ComboFix 08-07-18.1 - Administrator 07/19/2008 0:01:36.1 -
FAT32x86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.121 [GMT -5:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\My Documents\My Documents.url
C:\Documents and Settings\Administrator\My Documents\My Pictures\My Pictures.url
C:\Program Files\Common Files\WinSoftware
C:\Program Files\Common Files\WinSoftware\CrXML.dll
C:\Program Files\Common Files\WinSoftware\PCheck.dll
C:\Program Files\Web Technologies
C:\Program Files\Web Technologies\myd.ico
C:\Program Files\Web Technologies\mym.ico
C:\Program Files\Web Technologies\myp.ico
C:\Program Files\Web Technologies\myv.ico
C:\Program Files\Web Technologies\ot.ico
C:\Program Files\Web Technologies\ts.ico
C:\WINNT\Downloaded Program Files\UWFX5LP_0001_0614NetInstaller.exe
C:\WINNT\emdat.tm
C:\WINNT\emdat.tmp
C:\WINNT\regsvr.exe
C:\WINNT\SYSTEM32\238044
C:\WINNT\SYSTEM32\238044\238044.dll
C:\WINNT\system32\Cache
C:\WINNT\system32\Update.exe
C:\WINNT\Web\default.htt
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_RDRIV
-------\Service_rdriv
((((((((((((((((((((((((( Files Created from 2008-06-19 to 2008-07-19 )))))))))))))))))))))))))))))))
.
2008-07-18 22:24 . 08-07-18 22:24 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-18 22:24 . 08-07-18 22:24 <DIR> d-------- C:\New Folder
2008-07-16 01:53 . 08-07-16 01:53 19,387 --a------ C:\WINNT\SYSTEM32\DRIVERS\AegisP.sys
2008-07-16 01:52 . 08-07-16 01:52 <DIR> d-------- C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor
2008-07-16 01:52 . 05-11-24 19:51 245,248 --a------ C:\WINNT\SYSTEM32\rt73.sys
2008-07-16 01:52 . 03-10-13 15:30 94,208 --a------ C:\WINNT\SYSTEM32\GTW32N50.dll
2008-07-16 01:52 . 05-11-03 17:41 32,768 --a------ C:\WINNT\SYSTEM32\GTGina.dll
2008-07-16 01:52 . 03-09-25 23:28 31,930 --a------ C:\WINNT\SYSTEM32\GTNDIS3.VXD
2008-07-16 01:52 . 05-02-01 18:18 17,992 --a------ C:\WINNT\SYSTEM32\DRIVERS\bcm42rly.sys
2008-07-16 01:52 . 05-02-01 18:18 17,992 --a------ C:\WINNT\SYSTEM32\bcm42rly.sys
2008-07-16 01:52 . 05-02-01 18:18 17,992 --a------ C:\WINNT\bcm42rly.sys
2008-07-16 01:52 . 03-09-25 22:15 15,872 --a------ C:\WINNT\SYSTEM32\GTNDIS5.sys
2008-07-16 01:52 . 05-12-06 04:24 7,846 --a------ C:\WINNT\SYSTEM32\rt73.cat
2008-07-16 01:51 . 08-07-16 01:51 1,361 --a------ C:\WINNT\SYSTEM32\WLAN.INI
2008-06-28 20:16 . 03-03-15 23:15 90,112 --a------ C:\WINNT\unvise32.exe
2008-06-28 12:05 . 08-06-28 12:05 <DIR> d-------- C:\WINNT\D45EC2594A194656B588C2C360DD18EA.TMP
2008-06-27 13:20 . 08-06-27 13:20 <DIR> d-------- C:\FOUND.000
2008-06-26 16:04 . 08-06-26 16:05 <DIR> d-------- C:\Program Files\DreamCatcher
2008-06-26 13:55 . 02-12-11 17:34 208,896 --a------ C:\WINNT\SYSTEM32\wmpns.dll
2008-06-26 13:19 . 08-06-26 13:19 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Dealio
2008-06-26 13:17 . 02-12-11 18:50 301,712 --a------ C:\WINNT\SYSTEM32\drmclien.dll
2008-06-26 13:17 . 02-12-11 17:34 82,432 --a------ C:\WINNT\SYSTEM32\drmstor.dll
2008-06-21 12:35 . 08-06-21 12:35 <DIR> d-------- C:\Program Files\AskSBar
2008-06-21 12:35 . 08-01-04 20:56 1,526,640 --a------ C:\WINNT\WRSetup.dll
2008-06-21 12:35 . 08-01-04 20:34 163,696 --a------ C:\WINNT\SYSTEM32\DRIVERS\ssidrv.sys
2008-06-21 12:35 . 08-01-04 20:34 23,920 --a------ C:\WINNT\SYSTEM32\DRIVERS\sskbfd.sys
2008-06-21 12:35 . 08-01-04 20:34 21,872 --a------ C:\WINNT\SYSTEM32\DRIVERS\sshrmd.sys
2008-06-21 12:35 . 08-01-04 20:34 20,336 --a------ C:\WINNT\SYSTEM32\DRIVERS\SSFS0BB9.sys
2008-06-21 12:33 . 08-06-21 12:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Webroot
2008-06-19 20:11 . 08-06-19 20:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-19 20:10 . 08-06-19 20:54 141 --a------ C:\WINNT\My Video.url
2008-06-19 20:10 . 08-06-19 20:54 141 --a------ C:\WINNT\My Music.url
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-04 00:06 36,864 ----a-w C:\WINNT\uneng.exe
2008-06-03 20:46 --------- d-----w C:\Program Files\DVDVideoSoft
2008-06-03 20:46 --------- d-----w C:\Program Files\Common Files\DVDVideoSoft
2008-06-03 00:05 --------- d-----w C:\Documents and Settings\Administrator\Application Data\IEPro
2008-06-03 00:04 --------- d-----w C:\Program Files\IEPro
2008-06-02 00:22 --------- d-----w C:\Documents and Settings\Administrator\Application Data\LimeWire
2008-06-02 00:21 --------- d-----w C:\Program Files\LimeWire
2008-05-20 17:05 --------- d-----w C:\Program Files\Citrix
2008-05-20 17:05 --------- d-----w C:\Documents and Settings\Administrator\Application Data\ICAClient
2005-07-27 20:13 277 ----a-w C:\Program Files\index.htm
2005-07-27 20:08 277 ----a-w C:\Program Files\Web Site 1.htm
2005-05-24 14:19 262,144 ----a-w C:\Program Files\Uninstall My Web Search.dll
2004-09-15 08:54 31,465 ------w C:\Program Files\2wconfig.dll
2004-09-15 08:52 393,216 ------w C:\Program Files\2PortalMon.exe
2004-09-15 08:51 290,816 ------w C:\Program Files\Uninstaller.exe
2004-09-15 08:51 163,840 ------w C:\Program Files\GoHomePortal.exe
2004-09-15 08:50 622,592 ------w C:\Program Files\WebWorks.exe
2004-09-15 08:50 180,224 ------w C:\Program Files\WCAG.exe
2004-09-15 08:50 167,936 ------w C:\Program Files\WirelessConsoleApp.exe
2004-09-15 08:49 135,168 ------w C:\Program Files\WebSec.dll
2004-09-15 08:48 364,544 ------w C:\Program Files\RGWProv.dll
2004-09-15 08:47 266,240 ------w C:\Program Files\NetAPI.dll
2004-09-15 08:47 139,264 ------w C:\Program Files\Endec.dll
2004-09-15 08:42 9,158 ------w C:\Program Files\Language.ini
2004-09-15 08:42 368,726 ------w C:\Program Files\PRISMAPI.dll
2004-09-15 08:42 3,157 ------w C:\Program Files\2wconfig.ini
2004-09-15 08:42 27,478 ------w C:\Program Files\SysTrayMenu_256.bmp
2004-09-15 08:42 208,993 ------w C:\Program Files\CardPres.exe
2001-04-10 12:58 271 ---ha-w C:\Program Files\DESKTOP.INI
2001-04-10 12:58 21,952 ---ha-w C:\Program Files\FOLDER.HTT
2000-07-26 12:00 32,528 ----a-w C:\WINNT\INF\WBFIRDMA.SYS
2005-09-12 16:20 153,600 --sha-r C:\WINNT\SYSTEM32\ms-dos.pif
.
------- Sigcheck -------
01-02-20 13:09 8192 d36a33c21eeed5a6c1daecb7c80a1909 C:\WINNT\SYSTEM32\CTFMON.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
08-06-21 12:35 66912 --a------ C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="ctfmon.exe" [01-02-20 13:09 8192 C:\WINNT\SYSTEM32\CTFMON.EXE]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINNT\system32\NvCpl.dll" [05-07-20 21:07 7110656]
"zBrowser Launcher"="C:\Program Files\Logitech\iTouch\iTouch.exe" [01-03-28 01:59 168013]
"SandIcon"="C:\ImageMate CompactFlash USB\SandIcon.Exe" [00-11-13 11:36 131072]
"HPDJ Taskbar Utility"="C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb04.exe" [01-11-19 20:10 196608]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [05-05-14 00:20 278528]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [05-06-14 17:49 98304]
"vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe" [02-07-30 11:35 77824]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [05-07-17 21:08 180269]
"CreateCD"="C:\PROGRA~1\Adaptec\EASYCD~1\CreateCD\CreateCD.exe" [01-03-22 10:20 245760]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [08-01-04 20:56 5367664]
"Synchronization Manager"="mobsync.exe" [03-06-19 12:05 111376 C:\WINNT\SYSTEM32\mobsync.exe]
"nwiz"="nwiz.exe" [05-07-20 21:07 1519616 C:\WINNT\SYSTEM32\nwiz.exe]
"Mouse Suite 98 Daemon"="ICO.EXE" [01-08-23 11:23 45056 C:\WINNT\SYSTEM32\ico.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe" [03-06-19 12:05 186640]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{99f8405b-63d1-421a-83bb-7b4b0642ac28}"= "C:\WINNT\system32\funfsnv.dll" [01-07-24 21:18 13312]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= mmdrv.dll
"aux1"= ctwdm32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
R0 aaatimeo;aaatimeo;C:\WINNT\system32\DRIVERS\aaatimeo.sys [00-11-21 16:19 ]
R0 Fd16_700;Fd16_700;C:\WINNT\system32\DRIVERS\fd16_700.sys [99-09-25 11:11 ]
R0 idebd;idebd;C:\WINNT\system32\DRIVERS\idebd.sys [00-05-30 00:00 ]
R0 intelata;intelata;C:\WINNT\system32\DRIVERS\intelata.sys [00-05-30 00:00 ]
R1 cmosa;cmosa;C:\WINNT\system32\DRIVERS\cmosa.sys [00-11-30 14:17 ]
R3 Winacpci;Winacpci;C:\WINNT\system32\DRIVERS\winacpci.sys [00-05-12 19:17 ]
S0 cda1000;cda1000;C:\WINNT\system32\DRIVERS\cda1000.sys [00-12-14 13:14 ]
S2 tcaicchg;tcaicchg;C:\WINNT\System32\tcaicchg.sys []
S3 pelmouse;Mouse Suite Driver;C:\WINNT\system32\DRIVERS\pelmouse.sys [01-01-09 16:49 ]
S3 pelusblf;USB Mouse Low Filter Driver;C:\WINNT\system32\DRIVERS\pelusblf.sys [01-10-08 11:46 ]
S3 usbprint;Microsoft USB PRINTER Class;C:\WINNT\system32\DRIVERS\usbprint.sys [03-06-19 12:05 ]
S3 WDCFX_AT;USB Storage Adapter FX_AT (WDC);C:\WINNT\system32\DRIVERS\WDCFX_AT.SYS [04-08-02 14:50 ]
S3 WlanUIG;2Wire 802.11g USB Driver;C:\WINNT\system32\DRIVERS\WlanUIG.sys [04-05-16 19:46 ]
*Newly Created Service* - IPNAT
*Newly Created Service* - SHAREDACCESS
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-WINP - C:\WINNT\winmic.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-07-19 00:08:40
Windows 5.0.2195 Service Pack 4 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-07-19 0:12:42 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-19 05:12:28
Pre-Run: 19,383,517,184 bytes free
Post-Run: 21,480,964,096 bytes free
174
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:24:53 AM, on 7/19/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\LEXPPS.EXE
C:\WINNT\System32\cisvc.exe
C:\WINNT\System32\CTsvcCDA.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\system32\nvsvc32.exe
C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\WINNT\system32\devldr32.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\ImageMate CompactFlash USB\SandIcon.Exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINNT\system32\ICO.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Adaptec\EASYCD~1\CreateCD\CreateCD.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINNT\explorer.exe
C:\WINNT\system32\NOTEPAD.EXE
C:\WINNT\System32\cidaemon.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vpc32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL =
http://internetsearchservice.comR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://internetsearchservice.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [zBrowser Launcher] "C:\Program Files\Logitech\iTouch\iTouch.exe"
O4 - HKLM\..\Run: [SandIcon] "C:\ImageMate CompactFlash USB\SandIcon.Exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CreateCD] "C:\PROGRA~1\Adaptec\EASYCD~1\CreateCD\CreateCD.exe" -r
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O16 - DPF: DigiChat Applet -
http://host16.digich...s/Client_IE.cabO16 - DPF: {1DF36010-E276-11D4-A7C0-00C04F0453DD} (Stamps.com Secure Postal Account Registration) -
https://secure.stamp...16/sdcregie.cabO16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) -
http://photos.yahoo....plorer1_9us.cabO16 - DPF: {DAB941D8-BC94-4819-AB4D-5598C65FA3FE} -
http://tb.searchitqu...com/v30/siq.cabO16 - DPF: {EF0DBA6F-43CE-4B26-9808-2AB38FA0DB29} (MSN Money Ticker) -
http://fdl.msn.com/p.../v13/ticker.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{6BB7084D-EF77-4D29-826E-39CFB64F4A92}: NameServer = 68.94.156.1,68.94.157.1
O22 - SharedTaskScheduler: eulogical - {99f8405b-63d1-421a-83bb-7b4b0642ac28} - C:\WINNT\system32\funfsnv.dll
O23 - Service: Cpmcatciipp - Dell Computer Corporation. - (no file)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: WUSB54GCSVC - GEMTEKS - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
--
End of file - 7643 bytes