C:\Program Files\MediaGateway\MediaGateway.exe
    O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
    O4 - HKLM\..\Run: [WinProfile] sndcfg16.exe
    O4 - HKLM\..\Run: [MNI.UWFX5_0001_MNI] "C:\Documents and Settings\Administrator\Desktop\WinFixer2005ScannerInstall.exe"
    O4 - HKLM\..\RunServices: [WinProfile] sndcfg16.exe
    O4 - HKCU\..\Run: [WinFixer  2005] C:\Program Files\WinFixer  2005\uwfx5.exe /scan
    O4 - HKCU\..\Run: [WinFixer2005] "C:\Program Files\WinFixer  2005\uwfx5.exe" /min
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
    O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
    O20 - Winlogon Notify: Installer - C:\WINDOWS\system32\muftedit.dll

    Run ccleaner.exe, uncheck everything on the first page except the two entries
    with Temporary and then Run Cleaner.
     
    Run RegSeeker and select Find in Registry then check all of the HKEY options then have it search for:
    MNI.UWFX5_0001_MNI
    When it finishes, press the Select All button at the bottom of the page then when it opens up a little menu Select All again then right click on the selection and Delete Selected Items.
     
    Repeat regseeker search and delete for:
    WinFixer
    muftedit.dll
     

    Run killbox.  Open Options and check Remove Directories
    Where it says Full Path of File to Delete you need to type or copy (Hightlight and Ctrl + c)
    and Paste (move to the killbox and place the cursor in the box and Ctrl + V):
    C:\Program Files\MediaGateway
    Then check the Delete on Reboot box then the red button. 
    It will say:  File Will Be Removed On Reboot, Do you want to reboot Now.
    Tell it NO.  (If it can't find it that's OK just go on to the next one)
     
    Repeat for:
     
    C:\Program Files\winupdates
    C:\WINDOWS\system32\muftedit.dll
    C:\Program Files\WinFixer  2005
    C:\WINDOWS\system32\sndcfg16.exe
     
    Let it reboot after the last one. 

    Reboot into regular mode and run a new hjt log and post it as a reply.
     
    Ron
  • blistex

    15 Posts

    448

    0

    Posted February 9th, 2006 03:00

    So whats the prognosis:
     
    Logfile of HijackThis v1.99.1
    Scan saved at 12:30:43 AM, on 2/9/2006
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\ewido\security suite\ewidoctrl.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\aim\aim.exe
    C:\Program Files\AWS\WeatherBug\Weather.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Program Files\CASIO\Photo Loader\Plauto.exe
    C:\Documents and Settings\Gizzard\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
    C:\WINDOWS\System32\wuauclt.exe
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [McAfee Guardian] "C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [VTPreset] VTPreset.exe
    O4 - HKLM\..\Run: [EPSON Stylus Photo R220 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE /P30 "EPSON Stylus Photo R220 Series" /O6 "USB001" /M "Stylus Photo R220"
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
    O4 - Startup: Epson printer Registration.lnk = E:\Titles\Ereg\EPSONREG.EXE
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
    O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\WINDOWS\System32\shdocvw.dll
    O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
    O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
    O15 - Trusted Zone: *.bitdefender.com
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
    O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1129313162921
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1129260915562
    O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
    O18 - Protocol: aim - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
    O18 - Protocol: shell - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
    O20 - Winlogon Notify: Setup - C:\WINDOWS\system32\muftedit.dll
    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: SmartLinkService (SLService) -   - C:\WINDOWS\SYSTEM32\slserv.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
     
  • RKinner

    2 Intern

    5851 Posts

    448

    0

    Posted February 9th, 2006 13:00

    We're getting there.  Still need to get rid of this one:

     

    O20 - Winlogon Notify: Setup - C:\WINDOWS\system32\muftedit.dll

     

    Let's try atribune's old fix for winfixer.  It doesn't rely on the presence of a BHO to attack the problem.

    Follow Atribune's procedure at:
     
    http://www.atribune.org/forums/index.php?showtopic=447&hl=killvundo
     
    The paths the program asks you for would be:
     
    C:\WINDOWS\system32\muftedit.dll


    and
     
    C:\WINDOWS\system32\tidetfum.*

    (If it doesn't like the second one then use the first one again)


    Please do not use the ones given in the article since they will not work for your infection.

    You will know that it worked if the line

    O20 - Winlogon Notify: Setup - C:\WINDOWS\system32\muftedit.dll

    Either drop out of the scan or says File Missing.  Post a new HijackThis scan when you are done

     

    Ron

     

     

  • RKinner

    2 Intern

    5851 Posts

    448

    0

    Posted February 9th, 2006 20:00

    First time I've seen it with that program but there is another program we use that has a fix built in for the same error.

    Wouldn't hurt to run it anyway.  Maybe we will get lucky.

    "Download L2mfix from one of these two locations:

    www.atribune.org/downloads/l2mfix.exe
    www.downloads.subratam.org/l2mfix.exe

    Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

    IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!

    * Note: If you receive an error while running option #1 like: ''C:\windows\system32\cmd.exe
    C:\windows\system32\autoexec.nt the system file is not suitable for running ms-dos and microsoft windows applications, choose close to terminate the application.."...then do one of the following:

    1: Click on the l2mfix.bat again and choose option # 5 for Fix Autoexec.nt/cmd.exe error.
    2: Alternatively, you can click the fixautont.html link in the l2mfix folder and follow the directions there to fix it manually.
    Do not run the fix portion without fixing the error first.
    After you have performed the procedures to fix the error, repeat the steps above to run option #1 for Run Find Log."

    Ron

  • blistex

    15 Posts

    448

    0

    Posted February 9th, 2006 20:00

    Thanks for your continued help. You were right, it didn't like the second one. Gave me this message:
     
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\AUTOEXEC.NT  The system file is not suitable for running. MS-DOS and Microsoft Windows applications. Choose 'close' to terminate the applications.
     
    So I did, and entered the first one again instead of the second. I got the same message, so I tried choosing ignore but that didn't work. Any idea how I can get around this?
  • blistex

    15 Posts

    448

    0

    Posted February 9th, 2006 23:00

    L2MFIX find log 010406
    These are the registry keys present
    **********************************************************************************
    Winlogon/notify:
    Windows Registry Editor Version 5.00
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
    "Asynchronous"=dword:00000000
    "DllName"=""
    "Impersonate"=dword:00000000
    "Logon"="WinLogon"
    "Logoff"="WinLogoff"
    "Shutdown"="WinShutdown"
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
    "Asynchronous"=dword:00000000
    "Impersonate"=dword:00000000
    "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
      6c,00,00,00
    "Logoff"="ChainWlxLogoffEvent"
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
    "Asynchronous"=dword:00000000
    "Impersonate"=dword:00000000
    "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
      6c,00,6c,00,00,00
    "Logoff"="CryptnetWlxLogoffEvent"
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\URL]
    "Asynchronous"=dword:00000000
    "DllName"="C:\\WINDOWS\\system32\\muftedit.dll"
    "Impersonate"=dword:00000000
    "Logon"="WinLogon"
    "Logoff"="WinLogoff"
    "Shutdown"="WinShutdown"
    **********************************************************************************
    useragent:
    Windows Registry Editor Version 5.00
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
    "{2B43DB2D-CE7B-A4B5-92D9-ABCB8CB79204}"=""
    **********************************************************************************
    Shell Extension key:
    Windows Registry Editor Version 5.00
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
    "{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
    "{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
    "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
    "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
    "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
    "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
    "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
    "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
    "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
    "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
    "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
    "{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
    "{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
    "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
    "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
    "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
    "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
    "{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
    "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
    "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
    "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
    "{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
    "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
    "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
    "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
    "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
    "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
    "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
    "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
    "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras"
    "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras"
    "{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras"
    "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras"
    "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras"
    "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
    "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
    "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
    "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
    "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
    "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
    "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
    "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
    "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
    "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
    "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
    "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run..."
    "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
    "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
    "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
    "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
    "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
    "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
    "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
    "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
    "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
    "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
    "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
    "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
    "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
    "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
    "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
    "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
    "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
    "{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
    "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
    "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
    "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
    "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address"
    "{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
    "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
    "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
    "{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
    "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
    "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
    "{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
    "{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
    "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
    "{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
    "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
    "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
    "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
    "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
    "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
    "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
    "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
    "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
    "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
    "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
    "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
    "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
    "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
    "{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
    "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
    "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
    "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
    "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
    "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
    "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
    "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
    "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
    "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
    "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
    "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
    "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
    "{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
    "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
    "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
    "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
    "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
    "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
    "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
    "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
    "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
    "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
    "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
    "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
    "{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
    "{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
    "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
    "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
    "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
    "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
    "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
    "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
    "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard"
    "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web"
    "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
    "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard"
    "{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
    "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
    "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
    "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File"
    "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut"
    "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
    "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
    "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
    "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
    "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
    "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
    "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
    "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
    "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
    "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
    "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
    "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
    "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
    "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
    "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
    "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
    "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
    "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
    "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
    "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
    "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
    "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
    "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
    "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
    "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
    "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
    "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
    "{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People..."
    "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
    "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
    "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
    "{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
    "{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
    "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
    "{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}"="iTunes"
    "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
    "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
    "{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Web Folders"
    "{B4BD5516-4F4C-46E0-9AF2-49F7CCE564E2}"=""
    "{28461F70-320B-463A-9372-6F3D509C0325}"=""
    **********************************************************************************
    HKEY ROOT CLASSIDS:
    Windows Registry Editor Version 5.00
    [HKEY_CLASSES_ROOT\CLSID\{B4BD5516-4F4C-46E0-9AF2-49F7CCE564E2}]
    @=""
    [HKEY_CLASSES_ROOT\CLSID\{B4BD5516-4F4C-46E0-9AF2-49F7CCE564E2}\Implemented Categories]
    @=""
    [HKEY_CLASSES_ROOT\CLSID\{B4BD5516-4F4C-46E0-9AF2-49F7CCE564E2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""
    [HKEY_CLASSES_ROOT\CLSID\{B4BD5516-4F4C-46E0-9AF2-49F7CCE564E2}\InprocServer32]
    @="C:\\WINDOWS\\system32\\myrapi.dll"
    "ThreadingModel"="Apartment"
    Windows Registry Editor Version 5.00
    [HKEY_CLASSES_ROOT\CLSID\{28461F70-320B-463A-9372-6F3D509C0325}]
    @=""
    [HKEY_CLASSES_ROOT\CLSID\{28461F70-320B-463A-9372-6F3D509C0325}\Implemented Categories]
    @=""
    [HKEY_CLASSES_ROOT\CLSID\{28461F70-320B-463A-9372-6F3D509C0325}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""
    [HKEY_CLASSES_ROOT\CLSID\{28461F70-320B-463A-9372-6F3D509C0325}\InprocServer32]
    @="C:\\WINDOWS\\system32\\lc32.dll"
    "ThreadingModel"="Apartment"
    **********************************************************************************
    (Couldn't fit entire log-word limit)
  • blistex

    15 Posts

    314

    0

    Posted February 10th, 2006 00:00

    uh oh...make that triple post:

     

    Directory Listing of system files:
     Volume in drive C has no label.
     Volume Serial Number is C473-D515
     Directory of C:\WINDOWS\System32
    02/09/2006  08:47 PM            ..
    02/09/2006  08:47 PM            .
    02/09/2006  04:57 PM           417,792 lc32.dll
    02/09/2006  04:41 PM           417,792 khdbene.dll
    02/09/2006  04:27 PM           417,792 iumpagnt.dll
    02/09/2006  12:29 AM           417,792 rnpsnd.dll
    02/08/2006  11:59 PM           417,792 myrapi.dll
    02/08/2006  10:21 PM           417,792 ilv6mon.dll
    02/08/2006  08:34 PM            dllcache
    02/08/2006  01:25 AM           417,792 hvp95en.dll
    02/08/2006  01:01 AM           417,792 PLCSDK.dll
    02/07/2006  11:24 PM           417,792 OmgDS.dll
    02/07/2006  10:16 PM           417,792 ducpcsvc.dll
    02/07/2006  09:38 PM           417,792 misap.dll
    02/07/2006  09:23 PM           417,792 lwcwmi.dll
    02/07/2006  08:51 PM           417,792 symedia.dll
    02/07/2006  05:30 PM           417,792 dgocx.dll
    02/07/2006  04:52 PM           417,792 oDkley.dll
    02/07/2006  04:47 PM           417,792 wz2help.dll
    02/07/2006  04:21 PM           417,792 gmmf32.dll
    02/07/2006  03:52 PM           417,792 wgnsta.dll
    02/07/2006  03:34 PM           417,792 jrdw400.dll
    02/07/2006  02:36 PM           417,792 hntplug.dll
    02/07/2006  02:28 PM           417,792 decprop.dll
    02/07/2006  01:37 PM           417,792 ope2.dll
    02/07/2006  11:58 AM           417,792 drmodemx.dll
    02/07/2006  11:03 AM           417,792 rJsmxs.dll
    02/07/2006  10:50 AM           417,792 rxgapi.dll
    02/06/2006  08:32 PM           417,792 MTSTKPRP.DLL
    02/06/2006  05:18 PM           417,792 nzmsmgr.dll
    02/06/2006  04:39 PM           417,792 wospdmoe.dll
    02/06/2006  04:22 PM           417,792 apsldp.dll
    02/06/2006  03:55 PM           417,792 dnmsadsn.dll
    02/06/2006  03:50 PM           417,792 ihircl.dll
    02/06/2006  03:31 PM           417,792 opbc32.dll
    02/06/2006  03:24 PM           417,792 mwcms.dll
    02/06/2006  03:13 PM           417,792 wxvdmoe2.dll
    02/06/2006  03:02 PM           417,792 iWsrad.dll
    02/06/2006  02:33 PM           417,792 dvmsadsn.dll
    02/06/2006  12:47 PM           417,792 cqmuid.dll
    02/06/2006  11:18 AM           417,792 wmhtcpip.dll
    02/04/2006  11:10 PM           417,792 snorage.dll
    02/04/2006  10:23 PM           417,792 rHsmans.dll
    02/04/2006  09:48 PM           417,792 mirdim.dll
    02/04/2006  09:42 PM           417,792 opbcconf.dll
    02/04/2006  08:57 PM           417,792 AntPanel.dll
    02/04/2006  08:41 PM           417,792 okesvr.dll
    02/04/2006  08:36 PM           417,792 uiiplat.dll
    02/04/2006  08:22 PM           417,792 stcbase.dll
    02/04/2006  07:51 PM           417,792 fxsrch.dll
    02/04/2006  07:41 PM           417,792 mptask.dll
    02/04/2006  07:37 PM           417,792 bhowser.dll
    02/04/2006  07:12 PM           417,792 jusd400.dll
    02/04/2006  06:57 PM           417,792 axmeter.dll
    02/04/2006  06:51 PM           417,792 Dwclw.dll
    02/04/2006  06:40 PM           417,792 mcvci70.dll
    02/04/2006  06:10 PM           417,792 cQtsrvut.dll
    02/04/2006  05:55 PM           417,792 sbmsg.dll
    02/04/2006  05:39 PM           417,792 mamdd.dll
    02/04/2006  05:20 PM           417,792 mjtext40.dll
    02/04/2006  05:10 PM           417,792 cscfg32.dll
    02/04/2006  05:01 PM           417,792 utandlg.dll
    02/04/2006  04:53 PM           417,792 repsnd.dll
    02/04/2006  04:45 PM           417,792 mqjava.dll
    02/04/2006  04:30 PM           417,792 ithlpapi.dll
    02/03/2006  07:41 PM           417,792 mpjava.dll
    02/03/2006  07:28 PM           417,792 mgdtclog.dll
    02/03/2006  07:21 PM           417,792 LKDIS11n.dll
    02/03/2006  06:56 PM           417,792 rUsrad.dll
    02/03/2006  06:35 PM           417,792 spesrv.dll
    02/03/2006  06:22 PM           417,792 wfvcore.dll
    02/03/2006  06:15 PM           417,792 sabcsp.dll
    02/03/2006  05:55 PM           417,792 scorage.dll
    02/02/2006  08:58 PM           417,792 pfmas.dll
    02/02/2006  08:47 PM           417,792 bvowser.dll
    02/02/2006  07:51 PM           417,792 aistream.dll
    02/02/2006  07:49 PM           417,792 onuninst.dll
    02/02/2006  07:10 PM           417,792 sxdll.dll
    10/15/2005  06:52 PM           417,792 qoartz.dll
    10/11/2005  06:39 PM           417,792 sxarddlg.dll
    10/11/2005  09:46 AM           417,792 oebc16gt.dll
    10/11/2005  09:45 AM           417,792 mbd32.dll
    10/11/2005  09:38 AM           417,792 kodusx.dll
    10/11/2005  09:31 AM           417,792 kodcr.dll
    10/10/2005  07:58 PM           417,792 skclient.dll
    10/10/2005  07:47 PM           417,792 dwcpmon.dll
    10/10/2005  07:39 PM           417,792 sgfolder.dll
    10/10/2005  06:41 PM           417,792 muftedit.dll
    10/10/2005  06:29 PM           417,792 ote2disp.dll
    10/10/2005  06:14 PM           417,792 iweshare.dll
    10/10/2005  06:09 PM           417,792 iketcomm.dll
    10/10/2005  05:51 PM           417,792 lvadperf.dll
    10/10/2005  05:48 PM           417,792 vvdex.dll
    10/10/2005  01:05 PM           417,792 ipetres.dll
    10/10/2005  01:04 PM           417,792 dVdxof.dll
    10/10/2005  12:12 PM           417,792 mxwsock.dll
    10/10/2005  12:11 PM           417,792 mvcsubs.dll
    10/10/2005  12:09 PM           417,792 cvmctl32.dll
    10/10/2005  12:06 PM           417,792 pPdll
    10/09/2005  11:54 PM           417,792 mtvcr70.dll
    10/09/2005  11:45 PM           417,792 dvauth.dll
    10/09/2005  10:34 PM           417,792 nrlanui.dll
    10/09/2005  10:29 PM           417,792 sBfrdm.dll
    10/09/2005  10:24 PM           417,792 byowser.dll
    10/09/2005  10:21 PM           417,792 nqtlogon.dll
    10/09/2005  10:19 PM           417,792 kedno.dll
    10/09/2005  09:36 PM           417,792 lrcwmi.dll
    10/09/2005  09:24 PM           417,792 LJDIS11n.dll
    10/09/2005  09:22 PM           417,792 cortcli.dll
    10/09/2005  09:17 PM           417,792 kjdsf.dll
    10/09/2005  09:15 PM           417,792 wuhisn.dll
    10/09/2005  08:52 PM           417,792 drmasf.dll
    10/09/2005  02:24 PM           417,792 osepro32.dll
    10/08/2005  09:08 PM           417,792 nyxF4.dll
    10/08/2005  09:06 PM           417,792 ibrtprio.dll
    10/08/2005  04:47 PM           417,792 imctl.dll
    10/08/2005  04:34 PM           417,792 dftmsft.dll
    10/08/2005  01:27 PM           417,792 cYbinet.dll
    10/08/2005  12:54 AM           417,792 saarddlg.dll
    10/07/2005  09:29 PM           417,792 guard.tmp
    10/07/2005  09:02 PM           417,792 wihtcpip.dll
    10/07/2005  02:52 PM           417,792 iPsads.dll
    10/07/2005  02:43 PM           417,792 uinpui.dll
    10/06/2005  01:10 PM           417,792 kqlcy.dll
    10/03/2005  09:01 AM           417,792 obbcconf.dll
    10/03/2005  08:54 AM           417,792 mxjdbc10.dll
    10/02/2005  08:50 PM           417,792 mvvcirt.dll
    10/02/2005  08:48 PM           417,792 fqlemgmt.dll
    10/02/2005  08:41 PM           417,792 ddrpsetu.dll
    10/02/2005  08:34 PM           417,792 EvnClass.Dll
    10/02/2005  09:46 AM           417,792 ldwmf11n.dll
    10/01/2005  08:25 PM           417,792 dzauth.dll
    10/01/2005  08:15 PM           417,792 mgoert2.dll
    10/01/2005  07:16 PM           417,792 ckmuid.dll
    10/01/2005  07:12 PM           417,792 mOpistub.dll
    10/01/2005  06:49 PM           417,792 rhnd.dll
    10/01/2005  06:23 PM           417,792 MQCTFP.dll
    10/01/2005  06:14 PM           417,792 cymaddin.dll
    09/23/2005  08:10 AM           417,792 mptime.dll
    09/23/2005  07:04 AM           417,792 dsnlobby.dll
    09/22/2005  11:14 PM           417,792 mrl_qic.dll
    09/22/2005  10:55 PM           417,792 kpdmon.dll
    09/22/2005  06:12 PM           417,792 hvetwiz.dll
    09/22/2005  03:29 PM           417,792 wbsdmoe2.dll
    09/22/2005  03:07 PM           417,792 uitfs.dll
    09/22/2005  02:21 PM           417,792 kjdhe220.dll
    09/22/2005  01:42 PM           417,792 wnavideo.dll
    09/22/2005  01:24 PM           417,792 wevcore.dll
    09/21/2005  09:39 PM           417,792 sXfrdm.dll
    09/21/2005  09:38 PM           417,792 mwsap.dll
    09/08/2005  08:46 AM           401,408 ?hkdsk.exe
    08/30/2005  11:35 AM           401,408 j?vaw.exe
    09/18/2002  04:38 AM            Microsoft
                149 File(s)     62,218,240 bytes
                  4 Dir(s)  44,650,405,888 bytes free
  • RKinner

    2 Intern

    5851 Posts

    314

    0

    Posted February 10th, 2006 00:00

    Looks like it made a few spare copies.  Run the l2mfix again and select option 2. 
     
    Post its log too.
     
    Ron