Pmultimedia
Technical User
- Oct 13, 2007
- 4
hello,
I ref'ed to thread760-1288784, and follow the steps for the logs of the two so here they are:
Username "Owner" - 10/13/2007 22:11:56 [Fixwareout edited 9/01/2007]
~~~~~ Prerun check
HKLM\SOFTWARE\~\Winlogon\ "System"="cszky.exe"
Service: "Windows Management Service" = C:\WINDOWS\System32\dmfbo.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
"nameserver"="85.255.116.46 85.255.112.187" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{4F6B2923-AB5D-4DE1-B8B6-71E96F7229D0}
"nameserver"="85.255.116.46,85.255.112.187" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{682879CE-B34D-4DA4-8AB9-222F584F43D8}
"nameserver"="85.255.116.46,85.255.112.187" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{97DAB2D9-58B5-40C0-ADB0-BB30E887417F}
"nameserver"="85.255.116.46,85.255.112.187" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{D894E858-699E-4357-B7BE-FAF9FDA11B4C}
"nameserver"="85.255.116.46,85.255.112.187" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{4F6B2923-AB5D-4DE1-B8B6-71E96F7229D0}
"DhcpNameServer"="85.255.116.46,85.255.112.187" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{97DAB2D9-58B5-40C0-ADB0-BB30E887417F}
"DhcpNameServer"="85.255.116.46,85.255.112.187" <Value cleared.
Successfully flushed the DNS Resolver Cache.
System was rebooted successfully.
~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
....
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "0mdm" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "1mdm" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}B60E46AC6110-9FE8-8654-73F4-15195881{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}9E4273BC6335-C798-DC74-04DF-0F84FC5E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "ravmd" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}D73847D4EAEE-D778-4E04-74D8-30534A9E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "obfmd" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion "ykzsc" Value deleted
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion "dmvar.exe" Value deleted
HKCR\CLSID\{4A637D55-7361-4294-A789-CECC1215F572}\_h\4 Deleted.
C:\WINDOWS\System32\qoptj.exe Deleted
....
~~~~~ Misc files.
C:\WINDOWS\System32\kernel32.exe Deleted
....
~~~~~ Checking for older varients.
....
~~~~~ Other
I ref'ed to thread760-1288784, and follow the steps for the logs of the two so here they are:
Username "Owner" - 10/13/2007 22:11:56 [Fixwareout edited 9/01/2007]
~~~~~ Prerun check
HKLM\SOFTWARE\~\Winlogon\ "System"="cszky.exe"
Service: "Windows Management Service" = C:\WINDOWS\System32\dmfbo.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
"nameserver"="85.255.116.46 85.255.112.187" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{4F6B2923-AB5D-4DE1-B8B6-71E96F7229D0}
"nameserver"="85.255.116.46,85.255.112.187" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{682879CE-B34D-4DA4-8AB9-222F584F43D8}
"nameserver"="85.255.116.46,85.255.112.187" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{97DAB2D9-58B5-40C0-ADB0-BB30E887417F}
"nameserver"="85.255.116.46,85.255.112.187" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{D894E858-699E-4357-B7BE-FAF9FDA11B4C}
"nameserver"="85.255.116.46,85.255.112.187" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{4F6B2923-AB5D-4DE1-B8B6-71E96F7229D0}
"DhcpNameServer"="85.255.116.46,85.255.112.187" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{97DAB2D9-58B5-40C0-ADB0-BB30E887417F}
"DhcpNameServer"="85.255.116.46,85.255.112.187" <Value cleared.
Successfully flushed the DNS Resolver Cache.
System was rebooted successfully.
~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
....
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "0mdm" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "1mdm" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}B60E46AC6110-9FE8-8654-73F4-15195881{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}9E4273BC6335-C798-DC74-04DF-0F84FC5E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "ravmd" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}D73847D4EAEE-D778-4E04-74D8-30534A9E{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "obfmd" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion "ykzsc" Value deleted
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion "dmvar.exe" Value deleted
HKCR\CLSID\{4A637D55-7361-4294-A789-CECC1215F572}\_h\4 Deleted.
C:\WINDOWS\System32\qoptj.exe Deleted
....
~~~~~ Misc files.
C:\WINDOWS\System32\kernel32.exe Deleted
....
~~~~~ Checking for older varients.
....
~~~~~ Other