L2MFIX find log 010406 These are the registry keys present ********************************************************************************** Winlogon/notify: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] “Asynchronous”=dword:00000000 “Impersonate”=dword:00000000 “DllName”=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 “Logoff”=“ChainWlxLogoffEvent” [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] “Asynchronous”=dword:00000000 “Impersonate”=dword:00000000 “DllName”=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\ 6c,00,6c,00,00,00 “Logoff”=“CryptnetWlxLogoffEvent” [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] “DLLName”=“cscdll.dll” “Logon”=“WinlogonLogonEvent” “Logoff”=“WinlogonLogoffEvent” “ScreenSaver”=“WinlogonScreenSaverEvent” “Startup”=“WinlogonStartupEvent” “Shutdown”=“WinlogonShutdownEvent” “StartShell”=“WinlogonStartShellEvent” “Impersonate”=dword:00000000 “Asynchronous”=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MCD] “Asynchronous”=dword:00000000 “DllName”=“C:\WINDOWS\system32\lv0409dqe.dll” “Impersonate”=dword:00000000 “Logon”=“WinLogon” “Logoff”=“WinLogoff” “Shutdown”=“WinShutdown” [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\satmmc] “DllName”=hex(2):73,00,61,00,74,00,6d,00,6d,00,63,00,2e,00,64,00,6c,00,6c,00,\ 00,00 “Startup”=“satmmc” “Impersonate”=dword:00000001 “Asynchronous”=dword:00000001 “MaxWait”=dword:00000001 “M41key”="[34524185323259[DLA WSZYSTKICH]" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] “DLLName”=“wlnotify.dll” “Logon”=“SCardStartCertProp” “Logoff”=“SCardStopCertProp” “Lock”=“SCardSuspendCertProp” “Unlock”=“SCardResumeCertProp” “Enabled”=dword:00000001 “Impersonate”=dword:00000001 “Asynchronous”=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] “Asynchronous”=dword:00000000 “DllName”=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 “Impersonate”=dword:00000000 “StartShell”=“SchedStartShell” “Logoff”=“SchedEventLogOff” [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] “Logoff”=“WLEventLogoff” “Impersonate”=dword:00000000 “Asynchronous”=dword:00000001 “DllName”=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] “DLLName”=“WlNotify.dll” “Lock”=“SensLockEvent” “Logon”=“SensLogonEvent” “Logoff”=“SensLogoffEvent” “Safe”=dword:00000001 “MaxWait”=dword:00000258 “StartScreenSaver”=“SensStartScreenSaverEvent” “StopScreenSaver”=“SensStopScreenSaverEvent” “Startup”=“SensStartupEvent” “Shutdown”=“SensShutdownEvent” “StartShell”=“SensStartShellEvent” “PostShell”=“SensPostShellEvent” “Disconnect”=“SensDisconnectEvent” “Reconnect”=“SensReconnectEvent” “Unlock”=“SensUnlockEvent” “Impersonate”=dword:00000001 “Asynchronous”=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] “Asynchronous”=dword:00000000 “DllName”=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 “Impersonate”=dword:00000000 “Logoff”=“TSEventLogoff” “Logon”=“TSEventLogon” “PostShell”=“TSEventPostShell” “Shutdown”=“TSEventShutdown” “StartShell”=“TSEventStartShell” “Startup”=“TSEventStartup” “MaxWait”=dword:00000258 “Reconnect”=“TSEventReconnect” “Disconnect”=“TSEventDisconnect” [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wancp] “Asynchronous”=dword:00000000 “Impersonate”=dword:00000000 “DLLName”=“wancp.dll” “Logon”=“StartProcessAtWinLogon” “Logoff”=“StopProcessAtWinLogoff” [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] “DLLName”=“wlnotify.dll” “Logon”=“RegisterTicketExpiredNotificationEvent” “Logoff”=“UnregisterTicketExpiredNotificationEvent” “Impersonate”=dword:00000001 “Asynchronous”=dword:00000001 ********************************************************************************** useragent: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] “{5CA22D04-2BE9-83F0-6EDC-1E60CB729E93}”="" ********************************************************************************** Shell Extension key: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved] “{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}”=“iTunes” “{5F327514-6C5E-4d60-8F16-D07FA08A78ED}”=“Auto Update Property Sheet Extension” “{B41DB860-8EE4-11D2-9906-E49FADC173CA}”=“WinRAR shell extension” “{AEEFD283-06F5-46AA-A6CD-14AE9DFDA03E}”="" “{99496818-3323-4FC1-AD15-A878FBF59DDD}”="" “{B7E6D8ED-F762-4091-B462-B1EF0CC392D1}”="" “{ABE58A89-E9B7-4CBA-B7A5-4DD4AC596F88}”="" “{5EAC7821-996E-4DAB-8E18-489881C7DDB8}”="" “{54397E21-F6FB-4CEA-B696-948E662C089F}”="" “{30120BD7-6D3E-4FD3-9C82-590B086C2EC0}”="" “{1FC62D5C-D4B6-4A8B-B6CD-321C672E74E7}”="" “{BF04AA25-A950-40CE-85B5-F6BF0462AED0}”="" “{DB7565E5-F903-45B2-832F-7AF1C6A1ECB8}”="" “{63A34EA6-9C4F-47D3-BB14-A60FD564310E}”="" “{67B20E57-C8D2-452C-B65C-6021EE418AFC}”="" “{C26E38BB-0AA9-4412-AD66-22F309AA82F5}”="" ********************************************************************************** HKEY ROOT CLASSIDS: Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID{AEEFD283-06F5-46AA-A6CD-14AE9DFDA03E}] @="" “IDEx”=“ADDR” [HKEY_CLASSES_ROOT\CLSID{AEEFD283-06F5-46AA-A6CD-14AE9DFDA03E}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID{AEEFD283-06F5-46AA-A6CD-14AE9DFDA03E}\Implemented Categories{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID{AEEFD283-06F5-46AA-A6CD-14AE9DFDA03E}\InprocServer32] @=“C:\WINDOWS\system32\wbashext.dll” “ThreadingModel”=“Apartment” Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID{99496818-3323-4FC1-AD15-A878FBF59DDD}] @="" [HKEY_CLASSES_ROOT\CLSID{99496818-3323-4FC1-AD15-A878FBF59DDD}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID{99496818-3323-4FC1-AD15-A878FBF59DDD}\Implemented Categories{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID{99496818-3323-4FC1-AD15-A878FBF59DDD}\InprocServer32] @=“C:\WINDOWS\system32\czmrepl.dll” “ThreadingModel”=“Apartment” Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID{B7E6D8ED-F762-4091-B462-B1EF0CC392D1}] @="" [HKEY_CLASSES_ROOT\CLSID{B7E6D8ED-F762-4091-B462-B1EF0CC392D1}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID{B7E6D8ED-F762-4091-B462-B1EF0CC392D1}\Implemented Categories{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID{B7E6D8ED-F762-4091-B462-B1EF0CC392D1}\InprocServer32] @=“C:\WINDOWS\system32\GUARAspi.dll” “ThreadingModel”=“Apartment” Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID{ABE58A89-E9B7-4CBA-B7A5-4DD4AC596F88}] @="" [HKEY_CLASSES_ROOT\CLSID{ABE58A89-E9B7-4CBA-B7A5-4DD4AC596F88}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID{ABE58A89-E9B7-4CBA-B7A5-4DD4AC596F88}\Implemented Categories{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID{ABE58A89-E9B7-4CBA-B7A5-4DD4AC596F88}\InprocServer32] @=“C:\WINDOWS\system32\pbtorsvc.dll” “ThreadingModel”=“Apartment” Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID{5EAC7821-996E-4DAB-8E18-489881C7DDB8}] @="" [HKEY_CLASSES_ROOT\CLSID{5EAC7821-996E-4DAB-8E18-489881C7DDB8}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID{5EAC7821-996E-4DAB-8E18-489881C7DDB8}\Implemented Categories{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID{5EAC7821-996E-4DAB-8E18-489881C7DDB8}\InprocServer32] @=“C:\WINDOWS\system32\aomparse.dll” “ThreadingModel”=“Apartment” Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID{54397E21-F6FB-4CEA-B696-948E662C089F}] @="" [HKEY_CLASSES_ROOT\CLSID{54397E21-F6FB-4CEA-B696-948E662C089F}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID{54397E21-F6FB-4CEA-B696-948E662C089F}\Implemented Categories{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID{54397E21-F6FB-4CEA-B696-948E662C089F}\InprocServer32] @=“C:\WINDOWS\system32\dynaddr.dll” “ThreadingModel”=“Apartment” Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID{30120BD7-6D3E-4FD3-9C82-590B086C2EC0}] @="" [HKEY_CLASSES_ROOT\CLSID{30120BD7-6D3E-4FD3-9C82-590B086C2EC0}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID{30120BD7-6D3E-4FD3-9C82-590B086C2EC0}\Implemented Categories{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID{30120BD7-6D3E-4FD3-9C82-590B086C2EC0}\InprocServer32] @=“C:\WINDOWS\system32\ecentprf.dll” “ThreadingModel”=“Apartment” Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID{1FC62D5C-D4B6-4A8B-B6CD-321C672E74E7}] @="" [HKEY_CLASSES_ROOT\CLSID{1FC62D5C-D4B6-4A8B-B6CD-321C672E74E7}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID{1FC62D5C-D4B6-4A8B-B6CD-321C672E74E7}\Implemented Categories{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID{1FC62D5C-D4B6-4A8B-B6CD-321C672E74E7}\InprocServer32] @=“C:\WINDOWS\system32\guard.tmp” “ThreadingModel”=“Apartment” Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID{BF04AA25-A950-40CE-85B5-F6BF0462AED0}] @="" [HKEY_CLASSES_ROOT\CLSID{BF04AA25-A950-40CE-85B5-F6BF0462AED0}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID{BF04AA25-A950-40CE-85B5-F6BF0462AED0}\Implemented Categories{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID{BF04AA25-A950-40CE-85B5-F6BF0462AED0}\InprocServer32] @=“C:\WINDOWS\system32\iHssvcs.dll” “ThreadingModel”=“Apartment” Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID{DB7565E5-F903-45B2-832F-7AF1C6A1ECB8}] @="" [HKEY_CLASSES_ROOT\CLSID{DB7565E5-F903-45B2-832F-7AF1C6A1ECB8}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID{DB7565E5-F903-45B2-832F-7AF1C6A1ECB8}\Implemented Categories{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID{DB7565E5-F903-45B2-832F-7AF1C6A1ECB8}\InprocServer32] @=“C:\WINDOWS\system32\ajfsipc.dll” “ThreadingModel”=“Apartment” Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID{63A34EA6-9C4F-47D3-BB14-A60FD564310E}] @="" [HKEY_CLASSES_ROOT\CLSID{63A34EA6-9C4F-47D3-BB14-A60FD564310E}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID{63A34EA6-9C4F-47D3-BB14-A60FD564310E}\Implemented Categories{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID{63A34EA6-9C4F-47D3-BB14-A60FD564310E}\InprocServer32] @=“C:\WINDOWS\system32\wccsvc.dll” “ThreadingModel”=“Apartment” Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID{67B20E57-C8D2-452C-B65C-6021EE418AFC}] @="" [HKEY_CLASSES_ROOT\CLSID{67B20E57-C8D2-452C-B65C-6021EE418AFC}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID{67B20E57-C8D2-452C-B65C-6021EE418AFC}\Implemented Categories{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID{67B20E57-C8D2-452C-B65C-6021EE418AFC}\InprocServer32] @=“C:\WINDOWS\system32\dqcpsapi.dll” “ThreadingModel”=“Apartment” Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID{C26E38BB-0AA9-4412-AD66-22F309AA82F5}] @="" [HKEY_CLASSES_ROOT\CLSID{C26E38BB-0AA9-4412-AD66-22F309AA82F5}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID{C26E38BB-0AA9-4412-AD66-22F309AA82F5}\Implemented Categories{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID{C26E38BB-0AA9-4412-AD66-22F309AA82F5}\InprocServer32] @=“C:\WINDOWS\system32\vtmredir.dll” “ThreadingModel”=“Apartment” ********************************************************************************** Files Found are not all bad files: Locate .tmp files: ********************************************************************************** Directory Listing of system files: Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 74CA-DE6F Katalog: C:\WINDOWS\System32 2006-02-26 16:03 234˙254 vtmredir.dll 2006-02-26 15:28 235˙667 s4pule791h.dll 2006-02-26 15:28 234˙254 lv0409dqe.dll 2006-01-25 20:20 2005-11-05 13:59 3 plik(˘w) 704˙175 bajt˘w 2 katalog(˘w) 35˙906˙228˙224 bajt˘w wolnych