Similar problems with this virus. Reloads itself at startup after being deleted, messes with Spybot S&D, Killbox.exe, etc. Help! Thanks in advance. Here's the HJT log per instuctions.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:17:53 PM, on 10/27/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ThreatFire\TFService.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\PROGRA~1\VISION~1\ONETOU~2.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ThreatFire\TFTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
C:\Program Files\Palm\Hotsync.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [OneTouch Monitor] C:\PROGRA~1\VISION~1\ONETOU~2.EXE
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA7219] command /c del "C:\WINDOWS\system32\WinCtrl32.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8641] cmd /c del "C:\WINDOWS\system32\WinCtrl32.dll_old"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7794] command /c del "C:\WINDOWS\system32\WinCtrl32.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1371] cmd /c del "C:\WINDOWS\system32\WinCtrl32.dll_old"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {49E67060-2C0D-415E-94C7-52A49F73B2F1} (CPlayFirstPiratePoppersControl Object) - http://zone.msn.com/bingame/pppp/default/PiratePoppers.1.0.0.39.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/luxr/default/mjolauncher.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) - http://myspace.oberon-media.com/gam...cd/online/Diner_Dash_3/en/ddfotg.1.0.0.37.cab
O16 - DPF: {C86FF4B0-AA1D-46D4-8612-025FB86583C7} (AstoundLauncher Control) - http://zone.msn.com/bingame/jobo/default/AstoundLauncher.cab#version=1,0,0,10
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://games.myspace.com/Gameshell/GameHost/1.0/OberonGameHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://myspace.oberon-media.com/gam...5/online/diner_dash/en/DinerDash.1.0.0.80.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O20 - AppInit_DLLs: karna.dat
O20 - Winlogon Notify: WinCtrl32 - WinCtrl32.dll (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Alerter AlerterRasAutoAticlr_optimization_v2.0.50727_32 (AlerterRasAutoAticlr_optimization_v2.0.50727_32) - Unknown owner - C:\WINDOWS\
O23 - Service: Alerter AlerterRpcSs (AlerterRpcSs) - Unknown owner - .exe (file missing)
O23 - Service: Application Management AppMgmtCiSvc (AppMgmtCiSvc) - Unknown owner - C:\WINDOWS\
O23 - Service: Application Management AppMgmtCiSvc AppMgmtCiSvcFastUserSwitchingCompatibility (AppMgmtCiSvcFastUserSwitchingCompatibility) - Unknown owner - C:\WINDOWS\
O23 - Service: Application Management AppMgmtFastUserSwitchingCompatibility (AppMgmtFastUserSwitchingCompatibility) - Unknown owner - C:\WINDOWS\
O23 - Service: Application Management AppMgmtFastUserSwitchingCompatibility AppMgmtFastUserSwitchingCompatibilityTrkWksImapiService (AppMgmtFastUserSwitchingCompatibilityTrkWksImapiService) - Unknown owner - C:\WINDOWS\
O23 - Service: Application Management AppMgmtFastUserSwitchingCompatibility AppMgmtFastUserSwitchingCompatibilityTrkWksImapiService AppMgmtFastUserSwitchingCompatibilityTrkWksImapiService PMSP Service (AppMgmtFastUserSwitchingCompatibilityTrkWksImapiService PMSP Service) - Unknown owner - C:\WINDOWS\
O23 - Service: Application Management AppMgmtFastUserSwitchingCompatibility AppMgmtFastUserSwitchingCompatibilityTrkWksImapiService AppMgmtFastUserSwitchingCompatibilityTrkWksImapiServiceNetman (AppMgmtFastUserSwitchingCompatibilityTrkWksImapiServiceNetman) - Unknown owner - C:\WINDOWS\
O23 - Service: ASP.NET State Service aspnet_stateLmHosts (aspnet_stateLmHosts) - Unknown owner - C:\WINDOWS\
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Ati HotKey Poller Aticlr_optimization_v2.0.50727_32 (Aticlr_optimization_v2.0.50727_32) - Unknown owner - C:\WINDOWS\
O23 - Service: Ati HotKey Poller Aticlr_optimization_v2.0.50727_32 Aticlr_optimization_v2.0.50727_32AppMgmtFastUserSwitchingCompatibilityTrkWksImapiService (Aticlr_optimization_v2.0.50727_32AppMgmtFastUserSwitchingCompatibilityTrkWksImapiService) - Unknown owner - .exe (file missing)
O23 - Service: Windows Audio AudioSrvRDSessMgr (AudioSrvRDSessMgr) - Unknown owner - C:\WINDOWS\
O23 - Service: Computer Browser Browseraspnet_stateLmHosts (Browseraspnet_stateLmHosts) - Unknown owner - .exe (file missing)
O23 - Service: Computer Browser Browserwuauserv (Browserwuauserv) - Unknown owner - C:\WINDOWS\
O23 - Service: Computer Browser Browserwuauserv BrowserwuauservALG (BrowserwuauservALG) - Unknown owner - C:\WINDOWS\
O23 - Service: Computer Browser Browserwuauserv BrowserwuauservW32TimeSpoolerNVSvc (BrowserwuauservW32TimeSpoolerNVSvc) - Unknown owner - C:\WINDOWS\
O23 - Service: ClipBook ClipSrvSSDPSRVEventSystemwuauservEventlogImapiServicegusvc (ClipSrvSSDPSRVEventSystemwuauservEventlogImapiServicegusvc) - Unknown owner - .exe (file missing)
O23 - Service: .NET Runtime Optimization Service v2.0.50727_X86 clr_optimization_v2.0.50727_32RasMan (clr_optimization_v2.0.50727_32RasMan) - Unknown owner - C:\WINDOWS\
O23 - Service: COM+ System Application COMSysAppFastUserSwitchingCompatibility (COMSysAppFastUserSwitchingCompatibility) - Unknown owner - C:\WINDOWS\
O23 - Service: COM+ System Application COMSysAppFastUserSwitchingCompatibility COMSysAppFastUserSwitchingCompatibilityWMPNetworkSvcWebClient (COMSysAppFastUserSwitchingCompatibilityWMPNetworkSvcWebClient) - Unknown owner - C:\WINDOWS\
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DHCP Client DhcpNetman (DhcpNetman) - Unknown owner - .exe (file missing)
O23 - Service: Logical Disk Manager Administrative Service dmadminEventlog (dmadminEventlog) - Unknown owner - C:\WINDOWS\
O23 - Service: DNS Client Dnscachegusvc (Dnscachegusvc) - Unknown owner - C:\WINDOWS\
O23 - Service: COM+ Event System EventSystemgusvc (EventSystemgusvc) - Unknown owner - C:\WINDOWS\
O23 - Service: COM+ Event System EventSystemgusvc EventSystemgusvcWMPNetworkSvc (EventSystemgusvcWMPNetworkSvc) - Unknown owner - C:\WINDOWS\
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Google Updater Service gusvcstisvc (gusvcstisvc) - Unknown owner - C:\WINDOWS\
O23 - Service: Human Interface Device Access HidServaspnet_state (HidServaspnet_state) - Unknown owner - .exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: TCP/IP NetBIOS Helper LmHostsNtLmSsp (LmHostsNtLmSsp) - Unknown owner - C:\WINDOWS\
O23 - Service: Messenger MessengerRSVP (MessengerRSVP) - Unknown owner - .exe (file missing)
O23 - Service: Distributed Transaction Coordinator MSDTCWZCSVC (MSDTCWZCSVC) - Unknown owner - C:\WINDOWS\
O23 - Service: Distributed Transaction Coordinator MSDTCWZCSVC MSDTCWZCSVCAppMgmtCiSvcFastUserSwitchingCompatibility (MSDTCWZCSVCAppMgmtCiSvcFastUserSwitchingCompatibility) - Unknown owner - .exe (file missing)
O23 - Service: Distributed Transaction Coordinator MSDTCWZCSVC MSDTCWZCSVCAppMgmtCiSvcFastUserSwitchingCompatibility MSDTCWZCSVCAppMgmtCiSvcFastUserSwitchingCompatibility Smart (MSDTCWZCSVCAppMgmtCiSvcFastUserSwitchingCompatibility Smart) - Unknown owner - .exe (file missing)
O23 - Service: Windows Installer MSIServerTrkWksALG (MSIServerTrkWksALG) - Unknown owner - .exe (file missing)
O23 - Service: Network DDE NetDDEclr_optimization_v2.0.50727_32 (NetDDEclr_optimization_v2.0.50727_32) - Unknown owner - C:\WINDOWS\
O23 - Service: Network DDE DSDM NetDDEdsdm Smart (NetDDEdsdm Smart) - Unknown owner - C:\WINDOWS\
O23 - Service: Network DDE DSDM NetDDEdsdmgusvcstisvc (NetDDEdsdmgusvcstisvc) - Unknown owner - C:\WINDOWS\
O23 - Service: Network Connections NetmanSamSs (NetmanSamSs) - Unknown owner - .exe (file missing)
O23 - Service: Network Connections NetmanWMPNetworkSvcNtmsSvc (NetmanWMPNetworkSvcNtmsSvc) - Unknown owner - .exe (file missing)
O23 - Service: Network Location Awareness (NLA) NlaSENS (NlaSENS) - Unknown owner - C:\WINDOWS\
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NVIDIA Driver Helper Service NVSvchkmsvc (NVSvchkmsvc) - Unknown owner - .exe (file missing)
O23 - Service: NVIDIA Driver Helper Service NVSvcRemoteAccess (NVSvcRemoteAccess) - Unknown owner - C:\WINDOWS\
O23 - Service: NVIDIA Driver Helper Service NVSvcRemoteAccess NVSvcRemoteAccessDhcpNetman (NVSvcRemoteAccessDhcpNetman) - Unknown owner - .exe (file missing)
O23 - Service: IPSEC Services PolicyAgentWebClient (PolicyAgentWebClient) - Unknown owner - C:\WINDOWS\
O23 - Service: IPSEC Services PolicyAgentWebClient PolicyAgentWebClientWmiApSrv (PolicyAgentWebClientWmiApSrv) - Unknown owner - .exe (file missing)
O23 - Service: Remote Access Auto Connection Manager RasAutoAticlr_optimization_v2.0.50727_32 (RasAutoAticlr_optimization_v2.0.50727_32) - Unknown owner - C:\WINDOWS\
O23 - Service: Routing and Remote Access RemoteAccessNtLmSsp (RemoteAccessNtLmSsp) - Unknown owner - C:\WINDOWS\
O23 - Service: Remote Procedure Call (RPC) Locator RpcLocatorRemoteAccessNtLmSsp (RpcLocatorRemoteAccessNtLmSsp) - Unknown owner - C:\WINDOWS\
O23 - Service: Smart Card SCardSvrThemes (SCardSvrThemes) - Unknown owner - C:\WINDOWS\
O23 - Service: Secondary Logon seclogonALG (seclogonALG) - Unknown owner - .exe (file missing)
O23 - Service: Internet Connection Firewall (ICF) / Internet Connection Sharing (ICS) SharedAccessWMPNetworkSvcNtmsSvc (SharedAccessWMPNetworkSvcNtmsSvc) - Unknown owner - C:\WINDOWS\
O23 - Service: Shell Hardware Detection ShellHWDetection Service for CDROM Access (ShellHWDetection Service for CDROM Access) - Unknown owner - C:\WINDOWS\
O23 - Service: Shell Hardware Detection ShellHWDetectionIDriverT (ShellHWDetectionIDriverT) - Unknown owner - C:\WINDOWS\
O23 - Service: Shell Hardware Detection ShellHWDetectionIDriverT ShellHWDetectionIDriverTPlugPlay (ShellHWDetectionIDriverTPlugPlay) - Unknown owner - .exe (file missing)
O23 - Service: Shell Hardware Detection ShellHWDetectionIDriverT ShellHWDetectionIDriverTPlugPlay ShellHWDetectionIDriverTPlugPlayNVSvcRemoteAccess (ShellHWDetectionIDriverTPlugPlayNVSvcRemoteAccess) - Unknown owner - .exe (file missing)
O23 - Service: Shell Hardware Detection ShellHWDetectionIDriverT ShellHWDetectionIDriverTPlugPlay ShellHWDetectionIDriverTPlugPlayRpcLocatorRemoteAccessNtLmSsp (ShellHWDetectionIDriverTPlugPlayRpcLocatorRemoteAccessNtLmSsp) - Unknown owner - .exe (file missing)
O23 - Service: Print Spooler Spooler Smart (Spooler Smart) - Unknown owner - C:\WINDOWS\
O23 - Service: Print Spooler SpoolerAudioSrvRDSessMgr (SpoolerAudioSrvRDSessMgr) - Unknown owner - C:\WINDOWS\
O23 - Service: Print Spooler SpoolerNVSvc (SpoolerNVSvc) - Unknown owner - C:\WINDOWS\
O23 - Service: SSDP Discovery Service SSDPSRVEventSystem (SSDPSRVEventSystem) - Unknown owner - C:\WINDOWS\
O23 - Service: SSDP Discovery Service SSDPSRVEventSystem SSDPSRVEventSystemwuauservEventlogImapiServicegusvc (SSDPSRVEventSystemwuauservEventlogImapiServicegusvc) - Unknown owner - .exe (file missing)
O23 - Service: MS Software Shadow Copy Provider SwPrvSharedAccess (SwPrvSharedAccess) - Unknown owner - C:\WINDOWS\
O23 - Service: Performance Logs and Alerts SysmonLogAppMgmtCiSvcFastUserSwitchingCompatibility (SysmonLogAppMgmtCiSvcFastUserSwitchingCompatibility) - Unknown owner - .exe (file missing)
O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
O23 - Service: Distributed Link Tracking Client TrkWksALG (TrkWksALG) - Unknown owner - C:\WINDOWS\
O23 - Service: Distributed Link Tracking Client TrkWksImapiService (TrkWksImapiService) - Unknown owner - C:\WINDOWS\
O23 - Service: Distributed Link Tracking Client TrkWkslanmanserver (TrkWkslanmanserver) - Unknown owner - .exe (file missing)
O23 - Service: Distributed Link Tracking Client TrkWksNetmanSamSs (TrkWksNetmanSamSs) - Unknown owner - .exe (file missing)
O23 - Service: Uninterruptible Power Supply UPSAudioSrvRDSessMgr (UPSAudioSrvRDSessMgr) - Unknown owner - C:\WINDOWS\
O23 - Service: Windows Time W32TimeSpoolerNVSvc (W32TimeSpoolerNVSvc) - Unknown owner - C:\WINDOWS\
O23 - Service: Portable Media Serial Number Service WmdmPmSNaspnet_stateLmHosts (WmdmPmSNaspnet_stateLmHosts) - Unknown owner - .exe (file missing)
O23 - Service: WMI Performance Adapter WmiApSrvAppMgmtCiSvcFastUserSwitchingCompatibility (WmiApSrvAppMgmtCiSvcFastUserSwitchingCompatibility) - Unknown owner - .exe (file missing)
O23 - Service: WMI Performance Adapter WmiApSrvRemoteAccessNtLmSsp (WmiApSrvRemoteAccessNtLmSsp) - Unknown owner - .exe (file missing)
O23 - Service: Windows Media Player Network Sharing Service WMPNetworkSvcNtmsSvc (WMPNetworkSvcNtmsSvc) - Unknown owner - C:\WINDOWS\
O23 - Service: Windows Media Player Network Sharing Service WMPNetworkSvcNtmsSvc WMPNetworkSvcNtmsSvcTermService (WMPNetworkSvcNtmsSvcTermService) - Unknown owner - .exe (file missing)
O23 - Service: Windows Media Player Network Sharing Service WMPNetworkSvcWebClient (WMPNetworkSvcWebClient) - Unknown owner - C:\WINDOWS\
O23 - Service: Windows Media Player Network Sharing Service WMPNetworkSvcWebClient WMPNetworkSvcWebClientDhcp (WMPNetworkSvcWebClientDhcp) - Unknown owner - .exe (file missing)
O23 - Service: Security Center wscsvc Service for CDROM Access (wscsvc Service for CDROM Access) - Unknown owner - C:\WINDOWS\
O23 - Service: Security Center wscsvcDhcp (wscsvcDhcp) - Unknown owner - .exe (file missing)
O23 - Service: Automatic Updates wuauservDhcp (wuauservDhcp) - Unknown owner - C:\WINDOWS\
O23 - Service: Automatic Updates wuauservEventlog (wuauservEventlog) - Unknown owner - C:\WINDOWS\
O23 - Service: Automatic Updates wuauservEventlog wuauservEventlogImapiService (wuauservEventlogImapiService) - Unknown owner - C:\WINDOWS\
O23 - Service: Automatic Updates wuauservEventlog wuauservEventlogImapiService wuauservEventlogImapiServicegusvc (wuauservEventlogImapiServicegusvc) - Unknown owner - C:\WINDOWS\
--
End of file - 20366 bytes
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:17:53 PM, on 10/27/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ThreatFire\TFService.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\PROGRA~1\VISION~1\ONETOU~2.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ThreatFire\TFTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
C:\Program Files\Palm\Hotsync.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [OneTouch Monitor] C:\PROGRA~1\VISION~1\ONETOU~2.EXE
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA7219] command /c del "C:\WINDOWS\system32\WinCtrl32.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8641] cmd /c del "C:\WINDOWS\system32\WinCtrl32.dll_old"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7794] command /c del "C:\WINDOWS\system32\WinCtrl32.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1371] cmd /c del "C:\WINDOWS\system32\WinCtrl32.dll_old"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {49E67060-2C0D-415E-94C7-52A49F73B2F1} (CPlayFirstPiratePoppersControl Object) - http://zone.msn.com/bingame/pppp/default/PiratePoppers.1.0.0.39.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/luxr/default/mjolauncher.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) - http://myspace.oberon-media.com/gam...cd/online/Diner_Dash_3/en/ddfotg.1.0.0.37.cab
O16 - DPF: {C86FF4B0-AA1D-46D4-8612-025FB86583C7} (AstoundLauncher Control) - http://zone.msn.com/bingame/jobo/default/AstoundLauncher.cab#version=1,0,0,10
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://games.myspace.com/Gameshell/GameHost/1.0/OberonGameHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://myspace.oberon-media.com/gam...5/online/diner_dash/en/DinerDash.1.0.0.80.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O20 - AppInit_DLLs: karna.dat
O20 - Winlogon Notify: WinCtrl32 - WinCtrl32.dll (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Alerter AlerterRasAutoAticlr_optimization_v2.0.50727_32 (AlerterRasAutoAticlr_optimization_v2.0.50727_32) - Unknown owner - C:\WINDOWS\
O23 - Service: Alerter AlerterRpcSs (AlerterRpcSs) - Unknown owner - .exe (file missing)
O23 - Service: Application Management AppMgmtCiSvc (AppMgmtCiSvc) - Unknown owner - C:\WINDOWS\
O23 - Service: Application Management AppMgmtCiSvc AppMgmtCiSvcFastUserSwitchingCompatibility (AppMgmtCiSvcFastUserSwitchingCompatibility) - Unknown owner - C:\WINDOWS\
O23 - Service: Application Management AppMgmtFastUserSwitchingCompatibility (AppMgmtFastUserSwitchingCompatibility) - Unknown owner - C:\WINDOWS\
O23 - Service: Application Management AppMgmtFastUserSwitchingCompatibility AppMgmtFastUserSwitchingCompatibilityTrkWksImapiService (AppMgmtFastUserSwitchingCompatibilityTrkWksImapiService) - Unknown owner - C:\WINDOWS\
O23 - Service: Application Management AppMgmtFastUserSwitchingCompatibility AppMgmtFastUserSwitchingCompatibilityTrkWksImapiService AppMgmtFastUserSwitchingCompatibilityTrkWksImapiService PMSP Service (AppMgmtFastUserSwitchingCompatibilityTrkWksImapiService PMSP Service) - Unknown owner - C:\WINDOWS\
O23 - Service: Application Management AppMgmtFastUserSwitchingCompatibility AppMgmtFastUserSwitchingCompatibilityTrkWksImapiService AppMgmtFastUserSwitchingCompatibilityTrkWksImapiServiceNetman (AppMgmtFastUserSwitchingCompatibilityTrkWksImapiServiceNetman) - Unknown owner - C:\WINDOWS\
O23 - Service: ASP.NET State Service aspnet_stateLmHosts (aspnet_stateLmHosts) - Unknown owner - C:\WINDOWS\
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Ati HotKey Poller Aticlr_optimization_v2.0.50727_32 (Aticlr_optimization_v2.0.50727_32) - Unknown owner - C:\WINDOWS\
O23 - Service: Ati HotKey Poller Aticlr_optimization_v2.0.50727_32 Aticlr_optimization_v2.0.50727_32AppMgmtFastUserSwitchingCompatibilityTrkWksImapiService (Aticlr_optimization_v2.0.50727_32AppMgmtFastUserSwitchingCompatibilityTrkWksImapiService) - Unknown owner - .exe (file missing)
O23 - Service: Windows Audio AudioSrvRDSessMgr (AudioSrvRDSessMgr) - Unknown owner - C:\WINDOWS\
O23 - Service: Computer Browser Browseraspnet_stateLmHosts (Browseraspnet_stateLmHosts) - Unknown owner - .exe (file missing)
O23 - Service: Computer Browser Browserwuauserv (Browserwuauserv) - Unknown owner - C:\WINDOWS\
O23 - Service: Computer Browser Browserwuauserv BrowserwuauservALG (BrowserwuauservALG) - Unknown owner - C:\WINDOWS\
O23 - Service: Computer Browser Browserwuauserv BrowserwuauservW32TimeSpoolerNVSvc (BrowserwuauservW32TimeSpoolerNVSvc) - Unknown owner - C:\WINDOWS\
O23 - Service: ClipBook ClipSrvSSDPSRVEventSystemwuauservEventlogImapiServicegusvc (ClipSrvSSDPSRVEventSystemwuauservEventlogImapiServicegusvc) - Unknown owner - .exe (file missing)
O23 - Service: .NET Runtime Optimization Service v2.0.50727_X86 clr_optimization_v2.0.50727_32RasMan (clr_optimization_v2.0.50727_32RasMan) - Unknown owner - C:\WINDOWS\
O23 - Service: COM+ System Application COMSysAppFastUserSwitchingCompatibility (COMSysAppFastUserSwitchingCompatibility) - Unknown owner - C:\WINDOWS\
O23 - Service: COM+ System Application COMSysAppFastUserSwitchingCompatibility COMSysAppFastUserSwitchingCompatibilityWMPNetworkSvcWebClient (COMSysAppFastUserSwitchingCompatibilityWMPNetworkSvcWebClient) - Unknown owner - C:\WINDOWS\
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DHCP Client DhcpNetman (DhcpNetman) - Unknown owner - .exe (file missing)
O23 - Service: Logical Disk Manager Administrative Service dmadminEventlog (dmadminEventlog) - Unknown owner - C:\WINDOWS\
O23 - Service: DNS Client Dnscachegusvc (Dnscachegusvc) - Unknown owner - C:\WINDOWS\
O23 - Service: COM+ Event System EventSystemgusvc (EventSystemgusvc) - Unknown owner - C:\WINDOWS\
O23 - Service: COM+ Event System EventSystemgusvc EventSystemgusvcWMPNetworkSvc (EventSystemgusvcWMPNetworkSvc) - Unknown owner - C:\WINDOWS\
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Google Updater Service gusvcstisvc (gusvcstisvc) - Unknown owner - C:\WINDOWS\
O23 - Service: Human Interface Device Access HidServaspnet_state (HidServaspnet_state) - Unknown owner - .exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: TCP/IP NetBIOS Helper LmHostsNtLmSsp (LmHostsNtLmSsp) - Unknown owner - C:\WINDOWS\
O23 - Service: Messenger MessengerRSVP (MessengerRSVP) - Unknown owner - .exe (file missing)
O23 - Service: Distributed Transaction Coordinator MSDTCWZCSVC (MSDTCWZCSVC) - Unknown owner - C:\WINDOWS\
O23 - Service: Distributed Transaction Coordinator MSDTCWZCSVC MSDTCWZCSVCAppMgmtCiSvcFastUserSwitchingCompatibility (MSDTCWZCSVCAppMgmtCiSvcFastUserSwitchingCompatibility) - Unknown owner - .exe (file missing)
O23 - Service: Distributed Transaction Coordinator MSDTCWZCSVC MSDTCWZCSVCAppMgmtCiSvcFastUserSwitchingCompatibility MSDTCWZCSVCAppMgmtCiSvcFastUserSwitchingCompatibility Smart (MSDTCWZCSVCAppMgmtCiSvcFastUserSwitchingCompatibility Smart) - Unknown owner - .exe (file missing)
O23 - Service: Windows Installer MSIServerTrkWksALG (MSIServerTrkWksALG) - Unknown owner - .exe (file missing)
O23 - Service: Network DDE NetDDEclr_optimization_v2.0.50727_32 (NetDDEclr_optimization_v2.0.50727_32) - Unknown owner - C:\WINDOWS\
O23 - Service: Network DDE DSDM NetDDEdsdm Smart (NetDDEdsdm Smart) - Unknown owner - C:\WINDOWS\
O23 - Service: Network DDE DSDM NetDDEdsdmgusvcstisvc (NetDDEdsdmgusvcstisvc) - Unknown owner - C:\WINDOWS\
O23 - Service: Network Connections NetmanSamSs (NetmanSamSs) - Unknown owner - .exe (file missing)
O23 - Service: Network Connections NetmanWMPNetworkSvcNtmsSvc (NetmanWMPNetworkSvcNtmsSvc) - Unknown owner - .exe (file missing)
O23 - Service: Network Location Awareness (NLA) NlaSENS (NlaSENS) - Unknown owner - C:\WINDOWS\
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NVIDIA Driver Helper Service NVSvchkmsvc (NVSvchkmsvc) - Unknown owner - .exe (file missing)
O23 - Service: NVIDIA Driver Helper Service NVSvcRemoteAccess (NVSvcRemoteAccess) - Unknown owner - C:\WINDOWS\
O23 - Service: NVIDIA Driver Helper Service NVSvcRemoteAccess NVSvcRemoteAccessDhcpNetman (NVSvcRemoteAccessDhcpNetman) - Unknown owner - .exe (file missing)
O23 - Service: IPSEC Services PolicyAgentWebClient (PolicyAgentWebClient) - Unknown owner - C:\WINDOWS\
O23 - Service: IPSEC Services PolicyAgentWebClient PolicyAgentWebClientWmiApSrv (PolicyAgentWebClientWmiApSrv) - Unknown owner - .exe (file missing)
O23 - Service: Remote Access Auto Connection Manager RasAutoAticlr_optimization_v2.0.50727_32 (RasAutoAticlr_optimization_v2.0.50727_32) - Unknown owner - C:\WINDOWS\
O23 - Service: Routing and Remote Access RemoteAccessNtLmSsp (RemoteAccessNtLmSsp) - Unknown owner - C:\WINDOWS\
O23 - Service: Remote Procedure Call (RPC) Locator RpcLocatorRemoteAccessNtLmSsp (RpcLocatorRemoteAccessNtLmSsp) - Unknown owner - C:\WINDOWS\
O23 - Service: Smart Card SCardSvrThemes (SCardSvrThemes) - Unknown owner - C:\WINDOWS\
O23 - Service: Secondary Logon seclogonALG (seclogonALG) - Unknown owner - .exe (file missing)
O23 - Service: Internet Connection Firewall (ICF) / Internet Connection Sharing (ICS) SharedAccessWMPNetworkSvcNtmsSvc (SharedAccessWMPNetworkSvcNtmsSvc) - Unknown owner - C:\WINDOWS\
O23 - Service: Shell Hardware Detection ShellHWDetection Service for CDROM Access (ShellHWDetection Service for CDROM Access) - Unknown owner - C:\WINDOWS\
O23 - Service: Shell Hardware Detection ShellHWDetectionIDriverT (ShellHWDetectionIDriverT) - Unknown owner - C:\WINDOWS\
O23 - Service: Shell Hardware Detection ShellHWDetectionIDriverT ShellHWDetectionIDriverTPlugPlay (ShellHWDetectionIDriverTPlugPlay) - Unknown owner - .exe (file missing)
O23 - Service: Shell Hardware Detection ShellHWDetectionIDriverT ShellHWDetectionIDriverTPlugPlay ShellHWDetectionIDriverTPlugPlayNVSvcRemoteAccess (ShellHWDetectionIDriverTPlugPlayNVSvcRemoteAccess) - Unknown owner - .exe (file missing)
O23 - Service: Shell Hardware Detection ShellHWDetectionIDriverT ShellHWDetectionIDriverTPlugPlay ShellHWDetectionIDriverTPlugPlayRpcLocatorRemoteAccessNtLmSsp (ShellHWDetectionIDriverTPlugPlayRpcLocatorRemoteAccessNtLmSsp) - Unknown owner - .exe (file missing)
O23 - Service: Print Spooler Spooler Smart (Spooler Smart) - Unknown owner - C:\WINDOWS\
O23 - Service: Print Spooler SpoolerAudioSrvRDSessMgr (SpoolerAudioSrvRDSessMgr) - Unknown owner - C:\WINDOWS\
O23 - Service: Print Spooler SpoolerNVSvc (SpoolerNVSvc) - Unknown owner - C:\WINDOWS\
O23 - Service: SSDP Discovery Service SSDPSRVEventSystem (SSDPSRVEventSystem) - Unknown owner - C:\WINDOWS\
O23 - Service: SSDP Discovery Service SSDPSRVEventSystem SSDPSRVEventSystemwuauservEventlogImapiServicegusvc (SSDPSRVEventSystemwuauservEventlogImapiServicegusvc) - Unknown owner - .exe (file missing)
O23 - Service: MS Software Shadow Copy Provider SwPrvSharedAccess (SwPrvSharedAccess) - Unknown owner - C:\WINDOWS\
O23 - Service: Performance Logs and Alerts SysmonLogAppMgmtCiSvcFastUserSwitchingCompatibility (SysmonLogAppMgmtCiSvcFastUserSwitchingCompatibility) - Unknown owner - .exe (file missing)
O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
O23 - Service: Distributed Link Tracking Client TrkWksALG (TrkWksALG) - Unknown owner - C:\WINDOWS\
O23 - Service: Distributed Link Tracking Client TrkWksImapiService (TrkWksImapiService) - Unknown owner - C:\WINDOWS\
O23 - Service: Distributed Link Tracking Client TrkWkslanmanserver (TrkWkslanmanserver) - Unknown owner - .exe (file missing)
O23 - Service: Distributed Link Tracking Client TrkWksNetmanSamSs (TrkWksNetmanSamSs) - Unknown owner - .exe (file missing)
O23 - Service: Uninterruptible Power Supply UPSAudioSrvRDSessMgr (UPSAudioSrvRDSessMgr) - Unknown owner - C:\WINDOWS\
O23 - Service: Windows Time W32TimeSpoolerNVSvc (W32TimeSpoolerNVSvc) - Unknown owner - C:\WINDOWS\
O23 - Service: Portable Media Serial Number Service WmdmPmSNaspnet_stateLmHosts (WmdmPmSNaspnet_stateLmHosts) - Unknown owner - .exe (file missing)
O23 - Service: WMI Performance Adapter WmiApSrvAppMgmtCiSvcFastUserSwitchingCompatibility (WmiApSrvAppMgmtCiSvcFastUserSwitchingCompatibility) - Unknown owner - .exe (file missing)
O23 - Service: WMI Performance Adapter WmiApSrvRemoteAccessNtLmSsp (WmiApSrvRemoteAccessNtLmSsp) - Unknown owner - .exe (file missing)
O23 - Service: Windows Media Player Network Sharing Service WMPNetworkSvcNtmsSvc (WMPNetworkSvcNtmsSvc) - Unknown owner - C:\WINDOWS\
O23 - Service: Windows Media Player Network Sharing Service WMPNetworkSvcNtmsSvc WMPNetworkSvcNtmsSvcTermService (WMPNetworkSvcNtmsSvcTermService) - Unknown owner - .exe (file missing)
O23 - Service: Windows Media Player Network Sharing Service WMPNetworkSvcWebClient (WMPNetworkSvcWebClient) - Unknown owner - C:\WINDOWS\
O23 - Service: Windows Media Player Network Sharing Service WMPNetworkSvcWebClient WMPNetworkSvcWebClientDhcp (WMPNetworkSvcWebClientDhcp) - Unknown owner - .exe (file missing)
O23 - Service: Security Center wscsvc Service for CDROM Access (wscsvc Service for CDROM Access) - Unknown owner - C:\WINDOWS\
O23 - Service: Security Center wscsvcDhcp (wscsvcDhcp) - Unknown owner - .exe (file missing)
O23 - Service: Automatic Updates wuauservDhcp (wuauservDhcp) - Unknown owner - C:\WINDOWS\
O23 - Service: Automatic Updates wuauservEventlog (wuauservEventlog) - Unknown owner - C:\WINDOWS\
O23 - Service: Automatic Updates wuauservEventlog wuauservEventlogImapiService (wuauservEventlogImapiService) - Unknown owner - C:\WINDOWS\
O23 - Service: Automatic Updates wuauservEventlog wuauservEventlogImapiService wuauservEventlogImapiServicegusvc (wuauservEventlogImapiServicegusvc) - Unknown owner - C:\WINDOWS\
--
End of file - 20366 bytes