مرحبا
هذا التقرير الأول
ComboFix 08-12-05.02 - nc 12/06/2008 5:55:16.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.660 [GMT 3:00]
Running from: c:\documents and settings\nc\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\mfc45.dll
D:\install.exe
.
((((((((((((((((((((((((( Files Created from 2008-11-06 to 2008-12-06 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-06 02:59 622,624 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-12-06 02:59 4,256 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-12-06 02:59 24,976 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-12-06 02:59 2,924,576 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-06 02:59 --------- d-----w c:\program files\microsoft frontpage
2008-12-06 02:58 --------- d-----w c:\documents and settings\nc\Application Data\DMCache
2008-12-06 02:17 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab
2008-12-06 01:32 --------- d-----w c:\documents and settings\nc\Application Data\cleaner
2008-12-06 01:25 --------- d---a-w c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2008-12-05 23:53 --------- d-----w c:\program files\Save Flash
2008-12-05 22:20 --------- d-----w c:\documents and settings\nc\Application Data\IDM
2008-12-04 00:01 --------- d-----w c:\program files\MSXML 4.0
2008-12-03 22:20 --------- d-----w c:\documents and settings\nc\Application Data\Nokia Multimedia Player
2008-12-01 17:48 --------- d-----w c:\documents and settings\nc\Application Data\Datalayer
2008-12-01 12:41 --------- d-----w c:\program files\Common Files\PCSuite
2008-12-01 12:41 --------- d-----w c:\program files\Common Files\Nokia
2008-12-01 12:38 --------- d-----w c:\program files\Nokia
2008-11-29 23:59 --------- d-----w c:\documents and settings\nc\Application Data\AntsSoft
2008-11-29 23:58 --------- d-----w c:\program files\SWFText
2008-11-29 15:00 --------- d-----w c:\program files\JetAudio
2008-11-29 13:46 --------- d-----w c:\program files\Steganos Internet Trace Destructor 7
2008-11-29 12:42 --------- d-----w c:\program files\Internet Download Manager
2008-11-29 11:55 --------- d-----w c:\program files\Google
2008-11-29 11:55 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\iolo
2008-11-29 05:31 --------- d-----w c:\program files\Common Files\xing shared
2008-11-29 05:30 --------- d-----w c:\program files\Common Files\Real
2008-11-29 05:02 --------- d-----w c:\program files\DAP
2008-11-29 05:00 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\SpeedBit
2008-11-29 03:38 --------- d-----w c:\program files\HP
2008-11-29 03:38 --------- d-----w c:\program files\Common Files\HP
2008-11-29 03:27 --------- d-----w c:\program files\Common Files\Ahead
2008-11-29 03:23 --------- d-----w c:\program files\Real
2008-11-28 14:23 --------- d-----w c:\documents and settings\nc\Application Data\iolo
2008-11-27 23:47 --------- d-----w c:\documents and settings\LocalService\Application Data\iolo
2008-11-16 16:33 --------- d-----w c:\documents and settings\nc\Application Data\Ahead
2008-11-16 16:20 --------- d-----w c:\program files\Nero
2008-11-06 21:31 --------- d-----w c:\program files\NSS
2008-11-04 09:17 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Installations
2008-11-01 21:04 --------- d-----w c:\documents and settings\nc\Application Data\HP
2008-11-01 21:04 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\HP
2008-11-01 20:58 --------- d-----w c:\program files\Hewlett-Packard
2008-10-31 16:47 --------- d-----w c:\documents and settings\nc\Application Data\JewelMatch2
2008-10-31 13:23 774,144 ----a-w c:\program files\RngInterstitial.dll
2008-10-27 22:38 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft Help
2008-10-27 22:33 --------- d-----w c:\program files\Microsoft Works
2008-10-27 22:07 --------- d-----w c:\program files\MSBuild
2008-10-26 11:53 --------- d-----w c:\documents and settings\nc\Application Data\OfficeUpdate12
2008-10-25 19:14 --------- d-----w c:\documents and settings\nc\Application Data\Acronis
2008-10-25 16:17 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Acronis
2008-10-25 16:14 98,880 ----a-w c:\windows\system32\drivers\psh_drv.sys
2008-10-25 16:14 96,320 ----a-w c:\windows\system32\drivers\snapman.sys
2008-10-25 16:14 --------- d-----w c:\program files\Acronis
2008-10-24 19:39 --------- d-----w c:\program files\Wise Registry Cleaner 3
2008-10-24 19:35 --------- d-----w c:\program files\Wise Disk Cleaner
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-14 12:55 --------- d-----w c:\documents and settings\nc\Application Data\GameHouse
2008-10-13 21:29 --------- d-----w c:\program files\SweetIM
2008-10-13 21:16 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\SweetIM
2008-10-13 19:55 --------- d-----w c:\program files\Reference Assemblies
2008-10-13 02:47 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\n7-89-o9-3r-4t-r9
2008-10-13 02:46 --------- d-----w c:\program files\GameHouse
2008-10-13 01:49 --------- d-----w c:\program files\Diamond Drop
2008-10-12 10:26 --------- d-----w c:\program files\Golden Al-Wafi Translator
2008-10-10 12:12 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-09 13:33 --------- d-----w c:\program files\Common Files\InstallShield
2008-10-08 12:41 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Messenger Plus!
2008-10-07 23:02 --------- d-----w c:\program files\Messenger Plus! Live
2008-10-07 23:01 --------- d-----w c:\program files\Windows Live
2008-10-07 17:07 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Adobe Systems
2008-10-07 16:48 --------- d-----w c:\program files\Common Files\Adobe
2008-09-17 16:46 155,995 ----a-w c:\windows\java\Packages\MYGQ02DN.ZIP
2008-08-24 20:06 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008082420080825\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [11/29/2007 07:25 PM 5724184]
"ITD7"="c:\program files\Steganos Internet Trace Destructor 7\ITD7.exe" [05/02/2005 10:31 AM 274432]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [04/15/2008 12:29 AM 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [04/25/2008 06:21 PM 201992]
"PCSuiteTrayApplication"="c:\progra~1\Nokia\NOKIAP~1\LAUNCH~1.EXE" [04/26/2006 08:29 AM 237568]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [11/29/2008 08:29 AM 185872]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [04/15/2008 12:29 AM 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"ITD7"="c:\program files\Steganos Internet Trace Destructor 7\ITD7.exe" [05/02/2005 10:31 AM 274432]
c:\documents and settings\nc\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R0 ulsata2;ulsata2;c:\windows\system32\drivers\ulsata2.sys [2008-05-07 124928]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys []
S3 SetupNTGLM7X;SetupNTGLM7X;\??\E:\NTGLM7X.sys []
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uInternet Settings,ProxyOverride = *.local
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Free Download Manager تحميل الفيديو بواسطة -
files\Free Download Manager\dlfvideo.htm
IE: أضافة إلى مانع الأعلانات - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: تحميل الكل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل المحددة بفري داونلود مانيجر -
files\Free Download Manager\dlselected.htm
IE: تحميل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetVL.htm
IE: تنزيل الكل بفري داونلود مانيجر -
files\Free Download Manager\dlall.htm
IE: تنزيل بفري داونلود مانيجر -
files\Free Download Manager\dllink.htm
O16 -: Microsoft XML Parser for Java -
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
.
------- File Associations -------
.
JSEFile=NOTEPAD.EXE %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-12-06 06:00:27
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Common Files\PCSuite\Services\ServiceLayer.exe
.
**************************************************************************
.
Completion time: 12/06/2008 6:15:18 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-06 03:10:11
Pre-Run: 21,378,535,424 bytes free
Post-Run: 21,374,578,688 bytes free
180 --- E O F --- 2008-12-04 00:01:03
وهذا تقرير الهايجيك
Logfile of HijackThis v1.99.1
Scan saved at 06:27:39 ص, on 06/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\nc\سطح المكتب\برامج\تنظيف وحذف\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 9\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 9\SnagItIEAddin.dll
O3 - Toolbar: &Save Flash - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files\Save Flash\SaveFlash.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ITD7] "C:\Program Files\Steganos Internet Trace Destructor 7\ITD7.exe" -boot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &تصدير إلى Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Free Download Manager تحميل الفيديو بواسطة -
Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: أضافة إلى مانع الأعلانات - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 - Extra context menu item: ت&صدير إلى Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: تحميل الكل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل المحددة بفري داونلود مانيجر -
Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: تحميل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: تنزيل الكل بفري داونلود مانيجر -
Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: تنزيل بفري داونلود مانيجر -
Files\Free Download Manager\dllink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O11 - Options group: [TABS] Tabbed Browsing
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) -
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash ) -
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~1\Office12\GR99D3~1.DLL
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Unknown owner - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Kaspersky Internet Security (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" -r (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe