Same computer description as before: "It seems there was not much improvement in computer performance. That is to say, as of right now there are no pop-ups and re-directions happening, but a little more sluggish then normal."
ComboFix 09-04-23.02 - Dean 04/22/2009 15:13.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2558.2233 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Dean\Application Data\
020000000769c4cf579C.manifest
c:\documents and settings\Dean\Application Data\
020000000769c4cf579O.manifest
c:\documents and settings\Dean\Application Data\
020000000769c4cf579P.manifest
c:\documents and settings\Dean\Application Data\
020000000769c4cf579S.manifest
c:\windows\GnuHashes.ini
c:\windows\system32\drivers\ovfsthvbbidompyqxrmgfimpqjwavdkdplqgix.sys
c:\windows\system32\GroupPolicy000.dat
c:\windows\system32\ovfsthbvogwjuutswohsaceyxtppklrvkclpbh.dll
c:\windows\system32\ovfsthdtptisqoyeondmrleaelbdmnaxqunnri.dat
c:\windows\system32\ovfsthmdmkamyjuieeeuyxtuddusqxjtgbodsk.dll
c:\windows\system32\ovfsthpdobyodqjpulhhxswhbotxfhxsrddnot.dat
c:\windows\system32\ovfsthwbbgjurtnmtyyedwnjlcioubxcbfmbcw.dll
c:\windows\system32\p2hhr.bat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_ovfsthprmjkvtqoiqaoethsantxelnlnmnayta
((((((((((((((((((((((((( Files Created from 2009-03-23 to 2009-04-23 )))))))))))))))))))))))))))))))
.
2009-04-21 02:33 . 2009-04-21 02:33 ——– d—–w c:\documents and settings\Dean\Application Data\Jasc
2009-04-20 23:32 . 2009-04-20 23:32 ——– d—–w c:\documents and settings\All Users\Application Data\InstallShield
2009-04-20 23:31 . 2009-04-20 23:31 ——– d—–w c:\documents and settings\Dean\Application Data\Jasc Software Inc
2009-04-20 22:53 . 2009-04-20 22:53 15000 —-a-w c:\windows\system32\sf87wuijndoio43j.dll
2009-04-20 22:53 . 2009-04-20 22:53 21504 —-a-w c:\windows\system32\ak1.exe
2009-04-20 21:22 . 2009-04-20 21:22 ——– d—–w c:\documents and settings\Dean\Application Data\Malwarebytes
2009-04-20 21:22 . 2009-04-06 19:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-04-20 21:22 . 2009-04-06 19:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-20 21:22 . 2009-04-20 21:22 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-20 12:14 . 2009-04-20 12:14 ——– d—–w c:\documents and settings\Dean\Local Settings\Application Data\{D3CA3802-B1E3-46EE-8F81-6A0C4921B901}
2009-04-20 11:50 . 2009-04-20 11:50 615 —-a-w c:\windows\system32\bSeQ5EE.vbs
2009-04-20 04:15 . 2009-04-20 04:34 ——– d—–w c:\documents and settings\Dean\Local Settings\Application Data\WMTools Downloaded Files
2009-04-20 03:56 . 2005-08-24 19:28 119296 —-a-w c:\windows\system32\WNASPI32.DLL
2009-04-20 03:56 . 1999-09-10 16:06 5600 —-a-w c:\windows\system\WINASPI.DLL
2009-04-20 03:56 . 1999-09-10 16:06 4672 —-a-w c:\windows\system\WOWPOST.EXE
2009-04-20 03:56 . 1999-09-10 16:06 25244 —-a-w c:\windows\system32\drivers\ASPI32.SYS
2009-04-18 18:44 . 2009-04-18 18:44 155 —-a-w c:\windows\system32\SelfDel.bat
2009-04-16 23:59 . 2009-03-06 14:22 284160 -c—-w c:\windows\system32\dllcache\pdh.dll
2009-04-16 23:59 . 2009-02-09 12:10 401408 -c—-w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 23:59 . 2009-02-09 12:10 473600 -c—-w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 23:59 . 2009-02-09 12:10 453120 -c—-w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 23:59 . 2009-02-06 11:11 110592 -c—-w c:\windows\system32\dllcache\services.exe
2009-04-16 23:59 . 2009-02-06 10:10 227840 -c—-w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 23:59 . 2009-02-09 12:10 729088 -c—-w c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 23:59 . 2009-02-09 12:10 714752 -c—-w c:\windows\system32\dllcache\ntdll.dll
2009-04-16 23:59 . 2009-02-09 12:10 617472 -c—-w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 23:59 . 2008-05-03 11:55 2560 ——w c:\windows\system32\xpsp4res.dll
2009-04-16 23:59 . 2009-03-27 06:58 1203922 -c—-w c:\windows\system32\dllcache\sysmain.sdb
2009-04-16 23:59 . 2008-04-21 12:08 215552 -c—-w c:\windows\system32\dllcache\wordpad.exe
2009-04-04 17:24 . 2009-04-04 17:24 ——– d—–w c:\documents and settings\Dean\Local Settings\Application Data\assembly
2009-04-04 17:23 . 2009-04-04 17:23 ——– d—–w c:\documents and settings\Dean\Local Settings\Application Data\IsolatedStorage
2009-03-28 00:53 . 2009-03-28 00:53 ——– d—–w c:\documents and settings\Dean\Local Settings\Application Data\Turbine
2009-03-27 00:18 . 2009-03-27 00:18 ——– d—–w c:\windows\Logs
2009-03-26 10:34 . 2009-03-27 15:26 ——– d—–w c:\documents and settings\Dean\Application Data\GetRightToGo
2009-03-26 09:33 . 2009-03-26 09:33 ——– d—–w c:\documents and settings\All Users\Application Data\Turbine
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-22 02:47 . 2008-12-01 06:11 ——– d—–w c:\program files\City of Heroes
2009-04-21 02:30 . 2009-04-20 23:31 ——– d—–w c:\program files\Jasc Software Inc
2009-04-20 23:32 . 2009-04-20 23:31 ——– d—–w c:\program files\Common Files\Jasc Software Inc
2009-04-20 23:31 . 2008-05-17 04:17 ——– d—–w c:\program files\Common Files\InstallShield
2009-04-20 23:12 . 2008-05-28 04:23 ——– d—–w c:\documents and settings\Dean\Application Data\LimeWire
2009-04-20 21:22 . 2009-04-20 21:22 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-04-20 19:10 . 2009-04-20 19:10 ——– d—–w c:\program files\Trend Micro
2009-04-20 03:56 . 2009-04-20 03:56 ——– d—–w c:\program files\Nidesoft Studio
2009-04-20 03:52 . 2009-04-20 03:52 ——– d—–w c:\program files\Easy Video Splitter
2009-04-20 03:15 . 2009-04-20 03:15 ——– d—–w c:\program files\avisplit
2009-04-19 01:08 . 2008-07-18 03:40 ——– d—–w c:\program files\Spybot - Search & Destroy
2009-04-19 01:06 . 2008-07-18 03:40 ——– d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-16 04:37 . 2008-10-14 03:12 ——– d—–w c:\documents and settings\Dean\Application Data\U3
2009-04-07 04:56 . 2009-04-07 04:56 ——– d—–w c:\program files\DivX
2009-04-07 04:56 . 2009-04-07 04:56 ——– d—–w c:\program files\Common Files\DivX Shared
2009-04-07 04:50 . 2008-05-17 04:17 ——– d–h–w c:\program files\InstallShield Installation Information
2009-04-07 04:44 . 2008-05-28 04:23 ——– d—–w c:\program files\LimeWire
2009-04-04 17:21 . 2009-04-04 17:20 ——– d—–w c:\program files\Virtual Earth 3D
2009-04-01 00:24 . 2008-08-07 20:41 20 —h–w c:\documents and settings\All Users\Application Data\PKP_DLec.DAT
2009-03-26 09:27 . 2009-03-26 09:27 ——– d—–w c:\program files\Turbine
2009-03-16 21:24 . 2009-03-16 21:24 ——– d—–w c:\program files\StratX
2009-03-06 14:22 . 2002-08-29 10:41 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2002-08-29 10:41 826368 —-a-w c:\windows\system32\wininet.dll
2009-02-27 18:12 . 2009-02-09 01:14 ——– d—–w c:\program files\Microsoft Silverlight
2009-02-22 14:35 . 2009-02-22 14:35 ——– d—–w c:\program files\MP3 Converter
2009-02-20 18:09 . 2004-08-04 07:56 78336 —-a-w c:\windows\system32\ieencode.dll
2009-02-09 12:10 . 2002-08-29 10:41 729088 —-a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2002-08-29 10:41 401408 —-a-w c:\windows\system32\rpcss.dll
2009-02-09 12:10 . 2002-08-29 10:40 617472 —-a-w c:\windows\system32\advapi32.dll
2009-02-09 12:10 . 2002-08-29 10:40 714752 —-a-w c:\windows\system32\ntdll.dll
2009-02-09 11:13 . 2002-08-29 09:14 1846784 —-a-w c:\windows\system32\win32k.sys
2009-02-07 23:02 . 2002-08-29 01:04 2066048 —-a-w c:\windows\system32\ntkrnlpa.exe
2009-02-06 11:11 . 2001-08-23 17:00 110592 —-a-w c:\windows\system32\services.exe
2009-02-06 11:08 . 2002-08-29 09:03 2189056 —-a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2001-08-23 17:00 35328 —-a-w c:\windows\system32\sc.exe
2009-02-03 19:59 . 2002-08-29 10:41 56832 —-a-w c:\windows\system32\secur32.dll
2008-08-07 21:13 . 2008-05-20 20:52 27608 —-a-w c:\documents and settings\Dean\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-02-24 19:2009-02-24 19:34 34:32 . c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:2009-02-24 19:34 34:32 . c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-01-23 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-01-23 126976]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"BootSkin Startup Jobs"="c:\program files\Stardock\WinCustomize\BootSkin\BootSkin.exe" [2004-04-26 270336]
"LogonStudio"="c:\program files\WinCustomize\LogonStudio\logonstudio.exe" [2002-09-03 987187]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-05-27 413696]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-10-07 1630208]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2008-8-7 118784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\windows\system32\logonuiX.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"c:\\Program Files\\Turbine\\The Lord of the Rings Online\\lotroclient.exe"=
"c:\\Program Files\\Turbine\\The Lord of the Rings Online\\TurbineLauncher.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
S0 BootScreen;BootScreen; [x]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{30e6dcc0-9956-11dd-90ae-0011432cc01b}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Aim6 - (no file)
Notify-f0f704a9579 - (no file)
Notify-__c00D5B8A - (no file)
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: practice4performance.com\www
DPF: {BA2CB6B1-03EE-4068-87CC-F5E4DD772A9B} - hxxps://citrix2.cleanevent.com/CitrixLogonPoint/CleaneventAACPrimary/EPAClient/CitrixCAO.cab
FF - ProfilePath - c:\documents and settings\Dean\Application Data\Mozilla\Firefox\Profiles\x8mry4vi.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-22 15:15
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-1614895754-1450960922-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
.
Completion time: 2009-04-22 15:17
ComboFix-quarantined-files.txt 2009-04-22 19:17
Pre-Run: 88,970,694,656 bytes free
Post-Run: 89,136,640,000 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
191 — E O F — 2009-04-17 07:04
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:20:44 PM, on 4/22/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\Program Files\Stardock\WinCustomize\BootSkin\BootSkin.exe" /StartupJobs
O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone:
http://www.practice4performance.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/microsoftu…b?1211315408046
O16 - DPF: {BA2CB6B1-03EE-4068-87CC-F5E4DD772A9B} (CCAOControl Object) -
https://citrix2.cleanevent.com/CitrixLogonP…t/CitrixCAO.cab
O20 - Winlogon Notify: f0f704a9579 - C:\WINDOWS\
O20 - Winlogon Notify: __c00D5B8A - C:\WINDOWS\
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
–
End of file - 5665 bytes