Thanks for replying. Here is all the logs
* fresh hijack log *
Logfile of HijackThis v1.99.0
Scan saved at 6:21:24 PM, on 1/20/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Jack\Desktop\HijackThis.exe
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O2 - BHO: (no name) - {49FAC937-0255-417C-F5CF-DBF2A1908CCC} - (no file)
O2 - BHO: (no name) - {8E3908A9-E51A-272A-E16F-0FDF0CF1E52E} - (no file)
* VX2 log *
Log for VX2.BetterInternet File Finder (ALL)
Files Found---
Additional Files---
Keys Under Notify---
Applets
Schedule
sclgntfy
Guardian Key--- is called:
Guardian Key--- :
User Agent String---
{C51E540C-C0FE-484C-AA63-00E552C043B0}
# Start of entries inserted by Spybot - Search & Destroy
# End of entries inserted by Spybot - Search & Destroy
# End of entries inserted by Spybot - Search & Destroy
# End of entries inserted by Spybot - Search & Destroy
# End of entries inserted by Spybot - Search & Destroy
# End of entries inserted by Spybot - Search & Destroy
# End of entries inserted by Spybot - Search & Destroy
# End of entries inserted by Spybot - Search & Destroy
127.0.0.1
www.igetnet.com
127.0.0.1 code.ignphrases.com
127.0.0.1 clear-search.com
127.0.0.1 r1.clrsch.com
127.0.0.1 sds.clrsch.com
127.0.0.1 status.clrsch.com
127.0.0.1
www.clrsch.com
127.0.0.1 clr-sch.com
127.0.0.1 sds-qckads.com
127.0.0.1 status.qckads.com
69.20.16.183 auto.search.msn.com
69.20.16.183 search.netscape.com
69.20.16.183 ieautosearch
69.20.16.183 ieautosearch
* DLLCompare Log version(1.0.0.127) *
Files Found that Windows does not See or cannot Access
*Not everything listed here means you are infected!
________________________________________________
C:\WINDOWS\SYSTEM32\aza6l3~1.dll Thu Dec 16 2004 3:42:56p ..S.R 224,520 219.26 K
C:\WINDOWS\SYSTEM32\azam0c~1.dll Sun Jan 16 2005 12:16:58p ..S.R 223,812 218.57 K
C:\WINDOWS\SYSTEM32\cpm.dll Sat Dec 18 2004 5:41:12p ..S.R 223,037 217.81 K
C:\WINDOWS\SYSTEM32\d8j0li~1.dll Sat Dec 18 2004 6:10:52p ..S.R 223,178 217.95 K
C:\WINDOWS\SYSTEM32\dn4401~1.dll Wed Dec 15 2004 3:37:52p ..S.R 224,520 219.26 K
C:\WINDOWS\SYSTEM32\dnnu01~1.dll Thu Jan 20 2005 4:47:16p ..S.R 225,689 220.40 K
C:\WINDOWS\SYSTEM32\dwcompos.dll Sat Dec 18 2004 2:54:34p ..S.R 223,132 217.90 K
C:\WINDOWS\SYSTEM32\dxnaddr.dll Sat Jan 1 2005 3:52:02a ..S.R 225,441 220.16 K
C:\WINDOWS\SYSTEM32\e2jm0c~1.dll Wed Dec 15 2004 11:37:06p ..S.R 224,520 219.26 K
C:\WINDOWS\SYSTEM32\e4020e~1.dll Sat Dec 18 2004 7:22:50a ..S.R 223,336 218.10 K
C:\WINDOWS\SYSTEM32\enlsl1~1.dll Thu Jan 20 2005 3:34:32p ..S.R 225,689 220.40 K
C:\WINDOWS\SYSTEM32\enn0l1~1.dll Fri Dec 17 2004 9:45:32p ..S.R 225,571 220.28 K
C:\WINDOWS\SYSTEM32\ennol1~1.dll Tue Dec 28 2004 10:39:34a ..S.R 225,396 220.11 K
C:\WINDOWS\SYSTEM32\enpml1~1.dll Thu Dec 30 2004 4:48:00a ..S.R 224,311 219.05 K
C:\WINDOWS\SYSTEM32\fn2021~1.dll Mon Dec 13 2004 3:27:14p ..S.R 224,520 219.26 K
C:\WINDOWS\SYSTEM32\gdtext.dll Sat Dec 18 2004 5:55:28a ..S.R 224,520 219.26 K
C:\WINDOWS\SYSTEM32\gp46l3~1.dll Mon Dec 13 2004 3:11:26p ..S.R 224,210 218.95 K
C:\WINDOWS\SYSTEM32\h0n0la~1.dll Mon Jan 17 2005 7:25:44p ..S.R 222,733 217.51 K
C:\WINDOWS\SYSTEM32\h40q0e~1.dll Sun Dec 12 2004 3:00:38p ..S.R 223,736 218.49 K
C:\WINDOWS\SYSTEM32\h40qle~1.dll Sun Dec 12 2004 10:33:24p ..S.R 224,736 219.47 K
C:\WINDOWS\SYSTEM32\h4l20e~1.dll Sun Dec 19 2004 4:52:44p ..S.R 222,909 217.68 K
C:\WINDOWS\SYSTEM32\i6240g~1.dll Sat Jan 15 2005 6:15:10p ..S.R 223,636 218.39 K
C:\WINDOWS\SYSTEM32\i6jqlg~1.dll Sat Jan 8 2005 8:19:18p ..S.R 224,223 218.96 K
C:\WINDOWS\SYSTEM32\i8loli~1.dll Tue Dec 28 2004 10:37:54a ..S.R 224,916 219.64 K
C:\WINDOWS\SYSTEM32\igjp81k.dll Sat Dec 18 2004 5:22:32p ..S.R 223,132 217.90 K
C:\WINDOWS\SYSTEM32\ir48l5~1.dll Wed Jan 19 2005 12:21:56a ..S.R 225,945 220.65 K
C:\WINDOWS\SYSTEM32\irj2l5~1.dll Tue Dec 21 2004 5:23:06a ..S.R 224,311 219.05 K
C:\WINDOWS\SYSTEM32\irjsl5~1.dll Sun Dec 12 2004 10:33:28p ..S.R 223,827 218.58 K
C:\WINDOWS\SYSTEM32\j8l40i~1.dll Sun Dec 19 2004 8:07:06a ..S.R 225,992 220.70 K
C:\WINDOWS\SYSTEM32\jt6u07~1.dll Tue Dec 28 2004 5:26:44a ..S.R 224,311 219.05 K
C:\WINDOWS\SYSTEM32\jtpo07~1.dll Fri Dec 17 2004 6:42:00p ..S.R 224,520 219.26 K
C:\WINDOWS\SYSTEM32\k4620e~1.dll Tue Dec 21 2004 12:55:24a ..S.R 224,311 219.05 K
C:\WINDOWS\SYSTEM32\k6260g~1.dll Thu Dec 16 2004 4:06:36p ..S.R 224,520 219.26 K
C:\WINDOWS\SYSTEM32\k8noli~1.dll Sun Dec 19 2004 4:32:36p ..S.R 224,033 218.78 K
C:\WINDOWS\SYSTEM32\kt26l7~1.dll Thu Dec 16 2004 3:44:54p ..S.R 224,520 219.26 K
C:\WINDOWS\SYSTEM32\ktrul7~1.dll Mon Dec 20 2004 3:09:00a ..S.R 224,700 219.43 K
C:\WINDOWS\SYSTEM32\l06o0a~1.dll Thu Jan 20 2005 3:02:40p ..S.R 225,172 219.89 K
C:\WINDOWS\SYSTEM32\l06ola~1.dll Mon Dec 13 2004 2:01:34p ..S.R 225,570 220.28 K
C:\WINDOWS\SYSTEM32\l64q0g~1.dll Fri Jan 7 2005 12:14:36a ..S.R 225,987 220.69 K
C:\WINDOWS\SYSTEM32\luprxy.dll Sun Dec 19 2004 7:39:52a ..S.R 225,554 220.27 K
C:\WINDOWS\SYSTEM32\lv2m09~1.dll Fri Jan 14 2005 11:43:22a ..S.R 223,210 217.98 K
C:\WINDOWS\SYSTEM32\m4820e~1.dll Mon Jan 17 2005 7:05:28p ..S.R 226,229 220.93 K
C:\WINDOWS\SYSTEM32\m828li~1.dll Sat Jan 8 2005 6:10:42p ..S.R 224,535 219.27 K
C:\WINDOWS\SYSTEM32\m8640i~1.dll Sat Jan 8 2005 8:04:48p ..S.R 223,175 217.94 K
C:\WINDOWS\SYSTEM32\m864li~1.dll Thu Dec 16 2004 11:04:34p ..S.R 224,520 219.26 K
C:\WINDOWS\SYSTEM32\mv2ol9~1.dll Sun Dec 19 2004 2:00:52a ..S.R 224,836 219.57 K
C:\WINDOWS\SYSTEM32\mvjul9~1.dll Mon Dec 20 2004 5:58:28p ..S.R 222,703 217.48 K
C:\WINDOWS\SYSTEM32\n26q0c~1.dll Fri Dec 17 2004 6:11:44p ..S.R 224,520 219.26 K
C:\WINDOWS\SYSTEM32\n42ule~1.dll Sat Dec 18 2004 5:41:12p ..S.R 224,961 219.69 K
C:\WINDOWS\SYSTEM32\n6n6lg~1.dll Tue Dec 21 2004 12:57:42a ..S.R 224,311 219.05 K
C:\WINDOWS\SYSTEM32\nhwrsde.dll Sat Dec 18 2004 7:22:50a ..S.R 223,132 217.90 K
C:\WINDOWS\SYSTEM32\p28q0c~1.dll Wed Dec 15 2004 11:08:24p ..S.R 224,520 219.26 K
C:\WINDOWS\SYSTEM32\p4p6le~1.dll Thu Dec 16 2004 3:59:20p ..S.R 224,520 219.26 K
C:\WINDOWS\SYSTEM32\p8r4li~1.dll Thu Jan 20 2005 4:41:26p ..S.R 223,209 217.98 K
C:\WINDOWS\SYSTEM32\pcpoops2.dll Wed Jan 19 2005 12:59:12a ..S.R 222,554 217.34 K
C:\WINDOWS\SYSTEM32\pi8q0c~1.dll Sat Dec 18 2004 5:32:04p ..S.R 225,165 219.89 K
C:\WINDOWS\SYSTEM32\ruvpsp.dll Sat Dec 18 2004 5:59:32p ..S.R 223,037 217.81 K
________________________________________________
1,372 items found: 1,372 files (57 H/S), 0 directories.
Total of file sizes: 274,904,496 bytes 262.17 M
Administrator Account = True
--------------------End log--------------------
* silent runners *
"Silent Runners.vbs", revision 29, launched at: 18:23
Output limited to non-default values, except where indicated by "{++}"
Operating System: Windows XP
Startup items buried in registry:
---------------------------------
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"
-> CLSID InProcServer32 resolves to: "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
-> CLSID InProcServer32 resolves to: "C:\Program Files\Microsoft Office\Office10\OLKFSTUB.DLL" [file not found]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> CLSID InProcServer32 resolves to: "C:\Program Files\Microsoft Office\Office10\msohev.dll" [file not found]
"{1CDB2949-8F65-4355-8456-263E7C208A5D}" = "Desktop Explorer"
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" = "Desktop Explorer Menu"
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
-> CLSID InProcServer32 resolves to: "C:\Program Files\Real\RealPlayer\rpshell.dll" ["RealNetworks, Inc."]
"{FFB699E0-306A-11d3-8BD1-00104B6F7516}" = "Play on my TV helper"
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\System32\nvcpl.dll" ["NVIDIA Corporation"]
"{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class"
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\System32\NVCPL.DLL" ["NVIDIA Corporation"]
"{1E9B04FB-F9E5-4718-997B-B8DA88302A48}" = "nView Desktop Context Menu"
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
"{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices"
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\System32\Audiodev.dll" [MS]
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\System32\Audiodev.dll" [MS]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
-> CLSID InProcServer32 resolves to: "C:\Program Files\WinRAR\rarext.dll" [null data]
"{1C7493B8-ADF8-4A8A-B48A-53AFE918B117}" = (no title provided)
-> CLSID InProcServer32 resolves to: "blank" [file not found]
"{1406A802-54FA-4D11-88A0-B4C7F9468685}" = (no title provided)
-> CLSID InProcServer32 resolves to: "blank" [file not found]
"{C7A441C1-9EC5-457C-9802-7D57ED9FFEEF}" = (no title provided)
-> CLSID InProcServer32 resolves to: "blank" [file not found]
"{3C99EB25-125C-4CD7-9481-C897C2C8B111}" = (no title provided)
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\system32\lUprxy.dll" [null data]
"{64302F22-1A89-4955-ACD1-2913B793C311}" = (no title provided)
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\system32\wwspdmod.dll" [null data]
"{FFB4856B-3197-43C7-86B1-6217BE50E191}" = (no title provided)
-> CLSID InProcServer32 resolves to: "blank" [file not found]
"{30E090EB-6C52-412D-A40B-2D9DA4CB93B9}" = (no title provided)
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\system32\wlpsrcwp.dll" [null data]
"{D2E6C52C-F6A9-4DA9-AF33-4DD2466BC2CE}" = (no title provided)
-> CLSID InProcServer32 resolves to: "blank" [file not found]
"{3723FED2-9031-46E1-A30A-D5046114B43A}" = (no title provided)
-> CLSID InProcServer32 resolves to: "blank" [file not found]
"{FA16833A-1D28-44E0-B1ED-004644009591}" = (no title provided)
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\system32\mwiole32.dll" [null data]
"{89CC7B4E-0A4D-4C20-A1B6-E440CAC9E733}" = (no title provided)
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\system32\guard.tmp" [null data]
"{35D3B0BE-9754-4AA5-9C55-444C2FF54D9B}" = (no title provided)
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\system32\mklogmgr.dll" [null data]
"{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Shell Extension"
-> CLSID InProcServer32 resolves to: "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
"{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Find Extension"
-> CLSID InProcServer32 resolves to: "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
"{AEA6995A-2D31-4790-8866-4FA6F8F596F5}" = (no title provided)
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\system32\hW23msp.dll" [file not found]
"{B9626865-10A6-4839-A015-4DA33D162839}" = (no title provided)
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\system32\guard.tmp" [null data]
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
INFECTION WARNING! "Applets\DLLName" = "C:\WINDOWS\system32\enlsl1371.dll" [null data]
Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------
Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\System32\wdfmgr.exe" [MS]
----------
This report excludes default entries except where indicated.
To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
----------
* findit output.txt *
Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.
------- System Files in System32 Directory -------
Volume in drive C has no label.
Volume Serial Number is 8403-2473
Directory of C:\WINDOWS\System32
01/20/2005 05:04 PM <DIR> dllcache
01/20/2005 04:47 PM 225,689 dnnu0159e.dll
01/20/2005 04:41 PM 223,209 p8r4li9q18.dll
01/20/2005 03:34 PM 225,689 enlsl1371.dll
01/20/2005 03:02 PM 225,172 l06o0aj3edo.dll
01/19/2005 12:59 AM 222,554 PcpOops2.dll
01/19/2005 12:21 AM 225,945 ir48l5hu1.dll
01/17/2005 07:25 PM 222,733 h0n0la5m1d.dll
01/17/2005 07:05 PM 226,229 m4820eloehqc0.dll
01/16/2005 12:16 PM 223,812 azam0c11ef.dll
01/15/2005 06:15 PM 223,636 i6240gfqe62e0.dll
01/14/2005 11:43 AM 223,210 lv2m09f1e.dll
01/11/2005 06:11 AM 401,408 ?ti2evxx.exe
01/08/2005 08:19 PM 224,223 i6jqlg1516.dll
01/08/2005 08:04 PM 223,175 m8640ijqe8oe0.dll
01/08/2005 06:10 PM 224,535 m828lifu1828.dll
01/07/2005 12:14 AM 225,987 l64q0gh5e64.dll
01/01/2005 03:52 AM 225,441 dxnaddr.dll
12/30/2004 04:47 AM 224,311 enpml1711.dll
12/28/2004 10:39 AM 225,396 ennol1531.dll
12/28/2004 10:37 AM 224,916 i8loli3318.dll
12/28/2004 05:26 AM 224,311 jt6u07j9e.dll
12/21/2004 05:23 AM 224,311 irj2l51o1.dll
12/21/2004 12:57 AM 224,311 n6n6lg5s16.dll
12/21/2004 12:55 AM 224,311 k4620ejoehoc0.dll
12/20/2004 05:58 PM 222,703 mvjul9191.dll
12/20/2004 03:08 AM 224,700 ktrul7991.dll
12/19/2004 04:52 PM 222,909 h4l20e3oeh.dll
12/19/2004 04:32 PM 224,033 k8noli5318.dll
12/19/2004 08:07 AM 225,992 j8l40i3qe8.dll
12/19/2004 07:39 AM 225,554 lUprxy.dll
12/19/2004 02:00 AM 224,836 mv2ol9f31.dll
12/18/2004 06:10 PM 223,178 d8j0li1m18.dll
12/18/2004 05:59 PM 223,037 ruvpsp.dll
12/18/2004 05:41 PM 223,037 cpm.dll
12/18/2004 05:41 PM 224,961 n42ulef91h2.dll
12/18/2004 05:32 PM 225,165 pI8q0cl5efq.dll
12/18/2004 05:22 PM 223,132 igjp81k.dll
12/18/2004 02:54 PM 223,132 dwcompos.dll
12/18/2004 07:22 AM 223,132 nhwrsde.dll
12/18/2004 07:22 AM 223,336 e4020edoeh0c0.dll
12/18/2004 05:55 AM 224,520 gdtext.dll
12/17/2004 09:45 PM 225,571 enn0l15m1.dll
12/17/2004 06:41 PM 224,520 jtpo0773e.dll
12/17/2004 06:11 PM 224,520 n26q0cj5efo.dll
12/16/2004 11:04 PM 224,520 m864lijq18oe.dll
12/16/2004 04:06 PM 224,520 k6260gfse6260.dll
12/16/2004 03:59 PM 224,520 p4p6le7s1h.dll
12/16/2004 03:44 PM 224,520 kt26l7fs1.dll
12/16/2004 03:42 PM 224,520 aza6l3hs1.dll
12/15/2004 11:37 PM 224,520 e2jm0c11ef.dll
12/15/2004 11:08 PM 224,520 p28q0cl5efq.dll
12/15/2004 03:37 PM 224,520 dn4401hqe.dll
12/13/2004 03:27 PM 224,520 fn2021fmg.dll
12/13/2004 03:11 PM 224,210 gp46l3hs1.dll
12/13/2004 02:01 PM 225,570 l06olaj31do.dll
12/12/2004 10:33 PM 223,827 irjsl5171.dll
12/12/2004 10:33 PM 224,736 h40qled51h0.dll
12/12/2004 03:00 PM 223,736 h40q0ed5eh0.dll
58 File(s) 13,189,241 bytes
1 Dir(s) 20,127,576,064 bytes free
------- Hidden Files in System32 Directory -------
Volume in drive C has no label.
Volume Serial Number is 8403-2473
Directory of C:\WINDOWS\System32
01/20/2005 05:04 PM <DIR> dllcache
01/16/2005 08:15 PM <DIR> GroupPolicy
01/16/2005 07:27 PM 49,152 ykhg.exe
01/11/2005 06:11 AM 401,408 ?ti2evxx.exe
2 File(s) 450,560 bytes
2 Dir(s) 20,127,571,968 bytes free
---------- Files Named "Guard" -------------
Volume in drive C has no label.
Volume Serial Number is 8403-2473
Directory of C:\WINDOWS\System32
01/20/2005 04:55 PM 225,689 guard.tmp
1 File(s) 225,689 bytes
0 Dir(s) 20,127,571,968 bytes free
--------- Temp Files in System32 Directory --------
Volume in drive C has no label.
Volume Serial Number is 8403-2473
Directory of C:\WINDOWS\System32
01/20/2005 04:55 PM 225,689 guard.tmp
1 File(s) 225,689 bytes
0 Dir(s) 20,127,571,968 bytes free
---------------- User Agent ------------
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{C51E540C-C0FE-484C-AA63-00E552C043B0}"=""
------------ Keys Under Notify ------------
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Applets]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\enlsl1371.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00
---------------- Xfind Results -----------------
C:\WINDOWS\System32\DNNU01~1.DLL +++ File read error
-------------- Locate.com Results ---------------
C:\WINDOWS\SYSTEM32\
azam0c~1.dll Sun Jan 16 2005 12:16:58p ..S.R 223,812 218.57 K
dnnu01~1.dll Thu Jan 20 2005 4:47:16p ..S.R 225,689 220.40 K
dxnaddr.dll Sat Jan 1 2005 3:52:02a ..S.R 225,441 220.16 K
enlsl1~1.dll Thu Jan 20 2005 3:34:32p ..S.R 225,689 220.40 K
ennol1~1.dll Tue Dec 28 2004 10:39:34a ..S.R 225,396 220.11 K
enpml1~1.dll Thu Dec 30 2004 4:48:00a ..S.R 224,311 219.05 K
h0n0la~1.dll Mon Jan 17 2005 7:25:44p ..S.R 222,733 217.51 K
i6240g~1.dll Sat Jan 15 2005 6:15:10p ..S.R 223,636 218.39 K
i6jqlg~1.dll Sat Jan 8 2005 8:19:18p ..S.R 224,223 218.96 K
i8loli~1.dll Tue Dec 28 2004 10:37:54a ..S.R 224,916 219.64 K
ir48l5~1.dll Wed Jan 19 2005 12:21:56a ..S.R 225,945 220.65 K
irj2l5~1.dll Tue Dec 21 2004 5:23:06a ..S.R 224,311 219.05 K
jt6u07~1.dll Tue Dec 28 2004 5:26:44a ..S.R 224,311 219.05 K
k4620e~1.dll Tue Dec 21 2004 12:55:24a ..S.R 224,311 219.05 K
l06o0a~1.dll Thu Jan 20 2005 3:02:40p ..S.R 225,172 219.89 K
l64q0g~1.dll Fri Jan 7 2005 12:14:36a ..S.R 225,987 220.69 K
lv2m09~1.dll Fri Jan 14 2005 11:43:22a ..S.R 223,210 217.98 K
m4820e~1.dll Mon Jan 17 2005 7:05:28p ..S.R 226,229 220.93 K
m828li~1.dll Sat Jan 8 2005 6:10:42p ..S.R 224,535 219.27 K
m8640i~1.dll Sat Jan 8 2005 8:04:48p ..S.R 223,175 217.94 K
n6n6lg~1.dll Tue Dec 21 2004 12:57:42a ..S.R 224,311 219.05 K
p8r4li~1.dll Thu Jan 20 2005 4:41:26p ..S.R 223,209 217.98 K
pcpoops2.dll Wed Jan 19 2005 12:59:12a ..S.R 222,554 217.34 K
ykhg.exe Sun Jan 16 2005 7:27:04p A..H. 49,152 48.00 K
ti2evx~1.exe Tue Jan 11 2005 6:11:36a ..SHR 401,408 392.00 K
25 items found: 25 files, 0 directories.
Total of file sizes: 5,613,666 bytes 5.35 M