Okay, Joey, here we go. Sorry it took so long to get this done. We got it cleaned enough to be usable for our users, and were dealing with other issues.
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 7:24:27 AM, 03/09/2005
+ Report-Checksum: 9D194E2B
+ Date of database: 03/09/2005
+ Version of scan engine: v3.0
+ Duration: 18 min
+ Scanned Files: 31780
+ Speed: 28.26 Files/Second
+ Infected files: 107
+ Removed files: 107
+ Files put in quarantine: 107
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0
+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes
+ Scanned items:
C:\
+ Scan result:
C:\Documents and Settings\80166pos\Application Data\erts.exe -> Spyware.PurityScan.v -> Cleaned with backup
C:\Documents and Settings\80166pos\Desktop\backups\backup-20050304-091555-234.dll -> Spyware.Adstart.c -> Cleaned with backup
C:\Documents and Settings\80166pos\Desktop\backups\backup-20050304-091555-390.dll -> Spyware.ClearSearch.u -> Cleaned with backup
C:\Documents and Settings\80166pos\Desktop\backups\backup-20050304-091555-646.dll -> Spyware.ClearSearch.u -> Cleaned with backup
C:\Documents and Settings\80166pos\Desktop\backups\backup-20050304-091555-805.dll -> Spyware.ClearSearch.u -> Cleaned with backup
C:\Documents and Settings\80166pos\Desktop\backups\backup-20050304-091555-885.dll -> Spyware.Adstart.c -> Cleaned with backup
C:\Documents and Settings\80166pos\Desktop\backups\backup-20050304-091555-972.dll -> Spyware.ClearSearch.u -> Cleaned with backup
C:\Documents and Settings\80166pos\Desktop\backups\backup-20050304-091556-300.dll -> Spyware.ClearSearch.u -> Cleaned with backup
C:\Documents and Settings\80166pos\Desktop\backups\backup-20050304-091556-444.dll -> Spyware.ClearSearch.u -> Cleaned with backup
C:\Documents and Settings\80166pos\Desktop\backups\backup-20050304-091556-524.dll -> Spyware.ClearSearch.u -> Cleaned with backup
C:\Documents and Settings\80166pos\Desktop\backups\backup-20050304-091556-545.dll -> Spyware.ClearSearch.u -> Cleaned with backup
C:\Documents and Settings\80166pos\Desktop\backups\backup-20050304-091556-579.dll -> Spyware.ClearSearch.u -> Cleaned with backup
C:\Documents and Settings\80166pos\Desktop\backups\backup-20050304-091556-586.dll -> Spyware.ClearSearch.u -> Cleaned with backup
C:\Documents and Settings\80166pos\Desktop\backups\backup-20050304-091556-608.dll -> Spyware.ClearSearch.u -> Cleaned with backup
C:\Documents and Settings\80166pos\Desktop\backups\backup-20050304-091556-671.dll -> Spyware.ClearSearch.u -> Cleaned with backup
C:\Documents and Settings\80166pos\Desktop\backups\backup-20050304-091556-683.dll -> Spyware.ClearSearch.u -> Cleaned with backup
C:\Documents and Settings\80166pos\Desktop\backups\backup-20050304-091556-769.dll -> Spyware.ClearSearch.u -> Cleaned with backup
C:\Documents and Settings\80166pos\Desktop\backups\backup-20050304-091556-781.dll -> Spyware.ClearSearch.u -> Cleaned with backup
C:\Documents and Settings\80166pos\Desktop\backups\backup-20050304-091556-866.dll -> Spyware.ClearSearch.u -> Cleaned with backup
C:\Documents and Settings\80166pos\Desktop\backups\backup-20050304-091556-985.dll -> Spyware.ClearSearch.u -> Cleaned with backup
C:\Documents and Settings\Administrator\Application Data\erts.exe -> Spyware.PurityScan.v -> Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@ping[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\diagus\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\diagus\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\diagus\Cookies\
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\diagus\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\diagus\Cookies\diagus@link[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\diagus\Cookies\diagus@S120498[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\diagus\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\elibar\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\elibar\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\elipfa\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\elipfa\Cookies\elipfa@atdmt[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\elipfa\Cookies\elipfa@dcslt9a2911e5h27gz9cy9xcg_5f1j[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\elipfa\Cookies\elipfa@dcsuuftkberp17368wkcsn8pc_5z5u[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\elipfa\Cookies\elipfa@dcsx8czs1erp17368wkcsn8pc_9z2q[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\elipfa\Cookies\elipfa@doubleclick[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\elipfa\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\jamkee\Cookies\jamkee@com[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\jamkee\Cookies\jamkee@exitexchange[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\jamkee\Cookies\jamkee@S005-01-9-28-233860-106434[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\NELBRO\Cookies\
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\NELBRO\Cookies\
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\NELBRO\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\NELBRO\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\NELBRO\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\NELBRO\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\NELBRO\Cookies\nelbro@tryaolfree[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\1AC2758D-6027-48E4-9449-49DC54\42987E0F-65CF-401A-ABDE-894574 -> Spyware.IBISToolbar -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\1AC2758D-6027-48E4-9449-49DC54\B7639B93-AF13-45C3-A3CD-E9CFB2 -> Spyware.IBISToolbar -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\F2CB59EF-25A2-4D58-9569-76818D\2F279D70-DAAC-441E-A0D9-86C29D -> Spyware.BiSpy.t -> Cleaned with backup
C:\Program Files\vhkcb4a6\vhkcb4a6.dll -> Spyware.ClearSearch.u -> Cleaned with backup
C:\Program Files\vhkcb4a6\vhkcb4a6.exe -> Backdoor.Ruledor.f -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc10.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc104.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc108.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc110.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc113.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc121.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc124.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc13.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc134.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc135.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc136.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc138.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc146.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc150.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc157.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc159.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc161.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc163.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc165.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc168.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc169.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc171.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc18.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc19.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc27.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc34.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc35.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc36.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc37.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc4.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc42.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc45.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc50.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc51.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc6.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc61.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc63.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc64.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc65.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc66.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc70.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc73.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc74.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc75.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc8.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc81.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc83.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc89.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc9.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\S-1-5-21-2041269577-444530729-9522986-33502\Dc99.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\WINNT\farmmext.bad -> Spyware.ConsCorr -> Cleaned with backup
C:\WINNT\farmmext.exe -> Spyware.ConsCorr -> Cleaned with backup
C:\WINNT\system\wuhfnpjpp.exe -> TrojanDownloader.Small.aly -> Cleaned with backup
C:\WINNT\system32\dun.exe -> Spyware.DealHelper.x -> Cleaned with backup
::Report End-----------------------------------------------------------------------------------------------
Logfile of HijackThis v1.99.1Scan saved at 7:28:05 AM, on 03/09/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINNT\System32\svchost.exe
C:\PROGRA~1\MICROS~2\MSSQL\binn\sqlservr.exe
C:\Program Files\Reflection\rtsserv.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\r_server.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINNT\system32\CCM\CcmExec.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\igfxtray.exe
C:\WINNT\System32\hkcmd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINNT\TWShell.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Spyware\Hijack This\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - Global Startup: logon.bat
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: Shortcut to TWShell.lnk = C:\WINNT\TWShell.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar2.dll/cmtrans.html
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0006F063-0000-0000-C000-000000000046} (Microsoft Outlook View Control) -
http://activex.micro...ce/outlctlx.CABO16 - DPF: {62CEC9E0-3811-4C36-A94E-4F7565DCD23F} (DDSC Class) -
http://sptsrv19/BISP...rces/msddsc.cabO17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = thecreek.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = thecreek.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = thecreek.com
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: MultiCast Listener (MCListener) - Datavantage - C:\PROGRA~1\TRADEW~1\MULTIC~1.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: Reflection TimeSync - WRQ, Inc. - C:\Program Files\Reflection\rtsserv.exe
O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINNT\system32\r_server.exe" /service (file missing)
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
End of log-----------------------------------------------------------------------------------------------
I sure do appreciate your help! Thank you for your time on this.