For a minute it looked fixed it was able to delete the dll and after combofix restarted the computer I checked the process and alg was no longer running at startup. I rebooted the computer normally afterwards to double check and the process is back again. But the dll is gone as well as the sdfix folder so im thinking maybe this is something sdfix did. The three dlls that got put into the system32 folder are gone so I dont think there is anymore spyware that could be doing it. I memorize the number of files on the last row of the folder just to be safe and it was only one before the infection and after there was four so im pretty sure those three files were the only thing added that day. Somethine else that was strange is when I first ran sdfix for the first few reboots afterwards the wmiprvse process would run after connecting online then go away after about two minutes and I hadn't seen it do that since but after deleting that folder just now it started again then stopped. So should I just disable the alg process from running altogether because it might be possible that its only running because of something sdfix did.
ComboFix 08-05-21.2 - Owner 2008-05-27 18:13:47.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.0.1252.1.1033.18.298 [GMT -5:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\system32\disk.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\SDfix
C:\SDfix\SDFix\apps\assosfix.reg
C:\SDfix\SDFix\apps\cliptext.exe
C:\SDfix\SDFix\apps\download.exe
C:\SDfix\SDFix\apps\dummy.sys
C:\SDfix\SDFix\apps\Enable_Command_Prompt.reg
C:\SDfix\SDFix\apps\ERDNT.E_E
C:\SDfix\SDFix\apps\ERDNTDOS.LOC
C:\SDfix\SDFix\apps\ERDNTWIN.LOC
C:\SDfix\SDFix\apps\ERUNT.EXE
C:\SDfix\SDFix\apps\ERUNT.LOC
C:\SDfix\SDFix\apps\fix.reg
C:\SDfix\SDFix\apps\FixBH.reg
C:\SDfix\SDFix\apps\FixComponents.reg
C:\SDfix\SDFix\apps\FIXCU.reg
C:\SDfix\SDFix\apps\FIXLM.reg
C:\SDfix\SDFix\apps\FixPath.exe
C:\SDfix\SDFix\apps\FixRedir.reg
C:\SDfix\SDFix\apps\FixSchedule.reg
C:\SDfix\SDFix\apps\FixWebCheck.reg
C:\SDfix\SDFix\apps\fixXP.reg
C:\SDfix\SDFix\apps\FixXPsp2.reg
C:\SDfix\SDFix\apps\grep.exe
C:\SDfix\SDFix\apps\HPFix.reg
C:\SDfix\SDFix\apps\HPFix2.reg
C:\SDfix\SDFix\apps\HPFix3.reg
C:\SDfix\SDFix\apps\HPFix4.reg
C:\SDfix\SDFix\apps\HPFix5.reg
C:\SDfix\SDFix\apps\HPFix6.reg
C:\SDfix\SDFix\apps\HPFix7.reg
C:\SDfix\SDFix\apps\HPFix8.reg
C:\SDfix\SDFix\apps\isadmin.exe
C:\SDfix\SDFix\apps\leg2.txt
C:\SDfix\SDFix\apps\legacy.txt
C:\SDfix\SDFix\apps\legacybk.txt
C:\SDfix\SDFix\apps\locate.com
C:\SDfix\SDFix\apps\LS.exe
C:\SDfix\SDFix\apps\MD5File.exe
C:\SDfix\SDFix\apps\MyGcpvFix.reg
C:\SDfix\SDFix\apps\MyGkFix2.reg
C:\SDfix\SDFix\apps\Process.exe
C:\SDfix\SDFix\apps\procs.exe
C:\SDfix\SDFix\apps\psservice.exe
C:\SDfix\SDFix\apps\Rem.txt
C:\SDfix\SDFix\apps\Rem2.txt
C:\SDfix\SDFix\apps\Replace\regedit.exe
C:\SDfix\SDFix\apps\Replace\W2K.exe
C:\SDfix\SDFix\apps\Replace\w2k\beep.sys
C:\SDfix\SDFix\apps\Replace\w2k\null.sys
C:\SDfix\SDFix\apps\Replace\XP.exe
C:\SDfix\SDFix\apps\Replace\xp\beep.sys
C:\SDfix\SDFix\apps\Replace\xp\null.sys
C:\SDfix\SDFix\apps\Reset_AppInit_DLLs.reg
C:\SDfix\SDFix\apps\RestartIt!.exe
C:\SDfix\SDFix\apps\Restore_SecurityCenter.reg
C:\SDfix\SDFix\apps\Restore_SharedAccess.reg
C:\SDfix\SDFix\apps\sc.exe
C:\SDfix\SDFix\apps\sed.exe
C:\SDfix\SDFix\apps\SF.exe
C:\SDfix\SDFix\apps\shutdown.exe
C:\SDfix\SDFix\apps\srv2.txt
C:\SDfix\SDFix\apps\srv2bk.txt
C:\SDfix\SDFix\apps\svc.txt
C:\SDfix\SDFix\apps\svcbk.txt
C:\SDfix\SDFix\apps\swreg.exe
C:\SDfix\SDFix\apps\swsc.exe
C:\SDfix\SDFix\apps\unzip.exe
C:\SDfix\SDFix\apps\vfind.exe
C:\SDfix\SDFix\apps\WINMSG.EXE
C:\SDfix\SDFix\apps\winsec.reg
C:\SDfix\SDFix\apps\zip.exe
C:\SDfix\SDFix\backups\backupreg.zip
C:\SDfix\SDFix\backups\backups.zip
C:\SDfix\SDFix\backups\catchme.log
C:\SDfix\SDFix\backups\HOSTS
C:\SDfix\SDFix\catchme.exe
C:\SDfix\SDFix\dummy.sys
C:\SDfix\SDFix\Report.txt
C:\SDfix\SDFix\RunThis.bat
C:\SDfix\SDFix\SDFIX_ReadMe_Online.url
C:\WINDOWS\system32\disk.dll
.
((((((((((((((((((((((((( Files Created from 2008-04-27 to 2008-05-27 )))))))))))))))))))))))))))))))
.
2008-05-25 18:13 . 2008-05-25 18:13 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-25 18:13 . 2008-05-25 18:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-23 01:54 . 2008-05-23 01:54 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-23 01:54 . 2008-05-23 01:54 1,409 --a------ C:\WINDOWS\QTFont.for
2008-05-21 17:28 . 2008-05-21 17:28 <DIR> d-------- C:\Program Files\Alwil Software
2008-05-20 16:31 . 2008-05-20 15:57 691,545 --a------ C:\WINDOWS\unins000.exe
2008-05-20 16:31 . 2008-05-20 16:31 2,550 --a------ C:\WINDOWS\unins000.dat
2008-05-17 20:30 . 2008-05-17 20:30 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-17 20:30 . 2008-05-17 20:30 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-05-17 20:30 . 2008-05-17 20:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-17 20:30 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-17 20:30 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-09 13:55 . 2008-05-09 13:55 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-09 01:46 . 2008-05-09 01:46 <DIR> d-------- C:\WINDOWS\ERUNT
2008-05-09 01:43 . 2008-05-09 01:43 <DIR> d-------- C:\Documents and Settings\Administrator
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-20 21:42 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-05-19 06:01 --------- d-----w C:\Documents and Settings\Owner\Application Data\U3
2008-04-09 18:49 --------- d-----w C:\Program Files\PuzzleMaker Version 3
2008-04-09 02:53 --------- d-----w C:\Program Files\McGraw-Hill
2007-05-07 00:04 1,010 ----a-w C:\Program Files\DivXPlayer.dbf
.
------- Sigcheck -------
.
((((((((((((((((((((((((((((( snapshot@2008-05-22_18.34.51.18 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-22 23:28:01 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-27 05:19:32 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-05-22 23:28:03 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-05-22 23:59:42 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-05-22 23:28:03 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-05-22 23:59:42 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-05-22 23:28:03 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-05-22 23:59:42 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2005-05-24 17:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 20:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 20:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
+ 2008-05-27 05:19:45 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_49c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2005-06-21 15:48 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2005-06-21 15:44 126976]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-11 03:19 69632]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-05-06 16:08 98304]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2007-08-08 14:56 26112]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
hp psc 2000 Series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe [2002-05-29 13:57:06 323646]
officejet 6100.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe [2002-05-29 13:57:28 147456]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL Companion.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AOL Companion.lnk
backup=C:\WINDOWS\pss\AOL Companion.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection]
--a------ 2004-03-19 14:17 78960 C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASM]
--a------ 2006-11-07 15:11 2500096 C:\Program Files\AOL\Active Security Monitor\ASMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
--a------ 2007-10-08 16:50 41824 C:\Program Files\Common Files\AOL\1179228576\ee\AOLSoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft security adviser]
C:\Program Files\Microsoft Security Adviser\mssadv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msavsc.exe]
C:\Program Files\Microsoft Security Adviser\msavsc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msctrl.exe]
C:\Program Files\Microsoft Security Adviser\msctrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msfw.exe]
C:\Program Files\Microsoft Security Adviser\msfw.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msiemon.exe]
C:\Program Files\Microsoft Security Adviser\msiemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2001-08-02 06:14 1077277 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mssadv.exe]
C:\Program Files\Microsoft Security Adviser\msfw.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msscan.exe]
C:\Program Files\Microsoft Security Adviser\msscan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pure Networks Port Magic]
--a------ 2004-05-07 16:54 99480 C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RunOnce2Upd]
C:\WINDOWS\System32\KB_963493.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
-ra------ 2004-02-09 03:54 65024 C:\WINDOWS\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-05-22 17:39 32881 C:\Program Files\Java\j2re1.4.2_15\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\userinit]
C:\WINDOWS\System32\ntos.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"dnlsvc"=2 (0x2)
R1 aswSP;avast! Self Protection;C:\WINDOWS\System32\drivers\aswSP.sys [2008-05-15 18:20]
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2007-08-06 22:23:18 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 2100 series#1178485382.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-27 18:15:43
Windows 5.1.2600 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
"ServiceDll"="%SystemRoot%\System32\browser.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\C:]
.
Completion time: 2008-05-27 18:18:38
ComboFix-quarantined-files.txt 2008-05-27 23:17:36
ComboFix2.txt 2008-05-24 22:05:41
ComboFix3.txt 2008-05-22 23:35:06
Pre-Run: 32,228,306,944 bytes free
Post-Run: 32,226,050,048 bytes free
224
--------------------------------------------------------------------------------------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:26:12 PM, on 5/27/2008
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: officejet 6100.lnk = ?
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_15\bin\npjpi142_15.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_15\bin\npjpi142_15.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone:
http://fpdownload.macromedia.com
O15 - Trusted Zone:
http://www.macromedia.com
O15 - Trusted Zone:
http://moneycentral.msn.com
O15 - Trusted Zone:
http://sdc.shockwave.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} -
http://software-dl.r...ip/RdxIE601.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
--
End of file - 4597 bytes