Announcement Banner
UNSOLVED

p2jonas

updated

22 years ago

P

p2jonas

2 Posts

0

6038

March 4th, 2005 14:00

Dr Watson postmortem debugger

Hi
 
Pls help
When i click the start menu and click documents or my computer or control panel...etc
the system hangs. and after some time the below mentioned info appears
 
" dr. watson postmortem debugger has encountered a problem and needs to close....."
 
 
can anyone help me please.. ive tried windows updates, anti spyware and also system configuration to clear any bugs...but nothing has resolved this problem.
 
 
 
  • Chik

    453 Posts

    440

    0

    Posted March 4th, 2005 15:00

    p2jonas-
     
    I think you have a very wicked About:Blank infection.
     
    Download Hijackthis from  http://tomcoyote.org/hjt/hjt199//HijackThis.exe
     
    Click "My Computer", then "C:\" and then on "Program Files".
    In the menu bar, "File"->"New"->"Folder".
    That will create a folder named "New Folder", which you can rename to "HJT" or "HijackThis".
    Now you have "C:\Program Files\HijackThis". Put your HijackThis.exe there.
     
    Run Hijackthis, click on the 'scan' button and then 'save log' button. Copy and paste the contents of the text file you save into a reply to this message.
     
    Someone here will help you out.
     
    -chik
  • andleder

    5 Posts

    440

    0

    Posted March 7th, 2005 00:00

    I am having a similar problem.  I can't open My Computer, Windows Explorer, Search and other similar non-program files.  My internet explorer keeps reverting to about.blank. 

    I have installed and run spyblaster and spybot but I haven't gotten rid of the above mentioned problem.  What should I do?

  • Chik

    453 Posts

    440

    0

    Posted March 7th, 2005 00:00

    andleder-
     
    Download Hijackthis from  http://tomcoyote.org/hjt/hjt199//HijackThis.exe
     
    Click "My Computer", then "C:\" and then on "Program Files".
    In the menu bar, "File"->"New"->"Folder".
    That will create a folder named "New Folder", which you can rename to "HJT" or "HijackThis".
    Now you have "C:\Program Files\HijackThis". Put your HijackThis.exe there.
     
    Run Hijackthis, click on the 'scan' button and then 'save log' button. Copy and paste the contents of the text file you save and start a new thread stating your problem.
     
    Someone here will help you out.
     
    -chik
  • mcgator

    3 Posts

    439

    0

    Posted March 19th, 2005 12:00

    I have the same problem, but I cannot download HijackThis because I cannot get past the desktop. The mouse moves around, but nothing will open. The Start menu will open, but anything you click on in the menu will not open, so I cannot get to anything. What can I do???
  • zbestwun2001

    4 Apprentice

    •

    8831 Posts

    439

    0

    Posted March 23rd, 2005 16:00

    mcgator,
    My suggestion is to download the setup file for HJT to disc from another computer.

    Using the disc install it on the infected system and perform the scan and save it to log and post it in the HJT forum.

    Also please download to disc and follow these insturctions while on the other computer. Using that disc install these programs on your system and run them.

    Here are the instuctions:

    Remember you are using the good system to download these programs.

    You should have no problem installing them from the disc to the infected system. If you do let me know

    Be sure to post the results in the HiJackThis forum.

    To begin with go to Trend Micro and do an online scan and delete whatever it finds. Be sure to highlight the drives you want to have searched. Try doing this on the infected system.

    After that could you please go to here and download AdAwareSE and delete what it finds. Then go here here and download its VX2 cleaner. Run it and delete what it finds.

    After that go to here and download SpyBot and run that and delete what it finds.

    Now go to here and download HiJackThis to its own folder that you create on your C:\ drive.
    After it is downloaded open the program and click Scan and Save to log.

    Post the log that it generates on the HJT board.

    Steve

    Message Edited by zbestwun2001 on 03-23-2005 11:45 AM

  • ora1313

    27 Posts

    439

    0

    Posted March 26th, 2005 11:00

    It is an easy fix...Print this out

    It is not a virus, nor do you have to down-load anything to fix it. And for God Sake, do not re-format your pc.......or mess with your registry!

    A Tech informed me it is a microsoft problem, don’t know if it is true, it seems to be. Problems are from an update from microsoft with the SP2....Tech didn’t know how to fix it, but I figured it out........

    When the error box pops up, click on the link in the box: see error file........You will see a path or 2 that looks something like this:

    c:\docume~1\user\locals~1\Temp\werabbb.dir00\DRWTSN32.exe.mdmp

    Write it down

    Now, Re-Boot computer in safe-mode.............press F8 as soon as it starts to re-boot: This brings you into safe-mode. Here, you can get into your files.

    Go into Windows Explorer, follow the path and delete the file: DRWTSN32.exe.

    Now step 2: Go into the control panel, then add/remove programs. Find the program.........SP2 and click uninstall. This is the up-date from microsoft. You don’t need it anyway. If you don’t do both steps, it will just re-load.

    Then, Re-boot system in normal mode, it should be ok.

    Hope this helps, it worked for me....Let me know

  • mcgator

    3 Posts

    439

    0

    Posted April 5th, 2005 23:00

    First I want to say thank you so much to both of you for responding. I think it's really great that you take the time to help:)

    zbestwun2001--I tried what you said, but when I tried to transfer it over to my computer, I couldn't open the file to download it...then I went out of town...and came back and tried...

    ora1313-and yes! that did work!!! at least to get onto my computer. Thank you so much because now I can get to my files :)  Now there are other prolems, though. A little error box comes up every time I try to open something that says. "Explorer!", but when I click OK, it opens what I wanted. Then, my DVD drive doesn't work and I cannot get onto the internet. I don't know if this is all related or if I have to go to several different forums to see what the problems are. I'm just really happy to get onto my computer.

    Thanks again :)

  • ora1313

    27 Posts

    439

    0

    Posted April 8th, 2005 02:00

    Your welcome...Sorry, I don't use the internet explorer, just use aol and my dvd is working fine.  I hope you figure it out...

    donna

  • RenzyB

    4 Posts

    439

    0

    Posted April 28th, 2005 19:00

    I need help!! I followed Spot Check Billy's previous instructions about the ad-aware and spybot and this si what I got after the two scans
     
     
     
     
    Logfile of HijackThis v1.99.1
    Scan saved at 9:53:22 AM, on 4/28/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\NavNT\defwatch.exe
    C:\Program Files\Canon\MultiPASS\mpservic.exe
    C:\Program Files\NavNT\rtvscan.exe
    C:\WINDOWS\system32\MsgSys.EXE
    C:\PROGRA~1\NavNT\vptray.exe
    C:\WINDOWS\system32\atiptaxx.exe
    C:\Program Files\Canon\MultiPASS\monitr32.exe
    C:\PROGRA~1\Canon\MULTIP~1\MPTBox.exe
    C:\Program Files\Microsoft IntelliPoint\point32.exe
    C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
    C:\Program Files\ATI Multimedia\main\LaunchPd.exe
    C:\Program Files\AIM\aim.exe
    C:\Program Files\Plaxo\2.2.3.2\InstallStub.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\Spyware Doctor\swdoctor.exe
    C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    C:\Program Files\eFax Messenger 3.4\J2GDllCmd.exe
    C:\Program Files\eFax Messenger 3.4\J2GTray.exe
    C:\PROGRA~1\Webshots\webshots.scr
    C:\WINDOWS\system32\FxRedir.EXE
    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\drwtsn32.exe
    C:\WINDOWS\system32\drwtsn32.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
    C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
    C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Aware.exe
    C:\HJT\HijackThis.exe
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://dslstart.verizon.net/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://minisearch.startnow.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://minisearch.startnow.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://minisearch.startnow.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\NavNT\vptray.exe
    O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
    O4 - HKLM\..\Run: [MP_STATUS_MONITOR] "C:\Program Files\Canon\MultiPASS\monitr32.exe" I
    O4 - HKLM\..\Run: [MPTBox] C:\PROGRA~1\Canon\MULTIP~1\MPTBox.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - HKLM\..\RunOnce: [MicrosoftAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
    O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\LaunchPd.exe"
    O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.2.3.2\InstallStub.exe -a
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
    O4 - Startup: eFax Live Menu 3.4.lnk = C:\Program Files\eFax Messenger 3.4\J2GDllCmd.exe
    O4 - Startup: eFax Tray Menu 3.4.lnk = C:\Program Files\eFax Messenger 3.4\J2GTray.exe
    O4 - Startup: Spyware Doctor.lnk = C:\Program Files\Spyware Doctor\swdoctor.exe
    O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZUxdm082YYUS
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: REsearch MSOutlook Interface v2.831 - http://webre1.hawaiiinformation.com/re4/Base/Functions/Email/Java/mlshioli.cab
    O16 - DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) - http://down.plaxo.com/down/latest/PlaxoInstall.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
    O16 - DPF: {49232000-16E4-426C-A231-62846947304B} - http://ipgweb.cce.hp.com/rdqna/downloads/sysinfo.cab
    O16 - DPF: {7DD62E58-5FA8-11D2-AFB7-00104B64F126} (Sview Control) - https://www.docprepservices.com/CABS/SWIFTVIEW/svinstall_a_stat.cab
    O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) - http://h30155.www3.hp.com/ediags/gs/install/guidedsolutions.cab
    O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
    O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
    O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
    O23 - Service: MPService - Canon Information Systems - C:\Program Files\Canon\MultiPASS\mpservic.exe
    O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
  • 141

    0

    Posted May 27th, 2005 02:00

    Here is my problem. Please help me  ss soon as you can
    Logfile of HijackThis v1.99.1
    Scan saved at 7:16:29 PM, on 5/26/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\wltrysvc.exe
    C:\WINDOWS\System32\bcmwltry.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Panda Software\Panda Platinum 2005 Internet Security\Firewall\PavFires.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\XGI\XWatDog.exe
    C:\WINDOWS\BCMSMMSG.exe
    C:\WINDOWS\system32\Trirot.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
    C:\Program Files\Yahoo!\browser\ybrwicon.exe
    C:\Program Files\2Wire\2PortalMon.exe
    C:\WINDOWS\system32\WLTRAY.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\PROGRA~1\Yahoo!\browser\ycommon.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\WINDOWS\system32\drwtsn32.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    D:\HijackThis.exe
    C:\Program Files\hjt\HijackThis.exe
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sb/*http://www.yahoo.com/search/ie.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sp/*http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
    O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
    O4 - HKLM\..\Run: [XGIWatchDog] C:\Program Files\XGI\XWatDog.exe
    O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
    O4 - HKLM\..\Run: [RegServer] regserve.exe
    O4 - HKLM\..\Run: [Trirot] Trirot.exe
    O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Software\Panda Platinum 2005 Internet Security\Inicio.exe"
    O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Platinum 2005 Internet Security\APVXDWIN.EXE" /s
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
    O4 - HKLM\..\Run: [WordPerfect Office 1215] C:\Program Files\WordPerfect Office 12\Programs\Registration.exe /title="WordPerfect Office 12" /date=060906 serial=wa12wrx-0000002-hmd lang=EN
    O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\system32\PRISMSVR.EXE" /APPLY
    O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
    O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
    O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
    O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\RunServices: [PANDA ANTISPAM SERVER SERVICE] "C:\Program Files\Panda Software\Panda Platinum 2005 Internet Security\PasSrv.exe"
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
    O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Panda Firewall Service (PAVFIRES) - Panda Software - C:\Program Files\Panda Software\Panda Platinum 2005 Internet Security\Firewall\PavFires.exe
    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
    O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE