ok this is the l2mfix log generated after startup
Starting Beta Fix 112305
Creating Account.
The command completed successfully.
Adding Administrative privleges.
The command completed successfully.
Checking for L2MFix account(0=no 1=yes):
1
Granting SeDebugPrivilege to L2MFIX ... successful
Setting Directory
C:\Documents and Settings\Owner\Desktop\l2mfix
C:\Documents and Settings\Owner\Desktop\l2mfix
Running From:
C:\Documents and Settings\Owner\Desktop\l2mfix
Killing Processes!
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 352 'smss.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 432 'winlogon.exe'
Killing PID 432 'winlogon.exe'
Killing PID 432 'winlogon.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 1312 'explorer.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 1080 'rundll32.exe'
Scanning First Pass. Please Wait!
First Pass Completed
Second Pass Scanning
Second pass Completed!
Backing Up: C:\WINDOWS\system32\c6002gdmg60a2.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\cdmpstui.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\en2ql1f51.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\enlol1331.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\f8l02i3mg8.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\fppu0379e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\g8jo0i13e8.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\gp00l3dm1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\h40q0ed5eh0.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ir2sl5f71.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ir60l5jm1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\kndes.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\kt4ol7h31.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\l6n4lg5q16.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\lvn6095se.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\lvnm0951e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\lZprxy.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\n08o0al3edq.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\n62u0gf9e62.dll
1 file(s) copied.
deleting: C:\WINDOWS\system32\c6002gdmg60a2.dll
Successfully Deleted: C:\WINDOWS\system32\c6002gdmg60a2.dll
deleting: C:\WINDOWS\system32\cdmpstui.dll
Successfully Deleted: C:\WINDOWS\system32\cdmpstui.dll
deleting: C:\WINDOWS\system32\en2ql1f51.dll
Successfully Deleted: C:\WINDOWS\system32\en2ql1f51.dll
deleting: C:\WINDOWS\system32\enlol1331.dll
Successfully Deleted: C:\WINDOWS\system32\enlol1331.dll
deleting: C:\WINDOWS\system32\f8l02i3mg8.dll
Successfully Deleted: C:\WINDOWS\system32\f8l02i3mg8.dll
deleting: C:\WINDOWS\system32\fppu0379e.dll
Successfully Deleted: C:\WINDOWS\system32\fppu0379e.dll
deleting: C:\WINDOWS\system32\g8jo0i13e8.dll
Successfully Deleted: C:\WINDOWS\system32\g8jo0i13e8.dll
deleting: C:\WINDOWS\system32\gp00l3dm1.dll
Successfully Deleted: C:\WINDOWS\system32\gp00l3dm1.dll
deleting: C:\WINDOWS\system32\h40q0ed5eh0.dll
Successfully Deleted: C:\WINDOWS\system32\h40q0ed5eh0.dll
deleting: C:\WINDOWS\system32\ir2sl5f71.dll
Successfully Deleted: C:\WINDOWS\system32\ir2sl5f71.dll
deleting: C:\WINDOWS\system32\ir60l5jm1.dll
Successfully Deleted: C:\WINDOWS\system32\ir60l5jm1.dll
deleting: C:\WINDOWS\system32\kndes.dll
Successfully Deleted: C:\WINDOWS\system32\kndes.dll
deleting: C:\WINDOWS\system32\kt4ol7h31.dll
Successfully Deleted: C:\WINDOWS\system32\kt4ol7h31.dll
deleting: C:\WINDOWS\system32\l6n4lg5q16.dll
Successfully Deleted: C:\WINDOWS\system32\l6n4lg5q16.dll
deleting: C:\WINDOWS\system32\lvn6095se.dll
Successfully Deleted: C:\WINDOWS\system32\lvn6095se.dll
deleting: C:\WINDOWS\system32\lvnm0951e.dll
Successfully Deleted: C:\WINDOWS\system32\lvnm0951e.dll
deleting: C:\WINDOWS\system32\lZprxy.dll
Successfully Deleted: C:\WINDOWS\system32\lZprxy.dll
deleting: C:\WINDOWS\system32\n08o0al3edq.dll
Successfully Deleted: C:\WINDOWS\system32\n08o0al3edq.dll
deleting: C:\WINDOWS\system32\n62u0gf9e62.dll
Successfully Deleted: C:\WINDOWS\system32\n62u0gf9e62.dll
Zipping up files for submission:
adding: c6002gdmg60a2.dll (164 bytes security) (deflated 5%)
adding: cdmpstui.dll (164 bytes security) (deflated 5%)
adding: en2ql1f51.dll (164 bytes security) (deflated 5%)
adding: enlol1331.dll (164 bytes security) (deflated 4%)
adding: f8l02i3mg8.dll (164 bytes security) (deflated 4%)
adding: fppu0379e.dll (164 bytes security) (deflated 5%)
adding: g8jo0i13e8.dll (164 bytes security) (deflated 4%)
adding: gp00l3dm1.dll (164 bytes security) (deflated 5%)
adding: h40q0ed5eh0.dll (164 bytes security) (deflated 5%)
adding: ir2sl5f71.dll (164 bytes security) (deflated 5%)
adding: ir60l5jm1.dll (164 bytes security) (deflated 5%)
adding: kndes.dll (164 bytes security) (deflated 4%)
adding: kt4ol7h31.dll (164 bytes security) (deflated 5%)
adding: l6n4lg5q16.dll (164 bytes security) (deflated 5%)
adding: lvn6095se.dll (164 bytes security) (deflated 5%)
adding: lvnm0951e.dll (164 bytes security) (deflated 6%)
adding: lZprxy.dll (164 bytes security) (deflated 5%)
adding: n08o0al3edq.dll (164 bytes security) (deflated 4%)
adding: n62u0gf9e62.dll (164 bytes security) (deflated 5%)
zip warning: name not matched: *.tmp
zip error: Nothing to do! (backup.zip)
adding: clear.reg (164 bytes security) (deflated 22%)
zip warning: name not matched: *.ini
zip error: Nothing to do! (backup.zip)
adding: direct.txt (164 bytes security) (stored 0%)
adding: flag.txt (164 bytes security) (stored 0%)
adding: lo2.txt (164 bytes security) (deflated 83%)
adding: readme.txt (164 bytes security) (deflated 52%)
adding: report.txt (164 bytes security) (deflated 65%)
adding: sec.txt (164 bytes security) (stored 0%)
adding: test.txt (164 bytes security) (deflated 77%)
adding: test2.txt (164 bytes security) (stored 0%)
adding: test3.txt (164 bytes security) (stored 0%)
adding: test5.txt (164 bytes security) (stored 0%)
adding: xfind.txt (164 bytes security) (deflated 71%)
adding: backregs/4AB382F9-384C-4D22-967A-A751582AD752.reg (164 bytes security) (deflated 70%)
adding: backregs/notibac.reg (164 bytes security) (deflated 87%)
adding: backregs/shell.reg (164 bytes security) (deflated 74%)
Restoring Sedebugprivilege:
Granting SeDebugPrivilege to Administrators ... successful
Restoring Windows Update Certificates.:
deleting local copy: c6002gdmg60a2.dll
deleting local copy: cdmpstui.dll
deleting local copy: en2ql1f51.dll
deleting local copy: enlol1331.dll
deleting local copy: f8l02i3mg8.dll
deleting local copy: fppu0379e.dll
deleting local copy: g8jo0i13e8.dll
deleting local copy: gp00l3dm1.dll
deleting local copy: h40q0ed5eh0.dll
deleting local copy: ir2sl5f71.dll
deleting local copy: ir60l5jm1.dll
deleting local copy: kndes.dll
deleting local copy: kt4ol7h31.dll
deleting local copy: l6n4lg5q16.dll
deleting local copy: lvn6095se.dll
deleting local copy: lvnm0951e.dll
deleting local copy: lZprxy.dll
deleting local copy: n08o0al3edq.dll
deleting local copy: n62u0gf9e62.dll
The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Nls]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\l6n4lg5q16.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
"DLLName"="wzcdlg.dll"
"Logon"="WZCEventLogon"
"Logoff"="WZCEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000000
The following are the files found:
****************************************************************************
C:\WINDOWS\system32\c6002gdmg60a2.dll
C:\WINDOWS\system32\cdmpstui.dll
C:\WINDOWS\system32\en2ql1f51.dll
C:\WINDOWS\system32\enlol1331.dll
C:\WINDOWS\system32\f8l02i3mg8.dll
C:\WINDOWS\system32\fppu0379e.dll
C:\WINDOWS\system32\g8jo0i13e8.dll
C:\WINDOWS\system32\gp00l3dm1.dll
C:\WINDOWS\system32\h40q0ed5eh0.dll
C:\WINDOWS\system32\ir2sl5f71.dll
C:\WINDOWS\system32\ir60l5jm1.dll
C:\WINDOWS\system32\kndes.dll
C:\WINDOWS\system32\kt4ol7h31.dll
C:\WINDOWS\system32\l6n4lg5q16.dll
C:\WINDOWS\system32\lvn6095se.dll
C:\WINDOWS\system32\lvnm0951e.dll
C:\WINDOWS\system32\lZprxy.dll
C:\WINDOWS\system32\n08o0al3edq.dll
C:\WINDOWS\system32\n62u0gf9e62.dll
Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{4AB382F9-384C-4D22-967A-A751582AD752}"=-
[-HKEY_CLASSES_ROOT\CLSID\{4AB382F9-384C-4D22-967A-A751582AD752}]
REGEDIT4
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"SV1"=""
****************************************************************************
Desktop.ini Contents:
****************************************************************************
****************************************************************************
this is the hijackthis log
Logfile of HijackThis v1.99.1
Scan saved at 11:42:54 PM, on 11/26/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Shaw Secure\Anti-Virus\fsgk32st.exe
C:\Program Files\Shaw Secure\Anti-Virus\FSGK32.EXE
C:\Program Files\Shaw Secure\Common\FSMA32.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Shaw Secure\Anti-Virus\fssm32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Shaw Secure\Common\FSLAUNCH.EXE
C:\Program Files\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.jobbank.gc.ca/Search_en.asp
O1 - Hosts: 203.161.127.141 www.dcsresearch.com
O4 - HKLM\..\Run: [Windows Logon Application] C:\WINDOWS\System32\logon.exe
O4 - HKLM\..\Run: [Configuration Loader] scvhost.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [Windows Network Firewall] C:\WINDOWS\System32\firewall.exe
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Shaw Secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Shaw Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\Shaw Secure\FSGUI\FSSW.EXE" /reboot
O4 - HKLM\..\Run: [News Service] "C:\Program Files\Shaw Secure\FSGUI\ispnews.exe"
O4 - HKLM\..\RunServices: [GlobalSCAPE] vkufibu.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Block this popup - C:\Program Files\Shaw Secure\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Web Filter - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Shaw Secure\FSPC\fspcmsie.dll
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\Shaw Secure\FSPC\fspcmsie.dll
O9 - Extra 'Tools' menuitem: Web Filter - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\Shaw Secure\FSPC\fspcmsie.dll
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Shaw Secure\Anti-Spyware\ieshield.dll
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Shaw Secure\Anti-Spyware\ieshield.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'winsflt.dll' missing
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -
http://housecall60.t...all/xscan60.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1132892240702
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1132892228483
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: Nls - C:\WINDOWS\system32\l6n4lg5q16.dll (file missing)
O23 - Service: Shaw Secure (BackWeb Plug-in - 3875767) - BackWeb Technologies Inc. - C:\PROGRA~1\SHAWSE~1\backweb\3875767\Program\SERVIC~1.EXE
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\Shaw Secure\Anti-Virus\fsgk32st.exe
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\Shaw Secure\backweb\3875767\program\fsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Shaw Secure\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure HTTP Server (fshttps) - F-Secure Corporation - C:\Program Files\Shaw Secure\FSPC\fshttps\fshttps.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Shaw Secure\Common\FSMA32.EXE
hope this helps
by the way, thanks alot, you guys are quick