|
Help with Browser Hijacker
I have used Spyware Nuker, Ad-Aware SE and norton antivirus and the Hijacker keeps coming back. Here is my Hijackthis log.
Logfile of HijackThis v1.99.1
Scan saved at 4:48:25 AM, on 7/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\atljl.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\PROGRA~1\MICROS~2\GAMECO~1\Common\SWTrayV4.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe
C:\Program Files\Lexmark 4200 Series\lxbmbmon.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Creative\SBAudigy\TaskBar\CTLTray.exe
C:\Program Files\Creative\SBAudigy\TaskBar\CTLTask.exe
C:\Palm\HOTSYNC.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\Program Files\Verizon Online\SupportCenter\bin\mpbtn.exe
C:\Program Files\Spyware Nuker 2004\SWN2.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\hripo.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\hripo.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\hripo.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\hripo.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\hripo.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\hripo.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\hripo.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>
R3 - Default URLSearchHook is missing
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: Class - {FE3D33D0-958B-2C94-A4A8-DB4A4566ED06} - C:\WINDOWS\system32\ieto32.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [SideWinderTrayV4] C:\PROGRA~1\MICROS~2\GAMECO~1\Common\SWTrayV4.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\system32\spool\drivers\w32x86\lexmarklexmark_x63b8e1\printray.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [Lexmark 4200 Series] "C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe"
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [FaxCenterServer4_in_1] "C:\Program Files\Lexmark 4200 Series\Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [netsw32.exe] C:\WINDOWS\netsw32.exe
O4 - HKLM\..\Run: [atljl.exe] C:\WINDOWS\atljl.exe
O4 - HKLM\..\RunOnce: [d3rx32.exe] C:\WINDOWS\system32\d3rx32.exe
O4 - HKLM\..\RunOnce: [sysny.exe] C:\WINDOWS\sysny.exe
O4 - HKLM\..\RunOnce: [systp.exe] C:\WINDOWS\systp.exe
O4 - HKLM\..\RunOnce: [netqn32.exe] C:\WINDOWS\netqn32.exe
O4 - HKLM\..\RunOnce: [apiwk32.exe] C:\WINDOWS\system32\apiwk32.exe
O4 - HKLM\..\RunOnce: [apiwm.exe] C:\WINDOWS\system32\apiwm.exe
O4 - HKLM\..\RunOnce: [crfy.exe] C:\WINDOWS\system32\crfy.exe
O4 - HKLM\..\RunOnce: [ntuu.exe] C:\WINDOWS\ntuu.exe
O4 - HKLM\..\RunOnce: [d3dc32.exe] C:\WINDOWS\system32\d3dc32.exe
O4 - HKLM\..\RunOnce: [appvl32.exe] C:\WINDOWS\system32\appvl32.exe
O4 - HKLM\..\RunOnce: [ntnt.exe] C:\WINDOWS\system32\ntnt.exe
O4 - HKLM\..\RunOnce: [cruq.exe] C:\WINDOWS\system32\cruq.exe
O4 - HKLM\..\RunOnce: [mssa32.exe] C:\WINDOWS\mssa32.exe
O4 - HKLM\..\RunOnce: [atlmf32.exe] C:\WINDOWS\system32\atlmf32.exe
O4 - HKLM\..\RunOnce: [msge.exe] C:\WINDOWS\system32\msge.exe
O4 - HKLM\..\RunOnce: [ieur32.exe] C:\WINDOWS\system32\ieur32.exe
O4 - HKLM\..\RunOnce: [crbc.exe] C:\WINDOWS\system32\crbc.exe
O4 - HKLM\..\RunOnce: [mfcjs32.exe] C:\WINDOWS\system32\mfcjs32.exe
O4 - HKLM\..\RunOnce: [msri32.exe] C:\WINDOWS\msri32.exe
O4 - HKLM\..\RunOnce: [apilu32.exe] C:\WINDOWS\system32\apilu32.exe
O4 - HKLM\..\RunOnce: [javajx.exe] C:\WINDOWS\javajx.exe
O4 - HKLM\..\RunOnce: [crya32.exe] C:\WINDOWS\system32\crya32.exe
O4 - HKLM\..\RunOnce: [ieip.exe] C:\WINDOWS\system32\ieip.exe
O4 - HKLM\..\RunOnce: [addqq.exe] C:\WINDOWS\system32\addqq.exe
O4 - HKLM\..\RunOnce: [javahz32.exe] C:\WINDOWS\javahz32.exe
O4 - HKLM\..\RunOnce: [mfcoz32.exe] C:\WINDOWS\system32\mfcoz32.exe
O4 - HKLM\..\RunOnce: [crww32.exe] C:\WINDOWS\system32\crww32.exe
O4 - HKLM\..\RunOnce: [wingw32.exe] C:\WINDOWS\system32\wingw32.exe
O4 - HKLM\..\RunOnce: [crhl32.exe] C:\WINDOWS\crhl32.exe
O4 - HKLM\..\RunOnce: [atlok32.exe] C:\WINDOWS\atlok32.exe
O4 - HKLM\..\RunOnce: [atlbf32.exe] C:\WINDOWS\system32\atlbf32.exe
O4 - HKLM\..\RunOnce: [ielk.exe] C:\WINDOWS\ielk.exe
O4 - HKLM\..\RunOnce: [ieez32.exe] C:\WINDOWS\system32\ieez32.exe
O4 - HKLM\..\RunOnce: [addun32.exe] C:\WINDOWS\addun32.exe
O4 - HKLM\..\RunOnce: [sysde.exe] C:\WINDOWS\system32\sysde.exe
O4 - HKLM\..\RunOnce: [d3qw.exe] C:\WINDOWS\system32\d3qw.exe
O4 - HKLM\..\RunOnce: [mssx.exe] C:\WINDOWS\system32\mssx.exe
O4 - HKLM\..\RunOnce: [addtd32.exe] C:\WINDOWS\system32\addtd32.exe
O4 - HKLM\..\RunOnce: [javaeu.exe] C:\WINDOWS\system32\javaeu.exe
O4 - HKLM\..\RunOnce: [mshq32.exe] C:\WINDOWS\mshq32.exe
O4 - HKLM\..\RunOnce: [netxw.exe] C:\WINDOWS\system32\netxw.exe
O4 - HKLM\..\RunOnce: [appms.exe] C:\WINDOWS\appms.exe
O4 - HKLM\..\RunOnce: [javapa32.exe] C:\WINDOWS\system32\javapa32.exe
O4 - HKLM\..\RunOnce: [addpo32.exe] C:\WINDOWS\system32\addpo32.exe
O4 - HKLM\..\RunOnce: [ipqt32.exe] C:\WINDOWS\ipqt32.exe
O4 - HKLM\..\RunOnce: [sysbl32.exe] C:\WINDOWS\sysbl32.exe
O4 - HKLM\..\RunOnce: [mshh32.exe] C:\WINDOWS\mshh32.exe
O4 - HKLM\..\RunOnce: [winub32.exe] C:\WINDOWS\winub32.exe
O4 - HKLM\..\RunOnce: [apptw32.exe] C:\WINDOWS\apptw32.exe
O4 - HKLM\..\RunOnce: [crvw32.exe] C:\WINDOWS\crvw32.exe
O4 - HKLM\..\RunOnce: [ntsw.exe] C:\WINDOWS\system32\ntsw.exe
O4 - HKLM\..\RunOnce: [javaix32.exe] C:\WINDOWS\javaix32.exe
O4 - HKLM\..\RunOnce: [ipgc.exe] C:\WINDOWS\ipgc.exe
O4 - HKLM\..\RunOnce: [mfcpa32.exe] C:\WINDOWS\mfcpa32.exe
O4 - HKLM\..\RunOnce: [ntdi32.exe] C:\WINDOWS\ntdi32.exe
O4 - HKLM\..\RunOnce: [ntqg32.exe] C:\WINDOWS\ntqg32.exe
O4 - HKLM\..\RunOnce: [syszt.exe] C:\WINDOWS\system32\syszt.exe
O4 - HKLM\..\RunOnce: [atlqo.exe] C:\WINDOWS\system32\atlqo.exe
O4 - HKLM\..\RunOnce: [ipjs32.exe] C:\WINDOWS\ipjs32.exe
O4 - HKLM\..\RunOnce: [crdo32.exe] C:\WINDOWS\system32\crdo32.exe
O4 - HKLM\..\RunOnce: [netqd.exe] C:\WINDOWS\system32\netqd.exe
O4 - HKLM\..\RunOnce: [ntdc32.exe] C:\WINDOWS\system32\ntdc32.exe
O4 - HKLM\..\RunOnce: [d3vk.exe] C:\WINDOWS\system32\d3vk.exe
O4 - HKLM\..\RunOnce: [appbj32.exe] C:\WINDOWS\appbj32.exe
O4 - HKLM\..\RunOnce: [addhe.exe] C:\WINDOWS\addhe.exe
O4 - HKLM\..\RunOnce: [netxu32.exe] C:\WINDOWS\netxu32.exe
O4 - HKLM\..\RunOnce: [appko.exe] C:\WINDOWS\appko.exe
O4 - HKLM\..\RunOnce: [iewi32.exe] C:\WINDOWS\system32\iewi32.exe
O4 - HKLM\..\RunOnce: [javasr.exe] C:\WINDOWS\javasr.exe
O4 - HKLM\..\RunOnce: [appgo32.exe] C:\WINDOWS\appgo32.exe
O4 - HKLM\..\RunOnce: [crxk.exe] C:\WINDOWS\system32\crxk.exe
O4 - HKLM\..\RunOnce: [ntod32.exe] C:\WINDOWS\ntod32.exe
O4 - HKLM\..\RunOnce: [apppu.exe] C:\WINDOWS\apppu.exe
O4 - HKLM\..\RunOnce: [sdkeb.exe] C:\WINDOWS\sdkeb.exe
O4 - HKLM\..\RunOnce: [apirw32.exe] C:\WINDOWS\apirw32.exe
O4 - HKLM\..\RunOnce: [mszm32.exe] C:\WINDOWS\mszm32.exe
O4 - HKLM\..\RunOnce: [ntpy.exe] C:\WINDOWS\ntpy.exe
O4 - HKLM\..\RunOnce: [winbo.exe] C:\WINDOWS\winbo.exe
O4 - HKLM\..\RunOnce: [ipyb.exe] C:\WINDOWS\system32\ipyb.exe
O4 - HKLM\..\RunOnce: [ntad32.exe] C:\WINDOWS\ntad32.exe
O4 - HKLM\..\RunOnce: [apihw32.exe] C:\WINDOWS\apihw32.exe
O4 - HKLM\..\RunOnce: [appns32.exe] C:\WINDOWS\appns32.exe
O4 - HKLM\..\RunOnce: [mfcvu32.exe] C:\WINDOWS\system32\mfcvu32.exe
O4 - HKLM\..\RunOnce: [netca.exe] C:\WINDOWS\netca.exe
O4 - HKLM\..\RunOnce: [apppl32.exe] C:\WINDOWS\system32\apppl32.exe
O4 - HKLM\..\RunOnce: [javapq.exe] C:\WINDOWS\system32\javapq.exe
O4 - HKLM\..\RunOnce: [crls32.exe] C:\WINDOWS\system32\crls32.exe
O4 - HKLM\..\RunOnce: [crxg.exe] C:\WINDOWS\system32\crxg.exe
O4 - HKLM\..\RunOnce: [netee.exe] C:\WINDOWS\system32\netee.exe
O4 - HKLM\..\RunOnce: [javazp32.exe] C:\WINDOWS\system32\javazp32.exe
O4 - HKLM\..\RunOnce: [atlwp.exe] C:\WINDOWS\system32\atlwp.exe
O4 - HKLM\..\RunOnce: [mfcsc32.exe] C:\WINDOWS\system32\mfcsc32.exe
O4 - HKLM\..\RunOnce: [d3bb32.exe] C:\WINDOWS\system32\d3bb32.exe
O4 - HKLM\..\RunOnce: [ipxb.exe] C:\WINDOWS\system32\ipxb.exe
O4 - HKLM\..\RunOnce: [iell32.exe] C:\WINDOWS\system32\iell32.exe
O4 - HKLM\..\RunOnce: [netou.exe] C:\WINDOWS\netou.exe
O4 - HKLM\..\RunOnce: [sdkvb32.exe] C:\WINDOWS\sdkvb32.exe
O4 - HKLM\..\RunOnce: [winha32.exe] C:\WINDOWS\system32\winha32.exe
O4 - HKLM\..\RunOnce: [apifg32.exe] C:\WINDOWS\system32\apifg32.exe
O4 - HKLM\..\RunOnce: [appmj.exe] C:\WINDOWS\appmj.exe
O4 - HKLM\..\RunOnce: [atlae32.exe] C:\WINDOWS\system32\atlae32.exe
O4 - HKLM\..\RunOnce: [sdkdl32.exe] C:\WINDOWS\sdkdl32.exe
O4 - HKLM\..\RunOnce: [appoa.exe] C:\WINDOWS\system32\appoa.exe
O4 - HKLM\..\RunOnce: [ntpi.exe] C:\WINDOWS\ntpi.exe
O4 - HKLM\..\RunOnce: [msjt32.exe] C:\WINDOWS\msjt32.exe
O4 - HKLM\..\RunOnce: [appmf.exe] C:\WINDOWS\appmf.exe
O4 - HKLM\..\RunOnce: [mfcyo32.exe] C:\WINDOWS\system32\mfcyo32.exe
O4 - HKLM\..\RunOnce: [sdkhg32.exe] C:\WINDOWS\sdkhg32.exe
O4 - HKCU\..\Run: [TaskTray] "C:\Program Files\Creative\SBAudigy\TaskBar\CTLTray.exe"
O4 - HKCU\..\Run: [TaskBar] "C:\Program Files\Creative\SBAudigy\TaskBar\CTLTask.exe"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: RealAudio.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Control Pad - {28D44DAD-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\Verizon Online Control Pad\VerizonControlPad.Exe
O9 - Extra 'Tools' menuitem: Control Pad - {28D44DAD-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\Verizon Online Control Pad\VerizonControlPad.Exe
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O17 - HKLM\System\CCS\Services\Tcpip\..\{D5B61ECA-6052-4A3F-88F9-D39ADAA280EE}: NameServer = 192.168.1.1
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
|