---------------------------
lsass.exe - Application Error
---------------------------
The application failed to initialize properly (0xc00000ba). Click on OK to terminate the application.
---------------------------
OK
---------------------------
Pressing OK only makes the window pop up again. I can open up two or three programs when I first start my computer although they're slow. After about twenty minutes or so, I can't open up any other programs because there is insufficient memory, which I think is because lsass.exe is opening itself up like a gajillion times.
I had a friend try and install McAfee, but the virus wouldn't let the scan run. I took my computer to the Dell store (I live in China) where despite not understanding my English laptop, they managed to find the viruses but couldn't get rid of them. They recommended I re-install Windows, but they only have Chinese versions so I'd much prefer to kill the virus .
I was messing around this weekend and here's what I've done - I originally thought it was the W32.Sasser.worm thing and downloaded/ran the Symantec removal tool but it told me there was no worm on my computer. I turned off the automatic system restore so that infected files aren't saved as back-up. I ran ATF Cleaner and got rid of all unnecessary files. I have an ERUNT back-up of my system. I ran Malwarebytes' Anti-Malware which found seven infected files and tried to delete them. It couldn't, so rebooted my computer and said it would delete them after rebooting. My computer started up and...the lsass.exe window popped up again. So I ran Malwarebytes' again (this time with a full scan)...same result. I don't know what MSConfig is or how to check start up stuff and I personally have never operated my computer in Safe Mode.
Here's the latest Malwarebytes' Anti-Malware log:
Malwarebytes' Anti-Malware 1.25
Database version: 1075
Windows 5.1.2600 Service Pack 2
7:10:15 22.08.08
mbam-log-08-22-2008 (07-10-15).txt
Scan type: Full Scan (C:\|)
Objects scanned: 83070
Time elapsed: 2 hour(s), 11 minute(s), 51 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\Com\lsass.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
C:\WINDOWS\system32\Com\smss.exe (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.
Here's my HijackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:54:19 AM, on 24.08.08
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Vidalia Bundle\Vidalia\vidalia.exe
C:\Program Files\Vidalia Bundle\Privoxy\privoxy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\com\lsass.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Vidalia Bundle\Tor\tor.exe
C:\WINDOWS\system32\com\lsass.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
C:\Documents and Settings\Andrea\My Documents\Installations\HiJackThis.exe
C:\WINDOWS\system32\com\lsass.exe
C:\WINDOWS\system32\com\lsass.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Vidalia] "C:\Program Files\Vidalia Bundle\Vidalia\vidalia.exe"
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: Privoxy.lnk = C:\Program Files\Vidalia Bundle\Privoxy\privoxy.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akama...ex/qtplugin.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {2E12FB00-546B-4EE3-9CC2-057BF02E1C17} (Webshots Multiple Media Uploader - Container) - http://community.web...wsaxcontrol.cab
O16 - DPF: {3527C5BD-4A46-4362-94B6-12341D087A4B} (esProxy.GeneralHandler) - http://echospin.com/...es/esWizard.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebo...otoUploader.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.on...e/en/crlocx.ocx
O20 - AppInit_DLLs: C:\WINDOWS\system32\dnsq.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: NAI ePO Agent Install (NAIMServInst) - McAfee, Inc. - C:\DOCUME~1\Andrea\LOCALS~1\Temp\unz27.tmp\FramePkg.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
--
End of file - 16164 bytes