-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Friday, June 06, 2008 4:35:05 PM
Operating System: Microsoft Windows Vista Home Edition, (Build 6000)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 6/06/2008
Kaspersky Anti-Virus database records: 833663
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 130981
Number of viruses found: 5
Number of infected objects: 62
Number of suspicious objects: 0
Duration of the scan process: 02:10:56
Infected Object Name / Virus Name / Last Action
C:\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Office.en-us/OfficeMUI.exe/update.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Office.en-us/OfficeMUI.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Office.en-us/OfficeMUISet.exe/update.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Office.en-us/OfficeMUISet.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Office64.en-us/Office64MUI.exe/update.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Office64.en-us/Office64MUI.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Office64.en-us/Office64MUISet.exe/update.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Office64.en-us/Office64MUISet.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Proofing.en-us/Proof.en/Proof.exe/update.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Proofing.en-us/Proof.en/Proof.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Proofing.en-us/Proof.es/Proof.exe/update.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Proofing.en-us/Proof.es/Proof.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Proofing.en-us/Proof.fr/Proof.exe/update.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Proofing.en-us/Proof.fr/Proof.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Proofing.en-us/Proofing.exe/update.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Proofing.en-us/Proofing.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Rosebud.en-us/RosebudMUI.exe/update.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Rosebud.en-us/RosebudMUI.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/setup.exe/update.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/setup.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/WebDesigner.en-us/WebDesignerMUI.exe/update.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/WebDesigner.en-us/WebDesignerMUI.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/WebDesigner.WW/Office64WW.exe/update.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/WebDesigner.WW/Office64WW.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/WebDesigner.WW/WebDesignerWW.exe/update.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/WebDesigner.WW/WebDesignerWW.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar RAR: infected - 26 skipped
C:\Program Files\InstallShield Installation Information\{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}\Setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{B145EC69-66F5-11D8-9D75-000129760D75}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{B804C424-B66D-447A-84BD-C6B88C392C3A}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{EFBDC2B0-FAA8-4B78-8DE1-AEBE7958FA37}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{F79A208D-D929-11D9-9D77-000129760D75}\setup.ilg Object is locked skipped
C:\Program Files\Nero\Nero8\Nero BackItUp\BIU9839.txt Object is locked skipped
C:\ProgramData\avg7\Log\emc.log Object is locked skipped
C:\ProgramData\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\ProgramData\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3dd73f2ffceff2e1a38ac7bf71e02846_1813b7fa-6b78-40c7-97a3-a02bb7b5f3ac Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5432b656786d809c24c1c61f27b0205a_2d40fb33-49e0-49ec-893b-9503ec2e2da5 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9f7a53ae8a998b18ee83b063f84cbb68_2d40fb33-49e0-49ec-893b-9503ec2e2da5 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a245bed7ae991b8daff703982d5e4ead_1813b7fa-6b78-40c7-97a3-a02bb7b5f3ac Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ae312568acf22e79789e507e6269a537_1813b7fa-6b78-40c7-97a3-a02bb7b5f3ac Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\bc0b31a1775b8384e942ee50d0562f6b_1813b7fa-6b78-40c7-97a3-a02bb7b5f3ac Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\bf8aece8b782c452da9452251c2e86d1_2d40fb33-49e0-49ec-893b-9503ec2e2da5 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cd73efca1b828f9bcc99a0b81402654e_1813b7fa-6b78-40c7-97a3-a02bb7b5f3ac Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ddf2bcbaf53106d123d4455d08aacf6f_2d40fb33-49e0-49ec-893b-9503ec2e2da5 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\eb347e7b01c6b9c21b1691a8f0eef7e3_2d40fb33-49e0-49ec-893b-9503ec2e2da5 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f00241eae9bfaf501cd8a1b3152ce025_1813b7fa-6b78-40c7-97a3-a02bb7b5f3ac Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f56f394e3272cd5a9e9ce3eb2e6e95e3_5b4feb49-5573-42f5-bc41-2614fccf585d Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f5c726b72b72a4c1352f3ee68e701f4a_1813b7fa-6b78-40c7-97a3-a02bb7b5f3ac Object is locked skipped
C:\ProgramData\Microsoft\Windows\DRM\Cache\Indiv01.tmp Object is locked skipped
C:\ProgramData\Microsoft\Windows\DRM\drmstore.hds Object is locked skipped
C:\ProgramData\Nero\Nero8\Nero BackItUp\Cache\NeroBackItUpScheduler3.log Object is locked skipped
C:\Users\Garry\AppData\Local\Ahead\Nero Home\bl.db Object is locked skipped
C:\Users\Garry\AppData\Local\Ahead\Nero Home\is2.db Object is locked skipped
C:\Users\Garry\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped
C:\Users\Garry\AppData\Local\Microsoft\Media Player\CurrentDatabase_360.wmdb Object is locked skipped
C:\Users\Garry\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db Object is locked skipped
C:\Users\Garry\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped
C:\Users\Garry\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008060620080607\index.dat Object is locked skipped
C:\Users\Garry\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Users\Garry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Users\Garry\AppData\Local\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Users\Garry\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Object is locked skipped
C:\Users\Garry\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Object is locked skipped
C:\Users\Garry\AppData\Local\Microsoft\Windows\UsrClass.dat{c9ea72bd-78ca-11dc-affa-0016d354dfda}.TM.blf Object is locked skipped
C:\Users\Garry\AppData\Local\Microsoft\Windows\UsrClass.dat{c9ea72bd-78ca-11dc-affa-0016d354dfda}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\Garry\AppData\Local\Microsoft\Windows\UsrClass.dat{c9ea72bd-78ca-11dc-affa-0016d354dfda}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Users\Garry\AppData\Local\Microsoft\Windows Defender\FileTracker\{028688B7-DFAB-44D0-B444-620BF98D774E} Object is locked skipped
C:\Users\Garry\AppData\Local\Microsoft\Windows Sidebar\Settings.ini Object is locked skipped
C:\Users\Garry\AppData\Local\Temp\~DFA7DF.tmp Object is locked skipped
C:\Users\Garry\AppData\Local\Temp\~DFA7E9.tmp Object is locked skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\! CDRoller v7.00 - Crack Included\CDRoller700_en.exe/data0000.cab/update.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.qpu skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\! CDRoller v7.00 - Crack Included\CDRoller700_en.exe/data0000.cab Infected: not-a-virus:AdWare.Win32.Virtumonde.qpu skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\! CDRoller v7.00 - Crack Included\CDRoller700_en.exe Rsrc-Package: infected - 2 skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Office.en-us/OfficeMUI.exe/update.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Office.en-us/OfficeMUI.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Office.en-us/OfficeMUISet.exe/update.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Office.en-us/OfficeMUISet.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Office64.en-us/Office64MUI.exe/update.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Office64.en-us/Office64MUI.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Office64.en-us/Office64MUISet.exe/update.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Office64.en-us/Office64MUISet.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Proofing.en-us/Proof.en/Proof.exe/update.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Proofing.en-us/Proof.en/Proof.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Proofing.en-us/Proof.es/Proof.exe/update.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Proofing.en-us/Proof.es/Proof.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Proofing.en-us/Proof.fr/Proof.exe/update.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Proofing.en-us/Proof.fr/Proof.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Proofing.en-us/Proofing.exe/update.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Proofing.en-us/Proofing.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Rosebud.en-us/RosebudMUI.exe/update.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/Rosebud.en-us/RosebudMUI.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/setup.exe/update.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/setup.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/WebDesigner.en-us/WebDesignerMUI.exe/update.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/WebDesigner.en-us/WebDesignerMUI.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/WebDesigner.WW/Office64WW.exe/update.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/WebDesigner.WW/Office64WW.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/WebDesigner.WW/WebDesignerWW.exe/update.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar/Microsoft Expression Web (FrontPage 2007)/WebDesigner.WW/WebDesignerWW.exe Infected: Trojan.Win32.Monder.ld skipped
C:\Users\Garry\AppData\Local\VirtualStore\Program Files\BitLord\Downloads\Microsoft Expression Web (FrontPage 2007).rar RAR: infected - 26 skipped
C:\Users\Garry\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked skipped
C:\Users\Garry\Desktop\[4]-Submit_2008-06-06@1.18.zip/rQhEwUNg.dll Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Garry\Desktop\[4]-Submit_2008-06-06@1.18.zip ZIP: infected - 1 skipped
C:\Users\Garry\Downloads\Nero-8.1.1.0b_eng_trial.exe/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Users\Garry\Downloads\Nero-8.1.1.0b_eng_trial.exe 7-Zip: infected - 1 skipped
C:\Users\Garry\ntuser.dat Object is locked skipped
C:\Users\Garry\ntuser.dat.LOG1 Object is locked skipped
C:\Users\Garry\ntuser.dat.LOG2 Object is locked skipped
C:\Users\Garry\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped
C:\Users\Garry\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\Garry\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\bthservsdp.dat Object is locked skipped
C:\Windows\Debug\PASSWD.LOG Object is locked skipped
C:\Windows\Debug\sam.log Object is locked skipped
C:\Windows\Debug\WIA\wiatrace.log Object is locked skipped
C:\Windows\Logs\CBS\CBS.log Object is locked skipped
C:\Windows\Logs\CBS\CBS.persist.log Object is locked skipped
C:\Windows\Logs\DPX\setupact.log Object is locked skipped
C:\Windows\Logs\DPX\setuperr.log Object is locked skipped
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe.config Object is locked skipped
C:\Windows\Panther\UnattendGC\diagerr.xml Object is locked skipped
C:\Windows\Panther\UnattendGC\diagwrn.xml Object is locked skipped
C:\Windows\Panther\UnattendGC\setupact.log Object is locked skipped
C:\Windows\Panther\UnattendGC\setuperr.log Object is locked skipped
C:\Windows\SA0594035.tmp Object is locked skipped
C:\Windows\security\database\secedit.sdb Object is locked skipped
C:\Windows\SoftwareDistribution\DataStore\DataStore.edb Object is locked skipped
C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log Object is locked skipped
C:\Windows\SoftwareDistribution\DataStore\Logs\tmp.edb Object is locked skipped
C:\Windows\SoftwareDistribution\EventCache\{15F8C4B7-8CA7-4B9E-AC7F-1F47B6EC9F07}.bin Object is locked skipped
C:\Windows\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\catroot2\edb.log Object is locked skipped
C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\config\COMPONENTS Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG1 Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG2 Object is locked skipped
C:\Windows\System32\config\DEFAULT Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG1 Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG2 Object is locked skipped
C:\Windows\System32\config\SAM Object is locked skipped
C:\Windows\System32\config\SAM.LOG1 Object is locked skipped
C:\Windows\System32\config\SAM.LOG2 Object is locked skipped
C:\Windows\System32\config\SECURITY Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG1 Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG2 Object is locked skipped
C:\Windows\System32\config\SOFTWARE Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG1 Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG2 Object is locked skipped
C:\Windows\System32\config\SYSTEM Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG1 Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG2 Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000003.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000004.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{5ff84fe7-7f10-11dc-a7ee-0016d354dfda}.TxR.0.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{5ff84fe7-7f10-11dc-a7ee-0016d354dfda}.TxR.1.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{5ff84fe7-7f10-11dc-a7ee-0016d354dfda}.TxR.2.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{5ff84fe7-7f10-11dc-a7ee-0016d354dfda}.TxR.blf Object is locked skipped
C:\Windows\System32\LogFiles\Scm\SCM.EVM Object is locked skipped
C:\Windows\System32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\Windows\System32\restore\MachineGuid.txt Object is locked skipped
C:\Windows\System32\spool\SpoolerETW.etl Object is locked skipped
C:\Windows\System32\sysprep\Panther\diagerr.xml Object is locked skipped
C:\Windows\System32\sysprep\Panther\diagwrn.xml Object is locked skipped
C:\Windows\System32\sysprep\Panther\setupact.log Object is locked skipped
C:\Windows\System32\sysprep\Panther\setuperr.log Object is locked skipped
C:\Windows\System32\wbem\AutoRecover\1EBE968EB7AF815A32641E6185350A9E.mof Object is locked skipped
C:\Windows\System32\wbem\AutoRecover\3460B7617E0429A960E481B197F238A3.mof Object is locked skipped
C:\Windows\System32\wbem\AutoRecover\75054C3771DF289038069A9BB1C1FB6E.mof Object is locked skipped
C:\Windows\System32\wbem\AutoRecover\7BDE76979585395D59B5DA1D62E63C50.mof Object is locked skipped
C:\Windows\System32\wbem\AutoRecover\DFB9AD54AC2D3B8122567AAD3BF3EB7F.mof Object is locked skipped
C:\Windows\System32\wbem\Logs\WMITracing.log Object is locked skipped
C:\Windows\System32\wbem\repository\INDEX.BTR Object is locked skipped
C:\Windows\System32\wbem\repository\MAPPING1.MAP Object is locked skipped
C:\Windows\System32\wbem\repository\MAPPING2.MAP Object is locked skipped
C:\Windows\System32\wbem\repository\OBJECTS.DATA Object is locked skipped
C:\Windows\System32\winevt\Logs\Application.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\DFS Replication.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\HardwareEvents.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Internet Explorer.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Key Management Service.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Media Center.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-PLA%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Networking%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-DiskDiagnosticDataCollector%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-DriverFrameworks-UserMode%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Help%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-MUI%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ParentalControls%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Leak-Diagnostic%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-RestartManager%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-UAC%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-UAC-FileVirtualization%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-WLAN-AutoConfig%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Security.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Setup.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\System.evtx Object is locked skipped
C:\Windows\Tasks\SCHEDLGU.TXT Object is locked skipped
C:\Windows\WindowsUpdate.log Object is locked skipped
C:\Windows\winsxs\x86_microsoft-windows-n..n_service_datastore_31bf3856ad364e35_6.0.6000.16386_none_cef7ceb03914a67f\dnary.xsd Object is locked skipped
D:\My Music\Limewire Shared\Eighties classic.wma Infected: Trojan-Downloader.WMA.Wimad.l skipped
Scan process completed.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:35, on 2008-06-06
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Users\Garry\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wermgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.virginmedia.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://en.uk.acer.yahoo.comR1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://uk.rd.yahoo.com/customize/ycomp/ ... .yahoo.comR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [Creative Launcher] C:\Program Files\Creative\Launcher\CTLauncher.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Corel Photo Downloader] "C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe" -startup
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\Windows\TEMP\E_S9CFA.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O13 - Gopher Prefix:
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) -
http://upload.facebook.com/controls/Fac ... oader5.cabO16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/eng/partne ... nicode.cabO16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) -
http://upload.facebook.com/controls/Fac ... oader3.cabO16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
http://javadl-esd.sun.com/update/1.6.0/ ... 586-jc.cabO16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) -
http://www.adobe.com/products/acrobat/nos/gp.cabO18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: eNetHook.dll
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: eDataSecurity Service - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 9792 bytes