L2mfix 010406
Creating Account.
Polecenie zostao wykonane pomylnie.
Adding Administrative privleges.
Checking for L2MFix account(0=no 1=yes):
1
Granting SeDebugPrivilege to L2MFIX ... successful
Running From:
D:\WINDOWS\system32
Killing Processes!
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003
Craig.Peacock@beyondlogic.orgKilling PID 600 'smss.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003
Craig.Peacock@beyondlogic.orgKilling PID 696 'winlogon.exe'
Killing PID 696 'winlogon.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003
Craig.Peacock@beyondlogic.orgKilling PID 2708 'explorer.exe'
Killing PID 2708 'explorer.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003
Craig.Peacock@beyondlogic.orgKilling PID 1616 'rundll32.exe'
Restoring Sedebugprivilege:
Granting SeDebugPrivilege to Administratorzy ... successful
Scanning First Pass. Please Wait!
First Pass Completed
Second Pass Scanning
Second pass Completed!
Liczba skopiowanych plik˘w: 1.
Liczba skopiowanych plik˘w: 1.
Liczba skopiowanych plik˘w: 1.
Liczba skopiowanych plik˘w: 1.
Liczba skopiowanych plik˘w: 1.
Liczba skopiowanych plik˘w: 1.
Liczba skopiowanych plik˘w: 1.
Liczba skopiowanych plik˘w: 1.
Liczba skopiowanych plik˘w: 1.
Liczba skopiowanych plik˘w: 1.
Liczba skopiowanych plik˘w: 1.
Liczba skopiowanych plik˘w: 1.
Liczba skopiowanych plik˘w: 1.
Deleting: D:\WINDOWS\system32\aesnw.dll
Successfully Deleted: D:\WINDOWS\system32\aesnw.dll
Deleting: D:\WINDOWS\system32\e820lifm182a.dll
Successfully Deleted: D:\WINDOWS\system32\e820lifm182a.dll
Deleting: D:\WINDOWS\system32\hr4005hme.dll
Successfully Deleted: D:\WINDOWS\system32\hr4005hme.dll
Deleting: D:\WINDOWS\system32\iXsnap.dll
Successfully Deleted: D:\WINDOWS\system32\iXsnap.dll
Deleting: D:\WINDOWS\system32\jt0807due.dll
Successfully Deleted: D:\WINDOWS\system32\jt0807due.dll
Deleting: D:\WINDOWS\system32\jt2007fme.dll
Successfully Deleted: D:\WINDOWS\system32\jt2007fme.dll
Deleting: D:\WINDOWS\system32\kvdkaz.dll
Successfully Deleted: D:\WINDOWS\system32\kvdkaz.dll
Deleting: D:\WINDOWS\system32\l2n4lc5q1f.dll
Successfully Deleted: D:\WINDOWS\system32\l2n4lc5q1f.dll
Deleting: D:\WINDOWS\system32\m046lahs1d46.dll
Successfully Deleted: D:\WINDOWS\system32\m046lahs1d46.dll
Deleting: D:\WINDOWS\system32\mfwstr10.dll
Successfully Deleted: D:\WINDOWS\system32\mfwstr10.dll
Deleting: D:\WINDOWS\system32\mv88l9lu1.dll
Successfully Deleted: D:\WINDOWS\system32\mv88l9lu1.dll
Deleting: D:\WINDOWS\system32\ojesvr32.dll
Successfully Deleted: D:\WINDOWS\system32\ojesvr32.dll
Deleting: D:\WINDOWS\system32\opbc32gt.dll
Successfully Deleted: D:\WINDOWS\system32\opbc32gt.dll
msg11?.dll
Liczba skopiowanych plik˘w: 0.
Desktop.ini sucessfully removed
Restoring Windows Update Certificates.:
The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
"DLLName"="Ati2evxx.dll"
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000001
"Lock"="AtiLockEvent"
"Logoff"="AtiLogoffEvent"
"Logon"="AtiLogonEvent"
"Disconnect"="AtiDisConnectEvent"
"Reconnect"="AtiReConnectEvent"
"Safe"=dword:00000000
"Shutdown"="AtiShutdownEvent"
"StartScreenSaver"="AtiStartScreenSaverEvent"
"StartShell"="AtiStartShellEvent"
"Startup"="AtiStartupEvent"
"StopScreenSaver"="AtiStopScreenSaverEvent"
"Unlock"="AtiUnLockEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ShellCompatibility]
"Asynchronous"=dword:00000000
"DllName"="D:\\WINDOWS\\system32\\m046lahs1d46.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
The following are the files found:
****************************************************************************
D:\WINDOWS\system32\aesnw.dll
D:\WINDOWS\system32\e820lifm182a.dll
D:\WINDOWS\system32\hr4005hme.dll
D:\WINDOWS\system32\iXsnap.dll
D:\WINDOWS\system32\jt0807due.dll
D:\WINDOWS\system32\jt2007fme.dll
D:\WINDOWS\system32\kvdkaz.dll
D:\WINDOWS\system32\l2n4lc5q1f.dll
D:\WINDOWS\system32\m046lahs1d46.dll
D:\WINDOWS\system32\mfwstr10.dll
D:\WINDOWS\system32\mv88l9lu1.dll
D:\WINDOWS\system32\ojesvr32.dll
D:\WINDOWS\system32\opbc32gt.dll
Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{5BAB52B2-107C-45A9-B905-D87A40BB4444}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{5BAB52B2-107C-45A9-B905-D87A40BB4444}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{5BAB52B2-107C-45A9-B905-D87A40BB4444}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{5BAB52B2-107C-45A9-B905-D87A40BB4444}\InprocServer32]
@="D:\\WINDOWS\\system32\\kvdkaz.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{EE0AC656-EE74-4C1E-9E70-D67E9B67954C}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{EE0AC656-EE74-4C1E-9E70-D67E9B67954C}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{EE0AC656-EE74-4C1E-9E70-D67E9B67954C}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{EE0AC656-EE74-4C1E-9E70-D67E9B67954C}\InprocServer32]
@="D:\\WINDOWS\\system32\\iXsnap.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{105384E9-D42B-416A-B8BF-5C48D82FE73D}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{105384E9-D42B-416A-B8BF-5C48D82FE73D}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{105384E9-D42B-416A-B8BF-5C48D82FE73D}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{105384E9-D42B-416A-B8BF-5C48D82FE73D}\InprocServer32]
@="D:\\WINDOWS\\system32\\aesnw.dll"
"ThreadingModel"="Apartment"
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{5BAB52B2-107C-45A9-B905-D87A40BB4444}"=-
"{EE0AC656-EE74-4C1E-9E70-D67E9B67954C}"=-
"{105384E9-D42B-416A-B8BF-5C48D82FE73D}"=-
[-HKEY_CLASSES_ROOT\CLSID\{5BAB52B2-107C-45A9-B905-D87A40BB4444}]
[-HKEY_CLASSES_ROOT\CLSID\{EE0AC656-EE74-4C1E-9E70-D67E9B67954C}]
[-HKEY_CLASSES_ROOT\CLSID\{105384E9-D42B-416A-B8BF-5C48D82FE73D}]
REGEDIT4
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
****************************************************************************
Desktop.ini Contents:
****************************************************************************
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
****************************************************************************
Checking for L2MFix account(0=no 1=yes):
0
Zipping up files for submission:
adding: dlls/aesnw.dll (deflated 5%)
adding: dlls/e820lifm182a.dll (deflated 4%)
adding: dlls/hr4005hme.dll (deflated 4%)
adding: dlls/iXsnap.dll (deflated 5%)
adding: dlls/jt0807due.dll (deflated 5%)
adding: dlls/jt2007fme.dll (deflated 4%)
adding: dlls/kvdkaz.dll (deflated 4%)
adding: dlls/l2n4lc5q1f.dll (deflated 5%)
adding: dlls/m046lahs1d46.dll (deflated 5%)
adding: dlls/mfwstr10.dll (deflated 5%)
adding: dlls/mv88l9lu1.dll (deflated 5%)
adding: dlls/ojesvr32.dll (deflated 5%)
adding: dlls/opbc32gt.dll (deflated 4%)
adding: backregs/notibac.reg (deflated 87%)
adding: backregs/shell.reg (deflated 73%)
adding: backregs/5BAB52B2-107C-45A9-B905-D87A40BB4444.reg (deflated 70%)
adding: backregs/EE0AC656-EE74-4C1E-9E70-D67E9B67954C.reg (deflated 70%)
adding: backregs/105384E9-D42B-416A-B8BF-5C48D82FE73D.reg (deflated 70%)