Hi,
Here are the logs:
ComboFix
"Eric" - 05/16/2007 20:50:01 Service Pack 4
ComboFix 07-05.17.V - Running from: "C:\Documents and Settings\Eric\Desktop\"
Command switches used :: "/v awvvt wmjdfhsb xwswmhos mqwopmyr"
(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINNT\system32\wmjdfhsb.dll
C:\WINNT\system32\xwswmhos.dll
C:\WINNT\system32\mqwopmyr.dll
C:\WINNT\system32\dlpksvoo.dll
C:\WINNT\system32\gyduuedt.dll
C:\WINNT\system32\whxtondd.dll
C:\WINNT\system32\tvvwa.ini
C:\WINNT\system32\rympowqm.ini
C:\WINNT\system32\awvvt.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\Program Files\Common Files\Yazzle1281OinAdmin.exe
C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe
C:\WINNT\retadpu.exe
C:\Program Files\ipwindows\ipwins.dll
C:\Program Files\ipwindows\ipwins.exe
C:\Program Files\ipwindows\UnInstall.exe
C:\Program Files\outerinfo\Terms.rtf
C:\WINNT\b122.exe
C:\Program Files\ipwindows
C:\Program Files\outerinfo
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\C\DOCUME~1
C:\qoobox\purity\C\DOCUME~1\Eric
C:\qoobox\purity\C\DOCUME~1\Eric\APPLIC~1
C:\qoobox\purity\C\DOCUME~1\Eric\MYDOCU~1
C:\qoobox\purity\C\DOCUME~1\Eric\APPLIC~1\DOBE~1
C:\qoobox\purity\C\DOCUME~1\Eric\MYDOCU~1\ICROSO~1
C:\qoobox\purity\C\DOCUME~1\Eric\MYDOCU~1\SSTEM3~1
C:\qoobox\purity\C\WINNT\system32\RACLE~1
((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_CMDSERVICE
-------\LEGACY_NETWORK_MONITOR
((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-16 ))))))))))))))))))))))))))))))))))
2007-05-16 21:02 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_858.dat
2007-05-10 00:33 60,928 --a------ C:\WINNT\system32\zqkv.dll
2007-05-10 00:33 <DIR> d-------- C:\Program Files\àdobe
2007-05-05 11:15 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-05-04 23:29 <DIR> d-------- C:\VundoFix Backups
2007-05-04 20:35 <DIR> d-------- C:\DOCUME~1\db2admin\APPLIC~1\Google
2007-04-30 13:21 <DIR> d-------- C:\DOCUME~1\DEFAUL~1\APPLIC~1\Google
2007-04-28 11:09 <DIR> d--hs---- C:\WINNT\V29ybGRpbnN1cmU
2007-04-26 10:36 2 --a------ C:\WINNT\system32\wcpisu32.exe
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-10 04:33:22 -------- d-----w C:\Program Files\?dobe
2007-03-23 04:15:58 -------- d-----w C:\Program Files\iPod
2007-03-23 04:13:43 -------- d-----w C:\Program Files\QuickTime
2007-03-23 04:10:46 -------- d-----w C:\Program Files\Apple Software Update
2007-03-13 09:44:49 245,520 ----a-w C:\WINNT\system32\WINSRV.DLL
2007-03-06 11:17:48 381,200 ----a-w C:\WINNT\system32\USER32.DLL
2007-03-06 11:17:46 38,160 ----a-w C:\WINNT\system32\mf3216.dll
2007-03-06 11:17:46 235,280 ----a-w C:\WINNT\system32\GDI32.DLL
2007-03-06 06:12:21 1,641,936 ----a-w C:\WINNT\system32\WIN32K.SYS
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll [03-11-03 14:17 ]
{43EBA266-14F6-3C76-F24F-6CE33BE3F9BB}=C:\WINNT\system32\zqkv.dll [07-03-19 14:30 ]
{53707962-6F74-2D53-2644-206D7942484F}=e:\Program Files\Spybot - Search & Destroy\SDHelper.dll [05-05-31 01:04 ]
{5CA3D70E-1895-11CF-8E15-001234567890}=C:\WINNT\system32\dla\tfswshx.dll [03-08-06 01:04 ]
{AA58ED58-01DD-4d91-8333-CF10577473F7}=c:\program files\google\googletoolbar2.dll [07-01-20 00:55 ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [03-06-19 15:05 C:\WINNT\system32\mobsync.exe]
"IgfxTray"="C:\WINNT\System32\igfxtray.exe" [01-10-12 21:34 ]
"HotKeysCmds"="C:\WINNT\System32\hkcmd.exe" [01-10-12 21:27 ]
"vptray"="C:\Program Files\NavNT\vptray.exe" [00-12-22 07:51 ]
"NuTCSetupEnviron"="C:\DEV\TOOLS\RATIONAL\RATION~1\NUTCROOT\bin\ncoeenv.exe" [01-01-02 18:25 ]
"MMTray"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [03-04-09 15:08 ]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [03-08-19 01:01 ]
"dla"="C:\WINNT\system32\dla\tfswctrl.exe" [03-08-06 01:04 ]
"PinnacleDriverCheck"="C:\WINNT\system32\PSDrvCheck.exe" [04-03-10 16:26 ]
"QBCD Autorun"="F:\autorun.exe" []
"NeroFilterCheck"="C:\WINNT\system32\NeroCheck.exe" [01-07-09 12:50 ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [07-02-16 11:54 ]
"iTunesHelper"="E:\Program Files\iTunes\iTunesHelper.exe" [07-03-14 20:05 ]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RHSI SHS"="C:\Program Files\Rogers\SelfHealing\SHS.exe" [07-04-25 10:46 ]
"Update Manager"="C:\Program Files\Rogers\Update Manager\UpdateManager.exe" [07-04-25 10:46 ]
"SHS"="C:\Program Files\Rogers\SelfHealing\SHS.exe" [07-04-25 10:46 ]
"PhotoShow Deluxe Media Manager"="C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe" [05-02-25 20:28 ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [07-01-25 23:02 ]
"RogersAgent"="c:\program files\Rogers\SelfHealing\RogersAgent.exe" []
"Hela"="C:\DOCUME~1\Eric\APPLIC~1\DOBE~1\wuauclt.exe" []
"Sgjec"="C:\Documents and Settings\Eric\My Documents\?icrosoft\d?dplay.exe" []
"Ctrzan"="C:\WINNT\system32\?racle\?ti2evxx.exe" []
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"^SetupICWDesktop"="C:\\Program Files\\Internet Explorer\\Connection Wizard\\icwconn1.exe /desktop"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"="C:\Program Files\Qualcomm\Eudora\EuShlExt.dll" [01-04-12 18:05 ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awturrp]
awturrp.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages msv1_0
Security Packages kerberos msv1_0 schannel
Notification Packages scecli
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
rpcss RpcSs
wugroup wuauserv
BITSgroup BITS
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
*newlycreated* -IPNAT
Contents of the 'Scheduled Tasks' folder
C:\WINNT\tasks\AppleSoftwareUpdate.job
********************************************************************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-05-16 21:02:59
Windows 5.0.2195 Service Pack 4 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
********************************************************************
Completion time: 2007-05-16 21:09:19 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 07-05-16 21:09
--- E O F ---
HijackThis:
Logfile of HijackThis v1.99.1
Scan saved at 9:14:27 PM, on 5/16/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Dev\Tools\Apache Group\Apache2\bin\Apache.exe
C:\Dev\Tools\Apache Group\Apache2\bin\Apache.exe
C:\Dev\Tools\IBM\SQLLIB\BIN\db2jds.exe
C:\Dev\Tools\IBM\SQLLIB\BIN\db2sec.exe
C:\Dev\Tools\IBM\SQLLIB\bin\db2dasstm.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\PROGRA~1\OSITIS~1\WINPRO~1\WPService.exe
C:\WINNT\System32\mspmspsv.exe
C:\PROGRA~1\OSITIS~1\WINPRO~1\WinProxy.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\nutsrv4.exe
C:\WINNT\System32\igfxtray.exe
C:\WINNT\System32\hkcmd.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINNT\system32\dla\tfswctrl.exe
C:\Program Files\QuickTime\qttask.exe
E:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Symantec\ACT\ACTLDR.EXE
C:\Dev\Tools\Apache Group\Apache2\bin\ApacheMonitor.exe
E:\Program Files\Intuit\QUICKENW\QWDLLS.EXE
C:\WINNT\explorer.exe
C:\Dev\Tools\IBM\SQLLIB\bin\db2fmp.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINNT\system32\notepad.exe
M:\Downloads\HijackThis\scanner.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.hispeed.rogers.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {43EBA266-14F6-3C76-F24F-6CE33BE3F9BB} - C:\WINNT\system32\zqkv.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - e:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINNT\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [NuTCSetupEnviron] C:\DEV\TOOLS\RATIONAL\RATION~1\NUTCROOT\bin\ncoeenv.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINNT\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINNT\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QBCD Autorun] F:\autorun.exe restart 5 1
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "E:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [RHSI SHS] "C:\Program Files\Rogers\SelfHealing\SHS.exe" /background
O4 - HKCU\..\Run: [Update Manager] "C:\Program Files\Rogers\Update Manager\UpdateManager.exe" /background
O4 - HKCU\..\Run: [SHS] "C:\Program Files\Rogers\SelfHealing\SHS.exe" /background
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [RogersAgent] c:\program files\Rogers\SelfHealing\RogersAgent.exe
O4 - HKCU\..\Run: [Hela] "C:\DOCUME~1\Eric\APPLIC~1\DOBE~1\wuauclt.exe" -vt yazb
O4 - HKCU\..\Run: [Sgjec] "C:\Documents and Settings\Eric\My Documents\?icrosoft\d?dplay.exe"
O4 - HKCU\..\Run: [Ctrzan] C:\WINNT\system32\?racle\?ti2evxx.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: ACT! Speed Loader.lnk = C:\Program Files\Symantec\ACT\ACTLDR.EXE
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Billminder.lnk = E:\Program Files\Intuit\QUICKENW\BILLMIND.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Monitor Apache Servers.lnk = C:\Dev\Tools\Apache Group\Apache2\bin\ApacheMonitor.exe
O4 - Global Startup: Quicken Startup.lnk = E:\Program Files\Intuit\QUICKENW\QWDLLS.EXE
O4 - Global Startup: startupb.lnk = C:\Bin\startupb.bat
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.hispeed.rogers.com
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) -
http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) -
http://pix.futureshop.ca/en/ImageUploader4.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) -
http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {D57262F5-9637-4E67-BC59-88C53EA76FC3} (ULcontrol Control) -
http://pix.futureshop.ca/en/ulcontrol.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = winamerica.worldinsure.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{4D7610B4-D8BE-4BF4-A1F0-DFBF8350A6ED}: NameServer = 24.153.22.195,24.153.22.67
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = winamerica.worldinsure.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = winamerica.worldinsure.com
O20 - Winlogon Notify: awturrp - awturrp.dll (file missing)
O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apache2 - Unknown owner - C:\Dev\Tools\Apache Group\Apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: DB2 - DB2 (DB2) - International Business Machines Corporation - C:\Dev\Tools\IBM\SQLLIB\bin\db2syscs.exe
O23 - Service: DB2DAS - DB2DAS00 (DB2DAS00) - International Business Machines Corporation - C:\Dev\Tools\IBM\SQLLIB\\bin\db2dasrrm.exe
O23 - Service: DB2 Governor (DB2GOVERNOR) - International Business Machines Corporation - C:\Dev\Tools\IBM\SQLLIB\BIN\db2govds.exe
O23 - Service: DB2 JDBC Applet Server (DB2JDS) - International Business Machines Corporation - C:\Dev\Tools\IBM\SQLLIB\BIN\db2jds.exe
O23 - Service: DB2 Security Server (DB2NTSECSERVER) - International Business Machines Corporation - C:\Dev\Tools\IBM\SQLLIB\BIN\db2sec.exe
O23 - Service: DB2 Remote Command Server (DB2REMOTECMD) - International Business Machines Corporation - C:\Dev\Tools\IBM\SQLLIB\BIN\db2rcmd.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IBM HTTP Administration 1.3.26 (IBMHTTPAdministration1.3.26) - Unknown owner - C:\Dev\Tools\IBM\IBMHttpServer\apache.exe" --ntservice (file missing)
O23 - Service: IBM HTTP Server 1.3.26 (IBMHTTPServer1.3.26) - Unknown owner - C:\Dev\Tools\IBM\IBMHttpServer\apache.exe" --ntservice (file missing)
O23 - Service: IBM WebSphere Application Server V5 - server1 (IBMWAS5Service - server1) - Unknown owner - C:\Dev\Tools\IBM\WebSphere\AppServer\bin\wasservice.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: NuTCRACKER Service (NuTCRACKERService) - DataFocus, Inc. - C:\WINNT\System32\nutsrv4.exe
O23 - Service: OracleOraHome081ClientCache - Unknown owner - C:\Dev\Tools\Oracle\Ora81\BIN\ONRSD.EXE
O23 - Service: OracleOraHome81ClientCache - Unknown owner - C:\Dev\Oracle\Ora81\BIN\ONRSD.EXE (file missing)
O23 - Service: WebSphere Embedded Messaging Publish And SubscribeWAS_CompaqWI_server1 (WebSphereEmbeddedMessagingPublishAndSubscribeWAS_CompaqWI_server1) - Unknown owner - C:/Dev/Tools/IBM/WebSphere MQ/WEMPS/bin/bipservice.exe (file missing)
O23 - Service: WinProxy - Unknown owner - C:\PROGRA~1\OSITIS~1\WINPRO~1\WPService.exe