QUOTE (LoPhatPhuud @ Feb 24 2006, 11:20 PM)

First:
Close any programs you have open since this step requires a reboot.
From the l2mfix folder on your desktop, double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing enter, then press any key to reboot your computer. After a reboot, your desktop and icons will appear, then disappear (this is normal). L2mfix will continue to scan your computer and when it's finished, notepad will open with a log. Copy the contents of that log and paste it back into this thread, along with a new hijackthis log.
IMPORTANT: Do NOT run any other files in the l2mfix folder until you are asked to do so!
Second:
Run HiJackThis again and post a new log in this thread.
hello hope that's alla right
L2mfix 010406
Creating Account.
Esecuzione comando riuscita.
Adding Administrative privleges.
Checking for L2MFix account(0=no 1=yes):
1
Granting SeDebugPrivilege to L2MFIX ... successful
Running From:
C:\WINNT\system32
Killing Processes!
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peaco*k@beyondlogic.org
Killing PID 148 'smss.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peaco*k@beyondlogic.org
Killing PID 172 'winlogon.exe'
Killing PID 172 'winlogon.exe'
Error 0x5 : Accesso negato.
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peaco*k@beyondlogic.org
Killing PID 848 'explorer.exe'
Killing PID 848 'explorer.exe'
Error 0x5 : Accesso negato.
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peaco*k@beyondlogic.org
Killing PID 1744 'rundll32.exe'
Killing PID 1744 'rundll32.exe'
Error 0x5 : Accesso negato.
Restoring Sedebugprivilege:
Granting SeDebugPrivilege to Administrators ... successful
Scanning First Pass. Please Wait!
First Pass Completed
Second Pass Scanning
Second pass Completed!
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
1 file copiati.
Deleting: C:\WINNT\system32\aza8l97u1.dll
Successfully Deleted: C:\WINNT\system32\aza8l97u1.dll
Deleting: C:\WINNT\system32\ckcdll.dll
Successfully Deleted: C:\WINNT\system32\ckcdll.dll
Deleting: C:\WINNT\system32\cLrds.dll
Successfully Deleted: C:\WINNT\system32\cLrds.dll
Deleting: C:\WINNT\system32\dlkquoui.dll
Successfully Deleted: C:\WINNT\system32\dlkquoui.dll
Deleting: C:\WINNT\system32\dnnu0159e.dll
Successfully Deleted: C:\WINNT\system32\dnnu0159e.dll
Deleting: C:\WINNT\system32\dpskadp.dll
Successfully Deleted: C:\WINNT\system32\dpskadp.dll
Deleting: C:\WINNT\system32\duvenum.dll
Successfully Deleted: C:\WINNT\system32\duvenum.dll
Deleting: C:\WINNT\system32\dxmv2clt.dll
Successfully Deleted: C:\WINNT\system32\dxmv2clt.dll
Deleting: C:\WINNT\system32\ennsl1571.dll
Successfully Deleted: C:\WINNT\system32\ennsl1571.dll
Deleting: C:\WINNT\system32\f82mlif1182.dll
Successfully Deleted: C:\WINNT\system32\f82mlif1182.dll
Deleting: C:\WINNT\system32\fktlib.dll
Successfully Deleted: C:\WINNT\system32\fktlib.dll
Deleting: C:\WINNT\system32\fYxtiff.dll
Successfully Deleted: C:\WINNT\system32\fYxtiff.dll
Deleting: C:\WINNT\system32\hhpertrm.dll
Successfully Deleted: C:\WINNT\system32\hhpertrm.dll
Deleting: C:\WINNT\system32\hrp8057ue.dll
Successfully Deleted: C:\WINNT\system32\hrp8057ue.dll
Deleting: C:\WINNT\system32\hrr2059oe.dll
Successfully Deleted: C:\WINNT\system32\hrr2059oe.dll
Deleting: C:\WINNT\system32\icdicdll.dll
Successfully Deleted: C:\WINNT\system32\icdicdll.dll
Deleting: C:\WINNT\system32\iexsap.dll
Successfully Deleted: C:\WINNT\system32\iexsap.dll
Deleting: C:\WINNT\system32\IJETMIB1.DLL
Successfully Deleted: C:\WINNT\system32\IJETMIB1.DLL
Deleting: C:\WINNT\system32\IpagXpr5.dll
Successfully Deleted: C:\WINNT\system32\IpagXpr5.dll
Deleting: C:\WINNT\system32\irrql5951.dll
Successfully Deleted: C:\WINNT\system32\irrql5951.dll
Deleting: C:\WINNT\system32\kcdgr.dll
Successfully Deleted: C:\WINNT\system32\kcdgr.dll
Deleting: C:\WINNT\system32\kkdmac.dll
Successfully Deleted: C:\WINNT\system32\kkdmac.dll
Deleting: C:\WINNT\system32\knuser.dll
Successfully Deleted: C:\WINNT\system32\knuser.dll
Deleting: C:\WINNT\system32\kt62l7jo1.dll
Successfully Deleted: C:\WINNT\system32\kt62l7jo1.dll
Deleting: C:\WINNT\system32\ktj6l71s1.dll
Successfully Deleted: C:\WINNT\system32\ktj6l71s1.dll
Deleting: C:\WINNT\system32\lvp0097me.dll
Successfully Deleted: C:\WINNT\system32\lvp0097me.dll
Deleting: C:\WINNT\system32\lvr6099se.dll
Successfully Deleted: C:\WINNT\system32\lvr6099se.dll
Deleting: C:\WINNT\system32\mddex.dll
Successfully Deleted: C:\WINNT\system32\mddex.dll
Deleting: C:\WINNT\system32\mk42l9ho1.dll
Successfully Deleted: C:\WINNT\system32\mk42l9ho1.dll
Deleting: C:\WINNT\system32\mrdrv.dll
Successfully Deleted: C:\WINNT\system32\mrdrv.dll
Deleting: C:\WINNT\system32\mrvidc32.dll
Successfully Deleted: C:\WINNT\system32\mrvidc32.dll
Deleting: C:\WINNT\system32\mv42l9ho1.dll
Successfully Deleted: C:\WINNT\system32\mv42l9ho1.dll
Deleting: C:\WINNT\system32\MVHTML.DLL
Successfully Deleted: C:\WINNT\system32\MVHTML.DLL
Deleting: C:\WINNT\system32\mvlml9311.dll
Successfully Deleted: C:\WINNT\system32\mvlml9311.dll
Deleting: C:\WINNT\system32\mvp8l97u1.dll
Successfully Deleted: C:\WINNT\system32\mvp8l97u1.dll
Deleting: C:\WINNT\system32\mvpol9731.dll
Successfully Deleted: C:\WINNT\system32\mvpol9731.dll
Deleting: C:\WINNT\system32\mxawt.dll
Successfully Deleted: C:\WINNT\system32\mxawt.dll
Deleting: C:\WINNT\system32\myastmib.dll
Successfully Deleted: C:\WINNT\system32\myastmib.dll
Deleting: C:\WINNT\system32\mzastmib.dll
Successfully Deleted: C:\WINNT\system32\mzastmib.dll
Deleting: C:\WINNT\system32\nudsxds.dll
Successfully Deleted: C:\WINNT\system32\nudsxds.dll
Deleting: C:\WINNT\system32\o2rolc931f.dll
Successfully Deleted: C:\WINNT\system32\o2rolc931f.dll
Deleting: C:\WINNT\system32\ogethk32.dll
Successfully Deleted: C:\WINNT\system32\ogethk32.dll
Deleting: C:\WINNT\system32\ooeacc.dll
Successfully Deleted: C:\WINNT\system32\ooeacc.dll
Deleting: C:\WINNT\system32\OSE32.DLL
Successfully Deleted: C:\WINNT\system32\OSE32.DLL
Deleting: C:\WINNT\system32\p46slej71ho.dll
Successfully Deleted: C:\WINNT\system32\p46slej71ho.dll
Deleting: C:\WINNT\system32\pdrfnw.dll
Successfully Deleted: C:\WINNT\system32\pdrfnw.dll
Deleting: C:\WINNT\system32\pkustab.dll
Successfully Deleted: C:\WINNT\system32\pkustab.dll
Deleting: C:\WINNT\system32\pnustab.dll
Successfully Deleted: C:\WINNT\system32\pnustab.dll
Deleting: C:\WINNT\system32\q668lgju16o8.dll
Successfully Deleted: C:\WINNT\system32\q668lgju16o8.dll
Deleting: C:\WINNT\system32\rYrv1032.dll
Successfully Deleted: C:\WINNT\system32\rYrv1032.dll
Deleting: C:\WINNT\system32\sqlfx.dll
Successfully Deleted: C:\WINNT\system32\sqlfx.dll
Deleting: C:\WINNT\system32\stns.dll
Successfully Deleted: C:\WINNT\system32\stns.dll
Deleting: C:\WINNT\system32\TmnLib20.dll
Successfully Deleted: C:\WINNT\system32\TmnLib20.dll
Deleting: C:\WINNT\system32\toaffic.dll
Successfully Deleted: C:\WINNT\system32\toaffic.dll
Deleting: C:\WINNT\system32\uol.dll
Successfully Deleted: C:\WINNT\system32\uol.dll
Deleting: C:\WINNT\system32\wfn87em.dll
Successfully Deleted: C:\WINNT\system32\wfn87em.dll
Deleting: C:\WINNT\system32\wvi.dll
Successfully Deleted: C:\WINNT\system32\wvi.dll
Deleting: C:\WINNT\system32\guard.tmp
Successfully Deleted: C:\WINNT\system32\guard.tmp
msg11?.dll
0 file copiati.
Desktop.ini sucessfully removed
Restoring Windows Update Certificates.:
The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\App Management]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINNT\\system32\\aza8l97u1.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
"DLLName"="wzcdlg.dll"
"Logon"="WZCEventLogon"
"Logoff"="WZCEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000000
The following are the files found:
****************************************************************************
C:\WINNT\system32\aza8l97u1.dll
C:\WINNT\system32\ckcdll.dll
C:\WINNT\system32\cLrds.dll
C:\WINNT\system32\dlkquoui.dll
C:\WINNT\system32\dnnu0159e.dll
C:\WINNT\system32\dpskadp.dll
C:\WINNT\system32\duvenum.dll
C:\WINNT\system32\dxmv2clt.dll
C:\WINNT\system32\ennsl1571.dll
C:\WINNT\system32\f82mlif1182.dll
C:\WINNT\system32\fktlib.dll
C:\WINNT\system32\fYxtiff.dll
C:\WINNT\system32\hhpertrm.dll
C:\WINNT\system32\hrp8057ue.dll
C:\WINNT\system32\hrr2059oe.dll
C:\WINNT\system32\icdicdll.dll
C:\WINNT\system32\iexsap.dll
C:\WINNT\system32\IJETMIB1.DLL
C:\WINNT\system32\IpagXpr5.dll
C:\WINNT\system32\irrql5951.dll
C:\WINNT\system32\kcdgr.dll
C:\WINNT\system32\kkdmac.dll
C:\WINNT\system32\knuser.dll
C:\WINNT\system32\kt62l7jo1.dll
C:\WINNT\system32\ktj6l71s1.dll
C:\WINNT\system32\lvp0097me.dll
C:\WINNT\system32\lvr6099se.dll
C:\WINNT\system32\mddex.dll
C:\WINNT\system32\mk42l9ho1.dll
C:\WINNT\system32\mrdrv.dll
C:\WINNT\system32\mrvidc32.dll
C:\WINNT\system32\mv42l9ho1.dll
C:\WINNT\system32\MVHTML.DLL
C:\WINNT\system32\mvlml9311.dll
C:\WINNT\system32\mvp8l97u1.dll
C:\WINNT\system32\mvpol9731.dll
C:\WINNT\system32\mxawt.dll
C:\WINNT\system32\myastmib.dll
C:\WINNT\system32\mzastmib.dll
C:\WINNT\system32\nudsxds.dll
C:\WINNT\system32\o2rolc931f.dll
C:\WINNT\system32\ogethk32.dll
C:\WINNT\system32\ooeacc.dll
C:\WINNT\system32\OSE32.DLL
C:\WINNT\system32\p46slej71ho.dll
C:\WINNT\system32\pdrfnw.dll
C:\WINNT\system32\pkustab.dll
C:\WINNT\system32\pnustab.dll
C:\WINNT\system32\q668lgju16o8.dll
C:\WINNT\system32\rYrv1032.dll
C:\WINNT\system32\sqlfx.dll
C:\WINNT\system32\stns.dll
C:\WINNT\system32\TmnLib20.dll
C:\WINNT\system32\toaffic.dll
C:\WINNT\system32\uol.dll
C:\WINNT\system32\wfn87em.dll
C:\WINNT\system32\wvi.dll
C:\WINNT\system32\guard.tmp
Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{4A80F243-9EA7-450E-84F3-2222CBE3B8F5}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{4A80F243-9EA7-450E-84F3-2222CBE3B8F5}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{4A80F243-9EA7-450E-84F3-2222CBE3B8F5}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{4A80F243-9EA7-450E-84F3-2222CBE3B8F5}\InprocServer32]
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{B9433D1B-7FCD-4C47-8752-DA2E7F79CA62}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{B9433D1B-7FCD-4C47-8752-DA2E7F79CA62}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{B9433D1B-7FCD-4C47-8752-DA2E7F79CA62}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{B9433D1B-7FCD-4C47-8752-DA2E7F79CA62}\InprocServer32]
@="C:\\WINNT\\system32\\rYrv1032.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{3A46714B-9258-4C05-B375-0970C3599025}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{3A46714B-9258-4C05-B375-0970C3599025}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{3A46714B-9258-4C05-B375-0970C3599025}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{3A46714B-9258-4C05-B375-0970C3599025}\InprocServer32]
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{5B928B93-6C54-46C9-BA0B-F6E32FB5108B}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{5B928B93-6C54-46C9-BA0B-F6E32FB5108B}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{5B928B93-6C54-46C9-BA0B-F6E32FB5108B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{5B928B93-6C54-46C9-BA0B-F6E32FB5108B}\InprocServer32]
@="C:\\WINNT\\system32\\knuser.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{17421275-4F1F-44D2-A686-7A7ACA19C7A5}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{17421275-4F1F-44D2-A686-7A7ACA19C7A5}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{17421275-4F1F-44D2-A686-7A7ACA19C7A5}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{17421275-4F1F-44D2-A686-7A7ACA19C7A5}\InprocServer32]
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{9BF0E7DF-1A29-403B-9436-205CCE0662AF}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{9BF0E7DF-1A29-403B-9436-205CCE0662AF}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{9BF0E7DF-1A29-403B-9436-205CCE0662AF}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{9BF0E7DF-1A29-403B-9436-205CCE0662AF}\InprocServer32]
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{685F953B-11E3-4EEE-AB87-6333F39D6E7C}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{685F953B-11E3-4EEE-AB87-6333F39D6E7C}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{685F953B-11E3-4EEE-AB87-6333F39D6E7C}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{685F953B-11E3-4EEE-AB87-6333F39D6E7C}\InprocServer32]
@="C:\\WINNT\\system32\\duvenum.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{707144A7-32DD-4175-B64C-0ED6DF71990E}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{707144A7-32DD-4175-B64C-0ED6DF71990E}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{707144A7-32DD-4175-B64C-0ED6DF71990E}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{707144A7-32DD-4175-B64C-0ED6DF71990E}\InprocServer32]
@="C:\\WINNT\\system32\\dscompos.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{4B514CB2-A51F-493E-81E1-978EB9DE04E0}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{4B514CB2-A51F-493E-81E1-978EB9DE04E0}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{4B514CB2-A51F-493E-81E1-978EB9DE04E0}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{4B514CB2-A51F-493E-81E1-978EB9DE04E0}\InprocServer32]
@="C:\\WINNT\\system32\\ooeacc.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{ED90EE6B-9717-4B0B-BCEF-F4D4095EC030}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{ED90EE6B-9717-4B0B-BCEF-F4D4095EC030}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{ED90EE6B-9717-4B0B-BCEF-F4D4095EC030}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{ED90EE6B-9717-4B0B-BCEF-F4D4095EC030}\InprocServer32]
@="C:\\WINNT\\system32\\MVHTML.DLL"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{27358924-4091-4C87-A153-F6DE7AA11918}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{27358924-4091-4C87-A153-F6DE7AA11918}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{27358924-4091-4C87-A153-F6DE7AA11918}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{27358924-4091-4C87-A153-F6DE7AA11918}\InprocServer32]
@="C:\\WINNT\\system32\\fYxtiff.dll"
"ThreadingModel"="Apartment"
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{4A80F243-9EA7-450E-84F3-2222CBE3B8F5}"=-
"{B9433D1B-7FCD-4C47-8752-DA2E7F79CA62}"=-
"{3A46714B-9258-4C05-B375-0970C3599025}"=-
"{5B928B93-6C54-46C9-BA0B-F6E32FB5108B}"=-
"{17421275-4F1F-44D2-A686-7A7ACA19C7A5}"=-
"{9BF0E7DF-1A29-403B-9436-205CCE0662AF}"=-
"{685F953B-11E3-4EEE-AB87-6333F39D6E7C}"=-
"{707144A7-32DD-4175-B64C-0ED6DF71990E}"=-
"{4B514CB2-A51F-493E-81E1-978EB9DE04E0}"=-
"{ED90EE6B-9717-4B0B-BCEF-F4D4095EC030}"=-
"{27358924-4091-4C87-A153-F6DE7AA11918}"=-
[-HKEY_CLASSES_ROOT\CLSID\{4A80F243-9EA7-450E-84F3-2222CBE3B8F5}]
[-HKEY_CLASSES_ROOT\CLSID\{B9433D1B-7FCD-4C47-8752-DA2E7F79CA62}]
[-HKEY_CLASSES_ROOT\CLSID\{3A46714B-9258-4C05-B375-0970C3599025}]
[-HKEY_CLASSES_ROOT\CLSID\{5B928B93-6C54-46C9-BA0B-F6E32FB5108B}]
[-HKEY_CLASSES_ROOT\CLSID\{17421275-4F1F-44D2-A686-7A7ACA19C7A5}]
[-HKEY_CLASSES_ROOT\CLSID\{9BF0E7DF-1A29-403B-9436-205CCE0662AF}]
[-HKEY_CLASSES_ROOT\CLSID\{685F953B-11E3-4EEE-AB87-6333F39D6E7C}]
[-HKEY_CLASSES_ROOT\CLSID\{707144A7-32DD-4175-B64C-0ED6DF71990E}]
[-HKEY_CLASSES_ROOT\CLSID\{4B514CB2-A51F-493E-81E1-978EB9DE04E0}]
[-HKEY_CLASSES_ROOT\CLSID\{ED90EE6B-9717-4B0B-BCEF-F4D4095EC030}]
[-HKEY_CLASSES_ROOT\CLSID\{27358924-4091-4C87-A153-F6DE7AA11918}]
REGEDIT4
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
****************************************************************************
Desktop.ini Contents:
****************************************************************************
****************************************************************************
Checking for L2MFix account(0=no 1=yes):
0
Zipping up files for submission:
adding: dlls/aza8l97u1.dll (deflated 6%)
adding: dlls/ckcdll.dll (deflated 4%)
adding: dlls/cLrds.dll (deflated 5%)
adding: dlls/dlkquoui.dll (deflated 5%)
adding: dlls/dnnu0159e.dll (deflated 5%)
adding: dlls/dpskadp.dll (deflated 5%)
adding: dlls/duvenum.dll (deflated 5%)
adding: dlls/dxmv2clt.dll (deflated 4%)
adding: dlls/ennsl1571.dll (deflated 4%)
adding: dlls/f82mlif1182.dll (deflated 4%)
adding: dlls/fktlib.dll (deflated 5%)
adding: dlls/fYxtiff.dll (deflated 6%)
adding: dlls/hhpertrm.dll (deflated 5%)
adding: dlls/hrp8057ue.dll (deflated 4%)
adding: dlls/hrr2059oe.dll (deflated 4%)
adding: dlls/icdicdll.dll (deflated 4%)
adding: dlls/iexsap.dll (deflated 5%)
adding: dlls/IJETMIB1.DLL (deflated 5%)
adding: dlls/IpagXpr5.dll (deflated 4%)
adding: dlls/irrql5951.dll (deflated 6%)
adding: dlls/kcdgr.dll (deflated 4%)
adding: dlls/kkdmac.dll (deflated 6%)
adding: dlls/knuser.dll (deflated 5%)
adding: dlls/kt62l7jo1.dll (deflated 5%)
adding: dlls/ktj6l71s1.dll (deflated 5%)
adding: dlls/lvp0097me.dll (deflated 4%)
adding: dlls/lvr6099se.dll (deflated 5%)
adding: dlls/mddex.dll (deflated 4%)
adding: dlls/mk42l9ho1.dll (deflated 5%)
adding: dlls/mrdrv.dll (deflated 4%)
adding: dlls/mrvidc32.dll (deflated 5%)
adding: dlls/mv42l9ho1.dll (deflated 5%)
adding: dlls/MVHTML.DLL (deflated 5%)
adding: dlls/mvlml9311.dll (deflated 4%)
adding: dlls/mvp8l97u1.dll (deflated 5%)
adding: dlls/mvpol9731.dll (deflated 5%)
adding: dlls/mxawt.dll (deflated 4%)
adding: dlls/myastmib.dll (deflated 5%)
adding: dlls/mzastmib.dll (deflated 4%)
adding: dlls/nudsxds.dll (deflated 5%)
adding: dlls/o2rolc931f.dll (deflated 4%)
adding: dlls/ogethk32.dll (deflated 6%)
adding: dlls/ooeacc.dll (deflated 5%)
adding: dlls/OSE32.DLL (deflated 5%)
adding: dlls/p46slej71ho.dll (deflated 4%)
adding: dlls/pdrfnw.dll (deflated 5%)
adding: dlls/pkustab.dll (deflated 4%)
adding: dlls/pnustab.dll (deflated 5%)
adding: dlls/q668lgju16o8.dll (deflated 5%)
adding: dlls/rYrv1032.dll (deflated 5%)
adding: dlls/sqlfx.dll (deflated 5%)
adding: dlls/stns.dll (deflated 5%)
adding: dlls/TmnLib20.dll (deflated 5%)
adding: dlls/toaffic.dll (deflated 5%)
adding: dlls/uol.dll (deflated 5%)
adding: dlls/wfn87em.dll (deflated 5%)
adding: dlls/wvi.dll (deflated 5%)
adding: dlls/guard.tmp (deflated 6%)
adding: backregs/notibac.reg (deflated 63%)
adding: backregs/shell.reg (deflated 74%)
adding: backregs/4A80F243-9EA7-450E-84F3-2222CBE3B8F5.reg (deflated 71%)
adding: backregs/B9433D1B-7FCD-4C47-8752-DA2E7F79CA62.reg (deflated 70%)
adding: backregs/3A46714B-9258-4C05-B375-0970C3599025.reg (deflated 71%)
adding: backregs/5B928B93-6C54-46C9-BA0B-F6E32FB5108B.reg (deflated 70%)
adding: backregs/17421275-4F1F-44D2-A686-7A7ACA19C7A5.reg (deflated 71%)
adding: backregs/9BF0E7DF-1A29-403B-9436-205CCE0662AF.reg (deflated 71%)
adding: backregs/685F953B-11E3-4EEE-AB87-6333F39D6E7C.reg (deflated 70%)
adding: backregs/707144A7-32DD-4175-B64C-0ED6DF71990E.reg (deflated 70%)
adding: backregs/4B514CB2-A51F-493E-81E1-978EB9DE04E0.reg (deflated 70%)
adding: backregs/ED90EE6B-9717-4B0B-BCEF-F4D4095EC030.reg (deflated 70%)
adding: backregs/27358924-4091-4C87-A153-F6DE7AA11918.reg (deflated 70%)
bye and thank you very much roby