Thank you for taking time in helping me.
Here are the logs after I did the procedures you told me:
HijackThis:
Logfile of HijackThis v1.99.1
Scan saved at 12:12:48 PM, on 2/19/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe
C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder\OrderReminder.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Documents and Settings\Family room\Desktop\walang gagalaw nito II\HijackThis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O2 - BHO: XBTB04715 - {A8B0BDED-64A5-495b-97DA-42C0301E229B} - C:\PROGRA~1\TOOLBA~1\TOOLBA~1.DLL (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Toolbar888 - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - C:\Program Files\Toolbar888\ToolBar888.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [StatusClient 2.6] C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [TomcatStartup 2.5] C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe
O4 - HKLM\..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder\OrderReminder.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IpNetwork] C:\Program Files\Network\ipnetwork.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-110-12-0000206.exe
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt3_x.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A1426AC5-8CE5-4A00-B71E-011D35709AC6} (Progetto1.int_ver34) - http://advnt01.com/dialer/int_ver34.CAB
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{032D5287-D5BB-4BBA-A985-076AF2EB7670}: NameServer = 58.69.254.43 203.84.191.216
O17 - HKLM\System\CS3\Services\Tcpip\..\{032D5287-D5BB-4BBA-A985-076AF2EB7670}: NameServer = 58.69.254.43 203.84.191.216
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\hpzipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
ewido:
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 11:52:10 AM, 2/19/2006
+ Report-Checksum: 700F17C2
+ Scan result:
HKU\S-1-5-21-1547161642-2052111302-725345543-1003\Software\DNS -> Adware.Shorty : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.105:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.107:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.108:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.109:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.110:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.128:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.129:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.130:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.137:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Starware : Cleaned with backup
:mozilla.138:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Starware : Cleaned with backup
:mozilla.139:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Starware : Cleaned with backup
:mozilla.183:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.184:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.185:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.186:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.187:C:\Documents and Settings\Family room\Application Data\Mozilla\Firefox\Profiles\d2uom7tk.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\Family room\Cookies\family room@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Family room\Cookies\family room@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Family room\Cookies\family room@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\Family room\Cookies\family room@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Family room\Cookies\family room@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned with backup
C:\Documents and Settings\Family room\Cookies\family room@h.starware[1].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\Family room\Cookies\family room@media.fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned with backup
C:\Documents and Settings\Family room\Cookies\family room@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\Family room\Cookies\family room@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\Family room\Cookies\family room@statse.webtrendslive[1].txt -> TrackingCookie.Webtrendslive : Cleaned with backup
C:\Documents and Settings\Family room\Cookies\family room@targetnet[2].txt -> TrackingCookie.Targetnet : Cleaned with backup
C:\Documents and Settings\Family room\Cookies\family room@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Family room\Cookies\family room@www.starware[1].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\Family room\Cookies\family room@zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\Documents and Settings\Family room\Desktop\walang gagalaw nito II\backups\backup-20060218-105221-721.dll -> Adware.Softomate : Cleaned with backup
C:\Documents and Settings\Family room\lup.exe -> Backdoor.Rbot.aeu : Cleaned with backup
C:\Program Files\Common Files\InetGet\mc-110-12-0000206.exe -> Dropper.Agent.aac : Cleaned with backup
C:\Program Files\Common Files\Windows\mc-110-12-0000206.exe -> Dropper.Agent.aac : Cleaned with backup
C:\Program Files\Common Files\Windows\services32.exe -> Adware.Maxifiles : Cleaned with backup
C:\Program Files\Common Files\Windows\__delete_on_reboot__services32.exe -> Adware.Maxifiles : Cleaned with backup
C:\Program Files\Network\__delete_on_reboot__ipnetwork.exe -> Adware.Maxifiles : Cleaned with backup
C:\Program Files\Toolbar888\ToolBar888.dll -> Adware.Softomate : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\int_ver34.ocx -> Dialer.VB.j : Cleaned with backup
C:\WINDOWS\system32\bot.exe -> Backdoor.Rbot.aht : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\G1U30TU3\rp5[1].exe -> Backdoor.SdBot.aad : Cleaned with backup
C:\WINDOWS\system32\eraseme_28244.exe -> Backdoor.SdBot.aad : Cleaned with backup
C:\WINDOWS\system32\eraseme_30433.exe -> Backdoor.SdBot.aad : Cleaned with backup
C:\WINDOWS\system32\eraseme_35163.exe -> Backdoor.SdBot.xd : Cleaned with backup
C:\WINDOWS\system32\eraseme_44403.exe -> Backdoor.SdBot.aad : Cleaned with backup
C:\WINDOWS\system32\eraseme_56874.exe -> Backdoor.SdBot.aad : Cleaned with backup
C:\WINDOWS\system32\eraseme_56887.exe -> Backdoor.SdBot.xd : Cleaned with backup
C:\WINDOWS\system32\eraseme_57847.exe -> Backdoor.SdBot.xd : Cleaned with backup
C:\WINDOWS\system32\eraseme_72281.exe -> Backdoor.SdBot.aad : Cleaned with backup
C:\WINDOWS\system32\eraseme_74516.exe -> Backdoor.SdBot.aad : Cleaned with backup
C:\WINDOWS\system32\eraseme_77110.exe -> Backdoor.SdBot.aad : Cleaned with backup
C:\WINDOWS\system32\eraseme_77637.exe -> Backdoor.SdBot.aad : Cleaned with backup
C:\WINDOWS\system32\eraseme_78660.exe -> Backdoor.SdBot.aad : Cleaned with backup
C:\WINDOWS\system32\irlul5391.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\k8no0i53e8.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\ksdgr.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mswindtc.exe -> Trojan.Crypt.d : Cleaned with backup
C:\WINDOWS\system32\myiqtz32.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\oqffilt.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\phr.exe -> Backdoor.Rbot.aeu : Cleaned with backup
C:\WINDOWS\system32\q068laju1do8.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\win32ssr.exe -> Backdoor.SdBot.ale : Cleaned with backup
C:\WINDOWS\system32\win33.exe -> Backdoor.Rbot : Cleaned with backup
::Report End
Look2Me-Remover:
Look2Me-Destroyer V1.0.5
Scanning for infected files.....
Scan started at 2/19/2006 10:38:04 AM
Infected! C:\WINDOWS\system32\k8no0i53e8.dll
Infected! C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032626.dll
Infected! C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032636.dll
Infected! C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032643.dll
Infected! C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032661.dll
Infected! C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032682.dll
Infected! C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032704.dll
Infected! C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032715.dll
Infected! C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032736.dll
Infected! C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032746.dll
Infected! C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032792.dll
Infected! C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032845.dll
Infected! C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032846.dll
Infected! C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0033801.dll
Infected! C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP54\A0034804.dll
Infected! C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP54\A0034809.dll
Infected! C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP54\A0034836.dll
Infected! C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP56\A0035649.dll
Infected! C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP56\A0035656.dll
Infected! C:\WINDOWS\system32\dn2u01f9e.dll
Attempting to delete infected files...
Attempting to delete: C:\WINDOWS\system32\k8no0i53e8.dll
C:\WINDOWS\system32\k8no0i53e8.dllcould not be deleted!
Attempting to delete: C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032626.dll
C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032626.dllcould not be deleted!
Attempting to delete: C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032636.dll
C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032636.dllcould not be deleted!
Attempting to delete: C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032643.dll
C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032643.dllcould not be deleted!
Attempting to delete: C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032661.dll
C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032661.dllcould not be deleted!
Attempting to delete: C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032682.dll
C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032682.dllcould not be deleted!
Attempting to delete: C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032704.dll
C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032704.dllcould not be deleted!
Attempting to delete: C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032715.dll
C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032715.dllcould not be deleted!
Attempting to delete: C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032736.dll
C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032736.dllcould not be deleted!
Attempting to delete: C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032746.dll
C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032746.dllcould not be deleted!
Attempting to delete: C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032792.dll
C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032792.dllcould not be deleted!
Attempting to delete: C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032845.dll
C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032845.dllcould not be deleted!
Attempting to delete: C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032846.dll
C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0032846.dllcould not be deleted!
Attempting to delete: C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0033801.dll
C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP53\A0033801.dllcould not be deleted!
Attempting to delete: C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP54\A0034804.dll
C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP54\A0034804.dllcould not be deleted!
Attempting to delete: C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP54\A0034809.dll
C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP54\A0034809.dllcould not be deleted!
Attempting to delete: C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP54\A0034836.dll
C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP54\A0034836.dllcould not be deleted!
Attempting to delete: C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP56\A0035649.dll
C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP56\A0035649.dllcould not be deleted!
Attempting to delete: C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP56\A0035656.dll
C:\System Volume Information\_restore{12B802B7-EBCA-4D5A-811D-7069E1DD3A85}\RP56\A0035656.dllcould not be deleted!
Attempting to delete: C:\WINDOWS\system32\dn2u01f9e.dll
C:\WINDOWS\system32\dn2u01f9e.dllcould not be deleted!
Making registry repairs.
Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Setup
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{B3DCBB5C-01B5-4176-ACDB-3BA4ADF5E543}"
HKCR\Clsid\{B3DCBB5C-01B5-4176-ACDB-3BA4ADF5E543}
Restoring Windows certificates.
Replaced hosts file with default windows hosts file
look1.txt:
doesn't exist HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\System
doesn't exist HKEY_LOCAL_MACHINE\SSYSTEM\CurrentControlSet\Services\windowsnetwork
doesn't exist HKEY_CURRENT_USER\SYSTEM\CurrentControlSet\Control\Lsa
-----------------------
-----------------------
REGEDIT4
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess]
"Type"=dword:00000020
"Start"=dword:00000003
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,33,\
32,5c,73,76,63,68,6f,73,74,2e,65,78,65,20,2d,6b,20,6e,65,74,73,76,63,73,00
"DisplayName"="Internet Connection Firewall (ICF) / Internet Connection Sharing (ICS)"
"DependOnService"=hex(7):4e,65,74,6d,61,6e,00,4e,4c,41,00,52,61,73,4d,61,6e,00,\
41,4c,47,00,00
"DependOnGroup"=hex(7):00
"ObjectName"="LocalSystem"
"Description"="Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network."
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters]
"ServiceDll"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,\
33,32,5c,69,70,6e,61,74,68,6c,70,2e,64,6c,6c,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum]
"0"="Root\\LEGACY_SHAREDACCESS\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
"EnableFirewall"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc]
"Start"=dword:00000004
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters]
"autodisconnect"=dword:0000000f
"enableforcedlogoff"=dword:00000001
"enablesecuritysignature"=dword:00000000
"requiresecuritysignature"=dword:00000000
"NullSessionPipes"=hex(7):43,4f,4d,4e,41,50,00,43,4f,4d,4e,4f,44,45,00,53,51,\
4c,5c,51,55,45,52,59,00,53,50,4f,4f,4c,53,53,00,4c,4c,53,52,50,43,00,45,50,\
4d,41,50,50,45,52,00,4c,4f,43,41,54,4f,52,00,54,72,6b,57,6b,73,00,54,72,6b,\
53,76,72,00,00
"NullSessionShares"=hex(7):43,4f,4d,43,46,47,00,44,46,53,24,00,00
"ServiceDll"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,\
33,32,5c,73,72,76,73,76,63,2e,64,6c,6c,00
"Lmannounce"=dword:00000000
"Size"=dword:00000001
"Guid"=hex:2b,fe,f8,74,4b,74,48,42,91,5a,d5,f5,5c,c8,f1,7d
"AutoShareWks"=dword:00000000
"AutoShareServer"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanworkstation\parameters]
"enableplaintextpassword"=dword:00000000
"enablesecuritysignature"=dword:00000001
"requiresecuritysignature"=dword:00000000
"ServiceDll"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,\
33,32,5c,77,6b,73,73,76,63,2e,64,6c,6c,00
"OtherDomains"=hex(7):00
"AutoShareWks"=dword:00000000
"AutoShareServer"=dword:00000000
[HKEY_CURRENT_USER\Software\Microsoft\OLE]
"ethernet"="msfpc.exe"
"MediaP"="BSDMPlyr32.exe"
"Service"="ccApp.exe"
"BnCtest2"="lfxss.exe"
"Sonytest"="jswTss.exe"
"internet service"="ssvhoost94.exe"
"ServicesLog2"="MScdDriverLK872.exe"
"internet Monitoring service"="winxpstats.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Messenger]
"Type"=dword:00000020
"Start"=dword:00000004
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,33,\
32,5c,73,76,63,68,6f,73,74,2e,65,78,65,20,2d,6b,20,6e,65,74,73,76,63,73,00
"DisplayName"="Messenger"
"DependOnService"=hex(7):4c,61,6e,6d,61,6e,57,6f,72,6b,73,74,61,74,69,6f,6e,00,\
4e,65,74,42,49,4f,53,00,50,6c,75,67,50,6c,61,79,00,52,70,63,53,53,00,00
"DependOnGroup"=hex(7):00
"ObjectName"="LocalSystem"
"Description"="Transmits net send and Alerter service messages between clients and servers. This service is not related to Windows Messenger. If this service is stopped, Alerter messages will not be transmitted. If this service is disabled, any services that explicitly depend on it will fail to start."
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Messenger\Parameters]
"ServiceDll"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,\
33,32,5c,6d,73,67,73,76,63,2e,64,6c,6c,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Messenger\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\
23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\
02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Messenger\Enum]
"0"="Root\\LEGACY_MESSENGER\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry]
"Description"="Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start."
"DependOnService"=hex(7):52,50,43,53,53,00,00
"DisplayName"="Remote Registry"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,33,\
32,5c,73,76,63,68,6f,73,74,2e,65,78,65,20,2d,6b,20,4c,6f,63,61,6c,53,65,72,\
76,69,63,65,00
"ObjectName"="NT AUTHORITY\\LocalService"
"Group"=""
"Start"=dword:00000004
"Type"=dword:00000020
"FailureActions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,01,00,00,00,e0,ad,08,\
00,01,00,00,00,e8,03,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Parameters]
"ServiceDll"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,\
33,32,5c,72,65,67,73,76,63,2e,64,6c,6c,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\
23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\
02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Enum]
"0"="Root\\LEGACY_REMOTEREGISTRY\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr]
"Type"=dword:00000010
"Start"=dword:00000004
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,53,79,73,74,65,6d,33,32,5c,\
74,6c,6e,74,73,76,72,2e,65,78,65,00
"DisplayName"="Telnet"
"DependOnService"=hex(7):52,50,43,53,53,00,54,43,50,49,50,00,4e,54,4c,4d,53,53,\
50,00,00
"DependOnGroup"=hex(7):00
"ObjectName"="LocalSystem"
"Description"=hex(2):45,6e,61,62,6c,65,73,20,61,20,72,65,6d,6f,74,65,20,75,73,\
65,72,20,74,6f,20,6c,6f,67,20,6f,6e,20,74,6f,20,74,68,69,73,20,63,6f,6d,70,\
75,74,65,72,20,61,6e,64,20,72,75,6e,20,70,72,6f,67,72,61,6d,73,2c,20,61,6e,\
64,20,73,75,70,70,6f,72,74,73,20,76,61,72,69,6f,75,73,20,54,43,50,2f,49,50,\
20,54,65,6c,6e,65,74,20,63,6c,69,65,6e,74,73,2c,20,69,6e,63,6c,75,64,69,6e,\
67,20,55,4e,49,58,2d,62,61,73,65,64,20,61,6e,64,20,57,69,6e,64,6f,77,73,2d,\
62,61,73,65,64,20,63,6f,6d,70,75,74,65,72,73,2e,20,49,66,20,74,68,69,73,20,\
73,65,72,76,69,63,65,20,69,73,20,73,74,6f,70,70,65,64,2c,20,72,65,6d,6f,74,\
65,20,75,73,65,72,20,61,63,63,65,73,73,20,74,6f,20,70,72,6f,67,72,61,6d,73,\
20,6d,69,67,68,74,20,62,65,20,75,6e,61,76,61,69,6c,61,62,6c,65,2e,20,49,66,\
20,74,68,69,73,20,73,65,72,76,69,63,65,20,69,73,20,64,69,73,61,62,6c,65,64,\
2c,20,61,6e,79,20,73,65,72,76,69,63,65,73,20,74,68,61,74,20,65,78,70,6c,69,\
63,69,74,6c,79,20,64,65,70,65,6e,64,20,6f,6e,20,69,74,20,77,69,6c,6c,20,66,\
61,69,6c,20,74,6f,20,73,74,61,72,74,2e,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate]
"DoNotAllowXPSP2"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole]
"DefaultLaunchPermission"=hex:01,00,04,80,64,00,00,00,80,00,00,00,00,00,00,00,\
14,00,00,00,02,00,50,00,03,00,00,00,00,00,18,00,01,00,00,00,01,01,00,00,00,\
00,00,05,12,00,00,00,00,00,00,00,00,00,18,00,01,00,00,00,01,01,00,00,00,00,\
00,05,04,00,00,00,00,00,00,00,00,00,18,00,01,00,00,00,01,02,00,00,00,00,00,\
05,20,00,00,00,20,02,00,00,01,05,00,00,00,00,00,05,15,00,00,00,a0,5f,84,1f,\
5e,2e,6b,49,ce,12,03,03,f4,01,00,00,01,05,00,00,00,00,00,05,15,00,00,00,a0,\
5f,84,1f,5e,2e,6b,49,ce,12,03,03,f4,01,00,00
"EnableDCOM"="N"
"MSI_Place_holder"="\"9x Msi uninstaller fix\""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,6e,77,70,72,6f,76,61,75,\
00,00
"Bounds"=hex:00,30,00,00,00,20,00,00
"Security Packages"=hex(7):6b,65,72,62,65,72,6f,73,00,6d,73,76,31,5f,30,00,73,\
63,68,61,6e,6e,65,6c,00,77,64,69,67,65,73,74,00,00
"LsaPid"=dword:00000308
"SecureBoot"=dword:00000001
"auditbaseobjects"=dword:00000000
"crashonauditfail"=dword:00000000
"disabledomaincreds"=dword:00000000
"everyoneincludesanonymous"=dword:00000000
"fipsalgorithmpolicy"=dword:00000000
"forceguest"=dword:00000001
"fullprivilegeauditing"=hex:00
"limitblankpassworduse"=dword:00000001
"lmcompatibilitylevel"=dword:00000000
"nodefaultadminowner"=dword:00000001
"nolmhash"=dword:00000000
"restrictanonymous"=dword:00000001
"restrictanonymoussam"=dword:00000001
"Notification Packages"=hex(7):73,63,65,63,6c,69,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders]
"ProviderOrder"=hex(7):57,69,6e,64,6f,77,73,20,4e,54,20,41,63,63,65,73,73,20,\
50,72,6f,76,69,64,65,72,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\Windows NT Access Provider]
"ProviderPath"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,\
33,32,5c,6e,74,6d,61,72,74,61,2e,64,6c,6c,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Data]
"Pattern"=hex:6b,a8,28,f0,67,b7,06,c6,1f,04,f0,d1,42,f6,2f,89,35,34,32,64,31,\
63,35,35,00,68,07,00,01,00,00,00,d8,00,00,00,dc,00,00,00,48,fa,06,00,d6,48,\
5a,74,04,00,00,00,a0,fd,06,00,b8,fd,06,00,a4,97,ad,2a
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\GBG]
"GrafBlumGroup"=hex:95,bd,9a,fe,c7,79,e5,16,df
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\JD]
"Lookup"=hex:2c,91,a8,df,6a,a7
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Domains]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\SidCache]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0]
"Auth132"="IISSUBA"
"ntlmminclientsec"=dword:00000000
"ntlmminserversec"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Skew1]
"SkewMatrix"=hex:dc,05,86,4e,1c,b8,2e,e0,25,b4,c4,b1,67,1b,b5,6c
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\Passport1.4]
"SSOURL"="http://www.passport.com"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache]
"Time"=hex:d8,5c,1f,05,02,fb,c5,01
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll]
"Name"="Digest"
"Comment"="Digest SSPI Authentication Package"
"Capabilities"=dword:00004050
"RpcId"=dword:0000ffff
"Version"=dword:00000001
"TokenSize"=dword:0000ffff
"Time"=hex:00,cd,02,d0,ca,4e,c2,01
"Type"=dword:00000031
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll]
"Name"="DPA"
"Comment"="DPA Security Package"
"Capabilities"=dword:00000037
"RpcId"=dword:00000011
"Version"=dword:00000001
"TokenSize"=dword:00000300
"Time"=hex:00,e0,58,14,88,2b,c1,01
"Type"=dword:00000031
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll]
"Name"="MSN"
"Comment"="MSN Security Package"
"Capabilities"=dword:00000037
"RpcId"=dword:00000012
"Version"=dword:00000001
"TokenSize"=dword:00000300
"Time"=hex:00,35,8c,d9,ca,4e,c2,01
"Type"=dword:00000031
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"UpdatesDisableNotify"=dword:00000000
"AntiVirusDisableNotify"=dword:00000000
"FirewallDisableNotify"=dword:00000000
"AntiVirusOverride"=dword:00000000
"FirewallOverride"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
"EnableFirewall"=dword:00000000
There, that's it. Thanks again!
|