Hello,
Sadly, I have returned as I have become newly infected with a new "quirk". I recently installed firefox to use as my default browser and after a week of use i started getting things popping up in IE windows even though I haven't used it for a while. I have used Kaspersky online scanner, Norton, spybot, ad-Aware and Malwarebytes and i will always find something new even if I scan with one immediatly after a scan and cleanup from any other one.
I have done all in the "Before you post" thread. Here is my HJT log as I need expert help!
Thanks in advance.
Fuzzhead23
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:23:35 PM, on 09/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~2\VPTray.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TY...ION&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...ION&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Spybot-S&D IE Protection - {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {d2622bef-046a-4ca8-9fd7-b48c77dd5534} - (no file)
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [qa1jscj88butp44okg2dy4k3] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\zg7nch5hh3.exe
O4 - HKCU\..\Run: [gtns00w0vffj3aamxmicwarzwho3c86yprxrehhiwf] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\j2ohv6zi1tgl1.exe
O4 - HKCU\..\Run: [yd1kjd1s0ea82zr3vpx4po6hw4paj] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\cz53f4zzw.exe
O4 - HKCU\..\Run: [h2rmymi812ndiw8gjcc6cxl61] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\w61kxiqgj0ma.exe
O4 - HKCU\..\Run: [c2k37ik1fw0fy7j7eefs39qkwetp8jtb1g6s24] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\nhuftmxcq.exe
O4 - HKCU\..\Run: [sxs6pg8qqz29a42o1pk784p] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\onghuvi5vm.exe
O4 - HKCU\..\Run: [bqe0jza8n7kb0oq7ssqp104vaas5j85uyc6892] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\oxd2urfv4u2j.exe
O4 - HKCU\..\Run: [jrvh3ck6dq8kezsm4q2wktk0gznrmiqpx] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\dejjyhfiw.exe
O4 - HKCU\..\Run: [thpu2jaoh1cjkmask9hv3pcg0xb2foadriufxsa08xnzyjz] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\t6unoy48k5.exe
O4 - HKCU\..\Run: [kf7n0s30r2hbdfa92yk3fv7lrgqiuoxa8dd5r0r5j7smq] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\jag62gn8mu.exe
O4 - HKCU\..\Run: [uj07ylf03ptd5l0k3uqkrz8ocz60n0o66oyw2rlr40d26dg4wg] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\vhrkh7nxlsb.exe
O4 - HKCU\..\Run: [oxlfg3axn70e3h8jecc80gdud5cmj3u5ptaxh434fplyahk0o] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\c63lum0s8y1y2.exe
O4 - HKCU\..\Run: [gw0axu13jr7n32z4w] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\b6t7s2gy.exe
O4 - HKCU\..\Run: [f286w6cfnzs81jdtyzeceg48cfvso8wfrnd6il] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\i1lz0t8gz5s.exe
O4 - HKCU\..\Run: [et3accef482qdvqlq78q] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\l403568dz.exe
O4 - HKCU\..\Run: [lrxek2g4bjssmyh1xxio0] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\p5pltkb47p54.exe
O4 - HKCU\..\Run: [g8a1boi506wjrqhb4iugak] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\b07ftsci.exe
O4 - HKCU\..\Run: [bsujnbhn7t801ld0n5kii4e1r3ul] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\juubf769ow.exe
O4 - HKCU\..\Run: [io84zro9p60k52v] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\eq3yq5g2xya.exe
O4 - HKCU\..\Run: [l0rimbk1q6bypvlsbim1xa] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\la2d4kqif7zy.exe
O4 - HKCU\..\Run: [zac2qvy63q2o3couv4jw6x469aq] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\ym21o68z4.exe
O4 - HKCU\..\Run: [o5fiyk62se] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\y0pyp65k.exe
O4 - HKCU\..\Run: [evykwh9472oyizfeeoegzn5bvza3t1pv] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\moexqu3pm5.exe
O4 - HKCU\..\Run: [gz8iq4u2lvo] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\fpdcyz7mno.exe
O4 - HKCU\..\Run: [dhrddfa15oa6p08rrpd58fa7c084j2eein3dsjy0d5j] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\khnsoprkdlgm4.exe
O4 - HKCU\..\Run: [z1idnl692p] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\vet8vzqybphz6.exe
O4 - HKCU\..\Run: [fcut3n4tpkpy9m2t6b315exjskk39e6e] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\flkqx3.exe
O4 - HKCU\..\Run: [i0yg49s3wz8rbjel3b3tqs] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\awfuz6o.exe
O4 - HKCU\..\Run: [bfxno9gzi6b5o3gt2] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\rjs8y6rnrdjz.exe
O4 - HKCU\..\Run: [x19f0t9fxw9k2p49] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\grnsyc6.exe
O4 - HKCU\..\Run: [zrk0zhnving] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\udwyzip2.exe
O4 - HKCU\..\Run: [w21un0rqyl] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\i21pal8h.exe
O4 - HKCU\..\Run: [d0vkzge3try1vxgq7ia7wptwr8rl8yeyl9nw05iwpccw] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\pf8qkzx.exe
O4 - HKCU\..\Run: [bnal9sndm8k2sv3skrdb4d7xr7o5ybpj7ik17w6] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\a66y8201emw.exe
O4 - HKCU\..\Run: [a22zjzkvg4ozsg4w6jsc] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\tuporftt90c2o.exe
O4 - HKCU\..\Run: [w4ecg7tc0ve206uqqnh2temk4wra382uorw7807v7h544cxvyf] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\se1z8r.exe
O4 - HKCU\..\Run: [uoszxjbtsuax5s65kzumnd0o8m8mpisq4g50wynr31a] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\jvolm2ey1g9.exe
O4 - HKCU\..\Run: [fdpv0an581u1q557htb2ni817q7] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\ivlrd4dt.exe
O4 - HKCU\..\Run: [bbj98pfehn2dzx42ni8y59g1lcfyo0nlqxa81ri2q] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\ttixf7b3yt3k.exe
O4 - HKCU\..\Run: [i5s7lizxgm5cddj5fsem0wii781r50zzi0] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\uyosbl5n8b0.exe
O4 - HKCU\..\Run: [z5u0040lmu5w3r] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\v8tq226y95vn.exe
O4 - HKCU\..\Run: [zetdlcip3whud0zilhy1mi0anevg47i] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\q3ijgg0yc.exe
O4 - HKCU\..\Run: [vew9x694z0buzh7b0zoyjim37ad2eqx41l3mbs5mejaa] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\lyc0ikborz5ax.exe
O4 - HKCU\..\Run: [o36q3m5be2lrra53ih9] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\se7gi8ledncq.exe
O4 - HKCU\..\Run: [yrot72yfvlm325] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\zrehb3pmf8k.exe
O4 - HKCU\..\Run: [bmlw8ayh8t88pj1aicxq198rjk8qnyrjrjpo] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\zdx11ku0yr.exe
O4 - HKCU\..\Run: [yblaf7votafiait3mmy36x1gxwid59758o3z9x6onw5t] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\synnn3.exe
O4 - HKCU\..\Run: [fbge74wtxfaglf8boeqxtsxtnatv5y] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\q6j5lx.exe
O4 - HKCU\..\Run: [cmxcb80zlulorvxucr] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\lrzwmfwszmc8g.exe
O4 - HKCU\..\Run: [exqqrjukiw1sg7h6s10sszfyh9sofh0925y902lgolpap7wo] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\fjc6ecnzb4n3s.exe
O4 - HKCU\..\Run: [faxsq5m5pkvwbezrylult13nuq6rpio] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\yb78uymfvshvu.exe
O4 - HKCU\..\Run: [kv1g52yicf2hxrss5te] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\v6vpegac.exe
O4 - HKCU\..\Run: [zsh2ad2rmy4jx0ptkv0] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\mn2b655pag.exe
O4 - HKCU\..\Run: [p80xg94unbek0kkmpktzkmpcqfioiunnjtuv36] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\rrer70eyrm.exe
O4 - HKCU\..\Run: [f6gba6ghtywa5jh279j17ezmv9x3eqqfyezmcutbmppbi] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\m9lvwma3a.exe
O4 - HKCU\..\Run: [nwz49oa6hyirkt52jkpdfnuje] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\p7by113nws.exe
O4 - HKCU\..\Run: [tvmulid1to314i77bybirquhegd1xgahph] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\i4pk7l7hz.exe
O4 - HKCU\..\Run: [diav4gatfzm1pnlf4zc6ug] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\uwwrxgshfe5cg.exe
O4 - HKCU\..\Run: [itpl2luf4r7mix0qm6bcda91d52alun3sadgir9oywr] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\wx94assq9q3s.exe
O4 - HKCU\..\Run: [br4ssd2sdd0etz5z80kerj2em2t7jvd2jpt9] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\vsn9sswc8w.exe
O4 - HKCU\..\Run: [qh2otgon3dxfrk9sy2oc2z2wnbtllcdu] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\p846qzyk1im0.exe
O4 - HKCU\..\Run: [ba5xbcskhynfc0df9dejv1ddb3c7r125cle5] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\o3is8vcss3.exe
O4 - HKCU\..\Run: [fippw3xi0zf8h1aw20ta7yk4k8tosrjvw] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\dgdwhiwu1r22.exe
O4 - HKCU\..\Run: [xfigt1jm0sjjhvecjct5] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\glpwxh8xu.exe
O4 - HKCU\..\Run: [ia4rqp649f9sbngkp5uapnj1ly6j92qa7vp5sa9] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\q454wfx.exe
O4 - HKCU\..\Run: [jtgk1w3w6qg2] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\efo3f9r083x65.exe
O4 - HKCU\..\Run: [rdbll8vvlhbwxtfjfr4v29k80xmwii9php14sadn] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\rndieu55fm.exe
O4 - HKCU\..\Run: [hc9meyx78lwqytw7f2t07ceknwz6b9e7ficd8yytvcfvr] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\awvtukpyp.exe
O4 - HKCU\..\Run: [qgxusqb2tn] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\znu51g8q7za2.exe
O4 - HKCU\..\Run: [xbq1yevzsoea8tentima89w44cv980ek5pbwj7] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\kpvrhejbwz.exe
O4 - HKCU\..\Run: [g34rh6id1qpzcsn7g20gnq1klq] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\g07nlbzni.exe
O4 - HKCU\..\Run: [ogynzox1mz6m8vl6c8vo] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\z2x97ufkerwb3.exe
O4 - HKCU\..\Run: [gyfzjk8rp1r4upe4axkshyy99ndyxu3] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\sp98ez.exe
O4 - HKCU\..\Run: [s2m9zrkap369vei0c] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\ry4a6i6bxl4e9.exe
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - https://www.epost.ca/printing/smsx.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanage...ex-2.2.4.1.cab
O16 - DPF: {CBD8B1CB-2F5F-415F-93E8-A297B33DCBB2} (CentrinoCheck Control) - http://entriq.vo.llnwd.net/o1/NBCUni...ck_1_0_0_5.cab
O16 - DPF: {CE7D2BF2-D173-4CE2-9DAF-15EA153B5B43} - http://entriq.vo.llnwd.net/o1/NBCUni...2_2_Silent.cab
O16 - DPF: {DE0FB644-C59B-46D1-B650-88BA945BC98F} - http://entriq.vo.llnwd.net/o1/NBCUni...al_1_0_0_7.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://l.yimg.com/jh/games/web_games...ploader_v6.cab
O18 - Protocol: CDS300 - {AD43AA67-6860-4531-AC8A-0E68F9CF023E} - E:\CDS300\__CDS2.dll (file missing)
O20 - AppInit_DLLs: bzqpfd.dll
O20 - Winlogon Notify: fccccYpM - C:\WINDOWS\
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service (lavasoft ad-aware service) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
--
End of file - 16088 bytes