Win32.TDSS.rtk and Win32.Bredolab.b

ysflight controller

Do you recognize this?

C:\Program Files\YSFLIGHT.COM\YSFLIGHT\bundle\jwv_for_PA005354.exe

There is a game program on my computer by that name but I do not recognize that exe. It can be deleted as I have the installation disk.
I updated my spybot immunization, immunized and ran a scan which came up clean.
However my macafee antivirus will not fix itself due to error.
I also had turned off TeaTimer on spybot, should I turn it back on?
R2
 
Then please delete these:

C:\Documents and Settings\Russell Radcliffe\My Documents\Danny\gay boyfriend.mp3
C:\Documents and Settings\Russell Radcliffe\My Documents\Danny\Korpiklaani - Korven Kuningas (2008).wma
C:\Documents and Settings\Russell Radcliffe\My Documents\Danny\maniquin kary perry.mp3
C:\Documents and Settings\Russell Radcliffe\My Documents\Danny\summer crush shirubon live.snd
C:\Documents and Settings\Russell Radcliffe\My Documents\Danny\summer crush shirubon.au
C:\Documents and Settings\Russell Radcliffe\My Documents\Danny\wolves unicorn kid.wma
C:\Documents and Settings\Russell Radcliffe\My Documents\Danny\Laurins music\caramelladasen - high quality.mp3
C:\Documents and Settings\Russell Radcliffe\My Documents\Danny\Laurins music\squeeze box who.mp3
C:\Documents and Settings\Russell Radcliffe\My Documents\Danny\Laurins music\tier swing kimya dawson - high quality.mp3
C:\Program Files\YSFLIGHT.COM\YSFLIGHT\bundle\jwv_for_PA005354.exe
C:\Qoobox\Quarantine
C:\WINDOWS\iedisco.exe
C:\WINDOWS\otstuk.bat

And empty this folder:

C:\Qoobox\Quarantine

Empty Recycle Bin.

Do you mean that McAfee doesn't work?
 
macafee

Then please delete these:

C:\Documents and Settings\Russell Radcliffe\My Documents\Danny\gay boyfriend.mp3
C:\Documents and Settings\Russell Radcliffe\My Documents\Danny\Korpiklaani - Korven Kuningas (2008).wma
C:\Documents and Settings\Russell Radcliffe\My Documents\Danny\maniquin kary perry.mp3
C:\Documents and Settings\Russell Radcliffe\My Documents\Danny\summer crush shirubon live.snd
C:\Documents and Settings\Russell Radcliffe\My Documents\Danny\summer crush shirubon.au
C:\Documents and Settings\Russell Radcliffe\My Documents\Danny\wolves unicorn kid.wma
C:\Documents and Settings\Russell Radcliffe\My Documents\Danny\Laurins music\caramelladasen - high quality.mp3
C:\Documents and Settings\Russell Radcliffe\My Documents\Danny\Laurins music\squeeze box who.mp3
C:\Documents and Settings\Russell Radcliffe\My Documents\Danny\Laurins music\tier swing kimya dawson - high quality.mp3
C:\Program Files\YSFLIGHT.COM\YSFLIGHT\bundle\jwv_for_PA005354.exe
C:\Qoobox\Quarantine
C:\WINDOWS\iedisco.exe
C:\WINDOWS\otstuk.bat

And empty this folder:

C:\Qoobox\Quarantine

Empty Recycle Bin.

Do you mean that McAfee doesn't work?

I have delete all of those files.
Macafee does not work. The trojan had disabled the virus protection and macafee will not fix itself, saying that there is some error. While trying to enable virus protection in the configure computer and files, I get "the setting cannot be changed because of an error". And when I try to configure Internet and Network network monitoring, I get " you cannot enable network monitoring right now, but please try again later. If you still have trouble, you may want to reinstall your Mcafee product".
I currently have that computer in safe mode without networking
R2
 
macafee 2

I have delete all of those files.
Macafee does not work. The trojan had disabled the virus protection and macafee will not fix itself, saying that there is some error. While trying to enable virus protection in the configure computer and files, I get "the setting cannot be changed because of an error". And when I try to configure Internet and Network network monitoring, I get " you cannot enable network monitoring right now, but please try again later. If you still have trouble, you may want to reinstall your Mcafee product".
I currently have that computer in safe mode without networking
R2

The macafee firewall is also disabled
R2
 
mcafee3

Then I suggest that you uninstall and reinstall McAfee to see if it helps.

There is no uninstall for my McAfee Security Center listed in the Control Panel Add/Remove Programs tab. When I go to mcafee.com and try to run the Virtual Technician, I get the screen that says the system administrator has set policies to prevent this installation. THe mcafee site says to remove the security center thru the add/remove programs function before you use the MCRP.exe tool to complete remove McAfee before reinstalling.
When restarting my computer, it appears to always be opening in safe mode, though it doesnt say that. The Administrator logon tab always appears and this should only be there in safe mode. Could be why I am denied access to the virtual technician?
Help
Thanks
Russ Radcliffe


Document ID: TS100507Email a Friend
Printer-Friendly View
Rate This Solution


How to uninstall or reinstall supported McAfee consumer products using the McAfee Consumer Products Removal tool (MCPR.exe)
Summary: This document explains how to remove and reinstall McAfee Consumer products using the McAfee Consumer Products Removal tool. This option should only be used after you remove your McAfee product through Add/Remove Programs.


Affected Suites: Affected Products: Affected Operating Systems:
Total Protection
Internet Security Suite
PC Protection Plus
VirusScan Plus
Wireless Protection

AntiSpyware
Data Backup
Personal Firewall
Privacy Service
QuickClean
SecurityCenter
SiteAdvisor
Anti-Spam
SpamKiller
VirusScan
Wireless Protection

Windows 2000
Windows XP
Windows Vista




Note: This tool (previously named MCPR2.EXE) is not compatible with Microsoft Windows 98 or ME.

Description
Running the McAfee Consumer Product Removal tool (MCPR.exe) removes all 2005, 2006, 2007, 2008, and 2009 versions of McAfee consumer products.

Solution
IMPORTANT: If your McAfee products were preinstalled by the manufacturer of your computer, please make sure to activate your McAfee subscription before uninstalling. Reinstalling from a CD or download will only install your McAfee consumer applications, but may not recover your paid subscription term information.



--------------------------------------------------------------------------------


You can now watch a Flash video of the following steps!
Click the button below to start the video.

Note: This option is recommended for Broadband Users Only.
To view this demonstration, you will need Adobe Flash. Download this for free by visiting Adobe at www.adobe.com.


--------------------------------------------------------------------------------

Step 1 - Uninstall your McAfee consumer products using Add/Remove Programs in the Windows Control Panel
Windows 2000/XP
Click Start, Settings, Control Panel.
Double-click Add or Remove Programs.
Select the McAfee SecurityCenter product.
Click Remove and follow the steps provided.
Windows Vista
Click Start, Search, type Programs and Features, and click Go.
Double-click Programs and Features.
Select the McAfee SecurityCenter product.
Click Uninstall and follow the steps provided.
Step 2 - Download and run MCPR.exe
Download the removal tool from:

http://download.mcafee.com/products/licensed/cust_support_patches/MCPR.exe


Click Save and save the file to a folder on your computer.
Navigate to the folder where the file was saved.
Make sure all McAfee windows are closed.
Double-click MCPR.exe to run the removal tool.

Note: Windows Vista users must right-click MCPR.exe and select Run as Administrator.


Restart your computer after receiving the message CleanUp Successful.

Your McAfee product will not be fully removed until the system is restarted.
If the message Cleanup Unsuccessful is displayed, follow the steps below to view and save your MCPR log files for analysis by Technical Support.

Saving troubleshooting logs
On the Cleanup Unsuccessful notification dialog, click View Logs.
Your troubleshooting logs will open in a Notepad window. Click File, Save As, and save the file to your Desktop. Name the file MCPR_date.txt (for example: MCPR_Jan10_08.txt).
Contact McAfee Technical Support and provide the log file to your technician for troubleshooting.
When all McAfee products are removed from your computer, continue to Step 3.

Step 3 - Reinstall your McAfee Products
Note: Please refer to the instructions from the partner you purchased your McAfee consumer product from, or reinstall using the partner links below.

If you purchased your software directly from McAfee, go to https://home.mcafee.com/Secure/Protected/Login.aspx to log in and download your software.

AT&T users should go to https://uversecentral1.att.com/uvp/myhome/mam/ISS/

Comcast users should go to http://security.comcast.net/

Cox users should go to http://www.cox.net

DELL users should go to https://us.mcafee.com/root/login.asp?affid=105

Gateway users should go to https://us.mcafee.com/root/login.asp?affid=370

eMachines users should go to https://us.mcafee.com/root/login.asp?affid=365

MSN users should go to http://membercenter.msn.com

AOL users should search on keyword: Safety (http://daol.aol.com/safetycenter). On the AOL Safety & Security page, click Download Now.
Rate this document 1 2 3 4 5(Best)
* Required Field
Did this article resolve your issue?
No Yes
* Required Field
Please provide any comments below
 
I'd use straight that MCRP.exe if no McAfee Security Center listed in the Control Panel Add/Remove Programs tab.
 
I'd use straight that MCRP.exe if no McAfee Security Center listed in the Control Panel Add/Remove Programs tab.

I am running mcrp.exe but it says error obtaining full permission for cleanup. Some products may not be removed. I am running this in safe with networking mode.
When restarting in normal mode, I get the Admin logon with my regular logon. That should only show in safe mode. I was also unable to get an internet connection in "normal" mode.
I keep getting command screens flashing on and off.
MCRP Cleanup log to large to paste here
mcrp.exe says the cleanup was unsuccessful and to reboot to finish cleanup
I am going to reboot
R2
 
That might mean corrupted windows installation.

Are you able to logon with Admin account?
 
That might mean corrupted windows installation.

Are you able to logon with Admin account?

Yes,
I ran the mcrp and reboot which appeared to remove all of mcafee. I went to the mcafee site and redownloaded the mcafee security suite and reinstalled it BUT the program is still totally disabled
r2
 
That might mean malware issues or totally something else and we need to test.

Please uninstall McAfee with mcrp and install one free antivirus from below:

1) Antivir PersonalEdition Classic - Free anti-virus software for Windows. Free support.
2) avast! 4 Home Edition - Anti-virus program for Windows. The home edition is freeware for noncommercial users.
3) AVG Anti-Virus Free Edition - Free edition of the AVG anti-virus program for Windows.

You should run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and results in program conflicts and false virus alerts.

Let me know if that works or not.
 
mcafee whatever

That might mean malware issues or totally something else and we need to test.

Please uninstall McAfee with mcrp and install one free antivirus from below:

1) Antivir PersonalEdition Classic - Free anti-virus software for Windows. Free support.
2) avast! 4 Home Edition - Anti-virus program for Windows. The home edition is freeware for noncommercial users.
3) AVG Anti-Virus Free Edition - Free edition of the AVG anti-virus program for Windows.

You should run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and results in program conflicts and false virus alerts.

Let me know if that works or not.

I contacted mcafee and they indicated that I had an infected program and that I should remove and redownload. I did this thru the control panel add/remove program list. McAfee Security Center was there! However the result was the same with a disabled mcafee program.
I have used the add/remove list uninstall plus the mcrp.exe. I have to reboot now but I will proceed as directed
r2
 
Avir

Thanks for update and keep me informed.

I tried to download the first antivirus, Avir but I dont think it ever finished downloading because there was never an icon any kind of screen, so I am moving on to the next one
r2
 
Avast

OK, that is not a good sign.

Let me know about any updates.

Avast is still loading.
My other computer was infected this afternoon after my daughter was on facebook. AARGH!
I rebooted in safe mode, ran spybot which found right click and casalemedia, rebooted with spybot to run at startup which found nothing. However mcafee was disabled. I uninstalled it thru the control panel and redownloaded it. That seemed to work. I am currently running spybot in normal mode and will run mcafee after that.
Avast is ready for setup, so I am exiting this screen
AND going to bed! Will check in the am
THANKS for your help
R2
 
short nap

OK, post back when you can.

I loaded avast and rebooted.
I got "avast: THe AAVM subsystem detected a RPC error. The operation could not be completed." The info directed me to Windows Update. When I access windows update i get "website has encountered a problem and cannot display the page you are trying to view"
I was also directed to computer management lists and accessed the avast repair option to no avail.
?
R2
 
combofix again

Please then run combofix again to see if something has returned.

Here are the current combofix and hijack this logs.
They were run in safe mode with networking. Combofix download with errors in normal mode.
Happy news. The other computer appears to be OK. I have an enabled McAfee, no virus popups, an updated and Resident spybot with a clean run and the McAfee scan is 70% done and still clean.
I am off to work and will be back in 8 to 10 hours
Thanks for the help
R2
ComboFix 09-08-10.06 - Russell Radcliffe 08/14/2009 8:32.2.1 - NTFSx86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.751 [GMT -7:00]
Running from: c:\documents and settings\Russell Radcliffe\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2009-07-14 to 2009-08-14 )))))))))))))))))))))))))))))))
.

2100-02-23 22:35 . 2001-02-22 17:54 768 -c--a-w- c:\program files\x73_lut.dat
2100-02-23 21:35 . 2001-02-22 16:54 768 -c--a-w- c:\windows\x73_lut.dat
2100-02-09 00:03 . 2001-05-11 19:39 53248 -c--a-w- c:\program files\ACMonitor_X73.exe
2009-08-14 06:11 . 2009-02-05 20:06 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-14 06:11 . 2009-02-05 20:06 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-14 06:11 . 2009-02-05 20:05 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-08-14 06:11 . 2009-02-05 20:08 93296 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-08-14 06:11 . 2009-02-05 20:08 94032 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-08-14 06:11 . 2009-02-05 20:07 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-14 06:11 . 2009-02-05 20:07 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-14 06:11 . 2009-02-05 20:04 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-08-14 06:10 . 2009-02-05 20:11 1256296 ----a-w- c:\windows\system32\aswBoot.exe
2009-08-14 06:10 . 2009-08-14 06:10 -------- d-----w- c:\program files\Alwil Software
2009-08-14 04:05 . 2009-08-14 04:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Citrix
2009-08-14 03:50 . 2009-08-14 03:50 -------- d-----w- c:\program files\Citrix
2009-08-14 03:50 . 2009-08-14 03:50 -------- d-----w- c:\documents and settings\Russell Radcliffe\Local Settings\Application Data\Citrix
2009-08-14 03:50 . 2009-08-14 03:50 61224 ----a-w- c:\documents and settings\Russell Radcliffe\GoToAssistDownloadHelper.exe
2009-08-13 19:59 . 2009-08-13 19:59 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Dell
2009-08-13 19:00 . 2009-08-14 04:22 -------- d-----w- c:\windows\LastGood
2009-08-13 17:03 . 2009-08-13 17:03 73392 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-12 20:18 . 2009-08-12 20:18 -------- d-----w- c:\windows\LastGood.Tmp
2009-08-12 18:00 . 2009-08-12 18:00 -------- d-----w- c:\program files\ESET
2009-08-12 17:48 . 2009-08-12 17:48 -------- d-----w- c:\documents and settings\Administrator\Application Data\Yahoo!
2009-08-12 17:48 . 2009-08-12 17:48 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Google
2009-08-12 06:17 . 2009-08-12 06:17 616448 ---ha-w- C:\StashIMAPI.bin
2009-08-08 21:31 . 2009-08-08 21:31 -------- d-----w- c:\program files\ERUNT
2009-08-08 20:32 . 2009-08-08 20:32 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Apple Computer
2009-08-08 20:26 . 2009-08-08 20:26 -------- d-----w- c:\documents and settings\Administrator\Application Data\Sony Corporation
2009-07-29 22:48 . 2009-07-29 22:48 -------- d-----w- c:\program files\Zone Labs
2009-07-29 22:48 . 2009-07-29 22:48 -------- d-----w- c:\windows\Internet Logs

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-14 15:25 . 2003-04-06 19:01 24 ----a-w- c:\windows\system32\DVCStateBkp-{00000002-00000000-00000007-00001102-00000002-80221102}.dat
2009-08-14 15:25 . 2003-04-06 19:01 24 ----a-w- c:\windows\system32\DVCState-{00000002-00000000-00000007-00001102-00000002-80221102}.dat
2009-08-08 16:57 . 2001-12-22 16:48 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-08 16:55 . 2005-02-20 22:08 -------- d-----w- c:\program files\DAZZLE
2009-08-08 16:54 . 2006-02-01 20:26 -------- d-----w- c:\program files\Stamps.com Internet Postage
2009-08-08 16:52 . 2005-11-19 00:23 -------- d-----w- c:\program files\Atari
2009-08-08 16:48 . 2008-08-07 17:21 -------- d-----w- c:\program files\LimeWire
2009-07-29 15:16 . 2005-10-02 15:25 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-07-26 22:23 . 2008-04-05 23:56 -------- d-----w- c:\documents and settings\Russell Radcliffe\Application Data\LimeWire
2009-07-15 15:59 . 2009-07-14 17:38 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-07-15 15:59 . 2009-07-14 17:38 -------- d-----w- c:\program files\NOS
2009-07-14 18:26 . 2006-05-23 16:18 -------- d-----w- c:\program files\LexmarkX73
2009-07-14 18:04 . 2003-04-06 20:23 -------- d-----w- c:\program files\Common Files\Adobe
2009-07-14 18:02 . 2009-07-14 18:02 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-07-14 18:00 . 2009-07-14 17:39 8303545 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\air_compressed.exe
2009-07-14 17:39 . 2009-07-14 17:39 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-06-30 15:51 . 2001-12-22 16:50 -------- d-----w- c:\program files\PhoneTools
2009-06-25 04:10 . 2007-07-10 13:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-06-25 03:01 . 2009-06-25 03:00 -------- d-----w- c:\program files\iTunes
2009-06-25 03:00 . 2009-06-25 03:00 -------- d-----w- c:\program files\iPod
2009-06-25 03:00 . 2007-07-10 13:34 -------- d-----w- c:\program files\Common Files\Apple
2009-06-25 02:57 . 2002-01-15 00:49 -------- d-----w- c:\program files\QuickTime
2009-06-25 02:48 . 2009-06-25 02:48 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-23 03:45 . 2006-12-15 01:38 -------- d-----w- c:\documents and settings\Russell Radcliffe\Application Data\Apple Computer
2009-06-05 18:42 . 2009-05-07 23:16 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-06-05 18:42 . 2007-12-30 21:16 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-05-26 19:30 . 2009-05-16 22:45 100 --s-a-w- c:\windows\system32\2092623811.dat
2005-12-30 22:09 . 2005-12-30 22:09 774144 -c--a-w- c:\program files\RngInterstitial.dll
2001-07-27 00:58 . 2000-01-11 20:50 47 -c--a-w- c:\program files\ACMonitor_X73.ini
2001-07-05 20:46 . 2001-07-20 18:48 8116 -c--a-w- c:\program files\OSLO3071b2.USB
2001-05-09 00:36 . 2000-12-05 23:56 114688 -c--a-w- c:\program files\lxarscan.dll
2001-04-23 22:22 . 2100-02-08 23:53 1437 -c--a-w- c:\program files\gtx73.ini
.

((((((((((((((((((((((((((((( SnapShot@2009-08-12_16.38.05 )))))))))))))))))))))))))))))))))))))))))
.
+ 2001-12-22 16:38 . 2009-08-13 17:13 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
- 2001-12-22 16:38 . 2009-08-12 16:18 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
+ 2001-12-22 16:38 . 2009-08-13 17:13 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
- 2001-12-22 16:38 . 2009-08-12 16:18 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
+ 2009-08-13 19:41 . 2008-04-14 00:12 23040 c:\windows\LastGood\system32\psapi.dll
+ 2009-08-13 19:00 . 2007-01-03 01:16 86848 c:\windows\LastGood\system32\DRIVERS\WscNetDr.sys
+ 2009-08-13 17:00 . 2009-08-13 17:00 8192 c:\windows\ERDNT\AutoBackup\8-13-2009\Users\00000002\UsrClass.dat
+ 2009-08-12 17:47 . 2009-08-12 17:47 8192 c:\windows\ERDNT\AutoBackup\8-12-2009\Users\00000002\UsrClass.dat
+ 2008-10-16 21:07 . 2008-10-16 21:07 208744 c:\windows\SYSTEM32\muweb.dll
+ 2009-08-13 17:00 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\8-13-2009\ERDNT.EXE
+ 2009-08-12 17:47 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\8-12-2009\ERDNT.EXE
+ 2009-08-13 17:00 . 2009-08-13 17:00 5259264 c:\windows\ERDNT\AutoBackup\8-13-2009\Users\00000001\NTUSER.DAT
+ 2009-08-12 17:47 . 2009-08-12 17:47 5165056 c:\windows\ERDNT\AutoBackup\8-12-2009\Users\00000001\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="c:\windows\system32\NVMCTRAY.DLL" [2003-07-28 49152]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"NVIEW"="nview.dll" - c:\windows\SYSTEM32\nview.dll [2003-07-28 852038]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellTouch"="c:\windows\MMKeybd.exe" [2002-01-17 163840]
"AdaptecDirectCD"="c:\program files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" [2001-09-04 655360]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"AHQInit"="c:\program files\Creative\SBLive\Program\AHQInit.exe" [2001-03-28 102400]
"Jet Detection"="c:\program files\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-11-29 28672]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2004-06-03 204800]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 172032]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"FLMK08KB"="c:\program files\Multimedia keyboard utility\1.3\MMKEYBD.EXE" [2005-07-28 207360]
"Disc Detector"="c:\program files\Creative\ShareDLL\CtNotify.exe" [1999-08-30 189952]
"au"="c:\program files\Dealio\DealioAU.exe" [2008-05-27 595296]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-14 177472]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"Lexmark X73 Button Monitor"="c:\progra~1\LEXMAR~1\ACMonitor_X73.exe" [2001-10-08 53248]
"Lexmark X73 Button Manager"="c:\progra~1\LEXMAR~1\AcBtnMgr_X73.exe" [2001-07-11 53248]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\SYSTEM32\narrator.exe [2008-04-14 53760]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2009-08-14 03:50 10536 ----a-w- c:\program files\Citrix\GoToAssist\516\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0aswBoot.exe /A:* /L:English /KBD:2

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R3 Msikbd2k;DellTouch;c:\windows\SYSTEM32\DRIVERS\Msikbd2k.sys [12/22/2001 9:51 AM 6656]
S1 aswSP;avast! Self Protection;c:\windows\SYSTEM32\DRIVERS\aswSP.sys [8/13/2009 11:11 PM 114768]
S1 e740e0ab;e740e0ab;c:\windows\system32\drivers\e740e0ab.sys --> c:\windows\system32\drivers\e740e0ab.sys [?]
S2 0084901250223732mcinstcleanup;McAfee Application Installer Cleanup (0084901250223732);c:\docume~1\RUSSEL~1\LOCALS~1\Temp\008490~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service --> c:\docume~1\RUSSEL~1\LOCALS~1\Temp\008490~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]
S2 aswFsBlk;aswFsBlk;c:\windows\SYSTEM32\DRIVERS\aswFsBlk.sys [8/13/2009 11:11 PM 20560]
S2 Nhksrv;Netropa NHK Server;c:\windows\Nhksrv.exe [12/31/1979 11:00 PM 28672]
S2 oulzeryoudmyt;oulzeryoudmyt;\??\c:\windows\system32\drivers\ywmrpblkntqaty.sys --> c:\windows\system32\drivers\ywmrpblkntqaty.sys [?]
S3 Wdm1;USB Bridge Cable Driver;c:\windows\SYSTEM32\DRIVERS\usbbc.sys [6/2/2002 12:40 PM 15576]
.
Contents of the 'Scheduled Tasks' folder

2009-08-13 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\progra~1\SPYBOT~1\SpybotSD.exe [2008-02-15 23:31]
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-MCODS


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/advanced_search?hl=en
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: {{0264505A-6793-44E0-AC75-9DCE3B13185C} - c:\program files\AT&T\WnClient\Programs\AnyWho.exe
IE: {{9239E4EC-C9A6-11D2-A844-00C04F68D538}
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: turbotax.com
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-14 08:42
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Disc Detector = c:\program files\Creative\ShareDLL\CtNotify.exe?X???????????????? C?????Disc Detector?B???A???????A???????B???@?$?@?? C?????U?@?????????@?B???A???????A?p?????B???@?????P???$?@? ???????~?B~??????????@?A?????????????????B?????|?????????????????????????????B

scanning hidden files ...


**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(464)
c:\program files\Citrix\GoToAssist\516\G2AWinLogon.dll

- - - - - - - > 'winlogon.exe'(220)
c:\program files\Citrix\GoToAssist\516\G2AWinLogon.dll

- - - - - - - > 'explorer.exe'(1188)
c:\program files\Microsoft Office\Office10\msohev.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCR80.dll
.
Completion time: 2009-08-14 8:47
ComboFix-quarantined-files.txt 2009-08-14 15:46
ComboFix2.txt 2009-08-12 16:50

Pre-Run: 5,481,066,496 bytes free
Post-Run: 5,552,816,128 bytes free

201 --- E O F --- 2009-05-13 14:26

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:49:00 AM, on 8/14/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\Citrix\GoToAssist\516\G2AProcessFactory.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Documents and Settings\Russell Radcliffe\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: CSMHelperObj Class - {0F660F64-F4C9-477F-8529-44181B717472} - C:\Program Files\AT&T\WnClient\Programs\CSMBHO.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:\Program Files\Dealio\kb127\Dealio.dll
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\MMKeybd.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [FLMK08KB] C:\Program Files\Multimedia keyboard utility\1.3\MMKEYBD.EXE
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [au] C:\Program Files\Dealio\DealioAU.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Lexmark X73 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
O4 - HKLM\..\Run: [Lexmark X73 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKUS\S-1-5-21-2771580065-4282951562-813958858-500\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Administrator')
O4 - HKUS\S-1-5-21-2771580065-4282951562-813958858-500\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Administrator')
O4 - HKUS\S-1-5-21-2771580065-4282951562-813958858-500\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe (User 'Administrator')
O4 - HKUS\S-1-5-21-2771580065-4282951562-813958858-500\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User 'Administrator')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - S-1-5-21-2771580065-4282951562-813958858-500 Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'Administrator')
O4 - S-1-5-21-2771580065-4282951562-813958858-500 User Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'Administrator')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AnyWho - {0264505A-6793-44E0-AC75-9DCE3B13185C} - C:\Program Files\AT&T\WnClient\Programs\AnyWho.exe (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {9239E4EC-C9A6-11D2-A844-00C04F68D538} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb127\Dealio.dll
O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb127\Dealio.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20070501/qtinstall.info.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (MSN Games – Matchmaking) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...pple.com/mickey/us/win/QuickTimeInstaller.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (MSN Games – Game Chat) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1250193754906
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
O16 - DPF: {C52439A0-2693-4E40-B141-9F9AD5257241} (Lexmark eDiagnostics Class) - https://ediagnostics.lexmark.com/serval.cab
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} (Photodex Presenter AX control) - http://www.photodex.com/pxplay.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup161.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5230/mcfscan.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - (no file)
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\516\G2AWinLogon.dll
O23 - Service: McAfee Application Installer Cleanup (0084901250223732) (0084901250223732mcinstcleanup) - Unknown owner - C:\DOCUME~1\RUSSEL~1\LOCALS~1\Temp\008490~1.EXE (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\516\g2aservice.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\WINDOWS\Nhksrv.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O24 - Desktop Component 0: (no name) - http://www.tripcheck.com/roadcams/cams/WillamettePass_pid658.jpg

--
End of file - 12089 bytes
 
Back
Top