تقرير الهايجاك
logfile of trend micro hijackthis v2.0.4
scan saved at 12:56:30 ص, on 15/06/11
platform: Windows 7 sp1 (winnt 6.00.3505)
msie: Internet explorer v9.00 (9.00.8112.16421)
boot mode: Normal
running processes:
C:\program files (x86)\norton 360\engine\5.1.0.29\ccsvchst.exe
c:\program files (x86)\asus\smartlogon\sensorsrv.exe
c:\program files (x86)\asus\controldeck\controldeckstartup.exe
c:\program files (x86)\asus\asus live update\alu.exe
c:\program files (x86)\asus\wireless console 3\wcourier.exe
c:\windows\asscrpro.exe
c:\program files (x86)\cyberlink\power2go\clmlsvc.exe
c:\program files (x86)\samsung\kies\kiestrayagent.exe
c:\program files (x86)\samsung\kies\external\firmwareupdate\kiespdlr.exe
c:\program files (x86)\internet download manager\idman.exe
c:\program files (x86)\asus\atk package\atkosd2\atkosd2.exe
c:\program files (x86)\asus\atk package\atk media\dmedia.exe
c:\program files (x86)\asus\atk package\atk hotkey\hcontroluser.exe
c:\program files (x86)\common files\java\java update\jusched.exe
c:\program files (x86)\vmware\vmware workstation\vmware-tray.exe
c:\program files (x86)\common files\nokia\mplatform\nokiamserver.exe
c:\program files\widcomm\bluetooth software\bluetoothheadsetproxy.exe
c:\program files (x86)\internet download manager\iemonitor.exe
c:\program files (x86)\skype\plugin manager\skypepm.exe
c:\program files (x86)\google\chrome\application\chrome.exe
c:\program files (x86)\google\chrome\application\chrome.exe
c:\program files (x86)\google\chrome\application\chrome.exe
c:\program files (x86)\google\chrome\application\chrome.exe
c:\program files (x86)\google\chrome\application\chrome.exe
c:\program files (x86)\google\chrome\application\chrome.exe
c:\program files (x86)\google\chrome\application\chrome.exe
c:\program files (x86)\google\chrome\application\chrome.exe
c:\program files (x86)\google\chrome\application\chrome.exe
c:\program files (x86)\google\chrome\application\chrome.exe
c:\program files (x86)\google\chrome\application\chrome.exe
c:\program files (x86)\google\chrome\application\chrome.exe
c:\program files (x86)\google\chrome\application\chrome.exe
c:\program files (x86)\google\chrome\application\chrome.exe
c:\program files (x86)\google\chrome\application\chrome.exe
c:\program files (x86)\hotspot shield\bin\openvpntray.exe
c:\program files (x86)\real\realplayer\update\realsched.exe
c:\program files (x86)\pc connectivity solution\transports\nclmsbtsrvex.exe
c:\program files (x86)\google\chrome\application\chrome.exe
c:\program files (x86)\google\chrome\application\chrome.exe
c:\program files (x86)\google\chrome\application\chrome.exe
c:\program files (x86)\google\chrome\application\chrome.exe
c:\program files (x86)\utorrent\utorrent.exe
c:\program files (x86)\google\chrome\application\chrome.exe
c:\program files (x86)\google\chrome\application\chrome.exe
c:\program files (x86)\google\chrome\application\chrome.exe
d:\program files (x86)\mcg\mcg (tomtest.net).exe
c:\zyzoom_forum_tools\zyzoom.exe
c:\zyzoom_forum_tools\zhijak.com
r0 - hkcu\software\microsoft\internet explorer\main,start page = about:blank
r1 - hklm\software\microsoft\internet explorer\main,default_search_url =
r0 - hklm\software\microsoft\internet explorer\main,start page = about:blank
r0 - hklm\software\microsoft\internet explorer\main,local page = c:\windows\syswow64\blank.htm
r1 - hkcu\software\microsoft\windows\currentversion\internet settings,proxyserver = http=;ftp=;https=;
r1 - hkcu\software\microsoft\windows\currentversion\internet settings,proxyoverride = *.local
r0 - hkcu\software\microsoft\internet explorer\toolbar,linksfoldername =
r3 - urlsearchhook: Urlsearchhook class - {00000000-6e41-4fd3-8538-502f5495e5fc} - c:\program files (x86)\ask.com\genericasktoolbar.dll
f2 - reg:system.ini: Userinit=userinit.exe
o2 - bho: Idm helper - {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files (x86)\internet download manager\idmiecc.dll
o2 - bho: Acroiehelperstub - {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\acroiehelpershim.dll
o2 - bho: Babylon toolbar helper - {2eecd738-5844-4a99-b4b6-146bf802613b} - c:\program files (x86)\babylontoolbar\babylontoolbar\1.4.19.5\bh\babylontoolbar.dll
o2 - bho: Realplayer download and record plugin for internet explorer - {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
o2 - bho: Symantec nco bho - {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files (x86)\norton 360\engine\5.1.0.29\coieplg.dll
o2 - bho: Symantec intrusion prevention - {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files (x86)\norton 360\engine\5.1.0.29\ips\ipsbho.dll
o2 - bho: Groove gfs browser helper - {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~2\micros~1\office14\grooveex.dll
o2 - bho: مساعد تسجيل الدخول إلى معرف windows live - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\windowslivelogin.dll
o2 - bho: Babylon ie plugin - {9cfaccb6-2f3f-4177-94ea-0d2b72d384c1} - c:\program files (x86)\babylon\babylon-pro\utils\babyloniepi.dll
o2 - bho: Windows live messenger companion helper - {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files (x86)\windows live\companion\companioncore.dll
o2 - bho: Leapftp internet explorer hook - {a5479da1-7843-43a7-b5c0-be342c77b629} - c:\progra~2\leapftp 3.0\lftpie.dll
o2 - bho: Google toolbar helper - {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files (x86)\google\google toolbar\googletoolbar_32.dll
o2 - bho: Skypeiepluginbho - {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files (x86)\skype\toolbars\internet explorer\skypeieplugin.dll
o2 - bho: Google toolbar notifier bho - {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files (x86)\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
o2 - bho: Urlredirectionbho - {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~2\micros~1\office14\urlredir.dll
o2 - bho: Google dictionary compression sdch - {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files (x86)\google\google toolbar\component\fastsearch_b7c5ac242193bb3e.dll
o2 - bho: Ask toolbar bho - {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files (x86)\ask.com\genericasktoolbar.dll
o2 - bho: Java(tm) plug-in 2 ssv helper - {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll
o2 - bho: Hotspot shield class - {f9e4a054-e9b1-4bc3-83a3-76a1ae736170} - c:\program files (x86)\hotspot shield\hssie\hssie.dll
o3 - toolbar: Google toolbar - {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files (x86)\google\google toolbar\googletoolbar_32.dll
o3 - toolbar: Norton toolbar - {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files (x86)\norton 360\engine\5.1.0.29\coieplg.dll
o3 - toolbar: Babylon toolbar - {98889811-442d-49dd-99d7-dc866be87dbc} - c:\program files (x86)\babylontoolbar\babylontoolbar\1.4.19.5\babylontoolbartlbr.dll
o3 - toolbar: Ask toolbar - {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files (x86)\ask.com\genericasktoolbar.dll
o4 - hklm\..\run: [updatelbpshortcut] "c:\program files (x86)\cyberlink\labelprint\muitransfer\muistartmenu.exe" "c:\program files (x86)\cyberlink\labelprint" updatewithcreateonce "software\cyberlink\labelprint\2.5"
o4 - hklm\..\run: [updatep2goshortcut] "c:\program files (x86)\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files (x86)\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0"
o4 - hklm\..\run: [startccc] "c:\program files (x86)\ati technologies\ati.ace\core-static\clistart.exe" msrun
o4 - hklm\..\run: [atkosd2] c:\program files (x86)\asus\atk package\atkosd2\atkosd2.exe
o4 - hklm\..\run: [atkmedia] c:\program files (x86)\asus\atk package\atk media\dmedia.exe
o4 - hklm\..\run: [hcontroluser] c:\program files (x86)\asus\atk package\atk hotkey\hcontroluser.exe
o4 - hklm\..\run: [sunjavaupdatesched] "c:\program files (x86)\common files\java\java update\jusched.exe"
o4 - hklm\..\run: [babylontoolbar] "c:\program files (x86)\babylontoolbar\babylontoolbar\1.4.19.5\babylontoolbarsrv.exe" /md i
o4 - hklm\..\run: [babylon client] c:\program files (x86)\babylon\babylon-pro\babylon.exe -autostart
o4 - hklm\..\run: [switchboard] c:\program files (x86)\common files\adobe\switchboard\switchboard.exe
o4 - hklm\..\run: [adobecs5servicemanager] "c:\program files (x86)\common files\adobe\cs5servicemanager\cs5servicemanager.exe" -launchedbylogin
o4 - hklm\..\run: [vmware-tray] "c:\program files (x86)\vmware\vmware workstation\vmware-tray.exe"
o4 - hklm\..\run: [adobe arm] "c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe"
o4 - hklm\..\run: [quicktime task] "c:\program files (x86)\quicktime\qttask.exe" -atboottime
o4 - hklm\..\run: [nbagent] "c:\program files (x86)\nero\nero 10\nero backitup\nbagent.exe" /winstart
o4 - hklm\..\run: [tkbellexe] "c:\program files (x86)\real\realplayer\update\realsched.exe" -osboot
o4 - hklm\..\run: [nokiamserver] c:\program files (x86)\common files\nokia\mplatform\nokiamserver /watchfiles startup
o4 - hkcu\..\run: [utorrent] "c:\program files (x86)\utorrent\utorrent.exe"
o4 - hkcu\..\run: [msnmsgr] "c:\program files (x86)\windows live\messenger\msnmsgr.exe" /background
o4 - hkcu\..\run: [vidalia] "c:\users\mohammed-omar\downloads\programs\tor browser\app\vidalia.exe"
o4 - hkcu\..\run: [nokiaovisuite2] c:\program files (x86)\nokia\nokia ovi suite\nokiaovisuite.exe -tray
o4 - hkcu\..\run: [steam] "c:\program files (x86)\steam\steam.exe" -silent
o4 - hkcu\..\run: [kieshelper] c:\program files (x86)\samsung\kies\kieshelper.exe /s
o4 - hkcu\..\run: [kiestrayagent] c:\program files (x86)\samsung\kies\kiestrayagent.exe
o4 - hkcu\..\run: [kiespdlr] c:\program files (x86)\samsung\kies\external\firmwareupdate\kiespdlr.exe
o4 - hkcu\..\run: [skype] "c:\program files (x86)\skype\phone\skype.exe" /nosplash /minimized
o4 - hkcu\..\run: [idman] c:\program files (x86)\internet download manager\idman.exe /onboot
o4 - hkcu\..\run: [software informer] "c:\program files (x86)\software informer\softinfo.exe" -autorun
o4 - hkcu\..\run: [sidebar] c:\program files\windows sidebar\sidebar.exe /autorun
o4 - hkus\s-1-5-19\..\run: [sidebar] %programfiles%\windows sidebar\sidebar.exe /autorun (user 'local service')
o4 - hkus\s-1-5-19\..\runonce: [mctadmin] c:\windows\system32\mctadmin.exe (user 'local service')
o4 - hkus\s-1-5-20\..\run: [sidebar] %programfiles%\windows sidebar\sidebar.exe /autorun (user 'network service')
o4 - hkus\s-1-5-20\..\runonce: [mctadmin] c:\windows\system32\mctadmin.exe (user 'network service')
o4 - startup: Gameranger.lnk = c:\users\mohammed-omar\appdata\roaming\gameranger\gameranger\gameranger.exe
o4 - global startup: Bluetooth.lnk = ?
O4 - global startup: Fancystart daemon.lnk = ?
O4 - global startup: Srs premium sound.lnk = ?
O8 - extra context menu item: E&xport to microsoft excel - res://c:\progra~2\micros~1\office12\excel.exe/3000
o8 - extra context menu item: Send image to &bluetooth device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
o8 - extra context menu item: Send page to &bluetooth device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
o8 - extra context menu item: Translate this web page with babylon - res://c:\program files (x86)\babylon\babylon-pro\utils\babyloniepi.dll/actiontu.htm
o8 - extra context menu item: Translate with babylon - res://c:\program files (x86)\babylon\babylon-pro\utils\babyloniepi.dll/action.htm
o8 - extra context menu item: إر&سال إلى onenote - res://c:\progra~1\micros~2\office14\onbttnie.dll/105
o8 - extra context menu item: ت&صدير إلى microsoft excel - res://c:\progra~1\micros~2\office14\excel.exe/3000
o8 - extra context menu item: تحميل الكل بواسطة internet download manager - c:\program files (x86)\internet download manager\iegetall.htm
o8 - extra context menu item: تحميل بواسطة internet download manager - c:\program files (x86)\internet download manager\ieext.htm
o9 - extra button: @c:\program files (x86)\windows live\companion\companionlang.dll,-600 - {0000036b-c524-4050-81a0-243669a86b9f} - c:\program files (x86)\windows live\companion\companioncore.dll
o9 - extra button: @c:\program files (x86)\windows live\writer\windowslivewritershortcuts.dll,-1004 - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - c:\program files (x86)\windows live\writer\writerbrowserextension.dll
o9 - extra 'tools' menuitem: @c:\program files (x86)\windows live\writer\windowslivewritershortcuts.dll,-1003 - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - c:\program files (x86)\windows live\writer\writerbrowserextension.dll
o9 - extra button: إرسال إلى onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - c:\program files (x86)\microsoft office\office14\onbttnie.dll
o9 - extra 'tools' menuitem: إر&سال إلى onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - c:\program files (x86)\microsoft office\office14\onbttnie.dll
o9 - extra button: ملاحظات onenote الم&رتبطة - {789fe86f-6fc4-46a1-9849-ede0db0c95ca} - c:\program files (x86)\microsoft office\office14\onbttnielinkednotes.dll
o9 - extra 'tools' menuitem: ملاحظات onenote الم&رتبطة - {789fe86f-6fc4-46a1-9849-ede0db0c95ca} - c:\program files (x86)\microsoft office\office14\onbttnielinkednotes.dll
o9 - extra button: Skype plug-in - {898ea8c8-e7ff-479b-8935-aec46303b9e5} - c:\program files (x86)\skype\toolbars\internet explorer\skypeieplugin.dll
o9 - extra 'tools' menuitem: Skype plug-in - {898ea8c8-e7ff-479b-8935-aec46303b9e5} - c:\program files (x86)\skype\toolbars\internet explorer\skypeieplugin.dll
o9 - extra button: Encarta search bar - {b205a35e-1fc4-4ce3-818b-899dbbb3388c} - c:\program files (x86)\common files\microsoft shared\encarta search bar\encsbar.dll
o9 - extra button: إرسال إلى bluetooth - {cca281ca-c863-46ef-9331-5c8d4460577f} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
o9 - extra 'tools' menuitem: إرسال إلى &جهاز bluetooth... - {cca281ca-c863-46ef-9331-5c8d4460577f} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
o9 - extra button: Translate this web page with babylon - {f72841f0-4ef1-4df5-bce5-b3ac8acf5478} - c:\program files (x86)\babylon\babylon-pro\utils\babyloniepi.dll
o9 - extra 'tools' menuitem: Translate this web page with babylon - {f72841f0-4ef1-4df5-bce5-b3ac8acf5478} - c:\program files (x86)\babylon\babylon-pro\utils\babyloniepi.dll
o10 - unknown file in winsock lsp: C:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
o10 - unknown file in winsock lsp: C:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
o10 - unknown file in winsock lsp: C:\program files (x86)\vmware\vmware workstation\vsocklib.dll
o10 - unknown file in winsock lsp: C:\program files (x86)\vmware\vmware workstation\vsocklib.dll
o11 - options group: [accelerated_graphics] accelerated graphics
o17 - hklm\system\ccs\services\tcpip\..\{409a4a0d-d885-4763-b036-953c0f1a018c}: Nameserver = 10.72.56.1
o18 - protocol: Skype-ie-addon-data - {91774881-d725-4e58-b298-07617b9b86a8} - c:\program files (x86)\skype\toolbars\internet explorer\skypeieplugin.dll
o18 - protocol: Skype4com - {ffc8b962-9b40-4dff-9458-1830c7dd7f5d} - c:\progra~2\common~1\skype\skype4com.dll
o18 - protocol: Wlpg - {e43ef6cd-a37a-4a9b-9e6f-83f89b8e6324} - c:\program files (x86)\windows live\photo gallery\albumdownloadprotocolhandler.dll
o18 - filter hijack: Text/xml - {807573e5-5146-11d5-a672-00b0d022e945} - c:\program files (x86)\common files\microsoft shared\office14\msoxmlmf.dll
o23 - service: Afbagent - unknown owner - c:\windows\system32\fbagent.exe (file missing)
o23 - service: @%systemroot%\system32\alg.exe,-112 (alg) - unknown owner - c:\windows\system32\alg.exe (file missing)
o23 - service: Amd external events utility - unknown owner - c:\windows\system32\atiesrxx.exe (file missing)
o23 - service: Asldr service (asldrservice) - asus - c:\program files (x86)\asus\atk package\atk hotkey\asldrsrv.exe
o23 - service: Atkgfnex service (atkgfnexsrv) - asus - c:\program files (x86)\asus\atk package\atkgfnex\gfnexsrv.exe
o23 - service: Bonjour service - apple inc. - c:\program files (x86)\bonjour\mdnsresponder.exe
o23 - service: Bluetooth service (btwdins) - broadcom corporation. - c:\program files\widcomm\bluetooth software\btwdins.exe
o23 - service: @%systemroot%\system32\efssvc.dll,-100 (efs) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: @%systemroot%\system32\fxsresm.dll,-118 (fax) - unknown owner - c:\windows\system32\fxssvc.exe (file missing)
o23 - service: Google update service (gupdate) (gupdate) - google inc. - c:\program files (x86)\google\update\googleupdate.exe
o23 - service: خدمة google update (gupdatem) (gupdatem) - google inc. - c:\program files (x86)\google\update\googleupdate.exe
o23 - service: Google software updater (gusvc) - google - c:\program files (x86)\google\common\google updater\googleupdaterservice.exe
o23 - service: Hotspot shield service (hshld) - unknown owner - c:\program files (x86)\hotspot shield\bin\openvpnas.exe
o23 - service: Hotspot shield routing service (hsssrv) - anchorfree inc. - c:\program files (x86)\hotspot shield\hsswpr\hsssrv.exe
o23 - service: Hotspot shield tray service (hsstrayservice) - unknown owner - c:\program files (x86)\hotspot shield\bin\hsstrayservice.exe
o23 - service: Hotspot shield monitoring service (hsswd) - unknown owner - c:\program files (x86)\hotspot shield\bin\hsswd.exe
o23 - service: @keyiso.dll,-100 (keyiso) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: Intel(r) management and security application local management service (lms) - intel corporation - c:\program files (x86)\intel\intel(r) management engine components\lms\lms.exe
o23 - service: @comres.dll,-2797 (msdtc) - unknown owner - c:\windows\system32\msdtc.exe (file missing)
o23 - service: Norton 360 (n360) - symantec corporation - c:\program files (x86)\norton 360\engine\5.1.0.29\ccsvchst.exe
o23 - service: @c:\program files (x86)\nero\update\nasvc.exe,-200 (naupdate) - nero ag - c:\program files (x86)\nero\update\nasvc.exe
o23 - service: @%systemroot%\system32\netlogon.dll,-102 (netlogon) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: Pnkbstra - unknown owner - c:\windows\system32\pnkbstra.exe
o23 - service: @%systemroot%\system32\psbase.dll,-300 (protectedstorage) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: @%systemroot%\system32\locator.exe,-2 (rpclocator) - unknown owner - c:\windows\system32\locator.exe (file missing)
o23 - service: @%systemroot%\system32\samsrv.dll,-1 (samss) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: Servicelayer - nokia - c:\program files (x86)\pc connectivity solution\servicelayer.exe
o23 - service: @%systemroot%\system32\snmptrap.exe,-3 (snmptrap) - unknown owner - c:\windows\system32\snmptrap.exe (file missing)
o23 - service: @%systemroot%\system32\spoolsv.exe,-1 (spooler) - unknown owner - c:\windows\system32\spoolsv.exe (file missing)
o23 - service: @%systemroot%\system32\sppsvc.exe,-101 (sppsvc) - unknown owner - c:\windows\system32\sppsvc.exe (file missing)
o23 - service: Steam client service - valve corporation - c:\program files (x86)\common files\steam\steamservice.exe
o23 - service: Switchboard - adobe systems incorporated - c:\program files (x86)\common files\adobe\switchboard\switchboard.exe
o23 - service: Teamviewer 6 (teamviewer6) - teamviewer gmbh - c:\program files (x86)\teamviewer\version6\teamviewer_service.exe
o23 - service: Turboboost - intel(r) corporation - c:\program files\intel\turboboost\turboboost.exe
o23 - service: Vmware agent service (ufad-ws60) - vmware, inc. - c:\program files (x86)\vmware\vmware workstation\vmware-ufad.exe
o23 - service: @%systemroot%\system32\ui0detect.exe,-101 (ui0detect) - unknown owner - c:\windows\system32\ui0detect.exe (file missing)
o23 - service: Intel(r) management & security application user notification service (uns) - intel corporation - c:\program files (x86)\intel\intel(r) management engine components\uns\uns.exe
o23 - service: @%systemroot%\system32\vaultsvc.dll,-1003 (vaultsvc) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: @%systemroot%\system32\vds.exe,-100 (vds) - unknown owner - c:\windows\system32\vds.exe (file missing)
o23 - service: Vmware authorization service (vmauthdservice) - vmware, inc. - c:\program files (x86)\vmware\vmware workstation\vmware-authd.exe
o23 - service: Vmware dhcp service (vmnetdhcp) - vmware, inc. - c:\windows\system32\vmnetdhcp.exe
o23 - service: Vmware usb arbitration service (vmusbarbservice) - vmware, inc. - c:\program files (x86)\common files\vmware\usb\vmware-usbarbitrator.exe
o23 - service: Vmware nat service - vmware, inc. - c:\windows\system32\vmnat.exe
o23 - service: @%systemroot%\system32\vssvc.exe,-102 (vss) - unknown owner - c:\windows\system32\vssvc.exe (file missing)
o23 - service: @%systemroot%\system32\wat\watux.exe,-601 (watadminsvc) - unknown owner - c:\windows\system32\wat\watadminsvc.exe (file missing)
o23 - service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - unknown owner - c:\windows\system32\wbengine.exe (file missing)
o23 - service: @%systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiapsrv) - unknown owner - c:\windows\system32\wbem\wmiapsrv.exe (file missing)
o23 - service: @%programfiles%\windows media player\wmpnetwk.exe,-101 (wmpnetworksvc) - unknown owner - c:\program files (x86)\windows media player\wmpnetwk.exe (file missing)
--
end of file - 21819 bytes