Hello and thanks for your time. 2 days ago my dad downloaded this ActiveX plugin and caught this virus that keeps crashing Windows explorer by overloading on IE tabs. It tries to do this any time a different web page is loaded through AOL or IE, but doesn't react when using Firefox.
I have run S&D and it found 96 inital items, most of which were cookies, but found 7 Zlob entries and several references to Virtumonde entries. It removed all but 1 Zlob entry, but I am still having as much trouble now as before so nothing solved there yet. I ran S&D again and it found, but was unable to remove the 1 Zlob entry again, but that was the only thing it found. I then ran both the CA and Trend Micro scans and both came up with nothing.
Here are the generated reports.
--- Report generated: 2007-07-31 20:21 ---
SpyLocked.FakeAlert: Uninstall settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Safety Alert
VirusProtectPro: Link (File, fixed)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VirusProtectPro\Uninstall VirusProtectPro 3.5.lnk
VirusProtectPro: Link (File, fixed)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VirusProtectPro\VirusProtectPro 3.5.lnk
Zlob.VideoActiveXAccess: User settings (Registry value, fixed)
HKEY_USERS\S-1-5-21-2922032724-3356562638-220989508-1000\Software\Security Tools\Path=...C:\Program Files\Video ActiveX Access...
Zlob.VideoActiveXAccess: Program directory (Directory, fixing failed)
C:\Program Files\Video ActiveX Access\
Zlob.VideoActiveXAccess: Data (File, fixed)
C:\Program Files\Video ActiveX Access\ts.ico
Virtumonde: User settings (Registry key, fixed)
HKEY_USERS\S-1-5-21-2922032724-3356562638-220989508-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{09F1ADAC-76D8-4D0F-99A5-5C907DADB988}
Zlob.VideoActiveXAccess: IE toolbar (Registry value, fixed)
HKEY_USERS\S-1-5-21-2922032724-3356562638-220989508-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{29C5A3B6-9A8D-4FA0-B5AD-3E20F4AA5C00}
Zlob.VideoActiveXAccess: IE toolbar (Registry value, fixed)
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\{29C5A3B6-9A8D-4FA0-B5AD-3E20F4AA5C00}
Zlob.VideoActiveXAccess: Library (File, fixed)
C:\Program Files\Video ActiveX Access\iesplg.dll
Zlob.VideoActiveXAccess: Library (File, fixed)
C:\Program Files\Video ActiveX Access\iesbpl.dll
Zlob.VideoActiveXObject: Executable (File, fixed)
C:\Program Files\Video ActiveX Access\iesmin.exe
AdRevolver: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
Bluemountain: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
DirectTrack: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
Clickbank: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
BlueStreak: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
DoubleClick: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
CasaleMedia: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
Virtumonde: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
AdRevolver: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
FastClick: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
HitBox: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
SexTracker: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
HitBox: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
Win32.Small.ddx: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
SexList: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
TagASaurus: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
HitBox: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
Zedo: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
SexTracker: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
DirectTrack: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
WebTrends live: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
Advertising.com: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
MediaPlex: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
DirectTrack: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
Statcounter: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
Zedo: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
SexTracker: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
SexTracker: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
SexTracker: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
SexTracker: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
ReliableStats: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
ErrorSafe: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
SexTracker: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
HitBox: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
HitBox: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
ErrorSafe: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
HitBox: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
SexTracker: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
SexTracker: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
SexTracker: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
HitBox: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
SexTracker: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
CasaleMedia: Tracking cookie (Firefox: default) (Cookie, fixed)
CasaleMedia: Tracking cookie (Firefox: default) (Cookie, fixed)
CasaleMedia: Tracking cookie (Firefox: default) (Cookie, fixed)
CasaleMedia: Tracking cookie (Firefox: default) (Cookie, fixed)
CasaleMedia: Tracking cookie (Firefox: default) (Cookie, fixed)
DoubleClick: Tracking cookie (Firefox: default) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: default) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: default) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: default) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: default) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: default) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: default) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: default) (Cookie, fixed)
FastClick: Tracking cookie (Firefox: default) (Cookie, fixed)
Virtumonde: Tracking cookie (Firefox: default) (Cookie, fixed)
Win32.Small.ddx: Tracking cookie (Firefox: default) (Cookie, fixed)
Win32.Small.ddx: Tracking cookie (Firefox: default) (Cookie, fixed)
Win32.Small.ddx: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexTracker: Tracking cookie (Firefox: default) (Cookie, fixed)
Statcounter: Tracking cookie (Firefox: default) (Cookie, fixed)
Statcounter: Tracking cookie (Firefox: default) (Cookie, fixed)
Zedo: Tracking cookie (Firefox: default) (Cookie, fixed)
Zedo: Tracking cookie (Firefox: default) (Cookie, fixed)
Zedo: Tracking cookie (Firefox: default) (Cookie, fixed)
SexTracker: Tracking cookie (Firefox: default) (Cookie, fixed)
--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---
2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2007-07-31 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2007-05-23 advcheck.dll (1.5.3.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2007-01-02 Tools.dll (2.0.1.0)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2007-07-25 Includes\Cookies.sbi (*)
2007-07-25 Includes\Dialer.sbi (*)
2007-07-25 Includes\DialerC.sbi (*)
2007-07-11 Includes\Hijackers.sbi (*)
2007-07-25 Includes\HijackersC.sbi (*)
2007-07-25 Includes\Keyloggers.sbi (*)
2007-07-25 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2007-07-25 Includes\Malware.sbi (*)
2007-07-25 Includes\MalwareC.sbi (*)
2007-07-11 Includes\PUPS.sbi (*)
2007-07-25 Includes\PUPSC.sbi (*)
2007-07-25 Includes\Revision.sbi (*)
2007-05-30 Includes\Security.sbi (*)
2007-07-25 Includes\SecurityC.sbi (*)
2007-07-11 Includes\Spybots.sbi (*)
2007-07-25 Includes\SpybotsC.sbi (*)
2005-02-17 Includes\Tracks.uti
2007-07-25 Includes\Trojans.sbi (*)
2007-07-25 Includes\TrojansC.sbi (*)
2007-06-06 Plugins\TCPIPAddress.dll
-----------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:30:06 AM, on 8/2/2007
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Boot mode: Safe mode
Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.camelotherald.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=71&bd=Pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=71&bd=Pavilion&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: (no name) - {34E6F97C-34E0-4CE5-B92B-F83634BEDC01} - C:\Program Files\Video ActiveX Access\iesplg.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
O2 - BHO: (no name) - {CF46BFB3-2ACC-441b-B82B-36B9562C7FF1} - C:\Windows\system32\__c0022D3F.dat
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "c:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1173461808\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\Windows\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.0\AOL.EXE" -b
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Connections.lnk = C:\Program Files\HP Connections\6811507\Program\HP Connections.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O13 - Gopher Prefix:
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - AppInit_DLLs: C:\Windows\system32\__c00C54E9.dat
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\Windows\System32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 9074 bytes
I have run S&D and it found 96 inital items, most of which were cookies, but found 7 Zlob entries and several references to Virtumonde entries. It removed all but 1 Zlob entry, but I am still having as much trouble now as before so nothing solved there yet. I ran S&D again and it found, but was unable to remove the 1 Zlob entry again, but that was the only thing it found. I then ran both the CA and Trend Micro scans and both came up with nothing.
Here are the generated reports.
--- Report generated: 2007-07-31 20:21 ---
SpyLocked.FakeAlert: Uninstall settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Safety Alert
VirusProtectPro: Link (File, fixed)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VirusProtectPro\Uninstall VirusProtectPro 3.5.lnk
VirusProtectPro: Link (File, fixed)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VirusProtectPro\VirusProtectPro 3.5.lnk
Zlob.VideoActiveXAccess: User settings (Registry value, fixed)
HKEY_USERS\S-1-5-21-2922032724-3356562638-220989508-1000\Software\Security Tools\Path=...C:\Program Files\Video ActiveX Access...
Zlob.VideoActiveXAccess: Program directory (Directory, fixing failed)
C:\Program Files\Video ActiveX Access\
Zlob.VideoActiveXAccess: Data (File, fixed)
C:\Program Files\Video ActiveX Access\ts.ico
Virtumonde: User settings (Registry key, fixed)
HKEY_USERS\S-1-5-21-2922032724-3356562638-220989508-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{09F1ADAC-76D8-4D0F-99A5-5C907DADB988}
Zlob.VideoActiveXAccess: IE toolbar (Registry value, fixed)
HKEY_USERS\S-1-5-21-2922032724-3356562638-220989508-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{29C5A3B6-9A8D-4FA0-B5AD-3E20F4AA5C00}
Zlob.VideoActiveXAccess: IE toolbar (Registry value, fixed)
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\{29C5A3B6-9A8D-4FA0-B5AD-3E20F4AA5C00}
Zlob.VideoActiveXAccess: Library (File, fixed)
C:\Program Files\Video ActiveX Access\iesplg.dll
Zlob.VideoActiveXAccess: Library (File, fixed)
C:\Program Files\Video ActiveX Access\iesbpl.dll
Zlob.VideoActiveXObject: Executable (File, fixed)
C:\Program Files\Video ActiveX Access\iesmin.exe
AdRevolver: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
Bluemountain: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
DirectTrack: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
Clickbank: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
BlueStreak: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
DoubleClick: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
CasaleMedia: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
Virtumonde: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
AdRevolver: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
FastClick: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
HitBox: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
SexTracker: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
HitBox: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
Win32.Small.ddx: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
SexList: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
TagASaurus: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
HitBox: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
Zedo: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
SexTracker: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
DirectTrack: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
WebTrends live: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
Advertising.com: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
MediaPlex: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
DirectTrack: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
Statcounter: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
Zedo: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
SexTracker: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
SexTracker: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
SexTracker: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
SexTracker: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
ReliableStats: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
ErrorSafe: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
SexTracker: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
HitBox: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
HitBox: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
ErrorSafe: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
HitBox: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
SexTracker: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
SexTracker: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
SexTracker: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
HitBox: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
SexTracker: Tracking cookie (Internet Explorer: Sliph24) (Cookie, fixed)
CasaleMedia: Tracking cookie (Firefox: default) (Cookie, fixed)
CasaleMedia: Tracking cookie (Firefox: default) (Cookie, fixed)
CasaleMedia: Tracking cookie (Firefox: default) (Cookie, fixed)
CasaleMedia: Tracking cookie (Firefox: default) (Cookie, fixed)
CasaleMedia: Tracking cookie (Firefox: default) (Cookie, fixed)
DoubleClick: Tracking cookie (Firefox: default) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: default) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: default) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: default) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: default) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: default) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: default) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: default) (Cookie, fixed)
FastClick: Tracking cookie (Firefox: default) (Cookie, fixed)
Virtumonde: Tracking cookie (Firefox: default) (Cookie, fixed)
Win32.Small.ddx: Tracking cookie (Firefox: default) (Cookie, fixed)
Win32.Small.ddx: Tracking cookie (Firefox: default) (Cookie, fixed)
Win32.Small.ddx: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexList: Tracking cookie (Firefox: default) (Cookie, fixed)
SexTracker: Tracking cookie (Firefox: default) (Cookie, fixed)
Statcounter: Tracking cookie (Firefox: default) (Cookie, fixed)
Statcounter: Tracking cookie (Firefox: default) (Cookie, fixed)
Zedo: Tracking cookie (Firefox: default) (Cookie, fixed)
Zedo: Tracking cookie (Firefox: default) (Cookie, fixed)
Zedo: Tracking cookie (Firefox: default) (Cookie, fixed)
SexTracker: Tracking cookie (Firefox: default) (Cookie, fixed)
--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---
2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2007-07-31 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2007-05-23 advcheck.dll (1.5.3.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2007-01-02 Tools.dll (2.0.1.0)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2007-07-25 Includes\Cookies.sbi (*)
2007-07-25 Includes\Dialer.sbi (*)
2007-07-25 Includes\DialerC.sbi (*)
2007-07-11 Includes\Hijackers.sbi (*)
2007-07-25 Includes\HijackersC.sbi (*)
2007-07-25 Includes\Keyloggers.sbi (*)
2007-07-25 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2007-07-25 Includes\Malware.sbi (*)
2007-07-25 Includes\MalwareC.sbi (*)
2007-07-11 Includes\PUPS.sbi (*)
2007-07-25 Includes\PUPSC.sbi (*)
2007-07-25 Includes\Revision.sbi (*)
2007-05-30 Includes\Security.sbi (*)
2007-07-25 Includes\SecurityC.sbi (*)
2007-07-11 Includes\Spybots.sbi (*)
2007-07-25 Includes\SpybotsC.sbi (*)
2005-02-17 Includes\Tracks.uti
2007-07-25 Includes\Trojans.sbi (*)
2007-07-25 Includes\TrojansC.sbi (*)
2007-06-06 Plugins\TCPIPAddress.dll
-----------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:30:06 AM, on 8/2/2007
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Boot mode: Safe mode
Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.camelotherald.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=71&bd=Pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=71&bd=Pavilion&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: (no name) - {34E6F97C-34E0-4CE5-B92B-F83634BEDC01} - C:\Program Files\Video ActiveX Access\iesplg.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
O2 - BHO: (no name) - {CF46BFB3-2ACC-441b-B82B-36B9562C7FF1} - C:\Windows\system32\__c0022D3F.dat
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "c:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1173461808\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\Windows\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.0\AOL.EXE" -b
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Connections.lnk = C:\Program Files\HP Connections\6811507\Program\HP Connections.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O13 - Gopher Prefix:
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - AppInit_DLLs: C:\Windows\system32\__c00C54E9.dat
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\Windows\System32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 9074 bytes