O.K here is the new l2mfix and the hijack this is after this...
L2mfix 010406
Creating Account.
The command completed successfully.
Adding Administrative privleges.
The command completed successfully.
Checking for L2MFix account(0=no 1=yes):
1
Granting SeDebugPrivilege to L2MFIX ... successful
Running From:
C:\WINDOWS\system32
Killing Processes!
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 788 'smss.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 888 'winlogon.exe'
Killing PID 888 'winlogon.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 716 'explorer.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 1500 'rundll32.exe'
Restoring Sedebugprivilege:
Granting SeDebugPrivilege to Administrators ... successful
Scanning First Pass. Please Wait!
First Pass Completed
Second Pass Scanning
Second pass Completed!
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
Deleting: C:\WINDOWS\system32\ail70.dll
Successfully Deleted: C:\WINDOWS\system32\ail70.dll
Deleting: C:\WINDOWS\system32\bSsesrv.dll
Successfully Deleted: C:\WINDOWS\system32\bSsesrv.dll
Deleting: C:\WINDOWS\system32\cdcdll.dll
Successfully Deleted: C:\WINDOWS\system32\cdcdll.dll
Deleting: C:\WINDOWS\system32\db8vb.dll
Successfully Deleted: C:\WINDOWS\system32\db8vb.dll
Deleting: C:\WINDOWS\system32\dbloader.dll
Successfully Deleted: C:\WINDOWS\system32\dbloader.dll
Deleting: C:\WINDOWS\system32\drgest.dll
Successfully Deleted: C:\WINDOWS\system32\drgest.dll
Deleting: C:\WINDOWS\system32\dsskadp.dll
Successfully Deleted: C:\WINDOWS\system32\dsskadp.dll
Deleting: C:\WINDOWS\system32\enl8l13u1.dll
Successfully Deleted: C:\WINDOWS\system32\enl8l13u1.dll
Deleting: C:\WINDOWS\system32\enp8l17u1.dll
Successfully Deleted: C:\WINDOWS\system32\enp8l17u1.dll
Deleting: C:\WINDOWS\system32\f4l00e3meh.dll
Successfully Deleted: C:\WINDOWS\system32\f4l00e3meh.dll
Deleting: C:\WINDOWS\system32\f80o0id3e80.dll
Successfully Deleted: C:\WINDOWS\system32\f80o0id3e80.dll
Deleting: C:\WINDOWS\system32\HBFCI007.dll
Successfully Deleted: C:\WINDOWS\system32\HBFCI007.dll
Deleting: C:\WINDOWS\system32\HCFCI007.dll
Successfully Deleted: C:\WINDOWS\system32\HCFCI007.dll
Deleting: C:\WINDOWS\system32\i0lola331d.dll
Successfully Deleted: C:\WINDOWS\system32\i0lola331d.dll
Deleting: C:\WINDOWS\system32\i606lgds1606.dll
Successfully Deleted: C:\WINDOWS\system32\i606lgds1606.dll
Deleting: C:\WINDOWS\system32\INIresizeM6.dll
Successfully Deleted: C:\WINDOWS\system32\INIresizeM6.dll
Deleting: C:\WINDOWS\system32\ir00l5dm1.dll
Successfully Deleted: C:\WINDOWS\system32\ir00l5dm1.dll
Deleting: C:\WINDOWS\system32\iyrop.dll
Successfully Deleted: C:\WINDOWS\system32\iyrop.dll
Deleting: C:\WINDOWS\system32\j60slgd7160.dll
Successfully Deleted: C:\WINDOWS\system32\j60slgd7160.dll
Deleting: C:\WINDOWS\system32\k6lqlg3516.dll
Successfully Deleted: C:\WINDOWS\system32\k6lqlg3516.dll
Deleting: C:\WINDOWS\system32\kcdmaori.dll
Successfully Deleted: C:\WINDOWS\system32\kcdmaori.dll
Deleting: C:\WINDOWS\system32\khdpl.dll
Successfully Deleted: C:\WINDOWS\system32\khdpl.dll
Deleting: C:\WINDOWS\system32\khymgr.dll
Successfully Deleted: C:\WINDOWS\system32\khymgr.dll
Deleting: C:\WINDOWS\system32\kxdblr.dll
Successfully Deleted: C:\WINDOWS\system32\kxdblr.dll
Deleting: C:\WINDOWS\system32\loefx10N.dll
Successfully Deleted: C:\WINDOWS\system32\loefx10N.dll
Deleting: C:\WINDOWS\system32\lqkrn10N.dll
Successfully Deleted: C:\WINDOWS\system32\lqkrn10N.dll
Deleting: C:\WINDOWS\system32\lv4o09h3e.dll
Successfully Deleted: C:\WINDOWS\system32\lv4o09h3e.dll
Deleting: C:\WINDOWS\system32\lvl4093qe.dll
Successfully Deleted: C:\WINDOWS\system32\lvl4093qe.dll
Deleting: C:\WINDOWS\system32\lvr0099me.dll
Successfully Deleted: C:\WINDOWS\system32\lvr0099me.dll
Deleting: C:\WINDOWS\system32\lvr8099ue.dll
Successfully Deleted: C:\WINDOWS\system32\lvr8099ue.dll
Deleting: C:\WINDOWS\system32\lvro0993e.dll
Successfully Deleted: C:\WINDOWS\system32\lvro0993e.dll
Deleting: C:\WINDOWS\system32\lvrq0995e.dll
Successfully Deleted: C:\WINDOWS\system32\lvrq0995e.dll
Deleting: C:\WINDOWS\system32\m082lalo1dqc.dll
Successfully Deleted: C:\WINDOWS\system32\m082lalo1dqc.dll
Deleting: C:\WINDOWS\system32\m4po0e73eh.dll
Successfully Deleted: C:\WINDOWS\system32\m4po0e73eh.dll
Deleting: C:\WINDOWS\system32\mtmdd.dll
Successfully Deleted: C:\WINDOWS\system32\mtmdd.dll
Deleting: C:\WINDOWS\system32\mzi.dll
Successfully Deleted: C:\WINDOWS\system32\mzi.dll
Deleting: C:\WINDOWS\system32\oeuninst.dll
Successfully Deleted: C:\WINDOWS\system32\oeuninst.dll
Deleting: C:\WINDOWS\system32\olbccr32.dll
Successfully Deleted: C:\WINDOWS\system32\olbccr32.dll
Deleting: C:\WINDOWS\system32\ote2.dll
Successfully Deleted: C:\WINDOWS\system32\ote2.dll
Deleting: C:\WINDOWS\system32\suns.dll
Successfully Deleted: C:\WINDOWS\system32\suns.dll
Deleting: C:\WINDOWS\system32\trpmonui.dll
Successfully Deleted: C:\WINDOWS\system32\trpmonui.dll
Deleting: C:\WINDOWS\system32\wfnchip.dll
Successfully Deleted: C:\WINDOWS\system32\wfnchip.dll
msg11?.dll
0 file(s) copied.
Restoring Windows Update Certificates.:
The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
"DLLName"="Ati2evxx.dll"
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000001
"Lock"="AtiLockEvent"
"Logoff"="AtiLogoffEvent"
"Logon"="AtiLogonEvent"
"Disconnect"="AtiDisConnectEvent"
"Reconnect"="AtiReConnectEvent"
"Safe"=dword:00000000
"Shutdown"="AtiShutdownEvent"
"StartScreenSaver"="AtiStartScreenSaverEvent"
"StartShell"="AtiStartShellEvent"
"Startup"="AtiStartupEvent"
"StopScreenSaver"="AtiStopScreenSaverEvent"
"Unlock"="AtiUnLockEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\RunServices]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\i606lgds1606.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
The following are the files found:
****************************************************************************
C:\WINDOWS\system32\ail70.dll
C:\WINDOWS\system32\bSsesrv.dll
C:\WINDOWS\system32\cdcdll.dll
C:\WINDOWS\system32\db8vb.dll
C:\WINDOWS\system32\dbloader.dll
C:\WINDOWS\system32\drgest.dll
C:\WINDOWS\system32\dsskadp.dll
C:\WINDOWS\system32\enl8l13u1.dll
C:\WINDOWS\system32\enp8l17u1.dll
C:\WINDOWS\system32\f4l00e3meh.dll
C:\WINDOWS\system32\f80o0id3e80.dll
C:\WINDOWS\system32\HBFCI007.dll
C:\WINDOWS\system32\HCFCI007.dll
C:\WINDOWS\system32\i0lola331d.dll
C:\WINDOWS\system32\i606lgds1606.dll
C:\WINDOWS\system32\INIresizeM6.dll
C:\WINDOWS\system32\ir00l5dm1.dll
C:\WINDOWS\system32\iyrop.dll
C:\WINDOWS\system32\j60slgd7160.dll
C:\WINDOWS\system32\k6lqlg3516.dll
C:\WINDOWS\system32\kcdmaori.dll
C:\WINDOWS\system32\khdpl.dll
C:\WINDOWS\system32\khymgr.dll
C:\WINDOWS\system32\kxdblr.dll
C:\WINDOWS\system32\loefx10N.dll
C:\WINDOWS\system32\lqkrn10N.dll
C:\WINDOWS\system32\lv4o09h3e.dll
C:\WINDOWS\system32\lvl4093qe.dll
C:\WINDOWS\system32\lvr0099me.dll
C:\WINDOWS\system32\lvr8099ue.dll
C:\WINDOWS\system32\lvro0993e.dll
C:\WINDOWS\system32\lvrq0995e.dll
C:\WINDOWS\system32\m082lalo1dqc.dll
C:\WINDOWS\system32\m4po0e73eh.dll
C:\WINDOWS\system32\mtmdd.dll
C:\WINDOWS\system32\mzi.dll
C:\WINDOWS\system32\oeuninst.dll
C:\WINDOWS\system32\olbccr32.dll
C:\WINDOWS\system32\ote2.dll
C:\WINDOWS\system32\suns.dll
C:\WINDOWS\system32\trpmonui.dll
C:\WINDOWS\system32\wfnchip.dll
Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{0AB24450-32EE-4E76-AB34-79973DF8031E}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{0AB24450-32EE-4E76-AB34-79973DF8031E}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{0AB24450-32EE-4E76-AB34-79973DF8031E}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{0AB24450-32EE-4E76-AB34-79973DF8031E}\InprocServer32]
@="C:\\WINDOWS\\system32\\trpmonui.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{80DEE5E5-E592-4854-9A6A-596F003A972F}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{80DEE5E5-E592-4854-9A6A-596F003A972F}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{80DEE5E5-E592-4854-9A6A-596F003A972F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{80DEE5E5-E592-4854-9A6A-596F003A972F}\InprocServer32]
@="C:\\WINDOWS\\system32\\lqkrn10N.dll"
"ThreadingModel"="Apartment"
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{CA5CF48C-E54D-41FF-A853-BB35A82616F3}"=-
"{0AB24450-32EE-4E76-AB34-79973DF8031E}"=-
"{F0D6F8CC-25BF-4906-93E7-9E258DA35797}"=-
"{80DEE5E5-E592-4854-9A6A-596F003A972F}"=-
[-HKEY_CLASSES_ROOT\CLSID\{CA5CF48C-E54D-41FF-A853-BB35A82616F3}]
[-HKEY_CLASSES_ROOT\CLSID\{0AB24450-32EE-4E76-AB34-79973DF8031E}]
[-HKEY_CLASSES_ROOT\CLSID\{F0D6F8CC-25BF-4906-93E7-9E258DA35797}]
[-HKEY_CLASSES_ROOT\CLSID\{80DEE5E5-E592-4854-9A6A-596F003A972F}]
REGEDIT4
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"SV1"=""
****************************************************************************
Desktop.ini Contents:
****************************************************************************
****************************************************************************
Checking for L2MFix account(0=no 1=yes):
0
Zipping up files for submission:
adding: dlls/ail70.dll (164 bytes security) (deflated 5%)
adding: dlls/bSsesrv.dll (164 bytes security) (deflated 5%)
adding: dlls/cdcdll.dll (164 bytes security) (deflated 4%)
adding: dlls/db8vb.dll (164 bytes security) (deflated 5%)
adding: dlls/dbloader.dll (164 bytes security) (deflated 5%)
adding: dlls/drgest.dll (164 bytes security) (deflated 5%)
adding: dlls/dsskadp.dll (164 bytes security) (deflated 5%)
adding: dlls/enl8l13u1.dll (164 bytes security) (deflated 5%)
adding: dlls/enp8l17u1.dll (164 bytes security) (deflated 4%)
adding: dlls/f4l00e3meh.dll (164 bytes security) (deflated 5%)
adding: dlls/f80o0id3e80.dll (164 bytes security) (deflated 5%)
adding: dlls/HBFCI007.dll (164 bytes security) (deflated 5%)
adding: dlls/HCFCI007.dll (164 bytes security) (deflated 5%)
adding: dlls/i0lola331d.dll (164 bytes security) (deflated 5%)
adding: dlls/i606lgds1606.dll (164 bytes security) (deflated 5%)
adding: dlls/INIresizeM6.dll (164 bytes security) (deflated 5%)
adding: dlls/ir00l5dm1.dll (164 bytes security) (deflated 4%)
adding: dlls/iyrop.dll (164 bytes security) (deflated 5%)
adding: dlls/j60slgd7160.dll (164 bytes security) (deflated 5%)
adding: dlls/k6lqlg3516.dll (164 bytes security) (deflated 5%)
adding: dlls/kcdmaori.dll (164 bytes security) (deflated 4%)
adding: dlls/khdpl.dll (164 bytes security) (deflated 5%)
adding: dlls/khymgr.dll (164 bytes security) (deflated 5%)
adding: dlls/kxdblr.dll (164 bytes security) (deflated 5%)
adding: dlls/loefx10N.dll (164 bytes security) (deflated 4%)
adding: dlls/lqkrn10N.dll (164 bytes security) (deflated 5%)
adding: dlls/lv4o09h3e.dll (164 bytes security) (deflated 5%)
adding: dlls/lvl4093qe.dll (164 bytes security) (deflated 5%)
adding: dlls/lvr0099me.dll (164 bytes security) (deflated 4%)
adding: dlls/lvr8099ue.dll (164 bytes security) (deflated 5%)
adding: dlls/lvro0993e.dll (164 bytes security) (deflated 4%)
adding: dlls/lvrq0995e.dll (164 bytes security) (deflated 5%)
adding: dlls/m082lalo1dqc.dll (164 bytes security) (deflated 4%)
adding: dlls/m4po0e73eh.dll (164 bytes security) (deflated 4%)
adding: dlls/mtmdd.dll (164 bytes security) (deflated 5%)
adding: dlls/mzi.dll (164 bytes security) (deflated 5%)
adding: dlls/oeuninst.dll (164 bytes security) (deflated 5%)
adding: dlls/olbccr32.dll (164 bytes security) (deflated 5%)
adding: dlls/ote2.dll (164 bytes security) (deflated 5%)
adding: dlls/suns.dll (164 bytes security) (deflated 5%)
adding: dlls/trpmonui.dll (164 bytes security) (deflated 5%)
adding: dlls/wfnchip.dll (164 bytes security) (deflated 4%)
adding: backregs/0AB24450-32EE-4E76-AB34-79973DF8031E.reg (188 bytes security) (deflated 70%)
adding: backregs/80DEE5E5-E592-4854-9A6A-596F003A972F.reg (188 bytes security) (deflated 70%)
adding: backregs/notibac.reg (164 bytes security) (deflated 87%)
adding: backregs/shell.reg (164 bytes security) (deflated 74%)
Logfile of HijackThis v1.99.1
Scan saved at 6:01:23 PM, on 1/29/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe
C:\Program Files\Sony\vaio media integrated server\VMISrv.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\ATK0100\Hcontrol.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HiJack This\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.wvu.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.sony.com/vaiopeople
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.sony.com/vaiopeople
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O4 - HKLM\..\Run: [Hcontrol] C:\WINDOWS\ATK0100\Hcontrol.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} -
http://softdev.adelp...ad/tgctlins.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204
O16 - DPF: {321FB770-1FBE-4BFE-BDC1-6F622D4FA499} -
https://activation.alltel.com/wizlet/ALLTEL...aller_2-0-0.cab
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} (Personal System Administrator Control) -
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) -
http://cdn.digitalci...illama/ampx.cab
O20 - Winlogon Notify: RunServices - C:\WINDOWS\system32\i606lgds1606.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
O23 - Service: VAIO Entertainment File Import Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VCSW\VCSW.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Video Server (UPnP) (VAIOMediaPlatform-VideoServer-UPnP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\UPnPFramework.exe