• Announcements

    • Budfred

      IE 11 copy/paste problem

      It has come to our attention that people using Internet Explorer 11 (IE 11) are having trouble with copy/paste to the forum. If you encounter this problem, using a different browser like Firefox or Chrome seems to get around the problem. We do not know what the problem is, but it seems to be specific to IE 11 and we are hopeful that Microsoft will eventually fix it.
Sign in to follow this  
Followers 0
Gao

Need help with "CWS sp.html hijack" removal

43 posts in this topic

First of all, thanks for reading.

 

Secondly, I really hope I'm not being uncouth in any way with my posting of this problem. Be assured I actually would like help; so, if I break any rules or I haven't tried something I should have I guarantee you it is unintentional. I'm just ignorant.

 

Ive gone over the information on this site and others to try and fix my problem myself with relative success. However, one file seems to keep coming back. While I am sure that NOW I am safe from this annoyance (althhough I do have what I imagine is a seperate problem with java now) I cannot seem to get rid of the "CWS sp.html hijack" file.

 

Iv'e done all kinda stuff, most of which I can't remember at the moment.

Ive updated Windows completely.

I have Norton's Firewall and virus protection, Webroot Spysweeper, Spy Guard and Spyware Blaster, Security Task Manager, Pop-up Stopper, and have just run the CWS Shredder program. While CWS Shredder did find a handful of files that nothing else turned up, Spysweeper keeps finding the afore mentioned file in what I assume is the "registry".

 

Lemme give a little backstory:

 

Initally the only noticable problems were pop-ups and that I kept getting hijacked (a term that was unknown to me until just a few days ago, I have little to no idea what I'm doing if that's not already obvious) to the "about:blank" page. Spysweeper was a little helpful in reseting my homepage but Spy Guard or Spyware Blocker, whichever one it is, really clued me in as to just how often my homepage was being changed. I was going nuts having to click to reset my homepage numerous times every few minutes.

 

Here's the situation now:

 

After doing some research and implementing posted advice, something (more or less) worked. I am no longer getting pop-ups telling me I'm infected and my page is no longer getting jacked. However, whenever I run Spy Sweeper it still finds the "CWS sp.html hijack" file. Upon removal I always get several more alerts from Spy Guard/ware Blocker telling me my homepage has yet again been changed. When I run it again the same thing happens, over and over. This also occured upon finishing up with the CWS Shredder program. These are the only times I ever get them anymore.

 

While it's not doing anything that I can see now and everything is telling its been 86'ed (aside from Spy Sweeper that is) I know it is still there, and what it's doing that I can't see is what's got me bugging out.

 

I appologize for the verbose post but I don't know what else to do and I want any helper(s) to have all the info I can give. I suppose the thing to do now is post the Hijack This log, which I willl do presently. If the startup log is also needed I'm ready to post it as well. I can also guarantee speedy replies to posts; I'm at this contraption nearly all day, every day.

 

I'll be thanking any helpers constantly I'm sure, but allow me to thank some in advance:

thank you.

 

Without further ado, the log...

 

 

Logfile of HijackThis v1.98.0

Scan saved at 12:21:11 PM, on 7/14/2004

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\PROGRA~1\popup\POP-UP~1\dpps2.exe

C:\Program Files\Common Files\Symantec Shared\ccApp.exe

C:\WINDOWS\System32\CTHELPER.EXE

C:\WINDOWS\System32\ctfmon.exe

C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

C:\Program Files\Common Files\Symantec Shared\ccProxy.exe

C:\Program Files\SWGuard\SpywareGuard\sgmain.exe

C:\Program Files\Norton AntiVirus\navapsvc.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\Program Files\Norton AntiVirus\SAVScan.exe

C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

C:\Program Files\SWGuard\SpywareGuard\sgbhp.exe

C:\Program Files\HThis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rd.yahoo.com/customize/ymsgr/defaul...://my.yahoo.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/customize/ymsgr/defaul...//www.yahoo.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://rd.yahoo.com/customize/ymsgr/defaul...//www.yahoo.com

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SWGuard\SpywareGuard\dlprotect.dll

O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll

O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll

O4 - HKLM\..\Run: [Pop-Up Stopper] "C:\PROGRA~1\popup\POP-UP~1\dpps2.exe"

O4 - HKLM\..\Run: [iS CfgWiz] C:\Program Files\Common Files\Symantec Shared\cfgwiz.exe /GUID NIS /CMDLINE "REBOOT"

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe

O4 - HKCU\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe

O4 - HKCU\..\Run: [spySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0

O4 - HKCU\..\Run: [Jet Detection] C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe

O4 - Startup: SpywareGuard.lnk = C:\Program Files\SWGuard\SpywareGuard\sgmain.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll (file missing)

O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll (file missing)

O12 - Plugin for .bmp: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll

O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab

O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200210...meInstaller.exe

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/1755c86b4aec5aad9c04/netzip/RdxIE2.cab

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab

O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) -

Share this post


Link to post
Share on other sites

You have a hijack which can be removed using CWShredder but will be reinstalled by a hidden file. So first we have to find the hidden file and remove it.

 

Copy the contents of the quote box to Notepad.

Name the file Appinit.bat

Save as type All Files

Save on the Desktop.

 

Reg save "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows" windows1.hiv

ren windows1.hiv windows.txt

 

Double click on Appinit.bat

This will create a file on the desktop named windows.txt

 

Double click on the windows.txt file to open and copy and paste the entire contents into a reply to this post. The text will look funny but that is ok.

Share this post


Link to post
Share on other sites

thanks for the reply!

okay sir, i think this is what you want...

 

regf Pugf hbin ¨ÿÿÿnk, œ)úÑ·= ÿÿÿÿ ÿÿÿÿÿÿÿÿ ° x ÿÿÿÿ 0 A R Windows ÿÿÿsk x x Ô „¸ È ¤ ! € ! ? ? Øÿÿÿvk € fùAppInit_DLLsÖ?æG h Ðÿÿÿvk È ÀUDeviceNotSelectedTimeoutðÿÿÿ1 5 Pâ ðÿÿÿ9 0 Ð Ðÿÿÿvk €' zGDIProcessHandleQuota"þàÿÿÿvk 8 °ºSpooler2ðÿÿÿy e s

Ñ_å h ˜ è ` àÿÿÿvk € 5swapdiskÐÿÿÿvk Ø . TransmissionRetryTimeoutàÿÿÿh ˜ è ` € Ð Ðÿÿÿvk €' 0 USERProcessHandleQuotaR

Share this post


Link to post
Share on other sites

I stumbled across this...

maybe it has something to do with where the hidden file is at?

...It's greek to me.

 

<<sp.html seems to be related to a browser redirector . It add the following in the registry res://C:\WINDOWS\system32\gcuxg.dll/sp.html#96676.

The redirector has also been seen using index.html as its filename, and adding the following in the registry:

res://C:\WINDOWS\system32\csmzs.dll/sp.html#96676>>

Share this post


Link to post
Share on other sites

Winter, that is another variant of this infection and it´s not applicable to this case.

Share this post


Link to post
Share on other sites

thanks for the post Winter,but im not so sure that guy has ONLY the same problem as me...

 

I see he does have an "sp.html" issue but i think thats where our similarity ends. I poured over that thread but there is no way for me to tell which solution is the one i should implement, nor can I tell which ones I should NOT implement. knowhudimeen?

Share this post


Link to post
Share on other sites

Gao , I´ve been around all the time.

I just sent you an email, check it. :D

Edited by mmxx66

Share this post


Link to post
Share on other sites

Gao, please download and install the program Registry Lite from here:

 

http://www.resplendence.com/reglite

 

Once it is installed, please double click on the icon that should now be on your desktop. If an icon is not there, then check under programs portion of the Start Menu.

 

Once it is opened, copy and paste the below line, into the address field of Registrar Lite.

 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs

 

And press enter. You will now be presented with new information in the bottom right and left sections and on the right section, the name AppInit_DLLs should be highlighted. Double-click on the AppInit_DLLs entry and copy and paste the text found in the value field in your next reply to this post.

Share this post


Link to post
Share on other sites

Okay, I'll do that now.

I sent the file you wanted to your hotmail account...

that is what you wanted I hope.

Share this post


Link to post
Share on other sites

Okay I did it.

 

However, when I double-click the appinint_dlls in the right side after copy and pasting, tha "data editor" window that pops up displays this stuff:

 

Key Name

Value Name

Catagory

Description

Type

Type #

Size

Value

 

All but the Key and value name, the type and type #, and size are completely empty fields. including the afore mentioned value field you wanted me to copy and paste. it's empty. is that bad?

Share this post


Link to post
Share on other sites

There should be a hidden file there, may be it´s a new variant, please download CWShredder install, run and click fix. and post a new hijack this log.

Share this post


Link to post
Share on other sites

Thank you for your continued help. :D

I already had that installed so it was a easy to run another scan. It still does the same thing I mentioned in my first post however.

Nevertheless, heres my log:

 

Logfile of HijackThis v1.98.0

Scan saved at 12:32:26 PM, on 7/15/2004

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\PROGRA~1\popup\POP-UP~1\dpps2.exe

C:\Program Files\Common Files\Symantec Shared\ccApp.exe

C:\WINDOWS\System32\CTHELPER.EXE

C:\WINDOWS\System32\ctfmon.exe

C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

C:\Program Files\Common Files\Symantec Shared\ccProxy.exe

C:\Program Files\Norton AntiVirus\navapsvc.exe

C:\Program Files\SWGuard\SpywareGuard\sgmain.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\Program Files\Norton AntiVirus\SAVScan.exe

C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

C:\Program Files\SWGuard\SpywareGuard\sgbhp.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

C:\Program Files\HThis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rd.yahoo.com/customize/ymsgr/defaul...://my.yahoo.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/customize/ymsgr/defaul...//www.yahoo.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://rd.yahoo.com/customize/ymsgr/defaul...//www.yahoo.com

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SWGuard\SpywareGuard\dlprotect.dll

O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll

O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll

O4 - HKLM\..\Run: [Pop-Up Stopper] "C:\PROGRA~1\popup\POP-UP~1\dpps2.exe"

O4 - HKLM\..\Run: [iS CfgWiz] C:\Program Files\Common Files\Symantec Shared\cfgwiz.exe /GUID NIS /CMDLINE "REBOOT"

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe

O4 - HKCU\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe

O4 - HKCU\..\Run: [spySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0

O4 - HKCU\..\Run: [Jet Detection] C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe

O4 - Startup: SpywareGuard.lnk = C:\Program Files\SWGuard\SpywareGuard\sgmain.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll (file missing)

O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll (file missing)

O12 - Plugin for .bmp: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll

O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab

O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200210...meInstaller.exe

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/1755c86b4aec5aad9c04/netzip/RdxIE2.cab

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab

O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) -

Share this post


Link to post
Share on other sites

In th e CWShredder click on check for update a couple of times to check if you have the latest version.

Share this post


Link to post
Share on other sites

I thought I had updaded completely but the update text seems odd...

 

Here, I'll paste it in it's entirety

-------------------------------------

 

Current version: CWShredder v1.59.1

Connecting...

Fetching CWShredder update information from merijn.org...

Unable to retrieve CWShredder update information. The server might be unavailable, try again later.

 

Fetching CWShredder update information from spywareinfo.com...

You have the latest version of CWShredder.

----------------------------------------------------

 

is it actually updating or no?

Share this post


Link to post
Share on other sites

Copy the contents of the quote box to Notepad.

Name the file dllsizes.bat

Save as type All Files

Save on the Desktop.

 

dir /o:s c:\windows\system32\*.dll > dllsizes.txt

notepad dllsizes.txt

 

Double click on the file, dllsizes.bat, that is found on your desktop.

 

A notepad will appear with information. paste the contents of that notepad into a reply to this post.

Share this post


Link to post
Share on other sites

Gotchya.

 

Here ya go:

 

Directory of c:\windows\system32

 

07/12/2004 01:46 PM 0 wdmigh.dll

07/12/2004 12:08 PM 0 sqlbokj.dll

07/12/2004 12:26 PM 2 nthst32.dll

07/12/2004 12:26 PM 34 mtjpgb.dll

09/06/2002 01:41 AM 2,272 w95inf16.dll

08/18/2001 08:00 AM 2,560 lz32.dll

08/18/2001 08:00 AM 2,864 winsock.dll

12/12/2002 12:14 AM 3,072 dpnaddr.dll

08/18/2001 08:00 AM 3,072 icmp.dll

08/18/2001 08:00 AM 3,072 rnr20.dll

12/12/2002 12:14 AM 3,072 dpnlobby.dll

08/18/2001 08:00 AM 3,200 wowfax.dll

08/18/2001 08:00 AM 3,584 riched32.dll

08/18/2001 08:00 AM 3,584 iprop.dll

08/18/2001 08:00 AM 3,584 msafd.dll

08/29/2002 04:14 AM 3,584 dsprpres.dll

08/18/2001 08:00 AM 3,584 comcat.dll

08/18/2001 08:00 AM 3,584 mll_hp.dll

08/18/2001 08:00 AM 4,096 rdpcfgex.dll

08/18/2001 08:00 AM 4,096 mtxex.dll

08/18/2001 08:00 AM 4,096 iprtprio.dll

12/12/2002 12:14 AM 4,096 ksuser.dll

08/18/2001 08:00 AM 4,096 sfc.dll

08/29/2002 06:39 AM 4,126 msdxmlc.dll

08/18/2001 08:00 AM 4,208 storage.dll

08/18/2001 08:00 AM 4,608 mssip32.dll

08/18/2001 08:00 AM 4,608 mchgrcoi.dll

08/29/2002 06:41 AM 4,608 msimg32.dll

08/18/2001 08:00 AM 4,608 vjoy.dll

09/06/2002 01:41 AM 4,608 w95inf32.dll

08/18/2001 08:00 AM 4,656 ds16gt.dLL

08/18/2001 08:00 AM 5,120 winnls.dll

08/18/2001 08:00 AM 5,120 kbddv.dll

08/18/2001 08:00 AM 5,120 shell.dll

08/29/2002 06:40 AM 5,120 hccoin.dll

08/18/2001 08:00 AM 5,120 msidle.dll

08/18/2001 08:00 AM 5,632 kbdblr.dll

08/18/2001 08:00 AM 5,632 kbdro.dll

08/18/2001 08:00 AM 5,632 mll_qic.dll

08/18/2001 08:00 AM 5,632 kbdpl1.dll

08/18/2001 08:00 AM 5,632 wmi.dll

08/18/2001 08:00 AM 5,632 kbdbu.dll

10/17/2002 12:13 AM 5,632 pndx5032.dll

08/18/2001 08:00 AM 5,632 kbdru.dll

08/18/2001 08:00 AM 5,632 softpub.dll

08/18/2001 08:00 AM 5,632 kbdus.dll

08/18/2001 08:00 AM 5,632 kbdmon.dll

08/18/2001 08:00 AM 5,632 kbduzb.dll

08/18/2001 08:00 AM 5,632 kbdycc.dll

08/18/2001 08:00 AM 5,632 kbduk.dll

08/18/2001 08:00 AM 5,632 kbdlt1.dll

08/18/2001 08:00 AM 5,632 kbdlt.dll

08/18/2001 08:00 AM 5,632 kbdazel.dll

08/18/2001 08:00 AM 5,632 kbdkyr.dll

08/18/2001 08:00 AM 5,632 kbdkaz.dll

08/18/2001 08:00 AM 5,632 kbdru1.dll

08/18/2001 08:00 AM 5,632 kbdaze.dll

08/18/2001 08:00 AM 5,632 kbdit142.dll

08/18/2001 08:00 AM 5,632 kbdit.dll

08/18/2001 08:00 AM 5,632 kbdir.dll

08/18/2001 08:00 AM 5,632 kbdhu1.dll

08/18/2001 08:00 AM 5,632 kbdur.dll

08/18/2001 08:00 AM 5,632 security.dll

08/18/2001 08:00 AM 5,632 tapiperf.dll

08/18/2001 08:00 AM 5,632 kbdgae.dll

08/18/2001 08:00 AM 5,632 skdll.dll

08/18/2001 08:00 AM 5,632 kbdtat.dll

08/18/2001 08:00 AM 5,632 kbdhe319.dll

08/18/2001 08:00 AM 5,632 kbdhe220.dll

08/18/2001 08:00 AM 5,632 kbdhe.dll

08/18/2001 08:00 AM 6,144 kbdgr1.dll

08/18/2001 08:00 AM 6,144 kbdgr.dll

08/18/2001 08:00 AM 6,144 kbdgkl.dll

08/18/2001 08:00 AM 6,144 kbdfr.dll

08/18/2001 08:00 AM 6,144 kbdhela2.dll

08/18/2001 08:00 AM 6,144 kbdtuf.dll

08/18/2001 08:00 AM 6,144 kbdfo.dll

08/18/2001 08:00 AM 6,144 svcpack.dll

08/18/2001 08:00 AM 6,144 kbdfi.dll

08/29/2002 06:41 AM 6,144 sensapi.dll

08/18/2001 08:00 AM 6,144 rasadhlp.dll

08/18/2001 08:00 AM 6,144 kbdic.dll

08/18/2001 08:00 AM 6,144 kbdfc.dll

08/18/2001 08:00 AM 6,144 kbdest.dll

08/18/2001 08:00 AM 6,144 kbdes.dll

08/18/2001 08:00 AM 6,144 kbdbe.dll

08/18/2001 08:00 AM 6,144 kbdda.dll

08/18/2001 08:00 AM 6,144 kbdusl.dll

08/18/2001 08:00 AM 6,144 kbdbene.dll

08/18/2001 08:00 AM 6,144 kbdsw.dll

08/18/2001 08:00 AM 6,144 kbdpo.dll

08/18/2001 08:00 AM 6,144 kbdtuq.dll

08/18/2001 08:00 AM 6,144 kbdbr.dll

08/18/2001 08:00 AM 6,144 kbdusx.dll

08/18/2001 08:00 AM 6,144 kbdlv.dll

08/18/2001 08:00 AM 6,144 kbdlv1.dll

08/18/2001 08:00 AM 6,144 kbdmac.dll

08/18/2001 08:00 AM 6,144 kbdca.dll

08/18/2001 08:00 AM 6,144 kbdsp.dll

08/18/2001 08:00 AM 6,144 kbdno.dll

08/18/2001 08:00 AM 6,144 kbdne.dll

08/18/2001 08:00 AM 6,144 kbdusr.dll

08/18/2001 08:00 AM 6,144 kbdsf.dll

08/18/2001 08:00 AM 6,656 kbdcr.dll

08/18/2001 08:00 AM 6,656 kbdhela3.dll

12/11/2002 03:16 PM 6,656 laprxy.dll

08/18/2001 08:00 AM 6,656 routetab.dll

08/18/2001 08:00 AM 6,656 kbdpl.dll

08/18/2001 08:00 AM 6,656 kbdcz1.dll

08/29/2002 06:40 AM 6,656 batt.dll

08/18/2001 08:00 AM 6,656 KBDAL.DLL

08/18/2001 08:00 AM 6,656 kbdcz2.dll

08/18/2001 08:00 AM 6,656 kbdsl1.dll

08/18/2001 08:00 AM 6,656 kbdla.dll

08/18/2001 08:00 AM 6,656 ntlsapi.dll

08/18/2001 08:00 AM 6,656 kbdycl.dll

10/17/2002 12:13 AM 6,656 pndx5016.dll

08/18/2001 08:00 AM 6,656 kbdsl.dll

08/18/2001 08:00 AM 6,656 kbdhu.dll

03/17/2004 02:33 PM 6,656 spmsg.dll

08/18/2001 08:00 AM 6,656 kbdsg.dll

08/18/2001 08:00 AM 7,040 kdcom.dll

08/29/2002 04:05 AM 7,040 kd1394.dll

08/18/2001 08:00 AM 7,168 kbdnec.dll

07/01/2004 06:08 PM 7,168 bitsprx3.dll

08/18/2001 08:00 AM 7,168 wshnetbs.dll

08/18/2001 08:00 AM 7,168 mscat32.dll

08/18/2001 08:00 AM 7,168 kbdcz.dll

08/18/2001 08:00 AM 7,168 msr2cenu.dll

08/18/2001 08:00 AM 7,680 vcdex.dll

08/18/2001 08:00 AM 7,680 mciole32.dll

07/01/2004 06:08 PM 7,680 bitsprx2.dll

12/11/2002 03:16 PM 7,680 asferror.dll

08/18/2001 08:00 AM 7,680 kbdcan.dll

08/18/2001 08:00 AM 7,680 mll_mtf.dll

08/18/2001 08:00 AM 7,680 dciman32.dll

08/18/2001 08:00 AM 7,680 ncxpnt.dll

12/12/2002 12:14 AM 8,192 d3d8thk.dll

08/18/2001 08:00 AM 8,192 mag_hook.dll

08/18/2001 08:00 AM 8,192 kbdhept.dll

08/18/2001 08:00 AM 8,192 psnppagn.dll

08/18/2001 08:00 AM 8,192 tsbyuv.dll

08/18/2001 08:00 AM 8,192 qosname.dll

08/18/2001 08:00 AM 8,192 streamci.dll

08/18/2001 08:00 AM 8,192 igmpagnt.dll

08/18/2001 08:00 AM 8,192 mciole16.dll

08/18/2001 08:00 AM 8,456 tsddd.dll

12/20/1999 01:16 PM 8,704 npwmsdrm.dll

08/18/2001 08:00 AM 8,704 lprhelp.dll

08/29/2002 06:40 AM 8,832 framebuf.dll

08/18/2001 08:00 AM 9,008 ver.dll

08/29/2002 06:41 AM 9,216 wuauserv.dll

08/18/2001 08:00 AM 9,216 lprmonui.dll

08/18/2001 08:00 AM 9,216 wshatm.dll

08/18/2001 08:00 AM 9,216 wifeman.dll

08/29/2002 06:40 AM 9,216 icaapi.dll

08/18/2001 08:00 AM 9,216 winfax.dll

08/18/2001 08:00 AM 9,344 vga.dll

08/18/2001 08:00 AM 9,728 gpkrsrc.dll

08/18/2001 08:00 AM 9,728 xolehlp.dll

08/18/2001 08:00 AM 9,728 rsvpperf.dll

08/17/2001 10:36 PM 9,759 HSF_INST.dll

08/18/2001 08:00 AM 9,936 lzexpand.dll

08/18/2001 08:00 AM 10,112 modex.dll

08/17/1998 05:21 AM 10,240 vidx16.dll

08/18/2001 08:00 AM 10,240 WshRm.dll

08/18/2001 08:00 AM 10,240 panmap.dll

08/18/2001 08:00 AM 10,240 mcd32.dll

08/29/2002 06:41 AM 10,240 localui.dll

08/29/2002 06:41 AM 10,240 msrle32.dll

08/18/2001 08:00 AM 10,496 mcdsrv32.dll

08/18/2001 08:00 AM 10,752 clb.dll

08/18/2001 08:00 AM 10,752 netrap.dll

08/18/2001 08:00 AM 10,752 pschdprf.dll

08/18/2001 08:00 AM 11,264 atrace.dll

08/18/2001 08:00 AM 11,776 rasctrs.dll

08/18/2001 08:00 AM 11,776 wshisn.dll

08/18/2001 08:00 AM 11,776 drprov.dll

08/29/2002 06:41 AM 11,776 sigtab.dll

06/22/2004 08:45 PM 12,067 SIntf16.dll

08/18/2001 08:00 AM 12,288 lmhsvc.dll

08/18/2001 08:00 AM 12,288 nmevtmsg.dll

08/18/2001 08:00 AM 12,288 cmcfg32.dll

08/18/2001 08:00 AM 12,288 jsproxy.dll

08/29/2002 06:39 AM 12,288 odbcp32r.dll

08/18/2001 08:00 AM 12,288 mmdrv.dll

08/18/2001 08:00 AM 12,288 bootvid.dll

08/18/2001 08:00 AM 12,288 perfts.dll

08/29/2002 06:39 AM 12,288 mscpx32r.dll

08/18/2001 08:00 AM 12,800 pjlmon.dll

08/18/2001 08:00 AM 12,800 rasser.dll

08/18/2001 08:00 AM 12,800 mcastmib.dll

08/18/2001 08:00 AM 12,800 mgmtapi.dll

08/18/2001 08:00 AM 13,312 win87em.dll

08/29/2002 06:41 AM 13,312 wship6.dll

08/18/2001 08:00 AM 13,312 irclass.dll

08/18/2001 08:00 AM 13,312 verifier.dll

08/18/2001 08:00 AM 13,312 ntvdmd.dll

08/18/2001 08:00 AM 13,312 atkctrs.dll

08/18/2001 08:00 AM 13,312 tcpmib.dll

08/18/2001 08:00 AM 13,312 umdmxfrm.dll

12/12/2002 12:14 AM 13,312 msdmo.dll

08/18/2001 08:00 AM 13,312 msswch.dll

08/18/2001 08:00 AM 13,824 senscfg.dll

08/18/2001 08:00 AM 13,824 uniplat.dll

08/18/2001 08:00 AM 13,824 sisbkup.dll

08/18/2001 08:00 AM 13,824 wowfaxui.dll

08/29/2002 06:41 AM 13,824 rassapi.dll

08/18/2001 08:00 AM 13,888 toolhelp.dll

10/15/1996 09:53 AM 14,160 HLINKPRX.DLL

08/18/2001 08:00 AM 14,336 cmpbk32.dll

08/18/2001 08:00 AM 14,336 serialui.dll

08/18/2001 08:00 AM 14,336 inetppui.dll

08/18/2001 08:00 AM 14,336 ntlanui2.dll

08/29/2002 06:40 AM 14,366 asfsipc.dll

02/23/1996 02:34 PM 14,629 Declw.dll

08/18/2001 08:00 AM 14,848 winrnr.dll

08/18/2001 08:00 AM 14,848 powrprof.dll

08/29/2002 06:40 AM 14,848 cdm.dll

08/18/2001 08:00 AM 14,848 bidispl.dll

08/18/2001 08:00 AM 14,848 msidntld.dll

08/18/2001 08:00 AM 14,848 usbmon.dll

08/18/2001 08:00 AM 14,848 hnetmon.dll

08/18/2001 08:00 AM 14,848 slbrccsp.dll

08/29/2002 06:41 AM 14,848 rdpsnd.dll

08/18/2001 08:00 AM 14,848 serwvdrv.dll

08/18/2001 08:00 AM 14,877 corpol.dll

08/18/2001 08:00 AM 15,360 nddeapi.dll

08/18/2001 08:00 AM 15,360 tsd32.dll

08/18/2001 08:00 AM 15,360 linkinfo.dll

08/18/2001 08:00 AM 15,872 alrsvc.dll

08/18/2001 08:00 AM 15,872 sysinv.dll

08/18/2001 08:00 AM 15,872 cdmodem.dll

08/18/2001 08:00 AM 16,384 prflbmsg.dll

08/18/2001 08:00 AM 16,384 avmeter.dll

08/18/2001 08:00 AM 16,384 fmifs.dll

08/18/2001 08:00 AM 16,384 icfgnt5.dll

08/29/2002 06:41 AM 16,384 nddenb32.dll

08/29/2002 06:41 AM 16,384 odbc32gt.dll

08/18/2001 08:00 AM 16,384 version.dll

08/18/2001 08:00 AM 16,384 deskadp.dll

08/29/2002 06:40 AM 16,384 ds32gt.dll

08/18/2001 08:00 AM 16,384 mmfutil.dll

08/18/2001 08:00 AM 16,896 oleaccrc.dll

02/17/2003 10:16 AM 16,896 msyuv.dll

08/29/2002 06:41 AM 16,896 snmpapi.dll

08/18/2001 08:00 AM 16,896 deskmon.dll

08/18/2001 08:00 AM 16,896 vss_ps.dll

08/18/2001 08:00 AM 16,896 perfnet.dll

08/18/2001 08:00 AM 16,896 cfgmgr32.dll

06/22/2004 08:45 PM 17,212 SIntf32.dll

08/18/2001 08:00 AM 17,408 mcicda.dll

08/29/2002 06:41 AM 17,408 wtsapi32.dll

08/18/2001 08:00 AM 17,408 esentprf.dll

08/29/2002 06:41 AM 17,408 psapi.dll

08/18/2001 08:00 AM 17,408 wshtcpip.dll

07/01/2004 06:08 PM 17,408 qmgrprxy.dll

07/12/2004 12:26 PM 17,637 mtjpgh.dll

08/18/2001 08:00 AM 17,920 ureg.dll

08/18/2001 08:00 AM 17,920 midimap.dll

08/18/2001 08:00 AM 17,920 iaspolcy.dll

08/18/2001 08:00 AM 18,176 vga64k.dll

08/18/2001 08:00 AM 18,432 feclient.dll

12/12/2002 12:14 AM 18,432 dswave.dll

08/18/2001 08:00 AM 18,432 deskperf.dll

08/18/2001 08:00 AM 18,432 dmintf.dll

08/18/2001 08:00 AM 18,432 sclgntfy.dll

08/18/2001 08:00 AM 18,432 rsmps.dll

08/18/2001 08:00 AM 18,944 wmiprop.dll

08/18/2001 08:00 AM 18,944 mimefilt.dll

08/18/2001 08:00 AM 18,944 winstrm.dll

12/12/2002 12:14 AM 18,944 encapi.dll

08/18/2001 08:00 AM 18,944 lpk.dll

08/18/2001 08:00 AM 18,944 ws2help.dll

08/18/2001 08:00 AM 19,200 tapi.dll

08/18/2001 08:00 AM 19,456 dmocx.dll

08/29/2002 06:40 AM 19,456 ersvc.dll

08/29/2002 06:41 AM 19,456 licmgr10.dll

12/12/2002 12:14 AM 19,968 dpvacm.dll

12/11/2002 03:09 PM 20,480 wmpui.dll

08/17/2001 10:36 PM 20,480 OVComC.dll

08/29/2002 06:40 AM 20,480 dbmsadsn.dll

08/18/2001 08:00 AM 20,480 mtxdm.dll

08/18/2001 08:00 AM 20,480 msorc32r.dll

12/11/2002 03:09 PM 20,480 wmpcd.dll

12/11/2002 03:09 PM 20,480 wmpcore.dll

08/18/2001 08:00 AM 20,535 vfpodbc.dll

08/18/2001 08:00 AM 20,553 odpdx32.dll

08/18/2001 08:00 AM 20,553 odexl32.dll

08/18/2001 08:00 AM 20,553 odfox32.dll

08/18/2001 08:00 AM 20,554 oddbse32.dll

08/18/2001 08:00 AM 20,554 odtext32.dll

08/18/2001 08:00 AM 20,992 ipxwan.dll

08/18/2001 08:00 AM 20,992 mciseq.dll

08/18/2001 08:00 AM 20,992 seclogon.dll

08/18/2001 08:00 AM 20,992 mfcsubs.dll

02/28/2003 06:26 PM 21,264 msjdbc10.dll

08/18/2001 08:00 AM 21,504 dmserver.dll

08/18/2001 08:00 AM 21,504 ipxrip.dll

08/18/2001 08:00 AM 21,504 wsock32.dll

06/22/2004 08:45 PM 21,840 SIntfNT.dll

12/12/2002 12:14 AM 22,016 dpmodemx.dll

08/18/2001 08:00 AM 22,016 davclnt.dll

08/18/2001 08:00 AM 22,016 olesvr32.dll

08/18/2001 08:00 AM 22,016 w32topl.dll

08/18/2001 08:00 AM 22,016 mciwave.dll

08/18/2001 08:00 AM 22,016 rpcns4.dll

08/29/2002 06:41 AM 22,016 udhisapi.dll

08/29/2002 06:41 AM 22,528 mslbui.dll

08/29/2002 06:41 AM 22,528 slayerxp.dll

08/18/2001 08:00 AM 22,528 rasmxs.dll

08/29/2002 06:41 AM 22,528 shfolder.dll

08/18/2001 08:00 AM 22,528 hid.dll

08/18/2001 08:00 AM 23,040 perfos.dll

08/18/2001 08:00 AM 23,040 shscrap.dll

08/18/2001 08:00 AM 23,040 iernonce.dll

08/18/2001 08:00 AM 23,552 rasrad.dll

11/26/2002 07:03 PM 23,552 wmdmps.dll

08/29/2002 06:41 AM 23,552 wzcsapi.dll

08/18/2001 08:00 AM 23,552 perfdisk.dll

08/18/2001 08:00 AM 23,552 iasacct.dll

08/18/2001 08:00 AM 23,552 sfmapi.dll

08/18/2001 08:00 AM 23,552 rsvpmsg.dll

08/18/2001 08:00 AM 24,064 vdmdbg.dll

12/12/2002 12:14 AM 24,064 ddrawex.dll

08/18/2001 08:00 AM 24,064 olesvr.dll

10/27/2003 08:13 PM 24,576 odbcbcp.dll

08/29/2002 03:36 AM 24,576 dbmsvinn.dll

08/29/2002 06:41 AM 24,576 nmmkcert.dll

08/29/2002 03:36 AM 24,576 dbmsrpcn.dll

12/18/2002 08:31 AM 24,576 msxml3a.dll

08/18/2001 08:00 AM 24,603 sqlwid.dll

08/18/2001 08:00 AM 24,661 spxcoins.dll

08/18/2001 08:00 AM 25,088 mtxlegih.dll

08/29/2002 06:40 AM 25,600 dfsshlex.dll

08/18/2001 08:00 AM 25,600 comaddin.dll

08/18/2001 08:00 AM 25,600 pstorsvc.dll

08/18/2001 08:00 AM 25,600 aaaamon.dll

08/18/2001 08:00 AM 25,600 winipsec.dll

08/18/2001 08:00 AM 25,600 utildll.dll

08/18/2001 08:00 AM 25,600 msvidc32.dll

08/18/2001 08:00 AM 26,112 adptif.dll

08/18/2001 08:00 AM 26,224 odbc16gt.dll

10/17/1999 07:01 PM 26,384 FM20ENU.DLL

08/18/2001 08:00 AM 26,624 cnvfat.dll

08/18/2001 08:00 AM 26,624 msxmlr.dll

08/18/2001 08:00 AM 26,624 safrdm.dll

08/18/2001 08:00 AM 26,624 scredir.dll

07/13/1995 02:01 AM 26,768 ctl3d.dll

08/18/2001 08:00 AM 27,136 batmeter.dll

11/26/2002 07:03 PM 27,136 wmdmlog.dll

08/18/2001 08:00 AM 27,136 ctl3d32.dll

08/18/2001 08:00 AM 27,136 mspatcha.dll

08/18/2001 08:00 AM 27,136 atmlib.dll

08/18/2001 08:00 AM 27,136 sendcmsg.dll

12/12/2002 12:14 AM 27,136 dmband.dll

08/29/2002 06:41 AM 27,136 ssdpapi.dll

08/18/2001 08:00 AM 27,200 ctl3dv2.dll

08/18/2001 08:00 AM 27,648 ccfgnt.dll

08/29/2002 04:08 AM 27,648 pidgen.dll

08/18/2001 08:00 AM 28,672 profmap.dll

01/10/2002 01:40 AM 28,672 EA02.dll

08/29/2002 03:34 AM 28,672 dbnmpntw.dll

07/19/2002 12:07 PM 28,672 CTSPKHLP.DLL

08/18/2001 08:00 AM 28,672 isrdbg32.dll

01/09/2002 01:40 AM 28,672 EA01.dll

08/18/2001 08:00 AM 28,721 wshcon.dll

08/18/2001 08:00 AM 28,746 msrecr40.dll

08/29/2002 06:40 AM 29,184 csrsrv.dll

08/18/2001 08:00 AM 29,184 cryptdll.dll

08/18/2001 08:00 AM 29,696 rtipxmib.dll

01/15/1997 04:00 PM 29,696 VB5StKit.dll

08/18/2001 08:00 AM 30,160 compobj.dll

08/29/2002 06:40 AM 30,208 imgutil.dll

08/18/2001 08:00 AM 30,720 iologmsg.dll

08/18/2001 08:00 AM 30,720 plustab.dll

03/16/2004 02:44 PM 30,749 vbajet32.dll

08/18/2001 08:00 AM 31,232 traffic.dll

08/18/2001 08:00 AM 31,232 inetmib1.dll

08/29/2002 06:41 AM 31,744 pid.dll

08/29/2002 06:41 AM 32,256 mnmdd.dll

03/24/2004 10:04 AM 32,256 nvcodins.dll

02/22/1996 12:09 PM 32,256 Decln.dll

08/18/2001 08:00 AM 32,256 perfproc.dll

10/21/2003 07:06 PM 32,256 msgsvc.dll

08/18/2001 08:00 AM 32,256 iashlpr.dll

08/29/2002 06:41 AM 32,256 umandlg.dll

03/24/2004 10:04 AM 32,256 nvcod.dll

01/22/2001 03:25 AM 32,768 ATHPRXY.DLL

08/18/2001 08:00 AM 32,768 cnetcfg.dll

03/24/2003 09:00 AM 32,768 dpnhpast.dll

08/29/2002 06:40 AM 32,768 cfgbkend.dll

08/18/2001 08:00 AM 32,816 commdlg.dll

08/18/2001 08:00 AM 33,040 dplay.dll

08/18/2001 08:00 AM 33,280 racpldlg.dll

12/12/2002 12:14 AM 33,280 dmloader.dll

08/18/2001 08:00 AM 33,280 eventcls.dll

08/18/2001 08:00 AM 33,280 msobjs.dll

12/12/2002 12:14 AM 34,304 mciqtz32.dll

08/18/2001 08:00 AM 34,304 olecnv32.dll

05/22/2003 10:01 PM 34,304 PNGFILT.DLL

08/23/2001 05:00 AM 34,816 d3dpmesh.dll

08/18/2001 08:00 AM 34,816 atmpvcno.dll

08/29/2002 06:40 AM 35,328 dfrgsnap.dll

09/21/2000 01:47 AM 35,328 picn20.dll

08/18/2001 08:00 AM 35,328 pifmgr.dll

08/18/2001 08:00 AM 35,840 jgmd400.dll

08/18/2001 08:00 AM 35,840 narrhook.dll

08/18/2001 08:00 AM 35,840 mssign32.dll

08/18/2001 08:00 AM 36,352 cmutil.dll

08/29/2002 06:41 AM 36,352 sens.dll

08/29/2002 06:41 AM 36,352 rshx32.dll

07/19/2002 11:54 AM 36,864 CTEMUPIA.DLL

08/17/2001 03:35 PM 36,864 sfman32.dll

03/24/2004 10:04 AM 36,864 nvwddi.dll

08/18/2001 08:00 AM 36,864 ntsdexts.dll

09/11/2001 08:21 AM 36,864 CTEMUPIADEFAULT.DLL

12/18/2002 08:31 AM 36,864 xmlparse.dll

08/18/2001 08:00 AM 36,864 ntmsevt.dll

03/29/2004 09:48 PM 36,864 mf3216.dll

08/18/2001 08:00 AM 36,864 mscpxl32.dLL

08/29/2002 06:40 AM 36,922 imeshare.dll

08/18/2001 08:00 AM 37,376 perfctrs.dll

08/18/2001 08:00 AM 37,888 pstorec.dll

01/10/2003 02:43 PM 37,888 hhsetup.dll

08/18/2001 08:00 AM 37,916 msxml2r.dll

09/02/1998 04:28 AM 38,160 LMRTREND.dll

08/29/2002 06:41 AM 38,400 ntlanman.dll

08/29/2002 06:41 AM 38,400 ntmsapi.dll

07/05/2000 05:16 PM 38,400 clsNOL22.dll

08/29/2002 06:40 AM 38,912 audiosrv.dll

08/29/2002 06:41 AM 38,912 wsnmp32.dll

08/18/2001 08:00 AM 39,424 safrcdlg.dll

08/18/2001 08:00 AM 39,424 ddeml.dll

08/18/2001 08:00 AM 39,744 ole2.dll

08/18/2001 08:00 AM 39,936 rtutils.dll

08/18/2001 08:00 AM 39,936 ipxrtmgr.dll

08/18/2001 08:00 AM 39,936 msisip.dll

08/18/2001 08:00 AM 39,936 htui.dll

08/18/2001 08:00 AM 40,448 webhits.dll

08/18/2001 08:00 AM 40,448 tcpmon.dll

07/06/1999 03:13 PM 40,960 EAX.DLL

08/18/2001 08:00 AM 40,960 safrslv.dll

08/18/2001 08:00 AM 40,960 tcpmonui.dll

08/18/2001 08:00 AM 41,019 usrsvpia.dll

04/30/2002 08:02 PM 41,068 ActPanel.dll

08/18/2001 08:00 AM 41,472 iasads.dll

08/18/2001 08:00 AM 41,984 msports.dll

08/17/2001 10:36 PM 41,984 OVUI2RC.dll

08/29/2002 06:41 AM 42,496 ncobjapi.dll

12/20/2001 09:00 AM 42,496 AudCtrl.dll

08/18/2001 08:00 AM 42,496 jgpl400.dll

08/18/2001 08:00 AM 42,768 dpwsock.dll

08/29/2002 06:41 AM 43,008 ssdpsrv.dll

06/24/2004 06:22 PM 43,520 CmdLineExt03.dll

08/23/2001 05:00 AM 44,032 dimap.dll

08/29/2002 06:40 AM 44,032 basesrv.dll

08/18/2001 08:00 AM 44,032 msxml3r.dll

03/03/2003 04:57 PM 44,032 MSIDENT.DLL

08/18/2001 08:00 AM 44,032 dnsrslvr.dll

08/29/2002 06:41 AM 44,032 regapi.dll

08/18/2001 08:00 AM 44,544 jgaw400.dll

08/17/2001 10:36 PM 44,544 OVUI2.dll

08/18/2001 08:00 AM 44,544 hticons.dll

08/18/2001 08:00 AM 45,056 camocx.dll

08/18/2001 08:00 AM 45,056 msprivs.dll

08/18/2001 08:00 AM 45,083 dispex.dll

08/18/2001 08:00 AM 45,116 usrvoica.dll

08/29/2002 06:40 AM 45,568 docprop2.dll

08/18/2001 08:00 AM 45,568 cnbjmon.dll

08/18/2001 08:00 AM 45,568 jgsd400.dll

08/18/2001 08:00 AM 45,568 iyuv_32.dll

03/24/2004 10:04 AM 46,080 nvmctray.dll

08/18/2001 08:00 AM 46,080 docprop.dll

08/18/2001 08:00 AM 46,592 wdigest.dll

08/18/2001 08:00 AM 46,592 pmspl.dll

08/18/2001 08:00 AM 46,592 mmcshext.dll

08/18/2001 08:00 AM 47,104 mspmspsv.dll

08/18/2001 08:00 AM 47,104 mprui.dll

08/18/2001 08:00 AM 47,104 dssec.dll

02/17/2003 10:16 AM 47,104 wstdecod.dll

08/23/2001 05:00 AM 47,616 d3dxof.dll

10/11/2002 03:08 PM 47,616 INETRES.DLL

08/18/2001 08:00 AM 47,952 jobexec.dll

08/29/2002 06:41 AM 48,128 winsta.dll

08/29/2002 06:41 AM 48,640 vdmredir.dll

08/18/2001 08:00 AM 48,640 cryptext.dll

08/29/2002 06:40 AM 49,152 browser.dll

10/10/2000 01:00 AM 49,152 DartObjects.dll

08/18/2001 08:00 AM 49,152 mprdim.dll

08/29/2002 06:41 AM 49,152 npptools.dll

08/29/2002 06:40 AM 49,152 eventlog.dll

08/18/2001 08:00 AM 49,179 sqlwoa.dll

08/18/2001 08:00 AM 49,209 usrv80a.dll

08/18/2001 08:00 AM 49,211 usrsdpia.dll

08/18/2001 08:00 AM 49,211 usrvpa.dll

08/29/2002 06:41 AM 49,664 vfwwdm32.dll

08/29/2002 06:40 AM 49,664 ixsso.dll

08/18/2001 08:00 AM 50,176 loghours.dll

08/18/2001 08:00 AM 50,176 mdhcp.dll

08/18/2001 08:00 AM 50,688 dmutil.dll

08/18/2001 08:00 AM 50,688 msvcirt.dll

08/29/2002 06:39 AM 51,200 wmerrenu.dll

08/18/2001 08:00 AM 51,200 authz.dll

08/18/2001 08:00 AM 51,200 dfrgres.dll

08/18/2001 08:00 AM 51,456 vga256.dll

08/18/2001 08:00 AM 51,712 regsvc.dll

03/29/2004 09:48 PM 51,712 msasn1.dll

08/18/2001 08:00 AM 51,712 synceng.dll

08/18/2001 08:00 AM 51,712 dataclen.dll

08/18/2001 08:00 AM 52,224 tsappcmp.dll

11/26/2002 07:03 PM 52,224 mspmsnsv.dll

08/29/2002 06:41 AM 52,224 secur32.dll

08/18/2001 08:00 AM 53,248 servdeps.dll

08/18/2001 08:00 AM 53,248 sendmail.dll

05/30/2003 09:00 AM 53,248 devenum.dll

08/18/2001 08:00 AM 53,248 cryptnet.dll

07/19/2002 12:07 PM 53,248 Ac3api.dll

06/17/1998 06:08 PM 53,248 MFC42ENU.DLL

08/18/2001 08:00 AM 53,279 odbcji32.dll

01/10/2004 07:36 AM 53,279 msjter40.dll

08/18/2001 08:00 AM 53,305 usrlbva.dll

08/18/2001 08:00 AM 53,520 dpserial.dll

03/25/2003 04:40 PM 53,760 cryptsvc.dll

08/29/2002 06:41 AM 54,272 rastapi.dll

08/18/2001 08:00 AM 54,272 stclient.dll

08/29/2002 06:40 AM 54,272 clusapi.dll

08/29/2002 06:41 AM 54,784 samlib.dll

01/05/2002 06:38 AM 54,784 msvci70.dll

10/20/1998 04:05 PM 54,784 Inetwh32.dll

08/18/2001 08:00 AM 54,784 icmui.dll

08/18/2001 08:00 AM 54,784 msdtclog.dll

08/18/2001 08:00 AM 54,784 resutils.dll

08/29/2002 06:40 AM 55,296 digest.dll

08/29/2002 06:41 AM 55,808 rasman.dll

08/18/2001 08:00 AM 55,808 mpr.dll

08/29/2002 06:41 AM 56,320 remotepg.dll

08/29/2002 06:39 AM 56,320 mshtmler.dll

08/18/2001 08:00 AM 56,320 miglibnt.dll

08/29/2002 06:41 AM 56,832 wzcdlg.dll

08/18/2001 08:00 AM 57,344 admparse.dll

03/13/2002 04:25 PM 57,344 CTAGENT.DLL

08/29/2002 06:41 AM 57,856 licwmi.dll

08/18/2001 08:00 AM 57,856 ntlanui.dll

08/18/2001 08:00 AM 57,856 scripto.dll

08/29/2002 06:41 AM 57,856 raschap.dll

12/12/2002 12:14 AM 58,368 dmcompos.dll

08/29/2002 06:41 AM 58,880 pautoenr.dll

05/31/2002 04:40 PM 59,112 SymStore.dll

08/18/2001 08:00 AM 59,392 iassvcs.dll

08/29/2002 06:40 AM 59,392 iesetup.dll

08/29/2002 06:40 AM 59,392 6to4svc.dll

08/29/2002 06:40 AM 59,904 cabinet.dll

08/29/2002 06:41 AM 60,416 shimeng.dll

08/18/2001 08:00 AM 60,416 msratelc.dll

08/18/2001 08:00 AM 60,928 ocmanage.dll

08/18/2001 08:00 AM 61,168 msacm.dll

08/29/2002 06:41 AM 61,440 odbccu32.dll

08/18/2001 08:00 AM 61,440 icwphbk.dll

08/29/2002 06:41 AM 61,440 odbccr32.dll

10/27/2003 08:12 PM 61,440 DBnetlib.dll

08/18/2001 08:00 AM 61,500 usrcntra.dll

08/18/2001 08:00 AM 61,952 dpnwsock.dll

08/29/2002 06:41 AM 61,952 webclnt.dll

08/18/2001 08:00 AM 61,952 osuninst.dll

08/29/2002 06:41 AM 61,952 sti.dll

08/18/2001 08:00 AM 62,464 iasnap.dll

08/29/2002 06:40 AM 62,464 adsmsext.dll

08/18/2001 08:00 AM 62,464 dpnmodem.dll

08/18/2001 08:00 AM 62,976 dsauth.dll

08/29/2002 06:40 AM 62,976 browselc.dll

08/29/2002 06:41 AM 62,976 shgina.dll

02/28/2003 06:26 PM 63,248 javaprxy.dll

08/29/2002 06:41 AM 63,488 srclient.dll

08/18/2001 08:00 AM 64,000 avicap32.dll

12/12/2002 12:14 AM 64,512 amstream.dll

08/18/2001 08:00 AM 64,512 acctres.dll

08/29/2002 06:40 AM 64,512 ciodm.dll

03/05/2004 10:16 PM 64,512 colbact.dll

08/18/2001 08:00 AM 64,512 ntdsapi.dll

03/05/2004 10:16 PM 64,512 mtxclu.dll

08/18/2001 08:00 AM 65,024 msaudite.dll

08/18/2001 08:00 AM 65,024 msvcrt40.dll

07/19/2002 11:43 AM 65,536 a3d.dll

08/29/2002 06:41 AM 65,536 msconf.dll

08/18/2001 08:00 AM 65,536 jgsh400.dll

08/18/2001 08:00 AM 65,585 wshext.dll

08/18/2001 08:00 AM 66,048 msw3prt.dll

08/18/2001 08:00 AM 66,560 scarddlg.dll

08/18/2001 08:00 AM 66,560 console.dll

08/18/2001 08:00 AM 66,560 ipxsap.dll

08/29/2002 06:40 AM 66,560 faultrep.dll

08/29/2002 06:41 AM 66,560 spoolss.dll

08/18/2001 08:00 AM 66,560 mmcbase.dll

08/17/2001 06:36 PM 67,072 usbui.dll

08/18/2001 08:00 AM 67,072 msacm32.dll

08/29/2002 06:41 AM 67,584 msctfp.dll

03/24/2003 09:00 AM 68,096 dpnhupnp.dll

08/29/2002 06:41 AM 68,096 mscms.dll

08/18/2001 08:00 AM 68,096 inetpp.dll

12/12/2002 12:14 AM 68,096 dsdmoprp.dll

08/18/2001 08:00 AM 68,608 olecli32.dll

08/18/2001 08:00 AM 68,928 mmsystem.dll

08/18/2001 08:00 AM 69,120 mprddm.dll

08/18/2001 08:00 AM 69,120 unimdmat.dll

08/18/2001 08:00 AM 69,120 olethk32.dll

08/18/2001 08:00 AM 69,120 ipxpromn.dll

08/18/2001 08:00 AM 69,584 avicap.dll

12/18/2002 08:31 AM 69,632 xmltok.dll

08/18/2001 08:00 AM 69,632 msr2c.dll

08/18/2001 08:00 AM 69,632 icwdial.dll

08/29/2002 06:40 AM 69,632 inseng.dll

08/18/2001 08:00 AM 69,632 spnike.dll

08/18/2001 08:00 AM 69,699 usrcoina.dll

08/29/2002 06:40 AM 70,144 cryptdlg.dll

08/18/2001 08:00 AM 70,656 wiascr.dll

08/18/2001 08:00 AM 70,656 sprio600.dll

08/18/2001 08:00 AM 70,656 ifsutil.dll

08/29/2002 06:41 AM 71,168 storprop.dll

08/29/2002 06:40 AM 71,680 browsewm.dll

08/18/2001 08:00 AM 72,192 sprio800.dll

08/18/2001 08:00 AM 73,216 avwav.dll

08/18/2001 08:00 AM 73,728 csseqchk.dll

08/29/2002 06:40 AM 73,728 ils.dll

08/18/2001 08:00 AM 73,802 msrclr40.dll

08/18/2001 08:00 AM 74,240 dhcpsapi.dll

08/18/2001 08:00 AM 74,752 netui0.dll

08/29/2002 06:40 AM 74,810 atl.dll

08/18/2001 08:00 AM 75,264 ws2_32.dll

08/29/2002 06:46 AM 75,912 rdpwsx.dll

08/29/2002 06:40 AM 76,288 avifil32.dll

12/12/2002 12:14 AM 76,800 dmscript.dll

04/12/2004 11:11 PM 76,800 dpwsockx.dll

08/18/2001 08:00 AM 77,824 asycfilt.dll

07/11/2001 11:51 AM 77,824 EAXAC3.DLL

08/18/2001 08:00 AM 77,824 isign32.dll

08/18/2001 08:00 AM 77,850 hlink.dll

08/18/2001 08:00 AM 77,883 usrrtosa.dll

08/18/2001 08:00 AM 77,890 usrdpa.dll

08/18/2001 08:00 AM 78,848 tapiui.dll

10/15/1996 09:53 AM 78,848 INLOADER.DLL

08/18/2001 08:00 AM 79,360 fontsub.dll

08/18/2001 08:00 AM 79,360 mprapi.dll

08/18/2001 08:00 AM 80,128 msapsspc.dll

08/18/2001 08:00 AM 80,384 cabview.dll

08/18/2001 08:00 AM 80,384 autodisc.dll

08/18/2001 08:00 AM 80,384 mciavi32.dll

08/29/2002 06:41 AM 80,896 ntprint.dll

08/18/2001 08:00 AM 81,408 fsusd.dll

08/29/2002 06:41 AM 81,920 trkwks.dll

06/12/1998 12:01 PM 81,946 VB5JP.dll

04/16/2004 08:56 PM 82,432 fldrclnr.dll

08/30/1995 02:02 AM 82,432 ctwflt32.dll

02/04/2002 02:43 AM 82,432 msxml4r.dll

12/11/2002 05:34 PM 82,432 drmstor.dll

08/18/2001 08:00 AM 82,432 ufat.dll

03/05/2004 10:16 PM 82,432 mtxoci.dll

08/18/2001 08:00 AM 82,432 comrepl.dll

08/29/2002 06:41 AM 82,944 psbase.dll

08/18/2001 08:00 AM 82,944 rasauto.dll

08/29/2002 06:40 AM 82,944 iphlpapi.dll

08/18/2001 08:00 AM 82,944 olecli.dll

11/21/2003 10:07 AM 82,984 S32EVNT1.DLL

08/18/2001 08:00 AM 83,968 ipxmontr.dll

01/05/2002 05:18 AM 84,992 atl70.dll

08/18/2001 08:00 AM 84,992 dskquota.dll

06/05/1998 02:00 AM 84,992 sfcvrt32.dll

08/18/2001 08:00 AM 85,020 dgsetup.dll

08/18/2001 08:00 AM 85,504 catsrvps.dll

08/29/2002 06:41 AM 86,016 xactsrv.dll

07/05/2000 05:03 PM 86,016 clsNCX22.dll

08/18/2001 08:00 AM 86,073 usrfaxa.dll

08/29/2002 06:41 AM 86,528 wlnotify.dll

08/18/2001 08:00 AM 86,528 iassam.dll

08/18/2001 08:00 AM 87,040 srvsvc.dll

08/29/2002 06:46 AM 87,304 rdpdd.dll

08/18/2001 08:00 AM 87,552 polstore.dll

08/18/2001 08:00 AM 87,552 occache.dll

08/29/2002 06:41 AM 88,064 tscfgwmi.dll

08/18/2001 08:00 AM 88,064 mydocs.dll

12/18/2002 08:31 AM 89,360 VB5DB.DLL

08/18/2001 08:00 AM 89,600 langwrbk.dll

08/18/2001 08:00 AM 89,600 slbiop.dll

08/18/2001 08:00 AM 89,600 cscdll.dll

08/18/2001 08:00 AM 90,112 odbcint.dll

08/18/2001 08:00 AM 90,112 mycomput.dll

08/18/2001 08:00 AM 90,112 rsvpsp.dll

03/03/2003 04:57 PM 91,136 MSOERT2.DLL

08/29/2002 06:41 AM 91,136 rastls.dll

08/29/2002 06:40 AM 91,136 advpack.dll

08/18/2001 08:00 AM 91,648 loadperf.dll

08/18/2001 08:00 AM 93,184 winscard.dll

04/03/2000 06:52 PM 94,208 msstkprp.dll

08/18/2001 08:00 AM 94,282 msencode.dll

08/29/2002 06:41 AM 95,744 nlhtml.dll

08/18/2001 08:00 AM 96,256 rcbdyctl.dll

03/05/2004 10:16 PM 97,280 txflog.dll

12/12/2002 12:14 AM 97,280 dmusic.dll

10/27/2003 08:13 PM 98,304 ODBCCP32.dll

08/18/2001 08:00 AM 98,304 rtm.dll

08/29/2002 06:41 AM 98,304 oleprn.dll

08/18/2001 08:00 AM 98,304 actxprxy.dll

12/11/2002 05:34 PM 98,304 wmpshell.dll

12/12/2002 12:14 AM 98,816 dmstyle.dll

08/29/2002 06:41 AM 99,328 win32spl.dll

08/18/2001 08:00 AM 99,840 mprmsg.dll

08/29/2002 06:40 AM 99,840 dhcpcsvc.dll

12/12/2002 12:14 AM 100,864 dmsynth.dll

08/18/2001 08:00 AM 101,888 gpkcsp.dll

08/18/2001 08:00 AM 102,457 usrv42a.dll

08/18/2001 08:00 AM 102,912 apcups.dll

08/18/2001 08:00 AM 102,912 msaatext.dll

08/18/2001 08:00 AM 103,424 EqnClass.Dll

08/29/2002 06:40 AM 103,424 dgnet.dll

08/29/2002 06:40 AM 103,936 imm32.dll

08/18/2001 08:00 AM 103,936 mstlsapi.dll

08/18/2001 08:00 AM 104,448 wiavideo.dll

08/18/2001 08:00 AM 106,496 dsuiext.dll

08/29/2002 06:41 AM 106,496 url.dll

07/19/2002 11:54 AM 106,496 CTASIO.DLL

12/11/2002 05:34 PM 106,496 wmpasf.dll

06/26/2000 04:45 AM 106,496 TwnLib20.dll

07/19/2002 11:53 AM 106,496 CTDPROXY.DLL

08/18/2001 08:00 AM 106,496 olepro32.dll

08/29/2002 06:41 AM 107,008 umpnpmgr.dll

08/18/2001 08:00 AM 107,008 aclui.dll

08/18/2001 08:00 AM 107,520 rend.dll

01/13/1995 02:10 PM 108,032 mfcuia32.dll

08/18/2001 08:00 AM 108,464 netapi.dll

08/18/2001 08:00 AM 108,544 mdminst.dll

08/29/2002 06:41 AM 108,544 msv1_0.dll

08/18/2001 08:00 AM 109,456 avifile.dll

08/18/2001 08:00 AM 109,568 cic.dll

08/29/2002 06:41 AM 109,568 offfilt.dll

08/29/2002 06:41 AM 110,080 sbeio.dll

03/05/2004 10:16 PM 110,080 clbcatex.dll

07/19/2002 11:55 AM 110,592 PIAPROXY.DLL

07/19/2002 11:54 AM 110,592 COMMONFX.DLL

08/18/2001 08:00 AM 110,592 inetcplc.dll

08/18/2001 08:00 AM 110,592 iccvid.dll

08/18/2001 08:00 AM 112,128 mapi32.dll

08/18/2001 08:00 AM 112,128 mapistub.dll

12/12/2002 12:14 AM 112,128 dpvvox.dll

08/29/2002 06:41 AM 112,128 ntmarta.dll

08/29/2002 06:40 AM 113,152 idq.dll

08/29/2002 06:40 AM 113,152 dfrgui.dll

08/29/2002 06:41 AM 113,664 msvfw32.dll

08/29/2002 06:40 AM 114,176 input.dll

08/29/2002 05:20 AM 115,200 dpcdll.dll

08/29/2002 06:40 AM 115,712 apphelp.dll

08/25/2003 06:06 PM 115,808 iuctl.dll

06/29/2004 04:13 PM 115,936 SymRedir.dll

08/29/2002 06:41 AM 116,224 shsvcs.dll

08/18/2001 08:00 AM 116,224 iasrad.dll

08/18/2001 08:00 AM 116,736 glu32.dll

08/17/2001 10:36 PM 116,736 OVCodec2.dll

08/18/2001 08:00 AM 117,760 oledlg.dll

08/29/2002 06:41 AM 117,760 stobject.dll

08/18/2001 08:00 AM 118,784 scardssp.dll

11/25/2002 01:00 AM 118,784 DartWeb.dll

08/29/2002 06:41 AM 118,784 wmsdmoe.dll

08/18/2001 08:00 AM 118,784 dmdskres.dll

03/14/2000 11:04 AM 118,784 MSSTDFMT.DLL

08/29/2002 06:41 AM 119,808 wiadss.dll

08/18/2001 08:00 AM 119,808 mmutilse.dll

10/21/2003 07:06 PM 119,808 wkssvc.dll

08/29/2002 06:41 AM 120,320 upnp.dll

11/14/2002 12:58 PM 120,320 ir41_qc.dll

08/18/2001 08:00 AM 121,856 exts.dll

08/29/2002 06:41 AM 122,880 odbcconf.dll

06/22/2004 08:43 PM 123,392 itss.dll

08/29/2002 06:41 AM 124,928 webvw.dll

08/29/2002 01:27 AM 124,928 dssenh.dll

09/30/2002 10:58 AM 125,440 shmedia.dll

08/18/2001 08:00 AM 125,952 ifmon.dll

07/05/2000 05:02 PM 125,952 clsNPB22.dll

08/18/2001 08:00 AM 126,912 msvideo.dll

10/27/2003 08:09 PM 126,976 msdart.dll

08/29/2002 06:40 AM 126,976 imagehlp.dll

08/29/2002 06:40 AM 126,976 ieakeng.dll

08/18/2001 08:00 AM 127,552 cliconfg.dll

08/29/2002 04:05 AM 127,872 HAL.DLL

08/18/2001 08:00 AM 129,536 acledit.dll

08/18/2001 08:00 AM 130,048 sdpblb.dll

08/29/2002 06:41 AM 130,560 sti_ci.dll

03/24/2004 10:04 AM 131,072 nvinstnt.dll

08/29/2002 06:41 AM 131,072 msorcl32.dll

08/29/2002 06:41 AM 132,096 msrating.dll

08/29/2002 06:41 AM 133,120 sfc_os.dll

08/29/2002 06:41 AM 133,632 nwprovau.dll

08/29/2002 01:27 AM 133,632 rsaenh.dll

08/29/2002 06:40 AM 134,144 ipv6mon.dll

08/18/2001 08:00 AM 134,656 netid.dll

07/19/2002 11:54 AM 135,168 OpenAL32.dll

08/29/2002 06:40 AM 135,680 dsprop.dll

08/29/2002 06:41 AM 135,680 rdchost.dll

03/29/2004 09:48 PM 136,704 schannel.dll

08/18/2001 08:00 AM 137,216 hotplug.dll

08/29/2002 06:41 AM 137,216 ntshrui.dll

08/18/2001 08:00 AM 138,752 swprv.dll

08/29/2002 06:40 AM 139,264 dnsapi.dll

02/28/2003 06:26 PM 139,536 javaee.dll

08/29/2002 06:40 AM 139,776 adsldpc.dll

08/18/2001 08:00 AM 141,312 iasrecst.dll

08/18/2001 08:00 AM 142,336 cdfview.dll

08/18/2001 08:00 AM 142,848 capesnpn.dll

08/18/2001 08:00 AM 143,360 rasmontr.dll

12/11/2002 03:16 PM 143,360 wmidx.dll

08/29/2002 06:41 AM 143,872 msimtf.dll

08/28/2003 09:57 AM 143,872 itircl.dll

08/18/2001 08:00 AM 144,384 dskquoui.dll

08/18/2001 08:00 AM 144,896 jgdw400.dll

08/18/2001 08:00 AM 144,896 initpki.dll

08/18/2001 08:00 AM 145,408 wiavusd.dll

08/18/2001 08:00 AM 145,408 modemui.dll

08/18/2001 08:00 AM 146,432 keymgr.dll

08/18/2001 08:00 AM 146,432 msls31.dll

08/18/2001 08:00 AM 147,456 comsnap.dll

08/29/2002 06:41 AM 147,456 odbctrac.dll

08/18/2001 08:00 AM 147,483 scrrun.dll

10/17/2002 12:13 AM 147,495 rmoc3260.dll

03/28/2002 04:50 AM 147,512 hpzlnt05.dll

08/18/2001 08:00 AM 147,968 mdwmdmsp.dll

08/18/2001 08:00 AM 149,019 crtdll.dll

01/13/1995 02:10 PM 149,504 mfcans32.dll

03/05/2004 10:16 PM 150,528 msdtcuiu.dll

08/29/2002 06:40 AM 151,552 dinput.dll

04/03/2000 05:52 PM 151,552 RDOCURS.DLL

03/16/2004 01:38 PM 151,583 msjint40.dll

08/18/2001 08:00 AM 152,064 datime.dll

08/18/2001 08:00 AM 153,008 ole2nls.dll

08/18/2001 08:00 AM 154,112 ipmontr.dll

08/29/2002 06:41 AM 154,112 netman.dll

02/28/2003 06:26 PM 154,384 msawt.dll

08/29/2002 06:40 AM 155,648 encdec.dll

08/29/2002 06:40 AM 155,648 ipsecsvc.dll

07/19/2002 11:54 AM 155,648 CTOSUSER.DLL

08/18/2001 08:00 AM 155,675 scrobj.dll

08/18/2001 08:00 AM 157,696 paqsp.dll

06/30/2004 07:59 PM 158,720 xpob2res.dll

08/29/2002 06:41 AM 158,720 srsvc.dll

08/29/2002 06:40 AM 158,720 credui.dll

08/29/2002 06:41 AM 158,720 rasmans.dll

11/26/2002 07:03 PM 159,232 CEWMDM.dll

08/29/2002 06:40 AM 162,816 adsldp.dll

08/18/2001 08:00 AM 163,328 oleacc.dll

08/18/2001 08:00 AM 163,328 ciadmin.dll

08/09/1999 03:40 PM 163,600 wmaudsdk.dll

08/29/2002 06:41 AM 163,840 mindex.dll

08/29/2002 06:41 AM 164,864 upnphost.dll

08/29/2002 06:40 AM 165,376 els.dll

08/29/2002 06:41 AM 165,376 tapi32.dll

08/29/2002 06:41 AM 165,376 w32time.dll

08/29/2002 06:41 AM 165,888 ntmsdba.dll

08/18/2001 08:00 AM 166,912 photowiz.dll

08/18/2001 08:00 AM 166,912 wintrust.dll

12/11/2002 03:16 PM 167,936 wmerror.dll

08/29/2002 06:41 AM 168,448 wldap32.dll

08/29/2002 06:40 AM 168,960 dinput8.dll

08/18/2001 08:00 AM 169,520 ole2disp.dll

08/29/2002 01:27 AM 169,984 sccbase.dll

08/18/2001 08:00 AM 169,984 iprtrmgr.dll

08/29/2002 06:41 AM 171,008 sccsccp.dll

08/18/2001 08:00 AM 171,008 netmsg.dll

02/28/2003 06:26 PM 171,280 jit.dll

08/29/2002 06:41 AM 171,520 winmm.dll

12/12/2002 12:14 AM 171,520 dmime.dll

08/18/2001 08:00 AM 172,032 snmpsnap.dll

08/29/2002 06:41 AM 172,032 mssap.dll

06/08/2004 06:02 PM 172,544 schedsvc.dll

07/17/2002 10:09 AM 172,664 xenroll.dll

08/18/2001 08:00 AM 174,592 cmprops.dll

08/29/2002 06:41 AM 174,592 scecli.dll

08/18/2001 08:00 AM 176,128 ftsrch.dll

08/18/2001 08:00 AM 176,157 dgrpsetu.dll

12/12/2002 12:14 AM 177,152 qcap.dll

08/18/2001 08:00 AM 177,856 typelib.dll

08/18/2001 08:00 AM 180,800 sqlunirl.dll

08/18/2001 08:00 AM 181,760 activeds.dll

08/27/1998 12:51 AM 182,032 dxtmsft3.dll

08/29/2002 06:41 AM 182,784 msutb.dll

08/25/2003 06:06 PM 182,880 iuengine.dll

08/18/2001 08:00 AM 183,296 syncui.dll

11/14/2002 12:58 PM 183,808 ir50_qcx.dll

08/18/2001 08:00 AM 184,320 dmdskmgr.dll

08/29/2002 06:40 AM 186,880 certcli.dll

12/12/2002 12:14 AM 186,880 dsdmo.dll

02/28/2003 06:26 PM 187,152 javacypt.dll

08/29/2002 04:03 AM 187,904 xpsp1res.dll

08/29/2002 06:41 AM 189,440 wuaueng.dll

08/29/2002 06:41 AM 193,536 rasppp.dll

09/02/1998 04:02 AM 194,320 qcut.dll

12/12/2002 12:14 AM 194,560 mswebdvd.dll

08/29/2002 06:40 AM 194,560 dxtrans.dll

08/29/2002 06:41 AM 196,096 mobsync.dll

09/11/2001 08:21 AM 196,608 CTEAPSFX.DLL

08/18/2001 08:00 AM 198,656 t2embed.dll

08/18/2001 08:00 AM 199,168 ir32_32.dll

11/14/2002 12:58 PM 200,192 ir50_qc.dll

08/29/2002 06:41 AM 200,192 termsrv.dll

11/26/2002 07:03 PM 201,728 mspmsp.dll

08/29/2002 06:40 AM 202,496 ati2dvag.dll

08/18/2001 08:00 AM 202,752 localsec.dll

12/12/2002 12:14 AM 203,264 dpvoice.dll

08/29/2002 06:41 AM 203,264 uxtheme.dll

08/29/2002 06:40 AM 204,288 ieaksie.dll

10/27/2003 08:09 PM 204,800 ODBC32.dll

03/28/2002 04:50 AM 208,896 hpzcoi05.dll

12/11/2002 05:34 PM 208,896 wmpns.dll

08/18/2001 08:00 AM 208,896 wavemsp.dll

08/29/2002 06:39 AM 210,944 moricons.dll

12/08/1998 06:53 PM 212,480 PCDLIB32.DLL

01/10/2004 07:36 AM 213,023 msltus40.dll

08/18/2001 08:00 AM 214,016 netevent.dll

08/29/2002 06:41 AM 217,088 rasapi32.dll

08/29/2002 06:41 AM 218,112 sbe.dll

12/11/2002 05:23 PM 218,112 wmasf.dll

04/14/2004 02:56 PM 219,648 dplayx.dll

08/18/2001 08:00 AM 221,184 ieakui.dll

11/22/2002 01:00 AM 221,184 DartSock.dll

08/18/2001 08:00 AM 222,208 compstui.dll

08/23/2001 05:00 AM 223,232 gcdef.dll

12/11/2002 05:34 PM 225,280 wmpdxm.dll

03/05/2004 10:16 PM 225,280 catsrv.dll

03/05/2004 10:16 PM 226,816 es.dll

11/14/2002 12:50 PM 226,816 srrstr.dll

08/29/2002 06:40 AM 227,840 dsquery.dll

08/18/2001 08:00 AM 227,840 avtapi.dll

08/18/2001 08:00 AM 228,352 mswsock.dll

03/03/2003 04:57 PM 228,864 MSOEACCT.DLL

08/29/2002 06:41 AM 229,888 msieftp.dll

08/18/2001 08:00 AM 230,400 netui1.dll

08/29/2002 06:40 AM 231,424 iepeers.dll

08/29/2002 06:41 AM 231,424 upnpui.dll

12/11/2002 06:09 PM 232,960 blackbox.dll

08/29/2002 06:41 AM 233,984 tapisrv.dll

08/29/2002 06:40 AM 236,032 icm32.dll

01/31/2003 04:46 PM 238,080 newdev.dll

08/29/2002 06:40 AM 238,592 compatui.dll

08/29/2002 06:40 AM 239,616 adsnt.dll

08/29/2002 06:40 AM 240,640 hnetcfg.dll

03/24/2004 10:04 AM 241,664 nvnt4cpl.dll

12/11/2002 05:34 PM 241,664 qasf.dll

12/11/2002 05:34 PM 241,664 mpg4dmod.dll

03/01/2004 02:55 PM 241,693 msjtes40.dll

08/29/2002 06:41 AM 241,725 msuni11.dll

11/26/2002 07:03 PM 245,760 mswmdm.dll

08/29/2002 06:41 AM 247,808 wow32.dll

08/18/2001 08:00 AM 247,808 iassdo.dll

08/29/2002 06:41 AM 251,904 strmdll.dll

12/11/2002 06:09 PM 253,952 msnetobj.dll

08/18/2001 08:00 AM 253,952 neth.dll

08/18/2001 08:00 AM 253,952 msvcrt20.dll

08/29/2002 06:41 AM 254,976 pdh.dll

03/29/2004 09:48 PM 257,536 gdi32.dll

12/12/2002 12:14 AM 257,536 ddraw.dll

08/29/2002 06:41 AM 258,048 webcheck.dll

08/29/2002 06:40 AM 258,048 comdlg32.dll

03/01/2004 02:55 PM 258,077 mstext40.dll

06/08/2004 06:02 PM 260,096 mstask.dll

08/29/2002 06:40 AM 263,168 devmgr.dll

08/29/2002 06:40 AM 263,680 duser.dll

03/05/2004 10:16 PM 263,680 rpcss.dll

08/29/2002 06:41 AM 264,704 wzcsvc.dll

08/18/2001 08:00 AM 266,240 inetcfg.dll

03/28/2002 04:50 AM 266,240 hpzcon05.dll

08/29/2002 06:41 AM 266,752 msctf.dll

12/12/2002 12:14 AM 268,800 qdv.dll

08/18/2001 08:00 AM 268,800 ulib.dll

07/19/2002 11:56 AM 270,336 SFMS32.DLL

08/18/2001 08:00 AM 270,365 odbcjt32.dll

08/18/2001 08:00 AM 271,360 objsel.dll

08/18/2001 08:00 AM 272,768 atmfd.dll

11/01/2002 03:26 PM 272,896 winsrv.dll

08/29/2002 06:41 AM 272,896 kerberos.dll

08/18/2001 08:00 AM 273,920 dmdlgs.dll

09/21/2000 06:53 AM 275,312 ImagXpr5.dll

08/18/2001 08:00 AM 276,480 slbcsp.dll

10/17/2002 12:13 AM 278,528 pncrt.dll

08/18/2001 08:00 AM 285,184 glmf32.dll

02/28/2003 06:26 PM 286,992 vmhelper.dll

08/29/2002 06:40 AM 294,912 iedkcs32.dll

08/29/2002 06:41 AM 295,936 localspl.dll

08/29/2002 06:41 AM 296,448 wmstream.dll

08/29/2002 06:41 AM 297,984 scesrv.dll

12/11/2002 06:50 PM 301,712 drmclien.dll

08/29/2002 06:41 AM 302,080 untfs.dll

08/29/2002 06:41 AM 305,664 msihnd.dll

06/08/2004 06:02 PM 306,688 netapi32.dll

08/29/2002 06:40 AM 307,712 cscui.dll

08/18/2001 08:00 AM 308,224 netui2.dll

08/29/2002 06:41 AM 311,327 wmv8dmod.dll

02/28/2003 04:34 PM 313,856 dx3j.dll

01/10/2004 07:36 AM 315,423 msrd3x40.dll

08/18/2001 08:00 AM 315,904 hnetwiz.dll

12/11/2002 07:12 PM 316,040 mp43dmod.dll

08/29/2002 06:41 AM 316,416 wiaservc.dll

09/25/2002 03:18 PM 316,928 zipfldr.dll

08/29/2002 06:40 AM 318,464 ippromon.dll

07/19/2002 12:07 PM 319,488 CTDEVCON.DLL

03/01/2004 02:55 PM 319,517 msexcl40.dll

08/29/2002 06:41 AM 319,760 msnsspc.dll

08/18/2001 08:00 AM 323,072 filemgmt.dll

08/29/2002 06:41 AM 323,072 msvcrt.dll

10/16/2000 02:59 AM 323,584 mfimage.dll

08/18/2001 08:00 AM 323,641 usrdtea.dll

08/29/2002 06:40 AM 324,608 cmdial32.dll

08/29/2002 06:41 AM 328,704 oakley.dll

08/18/2001 08:00 AM 330,752 dmconfig.dll

07/01/2004 06:08 PM 331,776 winhttp.dll

08/18/2001 08:00 AM 332,800 ipsecsnp.dll

08/29/2002 06:41 AM 334,848 smlogcfg.dll

12/12/2002 12:14 AM 336,384 dsound.dll

08/29/2002 06:40 AM 337,920 dxtmsft.dll

11/14/2002 12:58 PM 338,432 ir41_qcx.dll

08/29/2002 06:41 AM 339,456 usp10.dll

10/09/2003 03:19 PM 339,968 mobho.dll

08/18/2001 08:00 AM 343,552 termmgr.dll

01/05/2002 06:37 AM 344,064 msvcr70.dll

08/18/2001 08:00 AM 345,600 confmsp.dll

03/01/2004 02:55 PM 348,189 msxbde40.dll

03/01/2004 02:55 PM 348,189 mspbde40.dll

08/23/2001 05:00 AM 350,208 d3drm.dll

02/17/2003 10:16 AM 354,816 psisdecd.dll

05/30/2003 09:00 AM 355,840 qdvd.dll

12/11/2002 06:09 PM 358,912 msscp.dll

03/01/2004 02:52 PM 358,976 msjetoledb40.dll

08/18/2001 08:00 AM 359,936 cards.dll

08/18/2001 08:00 AM 361,472 fontext.dll

07/01/2004 06:08 PM 361,984 qmgr.dll

08/18/2001 08:00 AM 362,496 jet500.dll

08/18/2001 08:00 AM 364,032 ipsmsnap.dll

03/05/2004 10:16 PM 367,616 msdtcprx.dll

08/29/2002 03:41 AM 367,616 licdll.dll

08/29/2002 06:41 AM 368,710 msisam11.dll

08/18/2001 08:00 AM 370,176 dhcpmon.dll

12/12/2002 12:14 AM 377,856 dpnet.dll

08/29/2002 06:40 AM 377,984 ati2dvaa.dll

01/10/2004 07:37 AM 380,957 expsrv.dll

08/29/2002 06:41 AM 381,440 lmrt.dll

08/29/2002 06:41 AM 384,000 themeui.dll

12/11/2002 03:16 PM 384,512 mp4sdmod.dll

10/27/2003 08:12 PM 385,024 SQLSRV32.dll

08/18/2001 08:00 AM 387,584 regwizc.dll

08/29/2002 06:41 AM 392,704 ntmssvc.dll

08/23/2001 05:00 AM 394,240 diactfrm.dll

05/11/2000 01:06 PM 397,312 MSRDO20.DLL

08/29/2002 06:41 AM 399,360 netlogon.dll

08/29/2002 06:41 AM 401,462 msvcp60.dll

08/29/2002 04:09 AM 403,456 winbrand.dll

02/28/2003 06:26 PM 404,752 javart.dll

04/08/2004 04:12 PM 406,528 shlwapi.dll

08/29/2002 06:41 AM 409,088 vssapi.dll

12/11/2002 07:11 PM 410,248 wmadmod.dll

08/18/2001 08:00 AM 411,136 samsrv.dll

08/18/2001 08:00 AM 414,208 setupdll.dll

08/29/2002 06:41 AM 420,864 shimgvw.dll

01/10/2004 07:36 AM 421,919 msrd2x40.dll

08/29/2002 06:41 AM 423,424 riched20.dll

10/02/2001 01:00 AM 430,080 CTVBase.dll

10/08/2001 01:00 AM 434,176 CTABase.dll

08/18/2001 08:00 AM 435,712 shellstyle.dll

08/23/2001 05:00 AM 436,224 d3dim.dll

08/18/2001 08:00 AM 436,736 certmgr.dll

03/29/2004 09:48 PM 439,808 ipnathlp.dll

08/29/2002 06:41 AM 440,320 mshtmled.dll

08/29/2002 06:41 AM 446,464 wmvdmoe.dll

08/18/2001 08:00 AM 449,536 wiadefui.dll

08/18/2001 08:00 AM 450,560 infosoft.dll

03/24/2004 10:04 AM 454,656 nvshell.dll

11/30/2001 01:00 AM 458,752 CTMBase.dll

08/18/2001 08:00 AM 460,288 ntmsmgr.dll

05/09/2001 04:47 PM 466,944 wmv8dmoe.dll

07/24/2003 04:40 PM 477,696 cryptui.dll

08/05/2002 09:30 AM 479,232 MusicCitydll2.dll

08/29/2002 06:41 AM 479,261 vbscript.dll

01/21/2004 04:20 PM 484,352 URLMON.DLL

12/11/2002 07:07 PM 486,536 wmspdmod.dll

01/05/2002 06:40 AM 487,424 msvcp70.dll

08/18/2001 08:00 AM 489,984 hypertrm.dll

08/29/2002 06:40 AM 489,984 dbghelp.dll

08/18/2001 08:00 AM 495,376 msxml.dll

08/29/2002 06:41 AM 496,128 mstime.dll

08/29/2002 06:40 AM 498,205 dxmasf.dll

03/05/2004 10:16 PM 499,200 comuid.dll

03/05/2004 10:16 PM 499,712 clbcatq.dll

08/29/2002 06:41 AM 504,832 msftedit.dll

06/29/2004 04:13 PM 505,056 SymNeti.dll

09/21/2000 11:02 AM 507,904 imagr5.dll

03/01/2004 02:55 PM 512,029 msexch40.dll

08/29/2002 06:41 AM 522,240 printui.dll

12/12/2002 12:14 AM 524,800 qedit.dll

09/27/2000 10:15 AM 532,480 imagx5.dll

03/05/2004 10:16 PM 535,552 rpcrt4.dll

09/23/2002 03:10 PM 544,256 crypt32.dll

03/29/2004 09:48 PM 548,352 rtcdll.dll

03/04/2002 08:09 PM 548,864 shdoclc.dll

03/01/2004 02:55 PM 552,989 msrepl40.dll

08/29/2002 06:40 AM 557,056 comctl32.dll

08/29/2002 06:40 AM 558,080 advapi32.dll

09/25/2003 12:49 PM 560,128 user32.dll

08/18/2001 08:00 AM 565,760 msvcp50.dll

08/18/2001 08:00 AM 568,832 wiashext.dll

08/29/2002 06:41 AM 569,344 oleaut32.dll

08/18/2001 08:00 AM 577,024 mlang.dll

08/29/2002 06:41 AM 584,192 netcfgx.dll

02/06/2004 06:05 PM 588,288 WININET.DLL

01/13/2003 02:57 PM 589,881 jscript.dll

08/23/2001 05:00 AM 590,336 d3dramp.dll

03/29/2004 09:48 PM 593,408 h323msp.dll

05/17/2004 11:46 PM 593,408 xpsp2res.dll

03/05/2004 10:16 PM 594,944 catsrvut.dll

06/07/2004 02:19 PM 596,480 INETCOMM.DLL

08/29/2002 04:40 AM 598,016 mstscax.dll

01/23/2003 07:19 PM 600,064 divx.dll

12/12/2002 12:14 AM 602,624 dx7vb.dll

08/18/2001 08:00 AM 605,696 getuname.dll

07/05/2000 05:16 PM 606,208 clsNRN22.dll

03/16/2004 01:38 PM 614,431 mswstr10.dll

08/29/2002 06:41 AM 631,808 rasdlg.dll

07/19/2002 11:55 AM 643,072 CTSBLFX.DLL

05/01/2003 04:56 PM 654,336 ntdll.dll

08/29/2002 06:41 AM 667,136 userenv.dll

03/29/2004 09:48 PM 667,648 lsasrv.dll

12/11/2002 05:34 PM 670,208 wmadmoe.dll

04/16/2004 08:56 PM 676,864 sxs.dll

12/11/2002 06:09 PM 678,912 drmv2clt.dll

08/29/2002 06:41 AM 686,080 opengl32.dll

01/07/2002 05:15 PM 689,424 msxml2.dll

12/12/2002 12:14 AM 733,184 qedwipes.dll

11/14/2002 12:58 PM 755,200 ir50_32.dll

12/11/2002 07:12 PM 760,968 wmsdmod.dll

08/18/2001 08:00 AM 762,368 winntbbu.dll

08/18/2001 08:00 AM 792,064 comres.dll

05/30/2003 09:00 AM 797,184 d3dim700.dll

08/29/2002 06:40 AM 802,304 dxmrtp.dll

12/11/2002 07:10 PM 816,264 wmvdmod.dll

08/18/2001 08:00 AM 829,952 tapi3.dll

01/10/2004 07:36 AM 831,519 mswdat10.dll

08/29/2002 06:40 AM 844,675 ati3d1ag.dll

08/18/2001 08:00 AM 847,872 msimsg.dll

08/18/2001 08:00 AM 847,872 dbgeng.dll

08/29/2002 06:41 AM 857,600 netplwiz.dll

12/11/2002 05:34 PM 892,416 wmspdmoe.dll

08/29/2002 06:40 AM 921,475 ati3d2ag.dll

08/18/2001 08:00 AM 924,432 mfc40u.dll

08/18/2001 08:00 AM 924,432 mfc40.dll

08/29/2002 06:41 AM 930,304 kernel32.dll

08/29/2002 06:41 AM 932,864 setupapi.dll

08/29/2002 06:41 AM 938,496 syssetup.dll

02/28/2003 06:26 PM 947,472 msjava.dll

01/05/2002 07:36 AM 964,608 mfc70u.dll

03/29/2004 09:48 PM 971,264 msgina.dll

01/05/200

Share this post


Link to post
Share on other sites

Please create a zip file containing the following dll's:

 

bitsprx3.dll

bitsprx2.dll

qmgrprxy.dll

winhttp.dll

qmgr.dll

wdmigh.dll

sqlbokj.dll

nthst32.dll

mtjpgb.dll

mtjpgh.dll

 

 

and email them HERE. Once i get them I will see if I can spot the offending dll.

Share this post


Link to post
Share on other sites

Gao,

 

I am going to step in here and work with you on this one. Please do the following for me:

 

Copy the contents of the quote box to Notepad.

Name the file Appinit.bat

Save as type All Files

Save on the Desktop.

Reg save "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows" windows1.hiv

ren windows1.hiv windows.txt

 

Double click on Appinit.bat

This will create a file on the desktop named windows.txt

 

Please zip and email that files to grinler@yahoo.com please.

 

Thanks

Share this post


Link to post
Share on other sites

I'm pretty sure I did it right.

However, I don't think it went well G-Dog...

 

take a look:

 

------------------------------------------------------------------------------

Based heavily off the script FindNFix by FreeatLast

This search script is only for Windows XP/2000

The information found here is for identification purposes only!

In no way will this tool actually fix the problem. Use the results to perform

a manual fix.

------------------------------------------------------------------------------

 

Registry keys failed to backup. Aborting script.

 

 

------------------------------------------------------------------------------

Please paste the contents of this log as reply to your current log.

Then delete this entire directory.

------------------------------------------------------------------------------

Share this post


Link to post
Share on other sites

Delete c:\search

 

Download a new version of search.zip from the same link above. I was trying to be fancy for absolutely no reason and the script was wrong.

 

Then run search.bat and post the contents of the notepad it opens.

Share this post


Link to post
Share on other sites

lol, alrighty.

worked this time so...

 

------------------------------------------------------------------------------

Based heavily off the script FindNFix by FreeatLast

This search script is only for Windows XP/2000

The information found here is for identification purposes only!

In no way will this tool actually fix the problem. Use the results to perform

a manual fix.

------------------------------------------------------------------------------

 

Windows Version:

 

Microsoft Windows XP [Version 5.1.2600]

 

############################################################################

 

Test1:

Using xfind to search for hookxx and StreamingDeviceSetup2 strings in system32\dlls

 

Found files that contain the string hookxx:

 

Found files that contain the string StreamingDeviceSetup2:

 

 

############################################################################

 

Conducting Test2:

Looking for files that can not be opened for identification with analyzer

 

 

 

############################################################################

 

Looking for dlls that have been packed with upx (usually malware)

 

 

 

############################################################################

 

Conducting Test4:

Looking for dlls in \windows\system32 that are readonly and younger than 5 months ago.

 

No matches found.

 

Looking for dlls in \windows\system32 that are hidden, system

and younger than 5 months ago.

 

 

No matches found.

 

 

############################################################################

 

Conducting Test5:

Looking for dlls in \windows\system32 that have attributes +hrs and younger than 5 months

 

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

 

.

.

------------------------------------------------------------------------------

Please paste the contents of this log as reply to your current log.

Then delete this entire directory.

Email any errors to grinler AT bleepingcomputer.com

http://www.bleepingcomputer.com

------------------------------------------------------------------------------

 

you have my continued thanks for all efforts.

Share this post


Link to post
Share on other sites

I want you to fix some of those entries. Please do the following:

 

Please make sure that you can view all hidden files. Instructions on how to do this can be found here:

 

How to see hidden files in Windows

 

Run Hijackthis again, click scan, and Put a checkmark next to each of these. Then click the Fix button

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rd.yahoo.com/customize/ymsgr/defaul...://my.yahoo.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/customize/ymsgr/defaul...//www.yahoo.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://rd.yahoo.com/customize/ymsgr/defaul...//www.yahoo.com

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/1755c86b4aec5aad9c04/netzip/RdxIE2.cab

 

 

Reboot your computer into Safe Mode and delete the following files:

 

Then delete these files or directories (Do not be concerned if they do not exist)

C:\DOCUMENTS AND SETTINGS\User\LOCAL SETTINGS\Temp\sp.html

 

Disable System Restore. You can find instructions on how to enable and reenable system restore here:

 

Managing Windows Millenium System Restore

or

 

Windows XP System Restore Guide

 

Renable system restore with instructions from tutorial above

 

Reboot your computer to go back to normal mode and post a new log.

Share this post


Link to post
Share on other sites

Okay. Firstly, all my hiddens are viewable.

Did the Hijack This fix and "it" started to try and jack my homepage (just like when I attempt a fix with CWShredder or Spy Sweeper) again but then it seemed to finish the process normaly.

Rebooted in safe mode and looked for sp.html but it wasn't there.

Rebooted in normal mode Disabled and then re-inabled Sys restore (oops, misunderstood the post and I didn't do that part in safe mode. should i redo all this then? does that matter?)

 

Rebooted, scanned, and here is the log:

 

Logfile of HijackThis v1.98.0

Scan saved at 3:38:22 PM, on 7/17/2004

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\System32\CTHELPER.EXE

C:\PROGRA~1\popup\POP-UP~1\dpps2.exe

C:\Program Files\Common Files\Symantec Shared\ccApp.exe

C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

C:\WINDOWS\System32\ctfmon.exe

C:\Program Files\Common Files\Symantec Shared\ccProxy.exe

C:\Program Files\SWGuard\SpywareGuard\sgmain.exe

C:\Program Files\Norton AntiVirus\navapsvc.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\Program Files\Norton AntiVirus\SAVScan.exe

C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

C:\Program Files\SWGuard\SpywareGuard\sgbhp.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

C:\Program Files\HThis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rd.yahoo.com/customize/ymsgr/defaul...://my.yahoo.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/customize/ymsgr/defaul...//www.yahoo.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SWGuard\SpywareGuard\dlprotect.dll

O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll

O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE

O4 - HKLM\..\Run: [Pop-Up Stopper] "C:\PROGRA~1\popup\POP-UP~1\dpps2.exe"

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [iS CfgWiz] C:\Program Files\Common Files\Symantec Shared\cfgwiz.exe /GUID NIS /CMDLINE "REBOOT"

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKCU\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe

O4 - HKCU\..\Run: [spySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0

O4 - HKCU\..\Run: [Jet Detection] C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe

O4 - Startup: SpywareGuard.lnk = C:\Program Files\SWGuard\SpywareGuard\sgmain.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll (file missing)

O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll (file missing)

O12 - Plugin for .bmp: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll

O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab

O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200210...meInstaller.exe

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab

O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) -

 

Huh... did that stuff come back again?

Share this post


Link to post
Share on other sites

Lets move on to something else. Thanksfully FreeAtLast has rereleased her tool which makes it easier to find the offending dll.

 

Please do the following:

 

Download the program FindNFix from the following location:

http://freeatlast100.100free.com/

 

Once it is downloaded, double-click on the file to run it. Follow the prompts to install the program. Once it is installed a window will open up showing the installation directory and a bunch of files in the right section of the window.

 

On the right portion of the window look for the file called !LOG!.bat and double-click on it. It will scan through your computer for a while, so be patient. When it is completed it will automatically open a notepad window called Log.txt.

 

Copy the contents of that file into a reply to this post.

Share this post


Link to post
Share on other sites

Okay.

I think that link is dead, but I found FindNFix here: http://downloads.subratam.org/FINDnFIX.exe

 

and here is the log:

 

 

»»»»»»»»»»»»»»»»»»*** freeatlast100.100free.com ***»»»»»»»»»»»»»»»»

--The directory 'junkxxx' is now included as a Subfolder in the FINDnfix folder

and is the destination for the file to be moved..

-*Previous directions will no longer work...

»»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»»

 

Microsoft Windows XP [Version 5.1.2600]

»»»IE build and last SP(s)

6.0.2800.1106 SP1-Q818529-Q330994-Q837009-Q832894-Q831167-Q823353

The type of the file system is NTFS.

C: is not dirty.

 

Sun 18 Jul 04 12:53:37

12:53am up 0 days, 2:58

 

»»»»»»»»»»»»»»»»»»*** Note! ***»»»»»»»»»»»»»»»»

The list will produce a small database of files that will match certain criteria.

You must know how to ID the file based on the filters provided in

the scan, as not all the files flagged are bad.

Ex: read only files, s/h files, last modified date. size, etc.

The filters provided should help narrow down the list, and hopefully

pinpoint the culprit.

Along with that,registry scan logged at the end should match the

corresponding file(s) listed.

»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Unless the file match the entire criteria, it should not be pointed to remove!

»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

*For *Helpers/Mods and/or users that are not familiar with any of the

items on the scan results- I recommend using an alternative, once

you know what to look for!

»»»»»»»»»»»»»»»»»»***LOG!***(*modified 7/16)»»»»»»»»»»»»»»»»

 

»»»*»»»*Boards that are not personally authorised by me are not allowed to use this fix!»»»*»»»*

 

Scanning for file(s)...

»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»

»»»»» (*1*) »»»»» .........

»»Locked or 'Suspect' file(s) found...

 

 

»»»»» (*2*) »»»»»........

**File C:\FINDnFIX\LIST.TXT

 

»»»»» (*3*) »»»»»........

 

No matches found.

 

unknown/hidden files...

 

No matches found.

 

»»»»» (*4*) »»»»».........

Sniffing..........

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

 

 

»»»»»(*5*)»»»»»

**File C:\WINDOWS\SYSTEM32\DLLXXX.TXT

 

»»»»»(*6*)»»»»»

 

»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»

»»»»»Search by size...

 

 

No matches found.

 

No matches found.

 

No matches found.

 

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

 

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

 

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

 

 

»»Size of Windows key:

(*Default-450 *No AppInit-398 *fake(infected)-448,504,512...)

 

Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 450

 

»»Dumping Values........

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DeviceNotSelectedTimeout SZ 15

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\GDIProcessHandleQuota DWORD 00002710

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Spooler SZ yes

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\swapdisk SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\TransmissionRetryTimeout SZ 90

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\USERProcessHandleQuota DWORD 00002710

 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows

AppInit_DLLs =

DeviceNotSelectedTimeout = 15

GDIProcessHandleQuota = REG_DWORD 0x00002710

Spooler = yes

swapdisk =

TransmissionRetryTimeout = 90

USERProcessHandleQuota = REG_DWORD 0x00002710

 

»»Security settings for 'Windows' key:

 

 

RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above

Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)

This program is Freeware, use it on your own risk!

 

Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:

(ID-NI) ALLOW Read BUILTIN\Users

(ID-IO) ALLOW Read BUILTIN\Users

(ID-NI) ALLOW Full access BUILTIN\Administrators

(ID-IO) ALLOW Full access BUILTIN\Administrators

(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM

(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM

(ID-IO) ALLOW Full access CREATOR OWNER

 

Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:

Read BUILTIN\Users

Full access BUILTIN\Administrators

Full access NT AUTHORITY\SYSTEM

 

 

»»Member of...: (Admin logon required!)

User is a member of group USER-D913XSCAE3\None.

User is a member of group \Everyone.

User is a member of group BUILTIN\Administrators.

User is a member of group BUILTIN\Users.

User is a member of group \LOCAL.

User is a member of group NT AUTHORITY\INTERACTIVE.

User is a member of group NT AUTHORITY\Authenticated Users.

 

 

»»»»»»Backups created...»»»»»»

12:54am up 0 days, 2:59

Sun 18 Jul 04 12:54:26

 

A C:\FINDnFIX\keyback.hiv

--a-- - - - - - 8,192 07-18-2004 keyback.hiv

A C:\FINDnFIX\keys1\winkey.reg

--a-- - - - - - 287 07-18-2004 winkey.reg

*Temp backups...

.

..

keyback2.hi_

winkey2.re_

 

 

C:\FINDNFIX\

JUNKXXX Sun Jul 18 2004 12:53:32p .D... <Dir>

 

1 item found: 0 files, 1 directory.

 

»»Performing string scan....

00001150: vk f AppInit_DLLs G

00001190: h vk UDeviceNotSelectedTimeout 1 5

000011D0: P 9 0 vk ' zGDIProcessHandle

00001210:Quota" vk 8 Spooler2 y e s _ h

00001250: ` vk 5swapdisk vk

00001290: . TransmissionRetryTimeout h `

000012D0: vk ' 0 USERProcessHandleQuotaR

00001310:

00001350:

00001390:

000013D0:

00001410:

00001450:

00001490:

000014D0:

00001510:

00001550:

00001590:

000015D0:

 

---------- WIN.TXT

fùAppInit_DLLsÖ?æG

--------------

--------------

$01180: AppInit_DLLs

$011AF: UDeviceNotSelectedTimeout

$011FF: zGDIProcessHandleQuota

$01298: TransmissionRetryTimeout

$012E8: USERProcessHandleQuotaR

--------------

--------------

No strings found.

 

--------------

--------------

REGEDIT4

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"AppInit_DLLs"=""

"DeviceNotSelectedTimeout"="15"

"GDIProcessHandleQuota"=dword:00002710

"Spooler"="yes"

"swapdisk"=""

"TransmissionRetryTimeout"="90"

"USERProcessHandleQuota"=dword:00002710

 

A handle was successfully obtained for the

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows key.

This key has 0 subkeys.

The AppInitDLLs value exists and reports as 2 bytes, including the 2 for string termination.

 

[AppInitDLLs]

Ansi string : ""

0000 00 00 | ..

Share this post


Link to post
Share on other sites

Are you still having a problem? I apologize i never got back to you but I never received the notification

Share this post


Link to post
Share on other sites

Yep, still right were ya left me. 'sokay.

As far as the problem, I don't have any noticeble ones aside from when I try to delete the CWS hijack file "sp.html" using spy sweeper or cwshredder (or anything for that matter) it starts trying to hijack my homepage again. repeatedly. Other than that I don't really have a problem. At least one that is visible, I hope it's not doing something without me noticing it.

 

Anyway, does the FindnFix log provide any useful info?

Share this post


Link to post
Share on other sites

No it does not but the version you are using is outdated. Please delete the entire c:\findnfix folder and ten follow these isntructions:

 

Please do the following:

 

Download the program FindNFix from the following location:

 

http://www10.brinkster.com/expl0iter/freeatlast/FNF/

 

Once it is downloaded, double-click on the file to run it. Follow the prompts to install the program. Once it is installed a window will open up showing the installation directory and a bunch of files in the right section of the window.

 

On the right portion of the window look for the file called !LOG!.bat and double-click on it. It will scan through your computer for a while, so be patient. When it is completed it will automatically open a notepad window called Log.txt.

 

Copy the contents of that file into a reply to this post.

Share this post


Link to post
Share on other sites

okay, done and done.

heres the log:

 

 

»»»»»»»»»*** www10.brinkster.com/expl0iter/freeatlast/FNF/ ***»»»»»»»»»

»»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»»

 

Microsoft Windows XP [Version 5.1.2600]

»»»IE build and last SP(s)

6.0.2800.1106 SP1-Q818529-Q330994-Q837009-Q832894-Q831167-Q823353

The type of the file system is NTFS.

C: is not dirty.

 

Sat 24 Jul 04 21:01:54

9:01pm up 0 days, 0:17

 

»»»»»»»»»»»»»»»»»»*** Note! ***»»»»»»»»»»»»»»»»

The list will produce a small database of files that will match certain criteria.

You must know how to ID the file based on the filters provided in

the scan, as not all the files flagged are bad.

Ex: read only files, s/h files, last modified date. size, etc.

The filters provided should help narrow down the list, and hopefully

pinpoint the culprit.

Along with that,registry scan logged at the end should match the

corresponding file(s) listed.

»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Unless the file match the entire criteria, it should not be pointed to remove

without attempting to confirm it's nature!

»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

At times there could be several (legit) files flagged, and/or duplicate culprit file(s)!

If in doubt, always search the file(s) and properties according to criteria!

 

The file(s) found should be moved to \FINDnFIX\"junkxxx" Subfolder

»»»»»»»»»»»»»»»»»»***LOG!***(*updated 7/24)»»»»»»»»»»»»»»»»

 

»»»*»»»*Use at your own risk!»»»*»»»*

 

Scanning for file(s)...

»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»

»»»»» (*1*) »»»»» .........

»»Locked or 'Suspect' file(s) found...

 

 

»»»»» (*2*) »»»»»........

**File C:\FINDnFIX\LIST.TXT

 

»»»»» (*3*) »»»»»........

 

No matches found.

 

unknown/hidden files...

 

No matches found.

 

»»»»» (*4*) »»»»».........

Sniffing..........

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

 

 

»»»»»(*5*)»»»»»

**File C:\WINDOWS\SYSTEM32\DLLXXX.TXT

 

»»»»»(*6*)»»»»»

 

»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»

»»»»»Search by size...

 

 

No matches found.

 

No matches found.

 

No matches found.

 

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

 

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

 

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

 

 

»»Size of Windows key:

(*Default-450 *No AppInit-398 *fake(infected)-448,504,512...)

 

Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 450

 

»»Dumping Values........

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DeviceNotSelectedTimeout SZ 15

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\GDIProcessHandleQuota DWORD 00002710

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Spooler SZ yes

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\swapdisk SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\TransmissionRetryTimeout SZ 90

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\USERProcessHandleQuota DWORD 00002710

 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows

AppInit_DLLs =

DeviceNotSelectedTimeout = 15

GDIProcessHandleQuota = REG_DWORD 0x00002710

Spooler = yes

swapdisk =

TransmissionRetryTimeout = 90

USERProcessHandleQuota = REG_DWORD 0x00002710

 

»»Security settings for 'Windows' key:

 

 

RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above

Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)

This program is Freeware, use it on your own risk!

 

Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:

(ID-NI) ALLOW Read BUILTIN\Users

(ID-IO) ALLOW Read BUILTIN\Users

(ID-NI) ALLOW Full access BUILTIN\Administrators

(ID-IO) ALLOW Full access BUILTIN\Administrators

(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM

(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM

(ID-IO) ALLOW Full access CREATOR OWNER

 

Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:

Read BUILTIN\Users

Full access BUILTIN\Administrators

Full access NT AUTHORITY\SYSTEM

 

 

»»Member of...: (Admin logon required!)

User is a member of group USER-D913XSCAE3\None.

User is a member of group \Everyone.

User is a member of group BUILTIN\Administrators.

User is a member of group BUILTIN\Users.

User is a member of group \LOCAL.

User is a member of group NT AUTHORITY\INTERACTIVE.

User is a member of group NT AUTHORITY\Authenticated Users.

 

 

»»»»»»Backups created...»»»»»»

9:02pm up 0 days, 0:18

Sat 24 Jul 04 21:02:44

 

A C:\FINDnFIX\keyback.hiv

--a-- - - - - - 8,192 07-24-2004 keyback.hiv

A C:\FINDnFIX\keys1\winkey.reg

--a-- - - - - - 287 07-24-2004 winkey.reg

*Temp backups...

.

..

keyback2.hi_

winkey2.re_

 

 

C:\FINDNFIX\

JUNKXXX Sat Jul 24 2004 9:01:54p .D... <Dir>

 

1 item found: 0 files, 1 directory.

 

»»Performing string scan....

00001150: vk f AppInit_DLLs G

00001190: h vk UDeviceNotSelectedTimeout 1 5

000011D0: P 9 0 vk ' zGDIProcessHandle

00001210:Quota" vk 8 Spooler2 y e s _ h

00001250: ` vk 5swapdisk vk

00001290: . TransmissionRetryTimeout h `

000012D0: vk ' 0 USERProcessHandleQuotaR

00001310:

00001350:

00001390:

000013D0:

00001410:

00001450:

00001490:

000014D0:

00001510:

00001550:

00001590:

000015D0:

 

---------- WIN.TXT

fùAppInit_DLLsÖ?æG

--------------

--------------

$01180: AppInit_DLLs

$011AF: UDeviceNotSelectedTimeout

$011FF: zGDIProcessHandleQuota

$01298: TransmissionRetryTimeout

$012E8: USERProcessHandleQuotaR

--------------

--------------

No strings found.

 

--------------

--------------

REGEDIT4

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"AppInit_DLLs"=""

"DeviceNotSelectedTimeout"="15"

"GDIProcessHandleQuota"=dword:00002710

"Spooler"="yes"

"swapdisk"=""

"TransmissionRetryTimeout"="90"

"USERProcessHandleQuota"=dword:00002710

 

A handle was successfully obtained for the

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows key.

This key has 0 subkeys.

The AppInitDLLs value exists and reports as 2 bytes, including the 2 for string termination.

 

[AppInitDLLs]

Ansi string : ""

0000 00 00 | ..

Share this post


Link to post
Share on other sites

Another suggestion.....

 

Use Appinit.bat. ( http://users.telenet.be/marcvn/spyware/appinit.zip )

Run it.

There will be a dosbox, a file will be created named windows.txt

In this file is the name located of the hidden dll on your system. We will call xxxx.dll.

 

Disconnect from the intranet. Run Hiving (download it from:

http://computercops.biz/modules.php?name=F...wnload&id=1183)

Reboot and check for the file: c:\Windows\System32\xxxx.dll

Delete it.

Run CWShredder

Reboot

Run HijackThis and fix all thats left over pointing to about:blanc (sp.html)

Or run Adware..

 

Good luck

Blub :bounce:

Share this post


Link to post
Share on other sites

Step 1:

 

Please make sure that you can view all hidden files. Instructions on how to do this can be found here:

 

How to see hidden files in Windows

 

Create new folder on your hard drive called c:\regbackup.

 

Step 2:

 

Run Registrar Lite again enter HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows into the address field and press enter. On the left side of the screen the Windows key should be selected and highlighted purple.

 

With the Windows key highlighted click on the File menu, and the click on export and save them in the following formats:

 

 

First save it with the name winkey.reg

Make the save type regedit4 .reg type and then press the save button.

 

Then click on file export again, and this time name it Winkey.hiv

Change the type to regetd32/WinAPI *hiv *dat files and press the save button.

 

 

When both files/backups are successfully saved, right-click on the highlighted Windows key and rename it to Windows 1.

 

Step 3:

 

With Windows1 highlighted, look in the right section and double-click on AppInit and clear the data in the value field. That is the dll you saw previuosly.

 

Rename Windows1 back to Windows and exit the program.

 

Reboot your computer.

 

Step 4:

 

When you are back at your desktop, navigate to the c:\regback folder. Double-click on the winkey.reg file. When it prompt if you would like to import/merge the data press the Yes button.

 

Then run Registrar Lite again, go to the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows key again as done above. While the Windows key is selected (highlighted purple/blue) in the left window, click on File and them Import.

 

Browse to c:\regback and select the winkey.hiv file that we created earlier. When it asks if you would like to merge, say yes/ok.

 

Step 5:

 

 

Then double-click on the appinit_dlls key again and clear the value again by double click on appinit_dlls and making sure there is nothing in the values field.

 

Then delete the entire c:\regback folder.

 

Step 6:

 

Now download and run CWShredder. You can download the program from the following locations:

 

http://www.merijn.org/files/cwshredder.zip

 

or

 

http://www.zerosrealm.com/downloads/CWShredder.zip

 

After you download the program, unzip it into a directory. Make sure all browser windows are closed and double click on the cwshredder.exe to start the program. When the program is loaded click on the "Check for Update" button, and if it finds an new version it will download it. You should then double click on cwshredder.exe again and click on the "FIX" button (not the "Scan only" button) and let it scan your computer.

 

A tutorial that goes over this process step by step can be found here:

 

How to remove CoolWebSearch with CWShredder

 

When that is completed, please download the latest version of Ad-Aware from the following location:

 

Ad-aware

 

Make sure you update the program before you scan with it. A tutorial on using ad-aware can be found below:

 

AD-AWARE - Using Ad-aware to remove Spyware & Hijackers from Your Computer.

 

When that is completed post a new hijackthis log

Edited by grinler

Share this post


Link to post
Share on other sites

Whew, done.

...a few probs however.

 

Firstly, the appinit.dll's value in registrar is already empty.

 

Secondly, I could not double-click the ".hiv" file as windows did not recognize the extention.

 

Thirdly Ad-Aware seems to have the same problem that Spy Sweeper and CWShredder do. Upon attempted removal the four seperate files each try to hijack and then get copied from somewhere back to where they just got quarentined from.

 

Aggrivating.

 

Well, here is the log:

 

Logfile of HijackThis v1.98.0

Scan saved at 5:06:32 PM, on 7/27/2004

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\System32\CTHELPER.EXE

C:\PROGRA~1\popup\POP-UP~1\dpps2.exe

C:\Program Files\Common Files\Symantec Shared\ccApp.exe

C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

C:\Program Files\Common Files\Symantec Shared\ccProxy.exe

C:\WINDOWS\System32\ctfmon.exe

C:\Program Files\Norton AntiVirus\navapsvc.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\Program Files\SWGuard\SpywareGuard\sgmain.exe

C:\Program Files\Norton AntiVirus\SAVScan.exe

C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

C:\Program Files\SWGuard\SpywareGuard\sgbhp.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

C:\Program Files\HThis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rd.yahoo.com/customize/ymsgr/defaul...://my.yahoo.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/customize/ymsgr/defaul...//www.yahoo.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SWGuard\SpywareGuard\dlprotect.dll

O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll

O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE

O4 - HKLM\..\Run: [Pop-Up Stopper] "C:\PROGRA~1\popup\POP-UP~1\dpps2.exe"

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [iS CfgWiz] C:\Program Files\Common Files\Symantec Shared\cfgwiz.exe /GUID NIS /CMDLINE "REBOOT"

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKCU\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe

O4 - HKCU\..\Run: [spySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0

O4 - HKCU\..\Run: [Jet Detection] C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe

O4 - Startup: SpywareGuard.lnk = C:\Program Files\SWGuard\SpywareGuard\sgmain.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll (file missing)

O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll (file missing)

O12 - Plugin for .bmp: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll

O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab

O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200210...meInstaller.exe

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab

O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) -

Share this post


Link to post
Share on other sites

You do not double click on the .hiv file. If you look at the instruction you need import that file. When you say the four files rehijack you..what four files?

Share this post


Link to post
Share on other sites

HA-HA!

It's GONE!

No programs are finding any spy/mal/adware, whatever, on my system anymore. Many thanks to MMXX66 and Grinler for all their efforts. I'm posting a HJT log just for old times sake and to see if maybe you notice anything that looks odd. For instance, what's all this yahoo messenger stuff still on my system for? I uninstalled messenger quite a ways back. Thanks again all!

Share this post


Link to post
Share on other sites

oops... forgot the log:

 

Logfile of HijackThis v1.98.0

Scan saved at 10:31:08 AM, on 8/2/2004

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Common Files\Symantec Shared\ccProxy.exe

C:\Program Files\Norton AntiVirus\navapsvc.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\Program Files\Norton AntiVirus\SAVScan.exe

C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

C:\WINDOWS\System32\CTHELPER.EXE

C:\PROGRA~1\popup\POP-UP~1\dpps2.exe

C:\Program Files\Common Files\Symantec Shared\ccApp.exe

C:\Program Files\Cleaner\The Cleaner\tca.exe

C:\Program Files\Cleaner\The Cleaner\tcm.exe

C:\WINDOWS\System32\ctfmon.exe

C:\Program Files\SWGuard\SpywareGuard\sgmain.exe

C:\Program Files\SWGuard\SpywareGuard\sgbhp.exe

C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\HThis\HijackThis.exe

C:\WINDOWS\system32\NOTEPAD.EXE

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rd.yahoo.com/customize/ymsgr/defaul...://my.yahoo.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/customize/ymsgr/defaul...//www.yahoo.com

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SWGuard\SpywareGuard\dlprotect.dll

O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll

O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll

O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE

O4 - HKLM\..\Run: [Pop-Up Stopper] "C:\PROGRA~1\popup\POP-UP~1\dpps2.exe"

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [iS CfgWiz] C:\Program Files\Common Files\Symantec Shared\cfgwiz.exe /GUID NIS /CMDLINE "REBOOT"

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [tcactive] C:\Program Files\Cleaner\The Cleaner\tca.exe

O4 - HKLM\..\Run: [tcmonitor] C:\Program Files\Cleaner\The Cleaner\tcm.exe

O4 - HKCU\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe

O4 - HKCU\..\Run: [spySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0

O4 - HKCU\..\Run: [Jet Detection] C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe

O4 - Startup: SpywareGuard.lnk = C:\Program Files\SWGuard\SpywareGuard\sgmain.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll (file missing)

O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll (file missing)

O12 - Plugin for .bmp: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll

O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha...v45/yacscom.cab

O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab

O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200210...meInstaller.exe

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab

O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab

O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) -

Share this post


Link to post
Share on other sites

Just fix these and you should be all clean...

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rd.yahoo.com/customize/ymsgr/defaul...://my.yahoo.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/customize/ymsgr/defaul...//www.yahoo.com

O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll (file missing)

O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll (file missing)

O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) -

 

 

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

  1. Make your Internet Explorer more secure - This can be done by following these simple instructions:

    1. From within Internet Explorer click on the Tools menu and then click on Options.
    2. Click once on the Security tab
    3. Click once on the Internet icon so it becomes highlighted.
    4. Click once on the Custom Level button.
      1. Change the Download signed ActiveX controls to Prompt
         
      2. Change the Download unsigned ActiveX controls to Disable
         
      3. Change the Initialize and script ActiveX controls not marked as safe to Disable
         
      4. Change the Installation of desktop items to Prompt
         
      5. Change the Launching programs and files in an IFRAME to Prompt
         
      6. Change the Navigate sub-frames across different domains to Prompt
         
      7. When all these settings have been made, click on the OK button.
         
      8. If it prompts you as to whether or not you want to save the settings, press the Yes button.

      [*]Next press the Apply button and then the OK to exit the Internet Properties page.

      [*]Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.

       

      See this link for a listing of some online & their stand-alone antivirus programs:

       

      Virus, Spyware, and Malware Protection and Removal Resources

       

       

      [*]Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

       

       

      [*]Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

       

      For a tutorial on Firewalls and a listing of some available ones see the link below:

       

      Understanding and Using Firewalls

       

       

      [*]Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

       

       

      [*]Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.

       

      A tutorial on installing & using this product can be found here:

       

      Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

       

       

      [*]Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.

       

      A tutorial on installing & using this product can be found here:

       

      Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

       

       

      [*]Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

       

      A tutorial on installing & using this product can be found here:

       

      Using SpywareBlaster to protect your computer from Spyware and Malware

       

       

      [*]Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

      Follow this list and your potential for being infected again will reduce dramatically.

       

      Glad I was able to help.


Share this post


Link to post
Share on other sites
:D your welcome :D

Share this post


Link to post
Share on other sites
Sign in to follow this  
Followers 0