When booting up this morning (XP SP3), a number of DOS boxes kept opening up with the words "C:windows/system32/command.com".
I ran my AVG 8.5, Spybot. It came back a few times but now seems to be gone.
The new thing that comes up in scans is "WIN32.TDSS.rtk. I now have Malwarebytes Anti Malware and it keeps finding "Trojan.TDSS". It says that it removes the problems, but when I reboot, it continues to come back.
Also, for what it's worth, I tried to do a System Restore. It showed the restore points, but when I clicked on a restore piont to go back to an earlier day, nothing happens. It's not frozen up, just nothing happens.
Thanks in advance for the help.
Logfile of HijackThis v1.99.1
Scan saved at 11:35:49 AM, on 8/10/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Nero\Nero 9\InCD\InCDSrv.exe
C:\Program Files\Microsoft SQL Server\MSSQL$ALAMODE\Binn\sqlservr.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files\Nero\Nero 9\InCD\NBHRegInCDSrv.exe
C:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton Ghost\Agent\GhostTray.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
F:\ITunes\iTunesHelper.exe
C:\Program Files\a la mode\Sched\eSched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Nero\Nero 9\InCD\InCD.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Virtual Weather Station Pro\vws.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.thedaily.com/bikini.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Norton Ghost 10.0] "C:\Program Files\Norton Ghost\Agent\GhostTray.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [iTunesHelper] "F:\ITunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [The Assistant] C:\Program Files\a la mode\Sched\eSched.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 9\InCD\InCD.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\RunOnce: [SpybotDeletingA3307] command.com /c del "C:\WINDOWS\system32\drivers\SKYNETmcrydppe.sys_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2821] cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETmcrydppe.sys_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5859] command.com /c del "C:\WINDOWS\system32\drivers\SKYNETmcrydppe.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2550] cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETmcrydppe.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1795] command.com /c del "C:\WINDOWS\system32\SKYNETbcmpxmdx.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4169] cmd.exe /c del "C:\WINDOWS\system32\SKYNETbcmpxmdx.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8911] command.com /c del "C:\WINDOWS\system32\SKYNETbcmpxmdx.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4846] cmd.exe /c del "C:\WINDOWS\system32\SKYNETbcmpxmdx.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7251] command.com /c del "C:\WINDOWS\system32\SKYNETyliotpjp.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4792] cmd.exe /c del "C:\WINDOWS\system32\SKYNETyliotpjp.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5139] command.com /c del "C:\WINDOWS\system32\SKYNETyliotpjp.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1078] cmd.exe /c del "C:\WINDOWS\system32\SKYNETyliotpjp.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4285] command.com /c del "C:\WINDOWS\system32\SKYNETidwkssov.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC791] cmd.exe /c del "C:\WINDOWS\system32\SKYNETidwkssov.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7004] command.com /c del "C:\WINDOWS\system32\SKYNETidwkssov.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6178] cmd.exe /c del "C:\WINDOWS\system32\SKYNETidwkssov.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA141] command.com /c del "C:\WINDOWS\system32\SKYNETupjcpuwy.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC885] cmd.exe /c del "C:\WINDOWS\system32\SKYNETupjcpuwy.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6022] command.com /c del "C:\WINDOWS\system32\SKYNETupjcpuwy.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8808] cmd.exe /c del "C:\WINDOWS\system32\SKYNETupjcpuwy.dat"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SB Audigy 2 Startup Menu] /L:ENG
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB4790] command.com /c del "C:\WINDOWS\system32\drivers\SKYNETmcrydppe.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2923] cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETmcrydppe.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3862] command.com /c del "C:\WINDOWS\system32\drivers\SKYNETmcrydppe.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2399] cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETmcrydppe.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2288] command.com /c del "C:\WINDOWS\system32\SKYNETbcmpxmdx.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6684] cmd.exe /c del "C:\WINDOWS\system32\SKYNETbcmpxmdx.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9584] command.com /c del "C:\WINDOWS\system32\SKYNETbcmpxmdx.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4254] cmd.exe /c del "C:\WINDOWS\system32\SKYNETbcmpxmdx.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2914] command.com /c del "C:\WINDOWS\system32\SKYNETyliotpjp.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1068] cmd.exe /c del "C:\WINDOWS\system32\SKYNETyliotpjp.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8940] command.com /c del "C:\WINDOWS\system32\SKYNETyliotpjp.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6940] cmd.exe /c del "C:\WINDOWS\system32\SKYNETyliotpjp.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1456] command.com /c del "C:\WINDOWS\system32\SKYNETidwkssov.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4676] cmd.exe /c del "C:\WINDOWS\system32\SKYNETidwkssov.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8414] command.com /c del "C:\WINDOWS\system32\SKYNETidwkssov.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8625] cmd.exe /c del "C:\WINDOWS\system32\SKYNETidwkssov.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5551] command.com /c del "C:\WINDOWS\system32\SKYNETupjcpuwy.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8555] cmd.exe /c del "C:\WINDOWS\system32\SKYNETupjcpuwy.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5315] command.com /c del "C:\WINDOWS\system32\SKYNETupjcpuwy.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2679] cmd.exe /c del "C:\WINDOWS\system32\SKYNETupjcpuwy.dat"
O4 - Startup: Secunia PSI (RC4).lnk = C:\Program Files\Secunia\PSI (RC4)\psi.exe
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://*.lvarmls.com
O15 - Trusted Zone: http://*.nwmls.com
O15 - Trusted Zone: http://*.vvmls.com
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDow ... eqlab3.cab
O16 - DPF: {6DE617B8-49C0-40F8-8118-D2C3741F1C28} (SetTrustedSitesControl.clsReg) - http://locmedia.nwmls.com/tools/MlsToTr ... ontrol.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 1565853709
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15028/CTPID.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (file missing)
O18 - Filter: text/html - {2d4734f0-5df5-4907-a33f-85b07ab73638} - C:\WINDOWS\system32\mst122.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDSrv) - Nero AG - C:\Program Files\Nero\Nero 9\InCD\InCDSrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: MSSQL$ALAMODE - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$ALAMODE\Binn\sqlservr.exe" -sALAMODE (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: Nero Registry InCD Service (NeroRegInCDSrv) - Nero AG - C:\Program Files\Nero\Nero 9\InCD\NBHRegInCDSrv.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SQLAgent$ALAMODE - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$ALAMODE\Binn\sqlagent.EXE" -i ALAMODE (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe