Jump to content


Photo

Need help with "CWS sp.html hijack" removal


  • Please log in to reply
42 replies to this topic

#1 Gao

Gao

    Member

  • Full Member
  • Pip
  • 21 posts

Posted 14 July 2004 - 12:42 PM

First of all, thanks for reading.

Secondly, I really hope I'm not being uncouth in any way with my posting of this problem. Be assured I actually would like help; so, if I break any rules or I haven't tried something I should have I guarantee you it is unintentional. I'm just ignorant.

Ive gone over the information on this site and others to try and fix my problem myself with relative success. However, one file seems to keep coming back. While I am sure that NOW I am safe from this annoyance (althhough I do have what I imagine is a seperate problem with java now) I cannot seem to get rid of the "CWS sp.html hijack" file.

Iv'e done all kinda stuff, most of which I can't remember at the moment.
Ive updated Windows completely.
I have Norton's Firewall and virus protection, Webroot Spysweeper, Spy Guard and Spyware Blaster, Security Task Manager, Pop-up Stopper, and have just run the CWS Shredder program. While CWS Shredder did find a handful of files that nothing else turned up, Spysweeper keeps finding the afore mentioned file in what I assume is the "registry".

Lemme give a little backstory:

Initally the only noticable problems were pop-ups and that I kept getting hijacked (a term that was unknown to me until just a few days ago, I have little to no idea what I'm doing if that's not already obvious) to the "about:blank" page. Spysweeper was a little helpful in reseting my homepage but Spy Guard or Spyware Blocker, whichever one it is, really clued me in as to just how often my homepage was being changed. I was going nuts having to click to reset my homepage numerous times every few minutes.

Here's the situation now:

After doing some research and implementing posted advice, something (more or less) worked. I am no longer getting pop-ups telling me I'm infected and my page is no longer getting jacked. However, whenever I run Spy Sweeper it still finds the "CWS sp.html hijack" file. Upon removal I always get several more alerts from Spy Guard/ware Blocker telling me my homepage has yet again been changed. When I run it again the same thing happens, over and over. This also occured upon finishing up with the CWS Shredder program. These are the only times I ever get them anymore.

While it's not doing anything that I can see now and everything is telling its been 86'ed (aside from Spy Sweeper that is) I know it is still there, and what it's doing that I can't see is what's got me bugging out.

I appologize for the verbose post but I don't know what else to do and I want any helper(s) to have all the info I can give. I suppose the thing to do now is post the Hijack This log, which I willl do presently. If the startup log is also needed I'm ready to post it as well. I can also guarantee speedy replies to posts; I'm at this contraption nearly all day, every day.

I'll be thanking any helpers constantly I'm sure, but allow me to thank some in advance:
thank you.

Without further ado, the log...


Logfile of HijackThis v1.98.0
Scan saved at 12:21:11 PM, on 7/14/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\popup\POP-UP~1\dpps2.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\SWGuard\SpywareGuard\sgmain.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\SWGuard\SpywareGuard\sgbhp.exe
C:\Program Files\HThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rd.yahoo.com/...://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://rd.yahoo.com/...//www.yahoo.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SWGuard\SpywareGuard\dlprotect.dll
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Pop-Up Stopper] "C:\PROGRA~1\popup\POP-UP~1\dpps2.exe"
O4 - HKLM\..\Run: [IS CfgWiz] C:\Program Files\Common Files\Symantec Shared\cfgwiz.exe /GUID NIS /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - HKCU\..\Run: [Jet Detection] C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SWGuard\SpywareGuard\sgmain.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll (file missing)
O12 - Plugin for .bmp: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150...tzip/RdxIE2.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) -

#2 mmxx66

mmxx66

    The SWI drummer

  • Retired Staff
  • PipPipPipPipPip
  • 4,412 posts

Posted 14 July 2004 - 01:00 PM

You have a hijack which can be removed using CWShredder but will be reinstalled by a hidden file. So first we have to find the hidden file and remove it.

Copy the contents of the quote box to Notepad.
Name the file Appinit.bat
Save as type All Files
Save on the Desktop.

Reg save "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows" windows1.hiv
ren windows1.hiv windows.txt


Double click on Appinit.bat
This will create a file on the desktop named windows.txt

Double click on the windows.txt file to open and copy and paste the entire contents into a reply to this post. The text will look funny but that is ok.

#3 Gao

Gao

    Member

  • Full Member
  • Pip
  • 21 posts

Posted 14 July 2004 - 01:19 PM

thanks for the reply!
okay sir, i think this is what you want...

regf       Pugf hbin  Ø’’’nk, œ)śŃ·=Ā ’’’’ ’’’’’’’’ ° x ’’’’ 0  A R  Windows ’’’sk x x  Ō  „ø Č   ¤       !  €  !  ?          ?               Ų’’’vk  €   fłAppInit_DLLsÖ?ęG h Š’’’vk  Č   ĄUDeviceNotSelectedTimeoutš’’’1 5  Pā š’’’9 0  Š Š’’’vk  €'   zGDIProcessHandleQuota"žą’’’vk  8   °ŗSpooler2š’’’y e s
Ń_å h ˜ č  ` ą’’’vk  €   5swapdiskŠ’’’vk  Ų   . TransmissionRetryTimeoutą’’’h ˜ č  ` € Š Š’’’vk  €'   0 USERProcessHandleQuotaR

#4 Gao

Gao

    Member

  • Full Member
  • Pip
  • 21 posts

Posted 15 July 2004 - 10:24 AM

I stumbled across this...
maybe it has something to do with where the hidden file is at?
...It's greek to me.

<<sp.html seems to be related to a browser redirector . It add the following in the registry res://C:\WINDOWS\system32\gcuxg.dll/sp.html#96676.
The redirector has also been seen using index.html as its filename, and adding the following in the registry:
res://C:\WINDOWS\system32\csmzs.dll/sp.html#96676>>

#5 winter

winter

    Member

  • Full Member
  • Pip
  • 5 posts

Posted 15 July 2004 - 10:37 AM

solution: http://boards.cexx.o...opic.php?t=7427

#6 mmxx66

mmxx66

    The SWI drummer

  • Retired Staff
  • PipPipPipPipPip
  • 4,412 posts

Posted 15 July 2004 - 10:43 AM

Winter, that is another variant of this infection and it“s not applicable to this case.

#7 Gao

Gao

    Member

  • Full Member
  • Pip
  • 21 posts

Posted 15 July 2004 - 10:54 AM

thanks for the post Winter,but im not so sure that guy has ONLY the same problem as me...

I see he does have an "sp.html" issue but i think thats where our similarity ends. I poured over that thread but there is no way for me to tell which solution is the one i should implement, nor can I tell which ones I should NOT implement. knowhudimeen?

#8 Gao

Gao

    Member

  • Full Member
  • Pip
  • 21 posts

Posted 15 July 2004 - 10:56 AM

OH!
hello mmxx66!
good to see your still around :D

#9 mmxx66

mmxx66

    The SWI drummer

  • Retired Staff
  • PipPipPipPipPip
  • 4,412 posts

Posted 15 July 2004 - 11:01 AM

Gao , I“ve been around all the time.
I just sent you an email, check it. :D

Edited by mmxx66, 15 July 2004 - 11:02 AM.


#10 mmxx66

mmxx66

    The SWI drummer

  • Retired Staff
  • PipPipPipPipPip
  • 4,412 posts

Posted 15 July 2004 - 11:05 AM

Gao, please download and install the program Registry Lite from here:

http://www.resplendence.com/reglite

Once it is installed, please double click on the icon that should now be on your desktop. If an icon is not there, then check under programs portion of the Start Menu.

Once it is opened, copy and paste the below line, into the address field of Registrar Lite.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs

And press enter. You will now be presented with new information in the bottom right and left sections and on the right section, the name AppInit_DLLs should be highlighted. Double-click on the AppInit_DLLs entry and copy and paste the text found in the value field in your next reply to this post.

#11 Gao

Gao

    Member

  • Full Member
  • Pip
  • 21 posts

Posted 15 July 2004 - 11:10 AM

Okay, I'll do that now.
I sent the file you wanted to your hotmail account...
that is what you wanted I hope.

#12 Gao

Gao

    Member

  • Full Member
  • Pip
  • 21 posts

Posted 15 July 2004 - 11:22 AM

Okay I did it.

However, when I double-click the appinint_dlls in the right side after copy and pasting, tha "data editor" window that pops up displays this stuff:

Key Name
Value Name
Catagory
Description
Type
Type #
Size
Value

All but the Key and value name, the type and type #, and size are completely empty fields. including the afore mentioned value field you wanted me to copy and paste. it's empty. is that bad?

#13 mmxx66

mmxx66

    The SWI drummer

  • Retired Staff
  • PipPipPipPipPip
  • 4,412 posts

Posted 15 July 2004 - 11:29 AM

There should be a hidden file there, may be it“s a new variant, please download CWShredder install, run and click fix. and post a new hijack this log.

#14 Gao

Gao

    Member

  • Full Member
  • Pip
  • 21 posts

Posted 15 July 2004 - 11:36 AM

Thank you for your continued help. :D
I already had that installed so it was a easy to run another scan. It still does the same thing I mentioned in my first post however.
Nevertheless, heres my log:

Logfile of HijackThis v1.98.0
Scan saved at 12:32:26 PM, on 7/15/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\popup\POP-UP~1\dpps2.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\SWGuard\SpywareGuard\sgmain.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\SWGuard\SpywareGuard\sgbhp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\HThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rd.yahoo.com/...://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://rd.yahoo.com/...//www.yahoo.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SWGuard\SpywareGuard\dlprotect.dll
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Pop-Up Stopper] "C:\PROGRA~1\popup\POP-UP~1\dpps2.exe"
O4 - HKLM\..\Run: [IS CfgWiz] C:\Program Files\Common Files\Symantec Shared\cfgwiz.exe /GUID NIS /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - HKCU\..\Run: [Jet Detection] C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SWGuard\SpywareGuard\sgmain.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll (file missing)
O12 - Plugin for .bmp: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150...tzip/RdxIE2.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) -

#15 mmxx66

mmxx66

    The SWI drummer

  • Retired Staff
  • PipPipPipPipPip
  • 4,412 posts

Posted 15 July 2004 - 11:43 AM

In th e CWShredder click on check for update a couple of times to check if you have the latest version.

#16 Gao

Gao

    Member

  • Full Member
  • Pip
  • 21 posts

Posted 15 July 2004 - 11:50 AM

I thought I had updaded completely but the update text seems odd...

Here, I'll paste it in it's entirety
-------------------------------------

Current version: CWShredder v1.59.1
Connecting...
Fetching CWShredder update information from merijn.org...
Unable to retrieve CWShredder update information. The server might be unavailable, try again later.

Fetching CWShredder update information from spywareinfo.com...
You have the latest version of CWShredder.
----------------------------------------------------

is it actually updating or no?

#17 mmxx66

mmxx66

    The SWI drummer

  • Retired Staff
  • PipPipPipPipPip
  • 4,412 posts

Posted 15 July 2004 - 12:35 PM

Copy the contents of the quote box to Notepad.
Name the file dllsizes.bat
Save as type All Files
Save on the Desktop.

dir /o:s c:\windows\system32\*.dll > dllsizes.txt
notepad dllsizes.txt


Double click on the file, dllsizes.bat, that is found on your desktop.

A notepad will appear with information. paste the contents of that notepad into a reply to this post.

#18 Gao

Gao

    Member

  • Full Member
  • Pip
  • 21 posts

Posted 15 July 2004 - 12:39 PM

Gotchya.

Here ya go:

Directory of c:\windows\system32

07/12/2004 01:46 PM 0 wdmigh.dll
07/12/2004 12:08 PM 0 sqlbokj.dll
07/12/2004 12:26 PM 2 nthst32.dll
07/12/2004 12:26 PM 34 mtjpgb.dll
09/06/2002 01:41 AM 2,272 w95inf16.dll
08/18/2001 08:00 AM 2,560 lz32.dll
08/18/2001 08:00 AM 2,864 winsock.dll
12/12/2002 12:14 AM 3,072 dpnaddr.dll
08/18/2001 08:00 AM 3,072 icmp.dll
08/18/2001 08:00 AM 3,072 rnr20.dll
12/12/2002 12:14 AM 3,072 dpnlobby.dll
08/18/2001 08:00 AM 3,200 wowfax.dll
08/18/2001 08:00 AM 3,584 riched32.dll
08/18/2001 08:00 AM 3,584 iprop.dll
08/18/2001 08:00 AM 3,584 msafd.dll
08/29/2002 04:14 AM 3,584 dsprpres.dll
08/18/2001 08:00 AM 3,584 comcat.dll
08/18/2001 08:00 AM 3,584 mll_hp.dll
08/18/2001 08:00 AM 4,096 rdpcfgex.dll
08/18/2001 08:00 AM 4,096 mtxex.dll
08/18/2001 08:00 AM 4,096 iprtprio.dll
12/12/2002 12:14 AM 4,096 ksuser.dll
08/18/2001 08:00 AM 4,096 sfc.dll
08/29/2002 06:39 AM 4,126 msdxmlc.dll
08/18/2001 08:00 AM 4,208 storage.dll
08/18/2001 08:00 AM 4,608 mssip32.dll
08/18/2001 08:00 AM 4,608 mchgrcoi.dll
08/29/2002 06:41 AM 4,608 msimg32.dll
08/18/2001 08:00 AM 4,608 vjoy.dll
09/06/2002 01:41 AM 4,608 w95inf32.dll
08/18/2001 08:00 AM 4,656 ds16gt.dLL
08/18/2001 08:00 AM 5,120 winnls.dll
08/18/2001 08:00 AM 5,120 kbddv.dll
08/18/2001 08:00 AM 5,120 shell.dll
08/29/2002 06:40 AM 5,120 hccoin.dll
08/18/2001 08:00 AM 5,120 msidle.dll
08/18/2001 08:00 AM 5,632 kbdblr.dll
08/18/2001 08:00 AM 5,632 kbdro.dll
08/18/2001 08:00 AM 5,632 mll_qic.dll
08/18/2001 08:00 AM 5,632 kbdpl1.dll
08/18/2001 08:00 AM 5,632 wmi.dll
08/18/2001 08:00 AM 5,632 kbdbu.dll
10/17/2002 12:13 AM 5,632 pndx5032.dll
08/18/2001 08:00 AM 5,632 kbdru.dll
08/18/2001 08:00 AM 5,632 softpub.dll
08/18/2001 08:00 AM 5,632 kbdus.dll
08/18/2001 08:00 AM 5,632 kbdmon.dll
08/18/2001 08:00 AM 5,632 kbduzb.dll
08/18/2001 08:00 AM 5,632 kbdycc.dll
08/18/2001 08:00 AM 5,632 kbduk.dll
08/18/2001 08:00 AM 5,632 kbdlt1.dll
08/18/2001 08:00 AM 5,632 kbdlt.dll
08/18/2001 08:00 AM 5,632 kbdazel.dll
08/18/2001 08:00 AM 5,632 kbdkyr.dll
08/18/2001 08:00 AM 5,632 kbdkaz.dll
08/18/2001 08:00 AM 5,632 kbdru1.dll
08/18/2001 08:00 AM 5,632 kbdaze.dll
08/18/2001 08:00 AM 5,632 kbdit142.dll
08/18/2001 08:00 AM 5,632 kbdit.dll
08/18/2001 08:00 AM 5,632 kbdir.dll
08/18/2001 08:00 AM 5,632 kbdhu1.dll
08/18/2001 08:00 AM 5,632 kbdur.dll
08/18/2001 08:00 AM 5,632 security.dll
08/18/2001 08:00 AM 5,632 tapiperf.dll
08/18/2001 08:00 AM 5,632 kbdgae.dll
08/18/2001 08:00 AM 5,632 skdll.dll
08/18/2001 08:00 AM 5,632 kbdtat.dll
08/18/2001 08:00 AM 5,632 kbdhe319.dll
08/18/2001 08:00 AM 5,632 kbdhe220.dll
08/18/2001 08:00 AM 5,632 kbdhe.dll
08/18/2001 08:00 AM 6,144 kbdgr1.dll
08/18/2001 08:00 AM 6,144 kbdgr.dll
08/18/2001 08:00 AM 6,144 kbdgkl.dll
08/18/2001 08:00 AM 6,144 kbdfr.dll
08/18/2001 08:00 AM 6,144 kbdhela2.dll
08/18/2001 08:00 AM 6,144 kbdtuf.dll
08/18/2001 08:00 AM 6,144 kbdfo.dll
08/18/2001 08:00 AM 6,144 svcpack.dll
08/18/2001 08:00 AM 6,144 kbdfi.dll
08/29/2002 06:41 AM 6,144 sensapi.dll
08/18/2001 08:00 AM 6,144 rasadhlp.dll
08/18/2001 08:00 AM 6,144 kbdic.dll
08/18/2001 08:00 AM 6,144 kbdfc.dll
08/18/2001 08:00 AM 6,144 kbdest.dll
08/18/2001 08:00 AM 6,144 kbdes.dll
08/18/2001 08:00 AM 6,144 kbdbe.dll
08/18/2001 08:00 AM 6,144 kbdda.dll
08/18/2001 08:00 AM 6,144 kbdusl.dll
08/18/2001 08:00 AM 6,144 kbdbene.dll
08/18/2001 08:00 AM 6,144 kbdsw.dll
08/18/2001 08:00 AM 6,144 kbdpo.dll
08/18/2001 08:00 AM 6,144 kbdtuq.dll
08/18/2001 08:00 AM 6,144 kbdbr.dll
08/18/2001 08:00 AM 6,144 kbdusx.dll
08/18/2001 08:00 AM 6,144 kbdlv.dll
08/18/2001 08:00 AM 6,144 kbdlv1.dll
08/18/2001 08:00 AM 6,144 kbdmac.dll
08/18/2001 08:00 AM 6,144 kbdca.dll
08/18/2001 08:00 AM 6,144 kbdsp.dll
08/18/2001 08:00 AM 6,144 kbdno.dll
08/18/2001 08:00 AM 6,144 kbdne.dll
08/18/2001 08:00 AM 6,144 kbdusr.dll
08/18/2001 08:00 AM 6,144 kbdsf.dll
08/18/2001 08:00 AM 6,656 kbdcr.dll
08/18/2001 08:00 AM 6,656 kbdhela3.dll
12/11/2002 03:16 PM 6,656 laprxy.dll
08/18/2001 08:00 AM 6,656 routetab.dll
08/18/2001 08:00 AM 6,656 kbdpl.dll
08/18/2001 08:00 AM 6,656 kbdcz1.dll
08/29/2002 06:40 AM 6,656 batt.dll
08/18/2001 08:00 AM 6,656 KBDAL.DLL
08/18/2001 08:00 AM 6,656 kbdcz2.dll
08/18/2001 08:00 AM 6,656 kbdsl1.dll
08/18/2001 08:00 AM 6,656 kbdla.dll
08/18/2001 08:00 AM 6,656 ntlsapi.dll
08/18/2001 08:00 AM 6,656 kbdycl.dll
10/17/2002 12:13 AM 6,656 pndx5016.dll
08/18/2001 08:00 AM 6,656 kbdsl.dll
08/18/2001 08:00 AM 6,656 kbdhu.dll
03/17/2004 02:33 PM 6,656 spmsg.dll
08/18/2001 08:00 AM 6,656 kbdsg.dll
08/18/2001 08:00 AM 7,040 kdcom.dll
08/29/2002 04:05 AM 7,040 kd1394.dll
08/18/2001 08:00 AM 7,168 kbdnec.dll
07/01/2004 06:08 PM 7,168 bitsprx3.dll
08/18/2001 08:00 AM 7,168 wshnetbs.dll
08/18/2001 08:00 AM 7,168 mscat32.dll
08/18/2001 08:00 AM 7,168 kbdcz.dll
08/18/2001 08:00 AM 7,168 msr2cenu.dll
08/18/2001 08:00 AM 7,680 vcdex.dll
08/18/2001 08:00 AM 7,680 mciole32.dll
07/01/2004 06:08 PM 7,680 bitsprx2.dll
12/11/2002 03:16 PM 7,680 asferror.dll
08/18/2001 08:00 AM 7,680 kbdcan.dll
08/18/2001 08:00 AM 7,680 mll_mtf.dll
08/18/2001 08:00 AM 7,680 dciman32.dll
08/18/2001 08:00 AM 7,680 ncxpnt.dll
12/12/2002 12:14 AM 8,192 d3d8thk.dll
08/18/2001 08:00 AM 8,192 mag_hook.dll
08/18/2001 08:00 AM 8,192 kbdhept.dll
08/18/2001 08:00 AM 8,192 psnppagn.dll
08/18/2001 08:00 AM 8,192 tsbyuv.dll
08/18/2001 08:00 AM 8,192 qosname.dll
08/18/2001 08:00 AM 8,192 streamci.dll
08/18/2001 08:00 AM 8,192 igmpagnt.dll
08/18/2001 08:00 AM 8,192 mciole16.dll
08/18/2001 08:00 AM 8,456 tsddd.dll
12/20/1999 01:16 PM 8,704 npwmsdrm.dll
08/18/2001 08:00 AM 8,704 lprhelp.dll
08/29/2002 06:40 AM 8,832 framebuf.dll
08/18/2001 08:00 AM 9,008 ver.dll
08/29/2002 06:41 AM 9,216 wuauserv.dll
08/18/2001 08:00 AM 9,216 lprmonui.dll
08/18/2001 08:00 AM 9,216 wshatm.dll
08/18/2001 08:00 AM 9,216 wifeman.dll
08/29/2002 06:40 AM 9,216 icaapi.dll
08/18/2001 08:00 AM 9,216 winfax.dll
08/18/2001 08:00 AM 9,344 vga.dll
08/18/2001 08:00 AM 9,728 gpkrsrc.dll
08/18/2001 08:00 AM 9,728 xolehlp.dll
08/18/2001 08:00 AM 9,728 rsvpperf.dll
08/17/2001 10:36 PM 9,759 HSF_INST.dll
08/18/2001 08:00 AM 9,936 lzexpand.dll
08/18/2001 08:00 AM 10,112 modex.dll
08/17/1998 05:21 AM 10,240 vidx16.dll
08/18/2001 08:00 AM 10,240 WshRm.dll
08/18/2001 08:00 AM 10,240 panmap.dll
08/18/2001 08:00 AM 10,240 mcd32.dll
08/29/2002 06:41 AM 10,240 localui.dll
08/29/2002 06:41 AM 10,240 msrle32.dll
08/18/2001 08:00 AM 10,496 mcdsrv32.dll
08/18/2001 08:00 AM 10,752 clb.dll
08/18/2001 08:00 AM 10,752 netrap.dll
08/18/2001 08:00 AM 10,752 pschdprf.dll
08/18/2001 08:00 AM 11,264 atrace.dll
08/18/2001 08:00 AM 11,776 rasctrs.dll
08/18/2001 08:00 AM 11,776 wshisn.dll
08/18/2001 08:00 AM 11,776 drprov.dll
08/29/2002 06:41 AM 11,776 sigtab.dll
06/22/2004 08:45 PM 12,067 SIntf16.dll
08/18/2001 08:00 AM 12,288 lmhsvc.dll
08/18/2001 08:00 AM 12,288 nmevtmsg.dll
08/18/2001 08:00 AM 12,288 cmcfg32.dll
08/18/2001 08:00 AM 12,288 jsproxy.dll
08/29/2002 06:39 AM 12,288 odbcp32r.dll
08/18/2001 08:00 AM 12,288 mmdrv.dll
08/18/2001 08:00 AM 12,288 bootvid.dll
08/18/2001 08:00 AM 12,288 perfts.dll
08/29/2002 06:39 AM 12,288 mscpx32r.dll
08/18/2001 08:00 AM 12,800 pjlmon.dll
08/18/2001 08:00 AM 12,800 rasser.dll
08/18/2001 08:00 AM 12,800 mcastmib.dll
08/18/2001 08:00 AM 12,800 mgmtapi.dll
08/18/2001 08:00 AM 13,312 win87em.dll
08/29/2002 06:41 AM 13,312 wship6.dll
08/18/2001 08:00 AM 13,312 irclass.dll
08/18/2001 08:00 AM 13,312 verifier.dll
08/18/2001 08:00 AM 13,312 ntvdmd.dll
08/18/2001 08:00 AM 13,312 atkctrs.dll
08/18/2001 08:00 AM 13,312 tcpmib.dll
08/18/2001 08:00 AM 13,312 umdmxfrm.dll
12/12/2002 12:14 AM 13,312 msdmo.dll
08/18/2001 08:00 AM 13,312 msswch.dll
08/18/2001 08:00 AM 13,824 senscfg.dll
08/18/2001 08:00 AM 13,824 uniplat.dll
08/18/2001 08:00 AM 13,824 sisbkup.dll
08/18/2001 08:00 AM 13,824 wowfaxui.dll
08/29/2002 06:41 AM 13,824 rassapi.dll
08/18/2001 08:00 AM 13,888 toolhelp.dll
10/15/1996 09:53 AM 14,160 HLINKPRX.DLL
08/18/2001 08:00 AM 14,336 cmpbk32.dll
08/18/2001 08:00 AM 14,336 serialui.dll
08/18/2001 08:00 AM 14,336 inetppui.dll
08/18/2001 08:00 AM 14,336 ntlanui2.dll
08/29/2002 06:40 AM 14,366 asfsipc.dll
02/23/1996 02:34 PM 14,629 Declw.dll
08/18/2001 08:00 AM 14,848 winrnr.dll
08/18/2001 08:00 AM 14,848 powrprof.dll
08/29/2002 06:40 AM 14,848 cdm.dll
08/18/2001 08:00 AM 14,848 bidispl.dll
08/18/2001 08:00 AM 14,848 msidntld.dll
08/18/2001 08:00 AM 14,848 usbmon.dll
08/18/2001 08:00 AM 14,848 hnetmon.dll
08/18/2001 08:00 AM 14,848 slbrccsp.dll
08/29/2002 06:41 AM 14,848 rdpsnd.dll
08/18/2001 08:00 AM 14,848 serwvdrv.dll
08/18/2001 08:00 AM 14,877 corpol.dll
08/18/2001 08:00 AM 15,360 nddeapi.dll
08/18/2001 08:00 AM 15,360 tsd32.dll
08/18/2001 08:00 AM 15,360 linkinfo.dll
08/18/2001 08:00 AM 15,872 alrsvc.dll
08/18/2001 08:00 AM 15,872 sysinv.dll
08/18/2001 08:00 AM 15,872 cdmodem.dll
08/18/2001 08:00 AM 16,384 prflbmsg.dll
08/18/2001 08:00 AM 16,384 avmeter.dll
08/18/2001 08:00 AM 16,384 fmifs.dll
08/18/2001 08:00 AM 16,384 icfgnt5.dll
08/29/2002 06:41 AM 16,384 nddenb32.dll
08/29/2002 06:41 AM 16,384 odbc32gt.dll
08/18/2001 08:00 AM 16,384 version.dll
08/18/2001 08:00 AM 16,384 deskadp.dll
08/29/2002 06:40 AM 16,384 ds32gt.dll
08/18/2001 08:00 AM 16,384 mmfutil.dll
08/18/2001 08:00 AM 16,896 oleaccrc.dll
02/17/2003 10:16 AM 16,896 msyuv.dll
08/29/2002 06:41 AM 16,896 snmpapi.dll
08/18/2001 08:00 AM 16,896 deskmon.dll
08/18/2001 08:00 AM 16,896 vss_ps.dll
08/18/2001 08:00 AM 16,896 perfnet.dll
08/18/2001 08:00 AM 16,896 cfgmgr32.dll
06/22/2004 08:45 PM 17,212 SIntf32.dll
08/18/2001 08:00 AM 17,408 mcicda.dll
08/29/2002 06:41 AM 17,408 wtsapi32.dll
08/18/2001 08:00 AM 17,408 esentprf.dll
08/29/2002 06:41 AM 17,408 psapi.dll
08/18/2001 08:00 AM 17,408 wshtcpip.dll
07/01/2004 06:08 PM 17,408 qmgrprxy.dll
07/12/2004 12:26 PM 17,637 mtjpgh.dll
08/18/2001 08:00 AM 17,920 ureg.dll
08/18/2001 08:00 AM 17,920 midimap.dll
08/18/2001 08:00 AM 17,920 iaspolcy.dll
08/18/2001 08:00 AM 18,176 vga64k.dll
08/18/2001 08:00 AM 18,432 feclient.dll
12/12/2002 12:14 AM 18,432 dswave.dll
08/18/2001 08:00 AM 18,432 deskperf.dll
08/18/2001 08:00 AM 18,432 dmintf.dll
08/18/2001 08:00 AM 18,432 sclgntfy.dll
08/18/2001 08:00 AM 18,432 rsmps.dll
08/18/2001 08:00 AM 18,944 wmiprop.dll
08/18/2001 08:00 AM 18,944 mimefilt.dll
08/18/2001 08:00 AM 18,944 winstrm.dll
12/12/2002 12:14 AM 18,944 encapi.dll
08/18/2001 08:00 AM 18,944 lpk.dll
08/18/2001 08:00 AM 18,944 ws2help.dll
08/18/2001 08:00 AM 19,200 tapi.dll
08/18/2001 08:00 AM 19,456 dmocx.dll
08/29/2002 06:40 AM 19,456 ersvc.dll
08/29/2002 06:41 AM 19,456 licmgr10.dll
12/12/2002 12:14 AM 19,968 dpvacm.dll
12/11/2002 03:09 PM 20,480 wmpui.dll
08/17/2001 10:36 PM 20,480 OVComC.dll
08/29/2002 06:40 AM 20,480 dbmsadsn.dll
08/18/2001 08:00 AM 20,480 mtxdm.dll
08/18/2001 08:00 AM 20,480 msorc32r.dll
12/11/2002 03:09 PM 20,480 wmpcd.dll
12/11/2002 03:09 PM 20,480 wmpcore.dll
08/18/2001 08:00 AM 20,535 vfpodbc.dll
08/18/2001 08:00 AM 20,553 odpdx32.dll
08/18/2001 08:00 AM 20,553 odexl32.dll
08/18/2001 08:00 AM 20,553 odfox32.dll
08/18/2001 08:00 AM 20,554 oddbse32.dll
08/18/2001 08:00 AM 20,554 odtext32.dll
08/18/2001 08:00 AM 20,992 ipxwan.dll
08/18/2001 08:00 AM 20,992 mciseq.dll
08/18/2001 08:00 AM 20,992 seclogon.dll
08/18/2001 08:00 AM 20,992 mfcsubs.dll
02/28/2003 06:26 PM 21,264 msjdbc10.dll
08/18/2001 08:00 AM 21,504 dmserver.dll
08/18/2001 08:00 AM 21,504 ipxrip.dll
08/18/2001 08:00 AM 21,504 wsock32.dll
06/22/2004 08:45 PM 21,840 SIntfNT.dll
12/12/2002 12:14 AM 22,016 dpmodemx.dll
08/18/2001 08:00 AM 22,016 davclnt.dll
08/18/2001 08:00 AM 22,016 olesvr32.dll
08/18/2001 08:00 AM 22,016 w32topl.dll
08/18/2001 08:00 AM 22,016 mciwave.dll
08/18/2001 08:00 AM 22,016 rpcns4.dll
08/29/2002 06:41 AM 22,016 udhisapi.dll
08/29/2002 06:41 AM 22,528 mslbui.dll
08/29/2002 06:41 AM 22,528 slayerxp.dll
08/18/2001 08:00 AM 22,528 rasmxs.dll
08/29/2002 06:41 AM 22,528 shfolder.dll
08/18/2001 08:00 AM 22,528 hid.dll
08/18/2001 08:00 AM 23,040 perfos.dll
08/18/2001 08:00 AM 23,040 shscrap.dll
08/18/2001 08:00 AM 23,040 iernonce.dll
08/18/2001 08:00 AM 23,552 rasrad.dll
11/26/2002 07:03 PM 23,552 wmdmps.dll
08/29/2002 06:41 AM 23,552 wzcsapi.dll
08/18/2001 08:00 AM 23,552 perfdisk.dll
08/18/2001 08:00 AM 23,552 iasacct.dll
08/18/2001 08:00 AM 23,552 sfmapi.dll
08/18/2001 08:00 AM 23,552 rsvpmsg.dll
08/18/2001 08:00 AM 24,064 vdmdbg.dll
12/12/2002 12:14 AM 24,064 ddrawex.dll
08/18/2001 08:00 AM 24,064 olesvr.dll
10/27/2003 08:13 PM 24,576 odbcbcp.dll
08/29/2002 03:36 AM 24,576 dbmsvinn.dll
08/29/2002 06:41 AM 24,576 nmmkcert.dll
08/29/2002 03:36 AM 24,576 dbmsrpcn.dll
12/18/2002 08:31 AM 24,576 msxml3a.dll
08/18/2001 08:00 AM 24,603 sqlwid.dll
08/18/2001 08:00 AM 24,661 spxcoins.dll
08/18/2001 08:00 AM 25,088 mtxlegih.dll
08/29/2002 06:40 AM 25,600 dfsshlex.dll
08/18/2001 08:00 AM 25,600 comaddin.dll
08/18/2001 08:00 AM 25,600 pstorsvc.dll
08/18/2001 08:00 AM 25,600 aaaamon.dll
08/18/2001 08:00 AM 25,600 winipsec.dll
08/18/2001 08:00 AM 25,600 utildll.dll
08/18/2001 08:00 AM 25,600 msvidc32.dll
08/18/2001 08:00 AM 26,112 adptif.dll
08/18/2001 08:00 AM 26,224 odbc16gt.dll
10/17/1999 07:01 PM 26,384 FM20ENU.DLL
08/18/2001 08:00 AM 26,624 cnvfat.dll
08/18/2001 08:00 AM 26,624 msxmlr.dll
08/18/2001 08:00 AM 26,624 safrdm.dll
08/18/2001 08:00 AM 26,624 scredir.dll
07/13/1995 02:01 AM 26,768 ctl3d.dll
08/18/2001 08:00 AM 27,136 batmeter.dll
11/26/2002 07:03 PM 27,136 wmdmlog.dll
08/18/2001 08:00 AM 27,136 ctl3d32.dll
08/18/2001 08:00 AM 27,136 mspatcha.dll
08/18/2001 08:00 AM 27,136 atmlib.dll
08/18/2001 08:00 AM 27,136 sendcmsg.dll
12/12/2002 12:14 AM 27,136 dmband.dll
08/29/2002 06:41 AM 27,136 ssdpapi.dll
08/18/2001 08:00 AM 27,200 ctl3dv2.dll
08/18/2001 08:00 AM 27,648 ccfgnt.dll
08/29/2002 04:08 AM 27,648 pidgen.dll
08/18/2001 08:00 AM 28,672 profmap.dll
01/10/2002 01:40 AM 28,672 EA02.dll
08/29/2002 03:34 AM 28,672 dbnmpntw.dll
07/19/2002 12:07 PM 28,672 CTSPKHLP.DLL
08/18/2001 08:00 AM 28,672 isrdbg32.dll
01/09/2002 01:40 AM 28,672 EA01.dll
08/18/2001 08:00 AM 28,721 wshcon.dll
08/18/2001 08:00 AM 28,746 msrecr40.dll
08/29/2002 06:40 AM 29,184 csrsrv.dll
08/18/2001 08:00 AM 29,184 cryptdll.dll
08/18/2001 08:00 AM 29,696 rtipxmib.dll
01/15/1997 04:00 PM 29,696 VB5StKit.dll
08/18/2001 08:00 AM 30,160 compobj.dll
08/29/2002 06:40 AM 30,208 imgutil.dll
08/18/2001 08:00 AM 30,720 iologmsg.dll
08/18/2001 08:00 AM 30,720 plustab.dll
03/16/2004 02:44 PM 30,749 vbajet32.dll
08/18/2001 08:00 AM 31,232 traffic.dll
08/18/2001 08:00 AM 31,232 inetmib1.dll
08/29/2002 06:41 AM 31,744 pid.dll
08/29/2002 06:41 AM 32,256 mnmdd.dll
03/24/2004 10:04 AM 32,256 nvcodins.dll
02/22/1996 12:09 PM 32,256 Decln.dll
08/18/2001 08:00 AM 32,256 perfproc.dll
10/21/2003 07:06 PM 32,256 msgsvc.dll
08/18/2001 08:00 AM 32,256 iashlpr.dll
08/29/2002 06:41 AM 32,256 umandlg.dll
03/24/2004 10:04 AM 32,256 nvcod.dll
01/22/2001 03:25 AM 32,768 ATHPRXY.DLL
08/18/2001 08:00 AM 32,768 cnetcfg.dll
03/24/2003 09:00 AM 32,768 dpnhpast.dll
08/29/2002 06:40 AM 32,768 cfgbkend.dll
08/18/2001 08:00 AM 32,816 commdlg.dll
08/18/2001 08:00 AM 33,040 dplay.dll
08/18/2001 08:00 AM 33,280 racpldlg.dll
12/12/2002 12:14 AM 33,280 dmloader.dll
08/18/2001 08:00 AM 33,280 eventcls.dll
08/18/2001 08:00 AM 33,280 msobjs.dll
12/12/2002 12:14 AM 34,304 mciqtz32.dll
08/18/2001 08:00 AM 34,304 olecnv32.dll
05/22/2003 10:01 PM 34,304 PNGFILT.DLL
08/23/2001 05:00 AM 34,816 d3dpmesh.dll
08/18/2001 08:00 AM 34,816 atmpvcno.dll
08/29/2002 06:40 AM 35,328 dfrgsnap.dll
09/21/2000 01:47 AM 35,328 picn20.dll
08/18/2001 08:00 AM 35,328 pifmgr.dll
08/18/2001 08:00 AM 35,840 jgmd400.dll
08/18/2001 08:00 AM 35,840 narrhook.dll
08/18/2001 08:00 AM 35,840 mssign32.dll
08/18/2001 08:00 AM 36,352 cmutil.dll
08/29/2002 06:41 AM 36,352 sens.dll
08/29/2002 06:41 AM 36,352 rshx32.dll
07/19/2002 11:54 AM 36,864 CTEMUPIA.DLL
08/17/2001 03:35 PM 36,864 sfman32.dll
03/24/2004 10:04 AM 36,864 nvwddi.dll
08/18/2001 08:00 AM 36,864 ntsdexts.dll
09/11/2001 08:21 AM 36,864 CTEMUPIADEFAULT.DLL
12/18/2002 08:31 AM 36,864 xmlparse.dll
08/18/2001 08:00 AM 36,864 ntmsevt.dll
03/29/2004 09:48 PM 36,864 mf3216.dll
08/18/2001 08:00 AM 36,864 mscpxl32.dLL
08/29/2002 06:40 AM 36,922 imeshare.dll
08/18/2001 08:00 AM 37,376 perfctrs.dll
08/18/2001 08:00 AM 37,888 pstorec.dll
01/10/2003 02:43 PM 37,888 hhsetup.dll
08/18/2001 08:00 AM 37,916 msxml2r.dll
09/02/1998 04:28 AM 38,160 LMRTREND.dll
08/29/2002 06:41 AM 38,400 ntlanman.dll
08/29/2002 06:41 AM 38,400 ntmsapi.dll
07/05/2000 05:16 PM 38,400 clsNOL22.dll
08/29/2002 06:40 AM 38,912 audiosrv.dll
08/29/2002 06:41 AM 38,912 wsnmp32.dll
08/18/2001 08:00 AM 39,424 safrcdlg.dll
08/18/2001 08:00 AM 39,424 ddeml.dll
08/18/2001 08:00 AM 39,744 ole2.dll
08/18/2001 08:00 AM 39,936 rtutils.dll
08/18/2001 08:00 AM 39,936 ipxrtmgr.dll
08/18/2001 08:00 AM 39,936 msisip.dll
08/18/2001 08:00 AM 39,936 htui.dll
08/18/2001 08:00 AM 40,448 webhits.dll
08/18/2001 08:00 AM 40,448 tcpmon.dll
07/06/1999 03:13 PM 40,960 EAX.DLL
08/18/2001 08:00 AM 40,960 safrslv.dll
08/18/2001 08:00 AM 40,960 tcpmonui.dll
08/18/2001 08:00 AM 41,019 usrsvpia.dll
04/30/2002 08:02 PM 41,068 ActPanel.dll
08/18/2001 08:00 AM 41,472 iasads.dll
08/18/2001 08:00 AM 41,984 msports.dll
08/17/2001 10:36 PM 41,984 OVUI2RC.dll
08/29/2002 06:41 AM 42,496 ncobjapi.dll
12/20/2001 09:00 AM 42,496 AudCtrl.dll
08/18/2001 08:00 AM 42,496 jgpl400.dll
08/18/2001 08:00 AM 42,768 dpwsock.dll
08/29/2002 06:41 AM 43,008 ssdpsrv.dll
06/24/2004 06:22 PM 43,520 CmdLineExt03.dll
08/23/2001 05:00 AM 44,032 dimap.dll
08/29/2002 06:40 AM 44,032 basesrv.dll
08/18/2001 08:00 AM 44,032 msxml3r.dll
03/03/2003 04:57 PM 44,032 MSIDENT.DLL
08/18/2001 08:00 AM 44,032 dnsrslvr.dll
08/29/2002 06:41 AM 44,032 regapi.dll
08/18/2001 08:00 AM 44,544 jgaw400.dll
08/17/2001 10:36 PM 44,544 OVUI2.dll
08/18/2001 08:00 AM 44,544 hticons.dll
08/18/2001 08:00 AM 45,056 camocx.dll
08/18/2001 08:00 AM 45,056 msprivs.dll
08/18/2001 08:00 AM 45,083 dispex.dll
08/18/2001 08:00 AM 45,116 usrvoica.dll
08/29/2002 06:40 AM 45,568 docprop2.dll
08/18/2001 08:00 AM 45,568 cnbjmon.dll
08/18/2001 08:00 AM 45,568 jgsd400.dll
08/18/2001 08:00 AM 45,568 iyuv_32.dll
03/24/2004 10:04 AM 46,080 nvmctray.dll
08/18/2001 08:00 AM 46,080 docprop.dll
08/18/2001 08:00 AM 46,592 wdigest.dll
08/18/2001 08:00 AM 46,592 pmspl.dll
08/18/2001 08:00 AM 46,592 mmcshext.dll
08/18/2001 08:00 AM 47,104 mspmspsv.dll
08/18/2001 08:00 AM 47,104 mprui.dll
08/18/2001 08:00 AM 47,104 dssec.dll
02/17/2003 10:16 AM 47,104 wstdecod.dll
08/23/2001 05:00 AM 47,616 d3dxof.dll
10/11/2002 03:08 PM 47,616 INETRES.DLL
08/18/2001 08:00 AM 47,952 jobexec.dll
08/29/2002 06:41 AM 48,128 winsta.dll
08/29/2002 06:41 AM 48,640 vdmredir.dll
08/18/2001 08:00 AM 48,640 cryptext.dll
08/29/2002 06:40 AM 49,152 browser.dll
10/10/2000 01:00 AM 49,152 DartObjects.dll
08/18/2001 08:00 AM 49,152 mprdim.dll
08/29/2002 06:41 AM 49,152 npptools.dll
08/29/2002 06:40 AM 49,152 eventlog.dll
08/18/2001 08:00 AM 49,179 sqlwoa.dll
08/18/2001 08:00 AM 49,209 usrv80a.dll
08/18/2001 08:00 AM 49,211 usrsdpia.dll
08/18/2001 08:00 AM 49,211 usrvpa.dll
08/29/2002 06:41 AM 49,664 vfwwdm32.dll
08/29/2002 06:40 AM 49,664 ixsso.dll
08/18/2001 08:00 AM 50,176 loghours.dll
08/18/2001 08:00 AM 50,176 mdhcp.dll
08/18/2001 08:00 AM 50,688 dmutil.dll
08/18/2001 08:00 AM 50,688 msvcirt.dll
08/29/2002 06:39 AM 51,200 wmerrenu.dll
08/18/2001 08:00 AM 51,200 authz.dll
08/18/2001 08:00 AM 51,200 dfrgres.dll
08/18/2001 08:00 AM 51,456 vga256.dll
08/18/2001 08:00 AM 51,712 regsvc.dll
03/29/2004 09:48 PM 51,712 msasn1.dll
08/18/2001 08:00 AM 51,712 synceng.dll
08/18/2001 08:00 AM 51,712 dataclen.dll
08/18/2001 08:00 AM 52,224 tsappcmp.dll
11/26/2002 07:03 PM 52,224 mspmsnsv.dll
08/29/2002 06:41 AM 52,224 secur32.dll
08/18/2001 08:00 AM 53,248 servdeps.dll
08/18/2001 08:00 AM 53,248 sendmail.dll
05/30/2003 09:00 AM 53,248 devenum.dll
08/18/2001 08:00 AM 53,248 cryptnet.dll
07/19/2002 12:07 PM 53,248 Ac3api.dll
06/17/1998 06:08 PM 53,248 MFC42ENU.DLL
08/18/2001 08:00 AM 53,279 odbcji32.dll
01/10/2004 07:36 AM 53,279 msjter40.dll
08/18/2001 08:00 AM 53,305 usrlbva.dll
08/18/2001 08:00 AM 53,520 dpserial.dll
03/25/2003 04:40 PM 53,760 cryptsvc.dll
08/29/2002 06:41 AM 54,272 rastapi.dll
08/18/2001 08:00 AM 54,272 stclient.dll
08/29/2002 06:40 AM 54,272 clusapi.dll
08/29/2002 06:41 AM 54,784 samlib.dll
01/05/2002 06:38 AM 54,784 msvci70.dll
10/20/1998 04:05 PM 54,784 Inetwh32.dll
08/18/2001 08:00 AM 54,784 icmui.dll
08/18/2001 08:00 AM 54,784 msdtclog.dll
08/18/2001 08:00 AM 54,784 resutils.dll
08/29/2002 06:40 AM 55,296 digest.dll
08/29/2002 06:41 AM 55,808 rasman.dll
08/18/2001 08:00 AM 55,808 mpr.dll
08/29/2002 06:41 AM 56,320 remotepg.dll
08/29/2002 06:39 AM 56,320 mshtmler.dll
08/18/2001 08:00 AM 56,320 miglibnt.dll
08/29/2002 06:41 AM 56,832 wzcdlg.dll
08/18/2001 08:00 AM 57,344 admparse.dll
03/13/2002 04:25 PM 57,344 CTAGENT.DLL
08/29/2002 06:41 AM 57,856 licwmi.dll
08/18/2001 08:00 AM 57,856 ntlanui.dll
08/18/2001 08:00 AM 57,856 scripto.dll
08/29/2002 06:41 AM 57,856 raschap.dll
12/12/2002 12:14 AM 58,368 dmcompos.dll
08/29/2002 06:41 AM 58,880 pautoenr.dll
05/31/2002 04:40 PM 59,112 SymStore.dll
08/18/2001 08:00 AM 59,392 iassvcs.dll
08/29/2002 06:40 AM 59,392 iesetup.dll
08/29/2002 06:40 AM 59,392 6to4svc.dll
08/29/2002 06:40 AM 59,904 cabinet.dll
08/29/2002 06:41 AM 60,416 shimeng.dll
08/18/2001 08:00 AM 60,416 msratelc.dll
08/18/2001 08:00 AM 60,928 ocmanage.dll
08/18/2001 08:00 AM 61,168 msacm.dll
08/29/2002 06:41 AM 61,440 odbccu32.dll
08/18/2001 08:00 AM 61,440 icwphbk.dll
08/29/2002 06:41 AM 61,440 odbccr32.dll
10/27/2003 08:12 PM 61,440 DBnetlib.dll
08/18/2001 08:00 AM 61,500 usrcntra.dll
08/18/2001 08:00 AM 61,952 dpnwsock.dll
08/29/2002 06:41 AM 61,952 webclnt.dll
08/18/2001 08:00 AM 61,952 osuninst.dll
08/29/2002 06:41 AM 61,952 sti.dll
08/18/2001 08:00 AM 62,464 iasnap.dll
08/29/2002 06:40 AM 62,464 adsmsext.dll
08/18/2001 08:00 AM 62,464 dpnmodem.dll
08/18/2001 08:00 AM 62,976 dsauth.dll
08/29/2002 06:40 AM 62,976 browselc.dll
08/29/2002 06:41 AM 62,976 shgina.dll
02/28/2003 06:26 PM 63,248 javaprxy.dll
08/29/2002 06:41 AM 63,488 srclient.dll
08/18/2001 08:00 AM 64,000 avicap32.dll
12/12/2002 12:14 AM 64,512 amstream.dll
08/18/2001 08:00 AM 64,512 acctres.dll
08/29/2002 06:40 AM 64,512 ciodm.dll
03/05/2004 10:16 PM 64,512 colbact.dll
08/18/2001 08:00 AM 64,512 ntdsapi.dll
03/05/2004 10:16 PM 64,512 mtxclu.dll
08/18/2001 08:00 AM 65,024 msaudite.dll
08/18/2001 08:00 AM 65,024 msvcrt40.dll
07/19/2002 11:43 AM 65,536 a3d.dll
08/29/2002 06:41 AM 65,536 msconf.dll
08/18/2001 08:00 AM 65,536 jgsh400.dll
08/18/2001 08:00 AM 65,585 wshext.dll
08/18/2001 08:00 AM 66,048 msw3prt.dll
08/18/2001 08:00 AM 66,560 scarddlg.dll
08/18/2001 08:00 AM 66,560 console.dll
08/18/2001 08:00 AM 66,560 ipxsap.dll
08/29/2002 06:40 AM 66,560 faultrep.dll
08/29/2002 06:41 AM 66,560 spoolss.dll
08/18/2001 08:00 AM 66,560 mmcbase.dll
08/17/2001 06:36 PM 67,072 usbui.dll
08/18/2001 08:00 AM 67,072 msacm32.dll
08/29/2002 06:41 AM 67,584 msctfp.dll
03/24/2003 09:00 AM 68,096 dpnhupnp.dll
08/29/2002 06:41 AM 68,096 mscms.dll
08/18/2001 08:00 AM 68,096 inetpp.dll
12/12/2002 12:14 AM 68,096 dsdmoprp.dll
08/18/2001 08:00 AM 68,608 olecli32.dll
08/18/2001 08:00 AM 68,928 mmsystem.dll
08/18/2001 08:00 AM 69,120 mprddm.dll
08/18/2001 08:00 AM 69,120 unimdmat.dll
08/18/2001 08:00 AM 69,120 olethk32.dll
08/18/2001 08:00 AM 69,120 ipxpromn.dll
08/18/2001 08:00 AM 69,584 avicap.dll
12/18/2002 08:31 AM 69,632 xmltok.dll
08/18/2001 08:00 AM 69,632 msr2c.dll
08/18/2001 08:00 AM 69,632 icwdial.dll
08/29/2002 06:40 AM 69,632 inseng.dll
08/18/2001 08:00 AM 69,632 spnike.dll
08/18/2001 08:00 AM 69,699 usrcoina.dll
08/29/2002 06:40 AM 70,144 cryptdlg.dll
08/18/2001 08:00 AM 70,656 wiascr.dll
08/18/2001 08:00 AM 70,656 sprio600.dll
08/18/2001 08:00 AM 70,656 ifsutil.dll
08/29/2002 06:41 AM 71,168 storprop.dll
08/29/2002 06:40 AM 71,680 browsewm.dll
08/18/2001 08:00 AM 72,192 sprio800.dll
08/18/2001 08:00 AM 73,216 avwav.dll
08/18/2001 08:00 AM 73,728 csseqchk.dll
08/29/2002 06:40 AM 73,728 ils.dll
08/18/2001 08:00 AM 73,802 msrclr40.dll
08/18/2001 08:00 AM 74,240 dhcpsapi.dll
08/18/2001 08:00 AM 74,752 netui0.dll
08/29/2002 06:40 AM 74,810 atl.dll
08/18/2001 08:00 AM 75,264 ws2_32.dll
08/29/2002 06:46 AM 75,912 rdpwsx.dll
08/29/2002 06:40 AM 76,288 avifil32.dll
12/12/2002 12:14 AM 76,800 dmscript.dll
04/12/2004 11:11 PM 76,800 dpwsockx.dll
08/18/2001 08:00 AM 77,824 asycfilt.dll
07/11/2001 11:51 AM 77,824 EAXAC3.DLL
08/18/2001 08:00 AM 77,824 isign32.dll
08/18/2001 08:00 AM 77,850 hlink.dll
08/18/2001 08:00 AM 77,883 usrrtosa.dll
08/18/2001 08:00 AM 77,890 usrdpa.dll
08/18/2001 08:00 AM 78,848 tapiui.dll
10/15/1996 09:53 AM 78,848 INLOADER.DLL
08/18/2001 08:00 AM 79,360 fontsub.dll
08/18/2001 08:00 AM 79,360 mprapi.dll
08/18/2001 08:00 AM 80,128 msapsspc.dll
08/18/2001 08:00 AM 80,384 cabview.dll
08/18/2001 08:00 AM 80,384 autodisc.dll
08/18/2001 08:00 AM 80,384 mciavi32.dll
08/29/2002 06:41 AM 80,896 ntprint.dll
08/18/2001 08:00 AM 81,408 fsusd.dll
08/29/2002 06:41 AM 81,920 trkwks.dll
06/12/1998 12:01 PM 81,946 VB5JP.dll
04/16/2004 08:56 PM 82,432 fldrclnr.dll
08/30/1995 02:02 AM 82,432 ctwflt32.dll
02/04/2002 02:43 AM 82,432 msxml4r.dll
12/11/2002 05:34 PM 82,432 drmstor.dll
08/18/2001 08:00 AM 82,432 ufat.dll
03/05/2004 10:16 PM 82,432 mtxoci.dll
08/18/2001 08:00 AM 82,432 comrepl.dll
08/29/2002 06:41 AM 82,944 psbase.dll
08/18/2001 08:00 AM 82,944 rasauto.dll
08/29/2002 06:40 AM 82,944 iphlpapi.dll
08/18/2001 08:00 AM 82,944 olecli.dll
11/21/2003 10:07 AM 82,984 S32EVNT1.DLL
08/18/2001 08:00 AM 83,968 ipxmontr.dll
01/05/2002 05:18 AM 84,992 atl70.dll
08/18/2001 08:00 AM 84,992 dskquota.dll
06/05/1998 02:00 AM 84,992 sfcvrt32.dll
08/18/2001 08:00 AM 85,020 dgsetup.dll
08/18/2001 08:00 AM 85,504 catsrvps.dll
08/29/2002 06:41 AM 86,016 xactsrv.dll
07/05/2000 05:03 PM 86,016 clsNCX22.dll
08/18/2001 08:00 AM 86,073 usrfaxa.dll
08/29/2002 06:41 AM 86,528 wlnotify.dll
08/18/2001 08:00 AM 86,528 iassam.dll
08/18/2001 08:00 AM 87,040 srvsvc.dll
08/29/2002 06:46 AM 87,304 rdpdd.dll
08/18/2001 08:00 AM 87,552 polstore.dll
08/18/2001 08:00 AM 87,552 occache.dll
08/29/2002 06:41 AM 88,064 tscfgwmi.dll
08/18/2001 08:00 AM 88,064 mydocs.dll
12/18/2002 08:31 AM 89,360 VB5DB.DLL
08/18/2001 08:00 AM 89,600 langwrbk.dll
08/18/2001 08:00 AM 89,600 slbiop.dll
08/18/2001 08:00 AM 89,600 cscdll.dll
08/18/2001 08:00 AM 90,112 odbcint.dll
08/18/2001 08:00 AM 90,112 mycomput.dll
08/18/2001 08:00 AM 90,112 rsvpsp.dll
03/03/2003 04:57 PM 91,136 MSOERT2.DLL
08/29/2002 06:41 AM 91,136 rastls.dll
08/29/2002 06:40 AM 91,136 advpack.dll
08/18/2001 08:00 AM 91,648 loadperf.dll
08/18/2001 08:00 AM 93,184 winscard.dll
04/03/2000 06:52 PM 94,208 msstkprp.dll
08/18/2001 08:00 AM 94,282 msencode.dll
08/29/2002 06:41 AM 95,744 nlhtml.dll
08/18/2001 08:00 AM 96,256 rcbdyctl.dll
03/05/2004 10:16 PM 97,280 txflog.dll
12/12/2002 12:14 AM 97,280 dmusic.dll
10/27/2003 08:13 PM 98,304 ODBCCP32.dll
08/18/2001 08:00 AM 98,304 rtm.dll
08/29/2002 06:41 AM 98,304 oleprn.dll
08/18/2001 08:00 AM 98,304 actxprxy.dll
12/11/2002 05:34 PM 98,304 wmpshell.dll
12/12/2002 12:14 AM 98,816 dmstyle.dll
08/29/2002 06:41 AM 99,328 win32spl.dll
08/18/2001 08:00 AM 99,840 mprmsg.dll
08/29/2002 06:40 AM 99,840 dhcpcsvc.dll
12/12/2002 12:14 AM 100,864 dmsynth.dll
08/18/2001 08:00 AM 101,888 gpkcsp.dll
08/18/2001 08:00 AM 102,457 usrv42a.dll
08/18/2001 08:00 AM 102,912 apcups.dll
08/18/2001 08:00 AM 102,912 msaatext.dll
08/18/2001 08:00 AM 103,424 EqnClass.Dll
08/29/2002 06:40 AM 103,424 dgnet.dll
08/29/2002 06:40 AM 103,936 imm32.dll
08/18/2001 08:00 AM 103,936 mstlsapi.dll
08/18/2001 08:00 AM 104,448 wiavideo.dll
08/18/2001 08:00 AM 106,496 dsuiext.dll
08/29/2002 06:41 AM 106,496 url.dll
07/19/2002 11:54 AM 106,496 CTASIO.DLL
12/11/2002 05:34 PM 106,496 wmpasf.dll
06/26/2000 04:45 AM 106,496 TwnLib20.dll
07/19/2002 11:53 AM 106,496 CTDPROXY.DLL
08/18/2001 08:00 AM 106,496 olepro32.dll
08/29/2002 06:41 AM 107,008 umpnpmgr.dll
08/18/2001 08:00 AM 107,008 aclui.dll
08/18/2001 08:00 AM 107,520 rend.dll
01/13/1995 02:10 PM 108,032 mfcuia32.dll
08/18/2001 08:00 AM 108,464 netapi.dll
08/18/2001 08:00 AM 108,544 mdminst.dll
08/29/2002 06:41 AM 108,544 msv1_0.dll
08/18/2001 08:00 AM 109,456 avifile.dll
08/18/2001 08:00 AM 109,568 cic.dll
08/29/2002 06:41 AM 109,568 offfilt.dll
08/29/2002 06:41 AM 110,080 sbeio.dll
03/05/2004 10:16 PM 110,080 clbcatex.dll
07/19/2002 11:55 AM 110,592 PIAPROXY.DLL
07/19/2002 11:54 AM 110,592 COMMONFX.DLL
08/18/2001 08:00 AM 110,592 inetcplc.dll
08/18/2001 08:00 AM 110,592 iccvid.dll
08/18/2001 08:00 AM 112,128 mapi32.dll
08/18/2001 08:00 AM 112,128 mapistub.dll
12/12/2002 12:14 AM 112,128 dpvvox.dll
08/29/2002 06:41 AM 112,128 ntmarta.dll
08/29/2002 06:40 AM 113,152 idq.dll
08/29/2002 06:40 AM 113,152 dfrgui.dll
08/29/2002 06:41 AM 113,664 msvfw32.dll
08/29/2002 06:40 AM 114,176 input.dll
08/29/2002 05:20 AM 115,200 dpcdll.dll
08/29/2002 06:40 AM 115,712 apphelp.dll
08/25/2003 06:06 PM 115,808 iuctl.dll
06/29/2004 04:13 PM 115,936 SymRedir.dll
08/29/2002 06:41 AM 116,224 shsvcs.dll
08/18/2001 08:00 AM 116,224 iasrad.dll
08/18/2001 08:00 AM 116,736 glu32.dll
08/17/2001 10:36 PM 116,736 OVCodec2.dll
08/18/2001 08:00 AM 117,760 oledlg.dll
08/29/2002 06:41 AM 117,760 stobject.dll
08/18/2001 08:00 AM 118,784 scardssp.dll
11/25/2002 01:00 AM 118,784 DartWeb.dll
08/29/2002 06:41 AM 118,784 wmsdmoe.dll
08/18/2001 08:00 AM 118,784 dmdskres.dll
03/14/2000 11:04 AM 118,784 MSSTDFMT.DLL
08/29/2002 06:41 AM 119,808 wiadss.dll
08/18/2001 08:00 AM 119,808 mmutilse.dll
10/21/2003 07:06 PM 119,808 wkssvc.dll
08/29/2002 06:41 AM 120,320 upnp.dll
11/14/2002 12:58 PM 120,320 ir41_qc.dll
08/18/2001 08:00 AM 121,856 exts.dll
08/29/2002 06:41 AM 122,880 odbcconf.dll
06/22/2004 08:43 PM 123,392 itss.dll
08/29/2002 06:41 AM 124,928 webvw.dll
08/29/2002 01:27 AM 124,928 dssenh.dll
09/30/2002 10:58 AM 125,440 shmedia.dll
08/18/2001 08:00 AM 125,952 ifmon.dll
07/05/2000 05:02 PM 125,952 clsNPB22.dll
08/18/2001 08:00 AM 126,912 msvideo.dll
10/27/2003 08:09 PM 126,976 msdart.dll
08/29/2002 06:40 AM 126,976 imagehlp.dll
08/29/2002 06:40 AM 126,976 ieakeng.dll
08/18/2001 08:00 AM 127,552 cliconfg.dll
08/29/2002 04:05 AM 127,872 HAL.DLL
08/18/2001 08:00 AM 129,536 acledit.dll
08/18/2001 08:00 AM 130,048 sdpblb.dll
08/29/2002 06:41 AM 130,560 sti_ci.dll
03/24/2004 10:04 AM 131,072 nvinstnt.dll
08/29/2002 06:41 AM 131,072 msorcl32.dll
08/29/2002 06:41 AM 132,096 msrating.dll
08/29/2002 06:41 AM 133,120 sfc_os.dll
08/29/2002 06:41 AM 133,632 nwprovau.dll
08/29/2002 01:27 AM 133,632 rsaenh.dll
08/29/2002 06:40 AM 134,144 ipv6mon.dll
08/18/2001 08:00 AM 134,656 netid.dll
07/19/2002 11:54 AM 135,168 OpenAL32.dll
08/29/2002 06:40 AM 135,680 dsprop.dll
08/29/2002 06:41 AM 135,680 rdchost.dll
03/29/2004 09:48 PM 136,704 schannel.dll
08/18/2001 08:00 AM 137,216 hotplug.dll
08/29/2002 06:41 AM 137,216 ntshrui.dll
08/18/2001 08:00 AM 138,752 swprv.dll
08/29/2002 06:40 AM 139,264 dnsapi.dll
02/28/2003 06:26 PM 139,536 javaee.dll
08/29/2002 06:40 AM 139,776 adsldpc.dll
08/18/2001 08:00 AM 141,312 iasrecst.dll
08/18/2001 08:00 AM 142,336 cdfview.dll
08/18/2001 08:00 AM 142,848 capesnpn.dll
08/18/2001 08:00 AM 143,360 rasmontr.dll
12/11/2002 03:16 PM 143,360 wmidx.dll
08/29/2002 06:41 AM 143,872 msimtf.dll
08/28/2003 09:57 AM 143,872 itircl.dll
08/18/2001 08:00 AM 144,384 dskquoui.dll
08/18/2001 08:00 AM 144,896 jgdw400.dll
08/18/2001 08:00 AM 144,896 initpki.dll
08/18/2001 08:00 AM 145,408 wiavusd.dll
08/18/2001 08:00 AM 145,408 modemui.dll
08/18/2001 08:00 AM 146,432 keymgr.dll
08/18/2001 08:00 AM 146,432 msls31.dll
08/18/2001 08:00 AM 147,456 comsnap.dll
08/29/2002 06:41 AM 147,456 odbctrac.dll
08/18/2001 08:00 AM 147,483 scrrun.dll
10/17/2002 12:13 AM 147,495 rmoc3260.dll
03/28/2002 04:50 AM 147,512 hpzlnt05.dll
08/18/2001 08:00 AM 147,968 mdwmdmsp.dll
08/18/2001 08:00 AM 149,019 crtdll.dll
01/13/1995 02:10 PM 149,504 mfcans32.dll
03/05/2004 10:16 PM 150,528 msdtcuiu.dll
08/29/2002 06:40 AM 151,552 dinput.dll
04/03/2000 05:52 PM 151,552 RDOCURS.DLL
03/16/2004 01:38 PM 151,583 msjint40.dll
08/18/2001 08:00 AM 152,064 datime.dll
08/18/2001 08:00 AM 153,008 ole2nls.dll
08/18/2001 08:00 AM 154,112 ipmontr.dll
08/29/2002 06:41 AM 154,112 netman.dll
02/28/2003 06:26 PM 154,384 msawt.dll
08/29/2002 06:40 AM 155,648 encdec.dll
08/29/2002 06:40 AM 155,648 ipsecsvc.dll
07/19/2002 11:54 AM 155,648 CTOSUSER.DLL
08/18/2001 08:00 AM 155,675 scrobj.dll
08/18/2001 08:00 AM 157,696 paqsp.dll
06/30/2004 07:59 PM 158,720 xpob2res.dll
08/29/2002 06:41 AM 158,720 srsvc.dll
08/29/2002 06:40 AM 158,720 credui.dll
08/29/2002 06:41 AM 158,720 rasmans.dll
11/26/2002 07:03 PM 159,232 CEWMDM.dll
08/29/2002 06:40 AM 162,816 adsldp.dll
08/18/2001 08:00 AM 163,328 oleacc.dll
08/18/2001 08:00 AM 163,328 ciadmin.dll
08/09/1999 03:40 PM 163,600 wmaudsdk.dll
08/29/2002 06:41 AM 163,840 mindex.dll
08/29/2002 06:41 AM 164,864 upnphost.dll
08/29/2002 06:40 AM 165,376 els.dll
08/29/2002 06:41 AM 165,376 tapi32.dll
08/29/2002 06:41 AM 165,376 w32time.dll
08/29/2002 06:41 AM 165,888 ntmsdba.dll
08/18/2001 08:00 AM 166,912 photowiz.dll
08/18/2001 08:00 AM 166,912 wintrust.dll
12/11/2002 03:16 PM 167,936 wmerror.dll
08/29/2002 06:41 AM 168,448 wldap32.dll
08/29/2002 06:40 AM 168,960 dinput8.dll
08/18/2001 08:00 AM 169,520 ole2disp.dll
08/29/2002 01:27 AM 169,984 sccbase.dll
08/18/2001 08:00 AM 169,984 iprtrmgr.dll
08/29/2002 06:41 AM 171,008 sccsccp.dll
08/18/2001 08:00 AM 171,008 netmsg.dll
02/28/2003 06:26 PM 171,280 jit.dll
08/29/2002 06:41 AM 171,520 winmm.dll
12/12/2002 12:14 AM 171,520 dmime.dll
08/18/2001 08:00 AM 172,032 snmpsnap.dll
08/29/2002 06:41 AM 172,032 mssap.dll
06/08/2004 06:02 PM 172,544 schedsvc.dll
07/17/2002 10:09 AM 172,664 xenroll.dll
08/18/2001 08:00 AM 174,592 cmprops.dll
08/29/2002 06:41 AM 174,592 scecli.dll
08/18/2001 08:00 AM 176,128 ftsrch.dll
08/18/2001 08:00 AM 176,157 dgrpsetu.dll
12/12/2002 12:14 AM 177,152 qcap.dll
08/18/2001 08:00 AM 177,856 typelib.dll
08/18/2001 08:00 AM 180,800 sqlunirl.dll
08/18/2001 08:00 AM 181,760 activeds.dll
08/27/1998 12:51 AM 182,032 dxtmsft3.dll
08/29/2002 06:41 AM 182,784 msutb.dll
08/25/2003 06:06 PM 182,880 iuengine.dll
08/18/2001 08:00 AM 183,296 syncui.dll
11/14/2002 12:58 PM 183,808 ir50_qcx.dll
08/18/2001 08:00 AM 184,320 dmdskmgr.dll
08/29/2002 06:40 AM 186,880 certcli.dll
12/12/2002 12:14 AM 186,880 dsdmo.dll
02/28/2003 06:26 PM 187,152 javacypt.dll
08/29/2002 04:03 AM 187,904 xpsp1res.dll
08/29/2002 06:41 AM 189,440 wuaueng.dll
08/29/2002 06:41 AM 193,536 rasppp.dll
09/02/1998 04:02 AM 194,320 qcut.dll
12/12/2002 12:14 AM 194,560 mswebdvd.dll
08/29/2002 06:40 AM 194,560 dxtrans.dll
08/29/2002 06:41 AM 196,096 mobsync.dll
09/11/2001 08:21 AM 196,608 CTEAPSFX.DLL
08/18/2001 08:00 AM 198,656 t2embed.dll
08/18/2001 08:00 AM 199,168 ir32_32.dll
11/14/2002 12:58 PM 200,192 ir50_qc.dll
08/29/2002 06:41 AM 200,192 termsrv.dll
11/26/2002 07:03 PM 201,728 mspmsp.dll
08/29/2002 06:40 AM 202,496 ati2dvag.dll
08/18/2001 08:00 AM 202,752 localsec.dll
12/12/2002 12:14 AM 203,264 dpvoice.dll
08/29/2002 06:41 AM 203,264 uxtheme.dll
08/29/2002 06:40 AM 204,288 ieaksie.dll
10/27/2003 08:09 PM 204,800 ODBC32.dll
03/28/2002 04:50 AM 208,896 hpzcoi05.dll
12/11/2002 05:34 PM 208,896 wmpns.dll
08/18/2001 08:00 AM 208,896 wavemsp.dll
08/29/2002 06:39 AM 210,944 moricons.dll
12/08/1998 06:53 PM 212,480 PCDLIB32.DLL
01/10/2004 07:36 AM 213,023 msltus40.dll
08/18/2001 08:00 AM 214,016 netevent.dll
08/29/2002 06:41 AM 217,088 rasapi32.dll
08/29/2002 06:41 AM 218,112 sbe.dll
12/11/2002 05:23 PM 218,112 wmasf.dll
04/14/2004 02:56 PM 219,648 dplayx.dll
08/18/2001 08:00 AM 221,184 ieakui.dll
11/22/2002 01:00 AM 221,184 DartSock.dll
08/18/2001 08:00 AM 222,208 compstui.dll
08/23/2001 05:00 AM 223,232 gcdef.dll
12/11/2002 05:34 PM 225,280 wmpdxm.dll
03/05/2004 10:16 PM 225,280 catsrv.dll
03/05/2004 10:16 PM 226,816 es.dll
11/14/2002 12:50 PM 226,816 srrstr.dll
08/29/2002 06:40 AM 227,840 dsquery.dll
08/18/2001 08:00 AM 227,840 avtapi.dll
08/18/2001 08:00 AM 228,352 mswsock.dll
03/03/2003 04:57 PM 228,864 MSOEACCT.DLL
08/29/2002 06:41 AM 229,888 msieftp.dll
08/18/2001 08:00 AM 230,400 netui1.dll
08/29/2002 06:40 AM 231,424 iepeers.dll
08/29/2002 06:41 AM 231,424 upnpui.dll
12/11/2002 06:09 PM 232,960 blackbox.dll
08/29/2002 06:41 AM 233,984 tapisrv.dll
08/29/2002 06:40 AM 236,032 icm32.dll
01/31/2003 04:46 PM 238,080 newdev.dll
08/29/2002 06:40 AM 238,592 compatui.dll
08/29/2002 06:40 AM 239,616 adsnt.dll
08/29/2002 06:40 AM 240,640 hnetcfg.dll
03/24/2004 10:04 AM 241,664 nvnt4cpl.dll
12/11/2002 05:34 PM 241,664 qasf.dll
12/11/2002 05:34 PM 241,664 mpg4dmod.dll
03/01/2004 02:55 PM 241,693 msjtes40.dll
08/29/2002 06:41 AM 241,725 msuni11.dll
11/26/2002 07:03 PM 245,760 mswmdm.dll
08/29/2002 06:41 AM 247,808 wow32.dll
08/18/2001 08:00 AM 247,808 iassdo.dll
08/29/2002 06:41 AM 251,904 strmdll.dll
12/11/2002 06:09 PM 253,952 msnetobj.dll
08/18/2001 08:00 AM 253,952 neth.dll
08/18/2001 08:00 AM 253,952 msvcrt20.dll
08/29/2002 06:41 AM 254,976 pdh.dll
03/29/2004 09:48 PM 257,536 gdi32.dll
12/12/2002 12:14 AM 257,536 ddraw.dll
08/29/2002 06:41 AM 258,048 webcheck.dll
08/29/2002 06:40 AM 258,048 comdlg32.dll
03/01/2004 02:55 PM 258,077 mstext40.dll
06/08/2004 06:02 PM 260,096 mstask.dll
08/29/2002 06:40 AM 263,168 devmgr.dll
08/29/2002 06:40 AM 263,680 duser.dll
03/05/2004 10:16 PM 263,680 rpcss.dll
08/29/2002 06:41 AM 264,704 wzcsvc.dll
08/18/2001 08:00 AM 266,240 inetcfg.dll
03/28/2002 04:50 AM 266,240 hpzcon05.dll
08/29/2002 06:41 AM 266,752 msctf.dll
12/12/2002 12:14 AM 268,800 qdv.dll
08/18/2001 08:00 AM 268,800 ulib.dll
07/19/2002 11:56 AM 270,336 SFMS32.DLL
08/18/2001 08:00 AM 270,365 odbcjt32.dll
08/18/2001 08:00 AM 271,360 objsel.dll
08/18/2001 08:00 AM 272,768 atmfd.dll
11/01/2002 03:26 PM 272,896 winsrv.dll
08/29/2002 06:41 AM 272,896 kerberos.dll
08/18/2001 08:00 AM 273,920 dmdlgs.dll
09/21/2000 06:53 AM 275,312 ImagXpr5.dll
08/18/2001 08:00 AM 276,480 slbcsp.dll
10/17/2002 12:13 AM 278,528 pncrt.dll
08/18/2001 08:00 AM 285,184 glmf32.dll
02/28/2003 06:26 PM 286,992 vmhelper.dll
08/29/2002 06:40 AM 294,912 iedkcs32.dll
08/29/2002 06:41 AM 295,936 localspl.dll
08/29/2002 06:41 AM 296,448 wmstream.dll
08/29/2002 06:41 AM 297,984 scesrv.dll
12/11/2002 06:50 PM 301,712 drmclien.dll
08/29/2002 06:41 AM 302,080 untfs.dll
08/29/2002 06:41 AM 305,664 msihnd.dll
06/08/2004 06:02 PM 306,688 netapi32.dll
08/29/2002 06:40 AM 307,712 cscui.dll
08/18/2001 08:00 AM 308,224 netui2.dll
08/29/2002 06:41 AM 311,327 wmv8dmod.dll
02/28/2003 04:34 PM 313,856 dx3j.dll
01/10/2004 07:36 AM 315,423 msrd3x40.dll
08/18/2001 08:00 AM 315,904 hnetwiz.dll
12/11/2002 07:12 PM 316,040 mp43dmod.dll
08/29/2002 06:41 AM 316,416 wiaservc.dll
09/25/2002 03:18 PM 316,928 zipfldr.dll
08/29/2002 06:40 AM 318,464 ippromon.dll
07/19/2002 12:07 PM 319,488 CTDEVCON.DLL
03/01/2004 02:55 PM 319,517 msexcl40.dll
08/29/2002 06:41 AM 319,760 msnsspc.dll
08/18/2001 08:00 AM 323,072 filemgmt.dll
08/29/2002 06:41 AM 323,072 msvcrt.dll
10/16/2000 02:59 AM 323,584 mfimage.dll
08/18/2001 08:00 AM 323,641 usrdtea.dll
08/29/2002 06:40 AM 324,608 cmdial32.dll
08/29/2002 06:41 AM 328,704 oakley.dll
08/18/2001 08:00 AM 330,752 dmconfig.dll
07/01/2004 06:08 PM 331,776 winhttp.dll
08/18/2001 08:00 AM 332,800 ipsecsnp.dll
08/29/2002 06:41 AM 334,848 smlogcfg.dll
12/12/2002 12:14 AM 336,384 dsound.dll
08/29/2002 06:40 AM 337,920 dxtmsft.dll
11/14/2002 12:58 PM 338,432 ir41_qcx.dll
08/29/2002 06:41 AM 339,456 usp10.dll
10/09/2003 03:19 PM 339,968 mobho.dll
08/18/2001 08:00 AM 343,552 termmgr.dll
01/05/2002 06:37 AM 344,064 msvcr70.dll
08/18/2001 08:00 AM 345,600 confmsp.dll
03/01/2004 02:55 PM 348,189 msxbde40.dll
03/01/2004 02:55 PM 348,189 mspbde40.dll
08/23/2001 05:00 AM 350,208 d3drm.dll
02/17/2003 10:16 AM 354,816 psisdecd.dll
05/30/2003 09:00 AM 355,840 qdvd.dll
12/11/2002 06:09 PM 358,912 msscp.dll
03/01/2004 02:52 PM 358,976 msjetoledb40.dll
08/18/2001 08:00 AM 359,936 cards.dll
08/18/2001 08:00 AM 361,472 fontext.dll
07/01/2004 06:08 PM 361,984 qmgr.dll
08/18/2001 08:00 AM 362,496 jet500.dll
08/18/2001 08:00 AM 364,032 ipsmsnap.dll
03/05/2004 10:16 PM 367,616 msdtcprx.dll
08/29/2002 03:41 AM 367,616 licdll.dll
08/29/2002 06:41 AM 368,710 msisam11.dll
08/18/2001 08:00 AM 370,176 dhcpmon.dll
12/12/2002 12:14 AM 377,856 dpnet.dll
08/29/2002 06:40 AM 377,984 ati2dvaa.dll
01/10/2004 07:37 AM 380,957 expsrv.dll
08/29/2002 06:41 AM 381,440 lmrt.dll
08/29/2002 06:41 AM 384,000 themeui.dll
12/11/2002 03:16 PM 384,512 mp4sdmod.dll
10/27/2003 08:12 PM 385,024 SQLSRV32.dll
08/18/2001 08:00 AM 387,584 regwizc.dll
08/29/2002 06:41 AM 392,704 ntmssvc.dll
08/23/2001 05:00 AM 394,240 diactfrm.dll
05/11/2000 01:06 PM 397,312 MSRDO20.DLL
08/29/2002 06:41 AM 399,360 netlogon.dll
08/29/2002 06:41 AM 401,462 msvcp60.dll
08/29/2002 04:09 AM 403,456 winbrand.dll
02/28/2003 06:26 PM 404,752 javart.dll
04/08/2004 04:12 PM 406,528 shlwapi.dll
08/29/2002 06:41 AM 409,088 vssapi.dll
12/11/2002 07:11 PM 410,248 wmadmod.dll
08/18/2001 08:00 AM 411,136 samsrv.dll
08/18/2001 08:00 AM 414,208 setupdll.dll
08/29/2002 06:41 AM 420,864 shimgvw.dll
01/10/2004 07:36 AM 421,919 msrd2x40.dll
08/29/2002 06:41 AM 423,424 riched20.dll
10/02/2001 01:00 AM 430,080 CTVBase.dll
10/08/2001 01:00 AM 434,176 CTABase.dll
08/18/2001 08:00 AM 435,712 shellstyle.dll
08/23/2001 05:00 AM 436,224 d3dim.dll
08/18/2001 08:00 AM 436,736 certmgr.dll
03/29/2004 09:48 PM 439,808 ipnathlp.dll
08/29/2002 06:41 AM 440,320 mshtmled.dll
08/29/2002 06:41 AM 446,464 wmvdmoe.dll
08/18/2001 08:00 AM 449,536 wiadefui.dll
08/18/2001 08:00 AM 450,560 infosoft.dll
03/24/2004 10:04 AM 454,656 nvshell.dll
11/30/2001 01:00 AM 458,752 CTMBase.dll
08/18/2001 08:00 AM 460,288 ntmsmgr.dll
05/09/2001 04:47 PM 466,944 wmv8dmoe.dll
07/24/2003 04:40 PM 477,696 cryptui.dll
08/05/2002 09:30 AM 479,232 MusicCitydll2.dll
08/29/2002 06:41 AM 479,261 vbscript.dll
01/21/2004 04:20 PM 484,352 URLMON.DLL
12/11/2002 07:07 PM 486,536 wmspdmod.dll
01/05/2002 06:40 AM 487,424 msvcp70.dll
08/18/2001 08:00 AM 489,984 hypertrm.dll
08/29/2002 06:40 AM 489,984 dbghelp.dll
08/18/2001 08:00 AM 495,376 msxml.dll
08/29/2002 06:41 AM 496,128 mstime.dll
08/29/2002 06:40 AM 498,205 dxmasf.dll
03/05/2004 10:16 PM 499,200 comuid.dll
03/05/2004 10:16 PM 499,712 clbcatq.dll
08/29/2002 06:41 AM 504,832 msftedit.dll
06/29/2004 04:13 PM 505,056 SymNeti.dll
09/21/2000 11:02 AM 507,904 imagr5.dll
03/01/2004 02:55 PM 512,029 msexch40.dll
08/29/2002 06:41 AM 522,240 printui.dll
12/12/2002 12:14 AM 524,800 qedit.dll
09/27/2000 10:15 AM 532,480 imagx5.dll
03/05/2004 10:16 PM 535,552 rpcrt4.dll
09/23/2002 03:10 PM 544,256 crypt32.dll
03/29/2004 09:48 PM 548,352 rtcdll.dll
03/04/2002 08:09 PM 548,864 shdoclc.dll
03/01/2004 02:55 PM 552,989 msrepl40.dll
08/29/2002 06:40 AM 557,056 comctl32.dll
08/29/2002 06:40 AM 558,080 advapi32.dll
09/25/2003 12:49 PM 560,128 user32.dll
08/18/2001 08:00 AM 565,760 msvcp50.dll
08/18/2001 08:00 AM 568,832 wiashext.dll
08/29/2002 06:41 AM 569,344 oleaut32.dll
08/18/2001 08:00 AM 577,024 mlang.dll
08/29/2002 06:41 AM 584,192 netcfgx.dll
02/06/2004 06:05 PM 588,288 WININET.DLL
01/13/2003 02:57 PM 589,881 jscript.dll
08/23/2001 05:00 AM 590,336 d3dramp.dll
03/29/2004 09:48 PM 593,408 h323msp.dll
05/17/2004 11:46 PM 593,408 xpsp2res.dll
03/05/2004 10:16 PM 594,944 catsrvut.dll
06/07/2004 02:19 PM 596,480 INETCOMM.DLL
08/29/2002 04:40 AM 598,016 mstscax.dll
01/23/2003 07:19 PM 600,064 divx.dll
12/12/2002 12:14 AM 602,624 dx7vb.dll
08/18/2001 08:00 AM 605,696 getuname.dll
07/05/2000 05:16 PM 606,208 clsNRN22.dll
03/16/2004 01:38 PM 614,431 mswstr10.dll
08/29/2002 06:41 AM 631,808 rasdlg.dll
07/19/2002 11:55 AM 643,072 CTSBLFX.DLL
05/01/2003 04:56 PM 654,336 ntdll.dll
08/29/2002 06:41 AM 667,136 userenv.dll
03/29/2004 09:48 PM 667,648 lsasrv.dll
12/11/2002 05:34 PM 670,208 wmadmoe.dll
04/16/2004 08:56 PM 676,864 sxs.dll
12/11/2002 06:09 PM 678,912 drmv2clt.dll
08/29/2002 06:41 AM 686,080 opengl32.dll
01/07/2002 05:15 PM 689,424 msxml2.dll
12/12/2002 12:14 AM 733,184 qedwipes.dll
11/14/2002 12:58 PM 755,200 ir50_32.dll
12/11/2002 07:12 PM 760,968 wmsdmod.dll
08/18/2001 08:00 AM 762,368 winntbbu.dll
08/18/2001 08:00 AM 792,064 comres.dll
05/30/2003 09:00 AM 797,184 d3dim700.dll
08/29/2002 06:40 AM 802,304 dxmrtp.dll
12/11/2002 07:10 PM 816,264 wmvdmod.dll
08/18/2001 08:00 AM 829,952 tapi3.dll
01/10/2004 07:36 AM 831,519 mswdat10.dll
08/29/2002 06:40 AM 844,675 ati3d1ag.dll
08/18/2001 08:00 AM 847,872 msimsg.dll
08/18/2001 08:00 AM 847,872 dbgeng.dll
08/29/2002 06:41 AM 857,600 netplwiz.dll
12/11/2002 05:34 PM 892,416 wmspdmoe.dll
08/29/2002 06:40 AM 921,475 ati3d2ag.dll
08/18/2001 08:00 AM 924,432 mfc40u.dll
08/18/2001 08:00 AM 924,432 mfc40.dll
08/29/2002 06:41 AM 930,304 kernel32.dll
08/29/2002 06:41 AM 932,864 setupapi.dll
08/29/2002 06:41 AM 938,496 syssetup.dll
02/28/2003 06:26 PM 947,472 msjava.dll
01/05/2002 07:36 AM 964,608 mfc70u.dll
03/29/2004 09:48 PM 971,264 msgina.dll
01/05/200

#19 mmxx66

mmxx66

    The SWI drummer

  • Retired Staff
  • PipPipPipPipPip
  • 4,412 posts

Posted 15 July 2004 - 03:18 PM

Please create a zip file containing the following dll's:

bitsprx3.dll
bitsprx2.dll
qmgrprxy.dll
winhttp.dll
qmgr.dll
wdmigh.dll
sqlbokj.dll
nthst32.dll
mtjpgb.dll
mtjpgh.dll


and email them HERE. Once i get them I will see if I can spot the offending dll.

#20 Gao

Gao

    Member

  • Full Member
  • Pip
  • 21 posts

Posted 15 July 2004 - 05:23 PM

On it's way my friend :D

#21 grinler

grinler

    Bleeper

  • Expert
  • PipPipPipPipPip
  • 530 posts

Posted 15 July 2004 - 09:11 PM

Gao,

I am going to step in here and work with you on this one. Please do the following for me:

Copy the contents of the quote box to Notepad.
Name the file Appinit.bat
Save as type All Files
Save on the Desktop.

Reg save "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows" windows1.hiv
ren windows1.hiv windows.txt


Double click on Appinit.bat
This will create a file on the desktop named windows.txt

Please zip and email that files to grinler@yahoo.com please.

Thanks
<b>Lawrence</b>

#22 grinler

grinler

    Bleeper

  • Expert
  • PipPipPipPipPip
  • 530 posts

Posted 16 July 2004 - 10:49 AM

Please download this file:

http://www.bleepingc...ware/search.zip

Extract it directory to your c:\ drive. It will create a directory called search. Navigate to c:\search and double-click on search.bat

Please paste the output of the notepad that opens at the end of the process as a reply to this message.
<b>Lawrence</b>

#23 Gao

Gao

    Member

  • Full Member
  • Pip
  • 21 posts

Posted 16 July 2004 - 01:44 PM

I'm pretty sure I did it right.
However, I don't think it went well G-Dog...

take a look:

------------------------------------------------------------------------------
Based heavily off the script FindNFix by FreeatLast
This search script is only for Windows XP/2000
The information found here is for identification purposes only!
In no way will this tool actually fix the problem. Use the results to perform
a manual fix.
------------------------------------------------------------------------------

Registry keys failed to backup. Aborting script.


------------------------------------------------------------------------------
Please paste the contents of this log as reply to your current log.
Then delete this entire directory.
------------------------------------------------------------------------------

#24 grinler

grinler

    Bleeper

  • Expert
  • PipPipPipPipPip
  • 530 posts

Posted 16 July 2004 - 02:31 PM

Ignore

Edited by grinler, 16 July 2004 - 11:34 PM.

<b>Lawrence</b>

#25 grinler

grinler

    Bleeper

  • Expert
  • PipPipPipPipPip
  • 530 posts

Posted 16 July 2004 - 03:19 PM

Delete c:\search

Download a new version of search.zip from the same link above. I was trying to be fancy for absolutely no reason and the script was wrong.

Then run search.bat and post the contents of the notepad it opens.
<b>Lawrence</b>

#26 Gao

Gao

    Member

  • Full Member
  • Pip
  • 21 posts

Posted 16 July 2004 - 08:25 PM

lol, alrighty.
worked this time so...

------------------------------------------------------------------------------
Based heavily off the script FindNFix by FreeatLast
This search script is only for Windows XP/2000
The information found here is for identification purposes only!
In no way will this tool actually fix the problem. Use the results to perform
a manual fix.
------------------------------------------------------------------------------

Windows Version:

Microsoft Windows XP [Version 5.1.2600]

############################################################################

Test1:
Using xfind to search for hookxx and StreamingDeviceSetup2 strings in system32\dlls

Found files that contain the string hookxx:

Found files that contain the string StreamingDeviceSetup2:


############################################################################

Conducting Test2:
Looking for files that can not be opened for identification with analyzer



############################################################################

Looking for dlls that have been packed with upx (usually malware)



############################################################################

Conducting Test4:
Looking for dlls in \windows\system32 that are readonly and younger than 5 months ago.

No matches found.

Looking for dlls in \windows\system32 that are hidden, system
and younger than 5 months ago.


No matches found.


############################################################################

Conducting Test5:
Looking for dlls in \windows\system32 that have attributes +hrs and younger than 5 months

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

.
.
------------------------------------------------------------------------------
Please paste the contents of this log as reply to your current log.
Then delete this entire directory.
Email any errors to grinler AT bleepingcomputer.com
http://www.bleepingcomputer.com
------------------------------------------------------------------------------

you have my continued thanks for all efforts.

#27 grinler

grinler

    Bleeper

  • Expert
  • PipPipPipPipPip
  • 530 posts

Posted 16 July 2004 - 10:38 PM

I want you to fix some of those entries. Please do the following:

Please make sure that you can view all hidden files. Instructions on how to do this can be found here:

How to see hidden files in Windows

Run Hijackthis again, click scan, and Put a checkmark next to each of these. Then click the Fix button
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rd.yahoo.com/...://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://rd.yahoo.com/...//www.yahoo.com
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150...tzip/RdxIE2.cab


Reboot your computer into Safe Mode and delete the following files:

Then delete these files or directories (Do not be concerned if they do not exist)
C:\DOCUMENTS AND SETTINGS\User\LOCAL SETTINGS\Temp\sp.html

Disable System Restore. You can find instructions on how to enable and reenable system restore here:

Managing Windows Millenium System Restore
or

Windows XP System Restore Guide

Renable system restore with instructions from tutorial above

Reboot your computer to go back to normal mode and post a new log.
<b>Lawrence</b>

#28 Gao

Gao

    Member

  • Full Member
  • Pip
  • 21 posts

Posted 17 July 2004 - 02:50 PM

Okay. Firstly, all my hiddens are viewable.
Did the Hijack This fix and "it" started to try and jack my homepage (just like when I attempt a fix with CWShredder or Spy Sweeper) again but then it seemed to finish the process normaly.
Rebooted in safe mode and looked for sp.html but it wasn't there.
Rebooted in normal mode Disabled and then re-inabled Sys restore (oops, misunderstood the post and I didn't do that part in safe mode. should i redo all this then? does that matter?)

Rebooted, scanned, and here is the log:

Logfile of HijackThis v1.98.0
Scan saved at 3:38:22 PM, on 7/17/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\PROGRA~1\popup\POP-UP~1\dpps2.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\SWGuard\SpywareGuard\sgmain.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\SWGuard\SpywareGuard\sgbhp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\HThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rd.yahoo.com/...://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SWGuard\SpywareGuard\dlprotect.dll
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [Pop-Up Stopper] "C:\PROGRA~1\popup\POP-UP~1\dpps2.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [IS CfgWiz] C:\Program Files\Common Files\Symantec Shared\cfgwiz.exe /GUID NIS /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - HKCU\..\Run: [Jet Detection] C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SWGuard\SpywareGuard\sgmain.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll (file missing)
O12 - Plugin for .bmp: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) -

Huh... did that stuff come back again?

#29 grinler

grinler

    Bleeper

  • Expert
  • PipPipPipPipPip
  • 530 posts

Posted 17 July 2004 - 03:59 PM

Lets move on to something else. Thanksfully FreeAtLast has rereleased her tool which makes it easier to find the offending dll.

Please do the following:

Download the program FindNFix from the following location:
http://freeatlast100.100free.com/

Once it is downloaded, double-click on the file to run it. Follow the prompts to install the program. Once it is installed a window will open up showing the installation directory and a bunch of files in the right section of the window.

On the right portion of the window look for the file called !LOG!.bat and double-click on it. It will scan through your computer for a while, so be patient. When it is completed it will automatically open a notepad window called Log.txt.

Copy the contents of that file into a reply to this post.
<b>Lawrence</b>

#30 Gao

Gao

    Member

  • Full Member
  • Pip
  • 21 posts

Posted 18 July 2004 - 11:58 AM

Okay.
I think that link is dead, but I found FindNFix here: http://downloads.sub...rg/FINDnFIX.exe

and here is the log:


»»»»»»»»»»»»»»»»»»*** freeatlast100.100free.com ***»»»»»»»»»»»»»»»»
--The directory 'junkxxx' is now included as a Subfolder in the FINDnfix folder
and is the destination for the file to be moved..
-*Previous directions will no longer work...
»»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»»

Microsoft Windows XP [Version 5.1.2600]
»»»IE build and last SP(s)
6.0.2800.1106 SP1-Q818529-Q330994-Q837009-Q832894-Q831167-Q823353
The type of the file system is NTFS.
C: is not dirty.

Sun 18 Jul 04 12:53:37
12:53am up 0 days, 2:58

»»»»»»»»»»»»»»»»»»*** Note! ***»»»»»»»»»»»»»»»»
The list will produce a small database of files that will match certain criteria.
You must know how to ID the file based on the filters provided in
the scan, as not all the files flagged are bad.
Ex: read only files, s/h files, last modified date. size, etc.
The filters provided should help narrow down the list, and hopefully
pinpoint the culprit.
Along with that,registry scan logged at the end should match the
corresponding file(s) listed.
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Unless the file match the entire criteria, it should not be pointed to remove!
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
*For *Helpers/Mods and/or users that are not familiar with any of the
items on the scan results- I recommend using an alternative, once
you know what to look for!
»»»»»»»»»»»»»»»»»»***LOG!***(*modified 7/16)»»»»»»»»»»»»»»»»

»»»*»»»*Boards that are not personally authorised by me are not allowed to use this fix!»»»*»»»*

Scanning for file(s)...
»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»
»»»»» (*1*) »»»»» .........
»»Locked or 'Suspect' file(s) found...


»»»»» (*2*) »»»»»........
**File C:\FINDnFIX\LIST.TXT

»»»»» (*3*) »»»»»........

No matches found.

unknown/hidden files...

No matches found.

»»»»» (*4*) »»»»».........
Sniffing..........
Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.


»»»»»(*5*)»»»»»
**File C:\WINDOWS\SYSTEM32\DLLXXX.TXT

»»»»»(*6*)»»»»»

»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»
»»»»»Search by size...


No matches found.

No matches found.

No matches found.

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.


»»Size of Windows key:
(*Default-450 *No AppInit-398 *fake(infected)-448,504,512...)

Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 450

»»Dumping Values........
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DeviceNotSelectedTimeout SZ 15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\GDIProcessHandleQuota DWORD 00002710
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Spooler SZ yes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\swapdisk SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\TransmissionRetryTimeout SZ 90
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\USERProcessHandleQuota DWORD 00002710

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs =
DeviceNotSelectedTimeout = 15
GDIProcessHandleQuota = REG_DWORD 0x00002710
Spooler = yes
swapdisk =
TransmissionRetryTimeout = 90
USERProcessHandleQuota = REG_DWORD 0x00002710

»»Security settings for 'Windows' key:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER

Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:
Read BUILTIN\Users
Full access BUILTIN\Administrators
Full access NT AUTHORITY\SYSTEM


»»Member of...: (Admin logon required!)
User is a member of group USER-D913XSCAE3\None.
User is a member of group \Everyone.
User is a member of group BUILTIN\Administrators.
User is a member of group BUILTIN\Users.
User is a member of group \LOCAL.
User is a member of group NT AUTHORITY\INTERACTIVE.
User is a member of group NT AUTHORITY\Authenticated Users.


»»»»»»Backups created...»»»»»»
12:54am up 0 days, 2:59
Sun 18 Jul 04 12:54:26

A C:\FINDnFIX\keyback.hiv
--a-- - - - - - 8,192 07-18-2004 keyback.hiv
A C:\FINDnFIX\keys1\winkey.reg
--a-- - - - - - 287 07-18-2004 winkey.reg
*Temp backups...
.
..
keyback2.hi_
winkey2.re_


C:\FINDNFIX\
JUNKXXX Sun Jul 18 2004 12:53:32p .D... <Dir>

1 item found: 0 files, 1 directory.

»»Performing string scan....
00001150: vk f AppInit_DLLs G
00001190: h vk UDeviceNotSelectedTimeout 1 5
000011D0: P 9 0 vk ' zGDIProcessHandle
00001210:Quota" vk 8 Spooler2 y e s _ h
00001250: ` vk 5swapdisk vk
00001290: . TransmissionRetryTimeout h `
000012D0: vk ' 0 USERProcessHandleQuotaR
00001310:
00001350:
00001390:
000013D0:
00001410:
00001450:
00001490:
000014D0:
00001510:
00001550:
00001590:
000015D0:

---------- WIN.TXT
fłAppInit_DLLsÖ?ęG
--------------
--------------
$01180: AppInit_DLLs
$011AF: UDeviceNotSelectedTimeout
$011FF: zGDIProcessHandleQuota
$01298: TransmissionRetryTimeout
$012E8: USERProcessHandleQuotaR
--------------
--------------
No strings found.

--------------
--------------
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
"DeviceNotSelectedTimeout"="15"
"GDIProcessHandleQuota"=dword:00002710
"Spooler"="yes"
"swapdisk"=""
"TransmissionRetryTimeout"="90"
"USERProcessHandleQuota"=dword:00002710

A handle was successfully obtained for the
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows key.
This key has 0 subkeys.
The AppInitDLLs value exists and reports as 2 bytes, including the 2 for string termination.

[AppInitDLLs]
Ansi string : ""
0000 00 00 | ..


#31 grinler

grinler

    Bleeper

  • Expert
  • PipPipPipPipPip
  • 530 posts

Posted 24 July 2004 - 04:32 PM

Are you still having a problem? I apologize i never got back to you but I never received the notification
<b>Lawrence</b>

#32 Gao

Gao

    Member

  • Full Member
  • Pip
  • 21 posts

Posted 24 July 2004 - 07:05 PM

Yep, still right were ya left me. 'sokay.
As far as the problem, I don't have any noticeble ones aside from when I try to delete the CWS hijack file "sp.html" using spy sweeper or cwshredder (or anything for that matter) it starts trying to hijack my homepage again. repeatedly. Other than that I don't really have a problem. At least one that is visible, I hope it's not doing something without me noticing it.

Anyway, does the FindnFix log provide any useful info?

#33 grinler

grinler

    Bleeper

  • Expert
  • PipPipPipPipPip
  • 530 posts

Posted 24 July 2004 - 07:13 PM

No it does not but the version you are using is outdated. Please delete the entire c:\findnfix folder and ten follow these isntructions:

Please do the following:

Download the program FindNFix from the following location:

http://www10.brinkst...freeatlast/FNF/

Once it is downloaded, double-click on the file to run it. Follow the prompts to install the program. Once it is installed a window will open up showing the installation directory and a bunch of files in the right section of the window.

On the right portion of the window look for the file called !LOG!.bat and double-click on it. It will scan through your computer for a while, so be patient. When it is completed it will automatically open a notepad window called Log.txt.

Copy the contents of that file into a reply to this post.
<b>Lawrence</b>

#34 Gao

Gao

    Member

  • Full Member
  • Pip
  • 21 posts

Posted 24 July 2004 - 08:03 PM

okay, done and done.
heres the log:


»»»»»»»»»*** www10.brinkster.com/expl0iter/freeatlast/FNF/ ***»»»»»»»»»
»»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»»

Microsoft Windows XP [Version 5.1.2600]
»»»IE build and last SP(s)
6.0.2800.1106 SP1-Q818529-Q330994-Q837009-Q832894-Q831167-Q823353
The type of the file system is NTFS.
C: is not dirty.

Sat 24 Jul 04 21:01:54
9:01pm up 0 days, 0:17

»»»»»»»»»»»»»»»»»»*** Note! ***»»»»»»»»»»»»»»»»
The list will produce a small database of files that will match certain criteria.
You must know how to ID the file based on the filters provided in
the scan, as not all the files flagged are bad.
Ex: read only files, s/h files, last modified date. size, etc.
The filters provided should help narrow down the list, and hopefully
pinpoint the culprit.
Along with that,registry scan logged at the end should match the
corresponding file(s) listed.
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Unless the file match the entire criteria, it should not be pointed to remove
without attempting to confirm it's nature!
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
At times there could be several (legit) files flagged, and/or duplicate culprit file(s)!
If in doubt, always search the file(s) and properties according to criteria!

The file(s) found should be moved to \FINDnFIX\"junkxxx" Subfolder
»»»»»»»»»»»»»»»»»»***LOG!***(*updated 7/24)»»»»»»»»»»»»»»»»

»»»*»»»*Use at your own risk!»»»*»»»*

Scanning for file(s)...
»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»
»»»»» (*1*) »»»»» .........
»»Locked or 'Suspect' file(s) found...


»»»»» (*2*) »»»»»........
**File C:\FINDnFIX\LIST.TXT

»»»»» (*3*) »»»»»........

No matches found.

unknown/hidden files...

No matches found.

»»»»» (*4*) »»»»».........
Sniffing..........
Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.


»»»»»(*5*)»»»»»
**File C:\WINDOWS\SYSTEM32\DLLXXX.TXT

»»»»»(*6*)»»»»»

»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»
»»»»»Search by size...


No matches found.

No matches found.

No matches found.

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.


»»Size of Windows key:
(*Default-450 *No AppInit-398 *fake(infected)-448,504,512...)

Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 450

»»Dumping Values........
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DeviceNotSelectedTimeout SZ 15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\GDIProcessHandleQuota DWORD 00002710
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Spooler SZ yes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\swapdisk SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\TransmissionRetryTimeout SZ 90
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\USERProcessHandleQuota DWORD 00002710

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs =
DeviceNotSelectedTimeout = 15
GDIProcessHandleQuota = REG_DWORD 0x00002710
Spooler = yes
swapdisk =
TransmissionRetryTimeout = 90
USERProcessHandleQuota = REG_DWORD 0x00002710

»»Security settings for 'Windows' key:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER

Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:
Read BUILTIN\Users
Full access BUILTIN\Administrators
Full access NT AUTHORITY\SYSTEM


»»Member of...: (Admin logon required!)
User is a member of group USER-D913XSCAE3\None.
User is a member of group \Everyone.
User is a member of group BUILTIN\Administrators.
User is a member of group BUILTIN\Users.
User is a member of group \LOCAL.
User is a member of group NT AUTHORITY\INTERACTIVE.
User is a member of group NT AUTHORITY\Authenticated Users.


»»»»»»Backups created...»»»»»»
9:02pm up 0 days, 0:18
Sat 24 Jul 04 21:02:44

A C:\FINDnFIX\keyback.hiv
--a-- - - - - - 8,192 07-24-2004 keyback.hiv
A C:\FINDnFIX\keys1\winkey.reg
--a-- - - - - - 287 07-24-2004 winkey.reg
*Temp backups...
.
..
keyback2.hi_
winkey2.re_


C:\FINDNFIX\
JUNKXXX Sat Jul 24 2004 9:01:54p .D... <Dir>

1 item found: 0 files, 1 directory.

»»Performing string scan....
00001150: vk f AppInit_DLLs G
00001190: h vk UDeviceNotSelectedTimeout 1 5
000011D0: P 9 0 vk ' zGDIProcessHandle
00001210:Quota" vk 8 Spooler2 y e s _ h
00001250: ` vk 5swapdisk vk
00001290: . TransmissionRetryTimeout h `
000012D0: vk ' 0 USERProcessHandleQuotaR
00001310:
00001350:
00001390:
000013D0:
00001410:
00001450:
00001490:
000014D0:
00001510:
00001550:
00001590:
000015D0:

---------- WIN.TXT
fłAppInit_DLLsÖ?ęG
--------------
--------------
$01180: AppInit_DLLs
$011AF: UDeviceNotSelectedTimeout
$011FF: zGDIProcessHandleQuota
$01298: TransmissionRetryTimeout
$012E8: USERProcessHandleQuotaR
--------------
--------------
No strings found.

--------------
--------------
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
"DeviceNotSelectedTimeout"="15"
"GDIProcessHandleQuota"=dword:00002710
"Spooler"="yes"
"swapdisk"=""
"TransmissionRetryTimeout"="90"
"USERProcessHandleQuota"=dword:00002710

A handle was successfully obtained for the
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows key.
This key has 0 subkeys.
The AppInitDLLs value exists and reports as 2 bytes, including the 2 for string termination.

[AppInitDLLs]
Ansi string : ""
0000 00 00 | ..


#35 Gao

Gao

    Member

  • Full Member
  • Pip
  • 21 posts

Posted 27 July 2004 - 12:31 PM

...that one manage to give you any useful info?

#36 blub

blub

    Member

  • Full Member
  • Pip
  • 8 posts

Posted 27 July 2004 - 01:03 PM

Another suggestion.....

Use Appinit.bat. ( http://users.telenet...are/appinit.zip )
Run it.
There will be a dosbox, a file will be created named windows.txt
In this file is the name located of the hidden dll on your system. We will call xxxx.dll.

Disconnect from the intranet. Run Hiving (download it from:
http://computercops....wnload&id=1183)
Reboot and check for the file: c:\Windows\System32\xxxx.dll
Delete it.
Run CWShredder
Reboot
Run HijackThis and fix all thats left over pointing to about:blanc (sp.html)
Or run Adware..

Good luck
Blub :bounce:

#37 grinler

grinler

    Bleeper

  • Expert
  • PipPipPipPipPip
  • 530 posts

Posted 27 July 2004 - 01:40 PM

Step 1:

Please make sure that you can view all hidden files. Instructions on how to do this can be found here:

How to see hidden files in Windows

Create new folder on your hard drive called c:\regbackup.

Step 2:

Run Registrar Lite again enter HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows into the address field and press enter. On the left side of the screen the Windows key should be selected and highlighted purple.

With the Windows key highlighted click on the File menu, and the click on export and save them in the following formats:


First save it with the name winkey.reg
Make the save type regedit4 .reg type and then press the save button.

Then click on file export again, and this time name it Winkey.hiv
Change the type to regetd32/WinAPI *hiv *dat files and press the save button.


When both files/backups are successfully saved, right-click on the highlighted Windows key and rename it to Windows 1.

Step 3:

With Windows1 highlighted, look in the right section and double-click on AppInit and clear the data in the value field. That is the dll you saw previuosly.

Rename Windows1 back to Windows and exit the program.

Reboot your computer.

Step 4:

When you are back at your desktop, navigate to the c:\regback folder. Double-click on the winkey.reg file. When it prompt if you would like to import/merge the data press the Yes button.

Then run Registrar Lite again, go to the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows key again as done above. While the Windows key is selected (highlighted purple/blue) in the left window, click on File and them Import.

Browse to c:\regback and select the winkey.hiv file that we created earlier. When it asks if you would like to merge, say yes/ok.

Step 5:


Then double-click on the appinit_dlls key again and clear the value again by double click on appinit_dlls and making sure there is nothing in the values field.

Then delete the entire c:\regback folder.

Step 6:

Now download and run CWShredder. You can download the program from the following locations:

http://www.merijn.or.../cwshredder.zip

or

http://www.zerosreal.../CWShredder.zip

After you download the program, unzip it into a directory. Make sure all browser windows are closed and double click on the cwshredder.exe to start the program. When the program is loaded click on the "Check for Update" button, and if it finds an new version it will download it. You should then double click on cwshredder.exe again and click on the "FIX" button (not the "Scan only" button) and let it scan your computer.

A tutorial that goes over this process step by step can be found here:

How to remove CoolWebSearch with CWShredder

When that is completed, please download the latest version of Ad-Aware from the following location:

Ad-aware

Make sure you update the program before you scan with it. A tutorial on using ad-aware can be found below:

AD-AWARE - Using Ad-aware to remove Spyware & Hijackers from Your Computer.

When that is completed post a new hijackthis log

Edited by grinler, 27 July 2004 - 01:42 PM.

<b>Lawrence</b>

#38 Gao

Gao

    Member

  • Full Member
  • Pip
  • 21 posts

Posted 27 July 2004 - 04:13 PM

Whew, done.
...a few probs however.

Firstly, the appinit.dll's value in registrar is already empty.

Secondly, I could not double-click the ".hiv" file as windows did not recognize the extention.

Thirdly Ad-Aware seems to have the same problem that Spy Sweeper and CWShredder do. Upon attempted removal the four seperate files each try to hijack and then get copied from somewhere back to where they just got quarentined from.

Aggrivating.

Well, here is the log:

Logfile of HijackThis v1.98.0
Scan saved at 5:06:32 PM, on 7/27/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\PROGRA~1\popup\POP-UP~1\dpps2.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\SWGuard\SpywareGuard\sgmain.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\SWGuard\SpywareGuard\sgbhp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\HThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rd.yahoo.com/...://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SWGuard\SpywareGuard\dlprotect.dll
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [Pop-Up Stopper] "C:\PROGRA~1\popup\POP-UP~1\dpps2.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [IS CfgWiz] C:\Program Files\Common Files\Symantec Shared\cfgwiz.exe /GUID NIS /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - HKCU\..\Run: [Jet Detection] C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SWGuard\SpywareGuard\sgmain.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll (file missing)
O12 - Plugin for .bmp: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) -

#39 grinler

grinler

    Bleeper

  • Expert
  • PipPipPipPipPip
  • 530 posts

Posted 28 July 2004 - 10:56 AM

You do not double click on the .hiv file. If you look at the instruction you need import that file. When you say the four files rehijack you..what four files?
<b>Lawrence</b>

#40 Gao

Gao

    Member

  • Full Member
  • Pip
  • 21 posts

Posted 02 August 2004 - 09:37 AM

HA-HA!
It's GONE!
No programs are finding any spy/mal/adware, whatever, on my system anymore. Many thanks to MMXX66 and Grinler for all their efforts. I'm posting a HJT log just for old times sake and to see if maybe you notice anything that looks odd. For instance, what's all this yahoo messenger stuff still on my system for? I uninstalled messenger quite a ways back. Thanks again all!

#41 Gao

Gao

    Member

  • Full Member
  • Pip
  • 21 posts

Posted 02 August 2004 - 09:38 AM

oops... forgot the log:

Logfile of HijackThis v1.98.0
Scan saved at 10:31:08 AM, on 8/2/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\PROGRA~1\popup\POP-UP~1\dpps2.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Cleaner\The Cleaner\tca.exe
C:\Program Files\Cleaner\The Cleaner\tcm.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\SWGuard\SpywareGuard\sgmain.exe
C:\Program Files\SWGuard\SpywareGuard\sgbhp.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HThis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rd.yahoo.com/...://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/...//www.yahoo.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SWGuard\SpywareGuard\dlprotect.dll
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [Pop-Up Stopper] "C:\PROGRA~1\popup\POP-UP~1\dpps2.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [IS CfgWiz] C:\Program Files\Common Files\Symantec Shared\cfgwiz.exe /GUID NIS /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [tcactive] C:\Program Files\Cleaner\The Cleaner\tca.exe
O4 - HKLM\..\Run: [tcmonitor] C:\Program Files\Cleaner\The Cleaner\tcm.exe
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - HKCU\..\Run: [Jet Detection] C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SWGuard\SpywareGuard\sgmain.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll (file missing)
O12 - Plugin for .bmp: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg...v45/yacscom.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) -

#42 grinler

grinler

    Bleeper

  • Expert
  • PipPipPipPipPip
  • 530 posts

Posted 02 August 2004 - 12:31 PM

Just fix these and you should be all clean...

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rd.yahoo.com/...://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/...//www.yahoo.com
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll (file missing)
O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) -


Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.

    See this link for a listing of some online & their stand-alone antivirus programs:

    Virus, Spyware, and Malware Protection and Removal Resources

  • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:

    Understanding and Using Firewalls

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.

    A tutorial on installing & using this product can be found here:

    Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

  • Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.

    A tutorial on installing & using this product can be found here:

    Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

Glad I was able to help.
<b>Lawrence</b>

#43 mmxx66

mmxx66

    The SWI drummer

  • Retired Staff
  • PipPipPipPipPip
  • 4,412 posts

Posted 02 August 2004 - 07:20 PM

:D your welcome :D




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button