OK, everything on your list was done or attempted. A few things I need to pass on.
1. The 3 files listed above that you wanted me to kill with the kill box still didn't exist. I ran a manual search and everything and just couldn't find any of them.
2. When I went to safe mode to run HJT the 020 - winlogon notify line was not listed.
3. There was nothing listed after the 127.0.0.1 localhost in the drivers/etc file.
4. MS Antispyware is reporting the following:
VX2.BETTERNET
BROADCASTPC ADWARE
POSSIBLE HOSTS FILE HIHACK
TRANSPONDER.ABETTERINTERNET
ISEARCH.DESKTOPSEARCH
5. Spybot reports the following:
Common Hijacker
IGETNET
I have tried several times to delete them and they either keep coming back or can't be deleted at all. I thought I would pass this on in the hopes that it might help. I didn't try to delete this time since I thought it might delete files that you would need to know about.
Your requested logs follow:
Logfile of HijackThis v1.99.1
Scan saved at 10:21:31 PM, on 3/18/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\Program Files\Microsoft SQL Server\MSSQL$SOSHOME\Binn\sqlservr.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\System32\hphmon04.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
C:\Program Files\Trend Micro\Internet Security\pccguide.exe
C:\Program Files\Trend Micro\Internet Security\PCClient.exe
C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\APC\APC PowerChute Personal Edition\systray.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Trend Micro\Internet Security\Tmntsrv.exe
C:\Program Files\Trend Micro\Internet Security\tmproxy.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Trend Micro\Internet Security\PccPfw.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [hpinstantsupport] "C:\Program Files\Hewlett-Packard\HP Instant Support DI\bin\matcliwrapper.exe" "C:\Program Files\Hewlett-Packard\HP Instant Support DI\" -boot
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security\pccguide.exe"
O4 - HKLM\..\Run: [PCClient.exe] "C:\Program Files\Trend Micro\Internet Security\PCClient.exe"
O4 - HKLM\..\Run: [TM Outbreak Agent] "C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe" /run
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: ePrompter (2).lnk = C:\Program Files\ePrompter\ephtml.exe
O4 - Startup: ePrompter.lnk = C:\Program Files\ePrompter\ephtml.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Blackjack -
http://download.games.yahoo.com/game...ts/y/jt0_x.cab
O16 - DPF: Yahoo! Chat -
http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab
O16 - DPF: Yahoo! Hearts -
http://download.games.yahoo.com/game...ts/y/ht0_x.cab
O16 - DPF: Yahoo! Pinochle -
http://download.games.yahoo.com/game...ts/y/ut2_x.cab
O16 - DPF: Yahoo! Poker -
http://download.games.yahoo.com/game...ts/y/pt0_x.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) -
http://support.dell.com/us/en/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?link...38&clcid=0x409
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.co...?1093350161718
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Trend Micro Personal Firewall (PccPfw) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Internet Security\PccPfw.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Internet Security\Tmntsrv.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Internet Security\tmproxy.exe
Here's the DLL compare log:
* DLLCompare Log version(1.0.0.125)
Files Found that Windows does not See or cannot Access
*Not everything listed here means you are infected!
________________________________________________
C:\WINDOWS\SYSTEM32\dn6401~1.dll Thu Mar 17 2005 9:30:14a ..S.R 235,592 230.07 K
C:\WINDOWS\SYSTEM32\dnkquota.dll Fri Mar 18 2005 8:37:32a ..S.R 233,246 227.78 K
C:\WINDOWS\SYSTEM32\en4ql1~1.dll Thu Mar 17 2005 7:27:32p ..S.R 232,994 227.53 K
C:\WINDOWS\SYSTEM32\en6ol1~1.dll Thu Mar 17 2005 5:58:32p ..S.R 232,904 227.45 K
C:\WINDOWS\SYSTEM32\enj0l1~1.dll Fri Mar 18 2005 9:48:44a ..S.R 234,185 228.70 K
C:\WINDOWS\SYSTEM32\fp0m03~1.dll Thu Mar 17 2005 6:58:48p ..S.R 236,186 230.65 K
C:\WINDOWS\SYSTEM32\h2l20c~1.dll Thu Mar 17 2005 1:27:38p ..S.R 235,824 230.30 K
C:\WINDOWS\SYSTEM32\jtr607~1.dll Thu Mar 17 2005 5:52:10p ..S.R 232,572 227.12 K
C:\WINDOWS\SYSTEM32\kt22l7~1.dll Fri Mar 18 2005 7:55:18a ..S.R 234,374 228.88 K
C:\WINDOWS\SYSTEM32\mnltus40.dll Fri Mar 18 2005 1:37:42p ..S.R 233,700 228.22 K
C:\WINDOWS\SYSTEM32\mv22l9~1.dll Thu Mar 17 2005 5:16:54p ..S.R 232,838 227.38 K
C:\WINDOWS\SYSTEM32\mv8ql9~1.dll Fri Mar 18 2005 9:54:46a ..S.R 234,763 229.26 K
C:\WINDOWS\SYSTEM32\mvnql9~1.dll Thu Mar 17 2005 5:45:16p ..S.R 233,003 227.54 K
C:\WINDOWS\SYSTEM32\n.dll Wed Mar 16 2005 6:19:58p A..H. 106 0.10 K
C:\WINDOWS\SYSTEM32\o2840c~1.dll Thu Mar 17 2005 10:30:16a ..S.R 236,074 230.54 K
C:\WINDOWS\SYSTEM32\wwnscard.dll Fri Mar 18 2005 10:00:48a ..S.R 233,174 227.71 K
________________________________________________
1,469 items found: 1,469 files (16 H/S), 0 directories.
Total of file sizes: 301,550,200 bytes 287.58 M
Administrator Account = True
--------------------End log---------------------
Here's the find it log:
Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.
Find.bat is running from: C:\8250fix\Find It NT-2K-XP
------- System Files in System32 Directory -------
Volume in drive C has no label.
Volume Serial Number is C401-F0D6
Directory of C:\WINDOWS\System32
03/18/2005 01:37 PM 233,700 mnltus40.dll
03/18/2005 10:00 AM 233,174 wwnscard.dll
03/18/2005 09:54 AM 234,763 mv8ql9l51.dll
03/18/2005 09:48 AM 234,185 enj0l11m1.dll
03/18/2005 08:37 AM 233,246 dnkquota.dll
03/18/2005 07:55 AM 234,374 kt22l7fo1.dll
03/17/2005 07:27 PM 232,994 en4ql1h51.dll
03/17/2005 06:58 PM 236,186 fp0m03d1e.dll
03/17/2005 05:58 PM 232,904 en6ol1j31.dll
03/17/2005 05:52 PM 232,572 jtr6079se.dll
03/17/2005 05:45 PM 233,003 mvnql9551.dll
03/17/2005 05:16 PM 232,838 mv22l9fo1.dll
03/17/2005 01:27 PM 235,824 h2l20c3oef.dll
03/17/2005 10:30 AM 236,074 o2840clqefqe0.dll
03/17/2005 09:30 AM 235,592 dn6401jqe.dll
02/20/2005 07:23 PM <DIR> DLLCACHE
12/14/2002 07:23 PM <DIR> Microsoft
15 File(s) 3,511,429 bytes
2 Dir(s) 104,929,488,896 bytes free
------- Hidden Files in System32 Directory -------
Volume in drive C has no label.
Volume Serial Number is C401-F0D6
Directory of C:\WINDOWS\System32
03/17/2005 06:43 PM <DIR> vmss
03/16/2005 06:19 PM 106 n.dll
02/20/2005 07:23 PM <DIR> DLLCACHE
09/09/2004 09:06 AM 488 WindowsLogon.manifest
09/09/2004 09:06 AM 488 logonui.exe.manifest
09/09/2004 09:06 AM 749 ncpa.cpl.manifest
09/09/2004 09:06 AM 749 nwc.cpl.manifest
09/09/2004 09:06 AM 749 sapi.cpl.manifest
09/09/2004 09:06 AM 749 wuaucpl.cpl.manifest
09/09/2004 09:06 AM 749 cdplayer.exe.manifest
04/18/2004 11:05 AM 296,859 log.bak.txt
04/18/2004 11:05 AM 5,661 log0.txt
04/18/2004 11:05 AM 27,553 fiz0
04/18/2004 11:05 AM 10,285 log1.txt
04/18/2004 11:04 AM 10,347 log2.txt
04/18/2004 11:04 AM 10,344 log3.txt
04/18/2004 11:04 AM 10,250 log4.txt
15 File(s) 376,126 bytes
2 Dir(s) 104,929,484,800 bytes free
------------ Files Named "Guard" ---------------
Volume in drive C has no label.
Volume Serial Number is C401-F0D6
Directory of C:\WINDOWS\System32
------ Temp Files in System32 Directory ------
Volume in drive C has no label.
Volume Serial Number is C401-F0D6
Directory of C:\WINDOWS\System32
10/02/2002 03:11 PM 180,800 sqlunirl.dll.tmp
08/29/2002 06:00 AM 2,577 CONFIG.TMP
2 File(s) 183,377 bytes
0 Dir(s) 104,929,484,800 bytes free
------------------ User Agent ----------------
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{D8F4AE3D-68D5-2585-F277-7270ABDD7176}"=""
------------- Keys Under Notify -------------
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
"Asynchronous"=dword:00000000
"DllName"=""
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
------------- Locate.com Results -------------
C:\WINDOWS\SYSTEM32\
dn6401~1.dll Thu Mar 17 2005 9:30:14a ..S.R 235,592 230.07 K
dnkquota.dll Fri Mar 18 2005 8:37:32a ..S.R 233,246 227.78 K
en4ql1~1.dll Thu Mar 17 2005 7:27:32p ..S.R 232,994 227.53 K
en6ol1~1.dll Thu Mar 17 2005 5:58:32p ..S.R 232,904 227.45 K
enj0l1~1.dll Fri Mar 18 2005 9:48:44a ..S.R 234,185 228.70 K
fp0m03~1.dll Thu Mar 17 2005 6:58:48p ..S.R 236,186 230.65 K
h2l20c~1.dll Thu Mar 17 2005 1:27:38p ..S.R 235,824 230.30 K
jtr607~1.dll Thu Mar 17 2005 5:52:10p ..S.R 232,572 227.12 K
kt22l7~1.dll Fri Mar 18 2005 7:55:18a ..S.R 234,374 228.88 K
mnltus40.dll Fri Mar 18 2005 1:37:42p ..S.R 233,700 228.22 K
mv22l9~1.dll Thu Mar 17 2005 5:16:54p ..S.R 232,838 227.38 K
mv8ql9~1.dll Fri Mar 18 2005 9:54:46a ..S.R 234,763 229.26 K
mvnql9~1.dll Thu Mar 17 2005 5:45:16p ..S.R 233,003 227.54 K
n.dll Wed Mar 16 2005 6:19:58p A..H. 106 0.10 K
o2840c~1.dll Thu Mar 17 2005 10:30:16a ..S.R 236,074 230.54 K
wwnscard.dll Fri Mar 18 2005 10:00:48a ..S.R 233,174 227.71 K
16 items found: 16 files, 0 directories.
Total of file sizes: 3,511,535 bytes 3.35 M
-------- Strings.exe Qoologic Results --------
--------- Strings.exe Aspack Results ---------
C:\WINDOWS\SYSTEM32\ntdll.dll: .aspack
-------------- HKLM Run Key ----------------
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"zBrowser Launcher"="C:\\Program Files\\Logitech\\iTouch\\iTouch.exe"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"Microsoft Works Update Detection"="C:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\WkUFind.exe"
"HPHUPD04"="\"C:\\Program Files\\HP Photosmart 11\\hphinstall\\UniPatch\\hphupd04.exe\""
"HPHmon04"="C:\\WINDOWS\\System32\\hphmon04.exe"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb05.exe"
"EM_EXEC"="C:\\PROGRA~1\\MOUSEW~1\\SYSTEM\\EM_EXEC.EXE"
"DVDSentry"="C:\\WINDOWS\\System32\\DSentry.exe"
"diagent"="\"C:\\Program Files\\Creative\\SBLive\\Diagnostics\\diagent.exe\" startup"
"AdaptecDirectCD"="\"C:\\Program Files\\Roxio\\Easy CD Creator 5\\DirectCD\\DirectCD.exe\""
"IMJPMIG8.1"="\"C:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE\" /Spoil /RemAdvDef /Migration32"
"MSPY2002"="C:\\WINDOWS\\System32\\IME\\PINTLGNT\\ImScInst.exe /SYNC"
"PHIME2002ASync"="C:\\WINDOWS\\System32\\IME\\TINTLGNT\\TINTSETP.EXE /SYNC"
"PHIME2002A"="C:\\WINDOWS\\System32\\IME\\TINTLGNT\\TINTSETP.EXE /IMEName"
"nwiz"="nwiz.exe /install"
"hpinstantsupport"="\"C:\\Program Files\\Hewlett-Packard\\HP Instant Support DI\\bin\\matcliwrapper.exe\" \"C:\\Program Files\\Hewlett-Packard\\HP Instant Support DI\\\" -boot"
"MediaFace Integration"="C:\\Program Files\\Fellowes\\MediaFACE 4.0\\SetHook.exe"
"pccguide.exe"="\"C:\\Program Files\\Trend Micro\\Internet Security\\pccguide.exe\""
"PCClient.exe"="\"C:\\Program Files\\Trend Micro\\Internet Security\\PCClient.exe\""
"TM Outbreak Agent"="\"C:\\Program Files\\Trend Micro\\Internet Security\\TMOAgent.exe\" /run"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"IMEKRMIG6.1"="C:\\WINDOWS\\ime\\imkr6_1\\IMEKRMIG.EXE"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"gcasServ"="\"C:\\Program Files\\Microsoft AntiSpyware\\gcasServ.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
Thanks again !!! I will keep this computer on all night to keep it from rebooting.