wanstor
asked on
unable to remove Troj_agent.fz
Hi,
I have a pc which is infected with the above virus, problem is its part of mfcdoc.dll which is part of the winlogon service, how can i get rid of it (the virus that is) :)
I have a pc which is infected with the above virus, problem is its part of mfcdoc.dll which is part of the winlogon service, how can i get rid of it (the virus that is) :)
ASKER
sorry XP professional, Is it possible to fix remotely via Network streaming?
ASKER
have tried latest trend office scan eng and ptn, and house call with no luck
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Yes, thats right - I'm looking at it now.
RF
RF
I don't see much of anything wrong in your log file - a 02 entry (we'll deal with that later) -
the one entry I'm wondering about is:
O20 - Winlogon Notify: mfcdoc - C:\WINDOWS\repair\mfcdoc.d ll
Let's try this -
Make sure "Show all Files and Folders", including hidden and system, is enabled.
Download L2mfix from one of these two locations:
http://www.atribune.org/downloads/l2mfix.exe
http://www.downloads.subratam.org/l2mfix.exe
Save the file to your desktop and double click "l2mfix.exe".
Click the "Install" button to extract the files and follow the prompts -
then open the newly added l2mfix folder on your desktop.
Double click "l2mfix.bat" and select option #1 for "Run Find Log" by typing 1 and then pressing enter.
This will scan your computer and it may appear nothing is happening -
then, after a minute or 2 (the time varies), notepad will open with a log.
Copy the contents of that log and paste it into this thread.
->-> IMPORTANT: <-<-
DO NOT run option #2 OR any other files in the l2mfix folder -
until you are asked to do so!
RF
the one entry I'm wondering about is:
O20 - Winlogon Notify: mfcdoc - C:\WINDOWS\repair\mfcdoc.d
Let's try this -
Make sure "Show all Files and Folders", including hidden and system, is enabled.
Download L2mfix from one of these two locations:
http://www.atribune.org/downloads/l2mfix.exe
http://www.downloads.subratam.org/l2mfix.exe
Save the file to your desktop and double click "l2mfix.exe".
Click the "Install" button to extract the files and follow the prompts -
then open the newly added l2mfix folder on your desktop.
Double click "l2mfix.bat" and select option #1 for "Run Find Log" by typing 1 and then pressing enter.
This will scan your computer and it may appear nothing is happening -
then, after a minute or 2 (the time varies), notepad will open with a log.
Copy the contents of that log and paste it into this thread.
->-> IMPORTANT: <-<-
DO NOT run option #2 OR any other files in the l2mfix folder -
until you are asked to do so!
RF
ASKER
L2MFIX find log 1.03
These are the registry keys present
************************** ********** ********** ********** ********** ********** ******
Winlogon/notify:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Softwa re\Microso ft\Windows NT\CurrentVersion\Winlogon \Notify]
[HKEY_LOCAL_MACHINE\Softwa re\Microso ft\Windows NT\CurrentVersion\Winlogon \Notify\cr ypt32chain ]
"Asynchronous"=dword:00000 000
"Impersonate"=dword:000000 00
"DllName"=hex(2):63,00,72, 00,79,00,7 0,00,74,00 ,33,00,32, 00,2e,00,6 4,00,6c,00 ,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEv ent"
[HKEY_LOCAL_MACHINE\Softwa re\Microso ft\Windows NT\CurrentVersion\Winlogon \Notify\cr yptnet]
"Asynchronous"=dword:00000 000
"Impersonate"=dword:000000 00
"DllName"=hex(2):63,00,72, 00,79,00,7 0,00,74,00 ,6e,00,65, 00,74,00,2 e,00,64,00 ,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogof fEvent"
[HKEY_LOCAL_MACHINE\Softwa re\Microso ft\Windows NT\CurrentVersion\Winlogon \Notify\cs cdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEven t"
"Logoff"="WinlogonLogoffEv ent"
"ScreenSaver"="WinlogonScr eenSaverEv ent"
"Startup"="WinlogonStartup Event"
"Shutdown"="WinlogonShutdo wnEvent"
"StartShell"="WinlogonStar tShellEven t"
"Impersonate"=dword:000000 00
"Asynchronous"=dword:00000 001
[HKEY_LOCAL_MACHINE\Softwa re\Microso ft\Windows NT\CurrentVersion\Winlogon \Notify\mf cdoc]
"Asynchronous"=dword:00000 001
"DllName"="C:\\WINDOWS\\re pair\\mfcd oc.dll"
"Impersonate"=dword:000000 00
"Startup"="SysLogon"
"Logoff"="SysLogoff"
[HKEY_LOCAL_MACHINE\Softwa re\Microso ft\Windows NT\CurrentVersion\Winlogon \Notify\Sc CertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertPro p"
"Logoff"="SCardStopCertPro p"
"Lock"="SCardSuspendCertPr op"
"Unlock"="SCardResumeCertP rop"
"Enabled"=dword:00000001
"Impersonate"=dword:000000 01
"Asynchronous"=dword:00000 001
[HKEY_LOCAL_MACHINE\Softwa re\Microso ft\Windows NT\CurrentVersion\Winlogon \Notify\Sc hedule]
"Asynchronous"=dword:00000 000
"DllName"=hex(2):77,00,6c, 00,6e,00,6 f,00,74,00 ,69,00,66, 00,79,00,2 e,00,64,00 ,\
6c,00,6c,00,00,00
"Impersonate"=dword:000000 00
"StartShell"="SchedStartSh ell"
"Logoff"="SchedEventLogOff "
[HKEY_LOCAL_MACHINE\Softwa re\Microso ft\Windows NT\CurrentVersion\Winlogon \Notify\sc lgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:000000 00
"Asynchronous"=dword:00000 001
"DllName"=hex(2):73,00,63, 00,6c,00,6 7,00,6e,00 ,74,00,66, 00,79,00,2 e,00,64,00 ,\
6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\Softwa re\Microso ft\Windows NT\CurrentVersion\Winlogon \Notify\Se nsLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensSt artScreenS averEvent"
"StopScreenSaver"="SensSto pScreenSav erEvent"
"Startup"="SensStartupEven t"
"Shutdown"="SensShutdownEv ent"
"StartShell"="SensStartShe llEvent"
"PostShell"="SensPostShell Event"
"Disconnect"="SensDisconne ctEvent"
"Reconnect"="SensReconnect Event"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:000000 01
"Asynchronous"=dword:00000 001
[HKEY_LOCAL_MACHINE\Softwa re\Microso ft\Windows NT\CurrentVersion\Winlogon \Notify\te rmsrv]
"Asynchronous"=dword:00000 000
"DllName"=hex(2):77,00,6c, 00,6e,00,6 f,00,74,00 ,69,00,66, 00,79,00,2 e,00,64,00 ,\
6c,00,6c,00,00,00
"Impersonate"=dword:000000 00
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostSh ell"
"Shutdown"="TSEventShutdow n"
"StartShell"="TSEventStart Shell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconn ect"
"Disconnect"="TSEventDisco nnect"
[HKEY_LOCAL_MACHINE\Softwa re\Microso ft\Windows NT\CurrentVersion\Winlogon \Notify\wl balloon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExp iredNotifi cationEven t"
"Logoff"="UnregisterTicket ExpiredNot ificationE vent"
"Impersonate"=dword:000000 01
"Asynchronous"=dword:00000 001
************************** ********** ********** ********** ********** ********** ******
useragent:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWA RE\Microso ft\Windows \CurrentVe rsion\Inte rnet Settings\User Agent\Post Platform]
"SV1"=""
************************** ********** ********** ********** ********** ********** ******
Shell Extension key:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWA RE\Microso ft\Windows \CurrentVe rsion\Shel l Extensions\Approved]
"{00022613-0000-0000-C000- 0000000000 46}"="Mult imedia File Property Sheet"
"{176d6597-26d3-11d1-b350- 080036a75b 03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2- 00AA006E08 6C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB- 666CCB9BCD 32}"="OLE Docfile Property Page"
"{40dd6e20-7c17-11ce-a804- 00aa003ca9 f6}"="Shel l extensions for sharing"
"{41E300E0-78B6-11ce-849B- 4445535400 00}"="Plus Pack CPL Extension"
"{42071712-76d4-11d1-8b24- 00a0c9068f f3}"="Disp lay Adapter CPL Extension"
"{42071713-76d4-11d1-8b24- 00a0c9068f f3}"="Disp lay Monitor CPL Extension"
"{42071714-76d4-11d1-8b24- 00a0c9068f f3}"="Disp lay Panning CPL Extension"
"{4E40F770-369C-11d0-8922- 00A024AB2D BB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB- 0CBC76FB1A F8}"="Comp atibility Page"
"{56117100-C0CD-101B-81E2- 00AA004AE8 37}"="Shel l Scrap DataHandler"
"{59099400-57FF-11CE-BD94- 0020AF85B5 90}"="Disk Copy Extension"
"{59be4990-f85c-11ce-aff7- 00aa003ca9 f6}"="Shel l extensions for Microsoft Windows Network objects"
"{5DB2625A-54DF-11D0-B6C4- 0800091AA6 05}"="ICM Monitor Management"
"{675F097E-4C4D-11D0-B6C1- 0800091AA6 05}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D- 00AA00A14F 56}"="Shel l extensions for file compression"
"{77597368-7b15-11d0-a0c2- 080036af3f 03}"="Web Printer Shell Extension"
"{7988B573-EC89-11cf-9C00- 00AA00A14F 56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E- 00C04FB6C6 FA}"="Encr yption Context Menu"
"{85BBD920-42A0-1069-A2E4- 08002B3030 9D}"="Brie fcase"
"{88895560-9AA2-1069-930E- 00AA0030EB C8}"="Hype rTerminal Icon Ext"
"{BD84B380-8CA2-1069-AB1D- 08000948F5 34}"="Font s"
"{DBCE2480-C732-101B-BE72- BA78E9AD5B 27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF- 00AA00BBB7 23}"="Prin ters Security Page"
"{f81e9010-6ea4-11ce-a7ff- 00aa003ca9 f6}"="Shel l extensions for sharing"
"{f92e8c40-3d33-11d2-b1aa- 080036a75b 03}"="Disp lay TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9- 00C04FC29D 45}"="Cryp to PKO Extension"
"{7444C719-39BF-11D1-8CD9- 00C04FC29D 45}"="Cryp to Sign Extension"
"{7007ACC7-3202-11D1-AAD2- 00805FC127 0E}"="Netw ork Connections"
"{992CFFA0-F557-101A-88EC- 00DD010CCC 48}"="Netw ork Connections"
"{E211B736-43FD-11D1-9EFB- 0000F8757F CD}"="Scan ners & Cameras"
"{FB0C9C8A-6C50-11D1-9F1D- 0000F8757F CD}"="Scan ners & Cameras"
"{905667aa-acd6-11d2-8080- 00805f6596 d2}"="Scan ners & Cameras"
"{3F953603-1008-4f6e-A73A- 04AAC7A992 F1}"="Scan ners & Cameras"
"{83bbcbf3-b28a-4919-a5aa- 73027445d6 72}"="Scan ners & Cameras"
"{F0152790-D56E-4445-850E- 4F3117DB74 0C}"="Remo te Sessions CPL Extension"
"{5F327514-6C5E-4d60-8F16- D07FA08A78 ED}"="Auto Update Property Sheet Extension"
"{60254CA5-953B-11CF-8C96- 00AA00B870 8C}"="Shel l extensions for Windows Script Host"
"{2206CDB2-19C1-11D1-89E0- 00C04FD7A8 29}"="Micr osoft Data Link"
"{DD2110F0-9EEF-11cf-8D8E- 00AA0060F5 BF}"="Task s Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E- 00AA0060F5 BF}"="Task s Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87- 00AA0060F5 BF}"="Sche duled Tasks"
"{0DF44EAA-FF21-4412-828E- 260A8728E7 F1}"="Task bar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf- 00c04f60b9 f0}"="Sear ch"
"{2559a1f1-21d7-11d4-bdaf- 00c04f60b9 f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf- 00c04f60b9 f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf- 00c04f60b9 f0}"="Run. .."
"{2559a1f4-21d7-11d4-bdaf- 00c04f60b9 f0}"="Inte rnet"
"{2559a1f5-21d7-11d4-bdaf- 00c04f60b9 f0}"="E-ma il"
"{D20EA4E1-3957-11d2-A40B- 0C50205241 52}"="Font s"
"{D20EA4E1-3957-11d2-A40B- 0C50205241 53}"="Admi nistrative Tools"
"{875CB1A1-0F29-45de-A1AE- CFB4950D0B 78}"="Audi o Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41- 0E5BBEA288 17}"="Vide o Media Properties Handler"
"{E4B29F9D-D390-480b-92FD- 7DDB47101D 71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489- 5FE6850DC7 3E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644- 08598F5A74 D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb- c394da41d5 90}"="Vide o Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B- 00AA004AE8 37}"="Micr osoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373- 00A0C90349 38}"="Down load Status"
"{91EA3F8B-C99B-11d0-9815- 00C04FD919 72}"="Augm ented Shell Folder"
"{6413BA2C-B461-11d1-A18A- 080036B11A 03}"="Augm ented Shell Folder 2"
"{F61FFEC1-754F-11d0-80CA- 00AA005B43 83}"="Band Proxy"
"{7BA4C742-9E81-11CF-99D3- 00AA004AE8 37}"="Micr osoft BrowserBand"
"{30D02401-6A81-11d0-8274- 00C04FD5AE 38}"="Sear ch Band"
"{32683183-48a0-441b-a342- 7c2a440a94 78}"="Medi a Band"
"{169A0691-8DF9-11d1-A1C4- 00C04FD75D 13}"="In-p ane search"
"{07798131-AF23-11d1-9111- 00A0C98BA6 7D}"="Web Search"
"{AF4F6510-F982-11d0-8595- 00AA004CD6 D8}"="Regi stry Tree Options Utility"
"{01E04581-4EEE-11d0-BFE9- 00AA005B43 83}"="&Add ress"
"{A08C11D2-A228-11d0-825B- 00AA005B43 83}"="Addr ess EditBox"
"{00BB2763-6A77-11D0-A535- 00C04FD7D0 62}"="Micr osoft AutoComplete"
"{7376D660-C583-11d0-A3A5- 00C04FD706 EC}"="Trid entImageEx tractor"
"{6756A641-DE71-11d0-831B- 00AA005B43 83}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9- 9FE3C77A29 7A}"="Cust om MRU AutoCompleted List"
"{7e653215-fa25-46bd-a339- 34a2790f3c b7}"="Acce ssible"
"{acf35015-526e-4230-9596- becbe19f0a c9}"="Trac k Popup Bar"
"{E0E11A09-5CB8-4B6C-8332- E00720A168 F2}"="Addr ess Bar Parser"
"{00BB2764-6A77-11D0-A535- 00C04FD7D0 62}"="Micr osoft History AutoComplete List"
"{03C036F1-A186-11D0-824A- 00AA005B43 83}"="Micr osoft Shell Folder AutoComplete List"
"{00BB2765-6A77-11D0-A535- 00C04FD7D0 62}"="Micr osoft Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792- 00A0C90312 E1}"="Shel l Band Site Menu"
"{3CCF8A41-5C85-11d0-9796- 00AA00B90A DF}"="Shel l DeskBarApp"
"{ECD4FC4C-521C-11D0-B792- 00A0C90312 E1}"="Shel l DeskBar"
"{ECD4FC4D-521C-11D0-B792- 00A0C90312 E1}"="Shel l Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD- 0000F87A47 0C}"="User Assist"
"{EF8AD2D1-AE36-11D1-B2D2- 006097DF8C 11}"="Glob al Folder Settings"
"{EFA24E61-B078-11d0-89E4- 00C04FC9E2 6E}"="Favo rites Band"
"{0A89A860-D7B1-11CE-8350- 4445535400 00}"="Shel l Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB- 00AA004AE8 37}"="Shel l DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C- 00C04FC99D 61}"="Micr osoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488- 00AA003E56 F8}"="Inte rnetShortc ut"
"{3C374A40-BAE4-11CF-BF7D- 00AA006946 EE}"="Micr osoft Url History Service"
"{FF393560-C2A7-11CF-BFF4- 4445535400 00}"="Hist ory"
"{7BD29E00-76C1-11CF-9DD0- 00A0C90349 33}"="Temp orary Internet Files"
"{7BD29E01-76C1-11CF-9DD0- 00A0C90349 33}"="Temp orary Internet Files"
"{CFBFAE00-17A6-11D0-99CB- 00C04FD644 97}"="Micr osoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5- 00C04FD706 EC}"="IE4 Suite Splash Screen"
"{67EA19A0-CCEF-11d0-8024- 00C04FD75D 13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979- 00C04FD705 A2}"="ISFB and OC"
"{9461b922-3c5a-11d2-bf8b- 00c04fb936 61}"="Sear ch Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB- 00AA004AE8 37}"="The Internet"
"{871C5380-42A0-1069-A2EA- 08002B3030 9D}"="Inte rnet Name Space"
"{EFA24E64-B078-11d0-89E4- 00C04FC9E2 6E}"="Expl orer Band"
"{9E56BE60-C50F-11CF-9A2C- 00A0C90A90 CE}"="Send mail service"
"{9E56BE61-C50F-11CF-9A2C- 00A0C90A90 CE}"="Send mail service"
"{88C6C381-2E85-11D0-94DE- 4445535400 00}"="Acti veX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87- 00AA005127 ED}"="WebC heck"
"{ABBE31D0-6DAE-11D0-BECA- 00C04FD940 BE}"="Subs cription Mgr"
"{F5175861-2688-11d0-9C5E- 00AA00A459 57}"="Subs cription Folder"
"{08165EA0-E946-11CF-9C87- 00AA005127 ED}"="WebC heckWebCra wler"
"{E3A8BDE6-ABCE-11d0-BC4B- 00C04FD929 DB}"="WebC heckChanne lAgent"
"{E8BB6DC0-6B4E-11d0-92DB- 00A0C90C2B D7}"="Tray Agent"
"{7D559C10-9FE9-11d0-93F7- 00AA0059CE 02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA- 00C04FD940 BE}"="Conn ectionAgen t"
"{D8BD2030-6FC9-11D0-864F- 00AA006809 D9}"="Post Agent"
"{7FC0B86E-5FA7-11d1-BC7C- 00C04FD929 DB}"="WebC heck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE- 0060080593 82}"="Shel l Application Manager"
"{0B124F8F-91F0-11D1-B8B5- 0060080593 82}"="Inst alled Apps Enumerator"
"{CFCCC7A0-A282-11D1-9082- 0060080593 82}"="Darw in App Publisher"
"{e84fda7c-1d6a-45f6-b725- cb260c2360 66}"="Shel l Image Verbs"
"{66e4e4fb-f385-4dd0-8d74- a2efd1bc61 78}"="Shel l Image Data Factory"
"{3F30C968-480A-4C6C-862D- EFC0897BB8 4B}"="GDI+ file thumbnail extractor"
"{9DBD2C50-62AD-11d0-B806- 00C04FD706 EC}"="Summ ary Info Thumbnail handler (DOCFILES)"
"{EAB841A0-9550-11cf-8C16- 00805F1408 F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a- a3266bc3d7 fe}"="Shel l Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619- 51D571967F 7D}"="Web Publishing Wizard"
"{add36aa8-751a-4579-a266- d66f5202cc bb}"="Prin t Ordering via the Web"
"{6b33163c-76a5-4b6c-bf21- 45de9cd503 a1}"="Shel l Publishing Wizard Object"
"{58f1f272-9240-4f51-b6d4- fd63d16185 91}"="Get a Passport Wizard"
"{7A9D77BD-5403-11d2-8785- 2E04205241 53}"="User Accounts"
"{BD472F60-27FA-11cf-B8B4- 4445535400 00}"="Comp ressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F- 00C04FD7D0 62}"="Comp ressed (zipped) Folder SendTo Target"
"{f39a0dc0-9cc8-11d0-a599- 00c04fd644 33}"="Chan nel File"
"{f3aa0dc0-9cc8-11d0-a599- 00c04fd644 34}"="Chan nel Shortcut"
"{f3ba0dc0-9cc8-11d0-a599- 00c04fd644 35}"="Chan nel Handler Object"
"{f3da0dc0-9cc8-11d0-a599- 00c04fd644 37}"="Chan nel Menu"
"{f3ea0dc0-9cc8-11d0-a599- 00c04fd644 38}"="Chan nel Properties"
"{63da6ec0-2e98-11cf-8d82- 4445535400 00}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35- 080036B11A 03}"="Micr osoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481- E35B73E47F 6D}"="Micr osoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA- 67914005F0 20}"="Micr osoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B- 86EE61B0D3 EB}"="Micr osoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881- F787FAB579 A3}"="Micr osoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177- 82BFC914FA 33}"="Micr osoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C- 00A024AB2D BB}"="Dire ctory Query UI"
"{9E51E0D0-6E0F-11d2-9601- 00C04FA31A 86}"="Shel l properties for a DS object"
"{163FDC20-2ABC-11d0-88F0- 00A024AB2D BB}"="Dire ctory Object Find"
"{F020E586-5264-11d1-A532- 0000F8757D 7E}"="Dire ctory Start/Search Find"
"{0D45D530-764B-11d0-A1CA- 00AA00C16E 65}"="Dire ctory Property UI"
"{62AE1F9A-126A-11D0-A14B- 0800361B11 03}"="Dire ctory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D- 0060080593 67}"="MyDo cs Copy Hook"
"{ECF03A32-103D-11d2-854D- 0060080593 67}"="MyDo cs Drop Target"
"{4a7ded0a-ad25-11d0-98a8- 0800361b11 03}"="MyDo cs Properties"
"{750fdf0e-2a26-11d1-a3ea- 080036587f 03}"="Offl ine Files Menu"
"{10CFC467-4392-11d2-8DB4- 00C04FA31A 66}"="Offl ine Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039- 00C04F8EEB 3E}"="Offl ine Files Folder"
"{143A62C8-C33B-11D1-84FE- 00C04FA34A 14}"="Micr osoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF- 0080C87CDB A6}"="DfsS hell"
"{60fd46de-f830-4894-a628- 6fa81bc019 0d}"="%DES C_PublishD ropTarget% "
"{7A80E4A8-8005-11D2-BCF8- 00C04F72C7 17}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65- 08002B2E12 62}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85- 00AA0044F9 41}"="For &People..."
"{8DD448E6-C188-4aed-AF92- 44956194EB 1F}"="Wind ows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9- D9F1B4073E 6C}"="Wind ows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E- 42362A59F0 FD}"="Wind ows Media Player Add to Playlist Context Menu Handler"
"{40E85620-3DCB-11D3-8A0D- 0060080C1E FA}"="ZipC entral"
"{BDEADF00-C265-11D0-BCED- 00A0C90AB5 0F}"="Web Folders"
"{00020D75-0000-0000-C000- 0000000000 46}"="Micr osoft Office Outlook Desktop Icon Handler"
"{0006F045-0000-0000-C000- 0000000000 46}"="Micr osoft Office Outlook Custom Icon Handler"
"{42042206-2D85-11D3-8CFF- 0050048385 97}"="Micr osoft Office HTML Icon Handler"
"{2559a1f7-21d7-11d4-bdaf- 00c04f60b9 f0}"="Set Program Access and Defaults"
"{596AB062-B4D2-4215-9F74- E9109B0A81 53}"="Prev ious Versions Property Page"
"{9DB7A13C-F208-4981-8353- 73CC61AE27 83}"="Prev ious Versions"
"{692F0339-CBAA-47e6-B5B5- 3B84DB604E 87}"="Exte nsions Manager Folder"
"{e57ce731-33e8-4c51-8354- bb4de9d215 d1}"="Univ ersal Plug and Play Devices"
"{640167b4-59b0-47a6-b335- a6b3c0695a ea}"="Port able Media Devices"
"{cc86590a-b60a-48e6-996b- 41d25ed39a 1e}"="Port able Media Devices Menu"
************************** ********** ********** ********** ********** ********** ******
HKEY ROOT CLASSIDS:
************************** ********** ********** ********** ********** ********** ******
Files Found are not all bad files:
C:\WINDOWS\SYSTEM32\
authz.dll Wed 2 Mar 2005 19:09:30 A.... 56,832 55.50 K
browseui.dll Thu 10 Mar 2005 9:02:34 A.... 1,016,832 993.00 K
cdfview.dll Thu 10 Mar 2005 9:02:34 A.... 151,040 147.50 K
iepeers.dll Thu 10 Mar 2005 9:02:34 A.... 250,880 245.00 K
inseng.dll Thu 10 Mar 2005 9:02:34 A.... 96,256 94.00 K
mshtml.dll Thu 10 Mar 2005 9:02:34 A.... 3,010,560 2.87 M
msi.dll Mon 21 Mar 2005 15:00:20 A.... 2,890,240 2.75 M
msihnd.dll Mon 21 Mar 2005 15:00:22 A.... 271,360 265.00 K
msimsg.dll Mon 21 Mar 2005 15:00:22 A.... 884,736 864.00 K
msisip.dll Mon 21 Mar 2005 15:00:22 A.... 15,360 15.00 K
msrating.dll Thu 10 Mar 2005 9:02:34 A.... 146,432 143.00 K
shdocvw.dll Thu 10 Mar 2005 9:02:34 A.... 1,483,264 1.41 M
shell32.dll Tue 1 Mar 2005 0:11:18 A.... 8,450,048 8.06 M
shlwapi.dll Thu 10 Mar 2005 9:02:34 A.... 473,600 462.50 K
spmsg.dll Thu 24 Feb 2005 19:35:06 ..... 14,048 13.72 K
urlmon.dll Thu 10 Mar 2005 9:02:36 A.... 607,744 593.50 K
user32.dll Wed 2 Mar 2005 19:09:30 A.... 577,024 563.50 K
wininet.dll Thu 10 Mar 2005 9:02:36 A.... 656,896 641.50 K
winsrv.dll Wed 2 Mar 2005 19:09:30 A.... 291,328 284.50 K
19 items found: 19 files, 0 directories.
Total of file sizes: 21,344,480 bytes 20.36 M
Locate .tmp files:
No matches found.
************************** ********** ********** ********** ********** ********** ******
Directory Listing of system files:
Volume in drive C has no label.
Volume Serial Number is 7594-4EC0
Directory of C:\WINDOWS\System32
18/05/2005 12:14 4,096 psc.exe
19/04/2005 20:39 <DIR> dllcache
05/07/2004 22:57 <DIR> Microsoft
1 File(s) 4,096 bytes
2 Dir(s) 1,931,616,256 bytes free
These are the registry keys present
**************************
Winlogon/notify:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Softwa
[HKEY_LOCAL_MACHINE\Softwa
"Asynchronous"=dword:00000
"Impersonate"=dword:000000
"DllName"=hex(2):63,00,72,
6c,00,00,00
"Logoff"="ChainWlxLogoffEv
[HKEY_LOCAL_MACHINE\Softwa
"Asynchronous"=dword:00000
"Impersonate"=dword:000000
"DllName"=hex(2):63,00,72,
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogof
[HKEY_LOCAL_MACHINE\Softwa
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEven
"Logoff"="WinlogonLogoffEv
"ScreenSaver"="WinlogonScr
"Startup"="WinlogonStartup
"Shutdown"="WinlogonShutdo
"StartShell"="WinlogonStar
"Impersonate"=dword:000000
"Asynchronous"=dword:00000
[HKEY_LOCAL_MACHINE\Softwa
"Asynchronous"=dword:00000
"DllName"="C:\\WINDOWS\\re
"Impersonate"=dword:000000
"Startup"="SysLogon"
"Logoff"="SysLogoff"
[HKEY_LOCAL_MACHINE\Softwa
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertPro
"Logoff"="SCardStopCertPro
"Lock"="SCardSuspendCertPr
"Unlock"="SCardResumeCertP
"Enabled"=dword:00000001
"Impersonate"=dword:000000
"Asynchronous"=dword:00000
[HKEY_LOCAL_MACHINE\Softwa
"Asynchronous"=dword:00000
"DllName"=hex(2):77,00,6c,
6c,00,6c,00,00,00
"Impersonate"=dword:000000
"StartShell"="SchedStartSh
"Logoff"="SchedEventLogOff
[HKEY_LOCAL_MACHINE\Softwa
"Logoff"="WLEventLogoff"
"Impersonate"=dword:000000
"Asynchronous"=dword:00000
"DllName"=hex(2):73,00,63,
6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\Softwa
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensSt
"StopScreenSaver"="SensSto
"Startup"="SensStartupEven
"Shutdown"="SensShutdownEv
"StartShell"="SensStartShe
"PostShell"="SensPostShell
"Disconnect"="SensDisconne
"Reconnect"="SensReconnect
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:000000
"Asynchronous"=dword:00000
[HKEY_LOCAL_MACHINE\Softwa
"Asynchronous"=dword:00000
"DllName"=hex(2):77,00,6c,
6c,00,6c,00,00,00
"Impersonate"=dword:000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostSh
"Shutdown"="TSEventShutdow
"StartShell"="TSEventStart
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconn
"Disconnect"="TSEventDisco
[HKEY_LOCAL_MACHINE\Softwa
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExp
"Logoff"="UnregisterTicket
"Impersonate"=dword:000000
"Asynchronous"=dword:00000
**************************
useragent:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWA
"SV1"=""
**************************
Shell Extension key:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWA
"{00022613-0000-0000-C000-
"{176d6597-26d3-11d1-b350-
"{1F2E5C40-9550-11CE-99D2-
"{3EA48300-8CF6-101B-84FB-
"{40dd6e20-7c17-11ce-a804-
"{41E300E0-78B6-11ce-849B-
"{42071712-76d4-11d1-8b24-
"{42071713-76d4-11d1-8b24-
"{42071714-76d4-11d1-8b24-
"{4E40F770-369C-11d0-8922-
"{513D916F-2A8E-4F51-AEAB-
"{56117100-C0CD-101B-81E2-
"{59099400-57FF-11CE-BD94-
"{59be4990-f85c-11ce-aff7-
"{5DB2625A-54DF-11D0-B6C4-
"{675F097E-4C4D-11D0-B6C1-
"{764BF0E1-F219-11ce-972D-
"{77597368-7b15-11d0-a0c2-
"{7988B573-EC89-11cf-9C00-
"{853FE2B1-B769-11d0-9C4E-
"{85BBD920-42A0-1069-A2E4-
"{88895560-9AA2-1069-930E-
"{BD84B380-8CA2-1069-AB1D-
"{DBCE2480-C732-101B-BE72-
"{F37C5810-4D3F-11d0-B4BF-
"{f81e9010-6ea4-11ce-a7ff-
"{f92e8c40-3d33-11d2-b1aa-
"{7444C717-39BF-11D1-8CD9-
"{7444C719-39BF-11D1-8CD9-
"{7007ACC7-3202-11D1-AAD2-
"{992CFFA0-F557-101A-88EC-
"{E211B736-43FD-11D1-9EFB-
"{FB0C9C8A-6C50-11D1-9F1D-
"{905667aa-acd6-11d2-8080-
"{3F953603-1008-4f6e-A73A-
"{83bbcbf3-b28a-4919-a5aa-
"{F0152790-D56E-4445-850E-
"{5F327514-6C5E-4d60-8F16-
"{60254CA5-953B-11CF-8C96-
"{2206CDB2-19C1-11D1-89E0-
"{DD2110F0-9EEF-11cf-8D8E-
"{797F1E90-9EDD-11cf-8D8E-
"{D6277990-4C6A-11CF-8D87-
"{0DF44EAA-FF21-4412-828E-
"{2559a1f0-21d7-11d4-bdaf-
"{2559a1f1-21d7-11d4-bdaf-
"{2559a1f2-21d7-11d4-bdaf-
"{2559a1f3-21d7-11d4-bdaf-
"{2559a1f4-21d7-11d4-bdaf-
"{2559a1f5-21d7-11d4-bdaf-
"{D20EA4E1-3957-11d2-A40B-
"{D20EA4E1-3957-11d2-A40B-
"{875CB1A1-0F29-45de-A1AE-
"{40C3D757-D6E4-4b49-BB41-
"{E4B29F9D-D390-480b-92FD-
"{87D62D94-71B3-4b9a-9489-
"{A6FD9E45-6E44-43f9-8644-
"{c5a40261-cd64-4ccf-84cb-
"{5E6AB780-7743-11CF-A12B-
"{22BF0C20-6DA7-11D0-B373-
"{91EA3F8B-C99B-11d0-9815-
"{6413BA2C-B461-11d1-A18A-
"{F61FFEC1-754F-11d0-80CA-
"{7BA4C742-9E81-11CF-99D3-
"{30D02401-6A81-11d0-8274-
"{32683183-48a0-441b-a342-
"{169A0691-8DF9-11d1-A1C4-
"{07798131-AF23-11d1-9111-
"{AF4F6510-F982-11d0-8595-
"{01E04581-4EEE-11d0-BFE9-
"{A08C11D2-A228-11d0-825B-
"{00BB2763-6A77-11D0-A535-
"{7376D660-C583-11d0-A3A5-
"{6756A641-DE71-11d0-831B-
"{6935DB93-21E8-4ccc-BEB9-
"{7e653215-fa25-46bd-a339-
"{acf35015-526e-4230-9596-
"{E0E11A09-5CB8-4B6C-8332-
"{00BB2764-6A77-11D0-A535-
"{03C036F1-A186-11D0-824A-
"{00BB2765-6A77-11D0-A535-
"{ECD4FC4E-521C-11D0-B792-
"{3CCF8A41-5C85-11d0-9796-
"{ECD4FC4C-521C-11D0-B792-
"{ECD4FC4D-521C-11D0-B792-
"{DD313E04-FEFF-11d1-8ECD-
"{EF8AD2D1-AE36-11D1-B2D2-
"{EFA24E61-B078-11d0-89E4-
"{0A89A860-D7B1-11CE-8350-
"{E7E4BC40-E76A-11CE-A9BB-
"{A5E46E3A-8849-11D1-9D8C-
"{FBF23B40-E3F0-101B-8488-
"{3C374A40-BAE4-11CF-BF7D-
"{FF393560-C2A7-11CF-BFF4-
"{7BD29E00-76C1-11CF-9DD0-
"{7BD29E01-76C1-11CF-9DD0-
"{CFBFAE00-17A6-11D0-99CB-
"{A2B0DD40-CC59-11d0-A3A5-
"{67EA19A0-CCEF-11d0-8024-
"{131A6951-7F78-11D0-A979-
"{9461b922-3c5a-11d2-bf8b-
"{3DC7A020-0ACD-11CF-A9BB-
"{871C5380-42A0-1069-A2EA-
"{EFA24E64-B078-11d0-89E4-
"{9E56BE60-C50F-11CF-9A2C-
"{9E56BE61-C50F-11CF-9A2C-
"{88C6C381-2E85-11D0-94DE-
"{E6FB5E20-DE35-11CF-9C87-
"{ABBE31D0-6DAE-11D0-BECA-
"{F5175861-2688-11d0-9C5E-
"{08165EA0-E946-11CF-9C87-
"{E3A8BDE6-ABCE-11d0-BC4B-
"{E8BB6DC0-6B4E-11d0-92DB-
"{7D559C10-9FE9-11d0-93F7-
"{E6CC6978-6B6E-11D0-BECA-
"{D8BD2030-6FC9-11D0-864F-
"{7FC0B86E-5FA7-11d1-BC7C-
"{352EC2B7-8B9A-11D1-B8AE-
"{0B124F8F-91F0-11D1-B8B5-
"{CFCCC7A0-A282-11D1-9082-
"{e84fda7c-1d6a-45f6-b725-
"{66e4e4fb-f385-4dd0-8d74-
"{3F30C968-480A-4C6C-862D-
"{9DBD2C50-62AD-11d0-B806-
"{EAB841A0-9550-11cf-8C16-
"{eb9b1153-3b57-4e68-959a-
"{CC6EEFFB-43F6-46c5-9619-
"{add36aa8-751a-4579-a266-
"{6b33163c-76a5-4b6c-bf21-
"{58f1f272-9240-4f51-b6d4-
"{7A9D77BD-5403-11d2-8785-
"{BD472F60-27FA-11cf-B8B4-
"{888DCA60-FC0A-11CF-8F0F-
"{f39a0dc0-9cc8-11d0-a599-
"{f3aa0dc0-9cc8-11d0-a599-
"{f3ba0dc0-9cc8-11d0-a599-
"{f3da0dc0-9cc8-11d0-a599-
"{f3ea0dc0-9cc8-11d0-a599-
"{63da6ec0-2e98-11cf-8d82-
"{883373C3-BF89-11D1-BE35-
"{A9CF0EAE-901A-4739-A481-
"{8EE97210-FD1F-4B19-91DA-
"{0EEA25CC-4362-4A12-850B-
"{6A205B57-2567-4A2C-B881-
"{28F8A4AC-BBB3-4D9B-B177-
"{8A23E65E-31C2-11d0-891C-
"{9E51E0D0-6E0F-11d2-9601-
"{163FDC20-2ABC-11d0-88F0-
"{F020E586-5264-11d1-A532-
"{0D45D530-764B-11d0-A1CA-
"{62AE1F9A-126A-11D0-A14B-
"{ECF03A33-103D-11d2-854D-
"{ECF03A32-103D-11d2-854D-
"{4a7ded0a-ad25-11d0-98a8-
"{750fdf0e-2a26-11d1-a3ea-
"{10CFC467-4392-11d2-8DB4-
"{AFDB1F70-2A4C-11d2-9039-
"{143A62C8-C33B-11D1-84FE-
"{ECCDF543-45CC-11CE-B9BF-
"{60fd46de-f830-4894-a628-
"{7A80E4A8-8005-11D2-BCF8-
"{0CD7A5C0-9F37-11CE-AE65-
"{32714800-2E5F-11d0-8B85-
"{8DD448E6-C188-4aed-AF92-
"{CE3FB1D1-02AE-4a5f-A6E9-
"{F1B9284F-E9DC-4e68-9D7E-
"{40E85620-3DCB-11D3-8A0D-
"{BDEADF00-C265-11D0-BCED-
"{00020D75-0000-0000-C000-
"{0006F045-0000-0000-C000-
"{42042206-2D85-11D3-8CFF-
"{2559a1f7-21d7-11d4-bdaf-
"{596AB062-B4D2-4215-9F74-
"{9DB7A13C-F208-4981-8353-
"{692F0339-CBAA-47e6-B5B5-
"{e57ce731-33e8-4c51-8354-
"{640167b4-59b0-47a6-b335-
"{cc86590a-b60a-48e6-996b-
**************************
HKEY ROOT CLASSIDS:
**************************
Files Found are not all bad files:
C:\WINDOWS\SYSTEM32\
authz.dll Wed 2 Mar 2005 19:09:30 A.... 56,832 55.50 K
browseui.dll Thu 10 Mar 2005 9:02:34 A.... 1,016,832 993.00 K
cdfview.dll Thu 10 Mar 2005 9:02:34 A.... 151,040 147.50 K
iepeers.dll Thu 10 Mar 2005 9:02:34 A.... 250,880 245.00 K
inseng.dll Thu 10 Mar 2005 9:02:34 A.... 96,256 94.00 K
mshtml.dll Thu 10 Mar 2005 9:02:34 A.... 3,010,560 2.87 M
msi.dll Mon 21 Mar 2005 15:00:20 A.... 2,890,240 2.75 M
msihnd.dll Mon 21 Mar 2005 15:00:22 A.... 271,360 265.00 K
msimsg.dll Mon 21 Mar 2005 15:00:22 A.... 884,736 864.00 K
msisip.dll Mon 21 Mar 2005 15:00:22 A.... 15,360 15.00 K
msrating.dll Thu 10 Mar 2005 9:02:34 A.... 146,432 143.00 K
shdocvw.dll Thu 10 Mar 2005 9:02:34 A.... 1,483,264 1.41 M
shell32.dll Tue 1 Mar 2005 0:11:18 A.... 8,450,048 8.06 M
shlwapi.dll Thu 10 Mar 2005 9:02:34 A.... 473,600 462.50 K
spmsg.dll Thu 24 Feb 2005 19:35:06 ..... 14,048 13.72 K
urlmon.dll Thu 10 Mar 2005 9:02:36 A.... 607,744 593.50 K
user32.dll Wed 2 Mar 2005 19:09:30 A.... 577,024 563.50 K
wininet.dll Thu 10 Mar 2005 9:02:36 A.... 656,896 641.50 K
winsrv.dll Wed 2 Mar 2005 19:09:30 A.... 291,328 284.50 K
19 items found: 19 files, 0 directories.
Total of file sizes: 21,344,480 bytes 20.36 M
Locate .tmp files:
No matches found.
**************************
Directory Listing of system files:
Volume in drive C has no label.
Volume Serial Number is 7594-4EC0
Directory of C:\WINDOWS\System32
18/05/2005 12:14 4,096 psc.exe
19/04/2005 20:39 <DIR> dllcache
05/07/2004 22:57 <DIR> Microsoft
1 File(s) 4,096 bytes
2 Dir(s) 1,931,616,256 bytes free
Navigate to this file:
C:\WINDOWS\repair\mfcdoc.d ll
Check it's properties.
Let me know what they are.
It's very unusual to see a "Winlogon" entry running from the "repair" folder -
let me know what other files are in there - the "repair" folder.
RF
C:\WINDOWS\repair\mfcdoc.d
Check it's properties.
Let me know what they are.
It's very unusual to see a "Winlogon" entry running from the "repair" folder -
let me know what other files are in there - the "repair" folder.
RF
ASKER
autoexec.nt
codcfm.bak1
codcfm.bak2
codcfm.ini
config.nt
default
DS_SAM
DS_SECURITY
DS_SOFTWARE
mfcdoc.dll
moveonb.exe
ntuser.dat
sam
secsetup.inf
security
setup.log
software
system.bak
zap.exe
codcfm.bak1
codcfm.bak2
codcfm.ini
config.nt
default
DS_SAM
DS_SECURITY
DS_SOFTWARE
mfcdoc.dll
moveonb.exe
ntuser.dat
sam
secsetup.inf
security
setup.log
software
system.bak
zap.exe
Check the properties on:
moveonb.exe
mfcdoc.dll
zap.exe
codcfm.ini
Let me know what they are.
RF
moveonb.exe
mfcdoc.dll
zap.exe
codcfm.ini
Let me know what they are.
RF
ASKER
moveonb.exe and zap.exe was my attempt to kill the winlogon service.
mfcdoc.dll Unknown application
codcfm.ini opens with note pad and is hidden
mfcdoc.dll Unknown application
codcfm.ini opens with note pad and is hidden
Can you open codcfm.ini in Notepad and copy and paste the contents back here.
ASKER
âpRÓ Š ` ê ê ê
" " «b Íc ác ác ác 4 d d d d !d Ï694ÄdŠ8¨²v4ec0V/Pv4ec0[ Pv4ec03594 Tc0·Û4,e c0759449E5 7594Yec0X= \v4ec07594 4e“75944e {p6P]]UK _rRZsvsT' u URs S V/Pv4ec0V/Pv4ec015944ec0L VXYD
WYwUBQC\VZq_EUWa7/cL \@
K[]L\@AJGLXQMJN ZUYYP[g q$1sjxxxG A UTbgugOEAXCAIJG@JQU XW[LCRTKW\KXG
X]PXGDGCME@UQGKBRR\LDGMLJ@V JRiW[eHCJF@\FMGSOo;EmHWRMINDPXFW?TZTIOKlIE^KlkiAG\SQBUVUVGZ\hK _ZH9\L@QCKXM 8nhILKBRR\LDGMLT[[A?TZTIOKlI@ ]DBojC>JF UOE\[AQQC lVVYIKIk
EMLF@\FML^KlkiAG\SQBUXF^FMUhK _ZH9\LEHQKTHDH_BojC>JF UOEUkXX@YDAXh]JhZHHULVDIHU
Nbj8HMFQHGODVCPG@?TZeAeHCJFIXEUAGIXE[L^KlkiAG\SQBUY_YiW[eHMELMUUF\UFleR\SRQMBSF H@PTNbj8HMFQHGOQMZWhMhKKLKGRWJQU Xkh
U[Q_Q_EQJ FSBojC>JF UOE]VOVZhKBJhZILJ@P[GQS_ihZYRY]_ GXG]GXQOo;EmHWRMINQZTC[Z9MSXiA_M iHCRDPXFW?iR] T^\MC
TDHVLngiNKQS @OUG_ZeW
MhEDKMHoFIXGk AKTJk[\VFMZU
Nbj8HMFQHGO\kZ[YMiHLKABPKMHoFIXGk AKTJk[JLngiNKQS @OU
lQ\IOKlIEXkidIGJEP^QLANX[X9MVEH9\LEHUELEUD<DRGTGXkidIGJEP^QLANX[X9MSXiA_MiHLKAKDLQFQGFf@QCBojC>JF UOEBPZJhl@RIOKlIG BT]MQFLngiNKQS @OUZRPOQG9MSXXDM?KULFOo;EmHWRMINQD^SQQCkZ[hK [JhZXG_
Nbj8HMFQHGO_ZOeW
MhEDEE 8nhILKBRR\LDGMLTM@hKUC H9\LEFQDjHHU<_FIXGk ABojC>JF UOERTiW[9ME\H9\LH O>=jDMUPPADKHKUPJ@UYCPJIOK lI_XkidIGJEP^QLAN[QGENiW[eHCJCABojC>JF UOEYMGX@Q9MSXXDM?K_Q_EQOo;EmHWRMINR[@\M[UEiW[9ME\H9\LH O>=jDMUPPADKHKUTKZQ^S[VVX ?TZTIOKlI\KTM\HTKAP@X QBAQ[FUNBVFP^PIPZGR[ IWYQSCI] F@GEOo;EmHWRMINRCZIQZB[QeW
MhEF@\FMXkidIGJEP^QLAN[AM9MSXXDM?KEAXkidIGJEP^QLANZ]FYCVP@M9MSXXDM?KGQS_BojC>JF UOE ^RAeW
MhEFBojC>JF UOE ^YiW[eHCJABPKM 8nhILKBRR\LDGMLVVYQI DA\YG9MSXX DM?KEF^KlkiAG\SQBW[EDTeW
MhE\P@C[LngiNKQS @OW
@BF\FB ?TZTIOKlIEBNBojC>JF UOE BV\^GXDkVFSMiHLERG@ O>=jDMUPPADKHKTCJh]JhZDLQF^KlkiAG\SQBPQD^X\h]JhZ^\MC
T
Nbj8HMFQHGO
^XVZXUk]QIKIk
EMERG@HCABojC>JF UOEYEPZ@\lVVYIKIk
EI
Nbj8HMFQHGO_Mi[FeHCJCRTKW\XkidIGJEP^QLAN][S
\RiW[eHCJFIH_CL^KlkiAG\SQBP[EGiW[eHCJ[
Nbj8HMFQHGOEPFM[F ?TZTIOKlIG BT]Oo;EmHWRMINUVGM\X[kWQ@MiHLLngiNKQS @OQIkZ[YMiHLKCX\WWXU@ZKPGQC\M XQERG@h ZJH@QiOo;EmHWRMINUUT@hMhEDLQFQlIJ[] \BQ\C[CKFX@]UWh8nhILKBRR\LDGMLP[UM9MV EH9\LEA IiHG
^TYLPQBSFEGU
D[P @QK9\KlkiAG\SQBQVlVVhMhEFV]ZESPN[FLDTM]@ LF@\FMW?Wh8nhILKBRR\LDGMLPWS]iW[eHCJA
Nbj8HMFQHGO YY\VZG9MSXXDM?KGQS_jJ@FW
Nbj8HMFQHGO S^A\h]JhZH_C
Nbj8HMFQHGO
^STK@]UDiW[eHCJ[RLOo;EmHWRMINV^[]]U9M^RADM?KEA I
Nbj8HMFQHGO
BRWXXX9MTRH9\LH O>=jDMUPPADKHKQG\QRTkZ[YMiHLERG@ O>=jDMUPPADKHKQG\QG FRiW[eHCJA
Nbj8HMFQHGODXGeW
M9\L^@kI@ZKPGXJLRLO^NLkidIGJEP^QLAN^]@
?TZTIOKlIEBNBojC>JF UOE_TYPW_9MSXXDM?KGQS_BojC>JF UOE__\Ih]JhZFZ O>=jDMUPPADKHK_TURhKRVLeW
MhE\P@C[LngiNKQS @O\lVVYIKIk
ED
Nbj8HMFQHGOVXFIUW ?TZTIOKlIGKDWHEJLngiNKQS @O]
\[T^QhK _ZH9\LHFMXkidIGJEP^QLANPC[?TZTIOKlIG BT]_[FXkidIGJEP^QLANPLE
S\iW[eHCJABPKM 8nhILKBRR\LDGML_ZDQUNiW[eHCJCRTKW\B^[^ O>=jDMUPPADKHK\TW[[UkZ[YM iHLERG@ O>=jDMUPPADKHK\PU_[
?TZeAeHCJC^A\GQS_DLQF^KlkiAG\SQB_XD@Z\Q?SPDM?KEA I
Nbj8HMFQHGO
^\OeW
MhECPKY 8nhILKBRR\LDGMLYV[_Q EAeW
MhE\P@ O>=jDMUPPADKHK[ZV_GBCiW[9M E\H9\LRQMXkidIGJEP^QLANUAWXXX\DUlVVYIKIk
E^KlkiAG\SQBXMCkZ[YMiHLKABPKMHAKRMk_ GXG]GXkidIGJEP^QLANUMW
lQ\IOKlIUELEDGJLngiNKQS @OX _DiW[9ME\H9\LEA IKEJPXkidIGJEP^QLANTUYlVVYIKIk
EUELOo;EmHWRMIN]VFMQF9MSXXDM?KE 8nhILKBRR\LDGMLX\SUlVVYIKIlNbj8HMFQHGOWVB\VhK _ZHhZkidIGJEP^QLANTQFZP]W[9MSXXDM?KGQS_A\L@XkidIGJEP^QLANTQ@ BVBUQF9MSXXDM?KE 8nhILKBRR\LDGMLXVZP
UVGZ\hK _ZH9\LHAQLngiNKQS @OY
CCPKh]JhZDOo;EmHWRMIN]D[eW
MhEFBojC>JF UOECYiPQMiHLLngiNKQS @OYlPJIOKlIEXkidIGJEP^QLANTGZ9MCRH9\LH O>=jDMUPPADKHKZFWhl@RIOKlIEXkidIGJEP^QLAN^h^kZ[YL BFQDTSihMJF UOEUVGZ\hKCYiW[EPJAXoC>A
Nbj8HMFQHGOCRTKW\9MSXXDM?KG BT]_[FChDEUG:@FIXGk
Nbj8HMFQHGOC^XVZhK _ZH9\LEHL^[IA@I@ZKPXkidIGJEP^QLANWQ@ QGPeW
MhEF@\FMXkidIGJEP^QLANWQLWkZ[YMiHLUVGZ\ 8nhILKBRR\LDGML[VF@BY YPS\?TZTIOKlIE^KlkiAG\SQBZ@ _EY]h]JhZDOo;EmHWRMIN_APK@AlVVYIKI k
EI@ZKPGXkidIGJEP^QLANIUS UR^\FhK _ZH9\LJQU X
Nbj8HMFQHGOYTP^FUUEiW[eHCJVXGTk_ GXG] O>=jDMUPPADKHKDPXFWRiW[eHCJABPKM 8nhILKBRR\LDGMLF\UF[^[^h]JhZ^\MC
T
Nbj8HMFQHGOQEVQFQ\CiZQeHCJCPKYHJLngiNKQS @OG
_BBXZZ?TZTIOKlIC
TDBojC>JF UOEET]\ZhK _ZH9\LH O>=jDMUPPADKHKD@IQFWRFeW
MhE[EWXkidIGJEP^QLANJAF UR^\FhK _ZH9\LJQU X
Nbj8HMFQHGOBPPMh]JhZSPQXKKPI@ZKPGXkidIGJEP^QLANMQWQER\@hK _ZH9\LHAQLngiNKQS @O@ ]ViW[eHCJkFAd O>=jDMUPPADKHKC\Z_QQDA\FhK _ZH9\LRQMBSBojC>JF UOEYDVXX]MhE\P@ O>=jDMUPPADKHKC\JWU
YCH9\LRQMXkidIGJEP^QLANM]G\^iW[9ME\H9\LHAQLngiNKQS @O@RXSPZP9MSXXDM?K@QC
Nbj8HMFQHGO
BP\U][9MYCH9\LHG 8nhILKBRR\LDGMLBXXYD kZ[YMiHLUVGZ\kUELOo;EmHWRMINGRWeP eHCJCBBojC>JF UOEUUX]h]JhZDLQF^KlkiAG\SQBC\EDP\_hK _ZH9\LEA IKTKSXkidIGJEP^QLANAADUEiW[eHCJDRGTG 8nhILKBRR\LDGMLMLDD?TZTIOKlI_ GXG] O>=jDMUPPADKHKNTQ[[9MSXXDM?KBFGIO[HJLngiNKQS @OP ?NTQ[[9MSXXDM?KBFGIO[HJLngiNKQS @OM_XiGQMiHLKFVIODHLGOo;EmHWRMINIV]V[hK _kL_IKIk
EMQKCIHB
@BojC>JF UOEUVGZ\XXZW[DPXFWMl
iDXkidIGJEP^QLANU[[?TZTIOKlIEXkidIGJEP^QLANQ[@DkZ[YMiHLERG@ O>=jDMUPPADKHKDPXFW?TZTIOKlIEXkidIGJEP^QLANVZQ _\iW[eHCJG
Nbj8HMFQHGOC^[\GG9MSXXDM?KEA I
Nbj8HMFQHGO^kZ[YMiHLDCBojC>JF UOEID\T[Z9MSXXDM?KE@XkidIGJEP^QLAN\D]
_YFeW
MhEDPXFW<CCGPZSXkidIGJEP^QLANJ\[UEJQU XkZZQ?TZTIOKlIEXkidIGJEP^QLANZ]@UVGZ\hK _ZH9\LN\QLngiNKQS @OZYX[XXhK YCLJQU XkZ[YMiHLERG@ O>=jDMUPPADKHKRCP@Q9MSXXDM?K_Q_EQJ O>=jDMUPPADKHKP\_@G9MSXXDM?KEA I
Nbj8HMFQHGOQGiW[eHCJABPKM 8nhILKBRR\LDGMLFZ]Fl VVYIKIk
E^KlkiAG\SQBUX QkZ[YMiHLLngiNKQS @OV [RY\MhKTBH9\LRQMBSFOo;EmHWRMINWXZ^XQ9MSXXDM?KE 8nhIL_GAP[ZGZJ]@^EVDAAVVAZADFB^A@UAJHB_Q_EQJg BT]GAWXZ^XQGACRTKW\KQ _ZVW
F\UFZFWW
BNC\DPXFWMSXXG BT]JW[TZT^XZ]XQK _ZGQS_\VUMSXXG BT]G@YTOW
PXFWM\NVVG]NCCKYEF\UFTZTG QEVQW
BNC QTAJQU X[\@GG@JX[ XVVYGG@JQQUR^W[A^ FC CRTKW\K _ZKQTVJQU XE\FR DYTOW
JQU XVVYGIDPXFWM]NBXM]NQVKC\Z[YGAG@BFQBR [ZQ]UUZ
^P][Y
^DEVZG
TZTGLV[S TZTFFKW\K _ZVXUQ\WP] WPTV NCCKUDA@R]TZTGENFG XVVYGG@JQU XVFJ]G^CWQ@GAG@BUXF^ FMU]NCCKIDPXFWMSXXY][ \LWUVVYGUVGZ\QEAPAYK _ZFQ^BPZQA@BNRTC]\CQYCP@[AUSZ[YGAG@BRF UDPXFWMSXXCYAJQU XVVYGUVGZ\DMPK[D_]ZMYYA\X]TZTGZOQFBRZ[YGACRT KW\KQAPKW
XJLY MR[ZNGQS_Z[YGAG@BP[Y [PW[APY VVU NV^[]QFK _ZGQS_Z[Y CNFMQYMSXXC^F\UFTZTGR\@R
^SZ[YGAG@BCQ BVBUZ BNCGRWJQU XVVYGG@_QUBRQFQ\C FW[AZF KIDPXFW MSXXC@]@DDMSXXCUYXNQ
^SZ[YGACRTKW\WRZWGUV GZ\VXGTU@^VVYGTX@GQS_TMCTZTGF\QEK _ZAGU\Z[YGAG@BWX BDPXFWMSTCCMCRTKW\W[\@GG@XXYXCLJQU XVVYGUVGZ\ BC]U]ZM^RAG BT]U[ MSXXCOEJZ]JQU X[\@G@RZ[YGAG@BYUV^ []W
BNCKUR^W
BNC
]GYPW
@JGQS_Z[YGARRFMG BT]WWGACRTKW\TZT]V\W\[MSXXUCV]ZTZTG[\C@
C^A\G]JQU XVEAZTZTGF\UFBRFU@]NCCKRF\UFQDFPG@DVVYGG@JAFIDV VA@K _ZCCMV[TJ\XXCF\UFTZT W^[\Y QT]XFS MSXXUMCRTKW\E^G\W
JNRQMBSFd[@vQJWAPZVSX ADPXFWMIV]V[]JQU XXJZ]NCCK_[F\UFTZTQEVQGW
DVVYGQYZVPX MSXXG BT]QVTZTQEVQ_G[XB]\UF[LZ[GK _ZCCMC^GJQU XVVYGG@UUVGZ\]NCCKHVVMGQS_WQ@GAG@ BGX
S_Z[YGAG@BGQ CRPRW
\JRDPXFWMSXXSM KR GQS_IQFSC[XB]GQS_Z[YGA]NF\UFZLNUMK _ZCQMQD^W[A@BNF UEPWWQK _ZXUYYRP[YYFI[ZBVVYGG@@[[UVVYG@DJFWMSXXV JRSPZPK _Z KQ KRCCMJRFMMRTVVYGG@ICFS_Z[YGAG@ BGQS_TJ G]QYAZQ A@BNU QA\J@UK _ZCCM]NF\UFTZTHZYQL
DRZ[YGACRTKW\KDVGM]AMSX XF UY@\Z BNC
^SAQQC C^A\M[URQW[A@BNRUR F\UFTZTG[MGQS_Z[YGACRT KW\KUCO\F[ KUCR]^[MQXCVVYGG@VBQEEPW[A DPXFWM^VC\ F]TGLUYVCG BT]W[A@BNP
@^Y\W
RU[VQ\WPQMSXXG BT]W[DDLJ@QTZTG\JQU XVVYGG@^Q@EYQW[A@BNC SETNXDNCCKI@P[GQS_Z[YGAG @BRQEEP ]F E[AJW
XJTM]NF\UFTZTGBQMD TZTGWUUN YYQW[ADPXFWQPPWWGACR TKW\K
^QZKYU
_YZ[YGA[STMG BT]YMIVVYGG@JQQMS XXAUR^ W[A@BN W QEF\UFTVCDPXFW
^PWQ@GAG@BUX
W_A@GQS_Z[YGACRTKW\KQE AQX]YPMQEVQU
TZTGMIGZK _ZGQS_WQ@ QGPW[A@BNYCQ\WP]NCCWMCRPR]NCCKYZEU]]LGG BT]W[AUPJ@QEVQWA DPXFW _VVYG_ZTPZ\
TZT@D []_VVYGG@WQC@D\MQGK _ZGQS_TIATVVYGG@JQU XEPJX@K _ZCCMJQU XVFJ]G^CZ[YGAG@BGAUN FZ[AMSXX CQYXG\
W_AJQU XVVYG^P\WQDVVQUFTZTDPXFWAB\KQ]PYUCAKUR
SZEW[AMUPBAPKW
T]GKUAPWAQKUCUPK_B WUQW
S\WQ@GAQSF\FB D]XFQBRZWX]TZT^DWM_EZ[YGAGRWIPDKQCZKW
VVAZMUO\MQLQYR\W
WXZZ VVGTUVQOQF
C^[^W
FKUQAPW[AXTJW DETUF \ZP]]UK _ZUPMS[\Z_U^CFW[A@ BN^QSW [AUTWZQ GPWZMRVVYG O\P[K _Z^V@XEJW[\@GYCGVAGKH^ A_AQ MSXXUU\]WXTZTCM]W]@EDPZ@ ^RA_AQ MSXXUGTK@Z GGVR]MSXXUTPW@F]RQPUPFZTRTZTUVQ]@S\P@GTB\U@BU @^W
BNC@BEIQFMSXXUMDET_R]@ VVYGTDX PPQZ\AW
T]GU[Z[YGA@XELD^ VVYGTDP KBDRGWQ@U[Z[YGAYDR CVY\YQ
QVVYGTDJDQ
V^VI[DK _ZUYUTURA
_YZ[YGAZC]\PQ YYZ^@TM^RA] ZUGUZP]]UK _Z]GSVXGU ]RQPU]I[DCT]X
YTFW[A^F^ K QDTUQY YVZ[YGAYDR CVY\YQ
QVVYGTD]QU U[E\F]SYQ
QU@@ DWQ@GASQZ[ZKC[]NGAQS SXFYKUS\X DX TZTGZ]MGEDXXF_ YYRW[ATTZ\QK^^VXG@K _ZWKUSZW[AVS_C D_PKVAMSXXV^RGJBER T]W
BNCQQSPWQ\XG\F]PWWK
^CPUX]F[\@GUS\XRDT YPW_KUCG QUSW@U UEAPG]TZTSXX_SPUQYXG\QT^ZQAXOBU UTYPW_K _ZUFKD@ZUU]ZX] DDOUXS[\Z_]ZU ]GZ[YGASYAFU
TUYXG@ TZTG@QGFRGM]GWVVYGRVF\K _ZCCM^RMMUSK _ZCCMQSCW@TMSXXWQMJR QVW
Z[^QGTJG@
CX[W[ABFFPKQ_ZVW
@JRTMIV]V[RMSXXFNTQ[[K _ZAGKLX\[
CVVYGG@DU_G@IW
QVCZ QSFUURCTG\QZFRGJW
BNCKQNEVDAMSXXG FRXXW QVVYGG@ZX_QMSXXC L\GUUEAP G]TZTFYA ]XGGVC\W
EKQBGGZIG]I[DKYEVAW
BNCKUDT]BQYD\WS]JCDRGI[X TZTB\U@BU@^W
BNCC_ZV@QMSXXWK QDTUQY YVZ[YGAS CQP
MSXXCGT@D[@VVYG
]VR\G^M\W[AVQJCQSZVFQ
UVVYGS\PMR^OV^RGJP
C^CUGXBQDVVYG S[\Z_GYYRW^RYPMGIUM@BEW[ADE@FV^VTUFDG YXWQK _Z\[MS[\Z_V[[\@GG@ H_GYPMGWQLWVVYG \\X@PTZTGTC[[UVQJW
_PWY YVZ^@TM^RAY YVXPF _[C\F]XPGK]Y\W[A_AMDUSRQ^QVVYGQY[\FGK_CP TQ]NCCK _YFLYD
_Y_LZW
_YZ[YGAEDXFPKQ_ZVW
_PYQT_MDNCCK\XB^[][UZBPZQNDET_R]MSXXUU EAPG]GTU@U TZTCRGOQFKBUZ[YGAG@B CQXRG[A SK _Z^UDVGW^RYPMBAPKCEC\W
T]GOMYWM^RA[S R[MFU MST\XPGKCNCC\M@VLI[DTZTT[Z^]LK ZCZQATYPW_MDXA\YQK _ZRUNZ AXFS ^RAW[A@BNX
[X\W
BNCTXZKW
SXPQRXMX KQER\@Z TZTGPTUFDZTRQFMSXX R SMUFDYPMW
_I Z[YGAQSFF UY@\Z TC[[UVQJW
BNCQQSPW^APK@QMSXXRYAXFS ^RAW[AVQJPUTADF
YPLZQAVS_]XDR]@]BAZ[YGAVVQU[YLZBPPMZQMSXXW
S\U]ZIYPKSMK _ZCCMQSFKBQK _Z@FD@[X]VQPKW
\TUS MQCQT@]NCCK
^Q\W]@ NQSFW[A@BNVS[\AW
EXMD
EGZ[YGAS[\Z_]MWXWQ@K _ZCCMVQI[C TZT^[J]SUOEKQGMSXXU G[ D^ZWG]HB\[V^Y\u!0ozj`GUV VM][KVUQUA_UTUPA][\@GY[P[VTBLXYD][C_VQ_UQVVYG \^XNUMSXXWC]XC@ MSXXWAPK]G^VVYGUD^M[DKQMTXW
VKXB^FPSZK _ZUVMWTRUY
YPMU^U]V\ZQA~[ _[GSRZ[ YGA}DMAYXK
^QZJDUTZTR SQZTPZ [X[T]GBVI@RTZTWSWP
C^ZWU]BFW[A]T[ [\@GTCRTKW\K _ZuPK_BWUQW
S\WQ@GAqSF\FBK
^CPKZQERYW[Av^XDDKXR [LW
tIDUY@W[AuTWGQ^[MQFDQ@\X]{]PDBQQZMSXXw
BVVZGBEZ[YGAtTYZ[FMBGAJZ qK_ SVYWFPK _Z|[SPZZUV YPM+DUGVUPCCZ[YGAcZT K@D
CVVYG0@VEIC^BZ[YGAhO MM[[ QEZ[YGAQUPM@Q
^CPKZQMSXXUYAPUX DF\FB TZT D^C\YTZTT^VM]B UT]W[X
YRFZQAVQ]FQ]XP[_ZMVUMSXXU_GE\F
DUYXNQK _ZUPQEZ[YGAQSFUPQEZ[YGAQSFUP]^Z[YGAQSFWQBVYTQP@FU_ZMVUMSXXU^[MQFDZI@]
JRGW[AVQJ[UEZI@]
JRGW[AVQJBQTVUCPF@EYQVW
T]G KYEALYA_VVYGTDPKBKRVA\G]XP@ D^VJW
T]@F [RG TUUZ[YGAQSC\F@YYRXSQTZTUYAWRTZT _\PXPUMSXXUMYZR_UFMSXXU@ GN\QTZTGRWC\ EVVYG\[T[[AUVGZ\]TZT]^RQ@MQEVQW
TUD\MCRTKW\C^FMUZM^ RAU ^RAW[AVXXN]QBAVGG BT]W[AVXWBDX[ @VVYG@G]QG_GX_D@ZK_GK _ZUDMUM@UU]XDDKXR[LW
TIDUY@GD TRGXZ TJG]QYAWRTZTUY@\YQ
QVVYGIUU[DK _ZVMSXXVCXYV]QD Z[YGARVQLF XKBV[]G@ UC\W@QS C\OQ][UP\\\DXYYZ[YGARV [WQFBAPK S_EZ[Y GARV[WQF S_TWSQK _ZVUUEMUPSC\ZG][UFKI@P[GQS_Z[YGART SUBVVYGTR]W
W\X@KRRAMQFDRGWQ@K _ZVQDPXFWCD\J@UYPMPTM[FK _ZVSWMWVAVF][]DXGW[AU\]@LMG_ PWA][]S_C]\F
WVA\W\VCBXFQK _ZV][ZIW
WPGT[ DZUA@^DZ[YGAR[@\\U^ZP]]UK _ZVF\^TW@PYCTUW
WK[CB@\JQ][AZU@TKQ]ZUDCPK]ZBYPMW
VWQBVYTQP@FWK_E[VSFXVVYG \N[ZK _ZW KQOF\FBWVVYG X@GQS_Z[YGASVQJ[XKYV [XG]ZUG_U@PXP ^U[[@VVYG QDFXZPDPXFWCD\J@UYPM ^BVZ]ZPZK \^XXLV [DZ[YGASS[Y[
UD\@WK _ZWQBVYTQP@FWZLJQU XVVYG VPTMC CRTKW\K _ZW\ [^[WX [VYZ\QTZTBXXPAYKXR[LW
VS@KUCWX ^PPMUCU\CYT^R]^XBW[ATYPW_S_PTM]ZX]HU@Z_GK _ZWZM W
VWGY]Z[WQ^YZUGMSXXW
U\^ZDQDPJW
VVZRPGXZPBRPM]ZBVVM]B MSXXW
DR[MPXUTKW
VVZ@ EVYJQU XVVYG _EEWRTZTEGZWGDXGW[ATGG@
GZIADHTDW[CK _ZWFVVYG BXFJF[CG\_PQVVYG C]V@VTZTTL][[MSXXWCBX]ZHUT]W[AT@J@JRD PZ@KUCPU UDAGD TU\MW
QX@U_EXV]ASPU@UKTEZXF]]]FKPW[AS\KQWMC^ XIXQQQSP W]][WR^BVZ]][Y
^\X[
EGZ[YGATXBWX[]][C_VQUV DRGPZ@ ^RAW[ASZNZX
TWVZNMSXXP
^[ZXP\[PMDF
VDZ_@]][C_VQRQQYRW[ASZNZX
TRPSUS_FVR@BRZ[YGAT XBWX[^EPZGXCWQ@GATXBWX[AMWASZNZX
TBQQZMSXXP
^[ZXPKRRAMQFDRGWQ@K _ZPMMF^GMAYTXZ[YGATN[XY]MXX A[UFK _ZPMUY@\[QEZ[YGAUTETW
P_W_YZ[YGAUGFPX[MCRTKW\C^FMUZM^RAQBRFJRQVVYGJF\UFYYRW[AROLXUK _ZR]F@PW_K _ZR]_[Z^MY[\BQ_YPZQA QFMFU F\UFTZT@VU]WBVVR]ZMYYS VDXGDXGW[APTM[FURX@[ MSXXSPTM[FK _ZSQUVAQQFCCZ[YGAW^ ^U@
TZT_UTU@[
RVGW[APYVVU UUF\UFTZTQYQJ@F D^[MQF D^C\W
RJS_EZ[YGAWC^U@
TZT\GTMG BT]W[A_\MGQR@P[W
]VYQK
GX[W[A_ZMVUMSXX]H_X ^LD]P]TZTTDXPF
BVVYG
UGYLS]MSXX]DYPMW
\TUS MY\TS]PYU^X^RUTZTQPPJV
J^Z[YGAYZT^QGKQCZKW
\TSVTZ[YGAYZRY QVVYG
]P[UZBDMZ\UUVVYG
]PU[DK _Z]YQEXW[A^XIFQYX [G BT]W[A^[J@U UGVCG DXZUVUMSXX]DVYUP[ QEFW[A^[J@U C]V@VTZTDRGWUXKHZWG
^CPKZQN_GAPY]BVVYG
@R[]PQDAVFYKYM]DC^RQ@]PF[MG_PWA]SUBQEZ^@TM^RA^C ZMP
BVVYG SSPZYW]ZU@]M^RA^U[TGK _[APPDSWP N^ZF^
D^QZQA]VTGTXZKW
_Z[Z^C[ZGTM^RA^GYYVUP SVS@KUC^Q^\P@W[\@G YTDW^RYPMYYQJQ@K ZCZQA]E\P[\XT]^
D^QW[A]EP[X T_MDSC] ]RQPU DWQ@GA[KYYFX[MSX X_QYZW W
Y\UPKXR[LW
YPWQU]V@VTZT
CCFUPQEZ[YGA\XZR@
QNZ[YGA\XZRY MSXXX
TZTW^VWRTZTY[OLK STUDKQCZKW
XXF_KPW[AZTJ@QM] OMUFD^[ ^W
XXLQTZTT^TUXUCZ[YGA]RQP UVY\ZW[\@GUZZKMY UEZ[YGA]RGZAFMG_PWA]TQGWRWK[U QDA\FDTQ@M W
XPZPD^Z[YGA]XCPQGHD TZ[YGA]DP XFWM W
XJB] TVYRTYPYUET^JW
XMK \^XXLV [DZ[YGA]NPC[MSXXYQY\ZVA_YZ[YGA]NF\UF^XBW[AZLNQVQEVQW
[\@D^XBW[AYPMDU VQPKGDWQ@QEVQG[TZTG[\@GYTA\W\D@ZK_GK _ZZ[@[\@GC\LD
DBFXW
[JVZCA Z]MGEDXXF_ YYRW[AXS_QF
D^XPNQMSXX[WVF\UFTZT
Y@IPUYPM
R^A\LD BRGW[AGTK@Z C]V@VTZTIGPK@QTZT X^O@FMF^GMAYTXZ[YGA@[@ ^AGTTJ\]IXAMY@ZWW
ETU ^RAW[AGG\P]YAPJQU XVVYGB^V\VUYCZ[YGA@E\OUWMF^GMAYTXZ[YGA@E\CQY X^[\SUDPC[MSXXD]XF\[QEZ[YGA@EZJQU X^[^W
ELBDUTKW
DLQFMYYV[_TZTWDPKBQMWVAVF]KQD
DDQ[@BVVYGUGZK@GKVQPK[D
]^O\F]KQGDD]UGQEZ[YGABRF LX@MCRTKW \ _BAW[AEPJAX]VFMQFK _ZFGKQCZKW
GJDG BT]W[ADXVQUE\W@QUC Z[YGACVC\ Z[N@XEUP MSXXG UYZND
EGXPGK _ZGV
]JVBMSXXGYGAJQFB RX@[MSXX G BT]UW
FRTULK _ZGQS_^U@
TZTQEVQ] \BRPZ]JQU X\N[ZK _ZGQS_TMG BT]W[CK _ZGQS_AFQTRGW[ADPXFWQ^U[[@VVYGUVGZ\USTZTQEVQUG
CCTW@_YZ[YGACRTKW\C^FMUZM^ RAG BT][AGK _ZGQS_QPGDK_CWXF]JQU XRM\W
F\UFGRWW
F\Z@]X[]DC^RQ@DJQFB\I]Z
W_AZQAD]XZSYK _ZG]
\VGJ]ZUDZ[YGAC^[XRQ VVYG[^[J \
RVGW[ADZXDUOTW[A DEXDDKXR[ LW
FIUCDVVYG@RP]VUM]NBXM]JDAY\OLK SJDC D_PKC^BZ[YGACGB\VUY@W[ADE@CUXRYIZ FHC]TZTG^G\]H_X^LD]JFWM\XEW[ADFSUBVVYGCUTZ_AMWVAVF]J@Y[YPUZYP\MUXK _ZG@YTRVVYGDXE D[@T]G GVVYGDBWT[ZK
@^[J]SYPMUYVD]JAD GRWJQU XVVYGID@IPUPGXZPBRPM]ZBVVM]B MSXXGEGQX@QK
UGYLS]MSXX@_VVYGTZLW[A CP_G]MR] MSXX@
^\\WSY YVWQ@GAD_\WG@\T[Q@B ^[MQFDVVYGYYN\QTZT
DV[PAYKXR[LW
AV[XB\X[
EGZ[YGADXZUVUQ^U[[@VVYG_XYM]DMXXA [UFK _Z@[
S\FW[ACZMUX\XVP@MK _Z@DCAVD]CVVYG@S ZNZX
TAVD]CVVYG@EPI[FMD XEPW_MSXX @S\]X G BT][UFK _Z@F [FPYD DET_R]MSXX@S\\WSYDE@W
AKUW
^PJD]BUTP@]MFUYYR@\TRG][C_VQJW
AKUR
S_Z^W
AKUZ D[]QBKHZWGBV[JW@ MFOWWGADE\Z_X MWVAVF]MGDYPMW
AJS_EZ[YGADDFUXUC Z[YGADA \BAP[ZMSXXAQCPGD TU\MW
@IPUDAVD@BEUPN^XBW[ABE]U@ MD_@WPQ_@[U[UTZTTVA\GC\AVDYPMC[CVVYG@STMQGKUD^ M[DKYEALY A_VVYG@STMQGK_CWXF]LDPUDPKBQMWVAVF]LDSTRF\[QEZ[YGAED PKRQVV YGYRBU@ DVVYG YG_UFR_ZMVUMSXXBQTKYMXXA[UFK _ZB]NVVGTDUTKW
CPDBZO\
RVGW[AA\IR]O\
RVGW[AA\IR]C\[Q EZ[YGAF^G MAYTXZ[Y GAF[Z^]WK [[\@C
[DZ[YGAFZT]Y]MSXXB@RQUF_AP]W
CMFUA\K@A^SZW[A@TIRQV VYGRRX@ [MSXXC D_PKS_EZ[YGAGRTM\QMG _PWA]NQUUEN\QDE\QP Q[\@GUU[UXSR^U@
TZTRBQQZMSXXC @]\ZAK@RP]QFM^RAC @SESUBVVYGV^MW[A@]\ZAHTA PK@]
^PPZR
MSXXC^BXPB D^FPZSK _ZC\ EEVDANQSFW[A@]\ZAK _ZC\ EDPXFWMSXXC^BFQ[DHTAPK @]
^PZQZQ[Z[YGAG_PWAG@EVDCVVYGXR[LG\
DEXWQK _ZC\ ED]VDUY@W[A@B] \BRPZ]NCK
UGYLS]MSXXC^PIXA
^VVYGGSPQD W^[W[A@BNUSTXJW
BNCVTZ[YGAG@BURWQ@GAG@BY QDPXFWMSXXC F\UFTZTGTXPW
TZTGT[Q@B^[MQFDVVYGG@XW@UTUQFNCRGOQFK _ZCCMQTAPBQHQOZ[YGAG@ BUWDVA W[A@BNU YTAPBQ S_[VX[
UDWQ@GAG@BUPQEZ[YGAG@BUPSC\ZG]NCCKTCZT]]NCCKYZQVXXMSXXCV\TD\ [VVYGG@XXQTZTGTUXUECF\UFYYRW[A@BNU XNE\FX[DZ[YGAG@BUX
W_A@GQS_Z[YGAG@BUXUC Z[YGAG@BU XUCED]NCCK]VOPZSDXFJQU XVVYGG@XYZM^RACVASUCVVYGG@XBQUZP]]UK _ZCCMRQW[A@BNVT Z[YGAG@BVXXVC\ZY YVZ[YGAG@BVZRYPMGWWGKUCCCMRX[C ]]NCCK_YOPVAIVVYGG@ [F] YV[MP]
DVYW[A@BNVGDPK@[
RVGW[A@BNVGDPKC]TZTGWLXX @EZVRG
DVVYGG@[AZU@TKQ]NCCK UYAKUXT^TCGGAG@BWX ^PPMUCU\CGVU]WQV^[]Z[MSXX CTYPW_S_PTM]NCCK \^VR@F [^[^]_NCCK \^XXLV [DZ[YGAG@BWX
[F@ZWK _ZCCMSZFZ BNCCWQ@GAG@BW[D V\UWUTZTGVVZ@ EVYJQU XVVYGG@ZFUQTZTGV@P[
TZTGQXG\BVVYGG@ ]U@DXGT VBNCDRTUZUEZ[YGAG @BP]EG W[A@BN P
Q^[] _\@IW
BNC QCPJW
BNC @ZZ[YGAG@BQNHUVGZ\]TZTGSPZPHE^VRW
BNC
^SZU[SMSXXCQ@WCQBXQLW@MSXXCPTM[FK _ZCCMWVAVFUUEAPG]YYSVFYYX[WQ@B\Z[YGAG@BSUBTZKD[D^ZWW
BNCD@PX@\ SVFMW
BNC
WVA\W\VCBXFQK _ZCCMWX[WUG BT]W[A@BNS^SFMFQ YYA\FUYAPW[A@BNSQ DLZ[CK _ZCCMXXA[UFK _ZCCMYYV[_TZTG\\DXYYZ[YGAG@B ]S ^RAW[A@BN][RLN[FTZTG\^ZDQDPJW
BNCRBXW[A@BN]UE[\@
D^XPNQMSXXC^EPZGXCZ[YGAG@B]DC^RQ@DNCCK
GX[W[A@BN_QYZWW
BNC
^\FM[M
TZTGYV[_H_ST@W
BNC _\TQ]NCCK_X^YQTMSXXC[ZV_VVYGG@U[[Q]R W[A@BN X
TZTGYVDK _ZCCM\XC\@FV^VW[A@ BNXQDPXF WMSXXC ZPT[FUCPKW
BNCCDT^QVQSVXG@ YPMGXPZPD^Z[YGAG@B Y]CRAPZ@ QTAPBQK _ZCCM]XCPQGHDTZ[YGAG@ BYDVUVGZ \]NCCKCA\\C BNCCTKSQ
^PZ[YGAG@BYM^^V[A@^VVYGG@TMDEYPLD]NCCKIDPXFWMSXXCZLJQU XYZNW
BNCGRWJQU XVVYGG@WQ@\YZNW
BNCDGTU[RBDWQ@GAG@BZQU VGZ\G
DVVYGG@WQC^\[VCGK _ZCCM^^VMQWUCBVF_MSXX CYZD[TZTG[VD[M^RACY@RQFK _ZCCM_SLJGQ]VGRQ@WVVYGG@VRR SXXIUZ^VVYGG@VRR _GAPY]BVVYGG@VYQCRTKW\K _ZCCM_Z\ADDRWQ@GAG@ BDUN@RGGQS_Z[YGAG@BDUUEGXZ_WVVYGG@IXAC^[WUTZTGEKQWYX[@]TZTGEK]W QYQP@]NCCKBXF\UFYYRW[A@BNECRTKW\K _ZCCMBRFLX@QDA\F]NCCKWDZQA@BNF [\@GG@K []IVVY GG@KGD QEVQW
BNCRAVGF[BFK _ZCCMCRTKW\WS VVYGG@JQU XVFJ]G^CWQ@GAG@BGQS_ PAQ]NCCKUVGZ\GECZ[YGAG@BGQS_B\VK _ZCCMC^XPXUYYRUQGK _ZCCMCGTNZQMSXXCDEPPQQ^AW[A@BNGGVG \\Q YPMGFIMCUY@RQFK _ZCCMCECWDMSXXCDAVD@BEUPN^XBW[A@BN@_ VVYGG@M R] MSXXCCRZGQS_Z[YGAG@B@\[^[^YQ
Q[\@GG@M[D [DZ[YGAG@B@[\APU[WIVVYGG@MDGTSZKSGG @MFQ\BP W[A@BN @YYMQWM SXXCB[P@QUYQPZSKUCCCMF^GM AYTXZ[YG AG@BBLWMS TCCMGRT M\QSXE\ W
BNCRDPZAF \RGMW
BNCUY@W[A@BNC^BZ[YKTPP JA]YPMGBQQZUVGZ\]NCCKXR[LG\
TZTGBVFXN@XGMUXK _ZCCMIXZ^QQK _ZCCMJRFMMRTVVYGG@CGQS_AV[XB VVYGG@ ]C
TZTGU[DK _ZCCQUGVCG DXZUVUMSXXC\X[
EGZ[YGAHVQJ[UEZI@]
JRGW[AOT]G[KVQPK[D
]^O\F]AUPXS_QF
D^XPNQMSXXLHZ_RQ@C\T]N TZTCVU]YRBVRG]AVGK _T^MU] QD]W[AO\TUS XS_QF
D^XPNQMSXXL@^A\F]AX]XS_QF
D^XPNQMSXXLCQMSXXLCRTKW\KQ[T WWQKQCZK W
MTXG BT]SUBVVYGQ_ZVRQVVYG_X R\Q]CVZCCL_]ZMSXXNSBQQZMSXXNQEVQ@[
RVGW[AJH96594uH
r7594uH
r7594}m`d_LXWXXPQZWQ@JY|`13
VVU ENTTZ 6594t]c0759475944ec0
" " «b Íc ác ác ác 4 d d d d !d Ï694ÄdŠ8¨²v4ec0V/Pv4ec0[
WYwUBQC\VZq_EUWa7/cL
K[]L\@AJGLXQMJN
X]PXGDGCME@UQGKBRR\LDGMLJ@V JRiW[eHCJF@\FMGSOo;EmHWRMINDPXFW?TZTIOKlIE^KlkiAG\SQBUVUVGZ\hK _ZH9\L@QCKXM 8nhILKBRR\LDGMLT[[A?TZTIOKlI@ ]DBojC>JF UOE\[AQQC lVVYIKIk
EMLF@\FML^KlkiAG\SQBUXF^FMUhK _ZH9\LEHQKTHDH_BojC>JF UOEUkXX@YDAXh]JhZHHULVDIHU
Nbj8HMFQHGODVCPG@?TZeAeHCJFIXEUAGIXE[L^KlkiAG\SQBUY_YiW[eHMELMUUF\UFleR\SRQMBSF H@PTNbj8HMFQHGOQMZWhMhKKLKGRWJQU Xkh
U[Q_Q_EQJ FSBojC>JF UOE]VOVZhKBJhZILJ@P[GQS_ihZYRY]_ GXG]GXQOo;EmHWRMINQZTC[Z9MSXiA_M
TDHVLngiNKQS @OUG_ZeW
MhEDKMHoFIXGk AKTJk[\VFMZU
Nbj8HMFQHGO\kZ[YMiHLKABPKMHoFIXGk AKTJk[JLngiNKQS @OU
lQ\IOKlIEXkidIGJEP^QLANX[X9MVEH9\LEHUELEUD<DRGTGXkidIGJEP^QLANX[X9MSXiA_MiHLKAKDLQFQGFf@QCBojC>JF UOEBPZJhl@RIOKlIG BT]MQFLngiNKQS @OUZRPOQG9MSXXDM?KULFOo;EmHWRMINQD^SQQCkZ[hK
Nbj8HMFQHGO_ZOeW
MhEDEE 8nhILKBRR\LDGMLTM@hKUC
MhEF@\FMXkidIGJEP^QLAN[AM9MSXXDM?KEAXkidIGJEP^QLANZ]FYCVP@M9MSXXDM?KGQS_BojC>JF UOE ^RAeW
MhEFBojC>JF UOE ^YiW[eHCJABPKM 8nhILKBRR\LDGMLVVYQI
MhE\P@C[LngiNKQS @OW
@BF\FB ?TZTIOKlIEBNBojC>JF UOE BV\^GXDkVFSMiHLERG@ O>=jDMUPPADKHKTCJh]JhZDLQF^KlkiAG\SQBPQD^X\h]JhZ^\MC
T
Nbj8HMFQHGO
^XVZXUk]QIKIk
EMERG@HCABojC>JF UOEYEPZ@\lVVYIKIk
EI
Nbj8HMFQHGO_Mi[FeHCJCRTKW\XkidIGJEP^QLAN][S
\RiW[eHCJFIH_CL^KlkiAG\SQBP[EGiW[eHCJ[
Nbj8HMFQHGOEPFM[F ?TZTIOKlIG BT]Oo;EmHWRMINUVGM\X[kWQ@MiHLLngiNKQS @OQIkZ[YMiHLKCX\WWXU@ZKPGQC\M
^TYLPQBSFEGU
D[P @QK9\KlkiAG\SQBQVlVVhMhEFV]ZESPN[FLDTM]@ LF@\FMW?Wh8nhILKBRR\LDGMLPWS]iW[eHCJA
Nbj8HMFQHGO YY\VZG9MSXXDM?KGQS_jJ@FW
Nbj8HMFQHGO S^A\h]JhZH_C
Nbj8HMFQHGO
^STK@]UDiW[eHCJ[RLOo;EmHWRMINV^[]]U9M^RADM?KEA I
Nbj8HMFQHGO
BRWXXX9MTRH9\LH O>=jDMUPPADKHKQG\QRTkZ[YMiHLERG@ O>=jDMUPPADKHKQG\QG FRiW[eHCJA
Nbj8HMFQHGODXGeW
M9\L^@kI@ZKPGXJLRLO^NLkidIGJEP^QLAN^]@
?TZTIOKlIEBNBojC>JF UOE_TYPW_9MSXXDM?KGQS_BojC>JF UOE__\Ih]JhZFZ O>=jDMUPPADKHK_TURhKRVLeW
MhE\P@C[LngiNKQS @O\lVVYIKIk
ED
Nbj8HMFQHGOVXFIUW ?TZTIOKlIGKDWHEJLngiNKQS @O]
\[T^QhK _ZH9\LHFMXkidIGJEP^QLANPC[?TZTIOKlIG BT]_[FXkidIGJEP^QLANPLE
S\iW[eHCJABPKM 8nhILKBRR\LDGML_ZDQUNiW[eHCJCRTKW\B^[^ O>=jDMUPPADKHK\TW[[UkZ[YM
?TZeAeHCJC^A\GQS_DLQF^KlkiAG\SQB_XD@Z\Q?SPDM?KEA I
Nbj8HMFQHGO
^\OeW
MhECPKY 8nhILKBRR\LDGMLYV[_Q
MhE\P@ O>=jDMUPPADKHK[ZV_GBCiW[9M
E^KlkiAG\SQBXMCkZ[YMiHLKABPKMHAKRMk_ GXG]GXkidIGJEP^QLANUMW
lQ\IOKlIUELEDGJLngiNKQS @OX _DiW[9ME\H9\LEA IKEJPXkidIGJEP^QLANTUYlVVYIKIk
EUELOo;EmHWRMIN]VFMQF9MSXXDM?KE 8nhILKBRR\LDGMLX\SUlVVYIKIlNbj8HMFQHGOWVB\VhK _ZHhZkidIGJEP^QLANTQFZP]W[9MSXXDM?KGQS_A\L@XkidIGJEP^QLANTQ@ BVBUQF9MSXXDM?KE 8nhILKBRR\LDGMLXVZP
UVGZ\hK _ZH9\LHAQLngiNKQS @OY
CCPKh]JhZDOo;EmHWRMIN]D[eW
MhEFBojC>JF UOECYiPQMiHLLngiNKQS @OYlPJIOKlIEXkidIGJEP^QLANTGZ9MCRH9\LH O>=jDMUPPADKHKZFWhl@RIOKlIEXkidIGJEP^QLAN^h^kZ[YL BFQDTSihMJF UOEUVGZ\hKCYiW[EPJAXoC>A
Nbj8HMFQHGOCRTKW\9MSXXDM?KG BT]_[FChDEUG:@FIXGk
Nbj8HMFQHGOC^XVZhK _ZH9\LEHL^[IA@I@ZKPXkidIGJEP^QLANWQ@ QGPeW
MhEF@\FMXkidIGJEP^QLANWQLWkZ[YMiHLUVGZ\ 8nhILKBRR\LDGML[VF@BY
EI@ZKPGXkidIGJEP^QLANIUS UR^\FhK _ZH9\LJQU X
Nbj8HMFQHGOYTP^FUUEiW[eHCJVXGTk_ GXG] O>=jDMUPPADKHKDPXFWRiW[eHCJABPKM 8nhILKBRR\LDGMLF\UF[^[^h]JhZ^\MC
T
Nbj8HMFQHGOQEVQFQ\CiZQeHCJCPKYHJLngiNKQS @OG
_BBXZZ?TZTIOKlIC
TDBojC>JF UOEET]\ZhK _ZH9\LH O>=jDMUPPADKHKD@IQFWRFeW
MhE[EWXkidIGJEP^QLANJAF UR^\FhK _ZH9\LJQU X
Nbj8HMFQHGOBPPMh]JhZSPQXKKPI@ZKPGXkidIGJEP^QLANMQWQER\@hK _ZH9\LHAQLngiNKQS @O@ ]ViW[eHCJkFAd O>=jDMUPPADKHKC\Z_QQDA\FhK _ZH9\LRQMBSBojC>JF UOEYDVXX]MhE\P@ O>=jDMUPPADKHKC\JWU
YCH9\LRQMXkidIGJEP^QLANM]G\^iW[9ME\H9\LHAQLngiNKQS @O@RXSPZP9MSXXDM?K@QC
Nbj8HMFQHGO
BP\U][9MYCH9\LHG 8nhILKBRR\LDGMLBXXYD
EMQKCIHB
@BojC>JF UOEUVGZ\XXZW[DPXFWMl
iDXkidIGJEP^QLANU[[?TZTIOKlIEXkidIGJEP^QLANQ[@DkZ[YMiHLERG@ O>=jDMUPPADKHKDPXFW?TZTIOKlIEXkidIGJEP^QLANVZQ _\iW[eHCJG
Nbj8HMFQHGOC^[\GG9MSXXDM?KEA I
Nbj8HMFQHGO^kZ[YMiHLDCBojC>JF UOEID\T[Z9MSXXDM?KE@XkidIGJEP^QLAN\D]
_YFeW
MhEDPXFW<CCGPZSXkidIGJEP^QLANJ\[UEJQU XkZZQ?TZTIOKlIEXkidIGJEP^QLANZ]@UVGZ\hK _ZH9\LN\QLngiNKQS @OZYX[XXhK YCLJQU XkZ[YMiHLERG@ O>=jDMUPPADKHKRCP@Q9MSXXDM?K_Q_EQJ O>=jDMUPPADKHKP\_@G9MSXXDM?KEA I
Nbj8HMFQHGOQGiW[eHCJABPKM 8nhILKBRR\LDGMLFZ]Fl
E^KlkiAG\SQBUX QkZ[YMiHLLngiNKQS @OV [RY\MhKTBH9\LRQMBSFOo;EmHWRMINWXZ^XQ9MSXXDM?KE 8nhIL_GAP[ZGZJ]@^EVDAAVVAZADFB^A@UAJHB_Q_EQJg BT]GAWXZ^XQGACRTKW\KQ
F\UFZFWW
BNC\DPXFWMSXXG BT]JW[TZT^XZ]XQK _ZGQS_\VUMSXXG BT]G@YTOW
PXFWM\NVVG]NCCKYEF\UFTZTG QEVQW
BNC QTAJQU X[\@GG@JX[ XVVYGG@JQQUR^W[A^
JQU XVVYGIDPXFWM]NBXM]NQVKC\Z[YGAG@BFQBR
^P][Y
^DEVZG
TZTGLV[S TZTFFKW\K _ZVXUQ\WP] WPTV NCCKUDA@R]TZTGENFG XVVYGG@JQU XVFJ]G^CWQ@GAG@BUXF^
XJLY MR[ZNGQS_Z[YGAG@BP[Y
^SZ[YGAG@BCQ BVBUZ BNCGRWJQU XVVYGG@_QUBRQFQ\C
^SZ[YGACRTKW\WRZWGUV
BNCKUR^W
BNC
]GYPW
@JGQS_Z[YGARRFMG BT]WWGACRTKW\TZT]V\W\[MSXXUCV]ZTZTG[\C@
C^A\G]JQU XVEAZTZTGF\UFBRFU@]NCCKRF\UFQDFPG@DVVYGG@JAFIDV
JNRQMBSFd[@vQJWAPZVSX ADPXFWMIV]V[]JQU XXJZ]NCCK_[F\UFTZTQEVQGW
DVVYGQYZVPX MSXXG BT]QVTZTQEVQ_G[XB]\UF[LZ[GK _ZCCMC^GJQU XVVYGG@UUVGZ\]NCCKHVVMGQS_WQ@GAG@
S_Z[YGAG@BGQ CRPRW
\JRDPXFWMSXXSM
DRZ[YGACRTKW\KDVGM]AMSX
^SAQQC C^A\M[URQW[A@BNRUR
@^Y\W
RU[VQ\WPQMSXXG BT]W[DDLJ@QTZTG\JQU XVVYGG@^Q@EYQW[A@BNC SETNXDNCCKI@P[GQS_Z[YGAG
XJTM]NF\UFTZTGBQMD TZTGWUUN YYQW[ADPXFWQPPWWGACR
^QZKYU
_YZ[YGA[STMG BT]YMIVVYGG@JQQMS
^PWQ@GAG@BUX
W_A@GQS_Z[YGACRTKW\KQE
TZTGMIGZK _ZGQS_WQ@ QGPW[A@BNYCQ\WP]NCCWMCRPR]NCCKYZEU]]LGG BT]W[AUPJ@QEVQWA
TZT@D []_VVYGG@WQC@D\MQGK _ZGQS_TIATVVYGG@JQU XEPJX@K _ZCCMJQU XVFJ]G^CZ[YGAG@BGAUN
W_AJQU XVVYG^P\WQDVVQUFTZTDPXFWAB\KQ]PYUCAKUR
SZEW[AMUPBAPKW
T]GKUAPWAQKUCUPK_B
S\WQ@GAQSF\FB D]XFQBRZWX]TZT^DWM_EZ[YGAGRWIPDKQCZKW
VVAZMUO\MQLQYR\W
WXZZ VVGTUVQOQF
C^[^W
FKUQAPW[AXTJW DETUF \ZP]]UK _ZUPMS[\Z_U^CFW[A@
BNC@BEIQFMSXXUMDET_R]@
T]GU[Z[YGA@XELD^
QVVYGTDJDQ
V^VI[DK _ZUYUTURA
_YZ[YGAZC]\PQ YYZ^@TM^RA] ZUGUZP]]UK _Z]GSVXGU ]RQPU]I[DCT]X
YTFW[A^F^ K QDTUQY YVZ[YGAYDR CVY\YQ
QVVYGTD]QU U[E\F]SYQ
QU@@ DWQ@GASQZ[ZKC[]NGAQS
BNCQQSPWQ\XG\F]PWWK
^CPUX]F[\@GUS\XRDT
TUYXG@ TZTG@QGFRGM]GWVVYGRVF\K _ZCCM^RMMUSK _ZCCMQSCW@TMSXXWQMJR
Z[^QGTJG@
CX[W[ABFFPKQ_ZVW
@JRTMIV]V[RMSXXFNTQ[[K _ZAGKLX\[
CVVYGG@DU_G@IW
QVCZ QSFUURCTG\QZFRGJW
BNCKQNEVDAMSXXG FRXXW QVVYGG@ZX_QMSXXC
EKQBGGZIG]I[DKYEVAW
BNCKUDT]BQYD\WS]JCDRGI[X TZTB\U@BU@^W
BNCC_ZV@QMSXXWK QDTUQY YVZ[YGAS CQP
MSXXCGT@D[@VVYG
]VR\G^M\W[AVQJCQSZVFQ
UVVYGS\PMR^OV^RGJP
C^CUGXBQDVVYG S[\Z_GYYRW^RYPMGIUM@BEW[ADE@FV^VTUFDG
_PWY YVZ^@TM^RAY YVXPF _[C\F]XPGK]Y\W[A_AMDUSRQ^QVVYGQY[\FGK_CP
_Y_LZW
_YZ[YGAEDXFPKQ_ZVW
_PYQT_MDNCCK\XB^[][UZBPZQNDET_R]MSXXUU
T]GOMYWM^RA[S
[X\W
BNCTXZKW
SXPQRXMX KQER\@Z TZTGPTUFDZTRQFMSXX
_I Z[YGAQSFF UY@\Z TC[[UVQJW
BNCQQSPW^APK@QMSXXRYAXFS ^RAW[AVQJPUTADF
YPLZQAVS_]XDR]@]BAZ[YGAVVQU[YLZBPPMZQMSXXW
S\U]ZIYPKSMK _ZCCMQSFKBQK _Z@FD@[X]VQPKW
\TUS MQCQT@]NCCK
^Q\W]@ NQSFW[A@BNVS[\AW
EXMD
EGZ[YGAS[\Z_]MWXWQ@K _ZCCMVQI[C TZT^[J]SUOEKQGMSXXU G[ D^ZWG]HB\[V^Y\u!0ozj`GUV
VKXB^FPSZK _ZUVMWTRUY
YPMU^U]V\ZQA~[
^QZJDUTZTR SQZTPZ [X[T]GBVI@RTZTWSWP
C^ZWU]BFW[A]T[ [\@GTCRTKW\K _ZuPK_BWUQW
S\WQ@GAqSF\FBK
^CPKZQERYW[Av^XDDKXR
tIDUY@W[AuTWGQ^[MQFDQ@\X]{]PDBQQZMSXXw
BVVZGBEZ[YGAtTYZ[FMBGAJZ qK_ SVYWFPK _Z|[SPZZUV YPM+DUGVUPCCZ[YGAcZT
CVVYG0@VEIC^BZ[YGAhO
^CPKZQMSXXUYAPUX DF\FB TZT D^C\YTZTT^VM]B UT]W[X
YRFZQAVQ]FQ]XP[_ZMVUMSXXU_GE\F
DUYXNQK _ZUPQEZ[YGAQSFUPQEZ[YGAQSFUP]^Z[YGAQSFWQBVYTQP@FU_ZMVUMSXXU^[MQFDZI@]
JRGW[AVQJ[UEZI@]
JRGW[AVQJBQTVUCPF@EYQVW
T]G KYEALYA_VVYGTDPKBKRVA\G]XP@ D^VJW
T]@F [RG TUUZ[YGAQSC\F@YYRXSQTZTUYAWRTZT _\PXPUMSXXUMYZR_UFMSXXU@
TUD\MCRTKW\C^FMUZM^
TIDUY@GD TRGXZ TJG]QYAWRTZTUY@\YQ
QVVYGIUU[DK _ZVMSXXVCXYV]QD
W\X@KRRAMQFDRGWQ@K _ZVQDPXFWCD\J@UYPMPTM[FK _ZVSWMWVAVF][]DXGW[AU\]@LMG_
WVA\W\VCBXFQK _ZV][ZIW
WPGT[ DZUA@^DZ[YGAR[@\\U^ZP]]UK _ZVF\^TW@PYCTUW
WK[CB@\JQ][AZU@TKQ]ZUDCPK]ZBYPMW
VWQBVYTQP@FWK_E[VSFXVVYG \N[ZK _ZW KQOF\FBWVVYG X@GQS_Z[YGASVQJ[XKYV
UD\@WK _ZWQBVYTQP@FWZLJQU XVVYG VPTMC CRTKW\K _ZW\ [^[WX [VYZ\QTZTBXXPAYKXR[LW
VS@KUCWX ^PPMUCU\CYT^R]^XBW[ATYPW_S_PTM]ZX]HU@Z_GK _ZWZM W
VWGY]Z[WQ^YZUGMSXXW
U\^ZDQDPJW
VVZRPGXZPBRPM]ZBVVM]B MSXXW
DR[MPXUTKW
VVZ@ EVYJQU XVVYG _EEWRTZTEGZWGDXGW[ATGG@
GZIADHTDW[CK _ZWFVVYG BXFJF[CG\_PQVVYG C]V@VTZTTL][[MSXXWCBX]ZHUT]W[AT@J@JRD
QX@U_EXV]ASPU@UKTEZXF]]]FKPW[AS\KQWMC^
^\X[
EGZ[YGATXBWX[]][C_VQUV DRGPZ@ ^RAW[ASZNZX
TWVZNMSXXP
^[ZXP\[PMDF
VDZ_@]][C_VQRQQYRW[ASZNZX
TRPSUS_FVR@BRZ[YGAT
TBQQZMSXXP
^[ZXPKRRAMQFDRGWQ@K _ZPMMF^GMAYTXZ[YGATN[XY]MXX
P_W_YZ[YGAUGFPX[MCRTKW\C^FMUZM^RAQBRFJRQVVYGJF\UFYYRW[AROLXUK _ZR]F@PW_K _ZR]_[Z^MY[\BQ_YPZQA
TZT_UTU@[
RVGW[APYVVU UUF\UFTZTQYQJ@F D^[MQF D^C\W
RJS_EZ[YGAWC^U@
TZT\GTMG BT]W[A_\MGQR@P[W
]VYQK
GX[W[A_ZMVUMSXX]H_X
BVVYG
UGYLS]MSXX]DYPMW
\TUS MY\TS]PYU^X^RUTZTQPPJV
J^Z[YGAYZT^QGKQCZKW
\TSVTZ[YGAYZRY QVVYG
]P[UZBDMZ\UUVVYG
]PU[DK _Z]YQEXW[A^XIFQYX
^CPKZQN_GAPY]BVVYG
@R[]PQDAVFYKYM]DC^RQ@]PF[MG_PWA]SUBQEZ^@TM^RA^C
BVVYG SSPZYW]ZU@]M^RA^U[TGK _[APPDSWP N^ZF^
D^QZQA]VTGTXZKW
_Z[Z^C[ZGTM^RA^GYYVUP SVS@KUC^Q^\P@W[\@G YTDW^RYPMYYQJQ@K ZCZQA]E\P[\XT]^
D^QW[A]EP[X T_MDSC] ]RQPU DWQ@GA[KYYFX[MSX
Y\UPKXR[LW
YPWQU]V@VTZT
CCFUPQEZ[YGA\XZR@
QNZ[YGA\XZRY MSXXX
TZTW^VWRTZTY[OLK STUDKQCZKW
XXF_KPW[AZTJ@QM]
XXLQTZTT^TUXUCZ[YGA]RQP
XPZPD^Z[YGA]XCPQGHD
XJB] TVYRTYPYUET^JW
XMK \^XXLV [DZ[YGA]NPC[MSXXYQY\ZVA_YZ[YGA]NF\UF^XBW[AZLNQVQEVQW
[\@D^XBW[AYPMDU VQPKGDWQ@QEVQG[TZTG[\@GYTA\W\D@ZK_GK _ZZ[@[\@GC\LD
DBFXW
[JVZCA Z]MGEDXXF_ YYRW[AXS_QF
D^XPNQMSXX[WVF\UFTZT
Y@IPUYPM
R^A\LD BRGW[AGTK@Z C]V@VTZTIGPK@QTZT X^O@FMF^GMAYTXZ[YGA@[@
ETU ^RAW[AGG\P]YAPJQU XVVYGB^V\VUYCZ[YGA@E\OUWMF^GMAYTXZ[YGA@E\CQY X^[\SUDPC[MSXXD]XF\[QEZ[YGA@EZJQU X^[^W
ELBDUTKW
DLQFMYYV[_TZTWDPKBQMWVAVF]KQD
DDQ[@BVVYGUGZK@GKVQPK[D
]^O\F]KQGDD]UGQEZ[YGABRF
GJDG BT]W[ADXVQUE\W@QUC
EGXPGK _ZGV
]JVBMSXXGYGAJQFB
FRTULK _ZGQS_^U@
TZTQEVQ] \BRPZ]JQU X\N[ZK _ZGQS_TMG BT]W[CK _ZGQS_AFQTRGW[ADPXFWQ^U[[@VVYGUVGZ\USTZTQEVQUG
CCTW@_YZ[YGACRTKW\C^FMUZM^
F\UFGRWW
F\Z@]X[]DC^RQ@DJQFB\I]Z
W_AZQAD]XZSYK _ZG]
\VGJ]ZUDZ[YGAC^[XRQ
RVGW[ADZXDUOTW[A
FIUCDVVYG@RP]VUM]NBXM]JDAY\OLK SJDC D_PKC^BZ[YGACGB\VUY@W[ADE@CUXRYIZ FHC]TZTG^G\]H_X^LD]JFWM\XEW[ADFSUBVVYGCUTZ_AMWVAVF]J@Y[YPUZYP\MUXK _ZG@YTRVVYGDXE
@^[J]SYPMUYVD]JAD GRWJQU XVVYGID@IPUPGXZPBRPM]ZBVVM]B MSXXGEGQX@QK
UGYLS]MSXX@_VVYGTZLW[A
^\\WSY YVWQ@GAD_\WG@\T[Q@B
DV[PAYKXR[LW
AV[XB\X[
EGZ[YGADXZUVUQ^U[[@VVYG_XYM]DMXXA
S\FW[ACZMUX\XVP@MK _Z@DCAVD]CVVYG@S
TAVD]CVVYG@EPI[FMD
AKUW
^PJD]BUTP@]MFUYYR@\TRG][C_VQJW
AKUR
S_Z^W
AKUZ D[]QBKHZWGBV[JW@ MFOWWGADE\Z_X MWVAVF]MGDYPMW
AJS_EZ[YGADDFUXUC
@IPUDAVD@BEUPN^XBW[ABE]U@ MD_@WPQ_@[U[UTZTTVA\GC\AVDYPMC[CVVYG@STMQGKUD^
CPDBZO\
RVGW[AA\IR]O\
RVGW[AA\IR]C\[Q
[DZ[YGAFZT]Y]MSXXB@RQUF_AP]W
CMFUA\K@A^SZW[A@TIRQV
TZTRBQQZMSXXC @]\ZAK@RP]QFM^RAC @SESUBVVYGV^MW[A@]\ZAHTA
^PPZR
MSXXC^BXPB D^FPZSK _ZC\ EEVDANQSFW[A@]\ZAK _ZC\ EDPXFWMSXXC^BFQ[DHTAPK
^PZQZQ[Z[YGAG_PWAG@EVDCVVYGXR[LG\
DEXWQK _ZC\ ED]VDUY@W[A@B] \BRPZ]NCK
UGYLS]MSXXC^PIXA
^VVYGGSPQD W^[W[A@BNUSTXJW
BNCVTZ[YGAG@BURWQ@GAG@BY QDPXFWMSXXC F\UFTZTGTXPW
TZTGT[Q@B^[MQFDVVYGG@XW@UTUQFNCRGOQFK _ZCCMQTAPBQHQOZ[YGAG@
UDWQ@GAG@BUPQEZ[YGAG@BUPSC\ZG]NCCKTCZT]]NCCKYZQVXXMSXXCV\TD\ [VVYGG@XXQTZTGTUXUECF\UFYYRW[A@BNU XNE\FX[DZ[YGAG@BUX
W_A@GQS_Z[YGAG@BUXUC
DVYW[A@BNVGDPK@[
RVGW[A@BNVGDPKC]TZTGWLXX @EZVRG
DVVYGG@[AZU@TKQ]NCCK UYAKUXT^TCGGAG@BWX ^PPMUCU\CGVU]WQV^[]Z[MSXX
[F@ZWK _ZCCMSZFZ BNCCWQ@GAG@BW[D
TZTGQXG\BVVYGG@
Q^[] _\@IW
BNC QCPJW
BNC @ZZ[YGAG@BQNHUVGZ\]TZTGSPZPHE^VRW
BNC
^SZU[SMSXXCQ@WCQBXQLW@MSXXCPTM[FK _ZCCMWVAVFUUEAPG]YYSVFYYX[WQ@B\Z[YGAG@BSUBTZKD[D^ZWW
BNCD@PX@\ SVFMW
BNC
WVA\W\VCBXFQK _ZCCMWX[WUG BT]W[A@BNS^SFMFQ YYA\FUYAPW[A@BNSQ
BNCRBXW[A@BN]UE[\@
D^XPNQMSXXC^EPZGXCZ[YGAG@B]DC^RQ@DNCCK
GX[W[A@BN_QYZWW
BNC
^\FM[M
TZTGYV[_H_ST@W
BNC _\TQ]NCCK_X^YQTMSXXC[ZV_VVYGG@U[[Q]R
TZTGYVDK _ZCCM\XC\@FV^VW[A@
BNCCDT^QVQSVXG@ YPMGXPZPD^Z[YGAG@B
^PZ[YGAG@BYM^^V[A@^VVYGG@TMDEYPLD]NCCKIDPXFWMSXXCZLJQU XYZNW
BNCGRWJQU XVVYGG@WQ@\YZNW
BNCDGTU[RBDWQ@GAG@BZQU
DVVYGG@WQC^\[VCGK _ZCCM^^VMQWUCBVF_MSXX
BNCRAVGF[BFK _ZCCMCRTKW\WS VVYGG@JQU XVFJ]G^CWQ@GAG@BGQS_
Q[\@GG@M[D [DZ[YGAG@B@[\APU[WIVVYGG@MDGTSZKSGG
BNCRDPZAF \RGMW
BNCUY@W[A@BNC^BZ[YKTPP
TZTGBVFXN@XGMUXK _ZCCMIXZ^QQK _ZCCMJRFMMRTVVYGG@CGQS_AV[XB
TZTGU[DK _ZCCQUGVCG DXZUVUMSXXC\X[
EGZ[YGAHVQJ[UEZI@]
JRGW[AOT]G[KVQPK[D
]^O\F]AUPXS_QF
D^XPNQMSXXLHZ_RQ@C\T]N TZTCVU]YRBVRG]AVGK _T^MU] QD]W[AO\TUS XS_QF
D^XPNQMSXXL@^A\F]AX]XS_QF
D^XPNQMSXXLCQMSXXLCRTKW\KQ[T
MTXG BT]SUBVVYGQ_ZVRQVVYG_X
RVGW[AJH96594uH
r7594uH
r7594}m`d_LXWXXPQZWQ@JY|`13
VVU ENTTZ 6594t]c0759475944ec0
ASKER
useful isn't it!!!!
Before we do anything else - do this:
From the l2mfix folder on your desktop,
double click l2mfix.bat and select option # 2 for "Run Fix" by typing 2 and then pressing enter,
then press any key to reboot your computer.
After a reboot, your desktop and icons will appear, then disappear (this is normal).
L2mfix will continue to scan your computer and when it's finished, notepad will open with a log.
The log should be in the same folder as l2mfix.
Copy the contents of that log and paste it back into this thread.
Then download and run TDS-3 Trojan Scan (free 30 day trial).
http://tds.diamondcs.com.au/
Update before you run it.
We'll see what it comes up with - make a note of all files it shows up as bad.
I hesitate to try and remove this manually -
I don't like the fact that it appears to have "winlogon" hooked.
RF
From the l2mfix folder on your desktop,
double click l2mfix.bat and select option # 2 for "Run Fix" by typing 2 and then pressing enter,
then press any key to reboot your computer.
After a reboot, your desktop and icons will appear, then disappear (this is normal).
L2mfix will continue to scan your computer and when it's finished, notepad will open with a log.
The log should be in the same folder as l2mfix.
Copy the contents of that log and paste it back into this thread.
Then download and run TDS-3 Trojan Scan (free 30 day trial).
http://tds.diamondcs.com.au/
Update before you run it.
We'll see what it comes up with - make a note of all files it shows up as bad.
I hesitate to try and remove this manually -
I don't like the fact that it appears to have "winlogon" hooked.
RF
ASKER
L2Mfix 1.03
Running From:
C:\Documents and Settings\2care\Desktop\l2m fix
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Wi ndows NT\CurrentVersion\Winlogon \Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access Everyone
(IO) ALLOW Full access Everyone
Setting registry permissions:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Denying C(CI) access for predefined group "Administrators"
- adding new ACCESS DENY entry
Registry Permissions set too:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Wi ndows NT\CurrentVersion\Winlogon \Notify:
(CI) DENY --C------- BUILTIN\Administrators
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access Everyone
(IO) ALLOW Full access Everyone
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Read BUILTIN\Power Users
(ID-IO) ALLOW Read BUILTIN\Power Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER
Setting up for Reboot
Starting Reboot!
C:\Documents and Settings\2care\Desktop\l2m fix
System Rebooted!
Running From:
C:\Documents and Settings\2care\Desktop\l2m fix
killing explorer and rundll32.exe
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic. org
Killing PID 1548 'explorer.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic. org
Error, Cannot find a process with an image name of rundll32.exe
Scanning First Pass. Please Wait!
First Pass Completed
Second Pass Scanning
Second pass Completed!
Zipping up files for submission:
adding: clear.reg (164 bytes security) (deflated 2%)
adding: echo.reg (164 bytes security) (deflated 9%)
adding: direct.txt (164 bytes security) (stored 0%)
adding: lo2.txt (164 bytes security) (deflated 71%)
adding: readme.txt (164 bytes security) (deflated 49%)
adding: test.txt (164 bytes security) (stored 0%)
adding: test2.txt (164 bytes security) (stored 0%)
adding: test3.txt (164 bytes security) (stored 0%)
adding: test5.txt (164 bytes security) (stored 0%)
adding: backregs/shell.reg (164 bytes security) (deflated 74%)
Restoring Registry Permissions:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Revoking access for predefined group "Administrators"
Warning (option /rga:(ci)) - There is no ACE to remove!
Registry permissions set too:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Wi ndows NT\CurrentVersion\Winlogon \Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access Everyone
(IO) ALLOW Full access Everyone
Restoring Sedebugprivilege:
Granting SeDebugPrivilege to Administrators ... successful
The following Is the Current Export of the Winlogon notify key:
************************** ********** ********** ********** ********** **********
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Softwa re\Microso ft\Windows NT\CurrentVersion\Winlogon \Notify]
[HKEY_LOCAL_MACHINE\Softwa re\Microso ft\Windows NT\CurrentVersion\Winlogon \Notify\cr ypt32chain ]
"Asynchronous"=dword:00000 000
"Impersonate"=dword:000000 00
"DllName"=hex(2):63,00,72, 00,79,00,7 0,00,74,00 ,33,00,32, 00,2e,00,6 4,00,6c,00 ,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEv ent"
[HKEY_LOCAL_MACHINE\Softwa re\Microso ft\Windows NT\CurrentVersion\Winlogon \Notify\cr yptnet]
"Asynchronous"=dword:00000 000
"Impersonate"=dword:000000 00
"DllName"=hex(2):63,00,72, 00,79,00,7 0,00,74,00 ,6e,00,65, 00,74,00,2 e,00,64,00 ,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogof fEvent"
[HKEY_LOCAL_MACHINE\Softwa re\Microso ft\Windows NT\CurrentVersion\Winlogon \Notify\cs cdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEven t"
"Logoff"="WinlogonLogoffEv ent"
"ScreenSaver"="WinlogonScr eenSaverEv ent"
"Startup"="WinlogonStartup Event"
"Shutdown"="WinlogonShutdo wnEvent"
"StartShell"="WinlogonStar tShellEven t"
"Impersonate"=dword:000000 00
"Asynchronous"=dword:00000 001
[HKEY_LOCAL_MACHINE\Softwa re\Microso ft\Windows NT\CurrentVersion\Winlogon \Notify\mf cdoc]
"Asynchronous"=dword:00000 001
"DllName"="C:\\WINDOWS\\re pair\\mfcd oc.dll"
"Impersonate"=dword:000000 00
"Startup"="SysLogon"
"Logoff"="SysLogoff"
[HKEY_LOCAL_MACHINE\Softwa re\Microso ft\Windows NT\CurrentVersion\Winlogon \Notify\Sc CertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertPro p"
"Logoff"="SCardStopCertPro p"
"Lock"="SCardSuspendCertPr op"
"Unlock"="SCardResumeCertP rop"
"Enabled"=dword:00000001
"Impersonate"=dword:000000 01
"Asynchronous"=dword:00000 001
[HKEY_LOCAL_MACHINE\Softwa re\Microso ft\Windows NT\CurrentVersion\Winlogon \Notify\Sc hedule]
"Asynchronous"=dword:00000 000
"DllName"=hex(2):77,00,6c, 00,6e,00,6 f,00,74,00 ,69,00,66, 00,79,00,2 e,00,64,00 ,\
6c,00,6c,00,00,00
"Impersonate"=dword:000000 00
"StartShell"="SchedStartSh ell"
"Logoff"="SchedEventLogOff "
[HKEY_LOCAL_MACHINE\Softwa re\Microso ft\Windows NT\CurrentVersion\Winlogon \Notify\sc lgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:000000 00
"Asynchronous"=dword:00000 001
"DllName"=hex(2):73,00,63, 00,6c,00,6 7,00,6e,00 ,74,00,66, 00,79,00,2 e,00,64,00 ,\
6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\Softwa re\Microso ft\Windows NT\CurrentVersion\Winlogon \Notify\Se nsLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensSt artScreenS averEvent"
"StopScreenSaver"="SensSto pScreenSav erEvent"
"Startup"="SensStartupEven t"
"Shutdown"="SensShutdownEv ent"
"StartShell"="SensStartShe llEvent"
"PostShell"="SensPostShell Event"
"Disconnect"="SensDisconne ctEvent"
"Reconnect"="SensReconnect Event"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:000000 01
"Asynchronous"=dword:00000 001
[HKEY_LOCAL_MACHINE\Softwa re\Microso ft\Windows NT\CurrentVersion\Winlogon \Notify\te rmsrv]
"Asynchronous"=dword:00000 000
"DllName"=hex(2):77,00,6c, 00,6e,00,6 f,00,74,00 ,69,00,66, 00,79,00,2 e,00,64,00 ,\
6c,00,6c,00,00,00
"Impersonate"=dword:000000 00
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostSh ell"
"Shutdown"="TSEventShutdow n"
"StartShell"="TSEventStart Shell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconn ect"
"Disconnect"="TSEventDisco nnect"
[HKEY_LOCAL_MACHINE\Softwa re\Microso ft\Windows NT\CurrentVersion\Winlogon \Notify\wl balloon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExp iredNotifi cationEven t"
"Logoff"="UnregisterTicket ExpiredNot ificationE vent"
"Impersonate"=dword:000000 01
"Asynchronous"=dword:00000 001
The following are the files found:
************************** ********** ********** ********** ********** **********
Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
************************** ********** ********** ********** ********** **********
REGEDIT4
[HKEY_LOCAL_MACHINE\Softwa re\Microso ft\Windows \CurrentVe rsion\Shel l Extensions\Approved]
REGEDIT4
[-HKEY_LOCAL_MACHINE\SOFTW ARE\Micros oft\Window s\CurrentV ersion\Int ernet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWA RE\Microso ft\Windows \CurrentVe rsion\Inte rnet Settings\User Agent\Post Platform]
"SV1"=""
************************** ********** ********** ********** ********** **********
Desktop.ini Contents:
************************** ********** ********** ********** ********** **********
************************** ********** ********** ********** ********** **********
Running From:
C:\Documents and Settings\2care\Desktop\l2m
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Wi
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access Everyone
(IO) ALLOW Full access Everyone
Setting registry permissions:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Denying C(CI) access for predefined group "Administrators"
- adding new ACCESS DENY entry
Registry Permissions set too:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Wi
(CI) DENY --C------- BUILTIN\Administrators
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access Everyone
(IO) ALLOW Full access Everyone
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Read BUILTIN\Power Users
(ID-IO) ALLOW Read BUILTIN\Power Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER
Setting up for Reboot
Starting Reboot!
C:\Documents and Settings\2care\Desktop\l2m
System Rebooted!
Running From:
C:\Documents and Settings\2care\Desktop\l2m
killing explorer and rundll32.exe
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.
Killing PID 1548 'explorer.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.
Error, Cannot find a process with an image name of rundll32.exe
Scanning First Pass. Please Wait!
First Pass Completed
Second Pass Scanning
Second pass Completed!
Zipping up files for submission:
adding: clear.reg (164 bytes security) (deflated 2%)
adding: echo.reg (164 bytes security) (deflated 9%)
adding: direct.txt (164 bytes security) (stored 0%)
adding: lo2.txt (164 bytes security) (deflated 71%)
adding: readme.txt (164 bytes security) (deflated 49%)
adding: test.txt (164 bytes security) (stored 0%)
adding: test2.txt (164 bytes security) (stored 0%)
adding: test3.txt (164 bytes security) (stored 0%)
adding: test5.txt (164 bytes security) (stored 0%)
adding: backregs/shell.reg (164 bytes security) (deflated 74%)
Restoring Registry Permissions:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Revoking access for predefined group "Administrators"
Warning (option /rga:(ci)) - There is no ACE to remove!
Registry permissions set too:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Wi
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access Everyone
(IO) ALLOW Full access Everyone
Restoring Sedebugprivilege:
Granting SeDebugPrivilege to Administrators ... successful
The following Is the Current Export of the Winlogon notify key:
**************************
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Softwa
[HKEY_LOCAL_MACHINE\Softwa
"Asynchronous"=dword:00000
"Impersonate"=dword:000000
"DllName"=hex(2):63,00,72,
6c,00,00,00
"Logoff"="ChainWlxLogoffEv
[HKEY_LOCAL_MACHINE\Softwa
"Asynchronous"=dword:00000
"Impersonate"=dword:000000
"DllName"=hex(2):63,00,72,
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogof
[HKEY_LOCAL_MACHINE\Softwa
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEven
"Logoff"="WinlogonLogoffEv
"ScreenSaver"="WinlogonScr
"Startup"="WinlogonStartup
"Shutdown"="WinlogonShutdo
"StartShell"="WinlogonStar
"Impersonate"=dword:000000
"Asynchronous"=dword:00000
[HKEY_LOCAL_MACHINE\Softwa
"Asynchronous"=dword:00000
"DllName"="C:\\WINDOWS\\re
"Impersonate"=dword:000000
"Startup"="SysLogon"
"Logoff"="SysLogoff"
[HKEY_LOCAL_MACHINE\Softwa
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertPro
"Logoff"="SCardStopCertPro
"Lock"="SCardSuspendCertPr
"Unlock"="SCardResumeCertP
"Enabled"=dword:00000001
"Impersonate"=dword:000000
"Asynchronous"=dword:00000
[HKEY_LOCAL_MACHINE\Softwa
"Asynchronous"=dword:00000
"DllName"=hex(2):77,00,6c,
6c,00,6c,00,00,00
"Impersonate"=dword:000000
"StartShell"="SchedStartSh
"Logoff"="SchedEventLogOff
[HKEY_LOCAL_MACHINE\Softwa
"Logoff"="WLEventLogoff"
"Impersonate"=dword:000000
"Asynchronous"=dword:00000
"DllName"=hex(2):73,00,63,
6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\Softwa
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensSt
"StopScreenSaver"="SensSto
"Startup"="SensStartupEven
"Shutdown"="SensShutdownEv
"StartShell"="SensStartShe
"PostShell"="SensPostShell
"Disconnect"="SensDisconne
"Reconnect"="SensReconnect
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:000000
"Asynchronous"=dword:00000
[HKEY_LOCAL_MACHINE\Softwa
"Asynchronous"=dword:00000
"DllName"=hex(2):77,00,6c,
6c,00,6c,00,00,00
"Impersonate"=dword:000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostSh
"Shutdown"="TSEventShutdow
"StartShell"="TSEventStart
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconn
"Disconnect"="TSEventDisco
[HKEY_LOCAL_MACHINE\Softwa
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExp
"Logoff"="UnregisterTicket
"Impersonate"=dword:000000
"Asynchronous"=dword:00000
The following are the files found:
**************************
Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
**************************
REGEDIT4
[HKEY_LOCAL_MACHINE\Softwa
REGEDIT4
[-HKEY_LOCAL_MACHINE\SOFTW
[HKEY_LOCAL_MACHINE\SOFTWA
"SV1"=""
**************************
Desktop.ini Contents:
**************************
**************************
Hi!
Did you try running TDS-3?
What were it's results?
RF
Did you try running TDS-3?
What were it's results?
RF
ASKER
What if i boot into safe mode and remove mfcdoc.dll? is it a important file?
Here's info on how to use TDS-3:
http://tds.diamondcs.com.au/index.php?page=easytouse
And, here's how to update it if you are not registered (trial version users):
http://tds.diamondcs.com.au/index.php?page=update
http://tds.diamondcs.com.au/index.php?page=easytouse
And, here's how to update it if you are not registered (trial version users):
http://tds.diamondcs.com.au/index.php?page=update
ASKER
ok i updated TDS did a full system scan found about +-15 alarms, deleted 3 definite problems the rest were all possible problems, none of them seemed related to the winlogon
or mfcdoc.dll or troj_agent.fz
or mfcdoc.dll or troj_agent.fz
Well, that mfcdoc.dll file does not appear to be a valid Windows file.
Yes, you could try going into "Safe" mode and delete it -
or use Killbox in safe mode to get rid of it.
RF
Yes, you could try going into "Safe" mode and delete it -
or use Killbox in safe mode to get rid of it.
RF
XP Home - Pro - Win 2000 - 98 - ME
RF