I did option 2, here is the result:
L2mfix 032106
Creating Account.
The command completed successfully.
Adding Administrative privleges.
The command completed successfully.
Checking for L2MFix account(0=no 1=yes):
1
Granting SeDebugPrivilege to L2MFIX ... successful
Running From:
C:\WINDOWS\system32
Killing Processes!
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003
Craig.Peacock@beyondlogic.org
Killing PID 416 'smss.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003
Craig.Peacock@beyondlogic.org
Killing PID 652 'winlogon.exe'
Killing PID 652 'winlogon.exe'
Killing PID 652 'winlogon.exe'
Killing PID 652 'winlogon.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003
Craig.Peacock@beyondlogic.org
Killing PID 1504 'explorer.exe'
Killing PID 1504 'explorer.exe'
Killing PID 1504 'explorer.exe'
Killing PID 1504 'explorer.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003
Craig.Peacock@beyondlogic.org
Killing PID 3240 'rundll32.exe'
Restoring Sedebugprivilege:
Granting SeDebugPrivilege to Administrators ... successful
Scanning First Pass. Please Wait!
First Pass Completed
Second Pass Scanning
Second pass Completed!
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
Deleting: C:\WINDOWS\system32\g4lm0e31eh.dll
Successfully Deleted: C:\WINDOWS\system32\g4lm0e31eh.dll
Deleting: C:\WINDOWS\system32\gp22l3fo1.dll
Successfully Deleted: C:\WINDOWS\system32\gp22l3fo1.dll
Deleting: C:\WINDOWS\system32\mv22l9fo1.dll
Successfully Deleted: C:\WINDOWS\system32\mv22l9fo1.dll
Deleting: C:\WINDOWS\system32\n48o0el3ehq.dll
Successfully Deleted: C:\WINDOWS\system32\n48o0el3ehq.dll
Deleting: C:\WINDOWS\system32\p6r40g9qe6.dll
Successfully Deleted: C:\WINDOWS\system32\p6r40g9qe6.dll
Deleting: C:\WINDOWS\system32\redist.dll
Successfully Deleted: C:\WINDOWS\system32\redist.dll
Deleting: C:\WINDOWS\system32\rvpcfgex.dll
Successfully Deleted: C:\WINDOWS\system32\rvpcfgex.dll
Deleting: C:\WINDOWS\system32\guard.tmp
Successfully Deleted: C:\WINDOWS\system32\guard.tmp
msg11?.dll
0 file(s) copied.
Restoring Windows Update Certificates.:
The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SideBySide]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\rvpcfgex.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
The following are the files found:
****************************************************************************
C:\WINDOWS\system32\g4lm0e31eh.dll
C:\WINDOWS\system32\gp22l3fo1.dll
C:\WINDOWS\system32\mv22l9fo1.dll
C:\WINDOWS\system32\n48o0el3ehq.dll
C:\WINDOWS\system32\p6r40g9qe6.dll
C:\WINDOWS\system32\redist.dll
C:\WINDOWS\system32\rvpcfgex.dll
C:\WINDOWS\system32\guard.tmp
Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{F09C99AC-7F48-4822-8776-DA3D8785BFBE}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F09C99AC-7F48-4822-8776-DA3D8785BFBE}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F09C99AC-7F48-4822-8776-DA3D8785BFBE}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F09C99AC-7F48-4822-8776-DA3D8785BFBE}\InprocServer32]
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{B88BF0AC-8FB2-4536-B501-4D5A808F6403}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{B88BF0AC-8FB2-4536-B501-4D5A808F6403}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{B88BF0AC-8FB2-4536-B501-4D5A808F6403}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{B88BF0AC-8FB2-4536-B501-4D5A808F6403}\InprocServer32]
@="C:\\WINDOWS\\system32\\rvpcfgex.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{F963751A-675B-4FF0-9803-9C8660A69DF0}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F963751A-675B-4FF0-9803-9C8660A69DF0}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F963751A-675B-4FF0-9803-9C8660A69DF0}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F963751A-675B-4FF0-9803-9C8660A69DF0}\InprocServer32]
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{D75137F2-97A1-4D83-9398-668372F3A58C}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{D75137F2-97A1-4D83-9398-668372F3A58C}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{D75137F2-97A1-4D83-9398-668372F3A58C}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{D75137F2-97A1-4D83-9398-668372F3A58C}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{F09C99AC-7F48-4822-8776-DA3D8785BFBE}"=-
"{B88BF0AC-8FB2-4536-B501-4D5A808F6403}"=-
"{F963751A-675B-4FF0-9803-9C8660A69DF0}"=-
"{D75137F2-97A1-4D83-9398-668372F3A58C}"=-
[-HKEY_CLASSES_ROOT\CLSID\{F09C99AC-7F48-4822-8776-DA3D8785BFBE}]
[-HKEY_CLASSES_ROOT\CLSID\{B88BF0AC-8FB2-4536-B501-4D5A808F6403}]
[-HKEY_CLASSES_ROOT\CLSID\{F963751A-675B-4FF0-9803-9C8660A69DF0}]
[-HKEY_CLASSES_ROOT\CLSID\{D75137F2-97A1-4D83-9398-668372F3A58C}]
REGEDIT4
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
****************************************************************************
Desktop.ini Contents:
****************************************************************************
****************************************************************************
Checking for L2MFix account(0=no 1=yes):
0
Zipping up files for submission:
adding: dlls/g4lm0e31eh.dll (104 bytes security) (deflated 5%)
adding: dlls/gp22l3fo1.dll (104 bytes security) (deflated 5%)
adding: dlls/guard.tmp (104 bytes security) (deflated 4%)
adding: dlls/mv22l9fo1.dll (104 bytes security) (deflated 5%)
adding: dlls/n48o0el3ehq.dll (104 bytes security) (deflated 5%)
adding: dlls/p6r40g9qe6.dll (104 bytes security) (deflated 5%)
adding: dlls/redist.dll (104 bytes security) (deflated 54%)
adding: dlls/rvpcfgex.dll (104 bytes security) (deflated 4%)
adding: backregs/B88BF0AC-8FB2-4536-B501-4D5A808F6403.reg (104 bytes security) (deflated 70%)
adding: backregs/D75137F2-97A1-4D83-9398-668372F3A58C.reg (104 bytes security) (deflated 70%)
adding: backregs/F09C99AC-7F48-4822-8776-DA3D8785BFBE.reg (104 bytes security) (deflated 71%)
adding: backregs/F963751A-675B-4FF0-9803-9C8660A69DF0.reg (104 bytes security) (deflated 71%)
adding: backregs/notibac.reg (104 bytes security) (deflated 63%)
adding: backregs/shell.reg (104 bytes security) (deflated 73%)