Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: windows xp virus  (Read 13548 times)

0 Members and 1 Guest are viewing this topic.

7up

    Topic Starter


    Rookie

    windows xp virus
    « on: December 05, 2008, 07:04:42 AM »
    can anyone help me the BV virus, or at least that is what its says when I scan my computer with avast. It seems to have destroyed my system restore function, and if I do an internet search, click a link, it takes me to where ever it wants to.
    I really need to know specifics on killing this virus

    Carbon Dudeoxide

    • Global Moderator

    • Mastermind
    • Thanked: 169
      • Yes
      • Yes
      • Yes
    • Certifications: List
    • Experience: Guru
    • OS: Mac OS
    Re: windows xp virus
    « Reply #1 on: December 05, 2008, 07:09:58 AM »
    Welcome to ComputerHope.

    Please follow this:
    http://www.computerhope.com/forum/index.php/topic,46313.0.html

    Also, I'm moving this to the Computer Virus and Spyware Section.

    7up

      Topic Starter


      Rookie

      Re: windows xp virus
      « Reply #2 on: December 05, 2008, 01:18:12 PM »
      I made it to step 3, but my browser wont let me connect to superantivirus site. Any suggestions?

      7up

        Topic Starter


        Rookie

        Re: windows xp virus
        « Reply #3 on: December 05, 2008, 01:20:45 PM »
        i meant to say superantispyware site

        Carbon Dudeoxide

        • Global Moderator

        • Mastermind
        • Thanked: 169
          • Yes
          • Yes
          • Yes
        • Certifications: List
        • Experience: Guru
        • OS: Mac OS
        Re: windows xp virus
        « Reply #4 on: December 05, 2008, 08:07:27 PM »

        bobgar34



          Intermediate

          Thanked: 3
        • Experience: Experienced
        • OS: Windows XP
        Re: windows xp virus
        « Reply #5 on: December 06, 2008, 12:33:55 AM »
        after you get your system clean this will restore your system restore calender. unzip it and double click.

        [Saving space - attachment deleted by admin]

        Carbon Dudeoxide

        • Global Moderator

        • Mastermind
        • Thanked: 169
          • Yes
          • Yes
          • Yes
        • Certifications: List
        • Experience: Guru
        • OS: Mac OS
        Re: windows xp virus
        « Reply #6 on: December 05, 2008, 09:54:32 PM »
        after you get your system clean this will restore your system restore calender. unzip it and double click.
        Ignore this for now. Let's wait until our malware specialists have a look...

        7up

          Topic Starter


          Rookie

          Re: windows xp virus
          « Reply #7 on: December 06, 2008, 08:31:19 AM »
          that link does not open either, i get "page cannot be displayed".
          could this be a dns error or something else? if so how do I fix it so I can proceed with my virus issue?

          7up

            Topic Starter


            Rookie

            Re: windows xp virus
            « Reply #8 on: December 06, 2008, 08:52:16 AM »
            as I was reading post by other people, it seems that "poorstudent" and I are/were havinf the same problem. I was wondering if I could download the needed software to a flash drive, rename name it and load it on my infectec computer. If so, can anyone give me the steps and procedure to do this? Also HP is sending me a disc of XP, should I just wait on this and reimage my computer?

            Carbon Dudeoxide

            • Global Moderator

            • Mastermind
            • Thanked: 169
              • Yes
              • Yes
              • Yes
            • Certifications: List
            • Experience: Guru
            • OS: Mac OS
            Re: windows xp virus
            « Reply #9 on: December 06, 2008, 08:55:57 AM »
            I don't see how an XP CD will do anything besides formatting the Hard Drive (erasing everything) or....well that's it unless you want to risk keeping the virus.

            Anyways, yes. Download the three programs to a flash drive on another computer, rename them, and then transfer them over.

            7up

              Topic Starter


              Rookie

              Re: windows xp virus
              « Reply #10 on: December 07, 2008, 09:59:06 AM »
              SUPERAntiSpyware Scan Log
              http://www.superantispyware.com

              Generated 12/07/2008 at 11:46 AM

              Application Version : 4.22.1014

              Core Rules Database Version : 3640
              Trace Rules Database Version: 1623

              Scan type       : Complete Scan
              Total Scan Time : 00:17:20

              Memory items scanned      : 594
              Memory threats detected   : 0
              Registry items scanned    : 6816
              Registry threats detected : 5
              File items scanned        : 28461
              File threats detected     : 3

              Unclassified.Unknown Origin
                 HKU\S-1-5-21-2962165191-2854740113-1532012136-1008\Software\Classes\CLSID\{0656A137-B161-CADD-9777-E37A75727E78}
                 HKCR\CLSID\{0656A137-B161-CADD-9777-E37A75727E78}

              Trojan.DNS-Changer (Hi-Jacked DNS)
                 HKLM\SYSTEM\CONTROLSET002\SERVICES\TCPIP\PARAMETERS\INTERFACES\{71AC8796-5FBA-4AC0-B71A-D9C2D7075553}#NAMESERVER
                 HKLM\SYSTEM\CONTROLSET004\SERVICES\TCPIP\PARAMETERS\INTERFACES\{71AC8796-5FBA-4AC0-B71A-D9C2D7075553}#NAMESERVER

              Trojan.Unclassified/K-Series
                 HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON#SYSTEM

              Adware.Tracking Cookie
                 C:\Documents and Settings\Guest\Cookies\guest@2o7[1].txt
                 C:\Documents and Settings\Guest\Cookies\guest@atwola[2].txt
                 C:\Documents and Settings\Guest\Cookies\guest@doubleclick[1].txt


              this is what i found on my first superantispyware scan

              7up

                Topic Starter


                Rookie

                Re: windows xp virus
                « Reply #11 on: December 07, 2008, 10:26:16 AM »
                ok, know I cannot get MBAM to run, I loaded it to a flash drive, renamed it, and loaded it my infected computer, but it will not run, what now?

                Carbon Dudeoxide

                • Global Moderator

                • Mastermind
                • Thanked: 169
                  • Yes
                  • Yes
                  • Yes
                • Certifications: List
                • Experience: Guru
                • OS: Mac OS
                Re: windows xp virus
                « Reply #12 on: December 07, 2008, 05:43:45 PM »
                Can you get a HijackThis Log?

                7up

                  Topic Starter


                  Rookie

                  Re: windows xp virus
                  « Reply #13 on: December 08, 2008, 06:11:55 AM »
                  no, it does the same, "page cannot be displayed", if I try to go to the website to download, and if I download to a flash drive, it will not install HJT on the computer.
                  Avast scan says that autorun is infected in all drives.
                  Does anyone have telnet capabilities where they can remotely look at my computer, don't know if that would help or work, but I am stumbling in the dark here.

                  Carbon Dudeoxide

                  • Global Moderator

                  • Mastermind
                  • Thanked: 169
                    • Yes
                    • Yes
                    • Yes
                  • Certifications: List
                  • Experience: Guru
                  • OS: Mac OS
                  Re: windows xp virus
                  « Reply #14 on: December 08, 2008, 06:18:23 AM »
                  Try this.

                  On the damaged computer, go to Notepad and, leaving it blank, go to File --> Save As --> autorun.inf (save it to the desktop).
                  Now copy it to the root of all the drives on the computer. If it says 'do you want to replace a file', replace it.
                  On the other computer, install HJT.
                  Once installed, travel to C:\Program Files\Trend Micro\HijackThis and copy hijackthis.exe to the flash drive and rename it to sniper.exe.
                  Now try to get the log.

                  (note: Not sure if that's the exact path for hijackthis)

                  7up

                    Topic Starter


                    Rookie

                    Re: windows xp virus
                    « Reply #15 on: December 09, 2008, 06:47:38 AM »
                    got hjt loaded and ran, but something went wrong. I can ping the internet but cannot connect. My isp provider couldn't help get the connection back working.
                    I will transfer the HJT log to a flash and post it soon

                    7up

                      Topic Starter


                      Rookie

                      Re: windows xp virus
                      « Reply #16 on: December 09, 2008, 01:17:11 PM »
                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 5:43:32 PM, on 12/8/2008
                      Platform: Windows XP SP3 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Windows Defender\MsMpEng.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      C:\WINDOWS\arservice.exe
                      C:\Program Files\Bonjour\mDNSResponder.exe
                      C:\WINDOWS\eHome\ehRecvr.exe
                      C:\WINDOWS\eHome\ehSched.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Java\jre6\bin\jqs.exe
                      C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
                      C:\WINDOWS\system32\svchost.exe
                      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      C:\Program Files\Windows Defender\MSASCui.exe
                      C:\Program Files\Java\jre6\bin\jusched.exe
                      C:\Program Files\QuickTime\QTTask.exe
                      C:\PROGRA~1\VIRTUA~1\SMARTB~1\SprintDSLAlert.exe
                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      C:\HP\KBD\KBD.EXE
                      C:\Program Files\iTunes\iTunesHelper.exe
                      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                      C:\WINDOWS\ehome\ehtray.exe
                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      C:\Program Files\DISC\DiscUpdateMgr.exe
                      C:\Program Files\DISC\DISCover.exe
                      C:\WINDOWS\ARPWRMSG.EXE
                      C:\WINDOWS\eHome\ehmsas.exe
                      C:\Program Files\DISC\DiscGui.exe
                      C:\WINDOWS\system32\dllhost.exe
                      C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
                      C:\Program Files\Messenger\msmsgs.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                      C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
                      C:\Program Files\iPod\bin\iPodService.exe
                      C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
                      C:\Program Files\DISC\DiscStreamHub.exe
                      C:\WINDOWS\system32\wuauclt.exe
                      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                      C:\WINDOWS\ALCXMNTR.EXE
                      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                      C:\Program Files\Trend Micro\Sniper\HijackThis.exe
                      c:\windows\system\hpsysdrv.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
                      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
                      O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
                      O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
                      O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
                      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                      O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                      O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VIRTUA~1\SMARTB~1\SprintDSLAlert.exe
                      O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                      O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
                      O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
                      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                      O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                      O4 - HKLM\..\Run: [DiscUpdateManager] C:\Program Files\DISC\DiscUpdateMgr.exe
                      O4 - HKLM\..\Run: [DISCover] C:\Program Files\DISC\DISCover.exe
                      O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                      O4 - HKLM\..\Run: [C:\WINDOWS\system32\kdpei.exe] C:\WINDOWS\system32\kdpei.exe
                      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                      O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
                      O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                      O4 - Startup: wkcalrem.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
                      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                      O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
                      O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
                      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
                      O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                      O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
                      O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                      O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O15 - Trusted Zone: http://*.trymedia.com (HKLM)
                      O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
                      O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
                      O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
                      O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
                      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
                      O16 - DPF: {47B863BD-9069-43B1-A1BA-C7B73953697A} (SDD2MS Control) - http://partners.sonypictures.com/activex/msep3/v1108/SDD2MS.CAB
                      O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqcpc/downloads/sysinfo.cab
                      O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6662.cab
                      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1179866189979
                      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1199402303125
                      O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
                      O16 - DPF: {7FE26BE2-B923-4B41-9834-E84DA1CC1F96} (Maid Control) - http://vsp.closetmaid.com/vsp/cmaidctl_vsp.closetmaid.com_downloader.cab
                      O16 - DPF: {843EE768-3A97-455C-9076-741BA3AD7B62} (QuickBooks Online Edition Utilities Class v10) - https://accounting.quickbooks.com/c14/v21.148/qboax10.cab
                      O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=24931
                      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
                      O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
                      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE

                      --
                      End of file - 12096 bytes