hi,
thanks for your reply, cleaning.exe was indeed hijackthis.exe, i now placed it in a own folder on C:\
These two files are for bloomberg, they are okay, a real time news program that costs a fortune (see. www.bloomberg.com):
C:\blp\API\OFFICE~1\Bloomberg.UIServer.exe
C:\blp\API\OFFICE~1\Bloomberg.RtdServer.exe
First step:
Run MoveIt
output:
C:\WINDOWS\system32\qwerty12.exe moved successfully.
Created on 07-23-2007 21:42:16
Second step:
combodix.exe
after a reboot this log:
"Administrator" - 2007-07-23 21:43:43 - ComboFix 07-07-23.6 - Service Pack 2 NTFS
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\geebbab.dll
C:\WINDOWS\system32\mljjkhg.dll
C:\WINDOWS\byvwxy.dll
C:\WINDOWS\tutqqq.dll
C:\WINDOWS\system32\awvvt.exe
C:\WINDOWS\system32\ddccb.exe
C:\WINDOWS\system32\vturr.exe
C:\WINDOWS\yxwvyb.ini
C:\WINDOWS\qqqtut.ini
C:\WINDOWS\qqqtut.ini2
C:\WINDOWS\qqqtut.tmp
C:\WINDOWS\system32\audonv.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\ADMINI~1\APPLIC~1\tmp14.tmp.exe
C:\DOCUME~1\ADMINI~1\APPLIC~1\tmp16.tmp.exe
C:\DOCUME~1\ADMINI~1\APPLIC~1\tmp227.tmp.exe
C:\DOCUME~1\ADMINI~1\APPLIC~1\tmp7.tmp.exe
C:\DOCUME~1\ADMINI~1\APPLIC~1\tmp8.tmp.exe
C:\DOCUME~1\ADMINI~1\APPLIC~1\tmp85.tmp.exe
C:\DOCUME~1\ADMINI~1\APPLIC~1\tmp86.tmp.exe
C:\DOCUME~1\ADMINI~1\APPLIC~1\tmp8A.tmp.exe
C:\DOCUME~1\ADMINI~1\APPLIC~1\tmpA.tmp.exe
C:\DOCUME~1\ADMINI~1\APPLIC~1\tmpBA2.tmp.exe
C:\DOCUME~1\ADMINI~1\APPLIC~1\tmpBA9.tmp.exe
C:\Program Files\Common Files\drivecleaner free
C:\Program Files\Common Files\drivecleaner free\laststat.dat
C:\Program Files\ystem3~1
C:\WINDOWS\b122.exe
C:\WINDOWS\b136.exe
C:\WINDOWS\b138.exe
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\core.sys
C:\WINDOWS\system32\tmp16.tmp.dll
C:\WINDOWS\system32\tmp8.tmp.dll
C:\WINDOWS\system32\tmpBA9.tmp.dll
C:\WINDOWS\system32\wnsintisv32.exe
C:\WINDOWS\wr.txt
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
——-\LEGACY_CORE
——-\LEGACY_DOMAINSERVICE
——-\core
——-\DomainService
((((((((((((((((((((((((( Files Created from 2007-06-23 to 2007-07-23 )))))))))))))))))))))))))))))))
2007-07-23 21:43 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-23 21:31 d——– C:\hijackthis
2007-07-22 21:07 d——– C:\Program Files\Lavasoft
2007-07-22 21:07 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-07-22 21:06 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-07-22 20:17 d——– C:\backup drivers
2007-07-22 19:32 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-07-22 19:31 d——– C:\Program Files\SUPERAntiSpyware
2007-07-22 19:31 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\SUPERAntiSpyware.com
2007-07-22 17:53 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-07-22 12:34 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-07-22 09:27 d–h—– C:\WINDOWS\PIF
2007-07-22 09:09 d——– C:\Program Files\Common Files\Symantec Shared
2007-07-22 09:09 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
2007-07-19 23:23 d——– C:\WINDOWS\system32\xircom
2007-07-19 23:23 d——– C:\Program Files\microsoft frontpage
2007-07-19 22:56 d——– C:\Program Files\eMule
2007-07-19 22:55 89,088 –a—— C:\WINDOWS\system32\atl71.dll
2007-07-19 22:55 499,712 –a—— C:\WINDOWS\system32\msvcp71.dll
2007-07-19 22:55 348,160 –a—— C:\WINDOWS\system32\msvcr71.dll
2007-07-19 22:55 1,060,864 –a—— C:\WINDOWS\system32\mfc71.dll
2007-07-19 22:50 d——– C:\Program Files\LimeWire Turbo Accelerator
2007-07-19 22:50 d——– C:\Program Files\Common Files\Download Manager
2007-07-19 22:41 d——– C:\DOCUME~1\ADMINI~1\Shared
2007-07-19 22:41 d——– C:\DOCUME~1\ADMINI~1\Incomplete
2007-07-19 22:41 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\LimeWire
2007-07-17 22:53 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\MathWorks
2007-07-17 22:40 d——– C:\Program Files\MATLAB
2007-07-17 22:16 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Quantitative Micro Software
2007-07-17 20:10 d——– C:\DOCUME~1\ADMINI~1\Contacts
2007-07-15 19:49 d——– C:\Program Files\MSN Messenger
2007-07-06 22:37 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\ICAClient
2007-07-05 22:03 d——– C:\blp
2007-06-25 22:50 d——– C:\WINDOWS\SxsCaPendDel
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-22 19:50:59 ——– d—–w C:\Program Files\Common Files\InstallShield
2007-07-22 19:50:55 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-07-22 19:19:25 ——– d—–w C:\Program Files\DriverGuide Toolkit
2007-07-22 14:43:28 ——– d—–w C:\DOCUME~1\ADMINI~1\APPLIC~1\uTorrent
2007-07-21 23:19:01 ——– d—–w C:\Program Files\mIRC
2007-06-23 17:57:55 ——– d—–w C:\DOCUME~1\ADMINI~1\APPLIC~1\VoipBuster
2007-06-16 15:22:31 17,880 —ha-w C:\WINDOWS\system32\mlfcache.dat
2007-06-16 15:19:07 ——– d—–w C:\DOCUME~1\ADMINI~1\APPLIC~1\Apple Computer
2007-06-10 20:51:43 ——– d—–w C:\DOCUME~1\ADMINI~1\APPLIC~1\Configuration
2007-06-10 12:09:54 ——– d—–w C:\Program Files\RAXCO
2007-06-10 12:09:54 ——– d—–w C:\Program Files\Common Files\Raxco
2007-06-09 18:08:26 ——– d—–w C:\Program Files\LEd
2007-06-09 18:01:44 ——– d—–w C:\Program Files\MiKTeX 2.5
2007-06-04 14:18:48 9,344 —-a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2007-06-04 14:17:02 8,320 —-a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-06-04 14:14:56 6,272 —-a-w C:\WINDOWS\system32\drivers\AWRTPD.sys
2007-06-02 16:36:03 ——– d—–w C:\DOCUME~1\ADMINI~1\APPLIC~1\Red Chair Software
2007-06-02 16:36:02 ——– d—–w C:\Program Files\Red Chair Software
2007-06-02 16:14:11 ——– d—–w C:\Program Files\iPod Access for Windows
2007-06-01 22:00:46 ——– d—–w C:\DOCUME~1\ADMINI~1\APPLIC~1\Skype
2007-05-26 16:39:33 ——– d—–w C:\DOCUME~1\ADMINI~1\APPLIC~1\Ahead
2007-05-26 16:37:52 ——– d—–w C:\Program Files\Common Files\Ahead
2007-05-26 16:37:39 ——– d—–w C:\Program Files\Nero
2007-05-25 18:45:14 ——– d—–w C:\Program Files\Common Files\logishrd
2007-05-23 21:14:36 81 —-a-w C:\CTX.DAT
2007-05-20 20:08:36 1,277 —-a-w C:\WINDOWS\mozver.dat
2007-05-19 20:20:55 0 —-a-w C:\WINDOWS\nsreg.dat
2007-05-19 19:25:55 0 –sha-r C:\MSDOS.SYS
2007-05-19 19:25:55 0 –sha-r C:\IO.SYS
2007-05-19 19:25:55 0 —-a-w C:\CONFIG.SYS
2007-05-19 19:25:55 0 —-a-w C:\AUTOEXEC.BAT
2007-05-19 19:21:25 21,640 —-a-w C:\WINDOWS\system32\emptyregdb.dat
2007-05-16 15:32:55 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-04-25 14:21:15 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SkyTel"="SkyTel.EXE" [2006-05-17 01:04 C:\WINDOWS\SkyTel.exe]
"Alcmtr"="ALCMTR.EXE" [2005-05-04 01:43 C:\WINDOWS\Alcmtr.exe]
"AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [2005-08-25 21:21]
"Mouse Suite 98 Daemon"="ICO.EXE" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 15:57]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-07-28 01:10]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-05-16 09:27]
"12Voip"="C:\Program Files\12Voip.com\12Voip\12Voip.exe" []
"CLRHost"="C:\blp\API\OFFICE~1\bbxlcmd.exe" [2007-05-21 17:50]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"nltide_3"=rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\atmpnp]
atmpnp.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=c:\windows\system32\mljjkhg.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]
R1 Tosrfcom;Bluetooth RFCOMM;C:\WINDOWS\system32\Drivers\tosrfcom.sys
R2 rspndr;Link-Layer Topology Discovery Responder;C:\WINDOWS\system32\DRIVERS\rspndr.sys
R2 s24trans;WLAN Transport;C:\WINDOWS\system32\DRIVERS\s24trans.sys
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service;C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
R3 HSF_DPV;HSF_DPV;C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys
R3 HSFHWAZL;HSFHWAZL;C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys
R3 SNC;Sony Notebook Control Device;C:\WINDOWS\system32\DRIVERS\SonyNC.sys
R3 ti21sony;ti21sony;C:\WINDOWS\system32\drivers\ti21sony.sys
R3 tosporte;Bluetooth COM Port;C:\WINDOWS\system32\DRIVERS\tosporte.sys
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver;C:\WINDOWS\system32\DRIVERS\usbehci.sys
R3 usbhub;USB2 Enabled Hub;C:\WINDOWS\system32\DRIVERS\usbhub.sys
R3 usbstor;USB Mass Storage Driver;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver;C:\WINDOWS\system32\DRIVERS\usbuhci.sys
S3 LVUSBSta;Logitech USB Monitor Filter;C:\WINDOWS\system32\DRIVERS\LVUSBSta.sys
S3 NETw3x32;Intel® PRO/Wireless 3945ABG Adapter Driver for Windows XP 32 Bit;C:\WINDOWS\system32\DRIVERS\NETw3x32.sys
S3 PID_PEPI;Logitech QuickCam IM(PID_PEPI);C:\WINDOWS\system32\DRIVERS\LV302V32.SYS
S3 toshidpt;Bluetooth HID Port;C:\WINDOWS\system32\drivers\Toshidpt.sys
S3 tosrfbd;Bluetooth RFBUS;C:\WINDOWS\system32\DRIVERS\tosrfbd.sys
S3 tosrfbnp;Bluetooth RFBNEP;C:\WINDOWS\system32\Drivers\tosrfbnp.sys
S3 Tosrfhid;Bluetooth RFHID;C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys
S3 tosrfnds;Bluetooth Personal Area Network;C:\WINDOWS\system32\DRIVERS\tosrfnds.sys
S3 TosRfSnd;Bluetooth Audio;C:\WINDOWS\system32\drivers\tosrfsnd.sys
S3 Tosrfusb;Bluetooth USB Controller;C:\WINDOWS\system32\DRIVERS\tosrfusb.sys
S3 usbaudio;USB Audio Driver (WDM);C:\WINDOWS\system32\drivers\usbaudio.sys
S3 usbccgp;Microsoft USB Generic Parent Driver;C:\WINDOWS\system32\DRIVERS\usbccgp.sys
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-07-23 21:47:55
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden registry entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-23 21:48:38 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-07-23 21:48
— E O F —
Third step:
hijeckthis.exe log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:50:38, on 23-7-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\blp\API\OFFICE~1\Bloomberg.UIServer.exe
C:\blp\API\OFFICE~1\Bloomberg.RtdServer.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\Explorer.EXE
C:\hijackthis\hijackthis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [12Voip] "C:\Program Files\12Voip.com\12Voip\12Voip.exe" -nosplash -minimized
O4 - HKCU\..\Run: [CLRHost] C:\blp\API\OFFICE~1\bbxlcmd.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: c:\windows\system32\mljjkhg.dll
O20 - Winlogon Notify: atmpnp - atmpnp.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: iPod-service (iPod Service) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
–
End of file - 5650 bytes