L2Mfix 1.02a
Running From:
C:\DOCUME~1\XPUSER\Desktop\l2mfix
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (
http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER
Setting registry permissions:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (
http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Denying C access for really "Everyone"
- adding new ACCESS DENY entry
Registry Permissions set too:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (
http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(CI) DENY –C——- Everyone
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER
Setting up for Reboot
Starting Reboot!
C:\Documents and Settings\XPUSER\Desktop\l2mfix
System Rebooted!
Running From:
C:\Documents and Settings\XPUSER\Desktop\l2mfix
killing explorer and rundll32.exe
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Killing PID 124 'explorer.exe'
Killing PID 124 'explorer.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Killing PID 492 'rundll32.exe'
Scanning First Pass. Please Wait!
First Pass Completed
Second Pass Scanning
Second pass Completed!
Backing Up: C:\WINDOWS\system32\AKIFIL32.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\CEBINET.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\dfvvox.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\DIWSOCK.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\DLSRSLVR.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\DYSERIAL.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\e020lafm1d2a.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\gfUnCompress.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\IELOGMSG.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\j00s0ad7ed0.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\jrj0251mg.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\k8no0i53e8.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\KJDFC.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\lhasrv.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\lvj4091qe.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\lvr4099qe.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\MYPISTUB.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\n0r2la9o1d.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\n4p40e7qeh.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\nlwrsja.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\UWRFAXA.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\VWAR332.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\WBVDMOE.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\guard.tmp
1 file(s) copied.
deleting: C:\WINDOWS\system32\AKIFIL32.DLL
Successfully Deleted: C:\WINDOWS\system32\AKIFIL32.DLL
deleting: C:\WINDOWS\system32\CEBINET.DLL
Successfully Deleted: C:\WINDOWS\system32\CEBINET.DLL
deleting: C:\WINDOWS\system32\dfvvox.dll
Successfully Deleted: C:\WINDOWS\system32\dfvvox.dll
deleting: C:\WINDOWS\system32\DIWSOCK.DLL
Successfully Deleted: C:\WINDOWS\system32\DIWSOCK.DLL
deleting: C:\WINDOWS\system32\DLSRSLVR.DLL
Successfully Deleted: C:\WINDOWS\system32\DLSRSLVR.DLL
deleting: C:\WINDOWS\system32\DYSERIAL.DLL
Successfully Deleted: C:\WINDOWS\system32\DYSERIAL.DLL
deleting: C:\WINDOWS\system32\e020lafm1d2a.dll
Successfully Deleted: C:\WINDOWS\system32\e020lafm1d2a.dll
deleting: C:\WINDOWS\system32\gfUnCompress.dll
Successfully Deleted: C:\WINDOWS\system32\gfUnCompress.dll
deleting: C:\WINDOWS\system32\IELOGMSG.DLL
Successfully Deleted: C:\WINDOWS\system32\IELOGMSG.DLL
deleting: C:\WINDOWS\system32\j00s0ad7ed0.dll
Successfully Deleted: C:\WINDOWS\system32\j00s0ad7ed0.dll
deleting: C:\WINDOWS\system32\jrj0251mg.dll
Successfully Deleted: C:\WINDOWS\system32\jrj0251mg.dll
deleting: C:\WINDOWS\system32\k8no0i53e8.dll
Successfully Deleted: C:\WINDOWS\system32\k8no0i53e8.dll
deleting: C:\WINDOWS\system32\KJDFC.DLL
Successfully Deleted: C:\WINDOWS\system32\KJDFC.DLL
deleting: C:\WINDOWS\system32\lhasrv.dll
Successfully Deleted: C:\WINDOWS\system32\lhasrv.dll
deleting: C:\WINDOWS\system32\lvj4091qe.dll
Successfully Deleted: C:\WINDOWS\system32\lvj4091qe.dll
deleting: C:\WINDOWS\system32\lvr4099qe.dll
Successfully Deleted: C:\WINDOWS\system32\lvr4099qe.dll
deleting: C:\WINDOWS\system32\MYPISTUB.DLL
Successfully Deleted: C:\WINDOWS\system32\MYPISTUB.DLL
deleting: C:\WINDOWS\system32\n0r2la9o1d.dll
Successfully Deleted: C:\WINDOWS\system32\n0r2la9o1d.dll
deleting: C:\WINDOWS\system32\n4p40e7qeh.dll
Successfully Deleted: C:\WINDOWS\system32\n4p40e7qeh.dll
deleting: C:\WINDOWS\system32\nlwrsja.dll
Successfully Deleted: C:\WINDOWS\system32\nlwrsja.dll
deleting: C:\WINDOWS\system32\UWRFAXA.DLL
Successfully Deleted: C:\WINDOWS\system32\UWRFAXA.DLL
deleting: C:\WINDOWS\system32\VWAR332.DLL
Successfully Deleted: C:\WINDOWS\system32\VWAR332.DLL
deleting: C:\WINDOWS\system32\WBVDMOE.DLL
Successfully Deleted: C:\WINDOWS\system32\WBVDMOE.DLL
deleting: C:\WINDOWS\system32\guard.tmp
Successfully Deleted: C:\WINDOWS\system32\guard.tmp
Desktop.ini sucessfully removed
Zipping up files for submission:
adding: AKIFIL32.DLL (164 bytes security) (deflated 5%)
adding: CEBINET.DLL (164 bytes security) (deflated 5%)
adding: dfvvox.dll (164 bytes security) (deflated 5%)
adding: DIWSOCK.DLL (164 bytes security) (deflated 4%)
adding: DLSRSLVR.DLL (164 bytes security) (deflated 5%)
adding: DYSERIAL.DLL (164 bytes security) (deflated 5%)
adding: e020lafm1d2a.dll (164 bytes security) (deflated 3%)
adding: gfUnCompress.dll (164 bytes security) (deflated 4%)
adding: IELOGMSG.DLL (164 bytes security) (deflated 5%)
adding: j00s0ad7ed0.dll (164 bytes security) (deflated 5%)
adding: jrj0251mg.dll (164 bytes security) (deflated 4%)
adding: k8no0i53e8.dll (164 bytes security) (deflated 4%)
adding: KJDFC.DLL (164 bytes security) (deflated 4%)
adding: lhasrv.dll (164 bytes security) (deflated 5%)
adding: lvj4091qe.dll (164 bytes security) (deflated 4%)
adding: lvr4099qe.dll (164 bytes security) (deflated 4%)
adding: MYPISTUB.DLL (164 bytes security) (deflated 4%)
adding: n0r2la9o1d.dll (164 bytes security) (deflated 5%)
adding: n4p40e7qeh.dll (164 bytes security) (deflated 4%)
adding: nlwrsja.dll (164 bytes security) (deflated 4%)
adding: UWRFAXA.DLL (164 bytes security) (deflated 3%)
adding: VWAR332.DLL (164 bytes security) (deflated 3%)
adding: WBVDMOE.DLL (164 bytes security) (deflated 4%)
adding: guard.tmp (164 bytes security) (deflated 5%)
adding: clear.reg (164 bytes security) (deflated 46%)
adding: echo.reg (164 bytes security) (deflated 9%)
adding: desktop.ini (164 bytes security) (deflated 15%)
adding: direct.txt (164 bytes security) (stored 0%)
adding: lo2.txt (164 bytes security) (deflated 82%)
adding: readme.txt (164 bytes security) (deflated 49%)
adding: report.txt (164 bytes security) (deflated 66%)
adding: test.txt (164 bytes security) (deflated 77%)
adding: test2.txt (164 bytes security) (deflated 28%)
adding: test3.txt (164 bytes security) (deflated 28%)
adding: test5.txt (164 bytes security) (deflated 28%)
adding: xfind.txt (164 bytes security) (deflated 70%)
adding: backregs/44B77C4C-7754-4C25-9117-0B49EDE0FF54.reg (164 bytes security) (deflated 70%)
adding: backregs/F51207AF-2954-4E67-A66A-631D54783625.reg (164 bytes security) (deflated 70%)
adding: backregs/F92EE73C-5657-4095-8FD6-59780F4B8484.reg (164 bytes security) (deflated 70%)
adding: backregs/shell.reg (164 bytes security) (deflated 73%)
Restoring Registry Permissions:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (
http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Revoking access for really "Everyone"
Registry permissions set too:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (
http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER
Restoring Sedebugprivilege:
Granting SeDebugPrivilege to Administrators … successful
deleting local copy: AKIFIL32.DLL
deleting local copy: CEBINET.DLL
deleting local copy: dfvvox.dll
deleting local copy: DIWSOCK.DLL
deleting local copy: DLSRSLVR.DLL
deleting local copy: DYSERIAL.DLL
deleting local copy: e020lafm1d2a.dll
deleting local copy: gfUnCompress.dll
deleting local copy: IELOGMSG.DLL
deleting local copy: j00s0ad7ed0.dll
deleting local copy: jrj0251mg.dll
deleting local copy: k8no0i53e8.dll
deleting local copy: KJDFC.DLL
deleting local copy: lhasrv.dll
deleting local copy: lvj4091qe.dll
deleting local copy: lvr4099qe.dll
deleting local copy: MYPISTUB.DLL
deleting local copy: n0r2la9o1d.dll
deleting local copy: n4p40e7qeh.dll
deleting local copy: nlwrsja.dll
deleting local copy: UWRFAXA.DLL
deleting local copy: VWAR332.DLL
deleting local copy: WBVDMOE.DLL
deleting local copy: guard.tmp
The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
The following are the files found:
****************************************************************************
C:\WINDOWS\system32\AKIFIL32.DLL
C:\WINDOWS\system32\CEBINET.DLL
C:\WINDOWS\system32\dfvvox.dll
C:\WINDOWS\system32\DIWSOCK.DLL
C:\WINDOWS\system32\DLSRSLVR.DLL
C:\WINDOWS\system32\DYSERIAL.DLL
C:\WINDOWS\system32\e020lafm1d2a.dll
C:\WINDOWS\system32\gfUnCompress.dll
C:\WINDOWS\system32\IELOGMSG.DLL
C:\WINDOWS\system32\j00s0ad7ed0.dll
C:\WINDOWS\system32\jrj0251mg.dll
C:\WINDOWS\system32\k8no0i53e8.dll
C:\WINDOWS\system32\KJDFC.DLL
C:\WINDOWS\system32\lhasrv.dll
C:\WINDOWS\system32\lvj4091qe.dll
C:\WINDOWS\system32\lvr4099qe.dll
C:\WINDOWS\system32\MYPISTUB.DLL
C:\WINDOWS\system32\n0r2la9o1d.dll
C:\WINDOWS\system32\n4p40e7qeh.dll
C:\WINDOWS\system32\nlwrsja.dll
C:\WINDOWS\system32\UWRFAXA.DLL
C:\WINDOWS\system32\VWAR332.DLL
C:\WINDOWS\system32\WBVDMOE.DLL
C:\WINDOWS\system32\guard.tmp
Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{F51207AF-2954-4E67-A66A-631D54783625}"=-
"{44B77C4C-7754-4C25-9117-0B49EDE0FF54}"=-
"{F92EE73C-5657-4095-8FD6-59780F4B8484}"=-
[-HKEY_CLASSES_ROOT\CLSID\{F51207AF-2954-4E67-A66A-631D54783625}]
[-HKEY_CLASSES_ROOT\CLSID\{44B77C4C-7754-4C25-9117-0B49EDE0FF54}]
[-HKEY_CLASSES_ROOT\CLSID\{F92EE73C-5657-4095-8FD6-59780F4B8484}]
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{6AF961A4-5067-49F9-9569-2A2193731A86}"=-
****************************************************************************
Desktop.ini Contents:
****************************************************************************
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
{6AF961A4-5067-49F9-9569-2A2193731A86}
VT00
200
****************************************************************************
_______________________________________________________________________
Logfile of HijackThis v1.99.0
Scan saved at 9:35:31 PM, on 01/31/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\cisvc.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ygroqg.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\System32\vmss\vmss.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\temp\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O3 - Toolbar: (no name) - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - (no file)
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [vmss] C:\WINDOWS\System32\vmss\vmss.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O15 - Trusted IP range: 213.159.117.202
O15 - Trusted IP range: 213.159.117.202 (HKLM)
O16 - DPF: {1DF36010-E276-11D4-A7C0-00C04F0453DD} (Stamps.com Secure Postal Account Registration) -
https://secure.stamps.com/download/us/regis…16/sdcregie.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) -
http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O23 - Service: LexBce Server - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe