I have been clean of malware and viruses for a couple years now, so this is rather unusual for me
Some symptoms (example file names are in bold):
1. iexplore.exe tries to connect to the internet on startup.
2. A program called (I think) "Monaco Gold Casino" tried to download/install itself at one time, which I promply killed.
3. At random times, AVG gives around 9 warnings in a row about Trojan files in C:\WINDOWS\system32\ and the name in the format: {C3136BED-7241-4140-BBA1-730C73F7EA05}.exe The name of the trojan that AVG reports and the string of numbers vary. An example of a name that AVG reports is Generic.XVF. When I tell AVG to do somthing with the files, I says (and I am paraphrasing) that it is unable to access them. Most of the time when I try to look for the files by hand, they do not show up in the system32 foulder. The one time I did find one, it had a simmalar icon to the "Monaco Gold Casino" task bar icon.
4. Several trojans were detected in system restore backups with name format A0036661.exe AVG said that it "healed" them, but they kept showing up in scans untill I deleted all system restore points.
5. Firefox and various other programs stoped working. When I try to open one, it will use up 95-100% of CPU time and do nothing. I had to install Opera to write this.
Things I have tried:
A. Ran Ad-aware. It fould mulitaple trojans in the JRE cache, a copy of CWS, and a couple others.
B. Ran Cwshredder. Found nothing.
C. Ran Spybot S&D. Runs extreamly slowly, then after 20 minutes locks up at around item 5000. Never managed to finish a scan. Reinstalling did not help. I checked, and it is not a heat issue.
D. Ran Windows Update (about a month out of date), and downloaded 29 patches (25 security related, one critical)
E. Ran HJT. Log included. I assume that the IP address from the Ukraine are not a good thing.
I am normaly fairly good with computers (I help clean up other peoples computers for them), but this one has me stumped. I hope one of you has some insight on what is causing this.
Some computer info not in the HJT log:
Athlon 64 3000+ (Venice core)
MSI Neo4 Platinum motherboard
2GB ram
C: OS drive
D: Programs drive and 20GB for Mandrive Linux
E: Photo database
J: Bulk data storage
Logfile of HijackThis v1.99.1
Scan saved at 7:34:09 PM, on 8/27/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
D:\Programs\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\dmadmin.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
D:\Programs\Java\jre1.5.0_08\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RunDLL32.exe
D:\Programs\Ahead\InCD\InCD.exe
C:\WINDOWS\system32\msdtc.exe
D:\Programs\D4\D4.exe
D:\Programs\DAEMON Tools\daemon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
D:\Programs\Internet Explorer\iexplore.exe
D:\Programs\Pro Imaging Powertoys\Microsoft Color Control Panel Applet for Windows XP\WinColorReminder.exe
D:\Programs\Monaco Systems\MonacoOPTIX 2.0\MonacoGamma.exe
D:\Programs\palmOne\HOTSYNC.EXE
C:\WINDOWS\System32\alg.exe
D:\Programs\Opera\Opera.exe
C:\WINDOWS\Explorer.EXE
D:\downloads\Utiletys\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Programs\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Programs\Java\jre1.5.0_08\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Programs\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Resume copy] copyfstq.exe /startup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NVRTCLK] C:\WINDOWS\system32\NVRTCLK\NVRTClk.exe
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" clear
O4 - HKLM\..\Run: [InCD] D:\Programs\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Dimension4] D:\Programs\D4\D4.exe
O4 - HKLM\..\Run: [DAEMON Tools] "D:\Programs\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [wlzvc.exe] C:\WINDOWS\system32\wlzvc.exe
O4 - HKCU\..\Run: [WinColorReminder] D:\Programs\Pro Imaging Powertoys\Microsoft Color Control Panel Applet for Windows XP\WinColorReminder.exe
O4 - HKCU\..\Run: [TClockEx] D:\Programs\TClockEx\TCLOCKEX.EXE
O4 - Startup: HotSync Manager.lnk = D:\Programs\palmOne\HOTSYNC.EXE
O4 - Global Startup: MonacoGamma.lnk = D:\Programs\Monaco Systems\MonacoOPTIX 2.0\MonacoGamma.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Programs\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Programs\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.update.microsoft.com
O15 - Trusted Zone: *.phaseone.com
O15 - Trusted Zone: http://download.windowsupdate.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{1E6883D9-EB1E-4D48-85D0-421B74296264}: NameServer = 85.255.114.55,85.255.112.21
O17 - HKLM\System\CCS\Services\Tcpip\..\{3FEE6B4F-2823-460C-B123-72B5559F697E}: NameServer = 85.255.114.55,85.255.112.21
O17 - HKLM\System\CCS\Services\Tcpip\..\{776DC5EE-336E-47E8-B185-6D8F6ED99245}: NameServer = 85.255.114.55,85.255.112.21
O17 - HKLM\System\CCS\Services\Tcpip\..\{DF77C9D3-405F-4765-998A-4A0E278445F4}: NameServer = 85.255.114.55,85.255.112.21
O17 - HKLM\System\CCS\Services\Tcpip\..\{F0082535-5F8D-4ED8-A47D-DF57F9533F59}: NameServer = 85.255.114.55,85.255.112.21
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.114.55 85.255.112.21
O17 - HKLM\System\CS2\Services\Tcpip\..\{1E6883D9-EB1E-4D48-85D0-421B74296264}: NameServer = 85.255.114.55,85.255.112.21
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.114.55 85.255.112.21
O17 - HKLM\System\CS3\Services\Tcpip\..\{1E6883D9-EB1E-4D48-85D0-421B74296264}: NameServer = 85.255.114.55,85.255.112.21
O17 - HKLM\System\CS4\Services\Tcpip\Parameters: NameServer = 85.255.114.55 85.255.112.21
O17 - HKLM\System\CS4\Services\Tcpip\..\{1E6883D9-EB1E-4D48-85D0-421B74296264}: NameServer = 85.255.114.55,85.255.112.21
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.55 85.255.112.21
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: DirMS_Defragmentation - Unknown owner - D:\Programs\DirMS\DirmsService.exe
O23 - Service: DM1Service - Unknown owner - D:\Programs\Olympus\DeviceDetector\DM1Service.exe (file missing)
O23 - Service: FileZilla Server FTP server (FileZilla Server) - Unknown owner - D:\Programs\FileZilla Server\FileZilla Server.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - D:\Programs\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - D:\Programs\SiSoftware\SiSoftware Sandra Lite 2007\Win32\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - D:\Programs\SiSoftware\SiSoftware Sandra Lite 2007\RpcSandraSrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Some symptoms (example file names are in bold):
1. iexplore.exe tries to connect to the internet on startup.
2. A program called (I think) "Monaco Gold Casino" tried to download/install itself at one time, which I promply killed.
3. At random times, AVG gives around 9 warnings in a row about Trojan files in C:\WINDOWS\system32\ and the name in the format: {C3136BED-7241-4140-BBA1-730C73F7EA05}.exe The name of the trojan that AVG reports and the string of numbers vary. An example of a name that AVG reports is Generic.XVF. When I tell AVG to do somthing with the files, I says (and I am paraphrasing) that it is unable to access them. Most of the time when I try to look for the files by hand, they do not show up in the system32 foulder. The one time I did find one, it had a simmalar icon to the "Monaco Gold Casino" task bar icon.
4. Several trojans were detected in system restore backups with name format A0036661.exe AVG said that it "healed" them, but they kept showing up in scans untill I deleted all system restore points.
5. Firefox and various other programs stoped working. When I try to open one, it will use up 95-100% of CPU time and do nothing. I had to install Opera to write this.
Things I have tried:
A. Ran Ad-aware. It fould mulitaple trojans in the JRE cache, a copy of CWS, and a couple others.
B. Ran Cwshredder. Found nothing.
C. Ran Spybot S&D. Runs extreamly slowly, then after 20 minutes locks up at around item 5000. Never managed to finish a scan. Reinstalling did not help. I checked, and it is not a heat issue.
D. Ran Windows Update (about a month out of date), and downloaded 29 patches (25 security related, one critical)
E. Ran HJT. Log included. I assume that the IP address from the Ukraine are not a good thing.
I am normaly fairly good with computers (I help clean up other peoples computers for them), but this one has me stumped. I hope one of you has some insight on what is causing this.
Some computer info not in the HJT log:
Athlon 64 3000+ (Venice core)
MSI Neo4 Platinum motherboard
2GB ram
C: OS drive
D: Programs drive and 20GB for Mandrive Linux
E: Photo database
J: Bulk data storage
Logfile of HijackThis v1.99.1
Scan saved at 7:34:09 PM, on 8/27/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
D:\Programs\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\dmadmin.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
D:\Programs\Java\jre1.5.0_08\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RunDLL32.exe
D:\Programs\Ahead\InCD\InCD.exe
C:\WINDOWS\system32\msdtc.exe
D:\Programs\D4\D4.exe
D:\Programs\DAEMON Tools\daemon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
D:\Programs\Internet Explorer\iexplore.exe
D:\Programs\Pro Imaging Powertoys\Microsoft Color Control Panel Applet for Windows XP\WinColorReminder.exe
D:\Programs\Monaco Systems\MonacoOPTIX 2.0\MonacoGamma.exe
D:\Programs\palmOne\HOTSYNC.EXE
C:\WINDOWS\System32\alg.exe
D:\Programs\Opera\Opera.exe
C:\WINDOWS\Explorer.EXE
D:\downloads\Utiletys\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Programs\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Programs\Java\jre1.5.0_08\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Programs\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Resume copy] copyfstq.exe /startup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NVRTCLK] C:\WINDOWS\system32\NVRTCLK\NVRTClk.exe
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" clear
O4 - HKLM\..\Run: [InCD] D:\Programs\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Dimension4] D:\Programs\D4\D4.exe
O4 - HKLM\..\Run: [DAEMON Tools] "D:\Programs\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [wlzvc.exe] C:\WINDOWS\system32\wlzvc.exe
O4 - HKCU\..\Run: [WinColorReminder] D:\Programs\Pro Imaging Powertoys\Microsoft Color Control Panel Applet for Windows XP\WinColorReminder.exe
O4 - HKCU\..\Run: [TClockEx] D:\Programs\TClockEx\TCLOCKEX.EXE
O4 - Startup: HotSync Manager.lnk = D:\Programs\palmOne\HOTSYNC.EXE
O4 - Global Startup: MonacoGamma.lnk = D:\Programs\Monaco Systems\MonacoOPTIX 2.0\MonacoGamma.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Programs\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Programs\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.update.microsoft.com
O15 - Trusted Zone: *.phaseone.com
O15 - Trusted Zone: http://download.windowsupdate.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{1E6883D9-EB1E-4D48-85D0-421B74296264}: NameServer = 85.255.114.55,85.255.112.21
O17 - HKLM\System\CCS\Services\Tcpip\..\{3FEE6B4F-2823-460C-B123-72B5559F697E}: NameServer = 85.255.114.55,85.255.112.21
O17 - HKLM\System\CCS\Services\Tcpip\..\{776DC5EE-336E-47E8-B185-6D8F6ED99245}: NameServer = 85.255.114.55,85.255.112.21
O17 - HKLM\System\CCS\Services\Tcpip\..\{DF77C9D3-405F-4765-998A-4A0E278445F4}: NameServer = 85.255.114.55,85.255.112.21
O17 - HKLM\System\CCS\Services\Tcpip\..\{F0082535-5F8D-4ED8-A47D-DF57F9533F59}: NameServer = 85.255.114.55,85.255.112.21
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.114.55 85.255.112.21
O17 - HKLM\System\CS2\Services\Tcpip\..\{1E6883D9-EB1E-4D48-85D0-421B74296264}: NameServer = 85.255.114.55,85.255.112.21
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.114.55 85.255.112.21
O17 - HKLM\System\CS3\Services\Tcpip\..\{1E6883D9-EB1E-4D48-85D0-421B74296264}: NameServer = 85.255.114.55,85.255.112.21
O17 - HKLM\System\CS4\Services\Tcpip\Parameters: NameServer = 85.255.114.55 85.255.112.21
O17 - HKLM\System\CS4\Services\Tcpip\..\{1E6883D9-EB1E-4D48-85D0-421B74296264}: NameServer = 85.255.114.55,85.255.112.21
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.55 85.255.112.21
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: DirMS_Defragmentation - Unknown owner - D:\Programs\DirMS\DirmsService.exe
O23 - Service: DM1Service - Unknown owner - D:\Programs\Olympus\DeviceDetector\DM1Service.exe (file missing)
O23 - Service: FileZilla Server FTP server (FileZilla Server) - Unknown owner - D:\Programs\FileZilla Server\FileZilla Server.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - D:\Programs\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - D:\Programs\SiSoftware\SiSoftware Sandra Lite 2007\Win32\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - D:\Programs\SiSoftware\SiSoftware Sandra Lite 2007\RpcSandraSrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Last edited by a moderator: