Recommended Driver Scanner

Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » Suspected Malware? What is it?

[Fixed] Hijackthis! Logs - Suspected Malware? What is it? posted in the Security & Safety forums; As the directions stated, I ran the scanner and only one box appeared. I am not sure if this is the correct information, but this is all I have from ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 08-19-2008
Bronze Member
 
Join Date: Aug 2008
Posts: 15
PC Experience: Beginner
DellUser2008 - See this Members User comments on their Profile page
Exclamation Suspected Malware? What is it?

As the directions stated, I ran the scanner and only one box appeared. I am not sure if this is the correct information, but this is all I have from the scan:

---------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:27:04 PM, on 8/19/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\lphctvhj0e553.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\EDiaz\My Documents\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\s wg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [advap32] C:\DOCUME~1\STEPHA~1\LOCALS~1\Temp\Wjcv.exe/r
O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup
O4 - HKLM\..\Run: [lanmanwrk.exe clean] C:\WINDOWS\System32\lanmanwrk.exe clean
O4 - HKLM\..\Run: [KernelDrv.exe clean] C:\WINDOWS\System32\KernelDrv.exe clean
O4 - HKLM\..\Run: [lphctvhj0e553] C:\WINDOWS\system32\lphctvhj0e553.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
O4 - Startup: wkcalrem.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
O4 - Global Startup: WG111v2 Smart Wizard Wireless Setting.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1219115839502
O20 - Winlogon Notify: WinCtrl32 - C:\WINDOWS\SYSTEM32\WinCtrl32.dll
O23 - Service: Alerter Alerterlanmanserver (Alerterlanmanserver) - Unknown owner - C:\WINDOWS\
O23 - Service: Alerter Alerterlanmanserver AlerterlanmanserverBITSNtLmSspNetDDE (AlerterlanmanserverBITSNtLmSspNetDDE) - Unknown owner - C:\WINDOWS\
O23 - Service: Application Layer Gateway Service ALGTrkWksCryptSvclanmanworkstation (ALGTrkWksCryptSvclanmanworkstation) - Unknown owner - C:\WINDOWS\
O23 - Service: Application Management AppMgmtAudioSrv (AppMgmtAudioSrv) - Unknown owner - C:\WINDOWS\
O23 - Service: Application Management AppMgmtAudioSrv AppMgmtAudioSrvlanmanworkstation (AppMgmtAudioSrvlanmanworkstation) - Unknown owner - C:\WINDOWS\
O23 - Service: Application Management AppMgmtAudioSrv AppMgmtAudioSrvlanmanworkstation AppMgmtAudioSrvlanmanworkstationCiSvcAlerterFastUs erSwitchingCompatibilitySwPrv (AppMgmtAudioSrvlanmanworkstationCiSvcAlerterFastU serSwitchingCompatibilitySwPrv) - Unknown owner - C:\WINDOWS\
O23 - Service: Application Management AppMgmtDcomLaunchAppMgmtSwPrv (AppMgmtDcomLaunchAppMgmtSwPrv) - Unknown owner - C:\WINDOWS\
O23 - Service: Application Management AppMgmtDcomLaunchAppMgmtSwPrv AppMgmtDcomLaunchAppMgmtSwPrvDcomLaunchSamSs (AppMgmtDcomLaunchAppMgmtSwPrvDcomLaunchSamSs) - Unknown owner - C:\WINDOWS\
O23 - Service: Application Management AppMgmtSwPrv (AppMgmtSwPrv) - Unknown owner - C:\WINDOWS\
O23 - Service: Application Management AppMgmtWudfSvc (AppMgmtWudfSvc) - Unknown owner - C:\WINDOWS\
O23 - Service: Application Management AppMgmtWudfSvc AppMgmtWudfSvcwinmgmtFastUserSwitchingCompatibilit yTermServiceSysmonLog (AppMgmtWudfSvcwinmgmtFastUserSwitchingCompatibili tyTermServiceSysmonLog) - Unknown owner - C:\WINDOWS\
O23 - Service: Application Management AppMgmtWudfSvc AppMgmtWudfSvcwinmgmtFastUserSwitchingCompatibilit yTermServiceSysmonLog AppMgmtWudfSvcwinmgmtFastUserSwitchingCompatibilit yTermServiceSysmonLogaspnet_state (AppMgmtWudfSvcwinmgmtFastUserSwitchingCompatibili tyTermServiceSysmonLogaspnet_state) - Unknown owner - C:\WINDOWS\
O23 - Service: Application Management AppMgmtWudfSvc AppMgmtWudfSvcwinmgmtFastUserSwitchingCompatibilit yTermServiceSysmonLog AppMgmtWudfSvcwinmgmtFastUserSwitchingCompatibilit yTermServiceSysmonLogSSDPSRVPctspkhelpsvcSpoolerFa stUserSwitchingCompatibilityTermServiceNetDDE (AppMgmtWudfSvcwinmgmtFastUserSwitchingCompatibili tyTermServiceSysmonLogSSDPSRVPctspkhelpsvcSpoolerF astUserSwitchingCompatibilityTermServiceNetDDE) - Unknown owner - C:\WINDOWS\
O23 - Service: Application Management AppMgmtWudfSvc AppMgmtWudfSvcxmlprov (AppMgmtWudfSvcxmlprov) - Unknown owner - C:\WINDOWS\
O23 - Service: Application Management AppMgmtWudfSvc AppMgmtWudfSvcxmlprov AppMgmtWudfSvcxmlprovAlerter (AppMgmtWudfSvcxmlprovAlerter) - Unknown owner - C:\WINDOWS\
O23 - Service: ASP.NET State Service aspnet_stateRasAutoCOMSysApp (aspnet_stateRasAutoCOMSysApp) - Unknown owner - C:\WINDOWS\
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Background Intelligent Transfer Service BITSmnmsrvc (BITSmnmsrvc) - Unknown owner - C:\WINDOWS\
O23 - Service: Background Intelligent Transfer Service BITSmnmsrvc BITSmnmsrvcFastUserSwitchingCompatibilityTermServi ceThemesEventSystemRasMan (BITSmnmsrvcFastUserSwitchingCompatibilityTermServ iceThemesEventSystemRasMan) - Unknown owner - C:\WINDOWS\
O23 - Service: Background Intelligent Transfer Service BITSNtLmSsp (BITSNtLmSsp) - Unknown owner - C:\WINDOWS\
O23 - Service: Background Intelligent Transfer Service BITSNtLmSsp BITSNtLmSspEventSystemRasManALGPctspkTrkWks (BITSNtLmSspEventSystemRasManALGPctspkTrkWks) - Unknown owner - C:\WINDOWS\
O23 - Service: Background Intelligent Transfer Service BITSNtLmSsp BITSNtLmSspNetDDE (BITSNtLmSspNetDDE) - Unknown owner - C:\WINDOWS\
O23 - Service: Background Intelligent Transfer Service BITSNtLmSsp BITSNtLmSspNetDDE BITSNtLmSspNetDDECiSvc (BITSNtLmSspNetDDECiSvc) - Unknown owner - C:\WINDOWS\
O23 - Service: Background Intelligent Transfer Service BITSNtLmSsp BITSNtLmSspNetDDEHTTPFilter (BITSNtLmSspNetDDEHTTPFilter) - Unknown owner - C:\WINDOWS\
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bonjour Service BonjourSchedule (BonjourSchedule) - Unknown owner - C:\WINDOWS\
O23 - Service: Computer Browser Browserwinmgmtdmadmin (Browserwinmgmtdmadmin) - Unknown owner - C:\WINDOWS\
O23 - Service: Indexing Service CiSvcAlerter (CiSvcAlerter) - Unknown owner - C:\WINDOWS\
O23 - Service: Indexing Service CiSvcAlerter CiSvcAlerterFastUserSwitchingCompatibility (CiSvcAlerterFastUserSwitchingCompatibility) - Unknown owner - C:\WINDOWS\
O23 - Service: Indexing Service CiSvcAlerter CiSvcAlerterFastUserSwitchingCompatibility CiSvcAlerterFastUserSwitchingCompatibilitySwPrv (CiSvcAlerterFastUserSwitchingCompatibilitySwPrv) - Unknown owner - C:\WINDOWS\
O23 - Service: Indexing Service CiSvcCryptSvcNetlogon (CiSvcCryptSvcNetlogon) - Unknown owner - C:\WINDOWS\
O23 - Service: Indexing Service CiSvcThemes (CiSvcThemes) - Unknown owner - C:\WINDOWS\
O23 - Service: Indexing Service CiSvcThemes CiSvcThemesRpcSsseclogon (CiSvcThemesRpcSsseclogon) - Unknown owner - C:\WINDOWS\
O23 - Service: COM+ System Application COMSysAppPctspkTrkWks (COMSysAppPctspkTrkWks) - Unknown owner - C:\WINDOWS\
O23 - Service: COM+ System Application COMSysAppPctspkTrkWks COMSysAppPctspkTrkWks HotKey Poller (COMSysAppPctspkTrkWks HotKey Poller) - Unknown owner - C:\WINDOWS\
O23 - Service: COM+ System Application COMSysAppPctspkTrkWks COMSysAppPctspkTrkWksPlugPlay (COMSysAppPctspkTrkWksPlugPlay) - Unknown owner - C:\WINDOWS\
O23 - Service: COM+ System Application COMSysAppPolicyAgent (COMSysAppPolicyAgent) - Unknown owner - C:\WINDOWS\
O23 - Service: COM+ System Application COMSysAppPolicyAgent COMSysAppPolicyAgentTrkWksFastUserSwitchingCompati bilityCiSvcAlerter (COMSysAppPolicyAgentTrkWksFastUserSwitchingCompat ibilityCiSvcAlerter) - Unknown owner - C:\WINDOWS\
O23 - Service: COM+ System Application COMSysAppPolicyAgent COMSysAppPolicyAgentTrkWksFastUserSwitchingCompati bilityCiSvcAlerter COMSysAppPolicyAgentTrkWksFastUserSwitchingCompati bilityCiSvcAlerterRpcSsNetlogon (COMSysAppPolicyAgentTrkWksFastUserSwitchingCompat ibilityCiSvcAlerterRpcSsNetlogon) - Unknown owner - C:\WINDOWS\
O23 - Service: COM+ System Application COMSysAppRasMan (COMSysAppRasMan) - Unknown owner - C:\WINDOWS\
O23 - Service: COM+ System Application COMSysAppVSSFastUserSwitchingCompatibilityCiSvcAle rter (COMSysAppVSSFastUserSwitchingCompatibilityCiSvcAl erter) - Unknown owner - C:\WINDOWS\
O23 - Service: Cryptographic Services CryptSvclanmanworkstation (CryptSvclanmanworkstation) - Unknown owner - C:\WINDOWS\
O23 - Service: Cryptographic Services CryptSvclanmanworkstation CryptSvclanmanworkstation Service (CryptSvclanmanworkstation Service) - Unknown owner - C:\WINDOWS\
O23 - Service: Cryptographic Services CryptSvclanmanworkstation CryptSvclanmanworkstation Service CryptSvclanmanworkstationCiSvcAlerterFastUserSwitc hingCompatibilitySwPrv (CryptSvclanmanworkstationCiSvcAlerterFastUserSwit chingCompatibilitySwPrv) - Unknown owner - C:\WINDOWS\
O23 - Service: Cryptographic Services CryptSvclanmanworkstation CryptSvclanmanworkstationSamSsWmiApSrvSCardSvrIDri verTdmadminRasAutoCOMSysAppupnphostTapiSrv (CryptSvclanmanworkstationSamSsWmiApSrvSCardSvrIDr iverTdmadminRasAutoCOMSysAppupnphostTapiSrv) - Unknown owner - C:\WINDOWS\
O23 - Service: Cryptographic Services CryptSvclanmanworkstation CryptSvclanmanworkstation Service CryptSvclanmanworkstationxmlprov (CryptSvclanmanworkstationxmlprov) - Unknown owner - C:\WINDOWS\
O23 - Service: Cryptographic Services CryptSvclanmanworkstation CryptSvclanmanworkstation Service CryptSvclanmanworkstationxmlprov CryptSvclanmanworkstationxmlprovRasManUPSRpcSsNetl ogonTrkWksWmdmPmSNSchedulewinmgmt (CryptSvclanmanworkstationxmlprovRasManUPSRpcSsNet logonTrkWksWmdmPmSNSchedulewinmgmt) - Unknown owner - C:\WINDOWS\
O23 - Service: Cryptographic Services CryptSvcNetlogon (CryptSvcNetlogon) - Unknown owner - C:\WINDOWS\
O23 - Service: Cryptographic Services CryptSvcNetlogon CryptSvcNetlogonSCardSvr (CryptSvcNetlogonSCardSvr) - Unknown owner - C:\WINDOWS\
O23 - Service: DCOM Server Process Launcher DcomLaunchAppMgmtSwPrv (DcomLaunchAppMgmtSwPrv) - Unknown owner - C:\WINDOWS\
O23 - Service: DCOM Server Process Launcher DcomLaunchAppMgmtSwPrv DcomLaunchAppMgmtSwPrvPolicyAgentRpcLocatorlanmans erverWebClientThemes (DcomLaunchAppMgmtSwPrvPolicyAgentRpcLocatorlanman serverWebClientThemes) - Unknown owner - C:\WINDOWS\
O23 - Service: DCOM Server Process Launcher DcomLaunchAppMgmtSwPrv DcomLaunchAppMgmtSwPrvThemesEventSystemRasMan (DcomLaunchAppMgmtSwPrvThemesEventSystemRasMan) - Unknown owner - C:\WINDOWS\
O23 - Service: DCOM Server Process Launcher DcomLaunchSamSs (DcomLaunchSamSs) - Unknown owner - C:\WINDOWS\
O23 - Service: Logical Disk Manager dmserverDcomLaunchAppMgmtSwPrv (dmserverDcomLaunchAppMgmtSwPrv) - Unknown owner - C:\WINDOWS\
O23 - Service: DNS Client DnscacheProtectedStorage (DnscacheProtectedStorage) - Unknown owner - C:\WINDOWS\
O23 - Service: DNS Client DnscacheProtectedStorage DnscacheProtectedStorageBITSmnmsrvc (DnscacheProtectedStorageBITSmnmsrvc) - Unknown owner - C:\WINDOWS\
O23 - Service: DNS Client DnscacheProtectedStorage DnscacheProtectedStorageIDriverT (DnscacheProtectedStorageIDriverT) - Unknown owner - C:\WINDOWS\
O23 - Service: DNS Client DnscacheWMPNetworkSvcRemoteAccessWmdmPmSN (DnscacheWMPNetworkSvcRemoteAccessWmdmPmSN) - Unknown owner - C:\WINDOWS\
O23 - Service: Error Reporting Service ERSvclanmanworkstation (ERSvclanmanworkstation) - Unknown owner - C:\WINDOWS\
O23 - Service: Error Reporting Service ERSvclanmanworkstation ERSvclanmanworkstationNetDDEdsdm (ERSvclanmanworkstationNetDDEdsdm) - Unknown owner - C:\WINDOWS\
O23 - Service: Event Log EventlogNetlogon (EventlogNetlogon) - Unknown owner - C:\WINDOWS\
O23 - Service: COM+ Event System EventSystemRasMan (EventSystemRasMan) - Unknown owner - C:\WINDOWS\
O23 - Service: COM+ Event System EventSystemRasMan EventSystemRasManALG (EventSystemRasManALG) - Unknown owner - C:\WINDOWS\
O23 - Service: COM+ Event System EventSystemRasMan EventSystemRasManALG EventSystemRasManALGPctspkTrkWks (EventSystemRasManALGPctspkTrkWks) - Unknown owner - C:\WINDOWS\
O23 - Service: COM+ Event System EventSystemRasMan EventSystemRasManALG EventSystemRasManALGwuauservRasAutoCOMSysApp (EventSystemRasManALGwuauservRasAutoCOMSysApp) - Unknown owner - C:\WINDOWS\
O23 - Service: Fast User Switching Compatibility FastUserSwitchingCompatibilityCiSvcAlerter (FastUserSwitchingCompatibilityCiSvcAlerter) - Unknown owner - C:\WINDOWS\
O23 - Service: Fast User Switching Compatibility FastUserSwitchingCompatibilityTermService (FastUserSwitchingCompatibilityTermService) - Unknown owner - C:\WINDOWS\
O23 - Service: Fast User Switching Compatibility FastUserSwitchingCompatibilityTermService FastUserSwitchingCompatibilityTermServiceNetDDE (FastUserSwitchingCompatibilityTermServiceNetDDE) - Unknown owner - C:\WINDOWS\
O23 - Service: Fast User Switching Compatibility FastUserSwitchingCompatibilityTermService FastUserSwitchingCompatibilityTermServiceThemesEve ntSystemRasMan (FastUserSwitchingCompatibilityTermServiceThemesEv entSystemRasMan) - Unknown owner - C:\WINDOWS\
O23 - Service: Fast User Switching Compatibility FastUserSwitchingCompatibilityTermService FastUserSwitchingCompatibilityTermServiceThemesEve ntSystemRasMan FastUserSwitchingCompatibilityTermServiceThemesEve ntSystemRasManClipSrv (FastUserSwitchingCompatibilityTermServiceThemesEv entSystemRasManClipSrv) - Unknown owner - C:\WINDOWS\
O23 - Service: Fast User Switching Compatibility FastUserSwitchingCompatibilityTermService FastUserSwitchingCompatibilityTermServiceThemesEve ntSystemRasMan FastUserSwitchingCompatibilityTermServiceThemesEve ntSystemRasManDnscacheProtectedStorage (FastUserSwitchingCompatibilityTermServiceThemesEv entSystemRasManDnscacheProtectedStorage) - Unknown owner - C:\WINDOWS\
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Help and Support helpsvcAppMgmtAudioSrv (helpsvcAppMgmtAudioSrv) - Unknown owner - C:\WINDOWS\
O23 - Service: Human Interface Device Access HidServFastUserSwitchingCompatibilityCiSvcAlerter (HidServFastUserSwitchingCompatibilityCiSvcAlerter ) - Unknown owner - C:\WINDOWS\
O23 - Service: Human Interface Device Access HidServFastUserSwitchingCompatibilityCiSvcAlerter HidServFastUserSwitchingCompatibilityCiSvcAlerterF astUserSwitchingCompatibilityTermServiceThemesEven tSystemRasManClipSrv (HidServFastUserSwitchingCompatibilityCiSvcAlerter FastUserSwitchingCompatibilityTermServiceThemesEve ntSystemRasManClipSrv) - Unknown owner - C:\WINDOWS\
O23 - Service: Human Interface Device Access HidServFastUserSwitchingCompatibilityCiSvcAlerter HidServFastUserSwitchingCompatibilityCiSvcAlerterS CardSvrIDriverT (HidServFastUserSwitchingCompatibilityCiSvcAlerter SCardSvrIDriverT) - Unknown owner - C:\WINDOWS\
O23 - Service: HTTP SSL HTTPFilterFastUserSwitchingCompatibilityCiSvcAlert er (HTTPFilterFastUserSwitchingCompatibilityCiSvcAler ter) - Unknown owner - C:\WINDOWS\
O23 - Service: HTTP SSL HTTPFilterFastUserSwitchingCompatibilityCiSvcAlert er HTTPFilterFastUserSwitchingCompatibilityCiSvcAlert erNtLmSsp (HTTPFilterFastUserSwitchingCompatibilityCiSvcAler terNtLmSsp) - Unknown owner - C:\WINDOWS\
O23 - Service: HTTP SSL HTTPFilterUPSRpcSsNetlogonTrkWks (HTTPFilterUPSRpcSsNetlogonTrkWks) - Unknown owner - C:\WINDOWS\
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service ImapiServiceBITS (ImapiServiceBITS) - Unknown owner - C:\WINDOWS\
O23 - Service: IMAPI CD-Burning COM Service ImapiServiceRpcLocator (ImapiServiceRpcLocator) - Unknown owner - C:\WINDOWS\
O23 - Service: IMAPI CD-Burning COM Service ImapiServiceRpcLocator ImapiServiceRpcLocatorWmiApSrv (ImapiServiceRpcLocatorWmiApSrv) - Unknown owner - C:\WINDOWS\
O23 - Service: Messenger MessengerPctspkTrkWks (MessengerPctspkTrkWks) - Unknown owner - C:\WINDOWS\
O23 - Service: Messenger MessengerPctspkTrkWks MessengerPctspkTrkWksNetDDEHTTPFilterTapiSrvNetDDE HTTPFilter (MessengerPctspkTrkWksNetDDEHTTPFilterTapiSrvNetDD EHTTPFilter) - Unknown owner - C:\WINDOWS\
O23 - Service: Messenger MessengerTrkWks (MessengerTrkWks) - Unknown owner - C:\WINDOWS\
O23 - Service: Messenger MessengerTrkWks MessengerTrkWksSENS (MessengerTrkWksSENS) - Unknown owner - C:\WINDOWS\
O23 - Service: Messenger MessengerTrkWks MessengerTrkWksSENS MessengerTrkWksSENSNetDDEHTTPFilterTapiSrvNetDDEHT TPFilter (MessengerTrkWksSENSNetDDEHTTPFilterTapiSrvNetDDEH TTPFilter) - Unknown owner - C:\WINDOWS\
O23 - Service: Messenger MessengerTrkWks MessengerTrkWksSENS MessengerTrkWksSENSNetDDEHTTPFilterTapiSrvNetDDEHT TPFilter MessengerTrkWksSENSNetDDEHTTPFilterTapiSrvNetDDEHT TPFilterMessengerTrkWksSENS (MessengerTrkWksSENSNetDDEHTTPFilterTapiSrvNetDDEH TTPFilterMessengerTrkWksSENS) - Unknown owner - C:\WINDOWS\
O23 - Service: Messenger MessengerTrkWks MessengerTrkWksSENS MessengerTrkWksSENSwinmgmtFastUserSwitchingCompati bilityTermServiceSysmonLogHidServ (MessengerTrkWksSENSwinmgmtFastUserSwitchingCompat ibilityTermServiceSysmonLogHidServ) - Unknown owner - C:\WINDOWS\
O23 - Service: Network DDE NetDDEHTTPFilter (NetDDEHTTPFilter) - Unknown owner - C:\WINDOWS\
O23 - Service: Network DDE NetDDEHTTPFilter NetDDEHTTPFilterTapiSrvNetDDEHTTPFilter (NetDDEHTTPFilterTapiSrvNetDDEHTTPFilter) - Unknown owner - C:\WINDOWS\
O23 - Service: Net Logon NetlogonCOMSysAppPctspkTrkWks (NetlogonCOMSysAppPctspkTrkWks) - Unknown owner - C:\WINDOWS\
O23 - Service: Removable Storage NtmsSvcNtLmSsp (NtmsSvcNtLmSsp) - Unknown owner - C:\WINDOWS\
O23 - Service: PCTEL Speaker Phone (Pctspk) - Unknown owner - C:\WINDOWS\system32\pctspk.exe
O23 - Service: PCTEL Speaker Phone PctspkTrkWks (PctspkTrkWks) - Unknown owner - C:\WINDOWS\
O23 - Service: PCTEL Speaker Phone PctspkVSSxmlprov (PctspkVSSxmlprov) - Unknown owner - C:\WINDOWS\
O23 - Service: IPSEC Services PolicyAgentNtmsSvc (PolicyAgentNtmsSvc) - Unknown owner - C:\WINDOWS\
O23 - Service: IPSEC Services PolicyAgentRpcLocator (PolicyAgentRpcLocator) - Unknown owner - C:\WINDOWS\
O23 - Service: IPSEC Services PolicyAgentRpcLocator PolicyAgentRpcLocatorlanmanserver (PolicyAgentRpcLocatorlanmanserver) - Unknown owner - C:\WINDOWS\
O23 - Service: IPSEC Services PolicyAgentRpcLocator PolicyAgentRpcLocatorlanmanserver PolicyAgentRpcLocatorlanmanserverWebClient (PolicyAgentRpcLocatorlanmanserverWebClient) - Unknown owner - C:\WINDOWS\
O23 - Service: IPSEC Services PolicyAgentRpcLocator PolicyAgentRpcLocatorlanmanserver PolicyAgentRpcLocatorlanmanserverWebClient PolicyAgentRpcLocatorlanmanserverWebClientThemes (PolicyAgentRpcLocatorlanmanserverWebClientThemes) - Unknown owner - C:\WINDOWS\
O23 - Service: IPSEC Services PolicyAgentW32Time (PolicyAgentW32Time) - Unknown owner - C:\WINDOWS\
O23 - Service: Protected Storage ProtectedStoragewinmgmtFastUserSwitchingCompatibil ityTermServiceupnphostCiSvcThemes (ProtectedStoragewinmgmtFastUserSwitchingCompatibi lityTermServiceupnphostCiSvcThemes) - Unknown owner - C:\WINDOWS\
O23 - Service: Remote Access Auto Connection Manager RasAutoCOMSysApp (RasAutoCOMSysApp) - Unknown owner - C:\WINDOWS\
O23 - Service: Remote Access Auto Connection Manager RasAutoCOMSysApp RasAutoCOMSysAppImapiServiceRpcLocator (RasAutoCOMSysAppImapiServiceRpcLocator) - Unknown owner - C:\WINDOWS\
O23 - Service: Remote Access Auto Connection Manager RasAutoCOMSysApp RasAutoCOMSysAppImapiServiceRpcLocator RasAutoCOMSysAppImapiServiceRpcLocatorFastUserSwit chingCompatibilityTermServiceThemesEventSystemRasM anClipSrv (RasAutoCOMSysAppImapiServiceRpcLocatorFastUserSwi tchingCompatibilityTermServiceThemesEventSystemRas ManClipSrv) - Unknown owner - C:\WINDOWS\
O23 - Service: Remote Access Auto Connection Manager RasAutoCOMSysAppRasMan (RasAutoCOMSysAppRasMan) - Unknown owner - C:\WINDOWS\
O23 - Service: Remote Access Connection Manager RasManUPSRpcSsNetlogonTrkWksWmdmPmSNSchedulewinmgm t (RasManUPSRpcSsNetlogonTrkWksWmdmPmSNSchedulewinmg mt) - Unknown owner - C:\WINDOWS\
O23 - Service: Remote Access Connection Manager RasManUPSRpcSsNetlogonTrkWksWmdmPmSNSchedulewinmgm t RasManUPSRpcSsNetlogonTrkWksWmdmPmSNSchedulewinmgm tCiSvc (RasManUPSRpcSsNetlogonTrkWksWmdmPmSNSchedulewinmg mtCiSvc) - Unknown owner - C:\WINDOWS\
O23 - Service: Remote Access Connection Manager RasManWmdmPmSNSchedule (RasManWmdmPmSNSchedule) - Unknown owner - C:\WINDOWS\
O23 - Service: Remote Procedure Call (RPC) Locator RpcLocatorWmiApSrvSCardSvrIDriverTdmadmin (RpcLocatorWmiApSrvSCardSvrIDriverTdmadmin) - Unknown owner - C:\WINDOWS\
O23 - Service: Remote Procedure Call (RPC) RpcSsMessenger (RpcSsMessenger) - Unknown owner - C:\WINDOWS\
O23 - Service: Remote Procedure Call (RPC) RpcSsMessenger RpcSsMessengerALG (RpcSsMessengerALG) - Unknown owner - C:\WINDOWS\
O23 - Service: Remote Procedure Call (RPC) RpcSsNetlogon (RpcSsNetlogon) - Unknown owner - C:\WINDOWS\
O23 - Service: Remote Procedure Call (RPC) RpcSsNetlogon RpcSsNetlogonCOMSysAppPctspkTrkWks (RpcSsNetlogonCOMSysAppPctspkTrkWks) - Unknown owner - C:\WINDOWS\
O23 - Service: Remote Procedure Call (RPC) RpcSsNetlogon RpcSsNetlogonCOMSysAppPctspkTrkWks RpcSsNetlogonCOMSysAppPctspkTrkWksTrkWksCryptSvcla nmanworkstation (RpcSsNetlogonCOMSysAppPctspkTrkWksTrkWksCryptSvcl anmanworkstation) - Unknown owner - C:\WINDOWS\
O23 - Service: Remote Procedure Call (RPC) RpcSsNetlogon RpcSsNetlogonTrkWks (RpcSsNetlogonTrkWks) - Unknown owner - C:\WINDOWS\
O23 - Service: Remote Procedure Call (RPC) RpcSsPolicyAgent (RpcSsPolicyAgent) - Unknown owner - C:\WINDOWS\
O23 - Service: Remote Procedure Call (RPC) RpcSsseclogon (RpcSsseclogon) - Unknown owner - C:\WINDOWS\
O23 - Service: Remote Procedure Call (RPC) RpcSsseclogon RpcSsseclogonlanmanserver (RpcSsseclogonlanmanserver) - Unknown owner - C:\WINDOWS\
O23 - Service: Remote Procedure Call (RPC) RpcSsseclogon RpcSsseclogonWmdmPmSNSchedule (RpcSsseclogonWmdmPmSNSchedule) - Unknown owner - C:\WINDOWS\
O23 - Service: Remote Procedure Call (RPC) RpcSsseclogon RpcSsseclogonWmdmPmSNSchedule RpcSsseclogonWmdmPmSNScheduleRSVP (RpcSsseclogonWmdmPmSNScheduleRSVP) - Unknown owner - C:\WINDOWS\
O23 - Service: Remote Procedure Call (RPC) RpcSsseclogon RpcSsseclogonWmdmPmSNSchedule RpcSsseclogonWmdmPmSNScheduleRSVP RpcSsseclogonWmdmPmSNScheduleRSVPRasManUPSRpcSsNet logonTrkWksWmdmPmSNSchedulewinmgmt (RpcSsseclogonWmdmPmSNScheduleRSVPRasManUPSRpcSsNe tlogonTrkWksWmdmPmSNSchedulewinmgmt) - Unknown owner - C:\WINDOWS\
O23 - Service: QoS RSVP RSVPBITSNtLmSspNetDDE (RSVPBITSNtLmSspNetDDE) - Unknown owner - C:\WINDOWS\
O23 - Service: Security Accounts Manager SamSsWmiApSrvSCardSvrIDriverTdmadmin (SamSsWmiApSrvSCardSvrIDriverTdmadmin) - Unknown owner - C:\WINDOWS\
O23 - Service: Security Accounts Manager SamSsWmiApSrvSCardSvrIDriverTdmadmin SamSsWmiApSrvSCardSvrIDriverTdmadminRasAutoCOMSysA pp (SamSsWmiApSrvSCardSvrIDriverTdmadminRasAutoCOMSys App) - Unknown owner - C:\WINDOWS\
O23 - Service: Security Accounts Manager SamSsWmiApSrvSCardSvrIDriverTdmadmin SamSsWmiApSrvSCardSvrIDriverTdmadminRasAutoCOMSysA pp SamSsWmiApSrvSCardSvrIDriverTdmadminRasAutoCOMSysA ppSysmonLogERSvc (SamSsWmiApSrvSCardSvrIDriverTdmadminRasAutoCOMSys AppSysmonLogERSvc) - Unknown owner - C:\WINDOWS\
O23 - Service: Security Accounts Manager SamSsWmiApSrvSCardSvrIDriverTdmadmin SamSsWmiApSrvSCardSvrIDriverTdmadminRasAutoCOMSysA pp SamSsWmiApSrvSCardSvrIDriverTdmadminRasAutoCOMSysA ppupnphostTapiSrv (SamSsWmiApSrvSCardSvrIDriverTdmadminRasAutoCOMSys AppupnphostTapiSrv) - Unknown owner - C:\WINDOWS\
O23 - Service: Smart Card SCardSvrIDriverT (SCardSvrIDriverT) - Unknown owner - C:\WINDOWS\
O23 - Service: Smart Card SCardSvrIDriverT SCardSvrIDriverTdmadmin (SCardSvrIDriverTdmadmin) - Unknown owner - C:\WINDOWS\
O23 - Service: Smart Card SCardSvrIDriverT SCardSvrIDriverTdmadmin SCardSvrIDriverTdmadminxmlprov (SCardSvrIDriverTdmadminxmlprov) - Unknown owner - C:\WINDOWS\
O23 - Service: Smart Card SCardSvrIDriverT SCardSvrIDriverTdmadmin SCardSvrIDriverTdmadminxmlprov SCardSvrIDriverTdmadminxmlprovTapiSrv (SCardSvrIDriverTdmadminxmlprovTapiSrv) - Unknown owner - C:\WINDOWS\
O23 - Service: Smart Card SCardSvrRpcSsMessengerALG (SCardSvrRpcSsMessengerALG) - Unknown owner - C:\WINDOWS\
O23 - Service: Task Scheduler ScheduleTrkWksFastUserSwitchingCompatibilityCiSvcA lerter (ScheduleTrkWksFastUserSwitchingCompatibilityCiSvc Alerter) - Unknown owner - C:\WINDOWS\
O23 - Service: Secondary Logon seclogonEventSystemRasMan (seclogonEventSystemRasMan) - Unknown owner - C:\WINDOWS\
O23 - Service: System Event Notification SENSEventSystem (SENSEventSystem) - Unknown owner - C:\WINDOWS\
O23 - Service: System Event Notification SENSEventSystem SENSEventSystemhelpsvcAppMgmtAudioSrv (SENSEventSystemhelpsvcAppMgmtAudioSrv) - Unknown owner - C:\WINDOWS\
O23 - Service: Shell Hardware Detection ShellHWDetectionTermServicesrserviceSENS (ShellHWDetectionTermServicesrserviceSENS) - Unknown owner - C:\WINDOWS\
O23 - Service: Shell Hardware Detection ShellHWDetectionWmiApSrvSCardSvrIDriverTdmadmin (ShellHWDetectionWmiApSrvSCardSvrIDriverTdmadmin) - Unknown owner - C:\WINDOWS\
O23 - Service: System Restore Service srserviceAudioSrv (srserviceAudioSrv) - Unknown owner - C:\WINDOWS\
O23 - Service: System Restore Service srserviceAudioSrv srserviceAudioSrvAppMgmtWudfSvcwinmgmtFastUserSwit chingCompatibilityTermServiceSysmonLogaspnet_state (srserviceAudioSrvAppMgmtWudfSvcwinmgmtFastUserSwi tchingCompatibilityTermServiceSysmonLogaspnet_stat e) - Unknown owner - C:\WINDOWS\
O23 - Service: System Restore Service srserviceAudioSrv srserviceAudioSrvProtectedStorage (srserviceAudioSrvProtectedStorage) - Unknown owner - C:\WINDOWS\
O23 - Service: System Restore Service srserviceSCardSvrIDriverTdmadminxmlprov (srserviceSCardSvrIDriverTdmadminxmlprov) - Unknown owner - C:\WINDOWS\
O23 - Service: System Restore Service srserviceSENS (srserviceSENS) - Unknown owner - C:\WINDOWS\
O23 - Service: SSDP Discovery Service SSDPSRVPctspk (SSDPSRVPctspk) - Unknown owner - C:\WINDOWS\
O23 - Service: SSDP Discovery Service SSDPSRVPctspk SSDPSRVPctspkhelpsvc (SSDPSRVPctspkhelpsvc) - Unknown owner - C:\WINDOWS\
O23 - Service: SSDP Discovery Service SSDPSRVPctspk SSDPSRVPctspkhelpsvc SSDPSRVPctspkhelpsvcSpooler (SSDPSRVPctspkhelpsvcSpooler) - Unknown owner - C:\WINDOWS\
O23 - Service: SSDP Discovery Service SSDPSRVPctspk SSDPSRVPctspkhelpsvc SSDPSRVPctspkhelpsvcSpooler SSDPSRVPctspkhelpsvcSpoolerFastUserSwitchingCompat ibilityTermServiceNetDDE (SSDPSRVPctspkhelpsvcSpoolerFastUserSwitchingCompa tibilityTermServiceNetDDE) - Unknown owner - C:\WINDOWS\
O23 - Service: SSDP Discovery Service SSDPSRVPctspk SSDPSRVPctspkhelpsvc SSDPSRVPctspkhelpsvcstisvc (SSDPSRVPctspkhelpsvcstisvc) - Unknown owner - C:\WINDOWS\
O23 - Service: SSDP Discovery Service SSDPSRVPctspk SSDPSRVPctspkhelpsvc SSDPSRVPctspkhelpsvcstisvc SSDPSRVPctspkhelpsvcstisvcmnmsrvc (SSDPSRVPctspkhelpsvcstisvcmnmsrvc) - Unknown owner - C:\WINDOWS\
O23 - Service: Windows Image Acquisition (WIA) stisvcMSIServer (stisvcMSIServer) - Unknown owner - C:\WINDOWS\
O23 - Service: Performance Logs and Alerts SysmonLogERSvc (SysmonLogERSvc) - Unknown owner - C:\WINDOWS\
O23 - Service: Telephony TapiSrvNetDDEHTTPFilter (TapiSrvNetDDEHTTPFilter) - Unknown owner - C:\WINDOWS\
O23 - Service: Telephony TapiSrvNetDDEHTTPFilter TapiSrvNetDDEHTTPFilterEventSystemRasManALG (TapiSrvNetDDEHTTPFilterEventSystemRasManALG) - Unknown owner - C:\WINDOWS\
O23 - Service: Terminal Services TermServicesrserviceSENS (TermServicesrserviceSENS) - Unknown owner - C:\WINDOWS\
O23 - Service: Terminal Services TermServicesrserviceSENS TermServicesrserviceSENSSwPrv (TermServicesrserviceSENSSwPrv) - Unknown owner - C:\WINDOWS\
O23 - Service: Terminal Services TermServicewuauservUPS (TermServicewuauservUPS) - Unknown owner - C:\WINDOWS\
O23 - Service: Terminal Services TermServicewuauservUPS TermServicewuauservUPSPolicyAgentRpcLocatorlanmans erverWebClientThemes (TermServicewuauservUPSPolicyAgentRpcLocatorlanman serverWebClientThemes) - Unknown owner - C:\WINDOWS\
O23 - Service: Terminal Services TermServicewuauservUPS TermServicewuauservUPSWmdmPmSNPolicyAgentRpcLocato rlanmanserverWebClientThemesAudioSrv (TermServicewuauservUPSWmdmPmSNPolicyAgentRpcLocat orlanmanserverWebClientThemesAudioSrv) - Unknown owner - C:\WINDOWS\
O23 - Service: Themes ThemesEventSystemRasMan (ThemesEventSystemRasMan) - Unknown owner - C:\WINDOWS\
O23 - Service: Themes ThemesNtmsSvc (ThemesNtmsSvc) - Unknown owner - C:\WINDOWS\
O23 - Service: Themes ThemesSCardSvrIDriverTdmadminxmlprovTapiSrv (ThemesSCardSvrIDriverTdmadminxmlprovTapiSrv) - Unknown owner - C:\WINDOWS\
O23 - Service: Themes ThemesSCardSvrIDriverTdmadminxmlprovTapiSrv ThemesSCardSvrIDriverTdmadminxmlprovTapiSrvHTTPFil ter (ThemesSCardSvrIDriverTdmadminxmlprovTapiSrvHTTPFi lter) - Unknown owner - C:\WINDOWS\
O23 - Service: Themes ThemesSCardSvrIDriverTdmadminxmlprovTapiSrv ThemesSCardSvrIDriverTdmadminxmlprovTapiSrvHTTPFil ter ThemesSCardSvrIDriverTdmadminxmlprovTapiSrvHTTPFil terThemesEventSystemRasMan (ThemesSCardSvrIDriverTdmadminxmlprovTapiSrvHTTPFi lterThemesEventSystemRasMan) - Unknown owner - C:\WINDOWS\
O23 - Service: Distributed Link Tracking Client TrkWksCryptSvclanmanworkstation (TrkWksCryptSvclanmanworkstation) - Unknown owner - C:\WINDOWS\
O23 - Service: Distributed Link Tracking Client TrkWksFastUserSwitchingCompatibilityCiSvcAlerter (TrkWksFastUserSwitchingCompatibilityCiSvcAlerter) - Unknown owner - C:\WINDOWS\
O23 - Service: Distributed Link Tracking Client TrkWksFastUserSwitchingCompatibilityCiSvcAlerter TrkWksFastUserSwitchingCompatibilityCiSvcAlerterSC ardSvrIDriverTdmadminxmlprovTapiSrv (TrkWksFastUserSwitchingCompatibilityCiSvcAlerterS CardSvrIDriverTdmadminxmlprovTapiSrv) - Unknown owner - C:\WINDOWS\
O23 - Service: Distributed Link Tracking Client TrkWksFastUserSwitchingCompatibilityCiSvcAlerter TrkWksFastUserSwitchingCompatibilityCiSvcAlerterst isvc (TrkWksFastUserSwitchingCompatibilityCiSvcAlerters tisvc) - Unknown owner - C:\WINDOWS\
O23 - Service: Universal Plug and Play Device Host upnphostEventlog (upnphostEventlog) - Unknown owner - C:\WINDOWS\
O23 - Service: Universal Plug and Play Device Host upnphostEventlog upnphostEventlogPctspkTrkWks (upnphostEventlogPctspkTrkWks) - Unknown owner - C:\WINDOWS\
O23 - Service: Universal Plug and Play Device Host upnphostEventlog upnphostEventlogTrkWks (upnphostEventlogTrkWks) - Unknown owner - C:\WINDOWS\
O23 - Service: Universal Plug and Play Device Host upnphostTapiSrv (upnphostTapiSrv) - Unknown owner - C:\WINDOWS\
O23 - Service: Universal Plug and Play Device Host upnphostTapiSrv upnphostTapiSrvgusvc (upnphostTapiSrvgusvc) - Unknown owner - C:\WINDOWS\
O23 - Service: Universal Plug and Play Device Host upnphostTapiSrv upnphostTapiSrvHTTPFilterUPSRpcSsNetlogonTrkWks (upnphostTapiSrvHTTPFilterUPSRpcSsNetlogonTrkWks) - Unknown owner - C:\WINDOWS\
O23 - Service: Universal Plug and Play Device Host upnphostTapiSrv upnphostTapiSrvRpcSsseclogonlanmanserver (upnphostTapiSrvRpcSsseclogonlanmanserver) - Unknown owner - C:\WINDOWS\
O23 - Service: Uninterruptible Power Supply UPSRpcSsNetlogonTrkWks (UPSRpcSsNetlogonTrkWks) - Unknown owner - C:\WINDOWS\
O23 - Service: Uninterruptible Power Supply UPSRpcSsNetlogonTrkWks UPSRpcSsNetlogonTrkWksWmdmPmSNSchedulewinmgmt (UPSRpcSsNetlogonTrkWksWmdmPmSNSchedulewinmgmt) - Unknown owner - C:\WINDOWS\
O23 - Service: Volume Shadow Copy VSSFastUserSwitchingCompatibilityCiSvcAlerter (VSSFastUserSwitchingCompatibilityCiSvcAlerter) - Unknown owner - C:\WINDOWS\
O23 - Service: Volume Shadow Copy VSSNetman (VSSNetman) - Unknown owner - C:\WINDOWS\
O23 - Service: Volume Shadow Copy VSSNetman VSSNetmanUPS (VSSNetmanUPS) - Unknown owner - C:\WINDOWS\
O23 - Service: Volume Shadow Copy VSSxmlprov (VSSxmlprov) - Unknown owner - C:\WINDOWS\
O23 - Service: Windows Management Instrumentation winmgmtdmadmin (winmgmtdmadmin) - Unknown owner - C:\WINDOWS\
O23 - Service: Windows Management Instrumentation winmgmtFastUserSwitchingCompatibilityTermService (winmgmtFastUserSwitchingCompatibilityTermService) - Unknown owner - C:\WINDOWS\
O23 - Service: Windows Management Instrumentation winmgmtFastUserSwitchingCompatibilityTermService winmgmtFastUserSwitchingCompatibilityTermServiceSy smonLog (winmgmtFastUserSwitchingCompatibilityTermServiceS ysmonLog) - Unknown owner - C:\WINDOWS\
O23 - Service: Windows Management Instrumentation winmgmtFastUserSwitchingCompatibilityTermService winmgmtFastUserSwitchingCompatibilityTermServiceSy smonLog winmgmtFastUserSwitchingCompatibilityTermServiceSy smonLogHidServ (winmgmtFastUserSwitchingCompatibilityTermServiceS ysmonLogHidServ) - Unknown owner - C:\WINDOWS\
O23 - Service: Windows Management Instrumentation winmgmtFastUserSwitchingCompatibilityTermService winmgmtFastUserSwitchingCompatibilityTermServiceSy smonLog winmgmtFastUserSwitchingCompatibilityTermServiceSy smonLogLmHosts (winmgmtFastUserSwitchingCompatibilityTermServiceS ysmonLogLmHosts) - Unknown owner - C:\WINDOWS\
O23 - Service: Windows Management Instrumentation winmgmtFastUserSwitchingCompatibilityTermService winmgmtFastUserSwitchingCompatibilityTermServiceup nphost (winmgmtFastUserSwitchingCompatibilityTermServiceu pnphost) - Unknown owner - C:\WINDOWS\
O23 - Service: Windows Management Instrumentation winmgmtFastUserSwitchingCompatibilityTermService winmgmtFastUserSwitchingCompatibilityTermServiceup nphost winmgmtFastUserSwitchingCompatibilityTermServiceup nphostCiSvcThemes (winmgmtFastUserSwitchingCompatibilityTermServiceu pnphostCiSvcThemes) - Unknown owner - C:\WINDOWS\
O23 - Service: Portable Media Serial Number Service WmdmPmSNgusvc (WmdmPmSNgusvc) - Unknown owner - C:\WINDOWS\
O23 - Service: Portable Media Serial Number Service WmdmPmSNPolicyAgentRpcLocatorlanmanserverWebClient Themes (WmdmPmSNPolicyAgentRpcLocatorlanmanserverWebClien tThemes) - Unknown owner - C:\WINDOWS\
O23 - Service: Portable Media Serial Number Service WmdmPmSNPolicyAgentRpcLocatorlanmanserverWebClient Themes WmdmPmSNPolicyAgentRpcLocatorlanmanserverWebClient ThemesAudioSrv (WmdmPmSNPolicyAgentRpcLocatorlanmanserverWebClien tThemesAudioSrv) - Unknown owner - C:\WINDOWS\
O23 - Service: Portable Media Serial Number Service WmdmPmSNSchedule (WmdmPmSNSchedule) - Unknown owner - C:\WINDOWS\
O23 - Service: Portable Media Serial Number Service WmdmPmSNSchedule WmdmPmSNScheduleEventlog (WmdmPmSNScheduleEventlog) - Unknown owner - C:\WINDOWS\
O23 - Service: Portable Media Serial Number Service WmdmPmSNSchedule WmdmPmSNScheduleEventlog WmdmPmSNScheduleEventlogwscsvcImapiServiceRpcLocat orWmiApSrv (WmdmPmSNScheduleEventlogwscsvcImapiServiceRpcLoca torWmiApSrv) - Unknown owner - C:\WINDOWS\
O23 - Service: Portable Media Serial Number Service WmdmPmSNSchedule WmdmPmSNSchedulewinmgmt (WmdmPmSNSchedulewinmgmt) - Unknown owner - C:\WINDOWS\
O23 - Service: Portable Media Serial Number Service WmdmPmSNSchedule WmdmPmSNSchedulewinmgmt WmdmPmSNSchedulewinmgmtIDriverT (WmdmPmSNSchedulewinmgmtIDriverT) - Unknown owner - C:\WINDOWS\
O23 - Service: Portable Media Serial Number Service WmdmPmSNSchedule WmdmPmSNSchedulewinmgmt WmdmPmSNSchedulewinmgmtPolicyAgent (WmdmPmSNSchedulewinmgmtPolicyAgent) - Unknown owner - C:\WINDOWS\
O23 - Service: WMI Performance Adapter WmiApSrvBITS (WmiApSrvBITS) - Unknown owner - C:\WINDOWS\
O23 - Service: WMI Performance Adapter WmiApSrvBITS WmiApSrvBITSAppMgmtWudfSvcxmlprov (WmiApSrvBITSAppMgmtWudfSvcxmlprov) - Unknown owner - C:\WINDOWS\
O23 - Service: WMI Performance Adapter WmiApSrvSCardSvrIDriverTdmadmin (WmiApSrvSCardSvrIDriverTdmadmin) - Unknown owner - C:\WINDOWS\
O23 - Service: Windows Media Player Network Sharing Service WMPNetworkSvcFastUserSwitchingCompatibility (WMPNetworkSvcFastUserSwitchingCompatibility) - Unknown owner - C:\WINDOWS\
O23 - Service: Windows Media Player Network Sharing Service WMPNetworkSvcRemoteAccess (WMPNetworkSvcRemoteAccess) - Unknown owner - C:\WINDOWS\
O23 - Service: Windows Media Player Network Sharing Service WMPNetworkSvcRemoteAccess WMPNetworkSvcRemoteAccessFastUserSwitchingCompatib ilityTermServiceThemesEventSystemRasMan (WMPNetworkSvcRemoteAccessFastUserSwitchingCompati bilityTermServiceThemesEventSystemRasMan) - Unknown owner - C:\WINDOWS\
O23 - Service: Windows Media Player Network Sharing Service WMPNetworkSvcRemoteAccess WMPNetworkSvcRemoteAccessWmdmPmSN (WMPNetworkSvcRemoteAccessWmdmPmSN) - Unknown owner - C:\WINDOWS\
O23 - Service: Windows Media Player Network Sharing Service WMPNetworkSvcRemoteAccess WMPNetworkSvcRemoteAccessWmdmPmSN WMPNetworkSvcRemoteAccessWmdmPmSNERSvclanmanworkst ationNetDDEdsdm (WMPNetworkSvcRemoteAccessWmdmPmSNERSvclanmanworks tationNetDDEdsdm) - Unknown owner - C:\WINDOWS\
O23 - Service: Windows Media Player Network Sharing Service WMPNetworkSvcRSVP (WMPNetworkSvcRSVP) - Unknown owner - C:\WINDOWS\
O23 - Service: Security Center wscsvcImapiServiceRpcLocatorWmiApSrv (wscsvcImapiServiceRpcLocatorWmiApSrv) - Unknown owner - C:\WINDOWS\
O23 - Service: Automatic Updates wuauservRasAutoCOMSysApp (wuauservRasAutoCOMSysApp) - Unknown owner - C:\WINDOWS\
O23 - Service: Automatic Updates wuauservRasAutoCOMSysApp wuauservRasAutoCOMSysAppgusvc (wuauservRasAutoCOMSysAppgusvc) - Unknown owner - C:\WINDOWS\
O23 - Service: Automatic Updates wuauservRasAutoCOMSysApp wuauservRasAutoCOMSysAppgusvc wuauservRasAutoCOMSysAppgusvc Service (wuauservRasAutoCOMSysAppgusvc Service) - Unknown owner - C:\WINDOWS\
O23 - Service: Automatic Updates wuauservRasAutoCOMSysApp wuauservRasAutoCOMSysAppgusvc wuauservRasAutoCOMSysAppgusvcPlugPlay (wuauservRasAutoCOMSysAppgusvcPlugPlay) - Unknown owner - C:\WINDOWS\
O23 - Service: Automatic Updates wuauservRasAutoCOMSysApp wuauservRasAutoCOMSysAppgusvc wuauservRasAutoCOMSysAppgusvc Service wuauservRasAutoCOMSysAppgusvcSSDPSRVPctspkhelpsvcS poolerFastUserSwitchingCompatibilityTermServiceNet DDE (wuauservRasAutoCOMSysAppgusvcSSDPSRVPctspkhelpsvc SpoolerFastUserSwitchingCompatibilityTermServiceNe tDDE) - Unknown owner - C:\WINDOWS\
O23 - Service: Automatic Updates wuauservRasAutoCOMSysApp wuauservRasAutoCOMSysAppgusvc wuauservRasAutoCOMSysAppgusvc Service wuauservRasAutoCOMSysAppgusvcstisvcMSIServer (wuauservRasAutoCOMSysAppgusvcstisvcMSIServer) - Unknown owner - C:\WINDOWS\
O23 - Service: Automatic Updates wuauservRasAutoCOMSysApp wuauservRasAutoCOMSysAppNtmsSvcNtLmSsp (wuauservRasAutoCOMSysAppNtmsSvcNtLmSsp) - Unknown owner - C:\WINDOWS\
O23 - Service: Automatic Updates wuauservUPS (wuauservUPS) - Unknown owner - C:\WINDOWS\
O23 - Service: Windows Driver Foundation - User-mode Driver Framework WudfSvcDcomLaunch (WudfSvcDcomLaunch) - Unknown owner - C:\WINDOWS\
O23 - Service: Network Provisioning Service xmlprovERSvclanmanworkstation (xmlprovERSvclanmanworkstation) - Unknown owner - C:\WINDOWS\
--
End of file - 41898 bytes

CURRENT CONDITIONS:

I have only used one other scan/fix tool, and that was from Microsoft Live. It was called “One” or something along those lines. It did not work at all, and a blue screen appeared with text and some sort of code, “RQTL NOT_LESS_OR_EQUAL” and it suddenly restarted. A while later, I tried using the computer again. It went out of control. It kept restarting. However, I am not sure if the computer was actually restarting or not. A large Windows banner would appear, as well as the standard blue loading bar, but when I tried to shut down by pressing the power button, I received a flash of my regular desktop, claiming that other users were logged in and it would be hazardous to turn off the computer.

PAST PROBLEMS: JUNE 2008

I still have AntiVirus XP 2008 on my desktop, as I tried to manually remove it myself, with little success. It no longer pops up, but it is obvious something is wrong. When I was working on getting rid of it, the computer would do the same thing as before---present a blue screen with phony error messages.

I tried using the suggested Malwarebytes’ Anti-Malware program when the XP malware appear in June. It did not work, and presented a blue screen whenever it was about to finish the scan. I did a system restore, and had to restart the process all over again.

CURRENT PROBLEM:

Right now, symptoms include the random restarting of the computer with a disk check, a reemerging background, consisting of a red and gray box urging me to purchase some sort of spyware remover, and it also shows this image after I start my computer, right before logging in.
I value my computer greatly, and I desperately need help. I am terrible when it comes to technical problems!


  #2  
Old 08-19-2008
Pancake's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Victoria, Australia
Posts: 3,962
PC Experience: Elite PC Guru
Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page
Default Re: Suspected Malware? What is it?

Hi.Yes you do have malware..Its infected a lot of your files.



Please download Malwarebytes' Anti-Malware from one of these places:

|MG| Malwarebytes Anti-Malware 1.25

http://www.besttechie.net/tools/mbam-setup.exe

Double Click mbam-setup.exe to install the application.

* Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select "Perform Quick Scan", then click Scan.
* The scan may take some time to finish,so please be patient.
* When the scan is complete, click OK, then Show Results to view the results.
* Make sure that everything is checked, and click Remove Selected.
* When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
* Copy&Paste the entire report in your next reply along with a fresh HijackThis log.

Please Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.


==============================================


Ok.Lets download ComboFix.exe. This will give me a better view to the files running and also hidden on your computer and also those in the registry..Please visit this webpage for downloading and instructions for running the tool:

Go here ======> A guide and tutorial on using ComboFix <====== Go here

Please ensure you read this guide carefully and install the Recovery Console first.This applies to XP Pro and XP Home users only.If you have SP3 installed you will need to use SP2

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Once installed, you should get a prompt that says:

The Recovery Console was successfully installed.

Please continue as follows:

(1) Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
(2) Click Yes to allow ComboFix to continue scanning for malware.

When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleansing the system:

C:\ComboFix.txt
New HijackThis log.


Caution: Never run and remove files with Combofix unless supervised by a qualified security analyst who is experienced in the use of Combofix. Mal use can cause serious computer problems

NOTE: Combofix prevents autorun of all CDs, floppies and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you - please let me know.


__________________
  • An Australian Member of
  • and
My real name is Eddy

Last edited by Pancake; 08-19-2008 at 11:42 PM.
  #3  
Old 08-21-2008
Bronze Member
 
Join Date: Aug 2008
Posts: 15
PC Experience: Beginner
DellUser2008 - See this Members User comments on their Profile page
Arrow Re: Suspected Malware? What is it?

Here are the results from the Malwarebytes' scan. I was asked to restart during the process.

-----------------------

Malwarebytes' Anti-Malware 1.25
Database version: 1073
Windows 5.1.2600 Service Pack 2
8:36:57 PM 8/20/2008
mbam-log-08-20-2008 (20-36-57).txt
Scan type: Quick Scan
Objects scanned: 78522
Time elapsed: 16 minute(s), 47 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 3
Registry Keys Infected: 12
Registry Values Infected: 9
Registry Data Items Infected: 2
Folders Infected: 11
Files Infected: 138
Memory Processes Infected:
C:\WINDOWS\system32\lphctvhj0e553.exe (Trojan.FakeAlert) -> Unloaded process successfully.
Memory Modules Infected:
C:\WINDOWS\system32\WinCtrl32.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\System32\Dll.dll (Trojan.Downloader) -> Delete on reboot.
C:\WINDOWS\system32\blphctvhj0e553.scr (Trojan.FakeAlert) -> Delete on reboot.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\rhcpvhj0e553 (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\rhcpvhj0e553 (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WinCtrl32 (Trojan.Agent) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\l anmandrv (Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\l anmandrv (Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\lanmandrv (Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\s ysrest.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\sysrest.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\w inbh52 (Rootkit.Agent) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\w inbh52 (Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\winbh52 (Rootkit.Agent) -> Delete on reboot.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\lanmanwrk.exe clean (Backdoor.Qmop) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\kerneldrv.exe clean (Trojan.Agent) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\advap32 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\sysrest32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\lphctvhj0e553 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\wallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\originalwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\convertedwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\scrnsave.exe (Hijack.Wallpaper) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Policies\System\NoDispBackgroundPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Policies\System\NoDispScrSavPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
C:\Documents and Settings\StephH\Application Data\rhcpvhj0e553 (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\StephH\Application Data\rhcpvhj0e553\Quarantine (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\StephH\Application Data\rhcpvhj0e553\Quarantine\BrowserObjects (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\StephH\Application Data\rhcpvhj0e553\Quarantine\Packages (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\StephH\Application Data\rhcpvhj0e553\Quarantine\Autorun (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\StephH\Application Data\rhcpvhj0e553\Quarantine\Autorun\HKCU (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\StephH\Application Data\rhcpvhj0e553\Quarantine\Autorun\HKCU\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\StephH\Application Data\rhcpvhj0e553\Quarantine\Autorun\HKLM (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\StephH\Application Data\rhcpvhj0e553\Quarantine\Autorun\HKLM\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\StephH\Application Data\rhcpvhj0e553\Quarantine\Autorun\StartMenuAllU sers (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\StephH\Application Data\rhcpvhj0e553\Quarantine\Autorun\StartMenuCurr entUser (Rogue.Multiple) -> Quarantined and deleted successfully.
Files Infected:
C:\WINDOWS\system32\lanmanwrk.exe (Backdoor.Qmop) -> Delete on reboot.
C:\WINDOWS\system32\drivers\199lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\884lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\670lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\140lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\647lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\26lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\629lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\12lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\657lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\Winbh52(2).sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\Winbh52(3).sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\869lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\482lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\691lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\331lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\425lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\780lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\652lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\612lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\233lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\923lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\914lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\450lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\898lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\773lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\846lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\813lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\976lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\257lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\352lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\470lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\550lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\804lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\590lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\236lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\934lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\284lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\464lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\165lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\808lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\885lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\818lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\518lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\880lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\148lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\339lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\906lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\262lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\803lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\809lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\678lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\776lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\332lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\805lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\295lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\273lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\760lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\137lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\473lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\928lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\656lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\254lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\674lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\659lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\139lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\469lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\789lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\895lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\103lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\447lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\40lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\68lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\183lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\432lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\356lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\200lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\47lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\754lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\881lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\562lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\290lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\304lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\390lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\922lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\874lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\664lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\182lsf.exe (Backdoor.Qmop) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\xbrdhotp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\StephH\Local Settings\Temp\Wjcv.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\StephH\Local Settings\Temporary Internet Files\Content.IE5\Y6UKPUSZ\index[1] (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\StephH\Local Settings\Temporary Internet Files\Content.IE5\F9DV58IS\index[1] (Worm.Nuwar) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\KernelDrv.exe (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\WinCtrl32.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\WinCtrl32.dl_ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sysrest32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\Dll.dll (Trojan.Downloader) -> Delete on reboot.
C:\WINDOWS\system32\ksvcl.dll (Stolen.Data) -> Delete on reboot.
C:\WINDOWS\system32\kcopt.dll (Stolen.Data) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\phctvhj0e553.bmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\blphctvhj0e553.scr (Trojan.