louball
2009-09-11, 08:09
I've read the "read this first" section and have installed erunt and hijack this. Here is my ht log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:45:25 AM, on 11/09/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [RecoverFromReboot] C:\WINDOWS\Temp\RecoverFromReboot.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe
O4 - HKLM\..\Run: [PromoReg] C:\WINDOWS\Temp\_ex-08.exe
O4 - HKLM\..\Run: [13091744] C:\Documents and Settings\All Users\Application Data\13091744\13091744.exe
O4 - HKLM\..\RunOnce: [SpybotDeletingA9468] command.com /c del "C:\WINDOWS\system32\braviax.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3417] cmd.exe /c del "C:\WINDOWS\system32\braviax.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4961] command.com /c del "C:\Program Files\PC_Antispyware2010\AVEngn.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7968] cmd.exe /c del "C:\Program Files\PC_Antispyware2010\AVEngn.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4717] command.com /c del "C:\Program Files\PC_Antispyware2010\htmlayout.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2168] cmd.exe /c del "C:\Program Files\PC_Antispyware2010\htmlayout.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2201] command.com /c del "C:\Program Files\PC_Antispyware2010\pthreadVC2.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC153] cmd.exe /c del "C:\Program Files\PC_Antispyware2010\pthreadVC2.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7998] command.com /c del "C:\Program Files\PC_Antispyware2010\data\daily.cvd"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3526] cmd.exe /c del "C:\Program Files\PC_Antispyware2010\data\daily.cvd"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7583] command.com /c del "C:\Program Files\PC_Antispyware2010\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1956] cmd.exe /c del "C:\Program Files\PC_Antispyware2010\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest"
O4 - HKLM\..\RunOnce: [SpybotDeletingA816] command.com /c del "C:\Program Files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcm80.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4434] cmd.exe /c del "C:\Program Files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcm80.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3316] command.com /c del "C:\Program Files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcp80.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2220] cmd.exe /c del "C:\Program Files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcp80.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1816] command.com /c del "C:\Program Files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcr80.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8510] cmd.exe /c del "C:\Program Files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcr80.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4675] command.com /c del "C:\Program Files\PC_Antispyware2010\PC_Antispyware2010.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3905] cmd.exe /c del "C:\Program Files\PC_Antispyware2010\PC_Antispyware2010.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingA208] command.com /c del "C:\Program Files\PC_Antispyware2010\wscui.cpl"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4866] cmd.exe /c del "C:\Program Files\PC_Antispyware2010\wscui.cpl"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7253] command.com /c del "C:\Documents and Settings\lcarden\Desktop\PC_Antispyware2010.lnk"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5154] cmd.exe /c del "C:\Documents and Settings\lcarden\Desktop\PC_Antispyware2010.lnk"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4397] command.com /c del "C:\Documents and Settings\lcarden\Start Menu\Programs\PC_Antispyware2010\PC_Antispyware2010.lnk"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3742] cmd.exe /c del "C:\Documents and Settings\lcarden\Start Menu\Programs\PC_Antispyware2010\PC_Antispyware2010.lnk"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [sys32_nov] C:\Documents and Settings\lcarden\sys32_nov.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: ikowin32.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
--
End of file - 8947 bytes
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:45:25 AM, on 11/09/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [RecoverFromReboot] C:\WINDOWS\Temp\RecoverFromReboot.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe
O4 - HKLM\..\Run: [PromoReg] C:\WINDOWS\Temp\_ex-08.exe
O4 - HKLM\..\Run: [13091744] C:\Documents and Settings\All Users\Application Data\13091744\13091744.exe
O4 - HKLM\..\RunOnce: [SpybotDeletingA9468] command.com /c del "C:\WINDOWS\system32\braviax.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3417] cmd.exe /c del "C:\WINDOWS\system32\braviax.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4961] command.com /c del "C:\Program Files\PC_Antispyware2010\AVEngn.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7968] cmd.exe /c del "C:\Program Files\PC_Antispyware2010\AVEngn.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4717] command.com /c del "C:\Program Files\PC_Antispyware2010\htmlayout.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2168] cmd.exe /c del "C:\Program Files\PC_Antispyware2010\htmlayout.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2201] command.com /c del "C:\Program Files\PC_Antispyware2010\pthreadVC2.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC153] cmd.exe /c del "C:\Program Files\PC_Antispyware2010\pthreadVC2.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7998] command.com /c del "C:\Program Files\PC_Antispyware2010\data\daily.cvd"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3526] cmd.exe /c del "C:\Program Files\PC_Antispyware2010\data\daily.cvd"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7583] command.com /c del "C:\Program Files\PC_Antispyware2010\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1956] cmd.exe /c del "C:\Program Files\PC_Antispyware2010\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest"
O4 - HKLM\..\RunOnce: [SpybotDeletingA816] command.com /c del "C:\Program Files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcm80.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4434] cmd.exe /c del "C:\Program Files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcm80.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3316] command.com /c del "C:\Program Files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcp80.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2220] cmd.exe /c del "C:\Program Files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcp80.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1816] command.com /c del "C:\Program Files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcr80.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8510] cmd.exe /c del "C:\Program Files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcr80.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4675] command.com /c del "C:\Program Files\PC_Antispyware2010\PC_Antispyware2010.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3905] cmd.exe /c del "C:\Program Files\PC_Antispyware2010\PC_Antispyware2010.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingA208] command.com /c del "C:\Program Files\PC_Antispyware2010\wscui.cpl"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4866] cmd.exe /c del "C:\Program Files\PC_Antispyware2010\wscui.cpl"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7253] command.com /c del "C:\Documents and Settings\lcarden\Desktop\PC_Antispyware2010.lnk"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5154] cmd.exe /c del "C:\Documents and Settings\lcarden\Desktop\PC_Antispyware2010.lnk"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4397] command.com /c del "C:\Documents and Settings\lcarden\Start Menu\Programs\PC_Antispyware2010\PC_Antispyware2010.lnk"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3742] cmd.exe /c del "C:\Documents and Settings\lcarden\Start Menu\Programs\PC_Antispyware2010\PC_Antispyware2010.lnk"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [sys32_nov] C:\Documents and Settings\lcarden\sys32_nov.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: ikowin32.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
--
End of file - 8947 bytes