Problems:
1) services.exe (the valid one for EventLog & Plug&Play) consumes all remaining CPU time so
it's at 100%CPU usage and system slows to a crawl. Starts immediately or shortly after
establishing an internet connection; if system is booted but not used for internet, it does
not appear to occur.
2) After deleting a number of "O1-Hosts" entries using HijackThis, the system provides what
appears to be a clean log (see 1st log below); however, the entries return to the HJT log
(and remain until deleted again) after the 100%CPU issue starts up (see 2nd log below).
Virus Scan: Ran the latest versions (as of 10/07/07) of Spybot-S&D, Microsoft Malicious
Software Tool, TrendMicro Housecall, TrendMicro Sysclean, McAfee Stinger and AdAware. These
all failed to find ANY viruses or issues on the system.
System Clean: Cleaned each user acct with CCleaner. Eliminated all unnecessary services and
startup items. Installed MS Hotfix 903737.
Questions:
1) What is causing the standard services.exe to hog the CPU?
2) Are the "O1-Hosts" entries in HJT normal or do they indicate a specific issue?
3) Are these two conditions related?
4) And, of course, how do I fix it?
Thanks,
Bo
HijackThis log after cleanup:
-----------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:17:13 AM, on 10/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\admin\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/HomePage.htm
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: MA111 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA111
Configuration Utility\wlancfg.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration -
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?119
1806457793
O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) -
http://das.microsoft.com/activate/cab/x86/i486/NTANSI/retail/DASAct.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program
Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company -
C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company -
C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 3241 bytes
HijackThis log 8min later (100%CPU issue triggered):
----------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:28:40 AM, on 10/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.EXE
C:\Documents and Settings\admin\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/HomePage.htm
O1 - Hosts: 69.25.74.36 MAIL006 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.37 MAIL007 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.38 BE008 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.39 BE009 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.40 BE010 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.41 BE011 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.42 BE012 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.43 BE013 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.44 BE014 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.75.222 BE015 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.46 BE016 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.47 BE017 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.48 BE018 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.49 BE019 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.50 BE020 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.51 BE021 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.52 BE022 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.53 BE023 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.54 BE024 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.55 BE025 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.56 BE026 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.57 BE027 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.58 BE028 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 64.95.72.199 BE029 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 64.95.72.200 BE030 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 64.95.72.201 BE031 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 64.95.72.202 BE032 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 64.95.72.203 BE033 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 64.95.72.204 BE034 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 64.95.72.205 BE035 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 64.95.72.206 BE036 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 64.95.72.207 BE037 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 64.95.72.208 BE038 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 64.95.72.209 BE039 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 64.95.72.210 BE040 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 64.95.72.211 BE041 #Exchange Hosting 10/08/07 08:27:07
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: MA111 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA111
Configuration Utility\wlancfg.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration -
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?119
1806457793
O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) -
http://das.microsoft.com/activate/cab/x86/i486/NTANSI/retail/DASAct.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program
Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company -
C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company -
C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 5638 bytes
1) services.exe (the valid one for EventLog & Plug&Play) consumes all remaining CPU time so
it's at 100%CPU usage and system slows to a crawl. Starts immediately or shortly after
establishing an internet connection; if system is booted but not used for internet, it does
not appear to occur.
2) After deleting a number of "O1-Hosts" entries using HijackThis, the system provides what
appears to be a clean log (see 1st log below); however, the entries return to the HJT log
(and remain until deleted again) after the 100%CPU issue starts up (see 2nd log below).
Virus Scan: Ran the latest versions (as of 10/07/07) of Spybot-S&D, Microsoft Malicious
Software Tool, TrendMicro Housecall, TrendMicro Sysclean, McAfee Stinger and AdAware. These
all failed to find ANY viruses or issues on the system.
System Clean: Cleaned each user acct with CCleaner. Eliminated all unnecessary services and
startup items. Installed MS Hotfix 903737.
Questions:
1) What is causing the standard services.exe to hog the CPU?
2) Are the "O1-Hosts" entries in HJT normal or do they indicate a specific issue?
3) Are these two conditions related?
4) And, of course, how do I fix it?
Thanks,
Bo
HijackThis log after cleanup:
-----------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:17:13 AM, on 10/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\admin\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/HomePage.htm
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: MA111 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA111
Configuration Utility\wlancfg.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration -
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?119
1806457793
O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) -
http://das.microsoft.com/activate/cab/x86/i486/NTANSI/retail/DASAct.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program
Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company -
C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company -
C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 3241 bytes
HijackThis log 8min later (100%CPU issue triggered):
----------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:28:40 AM, on 10/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.EXE
C:\Documents and Settings\admin\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/HomePage.htm
O1 - Hosts: 69.25.74.36 MAIL006 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.37 MAIL007 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.38 BE008 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.39 BE009 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.40 BE010 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.41 BE011 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.42 BE012 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.43 BE013 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.44 BE014 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.75.222 BE015 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.46 BE016 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.47 BE017 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.48 BE018 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.49 BE019 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.50 BE020 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.51 BE021 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.52 BE022 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.53 BE023 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.54 BE024 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.55 BE025 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.56 BE026 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.57 BE027 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 69.25.74.58 BE028 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 64.95.72.199 BE029 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 64.95.72.200 BE030 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 64.95.72.201 BE031 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 64.95.72.202 BE032 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 64.95.72.203 BE033 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 64.95.72.204 BE034 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 64.95.72.205 BE035 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 64.95.72.206 BE036 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 64.95.72.207 BE037 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 64.95.72.208 BE038 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 64.95.72.209 BE039 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 64.95.72.210 BE040 #Exchange Hosting 10/08/07 08:27:07
O1 - Hosts: 64.95.72.211 BE041 #Exchange Hosting 10/08/07 08:27:07
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: MA111 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA111
Configuration Utility\wlancfg.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration -
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?119
1806457793
O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) -
http://das.microsoft.com/activate/cab/x86/i486/NTANSI/retail/DASAct.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program
Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company -
C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company -
C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 5638 bytes