View Single Post
Old 06-11-2006, 10:43 AM   #21 (permalink)
LynRis
Registered User
 
Join Date: Jun 2006
Posts: 49
OS: XP


smithfraud,findlop,hijack logs



SmitFraudFix v2.58

Scan done at 800.26, 11/06/2006
Run from C:\Documents and Settings\Lyndon\Desktop\Spyware stuff\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\WINDOWS\alexaie.dll Deleted
C:\WINDOWS\alxie328.dll Deleted
C:\WINDOWS\alxtb1.dll Deleted
C:\WINDOWS\infected.gif Deleted
C:\WINDOWS\Pynix.dll Deleted
C:\WINDOWS\star.gif Deleted
C:\WINDOWS\ZServ.dll Deleted
C:\WINDOWS\system32\jao.dll Deleted
C:\WINDOWS\system32\questmod.dll Deleted
C:\WINDOWS\system32\runsrv32.dll Deleted
C:\WINDOWS\system32\udpmod.dll Deleted

»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End

Volume in drive C has no label.
Volume Serial Number is BCC1-CC60

Directory of C:\Documents and Settings\Administrator\Application Data

11/09/2003 11:36 PM <DIR> .
11/09/2003 11:36 PM <DIR> ..
11/09/2003 11:36 PM <DIR> Microsoft
0 File(s) 0 bytes
3 Dir(s) 41,985,916,928 bytes free
Volume in drive C has no label.
Volume Serial Number is BCC1-CC60

Directory of C:\Documents and Settings\All Users\Application Data

21/04/2006 11:14 AM <DIR> Adobe
16/07/2005 03:28 PM <DIR> Apple Computer
11/09/2003 11:34 PM <DIR> BVRP Software
08/09/2005 08:07 AM <DIR> Creative
23/05/2005 11:09 AM <DIR> Dell
28/05/2006 03:37 PM 6 DragToDiscUserNameE.txt
09/05/2005 09:12 AM <DIR> Hewlett-Packard
11/08/2005 09:26 PM 2,436 hpzinstall.log
08/02/2006 09:02 AM <DIR> InstallShield
29/08/2005 09:01 PM <DIR> Kodak
17/07/2004 02:50 PM <DIR> McAfee.com
30/06/2004 12:11 AM <DIR> PACE Anti-Piracy
18/11/2005 04:22 PM <DIR> PopCap
30/06/2004 12:02 AM <DIR> Propellerhead Software
08/02/2004 05:01 PM <DIR> QuickTime
08/02/2006 09:05 AM <DIR> Roxio
11/09/2003 11:32 PM <DIR> SBSI
08/02/2006 09:01 AM <DIR> Sonic
06/06/2006 04:55 PM <DIR> Spybot - Search & Destroy
23/05/2005 06:59 PM <DIR> Viewpoint
06/06/2006 10:21 AM <DIR> Windows Genuine Advantage
2 File(s) 2,442 bytes
19 Dir(s) 41,985,912,832 bytes free
Volume in drive C has no label.
Volume Serial Number is BCC1-CC60

Directory of C:\Documents and Settings\Linda\Application Data

10/11/2003 05:19 PM <DIR> Adobe
13/02/2005 12:32 PM <DIR> AdobeUM
19/02/2006 05:29 PM <DIR> ArcSoft
20/12/2005 11:23 AM <DIR> Creative
07/01/2004 05:41 PM <DIR> Help
11/09/2003 11:01 PM <DIR> Identities
02/01/2006 05:37 PM <DIR> Macromedia
01/10/2003 06:30 PM <DIR> McAfee.com Personal Firewall
02/03/2006 12:47 PM <DIR> Mozilla
04/07/2005 05:52 PM <DIR> Real
11/02/2006 11:46 AM <DIR> Roxio
22/10/2005 04:47 PM <DIR> Sun
0 File(s) 0 bytes
12 Dir(s) 41,985,912,832 bytes free
Volume in drive C has no label.
Volume Serial Number is BCC1-CC60

Directory of C:\Documents and Settings\Lyndon\Application Data

27/08/2005 09:37 AM <DIR> Adobe
21/04/2006 11:17 AM <DIR> AdobeUM
19/09/2003 10:11 PM <DIR> ArcSoft
26/10/2003 02:28 PM <DIR> CyberLink
06/01/2006 11:31 PM <DIR> Digidesign
15/02/2004 01:02 PM 0 dm.ini
28/05/2006 09:51 AM <DIR> EPSON
31/08/2005 07:09 PM <DIR> Google
19/09/2003 09:56 PM <DIR> Help
11/09/2003 11:01 PM <DIR> Identities
11/06/2005 02:31 PM <DIR> Lavasoft
15/11/2003 05:28 PM <DIR> Leadertech
11/02/2006 12:33 AM <DIR> Macromedia
01/10/2003 06:14 PM <DIR> McAfee.com Personal Firewall
19/09/2003 09:25 PM <DIR> Microsoft Web Folders
11/02/2006 12:59 PM <DIR> Mozilla
29/08/2005 06:32 PM <DIR> OLYMPUS
25/03/2005 01:47 PM <DIR> Real
11/02/2006 12:31 AM <DIR> Roxio
20/05/2005 07:42 PM <DIR> Sun
23/11/2005 07:19 PM <DIR> V-Safe
1 File(s) 0 bytes
20 Dir(s) 41,985,912,832 bytes free
Volume in drive C has no label.
Volume Serial Number is BCC1-CC60

Directory of C:\Documents and Settings\Nathan\Application Data

27/09/2005 02:59 PM <DIR> Adobe
20/04/2005 05:20 PM <DIR> AdobeUM
19/04/2005 01:24 PM <DIR> Apple Computer
02/10/2003 08:06 AM <DIR> ArcSoft
13/09/2005 03:03 PM <DIR> Creative
18/09/2003 08:44 PM <DIR> CyberLink
10/09/2005 10:49 PM <DIR> Digidesign
13/10/2003 11:56 AM <DIR> DVD Shrink
20/09/2003 11:16 AM <DIR> EPSON
28/12/2005 02:42 PM <DIR> funkitron
26/11/2003 07:02 PM <DIR> Help
11/09/2003 11:01 PM <DIR> Identities
08/12/2004 08:48 PM <DIR> Lavasoft
15/11/2003 05:09 PM <DIR> Leadertech
23/12/2005 05:27 PM <DIR> Macromedia
01/10/2003 07:03 AM <DIR> McAfee.com Personal Firewall
08/02/2006 08:33 AM <DIR> Mozilla
29/08/2005 03:53 PM <DIR> OLYMPUS
30/06/2004 12:03 AM <DIR> Propellerhead Software
27/10/2004 09:43 AM <DIR> Real
14/05/2006 10:13 PM <DIR> Roxio
27/02/2006 09:48 PM <DIR> Sonic
04/06/2005 01:38 PM <DIR> Sun
07/05/2006 04:01 PM <DIR> VSO_HWE
19/11/2005 11:34 AM <DIR> {27ABEAD9-B7C4-4994-891F-48F5F48861FA}
0 File(s) 0 bytes
25 Dir(s) 41,985,908,736 bytes free
Volume in drive C has no label.
Volume Serial Number is BCC1-CC60

Directory of C:\Documents and Settings\Samantha\Application Data

03/04/2004 04:46 PM <DIR> Adobe
23/04/2005 08:32 AM <DIR> AdobeUM
19/12/2004 02:20 AM <DIR> Apple Computer
27/12/2003 10:22 PM <DIR> ArcSoft
20/05/2005 08:52 PM <DIR> Gtek
11/09/2003 11:01 PM <DIR> Identities
03/04/2004 04:46 PM <DIR> Leadertech
10/10/2003 10:14 PM <DIR> Macromedia
01/10/2003 08:23 PM <DIR> McAfee.com Personal Firewall
15/04/2006 10:29 AM <DIR> Mozilla
28/01/2005 09:37 PM <DIR> Real
19/02/2006 05:55 PM <DIR> Roxio
22/05/2005 09:42 AM <DIR> Sun
0 File(s) 0 bytes
13 Dir(s) 41,985,908,736 bytes free
Volume in drive C has no label.
Volume Serial Number is BCC1-CC60

Directory of C:\Documents and Settings\Default User\Application Data

20/05/2005 07:48 PM <DIR> .
20/05/2005 07:48 PM <DIR> ..
07/09/2004 09:04 PM 62 DESKTOP.INI
1 File(s) 62 bytes
2 Dir(s) 41,985,908,736 bytes free
Volume in drive C has no label.
Volume Serial Number is BCC1-CC60

Directory of C:\Documents and Settings\LocalService\Application Data

29/06/2005 03:45 PM <DIR> GTek
0 File(s) 0 bytes
1 Dir(s) 41,985,908,736 bytes free
Volume in drive C has no label.
Volume Serial Number is BCC1-CC60

Directory of C:\Documents and Settings\NetworkService\Application Data

[TRACE] Enumerating jobs and queues
[TRACE] Activating job 'MP Scheduled Scan.job'
[TRACE] Printing all job properties

ApplicationName: 'C:\Program Files\Windows Defender\MpCmdRun.exe'
Parameters: 'Scan -RestrictPrivileges'
WorkingDirectory: ''
Comment: 'Scheduled Scan'
Creator: 'SYSTEM'
Priority: NORMAL
MaxRunTime: 259200000 (3d 0:00:00)
IdleWait: 10
IdleDeadline: 60
MostRecentRun: 00/00/0000 0:00:00
NextRun: 06/12/2006 1:55:00
StartError: SCHED_S_TASK_HAS_NOT_RUN
ExitCode: 0
Status: SCHED_S_TASK_HAS_NOT_RUN
ScheduledWorkItem Flags:
DeleteWhenDone = 0
Suspend = 0
StartOnlyIfIdle = 0
KillOnIdleEnd = 0
RestartOnIdleResume = 0
DontStartIfOnBatteries = 1
KillIfGoingOnBatteries = 0
RunOnlyIfLoggedOn = 0
SystemRequired = 0
Hidden = 1
TaskFlags: 0

1 Trigger

Trigger 0:
Type: Daily
DaysInterval: 1
StartDate: 06/11/2006
EndDate: 00/00/0000
StartTime: 01:55
MinutesDuration: 0
MinutesInterval: 0
Flags:
HasEndDate = 0
KillAtDuration = 0
Disabled = 0


Logfile of HijackThis v1.99.1
Scan saved at 8:32:30 AM, on 11/06/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Digidesign\Drivers\MMERefresh.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Documents and Settings\Lyndon\Desktop\Spyware stuff\ewido anti-malware\ewidoctrl.exe
C:\Documents and Settings\Lyndon\Desktop\Spyware stuff\ewido anti-malware\ewidoguard.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
c:\program files\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\Program Files\Roxio\Easy Media Creator 8\Drag to Disc\DrgToDsc.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Messenger\msmsgs.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\CPSHelpRunner.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe
C:\Documents and Settings\Lyndon\Desktop\Spyware stuff\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [DigidesignMMERefresh] C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 8\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Noble Poker - {B723B1B8-9788-4684-ADA7-D1DB02E1D516} - C:\Program Files\Noble Poker\casino.exe
O9 - Extra 'Tools' menuitem: Noble Poker - {B723B1B8-9788-4684-ADA7-D1DB02E1D516} - C:\Program Files\Noble Poker\casino.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/sh...0/mcinsctl.cab
O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} (McAfee Virtual Technician Control Class) - http://us-download.mcafee.com/produc...ed/mvt/mvt.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/sh...20/mcgdmgr.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave.com/content/bej...ploader_v6.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Digidesign, A Division of Avid Technology, Inc. - C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Documents and Settings\Lyndon\Desktop\Spyware stuff\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Documents and Settings\Lyndon\Desktop\Spyware stuff\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxLiveShare.exe
O23 - Service: RoxMediaDB - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
O23 - Service: RoxUpnpRenderer (RoxUPnPRenderer) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCom\RoxUpnpRenderer.exe
O23 - Service: RoxUpnpServer - Sonic Solutions - C:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
LynRis is offline  
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here