File has already been analysed:
MD5: c23f378e5fb6f61370c6d03ccce6d731
Date: 12.22.2007 14:45:37 (CET) [<1D]
Results: 1/32
Permalink: resultado.html?54b71cc4382133ccbeaa83d76f40974b
File windows_ received on 12.22.2007 14:45:37 (CET)
Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED
Result: 1/32 (3.13%)
Loading server information…
Your file is queued in position: ___.
Estimated start time is between ___ and ___ .
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact Print results
Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.
You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
Email:
Antivirus Version Last Update Result
AhnLab-V3 - - -
AntiVir - - -
Authentium - - -
Avast - - -
AVG - - -
BitDefender - - -
CAT-QuickHeal - - -
ClamAV - - -
DrWeb - - -
eSafe - - -
eTrust-Vet - - -
Ewido - - -
FileAdvisor - - -
Fortinet - - -
F-Prot - - -
F-Secure - - -
Ikarus - - -
Kaspersky - - -
McAfee - - -
Microsoft - - -
NOD32v2 - - -
Norman - - -
Panda - - -
Prevx1 - - Heuristic: Suspicious File With Outbound Communications
Rising - - -
Sophos - - -
Sunbelt - - -
Symantec - - -
TheHacker - - -
VBA32 - - -
VirusBuster - - -
Webwasher-Gateway - - -
Additional information
MD5: c23f378e5fb6f61370c6d03ccce6d731
ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.
File xjnopfq.exe received on 12.23.2007 01:28:47 (CET)
Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED
Result: 2/32 (6.25%)
Loading server information…
Your file is queued in position: ___.
Estimated start time is between ___ and ___ .
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact Print results
Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.
You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
Email:
Antivirus Version Last Update Result
AhnLab-V3 - - -
AntiVir - - -
Authentium - - -
Avast - - -
AVG - - -
BitDefender - - -
CAT-QuickHeal - - -
ClamAV - - -
DrWeb - - -
eSafe - - -
eTrust-Vet - - -
Ewido - - -
FileAdvisor - - -
Fortinet - - -
F-Prot - - -
F-Secure - - -
Ikarus - - -
Kaspersky - - -
McAfee - - -
Microsoft - - -
NOD32v2 - - -
Norman - - -
Panda - - -
Prevx1 - - Heuristic: Suspicious Self Modifying EXE
Rising - - -
Sophos - - -
Sunbelt - - -
Symantec - - -
TheHacker - - -
VBA32 - - -
VirusBuster - - -
Webwasher-Gateway - - Virus.Win32.FileInfector.gen (suspicious)
Additional information
MD5: f8ad1eed879f42a4629daf4655c67007
ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.
ComboFix 07-12-23.1 - Owner 2007-12-23 19:35:25.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.142 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner.YOUR-9EFB86816C\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\pos1304.tmp
C:\pos138D.tmp
C:\pos13FA.tmp
C:\pos1580.tmp
C:\pos1718.tmp
C:\pos1795.tmp
C:\pos1936.tmp
C:\pos1962.tmp
C:\pos1AA4.tmp
C:\pos1B58.tmp
C:\pos1BC2.tmp
C:\pos2135.tmp
C:\pos2136.tmp
C:\pos2137.tmp
C:\pos2138.tmp
C:\pos2317.tmp
C:\pos237C.tmp
C:\pos251D.tmp
C:\pos26D.tmp
C:\pos3D7.tmp
C:\pos524.tmp
C:\pos6.tmp
C:\pos60A.tmp
C:\posAF1.tmp
C:\posB88.tmp
C:\posCAB.tmp
C:\posE29.tmp
C:\posEE0.tmp
C:\posFA4.tmp
C:\posFB.tmp
C:\posFED.tmp
C:\posFFA.tmp
C:\Program Files\iSpy Full.lnk
C:\WINDOWS\iun6002ev.exe
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\msuuncerb.dll
C:\WINDOWS\system32\wlyuyarj.dll
.
The following files were disabled during the run:
C:\WINDOWS\system32\msuuncerb.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Viewpoint
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\ComponentRegistry.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\HostRegistry.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\MetaStreamConfig.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\MetaStreamID.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_00\URLCache.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_01\URLCache.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_02\URLCache.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_03\URLCache.ini
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_0\Button_0.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_0\Button_0.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_1\Button_1.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_1\Button_1.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_10\Button_10.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_10\Button_10.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_11\Button_11.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_11\Button_11.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_2\Button_2.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_2\Button_2.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_3\Button_3.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_3\Button_3.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_4\Button_4.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_4\Button_4.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_5\Button_5.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_5\Button_5.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_6\Button_6.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_6\Button_6.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_7\Button_7.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_7\Button_7.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_8\Button_8.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_8\Button_8.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_9\Button_9.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Button_9\Button_9.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\configurator\configurator.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\configurator\configurator.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\ErrorSearch\ErrorSearch.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\ErrorSearch\ErrorSearch.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\postInstallLayout\postInstallLayout.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\postInstallLayout\postInstallLayout.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\products\products.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\products\products.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Resources\Button_0\images\alot_icon_35x16.bmp
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Resources\Button_1\images\alot_search_24x16.bmp
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Resources\Button_2\images\default_285_alot_celeb_search.bmp
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Resources\Button_3\images\active_default_286_alot_celeb_news.bmp
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Resources\Button_3\images\default_286_alot_celeb_news.bmp
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Resources\Button_4\images\default_287_alot_celeb_center.bmp
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Resources\Button_5\images\default_288_alot_mrkt_bang.bmp
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Resources\Shared\images\alot_brand.png
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\TimerManager\TimerManager.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\TimerManager\TimerManager.xml.backup
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\toolbar.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\ToolbarSearch\ToolbarSearch.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Updater\Updater.xml
C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\alot\Updater\Updater.xml.backup
C:\pos1304.tmp
C:\pos138D.tmp
C:\pos13FA.tmp
C:\pos1580.tmp
C:\pos1718.tmp
C:\pos1795.tmp
C:\pos1936.tmp
C:\pos1962.tmp
C:\pos1AA4.tmp
C:\pos1B58.tmp
C:\pos1BC2.tmp
C:\pos2135.tmp
C:\pos2136.tmp
C:\pos2137.tmp
C:\pos2138.tmp
C:\pos2317.tmp
C:\pos237C.tmp
C:\pos251D.tmp
C:\pos26D.tmp
C:\pos3D7.tmp
C:\pos524.tmp
C:\pos6.tmp
C:\pos60A.tmp
C:\posAF1.tmp
C:\posB88.tmp
C:\posCAB.tmp
C:\posE29.tmp
C:\posEE0.tmp
C:\posFA4.tmp
C:\posFB.tmp
C:\posFED.tmp
C:\posFFA.tmp
C:\Program Files\Adssite Advanced Toolbar
C:\Program Files\Common Files\irii
C:\Program Files\iSpy Full.lnk
C:\Program Files\Router
C:\Program Files\Router\Router.exe
C:\Program Files\Router\UnInstall.exe
C:\Program Files\Viewpoint
C:\Program Files\Viewpoint\Viewpoint Experience Technology\AxMetaStream.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\ClassIDs.ini
C:\Program Files\Viewpoint\Viewpoint Experience Technology\ComponentMgr.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\AOLArt.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\AOLShell.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\AOLUserShell.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\Cursors.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\DataTracking.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\GifReader.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\JpegReader.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\LensFlares.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\Mts3Reader.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\ObjectMovie.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\SceneComponent.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\ServiceComponent.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\SreeDMMX.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\SWFView.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\VectorView.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\VMPAudio.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\VMPExtras.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\VMPSpeech.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\VMPVideo.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\WaveletReader.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\ZoomView.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\MetaStreamID.ini
C:\Program Files\Viewpoint\Viewpoint Experience Technology\MtsAxInstaller.exe
C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
C:\VundoFix Backups
C:\VundoFix Backups\addmorefiles.txt
C:\VundoFix Backups\bfcwkfxx.exe.bad
C:\VundoFix Backups\bwcayira.dll.bad
C:\VundoFix Backups\byxxvuu.dll.bad
C:\VundoFix Backups\codjqbys.dll.bad
C:\VundoFix Backups\ditdlall.dll.bad
C:\VundoFix Backups\dloupqgw.dll.bad
C:\VundoFix Backups\dohtnsgl.exe.bad
C:\VundoFix Backups\dumoneef.exe.bad
C:\VundoFix Backups\gbonusds.dll.bad
C:\VundoFix Backups\jsoblgby.dll.bad
C:\VundoFix Backups\kuqiqfyc.exe.bad
C:\VundoFix Backups\kuveyyip.exe.bad
C:\VundoFix Backups\ldicoqsl.exe.bad
C:\VundoFix Backups\llaldtid.ini.bad
C:\VundoFix Backups\llygamwf.dll.bad
C:\VundoFix Backups\lrjcbdhp.dll.bad
C:\VundoFix Backups\mcauecac.exe.bad
C:\VundoFix Backups\mplmfana.exe.bad
C:\VundoFix Backups\npqcdqyx.dll.bad
C:\VundoFix Backups\okgheliu.dll.bad
C:\VundoFix Backups\olbrrwgv.exe.bad
C:\VundoFix Backups\prutv.bak1.bad
C:\VundoFix Backups\prutv.bak2.bad
C:\VundoFix Backups\prutv.ini.bad
C:\VundoFix Backups\qwxcqryg.exe.bad
C:\VundoFix Backups\riiyyqeh.exe.bad
C:\VundoFix Backups\rmjbsthx.dll.bad
C:\VundoFix Backups\spxkhucl.dll.bad
C:\VundoFix Backups\sybqjdoc.ini.bad
C:\VundoFix Backups\tdlythah.dll.bad
C:\VundoFix Backups\thufremu.exe.bad
C:\VundoFix Backups\urootcle.dll.bad
C:\VundoFix Backups\vturp.dll.bad
C:\VundoFix Backups\wgqpuold.ini.bad
C:\VundoFix Backups\wlyuyarj.dll.bad
C:\VundoFix Backups\wlyuyarj.dllbox.bad
C:\VundoFix Backups\wwrttvfu.dll.bad
C:\VundoFix Backups\xhtsbjmr.ini.bad
C:\VundoFix Backups\xvdxowgi.dll.bad
C:\VundoFix Backups\xyqdcqpn.ini.bad
C:\VundoFix Backups\xzrxgdpu.dll.bad
C:\VundoFix Backups\xzrxgdpu.dllbox.bad
C:\VundoFix Backups\ycljrhip.exe.bad
C:\VundoFix Backups\ytkdetcb.dll.bad
C:\WINDOWS\iun6002ev.exe
C:\WINDOWS\lahtgfws
C:\WINDOWS\lahtgfws\1.png
C:\WINDOWS\lahtgfws\2.png
C:\WINDOWS\lahtgfws\3.png
C:\WINDOWS\lahtgfws\4.png
C:\WINDOWS\lahtgfws\5.png
C:\WINDOWS\lahtgfws\6.png
C:\WINDOWS\lahtgfws\7.png
C:\WINDOWS\lahtgfws\8.png
C:\WINDOWS\lahtgfws\9.png
C:\WINDOWS\lahtgfws\bottom-rc.gif
C:\WINDOWS\lahtgfws\config.png
C:\WINDOWS\lahtgfws\content.png
C:\WINDOWS\lahtgfws\download.gif
C:\WINDOWS\lahtgfws\frame-bg.gif
C:\WINDOWS\lahtgfws\frame-bottom-left.gif
C:\WINDOWS\lahtgfws\frame-h1bg.gif
C:\WINDOWS\lahtgfws\head.png
C:\WINDOWS\lahtgfws\icon.png
C:\WINDOWS\lahtgfws\index.html
C:\WINDOWS\lahtgfws\main.css
C:\WINDOWS\lahtgfws\memory-prots.png
C:\WINDOWS\lahtgfws\net.png
C:\WINDOWS\lahtgfws\pc-mag.gif
C:\WINDOWS\lahtgfws\pc.gif
C:\WINDOWS\lahtgfws\poloska1.png
C:\WINDOWS\lahtgfws\poloska2.png
C:\WINDOWS\lahtgfws\poloska3.png
C:\WINDOWS\lahtgfws\promo1.html
C:\WINDOWS\lahtgfws\promo10.html
C:\WINDOWS\lahtgfws\promo11.html
C:\WINDOWS\lahtgfws\promo12.html
C:\WINDOWS\lahtgfws\promo13.html
C:\WINDOWS\lahtgfws\promo14.html
C:\WINDOWS\lahtgfws\promo15.html
C:\WINDOWS\lahtgfws\promo16.html
C:\WINDOWS\lahtgfws\promo17.html
C:\WINDOWS\lahtgfws\promo18.html
C:\WINDOWS\lahtgfws\promo2.html
C:\WINDOWS\lahtgfws\promo3.html
C:\WINDOWS\lahtgfws\promo4.html
C:\WINDOWS\lahtgfws\promo5.html
C:\WINDOWS\lahtgfws\promo6.html
C:\WINDOWS\lahtgfws\promo7.html
C:\WINDOWS\lahtgfws\promo8.html
C:\WINDOWS\lahtgfws\promo9.html
C:\WINDOWS\lahtgfws\reg.png
C:\WINDOWS\lahtgfws\repair.png
C:\WINDOWS\lahtgfws\scr-1.png
C:\WINDOWS\lahtgfws\scr-2.png
C:\WINDOWS\lahtgfws\start.png
C:\WINDOWS\lahtgfws\styles.css
C:\WINDOWS\lahtgfws\top-rc.gif
C:\WINDOWS\lahtgfws\vline.gif
C:\WINDOWS\lahtgfws\wp.png
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\wlyuyarj.dll
C:\WINDOWS\system32\wlyuyarj.dllbox
.
((((((((((((((((((((((((( Files Created from 2007-11-24 to 2007-12-24 )))))))))))))))))))))))))))))))
.
2007-12-23 19:10 . 2007-12-23 19:31 7,168 –a—— C:\WINDOWS\system32\windows
2007-12-23 18:28 . 2007-12-23 18:28 14,033 –a—— C:\pos290F.tmp
2007-12-23 17:44 . 2007-12-23 17:44 14,033 –a—— C:\pos2903.tmp
2007-12-22 16:20 . 2007-12-22 16:20 14,033 –a—— C:\pos24FB.tmp
2007-12-22 16:19 . 2007-12-22 16:19 14,033 –a—— C:\pos237A.tmp
2007-12-22 15:48 . 2007-12-22 15:48 14,033 –a—— C:\pos2315.tmp
2007-12-22 11:22 . 2007-12-22 11:23 14,033 –a—— C:\pos212C.tmp
2007-12-22 09:24 . 2007-12-22 09:24 d——– C:\WINDOWS\ERUNT
2007-12-22 09:13 . 2007-12-22 09:13 14,033 –a—— C:\pos1BBF.tmp
2007-12-22 08:59 . 2007-12-22 08:59 14,033 –a—— C:\pos1B4D.tmp
2007-12-22 08:58 . 2007-12-22 08:58 14,033 –a—— C:\pos1A9A.tmp
2007-12-22 08:45 . 2007-12-22 08:45 14,033 –a—— C:\pos195D.tmp
2007-12-22 08:44 . 2007-12-22 08:44 14,033 –a—— C:\pos192B.tmp
2007-12-22 08:43 . 2007-12-22 08:43 14,033 –a—— C:\pos1785.tmp
2007-12-21 20:08 . 2007-12-21 20:08 14,033 –a—— C:\pos175B.tmp
2007-12-21 20:07 . 2007-12-21 20:08 14,033 –a—— C:\pos1716.tmp
2007-12-21 07:34 . 2007-12-21 07:34 14,033 –a—— C:\pos156F.tmp
2007-12-21 07:33 . 2007-12-21 07:33 14,033 –a—— C:\pos13F5.tmp
2007-12-21 03:11 . 2007-12-21 03:11 14,033 –a—— C:\pos138B.tmp
2007-12-21 03:10 . 2007-12-21 03:10 14,033 –a—— C:\pos12FE.tmp
2007-12-20 18:28 . 2007-12-20 18:28 14,033 –a—— C:\posFF9.tmp
2007-12-20 18:27 . 2007-12-20 18:28 14,033 –a—— C:\posFE5.tmp
2007-12-20 17:10 . 2007-12-20 17:10 14,033 –a—— C:\posF8B.tmp
2007-12-20 17:09 . 2007-12-20 17:10 14,033 –a—— C:\posEDB.tmp
2007-12-20 16:55 . 2007-12-20 16:55 14,033 –a—— C:\posB7B.tmp
2007-12-20 16:54 . 2007-12-20 16:55 14,033 –a—— C:\posAE7.tmp
2007-12-20 16:25 . 2007-12-20 16:25 14,033 –a—— C:\posE27.tmp
2007-12-20 16:24 . 2007-12-20 16:24 14,033 –a—— C:\posC96.tmp
2007-12-20 15:51 . 2007-12-20 15:51 165,472 –a—— C:\WINDOWS\system32\gwytgksv.dll
2007-12-20 15:28 . 2007-12-20 15:28 d——– C:\Documents and Settings\All Users\Application Data\PopCap
2007-12-20 15:01 . 2007-12-20 15:01 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-12-20 15:01 . 2007-12-20 15:01 1,409 –a—— C:\WINDOWS\QTFont.for
2007-12-20 10:45 . 2007-12-20 10:46 14,033 –a—— C:\pos608.tmp
2007-12-20 10:18 . 2007-12-20 10:19 14,033 –a—— C:\pos50A.tmp
2007-12-20 10:07 . 2007-12-20 10:07 14,033 –a—— C:\pos3C5.tmp
2007-12-20 10:06 . 2007-12-20 10:06 14,033 –a—— C:\pos54.tmp
2007-12-20 09:35 . 2007-12-20 09:35 14,033 –a—— C:\pos26B.tmp
2007-12-20 09:34 . 2007-12-20 09:34 14,033 –a—— C:\posF9.tmp
2007-12-13 03:31 . 2007-12-20 15:31 d——– C:\Program Files\QdrPack(3)
2007-12-13 03:31 . 2007-12-20 15:31 d——– C:\Program Files\QdrModule(3)
2007-12-12 04:28 . 2007-12-20 15:34 d——– C:\Program Files\Outerinfo(2)
2007-12-06 17:36 . 2007-12-20 15:35 d——– C:\Program Files\QdrPack(2)
2007-12-06 17:36 . 2007-12-20 15:35 d——– C:\Program Files\QdrModule(2)
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-23 23:30 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-20 22:06 ——— d—–w C:\Program Files\Java
2007-12-20 20:36 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-12-20 20:34 ——— d—–w C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\AdobeUM
2007-12-20 00:01 ——— d—–w C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\UseNeXT
2007-12-05 14:56 ——— d—–w C:\Program Files\Yahoo!
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-10 13:11 ——— d—–w C:\Program Files\BoontyGames
2007-11-10 13:08 ——— d—–w C:\Program Files\GameFiesta
2007-11-10 13:07 ——— d—–w C:\Program Files\Gateway Games
2007-11-10 12:39 ——— d—–w C:\Program Files\High Quality Photo Resizer
2007-11-10 03:44 41,712 —-a-w C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\GDIPFONTCACHEV1.DAT
2007-11-07 21:28 ——— d—–w C:\Program Files\Photo Merge and Rename
2007-11-07 20:48 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-07 20:48 ——— d—–w C:\Program Files\PhotoBuilder
2007-11-07 20:20 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-11-07 20:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\InstallShield
2007-10-28 23:16 ——— d—–w C:\Program Files\Pilot Group Ltd
2007-10-24 00:30 ——— d—–w C:\Program Files\Microsoft Money 2006
2007-08-05 13:57 576 -c–a-w C:\Documents and Settings\Owner.YOUR-9EFB86816C\Application Data\wklnhst.dat
.
((((((((((((((((((((((((((((( snapshot@2007-12-23_16.44.04.93 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-03-29 21:27:02 9,845 -c–a-w C:\WINDOWS\system32\mswrn9ofe.dll
+ 2007-02-07 00:41:13 9,845 -c–a-w C:\WINDOWS\system32\mswrn9ofe.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 14:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24]
"Power2GoExpress"="NA" []
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 18:03]
"igndlm.exe"="C:\Program Files\Download Manager\DLM.exe" [2007-03-05 16:57]
"ProStoresStoreMonitor"="C:\Program Files\ProStores\StoreMonitor\StoreMonitor.exe" [2005-09-22 20:15]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 22:56]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-06-14 22:50]
"readericon"="C:\Program Files\Digital Media Reader\readericon45G.exe" [2005-12-09 20:44]
"RTHDCPL"="RTHDCPL.EXE" [2005-11-09 07:14 C:\WINDOWS\RTHDCPL.exe]
"HostManager"="C:\Program Files\Common Files\AOL\1181880268\EE\AOLHostManager.exe" [2004-11-03 16:03]
"AOL Spyware Protection"="C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2004-10-18 19:42]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-10 14:00 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2005-11-30 06:02 C:\WINDOWS\system32\nwiz.exe]
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" []
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 18:19 C:\WINDOWS\arpwrmsg.exe]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 18:16]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-10 14:00 C:\WINDOWS\system32\rundll32.exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-14 23:05]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 14:57]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BigFix.lnk - C:\Program Files\BigFix\bigfix.exe [2007-10-13 13:47:24]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04]
WG111v2 Smart Wizard Wireless Setting.lnk - C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe [2007-08-22 17:25:59]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
R2 Belkin Wireless USB Network Adapter Service;Belkin Wireless USB Network Adapter;C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe [2004-03-29 15:08]
R2 EAPPkt;Realtek EAPPkt Protocol;C:\WINDOWS\system32\DRIVERS\EAPPkt.sys [2005-04-01 10:43]
S3 Boonty Games;Boonty Games;"C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe" [2007-09-20 21:16]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys [2006-03-27 16:53]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c87c5be5-62f5-11dc-a80e-001150c173cc}]
\Shell\AutoRun\command - J:\PortableVault.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-23 19:43:32
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-23 19:46:31 - machine was rebooted
C:\ComboFix2.txt … 2007-12-23 16:45
.
2007-12-21 08:02:47 — E O F —
Logfile of HijackThis v1.99.1
Scan saved at 7:55:32 PM, on 12/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\ProStores\StoreMonitor\StoreMonitor.exe
C:\PROGRA~1\COMMON~1\AOL\118188~1\EE\AOLHOS~1.EXE
C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe
C:\PROGRA~1\COMMON~1\AOL\118188~1\EE\AOLServiceHost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1181880268\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [ProStoresStoreMonitor] C:\Program Files\ProStores\StoreMonitor\StoreMonitor.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WG111v2 Smart Wizard Wireless Setting.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} (ScrabbleCubes Control) -
http://www.worldwinner.com/games/v46/scrab…rabblecubes.cab
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) -
http://www.worldwinner.com/games/v47/share…GamesLoader.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} (king.com) -
http://www.king.com/ctl/kingcomie.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) -
http://lads.myspace.com/upload/MySpaceUploader.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) -
http://static.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {F73BE1F4-82AA-4405-AB81-FAFB5A122359} (SiteBuilderEditor Class) -
http://store01.prostores.com/storeadmin/ut…es/pssbedit.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Belkin Wireless USB Network Adapter (Belkin Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxcc_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcccoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS